• Last Updated
    Jun 2, 2026
  • Version
    2.0.1
  • Compatibility
    ThreatQ Versions >= 6.13.0
  • SentinelOne Action Bundle

    ThreatQuotient

    Overview

    The SentinelOne Action Bundle integrates ThreatQ with the SentinelOne Singularity platform, enabling analysts to operationalize threat intelligence and automate response actions directly from ThreatQ. Through this integration, users can manage hash-based restrictions and exclusions, perform threat mitigation actions, and export indicators of compromise (IOCs) to SentinelOne Threat Intelligence, helping to accelerate detection and response workflows while strengthening endpoint protection.

    The bundle supports the management of SHA-1 and SHA-256 hashes, threat mitigation activities, and the export of supported indicators, including file hashes, IP addresses, domains, and URLs, to SentinelOne. By combining ThreatQ intelligence with SentinelOne enforcement capabilities, organizations can more effectively investigate, enrich, and respond to threats across their security ecosystem.

    Note: Configuration information and credentials must be obtained from the SentinelOne platform. These actions are designed to support both automated workflows and large-scale operational deployments.

    The SentinelOne Action Bundle provides the following actions:

    • SentinelOne Blacklist or Whitelist – Adds SHA-1 and SHA-256 hashes to SentinelOne restrictions (blacklist) or exclusions (whitelist).
    • SentinelOne Mitigate Threats – Executes mitigation actions against threats managed by SentinelOne.
    • SentinelOne Delete Hashes – Removes SHA-1 and SHA-256 hashes from SentinelOne restrictions or exclusions.
    • SentinelOne Threat Intelligence - IOC Export – Exports supported indicators from ThreatQ to the SentinelOne Threat Intelligence database.

    The action bundle is compatible with the following indicator types:

    • FQDN
    • File Path
    • IP Address
    • IPv6 Address
    • MD5
    • SHA-1
    • SHA-256
    • URL

    All actions return enriched indicator data and any associated attributes available from SentinelOne.

    Note: This action is intended for use with ThreatQ TDR Orchestrator (TQO). An active TQO license is required for this feature.

    Copyright © 2026, ThreatQuotient, Inc. All Rights Reserved. Privacy Policy