LoFP LoFP / an administrator account can be created for legitimate purposes. investigate the account details to determine if it is authorized.

Techniques

Sample rules

FortiGate - New Administrator Account Created

Description

Detects the creation of an administrator account on a Fortinet FortiGate Firewall.

Detection logic

condition: selection
selection:
  action: Add
  cfgpath: system.admin