Skip to content
Cybersecurity Fortinet

FortiSandbox

FortiSandbox: Advanced Threat Protection with AI/ML. Zero-day malware detection, MITRE ATT&CK mapping, Security Fabric integration.

Sales Representative
Łukasz Gil

Łukasz Gil

Sales Representative

Key Features

  • Zero-day malware detection
  • AI/ML pre-filtering and analysis
  • MITRE ATT&CK technique mapping
  • Anti-evasion technology
  • Security Fabric native integration
Available now
Łukasz Gil

Łukasz Gil

Sales Representative

Send inquiry
Table of Contents

Why do you need FortiSandbox?

60% of malware is polymorphic or zero-day. Signature-based AV detects only known threats. Without sandbox analysis, weaponized documents, targeted attacks, and novel malware pass through traditional defenses.

FortiSandbox is an Advanced Threat Protection platform with AI-powered analysis and dynamic analysis in isolated environment. It detects zero-day malware, maps techniques to MITRE ATT&CK, and automatically shares intelligence with entire Security Fabric.

How does it work?

Pre-Filtering (AI/ML)

Fast elimination of known malware:

  • FortiGuard signature matching
  • Machine learning classification
  • Hash lookup and reputation
  • File type analysis
  • 95% samples processed without VM

Static Analysis

Analysis without execution:

  • Code structure analysis
  • Embedded object extraction
  • Metadata inspection
  • Anomaly detection
  • Verdict in seconds

Dynamic Analysis

Execution in isolated VM:

  • Multi-OS virtual machines
  • Behavioral monitoring
  • Network activity capture
  • Registry and file system changes
  • Anti-evasion technology

Key Features

Anti-Evasion

  • Hardware-level instrumentation
  • Environment randomization
  • Time acceleration
  • User interaction simulation
  • VM-aware malware detection

MITRE ATT&CK Mapping

  • Automatic technique identification
  • Tactic classification
  • Kill chain visualization
  • Threat actor attribution
  • Reporting with framework context

Threat Intelligence

  • Automatic IOC extraction
  • Real-time sharing with Fabric
  • STIX/TAXII export
  • Custom indicator import
  • Global intelligence enrichment

Forensic Reporting

  • Detailed analysis results
  • Screenshots and video
  • PCAP network captures
  • Dropped files collection
  • Evidence export

Deployment Options

On-Premise Appliances:

ModelFiles/HourVMsUse Case
500F3608SMB
1000F72016Mid-size
2000F1,44032Enterprise
3000F5,76056Large enterprise

FortiSandbox Cloud: SaaS, per-file licensing, global infrastructure

Security Fabric Integration

Inline sources:

  • FortiGate - files and URLs
  • FortiMail - email attachments
  • FortiClient - endpoint files
  • FortiWeb - web uploads
  • FortiProxy - downloads

Verdict sharing:

  • Real-time IOC propagation
  • Automatic signature creation
  • Policy enforcement
  • Global threat intelligence

Who is it for?

  • Organizations needing zero-day protection
  • Enterprises with targeted attack concerns
  • SOC requiring MITRE ATT&CK visibility
  • Companies with high-value assets and APT risk

Benefits

For SOC: MITRE mapping, forensic reports, threat hunting support

For security: Zero-day detection, anti-evasion, automated IOC sharing

For business: Protection against targeted attacks, reduced dwell time, compliance

Specifications

AnalysisStatic + Dynamic + AI/ML
Anti-evasionHardware-level, randomization
FrameworkMITRE ATT&CK mapping
DeploymentAppliance, VM, Cloud

FAQ

How does FortiSandbox detect zero-day? Behavioral analysis in isolated VM - observes what malware does, not what it is. Plus AI/ML for pre-filtering.

What is anti-evasion? Techniques preventing sandbox detection by malware - hardware instrumentation, environment randomization.

How quickly do I get verdict? Pre-filtering in seconds (95% samples). Full dynamic analysis 1-5 minutes depending on complexity.

Does FortiSandbox work inline? Yes. Hold-and-deliver mode blocks delivery until verdict. Or sniffer mode for alerts.

How does integration with FortiGate work? Automatic submission of suspicious files, instant verdict sharing, policy enforcement.

Is cloud version available? Yes. FortiSandbox Cloud - SaaS with global infrastructure, per-file billing.

What is MITRE ATT&CK mapping? Automatic identification of attack techniques and mapping to framework for threat intelligence.

How does FortiSandbox share intelligence? Real-time IOC sharing with Security Fabric. STIX/TAXII export for third-party.

Which file formats does it analyze? PE, Office documents, PDF, archives, scripts, URLs, email attachments, and more.

How does support work? Fortinet 24/7 TAC. nFlo as partner offers ATP deployment and detection tuning.

Inquire about FortiSandbox

Contact your product specialist and get a custom quote.

Sales Representative
Łukasz Gil

Łukasz Gil

Sales Representative

Response within 24 hours
Free technical consultation
Custom quote and configuration

Providing your phone number will speed up contact.

Want to Reduce IT Risk and Costs?

Book a free consultation - we respond within 24h

Response in 24h Free quote No obligations

Or download free guide:

Download NIS2 Checklist