2 Sources
[1]
SentinelOne turns Purple AI loose to investigate threats on its own
SentinelOne turns Purple AI loose to investigate threats on its own SentinelOne Inc. today opened its Purple AI Agentic Investigations capability to all customers, adding autonomous threat investigation that runs without an analyst having to launch it. The feature is available this week as a free trial inside the company's Singularity Platform. It can work through a threat on its own, from spotting it to deciding what it is to acting on the verdict. When something crosses a threshold the customer sets, Purple AI digs in, reaches a conclusion and moves to shut the threat down and analysts can watch it happen and step in at any point. SentinelOne calls the feature "zero-click" because the investigation kicks off by itself rather than waiting for someone to open it. The pitch targets a specific bottleneck. Detections rise with every new tool and every expansion of the attack surface, but verdicts still wait on analyst availability and coverage thins on nights, weekends and during surges. SentinelOne argues that investigation capacity has become the real limit in most security operations centers, ahead of detection, and that AI-driven attacks will stretch that gap further. "Today's security teams face more critical alerts than any staffing plan could investigate and AI-powered threats are only going to make that worse," said Chief Product Officer Chris Corde. "Purple AI's Agentic Investigation capability is designed to remove that constraint by making investigations automatic, continuous and immediate." Purple AI runs on telemetry already in the Singularity Platform across endpoint, identity, cloud and third-party security data and SentinelOne says activation takes a single click with no data leaving the platform. The software gathers the evidence, ties the telemetry together and lays out how the attack unfolded, which hands the analyst a finished verdict to act on. Every verdict comes with an evidence chain that can be audited, and customers decide how much autonomy to grant through an adjustable human-in-the-loop control that can fire off automated responses or just suggest next steps. Under the hood, Purple AI uses a mix of models, combining Anthropic PBC's Claude, OpenAI Group PBC's GPT and SentinelOne's own "Ultraviolet" models to compress investigations that once took hours into minutes. Alongside the launch, SentinelOne introduced Singularity Credits, a single currency customers draw down for AI-powered work across the platform, including the new investigations. The company is granting a complimentary allotment of credits to trial the feature. The trial is now live in Singularity consoles for new and existing customers, requires no payment method and is planned to run through Aug. 15. After it ends, customers can buy credits through partners, direct billing and e-commerce. The launch deepens SentinelOne's bet on AI as the centerpiece of its platform in a security operations market where it goes up against the likes of CrowdStrike Holdings Inc. and Microsoft Corp. The company says it protects nearly one-fifth of the Fortune 500.
[2]
SentinelOne Opens Purple AI Agentic Investigation to All Customers, Bringing Frontier AI Directly Into the SOC
SentinelOne opened Purple AI Agentic Investigation to its customers and introduced Singularity Credits, a unified currency for running AI-powered work across the Singularity Platform. Starting this week, customers can opt into a complimentary trial of the newest capability from Purple AI, SentinelOne?s autonomous security reasoning for the agentic SOC. That capability ? ?zero-click,? autonomously initiated investigations ? detects, investigates, verifies, and responds to threats without human dependencies. When a threat crosses a defined threshold, Purple AI investigates, renders a verdict, and stops it at machine speed, while analysts keep full visibility and control. Purple AI is built into the Singularity Platform, not bolted onto it. The new Agentic Investigation capability runs on telemetry already in the platform across endpoint, identity, cloud, and third-party security data, as well as inside the automated workflows customers already use. There is nothing to deploy, integrate, or tune, and no data leaves the platform. Activation is a single click. Purple AI does the investigation work, collecting evidence, correlating telemetry, and building the attack timeline, so analysts start at the verdict instead of the alert. It scales a team?s investigation capacity without scaling headcount, and frees analysts for the judgment, threat hunting, and response decisions that need a human. Every verdict carries a complete, auditable evidence chain, so analysts can review each AI step and outcome with confidence. Customers set the degree of autonomy through an adjustable human-in-the-loop approach that scales to their confidence and SOC maturity. Verdicts can trigger automated, policy-driven responses, or prompt an analyst with recommended actions. Activation is admin-controlled, role-based, and reversible at any time, and consumption guardrails keep usage and downstream cost in the hands of those with the right authority. Purple AI is the reasoning brain and interface for the entire Singularity Platform. It brings human-level reasoning from advanced frontier-AI models to bear through a multi-model approach, combining Anthropic?s Claude, OpenAI?s GPT, and SentinelOne?s proprietary ?Ultraviolet? models to compress investigations that once took hours or days into minutes and seconds. For critical threats, investigations trigger automatically and deliver verdicts that can be acted on autonomously or by an analyst. Singularity Credits are a flexible, unified currency customers draw down across AI-powered work in the Singularity Platform, including Purple AI Agentic Investigation. To start, SentinelOne is granting customers a complimentary allotment of Credits to trial the capability. The Purple AI Agentic Investigation trial is now available in Singularity Platform consoles. New and existing Singularity customers can opt in and begin running agentic investigations immediately. Investigations utilize Singularity Credits during the trial, but customers are not charged and no payment method is required. After the trial, customers can purchase Singularity Credits through partners, direct billing, and eCommerce.
Share
Copy Link
SentinelOne has launched Purple AI Agentic Investigations to all customers, introducing autonomous threat investigation that detects, investigates, and responds to cybersecurity threats without human intervention. The AI-driven capability runs on the company's Singularity Platform and compresses investigations from hours into minutes using multiple AI models.
SentinelOne has opened its Purple AI Agentic Investigations capability to all customers this week, marking a significant shift in how security teams handle threat detection and response
1
. The AI-driven capability runs autonomous threat investigation from start to finish without requiring an analyst to initiate the process, addressing what the company identifies as a critical bottleneck in modern Security Operations Center workflows2
.
Source: SiliconANGLE
The feature is available as a free trial inside the Singularity Platform through August 15, with no payment method required. When a threat crosses a customer-defined threshold, Purple AI automatically detects, investigates, verifies, and responds to cybersecurity threats at machine speed while analysts maintain full visibility and control
1
.SentinelOne calls the feature "zero-click" because investigations kick off automatically rather than waiting for someone to launch them. This addresses a specific problem: detections rise with every new tool and expansion of the attack surface, but verdicts still wait on analyst availability
1
. Coverage thins during nights, weekends, and surge periods, creating gaps that AI-powered attacks can exploit."Today's security teams face more critical alerts than any staffing plan could investigate and AI-powered threats are only going to make that worse," said Chief Product Officer Chris Corde
1
. The company argues that investigation capacity has become the real constraint in most security operations centers, ahead of autonomous threat detection itself.Purple AI runs on telemetry already present in the Singularity Platform across endpoint security, identity, cloud security, and third-party security data
2
. Activation takes a single click with no data leaving the platform, and there is nothing to deploy, integrate, or tune2
.The software gathers evidence, ties telemetry together, and builds complete attack timelines, handing analysts a finished verdict to act on. Under the hood, Purple AI uses a multi-model approach combining Anthropic Claude, OpenAI GPT, and SentinelOne's proprietary Ultraviolet models to compress investigations that once took hours or days into minutes and seconds
1
2
.Related Stories
Every verdict comes with a complete, auditable evidence chain so analysts can review each AI step and outcome with confidence
2
. Customers decide how much autonomy to grant through adjustable human-in-the-loop controls that scale to their confidence and SOC maturity. Verdicts can trigger automated, policy-driven responses or prompt an analyst with recommended actions2
. Activation is admin-controlled, role-based, and reversible at any time.Alongside the launch, SentinelOne introduced Singularity Credits, a unified currency customers draw down for AI-powered work across the platform, including the new investigations. The company is granting a complimentary allotment of credits to trial the feature. After the trial ends on August 15, customers can purchase Singularity Credits through partners, direct billing, and e-commerce
1
.The launch deepens SentinelOne's bet on AI as the centerpiece of its platform in a security operations market where it competes against CrowdStrike and Microsoft
1
. The company says it protects nearly one-fifth of the Fortune 500, positioning this capability as a way to scale investigation capacity without scaling headcount while freeing analysts for judgment, threat hunting, and response decisions that require human expertise2
.Summarized by
Navi
08 Aug 2024

30 Sept 2025•Technology

29 Aug 2025•Technology

1
Policy and Regulation

2
Policy and Regulation

3
Business and Economy
