Connecting CrowdStrike, SentinelOne, Sophos, Bitdefender or ESET (telemetry)
Bring another EDR's alerts and device inventory into Qorionix. All five connectors are read-only today - no isolate, no containment through any of them yet.
If your fleet already runs CrowdStrike Falcon, SentinelOne Singularity, Sophos Central, Bitdefender GravityZone or ESET PROTECT, you do not have to remove it to use Qorionix. All five connectors read that product's own alerts and device inventory and bring them into Qorionix as incidents and endpoint records, the same way the Microsoft Defender for Business connector does.
CrowdStrike Falcon
Create an API client in Falcon
In the Falcon console, go to Support and resources -> API clients and keys -> Add new API client. Grant it the Alerts (read) and Hosts (read) scopes, then copy the Client ID and Client Secret.
Note your cloud region
Falcon is cloud-region specific: us-1, us-2, eu-1 or us-gov-1. Pick the one your Falcon console URL shows.
Connect it in Qorionix
Under Integrations -> Catalog -> CrowdStrike Falcon, choose Endpoint telemetry, paste the Client ID and Secret, select the cloud region, and press Test and save. The test authenticates and runs a real, bounded alert and device query.
Once connected, CrowdStrike alerts and device inventory poll automatically on a schedule - there is no manual sync step. Each alert becomes a Qorionix alert; each device becomes an endpoint-agent record you can see on the Endpoints screen. A re-poll updates an existing record by CrowdStrike's own alert id rather than duplicating it. CrowdStrike gives Qorionix no shared incident grouping id across alerts, so each new alert opens its own Qorionix incident rather than being merged with related ones the way Microsoft Defender for Business's alerts are.
SentinelOne Singularity
Generate an API token
In the SentinelOne management console, go to Settings -> Users, open your own user (or a dedicated service account), and generate an API token.
Note your management console URL
SentinelOne is single-tenant per console; the connector calls your own console's own host, not a shared regional endpoint.
Connect it in Qorionix
Under Integrations -> Catalog -> SentinelOne, choose Endpoint telemetry, paste the console URL and the API token, and press Test and save.
Threats and agents poll automatically once connected, on the same schedule as CrowdStrike. As with CrowdStrike, SentinelOne exposes no shared incident id, so each threat opens its own Qorionix incident.
Sophos Central
Create an API credential
In Sophos Central Admin, go to Global Settings -> API Credentials Management -> Add credential, with the Service Principal role set to read-only. Copy the Client ID and Client Secret - both are shown once, at creation.
Connect it in Qorionix
Under Integrations -> Catalog -> Sophos Central, choose Endpoint telemetry, paste the Client ID and Secret, and press Test and save.
Alerts and endpoints poll automatically once connected. As with CrowdStrike and SentinelOne, Sophos gives Qorionix no shared incident id, so each alert opens its own Qorionix incident.
Bitdefender GravityZone
Create an API key
In GravityZone Control Center, go to My Account -> API keys -> Add, granting the Incidents and Network Inventory API access roles.
Note your console URL
GravityZone has no fixed host - a cloud deployment and an on-premises deployment each have their own console URL, so you enter yours rather than picking from a list.
Connect it in Qorionix
Under Integrations -> Catalog -> Bitdefender GravityZone, choose Endpoint telemetry, enter the console URL and the API key, and press Test and save.
Incidents and endpoints poll automatically once connected. Bitdefender, like the other four vendors here, gives Qorionix no shared incident id, so each incident opens its own Qorionix incident.
ESET PROTECT
Create an API client
In your ESET Business Account, go to API Clients -> New API Client, with the ESET PROTECT read-only scope. Copy the Client ID and Client Secret.
Note your region or console URL
Authentication always runs against ESET's central identity host, but detections and devices are read from a region-hosted API host - EU or US. If your PROTECT deployment is on-premises rather than in ESET's cloud, enter its API base URL instead of picking a region.
Connect it in Qorionix
Under Integrations -> Catalog -> ESET PROTECT, choose Endpoint telemetry, paste the Client ID and Secret and the region (or on-premises URL), and press Test and save.
Detections and devices poll automatically once connected. As with the other four vendors, ESET gives Qorionix no shared incident id, so each detection opens its own Qorionix incident.
What you see once it is polling
- New alerts, threats, incidents and detections appear as incidents in the same queue as everything else, tagged with their source connector.
- Devices each vendor protects appear on the Endpoints screen, matched by hostname where a Qorionix sensor also runs there. This applies to all five connectors - Sophos Central, Bitdefender GravityZone and ESET PROTECT devices and alerts are imported into the same endpoint and alert tables CrowdStrike and SentinelOne use, not just configured and health-checked without being wired in.
- Severity is mapped from each vendor's own scale; nothing is re-scored or re-interpreted beyond that mapping.