A Fortify 24x7 brand. Gauges, hourly readings and a watch desk kept for smaller firms.Client sign inReach the desk
CyberThreat Management
Front 01 / Detection watch

Something is always running. The question is whether anybody reads the gauge.

Nobody is asking you to sit and watch a screen. What you get instead: an instrument following what a program does, a layer setting that beside the rest of your estate, and somebody awake at four to decide. Each line here brings the whole set.

SentinelOneFluencyDesk with people on it
Six lines. Three response tiers. Computers and cluster nodes.
Lines posted6
Read bySentinelOne and Fluency
UnitComputer or node
DeskStaffed round the clock

What the instrument is really reading

Checking a file against a roll of bad ones stopped being sufficient years back. Conduct at the machine is what the SentinelOne agent watches. Which process spawned. Which files opened. Which destinations answered. Whether that pattern smells of encryption, of collection, or of a quiet walk sideways. It keeps deciding on no network at all, which is what a laptop in the air needs, and the spare box left running in the stockroom too.

Fluency takes agent output and puts it against the wider picture: sign in records, mail events, traffic on the wire, logs off tools you already pay a licence for. A reading landing at our desk therefore arrives decidable. That margin is the whole distance from being told to being helped.

A reading landing at our desk arrives decidable, and that margin is the whole product.

Choosing between the tiers

Reading, triage and advice come with the first line. Widening it hangs further gauges on one chart, so a peculiar sign in abroad and a strange process at a desk back home stop reading as unrelated curiosities. Containment plus reversal come with the response tier, wanted most at eleven on a Saturday night.

Nodes in a cluster carry lines of their own. No node is a laptop, agents conduct themselves otherwise up there, and rolling a node count into a machine count would quietly falsify the invoice. Tally the nodes. Pods are somebody else's arithmetic.

Lines on this front

Line records and rates

Every rate here is drawn from billing as the page renders. Anything you log stays in the observation log while reading continues.

Fortify-MDRLine record

Managed Detection and Response

Behaviour read by SentinelOne, readings joined by Fluency, a staffed desk behind

A gauge goes on the computer and follows what running programs get up to. Should the needle move, somebody at the desk works it and writes you a bulletin in ordinary words.

  • Windows, macOS and Linux all take the agent, which carries on judging once the network drops away.
  • A Fortify 24x7 engineer triages every needle that moves before anything travels to you.
  • The bulletin states what occurred, what got done, and which part is left for you to settle.
Observed atThe computer itself, from an agent installed on it
ForecastsBehaviour resembling encryption, credential theft or quiet movement between machines
ArchivedBulletins and case notes remain readable in your portal while the line runs
Issued bySentinelOne, with Fluency drawing the readings together
Confirmed atThe Fortify 24x7 desk, read by a person, before anything travels to you
Readingper protected endpoint
charged up front, each month
QTY
Fortify-XDRLine record

Extended Detection Across Layers

SentinelOne readings widened over identity, over mail, over the network

Same gauge, more dials wired in. Sign in events, mail events and traffic on the wire get plotted on one chart alongside the computer, so two odd numbers stop looking like two coincidences.

  • Machine readings get plotted beside identity, beside mail, beside the network.
  • Movements no single dial could show alone become legible once they share a chart.
  • Underlying records are held longer, since some questions only occur to people well afterwards.
Observed atComputers, and the identity, mail and network records you connect
ForecastsPatterns that only appear when several gauges are read on one chart
ArchivedExtended holding of correlated records for questions raised after the fact
Issued bySentinelOne with wider Fluency correlation
Confirmed atThe Fortify 24x7 desk, working the correlated case as one item
Readingper protected endpoint
charged up front, each month
QTY
Fortify-XDR+Line record

Extended Detection with Response

Containment and reversal permitted, under SentinelOne

The widened line, handed permission to act. Threshold crossed, the machine is pulled off its network and rolled back, all of it while an engineer reads.

  • Isolation happens by itself once conviction at the machine is firm enough to hold.
  • Alterations by a convicted process get reversed, on systems built to reverse.
  • Each automatic action is read back afterwards by a person and written into the bulletin.
Observed atThe computer itself, with the response threshold set during tuning
ForecastsThe same turns as the widened line, with the machine cut off rather than watched
ArchivedA record of each automatic action, held with the case that triggered it
Issued bySentinelOne, acting under a policy we agree with you first
Confirmed atThe Fortify 24x7 desk, reviewing every automatic action after it runs
Readingper protected endpoint
charged up front, each month
QTY
Fortify-MDR-K8Line record

Managed Detection, Kubernetes Node

SentinelOne reading container workloads up at the node

Detection over containerised workloads, tallied by node. The invoice then agrees with the figure whoever runs your cluster already keeps.

  • An agent at node level reads the workloads scheduled there, while they run.
  • Same desk, same triage, same bulletin shape as the lines that live on laptops.
  • It reads running conduct instead of only scanning images before they ship.
Observed atThe Kubernetes node, watching workloads while they run
ForecastsContainer behaviour that departs from what the workload normally does
ArchivedNode cases held in the portal on the same footing as machine cases
Issued bySentinelOne for Kubernetes
Confirmed atThe Fortify 24x7 desk, before a node bulletin is issued
Readingper Kubernetes node
charged up front, each month
QTY
Fortify-XDR-K8Line record

Extended Detection, Kubernetes Node

Node readings joined to the wider estate by Fluency

Node detection running correlation, so cluster activity gets plotted beside the sign in that reached it rather than on a chart by itself.

  • Node readings share a chart with identity, machine and network records.
  • Movement leaving an account, entering a workload and coming back again becomes one case.
  • Correlated cluster and machine records are held for a longer stretch.
Observed atThe node, plus the identity and machine records you connect
ForecastsSequences running out of an account, into a workload, then out again
ArchivedExtended holding of correlated cluster and machine records
Issued bySentinelOne for Kubernetes, with correlation through Fluency
Confirmed atThe Fortify 24x7 desk, working the correlated case as one item
Readingper Kubernetes node
charged up front, each month
QTY
Fortify-XDR+K8Line record

Response Tier, Kubernetes Node

SentinelOne, containing a container workload without waiting for anyone

The node line, response attached, suited to a cluster carrying something better not left misbehaving until Monday.

  • Containment happens by itself when a workload crosses the threshold agreed.
  • One case gets built out of cluster, identity and machine evidence together, all at once.
  • Each automatic action is read back by a person and recorded in the bulletin.
Observed atThe node, with a containment threshold agreed before the line goes live
ForecastsWorkload behaviour severe enough to act on rather than only report
ArchivedA record of each containment action alongside the case that caused it
Issued bySentinelOne for Kubernetes, response automated
Confirmed atThe Fortify 24x7 desk, reviewing every automatic action after it runs
Readingper Kubernetes node
charged up front, each month
QTY
Honest scope

Where this front stops

Detection is a fine instrument, a poor guarantee. Below, in plain words, is what these six lines fail to reach, so that you can judge what else is wanted.

  • Detection is not prevention. Recognising an intrusion means saying that something began already. Speed of working it is the product. Nothing beginning at all is on sale nowhere, and certainly not here.
  • We do not know which attack is coming. Nothing on this front names an attacker or forecasts a campaign aimed at you. It reads conditions across your own estate and reports the turn. Anybody offering the other thing is offering a story.
  • Software you build is out of scope. A flaw in a product you build, or in a website you run, stays invisible to any agent on a laptop. Testing applications, and reviewing the code behind them, is a separate trade. We would rather point at it than pretend this reaches.
  • A machine carrying no agent produces no reading. Enrol nothing and you get nothing. Such devices show up in no investigation, produce no telemetry, and fall under no line on this page.
  • Reversal is not backup. Alterations by a convicted process get undone by the response tier, on systems built to undo. A dead disk stays dead that way, and yesterday's spreadsheet stays gone. Those belong on the backup front.
NOTICE 01

Heads up: card statements show FORTIFY 24X7 - CyberThreat Management is a Fortify 24x7 brand, and your subscription is billed by Fortify 24x7.