Fortinet white logo
Fortinet white logo

Forensic analysis

Forensic analysis

The forensic analysis feature in SOCaaS allows you to submit and view forensic analysis requests using the FortiClient Forensic Service. The FortiClient Forensic Service provides analysis to help endpoint customers respond to and recover from cyber incidents using forensic analysts from Fortinet's FortiGuard Labs.

Note

SOCaaS does not perform any forensic analysis as a part of the service. When a forensic analysis request is submitted, a notice is provided from the SOCaaS portal to the forensic analysis team so that they can begin the requested analysis.

For more information on forensic analysis, see the FortiClient Forensic Service data sheet and Forensics Analysis User Guide.

In order to use forensic analysis, you must have the following:

  • A FortiClient EMS or FortiSASE onboarded to SOCaaS with an entitlement for Forensic Service. See Licensing.

  • Endpoint(s) with FortiClient managed by the onboarded FortiClient EMS or FortiSASE.

You can initiate new forensic analysis requests when viewing SOCaaS alerts. See Request forensic analysis.

After a forensic analysis request has been submitted, you can review the details of the request. See View forensic analysis request details

Forensic analysis

Forensic analysis

The forensic analysis feature in SOCaaS allows you to submit and view forensic analysis requests using the FortiClient Forensic Service. The FortiClient Forensic Service provides analysis to help endpoint customers respond to and recover from cyber incidents using forensic analysts from Fortinet's FortiGuard Labs.

Note

SOCaaS does not perform any forensic analysis as a part of the service. When a forensic analysis request is submitted, a notice is provided from the SOCaaS portal to the forensic analysis team so that they can begin the requested analysis.

For more information on forensic analysis, see the FortiClient Forensic Service data sheet and Forensics Analysis User Guide.

In order to use forensic analysis, you must have the following:

  • A FortiClient EMS or FortiSASE onboarded to SOCaaS with an entitlement for Forensic Service. See Licensing.

  • Endpoint(s) with FortiClient managed by the onboarded FortiClient EMS or FortiSASE.

You can initiate new forensic analysis requests when viewing SOCaaS alerts. See Request forensic analysis.

After a forensic analysis request has been submitted, you can review the details of the request. See View forensic analysis request details