Seven minutes vs. five hours
In late July 2026, the same attacker hit the same internet-facing application twice in 48 hours. One incident took more than five hours to contain. The second took about seven minutes. Both security tools saw the threat. Only one stopped it without waiting for a human.
Updated 2026-08-18
The situation
The client is a professional services firm that runs core operations on an on-premises enterprise resource planning system. That software handles project management, billing, and timesheets. To let people log time and reach data remotely, the server had to be reachable from the internet.
That setup is common. It is also exactly the kind of target automated attackers scan for around the clock.
Incident one: the long night
On a Sunday afternoon, an attacker found a way to run commands on that server through the application itself. Within minutes they had planted a hidden backdoor, explored the network, and began extracting stored credentials.
The endpoint detection and response platform already on the server, SentinelOne, spotted the suspicious activity almost immediately. Detecting a threat and stopping a threat are not the same thing. Under the policy configured for this server, activity of this classification was set to alert a monitoring team rather than isolate the host automatically. A human had to notice, evaluate, and decide before the attacker could be cut off.
Hour 0: the attacker gains initial access. The platform logs the activity and alerts the monitoring team.
Hours 2 to 3: the attacker extracts credentials. The monitoring team engages and begins remediation.
Hour 5 and beyond: the server is fully isolated and the immediate threat is contained.
Over five hours passed between detection and true containment. During that window our team worked with the vendor monitoring service to investigate, rotate credentials, and lock the environment down. Mid-incident we also deployed a second security agent, Huntress, onto the same server. That decision mattered more than anyone expected.
Incident two: the rematch
Forty-eight hours later, on a Tuesday morning, the same attacker infrastructure returned and used the same technique against the same application. This time both tools were watching side by side.
Within minutes of the attacker gaining code execution, Huntress identified the malicious behavior and autonomously isolated the host from the network. No human had to notice the alert, evaluate it, or approve the action. The server was already cut off by the time our team received the notification, along with a precise account of what had happened and what to do next.
SentinelOne detected the same activity, just as quickly as it had two days earlier. Once again the response for this classification was to alert, not act. Left alone, the same multi-hour gap would very likely have repeated. It did not, because a second layer with a different response model was now in place.
About seven minutes from attack to full containment in incident two. More than five hours in incident one.
What made the difference
This was not a story about one detection engine being smarter than another. Both platforms saw the threat. The difference was architectural. One response path depended on a policy classification and a human decision. The other acted when it recognized dangerous behavior, without waiting for permission.
Detection speed was a virtual tie. Both platforms flagged the activity within seconds in both incidents.
Response speed was not. One incident took over five hours to contain. The other took about seven minutes.
The gap was not a fluke. The same policy conditions were present both times. Only the presence of a second, autonomously acting agent changed the outcome on the second attempt.
The monitoring team behind the first platform did real, skilled work once engaged. They identified credential theft, walked through the attack chain, and helped guide remediation. That value is real. It was not fast enough on its own to prevent hours of unsupervised access to a production server.
Takeaways for businesses with on-premises systems
If your business depends on an older on-premises application that has to be reachable from the outside world, an ERP system, a practice management platform, or other line-of-business software, three points are worth taking seriously.
Detection alone is not protection. A tool that only alerts a human is only as fast as the human who responds. Attackers move in minutes, not hours.
Autonomous response matters more than most feature sheets suggest. Ask any vendor directly: does this platform act on its own, or does it wait for a person to decide?
Layered defense works. Adding a second tool with a different response model, even mid-incident, made a measurable difference within 48 hours.
Why we changed our standard
After this experience, Tailored Technology Services transitioned managed clients to Huntress as our standard endpoint protection and response solution. This case study is a direct account of why: not a comparison of marketing claims, but of what happened when the same attacker came back for a second round.
Security tools are judged on feature sheets all the time. We would rather be judged on what happens during an actual incident, on a real server, against a real attacker.
This case study describes a real incident affecting a Tailored Technology Services client. Identifying details have been generalized to protect client confidentiality. Timelines reflect data from vendor incident reports and internal documentation.
Keep going
Questions on this topic
Short answers for buyers comparing options.
Did both tools detect the attack?
Yes. Detection speed was essentially the same in both incidents. The difference was what happened after detection: alert-and-wait versus autonomous isolation.
Is alert-only EDR useless?
No. Strong detection and skilled monitoring still matter for investigation and recovery. On this attack path, alert-only response left hours of attacker access that autonomous isolation prevented on the second attempt.
Are internet-facing on-premises systems still common?
Yes. Many professional services and specialty firms still run line-of-business software that must accept remote connections. Those hosts need response policies that match how fast modern attackers move.
Is Huntress now the standard for Tailored Tech clients?
Yes. Following this incident, Huntress became our standard endpoint protection and response platform for managed clients. Ask us what is deployed in your environment if you are unsure.
Want this applied to your environment?
Tell us how the business runs. We will map the model without a long pitch.
