Fortinet white logo
Fortinet white logo

User Guide

Malware Hash

Malware Hash

Use the Malware Hash page to define a list of malware files and their hash functions. When FortiSIEM monitors a directory, it generates these directory events:

Directory EventGenerated by This Action
PH_DEV_MON_CUST_FILE_CREATENew file creation
PH_DEV_MON_CUST_FILE_SCANDirectory is scanned
PH_DEV_MON_CUST_FILE_CHANGE_CONTENTChanges in file content

When FortiSIEM scans a file and collects its hash, it uses the system rule Malware Hash Check to check the list of malware hashes. FortiSIEM will then trigger an alert if a match is found. A Python Threat Feed Framework is also available, see here.

The following sections describe Malware Hashes:

Malware Hash

Malware Hash

Use the Malware Hash page to define a list of malware files and their hash functions. When FortiSIEM monitors a directory, it generates these directory events:

Directory EventGenerated by This Action
PH_DEV_MON_CUST_FILE_CREATENew file creation
PH_DEV_MON_CUST_FILE_SCANDirectory is scanned
PH_DEV_MON_CUST_FILE_CHANGE_CONTENTChanges in file content

When FortiSIEM scans a file and collects its hash, it uses the system rule Malware Hash Check to check the list of malware hashes. FortiSIEM will then trigger an alert if a match is found. A Python Threat Feed Framework is also available, see here.

The following sections describe Malware Hashes: