Detecting Log4j Exploitation: Sentinel and GuardDuty Detections
Retrospective: this article looks back at events from December 2021, written in 2026 with the benefit of hindsight.
Log4Shell exploitation attempts appear in web logs and network traffic, and successful exploitation often produces outbound connections and unusual processes.
Signals worth watching
- Request strings containing
${jndi:and obfuscated variants (for example${${lower:j}ndi:or${::-j}) in headers, URLs and bodies. - Outbound LDAP, RMI or DNS connections from application servers to unfamiliar external hosts.
- Java processes spawning shells or downloading files.
- WAF alerts for Log4j managed rules.
Where the data lives
- WAF logs (Azure WAF, AWS WAF).
- Web server and application logs.
- Defender for Endpoint / Defender for Servers process and network events.
- VPC Flow Logs and NSG flow logs.
- DNS logs.
A starting query
Java processes spawning shells:
DeviceProcessEvents
| where InitiatingProcessFileName in~ ("java", "java.exe", "javaw.exe")
| where FileName in~ ("sh", "bash", "cmd.exe", "powershell.exe", "curl", "wget")
| project Timestamp, DeviceName, InitiatingProcessCommandLine, ProcessCommandLine
Web log search
Search raw web and WAF logs for jndi in any field, including decoded forms. Many attempts come from scanners; focus on attempts followed by outbound connections from the target server.
Response
- Patch or mitigate the affected application.
- Investigate hosts with outbound connections following exploit attempts.
- Look for persistence, crypto miners and credential theft.
- Rotate credentials the application could access.
- Log4Shell (Dec 2021): The Vulnerability in Everything Incident Teardowns
- How to Find Vulnerable Libraries in Azure and AWS Workloads How-To & Hardening
- CIO Brief: Software Bills of Materials After Log4Shell CIO Briefings