3 Sources
[1]
SentinelOne turns Purple AI loose to investigate threats on its own
SentinelOne turns Purple AI loose to investigate threats on its own SentinelOne Inc. today opened its Purple AI Agentic Investigations capability to all customers, adding autonomous threat investigation that runs without an analyst having to launch it. The feature is available this week as a free
[2]
SentinelOne Opens Purple AI Agentic Investigation to All Customers, Bringing Frontier AI Directly Into the SOC
Zero-configuration, autonomously initiated investigations run inside customers' existing Singularity™ Platform workflows, detecting, investigating, and responding to threats at machine speed, and giving every analyst a force multiplier, with a full evidence chain behind every verdict SentinelOne®
[3]
SentinelOne Opens Purple AI Agentic Investigation to All Customers, Bringing Frontier AI Directly Into the SOC
SentinelOne opened Purple AI Agentic Investigation to its customers and introduced Singularity Credits, a unified currency for running AI-powered work across the Singularity Platform. Starting this week, customers can opt into a complimentary trial of the newest capability from Purple AI,
Share
Copy Link
SentinelOne launched Purple AI Agentic Investigation for all customers, enabling zero-click autonomous threat investigation that detects, analyzes and responds without human intervention. The capability addresses a critical bottleneck in security operations centers where investigation capacity has become the binding constraint, with alerts queuing for analyst availability while AI-powered threats intensify pressure on defenders.
SentinelOne opened its Purple AI Agentic Investigation capability to all customers this week, introducing autonomous threat investigation that operates without requiring an analyst to initiate the process
1
. The feature is available as a complimentary trial inside the company's Singularity Platform, where it can detect, investigate and respond to cybersecurity threats entirely on its own2
. When a threat crosses a customer-defined threshold, Purple AI investigates, renders a verdict and stops the attack at machine speed while analysts maintain full visibility and control throughout the process.
Source: SiliconANGLE
The launch directly targets what SentinelOne identifies as the binding constraint in modern Security Operations Center environments: investigation capacity rather than threat detection. Detections climb with every new tool and expansion of the attack surface, but verdicts still wait on analyst availability, with coverage thinning during nights, weekends and surge periods
1
. "Today's security teams face more critical alerts than any staffing plan could investigate, and AI-powered threats are only going to make that worse," said Chris Corde, Chief Product Officer of SentinelOne2
.The AI-driven capability operates as what SentinelOne calls "zero-click" investigations because they kick off automatically rather than waiting for someone to launch them
1
. Purple AI runs on telemetry already present in the Singularity Platform across endpoint, identity, cloud and third-party security data, requiring nothing to deploy, integrate or tune3
. Activation takes a single click and no data leaves the platform during operation.The software gathers evidence, correlates telemetry and builds the complete attack timeline, handing analysts a finished verdict to act upon rather than starting from an alert
3
. This approach scales investigation capacity without scaling headcount, freeing analysts for judgment calls, threat hunting and response decisions that require human expertise. Every verdict includes a complete, auditable evidence chain so analysts can review each step and outcome with confidence2
.Under the hood, Purple AI employs a multi-model approach combining Anthropic Claude, OpenAI GPT and SentinelOne's proprietary Ultraviolet models to compress investigations that once consumed hours or days into minutes and seconds
1
. The frontier AI reasoning enables the system to bring human-level analytical capabilities to bear on critical threats automatically2
.Customers control how much autonomy to grant through an adjustable human-in-the-loop mechanism that scales to their confidence level and SOC maturity. Verdicts can trigger automated, policy-driven responses or simply prompt an analyst with recommended actions
3
. Activation remains admin-controlled, role-based and reversible at any time, with consumption guardrails keeping usage and cost in the hands of authorized personnel.Related Stories
Alongside the launch, SentinelOne introduced Singularity Credits, a unified currency customers draw down for AI-powered work across the Singularity Platform, including the new Agentic Investigation capability
1
. The company is granting a complimentary allotment of credits to trial the feature, with the trial running through Aug. 15 and requiring no payment method . After the trial ends, customers can purchase credits through partners, direct billing and e-commerce channels.The launch deepens SentinelOne's position in a competitive market where it faces rivals including CrowdStrike and Microsoft. The company says it protects nearly one-fifth of the Fortune 500
1
. The move toward agentic investigations reflects broader industry recognition that AI-powered attacks will continue stretching the gap between detection capabilities and investigation capacity, making autonomous remediation capabilities increasingly critical for endpoint security and cloud security operations alike.Summarized by
Navi
08 Aug 2024

04 Sept 2026•Technology
28 Jan 2026•Technology

1
Science and Research

2
Technology

3
Technology
