SentinelOne Attribute Reference
This reference lists the attributes that Device Security collects from SentinelOne,
their names as stored in Device Security, and the Device Security fields they map to.
When
Device Security integrates with SentinelOne Singularity, it
imports endpoint protection data to enrich the device inventory. The attributes in this
reference cover device records, network interface data, and vulnerability findings from
the SentinelOne Singularity platform.
The third-party attribute name in Device Security refers to the attribute name
as it appears in the Assets Inventory table and in Query Engine. This follows the format
of third-party-name.attribute-name.
When viewing the attribute name in the Assets Inventory table column selector or on a
Device Details page, where the third-party name can be found as a header for the
attributes section, then the third-party name is removed from the attribute name.
For example, micrsoft_defender_xdr.macAddress would appear in the
Query Builder and in the Assets Inventory table, but under , the attribute would appear as macAddress.
Device Attributes
Device Security collects device attributes from SentinelOne. The following table lists each SentinelOne attribute, its name as stored in Device Security, and the Device Security field it maps to (if applicable).
SentinelOne Attribute | Device Security Attribute Name | Device Security Common Attribute* | Description |
computerName | sentinelone.computerName | hostname | Computer name |
networkInterfaces.inet | — | IP Address | Inet |
locations.name | sentinelone.locations.name | Location | Name of the device |
networkInterfaces.physical | — | MAC Address; id | Physical |
modelName | sentinelone.modelName | Model | Model name |
networkStatus | sentinelone.networkStatus | operational_status | Network status |
osRevision | sentinelone.osRevision | OS Build Number | OS revision |
osType | sentinelone.osType | os_type | OS type |
externalIp | sentinelone.externalIp | public_ip_address | External IP |
osName | sentinelone.osName | raw_os | Os name |
serialNumber | — | Serial Number | Serial number |
siteName | sentinelone.siteName | Site | Site name |
installed_applications | — | third_party_learned_installed_software | Installed applications |
accountId | sentinelone.accountId | — | Account ID |
accountName | sentinelone.accountName | — | Account name |
activeDirectory.computerDistinguishedName | sentinelone.activeDirectory.computerDistinguishedName | — | Computer distinguished name |
activeDirectory.computerMemberOf | sentinelone.activeDirectory.computerMemberOf | — | Computer member of |
activeDirectory.lastUserDistinguishedName | sentinelone.activeDirectory.lastUserDistinguishedName | — | Last user distinguished name |
activeDirectory.lastUserMemberOf | sentinelone.activeDirectory.lastUserMemberOf | — | Last user member of |
activeDirectory.userPrincipalName | sentinelone.activeDirectory.userPrincipalName | — | User principal name |
activeProtection | sentinelone.activeProtection | — | Active protection |
activeThreats | sentinelone.activeThreats | — | Active threats |
agentVersion | sentinelone.agentVersion | — | Agent version |
allowRemoteShell | sentinelone.allowRemoteShell | — | Allow remote shell |
appsVulnerabilityStatus | sentinelone.appsVulnerabilityStatus | — | Apps vulnerability status |
cloudProviders | sentinelone.cloudProviders | — | Cloud providers |
consoleMigrationStatus | sentinelone.consoleMigrationStatus | — | Console migration status |
containerizedWorkloadCounts | sentinelone.containerizedWorkloadCounts | — | Containerized workload counts |
coreCount | sentinelone.coreCount | — | Number of cores |
cpuCount | sentinelone.cpuCount | — | Number of CPUs |
cpuId | sentinelone.cpuId | — | Cpu ID |
createdAt | sentinelone.createdAt | — | Created at |
detectionState | sentinelone.detectionState | — | Detection state |
domain | sentinelone.domain | — | Domain |
encryptedApplications | sentinelone.encryptedApplications | — | Encrypted applications |
externalId | sentinelone.externalId | — | External ID |
firewallEnabled | sentinelone.firewallEnabled | — | Firewall enabled |
firstFullModeTime | sentinelone.firstFullModeTime | — | First full mode time |
fullDiskScanLastUpdatedAt | sentinelone.fullDiskScanLastUpdatedAt | — | Full disk scan last updated at |
groupId | sentinelone.groupId | — | Group ID |
groupIp | sentinelone.groupIp | — | Group IP |
groupName | sentinelone.groupName | — | Group name |
hasContainerizedWorkload | sentinelone.hasContainerizedWorkload | — | Has containerized workload |
id | sentinelone.id | — | Unique identifier |
infected | sentinelone.infected | — | Infected |
inRemoteShellSession | sentinelone.inRemoteShellSession | — | In remote shell session |
installerType | sentinelone.installerType | — | Installer type |
isActive | sentinelone.isActive | — | Is active |
isAdConnector | sentinelone.isAdConnector | — | Is ad connector |
isDecommissioned | sentinelone.isDecommissioned | — | Is decommissioned |
isHyperAutomate | sentinelone.isHyperAutomate | — | Is hyper automate |
isPendingUninstall | sentinelone.isPendingUninstall | — | Is pending uninstall |
isUninstalled | sentinelone.isUninstalled | — | Is uninstalled |
isUpToDate | sentinelone.isUpToDate | — | Is up to date |
lastActiveDate | sentinelone.lastActiveDate | — | Last active date |
lastIpToMgmt | sentinelone.lastIpToMgmt | — | Last IP to mgmt |
lastLoggedInUserName | sentinelone.lastLoggedInUserName | — | Last logged in user name |
lastSuccessfulScanDate | sentinelone.lastSuccessfulScanDate | — | Last successful scan date |
licenseKey | sentinelone.licenseKey | — | License key |
locationEnabled | sentinelone.locationEnabled | — | Location enabled |
locations.id | sentinelone.locations.id | — | Unique identifier |
locations.scope | sentinelone.locations.scope | — | Scope |
locationType | sentinelone.locationType | — | Location type |
machineSid | sentinelone.machineSid | — | Machine sid |
machineType | sentinelone.machineType | — | Machine type |
missingPermissions | sentinelone.missingPermissions | — | Missing permissions |
mitigationMode | sentinelone.mitigationMode | — | Mitigation mode |
mitigationModeSuspicious | sentinelone.mitigationModeSuspicious | — | Mitigation mode suspicious |
networkQuarantineEnabled | sentinelone.networkQuarantineEnabled | — | Network quarantine enabled |
operationalState | sentinelone.operationalState | — | Operational state |
operationalStateExpiration | sentinelone.operationalStateExpiration | — | Operational state expiration |
osArch | sentinelone.osArch | — | OS arch |
osStartTime | sentinelone.osStartTime | — | Os start time |
osUsername | sentinelone.osUsername | — | OS username |
proxyStates.console | sentinelone.proxyStates.console | — | Console |
proxyStates.deepVisibility | sentinelone.proxyStates.deepVisibility | — | Deep visibility |
rangerStatus | sentinelone.rangerStatus | — | Ranger status |
rangerVersion | sentinelone.rangerVersion | — | Ranger version |
registeredAt | sentinelone.registeredAt | — | Registered at |
remoteProfilingState | sentinelone.remoteProfilingState | — | Remote profiling state |
remoteProfilingStateExpiration | sentinelone.remoteProfilingStateExpiration | — | Remote profiling state expiration |
scanAbortedAt | sentinelone.scanAbortedAt | — | Scan aborted at |
scanFinishedAt | sentinelone.scanFinishedAt | — | Scan finished at |
scanStartedAt | sentinelone.scanStartedAt | — | Scan started at |
scanStatus | sentinelone.scanStatus | — | Scan status |
showAlertIcon | sentinelone.showAlertIcon | — | Show alert icon |
siteId | sentinelone.siteId | — | Site ID |
storageName | sentinelone.storageName | — | Storage name |
storageType | sentinelone.storageType | — | Storage type |
tags.sentinelone | sentinelone.tags.sentinelone | — | Sentinelone |
threatRebootRequired | sentinelone.threatRebootRequired | — | Threat reboot required |
totalMemory | sentinelone.totalMemory | — | Total memory |
updatedAt | sentinelone.updatedAt | — | Updated at |
userActionsNeeded | sentinelone.userActionsNeeded | — | User actions needed |
uuid | sentinelone.uuid | — | UUID |
Device Interfaces Attributes
Device Security collects device interfaces attributes from SentinelOne. The following table lists each SentinelOne attribute, its name as stored in Device Security, and the Device Security field it maps to (if applicable).
SentinelOne Attribute | Device Security Attribute Name | Device Security Common Attribute* | Description |
networkInterfaces.inet | sentinelone.networkInterfaces.inet | IP Address | Inet |
networkInterfaces.physical | sentinelone.networkInterfaces.physical | MAC Address; id | Physical |
networkInterfaces | sentinelone.networkInterfaces | third_party_learned_network_interfaces | Network interfaces |
Vulnerability Attributes
Device Security collects vulnerability attributes from SentinelOne. The following table lists each SentinelOne attribute, its name as stored in Device Security, and the Device Security field it maps to (if applicable).
SentinelOne Attribute | Device Security Attribute Name | Device Security Common Attribute* | Description |
cveId | sentinelone.cveId | cve | Cve ID |
baseScore | sentinelone.baseScore | cvss_base_score | Base score |
detectionDate | sentinelone.detectionDate | detected_time | Detection date |
mac_address | sentinelone.mac_address | id | MAC address |
ip_address | sentinelone.ip_address | IP Address | IP address |
severity | sentinelone.severity | risk_level; severity | Severity |
id | sentinelone.id | vulnerability_id | Unique identifier |
application | sentinelone.application | — | Application |
applicationName | sentinelone.applicationName | — | Application name |
applicationVendor | sentinelone.applicationVendor | — | Application vendor |
applicationVersion | sentinelone.applicationVersion | — | Application version |
cvssVersion | sentinelone.cvssVersion | — | Cvss version |
daysDetected | sentinelone.daysDetected | — | Days detected |
endpointId | sentinelone.endpointId | — | Endpoint ID |
endpointName | sentinelone.endpointName | — | Endpoint name |
endpointType | sentinelone.endpointType | — | Endpoint type |
lastScanDate | sentinelone.lastScanDate | — | Last scan date |
lastScanResult | sentinelone.lastScanResult | — | Last scan result |
markedBy | sentinelone.markedBy | — | Marked by |
markedDate | sentinelone.markedDate | — | Marked date |
markType | sentinelone.markType | — | Mark type |
osType | sentinelone.osType | — | OS type |
publishedDate | sentinelone.publishedDate | — | Published date |
reason | sentinelone.reason | — | Reason |
status | sentinelone.status | — | Status of the device |
* Only some attributes map to a Device Security Common Attribute.