Skip to main content
filiaks1
Explorer III
June 16, 2025
Question

Is there an option FortiNDR be configured with the IP address of the AD server to detect AD attacks?

  • June 16, 2025
  • 3 replies
  • 630 views

Hey Everyone,

 

 

Is there an option FortiNDR be configured with the IP address of the AD server to detect AD attacks?

 

I did see Device Enrichment | FortiNDR 7.6.2 | Fortinet Document Library but I was wondering not about enriching the other hosts but for FortiNDR to monitor the AD server IP address or FortiNDR to autodiscover it, so to detect Pass-the-Hash / Pass-the-Ticket, Kerberoasting, DC Shadow, DCSync or Golden/Silver Ticket attacks Active Directory Attacks ?

 

For example by FortiNDR knowing that there are two AD servers on ip addresses 1.1.1.1 and 1.1.1.2 then if another host sends DCSync requests using MS-DRSR protocol to 1.1.1.1 or 1.1.1.2 this will suggest AD attack as only AD servers should use DCSync between them.

 

 

3 replies

Anthony_E
Staff
Staff
June 19, 2025

Hello,


Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.


Thanks,

Best Regards
Anthony_E
Staff
Staff
June 20, 2025

Hello,

We are still looking for someone to help you.

We will come back to you ASAP.


Thanks,

Best Regards
Anthony_E
Staff
Staff
June 20, 2025

Did you already have a look at our FortiNDR Knowledge Base?:

https://community.fortinet.com/t5/FortiNDR-on-premise/tkb-p/TKB49

 

You have some interesting KB article and it could help you.

 

Regards,

Best Regards
Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!