No more typing reviews! Try our Samantha, our new voice AI agent.
reviewer2646066 - PeerSpot reviewer
Information Security Officer at a tech vendor with 51-200 employees
Real User
Top 5
Nov 17, 2025
Automated workflows and real-time monitoring have improved operational control and customized data insights
Pros and Cons
  • "Singularity Platform's real-time personalization feature has helped our customer experience strategies by allowing us to have different workspaces where we have custom views, and depending on the use case because we have many products that use Singularity Platform, they interact with the UI in different ways, producing different elements and giving us tailored views for different products."
  • "Sometimes, these customized solutions our developers develop also get flagged in real time, and the processes get stopped and are blocked, and we have to whitelist the processes."

What is our primary use case?

As a company, we are using Singularity Platform to manage the data on the platform.

We use Singularity Platform as a unified view where we can see all the data from our applications in one place. It manages everything into one place and we have automations, so we can perform certain actions and we have rules in there where if we want to perform these actions, they can happen automatically via the Playbook functionality.

The impact of Singularity Platform on our supply chain processes streamlines it quite well. It helps in the processes. It is basically integrated into our pipeline and it helps us to push product more quickly and more securely.

Singularity Platform's real-time personalization feature has helped our customer experience strategies by allowing us to have different workspaces where we have custom views, and depending on the use case because we have many products that use Singularity Platform, they interact with the UI in different ways, producing different elements and giving us tailored views for different products.

Customizable dashboards have helped optimize operational efficiency for us because we have different products and different UIs for different products, allowing us to focus on the things that matter for different occasions. Since we are working with multiple data sources and multiple products, we needed customized solutions to really pay attention to the things that matter. These customized dashboards make it faster to work with certain products. It is easier to identify what is wrong with the product or where we need more resources.

Since starting to work with Singularity Platform, I have seen really good integration and control from the platform itself. You can perform many actions remotely through the agent, which helps with the administrative work of checking the versions of the software on the computer and what software and services are running. This really helps us collect this information on an organization-wide level.

What is most valuable?

I think the ability to automate actions and workflows is the best solution out of Singularity Platform. Other solutions are quite static in this case. You cannot really set up steps and gather information, certain pieces of information, filter them out, and based on that data, perform actions. However, Singularity Platform makes it very simple.

Singularity Platform's real-time monitoring capability has indeed helped me in decision making, as it is one of the best features of the platform. It is working really well, and while the software could seem a little bit invasive because it is working on a kernel level, it really detects a lot of things, perhaps too many things. Sometimes, these customized solutions our developers develop also get flagged in real time, and the processes get stopped and are blocked, and we have to whitelist the processes. However, for enhanced security, we definitely want this.

What needs improvement?

I think some parts of Singularity Platform could be improved or enhanced, as you most likely need to know the platform quite well to write queries and search for information. There are a few too many similar fields, such as the storyline ID and the storyline, which sometimes gets confusing. Perhaps the distinguishing could be better, but correlation in general is done very well with the storyline because it is the platform's own field for correlating data.

For how long have I used the solution?

We have been using the solution for two and a half years.

Buyer's Guide
SentinelOne Singularity Endpoint
August 2026
Learn what your peers think about SentinelOne Singularity Endpoint. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
910,454 professionals have used our research since 2012.

What do I think about the stability of the solution?

I have noticed only a few occasions where the features, particularly the search feature, are not working with Singularity Platform. The automations, however, are working. I did not notice that they announced maintenance in advance, so it was more that I was not prepared and did not read about planned maintenance. Other than that, everything else is good and stable, apart from short windows of four to eight hours of maintenance they do every month.

If I have to rate the stability level of Singularity Platform from one to ten, I would say it would be a strong nine.

What do I think about the scalability of the solution?

I have not run into any issues regarding how scalable Singularity Platform is, so I do not see any limitations for scalability. It is probably doing very well in that regard.

It is important to have the scalability that we have with Singularity Platform because we are always expanding and onboarding new computers. Definitely, new employees come in, and it takes a small amount of time, probably twenty minutes to set up new workers.

How are customer service and support?

My experience with the technical support of Singularity Platform is that they write us back semi-quickly. If I were to rate it out of ten, I would say they are quite helpful, perhaps an eight.

Which solution did I use previously and why did I switch?

Before using Singularity Platform, I was not aware of any different solution for the same use cases. When I came to the company, we moved relatively recently to Singularity Platform. We were basically fully migrated from SentinelOne.

How was the initial setup?

The process of onboarding new data points to Singularity Platform is quite easy to ingest. It is really simple to add new computers to the network; you just have one command to install the agent on the computer, and it automatically appears on the platform with data coming in. It is quite easy in terms of integration and expanding the existing network. Setting up the automation rules is not so easy initially, but once you know how to set up one rule, it becomes much easier to set up more advanced actions and automatic removals of certain software or scanning.

Which other solutions did I evaluate?

Before choosing Singularity Platform, we were evaluating other options, and we were using Microsoft side by side. Microsoft Sentinel was quite all right, but SentinelOne had more searching capabilities and threat hunting and more automation built in.

What other advice do I have?

Regarding Singularity Platform, I would go for the platform. I am most familiar with that one.

I do not currently know what version of Singularity Platform I am using. I will have to check. Probably I am using the latest version because we have automatic updates.

We are not using the fraud detection feature in financial services, as we are not doing any financial services.

Regarding Singularity Platform's real-time personalization feature, we are using it.

Overall, if I had to rate Singularity Platform from one to ten, I think an eight would be appropriate. It is quite up to our standards. I would rate this review an eight overall.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Director, Information Technology at a tech services company with 11-50 employees
Real User
Top 10
Oct 30, 2024
Top-notch support, well-designed console, and is less expensive than others
Pros and Cons
  • "The console is light years better than the CrowdStrike console, which had just a bunch of different screens cobbled together. It is much more unified and much easier to work with. It is very nicely designed."
  • "The false alerts can be annoying, especially during administrative tasks."

What is our primary use case?

We use SentinelOne Singularity Complete for all of our endpoints, including virtual machines, physical servers, and laptops.

How has it helped my organization?

The solution gives us a good sense that the systems are secured against malware, drive-by fileless attacks, and advanced behavioral attacks. This is our primary reason for having the product, and it does a good job in that regard.

It does not require a lot of management. It is hard to quantify the time savings but it does not require a lot of our time. If I spend an hour a week on it, that is a lot.

It is hard to quantify the reduction in the mean time to detect unless you are a pretty big organization and you are tracking that. However, it has been able to detect things and alert about them pretty much instantly in the console. We also get emails right after that. In terms of the Vigilance MDR service, one Saturday morning, I tripped an alert for something I was doing. I thought of waiting and seeing how long it would take on a Saturday morning at 10 AM for them to jump in and figure it out. They took about 20 minutes.

Any good endpoint security product should reduce your organizational risks, and SentinelOne Singularity Complete has done that. It is almost impossible to quantify the reduction.

We were able to easily realize its benefits within 30 days.

What is most valuable?

The console is light years better than the CrowdStrike console, which had just a bunch of different screens cobbled together. It is much more unified and much easier to work with. It is very nicely designed. It is one of the better user interfaces I have ever seen for web application management. 

The product is pretty easy to manage and pretty easy to deploy. It also has a pretty low resource footprint.

What needs improvement?

The false alerts can be annoying, especially during administrative tasks. We have had a number of occasions where the software impacted a third-party application, so the application would either not run or exhibit other technical issues. We were also not getting any alerts in the console to indicate that SentinelOne was having a negative interaction with the product. Finally, after hours of troubleshooting, we turned off the endpoint security for the product, and the application just started working fine. We have probably had a good half dozen of those. It is quite annoying.

For how long have I used the solution?

I have had experience with SentinelOne Singularity Complete for two years.

How are customer service and support?

Their support is top-notch. I have been in the business for thirty years, and I have dealt with just about every support company out there. I am used to mediocre enterprise support, but SentinelOne's support is very good, deserving a ten out of ten.

How would you rate customer service and support?

Positive

Which solution did I use previously and why did I switch?

We were running CrowdStrike prior to SentinelOne. We were using CrowdStrike Complete, but it was simply way too expensive to sustain for our budget. We were looking for something that was equally capable and did not have a huge price tag with it, so we ended up going with SentinelOne and their Vigilance MDR service.

SentinelOne Singularity Complete has not helped us consolidate other solutions. It was a one-for-one replacement for CrowdStrike. It has not helped us to get rid of anything at this point.

I have used Bitdefender in the past. We had their GravityZone Ultra, which had XDR Complete, but there were so many alerts. We would literally spend hours. We would pick a day a week or a day every couple of weeks and try to trace down alerts and clear out the console. From that perspective, SentinelOne does give off fewer false positives. However, when we are dealing with administrator or network administrator or developer tools, for obvious reasons, they tend to trip the alerts on the product. For normal end-user work, there are seldom any false positives or alerts that are not valid. It is almost never. I am the IT director, and it is always tripping on things I am doing. When I install some encryption software or disk wipe software, I get many alerts in SentinelOne, but for the actual end-users, typically, we do not get any false positives.

How was the initial setup?

We use their public cloud. We deploy the agents ourselves. We do the updates through their public cloud, but we do the initial deployment ourselves.

The initial setup was pretty straightforward. There are some nuances to the product, naturally. It is an enterprise-class endpoint security product, so there are things that you need to learn and understand about how it works. The same is true of CrowdStrike, Palo Alto Cortex, or any other product in the same category.

We have multiple locations with about 35 remote users.

What about the implementation team?

We used their onboarding service, which was very helpful because we would have meetings every week or two with the actual SentinelOne employee engineer to talk about our deployment and ask questions about particular features and best practices. It was worth the extra expense.

I had one other network administrator working on it with me, and I just assigned him the task of deploying software and working with me on some of the policy configurations.

I do most of the maintenance on it. The maintenance typically requires adding an exclusion here or there, troubleshooting an issue, or uploading logs for support to look at an issue or a question that we have. I do not spend 50 hours a year on it.

What's my experience with pricing, setup cost, and licensing?

SentinelOne is significantly less expensive than CrowdStrike. I recently did a price comparison between CrowdStrike and SentinelOne to determine where we are going for the next three years. CrowdStrike is 200% to 300% the cost.

For their complete service, we were paying CrowdStrike 45K for 85 endpoints for a year. We have stepped down, and we are doing MDR and not having SentinelOne manage our policies and things. We have 200 endpoints, and our yearly cost is 17K, so we have gone from 45K to 17K. From a detection standpoint, depending upon which MITRE framework tests you look at, both vendors jockey up and down in the top ten. They are pretty comparable from a performance and efficacy standpoint, so there is not a 200% to 300% gap there.

Which other solutions did I evaluate?

I always do a round-robin. My final three ended up being Palo Alto Network's Cortex product and CrowdStrike's Falcon product, the lesser version of their MDR Overwatch product.

The thing that I did not like about Overwatch was that they would tell you that something was going on and here is what you should do, but they would not help you with it. SentinelOne was a little bit more helpful in terms of hopping in. Ultimately, Palo Alto is not support-friendly. I use Palo Alto Firewalls, and their support is not that great. It has not been for a while, so I hesitate to go into their endpoint security as well. It is also expensive. It requires a lot more infrastructure and cost to deploy. It is probably more akin to CrowdStrike from a cost perspective.

I briefly considered Bitdefender's MDR solution using GravityZone where they did the MDR piece of it. It was probably half or a third of what we would have spent for SentinelOne, but I did not have the sense that it was quite the next-gen product that I was looking for, even though it scored pretty well.

All these are very similar because they base their activity on what a piece of software is trying to do on the system. It is a real-time behavioral analysis. They do not use predefined signatures from the last 25 years. They are trying to do things in real time. In terms of how long it takes to have visibility into what an application is doing and how quickly they can lock it down once they have the visibility, each vendor scores differently, but each of these three would generally be considered in anybody's top five.

SentinelOne is fairly innovative. I like what they are doing with the integration of their Purple AI for being able to do real-language queries of their telemetry data. You do not need to know all the correct syntax, which helps us non-SecOps folks who have to dabble in it periodically. We can do real-world queries. I have not asked for pricing on that. It is probably more than I want to pay for it, given that we do not get too much use out of this kind of feature, but they are continuing to innovate in that regard. From that perspective, it is a good product.

What other advice do I have?

SentinelOne Singularity Complete is very mature at this point.

We have not yet had an occasion to integrate it, although, in a couple of weeks, we are going to be integrating their Cloud Funnel service with another MDR provider, Red Canary. We have not done that yet, and we have not made use of their other interoperability pieces.

They have two Ranger products. One is the Ranger Identity Protection product, which is kind of an add-on product, and the other one is more of a rogue detection product. We did subscribe to the Ranger Identity Protection product, but it was so difficult to work with that we finally stopped using it. It was a subscription.

Our correlation is whatever is going on in the endpoints. We are not pulling in Palo Alto firewall telemetry, or Okta or O365 data at this point, but we are moving in that direction. We are simply using it for endpoint security and for their Vigilance MDR service.

SentinelOne is good as a strategic partner. We are in the third year of our three-year contract and plan to continue with them. We are not going to go directly to them. We are going to go through one of their partners, Red Canary, but we will be using the SentinelOne Complete product and then using Red Canary to do the MDR along with active remediation and SIEM ingestion of our Okta data, our Palo Alto firewall data, and our O365 data. They can then begin to cross-correlate events and attacks across different attack surfaces of ours.

I would rate SentinelOne Singularity Complete a nine out of ten.

Which deployment model are you using for this solution?

Public Cloud

If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

Other
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
PeerSpot user
Buyer's Guide
SentinelOne Singularity Endpoint
August 2026
Learn what your peers think about SentinelOne Singularity Endpoint. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
910,454 professionals have used our research since 2012.
Tanuja Parab - PeerSpot reviewer
Dark L2 Web Analyst at a tech services company with 11-50 employees
Real User
Top 5Leaderboard
Jul 21, 2026
Behavioral detection has transformed incident response and now speeds up endpoint threat containment
Pros and Cons
  • "SentinelOne Singularity Endpoint has positively impacted my organization by improving endpoint security through faster threat detection, providing better visibility and quicker incident response features including AI, automation, endpoint isolation, and effectively containing threats while reducing the workload for the SOC team."

    What is our primary use case?

    The main purpose of using SentinelOne Singularity Endpoint in my day-to-day work is for monitoring endpoint alerts, investigating any suspicious activity, analyzing behavior, and detecting potential threats. For example, SentinelOne detects suspicious PowerShell execution or potential ransomware behavior, and I review the alert, investigate the process tree, check affected endpoints, and if necessary, isolate endpoints and remediate threats, with our primary use case being protection on the EDR.

    In my day-to-day work, I primarily use SentinelOne Singularity Endpoint to investigate suspicious activity and support incident response by reviewing behavior detection, analyzing the process tree, and identifying the root cause of alerts while taking appropriate actions such as isolating compromised endpoints or initiating remediations whenever necessary. Overall, this helps us quickly detect, investigate, and contain endpoint threats and improve our overall security posture.

    What is most valuable?

    My favorite feature of SentinelOne Singularity Endpoint is the behavioral AI detection because it identifies suspicious activity or malicious PowerShell execution, even when malware has not been seen before, helping us respond to threats much faster.

    One example of how behavioral AI detection in SentinelOne Singularity Endpoint has helped us in real scenarios is when we detected PowerShell activity on an endpoint. Instead of relying on known malware signatures, it identified abnormal behavior, allowing us to investigate the process tree, confirm the suspicious activity, isolate the endpoint, and prevent the spread, enabling containment of the incident quickly before it impacted other systems.

    The behavioral AI in SentinelOne Singularity Endpoint helped us identify suspicious activity and is a feature I truly appreciate, as it aids in our investigations promptly alongside our SOC team.

    SentinelOne Singularity Endpoint has positively impacted my organization by improving endpoint security through faster threat detection, providing better visibility and quicker incident response features including AI, automation, endpoint isolation, and effectively containing threats while reducing the workload for the SOC team.

    I do not have exact metrics to share, but I have definitely seen a reduction in the manual effort of our SOC team. For instance, whenever SentinelOne detects suspicious behavior, it automatically correlates related processes and provides a complete process tree, saving analysts' time because we do not have to manually piece together events. Features including automation remediation and endpoint isolation also help contain threats quickly and decrease required manual intervention.

    What needs improvement?

    I am satisfied with SentinelOne Singularity Endpoint overall, but if it could be improved, it would be in providing more customizable reporting, a richer dashboard, and broader integration with third-party tools. Other than that, I find it effective and reliable with no major suggestions for improvement.

    Based on my experience with SentinelOne Singularity Endpoint, I have not encountered any major issues that significantly affect our day-to-day operations. The platform has been stable, and while every product continues to evolve with new features and integrations, I do not have additional improvements to suggest at this time.

    For how long have I used the solution?

    I have been using SentinelOne Singularity Endpoint for approximately two years, mainly for monitoring endpoint alerts, investigation, detection, and supporting incident response.

    What do I think about the stability of the solution?

    SentinelOne Singularity Endpoint is stable.

    What do I think about the scalability of the solution?

    I would rate its scalability a nine.

    How are customer service and support?

    I would rate the customer support a ten because it helps us greatly and has been very good for us. I would rate my experience with SentinelOne Singularity Endpoint's customer support a ten.

    How was the initial setup?

    Asset visibility is something we never see, but having asset visibility including expiry notifications provides us valuable visual information. Overall, my experience with pricing, setup cost, and licensing is good, although I am not the right person to comment extensively on pricing.

    What was our ROI?

    I see a return on investment, and while I cannot share specific metrics, it is evident in the improvements we have experienced.

    What other advice do I have?

    I advise others looking into using SentinelOne Singularity Endpoint to use this tool because it provides a comprehensive solution. It is very effective and if your organization does not require too many personnel, it is one of the best tools for you. I do not have any additional thoughts about SentinelOne Singularity Endpoint other than that it is a very good tool that provides us with a feasible and wonderful solution. I give this review a rating of nine.

    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    Last updated: Jul 21, 2026
    Flag as inappropriate
    PeerSpot user
    reviewer2799597 - PeerSpot reviewer
    Soc Analyst at a tech consulting company with 11-50 employees
    Real User
    Top 5Leaderboard
    Mar 30, 2026
    Unified security platform has enabled real-time threat detection and streamlined investigations
    Pros and Cons
    • "The best feature of Singularity Platform is that everything is unified in one platform, which would be a main unique selling point for them."
    • "For improvement, I would say the infrastructure is very slow; the application I use is sluggish, potentially due to workload or problems on my company's side."

    What is our primary use case?

    I use Singularity Platform as a SIEM across many infrastructures, including cloud and on-premises environments, to detect attacks on endpoints, cloud workloads, identities such as Active Directory, and network signals.

    Singularity Platform is used to detect, investigate, and respond to threats all in one platform, which is why it is called Singularity Platform, because it has EDR, XDR, and cloud security all unified in one system.

    I use fraud detection while working with financial companies and many fintech companies. Although SentinelOne is not known for fraud detection, it does detect stolen credentials, accounts that have been misused, or privilege abuse. I use it to a certain extent, but I cannot provide a deep-dive analysis on it today as I am fatigued from working through the night.

    In my organization, I have around ten clients, of which six use SentinelOne as a SIEM, mainly financial companies, with one being a shopping-based company. I cannot provide all client details, but that is the general overview.

    What is most valuable?

    The best feature of Singularity Platform is that everything is unified in one platform, which would be a main unique selling point for them. The unique feature is Next-Gen AV plus EDR, which detects and blocks threats in real-time.

    There is a rollback feature that rolls back to the previous state if anything goes wrong after a new feature is installed or a ransomware attack occurs. Singularity XDR extends visibility beyond the endpoints and correlates how the endpoint, cloud, identity, and network help me to see a full attack chain.

    The real-time personalization feature allows for customizing the detection rules and adapting security decisions based on who is doing what and where. It tracks users with behavior-based personalization, detecting abnormalities such as a non-admin gaining admin access. It also detects credential theft by correlating identity plus endpoint data for better context.

    For policy personalization in my SOC, I group devices based on alert names, agent versions, or OS types, which helps significantly. I can personalize based on alert severity and true positives or false positives, leading to automated responses. A unique feature in Singularity Platform is StoryLine technology, which connects incidents into a full storyline attack.

    It explains the attack pattern in a way that follows commands executed after an incident, and I can write workflows using AI, working even offline, mainly with agent-based decisions without constant cloud dependency.

    I have customized dashboards for my companies, including an overview dashboard showing alerts from endpoints. I created a unified dashboard with a network and an endpoint dashboard, consolidating SOC-related unassigned alerts and daily solved alerts. I customized that dashboard myself, and it is very easy to do, being a UI-based feature.

    Real-time monitoring is very helpful, helping me stay one step ahead in cybersecurity. It allows me to see exactly what is happening at this moment, and knowing about an attack immediately is better than knowing an hour or two later. The sooner I know, the better it is for me. Real-time monitoring helps me significantly as a SOC analyst, making it one of the best features. After an alert, analyzing what happens next is just two to three clicks away, needing only to input the timeline, the query, and the affected user or endpoint.

    What needs improvement?

    For improvement, I would say the infrastructure is very slow; the application I use is sluggish, potentially due to workload or problems on my company's side.

    Although they have fantastic features, if it is not working properly, it hinders performance. Recently, during maintenance, it was still operational but sluggish, with features not working as efficiently.

    Grouping alerts previously worked fine but now requires multiple clicks to achieve the same result, which is problematic. They could improve the UI and focus more on creating new rules from their MDR team.

    Although they are working on automation, they could advance automatic remediation capabilities further than they are currently.

    For how long have I used the solution?

    I have been using Singularity Platform for the last six months.

    What do I think about the stability of the solution?

    I would give stability a seven, as it usually crashes, requiring me to log in repeatedly.

    What do I think about the scalability of the solution?

    Singularity Platform is very scalable but requires planning; it is not as easy as Orca Security or agentless platforms because it has agents. I would still give scalability a seven.

    How are customer service and support?

    I would rate technical support as an eight.

    Which other solutions did I evaluate?

    Comparing Singularity Platform with other vendors, I find others also have fantastic features, but SentinelOne has unique offerings like the StoryLine feature, Purple AI, and a unified platform where endpoints, cloud security, and assets come together. This gives them a great advantage. Although there are better security tools in the market, considering the money I spend, SentinelOne is much more cost-efficient than other products. For example, Microsoft Sentinel is much too costly for my company, and although CrowdStrike provides top-notch service, SentinelOne is still doing well to keep up with market needs, though there is room for improvement.

    What other advice do I have?

    Singularity Platform requires maintenance, which is typically done on weekends. Although there was a maintenance window recently, it is almost acceptable, but technical issues can cause lag or latency, which is common in upgrades. They can improve by utilizing a backup or other measures.

    I recommend Singularity Platform because of features such as the StoryLine model, Purple AI, and automating workflows with hyper-automation capabilities. I would hesitate to recommend it solely due to reliability issues.

    Which deployment model are you using for this solution?

    Hybrid Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Other
    Disclosure: My company has a business relationship with this vendor other than being a customer. partner
    Last updated: Mar 30, 2026
    Flag as inappropriate
    PeerSpot user
    reviewer2218470 - PeerSpot reviewer
    Co-Founder & VP Sales and Marketing at a tech services company with 11-50 employees
    Reseller
    Top 5
    Sep 30, 2025
    Significantly reduces risks and streamlines our monitoring
    Pros and Cons
    • "Singularity Platform allows us to have one single view of potential threats and the health of our environment, helping us optimize operational efficiency."
    • "The dashboards can be improved, and their dashboarding functionality needs to be better. The way the dashboards look is not really impactful or meaningful."

    What is our primary use case?

    We protect our endpoints and servers, workstations, and we use Singularity Platform to ingest third-party data for alerts or detections. 

    We work in the cybersecurity industry, so we use Singularity Platform and implement it for our customers.

    How has it helped my organization?

    Singularity Platform basically keeps us protected. We utilize it across various sectors, including financial services, insurance, retail, and manufacturing. It has significantly reduced some of the risks associated with the current threats we face, both at the endpoint level and in terms of identity protection.

    Singularity Platform allows us to have one single view of potential threats and the health of our environment, helping us optimize operational efficiency. 

    Singularity Platform is allowing us to detect threats early on and make sure that they don't proliferate in our environment if there are any.

    What is most valuable?

    The best features of this product include its ability to detect malicious software and malware, and the functionality itself is exceptional. The console is easy to navigate. 

    What needs improvement?

    The dashboards can be improved, and their dashboarding functionality needs to be better. The way the dashboards look is not really impactful or meaningful.

    For how long have I used the solution?

    I have three years of experience with SentinelOne.

    What do I think about the stability of the solution?

    Singularity Platform is stable; so far, so good.

    What do I think about the scalability of the solution?

    It works. It's not designed for scalability, it's designed to protect the enterprise.

    How are customer service and support?

    I would evaluate their customer service and technical support as very good, five stars.

    How would you rate customer service and support?

    Positive

    Which solution did I use previously and why did I switch?

    Before, we were using Kaspersky, but then the Russians came in, and we had to stop using it. It's a Russian product, and with everything happening with that, we stopped using it.

    How was the initial setup?

    The initial setup of Singularity Platform was straightforward. We have a team member here who handles it.

    What about the implementation team?

    One person, a really good techie, handled the deployment.

    What was our ROI?

    I don't really see a return on investment; it's a necessary requirement today to protect the enterprise.

    What's my experience with pricing, setup cost, and licensing?

    The pricing for Singularity Platform is good, and the setup cost is very minimal.

    Which other solutions did I evaluate?

    We evaluated CrowdStrike, Microsoft Defender, and Trend Micro before choosing Singularity Platform. The main differences between Singularity Platform and some of these others include threat detection ability, lower cost, and that was the key factor in our decision-making.

    What other advice do I have?

    I would rate Singularity Platform a nine out of ten.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
    PeerSpot user
    Zack Moody - PeerSpot reviewer
    Domestic Security Alliance Council (DSAC) at KYOCERA AVX Components s.r.o.
    Video Review
    Real User
    Top 5
    Oct 30, 2024
    Consolidation of eight different antiviruses into one platform saved us costs, time, and human resources
    Pros and Cons
    • "When we first looked at SentinelOne, we had a very distributed legacy antivirus environment. Through SentinelOne's platform, we were able to consolidate about eight different antiviruses globally, thus saving money and time."
    • "There are things that they can do to improve the console or improve the product, and they are making strides in it."

    What is our primary use case?

    We use SentinelOne's EDR platform. We use Ranger for network discovery. It helps to find out any endpoints that do not have an agent or rogue devices that may come up on the network that are not protected. It allows us to isolate them until we have the proper protections in place.

    We are starting to delve into Identity.

    How has it helped my organization?

    The EDR platform has helped us achieve our business goals by providing the best security against ransomware, which is the number one threat to our business.

    We have seen a lot of benefits since we deployed SentinelOne many years ago. We were able to consolidate around eight different antiviruses globally. It saved us licensing costs, human capital, and the amount of time it takes to keep up with some of the legacy technologies.

    Other than that, the product gives us so much visibility to things. We did not have that visibility before. It also gave us access to every endpoint globally from a single platform. My engineers and my SOC operators are able to touch every endpoint globally in a matter of seconds. We are able to consolidate all the data that we are getting from the platform. We then build rule sets and protections and automate playbooks to be able to help save time so that we can focus on some of the bigger threats that we have.

    SentinelOne has had a huge impact on our risk management posture. In my viewpoint, any threats, especially with ransomware being the biggest threat to our business, can lead to downtime for operations. If manufacturers are not making the product, we are not making money.

    SentinelOne has helped us improve our analyst efficiency because of the simple fact that it is a single singular platform where they have access to every endpoint data that is out there in the world in our scope of devices. It gives them the ability at their fingertips to dive deep into the telemetry data that they need to make a justification or make a decision about a threat.

    SentinelOne helps us reduce noise. We also leverage SentinelOne Vigilance as a managed service provider, which takes away the load from my analysts. It enables us to develop playbooks to cut down the noise and helps us to prioritize what matters the most, which makes us way more efficient. It makes us speedier when it comes to the time to react to a threat.

    SentinelOne, especially the Vigilance team, helps us to reduce false positives. It is not only because the technology itself is so good at what it does; it is also because of the information that we get related to a threat or an alert. The information is enough for us to have some sort of disposition on what that is. We can then write a rule or mute that through a click of a button so that it is not constantly coming to the surface.

    SentinelOne helps us with our incident response process tenfold. We have so many options, from automation to using Purple AI, to give my analysts more confidence in their abilities. It is an amplifier. It is not a replacement. It is a way for them to build their confidence and skill set, but it also increases our efficiency and our time to respond to threats. The storylines with SentinelOne were probably one of the first things that caught my attention back when EDR was new to the market. They help the analyst develop a storyline or improve the storyline that they have already developed.

    SentinelOne helps us with our mean time to detect by the fact that we have every endpoint consolidated into one platform. We have the prioritization based on the rule sets, the type of devices, the classification of the data it holds, or the classification of the department or the sensitivity of a manufacturing process in that environment. These methods help to cut the detection time for my analysts.

    The platform provides multiple ways to communicate. With the addition of Vigilance and their main services, there is a very drastic reduction in the mean time to respond based on the information they give us. The information that we receive from those methods helps us to make a lot quicker decisions with the threats.

    From an organizational perspective, SentinelOne helps me and empowers my team to be able to communicate to the business about some of the adversarial threats that we have in our environment. A lot of times when an endpoint or a production or line unit is impacted, the teams come to us with reports of a false positive, but in fact, it is not. SentinelOne helps us to educate, inform, and reinforce to the organization why we are here. We are here to help. We are here to help the business grow.

    What is most valuable?

    When we first looked at SentinelOne, we had a very distributed legacy antivirus environment. Through SentinelOne's platform, we were able to consolidate about eight different antiviruses globally, thus saving money and time. There were savings in terms of human capital or the amount of time it takes to keep up with some of those legacy technologies.

    What needs improvement?

    Like any vendor, SentinelOne had its challenges, but throughout our history as a partner and as a customer, they followed through with every commitment they made. That is huge. I do not look for a vendor, I look for a partner—a long-term partner. CISOs need partners to be successful. We have to lean on each other. There are things that they can do to improve the console or improve the product, and they are making strides in it. One value that I can bring to them is the fact that I am on the advisory board. As a customer, we bring problems or challenges or even opportunities to them that they take back to their product teams and marketing teams to come up with a solution. Being able to ride side by side with some of the developments they are making now, in the near future, or in the far future is pivotal to the success of a security organization.

    For how long have I used the solution?

    We have been using SentinelOne's EDR platform since 2018.

    How are customer service and support?

    The support teams speak various languages worldwide, which is beneficial for a multinational corporation like ours. We have teams across the world, and having support in native languages saves us time and increases efficiency.

    How would you rate customer service and support?

    Positive

    Which solution did I use previously and why did I switch?

    We had a very distributed legacy antivirus environment before and selected SentinelOne for its consolidated platform.

    We are also using a different SIEM solution currently but are considering migrating to full XDR in the future. We rely very heavily on managed services and Vigilance. We have a small security team, but over time, we will be able to build some hybrid models or hybrid approaches and start to go towards XDR.

    When we looked at the EDR, having a single agent was a big deal. We have come a long way since then, but one of the primary reasons why we chose SentinelOne was their ability to package everything from a single agent.

    What was our ROI?

    The ROI is significant with SentinelOne, as it saves us money, time, and human resources by consolidating eight different antiviruses into one unified platform globally.

    What's my experience with pricing, setup cost, and licensing?

    SentinelOne makes licensing easy by reducing the number of modules or packages that they have to offer. A lot of other vendors make licensing very complicated with separate modules or separate costs. By bundling necessary features, SentinelOne ensures that security leaders are not left confused by options. This bundling of necessities has served our needs well.

    As they bring on more technologies and more offerings, they are either bundled with the premium packages or other packages they have or they are bundled separately as another SKU.

    Which other solutions did I evaluate?

    We compared SentinelOne against its competitors while evaluating EDR solutions. SentinelOne stands out to me from the competition because they stand by every commitment they make. They are extremely transparent and extremely collaborative with the customer base. They take back everything that the customers bring to the table and make the product better. It is a two-way street. We also have to give. We are giving that money for a product, so we are investing in them. At the same time, we want to have a voice. They allow us to have a voice. The fact that they are a true partner sets them apart from the competition.

    Their transparency, their willingness to work with customers and receive feedback, and the humility to admit their faults but figure out a way forward with their trusted partners or customers set them apart from the competition. They have done a good job of getting the endpoints correct. They have done a good job at saturating the market with such a good endpoint product. The endpoint data is the most critical telemetry data that we have. If you think about network and email, those are all delivery methods, but a crime is only committed at the target location, which is the endpoint. With that being the most valuable information we have, they have done such a good job with that. They are already there at the endpoint. There are a lot of other things they can do to improve the data that they have with things like identity and network discovery. There are opportunities where you take Purple AI out and put it on top and extend the width or breadth of your security team. You can extend the breadth of reach across multiple facets or multiple layers of defense from one single platform.

    What other advice do I have?

    AI is huge. It is a topic that comes with a lot of different variables. Some are good, and some are not so good. AI as a whole is not something to fear. It is no different than what mobile computing or cloud computing was. We have to embrace it. Embracing it empowers security organizations, security leaders, and security teams. It empowers them to make more and better decisions, and it also saves some time because a lot of the things that they are doing can be automated through the use of AI. It empowers the defenders, and by empowering them, it saves them time and allows them to focus on more important projects, more important topics, or more important threats. AI can help us cut down our mean time to detect and mean time to respond.

    I have had several colleagues looking at SentinelOne and comparing them against some of the competitors, which is what you are supposed to do. To those who are considering purchasing SentinelOne, I would advise moving beyond the product. Do not just consider the product when evaluating SentinelOne. Focus on the leadership, product development teams, and their commitment to working closely with customers for long-term success.

    SentinelOne is a true partner. We have had our issues. We have had our incidents. There were some times when I was desperate and needed help. They have been there. They are not there at the meat of it. They have traveled that road all the way to the end with me. That speaks volumes. To colleagues and people who are not yet using SentinelOne, I would recommend taking a look. Go beyond the curtain, the actual product, and the marketing. Look into the teams. Look into the leadership. Look into the success of other customers out there like myself. Call them. Talk to them. Challenge the product and challenge the teams, but do not let the first responses ever be the answer you go with. Continue to develop that relationship. That is what you should look for as a partner.

    On a scale of one to ten, SentinelOne is definitely a ten. That is not just product-specific, customer support-specific, or road map-specific. A lot of different areas combined give it that score. Having a true partnership means that you are bringing everything to the table. You are helping each other grow.

    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    Information Security Principal at a venture capital & private equity firm with 1,001-5,000 employees
    Real User
    Top 5
    Mar 10, 2025
    Reduces workload by consolidating functionalities into a single platform
    Pros and Cons
    • "APT and ransomware protection is valuable."
    • "This technology is perfect for us."
    • "They should host a data center in Saudi Arabia, making it easy for customers to go for a SaaS model."
    • "Sometimes, support can be lacking. We would like to have more interactive sessions, which are not currently available."

    How has it helped my organization?

    Singularity Complete integrates well. We have changed our monitoring solution, and SentinelOne supports that solution. We are using SecureWorks to monitor our system. It is directly using the SentinelOne agent. All security logs for SentinelOne and other security products are being pushed to that one. SecureWorks consolidates all the logs and alerts, and we are getting 24/7 monitoring.

    Singularity Complete significantly reduces alerts. It has reduced false positives by 30% to 40%.

    Singularity Complete helps free up our staff for other projects and tasks. We have fewer false positives. We are very comfortable with it. Before, we had to provide extensive technical support for endpoint protection, but after installing the agent, administration became much easier.

    Singularity Complete has been excellent, and we have not faced any issues in the last three to four years. It has reduced critical risks significantly.

    Singularity Complete has reduced our mean time to remediate to a good level. It has also reduced the organizational risk.

    We have used Ranger, but it is not always useful for us because most of our users are working from remote areas. It is a bit difficult for Ranger to identify them because they are working with some local networks. However, we are protecting our endpoints with the agents. It is mandatory for our technicians to install this agent.

    What is most valuable?

    APT and ransomware protection is valuable. We also use the Vigilance service from SentinelOne. It is a complete XDR platform for us.

    What needs improvement?

    Sometimes, support can be lacking. We would like to have more interactive sessions, which are not currently available. A chat service for technical support would also be beneficial. With other vendors, we are able to resolve small issues through the chat, whereas with SentinelOne, we have to open a ticket. Without a ticket, we cannot do anything. It takes more time.

    They should host a data center in Saudi Arabia, making it easy for customers to go for a SaaS model.

    For how long have I used the solution?

    We have been working with SentinelOne since 2019. It has been almost five years.

    What do I think about the stability of the solution?

    For EDR, the solution is perfect. Over the five years of using it, many improvements have been made. Initially, there were issues, particularly on the management side, but now the console is much more stable.

    How are customer service and support?

    They can provide more interactive options for support. For example, a chat service would be beneficial.

    How would you rate customer service and support?

    Positive

    Which solution did I use previously and why did I switch?

    Previously, we were using Trend Micro, which posed a lot of issues. Trend Micro has different products for different things. For example, they have a different product for servers and a different product for clients. For management and reporting, there is another product. We have to manage a lot of things in Trend Micro. 

    SentinelOne has consolidated these functionalities into a single platform, greatly reducing our workload. 

    How was the initial setup?

    The SaaS model is better, but due to some regulations, companies are hesitant to go for it. 

    Deployment was challenging because we did not have software distribution capabilities at the time, and my technicians faced many challenges. I tried using group policy, and it worked for some clients, but not all, since half of my employees work remotely. Once deployed, agent updates were automated from SentinelOne. 

    Maintenance is not required because we are using the SaaS model. We do not have any servers to manage, as it is a SaaS-based solution. When there is a new agent release from SentinelOne, we just have to deploy it from the console.

    We have different entities inside our organization. It took us three to four weeks to deploy to about 1,500 endpoints. 

    What about the implementation team?

    My team handled the deployments. We had five to six technicians.

    What was our ROI?

    We have not faced any attacks since we implemented it. We had some critical incidents before this. In that respect, we have saved costs.

    What's my experience with pricing, setup cost, and licensing?

    Its cost is similar to Trend Micro, but the protection is much better. If you want protection, you have to pay the price.

    What other advice do I have?

    This technology is perfect for us. They are good at innovation and enhancements. We have good visibility across the network and endpoints. The product is continually improving, and I am very satisfied with it. I have already recommended it to a few people.

    Overall, I would rate SentinelOne Singularity Complete a nine out of ten. There are areas for improvement, such as support and hosting data inside Saudi Arabia.

    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    AGM IT Security at Page Industries Ltd
    Real User
    Top 20
    Feb 16, 2025
    Achieved enhanced endpoint protection with AI-based zero-day threat mitigation and improved incident response time
    Pros and Cons
    • "The XDR is a valuable feature."
    • "I think they should consider enhancing complete visibility."

    What is our primary use case?

    I use it for our XDR solution, managing various endpoints including Windows and Deepak. There are around twenty-five hundred endpoints where SentinelOne EDR or the Synchrony Solution is installed, helping me manage all my files. It is a next-generation antivirus solution with zero-day protection using AI or ML-based logic running in the backend to protect endpoints. Currently, there is no integration. It's an independent solution supporting my endpoint protection.

    What is most valuable?

    The XDR is a valuable feature. The AI-based engine protects against various behaviors and takes action on files being accessed. In terms of protection, I have an advanced app providing visibility of all my endpoints, which was not the case before. My time to respond to incidents has reduced, making it much more complete. I have the ability to isolate endpoints if identified as having malicious files or serious activity.

    What needs improvement?

    I think they should consider enhancing complete visibility. I haven't explored the network-related aspects, but if lacking, it is an area for improvement. Providing a single pane of visibility for the end user would be beneficial. This means not just seeing endpoints, but also the network and other connected devices through the Singularity portal. This would enhance decision-making and improve security posture.

    For how long have I used the solution?

    I have used the solution for three years.

    What do I think about the stability of the solution?

    It's a stable solution. My endpoints use minimal resources, and I have encountered no problems with installation, making it a stable product.

    What do I think about the scalability of the solution?

    From the console or admin perspective, as it is a SaaS product, scalability and management pose no problems. It's all auto-scale and auto-categorized, configuring automatically.

    How are customer service and support?

    I think they were responsive, but there was a delay in reaching out to my team on one incident report. This happened only once, which is why I am rating them eight out of ten.

    How would you rate customer service and support?

    Positive

    Which solution did I use previously and why did I switch?

    I had a normal antivirus solution before upgrading to the next-gen XDR solution, which is SentinelOne.

    How was the initial setup?

    The setup is very straightforward. It took one month. Connecting to users was a manual process, but all network-connected devices were integrated without any challenges.

    What about the implementation team?

    There was a three-member team from the vendor side assisting with configuration and communication with my internal team. One of my team members coordinated with the end customers, who are the employees of my organization.

    What was our ROI?

    There isn't significant cost saving as such, but it has protected me from numerous virus or malware infections. This demonstrates an ROI.

    What's my experience with pricing, setup cost, and licensing?

    It's a fixed price per endpoint arrangement.

    Which other solutions did I evaluate?

    I have not used alternative solutions for the XDR solution. We were using an alternative antivirus solution before, but finalized on SentinelOne after considering other options.

    What other advice do I have?

    I rate the solution nine out of ten. It prevented potential losses, though not directly affecting ROI. To make it work effectively, ensure proper configuration and understanding of your network landscape. Initially set it to detect mode, then to protect mode, and later to auto-protect and quarantine mode. Allow one to three months to understand the network and work with a knowledgeable partner.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Disclosure: My company does not have a business relationship with this vendor other than being a customer.
    PeerSpot user
    reviewer2889561 - PeerSpot reviewer
    Founder & Owner at a consultancy with 11-50 employees
    Real User
    Top 20
    Aug 20, 2026
    Advanced endpoint protection has strengthened compliance and stopped risky user activity
    Pros and Cons
    • "SentinelOne Singularity Endpoint has really improved compliance and security, as there are no problems anymore."
    • "Since adopting SentinelOne Singularity Endpoint, I have seen a mixed bag of measurable results. SentinelOne Singularity Endpoint tends to block workstations at the slightest doubt, so it needs to be fine-tuned to be a bit more tolerant."

    What is our primary use case?

    fuck

    What is most valuable?

    The best features that SentinelOne Singularity Endpoint offers are its anti-malware function and prevention, which is more intelligent than a traditional antivirus. From what I see in current reviews, it is one of the best EDRs, which is why it was recommended, and it works together with NinjaOne RMM.

    As soon as SentinelOne Singularity Endpoint has a doubt, not necessarily just a malware signature, it will block the traffic. It has intelligent detection tools that go further than a traditional antivirus.

    SentinelOne Singularity Endpoint has had a positive impact on the organization because the cyber insurance company required this type of tool to be reimbursed in case of a cyber incident. In other contexts and engagements, ESET has been used, which is also very good.

    SentinelOne Singularity Endpoint has really improved compliance and security, as there are no problems anymore. Employees used to play around downloading files using eMule and other legal software that caused security or confidentiality issues, but all of that was able to be eliminated quickly. The firm had more than fifteen years of work behind it, accumulating bad habits and files that were not a problem before but can be today. The client was very happy to have cyber insurance and be reimbursed in case of a problem, allowing them to sleep much more soundly, because if there is an IT incident, it could mean the closure of the company.

    What needs improvement?

    Since adopting SentinelOne Singularity Endpoint, I have seen a mixed bag of measurable results. There have indeed been many fewer risks, but there have been other problems. SentinelOne Singularity Endpoint tends to block workstations at the slightest doubt, so it needs to be fine-tuned to be a bit more tolerant. Otherwise, there are blocked workstations and loss of productivity.

    There were many problems on old Windows Servers that were not compatible, so they had to be upgraded. If SentinelOne Singularity Endpoint were more backward compatible with older versions, that would be great. The old versions of Windows Server were not very compatible, but that is the only criticism.

    For how long have I used the solution?

    SentinelOne Singularity Endpoint has been used since 2023.

    Which deployment model are you using for this solution?

    Hybrid Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Disclosure: My company has a business relationship with this vendor other than being a customer. Partner
    Last updated: Aug 20, 2026
    Flag as inappropriate
    PeerSpot user
    Senior Vice President IT at AS IT Consulting Pvt. Ltd.
    Reseller
    Top 5Leaderboard
    Jan 20, 2026
    Security correlations have boosted compliance operations and improve user productivity
    Pros and Cons
    • "The main benefits the end-user gets from Singularity Platform are, first, the program itself being very small, and then we get better output from applications running on their systems."
    • "In my opinion, the real-time monitoring capabilities in Singularity Platform sometimes work and sometimes they don't, because there are a lot of false positives and people use unsigned applications which get deleted or quarantined by the product."

    What is our primary use case?

    My main use cases for Singularity Platform are compliance and security operations.

    What is most valuable?

    I have found the correlations in Singularity Platform to be the most valuable. The main benefits the end-user gets from Singularity Platform are, first, the program itself being very small, and then we get better output from applications running on their systems. The output of the users has gone up 50%, although I don't remember other benefits at this time.

    What needs improvement?

    There are a lot of false positives in that, which is why I'm not working with it. The use of the fraud detection feature in financial services in Singularity Platform depends on the compliances that are applicable to the organization, so it may be useful for some and may not be useful for others. I did that by myself, not with the help of Singularity Platform. In my opinion, the real-time monitoring capabilities in Singularity Platform sometimes work and sometimes they don't, because there are a lot of false positives and people use unsigned applications which get deleted or quarantined by the product. It's not a 100% foolproof solution.

    A point for improvement for SentinelOne is that the false positives are huge since people in India, at least, are using homegrown applications which get blocked. Right now, Singularity Platform is working fine, but people have concerns about enhancements like website monitoring that can be done through Singularity Platform itself, so they don't need to buy any SASE products for people working from home to control their browsing. If that feature can be included, it will be a big advantage.

    For how long have I used the solution?

    I have been working with Singularity Platform for almost two years now.

    What do I think about the stability of the solution?

    I had some issues with that.

    What do I think about the scalability of the solution?

    I would rate the scalability a nine.

    How are customer service and support?

    Technical support will always be between six and seven.

    How would you rate customer service and support?

    Positive

    How was the initial setup?

    The initial setup for Singularity Platform is very simple; the dashboard is quite simple, and the agents' installations are very simple, like one click, I would say.

    What's my experience with pricing, setup cost, and licensing?

    For pricing, I would say it's a six. It could be cheaper, as I understand.

    Which other solutions did I evaluate?

    The main competitor for Singularity Platform is CrowdStrike at number one, and the second is Trellix, which is coming up very fast. The leader on the market is still SentinelOne, but if they don't add some add-ons to their product like Trellix and CrowdStrike have, they may lag very soon. If we do only apple-to-apple comparison on Singularity Platform, then I'll give it ten marks.

    What other advice do I have?

    Singularity Platform functions as a security information and event management solution, and that is an inbuilt part of it. I believe in the correlations that I get because we work on it, but we don't use the Purple AI part of it. I'm not able to get clarity regarding the real-time personalization feature in Singularity Platform. I do not use the real-time personalization feature in Singularity Platform. It is a matter of false positives when people use it in my area.

    Regarding the impact of Singularity Platform on supply chain processes, I don't have much on it, but it's a good product and the tracking is better with the log capturing and the data that we get from it. The customer does require customizations on the dashboards as per the requirement of their organizations; if it's manufacturing, medical, or financial institution or banking, then they will have different requirements for their dashboards, which are yet not available, so we have to actually build up those dashboards for them. I can recommend Singularity Platform to other users. I have provided this review a rating of 9.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Other
    Disclosure: My company has a business relationship with this vendor other than being a customer. reseller
    Last updated: Jan 20, 2026
    Flag as inappropriate
    PeerSpot user
    Buyer's Guide
    Download our free SentinelOne Singularity Endpoint Report and get advice and tips from experienced pros sharing their opinions.
    Updated: August 2026
    Buyer's Guide
    Download our free SentinelOne Singularity Endpoint Report and get advice and tips from experienced pros sharing their opinions.