Nobody is asking you to sit and watch a screen. What you get instead: an instrument following what a program does, a layer setting that beside the rest of your estate, and somebody awake at four to decide. Each line here brings the whole set.
Checking a file against a roll of bad ones stopped being sufficient years back. Conduct at the machine is what the SentinelOne agent watches. Which process spawned. Which files opened. Which destinations answered. Whether that pattern smells of encryption, of collection, or of a quiet walk sideways. It keeps deciding on no network at all, which is what a laptop in the air needs, and the spare box left running in the stockroom too.
Fluency takes agent output and puts it against the wider picture: sign in records, mail events, traffic on the wire, logs off tools you already pay a licence for. A reading landing at our desk therefore arrives decidable. That margin is the whole distance from being told to being helped.
Reading, triage and advice come with the first line. Widening it hangs further gauges on one chart, so a peculiar sign in abroad and a strange process at a desk back home stop reading as unrelated curiosities. Containment plus reversal come with the response tier, wanted most at eleven on a Saturday night.
Nodes in a cluster carry lines of their own. No node is a laptop, agents conduct themselves otherwise up there, and rolling a node count into a machine count would quietly falsify the invoice. Tally the nodes. Pods are somebody else's arithmetic.
Every rate here is drawn from billing as the page renders. Anything you log stays in the observation log while reading continues.
A gauge goes on the computer and follows what running programs get up to. Should the needle move, somebody at the desk works it and writes you a bulletin in ordinary words.
| Observed at | The computer itself, from an agent installed on it |
|---|---|
| Forecasts | Behaviour resembling encryption, credential theft or quiet movement between machines |
| Archived | Bulletins and case notes remain readable in your portal while the line runs |
| Issued by | SentinelOne, with Fluency drawing the readings together |
| Confirmed at | The Fortify 24x7 desk, read by a person, before anything travels to you |
Same gauge, more dials wired in. Sign in events, mail events and traffic on the wire get plotted on one chart alongside the computer, so two odd numbers stop looking like two coincidences.
| Observed at | Computers, and the identity, mail and network records you connect |
|---|---|
| Forecasts | Patterns that only appear when several gauges are read on one chart |
| Archived | Extended holding of correlated records for questions raised after the fact |
| Issued by | SentinelOne with wider Fluency correlation |
| Confirmed at | The Fortify 24x7 desk, working the correlated case as one item |
The widened line, handed permission to act. Threshold crossed, the machine is pulled off its network and rolled back, all of it while an engineer reads.
| Observed at | The computer itself, with the response threshold set during tuning |
|---|---|
| Forecasts | The same turns as the widened line, with the machine cut off rather than watched |
| Archived | A record of each automatic action, held with the case that triggered it |
| Issued by | SentinelOne, acting under a policy we agree with you first |
| Confirmed at | The Fortify 24x7 desk, reviewing every automatic action after it runs |
Detection over containerised workloads, tallied by node. The invoice then agrees with the figure whoever runs your cluster already keeps.
| Observed at | The Kubernetes node, watching workloads while they run |
|---|---|
| Forecasts | Container behaviour that departs from what the workload normally does |
| Archived | Node cases held in the portal on the same footing as machine cases |
| Issued by | SentinelOne for Kubernetes |
| Confirmed at | The Fortify 24x7 desk, before a node bulletin is issued |
Node detection running correlation, so cluster activity gets plotted beside the sign in that reached it rather than on a chart by itself.
| Observed at | The node, plus the identity and machine records you connect |
|---|---|
| Forecasts | Sequences running out of an account, into a workload, then out again |
| Archived | Extended holding of correlated cluster and machine records |
| Issued by | SentinelOne for Kubernetes, with correlation through Fluency |
| Confirmed at | The Fortify 24x7 desk, working the correlated case as one item |
The node line, response attached, suited to a cluster carrying something better not left misbehaving until Monday.
| Observed at | The node, with a containment threshold agreed before the line goes live |
|---|---|
| Forecasts | Workload behaviour severe enough to act on rather than only report |
| Archived | A record of each containment action alongside the case that caused it |
| Issued by | SentinelOne for Kubernetes, response automated |
| Confirmed at | The Fortify 24x7 desk, reviewing every automatic action after it runs |
Detection is a fine instrument, a poor guarantee. Below, in plain words, is what these six lines fail to reach, so that you can judge what else is wanted.
Heads up: card statements show FORTIFY 24X7 - CyberThreat Management is a Fortify 24x7 brand, and your subscription is billed by Fortify 24x7.