{"id":215,"date":"2026-09-26T17:56:44","date_gmt":"2026-09-26T17:56:44","guid":{"rendered":"https:\/\/managedt.com\/blog\/sentinelone-wayfinder-threat-hunting-cloud-coverage\/"},"modified":"2026-09-26T17:56:45","modified_gmt":"2026-09-26T17:56:45","slug":"sentinelone-wayfinder-threat-hunting-cloud-coverage","status":"publish","type":"post","link":"https:\/\/managedt.com\/blog\/sentinelone-wayfinder-threat-hunting-cloud-coverage\/","title":{"rendered":"SentinelOne extends Wayfinder Threat Hunting coverage to AWS, Azure, and Google Cloud"},"content":{"rendered":"<p>SentinelOne has expanded its Wayfinder Threat Hunting service into AWS, Azure, and Google Cloud, giving subscribers one continuous, expert-led hunting capability across endpoints, identities, and cloud workloads. The new Wayfinder Threat Hunting for Cloud layer adds control-plane coverage on top of the existing endpoint hunting and the identity hunting already in place for Okta and Microsoft Entra ID.<\/p>\n<h2>What Wayfinder Threat Hunting for Cloud covers<\/h2>\n<p>The cloud extension combines SentinelOne&#8217;s AI-powered Singularity Platform telemetry with human-led hunting. Coverage spans cloud control-plane abuse, IAM privilege escalation, unauthorized access, and data exfiltration. Continuous, expert-led hunting runs across AWS, Azure, and GCP control-plane activity so defenders get a single view rather than stitched-together logs from three providers.<\/p>\n<p>Hunts in the new cloud package target specific attacker tradecraft:<\/p>\n<ul>\n<li>IAM user enumeration<\/li>\n<li>S3 bucket reconnaissance<\/li>\n<li>Root account logins<\/li>\n<li>AKS cluster-admin credential access<\/li>\n<li>Suspicious IAM policy changes<\/li>\n<li>AMI deregistration<\/li>\n<li>Telemetry destruction<\/li>\n<li>Cross-tenant delegation changes<\/li>\n<\/ul>\n<p>Curated indicators and behavioral rules are mapped to MITRE ATT&#038;CK techniques, and findings arrive with Purple AI summaries for triage.<\/p>\n<h2>Why the cloud control plane is now a frontline<\/h2>\n<p>The cloud has become an even more attractive attack surface as AI adoption has accelerated. A threat actor who compromises a cloud identity or exploits a misconfiguration can move directly to data without ever touching an endpoint, often leaving little trace in the logs a security team already watches. That gap between endpoint telemetry and cloud activity is what the Wayfinder expansion is built to close.<\/p>\n<h2>How it fits with the rest of Wayfinder<\/h2>\n<p>Wayfinder Threat Hunting has grown in three stages: first across the endpoint, then into identity with hunting for Okta and Microsoft Entra ID, and now into the cloud control plane itself. As with the rest of Wayfinder, the new cloud capability uses threat intelligence and intrusion findings from both SentinelOne and Google Threat Intelligence in a single hunting workflow.<\/p>\n<h2>Availability and setup<\/h2>\n<p>Wayfinder Threat Hunting for Cloud is generally available to all existing Wayfinder Threat Hunting customers. Enablement runs through existing Singularity Marketplace plugins for each cloud provider. Customers already using Wayfinder Threat Hunting on identities in Microsoft Entra ID require no additional setup for Azure environments.<\/p>\n<h2>FAQ<\/h2>\n<h3>What is Wayfinder Threat Hunting for Cloud?<\/h3>\n<p>It is the cloud extension of SentinelOne&#8217;s Wayfinder Threat Hunting service, providing continuous, expert-led hunting across AWS, Azure, and GCP control-plane activity. Coverage includes cloud control-plane abuse, IAM privilege escalation, unauthorized access, and data exfiltration.<\/p>\n<h3>Which cloud providers does Wayfinder Threat Hunting for Cloud support?<\/h3>\n<p>The service supports AWS, Azure, and Google Cloud, and combines SentinelOne&#8217;s Singularity Platform telemetry with human-led hunting alongside threat intelligence from SentinelOne and Google Threat Intelligence.<\/p>\n<h3>How do customers enable Wayfinder Threat Hunting for Cloud?<\/h3>\n<p>It is generally available to existing Wayfinder Threat Hunting customers through Singularity Marketplace plugins for each cloud provider. Customers already using Wayfinder Threat Hunting on Microsoft Entra ID identities do not need extra setup for Azure environments.<\/p>\n<p><script type=\"application\/ld+json\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"FAQPage\",\"mainEntity\":[{\"@type\":\"Question\",\"name\":\"What is Wayfinder Threat Hunting for Cloud?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"It is the cloud extension of SentinelOne's Wayfinder Threat Hunting service, providing continuous, expert-led hunting across AWS, Azure, and GCP control-plane activity. Coverage includes cloud control-plane abuse, IAM privilege escalation, unauthorized access, and data exfiltration.\"}},{\"@type\":\"Question\",\"name\":\"Which cloud providers does Wayfinder Threat Hunting for Cloud support?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"The service supports AWS, Azure, and Google Cloud, and combines SentinelOne's Singularity Platform telemetry with human-led hunting alongside threat intelligence from SentinelOne and Google Threat Intelligence.\"}},{\"@type\":\"Question\",\"name\":\"How do customers enable Wayfinder Threat Hunting for Cloud?\",\"acceptedAnswer\":{\"@type\":\"Answer\",\"text\":\"It is generally available to existing Wayfinder Threat Hunting customers through Singularity Marketplace plugins for each cloud provider. Customers already using Wayfinder Threat Hunting on Microsoft Entra ID identities do not need extra setup for Azure environments.\"}}]}]}<\/script><\/p>\n<hr style=\"margin:2.5em 0 1em;opacity:.35\" \/>\n<p style=\"font-size:.85em;opacity:.7\">This article summarizes reporting from <a href=\"https:\/\/www.helpnetsecurity.com\/2026\/09\/25\/sentinelone-extends-wayfinder-threat-hunting\/\" target=\"_blank\" rel=\"nofollow noopener\">helpnetsecurity.com<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>SentinelOne has expanded Wayfinder Threat Hunting to AWS, Azure, and Google Cloud, adding expert-led cloud control-plane coverage to its endpoint and identity<\/p>\n","protected":false},"author":3,"featured_media":214,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-215","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/posts\/215","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/comments?post=215"}],"version-history":[{"count":1,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/posts\/215\/revisions"}],"predecessor-version":[{"id":216,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/posts\/215\/revisions\/216"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/media\/214"}],"wp:attachment":[{"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/media?parent=215"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/categories?post=215"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/managedt.com\/blog\/wp-json\/wp\/v2\/tags?post=215"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}