Log4Shell — Forensic Investigation in AWS
ID: 5420716c-62de-51f9-8e54-60c4a0718da3
STIX ID: report--5420716c-62de-51f9-8e54-60c4a0718da3
Feed Name: Mitiga
Mitiga provides a hands-on compromise assessment and forensic tutorial for detecting exploitation of the Log4Shell vulnerability (CVE-2021-44228) in AWS environments. The guide instructs defenders to collect Application Load Balancer, VPC Flow, CloudTrail and application logs into S3 and query them with Athena (Phase 1: detect JNDI strings in request headers/URLs; Phase 2: verify outbound LDAP callbacks indicating successful exploitation). It outlines post-exploitation risks — credentials and metadata exfiltration, file/SSH key theft, lateral movement and misuse of AWS APIs — and recommends readiness controls including enabling CloudTrail with longer retention, VPC Flow and ALB logging, AWS WAF rules, and building a lab for testing.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
