FortiGate - New Firewall Policy Added
Detects the addition of a new firewall policy on a Fortinet FortiGate Firewall.
Sigma rule (View on GitHub)
1title: FortiGate - New Firewall Policy Added
2id: f24ab7a8-f09a-4319-82c1-915586aa642b
3status: experimental
4description: Detects the addition of a new firewall policy on a Fortinet FortiGate Firewall.
5references:
6 - https://www.fortiguard.com/psirt/FG-IR-24-535
7 - https://docs.fortinet.com/document/fortigate/7.6.4/fortios-log-message-reference/398/event
8 - https://docs.fortinet.com/document/fortigate/7.6.4/cli-reference/333889629/config-firewall-policy
9 - https://docs.fortinet.com/document/fortigate/7.6.4/fortios-log-message-reference/44547/44547-logid-event-config-objattr
10author: Marco Pedrinazzi (@pedrinazziM) (InTheCyber)
11date: 2025-11-01
12modified: 2026-05-04
13tags:
14 - attack.defense-impairment
15 - attack.t1686.002
16logsource:
17 product: fortigate
18 service: event
19detection:
20 selection:
21 action: 'Add'
22 cfgpath: 'firewall.policy'
23 condition: selection
24falsepositives:
25 - A firewall policy can be added for legitimate purposes.
26level: medium
References
Related rules
- FortiGate - Firewall Address Object Added
- Windows Defender Disabled Via SystemSettingsAdminFlows.EXE
- HackTool - SysmonEnte Execution
- Potential Privileged System Service Operation - SeLoadDriverPrivilege
- Suspicious PROCEXP152.sys File Created In TMP