SentinelOne Delivers on Autonomous SOC Vision with Introduction of Singularity Hyperautomation, AI SIEM, and New Purple AI Innovation
Cybersecurity leader unveils AI and automation breakthroughs at OneCon 2024, powered by data to transform security operations
Introduced at OneCon 2024, SentinelOne’s premier customer and cybersecurity conference, these new innovations set a new bar for AI, automation and data to make the promise of the Autonomous SOC a reality today:
- Singularity Hyperautomation – No-code automation of security workflows.
-
Singularity
AI SIEM – Ingestion and synthesis of all data from across the security ecosystem. - Purple AI – Automating alert triage, hunting, and investigations.
- SentinelOne’s Ultraviolet Family of Security Models – Large language models (LLMs) and multimodal models designed for cybersecurity AI use cases.
“The future of threat detection and response must keep up with the speed and sophistication of adversaries and the realities facing today’s already overstretched SOC teams,” said
Singularity Hyperautomation – No-Code Automation of Security Workflows
Singularity Hyperautomation is a new intelligent automation solution built to solve for customers’ unique SOC requirements. It empowers customers by offering over 100 integrations and dozens of out-of-the-box workflows designed to address common cyber threats, such as ransomware mitigation, asset compliance monitoring, and response to suspicious user activity and insider threats. Singularity Hyperautomation features a simple, no-code, drag-and-drop canvas for building custom workflows and automating tasks, along with no-code access to any API to leverage data from any security or IT source.
Built directly into the
Singularity
Formally introduced to
Singularity
And with
SentinelOne Purple AI – Automating Alert Triage, Hunting, and Investigations
SentinelOne’s Purple AI security analyst has set the standard for generative AI in cybersecurity since its introduction. Integrated with all aspects of the Singularity Platform, Purple AI translates natural language security questions into structured queries, summarizes event logs and indicators, guides analysts of all levels through complex investigations and scales collaboration with shared investigation notebooks. At OneCon 2024,
New Purple AI Auto-Alert Triage prioritizes top alerts and helps to quickly prioritize which alerts need further investigation. Auto-Alert Triage harnesses new Global Alert Analysis to assess thousands of anonymized similar alerts to better determine true positives, and surfaces prioritized ‘Alerts to Investigate’ to reduce alert fatigue and give security teams time back to focus on the most critical tasks that reduce risk.
Purple AI can now also be used to kick off and run autonomous investigations to fast track investigations and response. With the new Purple AI Auto-Investigations capability, Purple AI will take prioritized alerts, automatically compile a list of investigation steps based on the alert in question, independently run the steps and generate a recommended verdict. Evidence collected in the investigation is saved in an auditable and collaborative Purple AI investigation notebook to significantly shrink investigation and reporting times, while giving SOC teams and incident responders the advantage of speed and scale when addressing critical threats.
Introducing SentinelOne’s Ultraviolet Family of Security Models
Over the past three years, the costs of large general purpose multi-modal models have been driven down substantially, while the capability of these models has significantly increased. For cybersecurity-related generative AI applications, these models, coupled with extensive domain knowledge, have proven to be the best approach to building genuinely useful assistant experiences in the security domain. However, there remains areas of cybersecurity-related AI where proprietary models will have decisive advantages.
At OneCon 2024,
Ultraviolet will complement the best general purpose models, focusing specifically on unique areas like improving detection efficacy by enabling more context to be considered in real time and improving efficiency of reasoning about security problems to enable greater autonomy where better tuned models stay on task and require substantially fewer tokens to arrive at useful conclusions.
About
View source version on businesswire.com: https://www.businesswire.com/news/home/20241016072414/en/
Media Contact:
Press@sentinelone.com
Source: