InManDis
Product

FortiDeceptor

Agentless deception technology for detecting lateral movement, credential abuse, reconnaissance and other malicious activity using decoys, lures and tokens.

Overview

FortiDeceptor distributes realistic deception assets and endpoint lures across IT, OT and IoT environments. Interaction with those assets is a high-signal indicator that can be investigated or used to trigger containment workflows.

Architecture

Place the FortiDeceptor appliance or VM where it can orchestrate decoys into relevant network segments. Design VLAN/interface reachability, decoy personas, lure distribution, directory/integration dependencies, alert forwarding and containment integrations before rollout.

Common use cases

#Use case
1Lateral-movement detection
2Credential-theft detection
3Ransomware reconnaissance detection
4Insider-threat detection
5OT/IoT deception
6High-confidence SOC alerts
7Attacker engagement and investigation

Configuration focus

FortiDeceptor is primarily GUI/workflow driven. Validate network interfaces/VLANs, decoy deployment, lure/token configuration, integrations, alerting and response policies against the installed release.

Do not copy configuration steps across releases without checking the documentation for the installed version.

Troubleshooting framework

AreaWhat to validate
Decoy reachabilityConfirm the decoy network, VLAN, routing and service exposure are reachable from the intended monitored segment.
Lures/tokensVerify lure deployment status, supported endpoint method and that expected artifacts are present.
AlertsTest controlled interaction with a deception asset and confirm events reach the FortiDeceptor console and downstream SIEM/SOAR.
IntegrationsValidate credentials, API access and response integration before relying on automated containment.
CoverageReview whether decoys resemble the real environment closely enough and are distributed across the intended risk zones.

Deployment options

OptionBest fit
FortiDeceptor 1000GRackmount hardware appliance for enterprise deployments.
FortiDeceptor Rugged 100GFanless/ruggedized deployments including industrial environments.
FortiDeceptor VMVirtual deployment where supported hypervisor infrastructure is preferred.

Model availability and specifications can change. Use the Fortinet data sheet/product page below as the ordering authority.

Official documentation & downloads

FortiDeceptor Data Sheet PDF ↗
Direct Fortinet data-sheet PDF.
Official Fortinet
Search FortiDeceptor documentation ↗
Current administration, deployment and release documentation.
Fortinet Docs
FortiDeceptor product page ↗
Current Fortinet product overview and model/deployment information.
Official Fortinet

Lifecycle

Use the InManDis lifecycle explorer to search model/SKU lifecycle records when applicable. Software/SaaS release support does not always follow hardware EOO/EOS rules.

Open EOL / EOS search →