Vulnerable Log4j processes alerts
Lacework FortiCNAPP generates vulnerability alerts when it detects long-running, vulnerable Log4j processes on both hosts and containers at runtime.
The following table lists all the Log4j processes alerts in the Host Vulnerability subcategory.
| Alert Name | Alert Type | Connection |
|---|---|---|
|
NewVulnInternalConnection |
Process -> Process |
|
|
Outbound connection from vulnerable application to a domain Note: Legacy name: New external host server connection from vulnerable application |
NewExternalServerDNSConnFromVuln |
|
|
New external client IP address connection to vulnerable application |
NewExternalClientIpConnToVuln |
IP -> Process |
|
Outbound connection from vulnerable application to an IP address Note: Legacy name: New external server IP address connection from vulnerable application |
NewExternalServerIPConnFromVuln |
Process -> IP |
|
NewVulnBinaryType |
|
|
|
NewVulnChildLaunched |
Process -> Process |
|
|
NewChildLaunchedFromVulnParent |
Process -> Process |
|
|
User launched new vulnerable binary |
UserLaunchedNewVulnBinary |
User -> Process |
|
Bad external server host connection from vulnerable application |
NewExternalServerBadDNSConnFromVuln |
Process -> DNS |
|
Bad external server IP address connection from vulnerable application |
NewExternalServerBadIPConnFromVuln |
Process -> IP |
|
Bad external client IP address connection to vulnerable application |
NewExternalClientBadIpConnToVuln |
IP -> Process |