fortiproxy.exe

by Fortinet
Endpoint Security

Summary

FortiProxy is a component of Fortinet's FortiClient endpoint protection suite. It handles web filtering and proxy functionality for the FortiClient agent, intercepting and inspecting web traffic for security policy enforcement.

fortiproxy.exe is the 33rd most commonly executed Windows program in EchoTrail's dataset, observed 1,237,660 times across enterprise environments. It typically runs from C:\Program Files (x86)\Fortinet\FortiClient.

33rd
most commonly executed Windows program
1,237,660
observed executions
high
statistical confidence

Behavior

Top Paths

  • C:\Program Files (x86)\Fortinet\FortiClient100%

Top Hashes (SHA256)

  • 1bf076c2786f20423c6c50351d66c55a1d3d4f0d56bdeaa50051bbf2d3f8bced46.36%
  • 4b198372985a831c066034f9a7b9ac3875d08cc4b546937ce3b8cc6e3fbcc83522.01%
  • f10722045833366489597bb4925331df9170df354529162e6da9c2e7e4ccd33518.73%
  • 60c7aee91141d316128832f04f47b4e9ab6622d660025bb4779d25f8350eca5d8.81%
  • b28821d75000e8565057aad79aa2322c5484194dad2c479f53ad778e71760c9e4.08%

Process Ancestry

Top Grandparents

Rare or environment-specific process names are omitted from ancestry tables. Percentages are of all observed relationships.

Security Analysis

What does fortiproxy.exe normally do?

Located in C:\Program Files (x86)\Fortinet\FortiClient. Always launched by scheduler.exe (FortiClient scheduler component). Single instance.

When is fortiproxy.exe suspicious?

Running from outside the FortiClient directory. Parent process other than the FortiClient scheduler.

How do attackers abuse fortiproxy.exe?

Not a target for direct abuse. As a security product component, if compromised it could be used to intercept or modify network traffic.

Detection guidance

No detection needed. Presence indicates FortiClient endpoint protection.

False positive notes

Normal FortiClient operation.

Related Processes

Ask Rocky about fortiproxy.exe

Rocky answers questions about fortiproxy.exe grounded in this same dataset — free, no account needed.

Need this data programmatically? The Rocky API includes 500 free lookups a month. Or just ask Rocky.

Data from EchoTrail's dataset of ~346M Windows process executions. Last extracted 2026-08-04.