Techniques
Sample rules
FortiGate - New Administrator Account Created
- source: sigma
- technicques:
- t1136
- t1136.001
Description
Detects the creation of an administrator account on a Fortinet FortiGate Firewall.
Detection logic
condition: selection
selection:
action: Add
cfgpath: system.admin