PacketViper vs. SentinelOne Singularity Hologram
A dated, source-cited comparison that starts with an accurate account of Hologram’s current product status.
Last reviewed: October 2026. Vendor information was accessed on 2026-10-09 from the public sources listed at the end of this page. Vendor capabilities change; confirm current details with each vendor. Where a fact could not be found in public material, this page says “Not publicly documented”.
Product status: is Singularity Hologram still current?
Singularity Hologram is SentinelOne’s network deception product, introduced after SentinelOne completed its acquisition of Attivo Networks on May 4, 2022.[4] What public sources show as of 2026-10-09:
Summary
SentinelOne’s deception capability comes in two forms in public material: Hologram network decoys (hardware or virtual decoys mimicking operating systems, applications, ICS and IoT)[1] and identity deception delivered through the Singularity Identity agent (decoys and credentials that expose reconnaissance).[3] PacketViper is a network-layer inline platform. The two address different parts of the problem and differ mainly on where the control sits (endpoint and identity versus the network path) and whether the system enforces inline.
Comparison
| Dimension | SentinelOne Singularity Hologram / Identity deception | PacketViper |
|---|---|---|
| Deception approach | Hologram: high-interaction decoys that mimic production operating systems, applications, data, ICS, IoT and cloud functions.[1] Singularity Identity: “Plant decoys and credentials that expose reconnaissance early”.[3] | Deceptive responders on the network path, delivered as one capability within AMTD. |
| AMTD | Not publicly documented in the sources reviewed. | Yes. Network-layer AMTD continuously changes what an attacker can map. An optional AMTD Agent covers Windows and Linux hosts. |
| Inline enforcement | Hologram’s data sheet describes decoys that detect and alert, with attack visualization and playbooks. Singularity Identity describes automated containment workflows between identity and endpoint.[1][3] Inline network enforcement is Not publicly documented. | Yes. Enforcement runs in the packet path (block, redirect, throttle or tarpit). |
| Agentless | Hologram network decoys are hardware or virtual decoys.[1] Identity deception runs on the Singularity agent: “a single agent and console”.[3] | Yes for the network platform: nothing is installed on protected devices. The AMTD Agent is a separate, optional endpoint component. |
| OT protocol support | The 2022 data sheet lists “Decoy ICS-SCADA industrial control systems”.[1] Specific OT protocols are Not publicly documented in the sources reviewed. | Native, inline support for Modbus, DNP3, BACnet and S7COMM, with more than 20 OT protocols recognized. |
| Deployment model | Hologram: hardware and virtual decoys managed from a Hologram Central Manager, with cloud implementations named as Google Cloud, AWS, Azure and OpenStack (2022 data sheet).[1][3] Identity deception: part of the Singularity platform. | Inline nodes (bridge mode) on commodity server hardware, managed as a federation. Nodes keep enforcing when disconnected from central management. |
When to choose SentinelOne
When to choose PacketViper
Can they be used together?
Yes in principle: endpoint and identity deception on hosts, and AMTD with inline enforcement on the network, cover different layers. A direct integration between the two products is Not publicly documented.
PacketViper statements on this page come from PacketViper’s own published pages: Deception and AMTD, AMTD Agent, Performance Benchmarks and PacketViper vs Claroty.
Sources
- SentinelOne, Singularity Hologram data sheet (PDF, code S1-DS_SINGULARITY_HOLOGRAM-05032022, (c) 2022; reseller-hosted copy) Accessed 2026-10-09.
- SentinelOne, Singularity Identity data sheet (PDF, dated 07/01/24 in the file name; reseller-hosted copy) Accessed 2026-10-09.
- SentinelOne, Singularity Identity platform page (current; the former /platform/singularity-hologram/ address redirects here) Accessed 2026-10-09.
- SentinelOne, “SentinelOne Completes Acquisition of Attivo Networks” (press release, May 4, 2022) Accessed 2026-10-09.
Public sources are not conclusive. SentinelOne’s former Hologram product address now redirects to its Singularity Identity page, which markets identity deception, and we found no public end-of-sale notice. Confirm current availability with SentinelOne.
SentinelOne’s network deception product, introduced after its May 2022 acquisition of Attivo Networks. Its data sheet describes decoys that mimic operating systems, applications, ICS, IoT and cloud functions.
The 2022 data sheet describes hardware and virtual network decoys. SentinelOne’s identity deception runs on the Singularity agent.
PacketViper works at the network layer without agents on protected devices, combines AMTD, deception and inline enforcement, and keeps enforcing when disconnected from central management. SentinelOne’s deception is delivered through decoys and the Singularity endpoint agent.
See inline enforcement in your environment
Book a demonstration of PacketViper’s AMTD and inline enforcement, or request a proof of concept.
Explore further
Other vendor comparisons, buyer guides and the AMTD primer.