SentinelOne Singularity Endpoint integration
You can integrate SentinelOne Singularity Endpoint with Sophos Central so that it sends data to Sophos.
This page gives you an overview of the integration.
SentinelOne Singularity Endpoint product overview
SentinelOne Singularity is an AI-driven endpoint security solution designed to autonomously defend against a wide spectrum of attacks. By unifying endpoint protection, detection, response, and remediation, it offers a holistic view of the threat landscape and immediate action capabilities.
Sophos documents
Integrate SentinelOne Singularity Endpoint
What we ingest
Sample alerts seen by Sophos:
RansomwareMalwareTrojanminerExploitAdwareHacktoolRootkitVirusGeneric.HeuristicPhishingSpywareWormPacked
Filtering
We filter messages as follows:
- We ALLOW only messages in the correct format.
- We DENY messages that aren't in the correct format and don't DROP the data.
Sample threat mappings
Alert type is defined by the field threatInfo.classification.
Sample mappings:
{"Hacktool", "threatId": "TA0003", "threatName": "Persistence"}
{"Virus", "threatId": "TA0002", "threatName": "Execution"}
{"Spyware", "threatId": "T1033", "threatName": "System Owner/User Discovery"}