SentinelOne provides autonomous security solutions for various IT environments. The company's main focus is on endpoint security, cloud security, and identity security. It operates on an AI-powered platform that brings prevention, detection, response, remediation, and forensics under one umbrella. The endpoint security product uses artificial intelligence to constantly adapt to new threats, offering real-time protection and automated response. The key principle of SentinelOne's security approach is to allow organizations to detect harmful behavior across multiple vectors, rapidly eliminate threats with an integrated response, and continuously adapt defenses against advanced cyber attacks. The company also provides a range of services such as threat hunting, incident response, and incident management.
Do You Manage Peer Insights at SentinelOne?
Access Vendor Portal to update and manage your profile.
The XDR and EDR capabilities are amazing, we have a lot of platforms digesting information into the XDR and then overlapping with Purple AI for fast natural language lookups and queries has been a game changer, especially during incident investigation. Whenever we hit a bottleneck or knowledge gap, the Australian technical and sales team has been amazing at providing us with fast and personalised support.
Cloud Security is easy to set up, integrates with many different platforms, and provides insights into suspicious behavior (if you purchase the pro version).
What i like most is its unified approach to cloud security, where it combines visibility, threat detection and vulnerability management into a single platform. Real time monitoring and AI driven insights help in quickly identifying suspicious activity.
Purple AI, which is getting much better since the first launch, still has its occasional problems in terms of surfacing false-positives where a simple deep dive into the event would show it's not a threat. Additional work with Purple AI needs to happen to ensure it becomes an extremely reliable and accurate tool. Considering the amount of information we store in XDR, there is a lot to sift through, so AI is going to become a must have especially during incident investigation.
Integration with the central console. The new central console is where SentinelOne aims to collate all products into one view. Some people will like it however some do not. In the endpoint security tool you will still have access to the legacy view, but with cloud security this is not possible.
One of the main challenges is the initial alert volume, which can be a bit overwhelming until proper tuning is done. Some features require a learning curve, especially for teams new to cloud security tools. Reporting and customization options could be improved, as generating very specific reports is sometimes difficult.