FortiRecon
Your attack surface and brand, seen the way an attacker sees them
- Licensing
- Subscription by organisation and monitored assets
- Modules
- EASM, brand protection, adversary-centric intelligence
- Delivery
- SaaS with analyst-curated findings
FortiRecon covers external attack surface management, brand protection and adversary-centric intelligence, exposed assets you forgot you owned, credentials for sale, typosquatted domains, leaked code, and chatter naming you specifically.
Where it fits, and where it stops fitting
Its most common early value is simply finding infrastructure nobody on the team knew was still running. If you cannot produce a complete list of your external footprint, and almost nobody can; that is the argument for the product.
Highlights
- Finds shadow IT and forgotten cloud infrastructure
- Monitors for leaked credentials and source code
- Detects typosquatted and impersonating domains
- Analyst-curated rather than raw feed noise
Typical deployments
- Building an accurate external asset inventory
- Detecting brand impersonation targeting your customers
- Early warning that credentials have been exposed
What to work out first
FortiRecon looks at your organisation the way an attacker does: exposed assets you forgot you owned, credentials for sale, typosquatted domains, leaked code and data, and chatter naming you specifically.
It covers three areas, external attack surface management, brand protection, and adversary-centric intelligence, and its most common early value is simply finding infrastructure nobody on the team knew was still running.
Questions worth answering before you order
Do you know your full external footprint?
Almost nobody does. Shadow IT, acquisitions and forgotten cloud accounts accumulate. If you cannot produce the list, that is the argument for the product.
Is brand abuse a real problem for you?
Consumer-facing brands, financial services and anything with a login page get impersonated. B2B firms with no consumer login usually get less value here.
Who acts on the findings?
Findings need takedown requests, asset decommissioning and credential resets. Without an owner the reports pile up unread.
What this includes
Fortinet publishes no throughput table for this product; it is licensed per user, endpoint, workload or account. What follows is capability and sizing, not benchmarks.
What you are buying
| Licensing | Subscription by organisation and monitored assets |
|---|---|
| Modules | EASM, brand protection, adversary-centric intelligence |
| Delivery | SaaS with analyst-curated findings |
How this is sized
Fortinet licenses this product per user, endpoint, workload or account rather than by appliance throughput, so there is no comparable performance table to publish. We size it from your actual environment, tell us the numbers and we will work it through with you.
| Licensing | Subscription by organisation and monitored assets |
|---|
Sources
- Fortinet product line overview, retrieved 2026-09-01
Reproduced from Fortinet published documentation and subject to change without notice. Where a figure is load-bearing for your design, ask us to confirm it in writing before you order; we will.