Files
elastic-detection-rules/rules/network
Samirbous 4fed99a667 [New] Suspicious FortiGate and Fortinet Logon rules (#5640)
* [New] Suspicious FortiGate Admin Logon rules

- First-Time FortiGate Administrator Login
- FortiGate Administrator Login from Multiple IP Addresses

* Update initial_access_fortigate_admin_login_multi_srcip.toml

* ++

* ++

* Create initial_access_newly_observed_frotinet_logon.toml

* Update initial_access_newly_observed_frotinet_logon.toml

* build schema and manifest for fortinet

* Update pyproject.toml

* Update initial_access_newly_observed_frotinet_logon.toml

* Revert "Update initial_access_newly_observed_frotinet_logon.toml"

This reverts commit 7b99828b9a.

* Revert "Update pyproject.toml"

This reverts commit 025daf566f.

* Revert "build schema and manifest for fortinet"

This reverts commit a6234164f8.

* ++

(cherry picked from commit a2c1dd8575)
2026-01-28 18:00:25 +00:00
..