We moved from CrowdStrike to SentinelOne about six months ago, mostly for cost reasons. The sales pitch was strong on "autonomous" everything. I handle our Salesforce and Zendesk security stacks, so I was curious to see how it compared.
The initial deployment was smoother than I expected, but the console feels cluttered. I'm still not sure if we're using it to its full potential. The real surprise has been the resource usage—it's noticeably lighter on our endpoints than CrowdStrike was. But I find the reporting less intuitive for quick, ad-hoc requests. Has anyone else made this switch and found a better way to structure the policies or pull simple threat reports? The "Storyline" feature is interesting, but it feels like overkill for most of our incidents.
I'm a senior sysadmin at a 300-person ecommerce shop. We've run both platforms in the last three years - SentinelOne in production now for about 18 months, after a 2-year stint with CrowdStrike.
My comparison based on our switch:
1. **Price & Commitment**: SentinelOne came in at ~40% less for us on a 3-year term. CrowdStrike's premium was real, but their quote was for their full suite (NGAV, EDR, Falcon Complete). S1's competitive entry point is their Core platform, which is what you likely have.
2. **Agent Resource Impact**: This was the main win. Our fleet is mixed (Mac & Windows). S1's agent consistently uses 30-50MB RAM and <1% CPU on idle. CrowdStrike was often 80, spike, 120MB+ and we'd see 2-5% background scans.
3. **Console & Daily Use**: CrowdStrike's UI is cleaner for triage. S1's feels noisy. For simple reports, I live in the 'Threats' view and export from there. Ignore Storyline for day-to-day; it's for deep forensics. Their policy structure is flat - you can't nest them, which is a pain if you have many device groups.
4. **Support & Proactive Mgmt**: Here's where cost shows. With CrowdStrike we had a dedicated tech. With S1, it's ticket-based and slower. For a team that's stretched, the hands-off 'Complete' service from CrowdStrike might be worth the premium if you lack 24/7 coverage.
I'd pick SentinelOne if you have a dedicated security person who can tune policies and handle the console, and the budget is tight. I'd go back to CrowdStrike if you're a smaller team wanting that fully-managed, "call us when the light turns red" experience. To make a clean call, tell us your team size and if you have a dedicated SOC analyst.
—b
The "dedicated tech" from CrowdStrike is just a glorified sales retention tool. You get that warm feeling until renewal time, then they're nowhere to be found while the price jumps 30%.
That ticket-based support lag with S1 is the real cost. An extra hour of internal labor per incident eats that 40% list price savings pretty fast.
Your stack is too complicated.