Sagan high stable other
[WEB-ATTACKS] Log4j exploit attempt - CVE-2021-44228
[WEB-ATTACKS] Log4j exploit attempt - CVE-2021-44228
Detection Logic
alert any $EXTERNAL_NET any -> $HOME_NET any (msg: "[WEB-ATTACKS] Log4j exploit attempt - CVE-2021-44228"; content:"jndi
| 3a
| "; content: "{"; content: " 200 "; content:!"Rule"; nocase; content:!"drop"; content:!"tmm"; nocase; default_proto:tcp; default_dst_port: $HTTP_PORT; classtype: web-application-attack; parse_src_ip: 1; reference:url,lunasec.io/docs/blog/log4j-zero-day/; reference:cve,2021-44228; sid:5005958; rev:2;) Field Validations
Loading…
Comments (0)
Loading comments...