Files
splunk-security_content/docs/_playbooks/internal_host_ssh_log4j_investigate.md
2021-12-15 17:42:47 -06:00

1.4 KiB

title, last_modified_at, toc, toc_label, tags
title last_modified_at toc toc_label tags
Internal Host SSH Log4j Investigate 2021-12-14 true
Investigation
Splunk SOAR
SSH

Try in Splunk SOAR{: .btn .btn--success}

Description

Investigate an internal unix host using SSH. This pushes a bash script to the endpoint and runs it, collecting information specific to the December 2021 log4j vulnerability disclosure. This includes the java version installed on the host, any running java processes, and the results of a scan for the affected JndiLookup.class file or log4j .jar files.

  • Type: Investigation
  • Product: Splunk SOAR
  • Apps: SSH
  • Last Updated: 2021-12-14
  • Author: Philip Royer, Splunk
  • ID: 49b2b88c-8e22-48a6-8808-ace1efcb194b

Associated Detections

How To Implement

The ssh asset requires sudo access to scan the whole file system.

Playbooks

Required field

Reference

source | version: 1