mdecrevoisier high experimental sigma

Fortinet APT group abuse on Windows (task)

Detects scenarios where APT actors exploits Fortinet vulnerabilities to gain access into Windows infrastructure.

View Source

Detection Logic

{
  "selection": {
    "EventID": 4698,
    "TaskName
| endswith": "\\SynchronizeTimeZone"
  },
  "condition": "selection"
}

False Positives

  • None

Field Validations

Loading…

Comments (0)

Loading comments...