Reviews from AWS customer

48 AWS reviews

External reviews

187 reviews
from and

External reviews are not included in the AWS star rating for the product.


5-star reviews ( Show all reviews )

    Rakesh Das

Unified cloud security has reduced alert fatigue and improves response with AI-driven protection

  • April 19, 2026
  • Review from a verified AWS customer

What is our primary use case?

I have been using SentinelOne Singularity Cloud Security for the last two years.

My main use case for SentinelOne Singularity Cloud Security is Cloud Security Posture Management, cloud data security, and unified visibility.

A specific example of how I use SentinelOne Singularity Cloud Security for cloud data security management is with cloud object storage such as Amazon S3.

I continuously monitor and audit my environment for misconfigurations as part of my main use case for SentinelOne Singularity Cloud Security.

What is most valuable?

The best features SentinelOne Singularity Cloud Security offers in my experience are cloud Open-Sip Security Engine and a very tight expert path, as well as AI-powered runtime protection. This feature provides clear evidence of exploitability, allowing security teams to focus on fixing critical issues rather than chasing noise and false positives. It uses behavioral AI to detect ransomware, zero-day exploits, fileless attacks, and NDR attacks.

For visibility, SentinelOne Singularity Cloud Security has a Singularity Data Lake, where telemetry from cloud workload endpoints identifies into a single repository for rapid querying and analysis. It also has Graph Explorer, which visually maps the relationships between cloud assets, endpoints, and identities to help analysts understand the blast radius and root cause of the incident. It correlates related events into a single storyline, providing full historical context for deeper forensic analysis.

SentinelOne Singularity Cloud Security positively impacts my organization by reducing alert fatigue and decreasing false positives. The platform allows security analysts to focus strictly on actionable, verified risk rather than manual triage. It also provides faster response times, helping my organization see a reduction in mean time to respond and mean time to detect. It includes autonomous resolutions and eliminates blind spots, providing unified visibility across multi-cloud environments, endpoints, and enterprise risk, reducing the likelihood of major security incidents.

What needs improvement?

In terms of improvement for SentinelOne Singularity Cloud Security, users and industry analysts identify several areas where the platform can be enhanced, including administrative setup experience and operational tuning and performance.

The user interface of SentinelOne Singularity Cloud Security is quite good. I do not have any additional improvements needed for SentinelOne Singularity Cloud Security that I have not already mentioned.

For how long have I used the solution?

I have been working in my current field for two years.

What do I think about the stability of the solution?

SentinelOne Singularity Cloud Security is very stable.

What do I think about the scalability of the solution?

SentinelOne Singularity Cloud Security's scalability is quite good, as it is very scalable.

How are customer service and support?

I rate the customer support for SentinelOne Singularity Cloud Security a ten out of ten.

What other advice do I have?

I observe an approximate 88% reduction in mean time to respond as a specific metric around the reduction in false positives and response times.

I chose a rating of ten out of ten for SentinelOne Singularity Cloud Security because of its autonomous threat detection and response, comprehensive visibility, operational efficiency, and lightweight performance. It also demonstrates proven industry leadership.

SentinelOne Singularity Cloud Security's unified platform experience has helped streamline my security operations, functioning as a single pane of glass. My users appreciate having one source of truth for endpoints and cloud workloads, such as virtual machines and containers across AWS and other clouds. It has verified exploit paths, not just listing vulnerabilities but identifying which ones are actually reachable and exploitable by an attacker, helping my team focus only on high-priority risks.

I use Purple AI for threat investigations, and it is a game-changer.

SentinelOne Singularity Cloud Security's runtime protection is quite good in terms of adaptability to new and unknown threats compared to other solutions I have used.

It is significant for my team to have built-in integrations that unify various aspects of cloud security, resulting in superior threat detection and faster response, along with improved operational efficiency and security posture.

Drift detection significantly impacts my organization's ability to detect unexpected process behavior in containerized environments by reducing response times. The system can automatically share information and responses across different aspects to improve incident response time significantly. The automation of tasks and built-in integration enables automated compliance audit and risk remediation, reducing manual efforts and human error in managing security configurations.

SentinelOne Singularity Cloud Security drastically reduces the mean time to remediate for cloud incidents by shrinking investigation and response time from hours to seconds or minutes. The platform offers an autonomous AI-driven approach.

We measure the time savings in terms of SecOps operations achieved through SentinelOne Singularity Cloud Security by focusing on metrics, where automation reduces manual investigation and expedites incident response time. My organization frequently achieves significant efficiencies, with some customers achieving a 95% reduction in mean time to detect and an 88% reduction in mean time to respond. The reduction of false positives by using AI contextualized alerts allows teams to spend less time investigating non-malicious findings. The verified exploit paths feature helps my team prioritize vulnerabilities with a critical exploitable route, reducing time spent patching non-critical issues.

I advise others looking into using SentinelOne Singularity Cloud Security to prioritize the visibility feature, utilize the AI-driven Purple AI for cross-environment threat analysis, and adopt a least-privilege IAM model to maximize the security impact.

SentinelOne Singularity Cloud Security is a recognized Singularity Cloud system and a premier cloud-native application protection platform, heavily emphasizing autonomous and AI-driven protection over manual, policy-based detections. I rate this product ten out of ten.

Which deployment model are you using for this solution?

Private Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?


    Akshay Sankpal

Excellent defense, minimal performance impact, and great customer service

  • January 06, 2025
  • Review from a verified AWS customer

What is our primary use case?

I personally use this for infrastructure security purposes because it provides alerts for any threat detection or vulnerability detection in my infrastructure. This ensures that these issues are addressed promptly.

How has it helped my organization?

It has helped us a lot with security practices which are supported by the industry benchmarks. The security tools and policies are regularly updated based on new evidence or changing threat landscapes.

Furthermore, after SentinelOne Singularity Cloud Security was deployed in our system, it provided quick alerts. Previously, tools did not offer fast notifications in case of incidents. SentinelOne Singularity Cloud Security delivers alerts in seconds or milliseconds. It connects directly with my dashboard. I can see the issue. They also provide critical documentation, helping me address issues.

It has improved our risk posture significantly. The risk posture improved from 60% to 70% to 90% to 95%. We have better control over the risk posture.

It has reduced our mean time to detect. Previously, it took me around ten to fifteen minutes, but with SentinelOne Singularity Cloud Security, it takes around seven to eight minutes to resolve an issue. There is often a 60% to 70% reduction. It has also reduced our mean time to remediate by about 45%.

What is most valuable?

Its performance impact on the systems is low, which means there is a minimal impact on system performance compared to traditional antivirus solutions.

Another valuable feature is the excellent defense mechanism against ransomware, including rollback features. Their managed service for 24/7 monitoring of the infrastructure for any threats and risks is also valuable.

It is easy to use. A new person can easily understand what SentinelOne does by checking the dashboard. It has an intuitive dashboard and streamlined processes, making it user-friendly for security teams like us.

What needs improvement?

From my personal experience, the alerting system needs to be faster. If something happens in our infrastructure, the alert appears on the dashboard, but I have to log in to the dashboard and refresh it. I would prefer it to provide better alerting and notifications so that I can resolve issues on priority.

For how long have I used the solution?

I have been using the solution for 1.5 years.

What do I think about the stability of the solution?

I personally did not find any lagging issues or other issues. It is perfect.

What do I think about the scalability of the solution?

It is scalable. I would rate it a nine out of ten for scalability.

How are customer service and support?

They provide excellent customer service, coming to calls very quickly. Their information and technical knowledge are excellent with no comparison to other products I have used.

Which solution did I use previously and why did I switch?

We previously used an antivirus product.

How was the initial setup?

The initial setup is quite easy. Their customer support team was also there during deployment. They were knowledgeable, and it took about three to four days to complete deployment and testing.

Its maintenance is handled by SentinelOne. They update it regularly.

What about the implementation team?

We only took help from the PingSafe customer support team for deployment, mostly to address any issues. Four people were more than enough.

What other advice do I have?

I have not found any other solution to be this helpful. After its deployment, I feel totally secure. Everything works smoothly, and I do not need to look into any part. I am tension-free.

I would rate SentinelOne Singularity Cloud Security a ten out of ten.


    Akshay Bhosale

AI-powered threat detection secures cloud environments in real-time

  • December 19, 2024
  • Review from a verified AWS customer

What is our primary use case?

Our primary use case is for security purposes. It is deployed on our cloud to handle our security threat detections. It scans our infrastructure to recognize security issues, detect attacks, and provide protection.

How has it helped my organization?

SentinelOne offers an intuitive dashboard to streamline and set up processes. It is user-friendly for security and InfoSec teams.

It helps with regular compliance and transparency. They provide a clear rationale for security practices, which helps in gaining stakeholder's trust. The data-driven approach aligns with compliance framework requirements. I also see a reduction in reliance on human judgment.

It has reduced our mean time to detect by 30% to 40%. There is about a 20% to 30% reduction in the meantime to remediate. In case of any threat, we get alerted within milliseconds. It provides me with everything I need.

It scans my infrastructure very well and finds any issues.

What is most valuable?

The features that stand out are threat detection using advanced artificial intelligence and machine learning, helping to identify and respond to threats in real-time.

Additionally, the extended detection and response (XDR) provides deep visibility and unified security across our endpoints, network, and cloud environments.

What needs improvement?

The areas with room for improvement include the cost, which is higher compared to other security platforms. The dashboard can also be laggy.

For how long have I used the solution?

I have been using the solution for about one year.

What do I think about the stability of the solution?

The solution is stable. I would rate it a nine out of ten for stability.

What do I think about the scalability of the solution?

It is scalable. I would rate it an eight out of ten for scalability.

How are customer service and support?

The technical support is excellent. I would rate them a nine out of ten.

Which solution did I use previously and why did I switch?

We did not have any similar solution previously. We used AWS services such as GuardDuty and CloudTrail.

By implementing SentinelOne Singularity Cloud Security, we wanted AI-powered scanning and threat detection. SentinelOne stands out due to its ability to provide alerts and documentation without needing to continuously monitor the services. Everything is centralized. It alerts me through an email or a notification if something is happening in our infrastructure. I can look into it and see what I need to do.

How was the initial setup?

It is deployed on the cloud. It took about four days to implement it.

Its maintenance is taken care of by SentinelOne.

What about the implementation team?

Initially, 8 people were involved in deploying the solution. We have about 13 people using this solution.

What was our ROI?

The implementation of the solution has resulted in a saving of time and resources by around 40%.

What's my experience with pricing, setup cost, and licensing?

SentinelOne is quite costly compared to other security platforms. I would rate it an eight out of ten for costliness.

What other advice do I have?

I would recommend this solution to other users because of its security.

Overall, I would rate SentinelOne Singularity Cloud Security a ten out of ten.


    AmitVerma3

Highly effective with centralized security insights and real-time detection and response

  • December 17, 2024
  • Review from a verified AWS customer

What is our primary use case?

I use SentinelOne Singularity Cloud Security for security purposes. It is deployed in my cloud infrastructure, providing me with a main dashboard that allows me to monitor my infrastructure. It helps identify vulnerabilities, ransomware attacks, and other threats. Essentially, I use it to enhance security.

By implementing this solution, we wanted to prevent ransomware and DDoS attacks and have 24/7 threat monitoring of our infrastructure.

How has it helped my organization?

SentinelOne Singularity Cloud Security has helped us implement effective security measures to reduce risk. It has also had an impact on key performance indicators, security metrics, the false positive rate, the mean time to detect, and the mean time to respond.

Before SentinelOne Singularity Cloud Security, we had to use AWS services like GuardDuty and CloudTrail, or WAF in AWS. We had a console, but there was no alerting system. SentinelOne Singularity Cloud Security collects all the information from GuardDuty, CloudTrail, WAF, and other AWS services and organizes security insights into a single, comprehensive dashboard. It also provides us with the best practices and documentation to resolve issues.

We were able to realize its benefits immediately. It has reduced false positives by 30% to 40%.

SentinelOne Singularity Cloud Security is a trustworthy product. Since its implementation, I have confidence in the security of our infrastructure. It detects everything. I have a good overview of our infrastructure.

SentinelOne Singularity Cloud Security has reduced our mean time to detect by 40% to 50%. It has reduced our mean time to remediate by 60%.

What is most valuable?

The most valuable feature of SentinelOne Singularity Cloud Security is its advanced AI and machine learning capabilities, which allow it to identify and respond to threats in real time.

Furthermore, the user interface is intuitive, making it easy to understand even for those unfamiliar with cloud technology. This ease of use extends across the dashboard and overall user experience.

What needs improvement?

For SentinelOne, improvements could be made in managing Internet dependency as cloud-based operations can pose challenges in environments with limited connectivity.

Additionally, integration with certain third-party tools or legacy systems might require extra effort.

Its features may be overwhelming for smaller organizations with less complex security needs.

For how long have I used the solution?

I have been using SentinelOne Singularity Cloud Security for two years.

What do I think about the stability of the solution?

I would rate the stability an eight out of ten. Sometimes, I feel the dashboard is a bit laggy.

What do I think about the scalability of the solution?

It is scalable, and I would rate it a nine out of ten for scalability.

We have multiple locations and departments. In my team, there are about 22 users working with this solution from different locations.

How are customer service and support?

The technical support is highly knowledgeable and reliable in security matters. I would rate their support a nine out of ten.

Which solution did I use previously and why did I switch?

Before using SentinelOne, I used AWS-managed security tools like WAF and GuardDuty. I find SentinelOne superior due to its real-time detection and mean time to remediate threats.

How was the initial setup?

Its deployment was easy. We had the SentinelOne team on the call, making the process smooth and easy. It took us about three days.

I do not have to do any maintenance. The maintenance is taken care of by SentinelOne. When there are any maintenance activities, they send us an email about the time. They usually have maintenance activities on a quarterly basis.

What about the implementation team?

SentinelOne's team assisted us during the deployment. We had seven people involved.

What was our ROI?

Using SentinelOne has saved me both time and money. Before its deployment, it took one to two hours to detect or resolve issues, whereas now, it only takes ten to twenty minutes.

What's my experience with pricing, setup cost, and licensing?

SentinelOne is relatively cheap. If ten is the most expensive, I would rate it a seven.

What other advice do I have?

I would definitely recommend SentinelOne Singularity Cloud Security for infrastructure security. I would rate the solution a ten out of ten.


    Prathmesh Chavan

Maximize security monitoring with adaptable threat detection

  • December 03, 2024
  • Review from a verified AWS customer

What is our primary use case?

I have experience in both cloud and developer roles. In my cloud infrastructure role, I focused on the infrastructure itself, not the application level. We deployed SentinelOne Singularity Cloud Security across our cloud and data center environments for security purposes. This tool provided alerts and best practice recommendations, including vulnerability notifications. I would then use the Singularity console to address any issues promptly, which significantly reduced our mean time to resolution.

How has it helped my organization?

SentinelOne Singularity Cloud Security has an intuitive dashboard and streamlined setup process, making it user-friendly for security teams.

It categorizes alerts into four levels: critical, high, medium, and low. Singularity Cloud Security automatically prioritizes security concerns, such as ransomware attacks or best practices, eliminating the need for manual intervention and presenting the most urgent alerts.

SentinelOne Singularity Cloud Security is important because its reporting includes proof of exploitability. This is very helpful for engineers as it provides alerts, identifies areas needing attention, and directs us to the relevant documentation.

The benefits of SentinelOne Singularity Cloud Security were immediately apparent after deployment in our data center and cloud environment.

SentinelOne Singularity Cloud Security helps reduce false positives and improves system accuracy through machine learning. The detailed alerts aid in investigating potential threats, enhancing our security posture.

SentinelOne Singularity Cloud Security reduces our mean time to detect.

What is most valuable?

SentinelOne Singularity Cloud Security offers valuable scalability suitable for organizations of all sizes, from small businesses to large enterprises. Its comprehensive ransomware protection includes rollback features and 24/7 threat monitoring, with managed services providing continuous monitoring and threat hunting.

What needs improvement?

While SentinelOne Singularity Cloud Security offers robust protection, its cost could be a barrier for some users. Additionally, compatibility issues may arise with older operating systems and legacy environments. Organizations with limited internet connectivity might also face challenges due to the cloud-based nature of the platform.

The Singularity Cloud Security console is experiencing delays in clearing resolved issues, which can take over an hour to be removed from the display.

For how long have I used the solution?

I have been using SentinelOne Singularity Cloud Security for about two years.

What do I think about the stability of the solution?

Sometimes, I experience lag issues with SentinelOne Singularity Cloud Security, which might be related to my laptop or Internet connection.

What do I think about the scalability of the solution?

SentinelOne Singularity Cloud Security scales well, making it suitable for organizations of all sizes, from small enterprises to large businesses.

How are customer service and support?

Customer support is knowledgeable about the company's software and operating systems, responding quickly within two to four minutes.

Which solution did I use previously and why did I switch?

While GuardDuty and CloudTrail offer some overlapping functionalities with SentinelOne Singularity Cloud Security in cloud environments, SentinelOne provides a more comprehensive and integrated approach to cloud security.

How was the initial setup?

The initial setup was somewhat straightforward but took about three to four days due to the extensive infrastructure involved. Testing added more time to the process.

What about the implementation team?

Our team of six or seven collaborated with a third-party installer and SentinelOne's technical support team.

What's my experience with pricing, setup cost, and licensing?

While SentinelOne Singularity Cloud Security offers robust protection, its high cost may be prohibitive for small and medium-sized businesses.

What other advice do I have?

I rate SentinelOne Singularity Cloud Security ten out of ten.

SentinelOne manages the maintenance of Singularity Cloud Security.


    Neeraj Arde

Has significantly strengthened our security posture

  • November 12, 2024
  • Review from a verified AWS customer

What is our primary use case?

We use SentinelOne Singularity Cloud Security to maintain security best practices. The platform alerts us to security issues, ranging from low to critical severity, based on our infrastructure.

We chose SentinelOne Singularity Cloud Security for its targeted vulnerability recommendations and best practice guidance, which allow us to address alerts effectively and maintain a secure infrastructure.

How has it helped my organization?

SentinelOne Singularity Cloud Security is user-friendly and easy to understand.

SentinelOne Singularity Cloud Security's evidence-based reporting for helping prioritize and solve the most important cloud security issues is excellent.

The exploitability proof in reports is crucial, enabling me to pinpoint issues and solutions. Without it, identifying vulnerabilities and applying fixes would be impossible. The system alerts me to security events, pinpointing the problem's location with resource and account IDs. This detailed information allows for rapid resolution, saving valuable time.

Upon joining the company, the user interface was not very user-friendly. However, over time, upgrades were introduced, such as more issue resolution documentation and best practices, which enhanced the security of our infrastructure. I realized the benefits of SentinelOne Singularity Cloud Security within five months.

SentinelOne Singularity Cloud Security has significantly strengthened our security posture. Previously, we relied on AWS-managed security alarms, which provided a limited and reactive approach to threat detection. Singularity Cloud Security offers a more proactive and comprehensive solution, enhancing our ability to identify and respond to potential threats.

SentinelOne Singularity Cloud Security has reduced our mean time to detect by five to ten minutes.

SentinelOne Singularity Cloud Security allows us to complete remediation in five minutes.

What is most valuable?

The most valuable feature is the easy-to-understand user interface, which allows even non-technical users to comprehend and resolve issues. Additionally, the solution provides highly useful recommendations.

What needs improvement?

To enhance the notification system's efficiency, resolved issues should be promptly removed from the portal. Currently, these issues take two to three hours to be removed, creating unnecessary clutter and potentially delaying the identification of new issues.

For how long have I used the solution?

I have been using SentinelOne Singularity Cloud Security for almost two years.

What do I think about the stability of the solution?

I would rate the stability of SentinelOne Singularity Cloud Security nine out of ten.

What do I think about the scalability of the solution?

I would rate the scalability of SentinelOne Singularity Cloud Security ten out of ten.

How are customer service and support?

Customer service and support are excellent. They respond promptly, and the technical support is knowledgeable and helpful with any issues we face.

Which solution did I use previously and why did I switch?


How was the initial setup?

The initial setup took approximately one week due to the testing phase. It went smoothly with the team's collaboration.

What about the implementation team?

I was present with my team during the deployment process, but I did not personally deploy it.

What other advice do I have?

I would rate SentinelOne Singularity Cloud Security ten out of ten.

Our organization has multiple departments, but only five individuals have access to Singularity Cloud Security.

Singularity Cloud Security's maintenance is handled by SentinelOne.

From a security standpoint, SentinelOne Singularity Cloud Security is excellent, and I highly recommend it.


    Andrew W

Tells us about vulnerabilities as well as their impact and helps to focus on real issues

  • August 29, 2024
  • Review from a verified AWS customer

What is our primary use case?

We use it for a couple of use cases. The biggest one we use it for is to protect our AWS environment, and it does a couple of functions for us and our whole development. It scans all the code in our GitLab or our code repository and looks for any hard-coded passwords or keys or any insecurities. It checks if we have any old deprecated components within our software and points that out.

There are a couple of gates that we can set up. When we are pushing the code out of the repos into AWS, it finds any high-severity vulnerability. This is configurable, but we have critical, high, and medium severities. If it finds any, it blocks the push and puts some notes in for the developers to go in to remediate the issue before they can push the code into AWS. Let us assume the code is good in GitLab and gets over to AWS. It then does a couple of things on the AWS side. It looks at the overall infrastructure and how things are configured. There may be things in AWS that are misconfigured or old components that were manually built or deployed without going to GitLab. It points them out.

How has it helped my organization?

I have been very happy with the evidence-based reporting. It is not just theoretical. It scans the code or looks at the AWS environment and pulls back the details that tell us that this is a vulnerability. We have a good understanding of why it is a highly-rated vulnerability. It makes it much easier to prioritize and then go through and remediate the issue.

Agentless vulnerability scanning has been very good. It pulls back quite a bit of information that is actionable by our team.

Singularity Cloud Security includes proof of exploitability in its evidence-based reporting. That is critically important because especially in large environments, when you run scans or use the vulnerability scanning tool, you might be inundated with results. It takes a long time for analysts to go back through and validate whether it is a true positive or a false positive. Singularity Cloud Security can eliminate a lot of false positives or almost all of them, and we can focus on something that is a true issue, as opposed to wasting our time and resources.

The Offensive Security Engine is doing the attack path management. That is one of the most critical features to us because it tells us that we have this misconfiguration here, or we may have a secret or some vulnerability here. It tells us about the impact and how an attacker could exploit that to gain persistence in our environment and install data. We have a true impact of why this is important and why we need to fix it. With scanners like Rapid, Qualys, and others, we get the credentials and we get a scan, but then we spend an inordinate amount of time looking through reports and trying to figure out:

  • Where do we spend our time?
  • What do we prioritize?
  • What is remediated?
  • What is it that we can remediate?
  • What is it that we can take action on and make an improvement in the environment?

It is very frustrating when you are spending hours only to run down something and realize it is a false positive, and there is nothing you can do to make a positive impact. Eliminating all those false positives really helps us.

We have had very good luck with the IaC. For us, it is hugely valuable because we can catch things very early in the process before they get promoted into production. In case something flips through or escapes, it still helps you to find it.

We started seeing its benefits literally the day after deployment. The only reason I say the day after is because we ended up working on it kind of late in the afternoon. We got things set up, and it took a few hours for results to start populating, but its benefits were very apparent when we started looking through the reports and dashboards.

Singularity Cloud Security significantly helped reduce the number of false positives we deal with. The biggest aspect for us is allowing the security and development teams and DevOps to be much more efficient. As opposed to spending 80 hours going through some big reports, we are able to cut that down to a fraction of the time and make a positive impact on the environment. We are not chasing a bunch of dead ends.

It has made a great impact on the risk posture. We are also able to look at the trends over time in terms of where we started and what we remediated. You can see the environment getting more secure as we keep knocking down vulnerabilities.

Our mean time to detect is much faster. It is a much lower number there. There has been a significant change in the number of vulnerabilities remediated or per hour of investment from the engineering and security teams. By implementing this tool, we are able to do a lot more with the same team size and remediate things much faster than before.

It has made it much easier for these disparate teams to have the conversation in terms of what needs to be prioritized and fixed, and then it has given a lot more information. It eliminates some of the he said, she said, or some of the frustration that can happen between different teams because one team is looking at a tool they are familiar with and the other team has a different tool. Historically, there were some disagreements in terms of what issues exist in the environment and where we should spend our time in terms of trying to make improvements and remediate.

What is most valuable?

Our favorite feature is attack path management. If you have an S3 bucket that is configured to be publicly accessible, it will look and inform you that it is publicly accessible. If someone gets in this bucket, they could ultimately traverse, get into this RDS, and do something negative or detrimental to the environment there. You not only get to know about vulnerabilities and misconfigurations but also some of the actual impacts of having these vulnerabilities. It is not just a raw data dump.

So far, it has been very easy to use. It gives very rich information or a lot of details about the findings. It has a lot of links to go back into GitLab or into AWS to validate the CDF configuration, and then it gives a lot of guidance for remediation.

Standing it up was pretty straightforward. We did get assistance from SentinelOne SE at the time of the trial to ensure that everything was configured and working correctly.

What needs improvement?

Looking at all the different pieces, it has got everything we need. Some of the pieces we do not even use. For example, we do not have Kubernetes Security. We are not running any K8 clusters, so it is good for us.

Overall, we find the solution to be fantastic. There can be additional education components. This may not be truly fair to them because of what the product is going for, but it would be great to see additional education for compliance. It is not a criticism of the tool per se, but anything to help non-development resources understand some of the complexities of the cloud is always appreciated. Any additional educational resources are always helpful for security teams, especially those without a development background.

For how long have I used the solution?

I have been using this solution for six months.

What do I think about the stability of the solution?

We have not had any issues with stability. It has been solid on that front.

What do I think about the scalability of the solution?

We are not huge, so we have not run into any sort of scalability problems at all. We are running only six or seven subscriptions in AWS. Our bill in AWS is less than 20K a month, so it is not huge.

How are customer service and support?

I have talked to SentinelOne support multiple times, but not on the cloud-native security front. I cannot add anything on that side.

Which solution did I use previously and why did I switch?

I have not used any other tool at this company. In the past, I have used some different tools.

How was the initial setup?

It was very easy for us with one exception. We had a mono repo, and we worked it out with the SentinelOne security engineering team. We got some direction for them in terms of how to do some of the code-blocking configuration, but it was a pretty straightforward and quick setup.

It took us three weeks maybe, but it was not like we spent three weeks heavily. We did it slowly. We did most of the deployment in a couple of hours, and then we had some check-in meetings over the next few weeks to go through and just check on it, become familiarized with the system, and then ask questions. The initial deployment took less than a day and then learning, discovering, and getting familiar with it took us a few weeks.

It does not require any maintenance from our side. We may have some sort of maintenance to do. For example, we are planning to acquire assets from another institution. They are on-prem, so we will have to build up their AWS environment. Once we build out that environment, we may need to make some changes in SentinelOne so that it picks up those new environments. That is a guess. We have not done it yet.

What about the implementation team?

We literally did it with SentinelOne SE. They provided all the setup work for us. We did not pull in a third party.

What's my experience with pricing, setup cost, and licensing?

We found it to be fine for us. Its price was competitive. It was something we were happy with. We are not a Fortune 500 company, so I do not know how pricing scales at the top end, but for our cloud environment, it works very well.

Which other solutions did I evaluate?

We did look at Wiz, Orca Security, and Palo Alto's Prisma. We also looked at Lacework and ultimately settled on SentinelOne for a couple of reasons.

We did like the functionality provided by Palo Alto, but the way their licensing worked was frustrating, to say the least, and the cost was fairly high. We found it unaffordable.

Lacework was still at an early stage. We did not feel that they provided all the functionality we needed, so we did not feel the confidence there.

Wiz is a dominant player in the market. I have a lot of respect for them, but it did not provide all the reporting and data we needed. Especially for the price point, it was affordable for us.

In the case of Orca Security, in the previous organization, we saw some pretty glaring false positives, which turned us off on that platform.

What other advice do I have?

To new users, I would say that like any tool, you need to sit down and learn what the tool can do. Understand your objectives and then work through to make sure the tool meets your needs. It is straightforward and easy to use.

I would rate Singularity Cloud Security a ten out of ten at this point.


    Akshay Kshirsagar

Is user-friendly, reduces false positives, and improves security posture

  • May 07, 2024
  • Review from a verified AWS customer

What is our primary use case?

We're managing our cloud environment on AWS, and SentinelOne Singularity Cloud Security is assisting us as a CSPM tool. It identifies vulnerabilities in our configuration and helps prevent malicious attacks.

Our current cloud environment allows independent resource deployment by our six to eight-person team, which increases the risk of misconfiguration. To mitigate this, we implemented SentinelOne Singularity Cloud Security. This security tool generates alerts for misconfigurations, allowing us to promptly address them and maintain a strong cloud security posture.

How has it helped my organization?

Having too many resources with platform access made misconfigurations more likely. SentinelOne Singularity Cloud Security addressed this by helping us configure everything according to best practices, helping improve our security posture.

SentinelOne Singularity Cloud Security is easy to use.

Evidence-based alerts help us mitigate the priority issues that are detected.

The proof of exploitability in evidence-based reporting is helpful.

The offensive security engine strengthens our organization's security posture by validating potential attacker paths and prioritizing vulnerabilities with the highest likelihood of being exploited in a breach.

Infrastructure as Code facilitates the identification of pre-production issues within our Cloud Formation Templates and Terraform configurations.

SentinelOne Singularity Cloud Security has been instrumental in ensuring our strong cloud security posture, effectively helping us manage and mitigate risks. SentinelOne Singularity Cloud Security helped our team reduce the number of false positives.

SentinelOne Singularity Cloud Security plays a key role in strengthening our risk posture. By providing alerts, it assists both our information security and security assessment teams in identifying and mitigating potential threats, ultimately improving our overall security position.

It has improved our mean time to detection by 30 percent and effectively reduces our average time to resolve incidents. By providing valuable information, SentinelOne Singularity Cloud Security empowers our team to quickly diagnose and rectify problems.

It has improved the collaboration of our cloud security application developers and AppSec teams.

SentinelOne Singularity Cloud Security has helped save engineering time by 50 percent. 

What is most valuable?

SentinelOne Singularity Cloud Security offers security solutions for both Kubernetes and CI/CD pipelines. It helps with vulnerability remediation, ensuring timely alerts for misconfigured resources, so we can address security issues efficiently.

What needs improvement?

While SentinelOne Singularity Cloud Security offers real-time response, there is room for improvement in alert accuracy. We've encountered instances where misconfigurations created by teammates were not flagged promptly by SentinelOne Singularity Cloud Security, leading to downstream issues.

For how long have I used the solution?

I have been using SentinelOne Singularity Cloud Security for one year.

What do I think about the stability of the solution?

I would rate the stability of SentinelOne Singularity Cloud Security nine out of ten.

What do I think about the scalability of the solution?

I would rate the scalability of SentinelOne Singularity Cloud Security nine out of ten.

How are customer service and support?

The technical support is helpful.

How would you rate customer service and support?

Positive

How was the initial setup?

SentinelOne Singularity Cloud Security's team clearly explained the implementation process, which our team of three was then able to complete in just one week.

What's my experience with pricing, setup cost, and licensing?

SentinelOne Singularity Cloud Security falls within the typical price range for cloud security platforms.

What other advice do I have?

I would rate SentinelOne Singularity Cloud Security ten out of ten.

Our organization has over 35 members across various teams, each utilizing SentinelOne Singularity Cloud Security according to their specific needs.

No maintenance is required on our end.

I recommend SentinelOne Singularity Cloud Security to others. It has done a great job of improving our security posture.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?


    Nayan More

Cost-effective, identifies vulnerabilities in the infrastructure, and saves time

  • April 19, 2024
  • Review from a verified AWS customer

What is our primary use case?

We are using the solution to identify the security vulnerabilities in our AWS infrastructure. Whenever we create a new infrastructure in AWS, if there is a vulnerability, an issue is created in the SentinelOne Singularity Cloud Security console. There are different severities, such as critical, medium, and high. The product also provides solutions to resolve the issues. SentinelOne Singularity Cloud Security provides a solution document for AWS. It helps us resolve issues. We have seven to eight AWS accounts. It is all in SentinelOne Singularity Cloud Security. SentinelOne Singularity Cloud Security identifies the issues with all the accounts.

How has it helped my organization?

Our company has very strict compliance requirements for security. SentinelOne Singularity Cloud Security has helped us resolve vulnerabilities and issues using best practices. It helps us resolve the security vulnerabilities of the AWS cloud infrastructure. The compliance monitoring capabilities are helpful. The tool identifies issues quickly. It gives us the root cause of the security issues rapidly.

The evidence given by the product helps us resolve the issues. It provides a step-by-step guide to resolve issues. It helps us a lot. SentinelOne Singularity Cloud Security provides us with a lot of information. It provides us with a document of AWS. We use AWS CloudFormation. If there is an issue with AWS CloudFormation or if the code is rapidly changing, SentinelOne Singularity Cloud Security will identify the issue.

The number of false positives depends on the requirements of the clients. If the client needs something for their application and it shows as an issue in SentinelOne Singularity Cloud Security, we must contact SentinelOne Singularity Cloud Security and close the issue as an exception. The tool has reduced the false positives by 10%.

The solution helps us maintain our risk posture. We use a web firewall in AWS. If we do not have a firewall in any of the resources, the SentinelOne Singularity Cloud Security console will identify it as an issue. The tool has helped reduce the mean time to detect. We check the SentinelOne Singularity Cloud Security dashboard daily. We have a checklist. We can identify how many issues are open and how many issues are closed. It helps us reduce the time to identify the issues and open vulnerabilities. SentinelOne Singularity Cloud Security has helped us reduce our workload and time by 50% to 60%.

SentinelOne Singularity Cloud Security helps reduce our mean time to remediate by 70% to 80%. The product reduces workload and time. It is very important in every organization to reduce time and find vulnerabilities. SentinelOne Singularity Cloud Security also provides us with solutions to the issues. Every organization must have a tool like SentinelOne Singularity Cloud Security. I will recommend the product to others.

What is most valuable?

The SentinelOne Singularity Cloud Security team identifies issues when we create the infrastructure. Within two to three hours, they create an issue in the SentinelOne Singularity Cloud Security console. It helps us resolve the vulnerabilities during the creation of the infrastructure. SentinelOne Singularity Cloud Security provides us with documents on how to resolve issues with the infrastructure. It saves our time in identifying issues. Integration with our cloud environment was straightforward.

What needs improvement?

Based on our application requirements, we discussed some improvement points with the SentinelOne Singularity Cloud Security team. However, after the new updates, what we asked for was not implemented. The exceptions we requested from the SentinelOne Singularity Cloud Security team were not included in the console. When we request any changes, they must be reflected in the next update.

For how long have I used the solution?

I have been using the solution for two years.

What do I think about the stability of the solution?

The product is stable. I rate the stability a ten out of ten.

What do I think about the scalability of the solution?

We have 12 users, including internal users and clients. I rate the scalability a nine out of ten.

How was the initial setup?

The solution is deployed on the cloud. The deployment takes a few days. Our cloud team and the SentinelOne Singularity Cloud Security team were involved in the deployment process. We need two to three people for the deployment. The tool does not require any maintenance.

What about the implementation team?

I am satisfied with the technical support.

What was our ROI?

We save a lot of time identifying vulnerabilities. The product gives us the issue and the solution. It reduces our time and workload.

What's my experience with pricing, setup cost, and licensing?

The tool is cost-effective.

What other advice do I have?

The product is easy to use. My colleague provided me with a KT of the tool. I could learn to use it in two to three days. I understood how to check and resolve issues and segregate them into different severities. The ease of use is very helpful.

Overall, I rate the tool a ten out of ten.


    MOHITH PULIVENDULA

Cloud misconfigurations are managed effectively and response times have improved significantly

  • April 08, 2024
  • Review from a verified AWS customer

What is our primary use case?

In its all-in-one aspect, we started with Cloud Security Posture Management at the beginning and then added the Offensive Security Engine, Vulnerability Management of CDR. We also use it for compliance.

By implementing this solution, we wanted an alerting mechanism and detection of any deviation from our current configuration. We also wanted visibility into Kubernetes and AWS cloud. We wanted something that continuously monitors and gives us updates so that we can take action.

How has it helped my organization?

We have an overview of our compliance status. We check on a weekly or monthly basis where we are with respect to various compliance standards.

Its dashboard is quite good. We can select any resource and go to any details we want. We have a visual representation of our assets and how they are connected.

I like the granularity of access. We can give read-only, admin, or other types of access to team members based on their roles.

It provides an option for auto-remediation, but we are not leveraging that. However, we are using the exploit information to check what they saw versus what we are seeing. It helps to be able to see their evidence.

It includes proof of exploitability in its evidence-based reporting. This is very important for us. We can validate if something is false positive or not only if we have any evidence from the findings. Having the evidence for every issue helps us prioritize the findings.

Offensive Security Engine has helped to clear a lot of vulnerabilities in the past. Through the dashboard, we could see all the metrics related to public exposure and misconfigurations. We have a lot of services in our cloud, and they were very hard to track. It solves that problem for us. 

Our time to detect and respond has improved drastically. If a misconfiguration happens, we gain visibility quickly. Our mean time to detect and respond has reduced by about 50%.

It has enabled collaboration between multiple teams for implementing cloud detection and response and understanding vulnerabilities. It has saved 20% to 30% of our time.

It has been highly effective in risk mitigation. Slack and Jira integrations have been helpful for alerting and creating tickets. We also have Kubernetes integration for insights. 

What is most valuable?

The cloud misconfiguration feature and Offensive Security Engine, as well as their alerting process, are valuable. I get to customize severities or rules. The flexibility to rate a finding or category of vulnerabilities is the most interesting. 

The cloud misconfiguration feature gave us almost zero false positives. We are happy with this feature.

What needs improvement?

In version 2, a lot of rules have been deployed for Kubernetes security and CDR, which makes a lot of issues of critical severity, whereas they are not critical or of high severity. There is a mismatch of severities. They need to work on severity management. 

Alert fatigue is an issue as well. We get many alerts because of severity mismanagement. In CDR, there is no option to rescan or recheck. In cloud security, if a resource is restarting multiple times and gets a new name, we get alerts each time, leading to alert fatigue. If restarted five times, we get five alerts, which is not favorable.

For how long have I used the solution?

I have used the solution for two years.

What do I think about the stability of the solution?

It is a stable product. I would rate it a ten out of ten for stability.

What do I think about the scalability of the solution?

It is scalable. I would rate it a ten out of ten for scalability.

We are using the Enterprise plan which is the maximum that one can leverage. We are paying for all the features, but we are currently not leveraging VCS. We want to increase the usage of that.

How are customer service and support?

Their technical support is top-notch. I made friends there.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

Previously, there was no product. We relied on in-house, independent ad-hoc automations. We now have a comprehensive and all-in-one solution.

How was the initial setup?

Its deployment was easy. It was set up in less than a week.

What about the implementation team?

There were a couple of people from PingSafe and a couple of people from our side.

We are based out of Indonesia and India. The deployment was done on the cloud. We use AWS. The PingSafe team was from Bangalore, India.

Its maintenance is taken care of by the SentinelOne team. There is nothing required from us.

What was our ROI?

On the resource side, we do not have to invest much money or time into developing our own automation or tools. It has saved us more than 50% of our time.

What's my experience with pricing, setup cost, and licensing?

It is cost-effective compared to other solutions in the market.

What other advice do I have?

I recommend looking at the exact requirements and exploring options for CSPM and Offensive Security Engine. These two are a must-have. I would recommend reviewing the use case first and seeing if any other features are required. 

I would recommend this solution to others. Overall, I would rate it a ten on ten for cloud security.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Amazon Web Services (AWS)