FortiSandbox
FortiSandbox provides a solution to protect against advanced threats and ransomware for companies who don’t want to implement and maintain a sandbox environment on their own.
pchee
Staff
Staff
Article Id 313756
Description This article describes how to use FortiNDR to perform a static scan.
Scope FortiSandbox.
Solution
  1. Navigate to Security Fabric -> FortiNDR -> FortiNDR Settings.

 

keyin.jpg

 

  1. Select the 'Enable' checkbox.

  2. Fill in the IP address and get the API key from the FortiNDR.

  3. On the FortiNDR side, navigate under System -> Administrator -> Edit Administrator.

API.jpg

 

  1. Select Generate to acquire the API Key.

  2. Select Test Connection to make sure the integration is successful.

 

FSA.jpg

 

  1. Navigate under FortiNDR Security Fabric -> Device Input -> Other Device to make sure the status is showing as Connected.

 

OtherDevice.jpg

 

  1. Navigate to Scan Policy and Object -> Scan Profile -> Pre-Filter.

  2. Enable the toggle for FortiNDR entrust in the Scan Profile.

 

FNDR entrust.jpg

 

Note: When FortiNDR entrust in the scan profile is enabled, files rated by FortiNDR as clean will skip the sandboxing VM scan step.