FortiGate: Administrator Account Added via system.admin Events

Alerts on FortiGate events that add a new administrator account in system.admin.

FreeReviewedSigma · Medium · v2
Product
fortigate
Service
event
Author
Marco Pedrinazzi (@pedrinazziM) (InTheCyber) (SigmaHQ), DRL 1.1
Published
2025-11-01
Updated
2026-07-31

ATT&CK techniques

Persistence
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule flags FortiGate event logs indicating an administrator account was added under the system.admin configuration path. Creating or modifying admin accounts is a common persistence technique, allowing an attacker to regain access after initial compromise. The detection relies on FortiGate event telemetry containing the account-creation action and the cfgpath value for system.admin.

Related detections9 linkedT1136.001 — drag to rearrange
Suspicious Local Account Creation via Net User in Pre-Ransomware Phase
Suspicious Hidden Local Account Creation via Net User by UAT-8099
Malicious Local Account Creation of Support or Whiteninja via net.exe
Malicious Dynamicweb Unauthenticated Administrator Creation via Setup Default.aspx (via webserver)
Suspicious Hidden Backdoor Account Creation Ending With Dollar Sign (via process_creation)
Malicious User Creation via Commandline (via process_creation)
Suspicious Local Account Creation and Privileged Group Addition via Net.EXE (via process_creation)
Suspicious Hidden Local Account Creation via Dscl (via process_creation)
Suspicious Local Account Creation on Linux (via process_creation)
FortiGate: Administrator Account Added via system.admin Events
Pivot detection · T1136.001 · 9 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.