FortiEDR / FortiXDR
Endpoint detection and response that blocks at execution, not after
Compare all 2 models
Figures are Fortinet’s own, sortable, cited on every product pageHow to read these numbers
FortiEDR's distinguishing behaviour is that it blocks malicious activity at the moment of execution rather than detecting it and raising an alert for someone to action later. For ransomware, where the window between execution and encryption is seconds, that difference is the whole product.
More on choosing within this range
It runs pre-execution prevention and post-execution detection together, and can neutralise a threat while leaving the machine online, which matters when the machine is a clinical workstation or a production controller you cannot simply isolate.
FortiXDR extends the same telemetry across network, email and cloud so a detection arrives with the context needed to adjudicate it.
Before you order
How many endpoints, and what operating systems?
Licensing is per endpoint. Legacy and embedded systems, the ones that cannot be patched and most need compensating controls, need explicit checking against the supported list.
Do you have a SOC to respond?
EDR generates detections that need adjudication. If you have no 24/7 capacity, buy it as a managed service, ours or Fortinet's, rather than leaving a console nobody opens.
EDR or XDR?
EDR if you need endpoint coverage now. XDR if you have the other Fabric telemetry to correlate and the team to use it.
What are you replacing?
If it is traditional signature antivirus, the upgrade is substantial. If it is a modern EDR, the comparison is narrower and we will be straight with you about it.