It's good for log management and security and is integrated with other solutions. It offers automatic response and remediation.
SentinelOne Singularity Platform
SentinelOneExternal reviews
External reviews are not included in the AWS star rating for the product.
Interoperable with the ability to ingest and correlate across security solutions
What is our primary use case?
How has it helped my organization?
It's helped us filter for security issues. This product can organize and visualize incidents for us. It's helped a lot with remediation and mitigation.
What is most valuable?
The XDR is very useful. The agent that collects data from servers is pretty effective.
The interoperability with other SentinelOne solutions or third-party solutions is quite helpful.
Our impressions of the solution's ability to ingest and correlate across our security solutions is perfect. We're satisfied with its capabilities in this regard.
It's helped us consolidate our security solutions a bit.
The Ranger functionality helps provide visibility. We're provided with security mapping for applications and can see end-to-end traffic. We also don't need to add agents or hardware or make network changes. It's easy to use. The Ranger functionality 10% helps prevent vulnerable devices from becoming compromised.
It's reduced our alerts by about 80%.
We have been able to free up staff time as it's not that time-consuming.
It's helped us reduce our mean time to detect as we can now see issues in real time. It's also helped with our mean time to respond.
We've been able to reduce organizational risk by 70% using this solution.
What needs improvement?
I'd like to see us be able to take action on one platform for items such as security variation, security orchestration, automation, and response (SOAR).
For how long have I used the solution?
I've been using the solution for 3 years.
What do I think about the stability of the solution?
The stability of the solution has been good.
What do I think about the scalability of the solution?
The solution is scalable.
How are customer service and support?
I've never escalated questions to technical support in the past.
Which solution did I use previously and why did I switch?
I have used Splunk as well. SentinelOne is easier to use and integrate.
How was the initial setup?
The initial setup was easy for this solution.
What was our ROI?
While I cannot quantify it or share any data, we have seen an ROI from using this solution.
What's my experience with pricing, setup cost, and licensing?
I don't have any visibility on pricing or licensing.
What other advice do I have?
The solution's ability to innovate is very good. It's quite mature.
I'd recommend the solution to others.
I would rate the solution 8 out of 10.
Which deployment model are you using for this solution?
Best AI antivirus I have ever seen
Achieved enhanced endpoint protection with AI-based zero-day threat mitigation and improved incident response time
What is our primary use case?
I use it for our XDR solution, managing various endpoints including Windows and Deepak. There are around twenty-five hundred endpoints where SentinelOne EDR or the Synchrony Solution is installed, helping me manage all my files. It is a next-generation antivirus solution with zero-day protection using AI or ML-based logic running in the backend to protect endpoints. Currently, there is no integration. It's an independent solution supporting my endpoint protection.
What is most valuable?
The XDR is a valuable feature. The AI-based engine protects against various behaviors and takes action on files being accessed. In terms of protection, I have an advanced app providing visibility of all my endpoints, which was not the case before. My time to respond to incidents has reduced, making it much more complete. I have the ability to isolate endpoints if identified as having malicious files or serious activity.
What needs improvement?
I think they should consider enhancing complete visibility. I haven't explored the network-related aspects, but if lacking, it is an area for improvement. Providing a single pane of visibility for the end user would be beneficial. This means not just seeing endpoints, but also the network and other connected devices through the Singularity portal. This would enhance decision-making and improve security posture.
For how long have I used the solution?
I have used the solution for three years.
What do I think about the stability of the solution?
It's a stable solution. My endpoints use minimal resources, and I have encountered no problems with installation, making it a stable product.
What do I think about the scalability of the solution?
From the console or admin perspective, as it is a SaaS product, scalability and management pose no problems. It's all auto-scale and auto-categorized, configuring automatically.
How are customer service and support?
I think they were responsive, but there was a delay in reaching out to my team on one incident report. This happened only once, which is why I am rating them eight out of ten.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I had a normal antivirus solution before upgrading to the next-gen XDR solution, which is SentinelOne.
How was the initial setup?
The setup is very straightforward. It took one month. Connecting to users was a manual process, but all network-connected devices were integrated without any challenges.
What about the implementation team?
There was a three-member team from the vendor side assisting with configuration and communication with my internal team. One of my team members coordinated with the end customers, who are the employees of my organization.
What was our ROI?
There isn't significant cost saving as such, but it has protected me from numerous virus or malware infections. This demonstrates an ROI.
What's my experience with pricing, setup cost, and licensing?
It's a fixed price per endpoint arrangement.
Which other solutions did I evaluate?
I have not used alternative solutions for the XDR solution. We were using an alternative antivirus solution before, but finalized on SentinelOne after considering other options.
What other advice do I have?
I rate the solution nine out of ten. It prevented potential losses, though not directly affecting ROI. To make it work effectively, ensure proper configuration and understanding of your network landscape. Initially set it to detect mode, then to protect mode, and later to auto-protect and quarantine mode. Allow one to three months to understand the network and work with a knowledgeable partner.
Which deployment model are you using for this solution?
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Protects endpoints, reasonably priced, and provides network and asset visibility
What is our primary use case?
We use the solution for endpoint protection. Our clients are fintech companies, banks, and other organizations. The tool helps to pick up malicious files in the endpoint and protects the endpoint.
What is most valuable?
The Ranger feature is valuable. It helps us manage variable assets in our environment. The endpoints and nodes have SentinelOne engines on them.
What needs improvement?
The product must provide the ability to update applications from the SentinelOne Management Console. Using SentinelOne Management Console to patch applications will be quite useful.
For how long have I used the solution?
I have been using the solution for 3 years.
What do I think about the stability of the solution?
I rate the solution's stability 7 out of 10. I've only had issues with the agents once. I reported it through the management console.
What do I think about the scalability of the solution?
We use the solution in endpoints in different departments across the organization. The tool does not require maintenance. We can auto-update it from SentinelOne Management Console. We can push the auto-update agent from the console. I rate the solution's scalability 9 out of 10.
How are customer service and support?
The support personnel always want to share links instead of joining sessions. Getting them on sessions that would probably help resolve the situation is quite hard. They don't always want to do it. That's the only issue I have with them. When we raise a support case, they get back to us and point us to a link to a community guide or solution. They don't respond quickly if the problem requires us to join a virtual session.
How would you rate customer service and support?
Neutral
How was the initial setup?
The initial setup is not complex. The deployment takes about 30 minutes. It is quite fast.
What was our ROI?
Our customers have seen an ROI on the product. It takes them 4 months to see ROI.
What's my experience with pricing, setup cost, and licensing?
The tool's price is reasonable.
What other advice do I have?
We are partners and resellers. Singularity Complete’s interoperability with other SentinelOne solutions is fine. I've been able to push logs into our SIEM solution. We used our API. It was quite easy to do. The API token expires, so we have to regenerate and integrate it.
The solution’s ability to ingest and correlate across security solutions is quite fast. I don't have any issues with it. The Ranger functionality provides network and asset visibility. It's quite important. We can identify when endpoints that are not permitted or allowed on the network are active. It helps us isolate or deploy an agent on the endpoints. It's quite useful.
Ranger requires no new agents, hardware, or network changes. It is used for existing agents or endpoints. We can also identify neighboring endpoints that do not have agents. It's easy because we do not have to do any additional configurations. It leverages the current agents that we have deployed across endpoints. It's a good feature. We need not deploy another agent to work for Ranger.
A computer that doesn't have an agent is vulnerable to exploits. When Ranger helps to find the computer and network, it helps to prevent vulnerable devices from becoming compromised. We can identify and isolate the computer and deploy the agent on it. Singularity Complete does not reduce alerts.
The solution saves deployment time. We can push agents from the management console to the endpoint. It will save us time from physically going to the endpoint and installing the agent ourselves. The product reduces MTTD by 20%. The product reduces MTTR by 20%.
If an endpoint gets compromised, we will have to spend money. The tool generally helps us stay safe and protects computers. Thus, the solution reduces costs in the long run. Unprotected endpoints are risky endpoints. Singularity Complete has helped reduce our organizational risk.
Singularity Complete is quite a good tool. I'm quite confident in its ability to detect threats. It is good to have SentinelOne as a strategic security partner. People planning to use the tool must go for it. It's a good solution. It does what it claims.
Overall, I rate the product 8 out of 10.
Which deployment model are you using for this solution?
Best EDR we have used by far!
The solution performs well and is less resource-intensive than other products
What is our primary use case?
We use Singularity to secure our workstations and servers.
How has it helped my organization?
Singularity has added some features to our security setup. It adds layers of protection to our security servers and workstations. One advantage of Singularity over other traditional antivirus products I use is that it doesn't use as many resources as other products.
If you resolve them permanently, the solution can reduce the number of alerts. Some applications keep triggering alerts, and you need to remove them, or they will continue to do so. We need physical signatures to prevent them from alerting again in the future. We can reduce the alerts by about 80 to 90 percent annually. Our old antivirus wouldn't flag some applications as malicious, but SentinelOne detected them, so we removed those applications, and it reduced our alerts.
Singularity has reduced our organizational risk by about 80 to 90 percent. We were able to address those alerts and remove a lot of malicious files that our previous solution didn't recognize. We saw a significant advantage in the first year. We've experienced a massive improvement in our mean time to detect. We have a large user base, but Singularity Complete performs better than our previous solution.
What is most valuable?
Singularity has the same features as other antivirus products, but it provides an added layer of security and vulnerability protection. It's also light on resources. Singularity doesn't use a lot of CPU or memory. We can consolidate our security solutions into one centralized platform, and monitor all our workstations and servers from one place.
What needs improvement?
SentinelOne is causing a problem with the data service that causes one of our applications to crash randomly. We're still looking for a permanent fix, but we have implemented a temporary workaround that excludes that application from the scan.
For how long have I used the solution?
I have used Singularity for 4 or 5 years.
What do I think about the stability of the solution?
I rate Singularity Complete 9 out of 10 for stability.
What do I think about the scalability of the solution?
I rate Singularity Complete 9 out of 10 for scalability.
How are customer service and support?
I rate SentinelOne support 9 out of 10 because they're very responsive.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
I previously worked with Sophos and ESET. The primary reason we prefer SentinelOne is that it doesn't consume a lot of resources.
How was the initial setup?
Deploying Singularity is straightforward, and it doesn't require you to restart the servers in the latest version.
What's my experience with pricing, setup cost, and licensing?
Singularity isn't cheap, but it's worth what we pay for it.
What other advice do I have?
I rate SentinelOne Singularity Complete 9 out of 10 overall. Singularity performs as well as expected, and it's less resource-intensive than other products.
Absolutely Love SentinelOne!
The threat-hunting platform is user-friendly, and I like the built-in remote access feature
What is our primary use case?
We provide SOC services for mostly UK clients and use SentinelOne to monitor our clients' endpoints and remedy threats. Some threats are remedied automatically, but others require investigation. We analyze the file and log any new vulnerabilities in our threat intel account.
How has it helped my organization?
Singularity Complete is a one-stop solution that encompasses all the endpoint protection solutions from SentinelOne. We've eliminated about 99 percent of our other solutions by switching to Singularity. It's easy to integrate SentinelOne logs, and we don't need any other tools for threat hunting or SIEM. Everything is on one platform. You can fully realize Singularity's benefits after about 3 months of deployment and training.
The solution is supported by Vigilance, SentinelOne's MDR service. They monitor 24/7 since we have other things to do. We have an SLA that threats will be mitigated within 45 minutes to an hour after detection. Singularity has virtually eliminated our organizational risk from threats.
What is most valuable?
Singularity's threat-hunting platform is user-friendly, and I like the built-in remote access feature. External parties can log in securely via the S1 agent. It's easy to integrate S1 logs with our SIS. That's one good thing. We don't need to use any other tools, like a SIEM.
What needs improvement?
I would like SentinelOne to add a threat-hunting report and more UEBA features. They could add more SIEM functionality. It would be nice to have the ability to easily drag all the logs from the agents, so there's no need for multiple agents installed on the endpoint.
For how long have I used the solution?
I have used Singularity Complete for a year and a half.
What do I think about the stability of the solution?
We haven't seen any downtime outside of normal maintenance windows every few months.
What do I think about the scalability of the solution?
Singularity's scalability is good.
Which solution did I use previously and why did I switch?
I used CrowdStrike before, but SentinelOne is easier because I can do more stuff on that. For example, let's say I want to fetch some files from an end user's machine or install something, but I do not manage the machine as a security person. If we need to do something inside, I can do a full scan and use remote access to see everything.
The SentinelOne suite is appropriate for our use case. If the scope and tasks were different, another EDR might be better. CrowdStrike has built-in UEBA, but it's not as user-friendly as SentinelOne.
What's my experience with pricing, setup cost, and licensing?
I'm not involved with purchasing decisions, but I believe Singularity must be cost-effective because the management selected it.
What other advice do I have?
I rate SentinelOne Singularity Complete 9 out of 10. It's an excellent solution for monitoring and managing endpoints. I recommend doing SentinelOne's training to familiarize yourself with how to leverage the entire product.