SentinelOne announced new capabilities within its Singularity Platform designed to democratize advanced cybersecurity operations. The company unveiled the capabilities, which make top-tier Security Operations Centers (SOC) a reality for companies of all sizes, at RSA 2024.
With today?s news, SentinelOne is democratizing cybersecurity through AI and automation, enabling every enterprise to operate at the same scale, speed and sophistication, regardless of budgets and resources. When combined with the visibility of the Singularity Platform and the breadth and scale of the Singularity Data Lake, Purple AI provides an always-on, expert analyst to augment the skills of any security team and supercharge their capabilities.
Beyond a chatbot or virtual assistant, Purple AI is an advanced AI security solution that not only creates complex data queries from natural language, but anticipates what security analysts need to do and recommends next steps. Key features demonstrated and in use now include:AI-powered anomaly detection: Purple AI surfaces correlated risks from integrated log sources.
Automated alert triage: The technology analyzes trillions of anonymized data signals at a global scale to evaluate how security analysts assess and respond to similar alerts and provides automated verdicts and recommended actions.
AI-powered response recommendations and hyper automation rules: Using global similarity analyses, Purple AI provides intelligent response recommendations based on how others have responded to similar alerts and smart recommendations to turn those actions into hyper automation rules to put response actions in autonomous mode.
24/7 Auto-investigations: Through zero-touch auto-investigation capabilities, Purple AI eliminates the need for human-driven investigations and empowers security teams to focus on validating and mitigating threats at scale.
All current and future Purple AI capabilities are deeply embedded across the Singularity Platform and accessible via a new unified security console, the Singularity Operations Center.
Now generally available, the Operations Center consolidates security management with unified alerts, inventory management, correlation engine, and a contextualized Singularity Graph to accelerate detection, triage, and investigation.
Both Purple AI and the Singularity Platform have the unified Singularity Data Lake at their core. Built on the Open Cybersecurity Schema Framework (OCSF), source telemetry is rapidly ingested from any source, normalized, processed, and stored with critical issues escalated for analyst attention.