A Fortify 24x7 brand. Subscriptions that guard the people, the machines and the mailboxes standing around a set of keys.Portal sign inWrite to a custodian
Cryptinest
Chamber 01 / Deep watch

Somebody has to be awake when the machine is not.

Six lines of detection, running from one agent on one laptop up to a joined record that ties machine activity to sign in and cloud events. Every part of it is handled by duty staff at Fortify 24x7, since an alert that merely brightens a screen at three in the morning has accomplished precisely nothing.

SentinelOneFluencyIsolation from the consoleAnalysts on rota
Lines held here6
MakersSentinelOne, Fluency
UnitEndpoint or a cluster node
StaffedAround the clock, by us

What the agent is looking for

A signature list is a record of what somebody else already caught. The agent here reads behaviour instead: a process that starts enumerating documents, a script that reaches for the credential store, a binary that unpacks itself and then tries to talk to an address nobody has heard of. None of that requires anyone to have seen the sample before.

For a crypto team the shapes worth catching are specific. Clipboard monitors that swap a destination address at the moment of paste. Infostealers that sweep browser profiles for session cookies and extension storage. Remote access tooling installed under the name of something dull. All of them look ordinary in a file listing and obvious in behaviour.

An alert that only lights up a screen has not been handled. It has been displayed.

Where correlation earns its price

An endpoint agent sees the machine and stops there. Invisible to it: someone signing in from a city where nobody works, a mail rule quietly copying everything outward, a console session opened before dawn by a service account that has never kept late hours. Those sit in logs, and one at a time none of them proves a thing.

Joining them to the machine story inside one record is the moment a pattern stops looking like coincidence. It also means an awkward question raised a month and a half later can be answered from evidence, rather than from whoever happened to keep a log.

Lines held in this chamber

Records and rates

Billing supplies every figure below while the page loads. An entry holds its place while you go on reading.

Fortify-MDRDeposit record

Managed Detection and Response

A SentinelOne agent below, Fortify 24x7 analysts above

A behavioural agent sits on every machine you enroll. Whatever it raises lands with a duty analyst, not on a screen in an unattended room. Where the activity begins to resemble a robbery underway, the network connection on that machine can be severed well before the reading is finished.

  • Judgement is made on behaviour, so a stealer compiled this morning with no reputation anywhere still trips it.
  • Whatever hour it happens, an alert reaches staff here, and that includes the hours when nobody is looking at a signing laptop.
  • Isolation is a console action, not a site visit, so a suspect machine stops talking to anything within minutes.
  • Where the agent recorded enough of a change, encrypted files can be wound back to their earlier state under Windows.
Deposited onEnrolled machines of any kind, whether Windows, macOS or Linux, one unit apiece
SealsMalicious behaviour on the endpoint itself, with network isolation available
Held atDetection telemetry in the SentinelOne tenant raised for your account
Sealed bySentinelOne
Witnessed byDuty analysts at Fortify 24x7, who take the alert and then write to you
Loading rateper protected endpoint
renewing every month
UNITS
Fortify-XDRDeposit record

Extended Detection Across Layers

Endpoint signal joined to identity and cloud signal, on Fluency

The same agent, with the records from around the machine pulled in beside it. Sign in events, mail activity and cloud console actions are correlated against what the agent saw, which is how an account takeover that never writes a file to disk still turns into a shape somebody can recognise.

  • Correlation runs on Fluency, so one story is assembled out of sources that would otherwise be read in isolation.
  • A session token stolen from a browser leaves traces in identity logs long before it leaves any on the endpoint.
  • Impossible travel, unfamiliar consent grants and out of hours console work are the patterns most worth catching early.
  • Because the joined record is retained, a query raised weeks later still has somewhere to land.
Deposited onThe same enrolled machines, with identity and cloud sources attached
SealsCross layer patterns that a single endpoint view cannot see on its own
Held atEndpoint telemetry with correlated log data on the Fluency platform
Sealed bySentinelOne, correlated on Fluency
Witnessed byFortify 24x7 analysts reading the joined record, not one feed
Loading rateper protected endpoint
renewing every month
UNITS
Fortify-XDR+Deposit record

Extended Detection with Response

The correlated tier with vendor response resource behind it

Correlated detection with the heavier response package underneath. This is the tier for machines where a wrong answer is not survivable: the treasury workstation, the box that touches signing hardware, the laptop that holds the only copy of an operational runbook.

  • Deeper forensic capture on the endpoint, so the reconstruction afterwards is not guesswork.
  • Vendor side response resource sits behind our analysts for the incidents that outgrow a single desk.
  • Hunting queries are pushed across the estate on their own schedule instead of sitting idle until something fires.
  • Concentrate it on a handful of machines; spreading it evenly across the estate wastes the money.
Deposited onThe handful of machines whose compromise you could not absorb
SealsThe same cross layer patterns, with a heavier response package attached
Held atFull fidelity endpoint telemetry plus the correlated log record
Sealed bySentinelOne, correlated on Fluency
Witnessed byFortify 24x7 analysts with vendor response resource behind them
Loading rateper protected endpoint
renewing every month
UNITS
Fortify-MDR-K8Deposit record

Managed Detection, Kubernetes Node

The node agent for clustered workloads

The same managed watch, priced and deployed for cluster nodes instead of laptops. If you run indexers, relayers, validators or an internal API on Kubernetes, this is the line that covers the hosts underneath them.

  • A node is a unit here, not a pod, so the count follows the cluster and not the workload churn.
  • Container escape, crypto mining implants and tampered images are the behaviours this is aimed at.
  • Watching a container while it runs is a different job from scanning an image in the pipeline, and one will not stand in for the other.
  • Alerting reaches the same desk, so cluster findings do not live in a queue of their own.
Deposited onKubernetes nodes, each node counted as one unit
SealsMalicious runtime behaviour inside containers and on the node beneath them
Held atNode and container telemetry in your SentinelOne tenant
Sealed bySentinelOne
Witnessed byFortify 24x7 analysts, on the same rota as the endpoint lines
Loading rateper Kubernetes node
renewing every month
UNITS
Fortify-XDR-K8Deposit record

Extended Detection, Kubernetes Node

Node level detection joined to the wider record

Cluster nodes drawn into the joined picture. What the runtime turns up is placed beside identity and cloud activity, which matters when the real question is whether the credential that opened your cluster belonged to a colleague or to a laptop somebody walked off with.

  • Cluster events are read beside cloud control plane activity rather than apart from it.
  • A service account behaving unlike itself is easier to spot when its history is stored somewhere.
  • Suits teams whose infrastructure and whose staff are equally worth targeting.
  • Node count remains the billing unit, so scaling pods does not scale the invoice.
Deposited onKubernetes nodes, with cloud and identity sources correlated alongside
SealsRuntime behaviour read together with control plane and identity activity
Held atNode telemetry with the correlated log record on Fluency
Sealed bySentinelOne, correlated on Fluency
Witnessed byFortify 24x7 analysts holding both halves of the picture
Loading rateper Kubernetes node
renewing every month
UNITS
Fortify-XDR+K8Deposit record

Response Tier, Kubernetes Node

The heaviest node tier, for infrastructure that cannot stall

The response package applied to cluster nodes. Reserve it for the infrastructure whose failure is not a bad afternoon but a public one, and price the rest of the cluster at a lighter tier rather than buying this everywhere.

  • Full capture on the node, so an investigation does not stop at the first missing detail.
  • Vendor response resource is available for cluster incidents, not just endpoint ones.
  • Hunting runs across the cluster on a schedule instead of only after something fires.
  • Mixing tiers across a cluster is normal and we will help you draw the line.
Deposited onThe cluster nodes that carry work you cannot pause
SealsRuntime and control plane behaviour, with the heavier response package
Held atFull fidelity node telemetry plus the correlated record
Sealed bySentinelOne, correlated on Fluency
Witnessed byFortify 24x7 analysts with vendor response resource behind them
Loading rateper Kubernetes node
renewing every month
UNITS
Honest scope

Where deep watch stops

Detection reports that something is under way and buys the chance to interrupt it. Guarantee is the wrong word for any part of that, and its reach ends at whichever machines and accounts got enrolled.

  • It cannot reverse a transaction. Once a signature is broadcast it is settled, and no line on this site changes that. What detection can do is catch the intrusion in the hours before somebody reaches the point of signing.
  • It does not custody anything. We never hold your keys, your seed material or your funds, and we never ask for them. No Fortify 24x7 engineer will ever request a seed phrase, and any message claiming otherwise is not from us.
  • Coverage stops at enrolment. A personal laptop that never got an agent is not watched. Neither is the phone your co-founder uses for signing if it was never enrolled.
  • Isolation is quick, not instant. From the moment an analyst calls it, cutting a machine off the network runs in minutes. Rapid and prevented are two different words. Prevention is the blast door.
  • It is not insurance. There is no payout attached to any of this. If you want cover for loss, that is a separate conversation with an underwriter, and we are happy to describe our controls to one.
SEAL NOTE

Heads up: card statements show FORTIFY 24X7 - Cryptinest is a Fortify 24x7 brand, and your subscription is billed by Fortify 24x7.