SentinelOne opens Purple AI to all customers for zero-click autonomous threat investigation

2 Sources

Share

SentinelOne has launched Purple AI Agentic Investigations to all customers, introducing autonomous threat investigation that detects, investigates, and responds to cybersecurity threats without human intervention. The AI-driven capability runs on the company's Singularity Platform and compresses investigations from hours into minutes using multiple AI models.

SentinelOne launches autonomous security investigations for all customers

SentinelOne has opened its Purple AI Agentic Investigations capability to all customers this week, marking a significant shift in how security teams handle threat detection and response

1

. The AI-driven capability runs autonomous threat investigation from start to finish without requiring an analyst to initiate the process, addressing what the company identifies as a critical bottleneck in modern Security Operations Center workflows

2

.

Source: SiliconANGLE

Source: SiliconANGLE

The feature is available as a free trial inside the Singularity Platform through August 15, with no payment method required. When a threat crosses a customer-defined threshold, Purple AI automatically detects, investigates, verifies, and responds to cybersecurity threats at machine speed while analysts maintain full visibility and control

1

.

Zero-click investigations target SOC capacity constraints

SentinelOne calls the feature "zero-click" because investigations kick off automatically rather than waiting for someone to launch them. This addresses a specific problem: detections rise with every new tool and expansion of the attack surface, but verdicts still wait on analyst availability

1

. Coverage thins during nights, weekends, and surge periods, creating gaps that AI-powered attacks can exploit.

"Today's security teams face more critical alerts than any staffing plan could investigate and AI-powered threats are only going to make that worse," said Chief Product Officer Chris Corde

1

. The company argues that investigation capacity has become the real constraint in most security operations centers, ahead of autonomous threat detection itself.

Multi-model AI approach compresses investigation timelines

Purple AI runs on telemetry already present in the Singularity Platform across endpoint security, identity, cloud security, and third-party security data

2

. Activation takes a single click with no data leaving the platform, and there is nothing to deploy, integrate, or tune

2

.

The software gathers evidence, ties telemetry together, and builds complete attack timelines, handing analysts a finished verdict to act on. Under the hood, Purple AI uses a multi-model approach combining Anthropic Claude, OpenAI GPT, and SentinelOne's proprietary Ultraviolet models to compress investigations that once took hours or days into minutes and seconds

1

2

.

Adjustable autonomy with human-in-the-loop controls

Every verdict comes with a complete, auditable evidence chain so analysts can review each AI step and outcome with confidence

2

. Customers decide how much autonomy to grant through adjustable human-in-the-loop controls that scale to their confidence and SOC maturity. Verdicts can trigger automated, policy-driven responses or prompt an analyst with recommended actions

2

. Activation is admin-controlled, role-based, and reversible at any time.

Singularity Credits introduced as unified AI currency

Alongside the launch, SentinelOne introduced Singularity Credits, a unified currency customers draw down for AI-powered work across the platform, including the new investigations. The company is granting a complimentary allotment of credits to trial the feature. After the trial ends on August 15, customers can purchase Singularity Credits through partners, direct billing, and e-commerce

1

.

The launch deepens SentinelOne's bet on AI as the centerpiece of its platform in a security operations market where it competes against CrowdStrike and Microsoft

1

. The company says it protects nearly one-fifth of the Fortune 500, positioning this capability as a way to scale investigation capacity without scaling headcount while freeing analysts for judgment, threat hunting, and response decisions that require human expertise

2

.

Today's Top Stories

© 2026 TheOutpost.AI All rights reserved