Endpoint Protection That Works When Antivirus Doesn't
Isn't the antivirus already on your laptops enough? For most Johannesburg SMEs still running Windows Defender or a consumer product, no: it can only block what it has already seen before, and it needs a live connection back to base to check. As a SentinelOne partner, EndpointX runs behavioural detection instead, watching what a process actually does on the device and killing it the moment it turns malicious, even on a laptop that's offline or off your network entirely, as part of our wider cyber security services.
Why Signature-Based Antiviruses Miss What They Haven't Seen Before
If you’re already running Windows Defender or a consumer antivirus product, you’re right that it stops known malware. What it can’t do is stop something it has never checked against before, because that’s how signature-based detection works: it needs a matching entry in a database before it acts.
Detection That Reads Behaviour, Not a Signature List
EndpointX runs on SentinelOne's Storyline technology, which maps the full chain of what a process actually does on the device rather than checking it against a list of known bad files. That's how it flags something it has never encountered before.
Action Taken On the Device Itself, No Connection Needed
Detection and the kill and isolate step both happen locally on the laptop or server, not through a cloud lookup. A device that's offline, off the office wifi, or disconnected from the VPN is protected in exactly the same way as one sitting at a desk.
Effectiveness Independently Tested, Not Just a Vendor Claim
In MITRE ATT&CK evaluations, the industry's main independent test, SentinelOne's Singularity platform detected 80 out of 80 simulated attacks with zero detection delays. We hold SentinelOne partner status on the strength of that platform.
This gap is exactly what turns up when we run a tenant review: a Microsoft 365 licence that bundles basic antivirus but nothing that watches behaviour once a file has already run.
For a Johannesburg business where staff work from home, from a client site, or from whatever wifi is nearest more days than not, that's where a real incident actually starts, not on the office network signature checks were built to watch.
Everything EndpointX Covers On Every Device From Day One
This runs as one deployment, not a menu you build a rollout plan around. Every laptop, desktop and server on your asset register gets the same agent, running the same behavioural detection, from the day it goes live.
The Agent, Watching Continuously
A lightweight agent installs on every laptop, desktop and server. It doesn’t wait for a scheduled scan, it watches what every running process is actually doing, all the time, in the background.
Correlated Into Your Managed SOC
Everything the agent sees feeds into CyberCommand’s managed SOC for human review, checked against what’s happening on your network and in your inbox at the same time, not looked at on its own.
Automatic Kill and Network Isolation
When a chain of behaviour turns out to be malicious, the agent kills the process and isolates the device from your network on its own, in the moment, before anyone has reviewed a single alert.
Rollback From Windows Volume Shadow Copy
If files do get encrypted, Rollback deletes them and restores the originals from Windows Volume Shadow Copy snapshots taken before the attack.
Protection That Travels Off Your Network
Detection and response happen on the device itself, so a laptop working from home, from a client site, or from mall wifi is covered the same way as one sitting in the office.
Behavioural Detection, Not Signature Matching
SentinelOne’s Storyline technology maps the full chain of a process’s behaviour, so it can flag something it has never seen before instead of only recognising known malware.
How Detection, Isolation and Rollback Work As One System
None of this depends on a person watching a dashboard. The agent on the device makes the call itself, in sequence, the moment a process’s behaviour crosses from ordinary into something that matches a real attack chain.
Storyline Maps the Full Behaviour Chain
Rather than checking a file against a list of known bad hashes, Storyline tracks what a process actually does on the device: what it opens, what it writes, what it tries to connect to, and how one action leads to the next. That full chain gets judged, which is why it can flag a threat it has never encountered before instead of waiting for a signature update to catch up with it.
Kill and Isolate, Before a Human Reviews Anything
Once that chain is confirmed as malicious, the agent kills the process and cuts the device off from your network immediately, without waiting for a ticket to be raised or an analyst to log in. That immediacy matters because a ransomware encryption routine runs in minutes, and the difference between a contained laptop and an infected file share often comes down to the seconds before anyone else even sees an alert.
Rollback Restores What Encryption Touched
If encryption does start, Rollback uses Windows Volume Shadow Copy snapshots taken before the attack to delete the encrypted files and put the originals back. This only works if the agent was running in Protect mode and VSS was left switched on beforehand, and it isn’t a substitute for proper backup, it’s a fast first line of recovery on the device itself.
Works Whether the Device Is On Your Network or Not
Why There's No Flat Price Per Device Listed On This Page
A single published rate would be wrong for almost every business that reads it. A ten-laptop consultancy running Windows only is a different job to a fifty-device fleet mixing Windows, Mac and a handful of servers, each one needing the agent deployed, configured and watched. Cost moves with three things: how many devices you have, which mix of operating systems they run, and whether EndpointX runs standalone or bundled into a wider ESMS managed IT support package, usually the more cost effective route for growing SMEs.
01 Number Of Devices Across Your Whole Fleet
02Mix Of Windows, Mac And Server Endpoints
03 Standalone Cover Or Bundled Into ESMS Support
Who This Is For
EndpointX fits any business issuing company laptops, desktops or servers, especially where staff aren't behind the office firewall all day. Remote and hybrid teams on home wifi, client sites or the road are exactly where legacy antivirus runs out of cover: it needs a live connection back to base to work. We deploy it inside a wider 24/7 cyber security stack for Johannesburg SMEs.
How it works
frequently asked questions
Isn't the antivirus we already have enough?
Windows Defender and consumer antivirus tools match a file against threats they have already seen, so anything genuinely new gets through until that list updates. EndpointX runs on SentinelOne’s Storyline technology, watching what a process actually does, so it can act on a threat it has never seen before, on the spot, without waiting for a definition update or an internet connection.
Will running an agent on every laptop slow our team down?
The agent runs quietly in the background and watches process behaviour continuously, rather than working through scheduled full disk scans, so your team doesn’t notice it running day to day the way they would with older, heavier antivirus software.
Do our people's personal devices need to be enrolled too?
No, EndpointX is installed on company owned laptops, desktops and servers only, personal devices stay out of scope. Rollout is managed centrally and pushed to each machine remotely, so IT isn’t physically visiting every desk to install it.
Does this replace our backup, or cover our firewall and network too?
No. If a device is compromised and files get encrypted, SentinelOne’s Rollback feature uses Windows Volume Shadow Copy snapshots taken before the attack to delete the encrypted copies and restore the originals, provided the agent was running in Protect mode with VSS switched on beforehand. That isn’t a substitute for proper backup and disaster recovery. EndpointX also protects the device itself only: your office firewall, switches and wireless network are covered separately by our FortressNet network security.
What happens if a laptop is lost or stolen?
Because detection and the kill or quarantine step run on the device itself, EndpointX doesn’t need the laptop to be connected to your network to act on it.
Does this cover our servers too, or just staff laptops?
It covers laptops, desktops and servers, wherever the agent is installed.
Having Antivirus Installed Is Not The Same As Being Protected
Talk to our SentinelOne partner team about behavioural protection for the laptops, desktops and servers your business runs on.