SentinelOne Attribute Reference
Focus
Focus
Device Security

SentinelOne Attribute Reference

Table of Contents

SentinelOne Attribute Reference

This reference lists the attributes that Device Security collects from SentinelOne, their names as stored in Device Security, and the Device Security fields they map to.
When Device Security integrates with SentinelOne Singularity, it imports endpoint protection data to enrich the device inventory. The attributes in this reference cover device records, network interface data, and vulnerability findings from the SentinelOne Singularity platform.
The third-party attribute name in Device Security refers to the attribute name as it appears in the Assets Inventory table and in Query Engine. This follows the format of third-party-name.attribute-name. When viewing the attribute name in the Assets Inventory table column selector or on a Device Details page, where the third-party name can be found as a header for the attributes section, then the third-party name is removed from the attribute name.
For example, micrsoft_defender_xdr.macAddress would appear in the Query Builder and in the Assets Inventory table, but under Device DetailsAttributesIntegration Specific AttributesMicrosoft Defender, the attribute would appear as macAddress.

V2 1 Device Details Attributes

Device Security collects v2 1 device details attributes from SentinelOne. The following table lists each SentinelOne attribute, its name as stored in Device Security, and the Device Security field it maps to (if applicable).
SentinelOne Attribute
Device Security Attribute Name
Device Security Common Attribute*
Description
computerName
sentinelone.computerName
hostname
ComputerName
networkInterfaces.inet
IP Address
Inet
locations.name
sentinelone.locations.name
Location
Name of the device
networkInterfaces.physical
MAC; id
Physical
modelName
sentinelone.modelName
Model
ModelName
networkStatus
sentinelone.networkStatus
operational_status
NetworkStatus
osRevision
sentinelone.osRevision
OS Build Number
OsRevision
osName
sentinelone.osName
OS Name
OsName
osType
sentinelone.osType
os_type
OsType
externalIp
sentinelone.externalIp
public_ip_address
ExternalIp
serialNumber
Serial Number
SerialNumber
siteName
sentinelone.siteName
Site
SiteName
installed_applications
third_party_learned_installed_software
Installed applications
accountId
sentinelone.accountId
AccountId
accountName
sentinelone.accountName
AccountName
activeDirectory.computerDistinguishedName
sentinelone.activeDirectory.computerDistinguishedName
ComputerDistinguishedName
activeDirectory.computerMemberOf
sentinelone.activeDirectory.computerMemberOf
ComputerMemberOf
activeDirectory.lastUserDistinguishedName
sentinelone.activeDirectory.lastUserDistinguishedName
LastUserDistinguishedName
activeDirectory.lastUserMemberOf
sentinelone.activeDirectory.lastUserMemberOf
LastUserMemberOf
activeDirectory.userPrincipalName
sentinelone.activeDirectory.userPrincipalName
UserPrincipalName
activeProtection
sentinelone.activeProtection
ActiveProtection
activeThreats
sentinelone.activeThreats
ActiveThreats
agentVersion
sentinelone.agentVersion
AgentVersion
allowRemoteShell
sentinelone.allowRemoteShell
AllowRemoteShell
appsVulnerabilityStatus
sentinelone.appsVulnerabilityStatus
AppsVulnerabilityStatus
cloudProviders
sentinelone.cloudProviders
CloudProviders
consoleMigrationStatus
sentinelone.consoleMigrationStatus
ConsoleMigrationStatus
containerizedWorkloadCounts
sentinelone.containerizedWorkloadCounts
ContainerizedWorkloadCounts
coreCount
sentinelone.coreCount
CoreCount
cpuCount
sentinelone.cpuCount
CpuCount
cpuId
sentinelone.cpuId
CpuId
createdAt
sentinelone.createdAt
CreatedAt
detectionState
sentinelone.detectionState
DetectionState
domain
sentinelone.domain
Domain
encryptedApplications
sentinelone.encryptedApplications
EncryptedApplications
externalId
sentinelone.externalId
ExternalId
firewallEnabled
sentinelone.firewallEnabled
FirewallEnabled
firstFullModeTime
sentinelone.firstFullModeTime
FirstFullModeTime
fullDiskScanLastUpdatedAt
sentinelone.fullDiskScanLastUpdatedAt
FullDiskScanLastUpdatedAt
groupId
sentinelone.groupId
GroupId
groupIp
sentinelone.groupIp
GroupIp
groupName
sentinelone.groupName
GroupName
hasContainerizedWorkload
sentinelone.hasContainerizedWorkload
HasContainerizedWorkload
id
sentinelone.id
Id
infected
sentinelone.infected
Infected
inRemoteShellSession
sentinelone.inRemoteShellSession
InRemoteShellSession
installerType
sentinelone.installerType
InstallerType
isActive
sentinelone.isActive
IsActive
isAdConnector
sentinelone.isAdConnector
IsAdConnector
isDecommissioned
sentinelone.isDecommissioned
IsDecommissioned
isHyperAutomate
sentinelone.isHyperAutomate
IsHyperAutomate
isPendingUninstall
sentinelone.isPendingUninstall
IsPendingUninstall
isUninstalled
sentinelone.isUninstalled
IsUninstalled
isUpToDate
sentinelone.isUpToDate
IsUpToDate
lastActiveDate
sentinelone.lastActiveDate
LastActiveDate
lastIpToMgmt
sentinelone.lastIpToMgmt
LastIpToMgmt
lastLoggedInUserName
sentinelone.lastLoggedInUserName
LastLoggedInUserName
lastSuccessfulScanDate
sentinelone.lastSuccessfulScanDate
LastSuccessfulScanDate
licenseKey
sentinelone.licenseKey
LicenseKey
locationEnabled
sentinelone.locationEnabled
LocationEnabled
locations.id
sentinelone.locations.id
Id
locations.scope
sentinelone.locations.scope
Scope
locationType
sentinelone.locationType
LocationType
machineSid
sentinelone.machineSid
MachineSid
machineType
sentinelone.machineType
MachineType
missingPermissions
sentinelone.missingPermissions
MissingPermissions
mitigationMode
sentinelone.mitigationMode
MitigationMode
mitigationModeSuspicious
sentinelone.mitigationModeSuspicious
MitigationModeSuspicious
networkQuarantineEnabled
sentinelone.networkQuarantineEnabled
NetworkQuarantineEnabled
operationalState
sentinelone.operationalState
OperationalState
operationalStateExpiration
sentinelone.operationalStateExpiration
OperationalStateExpiration
osArch
sentinelone.osArch
OsArch
osStartTime
sentinelone.osStartTime
OsStartTime
osUsername
sentinelone.osUsername
OsUsername
proxyStates.console
sentinelone.proxyStates.console
Console
proxyStates.deepVisibility
sentinelone.proxyStates.deepVisibility
DeepVisibility
rangerStatus
sentinelone.rangerStatus
RangerStatus
rangerVersion
sentinelone.rangerVersion
RangerVersion
registeredAt
sentinelone.registeredAt
RegisteredAt
remoteProfilingState
sentinelone.remoteProfilingState
RemoteProfilingState
remoteProfilingStateExpiration
sentinelone.remoteProfilingStateExpiration
RemoteProfilingStateExpiration
scanAbortedAt
sentinelone.scanAbortedAt
ScanAbortedAt
scanFinishedAt
sentinelone.scanFinishedAt
ScanFinishedAt
scanStartedAt
sentinelone.scanStartedAt
ScanStartedAt
scanStatus
sentinelone.scanStatus
ScanStatus
showAlertIcon
sentinelone.showAlertIcon
ShowAlertIcon
siteId
sentinelone.siteId
SiteId
storageName
sentinelone.storageName
StorageName
storageType
sentinelone.storageType
StorageType
tags.sentinelone
sentinelone.tags.sentinelone
Sentinelone
threatRebootRequired
sentinelone.threatRebootRequired
ThreatRebootRequired
totalMemory
sentinelone.totalMemory
TotalMemory
updatedAt
sentinelone.updatedAt
UpdatedAt
userActionsNeeded
sentinelone.userActionsNeeded
UserActionsNeeded
uuid
sentinelone.uuid
Uuid

V2 1 Device Details Interfaces Attributes

Device Security collects v2 1 device details interfaces attributes from SentinelOne. The following table lists each SentinelOne attribute, its name as stored in Device Security, and the Device Security field it maps to (if applicable).
SentinelOne Attribute
Device Security Attribute Name
Device Security Common Attribute*
Description
networkInterfaces.inet
sentinelone.networkInterfaces.inet
IP Address
Inet
networkInterfaces.physical
sentinelone.networkInterfaces.physical
MAC; id
Physical
networkInterfaces
sentinelone.networkInterfaces
third_party_learned_network_interfaces
NetworkInterfaces

V2 1 Vulnerability Details Attributes

Device Security collects v2 1 vulnerability details attributes from SentinelOne. The following table lists each SentinelOne attribute, its name as stored in Device Security, and the Device Security field it maps to (if applicable).
SentinelOne Attribute
Device Security Attribute Name
Device Security Common Attribute*
Description
cveId
sentinelone.cveId
cve
CveId
baseScore
sentinelone.baseScore
cvss_base_score
BaseScore
detectionDate
sentinelone.detectionDate
detected_time
DetectionDate
mac_address
sentinelone.mac_address
id
Mac address
ip_address
sentinelone.ip_address
IP Address
IP address
severity
sentinelone.severity
risk_level; severity
Severity
id
sentinelone.id
vulnerability_id
Id
application
sentinelone.application
Application
applicationName
sentinelone.applicationName
ApplicationName
applicationVendor
sentinelone.applicationVendor
ApplicationVendor
applicationVersion
sentinelone.applicationVersion
ApplicationVersion
cvssVersion
sentinelone.cvssVersion
CvssVersion
daysDetected
sentinelone.daysDetected
DaysDetected
endpointId
sentinelone.endpointId
EndpointId
endpointName
sentinelone.endpointName
EndpointName
endpointType
sentinelone.endpointType
EndpointType
lastScanDate
sentinelone.lastScanDate
LastScanDate
lastScanResult
sentinelone.lastScanResult
LastScanResult
markedBy
sentinelone.markedBy
MarkedBy
markedDate
sentinelone.markedDate
MarkedDate
markType
sentinelone.markType
MarkType
osType
sentinelone.osType
OsType
publishedDate
sentinelone.publishedDate
PublishedDate
reason
sentinelone.reason
Reason
status
sentinelone.status
Status of the device
* Only some attributes map to a Device Security Common Attribute.