Adversarial AI: Thinking Like Attackers in the Age of AI
Joe DiMasiStaff Solutions Engineer, SentinelOne
Attackers are evolving with AI faster than we realize and defenders must do the same. In this gamified, interactive session, explore how adversaries are leveraging AI for evasion, automation, and scale. Then map those tactics to AI-driven defenses within SentinelOne. Participants will engage in scenario-based exercises to anticipate attacker behavior and strengthen proactive security strategies.
9:00 AM - 12:00 PM
SentinelOne University
AI-Driven Investigation: From Alert to Root Cause in Minutes
Harness the full power of AI-driven investigations across the Singularity Platform. In this hands-on session, you’ll learn how AI correlates telemetry, accelerates root cause analysis by correlating across multiple storylines, and implement hands-off vs human-in-the-loop AI. Walk away with repeatable, AI-assisted workflows that dramatically reduce mean time to respond (MTTR) and elevate analyst efficiency.
9:00 AM - 12:00 PM
SentinelOne University
Building and Optimizing Data Pipelines for AI SIEM
Joel MoraTeam Lead, Solutions Architect, SentinelOne
AI is only as strong as the data behind it. This session focuses on designing, optimizing, and scaling data pipelines that fuel SentinelOne’s AI SIEM. Learn how to ingest, normalize, and enrich, high-volume telemetry to improve detection accuracy, reduce noise, and unlock more powerful AI-driven insights across your environment.
9:00 AM - 12:00 PM
SentinelOne University
Secure Your AI: Protecting Models, Data, and Usage at Scale
Patrick MeehanPrincipal Field Architect - Prompt Security, SentinelOne
As AI adoption accelerates, so do new risk surfaces. This session focuses on security in your AI ecosystem, from models and training data to prompts and outputs. Learn how to identify vulnerabilities, enforce governance, and apply SentinelOne’s capabilities using Prompt to monitor and protect applications across the organization.
1:00 PM PDT
1:00 PM - 4:00 PM
1:00 PM - 4:00 PM
SentinelOne University
Hyperautomation in the SOC: From Alert Fatigue to Autonomous Response
Manual processes slow down security teams when speed matters most. In this session, you’ll design and implement hyperautomation workflows using SentinelOne to orchestrate detection, investigation, and response. Learn how to eliminate repetitive tasks and enable autonomous security operations at scale.
This session explores SentinelOne's capabilities of Identity and Endpoint protection. Through instructor demonstrations and discussion, you will learn how identity protection complements endpoint detection, enabling faster, more confident response decisions.
5:00 PM PDT
5:00 PM - 5:45 PM
Opening Keynote
5:00 PM - 5:45 PM
Steve StoneChief Customer Officer, SentinelOne
5:45 PM PDT
5:45 PM - 6:45 PM
Threat Hunting World Championship
5:45 PM - 6:45 PM
Anthony La ScalaPrincipal Technologist, SentinelOne
Ryan O'GradySr. Manager, Solutions Engineering, SentinelOne
Live on the OneCon main stage, the final comes down to one head-to-head showdown. For the past 16 weeks, hunters from 100+ countries have been battling it out. We're down to our final three, each representing their region. Who will be taking home the crown of the world's best threat hunter?
6:45 PM PDT
6:45 PM - 8:15 PM
Welcome Reception
6:45 PM - 8:15 PM
Wednesday
October 21, 2026
8:00 AM PDT
8:00 AM - 9:00 AM
Breakfast & Expo
8:00 AM - 9:00 AM
9:00 AM PDT
9:00 AM - 9:45 AM
CEO Vision Keynote
9:00 AM - 9:45 AM
Tomer WeingartenChief Executive Officer and Co-Founder, SentinelOne
9:45 AM PDT
9:45 AM - 10:45 AM
The FBI Agent and the Hacker He Took Down
9:45 AM - 10:45 AM
Chris TarbellDirector of Cyber Security and Investigations, Berkeley Research Group
Hector MonsegurDirector of Research, Alacrinet
10:45 AM PDT
10:45 AM - 11:30 AM
AM Break
10:45 AM - 11:30 AM
11:30 AM PDT
11:30 AM - 12:30 PM
Product Keynote
11:30 AM - 12:30 PM
Chris CordeChief Product Officer, SentinelOne
Nicandro ScarabeoTechnical Director, Cyber Security & Architecture, Bell Canada
12:30 PM PDT
12:30 PM - 1:00 PM
Customer Panel
12:30 PM - 1:00 PM
Eran AshkenaziChief Business Officer, SentinelOne
1:00 PM PDT
1:00 PM - 2:00 PM
Lunch & Expo
1:00 PM - 2:00 PM
2:00 PM PDT
2:00 PM - 2:45 PM
2:00 PM - 2:45 PM
Beyond the Human Perimeter: AI-SPM in the Age of Agentic Identity
Homayun YaqubSVP, Risk Advisory Services, Digital Hands
Service accounts, API keys, and AI agents now authenticate, request access, and act, but identity telemetry still assumes a human is behind every login. Each agent you deploy is a new identity with permissions most security programs can't monitor or explain. This session, brought to you by Digital Hands and SentinelOne, argues for AI Security Posture Management as the next layer of identity defense: why privilege drift and orphaned access are accelerating, how ISPM and ITDR are converging, and how to close the gap between AI adoption speed and governance maturity.
Track:
Securing the AI Lifecycle from Prompt to Production
Audience:
Business Leader
Product:
CloudPrompt
Technical Level:
200 - Intermediate
Speaker Type:
Partner
2:00 PM - 2:45 PM
From Alert to Root Cause: Scaling DFIR with RemoteOps Forensics, APIs, and AI
Jack ZimmerLead AI Cyber Security Engineer, Raymond James
Living-off-the-land and remote access tool abuse can leave critical clues in local endpoint artifacts that alert telemetry alone may not fully explain. This session shows how Raymond James built MOAF (Mother Of All Forensics), an analyst-led workflow using SentinelOne RemoteOps Forensics and APIs to collect, enrich, normalize, and agentically review host evidence so IR teams can move from alert to root cause and data-exposure decisions faster. Attendees will learn a repeatable pattern for pairing SentinelOne telemetry with host artifacts, scaling RemoteOps evidence collection, fusing timelines, adding analyst-in-the-loop AI review, and producing faster, more consistent root-cause, scope, and data-exposure decisions.
Track:
Protecting Attack Surfaces in the Agentic Era
Audience:
Practitioner
Product:
Endpoint
Technical Level:
200 - Intermediate
Speaker Type:
Customer
2:00 PM - 2:45 PM
From Breach to Recovery: A Real-World Incident Response Engagement
Bryce BlairVice President, Global Cyber Operations, Arete
Michael PopeDirector, Counter Threat Automations, Arete
Join Arete for a deep dive into real-world incident response engagements where collaboration and technology made the difference between disaster and recovery. In this session, we’ll walk through high-impact cybersecurity breaches where Arete’s incident response team leveraged SentinelOne’s autonomous platform—including Endpoint Detection and Response (EDR), AI-powered SIEM, and STAR detections—to investigate, contain, and remediate the threat.
Track:
Live From the Frontline
Audience:
Business Leader
Technical Level:
100 - All Levels
Speaker Type:
Partner
2:00 PM - 2:45 PM
The Autonomous SOC Starts With Data: Inside Singularity AI Data Pipelines
Every autonomous SOC capability — detection, investigation, AI-driven response — runs on the data underneath it. Noisy, unstructured data means noisy outcomes: more false positives, slower investigations, more analyst hours lost to triage. See how Singularity AI Data Pipelines fixes it at the source, cutting log noise by up to 80% before it ever reaches AI SIEM, and leave with a blueprint for delivering the right data, to the right place, instantly.
Miri PeerSenior Director of product management, SentinelOne
Join us to discover the exciting new features and capabilities coming soon to SentinelOne's attack surfaces portfolio. We'll cover some of the most impactful upcoming investments across Endpoint, Identity, Cloud, and Exposure Management, giving customers a clear picture of what's coming in the near-to-mid term. We'll walk through the vision, strategy, and product roadmap designed to protect customers from advanced threats, and set them up for success against evolving risk.
Track:
Protecting Attack Surfaces in the Agentic Era
Audience:
Business LeaderPractitioner
Product:
CloudEndpointExposure ManagementIdentity
Technical Level:
100 - All Levels
Speaker Type:
SentinelOne
3:00 PM PDT
3:00 PM - 3:45 PM
3:00 PM - 3:45 PM
Architecting the Autonomous SOC: What's Next Across AI SIEM, Data Pipelines, Purple AI, and Hyperautomation
Jonathan GarzonSenior Director of Product Management, AI SIEM, SentinelOne
Most security stacks force analysts to bridge the gaps as each tool evolves on its own timeline. This session lays out where AI SIEM, AI Data Pipelines, Purple AI, and Hyperautomation are headed next, and why SentinelOne is building all four on one continuous path instead of four separate ones: from raw data, to detection, to investigation, to autonomous response. See what's shipping soon, what's next, and what it takes to architect the autonomous SOC end to end.
Track:
Architecting the Autonomous SOC
Audience:
Practitioner
Product:
AI SIEMData PipelinesHyperautomationPlatformPurple AI
Technical Level:
100 - All Levels
Speaker Type:
SentinelOne
3:00 PM - 3:45 PM
Detection Operations: The Latest Research and Next Wave of Detection Innovations
Roman RusetskyDirector of Product Management - Detection Platform, SentinelOne
Steve RossVice President, Detection Engineering, SentinelOne
Discover the real-world threat landscape through the lens of SentinelOne's own detection operations, which monitor 32 million endpoints and process 10 petabytes of data every day. In this session, attendees will gain a clear understanding of what threats SentinelOne is actively detecting in the wild, how that intelligence translates into powerful, proactive protection, and get an exclusive look at the new detection infrastructure SentinelOne is building to stay ahead of tomorrow's threats.
Track:
Protecting Attack Surfaces in the Agentic Era
Audience:
Business LeaderPractitioner
Product:
EndpointPlatform
Technical Level:
100 - All Levels
Speaker Type:
SentinelOne
3:00 PM - 3:45 PM
No Network? No Problem: We Have Your Air-Gapped Environments Covered!
Nick KaraguezianStaff Pre-Sale Support Engineer, SentinelOne
Attackers don't always come through the network. In high-security environments, connectivity blind spots create risks that traditional tools weren't built for, making the isolation itself the vulnerable blind spot. No connectivity means zero visibility against threats originating from the inside or out.
This session covers how to protect fully isolated, compliance-heavy, or data-sovereignty-constrained environments. Learn how to extend endpoint security to systems that can't touch the cloud, see what that architecture looks like in practice, and discover how teams get total coverage without compromising isolation requirements.
AI deployments rely on a complex cloud AI supply chain that extends far beyond the model itself. Hidden relationships between AI services, data, identities, and infrastructure can create exploitable attack paths that traditional security tools often miss. This session explores how attackers leverage these interconnected risks and how security teams can discover, prioritize, and remediate the exposures that matter most across their cloud AI environments.
Track:
Securing the AI Lifecycle from Prompt to Production
Audience:
Business LeaderPractitioner
Product:
Cloud
Technical Level:
200 - Intermediate
Speaker Type:
SentinelOne
3:00 PM - 3:45 PM
The Volume Problem: Defending at Machine Speed in the Age of AI-Discovered Vulnerabilities
Tommy HardtSr. Product Manager, Incident Readiness and Response, SentinelOne
Josh PearceSr. Staff AppSec Engineer, SentinelOne
AI is changing both sides of the security equation. Frontier models and autonomous agents can now discover vulnerabilities, analyze code, and identify attack paths at a speed and scale no human team can match. Open source maintainers are already drowning in AI-generated bug reports, while enterprise security teams face the same challenge: more findings, more noise, and too little context. The risk is not simply that AI will uncover more weaknesses, but that attackers can compress the time between discovery and exploitation and operate at machine speed. Defenders need AI security strategies that can validate findings, separate genuine risk from plausible-looking noise, and prioritize what matters most. In this session, we’ll explore how Wayfinder Frontier AI Services combines agentic workflows with expert analysis to deliver validated, high-impact findings teams can confidently act on.
Track:
Securing the AI Lifecycle from Prompt to Production
Audience:
Business LeaderPractitioner
Product:
EndpointExposure ManagementWayfinder
Technical Level:
100 - All Levels
Speaker Type:
SentinelOne
4:00 PM PDT
4:00 PM - 4:45 PM
4:00 PM - 4:45 PM
Follow the Attack from Compromised Credential to Domain Takeover
François BaraerTeam Lead, Solutions Engineering, SentinelOne
Modern attacks rarely stop at the endpoint. They pivot to identity. In this hands-on workshop we follow an attacker from a compromised credential on a SentinelOne-protected device through reconnaissance, lateral movement, and Active Directory attacks such as Golden Ticket and DCSync. See how existing EDR customers can extend the same agent with Singularity Identity to detect credential misuse and lateral movement, use deception decoys for high-fidelity alerting, and close the AD misconfigurations that made the attack path possible in the first place. And as AI agents become identities in your environment, the same framework applies.
Track:
Protecting Attack Surfaces in the Agentic Era
Audience:
Practitioner
Product:
Identity
Technical Level:
100 - All Levels
Speaker Type:
SentinelOne
4:00 PM - 4:45 PM
Lean Teams, Stronger Defense: Where IT Operations Meet Security
Tim LanningVice President of IT, SJRC Texas
Tom MoldenCIO, Global Executive Engagement, NinjaOne
When the mission is critical but resources are tight, IT and security can’t afford to operate in silos. See how NinjaOne and SentinelOne work better together, helping organizations like SJRC Texas (a child and family well-being nonprofit) turn everyday IT operations into a first line of defense. By uniting endpoint management with autonomous security, lean teams can stay ahead of risk, protect every device, and strengthen security without adding complexity, headcount, or compromising operational stability
Track:
Protecting Attack Surfaces in the Agentic Era
Audience:
Business Leader
Technical Level:
100 - All Levels
Speaker Type:
Partner
4:00 PM - 4:45 PM
The Com: An Ecosystem in Evolution
Drea LondonVP Incident Readiness and Response, SentinelOne
Get an exclusive security update from our experts and threat researchers on the underworld activities of The Com. Learn about their origins, evolving ecosystem, emerging tactics and targeting, and the expanding investigative and law-enforcement response. Please note: Due to the sensitivity of the content, attendees will be asked to power off laptops and cellphones for the duration of the session.
Track:
Live From the Frontline
Audience:
Business LeaderPractitioner
Technical Level:
100 - All Levels
Speaker Type:
SentinelOne
4:00 PM - 4:45 PM
The Invisible Breach: AI Data Poisoning Through Cloud Identities
Brendan PutekDirector of DevOps, Relay Network
Zuaib SayyadSr Staff Product Manager, SentinelOne
Security teams often spend a lot of time talking about AI risk in terms of prompts, models, and infrastructure. But what happens when a legitimate cloud identity is compromised and already has the right permissions to tamper with training pipelines and production AI systems? In 2026, attackers poisoned a SageMaker training pipeline at a real organization through a misconfigured identity, silently backdooring the model in production. This session traces that chain live using CIEM-enriched Attack Paths, showing how toxic permission combinations enable privilege escalation, expose full blast radius, and help teams stop identity-driven attacks before AI systems are compromised.
Track:
Securing the AI Lifecycle from Prompt to Production
Audience:
Practitioner
Product:
Cloud
Technical Level:
200 - Intermediate
Speaker Type:
SentinelOne
4:45 PM PDT
4:45 PM - 6:00 PM
Expo Happy Hour
4:45 PM - 6:00 PM
Thursday
October 22, 2026
8:00 AM PDT
8:00 AM - 9:00 AM
Breakfast & Expo
8:00 AM - 9:00 AM
9:15 AM PDT
9:15 AM - 10:00 AM
9:15 AM - 10:00 AM
Countering AI Threats at Machine Speed: The Future of CTEM with SentinelOne and Tenable
Sean JenningsField CTO | Strategic Partnerships & M&A, Tenable
AI has forever changed the scale and speed of cyber attacks. SentinelOne leads in runtime detection and response. Tenable leads in exposure intelligence and prioritization. Together, they deliver continuous threat exposure management that preemptively identifies and responds to threats at machine speed: from "what's exposed" to "what's being exploited" to "threat contained." Attend this session to see what best-of-breed CTEM looks like when two category leaders unite.
Track:
Protecting Attack Surfaces in the Agentic Era
Audience:
Business Leader
Product:
Exposure Management
Technical Level:
200 - Intermediate
Speaker Type:
Partner
9:15 AM - 10:00 AM
How RSM Defense Operationalized SentinelOne to Deliver Enterprise-Grade Security at Scale
Leave this session with a concrete framework for operationalizing SentinelOne beyond the agent. RSM Defense's Threat Hunting Supervisor and Senior SOC Analyst will share how their team built a hunt-to-detection loop that has produced 300+ custom STAR rules across hundreds of managed environments, how Purple AI and Agentic Investigation changed SOC operations at scale, and what a real SentinelOne partner relationship looks like at the Paladin level.
Track:
Architecting the Autonomous SOC
Audience:
Practitioner
Product:
Purple AI
Technical Level:
200 - Intermediate
Speaker Type:
Partner
9:15 AM - 10:00 AM
Inside the Hunt: Tracking and Detecting ShinyHunters Across SaaS and Cloud Environments
Dennis LabossiereDirector, Cybersecurity & Technology Risk, KPMG
Matt WeikertSenior Manager, DFIR, SentinelOne
As organizations continue their migration to cloud and SaaS platforms, cybercriminal groups such as ShinyHunters are capitalizing on expanding attack surfaces. This session provides a deep dive into the group's intrusion methodologies, techniques, identity attacks, data exfiltration methods, and extortion workflows. SentinelOne and KPMG will analyze recent campaigns, discuss detection opportunities across the attack lifecycle, and share practical guidance for defending modern cloud-centric enterprises against data theft and extortion-driven threats.
Track:
Protecting Attack Surfaces in the Agentic Era
Audience:
Practitioner
Product:
Wayfinder
Technical Level:
200 - Intermediate
Speaker Type:
PartnerSentinelOne
9:15 AM - 10:00 AM
Prompt to Production: What a Full AI Attack Surface Actually Looks Like
Chris HoskingPrincipal Evangelist, SentinelOne
Most organizations are responding to AI threats the way they always have: a different tool for every problem. One for prompts, one for cloud, one for identity, one for posture. Each new addition widens the gaps between them, and attackers already know where those gaps are. This session presents a unified view of the AI attack surface: four interconnected layers covering the infrastructure AI runs on, the data flowing through it, the models turning inputs into decisions, and the users and agents behind them. A failure at any one travels through every downstream system. See how a single real-world attack crosses all four layers without triggering a single alert in a fragmented environment, and what a connected, platform-based defense looks like from prompt to production.
Track:
Securing the AI Lifecycle from Prompt to Production
Audience:
Business Leader
Product:
CloudEndpointIdentityPlatformPrompt
Technical Level:
100 - All Levels
Speaker Type:
SentinelOne
9:15 AM - 10:00 AM
SentinelOne Unplugged - Securing OT and Critical Infrastructure Without the Cloud
Dave GoldVP, Global Field CTO/CISO, SentinelOne
OT environments carry a unique set of challenges: legacy systems that can't be patched without risking downtime, proprietary protocols never built with security in mind, air-gapped networks, and converging IT/OT boundaries that widen the attack surface. The threats are real and growing, from ICS-specific malware, nation-state threats, supply chain attacks, insider threats, and remote access vulnerabilities.
This session covers the OT Threat landscape, how SentinelOne secures OT and critical infrastructure and how we can help achieve compliance in these high-stakes environments. We'll cover our self-hosted portfolio, including a sneak peak of our UniConsole, our unified console for managing on-prem environments, in addition to new on-prem product capabilities such as AppControl and RemoteOps. We'll also unpack the recently announced Honeywell partnership and how SentinelOne is helping better secure Experion PKS customers over legacy providers.
Track:
Protecting Attack Surfaces in the Agentic Era
Audience:
Business Leader
Product:
Endpoint
Technical Level:
200 - Intermediate
Speaker Type:
SentinelOne
10:15 AM PDT
10:15 AM - 11:00 AM
10:15 AM - 11:00 AM
Case Closed: Accelerating Incident Response in the Singularity Operations Center
Michael FrancessDirector, Cybersecurity Advanced Threat, Wyndham Hotels & Resorts
Security teams are overwhelmed by alerts and struggle to manage incidents end-to-end. Discover the latest innovations in the Singularity Operations Center, including a redesigned analyst experience, configurable alert views, and an upcoming capability that auto-correlates alerts into incidents with tasks, artifacts, and a shared workspace for real-time collaboration. See how teams can investigate, coordinate, and resolve threats faster from a single console.
Track:
Architecting the Autonomous SOC
Audience:
Practitioner
Product:
AI SIEMPlatform
Technical Level:
200 - Intermediate
Speaker Type:
CustomerSentinelOne
10:15 AM - 11:00 AM
Customer Zero: How SentinelOne Runs on SentinelOne
Reeny SondhiChief Trust Officer, SentinelOne
At SentinelOne, our own security team is one of our most demanding customers. This session goes inside our security organization to show how our teams use SentinelOne products against live threats every day, and how that daily use fuels a direct feedback loop with our product teams. See how real-world pain points and ideas surfaced by our own SOC get captured, prioritized, and turned into shipped capabilities, making our platform more battle-tested for the entire customer community.
Track:
Live From the Frontline
Audience:
Business Leader
Product:
Exposure Management
Technical Level:
100 - All Levels
Speaker Type:
SentinelOne
10:15 AM - 11:00 AM
Lean Team, Real Threats: Managing EDR and Wayfinder MDR in a Multi-Facility Healthcare Environment
Shawn ParkerIT Director, Elder Outreach
Healthcare organizations face real cybersecurity risk, but many operate with small IT teams, limited budgets, and high operational demands. This session shares practical lessons from using SentinelOne EDR and MDR in a multi-facility senior care environment, including deployment, response, staff impact, alert handling, and how endpoint security fits into a broader, realistic security program.
Track:
Protecting Attack Surfaces in the Agentic Era
Audience:
Business LeaderPractitioner
Product:
EndpointWayfinder
Technical Level:
100 - All Levels
Speaker Type:
Customer
10:15 AM - 11:00 AM
One Platform, No New Tool Required: A Guide to Singularity Exposure Management with JetBlue
Andy MaloneManager of Threat Detection & Response, JetBlue
King NgCyber Security Architect, JetBlue
Tal ShemeshStaff Product Manager, Exposure management, SentinelOne
While the exposure backlog piles up, the real question remains: which exposures are actually exploitable and what to fix first? Most teams tackle this by layering on a different tool for every surface, each with its own agent, separate console, and a disconnected view of risk. SentinelOne closes that gap in a single platform: the same agent already protecting endpoints extends into the network to surface unmanaged devices, while an agentless approach covers cloud assets and AI services across multi-cloud environments. Teams can automate pre-approved, remediation workflows, all in the same tool. This session includes a live walkthrough of the full path, from exposure to remediation without leaving the console. JetBlue joins this session to share their risk management journey with SentinelOne, from EDR and managing vulnerabilities, and the benefits of consolidating their teams and workflows into a unified platform.
Track:
Protecting Attack Surfaces in the Agentic Era
Audience:
Practitioner
Product:
Exposure Management
Technical Level:
100 - All Levels
Speaker Type:
SentinelOne
10:15 AM - 11:00 AM
SentinelOne Prompt Security: Latest Innovations and What's on the Roadmap
Benji PremingerHead Of Product, Prompt, SentinelOne
Join SentinelOne's Head of Product for Prompt Security to dive into the latest innovations and what's next on the AI Security roadmap. We'll cover some of the most impactful upcoming investments across AI Usage Control, AI Application Security, and Agentic AI Security. We'll walk through the vision, strategy, and product roadmap designed to secure AI at every stage and how it all connects with the Singularity Platform.
Track:
Securing the AI Lifecycle from Prompt to Production
Audience:
Business LeaderPractitioner
Product:
PlatformPrompt
Technical Level:
100 - All Levels
Speaker Type:
SentinelOne
10:15 AM PDT
10:15 AM - 1:15 PM
10:15 AM - 1:15 PM
Public Sector Breakout and Luncheon
Alex KirklandState Deputy Chief Information Security Officer/Director of AI Security, Georgia Technology Authority
Cyber priorities. Policy shifts. Funding outlooks. Get the critical insights and product updates straight from SentinelOne’s Public Sector leadership team. Join a candid customer panel on how AI-powered SecOps drives better mission outcomes. Connect with industry peers over thought leadership and a hosted networking lunch.
11:15 AM PDT
11:15 AM - 12:00 PM
11:15 AM - 12:00 PM
AI Governance in the Enterprise
Lori JaycoxFounder & CISO, Captain Chaos Consulting
AI deployments are outpacing governance. Organizations are shipping agents, models, and AI-integrated workflows into production before anyone has mapped what they can access, what they can do, or under what controls they operate. Governance isn't a policy written after the fact. It runs from the first code commit through every model update, agent action, and API call. This session shows how to build an AI governance program that keeps pace with deployment speed, satisfies EU AI Act and NIST AI RMF requirements, and gives security and compliance teams the audit trail they need to prove controls were in place.
Track:
Securing the AI Lifecycle from Prompt to Production
Audience:
Business Leader
Product:
Prompt
Technical Level:
100 - All Levels
Speaker Type:
Customer
11:15 AM - 12:00 PM
Inside the Lab, Ahead of the Roadmap: What We're Learning for the Autonomous SOC
Carter ChurchMTS, AI Engineering, SentinelOne
Spencer LichtensteinVice President of Product Management, SentinelOne
SentinelOne runs an AI innovation lab that has been at work for the last year using the latest in frontier AI capabilities, putting agentic SOC use cases through their paces. Hear from product leadership how we test frontier AI against real SOC operations, what we learned about trust, automation limits, and human oversight, and what's on the horizon. This is a look at where the Autonomous SOC goes next.
Track:
Architecting the Autonomous SOC
Audience:
Business LeaderPractitioner
Product:
Purple AI
Technical Level:
100 - All Levels
Speaker Type:
SentinelOne
11:15 AM - 12:00 PM
Managed Security's Three Unmet Promises in the Agentic AI Era
Agentic AI has raised the ceiling on what managed security can deliver: faster triage, broader coverage, autonomous investigation. But beneath the velocity, three fundamental problems remain unsolved: coverage that evolves with your actual attack surface; memory that carries investigation context across analyst rotations; and human judgment that stays accountable for what AI models produce. Solving each in isolation isn't enough; they only deliver real value when they work as one system. In this session, the Wayfinder Threat Services Product Management team will walk through how coverage, memory, and judgment come together in modern managed security, and what that means for organizations navigating this new era.
Track:
Protecting Attack Surfaces in the Agentic Era
Audience:
Business LeaderPractitioner
Product:
Wayfinder
Technical Level:
100 - All Levels
Speaker Type:
SentinelOne
11:15 AM - 12:00 PM
No AI Without ARMOR & ARGUS: Frameworks for Securing AI-Driven Security Operations
Zach CarnesTechnical Solutions Architect - SecOps, World Wide Technology
Jordan HildebrandGlobal Cyber Practice Director, WWT
AI is transforming security operations — and introducing a new class of risk. WWT's ARMOR (AI Readiness Model for Operational Resilience) gives security leaders a vendor-agnostic blueprint to secure AI deployments across seven domains: GRC, Model Protection, Infrastructure Security, Secure AI Operations, SDLC, Data Protection, and Cyber Resilience. In this session, WWT and SentinelOne show how ARMOR maps to real-world AI-powered SOC deployments — and how to accelerate adoption.
Track:
Securing the AI Lifecycle from Prompt to Production
Audience:
Business Leader
Product:
PlatformPromptPurple AI
Technical Level:
100 - All Levels
Speaker Type:
Partner
11:15 AM - 12:00 PM
Two Supply Chain Attacks, Twelve Days Apart: Detection and Response Using SentinelOne
In March 2026, our security team faced two supply chain attacks twelve days apart - Trivy via GitHub Actions, axios via a trojanized npm package. One was clean. One hit our AKS cluster. This session covers both: real-time S1QL detection rules, CWPP-driven container hunting, blast radius assessment, and how operational maturity at this scale directly translates to enterprise customer confidence and commercial trust.
Threat intelligence has never had more data. Telemetry, actor reporting, and vulnerability disclosure exist at a scale the industry has never seen. The problem is turning that knowledge into action fast enough to make a difference. This talk looks at how attacker tempo is compressing and how AI is lowering the cost of research, exploitation, deception, and scale. It covers PRC-nexus AI-assisted vulnerability research, DPRK remote-worker infiltration, and why strategic attack surfaces may be a more durable planning unit than individual CVEs. It closes with a practical discussion around how we need to adapt our defenses in response to this growing threat.
Track:
Live From the Frontline
Audience:
Business LeaderPractitioner
Technical Level:
100 - All Levels
Speaker Type:
SentinelOne
1:30 PM - 2:15 PM
Faster Answers, Fewer Blind Spots with SentinelOne and Google Threat Intelligence
Sarah SeilerHead of Partnership Program Office, Google Threat Intelligence Group, Google Cloud Security
Andre AlfredSr Director, Cloud Security Threat Operations, Google
Every alert your SOC sees is only as good as the intelligence behind it. This session shows how SentinelOne's proprietary telemetry and Google Threat Intelligence work in a continuous loop, sharpening each other with every alert. Backed by validated integrations across Google Security Operations, Google Threat Intelligence, and Chrome Enterprise, this partnership gives defenders faster answers, fewer blind spots, and higher-fidelity context at every stage of investigation and response, even as attacks on AI agents accelerate.
Track:
Protecting Attack Surfaces in the Agentic Era
Audience:
Business Leader
Product:
Wayfinder
Technical Level:
100 - All Levels
Speaker Type:
Partner
1:30 PM - 2:15 PM
Machine Speed, Human Trust: 451 Research on the State of AI in the SOC
Mark EhrPrincipal Research Analyst, S&P Global 451 Research
Michael FrancessDirector, Cybersecurity Advanced Threat, Wyndham Hotels & Resorts
Nico DiamondLead Security Operations Center Analyst, Alliant Credit Union
Attacks move at machine speed. Can your SOC keep up? 451 Research analyst Mark Ehr unveils 2026 survey data from 600+ security leaders: 98% are ramping up AI investment, yet only half have gone live, a third are still testing the waters. Almost none have made the jump to full trust. Join SentinelOne customers from Wyndham, Nebraska Medical Center, and Alliant Credit Union as they react live to the findings, sharing what matches reality and what falls short. You’ll learn where they are on their journey with experimenting with AI to trusting it in SecOps production, how it's impacting training, MTTR, and alert fatigue, plus what they have planned next.
Track:
Architecting the Autonomous SOC
Audience:
Business LeaderPractitioner
Product:
AI SIEMData PipelinesHyperautomationPurple AI
Technical Level:
100 - All Levels
Speaker Type:
Customer
1:30 PM - 2:15 PM
SecOps Optimization Tips from a Global MSSP
Nicholas JasperCyber Threat Analyst, LevelBlue
Hayden StimartTeam Lead, MSS Public Sector, LevelBlue
Most SOCs don't have a detection problem. They have a "what happens next" problem: alerts that sit in a queue, handoffs that stall, and containment that waits on the wrong approval. Two experts from LevelBlue's global managed security team share the operational changes that have shortened dwell time and sped up response across endpoint, cloud, and identity environments running SentinelOne, including public sector environments. Expect specific fixes to triage, escalation, and playbook design, drawn from real investigations, along with the mistakes behind each lesson. You'll leave with steps you can apply to your own SOC, whether you run it in-house or with a partner.
Track:
Architecting the Autonomous SOC
Audience:
Practitioner
Product:
AI SIEMEndpoint
Technical Level:
100 - All Levels
Speaker Type:
Partner
1:30 PM - 2:15 PM
Securing the Invisible Pipeline: How Agentic AI and MCP Break Everything You Assumed About Perimeter Security
Carlos PayésStrategic AI Executive, SentinelOne
Traditional security was designed for a world where humans made requests and tools waited. Agentic AI broke that assumption. When AI systems chain tools, call APIs, and act autonomously through protocols like MCP (Model Context Protocol), they create an attack surface that static, perimeter-based controls were never designed to see. A prompt injection can reach a credential. That credential can open a cloud service. That cloud service can instruct another agent, and none of it looks like an attack until three systems later. This session breaks down how prompt injection, tool abuse, and data exfiltration work in agentic environments, where defenders are blind today, and what a real security architecture looks like when the agent is the threat vector.
Track:
Securing the AI Lifecycle from Prompt to Production
Audience:
Practitioner
Product:
Prompt
Technical Level:
200 - Intermediate
Speaker Type:
SentinelOne
2:30 PM PDT
2:30 PM - 3:15 PM
2:30 PM - 3:15 PM
Before the Prompt: Building a Secure AI Cloud Foundation
Dave GoldVP, Global Field CTO/CISO, SentinelOne
AI adoption is moving faster than governance. Agents, models, and AI services are entering cloud environments before security teams can fully see what exists, who can access it, or what data those systems can reach. This session shows how SentinelOne helps teams build a secure AI foundation with AI-SPM, DSPM, AI Red Teaming, and runtime protection to find risky assets, understand data exposure, validate real weaknesses, and stop sensitive data loss before the first prompt is ever sent.
Track:
Securing the AI Lifecycle from Prompt to Production
Audience:
Business LeaderPractitioner
Product:
CloudPrompt
Technical Level:
200 - Intermediate
Speaker Type:
SentinelOne
2:30 PM - 3:15 PM
Deploy Fast, Govern Faster: AWS and SentinelOne on Agentic AI
Ross WarrenSenior Security Partner Solutions Architect, AWS
AI agents are moving faster than most security teams can govern them. In this session, AWS and SentinelOne unpack what it takes to close that gap, from our expanding partnership to the recent launch of unified AI governance across Amazon Bedrock AgentCore. We'll share how enterprises are gaining real-time visibility, policy enforcement, and autonomous remediation across their AI estate, and what it means for the future of the SOC: faster, smarter, and built for the pace of AI.
Track:
Architecting the Autonomous SOC
Audience:
Business Leader
Technical Level:
100 - All Levels
Speaker Type:
Partner
2:30 PM - 3:15 PM
Operationalizing CTI: Hunting for Adversarial Behaviors
Mark ParantoSenior Threat Hunter, SAP
Operationalizing CTI: Hunting for Adversarial Behaviors, highlights real-world examples (Shai-Hulud & TeamPCP) where threat actors rapidly changed indicators while reusing the same TTPs and behavioral patterns across multiple campaigns. The session emphasizes why organizations must evolve beyond IOC-centric strategies and invest more heavily in behavioral-based detections, visibility, and proactive hunting operations to improve resilience against modern adversaries and reduce detection gaps.
Track:
Protecting Attack Surfaces in the Agentic Era
Audience:
Practitioner
Product:
Wayfinder
Technical Level:
200 - Intermediate
Speaker Type:
Customer
2:30 PM - 3:15 PM
Protect More, Consume Less, Catch Cloud Threats Where They Run
Cloud environments generate more telemetry than ever. Tools built for yesterday's scale slow you down and bury the signals that matter. This session shows how SentinelOne treats both as one fix. It starts with detection that spans the entire stack, from infrastructure to the applications running inside it. Every alert arrives with the context analysts need, so they respond immediately instead of investigating first. Your environment keeps running without the added resource cost.
Track:
Protecting Attack Surfaces in the Agentic Era
Audience:
Business LeaderPractitioner
Product:
Cloud
Technical Level:
100 - All Levels
Speaker Type:
SentinelOne
2:30 PM - 3:15 PM
The Com: An Ecosystem in Evolution
Drea LondonVP Incident Readiness and Response, SentinelOne
Get an exclusive security update from our experts and threat researchers on the underworld activities of The Com. Learn about their origins, evolving ecosystem, emerging tactics and targeting, and the expanding investigative and law-enforcement response. Please note: Due to the sensitivity of the content, attendees will be asked to power off laptops and cellphones for the duration of the session.
Track:
Live From the Frontline
Audience:
Business LeaderPractitioner
Technical Level:
100 - All Levels
Speaker Type:
SentinelOne
4:00 PM PDT
4:00 PM - 5:00 PM
Closing Keynote
4:00 PM - 5:00 PM
Clifford StollAmerican Astronomer, Author and Teacher
6:30 PM PDT
6:30 PM - 9:30 PM
After Dark Party
6:30 PM - 9:30 PM
Join us for a night out at the iconic Jason Aldean's Kitchen + Bar in the heart of Las Vegas! Cap off an incredible OneCon with live entertainment, fun surprises, and plenty of food and drinks. This is your chance to unwind, connect, and celebrate with the team in true Vegas style. You won't want to miss it!