A Fortify 24x7 brand. Plain dealing, printed rates, and a name against every job.Sign in at the counterSend us a line
Stars and Stripes ITCarried · Posted · Signed for
Route 01 / Standing watch

Somebody is awake when the bell rings

Detection software is trivially easy to buy and close to useless standing alone. The console lights up while your office is dark, and if the only candidate to look at it is asleep with the phone turned over, what you own is a well kept record of the damage rather than anything that interrupted it. This route sells the watching. The software comes along with it.

SentinelOneFluencySix items on this route
FORM 3801
Items carried6
Rate followsEndpoint, or node
Worked byAnalysts in shifts
Runs onSentinelOne with Fluency

What the watching is made of

Each machine carries a sensor that judges conduct instead of labels. Renaming a tool leaves its conduct untouched, and conduct is the honest signal. When the sensor decides something deserves raising, that alarm leaves your building and arrives at a desk where reading alarms is somebody's entire occupation for the shift.

They sort it. Most alarms turn out to be noise, and saying so is genuine work, since the alternative is a business that trains itself to ignore its own bells inside a fortnight. Real ones get worked through. The decision and the reasoning behind it are recorded in sentences you can follow without a glossary.

A bell nobody hears is a smoke alarm fitted in an empty house

Choosing your depth

Managed Detection and Response covers the endpoint. Extended Detection and Response brings in Fluency, which gathers your sign in, mail, and network feeds and stitches them onto the endpoint story, so an event that crossed four systems reads as one account instead of four arguments.

The containment depth is what changes the arithmetic. Our analysts gain standing permission to lift a machine off the network and halt a process without telephoning anybody first. You draw those bounds at rollout and you may redraw them whenever. Firms that have lived through one bad night usually buy this depth the following month.

Every item on this route

Item by item, with the figure attached

Each figure here is pulled out of the billing service as this page opens. Load a line now and it waits in the bag until you have finished reading.

Fortify-MDRROUTE 01

Managed Detection and Response

per protected endpoint

SentinelOne runs on the machine and judges conduct rather than filenames. When it raises a flag, that flag reaches our analysts before it reaches you. They read it, rule on whether it is genuine, and act. You hear from us because a human looked, never because software forwarded you a graph.

  • Watches behavior on desktops and servers running Windows, macOS, or Linux.
  • Our analysts triage the alert before anybody wakes you about it.
  • Rollback is available on Windows for changes an attack made to files.
  • Every judgment call is written down, so you can read the reasoning later.
Carried onSentinelOne agent, one per protected machine
CoversWindows, macOS, and Linux endpoints and servers under management
Held in transitDetection telemetry retained on the SentinelOne platform for the standard window
Postmarked byFortify 24x7 analysts, awake in shifts
Signed forOne endpoint, one line, one monthly rate
Rate loadingcounted per protected endpoint
paid a month ahead
HOW MANY
Fortify-MDR-K8ROUTE 01

Managed Detection, Kubernetes Node

per Kubernetes node

The same watch, moved onto container infrastructure. The agent runs at node level and sees what the workloads on that node actually do. It is priced per node because that is the thing that exists, and counting pods would produce a number nobody could reconcile.

  • A single sensor per node, taking in the workloads placed there.
  • Conduct inside the running container, not merely the scan performed at build time.
  • Findings arrive at the desk that already reads your desktop alarms.
  • Counted by node, so a scaling event moves the bill in a way you can check.
Carried onSentinelOne agent deployed at Kubernetes node level
CoversContainer workloads scheduled onto the node
Held in transitDetection telemetry retained on the SentinelOne platform for the standard window
Postmarked byFortify 24x7 analysts, awake in shifts
Signed forOne Kubernetes node, one line, one monthly rate
Rate loadingcounted per Kubernetes node
paid a month ahead
HOW MANY
Fortify-XDRROUTE 01

Extended Detection and Response

per protected endpoint

Detection on the endpoint stops answering the interesting questions the moment an attack touches two places at once. Fluency collects the other sources and stitches them to the endpoint story, so an alert arrives already carrying the sign in, the mail event, and the network hop that went with it.

  • SentinelOne Complete on the endpoint, correlated by Fluency across the estate.
  • Identity, mail, and network events joined to the endpoint they belong with.
  • One timeline per incident instead of four consoles and a guess.
  • Retention long enough to answer the question a month after somebody asks it.
Carried onSentinelOne Complete agent with Fluency correlation
CoversThe endpoint, plus whichever sign in, mail, and network feeds you attach
Held in transitCorrelated events held in the Fluency platform for investigation and lookback
Postmarked byFortify 24x7 analysts, awake in shifts
Signed forOne endpoint, one line, one monthly rate
Rate loadingcounted per protected endpoint
paid a month ahead
HOW MANY
Fortify-XDR-K8ROUTE 01

Extended Detection, Kubernetes Node

per Kubernetes node

Correlated detection for container infrastructure. The node sensor feeds the same Fluency pipeline your laptops and identity provider feed, which is the only way an incident that begins in a browser and ends in a cluster reads as one event.

  • SentinelOne Complete at node level, tied by Fluency into everything else you run.
  • Cluster activity lines up beside endpoint and identity activity on one timeline.
  • Useful when the crown jewels moved into containers but the attacker did not.
  • Quoted by node, which is the count that survives an autoscaling event.
Carried onSentinelOne Complete agent at Kubernetes node level, with Fluency correlation
CoversContainer workloads on the node, joined to your other connected sources
Held in transitCorrelated events held in the Fluency platform for investigation and lookback
Postmarked byFortify 24x7 analysts, awake in shifts
Signed forOne Kubernetes node, one line, one monthly rate
Rate loadingcounted per Kubernetes node
paid a month ahead
HOW MANY
Fortify-XDR+ROUTE 01

Extended Detection with Containment

per protected endpoint

The deepest tier gives our analysts standing authority to act. Lift the machine off the network, halt the process, reverse the damage, and tell you once it is done. You are buying minutes here, and minutes are usually the whole argument.

  • Our analysts hold standing permission to cut a machine off without ringing you.
  • The full SentinelOne Complete feature set, rollback included where supported.
  • The action taken and the reason for it are recorded and readable afterwards.
  • You set the boundaries at rollout, and you can change them whenever you like.
Carried onSentinelOne Complete agent with Fluency correlation
CoversThe endpoint, plus whichever sign in, mail, and network feeds you attach
Held in transitCorrelated events held in the Fluency platform for investigation and lookback
Postmarked byFortify 24x7 analysts, acting under the authority you granted at rollout
Signed forOne endpoint, one line, one monthly rate
Rate loadingcounted per protected endpoint
paid a month ahead
HOW MANY
Fortify-XDR+K8ROUTE 01

Extended Detection with Containment, Kubernetes Node

per Kubernetes node

Containment authority extended to the cluster. Same agreement as the endpoint tier: our analysts may act at the node, and the record of what they did is written where you can read it without asking anybody.

  • Analysts may contain at node level under the authority you set.
  • SentinelOne Complete capability on container infrastructure.
  • Joined to endpoint and identity activity by Fluency, so containment is informed.
  • Priced per node, with the bill following the cluster you run.
Carried onSentinelOne Complete agent at Kubernetes node level, with Fluency correlation
CoversContainer workloads on the node, joined to your other connected sources
Held in transitCorrelated events held in the Fluency platform for investigation and lookback
Postmarked byFortify 24x7 analysts, acting under the authority you granted at rollout
Signed forOne Kubernetes node, one line, one monthly rate
Rate loadingcounted per Kubernetes node
paid a month ahead
HOW MANY
Honest scope

Where this route ends

A sensor watching one machine has a horizon, and hiding that is how customers end up startled. Read this block first, not later.

  • The sensor sees where the sensor sits. A private laptop that never enrolled, a router, a printer, or a supplier signing in from hardware you do not own all fall outside. Correlation widens the view to feeds you connect, and no further than that.
  • Response reaches as far as your depth. At the lower depths we notify and advise. Only the containment depth allows us to act unasked, and a supplier who acts on authority nobody granted is a worse problem than the one you hired them for.
  • Telemetry is not an audit package. It answers what took place. Assembling that into something a regulator accepts is its own job, and we flag it the moment a request has walked into that territory.
  • Rollback is a platform feature with edges. It reverses file damage on supported machines. Nothing about it constitutes a copy, which is precisely why the second copy route is sold on its own.
  • Nobody catches everything. Any supplier saying otherwise is selling a mood. Buy it to shorten the wait between something beginning and somebody qualified laying eyes on it.
NOTE 01

Heads up: card statements show FORTIFY 24X7 - Stars and Stripes IT is a Fortify 24x7 brand, and your subscription is billed by Fortify 24x7.