SentinelOne Singularity

SamurAI [Local] CollectorSamurAI [Cloud] Collector
Picture1.svg

This guide describes the steps required to configure and integrate SentinelOne Singularity with the SamurAI platform.

Prerequisites

The following are required to configure the SentinelOne Singularity integration:

  • An active SentinelOne Singularity tenant
  • Access to the SentinelOne Management Console
  • Permissions to create Service Users

Configuration Steps

Step 1 – Create a Service User

  1. Log in to the SentinelOne Management Console with administrator permissions

  2. Navigate to Settings - Users - Service Users

  3. Select Actions - Create New Service User

  4. The following parameters are required with suggestions:

    ParameterNote
    Namesamurai-mdr-service (example)
    Descriptionoptional
    Expiration Dateper your security policy
  5. Click Next

Step 2 – Assign Scope and Role

  1. Select the Scope of Access:
  • Account (recommended)
  1. In the Role type list assign the Viewer role

  2. Click Create User

Step 3 – Generate the Authentication Token (JWT)

When the service user is created:

  1. SentinelOne displays an API Token (JWT) once

  2. Copy and securely store the token (The token cannot be retrieved again)

Step 4 – Identify the SentinelOne Instance URL

Record the base URL of your SentinelOne Management Console.

Example:

https://<prefix>.sentinelone.net

Where ‘prefix’ is the value provided to you by SentinelOne

Complete the SentinelOne Singularity Integration

  1. Login to the SamurAI Portal

  2. Click Telemetry and select Integrations from the main menu

  3. Select Create

  4. Locate and click SentinelOne Singularity

  5. Click Next (we leverage a Samurai Cloud Collector)

  6. Enter a Name of Integration

  7. Enter a Description (Optional)

  8. Enter your SentinelOne Instance URL

  9. Enter your Authentication Token (JWT)

  10. Click Finish

Our Integration guide was accurate at the time of writing but vendors change things frequently! If you find errors or anything is outdated, let us know by raising a request in the SamurAI MDR Portal and we shall get it updated.