FortiEDR
Endpoint detection and response with real-time prevention, behavioral detection, investigation, threat hunting and automated response across endpoint fleets.
Overview
FortiEDR provides endpoint protection and EDR capabilities using endpoint collectors plus centrally managed security policies, event analysis, threat hunting and response workflows.
Architecture
Deploy endpoint collectors to supported Windows, macOS and Linux systems, with management delivered through Fortinet-hosted cloud, hybrid, or supported on-premises deployment models. Design around endpoint count, network egress, policy groups, exclusions, integrations and incident-response ownership.
Common use cases
| # | Use case |
|---|---|
| 1 | Ransomware prevention and containment |
| 2 | Endpoint detection and response |
| 3 | Threat hunting |
| 4 | Malware and behavior-based blocking |
| 5 | Endpoint isolation and remediation |
| 6 | SOC investigation |
| 7 | Server/workload protection |
Configuration focus
FortiEDR administration is policy/workflow driven rather than FortiOS-style CLI driven. Validate collector deployment, security policies, communication-control policies, exclusions, event handling, integrations and response actions against the current administration guide.
Do not copy configuration steps across releases without checking the documentation for the installed version.
Troubleshooting framework
| Area | What to validate |
|---|---|
| Collector health | Confirm the endpoint collector is installed, running, connected and assigned to the intended organization/group. |
| Policy | Check prevention/security policy assignment, exclusions and whether a policy change created the symptom. |
| Connectivity | Validate endpoint-to-management connectivity, proxy/TLS inspection dependencies and required destinations. |
| Events | Review security events, collector logs and device timeline before creating exclusions. |
| Performance | Investigate CPU/I/O impact and application compatibility carefully; avoid broad exclusions without evidence. |
Official documentation & downloads
Lifecycle
Use the InManDis lifecycle explorer to search model/SKU lifecycle records when applicable. Software/SaaS release support does not always follow hardware EOO/EOS rules.
Open EOL / EOS search →