Singularity Endpoint
Windows, macOS and Linux with Storyline, which rebuilds the chain behind every process, and the Behavioral AI engines.
For teams that already own SentinelOne but have nobody to read a Storyline at three in the morning, or a provider that flags instead of isolating the host. The Fortgale MDR service works on your console with analysts authorised to contain, at a median TTC of <30 minutes.
The Singularity modules the SOC operates, across endpoints, cloud workloads and identities. If SentinelOne is not in place yet, licensing and agent rollout are part of the service.
Windows, macOS and Linux with Storyline, which rebuilds the chain behind every process, and the Behavioral AI engines.
Cloud workloads, containers and Kubernetes nodes with Cloud Workload Security, in the same console as the endpoint.
Identity threats on Active Directory and Entra ID: reconnaissance, credential abuse and privilege escalation.
Storyline Active Response rules written by Fortgale: on a match they raise the alert, kill the process or put the host in network quarantine.
PowerQuery sessions led by Fortgale analysts on silent lateral movement, persistence and data staging.
Asset vulnerabilities found by the agent already installed, prioritised on CVEs actively exploited in the wild.
What no vendor supplies is the part that turns a platform into a defence. Fortgale detection engineering is built on 287 tracked adversary groups and attack tools: every custom rule is mapped to MITRE ATT&CK and every alert reaches the analyst already enriched with proprietary CTI. Noise drops by more than 90% by day 30, and the decision stays with an analyst who acts: median TTD <15 minutes, median TTC <30 minutes.
On SentinelOne the analyst acts from the console with native actions: kill, quarantine and remediate on the Storyline, Network Quarantine of the host and Remote Shell in PowerShell or Bash for live forensics; with RemoteOps, scripts run on many hosts at once.
Rollback on Windows returns files and configuration to their previous state through VSS shadow copies: the SOC runs it where you have authorised it, because on a production server a restore is also a business decision. Actions on third-party tools, such as a firewall or the identity provider, go through Singularity Hyperautomation and the integrations agreed at onboarding.
Fortgale CTI indicators, 34,000 IOCs a week, enter SentinelOne through the Threat Intelligence API, while STAR rules follow the techniques of tracked actors: known infrastructure and known behaviour open the same alert.
Takeover works on your SentinelOne console: existing agents, policies and exclusions stay in place and no endpoint needs reinstalling.
Monitoring starts as soon as accounts are live, and technical onboarding closes in one week: roles, STAR rules, response authorisations and the scope of rollback.
On your side: console users with the agreed roles, the groups where network quarantine is pre-authorised and the person who decides when a rollback touches a server.
In March 2026 Fortgale CTI described TeamPCP, a group active since late 2025 against cloud native infrastructure: exposed Docker APIs, misconfigured Kubernetes clusters, unauthenticated Redis and vulnerable Ray dashboards, up to the supply chain with compromised Trivy and KICS, PyPI packages tied to LiteLLM and malicious GitHub Actions. Compromised nodes become botnet members for Monero mining, credential theft from CI/CD pipelines and extortion through a leak site.
The article is not about SentinelOne, but the signals it lists are the kind an agent on the nodes sees: Kubernetes DaemonSets named like node-setup-* or host-provisioner-std, mining processes spawned from a container, outbound traffic to GitHub from hosts that should not generate it. On nodes covered by Singularity Cloud a STAR rule can kill the process at the first match, and the analyst decides whether to isolate the node.
No. Wayfinder and Vigilance are the names of the SentinelOne MDR services. Fortgale works independently on the Singularity console you already have, from a SOC in Milan that operates in European time zones.
You do. SentinelOne rollback restores files and configuration on Windows through VSS: on a workstation it is a fast remediation, on an application server it can also undo legitimate data. At onboarding we agree where the analyst can run it straight away and where your confirmation is needed.
The console, its policies and its exclusions remain yours. Our analysts work with the users and roles agreed, and every response action is recorded in the console activity log, where your team can review it.
Installed agents stay: only console users and authorisations change hands. Fortgale monitoring starts as soon as access is live, so the previous contract can end once technical onboarding is complete, after one week.
Either way. If you already own SentinelOne, Fortgale operates your console; if not, licensing is included in the service. At onboarding we check the package, because telemetry retention differs between packages and decides how far back hunting can go.
We walk through a Singularity incident step by step: the Storyline the analyst reads, the STAR rule that raised it, the network quarantine and the point where rollback was authorised or ruled out. Alongside it, the Report on the actors most likely to target your sector.
No nurturing sequences, no auto-replies. One of our analysts calls you back within one business day.
The full Report (executive summary · operational IoCs · technical runbook) is restricted. Share two details and one of our analysts contacts you with access and a short technical briefing.
Response in 30 minutes, containment in 1–4 hours. Even if you are not a Fortgale customer.