SentinelOne to acquire identity threat detection and response company Attivo Networks for $616.5M, its second acquisition; Attivo raised $60.1M in funding
'For Attivo, this acquisition is not an exit. Joining forces with SentinelOne is just the opposite: an opportunity to continue …
Context & Ripple Effects
SentinelOne has been assembling a data-and-detection stack beyond its AI-based endpoint core: after raising a $120M Series D and then a $200M Series E at a $1B+ valuation with Insight Partners, it bought logging startup Scalyr for $155M in early 2021. The $616.5M Attivo Networks deal is its second acquisition, and by far its largest.
Attivo built identity threat detection and response — detecting attackers once they steal credentials and move laterally — on just $60.1M of total funding, so the price represents roughly a ten-times return on capital raised. Notably, Attivo's framing is continuity rather than exit: joining SentinelOne is pitched as an opportunity to keep building inside a larger platform.
First-order effects
- SentinelOne's platform now spans endpoint, log data via the Scalyr acquisition, and identity-based attack detection, letting it sell customers coverage across the credential-theft stage of intrusions that endpoint tools alone miss.
- Attivo's investors convert $60.1M of cumulative funding into a $616.5M outcome, while Attivo's team continues under SentinelOne rather than winding down — the seller explicitly rejects calling this an exit.
Second-order effects
- Endpoint-security rivals now face pressure to answer with their own identity-threat capabilities or partnerships, because SentinelOne can bundle identity detection into the same console and contract where they currently leave a gap.
- The premium multiple over Attivo's capital raised sets a market signal that mature identity-detection startups command strategic prices well above their funding history, encouraging other ITDR vendors to entertain acquirers.
Third-order effects
- If the pattern holds, standalone security categories like identity threat detection get absorbed into consolidated detection-and-response platforms, shrinking the market for independent point products and shifting competition to whoever owns the broadest telemetry.
- Deals priced at many multiples of capital raised reinforce the asset-level view of security M&A: buyers pay for capability and installed base, not for the fundraising history, which reshapes how late-stage security startups are valued.
The trend: Security platforms are consolidating adjacent detection domains — endpoint, logging, now identity — through acquisition, turning point-product vendors into building blocks of extended detection stacks.