mdecrevoisier high experimental sigma
Fortinet APT group abuse on Windows (user)
Detects scenarios where APT actors exploits Fortinet vulnerabilities to gain access into Windows infrastructure.
Detection Logic
{
"selection": {
"EventID": 4720,
"TargetUserName": [
"elie",
"WADGUtilityAccount"
]
},
"condition": "selection"
} False Positives
- ⚠ None
Field Validations
Loading…
Comments (0)
Loading comments...