Analyst1 adds centralized credential management, Vault support and SentinelOne integration
Analyst1 released version 2.16.0 with centralized credential management, HashiCorp Vault support and a new SentinelOne EDR integration. The update also adds Microsoft Foundry BYO AI support and several platform and security improvements for existing customers.
Why it matters: - Analyst1 2.16.0 gives security teams a single place to manage credentials across sources and integrations, which should make access control and rotation easier. - The release expands how Analyst1 connects threat intelligence to operational tools, including endpoint security, secrets management and AI models. - The update also adds new detection and enrichment paths through SentinelOne and Microsoft Foundry.
What happened: - Analyst1 announced general availability of version 2.16.0 on September 25, 2026. - The release includes centralized credential management, HashiCorp Vault support, a new SentinelOne integration and Microsoft Foundry support as a BYO AI provider. - Existing customers can access full release notes and documentation at docs.analyst1.com.
The details: - Administrators can now manage credentials for all sources and integrations from one location. - Existing source and integration credentials migrate automatically to Analyst1 credential storage during upgrade. - HashiCorp Vault users can authenticate sources and integrations through Vault instead of storing integration credentials in Analyst1. - Analyst1 retrieves current credentials from Vault when an integration authenticates and stores only the credentials needed to reach Vault itself. - The platform can be configured with one or more credential management providers, including multiple providers of the same type. - Vault storage objects can be mapped to Analyst1 credential fields using path notation. - Current credentials are retrieved from Vault each time an integration authenticates. - SentinelOne Endpoint Security is now available as an endpoint detection and response integration. - Analyst1 can export domain, IPv4, IPv6, file hash and URL indicators to SentinelOne IOC Management at the Site level. - The SentinelOne export supports configurable risk score, severity and description. - Analyst1 can export SHA1 and SHA256 file hashes to a Site-level SentinelOne Blocklist scoped to macOS, Windows or Linux. - Indicators can stay active in SentinelOne for as long as they meet Analyst1 criteria and are removed automatically when they stop. - Analyst1 can poll SentinelOne Threats and Alerts on a configurable schedule and look-back window. - The polling records hit statistics for indicators Analyst1 already tracks. - Microsoft Foundry is now supported as a Bring Your Own AI provider, letting teams use models from their own Foundry environment for Analyst1 AI capabilities. - Censys Reputation Labels, including MALICIOUS, SUSPICIOUS, BENIGN, INACTIVE and HONEYPOT, are now available as Vendor Attributes. - Analysts can filter indicators created from Censys collections by label. - The release includes updates for MITRE ATT&CK v19.2 and ATLAS v2026.08. - Security updates include Chromium and several third-party libraries to address multiple CVEs. - Stability fixes cover Recorded Future API requests, custom evidence source retrieval and indicator extraction from uploaded email messages.
Between the lines: - Analyst1 is building around a clearer operating model for security teams: keep secrets in their existing vaults, push intelligence into downstream tools and pull results back into the platform. - The SentinelOne integration extends Analyst1’s endpoint reach and gives analysts another feedback loop between threat intel and observed activity. - The Microsoft Foundry support suggests Analyst1 wants to let customers bring their own AI infrastructure instead of forcing a single model provider.
What's next: - Existing customers can review upgrade details for credential migration and MITRE ATT&CK mappings in the release documentation. - Customers with questions can contact their account manager or support@analyst1.com. - Analyst1’s next phase appears focused on broader integrations, tighter credential governance and more automated intelligence-to-action workflows.
The bottom line: - Version 2.16.0 is a platform release centered on control: one place for credentials, more external systems to connect, and more ways to move intelligence into action.
Disclaimer: This article was produced by AGP Wire with the assistance of artificial intelligence based on original source content and has been refined to improve clarity, structure, and readability. This content is provided on an “as is” basis. While care has been taken in its preparation, it may contain inaccuracies or omissions, and readers should consult the original source and independently verify key information where appropriate. This content is for informational purposes only and does not constitute legal, financial, investment, or other professional advice.
Sign up for:
The Government Daily Review
The daily local news briefing you can trust. Every day. Subscribe now.
Check Your Email!
We sent a one-time activation link to: .
Confirm it's you by clicking the email link.
If the email is not in your inbox, check spam or try again.
Welcome back!
is already signed up. Check your inbox for updates.