Apache · log4j
CVE-2021-44228
CVE-2021-44228 Apache Log4j Log4Shell controlled lab
OVERVIEW
Lab observed
Java runtime
AdoptOpenJDK HotSpot 8u181-b13
Evidence
Vulnerable + Patched Control
Detection
Lab Validated
Primary analytic
ATTEMPT ONLY
Vendor reported
Vendor-reported fixed versions
2.3.1 / 2.12.2 / 2.15.0Only the lab versions above were independently reproduced by CVE Mapping.
LAB OBSERVED
What this lab demonstrates
One fixed request in vulnerable mode produced an internal support-service lookup, fixed class request, and container-only marker. The equivalent patched request produced no lookup and no marker.
The vulnerable and patched modes used equivalent controlled actions. Application state—not a successful HTTP status alone—is decisive.
VULNERABLE VS PATCHED RESULT
Runtime accepted and the documented state difference was observed.
Runtime accepted and the expected safe state was retained.
Evidence, telemetry, and detection checks are recorded in the manifest.
DETECTION COVERAGE
Detection engineering
- Sigma1 lab-validated analytic
- Splunk1 lab-validated analytic
- Elastic1 lab-validated analytic
Request telemetry provides context, while the strongest analytic requires correlated application-state telemetry. A request alone does not prove exploitation.
Lab queries
Sigma — log4j_jndi_lookup_attempt.yml lab-validated
title: Suspicious Log4j JNDI Lookup Attempt
id: 0c76f4cd-0b95-472a-960e-55f25ad0c7a2
status: test
description: Detects a normalized and sanitized Log4j JNDI lookup-attempt indicator in application request telemetry. This is attempt semantics and does not independently prove successful code execution.
references:
- https://logging.apache.org/log4j/2.x/security.html
- https://nvd.nist.gov/vuln/detail/CVE-2021-44228
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
author: CVE Mapping
date: "2026-08-28"
tags:
- cve.2021.44228
logsource:
product: java
service: normalized_application_request
detection:
selection:
event.category: web
event.type: application_request
service: log4j-lab
http.method: POST
log4j_lookup.attempt_indicator: true
log4j_lookup.syntax: jndi_lookup_redacted
condition: selection
falsepositives:
- Vulnerability scanners, security validation systems, WAF tests, honeypots, research traffic, lab traffic, and literal suspicious strings in logged application data
level: medium
Splunk — log4j_jndi_lookup_attempt.spl lab-validated
/*
CVE-2021-44228 suspicious Log4j JNDI lookup-attempt analytic.
Expected sourcetype: deployment-specific normalized Java application request
telemetry mapped to the fields used below. This search does not confirm
successful code execution.
*/
event.category="web" event.type="application_request" service="log4j-lab" http.method="POST" log4j_lookup.attempt_indicator=true log4j_lookup.syntax="jndi_lookup_redacted"
| eval analytic="log4j_jndi_lookup_attempt"
| table _time analytic service http.method url.path http.status_code log4j.version java.version lab.mode lab.lookup_observed lab.marker_observed message
Elastic — log4j_jndi_lookup_attempt.json lab-validated
{
"name": "Suspicious Log4j JNDI lookup attempt",
"cve": "CVE-2021-44228",
"type": "query",
"language": "kuery",
"query": "event.category:web and event.type:application_request and service:log4j-lab and http.method:POST and log4j_lookup.attempt_indicator:true and log4j_lookup.syntax:jndi_lookup_redacted",
"severity": "medium",
"risk_rationale": "The query identifies sanitized lookup-attempt semantics in normalized application telemetry. It does not prove successful Log4Shell exploitation or code execution.",
"false_positive_note": "Vulnerability scanners, security validation systems, WAF tests, honeypots, research traffic, lab traffic, and logged literal strings can match.",
"required_fields": [
"event.category",
"event.type",
"service",
"http.method",
"url.path",
"log4j_lookup.attempt_indicator",
"log4j_lookup.syntax",
"message"
],
"references": [
"https://logging.apache.org/log4j/2.x/security.html",
"https://nvd.nist.gov/vuln/detail/CVE-2021-44228",
"https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
],
"fixture_discrimination": {"vulnerable": 1, "patched": 1, "benign": 0}
}
FIXTURE DISCRIMINATION
Lab fixture performance
Validated state-change analytics matched vulnerable activity; 1 matched the patched control. See the detection validation record for discrimination notes. Contextual analytics are reported separately and are not promoted to vulnerability discriminators.
EVIDENCE & TELEMETRY
Preserved and verifiable
Sanitized evidence and normalized telemetry are tracked by manifest and SHA-256 integrity files.
RISK CONTEXT
Vendor enrichment
Additional risk feeds are omitted without a verified current lookup.
MITRE ATT&CK
Unassigned
COPYABLE RUNBOOK
Start with the Quickstart.
Disposable, localhost-only runbook commands taken from the lab's QUICKSTART.md. Proof internals stay in the repository — these are the operator workflow commands.
Runbook
./scripts/start.sh vulnerable
curl --fail http://127.0.0.1:39428/health
./scripts/collect-baseline.sh vulnerable
./scripts/reset.sh./scripts/start.sh patched
curl --fail http://127.0.0.1:39428/health
./scripts/collect-baseline.sh patched
./scripts/reset.sh./scripts/reproduce.sh vulnerableLIMITATIONS & SAFETY
Scope stays explicit.
The lab does not claim independent reproduction of every vendor-reported version. It requires authorized defensive use, synthetic identity, and a bounded controlled proof.