No more typing reviews! Try our Samantha, our new voice AI agent.
Abrar Mukhtar - PeerSpot reviewer
Director Of IT Security And Risk Management at AskDegree
Real User
Top 5
May 19, 2026
Endpoint protection has strengthened incident response and improved threat visibility
Pros and Cons
  • "Singularity Complete is a good product in its area and, obviously, when comparing to other organizations or companies providing endpoint detection solutions, it is an end-to-end solution for antimalware and XDR."
  • "However, I believe the vulnerability management is currently in pilot. If it can mature into good production where the vulnerability management module is working well within Singularity Complete edition, that would be an awesome step."

What is our primary use case?

I use SentinelOne Singularity Endpoint for endpoint protection. I utilize it for different companies and different purposes. It is effective for endpoint detections and remediation of the detections. Additionally, I use it for new endpoint discovery within the company intranet. Overall, I use SentinelOne for incident response activities.

What is most valuable?

The best features in SentinelOne Singularity Endpoint are the Sentinels and the features provided within the Sentinel module, which include machine identification and machine details. I can accomplish everything within the endpoint using these features. Endpoint Sentinel is a good detection rule, and if I can create or already have created rules, these are good working rules that protect my organization and make the endpoints more secure.

Ranger is also a cool feature that provides visibility of new endpoints that have been attached or connected within my infrastructure that do not have SentinelOne Singularity Endpoint agent installed on them.

What needs improvement?

Before using SentinelOne Singularity Endpoint, I used different products, including CrowdStrike. In the space where SentinelOne Singularity Endpoint is working, it is an awesome product. However, I believe the vulnerability management is currently in pilot. If it can mature into good production where the vulnerability management module is working well within Singularity Complete edition, that would be an awesome step. The vulnerability assessment is available, but application vulnerability assessment or other endpoint vulnerability assessment is not as good as what other products are providing.

Singularity Complete is a good product in its area and, obviously, when comparing to other organizations or companies providing endpoint detection solutions, it is an end-to-end solution for antimalware and XDR. This has been working fine for me so far. I am using it in small, medium, and enterprise organizations, and it is good. However, as I mentioned for the vulnerability assessment, along with the specification of handling core, detailed forensics, there could be more details I would add. However, if I recall correctly, there is a specific module within SentinelOne Singularity Endpoint to check all details of the functions that happened within the target machine. I am currently unable to recall the name of that module, but it exists. However, there is room for improvement where more details of the solution or from the target can be added, and this would help me more easily identify the impact or the root cause that impacts the endpoint. This would be more helpful for end users. Currently, if there is an impacted endpoint, I click on the endpoint, and it gives me insights about what happened with this endpoint. However, when I need to go into the details, there is some limitation to viewing those details for the target machine. It would be awesome if this module could be integrated into the normal Sentinels. This would be more helpful for engineers working on core identification of root causes.

For how long have I used the solution?

I have been working with SentinelOne Singularity Endpoint for more than two or three years.

Buyer's Guide
SentinelOne Singularity Endpoint
August 2026
Learn what your peers think about SentinelOne Singularity Endpoint. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
910,454 professionals have used our research since 2012.

What do I think about the stability of the solution?

It is working fine for me. In the majority of cases where files have been detected as malware or virus within the organization on the target machine, they are quarantined. This is good functionality from XDR, as I mentioned earlier.

What do I think about the scalability of the solution?

For me, it is good, but I believe SentinelOne Singularity Endpoint does not directly engage with customers who have fewer than one thousand nodes. I have to engage through SentinelOne's partners. This is an impact based on market or company strategy. The pricing is not too bad; it is good. If I directly engage the organization or company, the pricing is different and obviously better. Additionally, when I go directly within the company, they provide visibility or vigilance services to customers at the same price. When I go into the partner channel, my account is within the partner's umbrella, and they provide limited support for visibility and further incident investigations. This is a limitation for small and medium organizations. However, for large organizations that can directly engage SentinelOne Singularity Endpoint, this is a positive point, but there is a lag when I go into the partner channel. The partners engage with customers in their own way, and that is how it works.

How was the initial setup?

For me as an end user, the setup process was not difficult because everything was set up from the partner's side. I may not be the right person to answer for all aspects. For the end user, it is very easy. The partner set up the whole environment within a week or two. After creating the whole setup, as an end user, I would just have to install SentinelOne Singularity Endpoint agent into my end user devices or servers. It is easy to do that. Once I do this and the environment has been set up with all Sentinels collecting data from end user devices or servers, everything is there and the environment has been set up. It is easy for end users, but obviously for those creating the environment, the whole environment, creation of security rules, detection rules, and those kinds of things may be challenging, especially for beginners. That would be the challenging part, and I did not do it earlier, so I cannot comment on it fully.

What's my experience with pricing, setup cost, and licensing?

It is comparative to other products and is cost-efficient.

Which other solutions did I evaluate?

This is a competitive market with competitive solutions that have core good products and features within them. If I am looking for an endpoint protection solution, this is a good product because I always compare SentinelOne Singularity Endpoint with CrowdStrike and Microsoft Defender. Based on that comparison, if SentinelOne Singularity Endpoint had good vulnerability assessment capabilities, because currently the vulnerability assessment is based on the application, not the operating system, it would be a good point from the perspective of cost-efficiency along with the features within the product. SentinelOne Singularity Endpoint has Ranger, Sentinels, and visibility where I can go in and have detailed knowledge about every detection along with every happening on the target machine. This is good, but SentinelOne Singularity Endpoint is still lagging under the vulnerability assessment module.

What other advice do I have?

SentinelOne Singularity Endpoint provides alerting into the dashboard, but I did not configure it correctly and never received alerts over emails. If such a feature exists within the product, that would be awesome, and I could incorporate and configure it. Currently, I do not have visibility on it. Once I log into SentinelOne Singularity Endpoint, it provides visibility within the dashboard showing how many endpoints have been detected as infected, how many endpoints are impacted, and how many endpoints have been identified as malware where SentinelOne Singularity Endpoint has quarantined those files, and I can do analysis and further processing. However, currently, I did not configure it if it is available, but I am unable to navigate it. I do not have visibility on whether any endpoints or target machines have been impacted so that I receive email notifications or SMS notifications alerting me that a machine has been impacted and needs to be worked on urgently. This is a critical function I need to perform right now. If this would be configurable or is available in SentinelOne Singularity Endpoint, that is awesome. If not, then the alerting mechanism needs to be improved to get alerts over emails or SMS for at minimum critical assets.

I can say that I currently did not implement it in such a way because for what I am using SentinelOne Singularity Endpoint for, it is the on-premises infrastructure for some organizations and just for endpoints in other organizations. In that case, I believe for SaaS products, I am currently not utilizing it for such things. My question is whether SentinelOne Singularity Endpoint is an agent-based solution that I can only utilize on endpoints or servers or where the operating system is Linux or different flavors where the operating system is running. However, for the serverless environment, SentinelOne Singularity Endpoint cannot work. Is that the right expectation?

Obviously, the core concern is about data protection and privacy. There is something I have to adopt with AI. If I do not adopt it, I am not running with the market and chasing new goals. The thing is I have to implement frameworks such as ISO 42001 to manage data and contain my data's confidentiality and privacy. This is core importance for me in my job role. I take care of this all the time, and obviously if I am integrating solutions that utilize AI-based features into their product, I do have vendor management or vendor risk management to perform with vendors. I currently look into AI standards or framework implementation within organizations if they are providing me with full core data security. This is the point I engage in with existing and onboarding vendors. Additionally, I am currently utilizing AI and making AI models within my organizations. I implement security standards and maintain the whole implementation and operationalization of data protections within AI models and machine learning models.

This is the function that can be adopted, and if it is in the product, obviously this is a positive point and I do encourage that utilization of AI models within products. As I mentioned, if I got email alerts or SMS alerts for critical systems and if AI has been engaged into threat modeling with well-known algorithms that identify what threats, viruses, or malicious insights have been identified in the system, and if AI can guess that certain operating systems, files, or things are critical to my organization and can do this on a real-time basis, that would be a positive point. Obviously, as I mentioned, if I want to run with the market, I have to integrate those AI threat modeling or AI remediations within my organization. I have to do that. I give this review an overall rating of eight out of ten.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: May 19, 2026
Flag as inappropriate
PeerSpot user
Karthick Elangovan - PeerSpot reviewer
Technical Support Team Leader at Safezone Secure Solutions Private Limited
Real User
Top 20
Jul 15, 2026
Endpoint protection has delivered fast AI-driven ransomware defense and rapid incident response
Pros and Cons
  • "This is a very good solution because we can easily correlate the logs from the gateway and SentinelOne Singularity Endpoint, easily find out and get visibility on where the attack happened, how the virus came in, whether it is from mail or firewall or anything else, and easily monitor everything in SentinelOne Singularity Endpoint."
  • "However, competitors such as Trellix and Trend Micro have features for web protection with category-based web protection for web security."

What is our primary use case?

We have been using SentinelOne Singularity Endpoint for our customers. They requested next-gen antivirus, EDR solution, and XDR solutions. We are working with use cases that involve features such as behavioral AI detection for ransomware and zero-day exploit protection.

What is most valuable?

We have the VSS feature, which is the Windows Shadow Copy. This is one of the very good features of SentinelOne Singularity Endpoint. If a file gets corrupted or is affected with a virus, we can restore it within the previous four hours. The malware protection has been providing an AI-based NDR solution that is working effectively, and it is a lightweight agent that is not utilizing more CPU and does not impact customer system performance.

Other security solutions can easily correlate and integrate with our gateway solutions such as firewalls and mail security. The SIEM solution can be easily integrated, and we can monitor and correlate the logs. This is a very good solution because we can easily correlate the logs from the gateway and SentinelOne Singularity Endpoint. We can easily find out and get visibility on where the attack happened, how the virus came in, whether it is from mail or firewall or anything else. We can easily monitor everything in SentinelOne Singularity Endpoint.

What needs improvement?

Everything has been fine from my side. We are getting feedback from customers who are expecting web protection. The malware and Singularity capabilities are working fine with no problems. It can detect virus and spyware effectively. However, competitors such as Trellix and Trend Micro have features for web protection with category-based web protection for web security. This option is not available in SentinelOne Singularity Endpoint. We can block a particular URL, but we need to manually add the URL in SentinelOne Singularity Endpoint. Competitors such as Trellix and Trend Micro have category-based options such as social networking and search engines. If SentinelOne Singularity Endpoint provides this kind of feature in the future, it will be easier to approach our customers, and we can easily transition our existing customers from Trend Micro and Trellix.

For how long have I used the solution?

I have been working with SentinelOne Singularity Endpoint for five years.

What do I think about the stability of the solution?

SentinelOne Singularity Endpoint is very stable. I would rate it at nine points.

What do I think about the scalability of the solution?

Scalability is very good. I would rate it at ten.

How are customer service and support?

Customer support is good. If we create a ticket, we are getting a response within four hours, so we can get support without any problems on the customer side.

I would rate the customer support at seven points.

Which other solutions did I evaluate?

When I checked the price, almost everything has been equal. For the single agent when I compared SentinelOne Singularity Endpoint with Trend Micro and Trellix EDR solutions, they have almost similar pricing. There is no significant variant. From customer feedback, the only difference is that SentinelOne Singularity Endpoint requires manual URL addition for web protection, whereas Trend Micro and Trellix have category-based options.

What other advice do I have?

We can configure malware alerts, ransomware alerts, and email notification alerts. We can configure daily basis alerts and infected file notifications. Malware detection, virus detection, spyware detection, and ransomware protection can all be configured. We have also created AI-based alerts so that any suspicious or abnormal activity can be configured with a playbook to trigger on that activity.

Regarding mean time to respond, we are able to respond and communicate at the solution level. The productivity timing shows approximately ten minutes of saving on average. This is the mean time to respond.

The process of configuration is very easy and not complicated in SentinelOne Singularity Endpoint.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Amazon Web Services (AWS)
Disclosure: My company has a business relationship with this vendor other than being a customer. Integrator
Last updated: Jul 15, 2026
Flag as inappropriate
PeerSpot user
Buyer's Guide
SentinelOne Singularity Endpoint
August 2026
Learn what your peers think about SentinelOne Singularity Endpoint. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
910,454 professionals have used our research since 2012.
Omkar Gupta - PeerSpot reviewer
Edr Analyst at Softcell Technologies Limited
Reseller
Top 10
Jun 30, 2026
Automated threat response has reduced incident impact and gives teams faster attack visibility
Pros and Cons
  • "What I appreciate most about SentinelOne Singularity Endpoint is its automation features such as automated threat detection and responses, which can detect malicious activity, isolate devices, and even automatically roll back ransomware damage."
  • "I believe SentinelOne Singularity Endpoint is a strong security platform, but areas for improvement include reporting and dashboard customization, as well as providing more advanced threat hunting queries and easier navigation for new users, which would enhance the overall experience."

What is our primary use case?

My use case for SentinelOne Singularity Endpoint is that it is basically an EDR XDR platform that detects, investigates, and responds to cyber threats on endpoints, while also providing real-time visibility, automated threat detection, ransomware protection, and incident responses, thereby helping security teams protect the system from advanced attacks.

What is most valuable?

What I appreciate most about SentinelOne Singularity Endpoint is its automation features such as automated threat detection and responses, which can detect malicious activity, isolate devices, and even automatically roll back ransomware damage. It reduces response times and workload, making it the best feature in my view.

We correlate SentinelOne Singularity Endpoint with multiple device types, making it easy to respond to any triggered alerts, enabling us to link related security events and create a complete view of an attacker. This helps us analyze and understand how a threat spreads and impacts our systems, thus improving investigation speed and reducing false positive alerts for faster incident responses.

What needs improvement?

I believe SentinelOne Singularity Endpoint is a strong security platform, but areas for improvement include reporting and dashboard customization, as well as providing more advanced threat hunting queries and easier navigation for new users, which would enhance the overall experience.

For how long have I used the solution?

I have been using SentinelOne Singularity Endpoint for more than two to three years.

What do I think about the stability of the solution?

SentinelOne Singularity Endpoint is a stable and reliable platform that delivers continuous endpoint protection with minimal performance impact, efficiently handling large environments and providing consistent security monitoring and response capabilities without any observed lagging or downtime.

What do I think about the scalability of the solution?

The scalability of SentinelOne Singularity Endpoint is excellent as it is highly suitable for both small and large organizations, capable of protecting thousands of endpoints while maintaining good performance, making it a smart choice for growing businesses.

How are customer service and support?

I have contacted technical support several times and found them to be excellent as they respond quickly to my queries, providing dedicated support with knowledge-based documentation and training resources that assist engineers in troubleshooting, deploying policies, configurations, and threat investigations, helping our organization maintain smooth operations and resolve security issues quickly.

The quality and speed of support are excellent. Whenever I raise critical alerts or incidents that could impact business, the response is usually within ten to fifteen minutes, allowing them to troubleshoot and suggest actionable steps very quickly.

Which solution did I use previously and why did I switch?

I have used CrowdStrike for two to three months, along with other tools including QRadar and Splunk.

When comparing CrowdStrike to SentinelOne Singularity Endpoint, I prefer SentinelOne Singularity Endpoint more because it is more autonomous and AI-driven in its responses. It can automatically detect, kill, quarantine, remediate threats and roll back, including features such as asset discovery and ransomware recoveries, as well as providing strong offline protections. On the other hand, CrowdStrike offers excellent threat intelligence and managed threat hunting, utilizing a cloud-native architecture with lightweight agents and offering visibility and threat detection through the Falcon platform, which is widely adopted by large enterprises.

How was the initial setup?

The initial deployment of SentinelOne Singularity Endpoint was straightforward as I integrated it with multiple types of tools including threat intelligence platforms, cloud servers, firewalls, and ticketing tools, improving visibility and automating workflows to enhance overall security operations.

What about the implementation team?

I reviewed SentinelOne Singularity Endpoint, which is called Endpoint Detection and Response.

What was our ROI?

Regarding the pricing for SentinelOne Singularity Endpoint, I think although it requires investment, it helps reduce security risks and ransomware attacks while lowering operational costs through automation, providing excellent value and return on investment due to its strong protection and rapid response capabilities.

What's my experience with pricing, setup cost, and licensing?

SentinelOne Singularity Endpoint requires minimal maintenance because it offers cloud-based management and automated updates, allowing security teams to manage policies, monitor threats, and maintain endpoint security from a centralized console.

Which other solutions did I evaluate?

I have used the Ranger feature, which provides network visibility and asset discovery by automatically identifying unmanaged devices connected to the network, including laptops, servers, and printers, helping security teams find unknown assets and reduce blind spots to improve overall security visibility without requiring additional hardware.

I have used Purple AI, which is designed for incident analytics, enabling me to ask questions such as showing all devices affected by specific threats. It quickly provides insights into incidents and recommends actions for investigations.

What other advice do I have?

Purple AI is designed with data privacy and security in mind, ensuring that customer data is processed according to compliance requirements, which allows organizations to maintain control over their data while using AI-powered assistance for threat investigations and analysis. My overall rating for this product is eight out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer. MSSP
Last updated: Jun 30, 2026
Flag as inappropriate
PeerSpot user
Divya More - PeerSpot reviewer
Technical Support at Softcell Technologies Limited
Real User
Top 5
Mar 25, 2026
Automation has reduced detection time and has simplified ransomware recovery with reliable rollback
Pros and Cons
  • "Overall, SentinelOne Singularity Complete helps me consolidate my security solutions, as it provides strong automation, reliable support, and valuable rollback capabilities."
  • "I would like to see improvements in the hashes function, particularly in the hashes tab, as multiple hashes are difficult to add in the correct format in SentinelOne Singularity Complete for Windows, Linux, and Mac."

What is our primary use case?

I work with Purple AI and utilize it in SentinelOne.

In my day-to-day activities, SentinelOne Singularity Complete detects malicious activity or dynamic or static activity very quickly within the console.

What is most valuable?

I have been working with SentinelOne Singularity Complete, which is scalable and easy to deploy for the solution and has strong automation.

The main features of SentinelOne Singularity Complete that positively impact my organization are the useful rollback features, the anti-tampering mode, and automated local version upgrades or downgrades.

The rollback features represent the most usable feature of SentinelOne Singularity Complete. When a machine is infected, I can optionally roll back to the earliest date, providing ransomware protection.

Apart from the rollback feature, the most valuable features include the Ranger functionality, which provides network and asset visibility or endpoint visibility. It ingests logs from network sources and captures any threats, including the IOCs.

Overall, SentinelOne Singularity Complete helps me consolidate my security solutions, as it provides strong automation, reliable support, and valuable rollback capabilities.

What needs improvement?

I would like to see improvements in the hashes function, particularly in the hashes tab, as multiple hashes are difficult to add in the correct format in SentinelOne Singularity Complete for Windows, Linux, and Mac.

I would like to see included SIEM functionality, with enhancement in log collection capabilities in SentinelOne Singularity Complete.

For how long have I used the solution?

I have been working with SentinelOne Singularity Complete for the last 2.5 years.

What do I think about the stability of the solution?

In terms of stability, I believe it is not prone to downtime; it is a stable solution.

What do I think about the scalability of the solution?

I find it easy to scale up when necessary.

How are customer service and support?

I evaluate the customer service and technical support of SentinelOne Singularity Complete as very supportive, with fast response times.

I have seen improvements in meantime to detect and respond, with detection times being very good, less than 15 minutes or even less than 10 minutes.

Which solution did I use previously and why did I switch?

I previously worked with Trend Micro for EDR, XDR, and endpoint solutions.

The key differences between SentinelOne Singularity Complete and Trend Micro include the biggest benefit of automation, where most functions are automated, including threat detection and auto-remediation rules.

How was the initial setup?

The initial setup of SentinelOne Singularity Complete was straightforward.

What was our ROI?

I have seen a return on investment with SentinelOne Singularity Complete solution, as it is very easy to understand and functions through one unified agent managing the cloud, SIEM, and EDR solutions.

What's my experience with pricing, setup cost, and licensing?

I find the licensing cost to be very cheap, and implementation is easy, making it so easy to deploy for customers.

What other advice do I have?

SentinelOne Singularity Complete has helped reduce my organization's meantime to detect by minimizing false positives, especially for hashes and IOC blocklist functions.

It is the best method for reducing alerts through the exclusion method in SentinelOne Singularity Complete.

I use the SentinelOne Singularity Complete Ranger functionality.

Ranger in SentinelOne Singularity Complete reduces alerts by capturing different telemetry from the network devices, which is important for my organization as customers mainly use it for both public and private networks.

I don't have specific data to share, but it helps through exclusion and performance-based interoperability to reduce alerts.

Regarding time saving, I find that SentinelOne Singularity Complete helps free up my staff for other projects and tasks as it is a very good product compared to other solutions.

My recommendation for organizations considering SentinelOne Singularity Complete is particularly on the hash part, especially for Linux.

Overall, I would recommend SentinelOne Singularity Complete to others, as I find the solution very good and easy to understand. I have given this review a rating of 9.

Which deployment model are you using for this solution?

Hybrid Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor. The reviewer's company has a business relationship with this vendor other than being a customer: Partner
Last updated: Mar 25, 2026
Flag as inappropriate
PeerSpot user
Technical Specialist at Softcell Technologies Pvt. Ltd.
Real User
Top 5
Feb 25, 2026
Custom rules have strengthened endpoint protection and reduced false positives for my team
Pros and Cons
  • "Overall, SentinelOne Singularity Complete helps me consolidate my security solutions, being the best in endpoint, cloud, and identity."
  • "In the SIEM solution, I would like to see improvements in the data injection process, as it is very fast, and the log collector option is very nice. However, there are issues in blocking the hash, which is complicated due to different segregation for Windows, Linux, and macOS, so I ask for an improvement in this hash blocking function and the manual generation of how many VSS snapshots."

What is our primary use case?

I create policies based on the regarding policy, which means I created custom rules regarding the use case and customer use case.

Most of my use cases are related to the event ID and the process event, so it is easy to use.

What is most valuable?

My impressions of SentinelOne Singularity Complete's ability to ingest data and correlate across the security solutions is that it is better for blocking the hash value and generating the rules manually. It is easy to use.

Overall, SentinelOne Singularity Complete helps me consolidate my security solutions, being the best in endpoint, cloud, and identity.

The best features in SentinelOne Singularity Complete are in the SIEM solution, including the block list in hash value block list and anti-tampering mode.

The best part of the Ranger functionality is that it helps find known and unknown devices, locate IoT devices, and determine how many agents have not been installed in SentinelOne, making it easy to count how many machines are not installed and find IoT devices.

SentinelOne Singularity Complete has helped reduce alerts for me, with the best part being the exclusion, as it has already marked most of the alerts in the cloud as false positives.

SentinelOne Singularity Complete has helped free up my staff for other projects and tasks.

What needs improvement?

In the SIEM solution, I would like to see improvements in the data injection process, as it is very fast, and the log collector option is very nice. However, there are issues in blocking the hash, which is complicated due to different segregation for Windows, Linux, and macOS, so I ask for an improvement in this hash blocking function and the manual generation of how many VSS snapshots.

For how long have I used the solution?

I have been working with SentinelOne Singularity Complete for the last two years.

What do I think about the stability of the solution?

The performance issue with SentinelOne Singularity Complete is very good, but the hash blocking remains complicated and generating many snapshots manually is a recurring challenge.

What do I think about the scalability of the solution?

I work with the Ranger functionality in SentinelOne Singularity Complete, which is used to identify known and unknown devices both in and out of networks.

How are customer service and support?

I evaluate the customer support team of SentinelOne Singularity Complete highly, stating that they provide good support with 24/7 availability.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

I decided to switch to SentinelOne Singularity Complete because it offers a single solution for the endpoint SIEM and singularity purpose, and the console is very easy to handle.

How was the initial setup?

There were challenges during the setup, particularly with the custom rule as the customer asked for application-level blocking that I did not fully understand.

What was our ROI?

The project time is not the means full completely solution but it saves up to 40 days.

What other advice do I have?

Apart from the escalation matrix, I have seen improvement in the mean time to respond, with critical alerts raised below up to 15 minutes and false positive alerts raised in up to one hour.

I mostly use the custom rule and small things for the event type, event query, and searching in event query, focusing on endpoint based solutions in SentinelOne Singularity Complete and the SIEM solution.

I would rate the technical support of SentinelOne Singularity Complete a nine.

I have no recommendations for improvement regarding SentinelOne Singularity Complete as a product or solution.

I rate this review a nine overall.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Last updated: Feb 25, 2026
Flag as inappropriate
PeerSpot user
Luca Sanna - PeerSpot reviewer
security analyst at a tech vendor with 501-1,000 employees
Real User
Top 20
Aug 17, 2026
Advanced endpoint protection has boosted investigations and has reduced incident response time
Pros and Cons
  • "Using SentinelOne Singularity Endpoint has reduced alerts for me and my clients because the agent acts as a teacher for the user, making the good and bad status of a workstation visible to the user, which encourages them to be more careful about their actions."
  • "I give it a nine out of ten because, having worked with all the competitors, there are others that have some more advanced features, but SentinelOne Singularity Endpoint is really wonderful."

What is our primary use case?

My main use case for SentinelOne Singularity Endpoint is that I have a few clients who use it as an enterprise EDR solution because it is powerful, not heavy for the system, and it has really good ransomware protection. Additionally, it does not require many resources compared to other competitors.

I can share a specific example of how one of my clients uses SentinelOne Singularity Endpoint for protection. Since it is installed on all their company workstations, they benefit from an excellent experience offering both antivirus and anti-ransomware protection. Specifically, it blocks all the minor everyday threats, and in one instance, it successfully blocked a ransomware attack before propagation to another computer.

Regarding how my clients use SentinelOne Singularity Endpoint, they are really happy about it because before they were using Sophos Endpoint and had the same protection, but it was much heavier on the machine and used significantly more resources—around 200 MB of RAM more than SentinelOne. This additional resource consumption is excessive, specifically in large networks where not all computers are powerful or recent.

What is most valuable?

SentinelOne Singularity Endpoint's best features stand out to me because I really appreciate one feature named Storyline, and it works exceptionally well with automatic rollback. These features track activity continuously and map each single process in real-time, allowing me to have a visual reconstruction of what is happening. I can fix issues with one click and perform a really good and fast rollback of a computer in response to malware or ransomware. These features have worked really well in the past with encrypted files that were infected just a few seconds following the initial infection.

Storyline has really helped me and my clients in real investigations and incidents. Using the dashboard and Storyline, we can visualize a map of the infection and see how it was extending, which allowed us to find where the infection started. In that case, it was an old PC without SentinelOne Singularity Endpoint protection, but we saw in the logs an infected computer that spread infection over the network from a non-protected computer.

I would add that the AI agent can work directly on the endpoint without relying on the cloud, and the autonomous mitigation feature is really powerful. Additionally, the EDR cloud dashboard allows us to have a very clear visualization of the status of the entire company.

SentinelOne Singularity Endpoint has positively impacted my organization and my clients in several ways: it improves security, speeds up device performance because the previous EDR protection required more resources, saved time during boot time of computers, and reduced incidents. Thanks to the dashboard, it provides a comprehensive status of the company, allowing them to invest money wisely over time.

What needs improvement?

I would really appreciate having raw data of what is happening presented in a clearer format. Additionally, a cloud backup of malware would be beneficial so that we can maintain a copy of the ransomware and malware on SentinelOne for analysis purposes.

I would not want to add more about needed improvements because all of the current capabilities are really awesome, and they have done a really good job.

For how long have I used the solution?

I have been working as a security analyst for the last four years.

What other advice do I have?

I rate SentinelOne Singularity Endpoint a nine out of ten.

I give it a nine out of ten because, having worked with all the competitors, there are others that have some more advanced features, but SentinelOne Singularity Endpoint is really wonderful. I know they make a really good product and it is one of my favorites, but it is not perfect.

Regarding SentinelOne Singularity Endpoint's AI capabilities, I appreciate that feature, but I set rules manually all the time. I have never used or tried to use AI for that purpose. I prefer to use AI to ask about status and to monitor activity, but not for everything else. I have not tried using it for other purposes.

In monitoring, I have used SentinelOne Singularity Endpoint and it is really wonderful; the accuracy is really high, and I trust the output completely. For me, it is really good for all the other capabilities of SentinelOne Singularity Endpoint, which I have never used outside of monitoring. I do not have knowledge about those aspects.

SentinelOne Singularity Endpoint is deployed for my clients in different ways. I have a customer using the public cloud, where SentinelOne Singularity Endpoint protects a few virtual machines and containers in a Kubernetes cluster. I have other customers where it is on-premises and the agent is installed directly on physical endpoints, mostly Windows, to monitor local operating system behavior.

For the public cloud deployment, my customer uses AWS.

I did not purchase SentinelOne Singularity Endpoint through the AWS Marketplace; it was purchased with an Italian SentinelOne reseller.

I appreciate the data ingestion correlation of SentinelOne Singularity Endpoint and the automated Storyline; all of that is really wonderful. SentinelOne Singularity Endpoint helps me connect and analyze data from multiple sources. We have made some integrations with next-generation firewalls such as Palo Alto, and there are integrations that allow us to merge the data into SentinelOne Singularity Endpoint's Data Lake, which reduces our time for data analysis because we can find everything together in SentinelOne Singularity Endpoint.

SentinelOne Singularity Endpoint Complete has helped me consolidate my overall security solutions, also thanks to the automatic Storyline correlation. When Palo Alto logs go into SentinelOne Singularity Endpoint, the AI of SentinelOne Singularity Endpoint connects them to the Storyline technology. For example, one user from a company downloaded a suspicious file, which triggered the advanced threat protection of the Palo Alto firewall. All the data from Palo Alto is integrated with SentinelOne Singularity Endpoint; the AI merges the data from the computer and the firewall, allowing us to conduct a full analysis within SentinelOne Singularity Endpoint and providing a clear visual representation of how the attack or event unfolded—a diagram of the sequence of what happened during a security event.

Using SentinelOne Singularity Endpoint has reduced alerts for me and my clients because the agent acts as a teacher for the user, making the good and bad status of a workstation visible to the user, which encourages them to be more careful about their actions. It is really easy for them to use; the first problem in any company is human error.

SentinelOne Singularity Endpoint Complete has significantly freed up IT and SOC personnel by reducing their daily security operation workload, potentially by around thirty percent.

SentinelOne Singularity Endpoint has helped reduce my organization's Mean Time to Detect. Personally, I have saved between fifteen to twenty hours every week of work, allowing me to reallocate my time to infrastructure projects and other cloud migration tasks. This has given me a lot of spare time where it is most needed. The time savings come from the very core capabilities of SentinelOne Singularity Endpoint: Zero-Touch Remediation and Rollback, automated root cause analysis via Storyline, and the mitigation of alert fatigue.

The automatic capabilities of SentinelOne Singularity Endpoint have reduced the time to respond to incidents by an incredible ninety percent, and this is thanks to the automated emails sent to the security department whenever a potential incident occurs.

The autonomous response capabilities of SentinelOne Singularity Endpoint, specifically Zero-Touch MTTR, allow the agent to evaluate the threat locally on the endpoint and execute immediate containment protocols without waiting for human intervention, achieving an MTTR of under one minute, which is significantly different from competitors.

I do not have experience regarding pricing, setup costs, and licensing for SentinelOne Singularity Endpoint because I work in the IT and security department and do not have access to customer pricing information.

I do not have information about money saved, but I can tell about time saved. In my team, I currently have fifteen free hours each week, and the other four members have reduced their work by more than twenty hours a week.

My advice for others looking into using SentinelOne Singularity Endpoint is to definitely test the rollback feature in a sandbox because it is incredibly powerful, and it is truly awesome to see how quickly it works.

I really appreciate this product, and I want to pursue some certification courses for SentinelOne this autumn. Overall, I rate this product a nine out of ten.

Which deployment model are you using for this solution?

public cloud, on-premises

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

AWS
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Aug 17, 2026
Flag as inappropriate
PeerSpot user
Mohan Janarthanan - PeerSpot reviewer
Associate Vice President at Novac Technology Solutions
Real User
Top 5Leaderboard
Feb 4, 2026
Endpoint protection has delivered full visibility and has strengthened zero-day attack defense
Pros and Cons
  • "I believe Singularity Platform is perfectly fine overall."
  • "From an operational perspective, the customizable dashboards are easy to use, but I face concerns with the alerts from the email ticketing system."

What is our primary use case?

We bought the product for endpoint protection and platform use, where we have two environments: one is the endpoint with laptops, desktops, and VDI environment, and the other is our server environment. We are using CrowdStrike for the server environment, while for the desktops and VDI environment, we are using SentinelOne, Singularity Platform.

What is most valuable?

The benefits from the product include that Singularity Platform provides complete end-to-end visibility on our malware protection and our ransomware protection across our desktops, endpoints, and thin clients and VDI environments, allowing us to control zero-day protection across our environment. There is no need to do any signature patch or anything; we only updated the sensor and fine-tuned the policy here and there during the implementation. We focus on prevention and detection instead of only detection, and we do quarantining as well, leading to complete end-to-end protection across our desktops, laptops, and thin clients and VDI environments.

The real-time personalization feature provides protection against zero-day attacks. Real-time monitoring is very much available in Singularity Platform because once the agent is up to date, it protects critical assets across our network against malicious attacks. Malicious attacks pose a big challenge as if someone downloads malicious files, we face risks. Once an EXE file with vulnerabilities is detected during installation, it will be quarantined, indicating how effective real-time functions are in those scenarios.

What needs improvement?

From an operational perspective, the customizable dashboards are easy to use, but I face concerns with the alerts from the email ticketing system. We receive alerts for every event, such as USB access attempts, which can create unnecessary noise. We fine-tuned the alert mechanism after implementing the solution to reduce this noise.

The alerting mechanism could be improved in Singularity Platform as I want to fine-tune the alerts based on the specific environment. Each environment has different requirements, such as IoT or manufacturing, and we must adapt our policies accordingly.

For how long have I used the solution?

I have been using the product for the past two years.

What do I think about the stability of the solution?

I see no particular areas of improvement for the product because, having used both SentinelOne and CrowdStrike, I find SentinelOne to be good as it performs its functions without requiring much manpower after deployment. The automation helps a lot, and once implemented, we face no further issues regarding stability or scalability; everything works absolutely fine.

What do I think about the scalability of the solution?

Singularity Platform is scalable and stable, with no issues on that part.

How are customer service and support?

The tech support from SentinelOne is great.

How would you rate customer service and support?

Positive

How was the initial setup?

The installation process is quite easy, with no significant issues encountered.

What was our ROI?

We can achieve ROI in about nine months rather than one year. We save approximately 20%.

What's my experience with pricing, setup cost, and licensing?

Singularity Platform is very affordable compared to other options.

Which other solutions did I evaluate?

I would say both SentinelOne and CrowdStrike are equally good, at a 50/50 assessment between them.

What other advice do I have?

The impact of Singularity Platform on our supply chain processes is significant, as supply chain processes are a real headache for the complete organization. Whenever we face any supply chain challenges, we ensure that all end-user and end patch management are updated. We must ensure that particular patches do not have zero-day vulnerabilities or critical vulnerabilities. Ensuring proper IT hygiene is a challenge as well, as some users may not be using the latest patches or may have to stick to legacy applications that prevent upgrades. Protecting our networks and systems is crucial, especially when considering that older operating system versions may not be supported. The challenge in supply chain management is significant.

We use the fraud detection feature for financial services, where we provide financial applications and solutions to our customers. It helps with risk management as it comes with a complete structured approach whenever we implement Singularity Platform. We must ensure that the systems or agents are properly implemented in a tested environment. We first identify risks and then respond. Sometimes we only detect malware files, and depending on the use case, we do our risk assessment and develop a risk methodology to put policies in place based on whether we are using Windows, Linux, or legacy systems.

Regarding the implementation issue, moving from traditional signature-based antivirus solutions to an EDR solution means the new solution must do complete scanning on the initial implementation. However, EDR functions only when incidents occur, which is a change from the previous method used by typical antivirus solutions that scan all files. It is a challenge to explain this shift in expectations, but EDR only reacts when necessary, unlike traditional tools.

I believe Singularity Platform is perfectly fine overall. Some issues with report functionalities and latency are present in other solutions, but not here. The moment we implemented it, everything was clear. It is an excellent, robust tool for protecting our endpoints.

One small example of a challenge I faced is related to connecting my log management part, specifically SIEM. I encountered some issues with parsing when connecting SentinelOne to QRadar for log management.

I would rate this review a 9.

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Feb 4, 2026
Flag as inappropriate
PeerSpot user
Security Analyst at a media company with 501-1,000 employees
Real User
Top 20
Jun 24, 2026
Automated threat response has freed our security team to focus on high‑value client projects
Pros and Cons
  • "In my opinion, the main benefits that SentinelOne Singularity Endpoint provides are many, and the foremost thing you are getting is the best that anyone can offer at such a low price."
  • "Regarding potential areas for improvement for SentinelOne Singularity Endpoint, as I mentioned earlier, I felt that it was generating a very high number of false-positive alerts initially."

What is our primary use case?

My use case with SentinelOne Singularity Endpoint is primarily for security purposes, to secure our clients from different malware. If they download any suspicious file onto their desktop which creates a problem afterwards, then for that purpose, we are basically using this. We are basically an MSSP, providing services to our clients.

What is most valuable?

The features and functions in SentinelOne Singularity Endpoint that I have found most valuable include its fully autonomous nature. We don't have to put manual effort into that. Basically, mostly everything is automated, and also the threat detection feature, the rule remediation feature, and the rollback as I mentioned earlier. If anything comes out to be clean and genuine, then we can just do the rollback so that everything gets back to normal and keeps on running. I feel that is the foremost thing I appreciate: having a fast response and rollback capability.

Singularity Complete has helped me reduce the number of alerts. Although I would say that it is a depreciating factor when it comes to false-positive alerts. Initially, it generates a very high number of false-positive alerts, but by using it accordingly, very prominently, we can control the false-positive alerts by deploying only the necessary use cases that our clients need to detect only true-positive alerts rather than false-positive noises.

Singularity Complete helps my clients free up staff for other projects. I also mentioned earlier that it is fully autonomous. Every feature is automated. It does its work on its own by doing the quarantine. Any malicious thing it detects, its rule engine, which is obviously a behavioral AI. Because everything is automated, it decreases our manual effort. Rather than typing a manual email to a client, which obviously takes fifteen to twenty minutes extra, we are just taking action directly from the SentinelOne Singularity Endpoint user interface. So it reduces our manual effort and time overall.

What needs improvement?

Regarding potential areas for improvement for SentinelOne Singularity Endpoint, as I mentioned earlier, I felt that it was generating a very high number of false-positive alerts initially. Although by making a few changes, we reduced that. The first thing is the false-positive alerts. Also, I've felt that a few of our clients have a very high number of endpoints integrated, such as more than one thousand endpoints have been deployed for those particular clients. For those kinds of clients, I've felt that the resource consumption, including high CPU and disk utilization, is a factor. The utilization sometimes gets very high, so we have to keep it in control and monitor it from time to time. One more thing is creating a customized dashboard, which is not a feature in SentinelOne Singularity Endpoint. We can only view their existing dashboard. No custom dashboard feature is present in SentinelOne Singularity Endpoint, so that's also something that can be brought up in the future.

For how long have I used the solution?

I've been working with SentinelOne Singularity Endpoint product for about a year.

What do I think about the stability of the solution?

Stability-wise, I would rate SentinelOne Singularity Endpoint a nine out of ten.

What do I think about the scalability of the solution?

I would say ten out of ten for the scalability of SentinelOne Singularity Endpoint because we can scale up and scale down as per requirement. We can increase or decrease the number of endpoints, whatever suits perfectly at that particular time.

How are customer service and support?

I would rate SentinelOne's technical support ten out of ten. There have been a number of times when we get in contact with their OEM, the customer support. Their response is very quick. Within a day, we get a response from them. There are a number of times we get stuck in creating a use case or doing whitelisting, blacklisting, or deploying rules. At that particular time, we contact customer support, and we get their response very quickly.

How was the initial setup?

The initial setup for SentinelOne Singularity Endpoint is much simpler, although I have not been a part of the integration team. First, we have to allow SentinelOne Singularity Endpoint on a desktop, then we have to install its endpoint on the desktop or laptop.

Which other solutions did I evaluate?

The main competitor on the market for SentinelOne Singularity Endpoint can be CrowdStrike Falcon. I have not used that product, but I do know that the price range SentinelOne is offering is the best, as Falcon CrowdStrike is much more expensive.

What other advice do I have?

My experience with SentinelOne Singularity Endpoint's ability to ingest and correlate data across security solutions is great because we personally have integrated SentinelOne Singularity Endpoint with a different product and deployed a few correlation use cases. By doing that, we strengthen our use cases, correlating it with different email security solutions. It's been great doing that correlation.

The Mean Time To Respond automatically decreases because everything has been already completed by the AI engine running in the background.

I have limited experience with Purple AI, but I have used some of the features, including identifying IOCs (Indicators of Compromise) in Purple AI and a few other features as well.

Regarding Purple AI's capabilities in threat intelligence for detecting threats, IOCs are utilized for that purpose. By using the copilot feature in Purple AI, where I can use the pull-down menu on the left-hand side, from there I can get the IOCs present on my client's endpoint. By doing that, I can gather threat intelligence on our clients' endpoints.

In my opinion, the main benefits that SentinelOne Singularity Endpoint provides are many. I would say it's already a valuable security device. I can literally line up different things that SentinelOne is offering. Obviously, the foremost thing is for security purposes. You are securing your own desktop, laptop, or whatever server it is. And also, what you are getting at such a low price, I would say. The foremost thing you are getting is the best that anyone can offer. So that's what I would say about SentinelOne Singularity Endpoint.

I have not personally used the Ranger functionality because it has been blocked in our environment, but I am aware of the Ranger functionality that SentinelOne is providing for network security purposes.

Regarding Mean Time To Detect (MTTD), if I compare it with other SIEM solutions, what does that SIEM solution do? It just detects an alert and gives a pop-up that the threat is detected in an environment. But comparing it with SentinelOne Singularity Endpoint, it is doing its work on its own. So, it's very useful compared to other solutions.

I will recommend SentinelOne Singularity Endpoint to other users. I would rate this product ten out of ten overall.

Which deployment model are you using for this solution?

On-premises

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Last updated: Jun 24, 2026
Flag as inappropriate
PeerSpot user
GauravRanade - PeerSpot reviewer
CSO at TechnoCentic
Reseller
Top 10
Jan 15, 2026
Security operations have become more efficient and detection is improving across endpoints
Pros and Cons
  • "As a reseller and user, I would say that SentinelOne Singularity Complete is better than its competition; I have evaluated Palo Alto, Trellix, and CrowdStrike as well, and SentinelOne EDR is much better than all of them as the capability and technical capabilities are superior with efficient and faster detection."
  • "For ingestion and correlation across security solutions, the agent is quite heavier when compared to other competition."

What is our primary use case?

For the major use cases for the client, I would mention EDR.

I have worked and implemented Purple AI. While we were in India, it is more about data privacy as a protection law which has been implemented. Purple AI is collecting all the information which needs to be evaluated and correlate this entire data and segregate and disseminate into different roles and privileges. We have utilized that. These are the mechanisms which are very new into the Indian market and customers and their team members created it and accepted it as well. That is one of the major reasons to sell SentinelOne Singularity Complete.

However, we have not implemented the SecOps feature in major installation as of now.

What is most valuable?

SentinelOne Singularity Complete helps to reduce alerts by almost fifteen to twenty percent. The false alert activation is much more effective in SentinelOne Singularity Complete in competition with all the comparative tools.

It helps to free up my people and staff for other projects. It depends on a project-to-project and team-to-team basis, but it really helps. I would estimate between thirty to fifty percent.

SentinelOne Singularity Complete helps to reduce MTTD by about twenty to thirty percent.

For MTTR, it is almost another way for between fifteen to twenty percent.

As a reseller and user, I would say that SentinelOne Singularity Complete is better than its competition. I have evaluated Palo Alto, Trellix, and CrowdStrike as well. SentinelOne EDR is much better than all of them. The capability and technical capabilities are superior. It is efficient and faster detection.

What needs improvement?

For ingestion and correlation across security solutions, the agent is quite heavier when compared to other competition. The agent has to be light-weighted. That is one of the drawbacks for the competition. They have to work quite a lot.

For how long have I used the solution?

I have been selling the product for three and a half years.

What do I think about the stability of the solution?

As for stability, there are no issues. It is stable.

What do I think about the scalability of the solution?

As for scalability, it is acceptable. The scalability depends entirely on how much security is required for it. It is easy to scale that.

How are customer service and support?

I would say technical support from SentinelOne is excellent. Everyone in SentinelOne is known to us for the last many years.

I would rate support eight point five out of ten. One point five has been removed just because many times it has been delayed or the support has not been available due to vacation. That should be a challenge. Ten out of ten would not even be given to AWS.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

SentinelOne stands out and is the best product among those, especially in India. There was a recent strike incident with Microsoft, and SentinelOne's approach is much better and much more effective.

How was the initial setup?

It is easy to deploy. The deployment model depends on the type of organization. If it is government, then it has to be on-premises. If it is more like an enterprise and BFSI, that can be over the cloud. In India, it has to be done with the intent. It can be into the SentinelOne cloud with an instance in India, or whether it has to be AWS or Azure, they are acceptable in any format.

What about the implementation team?

There is a chance to buy this product through AWS Marketplace, the CPPO. I did that previously.

What's my experience with pricing, setup cost, and licensing?

It is neither too costly, but definitely, it is one of the advantages that SentinelOne is quite adapted towards the pricing.

What other advice do I have?

I do sell SentinelOne Singularity Complete.

I am a Chief Security Officer for Technocentric.

I have been selling this product for the last three and a half years.

I have been involved in this domain for twenty-five years.

I would give SentinelOne Singularity Complete a rating of nine out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
Last updated: Jan 15, 2026
Flag as inappropriate
PeerSpot user
reviewer2848245 - PeerSpot reviewer
Specialty Cybersecurity at a tech vendor with 10,001+ employees
Real User
Top 5Leaderboard
Jun 17, 2026
Real-time behavioral protection has reduced false positives and cuts response from hours to minutes
Pros and Cons
  • "SentinelOne Singularity Endpoint has impacted our organization positively, mainly through cost savings compared to other endpoints."
  • "Customer support for SentinelOne Singularity Endpoint is very good, but I think there needs to be more improvement in the support level to ensure proper responses for customers, especially during session requests."

What is our primary use case?

My main use case for SentinelOne Singularity Endpoint is managing threats and other security measures day-to-day.

Basically, the extensions that I am working on are focused on threat level and investigation level with SentinelOne detection response.

Regarding my main use case with SentinelOne Singularity Endpoint, I have many options to take control from SentinelOne Singularity Endpoint such as disconnecting for troubleshooting.

What is most valuable?

In my experience, the best features SentinelOne Singularity Endpoint offers are designed to protect.

What stands out to me regarding its real-time threat detection, automated response, or ease of use is that we have truly real-time protections, which we can call behavioral threat protection.

The behavioral detection helps my team in day-to-day operations by enabling us to take immediate action.

Another feature I think is worth mentioning is a new feature called VSS snapshot.

SentinelOne Singularity Endpoint has impacted our organization positively, mainly through cost savings compared to other endpoints.

Regarding cost savings, we can compare SentinelOne with other EDR solutions, and I find that SentinelOne is less costly while also having a higher security level for endpoints.

What needs improvement?

For improvement, I could say that there is a report level which needs to be improved at the endpoint level.

Regarding SentinelOne Singularity Endpoint's AI capabilities, I think it would be very good if we have more AI capability for endpoint level governance, which we currently possess.

The accuracy and reliability of SentinelOne Singularity Endpoint's AI output provide quick information about threats and their management, making it reliable very often for us.

For how long have I used the solution?

I have been working for almost nine years in cybersecurity.

What do I think about the stability of the solution?

SentinelOne Singularity Endpoint has been stable in my experience.

What do I think about the scalability of the solution?

Its scalability is very good; it has been easy to manage.

How are customer service and support?

Customer support for SentinelOne Singularity Endpoint is very good, but I think there needs to be more improvement in the support level to ensure proper responses for customers, especially during session requests.

Which solution did I use previously and why did I switch?

Previously, we used McAfee, and we wanted to switch to SentinelOne to see how it would protect our endpoint.

How was the initial setup?

Based on my experience so far, I believe it is fine now, as I already mentioned regarding improvements needed.

What about the implementation team?

I purchased SentinelOne Singularity Endpoint through the AWS Marketplace.

What was our ROI?

I have seen a return on investment in terms of money saved as well as time saved.

It has saved a lot of time for us, allowing us to reduce the time previously spent by our team, which was two to three hours.

SentinelOne Singularity Endpoint has completely reduced our Mean Time to Detect (MTTD), which has changed from the usual eight hours down to two to three hours.

It has improved our Mean Time to Respond (MTTR) significantly; while we used to take two to three hours, SentinelOne Singularity Endpoint can manage it within minutes, hardly ten to fifteen minutes.

What's my experience with pricing, setup cost, and licensing?

My experience with pricing, setup cost, and licensing has been good, and I feel it is very much fine compared to other EDR solutions.

Which other solutions did I evaluate?

Before choosing SentinelOne Singularity Endpoint, I evaluated other options, including CrowdStrike.

What other advice do I have?

The advice I would give to others looking into using SentinelOne Singularity Endpoint is that it saves money and enhances the protection level; it is also very good for saving time on analysis tasks.

Singularity Complete has helped us consolidate our security solutions and it has been completely secured at the endpoint level, which is very good for us.

We use SentinelOne Singularity Endpoint's Ranger functionality for asset visibility, which is important for our endpoint protection level and to assess the health and status of security.

Singularity Complete has reduced alerts significantly; we used to get many alerts but now we are getting very few, and those are true positives only while previously we experienced many false positives.

I would rate this solution nine out of ten.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Last updated: Jun 17, 2026
Flag as inappropriate
PeerSpot user
Buyer's Guide
Download our free SentinelOne Singularity Endpoint Report and get advice and tips from experienced pros sharing their opinions.
Updated: August 2026
Buyer's Guide
Download our free SentinelOne Singularity Endpoint Report and get advice and tips from experienced pros sharing their opinions.