mdecrevoisier high experimental sigma

Fortinet APT group abuse on Windows (user)

Detects scenarios where APT actors exploits Fortinet vulnerabilities to gain access into Windows infrastructure.

View Source

Detection Logic

{
  "selection": {
    "EventID": 4720,
    "TargetUserName": [
      "elie",
      "WADGUtilityAccount"
    ]
  },
  "condition": "selection"
}

False Positives

  • None

Field Validations

Loading…

Comments (0)

Loading comments...