Falco high stable other

Java Process Class File Download

Detecting a Java process downloading a class file which could indicate a successful exploit of the log4shell Log4j vulnerability (CVE-2021-44228). This rule is highly specific in its scope.

View Source

Detection Logic

java_network_read and evt.buffer bcontains cafebabe

Field Validations

Loading…

Comments (0)

Loading comments...