Annual
Threat
Report
A Defender’s Guide
from the Frontlines
Threat
Report
A Defender’s Guide
from the Frontlines
2SentinelOne Annual Threat Report
The cybersecurity industry currently faces a persistent irony: more is known about
threat actor behaviors, infrastructure, and playbooks than at any point in history,
yet the frequency and impact of attacks continues to rise.
The industry standard for annual threat reporting has long focused on cataloging
intrusion statistics and active threat groups, but reality has shown that simply
documenting what happened last year is not enough to prevent what happens
the following year or beyond.
Despite innovations like the MITRE ATT&CK framework and the widespread
adoption of standardized TTP tracking, the availability of detailed threat
intelligence has done little to slow the rate of successful breaches. The difficulty
lies in translating this high-level knowledge into the specific, grounded insights
needed to manage a local environment. Security teams find themselves with vast
amounts of telemetry, but they often lack the context required to distinguish a
genuine intrusion from a harmless anomaly.
The SentinelOne Annual Threat Report is designed to address that gap. Rather
than just naming actors or counting intrusions, we examine the mechanics of how
adversaries exploit the blind spots in organizations’ defensive logic. The goal is to
identify where technical alerts require a better understanding of normal operations
to be useful. By looking at threats through this lens, we can develop more effective
playbooks and prioritize the actions required to maintain the integrity of our
operations.
The insights that follow are not an exhaustive archive of 2025. Instead, they focus
on the technical and operational indicators that reveal an adversary’s intent. By
refining our ability to isolate malicious activity from the background noise of a
modern network, we can identify more effective ways to defeat adversaries who
rely on complexity and the sheer volume of data to hide their tracks.
Foreword
The Need for Clarity
The cybersecurity industry currently faces a persistent irony: more is known about
threat actor behaviors, infrastructure, and playbooks than at any point in history,
yet the frequency and impact of attacks continues to rise.
The industry standard for annual threat reporting has long focused on cataloging
intrusion statistics and active threat groups, but reality has shown that simply
documenting what happened last year is not enough to prevent what happens
the following year or beyond.
Despite innovations like the MITRE ATT&CK framework and the widespread
adoption of standardized TTP tracking, the availability of detailed threat
intelligence has done little to slow the rate of successful breaches. The difficulty
lies in translating this high-level knowledge into the specific, grounded insights
needed to manage a local environment. Security teams find themselves with vast
amounts of telemetry, but they often lack the context required to distinguish a
genuine intrusion from a harmless anomaly.
The SentinelOne Annual Threat Report is designed to address that gap. Rather
than just naming actors or counting intrusions, we examine the mechanics of how
adversaries exploit the blind spots in organizations’ defensive logic. The goal is to
identify where technical alerts require a better understanding of normal operations
to be useful. By looking at threats through this lens, we can develop more effective
playbooks and prioritize the actions required to maintain the integrity of our
operations.
The insights that follow are not an exhaustive archive of 2025. Instead, they focus
on the technical and operational indicators that reveal an adversary’s intent. By
refining our ability to isolate malicious activity from the background noise of a
modern network, we can identify more effective ways to defeat adversaries who
rely on complexity and the sheer volume of data to hide their tracks.
Foreword
The Need for Clarity
3SentinelOne Annual Threat Report
The SentinelOne Annual Threat Report highlights a clear shift in adversaries’ strategic
focus. While targeting core systems such as identity, infrastructure and automation is not
new, we observed these tactics executed at industrial scale in 2025.
As traditional perimeters have softened, much of the meaningful activity now takes place
inside the systems organizations rely on every day rather than at the initial point of entry. In
this report, we examine eight strategic phases that show how adversaries are using speed,
automation and deep integration with identity, infrastructure and automation to pressure
many organizations’ current, human-centred approaches.
Access: In Chapter 1, we show how intrusion has evolved into a mass-marketed
impersonation crisis. Stolen session tokens and automated MFA-bypass kits allow
attackers to maintain the appearance of legitimate activity at scale.
Persistence: Chapter 2 explores how adversaries are “living off the admin”, hijacking
authorized tools to ensure their presence is indistinguishable from routine IT maintenance.
Infrastructure: Chapter 3 describes the systematic targeting of unmanaged legacy edge
devices, and how these are exploited to create persistent beachheads that exist outside
the visibility of traditional endpoint security tools.
Production: Chapter 4 takes us inside the development pipeline and reveals how
adversaries are “shifting left” by integrating malicious logic into the build process itself,
compromising software before it ever reaches production.
Exfiltration: In Chapter 5, we detail how data theft is increasingly executed via authorized
machine identities.
Maintenance: Chapter 6 shows how adversaries are weaponizing vulnerabilities at scale
in systems that are technically patchable but remain unaddressed due to critical or legacy
status.
Connectivity: Chapter 7 delves into the unmonitored communication layer across SaaS,
APIs and integration engines, and shows how threat actors abuse forgotten endpoints and
background services to move data and commands between systems.
Scale: In Chapter 8, we examine how automation, polymorphism and AI-assisted tooling
are being used to increase the speed, scale and resilience of campaigns, compressing
response windows and eroding the effectiveness of purely manual detection and
investigation.
Throughout this report, we focus not only on how attackers are successful, but crucially on
how defenders can meet the challenges that we’ve observed over the last 12 months. Each
section is supplemented with a defender’s playbook that will be of value to anyone working
in Enterprise Security, as well as specific recommendations for SentinelOne customers.
Executive Summary
The SentinelOne Annual Threat Report highlights a clear shift in adversaries’ strategic
focus. While targeting core systems such as identity, infrastructure and automation is not
new, we observed these tactics executed at industrial scale in 2025.
As traditional perimeters have softened, much of the meaningful activity now takes place
inside the systems organizations rely on every day rather than at the initial point of entry. In
this report, we examine eight strategic phases that show how adversaries are using speed,
automation and deep integration with identity, infrastructure and automation to pressure
many organizations’ current, human-centred approaches.
Access: In Chapter 1, we show how intrusion has evolved into a mass-marketed
impersonation crisis. Stolen session tokens and automated MFA-bypass kits allow
attackers to maintain the appearance of legitimate activity at scale.
Persistence: Chapter 2 explores how adversaries are “living off the admin”, hijacking
authorized tools to ensure their presence is indistinguishable from routine IT maintenance.
Infrastructure: Chapter 3 describes the systematic targeting of unmanaged legacy edge
devices, and how these are exploited to create persistent beachheads that exist outside
the visibility of traditional endpoint security tools.
Production: Chapter 4 takes us inside the development pipeline and reveals how
adversaries are “shifting left” by integrating malicious logic into the build process itself,
compromising software before it ever reaches production.
Exfiltration: In Chapter 5, we detail how data theft is increasingly executed via authorized
machine identities.
Maintenance: Chapter 6 shows how adversaries are weaponizing vulnerabilities at scale
in systems that are technically patchable but remain unaddressed due to critical or legacy
status.
Connectivity: Chapter 7 delves into the unmonitored communication layer across SaaS,
APIs and integration engines, and shows how threat actors abuse forgotten endpoints and
background services to move data and commands between systems.
Scale: In Chapter 8, we examine how automation, polymorphism and AI-assisted tooling
are being used to increase the speed, scale and resilience of campaigns, compressing
response windows and eroding the effectiveness of purely manual detection and
investigation.
Throughout this report, we focus not only on how attackers are successful, but crucially on
how defenders can meet the challenges that we’ve observed over the last 12 months. Each
section is supplemented with a defender’s playbook that will be of value to anyone working
in Enterprise Security, as well as specific recommendations for SentinelOne customers.
Executive Summary
4SentinelOne Annual Threat Report
Table of Contents
11 The Challenge for the Defender06 Access – The Identity Paradox
12 Playbook – Defusing the Identity Paradox
20 The Challenge for the Defender13 Persistence – The Trusted Tool
21 Playbook – Defusing the Identity Paradox
28 The Challenge for the Defender24 Infrastructure – Edge Decay
29 Playbook – Defusing the Identity Paradox
38 The Challenge for the Defender31 Production – Living Off the Pipeline
39 Playbook – Defusing the Identity Paradox
46 The Challenge for the Defender41 Exfiltration – The Context Gap
47 Playbook | Defusing the Identity Paradox
53 The Challenge for the Defender49 Maintenance | The Priority Gap
54 Playbook – Defusing the Identity Paradox
60 The Challenge for the Defender56 Connectivity – The API Shadow
61 Playbook – Defusing the Identity Paradox
67 The Challenge for the Defender63 Scale – The Machine Multiplier
68 Playbook – Defusing the Identity Paradox
Table of Contents
11 The Challenge for the Defender06 Access – The Identity Paradox
12 Playbook – Defusing the Identity Paradox
20 The Challenge for the Defender13 Persistence – The Trusted Tool
21 Playbook – Defusing the Identity Paradox
28 The Challenge for the Defender24 Infrastructure – Edge Decay
29 Playbook – Defusing the Identity Paradox
38 The Challenge for the Defender31 Production – Living Off the Pipeline
39 Playbook – Defusing the Identity Paradox
46 The Challenge for the Defender41 Exfiltration – The Context Gap
47 Playbook | Defusing the Identity Paradox
53 The Challenge for the Defender49 Maintenance | The Priority Gap
54 Playbook – Defusing the Identity Paradox
60 The Challenge for the Defender56 Connectivity – The API Shadow
61 Playbook – Defusing the Identity Paradox
67 The Challenge for the Defender63 Scale – The Machine Multiplier
68 Playbook – Defusing the Identity Paradox