Cybersecurity platform company SentinelOne has acquired identity security company Attivo Networks. SentinelOne’s AI-powered prevention, detection, and response capabilities are now extended to identity-based attacks, raising the bar for XDR and speeding business zero trust adoption.

SentinelOne will pay $616.5 million in cash and shares to purchase Attivo Networks under the terms of the deal. The deal is scheduled to occur in the second quarter of SentinelOne’s fiscal year, subject to regulatory approval and other standard closing conditions.
Attivo Networks protects customers throughout the world, from Fortune 500 organizations to government agencies, from identity theft, privilege escalation, and lateral movement threats. The Identity Detection and Response (IDR) expert company offers an innovative protection against identity compromise, privilege escalation, and lateral movement assaults. By providing the highest visibility into security exposures and attack pathways, the Attivo NBetworks products prevent and derail attack escalation efforts across endpoints, Active Directory, and cloud environments.
“The shift to hybrid work and increased cloud adoption has established identity as the new perimeter, highlighting the importance of visibility into user activity,” said Nicholas Warner, Chief Operating Officer (COO) at SentinelOne. “Identity Threat Detection and Response (ITDR) is the missing link in holistic XDR and zero trust strategies. Our Attivo acquisition is a natural platform progression for protecting organizations from threats at every stage of the attack lifecycle.”
Identity Threat Detection & Response
As part of Singularity XDR for autonomous protection, SentinelOne and Attivo Networks will collaborate to provide full identity security, including:
- Identity Threat Detection and Response – The identity suite from Attivo provides comprehensive protection, detection, and reaction. It supports conditional access and zero trust cybersecurity by protecting against credential theft, privilege escalation, lateral movement, data cloaking, identity disclosure, and more in real time.
- Identity Infrastructure Assessment – Attivo’s identity assessment tool enables identity-focused attack surface reduction by providing quick Active Directory visibility of misconfigurations, suspicious password and account changes, credential exposures, unwanted access, and more.
- Identity Cyber Deception – Attivo’s network and cloud-based deception suite entices intruders to divulge their true identity. Organizations get the benefit of time by misdirecting attacks through strategies such as breadcrumbs and fake accounts, files, and IPs, allowing them to discover, analyze, and halt attackers and insider threats without compromising organizational assets.
“We are thrilled to join SentinelOne, the category leader in XDR. Attivo’s solutions are a perfect complement, as an XDR with identity protection significantly improves organizational security posture,” said Tushar Kothari, CEO at Attivo Networks. “As the threat landscape evolves, identity remains the central nervous system of the enterprise. Combined with the power of SentinelOne’s autonomous XDR, we’ll bring real-time identity threat detection and response to the front lines of cyberdefense.”
“The acquisition of Attivo Networks continues our commitment to defining and delivering autonomous XDR,” said Tomer Weingarten, CEO at SentinelOne. “Identity fuses together all enterprise assets, and I see identity threat detection and response as an integral part of our XDR vision. Attivo Networks is the right technology and team to advance our portfolio, complementing our hypergrowth and accelerating enterprise zero trust adoption.”