Archive for SentinelOne

SentinelOne Expands Collaboration with AWS to Deliver Unified AI Governance

Posted in Commentary with tags on August 4, 2026 by itnerd

SentinelOne today announced an expanded collaboration with Amazon Web Services (AWS) to deliver unified AI governance for customers building on Amazon Bedrock. The new integration brings together SentinelOne’s AI runtime security with Amazon Bedrock AgentCore, giving security teams one place to see, enforce, and remediate AI risk. As a result, it helps businesses confidently close the gap between how fast they deploy AI agents and how fast their security teams can secure them.

As organizations scale AI agent deployments, security teams need visibility into what their AI is doing, what data and applications it accesses, and whether it meets governance requirements. SentinelOne and AWS took the initial steps to address the first piece of that gap in June 2026, with an integration between SentinelOne’s Prompt Security and Amazon Bedrock AgentCore, putting runtime guardrails at the Amazon Bedrock AgentCore gateway.

Today’s integration moves beyond guardrails into a full governance layer for enterprise AI and will deliver:

  • AI usage governance: Visibility into how AI is being used across the enterprise — sanctioned and unsanctioned.
  • Policy enforcement: Real-time enforcement of AI usage policies across AWS and multi-cloud environments.
  • Threat detection: Detection and root cause analysis of AI-related security risks.
  • Automated remediation: Automated remediation of misconfigurations and non-compliant AI code.

This new governance layer connects Prompt Security, Singularity™ Cloud Security, and Singularity™ AI SIEM into a single view across Amazon Bedrock, including AgentCore, giving enterprises machine-speed policy enforcement, threat detection, and autonomous response across their full AI estate.

The integration deepens SentinelOne’s Prompt Security and Singularity AI runtime offerings for enterprises building on AWS. It also deepens joint work with AWS, AWS Marketplace distribution, and co-sell funding.

SentinelOne’s Prompt Security, Singularity Hyperautomation and AI SIEM are already available on AWS Marketplace and the general availability of the full unified AI governance layer is targeted for AWS re:Invent 2026

SentinelOne Makes the Autonomous SOC Trustworthy with Governed, Closed-Loop Response

Posted in Commentary with tags on August 3, 2026 by itnerd

SentinelOne today announced governed, closed-loop response across the Singularity™ Platform, delivering trustworthy automation for security operations. Purple AI® and Singularity Hyperautomation now autonomously investigate alerts, reach verdicts, and execute responses. Security teams set the boundaries first, deciding where AI acts on its own and where it stops for human sign-off. The Autonomous SOC now runs from alert to action, at the speed and scale of AI, with the confidence and control of human defenders.

SOC teams have tried to embrace automation for years to deal with an overwhelming volume of alerts and data. Response automation was first attempted through SOAR playbooks, though those playbooks are fixed decision trees that break the moment reality diverges from the script. What stayed missing was judgment at the point of action. Purple AI supplies it, choosing the next step from what the investigation actually found rather than from a branch encoded months earlier. The loop closes.

The foundation is already carrying a production load. Purple AI Agentic Investigation has been running in customer environments since June, and now handles more than 8,500 critical autonomous investigations every day. More than a third of the eligible customer base has it running. Across that base, Purple AI investigates nearly three times as many alerts as analysts reach by hand. Alerts that would have aged in a queue get investigated, and analysts spend their hours on the decisions that need judgment.

What decides whether a SOC can adopt autonomous response based on agentic reasoning is whether a human can see the action, trace it, and take it back. Every AI-driven action in the Singularity Platform is traceable, auditable, and overrideable by the team that authorized it.

Not every workflow needs to run unattended. The discipline is relevant control, staying in the decisions that carry real consequence and letting the rest run. Governance is the precondition, not the paperwork.

These capabilities are built into core components of the Singularity Platform. SOC teams get AI reasoning and automated execution inside the workflows, tools, and approval chains they already run. There is no integration work and no additional tooling required.

Building on Purple AI Agentic Investigation, the new capabilities use Singularity Hyperautomation workflows to:

  • Trigger a Purple AI Agentic Investigation from any point in a workflow, not only the initial alert.
  • Pull the full investigation report, with verdict and evidence, directly into automation logic.
  • Apply customizable LLM Actions to reason over the findings and call the right next step.
  • Call validated response snippets, reusable action blocks teams build once and use repeatedly.

The Hyperautomation workflow capabilities are expected to be generally available later this quarter. SentinelOne is demonstrating them at Black Hat USA 2026 in booth #2933, and a full demo is available on the SentinelOne YouTube channel.

Additional details and related information:

SentinelOne Opens Purple AI Agentic Investigations to All Customers, Bringing Frontier AI Directly Into the SOC

Posted in Commentary with tags on June 17, 2026 by itnerd

SentinelOne today opened Purple AI Agentic Investigations to its customers and introduced Singularity Creditsa unified currency for running AI-powered work across the Singularity Platform. Starting this week, customers can opt into a complimentary trial of the newest capability from Purple AI, SentinelOne’s autonomous security reasoning for the agentic SOC. That capability — ‘zero-click,’ autonomously initiated investigations — detects, investigates, verifies, and responds to threats without human dependencies. When a threat crosses a defined threshold, Purple AI investigates, renders a verdict, and stops it at machine speed, while analysts keep full visibility and control.

The capability arrives as security teams confront a hard limit, not detection, but investigation capacity. Detections climb with every new tool and every expansion of the attack surface, alerts queue for attention, and verdicts wait on analyst availability, with coverage thinning on nights, weekends, and during surges. Frontier-AI-powered threats are poised to widen that gap further.

Why SOC Teams Are Adopting Purple AI Agentic Investigations

  • Seamlessly integrated — zero configuration, working from day one.

Purple AI is built into the Singularity Platform, not bolted onto it. Agentic Investigations run on telemetry already in the platform — across endpoint, identity, cloud, and third-party security data — inside the automated workflows customers already use. There is nothing to deploy, integrate, or tune, and no data leaves the platform. Activation is a single click.

  • A force multiplier for every analyst.

Purple AI does the investigation work — collecting evidence, correlating telemetry, and building the attack timeline — so analysts start at the verdict instead of the alert. It scales a team’s investigation capacity without scaling headcount, and frees analysts for the judgment, threat hunting, and response decisions that need a human. It is designed as an extension of the analyst: amplifying human defenders, not replacing them.

  • Fully audited — governed autonomy, no black box

Every verdict carries a complete, auditable evidence chain, so analysts can review each AI step and outcome with confidence. Customers set the degree of autonomy through an adjustable human-in-the-loop approach that scales to their confidence and SOC maturity — verdicts can trigger automated, policy-driven responses, or prompt an analyst with recommended actions. Activation is admin-controlled, role-based, and reversible at any time, and consumption guardrails keep usage and downstream cost in the hands of those with the right authority.

  • Built on the most advanced reasoning in security

Purple AI is the reasoning brain and interface for the entire Singularity Platform. It brings human-level reasoning from advanced frontier-AI models to bear through a multi-model approach — combining Anthropic’s Claude, OpenAI’s GPT, and SentinelOne’s proprietary “Ultraviolet” models — to compress investigations that once took hours or days into minutes and seconds. For critical threats, investigations trigger automatically and deliver verdicts that can be acted on autonomously or by an analyst.

The introduction of Singularity Credits

Singularity Credits are a flexible, unified currency customers draw down across AI-powered work in the Singularity Platform, including Purple AI Agentic Investigations. To start, SentinelOne is granting customers a complimentary allotment of Credits to trial the capability.

Delivering on the agentic SOC by amplifying defenders, not replacing them

Agentic Investigations advances SentinelOne’s vision of the agentic SOC: one where frontier-AI reasoning amplifies and scales human defenders rather than sidelining them. Purple AI acts as the brain and interface for the entire platform from simplifying querying, to recommending actions, to autonomously detecting, triaging, and stopping threats. Because it operates natively on AI, endpoint, identity, cloud, and third-party telemetry already in the Singularity Platform, it drives Singularity to be an agentic realization of the integrated security operations center (ISOC) category defined by Gartner.

Availability & access

The Purple AI Agentic Investigations trial is now available in Singularity consoles. New and existing Singularity customers can opt in and begin running agentic investigations immediately. Investigations consume Singularity Credits during the trial, but customers are not charged and no payment method is required. The complimentary trial is currently planned to run through August 15, 2026. After the trial, customers can purchase Singularity Credits through partners, direct billing, and eCommerce.

SentinelOne Comes Across A New Python-Based Hacking Tool Known As FBot

Posted in Commentary with tags on January 13, 2024 by itnerd

There’s new research by SentinelOne about a Python-based hacking tool known as FBot capable of credential harvesting for spamming attacks, and AWS, PayPal and SaaS account hijacking:

FBot is unique in that it does not apparently adapt the Androxgh0st code so common among similar hacktools, though the earliest reference to FBot is one year more recent than the first sighting of Androxgh0st. However, there are several connections to the Legion cloud infostealer, making it likely the Legion maintainer adapted code from FBot into their tool.

FBot is primarily designed for actors to hijack cloud, SaaS, and web services. There is a secondary focus on obtaining accounts to conduct spamming attacks. Actors can use the credential harvesting features to obtain initial access, which they can sell to other parties.

The tool contains assorted utilities, including an IP address generator and port scanner. There is also an email validator function, which uses an Indonesian technology service provider to validate email addresses.

 Ken Westin, Field CISO, Panther Labs had this comment:

Many organizations rely on the vendors to provide security for their cloud platforms and often do not have full visibility into what is happening in their cloud environments. We will continue to see threat groups focus on attacking cloud applications and services, as this is where most corporate data resides, these tools will continue to evolve in maturity and leverage APIs to compromise cloud assets.

The fact that “the cloud” is still a bit of a black box where you have to trust the provider is a problem. But unless there’s full transparency about what goes on behind the curtain, it will allow threats like these to exist, and affect end customers.