Bit of a long shot, but figured I'd ask:
If you're running fortiSIEM, can you run watchtowr's CVE-2025-25256 detection artifact generator (https://github.com/watchtowrlabs/watchTowr-vs-FortiSIEM-CVE-2025-25256?ref=labs.watchtowr.com) and send me a pcap with the artifacts included?
It's for work, so I would not post the pcap anywhere. I just would love to have a pcap of the script running against an actual system so I can make sure the tag is as accurate as possible. You can send the pcap to brianna[AT]greynoise[.]io