I am an MSP and provide service on behalf of SentinelOne.
I manage the incident logs from SentinelOne for our clients.
I am an MSP and provide service on behalf of SentinelOne.
I manage the incident logs from SentinelOne for our clients.
We integrated the SysLog server with SentinelOne without any issues.
SentinelOne Singularity Complete saves clients time by offering a comprehensive security solution that combines automatic detection, machine learning, behavior monitoring, and zero-day attack protection, all in one place, compared to traditional on-premise solutions.
SentinelOne Singularity Complete significantly reduced the number of alerts.
SentinelOne Singularity Complete freed up three of our people to focus on other tasks.
The most valuable features of SentinelOne Singularity Complete are machine learning because it saves us time, device control for data privacy, and the token.
SentinelOne Singularity Complete needs to improve the integration capabilities with SIEM.
I have been using SentinelOne Singularity Complete for eight months.
SentinelOne Singularity Complete is extremely stable.
SentinelOne Singularity Complete is scalable.
Cloud deployment for this project was a simple process. With two people involved, it only took one hour to activate the tenant and configure everything.
I would rate SentinelOne Singularity Complete nine out of ten.
SentinelOne Singularity Complete stands out as a mature security solution. Its robust threat detection, data loss prevention, and machine learning capabilities all point to its effectiveness.
My company leverages SentinelOne Vigilance and SentinelOne Singularity Complete for managed SOC.
SentinelOne Singularity Complete, together with SentinelOne Vigilance, is an EDR tool, with capabilities such as these, which I found valuable: the dashboard that shows you all the information and the power to either manually or automatically quarantine issues or threats in the environment.
SentinelOne Vigilance is one of the feature sets of SentinelOne Singularity Complete as a whole, and my company found SentinelOne Singularity Complete a little bit easier to use and flexible; plus, it had several feature sets.
I've not been using SentinelOne Singularity Complete for a long time to have a lot of feedback on its areas for improvement, as my team is still learning the tool, but what comes to mind is the need for it to give more straightforward directions or communication about detection or what has been detected.
We officially deployed SentinelOne Singularity Complete, including its feature set SentinelOne Vigilance, about three months ago.
SentinelOne Singularity Complete has been very stable, so it's an eight out of ten for me, stability-wise.
SentinelOne Singularity Complete is a scalable solution, which is one of the reasons why my company uses it.
I found the technical support for SentinelOne Singularity Complete excellent, especially in terms of communication. Support is nine out of ten for me.
Positive
We previously used Atos as our SIEM tool and wanted to replace it with a newer technology, so we're now using SentinelOne Singularity Complete.
I'm involved in deploying SentinelOne Singularity Complete, and I found the process straightforward. My company is still going through with the deployment because of the ninety-day deployment model.
I have people in my team assisting with SentinelOne Singularity Complete implementation.
I've seen ROI from SentinelOne Singularity Complete within a month after deploying the solution, mainly after my company started getting different alerts, which I was happy about.
I found the pricing for SentinelOne Singularity Complete reasonable, which is one of the reasons my company went with it.
SentinelOne Singularity Complete requires just a little bit of maintenance, as my team has to update agents and do some finetuning, but not too much.
My rating for SentinelOne Singularity Complete as a solution is eight out of ten.
My advice to people looking into using SentinelOne Singularity Complete is to ask for sample reports and processes to understand how SentinelOne would let you do it.
The company I work with is a SentinelOne customer.
We use it as an Enterprise EDR solution for threat detection, anti-malware, and security investigations.
SentinelOne Singularity Complete has greatly enhanced our security posture. We feel that our endpoints are more secure. We are in the know of what is happening within our company from a security perspective. We are confident in the ability to detect untrue positives. It has also helped us in achieving industry certifications such as SOC 2.
SentinelOne Singularity Complete has absolutely helped reduce our organization's mean time to detect. There has also been an impact on our mean time to respond. With the integrations that we have set up with Splunk and other products, we are able to respond to incidents as soon as they alert us.
We have a couple of integrations with it. They are alright. I am not blown away by its integration capability.
SentinelOne Singularity Complete has not helped reduce alerts. If anything, we create more alerts with it. We are able to fine-tune the product to reduce noise and alerts, but without it, we would not have any alerts. It is the piece of software that provides that alerting capability for us.
SentinelOne Singularity Complete has not helped free up staff. In a way, it creates work for us, but that is the purpose of the product.
The deep visibility and the ability to perform security investigations and assess our endpoint security posture are the most valuable features.
There should be Terraform support for console administration. Dynamic tagging would be also useful.
The auto-upgrade capability should be improved.
I have been using SentinelOne Singularity Complete for two years at this company. My company has been using it longer than that.
Its stability is pretty good. I like the stability of their agent.
It is extremely scalable.
Their technical support is pretty good. I would rate them an eight out of ten.
Positive
I was not here when they bought this solution, but I know why we bought the tool. We replaced another EDR solution, and then we used it as our enterprise EDR solution for ransomware prevention, threat hunting, and security investigations. We were using CrowdStrike previously. SentinelOne Singularity Complete also saved us money. It is very competitive compared to CrowdStrike.
I have used a couple of EDR solutions. SentinelOne Singularity Complete is less mature than CrowdStrike, but it is definitely one of the top players in the industry.
SentinelOne Singularity Complete has not helped reduce our organizational risk. It is about the same as CrowdStrike in this aspect.
We have it on our laptops and the cloud, so our setup is hybrid. I am in charge of deployment, and it is as simple or complex as any other solution.
It requires maintenance on our end.
We have a team, but I do most of the work. I am in charge of it.
It is hard to define the ROI. It does not save us money, but it prevents security breaches. In the grand scheme of things, it is definitely worth investing in.
Its pricing is competitive.
It has competitive pricing and great support. It is a complete solution.
As a strategic security partner, they collaborate with us quite a bit on our overall posture. They constantly have webinars and education sessions for us to deepen our security knowledge and how to use their product. They have assisted us on various PoCs for different offerings that they have and different services they offer. They help us to understand how each of those components integrates into our overall security posture. We did a PoC of the Ranger functionality.
I would rate SentinelOne Singularity Complete a seven out of ten.
Our company is a platinum partner and uses the solution to provide endpoint protection for customers.
A few new customers require the on-premises solution but others use the cloud technology.
The solution offers excellent detection and integration capabilities.
Integrations talk to other security vendors and share data with the help of the API. No other product offers this functionality.
The solution is a bit costly for some customers.
DLP support would be a good addition. Currently, there are multiple vendors and agents on endpoints. The solution looks at data from a specific documentation view so it would be beneficial to use that same documentation to look at DLP.
I have been using the solution for six years.
The solution is stable so I rate it a nine out of ten.
The solution is very easy to scale. Scalability is the best and the GUI itself is very fast with no issues. A customer with 10,000 clients still gets fast responses.
Technical support is very good and helpful in getting results.
The turnaround time for solving bugs or finding workarounds for customers is quick.
The setup is simple and the solution can be deployed using any tool. Vendors can also remotely deploy the solution.
If the solution is set up properly with the right policies and processes in place, then it won't require too many maintenance resources. Customers can also utilize the solution's NDR service instead of staffing that position. One technician can easily handle ongoing maintenance.
We implement the solution for customers.
The pricing is comparable with other vendors but some customers find it a bit costly. There is a bit of pricing flexibility with the solution, but initial quotes can surprise customers.
I rate pricing a six out of ten.
The solution stands out because has excellent detection and integration capabilities. In my opinion, the solution is better than Microsoft, CrowdStrike, and Palo Alto.
Customers are very happy with deployments and stick with the solution year after year.
I rate the solution a nine out of ten.
Our company serves as resellers and solution engineers for our enterprise customers. We deploy and support the solution in customer environments.
The XDR capability is quite good and offers advantages such as its real-time detection that is superior to CrowdStrike. I hear that face detection capabilities have also been added.
The dashboard should include troubleshooting because it can have problems.
Sometimes, the XDR does not configure its policies for data security on time.
The XDR should include ECI compliance, multiple data securities, and the load balancer for network firewalls under one umbrella. It would be beneficial to buy a salient solution that does everything.
The cloud side could be improved to include security, advanced integrations with other products, storage accounts, monitoring, and support.
The solution should include USB blocking for specific machines.
I have been using the solution for one year.
The solution is stable with no issues.
The solution is scalable.
The technical support is half and half. They offer good support but response time is slow. Sometimes, you have to contact multiple engineers to get good information and that is a challenge.
Neutral
We deploy the solution for customers.
The solution's XDR is superior to CrowdStrike.
I am satisfied with the solution and rate it an eight out of ten.
We outsourced the operation to a partner, a supplier, and they have managed those services. If the product does identify some abnormal behavior, our supplier is informed, and our main IT division or group IT division is informed. They correct the machine, and they do whatever they need to do.
Nowadays, there is a lot of malware and various other malicious threats. Our system is an internal system. There might be a firewall there, however, malware can still get through an email. However, this solution is very good at detecting abnormal behavior. They act very fast and quarantine machines well.
We find that having an endpoint protection solution allows us to adapt and react faster.
I can put something on my pen drive and get the solution to scan it and see if there are any issues. They can identify and block without affecting any core sections.
The solution is easy to set up.
It's stable.
The solution works quite well and I don't have many notes for improvement.
The solution can use up a lot of resources when scanning. It would be ideal if it was lighter.
We find the initial setup does take some time, as you have to do a lot of whitelisting. We'd like the process to be faster.
I've used the solution for a while. It's been more than two years.
The solution is pretty stable. I'd rate it seven out of ten. It's pretty reliable.
You can scale the solution. However, you do have to pay more to expand as you need to purchase more licenses. At this point, we get additional blocks of licenses when we need them. We do not upgrade one license at a time.
We have about 5,000 clients on the solution currently.
I do not have much experience with technical support.
We also have Microsoft Defender. They are two different products. We use Defender on our machines and workstations, however, not for endpoint security reasons.
IT installed the solution on my machine.
That said, my understanding is the initial setup is not overly complex. At first, however, we had to do some whitelisting. You need to perform a few operations, and we had to reinstall the OS, install a backup, and handle whitelisting. While it takes time, it's not hard.
I'm not sure of the exact pricing of the solution. That's handled by a different team.
We have an IT department that may look at other options, depending on the use case. They've looked at, for example, Sophos, however, they found SentinelOne to be more suitable for us.
I'm an end-user and not very technical.
While the solution is cloud-based, there's an on-prem server, and that is for the administration of our nodes. Mainly, the subscription is controlled by the cloud.
I'd rate the solution seven out of ten. Depending on the use case and if it makes sense for the company, I'd recommend the product.
The primary use case is as an endpoint detection and response software. Basically, it is an enhanced antivirus, anti-malware, and anti-ransomware solution. It protects from ransomware attacks and other types of cyber attacks. It protects the endpoint from malicious actions.
Protection from cyber attacks is the feature we find the most valuable.
It's a stable product.
We find the solution to be scalable.
Technical support is good.
The pricing is not too high.
It has a pretty simple user interface and is user-friendly.
They need to improve how we install the software. For the agent of SentinelOne in the endpoint, it's not an automated process. We have to download it and then upload it on the endpoint. That is something that can be made simple. The uploading of the software in the endpoint, if that can be done publicly, would be great. The setup should be available publicly. The agent installation should all be done in the cloud.
I've been using the solution for more than a year.
The solution is stable and reliable. There are no bugs or glitches. It doesn't crash or freeze.
The solution scales well. You can expand it as needed.
We are a small organization and have around 200 to 250 people on the solution.
The management is outsourced, and I find they are doing a very good job. We are satisfied with how we are able to get help if we need it.
This is the first EDR solution we used. We did not have another solution in place beforehand. We only used basic antivirus software previously.
The initial setup is annoying since you have to download the agent and then upload it to the endpoint.
For maintenance, basically, I'm the admin for SentinelOne. Also, there is a different organization altogether to whom we have outsourced the management of SentinelOne. They have their own employees. Their particular team would be working for our organization. They are an SoC organization, and they work 24/7 for various clients. We are one of their clients.
The pricing is reasonable.
I'm not sure of the exact costs, as those are managed by a different team.
I'm a client and end-user.
The solution is pretty easy to implement and administrate. We have not tried to integrate it with other solutions. While the pricing is reasonable, it's a bit more than typical antivirus software. That said, it has advanced functionalities that make the price worthwhile. Therefore, I would rate it nine out of ten.
SentinelOne is an antivirus and an EDR platform. We are using is simply for its antivirus and EDR features.
The solution is overall very good in terms of protecting endpoints and servers from malicious activities, malware, cyber attacks, viruses, worms, and so on. It offers really good security.
The initial setup is easy.
We have been happy with the stability.
It is possible to scale the product.
There is good documentation available, and support works to help users resolve issues.
It doesn't have application control capability. Other antivirus or EDR solutions have that. I would be happy if SentinelOne added that to their platform. This is the first point.
The second point is SentinelOne should provide support for legacy open-source operating systems. For example, old versions of Oracle are not supported by SentinelOne.
The third point is that SentinelOne does not support a few platforms, including IBM AIX and UNIX-based OS. These three platforms are almost all used in all enterprises, and SentinelOne does not support them. If SentinelOne provides agents for these missing platforms, it'll be very good.
It would be ideal if they offered video support for troubleshooting issues.
I've been dealing with the solution for just over one year.
The solution is stable and reliable. We have been happy with its performance. There are no bugs or glitches, and it doesn't crash or freeze.
I'd give it a four out of five in terms of stability.
The scalability has been very good.
There are thousands of both users and servers. Everyone uses it.
I have raised a lot of tickets, and their support is very good. However, with other members, when we have raised tickets in the past, we were able to have technical sessions through Zoom, WebEx, or Teams very easily. That's true, for example, with Microsoft, Cisco, McAfee, and Kaspersky. With SentinelOne, they are providing very good support, excellent support, however, their engineers are not very interested in providing online sessions, which is more convenient.
When you face any issue, they always provide documentation and videos - and that's very good. However, sometimes it's required that they show us how something is done. Doing some sort of video call helps with the walk-through. SentinelOne engineers, most of them, are not so much interested in doing this.
We did previously use a different solution. However, I can't speak to which product that was.
Other solutions that I usually use in other organizations were on-premises. This one is cloud-based. The point is, when you have your antivirus or EDR solution on-prem, that's your responsibility to troubleshoot the core server and do that maintenance patch and all of those kinds of tasks. When the solution is hosted in the cloud, all of these responsibilities belong to the provider, in this case, SentinelOne. When a new patch is getting released from the vendor, normally, if we were using legacy platforms, we would have to upgrade each endpoint one by one. By using cloud-based EDRs, it can be done automatically and reduces maintenance time.
The solution is very easy to set up. It's not overly complex or difficult.
The implementation strategy was very simple: removing the old antivirus solution and replacing that with SentinelOne.
It took us three months to migrate and deploy.
We have ten to 14 people that can handle deployment and maintenance. Only one person, however, needs to handle typical maintenance tasks.
We handled the initial setup ourselves. We did not need any outside assistance.
Licensing is part of the procurement team. I can't speak to the exact cost of the product.
We are a customer of SentinelOne.
SentinelOne does not have a version. SentinelOne is a centralized platform that is hosted in the cloud. It's the agent that we install on servers and clients, it has versions we are using the latest version of agents.
The product has two deployment options, cloud deployment, and on-prem deployment. Most people prefer to use cloud deployment in the way we do.
I recommend this solution often. I'd rate the solution eight out of ten.
My advice for other companies that do not use SentinelOne is this: that everyone, every company, likely has its own antivirus solution, whether it's McAfee, Symantec, Kaspersky, and so on. These platforms provide only an antivirus solution, however. If they replace their solutions with SentinelOne, they will have two features: EPP, endpoint protection from antiviruses, and EDR, endpoint protection and response features. They will not need to install two applications, one antivirus, and one EDR, on their clients' computers; only one agent can do anything.
SentinelOne provides an amazing amount of visibility over clients and servers. Anything done on a server, on a client, with a network connection, login, logout, changes in directories, et cetera, is recorded. Using query searches, you can find what happened very easily.
