FortiSandbox
FortiSandbox: Advanced Threat Protection with AI/ML. Zero-day malware detection, MITRE ATT&CK mapping, Security Fabric integration.

Key Features
- Zero-day malware detection
- AI/ML pre-filtering and analysis
- MITRE ATT&CK technique mapping
- Anti-evasion technology
- Security Fabric native integration
Table of Contents
Why do you need FortiSandbox?
60% of malware is polymorphic or zero-day. Signature-based AV detects only known threats. Without sandbox analysis, weaponized documents, targeted attacks, and novel malware pass through traditional defenses.
FortiSandbox is an Advanced Threat Protection platform with AI-powered analysis and dynamic analysis in isolated environment. It detects zero-day malware, maps techniques to MITRE ATT&CK, and automatically shares intelligence with entire Security Fabric.
How does it work?
Pre-Filtering (AI/ML)
Fast elimination of known malware:
- FortiGuard signature matching
- Machine learning classification
- Hash lookup and reputation
- File type analysis
- 95% samples processed without VM
Static Analysis
Analysis without execution:
- Code structure analysis
- Embedded object extraction
- Metadata inspection
- Anomaly detection
- Verdict in seconds
Dynamic Analysis
Execution in isolated VM:
- Multi-OS virtual machines
- Behavioral monitoring
- Network activity capture
- Registry and file system changes
- Anti-evasion technology
Key Features
Anti-Evasion
- Hardware-level instrumentation
- Environment randomization
- Time acceleration
- User interaction simulation
- VM-aware malware detection
MITRE ATT&CK Mapping
- Automatic technique identification
- Tactic classification
- Kill chain visualization
- Threat actor attribution
- Reporting with framework context
Threat Intelligence
- Automatic IOC extraction
- Real-time sharing with Fabric
- STIX/TAXII export
- Custom indicator import
- Global intelligence enrichment
Forensic Reporting
- Detailed analysis results
- Screenshots and video
- PCAP network captures
- Dropped files collection
- Evidence export
Deployment Options
On-Premise Appliances:
| Model | Files/Hour | VMs | Use Case |
|---|---|---|---|
| 500F | 360 | 8 | SMB |
| 1000F | 720 | 16 | Mid-size |
| 2000F | 1,440 | 32 | Enterprise |
| 3000F | 5,760 | 56 | Large enterprise |
FortiSandbox Cloud: SaaS, per-file licensing, global infrastructure
Security Fabric Integration
Inline sources:
- FortiGate - files and URLs
- FortiMail - email attachments
- FortiClient - endpoint files
- FortiWeb - web uploads
- FortiProxy - downloads
Verdict sharing:
- Real-time IOC propagation
- Automatic signature creation
- Policy enforcement
- Global threat intelligence
Who is it for?
- Organizations needing zero-day protection
- Enterprises with targeted attack concerns
- SOC requiring MITRE ATT&CK visibility
- Companies with high-value assets and APT risk
Benefits
For SOC: MITRE mapping, forensic reports, threat hunting support
For security: Zero-day detection, anti-evasion, automated IOC sharing
For business: Protection against targeted attacks, reduced dwell time, compliance
Specifications
| Analysis | Static + Dynamic + AI/ML |
| Anti-evasion | Hardware-level, randomization |
| Framework | MITRE ATT&CK mapping |
| Deployment | Appliance, VM, Cloud |
FAQ
How does FortiSandbox detect zero-day? Behavioral analysis in isolated VM - observes what malware does, not what it is. Plus AI/ML for pre-filtering.
What is anti-evasion? Techniques preventing sandbox detection by malware - hardware instrumentation, environment randomization.
How quickly do I get verdict? Pre-filtering in seconds (95% samples). Full dynamic analysis 1-5 minutes depending on complexity.
Does FortiSandbox work inline? Yes. Hold-and-deliver mode blocks delivery until verdict. Or sniffer mode for alerts.
How does integration with FortiGate work? Automatic submission of suspicious files, instant verdict sharing, policy enforcement.
Is cloud version available? Yes. FortiSandbox Cloud - SaaS with global infrastructure, per-file billing.
What is MITRE ATT&CK mapping? Automatic identification of attack techniques and mapping to framework for threat intelligence.
How does FortiSandbox share intelligence? Real-time IOC sharing with Security Fabric. STIX/TAXII export for third-party.
Which file formats does it analyze? PE, Office documents, PDF, archives, scripts, URLs, email attachments, and more.
How does support work? Fortinet 24/7 TAC. nFlo as partner offers ATP deployment and detection tuning.
Inquire about FortiSandbox
Contact your product specialist and get a custom quote.

Related Services
Our services supporting the implementation and management of this solution
Firewall and NGFW Implementation
Cybersecurity
Effective network protection against threats. Implementation and configuration in 2 weeks.
ISA Security Audit
Cybersecurity
ISA (Information Security Assessment) audit for automotive and manufacturing. Foundation for TISAX certification.
Comprehensive Storage Services
IT Infrastructure
Build storage that won't fail at critical moment. Design, implementation, support from storage specialists.
Storage System Implementation
IT Infrastructure
Fast storage with enterprise redundancy. Performance matched to workloads, not budget.
From Our Knowledge Base
Articles related to this solution
Blocking the Device Code Flow in Microsoft Entra ID with Conditional Access
How to reduce the risk of Device Code Phishing? A practical guide to blocking the Device Code Flow in Microsoft Entra ID with Conditional Access — step by step, with pitfalls and validation.
Cyber threat landscape 2026: a report for Polish companies in the NIS2 era
Poland is the most digitally attacked EU country. Explore the 2026 cyber threat landscape in numbers, the three most dangerous attack vectors and the NIS2/KSC obligations for Polish companies.
Deepfake, vishing and CEO fraud: how to protect your company from AI-powered scams
A deepfake on a video call, voice cloning and AI-powered CEO fraud mean real losses in the millions. Learn how these scams work and the proven defenses, including second-channel verification.
Related Products
Other solutions you might be interested in
Aruba ClearPass
Aruba Networks
Aruba ClearPass: NAC platform with profiling of 70+ thousand device types. Zero Trust access control for users, BYOD, and IoT.
Barracuda CloudGen Firewall
Barracuda Networks
Barracuda CloudGen Firewall: next-gen firewall with SD-WAN. IPS, application control, VPN, threat protection. Appliance, virtual, cloud.
Barracuda Email Protection
Barracuda Networks
Barracuda Email Protection: AI-powered email security against phishing, ransomware, BEC and account takeover. Gateway + API for Microsoft 365 and Google.
Barracuda SecureEdge
Barracuda Networks
Barracuda SecureEdge: SASE platform combining SD-WAN with cloud security. Zero Trust, SWG, CASB, FWaaS. Protection for distributed workforce.
Want to Reduce IT Risk and Costs?
Book a free consultation - we respond within 24h
Or download free guide:
Download NIS2 Checklist