cve-2021-44228
cve-2021-44228 copied to clipboard
add id_orig_h and id_resp_h to log4j.log
It is very handy when hunting and doing IR to have the id_orig_h and id_resp_h (actually even the id_orig_p and id_resp_p) in the log4j.log as fields . This is in addition to the uid which exists there already.
I went through a triage exercise yesterday and can confirm that if we had these fields in log4j.log, it would make triage and hunting easier, missing them slowed me down.
Roger that. The ports too I take it? Let's figure out the best way to fix the target_host
nonsense and take care of both at once? Happy to put this on the docket for tomorrow (or feel free to open up a PR if someone responds to me question on the Zeek slack in #development
)