A detection product is three things bolted together: software on the machine that can tell an ordinary backup job apart from an encryption run, a layer that reads it against everything else moving through the estate, and a rota of people deciding what happens next. All three ride on each of the six lines below.
Matching a list of known bad files stopped being sufficient some years ago, and everybody in this trade knows it. The SentinelOne agent models what is going on inside the machine: the processes started, the files opened, the places reached, and whether the shape of it resembles collection, encryption, or somebody quietly working sideways through a network.
It keeps judging with nothing connected at all, which counts for more in an industrial business than most vendors will admit. The laptop in a van between depots and the workstation on a mezzanine that only sees the network on alternate Thursdays are both still being judged.
The detection line does triage and gives advice. The extended line broadens what is read side by side, so a peculiar sign-in at one site and an odd process at another stop being unrelated curiosities filed by different people. The response level adds containment and reversal with nobody asking for it, which is exactly the behavior you want on a Sunday night.
Kubernetes nodes carry lines of their own. Nodes get their own lines. The agent behaves unlike its endpoint sibling, and merging the two counts would leave an invoice that quietly misstates things. Count nodes, not pods.
Every rate on this page comes live off the billing service. Anything locked on stays on the worklist while you read on.
A behavioral agent watches what each process is actually doing, and a desk with people on it decides what happens next. What reaches you is a finding with a recommended action attached, not a chart to interpret in the small hours.
| Mounted on | SentinelOne, on a Windows, Mac, or Linux endpoint |
|---|---|
| Isolates | A process that has started encrypting, collecting, or spreading |
| Retained for | Case notes, retained the whole time a line is running |
| Released by | Your own team, working to the written instruction the analyst leaves |
| Signed off by | The Fortify 24x7 engineer who closed the case, in the case record |
Everything the detection line does, but widened, so a peculiar sign-in logged at one site and an odd process running at another stop being unrelated curiosities filed by different people.
| Mounted on | SentinelOne agent, with Fluency taking feeds from your other sources |
|---|---|
| Isolates | A pattern that only shows up once two systems are read together |
| Retained for | Joined-source retention, extended, agreed at scoping |
| Released by | Your own team, working to the written instruction the analyst leaves |
| Signed off by | The Fortify 24x7 engineer who closed the case, in the case record |
The joined-up tier with hands on it. Cross the response threshold and the machine leaves its network and is reverted before anyone at our desk has finished reading the case. That is the gap between a bad hour and a bad quarter.
| Mounted on | SentinelOne on the endpoint, response left armed |
|---|---|
| Isolates | The endpoint itself, off its network the moment conviction lands |
| Retained for | Case notes, retained the whole time a line is running |
| Released by | A Fortify 24x7 analyst, after the review of the automated action |
| Signed off by | The Fortify 24x7 engineer who closed the case, in the case record |
Detection for containerized workloads. Nodes are what get counted, so the invoice matches whatever figure your platform team is already tracking. Count nodes, not pods.
| Mounted on | SentinelOne for Kubernetes, on each node you enroll |
|---|---|
| Isolates | A workload behaving unlike anything the cluster is supposed to run |
| Retained for | Case notes, retained the whole time a line is running |
| Released by | Your own platform team, working to the analyst instruction |
| Signed off by | The Fortify 24x7 engineer who closed the case, in the case record |
Node detection with the joining layer live, which sets cluster activity next to identity records and endpoint records instead of walling it off in its own window.
| Mounted on | SentinelOne for Kubernetes, taking the cluster feed into Fluency |
|---|---|
| Isolates | A chain that runs from an account into a workload and back out |
| Retained for | Joined-source retention, extended, agreed at scoping |
| Released by | Your own platform team, working to the analyst instruction |
| Signed off by | The Fortify 24x7 engineer who closed the case, in the case record |
Node detection with response armed, for a cluster whose work cannot be left misbehaving until somebody opens a laptop on Monday.
| Mounted on | SentinelOne for Kubernetes, response left armed |
|---|---|
| Isolates | The offending workload, contained where it stands |
| Retained for | Case notes, retained the whole time a line is running |
| Released by | A Fortify 24x7 analyst, after the review of the automated action |
| Signed off by | The Fortify 24x7 engineer who closed the case, in the case record |
As a control detection is decent. As a guarantee it is worthless. What follows is the ground these six lines cannot cover, written down so the gap is yours to fill knowingly.
Heads up: card statements show FORTIFY 24X7 - Industry Lock Networks is a Fortify 24x7 brand, and your subscription is billed by Fortify 24x7.