Skip to main content
FSM_FTNT
Staff
Staff
February 11, 2022

Technical Tip: Using FortiSIEM to detect activities related to Active Directory privilege escalation vulnerabilities

  • February 11, 2022
  • 0 replies
  • 1610 views
Description

This article describes how to use custom Rules and Reports

to raise alerts for incident response related presence of Active Directory elevation of privilege vulnerabilities.

 

This escalation attack allows attackers to elevate their privilege to a Domain Admin once they compromise a regular user in the domain.

This vulnerability is assigned CVE-2021-42278 and CVE-2021-42287.

 

For more information about this attack, see the following FortiGuard Outbreak Alert FortiGuard Outbreak Alert - AD Privilege Escalation.

 

What is included in Fortinet_FortiSIEM_AD_Priv_Esc_v1.zip?


1) FortiSIEM_AD_Priv_Esc_Rules_v1.xml


These Rules help identify Active Directory privilege escalation exploit attempts detected in FortiClient and FortiGate IPS logs.

 

2) FortiSIEM_AD_Priv_Esc_Reports_v1.xml

 

This report displays the findings on the Active Directory privilege escalation outbreak from FortiClient and FortiGate IPS logs.
Scope The custom Rules and Reports provided can be used in FortiSIEM 6.x.
Solution

1) Download the Fortinet_FortiSIEM_AD_Priv_Esc_v1.zip file (contains 2 file).

 

2) Unzip Fortinet_FortiSIEM_AD_Priv_Esc_v1.zip

 

3) Use FortiSIEM_AD_Priv_Esc_Reports_v1.xml as the file to import the Reports
- Navigate to Resource / Reports.
- It is recommended to create a new group under Resource / Reports / Security called 'AD Privilege Escalation' and import reports to this group.
- Select the Import option under More.
- Select FortiSIEM_AD_Priv_Esc_Reports_v1.xml and import.

 

4) Use FortiSIEM_AD_Priv_Esc_Rules_v1.xml as the file to import the Rules
- Navigate to Resource / Rules.
- It is recommended to create a new group under Resource / Rules / Security / Threat Hunting is created called 'AD Privilege Escalation' and import the rules to this group.
- Select the Import.
- Select FortiSIEM_AD_Priv_Esc_Rules_v1.xml and import.
- Filter the rules for those defined in content pack 101 and ensure they are enabled.

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!