FortiSandbox and FortiGuard Sandbox Services
Advanced threats can't be countered with traditional defenses. The FortiSandbox data sheet shows how AI-powered sandboxing helps detect and stop zero-day malware, ransomware, and phishing attacks in real time. Download your copy of the data sheet to learn how it improves detection accuracy, accelerates threat response, and extends protection across cloud, hybrid, IT, and OT environments.
How does FortiSandbox use AI to detect advanced and zero-day threats?
FortiSandbox 5.0 uses an advanced AI engine built on purpose‑built machine learning to identify, analyze, and prioritize new and evasive threats in real time.
Key points for security teams:
- AI-driven dual analysis: It combines Static AI Scan and Dynamic AI Scan:
- Static AI Scan processes up to 50 files per second, returning verdicts in milliseconds for known or clearly malicious content.
- If a file has active content (URLs, scripts, macros, executables) but no obvious static threats, it moves to Dynamic AI Scan, which detonates the file in an isolated VM and observes behavior in just a few seconds.
- Performance and throughput:
- Delivers about 10X effective throughput compared with traditional sandboxes.
- Provides 10X faster real-time verdicts, helping reduce exploit windows, downtime, and incident handling time.
- In production, most files are scanned in under one second, with a typical median scan time of around 4–5 seconds.
- Detection quality:
- Offers roughly 3X improved detection and accuracy versus earlier versions, with near-zero false positives.
- Trained daily on thousands of new malware samples across multiple file types.
- Each AI model is validated for about two weeks before deployment to ensure reliability.
- Coverage across the attack surface: Protects Cloud, IT, Edge, hybrid, and OT environments, including zero-day malware, AI-powered threats, and zero-day phishing (via real-time URL and web page analysis in the FortiGuard cloud).
For SOC and IR teams, FortiSandbox also provides a single pane of glass for threat visibility and detailed MITRE ATT&CK–aligned reports, including IOCs in STIX 2.0 format, packet captures, logs, screenshots, and optional video recordings of malware behavior.
Will sandboxing slow down my network, email, or endpoints?
FortiSandbox is designed to reimagine sandboxing performance so you can add strong detection without creating bottlenecks.
Here is how it addresses speed and user experience:
- Engineered for real-time workflows:
- Static AI Scan can handle up to 50 files per second and returns verdicts in milliseconds for most submissions.
- Only a small subset of suspicious files move to Dynamic AI Scan for deeper behavioral analysis.
- Measured performance in practice:
- In a recent four-hour window, FortiSandbox scanned over 3,000 files and URLs.
- Only 8 items (about 0.3%) required the more time-intensive dynamic analysis.
- The median total processing time was about 4 seconds, with an average of 13 seconds for the full set.
- In well-resourced environments, most files complete in under one second.
- Inline protection without visible slowdown:
- Network, email, and endpoint solutions can safely hold files during analysis while staying within acceptable latency thresholds.
- FortiGate NGFW, FortiMail, FortiClient/FortiEDR, and FortiProxy can all use FortiSandbox verdicts to block or release content in real time.
- Scalable architecture:
- Up to 10X effective throughput over traditional sandboxes.
- Clustering support for up to 99 worker nodes to expand capacity.
- 3X more universal VMs for flexible scaling across local, cloud, or custom VM types and OSs.
The net result is that sandboxing no longer has to be a trade-off between security and performance. FortiSandbox is built so that high detection efficacy and high throughput can coexist in production environments.
How does FortiSandbox fit into our existing security stack and compliance needs?
FortiSandbox is designed to fit into and enhance your existing security stack while supporting a range of regulatory and assurance requirements.
1. Integration across your environment
- Fortinet Security Fabric integration:
- NGFW (FortiGate): Inline blocking of advanced threats at the perimeter (HTTP, FTP, SMTP and SSL-encrypted equivalents). Suspicious files are sent to FortiSandbox; malicious verdicts trigger immediate blocking or quarantine.
- Secure Email Gateway (FortiMail): Scans attachments and URLs to stop phishing, malware, and ransomware before they reach inboxes.
- Endpoint (FortiClient, FortiEDR): Unknown files are forwarded for analysis; malicious verdicts can kill processes, isolate hosts, and share IOCs across endpoints.
- Web Proxy (FortiProxy) and FortiWeb: Deep analysis of downloads, scripts, and web traffic to block zero-day malware and drive-by attacks.
- Shared storage: Scans SMB/NFS shares, OneDrive, AWS S3, Azure Blob, Google Cloud Storage, and other repositories to reduce lateral movement and insider risk.
- Analytics and SOAR: FortiAnalyzer, FortiSIEM, and FortiSOAR consume FortiSandbox IOCs and telemetry for correlation, alerting, and automated response.
- Third-party ecosystems:
- Supports ICAP and RESTful JSON APIs to integrate with non-Fortinet NGFWs, proxies, SIEMs, and email gateways.
- Enables “sandbox-as-a-service” for external products that need advanced malware analysis.
2. Deployment flexibility
- Available on-premises, virtualized, in public cloud, or as SaaS.
- Universal VM licensing lets you choose any local, cloud, or custom VM type and OS, decoupling VM licenses from OS licenses to simplify management.
- Supports air-gapped networks, OT protocols (e.g., BACnet, Modbus, S7comm), and high-availability clustering.
3. Compliance and assurance
- NIAP / Common Criteria: FortiSandbox G Series is listed on the NIAP Product Compliant List (PCL) as product 11636, supporting U.S. government, defense, and critical infrastructure requirements for high-assurance solutions.
- HIPAA: FortiSandbox is HIPAA-compliant, aligning with strict controls for protected health information (PHI) and supporting secure handling and analysis of healthcare data.
- SOC 2: SOC 2 certification validates its security, availability, and confidentiality controls, giving assurance around data protection and operational reliability.
- Regulatory frameworks: Sandboxing capabilities help address expectations in standards and regulations such as PCI DSS v4.0, EU NIS2, NIST CSF v2.0, Japan METI/IPA, and others that call for advanced malware detection, behavior-based analysis, and risk-based cybersecurity.
In practice, this means you can plug FortiSandbox into your current stack to strengthen detection, automate response, and support compliance without redesigning your entire architecture.

