|
|
|
|
|
|
|
|
1
|
+# Appendix A - production-style sample logs
|
|
|
|
2
|
+# Sources: FortiGate traffic/event/vpn style fields, Windows Security event field shapes, SOC Integrator DNS IOC format
|
|
|
|
3
|
+
|
|
|
|
4
|
+# A1-01 DNS IOC traffic
|
|
|
|
5
|
+soc_event=dns_ioc event_type=ioc_dns_traffic src_ip=10.26.45.214 query=ioc-2294.malicious.example action=blocked severity=medium
|
|
|
|
6
|
+
|
|
|
|
7
|
+# A1-02 DNS IOC domain match
|
|
|
|
8
|
+soc_event=dns_ioc event_type=ioc_domain_match src_ip=10.26.45.214 query=bad-c2.example feed=internal_main confidence=high action=alert
|
|
|
|
9
|
+
|
|
|
|
10
|
+# A2-01 Allowed RDP from public IP
|
|
|
|
11
|
+date=2026-03-09 time=10:01:31 devname="FGT80F-Branch01" devid="FGT80FTK20000001" eventtime=1773079291 vd="root" logid="0000000013" type="traffic" subtype="forward" level="warning" srcip=91.190.63.84 srcport=55123 dstip=10.20.55.10 dstport=3389 proto=6 action="accept" policyid=3
|
|
|
|
12
|
+
|
|
|
|
13
|
+# A2-02 Firewall admin password changed
|
|
|
|
14
|
+date=2026-03-09 time=10:02:04 devname="FGT80F-Branch01" devid="FGT80FTK20000001" eventtime=1773079324 vd="root" logid="0100044547" type="event" subtype="system" level="warning" user="admin" action="password-change" ui="https(10.20.55.1)"
|
|
|
|
15
|
+
|
|
|
|
16
|
+# A2-03 Firewall admin account created
|
|
|
|
17
|
+date=2026-03-09 time=10:02:17 devname="FGT80F-Branch01" devid="FGT80FTK20000001" eventtime=1773079337 vd="root" logid="0100044548" type="event" subtype="system" level="warning" user="admin" action="create-admin" target_user="soc-backup-admin"
|
|
|
|
18
|
+
|
|
|
|
19
|
+# A2-04 Notification disabled via config
|
|
|
|
20
|
+date=2026-03-09 time=10:03:41 devname="FGT80F-Branch01" devid="FGT80FTK20000001" eventtime=1773079421 vd="root" logid="0100044551" type="event" subtype="system" level="warning" user="admin" action="config-change" config_path="system.alertemail" config_key="email-notify" config_value=disable
|
|
|
|
21
|
+
|
|
|
|
22
|
+# A2-05 Config downloaded
|
|
|
|
23
|
+date=2026-03-09 time=10:04:03 devname="FGT80F-Branch01" devid="FGT80FTK20000001" eventtime=1773079443 vd="root" logid="0100044552" type="event" subtype="system" level="notice" user="admin" action="download-config" dstip=10.20.50.33
|
|
|
|
24
|
+
|
|
|
|
25
|
+# A2-06 Multiple critical IPS signatures
|
|
|
|
26
|
+date=2026-03-09 time=10:05:14 devname="FGT80F-Branch01" devid="FGT80FTK20000001" eventtime=1773079514 vd="root" logid="0720018432" type="utm" subtype="ips" level="alert" srcip=185.220.101.44 dstip=10.20.55.20 attack="Multiple.Critical.Signatures" action="blocked"
|
|
|
|
27
|
+
|
|
|
|
28
|
+# A2-07 TCP external scan
|
|
|
|
29
|
+date=2026-03-09 time=10:05:50 devname="FGT80F-Branch01" devid="FGT80FTK20000001" eventtime=1773079550 vd="root" logid="0419016384" type="utm" subtype="anomaly" level="warning" srcip=45.148.10.9 dstip=10.20.55.20 attack="TCP.Port.Scan" action="detected"
|
|
|
|
30
|
+
|
|
|
|
31
|
+# A2-08 IOC IP indicator detected
|
|
|
|
32
|
+date=2026-03-09 time=10:06:23 devname="FGT80F-Branch01" devid="FGT80FTK20000001" eventtime=1773079583 vd="root" logid="0720018433" type="utm" subtype="ips" level="warning" srcip=10.20.55.12 dstip=198.51.100.77 ioc_type=ip ioc_value=198.51.100.77 action="blocked"
|
|
|
|
33
|
+
|
|
|
|
34
|
+# A2-09 Internal scan
|
|
|
|
35
|
+date=2026-03-09 time=10:07:12 devname="FGT80F-Branch01" devid="FGT80FTK20000001" eventtime=1773079632 vd="root" logid="0419016385" type="utm" subtype="anomaly" level="warning" srcip=10.20.55.11 dstip=10.20.55.0/24 attack="Internal.Port.Scan" action="detected"
|
|
|
|
36
|
+
|
|
|
|
37
|
+# A2-10 Traffic to known C2
|
|
|
|
38
|
+date=2026-03-09 time=10:07:59 devname="FGT80F-Branch01" devid="FGT80FTK20000001" eventtime=1773079679 vd="root" logid="0000000014" type="traffic" subtype="forward" level="warning" srcip=10.20.55.50 dstip=203.0.113.60 dstport=443 threat_label="known-c2" action="accept"
|
|
|
|
39
|
+
|
|
|
|
40
|
+# A3-01 VPN guest login success
|
|
|
|
41
|
+date=2026-03-09 time=10:10:11 devname="FGT80F-Branch01" devid="FGT80FTK20000001" eventtime=1773079811 vd="root" logid="0101037133" type="event" subtype="vpn" tunneltype="ssl" level="warning" action="ssl-login-success" user="guest" srcip=203.0.113.17
|
|
|
|
42
|
+
|
|
|
|
43
|
+# A3-02 VPN success from different country than prior login
|
|
|
|
44
|
+date=2026-03-09 time=10:10:43 devname="FGT80F-Branch01" devid="FGT80FTK20000001" eventtime=1773079843 vd="root" logid="0101037135" type="event" subtype="vpn" tunneltype="ssl" level="warning" action="ssl-login-success" user="jane.doe" srcip=198.51.100.20 previous_country=TH current_country=DE
|
|
|
|
45
|
+
|
|
|
|
46
|
+# A3-03 VPN success after failures
|
|
|
|
47
|
+date=2026-03-09 time=10:11:12 devname="FGT80F-Branch01" devid="FGT80FTK20000001" eventtime=1773079872 vd="root" logid="0101037135" type="event" subtype="vpn" tunneltype="ssl" level="warning" action="ssl-login-success" user="ops.admin" srcip=198.51.100.42 failed_attempts_before_success=8
|
|
|
|
48
|
+
|
|
|
|
49
|
+# A3-04 Multiple account failures from one source
|
|
|
|
50
|
+date=2026-03-09 time=10:11:49 devname="FGT80F-Branch01" devid="FGT80FTK20000001" eventtime=1773079909 vd="root" logid="0101037134" type="event" subtype="vpn" tunneltype="ssl" level="notice" action="ssl-login-fail" srcip=198.51.100.42 failed_accounts=alice,bob,charlie
|
|
|
|
51
|
+
|
|
|
|
52
|
+# A3-05 VPN login from outside expected country
|
|
|
|
53
|
+date=2026-03-09 time=10:12:04 devname="FGT80F-Branch01" devid="FGT80FTK20000001" eventtime=1773079924 vd="root" logid="0101037135" type="event" subtype="vpn" tunneltype="ssl" level="warning" action="ssl-login-success" user="finance.user" srcip=203.0.113.71 expected_country=TH current_country=US
|
|
|
|
54
|
+
|
|
|
|
55
|
+# A4-01 Windows privileged account auth failure
|
|
|
|
56
|
+{"win":{"system":{"eventID":"4625"},"eventdata":{"targetUserName":"admin01"}}}
|
|
|
|
57
|
+# A4-02 Windows service account auth failure
|
|
|
|
58
|
+{"win":{"system":{"eventID":"4625"},"eventdata":{"targetUserName":"svc_backup$"}}}
|
|
|
|
59
|
+# A4-03 AD enumeration tool execution
|
|
|
|
60
|
+{"win":{"system":{"eventID":"4688"},"eventdata":{"newProcessName":"C:\\Tools\\adfind.exe"}}}
|
|
|
|
61
|
+# A4-06 Remote interactive auth success
|
|
|
|
62
|
+{"win":{"system":{"eventID":"4624"},"eventdata":{"logonType":"10","targetUserName":"helpdesk"}}}
|
|
|
|
63
|
+# A4-08 NTLM network logon (pass-the-hash indicator)
|
|
|
|
64
|
+{"win":{"system":{"eventID":"4624"},"eventdata":{"authenticationPackageName":"NTLM","logonType":"3","targetUserName":"it-admin"}}}
|
|
|
|
65
|
+# A4-09 Guest account auth success
|
|
|
|
66
|
+{"win":{"system":{"eventID":"4624"},"eventdata":{"targetUserName":"guest"}}}
|
|
|
|
67
|
+# A4-10 Service account interactive logon
|
|
|
|
68
|
+{"win":{"system":{"eventID":"4624"},"eventdata":{"logonType":"2","targetUserName":"service_sql"}}}
|
|
|
|
69
|
+# A4-12 Account added to privileged domain group
|
|
|
|
70
|
+{"win":{"system":{"eventID":"4728"},"eventdata":{"targetUserName":"new.user","groupName":"Domain Admins"}}}
|
|
|
|
71
|
+# A4-11 Account added to privileged local group
|
|
|
|
72
|
+{"win":{"system":{"eventID":"4732"},"eventdata":{"targetUserName":"new.user","groupName":"Administrators"}}}
|
|
|
|
73
|
+# A4-13 DSRM password set attempt
|
|
|
|
74
|
+{"win":{"system":{"eventID":"4794"},"eventdata":{"targetUserName":"Administrator"}}}
|
|
|
|
75
|
+# A4-21 Domain/local account created
|
|
|
|
76
|
+{"win":{"system":{"eventID":"4720"},"eventdata":{"targetUserName":"ops.newuser"}}}
|
|
|
|
77
|
+# A4-22 Domain/local account re-enabled
|
|
|
|
78
|
+{"win":{"system":{"eventID":"4722"},"eventdata":{"targetUserName":"legacy.disabled"}}}
|