A screen nobody opens is not detection. Detection needs three things at once: software on the machine able to tell a harmful sequence from an ordinary one, a layer that gathers evidence from everywhere else, and a human being on shift. Every line on this page carries all three.
Names and hashes stopped being useful years ago. The agent instead reads a whole sequence: which program started which, what was opened, what was written over, where traffic went, and whether the whole shape resembles encryption, hoarding, or a slow walk across a network. That judgement is made locally, so a laptop on a plane and a build box abandoned in a cupboard are both still being judged.
Fluency then sets that beside everything else on record: logins, messages, traffic, and the logs of whatever tools you were paying for beforehand. Something arriving already framed can be acted upon. Something arriving alone has to be researched from scratch, and by then the night has gone.
Level one observes and advises. Level two widens what gets read in a single pass, which is how an unusual login in one place and an unusual program somewhere else stop being filed as two coincidences. The third acts unaided, isolating and reverting without waiting for anybody to be woken.
Kubernetes nodes are billed apart, and deliberately. A node is no workstation, an agent behaves differently on one, and pretending otherwise would print a wrong number on your invoice. Nodes get counted. Pods do not.
Every figure below comes out of billing while this page draws. Anything entered waits inside the almanac, and reading on will not disturb it.
Judgement happens on the machine, about sequences rather than filenames, and a desk at Fortify 24x7 carries people through the night so a conviction raised while the office is empty gets read by somebody. What reaches your end is a finding with a recommendation attached, not a chart to puzzle over.
| Sighted on | macOS, Windows and Linux endpoints |
|---|---|
| Tracks | Program sequences, file activity and outbound connections |
| Archived for | Case history retained, telemetry window fixed while scoping |
| Resolved by | Fortify 24x7 engineers, advising and helping with the clean up |
| Observed by | SentinelOne, read alongside Fluency |
Identical agent, wider aperture. Login records, message events and network telemetry are read in the same pass as the endpoint evidence, which is how a peculiar sign in over here and a peculiar program over there arrive as one thing instead of two unconnected oddities.
| Sighted on | Endpoints, plus whichever identity, mail and network sources you connect |
|---|---|
| Tracks | Program sequences joined to sign in, message and traffic records |
| Archived for | A widened window, so an older signal remains re-readable |
| Resolved by | Fortify 24x7 engineers, advising and helping with the clean up |
| Observed by | SentinelOne, read alongside Fluency |
The widened line, with hands. A machine over the threshold gets pulled off the network, then put back as it stood, all while an engineer is still reading. Automation handles whatever cannot wait for a person to wake. Reviewing it later is the part that can.
| Sighted on | macOS, Windows and Linux endpoints, with correlated sources |
|---|---|
| Tracks | Program sequences, and whatever a convicted program touched |
| Archived for | A widened window, alongside a note on every automated action |
| Resolved by | Isolation and reversal, then an engineer reading back over it |
| Observed by | SentinelOne, read alongside Fluency |
Detection for containerised work, counted by the node, so an invoice matches whatever figure a platform engineer already carries about. Nodes behave nothing like workstations, an agent sits differently on them, and merging the two would print a wrong number on the bill.
| Sighted on | Kubernetes nodes and the workloads placed on them |
|---|---|
| Tracks | Runtime behaviour inside live containers |
| Archived for | Case history retained, telemetry window fixed while scoping |
| Resolved by | Fortify 24x7 engineers, advising and helping with the clean up |
| Observed by | SentinelOne for Kubernetes |
Nodes watched with correlation switched on, which means cluster activity is read beside identity and endpoint evidence rather than in a window all its own. A workload behaving strangely and an account behaving strangely arrive as one case.
| Sighted on | Kubernetes nodes, endpoints, identity and network sources |
|---|---|
| Tracks | Container runtime behaviour joined to sign in and endpoint records |
| Archived for | A widened window, so an older signal remains re-readable |
| Resolved by | Fortify 24x7 engineers, advising and helping with the clean up |
| Observed by | SentinelOne for Kubernetes, read alongside Fluency |
The node line with response attached, for clusters carrying something you would rather not leave misbehaving until the office opens. Containment lands first and the write up follows, which at three in the morning is the useful order to do things in.
| Sighted on | Kubernetes nodes carrying production workloads |
|---|---|
| Tracks | Container runtime behaviour, and what a workload reached for |
| Archived for | A widened window, alongside a note on every automated action |
| Resolved by | Automatic containment, then an engineer reading back over it |
| Observed by | SentinelOne for Kubernetes, read alongside Fluency |
Detection is an excellent control and a dreadful promise. Below sits everything the six lines here never manage to reach.
Heads up: card statements show FORTIFY 24X7 - Starlight IT Services is a Fortify 24x7 brand, and your subscription is billed by Fortify 24x7.