S

Get Threats

v1Verified
sentinelone.get_threats
securitygeneral

Lists active threats on SentinelOne-managed endpoints filtered by severity, status, and site. Returns threat classification and file details.

Technical Specs

External Calls

https://management.sentinelone.net/web/api/v2.1/threats

Data Classification

general

MFA Timeout

—

Enforcement

Rust / fail-closed

Usage in Manifest

Add this snippet to your agent manifest file to enable this tool.

{
  "tools": [
    {
      "name": "sentinelone.get_threats",
      "version": "1"
    }
  ]
}

Used By

6

6 agents currently use this tool

All calls are logged to the tamper evident audit chain

Trust & Security

Ed25519 signed descriptor
Rust enforcement, fail-closed
Every call logged to tamper evident chain
—
MFA not required

Add to Agent

Use this tool in your agent. Sign in to add it to a new or existing agent.

Via CLI

agentsight tool add \
  --name sentinelone.get_threats \
  --version 1