

SentinelOne and ThreatLocker are leading competitors in the Managed Detection and Response (MDR) space. ThreatLocker holds an edge due to its rapid response times and high security control.
Features: SentinelOne's EDR platform offers superb analytics, excellent integration capabilities, and low false positive rates. It also delivers seamless deployment across various operating systems, coupled with good performance and easy scalability. ThreatLocker, on the other hand, excels in proactive threat detection with response times under a minute and comprehensive monitoring. Its notable features include ringfencing and network control, which ensure a secure environment.
Room for Improvement: SentinelOne needs to enhance its integration with SaaS platforms, improve reporting granularity, and make dashboards more accessible. It also lacks mobile and Linux endpoint support. ThreatLocker requires better granularity in exclusion settings and improved training clarity, alongside cost adjustments for small businesses. Its EDR capabilities need further development to match competitors.
Ease of Deployment and Customer Service: SentinelOne offers diverse deployment options, including hybrid and private clouds, with highly rated customer support, though response depth on complex issues could improve. ThreatLocker is mainly deployed in public cloud setups, offering rapid and effective support, though pricing and suitability for smaller businesses remain concerns. Both solutions have strong customer service.
Pricing and ROI: Both SentinelOne and ThreatLocker are considered expensive, yet they each provide substantial value by enhancing security posture and reducing breach risks. SentinelOne's pricing model is device-based and varies with services, whereas ThreatLocker fits into broader security packages, showcasing potential ROI through improved security outcomes.
For the overall return on investment, both time and money, I would say it is a full 20.
One customer who previously did not have anything like this mentioned having peace of mind, which is invaluable for a business owner.
It saves us from extensive remediation when a compromise occurs and aids in proactive measures before threats arise.
We now have enough to support technicians and bring someone else on board, which we could not do before because we were very inexpensive.
Their threat detection capability positively influences our security operations.
The technical support from SentinelOne Singularity MDR rates at 7.5 out of 10.
I would rate the actual technical support from SentinelOne Vigilance a nine.
The senior team at ThreatLocker is also very accessible in case we need any help.
ThreatLocker's support and Cyber Heroes have the absolute best support in the industry, in my opinion, bar none.
The ThreatLocker team has been fantastic, assisting us at every step.
The scalability rates at nine because they are quite scalable; being a cloud solution means we do not have to worry about scalability issues.
I can onboard a new customer in no time, freeing up time for my team to onboard as many as needed without it taking too much time.
Scalability is great; I would rate it a ten out of ten.
It scales with you.
I find it absolutely stable.
What's been wonderful about ThreatLocker is when we have found an issue and identified it, the entire team has taken those things seriously and gotten them remediated for us and our clients quickly, and more quickly than I've experienced with other vendors.
I would rate it around nine out of ten.
Additionally, for C-suite executives, there can be more non-technical content that provides a bird's eye view of organizational risk posture, rather than just detailed technical analyses.
Regarding disadvantages of SentinelOne Vigilance, there is no local hub server that I can use to download the updates and signatures only once.
The approximate reduction of the time to respond to incidents has been considerably improved, and it has really helped to reduce that time.
It is preferred that everything is seen under one tool rather than multiple platforms requiring multiple logins.
The Cyber Hero Support is not as effective as it is portrayed.
From an MDR perspective, the solution can have the ability to ingest logs from other sources, such as M365, firewalls, external sources, and even cloud SaaS-based platforms.
The pricing, licensing, and setup costs in general are quite affordable.
Pricing is a bit high, with a minimum of 50 devices.
We would have been one of the biggest partners in Ireland, so we got pretty good pricing at the start, and it is still competitive.
We have an essential users package where we charge per head, and then we have an advanced security offering that we charge per head, and we've baked ThreatLocker into that advanced offering for our clients.
I am actually able to synthesize machine learning with human experience to manage complex threats in IRs.
The false positive rate in SentinelOne Singularity MDR is considerably lower compared to other solutions.
The impact of the threat hunting capabilities on detecting known and emerging threats in real-time is notable, and with the AI, it helps for real-time threat hunting.
We've seen an 80% to 90% improvement in remediation.
There is a tremendous amount that is helpful, such as their recording, watching the systems, locking down the systems, and their training.
When the update rolled out for version 18, it was able to catch a 3CX Supply Chain attack where a client had downloaded a DLL file that was trying to steal the authenticated Office 365 or authenticated G Suite tokens.
| Product | Mindshare (%) |
|---|---|
| SentinelOne Vigilance | 3.5% |
| ThreatLocker Cyber Hero MDR | 1.5% |
| Other | 95.0% |

| Company Size | Count |
|---|---|
| Small Business | 16 |
| Midsize Enterprise | 2 |
| Large Enterprise | 6 |
| Company Size | Count |
|---|---|
| Small Business | 8 |
SentinelOne Wayfinder Managed Detection & Response offers robust protection with analytics, behavior analysis, and real-time monitoring to safeguard enterprise environments against cyber threats, ensuring secure operations across platforms.
SentinelOne Wayfinder Managed Detection & Response is designed for comprehensive endpoint protection and real-time monitoring of malware threats. Employing machine learning, the service enhances security through automatic reports and comprehensive threat hunting. Features like real-time incident response and rollback functionality reinforce security measures, while 24/7 coverage and proactive breach readiness ensure protection. Its deployment across private clouds and on-premises supports managed SOC teams.
What are the most important features?In industries like finance and healthcare, organizations use SentinelOne Wayfinder Managed Detection & Response to protect sensitive data and ensure compliance. By utilizing this service for comprehensive security measures, they maintain a secure infrastructure in dynamic environments, safeguarding critical operations.
ThreatLocker Cyber Hero MDR offers advanced threat detection and response capabilities, providing organizations with comprehensive security by monitoring and blocking unauthorized actions to maintain a robust security posture.
ThreatLocker Cyber Hero MDR enhances cybersecurity with its rapid detection and response, 24/7 monitoring, and features like ringfencing. It focuses on limiting application access to block potential threats such as PowerShell scripts and supply chain attacks. Users benefit from a significant reduction in workload and receive quick responses, maintaining robust security through a customizable allowlist and application elevation features. While the platform excels in security measures, areas for improvement include better integration, an intuitive authentication process, and enhanced customization options in user alerts. Affordability may be a concern for small businesses, and there is room for improvement in EDR capabilities compared to SentinelOne.
What are the key features of ThreatLocker Cyber Hero MDR?In industries where protecting sensitive data is critical, such as healthcare, finance, and government, ThreatLocker Cyber Hero MDR is implemented to secure endpoints and servers. Organizations deploy it to establish a zero trust environment, manage administrative privileges, and prevent unauthorized software installations. Its capability to monitor continuously and control installation processes ensures reduced risks of cyber attacks, enhanced compliance with security protocols, and assures continuous support and incident response integration specific to industry requirements.
We monitor all Managed Detection and Response (MDR) reviews to prevent fraudulent reviews and keep review quality high. We do not post reviews by company employees or direct competitors. We validate each review for authenticity via cross-reference with LinkedIn, and personal follow-up with the reviewer when necessary.