This article provides onboarding steps for SentinelOne. Connecting the Expel Workbench to SentinelOne installation requires a user account with the proper level of access, API access, and an API authentication token. The first step is to create a new user account in SentinelOne and configure the account with the proper roles. After that's complete, you can connect SentinelOne to Workbench and test the connection.
Step 1: Create new user account in SentinelOne
This step procedure creates a user account for Expel that keeps the Expel activity separate from other activity on the SentinelOne console.
- Log into SentinelOne, navigate to Settings > Users and click New User.
- For Full Name type Expel SOC.
- For Email Address type soc+<your_org_name>@expel.io.
- Create a Password and make note of it for later use.
- Set Role Settings to Viewer at a minimum. Note: Viewer is the least privileged role that gives Expel the necessary API permissions, as well as covering all permissions an analyst needs. For Expel to perform a higher level of investigative support, we request an additional permission for
Endpoints Remote Shell&
Fetch Threat File.
- Click Save.
Step 2: Enable API Access for Expel
- Navigate to Settings > User and click New User.
- For Full Name add Expel API.
- For Email Address type soc+<your_org_name>firstname.lastname@example.org.
- Type a Password.
- Role Settings: IR Team is the least privileged role that gives Expel the necessary API permissions for polling alerts and disconnecting/isolating hosts.
- Click Save.
This procedure creates an authentication token that allows the Expel Assembler to access the SentinelOne API
- Log out of the SentinelOne Console.
- Log back into the SentinelOne Console, this time as the newly-created Expel API User.
- In the upper right, Expel API > Select My User.
- From the Option list, select Generate API Token.
- Click Download. The generated token is used next in the registration steps for Workbench.
Step 3: Configure SentinelOne in Workbench
Now that we have the correct access configured and noted the credentials, we can integrate SentinelOne with Expel Workbench.
Register device in Expel Workbench
- In a new browser tab, login to https://workbench.expel.io.
- On the console page, navigate to Settings and click Security Devices.
At the top right of the page, click Add Security Device.
- Search for and select SentinelOne.
Complete all fields using the credentials and information you collected in Step 2.
- For Name type what to name the security device.
- For Location type cloud.
- Username and Password fields can be left blank.
- For API Key type the previously generated API key.
- For Server type the SentinelOne device hostname in the following format: https://<your address>.sentinelone.net
- Click Save.
After a few minutes, refresh the Security Devices page and you see your device status reporting as Healthy, or if there is an issue, you see details of what the issue may be.
To check if alerts are coming through, navigate to Alerts on the console page. Click the icon in the upper right to switch to grid view, then check the list for device alerts.