Sora Yazılım
English
Custom software solutions from Türkiye
Fortinet · Network Security

FortiEDR / FortiXDR

Behavioral detection, real-time blocking and automated incident response at the endpoint.

Quick answer

FortiEDR is Fortinet's EDR solution that monitors running processes on endpoints at kernel level and stops malicious behavior in real time. It combines pre-execution machine learning-based antivirus with post-infection behavioral blocking in a single agent; it protects workstations, servers, cloud workloads and production stations running legacy operating systems, and automates response with playbooks.

FortiEDR is Fortinet's endpoint detection and response (EDR) solution that monitors running processes on endpoints at kernel level, stops malicious behavior in real time and automates incident response. It combines a pre-execution machine learning-based antivirus layer with a post-infection behavioral blocking layer in a single lightweight agent, protecting workstations, servers, cloud workloads and production systems with the same policy set.

Threat data shows why this two-layer approach is necessary. According to Verizon's 2025 Data Breach Investigations Report, ransomware was present in 44% of the breaches examined — in the previous report that figure was 32%, and among small and medium-sized organizations it rises to 88% (Verizon DBIR, 2025). FortiGuard Labs' 2026 Global Threat Landscape Report puts the number of confirmed ransomware victims in 2025 at 7,831; that is a 389% increase over the roughly 1,600 victims in the previous report (Fortinet, 2026).

What is FortiEDR and how does it differ from traditional antivirus?

Short answer: Traditional antivirus looks at what a file is; FortiEDR looks at what a process does. Even when there is no signature or hash match, the moment a process attempts to write to the file system, create a persistence entry or open an outbound connection, those behaviors are cut off by policy.

Fortinet describes this architecture as two protection layers. The first layer is the machine learning-based next-generation antivirus (NGAV) engine running at kernel level, aimed at blocking a malicious file before it executes; Fortinet states that its artificial intelligence and machine learning run at kernel level on both Windows and Linux. The second layer steps in against threats that get past the first: the moment FortiEDR detects a suspicious process flow, it blocks that process's outbound communication and its access to the file system. As a result, data exfiltration, command-and-control (C2) traffic, file and registry tampering and ransomware encryption cannot produce an outcome even if the device has been compromised. Because the device is not shut down and only the malicious process's capabilities are constrained, the user keeps working — in business continuity terms, this strikes a different balance from approaches that isolate the entire machine from the network.

In the background, Fortinet Cloud Services continues gathering evidence, enriches and classifies the incident data, and triggers the automated response playbook according to that classification. FortiEDR also reduces the attack surface before an attack happens: vulnerability assessment, tracking the CVE status of applications, virtual patching, discovery of unmanaged and IoT devices, application control and USB device control are all delivered inside the same agent. For this reason it is more accurate to position FortiEDR not merely as a detection tool but as an endpoint risk management layer.

At which stage of an attack do FortiEDR's protection layers come into play?

Short answer: There are five stages and each operates at a different moment in the attack chain. The table below summarizes which layer engages when, what it does and which threat type it targets.

LayerWhen it engagesWhat it doesThreat it targets
Discovery and predictionBefore the attackVulnerability assessment, application CVE tracking, virtual patching, discovery of unmanaged and IoT devices, application controlUnpatched applications, unregistered devices
Pre-infection protectionBefore the file executesKernel-level machine learning-based NGAV, enrichment with FortiGuard threat intelligence, offline protection, USB device controlKnown malware and its variants
Post-infection detection and neutralizationAfter the process starts runningCutting off the suspicious process's outbound communication and file system access, detecting memory-based and "living off the land" attacksFileless malware, ransomware encryption, data exfiltration
Response and remediationAfter the incident is classifiedPlaybook automation, file removal, process termination, rollback of persistence changes, device or application isolation, ticket creationPersistence, lateral movement
Investigation and threat huntingAfter the incidentFull attack chain visibility through patented code tracing, memory snapshots, translation of common IoC syntaxes such as TAXII into FortiEDR Lucene syntaxThreats that remained hidden or unclassified

The rollback step carries one critical detail in practice: on Windows, reversing malicious changes does not depend on the VSS (Volume Shadow Copy) snapshots that ransomware targets; the same function is also supported on macOS and Linux. Full attack chain visibility is produced by patented code tracing technology and is recorded even while the device is offline. The console interface explains why an incident was flagged as suspicious and maps the attack to techniques in the MITRE ATT&CK framework; for teams that struggle to retain senior analysts, this is a direct operational gain.

Which attacks are endpoints exposed to today?

Short answer: Initial access is now achieved predominantly through phishing and vulnerability exploitation, and the time an attacker needs to weaponize a vulnerability has fallen from days to hours. When these two trends combine, an endpoint strategy that relies solely on signature updates falls short.

In ENISA's Threat Landscape 2025 report, which covers July 2024 – June 2025 and examines 4,875 incidents, phishing was reported as the dominant intrusion vector at 60% and vulnerability exploitation as 21.3% of initial access (ENISA Threat Landscape, 2025). Verizon DBIR 2025 shows that vulnerability exploitation reached 20% as an initial access vector, a 34% increase over the previous report, and that the share of edge devices and VPNs among exploitation targets rose from 3% to 22% (Verizon DBIR, 2025). FortiGuard Labs' 2026 report states that time-to-exploit on critical advisories has fallen to 24–48 hours and that global exploitation attempts rose 25.49% year over year (Fortinet, 2026).

This picture leads to two conclusions. First, because an attack can occur before the patch window closes, virtual patching and behavioral blocking on the endpoint are needed as compensating controls. Second, because the starting point of a breach is often at the network edge, endpoint telemetry needs to be evaluated in the same correlation pool as the firewall and email layers. FortiEDR's position within the Fortinet Security Fabric is aimed precisely at that second need.

Which operating systems and devices does FortiEDR support?

Short answer: One of FortiEDR's most distinctive strengths is its legacy operating system coverage. According to Fortinet's data sheet, the agent supports a range extending from Windows XP SP2 to Windows 11 and from Windows Server 2003 SP2 to Windows Server 2025, as well as the Android 9.0 and later and iOS 15.0 and later mobile platforms (Fortinet FortiEDR Data Sheet, 2025).

Platform familyCoverage
Windows clientWindows XP SP2, 7, 8, 8.1, 10 and 11 (32- and 64-bit versions)
Windows ServerWindows Server 2003 SP2 and R2 SP2, 2008 SP1, 2008 R2 SP2, 2012, 2012 R2, 2016, 2019, 2022 and 2025
macOSFrom El Capitan (10.11) through Sequoia (15)
LinuxRed Hat Enterprise Linux and CentOS, Ubuntu LTS (server editions 64-bit only), Oracle Linux, Amazon Linux AMI 2, openSUSE Leap and SUSE Linux Enterprise Server
Virtual desktop (VDI)VMware Horizon 6 and 7, Citrix XenDesktop 7
MobileAndroid 9.0 and later, iOS 15.0 and later
CloudCloud workloads; deployment through Google Cloud Marketplace and automated endpoint installation orchestration for Google Compute Engine

This coverage maps directly onto manufacturing, healthcare and retail environments in Turkey. HMI stations on production lines, hospital imaging workstations and POS terminals often run a Windows version whose vendor support has ended; they cannot be updated because of application certification, and most modern EDR agents cannot be installed on them. On these devices, signature updates alone are not enough. Behavioral blocking, application control and virtual patching are the practicable way to reduce risk measurably without replacing the hardware. The fact that FortiEDR runs with full feature parity on manufacturing and OT systems is decisive in this scenario.

How much does the FortiEDR agent affect endpoint performance?

Short answer: Fortinet states that the FortiEDR agent uses between under 1% and 2% CPU, 200–350 MB of memory and 750 MB–1 GB of disk, and generates low-volume network traffic; the upper bounds of memory and disk usage are related to the threat hunting (response licence) capability (Fortinet FortiEDR Data Sheet, 2025).

In capacity planning these values need to be multiplied by the device count. Particularly in virtual desktop pools and heavily consolidated servers, 200–350 MB of memory per agent noticeably affects infrastructure sizing; for that reason, in VDI projects we plan in advance for embedding the agent in the golden image and for per-pool resource reservations. Because protection and detection run on the endpoint itself, the agent can also make decisions on offline devices that have no access to the console; this behavior matters for laptops in the field and branch devices with intermittent connectivity.

The management console can be positioned in the cloud as multi-tenant, on premises, or in a hybrid model. Organizations with data residency constraints may prefer to run the console in their own data center; that choice frequently proves decisive in data localization discussions under KVKK (Turkey's data protection law). The console runs in English, French, traditional Chinese and Japanese; it offers role-based access control (RBAC) and a REST API covering all console operations (Fortinet FortiEDR Data Sheet, 2025). Because there is no Turkish console interface, we conduct the deployment, procedure documentation and team training in Turkish.

How did FortiEDR perform in independent evaluations?

Short answer: The result we can attribute to a primary source is round 4 of the MITRE Engenuity ATT&CK Evaluations. According to Fortinet's statement about that round (the Wizard Spider and Sandworm scenarios), FortiEDR blocked 100% of the attacks, detected and catalogued 97% of the 90 non-Linux steps and reported 93% of the sub-steps at the "technique" level (Fortinet, 2022).

Two caveats should be stated alongside these figures. First, the values are taken from Fortinet's own blog post; they have not been independently confirmed against MITRE's results pages — so the correct phrasing is "according to Fortinet's statement", not "according to MITRE". Second, the ATT&CK Evaluations do not declare a winner; they are a comparison of raw telemetry and detection quality and are specific to the round's scenario. We do not use on this page any more recent round results we cannot verify, test grades whose scores have not been published, or unsourced claims of the "industry-leading detection rate" variety.

We recommend basing product selection not on a single test round but on a pilot run in your own environment. Your application inventory, your legacy operating system burden and your tolerance for false positives affect the outcome more than any test report.

What is the difference between FortiEDR and FortiXDR?

Short answer: FortiEDR is the endpoint layer itself; FortiXDR is built on the same agent and console foundation and is activated with an additional licence. In other words, FortiXDR is not a separate product installation but FortiEDR extended with telemetry from across the Security Fabric.

ComparisonFortiEDRFortiXDR
ScopeEndpoint: workstation, server, cloud workload, OT clientCorrelation of endpoint telemetry together with network, email and other Fabric sources
AgentA single lightweight agentThe same agent; no additional agent installation required
LicencePer-device licenceAdditional licence on top of FortiEDR
Typical buyerOrganizations modernizing endpoint protectionSOCs wanting to consolidate incident correlation and response in one place

In practice most organizations start with FortiEDR and bring the XDR layer online once the endpoint policy has settled and false positives have been trimmed. This sequence both staggers the licence cost and provides the opportunity to calibrate correlation rules with real environment data. On the licence model side, Fortinet speaks of a flat per-device licensing cost and of flexible purchasing options such as FortiFlex; it also states that thanks to native cloud infrastructure and a small footprint, the platform scales to protect hundreds of thousands of endpoints (Fortinet FortiEDR Data Sheet, 2025). You can request a quote from our team for the right licence combination and a phased transition plan.

How does FortiEDR integrate with the Fortinet Security Fabric?

Short answer: FortiEDR passes the threat intelligence it produces at the endpoint to the network, email and identity layers; in return, it enriches its incident classification with the context coming from those layers. Fortinet states that the Security Fabric ecosystem spans more than 500 third-party solutions and that FortiGuard Labs processes and analyzes more than 100 billion events every day (Fortinet, 2026).

ComponentValue the integration produces
FortiGateSharing endpoint threat and application information with the firewall; instructing it to suspend or block an IP address following an intrusion attempt
FortiNACSharing discovered assets and endpoint intelligence; moving a device to a quarantine VLAN in the event of a breach
FortiSandboxAutomatically submitting suspicious files to the cloud, real-time analysis and classification
FortiSIEMForwarding events and alerts to the SIEM with a ready-made parser, forensic examination
FortiClient / EMSFeeding endpoint state into the ZTNA posture check and device tagging
FortiNDRCombining network detection data with endpoint data, shortening incident analysis time
FortiReconExternal attack surface visibility and prioritization of risks
FortiGuard LabsReal-time incident classification with current intelligence and triggering of the correct playbook

The source of that intelligence is also meaningful in scale: Fortinet states that it feeds the FortiGuard services with telemetry from a customer base of more than 830,000 and produces 1.8 million new definitions per week for the antivirus engine (Fortinet FortiSASE Data Sheet, 2026). In practice, where these integrations help most is in joining up the traces the same incident leaves at different layers: in a single investigation it becomes possible to see which user executed by another route an attachment that was quarantined on the FortiMail side, which destination a connection was attempted to in the FortiGate firewall logs, and the reportable record of that chain on FortiAnalyzer. FortiAnalyzer's FortiGuard IOC service provides forensic data with 500,000 IOCs per day (Fortinet FortiAnalyzer Data Sheet, 2026). In organizations that have built the access layer for remote users with FortiSASE, endpoint posture information feeds directly into the access decision.

Which steps does FortiEDR automate during a ransomware attack?

Short answer: The moment a suspicious process is detected, its network and file system access is cut, the incident is classified automatically and the playbook tied to that classification is triggered. Encryption is halted without waiting for analyst intervention.

The typical flow proceeds as follows:

  • Blocking: The process's outbound communication and its permission to write to the file system are cut immediately; ransomware encryption, file tampering and data exfiltration are prevented.
  • Enrichment: Fortinet Cloud Services collects additional evidence and confirms the classification with a multi-engine sandbox and FortiGuard intelligence.
  • Classification: The incident is classified automatically; that classification determines which playbook will run.
  • Response: File removal, termination of the malicious process, rollback of persistence changes, notifying the user, isolating the device or application and opening a ticket are all executed automatically.
  • Rollback: The malicious changes made are reversed on a single device or across the environment; on Windows this operation does not depend on VSS snapshots.
  • Investigation: The full attack chain and stack visibility are produced through patented code tracing, and memory snapshots are retained for memory-based attacks.

This automation is not a substitute for a backup strategy. Halting encryption and guaranteeing the integrity of the data are different problems; for an enterprise recovery plan, endpoint protection needs to be designed together with a layer such as Acronis backup and cyber protection. Verizon DBIR 2025 puts the proportion of victims who did not pay the ransom at 64% (Verizon DBIR, 2025); what makes not paying possible is, to a large extent, a working recovery capability.

How do you choose between FortiEDR, Trend Micro Apex One and Bitdefender GravityZone?

Short answer: All three are mature EDR/XDR platforms; what is decisive is not the feature list but your existing infrastructure, your legacy operating system burden, your console placement constraints and your operating model. We clarify the decision criteria with the following questions.

Decision criterionQuestion to askHow it affects the decision
Existing network layerAre your firewall, SASE and NAC layers Fortinet?Native in-Fabric correlation and single-console response weigh heavily in FortiEDR's favor
Legacy operating system burdenHow many unpatchable Windows servers or industrial clients do you have?Support extending back to Windows XP SP2 and Server 2003 puts FortiEDR ahead
Console placementIs a cloud console acceptable, or is on premises mandatory?FortiEDR supports cloud, hybrid and on-premises placement
Operating modelDo you have your own SOC team monitoring 24/7?If not, you need a platform that offers a managed detection and response (MDR) option
Existing investmentWhich platform is already licensed on your endpoints?Migration cost and parallel running time determine total cost of ownership

If the organization's existing investment is outside Fortinet, the alternatives should be assessed honestly. On our Trend Micro Apex One and Bitdefender GravityZone solution pages we address the positioning of these platforms separately; because we have deployed and operated all three in the field, we base the comparison not on marketing claims but on your inventory. You can review our other product families on our solutions page.

Which KVKK and PCI DSS requirements does FortiEDR serve?

Short answer: FortiEDR does not deliver compliance on its own; it does, however, contribute directly to meeting KVKK technical measure headings and the endpoint-related requirements of PCI DSS in a demonstrable way. Compliance is built from the trio of product plus process plus evidence.

The technical measures table of the Personal Data Security Guide (Technical and Administrative Measures) issued under KVKK (Turkey's data protection law) explicitly lists intrusion detection and prevention systems, log records, up-to-date anti-virus systems, network security and data loss prevention; the guide also requires that intrusions or activity that should not occur be identified and that all user transaction activity be logged regularly (KVKK Personal Data Security Guide, January 2018). Of these items, FortiEDR addresses endpoint malware protection, breach detection and incident recording; long-term retention and reporting of records is handled by FortiAnalyzer. FortiAnalyzer offers ready-made compliance reports such as PCI-DSS and HIPAA (Fortinet FortiAnalyzer Data Sheet, 2026).

On the PCI DSS v4.0 side, the requirement that concerns the endpoint most directly is 1.5.1: security controls must be implemented on devices that can connect both to an untrusted network and to the cardholder data environment (CDE) — the typical example being a remote worker's laptop (PCI Security Standards Council, PCI DSS v4.0). Call center stations, store tills and administrator laptops that access card data fall within the scope of this requirement; FortiEDR's application control, USB device control and device isolation capabilities produce controls that can be demonstrated in an audit. The ISO 27001, ISO 27017 and ISO 27018 compliance stated in Fortinet's FortiEDR data sheet is also among the information requested in vendor assessment files (Fortinet FortiEDR Data Sheet, 2025).

An additional requirement we frequently encounter in institutions subject to BDDK (Turkey's banking regulator) supervision and in public sector bodies is that the management plane must remain within the country. FortiEDR's ability to be positioned on premises or in a hybrid model makes it possible to meet that requirement; Sora Yazılım provides local support, Turkish procedure documentation and post-deployment knowledge transfer.

How does a FortiEDR rollout project proceed?

Short answer: We proceed through inventory, a pilot group, policy calibration in monitoring mode, a phased move to blocking, playbook design and Fabric integration. We do not install with a blocking policy directly on all devices — the risk of false positives could halt the production environment.

In the first phase the endpoint inventory is produced: the operating system distribution, unpatchable systems, VDI pools, servers and OT clients are separated into distinct groups. The agent is then run in monitoring mode on a representative pilot group; legitimate but suspicious-looking behavior generated by your business applications (custom macros, legacy ERP clients, field software) is recorded in exception lists. Once the policy has been calibrated, the groups are moved into blocking mode in sequence. In the playbook design, which automatic action will run for which incident class — isolation, process termination, rollback, ticket creation — is decided together and documented.

For organizations without their own SOC team, Fortinet's managed detection and response (MDR) service offers 24/7 continuous threat monitoring, alert triage and incident management; in addition, a deployment service (Deployment Best Practices Services) covering architecture planning, installation, playbook design, environment tuning and training can be purchased. In projects where the endpoint layer needs to be designed together with infrastructure automation and the monitoring pipeline, our DevOps and infrastructure services come into play. In organizations that use FortiClient as the endpoint agent in the Fortinet ecosystem, FortiEDR is generally positioned alongside it as the advanced detection and response layer rather than in its place.

Let's talk about your FortiEDR licensing, rollout and managed operation needs. As a Fortinet authorized channel partner, Sora Yazılım produces your endpoint inventory, determines the right licence level with you (detection, protection, response and threat hunting scopes), runs the pilot deployment and takes on policy maintenance after go-live. For a quote prepared according to your device count and scope, contact us through our contact page; let us review your current environment and produce a workable migration plan.

Key features

What it offers

  • Pre-execution blocking with kernel-level machine learning-based NGAV
  • Post-infection behavioral blocking: cutting off the suspicious process's network and file system access
  • Real-time prevention of ransomware encryption, file/registry tampering and data exfiltration
  • Attack surface reduction through vulnerability assessment, application CVE tracking and virtual patching
  • Discovery of unmanaged and IoT devices, application control and USB device control
  • Automated incident classification and classification-driven response playbooks
  • Rollback of malicious changes (VSS-independent on Windows, with macOS and Linux support)
  • Full attack chain and stack visibility through patented code tracing
  • Detection of memory-based and 'living off the land' attacks, memory snapshot retention
  • Incident descriptions mapped to the MITRE ATT&CK framework and analyst guidance
  • Legacy operating system coverage from Windows XP SP2 through Server 2025, feature parity on OT systems
  • Decision-making on the agent for offline endpoints
  • Cloud, hybrid or on-premises console; RBAC and a REST API covering all console operations
  • Integrations with FortiGate, FortiNAC, FortiSandbox, FortiSIEM, FortiClient/EMS, FortiNDR and FortiRecon
  • Extension to FortiXDR with an additional licence and an optional 24/7 managed detection and response (MDR) service
Tech Summary

Important technical data

Product type
Endpoint detection and response (EDR); FortiXDR with an additional licence
Windows client support
Windows XP SP2 – Windows 11 (32- and 64-bit)
Windows Server support
Windows Server 2003 SP2 – Windows Server 2025
Other platforms
macOS El Capitan (10.11) – Sequoia (15); enterprise Linux distributions (RHEL/CentOS, Ubuntu LTS, Oracle Linux, Amazon Linux AMI 2, openSUSE Leap, SLES); VDI: VMware Horizon 6-7, Citrix XenDesktop 7
Mobile platforms
Android 9.0 and later, iOS 15.0 and later
Agent CPU usage
Under 1% – 2%
Agent memory usage
200–350 MB
Agent disk usage
750 MB – 1 GB
Console placement
Cloud (multi-tenant), hybrid or on premises
Console languages
English, French, traditional Chinese, Japanese
Authorization and automation
RBAC, secure remote shell, REST API covering all console operations
Compliance stated in the data sheet
ISO 27001, ISO 27017, ISO 27018
Fabric integrations
FortiGate, FortiNAC, FortiSandbox, FortiSIEM, FortiClient/EMS, FortiNDR, FortiRecon
Service options
Deployment service (BPS) and 24/7 managed detection and response (MDR)
Licensing
Flat per-device; flexible purchasing options including FortiFlex — we prepare a quote based on scope and device count
Use Cases

When would you choose this product?

Finance

Central protection of branch and call center endpoints

On branch workstations and call center computers that access card data and customer records, application control, USB device control and behavioral blocking are applied together; incident records are retained on FortiAnalyzer as audit evidence.

Manufacturing / OT

Behavioral protection of unpatchable production stations

On legacy Windows-based HMI and line stations that cannot be updated because of application certification, virtual patching and post-infection blocking reduce risk without replacing hardware; full feature parity is maintained on manufacturing and OT systems.

Healthcare

Patient admission and imaging workstations

The aim is to restrict, through application control, the execution of applications other than the HIS and modality software, to cut ransomware encryption at process level, and to maintain service continuity without shutting the device down entirely.

Public sector

Managed monitoring in an institution without its own SOC

In institutions without 24/7 monitoring capacity, automated response playbooks and a managed detection and response service are positioned together; by keeping the console on premises, the management plane can be kept within the country.

Retail

POS terminals and the store network

Application allowlisting and USB control are applied on till terminals running legacy operating systems; store devices continue making decisions on the agent even under intermittent connectivity.

Who is it for?

Medium and large organizations that want to move endpoint protection from signature-based antivirus to behavioral detection, that carry a burden of unpatchable legacy operating systems, and that seek correlation with the Fortinet network layer in a single console, as well as organizations looking for a managed detection and response service because they have no SOC team of their own.

Frequently Asked Questions

Frequently asked questions

What is FortiEDR?
FortiEDR is Fortinet's endpoint detection and response solution. In a single lightweight agent it combines kernel-level machine learning-based antivirus with post-infection behavioral blocking; it protects workstations, servers, cloud workloads and production systems and automates incident response with playbooks.
What does post-infection protection mean?
It means preventing the impact of a malicious process even after it has started running on the endpoint. The moment FortiEDR sees a suspicious process flow, it cuts that process's outbound communication and its access to the file system; as a result, data exfiltration, command-and-control traffic, file tampering and ransomware encryption cannot produce an outcome.
What is the difference between FortiEDR and FortiClient?
FortiClient is the client that brings endpoint protection, ZTNA, VPN and compliance checking together in a single agent; FortiEDR is the advanced detection, automated response, rollback and threat hunting layer. In many organizations the two are positioned together: FortiClient handles access and posture checking while FortiEDR handles detection and response.
Is FortiXDR a separate product or an additional licence?
FortiEDR is the foundation of FortiXDR, and FortiXDR is activated with an additional licence. You do not need to install a new agent; through the same agent and console, endpoint telemetry is correlated with other sources in the Security Fabric. Most organizations settle their FortiEDR policy first and then move to the XDR layer.
Does FortiEDR run on legacy Windows versions?
Yes. According to Fortinet's data sheet, FortiEDR provides support from Windows XP SP2 through Windows 11 and from Windows Server 2003 SP2 through Windows Server 2025. This coverage is a decisive advantage on manufacturing, healthcare and retail stations that cannot be updated because of application certification.
How much does the agent affect endpoint performance?
Fortinet states that the agent uses between under 1% and 2% CPU, 200–350 MB of memory and 750 MB–1 GB of disk; the upper bounds of memory and disk usage are related to the threat hunting capability. In VDI pools and heavily consolidated servers, capacity planning should multiply these values by the device count.
Can the management console be hosted on premises?
Yes. FortiEDR can be positioned in the cloud as multi-tenant, in a hybrid model, or entirely on premises. In KVKK and sector audit scenarios that require the management plane to remain within the country, the on-premises console is preferred.
How did FortiEDR perform in the MITRE ATT&CK evaluation?
According to Fortinet's statement about round 4 of the MITRE Engenuity ATT&CK Evaluations (Wizard Spider and Sandworm), FortiEDR blocked 100% of the attacks, detected 97% of the 90 non-Linux steps and reported 93% of the sub-steps at technique level. These values are taken from Fortinet's own publication; the evaluation does not declare a winner.
Can the changes made by ransomware be rolled back?
Yes. Malicious changes can be rolled back on a single device or across the environment, manually or automatically; on Windows this operation does not depend on the VSS snapshots that ransomware targets, and it is also supported on macOS and Linux. Even so, rollback is not a substitute for an enterprise backup strategy.
We do not have our own SOC team; is there a managed service option?
There is. Fortinet's managed detection and response (MDR) service offers 24/7 continuous threat monitoring, alert triage and incident management. A deployment service covering architecture planning, installation, playbook design and training can also be purchased. Sora Yazılım takes on the policy maintenance and local support side.
How is the FortiEDR licence cost determined?
The licence is structured per device and varies with the scope selected (detection, protection, response and threat hunting) and additional modules such as FortiXDR. The Fortinet data sheet speaks of flat per-device licensing and of flexible purchasing options such as FortiFlex. Once your device inventory and scope are clear, you can reach us through our contact page for a prepared quote.
Does FortiEDR deliver KVKK compliance on its own?
No. No product delivers compliance on its own. FortiEDR contributes to meeting technical measure headings in the KVKK Personal Data Security Guide such as intrusion detection and prevention, up-to-date anti-virus systems and log records; record retention, reporting, the authorization matrix and administrative measures must be designed separately.
Vendor's official product page

Opens the vendor's original technical documentation and product page in a new tab.

FortinetFortiEDR / FortiXDR
Related Services

Services we deliver alongside this product

FortiEDR / FortiXDR licensing + deployment + support

Sora Yazılım handles licensing, deployment, training and ongoing management — all from a single team.

WhatsApp Support