Firewalls are often viewed as the first line of defense against external threats. Every day, they inspect, filter, and control thousands of connections between internal systems and the internet.
Modern solutions such as Fortinet FortiGate do far more than simply allow or block traffic. They leverage threat intelligence, intrusion prevention signatures, reputation services, and behavioral analysis to identify potentially malicious activity in real time.
When reviewing firewall security events, most attention naturally goes to blocked threats. A blocked exploit attempt or denied connection demonstrates that a security control worked as intended.
However, from a detection engineering perspective, the more interesting question is often:
? “What happened to the threats that were detected but still allowed?”
Business requirements, policy exceptions, temporary firewall rules, misconfigurations, or incomplete threat coverage can sometimes result in suspicious traffic being permitted despite being identified as malicious or high risk.
For defenders, these situations deserve special attention because the firewall recognized something suspicious, yet the communication was still successful.
This detection was developed to identify exactly those scenarios by focusing on malicious or suspicious traffic that was allowed to communicate and remained active long enough to represent a meaningful security risk.


