A detection product has three parts, and any page showing only the first is selling a console. Part one weighs how a process actually behaves. Part two files that behaviour against everything else in the estate. Part three is a rostered person who reaches a decision at four in the morning. Six lines below, each carrying all three.
Signature lists went stale years ago, for the unglamorous reason that nobody trying to get in has ever seen yours. Conduct is what SentinelOne measures instead: processes spawned, files opened, addresses dialled, and whether the resulting pattern resembles somebody encrypting, hoarding or wandering about. The assessment forms locally, which is why a machine with no signal carries on forming it.
Filing is then Fluency's job. Authentication records, message records, traffic and logs drawn off tooling already inside your budget get stacked behind the agent's own account of events. Context is what allows a finding to be decided. Strip the context away and forwarding is the only move left, which happens to be most of what this industry ships.
Line one triages and advises. Line two broadens the field, so an odd authentication out of one country, beside an odd process on hardware in a different one, stop being two unexplained curiosities in separate windows. Line three arms response, which earns its keep across the hours when nobody anywhere is reading.
Three of the six lines exist purely for Kubernetes. Billing a node at laptop rates would misdescribe the agent and corrupt the arithmetic together, so the catalog holds the two apart. Nodes are the unit. Pods travel far too freely to measure.
Every figure below is taken from billing as this page loads. Whatever goes onto the tray remains there while you read on.
The agent studies how a process behaves; the desk decides what that behaviour means. Nothing lands in your inbox as a graph awaiting interpretation. It lands as a written finding with a recommended next step underneath it.
| Runs on | Endpoints under Linux, macOS or Windows |
|---|---|
| Reacts to | How a process behaves once it is already executing |
| Shelved for | Offices with nobody rostered to watch a console |
| Cleared by | Fortify 24x7 analysts, whatever the hour |
| Assayed by | Counted per protected endpoint, each month |
Same agent, wider field of view. Authentication records, message records and network traffic all get read against the endpoint, instead of sitting apart in windows nobody ever gets round to reconciling.
| Runs on | Endpoints, plus identity, mail and network sources |
|---|---|
| Reacts to | Shapes that only surface when sources are read together |
| Shelved for | Offices living inside a Microsoft or Google tenant |
| Cleared by | Fortify 24x7 analysts, whatever the hour |
| Assayed by | Counted per protected endpoint, each month |
Correlation with hands attached. Firm conviction pulls the endpoint out of the network and returns whatever it changed, the entire sequence completing before anyone has finished reading the file.
| Runs on | Endpoints under Linux, macOS or Windows, response armed |
|---|---|
| Reacts to | Conviction crossing a threshold, at any hour of the night |
| Shelved for | Signing hosts, build boxes, finance workstations |
| Cleared by | One analyst signs off each automated step |
| Assayed by | Counted per protected endpoint, each month |
Container workloads take their own lines and their own unit. Your platform engineer already carries the node count in their head, so nodes are what the invoice counts.
| Runs on | Kubernetes nodes |
|---|---|
| Reacts to | What a workload does after it has started running |
| Shelved for | Clusters holding anything you would miss on a Friday |
| Cleared by | Fortify 24x7 analysts, whatever the hour |
| Assayed by | Counted per Kubernetes node, each month |
Node coverage with correlation running, so cluster activity gets weighed against authentication records and laptop activity rather than marooned in a console of its own.
| Runs on | Kubernetes nodes, tied to endpoint and identity sources |
|---|---|
| Reacts to | Cluster activity weighed against the rest of the record |
| Shelved for | Clusters answering to the same logins as your laptops |
| Cleared by | Fortify 24x7 analysts, whatever the hour |
| Assayed by | Counted per Kubernetes node, each month |
Node coverage, response armed, for clusters holding something nobody wants running badly across a weekend.
| Runs on | Kubernetes nodes, with response armed |
|---|---|
| Reacts to | A workload stepping over the response threshold |
| Shelved for | Production clusters carrying customer traffic |
| Cleared by | One analyst signs off each automated step |
| Assayed by | Counted per Kubernetes node, each month |
Good control, poor guarantee. These six lines reach a long way, and here is precisely what they leave to somebody else.
Heads up: card statements show FORTIFY 24X7 - H2 Tech Systems is a Fortify 24x7 brand, and your subscription is billed by Fortify 24x7.