SentinelOne Singularity platform demo covering alert triage, investigation, threat hunting, and remediation using AI-assisted endpoint and cloud defense.
Open alerts are accessible from the left side menu. Selecting a ransomware alert for GPAgentInstaller.exe shows a natural language summary generated by Purple AI. Static AI identifies a ransomware file on user JeanLuc's desktop. The Graph view displays related entities, alerts, and misconfigurations, revealing that the endpoint TheBorg has multiple related alerts including a Lateral Movement alert. Purple AI summarizes the Lateral Movement alert, noting suspicious file manipulation, execution of malicious shellcode, and correlation to multiple MITRE ATT&CK indicators with severity tags.
The Storyline view organizes all atomic endpoint events into a single narrative describing the full chain of events on an endpoint. Nodes in Storyline can be expanded to show details such as command line arguments and network connections. Alert details include the detection engine that generated the alert, first-seen and last-updated timestamps, and an Alert Footprint showing how many times the malware has been seen across the organization. In this case the malware was first seen in 2024 and has impacted over 2,600 machines.
Singularity Threat Intelligence, an optional add-on, integrates Google Threat Intelligence context. Over 8,000 events were scanned with potential indicators found at 100 risk scores. The RACCOON malware family is identified as data-mining malware targeting Windows, with associated malware families and targeted industries listed. Searching for RACCOON indicators by hash in the Singularity Data Lake returns over 6,700 matching records including behavior indicators, network actions, and registry changes. Purple AI analyzes event properties and generates a summary identifying 9 defense evasion indicators.
Purple AI includes Quick Starts with pre-populated threat hunts and common support questions. Purple AI for Support is an always-on agent trained on SentinelOne technical documentation to answer administration questions. Selecting a hunt for MITRE ATT&CK T1140 (Deobfuscate/Decode Files), Purple AI automatically translates natural language into structured PowerQueries. The query returns 48 matching results in the Singularity Data Lake within the last 72 hours. Purple AI summarizes a selected event, identifying obfuscated PowerShell commands used to execute malicious code while evading detection. Purple AI also provides follow-up question recommendations to continue the hunt. A follow-up query for common T1140 indicators returns 4 results, the most common being suspicious shellcode followed by the obfuscated PowerShell command. Purple AI can generate an email summary of the hunt and supports full multilingual translation for globally dispersed SOC teams. Hunt findings can be saved as a named Notebook and shared with team members for collaborative review.
For remediation, multiple mitigation options are available and can be automated via policy to reduce attacker dwell time. The Kill action stops all running processes associated with the threat. The Quarantine action encrypts and moves threat executables to prevent further infection. The Remediate action deletes all system and file changes including persistence mechanisms. SentinelOne's 1-click Rollback restores files and configurations altered by the attacker, including files encrypted during a ransomware event. Mitigation is applied within milliseconds. Singularity Hyperautomation extends mitigation to third-party tools via customizable automation workflows with over 100 pre-built integrations for SaaS applications.
Alerts can be grouped into Incidents, either automatically through built-in correlation or manually. Incidents provide a higher-level view of all related alerts within an attack campaign and include related artifacts, assets, and all observed MITRE ATT&CK tactics. Incident names are generated automatically upon creation.
This demo covers an attack scenario based on UNC3944, a financially motivated threat group known for phishing, SIM swapping, social engineering, MFA compromise, help desk social engineering, extortion, and ransomware. The group has multiple aliases including ScatteredSpider and Storm-0875, and uses ALPHV malware and stolen credentials for initial access. The attack scenario spans email, endpoint, identity, and cloud, and is examined within the SentinelOne Singularity Operations Center.
Third-party tools such as Proofpoint can be integrated into Singularity via Marketplace and are available in AI SIEM and Purple AI. The attack begins with a phishing attempt on a user named Jean-Luc. Opening the Proofpoint alert triggers Purple AI agents to auto-triage and enrich the alert with AI Similarity Analysis, Community Verdict, and a natural language alert summary.
AI Similarity Analysis uses neural networks to analyze security-relevant data points and identify similar alerts across a global population. In this scenario, 216 similar alerts have been seen in the SentinelOne community. Community Verdict shows how similar alerts have been triaged by other analysts, including SentinelOne threat services and intelligence teams. A Community Verdict above 99% indicates the alert is almost always marked a true positive by the community.
Following the phishing attempt, the adversary uses Jean-Luc's workstation to dump credentials, then uses those credentials to perform Active Directory discovery. The adversary deploys GPAgentInstaller.exe via PowerShell, flagged as malicious with characteristics of ransomware including high entropy and self-modifying code. Over 1,000 similar alerts have been seen, with a Community Verdict of 96%. The ransomware then attempts lateral movement, deletes local backups, accesses raw volumes, and encrypts files. Alerts include automatic MITRE ATT&CK technique mapping.
For threat hunting, Purple AI scans events and identifies threat intelligence indicators. In this scenario, 1,270 events were scanned and 8 indicators found. SentinelOne provides contextual information on the ALPHV malware family, including associated actors and aliases, and links it to UNC3944.
Purple AI includes a dedicated workspace for hunting and investigation with patent-pending Quick Starts that provide pre-programmed hunting prompts. Analysts can query in natural language; Purple automatically converts these into PowerQueries without requiring knowledge of query languages. Querying Okta authentication events for Jean-Luc returns 34 events showing multiple authentication failures followed by a success. Purple summarizes results and suggests follow-up questions.
Drilling into failed logins reveals 24 failed attempts originating from Chicago and Bogota, Colombia, across multiple IP addresses sharing the same browser version. Querying MFA enrollment activity shows Jean-Luc added two new MFA tokens, a soft token and Okta Verify, within the last 72 hours, confirming compromise of his Okta account by UNC3944.
Purple AI can generate email summaries of investigation findings, including key findings and recommended actions. Summaries can be produced in multiple languages, including Spanish, supporting multilingual SOC teams. Investigation results are saved in Notebooks, which are private by default but can be shared with teammates within the current scope for collaborative review and knowledge sharing.
Singularity Cloud Security is a CNAPP platform combining agentless cloud security posture management, workload protection, compliance monitoring, graph-based attack path analysis, AI-driven alert triage, and security automation.
The Singularity Operations Center serves as the central hub connecting all modules. The Cloud Native Security dashboard provides a high-level summary of cloud risk exposure, including totals for detected misconfigurations, vulnerabilities, and other exposures. Cloud assets can be onboarded from AWS, Azure, GCP, Oracle Cloud, Alibaba, and other providers.
The Inventory section shows a full breakdown of the cloud environment by asset type, including AI/ML resources such as AWS SageMaker and Azure AI Service. The Compliance dashboard supports out-of-the-box frameworks including PCI, HIPAA, and NIST's AI Risk Management Framework. Compliance scores are calculated as the ratio of passed checks to total checks. Findings can be filtered by Controls, Sub-Controls, and other groupings, and the impact of findings on related compliance frameworks is also shown.
Cloud Native Security is the agentless CNAPP component. It includes an Offensive Security Engine that simulates real-world attacks using benign exploit payloads to produce Verified Exploit Paths, identifying which vulnerabilities and misconfigurations are actually exploitable by outside attackers. For example, a misconfigured EC2 instance exposed to remote code execution via Log4j can be validated by pointing a curl command at the instance to confirm the vulnerability is reachable. The same curl command can be used to verify remediation.
The Graph Explorer provides a visual representation of the full attack path, mapping exposures and alerts to connected cloud assets for blast radius and root cause analysis. In the Log4j example, the graph shows the exposed EC2 instance and any alerts triggered as a result, including alerts from the Cloud Workload Security agent. The graph reveals that the Log4j exposure led to a crypto mining attack.
Singularity Cloud Workload Security is the agent-based workload protection component, built on eBPF architecture for real-time detection and response across servers, containers, VMs, and serverless containers. It uses multiple AI detection engines to identify known and unknown threats. The crypto mining alert was detected by the Behavioral AI engine.
Alerts are summarized by Purple AI, SentinelOne's agentic AI security analyst, which provides human-readable explanations of alert origin and recommended next steps. In this case, Purple AI identified that malicious xmrig mining software was executed on the EC2 instance. Purple AI's Auto-Triage capability aggregates similar alerts across the SentinelOne community; in this example, over 1,000 similar alerts were reviewed and 99% were confirmed true positives.
The Storyline feature correlates atomic events into a visual sequence illustrating all malicious activity leading to the alert. In this case, the Storyline shows a Java process spawned due to the Log4j exposure, followed by a bash script executed by that Java process, followed by execution of the xmrig mining software.
Available mitigation actions include killing the process, quarantining files, remediating by deleting files and system changes, rolling back to a saved VSS snapshot (Windows only), and blacklisting the file hash. Detection agents can operate in Detect mode, where actions are taken on-demand, or Protect mode, where mitigation actions execute autonomously in real time.
Singularity Hyperautomation is a low-code/no-code security automation component integrated with Singularity Cloud Security. It allows analysts to build remediation workflows triggered by detections. Available workflow actions include locking down network ingress, creating a pull request to modify Terraform code, and creating Jira tickets for findings of specific severities. Hyperautomation supports 100+ out-of-the-box integrations for building custom workflows.
Experience the Most Advanced Cybersecurity Platform
See how the world’s most intelligent, autonomous cybersecurity
platform can protect your organization today and into the future.
This demo covers an attack scenario based on UNC3944, a financially motivated threat group known for phishing, SIM swapping, social engineering, MFA compromise, help desk social engineering, extortion, and ransomware. The group has multiple aliases including ScatteredSpider and Storm-0875, and uses ALPHV malware and stolen credentials for initial access. The attack scenario spans email, endpoint, identity, and cloud, and is examined within the SentinelOne Singularity Operations Center.
Third-party tools such as Proofpoint can be integrated into Singularity via Marketplace and are available in AI SIEM and Purple AI. The attack begins with a phishing attempt on a user named Jean-Luc. Opening the Proofpoint alert triggers Purple AI agents to auto-triage and enrich the alert with AI Similarity Analysis, Community Verdict, and a natural language alert summary.
AI Similarity Analysis uses neural networks to analyze security-relevant data points and identify similar alerts across a global population. In this scenario, 216 similar alerts have been seen in the SentinelOne community. Community Verdict shows how similar alerts have been triaged by other analysts, including SentinelOne threat services and intelligence teams. A Community Verdict above 99% indicates the alert is almost always marked a true positive by the community.
Following the phishing attempt, the adversary uses Jean-Luc's workstation to dump credentials, then uses those credentials to perform Active Directory discovery. The adversary deploys GPAgentInstaller.exe via PowerShell, flagged as malicious with characteristics of ransomware including high entropy and self-modifying code. Over 1,000 similar alerts have been seen, with a Community Verdict of 96%. The ransomware then attempts lateral movement, deletes local backups, accesses raw volumes, and encrypts files. Alerts include automatic MITRE ATT&CK technique mapping.
For threat hunting, Purple AI scans events and identifies threat intelligence indicators. In this scenario, 1,270 events were scanned and 8 indicators found. SentinelOne provides contextual information on the ALPHV malware family, including associated actors and aliases, and links it to UNC3944.
Purple AI includes a dedicated workspace for hunting and investigation with patent-pending Quick Starts that provide pre-programmed hunting prompts. Analysts can query in natural language; Purple automatically converts these into PowerQueries without requiring knowledge of query languages. Querying Okta authentication events for Jean-Luc returns 34 events showing multiple authentication failures followed by a success. Purple summarizes results and suggests follow-up questions.
Drilling into failed logins reveals 24 failed attempts originating from Chicago and Bogota, Colombia, across multiple IP addresses sharing the same browser version. Querying MFA enrollment activity shows Jean-Luc added two new MFA tokens, a soft token and Okta Verify, within the last 72 hours, confirming compromise of his Okta account by UNC3944.
Purple AI can generate email summaries of investigation findings, including key findings and recommended actions. Summaries can be produced in multiple languages, including Spanish, supporting multilingual SOC teams. Investigation results are saved in Notebooks, which are private by default but can be shared with teammates within the current scope for collaborative review and knowledge sharing.
SentinelOne Singularity platform demo covering alert triage, investigation, threat hunting, and remediation using AI-assisted endpoint and cloud defense.
Open alerts are accessible from the left side menu. Selecting a ransomware alert for GPAgentInstaller.exe shows a natural language summary generated by Purple AI. Static AI identifies a ransomware file on user JeanLuc's desktop. The Graph view displays related entities, alerts, and misconfigurations, revealing that the endpoint TheBorg has multiple related alerts including a Lateral Movement alert. Purple AI summarizes the Lateral Movement alert, noting suspicious file manipulation, execution of malicious shellcode, and correlation to multiple MITRE ATT&CK indicators with severity tags.
The Storyline view organizes all atomic endpoint events into a single narrative describing the full chain of events on an endpoint. Nodes in Storyline can be expanded to show details such as command line arguments and network connections. Alert details include the detection engine that generated the alert, first-seen and last-updated timestamps, and an Alert Footprint showing how many times the malware has been seen across the organization. In this case the malware was first seen in 2024 and has impacted over 2,600 machines.
Singularity Threat Intelligence, an optional add-on, integrates Google Threat Intelligence context. Over 8,000 events were scanned with potential indicators found at 100 risk scores. The RACCOON malware family is identified as data-mining malware targeting Windows, with associated malware families and targeted industries listed. Searching for RACCOON indicators by hash in the Singularity Data Lake returns over 6,700 matching records including behavior indicators, network actions, and registry changes. Purple AI analyzes event properties and generates a summary identifying 9 defense evasion indicators.
Purple AI includes Quick Starts with pre-populated threat hunts and common support questions. Purple AI for Support is an always-on agent trained on SentinelOne technical documentation to answer administration questions. Selecting a hunt for MITRE ATT&CK T1140 (Deobfuscate/Decode Files), Purple AI automatically translates natural language into structured PowerQueries. The query returns 48 matching results in the Singularity Data Lake within the last 72 hours. Purple AI summarizes a selected event, identifying obfuscated PowerShell commands used to execute malicious code while evading detection. Purple AI also provides follow-up question recommendations to continue the hunt. A follow-up query for common T1140 indicators returns 4 results, the most common being suspicious shellcode followed by the obfuscated PowerShell command. Purple AI can generate an email summary of the hunt and supports full multilingual translation for globally dispersed SOC teams. Hunt findings can be saved as a named Notebook and shared with team members for collaborative review.
For remediation, multiple mitigation options are available and can be automated via policy to reduce attacker dwell time. The Kill action stops all running processes associated with the threat. The Quarantine action encrypts and moves threat executables to prevent further infection. The Remediate action deletes all system and file changes including persistence mechanisms. SentinelOne's 1-click Rollback restores files and configurations altered by the attacker, including files encrypted during a ransomware event. Mitigation is applied within milliseconds. Singularity Hyperautomation extends mitigation to third-party tools via customizable automation workflows with over 100 pre-built integrations for SaaS applications.
Alerts can be grouped into Incidents, either automatically through built-in correlation or manually. Incidents provide a higher-level view of all related alerts within an attack campaign and include related artifacts, assets, and all observed MITRE ATT&CK tactics. Incident names are generated automatically upon creation.
SentinelOne Prompt Security is an AI security platform that monitors and controls AI application usage within organizations. Employees commonly use AI tools like Gemini and ChatGPT for daily tasks, but may inadvertently share sensitive data or violate security policies. Prompt Security blocks policy-violating prompts in real-time and redacts sensitive data before it reaches the LLM, allowing employees to remain productive while maintaining compliance.
The platform provides visibility into all AI applications in use across an organization, covering 13,000+ AI applications including AI copilots, chatbots, and embedded AI components, with detection of new AI tools as they emerge.
Administrators can configure AI usage policies with granular controls over specific data types, including PII, financial information, API keys, and cloud access keys. Content moderation settings enforce organizational guidelines, such as restricting discussion of certain topics within AI applications. Rules can specify which applications individual employees or user groups are permitted to access.
All AI-related activity is logged in detail, recording which employee used which application and how. Each interaction can be reviewed individually for compliance and audit purposes.
Deployment is done via a browser extension.
Prompt Security for Agentic AI by SentinelOne is a platform that monitors, inspects, and controls AI agents in real time across an organization's environment. This walkthrough demonstrates how the platform detects and stops an indirect prompt injection attack and provides evidence of the incident.
In the example scenario, a user asks an AI agent to summarize a Notion page. The page contains a hidden indirect prompt injection and hardcoded secrets, invisible to the user and security team, which hijack the agent into executing malicious actions. The agent runs the injected command, and Prompt Security's agentic guardrails flag the activity in real time.
The platform automatically discovers and inventories every agent instance, active user, connector, skills used, and tool calls across the organization. Data is collected via an endpoint agent, browser extension, native plugins, and APIs to provide coverage across the environment.
Each agent has a full activity profile showing every tool call, connector, and permission request mapped across its sessions. For the Claude Code agent used in this example, the console displays active connectors, connected skills, top users, and all executed tools.
The Sessions tab shows every agentic execution path with raw logs and step-by-step processes in chronological order. The Claude Code session from the attack scenario was automatically flagged for two violations: Indirect Prompt Injection (hidden command embedded in the Notion page) and Sensitive Data exposure (exposed secrets).
The session timeline displays the user's original Notion summarization prompt followed by every connected tool and permission request that followed. The two severe violations were caught inside the Notion response before any damage occurred.
An interactive Graph view maps how the user, agent, connectors, and tools interacted to trigger the flagged events. Hovering over any flagged entity in the graph surfaces the exact protections that were triggered, without navigating through additional menus.
AI SIEM by SentinelOne covers three core workflows: threat investigation, threat hunting, and Windows Event Log ingestion.
In threat investigation, SOC analysts start by viewing alerts prioritized by severity. Selecting a concerning alert surfaces an AI-generated threat summary from Purple AI, including destination IP address, protocol details, and malware identification such as Ramnet Malware. Scrolling reveals target asset information and associated threat intelligence. A graph view displays a visual representation of related interactions and can surface correlations, for example linking activity from third-party vendors to a single user. User context such as administrator status is visible without pivoting to other tools. Triage and remediation are handled directly within AI SIEM without requiring a separate SOAR platform. Automated remediation actions include blocking the source IP address in a Palo Alto Networks firewall and sending a Slack notification to the SOC team.
In threat hunting, Purple AI provides guided prompts for analysts who need a starting point. Analysts submit queries in plain English without learning vendor-specific search syntax. Purple AI translates natural language requests into the correct search syntax automatically, executes the search across all connected data sources, and returns a summary of findings including executables, processes, usernames, and operating systems. Follow-up questions can be suggested by Purple AI to refine the investigation. Results can be grouped by attributes such as country to detect unusual patterns. Third-party telemetry from firewalls can be interrogated in the same interface. Anomalies such as unexpected Dropbox activity in specific geographic locations can be identified and investigated by refining the query to focus on that traffic. Pivoting to raw telemetry provides unfiltered log views. Identified threats include details such as hostnames, usernames, and specific ports, enabling actions like pausing Dropbox to mitigate risk.
For Windows Event Log ingestion, configuration is done by selecting a policy under Endpoint and Cloud Workload Security settings. Default settings collect all application, security, system, setup, and forwarded events. Windows Event Log Extended provides the full collection of Windows Events. Policy overrides allow ingestion of specific logs to reduce noise and manage cost. Granular visibility options include Windows PowerShell and Remote Desktop Services logs. Once a configuration is saved, SentinelOne pushes it to the SentinelOne Endpoint Agent, which initiates monitoring and streams logs directly to AI SIEM. Logs can then be filtered and viewed from Event Search.
SentinelOne is a cybersecurity platform that protects Windows, macOS, and Linux devices from ransomware and malware. The platform includes customizable dashboards for monitoring security information in one location.
Agent Installation: Agents can be deployed via a device management tool or installed manually. To enroll a new device, navigate to Agent Management, select a Windows agent installer package, and copy the Site Token, which directs the agent to send security data to the correct management console. After downloading the agent (e.g., version 23.3, 32-bit), run the installer on the target device, paste the Site Token, and complete the installation. Once installed, the endpoint appears as secure in the SentinelOne management console and is visible in the device list.
Inventory: The Inventory section displays all enrolled devices. Selecting a device shows a sidebar with device details, health status, and a list of installed applications across all enrolled devices.
Policy and Configuration: The Policy and Settings section allows configuration of threat detection and response settings, including automated protection and recovery from cyberattacks. Network Control allows creation of firewall rules, such as blocking all traffic to specific domains. Device Control allows creation of rules to block data transfers to USB storage media. Both rule types are created using a step-by-step wizard and applied after saving.
Detection and Investigation: When a malicious file is executed—such as a Word document containing malware-delivering macros—SentinelOne autonomously kills associated processes, quarantines the file and any dropped files, and notifies the user that affected files have been restored. Alerts are presented in a single queue. Selecting an alert displays detailed incident information, file details, detection data, and recommended next steps. SentinelOne maps attacker behavior to the MITRE ATT&CK framework. Threat mitigation is performed autonomously by AI in milliseconds without human intervention.
Singularity Cloud Security is a CNAPP platform combining agentless cloud security posture management, workload protection, compliance monitoring, graph-based attack path analysis, AI-driven alert triage, and security automation.
The Singularity Operations Center serves as the central hub connecting all modules. The Cloud Native Security dashboard provides a high-level summary of cloud risk exposure, including totals for detected misconfigurations, vulnerabilities, and other exposures. Cloud assets can be onboarded from AWS, Azure, GCP, Oracle Cloud, Alibaba, and other providers.
The Inventory section shows a full breakdown of the cloud environment by asset type, including AI/ML resources such as AWS SageMaker and Azure AI Service. The Compliance dashboard supports out-of-the-box frameworks including PCI, HIPAA, and NIST's AI Risk Management Framework. Compliance scores are calculated as the ratio of passed checks to total checks. Findings can be filtered by Controls, Sub-Controls, and other groupings, and the impact of findings on related compliance frameworks is also shown.
Cloud Native Security is the agentless CNAPP component. It includes an Offensive Security Engine that simulates real-world attacks using benign exploit payloads to produce Verified Exploit Paths, identifying which vulnerabilities and misconfigurations are actually exploitable by outside attackers. For example, a misconfigured EC2 instance exposed to remote code execution via Log4j can be validated by pointing a curl command at the instance to confirm the vulnerability is reachable. The same curl command can be used to verify remediation.
The Graph Explorer provides a visual representation of the full attack path, mapping exposures and alerts to connected cloud assets for blast radius and root cause analysis. In the Log4j example, the graph shows the exposed EC2 instance and any alerts triggered as a result, including alerts from the Cloud Workload Security agent. The graph reveals that the Log4j exposure led to a crypto mining attack.
Singularity Cloud Workload Security is the agent-based workload protection component, built on eBPF architecture for real-time detection and response across servers, containers, VMs, and serverless containers. It uses multiple AI detection engines to identify known and unknown threats. The crypto mining alert was detected by the Behavioral AI engine.
Alerts are summarized by Purple AI, SentinelOne's agentic AI security analyst, which provides human-readable explanations of alert origin and recommended next steps. In this case, Purple AI identified that malicious xmrig mining software was executed on the EC2 instance. Purple AI's Auto-Triage capability aggregates similar alerts across the SentinelOne community; in this example, over 1,000 similar alerts were reviewed and 99% were confirmed true positives.
The Storyline feature correlates atomic events into a visual sequence illustrating all malicious activity leading to the alert. In this case, the Storyline shows a Java process spawned due to the Log4j exposure, followed by a bash script executed by that Java process, followed by execution of the xmrig mining software.
Available mitigation actions include killing the process, quarantining files, remediating by deleting files and system changes, rolling back to a saved VSS snapshot (Windows only), and blacklisting the file hash. Detection agents can operate in Detect mode, where actions are taken on-demand, or Protect mode, where mitigation actions execute autonomously in real time.
Singularity Hyperautomation is a low-code/no-code security automation component integrated with Singularity Cloud Security. It allows analysts to build remediation workflows triggered by detections. Available workflow actions include locking down network ingress, creating a pull request to modify Terraform code, and creating Jira tickets for findings of specific severities. Hyperautomation supports 100+ out-of-the-box integrations for building custom workflows.
Singularity Identity provides real-time identity protection and end-to-end visibility across on-premises and cloud environments, covering posture management, identity threat detection and response (ITDR), and conditional access policy enforcement.
Posture Management: The platform surfaces critical identity exposures requiring attention to prevent credential compromise and lateral movement. One example is users with replication permissions, which attackers can exploit to extract password hashes and escalate privileges. Each exposure includes a full overview with blast radius analysis, remediation steps, and affected assets in a single view. Blast radius analysis lists all users in the organization affected by a given misconfiguration. A graph model visualizes the exposure and everything it has touched, providing context about the user and associated misconfigurations. Remediation actions can be taken directly from the console, with options to mitigate, modify mitigation tools, track mitigation progress, and roll back if necessary. Individual exposures can be reviewed continuously to maintain visibility and prevent regression. Mitigation tasks display the objects being targeted and track exposure status per user.
ITDR: Open alerts are accessible from the Alerts section and can be filtered by identity-related detections. Alerts can be grouped by the detection engine that created them. Each alert includes severity, mitigation status, and an attack timeline. Purple AI provides an AI-powered alert summary and a community verdict indicating the likelihood of a false positive. Indicators view shows all suspicious alerts and associated timelines. Reconnaissance activity across the network can be visualized to reveal attacker movement and intent. Alerts can be directly mitigated from the same interface used in posture management.
Conditional Access: Identity policies can be configured for specific risk environments under Policies and Settings. Policy types include identity protection policies, such as one that detects Active Directory enumeration and hides sensitive objects. Conditional access policies can be created per user or per group. Examples include triggering an audit when a verified account uses Remote Desktop Protocol, enabling MFA verification requirements to prevent unauthorized access even when credentials are compromised, blocking Remote PowerShell sessions for users in a specified group, blocking access for known bad users instead of auditing, and blocking specific attack techniques such as DCShadow. Policies are saved and applied going forward.
Singularity Vulnerability Management identifies and reduces risk across an environment by providing visibility into assets, network devices, applications, and vulnerabilities.
The Inventory scans all relevant accounts, workstations, cloud workloads, and identities to show the security state of assets across the environment.
Network Discovery uses active and passive scanning techniques to detect unmanaged and potentially risky devices. Machine learning is used to fingerprint device type and operating system. Devices connected to the network without SentinelOne protection can be identified and filtered. Available actions on these devices include adjusting asset criticality, adding tags and contact information, deploying the SentinelOne agent, or isolating unprotected devices from managed devices.
A real-time application inventory shows all software installed across endpoints. This can be used to identify potentially harmful or unapproved applications. For example, filtering for VPN clients reveals multiple unapproved VPN applications installed across the environment. OpenVPN is present on 27 endpoints across multiple versions, with a breakdown of which endpoints have each version.
Vulnerability prioritization covers 2,100 vulnerable applications including critical and high severity vulnerabilities. The top risky applications are surfaced to show where remediation delivers the most risk reduction. Filtering is available for vulnerabilities actively being exploited by adversaries and for those with high exploit code maturity, which indicates easier access to commodity malware. Applying these filters narrows 2,100 vulnerabilities down to 93 high-impact ones.
Individual applications can be investigated, such as Microsoft Office Professional Plus 2010 with a critical vulnerability, showing which endpoints have the vulnerable version. Singularity Vulnerability Management includes bi-directional integration with JIRA for tracking patching status and SLA compliance. Vulnerability details include CVE description, CVE timeline, temporal risk score, exploit complexity, attack vectors, exploit code maturity, and whether an official fix or proof of concept exists. The scoring is transparent to help explain how each vulnerability was ranked.