SentinelOne has expanded Wayfinder Threat Hunting to the major public cloud services, according to Help Net Security. The service now hunts across AWS, Azure, and Google Cloud, extending earlier coverage of endpoints and identity providers such as Okta and Microsoft Entra ID. The goal is to catch attackers operating in cloud control planes, where compromised identities or misconfigurations can lead directly to data without endpoint activity.

The offering combines SentinelOne's AI-powered Singularity Platform telemetry with human-led hunting, using threat intelligence from SentinelOne and Google Threat Intelligence in one workflow. Coverage includes cloud control-plane abuse, IAM privilege escalation, unauthorized access, and data exfiltration. Specific hunts include IAM user enumeration, S3 bucket reconnaissance, root account logins, AKS cluster-admin credential access, suspicious IAM policy changes, AMI deregistration, telemetry destruction, and cross-tenant delegation changes.

Findings are mapped to MITRE ATT&CK techniques and include Purple AI summaries for triage. SentinelOne's chief customer officer, Steve Stone, said attackers often reach data fastest through the cloud control plane, and the expansion gives customers the same AI-plus-human scrutiny across their full footprint. The service is generally available to existing Wayfinder Threat Hunting customers, with enablement through Singularity Marketplace plugins; customers already hunting identities in Microsoft Entra ID need no additional setup for Azure.