QuestionQ17

Events, forensics, and threat hunting

You need to configure a query that runs every 15 minutes and automatically searches all endpoints for specified registry modifications.

Which FortiEDR feature must be configured?

Explanation

FortiEDR Threat Hunting can search registry keys and values across the environment. Marking a saved threat-hunting query as a Scheduled Query makes it run automatically on the defined schedule, enabling recurring detection of matching registry modifications.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!