Secure endpoints, servers and cloud workloads with SentinelOne Singularity, an AI-powered platform for autonomous prevention, detection, and response. SentinelOne sets the standard for how AI and automation transform security operations, stopping novel and evolving threats at machine speed, scaling under-resourced teams, and simplifying data to outpace adversaries. This pay-as-you-go (PAYGO) listing provides a unified platform defense against the most sophisticated attacks.
SentinelOne Singularity Endpoint is a market-leading security solution that reduces complexity, improves security posture, and seamlessly integrates powerful AI to protect endpoints, servers, and cloud workloads. This PAYGO model ensures you only pay for the endpoints you protect, providing the elasticity needed for growing businesses and dynamic teams.
Powered by Autonomous Security Intelligence, the Singularity Platform gives defenders a decisive operating advantage, leveraging an advanced AI-native architecture, agentic human-level reasoning, and autonomous response capabilities to give customers the advantage.
Contain Threats in Real Time: Instantaneous defense that achieves a state of constant protection against ransomware, zero-day exploits, and fileless malware.
Eliminate Blind Spots to Reduce Risk: Seamless integration of identity, cloud, and third-party telemetry with runtime activity to expose hidden lateral movement without the limitations of traditional dashboards.
Ensure Control and Resilience Across Critical, Complex Environments: AI-driven security tailored for SaaS, on-premises, hybrid, and air-gapped environments.
Reduce MTTR for Improved Efficiency: Built-in automation that slashes investigation times from hours to seconds by providing actionable intelligence.
Key AWS Service Integrations
SentinelOne Singularity Endpoint integrates seamlessly with the AWS ecosystem to centralize management and automate responses:
AWS Security Hub: Automatically exports endpoint threat findings into a centralized dashboard for a unified view of your security posture.
Amazon CloudWatch: Streams detailed security telemetry and logs for advanced monitoring and long-term operational analysis.
AWS Systems Manager (SSM): Simplifies the deployment and management of the SentinelOne agent across your managed instances at scale.
Amazon GuardDuty: Complements network-level threat detection by providing deep, agent-based visibility into host-level behavior.
Amazon S3: Facilitates the secure storage of forensic data and historical threat telemetry for compliance and deep-dive investigations.
Achieve Operational Efficiency
Singularity Endpoint is built to minimize the manual effort required by security teams. Because the AI resides directly on the agent, it can prevent and remediate threats even when a device is offline. With the 1-Click Rollback feature, administrators can instantly revert the unauthorized changes made by ransomware, restoring files to their original state without the need for manual reimaging or data recovery from backups.
Highlights
5-Year Gartner Magic Quadrant Leader for Endpoint Protection Platforms
2026 SC Awards "Best Endpoint Security" for three consecutive years, outperforming both legacy and modern alternatives.
Autonomous AI Protection & Rollback: Instantly detect and block ransomware, fileless malware, and zero day threats using on agent behavioral AI that can revert infected Windows devices to a clean state with a single click.
Access real-time vendor security and compliance information through their Trust Center powered by Drata or Vanta. Review certifications and security standards before purchase.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
You pay monthly based on what you protect. Each dimension bills per unit, so your cost scales with the number of units you run. One dimension covers workstations, priced per workstation. Three dimensions cover cloud workloads: one per container host, one per server, and one per pod or task for serverless container workloads. Pick the dimensions that match your environment and add units as you grow. Every dimension includes Purple AI and Standard Support at the same monthly per-unit structure.
Top-of-mind questions for buyers
What counts as one unit for each cloud workload dimension?
A container host is one machine running containers. A server is one operating system instance. A pod or task is one serverless container unit on Fargate. Each running instance counts separately. The workstation dimension counts one unit per protected workstation device.
What drives my bill when I run a mixed environment of servers, containers, and workstations?
Each dimension bills independently and appears on the same invoice. Your total adds the per-workstation charge, per-container-host charge, per-server charge, and per-pod-or-task charge. The dimension with the most units usually drives your cost. You only pay for the environment types you actually run.
What is included with every dimension besides the core protection?
Each dimension includes Purple AI and Standard Support at the same monthly per-unit rate. Purple AI is an AI security assistant that helps investigate threats. The platform combines threat prevention, detection, and automated response in one agent across the units you protect.
sentinelone.com
Helpful?
Vendor refund policy
All fees are non-cancellable and non-refundable except as required by law.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
SentinelOne Singularity AI SIEM revolutionizes your security operations on AWS. Eliminate the skyrocketing ingestion costs and data overloads of legacy SIEMs by utilizing Observo AI to filter data volumes. This provides a deeper, richer dataset, enabling smarter and more accurate detections, accelerated generative AI investigations, and precise responses with Singularity Hyperautomation. AI SIEM is fundamentally shifting the role of security analyst from manual, repetitive tasks to strategic defense. Empower your team to accelerate investigations and mitigate critical risks with a fast, scalable, and intelligent SIEM built for the Autonomous SOC.
Unlock enterprise-wide security for your AWS environment with SentinelOne Singularity Platform. This AI-powered solution provides real-time threat detection and automated response across your infrastructure, ensuring continuous protection at infinite scale. By autonomously securing endpoints, cloud workloads, and identity, SentinelOne delivers total visibility while eliminating security silos. Integrate seamlessly with AWS and leverage our unified data lake and Purple AI to accelerate investigations and gain deeper insights. Secure your AWS cloud and focus on innovation with the speed and efficiency of AI.
Boost your IT Security with the SentinelOne Complete AWS Bundel. Tailored EDR solutions, expert support, and training by MyDigitals. Secure your digital assets now!
SentinelOne Wayfinder TDR delivers expert-led readiness, hunting, incident response, and 24/7 MDR—uniting them into a proactive, scalable defense built for modern threats. Combining Google Threat Intelligence, agentic AI technology, and elite human expertise gives your team a turnkey detection and response program to move faster, see farther, act smarter against modern threats, and get your team back to running your business.
Block attacks and secure your entire cloud with SentinelOne Singularity Cloud Security, an AI-powered CNAPP providing deep visibility and robust, real-time protection to defend your AWS environment from initial access to mission target. It unifies proactive exposure management, and real-time protection to safeguard your AWS infrastructure, workloads (VMs, containers), and data with AI-powered detection and automated response. Try Cloud Security for free!
Fast, Feature-Rich Endpoint Protection with Deep Visibility and Vulnerability Scanning
Reviewed on Aug 29, 2026
Review provided by G2
What do you like best about the product?
End Point detection and response to the alerts, additional features like deep visibility search and Vulnerability scanning on end points. Fast response.
What do you dislike about the product?
At present, I’m not seeing any cons with SentinelOne Singularity Endpoint Protection. It may be more expensive than some other EDR solutions, but in my experience it delivers better results and offers more features.
What problems is the product solving and how is that benefiting you?
SentinelOne Singularity has been benefiting me by improving alert detection on endpoints and providing fast resolutions based on those alerts. The interactive AI helps address most alerts without the need for an analyst to intervene.
Muralidharan k.
Powerful EDR and Automated Threat Response with Centralized Visibility
Reviewed on Aug 24, 2026
Review provided by G2
What do you like best about the product?
What I like best about SentinelOne Singularity Endpoint is its strong endpoint detection and response capabilities, automated threat response, and centralized visibility. It makes it easier to identify suspicious activity, investigate incidents, and respond quickly while reducing the amount of manual effort required from security teams
What do you dislike about the product?
The main drawback is that some advanced features can take time to learn and configure properly. The platform is feature-rich, so administrators may need additional training and tuning to get the best results for their specific environment.
What problems is the product solving and how is that benefiting you?
SentinelOne Singularity Endpoint helps us improve endpoint security by detecting and responding to malware, suspicious activity, and other endpoint threats. Its automated response and centralized visibility reduce manual investigation time, improve incident response, and help the security team identify and contain threats more efficiently.
Computer & Network Security
SentinelOne: Balanced Endpoint Security with Strong Visibility and Automation
Reviewed on Aug 09, 2026
Review provided by G2
What do you like best about the product?
Overall, SentinelOne provides a good balance of security, visibility, automation, and ease of management, making it a valuable solution for protecting enterprise endpoints.
What do you dislike about the product?
Some advanced configurations and investigations can also feel a little complex, especially for teams that are new to endpoint security platforms. Reporting and customization could be more intuitive as well.
Overall, these are relatively minor concerns, but simplifying the user experience and making advanced features easier to configure would make the platform even better.
What problems is the product solving and how is that benefiting you?
The automated detection and response capabilities are especially beneficial because they reduce manual effort and help minimize the time required to contain and remediate threats. The centralized management also makes it easier to monitor endpoint security, apply policies, and maintain consistent protection across the environment.
Overall, it helps improve our endpoint security posture, reduces operational effort, and provides greater visibility and confidence in detecting and responding to security threats.
Victor M.
Autonomous Threat Mitigation and Storyline Visibility That Save Hours
Reviewed on Aug 07, 2026
Review provided by G2
What do you like best about the product?
What's provided the most value for me is the autonomous response. Running a mixed Windows/macOS fleet with a chunk of BYOD devices, I can't babysit every alert, and the on-agent behavioural AI catches and auto-mitigates threats without waiting on a cloud round-trip or an analyst clicking "contain". The Storyline attack visualisation is the feature I lean on daily; instead of stitching together process trees myself, I get the full execution chain mapped out, which turns what used to be a 30-minute triage into a few minutes of confirming and rolling back. AI / Intelligence: The static and behavioural AI models running locally mean detection holds up even when a device is offline, which matters for laptops that aren't always on the VPN. Fewer noisy false positives than the signature-based tooling I've used before. UI / UX: The console is clean, and the Deep Visibility query interface lets me hunt across the fleet quickly. Onboarding new admins doesn't require weeks of ramp-up. Performance: Agent footprint is light — I haven't had the user complaints about system slowdown that plagued our previous endpoint tool, which is a real win when you're deploying to BYOD machines you don't fully control. Integrations: Ranger for network visibility (surfacing unmanaged devices) plus the API and SIEM connectors have fit into our stack without much friction. Adding Ranger meant I stopped needing a separate discovery tool to find rogue endpoints. Support / Onboarding: Deployment was straightforward, and vendor support has been responsive on the escalations that mattered. Pricing / ROI: It is not the cheapest option, but the ROI shows up in reduced analyst hours; the one-click rollback on ransomware alone has justified the spend, and consolidating discovery (Ranger) into the same platform cut a line item elsewhere. Unexpected benefit: The rollback capability doubled as a safety net for my organisation during a legitimate-but-misclassified software push; being able to reverse endpoint changes cleanly saved a reimaging headache.
What do you dislike about the product?
The biggest pain point is policy and exclusion management at scale. Building exclusions is more manual than it should be; there's no clean way to test an exclusion's blast radius before it goes live, so tuning for a noisy line-of-business app on part of the fleet involves more trial-and-error than I'd like. A "preview affected endpoints" step or a staging mode for policy changes would cut real risk out of the process. Deep Visibility is powerful, but the query experience has a learning curve. The syntax isn't intuitive for newer analysts, and saved-query sharing and templating could be better. When I'm onboarding someone, threat hunting is the piece that takes longest to hand off, which partly defeats the "autonomous" pitch for smaller teams. Reporting is the other weak spot. The canned reports rarely match what I need for regulatory or management audiences, so I still end up exporting to build the view myself. More flexible, customisable reporting, or a proper report builder, would save hours each reporting cycle. On macOS, agent updates and OS-version compatibility have occasionally lagged behind Windows, which matters on a mixed fleet where I can't always hold back an OS update on a BYOD device. Tighter macOS parity would help. Console performance can also drag when pulling large time-range queries across the full fleet, and the alert volume before tuning is high enough that early days feel noisier than expected.
What problems is the product solving and how is that benefiting you?
The core problem it solves for us is endpoint visibility and response across a mixed Windows/macOS fleet that includes BYOD devices we don't fully control. Before, detection leaned heavily on signature-based tooling that missed behavioural threats and generated noise, and our response was manual; an analyst had to triage, decide, and contain, which meant slow reaction to anything that landed off-hours or while a laptop was off the VPN. Now the on-agent AI detects and auto-mitigates threats locally, so containment doesn't wait on an analyst or a cloud round trip. That's collapsed our mean time to respond to the incidents that matter, and the biggest single win is the one-click rollback on ransomware and malicious changes; reversing endpoint state cleanly has taken reimaging off the table for cases that used to mean hours of rebuild per machine. The second problem was unmanaged devices. We struggled to reliably find rogue or unenrolled endpoints on the network, but Ranger surfaces them without a separate discovery tool, which closed a real gap in our asset visibility and cut a line item from the stack. Third is investigation time. Storyline maps the full attack chain automatically, so triage that used to mean manually reconstructing process trees now takes a few minutes of confirming and acting – meaningfully less analyst time per alert, which for a lean team is the difference between keeping up and falling behind. Net benefit: faster response, less manual rebuild work, tighter asset visibility, and analyst hours redirected from triage to higher-value work.
James R.
Effective Endpoint Protection and Threat Detection
Reviewed on Jul 28, 2026
Review provided by G2
What do you like best about the product?
What I like best about SentinelOne Singularity Endpoint is its behavioral threat detection and automated response. It detects suspicious activity quickly, isolates infected endpoints when needed, and provides a clear investigation timeline that makes it easier to understand and respond to security incidents. The management console is also easy to navigate, which simplifies day to day security operations.
What do you dislike about the product?
I think the sentinelone singularity endpoint platform is a great security solution, however fine tuning policies and creating exclusions for trusted applications can take some time, especially for larger environment. This can be improved on.
What problems is the product solving and how is that benefiting you?
SentinelOne Singularity Endpoint helps us detect and stop malware, ransomware, and other endpoint threats before they spread. It provides real time visibility into endpoint activity, speeds up incident investigation, and automates response actions such as isolating compromised devices.