Overview

Product video
The SentinelOne Singularity Platform is the industry's first AI-powered security solution for the modern enterprise, offering a unified defense across your entire infrastructure from endpoints and cloud workloads to identity. As cloud adoption accelerates, traditional, siloed security tools create complexity and leave gaps in protection. Our platform consolidates multiple security capabilities into a single, intelligent solution, providing AWS customers with real-time visibility and autonomous protection to simplify security operations and reduce risk.
Core Capabilities & Benefits
Autonomous Protection: Singularity Platform is designed for customers seeking enterprise-wide protection, detection, and response capabilities, augmented by the intelligence and speed of advanced AI and automation. SentinelOne's Singularity Platform protects thousands of customer environments, including Amazon cloud workloads, across the globe.
Unified Visibility: Break down data silos and security tool sprawl. Using patented Storyline™ technology, the platform automatically correlates and contextually groups related events into a single attack story, providing a consolidated view for faster investigation and response within our unified data lake.
Extended Detection & Response (XDR): Gain a complete, correlated view of the full attack story across endpoints, identities, and cloud workloads. Our XDR solution provides the context needed to understand and respond to threats at machine speed.
Cloud Workload Protection Platform (CWPP): Secure your AWS compute resources from runtime threats. Our Singularity Cloud Workload Security delivers real-time, AI-powered threat detection and response for Amazon EC2 instances, EKS clusters, and AWS Fargate. It provides deep visibility into vulnerabilities and configuration risk while autonomously blocking malware, ransomware, and fileless attacks without disrupting production performance.
Identity Threat Detection & Response (ITDR): Proactively defend against credential theft, privilege escalation, and lateral movement attacks across hybrid environments. Our solution provides continuous monitoring and protection for Active Directory and leading cloud identity providers, including Entra ID, Okta, Ping, SecureAuth, and Duo, ensuring identity infrastructure remains secure.
Accelerated Incident Response with Generative AI: Purple AI, our generative AI security analyst, acts as a force multiplier for your security team. It automates threat hunting, provides instant summaries of complex incidents, and accelerates investigations, allowing your team to focus on strategic initiatives.
Seamless Integration with AWS Services
The SentinelOne Singularity Platform is designed for seamless integration into your existing AWS environment. We provide bidirectional integrations for AWS Security Hub and Amazon CloudWatch, ensuring your security findings are centralized and actionable. Additionally, our AI-powered malware scanning for Amazon S3 protects sensitive data while maintaining compliance, helping you maximize your AWS investment and enhance your overall security posture.
How to Get Started
Secure your AWS cloud and focus on innovation with the SentinelOne Singularity Platform. Simply click on the Request private offer button at the top of this page to begin your procurement process.
Highlights
- 338% three-year ROI for SentinelOne customers using Purple AI, included with SentinelOne Singularity Platform Complete
- 96% of Gartner Peer Insights™ EDR reviewers recommend SentinelOne Singularity
- 5-Consecutive Year Gartner® Magic Quadrant™ Leader for Endpoint Protection Platforms
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Trust Center
Buyer guide

Financing for AWS Marketplace purchases
Security credentials achieved
(1)

Pricing
Dimension | Description | Cost/month |
|---|---|---|
Custom Pricing and Packaging | Contact SentinelOne for custom pricing and packaging including Private Offers | $10,000.00 |
Vendor refund policy
Refunds available as required by law.
Custom pricing options
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
Software as a Service (SaaS)
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
Support
Vendor support
Multiple support options available. Email support available: support@sentinelone.com
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
FedRAMP
GDPR
HIPAA
ISO/IEC 27001
PCI DSS
SOC 2 Type 2
Standard contract
Customer reviews
Fast, Feature-Rich Endpoint Protection with Deep Visibility and Vulnerability Scanning
Endpoint security has provided deep attack visibility and delivers fast, reliable detections
What is our primary use case?
My main use case for SentinelOne Singularity Endpoint is running the Picus Breach and Attack Simulation tool in our lab environment. After performing attacks on specific EDR tools, we understand which tools require which kind of exclusions to complete the attacks properly. We also determine how we can tighten the security policy, what kind of rules we can add, or which options we can tighten. After the prevention section, we can integrate with the API endpoint on SentinelOne Singularity Endpoint, and thanks to that, we can also fetch some logs and validate the operation in the detection side.
What is most valuable?
The best features that SentinelOne Singularity Endpoint offers include the EDR visibility. It helps me understand which kind of operation Picus has done on the system, the timeline, the process tree, and which kind of command has been executed. Thanks to that, we can write the proper exclusions or write the proper security tightening rules. The visibility provided by SentinelOne Singularity Endpoint is the best part.
On the integration side, we integrate SentinelOne Singularity Endpoint with Picus to collect the logs from the host where SentinelOne Singularity Endpoint is installed. We can collect the logs and the alerts related to the specific machines. In different products, we can see some delay on the ingestion time. After a couple of attacks, sometimes we lose some of the logs because the security solution only logs a couple of the attacks but not all of them. However, we did not encounter this issue on SentinelOne Singularity Endpoint. Each time we can access all the logs created by Picus itself, which means SentinelOne Singularity Endpoint does not miss the logs. We also did not encounter any ingestion time delay issues on SentinelOne Singularity Endpoint. In some other products, we can encounter logs that have been created after the attacks have been finished, long after the fact. We did not encounter this issue on SentinelOne Singularity Endpoint. I can conclude that SentinelOne Singularity Endpoint is good at logging and alerting.
SentinelOne Singularity Endpoint has positively impacted our organization in that we do not use SentinelOne Singularity Endpoint in the whole company. We are only using SentinelOne Singularity Endpoint on the lab environments to validate the Picus attacks. Based on our experience, SentinelOne Singularity Endpoint's score is high when I compare it with well-known EDR solutions. I can say that SentinelOne Singularity Endpoint is one of the good products.
What needs improvement?
I cannot think of anything to suggest to improve SentinelOne Singularity Endpoint. If I find something, I can create a feature request for them.
The reason I provide an eight for SentinelOne Singularity Endpoint is that it is easy to use and detection is faster than the other EDR products. There is no delay, ingestion delay, or missing logs on SentinelOne Singularity Endpoint. However, I do not provide a ten out of ten because when I compare it with different products, SentinelOne Singularity Endpoint is at the third position. This means that on the prevention side, it might be better. This is the reason I provide an eight. Additionally, when I log into the system, sometimes I encounter some problems. For example, it asks for username and password. After the username and password, it asks for the token, meaning the OTP, but it turns me back to the first page without any notification. I just enter username, password, and OTP again to log into the system. I do not know which kind of problem I encountered, and it just did not throw an error. Instead of that, it just turned me back to the login page. This is not a good issue. I also encounter some problems on the support side. When the policy override was first announced for the Breach and Attack Simulation tools, we as Picus provided some feedback related to the policy override because it does not work for Picus. We contacted the support team, provided our observations, and explained why it does not work and what kind of enhancement could be done. However, the support team ignored us and just said they would look at it. I am not sure whether anybody looked at it, because it did not change. Still, when sometimes we encounter a customer using the policy overrides instead of the exclusions suggested by Picus, they encounter the problem where SentinelOne Singularity Endpoint kills the Picus services. After we connected to the system, we understood that the customer was using the policy override, but the policy override does not work. Perhaps the support responsiveness might be enhanced.
For how long have I used the solution?
I have been using SentinelOne Singularity Endpoint for approximately three years.
What other advice do I have?
I notice that integration is faster with SentinelOne Singularity Endpoint. It is also a kind of product that is easier to use. In some products, I do not want to mention the names of them, but some of them are hard to use, whereas SentinelOne Singularity Endpoint is easy to use. I did not use SentinelOne Singularity Endpoint before starting at Picus. Even though I did not use it before starting at Picus, I easily got used to it because the UI is easy to use and everything seems clear. I only use SentinelOne Singularity Endpoint in the lab environment. We did not use it in the whole company. However, if we had been using it, we would have benefited from it. I can say SentinelOne Singularity Endpoint offers faster detection.
I looked at the console and I see some numbers related to the different EDR vendors for both simulation speed and also the result itself. SentinelOne Singularity Endpoint's score is demonstrated as the third highest score in the system. It is also the third speediest one. This means that overall, SentinelOne Singularity Endpoint has demonstrated good performance. I provided a rating of eight out of ten for SentinelOne Singularity Endpoint.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Powerful EDR and Automated Threat Response with Centralized Visibility
Automated threat blocking has improved our detection speed and simplifies overnight incident response
What is our primary use case?
SentinelOne Singularity Endpoint actively monitors endpoints continuously whenever there is activity, and then correlates the events accordingly, and flags threats using a storyline.
It actively detects and monitors if anything suspicious happens on the endpoint, and then actively blocks it and raises an incident alert for the security team to review.
There was a recent incident where there was a modification of a VSS backup on a server endpoint. SentinelOne Singularity Endpoint actively detected that modification and raised an alert with us, and we quickly reviewed it. Although it was a false positive, it was a legitimate application that was trying to modify the VSS backup and delete and take a fresh backup from scratch. However, SentinelOne Singularity Endpoint actively monitored it and flagged it as suspicious activity. Though it was a false positive, the underlying activity was detected correctly.
Whenever it detects threats, it helps us respond to threats quickly because the EDR actively monitors the threat and blocks it. When there was suspicious activity at three o'clock in the night, SentinelOne Singularity Endpoint does not require active monitoring of the alert by the team. In that scenario, there could be a lot happening by the time when we see the alert, and the latent moment might have occurred since the start of the attack. SentinelOne Singularity Endpoint actively monitors the threat and then blocks the threat if any other suspicious attributes are being shown as part of the attack. This is the feature that I appreciate about SentinelOne Singularity Endpoint; it actively blocks the threat and once it blocks the thread, we can review it later on and look for more details, and we can unquarantine the thread if we feel it is a false positive, or we can take action accordingly. It actively blocks the threat from moving laterally.
What is most valuable?
The recent feature is the Prompt AI. Using that Prompt AI feature, we can get queries to build a quick summary. We can build a query using natural language processing, which means plain English text, and it gives the query accordingly, and it is going to be useful for us to threat hunt and actively identify threats. That is a good feature. The other additional feature is retrieving the files from the computer even though the machine is isolated through the shell. These are pretty good features that I have found useful.
It actively monitors the endpoints for any threats. There is no such EDR that could actively block any kind of threat in the world.
It consolidates the vulnerability management side by actively identifying the risk applications that have been running in the endpoints. We can do the threat hunting through the log collections from the endpoints and then actively write a query to identify the threat that has been running in the environment. It also does the network scanning and also a bit of the VSS management. We can manage the VSS backups as well, handling the VSS snapshot backups through that. It has been a pretty good product, and it could have more capabilities or additional capabilities as well.
What needs improvement?
For now, it has been pretty good. I could not think straight on top of my head what one feature could be added. But for now, the features that SentinelOne Singularity Endpoint offers are pretty great. However, I wish there could be patching that could be happening through the EDR so that we would not need to manage any other separate tool for patching those vulnerabilities since it actively identifies vulnerabilities. Maybe that feature could be helpful. I am not sure whether the single agent can uplift the bulk activity or not. That is one thing I wish I could add in SentinelOne Singularity Endpoint.
We need to set the guardrails for the Prompt AI because it actually queries the logs directly for whenever we want to search in the endpoint logs. Whenever we give a prompt to actively look for something, it actively queries directly inside the logs and returns the output directly instead of just giving a suggestion to go this way or do that way. It actively interacts with the application inside itself and provides results directly without showing the backend process. I am not sure about how the guardrails were set, but setting the guardrails for the AI needs to be taken care of. Since it has pretty much direct access to the endpoints and there are agent capabilities through SentinelOne Singularity Endpoint, we have to take care while handling or implementing AI.
For how long have I used the solution?
I have been using SentinelOne Singularity Endpoint for over a year.
What do I think about the scalability of the solution?
It has been good as far as I am concerned. If we have a good number of licenses, as long as we are near the limit, it is good.
How are customer service and support?
I can understand that since there is a shortage of staff in SentinelOne, sometimes when we raise a case, it takes some time to respond. However, since we have the Prompt AI, things have been pretty easy for us to handle by ourselves instead of relying on tech support or customer support. The tech support does a great job whenever we raise a ticket.
Which solution did I use previously and why did I switch?
We did evaluate CrowdStrike.
What other advice do I have?
The impressions are pretty great. It has been actively blocking the threat and also correlates all the events using storyline, which has been pretty great.
It is going to be really helpful because earlier, I used to go through the documentation, and it used to take a lot of time for me to actively find the relative answer to the question. With the Prompt AI, I can just query my question to the Prompt AI, and then it actually returns the results in a better way. If I have any queries, I can reach out to Prompt AI instead of raising a tech support case. It saves a lot of time.
My suggestion would be to look at whether, based on the range of the products that we use, SentinelOne Singularity Endpoint supports those products or not, and then accordingly, we can purchase SentinelOne Singularity Endpoint and also evaluate how well it integrates with other security solutions inside our environment. I gave this review a rating of eight out of ten.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Unified endpoint protection has reduced manual work and provides autonomous threat response
What is our primary use case?
My main use case is to protect the endpoints. Back in 2020, I conducted multiple proofs of value for different vendors, including SentinelOne. At the end of my evaluation, SentinelOne was the solution that provided a better fit for what we needed to do, and it was one of the best solutions, not just in terms of doing what it was supposed to do, but also in terms of cost. The end goal was to protect the endpoints, including Windows, Linux, and MacOS systems, as well as Windows servers and cell phones.
What is most valuable?
I have had multiple cases where end users fell victim to phishing emails or visited the wrong link. The EDR solution from SentinelOne was able to mitigate the potential threat, which protected not only the end user but also the company. This has also happened on servers. I have seen servers exposed to the Internet that had advanced threat actors trying to get into our networks, and SentinelOne's EDR solution has been able to mitigate such attacks and in some cases perform rollbacks. We also receive notifications via email and in some cases messages, which helps us stay on top of things and makes troubleshooting much easier. SentinelOne performs the mitigation on its own, which allows me to have peace of mind. Security is not absolute, and something else will happen, but from my experience, I am able to rely on the solution and know that it is going to do what it is supposed to do. Beyond protecting the endpoint, the autonomous response capability allows remediation of threats at machine speed without my intervention. The solution just does it on its own.
Today, I use SentinelOne for EDR, but we also use it for XDR. We are able to do assessments against our on-premise Active Directory as well as Azure, Microsoft Defender, and Exchange. We are collecting logs from our Azure enter ID, which gives me visibility that is sometimes difficult to find in the Microsoft 365 suite of tools. Being able to go into the SentinelOne Singularity Endpoint console and narrow down to the main events happening across the different platforms that we use makes things much easier, allowing me to be aware of what is happening and to triage items when needed. Having the complete SentinelOne Singularity Endpoint solution, not just with endpoint security but also with identity protection, makes my job much easier. If I had to do this manually, it would take a long time. Having the thermal response, behavioral AI, identity assessment, and the ability to stop potential lateral movements is a significant help.
SentinelOne Singularity Endpoint offers many features. I really appreciate what EDR is able to do, not only on the antivirus side. Having a single agent on an endpoint gives me the ability to handle multiple potential threat vectors. Instead of having multiple agents doing different things, SentinelOne Singularity Endpoint agent handles the antivirus side, endpoint protection, and with the behavioral side using AI, it is able to learn, see suspicious activities, track them, and isolate potential compromised devices automatically. When looking at our Active Directory, it has been able to do assessments and provide what the threat is using things such as MITRE, along with solutions on how to fix it. There is not one feature in particular; it is looking at it holistically and seeing how we can protect our premises not just from the endpoint but also from an identity perspective. Both complement one another.
On the behavioral AI, it is learning about our platforms and how they behave. We have multiple systems, some of which are exposed to the Internet because that is where our website is or where platforms multiple users use that are public facing. The behavioral AI is able to learn what a system is supposed to do, and if it notices something different, it tells us about it. Simple things such as if I remotely access a device and begin using PowerShell, in some cases it will alert me and say this activity does not look normal. The behavioral AI is able to see potential activity that is just not normal, create a baseline, and act upon it.
What needs improvement?
One of the things I would like to see from SentinelOne Singularity Endpoint is the vulnerability side of things. Today, vulnerabilities is one of the features that allows me to see what is happening with the endpoints, looking at the number of applications installed and which ones need immediate attention. However, we do not have patch management from SentinelOne Singularity Endpoint. Having patch management would make it even better. I would be able to take action from there and push the updates needed by the endpoints. If I were able to fix it or take action from SentinelOne Singularity Endpoint console, it would make my job much easier.
When it comes to reports, I was hoping to have better reports. For example, I tried to do a report to see the number of vulnerabilities affecting our endpoints and which were the most critical, but I was not really able to do that because of the limitations when it comes to doing reports. Reports is something that really needs work so that we can get better reporting, even though the dashboards are there and provide good telemetry. Having an executive level report would be a lot of help.
For how long have I used the solution?
I started using SentinelOne Singularity Endpoint in October 2020.
What do I think about the stability of the solution?
It has always been stable, and I have never seen any issues with it being unstable.
What do I think about the scalability of the solution?
Adding new endpoints is really not difficult at all and is super simple, especially because we use a script with our endpoint manager. We push the script, and it deploys without requiring a lot of work.
How are customer service and support?
Customer support has been amazing.
Which solution did I use previously and why did I switch?
For the current company I am working with, they had no EDR solutions. My recommendation was to deploy SentinelOne Singularity Endpoint as the EDR solution. At my previous company, we replaced CarbonBlack. I made a recommendation to replace CarbonBlack with SentinelOne Singularity Endpoint because of the functionality, being able to have antivirus and protect the endpoint using EDR as well as the AI side of things, including identity.
How was the initial setup?
When I first deployed SentinelOne Singularity Endpoint, we had multiple solutions handling orchestration for our cybersecurity program, which meant having multiple agents doing different things and collecting telemetry. In the past, I had CarbonBlack and other solutions and was missing out on things. Being able to have a single console to look at multiple metrics from different endpoints, including servers both Windows and Linux, as well as identity, has made performance and productivity much better.
What about the implementation team?
For hybrid deployment, we use NinjaOne. We are able to push the endpoint installation through our endpoint manager.
What was our ROI?
I do not have metrics as to how much time the solution has saved me, but I can give an example from my experience. I go to work in the morning and take a look at the platform for ten to fifteen minutes, then maybe during lunch and before I clock out. I do not have to spend a lot of time on the platform. If something happens, I get a notification or an alert about the incident. For the most part, we are not spending a lot of time looking at things. We know that if something happens, we are going to be notified.
What's my experience with pricing, setup cost, and licensing?
Pricing has been one of the best things. I have compared this to other platforms such as Cyber Reason and CrowdStrike. Price-wise, it was the best pricing. The deployment is straightforward and not complicated. We were able to use our Endpoint Manager solution to begin installation, and that has made a huge difference.
Which other solutions did I evaluate?
Cyber Reason, CarbonBlack, and CrowdStrike were all alternatives I evaluated.
What other advice do I have?
I do trust its alerts, and I do think that it is catching things. It is simple and straightforward. Looking at the marketplace, I am able to do the integrations as long as they follow the instructions, and it is pretty straightforward. I do not know that it has helped reduce alerts, but over time, users are aware that these platforms are installed on the endpoints and understand that if something happens, they are going to see the alerts come up and see the mitigation take place. They have seen that in the past. From an admin point of view, it is much easier to take a look at a single pane versus multiple platforms. Users are beginning to see that there is something installed on their computer whose whole job is to protect the endpoint. Do your homework and make sure that what you are getting out of SentinelOne Singularity Endpoint aligns with the goal of the business. Understand what the business is that you work with, conduct an assessment, and see if SentinelOne Singularity Endpoint aligns well with the company's goals. I would rate this solution a 9 out of 10.