SentinelOne broadens threat hunting to major cloud platforms

SentinelOne has broadened its Wayfinder Threat Hunting service to cover AWS, Azure, and Google Cloud. The offering blends AI-driven telemetry from its Singularity Platform with human analysts to hunt threats across endpoints, identities, AI, and cloud environments. The new cloud coverage targets control-plane abuse, IAM privilege escalation, unauthorized access, and data exfiltration, with findings mapped to MITRE ATT&CK and enriched by Purple AI.
SentinelOne’s Wayfinder Threat Hunting now spans AWS, Azure, and Google Cloud. The service combines machine-generated telemetry from Singularity with analysts who conduct investigations. It looks for cloud control-plane misuse, identity privilege escalation, unauthorized entry, and data theft.
Specific hunts include IAM user discovery, S3 bucket probing, root account sign-ins, AKS cluster-admin credential access, suspicious IAM policy edits, AMI deregistration, telemetry deletion, and cross-tenant delegation modifications. Results are tied to MITRE ATT&CK and paired with Purple AI summaries. Existing Wayfinder customers can enable it through Singularity Marketplace plugins; Entra ID users need no extra Azure setup.
Organizations using AWS, Azure, or GCP could gain earlier warning about cloud identity and control-plane attacks, potentially reducing breach costs and data loss. Security teams may face less manual triage if AI summaries and MITRE mapping help prioritize. Cloud engineers and identity administrators might see more scrutiny of permissions and configuration changes. Attackers may adapt, so benefits could depend on continuous tuning and coverage. Consumers whose data resides in these clouds may benefit indirectly through stronger protection, though no tool eliminates risk.