Fortinet white logo
Fortinet white logo

Feature details

Feature details

The following table shows the available agent features.

To determine which features are supported for your platform and agent version, see Agent support matrix for version 7.10 and later.

Feature Description

RiskWatch

Detects vulnerabilities in active packages that have been exploited on the machine.

Connection telemetry

Tracks inbound and outbound TCP and UDP connections.
Process telemetry Scans running process to detect potential vulnerabilities.

Package telemetry

Detects vulnerabilities in installed packages. This feature includes active package detection.

DNS telemetry Monitors DNS traffic for malicious behavior.

Resource limits

Limits agent CPU and memory usage by setting resource limits.

File integrity monitoring

Monitors files and directories for changes, allowing users to detect unauthorized modifications, tampering, and potential security breaches

UserLookup

Identifies suspicious logins where a succesfull SSH or RDP login follows one or more failed attempts from the same IP address.

For more information about these features, see the Agent-based workload security in the Lacework FortiCNAPP Administration Guide.

Feature details

Feature details

The following table shows the available agent features.

To determine which features are supported for your platform and agent version, see Agent support matrix for version 7.10 and later.

Feature Description

RiskWatch

Detects vulnerabilities in active packages that have been exploited on the machine.

Connection telemetry

Tracks inbound and outbound TCP and UDP connections.
Process telemetry Scans running process to detect potential vulnerabilities.

Package telemetry

Detects vulnerabilities in installed packages. This feature includes active package detection.

DNS telemetry Monitors DNS traffic for malicious behavior.

Resource limits

Limits agent CPU and memory usage by setting resource limits.

File integrity monitoring

Monitors files and directories for changes, allowing users to detect unauthorized modifications, tampering, and potential security breaches

UserLookup

Identifies suspicious logins where a succesfull SSH or RDP login follows one or more failed attempts from the same IP address.

For more information about these features, see the Agent-based workload security in the Lacework FortiCNAPP Administration Guide.