SentinelOne is a cybersecurity company that characterized Iran-linked cyber activity as a multi-pronged threat comprising various clusters with distinct missions, targeting, and tradecraft. These range from data collection and destruction to social engineering, cloud compromise, and opportunistic targeting of operational technology assets.