FortiGate - Firewall Address Object Added
Detects the addition of firewall address objects on a Fortinet FortiGate Firewall.
Sigma rule (View on GitHub)
1title: FortiGate - Firewall Address Object Added
2id: 5c8d7b41-3812-432f-a0bb-4cfb7c31827e
3status: experimental
4description: Detects the addition of firewall address objects on a Fortinet FortiGate Firewall.
5references:
6 - https://www.fortiguard.com/psirt/FG-IR-24-535
7 - https://docs.fortinet.com/document/fortigate/7.6.4/fortios-log-message-reference/398/event
8 - https://docs.fortinet.com/document/fortigate/7.6.4/cli-reference/306021697/config-firewall-address
9 - https://docs.fortinet.com/document/fortigate/7.6.4/fortios-log-message-reference/44547/44547-logid-event-config-objattr
10author: Marco Pedrinazzi @pedrinazziM (InTheCyber)
11date: 2025-11-01
12tags:
13 - attack.defense-evasion
14 - attack.t1562
15logsource:
16 product: fortigate
17 service: event
18detection:
19 selection:
20 action: 'Add'
21 cfgpath: 'firewall.address'
22 condition: selection
23falsepositives:
24 - An address could be added or deleted for legitimate purposes.
25level: medium
References
Related rules
- FortiGate - New Firewall Policy Added
- WFP Filter Added via Registry
- ETW Logging Disabled For SCM
- ETW Logging Disabled For rpcrt4.dll
- ETW Logging Disabled In .NET Processes - Registry