Skip to main content
Connector guides

Connect SentinelOne

SentinelOne is an endpoint protection platform — EDR — that runs an agent on your customers' laptops, desktops and servers. The agent detects and stops threats on the machine itself, and the…

Written By Christopher Scaminaci

Last updated 6 days ago

SentinelOne is an endpoint protection platform — EDR — that runs an agent on your customers' laptops, desktops and servers. The agent detects and stops threats on the machine itself, and the management console gives you one place to see every agent, every threat and every policy across all of the customers you manage. SentinelOne also extends past the endpoint into cloud and identity asset inventory, so the same console answers "what do we protect" as well as "what happened". StackJack talks to SentinelOne through its management API.

Connecting SentinelOne to StackJack gives your AI assistant a family of s1_ MCP tools — MCP (Model Context Protocol) tools are the standardized commands an AI assistant can call through StackJack. With them, your AI can:

  • Work the threat queue — list threats across every customer or one site, read the full detection detail behind each, follow the activity log, and see which alerts the detection rules raised
  • Answer questions about the fleet — which machines have an agent, which are out of date, which are disconnected, what is installed on them, and how many machines a filter actually matches before anyone acts on it
  • Report on protection — agent versions and health, policy assignment, exclusions and blocklist entries, firewall and device-control rules, and the endpoints network discovery found with no agent at all
  • See the wider estate — the cloud, identity, container, data-store and application asset inventories, their saved filters, and the security-posture findings that go with them
  • Run the customer structure — sites, accounts, groups, tags, users and roles, console settings, scheduled reports and saved views
  • Respond to an incident (on Pro plans) — isolate a machine from the network, start a scan, mitigate or blocklist a threat, collect logs and forensic evidence, and reconnect it when you are done
  • Change protection (on Pro plans) — exclusions, blocklist entries, detection rules, firewall and device-control rules, policies, and threat-intelligence indicators
  • Manage endpoints at scale (on Pro plans) — move machines between groups or sites, approve or reject uninstalls, push agent upgrades, run remote scripts, and decommission a machine that has left the business

How StackJack authenticates to SentinelOne

SentinelOne uses a single API token that you create in your own console. There is no sign-in flow, no client ID and no second secret — you paste the token into StackJack and that is the whole credential.

The one thing to plan for is expiry. SentinelOne creates tokens with a fixed lifetime that you choose when you generate them, and nothing renews them automatically. When a token expires or you rotate it, you paste the new one into StackJack. Put the expiry date in your calendar, because the connector stops working on that day.

Create the token against a service user

Generate the token from a dedicated service user rather than from your own profile. A token that belongs to a person stops working the day that person leaves or changes role, and every action StackJack takes is attributed to whoever owns the token.

What the token is allowed to do comes entirely from the role you give that service user. Give it the reach you actually want your AI to have.

Steps

  1. Find your console address. Sign in to SentinelOne and look at your browser's address bar. It looks like https://usea1-yourcompany.sentinelone.net — the first part identifies the region your data lives in. Copy the whole address up to and including .sentinelone.net.
  2. Create a service user. In the SentinelOne console, go to Settings, then Users, then Service Users, and create one for StackJack.
  3. Give it a role. The role decides what StackJack can do. A role that can read everything and act on endpoints gives your AI the full set; a narrower role simply means some tools are refused.
  4. Generate the API token for that service user. SentinelOne asks how long it should last — note the date.
  5. Copy the token straight away and store it securely. Treat it as a password: anyone holding it can read and act on your SentinelOne console.
  6. Paste both into StackJack. Open Connectors, choose SentinelOne, and enter the console address and the token.
  7. Run a Test Connection to confirm StackJack can reach your console with the token.

Your console address is specific to your tenant and your region, and there is no shared SentinelOne address. Copy it from your browser rather than typing one from memory. If you run consoles in more than one region, each one is a separate connection — SentinelOne does not look across regions.

What to know before your AI uses this connector

Endpoint actions are chosen by filter, not one machine at a time

This is the most important thing about the SentinelOne connector. SentinelOne's own API takes a filter for actions on endpoints, and it acts on everything the filter matches. Isolate, shut down, scan, uninstall, decommission — each of them applies to every machine that matched, and SentinelOne answers with success whether that was one laptop or the whole fleet.

Two things reduce the risk, and it is worth knowing both:

  • Every one of these tools requires the Pro tier and is marked destructive. Whether your AI application asks you to confirm before running one depends on that application's own settings — see Destructive tools and confirmation. Check that setting before you grant these tools, because the marking alone does not stop a call.
  • Each of their descriptions tells your AI to run the matching count first, so it can report how many machines a filter selects before it acts. If you are asking for something broad, ask for the count.

The same caution applies to reading the result. A successful response from SentinelOne carries a count of how many machines were affected, and that count can be zero. Success does not prove the action landed — ask your AI to re-read the machines afterwards.

Some tools change protection itself

  • Adding an exclusion stops SentinelOne acting on something it would otherwise catch, everywhere in the scope you gave it. Nothing looks broken afterwards; the threat simply stops being caught.
  • Detection rules can quarantine automatically. A rule that matches more than you intended acts on every machine in scope without waiting for anyone.
  • Blocklist entries and threat-intelligence indicators apply across the scope too, and can block software your customer relies on.
  • Firewall, device-control and network-quarantine rules change what a machine is allowed to do on the network. A location is part of this: SentinelOne picks which firewall rules an agent enforces from its location, so adding or editing one re-points live machines at a different rule set.
  • Uninstalling or decommissioning an agent removes protection from that machine. Decommissioning also removes it from the console, so it stops appearing in your reports.
  • Scheduled reports mail console data to whoever is on the recipient list. Creating or editing one can send information about your customers to an address outside your business.

Every one of these is marked as destructive and requires the Pro tier. Whether your AI application asks you to confirm first depends on that application's own settings.

A refused tool is usually the role, not a fault

SentinelOne checks permissions for each operation separately, against the role of the service user whose token you pasted. So reads can work perfectly while one specific action is refused, and that is not a broken connection — the connection test will still show as connected.

When a tool reports that SentinelOne refused it, widen the service user's role in the SentinelOne console, or point it at a role that already has that permission. Also check that the service user's scope covers the account or site you are asking about. Nothing needs changing in StackJack.

Plans and limits

Read tools are available on the Free tier. Everything that acts on an endpoint, changes protection, edits the customer structure or runs a script is Pro. Business reaches the same tools as Pro and differs by monthly call quota.

See the generated SentinelOne tool reference for the current inventory, plan assignment, input schemas, and destructive-action labels.

SentinelOne does not publish a request quota. StackJack paces requests and backs off automatically if you are throttled, which usually makes a large report slower rather than failed. Pacing smooths a burst; it does not guarantee that every call arrives. Retries are bounded, so a wide enough read can still come back throttled or time out. Narrow the read, honour any retry delay the vendor sends, and check whether a write landed before repeating it — see Retrying a failed or timed-out write.

Long lists are read a page at a time. Each page comes back with a marker for the next one, and your AI passes that marker back to read the following page. SentinelOne stops returning results past a certain depth when a caller jumps to a position rather than following the pages in order, so if you need a complete list, ask for the whole list rather than for "the next thousand".

Several customers

Every customer has their own SentinelOne console. Add one connection per console from the connector's card, name it after the customer, and your AI names it on each call. Omit the name and the call runs against your default connection. Pin an endpoint to one connection when an AI should never reach past a single customer. See Several connections of one connector.

Troubleshooting

"SentinelOne did not accept the API token" — the usual cause is that the token expired. SentinelOne tokens are created with a fixed lifetime and nothing renews them, so this is a normal end state rather than a fault. It can also mean the token was revoked, or copied incompletely. Generate a new token for the service user in your console, paste it into StackJack, and run a Test Connection.

"SentinelOne accepted the token but refused this operation" — the service user's role is missing the permission that one operation needs, or its scope does not cover the account or site in question. Widen the role in SentinelOne and try again. Your other SentinelOne tools are unaffected, which is the signal that the credential itself is fine.

"SentinelOne could not find what the request asked for" — check the id being used. SentinelOne ids are long numeric strings, and an id from the threats view is not interchangeable with one from the alerts view. Also confirm the record belongs to a site or account the service user's scope includes.

A customer's machines are missing from a report — check which site or account the report was scoped to before assuming the agents are gone. Everything in SentinelOne hangs off accounts and sites, and a report scoped to the wrong one looks exactly like a customer with no machines.

An action reported success but nothing changed — read the affected count in the response. SentinelOne returns success for a filter that matched nothing, so a count of zero means the filter selected no machines, not that the action failed. Ask your AI to run the matching count first and to re-read afterwards.

A machine shows as disconnected but the customer says it is fine — that is the agent's connection to the console, not the machine's connection to the internet. It usually means the agent is not running or cannot reach your console, and it is worth checking before treating the machine as offline.

SentinelOne tools

s1_ · 696 tools · Free 367 · Pro 329

Activity Log

ToolWhat it does
s1_get_activities
Free · Read-only
Get Activities.
s1_get_activity_types
Free · Read-only
Get Activity Types.
s1_get_last_activity_syslog_message
Free · Read-only
Last activity as Syslog message.

Agent Deployment and Updates

ToolWhat it does
s1_add_cred_details
Pro · Destructive
DESTRUCTIVE — Add cred details.
s1_create_cred_group
Pro · Destructive
DESTRUCTIVE — Create Cred Group.
s1_create_policy
Pro · Destructive
DESTRUCTIVE — Create Policy.
s1_create_policy_action
Pro · Destructive
DESTRUCTIVE — Policy Action.
s1_deactivate_policies
Pro · Destructive
DESTRUCTIVE — Deactivate Policies.
s1_delete_cred_group
Pro · Destructive
DESTRUCTIVE — Delete Cred Group.
s1_delete_cred_group_detail
Pro · Destructive
DESTRUCTIVE — Delete Cred Group Detail.
s1_delete_packages
Pro · Destructive
DESTRUCTIVE — Delete Packages.
s1_deploy_system_package
Pro · Destructive
DESTRUCTIVE — Deploy System Package.
s1_get_available_packages
Free · Read-only
Get Available Packages.
s1_get_cred_group_details
Free · Read-only
Get Cred group details.
s1_get_cred_groups
Free · Read-only
Get Cred groups.
s1_get_latest_packages
Free · Read-only
Get Latest Packages.
s1_get_parent_policies
Free · Read-only
Get Parent Policies.
s1_get_policies
Free · Read-only
Get Policies.
s1_get_policies_os_count
Free · Read-only
All Policies OS Count.
s1_get_policies_os_count_upgrade_policy
Free · Read-only
Policies OS Count.
s1_has_policy
Free · Read-only
Has Policy.
s1_reorder_policies
Pro · Destructive
DESTRUCTIVE — Reorder Policies.
s1_reset_policy_retry_counter
Pro · Destructive
DESTRUCTIVE — Reset Policy Retry Counter.
s1_set_scope_inheriting
Pro · Destructive
DESTRUCTIVE — Set Scope Inheriting.
s1_update_cred_group_details
Pro · Destructive
DESTRUCTIVE — Update Cred Group Details.
s1_update_package
Pro · Destructive
DESTRUCTIVE — Update package.
s1_update_policy
Pro · Destructive
DESTRUCTIVE — Update Policy.
s1_upload_agent_package
Pro · Destructive
DESTRUCTIVE — Upload Agent Package.
s1_upload_system_package
Pro · Destructive
DESTRUCTIVE — Upload System Package.

Alerts

ToolWhat it does
s1_create_internal_api_only_notify_action_was_triggered_without
Pro · Destructive
DESTRUCTIVE — Internal api only to notify action was triggered without actually performing it.
s1_create_perform_action_selected_assets_entities
Pro · Destructive
DESTRUCTIVE — Perform an Action on selected assets/entities.
s1_fetch_surface_ids_case_select_filters
Free · Read-only
Fetch surface ids in case of select all with filters.
s1_get_alerts
Free · Read-only
Get alerts.
s1_get_available_actions_asset_entity_type
Free · Read-only
Get Available Actions by Asset/Entity Type.
s1_update_alert_analyst_verdict
Pro · Destructive
DESTRUCTIVE — Update Alert Analyst Verdict.
s1_update_threat_incident
Pro · Destructive
DESTRUCTIVE — Update Threat Incident.

Detection Rules

ToolWhat it does
s1_activate_rules
Pro · Destructive
DESTRUCTIVE — Activate Rules.
s1_create_rule
Pro · Destructive
DESTRUCTIVE — Create Rule.
s1_delete_rules
Pro · Destructive
DESTRUCTIVE — Delete Rules.
s1_disable_managed_detection_rule
Pro · Destructive
DESTRUCTIVE — Disable a Managed Detection Rule.
s1_disable_rules
Pro · Destructive
DESTRUCTIVE — Disable Rules.
s1_enable_managed_detection_rule
Pro · Destructive
DESTRUCTIVE — Enable a Managed Detection Rule.
s1_get_data_sources
Free · Read-only
Get Data Sources.
s1_get_free_text_filters
Free · Read-only
Free-Text Filters.
s1_get_managed_detection_rules
Free · Read-only
Get Managed Detection Rules.
s1_get_managed_detection_rules_detection_library
Free · Read-only
Get Managed Detection Rules.
s1_get_rules
Free · Read-only
Get Rules.
s1_get_settings_managed_detection_rules
Free · Read-only
Get settings for Managed Detection Rules.
s1_get_severities
Free · Read-only
Get Severities.
s1_get_statuses
Free · Read-only
Get Statuses.
s1_get_surfaces
Free · Read-only
Get Surfaces.
s1_get_template_detection_rules
Free · Read-only
Get Template Detection Rules.
s1_update_rule
Pro · Destructive
DESTRUCTIVE — Update Rule.
s1_update_settings_managed_detection_rules
Pro · Destructive
DESTRUCTIVE — Update settings for Managed Detection Rules.

Endpoint Actions

ToolWhat it does
s1_abort_scan
Pro · Destructive
DESTRUCTIVE — Abort Scan.
s1_approve_stateless_upgrades
Pro · Destructive
DESTRUCTIVE — Approve Stateless Upgrades.
s1_approve_uninstall
Pro · Destructive
DESTRUCTIVE — Approve Uninstall.
s1_broadcast_message
Pro · Destructive
DESTRUCTIVE — Broadcast Message.
s1_can_run_remote_shell
Pro · Destructive
DESTRUCTIVE — Can run Remote Shell.
s1_clear_remote_shell
Pro · Destructive
DESTRUCTIVE — Clear Remote Shell.
s1_connect_network
Pro · Destructive
DESTRUCTIVE — Connect to Network.
s1_create_manage_endpoint_tags_add_remove_override
Pro · Destructive
DESTRUCTIVE — Manage endpoint tags: add, remove, override.
s1_create_randomize_uuid
Pro · Destructive
DESTRUCTIVE — Randomize UUID.
s1_create_terminate_remote_shell
Pro · Destructive
DESTRUCTIVE — Terminate Remote Shell.
s1_decommission
Pro · Destructive
DESTRUCTIVE — Decommission.
s1_disable_agent
Pro · Destructive
DESTRUCTIVE — Disable Agent.
s1_disable_network_discovery
Pro · Destructive
DESTRUCTIVE — Disable Network Discovery.
s1_disconnect_network
Pro · Destructive
DESTRUCTIVE — Disconnect from Network.
s1_edit_local_upgrade_downgrade_site_authorization
Pro · Destructive
DESTRUCTIVE — Edit local upgrade/downgrade Site authorization.
s1_enable_agent
Pro · Destructive
DESTRUCTIVE — Enable Agent.
s1_enable_network_discovery
Pro · Destructive
DESTRUCTIVE — Enable Network Discovery.
s1_fetch_files
Pro · Destructive
DESTRUCTIVE — Fetch Files.
s1_fetch_firewall_logs
Pro · Destructive
DESTRUCTIVE — Fetch Firewall Logs.
s1_fetch_firewall_rules
Pro · Destructive
DESTRUCTIVE — Fetch Firewall Rules.
s1_fetch_logs
Pro · Destructive
DESTRUCTIVE — Fetch Logs.
s1_get_applications
Pro · Destructive
DESTRUCTIVE — Get Applications.
s1_initiate_scan
Pro · Destructive
DESTRUCTIVE — Initiate Scan.
s1_mark_up_date
Pro · Destructive
DESTRUCTIVE — Mark as up-to-date.
s1_move_between_sites
Pro · Destructive
DESTRUCTIVE — Move between Sites.
s1_move_console
Pro · Destructive
DESTRUCTIVE — Move to Console.
s1_reject_uninstall
Pro · Destructive
DESTRUCTIVE — Reject uninstall.
s1_reset_local_config
Pro · Destructive
DESTRUCTIVE — Reset Local Config.
s1_reset_passphrase_capability
Pro · Destructive
DESTRUCTIVE — Reset Passphrase Capability.
s1_reset_passphrases
Pro · Destructive
DESTRUCTIVE — Reset Passphrases.
s1_restart
Pro · Destructive
DESTRUCTIVE — Restart.
s1_set_external_id
Pro · Destructive
DESTRUCTIVE — Set External ID.
s1_set_persistent_configuration_overrides
Pro · Destructive
DESTRUCTIVE — Set Persistent Configuration Overrides.
s1_shutdown
Pro · Destructive
DESTRUCTIVE — Shutdown.
s1_start_remote_profiling
Pro · Destructive
DESTRUCTIVE — Start Remote Profiling.
s1_start_remote_shell
Pro · Destructive
DESTRUCTIVE — Start Remote Shell.
s1_stop_remote_profiling
Pro · Destructive
DESTRUCTIVE — Stop Remote Profiling.
s1_uninstall
Pro · Destructive
DESTRUCTIVE — Uninstall.
s1_update_software
Pro · Destructive
DESTRUCTIVE — Update Software.

Endpoints

ToolWhat it does
s1_count_agents
Free · Read-only
Count Agents.
s1_create_access_token
Pro · Destructive
DESTRUCTIVE — Create Access Token.
s1_delete_access_token
Pro · Destructive
DESTRUCTIVE — Delete Access Token.
s1_disable_pna_hyperautomation
Pro · Destructive
DESTRUCTIVE — Disable PNA for Hyperautomation.
s1_enable_agent_pna_hyperautomation
Pro · Destructive
DESTRUCTIVE — Enable Agent PNA for Hyperautomation.
s1_export_agent_logs
Free · Read-only
Export Agent Logs.
s1_get_agents
Free · Read-only
Get Agents.
s1_get_applications_agents
Free · Read-only
Applications.
s1_get_endpoint_tags_count_filters
Free · Read-only
Endpoint tags count by Filters.
s1_get_endpoint_tags_match_filters
Free · Read-only
Get the endpoint tags that match the filters.
s1_get_local_upgrade_downgrade_agent_authorization
Free · Read-only
Get local upgrade/downgrade Agent authorization.
s1_get_passphrase
Free · Read-only
Get Passphrase.
s1_get_processes
Free · Read-only
Processes.
s1_list_access_tokens
Free · Read-only
List Access Tokens.

Network Discovery

ToolWhat it does
s1_change_device_review
Pro · Destructive
DESTRUCTIVE — Change Device Review.
s1_change_device_review_bulk
Pro · Destructive
DESTRUCTIVE — Change Device Review in Bulk.
s1_change_device_tags
Pro · Destructive
DESTRUCTIVE — Change Device Tags.
s1_export_json_raw_data
Free · Read-only
Export JSON Raw Data.
s1_export_network_discovery_data
Free · Read-only
Export Network Discovery Data.
s1_export_unprotected_endpoints_discovery_data
Free · Read-only
Export Unprotected Endpoints Discovery Data.
s1_get_json_raw_data
Free · Read-only
JSON Raw Data.
s1_get_network_discovery_settings
Free · Read-only
Get Network Discovery Settings.
s1_get_network_discovery_table
Free · Read-only
Get Network Discovery Table.
s1_get_unprotected_endpoints_discovery_settings
Free · Read-only
Get Unprotected Endpoints Discovery Settings.
s1_get_unprotected_endpoints_discovery_table
Free · Read-only
Get Unprotected Endpoints Discovery Table.
s1_update_network_discovery_settings
Pro · Destructive
DESTRUCTIVE — Update Network Discovery Settings.
s1_update_unprotected_endpoints_discovery_settings
Pro · Destructive
DESTRUCTIVE — Update Unprotected Endpoints Discovery Settings.

Network Quarantine

ToolWhat it does
s1_add_rule_tags
Pro · Write
Add Rule Tags.
s1_copy_rules_network_quarantine_control
Pro · Destructive
DESTRUCTIVE — Copy Rules.
s1_create_firewall_rule_firewall_control
Pro · Destructive
DESTRUCTIVE — Create Firewall Rule.
s1_delete_rules_network_quarantine_control
Pro · Destructive
DESTRUCTIVE — Delete Rules.
s1_enable_disable_rules_network_quarantine_control
Pro · Destructive
DESTRUCTIVE — Enable/Disable Rules.
s1_export_rules_network_quarantine_control
Free · Read-only
Export Rules.
s1_get_configuration_network_quarantine_control
Free · Read-only
Get Configuration.
s1_get_firewall_rules_firewall_control
Free · Read-only
Get Firewall Rules.
s1_get_protocols
Free · Read-only
Get Protocols.
s1_import_rules
Pro · Destructive
DESTRUCTIVE — Import Rules.
s1_move_rules_network_quarantine_control
Pro · Destructive
DESTRUCTIVE — Move Rules.
s1_remove_rule_tags
Pro · Destructive
DESTRUCTIVE — Remove Rule Tags.
s1_reorder_rules_network_quarantine_control
Pro · Destructive
DESTRUCTIVE — Reorder Rules.
s1_set_location
Pro · Destructive
DESTRUCTIVE — Set Location.
s1_update_configuration_network_quarantine_control
Pro · Destructive
DESTRUCTIVE — Update Configuration.

Tasks

ToolWhat it does
s1_create_task
Pro · Destructive
DESTRUCTIVE — Create Task.
s1_export_maintenance_windows_csv
Free · Read-only
Export Maintenance Windows as CSV.
s1_get_child_scope_task_configuration
Free · Read-only
Get Child Scope Task Configuration.
s1_get_task_configuration
Free · Read-only
Get Task Configuration.
s1_get_task_configuration_flexible_mw
Free · Read-only
Get Task Configuration (Flexible MW).
s1_has_child_scopes
Free · Read-only
Has Child Scopes.
s1_update_task_configuration_flexible_mw
Pro · Destructive
DESTRUCTIVE — Update Task Configuration (Flexible MW).

Threat Intelligence

ToolWhat it does
s1_create_iocs
Pro · Destructive
DESTRUCTIVE — Create IOCs.
s1_create_iocs_stix_bundle
Pro · Destructive
DESTRUCTIVE — Create IOCs from STIX bundle.
s1_create_threat_intelligence_user_config
Pro · Write
Create Threat Intelligence user config.
s1_delete_iocs
Pro · Destructive
DESTRUCTIVE — Delete IOCs.
s1_delete_threat_intelligence_user_config
Pro · Destructive
DESTRUCTIVE — Delete Threat Intelligence user config.
s1_get_threat_intelligence_user_config
Free · Read-only
Get Threat Intelligence user config.

Threats

ToolWhat it does
s1_add_blocklist
Pro · Destructive
DESTRUCTIVE — Add to Blocklist.
s1_add_blocklist_deep_visibility
Pro · Destructive
DESTRUCTIVE — Add to Blocklist (Deep Visibility).
s1_add_exclusions
Pro · Destructive
DESTRUCTIVE — Add to Exclusions.
s1_add_note_multiple
Pro · Write
Add Note to Multiple.
s1_create_updated_threat_incident
Pro · Destructive
DESTRUCTIVE — Updated Threat Incident.
s1_delete_threat_note
Pro · Destructive
DESTRUCTIVE — Delete Threat Note.
s1_disable_engines
Pro · Destructive
DESTRUCTIVE — Disable Engines.
s1_disconnect_container
Pro · Destructive
DESTRUCTIVE — Disconnect Container.
s1_export_mitigation_report
Free · Read-only
Export Mitigation Report.
s1_export_threats
Free · Read-only
Export Threats.
s1_fetch_threat_file
Pro · Destructive
DESTRUCTIVE — Fetch Threat File.
s1_get_events
Free · Read-only
Get Events.
s1_get_exclusion_options
Free · Read-only
Exclusion Options.
s1_get_threat_notes
Free · Read-only
Get Threat Notes.
s1_get_threat_timeline
Free · Read-only
Get Threat Timeline.
s1_get_threats
Free · Read-only
Get Threats.
s1_mark_threat_deep_visibility
Pro · Destructive
DESTRUCTIVE — Mark as Threat (Deep Visibility).
s1_mitigate_alerts
Pro · Destructive
DESTRUCTIVE — Mitigate Alerts.
s1_mitigate_threats
Pro · Destructive
DESTRUCTIVE — Mitigate Threats.
s1_reconnect_container
Pro · Destructive
DESTRUCTIVE — Reconnect Container.
s1_update_threat_analyst_verdict
Pro · Destructive
DESTRUCTIVE — Update Threat Analyst Verdict.
s1_update_threat_external_ticket_id
Pro · Destructive
DESTRUCTIVE — Update Threat External Ticket ID.
s1_update_threat_note
Pro · Write
Update Threat Note.

Accounts and Licensing

ToolWhat it does
s1_create_account
Pro · Destructive
DESTRUCTIVE — Create an account, the MSP-level container above sites.
s1_expire_account
Pro · Destructive
DESTRUCTIVE — Expire an account immediately.
s1_generate_regenerate_uninstall_password
Pro · Destructive
DESTRUCTIVE — Generate a new agent uninstall password for an account, replacing the current one.
s1_get_account
Free · Read-only
Get one account by its id, including its state, expiration date, license usage and the modules it has enabled.
s1_get_accounts
Free · Read-only
List the accounts in the console that match the filter, with their state, expiration and license counts.
s1_get_cloud_inventory_overview
Free · Read-only
Cloud Inventory resource overview.
s1_get_uninstall_password
Free · Read-only
Reveal the current agent uninstall password for an account, in plain text.
s1_get_uninstall_password_metadata
Free · Read-only
Get Uninstall Password Metadata.
s1_reactivate_account
Pro · Destructive
DESTRUCTIVE — Reactivate an expired account.
s1_revert_account_policy
Pro · Destructive
DESTRUCTIVE — Discard the account's own policy and revert it to inherit from the level above.
s1_revoke_uninstall_password
Pro · Destructive
DESTRUCTIVE — Revoke the account's agent uninstall password.
s1_update_account
Pro · Destructive
DESTRUCTIVE — Change an account's fields, which include its license allocation and expiration.
s1_update_sites_add_ons
Pro · Destructive
DESTRUCTIVE — Change which licensed modules are enabled on sites.

Console Settings

ToolWhat it does
s1_clear_pending_emails
Pro · Destructive
DESTRUCTIVE — Cancel every console email that is queued but not yet sent.
s1_create_location
Pro · Destructive
DESTRUCTIVE — Create a console LOCATION.
s1_delete_locations
Pro · Destructive
DESTRUCTIVE — Delete network location definitions.
s1_delete_notification_recipient
Pro · Destructive
DESTRUCTIVE — Remove one notification recipient.
s1_get_ad_fqdns
Free · Read-only
Get AD FQDNs.
s1_get_ad_settings
Free · Read-only
Get AD Settings.
s1_get_locations
Free · Read-only
List the network locations defined for a scope, with the parameters that match an agent to each one.
s1_get_notification_recipients
Free · Read-only
Get Notification Recipients.
s1_get_smtp_settings
Free · Read-only
Get SMTP Settings.
s1_get_sso_service_provider_certificate
Free · Read-only
Get SSO Service Provider Certificate.
s1_get_sso_settings
Free · Read-only
Get SSO Settings.
s1_get_syslog_settings
Free · Read-only
Get Syslog Settings.
s1_get_system_config
Free · Read-only
Get System Config.
s1_get_system_environment
Free · Read-only
System Environment.
s1_get_system_info
Free · Read-only
System Info.
s1_get_system_status
Free · Read-only
System Status.
s1_set_ad_fqdns
Pro · Destructive
DESTRUCTIVE — Replace the Active Directory scope mapping, which decides how directory groups map onto console scopes.
s1_set_ad_settings
Pro · Destructive
DESTRUCTIVE — Replace the console's Active Directory configuration.
s1_set_notification_recipients
Pro · Destructive
DESTRUCTIVE — Replace the list of people who receive console notifications.
s1_set_notification_settings
Pro · Destructive
DESTRUCTIVE — Replace the console's notification settings, which decide which events generate mail and to whom.
s1_set_smtp_settings
Pro · Destructive
DESTRUCTIVE — Replace the console's SMTP configuration.
s1_set_sso_settings
Pro · Destructive
DESTRUCTIVE — Replace the console's SSO configuration.
s1_set_syslog_settings
Pro · Destructive
DESTRUCTIVE — Replace the console's syslog forwarding configuration.
s1_set_system_config
Pro · Destructive
DESTRUCTIVE — Replace the console's system configuration.
s1_test_ad_settings
Pro · Destructive
DESTRUCTIVE — Test AD Settings.
s1_test_smtp_settings
Pro · Destructive
DESTRUCTIVE — Test SMTP Settings.
s1_test_sso_settings
Pro · Destructive
DESTRUCTIVE — Test SSO Settings.
s1_test_syslog_settings
Pro · Destructive
DESTRUCTIVE — Test Syslog Settings.
s1_update_location
Pro · Destructive
DESTRUCTIVE — Edit a console LOCATION.

Graph Explorer

ToolWhat it does
s1_delete_graph_query
Pro · Destructive
DESTRUCTIVE — Delete graph query.
s1_get_asset_query_builder_metadata
Free · Read-only
Get Graph Query Builder Initial Metadata.
s1_get_available_relations
Free · Read-only
Get the available relations.
s1_get_graph_explorer_autocomplete
Free · Read-only
Auto Complete.
s1_get_graph_query_builder_metadata
Free · Read-only
Get Graph Query Builder Initial Metadata.
s1_get_graph_query_builder_options
Free · Read-only
Get Query Builder metadata For Requested Resource Types.
s1_get_graph_query_list
Free · Read-only
List the saved Graph Explorer queries, with the owner and the query definition of each.
s1_get_graph_query_type_counts
Free · Read-only
Get graph query counts by type.
s1_get_graph_recent_query_list
Free · Read-only
Get graph recent query list.
s1_get_graph_services_feature_toggles
Free · Read-only
Get all of the feature toggles for graph services.
s1_get_tag_autocomplete
Free · Read-only
Tag Auto Complete.
s1_query_graph_explorer
Free · Read-only
Query the graph based on query builder filters.
s1_query_graph_explorer_v2
Free · Read-only
Query the graph based on query builder filters.
s1_query_subgraph
Free · Read-only
Query the sub graph of an asset type and id.
s1_save_graph_query
Pro · Write
Save graph query.
s1_update_graph_query
Pro · Write
Update graph query.

Groups and Tags

ToolWhat it does
s1_create_endpoint_tag
Pro · Write
Create a new endpoint tag.
s1_create_group
Pro · Write
Create Group.
s1_create_tag_rule
Pro · Write
Create new tag rule.
s1_create_tags
Pro · Write
Create Tags.
s1_delete_endpoint_tags
Pro · Destructive
DESTRUCTIVE — Delete endpoint tags from Tag Manager.
s1_delete_group
Pro · Destructive
DESTRUCTIVE — Delete an agent group.
s1_delete_tag
Pro · Destructive
DESTRUCTIVE — Delete one asset tag by its id.
s1_delete_tag_rules
Pro · Destructive
DESTRUCTIVE — Delete asset tag rules.
s1_delete_tags
Pro · Destructive
DESTRUCTIVE — Delete asset tags in bulk, by the criteria in the body rather than by a single id.
s1_get_group
Free · Read-only
Get one agent group by its id, including its rank, type, filter definition and the site it belongs to.
s1_get_group_registration_token
Free · Read-only
Get Site registration token by ID.
s1_get_groups
Free · Read-only
List the agent groups that match the filter, with the site each belongs to, its rank, its type (static or dynamic) and its agent count.
s1_get_tag_rules
Free · Read-only
Get all tags rules.
s1_get_tags
Free · Read-only
List the asset tags that match the filter, with the scope of each.
s1_move_agents
Pro · Destructive
DESTRUCTIVE — Move agents into a group by FILTER, not by a list of ids.
s1_regenerate_group_token
Pro · Destructive
DESTRUCTIVE — Regenerate a group's registration token.
s1_revert_group_policy
Pro · Destructive
DESTRUCTIVE — Discard the group's own policy and revert it to inherit from the site.
s1_test_tag_rule_match_count
Free · Read-only
Check how many assets this tag rule matches.
s1_update_endpoint_tag
Pro · Write
Edit an existing tag.
s1_update_group
Pro · Destructive
DESTRUCTIVE — Update Group.
s1_update_group_ranks
Pro · Destructive
DESTRUCTIVE — Reorder group ranks.
s1_update_tag
Pro · Write
Edit Tag.
s1_update_tag_rule
Pro · Write
Update tag rule.

Log Collection

ToolWhat it does
s1_change_activation_status_log_collection_rules
Pro · Destructive
DESTRUCTIVE — Activate or deactivate log collection rules.
s1_create_log_collection_rule
Pro · Write
Create a log collection rule.
s1_delete_log_collection_rules
Pro · Destructive
DESTRUCTIVE — Delete log collection rules.
s1_export_log_collection_rules
Free · Read-only
Export the log collection rules matching the filter.
s1_get_log_collection_agent_type_counts
Free · Read-only
Get Agent type count.
s1_get_log_collection_rules
Free · Read-only
List the log collection rules that match the filter, with the scope, agent type and activation state of each.
s1_get_log_collection_rules_by_agent_type
Free · Read-only
Get Log Collection rules by agent type.
s1_update_log_collection_rule
Pro · Destructive
DESTRUCTIVE — Change a log collection rule.

Policies

ToolWhat it does
s1_get_account_policy
Free · Read-only
Account Policy.
s1_get_global_policy
Free · Read-only
Global Policy.
s1_get_group_policy
Free · Read-only
Group Policy.
s1_get_site_policy
Free · Read-only
Site Policy.
s1_update_account_policy
Pro · Destructive
DESTRUCTIVE — Replace an account's agent policy.
s1_update_global_policy
Pro · Destructive
DESTRUCTIVE — Replace the tenant-wide agent policy.
s1_update_group_policy
Pro · Destructive
DESTRUCTIVE — Replace a group's agent policy.
s1_update_site_policy
Pro · Destructive
DESTRUCTIVE — Replace a site's agent policy.

Reports

ToolWhat it does
s1_create_default_report_task
Pro · Destructive
DESTRUCTIVE — Create a scheduled report task.
s1_delete_default_report_tasks
Pro · Destructive
DESTRUCTIVE — Delete Default Report Tasks.
s1_delete_default_reports
Pro · Destructive
DESTRUCTIVE — Delete Default Reports.
s1_download_default_report
Free · Read-only
Fetch a generated default report by id.
s1_get_default_report_tasks
Free · Read-only
List the report tasks that generate default reports now or on a schedule, including the recipients each task mails its report to.
s1_get_default_reports
Free · Read-only
List the generated default reports that match the filter, with the schedule, insight type, date range and the user who created each one.
s1_get_report_insight_types
Free · Read-only
Get Default Insight Reports.
s1_get_rss_feed
Free · Read-only
S1 RSS Feed.
s1_update_default_report_task
Pro · Destructive
DESTRUCTIVE — Edit a scheduled report task.

Saved Views

ToolWhat it does
s1_delete_filter
Pro · Destructive
DESTRUCTIVE — Delete Filter.
s1_delete_filter_xdr
Pro · Destructive
DESTRUCTIVE — Delete Filter.
s1_get_enriched_filters
Free · Read-only
Filters with Metadata.
s1_get_filters
Free · Read-only
List the saved filters (saved console views) that match the request, with the scope and the criteria each one stores.
s1_get_filters_xdr
Free · Read-only
Get Filters.
s1_save_filter
Pro · Write
Save Filter.
s1_save_filter_xdr
Pro · Write
Save Filter.
s1_update_filter
Pro · Write
Update Filter.
s1_update_filter_xdr
Pro · Write
Update Filter.
s1_upload_csv_filter
Pro · Write
Upload CSV file.

Sites

ToolWhat it does
s1_create_site
Pro · Write
Create a site under an account.
s1_create_site_with_admin
Pro · Destructive
DESTRUCTIVE — Create a site AND its first administrator in one call.
s1_delete_site
Pro · Destructive
DESTRUCTIVE — Delete a site.
s1_expire_site
Pro · Destructive
DESTRUCTIVE — Expire a site immediately.
s1_get_site
Free · Read-only
Get one site by its id, including its state, expiration date, license counts, policy inheritance and the account it belongs to.
s1_get_site_local_upgrade_approved_agents
Free · Read-only
Get a CSV file of local upgrade/downgrade Site authorization data.
s1_get_site_local_upgrade_authorization
Free · Read-only
Get local upgrade/downgrade Site authorization.
s1_get_site_registration_token
Free · Read-only
Get Site registration token by ID.
s1_get_sites
Free · Read-only
List the sites that match the filter, with their state, expiration, license counts and the account each belongs to.
s1_reactivate_site
Pro · Destructive
DESTRUCTIVE — Reactivate an expired site.
s1_regenerate_site_key
Pro · Destructive
DESTRUCTIVE — Regenerate a site's registration token.
s1_revert_site_policy
Pro · Destructive
DESTRUCTIVE — Discard the site's own policy and revert it to inherit from the account.
s1_set_site_local_upgrade_authorization
Pro · Destructive
DESTRUCTIVE — Change which agents in a site are authorized to be upgraded or DOWNGRADED locally, at the endpoint.
s1_update_site
Pro · Destructive
DESTRUCTIVE — Change a site's fields, which include its license allocation, expiration and policy inheritance.
s1_update_sites_bulk
Pro · Destructive
DESTRUCTIVE — Change many sites in one call.

Users and Roles

ToolWhat it does
s1_bulk_delete_service_users
Pro · Destructive
DESTRUCTIVE — Delete every service user matching a FILTER, not a list of ids.
s1_bulk_delete_users
Pro · Destructive
DESTRUCTIVE — Delete every console user matching a FILTER, not a list of ids.
s1_check_remote_shell_permissions
Free · Read-only
Check Remote Shell Permissions.
s1_check_tenant_admin_auth
Free · Read-only
Check Global User.
s1_check_viewer_auth
Free · Read-only
Check Viewer.
s1_create_role
Pro · Destructive
DESTRUCTIVE — Create an RBAC role with a permission set.
s1_create_service_user
Pro · Destructive
DESTRUCTIVE — Create a service user, which is an API-only identity, and mint its API token.
s1_create_user
Pro · Destructive
DESTRUCTIVE — Create a console user with a role and a scope.
s1_delete_role
Pro · Destructive
DESTRUCTIVE — Delete an RBAC role.
s1_delete_service_user
Pro · Destructive
DESTRUCTIVE — Delete a service user.
s1_delete_user
Pro · Destructive
DESTRUCTIVE — Delete a console user.
s1_enable_2fa_app
Pro · Destructive
DESTRUCTIVE — Complete two-factor enrollment for a console user by confirming the app code.
s1_generate_api_token
Pro · Destructive
DESTRUCTIVE — Mint a new API token for a console user.
s1_generate_api_token_service_user
Pro · Destructive
DESTRUCTIVE — Mint a new API token for a service user.
s1_generate_iframe_token
Pro · Destructive
DESTRUCTIVE — Mint a short-lived token that embeds the SentinelOne console in an iframe.
s1_get_current_user
Free · Read-only
Get the console user that owns the API token this connector is using, with their role and scope.
s1_get_new_role_template
Free · Read-only
Get template for new role.
s1_get_role
Free · Read-only
Get one RBAC role by its id, with the full permission list it grants.
s1_get_roles
Free · Read-only
List the RBAC roles defined in the console, with the scope each is defined at and the number of users assigned.
s1_get_service_user
Free · Read-only
Get Service User.
s1_get_service_users
Free · Read-only
List the service users that match the filter, with their scope, role and token expiry.
s1_get_user
Free · Read-only
Get one console user by their id, including role, scope, two-factor state and last login.
s1_get_user_api_token_details
Free · Read-only
API Token by User ID.
s1_list_users
Free · Read-only
List the console users that match the filter, with their role, scope, last login and whether they have verified their email.
s1_request_2fa_app
Pro · Destructive
DESTRUCTIVE — Start two-factor enrollment for a console user, which returns the secret the authenticator app needs.
s1_revoke_api_token
Pro · Destructive
DESTRUCTIVE — Revoke a user's API token.
s1_send_verification_email
Pro · Destructive
DESTRUCTIVE — Send the onboarding verification email to every user matching a FILTER.
s1_update_role
Pro · Destructive
DESTRUCTIVE — Change an RBAC role's permission set.
s1_update_service_user
Pro · Destructive
DESTRUCTIVE — Change a service user's fields, including its role and scope.
s1_update_user
Pro · Destructive
DESTRUCTIVE — Change a console user's fields, which include their role and their scope.
s1_verify_onboarding_email
Pro · Destructive
DESTRUCTIVE — Redeem an onboarding verification token and SET THAT USER'S PASSWORD.

Application Management

ToolWhat it does
s1_get_aggregated_applications_risk
Free · Read-only
Get Aggregated Applications With Risk.
s1_get_app_inventory_endpoints
Free · Read-only
Get App Inventory Endpoints.
s1_get_application_cves
Free · Read-only
Get Application CVEs.
s1_get_application_inventory
Free · Read-only
Get Application Inventory.
s1_get_application_management_settings
Free · Read-only
Get Application Management Settings.
s1_get_applications_risk
Free · Read-only
Get Applications With Risk.
s1_get_cve_data
Free · Read-only
Get CVE data.
s1_get_endpoint_apps
Free · Read-only
Get Endpoint Apps.
s1_get_endpoints_vulnerable_app
Free · Read-only
Get Endpoints For Vulnerable App.
s1_initiate_scan_application_management
Pro · Destructive
DESTRUCTIVE — Initiate scan.
s1_update_application_management_settings
Pro · Destructive
DESTRUCTIVE — Update Application Management Settings.

Device Control

ToolWhat it does
s1_copy_rules
Pro · Destructive
DESTRUCTIVE — Copy Rules.
s1_create_device_control_rule
Pro · Destructive
DESTRUCTIVE — Create Device Control Rule.
s1_delete_rules_device_control
Pro · Destructive
DESTRUCTIVE — Delete Rules.
s1_enable_disable_rules
Pro · Destructive
DESTRUCTIVE — Enable/Disable Rules.
s1_export_rules
Free · Read-only
Export Rules.
s1_get_configuration
Free · Read-only
Get Configuration.
s1_get_device_control_events
Free · Read-only
Get Device Control Events.
s1_get_device_rules
Free · Read-only
Get Device Rules.
s1_move_rules
Pro · Destructive
DESTRUCTIVE — Move rules.
s1_reorder_rules
Pro · Destructive
DESTRUCTIVE — Reorder Rules.
s1_update_configuration
Pro · Destructive
DESTRUCTIVE — Update Configuration.
s1_update_device_rule
Pro · Destructive
DESTRUCTIVE — Update Device Rule.

Exclusions and Blocklist

ToolWhat it does
s1_create_blocklist_item
Pro · Destructive
DESTRUCTIVE — Create Blocklist Item.
s1_create_bulk_unified_exclusion
Pro · Destructive
DESTRUCTIVE — Create Bulk Unified Exclusion.
s1_create_config_override
Pro · Destructive
DESTRUCTIVE — Create Config Override.
s1_create_exclusion
Pro · Destructive
DESTRUCTIVE — Create Exclusion.
s1_create_unified_exclusion
Pro · Destructive
DESTRUCTIVE — Create Unified Exclusion.
s1_delete_blocklist_item
Pro · Destructive
DESTRUCTIVE — Delete Blocklist Item.
s1_delete_config_override
Pro · Destructive
DESTRUCTIVE — Delete Config Override.
s1_delete_config_overrides
Pro · Destructive
DESTRUCTIVE — Delete Config Overrides.
s1_delete_exclusions
Pro · Destructive
DESTRUCTIVE — Delete Exclusions.
s1_delete_exclusions_unified_exclusions
Pro · Destructive
DESTRUCTIVE — Delete Exclusions.
s1_export_unified_exclusions
Free · Read-only
Export Unified Exclusions.
s1_get_blocklist
Free · Read-only
Get Blocklist.
s1_get_blocklist_import_validation_report
Free · Read-only
Get Blocklist Import Validation Report.
s1_get_config_overrides
Free · Read-only
Get Config Overrides.
s1_get_exclusion_actions
Free · Read-only
Get Exclusion Actions.
s1_get_exclusion_import_validation_report
Free · Read-only
Get Exclusion Import Validation Report.
s1_get_exclusions
Free · Read-only
Get Exclusions.
s1_get_exclusions_unified_exclusions
Free · Read-only
Get Exclusions.
s1_import_blocklist_items
Pro · Destructive
DESTRUCTIVE — Import Blocklist Items.
s1_import_exclusions
Pro · Destructive
DESTRUCTIVE — Import Exclusions.
s1_import_unified_exclusions
Pro · Destructive
DESTRUCTIVE — Import Unified Exclusions.
s1_update_blocklist_item
Pro · Destructive
DESTRUCTIVE — Update Blocklist Item.
s1_update_config_override
Pro · Destructive
DESTRUCTIVE — Update Config Override.
s1_update_exclusions
Pro · Destructive
DESTRUCTIVE — Update Exclusions.
s1_update_exclusions_unified_exclusions
Pro · Destructive
DESTRUCTIVE — Update Exclusions.
s1_validate_blocklist_item
Free · Read-only
Validate Blocklist Item.
s1_validate_exclusion_item
Free · Read-only
Validate Exclusion Item.

Firewall Control

ToolWhat it does
s1_add_rule_tags_firewall_control
Pro · Write
Add Rule Tags.
s1_copy_rules_firewall_control
Pro · Destructive
DESTRUCTIVE — Copy Rules.
s1_create_firewall_rule
Pro · Destructive
DESTRUCTIVE — Create Firewall Rule.
s1_delete_rules_firewall_control
Pro · Destructive
DESTRUCTIVE — Delete Rules.
s1_enable_disable_rules_firewall_control
Pro · Destructive
DESTRUCTIVE — Enable/Disable Rules.
s1_export_rules_firewall_control
Free · Read-only
Export Rules.
s1_get_configuration_firewall_control
Free · Read-only
Get Configuration.
s1_get_firewall_rules
Free · Read-only
Get Firewall Rules.
s1_get_protocols_firewall_control
Free · Read-only
Get Protocols.
s1_get_tag_firewall_rules
Free · Read-only
Get Tag Firewall Rules.
s1_import_rules_firewall_control
Pro · Destructive
DESTRUCTIVE — Import Rules.
s1_move_rules_firewall_control
Pro · Destructive
DESTRUCTIVE — Move Rules.
s1_remove_rule_tags_firewall_control
Pro · Destructive
DESTRUCTIVE — Remove Rule Tags.
s1_reorder_rules_firewall_control
Pro · Destructive
DESTRUCTIVE — Reorder Rules.
s1_set_location_firewall_control
Pro · Destructive
DESTRUCTIVE — Set Location.
s1_update_configuration_firewall_control
Pro · Destructive
DESTRUCTIVE — Update Configuration.
s1_update_firewall_rule
Pro · Destructive
DESTRUCTIVE — Update Firewall Rule.

Integrations

ToolWhat it does
s1_activate_workflow_version
Pro · Destructive
DESTRUCTIVE — Activate a workflow version.
s1_batch_export_workflows
Free · Read-only
Batch export workflows.
s1_batch_import_workflows
Pro · Destructive
DESTRUCTIVE — Batch import workflows.
s1_create_estimator_id
Pro · Write
Create Estimator ID.
s1_create_evaluate_expression
Pro · Destructive
DESTRUCTIVE — Evaluate Expression.
s1_create_expression_breakdown
Pro · Destructive
DESTRUCTIVE — Expression Breakdown.
s1_create_onboard_new_vcs_integration
Pro · Destructive
DESTRUCTIVE — Onboard a new VCS integration.
s1_create_provision_persist_mssp_partner_key
Pro · Destructive
DESTRUCTIVE — Provision - Persist MSSP partner key.
s1_create_provision_provision_mssp_partner_admin_user
Pro · Destructive
DESTRUCTIVE — Provision - Provision MSSP partner with admin user.
s1_create_provision_provision_tenant_admin_user
Pro · Destructive
DESTRUCTIVE — Provision - Provision tenant with admin user.
s1_create_register_tunnel_user
Pro · Destructive
DESTRUCTIVE — Register Tunnel User.
s1_create_vcs_cicd_scanner_policy
Pro · Destructive
DESTRUCTIVE — Create a VCS and CICD scanner policy.
s1_deactivate_active_workflow
Pro · Destructive
DESTRUCTIVE — Deactivate The active workflow.
s1_delete_cloud_funnel_rule
Pro · Destructive
DESTRUCTIVE — Delete cloud funnel rule.
s1_delete_mssp_partner_key
Pro · Destructive
DESTRUCTIVE — Deletes MSSP partner key by client ID.
s1_delete_vcs_cicd_scanner_policy
Pro · Destructive
DESTRUCTIVE — Delete a VCS and CICD scanner policy.
s1_delete_vcs_integration_cnapp
Pro · Destructive
DESTRUCTIVE — Delete a VCS integration.
s1_disable_scanning_repositories_vcs_integration
Pro · Destructive
DESTRUCTIVE — Disable scanning for repositories in a VCS integration.
s1_edit_tags_repositories_vcs_integration
Pro · Destructive
DESTRUCTIVE — Edit tags for repositories in a VCS integration.
s1_edit_tags_vcs_integration
Pro · Destructive
DESTRUCTIVE — Edit tags for a VCS integration.
s1_enable_scanning_repositories_vcs_integration
Pro · Destructive
DESTRUCTIVE — Enable scanning for repositories in a VCS integration.
s1_export_cloud_rogue_resources
Free · Read-only
Export cloud rogue resources to csv (default) or json.
s1_fetch_filter_count
Free · Read-only
Fetch filter count.
s1_fetch_repository_tags
Free · Read-only
Fetch repository tags.
s1_get_agent_merged_updates
Free · Read-only
Get Agent Merged Updates.
s1_get_aws_assume_role_external_id
Free · Read-only
Get AWS assume role external ID.
s1_get_cloud_funnel_rule
Free · Read-only
Get cloud funnel rule.
s1_get_cloud_rogue_resources
Free · Read-only
Get cloud rogue resources.
s1_get_devices_get_list_devices_specific_scope
Free · Read-only
Devices - Get list of devices for specific scope.
s1_get_estimate_size_events
Free · Read-only
Get estimate size of events.
s1_get_gateways
Free · Read-only
Get Gateways.
s1_get_incidents_get_list_incidents
Free · Read-only
Incidents - Get list of incidents.
s1_get_max_allowed_priority
Free · Read-only
Get max allowed priority.
s1_get_provision_check_if_tenant_can_be_provisioned
Free · Read-only
Provision - Check if tenant can be provisioned.
s1_get_provision_get_mssp_partner_admin_user
Free · Read-only
Provision - Get MSSP partner with admin user.
s1_get_provision_get_mssp_partner_key
Free · Read-only
Provision - Get MSSP partner key.
s1_get_provision_get_tenant_users
Free · Read-only
Provision - Get tenant with users.
s1_get_vcs_cicd_scanner_policy
Free · Read-only
Get a VCS and CICD scanner policy.
s1_get_workflow_execution_id
Free · Read-only
Get a workflow execution by its ID.
s1_import_workflow
Pro · Destructive
DESTRUCTIVE — Import workflow.
s1_list_vcs_cicd_scanner_policies
Free · Read-only
List VCS and CICD scanner policies.
s1_list_vcs_integration_repositories
Free · Read-only
List VCS integration repositories.
s1_list_vcs_integrations
Free · Read-only
List VCS integrations.
s1_list_workflow_executions
Free · Read-only
List all workflow executions.
s1_list_workflow_versions
Free · Read-only
List workflow versions.
s1_list_workflows
Free · Read-only
List all workflows.
s1_offboard_vcs_integration
Pro · Destructive
DESTRUCTIVE — off-board (delete) a VCS integration.
s1_post_onboarding_cloud_funnel
Pro · Destructive
DESTRUCTIVE — Post onboarding cloud funnel.
s1_trigger_workflow_uses_manual_trigger
Pro · Destructive
DESTRUCTIVE — Trigger a workflow that uses a manual trigger.
s1_update_gateway
Pro · Destructive
DESTRUCTIVE — Update Gateway.
s1_update_gateways
Pro · Destructive
DESTRUCTIVE — Update Gateways.
s1_update_provision_update_mssp_partner_key
Pro · Destructive
DESTRUCTIVE — Provision - Update MSSP partner key.
s1_update_resync_vcs_integration_repositories
Pro · Destructive
DESTRUCTIVE — Resync VCS Integration Repositories.
s1_update_vcs_cicd_scanner_policy
Pro · Destructive
DESTRUCTIVE — Update a VCS and CICD scanner policy.
s1_update_vcs_integration
Pro · Destructive
DESTRUCTIVE — Update a VCS integration.
s1_validate_bucket
Free · Read-only
Validate Bucket.
s1_validate_query
Free · Read-only
Validate Query.

Marketplace

ToolWhat it does
s1_delete_application
Pro · Destructive
DESTRUCTIVE — Delete Application.
s1_enable_disable_application
Pro · Destructive
DESTRUCTIVE — Enable Or Disable Application.
s1_get_application_log
Free · Read-only
Get application log.
s1_get_applications_catalog
Free · Read-only
Get Applications Catalog.
s1_get_configuration_fields
Free · Read-only
Get Configuration Fields.
s1_get_configuration_fields_installed_application
Free · Read-only
Get Configuration Fields For Installed Application.
s1_get_installed_applications
Free · Read-only
Get Installed Applications.
s1_install_applications
Pro · Destructive
DESTRUCTIVE — Install Applications.
s1_update_application_configuration
Pro · Destructive
DESTRUCTIVE — Update Application Configuration.

PowerQuery

ToolWhat it does
s1_create_update_saved_searches
Pro · Write
Create or update saved searches.
s1_delete_query
Pro · Destructive
DESTRUCTIVE — Delete query.
s1_delete_saved_searches
Pro · Destructive
DESTRUCTIVE — Delete saved searches.
s1_get_poll_query
Free · Read-only
Poll query.
s1_launch_query
Free · Read-only
Launch a query.
s1_list_saved_searches
Free · Read-only
List saved searches.

Remote Forensics

ToolWhat it does
s1_check_if_collection_file_exists_given_storyline
Free · Read-only
Check if collection file exists for given storyline.
s1_create_new_collection_profile
Pro · Write
Create new Collection profile.
s1_create_new_destination_profile
Pro · Write
Create new Destination profile.
s1_delete_collection_profiles
Pro · Destructive
DESTRUCTIVE — Delete Collection profiles.
s1_delete_destination_profile_id
Pro · Destructive
DESTRUCTIVE — Delete Destination profile by ID.
s1_delete_multiple_destination_profiles_id
Pro · Destructive
DESTRUCTIVE — Delete multiple Destination profiles by ID.
s1_delete_multiple_scheduled_tasks_id
Pro · Destructive
DESTRUCTIVE — Delete multiple scheduled tasks by ID.
s1_get_available_destination_profiles
Free · Read-only
Get available Destination profiles.
s1_get_available_scheduled_tasks
Free · Read-only
Get available Scheduled Tasks.
s1_get_collection_profile_id
Free · Read-only
Get Collection profile by ID.
s1_get_destination_profile_id
Free · Read-only
Get Destination profile by ID.
s1_get_forensics_collection_file_url
Free · Read-only
Returns collection file download pre-signed url.
s1_get_list_available_collection_profiles
Free · Read-only
Get list of available Collection profiles.
s1_get_list_supported_artifact_types
Free · Read-only
Get list of supported artifact types.
s1_get_results_sent_data_exporter
Free · Read-only
Get results sent to data exporter.
s1_get_return_result_collection_task
Free · Read-only
Return result of collection task.
s1_schedule_forensics_future_run
Pro · Destructive
DESTRUCTIVE — Schedule forensics for future run.
s1_schedule_remote_script_future_run
Pro · Destructive
DESTRUCTIVE — Schedule remote script for future run.
s1_set_profile_default_profile_scope
Pro · Destructive
DESTRUCTIVE — Set profile as default profile of the scope.
s1_start_forensics_collection
Pro · Destructive
DESTRUCTIVE — Start collection of Forensics artifacts according to specified profile.
s1_update_collection_profile_id
Pro · Destructive
DESTRUCTIVE — Update Collection profile by ID.
s1_update_existing_destination_profile
Pro · Destructive
DESTRUCTIVE — Update existing Destination profile.
s1_update_existing_scheduled_task
Pro · Destructive
DESTRUCTIVE — Update existing Scheduled task.

Remote Scripts

ToolWhat it does
s1_approve_decline_pending_execution
Pro · Destructive
DESTRUCTIVE — Approve/decline pending execution.
s1_check_whether_guardrail_applies_execution
Free · Read-only
Check whether guardrail applies to an execution.
s1_delete_remote_script_guardrails_config
Pro · Destructive
DESTRUCTIVE — Deletes a specific guardrails configuration.
s1_delete_scripts
Pro · Destructive
DESTRUCTIVE — Delete Scripts.
s1_get_paginated_pending_executions
Free · Read-only
Get paginated pending executions.
s1_get_remote_script_guardrails_config
Free · Read-only
Gets a guardrails configuration for a given scope.
s1_get_remote_scripts_tasks_status
Free · Read-only
Get Remote Scripts Tasks Status.
s1_get_script_content
Free · Read-only
Get script content.
s1_get_script_results
Free · Read-only
Get Script Results.
s1_get_scripts
Free · Read-only
Get Scripts.
s1_get_upload_limit_package
Free · Read-only
Get upload limit for Package.
s1_run_remote_script
Pro · Destructive
DESTRUCTIVE — Run Remote Script.
s1_update_script
Pro · Destructive
DESTRUCTIVE — Update a Script.
s1_update_script_remote_scripts
Pro · Destructive
DESTRUCTIVE — Update a Script.
s1_upload_new_script
Pro · Destructive
DESTRUCTIVE — Upload New Script.
s1_upsert_remote_script_guardrails_config
Pro · Destructive
DESTRUCTIVE — Updates or inserts (if record does not exist) a guardrails configuration.

Account

ToolWhat it does
s1_count_account_asset_filters
Free · Read-only
Returns the number of Account assets behind each filter value — the counts the console shows beside each facet.
s1_export_account_assets
Free · Read-only
Exports the Account asset class as JSON.
s1_get_account_asset_filter_values
Free · Read-only
Returns matching values for one Account asset filter field — the type-ahead behind the console's filter box.
s1_get_account_asset_text_filters
Free · Read-only
Lists the Account asset fields that a free-text search covers.
s1_list_account_asset_actions
Free · Read-only
Lists the inventory actions available for Account assets, with each action's current status.
s1_list_account_assets
Free · Read-only
Lists the Account asset class of the asset inventory.
s1_run_account_asset_action
Pro · Destructive
DESTRUCTIVE — runs an inventory action against the Account assets your request body selects.
s1_search_account_assets
Free · Read-only
Searches the Account asset class of the asset inventory using the filter criteria in the request body.

AI ML

ToolWhat it does
s1_count_ai_ml_asset_filters
Free · Read-only
Returns the number of AI/ML assets behind each filter value — the counts the console shows beside each facet.
s1_export_ai_ml_assets
Free · Read-only
Exports the AI/ML asset class as JSON.
s1_get_ai_ml_asset_filter_values
Free · Read-only
Returns matching values for one AI/ML asset filter field — the type-ahead behind the console's filter box.
s1_get_ai_ml_asset_text_filters
Free · Read-only
Lists the AI/ML asset fields that a free-text search covers.
s1_list_ai_ml_asset_actions
Free · Read-only
Lists the inventory actions available for AI/ML assets, with each action's current status.
s1_list_ai_ml_assets
Free · Read-only
Lists the AI/ML asset class of the asset inventory.
s1_run_ai_ml_asset_action
Pro · Destructive
DESTRUCTIVE — runs an inventory action against the AI/ML assets your request body selects.
s1_search_ai_ml_assets
Free · Read-only
Searches the AI/ML asset class of the asset inventory using the filter criteria in the request body.

Application Integration

ToolWhat it does
s1_count_application_integration_asset_filters
Free · Read-only
Returns the number of Application Integration assets behind each filter value — the counts the console shows beside each facet.
s1_export_application_integration_assets
Free · Read-only
Exports the Application Integration asset class as JSON.
s1_get_application_integration_asset_filter_values
Free · Read-only
Returns matching values for one Application Integration asset filter field — the type-ahead behind the console's filter box.
s1_get_application_integration_asset_text_filters
Free · Read-only
Lists the Application Integration asset fields that a free-text search covers.
s1_list_application_integration_asset_actions
Free · Read-only
Lists the inventory actions available for Application Integration assets, with each action's current status.
s1_list_application_integration_assets
Free · Read-only
Lists the Application Integration asset class of the asset inventory.
s1_run_application_integration_asset_action
Pro · Destructive
DESTRUCTIVE — runs an inventory action against the Application Integration assets your request body selects.
s1_search_application_integration_assets
Free · Read-only
Searches the Application Integration asset class of the asset inventory using the filter criteria in the request body.

Asset Inventory

ToolWhat it does
s1_export_asset_cloud_tags
Free · Read-only
Exports the cloud provider tags attached to inventory assets as JSON.
s1_export_assets
Free · Read-only
Exports assets across every inventory class as JSON.
s1_get_asset_category_counts
Free · Read-only
Returns the asset inventory categories and the number of assets in each.
s1_get_asset_inventory_counts
Free · Read-only
Returns the asset counts behind each inventory menu item — the numbers the console shows next to each asset class.
s1_get_asset_subcategory_counts
Free · Read-only
Returns the per-subcategory asset counts within the inventory categories.
s1_list_any_asset_actions
Free · Read-only
Lists the inventory actions available for the assets your request body selects, across every asset class, with each action's current status.
s1_list_assets
Free · Read-only
Lists assets across EVERY class of the asset inventory.
s1_run_any_asset_action
Pro · Destructive
DESTRUCTIVE — runs an inventory action against assets in ANY class, selected by the filter in the request body.
s1_search_assets
Free · Read-only
Searches assets across EVERY class of the asset inventory using the filter criteria in the request body.

Cloud Application

ToolWhat it does
s1_count_cloud_application_asset_filters
Free · Read-only
Returns the number of Cloud Application assets behind each filter value — the counts the console shows beside each facet.
s1_export_cloud_application_assets
Free · Read-only
Exports the Cloud Application asset class as JSON.
s1_get_cloud_application_asset_filter_values
Free · Read-only
Returns matching values for one Cloud Application asset filter field — the type-ahead behind the console's filter box.
s1_get_cloud_application_asset_text_filters
Free · Read-only
Lists the Cloud Application asset fields that a free-text search covers.
s1_list_cloud_application_asset_actions
Free · Read-only
Lists the inventory actions available for Cloud Application assets, with each action's current status.
s1_list_cloud_application_assets
Free · Read-only
Lists the Cloud Application asset class of the asset inventory.
s1_run_cloud_application_asset_action
Pro · Destructive
DESTRUCTIVE — runs an inventory action against the Cloud Application assets your request body selects.
s1_search_cloud_application_assets
Free · Read-only
Searches the Cloud Application asset class of the asset inventory using the filter criteria in the request body.

Cloud Surface

ToolWhat it does
s1_count_cloud_surface_asset_filters
Free · Read-only
Returns the number of Cloud Surface assets behind each filter value — the counts the console shows beside each facet.
s1_export_cloud_surface_assets
Free · Read-only
Exports the Cloud Surface asset class as JSON.
s1_get_cloud_surface_asset_filter_values
Free · Read-only
Returns matching values for one Cloud Surface asset filter field — the type-ahead behind the console's filter box.
s1_get_cloud_surface_asset_text_filters
Free · Read-only
Lists the Cloud Surface asset fields that a free-text search covers.
s1_list_cloud_surface_asset_actions
Free · Read-only
Lists the inventory actions available for Cloud Surface assets, with each action's current status.
s1_list_cloud_surface_assets
Free · Read-only
Lists the Cloud Surface asset class of the asset inventory.
s1_run_cloud_surface_asset_action
Pro · Destructive
DESTRUCTIVE — runs an inventory action against the Cloud Surface assets your request body selects.

Container

ToolWhat it does
s1_count_container_asset_filters
Free · Read-only
Returns the number of Container assets behind each filter value — the counts the console shows beside each facet.
s1_export_container_assets
Free · Read-only
Exports the Container asset class as JSON.
s1_get_container_asset_filter_values
Free · Read-only
Returns matching values for one Container asset filter field — the type-ahead behind the console's filter box.
s1_get_container_asset_text_filters
Free · Read-only
Lists the Container asset fields that a free-text search covers.
s1_list_container_asset_actions
Free · Read-only
Lists the inventory actions available for Container assets, with each action's current status.
s1_list_container_assets
Free · Read-only
Lists the Container asset class of the asset inventory.
s1_run_container_asset_action
Pro · Destructive
DESTRUCTIVE — runs an inventory action against the Container assets your request body selects.
s1_search_container_assets
Free · Read-only
Searches the Container asset class of the asset inventory using the filter criteria in the request body.

Data Analysis

ToolWhat it does
s1_count_data_analysis_asset_filters
Free · Read-only
Returns the number of Data Analysis assets behind each filter value — the counts the console shows beside each facet.
s1_export_data_analysis_assets
Free · Read-only
Exports the Data Analysis asset class as JSON.
s1_get_data_analysis_asset_filter_values
Free · Read-only
Returns matching values for one Data Analysis asset filter field — the type-ahead behind the console's filter box.
s1_get_data_analysis_asset_text_filters
Free · Read-only
Lists the Data Analysis asset fields that a free-text search covers.
s1_list_data_analysis_asset_actions
Free · Read-only
Lists the inventory actions available for Data Analysis assets, with each action's current status.
s1_list_data_analysis_assets
Free · Read-only
Lists the Data Analysis asset class of the asset inventory.
s1_run_data_analysis_asset_action
Pro · Destructive
DESTRUCTIVE — runs an inventory action against the Data Analysis assets your request body selects.
s1_search_data_analysis_assets
Free · Read-only
Searches the Data Analysis asset class of the asset inventory using the filter criteria in the request body.

Data Store

ToolWhat it does
s1_count_data_store_asset_filters
Free · Read-only
Returns the number of Data Store assets behind each filter value — the counts the console shows beside each facet.
s1_export_data_store_assets
Free · Read-only
Exports the Data Store asset class as JSON.
s1_get_data_store_asset_filter_values
Free · Read-only
Returns matching values for one Data Store asset filter field — the type-ahead behind the console's filter box.
s1_get_data_store_asset_text_filters
Free · Read-only
Lists the Data Store asset fields that a free-text search covers.
s1_list_data_store_asset_actions
Free · Read-only
Lists the inventory actions available for Data Store assets, with each action's current status.
s1_list_data_store_assets
Free · Read-only
Lists the Data Store asset class of the asset inventory.
s1_run_data_store_asset_action
Pro · Destructive
DESTRUCTIVE — runs an inventory action against the Data Store assets your request body selects.
s1_search_data_store_assets
Free · Read-only
Searches the Data Store asset class of the asset inventory using the filter criteria in the request body.

Developer Tool

ToolWhat it does
s1_count_developer_tool_asset_filters
Free · Read-only
Returns the number of Developer Tool assets behind each filter value — the counts the console shows beside each facet.
s1_export_developer_tool_assets
Free · Read-only
Exports the Developer Tool asset class as JSON.
s1_get_developer_tool_asset_filter_values
Free · Read-only
Returns matching values for one Developer Tool asset filter field — the type-ahead behind the console's filter box.
s1_get_developer_tool_asset_text_filters
Free · Read-only
Lists the Developer Tool asset fields that a free-text search covers.
s1_list_developer_tool_asset_actions
Free · Read-only
Lists the inventory actions available for Developer Tool assets, with each action's current status.
s1_list_developer_tool_assets
Free · Read-only
Lists the Developer Tool asset class of the asset inventory.
s1_run_developer_tool_asset_action
Pro · Destructive
DESTRUCTIVE — runs an inventory action against the Developer Tool assets your request body selects.
s1_search_developer_tool_assets
Free · Read-only
Searches the Developer Tool asset class of the asset inventory using the filter criteria in the request body.

Device

ToolWhat it does
s1_count_device_asset_filters
Free · Read-only
Returns the number of Device assets behind each filter value — the counts the console shows beside each facet.
s1_export_device_assets
Free · Read-only
Exports the Device asset class as JSON.
s1_get_device_asset_filter_values
Free · Read-only
Returns matching values for one Device asset filter field — the type-ahead behind the console's filter box.
s1_get_device_asset_text_filters
Free · Read-only
Lists the Device asset fields that a free-text search covers.
s1_list_device_asset_actions
Free · Read-only
Lists the inventory actions available for Device assets, with each action's current status.
s1_list_device_assets
Free · Read-only
Lists the Device asset class of the asset inventory.
s1_run_device_asset_action
Pro · Destructive
DESTRUCTIVE — runs an inventory action against the Device assets your request body selects.
s1_search_device_assets
Free · Read-only
Searches the Device asset class of the asset inventory using the filter criteria in the request body.

Endpoint Surface

ToolWhat it does
s1_count_endpoint_surface_asset_filters
Free · Read-only
Returns the number of Endpoint Surface assets behind each filter value — the counts the console shows beside each facet.
s1_export_endpoint_surface_assets
Free · Read-only
Exports the Endpoint Surface asset class as JSON.
s1_get_endpoint_surface_asset_filter_values
Free · Read-only
Returns matching values for one Endpoint Surface asset filter field — the type-ahead behind the console's filter box.
s1_get_endpoint_surface_asset_text_filters
Free · Read-only
Lists the Endpoint Surface asset fields that a free-text search covers.
s1_list_endpoint_surface_asset_actions
Free · Read-only
Lists the inventory actions available for Endpoint Surface assets, with each action's current status.
s1_list_endpoint_surface_assets
Free · Read-only
Lists the Endpoint Surface asset class of the asset inventory.
s1_run_endpoint_surface_asset_action
Pro · Destructive
DESTRUCTIVE — runs an inventory action against the Endpoint Surface assets your request body selects.
s1_search_endpoint_surface_assets
Free · Read-only
Searches the Endpoint Surface asset class of the asset inventory using the filter criteria in the request body.

Filters

ToolWhat it does
s1_count_asset_filters
Free · Read-only
Returns the number of assets behind each inventory filter value, across every asset class — the counts the console shows beside each facet.
s1_get_asset_filter_values
Free · Read-only
Returns matching values for one inventory filter field across every asset class — the type-ahead behind the console's filter box.
s1_get_asset_text_filters
Free · Read-only
Lists the inventory fields that a free-text search covers, across every asset class.
s1_upload_asset_filter_csv
Pro · Write
Uploads a CSV of asset identifiers and stores it as a reusable inventory filter, returning the csvFilterId that the inventory list tools accept.

Function

ToolWhat it does
s1_count_function_asset_filters
Free · Read-only
Returns the number of Function assets behind each filter value — the counts the console shows beside each facet.
s1_export_function_assets
Free · Read-only
Exports the Function asset class as JSON.
s1_get_function_asset_filter_values
Free · Read-only
Returns matching values for one Function asset filter field — the type-ahead behind the console's filter box.
s1_get_function_asset_text_filters
Free · Read-only
Lists the Function asset fields that a free-text search covers.
s1_list_function_asset_actions
Free · Read-only
Lists the inventory actions available for Function assets, with each action's current status.
s1_list_function_assets
Free · Read-only
Lists the Function asset class of the asset inventory.
s1_run_function_asset_action
Pro · Destructive
DESTRUCTIVE — runs an inventory action against the Function assets your request body selects.
s1_search_function_assets
Free · Read-only
Searches the Function asset class of the asset inventory using the filter criteria in the request body.

Governance

ToolWhat it does
s1_count_governance_asset_filters
Free · Read-only
Returns the number of Governance assets behind each filter value — the counts the console shows beside each facet.
s1_export_governance_assets
Free · Read-only
Exports the Governance asset class as JSON.
s1_get_governance_asset_filter_values
Free · Read-only
Returns matching values for one Governance asset filter field — the type-ahead behind the console's filter box.
s1_get_governance_asset_text_filters
Free · Read-only
Lists the Governance asset fields that a free-text search covers.
s1_list_governance_asset_actions
Free · Read-only
Lists the inventory actions available for Governance assets, with each action's current status.
s1_list_governance_assets
Free · Read-only
Lists the Governance asset class of the asset inventory.
s1_run_governance_asset_action
Pro · Destructive
DESTRUCTIVE — runs an inventory action against the Governance assets your request body selects.
s1_search_governance_assets
Free · Read-only
Searches the Governance asset class of the asset inventory using the filter criteria in the request body.

Identity

ToolWhat it does
s1_count_identity_asset_filters
Free · Read-only
Returns the number of Identity assets behind each filter value — the counts the console shows beside each facet.
s1_export_identity_assets
Free · Read-only
Exports the Identity asset class as JSON.
s1_get_identity_asset_filter_values
Free · Read-only
Returns matching values for one Identity asset filter field — the type-ahead behind the console's filter box.
s1_get_identity_asset_text_filters
Free · Read-only
Lists the Identity asset fields that a free-text search covers.
s1_list_identity_asset_actions
Free · Read-only
Lists the inventory actions available for Identity assets, with each action's current status.
s1_list_identity_assets
Free · Read-only
Lists the Identity asset class of the asset inventory.
s1_run_identity_asset_action
Pro · Destructive
DESTRUCTIVE — runs an inventory action against the Identity assets your request body selects.
s1_search_identity_assets
Free · Read-only
Searches the Identity asset class of the asset inventory using the filter criteria in the request body.

Identity Surface

ToolWhat it does
s1_count_identity_surface_asset_filters
Free · Read-only
Returns the number of Identity Surface assets behind each filter value — the counts the console shows beside each facet.
s1_export_identity_surface_assets
Free · Read-only
Exports the Identity Surface asset class as JSON.
s1_get_identity_surface_asset_filter_values
Free · Read-only
Returns matching values for one Identity Surface asset filter field — the type-ahead behind the console's filter box.
s1_get_identity_surface_asset_text_filters
Free · Read-only
Lists the Identity Surface asset fields that a free-text search covers.
s1_list_identity_surface_asset_actions
Free · Read-only
Lists the inventory actions available for Identity Surface assets, with each action's current status.
s1_list_identity_surface_assets
Free · Read-only
Lists the Identity Surface asset class of the asset inventory.
s1_run_identity_surface_asset_action
Pro · Destructive
DESTRUCTIVE — runs an inventory action against the Identity Surface assets your request body selects.

Network

ToolWhat it does
s1_count_network_asset_filters
Free · Read-only
Returns the number of Network assets behind each filter value — the counts the console shows beside each facet.
s1_export_network_assets
Free · Read-only
Exports the Network asset class as JSON.
s1_get_network_asset_filter_values
Free · Read-only
Returns matching values for one Network asset filter field — the type-ahead behind the console's filter box.
s1_get_network_asset_text_filters
Free · Read-only
Lists the Network asset fields that a free-text search covers.
s1_list_network_asset_actions
Free · Read-only
Lists the inventory actions available for Network assets, with each action's current status.
s1_list_network_assets
Free · Read-only
Lists the Network asset class of the asset inventory.
s1_run_network_asset_action
Pro · Destructive
DESTRUCTIVE — runs an inventory action against the Network assets your request body selects.
s1_search_network_assets
Free · Read-only
Searches the Network asset class of the asset inventory using the filter criteria in the request body.

Network Discovery Surface

ToolWhat it does
s1_count_network_discovery_surface_asset_filters
Free · Read-only
Returns the number of Network Discovery Surface assets behind each filter value — the counts the console shows beside each facet.
s1_export_network_discovery_surface_assets
Free · Read-only
Exports the Network Discovery Surface asset class as JSON.
s1_get_network_discovery_surface_asset_filter_values
Free · Read-only
Returns matching values for one Network Discovery Surface asset filter field — the type-ahead behind the console's filter box.
s1_get_network_discovery_surface_asset_text_filters
Free · Read-only
Lists the Network Discovery Surface asset fields that a free-text search covers.
s1_list_network_discovery_surface_asset_actions
Free · Read-only
Lists the inventory actions available for Network Discovery Surface assets, with each action's current status.
s1_list_network_discovery_surface_assets
Free · Read-only
Lists the Network Discovery Surface asset class of the asset inventory.
s1_run_network_discovery_surface_asset_action
Pro · Destructive
DESTRUCTIVE — runs an inventory action against the Network Discovery Surface assets your request body selects.

Notes

ToolWhat it does
s1_delete_asset_note
Pro · Destructive
DESTRUCTIVE — permanently deletes the note attached to an inventory asset.
s1_save_asset_note
Pro · Write
Creates or updates the free-text note attached to an inventory asset.

Security Posture

ToolWhat it does
s1_acknowledge_ad_exposures
Pro · Destructive
DESTRUCTIVE — sets the acknowledged status on Active Directory exposures.
s1_get_ad_affected_objects
Free · Read-only
Returns the Active Directory objects affected by the exposures your request body selects — the users, computers and groups behind a finding.
s1_get_ad_assessment_status
Free · Read-only
Returns the status of the Active Directory security assessment for the account — whether an assessment has run, and where the current one stands.
s1_get_ad_exposures
Free · Read-only
Returns the Active Directory exposures that Ranger AD found, filtered by the criteria in the request body.
s1_set_skipped_ad_exposures
Pro · Destructive
DESTRUCTIVE — SETS THE WHOLE LIST of Active Directory exposures to skip.
s1_trigger_ad_assessment
Pro · Destructive
DESTRUCTIVE — starts an Active Directory assessment run now.

Server

ToolWhat it does
s1_count_server_asset_filters
Free · Read-only
Returns the number of Server assets behind each filter value — the counts the console shows beside each facet.
s1_export_server_assets
Free · Read-only
Exports the Server asset class as JSON.
s1_get_server_asset_filter_values
Free · Read-only
Returns matching values for one Server asset filter field — the type-ahead behind the console's filter box.
s1_get_server_asset_text_filters
Free · Read-only
Lists the Server asset fields that a free-text search covers.
s1_list_server_asset_actions
Free · Read-only
Lists the inventory actions available for Server assets, with each action's current status.
s1_list_server_assets
Free · Read-only
Lists the Server asset class of the asset inventory.
s1_run_server_asset_action
Pro · Destructive
DESTRUCTIVE — runs an inventory action against the Server assets your request body selects.
s1_search_server_assets
Free · Read-only
Searches the Server asset class of the asset inventory using the filter criteria in the request body.

Storage

ToolWhat it does
s1_count_storage_asset_filters
Free · Read-only
Returns the number of Storage assets behind each filter value — the counts the console shows beside each facet.
s1_export_storage_assets
Free · Read-only
Exports the Storage asset class as JSON.
s1_get_storage_asset_filter_values
Free · Read-only
Returns matching values for one Storage asset filter field — the type-ahead behind the console's filter box.
s1_get_storage_asset_text_filters
Free · Read-only
Lists the Storage asset fields that a free-text search covers.
s1_list_storage_asset_actions
Free · Read-only
Lists the inventory actions available for Storage assets, with each action's current status.
s1_list_storage_assets
Free · Read-only
Lists the Storage asset class of the asset inventory.
s1_run_storage_asset_action
Pro · Destructive
DESTRUCTIVE — runs an inventory action against the Storage assets your request body selects.
s1_search_storage_assets
Free · Read-only
Searches the Storage asset class of the asset inventory using the filter criteria in the request body.

Tags

ToolWhat it does
s1_count_asset_tag_filters
Free · Read-only
Returns the asset counts behind each tag filter value — how many assets carry each tag.
s1_count_assets_by_tag
Free · Read-only
Returns the number of assets carrying each tag id in the request body.
s1_get_tags_for_assets
Free · Read-only
Returns the tags attached to each asset id in the request body.
s1_list_asset_tags
Free · Read-only
Lists the distinct SentinelOne tags in use across the asset inventory.

Unified Actions

ToolWhat it does
s1_get_agent_ids_for_asset_action
Free · Read-only
Returns the SentinelOne agent ids for the assets your request body selects, so a unified action can be aimed at them.
s1_list_unified_asset_actions
Free · Read-only
Lists the unified actions available for a given asset or entity type.
s1_run_unified_asset_action
Pro · Destructive
DESTRUCTIVE — runs a unified action against the assets and entities your request body selects.

Workstation

ToolWhat it does
s1_count_workstation_asset_filters
Free · Read-only
Returns the number of Workstation assets behind each filter value — the counts the console shows beside each facet.
s1_export_workstation_assets
Free · Read-only
Exports the Workstation asset class as JSON.
s1_get_workstation_asset_filter_values
Free · Read-only
Returns matching values for one Workstation asset filter field — the type-ahead behind the console's filter box.
s1_get_workstation_asset_text_filters
Free · Read-only
Lists the Workstation asset fields that a free-text search covers.
s1_list_workstation_asset_actions
Free · Read-only
Lists the inventory actions available for Workstation assets, with each action's current status.
s1_list_workstation_assets
Free · Read-only
Lists the Workstation asset class of the asset inventory.
s1_run_workstation_asset_action
Pro · Destructive
DESTRUCTIVE — runs an inventory action against the Workstation assets your request body selects.
s1_search_workstation_assets
Free · Read-only
Searches the Workstation asset class of the asset inventory using the filter criteria in the request body.