Falcon Insight XDR
Endpoint detection and response on the Falcon sensor, with Fortgale indicators loaded as Custom IOCs and behavioural Custom IOA rules.
For teams that already own Falcon but have nobody to act on a detection at night, or an MSSP that forwards alerts instead of containing them. The Fortgale MDR service runs on your Falcon console with analysts who have the mandate to contain, at a median TTC of <30 minutes.
The Falcon modules the SOC operates, on Windows, macOS and Linux endpoints, cloud workloads and identities. If Falcon is not in place yet, licensing and sensor deployment are part of the service.
Endpoint detection and response on the Falcon sensor, with Fortgale indicators loaded as Custom IOCs and behavioural Custom IOA rules.
Identity threat detection on Active Directory and Entra ID: lateral movement, credential abuse and LDAP anomalies read in the same console as the endpoint.
Cloud workloads and containers on AWS, Azure and GCP, monitored with the same sensor and correlated with endpoint and identity activity.
Asset and vulnerability visibility (the former Falcon Discover and Spotlight), prioritised on CVEs actively exploited in the wild.
Third-party logs brought next to Falcon telemetry in Next-Gen SIEM, so that correlation does not stop at the endpoint.
Hunting sessions led by Fortgale analysts for silent lateral movement, persistence and data staging that automatic detections miss.
What no vendor supplies is the part that turns a platform into a defence. Fortgale detection engineering is built on 287 tracked adversary groups and attack tools: every custom rule is mapped to MITRE ATT&CK and every alert reaches the analyst already enriched with proprietary CTI. Noise drops by more than 90% by day 30, and the decision stays with an analyst who acts: median TTD <15 minutes, median TTC <30 minutes.
On Falcon the analyst contains from the console: network containment of the host, process kill, file removal and a Real Time Response session to collect forensic artefacts or run remediation scripts on the machine.
Falcon Identity Protection adds policy-based enforcement on Active Directory and Entra ID, such as blocking a risky authentication or requiring MFA. Revoking cloud sessions outside those policies is not a Falcon action: it happens in the identity provider, with the permissions agreed at onboarding.
Because Fortgale indicators live in Falcon as Custom IOCs and IOA rules, an infrastructure already attributed to an actor raises a detection even before its behaviour is complete on the endpoint.
Falcon sensors already deployed stay untouched: takeover works on your existing CID, with no reinstallation.
Monitoring goes live as soon as console access is in place, and technical onboarding closes in one week: roles, host groups and Fortgale rules are in place and the service runs at full capacity.
What we need from you: console users with the roles agreed for our analysts, the host groups where containment is pre-authorised and the people to call when a decision is yours.
In July 2026 Fortgale published its analysis of MacSync, a macOS infostealer sold as a service. It arrives through poisoned search results and fake installation guides on GitHub that ask the user to paste a command such as curl … | zsh into the terminal; once running, it collects browser databases, session tokens, Keychain, SSH keys and wallets. On a developer's Mac at a customer, three execution attempts were stopped by behavioural detection on the endpoint, before the payload was downloaded.
The article is not about Falcon, but the lesson holds for any EDR with a macOS sensor: MaaS infrastructure rotates within days, the behaviour stays the same. On Falcon this is the kind of chain (terminal, curl, shell) a Custom IOA rule catches, and the analyst who gets the detection can contain the host and check in RTR that no file was written.
No. Falcon Complete Next-Gen MDR is the managed service of CrowdStrike. Fortgale works independently on the Falcon subscription you already have, with analysts in a SOC in Milan who operate in European time zones and under European rules.
On an existing instance nothing is transferred to us: your CID, your policies and your administrator accounts remain yours. Our analysts log in with the console roles agreed at onboarding, and their containment and RTR sessions appear in the Falcon audit trail.
If the previous provider also worked on Falcon, the sensors do not move: only console users and response authorisations change hands. Our monitoring starts as soon as access is live, so the old contract can end once technical onboarding is complete, after one week.
Either way. If you already own Falcon, Fortgale integrates the SOC on your existing instance; if not, Falcon licensing is included in the MDR service with no separate purchase.
NIS2 does not require an MDR and no service makes you compliant on its own. The service covers capabilities you have to answer for: continuous monitoring, incident handling and, for a significant incident, the technical evidence for the early warning within 24 hours and the notification within 72 hours. On Falcon that evidence comes from the detection timeline, the artefacts collected in RTR and the containment audit trail.
We walk through a containment on Falcon step by step: the detection that fired, the RTR commands the analyst ran, when the host was contained and what the identity policy did. Alongside it, the Report on the actors most likely to target your sector.
No nurturing sequences, no auto-replies. One of our analysts calls you back within one business day.
The full Report (executive summary · operational IoCs · technical runbook) is restricted. Share two details and one of our analysts contacts you with access and a short technical briefing.
Response in 30 minutes, containment in 1–4 hours. Even if you are not a Fortgale customer.