1d475a6cf5
Declared as a boolean, isActive rendered as a checkbox in the toolbox, and a checkbox has no empty state: the count was forced to one half of the fleet or the other, with no way to ask for both. As text, an empty field means the filter is not sent. true/yes/1 and false/no/0 are read in any case, a real JSON boolean from a playbook still works, and anything else is refused rather than folded into false — that would answer a different question than the one asked.
989 lines
51 KiB
YAML
989 lines
51 KiB
YAML
id: sentinelone
|
|
name: SentinelOne
|
|
version: 1.7.1
|
|
description: "SentinelOne Singularity (API v2.1) — endpoint detection & response: triage threats, enrich, isolate/reconnect hosts, mitigate, scan."
|
|
changelog: "1.7.1 — count_agents' isActive filter is a text field again: declared as a boolean it rendered as a checkbox, which has no empty state, so the count could never be asked for both the active and the inactive agents. Left empty the filter is not sent. 1.7.0 — count_agents takes an accountIds filter, so a multi-tenant console can be counted one account at a time. 1.6.0 — count_agents takes an isActive filter, to count the active agents apart from the inactive ones; left unset, the count still covers both. 1.5.0 — count_agents takes four more filters: agentVersion__gt to count the fleet still below a target build, networkStatuses to count only the endpoints in a given connection state, operationalStatesNin to leave states out of the count, and machineTypes to count servers apart from laptops. 1.4.0 — get_threats and get_alerts accept an optional account_ids filter (accountIds), so a multi-tenant console can be scoped to one or more accounts at fetch time. 1.3.0 — Exhaustive OCSF mappers: get_threats (38 fields) and get_alerts (58 fields) now cover device, finding, malware, actor/target process, file, registry, network, indicators and container. 1.2.4 — Re-modelled the OCSF mappers to OCSF actor/target semantics: the initiating process maps to actor.* (actor.process, actor.user), and the process/file acted upon maps to the target (process.*, file.*, user.*). 1.2.3 — Expanded the OCSF mappers (get_threats, get_alerts) with more fields: file hashes (sha1/md5), file ext/size, finding/rule ids, confidence, status, parent process and device/user identity. 1.2.2 — Added pre-built OCSF mappers (get_threats, get_alerts) for the mapper library. 1.2.1 — Added test_connection for the instance Test button. 1.2.0 — Added 13 commands: threat-analysis, threat-download-from-cloud, abort-endpoint-scan, endpoint-fetch-logs, fetch-file, get-remote-script-task-status/results, get-service-users, list-installed-singularity-marketplace-applications, update-uam-alert-status/verdict, run-powerquery and create-tag-rule (83 commands total). 1.1.0 — Command names prefixed with 'sentinelone-' (e.g. sentinelone-isolate-agent) for easier toolbox search; command IDs unchanged. 1.0.0 — Initial release: 70 commands covering agents, threats, alerts, blocklist/exclusions, IOCs, STAR rules, Deep Visibility, remote scripts, tags, firewall and network discovery based on the SentinelOne API v2.1."
|
|
category: endpoint
|
|
|
|
# Per-instance configuration. The scripts build the API base as <url>/web/api/v2.1.
|
|
config_schema:
|
|
properties:
|
|
url:
|
|
type: string
|
|
description: SentinelOne console URL, e.g. https://usea1.sentinelone.net
|
|
api_token:
|
|
type: string
|
|
description: API token (console → My User → API Token)
|
|
x-soar-sensitive: true
|
|
required:
|
|
- url
|
|
- api_token
|
|
|
|
# Documented for reference; the bundled scripts build the header themselves
|
|
# (Authorization: ApiToken <token>).
|
|
auth:
|
|
- id: apitoken
|
|
type: api_key
|
|
in: header
|
|
name: Authorization
|
|
value_template: "ApiToken {{secret}}"
|
|
secret_field: api_token
|
|
|
|
commands:
|
|
# ── Enrichment / read ─────────────────────────────────────────────────────
|
|
- id: get_threats
|
|
name: sentinelone-get-threats
|
|
description: List threats/detections matching filters.
|
|
inputs_schema:
|
|
properties:
|
|
limit: { type: number, description: "Max results (default 20)" }
|
|
mitigation_status: { type: string, description: "mitigated | active | blocked | suspicious | pending" }
|
|
query: { type: string, description: "Free-text (hash, file, computer name, uuid)" }
|
|
threat_ids: { type: string, description: "Comma-separated threat IDs" }
|
|
created_after: { type: string, description: "ISO8601 lower bound on createdAt" }
|
|
account_ids: { type: string, description: "Optional comma-separated account IDs to scope the search to." }
|
|
required: []
|
|
outputs_schema: { properties: {} }
|
|
ingest:
|
|
results_path: data
|
|
dedup_key: id
|
|
incremental_field: created_after
|
|
|
|
- id: list_agents
|
|
name: sentinelone-list-agents
|
|
description: List endpoints (agents) matching filters.
|
|
inputs_schema:
|
|
properties:
|
|
computer_name: { type: string, description: "Substring match on computer name" }
|
|
os_type: { type: string, description: "windows | macos | linux" }
|
|
is_active: { type: boolean, description: "Only active agents" }
|
|
limit: { type: number, description: "Max results (default 50)" }
|
|
required: []
|
|
outputs_schema: { properties: {} }
|
|
|
|
- id: get_agent
|
|
name: sentinelone-get-agent
|
|
description: Get details for one or more agents by ID.
|
|
inputs_schema:
|
|
properties:
|
|
agent_ids: { type: string, description: "Comma-separated agent IDs" }
|
|
required: [agent_ids]
|
|
outputs_schema: { properties: {} }
|
|
|
|
- id: get_hash_verdict
|
|
name: sentinelone-get-hash-verdict
|
|
description: Reputation verdict for a SHA1 hash.
|
|
inputs_schema:
|
|
properties:
|
|
hash: { type: string, description: "SHA1 hash" }
|
|
required: [hash]
|
|
outputs_schema: { properties: {} }
|
|
|
|
# ── Response ──────────────────────────────────────────────────────────────
|
|
- id: isolate_agent
|
|
name: sentinelone-isolate-agent
|
|
description: Disconnect agents from the network.
|
|
inputs_schema:
|
|
properties:
|
|
agent_ids: { type: string, description: "Comma-separated agent IDs" }
|
|
required: [agent_ids]
|
|
outputs_schema: { properties: {} }
|
|
|
|
- id: reconnect_agent
|
|
name: sentinelone-reconnect-agent
|
|
description: Reconnect agents to the network.
|
|
inputs_schema:
|
|
properties:
|
|
agent_ids: { type: string, description: "Comma-separated agent IDs" }
|
|
required: [agent_ids]
|
|
outputs_schema: { properties: {} }
|
|
|
|
- id: mitigate_threat
|
|
name: sentinelone-mitigate-threat
|
|
description: Apply a mitigation action to threats (kill, quarantine, remediate, rollback).
|
|
inputs_schema:
|
|
properties:
|
|
action: { type: string, description: "kill | quarantine | un-quarantine | remediate | rollback-remediation" }
|
|
threat_ids: { type: string, description: "Comma-separated threat IDs" }
|
|
required: [action, threat_ids]
|
|
outputs_schema: { properties: {} }
|
|
|
|
- id: initiate_scan
|
|
name: sentinelone-initiate-scan
|
|
description: Start a full disk scan on agents.
|
|
inputs_schema:
|
|
properties:
|
|
agent_ids: { type: string, description: "Comma-separated agent IDs" }
|
|
required: [agent_ids]
|
|
outputs_schema: { properties: {} }
|
|
|
|
- id: write_threat_note
|
|
name: sentinelone-write-threat-note
|
|
description: Add a note to one or more threats.
|
|
inputs_schema:
|
|
properties:
|
|
threat_ids: { type: string, description: "Comma-separated threat IDs" }
|
|
note: { type: string, description: "Note text" }
|
|
required: [threat_ids, note]
|
|
outputs_schema: { properties: {} }
|
|
|
|
# ── Agents: actions & info ────────────────────────────────────────────────
|
|
- id: shutdown_agent
|
|
name: sentinelone-shutdown-agent
|
|
description: "Send a shutdown command to agents matching the filter."
|
|
inputs_schema:
|
|
properties:
|
|
agent_id: { type: string, description: "Comma-separated agent IDs" }
|
|
group_id: { type: string, description: "Comma-separated group IDs" }
|
|
query: { type: string, description: "Free-text agent match" }
|
|
required: []
|
|
outputs_schema: { properties: {} }
|
|
- id: uninstall_agent
|
|
name: sentinelone-uninstall-agent
|
|
description: "Send an uninstall command to agents matching the filter."
|
|
inputs_schema:
|
|
properties:
|
|
agent_id: { type: string, description: "Comma-separated agent IDs" }
|
|
group_id: { type: string, description: "Comma-separated group IDs" }
|
|
query: { type: string, description: "Free-text agent match" }
|
|
required: []
|
|
outputs_schema: { properties: {} }
|
|
- id: broadcast_message
|
|
name: sentinelone-broadcast-message
|
|
description: "Broadcast a message to agents matching the filter."
|
|
inputs_schema:
|
|
properties:
|
|
message: { type: string, description: "Message to broadcast to agents" }
|
|
agent_id: { type: string, description: "Comma-separated agent IDs" }
|
|
group_id: { type: string, description: "Comma-separated group IDs" }
|
|
active_agent: { type: boolean, description: "Only target active agents" }
|
|
required: [message]
|
|
outputs_schema: { properties: {} }
|
|
- id: enable_agent
|
|
name: sentinelone-enable-agent
|
|
description: "Enable agents matching the given IDs, optionally rebooting them."
|
|
inputs_schema:
|
|
properties:
|
|
agent_ids: { type: string, description: "Comma-separated agent IDs" }
|
|
shouldReboot: { type: boolean, description: "Reboot agents after enabling" }
|
|
required: [agent_ids]
|
|
outputs_schema: { properties: {} }
|
|
- id: move_agent
|
|
name: sentinelone-move-agent
|
|
description: "Move agents into the specified group."
|
|
inputs_schema:
|
|
properties:
|
|
group_id: { type: string, description: "Target group ID" }
|
|
agents_ids: { type: string, description: "Comma-separated agent IDs to move" }
|
|
required: [group_id, agents_ids]
|
|
outputs_schema: { properties: {} }
|
|
- id: count_agents
|
|
name: sentinelone-count-agents
|
|
description: "Count agents matching the given filters."
|
|
inputs_schema:
|
|
properties:
|
|
computer_name: { type: string, description: "Filter by computer name" }
|
|
os_type: { type: string, description: "Filter by OS type" }
|
|
scan_status: { type: string, description: "Filter by scan status" }
|
|
siteIds: { type: string, description: "Comma-separated site IDs" }
|
|
groupIds: { type: string, description: "Comma-separated group IDs" }
|
|
accountIds: { type: string, description: "Comma-separated account IDs, to scope the count to one or more accounts" }
|
|
agentVersion__gt: { type: string, description: "Only agents on a version strictly greater than this one, e.g. 23.4.2.6" }
|
|
networkStatuses: { type: string, description: "Comma-separated network statuses: connected | connecting | disconnected | disconnecting" }
|
|
operationalStatesNin: { type: string, description: "Comma-separated operational states to exclude, e.g. na" }
|
|
machineTypes: { type: string, description: "Comma-separated machine types: desktop | laptop | server | kubernetes node | storage | unknown" }
|
|
isActive: { type: string, description: "true to count only active agents, false for only the inactive ones; leave empty to count both" }
|
|
required: []
|
|
outputs_schema: { properties: {} }
|
|
- id: get_agent_mac
|
|
name: sentinelone-get-agent-mac
|
|
description: "Retrieve network interfaces (IP and MAC) for a single agent."
|
|
inputs_schema:
|
|
properties:
|
|
agent_id: { type: string, description: "Agent ID" }
|
|
required: [agent_id]
|
|
outputs_schema: { properties: {} }
|
|
- id: get_installed_applications
|
|
name: sentinelone-get-installed-applications
|
|
description: "Retrieve the applications installed on the given agents."
|
|
inputs_schema:
|
|
properties:
|
|
agent_ids: { type: string, description: "Comma-separated agent IDs" }
|
|
required: [agent_ids]
|
|
outputs_schema: { properties: {} }
|
|
- id: manage_tags
|
|
name: sentinelone-manage-tags
|
|
description: "Add, override or remove a tag on the given agents."
|
|
inputs_schema:
|
|
properties:
|
|
tagId: { type: string, description: "Tag ID to apply" }
|
|
agent_ids: { type: string, description: "Comma-separated agent IDs" }
|
|
operation: { type: string, description: "Tag operation: add, override or remove" }
|
|
required: [tagId, agent_ids, operation]
|
|
outputs_schema: { properties: {} }
|
|
|
|
# ── Threats & Alerts ──────────────────────────────────────────────────────
|
|
- id: resolve_threat
|
|
name: sentinelone-resolve-threat
|
|
description: "Mark one or more threats as resolved."
|
|
inputs_schema:
|
|
properties:
|
|
threat_ids: { type: string, description: "Comma-separated threat IDs to resolve." }
|
|
required: [threat_ids]
|
|
outputs_schema: { properties: {} }
|
|
- id: mark_as_threat
|
|
name: sentinelone-mark-as-threat
|
|
description: "Mark detections as a true threat, scoped to a site or the whole tenant."
|
|
inputs_schema:
|
|
properties:
|
|
threat_ids: { type: string, description: "Comma-separated threat IDs to mark." }
|
|
target_scope: { type: string, description: "Scope of the action: site or tenant." }
|
|
required: [threat_ids, target_scope]
|
|
outputs_schema: { properties: {} }
|
|
- id: update_threats_verdict
|
|
name: sentinelone-update-threats-verdict
|
|
description: "Set the analyst verdict on one or more threats."
|
|
inputs_schema:
|
|
properties:
|
|
verdict: { type: string, description: "undefined, true_positive, false_positive, or suspicious." }
|
|
threat_ids: { type: string, description: "Comma-separated threat IDs to update." }
|
|
required: [verdict, threat_ids]
|
|
outputs_schema: { properties: {} }
|
|
- id: update_threats_status
|
|
name: sentinelone-update-threats-status
|
|
description: "Set the incident status on one or more threats."
|
|
inputs_schema:
|
|
properties:
|
|
status: { type: string, description: "in_progress, resolved, or unresolved." }
|
|
threat_ids: { type: string, description: "Comma-separated threat IDs to update." }
|
|
required: [status, threat_ids]
|
|
outputs_schema: { properties: {} }
|
|
- id: get_threat_notes
|
|
name: sentinelone-get-threat-notes
|
|
description: "Retrieve the notes attached to a single threat."
|
|
inputs_schema:
|
|
properties:
|
|
threat_id: { type: string, description: "ID of the threat whose notes to retrieve." }
|
|
required: [threat_id]
|
|
outputs_schema: { properties: {} }
|
|
- id: get_threat_summary
|
|
name: sentinelone-get-threat-summary
|
|
description: "Retrieve a dashboard threat summary, optionally filtered by site and group."
|
|
inputs_schema:
|
|
properties:
|
|
site_ids: { type: string, description: "Comma-separated site IDs." }
|
|
group_ids: { type: string, description: "Comma-separated group IDs." }
|
|
required: []
|
|
outputs_schema: { properties: {} }
|
|
- id: fetch_threat_file
|
|
name: sentinelone-fetch-threat-file
|
|
description: "Request the threat file for download, protected by a ZIP password."
|
|
inputs_schema:
|
|
properties:
|
|
threat_id: { type: string, description: "ID of the threat whose file to fetch." }
|
|
password: { type: string, description: "Password used to encrypt the fetched file ZIP." }
|
|
required: [threat_id, password]
|
|
outputs_schema: { properties: {} }
|
|
- id: get_alerts
|
|
name: sentinelone-get-alerts
|
|
description: "Retrieve cloud-detection alerts filtered by creation window and optional criteria."
|
|
inputs_schema:
|
|
properties:
|
|
created_from: { type: string, description: "Return alerts created at or after this timestamp." }
|
|
created_until: { type: string, description: "Return alerts created at or before this timestamp." }
|
|
ruleName: { type: string, description: "Filter by rule name substring." }
|
|
incidentStatus: { type: string, description: "Filter by incident status." }
|
|
analystVerdict: { type: string, description: "Filter by analyst verdict." }
|
|
alert_ids: { type: string, description: "Comma-separated alert IDs." }
|
|
site_ids: { type: string, description: "Comma-separated site IDs." }
|
|
account_ids: { type: string, description: "Optional comma-separated account IDs to scope the search to." }
|
|
limit: { type: number, description: "Max results (default 100)." }
|
|
required: [created_from]
|
|
outputs_schema: { properties: {} }
|
|
ingest:
|
|
results_path: data
|
|
dedup_key: id
|
|
incremental_field: created_from
|
|
- id: update_alerts_verdict
|
|
name: sentinelone-update-alerts-verdict
|
|
description: "Set the analyst verdict on one or more cloud-detection alerts."
|
|
inputs_schema:
|
|
properties:
|
|
verdict: { type: string, description: "undefined, true_positive, false_positive, or suspicious." }
|
|
alert_ids: { type: string, description: "Comma-separated alert IDs to update." }
|
|
required: [verdict, alert_ids]
|
|
outputs_schema: { properties: {} }
|
|
- id: update_alerts_status
|
|
name: sentinelone-update-alerts-status
|
|
description: "Set the incident status on one or more cloud-detection alerts."
|
|
inputs_schema:
|
|
properties:
|
|
status: { type: string, description: "in_progress, resolved, or unresolved." }
|
|
alert_ids: { type: string, description: "Comma-separated alert IDs to update." }
|
|
required: [status, alert_ids]
|
|
outputs_schema: { properties: {} }
|
|
|
|
# ── Hash, blocklist, exclusions, IOCs ─────────────────────────────────────
|
|
- id: get_blocklist
|
|
name: sentinelone-get-blocklist
|
|
description: "Retrieve hash blocklist (restriction) entries, optionally filtered by hash, scope, and pagination."
|
|
inputs_schema:
|
|
properties:
|
|
global: { type: boolean, description: "Query the global (tenant) scope. Defaults to true." }
|
|
hash: { type: string, description: "Filter by hash value substring." }
|
|
offset: { type: number, description: "Records to skip for pagination." }
|
|
limit: { type: number, description: "Max records to return (default 100)." }
|
|
site_ids: { type: string, description: "Comma-separated site IDs." }
|
|
group_ids: { type: string, description: "Comma-separated group IDs." }
|
|
account_ids: { type: string, description: "Comma-separated account IDs." }
|
|
required: []
|
|
outputs_schema: { properties: {} }
|
|
- id: add_hash_to_blocklist
|
|
name: sentinelone-add-hash-to-blocklist
|
|
description: "Add a SHA1 or SHA256 hash to the blocklist for the given scope."
|
|
inputs_schema:
|
|
properties:
|
|
os_type: { type: string, description: "Target OS type: windows, linux, or macos." }
|
|
sha1: { type: string, description: "SHA1 hash (used if sha256 not provided)." }
|
|
sha256: { type: string, description: "SHA256 hash (takes precedence over sha1)." }
|
|
description: { type: string, description: "Optional description." }
|
|
source: { type: string, description: "Source label (defaults to Riposte)." }
|
|
account_ids: { type: string, description: "Comma-separated account IDs." }
|
|
site_ids: { type: string, description: "Comma-separated site IDs." }
|
|
group_ids: { type: string, description: "Comma-separated group IDs." }
|
|
required: [os_type]
|
|
outputs_schema: { properties: {} }
|
|
- id: remove_hash_from_blocklist
|
|
name: sentinelone-remove-hash-from-blocklist
|
|
description: "Find blocklist entries matching a SHA1 hash and delete them."
|
|
inputs_schema:
|
|
properties:
|
|
sha1: { type: string, description: "SHA1 hash to remove." }
|
|
os_type: { type: string, description: "Optional OS type filter." }
|
|
required: [sha1]
|
|
outputs_schema: { properties: {} }
|
|
- id: get_white_list
|
|
name: sentinelone-get-white-list
|
|
description: "Retrieve exclusion items, optionally filtered by IDs, type, OS, and scope."
|
|
inputs_schema:
|
|
properties:
|
|
item_ids: { type: string, description: "Comma-separated exclusion item IDs." }
|
|
os_types: { type: string, description: "Filter by OS types." }
|
|
exclusion_type: { type: string, description: "Filter by exclusion type." }
|
|
limit: { type: number, description: "Max records (default 10)." }
|
|
include_parent: { type: boolean, description: "Include parent-scope exclusions." }
|
|
include_children: { type: boolean, description: "Include child-scope exclusions." }
|
|
site_ids: { type: string, description: "Comma-separated site IDs." }
|
|
required: []
|
|
outputs_schema: { properties: {} }
|
|
- id: create_white_list_item
|
|
name: sentinelone-create-white-list-item
|
|
description: "Create an exclusion (whitelist) item of the given type and value."
|
|
inputs_schema:
|
|
properties:
|
|
exclusion_type: { type: string, description: "Exclusion type (path, white_hash, certificate, browser, file_type)." }
|
|
exclusion_value: { type: string, description: "The value to exclude." }
|
|
os_type: { type: string, description: "Target OS type." }
|
|
description: { type: string, description: "Optional description." }
|
|
exclusion_mode: { type: string, description: "Optional exclusion mode." }
|
|
path_exclusion_type: { type: string, description: "Optional path exclusion type." }
|
|
group_ids: { type: string, description: "Comma-separated group IDs." }
|
|
site_ids: { type: string, description: "Comma-separated site IDs." }
|
|
required: [exclusion_type, exclusion_value, os_type]
|
|
outputs_schema: { properties: {} }
|
|
- id: remove_item_from_whitelist
|
|
name: sentinelone-remove-item-from-whitelist
|
|
description: "Find exclusion items matching a value and delete them."
|
|
inputs_schema:
|
|
properties:
|
|
item: { type: string, description: "The exclusion value to find and remove." }
|
|
os_type: { type: string, description: "Optional OS type filter." }
|
|
exclusion_type: { type: string, description: "Optional exclusion type filter." }
|
|
required: [item]
|
|
outputs_schema: { properties: {} }
|
|
- id: delete_exclusion
|
|
name: sentinelone-delete-exclusion
|
|
description: "Delete exclusion items by their IDs and type."
|
|
inputs_schema:
|
|
properties:
|
|
ids: { type: string, description: "Comma-separated exclusion item IDs to delete." }
|
|
type: { type: string, description: "Exclusion type of the items being deleted." }
|
|
required: [ids, type]
|
|
outputs_schema: { properties: {} }
|
|
- id: create_ioc
|
|
name: sentinelone-create-ioc
|
|
description: "Create a threat-intelligence IOC for the given account scope."
|
|
inputs_schema:
|
|
properties:
|
|
name: { type: string, description: "Name of the IOC." }
|
|
source: { type: string, description: "Source of the IOC." }
|
|
type: { type: string, description: "IOC type: DNS, IPV4, IPV6, MD5, SHA1, SHA256, or URL." }
|
|
method: { type: string, description: "Comparison method (e.g. EQUALS)." }
|
|
validUntil: { type: string, description: "Expiration timestamp (ISO 8601)." }
|
|
value: { type: string, description: "The IOC value." }
|
|
account_ids: { type: string, description: "Comma-separated account IDs." }
|
|
externalId: { type: string, description: "Optional external identifier." }
|
|
description: { type: string, description: "Optional description." }
|
|
required: [name, source, type, method, validUntil, value, account_ids]
|
|
outputs_schema: { properties: {} }
|
|
- id: delete_ioc
|
|
name: sentinelone-delete-ioc
|
|
description: "Delete threat-intelligence IOCs by UUID within the given account scope."
|
|
inputs_schema:
|
|
properties:
|
|
account_ids: { type: string, description: "Comma-separated account IDs." }
|
|
uuids: { type: string, description: "Comma-separated IOC UUIDs to delete." }
|
|
required: [account_ids, uuids]
|
|
outputs_schema: { properties: {} }
|
|
- id: get_iocs
|
|
name: sentinelone-get-iocs
|
|
description: "Retrieve threat-intelligence IOCs, optionally filtered by type, value, source, and name."
|
|
inputs_schema:
|
|
properties:
|
|
account_ids: { type: string, description: "Comma-separated account IDs." }
|
|
limit: { type: number, description: "Max records (default 1000)." }
|
|
type: { type: string, description: "Filter by IOC type." }
|
|
value: { type: string, description: "Filter by IOC value." }
|
|
source: { type: string, description: "Filter by IOC source." }
|
|
name_contains: { type: string, description: "Filter by IOC name substring." }
|
|
required: [account_ids]
|
|
outputs_schema: { properties: {} }
|
|
|
|
# ── Sites, groups, accounts, users, Deep Visibility ───────────────────────
|
|
- id: get_activities
|
|
name: sentinelone-get-activities
|
|
description: "Retrieve activities, optionally filtered by date, agents, or threats."
|
|
inputs_schema:
|
|
properties:
|
|
created_after: { type: string, description: "Activities created after this timestamp." }
|
|
limit: { type: number, description: "Max results (default 50)." }
|
|
agent_ids: { type: string, description: "Comma-separated agent IDs." }
|
|
threats_ids: { type: string, description: "Comma-separated threat IDs." }
|
|
required: []
|
|
outputs_schema: { properties: {} }
|
|
- id: get_groups
|
|
name: sentinelone-get-groups
|
|
description: "List groups with optional filters."
|
|
inputs_schema:
|
|
properties:
|
|
group_type: { type: string, description: "Group type (static, dynamic)." }
|
|
group_ids: { type: string, description: "Comma-separated group IDs." }
|
|
is_default: { type: boolean, description: "Filter for default groups only." }
|
|
name: { type: string, description: "Exact group name." }
|
|
query: { type: string, description: "Free-text search." }
|
|
limit: { type: number, description: "Max results (default 50)." }
|
|
required: []
|
|
outputs_schema: { properties: {} }
|
|
- id: delete_group
|
|
name: sentinelone-delete-group
|
|
description: "Delete a group by its ID."
|
|
inputs_schema:
|
|
properties:
|
|
group_id: { type: string, description: "ID of the group to delete." }
|
|
required: [group_id]
|
|
outputs_schema: { properties: {} }
|
|
- id: get_sites
|
|
name: sentinelone-get-sites
|
|
description: "List sites with optional filters."
|
|
inputs_schema:
|
|
properties:
|
|
query: { type: string, description: "Free-text search." }
|
|
state: { type: string, description: "Site state (active, expired)." }
|
|
site_type: { type: string, description: "Site type." }
|
|
site_name: { type: string, description: "Exact site name." }
|
|
site_ids: { type: string, description: "Comma-separated site IDs." }
|
|
limit: { type: number, description: "Max results (default 50)." }
|
|
required: []
|
|
outputs_schema: { properties: {} }
|
|
- id: get_site
|
|
name: sentinelone-get-site
|
|
description: "Retrieve a single site by its ID."
|
|
inputs_schema:
|
|
properties:
|
|
site_id: { type: string, description: "ID of the site." }
|
|
required: [site_id]
|
|
outputs_schema: { properties: {} }
|
|
- id: reactivate_site
|
|
name: sentinelone-reactivate-site
|
|
description: "Reactivate an expired site."
|
|
inputs_schema:
|
|
properties:
|
|
site_id: { type: string, description: "ID of the site to reactivate." }
|
|
unlimited: { type: boolean, description: "Set the site to unlimited duration." }
|
|
expiration: { type: string, description: "New expiration date (ISO 8601)." }
|
|
required: [site_id]
|
|
outputs_schema: { properties: {} }
|
|
- id: expire_site
|
|
name: sentinelone-expire-site
|
|
description: "Expire a site immediately."
|
|
inputs_schema:
|
|
properties:
|
|
site_id: { type: string, description: "ID of the site to expire." }
|
|
required: [site_id]
|
|
outputs_schema: { properties: {} }
|
|
- id: get_accounts
|
|
name: sentinelone-get-accounts
|
|
description: "List all accounts, or retrieve a single account when an ID is provided."
|
|
inputs_schema:
|
|
properties:
|
|
account_id: { type: string, description: "Optional account ID." }
|
|
required: []
|
|
outputs_schema: { properties: {} }
|
|
- id: list_users
|
|
name: sentinelone-list-users
|
|
description: "List users, optionally filtered by account IDs."
|
|
inputs_schema:
|
|
properties:
|
|
account_ids: { type: string, description: "Comma-separated account IDs." }
|
|
limit: { type: number, description: "Max results (default 100)." }
|
|
required: []
|
|
outputs_schema: { properties: {} }
|
|
- id: delete_user
|
|
name: sentinelone-delete-user
|
|
description: "Delete a user by their ID."
|
|
inputs_schema:
|
|
properties:
|
|
user_id: { type: string, description: "ID of the user to delete." }
|
|
required: [user_id]
|
|
outputs_schema: { properties: {} }
|
|
- id: create_query
|
|
name: sentinelone-create-query
|
|
description: "Initialize a Deep Visibility query over a given time range."
|
|
inputs_schema:
|
|
properties:
|
|
query: { type: string, description: "Deep Visibility query string." }
|
|
from_date: { type: string, description: "Start of the time range (ISO 8601)." }
|
|
to_date: { type: string, description: "End of the time range (ISO 8601)." }
|
|
required: [query, from_date, to_date]
|
|
outputs_schema: { properties: {} }
|
|
- id: get_dv_query_status
|
|
name: sentinelone-get-dv-query-status
|
|
description: "Get the status of a Deep Visibility query by ID."
|
|
inputs_schema:
|
|
properties:
|
|
query_id: { type: string, description: "ID of the Deep Visibility query." }
|
|
required: [query_id]
|
|
outputs_schema: { properties: {} }
|
|
- id: get_events
|
|
name: sentinelone-get-events
|
|
description: "Retrieve events for a completed Deep Visibility query."
|
|
inputs_schema:
|
|
properties:
|
|
query_id: { type: string, description: "ID of the Deep Visibility query." }
|
|
limit: { type: number, description: "Max events (default 50)." }
|
|
cursor: { type: string, description: "Pagination cursor." }
|
|
required: [query_id]
|
|
outputs_schema: { properties: {} }
|
|
- id: get_processes
|
|
name: sentinelone-get-processes
|
|
description: "Retrieve process events for a completed Deep Visibility query."
|
|
inputs_schema:
|
|
properties:
|
|
query_id: { type: string, description: "ID of the Deep Visibility query." }
|
|
limit: { type: number, description: "Max process events (default 50)." }
|
|
required: [query_id]
|
|
outputs_schema: { properties: {} }
|
|
|
|
# ── STAR rules & advanced (remote scripts, tags, firewall, discovery) ──────
|
|
- id: create_star_rule
|
|
name: sentinelone-create-star-rule
|
|
description: "Create a STAR custom detection rule in Draft status."
|
|
inputs_schema:
|
|
properties:
|
|
name: { type: string, description: "Rule name." }
|
|
query: { type: string, description: "S1QL detection query." }
|
|
rule_severity: { type: string, description: "Low | Medium | High | Critical." }
|
|
expiration_mode: { type: string, description: "Permanent | Temporary." }
|
|
query_type: { type: string, description: "Query type (defaults to events)." }
|
|
network_quarantine: { type: boolean, description: "Network-quarantine matching endpoints." }
|
|
treatAsThreat: { type: string, description: "Malicious | Suspicious | UNDEFINED." }
|
|
description: { type: string, description: "Rule description." }
|
|
expiration_date: { type: string, description: "Expiration date (when Temporary)." }
|
|
site_ids: { type: string, description: "Comma-separated site IDs." }
|
|
group_ids: { type: string, description: "Comma-separated group IDs." }
|
|
account_ids: { type: string, description: "Comma-separated account IDs." }
|
|
required: [name, query, rule_severity, expiration_mode, network_quarantine, treatAsThreat]
|
|
outputs_schema: { properties: {} }
|
|
- id: get_star_rules
|
|
name: sentinelone-get-star-rules
|
|
description: "List STAR custom detection rules."
|
|
inputs_schema:
|
|
properties:
|
|
status: { type: string, description: "Filter by rule status." }
|
|
queryType: { type: string, description: "Filter by query type." }
|
|
name_contains: { type: string, description: "Filter by name substring." }
|
|
ruleIds: { type: string, description: "Comma-separated rule IDs." }
|
|
accountIds: { type: string, description: "Comma-separated account IDs." }
|
|
siteIds: { type: string, description: "Comma-separated site IDs." }
|
|
limit: { type: number, description: "Max results (default 1000)." }
|
|
required: []
|
|
outputs_schema: { properties: {} }
|
|
- id: update_star_rule
|
|
name: sentinelone-update-star-rule
|
|
description: "Update an existing STAR custom detection rule by ID."
|
|
inputs_schema:
|
|
properties:
|
|
rule_id: { type: string, description: "ID of the rule to update." }
|
|
name: { type: string, description: "Rule name." }
|
|
query: { type: string, description: "S1QL detection query." }
|
|
rule_severity: { type: string, description: "Low | Medium | High | Critical." }
|
|
expiration_mode: { type: string, description: "Permanent | Temporary." }
|
|
query_type: { type: string, description: "Query type (defaults to events)." }
|
|
network_quarantine: { type: boolean, description: "Network-quarantine matching endpoints." }
|
|
treatAsThreat: { type: string, description: "Malicious | Suspicious | UNDEFINED." }
|
|
description: { type: string, description: "Rule description." }
|
|
expiration_date: { type: string, description: "Expiration date (when Temporary)." }
|
|
query_lang: { type: string, description: "Query language version." }
|
|
site_ids: { type: string, description: "Comma-separated site IDs." }
|
|
group_ids: { type: string, description: "Comma-separated group IDs." }
|
|
account_ids: { type: string, description: "Comma-separated account IDs." }
|
|
required: [rule_id, name, query, rule_severity, expiration_mode, network_quarantine, treatAsThreat]
|
|
outputs_schema: { properties: {} }
|
|
- id: enable_star_rules
|
|
name: sentinelone-enable-star-rules
|
|
description: "Enable one or more STAR custom detection rules by ID."
|
|
inputs_schema:
|
|
properties:
|
|
rule_ids: { type: string, description: "Comma-separated rule IDs to enable." }
|
|
required: [rule_ids]
|
|
outputs_schema: { properties: {} }
|
|
- id: disable_star_rules
|
|
name: sentinelone-disable-star-rules
|
|
description: "Disable one or more STAR custom detection rules by ID."
|
|
inputs_schema:
|
|
properties:
|
|
rule_ids: { type: string, description: "Comma-separated rule IDs to disable." }
|
|
required: [rule_ids]
|
|
outputs_schema: { properties: {} }
|
|
- id: delete_star_rule
|
|
name: sentinelone-delete-star-rule
|
|
description: "Delete one or more STAR custom detection rules by ID."
|
|
inputs_schema:
|
|
properties:
|
|
rule_ids: { type: string, description: "Comma-separated rule IDs to delete." }
|
|
required: [rule_ids]
|
|
outputs_schema: { properties: {} }
|
|
- id: run_remote_script
|
|
name: sentinelone-run-remote-script
|
|
description: "Execute a remote script (RSO) on the targeted agents."
|
|
inputs_schema:
|
|
properties:
|
|
account_ids: { type: string, description: "Comma-separated account IDs." }
|
|
script_id: { type: string, description: "ID of the remote script to run." }
|
|
output_destination: { type: string, description: "Where script output is sent." }
|
|
task_description: { type: string, description: "Description of the task." }
|
|
agent_ids: { type: string, description: "Comma-separated agent IDs to target." }
|
|
site_ids: { type: string, description: "Comma-separated site IDs." }
|
|
input_params: { type: string, description: "Input parameters passed to the script." }
|
|
password: { type: string, description: "Password for protected scripts." }
|
|
requires_approval: { type: boolean, description: "Whether execution requires approval." }
|
|
required: [account_ids, script_id, output_destination, task_description]
|
|
outputs_schema: { properties: {} }
|
|
- id: create_endpoint_tag
|
|
name: sentinelone-create-endpoint-tag
|
|
description: "Create an endpoint tag in the tag manager."
|
|
inputs_schema:
|
|
properties:
|
|
type: { type: string, description: "Tag type." }
|
|
key: { type: string, description: "Tag key." }
|
|
value: { type: string, description: "Tag value." }
|
|
description: { type: string, description: "Tag description." }
|
|
groupIds: { type: string, description: "Comma-separated group IDs." }
|
|
siteIds: { type: string, description: "Comma-separated site IDs." }
|
|
accountIds: { type: string, description: "Comma-separated account IDs." }
|
|
tenant: { type: boolean, description: "Apply at tenant scope." }
|
|
required: [type, key]
|
|
outputs_schema: { properties: {} }
|
|
- id: delete_endpoint_tag
|
|
name: sentinelone-delete-endpoint-tag
|
|
description: "Delete endpoint tags matching the given scope filter."
|
|
inputs_schema:
|
|
properties:
|
|
siteIds: { type: string, description: "Comma-separated site IDs." }
|
|
groupIds: { type: string, description: "Comma-separated group IDs." }
|
|
accountIds: { type: string, description: "Comma-separated account IDs." }
|
|
query: { type: string, description: "Free-text query filter." }
|
|
required: []
|
|
outputs_schema: { properties: {} }
|
|
- id: get_endpoint_tags
|
|
name: sentinelone-get-endpoint-tags
|
|
description: "List endpoint tags, optionally filtered by key or value substring."
|
|
inputs_schema:
|
|
properties:
|
|
key__contains: { type: string, description: "Filter by key substring." }
|
|
value__contains: { type: string, description: "Filter by value substring." }
|
|
required: []
|
|
outputs_schema: { properties: {} }
|
|
- id: create_firewall_rule
|
|
name: sentinelone-create-firewall-rule
|
|
description: "Create a firewall control rule scoped to an account or site."
|
|
inputs_schema:
|
|
properties:
|
|
action: { type: string, description: "Allow | Block." }
|
|
name: { type: string, description: "Rule name." }
|
|
status: { type: string, description: "Enabled | Disabled." }
|
|
description: { type: string, description: "Rule description." }
|
|
direction: { type: string, description: "incoming | outgoing | any." }
|
|
filter_type: { type: string, description: "Scope filter type: accountIds | siteIds." }
|
|
filter_id: { type: string, description: "ID for the chosen scope filter type." }
|
|
remote_host: { type: string, description: "Comma-separated remote host addresses." }
|
|
required: [action, name, status, description, direction, filter_type, filter_id]
|
|
outputs_schema: { properties: {} }
|
|
- id: get_network_discovery_table
|
|
name: sentinelone-get-network-discovery-table
|
|
description: "Retrieve the Ranger network discovery table view."
|
|
inputs_schema:
|
|
properties:
|
|
hostnames__contains: { type: string, description: "Filter by hostname substring." }
|
|
externalIp: { type: string, description: "Filter by exact external IP." }
|
|
externalIp__contains: { type: string, description: "Filter by external IP substring." }
|
|
required: []
|
|
outputs_schema: { properties: {} }
|
|
- id: get_network_discovery_assets
|
|
name: sentinelone-get-network-discovery-assets
|
|
description: "Retrieve XDR network discovery surface assets."
|
|
inputs_schema:
|
|
properties:
|
|
limit: { type: number, description: "Max results (default 50)." }
|
|
account_id: { type: string, description: "Account ID filter." }
|
|
site_id: { type: string, description: "Site ID filter." }
|
|
hostname: { type: string, description: "Filter by name substring." }
|
|
epp_status: { type: string, description: "Filter by EPP unsupported/unknown status." }
|
|
required: []
|
|
outputs_schema: { properties: {} }
|
|
- id: get_shadow_assets
|
|
name: sentinelone-get-shadow-assets
|
|
description: "Retrieve XDR shadow assets with optional coverage filters."
|
|
inputs_schema:
|
|
properties:
|
|
limit: { type: number, description: "Max results (default 50)." }
|
|
account_id: { type: string, description: "Account ID filter." }
|
|
site_id: { type: string, description: "Site ID filter." }
|
|
name: { type: string, description: "Filter by name substring." }
|
|
active_coverage: { type: string, description: "Filter by active coverage." }
|
|
missing_coverage: { type: string, description: "Filter by missing coverage." }
|
|
required: []
|
|
outputs_schema: { properties: {} }
|
|
- id: get_gateways
|
|
name: sentinelone-get-gateways
|
|
description: "List Ranger gateways."
|
|
inputs_schema:
|
|
properties: {}
|
|
required: []
|
|
outputs_schema: { properties: {} }
|
|
- id: purge_crash_dumps
|
|
name: sentinelone-purge-crash-dumps
|
|
description: "Purge agent crash dumps for the specified agents."
|
|
inputs_schema:
|
|
properties:
|
|
agent_ids: { type: string, description: "Comma-separated agent IDs." }
|
|
required: [agent_ids]
|
|
outputs_schema: { properties: {} }
|
|
- id: list_endpoints_with_application
|
|
name: sentinelone-list-endpoints-with-application
|
|
description: "List the application inventory across endpoints."
|
|
inputs_schema:
|
|
properties:
|
|
groupIds: { type: string, description: "Comma-separated group IDs." }
|
|
name__contains: { type: string, description: "Filter by application name substring." }
|
|
osTypes: { type: string, description: "Filter by OS types." }
|
|
vendor__contains: { type: string, description: "Filter by vendor substring." }
|
|
siteIds: { type: string, description: "Comma-separated site IDs." }
|
|
limit: { type: number, description: "Max results (default 10)." }
|
|
required: []
|
|
outputs_schema: { properties: {} }
|
|
- id: get_app_inventory_endpoints
|
|
name: sentinelone-get-app-inventory-endpoints
|
|
description: "List endpoints that have a given application installed."
|
|
inputs_schema:
|
|
properties:
|
|
applicationName: { type: string, description: "Application name filter." }
|
|
applicationVendor: { type: string, description: "Application vendor filter." }
|
|
siteIds: { type: string, description: "Comma-separated site IDs." }
|
|
groupIds: { type: string, description: "Comma-separated group IDs." }
|
|
accountIds: { type: string, description: "Comma-separated account IDs." }
|
|
cursor: { type: string, description: "Pagination cursor." }
|
|
limit: { type: number, description: "Max results (default 50)." }
|
|
required: []
|
|
outputs_schema: { properties: {} }
|
|
|
|
# ── Threat analysis / sample ──────────────────────────────────────────────
|
|
- id: threat_analysis
|
|
name: sentinelone-threat-analysis
|
|
description: "Return the detailed analysis for a threat (agent, detection and threat info)."
|
|
inputs_schema:
|
|
properties:
|
|
threat_id: { type: string, description: "Threat ID." }
|
|
required: [threat_id]
|
|
outputs_schema: { properties: {} }
|
|
|
|
- id: threat_download_from_cloud
|
|
name: sentinelone-threat-download-from-cloud
|
|
description: "Get a download URL for a threat's sample from the cloud (BinaryVault)."
|
|
inputs_schema:
|
|
properties:
|
|
threat_id: { type: string, description: "Threat ID." }
|
|
required: [threat_id]
|
|
outputs_schema: { properties: {} }
|
|
|
|
# ── Endpoint actions ──────────────────────────────────────────────────────
|
|
- id: abort_endpoint_scan
|
|
name: sentinelone-abort-endpoint-scan
|
|
description: "Abort the disk scan on the given agents."
|
|
inputs_schema:
|
|
properties:
|
|
agent_ids: { type: string, description: "Comma-separated agent IDs." }
|
|
required: [agent_ids]
|
|
outputs_schema: { properties: {} }
|
|
|
|
- id: endpoint_fetch_logs
|
|
name: sentinelone-endpoint-fetch-logs
|
|
description: "Fetch agent/endpoint logs from the given agents."
|
|
inputs_schema:
|
|
properties:
|
|
agent_ids: { type: string, description: "Comma-separated agent IDs." }
|
|
agents_logs: { type: boolean, description: "Fetch agent logs (default true)." }
|
|
customer_facing_logs: { type: boolean, description: "Fetch customer-facing logs (default false)." }
|
|
platform_logs: { type: boolean, description: "Fetch platform logs (default false)." }
|
|
required: [agent_ids]
|
|
outputs_schema: { properties: {} }
|
|
|
|
- id: fetch_file
|
|
name: sentinelone-fetch-file
|
|
description: "Request a file fetch from an agent endpoint (collected as a password-protected zip)."
|
|
inputs_schema:
|
|
properties:
|
|
agent_id: { type: string, description: "Agent ID." }
|
|
file_path: { type: string, description: "Absolute file path on the endpoint." }
|
|
password: { type: string, description: "Password to protect the resulting zip." }
|
|
required: [agent_id, file_path, password]
|
|
outputs_schema: { properties: {} }
|
|
|
|
# ── Remote scripts (status / results) ─────────────────────────────────────
|
|
- id: get_remote_script_task_status
|
|
name: sentinelone-get-remote-script-task-status
|
|
description: "Get the status of remote-script tasks for a parent task."
|
|
inputs_schema:
|
|
properties:
|
|
parent_task_id: { type: string, description: "Parent task ID." }
|
|
ids: { type: string, description: "Comma-separated task IDs." }
|
|
status: { type: string, description: "Filter by status (e.g. created, completed)." }
|
|
computer_name_contains: { type: string, description: "Filter by computer name substring." }
|
|
site_ids: { type: string, description: "Comma-separated site IDs." }
|
|
account_ids: { type: string, description: "Comma-separated account IDs." }
|
|
limit: { type: number, description: "Max results (default 50)." }
|
|
required: [parent_task_id]
|
|
outputs_schema: { properties: {} }
|
|
|
|
- id: get_remote_script_task_results
|
|
name: sentinelone-get-remote-script-task-results
|
|
description: "Get download links for the results of remote-script tasks."
|
|
inputs_schema:
|
|
properties:
|
|
task_ids: { type: string, description: "Comma-separated task IDs." }
|
|
computer_names: { type: string, description: "Comma-separated computer names." }
|
|
required: [task_ids]
|
|
outputs_schema: { properties: {} }
|
|
|
|
# ── Users / marketplace apps ──────────────────────────────────────────────
|
|
- id: get_service_users
|
|
name: sentinelone-get-service-users
|
|
description: "List service users (API token accounts)."
|
|
inputs_schema:
|
|
properties:
|
|
account_ids: { type: string, description: "Comma-separated account IDs." }
|
|
role_ids: { type: string, description: "Comma-separated RBAC role IDs." }
|
|
ids: { type: string, description: "Comma-separated service-user IDs." }
|
|
site_ids: { type: string, description: "Comma-separated site IDs." }
|
|
limit: { type: number, description: "Max results (default 100)." }
|
|
required: []
|
|
outputs_schema: { properties: {} }
|
|
|
|
- id: list_installed_singularity_marketplace_applications
|
|
name: sentinelone-list-installed-singularity-marketplace-applications
|
|
description: "List installed Singularity Marketplace applications."
|
|
inputs_schema:
|
|
properties:
|
|
account_ids: { type: string, description: "Comma-separated account IDs." }
|
|
application_catalog_id: { type: string, description: "Filter by application catalog ID." }
|
|
creator_contains: { type: string, description: "Filter by creator substring." }
|
|
ids: { type: string, description: "Comma-separated application IDs." }
|
|
name_contains: { type: string, description: "Filter by application name substring." }
|
|
site_ids: { type: string, description: "Comma-separated site IDs." }
|
|
limit: { type: number, description: "Max results (default 100)." }
|
|
required: []
|
|
outputs_schema: { properties: {} }
|
|
|
|
# ── Unified (UAM) alerts ──────────────────────────────────────────────────
|
|
- id: update_uam_alert_status
|
|
name: sentinelone-update-uam-alert-status
|
|
description: "Update the status of a unified (UAM) alert."
|
|
inputs_schema:
|
|
properties:
|
|
alert_id: { type: string, description: "UAM alert ID (UUID)." }
|
|
status: { type: string, description: "NEW | IN_PROGRESS | RESOLVED" }
|
|
required: [alert_id, status]
|
|
outputs_schema: { properties: {} }
|
|
|
|
- id: update_uam_alert_verdict
|
|
name: sentinelone-update-uam-alert-verdict
|
|
description: "Update the analyst verdict of a unified (UAM) alert."
|
|
inputs_schema:
|
|
properties:
|
|
alert_id: { type: string, description: "UAM alert ID (UUID)." }
|
|
analyst_verdict: { type: string, description: "Verdict enum, e.g. TRUE_POSITIVE_MALWARE, FALSE_POSITIVE_BENIGN, UNDEFINED." }
|
|
required: [alert_id, analyst_verdict]
|
|
outputs_schema: { properties: {} }
|
|
|
|
# ── PowerQuery (Singularity Data Lake) ────────────────────────────────────
|
|
- id: run_powerquery
|
|
name: sentinelone-run-powerquery
|
|
description: "Run a PowerQuery against the Singularity Data Lake (separate XDR URL + Log Read API key)."
|
|
inputs_schema:
|
|
properties:
|
|
singularity_xdr_url: { type: string, description: "Singularity Data Lake XDR URL (https://...)." }
|
|
singularity_xdr_api_key: { type: string, description: "Log Read Access API key." }
|
|
query: { type: string, description: "PowerQuery syntax query." }
|
|
start_time: { type: string, description: "Query start time." }
|
|
end_time: { type: string, description: "Query end time." }
|
|
priority: { type: string, description: "Execution priority (default low)." }
|
|
recurring: { type: boolean, description: "Create a materialized view (default false)." }
|
|
team_emails: { type: string, description: "Comma-separated account emails for cross-team search." }
|
|
required: [singularity_xdr_url, singularity_xdr_api_key, query]
|
|
outputs_schema: { properties: {} }
|
|
|
|
# ── Dynamic asset tag rule (XDR) ──────────────────────────────────────────
|
|
- id: create_tag_rule
|
|
name: sentinelone-create-tag-rule
|
|
description: "Create a dynamic asset tag rule (XDR) that tags assets matching a property filter."
|
|
inputs_schema:
|
|
properties:
|
|
name: { type: string, description: "Rule name." }
|
|
account_id: { type: string, description: "Account ID the rule belongs to." }
|
|
tag_id: { type: string, description: "Existing tag ID to apply." }
|
|
filter_values: { type: string, description: "Comma-separated values (e.g. SRV-,WEB-)." }
|
|
filter_name: { type: string, description: "Asset property to filter on (default assetName)." }
|
|
filter_operand: { type: string, description: "startsWith | contains | equals | endsWith (default startsWith)." }
|
|
conditions_operand: { type: string, description: "and | or (default or)." }
|
|
scope_type: { type: string, description: "account | site | global (default account)." }
|
|
site_ids: { type: string, description: "Site ID(s); first is used when scope_type=site." }
|
|
status: { type: string, description: "enabled | disabled (default enabled)." }
|
|
description: { type: string, description: "Rule description." }
|
|
required: [name, account_id, tag_id, filter_values]
|
|
outputs_schema: { properties: {} }
|
|
|
|
# ── Connectivity test ─────────────────────────────────────────────────────
|
|
- id: test_connection
|
|
name: sentinelone-test-connection
|
|
description: "Verify connectivity and credentials (used by the Test button)."
|
|
risk: read
|
|
inputs_schema:
|
|
properties: {}
|
|
required: []
|
|
outputs_schema: { properties: {} }
|
|
|
|
ingestion:
|
|
command: get_threats
|
|
mapper: get_threats
|
|
default_incident_type: "SentinelOne Threat"
|