Skip to main content
Authorized Fortinet reseller · DynaScale Technologies888-907-0723 · 24/7[email protected]
FNDR

FortiNDR

Behavioural detection of the attacker already inside

Licensing
By inspected throughput and deployment model
Deployment
Physical or virtual sensor, requires SPAN/TAP
Detection
Behavioural modelling of east-west traffic

FortiNDR models normal east-west traffic and flags the deviation: lateral movement, command-and-control beaconing, staging before exfiltration. Because it is behavioural rather than signature-based it catches novel tooling, and because it inspects internal traffic it sees activity that never crosses the firewall.

Is this the right model?

Where it fits — and where it stops fitting

The practical constraint is traffic access — NDR needs a SPAN, mirror or TAP at the right points, and that is a network engineering exercise we work through before quoting. Its strongest case is alongside EDR, because it sees the unmanaged devices EDR cannot be installed on.

Highlights

  • Sees the devices EDR cannot be installed on
  • Catches lateral movement and C2 beaconing
  • Behavioural — not dependent on signatures
  • Feeds FortiSIEM and FortiSOAR for response

Typical deployments

  • Detecting an intruder who already has valid credentials
  • Visibility across an OT or IoT segment with no agents
  • Confirming or ruling out lateral movement during an incident
Buying guidance

What to work out first

FortiNDR watches east-west traffic and models normal behaviour, then flags the deviation: lateral movement, beaconing to command and control, staging before exfiltration. It is aimed at the phase after initial access, which perimeter controls by definition have already missed.

Because it is behavioural rather than signature-based, it catches novel tooling — and because it inspects internal traffic, it sees activity that never crosses the firewall at all.

Questions worth answering before you order

Can you actually get the traffic?

NDR needs a SPAN, mirror or TAP at the right points. This is the practical constraint that decides whether a deployment succeeds, and it is a network engineering question we work through before quoting.

Do you have EDR already?

NDR and EDR overlap deliberately. NDR sees the unmanaged devices EDR cannot be installed on — which in an OT or IoT-heavy environment is most of them.

Who investigates the detections?

Behavioural detections need a human to adjudicate. Without SOC capacity, this generates alerts nobody closes.

Specifications

What this includes

Fortinet publishes no throughput table for this product — it is licensed per user, endpoint, workload or account. What follows is capability and sizing, not benchmarks.

What you are buying

What you are buying
LicensingBy inspected throughput and deployment model
DeploymentPhysical or virtual sensor, requires SPAN/TAP
DetectionBehavioural modelling of east-west traffic

How this is sized

Fortinet licenses this product per user, endpoint, workload or account rather than by appliance throughput, so there is no comparable performance table to publish. We size it from your actual environment — tell us the numbers and we will work it through with you.

How this is sized
LicensingBy inspected throughput and deployment model

Sources

Reproduced from Fortinet published documentation and subject to change without notice. Where a figure is load-bearing for your design, ask us to confirm it in writing before you order — we will.

Buyers also compare