FortiDeceptor
Agentless deception technology for detecting lateral movement, credential abuse, reconnaissance and other malicious activity using decoys, lures and tokens.
Overview
FortiDeceptor distributes realistic deception assets and endpoint lures across IT, OT and IoT environments. Interaction with those assets is a high-signal indicator that can be investigated or used to trigger containment workflows.
Architecture
Place the FortiDeceptor appliance or VM where it can orchestrate decoys into relevant network segments. Design VLAN/interface reachability, decoy personas, lure distribution, directory/integration dependencies, alert forwarding and containment integrations before rollout.
Common use cases
| # | Use case |
|---|---|
| 1 | Lateral-movement detection |
| 2 | Credential-theft detection |
| 3 | Ransomware reconnaissance detection |
| 4 | Insider-threat detection |
| 5 | OT/IoT deception |
| 6 | High-confidence SOC alerts |
| 7 | Attacker engagement and investigation |
Configuration focus
FortiDeceptor is primarily GUI/workflow driven. Validate network interfaces/VLANs, decoy deployment, lure/token configuration, integrations, alerting and response policies against the installed release.
Do not copy configuration steps across releases without checking the documentation for the installed version.
Troubleshooting framework
| Area | What to validate |
|---|---|
| Decoy reachability | Confirm the decoy network, VLAN, routing and service exposure are reachable from the intended monitored segment. |
| Lures/tokens | Verify lure deployment status, supported endpoint method and that expected artifacts are present. |
| Alerts | Test controlled interaction with a deception asset and confirm events reach the FortiDeceptor console and downstream SIEM/SOAR. |
| Integrations | Validate credentials, API access and response integration before relying on automated containment. |
| Coverage | Review whether decoys resemble the real environment closely enough and are distributed across the intended risk zones. |
Deployment options
| Option | Best fit |
|---|---|
| FortiDeceptor 1000G | Rackmount hardware appliance for enterprise deployments. |
| FortiDeceptor Rugged 100G | Fanless/ruggedized deployments including industrial environments. |
| FortiDeceptor VM | Virtual deployment where supported hypervisor infrastructure is preferred. |
Model availability and specifications can change. Use the Fortinet data sheet/product page below as the ordering authority.
Official documentation & downloads
Lifecycle
Use the InManDis lifecycle explorer to search model/SKU lifecycle records when applicable. Software/SaaS release support does not always follow hardware EOO/EOS rules.
Open EOL / EOS search →