A Fortify 24x7 brand. Detection engineering and analyst response, run from a staffed security operations center.Client sign inContact
S1XDR
Home / Tier matrix / XDR platform
Detection tiers · six SKUs

The Fortify XDR platform

One agent, five telemetry planes, and a shift rota that never hands the console back to you at 2am.

Detection tiersRates drawn live from the billing catalog
Fortify MDRFortify-MDR

The SentinelOne Complete agent under continuous watch from our operations center. Endpoint scope only, with escalation to your team.

per endpoint
billed monthly
Loading
QTY
Fortify XDRFortify-XDR

Adds Fluency correlation across email, cloud workloads, network, and Active Directory, with the integrated NGAV, EDR, UEBA, NTA, CWP, and SIEM module set.

per endpoint
billed monthly
Loading
QTY
Fortify XDR+Fortify-XDR+

The flagship. Everything in XDR, and our analysts perform direct remediation on every event they identify.

per endpoint
billed monthly
Loading
QTY
Fortify MDR for KubernetesFortify-MDR-K8

The MDR scope delivered by the SentinelOne Complete Kubernetes agent, counted per node.

per node
billed monthly
Loading
QTY
Fortify XDR for KubernetesFortify-XDR-K8

The XDR scope on the Kubernetes agent, with container telemetry joined into the same correlation graph as the rest of the estate.

per node
billed monthly
Loading
QTY
Fortify XDR+ for KubernetesFortify-XDR+K8

The XDR+ scope on the Kubernetes agent, including SOC direct remediation of identified events in containerized workloads.

per node
billed monthly
Loading
QTY
SpecificationPlatform specification
Endpoint agentSentinelOne Complete, covering Windows, macOS, Linux, and Kubernetes
Detection modelStatic and behavioral AI executing on the agent itself, without a cloud round trip
Correlation engineFluency cross-layer analytics, included from the Fortify-XDR tier upward
Telemetry planesEndpoint · email · cloud workloads on AWS, Azure and GCP · network · Active Directory
Integrated modulesNGAV, EDR, UEBA, cloud workload protection, network traffic analysis, and SIEM
Monitoring24x7, staffed shift rota, no seasonal gaps
Response at MDR and XDRTriaged escalation to your team with the recommended action stated
Response at XDR+SOC direct remediation of all identified events
RollbackAgent-native remediation and rollback on Windows endpoints
Tamper resistanceAgent self-protection; removal requires a console-issued key
Framework mappingDetections carry MITRE ATT&CK technique references
BillingCharged each month against one endpoint, or one node on the Kubernetes lines
01Architecture

Where each component actually sits

The stack has three layers and they fail independently, which is the point of building it this way rather than buying one console and hoping.

  • On the machine. The SentinelOne Complete agent evaluates process lineage, script behavior, memory activity, and file operations locally. Because the model runs on the endpoint, a laptop on hotel wifi with no route back to us is still defended, and conviction does not queue behind a network round trip.
  • Above the estate. Fluency receives the agent stream alongside mail flow, cloud control-plane records, network sessions, and directory events. It resolves them onto shared entities, so a user, a host, an address, and a session stop being four separate stories.
  • In the operations center. Analysts work the resulting case queue on a rota. They are the layer that turns a scored anomaly into a decision, and at XDR+ into an action.

Nothing here requires you to run a console, write detection content, or hold a pager. If your team wants console access, you get it; the service does not assume you will use it.

02Tier deltas

What genuinely changes between the three tiers

The tiers are cumulative and the differences are narrow enough to state in three sentences, which is deliberate. Vague tiering is how buyers end up paying for a capability they already had.

  • Fortify MDR. The SentinelOne Complete agent and a 24x7 SOC watching it. Detection and alerting on endpoint telemetry. No cross-layer correlation, so a mailbox compromise that never touches a managed endpoint is outside what this tier can see.
  • Fortify XDR. Adds Fluency, and with it the other four telemetry planes plus the integrated module set: next-generation antivirus, EDR, user and entity behavior analytics, cloud workload protection, network traffic analysis, and a SIEM. This is the tier at which the service stops being endpoint-shaped.
  • Fortify XDR+. Adds direct remediation by our analysts on every event they identify. The detection surface is identical to XDR; what changes is who executes the fix.

Read that last line carefully before you buy the middle tier. If nobody on your side is reliably available to isolate a host within minutes at any hour, XDR and XDR+ produce the same alerts and very different outcomes.

03 · Response scope

What SOC direct remediation means when it is 3am

At the Fortify-XDR+ tiers an identified event does not become an email you read later. It becomes an action, taken by an analyst on shift, inside the tooling your subscription provides. In practice that means:

  • Network isolation. The host is cut off from everything except our management channel, which stops lateral movement while leaving us able to work on the machine.
  • Process and chain termination. The malicious process tree is killed and the persistence it established is removed.
  • Quarantine and rollback. Dropped artifacts are quarantined, and on Windows the endpoint can be returned to its pre-incident state rather than rebuilt.
  • Identity containment. Where the case involves credential abuse, sessions are revoked and the account is disabled pending your confirmation.
  • A written record. Every action lands in your portal case with a timestamp, the analyst who took it, and the reasoning. You wake up to what was done, not to a decision still waiting on you.

Two things bound this, and we would rather you hear them now than during an incident. First, remediation covers the estate your subscription covers, using the tooling that subscription provides. Second, you tell us in advance which hosts must never be isolated without a phone call, because a domain controller and a marketing laptop do not deserve the same reflex.

04Vendor credibility

Why this agent, and how to check us on it

We are a service, not a vendor, so the honest position is that our platform choices should be auditable by you rather than taken on trust.

  • Independent adversary emulation. SentinelOne participates in the MITRE Engenuity ATT&CK Evaluations, which run a named threat actor's technique chain against participating products and publish the step-by-step results. Ask us and we will send you the round data itself rather than a slide summarizing it in our favor.
  • Technique-level mapping. Detections carry MITRE ATT&CK technique references, so the question "what are we actually covered for" has an answer with identifiers in it rather than adjectives.
  • Tamper protection. The agent defends itself against being stopped, unloaded, or uninstalled by anything short of a console-issued key. An attacker with local administrator rights is a normal Tuesday; an EDR that a local administrator can simply switch off is not a control, it is a report.
  • Rollback as a real control. Agent-native rollback on Windows is what converts a ransomware detonation from a restore project into an afternoon. It is also why our backup modules stay a separate purchase: they solve a different failure, and pretending otherwise would be selling you the same thing twice.
05Kubernetes

The container rows of the same matrix

The three Kubernetes lines are not a separate product. Each carries the capabilities of its column, delivered by the SentinelOne Complete Kubernetes agent, and is counted per node rather than per endpoint.

The agent runs as a DaemonSet, observing runtime behavior inside containers rather than only scanning images at rest. That distinction matters, because an image that passed its scan on Tuesday can still pull a payload at runtime on Thursday. On the XDR rows that container telemetry enters the same correlation graph as the rest of your estate, so a compromised pod reaching for cloud credentials appears as one case rather than a cluster alert and an unrelated identity alert.

Node pricing reflects the density of what is being watched. A node hosting forty pods is not an endpoint, and pricing it like one would be a quiet way of underdelivering.

Where this platform stops

It stops at the perimeter of what you deploy. An endpoint without the agent installed is invisible regardless of tier, and on XDR the cross-layer promise only holds once the email, cloud, network, and directory connectors are authorized. Until they are, you are paying for XDR and receiving MDR.

It also stops short of full incident response. Forensic investigation, breach counsel and regulatory notification, infrastructure rebuilds, and recovery of systems outside the covered estate are separate engagements. We will tell you the moment an event crosses that line, and we will keep working while we tell you. Restoring destroyed data is a different discipline again; that lives in backup and continuity, and no detection tier substitutes for it.