Elastic high stable eql
FortiGate SSO Login Followed by Administrator Account Creation
This rule detects a FortiCloud SSO login followed by administrator account creation on the same FortiGate device within 15 minutes. This sequence is a high-confidence indicator of the FG-IR-26-060 attack pattern, where threat actors authenticate via SAML-based SSO bypass and immediately create local administrator accounts for persistence.
Detection Logic
sequence by observer.name with maxspan=15m
[authentication where data_stream.dataset == "fortinet_fortigate.log" and
event.action == "login" and event.outcome == "success" and
(fortinet.firewall.method == "sso" or fortinet.firewall.ui like~ "sso*")]
[any where data_stream.dataset == "fortinet_fortigate.log" and
event.code == "0100044547" and
fortinet.firewall.cfgpath == "system.admin" and
fortinet.firewall.action == "Add"] Field Validations
Loading…
Comments (0)
Loading comments...