SentinelOne Singularity Cloud is on our computers and servers, mainly for threat hunting. I use it to ensure our devices remain healthy and are virus-free, ransomware-free, and threat-free.
IT Director at a government with 51-200 employees
Helps keep the environment safe and is easy to deploy and maintain
Pros and Cons
- "It is scalable, stable, and can detect any threat on a machine. It uses artificial intelligence and can lock down any virus."
- "The main area for improvement I want to see is for the platform to become less resource-intensive. Right now, it can slow down processes on the machine, and it would be a massive improvement if it were more lightweight than it currently is."
What is our primary use case?
How has it helped my organization?
We've felt more comfortable having SentinelOne Singularity Cloud because we've had a safer environment. The benefits from the platform were immediate.
What is most valuable?
What is most valuable in SentinelOne Singularity Cloud is that it can detect any threat on a machine or is being installed on a machine, so it is a platform that helps keep the environment safe.
I also found the real-time detection and response capabilities of SentinelOne Singularity Cloud impressive because it is a platform that uses artificial intelligence to determine what is normal and what is abnormal and can lock down any virus it may encounter.
SentinelOne Singularity Cloud has good automated remediation capabilities. It can catch threats that other antiviruses do not.
The platform also has a very good deep visibility feature, enabling you to run scans and find what you need.
SentinelOne Singularity Cloud provides excellent historical data to find what you need.
The platform reduced my organization's mean time to detect and mean time to remediate anywhere from a week to sixty days.
SentinelOne Singularity Cloud also helped free up SOC staff, enabling staff to work on other projects or tasks. Through the platform, the team does not have to spend as much time trying to go through different objects on the machines manually.
SentinelOne Singularity Cloud hasn't had a direct, everyday impact on my organization's productivity. What it has an impact on is uptime whenever there is a threat on a computer because it blocks it.
The platform has good interoperability with third-party solutions and integrates smoothly.
SentinelOne Singularity Cloud is able to support my organization's ability to innovate. It is good in that aspect, though I have yet to work with that extensively.
What needs improvement?
SentinelOne Singularity Cloud sometimes has false positives, but the main area for improvement I want to see is for it to become less resource-intensive. Right now, it can slow down processes on the machine, and it would be a massive improvement if it were more lightweight than it currently is.
Buyer's Guide
SentinelOne Singularity Cloud Security
January 2026
Learn what your peers think about SentinelOne Singularity Cloud Security. Get advice and tips from experienced pros sharing their opinions. Updated: January 2026.
881,082 professionals have used our research since 2012.
For how long have I used the solution?
I've been working with SentinelOne Singularity Cloud for about three years.
What do I think about the stability of the solution?
I found SentinelOne Singularity Cloud stable.
What do I think about the scalability of the solution?
SentinelOne Singularity Cloud is scalable, and it is pretty seamless in terms of autoscaling based on my organization's workload demands.
How are customer service and support?
I have not contacted the SentinelOne Singularity Cloud technical support team.
Which solution did I use previously and why did I switch?
My organization used Windows Defender but switched because SentinelOne Singularity Cloud was more robust.
Due to its notifications, you can also have the turnout time of obtaining telemetry data from SentinelOne Singularity Cloud automatically, so you do not have to watch it constantly to see the data. The platform automatically shuts down the computer, takes it off the network, and then reports to you versus Windows Defender, which requires you to do a little more research into the items, as it did not provide as much information.
How was the initial setup?
I was involved in the initial setup of SentinelOne Singularity Cloud, which I found pretty straightforward.
What about the implementation team?
We worked with a consultant in implementing SentinelOne Singularity Cloud.
Only two people were involved, and the process took about two weeks.
What was our ROI?
I believe there is ROI from SentinelOne Singularity Cloud because of its impact on productivity through its ability to remediate and self-resolve some of the items.
What's my experience with pricing, setup cost, and licensing?
I have no information on how much SentinelOne Singularity Cloud costs.
Which other solutions did I evaluate?
We did not evaluate other options before choosing SentinelOne Singularity Cloud.
What other advice do I have?
If someone were to tell me that they do not believe they need SentinelOne Singularity Cloud because they have a continuous security monitoring solution in place, I would disagree because, with the SentinelOne Singularity Cloud platform, you can allow or disallow items within the machine. It automatically disconnects the machine from the network, helping you determine what is happening.
My organization works with the cloud version of the platform. It is deployed in multiple departments, and about four hundred users work with the endpoints.
SentinelOne Singularity Cloud requires maintenance, but it's not difficult to maintain.
Only one person takes care of the maintenance of the platform.
My advice to other users who would like to start working with SentinelOne Singularity Cloud is that I would highly recommend it based on its abilities and what it can find and remediate for you. It is easy to deploy and maintain, so I would tell others it is a solid platform.
My rating for SentinelOne Singularity Cloud is eight out of ten.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Microsoft Azure
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
IT Security Specialist at a tech services company with 51-200 employees
Precise, integrates well, and helps consolidate security solutions
Pros and Cons
- "It integrates very well. We sell different products from different vendors. We know that the SentinelOne Singularity platform can be integrated with several different solutions from different vendors."
- "The application module focuses on the different codes and libraries that can be run on the machines. It is very important for Singularity EDR to detect what type of codes and what type of libraries can run in the machine. If they can implement a white list or a black list of codes or libraries that can be used in the machine, it would be very helpful. They can focus more on the application module."
What is our primary use case?
We are a channel partner of SentinelOne in Brazil. We have a distributor that we use to sell SentinelOne. We are very happy and very proud to represent SentinelOne here.
How has it helped my organization?
SentinelOne Singularity Complete helps consolidate security solutions. There is a hot discussion about the future of the Security Operations Center. Security Operations Centers generally use SIEM and SOAR, but SentinelOne Singularity XDR can also help there because you can see what is happening not only on the endpoints but also in the network. In other words, you can replace the NDR solution. We also see it going all the way to include all the clouds. This ecosystem is very important to us. In the near future, we see it being used for all the problems related to detection and response in cybersecurity.
Our customers use the Ranger functionality. There are two Ranger versions. There is Ranger AD, and there is Ranger Pro. SentinelOne Singularity platform has its own security ecosystem. You do not have the need to buy other solutions. For example, we sell a ZTNA solution. If you have ZTNA, you do not need to buy a PAM solution. You do not need to buy a NAC solution. The ZTNA technology has replaced all the other solutions. It is the same thing with Singularity. If you buy the ecosystem of Singularity, you do not need to buy several different technologies.
Ranger can do all the hardware inventory. It can point out the versions of the operating systems and then you can apply patching to update the versions of the operating systems. You can use Ranger in different ways. For a security professional, it is a very powerful tool.
It sends you alerts and warnings about possible incidents, but you do not get too many false positives. It is precise. You get real information about an incident.
It is very important to have good hygiene of your endpoints and your network. The uptime of the endpoints and networks is very important. SentinelOne Singularity Complete provides a good uptime. Incident identification is very important and having fewer false positives is also important. The SOC staff knows that if SentinelOne Singularity points out an incident, they have to pay attention to the threat. It is a very good checker.
SentinelOne Singularity Complete reduces the organization's risk.
What is most valuable?
ITDR or Ranger AD is an important feature for me.
It integrates very well. We sell different products from different vendors. We know that the SentinelOne Singularity platform can be integrated with several different solutions from different vendors. We sell products of a Spanish company, and they support the integration of logs produced by SentinelOne into their platform. We see the capacity to integrate SentinelOne with the solutions of other vendors. It is very important because you can get not only a more integrated ecosystem but also a more powerful ecosystem.
What needs improvement?
All EDRs are made of different modules. There is a firewall module, an IPS module, and an application module. The application module focuses on the different codes and libraries that can be run on the machines. It is very important for Singularity EDR to detect what type of codes and what type of libraries can run in the machine. If they can implement a white list or a black list of codes or libraries that can be used in the machine, it would be very helpful. They can focus more on the application module.
For how long have I used the solution?
It is a short duration because we started to be a channel partner of SentinelOne two months ago, but we are very focused on SentinelOne.
How are customer service and support?
Their technical support for me is good. I am not involved in the deployment of the solution, but I have not heard any kind of complaint about the support.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We are currently using McAfee in our company, but we are going to move to SentinelOne.
I am a very experienced security professional. I have got the CISSP certification and other specific certifications. I see too many different products. I have good experience with Trend Micro, but I find SentinelOne Singularity more comprehensive.
We are trying to replace the solutions from other vendors. Customers are trying to use more powerful tools such as CrowdStrike or SentinelOne. We do not believe that Microsoft has a very good solution. There are a lot of people who speak about problems with Microsoft Defender and other components of the Microsoft ecosystem. The technical side is not the only factor. Price too is important, but we are trying to replace it. We have some good prospects to replace EDRs or other malware detection tools with SentinelOne Singularity.
How was the initial setup?
I am a security architect. I am not involved in the deployment of the solution. Some other guys in the technical area are involved in the deployment, but from what I hear, there is no problem. You have to do some configurations.
The deployment duration depends on the customer. If you have an SMB customer, it takes less time than to deploy it for a big customer.
What about the implementation team?
We have a team of technicians who are specialized in different kinds of companies. They are specialized in the cloud and other things. We have about 10 people. They take care of the deployment and configuration of the solution. We can also count on the specialist from the distributor for support and vendor support.
What was our ROI?
You get good support. You get a good product and you are going to be protected. The technology can be integrated with different tools. This is important. We do not live alone in this world. There are other vendors, so the capability to integrate is very important. Singularity Complete is going in the right way.
What's my experience with pricing, setup cost, and licensing?
The price depends on the extension of the solution that you want to buy. If you want to buy just EDR, the price is less. XDR is a little bit more expensive. There are going to be different add-ons for Singularity. This is important for customers because they can add some new features. They do not need to change the product. They can simply add a new feature.
What other advice do I have?
My company is a reseller of SentinelOne. It is one of the top solutions as per Gartner's Magic Quadrants. I am always interested in everything that comes from SentinelOne. I have watched the recent webinars about the latest launch of SentinelOne. There is going to be Purple AI. They have a new console, and we are waiting for it.
What we see here is that companies or customers want more features. The gap between EDR and XDR is too large. XDR includes cloud workloads of the systems and network and not only the endpoints. SentinelOne EDR is a very good solution. You do not need to monitor the Windows operating system. SentinelOne can do this for you. For example, the registry of Windows is the most important part of the operating system. SentinelOne EDR can see what happens in the registry. It can warn about any modification in the registry.
The Singularity ecosystem is very powerful. SentinelOne is very focused on expanding the reach of Singularity and making it a more comprehensive solution. SentinelOne is doing a very good job to get there. We believe that there will be a consolidation of the market, and SentinelOne will survive this consolidation because SentinelOne Singularity is a very powerful and very good solution.
I would rate SentinelOne Singularity Complete a nine out of ten. We have a very good relationship with SentinelOne.
Disclosure: My company has a business relationship with this vendor other than being a customer. Reseller
Buyer's Guide
SentinelOne Singularity Cloud Security
January 2026
Learn what your peers think about SentinelOne Singularity Cloud Security. Get advice and tips from experienced pros sharing their opinions. Updated: January 2026.
881,082 professionals have used our research since 2012.
Intern SOC Analyst at a tech services company with 51-200 employees
Good visibility and vulnerability scanning with very good reliability
Pros and Cons
- "It gives me the information I need."
- "A few YouTube videos could be helpful. There isn't a lot of information out there to look at."
What is our primary use case?
I'm taking a look and digging into applications. I use it for general analysis.
What is most valuable?
The visibility is very good. It allows me to go deeper into my investigations. It gives me the information I need.
I do use the vulnerability scanning every day. It's excellent. I have no complaints.
We do get false positives, however, it can be from downloading from dodgy sites or whatever the case may be.
The mean time to detect is good. It's very fast.
What needs improvement?
It's good as is. From a beginner's perspective, while it's not necessarily complicated, it can be confusing. However, once you get the gist of it, it's pretty clear. For example, when you first go on it, you don't know what's going on. A few YouTube videos could be helpful. There isn't a lot of information out there to look at.
For how long have I used the solution?
I've been using the solution for roughly six to seven months.
What do I think about the stability of the solution?
The stability of the solution is good. There is no lagging, crashing or downtime. This year we haven't had any downtime with the solution.
What do I think about the scalability of the solution?
The solution is very scalable.
How are customer service and support?
I've never contacted technical support.
Which solution did I use previously and why did I switch?
I did not previously use a different solution.
How was the initial setup?
When I joined the company, it was already being used; I did not set up the solution.
It doesn't need ongoing maintenance, although there are occasional agent updates.
What's my experience with pricing, setup cost, and licensing?
I don't know about the pricing or licensing.
What other advice do I have?
I'm an end-user.
I've never used the evidence-based reporting or the offensive or infrastructure-as-code scanning yet.
I'd rate the solution nine out of ten.
Which deployment model are you using for this solution?
Hybrid Cloud
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Global IT Security Administrator at a manufacturing company with 1,001-5,000 employees
Easy to use with good historical data and real-time detection
Pros and Cons
- "The ease of use of the platform is very nice."
- "Bugs need to be disclosed quickly."
What is our primary use case?
We use the product across all of our entities for EDR, threat detection, and response methods.
How has it helped my organization?
We wanted a solution for protection. We had a number of entities with various EDR solutions. We wanted to centralize under one EDR solution, and we wanted one that was efficient and easy to manage with a small team.
The biggest thing for us was getting to a single platform. A single pane of glass has been nice. The ability to segment various sites out. The R-Back involved is super helpful for us as we are a multi-company organization. In general, the time has been greatly reduced for incidents.
What is most valuable?
The ease of use of the platform is very nice. The console provides excellent visibility into events that occur and, in general, the wide range of tools that are built into the agent itself.
My impression of the product's real-time detection and response capabilities is good. It definitely is a little bit different. It takes a little bit more time to learn than some of the other solutions that we have worked with in the past. Once you do understand it and once you're capable of running through the GUI and you understand what the logs and various windows they're trying to tell you, it's fairly straightforward.
The solution's automated remediation is good. I like that you can segment it into four options. You can choose to kill it at any time in the kill chain, so you can choose to quarantine it, you can choose to remediate, you can choose to roll back, you can choose to let it run. Being able to choose how far along you want those events to get is pretty nice.
The historical data record provided by the solution after an attack is decent. It gives you a flowchart of the attack. All along the processes you get good visibility and see all that were detected. Definitely, from a post-incident analysis perspective, it's very strong.
The solution has helped reduce our organization's mean time to detect by 20% to 30%. Given that extra 20% to 30%, it frees us up to focus on other items.
The solution's impact on our organization's productivity is good. It provides robust whitelisting capabilities and improves our productivity.
What needs improvement?
Agent releases need to be more stable before being pushed out.
Bugs need to be disclosed quickly.
The reporting, and the logging visibility, are not there. It's very, very crude and simple. It needs to be drastically expanded.
They need to expand their third-party integrations with SIM tools, and sites need to be given the option to expire at the end of the contract as well.
They could expand their integration with Kubernetes. They are trying to build out their third-party integrations. It does work well on Windows and Mac.
For how long have I used the solution?
I've used the product for three and a half years.
What do I think about the stability of the solution?
Agent stability and communication with the console and agents going offline can be an issue. It can be time-consuming to coordinate and fix. However, the cloud console is very resilient. It's mostly the agent releases where we might have issues. CrowdStrike agents seem a little more stable.
What do I think about the scalability of the solution?
We have about 3,000 users using the solution.
Scaling is no issue.
How are customer service and support?
Technical support is hit or miss. We have worked with some good agents and some less knowledgeable.
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We have used different solutions, including the fact that we still CrowdStrike at a couple of companies. We are now moving more fully towards SentinelOne.
The simplicity and ease of use were big and where SentinelOne stands out. It's a set-and-forget policy. Based on what we saw in testing, it was the best option.
In terms of telemetry data, we were all over the board.
How was the initial setup?
The initial setup was a little more complex when we first started. However, they've smoothed a lot of their implementation out and so it's gotten easier over time. It took us a couple of weeks to a month to deploy. About 20 were involved in the deployment. We have 30 to 40 companies around the world and it's across every company and every department.
The solution does require maintenance. You need to have agents up to date and cases closed properly. It does require you to be invested.
What was our ROI?
We have witnessed ROI. It's comprehensive in its detection capabilities and has saved us from multiple attacks. We've likely saved 30% based on prevented attacks.
What's my experience with pricing, setup cost, and licensing?
The solution is relatively cheaper and is willing to work with companies on pricing.
What other advice do I have?
We are customers.
For those who believe they already have a continuous monitoring solution in place, I'd advise that SentinelOne knows its own product. They can provide that extra confidence that nothing gets missed. And if you see a high number of alerts, they're able to really help you discern those and get down to the ones that matter most.
The solution doesn't affect our ability to innovate one way or another. It doesn't hold us back.
I'd recommend the solution and advise running a POC in your environment. It's good to run against CRowdStrike. They are seriously contending against CrowdStrike.
I'd rate the solution eight out of ten.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Solutions Consultant at a tech services company with 11-50 employees
A comprehensive solution for complete visibility
Pros and Cons
- "Visibility is the most important aspect."
- "I would rate this solution a nine out of ten."
- "The documentation could be better."
- "The documentation could be better."
How has it helped my organization?
The most beneficial aspect of adopting these solutions is gaining visibility. We manage false positives efficiently, using tools like Tenable, which also provide visibility and help differentiate between actual risks and false positives concerning vulnerabilities.
What is most valuable?
Visibility is the most important aspect. Azure Monitor, SentinelOne Singularity Cloud Security, and other tools help gain visibility into our environments. Previously, we did not have any information about our environment. We now have visibility.
Evidence-based reporting is essential as it guides us in deciding and prioritizing vulnerability by improving our understanding of our environment. Before implementing these tools, obtaining information about our environment was challenging.
What needs improvement?
The documentation could be better. Besides improving the documentation, obtaining a professional or partner specializing in the implementation of SentinelOne Singularity Cloud Security is very important, as it can save time during the implementation process.
For how long have I used the solution?
I have used this solution for four or five years.
What do I think about the stability of the solution?
In my previous company, we once discovered a problem in one of our environments using SentinelOne, but I do not remember exactly what the problem was.
Which solution did I use previously and why did I switch?
I have not used any similar solution. SentinelOne offers a comprehensive solution for the complete environment. It is very difficult to get the same results from different partners and manufacturers.
How was the initial setup?
It is easy; it is not difficult.
What about the implementation team?
Usually, we make a deal with a specific partner specializing in implementation. We do not implement it on our own.
What other advice do I have?
Most security solutions are easy to use but require minimal knowledge to implement and maintain them.
Overall, I would rate this solution a nine out of ten.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.
DevOps Engineer at a computer software company with 51-200 employees
Nice UI and features with helpful support
Pros and Cons
- "Support has been very helpful and provides regular feedback and help whenever needed. They've been very useful."
- "There should be more documentation about the product."
What is our primary use case?
We have multiple AWS accounts and we use it for our products and deployments, et cetera, and they are being monitored by SentinelOne Singularity Cloud Security for best practices and good security. In the past, we've had code exposed to the internet, and SentinelOne Singularity Cloud Security has been able to catch such instances. Basically, it is for security and monitoring purposes.
How has it helped my organization?
We've been able to integrate SentinelOne Singularity Cloud Security with out AWS and deployed their agents to Kubernetes. For production and compliance purposes, it allows us to monitor actively for issues from one place.
What is most valuable?
The solution reduces notifications.
We mainly use it for monitoring and security guidelines only. It's been really useful for us in terms of the developer accounts. If any have been exposed, we get notified and we can take care of issues before anything happens.
We haven't seen any server downtime. It's always been available when we've needed it.
The UI is very nice, and feature-wise, it's very good.
It has very good documentation.
Support has been very helpful and provides regular feedback and help whenever needed. They've been very useful.
The solution is very easy to use. We have not had to spend much time customizing or integrating items. We were able to integrate all four AWS accounts in order to centrally monitor everything.
There is evidence-based reporting which can help prioritize and solve cloud security issues. We haven't actively used it or set it up.
We use the infrastructure as code scanning feature. It's good for identifying pre-production issues.
About six months ago, there was a major upgrade. We can see the containers running and which vulnerabilities appear, et cetera.
We haven't seen any increase in false positives since using the solution.
It's helped us improve our risk posture. We're more confident now that things aren't happening and getting missed. We're on the right track to adapting proper security rules.
More than saving engineering time, this solution has helped promote confidence is the security of our cloud accounts. We're more sure of our configurations and security posture. Since we don't have a cloud expertise team that might identify issues, it has helped us gain confidence in SQL deployments.
What needs improvement?
There should be more documentation about the product. Sometimes we have to go to customer support to get clarification.
For how long have I used the solution?
I've been using the solution for 1.5 years.
What do I think about the stability of the solution?
The solution is stable. I have not seen any downtime.
What do I think about the scalability of the solution?
We have around 15 users leveraging SentinelOne Singularity Cloud Security. They are mainly admins and engineers.
How are customer service and support?
Technical support is very helpful. However, the documentation needs to be better.
They tend to resolve issues within an hour or so. With most issues, they are very helpful
How would you rate customer service and support?
Positive
Which solution did I use previously and why did I switch?
We have a different pipeline product working in parallel to this solution that is also helping us reduce vulnerabilities. Something else, for example, monitors compliance for us. SentinelOne Singularity Cloud Security is more of an additional tool than our main solution. We have been using open-source tools for scanning.
How was the initial setup?
The development was just one configuration, and we were able to implement SentinelOne Singularity Cloud Security in about an hour.
The solution does not require any maintenance.
What was our ROI?
We have noted an ROI based on the amount of confidence we've gained having visibility into our vulnerabilities. I do not have specific metrics on hand to illustrate that, however.
What's my experience with pricing, setup cost, and licensing?
The pricing is reasonable.
What other advice do I have?
We're a customer and end-user. I'm a DevOps engineer.
I'd recommend the solution to others. I would rate it 10 out of 10 as it currently meets all of our requirements. I can't speak to other companies that may have different requirements.
Which deployment model are you using for this solution?
Public Cloud
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Security Admin at a tech services company with 1,001-5,000 employees
Storyline enables us to deep dive and do threat hunting, decreasing our remediation time
Pros and Cons
- "We really appreciate the Slack integration. When we have an incident, we get an instant notification. We also use Joe Sandbox, which Singularity can integrate with, so we can verify if a threat is legitimate."
- "One of our use cases was setting up a firewall for our endpoints, specifically for our remote users... We were hoping to utilize SentinelOne's firewall capabilities, but there were limitations on how many URLs we could implement. Because of those limitations on the number of URLs, we weren't able to utilize that feature in the way we had hoped to."
What is our primary use case?
We have an environment in the cloud where we have a bunch of EC2 instances and S3 buckets. We have the SentinelOne agent installed on all of our EC2 instances, to monitor our environment, so we use it quite frequently.
We needed cloud-based endpoint protection that we could install to get a single pane of glass into our security environment. Specifically, we needed to see the version usage of the applications to ensure we didn't have any outdated applications.
How has it helped my organization?
It has definitely helped reduce our mean time to detect. It's much quicker than with our last platform. Singularity has also helped free up our staff to work on other projects. We don't usually come into the console unless we get an alert. In that sense, we have been working on many other projects in the last year. Now that everything is set up and running smoothly, we haven't had to spend as much time in the console as before.
And when I consider the solution's impact on overall productivity, features such as the reporting have helped. When we need to run a report on how many endpoints we have in our environment for regulatory requirements, we use the reporting feature of Singularity because we know it's installed on every endpoint, giving us full visibility. From a reporting standpoint, it has certainly helped us.
What is most valuable?
We really appreciate the Slack integration. When we have an incident, we get an instant notification. We also use Joe Sandbox, which Singularity can integrate with, so we can verify if a threat is legitimate. The third feature we use most often is the VirusTotal integration. That allows us to take the hash of a threat or virus and open it up in VirusTotal.
Also, it's amazing how quickly its real-time detection and response capabilities come through. There have been multiple times where either my coworker or I will be working on something—even in our elevated environment, and even just running a script. We wouldn't expect a pop-up, but it's good to know that it's checking for those anomalies, detecting them, and notifying us of them instantly. We love that feature.
In terms of the historical data record provided by Singularity after an attack, we like to use the Storyline feature for deep dives and threat hunting if needed. It has been very useful in our operations. We can see different event types on each endpoint, which comes in handy. Using the Storyline feature, we can dig in much quicker, connect the dots, and see what caused the alert. So it has quickened remediation.
And the SentinelOne Cloud engine detection types are useful when trying to determine whether a threat could be legitimate or a false positive.
What needs improvement?
One of our use cases was setting up a firewall for our endpoints, specifically for our remote users. We have a firewall on-premises that comes into play when someone is at our main campus. But we needed something more for our remote users. We were hoping to utilize SentinelOne's firewall capabilities, but there were limitations on how many URLs we could implement. Because of those limitations on the number of URLs, we weren't able to utilize that feature in the way we had hoped to.
For how long have I used the solution?
I have been using SentinelOne Singularity Cloud for about two years.
What do I think about the stability of the solution?
Singularity has been very stable. It has never lagged or crashed that I've noticed. In my experience, there has been 100 percent uptime.
The interoperability with AWS has been very straightforward and streamlined, without any major bugs or issues that I've come across.
What do I think about the scalability of the solution?
Its scalability is one of the main reasons we chose SentinelOne. Because it's hosted in the cloud, we can install as many agents as we're licensed for. We've never gone over that limit. As new servers and endpoints come online, it's easy to deploy. It's built into the image.
We do have a unique use case regarding scalability. We use a VDI environment in Azure, and it works. We haven't had any issues. But when we need to run updates on those machines, we have to rebuild the image. We can't have the agent built into the image because of our rebuild process. That makes it a manual process for us every month when we redeploy those desktops. We have it scripted out with a PowerShell script that helps, but it's a manual step for us. That's one area we're trying to address from a scalability standpoint.
As for auto-scaling, we're more of a static environment for most of our endpoints. The VDI is our only more fluid environment, since our VDI endpoints go up and down based on usage. Once the agent has been deployed to those images, the auto-scaling works flawlessly, and we haven't had any issues there.
Which solution did I use previously and why did I switch?
We used ESET, but the decision to go with Singularity was made before my time with the company.
How was the initial setup?
We have a couple different deployments: our end-user endpoints and our server fleet. I was involved with the server deployment. It was very straightforward, and we didn't run into any issues during that deployment.
The only maintenance involved is when we need to whitelist an application. For example, if a new user installs an application, we might get a false-positive pop-up. That's really the only maintenance we have to do.
What about the implementation team?
We did it ourselves, and there were four people involved.
What's my experience with pricing, setup cost, and licensing?
It's a fair price for what you get. We are happy with the price as it stands.
What other advice do I have?
My advice is that if you want an easy-to-deploy solution where you can have a single pane of glass to get visibility into all of your endpoints and applications, and run reports on those application versions, Singularity makes it a very easy-to-use, straightforward, and streamlined process that has helped us over and over again.
If someone thinks they don't need Singularity because they already have a continuous security monitoring solution in place, using SentinelOne gives us an overarching view from the single console, giving us the entire picture of the timeline of events that happened. Going through the timeline and connecting those dots really helps when threat hunting. It helps to get the full picture instead of just a specific point in time, which is the way some of the legacy antivirus programs work.
The solution has an automated remediation feature, but we don't currently use it because we are a smaller team. We like to remediate manually. For the time being, we haven't had a reason to use the automation feature yet.
One area we're trying to innovate more in is the AWS Security Hub. Singularity, in their marketplace, has a couple of apps related to that. We're trying to build more automations within AWS Security Hub to get better overall visibility, not only of our EC2 endpoints but of our applications as well.
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor.
Security Analyst at a tech services company with 501-1,000 employees
Offers a highly intuitive management console, easy to deploy, and saves us time
Pros and Cons
- "The management console is highly intuitive to comprehend and operate."
- "The cost has the potential for improvement."
What is our primary use case?
We utilize SentinelOne Singularity Cloud to safeguard our clients and servers from viruses and to perform forensic analysis on threats.
We are a service integrator in the public sector in Italy, and we implemented SentinelOne Singularity Cloud because we lacked an antivirus solution.
How has it helped my organization?
The real-time detection and response capabilities of SentinelOne Singularity Cloud are excellent. We have implemented automated remediation on the Singularity platform. I have tested this on both our tenant and our customers' tenant, and we haven't encountered any issues with this method.
Singularity offers profound forensic visibility, which proves highly advantageous for in-depth analysis of events. Through a single console, we can observe comprehensive event details from start to finish.
The historical data record provided by Singularity after an attack is valuable. It allows us to identify any misconfigurations and has assisted us in rectifying errors during the deployment of group policies in Active Directory. This capability helps us manage group policies more effectively, particularly in terms of security policy deployment.
SentinelOne Singularity Cloud has been immensely helpful in mitigating issues for us. Our organization consists of approximately five hundred employees, including technicians and administrators, and Singularity has played a vital role in safeguarding our organization.
It has helped us reduce our MTTD.
Singularity helps us reduce our MTTR.
We have saved time. The automatic remediation helped me a lot when an event occurred, as it analyzed and remediated the issue automatically. This saved a significant amount of time.
Singularity operates smoothly and does not cause our laptops to experience any performance degradation, which has been very beneficial.
What is most valuable?
Deploying SentinelOne Singularity Cloud is a simple process that requires only three clicks.
The management console is highly intuitive to comprehend and operate.
What needs improvement?
The cost has the potential for improvement. I would appreciate it if the full edition could be made more affordable, allowing me to upgrade from the intermediate version.
For how long have I used the solution?
I have been using SentinelOne Singularity Cloud for more than three years.
What do I think about the stability of the solution?
SentinelOne Singularity Cloud is incredibly reliable. I have never come across a crash or experienced any downtime. I have never needed to initiate a support case.
What do I think about the scalability of the solution?
The SentinelOne Singularity Cloud exhibits high scalability. We only need to incorporate licenses to facilitate scaling, eliminating concerns regarding servers or databases, as it functions as a cloud-based platform.
How was the initial setup?
The initial setup is straightforward because the platform is cloud-based, allowing accessibility from anywhere, and deploying the agent is as easy as clicking three times.
Two people were involved in the deployment.
What about the implementation team?
We are a system integrator and we implemented the solution in-house.
What's my experience with pricing, setup cost, and licensing?
As a partner, we receive a discount on the licenses. Currently, we possess over 250 licenses, but there is potential for the licenses to become even more affordable.
Which other solutions did I evaluate?
We evaluated various products such as Trend Micro, Symantec, and Sophos. SentinelOne Singularity Cloud stood out among the solutions we evaluated as the easiest to manage and with the best performance.
What other advice do I have?
I rate SentinelOne Singularity Cloud a nine out of ten.
SentinelOne is a novel form of endpoint detection and response that has assisted us in effectively managing our clients and servers. It provides us with substantial visibility and aids in safeguarding our infrastructure against emerging threats.
Regarding maintenance, I check the event logs every two weeks, in addition to reviewing emails, and I update the schedule to manage the agents.
The interoperability with third-party solutions is good. We don't have any compatibility issues.
SentinelOne Singularity Cloud is updated bi-weekly or monthly and the signature to the client is updated every two days.
Evaluating SentinelOne Singularity Cloud is made simple by installing the client and logging into the console.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Microsoft Azure
Disclosure: PeerSpot contacted the reviewer to collect the review and to validate authenticity. The reviewer was referred by the vendor, but the review is not subject to editing or approval by the vendor. The reviewer's company has a business relationship with this vendor other than being a customer: Partner
Last updated: Dec 9, 2025
Flag as inappropriateBuyer's Guide
Download our free SentinelOne Singularity Cloud Security Report and get advice and tips from experienced pros
sharing their opinions.
Updated: January 2026
Product Categories
Cloud-Native Application Protection Platforms (CNAPP) Vulnerability Management Cloud and Data Center Security Container Security Cloud Workload Protection Platforms (CWPP) Cloud Security Posture Management (CSPM) Compliance Management AI Software Development AI ObservabilityPopular Comparisons
Microsoft Defender for Cloud
Prisma Cloud by Palo Alto Networks
Tenable Nessus
CrowdStrike Falcon Cloud Security
AWS Security Hub
Buyer's Guide
Download our free SentinelOne Singularity Cloud Security Report and get advice and tips from experienced pros
sharing their opinions.
Quick Links
Learn More: Questions:
- Does SentinelOne have a Virtual Patching functionality?
- When evaluating Cloud-Native Application Protection Platforms (CNAPP), what aspect do you think is the most important to look for?
- Why is a CNAPP (Cloud-Native Application Protection Platform) important?
- What CNAPP solution do you recommend for a hybrid cloud?
- Why are Cloud-Native Application Protection Platforms (CNAPP) tools important for companies?
- When evaluating Cloud-Native Application Protection Platforms (CNAPP) solutions, what aspect do you think is the most important to look for?
- Why is Cloud-Native Application Protection Platforms (CNAPP) important for companies?
- What Cloud-Native Application Protection Platform do you recommend?


















