The AI cybersecurity leader unveils the new generation of Purple AI and defines the guidelines for the creation of the first complete Agentic AI cybersecurity platform
SentinelOne (NYSE: S), a global leader in AI-powered cybersecurity, today introduced the next generation of Purple AI – the Purple AI Athena release – which delivers the first Agentic AI capabilities that accurately replicate the security reasoning and sophisticated orchestration of experienced SOC analysts. The innovations, showcased at RSA Conference 2025, build on Purple AI's native Agentic capabilities and enable already overworked SecOps teams to automate and dramatically accelerate end-to-end threat triaging, investigation and response work. The Purple AI Athena release also enables Purple AI access to third-party SIEM platforms and data lakes, bringing the full power of SentinelOne's Agentic AI and automation to all of your modern SOC's security data, wherever it resides.
Since the first presentation at RSA Conference 2023, Purple AI leveraged the support of its own Agentic AI and a proprietary Agentic AI framework to meet the needs of cybersecurity teams around the world. SentinelOne continued to build on this Agentic framework and the experience gained in the field, introducing Agent-based innovations such as Purple AI Auto Triage and Purple AI Auto Investigate, presented in October 2024 at SentinelOne's OneCon event.
The Purple AI Athena release was unveiled and tested at the RSA Conference 2025 and is part of SentinelOne's broader Agentic AI strategy designed to deliver three core sets of AI and automation capabilities, such as:
- Deep security reasoning at machine speed – The Purple AI Athena release reflects the iterative thinking and deductive reasoning of the most experienced SOC analysts. By drawing on Purple AI's security models and Agentic framework, Athena can intelligently perform comprehensive investigations of suspicious activity across multiple sources, orchestrate multi-phase response actions, and remediate threats in seconds rather than hours. Such organic security reasoning is perfected by the combination of advanced neural networks working on trillions of security-relevant data points, along with an extensive human feedback loop made up of a global network of elite security professionals. The result is a self-contained level of SecOps that allows you to scale overloaded teams and dramatically reduce mean time to response (MTTR). Purple AI Auto Triage, available this week, leverages deep security reasoning to autonomously conduct AI similarity analysis on alerts to identify similar threats and determine the likelihood of a positive outcome for prioritization purposes.
- Remediation and full-loop response with hyperautomation – Purple AI's Agentic AI system leverages Purple AI's automated, no-code workflow capabilities Singularity Hyperautomation di SentinelOne to define new detection rules and transform the insights of automatic agentic investigations into autonomous, full-loop work. Purple AI's Auto-Triage and Agentic Auto-Investigation capabilities provide summaries of findings and processes, and suggest the ability for analysts to convert individual activities, responses, and insights into hyper-automation workflows. The agentic system investigates and resolves alerts and learns over time to independently resolve problems on behalf of analysts. As a result, security teams can move beyond rudimentary rules-based automation and automate fully integrated investigations and responses.
- Seamless and independent integration from any data source – With the Purple AI Athena release, SecOps teams can directly access third-party SIEMs, security data lakes and other security data sources, leveraging the full power of Purple AI intelligence, the Agentic framework and SentinelOne Singularity platform automation for all security data in the SOC. Alerts are captured and correlated immediately, and from there Purple AI applies real-time streaming analytics and full-loop remediation. This way SentinelOne Singularity customers can avoid costly migrations or intermediary pipelines, benefiting from instant time to value and immediate security outcomes across the entire environment.
The value of Purple AI – Agentic data right from the start, tested in production environments
The widespread production adoption of Purple AI over the past two years has allowed SentinelOne to develop highly sophisticated, security-specific models based on real-world use cases. This is strengthened by SentinelOne's sophisticated sensor architecture, designed for granular, customer-specific fine-tuning of telemetry data transmitted directly from endpoints and cloud workloads, and seamlessly integrated into the cloud-native data pipelines of SentinelOne's AI SIEM. The result is a large and unique dataset that is continuously refined, refined and optimized through a closed feedback loop comprised of SentinelOne's elite MDR team and extensive global network of world-class MDR partners.
With the Purple AI Athena release, SentinelOne leverages this proprietary foundation to execute the most comprehensive set of sophisticated agentic AI workflows in the cybersecurity industry. The Purple AI Athena release will expand Purple AI's agentic capabilities to provide: AI-powered data integrations, automatic threat hunting and detection, automatic triage and investigations, processing of new detection rules, automatic response and reporting, and AI-powered assistance.
"AI and automation have long promised to radically transform security practices and enhance analysts' ability to detect and respond – at machine speed – to threats from even the most sophisticated nation-state hackers and cybercriminals. At RSA we presented the first truly end-to-end agentic AI cybersecurity platform, built on more than a decade of security experience, and we bring it to all the security data of the modern SOC," said Tomer Weingarten, co-founder and CEO of SentinelOne. “Thanks to the automation and orchestration of Agentic AI, capable of thinking and responding like an expert security analyst, we believe that humans are valued even more when they take on oversight of these systems, an important role that will also shape the next generation of security service providers.”






