RtKelleher / Connect_SentinelOne

Connect plugin for ForeScout

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

Connect_SentinelOne

Connect plugin for ForeScout

Forescout connect plugin for SentinelOne using EyeConnect (OIM) module.

Requirements

Valid OIM subscription and SentinelOne subscription with API access

Configuration

SentinelOne Management URL: (e.g. https://usea1-012.sentinelone.net/login)

SentinelOne API:

Functions

Utilizes Forescout to compare online Forescout assets against SentinelOne. If the asset exists in SentinelOne the plugin then imports various agent information. The user can then add further automation in the form of responses such as auto disconnect via Forescout or alerting.

Example Output

Sample Ingest Data Image #1

Sample Ingest Data Image #2

About

Connect plugin for ForeScout

License:MIT License


Languages

Language:Python 100.0%