Technical Tip: Using FortiSIEM to detect activities related to Active Directory privilege escalation vulnerabilities
- February 11, 2022
- 0 replies
- 1610 views
| Description | This article describes how to use custom Rules and Reports to raise alerts for incident response related presence of Active Directory elevation of privilege vulnerabilities.
This escalation attack allows attackers to elevate their privilege to a Domain Admin once they compromise a regular user in the domain. This vulnerability is assigned CVE-2021-42278 and CVE-2021-42287.
For more information about this attack, see the following FortiGuard Outbreak Alert FortiGuard Outbreak Alert - AD Privilege Escalation.
What is included in Fortinet_FortiSIEM_AD_Priv_Esc_v1.zip?
2) FortiSIEM_AD_Priv_Esc_Reports_v1.xml This report displays the findings on the Active Directory privilege escalation outbreak from FortiClient and FortiGate IPS logs. |
| Scope | The custom Rules and Reports provided can be used in FortiSIEM 6.x. |
| Solution | 1) Download the Fortinet_FortiSIEM_AD_Priv_Esc_v1.zip file (contains 2 file).
2) Unzip Fortinet_FortiSIEM_AD_Priv_Esc_v1.zip
3) Use FortiSIEM_AD_Priv_Esc_Reports_v1.xml as the file to import the Reports
4) Use FortiSIEM_AD_Priv_Esc_Rules_v1.xml as the file to import the Rules |
