Hi Community,
Forti sandbox generates malware package, when it found any new malicious file hash the malware package will be updated, and we have the
1)Contribute detected suspicious files to Forti Sandbox Community Cloud. "
Now my query is if the locally detected file rated as malicious but actually it is a false positive not actually malicious, this signature will be created and contribute this signature to "Sandbox Community Cloud". Or FortiGuard
Next time when any one Across the global using Sandbox community cloud" or FortiGuard will also rate this as malicious or not based on this signature?
Thanks.
Hi @soolani
I hope you you know that we have Allow and Block list in Forti sandbox. If i add any hash in the block list, when we receive any new file matching this hash will be rated as malicious based on this added hash in the block list, and new signature will be added to the Malware package, and this will be contributed to Sandbox community cloud /FortiGuard database.
If the contributed hash is related to the Locally detected malicious file which is other than the allow or block list of local sandbox, then it is okay.
My idea is, we should have the segregation while generating the malware package in our local sandbox as mentioned below.
1) Malware package against the Allow or block list (This should not contribute to the sandbox community cloud/Forti Guard database ) why because in this we can have multiple false positives.
2) Malware package against the Static scan /Dynamic scan (behavior-based scan) (contributing this type of hashes to the sandbox community cloud /FortiGuard database makes sense)
Do you agree with this idea?
Thanks @soolani
| User | Count |
|---|---|
| 2803 | |
| 1425 | |
| 812 | |
| 750 | |
| 455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.