SentinelOne Singularity Cloud Security - AI Powered CNAPP logo

    SentinelOne Singularity Cloud Security - AI Powered CNAPP

    Block attacks and secure your entire cloud with SentinelOne Singularity Cloud Security, an AI-powered CNAPP providing deep visibility and robust, real-time protection to defend your AWS environment from initial access to mission target. It unifies proactive exposure management, and real-time protection to safeguard your AWS infrastructure, workloads (VMs, containers), and data with AI-powered detection and automated response. Try Cloud Security for free!

    Ratings and reviews

    4.6
    260 ratings
    2 star
    1 star
    77%
    22%
    1%
    0%
    0%
    54 AWS reviews
    |
    206 external reviews
    External reviews are from G2  and PeerSpot .

    Filters

    Review type

    AWS Marketplace reviews
    External reviews
    Reviews (260)
    Financial Services

    Centralized Cloud Visibility and Real-Time Threat Detection with SentinelOne Singularity

    Reviewed on Jul 29, 2026
    Review provided by G2
    What do you like best about the product?
    What I like best about SentinelOne Singularity Cloud Security is its ability to provide centralized visibility across cloud workloads and continuously monitor for misconfigurations, vulnerabilities, and suspicious activity in real time. The platform helps prioritize risks based on their potential impact, making it easier to focus on the most critical issues first. I also appreciate how it integrates cloud security posture management with runtime threat detection, giving security teams better context during investigations and enabling faster response to cloud-based threats.
    What do you dislike about the product?
    I would also like to see broader native integrations with third-party cloud and security tools to streamline workflows and reduce the need for additional configuration in complex environments.
    What problems is the product solving and how is that benefiting you?
    SentinelOne Singularity Cloud Security helps solve the challenge of maintaining visibility and security across cloud environments by identifying misconfigurations, vulnerabilities, and suspicious activity from a single platform. As a SOC Analyst, it enables me to detect cloud threats earlier, prioritize the most critical risks, and investigate incidents with better context. This reduces manual effort, improves response times, and helps strengthen our overall cloud security posture.
    DeepPujara

    Centralized risk insights have improved cloud visibility and simplify multi-cloud remediation

    Reviewed on Jul 26, 2026
    Review from a verified AWS customer

    What is our primary use case?

    Our primary use case for SentinelOne Singularity Cloud Security is securing multi-cloud workloads by identifying cloud misconfigurations, monitoring risks, and improving compliance while strengthening our overall cloud security posture.

    We use SentinelOne Singularity Cloud Security to continuously assess AWS environments for security risk. It helps detect configuration issues, prioritize critical findings, and provides practical remediation guidance, allowing us to resolve exposures before they become security incidents.

    SentinelOne Singularity Cloud Security is part of our daily cloud security workflow and gives us centralized visibility across cloud resources while simplifying risk management.

    What is most valuable?

    Key features of SentinelOne Singularity Cloud Security include Cloud Security Posture Management (CSPM), cloud workload protection, risk prioritization, compliance monitoring, and unified visibility across cloud environments.

    The risk prioritization feature of SentinelOne Singularity Cloud Security has definitely made a difference in our daily workflow. Compared to some other cloud security tools we have used, SentinelOne does a better job of prioritizing risk based on potential impact instead of simply listing every finding with the same level of importance. This helps us focus on the issues that require immediate attention rather than spending time triaging low-risk alerts. In practice, it has reduced the amount of manual work effort needed to review findings.

    It makes it easier to decide what should be remediated first with SentinelOne Singularity Cloud Security, especially in large cloud environments where the number of alerts can grow quickly. We still validate critical findings before making changes, but overall, it has made our remediation process more efficient and helped the team respond faster.

    SentinelOne Singularity Cloud Security has improved our security visibility, reduced the manual effort, accelerated the remediation process, and strengthened compliance across cloud environments.

    Since using SentinelOne Singularity Cloud Security, we have reduced the time spent identifying cloud misconfigurations, improved remediation efficiency, and achieved better compliance readiness through continuous monitoring.

    What needs improvement?

    I would like to see more customizable dashboards, deeper reporting capabilities, and broader integrations with third-party cloud management platforms in SentinelOne Singularity Cloud Security. Additionally, regarding the event search feature, the power query is useful, but it has a learning curve for those new to the platform, which could be improved.

    For how long have I used the solution?

    I have been working in the observability and cybersecurity domain for over two years, gaining hands-on experience with SIEM, cloud security, endpoint protection, and security operations.

    What do I think about the stability of the solution?

    SentinelOne Singularity Cloud Security has been stable and dependable in our production environment.

    What do I think about the scalability of the solution?

    SentinelOne Singularity Cloud Security scales well as our cloud environment grows and continues to perform consistently.

    How are customer service and support?

    Our experience with SentinelOne Singularity Cloud Security's customer support has been positive. The support team is knowledgeable and responsive. I would give the customer support of SentinelOne Singularity Cloud Security a nine out of ten.

    Which solution did I use previously and why did I switch?

    We previously relied on native cloud security tools and manual security reviews.

    How was the initial setup?

    The unified platform experience of SentinelOne Singularity Cloud Security has helped streamline our security operations. One of the biggest advantages is having cloud security insights in a single platform instead of switching between multiple tools. Earlier, we often had to correlate information from different dashboards to understand what was happening, which took extra time. With SentinelOne Singularity Cloud Security, posture findings, workload security, and risk insights are available in one place. This gives everyone on the team the same view of the environment, making collaboration much easier.

    What was our ROI?

    We have seen value through fast risk identification, reduced manual effort, and improved overall efficiency.

    What's my experience with pricing, setup cost, and licensing?

    My experience with SentinelOne Singularity Cloud Security's pricing, setup cost, and licensing has been positive in that deployment was straightforward, licensing was easy to understand, and overall pricing was reasonable considering the security capabilities provided.

    Which other solutions did I evaluate?

    We evaluated other cloud security platforms provided by CrowdStrike, but we chose SentinelOne because of its unified approach and ease of management.

    What other advice do I have?

    If I had to give one piece of advice to others looking into using SentinelOne Singularity Cloud Security, I would say to start with the initial deployment, integrate your cloud accounts, review the initial findings carefully, and establish remediation priorities before expanding across all environments. I would rate this product a nine out of ten overall.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Amazon Web Services (AWS)
    reviewer2869185

    Unified cloud security has strengthened posture and now prioritizes critical misconfigurations

    Reviewed on Jul 24, 2026
    Review provided by PeerSpot

    What is our primary use case?

    SentinelOne Singularity Cloud Security primary use cases are centered on protecting cloud-native infrastructure, applications, workloads, and data. It combines multiple cloud security capabilities into a unified cloud-native application platform. Multiple use cases include Cloud Security Posture Management, Cloud Workload Protection, Containers and Kubernetes security, Cloud Infrastructure Entitlement Management, Data Security Posture Management, and Cloud Threat Detection and Response.

    In my day-to-day work, I use SentinelOne Singularity Cloud Security primarily to monitor cloud posture and workload security. A recent example was when it identified a high-risk IAM misconfiguration in our cloud environment. I investigated the findings and remediated the exposure. I also remediated the permission before it could be misused. The platform's unified visibility and prioritized risk scoring helped me resolve the issue quickly and strengthen our cloud security posture.

    What is most valuable?

    Standout features include Cloud Security Posture Management, Cloud Workload Protections, Attack Path Analysis, Cloud Security, Data Security, and AI-powered investigation in which I use Purple AI to automate investigation, correlate cloud, endpoint, and identity telemetry, summarize incidents, and reduce alerts. It also has a unified security platform that brings together cloud, endpoint, and identity security in a single console with a shared data model. This simplifies operations and enables faster incident response.

    The feature that has made the biggest difference is Cloud Security Posture Management. In my day-to-day work, it continuously monitors our cloud environment for security misconfigurations, such as overly permissive IAM roles, publicly exposed storage buckets, or missing security controls. Instead of manually reviewing cloud configurations, I receive prioritized alerts that highlight the most critical risks in the management console, and this helps me focus on remediating issues that could have the greatest security impact. I reduce manual effort and improve our overall cloud security posture.

    SentinelOne Singularity Cloud Security has improved our organization's cloud security by giving us centralized visibility across cloud assets, workloads, identities, and configurations. It helps us detect misconfigurations, prioritize critical risks, and monitor threats in real time. As a result, I have reduced manual security reviews, fixed threats faster, and strengthened our overall cloud security posture. The unified platform also simplifies security operations by consolidating multiple cloud security capabilities into a single console, improving both efficiency and compliance.

    What needs improvement?

    SentinelOne Singularity Cloud Security is a strong platform, but there are a few areas where it could improve. I would like to see more customizable dashboards and reporting so different teams can focus on the metrics most relevant to them. The initial setup and policy tuning could also be simplified, especially for organizations with complex multi-cloud environments. Additionally, expanding integrations with third-party security and DevOps tools would make it even easier to fit into existing workflows.

    A few additional improvements would further enhance the platform. The user interface could be made more intuitive, especially for first-time users, by simplifying navigation and making key findings easier to locate. The documentation is comprehensive, but more step-by-step implementation guides, best practices, and real-world deployment examples would help administrators get up to speed more quickly. From a support perspective, faster response times for complex issues and a larger library of troubleshooting articles and knowledge base content would improve the overall customer experience.

    For how long have I used the solution?

    I have been working in my current field for the last six years.

    What do I think about the stability of the solution?

    I have not experienced stability issues.

    What do I think about the scalability of the solution?

    I have not experienced scalability issues.

    How are customer service and support?

    I have not experienced issues with customer service.

    How was the initial setup?

    The initial setup and policy tuning could be simplified, especially for organizations with complex multi-cloud environments.

    What other advice do I have?

    I would start with a clear understanding of your cloud environments and security goals before deployment. Make sure cloud accounts are properly integrated, and spend time tuning policies and risk thresholds during the initial rollout to reduce unnecessary alerts. It is important to involve both your cloud and security teams, so remediation workflows are well-defined. I rate this product an 8 out of 10.

    Adaku O.

    Clear Cloud Visibility with SentinelOne Singularity Cloud Security

    Reviewed on Jul 23, 2026
    Review provided by G2
    What do you like best about the product?
    What I like most about SentinelOne Singularity Cloud Security is how easy it is to get clear visibility into what’s happening in our cloud environment. It includes intelligence capabilities that provide useful content, which helps make investigations faster and easier.

    When it comes to the user interface, navigating through alerts and insights feels straightforward and not complicated at all. It also helps bring parts of our security operations together and integrates seamlessly with the security tools we already use.
    What do you dislike about the product?
    What I least like about SentinelOne Singularity Cloud Security is that it can actually take some time to fully understand it if one is a beginner or new to it.
    .
    What problems is the product solving and how is that benefiting you?
    SentinelOne Singularity Cloud Security platform helps improve our operational efficiency and makes onboarding new customers easier and more streamlined. Overall, it strengthens our security service delivery while reducing the time and effort needed to manage multiple environments.
    Jawahar A.

    At the heart of the Singularity Platform is Singularity Cloud Security

    Reviewed on Jul 22, 2026
    Review provided by G2
    What do you like best about the product?
    Smart Threat Prevention with unified cloud protection gives us a much clearer picture, no longer a hodgepodge of information, but an integrated AI-based approach to cloud security. Everything's running smoothly and we've got a lot more visibility in our multi-cloud environments (AWS, Azure, GCP, NAS). It does away with the time-consuming task of manually sifting through alerts, so our security and engineering staff can deal with vulnerabilities more quickly. Cloud security events are detected much faster, and automated remediation improves the efficiency of the analysts and targets zero business interruption.
    What do you dislike about the product?
    This isn't just a buzzword; it's a driver based on AI. Static AI and behavioural AI can detect threats and respond autonomously at machine speed. What's more, Purple AI is an agentic AI analyst.
    What problems is the product solving and how is that benefiting you?
    It's a piece of cake to connect it to our world. It's great how it can connect with other platforms, like SIEM platforms like Splunk, SOAR platforms, and RMM tools like NinjaOne. It's not just a threat detection platform, it's so much more. It works well with ServiceNow, Zscaler, GitLab and Snyk, and makes our development and operational processes even better. You can ask it questions in natural language, and it'll carry out threat hunting as well as create short event summaries and investigation notebooks. It's like you've got another analyst who never gets tired. AI-SPM also helps us out with It's like you've got another analyst who never gets tired. AI-SPM also helps us keep an eye on our own AI pipelines and models.
    reviewer2835498

    Improved cloud threat detection and response has strengthened our security posture

    Reviewed on Jul 22, 2026
    Review provided by PeerSpot

    What is our primary use case?

    The main use cases for SentinelOne Singularity Cloud Security are protecting workloads and applications by improving threat detection, visibility, and response. We rely on it most for the monitoring of cloud environments, identifying security risks, detecting suspicious activity, and helping our security team respond quickly to potential threats.

    What is most valuable?

    The best features of SentinelOne Singularity Cloud Security are its threat detection capabilities, real-time visibility across cloud environments, and automated response features. The ability to identify suspicious activity, quickly provide context around risk, and help security teams to investigate and remediate threats efficiently stand out the most. The centralized visibility and integrations with the broader security operations also make it easier to manage cloud security from a single platform.

    The integration with our broader security operations helped to streamline workflows by bringing cloud security insights into our existing security tools and processes. This integration reduces the need to manually correlate data from multiple sources, speeds up investigations, and gives our team better context when responding to alerts. This saves time during incident triage and helps security analysts prioritize and address threats more efficiently.

    SentinelOne Singularity Cloud Security has improved our organization's security visibility and response capability by giving our team better insights into cloud risk and suspicious activity. A major benefit has been faster threat investigations and response. Our security teams can quickly understand the context of alerts and take action. It has also helped reduce manual efforts, improve consistency in security operations, and strengthen our overall cloud security posture.

    Since using SentinelOne Singularity Cloud Security, we have seen improvements in how quickly our team can identify, investigate, and respond to potential threats. Better visibility and automated security insights have helped reduce manual investigation time and improve the efficiency of our response process. While we do not have specific metrics to share, the overall impact has been faster triage, better prioritization of risk, and a more proactive approach to cloud security.

    Its AI capability provides valuable support for governance and security by helping teams to identify risk, prioritize threats, and make faster security decisions. The AI-driven insights improve visibility across cloud environments and help to reduce the manual efforts required for monitoring and investigations.

    Overall, the AI capability is accurate and reliable. The AI-generated insights generally help to prioritize real risks, reduce alert fatigue, and provide useful context for investigations.

    What needs improvement?

    SentinelOne Singularity Cloud Security is a strong platform, but there are areas where it could be improved. Adding more flexible customization options for alerts, more advanced reporting and dashboards, and deeper integration with a wider range of cloud and security tools would make the platform even more valuable.

    While there is room for improvement in areas such as customization, reporting, and integration, it has been a reliable solution that has positively impacted our cloud security.

    For how long have I used the solution?

    I have been working for the last five years.

    What other advice do I have?

    My advice would be to clearly understand your cloud security requirements and take the time to plan the deployment and integration with your existing security tools. Make use of the platform's automation, threat detection, and visibility features to get the most value. I rate this solution an eight out of ten.

    Diogo A.

    Faster Misconfiguration Detection with an Easy Purple AI Integration

    Reviewed on Jul 22, 2026
    Review provided by G2
    What do you like best about the product?
    It does a good job for a cloud workload protection platform and it helps our team with detecting misconfigurations and risks faster. Again, purple AI intergation makes the tool easier to use.
    What do you dislike about the product?
    Pricing. the tool is not cheap and a bit pricey for startups.
    Since it is a thirdparty tool, integration with especially cloud-native environment and payment is a big challenge to our clients. Most of our cloud native client would prefer to use cloud native-CWPP like config and have the billing charged once.
    What problems is the product solving and how is that benefiting you?
    Security misconfigurations are the biggest challenge, for one of our clients who run multi-cloud environment. SentinelOne singularity Cloud Security saves the day especially where cloudnative CWPP or CNAPP can not reach their multi cloud environment.
    Prince Joseph

    Unified security platform has strengthened endpoint, cloud, and ransomware protection

    Reviewed on Jul 21, 2026
    Review from a verified AWS customer

    What is our primary use case?

    My primary use case is EDR, PDP, and additional features like the AI-SIM, and I'm also using it for ransomware protection which takes care of the lateral movement part. I'm now extending that usage for cloud workload protection as well, and I'm looking at trying to detect misconfigurations or vulnerabilities in that space. I'm also trying to explore a few things around multi-cloud and how that can help us protect our workloads in those spaces.

    What is most valuable?

    The quality of the product in terms of reliability and what it offers is exceptional. It actually delivers on what it says it does. I think SentinelOne Singularity Cloud Security is a leader, and the product is built with an incredible amount of robustness. The protection that it's meant to offer is what we are actually getting.

    SentinelOne Singularity Cloud Security wins out because the partner that we have and the support that we get from the SentinelOne Singularity Cloud Security team in the country makes it quite seamless for me.

    I'm using SentinelOne Singularity Cloud Security, especially on the log aggregation side, as the point where logs from my other security products and tools are flowing in. I found that pulling logs into SentinelOne Singularity Cloud Security through the established integration methods that it supports was not very complex. We were able to achieve that with the team's help fairly quickly.

    What needs improvement?

    There are some other features that probably could be done quite well for SentinelOne Singularity Cloud Security. Some of the features like the AI-SIM, for example, should be promoted more and should be enhanced a little bit more, so I don't have to worry about the SOC part of the operation being done by a third party. SentinelOne Singularity Cloud Security should be able to leverage this far more easily. Those are areas where SentinelOne Singularity Cloud Security can do better. They also have features where you're able to do a lot of log retention. If I'm getting the logs to be retained for a year and if the log aggregation is going to be working very effectively, then I think they should be able to build on this data that they're collecting and there should be a lot more security offerings and analytics that they should be able to do.

    The unified platform experience with SentinelOne Singularity Cloud Security is not fully realized yet. There are still other products that I have which are sitting in here. The moment this one and the architecting behind this can come forward and guide us, I think there are still some more steps we need to take before we can achieve the unified experience. It is consolidating, but it's not reached that level yet.

    At the moment on the MTTR side with SentinelOne Singularity Cloud Security, it can actually have an impact after I get to the next level of integration and consolidation. Right now, my team is having to work through multiple products before they can make decisions.

    For how long have I used the solution?

    We started using SentinelOne Singularity Cloud Security about four years ago, and we've gradually gone from endpoint protection to the other modules.

    What do I think about the stability of the solution?

    Over the last few months, I don't think there was any incident that needed any escalation. It has been running quite reliably.

    What do I think about the scalability of the solution?

    The scalability part is built into the stability I mentioned. If I'm going to add new workloads, then by default, this is something that's thought of and added in. I have not faced a challenge there.

    How are customer service and support?

    The partner that we have and the support that we get from the SentinelOne Singularity Cloud Security team in the country makes it quite seamless.

    Which solution did I use previously and why did I switch?

    The one that we looked at and maybe spent a little bit more time on was Sophos. They have a new XDR solution, and we have been looking to see how that sits in or how that compares with this. We didn't look at or explore directly competing products like Fortinet or others, but I haven't explored that much. However, Sophos did come up with a good pitch.

    How was the initial setup?

    We have made purchases from the AWS Marketplace. This was done through the AWS Marketplace because we switched the entire purchase through the AWS Marketplace.

    What about the implementation team?

    We are trying to get ourselves to be a bit more mature on using that.

    What was our ROI?

    For security with SentinelOne Singularity Cloud Security, it's hard to calculate ROI, but if one needs to do a mathematical exercise, you can find ROI because we're still in business. I would say that I don't think I've identified the right way to look at the benefits on this front. Apart from the fact that this is an operational requirement, it's mandatory for compliance and security. Without this, we really cannot operate.

    What's my experience with pricing, setup cost, and licensing?

    It's somewhat on the expensive side for SentinelOne Singularity Cloud Security, but looking at where the value is and looking at the long-term relationship and how the pricing is evolving, I think right now pricing is probably at a decent value for me.

    What other advice do I have?

    We also just recently made the use of Purple AI a little bit more extensive.

    We are using SentinelOne Singularity Cloud Security, but it tends to be more for forensics or going back to analyze things. It's not real-time or runtime, but tends to be more after an incident.

    I don't think SentinelOne Singularity Cloud Security is a leader in that respect. I don't think I've seen any product that's actually doing that perfectly. I'm not sure about that. My team is probably just looking into it, but I don't know the details about that one either. We don't have an extensive deployment of containers. Some of these features I would need to check with my SOC team who have been given the AI-SIM part to look at and see what benefits they have. But some of these questions are also asking me to check with them whether they really use these features correctly or only minimally.

    At the moment, one of my objectives is not to save on time. My KPI that I have is to detect and prevent. If the tools are doing their job, then they just need to make sure that something was detected, it was handled, and there's no risk to the organization. So far, we have not had to deal with any downtime because of security. My overall rating for this product is 8.

    Which deployment model are you using for this solution?

    On-premises

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Amazon Web Services (AWS)
    reviewer2873466

    Behavioral detection has strengthened cloud workload protection and speeds incident response

    Reviewed on Jul 18, 2026
    Review provided by PeerSpot

    What is our primary use case?

    Our primary use case for SentinelOne Singularity Cloud Security is protecting cloud workloads and servers by continuously monitoring for threat detection, malicious activity, and providing automated response capabilities. We use it to provide visibility across our cloud environment, strengthen our security posture, and reduce the time required to investigate and remediate security incidents.

    What is most valuable?

    The best features of SentinelOne Singularity Cloud Security are its real-time threat detection, behavioral AI-based analytics, automated response capabilities, and comprehensive visibility across cloud workloads. The centralized management console makes it easier to investigate alerts, while the detailed telemetry helps speed up incident analysis and remediation. Overall, it provides good visibility with minimal operational work.

    SentinelOne Singularity Cloud Security has improved our organization's overall security posture by providing better visibility into cloud workloads and faster threat detection. It has reduced the time needed to investigate security alerts, enabled quicker incident response, and helped our security team manage cloud risk more efficiently. Overall, it has increased confidence in the security of our cloud environment while reducing manual effort.

    What needs improvement?

    SentinelOne Singularity Cloud Security could be improved by providing more customizable reporting and dashboards, reducing false positives in certain scenarios, and offering deeper investigation with third-party security and IT management tools. More built-in guidance for alert investigation and remediation would also help teams resolve incidents more efficiently, especially those with smaller security teams.

    Overall, SentinelOne Singularity Cloud Security is a strong security platform, but continued improvement in user experience, reporting flexibility, and integration capabilities would make it even more effective. Enhancing documentation, providing more advanced customization options, and adding more automation around routine security tasks would help organizations get more value from the platform.

    For how long have I used the solution?

    I have been using SentinelOne Singularity Cloud Security for approximately one year.

    Which solution did I use previously and why did I switch?

    We previously used a different security solution and switched to SentinelOne Singularity Cloud Security because we were looking for stronger behavior-based threat detection, faster response capabilities, better visibility, and a more centralized management experience. SentinelOne Singularity Cloud Security's AI-driven approach and automated response features provide better protection against unknown threats compared to our previous solution.

    What was our ROI?

    We have seen a positive return on investment, mainly through improved efficiencies in our security operations. SentinelOne Singularity Cloud Security has helped reduce the time required for threat investigation and response by providing automated detection, detailed context, and centralized visibility. While we do not track exact financial savings, the platform has helped reduce the workload involved in monitoring and analyzing security events, allowing the team to spend more time on high-value security activities.

    What's my experience with pricing, setup cost, and licensing?

    Our experience with SentinelOne Singularity Cloud Security pricing, setup cost, and licensing has been generally positive. The licensing model is straightforward, and the value provided by the platform's threat detection, visibility, and automated response capabilities justifies the investment. The initial setup requires proper planning and configuration to align policies with the environment, but the deployment process is manageable. Clear documentation and support resources help reduce implementation challenges.

    Which other solutions did I evaluate?

    We evaluated other security solutions before choosing SentinelOne Singularity Cloud Security, including alternatives such as Microsoft Defender for Cloud, CrowdStrike Falcon, and other cloud security platforms. We selected SentinelOne Singularity Cloud Security because of its strong AI-driven detection, behavioral analysis capabilities, automated response features, and centralized visibility, which aligned well with our security requirements.

    What other advice do I have?

    My advice to others looking into using SentinelOne Singularity Cloud Security would be to clearly define your security requirements and evaluate how SentinelOne Singularity Cloud Security fits into your existing environment before deployment. Take advantage of AI-based protection, automation features, and centralized visibility, but also spend time on proper configuration, policy tuning, and integration with your existing security tools. Organizations should also plan for user training and regular review of alerts and reports to get maximum value from the platform. I would rate this product an 8 out of 10.

    Ayman Said

    Behavioral protection has strengthened our cloud workloads and streamlines unified security operations

    Reviewed on Jul 16, 2026
    Review provided by PeerSpot

    What is our primary use case?

    We have been working with SentinelOne Singularity Cloud Security for four years.

    What is most valuable?

    The runtime protection of SentinelOne Singularity Cloud Security compares favorably to other solutions I have used in the past. The concept is not signature-based antivirus. Most traditional antiviruses work with a signature base, having a database of viruses or threats updated daily. However, next-generation solutions such as SentinelOne Singularity Cloud Security and Sophos use a non-signature-based approach that is dependent on AI and behavior analysis. It is a behavioral EDR or MDR that supports XDR technology. XDR's concept is to exchange data between other components through the network, and it is excellent because SentinelOne Singularity Cloud Security and Sophos are leaders in this area according to Gartner.

    The unified platform experience with SentinelOne Singularity Cloud Security has helped us streamline our security operations. We have implemented multiple layers of security as part of our security journey over the past five years.

    What needs improvement?

    The only aspect of SentinelOne Singularity Cloud Security that requires improvement is the response time of the support team. The support response is not optimal.

    For how long have I used the solution?

    We have been working with SentinelOne Singularity Cloud Security for four years.

    How are customer service and support?

    The response time of the support team is not the best. Based on my experience, I rate the support as a six or seven.

    Which solution did I use previously and why did I switch?

    We also evaluated Trend Micro products and were working with ESET before migrating to SentinelOne Singularity Cloud Security four years ago. Before ESET, our group was working with different EDRs or antivirus solutions. The concept of EDR was not common five or six years ago, so we migrated from traditional antivirus to next-generation EDR.

    How was the initial setup?

    During the implementation of SentinelOne Singularity Cloud Security, I faced challenges. We were evaluating SentinelOne Singularity Cloud Security, Sophos, Kaspersky, and another Japanese brand for our EDR and MDR evaluation.

    What other advice do I have?

    SentinelOne Singularity Cloud Security is a cloud-based solution, not on-premises. Currently, we are working with our workload on Azure, but it is a SaaS technology hosted on SentinelOne Singularity Cloud Security's cloud infrastructure, not on Azure or AWS.

    SentinelOne Singularity Cloud Security integrates well with other third-party tools. The antivirus is integrated with SOC solutions, and we are working with IBM QRadar. It works well because once a detection happens, any virus or threat directly shares the incident with the SOC and sends emails or opens tickets through ServiceNow or the ticketing system.

    The impact of Drift Detection on our organization's ability to detect unexpected processes is direct. Any threat or incident directly integrates with QRadar and is sent to the SOC team. The SOC team then sends emails to the concerned people in any area, application, infrastructure, or networking to manage or solve the problem and close the ticket.

    I have utilized the Advanced SIEM capabilities of SentinelOne Singularity Cloud Security, and it is easy to manage. We are subscribed with an MDR team that manages all of that and sends information directly to us to solve any problem or incident. I rate this product an 8 overall.