Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
Hunts for known CVE exploitation against 3P network appliances (Fortinet, Palo Alto, Ivanti, SonicWall, Citrix) in CommonSecurityLog - covers exploit URL paths, CVE mentions in logs, and FortiCloud SSO bypass + admin creation (FG-IR-26-060).
| Attribute | Value |
|---|---|
| Type | Hunting Query |
| Solution | Hybrid Attack - Cloud & Identity |
| ID | e54511b5-f377-42d5-bf6b-9ab41fed938d |
| Tactics | InitialAccess, Persistence, DefenseEvasion |
| Techniques | T1190, T1133, T1136.001, T1070 |
| Required Connectors | CefAma |
| Source | View on GitHub |
This content item queries data from the following tables:
| Table | Selection Criteria | Transformations | Ingestion API | Lake-Only |
|---|---|---|---|---|
CommonSecurityLog |
DeviceEventClassID == "0100044547"DeviceProduct != "Cortex XDR"DeviceProduct !has "ASM"DeviceVendor == "Fortinet" |
✓ | ✓ | ✓ |
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
↑ Back to Hunting Queries · Back to Hybrid Attack - Cloud & Identity