SentinelOne threats, triaged and closed.
Neo reads the threat behind a ticket, checks the endpoint it hit, and records the verdict in SentinelOne. You set per area what runs on its own and what waits for a technician.
What Neo does with SentinelOne Singularity.
Threats and alerts, read in full
Neo reads threats, STAR alerts and unified alerts with their detection details and timeline. It sets the verdict and incident status, and adds notes.
Mitigate and contain
Kill, quarantine, remediate or roll back a threat. Scan, isolate or reboot an endpoint. Each action names its exact targets.
Deep Visibility searches
Neo searches endpoint events with Deep Visibility or PowerQuery, reads the console activity log and checks a hash's verdict. These areas are read only.
Concrete work Neo handles in SentinelOne Singularity.
Detail gathered first
Neo reads the threat and its timeline, checks if the endpoint is online and if SentinelOne already mitigated the threat. The technician gets a summary.
Console and PSA agree
When the ticket is resolved, Neo sets the verdict and incident status and writes the ticket number on the threat. The next run finds it and opens no duplicate.
Isolate an endpoint
Neo isolates the endpoint on its own or after a technician approves, as you set it. It reports the endpoint as isolated only after SentinelOne confirms it.
Library scripts on named endpoints
Neo runs a script from your SentinelOne library on the endpoints you name, then reads its results.
Live in under an hour.
Connect, configure, go. No code, no long implementation.
Connect SentinelOne
Create a service user in SentinelOne, usually at Account scope. Save its token and your console URL in Neo. Neo checks that the token works and can list your sites.
Check the site mapping
Neo matches your SentinelOne sites to your PSA companies by name. Confirm AI suggestions or set a mapping by hand on the Organization Mapping tab.
Set access per agent
Pick Read Only, Helpdesk, IT Admin or Full Automation, or set each area yourself. Neo adds the SentinelOne tool to every agent you enable.
Questions about the SentinelOne Singularity integration.
What can Neo change in SentinelOne?+
Threats and alerts, endpoints, exclusions and the blocklist, remote scripts, and sites and groups, as far as you allow per agent. Neo refuses policy changes, site deletion, user and token management and remote shell.
Does Neo need technician approval?+
You choose per area. Uninstalling, decommissioning or disabling the SentinelOne agent, and changes to unified alerts, always wait on a technician. You cannot turn this off.
What credentials does Neo need?+
A service-user API token and your console URL. Cloud consoles and US government consoles work. On-premises consoles are not supported. The token has an expiry date, and the service user's role limits what any agent can do.
How are SentinelOne sites mapped to PSA companies?+
By site name: an exact match first, then a match without a legal suffix such as Inc or LLC, then an AI match. An AI match waits on the Organization Mapping tab until someone confirms it.
Ready to wire up SentinelOne Singularity?
14-day free trial. No credit card. Live in under an hour, right inside your stack.