Fortinet white logo
Fortinet white logo

Administration Guide

Understanding IOC entries

Understanding IOC entries

When a log entry is received and inserted into the SQL database, the log entry is scanned and compared to the blocklist and suspicious list in the IOC threat database that is downloaded from FortiGuard.

If a match is found in the blocklist, FortiAnalyzer displays the endpoint in Indicator of Compromise with a Verdict of Infected.

If a match is found in the suspicious list, FortiAnalyzer flags the endpoint for further analysis.

When an endpoint is displayed in Indicator of Compromise, all the suspicious logs which contributed to the score are listed.

When the database is rebuilt, all log entries are reinserted and rescanned.

Understanding IOC entries

Understanding IOC entries

When a log entry is received and inserted into the SQL database, the log entry is scanned and compared to the blocklist and suspicious list in the IOC threat database that is downloaded from FortiGuard.

If a match is found in the blocklist, FortiAnalyzer displays the endpoint in Indicator of Compromise with a Verdict of Infected.

If a match is found in the suspicious list, FortiAnalyzer flags the endpoint for further analysis.

When an endpoint is displayed in Indicator of Compromise, all the suspicious logs which contributed to the score are listed.

When the database is rebuilt, all log entries are reinserted and rescanned.