mirror of
https://github.com/elastic/detection-rules
synced 2026-06-08 14:00:08 +00:00
a95f95ef49
* initial FG-IR-26-060 rules
* adjusted investigation guides to proper formatting
* Update initial_access_fortigate_sso_login_from_unusual_source.toml
* Update and rename exfiltration_fortigate_config_download.toml to collection_fortigate_config_download.toml
* Update collection_fortigate_config_download.toml
* Apply suggestion from @Samirbous
Co-authored-by: Samirbous <64742097+Samirbous@users.noreply.github.com>
* Apply suggestion from @Samirbous
Co-authored-by: Samirbous <64742097+Samirbous@users.noreply.github.com>
* Apply suggestion from @Samirbous
Co-authored-by: Samirbous <64742097+Samirbous@users.noreply.github.com>
* Apply suggestion from @Samirbous
Co-authored-by: Samirbous <64742097+Samirbous@users.noreply.github.com>
* adjusting rules
* revert super admin
* adjusted source.ip to 'fortinet.firewall.ui'
* changing ESQL to EQL for non-aggregate queries
* added CISA reference
* adjusted interval and maxspan
* updating dates
* changed download rule to EQL
* added additional sso checks; linted previous rules
---------
Co-authored-by: Samirbous <64742097+Samirbous@users.noreply.github.com>
(cherry picked from commit ae88c095e9)