Search and filter across all detection sources
16 rules
FortiManager Logout
User logout from FortiManager
FortiManager File Download
Download of a file on FortiManager
FortiManager FlatUI Login Success
Login Success via FlatUI on FortiManager
FortiManager FlatUI Upload Success
Upload Success via FlatUI on FortiManager
FortiManager Multiple Uploads
Multiple uploads to FortiManager in close temporality
FortiManager WebSocket Connection
A WebSocket connection successfully opened on FortiManager
FortiManager SSH Web Console Connection
SSH web console connection request via WebSocket on FortiManager
FortiManager Backup Method Call
Call to a backup method through the FlatUI proxy of FortiManager
FortiManager Low-privilege User Login Success
Successful login from a low-privilege user to FortiManager
FortiManager SSH Web Console Data Write
SSH web console data write via WebSocket on FortiManager
atexec-pro - Suspicious PowerShell script
Suspicious PowerShell script contents related to execution of atexec-pro remote execution tool
FortiManager Backup Success From Non-admin User
Successful system configuration backup of FortiManager from a non-admin user
atexec-pro - Suspicious PowerShell process creation
Suspicious PowerShell process creation where command line contents are related to execution of atexec-pro remote execution tool
CVE-2024-23666 - FortiManager SSH Web Console Exploitation Script
FortiManager SSH web console exploitation script simulating a shell on a FortiGate
CVE-2024-23666 - FortiManager Configuration Download By Low-Privilege User
Download by a low-privilege user of the full FortiManager system configuration containing information about all ADOM and managed equipments
CVE-2023-42791 | CVE-2024-23666 - Remote Code Execution On FortiManager
Exploitation script dropping a reverse shell or creating a new admin user via a low-privilege user