Dears,
Does FortiEDR scan an external HDD or USB once connected to a PC?
Does FortiEDR scan an external HDD or USB when I perform a scheduled scan or Ad hoc scan?
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
1. Once connected to a PC:
- FortiEDR does not automatically scan external HDDs or USB drives upon connection by default. However, it continuously monitors and can initiate scans based on file access or execution events triggered by activities involving these external devices.
2. During scheduled or ad hoc scans:
- Yes, FortiEDR can be configured to include external HDDs or USB drives in scheduled scans or ad hoc scans. Administrators can define scan policies to specify which devices and locations are included in these scans.
For detailed configuration and behavior, refer to Fortinet's documentation on FortiEDR's capabilities and policies: [FortiEDR Documentation](https://docs.fortinet.com/document/fortiedr/6.2.0/administration-guide/354083/introducing-fortiedr)
Dear Issa00,
Can you elaborate on this point?
During scheduled or ad hoc scans:
Yes, FortiEDR can be configured to include external HDDs or USB drives in scheduled scans or ad hoc scans. Administrators can define scan policies to specify which devices and locations are included in these scans.
Because, as far as I know, the FortiEDR on scheduled scans or ad hoc scans only scans hard drives, but any connected external HDD or USB is not
Hi,
Please find this link to the documentation on schedule a scan. Selecting "All collectors" should include all internal + external drivers as far as I can remember.
If you have already done this, there's another option by creating a policy under security settings. You can add scheduled scanning to "Endpoint policies" where you can specify the desired driver names to scan (like C:\, E:\ driver names).
Try the above method as well, I'll check from my end too if it's still possible.
From your provided link . it's clear that the FortiEDR only make a scan for hard drives. so I think doesn't scan external HDD or USB.
FortiEDR can perform periodic scans of the files in the system on a scheduled or on-demand basis, based on its execution prevention policy. During a periodic scan, only the files on the hard drive are scanned and no memory scan is performed. For a periodic scan, each file on the hard drive is scanned. If a malicious file is identified during a scan, a security event is triggered.
Transfer speeds have been impressive. Large files, even in the gigabytes, transfer relatively quickly. Of course, the actual speed might vary depending on the PC's USB port speed, but in general, it's been great.
Dear Bhantared,
I didn't get your idea
Thanks
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1660 | |
1077 | |
752 | |
443 | |
220 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.