01 / SENSOR
SentinelOne Complete on the endpoint
The agent runs static and behavioral models locally, so conviction does not wait on a cloud
round trip and does not stop when the laptop leaves your network. It carries next-generation
antivirus and full EDR telemetry, records the process lineage behind a detection, and holds
the rollback capability that makes a ransomware event survivable rather than final.
Vendor: SentinelOne · Included at MDR, XDR and XDR+
02 / ANALYTICS
Fluency across the other four planes
An endpoint alert on its own is a fragment. Fluency ingests email, cloud workloads across
AWS, Azure and GCP, network traffic, and Active Directory alongside the agent stream, then
joins them on shared entities so one attack path appears as one case. This is the layer that
separates XDR from a well-tuned EDR console, and it starts at the Fortify-XDR tier.
Vendor: Fluency · Included at XDR and XDR+
03 / ANALYSTS
A security operations center already staffed
Fortify 24x7 runs the shift rota, the hunting queue, and the escalation path. Every tier is
monitored around the clock. At Fortify-XDR+ the mandate widens: our analysts perform direct
remediation on identified events rather than writing them up and waiting for your morning.
Operated by Fortify 24x7 · Monitoring at every tier