Created
January 31, 2023 16:38
-
-
Save p4lsec/db517b49a1c2900ca6e1725df5d29642 to your computer and use it in GitHub Desktop.
YARA rule for detecting references to Log4j
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
rule log4j { | |
meta: | |
author = "Jace Powell" | |
description = "Searches for references to Log4j. Only used as a prelimiary/triage search, not a definitive result." | |
creation_date = "10 Dec 2021" | |
strings: | |
$a = /log4j/ nocase ascii wide | |
condition: | |
any of them | |
} |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment