SentinelOne has announced new capabilities within its Singularity Platform designed to democratize advanced cybersecurity operations. The company unveiled the capabilities, which make top-tier Security Operations Centers (SOC) a reality for companies of all sizes, at RSA 2024.
“Imagine a future where security solutions not only help enterprises respond to threats, but anticipate and mitigate them before they lead to a security incident. This is the future we are creating at SentinelOne,” said Tomer Weingarten, CEO of SentinelOne. “Our solutions are designed to transform how security teams manage the complexity of their environments and defend threats. With our latest innovations, customers can move from the reactive operating paradigm of today and enable a predictive and autonomous future.”
With today’s news, SentinelOne is democratizing cybersecurity through AI and automation, enabling every enterprise to operate at the same scale, speed and sophistication, regardless of budgets and resources. When combined with the visibility of the Singularity Platform and the breadth and scale of the Singularity Data Lake, Purple AI provides an always-on, expert analyst to augment the skills of any security team and supercharge their capabilities.
“It’s no secret that security teams are overwhelmed with data, alerts and labor-intensive triage,” said Ric Smith, Chief Product and Technology Officer, SentinelOne. “Purple AI doesn’t just do what you ask it to, it does what you need it to.”
Beyond a chatbot or virtual assistant, Purple AI is an advanced AI security solution that not only creates complex data queries from natural language, but anticipates what security analysts need to do and recommends next steps. Key features demonstrated and in use today include:
- AI-powered anomaly detection: Purple AI surfaces correlated risks from integrated log sources.
- Automated alert triage: The technology analyzes trillions of anonymized data signals at a global scale to evaluate how security analysts assess and respond to similar alerts and provides automated verdicts and recommended actions.
- AI-powered response recommendations and hyper automation rules: Using global similarity analyses, Purple AI provides intelligent response recommendations based on how others have responded to similar alerts and smart recommendations to turn those actions into hyper automation rules to put response actions in autonomous mode.
- 24/7 Auto-investigations: Through zero-touch auto-investigation capabilities, Purple AI eliminates the need for human-driven investigations and empowers security teams to focus on validating and mitigating threats at scale.
- Mandiant Threat Intelligence: Building on our existing OEM partnership, the Singularity platform integrates leading threat intelligence from Mandiant (part of Google Cloud) to provide the latest and most comprehensive securityinsights. This includes detailed adversarial TTPs, enrichment of all security alerts and enhancing threat hunting capabilities. Intelligence will also be accessible through Purple AI, boosting the platform’s proactive and automated functions in private preview later this quarter, with general availability later this year.
All current and future Purple AI capabilities are deeply embedded across the Singularity Platform and accessible via a new unified security console, the Singularity Operations Center.
“For years, security vendors have claimed unified dashboards and a single pane of glass. SentinelOne’s Singularity Operations Center delivers on that promise and represents a massive leap forward in simplifying the analyst experience by unifying alert triage and workflows across all event collections,” Smith said.
Now generally available, the Operations Center consolidates security management with unified alerts, inventory management, correlation engine, and a contextualized Singularity Graph to accelerate detection, triage, and investigation.
“For the first time, security analysts of any level can benefit from the tools, velocity, and performance once reserved for the largest organizations and budgets,” Smith added.
Both Purple AI and the Singularity Platform have the unified Singularity Data Lake at their core. Built on the Open Cybersecurity Schema Framework (OCSF), source telemetry is rapidly ingested from any source, normalized, processed, and stored with critical issues escalated for analyst attention.
“Having all of the data is one problem. Being able to process it fast enough to find the insights with enough time to action them is something else entirely,” Smith said. “The combination of the Singularity Data Lake and Purple AI removes much of this burden through automation, empowering the SOC to focus on the most critical task – keeping the organization safe.”
Democratizing the SOC
And analysts see it as game changing.
“The combination of AI, data and autonomous capabilities in a single platform is powerful,” said Steve McDowell, Chief Analyst, NAND Research. “Generative AI gives you a window into everything that’s happening across your environment and allows you to have a real, data-driven conversation with your infrastructure. Combining that with a unified data lake and platform-driven approach can accelerate and simplify how you protect the enterprise.”