LoFP LoFP / a firewall policy can be added for legitimate purposes.

Techniques

Sample rules

FortiGate - New Firewall Policy Added

Description

Detects the addition of a new firewall policy on a Fortinet FortiGate Firewall.

Detection logic

condition: selection
selection:
  action: Add
  cfgpath: firewall.policy