Falco high stable other
Java Process Class File Download
Detecting a Java process downloading a class file which could indicate a successful exploit of the log4shell Log4j vulnerability (CVE-2021-44228). This rule is highly specific in its scope.
Detection Logic
java_network_read and evt.buffer bcontains cafebabe Field Validations
Loading…
Comments (0)
Loading comments...