• CommunityEnterprisePlans
  • Intel Exchange
    Intel ExchangeDetections
  • Resources
  • About
  • Leaderboard
Join CommunitySign In
    All Detections

    T1098: FortiMail CLI Creation of Rogue Mail-Archive Account for Exfiltration

    avatar
    GlassDiceBearhttps://www.dicebear.comhttps://creativecommons.org/publicdomain/zero/1.0/„Glass” (https://www.dicebear.com) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)
    Tim Peck@timpeck
    •updated today•1•0•34

    Detects post-exploitation activities associated with FortiMail vulnerability CVE-2026-104286 (FG-IR-26-175). The rule identifies potential unauthorized persistence and data exfiltration, including the creation or modification of archive accounts with remote destinations, execution of 'migadmin' via root cron, and specific admin logout anomalies.

    YARA-L

    Tags

    T1505 - Server Software ComponentT1020 - Automated ExfiltrationT1114.002 - Remote Email CollectionTA0003 - PersistenceTA0010 - ExfiltrationTA0009 - CollectionApplication Configuration ChangeData ExfiltrationScheduled Task TriggeredAdmin ActivityFirmwareFortinet Fortigate FirewallCVE-2026-104286

    Found in

    • FortiMail Path Traversal Zero-Day Under Active ExploitationLast updated today
    • ShinyHunters Healthcare Identity Extortion and PeopleSoft ExploitationLast updated today

    Community Inspired.
    AI Enhanced.
    Better Detections.

    Follow Us

    Company

    • About
    • Leaderboard

    Product

    • Community
    • Enterprise
    • Plans

    © 2026 Copyright. All Rights Reserved.

    Privacy PolicyTerms of Service

    Sign up to view this detection

    or

    Already have an account?