Fortinet white logo
Fortinet white logo

User Guide

Getting Started

Getting Started

The Security Orchestration module comes pre-installed with the FortiRecon Automation Service Solution Pack. This pack includes pre-defined playbooks for various security use cases, helping you get started quickly.

Caution

If you are an existing user of Security Orchestration, you must manually upgrade the FortiRecon Automation Service solution pack. This step is not necessary for new installations or for existing users who have not yet accessed Security Orchestration.

  1. To uninstall the older version of solution pack, navigate to Content Hub > Installed tab, apply the Solution Packs filter, select the FortiRecon Automation Service 1.0.0 entry, and then click Delete Template in the dialog box.

  2. To install the new version, navigate to Content Hub > Discover tab, apply the Solution Packs filter, search for and select FortiRecon Automation Service 1.0.1, and then click Install in the dialog box.

For more information on managing Solution Packs, see Solution Packs .

Running Playbooks

You can run playbooks from various locations within FortiRecon, including the Home tab, the Playbooks tab, or directly from supported FortiRecon pages.

The Action button in the following FortiRecon modules contains the Run Automation option, allowing you to execute compatible playbooks:

  • Attack Surface Management: Security Issues (EASM), and Leaked Credentials.

  • Brand Protection: Domain Threats, Social Media Threats, Rogue Mobile Apps, Code Repo Exposure, and Open Bucket Exposure.

  • Adversary Centric Intelligence: Stealer Infections.

Note

On FortiRecon pages, the system initially displays contextual playbooks. Remove any applied filters to view all available playbooks.

Playbook Types

Security Orchestration features two types of playbooks, each designed for different execution methods:

  • Standalone Playbooks: You configure and run these playbooks directly from the Security Orchestration module by clicking Run Automation or from action menus on specific pages within other FortiRecon modules. They contain end-to-end steps for complete automation. See Configuring and Running a Standalone Playbook.

  • Contextual Playbooks: You configure these playbooks within the Security Orchestration module, but you execute them from action menus on specific pages within other FortiRecon modules. These playbooks require input data directly from those FortiRecon modules. For instance, you configure the Create Ticket for Typosquat Domain Threat Alerts playbook in Security Orchestration, but you execute it from the Brand Protection > Domain Threats page. See Configuring and Running Contextual Playbooks.

Note

Only users with the FortiRecon Admin role can configure connectors.

Getting Started

Getting Started

The Security Orchestration module comes pre-installed with the FortiRecon Automation Service Solution Pack. This pack includes pre-defined playbooks for various security use cases, helping you get started quickly.

Caution

If you are an existing user of Security Orchestration, you must manually upgrade the FortiRecon Automation Service solution pack. This step is not necessary for new installations or for existing users who have not yet accessed Security Orchestration.

  1. To uninstall the older version of solution pack, navigate to Content Hub > Installed tab, apply the Solution Packs filter, select the FortiRecon Automation Service 1.0.0 entry, and then click Delete Template in the dialog box.

  2. To install the new version, navigate to Content Hub > Discover tab, apply the Solution Packs filter, search for and select FortiRecon Automation Service 1.0.1, and then click Install in the dialog box.

For more information on managing Solution Packs, see Solution Packs .

Running Playbooks

You can run playbooks from various locations within FortiRecon, including the Home tab, the Playbooks tab, or directly from supported FortiRecon pages.

The Action button in the following FortiRecon modules contains the Run Automation option, allowing you to execute compatible playbooks:

  • Attack Surface Management: Security Issues (EASM), and Leaked Credentials.

  • Brand Protection: Domain Threats, Social Media Threats, Rogue Mobile Apps, Code Repo Exposure, and Open Bucket Exposure.

  • Adversary Centric Intelligence: Stealer Infections.

Note

On FortiRecon pages, the system initially displays contextual playbooks. Remove any applied filters to view all available playbooks.

Playbook Types

Security Orchestration features two types of playbooks, each designed for different execution methods:

  • Standalone Playbooks: You configure and run these playbooks directly from the Security Orchestration module by clicking Run Automation or from action menus on specific pages within other FortiRecon modules. They contain end-to-end steps for complete automation. See Configuring and Running a Standalone Playbook.

  • Contextual Playbooks: You configure these playbooks within the Security Orchestration module, but you execute them from action menus on specific pages within other FortiRecon modules. These playbooks require input data directly from those FortiRecon modules. For instance, you configure the Create Ticket for Typosquat Domain Threat Alerts playbook in Security Orchestration, but you execute it from the Brand Protection > Domain Threats page. See Configuring and Running Contextual Playbooks.

Note

Only users with the FortiRecon Admin role can configure connectors.