No more typing reviews! Try our Samantha, our new voice AI agent.
Hussain Nogama - PeerSpot reviewer
IT Administrator at a retailer with 201-500 employees
Real User
Top 20
Jun 4, 2026
Endpoint protection has blocked unknown threats and has improved incident response speed
Pros and Cons
  • "The most valuable features I find in SentinelOne Singularity Endpoint are the EDR, lateral movement feature, and machine learning feature, which I find impressive."
  • "It shows the vulnerability but does not provide the package to resolve that vulnerability."

What is our primary use case?

SentinelOne Singularity Endpoint is used in my company as we are a client of Sentinel. The primary use cases are for endpoint security, policies, and other features.

What is most valuable?

The most valuable features I find in SentinelOne Singularity Endpoint are the EDR, lateral movement feature, and machine learning feature, which I find impressive.

I am using the Ranger functionality in Singularity.

SentinelOne Singularity Endpoint does provide network and asset visibility, but in Singularity, you do not have the complete feature. If you want more EDR and want to know from where the attack happened and what it does, you have to purchase the EDR. When I purchased Sentinel, it had three products: SentinelOne Core, Control, and Complete. We are using Core. If you want full visibility on an EDR, there is one more add-on that you have to purchase. As a product, I think most of the features remain the same. It does not allow the machine to work if it finds any unknown activity; it immediately blocks the machine from the network and isolates it completely. Regardless of the location or where you are, if your machine is connected to the internet, you will get an alert that this machine has been isolated. It does not allow you to work at all.

What needs improvement?

There are certain things that need to be improved, such as the roll-up things because not every upgrade or update is useful. They have to do more work on the configuration side, which I believe they are already working on.

I would appreciate improvements in the patches. If I have Windows patches or application patches, it would be excellent if they could cover that on the same portal so I could go straight in and do it. It shows the vulnerability but does not provide the package to resolve that vulnerability. For example, if my Windows is outdated and Sentinel finds that there is an update that is not installed, there should be an option to install the Windows update from the portal itself.

The additional features I would appreciate in the future are already present in the Complete feature of SentinelOne Singularity Endpoint. Since I am using Core, whatever features are lacking in Core are already in Complete, so if customers want those features, they can upgrade their product.

For how long have I used the solution?

I have been working with SentinelOne Singularity Endpoint for more than four years.

Buyer's Guide
SentinelOne Singularity Endpoint
September 2026
Learn what your peers think about SentinelOne Singularity Endpoint. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
915,817 professionals have used our research since 2012.

How are customer service and support?

The response is excellent from them; the moment I submit a ticket, I can expect their response within 15 minutes, less than 15 minutes.

For technical support, I would rate them 9.5.

What other advice do I have?

For security solutions, we are also using different types of products, but I have never done the correlation across our different solutions.

Regarding Purple AI, we have recently done that with ManageEngine.

We have not integrated SentinelOne Singularity Endpoint with third-party solutions.

My overall review rating for SentinelOne Singularity Endpoint is 9.5.

Which deployment model are you using for this solution?

On-premises
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Jun 4, 2026
Flag as inappropriate
PeerSpot user
Sankha Rajaguru - PeerSpot reviewer
System Engineer at A-Networks
Reseller
Top 5
May 29, 2026
Endpoint security has improved and centralized control now simplifies device and alert management
Pros and Cons
  • "SentinelOne Singularity Endpoint scales well and is scalable."
  • "Most of the customers in Sri Lanka are currently migrating from SentinelOne Singularity Endpoint to CrowdStrike."

What is our primary use case?

I am using SentinelOne Singularity Endpoint basically for endpoint protection, and some customers have requirements for USB control and network control as well.

What is most valuable?

When it comes to the favorite features of the customers, they appreciate the additional management opportunities that SentinelOne Singularity Endpoint provides. For example, remote shell execution, rebooting, restarting, and pushing messages to the endpoint are the most favorite features that customers are requesting.

It has saved considerable time. For example, I can take device control and control all device control features and device control permissions through SentinelOne Singularity Endpoint. Otherwise, I would have to depend on a different solution to achieve that. Using SentinelOne Singularity Endpoint, I can achieve that as well.

What needs improvement?

When it comes to SentinelOne Singularity Endpoint, most of the complaints I am getting are related to the connectivity between the endpoint and the cloud console. It disconnects from time to time without proper reasons. Also, when I compare it to other next-generation antivirus or next-generation endpoints such as CrowdStrike, SentinelOne Singularity Endpoint has many dependencies on Windows. That is the most disliked aspect coming from the customers I work with.

Other than Windows, when it comes to Linux and Kubernetes, SentinelOne Singularity Endpoint is great. However, when it comes to Windows, there are a lot of dependencies.

There are some issues with collecting crash reports and crash logs on the endpoint. They are not visible over the console. Sometimes, the PC's hard disk and its available space is consumed by the SentinelOne Singularity Endpoint agent. I have to attend manually and clear the crash data. I can do it on the SentinelOne Singularity Endpoint management console as well, but I have to go with a restart. For critical servers, it is a huge headache for the end users.

For how long have I used the solution?

I have been working with SentinelOne Singularity Endpoint for about two and a half years.

What do I think about the scalability of the solution?

SentinelOne Singularity Endpoint scales well and is scalable.

How are customer service and support?

SentinelOne Singularity Endpoint provides pretty good support to their end customers.

There are some improvements needed. When it comes to some troubleshooting, such as technical troubleshooting, I have to do some follow-ups in order to get relevant feedback from them.

Which solution did I use previously and why did I switch?

Most of the customers in Sri Lanka are currently migrating from SentinelOne Singularity Endpoint to CrowdStrike. CrowdStrike is the main alternative product in the market at the moment for SentinelOne Singularity Endpoint.

I prefer CrowdStrike because it is easier to manage. When it comes to SentinelOne Singularity Endpoint, after the agent is pushed to the endpoint and the installation is done, I have to do a reboot to establish the connection and turn on the engines. With CrowdStrike, I do not need to do any restart upon installing the agent on the new device.

How was the initial setup?

SentinelOne Singularity Endpoint is easy to set up. It does not have any deployment mechanism, so I either have to install it one by one on the PC manually or I can use third-party tools to do the deployment. For example, I can do remote deployment through Active Directory. When it comes to deployment, it is not that difficult. It follows the same procedure as other vendors.

What's my experience with pricing, setup cost, and licensing?

Since I work in post-sales, prices are not revealed to me, but to my knowledge, SentinelOne Singularity Endpoint is a bit cheaper than other products in the market. For example, when I compare CrowdStrike with SentinelOne Singularity Endpoint, SentinelOne Singularity Endpoint is a bit cheaper. Since I work in post-sales, I do not get exact price information. Based on my understanding, that is the basic pricing.

Which other solutions did I evaluate?

Ranger functionality is used to detect the agents.

Asset discovery is an important feature. As far as my understanding goes, once I enable the Ranger function in the console, I can initiate a network scan through the available agent. By doing that, I can identify what IoT devices and other devices are available in my network infrastructure. I can get better visibility over the network, which devices have the SentinelOne Singularity Endpoint agent, which devices do not have the SentinelOne Singularity Endpoint agent, and so on.

What other advice do I have?

SentinelOne Singularity Endpoint helps to reduce alerts because there are customizable options when it comes to the alerts. For example, if I get false-positive alerts over time, I can do exclusions for that particular alert. Similarly, I can reduce many alerts using SentinelOne Singularity Endpoint and the Singularity platform. I gave this review a rating of 8.

Which deployment model are you using for this solution?

On-premises

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
Last updated: May 29, 2026
Flag as inappropriate
PeerSpot user
Buyer's Guide
SentinelOne Singularity Endpoint
September 2026
Learn what your peers think about SentinelOne Singularity Endpoint. Get advice and tips from experienced pros sharing their opinions. Updated: September 2026.
915,817 professionals have used our research since 2012.
reviewer2809476 - PeerSpot reviewer
Technical Account Manager at a computer software company with 11-50 employees
Real User
Top 5Leaderboard
Mar 23, 2026
Endpoint protection has reduced ransomware impact and streamlines daily threat hunting
Pros and Cons
  • "My advice for others looking into purchasing SentinelOne Singularity Complete is that I would definitely recommend it."
  • "One of the negatives we have found is that we receive quite a lot of false positives."

What is our primary use case?

I used SentinelOne Singularity Complete for endpoint security, and we selected it because we were looking for an AI-powered cloud solution.

What is most valuable?

The best features of SentinelOne Singularity Complete include a ransomware rollback feature that can be used on infected machines, which we have used before and appreciated. The deployment is fairly straightforward as well.

SentinelOne Singularity Complete's ability to ingest and correlate across our security solutions has not presented any problems. This capability provides a benefit when hunting for threats and leveraging the AI side of the platform.

Regarding alert reduction, I would not say the impact has been massive. One of the negatives we have found is that we receive quite a lot of false positives.

Overall, SentinelOne Singularity Complete saves me time, and I would say the time savings are approximately 10 to 15 percent.

What needs improvement?

The reporting in SentinelOne Singularity Complete could be improved as it is still somewhat clunky and lacks customization. Support response times could also be better.

For how long have I used the solution?

I have been using SentinelOne Singularity Complete for approximately 18 months.

What do I think about the stability of the solution?

I would rate the stability of SentinelOne Singularity Complete as an eight out of ten.

What do I think about the scalability of the solution?

I would rate the scalability of SentinelOne Singularity Complete as an eight out of ten.

How are customer service and support?

I would rate the support of SentinelOne Singularity Complete overall as a six out of ten.

How would you rate customer service and support?

Neutral

Which solution did I use previously and why did I switch?

SentinelOne Singularity Complete was already in place when I joined.

How was the initial setup?

The deployment of SentinelOne Singularity Complete was straightforward and easy. It took approximately one day to implement SentinelOne Singularity Complete, based on the number of clients we had.

What's my experience with pricing, setup cost, and licensing?

Regarding pricing for SentinelOne Singularity Complete, on a scale where one is cheap and ten is expensive, I would rate it as an eight.

Which other solutions did I evaluate?

When comparing SentinelOne Singularity Complete with other vendors, we use it for client-specific purposes, while other clients may use Microsoft or similar solutions. I have noticed it works well.

What other advice do I have?

SentinelOne Singularity Complete has not helped us consolidate any security tools that I am aware of.

We do not use the Ranger functionality in SentinelOne Singularity Complete as we use other solutions for that purpose.

Maintenance of SentinelOne Singularity Complete is straightforward to perform. Approximately 60 users use the solution, and all users are local. SentinelOne Singularity Complete requires some maintenance as part of our internal checks to ensure policies are up to date, which we perform on a weekly basis.

We do not use Purple AI.

My advice for others looking into purchasing SentinelOne Singularity Complete is that I would definitely recommend it. I would rate this review an eight out of ten overall.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Mar 23, 2026
Flag as inappropriate
PeerSpot user
Francesco Morabito - PeerSpot reviewer
L2 Cyber Security Analyst at a security firm with 51-200 employees
Real User
Top 5
Aug 17, 2026
Security has been strengthened as automated threat response and alert analysis reduce risk
Pros and Cons
  • "SentinelOne Singularity Endpoint has helped to consolidate our security solutions and has acted promptly on attempted attacks, such as worms, some Trojans, and many spyware, blocking everything."
  • "I rate it an eight and not a higher or lower score because it does not have web reputation management."

What is our primary use case?

My main use case for SentinelOne Singularity Endpoint involves checking the XDR, endpoint management, policy management, adding blocklists, and exclusions.

I give a quick, specific example of how I use policy management or the blocklist in my day-to-day work depending on whether there are alerts that identify malicious files or files detected as malicious that actually are not malicious. We create exclusions via policies, and if there are endpoints that maybe need to be updated, such as the version, or removed from isolation or disconnected from the network, we act from the endpoint inventory.

The use cases and operating methods I have described are quite practical, highly recommendable, and I appreciate this software.

What is most valuable?

The best features offered by SentinelOne Singularity Endpoint are definitely the speed in managing alerts, the ease of disconnecting an endpoint, and the speed in doing a shutdown or reverting to previous policies.

SentinelOne Singularity Endpoint has had a positive impact on my organization because it is a very advanced antimalware solution. It has a direct connection with VirusTotal and performs verification through Singularity. There is also Purple AI for management through artificial intelligence, checking alerts, and the analysis of the alerts. You can also check things from the XDR side, review all the logs, and check the mapping against MITRE ATT&CK.

Thanks to these features, I have achieved concrete results as it is very efficient because SentinelOne acts automatically. It kills and quarantines events and malware automatically. If it detects a malicious file, it acts automatically and performs kill and quarantine on its own, and then it is up to us to decide whether to remove the file from isolation, that is, from quarantine, or to leave it there.

SentinelOne Singularity Endpoint is fine as it is and really good.

What needs improvement?

Having some capture-the-flag exercises inside the console, perhaps from time to time if the vendors propose them, would be a good improvement. Additionally, improvements at the level of events and checks for all the new components and all the new features of the console would be beneficial.

I rate it an eight and not a higher or lower score because it does not have web reputation management. It does not act at the web level. It works primarily only at the file level and endpoint inventory.

There are no other aspects that could be improved in SentinelOne Singularity Endpoint that I have not mentioned.

For how long have I used the solution?

I have been working in my current field for two and a half years.

What do I think about the stability of the solution?

SentinelOne Singularity Endpoint is stable in my experience.

What do I think about the scalability of the solution?

I would rate the scalability of SentinelOne Singularity Endpoint as good.

How are customer service and support?

My experience with SentinelOne Singularity Endpoint's customer support has been good.

I rate customer support a nine on a scale from one to ten.

Which solution did I use previously and why did I switch?

We used Trend Micro before, but we have moved to SentinelOne because Trend Micro lately was not very active or responsive. SentinelOne is a bit more approachable, more direct, and more responsive.

What was our ROI?

I do not have data regarding return on investment with SentinelOne Singularity Endpoint.

It has not freed up staff for other projects and tasks.

What's my experience with pricing, setup cost, and licensing?

I do not handle pricing, configuration management, or licenses because I am part of the SOC. I do not deal with licenses, buying, and selling.

Which other solutions did I evaluate?

Before choosing SentinelOne Singularity Endpoint, I evaluated other options such as CrowdStrike, but in the end, it was too expensive and we opted for SentinelOne.

What other advice do I have?

SentinelOne Singularity Endpoint has helped to consolidate our security solutions. It has acted promptly on attempted attacks, such as worms, some Trojans, and many spyware. It blocks everything.

Ranger AD is used, but not by my team. It is used by another team.

SentinelOne Singularity Endpoint has helped reduce alerts, but it depends. At the beginning, it was very noisy, generating many alerts, but after some tuning and creating exclusions, it stopped making noise.

The solution has helped reduce the Mean Time to Detect in my organization by half an hour.

My advice to other people who are considering using SentinelOne Singularity Endpoint is that the console is very intuitive, and I recommend getting hands-on. Check out the endpoint inventory side and the alert side, understand how to examine an alert, check through Purple AI, study the details carefully, cross-check the data with VirusTotal, and analyze the alerts and the data provided by the alert thoroughly.

I rate this product an eight out of ten.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
Last updated: Aug 17, 2026
Flag as inappropriate
PeerSpot user
Soc Analyst at Softcell Technologies Limited
Real User
Top 20
Apr 23, 2026
Advanced detection has strengthened endpoint protection and simplifies real-time threat response
Pros and Cons
  • "The main benefits that SentinelOne Singularity Endpoint brings to the table are enhanced security and improved operational efficiency."
  • "I would like to see some improvements in SentinelOne Singularity Endpoint; there are features that are currently missing that I would like to see included or enhanced in the future."

What is our primary use case?

I use it primarily for endpoint protection, and I utilize it in various security scenarios. I work with SentinelOne Singularity Endpoint. I do use Purple AI, and data privacy and security are very important when utilizing Purple AI; it meets these needs well.

What is most valuable?

What I appreciate about it are its advanced detection capabilities and user-friendly interface; those are the best features in it.

My impressions of SentinelOne Singularity Endpoint's ability to ingest and correlate across my security solutions are very positive; it works effectively. SentinelOne Singularity Endpoint has helped me consolidate my security solutions significantly. I have examples about the consolidation of my security solutions with SentinelOne Singularity Endpoint; I appreciate discussing the threats that we have encountered.

I use the solution's Ranger functionality, and it has been helpful. SentinelOne Singularity Endpoint has helped to reduce alerts for me, making it easier to manage. SentinelOne Singularity Endpoint has helped to free up my staff for other projects and tasks, and I have seen time-saving aspects; I can share how much time it saved us.

It detects threats in real-time, which does not require prior scenarios. If we observe multiple false positives, we reach out to clients directly if the alert is serious; SentinelOne Singularity Endpoint does the remaining part for us by identifying and securing the client's endpoint, so we do not have to do any manual work.

Purple AI amplifies team knowledge effectively in my environment, and it has been very helpful. I assess Purple AI's capability in providing synthesized threat intelligence and contextual insights as strong. Purple AI's ability to streamline threat investigations has a positive impact on my SecOps workflows.

The main benefits that SentinelOne Singularity Endpoint brings to the table are enhanced security and improved operational efficiency.

What needs improvement?

I would like to see some improvements in SentinelOne Singularity Endpoint; there are features that are currently missing that I would like to see included or enhanced in the future.

For how long have I used the solution?

I have been using SentinelOne Singularity Endpoint more than a year.

What do I think about the stability of the solution?

Regarding the procurement aspect, I do not know where I bought it from, but I have not experienced any crashes, downtimes, or performance issues with SentinelOne Singularity Endpoint.

How are customer service and support?

I would evaluate customer service and technical support as an 8 on a scale of 1 to 10.

How was the initial setup?

The initial setup process is straightforward for me; I do not find any complexities with the setup.

What was our ROI?

Regarding the pricing aspect, I have experience with it, and I have seen ROI with it.

Which other solutions did I evaluate?

The main differences, both pros and cons of SentinelOne Singularity Endpoint compared to other endpoint protection products I have worked with, are notable.

What other advice do I have?

I use the solution's Ranger functionality, and it has been helpful. Given my experience with SentinelOne Singularity Endpoint, my advice for organizations considering it would be to certainly assess its capabilities. I rate this product as a 9 overall.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor. The reviewer's company has a business relationship with this vendor other than being a customer: Partner
Last updated: Apr 23, 2026
Flag as inappropriate
PeerSpot user
Sagar-Patel - PeerSpot reviewer
Security Engineer at a marketing services firm with 11-50 employees
Real User
Top 20
Jul 15, 2026
Deep visibility has transformed threat hunting and now cuts incident response from hours to seconds
Pros and Cons
  • "Singularity Endpoint has completed my security solutions; during the six pillars of zero trust architecture, I can implement all pillars—identity, application, endpoints, infrastructure, network, and cloud—through the Singularity platform."
  • "SentinelOne Singularity Endpoint can be improved by implementing more XDR in the network connections and connectivity."

What is our primary use case?

My main use case for SentinelOne Singularity Endpoint involves EDR, deep visibility, and threat hunting.

For EDR or threat hunting in my day-to-day work, I use SentinelOne Singularity Endpoint primarily for incident management and for daily threat hunting, where I run queries, XDR queries, EDR, and power queries for hunting.

In addition to my main use cases, I also use SentinelOne Singularity Endpoint for application management, inventory management, and identity management for all users, along with vulnerability recommendation and vulnerability development management.

What is most valuable?

SentinelOne Singularity Endpoint offers excellent features that include threat visibility, deep visibility, and threat hunting.

What stands out to me with SentinelOne Singularity Endpoint's threat visibility and threat hunting features is that deep visibility gives us a 360-degree angle view of cloud, endpoint, identity, and network data to assess any possible threat hunting or risky activities, which is a good feature.

SentinelOne Singularity Endpoint has positively impacted my organization with its Purple AI feature.

Purple AI has made a positive impact by saving time because it provides a summary glimpse of the incident, allowing me to get an overview of what happened, and then I can check the particular identity or asset, which helps in checking everything in the incident or particular device or organization.

SentinelOne Singularity Endpoint has helped me see the connections between different security events or alerts, and it integrates easily.

Singularity Endpoint has completed my security solutions; during the six pillars of zero trust architecture, I can implement all pillars—identity, application, endpoints, infrastructure, network, and cloud—through the Singularity platform.

Singularity Complete has helped reduce false positive alerts; by creating star rules or alert rules for valid files allowed in the network, we are getting fewer incidents from the beginning.

Singularity Endpoint has freed up my staff for other projects and tasks, saving us one to two days per week to focus on other things.

It has reduced the mean time to respond, MTTR, by shrinking the incident response and forensic science analysis cycles from hours to seconds.

What needs improvement?

SentinelOne Singularity Endpoint can be improved by implementing more XDR in the network connections and connectivity.

Regarding needed improvements, the device connectivity management feature is very good and is working effortlessly and connecting well, though if we could improve some Purple AI features such as providing direct results to queries, that would be a valuable enhancement.

For how long have I used the solution?

I have been using SentinelOne Singularity Endpoint for two years.

What do I think about the stability of the solution?

SentinelOne Singularity Endpoint is stable.

What do I think about the scalability of the solution?

Its scalability is impressive as it delivers horizontal scalability to a single agent and supports SaaS services, on-premises, and hybrid environments.

How are customer service and support?

Customer support is good, and the service is good.

Which solution did I use previously and why did I switch?

We previously used Microsoft Defender XDR, but we have SentinelOne Singularity Endpoint as a backup EDR solution.

How was the initial setup?

When we previously used Microsoft Defender XDR, the setup has been stable.

What was our ROI?

I do not have any metrics regarding return on investment, as I am part of the group and did not implement it.

What's my experience with pricing, setup cost, and licensing?

I am part of the group but do not have hands-on experience with the pricing, setup cost, and licensing.

Which other solutions did I evaluate?

Before choosing SentinelOne Singularity Endpoint, we did not evaluate any other options; one customer provided feedback indicating they use SentinelOne Singularity Endpoint, so we decided to go with it.

What other advice do I have?

My company acts as a service provider, MSSP, in our relationship with this vendor. I would rate this review a 9 overall.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Disclosure: My company has a business relationship with this vendor other than being a customer. MSP
Last updated: Jul 15, 2026
Flag as inappropriate
PeerSpot user
reviewer2842140 - PeerSpot reviewer
Security Engineer at a comms service provider with 11-50 employees
Real User
Top 10
May 28, 2026
Endpoint protection has reduced response times and now frees my team for deeper investigations
Pros and Cons
  • "My favorite feature about it is the full visibility into telemetry."
  • "It's easy to deploy, but the documentation about the Linux part could be better because it's a little complicated only on the Linux part, specifically on Ubuntu; it could be clearer and simpler."

What is our primary use case?

I use SentinelOne Singularity Endpoint as HDR, as the product is designed.

What is most valuable?

My favorite feature about it is the full visibility into telemetry.

SentinelOne Singularity Endpoint has helped reduce alerts, but false positives could be less.

It has helped me in my investigation to free up my staff for other projects.

I have seen a reduction in mean time to respond.

What needs improvement?

I think the visibility on Storyline could be better.

I could not comment on the Ranger functionality because I don't use it.

I have seen a reduction in mean time to respond and it has helped me in investigations to free up my staff for other projects.

I tried using the Purple AI feature.

I think it's great and it's working very well and has helped reduce the mean time to respond. The description is great; it's not too specific and not too much reduced. The long summary is excellent; it provides a great summary.

For how long have I used the solution?

I have been working with SentinelOne Singularity Endpoint for eight months.

What do I think about the stability of the solution?

The stability of SentinelOne Singularity Endpoint is great and I would rate it 10.

What do I think about the scalability of the solution?

SentinelOne Singularity Endpoint is very scalable and I would rate it 10.

How are customer service and support?

I have had to contact technical support and it worked well.

I think the quality of their support is 10 and the speed could be nine.

If I were to put together an overall score for the support, I would give them nine.

Which solution did I use previously and why did I switch?

I have used many products as alternatives to SentinelOne Singularity Endpoint.

How was the initial setup?

I am involved in the initial deployment and it's working great.

It's easy to deploy, but the documentation about the Linux part could be better because it's a little complicated only on the Linux part, specifically on Ubuntu; it could be clearer and simpler.

SentinelOne Singularity Endpoint requires a little bit of maintenance on the agent upgrade, so a feature to auto-deliver updates month by month would be great.

What about the implementation team?

SentinelOne Singularity Endpoint consolidated the environment.

What was our ROI?

I can give 30% as a number for the reduction.

Which other solutions did I evaluate?

The product closest in terms of quality and features to SentinelOne Singularity Endpoint is CrowdStrike.

I prefer CrowdStrike over SentinelOne Singularity Endpoint.

I prefer CrowdStrike because I could see a lot more information in the detection part and the false positives are reduced.

What other advice do I have?

Data privacy and security are very important for us when using Purple AI because we work with some Italian government companies or government-related companies, so privacy and European regulation are very important.

SentinelOne Singularity Endpoint consolidated the environment.

Endpoint protection solutions were consolidated now that I don't need them.

I would rate this review 9 overall.

Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
Last updated: May 28, 2026
Flag as inappropriate
PeerSpot user
Kandregula Sathvik - PeerSpot reviewer
Threat Engineer at Proficio
MSP
Top 5Leaderboard
Mar 18, 2026
Intelligent threat detection has reduced investigation time and improves real-time decisions
Pros and Cons
  • "Once it fully adapts to the environment, customers don't even need to monitor their endpoint protection landscape, as it can automatically learn and mitigate any threats or problems with minimal human interaction."
  • "Regarding the pricing, Singularity Platform is very high compared to other platforms that have been worked with, such as CrowdStrike and other Sophos EDRs."

What is our primary use case?

I mostly use Singularity Platform in incident response time, especially when there is a ransomware attack or when we want to recover any previous files. My other use case is when I have to investigate any files or EXE files that have been on the PC to deeply investigate what services they are using and what type of network connections they are establishing on the PC.

I use the Pro-detection feature in financial services, and it is a very good feature. There is no need to manage any complicated cases because the Pro-detection feature works by simply analyzing over time. It takes two to three days to investigate a specific issue thoroughly, and then it gives a conclusion based on that analysis, which helps determine the actions to take.

What is most valuable?

One of the likely features of Singularity Platform is that it is very user-friendly and easy to understand. The UI is indeed very user-friendly. Alerts and writing long queries are somewhat challenging. The predefined queries of SentinelOne can be very jargony to configure and hectic to write.

Singularity Platform's real-time personalization feature is a time-taking process and not a single setup process. It takes at least six to seven months to train the platform so it can be aware of the environment, after which there is some visibility over personalization setups.

The personalization feature has been good for customer experience strategies. People are very positive about that personalization feature because the machine learning offered by Singularity Platform is very good and easy to use. Once it fully adapts to the environment, customers don't even need to monitor their endpoint protection landscape, as it can automatically learn and mitigate any threats or problems with minimal human interaction.

Risk management efforts have improved significantly with Singularity Platform. Previously, a lot of time was spent investigating issues, but now this process has reduced investigation time from days to hours. The focus is on what type of recommendations and remediations to implement, which can be completed within an hour.

Singularity Platform's real-time monitoring capability has significantly improved decision-making. Previously, decision-making was more manual, but after integrating something called Purple AI, it doesn't hallucinate and provides accurate real-time decisions, pinpointing exact problems and suggesting what changes need to be made.

One of the main benefits from using Singularity Platform is that there are no over-alerts; there are very few false positives. Most triggers are by true positives, which helps manage alert fatigue effectively and allows focus on actual threats.

What needs improvement?

Singularity Platform could be improved by providing a more comprehensive analysis part, particularly on the threat dashboard. If automated analysis in simple terms could be received to explain to customers what exactly is happening, it would be a great addition to the product.

Regarding customizable dashboards, there are predefined dashboards that provide good visibility, but customized dashboards are not that helpful. I would not recommend using them as they can become messier.

My advice for organizations considering Singularity Platform is to encourage the addition of a threat analysis part that integrates with their Purple AI, allowing explanation of specific threats in a simpler way for customers.

For how long have I used the solution?

I have been using Singularity Platform for three years.

How are customer service and support?

Experience with customer service and technical support has been primarily with tech support because, during the initial configuration time, there were many doubts. Tech support was mostly used, while customer service has not needed to be contacted. Direct contacts for technical support were available.

On a scale of one to ten, the technical support of SentinelOne would be rated as an 8.5.

How would you rate customer service and support?

Positive

How was the initial setup?

The initial setup process for Singularity Platform is straightforward across all three platforms—Mac, Linux, and Windows—and doesn't require any prerequisites. It is a very lightweight agent, and the setup is easy to handle.

What was our ROI?

Singularity Platform does bring a good return on investment. First, proofs of concept are shown for the two EDRs, comparing what they offer. Large enterprises that can afford it often choose SentinelOne for its ease of management compared to other platforms.

What's my experience with pricing, setup cost, and licensing?

Regarding the pricing, Singularity Platform is very high compared to other platforms that have been worked with, such as CrowdStrike and other Sophos EDRs. While it offers very good features at the enterprise level, it comes at a premium price. Licensing includes various tiers like Pro and Singularity, and while highly customizable, it is indeed expensive.

Which other solutions did I evaluate?

In comparison to other products, a key difference in Singularity Platform is the ability to push customizable scripts, which other platforms offer in their tiers. If detailed analysis were received instead of just a graph, showing a step-by-step explanation of each threat or process would enhance the digital forensics perspective.

What other advice do I have?

From a features perspective, there are no missing functionalities in Singularity Platform; the features are quite good for now. The overall review rating for Singularity Platform is 8.

Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor. The reviewer's company has a business relationship with this vendor other than being a customer: Integrator
Last updated: Mar 18, 2026
Flag as inappropriate
PeerSpot user
reviewer2848893 - PeerSpot reviewer
Head of Security at a consultancy with 51-200 employees
Real User
Top 5
Jul 15, 2026
Behavioral detection has transformed endpoint investigations and now improves incident response
Pros and Cons
  • "SentinelOne Singularity Endpoint has positively impacted my organization by being one of the primary tools keeping us secure against modern security issues, with faster threat detection and investigation through better endpoint visibility which has greatly helped our team, resulting in improved incident response and reduced reliance on manual monitoring."
  • "SentinelOne Singularity Endpoint would benefit from broader security ecosystem integration, including deeper native integrations across identity access and other security domains, which would make it more competitive with larger security platforms."

What is our primary use case?

My main use case for SentinelOne Singularity Endpoint is primarily for endpoint detection and response, EDR, focusing on endpoint protection.

SentinelOne Singularity Endpoint is being used for behavioral threat detection, malware and ransomware protection, security investigations, response activities, and also to isolate endpoints where required.

How has it helped my organization?

SentinelOne Singularity Endpoint has positively impacted my organization by being one of the primary tools keeping us secure against modern security issues, with faster threat detection and investigation through better endpoint visibility which has greatly helped our team, resulting in improved incident response and reduced reliance on manual monitoring.

Regarding metrics on how it has improved incident response, I do not have any specific data to share.

What is most valuable?

The best features SentinelOne Singularity Endpoint offers include behavior-based detection, which can identify suspicious activity based on behavior patterns and has very few false positives, as well as autonomous prevention and response, where the agent can automatically block malicious activity. It also has strong investigation capabilities, and the process traceability along with endpoint activity context makes it very easy to understand what happened during an alert, and it includes ransomware protection and rollback capabilities, along with very low operational overhead.

From all the features I mentioned, I find myself relying most on behavior-based detection with endpoint investigation visibility because it allows our security team to quickly understand suspicious activity beyond simple malware alerts, helping analysts validate incidents faster and make better decisions.

What needs improvement?

SentinelOne Singularity Endpoint would benefit from broader security ecosystem integration, including deeper native integrations across identity access and other security domains, which would make it more competitive with larger security platforms.

I chose nine out of ten because I usually do not give out tens to be honest, but it is mainly due to areas outside its core endpoint security, as while it is very strong in EDR, there is still room for improvement around broader security platform capabilities and deeper cloud-native security coverage.

For how long have I used the solution?

I have been using SentinelOne Singularity Endpoint for more than a year.

What do I think about the stability of the solution?

SentinelOne Singularity Endpoint is stable.

What do I think about the scalability of the solution?

I am happy with the scalability of SentinelOne Singularity Endpoint.

How are customer service and support?

We pay for premium support for SentinelOne Singularity Endpoint, which is good, but they are charging us money.

Which solution did I use previously and why did I switch?

SentinelOne was already in this environment, so I did not previously use a different solution.

What was our ROI?

I have seen a return on investment, which is primarily on the improved SOC efficiency and reduced manual effort, along with the time saved during investigations and faster response actions. For example, a capability such as endpoint isolation helped reduce the time required to contain a suspicious activity, but I do not have numbers to present.

What's my experience with pricing, setup cost, and licensing?

I was involved in the decision-making regarding my experience with pricing, setup cost, and licensing.

Which other solutions did I evaluate?

Before choosing SentinelOne Singularity Endpoint, I did not evaluate other options, as we acquired it from an acquisition.

What other advice do I have?

Singularity Complete has not significantly consolidated our security solutions, as we are primarily relying on this for EDR.

To some extent, Singularity Complete has helped reduce alerts, with the main improvement being the platform's ability to automatically identify and prevent certain behaviors, but I do not have a number.

To some extent, Singularity Complete has helped free up my staff for other projects and tasks, primarily with its autonomous prevention capabilities, allowing analysts to spend less time collecting information manually and more time focusing on higher-value security activities.

It has definitely helped reduce my organization's mean time to detect, MTTD, but we have not measured the specific reduction percentage.

Mean time to response, MTTR, is primarily handled by humans.

The pricing for SentinelOne Singularity Endpoint is good compared to other industry vendors, and organizations should definitely focus on proper policy tuning and make use of the behavioral capabilities. I would rate this product nine out of ten overall.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
Last updated: Jul 15, 2026
Flag as inappropriate
PeerSpot user
Olive Kusumbara - PeerSpot reviewer
Consultant at a tech services company with 1,001-5,000 employees
MSP
Top 5
Nov 4, 2025
Has improved threat detection and streamlined integrations through strong XDR and forensic capabilities
Pros and Cons
  • "I've seen a lot of improvements and simplifications, and Google SecOps has recently moved into Gartner's as the highest one for visionaries."
  • "A weakness seen with one large customer was that the detections were too intrusive, blocking many applications that should have been working, which led to many false positives."

What is our primary use case?

I'm only dealing with Google SecOps right now, not other Google Cloud products. On a limited scale, I think we use Microsoft Defender for one particular customer; for the others, we are using SentinelOne Singularity Complete and Palo Alto Cortex.

What is most valuable?

I've seen a lot of improvements and simplifications, and Google SecOps has recently moved into Gartner's as the highest one for visionaries. The AI, agentic AI, integration with SOARs, and simplified SKUs and pricing are noteworthy. Most customers who have various platforms for cybersecurity do not choose Azure Defender unless they are on a Microsoft stack right now. SentinelOne Singularity Complete is the most capable in terms of detection and response, and I use it quite extensively for forensic capabilities.

SentinelOne Singularity Complete can be quite intrusive, but it has strong detection capabilities. The Ranger functionality of SentinelOne Singularity Complete for the EDR is extensively used for customers. Microsoft Defender has recently upgraded to XDR capabilities.

What needs improvement?

For Azure Sentinel, the main issue that needs improvement is the pricing; it's quite unpredictable right now in terms of cost. The use of many components within Azure itself is confusing, especially with the recent move in terms of the console from Azure Sentinel to the Defenders. The highlight is more into the pricing; it is too expensive and unpredictable right now.

For Google SecOps, the only improvement I suggest is in terms of the reporting, especially for out-of-the-box reporting that seems very lacking right now. There aren't too many useful reports coming from out-of-the-box; we have to develop them ourselves right now.

SentinelOne Singularity Complete needs to work more on increasing true positive detections to make it closer to 10. A weakness seen with one large customer was that the detections were too intrusive, blocking many applications that should have been working, which led to many false positives.

How are customer service and support?

I think technical support is quite good; we have been in contact quite occasionally, and they provide expected answers.

How would you rate customer service and support?

Positive

How was the initial setup?

I find the initial setup quite straightforward for SentinelOne Singularity Complete.

Which other solutions did I evaluate?

SentinelOne Singularity Complete can be quite intrusive; that's one of the drawbacks. It's also the first thing that we recommend right now. We prefer to use other EDR platforms such as SentinelOne Singularity Complete and Palo Alto Cortex right now.

What other advice do I have?

I'm using Google SecOps. If you want, I can leave my opinion on Google SecOps.

While the others will be on the cyber threat intelligence, the primary is Google SecOps, and I think the other one is Azure Sentinel.

There is room for improvement for these solutions. It's mostly SIEM and MDR for SentinelOne Singularity Complete. I haven't used Vigilance MDR; I only know the name.

We mainly focus on SentinelOne Singularity Complete and Cortex, while the other EDRs that we have managed are less significant. It's almost similar since both SentinelOne Singularity Complete and Cortex have EDR and XDR capabilities.

In terms of non-locked XDR platforms, the best one is SentinelOne Singularity Complete right now for their XDR capabilities. Other ones such as Palo Alto Cortex or even CrowdStrike are locked into their own ecosystem right now since they have many products within that ecosystem. In terms of integration, even though it looks quite open, some are tightly coupled into their own ecosystem, especially for Palo Alto Cortex.

We haven't had that in-depth experience in terms of ingesting and correlating for SentinelOne Singularity Complete; we mainly use it right now for their EDR capabilities. Since we provide the MDR services, we mainly integrate those with Google SecOps right now for the overall SOC services. I think they are the most capable in terms of detection and response.

We only tried Purple AI but haven't used it quite extensively. I find the pricing very reasonable, especially right now compared to other top-tier EDR platforms at the same level. I usually recommend the product for both smaller and bigger organizations. My overall rating for this review is 9.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
PeerSpot user
Buyer's Guide
Download our free SentinelOne Singularity Endpoint Report and get advice and tips from experienced pros sharing their opinions.
Updated: September 2026
Buyer's Guide
Download our free SentinelOne Singularity Endpoint Report and get advice and tips from experienced pros sharing their opinions.