Listing Thumbnail

    SentinelOne Singularity Platform

     Info
    Sold by: SentinelOne 
    Deployed on AWS
    Vendor Insights
    Unlock enterprise-wide security for your AWS environment with SentinelOne Singularity Platform. This AI-powered solution provides real-time threat detection and automated response across your infrastructure, ensuring continuous protection at infinite scale. By autonomously securing endpoints, cloud workloads, and identity, SentinelOne delivers total visibility while eliminating security silos. Integrate seamlessly with AWS and leverage our unified data lake and Purple AI to accelerate investigations and gain deeper insights. Secure your AWS cloud and focus on innovation with the speed and efficiency of AI.
    4.6

    Overview

    Play video

    The SentinelOne Singularity Platform is the industry's first AI-powered security solution for the modern enterprise, offering a unified defense across your entire infrastructure from endpoints and cloud workloads to identity. As cloud adoption accelerates, traditional, siloed security tools create complexity and leave gaps in protection. Our platform consolidates multiple security capabilities into a single, intelligent solution, providing AWS customers with real-time visibility and autonomous protection to simplify security operations and reduce risk.

    Core Capabilities & Benefits

    Autonomous Protection: Singularity Platform is designed for customers seeking enterprise-wide protection, detection, and response capabilities, augmented by the intelligence and speed of advanced AI and automation. SentinelOne's Singularity Platform protects thousands of customer environments, including Amazon cloud workloads, across the globe.

    Unified Visibility: Break down data silos and security tool sprawl. Using patented Storyline™ technology, the platform automatically correlates and contextually groups related events into a single attack story, providing a consolidated view for faster investigation and response within our unified data lake.

    Extended Detection & Response (XDR): Gain a complete, correlated view of the full attack story across endpoints, identities, and cloud workloads. Our XDR solution provides the context needed to understand and respond to threats at machine speed.

    Cloud Workload Protection Platform (CWPP): Secure your AWS compute resources from runtime threats. Our Singularity Cloud Workload Security delivers real-time, AI-powered threat detection and response for Amazon EC2 instances, EKS clusters, and AWS Fargate. It provides deep visibility into vulnerabilities and configuration risk while autonomously blocking malware, ransomware, and fileless attacks without disrupting production performance.

    Identity Threat Detection & Response (ITDR): Proactively defend against credential theft, privilege escalation, and lateral movement attacks across hybrid environments. Our solution provides continuous monitoring and protection for Active Directory and leading cloud identity providers, including Entra ID, Okta, Ping, SecureAuth, and Duo, ensuring identity infrastructure remains secure.

    Accelerated Incident Response with Generative AI: Purple AI, our generative AI security analyst, acts as a force multiplier for your security team. It automates threat hunting, provides instant summaries of complex incidents, and accelerates investigations, allowing your team to focus on strategic initiatives.

    Seamless Integration with AWS Services

    The SentinelOne Singularity Platform is designed for seamless integration into your existing AWS environment. We provide bidirectional integrations for AWS Security Hub and Amazon CloudWatch, ensuring your security findings are centralized and actionable. Additionally, our AI-powered malware scanning for Amazon S3 protects sensitive data while maintaining compliance, helping you maximize your AWS investment and enhance your overall security posture.

    How to Get Started

    Secure your AWS cloud and focus on innovation with the SentinelOne Singularity Platform. Simply click on the Request private offer button at the top of this page to begin your procurement process.

    Highlights

    • 338% three-year ROI for SentinelOne customers using Purple AI, included with SentinelOne Singularity Platform Complete
    • 96% of Gartner Peer Insights™ EDR reviewers recommend SentinelOne Singularity
    • 5-Consecutive Year Gartner® Magic Quadrant™ Leader for Endpoint Protection Platforms

    Details

    Delivery method

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Trust Center

    Trust Center
    Access real-time vendor security and compliance information through their Trust Center powered by Drata or Vanta. Review certifications and security standards before purchase.

    Buyer guide

    Gain valuable insights from real users who purchased this product, powered by PeerSpot.
    Buyer guide

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Vendor Insights

     Info
    Skip the manual risk assessment. Get verified and regularly updated security info on this product with Vendor Insights.
    Security credentials achieved
    (1)

    Pricing

    SentinelOne Singularity Platform

     Info
    Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    1-month contract (1)

     Info
    Dimension
    Description
    Cost/month
    Custom Pricing and Packaging
    Contact SentinelOne for custom pricing and packaging including Private Offers
    $10,000.00

    Vendor refund policy

    Refunds available as required by law.

    Custom pricing options

    Request a private offer to receive a custom quote.

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Software as a Service (SaaS)

    SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.

    Support

    Vendor support

    Multiple support options available. Email support available: support@sentinelone.com 

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Product comparison

     Info
    Updated weekly

    Accolades

     Info
    Top
    10
    In Generative AI, Security Observability

    Customer reviews

     Info
    Sentiment is AI generated from actual customer reviews on AWS and G2
    Reviews
    Functionality
    Ease of use
    Customer service
    Cost effectiveness
    Positive reviews
    Mixed reviews
    Negative reviews

    Overview

     Info
    AI generated from product descriptions
    AI-Powered Threat Detection and Response
    Real-time threat detection and automated response capabilities augmented by advanced AI and automation across endpoints, cloud workloads, and identity infrastructure.
    Cloud Workload Protection
    Runtime threat protection for Amazon EC2 instances, EKS clusters, and AWS Fargate with autonomous blocking of malware, ransomware, and fileless attacks.
    Extended Detection and Response
    Correlated view of full attack stories across endpoints, identities, and cloud workloads using patented Storyline technology to automatically correlate and contextually group related events.
    Identity Threat Detection and Response
    Continuous monitoring and protection against credential theft, privilege escalation, and lateral movement attacks across Active Directory and cloud identity providers including Entra ID, Okta, Ping, SecureAuth, and Duo.
    Generative AI Security Analysis
    Generative AI security analyst that automates threat hunting, provides incident summaries, and accelerates investigations through machine-speed analysis.
    Multi-Source Threat Data Integration
    Correlates security events from Trellix Security Platform and over 500 third-party tools including 13 AWS integrations to create unified threat visibility across the security stack.
    AI-Driven Alert Triage and Prioritization
    Applies artificial intelligence-driven analytics to perform 100% alert triage, prioritize threats, and provide GenAI-powered insights for threat investigation and remediation guidance.
    No-Code Automation for Investigation and Response
    Provides UI-driven, point-and-click automation capabilities to offload repetitive security operations tasks and accelerate investigation and response workflows.
    Pre-Built Analytics and Correlation Rules
    Ingests data from multiple sources and correlates events using pre-built analytics and rules to reconstruct complete attack narratives and reduce manual investigation pivots.
    Multi-Deployment Architecture Support
    Supports cloud, hybrid, and air-gapped deployment models with an open integration ecosystem for flexible security infrastructure configurations.
    Multi-Domain Attack Detection
    AI-powered detections that expose attacker activity across network, identity, and cloud environments including data centers, campuses, remote work, IoT/OT, AWS, Microsoft Active Directory, Microsoft Entra ID, Microsoft Azure, and Microsoft 365.
    Automated Alert Triage and Correlation
    AI agents that automatically triage, stitch, and prioritize attacks in real time, removing up to 99% of alert noise and reducing manual task time by up to 50%.
    Unified Investigation and Response Interface
    Centralized response user experience that enables discovery, hunting, detection, investigation, and automated response capabilities with aggregated and contextualized views of attack progression across network, identity, and cloud.
    Network Detection and Response
    Dedicated network detection and response (NDR) module for monitoring and detecting malicious activity across network infrastructure.
    Multi-Cloud and Identity Platform Coverage
    Modular architecture supporting AWS, Microsoft Azure, Microsoft 365, Microsoft Active Directory, and Microsoft Entra ID with configurable metadata retention periods ranging from 14 to 90 days.

    Security credentials

     Info
    Validated by AWS Marketplace
    FedRAMP
    GDPR
    HIPAA
    ISO/IEC 27001
    PCI DSS
    SOC 2 Type 2
    -
    -
    -
    -
    -
    No security profile
    No security profile

    Contract

     Info
    Standard contract
    No
    No
    No

    Customer reviews

    Ratings and reviews

     Info
    4.6
    406 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    76%
    21%
    1%
    1%
    1%
    46 AWS reviews
    |
    360 external reviews
    External reviews are from G2  and PeerSpot .
    Computer & Network Security

    SentinelOne: Balanced Endpoint Security with Strong Visibility and Automation

    Reviewed on Aug 09, 2026
    Review provided by G2
    What do you like best about the product?
    Overall, SentinelOne provides a good balance of security, visibility, automation, and ease of management, making it a valuable solution for protecting enterprise endpoints.
    What do you dislike about the product?
    Some advanced configurations and investigations can also feel a little complex, especially for teams that are new to endpoint security platforms. Reporting and customization could be more intuitive as well.

    Overall, these are relatively minor concerns, but simplifying the user experience and making advanced features easier to configure would make the platform even better.
    What problems is the product solving and how is that benefiting you?
    The automated detection and response capabilities are especially beneficial because they reduce manual effort and help minimize the time required to contain and remediate threats. The centralized management also makes it easier to monitor endpoint security, apply policies, and maintain consistent protection across the environment.

    Overall, it helps improve our endpoint security posture, reduces operational effort, and provides greater visibility and confidence in detecting and responding to security threats.
    Victor M.

    Autonomous Threat Mitigation and Storyline Visibility That Save Hours

    Reviewed on Aug 07, 2026
    Review provided by G2
    What do you like best about the product?
    What's provided the most value for me is the autonomous response. Running a mixed Windows/macOS fleet with a chunk of BYOD devices, I can't babysit every alert, and the on-agent behavioural AI catches and auto-mitigates threats without waiting on a cloud round-trip or an analyst clicking "contain". The Storyline attack visualisation is the feature I lean on daily; instead of stitching together process trees myself, I get the full execution chain mapped out, which turns what used to be a 30-minute triage into a few minutes of confirming and rolling back. AI / Intelligence: The static and behavioural AI models running locally mean detection holds up even when a device is offline, which matters for laptops that aren't always on the VPN. Fewer noisy false positives than the signature-based tooling I've used before. UI / UX: The console is clean, and the Deep Visibility query interface lets me hunt across the fleet quickly. Onboarding new admins doesn't require weeks of ramp-up. Performance: Agent footprint is light — I haven't had the user complaints about system slowdown that plagued our previous endpoint tool, which is a real win when you're deploying to BYOD machines you don't fully control. Integrations: Ranger for network visibility (surfacing unmanaged devices) plus the API and SIEM connectors have fit into our stack without much friction. Adding Ranger meant I stopped needing a separate discovery tool to find rogue endpoints. Support / Onboarding: Deployment was straightforward, and vendor support has been responsive on the escalations that mattered. Pricing / ROI: It is not the cheapest option, but the ROI shows up in reduced analyst hours; the one-click rollback on ransomware alone has justified the spend, and consolidating discovery (Ranger) into the same platform cut a line item elsewhere. Unexpected benefit: The rollback capability doubled as a safety net for my organisation during a legitimate-but-misclassified software push; being able to reverse endpoint changes cleanly saved a reimaging headache.
    What do you dislike about the product?
    The biggest pain point is policy and exclusion management at scale. Building exclusions is more manual than it should be; there's no clean way to test an exclusion's blast radius before it goes live, so tuning for a noisy line-of-business app on part of the fleet involves more trial-and-error than I'd like. A "preview affected endpoints" step or a staging mode for policy changes would cut real risk out of the process. Deep Visibility is powerful, but the query experience has a learning curve. The syntax isn't intuitive for newer analysts, and saved-query sharing and templating could be better. When I'm onboarding someone, threat hunting is the piece that takes longest to hand off, which partly defeats the "autonomous" pitch for smaller teams. Reporting is the other weak spot. The canned reports rarely match what I need for regulatory or management audiences, so I still end up exporting to build the view myself. More flexible, customisable reporting, or a proper report builder, would save hours each reporting cycle. On macOS, agent updates and OS-version compatibility have occasionally lagged behind Windows, which matters on a mixed fleet where I can't always hold back an OS update on a BYOD device. Tighter macOS parity would help. Console performance can also drag when pulling large time-range queries across the full fleet, and the alert volume before tuning is high enough that early days feel noisier than expected.
    What problems is the product solving and how is that benefiting you?
    The core problem it solves for us is endpoint visibility and response across a mixed Windows/macOS fleet that includes BYOD devices we don't fully control. Before, detection leaned heavily on signature-based tooling that missed behavioural threats and generated noise, and our response was manual; an analyst had to triage, decide, and contain, which meant slow reaction to anything that landed off-hours or while a laptop was off the VPN. Now the on-agent AI detects and auto-mitigates threats locally, so containment doesn't wait on an analyst or a cloud round trip. That's collapsed our mean time to respond to the incidents that matter, and the biggest single win is the one-click rollback on ransomware and malicious changes; reversing endpoint state cleanly has taken reimaging off the table for cases that used to mean hours of rebuild per machine. The second problem was unmanaged devices. We struggled to reliably find rogue or unenrolled endpoints on the network, but Ranger surfaces them without a separate discovery tool, which closed a real gap in our asset visibility and cut a line item from the stack. Third is investigation time. Storyline maps the full attack chain automatically, so triage that used to mean manually reconstructing process trees now takes a few minutes of confirming and acting – meaningfully less analyst time per alert, which for a lean team is the difference between keeping up and falling behind. Net benefit: faster response, less manual rebuild work, tighter asset visibility, and analyst hours redirected from triage to higher-value work.
    James R.

    Effective Endpoint Protection and Threat Detection

    Reviewed on Jul 28, 2026
    Review provided by G2
    What do you like best about the product?
    What I like best about SentinelOne Singularity Endpoint is its behavioral threat detection and automated response. It detects suspicious activity quickly, isolates infected endpoints when needed, and provides a clear investigation timeline that makes it easier to understand and respond to security incidents. The management console is also easy to navigate, which simplifies day to day security operations.
    What do you dislike about the product?
    I think the sentinelone singularity endpoint platform is a great security solution, however fine tuning policies and creating exclusions for trusted applications can take some time, especially for larger environment. This can be improved on.
    What problems is the product solving and how is that benefiting you?
    SentinelOne Singularity Endpoint helps us detect and stop malware, ransomware, and other endpoint threats before they spread. It provides real time visibility into endpoint activity, speeds up incident investigation, and automates response actions such as isolating compromised devices.
    Elizabeth E.

    SentinelOne Singularity: Proactive, Reliable EDR with Excellent Real-Time Detection

    Reviewed on Jul 27, 2026
    Review provided by G2
    What do you like best about the product?
    SentinelOne Singularity Endpoint is one of the most effective and efficient EDR solutions I've used. It's highly proactive, with excellent real-time threat detection and automated response capabilities. The platform is reliable, easy to use, and provides great visibility into endpoint security.
    What do you dislike about the product?
    One area for improvement is the blocklist functionality. Currently, it only supports blocking file hashes, whereas I would like to see support for a broader range of indicators of compromise (IOCs), such as IP addresses, domain names, and URLs.
    What problems is the product solving and how is that benefiting you?
    As a SOC Analyst, SentinelOne Singularity Endpoint enables me to detect and respond to endpoint threats quickly. Its real-time visibility, behavioral detection, and automated response capabilities reduce investigation time, improve incident response, and strengthen our overall endpoint security.
    Victor Y.

    Simply 1-Click Ransomware Rollback That Restores Files Fast

    Reviewed on Jul 24, 2026
    Review provided by G2
    What do you like best about the product?
    Provides 1-click ransomware rollback capabilities, reverting unauthorized changes and restoring encrypted files from local shadow copies in the event of a ransomware attack.
    What do you dislike about the product?
    High Memory Usage: The agent can occasionally consume significant CPU and RAM resources, especially during full system scans or database operations, which can cause my laptop to slow down.
    What problems is the product solving and how is that benefiting you?
    Real-time autonomous mitigation. The local behavioral AI engine can kill processes, isolate infected machines, and automatically roll back changes instantly, without needing cloud connectivity or human approval.
    View all reviews