Tools · MOUNTAIN VIEW
SentinelOne Extends Wayfinder Threat Hunting to AWS, Azure, and Google Cloud
September 25, 2026
By James Whitford, Tools, Austin

MOUNTAIN VIEW - SentinelOne on September 24, 2026, said it has expanded Wayfinder Threat Hunting to AWS, Azure, and Google Cloud. In a Business Wire announcement that day, the company said the service pairs Singularity Platform telemetry with human-led hunting, and that it uses threat intelligence and intrusion findings from SentinelOne and Google Threat Intelligence in one workflow. SentinelOne said the cloud step follows earlier Wayfinder coverage of endpoints and of identity hunting for Okta and Microsoft Entra ID.
The company said Wayfinder Threat Hunting for Cloud is continuous, expert-led hunting of AWS, Azure, and Google Cloud control-plane activity. It listed coverage of cloud control-plane abuse, identity and access management privilege escalation, unauthorized access, and data exfiltration. Named hunts include IAM user enumeration, S3 bucket reconnaissance, root account logins, AKS cluster-admin credential access, suspicious IAM policy changes, AMI deregistration, telemetry destruction, and cross-tenant delegation changes. SentinelOne said curated indicators and behavioral rules are mapped to MITRE ATT&CK techniques, and that findings include Purple AI summaries for triage.
"Attackers have learned that the fastest and most easily accessible way to an organization's data is often through the cloud control plane," Steve Stone, SentinelOne chief customer officer, said in the announcement. "Extending Wayfinder's elite hunters into AWS, Azure, and GCP means customers get the same continuous, AI-plus-human scrutiny across their entire footprint to eliminate the gaps in coverage that modern attackers prey on."
SentinelOne said Wayfinder Threat Hunting for Cloud is generally available to existing Wayfinder Threat Hunting customers. Enablement uses existing Singularity Marketplace plugins for each cloud provider. Customers already using Wayfinder Threat Hunting on identities in Microsoft Entra ID need no additional setup for Azure, the company said.
For security operations teams, this is a vendor hunting service on cloud control-plane telemetry, not a detection-engineering rule pack and not a substitute for native cloud logging. The published scope is existing Wayfinder customers, and the hunt list is the set SentinelOne named. Teams should confirm which accounts, subscriptions, and projects are connected through the marketplace plugins before treating the coverage as continuous across every cloud tenant.
Sources: https://www.businesswire.com/news/home/20260924339917/en/ ; https://www.financialcontent.com/article/bizwire-2026-9-24-sentinelone-extends-wayfinder-threat-huntings-continuous-coverage-to-aws-azure-and-google-cloud ; https://www.sentinelone.com/global-services/threat-hunting/ ; https://aithority.com/it-and-devops/cloud/sentinelone-extends-wayfinder-threat-huntings-continuous-coverage-to-aws-azure-and-google-cloud/
James Whitford covers SOC tooling, SIEM, SOAR, and detection platforms for SOCtember from Austin.