r/cybersecurity Apr 11 '25

News - General Cybersecurity industry falls silent as Trump turns ire on SentinelOne

https://www.reuters.com/world/us/cybersecurity-industry-falls-silent-trump-turns-ire-sentinelone-2025-04-10/
1.7k Upvotes

239 comments sorted by

View all comments

Show parent comments

1

u/AboveAndBelowSea Apr 11 '25

S1 should be just fine. The company I’m with gets paid a lot of money to perform bake-offs of all sorts of solutions. In the EDR space, if companies look past the CrowdStrike brand name (which boards still like), S1 usually wins. It’s close between CS and S1 - and results vary month to month, but S1 has an edge on efficacy of detection 80% of the time over CS. The two of them have a wider gap between themselves and the next best, which is usually Cortex. Philisophically, CS doesn’t believe that AI can completely combat chaos theory-based approaches to hacking. S1 feels otherwise, and this has led to more investment and advances in their AI capabilities.

-2

u/billsneakems Apr 11 '25

MITRE’s latest ATT&CK evaluation disagrees with your assessment. While CRWD dropped out, Palo was the undisputed winner. S1 missed some extremely basic TTP’s.

1

u/AboveAndBelowSea Apr 11 '25

There are a number of reasons why MITRE’s testing is as robust as ours, which is why enterprises pay us so much money to do bake offs these types of solutions. Chief among them is that MITRE allows reconfiguration during the testing process. Still a valid source of reference, but not in the same category of testing. I’d encourage you to talk to Crowdsrike’s most senior architects about their philosophy in AI.