Good Morning,
There were post about the symbolic link vulnerability on Fortigate recently, the document mentioned the updated AV / IPS can remove the bad symbolic link.
I want to know if there is AV/ IPS event tell us, the bad symbolic link detected and has been removed ?
How to check if bad symbolic link exists in the file system ?
Regards,
Jacky
Hi Jacky
Please check this PSIRT article.
https://www.fortinet.com/blog/psirt-blogs/analysis-of-threat-actor-activity
Hi,
I have read this document but it does not provide the log / event sample about AV/IPS removed the bad symbolic link .
If the AV/ IPS removed the bad symbolic link , is there any log / event I can check ?
User | Count |
---|---|
2546 | |
1354 | |
795 | |
643 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.