TTPwire Vol. 1 · MITRE ATT&CK·Tagged

← All stories

Huntress

Log4Shell: A Tradecraft Tuesday Recap | Huntress

2021-12-17 · Read original ↗

ATT&CK techniques detected

1 predictions
T1190Exploit Public-Facing Application
92%
"example, calls out this jndi functionality, allowing it to reach out to attackercontrolledhost ( using an ldap server ) and retrieve and return whatever malicious thing is there. in short, an attacker can insert and execute almost any line of code with just this single string — a…"

Summary

We recap our December 2021 episode of Tradecraft Tuesday where we dive into the Log4Shell vulnerability.