SentinelOne Singularity Platform
Effective Endpoint Protection and Threat Detection
SentinelOne Singularity: Proactive, Reliable EDR with Excellent Real-Time Detection
Simply 1-Click Ransomware Rollback That Restores Files Fast
Intuitive tool with generative AI, quick remediation, and effective support
With SentinelOne Singularity Endpoint, we have achieved more proactive protection thanks to its behavior-based detection and response (EDR) capabilities and artificial intelligence. The platform identifies suspicious activities in real-time, allows for the immediate isolation of compromised devices, and simplifies investigation by providing complete visibility into what is happening on each endpoint.
Storyline Visual Maps Make Threat Investigations Easy
Real-Time Endpoint Visibility with AI-Powered Protection
The user experience is easy to navigate and intuitive, and onboarding new endpoints is seamless. It also integrates well with other security tools to enable a centralized monitoring and streamlined workflow for IR. All of these ensure high performance.
Automated remediation has reduced investigation time and supports effective endpoint protection
What is our primary use case?
SentinelOne Singularity Endpoint's main use case is to monitor endpoint level alerts and server alerts, through which we monitor, detect, and remediate those alerts.
In a quick example of how I use SentinelOne Singularity Endpoint to monitor and remediate an alert, we monitor the alerts and based on the investigation, we take the remediations, often with SentinelOne Singularity Endpoint itself taking the remediation, allowing us to close the case or escalate to the clients.
The unique way I use SentinelOne Singularity Endpoint in my daily work is through the integration of Purple AI, which helps our job to hunt in the environment, allowing basic hunting and query generation, enabling analysts without knowledge in power query to generate queries efficiently, thus reducing investigation time.
What is most valuable?
The best features of SentinelOne Singularity Endpoint include the endpoint level remediation and the indicators referring for an alert, giving an overall picture of the actions that need to be taken by the analyst side.
The remediation part of SentinelOne Singularity Endpoint plays a major role in investigation because if I am unsure whether a file is genuine or malicious, SentinelOne Singularity Endpoint analyzes its behavior and automatically remediates it, facilitating easy removal of legitimate files from quarantine.
The user accessibility in SentinelOne Singularity Endpoint console is a feature I would highlight, as it is convenient for a new analyst, enabling them to understand and migrate to the console within a week.
SentinelOne Singularity Endpoint positively impacts my organization by effectively detecting alerts and endpoint level alerts.
The positive impact of SentinelOne Singularity Endpoint is evident in the remediation part, as it activates remediation as soon as the alert triggers, reducing environmental impact.
What needs improvement?
Recently, I faced an issue with SentinelOne Singularity Endpoint while detecting rogue devices, as there is a gap when scanning initiated from the admin console, recognizing different MAC IDs depending on the connection type, which leads to conflict between managed and unmanaged assets.
Another area needing improvement is the process graph of SentinelOne Singularity Endpoint, which could be made more user-friendly, eye-catching, and offer a better in-depth view.
For how long have I used the solution?
I have worked in cybersecurity for around six years and ten months.
What do I think about the stability of the solution?
SentinelOne Singularity Endpoint is stable.
What do I think about the scalability of the solution?
SentinelOne Singularity Endpoint's scalability is good.
How are customer service and support?
The customer support for SentinelOne Singularity Endpoint is moderate.
Which solution did I use previously and why did I switch?
I have not used a different solution prior to this.
How was the initial setup?
I am not sure about the purchase of SentinelOne Singularity Endpoint because I was in the monitoring team and do not know the specifics from the sales team.
What about the implementation team?
My company has a partner relationship with this vendor beyond being just a customer.
What was our ROI?
I do not have any return on investment to share.
What's my experience with pricing, setup cost, and licensing?
As for my experience with pricing, setup cost, and licensing, I am not knowledgeable since I was not in the sales team.
Which other solutions did I evaluate?
I did not evaluate other options before choosing SentinelOne Singularity Endpoint.
What other advice do I have?
For a long time, SentinelOne Singularity Endpoint is effective at correlating my security solutions, allowing for customization of rules based on requirements.
SentinelOne Complete did not reduce alerts; instead, it increased noise in the environment until fine-tunings were done for customized rules.
As of now, I have not seen a significant freeing up of staff for other projects due to SentinelOne Singularity Endpoint.
We are not using SentinelOne Singularity Endpoint for network and asset visibilities.
Regarding organizational MTTD and MTTR, this is at a moderate level.
My advice for others looking into using SentinelOne Singularity Endpoint is to go for it, as it effectively does the EDR job. I would rate this product an 8 out of 10.
Storyline and Automated Mitigation That Help SOC Analysts Stop Threats Fast
Secondly, The automated mitigation makes ensures a threat does not execute within the oversight of the Analyst
Also, SentinelOne doesn’t just mitigate; it provides useful information about the threat and integrates with VirusTotal.
SentinelOne is fast in detection and mitigation. For our new analyst, the SentinelOne University also helps make learning easier. On pricing, it is well-priced for the value and benefits it provides, but startups and small teams might still find it expensive to use. Even so, the benefit supersedes the cost.
As someone who has worked in an MSSP, having knowledge of SentinelOne is always a plus for my CV.
Behavioral detection has transformed incident response and now speeds up endpoint threat containment
What is our primary use case?
The main purpose of using SentinelOne Singularity Endpoint in my day-to-day work is for monitoring endpoint alerts, investigating any suspicious activity, analyzing behavior, and detecting potential threats. For example, SentinelOne detects suspicious PowerShell execution or potential ransomware behavior, and I review the alert, investigate the process tree, check affected endpoints, and if necessary, isolate endpoints and remediate threats, with our primary use case being protection on the EDR.
In my day-to-day work, I primarily use SentinelOne Singularity Endpoint to investigate suspicious activity and support incident response by reviewing behavior detection, analyzing the process tree, and identifying the root cause of alerts while taking appropriate actions such as isolating compromised endpoints or initiating remediations whenever necessary. Overall, this helps us quickly detect, investigate, and contain endpoint threats and improve our overall security posture.
What is most valuable?
My favorite feature of SentinelOne Singularity Endpoint is the behavioral AI detection because it identifies suspicious activity or malicious PowerShell execution, even when malware has not been seen before, helping us respond to threats much faster.
One example of how behavioral AI detection in SentinelOne Singularity Endpoint has helped us in real scenarios is when we detected PowerShell activity on an endpoint. Instead of relying on known malware signatures, it identified abnormal behavior, allowing us to investigate the process tree, confirm the suspicious activity, isolate the endpoint, and prevent the spread, enabling containment of the incident quickly before it impacted other systems.
The behavioral AI in SentinelOne Singularity Endpoint helped us identify suspicious activity and is a feature I truly appreciate, as it aids in our investigations promptly alongside our SOC team.
SentinelOne Singularity Endpoint has positively impacted my organization by improving endpoint security through faster threat detection, providing better visibility and quicker incident response features including AI, automation, endpoint isolation, and effectively containing threats while reducing the workload for the SOC team.
I do not have exact metrics to share, but I have definitely seen a reduction in the manual effort of our SOC team. For instance, whenever SentinelOne detects suspicious behavior, it automatically correlates related processes and provides a complete process tree, saving analysts' time because we do not have to manually piece together events. Features including automation remediation and endpoint isolation also help contain threats quickly and decrease required manual intervention.
What needs improvement?
I am satisfied with SentinelOne Singularity Endpoint overall, but if it could be improved, it would be in providing more customizable reporting, a richer dashboard, and broader integration with third-party tools. Other than that, I find it effective and reliable with no major suggestions for improvement.
Based on my experience with SentinelOne Singularity Endpoint, I have not encountered any major issues that significantly affect our day-to-day operations. The platform has been stable, and while every product continues to evolve with new features and integrations, I do not have additional improvements to suggest at this time.
For how long have I used the solution?
I have been using SentinelOne Singularity Endpoint for approximately two years, mainly for monitoring endpoint alerts, investigation, detection, and supporting incident response.
What do I think about the stability of the solution?
SentinelOne Singularity Endpoint is stable.
What do I think about the scalability of the solution?
I would rate its scalability a nine.
How are customer service and support?
I would rate the customer support a ten because it helps us greatly and has been very good for us. I would rate my experience with SentinelOne Singularity Endpoint's customer support a ten.
How was the initial setup?
Asset visibility is something we never see, but having asset visibility including expiry notifications provides us valuable visual information. Overall, my experience with pricing, setup cost, and licensing is good, although I am not the right person to comment extensively on pricing.
What was our ROI?
I see a return on investment, and while I cannot share specific metrics, it is evident in the improvements we have experienced.
What other advice do I have?
I advise others looking into using SentinelOne Singularity Endpoint to use this tool because it provides a comprehensive solution. It is very effective and if your organization does not require too many personnel, it is one of the best tools for you. I do not have any additional thoughts about SentinelOne Singularity Endpoint other than that it is a very good tool that provides us with a feasible and wonderful solution. I give this review a rating of nine.
Automated detection has reduced alerts and now speeds up incident response across endpoints
What is our primary use case?
My primary use case for SentinelOne Singularity Endpoint is endpoint protection for employee devices, including real-time threat detection, ransomware protection, malware prevention, and automated response. I use it to monitor Windows and macOS endpoints, investigate security incidents, and help maintain a secure environment with minimal manual interventions.
How has it helped my organization?
While I haven't formally measured specific metrics, I have noticed that incident response has become faster because SentinelOne Singularity Endpoint automatically detects and contains suspicious activity before manual intervention is needed. The automated remediations and centralized visibility have reduced the time I spend investigating alerts, allowing the IT team to resolve security events more efficiently. I have also experienced fewer endpoint-related security issues requiring manual cleanup since deploying the solution.
What is most valuable?
The best features of SentinelOne Singularity Endpoint are its AI-powered behavioral detection, automated threat response, and endpoint isolation capabilities. I also appreciate the centralized management console, which makes it easy to monitor all the endpoints and investigate incidents. The ability to automatically quarantine malicious files and provide a clear attack timeline helps me reduce investigation time and simplifies incident response.
The feature I rely on most from SentinelOne Singularity Endpoint is the automated threat detection and response. It identifies suspicious behavior in real time and can automatically quarantine malicious files or isolate the affected endpoint. This reduces the amount of manual investigation required, speeds up incident response, and allows me to focus on other IT admin tasks instead of constantly monitoring endpoints.
What needs improvement?
While SentinelOne Singularity Endpoint is a strong endpoint security solution, there are areas that could be improved. The management console could be more intuitive for new users, and some advanced features have a learning curve. Reporting and dashboard customization could offer more flexibility, and more detailed documentation and troubleshooting guidance would help admins resolve issues.
For how long have I used the solution?
I have been working in my current field for approximately one year.
What do I think about the stability of the solution?
SentinelOne Singularity Endpoint is stable, quite stable. The agent runs reliably.
How are customer service and support?
The customer support for SentinelOne Singularity Endpoint is really good.
I would rate the customer support for SentinelOne Singularity Endpoint a solid eight. The customer support experience has been good overall.
Which solution did I use previously and why did I switch?
I used Trend Micro previously. I switched to SentinelOne Singularity Endpoint because I wanted stronger behavioral detection, faster automated response, better visibility into endpoint activities, and a more efficient security management experience.
How was the initial setup?
The pricing and licensing model for SentinelOne Singularity Endpoint is straightforward with flexible options based on the number of endpoints and required capabilities. The initial setup cost was reasonable considering the security features provided. Deployment was relatively simple with lightweight agents that could be installed across endpoints and centralized management through the cloud console. Overall, the licensing process and implementation experience were smooth.
What was our ROI?
I have seen a positive return on investment through improved operational efficiency and reduced manual security efforts. SentinelOne Singularity Endpoint has helped save time by automating threat detection, investigation, and remediation processes. For example, a task that previously required manual checks now allows the security team to focus on higher-value projects.
Which other solutions did I evaluate?
Before choosing SentinelOne Singularity Endpoint, I evaluated other endpoint security solutions. I compared options based on threat detection capabilities, AI-driven protection, automated response, ease of management, reporting, and overall security effectiveness. SentinelOne Singularity Endpoint stood out because of its strong behavioral detection, autonomous response capabilities, and centralized management experience.
What other advice do I have?
One example of how I used SentinelOne Singularity Endpoint in a real-world scenario was when it detected and automatically quarantined a malicious executable that had been downloaded through a phishing email. SentinelOne Singularity Endpoint flagged the file based on its behavioral analysis before it could execute, isolated the affected endpoints, and provided a detailed incident timeline. This allowed me to quickly verify the threat, remove the file, and restore the endpoint without any impact on other systems.
SentinelOne Singularity Endpoint provides good visibility and correlation capabilities by collecting endpoint telemetry and security events in a centralized platform. It helps connect suspicious activities across endpoints, identify attack patterns, and provide a clear incident timeline for investigation. Its integration capabilities with other security tools improve overall visibility and streamline incident response workflows.
The centralized console of SentinelOne Singularity Endpoint provides better visibility into endpoint activities, specifies threat investigation and reporting, and reduces the operational efforts required to manage separate security solutions.
SentinelOne Singularity Endpoint has helped me reduce the volume of security alerts by using AI-driven detection, behavioral analysis, and automated prioritization. By filtering out low-risk events and providing more contextual information for investigations, it has reduced alert fatigue and allowed the IT security team to focus on high-priority incidents.
SentinelOne Singularity Endpoint has helped me free up time for my IT security team by reducing the amount of manual monitoring, investigation, and endpoint remediation required. The automated detection and response capabilities allow me to resolve many security events faster and spend more time on proactive security improvements and other IT projects.
SentinelOne Singularity Endpoint has helped reduce my Mean Time to Detect, with analysis on micro-threat detection and centralized visibility across endpoints. While I have not tracked an exact percentage reduction, detection that previously required manual investigation is much faster, allowing the team to respond to potential threats more quickly. If I had to estimate the reduction time, it would be around 40 to 50 percent.
SentinelOne Singularity Endpoint has reduced response time by automatic containment and remediation. The ability to quickly isolate endpoints and investigate incidents from a centralized console helps resolve security events faster and reduce manual efforts. While I have not tracked an exact percentage reduction, the overall response process has become significantly more efficient.
I would recommend evaluating SentinelOne Singularity Endpoint's strong threat detection and automated response capabilities. Before deployment, make sure to define your security requirements, test the agent in your environment, and plan policies carefully to get the best results. The centralized management, behavioral detection, and automation features can significantly improve endpoint protection and reduce the workload on security teams.
Overall, SentinelOne Singularity Endpoint has been a valuable security solution for my organization. The AI-driven detection, automatic response, and centralized management provide strong protection while reducing the time required for monitoring and incident response. SentinelOne Singularity Endpoint is reliable and easy to manage, and while improvements in user experience and reporting customization would make an already strong solution even better. I give this solution an overall rating of 8.