FortiGate: Administrator Account Added via System Admin Event
Alerts on FortiGate events that add a new administrator account in system.admin.
FreeUnreviewedSigmamediumv1
fortigate-administrator-account-added-via-system-admin-event-cd0a4943
title: "FortiGate: Administrator Account Added via System Admin Event"
id: 52c6480b-f92e-43b8-8b51-b45e82abfc5c
status: experimental
description: This rule flags FortiGate event records where an administrator account is added under the system.admin configuration path. Creating or modifying admin accounts is a common persistence technique because it can grant continued privileged access even after other changes are detected. The detection relies on FortiGate event telemetry indicating the action type "Add" and the affected configuration path "system.admin".
references:
- https://www.fortiguard.com/psirt/FG-IR-24-535
- https://docs.fortinet.com/document/fortigate/7.6.4/fortios-log-message-reference/398/event
- https://docs.fortinet.com/document/fortigate/7.6.4/cli-reference/390485493/config-system-admin
- https://docs.fortinet.com/document/fortigate/7.6.4/fortios-log-message-reference/44547/44547-logid-event-config-objattr
- https://github.com/SigmaHQ/sigma/blob/master/rules/network/fortinet/fortigate/fortinet_fortigate_new_admin_account_created.yml
author: Marco Pedrinazzi (@pedrinazziM) (InTheCyber), Huntrule Team
date: 2025-11-01
tags:
- attack.persistence
- attack.t1136.001
logsource:
product: fortigate
service: event
detection:
selection:
action: Add
cfgpath: system.admin
condition: selection
falsepositives:
- An administrator account can be created for legitimate purposes. Investigate the account details to determine if it is authorized.
level: medium
license: DRL-1.1
related:
- id: cd0a4943-0edd-42cf-b50c-06f77a10d4c1
type: derived
What it detects
This rule flags FortiGate event records where an administrator account is added under the system.admin configuration path. Creating or modifying admin accounts is a common persistence technique because it can grant continued privileged access even after other changes are detected. The detection relies on FortiGate event telemetry indicating the action type "Add" and the affected configuration path "system.admin".
Known false positives
- An administrator account can be created for legitimate purposes. Investigate the account details to determine if it is authorized.
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.