No more typing reviews! Try our Samantha, our new voice AI agent.
AGM IT Security at Page Industries Ltd
Real User
Top 20
Feb 16, 2025
Achieved enhanced endpoint protection with AI-based zero-day threat mitigation and improved incident response time
Pros and Cons
  • "The XDR is a valuable feature."
  • "I think they should consider enhancing complete visibility."

What is our primary use case?

I use it for our XDR solution, managing various endpoints including Windows and Deepak. There are around twenty-five hundred endpoints where SentinelOne EDR or the Synchrony Solution is installed, helping me manage all my files. It is a next-generation antivirus solution with zero-day protection using AI or ML-based logic running in the backend to protect endpoints. Currently, there is no integration. It's an independent solution supporting my endpoint protection.

What is most valuable?

The XDR is a valuable feature. The AI-based engine protects against various behaviors and takes action on files being accessed. In terms of protection, I have an advanced app providing visibility of all my endpoints, which was not the case before. My time to respond to incidents has reduced, making it much more complete. I have the ability to isolate endpoints if identified as having malicious files or serious activity.

What needs improvement?

I think they should consider enhancing complete visibility. I haven't explored the network-related aspects, but if lacking, it is an area for improvement. Providing a single pane of visibility for the end user would be beneficial. This means not just seeing endpoints, but also the network and other connected devices through the Singularity portal. This would enhance decision-making and improve security posture.

For how long have I used the solution?

I have used the solution for three years.

Buyer's Guide
SentinelOne Singularity Endpoint
September 2026
Learn what your peers think about SentinelOne Singularity Endpoint. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
915,817 professionals have used our research since 2012.

What do I think about the stability of the solution?

It's a stable solution. My endpoints use minimal resources, and I have encountered no problems with installation, making it a stable product.

What do I think about the scalability of the solution?

From the console or admin perspective, as it is a SaaS product, scalability and management pose no problems. It's all auto-scale and auto-categorized, configuring automatically.

How are customer service and support?

I think they were responsive, but there was a delay in reaching out to my team on one incident report. This happened only once, which is why I am rating them eight out of ten.

Which solution did I use previously and why did I switch?

I had a normal antivirus solution before upgrading to the next-gen XDR solution, which is SentinelOne.

How was the initial setup?

The setup is very straightforward. It took one month. Connecting to users was a manual process, but all network-connected devices were integrated without any challenges.

What about the implementation team?

There was a three-member team from the vendor side assisting with configuration and communication with my internal team. One of my team members coordinated with the end customers, who are the employees of my organization.

What was our ROI?

There isn't significant cost saving as such, but it has protected me from numerous virus or malware infections. This demonstrates an ROI.

What's my experience with pricing, setup cost, and licensing?

It's a fixed price per endpoint arrangement.

Which other solutions did I evaluate?

I have not used alternative solutions for the XDR solution. We were using an alternative antivirus solution before, but finalized on SentinelOne after considering other options.

What other advice do I have?

I rate the solution nine out of ten. It prevented potential losses, though not directly affecting ROI. To make it work effectively, ensure proper configuration and understanding of your network landscape. Initially set it to detect mode, then to protect mode, and later to auto-protect and quarantine mode. Allow one to three months to understand the network and work with a knowledgeable partner.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
SVP IT at AS IT Consulting Pvt. Ltd.
Real User
Top 5Leaderboard
Jan 20, 2026
Security correlations have boosted compliance operations and improve user productivity
Pros and Cons
  • "The main benefits the end-user gets from Singularity Platform are, first, the program itself being very small, and then we get better output from applications running on their systems."
  • "In my opinion, the real-time monitoring capabilities in Singularity Platform sometimes work and sometimes they don't, because there are a lot of false positives and people use unsigned applications which get deleted or quarantined by the product."

What is our primary use case?

My main use cases for Singularity Platform are compliance and security operations.

What is most valuable?

I have found the correlations in Singularity Platform to be the most valuable. The main benefits the end-user gets from Singularity Platform are, first, the program itself being very small, and then we get better output from applications running on their systems. The output of the users has gone up 50%, although I don't remember other benefits at this time.

What needs improvement?

There are a lot of false positives in that, which is why I'm not working with it. The use of the fraud detection feature in financial services in Singularity Platform depends on the compliances that are applicable to the organization, so it may be useful for some and may not be useful for others. I did that by myself, not with the help of Singularity Platform. In my opinion, the real-time monitoring capabilities in Singularity Platform sometimes work and sometimes they don't, because there are a lot of false positives and people use unsigned applications which get deleted or quarantined by the product. It's not a 100% foolproof solution.

A point for improvement for SentinelOne is that the false positives are huge since people in India, at least, are using homegrown applications which get blocked. Right now, Singularity Platform is working fine, but people have concerns about enhancements like website monitoring that can be done through Singularity Platform itself, so they don't need to buy any SASE products for people working from home to control their browsing. If that feature can be included, it will be a big advantage.

For how long have I used the solution?

I have been working with Singularity Platform for almost two years now.

What do I think about the stability of the solution?

I had some issues with that.

What do I think about the scalability of the solution?

I would rate the scalability a nine.

How are customer service and support?

Technical support will always be between six and seven.

How would you rate customer service and support?

Positive

How was the initial setup?

The initial setup for Singularity Platform is very simple; the dashboard is quite simple, and the agents' installations are very simple, like one click, I would say.

What's my experience with pricing, setup cost, and licensing?

For pricing, I would say it's a six. It could be cheaper, as I understand.

Which other solutions did I evaluate?

The main competitor for Singularity Platform is CrowdStrike at number one, and the second is Trellix, which is coming up very fast. The leader on the market is still SentinelOne, but if they don't add some add-ons to their product like Trellix and CrowdStrike have, they may lag very soon. If we do only apple-to-apple comparison on Singularity Platform, then I'll give it ten marks.

What other advice do I have?

Singularity Platform functions as a security information and event management solution, and that is an inbuilt part of it. I believe in the correlations that I get because we work on it, but we don't use the Purple AI part of it. I'm not able to get clarity regarding the real-time personalization feature in Singularity Platform. I do not use the real-time personalization feature in Singularity Platform. It is a matter of false positives when people use it in my area.

Regarding the impact of Singularity Platform on supply chain processes, I don't have much on it, but it's a good product and the tracking is better with the log capturing and the data that we get from it. The customer does require customizations on the dashboards as per the requirement of their organizations; if it's manufacturing, medical, or financial institution or banking, then they will have different requirements for their dashboards, which are yet not available, so we have to actually build up those dashboards for them. I can recommend Singularity Platform to other users. I have provided this review a rating of 9.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: My company has a business relationship with this vendor other than being a customer. reseller
Last updated: Jan 20, 2026
Flag as inappropriate
PeerSpot user
Buyer's Guide
SentinelOne Singularity Endpoint
September 2026
Learn what your peers think about SentinelOne Singularity Endpoint. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
915,817 professionals have used our research since 2012.
reviewer2890692 - PeerSpot reviewer
2nd Analyst at a tech vendor with 10,001+ employees
Real User
Top 20
Aug 22, 2026
Storyline has improved incident investigations and now needs deeper process visibility
Pros and Cons
  • "SentinelOne Singularity Endpoint positively impacts my organization by saving time because I can see many details right away without needing to look for everything in some queries or anywhere."
  • "To improve SentinelOne Singularity Endpoint, I want to continue working on this and provide even more data, more visibility, and everything clearer and faster."

What is our primary use case?

My main use case for SentinelOne Singularity Endpoint involves handling suspicious PowerShell activity, which is probably the most common one.

When I mention suspicious PowerShell activity, SentinelOne Singularity Endpoint helped me detect or respond to that incident with the Storyline feature, which I found excellent. It visually shows you what is going on, where, when, what the grandparent process is, what the parent process is, and what the child process is, so you can quickly go through it and gain insights on that.

I have more to add about my main use case or the types of incidents SentinelOne Singularity Endpoint helped me with. It is not just one use case; it is usually EDR and some XDR that helps you show various details. It is good that you can take actions from there, and it is really user-friendly to search something in the logs.

What is most valuable?

The best features SentinelOne Singularity Endpoint offers, which I found most valuable, is the Storyline, as it helps really well and provides deep visibility of everything.

SentinelOne Singularity Endpoint positively impacts my organization by saving time because I can see many details right away without needing to look for everything in some queries or anywhere. From the first vital glance, I can see the main information, which really saves time.

In terms of how much time it saved me or my team, if a usual ticket took about 20 minutes to investigate, with this solution it takes about 10 minutes; it is probably two times better.

What needs improvement?

To improve SentinelOne Singularity Endpoint, I want to continue working on this and provide even more data, more visibility, and everything clearer and faster. I guess everywhere could use a few additional functions, but they are not really needed.

I would add more about the needed improvements regarding features. I mean more deeper insights and bigger visibility so that when you have any process, you can click and it can show you everything for that process, so you can see really quickly everything that you need, enabling quick analysis and decision-making.

For how long have I used the solution?

I have been using SentinelOne Singularity Endpoint for a few months.

What do I think about the stability of the solution?

SentinelOne Singularity Endpoint is pretty much stable.

What do I think about the scalability of the solution?

The scalability of SentinelOne Singularity Endpoint is good.

Which solution did I use previously and why did I switch?

I did not previously switch from a different solution. We just added it for some clients, depending on what they wanted, but I was using CrowdStrike and Microsoft XDR as well.

What was our ROI?

I believe I have seen a return on investment from using SentinelOne Singularity Endpoint, though I am not sure and was not involved in prices. I guess it helps.

Which other solutions did I evaluate?

Before choosing SentinelOne Singularity Endpoint, I did not evaluate other options because I was not involved in that process.

What other advice do I have?

My advice to others looking into using SentinelOne Singularity Endpoint is to try it and use it to see if you it; it is good for me. I would rate this product a 7 out of 10.

Which deployment model are you using for this solution?

Hybrid Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Aug 22, 2026
Flag as inappropriate
PeerSpot user
reviewer2888406 - PeerSpot reviewer
Responsable Programme Cybersécurité at a retailer with 10,001+ employees
Real User
Top 10
Aug 17, 2026
Centralized endpoint protection has provided granular policies and improved threat detection
Pros and Cons
  • "SentinelOne Singularity Endpoint has helped us consolidate our security solutions by providing a complete overview of all of our devices."
  • "The UX in SentinelOne Singularity Endpoint can be quite difficult sometimes."

What is our primary use case?

Our main use case for SentinelOne Singularity Endpoint is to protect all devices in the company. We are protecting all our devices by deploying a SentinelOne Singularity Endpoint sensor to block all threats that can come into the devices, and we have some interconnection with our SIEM and SOC company to ensure that we will not miss any threat.

We are also using SentinelOne Singularity Endpoint to realize the flow of which devices are trying to contact to ensure that no external compromised flows are used by collaborators.

What is most valuable?

The best feature for me in SentinelOne Singularity Endpoint is the granularity of the policy that we can have. As you might know, the ADEO group is quite big with several business units, and each business unit will have its own policies. Our main issue at the beginning of the project was to deal with these different business units, and we had the opportunity with SentinelOne Singularity Endpoint to specify very granular policy for each business unit.

This granularity in SentinelOne Singularity Endpoint will offer us more control because each business unit will have its specific business capacity, which can trigger some alerts. We will have to add some whitelist and sometimes some blacklist to ensure to catch all of the threats on the group.

Another feature is the possibility to have some dashboarding directly on SentinelOne Singularity Endpoint. We had in the past other tools, and the dashboarding part was not as good as SentinelOne Singularity Endpoint, so we are really enjoying this part.

Thanks to SentinelOne Singularity Endpoint, the ADEO group can manage all sensors for all business units instead of having different EDR spread across all the business units. In the past, we had three or four different EDR; now we only have one SentinelOne Singularity Endpoint for our group, and we have the opportunity to keep the management in SentinelOne Singularity Endpoint by ADEO, with all business units able to manage their own deployment of the sensor and policy management.

SentinelOne Singularity Endpoint has helped us consolidate our security solutions by providing a complete overview of all of our devices. We deployed SentinelOne Singularity Endpoint in servers, point of sale, workstations, and so on. Thanks to the SentinelOne Singularity Endpoint solution, we now have a complete overview of all of our devices, their level of security across the business unit, and in one dashboard, we can manage all alerts and threats retrieved by SentinelOne Singularity Endpoint.

What needs improvement?

The UX in SentinelOne Singularity Endpoint can be quite difficult sometimes. We had in the past other EDR, and sometimes the former EDR was simpler than SentinelOne Singularity Endpoint, so at the beginning, it can be really complex to understand how it works, how to manage the policies, and how to handle the RBAC. We had to follow the documentation and the different knowledge transfers offered by SentinelOne Singularity Endpoint, but we are quite good now, so we can manage SentinelOne Singularity Endpoint by ourselves.

Except for the UX part of SentinelOne Singularity Endpoint which can be time-consuming, I do not have any other improvements to share.

I chose eight out of ten because even if SentinelOne Singularity Endpoint is quite good in our day-to-day works, there are some improvements needed, especially on the UX part. The UX part is really important for us because we have some turnover in the cybersecurity team, so we would like to be sure that newcomers can handle SentinelOne Singularity Endpoint quickly, and sometimes we have to share knowledge transfers, which can be time-consuming.

For how long have I used the solution?

I have been working in my current field for more than ten years.

What do I think about the stability of the solution?

SentinelOne Singularity Endpoint is stable; so far, we did not have any issues with it.

What do I think about the scalability of the solution?

So far, we have more than one thousand devices, with a total of one hundred thousand devices deployed, which indicates that the scalability is really good because we did not have any issues.

How are customer service and support?

The customer support for SentinelOne Singularity Endpoint was great; as soon as we had an issue, they were able to answer our questions.

Which solution did I use previously and why did I switch?

We used another solution for the whole group, but we were not satisfied with the log management offered and found it less effective with threat detection.

How was the initial setup?

We had the opportunity to interconnect SentinelOne Singularity Endpoint with our current SOC and SIEM tool, and the interconnection was really great and easy. SentinelOne Singularity Endpoint can offer some direct connectors, and we used one of them to ensure that everything can be configured quickly and easily, so we were really satisfied with this part.

What was our ROI?

SentinelOne Singularity Endpoint really reduced the number of threats. SentinelOne Singularity Endpoint reduced our MTTD by roughly forty percent. It reduced our MTTR by roughly thirty percent, depending on which business unit you are dealing with because some business units do not even have any cyber expert, making the alerts more complex to handle.

What's my experience with pricing, setup cost, and licensing?

The experience with the pricing in SentinelOne Singularity Endpoint can be quite difficult to understand because there are several licensing lines, and sometimes it can be complicated to know which lines will be used. Thanks to the help of the SentinelOne Singularity Endpoint team, we had a great test offer to follow our needs. Compared to our previous solution, the licensing part of SentinelOne Singularity Endpoint was less expensive, so we saved some money.

Which other solutions did I evaluate?

We only evaluated one other solution, which was Trend Micro.

What other advice do I have?

I would advise others looking into using SentinelOne Singularity Endpoint to ensure they have some experts able to manage the configuration of the product because it can be really difficult to manage. I would rate SentinelOne Singularity Endpoint an eight out of ten.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Google
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Aug 17, 2026
Flag as inappropriate
PeerSpot user
reviewer2846475 - PeerSpot reviewer
Senior Security Engineer at a consultancy with 1-10 employees
Real User
Top 20
Jun 3, 2026
Automated protection has minimized threats and reduced detection and response times dramatically
Pros and Cons
    • "It would be nice if they improved the user interface."

    What is our primary use case?

    My main use case for SentinelOne Singularity Endpoint is endpoint detection and monitoring as well as monitoring devices. An example of how I use SentinelOne Singularity Endpoint for endpoint detection is monitoring the device to see if there is any suspicious activity.

    SentinelOne Singularity Endpoint has a very quick detection capability, so we managed to detect a virus and quarantine it during a recent situation.

    What is most valuable?

    The best features SentinelOne Singularity Endpoint offers are the fact that it quarantines any malicious activity very quickly and it detects by hashes. When threats such as ransomware or malware are detected, it alerts me quickly and quarantines the file.

    SentinelOne Singularity Endpoint's scalability is very easy to scale because it just takes adding devices since the main server is already set up. SentinelOne Singularity Endpoint is deployed in my organization on-premises via agents that are installed on each device. SentinelOne Singularity Endpoint has impacted my organization positively as we have been able to minimize threats, and it is automated.

    What needs improvement?

    It is very difficult to say how SentinelOne Singularity Endpoint can be improved as it is such a great product. It would be nice if they improved the user interface. I wish it was easier to navigate the dashboard and that it was more user-friendly.

    For how long have I used the solution?

    I have been using SentinelOne Singularity Endpoint for three years in total.

    What do I think about the stability of the solution?

    SentinelOne Singularity Endpoint is stable.

    What do I think about the scalability of the solution?

    SentinelOne Singularity Endpoint's scalability is very easy to scale because it just takes adding devices since the main server is already set up.

    How are customer service and support?

    The customer support is great and very easy.

    I would rate the customer support on a scale of 1 to 10 as a 10, and I would give customer support a 9 from 1 to 10.

    Which solution did I use previously and why did I switch?

    I previously used Microsoft Defender. I switched because SentinelOne Singularity Endpoint has a lot more AI capabilities and is much easier to use and has a better detection procedure.

    How was the initial setup?

    My experience with pricing, setup cost, and licensing was very easy and simple.

    What about the implementation team?

    Singularity Complete has helped me consolidate my security solutions, as I was able to get rid of a lot of unnecessary software.

    What was our ROI?

    I have seen no return on investment as I do not deal with finances.

    What's my experience with pricing, setup cost, and licensing?

    My experience with pricing, setup cost, and licensing was very easy and simple.

    Which other solutions did I evaluate?

    I evaluated other options such as Microsoft Defender as well as Kaspersky before choosing SentinelOne Singularity Endpoint.

    What other advice do I have?

    SentinelOne Singularity Endpoint has helped reduce my organization's mean time to detect, or MTTD, by 56 percent. SentinelOne Singularity Endpoint has helped reduce my organization's mean time to respond, or MTTR, by 50 percent.

    My advice to others looking into using SentinelOne Singularity Endpoint is that they should evaluate the product and run a proof of concept to see if it is well-suited for the organization.

    Regarding SentinelOne Singularity Endpoint's AI capabilities, I believe it has a lot of governance and security features that are built-in, which I am very impressed with. It is very accurate in terms of its detection regarding SentinelOne Singularity Endpoint's AI capabilities in terms of accuracy and reliability of its output.

    I am very impressed with SentinelOne Singularity Endpoint's ability to ingest and correlate across my security solutions because the solution is able to do its own thing with very little interaction with anything else.

    Singularity Complete has helped reduce alerts by 56 percent as it was able to mitigate false positives. Singularity Complete has saved my staff a couple of hours every day as less human intervention is required and they are able to release the devices. I would rate this solution overall a 10.

    Which deployment model are you using for this solution?

    On-premises

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Microsoft Azure
    Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
    Last updated: Jun 3, 2026
    Flag as inappropriate
    PeerSpot user
    Ijeoma Nkemjika - PeerSpot reviewer
    Customer Success Manager at Digitank Technology
    Reseller
    Top 20
    Sep 27, 2025
    Has improved threat hunting through query suggestions and contextual incident storylines
    Pros and Cons
    • "SentinelOne Singularity Complete has shown a return on investment with its ability to detect threats at approximately 99% efficiency."
    • "The main area for improvement relates to Linux compatibility. When deploying on a Linux system, the process isn't as seamless compared to other operating systems."

    What is our primary use case?

    I have used SentinelOne Singularity Complete in a SOC environment where most customers were utilizing it. 

    How has it helped my organization?

    The solution has been helpful especially for the infrastructure security team. They can focus their energy on other business projects and priorities while having peace of mind knowing that even without real-time operation, SentinelOne Singularity Complete can detect vulnerabilities and contain threats until they intervene. This allows them to work on other projects, develop security policies, and strengthen their defense. The team can address other security loopholes while SentinelOne Singularity Complete manages their infrastructure.

    What is most valuable?

    One of the features I particularly appreciate is the hunting capability, specifically being able to use deep visibility for threat hunting. 

    It's quite elaborate. It allows you to create and manage queries easily. Even if you're not very proficient in the language being used, it suggests the correct syntax when you type in plain text. If there's an error, it points out where you're wrong, enabling you to adjust the syntax. This feature is particularly beneficial for threat hunting using the deep visibility feature of SentinelOne Singularity Complete.

    Additionally, the platform allows for compartmentalization, which is great because we use it for about 13 customers. It enables us to manage different environments from a single console and download relevant data for each customer.

    What stands out is that this solution is not just about detection; it's also about response and containment. When it addresses an incident, it explains what occurred and suggests actions to take before further investigation.

    Another excellent feature is its ability to filter events from the same company, helping to reduce noise. For instance, if a single user performs various actions that would typically trigger hundreds of alerts, this system consolidates those activities under that one user. This approach allows for tracking related events together rather than generating multiple alerts. As a result, you can analyze an incident from a holistic perspective rather than just viewing individual alerts in isolation. Overall, these capabilities enhance the effectiveness of threat management and incident response. That's my take on it!

    It's capable of integrating with SIEM and other solutions. It offers enhanced interoperability. 

    What needs improvement?

    The main area for improvement relates to Linux compatibility. When deploying on a Linux system, the process isn't as seamless compared to other operating systems. They could enhance this by providing an easier way to implement or deploy on Linux OS systems.

    For how long have I used the solution?

    I have used SentinelOne Singularity Complete for four years.

    What do I think about the stability of the solution?

    There have been no stability issues at the moment.

    What do I think about the scalability of the solution?

    It's scalable.

    How are customer service and support?

    Their support is very good. When we encounter an issue, we quickly raise support tickets, and the response time is very good.

    How would you rate customer service and support?

    Positive

    How was the initial setup?

    It's not complex. It's straightforward, and the support is very good. 

    What was our ROI?

    SentinelOne Singularity Complete has shown a return on investment with its ability to detect threats at approximately 99% efficiency.

    What's my experience with pricing, setup cost, and licensing?

    It's affordable. The pricing is competitive. 

    SentinelOne Singularity Complete has proven beneficial in a specific case. In one instance, a customer had Microsoft licenses that were very expensive at the enterprise level. By implementing SentinelOne Singularity Complete, they were able to reduce their license plans and focus on this solution because it offered more robust features than their previous solution.

    What other advice do I have?

    I would rate SentinelOne Singularity Complete a ten out of ten. It's a good solution.

    Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
    PeerSpot user
    Greg Hansen - PeerSpot reviewer
    Director, Information Technology at Lenovo
    Video Review
    Real User
    Top 5
    Oct 30, 2024
    Our security analysts can efficiently manage incidents and investigations with its succinct interface
    Pros and Cons
    • "We are freeing up our resources and our security analysts' time to focus on the most critical threats to our landscape by not having to chase down false positives."
    • "SentinelOne can continue to make the presentation of relevant and timely data to the analysts as succinct and clear as possible. It will allow analysts to execute remediation or resolution with the least amount of clicks."

    What is our primary use case?

    We have the Singularity Endpoint Detection platform along with the MDR service. We are using their Singularity Enterprise offering along with Vigilance Pro.

    We are currently in the process of deploying it. We started with the deployment earlier this calendar year with a goal of reaching 30,000 endpoints this year. We have deployed to about 25,000 endpoints to date. Our end goal is 100,000, but that will be phased in over the next year.

    How has it helped my organization?

    Our deployment experience has been excellent. We have received a ton of support from their customer success team. We are using this initial deployment to tune the product to make sure it is not causing performance issues on our endpoints. We are going about it in a very methodical fashion.

    It has helped us achieve business goals in a few areas. Even though we are early in our adoption, there are a few areas where I have seen benefits. One is around the technology, the solution itself. It provides our security analysts with a very succinct and usable interface that they can use to effectively and efficiently manage incidents and investigations. 

    The second area is around the MDR. This has been a huge benefit to us compared to our prior solution. We used to get a lot of false positives. That took up the time of our security analysts, which then took away time from addressing real problems.

    The risk management at Lenovo has improved greatly over our prior toolset. We have identified risks that we would not have otherwise identified with our prior implementation.

    Our analysts' efficiency has gone up tremendously. We are not chasing false positives. The tool provides timely and relevant information to our analysts so that they can address the events with confidence. They know they are working on the right activities, and then along with the managed service, they are not chasing rudimentary incidents. Those are being resolved before they can get to our team.

    It has definitely helped us reduce noise. In the prior platform, which we are phasing out, the false positive rate was tremendously high. That caused a huge amount of inefficiency in the team.

    It has helped us increase our incident response because we are working as a team. We not only have an improved platform for detecting and managing incidents; we are also partnering with SentinelOne on the MDR and the managed service aspect of it.

    It has helped us improve our mean time to respond from a perspective of seeing what is happening. I do not have any metrics related to the percentage of that improvement.

    It has highlighted the risk of insider threats, and we have found that on multiple occasions. It is hard to compare if they would have been caught in our prior solution, but we have increased visibility into what is going on across our network and the machines that are connected to it.

    SentinelOne is an integral part of our AI strategy. We have recently got a chief AI officer in our organization. He happened to be our chief security officer, so we take AI very seriously. There are two things that AI can impact. We can leverage SentinelOne to help us protect the AI models that we develop and use, but we can also leverage AI for endpoint protection in the product itself. We can utilize the AI offering to improve our response rate and mean time to respond.

    What is most valuable?

    We are freeing up our resources and our security analysts' time to focus on the most critical threats to our landscape by not having to chase down false positives. In conjunction with the MDR, many of those incidents and events are mitigated and resolved without any intervention from our team.

    What needs improvement?

    SentinelOne can continue to make the presentation of relevant and timely data to the analysts as succinct and clear as possible. It will allow analysts to execute remediation or resolution with the least amount of clicks.

    For how long have I used the solution?

    We started with the deployment earlier this calendar year.

    How are customer service and support?

    The support from SentinelOne has been second to none, exceeding expectations. Maybe we are in the honeymoon period, but they have definitely exceeded expectations. I have been part of many deployments, not just of cybersecurity platforms but also of other platforms, and SentinelOne, in comparison, has been second to none.

    How would you rate customer service and support?

    Positive

    What's my experience with pricing, setup cost, and licensing?

    We purchase it through CDW.

    Which other solutions did I evaluate?

    One of the primary considerations in evaluating EDR and identity security vendors was around the effectiveness of the detection and the ability to tune the solution to fit our needs. The presentation of the data to our analysts and the ability to detect events and threats that were not detected by our prior platform played a big role in that. We also were able to test out the MDR service as part of our proof of concept. That pushed it over the edge from anything we experienced with other vendors.

    Earlier, we had a high false positive rate coming in, which would take up our analysts' time. In addition to that, our prior vendors or other vendors would report threats and incidents to our team but not what action to take to resolve them. The huge difference that we have seen is that we are now getting feedback from SentinelOne and the MDR team, and it is coming back completely resolved and completed. We are more on an information basis, and we do not have to spend any time on resolution or investigation.

    What other advice do I have?

    Anyone considering changing their endpoint detection or SIEM solution should consider SentinelOne. It offers benefits in the product and technology aspect, service aspect, and partnership, allowing us to influence the roadmap and plan our cyber defenses.

    Even though we are early on in our adoption, we have had a direct line of contact with the product team. We have been able to provide feature requests. We are not simply a customer of SentinelOne. We view it as a partnership. We can influence the roadmap. Likewise, SentinelOne is providing us a vision of their roadmap, and we can plan accordingly how to steer our cyber defenses.

    As it stands today, I would rate SentinelOne Singularity Complete a nine out of ten simply because we are so early in our adoption that we are not taking full advantage of all the aspects of the solution. We will continue to grow and mature alongside the product.

    Which deployment model are you using for this solution?

    On-premises
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    reviewer2687556 - PeerSpot reviewer
    Cyber Consultant at a consultancy with 11-50 employees
    Consultant
    Top 10
    Apr 13, 2025
    User-friendly interface and policy customization helps with server protection
    Pros and Cons
    • "The interface of SentinelOne Singularity Complete is user-friendly, and we can quickly find what we need."
    • "Overall, I would rate SentinelOne Singularity Complete a nine out of ten because nothing is perfect, but it is close."
    • "SentinelOne Singularity Complete is the best EDR in the market, but it will evolve, though I have concerns about using US partners in Europe due to the geopolitical context. It is better to work with European companies."
    • "The main issue with SentinelOne Singularity Complete was the process memory used for Linux servers, which generated a lot of tickets and incidents due to the high load of disk consumption and memory."

    What is our primary use case?

    Our main use case is to protect all the Linux servers. We use it only for servers, not for users.

    How has it helped my organization?

    SentinelOne Singularity Complete is one of the most mature solutions available. It shows great benefits over time.

    We can install filters to analyze every alert, and make some whitelists, blacklists, and exceptions, thus helping reduce alerts.

    It can reduce the organization's risk. It gives better control to our limited team resources.

    It already has AI capabilities, which is one of their advantages.

    What is most valuable?

    When you select a policy for a type of server, such as an Active Directory, we can apply a dedicated policy. We can have a dedicated policy for Exchange Server and a dedicated policy for MS SQL, Oracle server, etc.

    The interface of SentinelOne Singularity Complete is user-friendly, and we can quickly find what we need.

    What needs improvement?

    The main issue with SentinelOne Singularity Complete was the process memory used for Linux servers, which generated a lot of tickets and incidents due to the high load of disk consumption and memory. The problem was on all systems, but especially on Linux servers. It might have already been fixed.

    SentinelOne Singularity Complete is the best EDR in the market, but it will evolve, though I have concerns about using US partners in Europe due to the geopolitical context. It is better to work with European companies.

    For how long have I used the solution?

    I have been using SentinelOne Singularity Complete for approximately four years.

    What do I think about the stability of the solution?

    For stability, I would rate it a nine, as I have experienced only the issue of overload.

    How are customer service and support?

    The technical support from SentinelOne Singularity Complete is very active and good, with a strong knowledge base available online. The response time of technical support is satisfactory and acceptable.

    I would rate their support a nine out of ten based on reactivity and the solutions they provide; this is based on my team's interactions, not mine.

    How would you rate customer service and support?

    Positive

    Which solution did I use previously and why did I switch?

    For Windows servers, we are using Defender. SentinelOne Singularity Complete is only used for Linux servers. 

    How was the initial setup?

    The initial setup was not really complex; we only needed one on-premise management server to deploy to different servers. It took about two months for about 300 servers.

    What about the implementation team?

    I am the third party assisting in the deployment.

    What's my experience with pricing, setup cost, and licensing?

    I don't know about the licensing model. It seems easy, but it's not my area of expertise. I don't have information on how it compares to its competitors, but the pricing is per device.

    Which other solutions did I evaluate?

    We conducted some PoCs between SentinelOne Singularity Complete, Defender, and Carbon Black, and we decided to go with SentinelOne Singularity Complete based on usability. 

    What other advice do I have?

    It is unclear if it has helped reduce our organization's mean time to detect or respond because we have a platform with four people, and we are using SOC as well. Our main activities are done by four people, and we don't have much time to conduct thorough investigations.

    I cannot assess SentinelOne Singularity Complete's ability to be innovative because we stayed with it after choosing it and never compared it with others.

    Overall, I would rate SentinelOne Singularity Complete a nine out of ten because nothing is perfect, but it is close.

    Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
    PeerSpot user
    Asim Naeem - PeerSpot reviewer
    Principal IT Security & Compliance at IBEX Holdings Ltd
    Real User
    Top 10
    Aug 15, 2024
    It integrates well with other platforms, is user-friendly, and is stable
    Pros and Cons
    • "Unlike other endpoint solutions like Kaspersky or Trend Micro, SentinelOne's agents are exceptionally lightweight, updating seamlessly without consuming significant network or system resources."
    • "When SentinelOne Singularity Complete is used as the central hub for viewing alerts from all integrated security solutions, it is challenging to identify the specific solution that triggered each alert."

    What is our primary use case?

    As a company with 30,000 employees and 26,000 endpoints worldwide, we have diverse operational needs that SentinelOne Singularity Complete effectively addresses.

    SentinelOne Singularity Complete effectively addresses numerous challenges. As a cloud-based SaaS solution, it seamlessly protects office and remote workers, safeguarding laptops and other devices. Its comprehensive coverage extends to cloud infrastructure across multiple operating systems like iOS, Linux, and Windows, including Kubernetes environments. This versatility, coupled with its ability to fulfill various use cases, has made SentinelOne Singularity Complete our trusted security solution for the past four years.

    How has it helped my organization?

    SentinelOne Singularity Complete integrates with our other security solutions, correlating data from NDR, ADR, SIEM, and XDR tools. All this information is consolidated within SentinelOne, providing a centralized access point.

    SentinelOne Singularity Complete has helped us streamline our security operations by consolidating multiple solutions into a single platform. We are currently in the process of acquiring a threat intelligence platform to complete our security stack.

    We use Ranger to monitor our network and track connected devices. This is crucial because it helps us quickly identify unauthorized machines connected to our infrastructure, including personal devices. We have additional security measures in place, but Ranger provides an extra layer of protection. It also alerts us if the SentinelOne Singularity Complete agent is missing from any new or existing machines, allowing us to take appropriate action.

    SentinelOne Ranger's agentless and hardware-independent nature is crucial for our environment with 26,000 endpoints, as manual management of such a large number would be extremely challenging.

    Ranger uses a multi-layered approach to prevent vulnerable devices from being compromised. We employ scanners, network configurations, and a risk scanner to assess devices, endpoints, servers, and cloud infrastructures. Vulnerability reports and timelines for remediation are shared with device owners or custodians. This proactive strategy enables us to address vulnerabilities efficiently and secure our infrastructure.

    SentinelOne Singularity Complete has significantly enhanced our security posture. While no system is impenetrable, this solution has brought us closer to achieving a high level of protection, ensuring we maintain at least a 90 percent security level.

    Our team is dedicated to refining alerts and eliminating false positives from our solutions. Additionally, a team is responsible for identifying and excluding alerts from the solution. We can manually expedite this process by reviewing these elements and utilizing our security tools. We have been able to reduce the alert volume by 20 percent.

    Our 30-member Security Operations Center team has been able to redirect their focus to other tasks due to the time saved after implementing SentinelOne Singularity Complete.

    SentinelOne Singularity Complete has helped us improve our mean time to detect threats, which we accomplish using the Vigilance service for detection and response.

    SentinelOne Singularity Complete has helped us decrease our organizational risk. We utilize the Security Scorecard to manage our security posture, which has remained steady at 90 percent.

    What is most valuable?

    Unlike other endpoint solutions like Kaspersky or Trend Micro, SentinelOne's agents are exceptionally lightweight, updating seamlessly without consuming significant network or system resources. This ensures smooth operation and user-friendly control. Moreover, SentinelOne's support team is highly competent, providing timely assistance and going the extra mile to resolve any issues.

    What needs improvement?

    When SentinelOne Singularity Complete is used as the central hub for viewing alerts from all integrated security solutions, it is challenging to identify the specific solution that triggered each alert.

    For how long have I used the solution?

    I have been using SentinelOne Singularity Complete for almost four years.

    What do I think about the stability of the solution?

    SentinelOne Singularity Complete is stable.

    How are customer service and support?

    The technical support team is quick to respond to and resolve our issues.

    How would you rate customer service and support?

    Positive

    Which solution did I use previously and why did I switch?

    Our hybrid environment has raised security concerns for management, leading them to seek an all-in-one solution. After conducting multiple proof-of-concept tests for endpoint security, they determined that Kaspersky was insufficient for their needs due to inadequate functionality and management complexity. As a result, they transitioned to SentinelOne Singularity Complete.

    SentinelOne is actively developing new innovations and introducing additional integration platforms.

    What other advice do I have?

    I would rate SentinelOne Singularity Complete nine out of ten.

    SentinelOne Singularity Complete offers comprehensive endpoint security by automatically updating without impacting bandwidth. Unlike traditional signature-based solutions, it employs a behavior-based approach to detect and immediately address malicious or suspicious files and processes.

    We are 100 percent confident with SentinelOne as a strategic security partner.

    Maintenance has been seamless, and while SentinelOne does notify us in advance of any required downtime, I haven't experienced any interruptions in the past year and a half.

    With 30,000 employees and 26,000 endpoints worldwide, our organization has implemented SentinelOne Singularity Complete across all endpoints.

    Which deployment model are you using for this solution?

    Public Cloud
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    reviewer2676195 - PeerSpot reviewer
    IT Infrastructure Manager at a training & coaching company with 11-50 employees
    Real User
    Top 20
    Mar 18, 2025
    Simplifies operations with good UI and centralization
    Pros and Cons
    • "The web portal has a really good web UI, and all the things are well integrated."
    • "Singularity Complete has helped reduce alerts."
    • "The basic functionalities should be up and running even during maintenance windows. I understand that it is a software-as-a-service model, but it becomes a problem if I cannot do anything when issues occur during maintenance."
    • "The maintenance window can be improved because once it happened that I had multiple laptops, and the maintenance window caused a lot of laptops to get stuck in the portal, blocking access."

    How has it helped my organization?

    Singularity Complete has helped reduce alerts. We have one place to go to check them, and there is also a reduction in false alerts.

    Singularity Complete helped free up our staff for other projects and tasks. I do not have the metrics, but it saves a lot of time compared to what I have used at other companies.

    Singularity Complete has helped reduce our mean time to detect. We only have to look at the portal. We can quickly isolate the user or the device, which also stops the virus from spreading. It also reduces our mean time to respond.

    What is most valuable?

    The web portal has a really good web UI, and all the things are well integrated. It is easy for us to increase the number of users because it is pretty simple.

    What needs improvement?

    The maintenance window can be improved because once it happened that I had multiple laptops, and the maintenance window caused a lot of laptops to get stuck in the portal, blocking access. This is important to address. The basic functionalities should be up and running even during maintenance windows. I understand that it is a software-as-a-service model, but it becomes a problem if I cannot do anything when issues occur during maintenance.

    They could make it simple to have a SIEM integrated with their solution so that we can send logs to their server and then analyze them.

    For how long have I used the solution?

    I have been using SentinelOne Singularity Complete for almost one year.

    What do I think about the stability of the solution?

    It is stable.

    What do I think about the scalability of the solution?

    It is scalable. We have 50 users in our company. We have three administrators. We also have a consultant.

    How are customer service and support?

    I did not have the opportunity to contact them because I had almost no issues.

    How would you rate customer service and support?

    Neutral

    Which solution did I use previously and why did I switch?

    We were probably using Webroot. I was not there when they made the decision to switch.

    How was the initial setup?

    I did not participate in the initial setup, but our new onboarding process for laptops is really straightforward. You just join the domain, and the software gets installed automatically. It is bound to our site, making it very easy.

    What was our ROI?

    It is difficult to measure ROI, but since we started using it, we have not had any problems related to security. We have not experienced any breaches or issues so far.

    It has absolutely helped reduce our organizational risk.

    What's my experience with pricing, setup cost, and licensing?

    Overall, it was a good experience. It is pretty easy for us to increase the number.

    What other advice do I have?

    SentinelOne is focused on this solution. This is evident in the GUI. The GUI is well done compared to solutions like Microsoft Defender which I have been trying to get into, but it almost repels me. SentinelOne Singularity Complete is very stable and mature. It is one of the best solutions that one can choose.

    I would rate SentinelOne Singularity Complete a nine out of ten.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    Buyer's Guide
    Download our free SentinelOne Singularity Endpoint Report and get advice and tips from experienced pros sharing their opinions.
    Updated: September 2026
    Buyer's Guide
    Download our free SentinelOne Singularity Endpoint Report and get advice and tips from experienced pros sharing their opinions.