SentinelOne
The agent decides, because waiting for a person is the vulnerability
SentinelOne built its platform around a single premise: that by the time an alert has travelled to a console, been read by an analyst and been acted upon, ransomware has finished its work. So the agent is given the authority to stop the process, undo the damage and revoke the access itself.
Signatures describe yesterday's attacks
Traditional antivirus works by comparison. A file arrives, its fingerprint is checked against a catalogue of known-bad fingerprints, and a match triggers a block. The model is efficient and it was adequate for years, in an era when malicious code was written once and distributed widely.
That era ended. Modern intrusion tooling is generated per target, repacked automatically, or assembled at run time from components that are individually innocuous. The fingerprint of the thing attacking you has never been seen before, and frequently will never be seen again, which means there is nothing in the catalogue to match it against.
Worse, a great deal of serious intrusion involves no malicious file at all. An attacker who has obtained valid credentials can use the administrative tools already installed on the machine. There is no foreign binary to detect because everything being executed is software the organization deliberately installed and trusts.
Behaviour is the thing that cannot be disguised
The alternative is to watch what software does rather than what it is. Encrypting files in rapid succession across a directory tree is recognisable regardless of which program is doing it. So is injecting code into another process, or deleting the shadow copies that would permit a restore, or reaching out to establish persistence in a startup location.
SentinelOne's behavioural engine evaluates activity as it happens and builds what the company calls a Storyline: a connected account of the processes involved, what each did, and how they relate. That structure matters for two reasons. It permits a judgement about the whole sequence rather than each isolated action, and it records precisely what was changed.
The second point is the one people underestimate. Knowing exactly which files a malicious process touched is what makes it possible to put them back.
What the platform actually does when it decides
Autonomy is the distinguishing claim, so it is worth being specific about what the agent is empowered to do without a human in the loop.
- Terminate and quarantine
- The offending process is stopped mid-execution and its artefacts are isolated, rather than flagged for later review. This happens on the endpoint itself, so it works whether or not the machine can currently reach the management console.
- Roll back the changes
- Because the agent recorded which files were modified and how, it can restore them to their prior state. For a ransomware event caught in progress, this is the difference between an incident and a restore from backup.
- Isolate the host
- A compromised machine can be cut from the network while remaining reachable by administrators, which stops lateral movement without stranding the investigation.
- Revoke the identity
- The platform extends beyond the endpoint to the identity signals attached to it, so a session or credential implicated in the activity can be revoked at the point of impact rather than after a separate investigation in a separate console.
What changes for the people who run it
The operational difference is where the work lands. Under the traditional model, the product raises an alert and a person performs the response. Under this one, the response has already happened and the person reviews whether it was correct.
That inversion suits organizations without a night shift, which is most of them. It does mean accepting that the agent will occasionally be wrong, and that a legitimate but unusual piece of software may get stopped. Every deployment therefore involves a tuning period, and pretending otherwise sets up an unpleasant first month.
| Moment | Signature antivirus | Autonomous behavioural agent |
|---|---|---|
| Novel ransomware executes | No match, permitted | Behaviour recognised, stopped |
| Files already encrypted | Restore from backup | Rolled back from the recorded chain |
| Attack uses built-in tools | Nothing to detect | Sequence flagged regardless |
| Machine is offline | Definitions may be stale | Judgement runs on the endpoint |
| Human response required | Before containment | After containment, to review |
Where this is the right purchase, and where it is not
The platform suits organizations that cannot guarantee a fast human response, and those running estates where a single encrypted file server would halt the business. The rollback capability in particular is worth paying for if your recovery point objective is currently measured in hours.
It is a less obvious purchase where an organization already operates a mature, staffed security function with its own response playbooks, since the autonomy overlaps with decisions that team has deliberately reserved for itself. It also asks more of the deployment than a simple antivirus rollout: policies need tuning against the applications you actually run, and that work needs an owner.
Decide what happens when nobody is watching the console
The question worth answering first is not which product detects more. It is what your current tooling is permitted to do on its own at two in the morning, and how long the gap is before a person arrives.
Schedule an Endpoint ReviewGet in touch with Your Company
Questions about this solution? Reach us directly.