Technical Specs
External Calls
https://management.sentinelone.net/web/api/v2.1/threatsData Classification
generalMFA Timeout
—Enforcement
Rust / fail-closedsentinelone.get_threatsLists active threats on SentinelOne-managed endpoints filtered by severity, status, and site. Returns threat classification and file details.
External Calls
https://management.sentinelone.net/web/api/v2.1/threatsData Classification
generalMFA Timeout
—Enforcement
Rust / fail-closedAdd this snippet to your agent manifest file to enable this tool.
{
"tools": [
{
"name": "sentinelone.get_threats",
"version": "1"
}
]
}6 agents currently use this tool
All calls are logged to the tamper evident audit chain
Use this tool in your agent. Sign in to add it to a new or existing agent.
Via CLI
agentsight tool add \
--name sentinelone.get_threats \
--version 1