Likelihood to Recommend I'm not sure about pricing but I have heard from larger companies that it was not very accessible because of their size. We are a small company and we also utilize a SIEM which helped offset costs right off the bat. I think it makes 100% sense for IT departments that don't have enough staff to monitor their environment in depth.
Read full review Cb Protect is best suited somewhere where you want to maximize the lockdown of workstations. So moving past no local admin rights to blocking specific applications and peripherals. The idea would be to have a list of applications you want to run, and then anything else is not able to be used. As stated prior, if you have a very fluid environment where you are having all sorts of new applications installed frequently (I feel for you!!) this is still do-able, but it misses the general idea. I think especially in environments that are more sensitive to new applications, like banks, healthcare systems etc, this is a good fit. The ability to look at application levels, drift, unapproved software etc is very useful.
Read full review Pros SentinelOne provides excellent protection against known and unknown attacks to our endpoints. The recovery option provides a fast, first line of defense against ransomware and other system damaging attacks. SentinelOne requires minimal administrative support making it a very cost effective and efficient solution. Read full review Controls file writes, executions of the scripts Defends from process injections, memory protection Visibility and lock down posibilities Read full review Cons Possibly for compatibility with legacy Windows OS's and non Windows OS's. Some settings are greyed out and unable to change but I believe this is to protect you from making a bad configuration change. Could do better with reporting at the base level subscription. Read full review Perhaps more specific training. Read full review Likelihood to Renew Reliable for simple installation and above all efficient
Read full review Usability Compared to all the other major players, SentinelOne is truly hands off. One installed, the tool is able to manage all the major threats on my endpoints without intervention. The biggest thing the IT Dept has to do now is just clear the incidents after SentinelOne has dealt with them. Every other tool I have used requires significantly more effort to maintain.
Read full review Support Rating Their support is good and quick to respond. The one issue we faced was when a non-protection issue arose there was a lot of dancing around trying to figure things out. This was frustrating as it took significantly longer to figure out issues. Lots of repetitive log gathers, screen caps, uninstalls that never seemed to resolve issues. Eventually, the product would be updated and the issue seemed to be resolved, but seemed to be the only solution.
Read full review Alternatives Considered Webroot is a great product but did not provide the versatility that we really were desiring. It allowed to us to centrally manage, but required policy-based management, and not the endpoint detail we wanted. SentinelOne's central management provides a variety of options for us to deploy and manage.
Read full review The big difference between Protect and
Barkly /AMP is how exactly it goes about what it's doing. Protect is application whitelisting and program reputation. So the way it's protecting you is using a proprietary reputation service, and hash values to identify applications, and then hitting a list of whitelisted programs to decide if you are able to run that or not, based on the policy you are in. There is a LOT of value in that. We actually are working on transitioning to Cisco Advanced Malware Protection (AMP). The main reason is cost (about the same cost as Cb Protect, but with (most of) the featureset of all 3 Carbon Black products for less than 1/3 of the total spend. AMP works differently, looking at a reputation service powered by Cisco's Talos cloud. You don't really have application whitelisting, but that also reduces how many "requests" you get for applications. So I'll have to find a different way to do whitelisting and USB blocking and the like, but I'm getting more visibility across my network and also built in antivirus (TETRA engine - ClamAV with some work).
Barkly is an add that we are looking to put in as it looks at behavior of programs. So specifically it watches for privilege elevation and the like. Thus far all the big name problem children (WannaCry, other ransomware problems) have been caught natively in
Barkly day 0.
Read full review Return on Investment SentinelOne has already proved its value by stopping attacks that would have gone otherwise unnoticed until much later in their infection process. The Vigilance team has provided quick response to threats that were not easily contained via the automated response SentinelOne's agents provide. This has given us a significant piece of mind. Read full review App Control can ensure Continuous Compliance. Solution can reduce expenses on different security software. Nowadays Zero Trust approach is very important for any organization and Application control is one of the main parts of it. Read full review ScreenShots SentinelOne Singularity Screenshots