SentinelOne has expanded its Wayfinder Frontier AI Services, now powered by OpenAI’s Daybreak models through the Daybreak Defense Network. The rollout starts with GPT-5.6-Cyber, which SentinelOne will use to help customers identify and remediate exploitable threats before attackers can act on them. Rather than generating longer vulnerability lists, the service pairs frontier AI models with SentinelOne’s offensive and defensive security experts to prioritize risks that are actually reachable by attackers.
The expansion adds two capabilities: AI-powered code risk analysis, which scans repositories for flaws, exposed secrets, and supply-chain risks, and AI-enabled compromise assessment, which evaluates telemetry to surface posture gaps. Both are reinforced by shared malware analysis and validated by SentinelOne’s security analysts before delivery.
SentinelLABS found GPT-5.6-Cyber excelled at reverse-engineering military-grade malware. Chief Customer Officer Steve Stone said the model has “proven to be exceptionally good at malware analysis, code risk assessments and other offensive cyber capabilities.” The new capabilities are rolling out in private preview.
As a longtime participant in Daybreak Defense Network, OpenAI’s cyber defense initiative, SentinelOne’s AI security and AI research teams have evaluated advanced public and private AI models against cyber tasks to understand where they can most effectively support defensive security workflows. In recent benchmarks, SentinelLABS, the AI and cyber research arm of SentinelOne, found that OpenAI’s GPT-5.6-Cyber delivered best-in-class in reverse engineering and analysis of military-grade malware, like fast16.
“Attackers are increasingly using AI to find and exploit weaknesses with greater speed and scale,” said Steve Stone, Chief Customer Officer, SentinelOne. “Our job is to help close that gap for customers by putting the most advanced models available in the hands of our elite experts to home in on the areas most likely to be attacked. In our testing, OpenAI’s GPT-5.6-Cyber has already proven to be exceptionally good at malware analysis, code risk assessments and other offensive cyber capabilities, making it a perfect fit for Wayfinder Frontier AI Services and our customers.”
In addition to the new models, the expanded Wayfinder Frontier AI Services will deliver two new capability areas, both reinforced by shared malware analysis, detection, and validation:
AI-Powered Code Risk Analysis
- Scans a customer’s repository for OWASP-class flaws, code implants, exposed secrets, and supply-chain risk at machine speed, giving customers a validated view of which vulnerabilities an attacker can actually reach.
- When a scan surfaces a suspected malicious sample, AI-assisted workflows support disassembly and deobfuscation, fusing static and sandbox evidence into an assessment of its capability, persistence, and command-and-control.
- Every verdict yields IOCs, MITRE ATT&CK mapping, and recommended detections for the fleet, validated by SentinelOne’s offensive-security analysts before delivery.
AI-Enabled Compromise Assessment
- Evaluates telemetry against detection rules to surface posture gaps, including potentially risky use of VPNs and proxies, remote-management tools, and other dual-use software, replacing hours of manual review with AI-driven triage.
- When triage surfaces a suspected malicious sample, the same malware analysis capability drives disassembly, deobfuscation, and behavioral analysis to confirm what the sample does and assess its potential scope and impact.
- Customers receive a completed findings package, validated by SentinelOne’s defensive security analysts, ranked by real-world exploitability.

No responses yet