What SentinelOne Purple AI does
Purple AI is SentinelOne's security reasoning layer for threat hunting, evidence correlation, attack timelines, agentic investigation, recommendations, and policy-driven response.
Purple AI acts as the reasoning interface across SentinelOne's Singularity platform. It converts natural-language questions into threat hunts, explains security concepts and results, correlates telemetry, builds attack timelines, and recommends next steps. Agentic Investigation can initiate work automatically, gather evidence across endpoint, identity, cloud, and third-party signals, and deliver a verdict with an evidence chain. Integration with AI SIEM and Hyperautomation can carry a validated conclusion into containment or remediation workflows.
SentinelOne introduced Singularity Credits in June 2026 as the shared usage currency for AI-powered work, including Purple AI Agentic Investigation. Existing customers received a complimentary trial allocation, but SentinelOne does not publish a universal ongoing dollar rate in the reviewed materials. Platform tier, protected endpoints or workloads, data ingestion and retention, SIEM, cloud and identity modules, credits, support, and response services shape the quote. Teams should demand a credit-consumption model and pilot normal and incident-surge workloads before enabling automatic investigations broadly.
An auditable evidence chain makes review possible; it does not make a verdict infallible. Purple AI may correlate unrelated events, miss unavailable telemetry, accept a poisoned signal, or label unusual administration malicious. SentinelOne allows adjustable human-in-the-loop autonomy and says activation is admin-controlled, role-based, reversible, and governed by consumption controls. Start with analyst-initiated read-only hunts, restrict automated response to narrow well-tested cases, validate every verdict against raw events, and require approval and rollback for host isolation, process termination, account changes, or deletion.
How SentinelOne Purple AI works
Purple AI reasons over telemetry already present in Singularity, including endpoint, cloud, identity, AI SIEM, and configured third-party data. Analysts ask natural-language questions or enable agentic investigation, which collects and correlates evidence, constructs a timeline, and produces an auditable verdict. Policies can recommend or trigger response according to administrator-controlled autonomy and role permissions.
Unify available security evidence
Purple AI operates on Singularity endpoint, cloud, identity, AI SIEM, and configured third-party telemetry. Data quality, coverage, normalization, retention, and roles constrain every conclusion.
Hunt and build an attack timeline
Natural-language or automatic investigations collect relevant signals, correlate events, test hypotheses, and produce a verdict with an auditable evidence chain.
Challenge the agentic verdict
Analysts inspect raw events, asset and change context, benign explanations, missing sources, and false-positive history. A complete trace supports review but does not guarantee truth.
Apply policy-driven response
Configured workflows recommend or execute containment and remediation under adjustable autonomy. Use approval, rollback, credit limits, audit logs, and reversible activation.
How to set up SentinelOne Purple AI
Define telemetry and response scope
Inventory endpoints, cloud, identity, SIEM, third-party sources, retention, incident classes, service accounts, actions, approvers, and evidence requirements.
Price platform and credits
Confirm Singularity modules, endpoints, ingestion, retention, support, incident services, included and overage credits, consumption reporting, regions, and renewal.
Configure roles and autonomy
Restrict activation, data access, hunting, workflow editing, and response actions; set credit, loop, duration, and downstream action limits by environment.
Benchmark agentic investigations
Replay true positives, false positives, benign admin behavior, incomplete and duplicated telemetry, adversarial artifacts, cross-tenant boundaries, and tool failure.
Stage production response
Begin with read-only verdicts, require analysts to inspect evidence, add approval and rollback, monitor credits and overrides, and expand autonomy only from measured results.
SentinelOne Purple AI FAQs
How much does Purple AI cost?
Purple AI uses Singularity Credits, with complimentary trial allocation announced for customers. Ongoing pricing depends on platform, data, modules, credits, and contract.
What is Agentic Investigation?
It can autonomously collect and correlate Singularity telemetry, construct an attack timeline, produce a verdict, and attach an auditable evidence chain.
Does Purple AI send data outside Singularity?
SentinelOne says Agentic Investigation runs on telemetry already in the platform and that no data leaves the platform for that capability. Verify model and region terms contractually.
Can Purple AI respond without an analyst?
Administrators can configure policy-driven autonomous response, but SentinelOne also supports adjustable human oversight. High-impact actions should require approval and rollback.
How should teams handle false positives?
Inspect the full evidence chain and raw telemetry, compare with asset and change context, record overrides, tune policies, and keep unusual or high-impact cases human-controlled.
Listing reviewed 2026-07-15. Product details and pricing can change; verify important terms on the provider's website.
Related Productivity AI tools
Related AI guides
Reviews
Tell the community what you made, what worked, and what you wish you knew before starting.