Webserver detections for Log4Shell (CVE-2021-44228) JNDI injection exploit strings
Detects webserver traffic containing Log4Shell-style JNDI injection payload strings, excluding Nessus scan artifacts.
FreeUnreviewedSigmahighv1
webserver-detections-for-log4shell-cve-2021-44228-jndi-injection-exploit-strings-5ea8faa8
title: Webserver detections for Log4Shell (CVE-2021-44228) JNDI injection exploit strings
id: f01064ca-d825-4cdb-9209-98a90f0c2708
status: test
description: This rule flags webserver requests containing common JNDI lookup payloads associated with Log4Shell exploitation attempts, including LDAP/RMI/LDAPS/DNS and nested/encoded ${jndi:...} variants. Attackers leverage these patterns to trigger unsafe lookups from the logging context, which can lead to remote code execution. The detection relies on the presence of specific keyword strings in webserver logs or HTTP content, while excluding lines matching a Nessus-related filter pattern.
references:
- https://web.archive.org/web/20231230220738/https://www.lunasec.io/docs/blog/log4j-zero-day/
- https://news.ycombinator.com/item?id=29504755
- https://github.com/tangxiaofeng7/apache-log4j-poc
- https://gist.github.com/Neo23x0/e4c8b03ff8cdf1fa63b7d15db6e3860b
- https://github.com/YfryTchsGD/Log4jAttackSurface
- https://twitter.com/shutingrz/status/1469255861394866177?s=21
- https://github.com/SigmaHQ/sigma/blob/master/rules-emerging-threats/2021/Exploits/CVE-2021-44228/web_cve_2021_44228_log4j.yml
author: Florian Roth (Nextron Systems), Huntrule Team
date: 2021-12-10
modified: 2022-02-06
tags:
- attack.initial-access
- attack.t1190
- detection.emerging-threats
logsource:
category: webserver
detection:
keywords:
- ${jndi:ldap:/
- ${jndi:rmi:/
- ${jndi:ldaps:/
- ${jndi:dns:/
- "/$%7bjndi:"
- "%24%7bjndi:"
- "$%7Bjndi:"
- "%2524%257Bjndi"
- "%2F%252524%25257Bjndi%3A"
- "${jndi:${lower:"
- ${::-j}${
- ${jndi:nis
- ${jndi:nds
- ${jndi:corba
- ${jndi:iiop
- "Reference Class Name: foo"
- ${${env:BARFOO:-j}
- ${::-l}${::-d}${::-a}${::-p}
- ${base64:JHtqbmRp
- ${${env:ENV_NAME:-j}ndi${env:ENV_NAME:-:}$
- "${${lower:j}ndi:"
- "${${upper:j}ndi:"
- "${${::-j}${::-n}${::-d}${::-i}:"
filter:
- w.nessus.org/nessus
- /nessus}
condition: keywords and not filter
falsepositives:
- Vulnerability scanning
level: high
license: DRL-1.1
related:
- id: 5ea8faa8-db8b-45be-89b0-151b84c82702
type: derived
What it detects
This rule flags webserver requests containing common JNDI lookup payloads associated with Log4Shell exploitation attempts, including LDAP/RMI/LDAPS/DNS and nested/encoded ${jndi:...} variants. Attackers leverage these patterns to trigger unsafe lookups from the logging context, which can lead to remote code execution. The detection relies on the presence of specific keyword strings in webserver logs or HTTP content, while excluding lines matching a Nessus-related filter pattern.
Known false positives
- Vulnerability scanning
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.