Something is already running.
The uncomfortable part of every serious incident is the gap. Somebody gets in on a Tuesday, and the business finds out the following Monday when the files stop opening. In between, they were reading mail, looking at the file server, and working out what you are worth.
That gap is what this rung shortens. Not by predicting who will attack you, which nobody can do honestly, but by watching what software actually does on your machines and reacting to the behaviour that only intruders exhibit.
Behaviour, not filenames.
The sensor is not comparing files against a list of known bad ones. It watches sequences. A document that spawns a script, a script that reaches out to a stranger, a process that starts renaming files in bulk: none of those is remarkable alone, and all of them together is one thing only.
Because the judgement is behavioural, software nobody has ever seen before is still catchable. And because the sensor keeps working when the network is unavailable, a laptop in a hotel is as covered as the machine in your office.
An analyst decides, then acts.
A tool that only sends alerts hands you a new job. Ours are read by analysts at the Fortify 24x7 desk on every shift, and what comes out of that is a decision rather than another notification. Isolate the machine, kill the process, leave it alone because it was your accountant running something unusual.
The three tiers on this page differ by how far the correlation reaches and how much authority you have given us in advance. The remediation tier lets us move first and inform you while we are moving, which is the only arrangement worth anything when the alarm sounds at three in the morning.
What this rung actually asks of you.
An agent has to be installed on every machine you want covered, and machines that are switched off are not being watched. Older hardware running very old operating systems may be out of support for the sensor, and we will tell you that during deployment rather than after you have paid.
There is also a settling in period. The first fortnight produces more questions from us than the months that follow, because we are still learning the shape of a normal day in your business. That is work, and it is worth doing properly.
Lines on this rung
6 lines · rates per unit, per monthManaged Detection and Response
Behavioural detection on the machine itself, watched by people who are paid to act on it. When something starts behaving like an intruder, the machine is isolated and you get a written account of what happened.
- Runs on Windows, macOS, and Linux, on hardware or in a cloud instance.
- Detection works from behaviour, so a file nobody has seen before is still catchable.
- Isolation is a decision an analyst makes, not a switch you are left holding.
- Every conviction arrives with the sequence of events that produced it.
| Sensor | SentinelOne agent, autonomous when the network is unavailable |
|---|---|
| Watched by | Fortify 24x7 analysts, continuously |
| Containment | Network isolation and process termination on analyst decision |
| Rollback | Available where the platform supports it, on Windows |
| Reporting | Written incident account with the timeline that led to it |
| Priced by | Protected endpoint, monthly |
monthly, taken in advance QTY
Extended Detection, Cross Layer
Everything the endpoint tier does, plus the records from your other systems folded into the same picture. One suspicious sign-in is noise. The same sign-in next to a new mailbox rule and a strange process is a story.
- Sign-in and directory records from Microsoft 365 or Google Workspace.
- Mail platform events, so an inbox rule change is visible next to the login.
- Firewall and network logs where your equipment can send them.
- Correlation lives in Fluency, so one event is judged against its neighbours.
| Sources | Endpoint, identity, mail, network, and firewall records |
|---|---|
| Correlation | Fluency, with rules maintained by our detection engineers |
| Retention | Searchable event history for investigations |
| Watched by | Fortify 24x7 analysts, continuously |
| Best fit | Any business whose mail and identity live in Google Workspace or Microsoft 365 |
| Priced by | Protected endpoint, monthly |
monthly, taken in advance QTY
Extended Detection with Remediation
The top tier. You give our team standing permission to contain, disable, and revoke without stopping to ask first. Response time drops to the time it takes to decide, which is the whole point of paying for it.
- Isolate a machine, kill a process, or quarantine a file immediately.
- Disable an account and cancel its live sessions when the sign-in is clearly stolen.
- Actions and their reasons are written down as they happen.
- The authority is yours to scope, and yours to withdraw in writing.
| Authority | Pre-authorised containment, scoped in your service record |
|---|---|
| Endpoint actions | Isolation, process termination, file quarantine |
| Identity actions | Account disable and session revocation, where connected |
| Notification | You are informed as the action is taken, not days later |
| Best fit | Businesses with no staffed technical cover out of hours |
| Priced by | Protected endpoint, monthly |
monthly, taken in advance QTY
Managed Detection, Kubernetes Node
The detection tier for a Kubernetes node, covering the containers scheduled on it. Priced by node rather than by pod, because pods come and go and nodes are what you actually run.
- One sensor per node covers the workloads placed on that node.
- Detections carry the container and image they came from.
- Ephemeral workloads are handled without a licence count that moves hourly.
- Runs alongside your existing cluster tooling.
| Scope | One Kubernetes node and the containers scheduled on it |
|---|---|
| Sensor | SentinelOne container sensor, deployed as a set |
| Watched by | Fortify 24x7 analysts, continuously |
| Context | Detections identify container and image |
| Best fit | Businesses running a cluster in production |
| Priced by | Kubernetes node, monthly |
monthly, taken in advance QTY
Extended Detection, Kubernetes Node
Node level detection with the cluster's activity correlated against the rest of your estate. A container reaching somewhere it never reached before is read next to what your identity and network records say.
- Cluster events correlated with identity, mail, and network records.
- Useful when the cluster holds customer data and the blast radius is wide.
- Same node based pricing as the detection tier.
- Investigations cover the cluster and the office, not one or the other.
| Scope | One Kubernetes node, correlated estate wide |
|---|---|
| Correlation | Fluency, cluster events alongside identity and network |
| Watched by | Fortify 24x7 analysts, continuously |
| Best fit | Clusters holding regulated or customer data |
| Priced by | Kubernetes node, monthly |
monthly, taken in advance QTY
Remediation Tier, Kubernetes Node
Correlated cluster detection with pre-authorised containment. Our team can act on a compromised workload at the moment it is identified, inside limits you set with us before anything happens.
- Immediate containment of a workload judged compromised.
- Scope agreed in advance so production is not stopped by surprise.
- Every action logged with the evidence behind it.
- Best paired with the same tier on the machines your engineers use.
| Authority | Pre-authorised containment on cluster workloads |
|---|---|
| Scope | One Kubernetes node, limits agreed in writing |
| Correlation | Fluency, estate wide |
| Watched by | Fortify 24x7 analysts, continuously |
| Priced by | Kubernetes node, monthly |
monthly, taken in advance QTY
Where this rung stops
Detection is about what happens on machines and in accounts we can see. It is not a guarantee, and there are edges worth naming.
- A machine without the agent is not covered. That includes personal laptops outside your management and any equipment we were not told about.
- Detection does not undo a wire transfer. If somebody is talked into paying a fraudulent invoice, that is a mail and training problem, covered on rung 03.
- Correlation on the extended tiers depends on your other systems being able to send us their records. Equipment too old to export logs cannot be folded in.
- Kubernetes lines cover the node and the containers scheduled on it. They are not a substitute for the sensor on the machines your engineers actually work from.
- A live break in is worked by the operations team through support, not by adding a subscription line. Say what you are seeing and we will tell you what happens next.
One more thing, stated where you can see it before you buy. Everything on this page is protective coverage bought in advance. It is not an emergency incident response retainer, and it does not put a responder on your site tomorrow because you subscribed today. An engagement of that kind is arranged directly with the Fortify 24x7 operations team. If something is under way as you read this, the quickest route to us is support@cyberthreat.help, or a case raised from your client portal.