Skip to main content
Connect SentinelOne so Myrmex can read its threats and alerts, endpoint inventory, and help you triage and respond. Myrmex queries the SentinelOne management console API in real time through a Collector.
Myrmex connects on demand and reads (and acts) in real time — nothing from SentinelOne is stored on the Myrmex side.

What Myrmex Can Do

Threats & alerts

Read SentinelOne threats live and triage them in Alerts.

Endpoint inventory

Read managed agents and their status on demand.

Investigate with AI

Let Hydra query SentinelOne to explain detections.

Guided response

Propose isolate and quarantine actions, always with your approval.

Before You Start

  • A SentinelOne account that can generate API tokens — a service user is recommended.
  • Your SentinelOne management console host.
  • A Collector that can reach the console over outbound HTTPS.

Step 1 — Create the Credential in SentinelOne

1

Create a service user (recommended)

In the console, go to Settings → Users → Service Users and create a new service user scoped to the right account, site, or group, with a role that has the access Myrmex needs (Viewer for read; higher for response actions).
2

Or use your profile

Alternatively, open My User → Options → Generate API Token.
3

Copy the token

Copy the API token now — it’s shown only once. Note your console host (for example usea1-016.sentinelone.net).

Step 2 — Add the Integration in Myrmex

From the Directory, choose Add Integration → SentinelOne, then fill in:

Connect

Click Connect to validate the token. SentinelOne then appears under Environment → Integrations, and you can triage its threats — queried live — in Alerts.