Webserver log detection of Log4j CVE-2021-44228 JNDI strings in User-Agent, URI query, or Referer

Flags webserver requests with ${jndi:...} payloads in User-Agent, URI query, or Referer indicative of Log4Shell attempts.

FreeUnreviewedSigmahighv1
title: Webserver log detection of Log4j CVE-2021-44228 JNDI strings in User-Agent, URI query, or Referer
id: e820f75d-6a43-4713-a8e9-a6a23159e668
status: test
description: This rule identifies HTTP requests in web server logs that contain Log4j-style ${jndi:...} payload fragments associated with the CVE-2021-44228 exploitation attempts, including multiple obfuscated variants. Attackers rely on these strings being processed by vulnerable logging components to trigger outbound lookups, enabling remote code execution or related impact. The detection relies on matching suspicious substrings in User-Agent, URI query parameters, and Referer fields (cs-user-agent, cs-uri-query, cs-referer) within webserver log telemetry.
references:
  - https://web.archive.org/web/20231230220738/https://www.lunasec.io/docs/blog/log4j-zero-day/
  - https://news.ycombinator.com/item?id=29504755
  - https://github.com/tangxiaofeng7/apache-log4j-poc
  - https://gist.github.com/Neo23x0/e4c8b03ff8cdf1fa63b7d15db6e3860b
  - https://github.com/YfryTchsGD/Log4jAttackSurface
  - https://twitter.com/shutingrz/status/1469255861394866177?s=21
  - https://github.com/SigmaHQ/sigma/blob/master/rules-emerging-threats/2021/Exploits/CVE-2021-44228/web_cve_2021_44228_log4j_fields.yml
author: Florian Roth (Nextron Systems), Huntrule Team
date: 2021-12-10
modified: 2023-01-02
tags:
  - attack.initial-access
  - attack.t1190
  - cve.2021-44228
  - detection.emerging-threats
logsource:
  category: webserver
detection:
  selection1:
    cs-user-agent|contains:
      - ${jndi:ldap:/
      - ${jndi:rmi:/
      - ${jndi:ldaps:/
      - ${jndi:dns:/
      - "/$%7bjndi:"
      - "%24%7bjndi:"
      - "$%7Bjndi:"
      - "%2524%257Bjndi"
      - "%2F%252524%25257Bjndi%3A"
      - "${jndi:${lower:"
      - ${::-j}${
      - ${jndi:nis
      - ${jndi:nds
      - ${jndi:corba
      - ${jndi:iiop
      - "Reference Class Name: foo"
      - ${${env:BARFOO:-j}
      - ${::-l}${::-d}${::-a}${::-p}
      - ${base64:JHtqbmRp
      - ${${env:ENV_NAME:-j}ndi${env:ENV_NAME:-:}$
      - "${${lower:j}ndi:"
      - "${${upper:j}ndi:"
      - "${${::-j}${::-n}${::-d}${::-i}:"
  selection3:
    cs-uri-query|contains:
      - ${jndi:ldap:/
      - ${jndi:rmi:/
      - ${jndi:ldaps:/
      - ${jndi:dns:/
      - "/$%7bjndi:"
      - "%24%7bjndi:"
      - "$%7Bjndi:"
      - "%2524%257Bjndi"
      - "%2F%252524%25257Bjndi%3A"
      - "${jndi:${lower:"
      - ${::-j}${
      - ${jndi:nis
      - ${jndi:nds
      - ${jndi:corba
      - ${jndi:iiop
      - "Reference Class Name: foo"
      - ${${env:BARFOO:-j}
      - ${::-l}${::-d}${::-a}${::-p}
      - ${base64:JHtqbmRp
      - ${${env:ENV_NAME:-j}ndi${env:ENV_NAME:-:}$
      - "${${lower:j}ndi:"
      - "${${upper:j}ndi:"
      - "${${::-j}${::-n}${::-d}${::-i}:"
  selection4:
    cs-referer|contains:
      - ${jndi:ldap:/
      - ${jndi:rmi:/
      - ${jndi:ldaps:/
      - ${jndi:dns:/
      - "/$%7bjndi:"
      - "%24%7bjndi:"
      - "$%7Bjndi:"
      - "%2524%257Bjndi"
      - "%2F%252524%25257Bjndi%3A"
      - "${jndi:${lower:"
      - ${::-j}${
      - ${jndi:nis
      - ${jndi:nds
      - ${jndi:corba
      - ${jndi:iiop
      - "Reference Class Name: foo"
      - ${${env:BARFOO:-j}
      - ${::-l}${::-d}${::-a}${::-p}
      - ${base64:JHtqbmRp
      - ${${env:ENV_NAME:-j}ndi${env:ENV_NAME:-:}$
      - "${${lower:j}ndi:"
      - "${${upper:j}ndi:"
      - "${${::-j}${::-n}${::-d}${::-i}:"
  condition: 1 of selection*
falsepositives:
  - Vulnerability scanning
level: high
license: DRL-1.1
related:
  - id: 9be472ed-893c-4ec0-94da-312d2765f654
    type: derived

What it detects

This rule identifies HTTP requests in web server logs that contain Log4j-style ${jndi:...} payload fragments associated with the CVE-2021-44228 exploitation attempts, including multiple obfuscated variants. Attackers rely on these strings being processed by vulnerable logging components to trigger outbound lookups, enabling remote code execution or related impact. The detection relies on matching suspicious substrings in User-Agent, URI query parameters, and Referer fields (cs-user-agent, cs-uri-query, cs-referer) within webserver log telemetry.

Known false positives

  • Vulnerability scanning

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.