Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
1 detection
Filters
Last updated
All Time
Detection languages
1
Contributors
1
Categories
1
1
1
1
Platforms
1
Products / Services
1
MITRE Techniques
1
1
1
1
1
CVEs
68
68
60
58
50
Detects post-exploitation activities associated with FortiMail vulnerability CVE-2026-104286 (FG-IR-26-175). The rule identifies potential unauthorized persistence and data exfiltration, including the creation or modification of archive accounts with remote destinations, execution of 'migadmin' via root cron, and specific admin logout anomalies.
