FortiGate event: Addition of VPN SSL Web Portal

Detects FortiGate configuration events where a VPN SSL web portal is added.

FreeUnreviewedSigmamediumv1
title: "FortiGate event: Addition of VPN SSL Web Portal"
id: 2cda79fa-b404-403f-acff-db1464a1165d
status: experimental
description: This rule alerts when a FortiGate configuration change adds a VPN SSL web portal. Adding a new web portal can help attackers establish new remote access paths or persist access by exposing an additional VPN entry point. The detection relies on FortiGate event telemetry indicating an "Add" action for the vpn.ssl.web.portal configuration path.
references:
  - https://www.fortiguard.com/psirt/FG-IR-24-535
  - https://docs.fortinet.com/document/fortigate/7.6.4/fortios-log-message-reference/398/event
  - https://docs.fortinet.com/document/fortigate/7.6.4/cli-reference/113121765/config-vpn-ssl-web-portal
  - https://docs.fortinet.com/document/fortigate/7.6.4/fortios-log-message-reference/44547/44547-logid-event-config-objattr
  - https://github.com/SigmaHQ/sigma/blob/master/rules/network/fortinet/fortigate/fortinet_fortigate_new_vpn_ssl_web_portal.yml
author: Marco Pedrinazzi (@pedrinazziM) (InTheCyber), Huntrule Team
date: 2025-11-01
tags:
  - attack.persistence
  - attack.initial-access
  - attack.t1133
logsource:
  product: fortigate
  service: event
detection:
  selection:
    action: Add
    cfgpath: vpn.ssl.web.portal
  condition: selection
falsepositives:
  - A VPN SSL Web Portal can be added for legitimate purposes.
level: medium
license: DRL-1.1
related:
  - id: 2bfb6216-0c31-4d20-8501-2629b29a3fa2
    type: derived

What it detects

This rule alerts when a FortiGate configuration change adds a VPN SSL web portal. Adding a new web portal can help attackers establish new remote access paths or persist access by exposing an additional VPN entry point. The detection relies on FortiGate event telemetry indicating an "Add" action for the vpn.ssl.web.portal configuration path.

Known false positives

  • A VPN SSL Web Portal can be added for legitimate purposes.

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.