please see this reply: https://learn.microsoft.com/en-us/answers/questions/1351962/log4j-vulnerability-exploit-aka-log4shell-ip-ioc
"Log4j vulnerability exploit aka Log4Shell IP IOC involving one user"

Zenzele Mdakane
20
Reputation points
Hi how do we go about resolving ( The detection rule "Log4j vulnerability exploit aka Log4Shell IP IOC involving one user" in Microsoft Sentinel identifies potential exploitation attempts of the Log4Shell vulnerability (CVE-2021-44228) by monitoring for indicators of compromise (IOCs) associated with a specific user account) Suspicious IP Address :185.220.101.25) will blocking the IP address, running full AV scan, request user to change password be the solution or what
Microsoft Security Microsoft Sentinel
1,299 questions
Accepted answer
-
Clive Watson 7,866 Reputation points MVP Volunteer Moderator
2025-04-16T09:21:05.8566667+00:00