SentinelOne

Receive SentinelOne endpoint threat detection notifications via webhook.

InboundSecurity
Start Free Trial

Quick Setup

Copy Webhook URL

Go to your Alert24 dashboard and copy the webhook URL for SentinelOne.

Configure SentinelOne

Add the webhook URL in your SentinelOne settings.

Auto-Detected

Alert24 auto-detects SentinelOne payloads and maps them to incidents.

Step-by-Step Setup Instructions

SentinelOne Webhook Setup

1.In SentinelOne console, go to Settings → Integrations
2.Click Add Integration and select Webhook
3.Set the URL to the webhook URL shown above
4.Choose which notification types to forward (threats, policy updates, etc.)
5.Click Save and test the connection

Example Webhook Payload

This is a sample payload that SentinelOne sends to Alert24 when an alert fires.

{
  "threatInfo": {
    "threatStatus": "active",
    "threatName": "Trojan.GenericKD.46789",
    "classification": "Trojan",
    "confidenceLevel": "malicious",
    "threatId": "T-98765"
  },
  "agentRealtimeInfo": {
    "agentComputerName": "WORKSTATION-042",
    "agentOs": "Windows 10",
    "siteName": "Production"
  },
  "createdAt": "2024-01-15T10:30:00Z"
}

How Alert24 Maps SentinelOne Data

Status Field

threatInfo.threatStatus

Message Field

threatInfo.threatName

Auto-Create Incidents

Yes

Auto-Resolve Incidents

Yes

Status Mapping

Alert24 StatusSentinelOne Values
operational
resolvedmitigated
down
activesuspicious

Connect SentinelOne to Alert24 in minutes

Free plan includes 5 monitors, 1 status page, and incident management. No credit card required.

More Security Integrations