Detecting Exploitation of CVE-2021-44228 (Log4j2) with Elastic Security
ID: 9345d361-96ff-56a1-b76d-f8be154fef97
STIX ID: report--9345d361-96ff-56a1-b76d-f8be154fef97
Feed Name: Elastic Security Labs
Threat Score
Elastic Security advisory summarizing CVE-2021-44228 (Log4Shell): a critical, trivial-to-exploit remote code execution flaw in Log4j2 that was widely observed in the wild. The advisory provides concrete detection rules (Endpoint, Auditbeat, Endgame EQL), hunting queries, post-exploitation detections (e.g., coinminer indicators, untrusted file execution, reverse shells), mitigation recommendations, and references to community resources and patches.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
