T1098: FortiMail CLI Creation of Rogue Mail-Archive Account for Exfiltration
Detects post-exploitation activities associated with FortiMail vulnerability CVE-2026-104286 (FG-IR-26-175). The rule identifies potential unauthorized persistence and data exfiltration, including the creation or modification of archive accounts with remote destinations, execution of 'migadmin' via root cron, and specific admin logout anomalies.
YARA-L

