SentinelOne Purple AI logo
AI SOC

SentinelOne Purple AI

Agentic AI that investigates alerts on its own — correlating endpoint, identity, and cloud telemetry into a verdict backed by a full evidence chain.

About SentinelOne Purple AI

Purple AI Agentic Investigation is SentinelOne's autonomous SOC capability, opened to all customers in June 2026. When an alert crosses a set threshold, it opens an investigation without an analyst triggering it, correlates telemetry across endpoint, identity, cloud, and third-party data inside the Singularity Platform, and builds an attack timeline. It then renders a verdict — real threat or false positive — with a reviewable evidence chain, aiming to remove investigation capacity as the binding constraint of the modern SOC.

Key Capabilities

Autonomous Investigation

  • Opens investigations on its own when an alert crosses a set threshold
  • Correlates telemetry across endpoint, identity, cloud, and third-party data
  • Builds a full attack timeline inside the Singularity Platform

Verdict With Evidence

  • Renders a real-threat or false-positive verdict for every alert
  • Backs each call with an evidence chain an analyst can review
  • Triggers automated response or a human-approved recommendation, per your autonomy settings

Zero-Config, Reversible

  • Rides on telemetry SentinelOne already collects — nothing new to deploy
  • Reasons with a mix of Anthropic Claude, OpenAI GPT, and SentinelOne's Ultraviolet models
  • Every action is role-based, admin-controlled, and reversible

Want a guided walkthrough of SentinelOne Purple AI?

Book a session with FieldCISO and we'll help you evaluate whether it fits your security program.