SentinelOne Singularity Platform logo

    SentinelOne Singularity Platform

    Unlock enterprise-wide security for your AWS environment with SentinelOne Singularity Platform. This AI-powered solution provides real-time threat detection and automated response across your infrastructure, ensuring continuous protection at infinite scale. By autonomously securing endpoints, cloud workloads, and identity, SentinelOne delivers total visibility while eliminating security silos. Integrate seamlessly with AWS and leverage our unified data lake and Purple AI to accelerate investigations and gain deeper insights. Secure your AWS cloud and focus on innovation with the speed and efficiency of AI.

    Ratings and reviews

    4.6
    404 ratings
    46 AWS reviews
    |
    358 external reviews
    External reviews are from G2  and PeerSpot .

    Filters

    Review type

    AWS Marketplace reviews
    External reviews
    Reviews (404)
    James R.

    Effective Endpoint Protection and Threat Detection

    Reviewed on Jul 28, 2026
    Review provided by G2
    What do you like best about the product?
    What I like best about SentinelOne Singularity Endpoint is its behavioral threat detection and automated response. It detects suspicious activity quickly, isolates infected endpoints when needed, and provides a clear investigation timeline that makes it easier to understand and respond to security incidents. The management console is also easy to navigate, which simplifies day to day security operations.
    What do you dislike about the product?
    I think the sentinelone singularity endpoint platform is a great security solution, however fine tuning policies and creating exclusions for trusted applications can take some time, especially for larger environment. This can be improved on.
    What problems is the product solving and how is that benefiting you?
    SentinelOne Singularity Endpoint helps us detect and stop malware, ransomware, and other endpoint threats before they spread. It provides real time visibility into endpoint activity, speeds up incident investigation, and automates response actions such as isolating compromised devices.
    Elizabeth E.

    SentinelOne Singularity: Proactive, Reliable EDR with Excellent Real-Time Detection

    Reviewed on Jul 27, 2026
    Review provided by G2
    What do you like best about the product?
    SentinelOne Singularity Endpoint is one of the most effective and efficient EDR solutions I've used. It's highly proactive, with excellent real-time threat detection and automated response capabilities. The platform is reliable, easy to use, and provides great visibility into endpoint security.
    What do you dislike about the product?
    One area for improvement is the blocklist functionality. Currently, it only supports blocking file hashes, whereas I would like to see support for a broader range of indicators of compromise (IOCs), such as IP addresses, domain names, and URLs.
    What problems is the product solving and how is that benefiting you?
    As a SOC Analyst, SentinelOne Singularity Endpoint enables me to detect and respond to endpoint threats quickly. Its real-time visibility, behavioral detection, and automated response capabilities reduce investigation time, improve incident response, and strengthen our overall endpoint security.
    Victor Y.

    Simply 1-Click Ransomware Rollback That Restores Files Fast

    Reviewed on Jul 24, 2026
    Review provided by G2
    What do you like best about the product?
    Provides 1-click ransomware rollback capabilities, reverting unauthorized changes and restoring encrypted files from local shadow copies in the event of a ransomware attack.
    What do you dislike about the product?
    High Memory Usage: The agent can occasionally consume significant CPU and RAM resources, especially during full system scans or database operations, which can cause my laptop to slow down.
    What problems is the product solving and how is that benefiting you?
    Real-time autonomous mitigation. The local behavioral AI engine can kill processes, isolate infected machines, and automatically roll back changes instantly, without needing cloud connectivity or human approval.
    Francisco F.

    Intuitive tool with generative AI, quick remediation, and effective support

    Reviewed on Jul 23, 2026
    Review provided by G2
    What do you like best about the product?
    Very intuitive tool, easy to use, with built-in Generative AI that greatly helps in solving cases. Remediation is simple and fast. In terms of resources, it requires little and is quickly deployed through other tools like NinjaOne RRM. The price is reasonable for the advanced capabilities the solution offers, and if you have any questions, the support team responds promptly and appropriately.
    What do you dislike about the product?
    Centralized console, easy to use and with many automations that make your day-to-day more efficient. Thanks to the incorporated AI, the tool helps you close cases under the law of least effort and gives you time for other investigations.
    What problems is the product solving and how is that benefiting you?
    Before implementing SentinelOne, we had limited visibility into the actual security status of the endpoints and relied heavily on signature-based detection and manual intervention by the IT team. This made it difficult to detect ransomware early, advanced malware, lateral movements, and other threats that could compromise user devices.

    With SentinelOne Singularity Endpoint, we have achieved more proactive protection thanks to its behavior-based detection and response (EDR) capabilities and artificial intelligence. The platform identifies suspicious activities in real-time, allows for the immediate isolation of compromised devices, and simplifies investigation by providing complete visibility into what is happening on each endpoint.
    Nancy U.

    Storyline Visual Maps Make Threat Investigations Easy

    Reviewed on Jul 23, 2026
    Review provided by G2
    What do you like best about the product?
    Most helpful for me would be its storyline feature. It threads together process trees, network requests, registry and file changes into one visual map.
    What do you dislike about the product?
    The SentinelOne query language used to threat hunt within Deep Visibility is a pain to use. It takes quite a toll to learn and use it efficiently and effectively. Else, you'll just keep getting 'No results found'.
    What problems is the product solving and how is that benefiting you?
    It's solving the problem of alert fatigue and disjointed logs in security operations. DV and the storyline function help with faster MTTR as it reduces the time spent on aimless log searches and threat hunts.
    Adaku O.

    Real-Time Endpoint Visibility with AI-Powered Protection

    Reviewed on Jul 23, 2026
    Review provided by G2
    What do you like best about the product?
    What I find most helpful about SentinelOne Singularity Endpoint is its AI-driven endpoint protection, which leverages machine learning and behavioral analysis to detect and respond to threats in real time. It provides excellent visibility across endpoints, making it easy to investigate incidents and understand what's happening throughout the environment.

    The user experience is easy to navigate and intuitive, and onboarding new endpoints is seamless. It also integrates well with other security tools to enable a centralized monitoring and streamlined workflow for IR. All of these ensure high performance.
    What do you dislike about the product?
    One downside I’ve noticed is the occasional false positives. They create a lot of noise in the environment, which ends up wasting time. Even when the same alert has been manually mitigated and flagged, it still repeats.
    What problems is the product solving and how is that benefiting you?
    There are many benefits, such as holistic visibility into endpoints through real-time monitoring, which can help with containing threats. I especially like the rollback feature because it can restore endpoints to a safe state when needed.
    reviewer2875941

    Automated remediation has reduced investigation time and supports effective endpoint protection

    Reviewed on Jul 22, 2026
    Review from a verified AWS customer

    What is our primary use case?

    SentinelOne Singularity Endpoint's main use case is to monitor endpoint level alerts and server alerts, through which we monitor, detect, and remediate those alerts.

    In a quick example of how I use SentinelOne Singularity Endpoint to monitor and remediate an alert, we monitor the alerts and based on the investigation, we take the remediations, often with SentinelOne Singularity Endpoint itself taking the remediation, allowing us to close the case or escalate to the clients.

    The unique way I use SentinelOne Singularity Endpoint in my daily work is through the integration of Purple AI, which helps our job to hunt in the environment, allowing basic hunting and query generation, enabling analysts without knowledge in power query to generate queries efficiently, thus reducing investigation time.

    What is most valuable?

    The best features of SentinelOne Singularity Endpoint include the endpoint level remediation and the indicators referring for an alert, giving an overall picture of the actions that need to be taken by the analyst side.

    The remediation part of SentinelOne Singularity Endpoint plays a major role in investigation because if I am unsure whether a file is genuine or malicious, SentinelOne Singularity Endpoint analyzes its behavior and automatically remediates it, facilitating easy removal of legitimate files from quarantine.

    The user accessibility in SentinelOne Singularity Endpoint console is a feature I would highlight, as it is convenient for a new analyst, enabling them to understand and migrate to the console within a week.

    SentinelOne Singularity Endpoint positively impacts my organization by effectively detecting alerts and endpoint level alerts.

    The positive impact of SentinelOne Singularity Endpoint is evident in the remediation part, as it activates remediation as soon as the alert triggers, reducing environmental impact.

    What needs improvement?

    Recently, I faced an issue with SentinelOne Singularity Endpoint while detecting rogue devices, as there is a gap when scanning initiated from the admin console, recognizing different MAC IDs depending on the connection type, which leads to conflict between managed and unmanaged assets.

    Another area needing improvement is the process graph of SentinelOne Singularity Endpoint, which could be made more user-friendly, eye-catching, and offer a better in-depth view.

    For how long have I used the solution?

    I have worked in cybersecurity for around six years and ten months.

    What do I think about the stability of the solution?

    SentinelOne Singularity Endpoint is stable.

    What do I think about the scalability of the solution?

    SentinelOne Singularity Endpoint's scalability is good.

    How are customer service and support?

    The customer support for SentinelOne Singularity Endpoint is moderate.

    Which solution did I use previously and why did I switch?

    I have not used a different solution prior to this.

    How was the initial setup?

    I am not sure about the purchase of SentinelOne Singularity Endpoint because I was in the monitoring team and do not know the specifics from the sales team.

    What about the implementation team?

    My company has a partner relationship with this vendor beyond being just a customer.

    What was our ROI?

    I do not have any return on investment to share.

    What's my experience with pricing, setup cost, and licensing?

    As for my experience with pricing, setup cost, and licensing, I am not knowledgeable since I was not in the sales team.

    Which other solutions did I evaluate?

    I did not evaluate other options before choosing SentinelOne Singularity Endpoint.

    What other advice do I have?

    For a long time, SentinelOne Singularity Endpoint is effective at correlating my security solutions, allowing for customization of rules based on requirements.

    SentinelOne Complete did not reduce alerts; instead, it increased noise in the environment until fine-tunings were done for customized rules.

    As of now, I have not seen a significant freeing up of staff for other projects due to SentinelOne Singularity Endpoint.

    We are not using SentinelOne Singularity Endpoint for network and asset visibilities.

    Regarding organizational MTTD and MTTR, this is at a moderate level.

    My advice for others looking into using SentinelOne Singularity Endpoint is to go for it, as it effectively does the EDR job. I would rate this product an 8 out of 10.

    Diogo A.

    Storyline and Automated Mitigation That Help SOC Analysts Stop Threats Fast

    Reviewed on Jul 22, 2026
    Review provided by G2
    What do you like best about the product?
    The storyline is always a life-saver for SOC analyst. Helping map out child processes associated with a process has helped us uncover many issues.

    Secondly, The automated mitigation makes ensures a threat does not execute within the oversight of the Analyst
    What do you dislike about the product?
    It is not easily to work with the queries. For example, inability to open some critical pages in a new tab or group related values makes it a bottleneck except for the use of purple AI, I really hate that for the tool .
    What problems is the product solving and how is that benefiting you?
    Malware detection and automated mitigation are a major benefit of the tool. Time that would otherwise be spent on detailed malware analysis, reverse engineering, or decoupling from a traditional anti-virus tool can be allocated to other tasks.

    Also, SentinelOne doesn’t just mitigate; it provides useful information about the threat and integrates with VirusTotal.

    SentinelOne is fast in detection and mitigation. For our new analyst, the SentinelOne University also helps make learning easier. On pricing, it is well-priced for the value and benefits it provides, but startups and small teams might still find it expensive to use. Even so, the benefit supersedes the cost.

    As someone who has worked in an MSSP, having knowledge of SentinelOne is always a plus for my CV.
    Tanuja Parab

    Behavioral detection has transformed incident response and now speeds up endpoint threat containment

    Reviewed on Jul 21, 2026
    Review from a verified AWS customer

    What is our primary use case?

    The main purpose of using SentinelOne Singularity Endpoint in my day-to-day work is for monitoring endpoint alerts, investigating any suspicious activity, analyzing behavior, and detecting potential threats. For example, SentinelOne detects suspicious PowerShell execution or potential ransomware behavior, and I review the alert, investigate the process tree, check affected endpoints, and if necessary, isolate endpoints and remediate threats, with our primary use case being protection on the EDR.

    In my day-to-day work, I primarily use SentinelOne Singularity Endpoint to investigate suspicious activity and support incident response by reviewing behavior detection, analyzing the process tree, and identifying the root cause of alerts while taking appropriate actions such as isolating compromised endpoints or initiating remediations whenever necessary. Overall, this helps us quickly detect, investigate, and contain endpoint threats and improve our overall security posture.

    What is most valuable?

    My favorite feature of SentinelOne Singularity Endpoint is the behavioral AI detection because it identifies suspicious activity or malicious PowerShell execution, even when malware has not been seen before, helping us respond to threats much faster.

    One example of how behavioral AI detection in SentinelOne Singularity Endpoint has helped us in real scenarios is when we detected PowerShell activity on an endpoint. Instead of relying on known malware signatures, it identified abnormal behavior, allowing us to investigate the process tree, confirm the suspicious activity, isolate the endpoint, and prevent the spread, enabling containment of the incident quickly before it impacted other systems.

    The behavioral AI in SentinelOne Singularity Endpoint helped us identify suspicious activity and is a feature I truly appreciate, as it aids in our investigations promptly alongside our SOC team.

    SentinelOne Singularity Endpoint has positively impacted my organization by improving endpoint security through faster threat detection, providing better visibility and quicker incident response features including AI, automation, endpoint isolation, and effectively containing threats while reducing the workload for the SOC team.

    I do not have exact metrics to share, but I have definitely seen a reduction in the manual effort of our SOC team. For instance, whenever SentinelOne detects suspicious behavior, it automatically correlates related processes and provides a complete process tree, saving analysts' time because we do not have to manually piece together events. Features including automation remediation and endpoint isolation also help contain threats quickly and decrease required manual intervention.

    What needs improvement?

    I am satisfied with SentinelOne Singularity Endpoint overall, but if it could be improved, it would be in providing more customizable reporting, a richer dashboard, and broader integration with third-party tools. Other than that, I find it effective and reliable with no major suggestions for improvement.

    Based on my experience with SentinelOne Singularity Endpoint, I have not encountered any major issues that significantly affect our day-to-day operations. The platform has been stable, and while every product continues to evolve with new features and integrations, I do not have additional improvements to suggest at this time.

    For how long have I used the solution?

    I have been using SentinelOne Singularity Endpoint for approximately two years, mainly for monitoring endpoint alerts, investigation, detection, and supporting incident response.

    What do I think about the stability of the solution?

    SentinelOne Singularity Endpoint is stable.

    What do I think about the scalability of the solution?

    I would rate its scalability a nine.

    How are customer service and support?

    I would rate the customer support a ten because it helps us greatly and has been very good for us. I would rate my experience with SentinelOne Singularity Endpoint's customer support a ten.

    How was the initial setup?

    Asset visibility is something we never see, but having asset visibility including expiry notifications provides us valuable visual information. Overall, my experience with pricing, setup cost, and licensing is good, although I am not the right person to comment extensively on pricing.

    What was our ROI?

    I see a return on investment, and while I cannot share specific metrics, it is evident in the improvements we have experienced.

    What other advice do I have?

    I advise others looking into using SentinelOne Singularity Endpoint to use this tool because it provides a comprehensive solution. It is very effective and if your organization does not require too many personnel, it is one of the best tools for you. I do not have any additional thoughts about SentinelOne Singularity Endpoint other than that it is a very good tool that provides us with a feasible and wonderful solution. I give this review a rating of nine.

    reviewer2873466

    Automated detection has reduced alerts and now speeds up incident response across endpoints

    Reviewed on Jul 17, 2026
    Review provided by PeerSpot

    What is our primary use case?

    My primary use case for SentinelOne Singularity Endpoint is endpoint protection for employee devices, including real-time threat detection, ransomware protection, malware prevention, and automated response. I use it to monitor Windows and macOS endpoints, investigate security incidents, and help maintain a secure environment with minimal manual interventions.

    How has it helped my organization?

    While I haven't formally measured specific metrics, I have noticed that incident response has become faster because SentinelOne Singularity Endpoint automatically detects and contains suspicious activity before manual intervention is needed. The automated remediations and centralized visibility have reduced the time I spend investigating alerts, allowing the IT team to resolve security events more efficiently. I have also experienced fewer endpoint-related security issues requiring manual cleanup since deploying the solution.

    What is most valuable?

    The best features of SentinelOne Singularity Endpoint are its AI-powered behavioral detection, automated threat response, and endpoint isolation capabilities. I also appreciate the centralized management console, which makes it easy to monitor all the endpoints and investigate incidents. The ability to automatically quarantine malicious files and provide a clear attack timeline helps me reduce investigation time and simplifies incident response.

    The feature I rely on most from SentinelOne Singularity Endpoint is the automated threat detection and response. It identifies suspicious behavior in real time and can automatically quarantine malicious files or isolate the affected endpoint. This reduces the amount of manual investigation required, speeds up incident response, and allows me to focus on other IT admin tasks instead of constantly monitoring endpoints.

    What needs improvement?

    While SentinelOne Singularity Endpoint is a strong endpoint security solution, there are areas that could be improved. The management console could be more intuitive for new users, and some advanced features have a learning curve. Reporting and dashboard customization could offer more flexibility, and more detailed documentation and troubleshooting guidance would help admins resolve issues.

    For how long have I used the solution?

    I have been working in my current field for approximately one year.

    What do I think about the stability of the solution?

    SentinelOne Singularity Endpoint is stable, quite stable. The agent runs reliably.

    How are customer service and support?

    The customer support for SentinelOne Singularity Endpoint is really good.

    I would rate the customer support for SentinelOne Singularity Endpoint a solid eight. The customer support experience has been good overall.

    Which solution did I use previously and why did I switch?

    I used Trend Micro previously. I switched to SentinelOne Singularity Endpoint because I wanted stronger behavioral detection, faster automated response, better visibility into endpoint activities, and a more efficient security management experience.

    How was the initial setup?

    The pricing and licensing model for SentinelOne Singularity Endpoint is straightforward with flexible options based on the number of endpoints and required capabilities. The initial setup cost was reasonable considering the security features provided. Deployment was relatively simple with lightweight agents that could be installed across endpoints and centralized management through the cloud console. Overall, the licensing process and implementation experience were smooth.

    What was our ROI?

    I have seen a positive return on investment through improved operational efficiency and reduced manual security efforts. SentinelOne Singularity Endpoint has helped save time by automating threat detection, investigation, and remediation processes. For example, a task that previously required manual checks now allows the security team to focus on higher-value projects.

    Which other solutions did I evaluate?

    Before choosing SentinelOne Singularity Endpoint, I evaluated other endpoint security solutions. I compared options based on threat detection capabilities, AI-driven protection, automated response, ease of management, reporting, and overall security effectiveness. SentinelOne Singularity Endpoint stood out because of its strong behavioral detection, autonomous response capabilities, and centralized management experience.

    What other advice do I have?

    One example of how I used SentinelOne Singularity Endpoint in a real-world scenario was when it detected and automatically quarantined a malicious executable that had been downloaded through a phishing email. SentinelOne Singularity Endpoint flagged the file based on its behavioral analysis before it could execute, isolated the affected endpoints, and provided a detailed incident timeline. This allowed me to quickly verify the threat, remove the file, and restore the endpoint without any impact on other systems.

    SentinelOne Singularity Endpoint provides good visibility and correlation capabilities by collecting endpoint telemetry and security events in a centralized platform. It helps connect suspicious activities across endpoints, identify attack patterns, and provide a clear incident timeline for investigation. Its integration capabilities with other security tools improve overall visibility and streamline incident response workflows.

    The centralized console of SentinelOne Singularity Endpoint provides better visibility into endpoint activities, specifies threat investigation and reporting, and reduces the operational efforts required to manage separate security solutions.

    SentinelOne Singularity Endpoint has helped me reduce the volume of security alerts by using AI-driven detection, behavioral analysis, and automated prioritization. By filtering out low-risk events and providing more contextual information for investigations, it has reduced alert fatigue and allowed the IT security team to focus on high-priority incidents.

    SentinelOne Singularity Endpoint has helped me free up time for my IT security team by reducing the amount of manual monitoring, investigation, and endpoint remediation required. The automated detection and response capabilities allow me to resolve many security events faster and spend more time on proactive security improvements and other IT projects.

    SentinelOne Singularity Endpoint has helped reduce my Mean Time to Detect, with analysis on micro-threat detection and centralized visibility across endpoints. While I have not tracked an exact percentage reduction, detection that previously required manual investigation is much faster, allowing the team to respond to potential threats more quickly. If I had to estimate the reduction time, it would be around 40 to 50 percent.

    SentinelOne Singularity Endpoint has reduced response time by automatic containment and remediation. The ability to quickly isolate endpoints and investigate incidents from a centralized console helps resolve security events faster and reduce manual efforts. While I have not tracked an exact percentage reduction, the overall response process has become significantly more efficient.

    I would recommend evaluating SentinelOne Singularity Endpoint's strong threat detection and automated response capabilities. Before deployment, make sure to define your security requirements, test the agent in your environment, and plan policies carefully to get the best results. The centralized management, behavioral detection, and automation features can significantly improve endpoint protection and reduce the workload on security teams.

    Overall, SentinelOne Singularity Endpoint has been a valuable security solution for my organization. The AI-driven detection, automatic response, and centralized management provide strong protection while reducing the time required for monitoring and incident response. SentinelOne Singularity Endpoint is reliable and easy to manage, and while improvements in user experience and reporting customization would make an already strong solution even better. I give this solution an overall rating of 8.