FortiGate - Firewall Address Object Added

Detects the addition of firewall address objects on a Fortinet FortiGate Firewall.

Sigma rule (View on GitHub)

 1title: FortiGate - Firewall Address Object Added
 2id: 5c8d7b41-3812-432f-a0bb-4cfb7c31827e
 3status: experimental
 4description: Detects the addition of firewall address objects on a Fortinet FortiGate Firewall.
 5references:
 6    - https://www.fortiguard.com/psirt/FG-IR-24-535
 7    - https://docs.fortinet.com/document/fortigate/7.6.4/fortios-log-message-reference/398/event
 8    - https://docs.fortinet.com/document/fortigate/7.6.4/cli-reference/306021697/config-firewall-address
 9    - https://docs.fortinet.com/document/fortigate/7.6.4/fortios-log-message-reference/44547/44547-logid-event-config-objattr
10author: Marco Pedrinazzi @pedrinazziM (InTheCyber)
11date: 2025-11-01
12tags:
13    - attack.defense-evasion
14    - attack.t1562
15logsource:
16    product: fortigate
17    service: event
18detection:
19    selection:
20        action: 'Add'
21        cfgpath: 'firewall.address'
22    condition: selection
23falsepositives:
24    - An address could be added or deleted for legitimate purposes.
25level: medium

References

Related rules

to-top