A Fortify 24x7 brand. Security engineering for the companies that build things.Client sign inTalk to an engineer
EagleTech Innovations
Sheet 03 / Detection and response

Something already runs on every machine. The question is who notices.

Detection is not a dashboard you are supposed to check. It is an agent that understands what a process is doing, a correlation layer that ties that to everything else happening in your estate, and a person who decides what to do about it at four in the morning. All three come with every line on this sheet.

SentinelOneFluency24x7 analyst desk
6 lines / 3 response tiers / endpoint and node
Lines on this sheet6
PlatformsSentinelOne + Fluency
Rate basisEndpoint or node
DeskStaffed 24 hours

What the agent is genuinely watching

Matching known signatures stopped being sufficient a long while ago. The SentinelOne agent models behavior on the machine itself: what a process spawned, which files it touched, where it reached out to, and whether that shape resembles encryption, collection, or somebody quietly walking a network. It carries on deciding with no connection at all, which is what you want on a laptop mid flight and on the build box somebody abandoned on a bench.

Fluency takes what the agents report and joins it to the rest of the picture: sign in events, mail events, network telemetry, and logs from tools you already own. By the time an alert reaches our desk it carries enough context to be decidable, and that gap is exactly what separates being told from being helped.

By the time an alert reaches our desk it carries enough context to be decidable.

How to pick a tier

The detection line triages and advises. The extended line widens what gets correlated, so a suspicious sign in from one country and a strange process on a laptop in another stop being two unrelated curiosities. The response tier adds automated containment and rollback, which is what you want when it kicks off during the small hours of a weekend.

Kubernetes nodes are priced on their own lines. A node is not a laptop, the agent behaves differently, and rolling them into an endpoint count would make the invoice quietly dishonest. Count nodes, not pods.

Lines on this sheet

Specifications and rates

Prices below are pulled straight out of billing. Anything you add sits in your basket while you carry on reading.

Fortify-MDRSpecification

Managed Detection and Response

SentinelOne on the box · Fluency joining it up · analyst triage

Behavioral detection on the endpoint with a staffed desk behind it. Alerts are worked by people and reach you with a recommendation attached rather than a chart to interpret.

  • Agent covers Windows, macOS, and Linux, and keeps deciding while offline.
  • Triage, investigation, and escalation all worked at the Fortify 24x7 desk.
  • Case history and findings readable from your client portal at any hour.
PlatformSentinelOne, with Fluency correlation
CoverageWindows, macOS, Linux
ResponseNotification, guidance, and assisted remediation
OfflineDetection continues with no connectivity
DeskFortify 24x7 engineers, whatever the hour
Rate basisProtected endpoint, monthly
Fetchingper protected endpoint
billed monthly, up front
QTY
Fortify-XDRSpecification

Extended Detection Across Layers

SentinelOne, widened by Fluency across sources

Everything the detection line does, widened so identity, mail, and network signal are read alongside the endpoint instead of in separate windows.

  • Endpoint telemetry joined to sign in, mail, and network events.
  • Detections that no single agent could reach on its own evidence.
  • Longer retention, because some investigations only make sense in hindsight.
PlatformSentinelOne with extended Fluency correlation
SourcesEndpoint, identity, mail, network
ResponseNotification, guidance, and assisted remediation
RetentionExtended, for retrospective investigation
Best fitTeams already living in a Microsoft or Google tenant
Rate basisProtected endpoint, monthly
Fetchingper protected endpoint
billed monthly, up front
QTY
Fortify-XDR+Specification

Extended Detection with Response

SentinelOne, with containment and rollback automated

The correlated tier with hands. A machine that crosses the response threshold gets isolated and reverted while the analyst is still reading the case.

  • Automatic isolation of an endpoint once conviction is confident enough.
  • Reversal of whatever a convicted process altered, on systems that support it.
  • Every automated action reviewed by a person afterwards and written up.
PlatformSentinelOne with automated response
ContainmentNetwork isolation of the affected endpoint
RollbackUndoes what a convicted process altered, where supported
OversightHuman review of each automated action, after the fact
Best fitSigning hosts, build machines, finance workstations
Rate basisProtected endpoint, monthly
Fetchingper protected endpoint
billed monthly, up front
QTY
Fortify-MDR-K8Specification

Managed Detection, Kubernetes Node

SentinelOne, watching container workloads

Detection for containerized workloads, counted by node so the invoice matches the number your platform engineer already knows.

  • Node level agent covering the workloads scheduled onto that node.
  • Same desk, same triage process, and same case flow as the endpoint lines.
  • Runtime visibility into container behavior rather than image scanning alone.
PlatformSentinelOne for Kubernetes
ScopeRuntime behavior of workloads on the node
ResponseNotification, guidance, and assisted remediation
DeskFortify 24x7 engineers, whatever the hour
Rate basisKubernetes node, monthly
Fetchingper Kubernetes node
billed monthly, up front
QTY
Fortify-XDR-K8Specification

Extended Detection, Kubernetes Node

SentinelOne on nodes, joined to the estate by Fluency

Node detection with the correlation layer switched on, so cluster activity is read next to identity and endpoint events rather than in isolation.

  • Node telemetry correlated with the rest of your estate in Fluency.
  • Detections that span a workload and the identity that reached it.
  • Extended retention across cluster and endpoint sources together.
PlatformSentinelOne for Kubernetes with Fluency correlation
SourcesNode runtime, identity, endpoint, network
ResponseNotification, guidance, and assisted remediation
RetentionExtended, for retrospective investigation
Rate basisKubernetes node, monthly
Fetchingper Kubernetes node
billed monthly, up front
QTY
Fortify-XDR+K8Specification

Response Tier, Kubernetes Node

SentinelOne, containing container workloads on its own

The node line with automated response attached, for clusters that run something you cannot afford to leave misbehaving until office hours.

  • Automated containment of a workload that crosses the response threshold.
  • Correlated case built across cluster, identity, and endpoint evidence.
  • Human review of each automated action, recorded and sent to you.
PlatformSentinelOne for Kubernetes with automated response
ContainmentAutomated action against the offending workload
OversightHuman review of each automated action, after the fact
Best fitProduction clusters carrying customer workloads
Rate basisKubernetes node, monthly
Fetchingper Kubernetes node
billed monthly, up front
QTY
Honest scope

Where this sheet stops

Detection makes a fine control and a lousy guarantee. Here is what these six lines do not reach, stated plainly so you can decide what else you need.

  • Detection is not prevention. An agent that recognizes an intrusion is telling you something has already begun. Speed of response is the product; a guarantee that nothing starts is not on offer here or anywhere else.
  • Your own code is not in scope. A flaw in the product you ship is invisible to an endpoint agent. Application security testing and code review are separate work and we will point you at them rather than imply this covers it.
  • A machine without an agent produces nothing. Devices that never enroll generate no telemetry, appear in no investigation, and are not covered by any line on this sheet.
  • Rollback is not backup. The response tier reverses what a convicted process changed on supported systems. It does not restore a failed drive or an old version of a file. That is the backup and continuity sheet.
  • Kubernetes lines cover the nodes. Your cluster architecture, role bindings, secrets handling, and admission policy stay yours to design. We will advise; we do not own them.
NOTE 01

Heads up: card statements show FORTIFY 24X7 - EagleTech Innovations is a Fortify 24x7 brand, and your subscription is billed by Fortify 24x7.