+
+

Related Products

  • ManageEngine Log360
    187 Ratings
    Visit Website
  • Graylog
    432 Ratings
    Visit Website
  • Daylight
    10 Ratings
    Visit Website
  • ManageEngine EventLog Analyzer
    211 Ratings
    Visit Website
  • Blumira
    150 Ratings
    Visit Website
  • SOCRadar Extended Threat Intelligence
    115 Ratings
    Visit Website
  • Criminal IP
    17 Ratings
    Visit Website
  • Safetica
    415 Ratings
    Visit Website
  • ThreatLocker
    695 Ratings
    Visit Website
  • Omnilert
    26 Ratings
    Visit Website

About

Standing watch, by your side. Intelligent security analytics for your entire enterprise. See and stop threats before they cause harm, with SIEM reinvented for a modern world. Microsoft Sentinel is your birds-eye view across the enterprise. Put the cloud and large-scale intelligence from decades of Microsoft security experience to work. Make your threat detection and response smarter and faster with artificial intelligence (AI). Eliminate security infrastructure setup and maintenance, and elastically scale to meet your security needs—while reducing IT costs. Collect data at cloud scale—across all users, devices, applications, and infrastructure, both on-premises and in multiple clouds. Detect previously uncovered threats and minimize false positives using analytics and unparalleled threat intelligence from Microsoft. Investigate threats with AI and hunt suspicious activities at scale, tapping into decades of cybersecurity work at Microsoft.

About

One intelligent platform. Unprecedented speed. Infinite scale. Singularity™ enables unfettered visibility, industry-leading detection, and autonomous response. Discover the power of AI-powered, enterprise-wide cybersecurity. The world’s leading enterprises use the Singularity platform to prevent, detect, and respond to cyber attacks at machine-speed, greater scale, and higher accuracy across endpoint, cloud, and identity. SentinelOne delivers cutting-edge security with this platform by offering protection against malware, exploits, and scripts. SentinelOne cloud-based platform has been perfected to be innovative compliant with security industry standards, and high-performance whether the work environment is Windows, Mac or Linux. Thanks to constant updating, threat hunting, and behavior AI, the platform is ready for any threat.

Platforms Supported

Windows
Mac
Linux
Cloud
On-Premises
iPhone
iPad
Android
Chromebook

Platforms Supported

Windows
Mac
Linux
Cloud
On-Premises
iPhone
iPad
Android
Chromebook

Audience

IT security teams

Audience

Organizations and businesses that want an all-in-one endpoint protection platform

Support

Phone Support
24/7 Live Support
Online

Support

Phone Support
24/7 Live Support
Online

API

Offers API

API

Offers API

Screenshots and Videos

Screenshots and Videos

Pricing

Logs from Microsoft 365 are ingested for free.
Free Version
Free Trial

Pricing

$45 per user per year
Free Version
Free Trial

Reviews/Ratings

Overall 5.0 / 5
ease 4.5 / 5
features 5.0 / 5
design 4.0 / 5
support 5.0 / 5

Reviews/Ratings

Overall 5.0 / 5
ease 4.7 / 5
features 5.0 / 5
design 4.7 / 5
support 4.8 / 5

Pros & Cons from Real Users

Pros

  • Seamlessly integrates with other Microsoft services such as Azure and Office 365, leveraging existing infrastructure and familiarity. Utilizes AI and machine learning to detect and respond to advanced threats quickly. Scales effectively to meet the needs of both small businesses and large enterprises, handling vast amounts of data efficiently. Provides automation capabilities for incident response and remediation, improving efficiency and reducing manual effort. Helps organizations meet compliance requirements with built-in tools and capabilities.
  • Built on Azure, Microsoft Sentinel scales effortlessly to handle increasing log volumes without requiring on-premises infrastructure upgrades Deep integration with M365, Azure Active Directory, Defender for Endpoint, and mdCloud enhances security monitoring across endpoints, identities, and workloads Sentinel collects and correlates data from a wide range of sources, including third-party solutions, using connectors. Integration with threat intelligence feeds enhances its detection capabilities Supports KQL (Kusto Query Language) for custom query creation, giving analysts flexibility in analyzing and visualizing log data Sentinel leverages built-in AI and ML to identify anomalies, detect threats, and reduce false positives. Customizable analytics rules allow security teams to focus on relevant alerts

Cons

  • Users may face a learning curve, especially if they are not familiar with Azure or Microsoft's ecosystem, impacting initial setup and configuration. Depending on usage and scale, costs associated with Azure Sentinel can be significant, especially for smaller organizations or those with limited budgets.
  • While Sentinel follows a pay-as-you-go model, costs for data ingestion can escalate quickly, especially for large-scale organizations generating high volumes of logs. Retention beyond 90 days incurs additional expenses, making cost management a challenge Sentinel works best within the Microsoft ecosystem. Organizations with diverse tech stacks or heavy reliance on non-Microsoft services may find its integrations with third-party tools less seamless or feature-rich compared to vendor-agnostic SIEM solutions

Pros & Cons from Real Users

Pros

  • 1. Can be deployed to all the endpoints including the Servers and supports most of the OS platforms 2. Triaging can be done which is very useful for identifying and remediation of the security incidents 3. Discovery of Asset and Software inventory is really a good feature
  • SentinelOne automatically recognizes, evaluates, and neutralizes ransomware and zero-day attacks using artificial intelligence (AI) and machine learning. It can better detect unknown threats because it doesn't only rely on signature-based detection. Through a single dashboard, Singularity offers consolidated visibility into the security state of every endpoint throughout the company.
  • Utilizes artificial intelligence and machine learning algorithms to detect and prevent advanced threats in real-time. Uses behavioral analysis to identify and block suspicious activities and malware, even those that are previously unseen or zero-day. Offers automated response capabilities to contain and remediate threats without human intervention, reducing response times and minimizing damage. Built on a cloud-native architecture, facilitating scalability and allowing organizations to manage endpoints efficiently from a centralized console. Offers continuous monitoring and support, ensuring timely response to security events and proactive protection against emerging threats.
  • SentinelOne provides full visibility across all endpoints, including servers, cloud environments, and mobile devices. This unified approach helps organizations identify threats and vulnerabilities wherever they occur. SentinelOne's Singularity platform automatically responds to detected threats by isolating affected devices, blocking malicious processes, or rolling back systems to a safe stat without requiring human intervention.
  • SentinelOne uses machine learning and artificial intelligence to automatically detect, analyze, and respond to threats in real time. This autonomous approach reduces the need for manual intervention and accelerates the time to response, preventing damage from cyber attacks. SentinelOne extends beyond endpoint protection by integrating with other security tools, giving businesses a more holistic view of their security posture across networks, cloud, and identity systems. In the event of ransomware or other destructive attacks, SentinelOne can automatically roll back endpoints to their pre-attack state, minimizing downtime and data loss.

Cons

  • 1.Hash values for adding IOC's were not able to add in bulk 2.Scheduling the AV scanning feature is not readily available which is available a manual scan
  • While SentinelOne interacts with a wide range of security technologies (e.g., SIEM platforms, firewalls), its integration ecosystem may be less extensive than those of larger manufacturers, which might be a constraint for companies with complicated IT systems. In rare situations, older or less capable hardware may suffer from more visible performance concerns as a result of SentinelOne's advanced features. However, this is not usually an issue with newer hardware.
  • SentinelOne Singularity can be relatively expensive compared to traditional antivirus solutions, especially for smaller organizations or those with limited budgets. While SentinelOne supports a wide range of operating systems and platforms, there may be compatibility issues with certain legacy systems or specific configurations.
  • SentinelOne provides a large volume of alerts, they can sometimes lack sufficient context or granularity. For security teams dealing with a high volume of alerts, it can become difficult to quickly assess whether an alert is truly critical or a false positive without deeper investigation.
  • SentinelOne can present a steep learning curve for smaller organizations or teams with limited cybersecurity expertise. Effectively configuring, managing, and interpreting the results from Singularity may require a level of experience that smaller IT teams may lack. SentinelOne can provide significant value through its AI-driven features, it may be cost-prohibitive for smaller companies or those with constrained budgets.

Training

Documentation
Webinars
Live Online
In Person

Training

Documentation
Webinars
Live Online
In Person

Company Information

Microsoft
Founded: 1975
United States
azure.microsoft.com/en-us/products/microsoft-sentinel/

Company Information

SentinelOne
Founded: 2013
United States
www.sentinelone.com

Alternatives

Alternatives

Criminal IP

Criminal IP

AI SPERA
CrowdStrike Falcon

CrowdStrike Falcon

CrowdStrike

Categories

Categories

SIEM Features

Application Security
Behavioral Analytics
Compliance Reporting
Endpoint Management
File Integrity Monitoring
Forensic Analysis
Log Management
Network Monitoring
Real Time Monitoring
Threat Intelligence
User Activity Monitoring

Endpoint Protection Features

Activity Log
Antivirus
Application Security
Behavioral Analytics
Device Management
Encryption
Signature Matching
Web Threat Management
Whitelisting / Blacklisting

Integrations

AXYVOR
Armis Centrix
Azure Marketplace
Blink
Check Point Exposure Management
Code42 Incydr
ContraForce
Daylight
Filigran
Google Digital Risk Protection
Intezer AI SOC
Revelstoke
SOC Prime Platform
SecurityHQ
Arista NDR
Blackpanda
Maltiverse
Recovery Point
Stellar Cyber
Vectra AI

Integrations

AXYVOR
Armis Centrix
Azure Marketplace
Blink
Check Point Exposure Management
Code42 Incydr
ContraForce
Daylight
Filigran
Google Digital Risk Protection
Intezer AI SOC
Revelstoke
SOC Prime Platform
SecurityHQ
Arista NDR
Blackpanda
Maltiverse
Recovery Point
Stellar Cyber
Vectra AI
Claim Microsoft Sentinel and update features and information
Claim Microsoft Sentinel and update features and information
Claim SentinelOne Singularity and update features and information
Claim SentinelOne Singularity and update features and information