logo

Log4Shell: Reconnaissance and post exploitation network detection

ID: fdf735ef-c676-55e1-abc2-e627ff3409a9

STIX ID: report--fdf735ef-c676-55e1-abc2-e627ff3409a9

Feed Name: Fox-IT blog

Threat Score
90/100

Date Published: 2021-12-12

Date Updated: 2026-04-27

Author: Joost Jansen

...
...

NCC Group RIFT analysis of CVE-2021-44228 (Log4Shell): the report supplies Suricata detection rules, hunting rules, a host-based log4j-finder script, and a curated list of observed listener IOCs. It documents active exploitation in the wild (including MobileIron incidents), describes evasion techniques and risks from centralized logging and post-exploitation, and urges immediate mitigation and scanning.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.