SentinelOne (NYSE: S) has expanded its Wayfinder Threat Hunting service to the cloud control planes of AWS, Azure and Google Cloud, extending continuous coverage to a layer where identity abuse and configuration changes can expose enterprise data without an endpoint compromise. The service is generally available today to existing Wayfinder Threat Hunting customers.
The expansion combines telemetry from SentinelOne’s Singularity Platform with human-led threat hunts across cloud control-plane activity. The company said the new service looks for cloud-control-plane abuse, identity and access-management privilege escalation, unauthorized access and data exfiltration across the three public clouds.
That shift matters because cloud attacks often begin with a compromised identity or a misconfiguration rather than malware on a managed device. Security teams can already collect logs from multiple services, but correlating identity, endpoint and cloud events into an investigation can create gaps and add manual triage work. SentinelOne is positioning Wayfinder as a continuous hunting layer across those environments rather than a point-in-time assessment.
The cloud coverage includes hunts for IAM user enumeration, S3 bucket reconnaissance, root-account logins, suspicious policy changes, telemetry destruction and cross-tenant delegation changes. It also covers AKS cluster-administrator credential access and Amazon Machine Image deregistration. SentinelOne said it maps curated indicators and behavioral rules to MITRE ATT&CK techniques, then delivers findings with Purple AI summaries intended to support analyst triage.
Wayfinder pairs those automated signals with human-led hunts rather than presenting cloud changes as automatically malicious. That distinction matters in environments where administrators routinely alter permissions, policies and workloads. The company describes the service as continuous scrutiny across the environment; customers still need to validate the context of a finding and decide which containment or remediation actions fit their own change-control and incident-response processes.
For security operations teams, the important operational change is the scope of the workflow. Analysts can apply the same Wayfinder service across endpoint, identity and cloud activity instead of treating the control plane as a separate investigation domain. The company said the service draws on threat intelligence and intrusion findings in a single hunting workflow, but it did not publish detection-rate data, response-time metrics or named customer deployments for the cloud expansion.
The service does not replace access controls, cloud configuration management or incident-response procedures. Its role is to surface suspicious behavior that can be difficult to find when control-plane evidence sits apart from endpoint and identity telemetry. That can help teams focus review on higher-risk activity, while human hunters remain part of the process for investigation and escalation.
Existing customers enable the cloud capability through Singularity Marketplace plugins for each cloud provider. SentinelOne said organizations already using Wayfinder Threat Hunting on Microsoft Entra ID do not need additional setup for Azure environments. The company did not disclose pricing or whether customers need to add plugins for the other clouds.
As enterprise workloads spread across cloud services, control-plane visibility has become a practical security-operations requirement rather than a specialized add-on. SentinelOne’s expansion gives existing Wayfinder customers a broader, continuous hunting workflow for cloud identity and configuration activity, though its effectiveness will still depend on each organization’s telemetry coverage, access policies and incident-response discipline.
