Six lines of detection, every one of them reporting into a queue that Fortify 24x7 engineers genuinely sit at. The agent takes a reading. A person rules on what the reading means and what follows from it.
It weighs conduct rather than checking a name against a roster. A program that starts quietly, reaches for stored credentials, phones somewhere it has no business phoning and then begins scrambling files has described itself perfectly well by its behavior, whether or not a signature for it exists anywhere yet.
That ruling is reached on the box, which counts for more than it sounds like. A laptop on hotel wireless with the tunnel down is exactly where you want an agent still able to reach a verdict without asking anyone's permission.
The detection line sorts and advises: you are told what occurred, what it signifies and what we suggest. The extended line widens the comparison, so behavior on one machine is weighed against logons, mail and wire traffic from the same span of minutes. The response tier carries a mandate to act, which is precisely what you want on a Sunday at two in the morning.
Kubernetes nodes carry their own lines. Nodes get counted and pods never do, and a cluster should never disappear inside an endpoint figure.
The agent takes a reading. A person rules on what happens next.
Figures below are read straight from billing. Whatever you sign out waits on your roll while you keep reading.
A behavioral agent lives on the box and judges conduct, not labels. Anything reading outside tolerance drops into a queue our engineers actually sit at, and what returns to you is a verdict with a recommended move beside it.
| Fits | A single protected endpoint. Machines count here, not headcount. |
|---|---|
| Works on | Windows and macOS boxes, and Linux ones too. |
| Stored for | Findings and working notes sit in the portal the whole time the line hangs there. |
| Issued by | SentinelOne, stood up and trimmed to fit by Fortify 24x7 engineers. |
| Inspected by | Fortify 24x7 analysts, at whatever hour the clock happens to show. |
Identical agent, far wider field of view. Machine activity gets read beside logon records, mail traffic and what crossed the wire. An improbable sign in from one country, plus an odd program starting on a laptop somewhere else, quit being two separate oddities that nobody joined up.
| Fits | A single protected endpoint, however much else it is weighed against. |
|---|---|
| Works on | Windows, macOS, Linux, and the cloud or identity feeds you plug in. |
| Stored for | Joined events held far enough back to reconstruct an episode afterward. |
| Issued by | SentinelOne with Fluency correlation, wired up by Fortify 24x7 engineers. |
| Inspected by | Fortify 24x7 analysts, hunting across everything that got joined. |
All of the wider reading, and a standing mandate to intervene. Our engineers pull the host off the network, halt what is running, and unwind whatever a convicted process altered, rather than sitting on it until somebody at your end wakes and gives a blessing.
| Fits | A single protected endpoint carrying direct remediation. |
|---|---|
| Works on | Windows, macOS and Linux. How far a reversal reaches follows the operating system. |
| Stored for | Each intervention on your estate is written up and filed beside the case. |
| Issued by | SentinelOne Complete with Fluency, run day to day by Fortify 24x7 engineers. |
| Inspected by | Fortify 24x7 analysts, the same people doing the containment. |
Detection aimed at container hosts. A node resembles a desk machine hardly at all: the agent lands differently, it sees other things, and rolling nodes in with laptops would quietly falsify the bill. So they hang on a hook of their own.
| Fits | A single Kubernetes node. Nodes get counted; pods never do. |
|---|---|
| Works on | Kubernetes clusters whose node operating system is supported. |
| Stored for | Node case history filed beside everything else in your estate. |
| Issued by | SentinelOne Kubernetes agent, landed with help from Fortify 24x7 engineers. |
| Inspected by | Fortify 24x7 analysts, working the queue they work for everything else. |
Node findings read in company with everything else you happen to run. Container behavior that signifies nothing by itself begins to signify plenty once it is set beside logon records and wire traffic from the same half hour.
| Fits | A single Kubernetes node, weighed against your other connected feeds. |
|---|---|
| Works on | Kubernetes clusters, plus whichever cloud and identity feeds you plug in. |
| Stored for | Joined node events retained for reconstruction well after the event. |
| Issued by | SentinelOne Complete with Fluency, landed with Fortify 24x7 engineers. |
| Inspected by | Fortify 24x7 analysts, hunting across everything that got joined. |
Intervention for container hosts. When a node throws a conviction, our engineers deal with the node itself, instead of mailing a chart across and trusting that somebody is awake to make sense of it.
| Fits | A single Kubernetes node carrying direct remediation. |
|---|---|
| Works on | Kubernetes clusters whose node operating system is supported. |
| Stored for | A written record of each intervention, filed beside the case. |
| Issued by | SentinelOne Complete with Fluency, run day to day by Fortify 24x7 engineers. |
| Inspected by | Fortify 24x7 analysts, the same people doing the remediation. |
Detection makes a fine instrument and a poor guarantee. Here sits the boundary of the six lines above, put plainly enough to plan around.
Heads up: card statements show FORTIFY 24X7 - CyberDefense Tools is a Fortify 24x7 brand, and your subscription is billed by Fortify 24x7.