Generative AI Security Analyst accelerates cybersecurity investigations and simplifies threat hunting across a growing number of native and third-party software
SentinelOne (NYSE: S), announced another innovation in the field of generative artificial intelligence and cybersecurity: the award-winning Purple AI The company's security analyst can now work with data from a growing list of popular third-party security solutions. The first supported products include the Zscaler Zero Trust Exchange™ platform, Palo Alto Networks Firewall, Okta, Proofpoint TAP, Fortinet FortGate and Microsoft Office 365. It is the latest innovation from SentinelOne that benefits from the advanced capabilities of Singularity™ Platform across data and AI, and extends the speed, power and value of Purple AI to rapidly counter today's increasingly sophisticated attacks.
The company also introduced multi-language support for Purple AI, expanding the popular English-language version with new support for natural language queries and summaries in Spanish, French, German, Italian, Dutch, Arabic, Japanese, Korean, Thai, Malay, Indonesian and more.
"Purple AI has quickly become SentinelOne's fastest-growing product, and customer feedback has been incredible. It's much more than just a natural language query tool, and Purple AI is automating investigations, prioritizing threats, and reducing response times from hours to minutes," said Ely Kahn, Vice President, Product Management, Cloud Security, AI/ML and Core Platform at SentinelOne. “By expanding Purple AI capabilities to native and third-party data in Singularity, customers can quickly block even the most sophisticated attacks, gaining more value from the entire security stack and the security data collected.”
Excessive alert volumes, multiple data sources, increasingly sophisticated threats and expanding attack surfaces are driving undetected incidents and complex investigations. Inhomogeneous data algorithms lead to limited visibility and threats that go undetected. Additionally, increasingly rapid attack paces too often put security teams at a disadvantage in stemming lateral movement before the damage is done.
Purple AI simplifies the data collection process for security teams, enabling easier and more complete threat detection while accelerating investigations and response. He is the only GenAI security analyst in the industry who leverages the Open Cybersecurity Schema Framework (OCSF) to query data that has been normalized at the time of data ingestion. As a result, customers benefit from immediate querying of native and third-party data, correlation and context across the security stack, and scalability across ever-expanding data sources for faster, more complete investigations.
For example, take joint SentinelOne and Zscaler customers, who can easily ingest Zscaler Security Service Edge (SSE) logs into the Singularity platform via an out-of-the-box integration available on the Singularity Marketplace. With this integration, which is configurable, customers can use Purple AI to search user activity or threat logs, zero trust or data protection policy violation logs, and streamline investigations into security events spanning network, endpoint, cloud, and identity data, using simple natural language queries such as:
- “Using Zscaler logs, how many users accessed cloud applications?”
- “Show me Zscaler logs where users downloaded malware”
- “Are any DLP violations detected in the Zscaler logs?”
- “Are there users making FTP file transfers in the Zscaler logs?”
“With Zscaler's extensive telemetry, the integration with SentinelOne significantly improves SOC teams' abilities to leverage AI for threat detection and complex investigations,” commented Amit Raikar, Vice President, Technology Alliances and Business Development at Zscaler. “Together, we are committed to helping customers enhance zero trust security in an increasingly complex risk environment, where it is critical to close security gaps with unprecedented speed and ease.”






