Overview
Detect and Block an Attack in Under 1 Minute
Detect and Block an Attack in Under 1 Minute
Cloud Native Security Overview
Block attacks and secure your entire cloud environment with SentinelOne Singularity Cloud Security, a comprehensive, AI-powered Cloud-Native Application Protection Platform (CNAPP). Our platform provides deep visibility and robust security from build time to runtime, with all security findings natively integrated into the Singularity Data Lake for investigation and custom detection. Safeguard your AWS cloud infrastructure and workloads against modern threats with our unified, real-time protection.
Our Comprehensive AI-Powered CNAPP is comprised of three key products designed to secure your entire cloud stack:
- Our agentless Cloud Native Security provides proactive exposure management capabilities that prevent attackers from gaining a foothold in your AWS environment with:
Offensive Security Engine: Reduce your cloud attack surface by simulating external exploits to produce Verified Exploit Paths to prioritize the expsoures that are truly reachable by an outside attacker.
Cloud Security Posture Management (CSPM): Continuously monitor and manage the security of your AWS configurations to prevent public exposure and ensure compliance.
Secrets Scanning: Identify more than 750 types of secrets across public and private repositories.
Cloud Infrastructure Entitlements Management (CIEM): Detect and manage excessive or unused permissions to mitigate the risk of privilege escalation.
Infrastructure as Code (IaC) Scanning: Scan and secure your IaC templates and images, including secrets and vulnerabilities, before deployment.
Cloud Detection and Response: Leverage our AI SIEM and forensics capabilities for advanced threat hunting and rapid incident response across your cloud.
- Cloud Workload Security is a real-time, AI-powered Cloud Workload Protection Platform (CWPP) for servers, virtual machines (VMs), and containers across public and private clouds. Built for the modern cloud, it helps you:
Detect and Stop Threats: Automatically stop runtime threats like ransomware, zero-days, and fileless attacks in real time without performance impact.
Accelerate Threat Hunting: Gather forensic data and telemetry for deep, comprehensive threat hunting and analysis.
Ensure Stability: Experience unmatched stability and performance without kernel panics, thanks to our lightweight, patented agent.
- Cloud Data Security provides AI-powered malware detection for cloud object storage, including Amazon S3 and file storage services like Amazon FSxN and NetApp. This product ensures that your data is always protected:
Real-Time Scanning: Detect malware, including zero-days, in milliseconds with scanning done directly in your own cloud environment.
Automated Action: Take immediate, automated action against threats, including quarantine and encryption.
AI Model Protection: Safeguard your AI models and pipelines deployed on services like Amazon SageMaker and Amazon Bedrock with our AI Security Posture Management (AISPM).
Additional SentinelOne integrations with AWS Services:
AWS CloudTrail: SentinelOne ingests AWS CloudTrial activity logs to identify and remediate cloud misconfigurations. By analyzing API and resource changes in real time, SentinelOne uncovers suspicious behaviors like unauthorized IAM change that create security gaps.
AWS Security Hub: Consolidates SentinelOne's deep security findings and context into AWS Security Hub for a single pane of glass and automated, high-fidelity response.
AWS Config: Uses AWS Config data to provide continuous compliance monitoring, track configuration changes over time, and ensure your cloud assets remain secure and auditable.
Amazon GuardDuty: Enriches Amazon GuardDuty's network and account-level threat detections with SentinelOne's detailed workload telemetry for more accurate correlation and faster threat hunting.
Get started
Verify exploitable risk and stop runtime threats with the most comprehensive and integrated CNAPP solution today. Simply click on the Request private offer button on this page to begin your procurement process.
Highlights
- Unified Visibility: Powered by Singularity Data Lake and Purple AI, customers can have a complete view of their security issues across endpoint, identity, and cloud
- Attacker's Mindset: Prioritize cloud health and remediation with evidence-based Verified Exploit Paths™ from code to multi-cloud environments.
- AI-Powered Threat Detection and Protection: Secure cloud and container workloads with real-time protection and forensic visibility.
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Trust Center
Buyer guide

Financing for AWS Marketplace purchases
Pricing
Free trial
Dimension | Description | Cost/12 months |
|---|---|---|
Pricing available upon request. | Contact SentinelOne for custom pricing. | $20,000.00 |
Vendor refund policy
No refunds are available for this solution.
Custom pricing options
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
Software as a Service (SaaS)
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
Resources
Support
Vendor support
Support is available for this solution. For custom pricing contact sales@sentinelone.com .
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Similar products
Customer reviews
Unified endpoint protection has simplified real-time threat blocking and policy-driven control
What is our primary use case?
I use SentinelOne Singularity Cloud Security to collect endpoint data from the company, such as servers, computers, and mobile phones. The solution functions similarly to Cortex XDR and provides antivirus protection that safeguards devices from viruses and malware.
What is most valuable?
SentinelOne Singularity Cloud Security offers real-time protection, anti-tamper capabilities, and a centralized platform with a good user interface. The UI is intuitive enough that even people without cybersecurity knowledge can understand how to use it.
The policy feature is valuable because it tells the product what to do with new files, such as whether to scan them or leave them untouched. One single tab covers all the features, so I do not have to open another tab or window to turn settings on or off. The simplicity of the product itself makes it better than competitors.
The real-time protection is quite valuable. If any attack occurs or if an employee tries to download something malicious, SentinelOne Singularity Cloud Security directly blocks it for us without requiring manual intervention. For example, if an employee accidentally clicks on a link that tries to download something malicious, SentinelOne Singularity Cloud Security directly blocks it and quarantines it, notifying us on the console about the employee's name and what they attempted to download. We can then check the file or ask the user, and if they did not download it intentionally, we can close the case. If it was critical for them, we can release it directly from the console.
The unified platform experience of SentinelOne Singularity Cloud Security is good. The dashboard, settings menu, policy menu, user menu, and endpoint menu are all well organized. I can say it is one of the best user interfaces I have used, and it is very user-friendly.
What needs improvement?
Integration could be improved because not all solutions can be integrated with SentinelOne Singularity Cloud Security or vice versa. I was in a project where the company wanted to integrate SentinelOne Singularity Cloud Security with another solution product. When I checked, it turned out that integration was possible but could not be directly connected. It had to go through middleware before reaching that product, which is more complicated.
SentinelOne Singularity Cloud Security is a newer product compared to Palo Alto Cortex , so perhaps some product solutions cannot be integrated yet. SentinelOne Singularity Cloud Security does not have as large a portfolio of integrations as Cortex XDR .
SentinelOne Singularity Cloud Security is more sensitive compared to other solutions. While all solutions perform well when it comes to real-time protection, SentinelOne Singularity Cloud Security tends to generate more false positive events due to its high sensitivity. For example, some companies use older types of WinRAR, which may get blocked by SentinelOne Singularity Cloud Security directly.
I would appreciate it if they introduced a filtering or archive feature where we could add applications that should not be marked as threats.
Many features in SentinelOne Singularity Cloud Security have additional costs, which limits our exploration of the full product.
It would be more convenient if SentinelOne Singularity Cloud Security could be integrated with other solution tools such as firewalls or SIEM , as it would be more comfortable for us to avoid checking the console every single time. In our SOC, we have many tabs open on our screen, and it is confusing; we might miss some alerts. With better integrations, we could go in one tab and have everything provided for us.
For how long have I used the solution?
I have used SentinelOne Singularity Cloud Security for almost one year.
What do I think about the stability of the solution?
SentinelOne Singularity Cloud Security is very stable, and there are no errors, even compared to Cortex where there were errors on the agent. We have not experienced any issues with SentinelOne Singularity Cloud Security. The platform is more convenient, and for the server, they choose the nearest one from Indonesia, so when we go to the console or when the devices try to connect, there are no errors. Even during power outages, the system remains stable.
What do I think about the scalability of the solution?
From the licensing perspective, it is very easy to scale. When a company wants to add more licenses, they simply call the provider or a consultant, and they can add it within one or two months from the time they request it. They will then receive the license instantly.
SentinelOne Singularity Cloud Security is more resource-friendly, so it does not consume a lot of RAM or storage. This is excellent because even companies with older devices can run SentinelOne Singularity Cloud Security. In Indonesia, especially in financial-related companies, there are regulations stating that some servers or programs can only run on older servers. SentinelOne Singularity Cloud Security can directly create a custom build for that specific server.
In the case of custom builds, the company itself has to contact SentinelOne Singularity Cloud Security, as this is not publicly available.
How are customer service and support?
I have experience with the technical support and customer service of SentinelOne Singularity Cloud Security.
During implementation, when we encounter any issues, we call support. The implementation process has only involved minor issues, so we have not needed extensive support. We simply email them, and they respond directly with documentation if available. Otherwise, they provide comments to help resolve the issue.
What other advice do I have?
After implementation, the process is fast. SentinelOne Singularity Cloud Security provides cloud hosting itself. If we choose the cloud option, they will set it up, and we simply wait until we have our domain and account. When we go to that domain and log in, our console is already there.
Regarding the deployment model, I recommend the cloud option for SentinelOne Singularity Cloud Security.
As far as I know, SentinelOne Singularity Cloud Security has one license for the cloud itself and another license for the devices. If the company size is one thousand people, they can buy one thousand or one thousand one hundred for a backup. If they need more, they can add more licenses, and the company will buy it and update it directly to the console. SentinelOne Singularity Cloud Security is much cheaper than Palo Alto Cortex.
SentinelOne Singularity Cloud Security is simpler than Cortex XDR . The process is similar to Cortex, but the difference is that Cortex integrates the package file with the license or token. With SentinelOne Singularity Cloud Security, we have to manually insert the token or copy it from the console to a notepad. When we try to install, we click the installer and open the notepad to paste the token.
AI-driven protection has improved endpoint security and currently saves significant analyst time
What is our primary use case?
Our main use case for SentinelOne Singularity Cloud Security in our company is using the endpoint for the machine.
What is most valuable?
In my opinion, the best features of SentinelOne Singularity Cloud Security are the integration with AI capability and more powerful performance; this is the future.
I find these features the best for my organization because the feature protects the machine.
SentinelOne Singularity Cloud Security has impacted my company positively as it provides good protection for the company and for the services.
What needs improvement?
In my opinion, SentinelOne Singularity Cloud Security can be improved by acknowledging that it has a good future with good capability for integrating with AI capability; it increased the high speed and performance for taking action.
For how long have I used the solution?
I have been using SentinelOne Singularity Cloud Security for one year.
What do I think about the stability of the solution?
SentinelOne Singularity Cloud Security has been very stable so far.
What do I think about the scalability of the solution?
My impression of SentinelOne Singularity Cloud Security's scalability is that it has high scalability and grows well.
How are customer service and support?
I would evaluate SentinelOne Singularity Cloud Security's customer service or technical support by giving them an eight.
I give them an eight because it is not quite exceeded to reach a ten.
For them to get a ten, I still do not have any notes to give them to improve their service.
Which solution did I use previously and why did I switch?
Before choosing SentinelOne Singularity Cloud Security, we evaluated other solutions and we are using Microsoft Defender.
The main differences between SentinelOne Singularity Cloud Security and Microsoft Defender, both pros and cons, are that SentinelOne Singularity Cloud Security has AI capability and is faster for performance and detection.
How was the initial setup?
My experience with the pricing, setup costs, and licensing of SentinelOne Singularity Cloud Security is that the pricing is good; it is not expensive, it is medium.
What about the implementation team?
I did not purchase SentinelOne Singularity Cloud Security through the AWS Marketplace .
What was our ROI?
I have not seen a return on my investment so far.
What's my experience with pricing, setup cost, and licensing?
My experience with the pricing, setup costs, and licensing of SentinelOne Singularity Cloud Security is that the pricing is good; it is not expensive, it is medium.
Which other solutions did I evaluate?
Before choosing SentinelOne Singularity Cloud Security, we evaluated other solutions and we are using Microsoft Defender.
The main differences between SentinelOne Singularity Cloud Security and Microsoft Defender, both pros and cons, are that SentinelOne Singularity Cloud Security has AI capability and is faster for performance and detection.
What other advice do I have?
There has been no impact on reducing our MTTR until now.
I do use Purple AI for threat investigations.
Its impact on understanding the root causes of security incidents is good; it understood the root cause for security.
SentinelOne Singularity Cloud Security's runtime protection compares well to other solutions I have used in terms of adaptability to new and unknown threats, as SentinelOne Singularity Cloud Security is a stable solution.
I am not using the Offensive Security Engine feature.
The role of SentinelOne Singularity Cloud Security's Secret Scanning feature in tightening my company's cloud hygiene is that it is a good one; it is very heavy and not too much load from the endpoint.
We measure the time savings achieved through SentinelOne Singularity Cloud Security as a good achievement.
I save time for my security operations by using SentinelOne Singularity Cloud Security.
I have saved approximately one year of time. I gave this review an overall rating of eight.
Centralized security monitoring has improved visibility and unified cloud threat detection
What is our primary use case?
I use it myself, as I have not recommended it or implemented it to my customers.
We usually use it as an EDR, and the main function for SentinelOne Singularity Cloud Security is the logs, which is the main function for us.
We did not use it as an investigation tool, but SentinelOne Singularity Cloud Security is useful for investigations and to collect the logs, making it easy. I can say it is an easy dashboard for the logs.
Currently, 600 people are using it in my company.
We need three administrators to manage it.
I did not use the Purple AI for threat investigation.
I did not use the Offensive Security Engine, OSE feature.
I did not use any AI SPM, Security Posture Management for AI workloads.
I did not check for the advanced CIEM capabilities in SentinelOne Singularity Cloud Security.
I do not integrate it with third-party solutions.
How has it helped my organization?
SentinelOne Singularity Cloud Security has reduced confusion and silos within my organization.
What is most valuable?
The features I find most valuable in SentinelOne Singularity Cloud Security are the XDR and the integrations with other vendors.
From using it, I get more visibility for what happens on the end-user side.
The role of SentinelOne Singularity Cloud Security's secret scanning feature is important as it is used for normal scans based on the behavior of the user.
It is significant for my team to have built-in integrations that unify various aspects of cloud security, as it is easy and gives us more visibility.
The detection for the agent is great, which allows us to identify unexpected process behavior.
Measurement of time savings in terms of SecOps operations with SentinelOne Singularity Cloud Security is based on cloud management.
What needs improvement?
I do not see room for improvement in SentinelOne Singularity Cloud Security.
In the future, I would like to see the identity feature with two-factor authentication.
It would be good if they could add AI agents to support in analysis and management.
For how long have I used the solution?
I have been working with it for three and a half years.
What do I think about the scalability of the solution?
SentinelOne Singularity Cloud Security is stable and scalable.
How are customer service and support?
I would rate the technical support by SentinelOne as good, as when I create a ticket, it takes the normal process and I get the answer before the SLA, so there is no delay.
I would give their technical support nine out of ten.
Which solution did I use previously and why did I switch?
Before choosing SentinelOne Singularity Cloud Security, I evaluated CrowdStrike.
Before SentinelOne Singularity Cloud Security, I did not use anything similar as an EDR solution.
What was our ROI?
For the ROI, we are paying as a subscription, and we see the benefits from the security tools; it is useful for us.
What other advice do I have?
I might plan to increase usage in the future.
I find the price reasonable.
The unified platform experience is good for us, and the GUI for the application is easy and not complex.
SentinelOne Singularity Cloud Security's runtime protection operates 24/7.
It helps me deal with new and unknown threats through the behaviors.
There is nothing in play regarding SentinelOne Singularity Cloud Security integration with other security tools affecting my team's workflow.
In the future, I would like to see the identity feature with two-factor authentication.
I do not know about the product's popularity in my region, and I do not think they should promote it more.
I would give this product an overall rating of 8 out of 10.
Cloud posture has improved and security team gains instant visibility into misconfigurations
What is our primary use case?
I am currently using the cloud security posture management capabilities. We are managing multiple cloud platforms, including AWS , Azure , and GCP. I need a consolidated security posture management across all of my cloud platforms.
We are managing multiple cloud workload profiles. For example, someone has mistakenly configured 0.0.0.0 access, and some misconfiguration has occurred. I want to get that update immediately, otherwise people may use that flaw and attack us. This misconfiguration detection will help us in eliminating missed configurations or configurations that our people have mistakenly implemented. That is my major use case. Additionally, I will get the consolidated asset inventory. These three purposes are what I am using Cloud Security Posture Management for.
What is most valuable?
The offensive security particular solution works by going through logs and seeing the logs on everything. It will provide complete visibility related to false positive and true positive information. That provides more visibility on the technical front. For example, if you are creating a use case on a SIM and that particular use case is not matching your end-to-end information related to our environment, it will not throw the alert. If you implement the offensive security, it will straight away point out that particular issue in that incident because the alert was triggered by that event.
Secret scanning is our automated scanning. We do not want to do the manual effort, and we do not want to create any automation during production. The moment you do this, the secret scanning will work because it is runtime scanning.
What needs improvement?
Mean time to detection and mean time to respond is a critical aspect. Most of the incidents sometimes will not be detected if you are not configured properly. The MTTR is very important. That is the reason we have mentioned that to eliminate the misconfiguration part, we need Cloud Security Posture Management. Because if someone has created an account opening 0.0.0.0, and then someone has opened the 'all all' access in the cloud instance itself, then anybody can come and penetrate my cloud workload and destroy it. In that scenario, I want to get a proper, proactive approach. The moment someone has made a mistake, I have to immediately respond. Then only can I protect. To eliminate the manual mistake and misconfiguration, this particular tool does the immediate alert so that we can prevent our cloud workloads based on the priority and based on the alert triggers. We can eliminate the alerts and incidents.
There is one concern related to SentinelOne Singularity Cloud Security platform. They claim it as an AI-based integration that will provide runtime protection. The moment it comes to the runtime protection, if someone is using an existing tool, this particular tool does not scan because we need to achieve it. For example, I have a CrowdStrike EDR in my console, on my VM, I have it installed. This particular runtime also has to be protected. Most of the runtime protection has to be implemented in a proper manner. For that reason, we are doing the scanning on an immediate basis. The first time, this particular runtime protection is not working. For example, I am trying that for the first time, and it is not getting the protection part. It is not working. If I try that particular trial again, only after that is it getting one more runtime protection. It is detection, and then it is getting the protection also.
For how long have I used the solution?
What do I think about the stability of the solution?
What do I think about the scalability of the solution?
How are customer service and support?
Which solution did I use previously and why did I switch?
What was our ROI?
What other advice do I have?
Centralized threat insight has improved frontline detection but support still needs faster, clearer help
What is our primary use case?
As a cyber security analyst, my main use case for SentinelOne Singularity Cloud Security is front line support. I use SentinelOne Singularity Cloud Security in my daily work for detection through our endpoints for any ingress on our clients.
What is most valuable?
The best features SentinelOne Singularity Cloud Security offers include the data lake where I can ingest data from all other applications that I use into one central location, making managing alerts much easier and more responsive.
SentinelOne Singularity Cloud Security has positively impacted our organization as it allows us to be more proactive on the alerts that we get and any threats that we receive. The data lake feature helps me day-to-day by ingesting all the information from Darktrace and Defender into one single point of reference, which makes it easier to locate information.
Being able to get information from one central source helps to streamline processes and security in my daily workflow.
What needs improvement?
I find the platform somewhat clunky at times, and SentinelOne Singularity Cloud Security does not always give me accurate data, which could also be due to fine tuning on our end.
SentinelOne Singularity Cloud Security needs to be more reliable for the information it is pulling, as I am not always confident that the data coming through is accurate and immediate. We have had a few issues with the configuration setup at our location, which will be resolved; however, some of the configurations have taken a long time to resolve, and the back and forth with support has been frustrating.
Regarding needed improvements, support can be more proactive, faster in responsiveness, and come back with workable solutions rather than just steering me back to online knowledge bases all the time.
For how long have I used the solution?
I have been using SentinelOne Singularity Cloud Security for about 18 months.
What do I think about the stability of the solution?
SentinelOne Singularity Cloud Security appears to be stable at the moment.
What do I think about the scalability of the solution?
I am not really sure how the scalability of SentinelOne Singularity Cloud Security plays out in our current position.
How are customer service and support?
The customer support for SentinelOne Singularity Cloud Security is about a 5 out of 10, and I think they need to be more interactive with their clients rather than just steering clients back to knowledge bases.
SentinelOne Singularity Cloud Security's unified platform experience has helped streamline our security operations, as it has definitely allowed us to get more accurate information faster.
What other advice do I have?
For others looking into using SentinelOne Singularity Cloud Security, I would definitely recommend it as worth a look for your current environment to see whether it would have a place, and also compare it against other products out there.
My only other thought about SentinelOne Singularity Cloud Security is that support needs to be enhanced with their clients, requiring more interaction with their customer base rather than online pushing clients to knowledge bases all the time.
I gave this review a rating of 6 out of 10.