I use SentinelOne Singularity Endpoint for endpoint protection. I utilize it for different companies and different purposes. It is effective for endpoint detections and remediation of the detections. Additionally, I use it for new endpoint discovery within the company intranet. Overall, I use SentinelOne for incident response activities.
Director Of IT Security And Risk Management at AskDegree
Endpoint protection has strengthened incident response and improved threat visibility
Pros and Cons
- "Singularity Complete is a good product in its area and, obviously, when comparing to other organizations or companies providing endpoint detection solutions, it is an end-to-end solution for antimalware and XDR."
- "However, I believe the vulnerability management is currently in pilot. If it can mature into good production where the vulnerability management module is working well within Singularity Complete edition, that would be an awesome step."
What is our primary use case?
What is most valuable?
The best features in SentinelOne Singularity Endpoint are the Sentinels and the features provided within the Sentinel module, which include machine identification and machine details. I can accomplish everything within the endpoint using these features. Endpoint Sentinel is a good detection rule, and if I can create or already have created rules, these are good working rules that protect my organization and make the endpoints more secure.
Ranger is also a cool feature that provides visibility of new endpoints that have been attached or connected within my infrastructure that do not have SentinelOne Singularity Endpoint agent installed on them.
What needs improvement?
Before using SentinelOne Singularity Endpoint, I used different products, including CrowdStrike. In the space where SentinelOne Singularity Endpoint is working, it is an awesome product. However, I believe the vulnerability management is currently in pilot. If it can mature into good production where the vulnerability management module is working well within Singularity Complete edition, that would be an awesome step. The vulnerability assessment is available, but application vulnerability assessment or other endpoint vulnerability assessment is not as good as what other products are providing.
Singularity Complete is a good product in its area and, obviously, when comparing to other organizations or companies providing endpoint detection solutions, it is an end-to-end solution for antimalware and XDR. This has been working fine for me so far. I am using it in small, medium, and enterprise organizations, and it is good. However, as I mentioned for the vulnerability assessment, along with the specification of handling core, detailed forensics, there could be more details I would add. However, if I recall correctly, there is a specific module within SentinelOne Singularity Endpoint to check all details of the functions that happened within the target machine. I am currently unable to recall the name of that module, but it exists. However, there is room for improvement where more details of the solution or from the target can be added, and this would help me more easily identify the impact or the root cause that impacts the endpoint. This would be more helpful for end users. Currently, if there is an impacted endpoint, I click on the endpoint, and it gives me insights about what happened with this endpoint. However, when I need to go into the details, there is some limitation to viewing those details for the target machine. It would be awesome if this module could be integrated into the normal Sentinels. This would be more helpful for engineers working on core identification of root causes.
For how long have I used the solution?
I have been working with SentinelOne Singularity Endpoint for more than two or three years.
Buyer's Guide
SentinelOne Singularity Endpoint
September 2026
Learn what your peers think about SentinelOne Singularity Endpoint. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
915,817 professionals have used our research since 2012.
What do I think about the stability of the solution?
It is working fine for me. In the majority of cases where files have been detected as malware or virus within the organization on the target machine, they are quarantined. This is good functionality from XDR, as I mentioned earlier.
What do I think about the scalability of the solution?
For me, it is good, but I believe SentinelOne Singularity Endpoint does not directly engage with customers who have fewer than one thousand nodes. I have to engage through SentinelOne's partners. This is an impact based on market or company strategy. The pricing is not too bad; it is good. If I directly engage the organization or company, the pricing is different and obviously better. Additionally, when I go directly within the company, they provide visibility or vigilance services to customers at the same price. When I go into the partner channel, my account is within the partner's umbrella, and they provide limited support for visibility and further incident investigations. This is a limitation for small and medium organizations. However, for large organizations that can directly engage SentinelOne Singularity Endpoint, this is a positive point, but there is a lag when I go into the partner channel. The partners engage with customers in their own way, and that is how it works.
How was the initial setup?
For me as an end user, the setup process was not difficult because everything was set up from the partner's side. I may not be the right person to answer for all aspects. For the end user, it is very easy. The partner set up the whole environment within a week or two. After creating the whole setup, as an end user, I would just have to install SentinelOne Singularity Endpoint agent into my end user devices or servers. It is easy to do that. Once I do this and the environment has been set up with all Sentinels collecting data from end user devices or servers, everything is there and the environment has been set up. It is easy for end users, but obviously for those creating the environment, the whole environment, creation of security rules, detection rules, and those kinds of things may be challenging, especially for beginners. That would be the challenging part, and I did not do it earlier, so I cannot comment on it fully.
What's my experience with pricing, setup cost, and licensing?
It is comparative to other products and is cost-efficient.
Which other solutions did I evaluate?
This is a competitive market with competitive solutions that have core good products and features within them. If I am looking for an endpoint protection solution, this is a good product because I always compare SentinelOne Singularity Endpoint with CrowdStrike and Microsoft Defender. Based on that comparison, if SentinelOne Singularity Endpoint had good vulnerability assessment capabilities, because currently the vulnerability assessment is based on the application, not the operating system, it would be a good point from the perspective of cost-efficiency along with the features within the product. SentinelOne Singularity Endpoint has Ranger, Sentinels, and visibility where I can go in and have detailed knowledge about every detection along with every happening on the target machine. This is good, but SentinelOne Singularity Endpoint is still lagging under the vulnerability assessment module.
What other advice do I have?
SentinelOne Singularity Endpoint provides alerting into the dashboard, but I did not configure it correctly and never received alerts over emails. If such a feature exists within the product, that would be awesome, and I could incorporate and configure it. Currently, I do not have visibility on it. Once I log into SentinelOne Singularity Endpoint, it provides visibility within the dashboard showing how many endpoints have been detected as infected, how many endpoints are impacted, and how many endpoints have been identified as malware where SentinelOne Singularity Endpoint has quarantined those files, and I can do analysis and further processing. However, currently, I did not configure it if it is available, but I am unable to navigate it. I do not have visibility on whether any endpoints or target machines have been impacted so that I receive email notifications or SMS notifications alerting me that a machine has been impacted and needs to be worked on urgently. This is a critical function I need to perform right now. If this would be configurable or is available in SentinelOne Singularity Endpoint, that is awesome. If not, then the alerting mechanism needs to be improved to get alerts over emails or SMS for at minimum critical assets.
I can say that I currently did not implement it in such a way because for what I am using SentinelOne Singularity Endpoint for, it is the on-premises infrastructure for some organizations and just for endpoints in other organizations. In that case, I believe for SaaS products, I am currently not utilizing it for such things. My question is whether SentinelOne Singularity Endpoint is an agent-based solution that I can only utilize on endpoints or servers or where the operating system is Linux or different flavors where the operating system is running. However, for the serverless environment, SentinelOne Singularity Endpoint cannot work. Is that the right expectation?
Obviously, the core concern is about data protection and privacy. There is something I have to adopt with AI. If I do not adopt it, I am not running with the market and chasing new goals. The thing is I have to implement frameworks such as ISO 42001 to manage data and contain my data's confidentiality and privacy. This is core importance for me in my job role. I take care of this all the time, and obviously if I am integrating solutions that utilize AI-based features into their product, I do have vendor management or vendor risk management to perform with vendors. I currently look into AI standards or framework implementation within organizations if they are providing me with full core data security. This is the point I engage in with existing and onboarding vendors. Additionally, I am currently utilizing AI and making AI models within my organizations. I implement security standards and maintain the whole implementation and operationalization of data protections within AI models and machine learning models.
This is the function that can be adopted, and if it is in the product, obviously this is a positive point and I do encourage that utilization of AI models within products. As I mentioned, if I got email alerts or SMS alerts for critical systems and if AI has been engaged into threat modeling with well-known algorithms that identify what threats, viruses, or malicious insights have been identified in the system, and if AI can guess that certain operating systems, files, or things are critical to my organization and can do this on a real-time basis, that would be a positive point. Obviously, as I mentioned, if I want to run with the market, I have to integrate those AI threat modeling or AI remediations within my organization. I have to do that. I give this review an overall rating of eight out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: May 19, 2026
Flag as inappropriateingénieur systèmes et sécurité at a financial services firm with 201-500 employees
Endpoint protection has unified workloads and has freed days each month for security projects
Pros and Cons
- "SentinelOne Singularity Endpoint has allowed me to free up time for my teams so they can focus on other projects or tasks."
- "I think there are other improvement points to consider regarding SentinelOne Singularity Endpoint. The public documentation is not quite comprehensive enough; it would be good if they improved the search engine for the technical documentation."
What is our primary use case?
My main use of SentinelOne Singularity Endpoint in my organization is to protect all of our endpoints, including our Kubernetes pods, our users' workstations, our Windows and Linux servers.
A concrete example of how I use SentinelOne Singularity Endpoint in my daily work is that the main tasks are to clear doubts on alerts related to threats. The majority of the time, approximately 90% of alerts turn out to be false positives, but the AI model learns relatively quickly and after two years, we no longer have to clear that many false positives.
Regarding rule customization and the remediation feature, these aspects concretely make my security management easier on a daily basis. The custom rules can allow you to reach a level similar to AppLocker. We use them to monitor everything that happens in certain user folders and to enable detection of unauthorized applications.
How has it helped my organization?
SentinelOne Singularity Endpoint has had a positive impact on my organization because it has allowed us to protect our entire environment, both Linux and Windows, which its former competitor did not do.
I have seen measurable benefits with SentinelOne Singularity Endpoint, specifically time savings, because the previous tool was very time-consuming in terms of the application itself. Here, we have very few failures of the SentinelOne client; it is very easy to update, and it is a considerable time saver compared to its former competitor.
Overall, SentinelOne Singularity Endpoint has helped me consolidate my security solutions as it allowed us to improve detection rules on our SIEM. Since we ingest SentinelOne logs into our SIEM, it has helped us improve our detection rules.
SentinelOne Singularity Endpoint has allowed me to free up time for my teams so they can focus on other projects or tasks. Comparing the person-day maintenance cost of the old product, it may have allowed us to gain one to two person-days per month.
What is most valuable?
My main use of SentinelOne Singularity Endpoint in my organization is to protect all of our endpoints, including our Kubernetes pods, our users' workstations, our Windows and Linux servers.
The tool offers Star Custom Rules. These rules actually allow you to customize detections based on the information system.
In my opinion, the best features that SentinelOne Singularity Endpoint offers my organization are, first, the Star Custom Rule component, which allows you to customize things based on the IS and the endpoints targeted by attacks. There is also the remediation component, which allows you to roll back based on the malicious actions that have been carried out on a workstation.
Another particularly useful aspect of SentinelOne Singularity Endpoint is the Deep Visibility component, which logs all system actions on the machines. This allows you to do forensics if needed or to really understand what happened on the endpoint.
What needs improvement?
SentinelOne Singularity Endpoint could be improved in the future by integrating detection models on prompts for the various artificial intelligences available on the market, in particular.
I think there are other improvement points to consider regarding SentinelOne Singularity Endpoint. The public documentation is not quite comprehensive enough; it would be good if they improved the search engine for the technical documentation.
For how long have I used the solution?
I have been using SentinelOne Singularity Endpoint in my company for about five years.
What do I think about the stability of the solution?
I find that SentinelOne Singularity Endpoint is stable in my environment; it is very stable. We really have very few crashes to report. When there are agent crashes, it is mainly related to the operating system version being obsolete.
What do I think about the scalability of the solution?
I have encountered difficulties or limitations when I wanted to extend or adapt the use of SentinelOne Singularity Endpoint to a larger number of workstations or servers in my organization. The only difficulty we have is that, since we have fairly old operating systems running on 32-bit CPUs, those are not supported by SentinelOne.
How are customer service and support?
I rate the customer support provided for SentinelOne Singularity Endpoint based on my experience as we do not have direct support with SentinelOne; our MSSP is responsible for contacting customer support. We have had incidents with fairly high levels of criticality, and SentinelOne responded very quickly.
Which solution did I use previously and why did I switch?
Before adopting SentinelOne Singularity Endpoint, we were using Bitdefender, which no longer suited us because it required a lot of maintenance time.
How was the initial setup?
The advice I would give to other professionals who are considering using SentinelOne Singularity Endpoint is that during implementation, do not put it directly into blocking mode but allow an adaptation period for the solution in detect mode in order to clear as many false positives as possible.
What about the implementation team?
Regarding the cloud part, I cannot answer that question; it is the MSSP company that manages it.
What was our ROI?
I have seen a return on investment with SentinelOne Singularity Endpoint; it is more about time savings than anything else.
What's my experience with pricing, setup cost, and licensing?
My perception regarding the price, implementation costs, and license management of SentinelOne Singularity Endpoint is that the price provided by our supplier is very competitive.
Which other solutions did I evaluate?
Before choosing SentinelOne Singularity Endpoint, it was the main one we evaluated; we also looked at HarfangLab, but the cost was significantly higher for minimal gains.
What other advice do I have?
I give SentinelOne Singularity Endpoint a rating of 8 out of 10. I chose 8 out of 10 because it is a very good score that comes close to perfection, but since there are always improvements to be made to a product, I did not want to give the maximum score.
Which deployment model are you using for this solution?
SentinelOne Singularity Endpoint is deployed on-premises in my organization.
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Sep 2, 2026
Flag as inappropriateBuyer's Guide
SentinelOne Singularity Endpoint
September 2026
Learn what your peers think about SentinelOne Singularity Endpoint. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
915,817 professionals have used our research since 2012.
Technical Support Team Leader at Safezone Secure Solutions Private Limited
Endpoint protection has delivered fast AI-driven ransomware defense and rapid incident response
Pros and Cons
- "This is a very good solution because we can easily correlate the logs from the gateway and SentinelOne Singularity Endpoint, easily find out and get visibility on where the attack happened, how the virus came in, whether it is from mail or firewall or anything else, and easily monitor everything in SentinelOne Singularity Endpoint."
- "However, competitors such as Trellix and Trend Micro have features for web protection with category-based web protection for web security."
What is our primary use case?
We have been using SentinelOne Singularity Endpoint for our customers. They requested next-gen antivirus, EDR solution, and XDR solutions. We are working with use cases that involve features such as behavioral AI detection for ransomware and zero-day exploit protection.
What is most valuable?
We have the VSS feature, which is the Windows Shadow Copy. This is one of the very good features of SentinelOne Singularity Endpoint. If a file gets corrupted or is affected with a virus, we can restore it within the previous four hours. The malware protection has been providing an AI-based NDR solution that is working effectively, and it is a lightweight agent that is not utilizing more CPU and does not impact customer system performance.
Other security solutions can easily correlate and integrate with our gateway solutions such as firewalls and mail security. The SIEM solution can be easily integrated, and we can monitor and correlate the logs. This is a very good solution because we can easily correlate the logs from the gateway and SentinelOne Singularity Endpoint. We can easily find out and get visibility on where the attack happened, how the virus came in, whether it is from mail or firewall or anything else. We can easily monitor everything in SentinelOne Singularity Endpoint.
What needs improvement?
Everything has been fine from my side. We are getting feedback from customers who are expecting web protection. The malware and Singularity capabilities are working fine with no problems. It can detect virus and spyware effectively. However, competitors such as Trellix and Trend Micro have features for web protection with category-based web protection for web security. This option is not available in SentinelOne Singularity Endpoint. We can block a particular URL, but we need to manually add the URL in SentinelOne Singularity Endpoint. Competitors such as Trellix and Trend Micro have category-based options such as social networking and search engines. If SentinelOne Singularity Endpoint provides this kind of feature in the future, it will be easier to approach our customers, and we can easily transition our existing customers from Trend Micro and Trellix.
For how long have I used the solution?
I have been working with SentinelOne Singularity Endpoint for five years.
What do I think about the stability of the solution?
SentinelOne Singularity Endpoint is very stable. I would rate it at nine points.
What do I think about the scalability of the solution?
Scalability is very good. I would rate it at ten.
How are customer service and support?
Customer support is good. If we create a ticket, we are getting a response within four hours, so we can get support without any problems on the customer side.
I would rate the customer support at seven points.
Which other solutions did I evaluate?
When I checked the price, almost everything has been equal. For the single agent when I compared SentinelOne Singularity Endpoint with Trend Micro and Trellix EDR solutions, they have almost similar pricing. There is no significant variant. From customer feedback, the only difference is that SentinelOne Singularity Endpoint requires manual URL addition for web protection, whereas Trend Micro and Trellix have category-based options.
What other advice do I have?
We can configure malware alerts, ransomware alerts, and email notification alerts. We can configure daily basis alerts and infected file notifications. Malware detection, virus detection, spyware detection, and ransomware protection can all be configured. We have also created AI-based alerts so that any suspicious or abnormal activity can be configured with a playbook to trigger on that activity.
Regarding mean time to respond, we are able to respond and communicate at the solution level. The productivity timing shows approximately ten minutes of saving on average. This is the mean time to respond.
The process of configuration is very easy and not complicated in SentinelOne Singularity Endpoint.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Amazon Web Services (AWS)
Disclosure: My company has a business relationship with this vendor other than being a customer. Integrator
Last updated: Jul 15, 2026
Flag as inappropriateEdr Analyst at Softcell Technologies Limited
Automated threat response has reduced incident impact and gives teams faster attack visibility
Pros and Cons
- "What I appreciate most about SentinelOne Singularity Endpoint is its automation features such as automated threat detection and responses, which can detect malicious activity, isolate devices, and even automatically roll back ransomware damage."
- "I believe SentinelOne Singularity Endpoint is a strong security platform, but areas for improvement include reporting and dashboard customization, as well as providing more advanced threat hunting queries and easier navigation for new users, which would enhance the overall experience."
What is our primary use case?
My use case for SentinelOne Singularity Endpoint is that it is basically an EDR XDR platform that detects, investigates, and responds to cyber threats on endpoints, while also providing real-time visibility, automated threat detection, ransomware protection, and incident responses, thereby helping security teams protect the system from advanced attacks.
What is most valuable?
What I appreciate most about SentinelOne Singularity Endpoint is its automation features such as automated threat detection and responses, which can detect malicious activity, isolate devices, and even automatically roll back ransomware damage. It reduces response times and workload, making it the best feature in my view.
We correlate SentinelOne Singularity Endpoint with multiple device types, making it easy to respond to any triggered alerts, enabling us to link related security events and create a complete view of an attacker. This helps us analyze and understand how a threat spreads and impacts our systems, thus improving investigation speed and reducing false positive alerts for faster incident responses.
What needs improvement?
I believe SentinelOne Singularity Endpoint is a strong security platform, but areas for improvement include reporting and dashboard customization, as well as providing more advanced threat hunting queries and easier navigation for new users, which would enhance the overall experience.
For how long have I used the solution?
I have been using SentinelOne Singularity Endpoint for more than two to three years.
What do I think about the stability of the solution?
SentinelOne Singularity Endpoint is a stable and reliable platform that delivers continuous endpoint protection with minimal performance impact, efficiently handling large environments and providing consistent security monitoring and response capabilities without any observed lagging or downtime.
What do I think about the scalability of the solution?
The scalability of SentinelOne Singularity Endpoint is excellent as it is highly suitable for both small and large organizations, capable of protecting thousands of endpoints while maintaining good performance, making it a smart choice for growing businesses.
How are customer service and support?
I have contacted technical support several times and found them to be excellent as they respond quickly to my queries, providing dedicated support with knowledge-based documentation and training resources that assist engineers in troubleshooting, deploying policies, configurations, and threat investigations, helping our organization maintain smooth operations and resolve security issues quickly.
The quality and speed of support are excellent. Whenever I raise critical alerts or incidents that could impact business, the response is usually within ten to fifteen minutes, allowing them to troubleshoot and suggest actionable steps very quickly.
Which solution did I use previously and why did I switch?
I have used CrowdStrike for two to three months, along with other tools including QRadar and Splunk.
When comparing CrowdStrike to SentinelOne Singularity Endpoint, I prefer SentinelOne Singularity Endpoint more because it is more autonomous and AI-driven in its responses. It can automatically detect, kill, quarantine, remediate threats and roll back, including features such as asset discovery and ransomware recoveries, as well as providing strong offline protections. On the other hand, CrowdStrike offers excellent threat intelligence and managed threat hunting, utilizing a cloud-native architecture with lightweight agents and offering visibility and threat detection through the Falcon platform, which is widely adopted by large enterprises.
How was the initial setup?
The initial deployment of SentinelOne Singularity Endpoint was straightforward as I integrated it with multiple types of tools including threat intelligence platforms, cloud servers, firewalls, and ticketing tools, improving visibility and automating workflows to enhance overall security operations.
What about the implementation team?
I reviewed SentinelOne Singularity Endpoint, which is called Endpoint Detection and Response.
What was our ROI?
Regarding the pricing for SentinelOne Singularity Endpoint, I think although it requires investment, it helps reduce security risks and ransomware attacks while lowering operational costs through automation, providing excellent value and return on investment due to its strong protection and rapid response capabilities.
What's my experience with pricing, setup cost, and licensing?
SentinelOne Singularity Endpoint requires minimal maintenance because it offers cloud-based management and automated updates, allowing security teams to manage policies, monitor threats, and maintain endpoint security from a centralized console.
Which other solutions did I evaluate?
I have used the Ranger feature, which provides network visibility and asset discovery by automatically identifying unmanaged devices connected to the network, including laptops, servers, and printers, helping security teams find unknown assets and reduce blind spots to improve overall security visibility without requiring additional hardware.
I have used Purple AI, which is designed for incident analytics, enabling me to ask questions such as showing all devices affected by specific threats. It quickly provides insights into incidents and recommends actions for investigations.
What other advice do I have?
Purple AI is designed with data privacy and security in mind, ensuring that customer data is processed according to compliance requirements, which allows organizations to maintain control over their data while using AI-powered assistance for threat investigations and analysis. My overall rating for this product is eight out of ten.
Disclosure: My company has a business relationship with this vendor other than being a customer. MSSP
Last updated: Jun 30, 2026
Flag as inappropriateTechnical Support at Softcell Technologies Limited
Automation has reduced detection time and has simplified ransomware recovery with reliable rollback
Pros and Cons
- "Overall, SentinelOne Singularity Complete helps me consolidate my security solutions, as it provides strong automation, reliable support, and valuable rollback capabilities."
- "I would like to see improvements in the hashes function, particularly in the hashes tab, as multiple hashes are difficult to add in the correct format in SentinelOne Singularity Complete for Windows, Linux, and Mac."
What is our primary use case?
I work with Purple AI and utilize it in SentinelOne.
In my day-to-day activities, SentinelOne Singularity Complete detects malicious activity or dynamic or static activity very quickly within the console.
What is most valuable?
I have been working with SentinelOne Singularity Complete, which is scalable and easy to deploy for the solution and has strong automation.
The main features of SentinelOne Singularity Complete that positively impact my organization are the useful rollback features, the anti-tampering mode, and automated local version upgrades or downgrades.
The rollback features represent the most usable feature of SentinelOne Singularity Complete. When a machine is infected, I can optionally roll back to the earliest date, providing ransomware protection.
Apart from the rollback feature, the most valuable features include the Ranger functionality, which provides network and asset visibility or endpoint visibility. It ingests logs from network sources and captures any threats, including the IOCs.
Overall, SentinelOne Singularity Complete helps me consolidate my security solutions, as it provides strong automation, reliable support, and valuable rollback capabilities.
What needs improvement?
I would like to see improvements in the hashes function, particularly in the hashes tab, as multiple hashes are difficult to add in the correct format in SentinelOne Singularity Complete for Windows, Linux, and Mac.
I would like to see included SIEM functionality, with enhancement in log collection capabilities in SentinelOne Singularity Complete.
For how long have I used the solution?
I have been working with SentinelOne Singularity Complete for the last 2.5 years.
What do I think about the stability of the solution?
In terms of stability, I believe it is not prone to downtime; it is a stable solution.
What do I think about the scalability of the solution?
I find it easy to scale up when necessary.
How are customer service and support?
I evaluate the customer service and technical support of SentinelOne Singularity Complete as very supportive, with fast response times.
I have seen improvements in meantime to detect and respond, with detection times being very good, less than 15 minutes or even less than 10 minutes.
Which solution did I use previously and why did I switch?
I previously worked with Trend Micro for EDR, XDR, and endpoint solutions.
The key differences between SentinelOne Singularity Complete and Trend Micro include the biggest benefit of automation, where most functions are automated, including threat detection and auto-remediation rules.
How was the initial setup?
The initial setup of SentinelOne Singularity Complete was straightforward.
What was our ROI?
I have seen a return on investment with SentinelOne Singularity Complete solution, as it is very easy to understand and functions through one unified agent managing the cloud, SIEM, and EDR solutions.
What's my experience with pricing, setup cost, and licensing?
I find the licensing cost to be very cheap, and implementation is easy, making it so easy to deploy for customers.
What other advice do I have?
SentinelOne Singularity Complete has helped reduce my organization's meantime to detect by minimizing false positives, especially for hashes and IOC blocklist functions.
It is the best method for reducing alerts through the exclusion method in SentinelOne Singularity Complete.
I use the SentinelOne Singularity Complete Ranger functionality.
Ranger in SentinelOne Singularity Complete reduces alerts by capturing different telemetry from the network devices, which is important for my organization as customers mainly use it for both public and private networks.
I don't have specific data to share, but it helps through exclusion and performance-based interoperability to reduce alerts.
Regarding time saving, I find that SentinelOne Singularity Complete helps free up my staff for other projects and tasks as it is a very good product compared to other solutions.
My recommendation for organizations considering SentinelOne Singularity Complete is particularly on the hash part, especially for Linux.
Overall, I would recommend SentinelOne Singularity Complete to others, as I find the solution very good and easy to understand. I have given this review a rating of 9.
Which deployment model are you using for this solution?
Hybrid Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor. The reviewer's company has a business relationship with this vendor other than being a customer: Partner
Last updated: Mar 25, 2026
Flag as inappropriateCentralized protection has reduced threats and enabled rapid remote scans and confident governance
Pros and Cons
- "To me, that would be the expected antivirus software or security software that should be standard with MSPs and organizations as a whole."
- "It might not be the best for whitelisting custom applications that are not preloaded into SentinelOne for whitelisting, but outside of that, it is a very good tool and probably one of the best ones I have ever used."
What is our primary use case?
My main use case for SentinelOne Singularity Endpoint is whitelisting applications. I use whitelisting for different domains, file paths, executables, and disabling snapshots.
What is most valuable?
The best features SentinelOne Singularity Endpoint offers include the ability to remotely scan computers with the current latest and greatest holistic software without downloading the newest agent to scan the system. I can scan a system remotely against the most recent signature database and updated definitions with holistic analysis of the application in a pinch. I can also remotely deploy and remotely update agents as needed, which is a really good feature to have.
I find myself using the remote scan and update feature constantly. When I work in IT, we get calls all the time from end users about clicking on suspicious links or emails, and being able to simply execute a remote scan on demand is extremely helpful.
SentinelOne Singularity Endpoint has helped reduce my organization's mean time to detect. Overall, it protects you instantly based on a user doing something they probably should not be doing and opening an application they should not have, and it usually gets stopped right then and there.
What needs improvement?
SentinelOne Singularity Endpoint is an amazing product for security and threat detection and mitigation, as well as for being able to secure an environment from a single location. It offers great flexibility with being able to add and remove devices, as well as keeping your environment secure. You can be confident in its ability to protect your environment because of how well SentinelOne Singularity Endpoint is put together. It might not be the best for whitelisting custom applications that are not preloaded into SentinelOne for whitelisting, but outside of that, it is a very good tool and probably one of the best ones I have ever used.
Overall, SentinelOne Singularity Endpoint is a great all-around product, but there is room for improvement when it comes to whitelisting services that also use VSS writers. For applications that use VSS writers such as backup data and recovery software, SentinelOne Singularity Endpoint needs to make it easier for customers to whitelist agents and BDR agents. There are so many nooks and crannies of BDR systems that in SentinelOne, you need to navigate to a multitude of different windows just to get the actual agent to be fully whitelisted. If it could all be on one screen, that would be amazing. If it could be a simple one-click completion, that would be even better.
I would recommend continuing the good work and working on making it easier for customers to whitelist third-party software, as that would be a huge step in the right direction. SentinelOne should start going further into mobile device protection, which would be amazing to have for tablets, mobile devices, and gaming systems. For Linux especially on gaming systems where people browse the internet, being able to deploy SentinelOne would be really awesome.
Regarding SentinelOne Singularity Endpoint's AI capabilities, I think it is probably more or less lacking in governance but has really good security. When I talk about governance, I am referring to FIPS certified governance. It would be really good if you could use SentinelOne to audit compliance with that, such as identifying that a particular router or switch is not compliant or that certain parts of a switch or a particular part of a server for Kerberos authentication or TLS is not compliant. If SentinelOne could fit that kind of feature inside its product, that would be amazing.
For how long have I used the solution?
I have been working in my current field for two months.
What do I think about the stability of the solution?
Even though SentinelOne Singularity Endpoint's ability to detect and respond to an issue is pretty much instant, we in IT still have to respond to the actual end user and their ticket.
What do I think about the scalability of the solution?
SentinelOne Singularity Endpoint's scalability is awesome, and I have not ever had any issues with that. As far as being stable, it is absolutely stable.
How are customer service and support?
Customer support for SentinelOne Singularity Endpoint is amazing. I have only had to use customer support once, which was to whitelist an application where the new UI of Singularity made whitelisting the file path difficult because it changed the order of operations on how whitelisting happens. My documentation was set up for the old portal through the old process of how you whitelist an application, and once the new view came out, it changed how that process worked. I had to go back through and update my documentation on it.
Licensing for SentinelOne Singularity Endpoint was great, as it was quick and easy to get users added and removed from the system. Outside of that, I have not had to do anything else with SentinelOne.
Which solution did I use previously and why did I switch?
I was working at a company that was already using CrowdStrike Falcon, so it was not that we switched or that I stopped using SentinelOne. It is just that CrowdStrike Falcon was what was given to me, and that is what I had to use.
What was our ROI?
The biggest benefit that SentinelOne would provide in this case is simply reputation. Because of how well SentinelOne is as a product, if a company or an MSP rolls out with it, you know you are secure and can feel confident in that. That is to me the biggest benefit that SentinelOne can offer.
What other advice do I have?
I have been using SentinelOne Singularity Endpoint on and off for a while now. I am used to the older portal, but since the transition to the newer one, I have only used it for maybe five to six months.
When you are working with an MSP that deploys SentinelOne Singularity Endpoint and has experience with it, you get a boost in reputation for just having that. To me, that would be the expected antivirus software or security software that should be standard with MSPs and organizations as a whole. SentinelOne sets the bar for security mitigation.
There was a specific section where I discussed governance, and I would actually include it here. If I could use SentinelOne as a way to audit my governance for specifically NIST 873 or FIPS 140-3 or CMMC2, that would be amazing.
If I was seeking a product for security and mitigation, I would start with SentinelOne and end with SentinelOne. I would put more trust in that application than any other on the market, one because I have a lot of experience with it, but two, it is trusted by most MSPs that I have worked with.
I have used SentinelOne Singularity Endpoint's Ranger functionality before, but only one time, and I cannot recall everything I did with it. It was with network enumeration, and that was kind of the limit of what I used it for.
I never got to choose between different security systems because the companies that I worked for either already had SentinelOne set up or they did not.
My advice for others looking into using SentinelOne Singularity Endpoint is to do it, as you have nothing to lose, and it is the best there is. I would probably shorten the name SentinelOne Singularity Endpoint, as it is kind of long and a mouthful. Just keeping it as SentinelOne sounds better, as it sounds SentinelOne has a new product called Singularity when you say it that way. I gave this review a rating of ten out of ten.
Which deployment model are you using for this solution?
Hybrid Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Sep 2, 2026
Flag as inappropriateTechnical Specialist at Softcell Technologies Pvt. Ltd.
Custom rules have strengthened endpoint protection and reduced false positives for my team
Pros and Cons
- "Overall, SentinelOne Singularity Complete helps me consolidate my security solutions, being the best in endpoint, cloud, and identity."
- "In the SIEM solution, I would like to see improvements in the data injection process, as it is very fast, and the log collector option is very nice. However, there are issues in blocking the hash, which is complicated due to different segregation for Windows, Linux, and macOS, so I ask for an improvement in this hash blocking function and the manual generation of how many VSS snapshots."
What is our primary use case?
I create policies based on the regarding policy, which means I created custom rules regarding the use case and customer use case.
Most of my use cases are related to the event ID and the process event, so it is easy to use.
What is most valuable?
My impressions of SentinelOne Singularity Complete's ability to ingest data and correlate across the security solutions is that it is better for blocking the hash value and generating the rules manually. It is easy to use.
Overall, SentinelOne Singularity Complete helps me consolidate my security solutions, being the best in endpoint, cloud, and identity.
The best features in SentinelOne Singularity Complete are in the SIEM solution, including the block list in hash value block list and anti-tampering mode.
The best part of the Ranger functionality is that it helps find known and unknown devices, locate IoT devices, and determine how many agents have not been installed in SentinelOne, making it easy to count how many machines are not installed and find IoT devices.
SentinelOne Singularity Complete has helped reduce alerts for me, with the best part being the exclusion, as it has already marked most of the alerts in the cloud as false positives.
SentinelOne Singularity Complete has helped free up my staff for other projects and tasks.
What needs improvement?
In the SIEM solution, I would like to see improvements in the data injection process, as it is very fast, and the log collector option is very nice. However, there are issues in blocking the hash, which is complicated due to different segregation for Windows, Linux, and macOS, so I ask for an improvement in this hash blocking function and the manual generation of how many VSS snapshots.
For how long have I used the solution?
I have been working with SentinelOne Singularity Complete for the last two years.
What do I think about the stability of the solution?
The performance issue with SentinelOne Singularity Complete is very good, but the hash blocking remains complicated and generating many snapshots manually is a recurring challenge.
What do I think about the scalability of the solution?
I work with the Ranger functionality in SentinelOne Singularity Complete, which is used to identify known and unknown devices both in and out of networks.
How are customer service and support?
I evaluate the customer support team of SentinelOne Singularity Complete highly, stating that they provide good support with 24/7 availability.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I decided to switch to SentinelOne Singularity Complete because it offers a single solution for the endpoint SIEM and singularity purpose, and the console is very easy to handle.
How was the initial setup?
There were challenges during the setup, particularly with the custom rule as the customer asked for application-level blocking that I did not fully understand.
What was our ROI?
The project time is not the means full completely solution but it saves up to 40 days.
What other advice do I have?
Apart from the escalation matrix, I have seen improvement in the mean time to respond, with critical alerts raised below up to 15 minutes and false positive alerts raised in up to one hour.
I mostly use the custom rule and small things for the event type, event query, and searching in event query, focusing on endpoint based solutions in SentinelOne Singularity Complete and the SIEM solution.
I would rate the technical support of SentinelOne Singularity Complete a nine.
I have no recommendations for improvement regarding SentinelOne Singularity Complete as a product or solution.
I rate this review a nine overall.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Last updated: Feb 25, 2026
Flag as inappropriatesecurity analyst at a tech vendor with 501-1,000 employees
Advanced endpoint protection has boosted investigations and has reduced incident response time
Pros and Cons
- "Using SentinelOne Singularity Endpoint has reduced alerts for me and my clients because the agent acts as a teacher for the user, making the good and bad status of a workstation visible to the user, which encourages them to be more careful about their actions."
- "I give it a nine out of ten because, having worked with all the competitors, there are others that have some more advanced features, but SentinelOne Singularity Endpoint is really wonderful."
What is our primary use case?
My main use case for SentinelOne Singularity Endpoint is that I have a few clients who use it as an enterprise EDR solution because it is powerful, not heavy for the system, and it has really good ransomware protection. Additionally, it does not require many resources compared to other competitors.
I can share a specific example of how one of my clients uses SentinelOne Singularity Endpoint for protection. Since it is installed on all their company workstations, they benefit from an excellent experience offering both antivirus and anti-ransomware protection. Specifically, it blocks all the minor everyday threats, and in one instance, it successfully blocked a ransomware attack before propagation to another computer.
Regarding how my clients use SentinelOne Singularity Endpoint, they are really happy about it because before they were using Sophos Endpoint and had the same protection, but it was much heavier on the machine and used significantly more resources—around 200 MB of RAM more than SentinelOne. This additional resource consumption is excessive, specifically in large networks where not all computers are powerful or recent.
What is most valuable?
SentinelOne Singularity Endpoint's best features stand out to me because I really appreciate one feature named Storyline, and it works exceptionally well with automatic rollback. These features track activity continuously and map each single process in real-time, allowing me to have a visual reconstruction of what is happening. I can fix issues with one click and perform a really good and fast rollback of a computer in response to malware or ransomware. These features have worked really well in the past with encrypted files that were infected just a few seconds following the initial infection.
Storyline has really helped me and my clients in real investigations and incidents. Using the dashboard and Storyline, we can visualize a map of the infection and see how it was extending, which allowed us to find where the infection started. In that case, it was an old PC without SentinelOne Singularity Endpoint protection, but we saw in the logs an infected computer that spread infection over the network from a non-protected computer.
I would add that the AI agent can work directly on the endpoint without relying on the cloud, and the autonomous mitigation feature is really powerful. Additionally, the EDR cloud dashboard allows us to have a very clear visualization of the status of the entire company.
SentinelOne Singularity Endpoint has positively impacted my organization and my clients in several ways: it improves security, speeds up device performance because the previous EDR protection required more resources, saved time during boot time of computers, and reduced incidents. Thanks to the dashboard, it provides a comprehensive status of the company, allowing them to invest money wisely over time.
What needs improvement?
I would really appreciate having raw data of what is happening presented in a clearer format. Additionally, a cloud backup of malware would be beneficial so that we can maintain a copy of the ransomware and malware on SentinelOne for analysis purposes.
I would not want to add more about needed improvements because all of the current capabilities are really awesome, and they have done a really good job.
For how long have I used the solution?
I have been working as a security analyst for the last four years.
What other advice do I have?
I rate SentinelOne Singularity Endpoint a nine out of ten.
I give it a nine out of ten because, having worked with all the competitors, there are others that have some more advanced features, but SentinelOne Singularity Endpoint is really wonderful. I know they make a really good product and it is one of my favorites, but it is not perfect.
Regarding SentinelOne Singularity Endpoint's AI capabilities, I appreciate that feature, but I set rules manually all the time. I have never used or tried to use AI for that purpose. I prefer to use AI to ask about status and to monitor activity, but not for everything else. I have not tried using it for other purposes.
In monitoring, I have used SentinelOne Singularity Endpoint and it is really wonderful; the accuracy is really high, and I trust the output completely. For me, it is really good for all the other capabilities of SentinelOne Singularity Endpoint, which I have never used outside of monitoring. I do not have knowledge about those aspects.
SentinelOne Singularity Endpoint is deployed for my clients in different ways. I have a customer using the public cloud, where SentinelOne Singularity Endpoint protects a few virtual machines and containers in a Kubernetes cluster. I have other customers where it is on-premises and the agent is installed directly on physical endpoints, mostly Windows, to monitor local operating system behavior.
For the public cloud deployment, my customer uses AWS.
I did not purchase SentinelOne Singularity Endpoint through the AWS Marketplace; it was purchased with an Italian SentinelOne reseller.
I appreciate the data ingestion correlation of SentinelOne Singularity Endpoint and the automated Storyline; all of that is really wonderful. SentinelOne Singularity Endpoint helps me connect and analyze data from multiple sources. We have made some integrations with next-generation firewalls such as Palo Alto, and there are integrations that allow us to merge the data into SentinelOne Singularity Endpoint's Data Lake, which reduces our time for data analysis because we can find everything together in SentinelOne Singularity Endpoint.
SentinelOne Singularity Endpoint Complete has helped me consolidate my overall security solutions, also thanks to the automatic Storyline correlation. When Palo Alto logs go into SentinelOne Singularity Endpoint, the AI of SentinelOne Singularity Endpoint connects them to the Storyline technology. For example, one user from a company downloaded a suspicious file, which triggered the advanced threat protection of the Palo Alto firewall. All the data from Palo Alto is integrated with SentinelOne Singularity Endpoint; the AI merges the data from the computer and the firewall, allowing us to conduct a full analysis within SentinelOne Singularity Endpoint and providing a clear visual representation of how the attack or event unfolded—a diagram of the sequence of what happened during a security event.
Using SentinelOne Singularity Endpoint has reduced alerts for me and my clients because the agent acts as a teacher for the user, making the good and bad status of a workstation visible to the user, which encourages them to be more careful about their actions. It is really easy for them to use; the first problem in any company is human error.
SentinelOne Singularity Endpoint Complete has significantly freed up IT and SOC personnel by reducing their daily security operation workload, potentially by around thirty percent.
SentinelOne Singularity Endpoint has helped reduce my organization's Mean Time to Detect. Personally, I have saved between fifteen to twenty hours every week of work, allowing me to reallocate my time to infrastructure projects and other cloud migration tasks. This has given me a lot of spare time where it is most needed. The time savings come from the very core capabilities of SentinelOne Singularity Endpoint: Zero-Touch Remediation and Rollback, automated root cause analysis via Storyline, and the mitigation of alert fatigue.
The automatic capabilities of SentinelOne Singularity Endpoint have reduced the time to respond to incidents by an incredible ninety percent, and this is thanks to the automated emails sent to the security department whenever a potential incident occurs.
The autonomous response capabilities of SentinelOne Singularity Endpoint, specifically Zero-Touch MTTR, allow the agent to evaluate the threat locally on the endpoint and execute immediate containment protocols without waiting for human intervention, achieving an MTTR of under one minute, which is significantly different from competitors.
I do not have experience regarding pricing, setup costs, and licensing for SentinelOne Singularity Endpoint because I work in the IT and security department and do not have access to customer pricing information.
I do not have information about money saved, but I can tell about time saved. In my team, I currently have fifteen free hours each week, and the other four members have reduced their work by more than twenty hours a week.
My advice for others looking into using SentinelOne Singularity Endpoint is to definitely test the rollback feature in a sandbox because it is incredibly powerful, and it is truly awesome to see how quickly it works.
I really appreciate this product, and I want to pursue some certification courses for SentinelOne this autumn. Overall, I rate this product a nine out of ten.
Which deployment model are you using for this solution?
public cloud, on-premises
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Aug 17, 2026
Flag as inappropriateCybersecurity Engineer at Gigabit Technologies Pvt Ltd
Automated detection and response have reduced investigations and protect endpoints in real time
Pros and Cons
- "Since deploying SentinelOne Singularity Endpoint, I have seen faster threat detection and response, better visibility across our endpoints, and less time spent investigating security incidents."
- "SentinelOne Singularity Endpoint can be improved in some areas."
What is our primary use case?
My main use cases for SentinelOne Singularity Endpoint are endpoint detection and response, real-time threat prevention, and incident investigations. It helps us protect laptops, desktops, and servers from malware, ransomware, and other advanced threats while providing centralized visibility into endpoints and their activity. I also use its automated remediation capabilities to quickly isolate infected devices, roll back ransomware where applicable, and reduce the manual response effort.
I can provide a specific example of how my team used SentinelOne Singularity Endpoint in a real situation. We received an alert from SentinelOne Singularity Endpoint indicating suspicious PowerShell activity on an employee's laptop. The platform correlated the behavior with a malicious Office document that had launched the script attempting to download additional payloads. SentinelOne automatically killed the malicious process, quarantined the file, and isolated the endpoint from the network to prevent lateral movement. Using the process timeline, the security team quickly identified the root cause, confirmed that no other endpoints were affected, removed the malicious document, and returned the device to service. The entire incident was contained within minutes without any ransomware encryption or data loss.
I have many use cases for SentinelOne Singularity Endpoint.
How has it helped my organization?
Since deploying SentinelOne Singularity Endpoint, I have seen faster threat detection and response, better visibility across our endpoints, and less time spent investigating security incidents. The automated containment and remediation features have reduced manual work for our security teams, and the centralized console has made it easier to monitor endpoint health and respond to threats.
I have seen faster detection with better context. Keeping our most critical security incidents in mind, the biggest improvement has been reduced investigation time thanks to the storyline features and automated remediation, allowing analysts to focus on the higher-priority security alerts.
What is most valuable?
The best features SentinelOne Singularity Endpoint offers that stand out to me the most are its behavioral AI detection, automated response capabilities, and detailed incident visibility. The storyline features, in particular, give a response timeline, while the process storyline makes it much easier to investigate the incident and understand exactly what happened.
SentinelOne Singularity Endpoint has behavioral AI detection, automated remediation and ransomware rollback, network isolations, storyline technology, threat hunting, remote response, and centralized management as the main features.
What needs improvement?
SentinelOne Singularity Endpoint can be improved in some areas. The management console can be complex for new users, and some advanced features require a learning curve to use effectively. Organizations with large environments may also want more flexible reporting and dashboard customization. While false positives are generally low, behavioral detection can still require analyst review and tuning to reduce unnecessary alerts.
I would like to see more customizable dashboards for executive reporting, simpler policy management and reduced false positives, faster support response times, deeper native integrations, more granular permissions, and easier onboarding and training.
For how long have I used the solution?
I have been working in my current field for the last one year.
I have been using SentinelOne Singularity Endpoint for one year.
What do I think about the stability of the solution?
SentinelOne Singularity Endpoint is generally stable and reliable.
What do I think about the scalability of the solution?
SentinelOne Singularity Endpoint has good scalability, ranging from small deployments to large enterprise environments. The cloud-based management model makes it easier to onboard, manage, and monitor large numbers of endpoints without needing additional backend infrastructure.
How are customer service and support?
Customer support for SentinelOne is generally good, with knowledgeable technical teams and useful resources for troubleshooting and deployment questions.
Which solution did I use previously and why did I switch?
I previously used another endpoint security solution and switched to SentinelOne Singularity Endpoint because I needed stronger behavior detection, faster incident response, and better automations. The previous solution provided basic endpoint protection.
What was our ROI?
I have seen a return on investment from SentinelOne Singularity Endpoint. The main value has come from reducing manual security operations, improved incident response time, and consolidating multiple endpoint security tools into one platform.
What's my experience with pricing, setup cost, and licensing?
My experience with pricing, setup cost, and licensing is that the licensing model was relatively straightforward and cost-effective compared to my past solutions.
Which other solutions did I evaluate?
Before choosing SentinelOne Singularity Endpoint, I evaluated several endpoint security solutions including Microsoft Defender for Endpoint and CrowdStrike.
What other advice do I have?
My advice to others looking into using SentinelOne Singularity Endpoint would be to clearly define your security goals and how SentinelOne Singularity Endpoint would fit into your existing security operations and deployment. I would rate this product a 9 out of 10.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Jul 7, 2026
Flag as inappropriateAssociate Vice President at Novac Technology Solutions
Endpoint protection has delivered full visibility and has strengthened zero-day attack defense
Pros and Cons
- "I believe Singularity Platform is perfectly fine overall."
- "From an operational perspective, the customizable dashboards are easy to use, but I face concerns with the alerts from the email ticketing system."
What is our primary use case?
We bought the product for endpoint protection and platform use, where we have two environments: one is the endpoint with laptops, desktops, and VDI environment, and the other is our server environment. We are using CrowdStrike for the server environment, while for the desktops and VDI environment, we are using SentinelOne, Singularity Platform.
What is most valuable?
The benefits from the product include that Singularity Platform provides complete end-to-end visibility on our malware protection and our ransomware protection across our desktops, endpoints, and thin clients and VDI environments, allowing us to control zero-day protection across our environment. There is no need to do any signature patch or anything; we only updated the sensor and fine-tuned the policy here and there during the implementation. We focus on prevention and detection instead of only detection, and we do quarantining as well, leading to complete end-to-end protection across our desktops, laptops, and thin clients and VDI environments.
The real-time personalization feature provides protection against zero-day attacks. Real-time monitoring is very much available in Singularity Platform because once the agent is up to date, it protects critical assets across our network against malicious attacks. Malicious attacks pose a big challenge as if someone downloads malicious files, we face risks. Once an EXE file with vulnerabilities is detected during installation, it will be quarantined, indicating how effective real-time functions are in those scenarios.
What needs improvement?
From an operational perspective, the customizable dashboards are easy to use, but I face concerns with the alerts from the email ticketing system. We receive alerts for every event, such as USB access attempts, which can create unnecessary noise. We fine-tuned the alert mechanism after implementing the solution to reduce this noise.
The alerting mechanism could be improved in Singularity Platform as I want to fine-tune the alerts based on the specific environment. Each environment has different requirements, such as IoT or manufacturing, and we must adapt our policies accordingly.
For how long have I used the solution?
I have been using the product for the past two years.
What do I think about the stability of the solution?
I see no particular areas of improvement for the product because, having used both SentinelOne and CrowdStrike, I find SentinelOne to be good as it performs its functions without requiring much manpower after deployment. The automation helps a lot, and once implemented, we face no further issues regarding stability or scalability; everything works absolutely fine.
What do I think about the scalability of the solution?
Singularity Platform is scalable and stable, with no issues on that part.
How are customer service and support?
The tech support from SentinelOne is great.
How would you rate customer service and support?
Positive
How was the initial setup?
The installation process is quite easy, with no significant issues encountered.
What was our ROI?
We can achieve ROI in about nine months rather than one year. We save approximately 20%.
What's my experience with pricing, setup cost, and licensing?
Singularity Platform is very affordable compared to other options.
Which other solutions did I evaluate?
I would say both SentinelOne and CrowdStrike are equally good, at a 50/50 assessment between them.
What other advice do I have?
The impact of Singularity Platform on our supply chain processes is significant, as supply chain processes are a real headache for the complete organization. Whenever we face any supply chain challenges, we ensure that all end-user and end patch management are updated. We must ensure that particular patches do not have zero-day vulnerabilities or critical vulnerabilities. Ensuring proper IT hygiene is a challenge as well, as some users may not be using the latest patches or may have to stick to legacy applications that prevent upgrades. Protecting our networks and systems is crucial, especially when considering that older operating system versions may not be supported. The challenge in supply chain management is significant.
We use the fraud detection feature for financial services, where we provide financial applications and solutions to our customers. It helps with risk management as it comes with a complete structured approach whenever we implement Singularity Platform. We must ensure that the systems or agents are properly implemented in a tested environment. We first identify risks and then respond. Sometimes we only detect malware files, and depending on the use case, we do our risk assessment and develop a risk methodology to put policies in place based on whether we are using Windows, Linux, or legacy systems.
Regarding the implementation issue, moving from traditional signature-based antivirus solutions to an EDR solution means the new solution must do complete scanning on the initial implementation. However, EDR functions only when incidents occur, which is a change from the previous method used by typical antivirus solutions that scan all files. It is a challenge to explain this shift in expectations, but EDR only reacts when necessary, unlike traditional tools.
I believe Singularity Platform is perfectly fine overall. Some issues with report functionalities and latency are present in other solutions, but not here. The moment we implemented it, everything was clear. It is an excellent, robust tool for protecting our endpoints.
One small example of a challenge I faced is related to connecting my log management part, specifically SIEM. I encountered some issues with parsing when connecting SentinelOne to QRadar for log management.
I would rate this review a 9.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Feb 4, 2026
Flag as inappropriateBuyer's Guide
Download our free SentinelOne Singularity Endpoint Report and get advice and tips from experienced pros
sharing their opinions.
Updated: September 2026
Product Categories
Endpoint Detection and Response (EDR) Endpoint Protection Platform (EPP) Anti-Malware Tools Extended Detection and Response (XDR) AI-Powered Cybersecurity Platforms AI ObservabilityPopular Comparisons
Cortex XDR by Palo Alto Networks
CrowdStrike Falcon
Microsoft Defender for Endpoint
SentinelOne Singularity Cloud Security
IBM Security QRadar
Microsoft Sentinel
Elastic Security
TrendAI Vision One
Huntress Managed EDR
Trellix Endpoint Security Platform
Buyer's Guide
Download our free SentinelOne Singularity Endpoint Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- What is the biggest difference between Carbon Black CB Defense, CrowdStrike, and SentinelOne?
- Which is better - SentinelOne or Darktrace?
- What do you recommend to choose when replacing Symantec EDR: SentinelOne or CrowdStirke Falcon?
- Cortex XDR by Palo Alto vs. Sentinel One
- Which solution do you prefer: CrowdStrike Falcon or SentinelOne Singularity Complete?
- Does SentinelOne have a Virtual Patching functionality?
- What is the biggest difference between EPP and EDR products?
- What is the difference between EDR and traditional antivirus?
- What is your recommendation for a 5-star EDR with low resource consumption for a financial services company?
- Which is the best EDR for a logistics company with 500-1000 employees?






















