Fortigate: SSL anomalies. Blocked connection.


Description

Fortigate: SSL anomalies. Blocked connection.

Query · wazuh

match="type="utm" subtype="ssl" eventtype="ssl-anomalies"|type=utm subtype=ssl eventtype=ssl-anomalies"

Fires when

Wazuh evaluates a chain top-down. Every rule above this one must match on the same event before this rule is tested at all.

  1. decoded_as=fortigate-firewall-v3
  2. Matches no fields of its own.
  3. 81645 Fortigate: SSL anomalies. Blocked connection. refinement level 5 this rule
    match="type="utm" subtype="ssl" eventtype="ssl-anomalies"|type=utm subtype=ssl eventtype=ssl-anomalies"

Rule dependencies

Depends on

Raw source Fortigate: SSL anomalies. Blocked connection. · Wazuh XML
Esc
Published by Wazuh Core Ruleset ↗, licensed under GPLv2 ↗. Reproduced here unmodified.
<rule id="81645" level="5">
    <if_sid>81603</if_sid>
    <match>type="utm" subtype="ssl" eventtype="ssl-anomalies"|type=utm subtype=ssl eventtype=ssl-anomalies</match>
    <action>blocked</action>
    <description>Fortigate: SSL anomalies. Blocked connection.</description>
  </rule>

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.