FortiGate event: Addition of VPN SSL Web Portal
Detects FortiGate configuration events where a VPN SSL web portal is added.
FreeUnreviewedSigmamediumv1
fortigate-event-addition-of-vpn-ssl-web-portal-2bfb6216
title: "FortiGate event: Addition of VPN SSL Web Portal"
id: 2cda79fa-b404-403f-acff-db1464a1165d
status: experimental
description: This rule alerts when a FortiGate configuration change adds a VPN SSL web portal. Adding a new web portal can help attackers establish new remote access paths or persist access by exposing an additional VPN entry point. The detection relies on FortiGate event telemetry indicating an "Add" action for the vpn.ssl.web.portal configuration path.
references:
- https://www.fortiguard.com/psirt/FG-IR-24-535
- https://docs.fortinet.com/document/fortigate/7.6.4/fortios-log-message-reference/398/event
- https://docs.fortinet.com/document/fortigate/7.6.4/cli-reference/113121765/config-vpn-ssl-web-portal
- https://docs.fortinet.com/document/fortigate/7.6.4/fortios-log-message-reference/44547/44547-logid-event-config-objattr
- https://github.com/SigmaHQ/sigma/blob/master/rules/network/fortinet/fortigate/fortinet_fortigate_new_vpn_ssl_web_portal.yml
author: Marco Pedrinazzi (@pedrinazziM) (InTheCyber), Huntrule Team
date: 2025-11-01
tags:
- attack.persistence
- attack.initial-access
- attack.t1133
logsource:
product: fortigate
service: event
detection:
selection:
action: Add
cfgpath: vpn.ssl.web.portal
condition: selection
falsepositives:
- A VPN SSL Web Portal can be added for legitimate purposes.
level: medium
license: DRL-1.1
related:
- id: 2bfb6216-0c31-4d20-8501-2629b29a3fa2
type: derived
What it detects
This rule alerts when a FortiGate configuration change adds a VPN SSL web portal. Adding a new web portal can help attackers establish new remote access paths or persist access by exposing an additional VPN entry point. The detection relies on FortiGate event telemetry indicating an "Add" action for the vpn.ssl.web.portal configuration path.
Known false positives
- A VPN SSL Web Portal can be added for legitimate purposes.
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.