Skip to content Skip to navigation Skip to footer

Overview

FortiSandbox features advanced AI and purpose-built machine learning, static and dynamic analysis, and enhanced real-time threat intelligence from FortiGuard Labs. It offers proactive and real-time detection, classification, and protection against emerging and unknown threats including zero-days, ransomware, malware, and sophisticated AI-based attacks—without impact on productivity or increasing security overhead. 

Advanced AI with Purpose-Built Machine Learning

FortiSandbox leverages static and dynamic analysis, advanced AI with purpose-built machine learning algorithms, and artificial neural networks to accelerate threat analysis, deliver more accurate threat detection through enhanced contextual analysis, and shorten attack windows. The advanced AI technology stack gives FortiSandbox the ability to adapt and react to evolving threats in real time more accurately. FortiSandbox delivers a powerful and effective solution for protecting organizations against today's complex cyber threats.

Protection for Any Environment

FortiSandbox solutions are offered in a number of form factors to fit the unique requirements of your organization. On-premises hardware, virtual machines (VMs), cloud hosted, and SaaS offerings are available for your enterprise, OT, or SOC needs. FortiSandbox functions autonomously or seamlessly integrates with the Fortinet Security Operations (SecOps) platform, offering comprehensive and coordinated defense against threats. 

Fast, Accurate, and Scalable

FortiSandbox delivers exceptional performance, accuracy, and scalability, empowering organizations to combat today's sophisticated threats. Its advanced AI engine accelerates analysis, enabling quicker response times and reducing the risk of exploitation. With excellent detection and accuracy, and universal VM options, FortiSandbox provides comprehensive threat detection and scalability to meet the needs of any organization.

New in FortiSandbox 5.0

FortiSandbox 5.0 represents a significant leap forward in threat detection and response compared to previous releases (v4.4.x). By harnessing the power of advanced AI, you can effectively combat the evolving threat landscape. Key new features and enhancements over prior versions include:

  • Accelerated threat detection: Analyzes files 10x faster, delivering rapid verdicts and reducing response times
  • Accuracy and detection: Delivers 3x improved detection and accuracy to ensure comprehensive threat protection
  • Scalable: Offers 3x more VMs to enable organizations to customize FortiSandbox for their needs
  • Contextual threat intelligence: Provides real-time analysis to deliver rich threat intelligence with additional risk context for accurate detection and prioritization based on exploitability
  • Universal VM: Offers a flexible VM approach, allowing users to detach VM licenses from the OS. Reduces licensing complexity and provides the flexibility to choose any local, cloud, or custom VM type and OS
  • SOC assistance: Empowers SOC teams with virtual security analyst capabilities for enhanced threat analysis, research, and operations
  • Advanced analysis: Provides in-depth job details, including sequences, file/memory/registry operations, and IOC correlations for enriched threat research

Features and Benefits

FortiSandbox powered by Advanced AI is armed with key features that empower security and SOC teams to protect their organizations with lightning-fast real-time analysis, protection, and response capabilities.

Real-time Protection

Provides real-time protection against zero-day threats with advanced AI and ML

Real-Time Verdicts

Analyzes files for patterns and anomalies, quickly delivering real-time verdicts

Broad Coverage

Analyzes a wide variety of file types so that no threats go undetected

SOC Assistance

Augment SOC analyst capabilities with a threat dashboard and MITRE ATT&CK® matrix for enhanced analysis & response

Universal VM

Offers universal VM for any local, cloud, or custom VM type and OS

Holistic IT/OT Zero-day Threat Protection

Protects IT, OT, converged environments, and assets with one solution

400M

Files Analyzed Daily

99.8%

Block Rate

200K

Zero-days Blocked Daily

Fortinet Security Fabric Integrations

The strength of Fortinet's platform-driven approach is to enable coordinated workflows including response while customers benefit from a globalized network effect across Fortinet’s worldwide install base. The FortiSandbox solutions portfolio are integrated into the following Fabric solutions:

FortiSandbox Use Cases

icon secure internet access
Secure IT Networks
Protect your networks from emerging and evasive threats with advanced AI and purpose-built ML protection. Stay secure while keeping pace with enterprise traffic and reducing security overhead.
icon secure email
Secure Email
Integrate with Fortinet FortiMail, and suspicious files in emails—including email-based ransomware/malware/phishing—can be analyzed in real time before reaching intended recipients.
icon secure industrial networks
Secure OT Networks
Protect your manufacturing, plant, safety, facility, or other OT environments from targeted malware attacks that can bring operations to a halt.
icon protect endpoints
Secure Endpoints
Stop suspicious files or malware from executing at the endpoint and quickly quarantine the affected endpoint to protect the organization with FortiClient and FortiSandbox.
icon web application
Secure Web Apps
Integrate with FortiWeb, and web applications are protected against all types of threats including phishing and zero-days.
icon network soc
Augment the SOC
Research, analyze, and correlate threats faster with FortiSandbox as the virtual security analyst. Get a better understanding of suspicious indicators with the Job Detail report.

Services and Product Deployment Options

Service/Product Type Description
FortiSandbox SaaS SaaS subscription Available as part of FortiGate Cloud, this subscription sandbox service protects against zero-day malware.
FortiSandbox PaaS PaaS subscription This Fortinet-hosted sandbox is a subscription service. It includes FortiSandbox VM with dedicated resources for high performance and centralization of reports. 
FortiSandbox Virtual Appliance VM subscription FortiSandbox VMs are offered as an alternative to hardware for greater deployment flexibility with the same features. 
FortiSandbox Hardware HW bundle + licenses

FortiSandbox hardware appliances natively integrate with the Security Fabric, Fabric Partners, adapters, APIs, network share, and sniffers to intercept and submit suspicious content to FortiSandbox. The integration also provides timely remediation and reporting capabilities to those devices.

Resources

Data Sheets
Checklists
eBooks
Solution Guides
Videos
Better Together: FortiSandbox + FortiSIEM
Better Together: FortiSandbox + FortiSIEM »

Using FortiSandbox and FortiSIEM together enables organizations to enhance and enrich their threat detection and response capabilities.

Better Together: FortiSandbox + FortiNDR
Better Together: FortiSandbox + FortiNDR »

When working together, FortiSandbox and FortiNDR provide improved and broader malware coverage, reduced vulnerability and threat workloads, and faster response times.

Better Together: FortiSandbox + FortiSOAR
Better Together: FortiSandbox + FortiSOAR »

FortiSandbox and FortiSOAR provide an automated security solution that enables security teams to focus on higher-level tasks while reducing the workload associated with manual threat detection and remediation.

Better Together: FortiSandbox + FortiClient
Better Together: FortiSandbox + FortiClient »

FortiSandbox and FortiClient work together to provide coordinated protection on endpoints so that organizations can quickly detect and protect against suspicious and zero-day file-based malware as well as advanced sophisticated threats before they can cause damage to the network

Better Together: FortiSandbox + FortiMail
Better Together: FortiSandbox + FortiMail »

When working together, FortiSandbox and FortiMail protect against the very latest threats delivered via inbound emails such as zero-day malware and ransomware as well as phishing and other URL-based attacks.

Better Together: FortiSandbox + FortiWeb
Better Together: FortiSandbox + FortiWeb »

When working together, FortiSandbox and FortiWeb provide improved detection and protection of web applications and APIs against suspicious, zero-day file based threats and malware.

Better Together: FortiSandbox + FortiSASE
Better Together: FortiSandbox + FortiSASE »

When working together, the Fortinet cloud sandbox solution and FortiSASE provide secure internet access and protection against known and unknown threats to remote users.

Better Together: FortiSandbox + FortiEDR
Better Together: FortiSandbox + FortiEDR »

When working together, FortiSandbox and FortiEDR provide improved detection, analysis enrichment, and protection against suspicious and zero-day file-based threats on endpoints.

Better Together: Inline Sandbox + FortiGate Next-Generation Firewall
Better Together: Inline Sandbox + FortiGate Next-Generation Firewall »

When working together, AI-powered inline sandbox and FortiGate NGFW provide organizations with peace of mind that they are protected against file-based zero-day and patient-zero threats such as malware and ransomware.

Free Product Demo



Sign up for a personalized demo of AI-powered sandboxing solutions and services from Fortinet.

What to Expect:

  • See how FortiSandbox isolates and analyzes unknown malware in real time.
  • Discover how FortiSandbox defends against even the newest threats with inline protection.
  • Witness how FortiSandbox maps and provides an understanding of different malware behaviors.