Detection software is trivially easy to buy and close to useless standing alone. The console lights up while your office is dark, and if the only candidate to look at it is asleep with the phone turned over, what you own is a well kept record of the damage rather than anything that interrupted it. This route sells the watching. The software comes along with it.
Each machine carries a sensor that judges conduct instead of labels. Renaming a tool leaves its conduct untouched, and conduct is the honest signal. When the sensor decides something deserves raising, that alarm leaves your building and arrives at a desk where reading alarms is somebody's entire occupation for the shift.
They sort it. Most alarms turn out to be noise, and saying so is genuine work, since the alternative is a business that trains itself to ignore its own bells inside a fortnight. Real ones get worked through. The decision and the reasoning behind it are recorded in sentences you can follow without a glossary.
Managed Detection and Response covers the endpoint. Extended Detection and Response brings in Fluency, which gathers your sign in, mail, and network feeds and stitches them onto the endpoint story, so an event that crossed four systems reads as one account instead of four arguments.
The containment depth is what changes the arithmetic. Our analysts gain standing permission to lift a machine off the network and halt a process without telephoning anybody first. You draw those bounds at rollout and you may redraw them whenever. Firms that have lived through one bad night usually buy this depth the following month.
Each figure here is pulled out of the billing service as this page opens. Load a line now and it waits in the bag until you have finished reading.
SentinelOne runs on the machine and judges conduct rather than filenames. When it raises a flag, that flag reaches our analysts before it reaches you. They read it, rule on whether it is genuine, and act. You hear from us because a human looked, never because software forwarded you a graph.
| Carried on | SentinelOne agent, one per protected machine |
|---|---|
| Covers | Windows, macOS, and Linux endpoints and servers under management |
| Held in transit | Detection telemetry retained on the SentinelOne platform for the standard window |
| Postmarked by | Fortify 24x7 analysts, awake in shifts |
| Signed for | One endpoint, one line, one monthly rate |
The same watch, moved onto container infrastructure. The agent runs at node level and sees what the workloads on that node actually do. It is priced per node because that is the thing that exists, and counting pods would produce a number nobody could reconcile.
| Carried on | SentinelOne agent deployed at Kubernetes node level |
|---|---|
| Covers | Container workloads scheduled onto the node |
| Held in transit | Detection telemetry retained on the SentinelOne platform for the standard window |
| Postmarked by | Fortify 24x7 analysts, awake in shifts |
| Signed for | One Kubernetes node, one line, one monthly rate |
Detection on the endpoint stops answering the interesting questions the moment an attack touches two places at once. Fluency collects the other sources and stitches them to the endpoint story, so an alert arrives already carrying the sign in, the mail event, and the network hop that went with it.
| Carried on | SentinelOne Complete agent with Fluency correlation |
|---|---|
| Covers | The endpoint, plus whichever sign in, mail, and network feeds you attach |
| Held in transit | Correlated events held in the Fluency platform for investigation and lookback |
| Postmarked by | Fortify 24x7 analysts, awake in shifts |
| Signed for | One endpoint, one line, one monthly rate |
Correlated detection for container infrastructure. The node sensor feeds the same Fluency pipeline your laptops and identity provider feed, which is the only way an incident that begins in a browser and ends in a cluster reads as one event.
| Carried on | SentinelOne Complete agent at Kubernetes node level, with Fluency correlation |
|---|---|
| Covers | Container workloads on the node, joined to your other connected sources |
| Held in transit | Correlated events held in the Fluency platform for investigation and lookback |
| Postmarked by | Fortify 24x7 analysts, awake in shifts |
| Signed for | One Kubernetes node, one line, one monthly rate |
The deepest tier gives our analysts standing authority to act. Lift the machine off the network, halt the process, reverse the damage, and tell you once it is done. You are buying minutes here, and minutes are usually the whole argument.
| Carried on | SentinelOne Complete agent with Fluency correlation |
|---|---|
| Covers | The endpoint, plus whichever sign in, mail, and network feeds you attach |
| Held in transit | Correlated events held in the Fluency platform for investigation and lookback |
| Postmarked by | Fortify 24x7 analysts, acting under the authority you granted at rollout |
| Signed for | One endpoint, one line, one monthly rate |
Containment authority extended to the cluster. Same agreement as the endpoint tier: our analysts may act at the node, and the record of what they did is written where you can read it without asking anybody.
| Carried on | SentinelOne Complete agent at Kubernetes node level, with Fluency correlation |
|---|---|
| Covers | Container workloads on the node, joined to your other connected sources |
| Held in transit | Correlated events held in the Fluency platform for investigation and lookback |
| Postmarked by | Fortify 24x7 analysts, acting under the authority you granted at rollout |
| Signed for | One Kubernetes node, one line, one monthly rate |
A sensor watching one machine has a horizon, and hiding that is how customers end up startled. Read this block first, not later.
Heads up: card statements show FORTIFY 24X7 - Stars and Stripes IT is a Fortify 24x7 brand, and your subscription is billed by Fortify 24x7.