cve-2021-44228 icon indicating copy to clipboard operation
cve-2021-44228 copied to clipboard

add id_orig_h and id_resp_h to log4j.log

Open benjeems opened this issue 3 years ago • 2 comments

It is very handy when hunting and doing IR to have the id_orig_h and id_resp_h (actually even the id_orig_p and id_resp_p) in the log4j.log as fields . This is in addition to the uid which exists there already.

benjeems avatar Dec 21 '21 00:12 benjeems

I went through a triage exercise yesterday and can confirm that if we had these fields in log4j.log, it would make triage and hunting easier, missing them slowed me down.

benjeems avatar Dec 22 '21 00:12 benjeems

Roger that. The ports too I take it? Let's figure out the best way to fix the target_host nonsense and take care of both at once? Happy to put this on the docket for tomorrow (or feel free to open up a PR if someone responds to me question on the Zeek slack in #development)

ynadji avatar Dec 22 '21 00:12 ynadji