Fortinet white logo
Fortinet white logo

Product integration and support

Product integration and support

Integrations

The following table lists FortiNDR Cloud product integration and support information. Integration guides are available on the FortiNDR Cloud Integrations page.

SIEM

CrowdStrike

Tested with Parser 1.0.2

FortiSIEM 7.1.0 or higher
Microsoft Sentinel Not applicable
QRadar IBM QRadar SIEM version 7.3.3 or higher
Splunk Splunk Cloud versions: 9.3, 9.2, 9.1

SOAR

Cortex-XSOAR Tested on: 6.6
FortiSOAR Tested on: 7.3.2-2150
Splunk SOAR

7.3.2-2150 or higher

EDR / Firewall

CrowdStrike EDR

Latest Falcon EDR APIs

FortiEDR Not applicable
FortiEDR Manager

6.2.0 or higher

FortiEDR Collector

5.2.0 or higher

FortiManager

7.4.2 or higher

FortiGate

7.4.2 or higher

Intelligence Feeds

CrowdStrike Falcon Intel

Included with FortiNDR Cloud

Fortinet Botnet IP List

Included with FortiNDR Cloud

Internet Scan Data B (Shodan)

Included with FortiNDR Cloud

Known Sinkholes

Included with FortiNDR Cloud

PhishTank

Included with FortiNDR Cloud

Proofpoint TAP

Included with FortiNDR Cloud

Recorded Future connect

Included with FortiNDR Cloud

ThreatConnect

Included with FortiNDR Cloud

Tor Nodes

Included with FortiNDR Cloud

URLHaus

Included with FortiNDR Cloud

Other

Endace 7.2.2 or higher

Netskope

Not applicable

Zscaler

Not applicable

Fortinet Automation Service

The following table lists the current Fortinet Automation Service solution pack versions. For information about the Fortinet Automation Service, see the FortiNDR Cloud User Guide.

Solution Pack Version Connectors and Playbooks
1.0.0 FortiClientEMS, FortiEDR, FortiDeceptor
1.0.1 FortiClientEMS, FortiEDR, FortiDeceptor, FortiGate, Sentinel One

1.0.2

FortiClientEMS, FortiEDR, FortiDeceptor, FortiGate, FortiProxy, Sentinel One

Product integration and support

Product integration and support

Integrations

The following table lists FortiNDR Cloud product integration and support information. Integration guides are available on the FortiNDR Cloud Integrations page.

SIEM

CrowdStrike

Tested with Parser 1.0.2

FortiSIEM 7.1.0 or higher
Microsoft Sentinel Not applicable
QRadar IBM QRadar SIEM version 7.3.3 or higher
Splunk Splunk Cloud versions: 9.3, 9.2, 9.1

SOAR

Cortex-XSOAR Tested on: 6.6
FortiSOAR Tested on: 7.3.2-2150
Splunk SOAR

7.3.2-2150 or higher

EDR / Firewall

CrowdStrike EDR

Latest Falcon EDR APIs

FortiEDR Not applicable
FortiEDR Manager

6.2.0 or higher

FortiEDR Collector

5.2.0 or higher

FortiManager

7.4.2 or higher

FortiGate

7.4.2 or higher

Intelligence Feeds

CrowdStrike Falcon Intel

Included with FortiNDR Cloud

Fortinet Botnet IP List

Included with FortiNDR Cloud

Internet Scan Data B (Shodan)

Included with FortiNDR Cloud

Known Sinkholes

Included with FortiNDR Cloud

PhishTank

Included with FortiNDR Cloud

Proofpoint TAP

Included with FortiNDR Cloud

Recorded Future connect

Included with FortiNDR Cloud

ThreatConnect

Included with FortiNDR Cloud

Tor Nodes

Included with FortiNDR Cloud

URLHaus

Included with FortiNDR Cloud

Other

Endace 7.2.2 or higher

Netskope

Not applicable

Zscaler

Not applicable

Fortinet Automation Service

The following table lists the current Fortinet Automation Service solution pack versions. For information about the Fortinet Automation Service, see the FortiNDR Cloud User Guide.

Solution Pack Version Connectors and Playbooks
1.0.0 FortiClientEMS, FortiEDR, FortiDeceptor
1.0.1 FortiClientEMS, FortiEDR, FortiDeceptor, FortiGate, Sentinel One

1.0.2

FortiClientEMS, FortiEDR, FortiDeceptor, FortiGate, FortiProxy, Sentinel One