Six lines of detection, running from one agent on one laptop up to a joined record that ties machine activity to sign in and cloud events. Every part of it is handled by duty staff at Fortify 24x7, since an alert that merely brightens a screen at three in the morning has accomplished precisely nothing.
A signature list is a record of what somebody else already caught. The agent here reads behaviour instead: a process that starts enumerating documents, a script that reaches for the credential store, a binary that unpacks itself and then tries to talk to an address nobody has heard of. None of that requires anyone to have seen the sample before.
For a crypto team the shapes worth catching are specific. Clipboard monitors that swap a destination address at the moment of paste. Infostealers that sweep browser profiles for session cookies and extension storage. Remote access tooling installed under the name of something dull. All of them look ordinary in a file listing and obvious in behaviour.
An endpoint agent sees the machine and stops there. Invisible to it: someone signing in from a city where nobody works, a mail rule quietly copying everything outward, a console session opened before dawn by a service account that has never kept late hours. Those sit in logs, and one at a time none of them proves a thing.
Joining them to the machine story inside one record is the moment a pattern stops looking like coincidence. It also means an awkward question raised a month and a half later can be answered from evidence, rather than from whoever happened to keep a log.
Billing supplies every figure below while the page loads. An entry holds its place while you go on reading.
A behavioural agent sits on every machine you enroll. Whatever it raises lands with a duty analyst, not on a screen in an unattended room. Where the activity begins to resemble a robbery underway, the network connection on that machine can be severed well before the reading is finished.
| Deposited on | Enrolled machines of any kind, whether Windows, macOS or Linux, one unit apiece |
|---|---|
| Seals | Malicious behaviour on the endpoint itself, with network isolation available |
| Held at | Detection telemetry in the SentinelOne tenant raised for your account |
| Sealed by | SentinelOne |
| Witnessed by | Duty analysts at Fortify 24x7, who take the alert and then write to you |
The same agent, with the records from around the machine pulled in beside it. Sign in events, mail activity and cloud console actions are correlated against what the agent saw, which is how an account takeover that never writes a file to disk still turns into a shape somebody can recognise.
| Deposited on | The same enrolled machines, with identity and cloud sources attached |
|---|---|
| Seals | Cross layer patterns that a single endpoint view cannot see on its own |
| Held at | Endpoint telemetry with correlated log data on the Fluency platform |
| Sealed by | SentinelOne, correlated on Fluency |
| Witnessed by | Fortify 24x7 analysts reading the joined record, not one feed |
Correlated detection with the heavier response package underneath. This is the tier for machines where a wrong answer is not survivable: the treasury workstation, the box that touches signing hardware, the laptop that holds the only copy of an operational runbook.
| Deposited on | The handful of machines whose compromise you could not absorb |
|---|---|
| Seals | The same cross layer patterns, with a heavier response package attached |
| Held at | Full fidelity endpoint telemetry plus the correlated log record |
| Sealed by | SentinelOne, correlated on Fluency |
| Witnessed by | Fortify 24x7 analysts with vendor response resource behind them |
The same managed watch, priced and deployed for cluster nodes instead of laptops. If you run indexers, relayers, validators or an internal API on Kubernetes, this is the line that covers the hosts underneath them.
| Deposited on | Kubernetes nodes, each node counted as one unit |
|---|---|
| Seals | Malicious runtime behaviour inside containers and on the node beneath them |
| Held at | Node and container telemetry in your SentinelOne tenant |
| Sealed by | SentinelOne |
| Witnessed by | Fortify 24x7 analysts, on the same rota as the endpoint lines |
Cluster nodes drawn into the joined picture. What the runtime turns up is placed beside identity and cloud activity, which matters when the real question is whether the credential that opened your cluster belonged to a colleague or to a laptop somebody walked off with.
| Deposited on | Kubernetes nodes, with cloud and identity sources correlated alongside |
|---|---|
| Seals | Runtime behaviour read together with control plane and identity activity |
| Held at | Node telemetry with the correlated log record on Fluency |
| Sealed by | SentinelOne, correlated on Fluency |
| Witnessed by | Fortify 24x7 analysts holding both halves of the picture |
The response package applied to cluster nodes. Reserve it for the infrastructure whose failure is not a bad afternoon but a public one, and price the rest of the cluster at a lighter tier rather than buying this everywhere.
| Deposited on | The cluster nodes that carry work you cannot pause |
|---|---|
| Seals | Runtime and control plane behaviour, with the heavier response package |
| Held at | Full fidelity node telemetry plus the correlated record |
| Sealed by | SentinelOne, correlated on Fluency |
| Witnessed by | Fortify 24x7 analysts with vendor response resource behind them |
Detection reports that something is under way and buys the chance to interrupt it. Guarantee is the wrong word for any part of that, and its reach ends at whichever machines and accounts got enrolled.
Heads up: card statements show FORTIFY 24X7 - Cryptinest is a Fortify 24x7 brand, and your subscription is billed by Fortify 24x7.