A Fortify 24x7 brand. Managed protection for businesses rebuilding after a security incident.Client sign insupport@hacked.help
Hacked.Help
Home / The board / Managed detection and response
Step 01 · Stop the bleeding

Managed detection and response

Six tiers, one question behind all of them: when something moves at three in the morning, who sees it, and are they allowed to act.

24x7 SOCSentinelOne agentFluency analyticsMITRE ATT&CK aligned
Controls in this family6 lines · live rates
Managed DetectionFortify-MDR
per endpoint, per month
Loading
QTY
Managed Detection, KubernetesFortify-MDR-K8
per Kubernetes node, per month
Loading
QTY
Extended DetectionFortify-XDR
per endpoint, per month
Loading
QTY
Extended Detection, KubernetesFortify-XDR-K8
per Kubernetes node, per month
Loading
QTY
Extended Detection PlusFortify-XDR+
per endpoint, per month
Loading
QTY
Extended Plus, KubernetesFortify-XDR+K8
per Kubernetes node, per month
Loading
QTY
Per unit, per month · billed in advance by Fortify 24x7 Review the full board
Technical specification 6 lines
Fortify-MDRSentinelOne agent with 24x7 SOC monitoring and alerting
Fortify-MDR-K8As above, delivered by the SentinelOne Kubernetes agent
Fortify-XDRSentinelOne Complete agent, cross-layer detection, 24x7 hunting and alerting
Fortify-XDR-K8SentinelOne Complete Kubernetes agent, including SOC direct remediation of identified events
Fortify-XDR+SentinelOne Complete agent, including SOC direct remediation of identified events
Fortify-XDR+K8SentinelOne Complete Kubernetes agent, including SOC direct remediation
Detection surface, XDR linesEndpoints, email, servers, cloud workloads on AWS, Azure and GCP, network, and Active Directory
Modules, XDR linesNext-generation antivirus and EDR, user and entity behaviour analytics, traffic analysis on the network, workload protection in the cloud, and a SIEM
Detection methodBehavioural models and a rule library rather than signature matching alone
Analytics layerAgent telemetry lands in Fluency, which is where the desk hunts, where signals from separate systems are correlated, and where a case is assembled
Operating hours24 hours a day, every day, including holidays
How it is billedOne rate for each endpoint, or for each Kubernetes node, charged monthly
01Problem

Prevention fails quietly. Behaviour is what gives it away.

The techniques that reach production estates in 2026 are chosen precisely because they do not look like malware. Credential theft from memory, a scheduled task added at an odd hour, a service account authenticating from a machine it has never touched, encryption performed by a signed binary that ships with the operating system. Nothing there is a file you can convict on sight.

Behavioural detection watches sequences instead of artefacts, which is why the agent on these lines carries a rule library mapped to attacker technique rather than a signature list. The distinction matters most in the cases where prevention has already lost, which is the situation most of our clients are in when they first call.

02Operation

What the desk actually does with an alert

An alert is not a product. What you are buying is the sequence that follows one:

  • Triage. An analyst works the detection in Fluency, where the agent telemetry is correlated, and decides whether the behaviour is a real intrusion, a misconfiguration, or the finance team doing something unusual but legitimate. Most alerts die here, which is the point.
  • Containment. Where the finding is real, the endpoint is isolated from the network while remaining reachable by the desk, so lateral movement stops before the investigation finishes.
  • Remediation. On the lines that include it, the desk performs the removal and rollback directly rather than sending you instructions and waiting.
  • Escalation. You are contacted through the channel agreed at onboarding, with what was seen, what was done, and what needs a decision from you.
03Choosing

How the six lines differ

MDR is endpoint detection with the desk behind it: monitoring and alerting on the SentinelOne agent. It is the right floor for a business whose estate is laptops, desktops, and a couple of servers.

XDR widens the surface. Detection correlates across endpoints, email, servers, cloud workloads on AWS, Azure and GCP, network telemetry, and Active Directory, with the SentinelOne Complete agent carrying next-generation antivirus, EDR, user and entity behaviour analytics, cloud workload protection, inspection of network traffic, and a SIEM, all of it correlated in Fluency. Correlation is what turns four unremarkable events on four systems into one intrusion with a timeline.

The plus lines add direct remediation, meaning the desk resolves identified events on your behalf rather than handing them back. Choose those when nobody on your side is available to act quickly at night.

04Containers

The Kubernetes lines are a different unit, not a different product

Container workloads are ephemeral, which defeats an agent model built around a persistent device. The Kubernetes lines deploy the SentinelOne Kubernetes agent so that runtime behaviour inside your clusters is visible to the same desk and correlated with the rest of the estate.

They are billed per node rather than per endpoint, which is why the rate differs. If you run clusters, price them separately and do not assume the endpoint line covers them.

The 03:00 problem

The agent is the cheap part. Somebody answering is the product.

Every business we onboard after an incident already owned security software. In most cases it had already detected something, weeks or months before we arrived. The finding was sitting in a console that had not been opened since the quarter somebody installed it, because staring at a console is nobody's actual job once the day fills up.

What you are buying on these lines is the staffing, not the software. Detections reach analysts whose entire shift is looking at them, at an hour when your team is asleep and an intruder is specifically counting on that.

Where this stops

This is detection, containment, and recovery. It is not digital forensics or an incident response retainer. The desk will contain and remediate what it identifies, and will tell you plainly what it saw. A defensible forensic investigation, breach counsel, regulatory notification, and insurer negotiation are separate engagements and are not sold through this checkout.

No detection platform sees everything. Coverage extends to the systems carrying an agent or an authorized connector, and the honest answer to what happens on an unmanaged device is that we will not know.