Skip to main content

Connect SentinelOne

Use this guide to import SentinelOne endpoint alerts and host data into Cracken.

Prerequisites

  • Permission to create a SentinelOne service user
  • The management-console URL for your SentinelOne deployment
  • A Cracken realm where you can configure data integrations

Prepare the credential

Create a dedicated service user and assign:

  • Viewer role
  • Scope covering every account, site, and group that Cracken should read

Generate an API token for that service user and store it securely. SentinelOne service-user tokens expire according to your deployment's policy and must be replaced in Cracken when rotated.

Use the management-console URL, in the form https://<host>.sentinelone.net, as Base URL.

Connect SentinelOne

  1. Open Integration Center → Data Integrations.
  2. On the SentinelOne card, click Install.
  3. Enter the Base URL and API Token.
  4. Click Test Connection, then Save & Connect.

Cracken can list endpoint alerts and request an on-demand synchronization of the latest results within the service user's scope.

Sources

Next steps

  • Data Integrations — Review how connected security data flows into Cracken.
  • Cybergraph — See how Cracken uses imported endpoint data.