Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

1 detection

Detects post-exploitation activities associated with FortiMail vulnerability CVE-2026-104286 (FG-IR-26-175). The rule identifies potential unauthorized persistence and data exfiltration, including the creation or modification of archive accounts with remote destinations, execution of 'migadmin' via root cron, and specific admin logout anomalies.
avatar
Tim Peck@timpeck
avatar
Detections.ai Community
9 hours ago
1038