Overview

Product video
The SentinelOne Singularity Platform is the industry's first AI-powered security solution for the modern enterprise, offering a unified defense across your entire infrastructure from endpoints and cloud workloads to identity. As cloud adoption accelerates, traditional, siloed security tools create complexity and leave gaps in protection. Our platform consolidates multiple security capabilities into a single, intelligent solution, providing AWS customers with real-time visibility and autonomous protection to simplify security operations and reduce risk.
Core Capabilities & Benefits
Autonomous Protection: Singularity Platform is designed for customers seeking enterprise-wide protection, detection, and response capabilities, augmented by the intelligence and speed of advanced AI and automation. SentinelOne's Singularity Platform protects thousands of customer environments, including Amazon cloud workloads, across the globe.
Unified Visibility: Break down data silos and security tool sprawl. Using patented Storyline™ technology, the platform automatically correlates and contextually groups related events into a single attack story, providing a consolidated view for faster investigation and response within our unified data lake.
Extended Detection & Response (XDR): Gain a complete, correlated view of the full attack story across endpoints, identities, and cloud workloads. Our XDR solution provides the context needed to understand and respond to threats at machine speed.
Cloud Workload Protection Platform (CWPP): Secure your AWS compute resources from runtime threats. Our Singularity Cloud Workload Security delivers real-time, AI-powered threat detection and response for Amazon EC2 instances, EKS clusters, and AWS Fargate. It provides deep visibility into vulnerabilities and configuration risk while autonomously blocking malware, ransomware, and fileless attacks without disrupting production performance.
Identity Threat Detection & Response (ITDR): Proactively defend against credential theft, privilege escalation, and lateral movement attacks across hybrid environments. Our solution provides continuous monitoring and protection for Active Directory and leading cloud identity providers, including Entra ID, Okta, Ping, SecureAuth, and Duo, ensuring identity infrastructure remains secure.
Accelerated Incident Response with Generative AI: Purple AI, our generative AI security analyst, acts as a force multiplier for your security team. It automates threat hunting, provides instant summaries of complex incidents, and accelerates investigations, allowing your team to focus on strategic initiatives.
Seamless Integration with AWS Services
The SentinelOne Singularity Platform is designed for seamless integration into your existing AWS environment. We provide bidirectional integrations for AWS Security Hub and Amazon CloudWatch, ensuring your security findings are centralized and actionable. Additionally, our AI-powered malware scanning for Amazon S3 protects sensitive data while maintaining compliance, helping you maximize your AWS investment and enhance your overall security posture.
How to Get Started
Secure your AWS cloud and focus on innovation with the SentinelOne Singularity Platform. Simply click on the Request private offer button at the top of this page to begin your procurement process.
Highlights
- 338% three-year ROI for SentinelOne customers using Purple AI, included with SentinelOne Singularity Platform Complete
- 96% of Gartner Peer Insights™ EDR reviewers recommend SentinelOne Singularity
- 5-Consecutive Year Gartner® Magic Quadrant™ Leader for Endpoint Protection Platforms
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Trust Center
Buyer guide

Financing for AWS Marketplace purchases
Security credentials achieved
(1)

Pricing
Dimension | Description | Cost/month |
|---|---|---|
Custom Pricing and Packaging | Contact SentinelOne for custom pricing and packaging including Private Offers | $10,000.00 |
Vendor refund policy
Refunds available as required by law.
Custom pricing options
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
Software as a Service (SaaS)
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
Support
Vendor support
Multiple support options available. Email support available: support@sentinelone.com
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
FedRAMP
GDPR
HIPAA
ISO/IEC 27001
PCI DSS
SOC 2 Type 2
Standard contract
Customer reviews
Powerful EDR and Automated Threat Response with Centralized Visibility
Unified endpoint protection has reduced manual work and provides autonomous threat response
What is our primary use case?
My main use case is to protect the endpoints. Back in 2020, I conducted multiple proofs of value for different vendors, including SentinelOne. At the end of my evaluation, SentinelOne was the solution that provided a better fit for what we needed to do, and it was one of the best solutions, not just in terms of doing what it was supposed to do, but also in terms of cost. The end goal was to protect the endpoints, including Windows, Linux, and MacOS systems, as well as Windows servers and cell phones.
What is most valuable?
I have had multiple cases where end users fell victim to phishing emails or visited the wrong link. The EDR solution from SentinelOne was able to mitigate the potential threat, which protected not only the end user but also the company. This has also happened on servers. I have seen servers exposed to the Internet that had advanced threat actors trying to get into our networks, and SentinelOne's EDR solution has been able to mitigate such attacks and in some cases perform rollbacks. We also receive notifications via email and in some cases messages, which helps us stay on top of things and makes troubleshooting much easier. SentinelOne performs the mitigation on its own, which allows me to have peace of mind. Security is not absolute, and something else will happen, but from my experience, I am able to rely on the solution and know that it is going to do what it is supposed to do. Beyond protecting the endpoint, the autonomous response capability allows remediation of threats at machine speed without my intervention. The solution just does it on its own.
Today, I use SentinelOne for EDR, but we also use it for XDR. We are able to do assessments against our on-premise Active Directory as well as Azure, Microsoft Defender, and Exchange. We are collecting logs from our Azure enter ID, which gives me visibility that is sometimes difficult to find in the Microsoft 365 suite of tools. Being able to go into the SentinelOne Singularity Endpoint console and narrow down to the main events happening across the different platforms that we use makes things much easier, allowing me to be aware of what is happening and to triage items when needed. Having the complete SentinelOne Singularity Endpoint solution, not just with endpoint security but also with identity protection, makes my job much easier. If I had to do this manually, it would take a long time. Having the thermal response, behavioral AI, identity assessment, and the ability to stop potential lateral movements is a significant help.
SentinelOne Singularity Endpoint offers many features. I really appreciate what EDR is able to do, not only on the antivirus side. Having a single agent on an endpoint gives me the ability to handle multiple potential threat vectors. Instead of having multiple agents doing different things, SentinelOne Singularity Endpoint agent handles the antivirus side, endpoint protection, and with the behavioral side using AI, it is able to learn, see suspicious activities, track them, and isolate potential compromised devices automatically. When looking at our Active Directory, it has been able to do assessments and provide what the threat is using things such as MITRE, along with solutions on how to fix it. There is not one feature in particular; it is looking at it holistically and seeing how we can protect our premises not just from the endpoint but also from an identity perspective. Both complement one another.
On the behavioral AI, it is learning about our platforms and how they behave. We have multiple systems, some of which are exposed to the Internet because that is where our website is or where platforms multiple users use that are public facing. The behavioral AI is able to learn what a system is supposed to do, and if it notices something different, it tells us about it. Simple things such as if I remotely access a device and begin using PowerShell, in some cases it will alert me and say this activity does not look normal. The behavioral AI is able to see potential activity that is just not normal, create a baseline, and act upon it.
What needs improvement?
One of the things I would like to see from SentinelOne Singularity Endpoint is the vulnerability side of things. Today, vulnerabilities is one of the features that allows me to see what is happening with the endpoints, looking at the number of applications installed and which ones need immediate attention. However, we do not have patch management from SentinelOne Singularity Endpoint. Having patch management would make it even better. I would be able to take action from there and push the updates needed by the endpoints. If I were able to fix it or take action from SentinelOne Singularity Endpoint console, it would make my job much easier.
When it comes to reports, I was hoping to have better reports. For example, I tried to do a report to see the number of vulnerabilities affecting our endpoints and which were the most critical, but I was not really able to do that because of the limitations when it comes to doing reports. Reports is something that really needs work so that we can get better reporting, even though the dashboards are there and provide good telemetry. Having an executive level report would be a lot of help.
For how long have I used the solution?
I started using SentinelOne Singularity Endpoint in October 2020.
What do I think about the stability of the solution?
It has always been stable, and I have never seen any issues with it being unstable.
What do I think about the scalability of the solution?
Adding new endpoints is really not difficult at all and is super simple, especially because we use a script with our endpoint manager. We push the script, and it deploys without requiring a lot of work.
How are customer service and support?
Customer support has been amazing.
Which solution did I use previously and why did I switch?
For the current company I am working with, they had no EDR solutions. My recommendation was to deploy SentinelOne Singularity Endpoint as the EDR solution. At my previous company, we replaced CarbonBlack. I made a recommendation to replace CarbonBlack with SentinelOne Singularity Endpoint because of the functionality, being able to have antivirus and protect the endpoint using EDR as well as the AI side of things, including identity.
How was the initial setup?
When I first deployed SentinelOne Singularity Endpoint, we had multiple solutions handling orchestration for our cybersecurity program, which meant having multiple agents doing different things and collecting telemetry. In the past, I had CarbonBlack and other solutions and was missing out on things. Being able to have a single console to look at multiple metrics from different endpoints, including servers both Windows and Linux, as well as identity, has made performance and productivity much better.
What about the implementation team?
For hybrid deployment, we use NinjaOne. We are able to push the endpoint installation through our endpoint manager.
What was our ROI?
I do not have metrics as to how much time the solution has saved me, but I can give an example from my experience. I go to work in the morning and take a look at the platform for ten to fifteen minutes, then maybe during lunch and before I clock out. I do not have to spend a lot of time on the platform. If something happens, I get a notification or an alert about the incident. For the most part, we are not spending a lot of time looking at things. We know that if something happens, we are going to be notified.
What's my experience with pricing, setup cost, and licensing?
Pricing has been one of the best things. I have compared this to other platforms such as Cyber Reason and CrowdStrike. Price-wise, it was the best pricing. The deployment is straightforward and not complicated. We were able to use our Endpoint Manager solution to begin installation, and that has made a huge difference.
Which other solutions did I evaluate?
Cyber Reason, CarbonBlack, and CrowdStrike were all alternatives I evaluated.
What other advice do I have?
I do trust its alerts, and I do think that it is catching things. It is simple and straightforward. Looking at the marketplace, I am able to do the integrations as long as they follow the instructions, and it is pretty straightforward. I do not know that it has helped reduce alerts, but over time, users are aware that these platforms are installed on the endpoints and understand that if something happens, they are going to see the alerts come up and see the mitigation take place. They have seen that in the past. From an admin point of view, it is much easier to take a look at a single pane versus multiple platforms. Users are beginning to see that there is something installed on their computer whose whole job is to protect the endpoint. Do your homework and make sure that what you are getting out of SentinelOne Singularity Endpoint aligns with the goal of the business. Understand what the business is that you work with, conduct an assessment, and see if SentinelOne Singularity Endpoint aligns well with the company's goals. I would rate this solution a 9 out of 10.
Storyline has improved incident investigations and now needs deeper process visibility
What is our primary use case?
My main use case for SentinelOne Singularity Endpoint involves handling suspicious PowerShell activity, which is probably the most common one.
When I mention suspicious PowerShell activity, SentinelOne Singularity Endpoint helped me detect or respond to that incident with the Storyline feature, which I found excellent. It visually shows you what is going on, where, when, what the grandparent process is, what the parent process is, and what the child process is, so you can quickly go through it and gain insights on that.
I have more to add about my main use case or the types of incidents SentinelOne Singularity Endpoint helped me with. It is not just one use case; it is usually EDR and some XDR that helps you show various details. It is good that you can take actions from there, and it is really user-friendly to search something in the logs.
What is most valuable?
The best features SentinelOne Singularity Endpoint offers, which I found most valuable, is the Storyline, as it helps really well and provides deep visibility of everything.
SentinelOne Singularity Endpoint positively impacts my organization by saving time because I can see many details right away without needing to look for everything in some queries or anywhere. From the first vital glance, I can see the main information, which really saves time.
In terms of how much time it saved me or my team, if a usual ticket took about 20 minutes to investigate, with this solution it takes about 10 minutes; it is probably two times better.
What needs improvement?
To improve SentinelOne Singularity Endpoint, I want to continue working on this and provide even more data, more visibility, and everything clearer and faster. I guess everywhere could use a few additional functions, but they are not really needed.
I would add more about the needed improvements regarding features. I mean more deeper insights and bigger visibility so that when you have any process, you can click and it can show you everything for that process, so you can see really quickly everything that you need, enabling quick analysis and decision-making.
For how long have I used the solution?
I have been using SentinelOne Singularity Endpoint for a few months.
What do I think about the stability of the solution?
SentinelOne Singularity Endpoint is pretty much stable.
What do I think about the scalability of the solution?
The scalability of SentinelOne Singularity Endpoint is good.
Which solution did I use previously and why did I switch?
I did not previously switch from a different solution. We just added it for some clients, depending on what they wanted, but I was using CrowdStrike and Microsoft XDR as well.
What was our ROI?
I believe I have seen a return on investment from using SentinelOne Singularity Endpoint, though I am not sure and was not involved in prices. I guess it helps.
Which other solutions did I evaluate?
Before choosing SentinelOne Singularity Endpoint, I did not evaluate other options because I was not involved in that process.
What other advice do I have?
My advice to others looking into using SentinelOne Singularity Endpoint is to try it and use it to see if you it; it is good for me. I would rate this product a 7 out of 10.
Advanced endpoint protection has strengthened compliance and stopped risky user activity
What is our primary use case?
fuck
What is most valuable?
The best features that SentinelOne Singularity Endpoint offers are its anti-malware function and prevention, which is more intelligent than a traditional antivirus. From what I see in current reviews, it is one of the best EDRs, which is why it was recommended, and it works together with NinjaOne RMM.
As soon as SentinelOne Singularity Endpoint has a doubt, not necessarily just a malware signature, it will block the traffic. It has intelligent detection tools that go further than a traditional antivirus.
SentinelOne Singularity Endpoint has had a positive impact on the organization because the cyber insurance company required this type of tool to be reimbursed in case of a cyber incident. In other contexts and engagements, ESET has been used, which is also very good.
SentinelOne Singularity Endpoint has really improved compliance and security, as there are no problems anymore. Employees used to play around downloading files using eMule and other legal software that caused security or confidentiality issues, but all of that was able to be eliminated quickly. The firm had more than fifteen years of work behind it, accumulating bad habits and files that were not a problem before but can be today. The client was very happy to have cyber insurance and be reimbursed in case of a problem, allowing them to sleep much more soundly, because if there is an IT incident, it could mean the closure of the company.
What needs improvement?
Since adopting SentinelOne Singularity Endpoint, I have seen a mixed bag of measurable results. There have indeed been many fewer risks, but there have been other problems. SentinelOne Singularity Endpoint tends to block workstations at the slightest doubt, so it needs to be fine-tuned to be a bit more tolerant. Otherwise, there are blocked workstations and loss of productivity.
There were many problems on old Windows Servers that were not compatible, so they had to be upgraded. If SentinelOne Singularity Endpoint were more backward compatible with older versions, that would be great. The old versions of Windows Server were not very compatible, but that is the only criticism.
For how long have I used the solution?
SentinelOne Singularity Endpoint has been used since 2023.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Endpoint defense has improved and remote investigations gain faster insights into attacks
What is our primary use case?
My main use case for SentinelOne Singularity Endpoint involves scanning customer endpoints and conducting forensic collection.
A specific example of how I use SentinelOne Singularity Endpoint for customer endpoints is that it has been able to notify us of quick fix attack activity from malicious MHTA being obfuscated and executed on different customer endpoints.
In addition to my main use case, I use SentinelOne Singularity Endpoint for checking endpoints' web activity, and it also helps with getting a comprehensive view of the overall activity and alerts that come in.
What is most valuable?
SentinelOne Singularity Endpoint's best features, which stand out to me the most, include the Remote Shell and Purple AI.
The Remote Shell and Purple AI help me in my day-to-day work by allowing some use cases to use the Remote Shell to remotely install or uninstall applications to support IT, or using Purple AI to provide quicker insight into alerts or activity that SentinelOne Singularity Endpoint is providing.
SentinelOne Singularity Endpoint has positively impacted my organization as it is our go-to EDR of choice.
It is my go-to EDR because we have noticed definitely faster response times, and the customer support has been better than some other companies we have had to deal with.
What needs improvement?
Regarding SentinelOne Singularity Endpoint's AI capabilities, I find its accuracy and reliability of output to be dependable, though I believe it could improve by opening up the access to more than summarizing or creating queries.
For how long have I used the solution?
I have been using SentinelOne Singularity Endpoint for about three years.
What do I think about the stability of the solution?
SentinelOne Singularity Endpoint is stable, and I am not aware of any issues with its reliability.
What do I think about the scalability of the solution?
SentinelOne Singularity Endpoint's scalability is excellent, as I have not had any issues with onboarding or offboarding new customers or adding new sites.
How are customer service and support?
SentinelOne Singularity Endpoint's customer support has been very good with good turnaround time and a solution-oriented approach.
Which solution did I use previously and why did I switch?
We have always had SentinelOne and used to use Trellix and their suite of tools, but we moved away from Trellix to stay with SentinelOne Singularity Endpoint as our main EDR, mainly due to updates and customer service.
Which other solutions did I evaluate?
Before choosing SentinelOne Singularity Endpoint, we evaluated SentinelOne and CrowdStrike, but it really depends on the customer's needs; overall, SentinelOne Singularity Endpoint is our go-to.
What other advice do I have?
Singularity Complete fills the role of EDR and helps us with monitoring, so it is a part of our complete puzzle that gives us the vision we need into a customer's environment, depending on whether they have SentinelOne Singularity Endpoint through us and we manage it.
We do not use the Ranger functionality because a different department manages network visibility.
Singularity Complete does not necessarily lessen alerts for us as we have it tuned to only create cases in our SIEM for things that are high and critical.
Although I do not have any direct metrics, I do find that it all ties into giving us the intelligence or data from detections, which get fed into our SIEM for us to take actions either in SentinelOne Singularity Endpoint or by contacting the customer.
My advice for others looking into using SentinelOne Singularity Endpoint is to take advantage of the partner support portal to get trained up on it, as that will definitely help you understand it and use it to its full capability.
I believe we fall under partner in terms of our business relationship with this vendor. I would rate my overall experience with SentinelOne Singularity Endpoint as an 8.