No more typing reviews! Try our Samantha, our new voice AI agent.

CrowdStrike Falcon Sandbox vs SentinelOne Singularity Endpoint comparison

Why PeerSpot?
 

Comparison Buyer's Guide

Executive SummaryUpdated on Jun 3, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
5.6
CrowdStrike Falcon Sandbox is valued for time savings in incident response, with mixed opinions on exact ROI and confidence.
Sentiment score
5.9
SentinelOne Singularity Endpoint offers cost-effective, automated security, increasing productivity and reducing incident response times while enhancing resource efficiency.
SentinelOne Singularity Complete has helped reduce my organization's mean time to detect by fifty percent.
Director, Infrastructure & Security at Dreamscape Companies
If I engage five engineers for this project and implement SentinelOne, then only one resource is needed to manage the dashboard and criticality alerts.
Business Head at Ivalue Infosolution
In comparison, other EDRs such as Microsoft Defender are quite resource-hungry, and employees often complain about laptop speed, but we do not face those issues.
Cybersecurity Product Manager at a tech services company with 51-200 employees
 

Customer Service

Sentiment score
7.0
CrowdStrike Falcon Sandbox customer service is praised for responsiveness and effectiveness, despite occasional remote assistance issues.
Sentiment score
7.3
SentinelOne Singularity Endpoint's support is responsive and knowledgeable, with quick assistance, though some complex issues face resolution delays.
I rate them a ten because the response has always been good; when you submit a case, the response is usually very clear and to the point, so it has been great as well.
Soc Manager at County of Orange, California
They respond within two hours after I raise a support ticket.
Security Senior Engineer at a consultancy with 51-200 employees
If I would rate support on a scale of 0 to 10, with 10 being the best, I would give them nine points.
Presales Consultant at Cyber Knight Technologies FZ LLC
If we get stuck at midnight, any other TAC team will be in GMT or Europe or America, and they will assign our support engineer and suddenly schedule a call for us and resolve the issue.
Soc Analyst at Softcell Technologies Limited
For the support team of SentinelOne Singularity Endpoint, I would rate them nine out of ten because there is a human voice there, so they are listening and responsive.
Mdr Analyst at Softcell Technologies
Most of the time, we are not aware of how to resolve those questions, and SentinelOne Singularity Endpoint's customer support helps us significantly with a prompt response.
SOC Analyst at Softcell Technologies
 

Scalability Issues

Sentiment score
7.8
CrowdStrike Falcon Sandbox offers excellent scalability and reliability for organizations of all sizes, despite its high cost.
Sentiment score
7.7
SentinelOne Singularity Endpoint excels in scalability, with high ratings and features like cloud management, seamless onboarding, and flexible licensing.
I would rate the scalability of the solution as very scalable, as it can support medium businesses, small businesses, and large enterprise businesses as well.
Presales Consultant at Cyber Knight Technologies FZ LLC
The system can scale any number of times, and only the license for each endpoint is needed.
Mdr Analyst at Softcell Technologies
I would say ten out of ten for the scalability of SentinelOne Singularity Endpoint because we can scale up and scale down as per requirement.
Security Analyst at a media company with 501-1,000 employees
The cloud-based management model makes it easier to onboard, manage, and monitor large numbers of endpoints without needing additional backend infrastructure.
Cybersecurity Engineer at Gigabit Technologies Pvt Ltd
 

Stability Issues

Sentiment score
7.8
Users rate CrowdStrike Falcon Sandbox highly for stability, finding it reliable with minimal issues and no significant stability concerns.
Sentiment score
8.0
SentinelOne Singularity Endpoint offers stable, reliable protection with minimal issues, effective threat detection, and low resource consumption.
We have not had any issues where we had to detonate something multiple times to get any sort of response back.
Soc Manager at County of Orange, California
If I have to rate the stability level of Singularity Platform from one to ten, I would say it would be a strong nine.
Information Security Officer at a tech vendor with 51-200 employees
The automation helps a lot, and once implemented, we face no further issues regarding stability or scalability; everything works absolutely fine.
Associate Vice President at Novac Technology Solutions
Even if the agent disconnects from our console, it will still protect the desktop or laptop.
Soc Analyst at Softcell Technologies Limited
 

Room For Improvement

CrowdStrike Falcon Sandbox struggles with deployment, user interface, slow support, and limited OS and malware detection features.
SentinelOne Singularity Endpoint needs UI improvements, better performance, more integrations, and competitive pricing against other solutions.
While CrowdStrike is a powerful tool, the user interface is cluttered with many features, making it challenging to navigate.
Security Senior Engineer at a consultancy with 51-200 employees
Additional integrations will be beneficial to cover the whole use cases.
Presales Consultant at Cyber Knight Technologies FZ LLC
There is a limitation to how long we can interact with the file, along with the types of operating systems available.
Soc Manager at County of Orange, California
The only thing that prevented the attack from succeeding was a free version of Malwarebytes.
Director, Information Technology at Premier Realty Group
When I find a log suspicious, if it automatically points out that a particular point in the log at a specific timing or frame is looking malicious, it would be easier for me.
Cyber Security Mentor at AICDA
SentinelOne Singularity Complete doesn't have data security solutions such as Forcepoint DLP or 48 layer; SentinelOne Singularity Complete doesn't have that DLP solution.
Soc Analyst at Softcell Technologies Limited
 

Setup Cost

CrowdStrike Falcon Sandbox is priced above mid-range, but some users find it affordable due to US data storage.
SentinelOne Singularity's flexible pricing offers enterprise-level features and ROI, with costs from $7 to $15 per device monthly.
Pricing is based on the number of endpoints and the features I need, operating on a usage-based cost structure.
Security Senior Engineer at a consultancy with 51-200 employees
I think it can be expensive, but it depends on the products.
IT- Manager at Orient Craft Ltd.
It was indeed cheaper than competitors due to where they keep the data;
Soc Manager at County of Orange, California
If you want protection, you have to pay the price.
Information Security Principal at a venture capital & private equity firm with 1,001-5,000 employees
There are other products that are less expensive, but I tell my clients that in security, they cannot cut corners or look for the cheapest solution.
President at a tech services company with 1-10 employees
Reputation and quality are important, but especially in today’s economy, price is a significant factor.
Security and Compliance at a outsourcing company with 1,001-5,000 employees
 

Valuable Features

CrowdStrike Falcon Sandbox excels in threat detection with automatic sandboxing, malware analysis, and enhances endpoint security and integration.
SentinelOne Singularity excels in AI threat detection, automated response, ransomware rollback, and efficient integration with minimal system impact.
One of the key features is its policy-based notifications, which alert us to unauthorized actions.
Security Senior Engineer at a consultancy with 51-200 employees
This product is powerful in detection, which is the most important part because any customer wants a solution that detects what's happening.
Presales Consultant at Cyber Knight Technologies FZ LLC
The detailed report in CrowdStrike Falcon Sandbox contains additional information on the file itself and gives us something we can provide to other teams to further bolster or support our claim that something is either malicious or benign.
Soc Manager at County of Orange, California
I have an advanced app providing visibility of all my endpoints, which was not the case before.
AGM IT Security at Page Industries Ltd
SentinelOne has a feature to decommission automatically, which has been fantastic.
Computer Technician at VILLE DE POINTE-CLAIRE
There's also automation that gives my team free time, preventing them from having to look for every alert.
Network & Security Section Head/Digital Transformation at a government with 201-500 employees
 

Categories and Ranking

CrowdStrike Falcon Sandbox
Ranking in Anti-Malware Tools
12th
Average Rating
8.2
Reviews Sentiment
7.1
Number of Reviews
9
Ranking in other categories
No ranking in other categories
SentinelOne Singularity End...
Ranking in Anti-Malware Tools
2nd
Average Rating
8.8
Reviews Sentiment
7.0
Number of Reviews
289
Ranking in other categories
Endpoint Protection Platform (EPP) (2nd), Endpoint Detection and Response (EDR) (1st), Extended Detection and Response (XDR) (1st), AI-Powered Cybersecurity Platforms (2nd), AI Observability (2nd)
 

Mindshare comparison

As of September 2026, in the Anti-Malware Tools category, the mindshare of CrowdStrike Falcon Sandbox is 1.5%, up from 1.3% compared to the previous year. The mindshare of SentinelOne Singularity Endpoint is 3.1%, down from 3.7% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Anti-Malware Tools Mindshare Distribution
ProductMindshare (%)
SentinelOne Singularity Endpoint3.1%
CrowdStrike Falcon Sandbox1.5%
Other95.4%
Anti-Malware Tools
 

Featured Reviews

BL
Soc Manager at County of Orange, California
Detailed sandbox reports have strengthened investigations and now provide clearer threat decisions
The additional quota was a factor that led us to consider a change; we went from five detonations per day to 250 per month. Multi-platform analysis in CrowdStrike Falcon Sandbox has helped identify threats. The effectiveness of CrowdStrike Falcon Sandbox has been roughly 90 to 100 percent for our operations. Custom indicators of compromise in CrowdStrike Falcon Sandbox add to our cybersecurity strategy; it is a small part of the strategy, but it plays a significant part in keeping all of the tenants that we have onboarded up to date on relevant files that we are seeing in our environment. That memory forensic capability in CrowdStrike Falcon Sandbox is not something we utilize significantly, but we know of its importance. We utilize memory forensics sometimes in CrowdStrike Falcon Sandbox to review the entropy snapshot; if we see a high level of entropy in the Sandbox report, that could lead to a decision that the file is most likely suspicious, but we use that as an additional item to review. Regarding how features of CrowdStrike Falcon Sandbox have benefited my organization, there is a real-time feature in CrowdStrike Falcon Sandbox, so we can deploy the operating system of choice; we can also analyze archived files, and those features have been helpful as we can interact with the file in certain ways and get additional interaction metrics. I rate CrowdStrike Falcon Sandbox overall as a solution at a nine out of ten. A higher interaction time with the file would give CrowdStrike Falcon Sandbox a ten out of ten for us. If you utilize Falcon Endpoint Protection, I would highly recommend CrowdStrike Falcon Sandbox because the telemetry goes hand-in-hand with that other product.
Vaibhav Mahendra Kolhe - PeerSpot reviewer
Soc Analyst at Softcell Technologies Limited
Automation has reduced alerts and freed the soc team to focus on faster incident response
Regarding mean time to respond, the improvements I see with SentinelOne Singularity Complete are that genuine files also get alerts. We are getting false positives, but we are also getting genuine true positive alerts. The improvement will be deep visibility because as I am using Splunk as a SIEM, I compare deep visibility with Splunk, but deep visibility has limited access with only a 14-day policy to retain logs. The improvement will be in overall policy management. The third point will be the complexity of policies. If we want some endpoints to use only USB or if we need to block USB on some points, the policy management is very complex. The fourth point will be that Mac OS and Linux don't have the rollback policy; that policy is only for Windows. These four points are improvements if SentinelOne Singularity Complete can address them. Data privacy and security when utilizing Purple AI is crucial for SentinelOne Singularity Complete, and SentinelOne Singularity Complete lacks in data security. Data security is very important in this world. In my organization, if we deploy SentinelOne Singularity Complete and we have integrated all the firewalls, all devices, and AWS devices to SentinelOne Singularity Complete, logs will be forwarded to SentinelOne Singularity Complete through SentinelOne Singularity Complete. However, SentinelOne Singularity Complete doesn't have data security solutions such as Forcepoint DLP or 48 layer; SentinelOne Singularity Complete doesn't have that DLP solution. From the data security point of view, SentinelOne Singularity Complete is not good.
report
Use our free recommendation engine to learn which Anti-Malware Tools solutions are best for your needs.
913,683 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Financial Services Firm
15%
Construction Company
13%
Manufacturing Company
11%
Comms Service Provider
10%
Outsourcing Company
11%
Manufacturing Company
9%
Computer Software Company
8%
Financial Services Firm
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business5
Midsize Enterprise1
Large Enterprise4
By reviewers
Company SizeCount
Small Business140
Midsize Enterprise73
Large Enterprise98
 

Questions from the Community

What is your experience regarding pricing and costs for CrowdStrike Falcon Sandbox?
I was not involved much on the pricing, setup costs, and licensing of CrowdStrike Falcon Sandbox, but I did have some interaction with a quote; however, the quote compared to other options was one ...
What needs improvement with CrowdStrike Falcon Sandbox?
I think one of the limitations of CrowdStrike Falcon Sandbox is the amount of interaction time when we interact with the file; I believe there is a limitation to how long we can interact with the f...
What is your primary use case for CrowdStrike Falcon Sandbox?
My main use cases for CrowdStrike Falcon Sandbox are for additional telemetry and a confidence score on files, specifically from email or even from endpoints.
Cortex XDR by Palo Alto vs. Sentinel One
Cortex XDR by Palo Alto vs. SentinelOne SentinelOne offers very detailed specifics with regard to risks or attacks. The ability to reverse damage caused by ransomware with minimal interruptions to...
Which is better - SentinelOne or Darktrace?
Which solution is better depends on which is more suitable specifically for your company. Darktrace, for example, is meant for smaller to medium-sized businesses. It is also a good option for organ...
What is your experience regarding pricing and costs for SentinelOne Singularity?
It is neither too costly, but definitely, it is one of the advantages that SentinelOne is quite adapted towards the pricing.
 

Also Known As

No data available
Sentinel Labs, SentinelOne Singularity, Singularity Platform
 

Overview

 

Sample Customers

Information Not Available
Havas, Flex, Estee Lauder, McKesson, Norfolk Southern, JetBlue, Norwegian airlines, TGI Friday, AVX, Fim Bank
Find out what your peers are saying about CrowdStrike Falcon Sandbox vs. SentinelOne Singularity Endpoint and other solutions. Updated: September 2026.
913,683 professionals have used our research since 2012.