Geen omschrijving

soc-a3-fortigate-vpn-rules.xml 2.0KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667
  1. <!--
  2. SOC Proposal Rules — Appendix A3: FortiGate VPN
  3. Simulation profile rule IDs : 100331-100335
  4. Production profile rule IDs : 110331-110335
  5. Severity mapping:
  6. High → level 12
  7. Low → level 5
  8. -->
  9. <group name="soc_mvp,appendix_a,a3,vpn,fortigate,">
  10. <!-- ── Simulation profile ── -->
  11. <!-- ── Production profile (if_group=fortigate) ── -->
  12. <rule id="110331" level="12">
  13. <if_group>fortigate</if_group>
  14. <match>action="ssl-login-success"</match>
  15. <match>user="guest"</match>
  16. <description>A3-01 [PROD] VPN authentication success by guest account</description>
  17. <group>soc_prod,a3,vpn_guest,</group>
  18. <mitre><id>T1078.001</id></mitre>
  19. </rule>
  20. <rule id="110332" level="12">
  21. <if_group>fortigate</if_group>
  22. <match>action="ssl-login-success"</match>
  23. <match>previous_country=</match>
  24. <description>A3-02 [PROD] VPN success from different country than last login</description>
  25. <group>soc_prod,a3,vpn_geo,</group>
  26. <mitre><id>T1078</id></mitre>
  27. </rule>
  28. <rule id="110333" level="12">
  29. <if_group>fortigate</if_group>
  30. <match>action="ssl-login-success"</match>
  31. <match>failed_attempts_before_success=</match>
  32. <description>A3-03 [PROD] VPN success after multiple prior failures (brute-force indicator)</description>
  33. <group>soc_prod,a3,vpn_bruteforce,</group>
  34. <mitre><id>T1110.001</id></mitre>
  35. </rule>
  36. <rule id="110334" level="5">
  37. <if_group>fortigate</if_group>
  38. <match>action="ssl-login-fail"</match>
  39. <match>failed_accounts=</match>
  40. <description>A3-04 [PROD] VPN multiple account failures from single source IP</description>
  41. <group>soc_prod,a3,vpn_bruteforce,</group>
  42. <mitre><id>T1110.003</id></mitre>
  43. </rule>
  44. <rule id="110335" level="12">
  45. <if_group>fortigate</if_group>
  46. <match>action="ssl-login-success"</match>
  47. <match>expected_country=TH</match>
  48. <description>A3-05 [PROD] VPN authentication success from outside Thailand</description>
  49. <group>soc_prod,a3,vpn_geo,</group>
  50. <mitre><id>T1078</id></mitre>
  51. </rule>
  52. </group>