An alert has no value until somebody decides what it means and what happens next. Six entries set an agent onto the machine, put something above it that reads identity and mail records beside the endpoint, and place an engineer on the decision before dawn so nobody at your practice has to take it.
Signature matching lost its usefulness some years back. The SentinelOne agent assembles a picture of conduct locally: what spawned what, which files came open, which addresses got reached, and whether that shape reads as encryption, as collection, or as somebody stepping sideways in the quiet. That judgement carries on offline, which is what counts on a laptop between airports and on the workstation nobody switched off in a back office.
Fluency then sets those reports against everything else your practice generates: authentication events, message flow, network records, and the logs of tools already sitting on your invoice. An item landing on our desk arrives with enough around it to be decided. That difference, between being informed of a problem and being assisted with one, is the whole purpose of a correlation layer.
The first grade triages and advises. The second broadens what gets set beside what, so an unexpected authentication in one place and a peculiar process in another cease arriving as two curiosities nobody connects. A third grade adds containment and reversal that fire without waiting on a human, which is the behavior a practice wants out of a control on a Sunday at two.
Nodes get entries to themselves. A node resembles no workstation; an agent conducts itself unlike itself there; folding one into an endpoint tally sets a quiet untruth onto an invoice. Count nodes. Pods belong to somebody else's arithmetic.
Billing hands over every figure below at page load. Present while you read; a quantity stands until you alter it.
Judgement is made on what a process does, never on the name it wears, and a staffed desk decides what follows. Your practice receives a decision it can act on rather than a chart wanting interpretation.
| Settles on | SentinelOne agent, installed once per machine |
|---|---|
| Nets | A single endpoint, on any operating system this book covers |
| Value date | Opens at enrollment, the moment the agent first checks in |
| Cleared by | Fortify 24x7 desk staff, at whichever hour it is |
| Reconciled by | Item notes and conclusions, filed against your record |
Authentication activity, message activity, and network records are read next to the machine, not across three unconnected windows. An unexpected login somewhere and a peculiar process somewhere else stop arriving as separate curiosities.
| Settles on | SentinelOne agent with Fluency correlation behind it |
|---|---|
| Nets | A single endpoint, plus its portion of the bound record |
| Value date | Opens once your first source has finished connecting |
| Cleared by | Fortify 24x7 desk staff, at whichever hour it is |
| Reconciled by | Bound case files, held for examination after the fact |
The bound grade, fitted with hands. Any machine over the threshold departs the network and reverts, the entire sequence running under an analyst who still has the file open.
| Settles on | SentinelOne agent with automated response switched on |
|---|---|
| Nets | A single endpoint, isolation and undo included |
| Value date | Arms at the close of the tuning stretch |
| Cleared by | Automation first, a Fortify 24x7 engineer on review after |
| Reconciled by | Each automatic action, written up once it has run |
Detection across containerized workloads, tallied by node, so the invoice figure is one your platform engineer already maintains. Count nodes. Pods belong to somebody else's arithmetic.
| Settles on | SentinelOne for Kubernetes, an agent on every node |
|---|---|
| Nets | One node of a cluster, whatever it happens to run |
| Value date | Opens as soon as the node agent registers |
| Cleared by | Fortify 24x7 desk staff, at whichever hour it is |
| Reconciled by | Item notes and conclusions, filed against your record |
The node entry with correlation running. Cluster activity gets read against whoever reached into it, a separate question from what a workload manages unaided.
| Settles on | Fluency correlation over SentinelOne for Kubernetes |
|---|---|
| Nets | One node of a cluster, plus its portion of the bound record |
| Value date | Opens once your first source has finished connecting |
| Cleared by | Fortify 24x7 desk staff, at whichever hour it is |
| Reconciled by | Bound case files, held for examination after the fact |
The node entry with response fitted, for clusters carrying work that cannot simply misbehave from Friday to Monday.
| Settles on | SentinelOne for Kubernetes, automated response enabled |
|---|---|
| Nets | One node of a cluster, containment included |
| Value date | Arms at the close of the tuning stretch |
| Cleared by | Automation first, a Fortify 24x7 engineer on review after |
| Reconciled by | Each automatic action, written up once it has run |
As a control, detection is excellent. As a guarantee it is hopeless. What these six entries decline to do is set out below, plainly, so that nobody buys expecting otherwise.
Heads up: card statements show FORTIFY 24X7 - FinShield Tech is a Fortify 24x7 brand, and your subscription is billed by Fortify 24x7.