SentinelOne Singularity Complete has improved our security stack. You don't have to worry about monitoring 24/7.
Manager at a computer software company with 501-1,000 employees
Solid and mature with standard EDR capabilities
Pros and Cons
- "The tool's most valuable feature is Vigilance Respond Pro monitoring. You don't have to have a dedicated SOC and worry about staffing."
- "I don't like switching the way you switch from legacy to XDR."
How has it helped my organization?
What is most valuable?
The tool's most valuable feature is Vigilance Respond Pro monitoring. You don't have to have a dedicated SOC and worry about staffing.
What needs improvement?
I don't like switching the way you switch from legacy to XDR.
For how long have I used the solution?
I have been using SentinelOne Singularity Complete since March 2023.
Buyer's Guide
SentinelOne Singularity Endpoint
September 2026
Learn what your peers think about SentinelOne Singularity Endpoint. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
915,817 professionals have used our research since 2012.
What do I think about the stability of the solution?
SentinelOne Singularity Complete is stable.
What do I think about the scalability of the solution?
The product is scalable.
What about the implementation team?
A reseller consultant helped us with the tool's implementation. Our experience was good.
What other advice do I have?
SentinelOne Singularity Complete has freed up my staff's time and helped them focus on other tasks.
The product's interoperability with other SentinelOne solutions and third-party tools is good.
The solution has reduced our organizational risk. We have faster responses to incidents.
SentinelOne Singularity Complete is a mature and solid product. I like the standard EDR capabilities.
I rate it a nine out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Security Engineer at a financial services firm with 51-200 employees
Provides deep visibility and has competitive pricing, but should support Terraform and dynamic tagging
Pros and Cons
- "The deep visibility and the ability to perform security investigations and assess our endpoint security posture are the most valuable features."
- "There should be Terraform support for console administration. Dynamic tagging would be also useful."
What is our primary use case?
We use it as an Enterprise EDR solution for threat detection, anti-malware, and security investigations.
How has it helped my organization?
SentinelOne Singularity Complete has greatly enhanced our security posture. We feel that our endpoints are more secure. We are in the know of what is happening within our company from a security perspective. We are confident in the ability to detect untrue positives. It has also helped us in achieving industry certifications such as SOC 2.
SentinelOne Singularity Complete has absolutely helped reduce our organization's mean time to detect. There has also been an impact on our mean time to respond. With the integrations that we have set up with Splunk and other products, we are able to respond to incidents as soon as they alert us.
We have a couple of integrations with it. They are alright. I am not blown away by its integration capability.
SentinelOne Singularity Complete has not helped reduce alerts. If anything, we create more alerts with it. We are able to fine-tune the product to reduce noise and alerts, but without it, we would not have any alerts. It is the piece of software that provides that alerting capability for us.
SentinelOne Singularity Complete has not helped free up staff. In a way, it creates work for us, but that is the purpose of the product.
What is most valuable?
The deep visibility and the ability to perform security investigations and assess our endpoint security posture are the most valuable features.
What needs improvement?
There should be Terraform support for console administration. Dynamic tagging would be also useful.
The auto-upgrade capability should be improved.
For how long have I used the solution?
I have been using SentinelOne Singularity Complete for two years at this company. My company has been using it longer than that.
What do I think about the stability of the solution?
Its stability is pretty good. I like the stability of their agent.
What do I think about the scalability of the solution?
It is extremely scalable.
How are customer service and support?
Their technical support is pretty good. I would rate them an eight out of ten.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I was not here when they bought this solution, but I know why we bought the tool. We replaced another EDR solution, and then we used it as our enterprise EDR solution for ransomware prevention, threat hunting, and security investigations. We were using CrowdStrike previously. SentinelOne Singularity Complete also saved us money. It is very competitive compared to CrowdStrike.
I have used a couple of EDR solutions. SentinelOne Singularity Complete is less mature than CrowdStrike, but it is definitely one of the top players in the industry.
SentinelOne Singularity Complete has not helped reduce our organizational risk. It is about the same as CrowdStrike in this aspect.
How was the initial setup?
We have it on our laptops and the cloud, so our setup is hybrid. I am in charge of deployment, and it is as simple or complex as any other solution.
It requires maintenance on our end.
What about the implementation team?
We have a team, but I do most of the work. I am in charge of it.
What was our ROI?
It is hard to define the ROI. It does not save us money, but it prevents security breaches. In the grand scheme of things, it is definitely worth investing in.
What's my experience with pricing, setup cost, and licensing?
Its pricing is competitive.
What other advice do I have?
It has competitive pricing and great support. It is a complete solution.
As a strategic security partner, they collaborate with us quite a bit on our overall posture. They constantly have webinars and education sessions for us to deepen our security knowledge and how to use their product. They have assisted us on various PoCs for different offerings that they have and different services they offer. They help us to understand how each of those components integrates into our overall security posture. We did a PoC of the Ranger functionality.
I would rate SentinelOne Singularity Complete a seven out of ten.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Buyer's Guide
SentinelOne Singularity Endpoint
September 2026
Learn what your peers think about SentinelOne Singularity Endpoint. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
915,817 professionals have used our research since 2012.
Network Engineer at a government with 11-50 employees
Discovers and deletes problem-causing processes, but the support team lacks knowledge
Pros and Cons
- "The tool deletes the problem-causing process and prevents issues."
- "They should train their own people so that they can train us better. The theory is good."
What is our primary use case?
Every five years, we research tools that could replace our old software. We combine our AV and intrusion detection. We were trying to find out if there’s an agent for the whole nine-yard, and we came across SentinelOne.
What is most valuable?
The product has an automated process where we find security issues. It’s a 24/7 behavior analytical tool to execute certain actions. The tool deletes the problem-causing process and prevents issues. It discovers, kills, and protects. The software is good. I don't see much of an issue with it.
What needs improvement?
They should train their own people so that they can train us better. The theory is good. If the product is good, but we cannot rely on it or pass it along to the customer, it's useless. When we purchased the solution, we were told that certain functions could be done. I understand it is part of sales, but I feel like I'm being fooled. We couldn't test it because it was in production. We first had a proof of concept but didn't connect it to our Azure portion.
For how long have I used the solution?
I have been using SentinelOne Singularity Complete since February.
What do I think about the stability of the solution?
The product's stability is okay.
What do I think about the scalability of the solution?
The tool's scalability is average.
How are customer service and support?
The support people of SentinelOne do not know the different products offered by SentinelOne. How can they support their customer if one person knows one thing and the other doesn't? They tell us the issue does not come under them and point us to a different team.
There is a SentinelOne support team and a Singularity support team. SentinelOne's support team is okay. Once, the technical support and help desk director got involved with all our issues. However, the director got involved after we strongly complained about the issues. That's not the way it's supposed to be.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
I have used Arctic Wolf.
How was the initial setup?
The initial deployment was good. The solution is cloud-based.
What about the implementation team?
We took help from SentinelOne to deploy the solution. We paid for it, but it was not worth the money we paid for. Two people from our company are required for the deployment. The solution requires maintenance.
What's my experience with pricing, setup cost, and licensing?
The licensing is okay. I don't see any issues with it.
Which other solutions did I evaluate?
We evaluated other options. We were trying to have one solution for everything. We heard that SentinelOne purchased another company. Other products like Rapid7 provide multiple solutions and products for our needs. We saw that SentinelOne provided us with one product and one support system. However, even while using SentinelOne, I have to contact different teams.
What other advice do I have?
When we purchased the solution, it did not do what we expected. We didn't use all of the features. It has quite a few options. There are a bunch of more add-on modules. Other products from SentinelOne are not good. I am really disappointed with them. The user must understand the solution by just reading the training documents. The team claims it is professional, but it lacks a lot of functions.
The integration is fine, but the feature is not how they market it. It looks good on paper, but it's not what we think it is. It's not a ready product in marketing. I am disappointed with it. The interoperability is still under development. Not many people know or understand it, including people from SentinelOne. When we call and try to figure out what's going on with the solution, not many understand what it is. There is a lack of training on their products and services.
The Ranger functionality is fine. It’s only been six months since we started using it. We're still learning as it goes. I think Ranger is probably better than Singularity. Sometimes, they send false positives. It's not really a big feature for us. It's good. They're trying to prevent any networking attack, but I don't think it’s there yet. They're just trying to discover what is on the network, but we already have other tools for that.
It is important for us that Ranger requires no new agents, hardware, or network changes. Ranger is just trying to discover whatever issues we have. I don't think it can prevent it. I don't think it can block issues or protect our devices.
Overall, I rate the product a seven out of ten.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Cybersecurity Engineer at a energy/utilities company with 1,001-5,000 employees
Improves our visibility and response across multiple platforms in our enterprise network
Pros and Cons
- "The visibility and, obviously, the protection aspects are second to none when it comes to speed. Another thing we fall back on is the option to roll back an endpoint if it is infected. There is a shadow copy so that if a PC downloads malicious content, we can roll it back to the state it was in before that package was imported."
- "Their documentation could afford to be a little bit better communicated. A lot of times we have to look at things in the knowledge base, and much of that could be communicated better, but that would probably be the only thing that needs to be improved."
What is our primary use case?
Our primary use case would be for active XDR protection. We wanted an innovative XDR to keep up with the rising dangers of malware, ransomware, et cetera.
How has it helped my organization?
Our visibility and response to a lot of the things that come with an enterprise network have improved. We have users doing multiple things across different platforms. There are applications, servers, endpoints, and certain things that fit in the wild, and it does a really good job protecting all of them.
It has saved time for my team because of what we can do in terms of device control that it provides externally. We have total control.
When it comes to detection, we have email alerts when a threat comes across, so it's pretty quick. And if we have predefined responses to certain threats, then obviously, our response is instantaneous. But in a lot of cases, we like to have our administrators take a look at it and make sure it gets remediated as quickly as possible.
As for security, SentinelOne Singularity puts us in a better place than most solutions. We can look at platform reviews that keep us in the loop regarding what's not considered a good solution.
What is most valuable?
The visibility and, obviously, the protection aspects are second to none when it comes to speed. Another thing we fall back on is the option to roll back an endpoint if it is infected. There is a shadow copy so that if a PC downloads malicious content, we can roll it back to the state it was in before that package was imported.
It also has a lot of flexibility with its ability to ingest things.
And the AI feature of the solution is prompt in how it learns a certain network and how it responds to certain things. If you do come across false positives, it's relatively easy to get around them.
What needs improvement?
There are some obstacles you have to overcome when it comes to whitelisting and the like, but that's true of every XDR platform.
Their documentation could afford to be a little bit better communicated. A lot of times we have to look at things in the knowledge base, and much of that could be communicated better, but that would probably be the only thing that needs to be improved.
For how long have I used the solution?
We've been using SentinelOne Singularity Complete for about three years.
What do I think about the stability of the solution?
I would give it an A-plus in stability. A lot of times, when you download a new endpoint protection agent or an AV agent, you might run into a lot of compatibility issues or programs kind of freezing up.
What do I think about the scalability of the solution?
I would give it an A-plus for scalability as well.
How are customer service and support?
Our experience with their technical support has been straightforward and good. We got good, timely responses.
As a strategic partner, they're "the new guy on the block." There is some talk of them being bought out. I have heard some rumors like that. But from what I've seen, SentinelOne is just as good as, or better than, any other security partner out there.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We did use an endpoint protection platform, but I can't comment on which one we used.
How was the initial setup?
I was involved in the whole process of deployment. One thing that wasn't SentinelOne's forte was compatibility with a script for an on-premises software distribution tool. Most of what we did was homegrown to deploy the agents to the machines.
What about the implementation team?
We did it in-house. There were a handful of us involved, probably 10 at least.
What's my experience with pricing, setup cost, and licensing?
I don't deal with the cost side of things, but the licensing, as far as endpoints go, is a pretty straightforward and simple process.
Which other solutions did I evaluate?
We looked at a couple of other solutions but, again, I can't disclose more about those.
What other advice do I have?
The speed and user friendliness that this platform offers break down some complex aspects of the security industry, and the solution lays them out in a way that a general user can understand.
Definitely compare and contrast Singularity with other solutions. It depends on what fits best for you, what industry you're in, how mobile your network is.
Which deployment model are you using for this solution?
On-premises
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Managing Director at NETITUDE
Quick deployment, effective zero-day detection, and beneficial recovery capabilities
Pros and Cons
- "The most valuble feature of SentinelOne Singularity Complete is the recovery and zero-day detection."
- "SentinelOne Singularity Complete could improve by having DNS filtering. Other competitor solutions have this feature."
What is our primary use case?
We are using SentinelOne Singularity Complete for an EDR platform for our clients.
What is most valuable?
The most valuble feature of SentinelOne Singularity Complete is the recovery and zero-day detection.
What needs improvement?
SentinelOne Singularity Complete could improve by having DNS filtering. Other competitor solutions have this feature.
For how long have I used the solution?
I have been using SentinelOne Singularity Complete for approximately one year.
What do I think about the scalability of the solution?
We have approximately 1,000 people using this solution. We have plans to increase our usage.
The scalability of SentinelOne Singularity Complete is great.
How are customer service and support?
We do the implementation of the solution in-house.
Which solution did I use previously and why did I switch?
I have previously used BitDefender.
How was the initial setup?
The initial setup of SentinelOne Singularity Complete is easy. For exciting clients, the deployment of the solution can be done in minutes.
What was our ROI?
I have received a return on investment using SentinelOne Singularity Complete.
We've used SentinelOne Singularity Complete capability to enhance our offering and, therefore, be able to leverage that to increase our pricing.
What's my experience with pricing, setup cost, and licensing?
For our use case, the solution is affordable. There are not any hidden fees.
Which other solutions did I evaluate?
We evaluated Sophos, Carbon Black, and CloudStrike before choosing SentinelOne Singularity Complete.
What other advice do I have?
I rate SentinelOne Singularity Complete a nine out of ten,
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Head of Cybersecurity at Technovage Solution
A valuable autonomous platform but the use case is valid mostly for the cloud deployments
Pros and Cons
- "The autonomous platform is valuable because we can separate false positives and negatives."
- "There is not much focus on the on-premise solution as the license cap is so huge for small and medium-sized institutions."
What is our primary use case?
Our primary use case for the solution was covering all the endpoints, including servers. We also added the Kubernetes nodes with the CI/CD platform, which covered end-to-end features that we need to fill the required security controls.
How has it helped my organization?
The solution has benefited us by monitoring most of the activities to endpoints that we control over the USB and the browser monitoring. Activity monitoring was also done through the XDR platform. We had a couple of incidents where there was zero-day malware planted inside the Lenovo firmware upgrade, which we were able to capture through the auto-detection feature.
What is most valuable?
The autonomous platform is valuable because we can separate false positives and negatives and update the database during certain types of automation.
What needs improvement?
The solution can be improved by ensuring threats are being mitigated on the platform autonomously and by considering introducing an on-premises solution with affordable pricing for government institutions.
There is not much focus on the on-premise solution as the license cap is so huge for small and medium-sized institutions.
For how long have I used the solution?
We have been using the solution for approximately one year.
What do I think about the stability of the solution?
The solution is stable.
What do I think about the scalability of the solution?
The solution is scalable and can use the facility to do the same license, which could be used for Kubernetes. So it is the same license but different scales which we have utilized. Approximately 1,000 users are using the solution.
How are customer service and support?
Our team has had a good experience with customer service and support.
How would you rate customer service and support?
Neutral
How was the initial setup?
The initial setup was straightforward. Our team has also done an equally simple upgrade. It took approximately 24-48 hours.
What was our ROI?
I would say that there could be better ROI if we tend to use more than 500 licenses under a multi-cloud solution. But it would not be the same for an on-premise solution.
What's my experience with pricing, setup cost, and licensing?
The license for the solution is quite expensive, but it is cheaper than CrowdStrike. However, if you consider specific organization requirements, it has covered them all, so we might move to CrowdStrike after evaluating three years. Then, we assess the kind of tool in line with our requirements and implement the latest and the best tool in the quadrant, and currently, in Cambodia, CrowdStrike and TrendMicro are more popular.
What other advice do I have?
I rate the solution a seven out of ten. The solution is good but can be improved by ensuring threats are being mitigated on the platform and considering reducing the license cap for an on-premises solution.
Which deployment model are you using for this solution?
Private Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Lead Security Analyst at SecurityHQ
Provides a better graph showing when the alert started, the process, the challenges, and the parameters; has an AI that segregates and categorizes events
Pros and Cons
- "The most valuable feature of SentinelOne is the good graph it provides. It has a specific page where it detects the recent attacks on other machines or the hackers, for example, group APT28 and all."
- "An area for improvement in SentinelOne is the search feature. You can't go beyond twenty thousand events, which ruins the task because it isn't enough when you're doing your investigation."
What is our primary use case?
Using SentinelOne isn't part of my daily tasks. My team only uses it when there's a detection, so the tool is only kept as a screenshot or wallpaper and is only used when there's an alert. It doesn't give us many alerts anyway.
My company uses SentinelOne for EDR purposes for alerts, detections, and patch deployment. For example, some clients ask my team to patch multiple devices and apply policies to the devices, so my team updates policies, applies patches, and updates machines per Windows and Mac updates.
My company also uses SentinelOne for EDR detections and investigations, including forensic purposes.
What is most valuable?
The most valuable feature of SentinelOne is the good graph it provides. It has a specific page where it detects the recent attacks on other machines or the hackers, for example, group APT28 and all. It shows the active group or predators in the market, the tactics the group uses, and the recent attacks the group performed.
My company even asked a particular client to onboard devices on SentinelOne because it's easier to graph the alerts. The tool can provide you with a better graph that shows when the alert started, the process, the challenges, and the parameters of the processes.
SentinelOne also has a knowledge base embedded in it. You have to visit the page to get the details.
I also like that you can see the activities performed for the alerts received from your end. You have a bunch of people working on SentinelOne, and you don't have to worry about not knowing who received and resolved the alerts because you can get information on the activities on the tool. You can view the actions on the alerts and who has taken action. This is a valuable feature of SentinelOne that's not usually provided on the other EDRs because it's unrelated to the investigations. I can see who recently closed or resolved a particular alert on SentinelOne because the name of the person who took action will appear on the activity page.
Another feature I like a lot about SentinelOne that I can't find in other EDR solutions is the AI segregation and categorization of events. You'll be directed to the logon events category if you're looking into logon-related events. If you're looking into network-related events, you'll be directed to another category, the appropriate one. Based on your search, the SentinelOne AI will segregate the results into categories. You can click on the category and view the categories related to your events. The segregated results then make it easier to do the investigations.
What needs improvement?
An area for improvement in SentinelOne is the search feature. It could be easier. For example, you can select the number of results that will be shown to you, such as two thousand events, and you can even go up to twenty thousand events for the search you've made, but you can't go beyond twenty thousand. You can only receive up to twenty thousand if you find login-related, detection-related, or process creation-related events. That's the limitation in the search feature of SentinelOne, which ruins the task because it isn't enough when you're doing your investigation.
The retention period of the tool also has room for improvement. The retention period is a time when you can patch up the logs, even older ones. Still, on SentinelOne, the retention period is only one week or one week up to twenty-eight days, and that period is insufficient, especially for a security breach. If a security breach occurs within the company, it could be six months to a year, so if you want to view the logs, you cannot go beyond the limit set by SentinelOne.
The retention period of the tool is way less than what other EDR solutions provide. SentinelOne and CrowdStrike come with a shorter retention period, which means you cannot go beyond one month when investigating the logs.
One month is the timeframe of the retention period, and one week is real-time, as scheduled by the vendor. For forensics purposes, the retention period is critical, so what would make SentinelOne better is a more extended retention period that lets you investigate logs. If you want to patch logs, you can directly call or reach out to the vendor who can provide you with the logs. If the vendor has no logs, you won't get the initial alert when the incident starts.
What I want to see from SentinelOne in its next release is a faster search. I also wish that the twenty thousand event limitation be removed.
For how long have I used the solution?
I've been using SentinelOne for nine to ten months now.
What do I think about the stability of the solution?
SentinelOne is a stable tool that never crashes. It's a good product.
Its stability is nine out of ten because, at times, the tool lacks robustness when searching. For example, if I want to search, it can take some time based on my ability to search. Searching on SentinelOne can be much faster because, search-wise, it could be a little laggy.
What do I think about the scalability of the solution?
The scalability of SentinelOne is much better than other tools, so it's a ten for me, scalability-wise.
How are customer service and support?
I haven't contacted the technical support for SentinelOne, but many of my colleagues had experience getting SentinelOne support. One case was about the retention period because a client had been compromised and needed more logs from SentinelOne, but the support team couldn't provide more logs as the retention period was too short.
Which solution did I use previously and why did I switch?
My company chose SentinelOne over other solutions because it's powerful in the areas of detection, flagging for alerts, and logs. The alert creation is stronger in SentinelOne, so my company went with this tool.
How was the initial setup?
The initial setup for SentinelOne was easy, and I manually performed it. It's easy to deploy a device onto SentinelOne. You have to run the agent, and the application, then the tool will be onboarded. It's that easy.
The deployment of SentinelOne hardly took me half an hour. Once you've learned how and executed the agent file on the machine, you'll start getting the logs. You'll test, configure, and collect the right resources and receive the logs.
What about the implementation team?
I implemented SentinelOne, so it's in-house.
What's my experience with pricing, setup cost, and licensing?
As a developer, I have no information on the pricing of SentinelOne.
What other advice do I have?
I'm using SentinelOne, the EDR solution.
SentinelOne is deployed on the cloud, probably the public cloud, though I wonder if it's private or public. It's on the cloud because it has many more features and doesn't use up many resources even when there's a high workload, and as a tool, SentinelOne performs very well. It may be on AWS or Azure, though.
Within the company, twenty people personally use SentinelOne daily.
My company is a partner of SentinelOne, so my team recommends it to clients, especially if clients require more detection and easy onboarding.
I'd tell anyone looking into implementing the tool that it's fun to learn and use. You can use it without needing many clicks to isolate the machine or perform your required activities. One of the best features of SentinelOne is that it has minimal mouse actions. For example, when you click on a machine, you'll get the hyperlink that shows you the machine details, the uptime, when it was first and last seen, the memory, and all the machine details. You get the details in one location, such as the applications installed on the machine, the network-related configurations of the machine, and the machine processes. You won't get as many features from other EDR solutions. You can isolate the machine, repair and update the machine, update the knowledge base and software, and onboard a particular device on SentinelOne. The tool has many more features. It's a good tool.
My rating for SentinelOne is nine out of ten. Still, if the twenty-thousand event limitation is removed, then that's the time I'd give the tool a score of ten because if there's no limit set, then you can get all process details related to your investigation.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Principal Forensics Lead at Dotcom Security
The most valuable features are Deep Visibility, Remote Script Orchestration, and Ranger
Pros and Cons
- "The solution is extremely stable."
- "The solution can improve by adding more granular firewall capabilities."
What is our primary use case?
The primary use case of the solution is cybersecurity. The solution provides endpoint protection against direct threats and insider threats.
What is most valuable?
The most valuable features are Deep Visibility, Remote Script Orchestration, and Ranger.
What needs improvement?
The solution can improve by adding more granular firewall capabilities. I would like to see an interface where I can in one view change the security posture of all groups with one click. I would like to have a listing of all the groups and then apply what's relevant to all the groups at once.
For how long have I used the solution?
I have been using the solution for one year.
What do I think about the stability of the solution?
The solution is extremely stable.
What do I think about the scalability of the solution?
The solution is scalable.
How are customer service and support?
The tech support is brilliant.
How would you rate customer service and support?
Positive
How was the initial setup?
The initial setup is straightforward. It takes about four weeks to deploy.
What about the implementation team?
The implementation was done in-house.
What was our ROI?
The ROI is good. Once you go through the stabilization phase and get to know and understand the customer's environment and configure accordingly to what the customer needs, the return is there immediately.
What's my experience with pricing, setup cost, and licensing?
The license is paid annually and is competitive. There are features that are not included in the licensing cost but it does include Vigilance and STAR.
What other advice do I have?
I give the solution a nine out of ten.
On average, once the implementation phase is complete the solution only requires two people to maintain it.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Chief Information Officer at Amadys
Simple deployment and the solution just works
Pros and Cons
- "SentinelOne is a stable solution."
- "We made the switch because SentinelOne is not signature-based, it's an AI solution."
- "There is room for improvement with the management interface. It could be more user friendly."
What is our primary use case?
Our primary use case for SentinelOne is antivirus and malware protection.
What is most valuable?
I found the detection the most valuable.
What needs improvement?
There is room for improvement with the management interface. It could be more user friendly.
For how long have I used the solution?
I have been using SentinelOne for less than a year but more than six months.
What do I think about the stability of the solution?
SentinelOne is a stable solution.
What do I think about the scalability of the solution?
SentinelOne is a scalable solution. We have some 300 people using it in our organization and plan to increase usage as the company grows. Every machine we roll out gets that product.
Which solution did I use previously and why did I switch?
We used Trend Micro before we switched to SentinelOne. We made the switch because SentinelOne is not signature-based, it's an AI solution.
How was the initial setup?
The initial setup was straightforward. It entails simple installers and we deployed it through policies. We deployed it as a package on all PCs and servers and it took two weeks.
What about the implementation team?
Deployment can be done in-house with one technical person.
What other advice do I have?
I recommend it. It just works.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Senior Manager INFOSEC AND Risk ASSESSMENT Engineering at Atlas Systems
Beneficial ransomware blocking, simple deployment, and easy to use
Pros and Cons
- "SentinelOne Singularity has hundreds of features. The most valuable feature of the solution is the ease of use and threat control."
- "Ransomware blocking is a better feature in SentinelOne Singularity."
- "The training for SentinelOne Singularity should be free. The solution has a lot of features but we do not know how to use them all. The moment someone purchases the solution they should contact them and provide them with a feature session on how to use the features."
- "The training for SentinelOne Singularity should be free."
What is our primary use case?
We use SentinelOne Singularity for cybersecurity. For example, ransomware protection. It protects our network against the latest cybersecurity threats, continuous monitoring, and real-time checks of our network.
There are many things that we consider in a solution, such as how often it updates and does patches, and what issues are there in the network or on the desktop or OS. If any patch is missing, it should inform me and send me CVSS and CVSE scoring of my threat perspective.
What is most valuable?
SentinelOne Singularity has hundreds of features. The most valuable feature of the solution is the ease of use and threat control.
What needs improvement?
The training for SentinelOne Singularity should be free. The solution has a lot of features but we do not know how to use them all. The moment someone purchases the solution they should contact them and provide them with a feature session on how to use the features.
When we connect the solution to our patch management system they should explain to us how to do it. Additionally, it should be notifying me what patch is missing in my system.
For how long have I used the solution?
I have been using SentinelOne Singularity for approximately six months.
What do I think about the stability of the solution?
SentinelOne Singularity is stable.
What do I think about the scalability of the solution?
We have approximately 250 users using this solution in my organization.
How are customer service and support?
I have used the support team from SentinelOne Singularity.
I rate the support from SentinelOne Singularity a four out of five.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We used two solutions for the comparison, CrowdStrike and McAfee. We did do tests before going to SentinelOne Singularity in many areas, such as ease of use, technical comparison, scanning capabilities in terms of cybersecurity perspective, and ransomware protection. Ransomware blocking is a better feature in SentinelOne Singularity.
We have a team of people who have a set of parameters that we use to scan all these tools. They perform comparisons on each and every aspect and SentinelOne Singularity scored better.
How was the initial setup?
The deployment of SentinelOne Singularity is straightforward and very easy. The whole process of deployment took four hours.
What's my experience with pricing, setup cost, and licensing?
When it came to the price compared to other solutions we tested, SentinelOne Singularity gave us the price of our expectations whereas CrowdStrike could not.
What other advice do I have?
First-time users of this solution should prioritize what they want to protect, and establish if they have the expertise to maintain it. The solutions don't require any high-end expertise to be deployed or maintained but a normal IT system administrator is needed to do it.
I would recommend this solution to others.
I rate SentinelOne Singularity a nine out of ten.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Buyer's Guide
Download our free SentinelOne Singularity Endpoint Report and get advice and tips from experienced pros
sharing their opinions.
Updated: September 2026
Product Categories
Endpoint Detection and Response (EDR) Endpoint Protection Platform (EPP) Anti-Malware Tools Extended Detection and Response (XDR) AI-Powered Cybersecurity Platforms AI ObservabilityPopular Comparisons
Cortex XDR by Palo Alto Networks
CrowdStrike Falcon
Microsoft Defender for Endpoint
SentinelOne Singularity Cloud Security
IBM Security QRadar
Microsoft Sentinel
Elastic Security
TrendAI Vision One
Huntress Managed EDR
Trellix Endpoint Security Platform
Buyer's Guide
Download our free SentinelOne Singularity Endpoint Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What is the biggest difference between Carbon Black CB Defense, CrowdStrike, and SentinelOne?
- Which is better - SentinelOne or Darktrace?
- What do you recommend to choose when replacing Symantec EDR: SentinelOne or CrowdStirke Falcon?
- Cortex XDR by Palo Alto vs. Sentinel One
- Which solution do you prefer: CrowdStrike Falcon or SentinelOne Singularity Complete?
- Does SentinelOne have a Virtual Patching functionality?
- What is the biggest difference between EPP and EDR products?
- What is the difference between EDR and traditional antivirus?
- What is your recommendation for a 5-star EDR with low resource consumption for a financial services company?
- Which is the best EDR for a logistics company with 500-1000 employees?




















