SentinelOne Attribute Reference
Focus
Focus
Device Security

SentinelOne Attribute Reference

Table of Contents

SentinelOne Attribute Reference

This reference lists the attributes that Device Security collects from SentinelOne, their names as stored in Device Security, and the Device Security fields they map to.
When Device Security integrates with SentinelOne Singularity, it imports endpoint protection data to enrich the device inventory. The attributes in this reference cover device records, network interface data, and vulnerability findings from the SentinelOne Singularity platform.
The third-party attribute name in Device Security refers to the attribute name as it appears in the Assets Inventory table and in Query Engine. This follows the format of third-party-name.attribute-name. When viewing the attribute name in the Assets Inventory table column selector or on a Device Details page, where the third-party name can be found as a header for the attributes section, then the third-party name is removed from the attribute name.
For example, micrsoft_defender_xdr.macAddress would appear in the Query Builder and in the Assets Inventory table, but under Device DetailsAttributesIntegration Specific AttributesMicrosoft Defender, the attribute would appear as macAddress.

Device Attributes

Device Security collects device attributes from SentinelOne. The following table lists each SentinelOne attribute, its name as stored in Device Security, and the Device Security field it maps to (if applicable).
SentinelOne Attribute
Device Security Attribute Name
Device Security Common Attribute*
Description
computerName
sentinelone.computerName
hostname
Computer name
networkInterfaces.inet
—
IP Address
Inet
locations.name
sentinelone.locations.name
Location
Name of the device
networkInterfaces.physical
—
MAC Address; id
Physical
modelName
sentinelone.modelName
Model
Model name
networkStatus
sentinelone.networkStatus
operational_status
Network status
osRevision
sentinelone.osRevision
OS Build Number
OS revision
osType
sentinelone.osType
os_type
OS type
externalIp
sentinelone.externalIp
public_ip_address
External IP
osName
sentinelone.osName
raw_os
Os name
serialNumber
—
Serial Number
Serial number
siteName
sentinelone.siteName
Site
Site name
installed_applications
—
third_party_learned_installed_software
Installed applications
accountId
sentinelone.accountId
—
Account ID
accountName
sentinelone.accountName
—
Account name
activeDirectory.computerDistinguishedName
sentinelone.activeDirectory.computerDistinguishedName
—
Computer distinguished name
activeDirectory.computerMemberOf
sentinelone.activeDirectory.computerMemberOf
—
Computer member of
activeDirectory.lastUserDistinguishedName
sentinelone.activeDirectory.lastUserDistinguishedName
—
Last user distinguished name
activeDirectory.lastUserMemberOf
sentinelone.activeDirectory.lastUserMemberOf
—
Last user member of
activeDirectory.userPrincipalName
sentinelone.activeDirectory.userPrincipalName
—
User principal name
activeProtection
sentinelone.activeProtection
—
Active protection
activeThreats
sentinelone.activeThreats
—
Active threats
agentVersion
sentinelone.agentVersion
—
Agent version
allowRemoteShell
sentinelone.allowRemoteShell
—
Allow remote shell
appsVulnerabilityStatus
sentinelone.appsVulnerabilityStatus
—
Apps vulnerability status
cloudProviders
sentinelone.cloudProviders
—
Cloud providers
consoleMigrationStatus
sentinelone.consoleMigrationStatus
—
Console migration status
containerizedWorkloadCounts
sentinelone.containerizedWorkloadCounts
—
Containerized workload counts
coreCount
sentinelone.coreCount
—
Number of cores
cpuCount
sentinelone.cpuCount
—
Number of CPUs
cpuId
sentinelone.cpuId
—
Cpu ID
createdAt
sentinelone.createdAt
—
Created at
detectionState
sentinelone.detectionState
—
Detection state
domain
sentinelone.domain
—
Domain
encryptedApplications
sentinelone.encryptedApplications
—
Encrypted applications
externalId
sentinelone.externalId
—
External ID
firewallEnabled
sentinelone.firewallEnabled
—
Firewall enabled
firstFullModeTime
sentinelone.firstFullModeTime
—
First full mode time
fullDiskScanLastUpdatedAt
sentinelone.fullDiskScanLastUpdatedAt
—
Full disk scan last updated at
groupId
sentinelone.groupId
—
Group ID
groupIp
sentinelone.groupIp
—
Group IP
groupName
sentinelone.groupName
—
Group name
hasContainerizedWorkload
sentinelone.hasContainerizedWorkload
—
Has containerized workload
id
sentinelone.id
—
Unique identifier
infected
sentinelone.infected
—
Infected
inRemoteShellSession
sentinelone.inRemoteShellSession
—
In remote shell session
installerType
sentinelone.installerType
—
Installer type
isActive
sentinelone.isActive
—
Is active
isAdConnector
sentinelone.isAdConnector
—
Is ad connector
isDecommissioned
sentinelone.isDecommissioned
—
Is decommissioned
isHyperAutomate
sentinelone.isHyperAutomate
—
Is hyper automate
isPendingUninstall
sentinelone.isPendingUninstall
—
Is pending uninstall
isUninstalled
sentinelone.isUninstalled
—
Is uninstalled
isUpToDate
sentinelone.isUpToDate
—
Is up to date
lastActiveDate
sentinelone.lastActiveDate
—
Last active date
lastIpToMgmt
sentinelone.lastIpToMgmt
—
Last IP to mgmt
lastLoggedInUserName
sentinelone.lastLoggedInUserName
—
Last logged in user name
lastSuccessfulScanDate
sentinelone.lastSuccessfulScanDate
—
Last successful scan date
licenseKey
sentinelone.licenseKey
—
License key
locationEnabled
sentinelone.locationEnabled
—
Location enabled
locations.id
sentinelone.locations.id
—
Unique identifier
locations.scope
sentinelone.locations.scope
—
Scope
locationType
sentinelone.locationType
—
Location type
machineSid
sentinelone.machineSid
—
Machine sid
machineType
sentinelone.machineType
—
Machine type
missingPermissions
sentinelone.missingPermissions
—
Missing permissions
mitigationMode
sentinelone.mitigationMode
—
Mitigation mode
mitigationModeSuspicious
sentinelone.mitigationModeSuspicious
—
Mitigation mode suspicious
networkQuarantineEnabled
sentinelone.networkQuarantineEnabled
—
Network quarantine enabled
operationalState
sentinelone.operationalState
—
Operational state
operationalStateExpiration
sentinelone.operationalStateExpiration
—
Operational state expiration
osArch
sentinelone.osArch
—
OS arch
osStartTime
sentinelone.osStartTime
—
Os start time
osUsername
sentinelone.osUsername
—
OS username
proxyStates.console
sentinelone.proxyStates.console
—
Console
proxyStates.deepVisibility
sentinelone.proxyStates.deepVisibility
—
Deep visibility
rangerStatus
sentinelone.rangerStatus
—
Ranger status
rangerVersion
sentinelone.rangerVersion
—
Ranger version
registeredAt
sentinelone.registeredAt
—
Registered at
remoteProfilingState
sentinelone.remoteProfilingState
—
Remote profiling state
remoteProfilingStateExpiration
sentinelone.remoteProfilingStateExpiration
—
Remote profiling state expiration
scanAbortedAt
sentinelone.scanAbortedAt
—
Scan aborted at
scanFinishedAt
sentinelone.scanFinishedAt
—
Scan finished at
scanStartedAt
sentinelone.scanStartedAt
—
Scan started at
scanStatus
sentinelone.scanStatus
—
Scan status
showAlertIcon
sentinelone.showAlertIcon
—
Show alert icon
siteId
sentinelone.siteId
—
Site ID
storageName
sentinelone.storageName
—
Storage name
storageType
sentinelone.storageType
—
Storage type
tags.sentinelone
sentinelone.tags.sentinelone
—
Sentinelone
threatRebootRequired
sentinelone.threatRebootRequired
—
Threat reboot required
totalMemory
sentinelone.totalMemory
—
Total memory
updatedAt
sentinelone.updatedAt
—
Updated at
userActionsNeeded
sentinelone.userActionsNeeded
—
User actions needed
uuid
sentinelone.uuid
—
UUID

Device Interfaces Attributes

Device Security collects device interfaces attributes from SentinelOne. The following table lists each SentinelOne attribute, its name as stored in Device Security, and the Device Security field it maps to (if applicable).
SentinelOne Attribute
Device Security Attribute Name
Device Security Common Attribute*
Description
networkInterfaces.inet
sentinelone.networkInterfaces.inet
IP Address
Inet
networkInterfaces.physical
sentinelone.networkInterfaces.physical
MAC Address; id
Physical
networkInterfaces
sentinelone.networkInterfaces
third_party_learned_network_interfaces
Network interfaces

Vulnerability Attributes

Device Security collects vulnerability attributes from SentinelOne. The following table lists each SentinelOne attribute, its name as stored in Device Security, and the Device Security field it maps to (if applicable).
SentinelOne Attribute
Device Security Attribute Name
Device Security Common Attribute*
Description
cveId
sentinelone.cveId
cve
Cve ID
baseScore
sentinelone.baseScore
cvss_base_score
Base score
detectionDate
sentinelone.detectionDate
detected_time
Detection date
mac_address
sentinelone.mac_address
id
MAC address
ip_address
sentinelone.ip_address
IP Address
IP address
severity
sentinelone.severity
risk_level; severity
Severity
id
sentinelone.id
vulnerability_id
Unique identifier
application
sentinelone.application
—
Application
applicationName
sentinelone.applicationName
—
Application name
applicationVendor
sentinelone.applicationVendor
—
Application vendor
applicationVersion
sentinelone.applicationVersion
—
Application version
cvssVersion
sentinelone.cvssVersion
—
Cvss version
daysDetected
sentinelone.daysDetected
—
Days detected
endpointId
sentinelone.endpointId
—
Endpoint ID
endpointName
sentinelone.endpointName
—
Endpoint name
endpointType
sentinelone.endpointType
—
Endpoint type
lastScanDate
sentinelone.lastScanDate
—
Last scan date
lastScanResult
sentinelone.lastScanResult
—
Last scan result
markedBy
sentinelone.markedBy
—
Marked by
markedDate
sentinelone.markedDate
—
Marked date
markType
sentinelone.markType
—
Mark type
osType
sentinelone.osType
—
OS type
publishedDate
sentinelone.publishedDate
—
Published date
reason
sentinelone.reason
—
Reason
status
sentinelone.status
—
Status of the device
* Only some attributes map to a Device Security Common Attribute.