SentinelOne Attribute Reference
This reference lists the attributes that Device Security collects from SentinelOne,
their names as stored in Device Security, and the Device Security fields they map to.
When
Device Security integrates with SentinelOne Singularity, it
imports endpoint protection data to enrich the device inventory. The attributes in this
reference cover device records, network interface data, and vulnerability findings from
the SentinelOne Singularity platform.
The third-party attribute name in Device Security refers to the attribute name
as it appears in the Assets Inventory table and in Query Engine. This follows the format
of third-party-name.attribute-name.
When viewing the attribute name in the Assets Inventory table column selector or on a
Device Details page, where the third-party name can be found as a header for the
attributes section, then the third-party name is removed from the attribute name.
For example, micrsoft_defender_xdr.macAddress would appear in the
Query Builder and in the Assets Inventory table, but under , the attribute would appear as macAddress.
V2 1 Device Details Attributes
Device Security collects v2 1 device details attributes from SentinelOne. The following table lists each SentinelOne attribute, its name as stored in Device Security, and the Device Security field it maps to (if applicable).
SentinelOne Attribute | Device Security Attribute Name | Device Security Common Attribute* | Description |
computerName | sentinelone.computerName | hostname | ComputerName |
networkInterfaces.inet | — | IP Address | Inet |
locations.name | sentinelone.locations.name | Location | Name of the device |
networkInterfaces.physical | — | MAC; id | Physical |
modelName | sentinelone.modelName | Model | ModelName |
networkStatus | sentinelone.networkStatus | operational_status | NetworkStatus |
osRevision | sentinelone.osRevision | OS Build Number | OsRevision |
osName | sentinelone.osName | OS Name | OsName |
osType | sentinelone.osType | os_type | OsType |
externalIp | sentinelone.externalIp | public_ip_address | ExternalIp |
serialNumber | — | Serial Number | SerialNumber |
siteName | sentinelone.siteName | Site | SiteName |
installed_applications | — | third_party_learned_installed_software | Installed applications |
accountId | sentinelone.accountId | — | AccountId |
accountName | sentinelone.accountName | — | AccountName |
activeDirectory.computerDistinguishedName | sentinelone.activeDirectory.computerDistinguishedName | — | ComputerDistinguishedName |
activeDirectory.computerMemberOf | sentinelone.activeDirectory.computerMemberOf | — | ComputerMemberOf |
activeDirectory.lastUserDistinguishedName | sentinelone.activeDirectory.lastUserDistinguishedName | — | LastUserDistinguishedName |
activeDirectory.lastUserMemberOf | sentinelone.activeDirectory.lastUserMemberOf | — | LastUserMemberOf |
activeDirectory.userPrincipalName | sentinelone.activeDirectory.userPrincipalName | — | UserPrincipalName |
activeProtection | sentinelone.activeProtection | — | ActiveProtection |
activeThreats | sentinelone.activeThreats | — | ActiveThreats |
agentVersion | sentinelone.agentVersion | — | AgentVersion |
allowRemoteShell | sentinelone.allowRemoteShell | — | AllowRemoteShell |
appsVulnerabilityStatus | sentinelone.appsVulnerabilityStatus | — | AppsVulnerabilityStatus |
cloudProviders | sentinelone.cloudProviders | — | CloudProviders |
consoleMigrationStatus | sentinelone.consoleMigrationStatus | — | ConsoleMigrationStatus |
containerizedWorkloadCounts | sentinelone.containerizedWorkloadCounts | — | ContainerizedWorkloadCounts |
coreCount | sentinelone.coreCount | — | CoreCount |
cpuCount | sentinelone.cpuCount | — | CpuCount |
cpuId | sentinelone.cpuId | — | CpuId |
createdAt | sentinelone.createdAt | — | CreatedAt |
detectionState | sentinelone.detectionState | — | DetectionState |
domain | sentinelone.domain | — | Domain |
encryptedApplications | sentinelone.encryptedApplications | — | EncryptedApplications |
externalId | sentinelone.externalId | — | ExternalId |
firewallEnabled | sentinelone.firewallEnabled | — | FirewallEnabled |
firstFullModeTime | sentinelone.firstFullModeTime | — | FirstFullModeTime |
fullDiskScanLastUpdatedAt | sentinelone.fullDiskScanLastUpdatedAt | — | FullDiskScanLastUpdatedAt |
groupId | sentinelone.groupId | — | GroupId |
groupIp | sentinelone.groupIp | — | GroupIp |
groupName | sentinelone.groupName | — | GroupName |
hasContainerizedWorkload | sentinelone.hasContainerizedWorkload | — | HasContainerizedWorkload |
infected | sentinelone.infected | — | Infected |
inRemoteShellSession | sentinelone.inRemoteShellSession | — | InRemoteShellSession |
installerType | sentinelone.installerType | — | InstallerType |
isActive | sentinelone.isActive | — | IsActive |
isAdConnector | sentinelone.isAdConnector | — | IsAdConnector |
isDecommissioned | sentinelone.isDecommissioned | — | IsDecommissioned |
isHyperAutomate | sentinelone.isHyperAutomate | — | IsHyperAutomate |
isPendingUninstall | sentinelone.isPendingUninstall | — | IsPendingUninstall |
isUninstalled | sentinelone.isUninstalled | — | IsUninstalled |
isUpToDate | sentinelone.isUpToDate | — | IsUpToDate |
lastActiveDate | sentinelone.lastActiveDate | — | LastActiveDate |
lastIpToMgmt | sentinelone.lastIpToMgmt | — | LastIpToMgmt |
lastLoggedInUserName | sentinelone.lastLoggedInUserName | — | LastLoggedInUserName |
lastSuccessfulScanDate | sentinelone.lastSuccessfulScanDate | — | LastSuccessfulScanDate |
licenseKey | sentinelone.licenseKey | — | LicenseKey |
locationEnabled | sentinelone.locationEnabled | — | LocationEnabled |
locations.id | sentinelone.locations.id | — | Id |
locations.scope | sentinelone.locations.scope | — | Scope |
locationType | sentinelone.locationType | — | LocationType |
machineSid | sentinelone.machineSid | — | MachineSid |
machineType | sentinelone.machineType | — | MachineType |
missingPermissions | sentinelone.missingPermissions | — | MissingPermissions |
mitigationMode | sentinelone.mitigationMode | — | MitigationMode |
mitigationModeSuspicious | sentinelone.mitigationModeSuspicious | — | MitigationModeSuspicious |
networkQuarantineEnabled | sentinelone.networkQuarantineEnabled | — | NetworkQuarantineEnabled |
operationalState | sentinelone.operationalState | — | OperationalState |
operationalStateExpiration | sentinelone.operationalStateExpiration | — | OperationalStateExpiration |
osArch | sentinelone.osArch | — | OsArch |
osStartTime | sentinelone.osStartTime | — | OsStartTime |
osUsername | sentinelone.osUsername | — | OsUsername |
proxyStates.console | sentinelone.proxyStates.console | — | Console |
proxyStates.deepVisibility | sentinelone.proxyStates.deepVisibility | — | DeepVisibility |
rangerStatus | sentinelone.rangerStatus | — | RangerStatus |
rangerVersion | sentinelone.rangerVersion | — | RangerVersion |
registeredAt | sentinelone.registeredAt | — | RegisteredAt |
remoteProfilingState | sentinelone.remoteProfilingState | — | RemoteProfilingState |
remoteProfilingStateExpiration | sentinelone.remoteProfilingStateExpiration | — | RemoteProfilingStateExpiration |
scanAbortedAt | sentinelone.scanAbortedAt | — | ScanAbortedAt |
scanFinishedAt | sentinelone.scanFinishedAt | — | ScanFinishedAt |
scanStartedAt | sentinelone.scanStartedAt | — | ScanStartedAt |
scanStatus | sentinelone.scanStatus | — | ScanStatus |
showAlertIcon | sentinelone.showAlertIcon | — | ShowAlertIcon |
siteId | sentinelone.siteId | — | SiteId |
storageName | sentinelone.storageName | — | StorageName |
storageType | sentinelone.storageType | — | StorageType |
tags.sentinelone | sentinelone.tags.sentinelone | — | Sentinelone |
threatRebootRequired | sentinelone.threatRebootRequired | — | ThreatRebootRequired |
totalMemory | sentinelone.totalMemory | — | TotalMemory |
updatedAt | sentinelone.updatedAt | — | UpdatedAt |
userActionsNeeded | sentinelone.userActionsNeeded | — | UserActionsNeeded |
uuid | sentinelone.uuid | — | Uuid |
V2 1 Device Details Interfaces Attributes
Device Security collects v2 1 device details interfaces attributes from SentinelOne. The following table lists each SentinelOne attribute, its name as stored in Device Security, and the Device Security field it maps to (if applicable).
SentinelOne Attribute | Device Security Attribute Name | Device Security Common Attribute* | Description |
networkInterfaces.inet | sentinelone.networkInterfaces.inet | IP Address | Inet |
networkInterfaces.physical | sentinelone.networkInterfaces.physical | MAC; id | Physical |
networkInterfaces | sentinelone.networkInterfaces | third_party_learned_network_interfaces | NetworkInterfaces |
V2 1 Vulnerability Details Attributes
Device Security collects v2 1 vulnerability details attributes from SentinelOne. The following table lists each SentinelOne attribute, its name as stored in Device Security, and the Device Security field it maps to (if applicable).
SentinelOne Attribute | Device Security Attribute Name | Device Security Common Attribute* | Description |
cveId | sentinelone.cveId | cve | CveId |
baseScore | sentinelone.baseScore | cvss_base_score | BaseScore |
detectionDate | sentinelone.detectionDate | detected_time | DetectionDate |
mac_address | sentinelone.mac_address | id | Mac address |
ip_address | sentinelone.ip_address | IP Address | IP address |
severity | sentinelone.severity | risk_level; severity | Severity |
id | sentinelone.id | vulnerability_id | Id |
application | sentinelone.application | — | Application |
applicationName | sentinelone.applicationName | — | ApplicationName |
applicationVendor | sentinelone.applicationVendor | — | ApplicationVendor |
applicationVersion | sentinelone.applicationVersion | — | ApplicationVersion |
cvssVersion | sentinelone.cvssVersion | — | CvssVersion |
daysDetected | sentinelone.daysDetected | — | DaysDetected |
endpointId | sentinelone.endpointId | — | EndpointId |
endpointName | sentinelone.endpointName | — | EndpointName |
endpointType | sentinelone.endpointType | — | EndpointType |
lastScanDate | sentinelone.lastScanDate | — | LastScanDate |
lastScanResult | sentinelone.lastScanResult | — | LastScanResult |
markedBy | sentinelone.markedBy | — | MarkedBy |
markedDate | sentinelone.markedDate | — | MarkedDate |
markType | sentinelone.markType | — | MarkType |
osType | sentinelone.osType | — | OsType |
publishedDate | sentinelone.publishedDate | — | PublishedDate |
reason | sentinelone.reason | — | Reason |
status | sentinelone.status | — | Status of the device |
* Only some attributes map to a Device Security Common Attribute.