logo

Detecting Exploitation of CVE-2021-44228 (Log4j2) with Elastic Security

ID: 9345d361-96ff-56a1-b76d-f8be154fef97

STIX ID: report--9345d361-96ff-56a1-b76d-f8be154fef97

Feed Name: Elastic Security Labs

Threat Score
95/100

Date Published: 2022-11-22

Date Updated: 2026-04-27

...
...

Elastic Security advisory summarizing CVE-2021-44228 (Log4Shell): a critical, trivial-to-exploit remote code execution flaw in Log4j2 that was widely observed in the wild. The advisory provides concrete detection rules (Endpoint, Auditbeat, Endgame EQL), hunting queries, post-exploitation detections (e.g., coinminer indicators, untrusted file execution, reverse shells), mitigation recommendations, and references to community resources and patches.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.