Technical Tip: FortiEDR threat hunting overview and best practices
| Description | This article provides an overview of the Threat Hunting feature in FortiEDR. |
| Scope | FortiEDR Manager v7.2+. |
| Solution |
Threat Hunting (TH) data retention depends on:
The repository size can be expanded through additional repository add-ons.
Collection profiles define which types of activity data are collected for Threat Hunting.
Available profile types:
The best approach to assign Threat Hunting profiles is to use the Standard profile at a minimum. If possible, use more extensive profiles to collect as much activity data as possible for forensics purposes.
Collection exclusions reduce the amount of data ingested into the TH repository.
Practical example: Tools such as TeamViewer or remote-control utilities typically produce very high event volumes.
Threat Hunting queries support:
For file paths, use double backslashes (3) (e.g., Users\\example\\file.exe).
Filters and facets help refine Threat Hunting results:
Facet values are filled automatically based on the content of the TH repository.
Applied facets can be converted into query syntax.
Any Threat Hunting query can be saved and scheduled. Playbook actions can be set as a response to the scheduled query detection.
FortiEDR supports importing external threat intelligence feeds through TAXII v1 and v2. Once the configuration is complete, FortiEDR will fetch the IOCs from the configured source and import them.
|








