Fortinet black logo

User Guide

Default alerts

Default alerts

FortiRecon automatically sends out default alerts if certain triggers are identified. Default alerts for each module include:

Module

Alert

External Attack Surface Management (EASM)
  • New scan refresh

  • Leaked credentials present as part of a third party breach

  • Continuous monitoring refresh alert

  • Leaked credentials for new domain

Internal Attack Surface Management (IASM)

  • New scan refresh

Brand Protection (BP)
  • Fraudulent domains identified, such as phishing and brand impersonation

  • New rogue mobile application identified

  • Social media impersonation identified

  • Exposed sensitive information on code repository

  • Files found in open cloud storage bucket

  • New threats to executives in executive monitoring

Adversary Centric Intelligence (ACI)
  • Any published flash alert or report

  • Any high relevance report

  • Stealer infection identified

  • Credit or debit cards identified on card shops

  • Organization or vendor listed on a ransomware naming and shaming site

  • Intelligence collection lookup alert, if there is a match in the default system ICL query

  • Daily digest

Default alerts

FortiRecon automatically sends out default alerts if certain triggers are identified. Default alerts for each module include:

Module

Alert

External Attack Surface Management (EASM)
  • New scan refresh

  • Leaked credentials present as part of a third party breach

  • Continuous monitoring refresh alert

  • Leaked credentials for new domain

Internal Attack Surface Management (IASM)

  • New scan refresh

Brand Protection (BP)
  • Fraudulent domains identified, such as phishing and brand impersonation

  • New rogue mobile application identified

  • Social media impersonation identified

  • Exposed sensitive information on code repository

  • Files found in open cloud storage bucket

  • New threats to executives in executive monitoring

Adversary Centric Intelligence (ACI)
  • Any published flash alert or report

  • Any high relevance report

  • Stealer infection identified

  • Credit or debit cards identified on card shops

  • Organization or vendor listed on a ransomware naming and shaming site

  • Intelligence collection lookup alert, if there is a match in the default system ICL query

  • Daily digest