Platform / product
fortigate Sigma detection rules
7 community-maintained Sigma detection rules in the library target the fortigate platform. Browse by severity, inspect the detection logic and MITRE ATT&CK mapping, and open the original Sigma YAML before using a rule in your detection engineering workflow.
Severity
FortiGate - Firewall Address Object Added
mediumDetects the addition of firewall address objects on a Fortinet FortiGate Firewall.
fortigate · event
FortiGate - New Administrator Account Created
mediumDetects the creation of an administrator account on a Fortinet FortiGate Firewall.
fortigate · event
FortiGate - New Firewall Policy Added
mediumDetects the addition of a new firewall policy on a Fortinet FortiGate Firewall.
fortigate · event
FortiGate - New Local User Created
mediumDetects the creation of a new local user on a Fortinet FortiGate Firewall. The new local user could be used for VPN connections.
fortigate · event
FortiGate - New VPN SSL Web Portal Added
mediumDetects the addition of a VPN SSL Web Portal on a Fortinet FortiGate Firewall. This behavior was observed in pair with modification of VPN SSL settings.
fortigate · event
FortiGate - User Group Modified
mediumDetects the modification of a user group on a Fortinet FortiGate Firewall. The group could be used to grant VPN access to a network.
fortigate · event
FortiGate - VPN SSL Settings Modified
mediumDetects the modification of VPN SSL Settings (for example, the modification of authentication rules). This behavior was observed in pair with the addition of a VPN SSL Web Portal.
fortigate · event