-
log4j2-rce-poc
A bare minimum proof-of-concept for Log4j2 JNDI RCE vulnerability (CVE-2021-44228/Log4Shell).
-
InfluxDB
Power Real-Time Data Analytics at Scale. Get real-time insights from all types of time series data with InfluxDB. Ingest, query, and analyze billions of data points in real-time with unbounded cardinality.
-
log4shell
Discontinued Operational information regarding the log4shell vulnerabilities in the Log4j logging library.
If you're talking about Florian's exploit detection note that nearly every hit in practice is going to be a DNS probe, like the Huntress one.
However, when using JNDI lookups, if you return properly formatted JNDI data (from a malicious server) then Java will execute that code. You can see this in PoC code: https://github.com/unlimitedsola/log4j2-rce-poc/blob/master/payload-server/src/main/kotlin/Main.kt
NCSC-NL has a researched list of specific vulnerabilities.