FortiEDR is Fortinet's endpoint detection and response (EDR) solution that monitors running processes on endpoints at kernel level, stops malicious behavior in real time and automates incident response. It combines a pre-execution machine learning-based antivirus layer with a post-infection behavioral blocking layer in a single lightweight agent, protecting workstations, servers, cloud workloads and production systems with the same policy set.
Threat data shows why this two-layer approach is necessary. According to Verizon's 2025 Data Breach Investigations Report, ransomware was present in 44% of the breaches examined — in the previous report that figure was 32%, and among small and medium-sized organizations it rises to 88% (Verizon DBIR, 2025). FortiGuard Labs' 2026 Global Threat Landscape Report puts the number of confirmed ransomware victims in 2025 at 7,831; that is a 389% increase over the roughly 1,600 victims in the previous report (Fortinet, 2026).
What is FortiEDR and how does it differ from traditional antivirus?
Short answer: Traditional antivirus looks at what a file is; FortiEDR looks at what a process does. Even when there is no signature or hash match, the moment a process attempts to write to the file system, create a persistence entry or open an outbound connection, those behaviors are cut off by policy.
Fortinet describes this architecture as two protection layers. The first layer is the machine learning-based next-generation antivirus (NGAV) engine running at kernel level, aimed at blocking a malicious file before it executes; Fortinet states that its artificial intelligence and machine learning run at kernel level on both Windows and Linux. The second layer steps in against threats that get past the first: the moment FortiEDR detects a suspicious process flow, it blocks that process's outbound communication and its access to the file system. As a result, data exfiltration, command-and-control (C2) traffic, file and registry tampering and ransomware encryption cannot produce an outcome even if the device has been compromised. Because the device is not shut down and only the malicious process's capabilities are constrained, the user keeps working — in business continuity terms, this strikes a different balance from approaches that isolate the entire machine from the network.
In the background, Fortinet Cloud Services continues gathering evidence, enriches and classifies the incident data, and triggers the automated response playbook according to that classification. FortiEDR also reduces the attack surface before an attack happens: vulnerability assessment, tracking the CVE status of applications, virtual patching, discovery of unmanaged and IoT devices, application control and USB device control are all delivered inside the same agent. For this reason it is more accurate to position FortiEDR not merely as a detection tool but as an endpoint risk management layer.
At which stage of an attack do FortiEDR's protection layers come into play?
Short answer: There are five stages and each operates at a different moment in the attack chain. The table below summarizes which layer engages when, what it does and which threat type it targets.
| Layer | When it engages | What it does | Threat it targets |
|---|
| Discovery and prediction | Before the attack | Vulnerability assessment, application CVE tracking, virtual patching, discovery of unmanaged and IoT devices, application control | Unpatched applications, unregistered devices |
| Pre-infection protection | Before the file executes | Kernel-level machine learning-based NGAV, enrichment with FortiGuard threat intelligence, offline protection, USB device control | Known malware and its variants |
| Post-infection detection and neutralization | After the process starts running | Cutting off the suspicious process's outbound communication and file system access, detecting memory-based and "living off the land" attacks | Fileless malware, ransomware encryption, data exfiltration |
| Response and remediation | After the incident is classified | Playbook automation, file removal, process termination, rollback of persistence changes, device or application isolation, ticket creation | Persistence, lateral movement |
| Investigation and threat hunting | After the incident | Full attack chain visibility through patented code tracing, memory snapshots, translation of common IoC syntaxes such as TAXII into FortiEDR Lucene syntax | Threats that remained hidden or unclassified |
The rollback step carries one critical detail in practice: on Windows, reversing malicious changes does not depend on the VSS (Volume Shadow Copy) snapshots that ransomware targets; the same function is also supported on macOS and Linux. Full attack chain visibility is produced by patented code tracing technology and is recorded even while the device is offline. The console interface explains why an incident was flagged as suspicious and maps the attack to techniques in the MITRE ATT&CK framework; for teams that struggle to retain senior analysts, this is a direct operational gain.
Which attacks are endpoints exposed to today?
Short answer: Initial access is now achieved predominantly through phishing and vulnerability exploitation, and the time an attacker needs to weaponize a vulnerability has fallen from days to hours. When these two trends combine, an endpoint strategy that relies solely on signature updates falls short.
In ENISA's Threat Landscape 2025 report, which covers July 2024 – June 2025 and examines 4,875 incidents, phishing was reported as the dominant intrusion vector at 60% and vulnerability exploitation as 21.3% of initial access (ENISA Threat Landscape, 2025). Verizon DBIR 2025 shows that vulnerability exploitation reached 20% as an initial access vector, a 34% increase over the previous report, and that the share of edge devices and VPNs among exploitation targets rose from 3% to 22% (Verizon DBIR, 2025). FortiGuard Labs' 2026 report states that time-to-exploit on critical advisories has fallen to 24–48 hours and that global exploitation attempts rose 25.49% year over year (Fortinet, 2026).
This picture leads to two conclusions. First, because an attack can occur before the patch window closes, virtual patching and behavioral blocking on the endpoint are needed as compensating controls. Second, because the starting point of a breach is often at the network edge, endpoint telemetry needs to be evaluated in the same correlation pool as the firewall and email layers. FortiEDR's position within the Fortinet Security Fabric is aimed precisely at that second need.
Which operating systems and devices does FortiEDR support?
Short answer: One of FortiEDR's most distinctive strengths is its legacy operating system coverage. According to Fortinet's data sheet, the agent supports a range extending from Windows XP SP2 to Windows 11 and from Windows Server 2003 SP2 to Windows Server 2025, as well as the Android 9.0 and later and iOS 15.0 and later mobile platforms (Fortinet FortiEDR Data Sheet, 2025).
| Platform family | Coverage |
|---|
| Windows client | Windows XP SP2, 7, 8, 8.1, 10 and 11 (32- and 64-bit versions) |
| Windows Server | Windows Server 2003 SP2 and R2 SP2, 2008 SP1, 2008 R2 SP2, 2012, 2012 R2, 2016, 2019, 2022 and 2025 |
| macOS | From El Capitan (10.11) through Sequoia (15) |
| Linux | Red Hat Enterprise Linux and CentOS, Ubuntu LTS (server editions 64-bit only), Oracle Linux, Amazon Linux AMI 2, openSUSE Leap and SUSE Linux Enterprise Server |
| Virtual desktop (VDI) | VMware Horizon 6 and 7, Citrix XenDesktop 7 |
| Mobile | Android 9.0 and later, iOS 15.0 and later |
| Cloud | Cloud workloads; deployment through Google Cloud Marketplace and automated endpoint installation orchestration for Google Compute Engine |
This coverage maps directly onto manufacturing, healthcare and retail environments in Turkey. HMI stations on production lines, hospital imaging workstations and POS terminals often run a Windows version whose vendor support has ended; they cannot be updated because of application certification, and most modern EDR agents cannot be installed on them. On these devices, signature updates alone are not enough. Behavioral blocking, application control and virtual patching are the practicable way to reduce risk measurably without replacing the hardware. The fact that FortiEDR runs with full feature parity on manufacturing and OT systems is decisive in this scenario.
How much does the FortiEDR agent affect endpoint performance?
Short answer: Fortinet states that the FortiEDR agent uses between under 1% and 2% CPU, 200–350 MB of memory and 750 MB–1 GB of disk, and generates low-volume network traffic; the upper bounds of memory and disk usage are related to the threat hunting (response licence) capability (Fortinet FortiEDR Data Sheet, 2025).
In capacity planning these values need to be multiplied by the device count. Particularly in virtual desktop pools and heavily consolidated servers, 200–350 MB of memory per agent noticeably affects infrastructure sizing; for that reason, in VDI projects we plan in advance for embedding the agent in the golden image and for per-pool resource reservations. Because protection and detection run on the endpoint itself, the agent can also make decisions on offline devices that have no access to the console; this behavior matters for laptops in the field and branch devices with intermittent connectivity.
The management console can be positioned in the cloud as multi-tenant, on premises, or in a hybrid model. Organizations with data residency constraints may prefer to run the console in their own data center; that choice frequently proves decisive in data localization discussions under KVKK (Turkey's data protection law). The console runs in English, French, traditional Chinese and Japanese; it offers role-based access control (RBAC) and a REST API covering all console operations (Fortinet FortiEDR Data Sheet, 2025). Because there is no Turkish console interface, we conduct the deployment, procedure documentation and team training in Turkish.
How did FortiEDR perform in independent evaluations?
Short answer: The result we can attribute to a primary source is round 4 of the MITRE Engenuity ATT&CK Evaluations. According to Fortinet's statement about that round (the Wizard Spider and Sandworm scenarios), FortiEDR blocked 100% of the attacks, detected and catalogued 97% of the 90 non-Linux steps and reported 93% of the sub-steps at the "technique" level (Fortinet, 2022).
Two caveats should be stated alongside these figures. First, the values are taken from Fortinet's own blog post; they have not been independently confirmed against MITRE's results pages — so the correct phrasing is "according to Fortinet's statement", not "according to MITRE". Second, the ATT&CK Evaluations do not declare a winner; they are a comparison of raw telemetry and detection quality and are specific to the round's scenario. We do not use on this page any more recent round results we cannot verify, test grades whose scores have not been published, or unsourced claims of the "industry-leading detection rate" variety.
We recommend basing product selection not on a single test round but on a pilot run in your own environment. Your application inventory, your legacy operating system burden and your tolerance for false positives affect the outcome more than any test report.
What is the difference between FortiEDR and FortiXDR?
Short answer: FortiEDR is the endpoint layer itself; FortiXDR is built on the same agent and console foundation and is activated with an additional licence. In other words, FortiXDR is not a separate product installation but FortiEDR extended with telemetry from across the Security Fabric.
| Comparison | FortiEDR | FortiXDR |
|---|
| Scope | Endpoint: workstation, server, cloud workload, OT client | Correlation of endpoint telemetry together with network, email and other Fabric sources |
| Agent | A single lightweight agent | The same agent; no additional agent installation required |
| Licence | Per-device licence | Additional licence on top of FortiEDR |
| Typical buyer | Organizations modernizing endpoint protection | SOCs wanting to consolidate incident correlation and response in one place |
In practice most organizations start with FortiEDR and bring the XDR layer online once the endpoint policy has settled and false positives have been trimmed. This sequence both staggers the licence cost and provides the opportunity to calibrate correlation rules with real environment data. On the licence model side, Fortinet speaks of a flat per-device licensing cost and of flexible purchasing options such as FortiFlex; it also states that thanks to native cloud infrastructure and a small footprint, the platform scales to protect hundreds of thousands of endpoints (Fortinet FortiEDR Data Sheet, 2025). You can request a quote from our team for the right licence combination and a phased transition plan.
How does FortiEDR integrate with the Fortinet Security Fabric?
Short answer: FortiEDR passes the threat intelligence it produces at the endpoint to the network, email and identity layers; in return, it enriches its incident classification with the context coming from those layers. Fortinet states that the Security Fabric ecosystem spans more than 500 third-party solutions and that FortiGuard Labs processes and analyzes more than 100 billion events every day (Fortinet, 2026).
| Component | Value the integration produces |
|---|
| FortiGate | Sharing endpoint threat and application information with the firewall; instructing it to suspend or block an IP address following an intrusion attempt |
| FortiNAC | Sharing discovered assets and endpoint intelligence; moving a device to a quarantine VLAN in the event of a breach |
| FortiSandbox | Automatically submitting suspicious files to the cloud, real-time analysis and classification |
| FortiSIEM | Forwarding events and alerts to the SIEM with a ready-made parser, forensic examination |
| FortiClient / EMS | Feeding endpoint state into the ZTNA posture check and device tagging |
| FortiNDR | Combining network detection data with endpoint data, shortening incident analysis time |
| FortiRecon | External attack surface visibility and prioritization of risks |
| FortiGuard Labs | Real-time incident classification with current intelligence and triggering of the correct playbook |
The source of that intelligence is also meaningful in scale: Fortinet states that it feeds the FortiGuard services with telemetry from a customer base of more than 830,000 and produces 1.8 million new definitions per week for the antivirus engine (Fortinet FortiSASE Data Sheet, 2026). In practice, where these integrations help most is in joining up the traces the same incident leaves at different layers: in a single investigation it becomes possible to see which user executed by another route an attachment that was quarantined on the FortiMail side, which destination a connection was attempted to in the FortiGate firewall logs, and the reportable record of that chain on FortiAnalyzer. FortiAnalyzer's FortiGuard IOC service provides forensic data with 500,000 IOCs per day (Fortinet FortiAnalyzer Data Sheet, 2026). In organizations that have built the access layer for remote users with FortiSASE, endpoint posture information feeds directly into the access decision.
Which steps does FortiEDR automate during a ransomware attack?
Short answer: The moment a suspicious process is detected, its network and file system access is cut, the incident is classified automatically and the playbook tied to that classification is triggered. Encryption is halted without waiting for analyst intervention.
The typical flow proceeds as follows:
- Blocking: The process's outbound communication and its permission to write to the file system are cut immediately; ransomware encryption, file tampering and data exfiltration are prevented.
- Enrichment: Fortinet Cloud Services collects additional evidence and confirms the classification with a multi-engine sandbox and FortiGuard intelligence.
- Classification: The incident is classified automatically; that classification determines which playbook will run.
- Response: File removal, termination of the malicious process, rollback of persistence changes, notifying the user, isolating the device or application and opening a ticket are all executed automatically.
- Rollback: The malicious changes made are reversed on a single device or across the environment; on Windows this operation does not depend on VSS snapshots.
- Investigation: The full attack chain and stack visibility are produced through patented code tracing, and memory snapshots are retained for memory-based attacks.
This automation is not a substitute for a backup strategy. Halting encryption and guaranteeing the integrity of the data are different problems; for an enterprise recovery plan, endpoint protection needs to be designed together with a layer such as Acronis backup and cyber protection. Verizon DBIR 2025 puts the proportion of victims who did not pay the ransom at 64% (Verizon DBIR, 2025); what makes not paying possible is, to a large extent, a working recovery capability.
How do you choose between FortiEDR, Trend Micro Apex One and Bitdefender GravityZone?
Short answer: All three are mature EDR/XDR platforms; what is decisive is not the feature list but your existing infrastructure, your legacy operating system burden, your console placement constraints and your operating model. We clarify the decision criteria with the following questions.
| Decision criterion | Question to ask | How it affects the decision |
|---|
| Existing network layer | Are your firewall, SASE and NAC layers Fortinet? | Native in-Fabric correlation and single-console response weigh heavily in FortiEDR's favor |
| Legacy operating system burden | How many unpatchable Windows servers or industrial clients do you have? | Support extending back to Windows XP SP2 and Server 2003 puts FortiEDR ahead |
| Console placement | Is a cloud console acceptable, or is on premises mandatory? | FortiEDR supports cloud, hybrid and on-premises placement |
| Operating model | Do you have your own SOC team monitoring 24/7? | If not, you need a platform that offers a managed detection and response (MDR) option |
| Existing investment | Which platform is already licensed on your endpoints? | Migration cost and parallel running time determine total cost of ownership |
If the organization's existing investment is outside Fortinet, the alternatives should be assessed honestly. On our Trend Micro Apex One and Bitdefender GravityZone solution pages we address the positioning of these platforms separately; because we have deployed and operated all three in the field, we base the comparison not on marketing claims but on your inventory. You can review our other product families on our solutions page.
Which KVKK and PCI DSS requirements does FortiEDR serve?
Short answer: FortiEDR does not deliver compliance on its own; it does, however, contribute directly to meeting KVKK technical measure headings and the endpoint-related requirements of PCI DSS in a demonstrable way. Compliance is built from the trio of product plus process plus evidence.
The technical measures table of the Personal Data Security Guide (Technical and Administrative Measures) issued under KVKK (Turkey's data protection law) explicitly lists intrusion detection and prevention systems, log records, up-to-date anti-virus systems, network security and data loss prevention; the guide also requires that intrusions or activity that should not occur be identified and that all user transaction activity be logged regularly (KVKK Personal Data Security Guide, January 2018). Of these items, FortiEDR addresses endpoint malware protection, breach detection and incident recording; long-term retention and reporting of records is handled by FortiAnalyzer. FortiAnalyzer offers ready-made compliance reports such as PCI-DSS and HIPAA (Fortinet FortiAnalyzer Data Sheet, 2026).
On the PCI DSS v4.0 side, the requirement that concerns the endpoint most directly is 1.5.1: security controls must be implemented on devices that can connect both to an untrusted network and to the cardholder data environment (CDE) — the typical example being a remote worker's laptop (PCI Security Standards Council, PCI DSS v4.0). Call center stations, store tills and administrator laptops that access card data fall within the scope of this requirement; FortiEDR's application control, USB device control and device isolation capabilities produce controls that can be demonstrated in an audit. The ISO 27001, ISO 27017 and ISO 27018 compliance stated in Fortinet's FortiEDR data sheet is also among the information requested in vendor assessment files (Fortinet FortiEDR Data Sheet, 2025).
An additional requirement we frequently encounter in institutions subject to BDDK (Turkey's banking regulator) supervision and in public sector bodies is that the management plane must remain within the country. FortiEDR's ability to be positioned on premises or in a hybrid model makes it possible to meet that requirement; Sora Yazılım provides local support, Turkish procedure documentation and post-deployment knowledge transfer.
How does a FortiEDR rollout project proceed?
Short answer: We proceed through inventory, a pilot group, policy calibration in monitoring mode, a phased move to blocking, playbook design and Fabric integration. We do not install with a blocking policy directly on all devices — the risk of false positives could halt the production environment.
In the first phase the endpoint inventory is produced: the operating system distribution, unpatchable systems, VDI pools, servers and OT clients are separated into distinct groups. The agent is then run in monitoring mode on a representative pilot group; legitimate but suspicious-looking behavior generated by your business applications (custom macros, legacy ERP clients, field software) is recorded in exception lists. Once the policy has been calibrated, the groups are moved into blocking mode in sequence. In the playbook design, which automatic action will run for which incident class — isolation, process termination, rollback, ticket creation — is decided together and documented.
For organizations without their own SOC team, Fortinet's managed detection and response (MDR) service offers 24/7 continuous threat monitoring, alert triage and incident management; in addition, a deployment service (Deployment Best Practices Services) covering architecture planning, installation, playbook design, environment tuning and training can be purchased. In projects where the endpoint layer needs to be designed together with infrastructure automation and the monitoring pipeline, our DevOps and infrastructure services come into play. In organizations that use FortiClient as the endpoint agent in the Fortinet ecosystem, FortiEDR is generally positioned alongside it as the advanced detection and response layer rather than in its place.
Let's talk about your FortiEDR licensing, rollout and managed operation needs. As a Fortinet authorized channel partner, Sora Yazılım produces your endpoint inventory, determines the right licence level with you (detection, protection, response and threat hunting scopes), runs the pilot deployment and takes on policy maintenance after go-live. For a quote prepared according to your device count and scope, contact us through our contact page; let us review your current environment and produce a workable migration plan.