Autonomous AI Response and Ransomware Rollback Are Game-Changers
What do you like best about the product?
Autonomous AI response, a ransomware rollback storyline, Purple AI, SIEM solution, and data recovery—there are many SentinelOne endpoints giving the best antivirus.
What do you dislike about the product?
There’s really nothing to dislike about this product, although I do find the pricing to be a bit on the higher side. Aside from that, everything else is good.
What problems is the product solving and how is that benefiting you?
This platform offers a single dashboard to manage all endpoints and servers, making it easy to monitor everything in one place. Its storyline analysis feature is helpful, and I haven't experienced any system lag. The tool also consolidates various functions and includes ransomware rollback, which adds an extra layer of security.
Effortless Deployment and Outstanding Support
What do you like best about the product?
Easy to deploy and use. Very responsive to config changes. Support team is amazing.
What do you dislike about the product?
I have not found anything I don’t like. The platform is very user friendly.
What problems is the product solving and how is that benefiting you?
EDR and single pane of glass view of our environment.
Automation has simplified threat detection and enabled seamless hybrid deployments
What is our primary use case?
The main use cases for
SentinelOne Singularity Complete include EDR,
XDR, and NGSIEM.
SentinelOne Singulality Complete has the ability to ingest and correlate across security solutions extensively.
SentinelOne Singularity Complete seamlessly ingests logs from various other technologies besides the SentinelOne EDR platform. We have integrated with several firewalls, different firewalls. We have integrated with cloud ingestion, such as AWS and GCP, which is seamless. There are other solutions that can be integrated with SentinelOne Singularity Complete, incorporating security log ingestion.
The XDR platform helps to consolidate different security solutions.
Regarding Ranger functionality, it provides network and asset visibility and can ingest logs from network sources, capturing any threat metrics, including IOCs.
I cannot confirm if SentinelOne Singularity Complete reduces alerts as I have not worked heavily on that aspect. The system captures different telemetry from network devices.
Customers mainly use SentinelOne Singularity Complete on both public and hybrid cloud. This is advantageous, as we can use a relay agent to commit updates for computers that do not have internet access. Those telemetry can also be received, which is a clear value differentiator.
What is most valuable?
The rollback feature is the most useful feature of SentinelOne Singularity Complete. When a machine is infected, we have the option to roll back to the earliest date, providing ransomware protection. The second biggest differentiator is the hybrid implementation, which means unlike other EDRs, all machines need not be connected to the internet. We can have a local relay agent that can perform updates and upgrades to machines that are not connected to the internet directly, which is very helpful for updating air-gapped implementations.
The installation of SentinelOne Singularity Complete is very seamless. We are able to implement fresh rollouts of thousands of machines in a matter of one or two days, provided the machines are available. We are immediately able to see the telemetry and ingestions of the log taking place.
The biggest benefit for my customers is that it is autonomous, where mostly everything is automated, and the threat detection, as well as auto-remediation rules, are set up. Hence, minimum intervention is required from our side in case of known threats. I consider the automation and autonomous decision-making as the cornerstone.
What needs improvement?
Sometimes, SentinelOne Singularity Complete takes time to reflect on some machines, which could be due to poor network connectivity. However, I don't see any major problems.
It takes time for updates to reflect on the central console when putting in a new machine.
Regarding recommendations, they have acquired a company called Prompt Security, which is working on AI gateway and AI security posture management. I want to see how it gets integrated with the SentinelOne platform, and I am looking forward to what they will do with Prompt Security.
My customers have not calculated a return on investment because most purchases happen as a mandate. It is imperative for organizations to move from antivirus to EDR and XDR platforms. The decision is mostly for corporate security rather than based on a return on investment.
For how long have I used the solution?
I have been working with SentinelOne Singularity Complete for three years.
What do I think about the stability of the solution?
I have not come across big disruptions or breaches with SentinelOne Singularity Complete. Whatever known viruses exist are automatically eliminated, similar to a usual antivirus. I have not used threat hunting situations and have not been exposed to that currently.
There are not many stability issues regarding upgrades. Everything is managed automatically, so there is no user interference needed for upgrades.
What do I think about the scalability of the solution?
SentinelOne Singularity Complete is very scalable. I have seen customers scaling up to 25,000 users very easily without challenges.
How are customer service and support?
I have contacted SentinelOne support via TAC lines for understanding suspicious behavior, and they help drill down further. We get support directly from the TAC line for any false positives or to understand whether it is a true positive or false positive alert.
I would rate the support from SentinelOne Singularity Complete as an eight out of ten.
How would you rate customer service and support?
How was the initial setup?
The initial setup of SentinelOne Singularity Complete is straightforward and very easy. All we need to do is set up a tenant, create the package file, and once we install it, it automatically connects. We can set up the entire system in a matter of one hour for a large customer.
What's my experience with pricing, setup cost, and licensing?
SentinelOne Singularity Complete is not expensive; they are very aggressive when it comes to price points.
Compared to Microsoft and other competing solutions, SentinelOne Singularity Complete is very aggressive price-wise.
The cost depends on a per-device basis.
The full-fledged platform should be around $7 to $10 per device per month.
What other advice do I have?
I have had limited experience with
Purple AI, which gives copilot-features wherein I can use a pull-down menu to identify based on any IOCs present. The retrieval time is very fast. I can ask certain copilot questions, frame certain queries on the drop-down menu, and immediately see whether those telemetry match in my systems.
Predominantly, my customers buy SentinelOne Singularity Complete from us. Small customers may purchase from the AWS marketplace, but enterprise customers mostly buy through partners.
I recommend SentinelOne Singularity Complete as a good investment where you can rely on the technical support. There is always a human voice available if we get stuck somewhere, and I am very happy about the solutions and interactions we have. You are bound to have clarity when alerts come in, and you need a vendor who can answer and troubleshoot those situations and clarify what the alert is all about. If you are looking for more TAC line support for incidents, go ahead with SentinelOne Singularity Complete.
I rate SentinelOne Singularity Complete eight out of ten.
Which deployment model are you using for this solution?
Hybrid Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Inheritly powerful,and a feeling of being protected.
What do you like best about the product?
That when necessary, I don't require to be attentive to the platform. But when I need to be on it or want to learn more, the possibilities are endless. I can go as far as I want. The platform is feature-rich. The use of Purple AI and the real language searching, you can go in depth with the threats.
What do you dislike about the product?
In the beginning, there was a bit of a learning curve.
What problems is the product solving and how is that benefiting you?
It is just one step in the layered defense in depth. Granted, it is a big part. Antiviruses based solely on signatures are a thing of the past.
Great security
What do you like best about the product?
easy to use and setup the agents in your environment
What do you dislike about the product?
a little expensive, the DFIR team hasn't been useful so far
What problems is the product solving and how is that benefiting you?
keeping my environment safe