DOCUMENT LIBRARY
DOCUMENT LIBRARY
Products
Best Practices
Hardware Guides
Products A-Z
Summary
By Solution
By 4D Pillars
By Cloud
Secure Networking
Unified SASE
Security Operations
Secure SD-WAN
Secure Access Service Edge (SASE)
ZTNA
LAN Edge
Identity and Access Management
Next Generation Firewall
Public Cloud
Private Cloud
FortiCloud
Secure Networking
Hybrid Mesh Firewall
FortiGate/ FortiOS
FortiGate-5000
/
6000
/
7000
NOC Management
FortiManager
/
FortiManager Cloud
Managed Fortigate Service
LAN
FortiSwitch
FortiAP / FortiWiFi
FortiEdge Cloud
FortiNAC-F
WAN
Secure SD-WAN
FortiExtender
More >>
Unified SASE
Single Vendor SASE
FortiSASE
Secure SD-WAN
Zero Trust Network Access (ZTNA)
FortiProxy
FortiMonitor
Cloud Network Security
FortiGate Public Cloud
FortiGate Private Cloud
FortiGate CNF
FortiFlex
Lacework FortiCNAPP
Secure Endpoint Connectivity
FortiClient
/
FortiClient Cloud
Web Application / API Protection
FortiWeb
FortiADC
FortiDAST
More >>
Security Operations
Security Operations Automation
FortiAnalyzer
/
FortiAnalyzer Cloud
FortiSIEM
/
FortiSIEM Cloud
FortiSOAR
SOC-as-a-Service (SOCaaS)
Identity
FortiAuthenticator
FortiTrust Identity
FortiPAM
Early Detection & Prevention
FortiSandbox
/
FortiSandbox Cloud
FortiNDR
FortiDeceptor
FortiRecon
More >>
Secure Networking
Hybrid Mesh Firewall
FortiGate/ FortiOS
FortiGate-5000
/
6000
/
7000
NOC Management
FortiManager
/
FortiManager Cloud
Managed Fortigate Service
FortiAIOps
LAN
FortiSwitch
FortiAP / FortiWiFi
FortiAP-U Series
FortiEdge Cloud
FortiNAC-F
WAN
Secure SD-WAN
FortiExtender
Communication & Surveillance
FortiVoice
/
FortiVoice Cloud
FortiFone
FortiCamera
FortiRecorder
FortiCentral
Unified SASE
Single Vendor SASE
FortiSASE
Secure SD-WAN
Zero Trust Network Access (ZTNA)
FortiProxy
FortiMonitor
Secure Endpoint Connectivity
FortiClient
/
FortiClient Cloud
Cloud Network Security
FortiGate Public Cloud
FortiGate Private Cloud
FortiGate CNF
FortiFlex
Cloud-Native Security
Lacework FortiCNAPP
FortiDevSec
Web Application / API Protection
FortiWeb
FortiADC
FortiDAST
Security Operations
Security Operations Automation
FortiAnalyzer
/
FortiAnalyzer Cloud
FortiSIEM
/
FortiSIEM Cloud
FortiSOAR
Endpoint
FortiClient
/
FortiClient Cloud
FortiEDR/XDR
Data Protection
FortiDLP
FortiDLP Agent
FortiDLP Policies
Identity
FortiAuthenticator
FortiTrust Identity
FortiToken
/
FortiToken Cloud
FortiPAM
Email
FortiMail
FortiPhish
Early Detection & Prevention
FortiSandbox
/
FortiSandbox Cloud
FortiNDR
FortiDeceptor
FortiRecon
Expert Services
SOC-as-a-Service (SOCaaS)
Edge Firewall
FortiGate/FortiOS
FortiGate-5000
/
6000
/
7000
FortiGate Public Cloud
FortiGate Private Cloud
Orchestration & management
FortiManager
/
FortiManager Cloud
FortiAnalyzer
/
FortiAnalyzer Cloud
Overlay-as-a-Service
SD Branch
FortiSwitch
FortiAP / FortiWiFi
FortiExtender
/
FortiExtender Cloud
Application Delivery
FortiADC
/
FortiGSLB
Single Vendor SASE
FortiSASE
Secure Endpoint Connectivity
FortiClient
/
FortiClient Cloud
Secure Private Access
Secure SD-WAN
Zero Trust Network Access (ZTNA)
Thin Edge
FortiGate/ FortiOS
FortiAP / FortiWiFi
FortiExtender
/
FortiExtender Cloud
Identity
FortiAuthenticator
FortiTrust Identity
FortiToken Cloud
FortiToken
Application Gateway
FortiGate/ FortiOS
FortiProxy
FortiADC
/
FortiGSLB
Enterprise Asset Management
FortiClient EMS
Endpoint Agent
FortiClient
/
FortiClient Cloud
Agentless Security Posture
FortiNAC-F
FortiSIEM
/
FortiSIEM Cloud
Identity
FortiAuthenticator
FortiTrust Identity
FortiToken Cloud
FortiToken
Wireless
FortiAP / FortiWiFi
FortiAP-U Series
FortiGate Cloud
Switching
FortiSwitch
FortiEdge Cloud
FortiNAC-F
Identity
FortiAuthenticator
FortiTrust Identity
FortiToken Cloud
FortiToken
Privilege Acccess Management
FortiPAM
Next Generation Firewall
FortiGate / FortiOS
FortiGate-5000
/
6000
/
7000
FortiGate Public Cloud
FortiGate Private Cloud
Orchestration & management
FortiManager
/
FortiManager Cloud
FortiAnalyzer
/
FortiAnalyzer Cloud
Expert Services
SOC-as-a-Service (SOCaaS)
Managed Fortigate Service
All
FortiADC Public Cloud
FortiAnalyzer Public Cloud
FortiAuthenticator Public Cloud
FortiDeceptor Public Cloud
FortiGate Public Cloud
FortiIsolator Public Cloud
FortiManager Public Cloud
FortiNDR Public Cloud
FortiPAM Public Cloud
FortiPortal Public Cloud
FortiProxy Public Cloud
FortiSandbox Public Cloud
FortiTester Public Cloud
FortiVoice Public Cloud
FortiWeb Manager Public Cloud
FortiWeb Public Cloud
All
FortiADC Private Cloud
FortiAnalyzer BigData Private Cloud
FortiAnalyzer Private Cloud
FortiAuthenticator Private Cloud
FortiDeceptor Private Cloud
FortiGate Private Cloud
FortiManager Private Cloud
FortiNDR Private Cloud
FortiPAM Private Cloud
FortiProxy Private Cloud
FortiSandbox Private Cloud
FortiTester Private Cloud
FortiVoice Private Cloud
FortiWeb Manager Private Cloud
FortiWeb Private Cloud
Account Management
FortiCloud Services
SAAS Management
FortiGate Cloud
FortiEdge Cloud
FortiEdge Cloud
FortiExtender Cloud
FortiPresence Cloud
FortiToken Cloud
FortiTrust Identity
FortiZTP
FortiCamera Cloud
SAAS Application Security
FortiWeb Cloud
FortiGSLB
FortiCASB
FortiCNP
FortiInsight
FortiPhish
FortiGate CNF
Managed Services
SOC-as-a-Service (SOCaaS)
Managed Fortigate Service
Platform as a service (PAAS)
FortiSASE
FortiAnalyzer Cloud
FortiManager Cloud
FortiClient Cloud
FortiSandbox Cloud
FortiMail Cloud
FortiSOAR Cloud
Other SAAS Services
Overlay-as-a-Service
FortiRecon
FortiConverter
ForiIPAM
FortiFlex
FortiCare Elite
4D Resources
Solution Hubs
Define, design, deploy, demo
4D Pillars
Secure SD-WAN
Zero Trust Network Access
Wireless
Switching
Secure Access Service Edge
Identity and Access Management
Next Generation Firewall
Curated Links by Solution
Cloud
FortiCloud
Public & Private Cloud
Popular Solutions
Secure SD-WAN
Zero Trust Network Access
Secure Access
Security Fabric
Tele-Working
Multi-Factor Authentication
FortiASIC
Operational Technology
MSSP
Next Generation Firewall
FortiAnalyzer
FortiAnalyzer Big-Data
FortiADC
FortiAP / FortiWiFi
FortiAP U-Series
FortiAuthenticator
FortiCache
FortiCarrier
FortiController
FortiDDoS
FortiDDoS-F
FortiDeceptor
FortiExtender
FortiGate-5000
FortiGate-6000
FortiGate-7000
FortiHypervisor
FortiIsolator
FortiMail
FortiManager
FortiNAC
FortiNDR
FortiProxy
FortiRecorder
FortiGate
FortiRPS
FortiSandbox
FortiSIEM
FortiSwitch
FortiTester
FortiToken
FortiVoice
FortiWAN
FortiWeb
FortiWLC
FortiWLM
AscenLink
AV Engine
AWS Firewall Rules
Container FortiOS
FortiADC
FortiADC E Series
FortiADC Manager
FortiADC Private Cloud
FortiADC Public Cloud
FortiAIOps
FortiAnalyzer
FortiAnalyzer BigData
FortiAnalyzer BigData Private Cloud
FortiAnalyzer Cloud
FortiAnalyzer Private Cloud
FortiAnalyzer Public Cloud
FortiAP / FortiWiFi
FortiAP-U Series
FortiAuthenticator
FortiAuthenticator Private Cloud
FortiAuthenticator Public Cloud
FortiAuthProxy
FortiBalancer
FortiBranchSASE
FortiBridge
FortiCache
FortiCamera
FortiCamera Cloud
FortiCare Elite
FortiCarrier
FortiCASB
FortiCentral
FortiClient
FortiClient Cloud
FortiCloud Services
FortiCNP
FortiConnect
FortiController
FortiConverter Service
FortiConverter Tool
FortiCore
FortiCSPM
FortiCWP
FortiDAST
FortiDB
FortiDDoS
FortiDDoS-F
FortiDeceptor
FortiDeceptor DaaS
FortiDeceptor Private Cloud
FortiDeceptor Public Cloud
FortiDevSec
FortiDLP
FortiDLP Agent
FortiDLP Policies
FortiDNS
FortiEdge Cloud
FortiEDR/XDR
FortiEndpoint
FortiExplorer
FortiExplorer Go
FortiExtender
FortiFlex
FortiFone
FortiGate / FortiOS
FortiGate Cloud
FortiGate CNF
FortiGate Private Cloud
FortiGate Public Cloud
FortiGate-5000
FortiGate-6000
FortiGate-7000
FortiGate-as-a-Service
FortiGSLB
FortiGuard Advanced Bot Protection
FortiGuest
FortiHypervisor
FortiInsight
FortiInsight Cloud
FortiIPAM
FortiIsolator
FortiIsolator Public Cloud
FortiLAN Cloud
FortiMail
FortiMail Cloud
FortiManager
FortiManager Cloud
FortiManager Private Cloud
FortiManager Public Cloud
FortiMonitor
FortiNAC
FortiNAC-F
FortiNDR
FortiNDR (on-premise) Private Cloud
FortiNDR (on-premise) Public Cloud
FortiNDR Cloud
FortiNDR Cloud Sensors
FortiPAM
FortiPAM Private Cloud
FortiPAM Public Cloud
FortiPhish
FortiPlanner
FortiPolicy
FortiPortal
FortiPortal Public Cloud
FortiPresence
FortiPresence VM
FortiProxy
FortiProxy Private Cloud
FortiProxy Public Cloud
FortiRecon
FortiRecorder
FortiRPS
FortiSandbox
FortiSandbox Cloud
FortiSandbox Private Cloud
FortiSandbox Public Cloud
FortiSASE
FortiScanner
FortiSIEM
FortiSIEM Cloud
FortiSOAR
FortiSOAR Cloud
FortiSRA
FortiSwitch
FortiSwitch Manager
FortiTap
FortiTester
FortiTester Private Cloud
FortiTester Public Cloud
FortiToken
FortiToken Cloud
FortiTrust Identity
FortiVoice
FortiVoice Cloud
FortiVoice Private Cloud
FortiVoice Public Cloud
FortiWAN
FortiWAN Controller
FortiWeb
FortiWeb Cloud
FortiWeb Manager Private Cloud
FortiWeb Manager Public Cloud
FortiWeb Private Cloud
FortiWeb Public Cloud
FortiWLM
FortiZTP
IPS Engine
Lacework FortiCNAPP
Managed FortiGate Service
Overlay-as-a-Service
Security Awareness and Training
SOCaaS
Wireless Controller
Search documents and hardware ...
Administration Guide
Introducing FortiEDR
FortiEDR components
How does FortiEDR work?
Using FortiEDR - workflow
Deploying FortiEDR Collectors
Installing FortiEDR Collectors
Before you start
Installing a FortiEDR Collector on Windows
Installing a FortiEDR Collector on macOS
Installing a FortiEDR Collector on Linux
Automated FortiEDR Collector deployment
Installing FortiEDR on Mac Big Sur devices using Jamf PRO
Setting up exclusions with other AV products
Working with FortiEDR on VDI environments
Uninstalling FortiEDR Collectors
Upgrading the Collector
Setting up a FortiEDR Core as a Jumpbox
Upgrading the Core
Security Settings
Security events
Out-of-the-box policies
Protection or Simulation mode
Security Policies page
Setting a security policy’s Prevention or Simulation mode
Creating a new security policy
Assigning a security policy to a Collector Group
Exception Manager
Exclusion Manager
Filtering
Defining Exclusion Lists
Defining exclusions
Application Control Manager
Adding application(s) to be blocked
Manually adding an application to be blocked
Uploading application(s) to be blocked
Exporting the list of applications to be blocked
Enabling/disabling application blocking
Changing the policy under which the application is blocked
Searching and filtering applications
Threat Hunting
Collection Profiles
Assigning a Collector Group to a Profile
Creating/cloning a Profile
Collection Exclusions
Filters
Defining Collection Exclusion Lists
Defining Collection Exclusions
Threat Hunting data retention
Playbook policies
Automated Incident Response - Playbooks Page
Assigned Collector Groups
Advanced Playbooks Data
Playbook policy actions
Inventory
Collectors
Defining a new Collector Group
Assigning Collectors to a Collector Group
Deleting a Collector Group/Collector
Enabling/disabling a Collector
Device isolation
Unmanaged devices
IoT devices
Defining a new IoT group
Assigning devices to an IoT group
Deleting an IoT device/IoT group
Refreshing IoT device data
Exporting IoT information
System Components
Aggregators
Cores
Repositories
Exporting logs
Exporting logs for Collectors
Exporting logs for Cores
Exporting logs for Aggregators
Dashboard
Introduction
Security Events chart
Communication Control chart
Collectors chart
Most Targeted charts
External Destinations
System Components
Executive Summary Report
Event Statistics
Destinations
Most-targeted Devices
Most-targeted Processes
Communication Control
System Components
License Status
Event Viewer
Introducing the Event Viewer
Events pane
Advanced Data
Event Graph
Geo Location
Automated Analysis
Marking a security event as handled/unhandled
Manually changing the classification of a security event
Defining security event exceptions
Defining the scope of an exception
Defining a security event as an exception
Device Control exceptions
Editing security event exceptions
Marking a security event as read/unread
Viewing relevant activity events
Viewing expired security events
Viewing Application Control security events
Viewing Device Control security events
Other options in the Event Viewer
Classification Details
Communication control
Application communication control - how does it work?
Introducing communication control
Applications
Reputation score
Vulnerability
Resolved vs. unresolved applications
Sorting the Application List
Marking an Entry as Read/Unread
Modifying a Policy Action
Searching the Application List
Other options in the Application pane
Advanced Data
Policies
Predefined policies
Policy mode
Policy rules
Assigning a policy to a Collector Group
Creating a new Communication Control policy
Other options in the Policies pane
Forensics
Introduction
Flow Analyzer view
Stack view
Compare view
Defining an exception
Remediating a device upon malware detection
Retrieving memory
Isolating a device
Threat Hunting
Threat Hunting
Filters
Facets
Activity events tables
Details pane
Legacy Threat Hunting
FortiEDR Connect
Connecting to a FortiEDR-protected device
File Library Pane
Uploading a file to the FortiEDR file library
Uploading a file from the FortiEDR file library to a FortiEDR-protected device
Download a file from a FortiEDR-protected device
Disconnecting FortiEDR Connect session
Administration
Licensing
Updating the Collector version
Loading a server certificate
Requesting and obtaining a Collector installer
Users
Two-factor authentication
Resetting a user password
LDAP authentication
SAML authentication
SAML IdP configuration with Azure
SAML IdP configuration with Okta
SAML IdP Configuration with FortiAuthenticator
Setting up FortiAuthenticator as an IdP
Setting up user group management
Setting up service provider for FortiEDR
Distribution lists
Export settings
SMTP
Open Ticket
Syslog
Tools
Audit trail
Component authentication
File scan
End-user notifications
IoT device discovery
Personal data handling
Windows Security Center
FortiEDR Connect
System events
IP sets
Integrations
Adding connectors
Firewall integration
Network Access Control (NAC) integration
Identity Management integration
User Access integration
Sandbox integration
eXtended detection source integration
FortiAnalyzer
Google Cloud Security Command Center (SCC)
AWS GuardDuty
Custom integration
Action Manager
Troubleshooting
A FortiEDR Collector does not display in the INVENTORY tab
User cannot communicate externally or files modification activity is blocked
Collector is slow or hangs
Multi-tenancy (organizations)
What is a multi-organization environment in FortiEDR?
Component registration in a multi-organization environment
Workflow
Step 1 – Logging in to a multi-organization system
Step 2 – Defining or importing an organization
Step 3 - Navigating between organizations
Step 4 – Defining an Administrator for an organization
Step 5 – Performing operations in the FortiEDR system
Migrating an organization
Hoster view
Licensing
Users
Tools
Dashboard
Event Viewer
Forensics
Communication Control
Threat Hunting
Security settings
Exception Manager
Inventory
Appendix A – Setting up an email feed for open ticket
Appendix B - Lucene syntax
Change log
Home
FortiEDR/XDR 5.2.1
Administration Guide
5.2.1
6.2.0
6.0.0
5.2.1
5.2.0
5.1.0
5.0.0
4.2.0
4.1.1
4.1.0
Export settings
Export settings
The
EXPORT SETTINGS
option provides access to the following options:
•
SMTP
•
Open Ticket
•
Syslog
Previous
Next
Export settings
Export settings
The
EXPORT SETTINGS
option provides access to the following options:
•
SMTP
•
Open Ticket
•
Syslog
Previous
Next
Home
Product Pillars
Network Security
Network Security
FortiGate / FortiOS
FortiGate 5000
FortiGate 6000
FortiGate 7000
FortiProxy
NOC & SOC Management
FortiManager
FortiManager Cloud
FortiAnalyzer
FortiAnalyzer Cloud
FortiMonitor
FortiGate Cloud
Enterprise Networking
Secure SD-WAN
FortiLAN Cloud
FortiSwitch
FortiAP / FortiWiFi
FortiAP-U Series
FortiNAC-F
FortiExtender
FortiExtender Cloud
FortiAIOps
Business Communications
FortiFone
FortiVoice
FortiVoice Cloud
FortiRecorder
FortiCamera
Zero Trust Access
ZTNA
Zero Trust Network Access
FortiClient EMS
SASE
FortiSASE
Identity
FortiAuthenticator
FortiTrust Identity
FortiToken Cloud
FortiToken
Cloud Security
Hybrid Cloud Security
FortiGate Public Cloud
FortiGate Private Cloud
FortiFlex
Cloud Native Protection
FortiCNP
FortiDevSec
Web Application / API Protection
FortiWeb
FortiWeb Cloud
FortiADC
FortiGSLB
FortiGuard ABP
SAAS Security
FortiMail
FortiMail Cloud
FortiCASB
Security Operations
SOC Platform
FortiAnalyzer
FortiAnalyzer Cloud
FortiSIEM
/
FortiSIEM Cloud
FortiSOAR
FortiPhish
Advanced Threat Protection
FortiSandbox
FortiSandbox Cloud
FortiNDR
FortiNDR Cloud
FortiDeceptor
FortiInsight
FortiInsight Cloud
FortiIsolator
Endpoint Security
FortiClient
FortiClient Cloud
FortiEDR
Best Practices
Solution Hubs
Cloud
FortiCloud
Public & Private Cloud
Popular Solutions
Secure SD-WAN
Zero Trust Network Access
Secure Access
Next Generation Firewall
Security Fabric
Tele-Working
Multi-Factor Authentication
FortiASIC
Operational Technology
MSSP
4-D Resources
Secure SD-WAN
Zero Trust Network Access
Wireless
Switching
Secure Access Service Edge
Identity and Access Management
Next Generation Firewall
Hardware Guides
FortiAnalyzer
FortiAnalyzer Big-Data
FortiADC
FortiAP / FortiWiFi
FortiAP U-Series
FortiAuthenticator
FortiCache
FortiCarrier
FortiController
FortiDDoS
FortiDDoS-F
FortiDeceptor
FortiExtender
FortiGate
FortiGate-5000
FortiGate-6000
FortiGate-7000
FortiHypervisor
FortiIsolator
FortiMail
FortiManager
FortiNAC
FortiNDR
FortiProxy
FortiRecorder
FortiRPS
FortiSandbox
FortiSIEM
FortiSwitch
FortiTester
FortiToken
FortiVoice
FortiWAN
FortiWeb
FortiWLC
FortiWLM
Product A-Z
AscenLink
AV Engine
AWS Firewall Rules
Container FortiOS
FortiADC
FortiADC E Series
FortiADC Manager
FortiADC Private Cloud
FortiADC Public Cloud
FortiAIOps
FortiAnalyzer
FortiAnalyzer BigData
FortiAnalyzer BigData Private Cloud
FortiAnalyzer Cloud
FortiAnalyzer Private Cloud
FortiAnalyzer Public Cloud
FortiAP / FortiWiFi
FortiAP-U Series
FortiAuthenticator
FortiAuthenticator Private Cloud
FortiAuthenticator Public Cloud
FortiAuthProxy
FortiBalancer
FortiBranchSASE
FortiBridge
FortiCache
FortiCamera
FortiCamera Cloud
FortiCare Elite
FortiCarrier
FortiCASB
FortiCentral
FortiClient
FortiClient Cloud
FortiCloud Services
FortiCNP
FortiConnect
FortiController
FortiConverter Service
FortiConverter Tool
FortiCore
FortiCSPM
FortiCWP
FortiDAST
FortiDB
FortiDDoS
FortiDDoS-F
FortiDeceptor
FortiDeceptor DaaS
FortiDeceptor Private Cloud
FortiDeceptor Public Cloud
FortiDevSec
FortiDLP
FortiDLP Agent
FortiDLP Policies
FortiDNS
FortiEdge Cloud
FortiEDR/XDR
FortiEndpoint
FortiExplorer
FortiExplorer Go
FortiExtender
FortiFlex
FortiFone
FortiGate / FortiOS
FortiGate Cloud
FortiGate CNF
FortiGate Private Cloud
FortiGate Public Cloud
FortiGate-5000
FortiGate-6000
FortiGate-7000
FortiGate-as-a-Service
FortiGSLB
FortiGuard Advanced Bot Protection
FortiGuest
FortiHypervisor
FortiInsight
FortiInsight Cloud
FortiIPAM
FortiIsolator
FortiIsolator Public Cloud
FortiLAN Cloud
FortiMail
FortiMail Cloud
FortiManager
FortiManager Cloud
FortiManager Private Cloud
FortiManager Public Cloud
FortiMonitor
FortiNAC
FortiNAC-F
FortiNDR
FortiNDR (on-premise) Private Cloud
FortiNDR (on-premise) Public Cloud
FortiNDR Cloud
FortiNDR Cloud Sensors
FortiPAM
FortiPAM Private Cloud
FortiPAM Public Cloud
FortiPhish
FortiPlanner
FortiPolicy
FortiPortal
FortiPortal Public Cloud
FortiPresence
FortiPresence VM
FortiProxy
FortiProxy Private Cloud
FortiProxy Public Cloud
FortiRecon
FortiRecorder
FortiRPS
FortiSandbox
FortiSandbox Cloud
FortiSandbox Private Cloud
FortiSandbox Public Cloud
FortiSASE
FortiScanner
FortiSIEM
FortiSIEM Cloud
FortiSOAR
FortiSOAR Cloud
FortiSRA
FortiSwitch
FortiSwitch Manager
FortiTap
FortiTester
FortiTester Private Cloud
FortiTester Public Cloud
FortiToken
FortiToken Cloud
FortiTrust Identity
FortiVoice
FortiVoice Cloud
FortiVoice Private Cloud
FortiVoice Public Cloud
FortiWAN
FortiWAN Controller
FortiWeb
FortiWeb Cloud
FortiWeb Manager Private Cloud
FortiWeb Manager Public Cloud
FortiWeb Private Cloud
FortiWeb Public Cloud
FortiWLM
FortiZTP
IPS Engine
Lacework FortiCNAPP
Managed FortiGate Service
Overlay-as-a-Service
Security Awareness and Training
SOCaaS
Wireless Controller
Ordering Guides
Download PDF
Table of Contents
Introducing FortiEDR
FortiEDR components
How does FortiEDR work?
Using FortiEDR - workflow
Deploying FortiEDR Collectors
Installing FortiEDR Collectors
Before you start
Installing a FortiEDR Collector on Windows
Installing a FortiEDR Collector on macOS
Installing a FortiEDR Collector on Linux
Automated FortiEDR Collector deployment
Installing FortiEDR on Mac Big Sur devices using Jamf PRO
Setting up exclusions with other AV products
Working with FortiEDR on VDI environments
Uninstalling FortiEDR Collectors
Upgrading the Collector
Setting up a FortiEDR Core as a Jumpbox
Upgrading the Core
Security Settings
Security events
Out-of-the-box policies
Protection or Simulation mode
Security Policies page
Setting a security policy’s Prevention or Simulation mode
Creating a new security policy
Assigning a security policy to a Collector Group
Exception Manager
Exclusion Manager
Filtering
Defining Exclusion Lists
Defining exclusions
Application Control Manager
Adding application(s) to be blocked
Manually adding an application to be blocked
Uploading application(s) to be blocked
Exporting the list of applications to be blocked
Enabling/disabling application blocking
Changing the policy under which the application is blocked
Searching and filtering applications
Threat Hunting
Collection Profiles
Assigning a Collector Group to a Profile
Creating/cloning a Profile
Collection Exclusions
Filters
Defining Collection Exclusion Lists
Defining Collection Exclusions
Threat Hunting data retention
Playbook policies
Automated Incident Response - Playbooks Page
Assigned Collector Groups
Advanced Playbooks Data
Playbook policy actions
Inventory
Collectors
Defining a new Collector Group
Assigning Collectors to a Collector Group
Deleting a Collector Group/Collector
Enabling/disabling a Collector
Device isolation
Unmanaged devices
IoT devices
Defining a new IoT group
Assigning devices to an IoT group
Deleting an IoT device/IoT group
Refreshing IoT device data
Exporting IoT information
System Components
Aggregators
Cores
Repositories
Exporting logs
Exporting logs for Collectors
Exporting logs for Cores
Exporting logs for Aggregators
Dashboard
Introduction
Security Events chart
Communication Control chart
Collectors chart
Most Targeted charts
External Destinations
System Components
Executive Summary Report
Event Statistics
Destinations
Most-targeted Devices
Most-targeted Processes
Communication Control
System Components
License Status
Event Viewer
Introducing the Event Viewer
Events pane
Advanced Data
Event Graph
Geo Location
Automated Analysis
Marking a security event as handled/unhandled
Manually changing the classification of a security event
Defining security event exceptions
Defining the scope of an exception
Defining a security event as an exception
Device Control exceptions
Editing security event exceptions
Marking a security event as read/unread
Viewing relevant activity events
Viewing expired security events
Viewing Application Control security events
Viewing Device Control security events
Other options in the Event Viewer
Classification Details
Communication control
Application communication control - how does it work?
Introducing communication control
Applications
Reputation score
Vulnerability
Resolved vs. unresolved applications
Sorting the Application List
Marking an Entry as Read/Unread
Modifying a Policy Action
Searching the Application List
Other options in the Application pane
Advanced Data
Policies
Predefined policies
Policy mode
Policy rules
Assigning a policy to a Collector Group
Creating a new Communication Control policy
Other options in the Policies pane
Forensics
Introduction
Flow Analyzer view
Stack view
Compare view
Defining an exception
Remediating a device upon malware detection
Retrieving memory
Isolating a device
Threat Hunting
Threat Hunting
Filters
Facets
Activity events tables
Details pane
Legacy Threat Hunting
FortiEDR Connect
Connecting to a FortiEDR-protected device
File Library Pane
Uploading a file to the FortiEDR file library
Uploading a file from the FortiEDR file library to a FortiEDR-protected device
Download a file from a FortiEDR-protected device
Disconnecting FortiEDR Connect session
Administration
Licensing
Updating the Collector version
Loading a server certificate
Requesting and obtaining a Collector installer
Users
Two-factor authentication
Resetting a user password
LDAP authentication
SAML authentication
SAML IdP configuration with Azure
SAML IdP configuration with Okta
SAML IdP Configuration with FortiAuthenticator
Setting up FortiAuthenticator as an IdP
Setting up user group management
Setting up service provider for FortiEDR
Distribution lists
Export settings
SMTP
Open Ticket
Syslog
Tools
Audit trail
Component authentication
File scan
End-user notifications
IoT device discovery
Personal data handling
Windows Security Center
FortiEDR Connect
System events
IP sets
Integrations
Adding connectors
Firewall integration
Network Access Control (NAC) integration
Identity Management integration
User Access integration
Sandbox integration
eXtended detection source integration
FortiAnalyzer
Google Cloud Security Command Center (SCC)
AWS GuardDuty
Custom integration
Action Manager
Troubleshooting
A FortiEDR Collector does not display in the INVENTORY tab
User cannot communicate externally or files modification activity is blocked
Collector is slow or hangs
Multi-tenancy (organizations)
What is a multi-organization environment in FortiEDR?
Component registration in a multi-organization environment
Workflow
Step 1 – Logging in to a multi-organization system
Step 2 – Defining or importing an organization
Step 3 - Navigating between organizations
Step 4 – Defining an Administrator for an organization
Step 5 – Performing operations in the FortiEDR system
Migrating an organization
Hoster view
Licensing
Users
Tools
Dashboard
Event Viewer
Forensics
Communication Control
Threat Hunting
Security settings
Exception Manager
Inventory
Appendix A – Setting up an email feed for open ticket
Appendix B - Lucene syntax
Change log