No more typing reviews! Try our Samantha, our new voice AI agent.

ExtraHop Reveal(x) 360 vs SentinelOne Singularity Endpoint comparison

Why PeerSpot?
Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Jun 3, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cortex XDR by Palo Alto Net...
Sponsored
Ranking in Extended Detection and Response (XDR)
4th
Average Rating
8.4
Reviews Sentiment
6.7
Number of Reviews
117
Ranking in other categories
Endpoint Protection Platform (EPP) (4th), Endpoint Detection and Response (EDR) (5th), Ransomware Protection (2nd), AI-Powered Cybersecurity Platforms (1st)
ExtraHop Reveal(x) 360
Ranking in Extended Detection and Response (XDR)
25th
Average Rating
8.6
Reviews Sentiment
7.0
Number of Reviews
6
Ranking in other categories
Intrusion Detection and Prevention Software (IDPS) (16th), Container Security (32nd), Network Traffic Analysis (NTA) (9th)
SentinelOne Singularity End...
Ranking in Extended Detection and Response (XDR)
1st
Average Rating
8.8
Reviews Sentiment
7.0
Number of Reviews
288
Ranking in other categories
Endpoint Protection Platform (EPP) (2nd), Anti-Malware Tools (2nd), Endpoint Detection and Response (EDR) (1st), AI-Powered Cybersecurity Platforms (2nd), AI Observability (2nd)
 

Mindshare comparison

As of September 2026, in the Extended Detection and Response (XDR) category, the mindshare of Cortex XDR by Palo Alto Networks is 4.8%, down from 6.1% compared to the previous year. The mindshare of ExtraHop Reveal(x) 360 is 1.2%, up from 0.6% compared to the previous year. The mindshare of SentinelOne Singularity Endpoint is 6.4%, down from 6.9% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Extended Detection and Response (XDR) Mindshare Distribution
ProductMindshare (%)
SentinelOne Singularity Endpoint6.4%
Cortex XDR by Palo Alto Networks4.8%
ExtraHop Reveal(x) 3601.2%
Other87.6%
Extended Detection and Response (XDR)
 

Featured Reviews

ABHISHEK_SINGH - PeerSpot reviewer
Senior Process Expert at A.P. Moller - Maersk
Gained full visibility and streamlined threat detection through behavior-based insights and AI integration
Initially, we got to have a lot of false positives when we onboarded, but nowadays it's quite smooth. We have fine-tuned our security policies and allowed different levels of policies to get rid of those false positives. Currently, we are getting a fairly good amount of incidents that are not false positives or benign, but actionable items. The process is streamlined. In the initial days, the operations used to get involved in a lot of benign and other activities, but now the process is streamlined. We are leveraging the auto-detection and remediation plans. The operations teams are now more involved in other business roles as well, not just looking into the logs and fetching out what's happening there. They have fixed a lot of things. Initially, they didn't have IAC code drift detection, cloud posture management, or security posture management, but they have those now. They purchased different vendors and did a merger with that. They have now Prisma Cloud that gets integrated and now they are working with Cortex Cloud. Everything that was negative has now been addressed, and the product altogether looks to be in a very better and mature shape now. Currently, it's more or less detecting the workloads with AI-based best practices. Since most organizations are consuming AI agents and other things, we are looking forward to seeing what other feature enhancements Palo Alto can support in that.
US
Consultant at a comms service provider with 1,001-5,000 employees
Unified visibility has transformed threat detection and performance troubleshooting across environments
ExtraHop Reveal(x) 360 is very powerful, and there is always room for improvement. One area is more customizable dashboards and reporting for executives, with more business-level reporting. Second, deeper native integrations with SOAR and ticketing tools to automate response even faster. Third, cost optimizations for SMBs, making some premium features more accessible would help wider adoption. From a consultant's perspective, a few enhancements could make ExtraHop Reveal(x) 360 even stronger. First, usability, with more intuitive, guided workflows and contextual AI assist for junior analysts to reduce the learning curve. Second, onboarding with more pre-built use case templates for healthcare, finance, and other industries to speed up time-to-value. Third, support and enablement with more granular role-based access and better in-product documentation for faster troubleshooting. These are not gaps, but opportunities to make an already powerful platform even more user-friendly and scalable.
Vaibhav Mahendra Kolhe - PeerSpot reviewer
Soc Analyst at Softcell Technologies Limited
Automation has reduced alerts and freed the soc team to focus on faster incident response
Regarding mean time to respond, the improvements I see with SentinelOne Singularity Complete are that genuine files also get alerts. We are getting false positives, but we are also getting genuine true positive alerts. The improvement will be deep visibility because as I am using Splunk as a SIEM, I compare deep visibility with Splunk, but deep visibility has limited access with only a 14-day policy to retain logs. The improvement will be in overall policy management. The third point will be the complexity of policies. If we want some endpoints to use only USB or if we need to block USB on some points, the policy management is very complex. The fourth point will be that Mac OS and Linux don't have the rollback policy; that policy is only for Windows. These four points are improvements if SentinelOne Singularity Complete can address them. Data privacy and security when utilizing Purple AI is crucial for SentinelOne Singularity Complete, and SentinelOne Singularity Complete lacks in data security. Data security is very important in this world. In my organization, if we deploy SentinelOne Singularity Complete and we have integrated all the firewalls, all devices, and AWS devices to SentinelOne Singularity Complete, logs will be forwarded to SentinelOne Singularity Complete through SentinelOne Singularity Complete. However, SentinelOne Singularity Complete doesn't have data security solutions such as Forcepoint DLP or 48 layer; SentinelOne Singularity Complete doesn't have that DLP solution. From the data security point of view, SentinelOne Singularity Complete is not good.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The most valuable features are incident creation, policy-based protection, IP whitelisting, and device encryption. These are beneficial for endpoint and server security."
"The good thing about the product is that it's always scanning."
"The most valuable feature of Cortex XDR by Palo Alto Networks is its machine-learning capabilities. Additionally, there is full integration with other solutions."
"The most valuable aspect of Cortex XDR by Palo Alto Networks for me is its integration with AI detection, where we get to know the behavioral detection based on users, traffic patterns, and different services that we consume."
"What I like about Cortex XDR by Palo Alto Networks is that it is a comprehensive solution that contains everything the organization may need when using endpoints."
"The most valuable features are the fact that it was running in the background and it would intercept any weird stuff, and the fact that it would send things directly to the cloud for sandboxing. It's quite practical."
"The tool's use cases are relevant to security."
"The most valuable for us is the correlation feature."
"It is scalable."
"ExtraHop Reveal(x) 360 has positively impacted my organization by helping us detect abnormal activity on our network that we could not detect through our SIEM or XDR platform."
"Overall, I use it as a single 360-degree platform for visibility across on-prem and cloud."
"Their technical support is more effective and of better quality than other competitors."
"It stands out for its intuitive and efficient user interface, robust detection capabilities with minimal false positives, and the ability to handle encrypted traffic, making it a valuable asset for network security and management."
"ExtraHop Reveal(x) 360 has undeniably improved our security posture, reduced manual investigation efforts, and facilitated fast threat detection mechanisms, which all help prevent costly potential breaches in enterprise environments."
"It is very easy to collect and handle data in ExtraHop Reveal(X) Cloud. Integration with Big Data is also easy. Many of our customers integrate it with Big Data platforms like Splunk or Elastic. It is also easy to handle and easy to understand."
"The CapEX is very low because you don't have to buy any management tools or install them on your hardware."
"All of the features are valuable. The way that it integrates into management with fault correction capabilities over is especially valuable. Any of the full gamut of the features that it provides are useful to us."
"Comparing SentinelOne Singularty Endpoint with other XDR solutions, the first thing is that it is easier to understand with a user-friendly interface."
"The Deep Visibility feature is the most useful part of the EDR platform. It gives us good insights into what is actually happening on the endpoints, e.g., when we have malicious or suspicious activity. We came from a legacy type AV previously, so we didn't have that level of visibility or understanding. For simplifying threat-hunting, it is extremely useful, where traditional techniques in threat hunting are quite laborious. We can put in indicators of compromise and it will sweep the environment for them, then they would give us a breakdown of what assets have been seen and where they have been seen, which is more of a forensics overview."
"My advice for others looking into using SentinelOne Singularity Endpoint is to go for it, as it effectively does the EDR job."
"The fact that this runs using AI instead of heuristics provides the best protection I've seen."
"It is very effective so far, it has saved us from a couple of ransomware attacks already, and the responsibility is taken off of us and onto them completely with complete and total protection."
"The initial setup is very straightforward and easy."
 

Cons

"Currently, if you use Palo Alto endpoint protection as the only solution it's very complicated to remove pre-existing threats."
"Limited remote connection."
"I think sometimes Cortex XDR agent automatically stops event capturing from the device, and then even the dashboard does not get any notifications from the agent."
"The main issue I could point out is the offline agents and the way that it is missing."
"Product might have some bugs."
"The downside to the solution is that there are a large number of false positives."
"The setup is quite easy. We had appropriate support from the manager. One thing that was missing was the integration part."
"Cortex XDR by Palo Alto Networks could improve by adding a sandbox feature to better compete with their competitors which have it."
"There needs to be more support."
"One challenge with ExtraHop Reveal(x) 360 is its pricing, which tends to be comparatively high in the marketplace."
"A drawback includes bucket storage limitations for payload data, necessitating timely extraction for thorough investigations."
"I would like to see ExtraHop Reveal(x) 360 improved by integrating XDR features with NDR."
"They can include integration with SAP. Currently, no vendor provides network performance monitoring in the SAP market. It is a very big market. We have around 400 customers for SAP in Korea. In the USA, there are more than 10,000 customers."
"Their professional service can be improved."
"The setup process could be improved."
"If they can extend their product further on the DLP side of it so that I don't have to have another agent run exclusively for DLP production, that would be ideal."
"The ability to integrate this product with an antivirus solution would be welcome. Even consolidation with more security products, like Umbrella networking abilities etc. to provide more on this platform, that would be great."
"SentinelOne Singularity Complete itself is somewhat laggy and loads slowly at times."
"Improvements for SentinelOne's Singularity Complete could include adjusting pricing for specific markets, ensuring affordability, and better alignment with customer expectations in those regions."
"The process of uninstalling and reinstalling older agent updates needs improvement."
"The only thing that would help complete the solution is the ability to execute and perform patching from the system since it is able to discover vulnerabilities and CVEs on the system."
"Sometimes, these customized solutions our developers develop also get flagged in real time, and the processes get stopped and are blocked, and we have to whitelist the processes."
 

Pricing and Cost Advice

"The solution has one subscription for endpoint protection and one subscription for detection and response. The two licenses combined give you the BRO version."
"The solution is expensive. It's pricing is on a yearly-basis."
"It is "expensive" and flexible."
"Its pricing is kind of in line with its competitors and everybody else out there."
"The price was fine."
"I am using the Community edition."
"It's about $55 per license on a yearly basis."
"The price of the solution is high for the license and in general."
"When compared to other solutions, it aligns with the market average, indicating a competitive pricing level."
"I can pay, for my environment, between $30,000 and $40,000 a year, and that's a pretty good deal."
"The pricing model is simple."
"The pricing is very fair for the solution they provide."
"This solution is less expensive than its competitors."
"I do not know much about the pricing. What I do know is that the person who negotiates most of the pricing is quite a hard bargainer. In that regard, he often says that he managed to get a very good deal. When we first looked at replacing our old system with Singularity Complete, its price was definitely a big factor. Back then, Singularity Complete was fairly new to the marketplace. We got quite a good deal as an early adopter. They have honored that and respected that we were an early adopter, and I feel we are still getting a very good price."
"Our licensing fees are about $5 USD per endpoint, per month."
"Its price can be lower because I'm seeing competition from another vendor who beats it on commercials."
"At this time it is only a trial. After the trial period, I am going to purchase two licenses from SentinelOne."
report
Use our free recommendation engine to learn which Extended Detection and Response (XDR) solutions are best for your needs.
912,788 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Outsourcing Company
12%
Comms Service Provider
12%
Construction Company
11%
Financial Services Firm
10%
Financial Services Firm
11%
Comms Service Provider
11%
Manufacturing Company
9%
Construction Company
8%
Outsourcing Company
11%
Manufacturing Company
9%
Computer Software Company
8%
Financial Services Firm
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business47
Midsize Enterprise21
Large Enterprise54
By reviewers
Company SizeCount
Small Business2
Midsize Enterprise1
Large Enterprise4
By reviewers
Company SizeCount
Small Business140
Midsize Enterprise73
Large Enterprise98
 

Questions from the Community

Cortex XDR by Palo Alto vs. Sentinel One
Cortex XDR by Palo Alto vs. SentinelOne SentinelOne offers very detailed specifics with regard to risks or attacks. ...
Comparing CrowdStrike Falcon to Cortex XDR (Palo Alto)
Cortex XDR by Palo Alto vs. CrowdStrike Falcon Both Cortex XDR and Crowd Strike Falcon offer cloud-based solutions th...
How is Cortex XDR compared with Microsoft Defender?
Microsoft Defender for Endpoint is a cloud-delivered endpoint security solution. The tool reduces the attack surface,...
What needs improvement with ExtraHop Reveal(x) 360?
One challenge with ExtraHop Reveal(x) 360 is its pricing, which tends to be comparatively high in the marketplace. In...
What advice do you have for others considering ExtraHop Reveal(x) 360?
We have covered most of the features over the past three years and look forward to discovering more as we work closel...
What is your primary use case for ExtraHop Reveal(X) Cloud?
I use ExtraHop Reveal(x) 360 as our cloud-native NDR platform, with primary use cases including monitoring real-time ...
Which is better - SentinelOne or Darktrace?
Which solution is better depends on which is more suitable specifically for your company. Darktrace, for example, is ...
What is your experience regarding pricing and costs for SentinelOne Singularity?
It is neither too costly, but definitely, it is one of the advantages that SentinelOne is quite adapted towards the p...
What needs improvement with SentinelOne Singularity?
I have encountered an issue related to the alerting mechanism in SentinelOne Singularity Complete. Sometimes I need t...
 

Also Known As

Cyvera, Cortex XDR, Palo Alto Networks Traps
ExtraHop Reveal(X) Cloud, Reveal(X) Cloud
Sentinel Labs, SentinelOne Singularity, Singularity Platform
 

Overview

 

Sample Customers

CBI Health Group, University Honda, VakifBank
Wizards of the Coast
Havas, Flex, Estee Lauder, McKesson, Norfolk Southern, JetBlue, Norwegian airlines, TGI Friday, AVX, Fim Bank
Find out what your peers are saying about ExtraHop Reveal(x) 360 vs. SentinelOne Singularity Endpoint and other solutions. Updated: August 2026.
912,788 professionals have used our research since 2012.