Singularity NDR refers to the network detection and response capabilities available within SentinelOne’s broader Singularity security ecosystem. By combining network-related security signals with endpoint, identity, cloud, and third-party telemetry, SentinelOne helps SOC teams detect lateral movement, suspicious communications, command-and-control activity, and other attacks that may not be fully visible from endpoints alone.
Quick Benefits
- Detection of suspicious network activity
- Visibility into lateral movement and attack propagation
- Analysis of east-west and north-south traffic behavior
- Correlation with endpoint, identity, and cloud telemetry
- Detection of command-and-control communication
- Identification of unusual network patterns
- Improved network threat investigation
- Support for third-party NDR integrations
- Centralized incident context within Singularity XDR
- Faster threat containment and response

Singularity NDR At a Glance
What it is: Network Detection and Response capability within the SentinelOne security ecosystem
Product family: SentinelOne Singularity
Parent category: SentinelOne Singularity License
Primary role: Detect, investigate, and respond to suspicious network activity
Security model: NDR integrated with XDR and broader security telemetry
Network visibility: East-west and north-south network activity
Data sources: Network telemetry, endpoints, identity, cloud, third-party NDR platforms, and security integrations
Related SentinelOne capability: Singularity Network Discovery, formerly Ranger
Core capabilities: Network anomaly detection, attack correlation, lateral movement visibility, investigation, and response
Third-party integrations: Supported through the Singularity Marketplace and XDR ecosystem
License Overview
A Singularity NDR License should be considered as part of the wider SentinelOne security architecture rather than as an isolated appliance license. SentinelOne’s current platform combines network-related detections with endpoint and other telemetry through Singularity XDR, while NDR data can also be brought in from supported partner solutions.
That distinction is important for sizing. Traditional NDR platforms are often licensed according to monitored network capacity, sensors, traffic volume, or appliances. In SentinelOne environments, the commercial scope may instead depend on the underlying Singularity package, connected security sources, network integrations, data ingestion, and any third-party NDR product being used.
SentinelOne also offers Singularity Network Discovery, formerly Ranger, for discovering and controlling IP-enabled devices without requiring dedicated network hardware or SPAN/TAP infrastructure. Network Discovery uses selected SentinelOne agents to observe and map local networks, identify unmanaged devices, and block unauthorized communication with managed endpoints. For buyers, the first decision is therefore architectural: determine whether the requirement is true network traffic detection, asset discovery and network control, broader XDR correlation, or a combination of these capabilities.
Product Overview
Network Detection Beyond Endpoint Telemetry
Endpoint security provides deep visibility into managed systems, but attackers do not always stay on protected endpoints.
They may scan internal networks, communicate with command-and-control infrastructure, move laterally, or interact with unmanaged devices.
NDR adds another perspective by examining network behavior. SentinelOne describes NDR as technology that looks for suspicious patterns, anomalies, and attack behaviors in network traffic and can identify activity such as lateral movement, data exfiltration, DNS tunneling, hidden beaconing, and unusual protocol use.
Cross-Layer Correlation Through Singularity XDR
Network alerts become more valuable when they are connected to endpoint and identity context.
SentinelOne Singularity XDR is designed to ingest and normalize data from multiple sources and correlate signals across endpoint, identity, cloud, email, network, and third-party tools. This gives analysts a wider view of the attack instead of forcing them to switch between disconnected consoles.
For example, a suspicious connection is more meaningful when analysts can see which endpoint initiated it, which user was logged in, whether that endpoint also generated behavioral alerts, and whether similar activity appeared elsewhere.
Lateral Movement and Command-and-Control Detection
Network behavior often exposes attack stages that endpoint-only monitoring may not show clearly.
NDR can help identify systems communicating unexpectedly, scanning internal resources, connecting repeatedly to unusual destinations, or transmitting abnormal volumes of information.
SentinelOne specifically describes NDR use cases including lateral movement, command-and-control callbacks, data exfiltration, unauthorized access, DNS tunneling, and anomalous protocols.
These detections provide SOC analysts with additional evidence during complex investigations.
Options and Licensing Models
| Licensing Option | Description | Suitable For |
|---|---|---|
| Singularity XDR Integration | Correlates network security data with endpoint, identity, cloud, and third-party telemetry | SOC teams requiring cross-layer investigations |
| Third-Party NDR Integration | Brings detections from supported NDR platforms into the Singularity ecosystem | Enterprises with existing NDR investments |
| Singularity Network Discovery | Discovers unmanaged devices and provides network visibility without dedicated scanning hardware | Organizations needing asset discovery and rogue-device control |
| Security Data Ingestion | Adds network or third-party security telemetry for investigation and correlation | Large SOC environments |
| Extended Data Retention | Preserves security telemetry for longer investigation windows | Threat hunting and forensic use cases |
| Managed Detection Services | Adds SentinelOne or partner-led monitoring and investigation | Organizations requiring external SOC support |
| Multi-Year Subscription | Provides longer-term platform coverage | Enterprise security programs |
The exact commercial configuration should be confirmed against the current SentinelOne package and any third-party NDR platform being integrated, because SentinelOne does not currently publish a single standalone “Singularity NDR” package with a universal traffic-based price.
Features and Benefits
The main value of Singularity NDR is context. Network activity by itself may reveal an unusual connection, but endpoint and identity telemetry can explain what caused it and whether it is part of a broader attack.
This cross-layer approach can shorten investigations considerably. Analysts do not need to manually compare a network alert with several endpoint consoles and identity systems before understanding the scope of the incident.
Network visibility also reduces blind spots around unmanaged systems. Singularity Network Discovery can identify devices that do not have the SentinelOne agent installed, which helps security teams locate deployment gaps and understand what is actually connected to sensitive network segments.
For organizations already using a dedicated NDR platform, SentinelOne’s integration model offers another advantage: existing network detections can contribute to XDR investigations without requiring the organization to discard its current network security technology.
Compatibility and Requirements
Before planning Singularity NDR capabilities, organizations should document their network and security architecture.
Important considerations include:
- Average and peak network traffic
- Data center and branch topology
- East-west and north-south visibility requirements
- Existing NDR platforms
- Network telemetry sources
- Endpoint coverage
- Cloud network environments
- Identity integrations
- Data retention requirements
- SIEM/XDR workflows
- Unmanaged and IoT device populations
Activation and Deployment
Deployment depends on which network security capability is being used.
Typical steps include:
- Activate the relevant Singularity subscription
- Identify network visibility requirements
- Connect supported network or NDR data sources
- Configure XDR integrations
- Enable Network Discovery where required
- Define discovery or monitoring policies
- Validate network alerts and asset visibility
- Test investigation and containment workflows
Organizations with an existing NDR platform should validate data mappings and alert enrichment before moving investigations into production workflows.
Pricing and Quote Process
Pricing for a Singularity NDR License cannot be accurately calculated from endpoint quantity alone. The quote should reflect which SentinelOne components and external network security capabilities are actually required.
Before requesting pricing, define:
- Existing Singularity package
- Number of protected endpoints
- Network locations and subnets
- Current NDR technology, if any
- Required network telemetry sources
- XDR integration requirements
- Security data ingestion volume
- Retention period
- Network Discovery requirements
- MDR or SOC service requirements
- Subscription duration
SentinelOne pricing depends on your security solution, endpoint coverage, XDR capabilities, threat detection requirements, deployment model, license term, and support needs.
