Explore OpenCTI or OpenAEV platform with 30 days Free Trial!
XTM Hub by Filigran
Sign Up
FortiSandbox logo

FortiSandbox

Automatic deploy
Supported by community
Detection & Response Enablement

Overview

Enrich StixFile and Artifact observables with Fortinet FortiSandbox verdicts.

The OpenCTI FortiSandbox enrichment connector enriches StixFile and Artifact observables with Fortinet FortiSandbox verdicts. For each observable it queries the FortiSandbox JSON-RPC API by hash (SHA-256/SHA-1/MD5), maps the rating (clean, low/medium/high risk, suspicious, malicious) to an OpenCTI score and labels, completes the file hashes, and attaches a STIX Malware Analysis object with the FortiSandbox result. When enabled, unknown files carried by the observable can be submitted for on-demand analysis and polled for a verdict. The connector is playbook compatible and always returns the enriched bundle.

Basic information

FortiSandbox
Connectors
7.260706.0
7.260706.0
0

    We use cookies to run XTM Hub. Necessary cookies are always on, optional cookies (functionality, analytics, marketing) are used with your consent. Accept all, reject all, or manage your choices anytime in "Cookie settings".