![Victor M.](/assets/transparent-ad5be28fbcd25b7b08d2cebe1d957125437fb5407d75ee717965ad22c8808791.gif "Victor M.")
VM

Victor M.

Penetration Tester

Mid-Market (51-1000 emp.)

8/7/2026

"Autonomous Threat Mitigation and Storyline Visibility That Save Hours"

5/5

What do you like best about SentinelOne Singularity Endpoint?

What's provided the most value for me is the autonomous response. Running a mixed Windows/macOS fleet with a chunk of BYOD devices, I can't babysit every alert, and the on-agent behavioural AI catches and auto-mitigates threats without waiting on a cloud round-trip or an analyst clicking "contain". The Storyline attack visualisation is the feature I lean on daily; instead of stitching together process trees myself, I get the full execution chain mapped out, which turns what used to be a 30-minute triage into a few minutes of confirming and rolling back. AI / Intelligence: The static and behavioural AI models running locally mean detection holds up even when a device is offline, which matters for laptops that aren't always on the VPN. Fewer noisy false positives than the signature-based tooling I've used before. UI / UX: The console is clean, and the Deep Visibility query interface lets me hunt across the fleet quickly. Onboarding new admins doesn't require weeks of ramp-up. Performance: Agent footprint is light — I haven't had the user complaints about system slowdown that plagued our previous endpoint tool, which is a real win when you're deploying to BYOD machines you don't fully control. Integrations: Ranger for network visibility (surfacing unmanaged devices) plus the API and SIEM connectors have fit into our stack without much friction. Adding Ranger meant I stopped needing a separate discovery tool to find rogue endpoints. Support / Onboarding: Deployment was straightforward, and vendor support has been responsive on the escalations that mattered. Pricing / ROI: It is not the cheapest option, but the ROI shows up in reduced analyst hours; the one-click rollback on ransomware alone has justified the spend, and consolidating discovery (Ranger) into the same platform cut a line item elsewhere. Unexpected benefit: The rollback capability doubled as a safety net for my organisation during a legitimate-but-misclassified software push; being able to reverse endpoint changes cleanly saved a reimaging headache. Review collected by and hosted on G2.com.

What do you dislike about SentinelOne Singularity Endpoint?

The biggest pain point is policy and exclusion management at scale. Building exclusions is more manual than it should be; there's no clean way to test an exclusion's blast radius before it goes live, so tuning for a noisy line-of-business app on part of the fleet involves more trial-and-error than I'd like. A "preview affected endpoints" step or a staging mode for policy changes would cut real risk out of the process. Deep Visibility is powerful, but the query experience has a learning curve. The syntax isn't intuitive for newer analysts, and saved-query sharing and templating could be better. When I'm onboarding someone, threat hunting is the piece that takes longest to hand off, which partly defeats the "autonomous" pitch for smaller teams. Reporting is the other weak spot. The canned reports rarely match what I need for regulatory or management audiences, so I still end up exporting to build the view myself. More flexible, customisable reporting, or a proper report builder, would save hours each reporting cycle. On macOS, agent updates and OS-version compatibility have occasionally lagged behind Windows, which matters on a mixed fleet where I can't always hold back an OS update on a BYOD device. Tighter macOS parity would help. Console performance can also drag when pulling large time-range queries across the full fleet, and the alert volume before tuning is high enough that early days feel noisier than expected. Review collected by and hosted on G2.com.

What problems is SentinelOne Singularity Endpoint solving and how is that benefiting you?

The core problem it solves for us is endpoint visibility and response across a mixed Windows/macOS fleet that includes BYOD devices we don't fully control. Before, detection leaned heavily on signature-based tooling that missed behavioural threats and generated noise, and our response was manual; an analyst had to triage, decide, and contain, which meant slow reaction to anything that landed off-hours or while a laptop was off the VPN. Now the on-agent AI detects and auto-mitigates threats locally, so containment doesn't wait on an analyst or a cloud round trip. That's collapsed our mean time to respond to the incidents that matter, and the biggest single win is the one-click rollback on ransomware and malicious changes; reversing endpoint state cleanly has taken reimaging off the table for cases that used to mean hours of rebuild per machine. The second problem was unmanaged devices. We struggled to reliably find rogue or unenrolled endpoints on the network, but Ranger surfaces them without a separate discovery tool, which closed a real gap in our asset visibility and cut a line item from the stack. Third is investigation time. Storyline maps the full attack chain automatically, so triage that used to mean manually reconstructing process trees now takes a few minutes of confirming and acting – meaningfully less analyst time per alert, which for a lean team is the difference between keeping up and falling behind. Net benefit: faster response, less manual rebuild work, tighter asset visibility, and analyst hours redirected from triage to higher-value work. Review collected by and hosted on G2.com.

Show More

Rating Updated (8/10/2026)
Current UserValidated ReviewerIncentivizedSource: Seller invite

See what 204 reviewers think of SentinelOne Singularity Endpoint

4.7 out of 5 · Verified reviews from real users

[
Read all reviews
](https://www.g2.com/products/sentinelone-singularity-endpoint/reviews)