A Fortify 24x7 brand. Protective coverage for small and medium businesses across North America.Client portalContact
CyberThreat Help
01RUNG
SentinelOne sensor · Fluency correlation · Fortify 24x7 analysts

Detection and response

The rung that tells you something is wrong while it is still going wrong. A sensor watches how software behaves on every machine, and people on shift decide what the alarm meant.

01The threat

Something is already running.

The uncomfortable part of every serious incident is the gap. Somebody gets in on a Tuesday, and the business finds out the following Monday when the files stop opening. In between, they were reading mail, looking at the file server, and working out what you are worth.

That gap is what this rung shortens. Not by predicting who will attack you, which nobody can do honestly, but by watching what software actually does on your machines and reacting to the behaviour that only intruders exhibit.

02The method

Behaviour, not filenames.

The sensor is not comparing files against a list of known bad ones. It watches sequences. A document that spawns a script, a script that reaches out to a stranger, a process that starts renaming files in bulk: none of those is remarkable alone, and all of them together is one thing only.

Because the judgement is behavioural, software nobody has ever seen before is still catchable. And because the sensor keeps working when the network is unavailable, a laptop in a hotel is as covered as the machine in your office.

03The people

An analyst decides, then acts.

A tool that only sends alerts hands you a new job. Ours are read by analysts at the Fortify 24x7 desk on every shift, and what comes out of that is a decision rather than another notification. Isolate the machine, kill the process, leave it alone because it was your accountant running something unusual.

The three tiers on this page differ by how far the correlation reaches and how much authority you have given us in advance. The remediation tier lets us move first and inform you while we are moving, which is the only arrangement worth anything when the alarm sounds at three in the morning.

04The cost

What this rung actually asks of you.

An agent has to be installed on every machine you want covered, and machines that are switched off are not being watched. Older hardware running very old operating systems may be out of support for the sensor, and we will tell you that during deployment rather than after you have paid.

There is also a settling in period. The first fortnight produces more questions from us than the months that follow, because we are still learning the shape of a normal day in your business. That is work, and it is worth doing properly.

Lines on this rung

6 lines · rates per unit, per month
Fortify-MDRManual entry

Managed Detection and Response

SentinelOne agent · Fluency correlation · analysts on every shift

Behavioural detection on the machine itself, watched by people who are paid to act on it. When something starts behaving like an intruder, the machine is isolated and you get a written account of what happened.

  • Runs on Windows, macOS, and Linux, on hardware or in a cloud instance.
  • Detection works from behaviour, so a file nobody has seen before is still catchable.
  • Isolation is a decision an analyst makes, not a switch you are left holding.
  • Every conviction arrives with the sequence of events that produced it.
SensorSentinelOne agent, autonomous when the network is unavailable
Watched byFortify 24x7 analysts, continuously
ContainmentNetwork isolation and process termination on analyst decision
RollbackAvailable where the platform supports it, on Windows
ReportingWritten incident account with the timeline that led to it
Priced byProtected endpoint, monthly
Loading per protected endpoint
monthly, taken in advance
QTY
Fortify-XDRManual entry

Extended Detection, Cross Layer

SentinelOne · Fluency · identity, mail, network, and firewall telemetry

Everything the endpoint tier does, plus the records from your other systems folded into the same picture. One suspicious sign-in is noise. The same sign-in next to a new mailbox rule and a strange process is a story.

  • Sign-in and directory records from Microsoft 365 or Google Workspace.
  • Mail platform events, so an inbox rule change is visible next to the login.
  • Firewall and network logs where your equipment can send them.
  • Correlation lives in Fluency, so one event is judged against its neighbours.
SourcesEndpoint, identity, mail, network, and firewall records
CorrelationFluency, with rules maintained by our detection engineers
RetentionSearchable event history for investigations
Watched byFortify 24x7 analysts, continuously
Best fitAny business whose mail and identity live in Google Workspace or Microsoft 365
Priced byProtected endpoint, monthly
Loading per protected endpoint
monthly, taken in advance
QTY
Fortify-XDR+Manual entry

Extended Detection with Remediation

SentinelOne · Fluency · standing authority to act

The top tier. You give our team standing permission to contain, disable, and revoke without stopping to ask first. Response time drops to the time it takes to decide, which is the whole point of paying for it.

  • Isolate a machine, kill a process, or quarantine a file immediately.
  • Disable an account and cancel its live sessions when the sign-in is clearly stolen.
  • Actions and their reasons are written down as they happen.
  • The authority is yours to scope, and yours to withdraw in writing.
AuthorityPre-authorised containment, scoped in your service record
Endpoint actionsIsolation, process termination, file quarantine
Identity actionsAccount disable and session revocation, where connected
NotificationYou are informed as the action is taken, not days later
Best fitBusinesses with no staffed technical cover out of hours
Priced byProtected endpoint, monthly
Loading per protected endpoint
monthly, taken in advance
QTY
Fortify-MDR-K8Manual entry

Managed Detection, Kubernetes Node

SentinelOne · Kubernetes node sensor

The detection tier for a Kubernetes node, covering the containers scheduled on it. Priced by node rather than by pod, because pods come and go and nodes are what you actually run.

  • One sensor per node covers the workloads placed on that node.
  • Detections carry the container and image they came from.
  • Ephemeral workloads are handled without a licence count that moves hourly.
  • Runs alongside your existing cluster tooling.
ScopeOne Kubernetes node and the containers scheduled on it
SensorSentinelOne container sensor, deployed as a set
Watched byFortify 24x7 analysts, continuously
ContextDetections identify container and image
Best fitBusinesses running a cluster in production
Priced byKubernetes node, monthly
Loading per Kubernetes node
monthly, taken in advance
QTY
Fortify-XDR-K8Manual entry

Extended Detection, Kubernetes Node

SentinelOne · Fluency · Kubernetes node sensor

Node level detection with the cluster's activity correlated against the rest of your estate. A container reaching somewhere it never reached before is read next to what your identity and network records say.

  • Cluster events correlated with identity, mail, and network records.
  • Useful when the cluster holds customer data and the blast radius is wide.
  • Same node based pricing as the detection tier.
  • Investigations cover the cluster and the office, not one or the other.
ScopeOne Kubernetes node, correlated estate wide
CorrelationFluency, cluster events alongside identity and network
Watched byFortify 24x7 analysts, continuously
Best fitClusters holding regulated or customer data
Priced byKubernetes node, monthly
Loading per Kubernetes node
monthly, taken in advance
QTY
Fortify-XDR+K8Manual entry

Remediation Tier, Kubernetes Node

SentinelOne · Fluency · standing authority on cluster workloads

Correlated cluster detection with pre-authorised containment. Our team can act on a compromised workload at the moment it is identified, inside limits you set with us before anything happens.

  • Immediate containment of a workload judged compromised.
  • Scope agreed in advance so production is not stopped by surprise.
  • Every action logged with the evidence behind it.
  • Best paired with the same tier on the machines your engineers use.
AuthorityPre-authorised containment on cluster workloads
ScopeOne Kubernetes node, limits agreed in writing
CorrelationFluency, estate wide
Watched byFortify 24x7 analysts, continuously
Priced byKubernetes node, monthly
Loading per Kubernetes node
monthly, taken in advance
QTY

Where this rung stops

Detection is about what happens on machines and in accounts we can see. It is not a guarantee, and there are edges worth naming.

  • A machine without the agent is not covered. That includes personal laptops outside your management and any equipment we were not told about.
  • Detection does not undo a wire transfer. If somebody is talked into paying a fraudulent invoice, that is a mail and training problem, covered on rung 03.
  • Correlation on the extended tiers depends on your other systems being able to send us their records. Equipment too old to export logs cannot be folded in.
  • Kubernetes lines cover the node and the containers scheduled on it. They are not a substitute for the sensor on the machines your engineers actually work from.
  • A live break in is worked by the operations team through support, not by adding a subscription line. Say what you are seeing and we will tell you what happens next.

One more thing, stated where you can see it before you buy. Everything on this page is protective coverage bought in advance. It is not an emergency incident response retainer, and it does not put a responder on your site tomorrow because you subscribed today. An engagement of that kind is arranged directly with the Fortify 24x7 operations team. If something is under way as you read this, the quickest route to us is support@cyberthreat.help, or a case raised from your client portal.

Heads up: card statements show FORTIFY 24X7 - CyberThreat Help is a Fortify 24x7 brand, and your subscription is billed by Fortify 24x7.