EDR / XDR integration
Automate SentinelOne Singularity EDR / XDR with plain language
Read SentinelOne agents, threats and applications, and disconnect an infected agent from the network.
What you can do
SentinelOne Singularity — Management Console API v2.1
- List agents with health and infection state
- Read threats and mitigation status
- Disconnect an agent from the network
Connection: header authentication against https://example.sentinelone.net. Credentials are encrypted at rest, or prompted per action if you prefer never to store them.
Example
Ask in plain English
Prompt: “Isolate the laptop with the latest critical detection in SentinelOne Singularity”
Result: VernacSecure SuperBot™ reads recent detections, confirms the device and isolates it, with a full audit entry.
Read actions
- Fetch agents — Lists managed agents.
- Fetch threats — Lists detected threats.
- Fetch installed applications — Lists application inventory.
Write actions
- Disconnect agent — Disconnects the named agent from the network.