The joint solution improves detection, triage and research with additional information on possible threats and contextual indicators
SentinelOne, provider of a cybersecurity platform with autonomous response capabilities, presented an integration with Mandiant to improve threat detection, triage, research and response processes. SentinelOne's Singularity
The number of attacks and the different methodologies adopted continue to increase and, even for IT and security professionals, it is becoming increasingly difficult to manage their cybersecurity processes. Many organizations are turning to Extended Detection and Response (XDR) platforms that gather data from multiple security and IT devices into a new cybersecurity platform where the data is correlated and managed, providing a more complete read on an organization's security posture. The integration between SentinelOne and Mandiant strengthens Singularity
“Our XDR portfolio offers customers the flexibility and choice they deserve when implementing an XDR strategy, and our business model supports, rather than competes with, our partners,” he said Raj Rajamani, Chief Product Officer at SentinelOne. “By leveraging the synergies between Singularity Storyline and Mandiant Threat Intelligence, every alert on the platform is handled even more quickly with root cause analysis and action options.” With SentinelOne identifying threats and Mandiant providing the background and information needed for rapid triage and recovery, enterprises can defend themselves against the new threat landscape.”
Thanks to the joint solution, suspicious activities and alerts are automatically enriched with Mandiant threat intelligence. These may include identification of the threat as malware or not, risk levels, hacker profiles, indicators (IOCs), and links to more in-depth information within the Mandiant Threat Advantage platform. Analysts can access a dashboard from Mandiant, saving valuable time when triaging incidents. Key benefits of the SentinelOne-Mandiant integration include:
- Automatic attack triage: SentinelOne interventions are automatically enriched with Mandiant Threat Intelligence context and intelligence.
- Optimizing threat management: Query and analyze IOC indicators on emerging threats within SentinelOne's Singularity.
- Accelerated detection and response: autonomous identification and correction of threats thanks to the Indicators of Compromise provided by Mandiant.
- No-code simplicity: combine the best solutions in the industry without the need for complex configurations or processes.
The integration will be available by Q4 2022 through SentinelOne's Singularity Marketplace.






