Detection is not a dashboard you are supposed to check. It is an agent that understands what a process is doing, a correlation layer that ties that to everything else happening in your estate, and a person who decides what to do about it at four in the morning. All three come with every line on this sheet.
Matching known signatures stopped being sufficient a long while ago. The SentinelOne agent models behavior on the machine itself: what a process spawned, which files it touched, where it reached out to, and whether that shape resembles encryption, collection, or somebody quietly walking a network. It carries on deciding with no connection at all, which is what you want on a laptop mid flight and on the build box somebody abandoned on a bench.
Fluency takes what the agents report and joins it to the rest of the picture: sign in events, mail events, network telemetry, and logs from tools you already own. By the time an alert reaches our desk it carries enough context to be decidable, and that gap is exactly what separates being told from being helped.
The detection line triages and advises. The extended line widens what gets correlated, so a suspicious sign in from one country and a strange process on a laptop in another stop being two unrelated curiosities. The response tier adds automated containment and rollback, which is what you want when it kicks off during the small hours of a weekend.
Kubernetes nodes are priced on their own lines. A node is not a laptop, the agent behaves differently, and rolling them into an endpoint count would make the invoice quietly dishonest. Count nodes, not pods.
Prices below are pulled straight out of billing. Anything you add sits in your basket while you carry on reading.
Behavioral detection on the endpoint with a staffed desk behind it. Alerts are worked by people and reach you with a recommendation attached rather than a chart to interpret.
| Platform | SentinelOne, with Fluency correlation |
|---|---|
| Coverage | Windows, macOS, Linux |
| Response | Notification, guidance, and assisted remediation |
| Offline | Detection continues with no connectivity |
| Desk | Fortify 24x7 engineers, whatever the hour |
| Rate basis | Protected endpoint, monthly |
Everything the detection line does, widened so identity, mail, and network signal are read alongside the endpoint instead of in separate windows.
| Platform | SentinelOne with extended Fluency correlation |
|---|---|
| Sources | Endpoint, identity, mail, network |
| Response | Notification, guidance, and assisted remediation |
| Retention | Extended, for retrospective investigation |
| Best fit | Teams already living in a Microsoft or Google tenant |
| Rate basis | Protected endpoint, monthly |
The correlated tier with hands. A machine that crosses the response threshold gets isolated and reverted while the analyst is still reading the case.
| Platform | SentinelOne with automated response |
|---|---|
| Containment | Network isolation of the affected endpoint |
| Rollback | Undoes what a convicted process altered, where supported |
| Oversight | Human review of each automated action, after the fact |
| Best fit | Signing hosts, build machines, finance workstations |
| Rate basis | Protected endpoint, monthly |
Detection for containerized workloads, counted by node so the invoice matches the number your platform engineer already knows.
| Platform | SentinelOne for Kubernetes |
|---|---|
| Scope | Runtime behavior of workloads on the node |
| Response | Notification, guidance, and assisted remediation |
| Desk | Fortify 24x7 engineers, whatever the hour |
| Rate basis | Kubernetes node, monthly |
Node detection with the correlation layer switched on, so cluster activity is read next to identity and endpoint events rather than in isolation.
| Platform | SentinelOne for Kubernetes with Fluency correlation |
|---|---|
| Sources | Node runtime, identity, endpoint, network |
| Response | Notification, guidance, and assisted remediation |
| Retention | Extended, for retrospective investigation |
| Rate basis | Kubernetes node, monthly |
The node line with automated response attached, for clusters that run something you cannot afford to leave misbehaving until office hours.
| Platform | SentinelOne for Kubernetes with automated response |
|---|---|
| Containment | Automated action against the offending workload |
| Oversight | Human review of each automated action, after the fact |
| Best fit | Production clusters carrying customer workloads |
| Rate basis | Kubernetes node, monthly |
Detection makes a fine control and a lousy guarantee. Here is what these six lines do not reach, stated plainly so you can decide what else you need.
Heads up: card statements show FORTIFY 24X7 - EagleTech Innovations is a Fortify 24x7 brand, and your subscription is billed by Fortify 24x7.