SentinelOne

Receive malware alerts and files from a SentinelOne tenant, with a choice about whether each endpoint becomes its own asset in Stairwell.

This integration connects Stairwell to a SentinelOne tenant. Once configured, Stairwell receives malware alerts and file objects from S1, and those files get the same treatment as anything else it holds: verdicts, variant discovery, rule matching, and prevalence.

There is one configuration choice on this page that matters more than the rest, and it is the asset mode. Get it wrong and you can still see the files, but you lose the ability to say which machine they were on.

What do I need before I start?

  • A SentinelOne organization tenant URL, for example stairwell.sentinelone.com.
  • An active S1 API key with the necessary permissions.
  • The Binary Vault Malware feature enabled in your SentinelOne environment.

That last one is the requirement people miss. Without Binary Vault, S1 has alerts to tell Stairwell about but no files to hand over.

How do I configure it?

  1. Select the settings icon in Stairwell.
  2. Open the Managed environments tab.
  3. Find the environment you are configuring, select (...) under Actions, and choose Manage integrations.
  4. Choose Add new SentinelOne integration.
  5. Provide the Base URI, your S1 organization tenant URL, and the API Key.

Then choose an asset mode, which is the next section, and select Save.

Which asset mode should I choose?

Leave the box unchecked. That is multi-asset mode, and it is the recommended setting.

The checkbox controls whether SentinelOne's endpoints become distinct assets in Stairwell or collapse into one.

Multi-asset mode, box unchecked. Each unique S1 agent becomes its own Stairwell asset, and files are mapped to the machine they came from. It uses the stable computer name from SentinelOne as the identifier, so you get exactly one Stairwell asset per computer rather than duplicates accumulating over time.

Single asset mode, box checked. Every file and alert from every S1 endpoint is attributed to one asset, named for the integration. Choose this only if you genuinely do not need per-machine tracking.

The reason multi-asset is the default recommendation is that most of what makes Stairwell useful runs through the asset. Sightings tie a file to a machine at a time, Run-to-Ground works outward from the assets that held a file, and prevalence counts how many of your assets have seen something. In single-asset mode all three answer "the SentinelOne integration", which is true and useless. Scoping an incident to a set of machines is the thing you will want on the worst day, and it is decided here on a quiet one.

What does "send variant analysis results" do?

Check Send variant analysis results for alerts and Stairwell posts its analysis back to the SentinelOne console for the corresponding alert.

Worth having if your team works primarily in the S1 console, because it puts Stairwell's view of a file where the alert already is rather than requiring a second window.

When does the configuration take effect?

On new events only. Changing the asset mode, or any other setting, affects incoming alerts and files from that point forward and does not reprocess or re-attribute what Stairwell already holds.

So if you start in single-asset mode and switch later, the earlier files stay attributed to the single asset. That is the practical reason to decide the mode before you turn the integration on rather than after.

Where do I get help?

[email protected].

What should I read next?

  • Assets, for why the asset mode decision matters as much as it does.
  • Integrations, for what else is available and the forwarder coverage question.
  • Variants, for what happens to the files once they arrive.

Did this page help you?