PCAP encryption keys
PCAP Encryption Keys are used in conjunction with Packet Capture. If an encryption key is uploaded, all PCAP files will be encrypted with the provided key. This prevents FortiNDR Cloud from having any visibility into the raw PCAP data that was captured. For more information, see Packet capture.
The Uploaded by field displays the full name and UUID of the user who uploaded the encryption key as well as the Uploaded date. If the user does not belong to the account, Unknown User is displayed.
|
|
The corresponding private key will be required to decrypt any downloaded PCAP files. If the private key is lost, the encrypted PCAP files cannot be recovered. |
To upload an encryption key:
- Click the gear icon at the top-right of the page and select Account Management.
- Select an account.
- Click the Settings tab.
- Under PCAP ENCRYPTION KEYS, click Set PCAP Encryption Key. The Set PCAP Encryption Key dialog opens.
- Paste the public key and click Set Key. The encryption key is validated for errors.
The key will take effect for any new PCAP files generated. Existing PCAP files are not retroactively encrypted.