redcanaryco / surveyor

A cross-platform baselining, threat hunting, and attack surface analysis tool for security teams.
MIT License
170 stars 59 forks source link

New Product: Support for SentinelOne #52

Closed xC0uNt3r7hr34t closed 2 years ago

xC0uNt3r7hr34t commented 2 years ago

Which category is the feature part of?

Use Cases SentinelOne supports fetching telemetry data from "Deep Visibility" through their API. It would be great to be able to run similar hunts and baselining strategies against SentinelOne EDR data.

Proposal Evaluate the integration with SentinelOne and determine what capabilities exist similar to Carbon Black integration.

Additional context Add any other context or screenshots about the feature request here.