SentinelOne Schema#
graph LR
S1Account -- RESOURCE --> S1Agent
S1Account -- RESOURCE --> S1AppFinding
S1Account -- RESOURCE --> S1Application
S1Account -- RESOURCE --> S1ApplicationVersion
S1Agent -- HAS_INSTALLED --> S1ApplicationVersion
S1AppFinding -- AFFECTS --> S1Agent
S1AppFinding -- AFFECTS --> S1ApplicationVersion
S1Application -- VERSION --> S1ApplicationVersion
S1Account#
A top-level SentinelOne account.
Ontology Mapping: This node uses the ontology label
Tenant.
Properties#
Ontology-generated fields are shown in italics.
Field |
Index |
Description |
|---|---|---|
id |
Yes |
SentinelOne account ID. |
firstseen |
Timestamp when a sync job first created this node. |
|
lastupdated |
Yes |
Timestamp of the last sync that observed this node. |
account_type |
SentinelOne account type. |
|
active_agents |
Number of active agents in the account. |
|
created_at |
Account creation timestamp. |
|
expiration |
Account expiration timestamp. |
|
name |
Yes |
SentinelOne account name. |
number_of_sites |
Number of sites in the account. |
|
state |
Current account state. |
|
_ont_name |
Yes |
Normalized field sourced from |
_ont_source |
Module that populated this node’s ontology fields. |
|
_ont_status |
Yes |
Normalized field sourced from |
Relationships#
(:S1Account)-[:RESOURCE]->(:S1Agent): Links a SentinelOne account to one of its agents.(:S1Account)-[:RESOURCE]->(:S1AppFinding): Links a SentinelOne account to one of its application findings.(:S1Account)-[:RESOURCE]->(:S1Application): Links a SentinelOne account to an application in its inventory.(:S1Account)-[:RESOURCE]->(:S1ApplicationVersion): Links a SentinelOne account to an application version in its inventory.
S1Agent#
A SentinelOne agent installed on an endpoint device.
Ontology Projection:
S1Agentcontributes data to canonicalDevicenodes.
Properties#
Field |
Index |
Description |
|---|---|---|
id |
Yes |
SentinelOne agent ID. |
firstseen |
Timestamp when a sync job first created this node. |
|
lastupdated |
Yes |
Timestamp of the last sync that observed this node. |
computer_name |
Yes |
Endpoint computer name. |
domain |
Domain joined by the endpoint. |
|
firewall_enabled |
Whether the endpoint firewall is enabled. |
|
last_active |
Timestamp of the agent’s last activity. |
|
last_successful_scan |
Timestamp of the agent’s last successful scan. |
|
local_ips |
Local IP addresses reported for the endpoint. |
|
os_name |
Endpoint operating system name. |
|
os_revision |
Endpoint operating system revision. |
|
public_ip |
Yes |
Public IP address reported for the endpoint. |
scan_status |
Status of the agent’s latest scan. |
|
serial_number |
Yes |
Endpoint serial number. |
uuid |
Yes |
SentinelOne agent UUID. |
Relationships#
(:Device)-[:OBSERVED_AS]->(:S1Agent): Links a canonical device to its SentinelOne agent, matched on hostname when no serial number is available. Links a canonical device to its SentinelOne agent, matched on serial number.(:S1Account)-[:RESOURCE]->(:S1Agent): Links a SentinelOne account to one of its agents.(:S1Agent)-[:HAS_INSTALLED]->(:S1ApplicationVersion): Links an agent to an application version installed on its endpoint.Properties:
Field
Description
installationpath
File system path where the application version is installed.
installeddatetime
Timestamp when the application version was installed.
(:S1AppFinding)-[:AFFECTS]->(:S1Agent): Links a finding to the endpoint agent it affects.
S1AppFinding#
A vulnerability finding for software on a SentinelOne endpoint.
Ontology Mapping: This node uses the ontology label
CVE.
Additional Labels: This node also uses
Risk,S1Finding.
Additional Label Definitions:
Risk: A node participating in the shared Risk graph interface.
S1Finding: A sentinelone node participating in the shared S1Finding graph interface.
Properties#
Ontology-generated fields are shown in italics.
Field |
Index |
Description |
|---|---|---|
id |
Yes |
SentinelOne application vulnerability finding ID. |
firstseen |
Timestamp when a sync job first created this node. |
|
lastupdated |
Yes |
Timestamp of the last sync that observed this node. |
cve_id |
Yes |
CVE identifier associated with the finding. |
days_detected |
Number of days since the vulnerability was detected. |
|
detection_date |
Vulnerability detection timestamp. |
|
last_scan_date |
Timestamp of the latest vulnerability scan. |
|
last_scan_result |
Result of the latest vulnerability scan. |
|
mark_type_description |
Description of the mark applied to the finding. |
|
marked_by |
User who marked the finding. |
|
marked_date |
Timestamp when the finding was marked. |
|
mitigation_status |
Current mitigation status. |
|
mitigation_status_change_time |
Timestamp of the latest mitigation status change. |
|
mitigation_status_changed_by |
User who last changed the mitigation status. |
|
mitigation_status_reason |
Reason for the mitigation status. |
|
reason |
Reason recorded for the finding. |
|
remediation_level |
Required remediation level. |
|
report_confidence |
Confidence level of the finding report. |
|
risk_score |
SentinelOne risk score. |
|
severity |
Finding severity. |
|
status |
Current finding status. |
|
_ont_base_severity |
Yes |
Normalized field sourced from |
_ont_cve_id |
Yes |
Normalized field sourced from |
_ont_source |
Module that populated this node’s ontology fields. |
Relationships#
(:S1Account)-[:RESOURCE]->(:S1AppFinding): Links a SentinelOne account to one of its application findings.(:S1AppFinding)-[:AFFECTS]->(:Device): Links a SentinelOne finding to the canonical device it affects.(:S1AppFinding)-[:AFFECTS]->(:S1Agent): Links a finding to the endpoint agent it affects.(:S1AppFinding)-[:AFFECTS]->(:S1ApplicationVersion): Links a finding to the application version it affects.(:S1AppFinding)-[:LINKED_TO]->(:CVE): Links a SentinelOne finding to its generic CVE definition.
S1Application#
An application observed in SentinelOne inventory.
Properties#
Field |
Index |
Description |
|---|---|---|
id |
Yes |
Normalized vendor and application name. |
firstseen |
Timestamp when a sync job first created this node. |
|
lastupdated |
Yes |
Timestamp of the last sync that observed this node. |
name |
Application name. |
|
vendor |
Application vendor. |
Relationships#
(:S1Account)-[:RESOURCE]->(:S1Application): Links a SentinelOne account to an application in its inventory.(:S1Application)-[:VERSION]->(:S1ApplicationVersion): Links an application to one of its observed versions.
S1ApplicationVersion#
A specific application version observed by SentinelOne.
Properties#
Field |
Index |
Description |
|---|---|---|
id |
Yes |
Normalized vendor, application name, and version. |
firstseen |
Timestamp when a sync job first created this node. |
|
lastupdated |
Yes |
Timestamp of the last sync that observed this node. |
application_name |
Application name. |
|
application_vendor |
Application vendor. |
|
version |
Application version. |
Relationships#
(:S1Account)-[:RESOURCE]->(:S1ApplicationVersion): Links a SentinelOne account to an application version in its inventory.(:S1Agent)-[:HAS_INSTALLED]->(:S1ApplicationVersion): Links an agent to an application version installed on its endpoint.Properties:
Field
Description
installationpath
File system path where the application version is installed.
installeddatetime
Timestamp when the application version was installed.
(:S1AppFinding)-[:AFFECTS]->(:S1ApplicationVersion): Links a finding to the application version it affects.(:S1Application)-[:VERSION]->(:S1ApplicationVersion): Links an application to one of its observed versions.