Integrate Your AssetsExternal Security Data

Import Data from SentinelOne

Import SentinelOne vulnerability data into Mondoo alongside your own scan results.

Mondoo can import data from SentinelOne and combine it with your Mondoo findings. The unified view gives you Mondoo's security visualization, prioritization, and ticketing on top of SentinelOne vulnerability data.

Prerequisites

Create a SentinelOne service user

Mondoo authenticates with a SentinelOne service user (a non-human account with an API token).

  1. Log into the SentinelOne management console as an administrator.

    SentinelOne navigation

  2. In the side navigation, select Settings > USERS > Service Users.

    SentinelOne service users

  3. Select Actions > Create New Service User.

    New SentinelOne service user

  4. Give the user a name and description that identify it as Mondoo's, then select Next.

    New SentinelOne service user scopes

  5. Choose the account(s) (not sites) you want Mondoo to access. Leave Viewer selected as the role.

  6. Select Create User.

    New SentinelOne service user API token

    SentinelOne shows the API token. Copy it; you need it in the next section.

Add a SentinelOne integration

In the Mondoo App, navigate to the space where you want to add the integration. In the side navigation bar, select Integrations. In the top right, select INSTALL. On the Install Integration page, find the integration you want by browsing a category or searching by name:

  1. Under Third-Party Data, select SentinelOne Singularity.

    The SentinelOne integration setup form in the Mondoo Console

  2. In Choose an integration name, enter a name for the integration.

  3. In Enter the host URL, enter the base URL for your SentinelOne management console. For example, if you access the console at https://my-company.sentinelone.net/dashboard, enter https://my-company.sentinelone.net.

  4. In Provide the SentinelOne API token, paste the token you copied.

  5. Choose how Mondoo handles the imported data:

    • Create new assets for unique detections (on by default): add an asset for each device SentinelOne reports that doesn't match an existing asset in the space.
    • Enrich findings with Mondoo (on by default): run Mondoo's vulnerability database against the data SentinelOne reports so findings include remediation guidance.
    • Import asset criticality levels (off by default): bring the asset criticality you maintain in SentinelOne into Mondoo as a business priority, so findings on your most important assets score higher.
  6. Select CREATE INTEGRATION.

Manage this integration

To open an existing integration, navigate to the space, select Integrations in the side navigation, choose the integration type, then select the integration.

The integration detail page shows the integration's status, configuration, import details, and recent activity. From there, you can:

  • Trigger an immediate import. Select RUN.
  • Edit settings. Select the edit (pencil) icon.
  • Remove the integration. Select the trash can icon and confirm.

After you connect

Once the import is running, your SentinelOne findings appear in Mondoo alongside its own. Assess and improve your security to review and prioritize them.

On this page