Synacktiv high experimental sigma
CVE-2023-42791 | CVE-2024-23666 - Remote Code Execution On FortiManager
Exploitation script dropping a reverse shell or creating a new admin user via a low-privilege user
Detection Logic
{
"type": "temporal",
"rules": [
"be1e0ec6-9cf8-49ba-aec0-fe380c74a23b",
"f4f2111e-ff70-4b1b-a452-fce8632df20e",
"f2e3749a-7d26-4c86-bec1-1da24cad99f6",
"99a0e638-9046-49a1-b032-124051a1bbe7"
],
"timespan": "2m"
} False Positives
- ⚠ Legitimate administrative actions by high-privilege users not in the filter
Field Validations
Loading…
Comments (0)
Loading comments...