VYPR
advisoryPublished Sep 25, 2026· 1 source

SentinelOne Extends Wayfinder Threat Hunting to Cloud Environments

SentinelOne's Wayfinder Threat Hunting now covers AWS, Azure, and Google Cloud, integrating AI telemetry with human expertise to protect cloud workloads and identities.

SentinelOne has announced a significant expansion of its Wayfinder Threat Hunting capabilities, extending its reach to encompass major public cloud services including Amazon Web Services (AWS), Microsoft Azure, and Google Cloud Platform (GCP). This enhancement integrates the AI-powered telemetry from SentinelOne's Singularity Platform with the expertise of human-led threat hunters. The initiative aims to bolster defenses across an organization's entire attack surface, which now prominently includes AI, endpoints, identities, and cloud workloads.

The increasing adoption of artificial intelligence and the inherent attractiveness of cloud environments have made them prime targets for threat actors. Compromising a cloud identity or exploiting a misconfiguration can allow attackers to access sensitive data directly, often bypassing traditional endpoint security measures and leaving minimal traces in standard security logs. SentinelOne's Wayfinder team is adapting to this evolving threat landscape by meeting attackers wherever they operate, first focusing on endpoints, then expanding to identity security with hunting for Okta and Microsoft Entra ID, and now extending to the cloud control plane.

This new cloud-focused offering leverages threat intelligence and intrusion findings from both SentinelOne and Google Threat Intelligence, consolidating them into a unified hunting workflow. The goal is to provide customers with a continuous, comprehensive hunting capability across their entire infrastructure, spanning endpoints, human and agent identities, and the cloud itself. This unified approach aims to give defenders a decisive operational advantage against sophisticated threats.

SentinelOne's Wayfinder Threat Hunting for Cloud is designed to continuously scrutinize AWS, Azure, and GCP control-plane activities. Its coverage includes detecting cloud control-plane abuse, identifying IAM privilege escalation tactics, spotting unauthorized access, and preventing data exfiltration. Specific hunts are engineered to detect suspicious activities such as IAM user enumeration, S3 bucket reconnaissance, root account logins, unauthorized AKS cluster-admin credential access, malicious IAM policy changes, AMI deregistration, telemetry destruction, and cross-tenant delegation modifications.

Each hunt is mapped to MITRE ATT&CK techniques, providing curated indicators and behavioral rules. Findings are presented with enriched Purple AI summaries to expedite triage and response efforts. The ultimate objective is to deliver stronger security posture with a reduced number of security incidents and a lower operational overhead for security teams.

"Attackers have learned that the fastest and most easily accessible way to an organization’s data is often through the cloud control plane," stated Steve Stone, Chief Customer Officer at SentinelOne. "Extending Wayfinder’s elite hunters into AWS, Azure, and GCP means customers get the same continuous, AI-plus-human scrutiny across their entire footprint to eliminate the gaps in coverage that modern attackers prey on."

The new Wayfinder Threat Hunting for Cloud capability is now generally available to all existing Wayfinder Threat Hunting customers. It can be enabled through existing Singularity Marketplace plugins for each respective cloud provider. Customers already utilizing Wayfinder Threat Hunting for identities within Microsoft Entra ID will find that their Azure environments require no additional setup for this new cloud coverage.

This expansion underscores SentinelOne's commitment to providing comprehensive security solutions that adapt to the dynamic nature of cyber threats, particularly in the rapidly growing and increasingly targeted cloud computing landscape.

Synthesized by Vypr AI