Listing Thumbnail

    SentinelOne Singularity Platform

     Info
    Sold by: SentinelOne 
    Deployed on AWS
    Vendor Insights
    Unlock enterprise-wide security for your AWS environment with SentinelOne Singularity Platform. This AI-powered solution provides real-time threat detection and automated response across your infrastructure, ensuring continuous protection at infinite scale. By autonomously securing endpoints, cloud workloads, and identity, SentinelOne delivers total visibility while eliminating security silos. Integrate seamlessly with AWS and leverage our unified data lake and Purple AI to accelerate investigations and gain deeper insights. Secure your AWS cloud and focus on innovation with the speed and efficiency of AI.
    4.6

    Overview

    Play video

    The SentinelOne Singularity Platform is the industry's first AI-powered security solution for the modern enterprise, offering a unified defense across your entire infrastructure from endpoints and cloud workloads to identity. As cloud adoption accelerates, traditional, siloed security tools create complexity and leave gaps in protection. Our platform consolidates multiple security capabilities into a single, intelligent solution, providing AWS customers with real-time visibility and autonomous protection to simplify security operations and reduce risk.

    Core Capabilities & Benefits

    Autonomous Protection: Singularity Platform is designed for customers seeking enterprise-wide protection, detection, and response capabilities, augmented by the intelligence and speed of advanced AI and automation. SentinelOne's Singularity Platform protects thousands of customer environments, including Amazon cloud workloads, across the globe.

    Unified Visibility: Break down data silos and security tool sprawl. Using patented Storyline™ technology, the platform automatically correlates and contextually groups related events into a single attack story, providing a consolidated view for faster investigation and response within our unified data lake.

    Extended Detection & Response (XDR): Gain a complete, correlated view of the full attack story across endpoints, identities, and cloud workloads. Our XDR solution provides the context needed to understand and respond to threats at machine speed.

    Cloud Workload Protection Platform (CWPP): Secure your AWS compute resources from runtime threats. Our Singularity Cloud Workload Security delivers real-time, AI-powered threat detection and response for Amazon EC2 instances, EKS clusters, and AWS Fargate. It provides deep visibility into vulnerabilities and configuration risk while autonomously blocking malware, ransomware, and fileless attacks without disrupting production performance.

    Identity Threat Detection & Response (ITDR): Proactively defend against credential theft, privilege escalation, and lateral movement attacks across hybrid environments. Our solution provides continuous monitoring and protection for Active Directory and leading cloud identity providers, including Entra ID, Okta, Ping, SecureAuth, and Duo, ensuring identity infrastructure remains secure.

    Accelerated Incident Response with Generative AI: Purple AI, our generative AI security analyst, acts as a force multiplier for your security team. It automates threat hunting, provides instant summaries of complex incidents, and accelerates investigations, allowing your team to focus on strategic initiatives.

    Seamless Integration with AWS Services

    The SentinelOne Singularity Platform is designed for seamless integration into your existing AWS environment. We provide bidirectional integrations for AWS Security Hub and Amazon CloudWatch, ensuring your security findings are centralized and actionable. Additionally, our AI-powered malware scanning for Amazon S3 protects sensitive data while maintaining compliance, helping you maximize your AWS investment and enhance your overall security posture.

    How to Get Started

    Secure your AWS cloud and focus on innovation with the SentinelOne Singularity Platform. Simply click on the Request private offer button at the top of this page to begin your procurement process.

    Highlights

    • 338% three-year ROI for SentinelOne customers using Purple AI, included with SentinelOne Singularity Platform Complete
    • 96% of Gartner Peer Insights™ EDR reviewers recommend SentinelOne Singularity
    • 5-Consecutive Year Gartner® Magic Quadrant™ Leader for Endpoint Protection Platforms

    Details

    Delivery method

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Trust Center

    Trust Center
    Access real-time vendor security and compliance information through their Trust Center powered by Drata or Vanta. Review certifications and security standards before purchase.

    Buyer guide

    Gain valuable insights from real users who purchased this product, powered by PeerSpot.
    Buyer guide

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Vendor Insights

     Info
    Skip the manual risk assessment. Get verified and regularly updated security info on this product with Vendor Insights.
    Security credentials achieved
    (1)

    Pricing

    SentinelOne Singularity Platform

     Info
    Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    1-month contract (1)

     Info
    Dimension
    Description
    Cost/month
    Custom Pricing and Packaging
    Contact SentinelOne for custom pricing and packaging including Private Offers
    $10,000.00

    Vendor refund policy

    Refunds available as required by law.

    Custom pricing options

    Request a private offer to receive a custom quote.

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Software as a Service (SaaS)

    SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.

    Support

    Vendor support

    Multiple support options available. Email support available: support@sentinelone.com 

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Product comparison

     Info
    Updated weekly

    Accolades

     Info
    Top
    10
    In Generative AI, Security Observability

    Customer reviews

     Info
    Sentiment is AI generated from actual customer reviews on AWS and G2
    Reviews
    Functionality
    Ease of use
    Customer service
    Cost effectiveness
    4 reviews
    Insufficient data
    Positive reviews
    Mixed reviews
    Negative reviews

    Overview

     Info
    AI generated from product descriptions
    AI-Powered Threat Detection and Response
    Real-time threat detection and automated response capabilities augmented by advanced AI and automation across endpoints, cloud workloads, and identity infrastructure.
    Cloud Workload Protection
    Runtime threat protection for Amazon EC2 instances, EKS clusters, and AWS Fargate with autonomous blocking of malware, ransomware, and fileless attacks.
    Extended Detection and Response
    Correlated view of full attack stories across endpoints, identities, and cloud workloads using patented Storyline technology to automatically correlate and contextually group related events.
    Identity Threat Detection and Response
    Continuous monitoring and protection against credential theft, privilege escalation, and lateral movement attacks across Active Directory and cloud identity providers including Entra ID, Okta, Ping, SecureAuth, and Duo.
    Generative AI Security Analysis
    Generative AI security analyst that automates threat hunting, provides incident summaries, and accelerates investigations through machine-speed analysis.
    Multi-Source Threat Data Integration
    Correlates security events from Trellix Security Platform and over 500 third-party tools including 13 AWS integrations to create unified threat visibility across the security stack.
    AI-Driven Alert Triage and Prioritization
    Applies artificial intelligence-driven analytics to perform 100% alert triage, prioritize threats, and provide GenAI-powered insights for threat investigation and remediation guidance.
    No-Code Automation for Investigation and Response
    Provides UI-driven, point-and-click automation capabilities to offload repetitive security operations tasks and accelerate investigation and response workflows.
    Pre-Built Analytics and Correlation Rules
    Ingests data from multiple sources and correlates events using pre-built analytics and rules to reconstruct complete attack narratives and reduce manual investigation pivots.
    Multi-Deployment Architecture Support
    Supports cloud, hybrid, and air-gapped deployment models with an open integration ecosystem for flexible security infrastructure configurations.
    Multi-Domain Attack Detection
    AI-powered detections that expose attacker activity across network, identity, and cloud environments including data centers, campuses, remote work, IoT/OT, AWS, Microsoft Active Directory, Microsoft Entra ID, Microsoft Azure, and Microsoft 365.
    Automated Alert Triage and Correlation
    AI agents that automatically triage, stitch, and prioritize attacks in real time, removing up to 99% of alert noise and reducing manual task time by up to 50%.
    Unified Investigation and Response Interface
    Centralized response user experience that enables discovery, hunting, detection, investigation, and automated response capabilities with aggregated and contextualized views of attack progression across network, identity, and cloud.
    Network Detection and Response
    Dedicated network detection and response (NDR) module for monitoring and detecting malicious activity across network infrastructure.
    Multi-Cloud and Identity Platform Coverage
    Modular architecture supporting AWS, Microsoft Azure, Microsoft 365, Microsoft Active Directory, and Microsoft Entra ID with configurable metadata retention periods ranging from 14 to 90 days.

    Security credentials

     Info
    Validated by AWS Marketplace
    FedRAMP
    GDPR
    HIPAA
    ISO/IEC 27001
    PCI DSS
    SOC 2 Type 2
    -
    -
    -
    -
    -
    No security profile
    No security profile

    Contract

     Info
    Standard contract
    No
    No
    No

    Customer reviews

    Ratings and reviews

     Info
    4.6
    380 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    76%
    21%
    1%
    1%
    1%
    38 AWS reviews
    |
    342 external reviews
    External reviews are from G2  and PeerSpot .
    Dinesh Yadav

    Security monitoring has improved and current endpoint deployments run smoothly for customers

    Reviewed on Jun 26, 2026
    Review provided by PeerSpot

    What is our primary use case?

    I use SentinelOne Singularity Endpoint  for my customers.

    I help our customers implement SentinelOne Singularity Endpoint  because its initial setup is straightforward and not complicated. However, there are cases where they are not integrated with Active Directory, so I assist them by sending the link or email to the end user so they can download the agent, and the rest can be done through the console.

    My customers purchase SentinelOne Singularity Endpoint from us. I place the order with SentinelOne distributors because local support is more important for customers, and they want to be locally supported by resellers or vendors. If you buy from AWS , then there will not be any support.

    What is most valuable?

    My experience working with SentinelOne Singularity Endpoint has been fantastic.

    The most valuable features I have found in SentinelOne Singularity Endpoint are MITRE ATT&CK, continuous monitoring, and threat vectors.

    What needs improvement?

    The drawbacks I have identified with SentinelOne Singularity Endpoint are that they should work on being more responsive than CrowdStrike. CrowdStrike has a very strong team here in the Middle East and they are very frequently available to discuss any kind of issues or challenges. In comparison to these, they are a bit slow.

    I think in the next release of SentinelOne Singularity Endpoint, they should be working on a SIEM  solution so that customers can have data logs for 30 days or 90 days.

    SentinelOne Singularity Endpoint's R&D team should learn from CrowdStrike's approach, looking at the technologies that protect endpoints, customer protection, and providing extra features that customers can utilize and be loyal to them. For example, CrowdStrike gives seven days data retrieval for end users in the SIEM  without any charges. If SentinelOne does something similar, they might gain more loyalty and more customers.

    For how long have I used the solution?

    I have been dealing with SentinelOne Singularity Endpoint for more than five to six years.

    What do I think about the stability of the solution?

    When it comes to functionalities and performance, SentinelOne Singularity Endpoint is fine, and there are not many issues with SentinelOne Singularity Endpoint products once deployed.

    How are customer service and support?

    I would rate their technical support around a nine out of ten. Every solution has some kind of drawback, but it is a pretty good score.

    How was the initial setup?

    Its initial setup is straightforward and not complicated. However, there are cases where they are not integrated with Active Directory, so I have to assist them by sending the link or email to the end user so they can download the agent, and the rest can be done through the console.

    What's my experience with pricing, setup cost, and licensing?

    I find SentinelOne Singularity Endpoint's pricing to be competitive because if I look at the pricing of CrowdStrike, they are competitive to CrowdStrike.

    Which other solutions did I evaluate?

    I cannot say SentinelOne Singularity Endpoint is the best option on the market at the moment, but I can say it is the second best. If I look at CrowdStrike, they have many other features and come with various other solutions including identity protection, SIEM, data protection, and firewall management. In terms of technology, SentinelOne is doing good and very competitive in the market, but CrowdStrike is still ahead of them.

    What other advice do I have?

    I have not gone through SentinelOne Singularity Endpoint's Purple AI  that much. I believe it is an AI feature. It is similar to all other AIs where you can ask questions about technical issues or challenges through the portal and it can access security, indicating if any configuration is missing or if there are any attacks or vectors, or if some users are inactive for longer periods. This can help them keep track of users in case some are offline for longer days or if their agent has not been updated. I would rate this review an eight out of ten.

    AbhishekVilas Sawant

    Automated threat response has freed our security team to focus on high‑value client projects

    Reviewed on Jun 22, 2026
    Review from a verified AWS customer

    What is our primary use case?

    My use case with SentinelOne Singularity Endpoint  is primarily for security purposes, to secure our clients from different malware. If they download any suspicious file onto their desktop which creates a problem afterwards, then for that purpose, we are basically using this. We are basically an MSSP , providing services to our clients.

    What is most valuable?

    The features and functions in SentinelOne Singularity Endpoint  that I have found most valuable include its fully autonomous nature. We don't have to put manual effort into that. Basically, mostly everything is automated, and also the threat detection feature, the rule remediation feature, and the rollback as I mentioned earlier. If anything comes out to be clean and genuine, then we can just do the rollback so that everything gets back to normal and keeps on running. I feel that is the foremost thing I appreciate: having a fast response and rollback capability.

    Singularity  Complete has helped me reduce the number of alerts. Although I would say that it is a depreciating factor when it comes to false-positive alerts. Initially, it generates a very high number of false-positive alerts, but by using it accordingly, very prominently, we can control the false-positive alerts by deploying only the necessary use cases that our clients need to detect only true-positive alerts rather than false-positive noises.

    Singularity  Complete helps my clients free up staff for other projects. I also mentioned earlier that it is fully autonomous. Every feature is automated. It does its work on its own by doing the quarantine. Any malicious thing it detects, its rule engine, which is obviously a behavioral AI. Because everything is automated, it decreases our manual effort. Rather than typing a manual email to a client, which obviously takes fifteen to twenty minutes extra, we are just taking action directly from the SentinelOne Singularity Endpoint user interface. So it reduces our manual effort and time overall.

    What needs improvement?

    Regarding potential areas for improvement for SentinelOne Singularity Endpoint, as I mentioned earlier, I felt that it was generating a very high number of false-positive alerts initially. Although by making a few changes, we reduced that. The first thing is the false-positive alerts. Also, I've felt that a few of our clients have a very high number of endpoints integrated, such as more than one thousand endpoints have been deployed for those particular clients. For those kinds of clients, I've felt that the resource consumption, including high CPU and disk utilization, is a factor. The utilization sometimes gets very high, so we have to keep it in control and monitor it from time to time. One more thing is creating a customized dashboard, which is not a feature in SentinelOne Singularity Endpoint. We can only view their existing dashboard. No custom dashboard feature is present in SentinelOne Singularity Endpoint, so that's also something that can be brought up in the future.

    For how long have I used the solution?

    I've been working with SentinelOne Singularity Endpoint product for about a year.

    What do I think about the stability of the solution?

    Stability-wise, I would rate SentinelOne Singularity Endpoint a nine out of ten.

    What do I think about the scalability of the solution?

    I would say ten out of ten for the scalability of SentinelOne Singularity Endpoint because we can scale up and scale down as per requirement. We can increase or decrease the number of endpoints, whatever suits perfectly at that particular time.

    How are customer service and support?

    I would rate SentinelOne's technical support ten out of ten. There have been a number of times when we get in contact with their OEM, the customer support. Their response is very quick. Within a day, we get a response from them. There are a number of times we get stuck in creating a use case or doing whitelisting, blacklisting, or deploying rules. At that particular time, we contact customer support, and we get their response very quickly.

    How was the initial setup?

    The initial setup for SentinelOne Singularity Endpoint is much simpler, although I have not been a part of the integration team. First, we have to allow SentinelOne Singularity Endpoint on a desktop, then we have to install its endpoint on the desktop or laptop.

    Which other solutions did I evaluate?

    The main competitor on the market for SentinelOne Singularity Endpoint can be CrowdStrike Falcon . I have not used that product, but I do know that the price range SentinelOne is offering is the best, as Falcon  CrowdStrike is much more expensive.

    What other advice do I have?

    My experience with SentinelOne Singularity Endpoint's ability to ingest and correlate data across security solutions is great because we personally have integrated SentinelOne Singularity Endpoint with a different product and deployed a few correlation use cases. By doing that, we strengthen our use cases, correlating it with different email security solutions. It's been great doing that correlation.

    The Mean Time To Respond automatically decreases because everything has been already completed by the AI engine running in the background.

    I have limited experience with Purple AI , but I have used some of the features, including identifying IOCs (Indicators of Compromise) in Purple AI  and a few other features as well.

    Regarding Purple AI's capabilities in threat intelligence for detecting threats, IOCs are utilized for that purpose. By using the copilot feature in Purple AI, where I can use the pull-down menu on the left-hand side, from there I can get the IOCs present on my client's endpoint. By doing that, I can gather threat intelligence on our clients' endpoints.

    In my opinion, the main benefits that SentinelOne Singularity Endpoint provides are many. I would say it's already a valuable security device. I can literally line up different things that SentinelOne is offering. Obviously, the foremost thing is for security purposes. You are securing your own desktop, laptop, or whatever server it is. And also, what you are getting at such a low price, I would say. The foremost thing you are getting is the best that anyone can offer. So that's what I would say about SentinelOne Singularity Endpoint.

    I have not personally used the Ranger functionality because it has been blocked in our environment, but I am aware of the Ranger functionality that SentinelOne is providing for network security purposes.

    Regarding Mean Time To Detect (MTTD), if I compare it with other SIEM  solutions, what does that SIEM  solution do? It just detects an alert and gives a pop-up that the threat is detected in an environment. But comparing it with SentinelOne Singularity Endpoint, it is doing its work on its own. So, it's very useful compared to other solutions.

    I will recommend SentinelOne Singularity Endpoint to other users. I would rate this product ten out of ten overall.

    Anish Varma

    Automated endpoint protection has reduced manual effort and improves real-time threat response

    Reviewed on Jun 19, 2026
    Review provided by PeerSpot

    What is our primary use case?

    We are working for SentinelOne Singularity Endpoint . We are using SentinelOne Singularity Endpoint  for endpoint detection to detect any suspicious malware detected in any PDF or file that users download and access. SentinelOne Singularity Endpoint marks suspicious or malicious files and takes appropriate action by quarantining that file in real time. This is the basic purpose that we are using SentinelOne Singularity Endpoint for.

    We have integrated SentinelOne Singularity Endpoint with third-party tools such as our ManageEngine ticketing portal and a few other security devices. It works very well and we have not faced any issues yet.

    What is most valuable?

    The foremost thing would be that the response is very fast, and capability-wise, it is highly capable. Its automated features, behavioral analysis, and machine learning features are numerous, and I feel SentinelOne Singularity Endpoint is best for these aspects.

    SentinelOne Singularity Endpoint has a faster response, so the mean time to detect is remarkably better than other products. This has improved the overall productivity for our organization, which is a plus point using SentinelOne Singularity Endpoint.

    Because it is fully automated, the moment any threat is detected on any file or system, that very second it marks the alert and takes appropriate automated action on it. If any manual human intervention is required, then we, the analysts, are responsible for drafting a mail to our client. This has overall reduced our manual effort significantly, making it very beneficial.

    What needs improvement?

    I feel that it can be much better. Initially, it creates a lot of false positive alerts, which can be improved. SentinelOne Singularity Endpoint does not have any custom dashboard feature, so adding that would be better for us. We could create our own customized dashboard rather than using the default dashboard that SentinelOne Singularity Endpoint has.

    Regarding CPU utilization, in a few of our clients, we have observed that the disk usage and utilization gets very high because they have lots of endpoints integrated on that particular client. This can be improved in that scenario as well.

    For how long have I used the solution?

    It has been a few months that I have been using SentinelOne Singularity Endpoint, and I have had a great experience with it.

    What do I think about the stability of the solution?

    As far as I am concerned, I have not seen any downtime in SentinelOne Singularity Endpoint. There has not been any scenario where we have to wait to see whenever the device gets back up and running. There has not been any issue on that.

    What do I think about the scalability of the solution?

    It is very much scalable. SentinelOne Singularity Endpoint charges on a per-endpoint basis, so whatever the requirement is, it charges the client on that basis. We can scale up and scale down whenever we want. If we want to scale up to a higher endpoint, then it is very much easy to scale up and scale down.

    How are customer service and support?

    There have been a number of scenarios where I have felt that this is not my area of expertise to manage. In those kinds of times, I have been connected with the OEM and the customer support team of SentinelOne Singularity Endpoint. These scenarios include when creating a new rule or finding out IOCs on a client's endpoint. I would rate the customer support a 10 out of 10 because their response was very quick, within a day.

    Which solution did I use previously and why did I switch?

    I have not been aware of other EDR or XDR  solutions. This is my first EDR endpoint detection response team, so I am not aware of what other vendors are providing.

    How was the initial setup?

    From what I am aware of, the deployment is very easy. You just have to install SentinelOne Singularity Endpoint agent on the desktop, laptop, server, or whatever device it is. Before installing, we have to allow its IP address and port in the firewall for better services. After that, we have to install SentinelOne Singularity Endpoint on the desktop and laptop.

    What was our ROI?

    Our return on investment is very much high. Our company is basically an MSSP , and we are providing managed services to our clients. By using SentinelOne Singularity Endpoint and providing its features to our clients, our company makes a huge amount of money. It is a great return of investment for our organization.

    What's my experience with pricing, setup cost, and licensing?

    What SentinelOne Singularity Endpoint is offering for the price range is very remarkable. They are pricing on the basis of per endpoint. They charge around six to ten dollars based on the required amount of endpoints that are necessary. At this price range, the type of solution we are getting is the best that we can ask for.

    What other advice do I have?

    We have a dedicated threat hunting team for that kind of thing, so I have never been a part of that threat hunting procedure in our team.

    The analytics bar allows us to view every threat that has been observed in whatever time frame it is. By seeing that, we can directly assess whatever threats that have been observed on any endpoints and take a particular action on that.

    There has been a scenario when SentinelOne Singularity Endpoint automatically remediated a threat, but the client confirmed us that the file is genuine and necessary for them. During that time, we used the rollback feature to get it back to the original state. By doing that rollback, we can roll back to our default settings. For that purpose, we use the rollback feature.

    The rollback feature has saved us quite a bit of time. Doing it manually would have taken much more time. By directly doing the rollback, it has saved us more than an hour of time.

    Everyone should go for SentinelOne Singularity Endpoint because at the price range that they are offering their services, it is the best that we can ask for. Everyone should keep SentinelOne Singularity Endpoint as their security device for their firm or their own personal purpose as well. I would rate this review a 9 out of 10 overall.

    Karrie Westmoreland

    Security platform has consolidated threat protection and delivers faster incident response

    Reviewed on Jun 18, 2026
    Review from a verified AWS customer

    What is our primary use case?

    The usual use cases for SentinelOne Singularity Endpoint  that I work with mostly are endpoint detection and response.

    What is most valuable?

    SentinelOne Singularity Endpoint 's malware detection and quarantine kill capabilities have been the most valuable features. SentinelOne Complete has helped my customers consolidate their security solutions very well; we house everything under one umbrella called N-able, where they have everything housed under the N-able platform, and we do everything through there. Once they are under our umbrella, we take care of everything, and SentinelOne Singularity Endpoint is a big part of that, enabling our customers to get what they need in one house. They also work with another solution called Adlumin, which is an XDR  solution, and they combine with that really well.

    What needs improvement?

    SentinelOne Singularity Endpoint's features are valuable because they are very quick and also easy; it is easy to set up exclusions, but it can be picky about how you do that, so that is a pro and a con.

    With this filtering, I think it is as best as it can be; however, there are some programs that have multiple files and paths for the same process, so if I do not get them all, such as an updater that has different files and paths for the update, it will still see it as malware, and they will not be able to update their software. I have to go in and build new exclusions daily, so it can be a headache for certain users and programs. I would prefer SentinelOne Singularity Endpoint to be more refined, or maybe more general would be easier.

    SentinelOne Singularity Endpoint does generate a lot of noise as far as tickets; anytime I change the resolution status or am working on a ticket, if I change the process from suspicious to a false positive, every time I change the status of anything, it generates a ticket and an email. I have all this noise every time I am working on tickets, which is annoying.

    For how long have I used the solution?

    I have been using SentinelOne Singularity Endpoint for a little over two years.

    What do I think about the stability of the solution?

    SentinelOne Singularity Endpoint is definitely reliable; we have never been able to take it down, even when we tried. I have never had any outages; it has never been down for repair, and they always send out emails letting us know if they are going to be doing maintenance at night or something, and it always comes right back up if they do, which is really good.

    What do I think about the scalability of the solution?

    SentinelOne Singularity Endpoint is definitely scalable; you bring a customer in through N-able, and then you can go from there. It is per endpoint, so you can have as many as you want.

    How are customer service and support?

    I have communicated with SentinelOne Singularity Endpoint's support a couple of times, usually right through the chat if I am trying to do something and cannot find it. They escalate if they have to and follow up by email, using a ticketing system through Jira , so everything is fine.

    Their skills and expertise are pretty good if you get through the right channel through chat right away; however, it can be hard because they have many chat channels, so if you are specific on your original ticket request, you might get through the right support person. Otherwise, they will have to transfer you depending on whether someone is covering that shift or not, which can lead to a wait for email support. It can take a couple of hours.

    What was our ROI?

    I have seen a definite ROI with this solution, as we have got a lot of new customers signed on just for SentinelOne Singularity Endpoint. A couple of customers came on just because they wanted SentinelOne Singularity Endpoint, which turned into sales points for other products that we offer, so that was really good.

    What's my experience with pricing, setup cost, and licensing?

    As for pricing, I think it is just right on the nose for us; we chose it because it was price efficient and everything, and it was good for the two years we had it, but unfortunately, we are switching away.

    What other advice do I have?

    My impression of SentinelOne Singularity Endpoint's ability to ingest and correlate across security solutions is that for cross-security, we do not mix with anything else, so I am not sure on that end.

    I am familiar with the Ranger functionality of SentinelOne Singularity Endpoint, and while we do not have it, I see it advertised everywhere and would love to be able to press that button to see further into the visibility of what is going on.

    From my experience, SentinelOne Complete has not reduced alerts; I would say it increased them just because it finds every little thing. This increase relates to the malware detection as I mentioned earlier. The customer does not really get the alerts; we do, and we handle them before they ever reach the customer because I do not think there has been only one actual real malware since I have been working with it that did reach the customer end because it was real malware, so that was one out of two years.

    From my experience, SentinelOne Complete has helped free up employees for other projects and tasks; I handle everything, even the noise, so there is no need to escalate beyond where I am working. I let people handle all the noise, and it is just easier for me to go in without having to explain to other people what is going on.

    I do not think that SentinelOne Singularity Endpoint saved me a lot of time; it creates work for me, but that is the point of the program, so I would say it is doing its job perfectly.

    SentinelOne Singularity Endpoint has absolutely helped reduce my customer's mean time to detect, and it is almost instant. I cannot say by how much compared to before SentinelOne Singularity Endpoint because it was online before I came into this business, but if you had to do this manually, such as if you were just watching as things came in, it would be a nightmare, saving a lot of time.

    Regarding the mean time to respond with SentinelOne Singularity Endpoint, that is up to me because I am the responder, so I would say within about two to three minutes. I would say it has been reduced by five minutes at maximum. It used to take around 10 minutes, and now it is about three minutes, which sounds about right.

    My overall review rating for SentinelOne Singularity Endpoint is 8 out of 10.

    Which deployment model are you using for this solution?

    Public Cloud

    If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?

    Amazon Web Services (AWS)
    Ravishankar KumarPatel

    Holistic security monitoring has reduced detection time and streamlines incident response

    Reviewed on Jun 18, 2026
    Review from a verified AWS customer

    What is our primary use case?

    I work with SentinelOne Singularity Endpoint 's complete Singularity  Lake, which includes XDR , SIM, and everything integrated together.

    I normally use SentinelOne Singularity Endpoint  for endpoint management, with the EDR setup to get data from my endpoints. As an MSSP , I receive alerts and incidents and work on securing endpoints.

    For mean time to detect, we promise less than 15 minutes for critical activity as an MSSP . This obviously depends on how good the platform is, and we commit to less than two hours for resolution. Obviously, this depends on many factors beyond what you can do from the platform. As an MSSP, you need to be very mindful that there are company resources which make the final call on whether to block something or not, whether it's malicious but still needed for that particular environment. So I normally commit to 15 minutes for MTTD and less than two hours for MTTR.

    What is most valuable?

    I think over the last one and a half years they have been improving significantly. Prior to that, they were also a very good product. In the market, there are hardly three products I can name: SentinelOne, CrowdStrike, Defender for Endpoint, and a bit of Cortex , but I am not that impressed with that product. These are the three major products that are doing very well in terms of their active EDR engine where you get the storyline correct—what exactly has happened, the parent process, child process, command line arguments. You get everything in a single fetch. Now with Purple AI , I think you get everything. Even an L1 engineer does not need to do anything complex. They can just write in natural language and get the details they need.

    I think SentinelOne Singularity Endpoint presents a very holistic picture of an alert. Their enrichment layer is quite great. Once you get an alert, you get the complete process around it: how the parent process has started, which child process it has enabled, what kind of command line arguments or modifications have been done, what kind of scheduled task has been created, what kind of network connection you have, and what kind of file activity has occurred. You get everything in a single view.

    In terms of their XDR , the consolidation is quite good. They have their own SIM and everything as well. The consolidation point has improved a lot, and you get everything under a single umbrella. This makes life much easier for MSSPs like me to manage a particular customer.

    I think a few things are the confidence level you get in an alert. You get that very straightforward, so it is easier and you do not need to worry about it. The second thing is the automation level within the platform. Your alerts lifecycle has false positives reduced dramatically. You get all these features, and they help a lot. Also, the biggest factor is when I am opening SentinelOne Singularity Endpoint and presenting to a customer, the question is whether I can get a complete story of what has happened. That is where the most fatigue happens. When an alert occurs, people have to reach out to multiple sources to find out what exactly has happened. I think the story completeness is quite great with SentinelOne Singularity Endpoint.

    The biggest problem for any organization is their L1 layer. That is where you spend more time when you get an alert, determining what exactly happened and whether it should be converted to an incident or whether it is a false positive or a true positive. Now with Purple AI  and their LLM module, it is quite easier for the L1 engineers. The fatigue is quite low, and the alert to incident ratio has improved quite a bit. You know what is coming and what is not, and the L1 can add more value than they normally did before. Your load becomes easier on the L1 engineer, and obviously you can cut your costs there as well because one person can do more work. You do not need to teach any new language to manage SentinelOne Singularity Endpoint. As an MSSP, we can utilize the same L1 for multiple providers.

    Since the enrichment layer is great and we get the data properly with deep visibility and the storyline is complete, the dashboarding is quite decent. You can make the call quite faster, and resolution time has decreased significantly.

    The Purple AI features are notable. One of the most notable features is that you get a complete summarized alert. This works for someone who is not a great security L1 professional who has just joined from college or even for a more experienced professional who wants to see much data. You also get your AI verdict, indicating whether something is a true positive or false positive, so you get validation from AI. You get community verdict as well. If someone else has seen those alerts, you also see if there are similar alerts happening 1000 plus times, 10,000 plus times, or even just twice, or if it is only a standalone alert. Apart from that, you get a complete summary of what has happened, where it has happened, and why it has happened. You get complete details about what exactly has happened in a single click. So I think this makes life much easier for a respondent.

    The two things that are top of my mind are Purple AI and the consolidation. What you get is detailed reporting and detailed RCA as well from them. The third thing is the storyline and complete visibility of what has happened and the complete flow of a particular attack vector. You get that very properly in SentinelOne Singularity Endpoint.

    In terms of advantages, I think I will still use the AI visibility and the storyline. Most of the EDR providers use the same capabilities. Everyone has similar feature sets and everyone has been rated by ISG or other organizations. The end of the story that matters for every end customer or a provider like me is how well I can use it without getting too complicated. I have multiple stacks that I manage in my day-to-day, so how well their dashboard is, how well they are able to tell me the story around it, what exactly has happened, how exactly it happened, and how well they let me customize it matters. I think that is where SentinelOne Singularity Endpoint stands out. They are doing quite great there. At the same time, the Purple AI feature is much better. Imagine going for Copilot, which is a generic AI platform not specific to security. You may need to train it and work around it to get the exact responses you want. Apart from that, you pay for it, and you have to integrate it with your XDR or SentinelOne Singularity Endpoint, which creates lots of complications. When you get SentinelOne Singularity Endpoint, it is easier. Purple AI is already built into it, so you do not have to worry about it. You just buy it and can use it from day one.

    What needs improvement?

    I think they are doing pretty decent. The only thing is that once you are competing with someone like Microsoft and CrowdStrike, I think the investment should be slightly more in terms of a holistic view. Their threat feed is also limited. You get a very vast threat feed, but again it is not as mature as you get from a CrowdStrike or Microsoft stack. I think that is where they can look at it. Threat hunting is also something they do, so I think they can improve there as well. I think everyone is almost similar in that regard, so I think the rest of everything looks fine.

    In terms of pricing, SentinelOne is slightly cheaper than CrowdStrike and Microsoft from what I have seen. Obviously, it is costlier than Sophos and a few other providers, but cheaper than those two. Deployment-wise I think it is there. I think the only thing is that Microsoft offers some free deployments to their customers with ECF funding and other options. I think that is something which Microsoft, being a bigger partner, has. Otherwise, I think they are doing good.

    Regional availability is there, and I do know they are in most locations. In terms of compliance, there are some locations where I have seen them saying they still host on the US or EMEA region. I think the regional maturity is something they need to improve. I think otherwise, everything they are doing is quite good.

    For how long have I used the solution?

    I have been using SentinelOne Singularity Endpoint for three to four years now.

    What do I think about the stability of the solution?

    I have not experienced any stability issues.

    What do I think about the scalability of the solution?

    It is a very scalable environment. We have some large deployments on SentinelOne Singularity Endpoint, so the environment is very stable.

    How are customer service and support?

    As a service provider, we manage most of the discussion in-house. Whenever we reach out to them, we get a very good response from them.

    Which solution did I use previously and why did I switch?

    I think SentinelOne Singularity Endpoint is quite straightforward. They have been in the market, so the deployment and initial setup is quite easy. It is not a very tricky task and is very mature.

    How was the initial setup?

    I think SentinelOne Singularity Endpoint is quite straightforward. They have been in the market, so the deployment and initial setup is quite easy. It is not a very tricky task and is very mature.

    What about the implementation team?

    We purchased directly from SentinelOne.

    What was our ROI?

    As an architect, I do not work directly on ROI, but I think it is understood.

    What's my experience with pricing, setup cost, and licensing?

    SentinelOne Singularity Endpoint sells on a SaaS model. For us, it does not matter whether it is AWS  or Azure , but we work with Azure , AWS , and everything.

    Which other solutions did I evaluate?

    SentinelOne Singularity Endpoint sells on a SaaS model. For us, it does not matter whether it is AWS or Azure, but we work with Azure, AWS, and everything.

    What other advice do I have?

    The ask is always simple from a customer standpoint. What exactly do you want to achieve, and what exactly is your problem base? Take a call in terms of what makes your life easier rather than having a very fancy-looking product and still having to learn a new technology or hire a new set of people. I think that is the concern most companies have. So just go for a genuine product which does serve the purpose and at the same time gets you out of the situations. I would rate this product and experience a 9 out of 10.

    View all reviews