No more typing reviews! Try our Samantha, our new voice AI agent.
reviewer2809476 - PeerSpot reviewer
Technical Account Manager at a computer software company with 11-50 employees
Real User
Top 5Leaderboard
Mar 23, 2026
Endpoint protection has reduced ransomware impact and streamlines daily threat hunting
Pros and Cons
  • "My advice for others looking into purchasing SentinelOne Singularity Complete is that I would definitely recommend it."
  • "One of the negatives we have found is that we receive quite a lot of false positives."

What is our primary use case?

I used SentinelOne Singularity Complete for endpoint security, and we selected it because we were looking for an AI-powered cloud solution.

What is most valuable?

The best features of SentinelOne Singularity Complete include a ransomware rollback feature that can be used on infected machines, which we have used before and appreciated. The deployment is fairly straightforward as well.

SentinelOne Singularity Complete's ability to ingest and correlate across our security solutions has not presented any problems. This capability provides a benefit when hunting for threats and leveraging the AI side of the platform.

Regarding alert reduction, I would not say the impact has been massive. One of the negatives we have found is that we receive quite a lot of false positives.

Overall, SentinelOne Singularity Complete saves me time, and I would say the time savings are approximately 10 to 15 percent.

What needs improvement?

The reporting in SentinelOne Singularity Complete could be improved as it is still somewhat clunky and lacks customization. Support response times could also be better.

For how long have I used the solution?

I have been using SentinelOne Singularity Complete for approximately 18 months.

Buyer's Guide
SentinelOne Singularity Endpoint
August 2026
Learn what your peers think about SentinelOne Singularity Endpoint. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
910,454 professionals have used our research since 2012.

What do I think about the stability of the solution?

I would rate the stability of SentinelOne Singularity Complete as an eight out of ten.

What do I think about the scalability of the solution?

I would rate the scalability of SentinelOne Singularity Complete as an eight out of ten.

How are customer service and support?

I would rate the support of SentinelOne Singularity Complete overall as a six out of ten.

Which solution did I use previously and why did I switch?

SentinelOne Singularity Complete was already in place when I joined.

How was the initial setup?

The deployment of SentinelOne Singularity Complete was straightforward and easy. It took approximately one day to implement SentinelOne Singularity Complete, based on the number of clients we had.

What's my experience with pricing, setup cost, and licensing?

Regarding pricing for SentinelOne Singularity Complete, on a scale where one is cheap and ten is expensive, I would rate it as an eight.

Which other solutions did I evaluate?

When comparing SentinelOne Singularity Complete with other vendors, we use it for client-specific purposes, while other clients may use Microsoft or similar solutions. I have noticed it works well.

What other advice do I have?

SentinelOne Singularity Complete has not helped us consolidate any security tools that I am aware of.

We do not use the Ranger functionality in SentinelOne Singularity Complete as we use other solutions for that purpose.

Maintenance of SentinelOne Singularity Complete is straightforward to perform. Approximately 60 users use the solution, and all users are local. SentinelOne Singularity Complete requires some maintenance as part of our internal checks to ensure policies are up to date, which we perform on a weekly basis.

We do not use Purple AI.

My advice for others looking into purchasing SentinelOne Singularity Complete is that I would definitely recommend it. I would rate this review an eight out of ten overall.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Mar 23, 2026
Flag as inappropriate
PeerSpot user
Francesco Morabito - PeerSpot reviewer
L2 Cyber Security Analyst at a security firm with 51-200 employees
Real User
Top 20
Aug 17, 2026
Security has been strengthened as automated threat response and alert analysis reduce risk
Pros and Cons
  • "SentinelOne Singularity Endpoint has helped to consolidate our security solutions and has acted promptly on attempted attacks, such as worms, some Trojans, and many spyware, blocking everything."
  • "I rate it an eight and not a higher or lower score because it does not have web reputation management."

What is our primary use case?

My main use case for SentinelOne Singularity Endpoint involves checking the XDR, endpoint management, policy management, adding blocklists, and exclusions.

I give a quick, specific example of how I use policy management or the blocklist in my day-to-day work depending on whether there are alerts that identify malicious files or files detected as malicious that actually are not malicious. We create exclusions via policies, and if there are endpoints that maybe need to be updated, such as the version, or removed from isolation or disconnected from the network, we act from the endpoint inventory.

The use cases and operating methods I have described are quite practical, highly recommendable, and I appreciate this software.

What is most valuable?

The best features offered by SentinelOne Singularity Endpoint are definitely the speed in managing alerts, the ease of disconnecting an endpoint, and the speed in doing a shutdown or reverting to previous policies.

SentinelOne Singularity Endpoint has had a positive impact on my organization because it is a very advanced antimalware solution. It has a direct connection with VirusTotal and performs verification through Singularity. There is also Purple AI for management through artificial intelligence, checking alerts, and the analysis of the alerts. You can also check things from the XDR side, review all the logs, and check the mapping against MITRE ATT&CK.

Thanks to these features, I have achieved concrete results as it is very efficient because SentinelOne acts automatically. It kills and quarantines events and malware automatically. If it detects a malicious file, it acts automatically and performs kill and quarantine on its own, and then it is up to us to decide whether to remove the file from isolation, that is, from quarantine, or to leave it there.

SentinelOne Singularity Endpoint is fine as it is and really good.

What needs improvement?

Having some capture-the-flag exercises inside the console, perhaps from time to time if the vendors propose them, would be a good improvement. Additionally, improvements at the level of events and checks for all the new components and all the new features of the console would be beneficial.

I rate it an eight and not a higher or lower score because it does not have web reputation management. It does not act at the web level. It works primarily only at the file level and endpoint inventory.

There are no other aspects that could be improved in SentinelOne Singularity Endpoint that I have not mentioned.

For how long have I used the solution?

I have been working in my current field for two and a half years.

What do I think about the stability of the solution?

SentinelOne Singularity Endpoint is stable in my experience.

What do I think about the scalability of the solution?

I would rate the scalability of SentinelOne Singularity Endpoint as good.

How are customer service and support?

My experience with SentinelOne Singularity Endpoint's customer support has been good.

I rate customer support a nine on a scale from one to ten.

Which solution did I use previously and why did I switch?

We used Trend Micro before, but we have moved to SentinelOne because Trend Micro lately was not very active or responsive. SentinelOne is a bit more approachable, more direct, and more responsive.

What was our ROI?

I do not have data regarding return on investment with SentinelOne Singularity Endpoint.

It has not freed up staff for other projects and tasks.

What's my experience with pricing, setup cost, and licensing?

I do not handle pricing, configuration management, or licenses because I am part of the SOC. I do not deal with licenses, buying, and selling.

Which other solutions did I evaluate?

Before choosing SentinelOne Singularity Endpoint, I evaluated other options such as CrowdStrike, but in the end, it was too expensive and we opted for SentinelOne.

What other advice do I have?

SentinelOne Singularity Endpoint has helped to consolidate our security solutions. It has acted promptly on attempted attacks, such as worms, some Trojans, and many spyware. It blocks everything.

Ranger AD is used, but not by my team. It is used by another team.

SentinelOne Singularity Endpoint has helped reduce alerts, but it depends. At the beginning, it was very noisy, generating many alerts, but after some tuning and creating exclusions, it stopped making noise.

The solution has helped reduce the Mean Time to Detect in my organization by half an hour.

My advice to other people who are considering using SentinelOne Singularity Endpoint is that the console is very intuitive, and I recommend getting hands-on. Check out the endpoint inventory side and the alert side, understand how to examine an alert, check through Purple AI, study the details carefully, cross-check the data with VirusTotal, and analyze the alerts and the data provided by the alert thoroughly.

I rate this product an eight out of ten.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Last updated: Aug 17, 2026
Flag as inappropriate
PeerSpot user
Buyer's Guide
SentinelOne Singularity Endpoint
August 2026
Learn what your peers think about SentinelOne Singularity Endpoint. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
910,454 professionals have used our research since 2012.
surajku32 - PeerSpot reviewer
System Administrator at VATSIN Technology Solutions Pvt
Real User
Top 5Leaderboard
Jul 15, 2026
Endpoint protection has reduced alerts and saved time with real-time monitoring and rollback
Pros and Cons
  • "Singularity Complete helped free up my staff for other projects and tasks by saving the costs of two employees after implementing this solution."

    What is our primary use case?

    I typically use SentinelOne Singularity Endpoint for endpoint detection, including EDR and EPP, to secure my endpoints.

    A specific example of how I use SentinelOne Singularity Endpoint to secure my endpoints is that it provides AI-powered threat detection that will be very profitable for us. If any malware behaves suspiciously, behavioral analytics will notify us, and it can stop zero-day threats and fileless malware, saving our system from the threat.

    The main use case for SentinelOne Singularity Endpoint is to secure my endpoints.

    How has it helped my organization?

    SentinelOne Singularity Endpoint has positively impacted my organization by saving many systems because we have more than 100 systems that are very critical to monitor individually, and it helps secure all our systems.

    Managing and securing those systems with SentinelOne Singularity Endpoint means it provides real-time monitoring and threat analysis for each system, which is very helpful for us.

    Singularity Complete helped free up my staff for other projects and tasks by saving the costs of two employees after implementing this solution.

    What is most valuable?

    The best features that SentinelOne Singularity Endpoint offers are real-time monitoring, process visibility, attack timelines, root cause analysis, threat hunting, and MITRE ATT&CK mapping, which is the best feature.

    Real-time monitoring and process visibility from SentinelOne Singularity Endpoint help me in my day-to-day work because if any malware files are downloaded, it will take real-time action on them. Additionally, there is a rollback plan, allowing us to easily revert to the malware-affected system, which is a very beneficial feature available in the system.

    What needs improvement?

    SentinelOne Singularity Endpoint can be improved by ensuring that all our endpoints are completely secure and risk-free. If anything happens, a rollback plan will be there so that we can easily revert everything.

    For how long have I used the solution?

    I have been using SentinelOne Singularity Endpoint for the last six months.

    What do I think about the stability of the solution?

    SentinelOne Singularity Endpoint is stable.

    What do I think about the scalability of the solution?

    The scalability of SentinelOne Singularity Endpoint is good.

    How are customer service and support?

    The customer support for SentinelOne Singularity Endpoint is very good.

    On a scale of 1 to 10, I would rate the customer support for SentinelOne Singularity Endpoint a 10 out of 10.

    Which solution did I use previously and why did I switch?

    I did not use any other solution before using SentinelOne Singularity Endpoint, as I started using it directly.

    What was our ROI?

    I have seen a return on investment with SentinelOne Singularity Endpoint as it saves a lot of time and reduces our employee costs.

    Which other solutions did I evaluate?

    I did not evaluate any other options before choosing SentinelOne Singularity Endpoint.

    What other advice do I have?

    Singularity Complete has helped reduce alerts because my system currently has no threats, so I am getting very low alerts.

    SentinelOne Singularity Endpoint has helped reduce my organization's Mean Time to Detect by about two to three hours per day.

    The solution has helped reduce my organization's Mean Time to Respond by five hours.

    If you want to secure your endpoint, you can go for SentinelOne Singularity Endpoint; it is a very good product that you can use. I would rate this product a 10 out of 10.

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Other
    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    Last updated: Jul 15, 2026
    Flag as inappropriate
    PeerSpot user
    Soc Analyst at Softcell Technologies Limited
    Real User
    Top 20
    Apr 23, 2026
    Advanced detection has strengthened endpoint protection and simplifies real-time threat response
    Pros and Cons
    • "The main benefits that SentinelOne Singularity Endpoint brings to the table are enhanced security and improved operational efficiency."
    • "I would like to see some improvements in SentinelOne Singularity Endpoint; there are features that are currently missing that I would like to see included or enhanced in the future."

    What is our primary use case?

    I use it primarily for endpoint protection, and I utilize it in various security scenarios. I work with SentinelOne Singularity Endpoint. I do use Purple AI, and data privacy and security are very important when utilizing Purple AI; it meets these needs well.

    What is most valuable?

    What I appreciate about it are its advanced detection capabilities and user-friendly interface; those are the best features in it.

    My impressions of SentinelOne Singularity Endpoint's ability to ingest and correlate across my security solutions are very positive; it works effectively. SentinelOne Singularity Endpoint has helped me consolidate my security solutions significantly. I have examples about the consolidation of my security solutions with SentinelOne Singularity Endpoint; I appreciate discussing the threats that we have encountered.

    I use the solution's Ranger functionality, and it has been helpful. SentinelOne Singularity Endpoint has helped to reduce alerts for me, making it easier to manage. SentinelOne Singularity Endpoint has helped to free up my staff for other projects and tasks, and I have seen time-saving aspects; I can share how much time it saved us.

    It detects threats in real-time, which does not require prior scenarios. If we observe multiple false positives, we reach out to clients directly if the alert is serious; SentinelOne Singularity Endpoint does the remaining part for us by identifying and securing the client's endpoint, so we do not have to do any manual work.

    Purple AI amplifies team knowledge effectively in my environment, and it has been very helpful. I assess Purple AI's capability in providing synthesized threat intelligence and contextual insights as strong. Purple AI's ability to streamline threat investigations has a positive impact on my SecOps workflows.

    The main benefits that SentinelOne Singularity Endpoint brings to the table are enhanced security and improved operational efficiency.

    What needs improvement?

    I would like to see some improvements in SentinelOne Singularity Endpoint; there are features that are currently missing that I would like to see included or enhanced in the future.

    For how long have I used the solution?

    I have been using SentinelOne Singularity Endpoint more than a year.

    What do I think about the stability of the solution?

    Regarding the procurement aspect, I do not know where I bought it from, but I have not experienced any crashes, downtimes, or performance issues with SentinelOne Singularity Endpoint.

    How are customer service and support?

    I would evaluate customer service and technical support as an 8 on a scale of 1 to 10.

    How was the initial setup?

    The initial setup process is straightforward for me; I do not find any complexities with the setup.

    What was our ROI?

    Regarding the pricing aspect, I have experience with it, and I have seen ROI with it.

    Which other solutions did I evaluate?

    The main differences, both pros and cons of SentinelOne Singularity Endpoint compared to other endpoint protection products I have worked with, are notable.

    What other advice do I have?

    I use the solution's Ranger functionality, and it has been helpful. Given my experience with SentinelOne Singularity Endpoint, my advice for organizations considering it would be to certainly assess its capabilities. I rate this product as a 9 overall.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor. The reviewer's company has a business relationship with this vendor other than being a customer: Partner
    Last updated: Apr 23, 2026
    Flag as inappropriate
    PeerSpot user
    Ijeoma Nkemjika - PeerSpot reviewer
    Customer Success Manager at Digitank Technology
    Reseller
    Top 20
    Sep 27, 2025
    Has improved threat hunting through query suggestions and contextual incident storylines
    Pros and Cons
    • "SentinelOne Singularity Complete has shown a return on investment with its ability to detect threats at approximately 99% efficiency."
    • "The main area for improvement relates to Linux compatibility. When deploying on a Linux system, the process isn't as seamless compared to other operating systems."

    What is our primary use case?

    I have used SentinelOne Singularity Complete in a SOC environment where most customers were utilizing it. 

    How has it helped my organization?

    The solution has been helpful especially for the infrastructure security team. They can focus their energy on other business projects and priorities while having peace of mind knowing that even without real-time operation, SentinelOne Singularity Complete can detect vulnerabilities and contain threats until they intervene. This allows them to work on other projects, develop security policies, and strengthen their defense. The team can address other security loopholes while SentinelOne Singularity Complete manages their infrastructure.

    What is most valuable?

    One of the features I particularly appreciate is the hunting capability, specifically being able to use deep visibility for threat hunting. 

    It's quite elaborate. It allows you to create and manage queries easily. Even if you're not very proficient in the language being used, it suggests the correct syntax when you type in plain text. If there's an error, it points out where you're wrong, enabling you to adjust the syntax. This feature is particularly beneficial for threat hunting using the deep visibility feature of SentinelOne Singularity Complete.

    Additionally, the platform allows for compartmentalization, which is great because we use it for about 13 customers. It enables us to manage different environments from a single console and download relevant data for each customer.

    What stands out is that this solution is not just about detection; it's also about response and containment. When it addresses an incident, it explains what occurred and suggests actions to take before further investigation.

    Another excellent feature is its ability to filter events from the same company, helping to reduce noise. For instance, if a single user performs various actions that would typically trigger hundreds of alerts, this system consolidates those activities under that one user. This approach allows for tracking related events together rather than generating multiple alerts. As a result, you can analyze an incident from a holistic perspective rather than just viewing individual alerts in isolation. Overall, these capabilities enhance the effectiveness of threat management and incident response. That's my take on it!

    It's capable of integrating with SIEM and other solutions. It offers enhanced interoperability. 

    What needs improvement?

    The main area for improvement relates to Linux compatibility. When deploying on a Linux system, the process isn't as seamless compared to other operating systems. They could enhance this by providing an easier way to implement or deploy on Linux OS systems.

    For how long have I used the solution?

    I have used SentinelOne Singularity Complete for four years.

    What do I think about the stability of the solution?

    There have been no stability issues at the moment.

    What do I think about the scalability of the solution?

    It's scalable.

    How are customer service and support?

    Their support is very good. When we encounter an issue, we quickly raise support tickets, and the response time is very good.

    How would you rate customer service and support?

    Positive

    How was the initial setup?

    It's not complex. It's straightforward, and the support is very good. 

    What was our ROI?

    SentinelOne Singularity Complete has shown a return on investment with its ability to detect threats at approximately 99% efficiency.

    What's my experience with pricing, setup cost, and licensing?

    It's affordable. The pricing is competitive. 

    SentinelOne Singularity Complete has proven beneficial in a specific case. In one instance, a customer had Microsoft licenses that were very expensive at the enterprise level. By implementing SentinelOne Singularity Complete, they were able to reduce their license plans and focus on this solution because it offered more robust features than their previous solution.

    What other advice do I have?

    I would rate SentinelOne Singularity Complete a ten out of ten. It's a good solution.

    Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
    PeerSpot user
    Sagar-Patel - PeerSpot reviewer
    Security Engineer at a marketing services firm with 11-50 employees
    Real User
    Top 20
    Jul 15, 2026
    Deep visibility has transformed threat hunting and now cuts incident response from hours to seconds
    Pros and Cons
    • "Singularity Endpoint has completed my security solutions; during the six pillars of zero trust architecture, I can implement all pillars—identity, application, endpoints, infrastructure, network, and cloud—through the Singularity platform."
    • "SentinelOne Singularity Endpoint can be improved by implementing more XDR in the network connections and connectivity."

    What is our primary use case?

    My main use case for SentinelOne Singularity Endpoint involves EDR, deep visibility, and threat hunting.

    For EDR or threat hunting in my day-to-day work, I use SentinelOne Singularity Endpoint primarily for incident management and for daily threat hunting, where I run queries, XDR queries, EDR, and power queries for hunting.

    In addition to my main use cases, I also use SentinelOne Singularity Endpoint for application management, inventory management, and identity management for all users, along with vulnerability recommendation and vulnerability development management.

    What is most valuable?

    SentinelOne Singularity Endpoint offers excellent features that include threat visibility, deep visibility, and threat hunting.

    What stands out to me with SentinelOne Singularity Endpoint's threat visibility and threat hunting features is that deep visibility gives us a 360-degree angle view of cloud, endpoint, identity, and network data to assess any possible threat hunting or risky activities, which is a good feature.

    SentinelOne Singularity Endpoint has positively impacted my organization with its Purple AI feature.

    Purple AI has made a positive impact by saving time because it provides a summary glimpse of the incident, allowing me to get an overview of what happened, and then I can check the particular identity or asset, which helps in checking everything in the incident or particular device or organization.

    SentinelOne Singularity Endpoint has helped me see the connections between different security events or alerts, and it integrates easily.

    Singularity Endpoint has completed my security solutions; during the six pillars of zero trust architecture, I can implement all pillars—identity, application, endpoints, infrastructure, network, and cloud—through the Singularity platform.

    Singularity Complete has helped reduce false positive alerts; by creating star rules or alert rules for valid files allowed in the network, we are getting fewer incidents from the beginning.

    Singularity Endpoint has freed up my staff for other projects and tasks, saving us one to two days per week to focus on other things.

    It has reduced the mean time to respond, MTTR, by shrinking the incident response and forensic science analysis cycles from hours to seconds.

    What needs improvement?

    SentinelOne Singularity Endpoint can be improved by implementing more XDR in the network connections and connectivity.

    Regarding needed improvements, the device connectivity management feature is very good and is working effortlessly and connecting well, though if we could improve some Purple AI features such as providing direct results to queries, that would be a valuable enhancement.

    For how long have I used the solution?

    I have been using SentinelOne Singularity Endpoint for two years.

    What do I think about the stability of the solution?

    SentinelOne Singularity Endpoint is stable.

    What do I think about the scalability of the solution?

    Its scalability is impressive as it delivers horizontal scalability to a single agent and supports SaaS services, on-premises, and hybrid environments.

    How are customer service and support?

    Customer support is good, and the service is good.

    Which solution did I use previously and why did I switch?

    We previously used Microsoft Defender XDR, but we have SentinelOne Singularity Endpoint as a backup EDR solution.

    How was the initial setup?

    When we previously used Microsoft Defender XDR, the setup has been stable.

    What was our ROI?

    I do not have any metrics regarding return on investment, as I am part of the group and did not implement it.

    What's my experience with pricing, setup cost, and licensing?

    I am part of the group but do not have hands-on experience with the pricing, setup cost, and licensing.

    Which other solutions did I evaluate?

    Before choosing SentinelOne Singularity Endpoint, we did not evaluate any other options; one customer provided feedback indicating they use SentinelOne Singularity Endpoint, so we decided to go with it.

    What other advice do I have?

    My company acts as a service provider, MSSP, in our relationship with this vendor. I would rate this review a 9 overall.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Disclosure: My company has a business relationship with this vendor other than being a customer. MSP
    Last updated: Jul 15, 2026
    Flag as inappropriate
    PeerSpot user
    reviewer2842140 - PeerSpot reviewer
    Security Engineer at a comms service provider with 11-50 employees
    Real User
    Top 10
    May 28, 2026
    Endpoint protection has reduced response times and now frees my team for deeper investigations
    Pros and Cons
    • "My favorite feature about it is the full visibility into telemetry."
    • "It's easy to deploy, but the documentation about the Linux part could be better because it's a little complicated only on the Linux part, specifically on Ubuntu; it could be clearer and simpler."

    What is our primary use case?

    I use SentinelOne Singularity Endpoint as HDR, as the product is designed.

    What is most valuable?

    My favorite feature about it is the full visibility into telemetry.

    SentinelOne Singularity Endpoint has helped reduce alerts, but false positives could be less.

    It has helped me in my investigation to free up my staff for other projects.

    I have seen a reduction in mean time to respond.

    What needs improvement?

    I think the visibility on Storyline could be better.

    I could not comment on the Ranger functionality because I don't use it.

    I have seen a reduction in mean time to respond and it has helped me in investigations to free up my staff for other projects.

    I tried using the Purple AI feature.

    I think it's great and it's working very well and has helped reduce the mean time to respond. The description is great; it's not too specific and not too much reduced. The long summary is excellent; it provides a great summary.

    For how long have I used the solution?

    I have been working with SentinelOne Singularity Endpoint for eight months.

    What do I think about the stability of the solution?

    The stability of SentinelOne Singularity Endpoint is great and I would rate it 10.

    What do I think about the scalability of the solution?

    SentinelOne Singularity Endpoint is very scalable and I would rate it 10.

    How are customer service and support?

    I have had to contact technical support and it worked well.

    I think the quality of their support is 10 and the speed could be nine.

    If I were to put together an overall score for the support, I would give them nine.

    Which solution did I use previously and why did I switch?

    I have used many products as alternatives to SentinelOne Singularity Endpoint.

    How was the initial setup?

    I am involved in the initial deployment and it's working great.

    It's easy to deploy, but the documentation about the Linux part could be better because it's a little complicated only on the Linux part, specifically on Ubuntu; it could be clearer and simpler.

    SentinelOne Singularity Endpoint requires a little bit of maintenance on the agent upgrade, so a feature to auto-deliver updates month by month would be great.

    What about the implementation team?

    SentinelOne Singularity Endpoint consolidated the environment.

    What was our ROI?

    I can give 30% as a number for the reduction.

    Which other solutions did I evaluate?

    The product closest in terms of quality and features to SentinelOne Singularity Endpoint is CrowdStrike.

    I prefer CrowdStrike over SentinelOne Singularity Endpoint.

    I prefer CrowdStrike because I could see a lot more information in the detection part and the false positives are reduced.

    What other advice do I have?

    Data privacy and security are very important for us when using Purple AI because we work with some Italian government companies or government-related companies, so privacy and European regulation are very important.

    SentinelOne Singularity Endpoint consolidated the environment.

    Endpoint protection solutions were consolidated now that I don't need them.

    I would rate this review 9 overall.

    Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
    Last updated: May 28, 2026
    Flag as inappropriate
    PeerSpot user
    reviewer2848893 - PeerSpot reviewer
    Head of Security at a consultancy with 51-200 employees
    Real User
    Top 5
    Jul 15, 2026
    Behavioral detection has transformed endpoint investigations and now improves incident response
    Pros and Cons
    • "SentinelOne Singularity Endpoint has positively impacted my organization by being one of the primary tools keeping us secure against modern security issues, with faster threat detection and investigation through better endpoint visibility which has greatly helped our team, resulting in improved incident response and reduced reliance on manual monitoring."
    • "SentinelOne Singularity Endpoint would benefit from broader security ecosystem integration, including deeper native integrations across identity access and other security domains, which would make it more competitive with larger security platforms."

    What is our primary use case?

    My main use case for SentinelOne Singularity Endpoint is primarily for endpoint detection and response, EDR, focusing on endpoint protection.

    SentinelOne Singularity Endpoint is being used for behavioral threat detection, malware and ransomware protection, security investigations, response activities, and also to isolate endpoints where required.

    How has it helped my organization?

    SentinelOne Singularity Endpoint has positively impacted my organization by being one of the primary tools keeping us secure against modern security issues, with faster threat detection and investigation through better endpoint visibility which has greatly helped our team, resulting in improved incident response and reduced reliance on manual monitoring.

    Regarding metrics on how it has improved incident response, I do not have any specific data to share.

    What is most valuable?

    The best features SentinelOne Singularity Endpoint offers include behavior-based detection, which can identify suspicious activity based on behavior patterns and has very few false positives, as well as autonomous prevention and response, where the agent can automatically block malicious activity. It also has strong investigation capabilities, and the process traceability along with endpoint activity context makes it very easy to understand what happened during an alert, and it includes ransomware protection and rollback capabilities, along with very low operational overhead.

    From all the features I mentioned, I find myself relying most on behavior-based detection with endpoint investigation visibility because it allows our security team to quickly understand suspicious activity beyond simple malware alerts, helping analysts validate incidents faster and make better decisions.

    What needs improvement?

    SentinelOne Singularity Endpoint would benefit from broader security ecosystem integration, including deeper native integrations across identity access and other security domains, which would make it more competitive with larger security platforms.

    I chose nine out of ten because I usually do not give out tens to be honest, but it is mainly due to areas outside its core endpoint security, as while it is very strong in EDR, there is still room for improvement around broader security platform capabilities and deeper cloud-native security coverage.

    For how long have I used the solution?

    I have been using SentinelOne Singularity Endpoint for more than a year.

    What do I think about the stability of the solution?

    SentinelOne Singularity Endpoint is stable.

    What do I think about the scalability of the solution?

    I am happy with the scalability of SentinelOne Singularity Endpoint.

    How are customer service and support?

    We pay for premium support for SentinelOne Singularity Endpoint, which is good, but they are charging us money.

    Which solution did I use previously and why did I switch?

    SentinelOne was already in this environment, so I did not previously use a different solution.

    What was our ROI?

    I have seen a return on investment, which is primarily on the improved SOC efficiency and reduced manual effort, along with the time saved during investigations and faster response actions. For example, a capability such as endpoint isolation helped reduce the time required to contain a suspicious activity, but I do not have numbers to present.

    What's my experience with pricing, setup cost, and licensing?

    I was involved in the decision-making regarding my experience with pricing, setup cost, and licensing.

    Which other solutions did I evaluate?

    Before choosing SentinelOne Singularity Endpoint, I did not evaluate other options, as we acquired it from an acquisition.

    What other advice do I have?

    Singularity Complete has not significantly consolidated our security solutions, as we are primarily relying on this for EDR.

    To some extent, Singularity Complete has helped reduce alerts, with the main improvement being the platform's ability to automatically identify and prevent certain behaviors, but I do not have a number.

    To some extent, Singularity Complete has helped free up my staff for other projects and tasks, primarily with its autonomous prevention capabilities, allowing analysts to spend less time collecting information manually and more time focusing on higher-value security activities.

    It has definitely helped reduce my organization's mean time to detect, MTTD, but we have not measured the specific reduction percentage.

    Mean time to response, MTTR, is primarily handled by humans.

    The pricing for SentinelOne Singularity Endpoint is good compared to other industry vendors, and organizations should definitely focus on proper policy tuning and make use of the behavioral capabilities. I would rate this product nine out of ten overall.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    Last updated: Jul 15, 2026
    Flag as inappropriate
    PeerSpot user
    Olive Kusumbara - PeerSpot reviewer
    Consultant at a tech services company with 1,001-5,000 employees
    MSP
    Top 5
    Nov 4, 2025
    Has improved threat detection and streamlined integrations through strong XDR and forensic capabilities
    Pros and Cons
    • "I've seen a lot of improvements and simplifications, and Google SecOps has recently moved into Gartner's as the highest one for visionaries."
    • "A weakness seen with one large customer was that the detections were too intrusive, blocking many applications that should have been working, which led to many false positives."

    What is our primary use case?

    I'm only dealing with Google SecOps right now, not other Google Cloud products. On a limited scale, I think we use Microsoft Defender for one particular customer; for the others, we are using SentinelOne Singularity Complete and Palo Alto Cortex.

    What is most valuable?

    I've seen a lot of improvements and simplifications, and Google SecOps has recently moved into Gartner's as the highest one for visionaries. The AI, agentic AI, integration with SOARs, and simplified SKUs and pricing are noteworthy. Most customers who have various platforms for cybersecurity do not choose Azure Defender unless they are on a Microsoft stack right now. SentinelOne Singularity Complete is the most capable in terms of detection and response, and I use it quite extensively for forensic capabilities.

    SentinelOne Singularity Complete can be quite intrusive, but it has strong detection capabilities. The Ranger functionality of SentinelOne Singularity Complete for the EDR is extensively used for customers. Microsoft Defender has recently upgraded to XDR capabilities.

    What needs improvement?

    For Azure Sentinel, the main issue that needs improvement is the pricing; it's quite unpredictable right now in terms of cost. The use of many components within Azure itself is confusing, especially with the recent move in terms of the console from Azure Sentinel to the Defenders. The highlight is more into the pricing; it is too expensive and unpredictable right now.

    For Google SecOps, the only improvement I suggest is in terms of the reporting, especially for out-of-the-box reporting that seems very lacking right now. There aren't too many useful reports coming from out-of-the-box; we have to develop them ourselves right now.

    SentinelOne Singularity Complete needs to work more on increasing true positive detections to make it closer to 10. A weakness seen with one large customer was that the detections were too intrusive, blocking many applications that should have been working, which led to many false positives.

    How are customer service and support?

    I think technical support is quite good; we have been in contact quite occasionally, and they provide expected answers.

    How would you rate customer service and support?

    Positive

    How was the initial setup?

    I find the initial setup quite straightforward for SentinelOne Singularity Complete.

    Which other solutions did I evaluate?

    SentinelOne Singularity Complete can be quite intrusive; that's one of the drawbacks. It's also the first thing that we recommend right now. We prefer to use other EDR platforms such as SentinelOne Singularity Complete and Palo Alto Cortex right now.

    What other advice do I have?

    I'm using Google SecOps. If you want, I can leave my opinion on Google SecOps.

    While the others will be on the cyber threat intelligence, the primary is Google SecOps, and I think the other one is Azure Sentinel.

    There is room for improvement for these solutions. It's mostly SIEM and MDR for SentinelOne Singularity Complete. I haven't used Vigilance MDR; I only know the name.

    We mainly focus on SentinelOne Singularity Complete and Cortex, while the other EDRs that we have managed are less significant. It's almost similar since both SentinelOne Singularity Complete and Cortex have EDR and XDR capabilities.

    In terms of non-locked XDR platforms, the best one is SentinelOne Singularity Complete right now for their XDR capabilities. Other ones such as Palo Alto Cortex or even CrowdStrike are locked into their own ecosystem right now since they have many products within that ecosystem. In terms of integration, even though it looks quite open, some are tightly coupled into their own ecosystem, especially for Palo Alto Cortex.

    We haven't had that in-depth experience in terms of ingesting and correlating for SentinelOne Singularity Complete; we mainly use it right now for their EDR capabilities. Since we provide the MDR services, we mainly integrate those with Google SecOps right now for the overall SOC services. I think they are the most capable in terms of detection and response.

    We only tried Purple AI but haven't used it quite extensively. I find the pricing very reasonable, especially right now compared to other top-tier EDR platforms at the same level. I usually recommend the product for both smaller and bigger organizations. My overall rating for this review is 9.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Other
    Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
    PeerSpot user
    Technical Support Engineer at Softcell Technologies
    Real User
    Top 20
    Jul 17, 2026
    AI-driven endpoint defense has transformed threat hunting and now speeds incident response
    Pros and Cons
      • "In SentinelOne Singularity Endpoint, there is room for improvement in custom rules and the dashboard for finding rules and blocking actions."

      What is our primary use case?

      I use SentinelOne Singularity Endpoint for endpoint detection and response on the endpoint, and I use it with Purple AI, which is the most important model for this product.

      What is most valuable?

      The best features of SentinelOne Singularity Endpoint are Purple AI and the network containment option, with Purple AI being the most important feature and the network containment model being the best feature.

      SentinelOne Singularity Endpoint has helped me consolidate security solutions as it is also used as a single solution.

      I use the Ranger functionality, which is used for finding known and unknown devices.

      The Ranger functionality provides clear network and asset visibility by showing how many endpoints are in the network and how many endpoints are not in the network.

      The ability to ingest and correlate across various security solutions is used for detection, incident detection, and response, which is related to the high severity of incident detection and preventing malware and ransomware attacks.

      Purple AI plays a crucial role in amplifying my team knowledge by being used for threat hunting and incident summarization on indicators of compromise like file hashes, IP addresses, and domains, helping us find the root cause of attacks.

      Purple AI impacts streamlining threat investigations on my SecOps workflow by enabling faster threat detection, reducing investigation time, and improving incident response.

      SentinelOne Singularity Endpoint frees up about twenty percent of my time.

      It has reduced my mean time to detect and my mean time to respond to incidents within fifteen minutes.

      What needs improvement?

      In SentinelOne Singularity Endpoint, there is room for improvement in custom rules and the dashboard for finding rules and blocking actions.

      For how long have I used the solution?

      I have been using SentinelOne Singularity Endpoint for the last three years.

      What do I think about the stability of the solution?

      SentinelOne Singularity Endpoint is the most stable product, which I also rate at nine.

      What do I think about the scalability of the solution?

      For scalability, I rate it at nine.

      How are customer service and support?

      I rate the technical support for SentinelOne at nine.

      Which other solutions did I evaluate?

      Compared to CrowdStrike, SentinelOne Singularity Endpoint is better for finding and responding in less time, and its threat hunting is very fast with deep visibility being a very important feature while the incident investigation is also very clear, functioning as an automated response tool.

      What other advice do I have?

      I have one hundred thirteen customers, and with SentinelOne Singularity Endpoint, there are multiple alerts, meaning twenty to thirty alerts per day.

      The pricing of SentinelOne Singularity Endpoint is expensive and considered moderate.

      My clients using SentinelOne Singularity Endpoint are medium and large enterprises.

      I would recommend SentinelOne Singularity Endpoint to other users because it is the best for endpoint security, addressing any attack surface, and the network containment option is the best, being very effective for the attack, mapping MITRE ATT&CK techniques and tactics accurately, while the AI detects threats and machine learning utilized from SentinelOne Purple AI provide deep visibility. I rate this product at nine.

      Disclosure: My company has a business relationship with this vendor other than being a customer. reseller
      Last updated: Jul 17, 2026
      Flag as inappropriate
      PeerSpot user
      Buyer's Guide
      Download our free SentinelOne Singularity Endpoint Report and get advice and tips from experienced pros sharing their opinions.
      Updated: August 2026
      Buyer's Guide
      Download our free SentinelOne Singularity Endpoint Report and get advice and tips from experienced pros sharing their opinions.