LoFP LoFP / an address could be added or deleted for legitimate purposes.

Techniques

Sample rules

FortiGate - Firewall Address Object Added

Description

Detects the addition of firewall address objects on a Fortinet FortiGate Firewall.

Detection logic

condition: selection
selection:
  action: Add
  cfgpath: firewall.address