Nobody here expects you to remember to open a screen. Detection is software with an opinion about how a program is behaving, a layer setting that opinion beside four other feeds, and a person in a chair who rules on the result at twenty past four. Every line below arrives with all three.
Signature lists stopped earning their keep a long while back. Conduct is what the SentinelOne agent reads instead. Parent and child. Files touched. Addresses dialled. Whether the run of it looks like a ransom note being prepared, like material being gathered up, or like a stranger working a corridor testing handles. Unplug the network and the ruling still happens, which matters for the laptop taken home and for the box behind the stock room door nobody has touched since Easter.
Whatever the agent writes then gets set alongside the rest of the afternoon by Fluency: who authenticated, what came in by mail, what went out onto the wire, plus whatever your other tooling was writing at the time. Anything reaching this chair has enough context around it for a ruling. The gap between an alert and a ruling is the gap between notification and help.
Line one rules and advises. Line two widens the chair, so an implausible login and a peculiar process in the back office stop being filed as separate oddities. Line three hands over standing authority to act unaccompanied, and at three on a Sunday the alternative involves waking somebody up first.
Nodes are priced separately. A node resembles a desk in no way whatsoever, the agent behaves differently up there, and folding nodes quietly into a desk count makes an invoice untrue. Nodes are what get counted. Pods are not. If that sentence meant nothing, then these three lines do not belong on your board, and nobody here will push them.
Billing supplies each figure below as the page draws. Add a line and it sits on the board while you read further down.
Software on the computer forms an opinion about how a program is behaving. Somebody at this console then forms an opinion about the software. You are handed the second opinion, in a sentence, with the reasoning under it.
| Position | Threat console, chair never empty |
|---|---|
| Watches for | Programs behaving like ransomware, like a collector, or like somebody quietly trying doors along a corridor |
| Log kept | The evidence, the analyst reasoning, and the action, filed under your account |
| Escalation path | Analyst raises a callout, then reaches the contact you nominated by mail |
| Sign-off | Closed by an engineer who states what it turned out to be, in plain words |
Widen the chair. Sign-ins, mail and traffic get lined up beside what the computer reported, and a login from somewhere odd stops being filed separately from a peculiar program running in the back office.
| Position | Threat console, neighbouring feeds switched in |
|---|---|
| Watches for | Sequences that only become obvious once four separate feeds are laid out together |
| Log kept | A joined timeline naming every feed that carried part of the sequence |
| Escalation path | Analyst raises the callout with the assembled timeline already attached |
| Sign-off | Closed by an engineer who names which feed carried the first useful signal |
Same watch, plus standing authority. Past the agreed line, the box gets cut from the network and its changes wound back, while the analyst catches up on paperwork afterwards. On a Sunday at three, waiting is the expensive option.
| Position | Threat console, standing authority granted in advance |
|---|---|
| Watches for | The same behaviour as the two tiers above, measured against the line you agreed |
| Log kept | Each automatic move, what tripped it, and the human read-back afterwards |
| Escalation path | The machine comes off the wire first; the call to your contact follows |
| Sign-off | An engineer either endorses the move or undoes it and tells you which and why |
Cover for containerised workloads, billed by node, a number your platform engineer could recite from memory. Never heard of Kubernetes? Then this line and the two after it are not yours, and we will say so.
| Position | Threat console, node watch |
|---|---|
| Watches for | How the workloads on a node behave once they are actually running |
| Log kept | Container evidence with the node and the workload both named in the file |
| Escalation path | Analyst raises a callout and reaches whoever owns your platform |
| Sign-off | Closed once the workload is explained, patched or taken out of the cluster |
Node cover with neighbouring feeds switched in. Cluster activity gets read against whichever account reached it, not off in a tab by itself.
| Position | Threat console, node watch with neighbouring feeds switched in |
|---|---|
| Watches for | Cluster activity measured against the identities and desktops that touched it |
| Log kept | A single timeline across node, identity, desktop and network |
| Escalation path | Analyst raises the callout to your platform contact with the timeline attached |
| Sign-off | Closed by an engineer who names the feed that carried the first useful signal |
Node cover carrying standing authority, for a cluster holding something you would sooner not leave misbehaving until somebody signs on again on Monday.
| Position | Threat console, node watch with standing authority granted |
|---|---|
| Watches for | Workload behaviour measured against the line you agreed during rollout |
| Log kept | The move made, the evidence under it, and the read-back that followed |
| Escalation path | Shut down first, then the call to whoever owns your platform |
| Sign-off | An engineer endorses the move, or reverses it and explains the judgement |
Detection is a decent control and a hopeless guarantee. The gaps are written out below, plainly, so that you can fill them knowingly.
Heads up: card statements show FORTIFY 24X7 - SecureOps Solutions is a Fortify 24x7 brand, and your subscription is billed by Fortify 24x7.