Myrmex connects on demand and reads (and acts) in real time — nothing from SentinelOne is stored on the Myrmex side.
What Myrmex Can Do
Threats & alerts
Read SentinelOne threats live and triage them in Alerts.
Endpoint inventory
Read managed agents and their status on demand.
Investigate with AI
Let Hydra query SentinelOne to explain detections.
Guided response
Propose isolate and quarantine actions, always with your approval.
Before You Start
- A SentinelOne account that can generate API tokens — a service user is recommended.
- Your SentinelOne management console host.
- A Collector that can reach the console over outbound HTTPS.
Step 1 — Create the Credential in SentinelOne
1
Create a service user (recommended)
In the console, go to Settings → Users → Service Users and create a new service user scoped to the right account, site, or group, with a role that has the access Myrmex needs (Viewer for read; higher for response actions).
2
Or use your profile
Alternatively, open My User → Options → Generate API Token.
3
Copy the token
Copy the API token now — it’s shown only once. Note your console host (for example
usea1-016.sentinelone.net).