Our main use case is to protect all the Linux servers. We use it only for servers, not for users.
SentinelOne Singularity Platform
SentinelOneExternal reviews
External reviews are not included in the AWS star rating for the product.
Good EDR product with bad customer support team.
it is easy to use.
there is no automation to do full disk scan in the UI.
Bad customer support. they take months to solve a simple issue. they hide behing the chat and they are reluctant to come on call to fix certain issue.
User-friendly interface and policy customization helps with server protection
What is our primary use case?
How has it helped my organization?
SentinelOne Singularity Complete is one of the most mature solutions available. It shows great benefits over time.
We can install filters to analyze every alert, and make some whitelists, blacklists, and exceptions, thus helping reduce alerts.
It can reduce the organization's risk. It gives better control to our limited team resources.
It already has AI capabilities, which is one of their advantages.
What is most valuable?
When you select a policy for a type of server, such as an Active Directory, we can apply a dedicated policy. We can have a dedicated policy for Exchange Server and a dedicated policy for MS SQL, Oracle server, etc.
The interface of SentinelOne Singularity Complete is user-friendly, and we can quickly find what we need.
What needs improvement?
The main issue with SentinelOne Singularity Complete was the process memory used for Linux servers, which generated a lot of tickets and incidents due to the high load of disk consumption and memory. The problem was on all systems, but especially on Linux servers. It might have already been fixed.
SentinelOne Singularity Complete is the best EDR in the market, but it will evolve, though I have concerns about using US partners in Europe due to the geopolitical context. It is better to work with European companies.
For how long have I used the solution?
I have been using SentinelOne Singularity Complete for approximately four years.
What do I think about the stability of the solution?
For stability, I would rate it a nine, as I have experienced only the issue of overload.
How are customer service and support?
The technical support from SentinelOne Singularity Complete is very active and good, with a strong knowledge base available online. The response time of technical support is satisfactory and acceptable.
I would rate their support a nine out of ten based on reactivity and the solutions they provide; this is based on my team's interactions, not mine.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
For Windows servers, we are using Defender. SentinelOne Singularity Complete is only used for Linux servers.
How was the initial setup?
The initial setup was not really complex; we only needed one on-premise management server to deploy to different servers. It took about two months for about 300 servers.
What about the implementation team?
I am the third party assisting in the deployment.
What's my experience with pricing, setup cost, and licensing?
I don't know about the licensing model. It seems easy, but it's not my area of expertise. I don't have information on how it compares to its competitors, but the pricing is per device.
Which other solutions did I evaluate?
We conducted some PoCs between SentinelOne Singularity Complete, Defender, and Carbon Black, and we decided to go with SentinelOne Singularity Complete based on usability.
What other advice do I have?
It is unclear if it has helped reduce our organization's mean time to detect or respond because we have a platform with four people, and we are using SOC as well. Our main activities are done by four people, and we don't have much time to conduct thorough investigations.
I cannot assess SentinelOne Singularity Complete's ability to be innovative because we stayed with it after choosing it and never compared it with others.
Overall, I would rate SentinelOne Singularity Complete a nine out of ten because nothing is perfect, but it is close.
Simplifies operations with good UI and centralization
How has it helped my organization?
Singularity Complete has helped reduce alerts. We have one place to go to check them, and there is also a reduction in false alerts.
Singularity Complete helped free up our staff for other projects and tasks. I do not have the metrics, but it saves a lot of time compared to what I have used at other companies.
Singularity Complete has helped reduce our mean time to detect. We only have to look at the portal. We can quickly isolate the user or the device, which also stops the virus from spreading. It also reduces our mean time to respond.
What is most valuable?
The web portal has a really good web UI, and all the things are well integrated. It is easy for us to increase the number of users because it is pretty simple.
What needs improvement?
The maintenance window can be improved because once it happened that I had multiple laptops, and the maintenance window caused a lot of laptops to get stuck in the portal, blocking access. This is important to address. The basic functionalities should be up and running even during maintenance windows. I understand that it is a software-as-a-service model, but it becomes a problem if I cannot do anything when issues occur during maintenance.
They could make it simple to have a SIEM integrated with their solution so that we can send logs to their server and then analyze them.
For how long have I used the solution?
I have been using SentinelOne Singularity Complete for almost one year.
What do I think about the stability of the solution?
It is stable.
What do I think about the scalability of the solution?
It is scalable. We have 50 users in our company. We have three administrators. We also have a consultant.
How are customer service and support?
I did not have the opportunity to contact them because I had almost no issues.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
We were probably using Webroot. I was not there when they made the decision to switch.
How was the initial setup?
I did not participate in the initial setup, but our new onboarding process for laptops is really straightforward. You just join the domain, and the software gets installed automatically. It is bound to our site, making it very easy.
What was our ROI?
It is difficult to measure ROI, but since we started using it, we have not had any problems related to security. We have not experienced any breaches or issues so far.
It has absolutely helped reduce our organizational risk.
What's my experience with pricing, setup cost, and licensing?
Overall, it was a good experience. It is pretty easy for us to increase the number.
What other advice do I have?
SentinelOne is focused on this solution. This is evident in the GUI. The GUI is well done compared to solutions like Microsoft Defender which I have been trying to get into, but it almost repels me. SentinelOne Singularity Complete is very stable and mature. It is one of the best solutions that one can choose.
I would rate SentinelOne Singularity Complete a nine out of ten.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Reduces workload by consolidating functionalities into a single platform
How has it helped my organization?
Singularity Complete integrates well. We have changed our monitoring solution, and SentinelOne supports that solution. We are using SecureWorks to monitor our system. It is directly using the SentinelOne agent. All security logs for SentinelOne and other security products are being pushed to that one. SecureWorks consolidates all the logs and alerts, and we are getting 24/7 monitoring.
Singularity Complete significantly reduces alerts. It has reduced false positives by 30% to 40%.
Singularity Complete helps free up our staff for other projects and tasks. We have fewer false positives. We are very comfortable with it. Before, we had to provide extensive technical support for endpoint protection, but after installing the agent, administration became much easier.
Singularity Complete has been excellent, and we have not faced any issues in the last three to four years. It has reduced critical risks significantly.
Singularity Complete has reduced our mean time to remediate to a good level. It has also reduced the organizational risk.
We have used Ranger, but it is not always useful for us because most of our users are working from remote areas. It is a bit difficult for Ranger to identify them because they are working with some local networks. However, we are protecting our endpoints with the agents. It is mandatory for our technicians to install this agent.
What is most valuable?
APT and ransomware protection is valuable. We also use the Vigilance service from SentinelOne. It is a complete XDR platform for us.
What needs improvement?
Sometimes, support can be lacking. We would like to have more interactive sessions, which are not currently available. A chat service for technical support would also be beneficial. With other vendors, we are able to resolve small issues through the chat, whereas with SentinelOne, we have to open a ticket. Without a ticket, we cannot do anything. It takes more time.
They should host a data center in Saudi Arabia, making it easy for customers to go for a SaaS model.
For how long have I used the solution?
We have been working with SentinelOne since 2019. It has been almost five years.
What do I think about the stability of the solution?
For EDR, the solution is perfect. Over the five years of using it, many improvements have been made. Initially, there were issues, particularly on the management side, but now the console is much more stable.
How are customer service and support?
They can provide more interactive options for support. For example, a chat service would be beneficial.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
Previously, we were using Trend Micro, which posed a lot of issues. Trend Micro has different products for different things. For example, they have a different product for servers and a different product for clients. For management and reporting, there is another product. We have to manage a lot of things in Trend Micro.
SentinelOne has consolidated these functionalities into a single platform, greatly reducing our workload.
How was the initial setup?
The SaaS model is better, but due to some regulations, companies are hesitant to go for it.
Deployment was challenging because we did not have software distribution capabilities at the time, and my technicians faced many challenges. I tried using group policy, and it worked for some clients, but not all, since half of my employees work remotely. Once deployed, agent updates were automated from SentinelOne.
Maintenance is not required because we are using the SaaS model. We do not have any servers to manage, as it is a SaaS-based solution. When there is a new agent release from SentinelOne, we just have to deploy it from the console.
We have different entities inside our organization. It took us three to four weeks to deploy to about 1,500 endpoints.
What about the implementation team?
My team handled the deployments. We had five to six technicians.
What was our ROI?
We have not faced any attacks since we implemented it. We had some critical incidents before this. In that respect, we have saved costs.
What's my experience with pricing, setup cost, and licensing?
Its cost is similar to Trend Micro, but the protection is much better. If you want protection, you have to pay the price.
What other advice do I have?
This technology is perfect for us. They are good at innovation and enhancements. We have good visibility across the network and endpoints. The product is continually improving, and I am very satisfied with it. I have already recommended it to a few people.
Overall, I would rate SentinelOne Singularity Complete a nine out of ten. There are areas for improvement, such as support and hosting data inside Saudi Arabia.
Automation has freed up our team, streamlining quick actions and restoration capabilities
What is our primary use case?
First, budget-wise, and for the quick actions I take in automation, certainly AI plays a crucial role.
What is most valuable?
The most valuable features are the quick action and restoration capabilities. I can catch any behavior and restore everything for the last two changes. There's also automation that gives my team free time, preventing them from having to look for every alert. As a result, we don't need their action on some emails.
What needs improvement?
Integration with the firewalls is needed because there is no integration with Forti as a FortiAnalyzer. It is currently integrated with FortiManager and the Forti box, but if I have an analyzer, it doesn’t integrate with them. It would be better if there were direct integration with FortiAnalyzer.
For how long have I used the solution?
I have used the solution for two years.
What do I think about the stability of the solution?
The stability is just okay.
What do I think about the scalability of the solution?
The scalability is good at more than ninety percent.
How are customer service and support?
I would rate the customer service at an eight.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I tried, when busy, CrowdStrike, and as an endpoint, I work with FortiClient.
How was the initial setup?
The setup is complex related to the XDR because there are more logs, and the queries need someone expert for that. I should create a guide.
What about the implementation team?
The deployment has been done in-house by my team.
What was our ROI?
If I compare prices between SentinelOne and another solution, I have already conducted this exercise, and SentinelOne is cheaper by more than sixteen percent.
What's my experience with pricing, setup cost, and licensing?
It’s cheaper than other competitors.
What other advice do I have?
I will recommend it to other clients. The quality is good for us based on our operations. We don't have a huge amount of transactions, but it’s good for us. The solution meets our needs. It’s good. Overall product rating is eight out of ten.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Has efficient licensing, minimal overhead, and fast client communication with the web console
What is our primary use case?
We have it for all of our client machines and servers. It is the antivirus solution for all clients and servers. We are also looking into going further with their log analysis portion. We are working with them in terms of pricing.
How has it helped my organization?
The overhead on the CPU is minimalistic, not taking up too many system resources.
Making exceptions and exclusions through the console interface is smooth, providing a very good experience. The clients communicate with the web console in less than a minute, which is much faster than other solutions such as Malwarebytes.
SentinelOne has helped us with consolidation. We have Malwarebytes installed along with SentinelOne, and we are moving just to SentinelOne. SentinelOne has the most widespread and up-to-date coverage because of the fact that we can deploy it fairly quickly. Its rogue detection feature helps catch systems missed during initial deployment. We are the most up-to-date now.
It saves time for the staff once it is up and running. Once the system has gotten used to everything, it just works. There is a six to eight-month learning curve for the system to get used to your servers and software.
In the beginning, we had a fair number of false positives coming across, but once the system got set up, it has been pretty much running on its own. If we are running a lot of internal IT scripts for applications that are triggering the antivirus, it might detect that as suspicious. We have to configure it to exclude things. Overall, it is pretty smart. Its automation is working fairly well for us that way.
As a strategic partner, they have been very vocal with us. They have been communicative and supportive. The product itself is robust. We have not had any situation where it failed and broke the computer. There is no CrowdStrike-type scenario going on.
Based on the updates they have done, they are focused on advancing the product. There is a constant evolution going on. The system is getting more robust. We are advancing and not digressing anywhere in terms of technology.
What is most valuable?
We moved from ESET, and we find that the licensing scheme, particularly how the licenses are attributed to clients, is pretty nice compared to what ESET offers. We work in a highly virtualized environment. We have roughly 150 to 160 virtualized clients that are refreshed daily. Every night, the systems refresh. With the old antivirus solution, the licensing would count into the thousands, necessitating manual deletion. Luckily, SentinelOne has a feature to decommission automatically, which has been fantastic.
What needs improvement?
One area for improvement is automated deployment. I use it through a group policy. I put in the PC name, and when the user logs in, if the PC is in that group, it attempts an MSI install through Active Directory via GPO. That seems to play a little havoc and can conflict with manual installs, causing issues where it wants to delete and reinstall the client. To resolve this, I remove the computer from the security group, and it then stops complaining. The automated installation could improve in this regard.
For how long have I used the solution?
We have been using SentinelOne for one year.
How are customer service and support?
I would rate their support an eight out of ten. The rating would be better if they picked up the phone and had someone talk immediately. We are using the automated email process for support, and they respond within an hour or two hours sometimes.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We had moved from ESET.
What was our ROI?
We have not been hit since using it. I have experienced a ransomware attack only once, a few years ago, with minimal damage. Since then, I have not faced any intrusions, which is one reason I chose SentinelOne over ESET.
It has not helped us save costs. We are increasing costs because we are going more toward the avenue of protecting as a city. We have been watching other cities around us get hit, so there is more focused attention on protection at this level. We are moving to the complete license solution and looking at expanding that into Vigilance.
What other advice do I have?
When it comes to interoperability, we are going to look at some integration with our FortiGate system for the firewall to help analyze the logs that come through there. We are slowly moving from stopping the intrusion to more like a preemptive, preventative focus.
To those considering using this solution, I would advise digging into the console and taking the time to learn. Some people complain and find it confusing, but understanding the system's ins and outs is crucial. The console is well laid out, so it is worth taking the time to learn it.
The quantity of detection is quite a lot in the first few months. The product has a learning curve, so you have to guide it in the beginning so it gets used to the scripts and applications that are running in your system. We have created quite a list of exclusions, and I always take the time to look at each one. Since September 2024, false positives have been reduced to one every two weeks.
Overall, I would rate it a nine out of ten.
Excellent EDR solution
Secures our environment with reduced alerts but better threat notifications needed
What is our primary use case?
I use SentinelOne Singularity Complete on our servers, specifically in our remote desktop services environment. I also use it alongside ESET for our workstations. Our environment isn't huge, with about 30 people, although we've had up to 50 users. I mostly use it as a security solution.
How has it helped my organization?
We have noticed a reduction in alerts since implementing SentinelOne Singularity Complete.
What is most valuable?
The security aspect is the most valuable feature for me. Although SentinelOne Singularity Complete is marketed as providing superior blocking capabilities, my experience has varied. It has helped reduce alerts compared to other security solutions, which can be a positive feature since constant alerts tend to be overwhelming. However, this also leads to uncertainty about whether the solution is doing its job effectively.
What needs improvement?
The solution could improve its notifications and communications. For example, I don't receive much information about what threats have been blocked. A weekly report logging blocked threats would be helpful. Additionally, there should be a balance between too many notifications and no notifications at all, as neither product I'm familiar with strikes a comfortable medium.
An agent of ours clicked a link in an email that initiated what appeared to be a ransomware attack. The only thing that prevented the attack from succeeding was a free version of Malwarebytes that was running on the session, which effectively protected against it. The MSP confirmed that SentinelOne failed to detect the threat, but the free Malwarebytes version ultimately prevented it from impacting or compromising our systems.
Singularity Complete's interoperability with other SentinelOne solutions works well, but it doesn't work well with other third-party tools. Initially, it conflicted with the ESET we use on our workstations and the staff computers, and then they had to set up a white list for that.
For how long have I used the solution?
I have a year and a half of experience with SentinelOne Singularity Complete.
What do I think about the stability of the solution?
SentinelOne Singularity Complete sometimes conflicts with third-party solutions. Initially, it conflicted with ESET on my workstations, requiring a whitelist setup. This indicates room for improvement in stability when interacting with other solutions.
What do I think about the scalability of the solution?
My deployment is relatively small, and SentinelOne Singularity Complete works within those constraints. However, it is more of an add-on than a tool for consolidating security solutions within my organization.
How are customer service and support?
My experience with SentinelOne's customer support has been mixed. We were performing a software upgrade for our Office Suite, which required temporarily disabling SentinelOne on the server. This was necessary because we were removing and reinstalling software. However, we couldn't simply request that our MSP disable it immediately. SentinelOne's policy required the MSP to contact their company and schedule the deactivation at least 24 hours before. Although we notified the MSP 12 hours before our intended start time, we could still not proceed as planned. Consequently, we had to postpone the project by an additional 24 hours.
How would you rate customer service and support?
Neutral
Which solution did I use previously and why did I switch?
We previously used ESET on our servers, but our managed service provider recommended switching to SentinelOne Singularity Complete. ESET provided more frequent notifications, alerting us when it blocked something, which was helpful, although sometimes a bit excessive, similar to Norton products. While not quite as intrusive, finding a comfortable balance between ESET's transparency and Singularity Complete's lack of communication is challenging. Neither product offers the ideal middle ground; it's either an overwhelming number of notifications or none at all.
How was the initial setup?
The initial setup was handled by the MSP, and I was somewhat against it from the start because I had heard rumours about it being a significant resource hog. My only concern was that I didn't want anything that would negatively impact the environment and slow it down, as the agents don't have time for that. Unfortunately, right from the start, we experienced the very impact I feared. Agent logins, which usually took around ten seconds, took six to seven minutes.
The deployment was completed in one day.
What about the implementation team?
My implementation involved three people: myself, the marketing VP, and a former IT staff member. I had to reboot the servers, which caused minimal downtime.
What was our ROI?
Other than some delays initially with the agents and then during a software upgrade, there hasn't been any significant impact on ROI.
What's my experience with pricing, setup cost, and licensing?
I did not notice a significant increase in cost after adding SentinelOne. It was close to the previous year's cost, which could be an annual increase unrelated to SentinelOne.
What other advice do I have?
I rate SentinelOne Singularity Complete seven out of ten.
When we first deployed SentinelOne Singularity Complete with remote desktop services on our RDS server, we encountered problems. The software was running multiple instances of itself, one for each user session, in addition to the instance running on the actual server hardware. This caused the server to run extremely slowly, with users experiencing login times of six to seven minutes before reaching their desktops. To fix this issue, the MSP changed it to where it wasn't running independent sessions. It would just run on the server itself. It took the MSP half a day to make the changes.
SentinelOne Singularity Complete can be a decent solution for environments with newer hardware that can handle the overhead. It has a reputation for being secure, but its impact on performance was not suitable for my environment.
Secure and gives the sense that our endpoints are protected
As something we use daily the console is inutitive and easy to use. We have very rarely used customer support but when we have they have been great.