← All integrations
Endpoint protection & containment Controls

SentinelOne

Disconnect an endpoint and reconnect it

This connector links containment actions to SentinelOne. isidaten looks the endpoint up by hostname, requires exactly one match and disconnects it from the network; reverting reconnects it. It addresses the tenant’s own console or the address of a self-hosted installation. The connector performs interventions and reads no detections.

Vendor: SentinelOne · www.sentinelone.com/platform/singularity-endpoint

What the connector performs
  • Disconnect an endpoint from the network
  • Reconnect the endpoint
  • Device lookup by hostname, aborting when ambiguous
  • Your own console address, including self-hosted installations
Your benefits

A service user instead of a personal token

The connector runs on a dedicated service user with the rights to view, disconnect and reconnect endpoints. A personal token expires with its account.

Two bolts, tracked separately

Isolating additionally via the isidaten agent yields two actions, each with its own approval and its own reversal. They do not cancel each other out.

Connect SentinelOne with isidaten

We show you the connector live in your own environment – non-binding and free of charge.