Your feedback drives change, make your voice count
Community Groups
Recently active
This week's updates deliver a broad refresh across FortiSOAR™, spanning Fortinet Fabric integrations, threat response content, and a large set of connector enhancements that strengthen automation across the security operations lifecycle.Several Fortinet Fabric connectors receive updates this week, including Fortinet FortiAI, Fortinet FortiAnalyzer, Fortinet FortiSIEM, and the FortiGuard family (IOC, Outbreak, and Threat Intelligence), deepening orchestration across Fortinet's threat intelligence and analytics services. Core FortiSOAR™ connectors such as AI Assistant Utils, Code Snippet, Utilities, and the FSR Agent Communication Bridge are also updated, improving the building blocks that power custom automation and distributed deployments.The integrations ecosystem expands with two new integrations, ANY.RUN Threat Intelligence Feeds and ANY.RUN Threat Intelligence Lookup, alongside an upgraded ANY.RUN Cloud Sandbox connector. Enhancements to more than a dozen widely used integrations,
This week’s updates focus on strengthening automation across the Fortinet ecosystem while expanding operational visibility and deployment workflows in FortiSOAR™.The release introduces enhancements to multiple Fortinet Fabric connectors, including Fortinet FortiAnalyzer, Fortinet FortiManager, Fortinet FortiNDR Cloud, and Fortinet FortiSIEM, improving integration depth and orchestration capabilities across security operations workflows.On the solution side, FortiManager ZTP Flow v1.2.0 and its accompanying Feature Examples pack extend zero-touch provisioning workflows and provide additional implementation guidance for automated device onboarding scenarios.Additional updates include improvements to the Code Snippet connector for custom automation use cases, expanded support for SonicWall Firewall integrations, and updates to the SLA Count Down Timer widget to enhance operational tracking and analyst visibility.The following table summarizes the changes since the last announcement. #
Two new Outbreak Response Solution Packs address emerging threats, including Interlock ransomware, a modern double-extortion malware targeting both Windows and Linux environments with data theft and encryption capabilities, and Iran-linked cyber operations, which continue to leverage coordinated campaigns and evolving tactics to disrupt organizations and exploit exposed attack surfaces. In addition, the new and improved ANY.RUN Cloud Sandbox enhances dynamic malware analysis by enabling analysts to safely detonate and observe suspicious files and URLs in an interactive environment, accelerating threat validation and response. Together, these updates improve readiness against active threat campaigns while strengthening analysis depth and response speed within security operations. The following table summarizes the progress we have made since the last announcement. # Type Name 1 Solution Pack Outbreak Response - Interlock Ransomware Attack v1.0.0 [Doc]
Community Update This cycle, there are no new connectors, solution packs, or widgets to announce for FortiSOAR™. No surprises, no breaking changes, and—most importantly—nothing to urgently read between the lines. The team has been focused on groundwork that does not always make it into release notes but keeps things stable, predictable, and ready for what comes next. Regular updates will resume shortly.
The Fortinet FortiSIEM connector v5.5.0 for FortiSOAR™ is now available with several enhancements to improve event investigation workflows. This update introduces support for the Event Type attribute in the Search Events action. A new Event Type option is now available under the Search Attributes parameter, enabling more precise event filtering during automated investigations. The release also updates the output schemas for the following actions to improve data consistency within playbooks: Get Device Information Run Advanced Search Query Get User Context These improvements strengthen the integration between FortiSOAR™ and Fortinet FortiSIEM, enabling more accurate event searches and more reliable automation workflows. The following table summarizes the progress we have made since the last announcement. # Type Name 1 Connector Fortinet FortiSIEM v5.5.0 [Doc]
Operational integrity and risk mitigation are at the heart of this week's release. We are introducing critical security hardening for custom extensibility alongside deepened orchestration capabilities for your primary logging and intelligence hubs. These updates ensure that while your automation grows in complexity, your underlying security posture remains uncompromised and your data remains synchronized across the enterprise. Proactive Security & Custom Automation We continue to prioritize the safety of your automation environment with key hardening for our core extensibility tools: Code Snippet Hardening: To prevent unauthorized system-level access and protect sensitive files, we have implemented strict blocking of high-risk Python modules. This ensures that custom-coded logic within your playbooks operates within a verified "Safe Mode" without sacrificing flexibility. Fabric Synchronization & SIEM Depth Maximize the value of your existing security stack with improved data
The threat landscape doesn't wait, and neither do we. This week’s FortiSOAR content release focuses on rapid-response capabilities for critical vulnerabilities and expanded visibility across your external attack surface. From securing SD-WAN infrastructure to patching gaps in collaboration tools, these updates empower your SOC to move faster and stay ahead of emerging exploits. High-Impact Outbreak Response We’ve released three high-priority Solution Packs designed to automate the detection and neutralization of critical RCE and authentication bypass threats: Versa Concerto SD-WAN Authentication Bypass: Secure your edge. This pack provides the automated playbooks needed to identify and remediate unauthorized access attempts within your SD-WAN environment. SmarterTools SmarterMail RCE: Eliminate the risk of remote code execution. Rapidly scan for indicators of compromise and secure your mail servers before attackers can gain a foothold. Zimbra Collaboration Local File Inclusion: Prote
New FortiSOAR Connector Releases Now Available We’re excited to announce the latest FortiSOAR connector updates, designed to help you enrich investigations, streamline response, and extend your automation ecosystem. These new and updated integrations make it easier to bring external intelligence and endpoint security data directly into your playbooks—right where your analysts need it. CrowdSec Cyber Threat Intelligence Connector v1.0.0 This brand-new connector enables FortiSOAR to integrate with CrowdSec’s community-powered cyber threat intelligence. You can now enrich alerts and incidents with reputation data on IPs and behaviors observed across CrowdSec’s global network. By leveraging real-world, crowdsourced intelligence, SOC teams can make faster, more informed decisions and automate response actions based on emerging threat patterns. McAfee ePO Connector v1.1.1 The updated McAfee ePO connector improves integration with your endpoint security environment, allowing FortiSOAR to inte
The SOC of 2026 waits for no one. Are you ready? We've just unlocked a massive wave of SOAR Integration Updates, and the benchmark for "speed of response" has officially shifted. Cisco ASA/FTD, Ansible, and CyberArk, you're operating at yesterday's speeds. From turning FortiPAM into a Zero-Trust engine to closing the loop between Rapid7 Threat Command and ServiceNow, we're giving you the keys to a truly self-healing infrastructure. What's inside: Next-Gen Perimeter Control: Cisco & Fortinet orchestration like you've never seen. The Zero-Touch Advantage: Deep-tier automation for CyberArk & Ansible Tower. Intelligence-to-Action: Real-time sync for Proofpoint, Exchange, and Threat Command. The gap between "alert" and "resolved" just got a lot smaller. Don't let your defense lag behind the curve. The following table summarizes the progress we have made since the last announcement. # Type Name 1 Solution Pack Outbreak Response - Cisco ASA and FTD Firewall
New Connectors, Solution Packs, and Platform Enhancements We are pleased to share a broad set of enhancements delivered across FortiSOAR™, reflecting sustained engineering investment in integrations, automation depth, and response readiness. This update introduces new connectors, major connector upgrades, expanded solution packs, and targeted platform improvements—strengthening FortiSOAR™’s role as a central automation and orchestration layer for security operations. Fortinet Fabric Connectors This release includes several important updates across Fortinet Fabric connectors, reinforcing deep, secure integration within the Fortinet Security Fabric: Fortinet FortiGuard Threat Intelligence v3.4.1 and Fortinet FortiGuard IOC v1.0.1 enhance threat intelligence ingestion and IOC search capabilities directly within FortiSOAR™. Fortinet FortiDLP v1.1.0 expands visibility into agents, users, and labels, enabling richer data-driven workflows. Fortinet FortiSIEM v5.4.3 improves data ingesti
We're pleased to announce FortiSOAR release 7.6.2. The main features of this release include: New dashboard visualizations that provide more options for displaying and interpreting data A new Playbook Developer widget that simplifies working with nested playbooks High availability enhancements A new version of FortiAI with improved playbook generation capabilities, and the ability to build a FortiSOAR connector using AI Release Notes: https://docs.fortinet.com/document/fortisoar/7.6.2/release-notes/800030/fortisoar-7-6-2-release Upgrade Information: Upgrade to this version from FortiSOAR 7.5.0, 7.5.1, 7.6.0, or 7.6.1.
Exciting updates available on the FortiSOAR Content Hub!! The Fortinet FortiManager ZTP Flow integration brings FortiManager's central management solution to Fortinet's security appliances such as firewalls and VPNs, seamlessly incorporating the Zero-Touch Provisioning (ZTP) flow. This allows for automated device configuration and deployment, reducing the need for manual intervention and enabling quick, plug-and-play setup. Additionally, the Outbreak Response - Apache Tomcat RCE solution pack works in tandem with the Threat Hunt rules in the Outbreak Response Framework to identify and investigate potential Indicators of Compromise (IOCs) associated with the Apache Tomcat remote code execution vulnerability, CVE-2025-24813. This vulnerability is actively targeted by attackers, and the solution aids in detecting and mitigating threats within operational environments such as FortiSIEM and FortiAnalyzer. Our Cisco ISE integration with FortiSOAR™ enhances network policy
We are pleased to announce the latest updates to the FortiSOAR platform, bringing enhanced capabilities and new integrations designed to further empower your security operations. This release introduces several new Solution Packs and Connector updates that will enhance your ability to manage and respond to various security threats more effectively. Among the updates, we have introduced Solution Packs such as the FortiManager ZTP Flow, multiple Outbreak Response packs covering critical vulnerabilities and attacks, as well as an upgrade to the Threat Intel Management pack. These additions are designed to address emerging threats and streamline incident response workflows. In addition, several Connector updates are now available, including enhancements to platforms such as Exchange, Fortinet FortiAppSec Cloud, Google Gemini, and Mandiant Threat Intelligence, among others. These updates offer improved integration, expanded coverage, and more reliable data sources for your sec
FortiSOAR Community Update: Powering Up with Industry Favorites! This month's spotlight is on the tools and solutions that have become indispensable to SOC teams across industries. From tackling outbreaks with precision to enhancing system monitoring, these updates are here to streamline your workflows and boost your security posture. Our Outbreak Response Framework together with its Configuration Wizard remain industry champions, offering swift and efficient responses to emerging threats. Coupled with the Fortinet FortiGuard Outbreak connector, these tools ensure you're always one step ahead of the threat landscape. And for those looking to enhance their data protection strategies, the Fortinet FortiDLP connector is here to secure your sensitive information with ease. The IBM Security QRadar SOAR and Maxmind connectors continue to deliver insights and integrations that empower your team. Add FortiSOAR's own System Monitoring and Netscout's Arbor Edge Defense to the mix, and you
We're pleased to announce the FortiSOAR 7.6.1 release. This new release provides the following key features: FortiFlex licensing Reduced downtime when upgrading HA clusters from 7.6.1 onwards Support for disk encryption Improved solution pack upgradability to preserve custom playbooks Improved management of playbook logs to optimize storage Various UI/UX enhancements Significant improvements to the Outbreak Response feature Improved indicator extraction Voice dictation into the FortiAI assistant Various integration and connector enhancements ...and more! see the release notes below for full details. Release notes:FortiSOAR 7.6.1 Release Notes (opens in new page) Availability and Upgrade:Customers with valid support contracts can upgrade from FortiSOAR 7.6.0 to version 7.6.1. FortiSOAR 7.6.1 can be downloaded from support.fortinet.com
FortiSOAR 7.6.1 is Here! Your SOC Just Got Smarter and Faster SOC operators, analysts, and cyber warriors—get ready for a big boost! FortiSOAR 7.6.1 has arrived, and it's packing a punch stronger than your morning coffee. Check out what's new: FortiFlex Licensing Support Reduced Downtime for HA Clusters Disk Encryption Support Improved Solution Pack Upgradability Optimized Playbook Log Management UI/UX Enhancements Enhanced Outbreak Response Improved Indicator Extraction Voice Dictation with FortiAI Assistant Integration and Connector Enhancements ...and so much more! Dive into the full details here: Release Notes. Upgrade to FortiSOAR 7.6.1 Already on version 7.6.0? Upgrading is a breeze! Visit support.fortinet.com and navigate to: Downloads > Firmware Images > FortiSOAR > 7.0.0 > 7.6 > 7.6.1 What's Fresh Since Our Last Announcement? The following table summarizes the progress we have made with respect to solutions since the last ann
Looking for a sassy way to secure your distributed workforce? Well, look no further — Fortinet FortiSASE (yes, that's Forti-sassy) has arrived! This cutting-edge connector adds some serious attitude to your cybersecurity arsenal by extending enterprise-grade security to users wherever they are. Whether you're in the office, working remotely, or sipping a latte at your favorite café, FortiSASE has your back (and your network). But that's not all! Here's a quick peek at the latest additions making waves in FortiSOAR: Our Outbreak Response packs are on high alert, tackling critical vulnerabilities like the Palo Alto Networks Management Interface Attack and the Progress Kemp LoadMaster OS Command Injection Vulnerability. Because cyberthreats don't take coffee breaks, and neither do we. CylancePROTECT is stepping up to keep malware at bay with AI-driven endpoint security. It's like having a cybersecurity crystal ball but cooler. Infoblox DDI brings seamless DNS, DHCP, and IPA
FortiSOAR's latest updates are here, and we've added some powerhouse connectors and solution packs that'll make your SOC team look like superheroes—minus the capes (but feel free to wear one if you'd like!). Whether you're facing ransomware threats, digging through cloud analytics, or looking to streamline incident response, our recent releases cover it all. With the Lacework FortiCNAPP, you get unparalleled cloud visibility, empowering you to innovate with confidence. The new Outbreak Response packs keep you ahead of emerging cyber threats like Mallox ransomware and vulnerabilities that dare to show up uninvited. For those of you who live for analytics, we've got Azure Log Analytics and Splunk updates to help you dive deep, uncovering insights faster than ever. And let's not forget our trusty AWS WAF and Akamai WAF connectors that add an extra layer of security to keep the bad guys out (they've had enough practice getting in). Integrations with Google Sheets and M
Exciting new updates have landed in FortiSOAR! As always, we’ve been working around the clock (and maybe over-caffeinated) to bring you the tools and integrations that make your cybersecurity life a whole lot easier—because fighting cyber threats shouldn’t feel like you're fighting a dragon without a sword - or the armor! Here’s what’s new: Integrate Bitbucket into your security operations and manage your repositories like a pro. Now, you can squash bugs in both your code and your network with one swoop. It’s like being a ninja, but with fewer flips. FortiSOAR now supports Cisco ESA (REST), making email security integrations smoother than Steve’s ‘reply all’ email faux pas in accounting. Stop email threats in their tracks before they get a chance to CC the entire company. Add and manage code snippets directly within FortiSOAR. Save yourself from the dreaded “where did I put that code?” scavenger hunt. Let’s face it, why reinvent the wheel when you can copy and past
Exciting Updates for Our Top Cybersecurity Solutions! Hello FortiSOAR community! We're buzzing with excitement as we unveil the latest updates to our most popular Solution Packs and Connectors! These top-tier tools are designed to elevate your security operations to new heights. Imagine taking a stroll down the tech aisle, but instead of random gadgets, you're picking up powerful solutions to combat cyber threats like a seasoned superhero—cape optional, of course. Prepare to arm yourself with what's trending and effective in cybersecurity, so you can tackle incidents and manage alerts like a pro! Lacework FortiCNAPP Composite Alert Incident Response v1.0.0: Wave goodbye to being buried under alerts! This pack helps you manage and respond to incidents with all the grace of a Jedi swatting away pesky droids. Outbreak Response - Russian Cyber Espionage Attack v1.0.0: Strengthen your defenses against those stealthy cyber espionage strikes. It's like having a secret age
Abhishek Narula, CTO (SOAR Business), would be talking about "Building Career in Cybersecurity & AI" at IIT Jodhpur Sandstone Summit 4.0 https://www.linkedin.com/feed/update/urn:li:activity:7244574804937195521/
We're pleased to announce the release of FortiSOAR 7.6.0. This release includes many new enhancements, including: A new cost effective starter edition license for SME environments with less than 10,000 actions per day A High Availability (HA) node license for cost effective HA clustering Trial license updated to 1,000 actions per day Upgrade process improvements A range of user interface enhancements, including code editing improvements Many solution pack, connector, and widget enhancements and more... Check the 7.6.0 release notes for full details:https://docs.fortinet.com/document/fortisoar/7.6.0/release-notes/269885/new-features-and-enhancements
New Connectors Alert: Your Security Arsenal Just Got Better! We've new connectors to boost your security toolkit. Whether you're all about the latest threat intel or just need a better way to scan those pesky QR codes (yes, really!), we've got you covered. Let's dive into what's new! LUMU v1.0.0: You asked, we delivered! LUMU is now integrated to help you continuously illuminate your security posture and detect threats in real-time. Your wish is our command! IBM Randori v1.0.0 Another community request making its debut! IBM Randori is here to provide you with attack surface management like never before. It's like having a friendly hacker who's on your side. Exchange v4.5.0 (Updated to Exchange lib 5.4.0) Because no one wants outdated libraries, right? We've polished up the Exchange connector, bringing it to v4.5.0, with an upgraded lib version to keep your email environment running smoother than ever. QR Code Tools v1.0.1 T
Unveiling some game-changing updates and enhancements for FortiSOAR that include FortiAI, Outbreak Response Framework, and Lacework FortiCNAPP integration — along with other widgets, connectors, and solution packs! Unlock the full potential of Generative AI with FortiAI solution pack! This groundbreaking tool answers your questions with contextual precision on security threats, response processes, work plans, Jinja expressions, and more. The real magic happens with its unique ability to craft customized playbook blocks based on your defined scenarios. Whether you're a seasoned pro or just starting out, FortiAI is your ultimate ally for designing streamlined, efficient playbooks that set you up for success. Stay ahead of the curve with our Outbreak Response Framework! This powerful tool provides essential insights into ongoing cybersecurity attacks that impact numerous organizations and industries. Powered with Fortinet FortiGuard Outbreaks, it is quick to install outbreak
We are excited to announce that new connectors, widgets, and solution packs are now available on the Content Hub. We have also released new versions of existing content with enhanced features and improved performance. Our new connectors enable seamless integration with popular threat intel platforms like Microsoft Graph Mail, ServiceNow, version control systems like GitHub and GitLab, and 600 more! SOAR Framework with version 3.0.0 has been optimized; SLA Management and other utilities are now new solution packs in themselves, complete with playbooks and user flows. The following table summarizes the progress we have made since the last announcement. 1 Solution Pack Platform Utilities v1.0.0 [Doc] 2 Solution Pack SOC Utilities v1.1.0 [Doc] 3 Solution Pack SLA Management v1.0.0 [Doc] 4 Solution Pack SOAR Framework v3.0.0 [Doc] 5 Connector Fortinet FortiEDR v2.0.0 [Doc] 6 Connector Remote FortiSOAR v2.0.0 [Doc] 7 Connector Gitlab v2.0.1 [Doc] 8 Conne
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.