Cybersecurity

A beginner’s guide to SentinelOne’s Purple AI

SentinelOne's Purple AI uses multi-model AI to reduce investigation times from hours to seconds. Security teams using these tools report 63% faster threat identification and 55% faster resolution through autonomous investigation capabilities.

A beginner's guide to SentinelOne's Purple AI

Autonomous Investigation Capabilities

SentinelOne opened Purple AI Agentic Investigation to all Singularity Platform customers. This capability uses a multi-model approach combining Claude and GPT models with proprietary Ultraviolet models to condense investigations. The system triggers "zero-click" investigations when threats cross a defined threshold. It operates on telemetry from endpoint, identity, cloud, and third-party security data already inside the platform. Analysts receive a verdict with a full evidence chain rather than starting with a raw alert. This capability runs on telemetry already in the platform across endpoint, identity, cloud, and third-party security data to detect, investigate, verify, and respond to threats at machine speed. Purple AI contains an MCP Server to allow external AI frameworks and applications to build on its capabilities. The software gathers evidence and ties telemetry together to lay out the attack timeline. It reduces investigation time from hours or days into minutes or seconds. Purple AI acts as the reasoning brain and interface for the entire Singularity Platform to simplify querying and recommend actions.

Deployment and Singularity Credits

The platform uses Singularity Credits to meter AI-powered work across the Singularity Platform. These credits provide a flexible, unified currency for all AI-driven activity. Customers access a complimentary allotment of credits to trial the new investigation capability. During this trial, customers use credits without incurring charges or providing a payment method. After the trial period, users purchase credits through direct billing or via e-commerce platforms. The Singularity Credits system allows for consumption guardrails so admins control usage through daily auto-trigger caps that bound the number of investigations based on threat volume and endpoint count. Customers define the level of autonomy through an adjustable human-in-the-loop approach. Verdicts can trigger automated, policy-driven responses or prompt an analyst with recommended actions. You should understand that the platform requires Singularity Complete to access Purple AI.

Feature Detail
Singularity Complete List Price \$179.99/endpoint/year
Negotiated Price (200-2,000 endpoints) \$135-\$153/endpoint
Trial Access No payment method required
Warranty \$1M

The product ships within the Singularity Complete tier. Negotiated deals for 200 to 2,000 endpoints typically land between \$135 and \$153 per endpoint.

Operational Impact and Comparisons

Security teams report 63% faster threat identification and 55% faster resolution when using these tools. This automation provides a force multiplier for every analyst. It scales a team’s investigation capacity without a headcount increase. Every investigation that resolves autonomously provides 20 to 30 minutes of analyst time back. Analysts shift their focus to judgment and threat hunting decisions that require human intervention. The platform uses telemetry from endpoint, identity, cloud, and third-party data to deliver verdicts that an analyst can act on autonomously to stop threats. SentinelOne’s Wayfinder MDR centers on Purple AI Athena for automated triage and investigation. The platform includes a unique Windows Rollback that restores endpoints after ransomware occurs. While Arctic Wolf only contains threats through host isolation or account disablement, SentinelOne kills processes and quarantines files. Arctic Wolf requires customers to buy Aurora Managed Endpoint Defense and a Security Operations Bundle for a \$3M warranty, while SentinelOne provides a \$1M warranty. SentinelOne also pulled out of the 2025 MITRE evaluation to prioritize product and engineering resources for its platform roadmap. False positive tuning remains a top complaint in 2026 reviews. The platform acts as an autonomous investigation engine for the modern SOC because it automates investigation. Can the platform maintain this speed as more customers adopt the agentic model?