What happens when the IOC breach detection engine on FortiAnalyzer finds web logs that match a blocklisted IP address?
The endpoint is marked as Compromised and. optionally, can be put in quarantine.
FortiAnalyzer flags the associated host for further analysis.
A new Infected entry is added for the corresponding endpoint.
The detection engine classifies those logs as Suspicious
Submit