We recently observed a concerning event on one of our endpoints involving the FortiClient Logging Daemon (FCDBLog.exe).
While FortiClient is a trusted security solution in our environment, we are puzzled by this behavior. Typically, security tools monitor the hosts file for unauthorized changes—not modify it directly. The involvement of a scheduled task and the elevated privileges make this worth investigating further.
Key Details:
Questions:
Thanks in advance for your help
BR
Stephan
Hello @StephanG
FCDBLog.exe is the FortiClient Logging Daemon, are you sending any logs from the FCT to FAZ/Syslog or debug is enabled ?
We have the "free" version of FortiClient - i am unsure if this is even an option :) But we do not send logs to FAZ or syslog servers.
Debug is not enabled. I cannot see any past incidents that on these clients we have enabled debug.
I have hunted for this behavior with Defender for Endpoint and this only affects 27 of about 410 active VPN users.
User | Count |
---|---|
2593 | |
1381 | |
800 | |
659 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.