Best Detection of 2026 Series – Edge Device and VPN Appliance Exploitation for I

Detects HTTP requests directed at edge appliances (FortiOS/FortiProxy, SonicWall, Cisco ASA) that match known CVE-associated URI paths, alongside successful administrative authentication to management or VPN interfaces originating from external source IP addresses. This rule is designed to identify potential initial access via vulnerability exploitation or unauthorized administrative login to critical infrastructure.