EDRSentinelOne Singularity

SentinelOne Singularity

Configure SentinelOne Singularity integration with RAD Security for AI-powered endpoint protection.

This guide walks you through integrating SentinelOne Singularity with RAD Security for AI-powered endpoint detection and response, enabling you to correlate endpoint security events with container and cloud runtime activity.

SentinelOne Singularity provides autonomous endpoint protection with behavioral AI analysis, automated threat remediation, and deep visibility across your endpoints.

Prerequisites

Before you begin, ensure you have:

  • Admin access to SentinelOne Management Console
  • SentinelOne Complete entitlement level or higher
  • Access to RAD Security workspace with integration permissions

Minimum Entitlement Required: This integration requires a minimum entitlement level of SentinelOne Complete. See SentinelOne platform packages for more information about entitlement levels.


Step 1: Access SentinelOne Management Console

Log in to Console

Log in to your SentinelOne Management Console with administrative privileges

Note Your Console URL

Take note of your Management Console URL as you'll need it for configuration

Example URLs:

  • https://usea1-partners.sentinelone.net/
  • https://euce1-partners.sentinelone.net/
  • https://apne1-partners.sentinelone.net/

This URL will be used as the URL parameter when configuring the integration in RAD Security.


Step 2: Generate API Token

Access User Settings

  1. Click your username (or "Admin") in the top right corner
  2. Select My User from the dropdown menu

Navigate to API Token Operations

  1. Click the Actions button
  2. Select API Token Operations

Generate New Token

  1. Click Regenerate API Token
  2. Immediately copy the API Token that appears

Save this token immediately! You may not be able to view it again. Store it securely for the integration configuration.


Step 3: Configure in RAD Security

Navigate to your RAD Security workspace and configure the SentinelOne Singularity integration with the following parameters:

Required Parameters

ParameterDescriptionExample
Base URLBase URL of your SentinelOne Management Console (include trailing slash)https://usea1-partners.sentinelone.net/
SecretThe API Token generated in Step 2your-api-token-here

The URL should be your SentinelOne Management Console URL, which typically follows the pattern https://<region>-partners.sentinelone.net/. Ensure you include the trailing slash.


Verify Integration

After completing the setup, verify your integration is working:

  1. Navigate to Data Sources > Integrations > EDR in RAD Security
  2. Locate your SentinelOne Singularity integration
  3. Check the connection status shows as Connected
  4. Verify endpoint data is being synced

Your SentinelOne Singularity integration is now configured! RAD Security can now correlate endpoint security data with container and cloud runtime events.

What Data is Synced

Once configured, RAD Security will sync the following data from SentinelOne:

Use Cases

AI-Powered Threat Detection Leverage SentinelOne's behavioral AI with RAD's runtime context for enhanced threat detection accuracy.

Automated Response Combine SentinelOne's autonomous response with RAD's container orchestration for coordinated remediation.

Container-to-Host Threats Detect when containerized threats attempt to escape or affect the underlying host system.

Unified Threat Visibility Gain comprehensive visibility across endpoints, containers, and cloud infrastructure from a single platform.

Troubleshooting

Security Best Practices

Use Dedicated Users Create a dedicated service account for the RAD Security integration rather than using a personal account.

Rotate Tokens Regularly Periodically regenerate API tokens as part of your security hygiene practices.

Least Privilege Access Only grant the minimum permissions required. Use Read-only keys for EDR Events access.

Secure Token Storage Store API tokens in a secure password manager or secrets vault. Never commit them to version control.

Monitor API Usage Regularly review API usage in SentinelOne to detect anomalous activity.

Track Token Changes Document when tokens are regenerated and update all dependent integrations immediately.

Regional Deployments

SentinelOne has different regional deployments. Ensure you're using the correct Management Console URL for your region:

Always use the URL shown in your browser's address bar when logged into the SentinelOne Management Console. Don't forget to include the trailing slash.

Next Steps