NGAV Detects & Blocks malware file transfers
FortiGuard AV real-time protection blocks ransomware file
EDR behaviour detection & blocking of ransomware activity out of the box.
Detected by pre-filter or scan engines, as this is a known ransomware.
Existing behaviour detection of the ransomware (launching files, visible windows, etc.).
Detects indicators attributed to the ransomware from Fabric products.
Detected by pre-filter or scan engines, as this is a known ransomware.
Detects & Blocks DNS traffic to known malicious domains associated with this attack
Detects & Blocks traffic to known C&C domains
Detected by FortiGuard IOC for post event analysis
Detected by FortiGuard IOC for post event analysis
Neural network / AI-based detection detects the ransomware
Detected by pre-filter or scan engines, as this is a known ransomware.
Detects & blocks access to known C&C domains
FortiGate
FortiClient
FortiEDR
FortiMail
FortiSandbox
FortiAI
FortiCASB
FortiCWP
Version Info: 85.00092
Link: https://www.fortiguard.com/updates/antivirus?version=85.00092
Behavior Detection
Version Info: v4, v5
Link: https://kb.fortinet.com/kb/microsites/search.do?cmd=displayKC&docType=kc&externalId=FD52267&sliceId=1&docTypeID=DT_KCARTICLE_1_1&dialogID=221610791&stateId=1%200%20221612085%27)
Other Info: EDR behaviour detection & blocking of ransomware activity out of the box.
FortiGuard DNS
Version Info: 6.2+
Link: https://www.fortiguard.com/learnmore#dns
Other Info: Detects & Blocks DNS traffic to known malicious domains associated with this attack
Behavior Detection
Version Info: 3.2+
Link: https://filestore.fortinet.com/fortiguard/downloads/9e779da82d86bcd4cc43ab29f929f73f.pdf
Other Info: Existing behaviour detection of the ransomware (launching files, visible windows, etc.).
Artificial Neural Networks (ANN)
Version Info: 1.5+
Link: https://filestore.fortinet.com/fortiguard/downloads/FortiAI%20Darkside%20VSA%20report_%20b278d7ec3681df16a541cf9e34d3b70a.pdf
Other Info: Neural network / AI-based detection detects the ransomware.
FortiGuard Botnet C&C (FortiGate)
FortiGuard Botnet Domain (FortiClient)
Version
Info: 4.693
Link: https://www.fortiguard.com/learnmore#botnet
Other Info: Detects & Blocks traffic to known C&C domains
FortiAnalyer and FortiSIEM
Version Info: 0.01868
Link: https://www.fortiguard.com/updates/ioc?version=0.01868
Other Info: Detected by FortiGuard IOC for post event analysis
FortiAnalyzer Event Hanlders & Reports
Version Info: 6.2+
Link: https://kb.fortinet.com/kb/microsites/microsite.do?cmd=displayKC&docType=kc&externalId=FD52270
Other Info: Detects indicators attributed to the ransomware from Fabric products.
FortiSIEM Rules & Reports
Version Info: 6.x+
Link: https://kb.fortinet.com/kb/microsites/microsite.do?cmd=displayKC&docType=kc&externalId=FD52277
Other Info: Detects indicators attributed to the ransomware from Fabric products and 3rd party
products.
Detects indicators attributed to the ransomware from Fabric products and 3rd party products.
Use Decoys & Deception Lures (CACHE CREDENTIALS & SMB & RDP) to detect activities related to the DarkSide ransomware .