Fortinet white logo
Fortinet white logo

Phishing Classifier Connector

1.0.0

Phishing Classifier Connector v1.0.0

Overview

FortiSOAR™ provides you with a number of pre-installed connectors or built-ins, such as the IMAP or Database connectors that you can use within FortiSOAR™ playbooks, as a connector step, and perform automated operations. These connectors are bundled and named based on the type of operations the connectors can perform. For example, the Database connector would contain actions that you can perform with respect to the database like querying the database. It is easy to extend and enhance these connectors.

Apart from the FortiSOAR™ Built-in connectors, Fortinet also provides a number of connectors for popular integrations like SIEMs, such as FortiSIEM, Splunk, etc., and Ticketing systems such as Jira. You can see a list of published connectors on the FortiSOAR Connectors Documentation site.

The process of installing, configuring, and using connectors is defined in the Introduction to connectors chapter in the "Connectors Guide", which is part of the FortiSOAR™ documentation or see the Installing a connector and Configuring a connector articles.

FortiSOAR™ Built-in connectors are upgraded by default with a FortiSOAR™ upgrade. Use the Content Hub to upgrade your connectors to the latest version. For more information on the connector store, see the Introduction to connectors chapter and see the FortiSOAR Built-in connectors article.

Important: Before you upgrade your FortiSOAR™ version, it is highly recommended that you take a backup of your FortiSOAR™ Built-in connector's (SSH, IMAP, Database, etc.) configuration since the configuration of your FortiSOAR™ Built-in connectors might be reset if there are changes to the configuration parameters across versions.

Phishing Classifier

The Phishing Classifier connector leverages Machine Learning (ML) to classify records (emails) into 'Phishing' and 'Non Phishing'.
The connector performs the following actions:

  • Train: Trains the dataset using the parameters specified while configuring the connector. You can choose the following methods to train the connector:
    • FortiSOAR Module: The connector integrates with FortiSOAR modules, so you can choose to train the connector using data present in your FortiSOAR system.
    • Pre-trained Module: You can also choose to use a pre-trained module that is shipped along with the connector so that you can use the connector from day one.
  • Predict: Provides suggestions for the 'Verdict' field of a record.
  • Get Training Results: Retrieves the training results.

You can view the Suggestions (Classification) of records on the Recommendations tab in the detail view of the record. For more information on the 'Phishing Classification' and how to configure the Phishing Classifier connector, see the "Recommendation Engine > Phishing Classifications" topic in the Application Editor chapter of the "Administration Guide", which is part of the FortiSOAR™ product documentation.

Previous
Next

Phishing Classifier Connector v1.0.0

Overview

FortiSOAR™ provides you with a number of pre-installed connectors or built-ins, such as the IMAP or Database connectors that you can use within FortiSOAR™ playbooks, as a connector step, and perform automated operations. These connectors are bundled and named based on the type of operations the connectors can perform. For example, the Database connector would contain actions that you can perform with respect to the database like querying the database. It is easy to extend and enhance these connectors.

Apart from the FortiSOAR™ Built-in connectors, Fortinet also provides a number of connectors for popular integrations like SIEMs, such as FortiSIEM, Splunk, etc., and Ticketing systems such as Jira. You can see a list of published connectors on the FortiSOAR Connectors Documentation site.

The process of installing, configuring, and using connectors is defined in the Introduction to connectors chapter in the "Connectors Guide", which is part of the FortiSOAR™ documentation or see the Installing a connector and Configuring a connector articles.

FortiSOAR™ Built-in connectors are upgraded by default with a FortiSOAR™ upgrade. Use the Content Hub to upgrade your connectors to the latest version. For more information on the connector store, see the Introduction to connectors chapter and see the FortiSOAR Built-in connectors article.

Important: Before you upgrade your FortiSOAR™ version, it is highly recommended that you take a backup of your FortiSOAR™ Built-in connector's (SSH, IMAP, Database, etc.) configuration since the configuration of your FortiSOAR™ Built-in connectors might be reset if there are changes to the configuration parameters across versions.

Phishing Classifier

The Phishing Classifier connector leverages Machine Learning (ML) to classify records (emails) into 'Phishing' and 'Non Phishing'.
The connector performs the following actions:

You can view the Suggestions (Classification) of records on the Recommendations tab in the detail view of the record. For more information on the 'Phishing Classification' and how to configure the Phishing Classifier connector, see the "Recommendation Engine > Phishing Classifications" topic in the Application Editor chapter of the "Administration Guide", which is part of the FortiSOAR™ product documentation.

Previous
Next