Synacktiv high experimental sigma

CVE-2023-42791 | CVE-2024-23666 - Remote Code Execution On FortiManager

Exploitation script dropping a reverse shell or creating a new admin user via a low-privilege user

View Source

Detection Logic

{
  "type": "temporal",
  "rules": [
    "be1e0ec6-9cf8-49ba-aec0-fe380c74a23b",
    "f4f2111e-ff70-4b1b-a452-fce8632df20e",
    "f2e3749a-7d26-4c86-bec1-1da24cad99f6",
    "99a0e638-9046-49a1-b032-124051a1bbe7"
  ],
  "timespan": "2m"
}

False Positives

  • Legitimate administrative actions by high-privilege users not in the filter

Field Validations

Loading…

Comments (0)

Loading comments...