SecurityBrief Australia - Technology news for CISOs & cybersecurity decision-makers
Australia
SentinelOne adds OpenAI GPT-5.6-Cyber to AI services

SentinelOne adds OpenAI GPT-5.6-Cyber to AI services

Wed, 9th Sep 2026 (Today)
Sean Mitchell
SEAN MITCHELL Publisher

SentinelOne has expanded its Wayfinder Frontier AI Services with OpenAI Daybreak models, adding OpenAI's GPT-5.6-Cyber to its existing lineup.

The expansion also introduces two new service areas: AI-Powered Code Risk Analysis and AI-Enabled Compromise Assessment. The additions are intended to bring frontier AI models into security workflows that examine software code, suspicious files and signs of intrusion across customer environments.

The announcement reflects a wider shift in cyber defence as vendors and corporate security teams test how newer AI models can be used in day-to-day operations. The focus is moving beyond broad vulnerability lists to identifying which weaknesses are actually reachable and exploitable in a given environment.

Under the code risk analysis service, SentinelOne scans customer code repositories for OWASP-class flaws, code implants, exposed secrets and supply-chain risks. The service is designed to produce a validated view of which vulnerabilities an attacker could realistically access.

If a scan identifies a potentially malicious sample, the workflow supports disassembly and deobfuscation, combining static and sandbox evidence to assess the sample's behaviour, persistence and command-and-control functions. Each verdict includes indicators of compromise, MITRE ATT&CK mapping and recommended detections for the wider fleet, with findings validated by SentinelOne's offensive security analysts.

The compromise assessment service uses telemetry and detection rules to identify posture gaps, including potentially risky use of VPNs, proxies, remote management tools and other dual-use software. The process is intended to reduce hours of manual review by using AI for triage before analysts validate the findings.

When triage flags a suspicious sample, the same malware analysis process is used to examine what the software does and estimate its possible scope and impact. Customers then receive a findings package ranked by real-world exploitability, according to SentinelOne.

SentinelOne said it has evaluated public and private AI models against cyber tasks through its AI security and AI research teams as part of its work in the Daybreak Defence Network, OpenAI's cyber defence initiative. In internal benchmarking, SentinelLABS, the company's research arm, found that GPT-5.6-Cyber performed strongly in reverse engineering and the analysis of military-grade malware.

The company is positioning the services around a central problem for security teams: not a shortage of alerts, but difficulty determining which exposures matter most. Traditional prioritisation methods often generate large backlogs, while defenders face pressure to distinguish between theoretical weaknesses and those that can be used in active attacks.

That issue has become more pressing as attackers use AI tools to speed up parts of reconnaissance, code analysis and exploitation. For defenders, the commercial question is whether newer AI systems can reduce the time and labour needed to investigate threats without adding noise or creating new governance risks.

Steve Stone, Chief Customer Officer at SentinelOne, linked the launch directly to that imbalance. "Attackers are increasingly using AI to find and exploit weaknesses with greater speed and scale," Stone said. "Our job is to help close that gap for customers by putting the most advanced models available in the hands of our elite experts to home in on the areas most likely to be attacked. In our testing, OpenAI's GPT-5.6-Cyber has already proven to be exceptionally good at malware analysis, code risk assessments and other offensive cyber capabilities, making it a perfect fit for Wayfinder Frontier AI Services and our customers."

The services are generally available, while the new functions and expanded model lineup featuring OpenAI Daybreak models are being introduced in private preview ahead of wider access. SentinelOne said the services use models selected for specific security tasks rather than relying on a single system for every workflow.

The approach underlines a broader pattern in cybersecurity, with suppliers beginning to sort AI tools by narrower operational uses such as malware analysis, threat triage, code review and compromise assessment. It also shows how model providers and security vendors are tightening their links as businesses look for ways to introduce advanced AI into security operations while keeping human oversight in place.

SentinelOne said the new services pair frontier AI models with its offensive and defensive security teams so customers receive prioritised remediation guidance rather than a larger backlog.