Playbook Connectors on Content Hub
Fleet-wide IP blocking with a FortiManager threat feed
Creates an IP threat feed on FortiManager and keeps it filled with malicious indicators raised by FortiNDR and FortiEDR alerts.
@ftnt-dspilleMaintainer v1.0.1 Platform 7.4.0+ Published Oct 6, 2026 Updated Oct 6, 2026
Download JSON · 55 KB
fortimanager-threat-feed-blocking-1.0.1.json
sha256:e3de212edf1565e6b12f194f7744f55951e2fe373c693e5d5a0277342f690234
Sanitized by the pipeline and shipped inactive. Follow the before turning it on.
Blocks malicious IPs across every FortiGate that a FortiManager manages, using an IP threat feed that FortiManager hosts.
- 00 Setup - Create FMG IP Threat Feed (run once): creates the resource file and the IP threat feed (external resource) in your ADOM, and stores the names in the global variable
FMG_Feed_Data. - Add entries to IP Threat feed: collects every indicator marked Malicious and writes the list into the feed file. FortiGates that reference the feed in a policy pick up the change on their next refresh.
- Triggers that feed it:
- Automated Block FortiNDR Destination IP: on a new FortiNDR Cloud alert, creates a malicious indicator for a public destination IP and updates the feed.
- Manual Block FortiNDR Destination IP: the same, from a button on the alert.
- Watch IOC's from FortiEDR: on a new FortiEDR alert (the example filter matches
powershell.exe, so adjust it), creates the indicator and updates the feed.
Needs the FortiManager JSON-RPC connector. Edit the ADOM, feed name and file name in the setup playbook's Set variables step, then reference the feed as an address in a FortiGate policy.
Something wrong with this item? Sign in to report