Release 3.42.0

SentinelOne EDR Findings Mapped to Cynomi Tasks

Endpoint posture data is something you typically collect manually, client by client and task by task. Cynomi now reads posture data directly from the SentinelOne Management API, turns it into findings, and maps those findings to relevant Cynomi tasks, so task status reflects what's actually deployed without manual collection.

Tasks Integrations

What’s in This Release

  • A direct API integration with SentinelOne EDR, connected from the client account
  • 14 endpoint posture checks across deployment, configuration, and hygiene
  • Findings that flag risk, including end-of-life systems and unmanaged devices
  • Findings that link to tasks in three states, with coverage that follows the license

Endpoint Posture, Read Straight from the SentinelOne Management API

Cynomi reads the SentinelOne Management API directly and converts what it finds into findings. Each finding evaluates a single question across all of a client’s endpoints, such as whether EDR is deployed and actively protecting every device, and rolls the answer up into one result you can act on rather than a per-machine list.

That result links to the relevant Cynomi tasks. Endpoint posture data populates the task plan automatically, instead of arriving as a console export that somebody has to interpret and then transcribe. The integration sits alongside the rest of the connected tooling on the integrations page.

Why this matters

Endpoint posture data used to be collected per task, per client, by a person. It now arrives as a linked finding. The task plan and the real state of the estate stay aligned without anyone reconciling them by hand.

14 Endpoint Posture Checks

The integration ships 14 checks, grouped across three areas:

  • Deployment and protection – EDR coverage, up-to-date anti-malware, and detect-only versus protect mode
  • Configuration controls – firewall, disk encryption, device control, and application control
  • Inventory and hygiene – asset and software inventory, policy exclusions, and admin activity cadence

It also surfaces findings that flag risk: prohibited or high-risk software, end-of-life operating systems, and unmanaged devices on the network. These findings can help surface endpoint risks that may not otherwise be visible in routine client reviews.

Together the checks give you a current picture of endpoint risk across workstations and servers, without a scheduled review meeting to assemble it.

Findings That Map to Tasks, in Three States

Every check reports one of three states:

  • Pass – compliant, so the task can be marked complete
  • Gap – a clear shortfall, which keeps the task open
  • at risk – partial coverage that needs review

The At Risk state captures partial coverage that requires review rather than a simple pass-or-fail determination. Each finding links directly to one or more Cynomi tasks, and a single task can be mapped to more than one check, so a control backed by several endpoint conditions shows all of them.

Your task plan in security program management and your endpoint reality stay in step without a manual pass over both, and the finding behind a status is visible on the task rather than in somebody’s export folder.

Coverage That Follows Each Client’s License

Coverage adapts to each tenant’s SentinelOne license. Checks available on every paid tier run for all tenants, while checks that require a higher tier or a paid add-on are skipped where the license does not support them.

The practical effect is that a client only ever sees the checks their license actually supports, rather than a list of gaps that are really licensing limits. It also means two clients on different SentinelOne tiers will show different numbers of checks, so check counts may differ between clients on different license tiers.

What This Changes for Your Delivery Team

Endpoint posture collection is a recurring manual task in many security engagements. Reading endpoint posture directly, turning it into findings, and mapping those findings to the tasks they relate to reduces manual administration for clients running SentinelOne, leaving your team to focus on reviewing and prioritizing the gaps.

Frequently Asked Questions

What does the SentinelOne EDR integration bring into Cynomi?

Endpoint posture, read directly from the SentinelOne Management API and turned into findings. Each finding evaluates one question across all endpoints and links to the relevant Cynomi tasks, so endpoint posture data populates the task plan automatically.

How many posture checks does it run, and what do they cover?

The integration runs 14 checks. They span deployment and protection, configuration controls such as firewall and disk encryption, and inventory and hygiene. The integration also surfaces prohibited or high-risk software, end-of-life operating systems, and unmanaged devices on the network.

What do the three finding states mean?

Pass means compliant, so the task can be marked complete. Gap is a clear shortfall that keeps the task open. At risk is partial coverage that needs review.

Can more than one check map to the same task?

Yes. Each finding links to one or more Cynomi tasks, and a single task can be mapped to more than one check.

What happens if a client's SentinelOne license does not support a check?

That check is skipped for the tenant. Checks available on every paid tier run for all tenants, while those needing a higher tier or a paid add-on only run where the license supports them.

Does this replace the existing SentinelOne vulnerability management integration?

No. SentinelOne Singularity Vulnerability Management is a separate integration that brings in vulnerability findings. This one reads endpoint posture from the SentinelOne Management API and maps the findings to tasks.

The Security Growth Platform
for Service Providers

Discover how Cynomi can help you standardize delivery, accelerate onboarding, and scale your CISO advisory services.