Introduction
You can request forensic analysis on a suspected device from EMS. The Fortinet forensics team investigates the logs and provides a detailed report with their verdict. You can download the report from EMS.
You can use this feature with on-premise EMS or FortiClient Cloud.
For on-premise EMS, you can only request forensic analysis for Windows or macOS endpoints. FortiClient (macOS) 7.4.1 and later versions support forensic analysis.
You need to apply the Forensics license to EMS to access this feature. The following assumes that you have acquired and applied the license as necessary.