SentinelOne | Dropzone AI Documentation

The Dropzone AI Platform integrates with SentinelOne, an endpoint cybersecurity platform that protects against various types of threats. Integrating SentinelOne with Dropzone allows Dropzone to automatically investigate security incidents in your SentinelOne environment.

Create a Service User and API Key

SentinelOne requires an API key from a Service User with Viewer Access to enable.

To obtain an API Key, do the following:

Settings

Create New Service User

Enter information

Assign roles to the new Account

Copy API Token

Enable SentinelOne

To enable the Data Source integration, you'll need the following information:

To enable the Data Source integration, do the following:

Integrations Dropdown

Click Available

The SentinelOne Tile

Enabling the XDR API is optional, but provides crucial investigation data.

The SentinelOne Data Source Configuration

If you have any errors or questions, engage your Dropzone AI support representative.