FortiDeceptor
Decoys that produce near-zero-false-positive alerts
- Licensing
- By number of decoys and deployment scale
- Decoy types
- IT, OT/ICS, IoT and cloud decoys plus credential lures
- Deployment
- Virtual appliance with distributed decoy VMs
FortiDeceptor scatters believable decoy hosts, services and credentials through the network. Nothing legitimate ever touches them, so any interaction is an intruder, which makes its alerts among the highest-confidence signals available to a SOC.
Where it fits, and where it stops fitting
Unusually effective in OT, where decoys can imitate industrial protocols and controllers and where conventional endpoint tooling cannot be installed on the real assets. Decoy placement is the entire deployment: put them where lateral movement is likely and where they are plausible.
Highlights
- Near-zero false positives, nothing legitimate touches a decoy
- OT and ICS protocol decoys for industrial segments
- Credential lures detect harvesting attempts
- Ideal trigger for automated containment
Typical deployments
- Detection on an OT segment where agents cannot be deployed
- High-confidence trigger for automated isolation
- Early warning of lateral movement after initial access
What to work out first
FortiDeceptor scatters believable decoy hosts, services and credentials through the network. Nothing legitimate ever touches them, so any interaction is an intruder, which makes its alerts among the highest-confidence signals in a SOC.
It is unusually effective in OT environments, where decoys can imitate industrial protocols and controllers, and where conventional endpoint tooling cannot be installed on the real assets.
Questions worth answering before you order
Where would an attacker go?
Decoy placement is the entire deployment. Put them where lateral movement is likely and where they are plausible, a decoy nobody would ever probe generates nothing.
Do you need OT decoys?
If you run industrial control systems, protocol-aware decoys are a strong argument on their own; they give you detection on a segment where you may have none.
Will you act on the alerts?
These are the alerts most worth wiring to automated containment, because the false-positive rate is close to zero. That is a FortiSOAR or managed-SOC conversation.
What this includes
Fortinet publishes no throughput table for this product; it is licensed per user, endpoint, workload or account. What follows is capability and sizing, not benchmarks.
What you are buying
| Licensing | By number of decoys and deployment scale |
|---|---|
| Decoy types | IT, OT/ICS, IoT and cloud decoys plus credential lures |
| Deployment | Virtual appliance with distributed decoy VMs |
How this is sized
Fortinet licenses this product per user, endpoint, workload or account rather than by appliance throughput, so there is no comparable performance table to publish. We size it from your actual environment, tell us the numbers and we will work it through with you.
| Licensing | By number of decoys and deployment scale |
|---|
Sources
- Fortinet product line overview, retrieved 2026-09-01
Reproduced from Fortinet published documentation and subject to change without notice. Where a figure is load-bearing for your design, ask us to confirm it in writing before you order; we will.