FortiGate: Local User Added (user.local) via Event Logs

Alerts on FortiGate events where a new local user is added under user.local.

FreeUnreviewedSigmamediumv1
title: "FortiGate: Local User Added (user.local) via Event Logs"
id: 34651e05-6a4a-479a-adba-a1dcba62086a
status: experimental
description: This rule flags FortiGate event activity where a local user is added under the user.local configuration path. Attackers often create local accounts to establish persistent access, including potential use for VPN authentication. The detection relies on FortiGate event telemetry containing an action of Add and cfgpath matching user.local.
references:
  - https://www.fortiguard.com/psirt/FG-IR-24-535
  - https://docs.fortinet.com/document/fortigate/7.6.4/fortios-log-message-reference/398/event
  - https://docs.fortinet.com/document/fortigate/7.6.4/cli-reference/109120963/config-user-local
  - https://docs.fortinet.com/document/fortigate/7.6.4/fortios-log-message-reference/44547/44547-logid-event-config-objattr
  - https://github.com/SigmaHQ/sigma/blob/master/rules/network/fortinet/fortigate/fortinet_fortigate_new_local_user_created.yml
author: Marco Pedrinazzi (@pedrinazziM) (InTheCyber), Huntrule Team
date: 2025-11-01
tags:
  - attack.persistence
  - attack.t1136.001
logsource:
  product: fortigate
  service: event
detection:
  selection:
    action: Add
    cfgpath: user.local
  condition: selection
falsepositives:
  - A local user can be created for legitimate purposes. Investigate the user details to determine if it is authorized.
level: medium
license: DRL-1.1
related:
  - id: ddbbe845-1d74-43a8-8231-2156d180234d
    type: derived

What it detects

This rule flags FortiGate event activity where a local user is added under the user.local configuration path. Attackers often create local accounts to establish persistent access, including potential use for VPN authentication. The detection relies on FortiGate event telemetry containing an action of Add and cfgpath matching user.local.

Known false positives

  • A local user can be created for legitimate purposes. Investigate the user details to determine if it is authorized.

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.