Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
KarlH
Contributor II

What would cause FortiEDR to NOT detect ransomware encryption

I see almost exclusively what FortiEDR can do in searching here, and only some minor dislikes on Gartner.

 

I have a case where it did not detect the encryption process, it was able to impede the vector but ultimately the ransomware was successful in encrypting the media.  I need cases where FortiEDR could be inhibited, either from improperly training the model, misconfiguration, or other security software that would impede the detection process.

 

Thanks, Karl

Karl Henning, Security Engineer, CISSP
Karl Henning, Security Engineer, CISSP
1 REPLY 1
KarlH
Contributor II

Thanks

I do appreciate the re iteration, I actually mention two of those in the post, I would like to avoid any more pitfalls, where would the docs be that discuss the modelling theory and principals, How should we establish a base line for clients, so it knows what "clean" looks like, the  time to train,  what kinds of misconfiguration?  Why would EDR not detect an entire disk being encrypted? it never even threw an alert? where are the logs kept for EDR?

 

Thank you.

Karl Henning, Security Engineer, CISSP
Karl Henning, Security Engineer, CISSP
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors