purple-ai

Generate PowerQuery strings and map MITRE ATT&CK TTPs via SentinelOne Purple AI.

39|17|Updated Feb 4, 2026
One-click install
npx skills add https://github.com/wyre-technology/msp-claude-plugins --skill purple-ai
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: purple-ai
Source: https://github.com/wyre-technology/msp-claude-plugins/tree/main/msp-claude-plugins/sentinelone/sentinelone/skills/purple-ai
Command: npx skills add https://github.com/wyre-technology/msp-claude-plugins --skill purple-ai

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

This Skill empowers cybersecurity analysts to rapidly investigate threats, hunt for malicious activity, and understand security incidents using natural language queries within the SentinelOne platform.

Core Features & Use Cases

  • Natural Language Investigation: Ask questions about threats, behaviors, and anomalies in plain English.
  • PowerQuery Generation: Automatically generates PowerQuery strings for in-depth data analysis.
  • MITRE ATT&CK Mapping: Provides context by mapping findings to MITRE ATT&CK techniques.
  • Use Case: An analyst can ask "Find PowerShell processes connecting to external IPs in the last 24 hours" and receive both an analysis and a ready-to-execute PowerQuery.

Quick Start

Use the purple_ai tool to investigate suspicious PowerShell activity by asking it to find PowerShell processes that have established network connections to external IP addresses in the last 24 hours.

Frequently Asked Questions about purple-ai

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I investigate SentinelOne threats using natural language queries?

SentinelOne threat investigation uses natural language processing to analyze security telemetry across endpoints, cloud workloads, and identities. You ask plain English questions about threats or anomalies, and the system returns an analysis with ready-to-execute PowerQuery strings for deeper data inspection.

Can I generate PowerQuery strings for threat hunting from plain English?

Yes, PowerQuery generation translates natural language questions into ready-to-execute query strings for in-depth security telemetry analysis. By asking about specific behaviors like PowerShell processes connecting to external IPs, the system automatically builds the corresponding query logic to hunt for malicious activity.

Does SentinelOne Purple AI map detected threats to MITRE ATT&CK techniques?

MITRE ATT&CK mapping provides context by linking detected threats and behavioral anomalies to known adversary tactics, techniques, and procedures. This contextual mapping helps cybersecurity analysts understand the broader attack framework and threat lifecycle during investigations.

What is the best way to hunt for behavioral anomalies across cloud workloads and endpoints?

Behavioral anomaly analysis across endpoints, cloud workloads, and identities is best handled by querying security telemetry with natural language to find suspicious activities. This approach leverages AI to rapidly identify malicious behavior and generate PowerQueries for targeted threat hunting.

Do I need a specific tool to execute PowerQuery for cybersecurity threat analysis?

Yes, executing PowerQuery for cybersecurity threat analysis requires the dedicated purple_ai tool for query execution and analysis. This tool processes the natural language input, generates the query strings, and returns the behavioral anomaly findings across your telemetry.