Connect SentinelOne Vulnerability Management
Use this guide to import SentinelOne vulnerability findings into Cracken.
Prerequisites
- SentinelOne Vulnerability Management enabled
- Permission to create a SentinelOne service user
- The management-console URL for your SentinelOne deployment
- A Cracken realm where you can configure data integrations
Prepare the credential
Create a dedicated service user and assign the Viewer role. Limit its account, site, and group scope if Cracken should read only part of the deployment. Generate an API token and store it securely; replace the credential in Cracken when the token is rotated.
Use the management-console URL, in the form https://<host>.sentinelone.net, as Base URL.
Connect SentinelOne Vulnerability Management
- Open Integration Center → Data Integrations.
- On the SentinelOne VM card, click Install.
- Enter the Base URL and API Token.
- Click Test Connection, then Save & Connect.
Cracken can list vulnerability findings and request an on-demand synchronization of the latest results within the service user's scope.
Sources
Next steps
- Data Integrations — Review how connected security data flows into Cracken.
- Cybergraph — See how Cracken uses imported vulnerability data.