SecurityBrief Australia - Technology news for CISOs & cybersecurity decision-makers
Story image
SentinelOne launches AI security analyst Purple AI
Thu, 11th Apr 2024

SentinelOne has announced the launch of its AI security analyst, Purple AI.

This innovative capability is designed to both simplify and expedite threat hunting, investigations, and responses, thereby enabling all sizes of security teams to deliver an elevated level of defence.

This development could be a significant game-changer in the cybersecurity landscape, given that the average enterprise security team reportedly handles more than a thousand alerts every day requiring investigation. Ric Smith, Chief Product and Technology Officer at SentinelOne, noted, "Security teams are overworked and understaffed and in dire need of help to keep pace. With Purple AI, SentinelOne is delivering the industry's most advanced GenAI security technology to help detect threats earlier, respond faster, and stay ahead of attacks in an efficient, scalable way."

From the user's perspective, significant reductions have already been reported in threat hunting time, with early adopters claiming to have achieved up to an 80 percent increase in speed. "The security insights provided by Purple AI have surpassed anything PruittHealth had before," celebrated Richard Bailey, SVP IT at PruittHealth Connect Inc. He went on to say that Purple AI has "enhance[d] accuracy and reduce[d] human error in data queries", freeing up staff to tackle other important tasks.

What makes Purple AI stand out from the crowd is its ability to go beyond the capabilities of a security chatbot or console search box. It radically simplifies threat hunting and investigations by translating natural language into structured queries. In turn, it automatically queries native and partner data and suggests next possible steps in natural language. It also offers security teams capabilities including simplifying complicated queries, finding and mitigating hidden risks in their environment with a single click, and driving down response and investigation times.

The benefits of using Purple AI don't stop there. John McLeod, Chief Information Security Officer at energy solutions manufacturer NOV, Inc coincides by saying, "Purple AI really increases the efficiency of our team that is focused on log management and SIEM use cases. The technology allows them to quickly query data and use suggested next queries and intelligent summaries to get the answers they need in a fraction of the time, reducing our mean time to respond."

NOV Cyber Incident Response Analyst Ryan Mason backed up McLeod's praise, adding, "Purple AI's Notebooks help me save time building and organising EDR queries for IR hunting scenarios... and suggested follow-up questions help uncover quick answers."

Purple AI is now available in all global regions. Its unleashed potential promises to revolutionize security operations and defense strategies across industries and enterprises of all sizes.