Adversarial AI: Thinking Like Attackers in the Age of AI
Attackers are evolving with AI faster than we realize and defenders must do the same. In this gamified, interactive session, explore how adversaries are leveraging AI for evasion, automation, and scale. Then map those tactics to AI-driven defenses within SentinelOne. Participants will engage in scenario-based exercises to anticipate attacker behavior and strengthen proactive security strategies.
9:00 AM - 12:00 PM
SentinelOne University
AI-Driven Investigation: From Alert to Root Cause in Minutes
Harness the full power of AI-driven investigations across the Singularity Platform. In this hands-on session, you’ll learn how AI correlates telemetry, accelerates root cause analysis by correlating across multiple storylines, and implement hands-off vs human-in-the-loop AI. Walk away with repeatable, AI-assisted workflows that dramatically reduce mean time to respond (MTTR) and elevate analyst efficiency.
9:00 AM - 12:00 PM
SentinelOne University
Building and Optimizing Data Pipelines for AI SIEM
AI is only as strong as the data behind it. This session focuses on designing, optimizing, and scaling data pipelines that fuel SentinelOne’s AI SIEM. Learn how to ingest, normalize, and enrich, high-volume telemetry to improve detection accuracy, reduce noise, and unlock more powerful AI-driven insights across your environment.
9:00 AM - 12:00 PM
SentinelOne University
Secure Your AI: Protecting Models, Data, and Usage at Scale
As AI adoption accelerates, so do new risk surfaces. This session focuses on security in your AI ecosystem, from models and training data to prompts and outputs. Learn how to identify vulnerabilities, enforce governance, and apply SentinelOne’s capabilities using Prompt to monitor and protect applications across the organization.
1:00 PM PDT
1:00 PM - 4:00 PM
1:00 PM - 4:00 PM
SentinelOne University
Hyperautomation in the SOC: From Alert Fatigue to Autonomous Response
Manual processes slow down security teams when speed matters most. In this session, you’ll design and implement hyperautomation workflows using SentinelOne to orchestrate detection, investigation, and response. Learn how to eliminate repetitive tasks and enable autonomous security operations at scale.
1:00 PM - 4:00 PM
SentinelOne University
Unified Protection: Endpoint and Identity Defense
This session explores SentinelOne's capabilities of Identity and Endpoint protection. Through instructor demonstrations and discussion, you will learn how identity protection complements endpoint detection, enabling faster, more confident response decisions.
5:00 PM PDT
5:00 PM - 6:30 PM
Opening Keynote
5:00 PM - 6:30 PM
6:45 PM PDT
6:45 PM - 8:15 PM
Welcome Reception
6:45 PM - 8:15 PM
Wednesday
October 21, 2026
8:00 AM PDT
8:00 AM - 9:00 AM
Breakfast & Expo
8:00 AM - 9:00 AM
9:00 AM PDT
9:00 AM - 1:00 PM
Keynotes
9:00 AM - 1:00 PM
1:00 PM PDT
1:00 PM - 2:00 PM
Lunch & Expo
1:00 PM - 2:00 PM
2:00 PM PDT
2:00 PM - 2:45 PM
2:00 PM - 2:45 PM
Beyond the Human Perimeter: AI-SPM in the Age of Agentic Identity
Service accounts, API keys, and AI agents now authenticate, request access, and act, but identity telemetry still assumes a human is behind every login. Each agent you deploy is a new identity with permissions most security programs can't monitor or explain. This session, brought to you by Digital Hands and SentinelOne, argues for AI Security Posture Management as the next layer of identity defense: why privilege drift and orphaned access are accelerating, how ISPM and ITDR are converging, and how to close the gap between AI adoption speed and governance maturity.
Track:
Securing the AI Lifecycle from Prompt to Production
Audience:
Business Leader
Product:
CloudPrompt
Technical Level:
200 - Intermediate
Speaker Type:
Partner
2:00 PM - 2:45 PM
Digital Extortion Compliance and Why It Matters to You - Driving Defensible Compliance and Extortion Decisions
Explore the risks surrounding ransom payments and the financial, operational, and regulatory consequences of compliance missteps. As cyber incidents increasingly intersect with financial crime, find out how to integrate data and intelligence to drive defensible decisions. Drawing on decades of experience in cryptocurrency operations and sanctions compliance, John Morrissey, Director, Cryptocurrency Operations and Compliance, Arete, will discuss the complexities of digital extortion and the value of a comprehensive Compliance & Sanctions Analysis process.
Track:
Live From the Frontline
Audience:
Business Leader
Technical Level:
100 - All Levels
Speaker Type:
Partner
2:00 PM - 2:45 PM
From Alert to Root Cause: Scaling DFIR with RemoteOps Forensics, APIs, and AI
Living-off-the-land and remote access tool abuse can leave critical clues in local endpoint artifacts that alert telemetry alone may not fully explain. This session shows how Raymond James built MOAF (Mother Of All Forensics), an analyst-led workflow using SentinelOne RemoteOps Forensics and APIs to collect, enrich, normalize, and agentically review host evidence so IR teams can move from alert to root cause and data-exposure decisions faster. Attendees will learn a repeatable pattern for pairing SentinelOne telemetry with host artifacts, scaling RemoteOps evidence collection, fusing timelines, adding analyst-in-the-loop AI review, and producing faster, more consistent root-cause, scope, and data-exposure decisions.
Track:
Protecting Attack Surfaces in the Agentic Era
Audience:
Practitioner
Product:
Endpoint
Technical Level:
200 - Intermediate
Speaker Type:
Customer
2:00 PM - 2:45 PM
What's Next: Attack Surfaces Roadmap & Vision
Join us to discover the exciting new features and capabilities coming soon to SentinelOne's attack surfaces portfolio. We'll cover some of the most impactful upcoming investments across Endpoint, Identity, Cloud, and Exposure Management, giving customers a clear picture of what's coming in the near-to-mid term. We'll walk through the vision, strategy, and product roadmap designed to protect customers from advanced threats, and set them up for success against evolving risk.
Track:
Protecting Attack Surfaces in the Agentic Era
Audience:
Business LeaderPractitioner
Product:
CloudEndpointExposure ManagementIdentity
Technical Level:
100 - All Levels
Speaker Type:
SentinelOne
3:00 PM PDT
3:00 PM - 3:45 PM
3:00 PM - 3:45 PM
Architecting the Autonomous SOC: What's Next Across AI SIEM, Data Pipelines, Purple AI, and Hyperautomation
Most security stacks force analysts to bridge the gaps as each tool evolves on its own timeline. This session lays out where AI SIEM, AI Data Pipelines, Purple AI, and Hyperautomation are headed next, and why SentinelOne is building all four on one continuous path instead of four separate ones: from raw data, to detection, to investigation, to autonomous response. See what's shipping soon, what's next, and what it takes to architect the autonomous SOC end to end.
Track:
Architecting the Autonomous SOC
Audience:
Practitioner
Product:
AI SIEMData PipelinesHyperautomationPlatformPurple AI
Technical Level:
100 - All Levels
Speaker Type:
SentinelOne
3:00 PM - 3:45 PM
Detection Operations: The Latest Research and Next Wave of Detection Innovations
Discover the real-world threat landscape through the lens of SentinelOne's own detection operations, which monitor 32 million endpoints and process 10 petabytes of data every day. In this session, attendees will gain a clear understanding of what threats SentinelOne is actively detecting in the wild, how that intelligence translates into powerful, proactive protection, and get an exclusive look at the new detection infrastructure SentinelOne is building to stay ahead of tomorrow's threats.
Track:
Protecting Attack Surfaces in the Agentic Era
Audience:
Business LeaderPractitioner
Product:
EndpointPlatform
Technical Level:
100 - All Levels
Speaker Type:
SentinelOne
3:00 PM - 3:45 PM
No Network? No Problem: We Have Your Air-Gapped Environments Covered!
Attackers don't always come through the network. In high-security environments, connectivity blind spots create risks that traditional tools weren't built for, making the isolation itself the vulnerable blind spot. No connectivity means zero visibility against threats originating from the inside or out.This session covers how to protect fully isolated, compliance-heavy, or data-sovereignty-constrained environments. Learn how to extend endpoint security to systems that can't touch the cloud, see what that architecture looks like in practice, and discover how teams get total coverage without compromising isolation requirements.
Track:
Protecting Attack Surfaces in the Agentic Era
Audience:
Practitioner
Product:
Endpoint
Technical Level:
200 - Intermediate
Speaker Type:
CustomerSentinelOne
3:00 PM - 3:45 PM
The Volume Problem: Defending at Machine Speed in the Age of AI-Discovered Vulnerabilities
AI is changing both sides of the security equation. Frontier models and autonomous agents can now discover vulnerabilities, analyze code, and identify attack paths at a speed and scale no human team can match. Open source maintainers are already drowning in AI-generated bug reports, while enterprise security teams face the same challenge: more findings, more noise, and too little context. The risk is not simply that AI will uncover more weaknesses, but that attackers can compress the time between discovery and exploitation and operate at machine speed. Defenders need AI security strategies that can validate findings, separate genuine risk from plausible-looking noise, and prioritize what matters most. In this session, we’ll explore how Wayfinder Frontier AI Services combines agentic workflows with expert analysis to deliver validated, high-impact findings teams can confidently act on.
Track:
Securing the AI Lifecycle from Prompt to Production
Audience:
Business LeaderPractitioner
Product:
EndpointExposure ManagementWayfinder
Technical Level:
100 - All Levels
Speaker Type:
SentinelOne
4:00 PM PDT
4:00 PM - 4:45 PM
4:00 PM - 4:45 PM
After the Ransom: Moving from Legacy Blind Spots to AI-Powered SOC Operations
When LockBit ransomware bypassed legacy AV to halt a firm's operations, a major migration began. In this session, the IT leader who survived the breach details how he now uses SentinelOne AI SIEM to close critical visibility gaps. Discover how small teams under intense regulatory pressure can automate triage, eliminate coverage blind spots, and maximize limited resources. Get a candid practitioner’s blueprint to protect your brand before your own LockBit moment.
Track:
Architecting the Autonomous SOC
Audience:
Business Leader
Product:
AI SIEM
Technical Level:
100 - All Levels
Speaker Type:
Customer
4:00 PM - 4:45 PM
Operationalizing CTI: Hunting for Adversarial Behaviors
Operationalizing CTI: Hunting for Adversarial Behaviors, highlights real-world examples (Shai-Hulud & TeamPCP) where threat actors rapidly changed indicators while reusing the same TTPs and behavioral patterns across multiple campaigns. The session emphasizes why organizations must evolve beyond IOC-centric strategies and invest more heavily in behavioral-based detections, visibility, and proactive hunting operations to improve resilience against modern adversaries and reduce detection gaps.
Track:
Protecting Attack Surfaces in the Agentic Era
Audience:
Practitioner
Product:
Wayfinder
Technical Level:
200 - Intermediate
Speaker Type:
Customer
4:00 PM - 4:45 PM
The Com: An Ecosystem in Evolution
Get an exclusive security update from our experts and threat researchers on the underworld activities of The Com. Learn about their origins, evolving ecosystem, emerging tactics and targeting, and the expanding investigative and law-enforcement response. Please note: Due to the sensitivity of the content, attendees will be asked to power off laptops and cellphones for the duration of the session.
Track:
Live From the Frontline
Audience:
Business LeaderPractitioner
Technical Level:
100 - All Levels
Speaker Type:
SentinelOne
4:00 PM - 4:45 PM
The Invisible Breach: AI Data Poisoning Through Cloud Identities
Security teams often spend a lot of time talking about AI risk in terms of prompts, models, and infrastructure. But what happens when a legitimate cloud identity is compromised and already has the right permissions to tamper with training pipelines and production AI systems? In 2026, attackers poisoned a SageMaker training pipeline at a real organization through a misconfigured identity, silently backdooring the model in production. This session traces that chain live using CIEM-enriched Attack Paths, showing how toxic permission combinations enable privilege escalation, expose full blast radius, and help teams stop identity-driven attacks before AI systems are compromised.
Track:
Securing the AI Lifecycle from Prompt to Production
Audience:
Practitioner
Product:
Cloud
Technical Level:
200 - Intermediate
Speaker Type:
SentinelOne
4:45 PM PDT
4:45 PM - 6:00 PM
Expo Happy Hour
4:45 PM - 6:00 PM
Thursday
October 22, 2026
8:00 AM PDT
8:00 AM - 9:00 AM
Breakfast & Expo
8:00 AM - 9:00 AM
9:15 AM PDT
9:15 AM - 10:00 AM
9:15 AM - 10:00 AM
Closing the Loop: SentinelOne + Tenable and the Future of Continuous Threat Exposure Management
The CTEM category is consolidating quickly — and no single vendor can close the loop alone. SentinelOne owns runtime detection and response. Tenable owns exposure intelligence and vulnerability prioritization. Together, they deliver what neither can independently: a closed-loop workflow from "what's exposed" to "what's being exploited" to "threat contained." This session unveils the joint partnership and what best-of-breed looks like when two category leaders unite.
Track:
Protecting Attack Surfaces in the Agentic Era
Audience:
Business Leader
Product:
Exposure Management
Technical Level:
200 - Intermediate
Speaker Type:
Partner
9:15 AM - 10:00 AM
How RSM Defense Operationalized SentinelOne to Deliver Enterprise-Grade Security at Scale
Leave this session with a concrete framework for operationalizing SentinelOne beyond the agent. RSM Defense's Threat Hunting Supervisor and Senior SOC Analyst will share how their team built a hunt-to-detection loop that has produced 300+ custom STAR rules across hundreds of managed environments, how Purple AI and Agentic Investigation changed SOC operations at scale, and what a real SentinelOne partner relationship looks like at the Paladin level.
Track:
Architecting the Autonomous SOC
Audience:
Practitioner
Product:
Purple AI
Technical Level:
200 - Intermediate
Speaker Type:
Partner
9:15 AM - 10:00 AM
Inside the Hunt: Tracking and Detecting ShinyHunters Across SaaS and Cloud Environments
As organizations continue their migration to cloud and SaaS platforms, cybercriminal groups such as ShinyHunters are capitalizing on expanding attack surfaces. This session provides a deep dive into the group's intrusion methodologies, techniques, identity attacks, data exfiltration methods, and extortion workflows. SentinelOne and KPMG will analyze recent campaigns, discuss detection opportunities across the attack lifecycle, and share practical guidance for defending modern cloud-centric enterprises against data theft and extortion-driven threats.
Track:
Protecting Attack Surfaces in the Agentic Era
Audience:
Practitioner
Product:
Wayfinder
Technical Level:
200 - Intermediate
Speaker Type:
CustomerSentinelOne
9:15 AM - 10:00 AM
Prompt to Production: What a Full AI Attack Surface Actually Looks Like
Most organizations are responding to AI threats the way they always have: a different tool for every problem. One for prompts, one for cloud, one for identity, one for posture. Each new addition widens the gaps between them, and attackers already know where those gaps are. This session presents a unified view of the AI attack surface: four interconnected layers covering the infrastructure AI runs on, the data flowing through it, the models turning inputs into decisions, and the users and agents behind them. A failure at any one travels through every downstream system. See how a single real-world attack crosses all four layers without triggering a single alert in a fragmented environment, and what a connected, platform-based defense looks like from prompt to production.
Track:
Securing the AI Lifecycle from Prompt to Production
Audience:
Business Leader
Product:
CloudEndpointIdentityPlatformPrompt
Technical Level:
100 - All Levels
Speaker Type:
SentinelOne
9:15 AM - 10:00 AM
Where OT Security Is Headed: Inside the Honeywell SentinelOne Partnership
Operational Technology (OT) environments cannot rely on cloud-dependent security, as air-gapped industrial plants require local, completely autonomous protection. Through a landmark strategic partnership, SentinelOne has become Honeywell’s certified Next-Gen Antivirus provider. This session explores how our expanded self-hosted and on-premises portfolio safeguards Experion PKS, the fundamental operating system and "brain" of critical infrastructure. We will demonstrate how our lightweight agent runs flawlessly inside high-stakes, disconnected environments to stop threats at machine speed without risking plant downtime. Attendees will discover how this historic displacement of a 20-year incumbent unlocks a massive market, leveraging a strict "Certification Moat" that protects system warranties while blocking legacy competitors. Ultimately, you will learn how to successfully standardize enterprise security across both traditional IT and highly sensitive, industrial OT networks.
Track:
Protecting Attack Surfaces in the Agentic Era
Audience:
Business Leader
Product:
Endpoint
Technical Level:
200 - Intermediate
Speaker Type:
Partner
10:15 AM PDT
10:15 AM - 11:00 AM
10:15 AM - 11:00 AM
Case Closed: Accelerating Incident Response in the Singularity Operations Center
Security teams are overwhelmed by alerts and struggle to manage incidents end-to-end. Discover the latest innovations in the Singularity Operations Center, including a redesigned analyst experience, configurable alert views, and an upcoming capability that auto-correlates alerts into incidents with tasks, artifacts, and a shared workspace for real-time collaboration. See how teams can investigate, coordinate, and resolve threats faster from a single console.
Track:
Architecting the Autonomous SOC
Audience:
Practitioner
Product:
AI SIEMPlatform
Technical Level:
200 - Intermediate
Speaker Type:
CustomerSentinelOne
10:15 AM - 11:00 AM
Customer Zero: How SentinelOne Runs on SentinelOne
At SentinelOne, our own security team is one of our most demanding customers. This session goes inside our security organization to show how our teams use SentinelOne products against live threats every day, and how that daily use fuels a direct feedback loop with our product teams. See how real-world pain points and ideas surfaced by our own SOC get captured, prioritized, and turned into shipped capabilities, making our platform more battle-tested for the entire customer community.
Track:
Protecting Attack Surfaces in the Agentic Era
Audience:
Business Leader
Product:
Exposure Management
Technical Level:
100 - All Levels
Speaker Type:
SentinelOne
10:15 AM - 11:00 AM
Exploitability is Key: How SentinelOne Prioritizes Exposure Across Endpoint, Network, and Cloud
While the exposure backlog piles up, the real question remains: which exposures are actually exploitable and what to fix first?Most teams tackle this by layering on a different tool for every surface, each with its own agent, separate console, and a disconnected view of risk. SentinelOne closes that gap in a single platform: the same agent already protecting endpoints extends into the network to surface unmanaged devices, while an agentless approach continuously covers cloud assets and AI services across multi-cloud environments, so every exposure lands in one queue ranked by real-world exploitability instead of severity alone. Prioritization considers CISA KEV and EPSS scoring, and, for cloud environments, Verified Exploit Paths, to enable teams to focus on top-priority issues. Teams can then route those issues into pre-approved, automated remediation workflows, all in the same tool.This session includes a live walkthrough of that path: a real exposure queue, prioritized by exploitability, routed to remediation without leaving the workflow. Leave with a practical model for turning a standing backlog into a working process.
Track:
Protecting Attack Surfaces in the Agentic Era
Audience:
Practitioner
Product:
Exposure Management
Technical Level:
100 - All Levels
Speaker Type:
SentinelOne
10:15 AM - 11:00 AM
Lean Team, Real Threats: Managing EDR and Wayfinder MDR in a Multi-Facility Healthcare Environment
Healthcare organizations face real cybersecurity risk, but many operate with small IT teams, limited budgets, and high operational demands. This session shares practical lessons from using SentinelOne EDR and MDR in a multi-facility senior care environment, including deployment, response, staff impact, alert handling, and how endpoint security fits into a broader, realistic security program.
Track:
Protecting Attack Surfaces in the Agentic Era
Audience:
Business LeaderPractitioner
Product:
EndpointWayfinder
Technical Level:
100 - All Levels
Speaker Type:
Customer
10:15 AM - 11:00 AM
The Human Left the Loop: Who's Watching the Agents?
Security controls assume a human in the loop. Agentic AI removes it. This session breaks down what that shift does to your threat model: why "employee using AI" and "agent acting alone" are collapsing into the same risk category, and the core properties (autonomy, composability) that make agents hard to secure with existing tools.
Track:
Securing the AI Lifecycle from Prompt to Production
Audience:
Business LeaderPractitioner
Product:
PlatformPrompt
Technical Level:
100 - All Levels
Speaker Type:
SentinelOne
10:15 AM PDT
10:15 AM - 1:15 PM
10:15 AM - 1:15 PM
Public Sector Breakout and Luncheon
Cyber priorities. Policy shifts. Funding outlooks. Get the critical insights and product updates straight from SentinelOne’s Public Sector leadership team. Join a candid customer panel on how AI-powered SecOps drives better mission outcomes. Connect with industry peers over thought leadership and a hosted networking lunch.
11:15 AM PDT
11:15 AM - 12:00 PM
11:15 AM - 12:00 PM
AI Governance in the Enterprise
AI deployments are outpacing governance. Organizations are shipping agents, models, and AI-integrated workflows into production before anyone has mapped what they can access, what they can do, or under what controls they operate. Governance isn't a policy written after the fact. It runs from the first code commit through every model update, agent action, and API call. This session shows how to build an AI governance program that keeps pace with deployment speed, satisfies EU AI Act and NIST AI RMF requirements, and gives security and compliance teams the audit trail they need to prove controls were in place.
Track:
Securing the AI Lifecycle from Prompt to Production
Audience:
Business Leader
Product:
Prompt
Technical Level:
100 - All Levels
Speaker Type:
Customer
11:15 AM - 12:00 PM
Managed Security's Three Unmet Promises in the Agentic AI Era
Agentic AI has raised the ceiling on what managed security can deliver: faster triage, broader coverage, autonomous investigation. But beneath the velocity, three fundamental problems remain unsolved: coverage that evolves with your actual attack surface; memory that carries investigation context across analyst rotations; and human judgment that stays accountable for what AI models produce. Solving each in isolation isn't enough; they only deliver real value when they work as one system. In this session, the Wayfinder Threat Services Product Management team will walk through how coverage, memory, and judgment come together in modern managed security, and what that means for organizations navigating this new era.
Track:
Protecting Attack Surfaces in the Agentic Era
Audience:
Business LeaderPractitioner
Product:
Wayfinder
Technical Level:
100 - All Levels
Speaker Type:
SentinelOne
11:15 AM - 12:00 PM
No AI Without ARMOR: A Framework for Securing AI-Driven Security Operations
AI is transforming security operations — and introducing a new class of risk. WWT's ARMOR (AI Readiness Model for Operational Resilience) gives security leaders a vendor-agnostic blueprint to secure AI deployments across seven domains: GRC, Model Protection, Infrastructure Security, Secure AI Operations, SDLC, Data Protection, and Cyber Resilience. In this session, WWT and SentinelOne show how ARMOR maps to real-world AI-powered SOC deployments — and how to accelerate adoption.
Track:
Securing the AI Lifecycle from Prompt to Production
Audience:
Business Leader
Product:
PlatformPromptPurple AI
Technical Level:
100 - All Levels
Speaker Type:
Partner
11:15 AM - 12:00 PM
Two Supply Chain Attacks, Twelve Days Apart: Detection and Response Using SentinelOne
In March 2026, our security team faced two supply chain attacks twelve days apart - Trivy via GitHub Actions, axios via a trojanized npm package. One was clean. One hit our AKS cluster. This session covers both: real-time S1QL detection rules, CWPP-driven container hunting, blast radius assessment, and how operational maturity at this scale directly translates to enterprise customer confidence and commercial trust.
Track:
Protecting Attack Surfaces in the Agentic Era
Audience:
Practitioner
Product:
Cloud
Technical Level:
300 - Advanced
Speaker Type:
Customer
12:00 PM PDT
12:00 PM - 1:15 PM
Lunch & Expo
12:00 PM - 1:15 PM
1:30 PM PDT
1:30 PM - 2:15 PM
1:30 PM - 2:15 PM
Faster Answers, Fewer Blind Spots with SentinelOne and Google Threat Intelligence
Every alert your SOC sees is only as good as the intelligence behind it. This session shows how SentinelOne's proprietary telemetry and Google Threat Intelligence work in a continuous loop, sharpening each other with every alert. Backed by validated integrations across Google Security Operations, Google Threat Intelligence, and Chrome Enterprise, this partnership gives defenders faster answers, fewer blind spots, and higher-fidelity context at every stage of investigation and response, even as attacks on AI agents accelerate.
Track:
Protecting Attack Surfaces in the Agentic Era
Audience:
Business Leader
Product:
Wayfinder
Technical Level:
100 - All Levels
Speaker Type:
Partner
1:30 PM - 2:15 PM
Machine Speed, Human Trust: 451 Research on the State of AI in the SOC
Attacks move at machine speed. Can your SOC keep up? 451 Research analyst Mark Ehr unveils 2026 survey data from 600+ security leaders: 98% are ramping up AI investment, yet only half have gone live, a third are still testing the waters. Almost none have made the jump to full trust. Hear SentinelOne customers react live to the findings, sharing what matches reality and what falls short. You’ll learn how they moved from experimenting with AI to trusting it in SecOps production, slashing MTTR, cutting alert fatigue, and reducing burnout.
Track:
Architecting the Autonomous SOC
Audience:
Business LeaderPractitioner
Product:
AI SIEMData PipelinesHyperautomationPurple AI
Technical Level:
100 - All Levels
Speaker Type:
Customer
1:30 PM - 2:15 PM
SecOps Optimization Tips from a Global MSSP
Detection is only half the battle. This session looks at how SentinelOne and LevelBlue work together to close the gap between spotting a threat and actually stopping it, pairing SentinelOne's AI SIEM and Purple AI with LevelBlue's Indigo platform and global MDR team. You'll walk away with real examples of faster detection, shorter dwell time, and quicker containment across endpoints, cloud, and identity, plus lessons learned from running security operations at global scale.
Track:
Architecting the Autonomous SOC
Audience:
Business Leader
Product:
AI SIEMPurple AI
Technical Level:
100 - All Levels
Speaker Type:
Partner
1:30 PM - 2:15 PM
Securing the Invisible Pipeline: How Agentic AI and MCP Break Everything You Assumed About Perimeter Security
Traditional security was designed for a world where humans made requests and tools waited. Agentic AI broke that assumption. When AI systems chain tools, call APIs, and act autonomously through protocols like MCP (Model Context Protocol), they create an attack surface that static, perimeter-based controls were never designed to see. A prompt injection can reach a credential. That credential can open a cloud service. That cloud service can instruct another agent, and none of it looks like an attack until three systems later. This session breaks down how prompt injection, tool abuse, and data exfiltration work in agentic environments, where defenders are blind today, and what a real security architecture looks like when the agent is the threat vector.
Track:
Securing the AI Lifecycle from Prompt to Production
Audience:
Practitioner
Product:
Prompt
Technical Level:
200 - Intermediate
Speaker Type:
SentinelOne
2:30 PM PDT
2:30 PM - 3:15 PM
2:30 PM - 3:15 PM
Before the Prompt: Building a Secure AI Cloud Foundation
AI adoption is moving faster than governance. Agents, models, and AI services are entering cloud environments before security teams can fully see what exists, who can access it, or what data those systems can reach. This session shows how SentinelOne helps teams build a secure AI foundation with AI-SPM, DSPM, AI Red Teaming, and runtime protection to find risky assets, understand data exposure, validate real weaknesses, and stop sensitive data loss before the first prompt is ever sent.
Track:
Securing the AI Lifecycle from Prompt to Production
Audience:
Business LeaderPractitioner
Product:
CloudPrompt
Technical Level:
200 - Intermediate
Speaker Type:
SentinelOne
2:30 PM - 3:15 PM
Deploy Fast, Govern Faster: AWS and SentinelOne on Agentic AI
AI agents are moving faster than most security teams can govern them. In this session, AWS and SentinelOne unpack what it takes to close that gap, from our expanding partnership to the recent launch of unified AI governance across Amazon Bedrock AgentCore. We'll share how enterprises are gaining real-time visibility, policy enforcement, and autonomous remediation across their AI estate, and what it means for the future of the SOC: faster, smarter, and built for the pace of AI.
Track:
Architecting the Autonomous SOC
Audience:
Business Leader
Technical Level:
100 - All Levels
Speaker Type:
Partner
2:30 PM - 3:15 PM
Protect More, Consume Less, Catch Cloud Threats Where They Run
Cloud environments generate more telemetry than ever. Tools built for yesterday's scale slow you down and bury the signals that matter. This session shows how SentinelOne treats both as one fix. It starts with detection that spans the entire stack, from infrastructure to the applications running inside it. Every alert arrives with the context analysts need, so they respond immediately instead of investigating first. Your environment keeps running without the added resource cost.
Track:
Protecting Attack Surfaces in the Agentic Era
Audience:
Business LeaderPractitioner
Product:
Cloud
Technical Level:
100 - All Levels
Speaker Type:
SentinelOne
2:30 PM - 3:15 PM
The Com: An Ecosystem in Evolution
Get an exclusive security update from our experts and threat researchers on the underworld activities of The Com. Learn about their origins, evolving ecosystem, emerging tactics and targeting, and the expanding investigative and law-enforcement response. Please note: Due to the sensitivity of the content, attendees will be asked to power off laptops and cellphones for the duration of the session.
Track:
Live From the Frontline
Audience:
Business LeaderPractitioner
Technical Level:
100 - All Levels
Speaker Type:
SentinelOne
2:30 PM - 3:15 PM
Turning IT Operations Into Your First Line of Defense with NinjaOne and SentinelOne
IT operations and security have operated separately for too long, creating a growing risk as threats accelerate and IT environments become more complex. This session explores how NinjaOne and SentinelOne close that gap, uniting endpoint management with autonomous detection and response to keep every managed device monitored, hardened, and remediated. We’ll share what this partnership means for organizations navigating an attack surface that continues to expand alongside their IT footprint, and how a unified approach changes the game.
Track:
Protecting Attack Surfaces in the Agentic Era
Audience:
Business Leader
Product:
Endpoint
Technical Level:
100 - All Levels
Speaker Type:
Partner
4:00 PM PDT
4:00 PM - 5:00 PM
Keynotes
4:00 PM - 5:00 PM
6:30 PM PDT
6:30 PM - 9:30 PM
After Dark Party
6:30 PM - 9:30 PM
Join us for a night out at the iconic Jason Aldean's Kitchen + Bar in the heart of Las Vegas! Cap off an incredible OneCon with live entertainment, fun surprises, and plenty of food and drinks. This is your chance to unwind, connect, and celebrate with the team in true Vegas style. You won't want to miss it!