Fortinet

Telemetry Evidence

These values show how indexed rules identify Fortinet telemetry.

Elastic

  • Index logs-fortinet_fortigate.* (1 rule)
  • Index logs-fortinet_fortigate.log-* (3 rules)
  • Integration fortinet_fortigate (9 rules)

Kusto

  • Queried source table Fortiweb (1 rule)

Sigma

  • Log-source product fortigate (7 rules)
  • Log-source product fortios (1 rule)

Detection Rules

Elastic #

  • Accepted Default Telnet Port Connection source medium: This rule detects network events that may indicate the use of Telnet traffic. Telnet is commonly used by system administrators to remotely control older or embedded systems using the command line shell. It should almost never be directly exposed to the Internet, as it is frequently targeted and exploited by threat actors as an initial access or backdoor vector. As a plain-text protocol, it may also expose usernames and passwords to anyone capable of observing the traffic.T1021, T1071, T1133, T1190
  • Elastic Defend and Network Security Alerts Correlation source high: This rule correlate any Elastic Defend alert with a set of suspicious events from Network security devices like Palo Alto Networks (PANW) and Fortinet Fortigate by host.ip and source.ip. This may indicate that this host is compromised and triggering multi-datasource alerts.
  • First-Time FortiGate Administrator Login source high: This rule detects the first observed successful login of a user with the Administrator role to the FortiGate management interface within the last 5 days. First-time administrator logins can indicate newly provisioned accounts, misconfigurations, or unauthorized access using valid credentials and should be reviewed promptly.T1078
  • FortiGate Administrator Login from Multiple IP Addresses source high: This rule detects successful logins to the FortiGate management interface using the same Administrator account from multiple distinct source IP addresses within an 24-hour period. Administrator logins from multiple locations in a short time window may indicate credential sharing, compromised credentials, or unauthorized access and should be investigated.T1078
  • FortiGate FortiCloud SSO Login from Unusual Source source medium: This rule detects the first successful FortiCloud SSO login from a previously unseen source IP address to a FortiGate device within the last 5 days. FortiCloud SSO logins from new source IPs may indicate exploitation of SAML-based authentication bypass vulnerabilities such as CVE-2026-24858, where crafted SAML assertions allow unauthorized access to FortiGate devices registered to other accounts. Environments that regularly use FortiCloud SSO will only alert on new source IPs not seen in the lookback window.T1078, T1078.004, T1190, T1606, T1606.002
  • FortiGate SOCKS Traffic from an Unusual Process source medium: This detection correlates FortiGate's application control SOCKS events with Elastic Defend network event to identify the source process performing SOCKS traffic. Adversaries may use a connection proxy to direct network traffic between systems or act as an intermediary for network communications to a command and control server to avoid direct connections to their infrastructure.T1090
  • FortiGate SSL VPN Login Followed by SIEM Alert by User source medium: Detects when a FortiGate SSL VPN login event is followed by any SIEM detection alert for the same user name within a short time window. This correlation can indicate abuse of VPN access for malicious activity, credential compromise used from a VPN session, or initial access via VPN followed by post-compromise behavior.T1078
  • Newly Observed FortiGate Alert source critical: This rule detects FortiGate alerts that are observed for the first time in the previous 5 days of alert history. Analysts can use this to prioritize triage and response.
  • React2Shell Network Security Alert source high: This rule identifies network security alerts related to CVE-2025-55182 exploitation attempts from different network security integrations. CVE-2025-55182 is a critical remote code execution vulnerability in React Server Components (RSC) Flight protocol. The vulnerability allows attackers to execute arbitrary code on the server by sending specially crafted deserialization payloads that exploit prototype chain traversal to access the Function constructor.T1059, T1059.007, T1190

Kusto #

Sigma #

Compatible Rules

These rules declare Fortinet connector or schema compatibility without a product-specific query filter.

Kusto #