redcanaryco / surveyor

A cross-platform baselining, threat hunting, and attack surface analysis tool for security teams.
MIT License
166 stars 62 forks source link

[FR] Add SentinelOne XDR support #150

Open xC0uNt3r7hr34t opened 10 months ago

xC0uNt3r7hr34t commented 10 months ago

Which category is the feature part of?

Which product is the feature part of?

Use Cases

Proposal

Support to query SentinelOne's newest XDR platform is needed. This new platform uses a different URL and API tokens. It might make sense to integrate a new product for S1 XDR due to the major changes. However, much of the code and query language does overlap with the existing PQ code, but uses a completely different API. This new XDR platform supports both powerqueries and a similar XDR query language.

Additional Context

In depth documentation is available for anyone with access to a SentinelOne console or the SentinelOne support site.