SentinelOne Singularity Endpoint Complete for Security Hub Extended logo

    SentinelOne Singularity Endpoint Complete for Security Hub Extended

    Secure endpoints, servers and cloud workloads with SentinelOne Singularity, an AI-powered platform for autonomous prevention, detection, and response. SentinelOne sets the standard for how AI and automation transform security operations, stopping novel and evolving threats at machine speed, scaling under-resourced teams, and simplifying data to outpace adversaries. This pay-as-you-go (PAYGO) listing provides a unified platform defense against the most sophisticated attacks.

    Ratings and reviews

    4.7
    212 ratings
    0 AWS reviews
    |
    212 external reviews
    External reviews are from G2 .

    Filters

    Review type

    AWS Marketplace reviews
    External reviews
    Reviews (212)
    Suresh K.

    Fast, Feature-Rich Endpoint Protection with Deep Visibility and Vulnerability Scanning

    Reviewed on Aug 29, 2026
    Review provided by G2
    What do you like best about the product?
    End Point detection and response to the alerts, additional features like deep visibility search and Vulnerability scanning on end points. Fast response.
    What do you dislike about the product?
    At present, I’m not seeing any cons with SentinelOne Singularity Endpoint Protection. It may be more expensive than some other EDR solutions, but in my experience it delivers better results and offers more features.
    What problems is the product solving and how is that benefiting you?
    SentinelOne Singularity has been benefiting me by improving alert detection on endpoints and providing fast resolutions based on those alerts. The interactive AI helps address most alerts without the need for an analyst to intervene.
    Muralidharan k.

    Powerful EDR and Automated Threat Response with Centralized Visibility

    Reviewed on Aug 24, 2026
    Review provided by G2
    What do you like best about the product?
    What I like best about SentinelOne Singularity Endpoint is its strong endpoint detection and response capabilities, automated threat response, and centralized visibility. It makes it easier to identify suspicious activity, investigate incidents, and respond quickly while reducing the amount of manual effort required from security teams
    What do you dislike about the product?
    The main drawback is that some advanced features can take time to learn and configure properly. The platform is feature-rich, so administrators may need additional training and tuning to get the best results for their specific environment.
    What problems is the product solving and how is that benefiting you?
    SentinelOne Singularity Endpoint helps us improve endpoint security by detecting and responding to malware, suspicious activity, and other endpoint threats. Its automated response and centralized visibility reduce manual investigation time, improve incident response, and help the security team identify and contain threats more efficiently.
    Computer & Network Security

    SentinelOne: Balanced Endpoint Security with Strong Visibility and Automation

    Reviewed on Aug 09, 2026
    Review provided by G2
    What do you like best about the product?
    Overall, SentinelOne provides a good balance of security, visibility, automation, and ease of management, making it a valuable solution for protecting enterprise endpoints.
    What do you dislike about the product?
    Some advanced configurations and investigations can also feel a little complex, especially for teams that are new to endpoint security platforms. Reporting and customization could be more intuitive as well.

    Overall, these are relatively minor concerns, but simplifying the user experience and making advanced features easier to configure would make the platform even better.
    What problems is the product solving and how is that benefiting you?
    The automated detection and response capabilities are especially beneficial because they reduce manual effort and help minimize the time required to contain and remediate threats. The centralized management also makes it easier to monitor endpoint security, apply policies, and maintain consistent protection across the environment.

    Overall, it helps improve our endpoint security posture, reduces operational effort, and provides greater visibility and confidence in detecting and responding to security threats.
    Victor M.

    Autonomous Threat Mitigation and Storyline Visibility That Save Hours

    Reviewed on Aug 07, 2026
    Review provided by G2
    What do you like best about the product?
    What's provided the most value for me is the autonomous response. Running a mixed Windows/macOS fleet with a chunk of BYOD devices, I can't babysit every alert, and the on-agent behavioural AI catches and auto-mitigates threats without waiting on a cloud round-trip or an analyst clicking "contain". The Storyline attack visualisation is the feature I lean on daily; instead of stitching together process trees myself, I get the full execution chain mapped out, which turns what used to be a 30-minute triage into a few minutes of confirming and rolling back. AI / Intelligence: The static and behavioural AI models running locally mean detection holds up even when a device is offline, which matters for laptops that aren't always on the VPN. Fewer noisy false positives than the signature-based tooling I've used before. UI / UX: The console is clean, and the Deep Visibility query interface lets me hunt across the fleet quickly. Onboarding new admins doesn't require weeks of ramp-up. Performance: Agent footprint is light — I haven't had the user complaints about system slowdown that plagued our previous endpoint tool, which is a real win when you're deploying to BYOD machines you don't fully control. Integrations: Ranger for network visibility (surfacing unmanaged devices) plus the API and SIEM connectors have fit into our stack without much friction. Adding Ranger meant I stopped needing a separate discovery tool to find rogue endpoints. Support / Onboarding: Deployment was straightforward, and vendor support has been responsive on the escalations that mattered. Pricing / ROI: It is not the cheapest option, but the ROI shows up in reduced analyst hours; the one-click rollback on ransomware alone has justified the spend, and consolidating discovery (Ranger) into the same platform cut a line item elsewhere. Unexpected benefit: The rollback capability doubled as a safety net for my organisation during a legitimate-but-misclassified software push; being able to reverse endpoint changes cleanly saved a reimaging headache.
    What do you dislike about the product?
    The biggest pain point is policy and exclusion management at scale. Building exclusions is more manual than it should be; there's no clean way to test an exclusion's blast radius before it goes live, so tuning for a noisy line-of-business app on part of the fleet involves more trial-and-error than I'd like. A "preview affected endpoints" step or a staging mode for policy changes would cut real risk out of the process. Deep Visibility is powerful, but the query experience has a learning curve. The syntax isn't intuitive for newer analysts, and saved-query sharing and templating could be better. When I'm onboarding someone, threat hunting is the piece that takes longest to hand off, which partly defeats the "autonomous" pitch for smaller teams. Reporting is the other weak spot. The canned reports rarely match what I need for regulatory or management audiences, so I still end up exporting to build the view myself. More flexible, customisable reporting, or a proper report builder, would save hours each reporting cycle. On macOS, agent updates and OS-version compatibility have occasionally lagged behind Windows, which matters on a mixed fleet where I can't always hold back an OS update on a BYOD device. Tighter macOS parity would help. Console performance can also drag when pulling large time-range queries across the full fleet, and the alert volume before tuning is high enough that early days feel noisier than expected.
    What problems is the product solving and how is that benefiting you?
    The core problem it solves for us is endpoint visibility and response across a mixed Windows/macOS fleet that includes BYOD devices we don't fully control. Before, detection leaned heavily on signature-based tooling that missed behavioural threats and generated noise, and our response was manual; an analyst had to triage, decide, and contain, which meant slow reaction to anything that landed off-hours or while a laptop was off the VPN. Now the on-agent AI detects and auto-mitigates threats locally, so containment doesn't wait on an analyst or a cloud round trip. That's collapsed our mean time to respond to the incidents that matter, and the biggest single win is the one-click rollback on ransomware and malicious changes; reversing endpoint state cleanly has taken reimaging off the table for cases that used to mean hours of rebuild per machine. The second problem was unmanaged devices. We struggled to reliably find rogue or unenrolled endpoints on the network, but Ranger surfaces them without a separate discovery tool, which closed a real gap in our asset visibility and cut a line item from the stack. Third is investigation time. Storyline maps the full attack chain automatically, so triage that used to mean manually reconstructing process trees now takes a few minutes of confirming and acting – meaningfully less analyst time per alert, which for a lean team is the difference between keeping up and falling behind. Net benefit: faster response, less manual rebuild work, tighter asset visibility, and analyst hours redirected from triage to higher-value work.
    James R.

    Effective Endpoint Protection and Threat Detection

    Reviewed on Jul 28, 2026
    Review provided by G2
    What do you like best about the product?
    What I like best about SentinelOne Singularity Endpoint is its behavioral threat detection and automated response. It detects suspicious activity quickly, isolates infected endpoints when needed, and provides a clear investigation timeline that makes it easier to understand and respond to security incidents. The management console is also easy to navigate, which simplifies day to day security operations.
    What do you dislike about the product?
    I think the sentinelone singularity endpoint platform is a great security solution, however fine tuning policies and creating exclusions for trusted applications can take some time, especially for larger environment. This can be improved on.
    What problems is the product solving and how is that benefiting you?
    SentinelOne Singularity Endpoint helps us detect and stop malware, ransomware, and other endpoint threats before they spread. It provides real time visibility into endpoint activity, speeds up incident investigation, and automates response actions such as isolating compromised devices.
    Elizabeth E.

    SentinelOne Singularity: Proactive, Reliable EDR with Excellent Real-Time Detection

    Reviewed on Jul 27, 2026
    Review provided by G2
    What do you like best about the product?
    SentinelOne Singularity Endpoint is one of the most effective and efficient EDR solutions I've used. It's highly proactive, with excellent real-time threat detection and automated response capabilities. The platform is reliable, easy to use, and provides great visibility into endpoint security.
    What do you dislike about the product?
    One area for improvement is the blocklist functionality. Currently, it only supports blocking file hashes, whereas I would like to see support for a broader range of indicators of compromise (IOCs), such as IP addresses, domain names, and URLs.
    What problems is the product solving and how is that benefiting you?
    As a SOC Analyst, SentinelOne Singularity Endpoint enables me to detect and respond to endpoint threats quickly. Its real-time visibility, behavioral detection, and automated response capabilities reduce investigation time, improve incident response, and strengthen our overall endpoint security.
    Victor Y.

    Simply 1-Click Ransomware Rollback That Restores Files Fast

    Reviewed on Jul 24, 2026
    Review provided by G2
    What do you like best about the product?
    Provides 1-click ransomware rollback capabilities, reverting unauthorized changes and restoring encrypted files from local shadow copies in the event of a ransomware attack.
    What do you dislike about the product?
    High Memory Usage: The agent can occasionally consume significant CPU and RAM resources, especially during full system scans or database operations, which can cause my laptop to slow down.
    What problems is the product solving and how is that benefiting you?
    Real-time autonomous mitigation. The local behavioral AI engine can kill processes, isolate infected machines, and automatically roll back changes instantly, without needing cloud connectivity or human approval.
    Francisco F.

    Intuitive tool with generative AI, quick remediation, and effective support

    Reviewed on Jul 23, 2026
    Review provided by G2
    What do you like best about the product?
    Very intuitive tool, easy to use, with built-in Generative AI that greatly helps in solving cases. Remediation is simple and fast. In terms of resources, it requires little and is quickly deployed through other tools like NinjaOne RRM. The price is reasonable for the advanced capabilities the solution offers, and if you have any questions, the support team responds promptly and appropriately.
    What do you dislike about the product?
    Centralized console, easy to use and with many automations that make your day-to-day more efficient. Thanks to the incorporated AI, the tool helps you close cases under the law of least effort and gives you time for other investigations.
    What problems is the product solving and how is that benefiting you?
    Before implementing SentinelOne, we had limited visibility into the actual security status of the endpoints and relied heavily on signature-based detection and manual intervention by the IT team. This made it difficult to detect ransomware early, advanced malware, lateral movements, and other threats that could compromise user devices.

    With SentinelOne Singularity Endpoint, we have achieved more proactive protection thanks to its behavior-based detection and response (EDR) capabilities and artificial intelligence. The platform identifies suspicious activities in real-time, allows for the immediate isolation of compromised devices, and simplifies investigation by providing complete visibility into what is happening on each endpoint.
    Nancy U.

    Storyline Visual Maps Make Threat Investigations Easy

    Reviewed on Jul 23, 2026
    Review provided by G2
    What do you like best about the product?
    Most helpful for me would be its storyline feature. It threads together process trees, network requests, registry and file changes into one visual map.
    What do you dislike about the product?
    The SentinelOne query language used to threat hunt within Deep Visibility is a pain to use. It takes quite a toll to learn and use it efficiently and effectively. Else, you'll just keep getting 'No results found'.
    What problems is the product solving and how is that benefiting you?
    It's solving the problem of alert fatigue and disjointed logs in security operations. DV and the storyline function help with faster MTTR as it reduces the time spent on aimless log searches and threat hunts.
    Adaku O.

    Real-Time Endpoint Visibility with AI-Powered Protection

    Reviewed on Jul 23, 2026
    Review provided by G2
    What do you like best about the product?
    What I find most helpful about SentinelOne Singularity Endpoint is its AI-driven endpoint protection, which leverages machine learning and behavioral analysis to detect and respond to threats in real time. It provides excellent visibility across endpoints, making it easy to investigate incidents and understand what's happening throughout the environment.

    The user experience is easy to navigate and intuitive, and onboarding new endpoints is seamless. It also integrates well with other security tools to enable a centralized monitoring and streamlined workflow for IR. All of these ensure high performance.
    What do you dislike about the product?
    One downside I’ve noticed is the occasional false positives. They create a lot of noise in the environment, which ends up wasting time. Even when the same alert has been manually mitigated and flagged, it still repeats.
    What problems is the product solving and how is that benefiting you?
    There are many benefits, such as holistic visibility into endpoints through real-time monitoring, which can help with containing threats. I especially like the rollback feature because it can restore endpoints to a safe state when needed.