SentinelOne to acquire identity threat detection and response company Attivo Networks for $616.5M, its second acquisition; Attivo raised $60.1M in funding
Context & Ripple Effects
SentinelOne had built its endpoint-security business through successive financings before adding data capabilities in its acquisition of logging startup Scalyr. Attivo is its second reported acquisition, extending that acquisition-led buildout into identity threat detection and response.
The deal matters because it joins endpoint protection, security-data handling and identity-focused detection under one vendor rather than leaving each capability as a separate product category.
First-order effects
- Attivo Networks becomes part of SentinelOne in a $616.5 million transaction, giving SentinelOne an identity threat detection and response capability alongside its endpoint-security offering.
- Attivo’s investors exit through a sale after the company raised $60.1 million in funding.
Second-order effects
- Security buyers evaluating SentinelOne can assess a broader endpoint, logging and identity-oriented stack, following its earlier Scalyr purchase.
- Endpoint-security rivals face a more bundled SentinelOne offering, raising the value of their own identity and security-data partnerships or product coverage.
Third-order effects
- If SentinelOne continues to use acquisitions to fill adjacent security functions, the market shifts toward broader detection platforms assembled around endpoint vendors rather than stand-alone point tools.
- The acquisition also illustrates how identity detection is becoming a strategic adjacent layer for vendors whose original foothold was device-level security.
The trend: Cybersecurity vendors are broadening endpoint platforms through acquisitions that add adjacent detection and response capabilities, particularly around identity and security data.