2nd Analyst at a tech vendor with 10,001+ employees
Real User
Top 20
Aug 20, 2026
My advice to others looking into using SentinelOne Singularity Endpoint is to try it and use it to see if you it; it is good for me. I would rate this product a 7 out of 10.
SOC Analyst II at a computer software company with 51-200 employees
Real User
Top 10
Aug 18, 2026
Singularity Complete fills the role of EDR and helps us with monitoring, so it is a part of our complete puzzle that gives us the vision we need into a customer's environment, depending on whether they have SentinelOne Singularity Endpoint through us and we manage it. We do not use the Ranger functionality because a different department manages network visibility. Singularity Complete does not necessarily lessen alerts for us as we have it tuned to only create cases in our SIEM for things that are high and critical. Although I do not have any direct metrics, I do find that it all ties into giving us the intelligence or data from detections, which get fed into our SIEM for us to take actions either in SentinelOne Singularity Endpoint or by contacting the customer. My advice for others looking into using SentinelOne Singularity Endpoint is to take advantage of the partner support portal to get trained up on it, as that will definitely help you understand it and use it to its full capability. I believe we fall under partner in terms of our business relationship with this vendor. I would rate my overall experience with SentinelOne Singularity Endpoint as an 8.
Senior Engineer - Cybersecurity at a comms service provider with 11-50 employees
MSP
Top 5
Aug 18, 2026
SentinelOne Singularity Endpoint is solid, and the support from the SOC is strong. We only use the Ranger functionality of SentinelOne Singularity Endpoint in a limited capacity, so I cannot speak to its ability to provide network and asset visibility or its importance to us. It is difficult to quantify whether SentinelOne Singularity Complete has helped reduce alerts, so I cannot provide specific details about it. SentinelOne Singularity Complete has helped free up our staff for other projects and tasks because we use the SOC with SentinelOne, allowing them to handle all first-line defense on detections. We do not track the reduction in our organization's Mean Time to Detect (MTTD). Similarly, we do not track the reduction in our organization's Mean Time to Respond (MTTR). My advice to others considering SentinelOne Singularity Endpoint is to ensure that you understand what is covered by support and their SLO targets. I would rate this review as a 9 out of 10.
security analyst at a tech vendor with 501-1,000 employees
Real User
Top 5
Aug 17, 2026
I rate SentinelOne Singularity Endpoint a nine out of ten. I give it a nine out of ten because, having worked with all the competitors, there are others that have some more advanced features, but SentinelOne Singularity Endpoint is really wonderful. I know they make a really good product and it is one of my favorites, but it is not perfect. Regarding SentinelOne Singularity Endpoint's AI capabilities, I appreciate that feature, but I set rules manually all the time. I have never used or tried to use AI for that purpose. I prefer to use AI to ask about status and to monitor activity, but not for everything else. I have not tried using it for other purposes. In monitoring, I have used SentinelOne Singularity Endpoint and it is really wonderful; the accuracy is really high, and I trust the output completely. For me, it is really good for all the other capabilities of SentinelOne Singularity Endpoint, which I have never used outside of monitoring. I do not have knowledge about those aspects. SentinelOne Singularity Endpoint is deployed for my clients in different ways. I have a customer using the public cloud, where SentinelOne Singularity Endpoint protects a few virtual machines and containers in a Kubernetes cluster. I have other customers where it is on-premises and the agent is installed directly on physical endpoints, mostly Windows, to monitor local operating system behavior. For the public cloud deployment, my customer uses AWS. I did not purchase SentinelOne Singularity Endpoint through the AWS Marketplace; it was purchased with an Italian SentinelOne reseller. I appreciate the data ingestion correlation of SentinelOne Singularity Endpoint and the automated Storyline; all of that is really wonderful. SentinelOne Singularity Endpoint helps me connect and analyze data from multiple sources. We have made some integrations with next-generation firewalls such as Palo Alto, and there are integrations that allow us to merge the data into SentinelOne Singularity Endpoint's Data Lake, which reduces our time for data analysis because we can find everything together in SentinelOne Singularity Endpoint. SentinelOne Singularity Endpoint Complete has helped me consolidate my overall security solutions, also thanks to the automatic Storyline correlation. When Palo Alto logs go into SentinelOne Singularity Endpoint, the AI of SentinelOne Singularity Endpoint connects them to the Storyline technology. For example, one user from a company downloaded a suspicious file, which triggered the advanced threat protection of the Palo Alto firewall. All the data from Palo Alto is integrated with SentinelOne Singularity Endpoint; the AI merges the data from the computer and the firewall, allowing us to conduct a full analysis within SentinelOne Singularity Endpoint and providing a clear visual representation of how the attack or event unfolded—a diagram of the sequence of what happened during a security event. Using SentinelOne Singularity Endpoint has reduced alerts for me and my clients because the agent acts as a teacher for the user, making the good and bad status of a workstation visible to the user, which encourages them to be more careful about their actions. It is really easy for them to use; the first problem in any company is human error. SentinelOne Singularity Endpoint Complete has significantly freed up IT and SOC personnel by reducing their daily security operation workload, potentially by around thirty percent. SentinelOne Singularity Endpoint has helped reduce my organization's Mean Time to Detect. Personally, I have saved between fifteen to twenty hours every week of work, allowing me to reallocate my time to infrastructure projects and other cloud migration tasks. This has given me a lot of spare time where it is most needed. The time savings come from the very core capabilities of SentinelOne Singularity Endpoint: Zero-Touch Remediation and Rollback, automated root cause analysis via Storyline, and the mitigation of alert fatigue. The automatic capabilities of SentinelOne Singularity Endpoint have reduced the time to respond to incidents by an incredible ninety percent, and this is thanks to the automated emails sent to the security department whenever a potential incident occurs. The autonomous response capabilities of SentinelOne Singularity Endpoint, specifically Zero-Touch MTTR, allow the agent to evaluate the threat locally on the endpoint and execute immediate containment protocols without waiting for human intervention, achieving an MTTR of under one minute, which is significantly different from competitors. I do not have experience regarding pricing, setup costs, and licensing for SentinelOne Singularity Endpoint because I work in the IT and security department and do not have access to customer pricing information. I do not have information about money saved, but I can tell about time saved. In my team, I currently have fifteen free hours each week, and the other four members have reduced their work by more than twenty hours a week. My advice for others looking into using SentinelOne Singularity Endpoint is to definitely test the rollback feature in a sandbox because it is incredibly powerful, and it is truly awesome to see how quickly it works. I really appreciate this product, and I want to pursue some certification courses for SentinelOne this autumn. Overall, I rate this product a nine out of ten.
I think we have covered everything because I have mentioned many things that can improve, and I hope they will because thanks to these improvements, they will become a ten out of ten. For now, I think this is the best ADR in my opinion, so I am happy to use SentinelOne Singularity Endpoint every day in my job. I would rate this solution nine out of ten. I can give many examples in these cases. Generally, we use a lot of Microsoft Defender for Endpoint and Azure Sentinel. I think the ability of SentinelOne Singularity Endpoint to share data with other security tools is very positive. It provides APIs and integration that allow us to send endpoint detection, alerts, and security telemetry to other platforms such as Azure Sentinel, Splunk, or SOAR. This is important because we do not want endpoint security to operate in isolation. Thanks to the integration with SentinelOne Singularity Endpoint with CMDB or with other security stacks, we can correlate endpoint data with information from the cloud, identity, network, and other security sources. This helps with automation. For example, SentinelOne Singularity Endpoint detection can be forwarded to a CMDB or SOAR platform, where it can trigger additional investigation or response workflows. I would say that the integration capabilities are strong and valuable for creating a more generalized and coordinated security operation. I can say that the platform can help us for other projects because the platform automates many activities such as threat detection, alert correlation, point containment, or detection. Instead of manually investigating every single endpoint, the storyline provides the context and attack chain and allows analysts to make decisions much faster. As a result, we can dedicate more time to threat hunting team, also to security architecture and to cloud security. It has improved a lot. Of course, SentinelOne Singularity Endpoint helps us to reduce the mean time to detect because thanks to the behavioral AI that is continuously monitoring endpoints and all the activity on the endpoint and identifies the suspicious behavior in real-time, including threats that may not be detected through traditional signature-based methods. This feature is very important. Also, the storyline automatically correlates the activity so our analyst does not need to manually connect multiple events to understand an incident. We can detect and understand potential threats much earlier thanks to these two features. This helps improve our response time and helps to reduce MTTR. Regarding metrics, I can say forty to fifty percent reduction. I can estimate forty percent because some incidents before could take hours to investigate and do the remediation because you have to do several steps manually. With the storyline and automated containment, the one-click remediation and the rollback, we can handle many incidents much faster, sometimes in some minutes. I can say the time went from hours to minutes. So I would say forty percent is a good estimation. Pricing is generally positive. It is being considered a premium solution, but the pricing is typically based on the number of endpoints bought and the package on the additional capabilities selected. I think I would say the pricing is competitive considering the security capability and the automation. I would say the pricing is fair for what SentinelOne Singularity Endpoint is giving to us. Regarding specific examples and time, I can say the main benefits come from MTTD and MTTR. Thanks to the automated remediation, we now do not have to do manual investigation. These are the parts that are the most important. Regarding SentinelOne Singularity Endpoint, I can first of all suggest to invest in it because I do a lot every day. I would recommend investing time in storyline and automated remediation capability because these are some of the areas where SentinelOne Singularity Endpoint provides the most value. Additionally, it is important to connect SentinelOne Singularity Endpoint with CMDB support or cloud identity which can help to get more value from the platform and improve the incident response process. I do not just deploy the agent and the found configuration. It is necessary to configure the platform based on our environment. This is what I suggest to configure the platform based on our environment and security equipment. With the proper configuration and integration, SentinelOne Singularity Endpoint can significantly improve the detection, response time and overall frequency efficiency.
Senior IT Administrator at a financial services firm with 201-500 employees
Real User
Top 10
Aug 16, 2026
I would rate this solution almost a 10, maybe a 9 because of the price. It is not a cheap solution, but it works really well. It is a really good solution that efficiently protects your endpoints and servers. Even if the price is not as competitive as some other solutions, the functionalities are worth it. I give this product an overall rating of 9 out of 10.
Learn what your peers think about SentinelOne Singularity Endpoint. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
I would advise others looking into using SentinelOne Singularity Endpoint to ensure they have some experts able to manage the configuration of the product because it can be really difficult to manage. I would rate SentinelOne Singularity Endpoint an eight out of ten.
L2 Cyber Security Analyst at a security firm with 51-200 employees
Real User
Top 5
Aug 13, 2026
SentinelOne Singularity Endpoint has helped to consolidate our security solutions. It has acted promptly on attempted attacks, such as worms, some Trojans, and many spyware. It blocks everything. Ranger AD is used, but not by my team. It is used by another team. SentinelOne Singularity Endpoint has helped reduce alerts, but it depends. At the beginning, it was very noisy, generating many alerts, but after some tuning and creating exclusions, it stopped making noise. The solution has helped reduce the Mean Time to Detect in my organization by half an hour. My advice to other people who are considering using SentinelOne Singularity Endpoint is that the console is very intuitive, and I recommend getting hands-on. Check out the endpoint inventory side and the alert side, understand how to examine an alert, check through Purple AI, study the details carefully, cross-check the data with VirusTotal, and analyze the alerts and the data provided by the alert thoroughly. I rate this product an eight out of ten.
Technical engineer at a tech services company with 10,001+ employees
Real User
Top 20
Jul 22, 2026
For a long time, SentinelOne Singularity Endpoint is effective at correlating my security solutions, allowing for customization of rules based on requirements. SentinelOne Complete did not reduce alerts; instead, it increased noise in the environment until fine-tunings were done for customized rules. As of now, I have not seen a significant freeing up of staff for other projects due to SentinelOne Singularity Endpoint. We are not using SentinelOne Singularity Endpoint for network and asset visibilities. Regarding organizational MTTD and MTTR, this is at a moderate level. My advice for others looking into using SentinelOne Singularity Endpoint is to go for it, as it effectively does the EDR job. I would rate this product an 8 out of 10.
I advise others looking into using SentinelOne Singularity Endpoint to use this tool because it provides a comprehensive solution. It is very effective and if your organization does not require too many personnel, it is one of the best tools for you. I do not have any additional thoughts about SentinelOne Singularity Endpoint other than that it is a very good tool that provides us with a feasible and wonderful solution. I give this review a rating of nine.
I am using the SaaS deployment model for SentinelOne. Ranger is important because it gives me visibility into how many devices in my network are unprotected. It provides security posture information showing how many detections exist, how many devices are protected, and how many are not. It gives an overview of what devices need protection and allows me to review why certain devices are not protected and identify any limitations. The company name is SentinelOne. I use Purple AI in SentinelOne. Purple AI is an AI developed by SentinelOne that helps me correlate or build queries for those who have not used SentinelOne Singularity Endpoint before. It also provides information about the product without sharing confidential information. SentinelOne has a policy ensuring that all data and queries are kept internally and not shared with any third party. Regarding workflow, Purple AI helps overall in my day-to-day operations by assisting with how alerts are triggered, retrieving results for alerts, providing alert descriptions from connected devices, and helping mitigate threats. I gave this review a rating of 8 out of 10.
Purple AI is designed with data privacy and security in mind, ensuring that customer data is processed according to compliance requirements, which allows organizations to maintain control over their data while using AI-powered assistance for threat investigations and analysis. My overall rating for this product is eight out of ten.
Technical Support Engineer Iii (Siem & Soar) at Barracuda Networks
Real User
Top 10
Jun 9, 2026
I primarily use the AI capabilities in SentinelOne Singularity Endpoint for endpoint detections, threat analysis, and threat hunting. I have not extensively used the AI capabilities, so I do not have much experience to share or feedback regarding its accuracy and reliability. My review rating for this product is 8.
Cybersecurity Product Manager at a tech services company with 51-200 employees
Real User
Top 10
May 21, 2026
I do recommend SentinelOne Singularity Endpoint to other users as part of my day-to-day responsibilities. I have given this review an overall rating of eight out of ten.
Presales Lead & Delivery Lead at a construction company with 1-10 employees
Reseller
Top 20
May 20, 2026
For the overall SentinelOne Singularity Endpoint, I would give a score of eight for the whole product. Regarding the price point of SentinelOne Singularity Endpoint, I do not know the exact number, but I have come from the community and attended many events. As far as the cost is concerned, before the CrowdStrike blue screen attack, CrowdStrike pricing was far more increased rather than SentinelOne. After the CrowdStrike shares decreased due to the blue screen attack, they are very competitive with SentinelOne nowadays. The impact of Purple AI on investigations ultimately depends on what incident I got. I do not think the analyst should rely completely on Purple AI because there are many hashes or threats that are not publicly available. If things are not publicly available or not learned by the AI, I do not think I should rely completely on Purple AI. If I have any sort of data and see any pattern from my analyst's perspective, I can completely tell Purple AI that I think it can demonstrate the storyline that I am right. Based on that, I can take a decision, but I should not rely on the decision solely on Purple AI. My overall rating for this product is eight out of ten.
Director Of IT Security And Risk Management at AskDegree
Real User
Top 5
May 19, 2026
SentinelOne Singularity Endpoint provides alerting into the dashboard, but I did not configure it correctly and never received alerts over emails. If such a feature exists within the product, that would be awesome, and I could incorporate and configure it. Currently, I do not have visibility on it. Once I log into SentinelOne Singularity Endpoint, it provides visibility within the dashboard showing how many endpoints have been detected as infected, how many endpoints are impacted, and how many endpoints have been identified as malware where SentinelOne Singularity Endpoint has quarantined those files, and I can do analysis and further processing. However, currently, I did not configure it if it is available, but I am unable to navigate it. I do not have visibility on whether any endpoints or target machines have been impacted so that I receive email notifications or SMS notifications alerting me that a machine has been impacted and needs to be worked on urgently. This is a critical function I need to perform right now. If this would be configurable or is available in SentinelOne Singularity Endpoint, that is awesome. If not, then the alerting mechanism needs to be improved to get alerts over emails or SMS for at minimum critical assets. I can say that I currently did not implement it in such a way because for what I am using SentinelOne Singularity Endpoint for, it is the on-premises infrastructure for some organizations and just for endpoints in other organizations. In that case, I believe for SaaS products, I am currently not utilizing it for such things. My question is whether SentinelOne Singularity Endpoint is an agent-based solution that I can only utilize on endpoints or servers or where the operating system is Linux or different flavors where the operating system is running. However, for the serverless environment, SentinelOne Singularity Endpoint cannot work. Is that the right expectation? Obviously, the core concern is about data protection and privacy. There is something I have to adopt with AI. If I do not adopt it, I am not running with the market and chasing new goals. The thing is I have to implement frameworks such as ISO 42001 to manage data and contain my data's confidentiality and privacy. This is core importance for me in my job role. I take care of this all the time, and obviously if I am integrating solutions that utilize AI-based features into their product, I do have vendor management or vendor risk management to perform with vendors. I currently look into AI standards or framework implementation within organizations if they are providing me with full core data security. This is the point I engage in with existing and onboarding vendors. Additionally, I am currently utilizing AI and making AI models within my organizations. I implement security standards and maintain the whole implementation and operationalization of data protections within AI models and machine learning models. This is the function that can be adopted, and if it is in the product, obviously this is a positive point and I do encourage that utilization of AI models within products. As I mentioned, if I got email alerts or SMS alerts for critical systems and if AI has been engaged into threat modeling with well-known algorithms that identify what threats, viruses, or malicious insights have been identified in the system, and if AI can guess that certain operating systems, files, or things are critical to my organization and can do this on a real-time basis, that would be a positive point. Obviously, as I mentioned, if I want to run with the market, I have to integrate those AI threat modeling or AI remediations within my organization. I have to do that. I give this review an overall rating of eight out of ten.
With SentinelOne Singularity Endpoint, we have detected incidents that triggered alerts, and we can raise them within a maximum time of 10 to 15 minutes later. I recommend blocking the connection and taking other necessary actions. The importance of the Secret Scanning feature in SentinelOne Singularity Endpoint is significant because it scans newly engaged endpoints for malicious activities. It detects harmful EXE files or suspicious abnormal behaviors, ensuring the health of our endpoints is maintained. I recommend implementing SentinelOne Singularity Endpoint because the integration part is very simple and suited for small organizations. It is reasonably priced, and the installation of the endpoint on the client side takes only two to three minutes. I can also explain how it compares with other endpoints and the types of alerts generated, making it suitable for potential clients. Deep visibility, full disk scan, and rollback features are impressive, especially in cases of ransomware attacks. The rollback feature helps easily revert to a safe state prior to attacks, while the full disk scan ensures that all machines are scanned for threats, thus maintaining endpoint health.
I do not use the Ranger functionality because I am an L1 and I have only read-only access, but I know the functionality. The main function is network discovery and control, which identifies and manages unmanaged devices on the network and detects rogue devices on the system. Before I joined, I can say my organization reduced alerts by 30-40% due to integrating multiple devices with SentinelOne Singularity Endpoint, impacting mostly the false positive alerts. Data privacy and security with Purple AI are important for my organization; the co-pilot feature of Purple AI helps pull down any IOC present in my network, allowing me to identify any IOC, hash, vulnerability, or malicious activities that occur. I am the only SOC analyst L1, and while my organization has an investigating team that uses Purple AI mainly for investigation and threat hunting purposes, I have only used it for basic commands and queries for investigation. My clients are medium-sized, not exceeding 2,000 to 4,000 crore companies. If you are considering implementing SentinelOne Singularity Endpoint in your organization, I have several recommendations: first, train the SOC team, especially if there are new joiners; second, start with a pilot deployment rather than deploying to all endpoints; third, integrate SentinelOne Singularity Endpoint with other products such as SIM tools or SOAR tools to realize the true value of SentinelOne Singularity Endpoint; using it alone will not provide its full potential. I would rate this solution a nine out of ten overall.
SentinelOne Singularity Endpoint has helped reduce alerts for us by almost 50%. Before implementing it, my colleague told me that we were using an AV, but I do not have knowledge about which AV it was. After using SentinelOne Singularity platform, the time has reduced by 50%. There is up to 30 to 40% mean time reduction in MTTD. For mean time to resolve, whenever we get the alert from the console, we integrate SentinelOne Singularity with a sub-console, so it raises the alert within five minutes. I would rate this solution a 9 out of 10 overall.
I do not have anything else to add about my main use case or how SentinelOne Singularity Endpoint fits into my workflow. The unified platform experience certainly helps streamline our security operations, making things easier for my team. In terms of adaptability to new and unknown threats, I believe SentinelOne Singularity Endpoint is the tool I have used the most, and while I cannot compare right now since I have only used CrowdStrike once, I find SentinelOne Singularity Endpoint easier to use than CrowdStrike. I was not aware of the possibility to use an Offensive Security Engine, but I will seek more information on it. Having built-in integrations that unify various aspects of cloud security is very significant for my team, as it makes everything easier to manage. I advise others looking into SentinelOne Singularity Endpoint to check the ease of usage of the tool, as the platform is very helpful and the protection it provides is truly exceptional. I have given this review a rating of 10.
Soc Analyst at Softcell Technologies Global Pvt.Ltd
Real User
Top 10
Apr 27, 2026
Purple AI is a tool I have used because we have the analyst access. I had limited access to Purple AI, but I have used it for finding the IOC in our networks and our customers' networks. It is a co-pilot feature where I can use a pull-down menu to identify based on the present IOC. The retrieve time is very fast, and we get the answer within five to ten seconds. We have IOC, zero-day vulnerability, or any other hashes present in our network. Because I am an L1 analyst, we have a forensic analyst team also, and they are using Purple AI. This tool is very helpful for our forensic team. SentinelOne Singularity Endpoint is reducing our time because we do not have that access to Purple AI. SentinelOne Singularity Endpoint is reducing our time to find the IOC in the organization. I gave this review an overall rating of 10 out of 10.
Soc Analyst Trainee at Softcell Technologies Limited
Real User
Top 5
Apr 27, 2026
I would recommend SentinelOne Singularity Endpoint to other users because its threat detection and alerting are very quick. We have used CrowdStrike for one and a half months, but SentinelOne Singularity Endpoint triggers alerts much faster. Its compact features allow us to check seven to eight features effectively, and its pricing is lower than other EDR products. SentinelOne Singularity Endpoint has better pricing compared to other endpoints. CrowdStrike has a high value, but SentinelOne Singularity Endpoint's pricing is easier for any organization to handle. Regarding maintenance, there is no need for maintenance according to me. I give this product an overall rating of 10 out of 10.
In terms of consolidating our security solutions, I would rate SentinelOne Singularity Endpoint a 9 out of 10 because it meets all our use cases effectively. It provides granular insights into endpoints and comes with feature roadmaps, including AI security analysis that helps us understand the usage of shadow AI in our environment, vulnerabilities, and overall system alerts. This functionality allows us to monitor how many threats were remediated and triggered, significantly enhancing our security posture. We assessed the Ranger functionality a few months ago; we activated it for a trial and subsequently turned it off. During activation, it scanned our network for shadow endpoints without SentinelOne Singularity Endpoint, identifying devices such as printers or scanners, and provided insights into unknown devices on our network, offering valuable reports through the Singularity dashboard. Although we have not yet activated Purple AI, the guidance provided when alerts occur is helpful, summarizing what triggered the alerts and offering analysis steps for our small team, providing high-level alert overviews. I rate this review a 10 out of 10.
Technical Support Executive at Softcell Technologies Limited
Real User
Top 5
Apr 3, 2026
We are managing 7,000 to 8,000 endpoints for clients, and the setup is very easy. I have given SentinelOne Singularity Complete an overall review rating of 10 out of 10.
Network Security Engineer at a retailer with 11-50 employees
Real User
Top 5
Mar 31, 2026
In our environment, we do use Purple AI as part of SentinelOne Singularity Complete to help with threat analysis, investigation workflows, and speeding up the incident triage. Purple AI acts as an AI-powered security analyst, helping translate complex data into actionable insights and enabling faster threat hunting and investigation across our endpoint security data. Purple AI plays a critical role in amplifying our team knowledge by helping us interpret alerts, investigate threats, and identify patterns across endpoints quickly. It essentially amplifies our team's knowledge by providing contextual insights, suggesting remediation steps, and correlating between security events that might otherwise be missed. SentinelOne Singularity Complete has significantly reduced the number of alerts our IT team has to handle manually. By leveraging AI-driven behavior analysis and automated threat automation, low-risk or duplicate alerts are filtered out, allowing the team to focus on the most critical incidents. In our experience, the platform has reduced actionable alerts by fifty to sixty percent. SentinelOne Singularity Complete has significantly reduced our organization's mean time to detect. With real-time AI-driven detection, automatic alerts, and behavioral analysis, threats are identified almost immediately upon occurrence. In our environment, we have observed that mean time to detect has improved by approximately sixty to seventy percent, meaning our IT team can detect and respond to incidents much faster than before. The rapid detection has been critical in preventing escalation and minimizing potential impact on end-user systems. SentinelOne Singularity Complete has significantly reduced our organization's mean time to respond, thanks to automated remediation, rollback capabilities, and prioritized alerts. Our IT team can respond to incidents almost immediately. Mean time to respond has been reduced by approximately sixty-two percent, allowing threats to be contained and resolved in minutes rather than hours. For others looking into using SentinelOne Singularity Complete, I advise utilizing the Purple AI summarization. The alert without much manual investigation allows us to determine if it is a true positive or not by seeing the Purple AI alert summarization, what happened, what process, activity, and what the underlying behavior is. Overall, SentinelOne Singularity Complete is highly effective, but organizations get the most value when they combine automation, AI, incident, and proactive management. Regularly reviewing the report with audit features is valuable for complete tracking of trends. Utilize the AI-driven insight to amplify your team knowledge and reduce alert fatigue. Planning for deployment across sites if you have multiple locations is essential, as is planning your policy and endpoint coverage for centralized management. I rate this solution a nine out of ten.
From a features perspective, there are no missing functionalities in Singularity Platform; the features are quite good for now. The overall review rating for Singularity Platform is 8.
Regarding Singularity Platform's real-time personalization feature, it does help with my customer experience strategies because, in my personal experience, I have taken a role as Treasury Manager and I am dealing with investment accounts every day. To do all that work manually compared to any type of platform work is pretty painful, so I would say anything in an automated space for any investment, any company with a bunch of investments in a portfolio, Singularity Platform is an option. Singularity Platform does help with fraud detection in the financial services as it has rules involved for risk management. If there was a purchase done, the way Singularity Platform works is it is fed in the custodian feeds as well as the bank feeds. There is no current trading platform associated with it, but there may be things in the works that will include a trading platform. I would say that there is a compliance module within Singularity Platform that helps clients determine if they want to remix their portfolio balances to stay compliant with whatever loan agreements they may have. Regarding Singularity Platform's customizable dashboards, I believe they help optimize operational efficiency. Since my role was really behind the scenes, not as a developer but on the QA implementation side of things, I believe any platform that can customize for any client will actually help them in the long run. I believe that having reports that are unique to each individual client helps them in their own way, so whatever reduces the manual workload for the client, especially customizing UI, is a good idea. I would absolutely recommend Singularity Platform to other users, but it depends on what their expectations are for the investment accounting software they plan to implement. For a smaller size insurance company, I believe that is fine. However, there are things that Singularity Platform cannot do that Clearwater does, and I am sure there are things that Clearwater does not do that Singularity Platform does. Therefore, it is hard to say definitively; it really depends on the client's needs. For a full-blown investment accounting and reporting system, I would still recommend Clearwater over SS&C. In terms of asset management and banking solutions, I cannot really respond because I believe SS&C and Clearwater probably have the same application capabilities. I would rate this solution a seven out of ten overall.
Singularity Platform functions as a security information and event management solution, and that is an inbuilt part of it. I believe in the correlations that I get because we work on it, but we don't use the Purple AI part of it. I'm not able to get clarity regarding the real-time personalization feature in Singularity Platform. I do not use the real-time personalization feature in Singularity Platform. It is a matter of false positives when people use it in my area. Regarding the impact of Singularity Platform on supply chain processes, I don't have much on it, but it's a good product and the tracking is better with the log capturing and the data that we get from it. The customer does require customizations on the dashboards as per the requirement of their organizations; if it's manufacturing, medical, or financial institution or banking, then they will have different requirements for their dashboards, which are yet not available, so we have to actually build up those dashboards for them. I can recommend Singularity Platform to other users. I have provided this review a rating of 9.
Information Security Officer at a tech vendor with 51-200 employees
Real User
Top 5
Nov 17, 2025
Regarding Singularity Platform, I would go for the platform. I am most familiar with that one. I do not currently know what version of Singularity Platform I am using. I will have to check. Probably I am using the latest version because we have automatic updates. We are not using the fraud detection feature in financial services, as we are not doing any financial services. Regarding Singularity Platform's real-time personalization feature, we are using it. Overall, if I had to rate Singularity Platform from one to ten, I think an eight would be appropriate. It is quite up to our standards. I would rate this review an eight overall.
SentinelOne Singularity Complete is an advanced endpoint security platform featuring centralized management across multiple locations. It leverages AI-driven behavior detection, threat prioritization, and ransomware rollback for enhanced protection and streamlined operations.
With a focus on endpoint protection, threat detection, and automated response, SentinelOne Singularity Complete provides comprehensive security through AI-powered behavioral analysis and real-time threat detection. The...
My advice to others looking into using SentinelOne Singularity Endpoint is to try it and use it to see if you it; it is good for me. I would rate this product a 7 out of 10.
Singularity Complete fills the role of EDR and helps us with monitoring, so it is a part of our complete puzzle that gives us the vision we need into a customer's environment, depending on whether they have SentinelOne Singularity Endpoint through us and we manage it. We do not use the Ranger functionality because a different department manages network visibility. Singularity Complete does not necessarily lessen alerts for us as we have it tuned to only create cases in our SIEM for things that are high and critical. Although I do not have any direct metrics, I do find that it all ties into giving us the intelligence or data from detections, which get fed into our SIEM for us to take actions either in SentinelOne Singularity Endpoint or by contacting the customer. My advice for others looking into using SentinelOne Singularity Endpoint is to take advantage of the partner support portal to get trained up on it, as that will definitely help you understand it and use it to its full capability. I believe we fall under partner in terms of our business relationship with this vendor. I would rate my overall experience with SentinelOne Singularity Endpoint as an 8.
SentinelOne Singularity Endpoint is solid, and the support from the SOC is strong. We only use the Ranger functionality of SentinelOne Singularity Endpoint in a limited capacity, so I cannot speak to its ability to provide network and asset visibility or its importance to us. It is difficult to quantify whether SentinelOne Singularity Complete has helped reduce alerts, so I cannot provide specific details about it. SentinelOne Singularity Complete has helped free up our staff for other projects and tasks because we use the SOC with SentinelOne, allowing them to handle all first-line defense on detections. We do not track the reduction in our organization's Mean Time to Detect (MTTD). Similarly, we do not track the reduction in our organization's Mean Time to Respond (MTTR). My advice to others considering SentinelOne Singularity Endpoint is to ensure that you understand what is covered by support and their SLO targets. I would rate this review as a 9 out of 10.
I rate SentinelOne Singularity Endpoint a nine out of ten. I give it a nine out of ten because, having worked with all the competitors, there are others that have some more advanced features, but SentinelOne Singularity Endpoint is really wonderful. I know they make a really good product and it is one of my favorites, but it is not perfect. Regarding SentinelOne Singularity Endpoint's AI capabilities, I appreciate that feature, but I set rules manually all the time. I have never used or tried to use AI for that purpose. I prefer to use AI to ask about status and to monitor activity, but not for everything else. I have not tried using it for other purposes. In monitoring, I have used SentinelOne Singularity Endpoint and it is really wonderful; the accuracy is really high, and I trust the output completely. For me, it is really good for all the other capabilities of SentinelOne Singularity Endpoint, which I have never used outside of monitoring. I do not have knowledge about those aspects. SentinelOne Singularity Endpoint is deployed for my clients in different ways. I have a customer using the public cloud, where SentinelOne Singularity Endpoint protects a few virtual machines and containers in a Kubernetes cluster. I have other customers where it is on-premises and the agent is installed directly on physical endpoints, mostly Windows, to monitor local operating system behavior. For the public cloud deployment, my customer uses AWS. I did not purchase SentinelOne Singularity Endpoint through the AWS Marketplace; it was purchased with an Italian SentinelOne reseller. I appreciate the data ingestion correlation of SentinelOne Singularity Endpoint and the automated Storyline; all of that is really wonderful. SentinelOne Singularity Endpoint helps me connect and analyze data from multiple sources. We have made some integrations with next-generation firewalls such as Palo Alto, and there are integrations that allow us to merge the data into SentinelOne Singularity Endpoint's Data Lake, which reduces our time for data analysis because we can find everything together in SentinelOne Singularity Endpoint. SentinelOne Singularity Endpoint Complete has helped me consolidate my overall security solutions, also thanks to the automatic Storyline correlation. When Palo Alto logs go into SentinelOne Singularity Endpoint, the AI of SentinelOne Singularity Endpoint connects them to the Storyline technology. For example, one user from a company downloaded a suspicious file, which triggered the advanced threat protection of the Palo Alto firewall. All the data from Palo Alto is integrated with SentinelOne Singularity Endpoint; the AI merges the data from the computer and the firewall, allowing us to conduct a full analysis within SentinelOne Singularity Endpoint and providing a clear visual representation of how the attack or event unfolded—a diagram of the sequence of what happened during a security event. Using SentinelOne Singularity Endpoint has reduced alerts for me and my clients because the agent acts as a teacher for the user, making the good and bad status of a workstation visible to the user, which encourages them to be more careful about their actions. It is really easy for them to use; the first problem in any company is human error. SentinelOne Singularity Endpoint Complete has significantly freed up IT and SOC personnel by reducing their daily security operation workload, potentially by around thirty percent. SentinelOne Singularity Endpoint has helped reduce my organization's Mean Time to Detect. Personally, I have saved between fifteen to twenty hours every week of work, allowing me to reallocate my time to infrastructure projects and other cloud migration tasks. This has given me a lot of spare time where it is most needed. The time savings come from the very core capabilities of SentinelOne Singularity Endpoint: Zero-Touch Remediation and Rollback, automated root cause analysis via Storyline, and the mitigation of alert fatigue. The automatic capabilities of SentinelOne Singularity Endpoint have reduced the time to respond to incidents by an incredible ninety percent, and this is thanks to the automated emails sent to the security department whenever a potential incident occurs. The autonomous response capabilities of SentinelOne Singularity Endpoint, specifically Zero-Touch MTTR, allow the agent to evaluate the threat locally on the endpoint and execute immediate containment protocols without waiting for human intervention, achieving an MTTR of under one minute, which is significantly different from competitors. I do not have experience regarding pricing, setup costs, and licensing for SentinelOne Singularity Endpoint because I work in the IT and security department and do not have access to customer pricing information. I do not have information about money saved, but I can tell about time saved. In my team, I currently have fifteen free hours each week, and the other four members have reduced their work by more than twenty hours a week. My advice for others looking into using SentinelOne Singularity Endpoint is to definitely test the rollback feature in a sandbox because it is incredibly powerful, and it is truly awesome to see how quickly it works. I really appreciate this product, and I want to pursue some certification courses for SentinelOne this autumn. Overall, I rate this product a nine out of ten.
I think we have covered everything because I have mentioned many things that can improve, and I hope they will because thanks to these improvements, they will become a ten out of ten. For now, I think this is the best ADR in my opinion, so I am happy to use SentinelOne Singularity Endpoint every day in my job. I would rate this solution nine out of ten. I can give many examples in these cases. Generally, we use a lot of Microsoft Defender for Endpoint and Azure Sentinel. I think the ability of SentinelOne Singularity Endpoint to share data with other security tools is very positive. It provides APIs and integration that allow us to send endpoint detection, alerts, and security telemetry to other platforms such as Azure Sentinel, Splunk, or SOAR. This is important because we do not want endpoint security to operate in isolation. Thanks to the integration with SentinelOne Singularity Endpoint with CMDB or with other security stacks, we can correlate endpoint data with information from the cloud, identity, network, and other security sources. This helps with automation. For example, SentinelOne Singularity Endpoint detection can be forwarded to a CMDB or SOAR platform, where it can trigger additional investigation or response workflows. I would say that the integration capabilities are strong and valuable for creating a more generalized and coordinated security operation. I can say that the platform can help us for other projects because the platform automates many activities such as threat detection, alert correlation, point containment, or detection. Instead of manually investigating every single endpoint, the storyline provides the context and attack chain and allows analysts to make decisions much faster. As a result, we can dedicate more time to threat hunting team, also to security architecture and to cloud security. It has improved a lot. Of course, SentinelOne Singularity Endpoint helps us to reduce the mean time to detect because thanks to the behavioral AI that is continuously monitoring endpoints and all the activity on the endpoint and identifies the suspicious behavior in real-time, including threats that may not be detected through traditional signature-based methods. This feature is very important. Also, the storyline automatically correlates the activity so our analyst does not need to manually connect multiple events to understand an incident. We can detect and understand potential threats much earlier thanks to these two features. This helps improve our response time and helps to reduce MTTR. Regarding metrics, I can say forty to fifty percent reduction. I can estimate forty percent because some incidents before could take hours to investigate and do the remediation because you have to do several steps manually. With the storyline and automated containment, the one-click remediation and the rollback, we can handle many incidents much faster, sometimes in some minutes. I can say the time went from hours to minutes. So I would say forty percent is a good estimation. Pricing is generally positive. It is being considered a premium solution, but the pricing is typically based on the number of endpoints bought and the package on the additional capabilities selected. I think I would say the pricing is competitive considering the security capability and the automation. I would say the pricing is fair for what SentinelOne Singularity Endpoint is giving to us. Regarding specific examples and time, I can say the main benefits come from MTTD and MTTR. Thanks to the automated remediation, we now do not have to do manual investigation. These are the parts that are the most important. Regarding SentinelOne Singularity Endpoint, I can first of all suggest to invest in it because I do a lot every day. I would recommend investing time in storyline and automated remediation capability because these are some of the areas where SentinelOne Singularity Endpoint provides the most value. Additionally, it is important to connect SentinelOne Singularity Endpoint with CMDB support or cloud identity which can help to get more value from the platform and improve the incident response process. I do not just deploy the agent and the found configuration. It is necessary to configure the platform based on our environment. This is what I suggest to configure the platform based on our environment and security equipment. With the proper configuration and integration, SentinelOne Singularity Endpoint can significantly improve the detection, response time and overall frequency efficiency.
I would rate this solution almost a 10, maybe a 9 because of the price. It is not a cheap solution, but it works really well. It is a really good solution that efficiently protects your endpoints and servers. Even if the price is not as competitive as some other solutions, the functionalities are worth it. I give this product an overall rating of 9 out of 10.
I would advise others looking into using SentinelOne Singularity Endpoint to ensure they have some experts able to manage the configuration of the product because it can be really difficult to manage. I would rate SentinelOne Singularity Endpoint an eight out of ten.
SentinelOne Singularity Endpoint has helped to consolidate our security solutions. It has acted promptly on attempted attacks, such as worms, some Trojans, and many spyware. It blocks everything. Ranger AD is used, but not by my team. It is used by another team. SentinelOne Singularity Endpoint has helped reduce alerts, but it depends. At the beginning, it was very noisy, generating many alerts, but after some tuning and creating exclusions, it stopped making noise. The solution has helped reduce the Mean Time to Detect in my organization by half an hour. My advice to other people who are considering using SentinelOne Singularity Endpoint is that the console is very intuitive, and I recommend getting hands-on. Check out the endpoint inventory side and the alert side, understand how to examine an alert, check through Purple AI, study the details carefully, cross-check the data with VirusTotal, and analyze the alerts and the data provided by the alert thoroughly. I rate this product an eight out of ten.
For a long time, SentinelOne Singularity Endpoint is effective at correlating my security solutions, allowing for customization of rules based on requirements. SentinelOne Complete did not reduce alerts; instead, it increased noise in the environment until fine-tunings were done for customized rules. As of now, I have not seen a significant freeing up of staff for other projects due to SentinelOne Singularity Endpoint. We are not using SentinelOne Singularity Endpoint for network and asset visibilities. Regarding organizational MTTD and MTTR, this is at a moderate level. My advice for others looking into using SentinelOne Singularity Endpoint is to go for it, as it effectively does the EDR job. I would rate this product an 8 out of 10.
I advise others looking into using SentinelOne Singularity Endpoint to use this tool because it provides a comprehensive solution. It is very effective and if your organization does not require too many personnel, it is one of the best tools for you. I do not have any additional thoughts about SentinelOne Singularity Endpoint other than that it is a very good tool that provides us with a feasible and wonderful solution. I give this review a rating of nine.
I am using the SaaS deployment model for SentinelOne. Ranger is important because it gives me visibility into how many devices in my network are unprotected. It provides security posture information showing how many detections exist, how many devices are protected, and how many are not. It gives an overview of what devices need protection and allows me to review why certain devices are not protected and identify any limitations. The company name is SentinelOne. I use Purple AI in SentinelOne. Purple AI is an AI developed by SentinelOne that helps me correlate or build queries for those who have not used SentinelOne Singularity Endpoint before. It also provides information about the product without sharing confidential information. SentinelOne has a policy ensuring that all data and queries are kept internally and not shared with any third party. Regarding workflow, Purple AI helps overall in my day-to-day operations by assisting with how alerts are triggered, retrieving results for alerts, providing alert descriptions from connected devices, and helping mitigate threats. I gave this review a rating of 8 out of 10.
Purple AI is designed with data privacy and security in mind, ensuring that customer data is processed according to compliance requirements, which allows organizations to maintain control over their data while using AI-powered assistance for threat investigations and analysis. My overall rating for this product is eight out of ten.
I primarily use the AI capabilities in SentinelOne Singularity Endpoint for endpoint detections, threat analysis, and threat hunting. I have not extensively used the AI capabilities, so I do not have much experience to share or feedback regarding its accuracy and reliability. My review rating for this product is 8.
I do recommend SentinelOne Singularity Endpoint to other users as part of my day-to-day responsibilities. I have given this review an overall rating of eight out of ten.
For the overall SentinelOne Singularity Endpoint, I would give a score of eight for the whole product. Regarding the price point of SentinelOne Singularity Endpoint, I do not know the exact number, but I have come from the community and attended many events. As far as the cost is concerned, before the CrowdStrike blue screen attack, CrowdStrike pricing was far more increased rather than SentinelOne. After the CrowdStrike shares decreased due to the blue screen attack, they are very competitive with SentinelOne nowadays. The impact of Purple AI on investigations ultimately depends on what incident I got. I do not think the analyst should rely completely on Purple AI because there are many hashes or threats that are not publicly available. If things are not publicly available or not learned by the AI, I do not think I should rely completely on Purple AI. If I have any sort of data and see any pattern from my analyst's perspective, I can completely tell Purple AI that I think it can demonstrate the storyline that I am right. Based on that, I can take a decision, but I should not rely on the decision solely on Purple AI. My overall rating for this product is eight out of ten.
SentinelOne Singularity Endpoint provides alerting into the dashboard, but I did not configure it correctly and never received alerts over emails. If such a feature exists within the product, that would be awesome, and I could incorporate and configure it. Currently, I do not have visibility on it. Once I log into SentinelOne Singularity Endpoint, it provides visibility within the dashboard showing how many endpoints have been detected as infected, how many endpoints are impacted, and how many endpoints have been identified as malware where SentinelOne Singularity Endpoint has quarantined those files, and I can do analysis and further processing. However, currently, I did not configure it if it is available, but I am unable to navigate it. I do not have visibility on whether any endpoints or target machines have been impacted so that I receive email notifications or SMS notifications alerting me that a machine has been impacted and needs to be worked on urgently. This is a critical function I need to perform right now. If this would be configurable or is available in SentinelOne Singularity Endpoint, that is awesome. If not, then the alerting mechanism needs to be improved to get alerts over emails or SMS for at minimum critical assets. I can say that I currently did not implement it in such a way because for what I am using SentinelOne Singularity Endpoint for, it is the on-premises infrastructure for some organizations and just for endpoints in other organizations. In that case, I believe for SaaS products, I am currently not utilizing it for such things. My question is whether SentinelOne Singularity Endpoint is an agent-based solution that I can only utilize on endpoints or servers or where the operating system is Linux or different flavors where the operating system is running. However, for the serverless environment, SentinelOne Singularity Endpoint cannot work. Is that the right expectation? Obviously, the core concern is about data protection and privacy. There is something I have to adopt with AI. If I do not adopt it, I am not running with the market and chasing new goals. The thing is I have to implement frameworks such as ISO 42001 to manage data and contain my data's confidentiality and privacy. This is core importance for me in my job role. I take care of this all the time, and obviously if I am integrating solutions that utilize AI-based features into their product, I do have vendor management or vendor risk management to perform with vendors. I currently look into AI standards or framework implementation within organizations if they are providing me with full core data security. This is the point I engage in with existing and onboarding vendors. Additionally, I am currently utilizing AI and making AI models within my organizations. I implement security standards and maintain the whole implementation and operationalization of data protections within AI models and machine learning models. This is the function that can be adopted, and if it is in the product, obviously this is a positive point and I do encourage that utilization of AI models within products. As I mentioned, if I got email alerts or SMS alerts for critical systems and if AI has been engaged into threat modeling with well-known algorithms that identify what threats, viruses, or malicious insights have been identified in the system, and if AI can guess that certain operating systems, files, or things are critical to my organization and can do this on a real-time basis, that would be a positive point. Obviously, as I mentioned, if I want to run with the market, I have to integrate those AI threat modeling or AI remediations within my organization. I have to do that. I give this review an overall rating of eight out of ten.
With SentinelOne Singularity Endpoint, we have detected incidents that triggered alerts, and we can raise them within a maximum time of 10 to 15 minutes later. I recommend blocking the connection and taking other necessary actions. The importance of the Secret Scanning feature in SentinelOne Singularity Endpoint is significant because it scans newly engaged endpoints for malicious activities. It detects harmful EXE files or suspicious abnormal behaviors, ensuring the health of our endpoints is maintained. I recommend implementing SentinelOne Singularity Endpoint because the integration part is very simple and suited for small organizations. It is reasonably priced, and the installation of the endpoint on the client side takes only two to three minutes. I can also explain how it compares with other endpoints and the types of alerts generated, making it suitable for potential clients. Deep visibility, full disk scan, and rollback features are impressive, especially in cases of ransomware attacks. The rollback feature helps easily revert to a safe state prior to attacks, while the full disk scan ensures that all machines are scanned for threats, thus maintaining endpoint health.
I do not use the Ranger functionality because I am an L1 and I have only read-only access, but I know the functionality. The main function is network discovery and control, which identifies and manages unmanaged devices on the network and detects rogue devices on the system. Before I joined, I can say my organization reduced alerts by 30-40% due to integrating multiple devices with SentinelOne Singularity Endpoint, impacting mostly the false positive alerts. Data privacy and security with Purple AI are important for my organization; the co-pilot feature of Purple AI helps pull down any IOC present in my network, allowing me to identify any IOC, hash, vulnerability, or malicious activities that occur. I am the only SOC analyst L1, and while my organization has an investigating team that uses Purple AI mainly for investigation and threat hunting purposes, I have only used it for basic commands and queries for investigation. My clients are medium-sized, not exceeding 2,000 to 4,000 crore companies. If you are considering implementing SentinelOne Singularity Endpoint in your organization, I have several recommendations: first, train the SOC team, especially if there are new joiners; second, start with a pilot deployment rather than deploying to all endpoints; third, integrate SentinelOne Singularity Endpoint with other products such as SIM tools or SOAR tools to realize the true value of SentinelOne Singularity Endpoint; using it alone will not provide its full potential. I would rate this solution a nine out of ten overall.
SentinelOne Singularity Endpoint has helped reduce alerts for us by almost 50%. Before implementing it, my colleague told me that we were using an AV, but I do not have knowledge about which AV it was. After using SentinelOne Singularity platform, the time has reduced by 50%. There is up to 30 to 40% mean time reduction in MTTD. For mean time to resolve, whenever we get the alert from the console, we integrate SentinelOne Singularity with a sub-console, so it raises the alert within five minutes. I would rate this solution a 9 out of 10 overall.
I do not have anything else to add about my main use case or how SentinelOne Singularity Endpoint fits into my workflow. The unified platform experience certainly helps streamline our security operations, making things easier for my team. In terms of adaptability to new and unknown threats, I believe SentinelOne Singularity Endpoint is the tool I have used the most, and while I cannot compare right now since I have only used CrowdStrike once, I find SentinelOne Singularity Endpoint easier to use than CrowdStrike. I was not aware of the possibility to use an Offensive Security Engine, but I will seek more information on it. Having built-in integrations that unify various aspects of cloud security is very significant for my team, as it makes everything easier to manage. I advise others looking into SentinelOne Singularity Endpoint to check the ease of usage of the tool, as the platform is very helpful and the protection it provides is truly exceptional. I have given this review a rating of 10.
Purple AI is a tool I have used because we have the analyst access. I had limited access to Purple AI, but I have used it for finding the IOC in our networks and our customers' networks. It is a co-pilot feature where I can use a pull-down menu to identify based on the present IOC. The retrieve time is very fast, and we get the answer within five to ten seconds. We have IOC, zero-day vulnerability, or any other hashes present in our network. Because I am an L1 analyst, we have a forensic analyst team also, and they are using Purple AI. This tool is very helpful for our forensic team. SentinelOne Singularity Endpoint is reducing our time because we do not have that access to Purple AI. SentinelOne Singularity Endpoint is reducing our time to find the IOC in the organization. I gave this review an overall rating of 10 out of 10.
I would recommend SentinelOne Singularity Endpoint to other users because its threat detection and alerting are very quick. We have used CrowdStrike for one and a half months, but SentinelOne Singularity Endpoint triggers alerts much faster. Its compact features allow us to check seven to eight features effectively, and its pricing is lower than other EDR products. SentinelOne Singularity Endpoint has better pricing compared to other endpoints. CrowdStrike has a high value, but SentinelOne Singularity Endpoint's pricing is easier for any organization to handle. Regarding maintenance, there is no need for maintenance according to me. I give this product an overall rating of 10 out of 10.
In terms of consolidating our security solutions, I would rate SentinelOne Singularity Endpoint a 9 out of 10 because it meets all our use cases effectively. It provides granular insights into endpoints and comes with feature roadmaps, including AI security analysis that helps us understand the usage of shadow AI in our environment, vulnerabilities, and overall system alerts. This functionality allows us to monitor how many threats were remediated and triggered, significantly enhancing our security posture. We assessed the Ranger functionality a few months ago; we activated it for a trial and subsequently turned it off. During activation, it scanned our network for shadow endpoints without SentinelOne Singularity Endpoint, identifying devices such as printers or scanners, and provided insights into unknown devices on our network, offering valuable reports through the Singularity dashboard. Although we have not yet activated Purple AI, the guidance provided when alerts occur is helpful, summarizing what triggered the alerts and offering analysis steps for our small team, providing high-level alert overviews. I rate this review a 10 out of 10.
We are managing 7,000 to 8,000 endpoints for clients, and the setup is very easy. I have given SentinelOne Singularity Complete an overall review rating of 10 out of 10.
In our environment, we do use Purple AI as part of SentinelOne Singularity Complete to help with threat analysis, investigation workflows, and speeding up the incident triage. Purple AI acts as an AI-powered security analyst, helping translate complex data into actionable insights and enabling faster threat hunting and investigation across our endpoint security data. Purple AI plays a critical role in amplifying our team knowledge by helping us interpret alerts, investigate threats, and identify patterns across endpoints quickly. It essentially amplifies our team's knowledge by providing contextual insights, suggesting remediation steps, and correlating between security events that might otherwise be missed. SentinelOne Singularity Complete has significantly reduced the number of alerts our IT team has to handle manually. By leveraging AI-driven behavior analysis and automated threat automation, low-risk or duplicate alerts are filtered out, allowing the team to focus on the most critical incidents. In our experience, the platform has reduced actionable alerts by fifty to sixty percent. SentinelOne Singularity Complete has significantly reduced our organization's mean time to detect. With real-time AI-driven detection, automatic alerts, and behavioral analysis, threats are identified almost immediately upon occurrence. In our environment, we have observed that mean time to detect has improved by approximately sixty to seventy percent, meaning our IT team can detect and respond to incidents much faster than before. The rapid detection has been critical in preventing escalation and minimizing potential impact on end-user systems. SentinelOne Singularity Complete has significantly reduced our organization's mean time to respond, thanks to automated remediation, rollback capabilities, and prioritized alerts. Our IT team can respond to incidents almost immediately. Mean time to respond has been reduced by approximately sixty-two percent, allowing threats to be contained and resolved in minutes rather than hours. For others looking into using SentinelOne Singularity Complete, I advise utilizing the Purple AI summarization. The alert without much manual investigation allows us to determine if it is a true positive or not by seeing the Purple AI alert summarization, what happened, what process, activity, and what the underlying behavior is. Overall, SentinelOne Singularity Complete is highly effective, but organizations get the most value when they combine automation, AI, incident, and proactive management. Regularly reviewing the report with audit features is valuable for complete tracking of trends. Utilize the AI-driven insight to amplify your team knowledge and reduce alert fatigue. Planning for deployment across sites if you have multiple locations is essential, as is planning your policy and endpoint coverage for centralized management. I rate this solution a nine out of ten.
From a features perspective, there are no missing functionalities in Singularity Platform; the features are quite good for now. The overall review rating for Singularity Platform is 8.
Regarding Singularity Platform's real-time personalization feature, it does help with my customer experience strategies because, in my personal experience, I have taken a role as Treasury Manager and I am dealing with investment accounts every day. To do all that work manually compared to any type of platform work is pretty painful, so I would say anything in an automated space for any investment, any company with a bunch of investments in a portfolio, Singularity Platform is an option. Singularity Platform does help with fraud detection in the financial services as it has rules involved for risk management. If there was a purchase done, the way Singularity Platform works is it is fed in the custodian feeds as well as the bank feeds. There is no current trading platform associated with it, but there may be things in the works that will include a trading platform. I would say that there is a compliance module within Singularity Platform that helps clients determine if they want to remix their portfolio balances to stay compliant with whatever loan agreements they may have. Regarding Singularity Platform's customizable dashboards, I believe they help optimize operational efficiency. Since my role was really behind the scenes, not as a developer but on the QA implementation side of things, I believe any platform that can customize for any client will actually help them in the long run. I believe that having reports that are unique to each individual client helps them in their own way, so whatever reduces the manual workload for the client, especially customizing UI, is a good idea. I would absolutely recommend Singularity Platform to other users, but it depends on what their expectations are for the investment accounting software they plan to implement. For a smaller size insurance company, I believe that is fine. However, there are things that Singularity Platform cannot do that Clearwater does, and I am sure there are things that Clearwater does not do that Singularity Platform does. Therefore, it is hard to say definitively; it really depends on the client's needs. For a full-blown investment accounting and reporting system, I would still recommend Clearwater over SS&C. In terms of asset management and banking solutions, I cannot really respond because I believe SS&C and Clearwater probably have the same application capabilities. I would rate this solution a seven out of ten overall.
Singularity Platform functions as a security information and event management solution, and that is an inbuilt part of it. I believe in the correlations that I get because we work on it, but we don't use the Purple AI part of it. I'm not able to get clarity regarding the real-time personalization feature in Singularity Platform. I do not use the real-time personalization feature in Singularity Platform. It is a matter of false positives when people use it in my area. Regarding the impact of Singularity Platform on supply chain processes, I don't have much on it, but it's a good product and the tracking is better with the log capturing and the data that we get from it. The customer does require customizations on the dashboards as per the requirement of their organizations; if it's manufacturing, medical, or financial institution or banking, then they will have different requirements for their dashboards, which are yet not available, so we have to actually build up those dashboards for them. I can recommend Singularity Platform to other users. I have provided this review a rating of 9.
Regarding Singularity Platform, I would go for the platform. I am most familiar with that one. I do not currently know what version of Singularity Platform I am using. I will have to check. Probably I am using the latest version because we have automatic updates. We are not using the fraud detection feature in financial services, as we are not doing any financial services. Regarding Singularity Platform's real-time personalization feature, we are using it. Overall, if I had to rate Singularity Platform from one to ten, I think an eight would be appropriate. It is quite up to our standards. I would rate this review an eight overall.
I would rate Singularity Platform a nine out of ten.