MDR partner · SentinelOne Singularity

MDR for SentinelOne Singularity, with the mandate to contain.

For teams that already own SentinelOne but have nobody to read a Storyline at three in the morning, or a provider that flags instead of isolating the host. The Fortgale MDR service works on your console with analysts authorised to contain, at a median TTC of <30 minutes.

<15 minMedian TTD
<30 minMedian TTC
24·7·365SOC in Milan since 2017
Fortgale × SentinelOne
MDR · live
SentinelOne sensor activeEndpoint · cloud · identity telemetry
SentinelOne
European SOC 24·7·365L2/L3 analysts · direct interaction
Fortgale
Multi-domain AI tier-zeroNoise reduced >90% by day 30
Fortgale
Native SentinelOne responseHost isolation in seconds
Live
Proprietary intelligence287 tracked adversary groups and attack tools
Fortgale
MDR live, SentinelOne + Fortgale SOC active
Compliance
ISO/IEC 27001
NIS2 ready
DORA aligned
GDPR · ENISA
Technology partnership
SentinelOne Singularity
MITRE ATT&CK aligned
OpenCTI
Coverage

What we cover on SentinelOne.

The Singularity modules the SOC operates, across endpoints, cloud workloads and identities. If SentinelOne is not in place yet, licensing and agent rollout are part of the service.

01

Singularity Endpoint

Windows, macOS and Linux with Storyline, which rebuilds the chain behind every process, and the Behavioral AI engines.

02

Singularity Cloud

Cloud workloads, containers and Kubernetes nodes with Cloud Workload Security, in the same console as the endpoint.

03

Singularity Identity

Identity threats on Active Directory and Entra ID: reconnaissance, credential abuse and privilege escalation.

04

STAR rules

Storyline Active Response rules written by Fortgale: on a match they raise the alert, kill the process or put the host in network quarantine.

05

Hunting on Singularity Data Lake

PowerQuery sessions led by Fortgale analysts on silent lateral movement, persistence and data staging.

06

Vulnerability management

Asset vulnerabilities found by the agent already installed, prioritised on CVEs actively exploited in the wild.

What we add

What Fortgale adds on top of SentinelOne.

What no vendor supplies is the part that turns a platform into a defence. Fortgale detection engineering is built on 287 tracked adversary groups and attack tools: every custom rule is mapped to MITRE ATT&CK and every alert reaches the analyst already enriched with proprietary CTI. Noise drops by more than 90% by day 30, and the decision stays with an analyst who acts: median TTD <15 minutes, median TTC <30 minutes.

On SentinelOne the analyst acts from the console with native actions: kill, quarantine and remediate on the Storyline, Network Quarantine of the host and Remote Shell in PowerShell or Bash for live forensics; with RemoteOps, scripts run on many hosts at once.

Rollback on Windows returns files and configuration to their previous state through VSS shadow copies: the SOC runs it where you have authorised it, because on a production server a restore is also a business decision. Actions on third-party tools, such as a firewall or the identity provider, go through Singularity Hyperautomation and the integrations agreed at onboarding.

Fortgale CTI indicators, 34,000 IOCs a week, enter SentinelOne through the Threat Intelligence API, while STAR rules follow the techniques of tracked actors: known infrastructure and known behaviour open the same alert.

Takeover

How we take over your SentinelOne environment.

Takeover works on your SentinelOne console: existing agents, policies and exclusions stay in place and no endpoint needs reinstalling.

Monitoring starts as soon as accounts are live, and technical onboarding closes in one week: roles, STAR rules, response authorisations and the scope of rollback.

On your side: console users with the agreed roles, the groups where network quarantine is pre-authorised and the person who decides when a rollback touches a server.

From the field

TeamPCP: when extortion starts from the cluster.

In March 2026 Fortgale CTI described TeamPCP, a group active since late 2025 against cloud native infrastructure: exposed Docker APIs, misconfigured Kubernetes clusters, unauthenticated Redis and vulnerable Ray dashboards, up to the supply chain with compromised Trivy and KICS, PyPI packages tied to LiteLLM and malicious GitHub Actions. Compromised nodes become botnet members for Monero mining, credential theft from CI/CD pipelines and extortion through a leak site.

The article is not about SentinelOne, but the signals it lists are the kind an agent on the nodes sees: Kubernetes DaemonSets named like node-setup-* or host-provisioner-std, mining processes spawned from a container, outbound traffic to GitHub from hosts that should not generate it. On nodes covered by Singularity Cloud a STAR rule can kill the process at the first match, and the analyst decides whether to isolate the node.

FAQ

What buyers running SentinelOne actually ask.

Do we need SentinelOne's MDR service to work with Fortgale?

No. Wayfinder and Vigilance are the names of the SentinelOne MDR services. Fortgale works independently on the Singularity console you already have, from a SOC in Milan that operates in European time zones.

Who decides on a rollback?

You do. SentinelOne rollback restores files and configuration on Windows through VSS: on a workstation it is a fast remediation, on an application server it can also undo legitimate data. At onboarding we agree where the analyst can run it straight away and where your confirmation is needed.

What happens to our console and our access?

The console, its policies and its exclusions remain yours. Our analysts work with the users and roles agreed, and every response action is recorded in the console activity log, where your team can review it.

How do we move from another provider without a gap in coverage?

Installed agents stay: only console users and authorisations change hands. Fortgale monitoring starts as soon as access is live, so the previous contract can end once technical onboarding is complete, after one week.

Do we buy the SentinelOne licences, or do you?

Either way. If you already own SentinelOne, Fortgale operates your console; if not, licensing is included in the service. At onboarding we check the package, because telemetry retention differs between packages and decides how far back hunting can go.

See a real runbook

A real runbook on your SentinelOne console.

We walk through a Singularity incident step by step: the Storyline the analyst reads, the STAR rule that raised it, the network quarantine and the point where rollback was authorised or ruled out. Alongside it, the Report on the actors most likely to target your sector.

Response time: < 1 business day.