SentinelOne Wayfinder MDR

MDR · XDR

SentinelOne Wayfinder MDR, formerly reflected in market listings as Vigilance Respond, is a 24/7 managed detection and response service for buyers using the SentinelOne Singularity platform. After an alert, SentinelOne analysts and platform automation triage, investigate, document, and can contain or mitigate threats in the approved Singularity scope, while the buyer still owns platform licensing, telemetry coverage, response authorization, business remediation, and recovery.

What they do
Contain threats
Works with
Their platform
Built for
Mid-Market / Enterprise
Price
Quote-based
Best for
Organizations already committed to SentinelOne Singularity Endpoint, Cloud or Identity

They cover

  • Endpoints
  • Cloud Workloads
  • Identity & Access
  • Email
  • Network
  • SaaS Applications

Your team still owns

  • Buying, deploying and maintaining SentinelOne Singularity modules and covered agents
  • Connecting endpoint, cloud, identity and supported third-party telemetry needed for investigation
  • Approving which containment, mitigation and automated response actions SentinelOne may take
  • Remediating business systems, restoring service and handling internal recovery decisions
  • Confirming whether Threat Hunting, MDR Essentials, MDR Elite or IRR is the contracted tier

Pricing

Line Figure
Published price Quote-based
Billing model Per-endpoint, Custom
Contract Not published
Onboarding Not published

Tradeoffs

Works well

  • Strong fit for buyers already standardized on SentinelOne telemetry and controls
  • Official sources support containment and mitigation, not only alert forwarding
  • Current Wayfinder packaging adds Google Threat Intelligence and clearer MDR Essentials versus MDR Elite tiers
  • Public review volume on Gartner is broader than many MDR services

Watch out for

  • Not a standalone, vendor-neutral SOC service for teams using another primary EDR or SIEM
  • Public pricing is quote-based and legacy reseller SKUs do not show universal list prices
  • Coverage outside SentinelOne endpoint, cloud and identity telemetry depends on supported integrations and contract scope
  • Public customer evidence includes some complaints about missed detections, custom detection handling and escalation quality

What buyers say

Alert noise

Not assessed

Transparency

Not assessed

Customers like

  • Gartner reviewers cite communication, implementation support, accessible subject-matter experts and autonomous response
  • G2 reviewers describe reduced staffing burden and support value, but from a small sample
  • Public review surfaces confirm the service is evaluated as MDR rather than only endpoint software

Watch out for

  • G2 has only a small number of Vigilance Respond reviews
  • Reddit evidence includes complaints about missed detections, custom-rule handling and support responsiveness
  • Review evidence mixes current Wayfinder naming with older Vigilance Respond deployments

Reputation reads from public reviews, not vendor-published numbers.

Ask before buying

  1. Which Wayfinder tier maps to our quote, and is it replacing a legacy Vigilance Respond or Respond Pro SKU?
  2. Which response actions can SentinelOne run automatically, which need approval and which remain our responsibility?
  3. What telemetry sources beyond SentinelOne Endpoint are included, and which are merely supported integrations?

Integrations

SentinelOne Singularity PlatformSentinelOne Singularity EndpointSentinelOne Singularity CloudSentinelOne Singularity IdentityGoogle Threat IntelligencePurple AISingularity HyperautomationSupported third-party telemetry

Editorial notes

Why contain threats

Official Wayfinder MDR pages support 24/7 monitoring, triage, managed response and mitigation, plus containment and risk-tailored response actions. Older Vigilance service definitions say console threats are reviewed, acted upon, documented and fully mitigated or escalated when needed, so the lane goes beyond advice-only MDR.

Why not co-managed SOC

The service adds analyst operations, threat hunting and advisory elements, but public evidence centers on SentinelOne running MDR over its own Singularity platform. It does not show a shared SIEM/SOC operating model where the buyer and provider co-own daily SOC workflow across a broad stack.

Why not run the SOC

Wayfinder MDR reduces monitoring, triage, investigation and containment work, but the buyer still owns platform deployment, telemetry coverage, authorization rules, business remediation and recovery. Public sources do not support saying SentinelOne replaces the whole SOC by default.

Pricing boundary

Current official pages do not publish numeric Wayfinder MDR pricing. A CDW legacy Respond Pro SKU confirms a per-endpoint one-year subscription path but routes to Request Pricing, so the profile removed stale endpoint-dollar ranges and treats pricing as quote-based.

Rebrand boundary

SentinelOne introduced Wayfinder TDR in November 2025 with MDR Essentials and MDR Elite. Gartner redirects the old Vigilance Respond review URL to SentinelOne Wayfinder MDR, while G2 and reseller pages still use Vigilance Respond naming, so the profile keeps the legacy slug but uses the current service name.

Questions

Is SentinelOne Vigilance still the current MDR name?
SentinelOne now markets the managed services portfolio as Wayfinder Threat Detection & Response, including Wayfinder MDR Essentials and Wayfinder MDR Elite. Gartner redirects the old Vigilance Respond review page to Wayfinder MDR, while some reseller and review pages still use the Vigilance name.
Does SentinelOne Wayfinder MDR contain threats?
Yes, within the contracted and approved SentinelOne scope. Official Wayfinder material supports managed response, mitigation and risk-tailored containment actions, and older Vigilance material says threats are reviewed, acted upon, documented and escalated when needed.
Is SentinelOne Wayfinder MDR pricing public?
No universal public list price was found. Reseller pages for legacy Vigilance Respond Pro show per-endpoint subscription SKUs but route buyers to request pricing, so buyers should get a current quote from SentinelOne or their reseller.