Sagan informational stable other

[FORTINET] UTM dns Event Detected - Suspicious Traffic [250/2hours]

[FORTINET] UTM dns Event Detected - Suspicious Traffic [250/2hours]

View Source

Detection Logic

alert any $HOME_NET any -> $HOME_NET any (msg:"[FORTINET] UTM dns Event Detected - Suspicious Traffic [250/2hours]"; content:" type=
| 22
| utm
| 22
| "; content:" subtype=
| 22
| dns
| 22
| "; meta_content:"catdesc=
| 22
| %sagan%",File
| 20
| Sharing
| 20
| and
| 20
| Storage,Remote
| 20
| Access,Child
| 20
| Sexual
| 20
| Abuse,Crypto
| 20
| Mining,Hacking,Terrorism,Potentially
| 20
| Unwanted
| 20
| Program,Dynamic
| 20
| DNS,Malicious
| 20
| Websites,Newly
| 20
| Observed
| 20
| Domain,Newly
| 20
| Registered
| 20
| Domain,Phishing,Spam
| 20
| URLs,Unrated,Not
| 20
| Rated; content:!"severity=low"; content:!"level=
| 22
| notice
| 22
| "; content:!".live.net"; content:!"oneclient.sfx.ms"; content:!".delivery.mp.microsoft.com"; content:!"icloud.com"; meta_content:!"%sagan%",
| 2e
| local,
| 2e
| internal,wpad
| 2e
| ; parse_src_ip:2; parse_dst_ip:3; after:track by_src,count 250, seconds 7200; threshold:type suppress, track by_src, count 1, seconds 86400; content:"- - - -"; classtype:system-event; reference:url,https://fortinetweb.s3.amazonaws.com/docs.fortinet.com/v2/attachments/efa7b0eb-45bc-11ee-8e6d-fa163e15d75b/FortiOS_7.4.1_Log_Reference.pdf; sid:5017308; rev:2; metadata:updated_at 2025_12_23;)

Field Validations

Loading…

Comments (0)

Loading comments...