Integrations/SentinelOne Singularity
SECURITY INTEGRATION

SentinelOne threats, triaged and closed.

Neo reads the threat behind a ticket, checks the endpoint it hit, and records the verdict in SentinelOne. You set per area what runs on its own and what waits for a technician.

01Capabilities

What Neo does with SentinelOne Singularity.

01
TRIAGE

Threats and alerts, read in full

Neo reads threats, STAR alerts and unified alerts with their detection details and timeline. It sets the verdict and incident status, and adds notes.

02
RESPOND

Mitigate and contain

Kill, quarantine, remediate or roll back a threat. Scan, isolate or reboot an endpoint. Each action names its exact targets.

03
INVESTIGATE

Deep Visibility searches

Neo searches endpoint events with Deep Visibility or PowerQuery, reads the console activity log and checks a hash's verdict. These areas are read only.

02Workflows

Concrete work Neo handles in SentinelOne Singularity.

THREAT TICKET

Detail gathered first

Neo reads the threat and its timeline, checks if the endpoint is online and if SentinelOne already mitigated the threat. The technician gets a summary.

CLOSE THE LOOP

Console and PSA agree

When the ticket is resolved, Neo sets the verdict and incident status and writes the ticket number on the threat. The next run finds it and opens no duplicate.

CONTAINMENT

Isolate an endpoint

Neo isolates the endpoint on its own or after a technician approves, as you set it. It reports the endpoint as isolated only after SentinelOne confirms it.

SCRIPTS

Library scripts on named endpoints

Neo runs a script from your SentinelOne library on the endpoints you name, then reads its results.

03Setup

Live in under an hour.

Connect, configure, go. No code, no long implementation.

01

Connect SentinelOne

Create a service user in SentinelOne, usually at Account scope. Save its token and your console URL in Neo. Neo checks that the token works and can list your sites.

02

Check the site mapping

Neo matches your SentinelOne sites to your PSA companies by name. Confirm AI suggestions or set a mapping by hand on the Organization Mapping tab.

03

Set access per agent

Pick Read Only, Helpdesk, IT Admin or Full Automation, or set each area yourself. Neo adds the SentinelOne tool to every agent you enable.

FAQ

Questions about the SentinelOne Singularity integration.

What can Neo change in SentinelOne?+

Threats and alerts, endpoints, exclusions and the blocklist, remote scripts, and sites and groups, as far as you allow per agent. Neo refuses policy changes, site deletion, user and token management and remote shell.

Does Neo need technician approval?+

You choose per area. Uninstalling, decommissioning or disabling the SentinelOne agent, and changes to unified alerts, always wait on a technician. You cannot turn this off.

What credentials does Neo need?+

A service-user API token and your console URL. Cloud consoles and US government consoles work. On-premises consoles are not supported. The token has an expiry date, and the service user's role limits what any agent can do.

How are SentinelOne sites mapped to PSA companies?+

By site name: an exact match first, then a match without a legal suffix such as Inc or LLC, then an AI match. An AI match waits on the Organization Mapping tab until someone confirms it.

Ready to wire up SentinelOne Singularity?

14-day free trial. No credit card. Live in under an hour, right inside your stack.