of 70
Current View
Annual
Threat

Report

A Defender’s Guide

from the Frontlines
2SentinelOne Annual Threat Report
The cybersecurity industry currently faces a persistent irony: more is known about

threat actor behaviors, infrastructure, and playbooks than at any point in history,

yet the frequency and impact of attacks continues to rise.

The industry standard for annual threat reporting has long focused on cataloging

intrusion statistics and active threat groups, but reality has shown that simply

documenting what happened last year is not enough to prevent what happens

the following year or beyond.

Despite innovations like the MITRE ATT&CK framework and the widespread

adoption of standardized TTP tracking, the availability of detailed threat

intelligence has done little to slow the rate of successful breaches. The difficulty

lies in translating this high-level knowledge into the specific, grounded insights

needed to manage a local environment. Security teams find themselves with vast

amounts of telemetry, but they often lack the context required to distinguish a

genuine intrusion from a harmless anomaly.

The SentinelOne Annual Threat Report is designed to address that gap. Rather

than just naming actors or counting intrusions, we examine the mechanics of how

adversaries exploit the blind spots in organizations’ defensive logic. The goal is to

identify where technical alerts require a better understanding of normal operations

to be useful. By looking at threats through this lens, we can develop more effective

playbooks and prioritize the actions required to maintain the integrity of our

operations.

The insights that follow are not an exhaustive archive of 2025. Instead, they focus

on the technical and operational indicators that reveal an adversary’s intent. By

refining our ability to isolate malicious activity from the background noise of a

modern network, we can identify more effective ways to defeat adversaries who

rely on complexity and the sheer volume of data to hide their tracks.

Foreword

The Need for Clarity
3SentinelOne Annual Threat Report
The SentinelOne Annual Threat Report highlights a clear shift in adversaries’ strategic

focus. While targeting core systems such as identity, infrastructure and automation is not

new, we observed these tactics executed at industrial scale in 2025.

As traditional perimeters have softened, much of the meaningful activity now takes place

inside the systems organizations rely on every day rather than at the initial point of entry. In

this report, we examine eight strategic phases that show how adversaries are using speed,

automation and deep integration with identity, infrastructure and automation to pressure

many organizations’ current, human-centred approaches.

Access:
In Chapter 1, we show how intrusion has evolved into a mass-marketed
impersonation crisis. Stolen session tokens and automated MFA-bypass kits allow

attackers to maintain the appearance of legitimate activity at scale.

Persistence:
Chapter 2 explores how adversaries are “living off the admin”, hijacking
authorized tools to ensure their presence is indistinguishable from routine IT maintenance.

Infrastructure:
Chapter 3 describes the systematic targeting of unmanaged legacy edge
devices, and how these are exploited to create persistent beachheads that exist outside

the visibility of traditional endpoint security tools.

Production:
Chapter 4 takes us inside the development pipeline and reveals how
adversaries are “shifting left” by integrating malicious logic into the build process itself,

compromising software before it ever reaches production.

Exfiltration:
In Chapter 5, we detail how data theft is increasingly executed via authorized
machine identities.

Maintenance:
Chapter 6 shows how adversaries are weaponizing vulnerabilities at scale
in systems that are technically patchable but remain unaddressed due to critical or legacy

status.

Connectivity:
Chapter 7 delves into the unmonitored communication layer across SaaS,
APIs and integration engines, and shows how threat actors abuse forgotten endpoints and

background services to move data and commands between systems.

Scale:
In Chapter 8, we examine how automation, polymorphism and AI-assisted tooling
are being used to increase the speed, scale and resilience of campaigns, compressing

response windows and eroding the effectiveness of purely manual detection and

investigation.

Throughout this report, we focus not only on how attackers are successful, but crucially on

how defenders can meet the challenges that we’ve observed over the last 12 months. Each

section is supplemented with a defender’s playbook that will be of value to anyone working

in Enterprise Security, as well as specific recommendations for SentinelOne customers.

Executive Summary
4SentinelOne Annual Threat Report
Table of Contents

11
The Challenge for the Defender06 Access – The Identity Paradox
12
Playbook – Defusing the Identity Paradox
20
The Challenge for the Defender13 Persistence – The Trusted Tool
21
Playbook – Defusing the Identity Paradox
28
The Challenge for the Defender24 Infrastructure – Edge Decay
29
Playbook – Defusing the Identity Paradox
38
The Challenge for the Defender31 Production – Living Off the Pipeline
39
Playbook – Defusing the Identity Paradox
46
The Challenge for the Defender41 Exfiltration – The Context Gap
47
Playbook | Defusing the Identity Paradox
53
The Challenge for the Defender49 Maintenance | The Priority Gap
54
Playbook – Defusing the Identity Paradox
60
The Challenge for the Defender56 Connectivity – The API Shadow
61
Playbook – Defusing the Identity Paradox
67
The Challenge for the Defender63 Scale – The Machine Multiplier
68
Playbook – Defusing the Identity Paradox
File name:

-

File size:

-

Title:

-

Author:

-

Subject:

-

Keywords:

-

Creation Date:

-

Modification Date:

-

Creator:

-

PDF Producer:

-

PDF Version:

-

Page Count:

-

Page Size:

-

Fast Web View:

-

Preparing document for printing…
0%
Next