Skip to main content
New Member
August 12, 2026
Question

FortiDeceptors running during PEN test - advice

  • August 12, 2026
  • 2 replies
  • 54 views

Our cyber insurance company is running an internal pen test, and I wanted to see what others do when FortiDeceptor is running. My plan was to say nothing but add their IP to the safe list to prevent them from getting locked out mid-test. Then, when they find one, I will disclose it if they report it as a finding.

On the other hand, I feel that I am lowering my security for them, so I am torn on what to do. Any pen testers or people with FortiDeceptor out there who have had a similar issue?
 

    2 replies

    Stephen_G
    Staff & Editor
    Staff & Editor
    August 18, 2026

    Hi richard37,

    Thank you for using our forums. We will seek to get you an answer or help.

    In the meantime, if anyone else has any advice, please feel free to contribute.

    Stephen_G - Fortinet Community Team
    acozzetti
    Staff
    Staff
    August 18, 2026

    I would generally leave FortiDeceptor operating normally during the penetration test rather than safelisting the tester.
    The important distinction is between detection and enforcement. If FortiDeceptor is only detecting interaction with decoys, there is little reason to exclude the penetration tester. In fact, seeing whether the tester interacts with the deception environment, and whether the security team detects it, is useful information.
    If automatic quarantine/blocking is enabled through FortiGate or another integration, then I would address that specifically in the penetration test Rules of Engagement rather than broadly safelisting the tester. Otherwise, you risk disabling the very control that could potentially detect their activity.
    If the objective is to assess the environment as an attacker would encounter it, leave FortiDeceptor fully operational. If the objective is primarily vulnerability discovery and automated quarantine would prevent the tester from completing the agreed scope, then an exception can make sense, but it should be narrowly scoped and documented as a test exclusion.
    I would also avoid disclosing the decoys in advance unless there is a specific operational reason to do so. If the tester identifies one as a vulnerable system, that can actually provide useful evidence that the deception technology is working as intended.

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!