otelrules.azureedge.net flagged as IOC on FortiGate / FortiAnalyzer
Hi,
The last few days we are experiencing mass endpoint quarantines because otelrules.azureedge.net is flagged as an indicator of compromise on our Fortigates / FortiAnalyzer.
otelrules.azureedge.net is number 92 on the required urls for Office 365 to function according to:
Office 365 URLs and IP address ranges - Microsoft 365 Enterprise | Microsoft Learn
Are there any other people / companies who experience the same, or is it something for only us?
Detection patern reads:
[{"wf_cate":"Information Technology","av_cate":"","spam_cates":[],"ioc_cate":"","ioc_tags":[],"confidence":"Low","reference_url":"https://ioc.fortiguard.com/search?query=otelrules.azureedge.net&filter=indicator","kill_chain_phases":["command-and-control"],"created":"2024-01-16T01:16:38Z","modified":"2024-01-16T06:29:53Z","malware_name":"","reportFasleIoc":true,"hideMiscellaneous":true,"tdpattern":"otelrules.azureedge.net","iocTitle":"Detect Pattern","iocDesc":"otelrules.azureedge.net"}]
