CVE Exploitation Indicators on Network Appliance (3P)

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Content Index


Hunts for known CVE exploitation against 3P network appliances (Fortinet, Palo Alto, Ivanti, SonicWall, Citrix) in CommonSecurityLog - covers exploit URL paths, CVE mentions in logs, and FortiCloud SSO bypass + admin creation (FG-IR-26-060).

Attribute Value
Type Hunting Query
Solution Hybrid Attack - Cloud & Identity
ID e54511b5-f377-42d5-bf6b-9ab41fed938d
Tactics InitialAccess, Persistence, DefenseEvasion
Techniques T1190, T1133, T1136.001, T1070
Required Connectors CefAma
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Selection Criteria Transformations Ingestion API Lake-Only
CommonSecurityLog DeviceEventClassID == "0100044547"
DeviceProduct != "Cortex XDR"
DeviceProduct !has "ASM"
DeviceVendor == "Fortinet"

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Hunting Queries · Back to Hybrid Attack - Cloud & Identity