
SentinelOne Purple AI
Agentic AI that investigates alerts on its own — correlating endpoint, identity, and cloud telemetry into a verdict backed by a full evidence chain.
Purple AI Agentic Investigation is SentinelOne's autonomous SOC capability, opened to all customers in June 2026. When an alert crosses a set threshold, it opens an investigation without an analyst triggering it, correlates telemetry across endpoint, identity, cloud, and third-party data inside the Singularity Platform, and builds an attack timeline. It then renders a verdict — real threat or false positive — with a reviewable evidence chain, aiming to remove investigation capacity as the binding constraint of the modern SOC.
Key Capabilities
Autonomous Investigation
- Opens investigations on its own when an alert crosses a set threshold
- Correlates telemetry across endpoint, identity, cloud, and third-party data
- Builds a full attack timeline inside the Singularity Platform
Verdict With Evidence
- Renders a real-threat or false-positive verdict for every alert
- Backs each call with an evidence chain an analyst can review
- Triggers automated response or a human-approved recommendation, per your autonomy settings
Zero-Config, Reversible
- Rides on telemetry SentinelOne already collects — nothing new to deploy
- Reasons with a mix of Anthropic Claude, OpenAI GPT, and SentinelOne's Ultraviolet models
- Every action is role-based, admin-controlled, and reversible
Want a guided walkthrough of SentinelOne Purple AI?
Book a session with FieldCISO and we'll help you evaluate whether it fits your security program.
