SentinelOne Purple AI logo
AI SOC

SentinelOne Purple AI

Agentic AI that investigates alerts on its own, correlating endpoint, identity, and cloud telemetry into a verdict backed by a full evidence chain.

Watch the SentinelOne Purple AI demo

Fill in your details below and the demo will unlock straight away.

We use your details to share relevant FieldCISO research. No spam, unsubscribe anytime.

About SentinelOne Purple AI

Purple AI Agentic Investigation is SentinelOne's autonomous SOC capability, opened to all customers in June 2026. When an alert crosses a set threshold, it opens an investigation without an analyst triggering it, correlates telemetry across endpoint, identity, cloud, and third-party data inside the Singularity Platform, and builds an attack timeline. It then renders a verdict of real threat or false positive, with a reviewable evidence chain, aiming to remove investigation capacity as the binding constraint of the modern SOC.

Key Capabilities

Autonomous Investigation

  • Opens investigations on its own when an alert crosses a set threshold
  • Correlates telemetry across endpoint, identity, cloud, and third-party data
  • Builds a full attack timeline inside the Singularity Platform

Verdict With Evidence

  • Renders a real-threat or false-positive verdict for every alert
  • Backs each call with an evidence chain an analyst can review
  • Triggers automated response or a human-approved recommendation, per your autonomy settings

Zero-Config, Reversible

  • Rides on telemetry SentinelOne already collects, so nothing new to deploy
  • Reasons with a mix of Anthropic Claude, OpenAI GPT, and SentinelOne's Ultraviolet models
  • Every action is role-based, admin-controlled, and reversible