SentinelOne - Experts & Thought Leaders
Latest SentinelOne news & announcements
Tenable® Holdings, Inc., the exposure management company, launches the CyberAgents Exchange, a new open-source AI exchange created to foster industry collaboration and improve collective cyber defense. The CyberAgents Exchange, powered by Tenable, is the only purpose-built, cybersecurity-native registry for AI agents, skills, MCP servers and multi-agent playbooks in the current market. Security teams are increasingly turning to AI to scale security operations and manage risk overload, but end up building AI agents in isolation, repeatedly reinventing the wheel. Existing AI exchanges are either general-purpose or vendor-gated, forcing security teams to wade through irrelevant use cases, waste time on duplicate design and build efforts, or accept restrictive vendor lock-in. To improve the cybersecurity industry’s collective defense and outpace AI-generated threats, defenders need a unified, cyber-specific hub to accelerate development and share collective agentic tooling. Peer-supported AI components The CyberAgents Exchange eliminates these development silos and empowers industry collaboration with a truly open, free-to-use exchange. Built for trust and transparency, the Exchange provides code-level visibility into who built each AI component, when it was created and its peer-supported status. This transparency enables members to deploy AI components tailored to their specific organizational needs confidently. Additionally, the Exchange is a career asset for practitioners to build verifiable expertise in an emerging discipline and develop a catalog of peer-supported AI components. Autonomous security operations "The CyberAgents Exchange fills a major and pressing industry need, especially as cybersecurity remains a growing issue and AI-enabled attacks rise," said Seth Fogie, Director of Security for Baptist Memorial Health Care. "Its core philosophy of working together is what made the threat intelligence community so invaluable. My team has benefited greatly from the Exchange, and we look forward to contributing and collaborating with the wider community." Underscoring the industry’s commitment to collaborative, open-source AI defense, industry pioneers SentinelOne and Recorded Future have joined the initiative as founding members of the CyberAgents Exchange. By contributing their deep expertise in autonomous security operations and threat intelligence, these industry pioneers will help anchor the Exchange as a truly unified, vendor-agnostic ecosystem. As founding members, both organizations will actively contribute secure AI agents, integration frameworks and playbooks to accelerate the community's defense capabilities against rapidly evolving AI-driven threats. Open-source security agents In conjunction with the launch, Tenable is hosting “SWARM: The Cybersecurity Agentic AI Build Event,” a hands-on, multi-day event at Black Hat USA 2026 sponsored by AWS and presented with support from Anthropic. At the event, security practitioners will build open-source security agents, skill files or MCP servers. Winners will be announced on Thursday, August 6, 2026. More than 50 AI components, released under open-source licenses, are available, including: Navi (Agent): A command-line tool that leverages the Tenable One Vulnerability Management APIs to automate common vulnerability management and cyber exposure workflows. SentinelOne Purple AI (MCP Server): Allows users to access SentinelOne services with any MCP client. Recorded Future MITRE APT Attack Path Analysis (Skill): Pulls an organization’s Recorded Future threat map, maps an APT group's MITRE ATT&CK techniques and cross-references against live Tenable findings to identify which attack path nodes are actively exploitable. SOC-Hunter (Skill): Leveraged daily by Tenable’s internal security operations team, SOC-Hunter provides proactive, hypothesis-driven threat hunting using the LOCK pattern across SIEM, EDR, VM, CSPM, CASB and code search. The Hounds Pack (Playbook): A skill-packaged playbook for The Hounds — 18 exposure-management specialists that hunt, tag and calibrate risk. Outpace modern adversaries “Security is a team sport. We’ve addressed a gaping hole in the ecosystem of AI Agents, built for defenders, by defenders. With the CyberAgents Exchange, we’re creating a collaborative 'town square' where cybersecurity practitioners can build, test, improve and share the best in agentic defense,” said Vlad Korsunsky, Chief Technology Officer, Tenable. “With our deep roots in the open source community and our global ecosystem of customers and partners, Tenable is uniquely positioned to steward this collaborative effort to help scale security teams' capabilities and outpace evolving threats.” "To truly scale defences against autonomous, AI-driven threats, the security community must move past isolated development and vendor-locked silos," said Braden Preston, vice president of product management, SentinelOne. "As a founding member of the CyberAgents Exchange, SentinelOne is proud to champion a transparent, open-source foundation for agentic security. By sharing trusted, autonomous components and collaborative playbooks, we are empowering security teams globally to innovate faster, defend smarter and outpace modern adversaries together." Open-source community "Joining the CyberAgents Exchange as a founding member lets us bring world-class threat intelligence directly into the open-source frameworks security teams are building today," said Jamie Zajac, Chief Product Officer at Recorded Future. "But the promise of AI agents in security depends entirely on whether they can be trusted. Intelligence doesn't just make agents smarter. It makes them traceable, auditable and repeatable. That's the foundation the community needs to build autonomous defense that's not only fast, but reliable." The Tenable CyberAgents Exchange is a free, open-source community with no fees for listing or using agents.
LevelBlue, the world’s largest pure-play provider of managed security services, and SentinelOne, the AI Security pioneer, announces a global strategic partnership to deliver integrated, intelligence-driven security operations for organizations worldwide. The collaboration brings together SentinelOne’s Purple AI and Singularity Platform with LevelBlue’s threat-intelligence-led operations and Indigo™ security platform to enhance visibility, accelerate detection, and strengthen response across complex environments. Unified security operations Under the expanded partnership, LevelBlue will serve as a SentinelOne preferred global partner provider for managed detection and response (MDR) and managed security information and event management (SIEM) services. The strategic partnership will also extend to incident response (IR), with LevelBlue named a SentinelOne preferred provider, enabling organizations to better prepare for, respond to, and recover from cyber incidents. Together, the companies will deliver a unified security operations model that combines AI-driven detection with human-led investigation and response, helping organizations reduce dwell time, accelerate remediation, and improve overall cyber resilience. Modern security operations The partnership integrates SentinelOne’s AI SIEM and AI-driven analytics technology with LevelBlue’s Indigo security platform, which orchestrates security operations across environments alongside its threat intelligence and digital forensics capabilities. This model combines a high-fidelity data and analytics foundation with a unified operational layer, closing the gap between detection and response, one of the most persistent challenges in modern security operations. SentinelOne provides the core data ingestion, normalisation, and analytics foundation, while Indigo drives investigation, response, and service delivery across LevelBlue’s global MXDR operations. SentinelOne powers the AI data and analytics layer, while LevelBlue delivers MDR, SIEM operations, incident response, and orchestration. Outcome-driven security strategy By aligning telemetry across endpoints, cloud workloads, and identities with continuous monitoring and expert-led triage, the combined offering enables earlier detection of advanced threats, faster coordinated response, improved visibility across hybrid environments, and reduced operational complexity. “Threat actors are moving faster and operating with increasing sophistication,” said Bob McCullen, Chairman and CEO of LevelBlue. “By combining SentinelOne’s AI-driven detection with LevelBlue’s global AI-driven MDR and incident response expertise, we’re enabling organizations to move from fragmented tools to a more unified, outcome-driven security strategy.” Flexible retainer models As a SentinelOne preferred IR provider, LevelBlue brings a global team of more than 300 digital forensics and incident response professionals to support clients facing complex cyber incidents. With deep expertise across ransomware, nation-state activity, and large-scale breaches, LevelBlue delivers rapid containment, forensic investigation, and recovery support. LevelBlue’s IR services are backed by CREST-certified teams, flexible retainer models, and proactive readiness services. “Organizations don’t need more controls, they need outcomes,” said Tomer Weingarten, CEO of SentinelOne. “As the world’s largest pure play MDR provider, LevelBlue brings the scale, expertise, and operational rigor required to turn AI-driven insights into decisive action. Together, we’re helping clients with all heavy lifting, to modernise security operations and stay ahead of evolving threats.” Delivering measurable security outcomes Clients of both organizations will benefit from: Integrated MDR and AI SIEM operations for detection and response Improved signal-to-noise ratio through advanced analytics and curated threat intelligence Seamless escalation to incident response, reducing time to containment and remediation End-to-end coverage across prevention, detection, response, and recovery A unified platform and service model, powered by Indigo, that reduces tool sprawl and operational overhead
Ambient.ai, the pioneer in Agentic Physical Security, announced the general availability of Ambient Pulsar, its most advanced AI engine yet. Built on Ambient's edge-optimized reasoning Vision-Language Model (VLM) architecture, Pulsar represents a quantum leap forward that transforms physical security from reactive response to proactive incident prevention. Physical security use cases Pulsar is engineered to reason like a human security operator, only at accelerated machine speed and scale. Trained from more than one million hours of ethically sourced enterprise video, Pulsar is the largest and most capable purpose-built vision-language model ever deployed in physical security, processing over 500,000 hours each day. It delivers frontier-model reasoning performance that exceeds OpenAI GPT-5 and Google Gemini 2.5 Pro in physical security use cases, at up to 50× higher efficiency, bringing true agentic AI to enterprise scale across thousands of cameras running 24/7. New benchmark for intelligent, autonomous security operations "With Pulsar, Ambient.ai has built what every enterprise security pioneer has been waiting for: an AI that's not just fast, but intelligent," said Cary Monbarren, Senior Director, Corporate Security at SentinelOne. "This platform is transforming how GSOCs operate, drastically reducing manual triage and response times." With this launch, Ambient.ai also introduces a suite of platform innovations, including the Agentic Video Wall, Activity Notifications, and Semantic Search, setting a new benchmark for intelligent, autonomous security operations. "Pulsar marks the beginning of a new era for physical security—one where AI doesn't just detect, but truly understands and acts," said Shikhar Shrestha, CEO and co-founder of Ambient.ai. "This release turns every camera, every sensor, and every SOC into an intelligent agent capable of reasoning, prioritizing, and responding in real time." The new core of Ambient intelligence: Pulsar Pulsar is Ambient.ai's next-generation Vision Language Model (VLM)—a fully agentic, open-set model that's been purpose-built for physical security. Unlike legacy deep-learning detectors or CLIP-based analytics, Pulsar operates continuously at the edge, combining visual perception, semantic understanding, and autonomous reasoning for unmatched real-world performance. Key breakthroughs include: Always-On Edge Reasoning: By running perception at the edge, inference happens where the data originates, reducing cloud cost, latency, and bandwidth constraints. Open-Set Detection: Pulsar recognizes an infinite variety of behaviors and threats, even those never explicitly trained, from unauthorized access and tailgating to emerging anomaly patterns. Contextual Intent Recognition: By fusing language and vision, Pulsar understands why something matters—distinguishing benign activity from genuine risk. Scalable Agentic Autonomy: With reasoning distributed across edge appliances, Pulsar powers multi-site environments for true real-time awareness at enterprise scale. Edge-Optimized Architecture: Pulsar's perception runs on Ambient.ai's edge appliance, an on-premises compact compute node powered by the latest NVIDIA AI infrastructure, enabling parallel inference across dozens of live video streams. Pulsar in action: The capabilities defining agentic physical security Powered by Pulsar, Ambient.ai is introducing a suite of breakthrough capabilities that chart the industry's path toward Agentic Physical Security. Launching now: Agentic Video Walls: They create a living, adaptive security operations center, turning static feeds into a dynamic system that highlights the streams with the most interesting activity, delivering focused situational awareness. Activity Notifications: Operators define custom events or scenes using open-set, natural-language input, enabling the system to proactively deliver context-aware notifications of everyday events in real time. Semantic Search: Operators can query their video archive just by asking questions, transforming hours of footage review into instantaneous insight. Early preview: Agentic Investigations: Transforms how security teams uncover the truth. Operators can ask an outcome-oriented question—"Tell me what led to the fire?"—and Ambient.ai instantly assembles a complete incident timeline using all its tools at its disposal, including Semantic Search, Similarity Search, License Plate Recognition, and more. Custom Threat Assessment: Enables adaptive threat assessment through natural-language input. Security teams can dynamically calibrate alert severity to scene specific criteria. A platform built for the agentic era The Pulsar release reinforces Ambient.ai's vision of Agentic Physical Security—a new approach where intelligent systems augment human operators to prevent incidents, not just record them. The Ambient.ai platform now unifies monitoring, threat assessment, access intelligence, investigations, and response under a single AI brain. Ambient.ai's enterprise customers, including Fortune 100 pioneers in technology, finance, manufacturing, aerospace, pharma and critical infrastructure, are already realizing measurable impact with as much as 95% false-alarm reduction, 80% of alerts resolved in under one minute, and millions saved annually in operational efficiency. With Pulsar as the core of the Ambient Intelligence engine, Ambient.ai is redefining what's possible in enterprise protection, creating a security system that not only understands what it sees, flagging precursors to risks to enable true prevention, but also orchestrates response and investigation autonomously to minimize potential impact. Online keynote details and registration Now at 10:00 a.m. PST, Ambient.ai will host an online keynote unveiling Pulsar in detail, including live demonstrations of each new capability.