All integrations
SentinelOne VM logo
// Data Integration · Vulnerability Management

Cracken + SentinelOne VM

SentinelOne Vulnerability Management reads CVEs from inside the endpoint, off the application inventory its Singularity agent keeps. Cracken comes at those endpoints across the network. It proves which of the flaws an attacker can reach.

Get started
// 01

Connecting SentinelOne VM

Connect with

A SentinelOne API token and your management console base URL

Cadence

Syncs on a schedule — every 6 hours by default, and the agent can force a fresh sync mid-operation

Requires

The hosted connection service enabled on your deployment — always on for Cracken-hosted workspaces

// 02

What Cracken gets from SentinelOne VM

  • Vulnerability findings with severity (critical, high, medium, low, info) and state (new, active, re-opened, fixed)

  • cve list with cvss_base_score, cvss_vector and cvss_version

  • device — hostnames, ipv4s, tags — of the endpoint carrying the finding, landed as a Device node linked to the Finding

  • port, protocol and service where SentinelOne supplies them

  • first_seen, last_seen, updated_at and state_updated_at

  • solution, patchable, category and vulnerability_url

  • vendor_id, vendor_severity and vendor_scan_id

// 03

What SentinelOne VM does not do

Trigger Scan does not start a SentinelOne scan — it posts an on-demand sync job to the hosted connection service to re-pull findings, and takes nothing but optional tags. There is no write path back into SentinelOne, and unlike the SentinelOne EDR integration this one is not filterable by host or user: its only filters are severity, state, CVE, resource ID and resource type.

// 04

How Cracken uses SentinelOne VM

  1. 01

    Connect SentinelOne VM

  2. 02

    Sync the endpoint findings

  3. 03

    Attack the endpoints in scope

  4. 04

    Confirm it connected

// 05

Frequently asked questions

Does Cracken need to install anything on my endpoints?

No; Cracken reads SentinelOne Vulnerability Management findings over the SentinelOne API with your console URL and token, adding no agent of its own.

Is SentinelOne VM the same as connecting SentinelOne for endpoint detection?

No; SentinelOne VM supplies vulnerability findings Cracken syncs and tries to exploit, while the separate endpoint detection integration supplies alerts Cracken reads on demand.

“…we've been continuously validating … the efficacy of Cracken with our own pen tests, like external pen test findings. Just being sure that we could recreate those with Cracken. It's been going good so far…”

Cybersecurity Engineer · test-and-measurement manufacturer

Attack with real SentinelOne VM context.

See how Cracken works what SentinelOne VM already knows into attack paths it proves end to end.