ThreatBook TDP + SentinelOne

Joint Solution Brief

Bridge Network Detection with Endpoint Response

Network traffic can reveal suspicious destinations, abnormal internal activity, and potential command-and-control behavior, but it may not identify the endpoint process responsible. ThreatBook TDP integrates with SentinelOne to combine network evidence with related endpoint process context, helping security teams investigate and contain network-detected threats with greater confidence.

    • Enrich TDP network alerts with related SentinelOne endpoint process context.
    • Investigate suspicious connections using process, command-line, file-path, signature, and parent-process information.
    • Isolate or release associated endpoints through SentinelOne from existing TDP workflows, helping security teams respond more efficiently.

What We Do with SentinelOne

ThreatBook TDP syncs endpoint assets from SentinelOne and precisely associates them with network alerts via the SentinelOne Agent UUID. When a security analyst investigates suspicious network activity, TDP retrieves related endpoint process context on demand to enrich the alert and support investigation. After malicious activity is confirmed, an authorized security analyst can isolate the associated endpoint through SentinelOne from within TDP and release it after remediation.

SentinelOnexTDP

Customer Benefits

  • Extend visibility into endpoint assets, helping security teams gain a more complete view of network-related entities.
  • Correlate hosts, timestamps, network indicators, and endpoint events in TDP to help analysts complete evidence correlation and investigation faster.
  • Combine network and endpoint evidence to confirm threats and make containment decisions faster and with greater confidence.
  • Improve response traceability with endpoint integration logs and audit records in TDP, supporting post-incident review.

About SentinelOne

SentinelOne delivers an AI-powered cybersecurity platform for prevention, detection, response, and threat hunting across endpoint, cloud, and identity environments.