Playbook: Internal Host SSH Log4j Investigate
Description
Investigate an internal unix host using SSH. This pushes a bash script to the endpoint and runs it, collecting information specific to the December 2021 log4j vulnerability disclosure. This includes the java version installed on the host, any running java processes, and the results of a scan for the affected JndiLookup.class file or log4j .jar files.
Apps
How To Implement
The ssh asset requires sudo access to scan the whole file system.
Explore Playbook
Click the playbook screenshot to explore in more detail!
Reference
source | version: 1