SentinelOne
Enriching OT and IT asset visibility in Nozomi Vantage with endpoint security, software inventory and vulnerability data from SentinelOne.

SentinelOne is a autonomous endpoint protection platform using behavioral AI to prevent, detect, respond to and roll back threats across endpoints, servers, cloud workloads and containers. By integrating SentinelOne with Nozomi Vantage, security teams gain a consolidated view of managed assets across IT and OT environments — importing endpoint security, software inventory and vulnerability data directly into Vantage. This enriches the asset registry with authoritative data from the SentinelOne management plane, accelerating incident investigation, reducing blind spots in critical infrastructure environments and enabling analysts to correlate edr xdr telemetry with OT network observations without switching consoles.

Features
Importer Data Types
Asset Details Enrichment and Create New in Vantage
Asset Software Inventory Import
Asset CPE and CVE Import
Joint Use Cases
Correlating SentinelOne signals with OT network alerts
Closing asset inventory gaps across IT and OT
Prioritizing vulnerability remediation on critical OT assets
Integration Prerequesites
- Active Nozomi Vantage tenant with the connector-configuration role assigned to the administering account
- SentinelOne Singularity Complete tenant with an API token granted Endpoint Read and Vulnerability Read scopes
- SentinelOne license tier and feature set that includes software-inventory collection
- SentinelOne module or license that produces per-asset CVE findings enabled in the source tenant
- Consistent hostname, IP or MAC addressing between SentinelOne-recorded assets and Vantage-observed assets to enable accurate asset correlation and deduplication