Fortinet white logo
Fortinet white logo

Alerts Reference

Vulnerable Log4j processes alerts

Vulnerable Log4j processes alerts

Lacework FortiCNAPP generates vulnerability alerts when it detects long-running, vulnerable Log4j processes on both hosts and containers at runtime.

The following table lists all the Log4j processes alerts in the Host Vulnerability subcategory.

Alert Name Alert Type Connection

New vulnerable internal connection

NewVulnInternalConnection

Process -> Process

Outbound connection from vulnerable application to a domain

Note: Legacy name: New external host server connection from vulnerable application

NewExternalServerDNSConnFromVuln

New external client IP address connection to vulnerable application

NewExternalClientIpConnToVuln

IP -> Process

Outbound connection from vulnerable application to an IP address

Note: Legacy name: New external server IP address connection from vulnerable application

NewExternalServerIPConnFromVuln

Process -> IP

New vulnerable application

NewVulnBinaryType

New vulnerable child launched

NewVulnChildLaunched

Process -> Process

New child launched from vulnerable application

NewChildLaunchedFromVulnParent

Process -> Process

User launched new vulnerable binary

UserLaunchedNewVulnBinary

User -> Process

Bad external server host connection from vulnerable application

NewExternalServerBadDNSConnFromVuln

Process -> DNS

Bad external server IP address connection from vulnerable application

NewExternalServerBadIPConnFromVuln

Process -> IP

Bad external client IP address connection to vulnerable application

NewExternalClientBadIpConnToVuln

IP -> Process

Vulnerable Log4j processes alerts

Vulnerable Log4j processes alerts

Lacework FortiCNAPP generates vulnerability alerts when it detects long-running, vulnerable Log4j processes on both hosts and containers at runtime.

The following table lists all the Log4j processes alerts in the Host Vulnerability subcategory.

Alert Name Alert Type Connection

New vulnerable internal connection

NewVulnInternalConnection

Process -> Process

Outbound connection from vulnerable application to a domain

Note: Legacy name: New external host server connection from vulnerable application

NewExternalServerDNSConnFromVuln

New external client IP address connection to vulnerable application

NewExternalClientIpConnToVuln

IP -> Process

Outbound connection from vulnerable application to an IP address

Note: Legacy name: New external server IP address connection from vulnerable application

NewExternalServerIPConnFromVuln

Process -> IP

New vulnerable application

NewVulnBinaryType

New vulnerable child launched

NewVulnChildLaunched

Process -> Process

New child launched from vulnerable application

NewChildLaunchedFromVulnParent

Process -> Process

User launched new vulnerable binary

UserLaunchedNewVulnBinary

User -> Process

Bad external server host connection from vulnerable application

NewExternalServerBadDNSConnFromVuln

Process -> DNS

Bad external server IP address connection from vulnerable application

NewExternalServerBadIPConnFromVuln

Process -> IP

Bad external client IP address connection to vulnerable application

NewExternalClientBadIpConnToVuln

IP -> Process