SentinelOne offers ActiveEDR which is delivered through a single agent, single codebase, single console architecture. ActiveEDR enables security teams to rapidly understand the reason behind the threats and responds automatically without any dependence on cloud resources. It can automatically mitigate threats and protect against advanced attacks.
Some of the features of SentinelOne:
Protection
- Independent multi-layered prevention that covers all attack paths, even when offline
- Artificial Intelligence technology that does not depend on signatures and does not need daily/weekly updates or recurring scans
- Remediation of the full context of malicious activity, reducing the required time and cost in fixing infected devices
- Providing the correct forensics to enable knowing where the threat is from and the type of threat
Visibility
- Cross-platform visibility into endpoints
- Visibility into encrypted traffic
- Visibility on all applications and running processes
Simplicity
- One lightweight agent offers the following functionality –
○ EPP
○ EDR
○ HIPS
○ File Integrity Monitoring ○ Vulnerability/Risk Management
- Managed console hosted in the cloud, on-premise, or in a hybrid model Higher efficacy, lower system impact, and an optimal end-user experience
Automation
- The SentinelOne platform is developed with an API-first approach and it can combine with SonicWall, Fortinet, Splunk, QRadar, LogRhythm, Demisto, Phantom, and Alexa.
- Automatically separate infected devices and protect the remaining of the endpoint estate
- Retrieve files in the highly unlikely case of ransomware.