FortiEDR
FortiEDR automates the protection against advanced threats, pre and post-execution, with real time orchestrated incident response functionality.
kwernecke
Staff
Staff
Article Id 256963
Description This article describes our testing tool SysSanityTester and how to use it on macOS.
Scope FortiEDR.
Solution

SysSanityTester is used for macOS and is a connectivity test tool that will generate a security event on macOS. If the event appears in the FortiEDR Manager, then connectivity between the Collector and Aggregator and Manager is working. 

SysSanityTester can be executed in the following methods:


1)Download SysSanity Testing Tool from the following location to the device to test the tool on: 

https://fortinet.egnyte.com/dl/GoLbQyENhm (Password: FMuCe8iw)

2) Verify in the Console where there is Execution Prevention Policy with the Malicious file Detected rule enabled and applied to the correct group.

 

Capture12.PNG

 

Capture13.PNG

 

3) 'Double-click' on the file to execute it which will open a Terminal prompt window.

4) Via Terminal: cd to file location run cmd: chmod +x SysSanityTester

5) In Terminal run:./SysSanityTester
6) A popup notification on the macOS will appear.

7) The event will be visible in the Console:

 

Capture14.PNG

 

Note:

In order to run the tool again on the same device, it will be necessary to delete the event in the console.

 

 

Contributors