ThreatBook TDP + SentinelOne
Joint Solution Brief
Bridge Network Detection with Endpoint Response
Network traffic can reveal suspicious destinations, abnormal internal activity, and potential command-and-control behavior, but it may not identify the endpoint process responsible. ThreatBook TDP integrates with SentinelOne to combine network evidence with related endpoint process context, helping security teams investigate and contain network-detected threats with greater confidence.
- Enrich TDP network alerts with related SentinelOne endpoint process context.
- Investigate suspicious connections using process, command-line, file-path, signature, and parent-process information.
- Isolate or release associated endpoints through SentinelOne from existing TDP workflows, helping security teams respond more efficiently.
What We Do with SentinelOne
ThreatBook TDP syncs endpoint assets from SentinelOne and precisely associates them with network alerts via the SentinelOne Agent UUID. When a security analyst investigates suspicious network activity, TDP retrieves related endpoint process context on demand to enrich the alert and support investigation. After malicious activity is confirmed, an authorized security analyst can isolate the associated endpoint through SentinelOne from within TDP and release it after remediation.
Customer Benefits
- Extend visibility into endpoint assets, helping security teams gain a more complete view of network-related entities.
- Correlate hosts, timestamps, network indicators, and endpoint events in TDP to help analysts complete evidence correlation and investigation faster.
- Combine network and endpoint evidence to confirm threats and make containment decisions faster and with greater confidence.
- Improve response traceability with endpoint integration logs and audit records in TDP, supporting post-incident review.