Vendor Sheet
FortiClient Forensic Service: Cyber Incident Analysis and Recovery
FortiClient Forensic Service gives endpoint customers access to FortiGuard Labs specialists who collect, examine, and analyze digital evidence after a cyber incident. Analysts securely gather disk artifacts, memory snapshots, system records, browser history, event logs, registry information, and other evidence through a remote collection process requiring minimal customer involvement. The investigation identifies the initial attack vector, malicious activity timeline, root cause, lateral movement, affected systems, compromised accounts, malware, vulnerabilities, and indicators of compromise. Analysis may cover persistence, program execution, memory, browser activity, event logs, shell artifacts, and malware behavior. Customers receive an executive summary, detailed technical findings, evid
