将 SentinelOne Singularity Operations Center 与 Google SecOps 集成

本文档解释了如何配置 SentinelOne Singularity Operations Center 并将其与 Google Security Operations 集成。

使用场景

SentinelOne 奇点运营中心集成功能可帮助您执行以下操作:

  • 集中分类和调查:从 SentinelOne Singularity Operations Center 访问统一的警报、资产、指标和可观察对象,以简化分析师的工作流程。
  • 更新警报状态和判决:直接从 Google SecOps 以编程方式更新警报详细信息、负责人和判决。
  • 添加分析师备注: 将案例评论和备注同步回 SentinelOne Singularity Operations Center 警报。

准备工作

要验证 Google SecOps 和您的 SentinelOne Singularity Operations Center 实例之间的连接,您必须提供有效的 API 令牌。

您可以在 SentinelOne 管理控制台中生成个人 API 令牌。

如需详细了解如何生成和管理令牌,请访问 SentinelOne 客户门户

集成参数

SentinelOne Singularity Operations Center 集成需要以下参数:

参数
API Root 必需

SentinelOne Singularity Operations Center 实例的 API 根目录。

API Token 必需

SentinelOne Singularity Operations Center 实例的 API 令牌。

Verify SSL 必需

如果选中,该集成会在连接到 SentinelOne Singularity Operations Center 时验证 SSL 证书。此选项将会默认选中。

有关如何在 Google SecOps 中配置集成的说明,请参阅 配置集成

操作

有关操作的更多信息,请参阅响应来自您的工作台的待处理操作执行手动操作

添加提醒评论

使用 添加警报注释 操作,向 SentinelOne Singularity Operations Center 中的警报添加注释。

此操作不适用于 Google SecOps 实体。

操作输入

添加提醒评论操作需要以下参数:

参数
Alert ID 必需

指定需要更新的提醒的 ID。

Comment 必需

请为提示信息添加注释。

操作输出

添加警告注释 操作提供以下输出:

操作输出类型 可用性
案例墙附件 不可用
案例墙链接 不可用
“支持请求墙”表格 不可用
丰富化表 不可用
JSON 结果 不可用
脚本结果 可用
脚本结果

下表列出了使用 添加警告注释 操作时脚本结果输出的值:

脚本结果名称
is_success truefalse
操作输出消息

添加提醒评论操作会输出以下消息:

输出消息 消息说明
Successfully added comment to the alert with ID ALERT_ID in SentinelOne Singularity Operations Center. 操作成功。
Error executing action "Add Alert Comment". Reason: ERROR_REASON 操作失败。检查与服务器的连接、输入参数或凭据。
Error executing action "Add Alert Comment". Reason: alert with ID ALERT_ID wasn't found in SentinelOne Singularity Operations Center. Please check the spelling. 操作失败。检查警报 ID 的拼写。

Ping

使用 Ping 操作测试与 SentinelOne Singularity Operations Center 的连接。

此操作不适用于 Google SecOps 实体。

操作输入

此操作没有输入参数。

操作输出

Ping 操作提供以下输出:

操作输出类型 可用性
案例墙附件 不可用
案例墙链接 不可用
“支持请求墙”表格 不可用
丰富化表 不可用
JSON 结果 不可用
脚本结果 可用
脚本结果

下表列出了使用 Ping 操作时脚本结果输出的值:

脚本结果名称
is_success truefalse
操作输出消息

Ping 操作提供以下输出消息:

输出消息 消息说明
Successfully connected to SentinelOne Singularity Operations Center. 操作成功。
Error executing action "Ping". Reason: ERROR_REASON 操作失败。检查与服务器的连接、输入参数或凭据。

更新提醒

使用 Update Alert 操作可在 SentinelOne Singularity Operations Center 中更新提醒的状态、判决或受让人。

此操作不适用于 Google SecOps 实体。

操作输入

更新提醒操作需要以下参数:

参数
Alert ID 必需

指定需要更新的提醒的 ID。

Status 可选

指定提醒的状态。可能的值:NewIn ProgressResolved

Verdict 可选

指定提醒的判定结果。可能的值:

  • True positive/Malware
  • True positive/Unauthorized access
  • True positive/Data exfiltration
  • True positive/Insider threat
  • True positive/Phishing attack
  • True positive/Advanced persistent threat
  • True positive/Denial of service
  • True positive/Ransomware
  • True positive/Policy violation
  • True positive/Benign but suspicious
  • True positive/Benign
  • True positive/Undefined
  • True positive/Exploitation tools
  • True positive/PUA Adware
  • False positive/Benign
  • False positive/Benign but suspicious
  • False positive/System error
  • False positive/User error
  • False positive/Undefined
Assignee 可选

指定需要将提醒分配给的分析师的名称。如果提供了 Unassign,则相应操作会从提醒中移除分配。

操作输出

更新提醒操作提供以下输出:

操作输出类型 可用性
案例墙附件 不可用
案例墙链接 不可用
“支持请求墙”表格 不可用
丰富化表 不可用
JSON 结果 可用
脚本结果 可用
脚本结果

下表列出了使用更新提醒操作时脚本结果输出的值:

脚本结果名称
is_success truefalse
操作输出消息

更新提醒操作提供以下输出消息:

输出消息 消息说明
Successfully updated alert with ID ALERT_ID in SentinelOne Singularity Operations Center. 操作成功。
Error executing action "Update Alert". Reason: ERROR_REASON 操作失败。检查与服务器的连接、输入参数或凭据。
Error executing action "Update Alert". Reason: alert with ID ALERT_ID wasn't found in SentinelOne Singularity Operations Center. Please check the spelling. 操作失败。检查警报 ID 的拼写。

连接器

有关连接器的更多信息,请参阅使用连接器摄取数据

SentinelOne Singularity Operations Center - 统一警报连接器

使用 SentinelOne Singularity Operations Center - Unified Alerts Connector 从 SentinelOne Singularity Operations Center 拉取统一警报。

连接器参数

使用以下参数配置连接器:

参数
Product Field Name 必需

请输入源字段名称以检索产品字段名称。默认值:Product Name

Event Field Name 必需

请输入源字段名称以检索事件字段名称。默认值:event_type

Environment Field Name 可选

描述存储环境名称的字段的名称。如果找不到环境字段,则环境为默认环境。

Environment Regex Pattern 可选

用于对“环境字段名称”字段中找到的值运行的正则表达式模式。默认值为 .*,表示捕获所有值并原样返回。

Script Timeout (Seconds) 必需

运行当前脚本的 Python 进程的超时限制(以秒为单位)。默认值:180

API Root 必需

SentinelOne Singularity Operations Center 实例的 API 根目录。

API Token 必需

SentinelOne Singularity Operations Center 实例的 API 令牌。

Lowest Severity To Fetch 可选

要获取的问题中严重程度最低的。如果没有提供任何信息,连接器将接收所有严重级别的问题。可能的值:Critical, High, Medium, Low, Info

Max Hours Backwards 必需

从指定位置获取警报的小时数。默认值:1

Max Alerts To Fetch 必需

每次连接器迭代要处理多少个警报? 默认值:10

Use dynamic list as a blocklist 必需

如果启用,动态列表将用作阻止列表。默认情况下处于未选中状态。

Disable Overflow 可选

如果启用,连接器将忽略溢出机制。默认情况下处于未选中状态。

Verify SSL 必需

如果选中,则验证与 SentinelOne Singularity Operations Center 服务器连接的 SSL 证书是否有效。默认情况下处于未选中状态。

Proxy Server Address 可选

要使用的代理服务器的地址。

Proxy Username 可选

用于进行身份验证的代理用户名。

Proxy Password 可选

用于进行身份验证的代理密码。

需要更多帮助?获得社区成员和 Google SecOps 专业人士的解答。