Overview
SentinelOne is an endpoint detection and response (EDR) platform with autonomous threat response. The Pwnbook integration surfaces active threats, agent health, and STAR (SentinelOne Threat Intelligence Response) alerts so endpoint security data sits alongside the rest of your security context.Prerequisites
- A SentinelOne account
- A SentinelOne API token with read access to the relevant site(s)
- Admin or Owner access in Pwnbook
Setup
1
Generate a SentinelOne API token
- In the SentinelOne console, click your user avatar → My User.
- Under API Token, click Generate.
- Copy the token.
2
Configure in Pwnbook
- Go to Organization Settings → Marketplace → SentinelOne.
- Enter your API Token and Console URL (e.g.
https://usea1.sentinelone.net). - Select the sites to monitor.
- Click Save & Test.