惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

大猫的无限游戏
大猫的无限游戏
阮一峰的网络日志
阮一峰的网络日志
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
WordPress大学
WordPress大学
博客园 - 叶小钗
Hugging Face - Blog
Hugging Face - Blog
博客园 - 司徒正美
Last Week in AI
Last Week in AI
罗磊的独立博客
量子位
Jina AI
Jina AI
T
Tailwind CSS Blog
Apple Machine Learning Research
Apple Machine Learning Research
IT之家
IT之家
美团技术团队
雷峰网
雷峰网
爱范儿
爱范儿
S
SegmentFault 最新的问题
小众软件
小众软件
月光博客
月光博客
酷 壳 – CoolShell
酷 壳 – CoolShell
人人都是产品经理
人人都是产品经理
The Cloudflare Blog
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报

Datadog | The Monitor blog

Introducing our open source AI-native SAST Instrument and monitor Boomi integration flows with OpenTelemetry and Datadog Not all index scans are equal: How we cut query latency by over 99% Platform engineering metrics: What to measure and what to ignore Integrate Recorded Future threat intelligence with Datadog Cloud SIEM CI/CD security: threat modeling using a MITRE-style threat matrix CI/CD security: How to secure your GitHub ecosystem Ingress NGINX is EOL: A practical guide for migrating to Kubernetes Gateway API Operating agentic AI with Amazon Bedrock AgentCore and Datadog LLM Observability: Lessons from NTT DATA Introducing the Datadog Code Security MCP Capture and analyze custom heatmaps in Session Replay Understand session replays faster with AI summaries and smart chapters Monitor ClickHouse query performance with Datadog Database Monitoring How we designed empathetic alert sounds for on-call engineers Search and act across Datadog to resolve issues faster with Bits Assistant Measure the business impact of every product change with Datadog Experiments Analyzing round trip query latency Configuring JavaScript caches for better performance Introducing Bits AI Dev Agent for Code Security Datadog achieves ISO 42001 certification for responsible AI Monitor Nutanix clusters, hosts, and VMs with Datadog Monitor Juniper Mist in Datadog A new Host Map for modern infrastructure Annotate traces to improve LLM quality with Datadog LLM Observability What’s new in Cloud SIEM: AI-powered investigations, enhanced threat intelligence, and scalable security operations Explore Kubernetes with native OpenTelemetry data Monitor Oracle Fusion Cloud Applications with Datadog Announcing the Datadog Terraform provider v4.0.0 Scaling Kubernetes workloads on custom metrics How to design cloud environments for AI-powered threat analysis
Monitor your SentinelOne logs and alerts with Datadog Clo...
Vera Chan, Jason Hunsberger · 2024-10-02 · via Datadog | The Monitor blog

Endpoints, whether physical devices or cloud resources, are critical targets for potential cyberattacks. SentinelOne is an endpoint detection and response (EDR) solution that provides real-time detection of and response to endpoint threats. Using both static and behavioral detections, SentinelOne Singularity Endpoint helps protect against a range of threats, including malware, zero-day exploits, advanced persistent threats, and more.

In this post, we’ll look at how you can use Datadog Cloud SIEM to get full security visibility into your SentinelOne activity logs, threat detections, and more. With Datadog’s built-in threat detection rules and centralized dashboards, you can easily monitor and surface suspicious activity that SentinelOne detects in your environment in order to stay on top of potential attacks to your endpoints and prioritize remediation.

Centralize alerts, threats, and telemetry from SentinelOne Singularity

In order to quickly begin monitoring your SentinelOne telemetry with Datadog Cloud SIEM, you can use the SentinelOne content pack. The content pack provides a centralized place to enable and configure Datadog’s SentinelOne integration, deploy out-of-the-box (OOTB) detection rules, and access the customizable dashboard.

Get started quickly with Datadog’s Cloud SIEM content pack for SentinelOne
Get started quickly with Datadog’s Cloud SIEM content pack for SentinelOne

Once you set up the integration, alert, threat, and activity logs from your SentinelOne environment will appear in Datadog. Additionally, by enabling Cloud Funnel Streaming in SentinelOne, you can collect SentinelOne Cloud Funnel telemetry alongside this log data. Cloud Funnel telemetry consists of raw, high-volume endpoint data, including detailed activity logs, behavioral patterns, threat detections, and other security-related events. This granular, real-time data captures every potential threat indicator, providing deeper insights into endpoint behavior. By forwarding telemetry through Cloud Funnel to Datadog, organizations can perform real-time analysis, long-term investigations, threat hunting, and custom detection development.

Detect Threats with detection rules

You can only act on security threats as fast as you’re alerted to them. Datadog continuously scans your SentinelOne events as it ingests and processes them. You can use custom security reference data to enrich them further with additional business-specific context. Built-in detection rules—that are mapped to the MITRE ATT&CK® framework—automatically look for specific threat indicators and stream any generated security signals in a unified explorer, helping to streamline security investigations and threat detection. In addition to generating signals from any alerts and detected threats from SentinelOne, Datadog’s OOTB detection rules look for behavior such as:

OOTB detection rules look for potential threats in your SentinelOne environment

If Datadog detects any of these actions, it automatically generates a security signal that includes additional context around the issue as well as actions and steps to take next. These rules help security teams identify key attack stages, from endpoint threats and credential theft to data extraction and destruction tactics. By monitoring for these specific behaviors, organizations can prevent lateral movement, privilege escalation, and data destruction, while responding quickly to threats like ransomware or directory service compromises.

Visualize logs and alert activity with dashboards

Datadog’s OOTB SentinelOne dashboard visualizes ingested log data so that you can easily track threats over time by confidence level, helping you identify patterns or escalation in threat severity. Additionally, you can track threats across your infrastructure, pinpointing them by computer name and examining a real-time threat log stream for detailed event analysis.

Track threat trends across your environment with the OOTB dashboard for SentinelOne

The dashboard also visualizes Cloud SIEM security signals so that you can understand your environment’s security posture at a glance. Seamlessly pivot to relevant security signals in order to better understand where you need to focus remediation efforts.

Use the OOTB SentinelOne dashboard to visualize Cloud SIEM security signal trends

For deeper context, the SentinelOne process context section displays detailed data on parent processes, process command-line activity, file activity, and even DNS activity, offering rich insights into how a threat is interacting with your systems. This level of granular visibility into process behavior makes it easier to trace back to the root cause of a threat and take targeted action.

Get deeper visibility into endpoint security with Datadog Cloud SIEM

With Datadog Cloud SIEM and the SentinelOne integration, organizations can monitor, triage, and respond to threats across both endpoints and cloud environments from a unified platform. This integration ensures seamless monitoring, enabling security teams to respond more effectively to evolving threats and maintain a stronger security posture. If you’re already a Datadog customer, see our documentation and start exploring our SentinelOne content pack now. If you’re not a customer, you can get started today with a 14-day free trial.