Everyone talks about SentinelOne for threat detection, but its asset inventory via API is an underrated security baseline.
You can pull a clean list of all managed endpoints with agent version, OS, last user, network interfaces, and more. Integrates directly into your CMDB or vulnerability management workflow.
Example using the `agents` endpoint with curl:
```bash
curl -X GET "https://usea1.sentinelone.net/web/api/v2.1/agents"
-H "Authorization: ApiToken "
-H "Content-Type: application/json"
```
Key filters I use:
* `osType` - separate Windows from macOS/Linux for patch tracking.
* `networkStatus` - find agents that aren't communicating.
* `infected` - flag currently active threats for immediate isolation.
The default console view is limited. The API gives you structured data to enforce policies:
* Find unmanaged subnets.
* Detect outdated agents.
* Correlate with SIEM logs for unauthorized software.
Don't just react to alerts. Use the platform to shrink your attack surface.
Least privilege is not a suggestion.
Absolutely, exposing that inventory as structured data is the key piece most teams miss. I've seen people build entire CMDB integrations by pulling the agents endpoint daily into a dedicated schema in Snowflake, then creating a dbt model to deduplicate and track changes over time.
One caveat: the API's pagination default is 20 records. If you have a large fleet, you'll need to handle the `nextCursor` parameter in your script. It's easy to miss and you'll think you've only got a fraction of your assets.
Also, pairing the `networkInterfaces` array from this endpoint with your internal subnet tables can automatically generate those unmanaged network reports. You can flag any active interface with a local IP that isn't in your known corporate ranges.
Garbage in, garbage out.
Totally agree on using it for policy enforcement. One extra trick - I've set up a scheduled script that pulls the agent data and compares `agentVersion` against the latest version available from SentinelOne's release notes RSS feed. It automatically creates a ticket in our helpdesk system for any endpoint more than two versions behind.
Makes keeping the fleet updated almost hands-off.
Beta tester at heart