Multi-CloudDetection & ResponseRetrospectives

Detecting Log4j Exploitation: Sentinel and GuardDuty Detections

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from December 2021, written in 2026 with the benefit of hindsight.

Log4Shell exploitation attempts appear in web logs and network traffic, and successful exploitation often produces outbound connections and unusual processes.

Signals worth watching

  • Request strings containing ${jndi: and obfuscated variants (for example ${${lower:j}ndi: or ${::-j}) in headers, URLs and bodies.
  • Outbound LDAP, RMI or DNS connections from application servers to unfamiliar external hosts.
  • Java processes spawning shells or downloading files.
  • WAF alerts for Log4j managed rules.

Where the data lives

  • WAF logs (Azure WAF, AWS WAF).
  • Web server and application logs.
  • Defender for Endpoint / Defender for Servers process and network events.
  • VPC Flow Logs and NSG flow logs.
  • DNS logs.

A starting query

Java processes spawning shells:

DeviceProcessEvents
| where InitiatingProcessFileName in~ ("java", "java.exe", "javaw.exe")
| where FileName in~ ("sh", "bash", "cmd.exe", "powershell.exe", "curl", "wget")
| project Timestamp, DeviceName, InitiatingProcessCommandLine, ProcessCommandLine

Web log search

Search raw web and WAF logs for jndi in any field, including decoded forms. Many attempts come from scanners; focus on attempts followed by outbound connections from the target server.

Response

  1. Patch or mitigate the affected application.
  2. Investigate hosts with outbound connections following exploit attempts.
  3. Look for persistence, crypto miners and credential theft.
  4. Rotate credentials the application could access.
detect log4j exploitationLog4Shell2021

More on this story