Defender for Endpoint
Windows, macOS and Linux endpoints and servers, with KQL custom detection rules and Fortgale indicators loaded as custom indicators.
For teams that already own Defender and Sentinel but have an incident queue nobody closes at night, or an MSSP that forwards alerts instead of revoking sessions. The Fortgale MDR service works in your Defender portal with analysts who have the mandate to contain, at a median TTC of <30 minutes.
The Defender workloads and Sentinel sources the SOC operates in the Defender portal. If your Microsoft agreement does not cover what is needed yet, licensing is part of the service.
Windows, macOS and Linux endpoints and servers, with KQL custom detection rules and Fortgale indicators loaded as custom indicators.
Active Directory and Entra ID: lateral movement, Kerberos abuse and LDAP reconnaissance in the same incident as the endpoint.
Phishing, malicious attachments and links on Exchange Online, with remediation of messages already delivered across every affected mailbox.
Anomalous activity in SaaS applications and suspicious OAuth apps, with governance actions on the accounts.
Azure, AWS and GCP workload alerts correlated in Defender XDR with endpoint and identity activity.
Firewalls, VPNs and on-prem sources in Sentinel, operated in the Defender portal, where Microsoft is moving it for good: management from the Azure portal ends on 31 March 2027.
Advanced hunting sessions led by Fortgale analysts on persistence, silent lateral movement and token abuse that automatic detections miss.
What no vendor supplies is the part that turns a platform into a defence. Fortgale detection engineering is built on 287 tracked adversary groups and attack tools: every custom rule is mapped to MITRE ATT&CK and every alert reaches the analyst already enriched with proprietary CTI. Noise drops by more than 90% by day 30, and the decision stays with an analyst who acts: median TTD <15 minutes, median TTC <30 minutes.
On Defender the analyst acts from the portal with native actions: device isolation and containment, app execution restriction, investigation package collection and a Live Response session for artefacts and remediation. Containment, restriction and Live Response require Defender for Endpoint Plan 2.
On identity, response goes through Defender for Identity and Entra ID: disabling the user, forcing a password change and revoking sessions. On email, with Defender for Office 365 Plan 2, delivered messages are moved or deleted. Blocking an IP on a third-party firewall is not a Defender action: it runs through a Sentinel playbook agreed at onboarding.
Fortgale CTI indicators, 34,000 IOCs a week, enter Defender as custom indicators and Sentinel as threat intelligence: infrastructure already attributed to an actor opens an incident even before its behaviour on the device is complete.
Takeover happens on your Microsoft tenant: sensors, policies and workspaces stay where they are, with no migration and no reinstallation.
Monitoring starts as soon as roles and access are live, and technical onboarding closes in one week: Defender XDR permissions, Sentinel workspace, playbooks and response authorisations.
On your side: an administrator to assign the agreed roles to our analysts, the device and user groups where response is pre-authorised, and the escalation list.
In September 2024 Fortgale documented the Supercar phishing kit, used against employees of several Italian companies: fax or employee benefit themed emails with HTML attachments that carry a fake Microsoft 365 login page, or PDFs with QR codes. Credentials are sent to one of more than 4,000 domains in the infrastructure, active since May 2024 and attributed to the Supercar Nebula group.
The article is not about Defender, but a kit like this crosses exactly the workloads the SOC operates. Defender for Office 365 sees the HTML attachment and lets the message be pulled from every mailbox that received it; if a credential has already been entered, the next sign-in shows up in Entra ID logs and response runs through a forced password change and session revocation.
No. Microsoft Defender Experts MDR, the current name of Defender Experts for XDR, is the managed service of Microsoft; Plan 2, which extends it to third-party data in Sentinel, requires Sentinel and at least 1,500 seats. Fortgale works independently on the Defender tenant you already have, from a SOC in Milan that operates in European time zones.
The tenant, its policies, the Sentinel workspace and the data remain yours. Our analysts work with the roles agreed at onboarding, and every response action is recorded in the Defender Action center and in audit logs, where your team can review it.
Defender sensors and existing rules stay untouched: only roles and response authorisations change hands. Our monitoring starts as soon as access is live, so the previous contract can end once technical onboarding is complete, after one week.
Both models work. If Defender and Sentinel are already in your Microsoft agreement, Fortgale operates your tenant; if not, licensing is part of the service. At onboarding we check what your plan enables: without Defender for Endpoint Plan 2, for example, containment and Live Response are not available.
NIS2 does not mandate an MDR, and the service alone does not make you compliant. It covers capabilities you have to answer for: continuous monitoring, incident handling and, for a significant incident, the technical evidence for the early warning within 24 hours and the notification within 72 hours. On Defender that evidence starts from the incident history in Defender XDR and the logs retained in Sentinel.
We walk through a Defender XDR incident step by step: the alert correlated across endpoint, identity and email, the analyst's KQL query, the device isolation and the session revocation. Alongside it, the Report on the actors most likely to target your sector.
No nurturing sequences, no auto-replies. One of our analysts calls you back within one business day.
The full Report (executive summary · operational IoCs · technical runbook) is restricted. Share two details and one of our analysts contacts you with access and a short technical briefing.
Response in 30 minutes, containment in 1–4 hours. Even if you are not a Fortgale customer.