Try our new research platform with insights from 80,000+ expert users

SentinelOne Singularity Complete vs Sophos EPP Suite vs VMware Carbon Black Endpoint comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

ROI

Sentiment score
7.5
SentinelOne Singularity Complete reduced incident response time and costs, improving ROI with advanced features and central management.
Sentiment score
7.7
Sophos EPP Suite boosts ROI in 12-16 months, enhancing productivity, protection, and compliance while ensuring customer satisfaction.
Sentiment score
7.1
Users reported significant ROI with VMware Carbon Black Endpoint, citing reduced malware and ransomware incidents, and 10% cost savings.
Since then, I have not faced any intrusions, which is one reason I chose SentinelOne over ESET.
We have not faced any attacks since we implemented it.
It has absolutely helped reduce our organizational risk.
 

Customer Service

Sentiment score
7.3
SentinelOne Singularity Complete is praised for effective, fast support, though some desire more phone and interactive assistance.
Sentiment score
7.7
User reviews of Sophos EPP Suite support highlight responsiveness and expertise, though some experience delays and ineffective resolutions.
Sentiment score
6.4
VMware Carbon Black Endpoint support is generally praised as effective and knowledgeable, but some report delays and issues with tiered support.
They do a great job of figuring out the problem and pointing you to generic documentation or working with you to fine-tune a solution.
We are using the automated email process for support, and they respond within an hour or two hours sometimes.
A chat service would be beneficial.
They have introduced a dedicated role called Technical Account Manager (TAM) for every partner.
The Sophos people here in South Africa are very helpful.
 

Scalability Issues

Sentiment score
8.1
SentinelOne Singularity Complete is versatile, seamlessly expanding across platforms, integrating easily, but faces issues when scaling down.
Sentiment score
8.5
Sophos EPP Suite offers scalable solutions for diverse organizations, accommodating growth and simplifying cloud deployments, despite third-party integration limits.
Sentiment score
7.5
VMware Carbon Black Endpoint is highly scalable and adaptable for various enterprises, praised for ease of adding tenants and managing environments.
It's all auto-scale and auto-categorized, configuring automatically.
The tool's built-in automation for deploying the agents works well for large infrastructures like mine.
My deployment is relatively small, and SentinelOne Singularity Complete works within those constraints.
 

Stability Issues

Sentiment score
7.9
SentinelOne Singularity Complete is stable, reliable, with minor connectivity issues during updates; users appreciate its performance and stability.
Sentiment score
9.0
Sophos EPP Suite is generally stable but has minor glitches; some users seek other solutions for better stability.
Sentiment score
7.6
VMware Carbon Black Endpoint is stable, lightweight, reliable, and highly rated, though minor issues with sensors and updates occasionally occur.
It has caused problems with interoperability between third-party tools, which could lead to entire servers crashing or specific tools failing.
This indicates room for improvement in stability when interacting with other solutions.
Initially, there were issues, particularly on the management side, but now the console is much more stable.
 

Room For Improvement

SentinelOne Singularity Complete needs UI refinement, better automation, flexible policies, reduced resource use, and improved pricing and support.
Sophos EPP Suite needs improvements in migration, resource usage, integration, support, and user interface for better performance and compatibility.
VMware Carbon Black Endpoint struggles with mobile support, complex UI, performance issues, inadequate reporting, and insufficient third-party integration.
The only thing that prevented the attack from succeeding was a free version of Malwarebytes.
Providing a single pane of visibility for the end user would be beneficial.
It's challenging to prevent a user from manipulating their privileges or someone else's of others, and it's difficult to control what users can access at the organizational level.
The enterprise integration is very poor, requiring a lot of manual work.
Users have noted that daily upload limits per device, overall data lake storage capacity tied to licenses, and daily API query limits can be restrictive.
 

Setup Cost

SentinelOne Singularity Complete is seen as cost-effective by some but pricey compared to traditional antivirus solutions, yet feature-rich.
Sophos EPP Suite offers competitive, often affordable pricing, with discounts for longer licenses, despite varying costs by features and users.
VMware Carbon Black Endpoint licensing is seen as expensive and inflexible, with prices ranging from $15 to $7,000 per node.
If you want protection, you have to pay the price.
They counted many of the instances and licenses as duplicates despite them only being alive once, which was frustrating.
It’s cheaper than other competitors.
The cost is reasonable and cheaper than other alternatives.
 

Valuable Features

SentinelOne Singularity Complete offers robust, AI-driven security and seamless integration, enhancing performance and protection for enterprises.
Sophos EPP Suite offers seamless integration, advanced threat detection, centralized management, and user-friendly features for comprehensive security solutions.
VMware Carbon Black Endpoint offers robust remote security with intuitive real-time detection, AI-driven threat response, and centralized cloud control.
I have an advanced app providing visibility of all my endpoints, which was not the case before.
SentinelOne has a feature to decommission automatically, which has been fantastic.
There's also automation that gives my team free time, preventing them from having to look for every alert.
Key features for comprehensive detection and prevention include advanced threat prevention, ransomware protections, exploit prevention, and AI-powered detections.
With the reseller management, I can manage multiple clients without having to log in to each client.
 

Mindshare comparison

As of June 2025, in the Endpoint Protection Platform (EPP) category, the mindshare of SentinelOne Singularity Complete is 4.5%, down from 5.9% compared to the previous year. The mindshare of Sophos EPP Suite is 0.8%, up from 0.5% compared to the previous year. The mindshare of VMware Carbon Black Endpoint is 1.6%, down from 2.5% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Endpoint Protection Platform (EPP)
 

Featured Reviews

Asim Naeem - PeerSpot reviewer
It integrates well with other platforms, is user-friendly, and is stable
SentinelOne Singularity Complete integrates with our other security solutions, correlating data from NDR, ADR, SIEM, and XDR tools. All this information is consolidated within SentinelOne, providing a centralized access point. SentinelOne Singularity Complete has helped us streamline our security operations by consolidating multiple solutions into a single platform. We are currently in the process of acquiring a threat intelligence platform to complete our security stack. We use Ranger to monitor our network and track connected devices. This is crucial because it helps us quickly identify unauthorized machines connected to our infrastructure, including personal devices. We have additional security measures in place, but Ranger provides an extra layer of protection. It also alerts us if the SentinelOne Singularity Complete agent is missing from any new or existing machines, allowing us to take appropriate action. SentinelOne Ranger's agentless and hardware-independent nature is crucial for our environment with 26,000 endpoints, as manual management of such a large number would be extremely challenging. Ranger uses a multi-layered approach to prevent vulnerable devices from being compromised. We employ scanners, network configurations, and a risk scanner to assess devices, endpoints, servers, and cloud infrastructures. Vulnerability reports and timelines for remediation are shared with device owners or custodians. This proactive strategy enables us to address vulnerabilities efficiently and secure our infrastructure. SentinelOne Singularity Complete has significantly enhanced our security posture. While no system is impenetrable, this solution has brought us closer to achieving a high level of protection, ensuring we maintain at least a 90 percent security level. Our team is dedicated to refining alerts and eliminating false positives from our solutions. Additionally, a team is responsible for identifying and excluding alerts from the solution. We can manually expedite this process by reviewing these elements and utilizing our security tools. We have been able to reduce the alert volume by 20 percent. Our 30-member Security Operations Center team has been able to redirect their focus to other tasks due to the time saved after implementing SentinelOne Singularity Complete. SentinelOne Singularity Complete has helped us improve our mean time to detect threats, which we accomplish using the Vigilance service for detection and response. SentinelOne Singularity Complete has helped us decrease our organizational risk. We utilize the Security Scorecard to manage our security posture, which has remained steady at 90 percent.
Sabbir Ahmed - PeerSpot reviewer
Experience significant threat prevention advancements with user-friendly deployment
The feature is called relay server, and some people refer to it as a cache server. The Sophos EPP Suite is scalable. Some customers in banks typically have 5,000 to 7,000 users. One customer started with 1,000 users and has now extended to 4,000 users. Some customers are using up to 8,000 users without any issues. Regarding AI elements in the Sophos EPP Suite, firewalls have already introduced AI features. They have integrated AI models similar to ChatGPT in firewalls. These AI features should be introduced in endpoint XDR as well. Key features for comprehensive detection and prevention include advanced threat prevention, ransomware protections, exploit prevention, and AI-powered detections. Extended visibility and data analysis include cross-product data correlations. They have a data lake, live discover, and threat graphs. They also offer AI case summary and AI common analysis, accessible from Sophos Central, which is the management portal for Sophos XDR. Sophos Central serves as one central management portal for managing firewalls, endpoint, Sophos encryption, and mobile device management solutions. This centralized management is particularly appealing to customers.
KarthikR1 - PeerSpot reviewer
The solution has an easy setup but needs to mature on cloud environment security
The maturity of the Kubernetes security is absent in Carbon Black CB Defense. The solution has to mature on container security and a lot of cloud environment security. Security is available only for Windows, while security for Linux and Mac is not very strong. The deadlock issue causes me to put more effort into installing an upgrade. The numerous issues with the environment of the product solution should be addressed. Work orders are taking more than two months to get resolved. There's been one issue open for two months, and the solution they gave is being implemented step by step. Still, it is not meeting the requirements and breaking the system. Hence, our business is completely disturbed.
report
Use our free recommendation engine to learn which Endpoint Protection Platform (EPP) solutions are best for your needs.
858,327 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
20%
Manufacturing Company
8%
Financial Services Firm
7%
Government
6%
Computer Software Company
18%
Financial Services Firm
10%
Manufacturing Company
8%
Educational Organization
8%
Computer Software Company
15%
Financial Services Firm
12%
Government
9%
Manufacturing Company
8%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
 

Questions from the Community

Cortex XDR by Palo Alto vs. Sentinel One
Cortex XDR by Palo Alto vs. SentinelOne SentinelOne offers very detailed specifics with regard to risks or attacks. ...
Which is better - SentinelOne or Darktrace?
Which solution is better depends on which is more suitable specifically for your company. Darktrace, for example, is ...
What do you like most about Sophos EPP Suite?
Sophos EPP Suite is a powerful antivirus.
What is your experience regarding pricing and costs for Sophos EPP Suite?
For Bangladesh, the price of the Sophos EPP Suite is reasonable. We recently won a deal when compared with CrowdStrik...
What needs improvement with Sophos EPP Suite?
The Sophos EPP Suite should work on key areas, especially in data management, specifically the data retention part. T...
What to choose: an endpoint antivirus, an EDR solution or both?
I can recommend Carbon Black, an award-winning next-gen anti-virus (NGAV) and endpoint detection and response (EDR) s...
What's the difference between Carbon Black CB Response and Carbon Black CB Defense?
Carbon Black offers two different levels of Endpoint Detection and Response. One is the VM Carbon Black Cloud Endpoin...
What do you like most about Carbon Black CB Defense?
VMware Carbon Black Endpoint is a highly stable solution.
 

Also Known As

Sentinel Labs, SentinelOne Singularity
EPP Suite
Carbon Black CB Defense, Bit9, Confer
 

Overview

 

Sample Customers

Havas, Flex, Estee Lauder, McKesson, Norfolk Southern, JetBlue, Norwegian airlines, TGI Friday, AVX, Fim Bank
EK Services
Netflix, Progress Residential, Indeed, Hologic, Gentle Giant, Samsung Research America
Find out what your peers are saying about Microsoft, CrowdStrike, SentinelOne and others in Endpoint Protection Platform (EPP). Updated: June 2025.
858,327 professionals have used our research since 2012.