SentinelOne Dealer and Integration ConsultantsSentinelOne's Singularity product line is a subscription-based, cloud-centric threat management stack that includes AI software and professional services to deliver comprehensive endpoint detection and response (Singularity Control and Complete) and managed detection and response (Singularity Complete with Vigilance MDR). SentinelOne's low-profile software agents can be installed in a few minutes to protect endpoints against modern threats such as ransomware, familiar and new malware, trojan viruses, hacking tools, memory exploits, malicious scripts, destructive macros, and living-off-the-land (LotL) attacks. SentinelOne software agents are available for Microsoft Windows, macOS, Linux, and Kubernetes powered endpoints. Supported form factors include physical, virtual, VDI desktops, hybrid data centers, and cloud service providers. Because SentinelOne agents operate autonomously, they can provide advanced behavior-based protection in real time even when endpoints are disconnected from the cloud.

Progent is a SentinelOne Partner and dealer and oversees thousands of endpoints secured by SentinelOne Singularity technology. SentinelOne is invariably the initial EDR response tool activated by Progent to gain control and visibility of a client's system at the outset of a ransomware emergency. SentinelOne is in addition the key EDR software behind Progent's Active Security Monitoring managed services. SentinelOne was ranked as a leading visionary in Gartner's 2022 Magic Quadrant for Endpoint Protection Platforms and attained the most analytic detections in real-time during the 2022 MITRE ATT&CK Phase 4 Evaluation. Gartner concludes, "This reaffirms its (SentinelOne's) ability to detect all attacks and provide full details of the techniques and tactics used." SentinelOne also outscored all competition for each use scenario in Gartner's evaluation of Critical Capabilities for Endpoint Protection Platforms (EPPs).

Singularity Bundles for SentinelOne Endpoint Security
SentinelOne's Singularity product line has several levels of endpoint security product packages delivered as a global SaaS solution that features high availability, centralized policy management, AI powered malware intelligence, rapid restoration, and an information-driven dashboard for cyberthreat analytics. Packages include Control for advanced management, Complete for automated root cause analysis, and Complete with Vigilance MDR for 24/7 advanced monitoring and response. The feature sets are incremental. Control and Complete each include all the features of the tier beneath it. Pricing begins at $10 for each endpoint per month for smaller customers with substantial discounts for larger deployments. There is no minimum endpoint count.

The SentinelOne Control Package
The SentinelOne Control Package is the base software and is 100% maintained by the client. For some examples: Endpoint agents need to be updated in the SentinelOne portal, allow rules need to be set, exclusions need to be made, blacklists should be created, threats must be responded to, and many other day-to-day activities that someone in your organization needs to manage and maintain. SentinelOne is just like any other security product in that it has frequent updates to keep its defenses current. Progent can assist with or directly handle these items, but there is additional time and materials billing for all services performed.

With the Control Package you manage your own portal and while Progent and SentinelOne personnel are monitoring and or receiving alerts of serious threats in your environment, we have no authorization to do any work in your environment and will only do best efforts to alert you in case of a serious threat.

Major Features of the SentinelOne Control Package include:

  • Endpoint Prevention (EPP) to block a broad range of malware, Trojans, hacking tools, and ransomware before they can get a foothold
  • ActiveEDR Basic for Endpoint Detection and Response operates in real-time even without cloud access. ActiveEDR detects highly sophisticated malware, script misuse and other fileless attacks as they attempt to do compromise your network.
  • ActiveEDR Recovery gets users up and running quickly and includes full remediation plus rollback for all non-legacy versions of Microsoft Windows.
  • Endpoint Control for Policy-based control of all USB and Bluetooth peripherals (Windows, Mac)
  • Firewall Control for Policy-based control of network connectivity to and from assets, including location awareness (Win, Mac, Linux)
  • Vulnerability Management, along with Application Inventory, for details of 3rd party apps that have known security gaps mapped to the MITRE Common Vulnerabilities and Exposures (CVE) security dictionary
  • Full Secure Remote Shell capability for direct endpoint connection by incident responders and forensics team
  • Autonomous SentinelOne agent Storyline Engine
  • Simultaneous Static AI and SentinelOne Cloud Intelligence file-based attack prevention
  • Behavioral AI fileless incursion detection
  • Autonomous Threat, Remediation, and Rollback Response
  • Quarantine device from network, Incident Analysis, Agent Anti-tamper, App inventory
  • Rogue endpoint discovery
The SentinelOne Singularity Complete Package
The SentinelOne Complete Package includes all the core capabilities and operates with the extra functions of the Control package and adds single-agent enterprise-grade endpoint detection and response (EDR), hunting for all endpoints, cloud, and IoT. The bundle eliminates substantial time for security admins, security operations center analysts, cyberthreat hunters, and incident responders by automatically correlating incidents and mapping it into the MITRE ATT&CK framework to determine root causes. The SentinelOne Complete Package offers an advanced EDR feature set:
  • Co-Managed environment with Progent being sent alerts and notices of all activities in your environment. Customers are responsible for resolving threats in their environment and optional help time and material is available from Progent's security experts
  • ActiveEDR Advanced provides visibility of all benign data.
  • ActiveEDR Advanced provides high-level threat hunting. SentinelOne stands out by the the ease-of-use characterized by the active quality of the solution in autonomously responding to threats.
  • Storyline technology for Automated Forensics and quick root cause analysis. All OS storylines are automatically contextualized with SentinelOne’s proprietary TrueContext technology, streamlining analysts' complex job of event correlation so they can get to root causes with reduced MTTR.
  • Storyline Active Response (STAR) mitigates zero-day threats with custom detection and hunting rules.
  • Deep visibility Storyline Pivot and Hunt technology by MITRE ATT&CK technique
  • EDR Hunting Data retention from 14 days standard to 365 days optional
  • Timelines, file fetch, file integrity monitoring, sandbox integrations
  • Other response alternatives are available and customized to your requirements. Includes one hour of training in advanced features and day-to-day management of the SentinelOne portal. During this training, Progent will demonstrate the specification of Exclusions, Blocklists, Mitigation, Agent Updates, Notifications, Client Reports, Application Features, Activity Logs and UI configuration Alerts.
Options for the SentinelOne Complete Package package include adding software-defined network discovery and aggregated active/passive device mapping through SentinelOne's Vigilance with MDR package plus elimination of agent installation gaps with configurable job automation. Progent also offers monthly client portal checks and threat response guidance.

Complete with Vigilance Respond Managed Detection and Response Services
Vigilance Respond and Vigilance Respond Pro are optional MDR programs for subscribers to SentinelOne's Singularity Complete package. These bundles include full 24x7x365 incident response delivered by Tier-1, Tier-2, and Tier-3 cybersecurity experts. Vigilance Respond subscriptions include confirmation of cyberthreats, event prioritization, false positive management and console cleanup, proactive threat deactivation, thorough reporting, SLAs, and escalation back to the customer's cybersecurity team.

Vigilance MDR analysts classify detected threat alerts according to a threat-handling hierarchy going from Benign to Malicious Urgent. This classification determines how the Vigilance analyst manages the detected threat. There are five classes of threats and associated responses. Most alerts do not require action by the client.

Benign Alert - False Positive
Vigilance takes care of the issue and annotates the SentinelOne console. For single False Positive alerts, no additional responses or notifications are required. For repeated False Positive alerts, Vigilance will escalate the issue to the customer to offer or approve a proper exclusion or agent update as required.

Malicious Alert - True Positive Non-Urgent, Potentially unwanted Program
Vigilance responds to ensure the threat is blocklisted, resolved, and annotated. Typically, no alert will be transmitted to the client unless the threat calls for follow up activity.

Malicious Alert - True Positive / No Action Necessary
Vigilance takes proper actions including remediation to ensure the threat is quarantined. Once the SentinelOne analyst confirms the threat is eliminated, the analyst will send a confirmation alert to the customer.

Malicious Alert - True Positive Non-Urgent / Action Necessary
Vigilance performs appropriate actions including remediation to make sure the threat is quarantined. Once the SentinelOne analyst confirms the threat is eliminated, the analyst will send a confirmation alert to the client. Follow-up procedures such as re-imaging may be necessary in certain cases.

Malicious Alert - True Positive Urgent / Action Necessary
Vigilance may react aggressively in serious breach cases including taking agent remediation actions and isolating compromised network devices to stall the attack and block additional lateral movement and spread. The analyst will send a proactive alert apprising the customer of the situation and request immediate response.

In addition to including all the features of SentinelOne Control and SentinelOne Complete, SentinelOne Complete with Vigilance MDR adds round-the-clock Monitoring with Immediate Threat Response, Remote Script Orchestration, and Ranger:

  • Fully Co-Managed Environment with Progent seeing warnings and notifications of all threats and activities in your environment and combined SOC response, delivering 3 levels of 24x7x365 Detection and Response. All threats are neutralized and responded to in near real-time. Further remediation options following threat mitigation are offered and customized to your organization's needs.
  • Remote Script Orchestration enables enterprises to send scripts to one machine, a few hundred machines, or even millions of machines, to respond to current and future cyberattacks instantly. Security Teams can send tailored scripts or choose from a broad selection of jobs – ranging from incident response to forensics artifact collection and even IT administration. In conjunction with SentinelOne Storyline Active Response, analysts benefit from automated workflows that promote incident response to the next level.
  • Ranger allows unmatched visibility into your system. Ranger is network-efficient by intelligently designating a few SentinelOne agents per subnet to undertake network mapping missions. Selected "Rangers" passively listen for network broadcast data including ARP, DHCP, and other network observances. Admins can modify current scan policies and select multiple IP Protocols for learning including ICMP, SNMP, UDP, TCP, SMB, and more. Rangers correlate all collected information within the backend to characterize known and unfamiliar devices. Ranger device inventories reveal what is attached to your environment, where they are connected, and which protocols the devices listen on. Ranger enables you to expose and eliminate SentinelOne Agent deployment gaps with Ranger Deploy, a peer-to-peer deployment (Windows, Mac, Linux). Ranger enables you to determine how unknown devices communicate with managed hosts and quarantine suspicious devices from managed devices with a click.
Includes one hour of training in advanced features and day-to-day management of the SentinelOne portal. During this time, Progent will train customers in the creation of Exclusions, Blocklists, Mitigation, Agent Updates, Notifications, Client Reports, Application Features, Activity Logs and UI configuration Alerts. Progent can provide tailored extra instruction for your company's requirements on a time and materials basis.

Download Progent's SentinelOne Singularity Packages Datasheets
See datasheets describing Progent's SentinelOne Singularity packages:

The Progent Advantage
Progent's team of more than 150 consultants includes certified experts in every facet of network technology related to small and mid-size organizations. With this scope of expertise, Progent can be your one-stop source for building and managing a comprehensive cybersecurity environment that delivers immediate business value. In addition to the endpoint security available from SentinelOne products and services, Progent offers a variety of managed services and specially-priced IT support packages designed to assist small and mid-size businesses to plan, deploy, test, and manage networks that deliver enterprise-level cybersecurity and low total cost of ownership.

Progent offers in-depth experience with all the endpoint devices, servers and virtual machines that can be secured by SentinelOne products. Progent can provide services that include Windows 11 planning and migration consulting, Windows 10 integration, Linux support, Mac OS X and macOS consulting, iPhone and iPad support, Android consulting, Windows Server 2022 migration expertise, Windows Server 2019 migration consulting, Hyper-V virtualization consulting, and VMware vSphere configuration consulting.

For single-click or manual rollback, Progent's Windows Server experts can help you to configure Windows Volume Shadow Copy Service (VSS). Progent also offers remote and on premises access to certified Cisco CCIE consultants to help you to design, protect or optimize your infrastructure. If your network relies on cloud resources, Progent offers the guidance of Microsoft Azure consultants, Amazon AWS consultants, and Google Cloud integration experts.

Contact Progent about SentinelOne Sales and Configuration Services
To learn more about how Progent can help you to buy or integrate SentinelOne products, call 1-800-993-9400 or see Contact Progent.



An index of content::





  • © 2002-2026 Progent Corporation. All rights reserved.