SentinelOne Singularity Platform
Fast, Feature-Rich Endpoint Protection with Deep Visibility and Vulnerability Scanning
Endpoint security has provided deep attack visibility and delivers fast, reliable detections
What is our primary use case?
My main use case for SentinelOne Singularity Endpoint is running the Picus Breach and Attack Simulation tool in our lab environment. After performing attacks on specific EDR tools, we understand which tools require which kind of exclusions to complete the attacks properly. We also determine how we can tighten the security policy, what kind of rules we can add, or which options we can tighten. After the prevention section, we can integrate with the API endpoint on SentinelOne Singularity Endpoint, and thanks to that, we can also fetch some logs and validate the operation in the detection side.
What is most valuable?
The best features that SentinelOne Singularity Endpoint offers include the EDR visibility. It helps me understand which kind of operation Picus has done on the system, the timeline, the process tree, and which kind of command has been executed. Thanks to that, we can write the proper exclusions or write the proper security tightening rules. The visibility provided by SentinelOne Singularity Endpoint is the best part.
On the integration side, we integrate SentinelOne Singularity Endpoint with Picus to collect the logs from the host where SentinelOne Singularity Endpoint is installed. We can collect the logs and the alerts related to the specific machines. In different products, we can see some delay on the ingestion time. After a couple of attacks, sometimes we lose some of the logs because the security solution only logs a couple of the attacks but not all of them. However, we did not encounter this issue on SentinelOne Singularity Endpoint. Each time we can access all the logs created by Picus itself, which means SentinelOne Singularity Endpoint does not miss the logs. We also did not encounter any ingestion time delay issues on SentinelOne Singularity Endpoint. In some other products, we can encounter logs that have been created after the attacks have been finished, long after the fact. We did not encounter this issue on SentinelOne Singularity Endpoint. I can conclude that SentinelOne Singularity Endpoint is good at logging and alerting.
SentinelOne Singularity Endpoint has positively impacted our organization in that we do not use SentinelOne Singularity Endpoint in the whole company. We are only using SentinelOne Singularity Endpoint on the lab environments to validate the Picus attacks. Based on our experience, SentinelOne Singularity Endpoint's score is high when I compare it with well-known EDR solutions. I can say that SentinelOne Singularity Endpoint is one of the good products.
What needs improvement?
I cannot think of anything to suggest to improve SentinelOne Singularity Endpoint. If I find something, I can create a feature request for them.
The reason I provide an eight for SentinelOne Singularity Endpoint is that it is easy to use and detection is faster than the other EDR products. There is no delay, ingestion delay, or missing logs on SentinelOne Singularity Endpoint. However, I do not provide a ten out of ten because when I compare it with different products, SentinelOne Singularity Endpoint is at the third position. This means that on the prevention side, it might be better. This is the reason I provide an eight. Additionally, when I log into the system, sometimes I encounter some problems. For example, it asks for username and password. After the username and password, it asks for the token, meaning the OTP, but it turns me back to the first page without any notification. I just enter username, password, and OTP again to log into the system. I do not know which kind of problem I encountered, and it just did not throw an error. Instead of that, it just turned me back to the login page. This is not a good issue. I also encounter some problems on the support side. When the policy override was first announced for the Breach and Attack Simulation tools, we as Picus provided some feedback related to the policy override because it does not work for Picus. We contacted the support team, provided our observations, and explained why it does not work and what kind of enhancement could be done. However, the support team ignored us and just said they would look at it. I am not sure whether anybody looked at it, because it did not change. Still, when sometimes we encounter a customer using the policy overrides instead of the exclusions suggested by Picus, they encounter the problem where SentinelOne Singularity Endpoint kills the Picus services. After we connected to the system, we understood that the customer was using the policy override, but the policy override does not work. Perhaps the support responsiveness might be enhanced.
For how long have I used the solution?
I have been using SentinelOne Singularity Endpoint for approximately three years.
What other advice do I have?
I notice that integration is faster with SentinelOne Singularity Endpoint. It is also a kind of product that is easier to use. In some products, I do not want to mention the names of them, but some of them are hard to use, whereas SentinelOne Singularity Endpoint is easy to use. I did not use SentinelOne Singularity Endpoint before starting at Picus. Even though I did not use it before starting at Picus, I easily got used to it because the UI is easy to use and everything seems clear. I only use SentinelOne Singularity Endpoint in the lab environment. We did not use it in the whole company. However, if we had been using it, we would have benefited from it. I can say SentinelOne Singularity Endpoint offers faster detection.
I looked at the console and I see some numbers related to the different EDR vendors for both simulation speed and also the result itself. SentinelOne Singularity Endpoint's score is demonstrated as the third highest score in the system. It is also the third speediest one. This means that overall, SentinelOne Singularity Endpoint has demonstrated good performance. I provided a rating of eight out of ten for SentinelOne Singularity Endpoint.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Powerful EDR and Automated Threat Response with Centralized Visibility
Unified endpoint protection has reduced manual work and provides autonomous threat response
What is our primary use case?
My main use case is to protect the endpoints. Back in 2020, I conducted multiple proofs of value for different vendors, including SentinelOne. At the end of my evaluation, SentinelOne was the solution that provided a better fit for what we needed to do, and it was one of the best solutions, not just in terms of doing what it was supposed to do, but also in terms of cost. The end goal was to protect the endpoints, including Windows, Linux, and MacOS systems, as well as Windows servers and cell phones.
What is most valuable?
I have had multiple cases where end users fell victim to phishing emails or visited the wrong link. The EDR solution from SentinelOne was able to mitigate the potential threat, which protected not only the end user but also the company. This has also happened on servers. I have seen servers exposed to the Internet that had advanced threat actors trying to get into our networks, and SentinelOne's EDR solution has been able to mitigate such attacks and in some cases perform rollbacks. We also receive notifications via email and in some cases messages, which helps us stay on top of things and makes troubleshooting much easier. SentinelOne performs the mitigation on its own, which allows me to have peace of mind. Security is not absolute, and something else will happen, but from my experience, I am able to rely on the solution and know that it is going to do what it is supposed to do. Beyond protecting the endpoint, the autonomous response capability allows remediation of threats at machine speed without my intervention. The solution just does it on its own.
Today, I use SentinelOne for EDR, but we also use it for XDR. We are able to do assessments against our on-premise Active Directory as well as Azure, Microsoft Defender, and Exchange. We are collecting logs from our Azure enter ID, which gives me visibility that is sometimes difficult to find in the Microsoft 365 suite of tools. Being able to go into the SentinelOne Singularity Endpoint console and narrow down to the main events happening across the different platforms that we use makes things much easier, allowing me to be aware of what is happening and to triage items when needed. Having the complete SentinelOne Singularity Endpoint solution, not just with endpoint security but also with identity protection, makes my job much easier. If I had to do this manually, it would take a long time. Having the thermal response, behavioral AI, identity assessment, and the ability to stop potential lateral movements is a significant help.
SentinelOne Singularity Endpoint offers many features. I really appreciate what EDR is able to do, not only on the antivirus side. Having a single agent on an endpoint gives me the ability to handle multiple potential threat vectors. Instead of having multiple agents doing different things, SentinelOne Singularity Endpoint agent handles the antivirus side, endpoint protection, and with the behavioral side using AI, it is able to learn, see suspicious activities, track them, and isolate potential compromised devices automatically. When looking at our Active Directory, it has been able to do assessments and provide what the threat is using things such as MITRE, along with solutions on how to fix it. There is not one feature in particular; it is looking at it holistically and seeing how we can protect our premises not just from the endpoint but also from an identity perspective. Both complement one another.
On the behavioral AI, it is learning about our platforms and how they behave. We have multiple systems, some of which are exposed to the Internet because that is where our website is or where platforms multiple users use that are public facing. The behavioral AI is able to learn what a system is supposed to do, and if it notices something different, it tells us about it. Simple things such as if I remotely access a device and begin using PowerShell, in some cases it will alert me and say this activity does not look normal. The behavioral AI is able to see potential activity that is just not normal, create a baseline, and act upon it.
What needs improvement?
One of the things I would like to see from SentinelOne Singularity Endpoint is the vulnerability side of things. Today, vulnerabilities is one of the features that allows me to see what is happening with the endpoints, looking at the number of applications installed and which ones need immediate attention. However, we do not have patch management from SentinelOne Singularity Endpoint. Having patch management would make it even better. I would be able to take action from there and push the updates needed by the endpoints. If I were able to fix it or take action from SentinelOne Singularity Endpoint console, it would make my job much easier.
When it comes to reports, I was hoping to have better reports. For example, I tried to do a report to see the number of vulnerabilities affecting our endpoints and which were the most critical, but I was not really able to do that because of the limitations when it comes to doing reports. Reports is something that really needs work so that we can get better reporting, even though the dashboards are there and provide good telemetry. Having an executive level report would be a lot of help.
For how long have I used the solution?
I started using SentinelOne Singularity Endpoint in October 2020.
What do I think about the stability of the solution?
It has always been stable, and I have never seen any issues with it being unstable.
What do I think about the scalability of the solution?
Adding new endpoints is really not difficult at all and is super simple, especially because we use a script with our endpoint manager. We push the script, and it deploys without requiring a lot of work.
How are customer service and support?
Customer support has been amazing.
Which solution did I use previously and why did I switch?
For the current company I am working with, they had no EDR solutions. My recommendation was to deploy SentinelOne Singularity Endpoint as the EDR solution. At my previous company, we replaced CarbonBlack. I made a recommendation to replace CarbonBlack with SentinelOne Singularity Endpoint because of the functionality, being able to have antivirus and protect the endpoint using EDR as well as the AI side of things, including identity.
How was the initial setup?
When I first deployed SentinelOne Singularity Endpoint, we had multiple solutions handling orchestration for our cybersecurity program, which meant having multiple agents doing different things and collecting telemetry. In the past, I had CarbonBlack and other solutions and was missing out on things. Being able to have a single console to look at multiple metrics from different endpoints, including servers both Windows and Linux, as well as identity, has made performance and productivity much better.
What about the implementation team?
For hybrid deployment, we use NinjaOne. We are able to push the endpoint installation through our endpoint manager.
What was our ROI?
I do not have metrics as to how much time the solution has saved me, but I can give an example from my experience. I go to work in the morning and take a look at the platform for ten to fifteen minutes, then maybe during lunch and before I clock out. I do not have to spend a lot of time on the platform. If something happens, I get a notification or an alert about the incident. For the most part, we are not spending a lot of time looking at things. We know that if something happens, we are going to be notified.
What's my experience with pricing, setup cost, and licensing?
Pricing has been one of the best things. I have compared this to other platforms such as Cyber Reason and CrowdStrike. Price-wise, it was the best pricing. The deployment is straightforward and not complicated. We were able to use our Endpoint Manager solution to begin installation, and that has made a huge difference.
Which other solutions did I evaluate?
Cyber Reason, CarbonBlack, and CrowdStrike were all alternatives I evaluated.
What other advice do I have?
I do trust its alerts, and I do think that it is catching things. It is simple and straightforward. Looking at the marketplace, I am able to do the integrations as long as they follow the instructions, and it is pretty straightforward. I do not know that it has helped reduce alerts, but over time, users are aware that these platforms are installed on the endpoints and understand that if something happens, they are going to see the alerts come up and see the mitigation take place. They have seen that in the past. From an admin point of view, it is much easier to take a look at a single pane versus multiple platforms. Users are beginning to see that there is something installed on their computer whose whole job is to protect the endpoint. Do your homework and make sure that what you are getting out of SentinelOne Singularity Endpoint aligns with the goal of the business. Understand what the business is that you work with, conduct an assessment, and see if SentinelOne Singularity Endpoint aligns well with the company's goals. I would rate this solution a 9 out of 10.
Storyline has improved incident investigations and now needs deeper process visibility
What is our primary use case?
My main use case for SentinelOne Singularity Endpoint involves handling suspicious PowerShell activity, which is probably the most common one.
When I mention suspicious PowerShell activity, SentinelOne Singularity Endpoint helped me detect or respond to that incident with the Storyline feature, which I found excellent. It visually shows you what is going on, where, when, what the grandparent process is, what the parent process is, and what the child process is, so you can quickly go through it and gain insights on that.
I have more to add about my main use case or the types of incidents SentinelOne Singularity Endpoint helped me with. It is not just one use case; it is usually EDR and some XDR that helps you show various details. It is good that you can take actions from there, and it is really user-friendly to search something in the logs.
What is most valuable?
The best features SentinelOne Singularity Endpoint offers, which I found most valuable, is the Storyline, as it helps really well and provides deep visibility of everything.
SentinelOne Singularity Endpoint positively impacts my organization by saving time because I can see many details right away without needing to look for everything in some queries or anywhere. From the first vital glance, I can see the main information, which really saves time.
In terms of how much time it saved me or my team, if a usual ticket took about 20 minutes to investigate, with this solution it takes about 10 minutes; it is probably two times better.
What needs improvement?
To improve SentinelOne Singularity Endpoint, I want to continue working on this and provide even more data, more visibility, and everything clearer and faster. I guess everywhere could use a few additional functions, but they are not really needed.
I would add more about the needed improvements regarding features. I mean more deeper insights and bigger visibility so that when you have any process, you can click and it can show you everything for that process, so you can see really quickly everything that you need, enabling quick analysis and decision-making.
For how long have I used the solution?
I have been using SentinelOne Singularity Endpoint for a few months.
What do I think about the stability of the solution?
SentinelOne Singularity Endpoint is pretty much stable.
What do I think about the scalability of the solution?
The scalability of SentinelOne Singularity Endpoint is good.
Which solution did I use previously and why did I switch?
I did not previously switch from a different solution. We just added it for some clients, depending on what they wanted, but I was using CrowdStrike and Microsoft XDR as well.
What was our ROI?
I believe I have seen a return on investment from using SentinelOne Singularity Endpoint, though I am not sure and was not involved in prices. I guess it helps.
Which other solutions did I evaluate?
Before choosing SentinelOne Singularity Endpoint, I did not evaluate other options because I was not involved in that process.
What other advice do I have?
My advice to others looking into using SentinelOne Singularity Endpoint is to try it and use it to see if you it; it is good for me. I would rate this product a 7 out of 10.
Endpoint protection has unified workloads and has freed days each month for security projects
What is our primary use case?
My main use of SentinelOne Singularity Endpoint in my organization is to protect all of our endpoints, including our Kubernetes pods, our users' workstations, our Windows and Linux servers.
A concrete example of how I use SentinelOne Singularity Endpoint in my daily work is that the main tasks are to clear doubts on alerts related to threats. The majority of the time, approximately 90% of alerts turn out to be false positives, but the AI model learns relatively quickly and after two years, we no longer have to clear that many false positives.
Regarding rule customization and the remediation feature, these aspects concretely make my security management easier on a daily basis. The custom rules can allow you to reach a level similar to AppLocker. We use them to monitor everything that happens in certain user folders and to enable detection of unauthorized applications.
How has it helped my organization?
SentinelOne Singularity Endpoint has had a positive impact on my organization because it has allowed us to protect our entire environment, both Linux and Windows, which its former competitor did not do.
I have seen measurable benefits with SentinelOne Singularity Endpoint, specifically time savings, because the previous tool was very time-consuming in terms of the application itself. Here, we have very few failures of the SentinelOne client; it is very easy to update, and it is a considerable time saver compared to its former competitor.
Overall, SentinelOne Singularity Endpoint has helped me consolidate my security solutions as it allowed us to improve detection rules on our SIEM. Since we ingest SentinelOne logs into our SIEM, it has helped us improve our detection rules.
SentinelOne Singularity Endpoint has allowed me to free up time for my teams so they can focus on other projects or tasks. Comparing the person-day maintenance cost of the old product, it may have allowed us to gain one to two person-days per month.
What is most valuable?
My main use of SentinelOne Singularity Endpoint in my organization is to protect all of our endpoints, including our Kubernetes pods, our users' workstations, our Windows and Linux servers.
The tool offers Star Custom Rules. These rules actually allow you to customize detections based on the information system.
In my opinion, the best features that SentinelOne Singularity Endpoint offers my organization are, first, the Star Custom Rule component, which allows you to customize things based on the IS and the endpoints targeted by attacks. There is also the remediation component, which allows you to roll back based on the malicious actions that have been carried out on a workstation.
Another particularly useful aspect of SentinelOne Singularity Endpoint is the Deep Visibility component, which logs all system actions on the machines. This allows you to do forensics if needed or to really understand what happened on the endpoint.
What needs improvement?
SentinelOne Singularity Endpoint could be improved in the future by integrating detection models on prompts for the various artificial intelligences available on the market, in particular.
I think there are other improvement points to consider regarding SentinelOne Singularity Endpoint. The public documentation is not quite comprehensive enough; it would be good if they improved the search engine for the technical documentation.
For how long have I used the solution?
I have been using SentinelOne Singularity Endpoint in my company for about five years.
What do I think about the stability of the solution?
I find that SentinelOne Singularity Endpoint is stable in my environment; it is very stable. We really have very few crashes to report. When there are agent crashes, it is mainly related to the operating system version being obsolete.
What do I think about the scalability of the solution?
I have encountered difficulties or limitations when I wanted to extend or adapt the use of SentinelOne Singularity Endpoint to a larger number of workstations or servers in my organization. The only difficulty we have is that, since we have fairly old operating systems running on 32-bit CPUs, those are not supported by SentinelOne.
How are customer service and support?
I rate the customer support provided for SentinelOne Singularity Endpoint based on my experience as we do not have direct support with SentinelOne; our MSSP is responsible for contacting customer support. We have had incidents with fairly high levels of criticality, and SentinelOne responded very quickly.
Which solution did I use previously and why did I switch?
Before adopting SentinelOne Singularity Endpoint, we were using Bitdefender, which no longer suited us because it required a lot of maintenance time.
How was the initial setup?
The advice I would give to other professionals who are considering using SentinelOne Singularity Endpoint is that during implementation, do not put it directly into blocking mode but allow an adaptation period for the solution in detect mode in order to clear as many false positives as possible.
What about the implementation team?
Regarding the cloud part, I cannot answer that question; it is the MSSP company that manages it.
What was our ROI?
I have seen a return on investment with SentinelOne Singularity Endpoint; it is more about time savings than anything else.
What's my experience with pricing, setup cost, and licensing?
My perception regarding the price, implementation costs, and license management of SentinelOne Singularity Endpoint is that the price provided by our supplier is very competitive.
Which other solutions did I evaluate?
Before choosing SentinelOne Singularity Endpoint, it was the main one we evaluated; we also looked at HarfangLab, but the cost was significantly higher for minimal gains.
What other advice do I have?
I give SentinelOne Singularity Endpoint a rating of 8 out of 10. I chose 8 out of 10 because it is a very good score that comes close to perfection, but since there are always improvements to be made to a product, I did not want to give the maximum score.
Advanced endpoint protection has strengthened compliance and stopped risky user activity
What is our primary use case?
fuck
What is most valuable?
The best features that SentinelOne Singularity Endpoint offers are its anti-malware function and prevention, which is more intelligent than a traditional antivirus. From what I see in current reviews, it is one of the best EDRs, which is why it was recommended, and it works together with NinjaOne RMM.
As soon as SentinelOne Singularity Endpoint has a doubt, not necessarily just a malware signature, it will block the traffic. It has intelligent detection tools that go further than a traditional antivirus.
SentinelOne Singularity Endpoint has had a positive impact on the organization because the cyber insurance company required this type of tool to be reimbursed in case of a cyber incident. In other contexts and engagements, ESET has been used, which is also very good.
SentinelOne Singularity Endpoint has really improved compliance and security, as there are no problems anymore. Employees used to play around downloading files using eMule and other legal software that caused security or confidentiality issues, but all of that was able to be eliminated quickly. The firm had more than fifteen years of work behind it, accumulating bad habits and files that were not a problem before but can be today. The client was very happy to have cyber insurance and be reimbursed in case of a problem, allowing them to sleep much more soundly, because if there is an IT incident, it could mean the closure of the company.
What needs improvement?
Since adopting SentinelOne Singularity Endpoint, I have seen a mixed bag of measurable results. There have indeed been many fewer risks, but there have been other problems. SentinelOne Singularity Endpoint tends to block workstations at the slightest doubt, so it needs to be fine-tuned to be a bit more tolerant. Otherwise, there are blocked workstations and loss of productivity.
There were many problems on old Windows Servers that were not compatible, so they had to be upgraded. If SentinelOne Singularity Endpoint were more backward compatible with older versions, that would be great. The old versions of Windows Server were not very compatible, but that is the only criticism.
For how long have I used the solution?
SentinelOne Singularity Endpoint has been used since 2023.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Centralized protection has reduced threats and enabled rapid remote scans and confident governance
What is our primary use case?
My main use case for SentinelOne Singularity Endpoint is whitelisting applications. I use whitelisting for different domains, file paths, executables, and disabling snapshots.
What is most valuable?
The best features SentinelOne Singularity Endpoint offers include the ability to remotely scan computers with the current latest and greatest holistic software without downloading the newest agent to scan the system. I can scan a system remotely against the most recent signature database and updated definitions with holistic analysis of the application in a pinch. I can also remotely deploy and remotely update agents as needed, which is a really good feature to have.
I find myself using the remote scan and update feature constantly. When I work in IT, we get calls all the time from end users about clicking on suspicious links or emails, and being able to simply execute a remote scan on demand is extremely helpful.
SentinelOne Singularity Endpoint has helped reduce my organization's mean time to detect. Overall, it protects you instantly based on a user doing something they probably should not be doing and opening an application they should not have, and it usually gets stopped right then and there.
What needs improvement?
SentinelOne Singularity Endpoint is an amazing product for security and threat detection and mitigation, as well as for being able to secure an environment from a single location. It offers great flexibility with being able to add and remove devices, as well as keeping your environment secure. You can be confident in its ability to protect your environment because of how well SentinelOne Singularity Endpoint is put together. It might not be the best for whitelisting custom applications that are not preloaded into SentinelOne for whitelisting, but outside of that, it is a very good tool and probably one of the best ones I have ever used.
Overall, SentinelOne Singularity Endpoint is a great all-around product, but there is room for improvement when it comes to whitelisting services that also use VSS writers. For applications that use VSS writers such as backup data and recovery software, SentinelOne Singularity Endpoint needs to make it easier for customers to whitelist agents and BDR agents. There are so many nooks and crannies of BDR systems that in SentinelOne, you need to navigate to a multitude of different windows just to get the actual agent to be fully whitelisted. If it could all be on one screen, that would be amazing. If it could be a simple one-click completion, that would be even better.
I would recommend continuing the good work and working on making it easier for customers to whitelist third-party software, as that would be a huge step in the right direction. SentinelOne should start going further into mobile device protection, which would be amazing to have for tablets, mobile devices, and gaming systems. For Linux especially on gaming systems where people browse the internet, being able to deploy SentinelOne would be really awesome.
Regarding SentinelOne Singularity Endpoint's AI capabilities, I think it is probably more or less lacking in governance but has really good security. When I talk about governance, I am referring to FIPS certified governance. It would be really good if you could use SentinelOne to audit compliance with that, such as identifying that a particular router or switch is not compliant or that certain parts of a switch or a particular part of a server for Kerberos authentication or TLS is not compliant. If SentinelOne could fit that kind of feature inside its product, that would be amazing.
For how long have I used the solution?
I have been working in my current field for two months.
What do I think about the stability of the solution?
Even though SentinelOne Singularity Endpoint's ability to detect and respond to an issue is pretty much instant, we in IT still have to respond to the actual end user and their ticket.
What do I think about the scalability of the solution?
SentinelOne Singularity Endpoint's scalability is awesome, and I have not ever had any issues with that. As far as being stable, it is absolutely stable.
How are customer service and support?
Customer support for SentinelOne Singularity Endpoint is amazing. I have only had to use customer support once, which was to whitelist an application where the new UI of Singularity made whitelisting the file path difficult because it changed the order of operations on how whitelisting happens. My documentation was set up for the old portal through the old process of how you whitelist an application, and once the new view came out, it changed how that process worked. I had to go back through and update my documentation on it.
Licensing for SentinelOne Singularity Endpoint was great, as it was quick and easy to get users added and removed from the system. Outside of that, I have not had to do anything else with SentinelOne.
Which solution did I use previously and why did I switch?
I was working at a company that was already using CrowdStrike Falcon, so it was not that we switched or that I stopped using SentinelOne. It is just that CrowdStrike Falcon was what was given to me, and that is what I had to use.
What was our ROI?
The biggest benefit that SentinelOne would provide in this case is simply reputation. Because of how well SentinelOne is as a product, if a company or an MSP rolls out with it, you know you are secure and can feel confident in that. That is to me the biggest benefit that SentinelOne can offer.
What other advice do I have?
I have been using SentinelOne Singularity Endpoint on and off for a while now. I am used to the older portal, but since the transition to the newer one, I have only used it for maybe five to six months.
When you are working with an MSP that deploys SentinelOne Singularity Endpoint and has experience with it, you get a boost in reputation for just having that. To me, that would be the expected antivirus software or security software that should be standard with MSPs and organizations as a whole. SentinelOne sets the bar for security mitigation.
There was a specific section where I discussed governance, and I would actually include it here. If I could use SentinelOne as a way to audit my governance for specifically NIST 873 or FIPS 140-3 or CMMC2, that would be amazing.
If I was seeking a product for security and mitigation, I would start with SentinelOne and end with SentinelOne. I would put more trust in that application than any other on the market, one because I have a lot of experience with it, but two, it is trusted by most MSPs that I have worked with.
I have used SentinelOne Singularity Endpoint's Ranger functionality before, but only one time, and I cannot recall everything I did with it. It was with network enumeration, and that was kind of the limit of what I used it for.
I never got to choose between different security systems because the companies that I worked for either already had SentinelOne set up or they did not.
My advice for others looking into using SentinelOne Singularity Endpoint is to do it, as you have nothing to lose, and it is the best there is. I would probably shorten the name SentinelOne Singularity Endpoint, as it is kind of long and a mouthful. Just keeping it as SentinelOne sounds better, as it sounds SentinelOne has a new product called Singularity when you say it that way. I gave this review a rating of ten out of ten.
Endpoint defense has improved and remote investigations gain faster insights into attacks
What is our primary use case?
My main use case for SentinelOne Singularity Endpoint involves scanning customer endpoints and conducting forensic collection.
A specific example of how I use SentinelOne Singularity Endpoint for customer endpoints is that it has been able to notify us of quick fix attack activity from malicious MHTA being obfuscated and executed on different customer endpoints.
In addition to my main use case, I use SentinelOne Singularity Endpoint for checking endpoints' web activity, and it also helps with getting a comprehensive view of the overall activity and alerts that come in.
What is most valuable?
SentinelOne Singularity Endpoint's best features, which stand out to me the most, include the Remote Shell and Purple AI.
The Remote Shell and Purple AI help me in my day-to-day work by allowing some use cases to use the Remote Shell to remotely install or uninstall applications to support IT, or using Purple AI to provide quicker insight into alerts or activity that SentinelOne Singularity Endpoint is providing.
SentinelOne Singularity Endpoint has positively impacted my organization as it is our go-to EDR of choice.
It is my go-to EDR because we have noticed definitely faster response times, and the customer support has been better than some other companies we have had to deal with.
What needs improvement?
Regarding SentinelOne Singularity Endpoint's AI capabilities, I find its accuracy and reliability of output to be dependable, though I believe it could improve by opening up the access to more than summarizing or creating queries.
For how long have I used the solution?
I have been using SentinelOne Singularity Endpoint for about three years.
What do I think about the stability of the solution?
SentinelOne Singularity Endpoint is stable, and I am not aware of any issues with its reliability.
What do I think about the scalability of the solution?
SentinelOne Singularity Endpoint's scalability is excellent, as I have not had any issues with onboarding or offboarding new customers or adding new sites.
How are customer service and support?
SentinelOne Singularity Endpoint's customer support has been very good with good turnaround time and a solution-oriented approach.
Which solution did I use previously and why did I switch?
We have always had SentinelOne and used to use Trellix and their suite of tools, but we moved away from Trellix to stay with SentinelOne Singularity Endpoint as our main EDR, mainly due to updates and customer service.
Which other solutions did I evaluate?
Before choosing SentinelOne Singularity Endpoint, we evaluated SentinelOne and CrowdStrike, but it really depends on the customer's needs; overall, SentinelOne Singularity Endpoint is our go-to.
What other advice do I have?
Singularity Complete fills the role of EDR and helps us with monitoring, so it is a part of our complete puzzle that gives us the vision we need into a customer's environment, depending on whether they have SentinelOne Singularity Endpoint through us and we manage it.
We do not use the Ranger functionality because a different department manages network visibility.
Singularity Complete does not necessarily lessen alerts for us as we have it tuned to only create cases in our SIEM for things that are high and critical.
Although I do not have any direct metrics, I do find that it all ties into giving us the intelligence or data from detections, which get fed into our SIEM for us to take actions either in SentinelOne Singularity Endpoint or by contacting the customer.
My advice for others looking into using SentinelOne Singularity Endpoint is to take advantage of the partner support portal to get trained up on it, as that will definitely help you understand it and use it to its full capability.
I believe we fall under partner in terms of our business relationship with this vendor. I would rate my overall experience with SentinelOne Singularity Endpoint as an 8.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Comprehensive endpoint visibility has empowered us to prevent threats and focus on higher‑value work
What is our primary use case?
SentinelOne Singularity Endpoint serves as our primary EDR product deployed to our managed clients.
We use SentinelOne Singularity Endpoint to investigate cyber events or incidents, such as Splashtop usage or other RMM usage.
We work with ConnectWise SOC and SentinelOne SOC to manage it, functioning as a second line of defense for their SOC teams.
How has it helped my organization?
SentinelOne Singularity Endpoint has positively impacted our organization by helping us prevent a number of issues across our clients.
While I don't have specific numbers, we receive alerts all the time regarding different potentially unwanted apps or illegitimate remote access tools, and continuing to receive those alerts demonstrates its impact.
What is most valuable?
The best features SentinelOne Singularity Endpoint offers are complete visibility into our endpoints and what has happened, which has been the biggest benefit for us.
That visibility helps our team by allowing us to see what RMMs are running and whether they are legitimate or not. Being able to see when files are downloaded, transferred, or deleted has proven useful in different situations.
The threat detection with SentinelOne's Wayfinder has been a valuable feature. They conduct threat hunts on our behalf and inform us if anything emerges from it.
What needs improvement?
I believe their SLAs could be tighter, but overall it is a good platform.
Those are the main improvements needed for SentinelOne Singularity Endpoint. I don't think there are any other significant improvements needed that I haven't mentioned; there may be minor items or wish-list features.
For how long have I used the solution?
I have been using SentinelOne Singularity Endpoint for six years.
What do I think about the stability of the solution?
SentinelOne Singularity Endpoint is stable.
What do I think about the scalability of the solution?
We have experienced no issues with the scalability of SentinelOne Singularity Endpoint.
How are customer service and support?
Customer support for SentinelOne Singularity Endpoint is excellent; we receive quick answers when we need them.
Which solution did I use previously and why did I switch?
SentinelOne Singularity Complete has helped us consolidate our security solutions; we previously used both SentinelOne and Huntress and consolidated to SentinelOne Singularity Complete for all EDR functions.
We previously used Huntress in addition to SentinelOne and switched because we were consolidating our tools.
What was our ROI?
In the sense that we have not experienced any major incidents of infection, this demonstrates a return on investment for SentinelOne Singularity Endpoint.
What's my experience with pricing, setup cost, and licensing?
My experience with pricing, setup cost, and licensing for SentinelOne Singularity Endpoint has been positive; we received a good price point on everything.
Which other solutions did I evaluate?
We did not evaluate other options before choosing SentinelOne Singularity Endpoint.
What other advice do I have?
SentinelOne Singularity Endpoint is solid, and the support from the SOC is strong.
We only use the Ranger functionality of SentinelOne Singularity Endpoint in a limited capacity, so I cannot speak to its ability to provide network and asset visibility or its importance to us.
It is difficult to quantify whether SentinelOne Singularity Complete has helped reduce alerts, so I cannot provide specific details about it.
SentinelOne Singularity Complete has helped free up our staff for other projects and tasks because we use the SOC with SentinelOne, allowing them to handle all first-line defense on detections.
We do not track the reduction in our organization's Mean Time to Detect (MTTD).
Similarly, we do not track the reduction in our organization's Mean Time to Respond (MTTR).
My advice to others considering SentinelOne Singularity Endpoint is to ensure that you understand what is covered by support and their SLO targets. I would rate this review as a 9 out of 10.