Who is this for? Workspace Admins or Security Engineers who manage a workspace that uses SentinelOne Singularity. This guide walks you through creating two SentinelOne Service Users, configuring both modules in ContraForce, and verifying that threats flow end-to-end.
Before You Begin
What These Modules Do
SentinelOne integrates with ContraForce through two separate modules:Detection Module
Threat ingestion and investigation
- Polls the SentinelOne Threats API for new threats
- Classifies them as ContraForce Incidents or Detections
- Round-trips status changes and analyst notes back to SentinelOne
- Records incident ownership in ContraForce (not written back to SentinelOne)
Response Module
Gamebook response actions
- Powers Contain and Lift Containment Gamebooks (Network Quarantine)
- Powers On-Demand Scan Gamebooks
- Required for any Gamebook that acts on a SentinelOne-managed endpoint
Incident ownership is tracked in ContraForce, not in SentinelOne. A SentinelOne threat has no owner or assignee property, and analysts working through a service provider rarely hold an account in the customer’s SentinelOne tenant. Assigning an owner in ContraForce therefore records the assignment in ContraForce, where every user who can see the incident can see who owns it. The SentinelOne console will continue to show the threat with no assignee.Status changes and analyst notes are unaffected — those still round-trip to SentinelOne. Unlike the CrowdStrike module, there is no option to mirror ownership to the vendor, because SentinelOne has no field to write it to.
Prerequisites
1
SentinelOne Singularity subscription
An active SentinelOne Singularity subscription with endpoint agents deployed and reporting to the management console.
2
SentinelOne admin access
Access to Settings → Users → Service Users in the SentinelOne console. Creating Service Users typically requires the SentinelOne Admin role at the scope you plan to integrate.
3
ContraForce workspace
A ContraForce workspace created for the tenant, with your account assigned the Workspace Admin role.
4
Your SentinelOne Management Console URL
Identify the full URL of your SentinelOne management console (for example,
https://yourtenant.sentinelone.net). You will enter this as the Endpoint when configuring the Detection module.Scope of Access
SentinelOne scopes roles by Global → Account → Site → Group. For most integrations, set the scope of each Service User to Site and pick the specific sites you want ContraForce to monitor. Use Account only if ContraForce should cover every site in the account.Step 1 — Create the Detection Service User in SentinelOne
- In the SentinelOne console, navigate to Settings → Users → Service Users
- Click Actions → Create New Service User
- Set Name to
ContraForce Detection - Set Description to
ContraForce threat ingestion and status writeback - Set Scope of access to Site (pick the sites ContraForce will monitor) or Account if all sites are in scope
- Assign the built-in role SOC
- Set an expiration date for the API token — SentinelOne supports up to 1 year. Pick a date that fits your rotation policy
- Click Create
If your organization doesn’t use the built-in SOC role, you can create a custom role with the following permissions instead: Threats (View, Modify), Threat Notes (View, Add, Edit, Delete), and Activity (View).
Step 2 — Create the Response Service User in SentinelOne
Repeat the process for a second Service User that ContraForce will use for Gamebook response actions.- In Settings → Users → Service Users, click Actions → Create New Service User
- Set Name to
ContraForce Response - Set Description to
ContraForce Gamebook response actions - Set Scope of access to match the Detection Service User
- Assign the built-in role IR Team
- Set an expiration date and click Create
If your organization doesn’t use the built-in IR Team role, you can create a custom role with the Detection permissions above plus Endpoints / Agents (View, Disconnect, Reconnect, Initiate Scan).
Step 3 — Configure the SentinelOne Detection Module in ContraForce
- In the ContraForce portal, navigate to Workspaces → your workspace → Modules
- Locate the SentinelOne Detection card and click Configure
- Fill in the following fields:
- Click Test Connection to verify the credentials reach SentinelOne and have the required permissions
- Click Configure and Save
Step 4 — Configure the SentinelOne Response Module in ContraForce
- On the same Modules page, locate the SentinelOne Response card and click Configure
- Fill in the following fields:
- Click Test Connection and then Configure and Save
Step 5 — Verify End-to-End
1
Wait for the first poll cycle
The Detection module polls SentinelOne on a short interval. New threats appear in ContraForce within a few minutes of being generated in SentinelOne.
2
Check the Command Dashboard
Navigate to the Command Dashboard. SentinelOne threats should appear alongside incidents from other sources.
3
Open an incident
Click into a SentinelOne-sourced incident and verify that the Entities and Timeline tabs are populated with threat data.
4
Try a Gamebook (optional)
If the Response module is configured, open a SentinelOne incident where the affected entity is an agent and confirm that Contain, Lift Containment, and On-Demand Scan Gamebook actions are available.
What Each Module Unlocks
You can configure the Detection module without the Response module if you don’t need Gamebook response actions for SentinelOne endpoints. Configuring only the Response module without Detection is not a supported configuration — you’d have no incidents for the Gamebooks to run on.
Troubleshooting
Rotating an API Token
SentinelOne API tokens expire (up to 1 year). Plan to rotate before expiration.- In SentinelOne, navigate to Settings → Users → Service Users
- Open the affected Service User (Detection or Response)
- Click Actions → Regenerate API Token
- Copy the new token immediately — it is only shown once
- In ContraForce, reopen the affected module (Detection or Response)
- Paste the new token into API Token and click Configure and Save
- Click Test Connection to verify
Related Documentation
What are Gamebooks?
Learn how Gamebook response actions work
Incident Management
Triage and resolve incidents in ContraForce
Entity Insights
Explore investigation context for an incident’s entities
Roles and Permissions
Detailed role reference for ContraForce users
Questions about connecting SentinelOne to ContraForce? Contact us at support@contraforce.com.