A Fortify 24x7 brand. Grown up security platforms, sold the way software used to be sold.Client sign inMail an engineer
Cyb3rs3cur1ty
Module 01 // Detection and response

Detection is not a dashboard. It is a human being on shift while you sleep.

Buying detection means buying three separate things at once: software that judges behavior on the machine, a layer reading the whole estate alongside it, and a person whose job is deciding what happens next. Every line here carries all three, which is what separates a running service from a shrink wrapped box.

SentinelOneFluencyStaffed desk
6 lines / 3 tiers of answer / endpoints and nodes
Lines here6
PlatformsSentinelOne and Fluency
Counted byEndpoint or node
Desk crewStaffed around the clock

What the agent is really looking at

Holding a file up against a list of things already known to be bad stopped being adequate years ago. The SentinelOne agent judges what a running process is doing: which programs it started, which documents it touched, which addresses it dialled, and whether the overall pattern looks like encryption, harvesting, or a slow crawl across a network. Those judgements carry on with the cable pulled out, which counts for something at thirty thousand feet and inside the cupboard where a forgotten box hums away.

Fluency then sets that account of events next to everything else: who signed in from where, what the mail platform saw, what crossed the wire, and whatever your other tools have been writing down. Surrounded by all of that, an alert can be settled inside a minute. Standing on its own it becomes a research project, and research projects get postponed until Monday.

Standing on its own, an alert becomes a research project.

Choosing between the three tiers

The first tier spots it, triages it and tells you what to do. The second widens the net, so a strange login on one continent and a peculiar process running on another stop looking like two separate curiosities. The third grows hands: isolation and rollback fire by themselves, before anybody has finished reading the write up.

Nodes are billed on lines of their own, and there is a reason for it. Nodes are not laptops, the agent has a different job on them, and rolling nodes into an endpoint tally would quietly produce a dishonest invoice. Count the nodes and ignore the pods.

Lines on this module

Specifications and rates

Every rate below arrives live from billing. Anything you pick up drops into the inventory panel and sits there quietly.

Fortify-MDRSpec

Managed Detection and Response

Agent work by SentinelOne · joined up by Fluency · triaged by people

Behavior watching on the endpoint, backed by a desk with people sitting at it. Those people work the alerts, so what lands with you is a recommendation rather than a graph to decode.

  • Windows, macOS and Linux are all covered, with no connection needed.
  • Triage, investigation and escalation all happen at the Fortify 24x7 desk.
  • Findings and case history stay readable in the portal, whenever you look.
EngineSentinelOne, correlated through Fluency
BoxesWindows, macOS and Linux
What we doAlerting, guidance and hands on help with cleanup
No networkJudgement continues while the link is down
Desk crewFortify 24x7 engineers, whatever hour it is
Counted byProtected endpoint, each month
Loadingper protected endpoint
billed each month, in advance
QTY
Fortify-XDRSpec

Extended Detection Across Layers

The same agent, with Fluency dragging in the neighbours

Everything the first tier does, with identity, mail and network signal read next to the endpoint rather than sitting in three other browser tabs waiting for somebody to notice.

  • Endpoint records read together with identity, mail and network activity.
  • Findings that no lone agent could reach using only its own view.
  • Longer retention, because some cases only make sense looking backwards.
EngineSentinelOne, with Fluency reading wider
Feeds inEndpoints, logins, mailboxes, network
What we doAlerting, guidance and hands on help with cleanup
Kept forExtended, for looking back at older activity
Best forTeams whose whole working day runs through Microsoft or Google
Counted byProtected endpoint, each month
Loadingper protected endpoint
billed each month, in advance
QTY
Fortify-XDR+Spec

Extended Detection with Response

Same again, except the containment switch stays on

The wide tier, given hands. Any machine crossing the threshold is pulled off the network and rewound before an engineer has finished reading the write up.

  • Automatic isolation once conviction on the machine is confident enough.
  • Anything the agent convicts gets rolled back, where the system allows it.
  • Each automatic action gets a written human review once the dust settles.
EngineSentinelOne, response left on automatic
Cut offThe machine drops off the network
UndoReverses file changes the agent convicts, where supported
Checked byReviewed by an engineer once the action has run
Best forFinance workstations, build hosts and signing machines
Counted byProtected endpoint, each month
Loadingper protected endpoint
billed each month, in advance
QTY
Fortify-MDR-K8Spec

Managed Detection, Kubernetes Node

Cluster nodes, watched in exactly the same way

Container workloads get the same treatment. Nodes are the unit here, which keeps the invoice speaking the same language as your cluster.

  • An agent at node level covering the workloads scheduled onto it.
  • Identical desk, identical triage, identical handling to the endpoint lines.
  • Sight of what a container actually does, not just what its image holds.
EngineSentinelOne for Kubernetes
Eyes onHow workloads behave once running on a node
What we doAlerting, guidance and hands on help with cleanup
Desk crewFortify 24x7 engineers, whatever hour it is
Counted byKubernetes node, each month
Loadingper Kubernetes node
billed each month, in advance
QTY
Fortify-XDR-K8Spec

Extended Detection, Kubernetes Node

Cluster nodes, read beside everything else you run

Node coverage with the correlation layer turned on, so what happens in the cluster is read alongside sign in and endpoint activity instead of off on a screen of its own.

  • Node telemetry parked next to everything else the estate reports in.
  • Findings that connect a workload to whichever identity reached it.
  • Longer retention covering cluster and endpoint records together.
EngineSentinelOne on nodes, correlated by Fluency
Feeds inNode runtime, logins, endpoints, network
What we doAlerting, guidance and hands on help with cleanup
Kept forExtended, for looking back at older activity
Counted byKubernetes node, each month
Loadingper Kubernetes node
billed each month, in advance
QTY
Fortify-XDR+K8Spec

Response Tier, Kubernetes Node

Cluster nodes, with the containment switch left on

The node line with automatic response bolted on, for clusters carrying something that cannot be left misbehaving until Monday opens.

  • A workload that trips the response threshold is contained without waiting.
  • A single case pulled together from cluster, login and endpoint evidence.
  • Every automatic action gets written up by a person and sent to you.
EngineSentinelOne on nodes, response left on automatic
Cut offThe offending workload gets stopped
Checked byReviewed by an engineer once the action has run
Best forProduction clusters carrying customer workloads
Counted byKubernetes node, each month
Loadingper Kubernetes node
billed each month, in advance
QTY
Honest scope

What sits in the box, and what does not

Detection makes an excellent control and a terrible guarantee. Here is the split, written out so you can work out what else you need to buy or write down.

IN THE BOX

  • Behavior based agents across Windows, macOS, Linux and cluster nodes, still deciding after the link drops.
  • Human triage at the Fortify 24x7 desk, with a recommendation attached to whatever reaches you.
  • Correlated context from identity, mail and network sources on the extended tiers.
  • Automatic containment and rollback on the response tiers, each one followed by a written review.
  • Case history visible in your portal, including what we did and why we did it.

NOT IN THE BOX

  • A promise that nothing ever starts. An agent spotting an intrusion means the intrusion started already. What is for sale here is the speed of the answer.
  • Your own application code. Bugs in the product you ship are invisible to an endpoint agent, and hunting them is a different trade with different people.
  • Machines with no agent on them. A device that never enrolled produces no telemetry and turns up in no investigation.
  • Backup. Rollback can put back the changes an agent later convicts, where the platform supports that. A dead drive is not something it can revive.
  • Cluster design. Admission policy, secrets handling and role bindings remain your design. Advice is available. Ownership is not.
NOTE 01

Heads up: card statements show FORTIFY 24X7 - Cyb3rs3cur1ty is a Fortify 24x7 brand, and your subscription is billed by Fortify 24x7.