SentinelOne has announced the expansion of Wayfinder Frontier AI Services to help customers stop AI-enabled threats before they can materialize. First announced in April 2026, the expanded offering brings together the latest models from Anthropic, SentinelOne's elite cyber experts, and strategic partners like LevelBlue, to deliver continuous, intelligence-led discovery, prioritization, and remediation across a customer's full attack surface. The offering is the latest from Wayfinder, SentinelOne's managed services arm.
SentinelOne expands Wayfinder Frontier AI Services with Anthropic's latest models and plans to add OpenAI GPT-5.5-cyber and GPT-5.6 for a multi-model approach.
LevelBlue named as premier remediation partner to develop and execute milestone-based remediation programs for Wayfinder customers.
Wayfinder MDR Workflows add customizable Hyperautomation capabilities, expected to be generally available in August 2026.
Wayfinder Threat Hunting for Identity now covers Okta and Microsoft Entra ID for expanded attack surface coverage.
The service delivers continuous intelligence-led discovery, prioritization, and remediation across the full attack surface.
SentinelOne plans to extend coverage to models from other frontier AI labs in the future for a fully multi-model approach.
Organizations of all sizes continue to grapple with the question of what frontier AI models mean when it comes to revealing and chaining potential vulnerabilities, exploits, and latent zero days in their enterprise. With Wayfinder Frontier AI Services, SentinelOne helps organizations quickly find the signal in the noise, identifying and validating the realistically exploitable threats versus a growing list of new vulnerabilities and misconfigurations. Customers are given clear and prioritized remediation guidance, making compromise assessments immediately actionable. As a result, security teams can maintain an operating advantage by capitalizing on the power of frontier AI to fortify their defenses before these same models can be used against them.
"Frontier AI models are powerful enough to find real exposure paths, but they still need experienced humans to validate what's real, what's noise, and what to do next," said Steve Stone, Chief Customer Officer, SentinelOne. "That's exactly what Wayfinder Frontier AI Services delivers. Our analysts working alongside Anthropic's latest models, layered directly on the telemetry customers already have, so nothing gets lost between detection and action."
The expanded Wayfinder Frontier AI Services leverage the latest models from Anthropic. SentinelOne also plans to extend this coverage to OpenAI's GPT-5.5-cyber and GPT-5.6 models, as well as models from other frontier AI labs in the future to offer a fully multi-model approach.
As part of the general availability launch, SentinelOne has named LevelBlue as Wayfinder's premier remediation partner. The expanded partnership complements Wayfinder's own cyber experts by bringing in distinct, best-in-class remediation services. SentinelOne customers that receive prioritized threat assessments and findings from Wayfinder Frontier AI Services are offered the options of a seamless, coordinated exchange with LevelBlue experts to develop and execute prioritized, milestone-based remediation programs. As a result, security teams can reduce risk and strengthen long-term resilience in their software and application environments.
"Finding a confirmed vulnerability is only half the job," said Spencer Lynch, SVP of Professional Services, LevelBlue. "What matters is knowing which ones actually matter, getting developers a fix that works, and confirming it holds up after deployment. Pairing Wayfinder's exploitability findings with LevelBlue's remediation expertise gives customers a complete path from discovery to resolution, not just a longer list of problems."
Wayfinder MDR Workflows – This new capability adds customizable Hyperautomation workflows into the MDR customer experience. SentinelOne's Wayfinder MDR analysts validate and escalate threats; customers dictate the automated response. From kicking off Slack channels and Jira tickets to executing direct response actions in Singularity and third-party software, Wayfinder customers remain in control of how their SOC workflows trigger and execute once a Wayfinder-qualified threat is received. The new capabilities will be previewed at Black Hat and will be generally available in August this year.
Managed Threat Hunting Across an Expanded Attack Surface – Wayfinder's AI-powered threat hunting now extends into identity environments. Wayfinder Threat Hunting for Identity covers Okta and Microsoft Entra ID. From low-and-slow endpoint tradecraft to MFA fatigue attacks and session hijacking, every finding is analyst-validated before it reaches the customer's SOC. The new capabilities are generally available and included at no additional cost for existing Wayfinder Threat Hunting customers.
About SentinelOne
SentinelOne is the leader in AI security, setting the standard for using AI and automation to give defenders a decisive operating advantage. Built for those who secure our world, its platform delivers unified coverage across endpoints, identity, cloud, and AI. Powered by Autonomous Security Intelligence, SentinelOne stops attacks at machine speed, reducing risk and delivering clarity and control to stay one step ahead. Headquartered in Mountain View, California, with teams worldwide, SentinelOne protects nearly one-fifth of the Fortune 500 and hundreds of Global 2000 enterprises. From Main Street to Wall Street, the world's most critical organizations trust SentinelOne with their security.