2nd Analyst at a tech vendor with 10,001+ employees
Real User
Top 20
Aug 20, 2026
To improve SentinelOne Singularity Endpoint, I want to continue working on this and provide even more data, more visibility, and everything clearer and faster. I guess everywhere could use a few additional functions, but they are not really needed. I would add more about the needed improvements regarding features. I mean more deeper insights and bigger visibility so that when you have any process, you can click and it can show you everything for that process, so you can see really quickly everything that you need, enabling quick analysis and decision-making.
Founder & Owner at a consultancy with 11-50 employees
Real User
Top 20
Aug 19, 2026
Since adopting SentinelOne Singularity Endpoint, I have seen a mixed bag of measurable results. There have indeed been many fewer risks, but there have been other problems. SentinelOne Singularity Endpoint tends to block workstations at the slightest doubt, so it needs to be fine-tuned to be a bit more tolerant. Otherwise, there are blocked workstations and loss of productivity. There were many problems on old Windows Servers that were not compatible, so they had to be upgraded. If SentinelOne Singularity Endpoint were more backward compatible with older versions, that would be great. The old versions of Windows Server were not very compatible, but that is the only criticism.
SOC Analyst II at a computer software company with 51-200 employees
Real User
Top 10
Aug 18, 2026
Regarding SentinelOne Singularity Endpoint's AI capabilities, I find its accuracy and reliability of output to be dependable, though I believe it could improve by opening up the access to more than summarizing or creating queries.
Senior Engineer - Cybersecurity at a comms service provider with 11-50 employees
MSP
Top 5
Aug 18, 2026
I believe their SLAs could be tighter, but overall it is a good platform. Those are the main improvements needed for SentinelOne Singularity Endpoint. I don't think there are any other significant improvements needed that I haven't mentioned; there may be minor items or wish-list features.
security analyst at a tech vendor with 501-1,000 employees
Real User
Top 5
Aug 17, 2026
I would really appreciate having raw data of what is happening presented in a clearer format. Additionally, a cloud backup of malware would be beneficial so that we can maintain a copy of the ransomware and malware on SentinelOne for analysis purposes. I would not want to add more about needed improvements because all of the current capabilities are really awesome, and they have done a really good job.
I think the area that can be improved is the reporting and the dashboard customization. Also, the other tooling and the false positive reduction is important because it is better to prioritize the critical ones and reduce the false positives. Additionally, the integration from CMDB source solution is another improvement. Because the platform gives a lot of information, creating a customized report for management and different security teams could be easier and more flexible. I think documentation can improve with more practical troubleshooting. Also, the agent performance is an area for improvement. I think the endpoint agent could be optimized to reduce CPU and memory consumption, especially on older systems. Additionally, policy management could be improved because managing policy across a large number of endpoints and different groups could be more intuitive.
Learn what your peers think about SentinelOne Singularity Endpoint. Get advice and tips from experienced pros sharing their opinions. Updated: August 2026.
Senior IT Administrator at a financial services firm with 201-500 employees
Real User
Top 10
Aug 16, 2026
SentinelOne could prepare more native integrations for downloading data from external sources. There are already many integrations available, but it would be beneficial if Purple AI could search also through the data ingested to Data Lake and generate alerts based on external data which is uploaded to AICM. Regarding functionalities, it is among the best protection that I have checked. However, the price and the fact that each functionality such as vulnerability management or cloud funnel requires additional licenses raises the yearly cost for the company.
The UX in SentinelOne Singularity Endpoint can be quite difficult sometimes. We had in the past other EDR, and sometimes the former EDR was simpler than SentinelOne Singularity Endpoint, so at the beginning, it can be really complex to understand how it works, how to manage the policies, and how to handle the RBAC. We had to follow the documentation and the different knowledge transfers offered by SentinelOne Singularity Endpoint, but we are quite good now, so we can manage SentinelOne Singularity Endpoint by ourselves. Except for the UX part of SentinelOne Singularity Endpoint which can be time-consuming, I do not have any other improvements to share. I chose eight out of ten because even if SentinelOne Singularity Endpoint is quite good in our day-to-day works, there are some improvements needed, especially on the UX part. The UX part is really important for us because we have some turnover in the cybersecurity team, so we would like to be sure that newcomers can handle SentinelOne Singularity Endpoint quickly, and sometimes we have to share knowledge transfers, which can be time-consuming.
L2 Cyber Security Analyst at a security firm with 51-200 employees
Real User
Top 5
Aug 13, 2026
Having some capture-the-flag exercises inside the console, perhaps from time to time if the vendors propose them, would be a good improvement. Additionally, improvements at the level of events and checks for all the new components and all the new features of the console would be beneficial. I rate it an eight and not a higher or lower score because it does not have web reputation management. It does not act at the web level. It works primarily only at the file level and endpoint inventory. There are no other aspects that could be improved in SentinelOne Singularity Endpoint that I have not mentioned.
Technical engineer at a tech services company with 10,001+ employees
Real User
Top 20
Jul 22, 2026
Recently, I faced an issue with SentinelOne Singularity Endpoint while detecting rogue devices, as there is a gap when scanning initiated from the admin console, recognizing different MAC IDs depending on the connection type, which leads to conflict between managed and unmanaged assets. Another area needing improvement is the process graph of SentinelOne Singularity Endpoint, which could be made more user-friendly, eye-catching, and offer a better in-depth view.
I am satisfied with SentinelOne Singularity Endpoint overall, but if it could be improved, it would be in providing more customizable reporting, a richer dashboard, and broader integration with third-party tools. Other than that, I find it effective and reliable with no major suggestions for improvement. Based on my experience with SentinelOne Singularity Endpoint, I have not encountered any major issues that significantly affect our day-to-day operations. The platform has been stable, and while every product continues to evolve with new features and integrations, I do not have additional improvements to suggest at this time.
When retrieving results for logs in the AI SIEM of SentinelOne, there is a limitation where I can download up to 10,000 columns at a time, and the same constraint applies to vulnerability data. This product limitation needs improvement in future updates. I would like to see these limitations removed in SentinelOne Singularity Endpoint. Additionally, the device control feature needs improvement. The EDR is solid, but there are several areas where the quality of work could be enhanced.
I believe SentinelOne Singularity Endpoint is a strong security platform, but areas for improvement include reporting and dashboard customization, as well as providing more advanced threat hunting queries and easier navigation for new users, which would enhance the overall experience.
Technical Support Engineer Iii (Siem & Soar) at Barracuda Networks
Real User
Top 10
Jun 9, 2026
Although it has been almost six and a half months, I do not have many features in mind that I find necessary. However, I really appreciate how I can specify scanning folders or areas in the system. Since it is endpoint detection, I can specify which areas to always check for scanning. It has exclusions as well; for example, if I want to scan everything in a system but exclude particular folders or extensions, I can specify that in SentinelOne Singularity Endpoint. That provides me with more granular control over what needs to be scanned and what does not, helping me avoid many false positives and making the systems more reliable in alert conditions. The results become more accurate. I do not feel anything needs to be flagged for improvement, but everything requires some enhancements. While using SentinelOne Singularity Endpoint, I do not feel anything needs to be added as a feature or improved. Most of its functions work well. I cannot think of anything at this moment regarding needed improvements.
Cybersecurity Product Manager at a tech services company with 51-200 employees
Real User
Top 10
May 21, 2026
We are not working with SentinelOne Complete to consolidate our security solutions in one place. If SentinelOne could localize the Purple AI and other features for larger environments such as ours, which has around 20,000 endpoints, that would be an improvement. If they could provide a local LLM that can be installed on-premise, it would be easier for us. Otherwise, we need to obtain government permissions, which is quite complex and can take years. A local version of the LLMs for Purple AI would be beneficial. I believe that SentinelOne's technical support needs to improve slightly. They are quite slow, and while I understand they might be busy, I would rate them at a seven out of ten.
Presales Lead & Delivery Lead at a construction company with 1-10 employees
Reseller
Top 20
May 20, 2026
For maintenance of SentinelOne Singularity Endpoint, there are two things. If I need to create any maintenance or upgrade policy, that is a different matter. The customer is looking for the maintenance window and wants the upgrade part mainly on Sunday or Saturday, the weekend part. They do not want the auto-upgrade whenever SentinelOne pushes from the backend. If I am looking at the impact of Purple AI on amplifying team knowledge, there are multiple things. If I am looking at how many endpoints are in my organization, how many endpoints have this application, and how many endpoints have multiple threats and alerts, I want to know how to reduce them. If I am asking particularly how to reduce the threat count, I do not think Purple AI can give this answer because AI is not particularly for this enterprise account. Purple AI is something I can rely on for multiple things, such as if I need to know how to create tags, policies, blocklists, exclusions, network control, device control, how to enable the firewall, and how to create a block policy with the hash. There are many things. If I need to install any agent on a particular Windows machine, whether it is 64 or 32-bit, or a Mac machine, or a Linux machine, or any other machine, how I need to add the token, and how I need to download the package are all considerations. Additionally, how to ensure that the agent is connected with my management plane is important.
Director Of IT Security And Risk Management at AskDegree
Real User
Top 5
May 19, 2026
Before using SentinelOne Singularity Endpoint, I used different products, including CrowdStrike. In the space where SentinelOne Singularity Endpoint is working, it is an awesome product. However, I believe the vulnerability management is currently in pilot. If it can mature into good production where the vulnerability management module is working well within Singularity Complete edition, that would be an awesome step. The vulnerability assessment is available, but application vulnerability assessment or other endpoint vulnerability assessment is not as good as what other products are providing. Singularity Complete is a good product in its area and, obviously, when comparing to other organizations or companies providing endpoint detection solutions, it is an end-to-end solution for antimalware and XDR. This has been working fine for me so far. I am using it in small, medium, and enterprise organizations, and it is good. However, as I mentioned for the vulnerability assessment, along with the specification of handling core, detailed forensics, there could be more details I would add. However, if I recall correctly, there is a specific module within SentinelOne Singularity Endpoint to check all details of the functions that happened within the target machine. I am currently unable to recall the name of that module, but it exists. However, there is room for improvement where more details of the solution or from the target can be added, and this would help me more easily identify the impact or the root cause that impacts the endpoint. This would be more helpful for end users. Currently, if there is an impacted endpoint, I click on the endpoint, and it gives me insights about what happened with this endpoint. However, when I need to go into the details, there is some limitation to viewing those details for the target machine. It would be awesome if this module could be integrated into the normal Sentinels. This would be more helpful for engineers working on core identification of root causes.
In terms of improvement areas for SentinelOne Singularity Endpoint, I think there are a couple of features that are improving, particularly the dashboard such as creating a multi-function dashboard. There is one loophole that needs addressing, but it is still better overall.
I would suggest a lot of improvements; first, the dashboard is critical for new joiners, especially with the addition of Purple AI and EDR, which makes it complex for new SOC users. Second, the rollback feature is only available for Windows systems, not for Linux and Mac OS. Third, the dashboard is not customizable; I cannot create a dashboard as it is already inbuilt in SentinelOne Singularity Endpoint management console.
For SentinelOne Singularity Endpoint, the first issue I dislike is the high CPU utilization, and the second is a very high number of false positive alerts from the EDR. Data security is very important in today's organizations when using Purple AI with endpoints in the SentinelOne Singularity network and applications everywhere. However, SentinelOne Singularity does not have strong features for data security. Purple AI is used to find IOCs, hashes, zero-day vulnerabilities, or CVEs found in the network. We use it for that purpose only. From a data security perspective, SentinelOne Singularity does not have a major role. With Purple AI, we ask questions about an IOC or provide a query and receive answers from Purple AI, but that is the extent of its functionality.
Currently, I have nothing to suggest for improvements to SentinelOne Singularity Endpoint; we are very happy with the tool. If I had to imagine one thing that could enhance my experience with SSentinelOne Singularity Endpoint, I would pick an easier way to view or follow the XDR platform, as I had some difficulties with it in the past. I think that training would be beneficial for using the XDR, as we have a lot of information available there.
Soc Analyst at Softcell Technologies Global Pvt.Ltd
Real User
Top 10
Apr 27, 2026
The first improvement is the dashboard because it is very complex. As a beginner-friendly SOC analyst or MDR analyst, the dashboard is a bit complex, so the dashboard needs to be more user-friendly. The second improvement is the VSS rollback feature, which is useful only for Windows laptops and servers, not for macOS and Linux. The third improvement is the policy management complexity; the policy is very complex in SentinelOne Singularity Endpoint, and we have to apply each and every policy for each endpoint. We have to create different groups for different policies, such as USB-based and Bluetooth-based.
Soc Analyst Trainee at Softcell Technologies Limited
Real User
Top 5
Apr 27, 2026
One area that has room for improvement in SentinelOne Singularity Endpoint is the inability to create a custom dashboard. You cannot create any dashboard according to your needs, which limits alert triggers across different countries. If they improve this feature to allow for custom dashboards, it would greatly benefit our customers.
To improve SentinelOne Singularity Endpoint, I suggest enhancing the dashboard and reporting functionalities for better customization, making it easier for management to access tailored reports. Also, deeper integration with other tools would streamline daily operations, especially as it currently does not support mobile devices—though I know this feature is on their roadmap.
Technical Support Executive at Softcell Technologies Limited
Real User
Top 5
Apr 3, 2026
What I dislike about SentinelOne Singularity Complete is the high number of false positive alerts we get because our client sends us mail within one week stating that the CPU is highly utilized and resource consumption is high. Regarding data privacy and security when using Purple AI, I can say that security-wise, it is good, though anyone can exploit that one.
Network Security Engineer at a retailer with 11-50 employees
Real User
Top 5
Mar 31, 2026
In terms of improvement areas for SentinelOne Singularity Complete, while it is a very strong platform, there are a few areas where it could be better. Custom reporting flexibility is an aspect to consider; while the existing reports are useful, having more customizable report templates or an easier drag-and-drop option would help tailor insights to different teams. Granular policy control is another aspect to improve, as some security policies could benefit from more fine-grained control, especially for organizations with highly diverse endpoint and specialization workflows. Lastly, integration with other IT tools could be expanded, as additional out-of-the-box integrations with other IT management or SIEM platforms could further streamline operations. Overall, these are relatively minor improvements and do not take away from the core strengths of the platform. Addressing them could make SentinelOne Singularity Complete even more powerful and flexible for larger, complex environments. A needed improvement for SentinelOne Singularity Complete is faster console load time. On very large deployments, the management console can sometimes be slightly slow to load dashboards or filter large endpoint lists. Faster performance here would improve efficiency. Additionally, enhanced threat insights in alerts would be beneficial. While alerts are clear, having contextual information and suggested remediation steps directly in the alert could help junior IT staff act even faster.
Security Engineer at a tech vendor with 11-50 employees
Real User
Top 5
Mar 18, 2026
Singularity Platform could be improved by providing a more comprehensive analysis part, particularly on the threat dashboard. If automated analysis in simple terms could be received to explain to customers what exactly is happening, it would be a great addition to the product. Regarding customizable dashboards, there are predefined dashboards that provide good visibility, but customized dashboards are not that helpful. I would not recommend using them as they can become messier. My advice for organizations considering Singularity Platform is to encourage the addition of a threat analysis part that integrates with their Purple AI, allowing explanation of specific threats in a simpler way for customers.
I believe there is room for improvement in Singularity Platform regarding its product. First of all, with all automated systems, they need to have the capabilities to expand rather quickly. When I was there, I do not believe they had the ability to do that. In addition, they are very concentrated on certain clients which they have contractual obligations to meet. As for other areas that could be improved in Singularity Platform, I believe there are a bunch of customer-facing uploads that need improvement. The communication between clients and the teams working internally with that client also needs enhancement. The automation itself has to be increased in terms of bandwidth or capability of the system. For example, there were times when there were severe lag problems on the system due to capacity issues. They may not have had enough servers. There was a lack of response time at times.
I do not recall a real-time personalization kind of feature in Singularity Platform. If ranking is applied, I would rank CrowdStrike as one, Singularity Platform as two, and Palo Alto's Cortex as three. The issues mentioned in Singularity Platform are well taken care of in CrowdStrike, and CrowdStrike now has a bigger portfolio in terms of data security, identity security, and AI security. The new-age integrations are better in CrowdStrike, and I'm sure Singularity Platform will catch up, but as of now, CrowdStrike has an added advantage. From an XDR perspective, if Singularity Platform could expand their existing set of supported log sources, that would be better. As of now, they have a limited set of security solutions that can be integrated as part of their XDR platform, and if they increase that, it would be better because not all customers will have the set of supported log sources that they have. Additionally, they don't have a scheduled scan feature; you have to do it through a different mechanism. If they can bring it as part of the platform, the scheduled scan feature would improve usability. Apart from that, from an operations or overall security perspective, we haven't found any such issues with the platform.
There are a lot of false positives in that, which is why I'm not working with it. The use of the fraud detection feature in financial services in Singularity Platform depends on the compliances that are applicable to the organization, so it may be useful for some and may not be useful for others. I did that by myself, not with the help of Singularity Platform. In my opinion, the real-time monitoring capabilities in Singularity Platform sometimes work and sometimes they don't, because there are a lot of false positives and people use unsigned applications which get deleted or quarantined by the product. It's not a 100% foolproof solution. A point for improvement for SentinelOne is that the false positives are huge since people in India, at least, are using homegrown applications which get blocked. Right now, Singularity Platform is working fine, but people have concerns about enhancements like website monitoring that can be done through Singularity Platform itself, so they don't need to buy any SASE products for people working from home to control their browsing. If that feature can be included, it will be a big advantage.
Information Security Officer at a tech vendor with 51-200 employees
Real User
Top 5
Nov 17, 2025
I think some parts of Singularity Platform could be improved or enhanced, as you most likely need to know the platform quite well to write queries and search for information. There are a few too many similar fields, such as the storyline ID and the storyline, which sometimes gets confusing. Perhaps the distinguishing could be better, but correlation in general is done very well with the storyline because it is the platform's own field for correlating data.
Co-Founder & VP Sales and Marketing at a tech services company with 11-50 employees
Reseller
Top 5
Sep 29, 2025
The dashboards can be improved, and their dashboarding functionality needs to be better. The way the dashboards look is not really impactful or meaningful.
SentinelOne Singularity Complete is an advanced endpoint security platform featuring centralized management across multiple locations. It leverages AI-driven behavior detection, threat prioritization, and ransomware rollback for enhanced protection and streamlined operations.
With a focus on endpoint protection, threat detection, and automated response, SentinelOne Singularity Complete provides comprehensive security through AI-powered behavioral analysis and real-time threat detection. The...
To improve SentinelOne Singularity Endpoint, I want to continue working on this and provide even more data, more visibility, and everything clearer and faster. I guess everywhere could use a few additional functions, but they are not really needed. I would add more about the needed improvements regarding features. I mean more deeper insights and bigger visibility so that when you have any process, you can click and it can show you everything for that process, so you can see really quickly everything that you need, enabling quick analysis and decision-making.
Since adopting SentinelOne Singularity Endpoint, I have seen a mixed bag of measurable results. There have indeed been many fewer risks, but there have been other problems. SentinelOne Singularity Endpoint tends to block workstations at the slightest doubt, so it needs to be fine-tuned to be a bit more tolerant. Otherwise, there are blocked workstations and loss of productivity. There were many problems on old Windows Servers that were not compatible, so they had to be upgraded. If SentinelOne Singularity Endpoint were more backward compatible with older versions, that would be great. The old versions of Windows Server were not very compatible, but that is the only criticism.
Regarding SentinelOne Singularity Endpoint's AI capabilities, I find its accuracy and reliability of output to be dependable, though I believe it could improve by opening up the access to more than summarizing or creating queries.
I believe their SLAs could be tighter, but overall it is a good platform. Those are the main improvements needed for SentinelOne Singularity Endpoint. I don't think there are any other significant improvements needed that I haven't mentioned; there may be minor items or wish-list features.
I would really appreciate having raw data of what is happening presented in a clearer format. Additionally, a cloud backup of malware would be beneficial so that we can maintain a copy of the ransomware and malware on SentinelOne for analysis purposes. I would not want to add more about needed improvements because all of the current capabilities are really awesome, and they have done a really good job.
I think the area that can be improved is the reporting and the dashboard customization. Also, the other tooling and the false positive reduction is important because it is better to prioritize the critical ones and reduce the false positives. Additionally, the integration from CMDB source solution is another improvement. Because the platform gives a lot of information, creating a customized report for management and different security teams could be easier and more flexible. I think documentation can improve with more practical troubleshooting. Also, the agent performance is an area for improvement. I think the endpoint agent could be optimized to reduce CPU and memory consumption, especially on older systems. Additionally, policy management could be improved because managing policy across a large number of endpoints and different groups could be more intuitive.
SentinelOne could prepare more native integrations for downloading data from external sources. There are already many integrations available, but it would be beneficial if Purple AI could search also through the data ingested to Data Lake and generate alerts based on external data which is uploaded to AICM. Regarding functionalities, it is among the best protection that I have checked. However, the price and the fact that each functionality such as vulnerability management or cloud funnel requires additional licenses raises the yearly cost for the company.
The UX in SentinelOne Singularity Endpoint can be quite difficult sometimes. We had in the past other EDR, and sometimes the former EDR was simpler than SentinelOne Singularity Endpoint, so at the beginning, it can be really complex to understand how it works, how to manage the policies, and how to handle the RBAC. We had to follow the documentation and the different knowledge transfers offered by SentinelOne Singularity Endpoint, but we are quite good now, so we can manage SentinelOne Singularity Endpoint by ourselves. Except for the UX part of SentinelOne Singularity Endpoint which can be time-consuming, I do not have any other improvements to share. I chose eight out of ten because even if SentinelOne Singularity Endpoint is quite good in our day-to-day works, there are some improvements needed, especially on the UX part. The UX part is really important for us because we have some turnover in the cybersecurity team, so we would like to be sure that newcomers can handle SentinelOne Singularity Endpoint quickly, and sometimes we have to share knowledge transfers, which can be time-consuming.
Having some capture-the-flag exercises inside the console, perhaps from time to time if the vendors propose them, would be a good improvement. Additionally, improvements at the level of events and checks for all the new components and all the new features of the console would be beneficial. I rate it an eight and not a higher or lower score because it does not have web reputation management. It does not act at the web level. It works primarily only at the file level and endpoint inventory. There are no other aspects that could be improved in SentinelOne Singularity Endpoint that I have not mentioned.
Recently, I faced an issue with SentinelOne Singularity Endpoint while detecting rogue devices, as there is a gap when scanning initiated from the admin console, recognizing different MAC IDs depending on the connection type, which leads to conflict between managed and unmanaged assets. Another area needing improvement is the process graph of SentinelOne Singularity Endpoint, which could be made more user-friendly, eye-catching, and offer a better in-depth view.
I am satisfied with SentinelOne Singularity Endpoint overall, but if it could be improved, it would be in providing more customizable reporting, a richer dashboard, and broader integration with third-party tools. Other than that, I find it effective and reliable with no major suggestions for improvement. Based on my experience with SentinelOne Singularity Endpoint, I have not encountered any major issues that significantly affect our day-to-day operations. The platform has been stable, and while every product continues to evolve with new features and integrations, I do not have additional improvements to suggest at this time.
When retrieving results for logs in the AI SIEM of SentinelOne, there is a limitation where I can download up to 10,000 columns at a time, and the same constraint applies to vulnerability data. This product limitation needs improvement in future updates. I would like to see these limitations removed in SentinelOne Singularity Endpoint. Additionally, the device control feature needs improvement. The EDR is solid, but there are several areas where the quality of work could be enhanced.
I believe SentinelOne Singularity Endpoint is a strong security platform, but areas for improvement include reporting and dashboard customization, as well as providing more advanced threat hunting queries and easier navigation for new users, which would enhance the overall experience.
Although it has been almost six and a half months, I do not have many features in mind that I find necessary. However, I really appreciate how I can specify scanning folders or areas in the system. Since it is endpoint detection, I can specify which areas to always check for scanning. It has exclusions as well; for example, if I want to scan everything in a system but exclude particular folders or extensions, I can specify that in SentinelOne Singularity Endpoint. That provides me with more granular control over what needs to be scanned and what does not, helping me avoid many false positives and making the systems more reliable in alert conditions. The results become more accurate. I do not feel anything needs to be flagged for improvement, but everything requires some enhancements. While using SentinelOne Singularity Endpoint, I do not feel anything needs to be added as a feature or improved. Most of its functions work well. I cannot think of anything at this moment regarding needed improvements.
We are not working with SentinelOne Complete to consolidate our security solutions in one place. If SentinelOne could localize the Purple AI and other features for larger environments such as ours, which has around 20,000 endpoints, that would be an improvement. If they could provide a local LLM that can be installed on-premise, it would be easier for us. Otherwise, we need to obtain government permissions, which is quite complex and can take years. A local version of the LLMs for Purple AI would be beneficial. I believe that SentinelOne's technical support needs to improve slightly. They are quite slow, and while I understand they might be busy, I would rate them at a seven out of ten.
For maintenance of SentinelOne Singularity Endpoint, there are two things. If I need to create any maintenance or upgrade policy, that is a different matter. The customer is looking for the maintenance window and wants the upgrade part mainly on Sunday or Saturday, the weekend part. They do not want the auto-upgrade whenever SentinelOne pushes from the backend. If I am looking at the impact of Purple AI on amplifying team knowledge, there are multiple things. If I am looking at how many endpoints are in my organization, how many endpoints have this application, and how many endpoints have multiple threats and alerts, I want to know how to reduce them. If I am asking particularly how to reduce the threat count, I do not think Purple AI can give this answer because AI is not particularly for this enterprise account. Purple AI is something I can rely on for multiple things, such as if I need to know how to create tags, policies, blocklists, exclusions, network control, device control, how to enable the firewall, and how to create a block policy with the hash. There are many things. If I need to install any agent on a particular Windows machine, whether it is 64 or 32-bit, or a Mac machine, or a Linux machine, or any other machine, how I need to add the token, and how I need to download the package are all considerations. Additionally, how to ensure that the agent is connected with my management plane is important.
Before using SentinelOne Singularity Endpoint, I used different products, including CrowdStrike. In the space where SentinelOne Singularity Endpoint is working, it is an awesome product. However, I believe the vulnerability management is currently in pilot. If it can mature into good production where the vulnerability management module is working well within Singularity Complete edition, that would be an awesome step. The vulnerability assessment is available, but application vulnerability assessment or other endpoint vulnerability assessment is not as good as what other products are providing. Singularity Complete is a good product in its area and, obviously, when comparing to other organizations or companies providing endpoint detection solutions, it is an end-to-end solution for antimalware and XDR. This has been working fine for me so far. I am using it in small, medium, and enterprise organizations, and it is good. However, as I mentioned for the vulnerability assessment, along with the specification of handling core, detailed forensics, there could be more details I would add. However, if I recall correctly, there is a specific module within SentinelOne Singularity Endpoint to check all details of the functions that happened within the target machine. I am currently unable to recall the name of that module, but it exists. However, there is room for improvement where more details of the solution or from the target can be added, and this would help me more easily identify the impact or the root cause that impacts the endpoint. This would be more helpful for end users. Currently, if there is an impacted endpoint, I click on the endpoint, and it gives me insights about what happened with this endpoint. However, when I need to go into the details, there is some limitation to viewing those details for the target machine. It would be awesome if this module could be integrated into the normal Sentinels. This would be more helpful for engineers working on core identification of root causes.
In terms of improvement areas for SentinelOne Singularity Endpoint, I think there are a couple of features that are improving, particularly the dashboard such as creating a multi-function dashboard. There is one loophole that needs addressing, but it is still better overall.
I would suggest a lot of improvements; first, the dashboard is critical for new joiners, especially with the addition of Purple AI and EDR, which makes it complex for new SOC users. Second, the rollback feature is only available for Windows systems, not for Linux and Mac OS. Third, the dashboard is not customizable; I cannot create a dashboard as it is already inbuilt in SentinelOne Singularity Endpoint management console.
For SentinelOne Singularity Endpoint, the first issue I dislike is the high CPU utilization, and the second is a very high number of false positive alerts from the EDR. Data security is very important in today's organizations when using Purple AI with endpoints in the SentinelOne Singularity network and applications everywhere. However, SentinelOne Singularity does not have strong features for data security. Purple AI is used to find IOCs, hashes, zero-day vulnerabilities, or CVEs found in the network. We use it for that purpose only. From a data security perspective, SentinelOne Singularity does not have a major role. With Purple AI, we ask questions about an IOC or provide a query and receive answers from Purple AI, but that is the extent of its functionality.
Currently, I have nothing to suggest for improvements to SentinelOne Singularity Endpoint; we are very happy with the tool. If I had to imagine one thing that could enhance my experience with SSentinelOne Singularity Endpoint, I would pick an easier way to view or follow the XDR platform, as I had some difficulties with it in the past. I think that training would be beneficial for using the XDR, as we have a lot of information available there.
The first improvement is the dashboard because it is very complex. As a beginner-friendly SOC analyst or MDR analyst, the dashboard is a bit complex, so the dashboard needs to be more user-friendly. The second improvement is the VSS rollback feature, which is useful only for Windows laptops and servers, not for macOS and Linux. The third improvement is the policy management complexity; the policy is very complex in SentinelOne Singularity Endpoint, and we have to apply each and every policy for each endpoint. We have to create different groups for different policies, such as USB-based and Bluetooth-based.
One area that has room for improvement in SentinelOne Singularity Endpoint is the inability to create a custom dashboard. You cannot create any dashboard according to your needs, which limits alert triggers across different countries. If they improve this feature to allow for custom dashboards, it would greatly benefit our customers.
To improve SentinelOne Singularity Endpoint, I suggest enhancing the dashboard and reporting functionalities for better customization, making it easier for management to access tailored reports. Also, deeper integration with other tools would streamline daily operations, especially as it currently does not support mobile devices—though I know this feature is on their roadmap.
What I dislike about SentinelOne Singularity Complete is the high number of false positive alerts we get because our client sends us mail within one week stating that the CPU is highly utilized and resource consumption is high. Regarding data privacy and security when using Purple AI, I can say that security-wise, it is good, though anyone can exploit that one.
In terms of improvement areas for SentinelOne Singularity Complete, while it is a very strong platform, there are a few areas where it could be better. Custom reporting flexibility is an aspect to consider; while the existing reports are useful, having more customizable report templates or an easier drag-and-drop option would help tailor insights to different teams. Granular policy control is another aspect to improve, as some security policies could benefit from more fine-grained control, especially for organizations with highly diverse endpoint and specialization workflows. Lastly, integration with other IT tools could be expanded, as additional out-of-the-box integrations with other IT management or SIEM platforms could further streamline operations. Overall, these are relatively minor improvements and do not take away from the core strengths of the platform. Addressing them could make SentinelOne Singularity Complete even more powerful and flexible for larger, complex environments. A needed improvement for SentinelOne Singularity Complete is faster console load time. On very large deployments, the management console can sometimes be slightly slow to load dashboards or filter large endpoint lists. Faster performance here would improve efficiency. Additionally, enhanced threat insights in alerts would be beneficial. While alerts are clear, having contextual information and suggested remediation steps directly in the alert could help junior IT staff act even faster.
Singularity Platform could be improved by providing a more comprehensive analysis part, particularly on the threat dashboard. If automated analysis in simple terms could be received to explain to customers what exactly is happening, it would be a great addition to the product. Regarding customizable dashboards, there are predefined dashboards that provide good visibility, but customized dashboards are not that helpful. I would not recommend using them as they can become messier. My advice for organizations considering Singularity Platform is to encourage the addition of a threat analysis part that integrates with their Purple AI, allowing explanation of specific threats in a simpler way for customers.
I believe there is room for improvement in Singularity Platform regarding its product. First of all, with all automated systems, they need to have the capabilities to expand rather quickly. When I was there, I do not believe they had the ability to do that. In addition, they are very concentrated on certain clients which they have contractual obligations to meet. As for other areas that could be improved in Singularity Platform, I believe there are a bunch of customer-facing uploads that need improvement. The communication between clients and the teams working internally with that client also needs enhancement. The automation itself has to be increased in terms of bandwidth or capability of the system. For example, there were times when there were severe lag problems on the system due to capacity issues. They may not have had enough servers. There was a lack of response time at times.
I do not recall a real-time personalization kind of feature in Singularity Platform. If ranking is applied, I would rank CrowdStrike as one, Singularity Platform as two, and Palo Alto's Cortex as three. The issues mentioned in Singularity Platform are well taken care of in CrowdStrike, and CrowdStrike now has a bigger portfolio in terms of data security, identity security, and AI security. The new-age integrations are better in CrowdStrike, and I'm sure Singularity Platform will catch up, but as of now, CrowdStrike has an added advantage. From an XDR perspective, if Singularity Platform could expand their existing set of supported log sources, that would be better. As of now, they have a limited set of security solutions that can be integrated as part of their XDR platform, and if they increase that, it would be better because not all customers will have the set of supported log sources that they have. Additionally, they don't have a scheduled scan feature; you have to do it through a different mechanism. If they can bring it as part of the platform, the scheduled scan feature would improve usability. Apart from that, from an operations or overall security perspective, we haven't found any such issues with the platform.
There are a lot of false positives in that, which is why I'm not working with it. The use of the fraud detection feature in financial services in Singularity Platform depends on the compliances that are applicable to the organization, so it may be useful for some and may not be useful for others. I did that by myself, not with the help of Singularity Platform. In my opinion, the real-time monitoring capabilities in Singularity Platform sometimes work and sometimes they don't, because there are a lot of false positives and people use unsigned applications which get deleted or quarantined by the product. It's not a 100% foolproof solution. A point for improvement for SentinelOne is that the false positives are huge since people in India, at least, are using homegrown applications which get blocked. Right now, Singularity Platform is working fine, but people have concerns about enhancements like website monitoring that can be done through Singularity Platform itself, so they don't need to buy any SASE products for people working from home to control their browsing. If that feature can be included, it will be a big advantage.
I think some parts of Singularity Platform could be improved or enhanced, as you most likely need to know the platform quite well to write queries and search for information. There are a few too many similar fields, such as the storyline ID and the storyline, which sometimes gets confusing. Perhaps the distinguishing could be better, but correlation in general is done very well with the storyline because it is the platform's own field for correlating data.
The dashboards can be improved, and their dashboarding functionality needs to be better. The way the dashboards look is not really impactful or meaningful.