FortiGate User Group Modified via Edit Event

Alerts on FortiGate user group edits that can change access permissions, including VPN-related group membership.

FreeReviewedSigma · Medium · v2
Product
fortigate
Service
event
Author
Marco Pedrinazzi (@pedrinazziM) (InTheCyber) (SigmaHQ), DRL 1.1
Published
2025-11-01
Updated
2026-07-31

What it detects

This rule identifies when a Fortinet FortiGate firewall user group is modified, indicated by an event action of "Edit" and targeting the "user.group" configuration path. Changing group definitions can allow an attacker to adjust access controls, including potential access such as VPN permissions. It relies on FortiGate event telemetry that records the configuration change action and affected config path.

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.