Log4Shell JNDI Injection Patterns in Web Request Logs
Detects Log4Shell (CVE-2021-44228) exploitation attempts by identifying JNDI lookup patterns (e.g., ldap://, rmi://, dns://) and common obfuscation techniques within HTTP headers, user-agents, and query parameters, which could lead to remote code execution.
Sigma

