What is our primary use case?
We have been using SentinelOne Singularity MDR for threat hunting and correlation, particularly when we identify if some kind of IOCs has been detected or if processes are found malicious. We then analyze it across the entire network for similar behaviors in other systems or processes. Accordingly, we curate responses, which can involve isolating those systems or conducting further investigation through back-end analysis, digging into command line consoles, or deleting files. This is the primary use case I can think of.
What is most valuable?
When discussing features in SentinelOne Singularity MDR, I find integration with third-party solutions and APIs very valuable because it eases management and response processes. With a robust library, it is easier to manage integrations with other technologies, such as the Check Point sandboxes, which we have found very useful.
In terms of minimizing false positives and delivering accurate detections, I have observed that the false positive rate in SentinelOne Singularity MDR is considerably lower compared to other solutions we have evaluated, thanks to the exceptions or policy changes that allow modifications to baseline policies hardcoded within the solution.
Regarding threat hunting capabilities, I assess that the threat hunting capability in SentinelOne Singularity MDR is quite good because their EDR collects extensive telemetry data, and the backend search engine processes this data quickly. This speed is crucial for our large-level customers who have around 50,000 inputs and multiple gigabytes of data daily. Therefore, threat hunting becomes easier due to the significant amount of telemetry data gathered and the fast processing time when firing queries.
The main benefits that clients receive from SentinelOne Singularity MDR, from an operational perspective, include ease of deployment, where the installation process across various operating systems and different hardware configurations goes smoothly with minimal impact on end users. It is important that end users have a smooth experience during deployment. Besides the navigation issue I mentioned, policy configurations and other processes are straightforward, similar to a plug-and-play setup that is easy to manage. Furthermore, the detection rate is very good compared to other solutions, and as previously mentioned, the false positive rate is low, making the workload for the SOC team much easier after implementing SentinelOne Singularity MDR at our customers.
What needs improvement?
I would like to improve the dashboard in SentinelOne Singularity MDR, as it could be much better, along with the reporting structure. The granularity of policies and ease of policy management from the console could be made better, while my experience from a feature standpoint has been good overall.
Regarding summary reports provided from SentinelOne Singularity MDR, I find the reporting structure could be much better in terms of granularity. Additionally, for C-suite executives, there can be more non-technical content that provides a bird's eye view of organizational risk posture, rather than just detailed technical analyses. This high-level perspective on the organization's risk would be highly beneficial at the management level.
For how long have I used the solution?
I have been with SentinelOne Singularity MDR since around December 2020, so it has been one and a half years.
What was my experience with deployment of the solution?
The initial setup for SentinelOne Singularity MDR is simple; there are not many complexities involved unless you encounter unsupported third-party integrations, which can introduce some challenges. However, if you are using compatible data sources, the setup process is generally smooth.
What do I think about the stability of the solution?
The stability of SentinelOne Singularity MDR deserves a rating of eight.
What do I think about the scalability of the solution?
The scalability rates at nine because they are quite scalable; being a cloud solution means we do not have to worry about scalability issues.
How are customer service and support?
The technical support from SentinelOne Singularity MDR rates at 7.5 out of 10.
How was the initial setup?
The initial setup for SentinelOne Singularity MDR is simple; there are not many complexities involved unless you encounter unsupported third-party integrations, which can introduce some challenges. However, if you are using compatible data sources, the setup process is generally smooth.
Which other solutions did I evaluate?
I can compare SentinelOne Singularity MDR to CrowdStrike as the main competitor in the market.
When comparing the two vendors, I feel that neither one is clearly better than the other, as both provide their own strong points and necessary features as part of their MDR solutions. Although I have not found significant differences, I do perceive that CrowdStrike has a slight edge regarding support and turnaround time for issue resolution, and they tend to introduce new features more regularly than SentinelOne Singularity MDR.
What other advice do I have?
We currently work with multiple vendors since I work for a cybersecurity solution company, and in the EDR space, we are engaged with CrowdStrike and SentinelOne Singularity MDR.
We work with SentinelOne Singularity MDR as it is similar to SentinelOne Vigilance, and I specifically use Singularity only. I use every module of SentinelOne Singularity MDR, including EDR, NGAV, ASM, and Identity.
I have not specifically worked on the solution's proactivity and branch readiness features to state how they help in preparing for incidents. I have not encountered any use case that has not been covered by SentinelOne Singularity MDR, but since I have not explored the entire range of products they offer and they introduce new features quarterly, I cannot provide specific suggestions at this time.
Pricing for SentinelOne Singularity MDR varies on a case-by-case basis, and I notice that they have flexibility when it comes to pricing. On a scale where one is high and ten is low, I would place it around six.
My overall rating for SentinelOne Singularity MDR is 8 out of 10.
Which deployment model are you using for this solution?
Public Cloud
If public cloud, private cloud, or hybrid cloud, which cloud provider do you use?
Other