Resources

Threat intelligence, research, and everything you need to understand preemptive security.

All resources

Press Enter to search or Esc to close

Vendor Comparison

PacketViper vs. SentinelOne Singularity Hologram

A dated, source-cited comparison that starts with an accurate account of Hologram’s current product status.

Last reviewed: October 2026. Vendor information was accessed on 2026-10-09 from the public sources listed at the end of this page. Vendor capabilities change; confirm current details with each vendor. Where a fact could not be found in public material, this page says “Not publicly documented”.

Product status: is Singularity Hologram still current?

Singularity Hologram is SentinelOne’s network deception product, introduced after SentinelOne completed its acquisition of Attivo Networks on May 4, 2022.[4] What public sources show as of 2026-10-09:

SentinelOne data sheets from 2022 and 2024 describe Hologram as a component of the Singularity platform that integrates with Singularity Identity.[1][2]
SentinelOne’s former Hologram product address (/platform/singularity-hologram/) now redirects to the Singularity Identity page, which markets “Identity Deception” inside a single agent and does not name Hologram.[3]
We found no public end-of-sale or end-of-life announcement for Hologram.

Summary

SentinelOne’s deception capability comes in two forms in public material: Hologram network decoys (hardware or virtual decoys mimicking operating systems, applications, ICS and IoT)[1] and identity deception delivered through the Singularity Identity agent (decoys and credentials that expose reconnaissance).[3] PacketViper is a network-layer inline platform. The two address different parts of the problem and differ mainly on where the control sits (endpoint and identity versus the network path) and whether the system enforces inline.

Comparison

DimensionSentinelOne Singularity Hologram / Identity deceptionPacketViper
Deception approachHologram: high-interaction decoys that mimic production operating systems, applications, data, ICS, IoT and cloud functions.[1] Singularity Identity: “Plant decoys and credentials that expose reconnaissance early”.[3]Deceptive responders on the network path, delivered as one capability within AMTD.
AMTDNot publicly documented in the sources reviewed.Yes. Network-layer AMTD continuously changes what an attacker can map. An optional AMTD Agent covers Windows and Linux hosts.
Inline enforcementHologram’s data sheet describes decoys that detect and alert, with attack visualization and playbooks. Singularity Identity describes automated containment workflows between identity and endpoint.[1][3] Inline network enforcement is Not publicly documented.Yes. Enforcement runs in the packet path (block, redirect, throttle or tarpit).
AgentlessHologram network decoys are hardware or virtual decoys.[1] Identity deception runs on the Singularity agent: “a single agent and console”.[3]Yes for the network platform: nothing is installed on protected devices. The AMTD Agent is a separate, optional endpoint component.
OT protocol supportThe 2022 data sheet lists “Decoy ICS-SCADA industrial control systems”.[1] Specific OT protocols are Not publicly documented in the sources reviewed.Native, inline support for Modbus, DNP3, BACnet and S7COMM, with more than 20 OT protocols recognized.
Deployment modelHologram: hardware and virtual decoys managed from a Hologram Central Manager, with cloud implementations named as Google Cloud, AWS, Azure and OpenStack (2022 data sheet).[1][3] Identity deception: part of the Singularity platform.Inline nodes (bridge mode) on commodity server hardware, managed as a federation. Nodes keep enforcing when disconnected from central management.

When to choose SentinelOne

You already run the SentinelOne Singularity platform and want identity and endpoint deception under the same agent and console.
Your concern is credential misuse and Active Directory attack paths; SentinelOne positions Singularity Identity around that problem.
You want deception that shares telemetry and containment workflows with your endpoint detection and response deployment.

When to choose PacketViper

You need protection at the network layer for devices that cannot run an agent, such as PLCs, RTUs and legacy hosts.
You want enforcement inline in the packet path rather than containment workflows that depend on an endpoint agent.
You want AMTD: a network surface that keeps changing for every scanner and reconnaissance tool that touches it.
You need nodes that keep enforcing in air-gapped or intermittently connected sites.

Can they be used together?

Yes in principle: endpoint and identity deception on hosts, and AMTD with inline enforcement on the network, cover different layers. A direct integration between the two products is Not publicly documented.

PacketViper statements on this page come from PacketViper’s own published pages: Deception and AMTD, AMTD Agent, Performance Benchmarks and PacketViper vs Claroty.

Sources

  1. SentinelOne, Singularity Hologram data sheet (PDF, code S1-DS_SINGULARITY_HOLOGRAM-05032022, (c) 2022; reseller-hosted copy) Accessed 2026-10-09.
  2. SentinelOne, Singularity Identity data sheet (PDF, dated 07/01/24 in the file name; reseller-hosted copy) Accessed 2026-10-09.
  3. SentinelOne, Singularity Identity platform page (current; the former /platform/singularity-hologram/ address redirects here) Accessed 2026-10-09.
  4. SentinelOne, “SentinelOne Completes Acquisition of Attivo Networks” (press release, May 4, 2022) Accessed 2026-10-09.
Is SentinelOne Singularity Hologram still sold?

Public sources are not conclusive. SentinelOne’s former Hologram product address now redirects to its Singularity Identity page, which markets identity deception, and we found no public end-of-sale notice. Confirm current availability with SentinelOne.

What was Singularity Hologram?

SentinelOne’s network deception product, introduced after its May 2022 acquisition of Attivo Networks. Its data sheet describes decoys that mimic operating systems, applications, ICS, IoT and cloud functions.

Does Singularity Hologram work without agents?

The 2022 data sheet describes hardware and virtual network decoys. SentinelOne’s identity deception runs on the Singularity agent.

How is PacketViper different from SentinelOne deception?

PacketViper works at the network layer without agents on protected devices, combines AMTD, deception and inline enforcement, and keeps enforcing when disconnected from central management. SentinelOne’s deception is delivered through decoys and the Singularity endpoint agent.

See inline enforcement in your environment

Book a demonstration of PacketViper’s AMTD and inline enforcement, or request a proof of concept.