StrikeShark Fortinet CVE-2022-40684 and CVE-2024-21762 Exploitation Attempt
Detects suspicious HTTP requests and API activity targeting Fortinet devices, specifically matching patterns associated with known vulnerabilities like CVE-2022-40684 and CVE-2024-21762. The rule monitors for unauthorized REST API calls, attempts to interact with sensitive administrative endpoints, and patterns indicating potential authentication bypass or remote code execution attempts on FortiGate, FortiOS, and FortiProxy appliances.
Microsoft Sentinel (KQL)

