Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
FortiHelp
New Contributor II

External HDD and USB

Dears,

 

Does FortiEDR scan an external HDD or USB once connected to a PC?

Does FortiEDR scan an external HDD or USB when I perform a scheduled scan or Ad hoc scan?

 

 

6 REPLIES 6
issa00
New Contributor II

1. Once connected to a PC:
- FortiEDR does not automatically scan external HDDs or USB drives upon connection by default. However, it continuously monitors and can initiate scans based on file access or execution events triggered by activities involving these external devices.

 

2. During scheduled or ad hoc scans:
- Yes, FortiEDR can be configured to include external HDDs or USB drives in scheduled scans or ad hoc scans. Administrators can define scan policies to specify which devices and locations are included in these scans.

 

For detailed configuration and behavior, refer to Fortinet's documentation on FortiEDR's capabilities and policies: [FortiEDR Documentation](https://docs.fortinet.com/document/fortiedr/6.2.0/administration-guide/354083/introducing-fortiedr)

The Omnivert
The Omnivert
FortiHelp
New Contributor II

Dear Issa00,

 

Can you elaborate on this point?

During scheduled or ad hoc scans:
Yes, FortiEDR can be configured to include external HDDs or USB drives in scheduled scans or ad hoc scans. Administrators can define scan policies to specify which devices and locations are included in these scans.

 

Because, as far as I know, the FortiEDR on scheduled scans or ad hoc scans only scans hard drives, but any connected external HDD or USB is not

issa00
New Contributor II

Hi,

Please find this link to the documentation on schedule a scan. Selecting "All collectors" should include all internal + external drivers as far as I can remember.

If you have already done this, there's another option by creating a policy under security settings. You can add scheduled scanning to "Endpoint policies" where you can specify the desired driver names to scan (like C:\, E:\ driver names). 

 

Try the above method as well, I'll check from my end too if it's still possible.

The Omnivert
The Omnivert
FortiHelp
New Contributor II

From your provided link . it's clear that the FortiEDR only make a scan for hard drives. so I think doesn't scan external HDD or USB. 

 

FortiEDR can perform periodic scans of the files in the system on a scheduled or on-demand basis, based on its execution prevention policy. During a periodic scan, only the files on the hard drive are scanned and no memory scan is performed. For a periodic scan, each file on the hard drive is scanned. If a malicious file is identified during a scan, a security event is triggered.

bhantared
New Contributor

Transfer speeds have been impressive. Large files, even in the gigabytes, transfer relatively quickly. Of course, the actual speed might vary depending on the PC's USB port speed, but in general, it's been great.

FortiHelp
New Contributor II

Dear Bhantared,

 

I didn't get your idea 

 

Thanks

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors