No more typing reviews! Try our Samantha, our new voice AI agent.

SentinelOne Singularity Endpoint vs Tanium comparison

Sponsored
 

Comparison Buyer's Guide

Executive SummaryUpdated on Jun 3, 2026

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Cortex XDR by Palo Alto Net...
Sponsored
Ranking in Endpoint Protection Platform (EPP)
4th
Ranking in Endpoint Detection and Response (EDR)
5th
Average Rating
8.4
Reviews Sentiment
6.7
Number of Reviews
117
Ranking in other categories
Extended Detection and Response (XDR) (4th), Ransomware Protection (2nd), AI-Powered Cybersecurity Platforms (1st)
SentinelOne Singularity End...
Ranking in Endpoint Protection Platform (EPP)
2nd
Ranking in Endpoint Detection and Response (EDR)
1st
Average Rating
8.8
Reviews Sentiment
7.0
Number of Reviews
284
Ranking in other categories
Anti-Malware Tools (2nd), Extended Detection and Response (XDR) (1st), AI-Powered Cybersecurity Platforms (2nd), AI Observability (2nd)
Tanium
Ranking in Endpoint Protection Platform (EPP)
14th
Ranking in Endpoint Detection and Response (EDR)
23rd
Average Rating
7.8
Reviews Sentiment
6.2
Number of Reviews
23
Ranking in other categories
Vulnerability Management (26th), Unified Endpoint Management (UEM) (8th), Autonomous Endpoint Management (3rd)
 

Mindshare comparison

As of August 2026, in the Endpoint Protection Platform (EPP) category, the mindshare of Cortex XDR by Palo Alto Networks is 3.9%, up from 3.7% compared to the previous year. The mindshare of SentinelOne Singularity Endpoint is 4.6%, up from 4.5% compared to the previous year. The mindshare of Tanium is 2.5%, up from 2.4% compared to the previous year. It is calculated based on PeerSpot user engagement data.
Endpoint Protection Platform (EPP) Mindshare Distribution
ProductMindshare (%)
SentinelOne Singularity Endpoint4.6%
Cortex XDR by Palo Alto Networks3.9%
Tanium2.5%
Other89.0%
Endpoint Protection Platform (EPP)
 

Featured Reviews

ABHISHEK_SINGH - PeerSpot reviewer
Senior Process Expert at A.P. Moller - Maersk
Gained full visibility and streamlined threat detection through behavior-based insights and AI integration
Initially, we got to have a lot of false positives when we onboarded, but nowadays it's quite smooth. We have fine-tuned our security policies and allowed different levels of policies to get rid of those false positives. Currently, we are getting a fairly good amount of incidents that are not false positives or benign, but actionable items. The process is streamlined. In the initial days, the operations used to get involved in a lot of benign and other activities, but now the process is streamlined. We are leveraging the auto-detection and remediation plans. The operations teams are now more involved in other business roles as well, not just looking into the logs and fetching out what's happening there. They have fixed a lot of things. Initially, they didn't have IAC code drift detection, cloud posture management, or security posture management, but they have those now. They purchased different vendors and did a merger with that. They have now Prisma Cloud that gets integrated and now they are working with Cortex Cloud. Everything that was negative has now been addressed, and the product altogether looks to be in a very better and mature shape now. Currently, it's more or less detecting the workloads with AI-based best practices. Since most organizations are consuming AI agents and other things, we are looking forward to seeing what other feature enhancements Palo Alto can support in that.
Vaibhav Mahendra Kolhe - PeerSpot reviewer
Soc Analyst at Softcell Technologies Limited
Automation has reduced alerts and freed the soc team to focus on faster incident response
Regarding mean time to respond, the improvements I see with SentinelOne Singularity Complete are that genuine files also get alerts. We are getting false positives, but we are also getting genuine true positive alerts. The improvement will be deep visibility because as I am using Splunk as a SIEM, I compare deep visibility with Splunk, but deep visibility has limited access with only a 14-day policy to retain logs. The improvement will be in overall policy management. The third point will be the complexity of policies. If we want some endpoints to use only USB or if we need to block USB on some points, the policy management is very complex. The fourth point will be that Mac OS and Linux don't have the rollback policy; that policy is only for Windows. These four points are improvements if SentinelOne Singularity Complete can address them. Data privacy and security when utilizing Purple AI is crucial for SentinelOne Singularity Complete, and SentinelOne Singularity Complete lacks in data security. Data security is very important in this world. In my organization, if we deploy SentinelOne Singularity Complete and we have integrated all the firewalls, all devices, and AWS devices to SentinelOne Singularity Complete, logs will be forwarded to SentinelOne Singularity Complete through SentinelOne Singularity Complete. However, SentinelOne Singularity Complete doesn't have data security solutions such as Forcepoint DLP or 48 layer; SentinelOne Singularity Complete doesn't have that DLP solution. From the data security point of view, SentinelOne Singularity Complete is not good.
Sandeepraj Gatla - PeerSpot reviewer
Dfir Analyst at a tech services company with 201-500 employees
Endpoint monitoring has strengthened incident response and provides rapid isolation and forensics
Tanium provides an endpoint which is isolated from the network and environment. We can easily search its logs and history and connect remotely directly to that particular device which has been isolated from the network. We can search for the history and logs, including audit logs and event logs. The complete activity of the user or owner of the device is visible to us. We can see the artifacts of particular USB transfers internally for official use. We can not only connect remotely but also see the device status and how many failures have occurred within the network so far. We can see the IP address, how many times it has changed its IP address, and how many times it was connected to VPN or external VPN or internal VPN and what has been searched while on VPN. We can block the IOCs or IP addresses as well. We can block domains, hashes, SHA values, SHA-256, SHA-1, SHA-5 and MD5. Although I am not completely involved in the automation team, we do have that team and I have worked in some CERT recently. Tanium is more useful while we are in the CERT because most of the times when we are on high alert, Tanium does play a main role for that particular incident or any high case. Tanium is a simple tool and we can easily integrate it to many devices and it is a mandatory tool to secure an endpoint. It is mandatory to give any RDP connection and the tool should be present in the particular device. It is completely mandatory and it is in the policy as well.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The user interface of the solution is sophisticated and straightforward."
"The most valuable features are incident creation, policy-based protection, IP whitelisting, and device encryption. These are beneficial for endpoint and server security."
"Its interface and pricing are most valuable, and it is better than other vendors in terms of security."
"The tool is easy to use."
"The one feature of Palo Alto Networks Traps that our organization finds most valuable is the App ID service."
"Based on my experience with Cortex XDR by Palo Alto Networks, I highly recommend it due to its quick response to zero-day attacks and low utilization from end-user devices."
"When the pandemic started, Palo Alto came up with many solutions, which helped with the quick shift from on-premises to the cloud."
"Traps has drastically reduced our endpoint attack surface via advanced detection capabilities, sandboxing of never before seen programs, and by drastically limiting where executables can launch in the first place."
"For me, the most valuable feature is the Deep Visibility. It gives you the ability to search all actions that were taken on a specific machine, like writing register keys, executing software, opening, reading, and writing files. All that stuff is available from the SentinelOne console. I'm able to see which software is permanent on a machine, and how that happened, whether by registry keys or writing it to a special folder on the machine."
"Unlike other endpoint solutions like Kaspersky or Trend Micro, SentinelOne's agents are exceptionally lightweight, updating seamlessly without consuming significant network or system resources."
"Device control and network control are valuable."
"The 365 management and analytics from the cloud is another great feature."
"Singularity Platform's functionality for ransomware rollback is quite useful because if you have a ransomware attack, most EDR solutions do not have the feature to do a rollback and bring the system to its earlier state, but that is one of the unique features that Singularity Platform has which can be a game changer for customers."
"The overall product quality is good."
"It's a plug-and-play solution that works well with other out of box integrations that we have."
"It delivers the type of security which we were hoping for, since we have a lot of different endpoint users utilizing different types of software. We have people who only use Office software, like email, Word, and PDFs. Then, we have people who use some applications that other people wrote. We also write applications in-house using people who develop software. Therefore, we have some machines using very high-end developer software for mechanical development, electronic development, and software development. Those users are used to managing their PC on their own. The centralize platform allows us to differentiate between those three groups of people. We have overall control and can oversee the security levels at all the endpoints. They have not yet been blocked in any way when performing the functions"
"Tanium’s best features include support for any Windows, Linux, or Mac endpoint, regardless of where it is, and the ability to do IT operations and security operations."
"Tanium's most valuable feature is its instant discovery aspect."
"Tanium is highly scalable."
"Tanium's most valuable features are patch management, inventory, and distribution software."
"For inventory purposes, it's from one of the best things on the scene, as you can get live inventory."
"I would say Tanium is the best tool for vulnerability management."
"I find the inventory and compliance features of Tanium to be the most impressive."
"The product is granular and can build complex roles compared to other EDR vendors."
 

Cons

"To jump from the partner to Palo Alto directly was challenging."
"It's more focused on network communication. If a customer wants to increase the level of protection and start working with documents, it's impossible to integrate these features into the system. It's more of a communication-oriented system than a content security-oriented system."
"It is not very strong in terms of endpoint management. It should have additional features like DLP, encryption, or advanced device control. Currently, Cortex is good in terms of the security of the endpoints, but it is not as good as other vendors in terms of the management of the endpoint."
"It's very time-consuming to log support issues and the people that answer the tickets aren't very knowledgeable."
"I would like to see some additional features related to email protection included."
"Palo Alto Networks Cortex XDR does not detect malicious activity like in other anti-virus solutions like Trend Micro and Windows with Cisco."
"The solution should offer more dashboards and they should be better customized."
"In general, the price could be more competitive."
"The "false positive" detection rate could be improved, if possible, but this should not increase the risk of the endpoint being breached."
"One of the negatives we have found is that we receive quite a lot of false positives."
"It is difficult to manage users in SentinelOne."
"There is not much flexibility in terms of policy fine-tuning. We can turn it off or turn it on, but, there's nothing much else to do. Everything is predefined. It's good in a way, but you don't get much flexibility if you want to do something particular."
"SentinelOne needs to provide more documentation for administrators and analytics."
"It would be good to see some small tools to test files or hashes that are a potential threat, I know there are already products offering this."
"Using the filters takes a little bit of time to get to used to."
"As a user, I personally feel that in SentinelOne Singularity Endpoint, the customized dashboard could be improved. We were not able to create a customized dashboard in it."
"There are some bugs in the product. The tool needs to improve in the area of reporting."
"The solution can give a lot of false positives."
"We set a policy to block USB access. The moment a device is being set up on the network, I apply the policy, but it does not come into effect immediately."
"Any movement into a SaaS solution has challenges since the processes and data flows are not well defined. Hence, you need to build it at the same time."
"Tanium's limitations should be improved because although it is a great tool, it is limited to only a few classes during a session."
"The solution needs to improve the reporting and tracking capabilities."
"Tanium’s scalability could be improved."
"It is not really additional functions, or the features that are needed, rather the complexity would be reduced based on the number of modules required to put together a comprehensive operational security and risk compliance model."
 

Pricing and Cost Advice

"I don't like that they have different types of licenses."
"Cortex XDR by Palo Alto Networks is an expensive solution."
"It's the most expensive solution, but features-wise, it's quite strong. It's very good for protection, so the results are very good in the case of protection. I would rate it a two out of ten in terms of pricing."
"Its pricing is kind of in line with its competitors and everybody else out there."
"It is cost-effective compared to similar solutions. It fits for the small businesses through to the big businesses."
"The price of the product is not very economical."
"The cost depends on your chosen license type, like Pro or other licenses."
"Our customers have expressed that the price is high."
"It is very affordable and easy to license, and it allows us to onboard new analysts quickly, with a turnaround time of one day at most."
"At this time it is only a trial. After the trial period, I am going to purchase two licenses from SentinelOne."
"When it came to the price compared to other solutions we tested, SentinelOne Singularity gave us the price of our expectations whereas CrowdStrike could not."
"The tool's price is reasonable."
"SentinelOne makes licensing easy by reducing the number of modules or packages that they have to offer. A lot of other vendors make licensing very complicated with separate modules or separate costs. By bundling necessary features, SentinelOne ensures that security leaders are not left confused by options. This bundling of necessities has served our needs well."
"Pricing is a bit of a pain point. That's where we have not been able to convince all of our customers to use SentinelOne. The pricing is still on the higher side. It's almost double the price, if not more, of a normal antivirus, such as NOD32, Kaspersky, or Symantec."
"Its price is per endpoint per year. One of the features of its licensing is that it is a multi-tenanted solution. From an MSSP point of view, if I want to have several different virtual clouds of customers, it is supported natively, which is not the case with, for example, Microsoft Defender. Another nice thing about it is that you can buy one license if you want to. Some vendors insist that you buy 50 or 100, whereas here, you can just buy one."
"The license is paid annually and is competitive."
"The product's pricing differs from region to region depending on negotiations and the number of endpoints."
"The solution offers value for money."
"There is an annual license required to use this solution."
"It's an expensive solution. It would be nice if the cost were lower."
"Tanium is a more expensive solution in Latin America than some of the competitors, such as BigFix."
"It is higher than some competitors in the market."
"The solution is expensive but it's a good investment."
report
Use our free recommendation engine to learn which Endpoint Protection Platform (EPP) solutions are best for your needs.
910,454 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Construction Company
12%
Outsourcing Company
11%
Comms Service Provider
10%
Financial Services Firm
10%
Outsourcing Company
10%
Manufacturing Company
9%
Computer Software Company
8%
Financial Services Firm
7%
Financial Services Firm
14%
Government
10%
Manufacturing Company
9%
Healthcare Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business47
Midsize Enterprise21
Large Enterprise54
By reviewers
Company SizeCount
Small Business138
Midsize Enterprise72
Large Enterprise96
By reviewers
Company SizeCount
Small Business8
Midsize Enterprise4
Large Enterprise12
 

Questions from the Community

Cortex XDR by Palo Alto vs. Sentinel One
Cortex XDR by Palo Alto vs. SentinelOne SentinelOne offers very detailed specifics with regard to risks or attacks. ...
Comparing CrowdStrike Falcon to Cortex XDR (Palo Alto)
Cortex XDR by Palo Alto vs. CrowdStrike Falcon Both Cortex XDR and Crowd Strike Falcon offer cloud-based solutions th...
How is Cortex XDR compared with Microsoft Defender?
Microsoft Defender for Endpoint is a cloud-delivered endpoint security solution. The tool reduces the attack surface,...
Which is better - SentinelOne or Darktrace?
Which solution is better depends on which is more suitable specifically for your company. Darktrace, for example, is ...
What is your experience regarding pricing and costs for SentinelOne Singularity?
It is neither too costly, but definitely, it is one of the advantages that SentinelOne is quite adapted towards the p...
What needs improvement with SentinelOne Singularity?
I have encountered an issue related to the alerting mechanism in SentinelOne Singularity Complete. Sometimes I need t...
What needs improvement with Tanium?
While there is always room for improvement, I am pleased with Tanium.
What is your primary use case for Tanium?
The primary use case for Tanium ( /products/tanium-reviews ) is compliance, patching, and inventory as part of the co...
What advice do you have for others considering Tanium?
For smaller companies, Tanium is quite a big investment, and one needs to have a considerable setup to make it econom...
 

Also Known As

Cyvera, Cortex XDR, Palo Alto Networks Traps
Sentinel Labs, SentinelOne Singularity, Singularity Platform
Tanium Inc Cloud, Tanium XEM
 

Overview

 

Sample Customers

CBI Health Group, University Honda, VakifBank
Havas, Flex, Estee Lauder, McKesson, Norfolk Southern, JetBlue, Norwegian airlines, TGI Friday, AVX, Fim Bank
JPMorgan Chase, eBay, Amazon, US Bank, MetLife, pwc, Cerner, Delphi, MGM Grand, New York Life
Find out what your peers are saying about SentinelOne Singularity Endpoint vs. Tanium and other solutions. Updated: August 2026.
910,454 professionals have used our research since 2012.