SentinelOne Singularity Platform logo

    SentinelOne Singularity Platform

    Unlock enterprise-wide security for your AWS environment with SentinelOne Singularity Platform. This AI-powered solution provides real-time threat detection and automated response across your infrastructure, ensuring continuous protection at infinite scale. By autonomously securing endpoints, cloud workloads, and identity, SentinelOne delivers total visibility while eliminating security silos. Integrate seamlessly with AWS and leverage our unified data lake and Purple AI to accelerate investigations and gain deeper insights. Secure your AWS cloud and focus on innovation with the speed and efficiency of AI.

    Ratings and reviews

    4.6
    391 ratings
    43 AWS reviews
    |
    348 external reviews
    External reviews are from G2  and PeerSpot .

    Filters

    Review type

    AWS Marketplace reviews
    External reviews
    Reviews (391)
    Abu Zafar

    Automated detection and response have transformed how my team manages endpoint threats

    Reviewed on Jul 15, 2026
    Review from a verified AWS customer

    What is our primary use case?

    My main use cases for SentinelOne Singularity Endpoint include endpoint protection, threat protection, threat detection, and automated response. I primarily rely on it to monitor endpoints for suspicious activity, identify and stop malware, ransomware, and other advanced threats, and provide visibility into security incidents across environments.

    I utilize SentinelOne Singularity Endpoint to support automated remediation of any kind of threats, investigation support, and improving overall security posture by reducing response times and helping my security team quickly understand and contain potential threats.

    What is most valuable?

    The best features of SentinelOne Singularity Endpoint include AI-powered threat detection and prevention, autonomous response and remediation, Storyline incident tracking, ransomware protection and rollback, and endpoint detection and response capabilities. It also has a single lightweight agent, protection across different environments, deep visibility, and investigation tools, and it offers identity and attack path context with related Singularity capabilities.

    The AI-powered detection and autonomous response capabilities have helped my team by improving our ability to identify and respond to threats quickly instead of relying only on manual investigation or signature-based detection. SentinelOne Singularity Endpoint helps to detect suspicious behaviors and emerging threats in real time while reducing the workload on my security team by automatically containing threats, stopping malicious processes, and helping prevent further impacts.

    SentinelOne Singularity Endpoint has positively impacted our organization by strengthening our overall endpoint security and improving our ability to detect, investigate, and respond to threats. Its AI-driven detection and automated response capability have reduced the time needed to identify and contain security incidents, improved visibility across endpoints, streamlined security operations, and reduced the manual efforts required for threat investigation and remediation. By automating key response actions and providing better incident context, SentinelOne Singularity Endpoint has helped my team improve efficiency, minimize risk, and maintain a stronger security posture, which has resulted in reduced team operations time.

    What needs improvement?

    SentinelOne Singularity Endpoint provides strong protection and automation capabilities, but there are a few areas where it could be improved, such as enhancing the user experience with more intuitive dashboards and simplified workflows. These improvements would make it easier for administrators to quickly access important insights and manage threats. Additional customization options for alerts, reporting, and automation policies would also be valuable, allowing organizations to better tailor the platform to their specific security needs. Improvements in integrations with a wide range of third-party security tools would also be beneficial.

    For how long have I used the solution?

    I have been using SentinelOne Singularity Endpoint for the last two years.

    What do I think about the stability of the solution?

    SentinelOne Singularity Endpoint is very stable because it is used for threat detection, threat prevention, and automated remediation for any kind of security operations.

    What do I think about the scalability of the solution?

    SentinelOne Singularity Endpoint has handled our organization's growth and expansion effectively.

    How are customer service and support?

    Customer support was very good, and I would give customer support a rating of eight out of ten.

    Which solution did I use previously and why did I switch?

    I did not previously use a different solution, and we did not use any solution before SentinelOne Singularity Endpoint.

    What was our ROI?

    I have seen a positive return on investment with SentinelOne Singularity Endpoint. The main value has come from reducing manual security operations, improving incident response times, and consolidating multiple security capabilities into a single platform, with relevant improvements including faster threat detection and response.

    What's my experience with pricing, setup cost, and licensing?

    My experience with SentinelOne Singularity Endpoint's pricing, setup cost, and licensing has been generally positive. The licensing model is straightforward, and the setup cost is low.

    Which other solutions did I evaluate?

    I did not evaluate other products before choosing SentinelOne Singularity Endpoint.

    What other advice do I have?

    For organizations considering SentinelOne Singularity Endpoint, I recommend evaluating it based on your specific security requirements and environments. I would give this product an overall rating of ten out of ten.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Nekkala Nagendra

    Unified security has reduced endpoint risk and streamlines protection across all devices

    Reviewed on Jul 13, 2026
    Review provided by PeerSpot

    What is our primary use case?

    My main purpose is to have protection for all my endpoint devices. I would like a unified solution which can reduce my operational cost and ensure my risk is less compared to other things. The primary use case is that I want to have my entire server and endpoint security solutions covered. I want to consolidate to ensure my maintenance and operational cost are streamlined in a better way.

    What is most valuable?

    This solution has really very good capabilities across the endpoint devices. It has real capabilities to ensure my endpoint device coverage across my organization. It can correlate my various threats so that it gives me clear detailed information across my entire enterprise landscape.

    It is enabling my security solutions from my servers, Linux, Windows security, all at various touchpoints. It gives my all my laptop devices and everything the entire range of security purpose.

    It prevents my vulnerable devices without any confirmation and without being compromised. The network and asset visibility has real visibility because it can see various types of devices connecting to my network.

    What needs improvement?

    It has reduced the MTTR significantly, at least 40 to 50 percent.

    When coming into the picture with AI, I think it has to enhance the time to respond and can increase in that way. Time to respond is a delay that should be improved. Documentation also should be in a better way. As a customer, the price is also high for me.

    It is not easy for engineers or for any new engineers, highly trained people would be better. For L2 engineers, it is not that easy for them.

    For how long have I used the solution?

    I have already shared on LinkedIn the solutions what I am offering. I am using the endpoint security and all the protection platforms. I am using SentinelOne Singularity Endpoint Go and SentinelOne Singularity Endpoint Cloud also and also SentinelOne Singularity Endpoint Identity. It is almost two years that I have been a customer.

    What do I think about the stability of the solution?

    Stability is very good.

    What do I think about the scalability of the solution?

    It is highly scalable.

    What was our ROI?

    In terms of my solution, the return on investment is better. I am able to get my staff reduced in that way. If the cost also can be decreased, then I will be happy.

    Which other solutions did I evaluate?

    I have already shared on LinkedIn the solutions what I am offering. I have shifted to another company which is called Wysely Digital. Microsoft Defender is another alternative that exists as an EDR.

    What other advice do I have?

    I am currently using SentinelOne Singularity Endpoint Go, SentinelOne Singularity Endpoint Cloud, and SentinelOne Singularity Endpoint Identity. It has eliminated all false positives that are generated. This has helped my staff to focus on other purposes. The cost price point at one hundred dollars or higher is a consideration. I would rate this solution an eight out of ten. It is on-premises deployment. For this review, I would give this solution an overall rating of eight.

    Ansh B.

    The Endpoint Security Platform That Actually Responds, Not Just Alerts.

    Reviewed on Jul 13, 2026
    Review provided by G2
    What do you like best about the product?
    What I like best about SentinelOne Singularity Endpoint is the autonomous threat detection and response capability it doesn't just alert you to a threat, it actively kills malicious processes and roll back changes in real time without requiring manual intervention or cloud connectivity. This alone sets it apart from traditional AV and even some other next-gen solutions.

    The storyline feature is a particular standout. It automatically maps the entire attack chain process trees, file events, network connections, registry modifications into a single correlated timeline. what would otherwise take an analyst 30-40 minutes to piece together manually is presented instantly, which significantly accelerates investigation and response.

    Policy management across large, distributed device fleets is also well thought out. Grouping devices, pushing configuration, and managing exclusions is intuitive from the console without needing to touch individual endpoints.

    For an IT or security administrator handling endpoint protection at scale, having deep visibility, automated remediation, and a clean centralized console in a single lightweight agent is a genuine operational advantage that's hard to go back from.
    What do you dislike about the product?
    While SentinelOne Singularity Endpoint is a powerful platform, there are a few pain points worth mentioning from an administrator's perspective. The initial learning curve around policy configuration can be steep getting detection versus protection policies, exclusions, and Device Control rules dialed in correctly takes time and some trial and error, especially in environments with diverse device types and software stacks.

    The console, while generally clean, can sometimes feel slow when pulling up large threat or activity logs across a big device fleet. filtering and searching through historical telemetry data isn't always as intuitive as it could be and exporting detailed reports require a bit of navigation.

    Agent removal from endpoints is another area that needs improvement If a license has expired or a device is being decommissioned, removing the agent without the passphrase adds unnecessary friction to what should be a straightforward offboarding process.

    Pricing and licensing tiers can also be confusing when you're managing multiple client environments as certain features like Ranger or the full storyline depth are gated behind higher tiers, which isn't always immediately clear during onboarding.

    Overall, these are manageable pain points, but they are friction areas that admins will encounter in day-to-day operations.
    What problems is the product solving and how is that benefiting you?
    SentinelOne Singularity Endpoint solves one of the most critical challenges in endpoint security the gap between threat detection and actual response. in traditional setups, an alert fires, an analyst investigates, and by the time a decision is made, the damage is already done. SentinelOne closes that gap by autonomously detecting, containing, and rolling back threats in real, which is a massive operational benefit especially when managing a large number of endpoints across multiple environments.

    From a day-to-day administration standpoint, it significantly reduces alert fatigue. The storyline feature correlates events into a single attack narrative, so instead of sifting through hundreds of individual log entries, I get a clear, contextualized picture of what happened, how it started, and what it touched. This directly benefits incident response time and overall, SOC efficiency.

    Device Control and Firewall Control features also solve real policy enforcement problems being able to control USB access, block specific applications, and manage network traffic from a single console without deploying separate tools is a huge operational advantage.

    For environments where compliance and audit readiness matter, having detailed telemetry, threat history, and policy enforcement logs all in one place simplifies reporting considerably. Overall, SentinelOne has reduced our dependency on multiple point solutions and brought endpoint visibility and control under one roof, which benefits both the security posture and the operational workload of the team.
    Sagar-Patel

    Deep visibility has transformed threat hunting and now cuts incident response from hours to seconds

    Reviewed on Jul 11, 2026
    Review provided by PeerSpot

    What is our primary use case?

    My main use case for SentinelOne Singularity Endpoint involves EDR, deep visibility, and threat hunting.

    For EDR or threat hunting in my day-to-day work, I use SentinelOne Singularity Endpoint primarily for incident management and for daily threat hunting, where I run queries, XDR queries, EDR, and power queries for hunting.

    In addition to my main use cases, I also use SentinelOne Singularity Endpoint for application management, inventory management, and identity management for all users, along with vulnerability recommendation and vulnerability development management.

    What is most valuable?

    SentinelOne Singularity Endpoint offers excellent features that include threat visibility, deep visibility, and threat hunting.

    What stands out to me with SentinelOne Singularity Endpoint's threat visibility and threat hunting features is that deep visibility gives us a 360-degree angle view of cloud, endpoint, identity, and network data to assess any possible threat hunting or risky activities, which is a good feature.

    SentinelOne Singularity Endpoint has positively impacted my organization with its Purple AI feature.

    Purple AI has made a positive impact by saving time because it provides a summary glimpse of the incident, allowing me to get an overview of what happened, and then I can check the particular identity or asset, which helps in checking everything in the incident or particular device or organization.

    SentinelOne Singularity Endpoint has helped me see the connections between different security events or alerts, and it integrates easily.

    Singularity Endpoint has completed my security solutions; during the six pillars of zero trust architecture, I can implement all pillars—identity, application, endpoints, infrastructure, network, and cloud—through the Singularity platform.

    Singularity Complete has helped reduce false positive alerts; by creating star rules or alert rules for valid files allowed in the network, we are getting fewer incidents from the beginning.

    Singularity Endpoint has freed up my staff for other projects and tasks, saving us one to two days per week to focus on other things.

    It has reduced the mean time to respond, MTTR, by shrinking the incident response and forensic science analysis cycles from hours to seconds.

    What needs improvement?

    SentinelOne Singularity Endpoint can be improved by implementing more XDR in the network connections and connectivity.

    Regarding needed improvements, the device connectivity management feature is very good and is working effortlessly and connecting well, though if we could improve some Purple AI features such as providing direct results to queries, that would be a valuable enhancement.

    For how long have I used the solution?

    I have been using SentinelOne Singularity Endpoint for two years.

    What do I think about the stability of the solution?

    SentinelOne Singularity Endpoint is stable.

    What do I think about the scalability of the solution?

    Its scalability is impressive as it delivers horizontal scalability to a single agent and supports SaaS services, on-premises, and hybrid environments.

    How are customer service and support?

    Customer support is good, and the service is good.

    Which solution did I use previously and why did I switch?

    We previously used Microsoft Defender XDR, but we have SentinelOne Singularity Endpoint as a backup EDR solution.

    How was the initial setup?

    When we previously used Microsoft Defender XDR, the setup has been stable.

    What was our ROI?

    I do not have any metrics regarding return on investment, as I am part of the group and did not implement it.

    What's my experience with pricing, setup cost, and licensing?

    I am part of the group but do not have hands-on experience with the pricing, setup cost, and licensing.

    Which other solutions did I evaluate?

    Before choosing SentinelOne Singularity Endpoint, we did not evaluate any other options; one customer provided feedback indicating they use SentinelOne Singularity Endpoint, so we decided to go with it.

    What other advice do I have?

    My company acts as a service provider, MSSP, in our relationship with this vendor. I would rate this review a 9 overall.

    AdityaJain

    Endpoint protection has improved threat blocking and simplified centralized device control

    Reviewed on Jul 09, 2026
    Review provided by PeerSpot

    What is our primary use case?

    We are using SentinelOne Singularity Endpoint as an EDR currently in our organization, and we are mapping the hash values into it so that the endpoint detection and response system will block all the corresponding prefix regarding that hash value. We also use it for USB blocking, such as blocking USB on particular devices or on the whole network.

    What is most valuable?

    From the administrative perspective, I appreciate the best features of SentinelOne Singularity Endpoint because we can block each and every traffic based on the hash value. We can manually check for this, and we have the AI feature to scan the vulnerability type and migrate that framework vulnerabilities. Additionally, we have the whole privilege to manually control the device, such as the endpoint, so we can close the running application or uninstall the applications that are malicious.

    SentinelOne Singularity Endpoint is very good in terms of time-saving, as no other task is getting hampered by installing it. Initially, when we install it on a particular endpoint, it scans all over the machine, and the user may feel that the machine is a bit slow. However, after the scanning is completed, the machine comes to the top factory stage, so the user has not faced any issues with the software.

    The key benefits I have seen from using SentinelOne Singularity Endpoint include that agent installation is pretty easy. We just need to run the EXE file and paste the key. After deployment, it works by scanning everything in the background, creating logs in SentinelOne and also in the client console app if it fails at anything. We have not encountered any malicious attacks, such as ransomware, and I feel that SentinelOne is working very well by patching it in the background.

    What needs improvement?

    I would like to see improvements in SentinelOne Singularity Endpoint where if the user agent is deployed on a particular machine, the user only sees the logs, and the rest are deleted, while the quarantine part is done by the console itself. Users should be given permissions to block or use the application as needed.

    In terms of features, I would like to see that if I need to deploy software in my environment with an endpoint EDR installed, I could use SentinelOne for that. It would be perfect for the software part, such as deploying an EXE file remotely to all employees so that it gets installed on every endpoint.

    For how long have I used the solution?

    I have been working with SentinelOne Singularity Endpoint for about two and a half years or more.

    What do I think about the stability of the solution?

    As for the stability of SentinelOne Singularity Endpoint, I do not have any negative thoughts. It was pretty clean and had a nice installation.

    What do I think about the scalability of the solution?

    I have not had any scalability issues with SentinelOne. We have deployed it in both 64-bit and 32-bit architectures, and both are working fine. We also received troubleshooting steps such as running commands in the command prompt or PowerShell to ensure its installation.

    How are customer service and support?

    I evaluate customer service and technical support of SentinelOne as adequate. We are not proactively calling them since our server management team is responsible for crashes or other issues and they bring in SentinelOne team when necessary.

    Which solution did I use previously and why did I switch?

    I have worked on Kaspersky EDR solutions and also SentinelOne Singularity Endpoint. We are deploying Deep Security from Trend Micro for the servers. For endpoint protection, I see SentinelOne as the perfect solution, and for the server, I feel that Deep Security from Trend Micro is working fine as I have seen various organizations using it.

    In my previous organization, they were using Kaspersky EDR solutions, so I did not switch from Kaspersky to SentinelOne. Instead, Deep Security is being installed in our servers here.

    How was the initial setup?

    The initial setup of SentinelOne Singularity Endpoint was straightforward, and there were no issues with it.

    What about the implementation team?

    We are not in a partnership with SentinelOne. We are just the end-users of the solution. SentinelOne has provided us with the EDR solution installed on our own servers, and if any updates need to be made, the vendor has to come and install them manually.

    Which other solutions did I evaluate?

    SentinelOne is indeed very highly regarded in the industry and is seen as a supreme solution. This is a significant advantage for us in our organization.

    What other advice do I have?

    I am not certain how to answer if SentinelOne Singularity Endpoint has helped to consolidate our security solutions.

    At the moment, I do not use SentinelOne Singularity Endpoint's Ranger functionality for network and asset visibility, and I am not aware of it, so there are no issues.

    SentinelOne Singularity Endpoint has helped to reduce alerts because we have predefined the hash values, and the mitigation part is done by automation itself.

    Currently, I am just in the deployment phase, and the administrator part is handled by another team, so I do not have specific data points on how much the alerts it has helped to reduce.

    SentinelOne Singularity Endpoint has indeed helped us to reduce our organization's mean time to detect, as the major vulnerabilities have already been patched by it, and we are not facing any downtime or related issues.

    As far as I know, regarding mean time to respond metrics, the alerts are getting in the queue itself, but I am not the right person to answer this at this time.

    I am utilizing Purple AI, but I feel that it is not available in our infrastructure since we have offloaded SentinelOne only on our servers and not from the vendor.

    Based on my experience with SentinelOne, I recommend that it should be available for home users as well, and I believe they are using SentinelOne for Azure cloud services, which is pretty good. I would rate this review as an eight out of ten.

    Karsh Trivedi

    Automation has reduced alert overhead and speeds up endpoint investigations for my team

    Reviewed on Jul 09, 2026
    Review provided by PeerSpot

    What is our primary use case?

    My usual use cases for SentinelOne Singularity Endpoint are to manage and deploy it on the endpoints across my organization. I also use it for automations, which represents my primary use case.

    I use SentinelOne Singularity Endpoint mostly with my EDR. I am not heavily focused on cloud at this time as I am still in the development and learning phase of cloud deployment and cloud telemetry collection. Seeing alerts on a single pane of glass and resolving incidents has helped me significantly. It provides a better ecosystem with the AI team and all the capabilities already included.

    What is most valuable?

    The EDR feature of SentinelOne Singularity Endpoint and their detection features are excellent. They perform very well at endpoint detection and resolution. Their automated response capability is equally strong. There is also granular control over endpoint detection policies, which is valuable.

    I have integrated SentinelOne Singularity Endpoint with Splunk, and the ingestion and correlation of logs and telemetry from endpoints is strong. It provides a good perspective on what exactly happened. This really helps me as a SOC analyst to investigate what has occurred on an endpoint if there is malware or a malfunction on that particular endpoint.

    SentinelOne Singularity Endpoint has reduced the overhead of my alerts with the enhanced telemetry provided. I do not have a precise count, but it has had a significant impact. I estimate that I experience approximately twenty to thirty percent less alert overhead as they are automatically enriched and resolved.

    SentinelOne Singularity Endpoint has helped reduce my team's time in analyzing alerts and determining what is wrong with endpoints. It also makes investigations easier without disrupting users. Mean time to detect and mean time to respond are metrics where I cannot provide exact numbers, but I can say that SentinelOne Singularity Endpoint has had a noticeable positive impact, making detection and response much faster than the very manual and tedious process we had before.

    The positive benefits from using SentinelOne Singularity Endpoint include reduced effort required to interact with users during critical investigations. It has provided automation capabilities and advanced telemetry from endpoints to investigate any issues that arise. My team interacts less directly with users, so the impact to user business is minimized when cyber incidents occur and investigations are needed.

    What needs improvement?

    They could still work on optimizing their agent. Additionally, they do not appear to provide a free trial. If they could provide a free trial for one or two endpoints, it would be a better option for testing.

    For how long have I used the solution?

    I worked with SentinelOne Singularity Endpoint at Infosys for two years and have continued using it recently, for a total of approximately three years.

    What do I think about the stability of the solution?

    SentinelOne Singularity Endpoint is reliable and stable. It does not create many issues.

    I measure the stability and reliability of SentinelOne Singularity Endpoint based on how well it detects threats and how stably it performs in user environments. I do not want an EDR tool or agent to consume excessive resources from the endpoint. SentinelOne Singularity Endpoint manages this well. It would be better if it were more optimized, but overall it performs well.

    What do I think about the scalability of the solution?

    SentinelOne Singularity Endpoint is scalable and easy to scale. We simply deploy it and it scales itself.

    Scaling out might be a concern, but I have not had a need to scale down, so this has not been an issue.

    How are customer service and support?

    I am not currently in touch with technical support for SentinelOne Singularity Endpoint as I am in the early deployment phase and am learning and brushing up on the platform myself. My peers have had interactions with technical support, and they have reported that it is excellent. Technical support is overall very strong, and though I do not have direct contact with them, the feedback I have received has been positive.

    Which solution did I use previously and why did I switch?

    I previously used Quick Heal Endpoint and Quick Heal EPS, which were not sufficient for our advanced threat protection needs. We switched to SentinelOne Singularity Endpoint because of these limitations.

    How was the initial setup?

    SentinelOne Singularity Endpoint is fairly straightforward to set up and has an intuitive user interface. A clear vision of your security policies is necessary, and a phased rollout is recommended. You cannot roll out the solution to everyone at once as it might impact many people simultaneously. A phased approach with policies tailored to your organization works best.

    What's my experience with pricing, setup cost, and licensing?

    The cost of SentinelOne Singularity Endpoint is reasonable and appropriate for the features it provides. It is not too expensive or cumbersome. However, it would be beneficial if they could provide a free trial at some point.

    Which other solutions did I evaluate?

    I was considering Trend Micro Vision One as an alternative option, but SentinelOne Singularity Endpoint stood out.

    I was evaluating Trend Micro Vision One and determined that SentinelOne Singularity Endpoint was the better option for my use case with one of my particular clients. As a consultant at a service-based firm, my role is to advise organizations on what will suit them best. For that particular client, this was the optimal choice, though other clients might benefit from different options. SentinelOne Singularity Endpoint was one of my top considerations for endpoint security along with Microsoft Defender for Endpoint for Windows-only environments.

    What other advice do I have?

    SentinelOne Singularity Endpoint is a SaaS-based platform that I deployed on-premises. I would rate this solution a ten out of ten.

    reviewer2848893

    Behavioral detection has transformed endpoint investigations and now improves incident response

    Reviewed on Jul 08, 2026
    Review from a verified AWS customer

    What is our primary use case?

    My main use case for SentinelOne Singularity Endpoint is primarily for endpoint detection and response, EDR, focusing on endpoint protection.

    SentinelOne Singularity Endpoint is being used for behavioral threat detection, malware and ransomware protection, security investigations, response activities, and also to isolate endpoints where required.

    How has it helped my organization?

    SentinelOne Singularity Endpoint has positively impacted my organization by being one of the primary tools keeping us secure against modern security issues, with faster threat detection and investigation through better endpoint visibility which has greatly helped our team, resulting in improved incident response and reduced reliance on manual monitoring.

    Regarding metrics on how it has improved incident response, I do not have any specific data to share.

    What is most valuable?

    The best features SentinelOne Singularity Endpoint offers include behavior-based detection, which can identify suspicious activity based on behavior patterns and has very few false positives, as well as autonomous prevention and response, where the agent can automatically block malicious activity. It also has strong investigation capabilities, and the process traceability along with endpoint activity context makes it very easy to understand what happened during an alert, and it includes ransomware protection and rollback capabilities, along with very low operational overhead.

    From all the features I mentioned, I find myself relying most on behavior-based detection with endpoint investigation visibility because it allows our security team to quickly understand suspicious activity beyond simple malware alerts, helping analysts validate incidents faster and make better decisions.

    What needs improvement?

    SentinelOne Singularity Endpoint would benefit from broader security ecosystem integration, including deeper native integrations across identity access and other security domains, which would make it more competitive with larger security platforms.

    I chose nine out of ten because I usually do not give out tens to be honest, but it is mainly due to areas outside its core endpoint security, as while it is very strong in EDR, there is still room for improvement around broader security platform capabilities and deeper cloud-native security coverage.

    For how long have I used the solution?

    I have been using SentinelOne Singularity Endpoint for more than a year.

    What do I think about the stability of the solution?

    SentinelOne Singularity Endpoint is stable.

    What do I think about the scalability of the solution?

    I am happy with the scalability of SentinelOne Singularity Endpoint.

    How are customer service and support?

    We pay for premium support for SentinelOne Singularity Endpoint, which is good, but they are charging us money.

    Which solution did I use previously and why did I switch?

    SentinelOne was already in this environment, so I did not previously use a different solution.

    What was our ROI?

    I have seen a return on investment, which is primarily on the improved SOC efficiency and reduced manual effort, along with the time saved during investigations and faster response actions. For example, a capability such as endpoint isolation helped reduce the time required to contain a suspicious activity, but I do not have numbers to present.

    What's my experience with pricing, setup cost, and licensing?

    I was involved in the decision-making regarding my experience with pricing, setup cost, and licensing.

    Which other solutions did I evaluate?

    Before choosing SentinelOne Singularity Endpoint, I did not evaluate other options, as we acquired it from an acquisition.

    What other advice do I have?

    Singularity Complete has not significantly consolidated our security solutions, as we are primarily relying on this for EDR.

    To some extent, Singularity Complete has helped reduce alerts, with the main improvement being the platform's ability to automatically identify and prevent certain behaviors, but I do not have a number.

    To some extent, Singularity Complete has helped free up my staff for other projects and tasks, primarily with its autonomous prevention capabilities, allowing analysts to spend less time collecting information manually and more time focusing on higher-value security activities.

    It has definitely helped reduce my organization's mean time to detect, MTTD, but we have not measured the specific reduction percentage.

    Mean time to response, MTTR, is primarily handled by humans.

    The pricing for SentinelOne Singularity Endpoint is good compared to other industry vendors, and organizations should definitely focus on proper policy tuning and make use of the behavioral capabilities. I would rate this product nine out of ten overall.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    surajku32

    Endpoint protection has reduced alerts and saved time with real-time monitoring and rollback

    Reviewed on Jul 07, 2026
    Review provided by PeerSpot

    What is our primary use case?

    I typically use SentinelOne Singularity Endpoint for endpoint detection, including EDR and EPP, to secure my endpoints.

    A specific example of how I use SentinelOne Singularity Endpoint to secure my endpoints is that it provides AI-powered threat detection that will be very profitable for us. If any malware behaves suspiciously, behavioral analytics will notify us, and it can stop zero-day threats and fileless malware, saving our system from the threat.

    The main use case for SentinelOne Singularity Endpoint is to secure my endpoints.

    How has it helped my organization?

    SentinelOne Singularity Endpoint has positively impacted my organization by saving many systems because we have more than 100 systems that are very critical to monitor individually, and it helps secure all our systems.

    Managing and securing those systems with SentinelOne Singularity Endpoint means it provides real-time monitoring and threat analysis for each system, which is very helpful for us.

    Singularity Complete helped free up my staff for other projects and tasks by saving the costs of two employees after implementing this solution.

    What is most valuable?

    The best features that SentinelOne Singularity Endpoint offers are real-time monitoring, process visibility, attack timelines, root cause analysis, threat hunting, and MITRE ATT&CK mapping, which is the best feature.

    Real-time monitoring and process visibility from SentinelOne Singularity Endpoint help me in my day-to-day work because if any malware files are downloaded, it will take real-time action on them. Additionally, there is a rollback plan, allowing us to easily revert to the malware-affected system, which is a very beneficial feature available in the system.

    What needs improvement?

    SentinelOne Singularity Endpoint can be improved by ensuring that all our endpoints are completely secure and risk-free. If anything happens, a rollback plan will be there so that we can easily revert everything.

    For how long have I used the solution?

    I have been using SentinelOne Singularity Endpoint for the last six months.

    What do I think about the stability of the solution?

    SentinelOne Singularity Endpoint is stable.

    What do I think about the scalability of the solution?

    The scalability of SentinelOne Singularity Endpoint is good.

    How are customer service and support?

    The customer support for SentinelOne Singularity Endpoint is very good.

    On a scale of 1 to 10, I would rate the customer support for SentinelOne Singularity Endpoint a 10 out of 10.

    Which solution did I use previously and why did I switch?

    I did not use any other solution before using SentinelOne Singularity Endpoint, as I started using it directly.

    What was our ROI?

    I have seen a return on investment with SentinelOne Singularity Endpoint as it saves a lot of time and reduces our employee costs.

    Which other solutions did I evaluate?

    I did not evaluate any other options before choosing SentinelOne Singularity Endpoint.

    What other advice do I have?

    Singularity Complete has helped reduce alerts because my system currently has no threats, so I am getting very low alerts.

    SentinelOne Singularity Endpoint has helped reduce my organization's Mean Time to Detect by about two to three hours per day.

    The solution has helped reduce my organization's Mean Time to Respond by five hours.

    If you want to secure your endpoint, you can go for SentinelOne Singularity Endpoint; it is a very good product that you can use. I would rate this product a 10 out of 10.

    ABUZAR KHAN

    Automated detection and response have reduced investigations and protect endpoints in real time

    Reviewed on Jul 07, 2026
    Review provided by PeerSpot

    What is our primary use case?

    My main use cases for SentinelOne Singularity Endpoint are endpoint detection and response, real-time threat prevention, and incident investigations. It helps us protect laptops, desktops, and servers from malware, ransomware, and other advanced threats while providing centralized visibility into endpoints and their activity. I also use its automated remediation capabilities to quickly isolate infected devices, roll back ransomware where applicable, and reduce the manual response effort.

    I can provide a specific example of how my team used SentinelOne Singularity Endpoint in a real situation. We received an alert from SentinelOne Singularity Endpoint indicating suspicious PowerShell activity on an employee's laptop. The platform correlated the behavior with a malicious Office document that had launched the script attempting to download additional payloads. SentinelOne automatically killed the malicious process, quarantined the file, and isolated the endpoint from the network to prevent lateral movement. Using the process timeline, the security team quickly identified the root cause, confirmed that no other endpoints were affected, removed the malicious document, and returned the device to service. The entire incident was contained within minutes without any ransomware encryption or data loss.

    I have many use cases for SentinelOne Singularity Endpoint.

    How has it helped my organization?

    Since deploying SentinelOne Singularity Endpoint, I have seen faster threat detection and response, better visibility across our endpoints, and less time spent investigating security incidents. The automated containment and remediation features have reduced manual work for our security teams, and the centralized console has made it easier to monitor endpoint health and respond to threats.

    I have seen faster detection with better context. Keeping our most critical security incidents in mind, the biggest improvement has been reduced investigation time thanks to the storyline features and automated remediation, allowing analysts to focus on the higher-priority security alerts.

    What is most valuable?

    The best features SentinelOne Singularity Endpoint offers that stand out to me the most are its behavioral AI detection, automated response capabilities, and detailed incident visibility. The storyline features, in particular, give a response timeline, while the process storyline makes it much easier to investigate the incident and understand exactly what happened.

    SentinelOne Singularity Endpoint has behavioral AI detection, automated remediation and ransomware rollback, network isolations, storyline technology, threat hunting, remote response, and centralized management as the main features.

    What needs improvement?

    SentinelOne Singularity Endpoint can be improved in some areas. The management console can be complex for new users, and some advanced features require a learning curve to use effectively. Organizations with large environments may also want more flexible reporting and dashboard customization. While false positives are generally low, behavioral detection can still require analyst review and tuning to reduce unnecessary alerts.

    I would like to see more customizable dashboards for executive reporting, simpler policy management and reduced false positives, faster support response times, deeper native integrations, more granular permissions, and easier onboarding and training.

    For how long have I used the solution?

    I have been working in my current field for the last one year.

    I have been using SentinelOne Singularity Endpoint for one year.

    What do I think about the stability of the solution?

    SentinelOne Singularity Endpoint is generally stable and reliable.

    What do I think about the scalability of the solution?

    SentinelOne Singularity Endpoint has good scalability, ranging from small deployments to large enterprise environments. The cloud-based management model makes it easier to onboard, manage, and monitor large numbers of endpoints without needing additional backend infrastructure.

    How are customer service and support?

    Customer support for SentinelOne is generally good, with knowledgeable technical teams and useful resources for troubleshooting and deployment questions.

    Which solution did I use previously and why did I switch?

    I previously used another endpoint security solution and switched to SentinelOne Singularity Endpoint because I needed stronger behavior detection, faster incident response, and better automations. The previous solution provided basic endpoint protection.

    What was our ROI?

    I have seen a return on investment from SentinelOne Singularity Endpoint. The main value has come from reducing manual security operations, improved incident response time, and consolidating multiple endpoint security tools into one platform.

    What's my experience with pricing, setup cost, and licensing?

    My experience with pricing, setup cost, and licensing is that the licensing model was relatively straightforward and cost-effective compared to my past solutions.

    Which other solutions did I evaluate?

    Before choosing SentinelOne Singularity Endpoint, I evaluated several endpoint security solutions including Microsoft Defender for Endpoint and CrowdStrike.

    What other advice do I have?

    My advice to others looking into using SentinelOne Singularity Endpoint would be to clearly define your security goals and how SentinelOne Singularity Endpoint would fit into your existing security operations and deployment. I would rate this product a 9 out of 10.

    reviewer2869185

    Automated threat detection has reduced response times and has restored critical files from attacks

    Reviewed on Jul 07, 2026
    Review from a verified AWS customer

    What is our primary use case?

    My main use case for SentinelOne Singularity Endpoint is to use the VSS Shadow Copies, which help us regain access to files that are deleted or modified by threats.

    Once in our network, there was an attack, something similar to ransomware, which affected files in our endpoints. VSS stores the shadows of every file and takes a backup every four hours. I used the ShadowExplorer app to re-export those files and gain access to those deleted, quarantined, or modified files.

    What is most valuable?

    SentinelOne Singularity Endpoint is very useful because it has lightweight agents and a single agent works on multiple platforms including Identity, EDR, XDR, DLP, firewall control, and device control.

    It has the capability to showcase the telemetries gathered from all the endpoints or devices in the network and shows every attack chain in the XDR dashboard.

    Normal detection does not show which back-end process or child process is malicious. By using the telemetry and the attack chains in the graph, I can explore more about how the attack is progressing in our environment, from which application to which process, which registry changes, which domains, or hosted IPs are working in the back end.

    Singularity Endpoint's AI capabilities help us detect more advanced threats in our environment, and it helps us gain less time to respond to those attacks. I use Purple AI to create multiple reports and can ask anything to generate reports or logs.

    It provides mostly accurate results.

    SentinelOne Singularity Endpoint is deployed in our organization in a public cloud. It can integrate with multiple third-party solutions which help us gain multiple logs from across the network, including firewall and SIEM. It helps us detect faster and hidden threats.

    It did help us consolidate our security solutions. We can manage multiple tools including next-gen SIEM, identity security, cloud security, EDR, and XDR in a single platform with a single agent, so we do not need to manage multiple products.

    I use the Ranger functionality in SentinelOne. It provides full visibility of both unprotected and protected devices. It also helps push the agent directly to unprotected devices, which is very important.

    Singularity Complete has helped reduce alerts.

    It saved much more time because we can take action on multiple solutions from a single management console.

    Mean Time to Detect is reduced by fifty percent.

    Mean Time to Respond is reduced by forty percent.

    SentinelOne Singularity is used mostly for its detection models, AI engines, and machine learning engines, and it has the capability to run multiple tools in a single platform.

    What needs improvement?

    Its agent gets offline multiple times, mostly in Windows 7 which has legacy versions.

    I chose nine out of ten for SentinelOne Singularity Endpoint because the endpoint is getting offline multiple times. Sometimes the firewall policy and device control policies are not working properly, so they need to work on this part.

    For how long have I used the solution?

    I have been using SentinelOne Singularity Endpoint for four years.

    What do I think about the stability of the solution?

    SentinelOne Singularity Endpoint is a stable tool.

    How are customer service and support?

    Customer support is good.

    Which solution did I use previously and why did I switch?

    I used Trend Micro Endpoint Security, which is very complex to use in the management console.

    After changing from Trend Micro, we are observing fewer attacks.

    There are multiple positive changes. Trend Micro's agent is very heavy and consumes more CPU, RAM, and storage. SentinelOne has a lightweight agent that also helps us regain the quarantined or modified files affected by viruses. Trend Micro does not have that feature.

    What was our ROI?

    I have seen a return on investment.

    What's my experience with pricing, setup cost, and licensing?

    The pricing and setup costs are not high but in the medium range.

    Which other solutions did I evaluate?

    I evaluated other options, which are CrowdStrike and Cortex XDR.

    What other advice do I have?

    I gave this product a review rating of nine out of ten.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?