Skip to main content

Connecting Vanta & SentinelOne

S
Written by Shannon DeLange
Updated today

About this article

  • This integration automates the collection of evidence for vulnerability scan results and proof of subsequent vulnerability remediation within your committed SLAs

  • Vanta requires read-only to endpoints, applications, endpoint policies and console users

  • Estimated setup time: Less than 10 minutes

How it works

Vanta schedule periodically fetching to official the SentinelOne API

Use Cases

Connecting SentinelOne will allow Vanta to perform the following tests:

  • Ensure SentinelOne accounts are linked in Vanta

  • Ensure a continuous visibility into application and OS vulnerabilities across different OS

  • SentinelOne groups have a secure prevention policy

  • SentinelOne alerts are addressed

  • Critical vulnerabilities identified in packages are addressed

  • High vulnerabilities identified in packages are addressed

  • Low vulnerabilities identified in packages are addressed

  • Medium vulnerabilities identified in packages are addressed

Overview

Step-by-step summary of what the user will do in this article. This is only required if there are multiple steps / sections in the article. For instance, creating an API key, install the integration, and map user profiles

To complete this setup, you will:

  • Create an user and role for the integration

  • Install the integration following the step-by-step instructions

Requirements

Clear list of prerequisites:

  • Admin role in SentinelOne console

Connecting Vanta & SentinelOne

You can connect SentinelOne to Vanta to ensure user access to SentinelOne is managed following your company's policies and to ingest and display vulnerabilities on the vulnerabilities page.

If you have already integrated with SentinelOne and you need to update the permissions, you may skip many of the steps in the instructions below and edit the existing Vanta Client in SentinelOne.

  • Navigate to the Integrations Page in Vanta

  • Select the Available tab

  • Search for SentinelOne

  • Click on Connect

Screenshot 2024-07-26 at 1.27.38 PM.png
  • Select the Product you would like to integrate

Screenshot 2024-07-26 at 1.31.18 PM.png

Configure RBAC (role-based access control permissions)

  • Login to SentinelOne

    • Navigate to the Settings, Users, Roles page in the SentinelOne console

  • Either create a new role or modify an existing role to have the following permissions

    • Endpoints: View

    • Applications: View

    • Applications: View Risks

    • Console Users: View

  • For the Alerts Management product, you need the next additional permissions:

    • STAR Rule Alerts: View

    • Endpoint Policy: View

Create Service User

  • Navigate to the Service Users tab within the Settings, Users page

  • Click on Actions and then Create New Service User.

  • Provide a name, description, and expiration date.

  • Press next

  • Select the account scope.

  • Select all relevant accounts and ensure they are set to the role configured in the previous Configure RBAC Permissions step.

  • Click on Create User.

  • Please note that this is the only time you can see the generated API token. If you close the dialog, you will no longer be able to access the service account and must create another one.

  • Keep the dialog open, or copy it for the next step!

Save API Token Details

  • Copy the displayed API token and paste into the appropriate box

  • Enter the Service Account name and the Base URL

  • Select Done

Permissions

Vanta accesses the following data from your SentinelOne account:

Vanta will be able to view:

  • Data about your users

  • Data about your user details

  • Data about your user groups

  • SentinelOne Monitored Host

  • SentinelOne Prevention Policy

  • SentinelOne Vulnerability Management Vulnerability

Vanta will be able to do:

  • Nothing