Self-initiated, zero-configuration investigations run within customers' existing Singularity™ platform workflows, detecting, analyzing and countering threats at machine speed. In this way, each analyst has the multiplier effect, supported by a complete set of evidentiary data to support every decision
SentinelOne (NYSE: S), a global leader in AI-powered cybersecurity, is making it available to customers Purple AI Agentic Investigation and introduces Singularity Credits, a common currency unit for managing AI-based assets from the Singularity platform. Starting this week, customers can request a free trial of the functionality of Purple AI, SentinelOne's autonomous detection system for the Agentic SOC. This functionality — autonomously initiated zero-click investigations — detects, investigates, verifies and responds to threats without depending on human intervention. When a threat exceeds a predefined threshold, Purple AI investigates, makes a judgment, and blocks it at machine speed, while analysts maintain full visibility and control.
The innovation comes at a time when teams face a critical limitation, not in detection, but in investigative capabilities. Detected cases increase with each new tool and expansion of the attack surface, alerts accumulate waiting to be examined and assessments depend on the availability of analysts, with coverage reducing at night, on weekends and during periods of increased activity. Threats based on the most advanced AI are set to further widen this gap.
“Today, security leaders must manage more critical alerts than any one team could review, and AI-based threats make the situation worse,” said Chris Corde, Chief Product Officer at SentinelOne. "The scope of investigations has become the restrictive limit of the modern SOC: detections increase, alerts accumulate and decisions depend on the availability of analysts. Purple AI's Agentic Investigation functionality is designed to eliminate this limit, making investigations automatic, continuous and immediate."
Why SOC teams are adopting Purple AI Agentic Investigation
- Seamless integration: no setup, up and running from day one
Purple AI is integrated into the Singularity platform, it is not simply add-on. The new Agentic Investigation functionality builds on the telemetry data already present in the platform, which includes endpoint, identity, cloud and third-party security data, as well as being integrated into the automated workflows already used by customers. You don't need to implement, integrate or optimize anything, and no data leaves the platform. Activation occurs with just one click.
- A force multiplier for every analyst
Purple AI dedicates itself to investigative work, collecting evidence, correlating telemetry data and reconstructing the history of the attack, thus allowing analysts to start directly from the final opinion rather than just the alert. Increase a team's investigative capacity without increasing headcount and free analysts to focus on assessment, threat hunting and response decisions that require human intervention. It is designed as an extension of the analyst: it enhances human defenders, without replacing them.
- Fully verifiable — controlled autonomy, no black box
Every decision is accompanied by complete, verifiable documentation, so analysts can confidently review every AI step and outcome. Customers define the degree of autonomy through an adjustable “human-in-the-loop” approach, which adapts to their level of trust and the maturity of the SOC. The results can trigger automated policy-based responses or suggest recommended actions to the analyst. Activation is administrator-controlled, role-based and reversible at any time, while consumption limits keep usage and downstream costs under the control of those with the necessary authority.
- Based on the most advanced reasoning models in the field of cybersecurity
Purple AI is the thought engine and interface of the entire Singularity platform. Harness the power of advanced, cutting-edge AI models that offer human-like reasoning through a multi-model approach that combines Anthropic's Claude, OpenAI's GPT and SentinelOne-owned “Ultraviolet” models to reduce investigations that once took hours or days to a few minutes or seconds. In the case of critical threats, investigations launch automatically and provide results that can be managed independently or by an analyst.
The introduction of Singularity Credits
Singularity Credits are a flexible currency that customers can use for AI-powered activities in the Singularity platform, including Purple AI Agentic Investigation. To get started, SentinelOne is offering customers free credits to try out the feature.
Create the “agentic” SOC by strengthening defenders, not replacing them
Agentic Investigation advances SentinelOne's vision of the “agentic” SOC: an environment where advanced AI reasoning empowers and enhances human defenders rather than sidelining them. Purple AI acts as the brain and interface for the platform, simplifying queries, suggesting actions, and autonomously detecting and blocking threats. Because it operates natively on third-party AI, endpoint, identity, cloud and telemetry data already present in the Singularity platform, it makes Singularity an agent of the “integrated security operations center” category (ISOC) defined by Gartner.
Availability and accessibility
The trial version of Purple AI Agentic Investigation is already available on the Singularity platform consoles. Both new and existing Singularity customers can join the initiative and immediately start running agent investigations. During the trial period, surveys use Singularity Credits, but customers are not charged and no payment method is required. After the trial period ends, customers can purchase Singularity Credits through partners, direct billing and e-commerce.






