No more typing reviews! Try our Samantha, our new voice AI agent.
Security Analyst at a media company with 501-1,000 employees
Real User
Top 20
Jun 24, 2026
Automated threat response has freed our security team to focus on high‑value client projects
Pros and Cons
  • "In my opinion, the main benefits that SentinelOne Singularity Endpoint provides are many, and the foremost thing you are getting is the best that anyone can offer at such a low price."
  • "Regarding potential areas for improvement for SentinelOne Singularity Endpoint, as I mentioned earlier, I felt that it was generating a very high number of false-positive alerts initially."

What is our primary use case?

My use case with SentinelOne Singularity Endpoint is primarily for security purposes, to secure our clients from different malware. If they download any suspicious file onto their desktop which creates a problem afterwards, then for that purpose, we are basically using this. We are basically an MSSP, providing services to our clients.

What is most valuable?

The features and functions in SentinelOne Singularity Endpoint that I have found most valuable include its fully autonomous nature. We don't have to put manual effort into that. Basically, mostly everything is automated, and also the threat detection feature, the rule remediation feature, and the rollback as I mentioned earlier. If anything comes out to be clean and genuine, then we can just do the rollback so that everything gets back to normal and keeps on running. I feel that is the foremost thing I appreciate: having a fast response and rollback capability.

Singularity Complete has helped me reduce the number of alerts. Although I would say that it is a depreciating factor when it comes to false-positive alerts. Initially, it generates a very high number of false-positive alerts, but by using it accordingly, very prominently, we can control the false-positive alerts by deploying only the necessary use cases that our clients need to detect only true-positive alerts rather than false-positive noises.

Singularity Complete helps my clients free up staff for other projects. I also mentioned earlier that it is fully autonomous. Every feature is automated. It does its work on its own by doing the quarantine. Any malicious thing it detects, its rule engine, which is obviously a behavioral AI. Because everything is automated, it decreases our manual effort. Rather than typing a manual email to a client, which obviously takes fifteen to twenty minutes extra, we are just taking action directly from the SentinelOne Singularity Endpoint user interface. So it reduces our manual effort and time overall.

What needs improvement?

Regarding potential areas for improvement for SentinelOne Singularity Endpoint, as I mentioned earlier, I felt that it was generating a very high number of false-positive alerts initially. Although by making a few changes, we reduced that. The first thing is the false-positive alerts. Also, I've felt that a few of our clients have a very high number of endpoints integrated, such as more than one thousand endpoints have been deployed for those particular clients. For those kinds of clients, I've felt that the resource consumption, including high CPU and disk utilization, is a factor. The utilization sometimes gets very high, so we have to keep it in control and monitor it from time to time. One more thing is creating a customized dashboard, which is not a feature in SentinelOne Singularity Endpoint. We can only view their existing dashboard. No custom dashboard feature is present in SentinelOne Singularity Endpoint, so that's also something that can be brought up in the future.

For how long have I used the solution?

I've been working with SentinelOne Singularity Endpoint product for about a year.

Buyer's Guide
SentinelOne Singularity Endpoint
September 2026
Learn what your peers think about SentinelOne Singularity Endpoint. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
915,817 professionals have used our research since 2012.

What do I think about the stability of the solution?

Stability-wise, I would rate SentinelOne Singularity Endpoint a nine out of ten.

What do I think about the scalability of the solution?

I would say ten out of ten for the scalability of SentinelOne Singularity Endpoint because we can scale up and scale down as per requirement. We can increase or decrease the number of endpoints, whatever suits perfectly at that particular time.

How are customer service and support?

I would rate SentinelOne's technical support ten out of ten. There have been a number of times when we get in contact with their OEM, the customer support. Their response is very quick. Within a day, we get a response from them. There are a number of times we get stuck in creating a use case or doing whitelisting, blacklisting, or deploying rules. At that particular time, we contact customer support, and we get their response very quickly.

How was the initial setup?

The initial setup for SentinelOne Singularity Endpoint is much simpler, although I have not been a part of the integration team. First, we have to allow SentinelOne Singularity Endpoint on a desktop, then we have to install its endpoint on the desktop or laptop.

Which other solutions did I evaluate?

The main competitor on the market for SentinelOne Singularity Endpoint can be CrowdStrike Falcon. I have not used that product, but I do know that the price range SentinelOne is offering is the best, as Falcon CrowdStrike is much more expensive.

What other advice do I have?

My experience with SentinelOne Singularity Endpoint's ability to ingest and correlate data across security solutions is great because we personally have integrated SentinelOne Singularity Endpoint with a different product and deployed a few correlation use cases. By doing that, we strengthen our use cases, correlating it with different email security solutions. It's been great doing that correlation.

The Mean Time To Respond automatically decreases because everything has been already completed by the AI engine running in the background.

I have limited experience with Purple AI, but I have used some of the features, including identifying IOCs (Indicators of Compromise) in Purple AI and a few other features as well.

Regarding Purple AI's capabilities in threat intelligence for detecting threats, IOCs are utilized for that purpose. By using the copilot feature in Purple AI, where I can use the pull-down menu on the left-hand side, from there I can get the IOCs present on my client's endpoint. By doing that, I can gather threat intelligence on our clients' endpoints.

In my opinion, the main benefits that SentinelOne Singularity Endpoint provides are many. I would say it's already a valuable security device. I can literally line up different things that SentinelOne is offering. Obviously, the foremost thing is for security purposes. You are securing your own desktop, laptop, or whatever server it is. And also, what you are getting at such a low price, I would say. The foremost thing you are getting is the best that anyone can offer. So that's what I would say about SentinelOne Singularity Endpoint.

I have not personally used the Ranger functionality because it has been blocked in our environment, but I am aware of the Ranger functionality that SentinelOne is providing for network security purposes.

Regarding Mean Time To Detect (MTTD), if I compare it with other SIEM solutions, what does that SIEM solution do? It just detects an alert and gives a pop-up that the threat is detected in an environment. But comparing it with SentinelOne Singularity Endpoint, it is doing its work on its own. So, it's very useful compared to other solutions.

I will recommend SentinelOne Singularity Endpoint to other users. I would rate this product ten out of ten overall.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Last updated: Jun 24, 2026
Flag as inappropriate
PeerSpot user
GauravRanade - PeerSpot reviewer
CSO at TechnoCentic
Reseller
Top 10
Jan 15, 2026
Security operations have become more efficient and detection is improving across endpoints
Pros and Cons
  • "As a reseller and user, I would say that SentinelOne Singularity Complete is better than its competition; I have evaluated Palo Alto, Trellix, and CrowdStrike as well, and SentinelOne EDR is much better than all of them as the capability and technical capabilities are superior with efficient and faster detection."
  • "For ingestion and correlation across security solutions, the agent is quite heavier when compared to other competition."

What is our primary use case?

For the major use cases for the client, I would mention EDR.

I have worked and implemented Purple AI. While we were in India, it is more about data privacy as a protection law which has been implemented. Purple AI is collecting all the information which needs to be evaluated and correlate this entire data and segregate and disseminate into different roles and privileges. We have utilized that. These are the mechanisms which are very new into the Indian market and customers and their team members created it and accepted it as well. That is one of the major reasons to sell SentinelOne Singularity Complete.

However, we have not implemented the SecOps feature in major installation as of now.

What is most valuable?

SentinelOne Singularity Complete helps to reduce alerts by almost fifteen to twenty percent. The false alert activation is much more effective in SentinelOne Singularity Complete in competition with all the comparative tools.

It helps to free up my people and staff for other projects. It depends on a project-to-project and team-to-team basis, but it really helps. I would estimate between thirty to fifty percent.

SentinelOne Singularity Complete helps to reduce MTTD by about twenty to thirty percent.

For MTTR, it is almost another way for between fifteen to twenty percent.

As a reseller and user, I would say that SentinelOne Singularity Complete is better than its competition. I have evaluated Palo Alto, Trellix, and CrowdStrike as well. SentinelOne EDR is much better than all of them. The capability and technical capabilities are superior. It is efficient and faster detection.

What needs improvement?

For ingestion and correlation across security solutions, the agent is quite heavier when compared to other competition. The agent has to be light-weighted. That is one of the drawbacks for the competition. They have to work quite a lot.

For how long have I used the solution?

I have been selling the product for three and a half years.

What do I think about the stability of the solution?

As for stability, there are no issues. It is stable.

What do I think about the scalability of the solution?

As for scalability, it is acceptable. The scalability depends entirely on how much security is required for it. It is easy to scale that.

How are customer service and support?

I would say technical support from SentinelOne is excellent. Everyone in SentinelOne is known to us for the last many years.

I would rate support eight point five out of ten. One point five has been removed just because many times it has been delayed or the support has not been available due to vacation. That should be a challenge. Ten out of ten would not even be given to AWS.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

SentinelOne stands out and is the best product among those, especially in India. There was a recent strike incident with Microsoft, and SentinelOne's approach is much better and much more effective.

How was the initial setup?

It is easy to deploy. The deployment model depends on the type of organization. If it is government, then it has to be on-premises. If it is more like an enterprise and BFSI, that can be over the cloud. In India, it has to be done with the intent. It can be into the SentinelOne cloud with an instance in India, or whether it has to be AWS or Azure, they are acceptable in any format.

What about the implementation team?

There is a chance to buy this product through AWS Marketplace, the CPPO. I did that previously.

What's my experience with pricing, setup cost, and licensing?

It is neither too costly, but definitely, it is one of the advantages that SentinelOne is quite adapted towards the pricing.

What other advice do I have?

I do sell SentinelOne Singularity Complete.

I am a Chief Security Officer for Technocentric.

I have been selling this product for the last three and a half years.

I have been involved in this domain for twenty-five years.

I would give SentinelOne Singularity Complete a rating of nine out of ten.

Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
Last updated: Jan 15, 2026
Flag as inappropriate
PeerSpot user
Buyer's Guide
SentinelOne Singularity Endpoint
September 2026
Learn what your peers think about SentinelOne Singularity Endpoint. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
915,817 professionals have used our research since 2012.
reviewer2848245 - PeerSpot reviewer
Specialty Cybersecurity at a tech vendor with 10,001+ employees
Real User
Top 5Leaderboard
Jun 17, 2026
Real-time behavioral protection has reduced false positives and cuts response from hours to minutes
Pros and Cons
  • "SentinelOne Singularity Endpoint has impacted our organization positively, mainly through cost savings compared to other endpoints."
  • "Customer support for SentinelOne Singularity Endpoint is very good, but I think there needs to be more improvement in the support level to ensure proper responses for customers, especially during session requests."

What is our primary use case?

My main use case for SentinelOne Singularity Endpoint is managing threats and other security measures day-to-day.

Basically, the extensions that I am working on are focused on threat level and investigation level with SentinelOne detection response.

Regarding my main use case with SentinelOne Singularity Endpoint, I have many options to take control from SentinelOne Singularity Endpoint such as disconnecting for troubleshooting.

What is most valuable?

In my experience, the best features SentinelOne Singularity Endpoint offers are designed to protect.

What stands out to me regarding its real-time threat detection, automated response, or ease of use is that we have truly real-time protections, which we can call behavioral threat protection.

The behavioral detection helps my team in day-to-day operations by enabling us to take immediate action.

Another feature I think is worth mentioning is a new feature called VSS snapshot.

SentinelOne Singularity Endpoint has impacted our organization positively, mainly through cost savings compared to other endpoints.

Regarding cost savings, we can compare SentinelOne with other EDR solutions, and I find that SentinelOne is less costly while also having a higher security level for endpoints.

What needs improvement?

For improvement, I could say that there is a report level which needs to be improved at the endpoint level.

Regarding SentinelOne Singularity Endpoint's AI capabilities, I think it would be very good if we have more AI capability for endpoint level governance, which we currently possess.

The accuracy and reliability of SentinelOne Singularity Endpoint's AI output provide quick information about threats and their management, making it reliable very often for us.

For how long have I used the solution?

I have been working for almost nine years in cybersecurity.

What do I think about the stability of the solution?

SentinelOne Singularity Endpoint has been stable in my experience.

What do I think about the scalability of the solution?

Its scalability is very good; it has been easy to manage.

How are customer service and support?

Customer support for SentinelOne Singularity Endpoint is very good, but I think there needs to be more improvement in the support level to ensure proper responses for customers, especially during session requests.

Which solution did I use previously and why did I switch?

Previously, we used McAfee, and we wanted to switch to SentinelOne to see how it would protect our endpoint.

How was the initial setup?

Based on my experience so far, I believe it is fine now, as I already mentioned regarding improvements needed.

What about the implementation team?

I purchased SentinelOne Singularity Endpoint through the AWS Marketplace.

What was our ROI?

I have seen a return on investment in terms of money saved as well as time saved.

It has saved a lot of time for us, allowing us to reduce the time previously spent by our team, which was two to three hours.

SentinelOne Singularity Endpoint has completely reduced our Mean Time to Detect (MTTD), which has changed from the usual eight hours down to two to three hours.

It has improved our Mean Time to Respond (MTTR) significantly; while we used to take two to three hours, SentinelOne Singularity Endpoint can manage it within minutes, hardly ten to fifteen minutes.

What's my experience with pricing, setup cost, and licensing?

My experience with pricing, setup cost, and licensing has been good, and I feel it is very much fine compared to other EDR solutions.

Which other solutions did I evaluate?

Before choosing SentinelOne Singularity Endpoint, I evaluated other options, including CrowdStrike.

What other advice do I have?

The advice I would give to others looking into using SentinelOne Singularity Endpoint is that it saves money and enhances the protection level; it is also very good for saving time on analysis tasks.

Singularity Complete has helped us consolidate our security solutions and it has been completely secured at the endpoint level, which is very good for us.

We use SentinelOne Singularity Endpoint's Ranger functionality for asset visibility, which is important for our endpoint protection level and to assess the health and status of security.

Singularity Complete has reduced alerts significantly; we used to get many alerts but now we are getting very few, and those are true positives only while previously we experienced many false positives.

I would rate this solution nine out of ten.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Last updated: Jun 17, 2026
Flag as inappropriate
PeerSpot user
reviewer2869185 - PeerSpot reviewer
Cyber Security Engineer at a outsourcing company with 51-200 employees
Real User
Top 5
Jul 7, 2026
Automated threat detection has reduced response times and has restored critical files from attacks
Pros and Cons
  • "We can manage multiple tools including next-gen SIEM, identity security, cloud security, EDR, and XDR in a single platform with a single agent, so we do not need to manage multiple products."
  • "Sometimes the firewall policy and device control policies are not working properly, so they need to work on this part."

What is our primary use case?

My main use case for SentinelOne Singularity Endpoint is to use the VSS Shadow Copies, which help us regain access to files that are deleted or modified by threats.

Once in our network, there was an attack, something similar to ransomware, which affected files in our endpoints. VSS stores the shadows of every file and takes a backup every four hours. I used the ShadowExplorer app to re-export those files and gain access to those deleted, quarantined, or modified files.

What is most valuable?

SentinelOne Singularity Endpoint is very useful because it has lightweight agents and a single agent works on multiple platforms including Identity, EDR, XDR, DLP, firewall control, and device control.

It has the capability to showcase the telemetries gathered from all the endpoints or devices in the network and shows every attack chain in the XDR dashboard.

Normal detection does not show which back-end process or child process is malicious. By using the telemetry and the attack chains in the graph, I can explore more about how the attack is progressing in our environment, from which application to which process, which registry changes, which domains, or hosted IPs are working in the back end.

Singularity Endpoint's AI capabilities help us detect more advanced threats in our environment, and it helps us gain less time to respond to those attacks. I use Purple AI to create multiple reports and can ask anything to generate reports or logs.

It provides mostly accurate results.

SentinelOne Singularity Endpoint is deployed in our organization in a public cloud. It can integrate with multiple third-party solutions which help us gain multiple logs from across the network, including firewall and SIEM. It helps us detect faster and hidden threats.

It did help us consolidate our security solutions. We can manage multiple tools including next-gen SIEM, identity security, cloud security, EDR, and XDR in a single platform with a single agent, so we do not need to manage multiple products.

I use the Ranger functionality in SentinelOne. It provides full visibility of both unprotected and protected devices. It also helps push the agent directly to unprotected devices, which is very important.

Singularity Complete has helped reduce alerts.

It saved much more time because we can take action on multiple solutions from a single management console.

Mean Time to Detect is reduced by fifty percent.

Mean Time to Respond is reduced by forty percent.

SentinelOne Singularity is used mostly for its detection models, AI engines, and machine learning engines, and it has the capability to run multiple tools in a single platform.

What needs improvement?

Its agent gets offline multiple times, mostly in Windows 7 which has legacy versions.

I chose nine out of ten for SentinelOne Singularity Endpoint because the endpoint is getting offline multiple times. Sometimes the firewall policy and device control policies are not working properly, so they need to work on this part.

For how long have I used the solution?

I have been using SentinelOne Singularity Endpoint for four years.

What do I think about the stability of the solution?

SentinelOne Singularity Endpoint is a stable tool.

How are customer service and support?

Customer support is good.

Which solution did I use previously and why did I switch?

I used Trend Micro Endpoint Security, which is very complex to use in the management console.

After changing from Trend Micro, we are observing fewer attacks.

There are multiple positive changes. Trend Micro's agent is very heavy and consumes more CPU, RAM, and storage. SentinelOne has a lightweight agent that also helps us regain the quarantined or modified files affected by viruses. Trend Micro does not have that feature.

What was our ROI?

I have seen a return on investment.

What's my experience with pricing, setup cost, and licensing?

The pricing and setup costs are not high but in the medium range.

Which other solutions did I evaluate?

I evaluated other options, which are CrowdStrike and Cortex XDR.

What other advice do I have?

I gave this product a review rating of nine out of ten.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Last updated: Jul 7, 2026
Flag as inappropriate
PeerSpot user
IT Security Consultant at Systemhaus for you GmbH
Real User
Top 5Leaderboard
Feb 24, 2026
Managed services have gained faster incident response and clear threat investigations
Pros and Cons
  • "The best features I and my clients like the most about Singularity Platform are that, first of all, it's easy to handle, it doesn't take a lot of time to get into, there's no real obscurity, it takes a load of work from the team, and in most cases, you can literally just configure it once and leave it running until something comes up, and it will just work."
  • "The areas that have room for improvement in Singularity Platform include the fact that I am really not happy with the vulnerability management."

What is our primary use case?

My use case for this solution is that we are an MSP. We take care of clients for small to medium-scale businesses. I think our current install base is around 7,000, maybe around there. Beyond that, we also are in the project business, so for larger customers, we handle it on a project basis.

My clients are small to medium businesses for the most part.

What is most valuable?

The best features I and my clients like the most about Singularity Platform are that, first of all, it's easy to handle. It doesn't take a lot of time to get into. There's no real obscurity. It's really easy to handle, takes a load of work from the team, and in most cases, you can literally just configure it once and leave it running until something comes up, and it will just work. There won't really be an issue in between then.

Singularity Platform saves me over 50% of my time or resources. If I have an incident I want to investigate, for example, I can just go in. I don't have to learn a complex query language. I can just ask the inbuilt Purple AI and ask about this situation. If I want to dive in deeper, I can, and it's really easy to do. I can very easily see the context, see what has happened, where it has happened, how it has happened, as opposed to other tools or even doing it manually. The time saved is almost immeasurable because it's just so much.

My thoughts on the real-time monitoring capabilities are that they are great. There's not really anything negative to say there; I like them.

When assessing the impact on supply chain processes, keeping it simple, it would basically be good. In use cases where customers are in a supply chain, the people who are concerned about them being in their supply chain usually have their concerns alleviated by SentinelOne being present.

My thoughts on the maintenance are that it is pretty easy. It is pretty much the way I would like it. If it works, you're not bothered by it. If it doesn't work, it's very easy and quick to figure out what is going wrong. The nice part about that as well is you can go the proper way and fix it as intended, or if that doesn't work, the wooden mallet is always an option to just fix it quick and dirty. Those work without issue.

What needs improvement?

The areas that have room for improvement in Singularity Platform include the fact that I am really not happy with the vulnerability management. I may or may not have a bit of a personal vendetta against vulnerability management as a whole. I feel that concept is a bit out of date in my opinion. But combine that with what I believe is absolutely subpar performance in the vulnerability management space. I just opened our console and am faced by a wall of red. We conduct regular internal pen tests on ourselves and our clients. I know those aren't able to be exploited, and seeing, even if I dive into the vulnerabilities, a good percentage of them isn't even real. Sometimes they may just be artifacts left over that are still being found and then identified. Last year, SentinelOne was awarded for best vulnerability scanner, and that was a bit amusing to me. But that's really the main part I would say could be improved. Other than that, there are a couple of minor features which I know are on the roadmap and I would like to see sooner.

For how long have I used the solution?

I've been using Singularity Platform since 2020.

What do I think about the stability of the solution?

When rating the stability, let me preface this by saying that thanks to the architecture of SentinelOne being not really cloud-dependent, it won't report to the cloud if the cloud is down. Thanks to that, I don't really care about occasional downtime on the console too much. That being said, I know there have been a couple of issues in the recent months, but those are getting a lot better. I would rate stability a nine.

What do I think about the scalability of the solution?

I rate the scalability of Singularity Platform a 10.

How are customer service and support?

From one to ten, I would rate the technical support an eight.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

I don't have any personal experience with CrowdStrike, sadly, but when comparing Singularity Platform to other solutions, one of the main parts is that performance is just so much better. Not just in threat detection and mitigation but also in regards to endpoint performance. If it works, nobody's going to complain, but the moment that performance is impacted just a tiny bit, it will come up. Even in those rare cases when that isn't optimal, it can very quickly be improved and worked around again. Looking at reports from MITRE ATT&CK, you can see that it works. That's what I enjoy so much about it; it's one of those things that let me sleep easy at night.

What about the implementation team?

Five specialists work with Singularity Platform in my organization.

What other advice do I have?

My thoughts on the customizable dashboards are somewhat detached on a general basis. I see the use for the dashboards; however, we have a bit of a unique issue because, as I mentioned, we are an MSP. We don't just have one console, but I think at this point we have 10, 13 or something consoles, all across different URLs. So I personally can't really use the dashboard customization for a lot of things. We are using it to some degree to monitor the full-service clients, but I generally recommend larger companies we onboard on a project business to utilize the customizable dashboards, especially for data ingestion. That's a real plus point to quickly visualize how much data and what types of data you ingest and where necessary, trim down on unnecessary data.

The minor features I would like to see sooner include, for example, the exclusions. When they trigger, I would like to know in retrospect and be able to see how often a certain exclusion has triggered in the past, let's say, year. So I could say that this hasn't triggered at all and I can just remove it. Also, for the upgrade policies, I would like to just be able to set that I want to upgrade agents on maybe one version behind, one major, one minor version behind, always update service packs, update with a delay of X weeks, and just do that automatically rather than having to adjust the target version manually all the time. But those are very, very minor gripes. That's pretty much all I would have as feedback.

I would rate Singularity Platform overall a 9 out of 10, as there are still some minor things that I think could be a tiny bit better.

The advice I would give others looking into Singularity Platform is that I would definitely recommend it. First off, it is easy to use. You can integrate it with everything, and you can integrate everything with SentinelOne. That isn't even an exaggeration. If you have anything that produces data, you can integrate it. That is what I love so much about it; it's just awesome. My advice would be to definitely do a proof of concept. Figure out the three to four main use cases or main causes of concern for your company, do a classic proof of concept, proof of value, figure out the key areas that you want to protect, and see if the agent plays nice with it and come to the conclusion that it does.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Disclosure: My company has a business relationship with this vendor other than being a customer. MSP
Last updated: Feb 24, 2026
Flag as inappropriate
PeerSpot user
Shaun Washington - PeerSpot reviewer
SOC Analyst II at a computer software company with 51-200 employees
Real User
Top 10
Aug 20, 2026
Endpoint defense has improved and remote investigations gain faster insights into attacks
Pros and Cons
  • "SentinelOne Singularity Endpoint has positively impacted my organization as it is our go-to EDR of choice."
  • "Regarding SentinelOne Singularity Endpoint's AI capabilities, I find its accuracy and reliability of output to be dependable, though I believe it could improve by opening up the access to more than summarizing or creating queries."

What is our primary use case?

My main use case for SentinelOne Singularity Endpoint involves scanning customer endpoints and conducting forensic collection.

A specific example of how I use SentinelOne Singularity Endpoint for customer endpoints is that it has been able to notify us of quick fix attack activity from malicious MHTA being obfuscated and executed on different customer endpoints.

In addition to my main use case, I use SentinelOne Singularity Endpoint for checking endpoints' web activity, and it also helps with getting a comprehensive view of the overall activity and alerts that come in.

What is most valuable?

SentinelOne Singularity Endpoint's best features, which stand out to me the most, include the Remote Shell and Purple AI.

The Remote Shell and Purple AI help me in my day-to-day work by allowing some use cases to use the Remote Shell to remotely install or uninstall applications to support IT, or using Purple AI to provide quicker insight into alerts or activity that SentinelOne Singularity Endpoint is providing.

SentinelOne Singularity Endpoint has positively impacted my organization as it is our go-to EDR of choice.

It is my go-to EDR because we have noticed definitely faster response times, and the customer support has been better than some other companies we have had to deal with.

What needs improvement?

Regarding SentinelOne Singularity Endpoint's AI capabilities, I find its accuracy and reliability of output to be dependable, though I believe it could improve by opening up the access to more than summarizing or creating queries.

For how long have I used the solution?

I have been using SentinelOne Singularity Endpoint for about three years.

What do I think about the stability of the solution?

SentinelOne Singularity Endpoint is stable, and I am not aware of any issues with its reliability.

What do I think about the scalability of the solution?

SentinelOne Singularity Endpoint's scalability is excellent, as I have not had any issues with onboarding or offboarding new customers or adding new sites.

How are customer service and support?

SentinelOne Singularity Endpoint's customer support has been very good with good turnaround time and a solution-oriented approach.

Which solution did I use previously and why did I switch?

We have always had SentinelOne and used to use Trellix and their suite of tools, but we moved away from Trellix to stay with SentinelOne Singularity Endpoint as our main EDR, mainly due to updates and customer service.

Which other solutions did I evaluate?

Before choosing SentinelOne Singularity Endpoint, we evaluated SentinelOne and CrowdStrike, but it really depends on the customer's needs; overall, SentinelOne Singularity Endpoint is our go-to.

What other advice do I have?

Singularity Complete fills the role of EDR and helps us with monitoring, so it is a part of our complete puzzle that gives us the vision we need into a customer's environment, depending on whether they have SentinelOne Singularity Endpoint through us and we manage it.

We do not use the Ranger functionality because a different department manages network visibility.

Singularity Complete does not necessarily lessen alerts for us as we have it tuned to only create cases in our SIEM for things that are high and critical.

Although I do not have any direct metrics, I do find that it all ties into giving us the intelligence or data from detections, which get fed into our SIEM for us to take actions either in SentinelOne Singularity Endpoint or by contacting the customer.

My advice for others looking into using SentinelOne Singularity Endpoint is to take advantage of the partner support portal to get trained up on it, as that will definitely help you understand it and use it to its full capability.

I believe we fall under partner in terms of our business relationship with this vendor. I would rate my overall experience with SentinelOne Singularity Endpoint as an 8.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Last updated: Aug 20, 2026
Flag as inappropriate
PeerSpot user
GANESAN K - PeerSpot reviewer
Senior Technical Engineer at Safezone Secure Solutions Private Limited
Reseller
Top 5Leaderboard
Nov 25, 2025
Helps identify vulnerabilities, recover from attacks swiftly, and unify security management from a single console
Pros and Cons
  • "During the time of attacks, if there is any data loss, we were able to easily roll back those attacks and retrieve that data for the client with a single click."
  • "The first thing I would say about the negative side of Singularity Platform is that it lacks some customization and integrations compared to competitors."

What is our primary use case?

I have worked with Singularity Platform, and I'm well-versed with Cloud Security, but I have not worked with the AI CM. Singularity Platform comprises three things: Identity Security, Endpoint Security, and Cloud Security. The platform has multiple products including Singularity Identity, Singularity Complete, and the AI-powered Singularity XDR. I have experience with Singularity Identity, Singularity Endpoint, and Singularity Complete products, and we will continue to work because we have more opportunities on this.

Purple AI provides features and functionalities that have been asked for by customers, and we have given those functionalities to them using Singularity Platform.

When we manage Identity Security and Endpoint Security, it's from a single console. We get data and visibility on everything happening in our environment and how it is related. We can integrate many other solutions such as Fortinet firewalls and Palo Alto firewalls. Singularity Platform provides a marketplace with many kinds of integrations with mail security solutions and firewall solutions that are very helpful for customers from the XDR point of view. We haven't used the SIM as of now, and we have not given the AI SIM to customers, but we have evaluated the product. To my knowledge, I think it's good, but when it comes to use cases, we will be able to tell how it exactly addresses the client's requirements, how it gives alerts, and how it stores data on correlation time. We need to implement it in the client's environment in order to get proper feedback.

These were the features and functionalities which have been asked for by customers, and we have provided those functionalities to them using Singularity Platform.

How has it helped my organization?

For the past three years, after Corona, we have started using Singularity Platform.

During the time of attacks, if there is any data loss, we were able to easily roll back those attacks and retrieve that data for the client with a single click. That's how Singularity Platform works for endpoint security. When it comes to Identity Detection and Response, it also gives much more visibility on what identities are weak. It scans all usernames and passwords in the Active Directory or Azure Directory. If you have Azure Directory, integrating with the Identity Security or Posture Management solution allows us to find out what users are in a vulnerable state and all the users to which they might have received five to ten attempts. If those kinds of attempts are received, that particular user account will be locked. We were able to write these kinds of rules from Singularity Identity itself. When it comes to threat intelligence, Singularity Platform holds its own threat intelligence data lake, and they have introduced Purple AI, which is very useful for us when dealing with attacks.

For many of our customers who got attacked after installing SentinelOne, they were not impacted on a larger scale. The impact of a ransomware attack typically encrypts all critical data and stops production. If one day of production is stopped, it sums up to, for an enterprise customer, a minimal margin of two to three crores. With this rollback functionality, we were able to address that and revert that particular endpoint to the previous good configuration state.

What is most valuable?

Singularity Platform does help with risk management. It refers to the MITRE ATT&CK framework and analyzes what the vulnerable points are in an endpoint. When it comes to cloud security through Singularity Platform's cloud capabilities, workload security or native security can scan accounts and find misconfigurations in the cloud. If there are containers, workloads, or instances, it scans everything and pinpoints any IAM roles that need to be configured, letting us know which things have not been configured for those workloads. This makes it easy for us to spot loopholes before they are exploited.

What needs improvement?

Singularity Platform has an easy-to-use console. When it comes to customization, it has some options, but I wouldn't say it is very customizable. If you are asking if this is fully customizable, I would say it is partially customizable, not fully customizable. In some places, I can understand from a security background that they have kept those features considering security. However, it lacks customization and could enable much more than that.

Even though Singularity Platform has multiple integrations with multiple solutions, it still needs more because competitive vendors such as CrowdStrike and Trend Micro provide more integrations than SentinelOne.

The first thing I would say about the negative side of Singularity Platform is that it lacks some customization and integrations compared to competitors. We can integrate Fortinet and Palo Alto, which are big players, but there are many other small companies. Even Zoho is a significant player in our market, but there are no integrations for Zoho.

For how long have I used the solution?

For the past three years, after Corona, we have started using Singularity Platform.

What do I think about the stability of the solution?

In SentinelOne, we have not received reports regarding outages. Until now, we have not experienced any issues regarding stability. The product is pretty stable, and even if the agent is offline, it will handle the threats. This is pretty solid and stable.

What do I think about the scalability of the solution?

Singularity Platform has flexible licenses, and it is also easily scalable.

How are customer service and support?

The technical support from SentinelOne is very good.

How would you rate customer service and support?

Which solution did I use previously and why did I switch?

One of our customers had an attack and they were using CrowdStrike. We proposed the SentinelOne alternative solution, and we were able to manage to get some details about the attack and present it to the customer.

How was the initial setup?

This is a straightforward approach. Singularity Platform provides pretty much everything that is easy to configure, even by a fresher. If a fresher has basic experience in configuring endpoint security, they would be able to handle SentinelOne. The console and the configuration part are that easy, but for an endpoint security specialist, an understanding of how threat vectors evolve and how they are attacked is necessary. The console view and everything, even writing queries in the XDR, are pretty simple.

What about the implementation team?

Singularity Platform is hybrid and has both on-prem deployment as well as SaaS deployment. However, when it comes to the implementation or deployment part, they recommend cloud. We have done only cloud because even from the SentinelOne team, they tell us that they do not recommend on-prem. I will say that the cloud version is better since we haven't done any on-prem deployments, and I don't believe they recommend that for customers.

What was our ROI?

For many of our customers who got attacked after installing SentinelOne, they were not impacted on a larger scale. The impact of a ransomware attack typically encrypts all critical data and stops production. If one day of production is stopped, it sums up to, for an enterprise customer, a minimal margin of two to three crores. With this rollback functionality, we were able to address that and revert that particular endpoint to the previous good configuration state.

What's my experience with pricing, setup cost, and licensing?

It's average. It's not cheap, but not expensive—average cost and quite affordable.

What other advice do I have?

Singularity Platform does help with risk management. It refers to the MITRE ATT&CK framework and analyzes what the vulnerable points are in an endpoint. When it comes to cloud security through Singularity Platform's cloud capabilities, workload security or native security can scan accounts and find misconfigurations in the cloud. If there are containers, workloads, or instances, it scans everything and pinpoints any IAM roles that need to be configured, letting us know which things have not been configured for those workloads. This makes it easy for us to spot loopholes before they are exploited.

My remarks are purely based on feedback from my clients.

The key unique selling points for SentinelOne are its patented rollback option and offline protection. Even when an agent is offline, we are still able to protect it. There are some protection events happening even when the agent is offline, which is not available with most vendors that expect the agents to be online. That's a good thing about SentinelOne. Additionally, we have not received any complaints regarding performance issues. I rate this solution an 8 out of 10.

Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
PeerSpot user
reviewer2891040 - PeerSpot reviewer
Network Security Administrator at a energy/utilities company with 51-200 employees
Real User
Top 20
Sep 14, 2026
Automated threat blocking has improved our detection speed and simplifies overnight incident response
Pros and Cons
  • "It has been actively blocking the threat and also correlates all the events using storyline, which has been pretty great"
  • "I can understand that since there is a shortage of staff in SentinelOne, sometimes when we raise a case, it takes some time to respond."

What is our primary use case?

SentinelOne Singularity Endpoint actively monitors endpoints continuously whenever there is activity, and then correlates the events accordingly, and flags threats using a storyline.

It actively detects and monitors if anything suspicious happens on the endpoint, and then actively blocks it and raises an incident alert for the security team to review.

There was a recent incident where there was a modification of a VSS backup on a server endpoint. SentinelOne Singularity Endpoint actively detected that modification and raised an alert with us, and we quickly reviewed it. Although it was a false positive, it was a legitimate application that was trying to modify the VSS backup and delete and take a fresh backup from scratch. However, SentinelOne Singularity Endpoint actively monitored it and flagged it as suspicious activity. Though it was a false positive, the underlying activity was detected correctly.

Whenever it detects threats, it helps us respond to threats quickly because the EDR actively monitors the threat and blocks it. When there was suspicious activity at three o'clock in the night, SentinelOne Singularity Endpoint does not require active monitoring of the alert by the team. In that scenario, there could be a lot happening by the time when we see the alert, and the latent moment might have occurred since the start of the attack. SentinelOne Singularity Endpoint actively monitors the threat and then blocks the threat if any other suspicious attributes are being shown as part of the attack. This is the feature that I appreciate about SentinelOne Singularity Endpoint; it actively blocks the threat and once it blocks the thread, we can review it later on and look for more details, and we can unquarantine the thread if we feel it is a false positive, or we can take action accordingly. It actively blocks the threat from moving laterally.

What is most valuable?

The recent feature is the Prompt AI. Using that Prompt AI feature, we can get queries to build a quick summary. We can build a query using natural language processing, which means plain English text, and it gives the query accordingly, and it is going to be useful for us to threat hunt and actively identify threats. That is a good feature. The other additional feature is retrieving the files from the computer even though the machine is isolated through the shell. These are pretty good features that I have found useful.

It actively monitors the endpoints for any threats. There is no such EDR that could actively block any kind of threat in the world.

It consolidates the vulnerability management side by actively identifying the risk applications that have been running in the endpoints. We can do the threat hunting through the log collections from the endpoints and then actively write a query to identify the threat that has been running in the environment. It also does the network scanning and also a bit of the VSS management. We can manage the VSS backups as well, handling the VSS snapshot backups through that. It has been a pretty good product, and it could have more capabilities or additional capabilities as well.

What needs improvement?

For now, it has been pretty good. I could not think straight on top of my head what one feature could be added. But for now, the features that SentinelOne Singularity Endpoint offers are pretty great. However, I wish there could be patching that could be happening through the EDR so that we would not need to manage any other separate tool for patching those vulnerabilities since it actively identifies vulnerabilities. Maybe that feature could be helpful. I am not sure whether the single agent can uplift the bulk activity or not. That is one thing I wish I could add in SentinelOne Singularity Endpoint.

We need to set the guardrails for the Prompt AI because it actually queries the logs directly for whenever we want to search in the endpoint logs. Whenever we give a prompt to actively look for something, it actively queries directly inside the logs and returns the output directly instead of just giving a suggestion to go this way or do that way. It actively interacts with the application inside itself and provides results directly without showing the backend process. I am not sure about how the guardrails were set, but setting the guardrails for the AI needs to be taken care of. Since it has pretty much direct access to the endpoints and there are agent capabilities through SentinelOne Singularity Endpoint, we have to take care while handling or implementing AI.

For how long have I used the solution?

I have been using SentinelOne Singularity Endpoint for over a year.

What do I think about the scalability of the solution?

It has been good as far as I am concerned. If we have a good number of licenses, as long as we are near the limit, it is good.

How are customer service and support?

I can understand that since there is a shortage of staff in SentinelOne, sometimes when we raise a case, it takes some time to respond. However, since we have the Prompt AI, things have been pretty easy for us to handle by ourselves instead of relying on tech support or customer support. The tech support does a great job whenever we raise a ticket.

Which solution did I use previously and why did I switch?

We did evaluate CrowdStrike.

What other advice do I have?

The impressions are pretty great. It has been actively blocking the threat and also correlates all the events using storyline, which has been pretty great.

It is going to be really helpful because earlier, I used to go through the documentation, and it used to take a lot of time for me to actively find the relative answer to the question. With the Prompt AI, I can just query my question to the Prompt AI, and then it actually returns the results in a better way. If I have any queries, I can reach out to Prompt AI instead of raising a tech support case. It saves a lot of time.

My suggestion would be to look at whether, based on the range of the products that we use, SentinelOne Singularity Endpoint supports those products or not, and then accordingly, we can purchase SentinelOne Singularity Endpoint and also evaluate how well it integrates with other security solutions inside our environment. I gave this review a rating of eight out of ten.

Which deployment model are you using for this solution?

Private Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Amazon Web Services (AWS)
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Sep 14, 2026
Flag as inappropriate
PeerSpot user
Kathiravan S - PeerSpot reviewer
Technical Support Engineer Iii (Siem & Soar) at Barracuda Networks
Real User
Top 10
Jun 9, 2026
Advanced endpoint protection has prevented ransomware spread and supports precise threat triage
Pros and Cons
  • "The fingerprint database is a particular feature I really appreciate, which captures almost every single malicious activity."

    What is our primary use case?

    I use SentinelOne Singularity Endpoint for threat analysis and threat detections on endpoint devices. Since Barracuda has the XDR product, that provides additional support for SentinelOne Singularity Endpoint. The product is primarily used for endpoint protection to identify threats, malicious payloads, unauthorized access, or accessing malicious websites. This is used for all endpoint level detections.

    While troubleshooting with one of the customers in the previous organization, they experienced a ransomware execution attack. The ransomware was changing file names and file properties while encrypting files. The customer called us to triage those particular incidents. I checked the endpoint to see which file was flagged. SentinelOne Singularity Endpoint had clear indications of a file with a hash that appeared to be malicious. It triggered an alert and blocked that particular file. I was able to identify which user clicked on this particular file, preventing the ransomware behavior. I contained that particular user using SentinelOne Singularity Endpoint and captured information about the ransomware attack. Additionally, SentinelOne Singularity Endpoint provides USB detection; if an endpoint device has a USB plugged in that contains something malicious, I can block it. It provides a very clean UI that allows me to control the entire endpoint with the options provided by SentinelOne Singularity Endpoint. I have many options along with user roles and can specifically give permissions to specific users. It has proven to be a very helpful platform for endpoint devices.

    I primarily use SentinelOne Singularity Endpoint for detection and threat analysis, containing that particular endpoint from the attacking surface. I also utilize it for whitelisting and blocklisting IPs, malicious hash values, or specific URLs. That is something I usually do while handling whitelist and blocklist tasks. It is a pretty easy task because SentinelOne Singularity Endpoint provides an option to upload text files with those parameters and indicators. The main use case is for threat analysis and triaging the incidents caused by a particular endpoint in an attacking way.

    SentinelOne Singularity Endpoint relates to ransomware attack cases and other incidents involving malicious file executions. In all those cases, it achieves specific outcomes, saves time, and prevents users from being exposed. It achieves these goals, although I do not remember a specific use case.

    What is most valuable?

    The best features SentinelOne Singularity Endpoint offers are clear fingerprints, malicious fingerprints, and the patterns they use to detect malicious files or activities. That fingerprint database is very unique and captures most threats. The fingerprint database is a particular feature I really appreciate, which captures almost every single malicious activity.

    The fingerprint database definitely helps me day-to-day, making my job easier and saving time. Most of the threats and malicious activities are flagged with those fingerprints. It makes me trust the software because when SentinelOne Singularity Endpoint flags something as malicious, it is most probably accurate. If it is not malicious, I can easily whitelist it. It helps in both ways, making my job easier as well as saving time on predefined threats. I do not need to check every time whether something is malicious; SentinelOne Singularity Endpoint has that feature, flagging it as malicious with proper notes and giving me trust that it has something to do with that.

    SentinelOne Singularity Endpoint positively impacts my organization based on the user experience I provide. Users mostly give good feedback about SentinelOne, which is a primary reason I support SentinelOne to assist customers. Most customers provide positive feedback since I support them on SentinelOne Singularity Endpoint regarding how endpoint detection works. I really appreciate using SentinelOne Singularity Endpoint to provide good support to customers using it.

    I find SentinelOne Singularity Endpoint to be a really good platform for ingesting and correlating across our security solutions. The correlation use case captures where the requests are coming from, who is making them, and who clicked them. All event logs, including Windows event logs, are captured from multiple devices, and it correlates event times from multiple systems to identify whether the execution affects the entire organization or just specific computers. I really appreciate that capability because when a ransomware attack happens, it executes almost simultaneously across 10 or 20 devices. This allows me to determine how many devices executed that particular file based on event time, enabling me to correlate and isolate all those devices.

    SentinelOne Singularity Endpoint has helped consolidate our security solutions. The same example I just provided helps prevent ransomware attacks and allows me to take appropriate actions immediately.

    What needs improvement?

    Although it has been almost six and a half months, I do not have many features in mind that I find necessary. However, I really appreciate how I can specify scanning folders or areas in the system. Since it is endpoint detection, I can specify which areas to always check for scanning. It has exclusions as well; for example, if I want to scan everything in a system but exclude particular folders or extensions, I can specify that in SentinelOne Singularity Endpoint. That provides me with more granular control over what needs to be scanned and what does not, helping me avoid many false positives and making the systems more reliable in alert conditions. The results become more accurate.

    I do not feel anything needs to be flagged for improvement, but everything requires some enhancements. While using SentinelOne Singularity Endpoint, I do not feel anything needs to be added as a feature or improved. Most of its functions work well.

    I cannot think of anything at this moment regarding needed improvements.

    For how long have I used the solution?

    I was using SentinelOne Singularity Endpoint for two and a half years until I worked at Barracuda Networks six months ago.

    What other advice do I have?

    I primarily use the AI capabilities in SentinelOne Singularity Endpoint for endpoint detections, threat analysis, and threat hunting.

    I have not extensively used the AI capabilities, so I do not have much experience to share or feedback regarding its accuracy and reliability.

    My review rating for this product is 8.

    Which deployment model are you using for this solution?

    Private Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    Last updated: Jun 9, 2026
    Flag as inappropriate
    PeerSpot user
    Michael Streaker - PeerSpot reviewer
    Senior Engineer - Cybersecurity at a comms service provider with 11-50 employees
    MSP
    Top 5
    Aug 18, 2026
    Comprehensive endpoint visibility has empowered us to prevent threats and focus on higher‑value work
    Pros and Cons
    • "SentinelOne Singularity Endpoint has positively impacted our organization by helping us prevent a number of issues across our clients."
    • "I believe their SLAs could be tighter, but overall it is a good platform."

    What is our primary use case?

    SentinelOne Singularity Endpoint serves as our primary EDR product deployed to our managed clients.

    We use SentinelOne Singularity Endpoint to investigate cyber events or incidents, such as Splashtop usage or other RMM usage.

    We work with ConnectWise SOC and SentinelOne SOC to manage it, functioning as a second line of defense for their SOC teams.

    How has it helped my organization?

    SentinelOne Singularity Endpoint has positively impacted our organization by helping us prevent a number of issues across our clients.

    While I don't have specific numbers, we receive alerts all the time regarding different potentially unwanted apps or illegitimate remote access tools, and continuing to receive those alerts demonstrates its impact.

    What is most valuable?

    The best features SentinelOne Singularity Endpoint offers are complete visibility into our endpoints and what has happened, which has been the biggest benefit for us.

    That visibility helps our team by allowing us to see what RMMs are running and whether they are legitimate or not. Being able to see when files are downloaded, transferred, or deleted has proven useful in different situations.

    The threat detection with SentinelOne's Wayfinder has been a valuable feature. They conduct threat hunts on our behalf and inform us if anything emerges from it.

    What needs improvement?

    I believe their SLAs could be tighter, but overall it is a good platform.

    Those are the main improvements needed for SentinelOne Singularity Endpoint. I don't think there are any other significant improvements needed that I haven't mentioned; there may be minor items or wish-list features.

    For how long have I used the solution?

    I have been using SentinelOne Singularity Endpoint for six years.

    What do I think about the stability of the solution?

    SentinelOne Singularity Endpoint is stable.

    What do I think about the scalability of the solution?

    We have experienced no issues with the scalability of SentinelOne Singularity Endpoint.

    How are customer service and support?

    Customer support for SentinelOne Singularity Endpoint is excellent; we receive quick answers when we need them.

    Which solution did I use previously and why did I switch?

    SentinelOne Singularity Complete has helped us consolidate our security solutions; we previously used both SentinelOne and Huntress and consolidated to SentinelOne Singularity Complete for all EDR functions.

    We previously used Huntress in addition to SentinelOne and switched because we were consolidating our tools.

    What was our ROI?

    In the sense that we have not experienced any major incidents of infection, this demonstrates a return on investment for SentinelOne Singularity Endpoint.

    What's my experience with pricing, setup cost, and licensing?

    My experience with pricing, setup cost, and licensing for SentinelOne Singularity Endpoint has been positive; we received a good price point on everything.

    Which other solutions did I evaluate?

    We did not evaluate other options before choosing SentinelOne Singularity Endpoint.

    What other advice do I have?

    SentinelOne Singularity Endpoint is solid, and the support from the SOC is strong.

    We only use the Ranger functionality of SentinelOne Singularity Endpoint in a limited capacity, so I cannot speak to its ability to provide network and asset visibility or its importance to us.

    It is difficult to quantify whether SentinelOne Singularity Complete has helped reduce alerts, so I cannot provide specific details about it.

    SentinelOne Singularity Complete has helped free up our staff for other projects and tasks because we use the SOC with SentinelOne, allowing them to handle all first-line defense on detections.

    We do not track the reduction in our organization's Mean Time to Detect (MTTD).

    Similarly, we do not track the reduction in our organization's Mean Time to Respond (MTTR).

    My advice to others considering SentinelOne Singularity Endpoint is to ensure that you understand what is covered by support and their SLO targets. I would rate this review as a 9 out of 10.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Other
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    Last updated: Aug 18, 2026
    Flag as inappropriate
    PeerSpot user
    Buyer's Guide
    Download our free SentinelOne Singularity Endpoint Report and get advice and tips from experienced pros sharing their opinions.
    Updated: September 2026
    Buyer's Guide
    Download our free SentinelOne Singularity Endpoint Report and get advice and tips from experienced pros sharing their opinions.