Troubleshooting Tip: How to resolve web shell attacks not being detected by FortiWeb
Description
This article describes a scenario where a web shell attack is not detected by FortiWeb and provides steps to resolve the issue. In this situation, the attack may not be blocked and can appear in the logs as normal traffic.
Scope
FortiWeb.
Solution
To resolve this issue, follow the steps below:
Enable the relevant Generic Attacks signature and set its action to Alert_Deny in the Web Protection Profile.
Navigate to Web Protection Profile -> Signatures -> Generic Attacks, then select Alert_Deny as the action.

Ensure that the Web Protection Profile is assigned to the appropriate Server Policy. Navigate to Server Policy -> Web Protection Profile, then select the relevant profile.
Reproduce the issue in the environment to verify whether the attack is now detected and blocked by FortiWeb.

Review the attack logs to confirm that the attack traffic is being blocked by FortiWeb.

If the issue persists, create a new technical support ticket and provide the following information for further troubleshooting: a configuration backup file from System -> Maintenance -> Backup & Restore -> Backup entire configuration, the name of the relevant server policy and Web Protection Profile, filtered traffic and attack logs, and the output of the following CLI command:
get system status
To create a technical support ticket on the FortiCloud portal, see Creating tickets.
Related document:
Known Attacks
