12/12

eXploit – CVE-2021-42287/CVE-2021-42278 Weaponisation

https://exploit.ph/cve-2021-42287-cve-2021-42278-weaponisation.html
eXploit – CVE-2021-42287/CVE-2021-42278 Weaponisation

Microsoft’s Response to CVE-2021-44228 Apache Log4j 2 | MSRC Blog | Microsoft Security Response Center

https://msrc-blog.microsoft.com/2021/12/11/microsofts-response-to-cve-2021-44228-apache-log4j2/
Microsoft’s Response to CVE-2021-44228 Apache Log4j 2 | MSRC Blog | Microsoft Security Response Center

Exploit samAccountName spoofing with Kerberos - Cloudbrothers

https://cloudbrothers.info/en/exploit-kerberos-samaccountname-spoofing/
Exploit samAccountName spoofing with Kerberos - Cloudbrothers

Log4j 0day being exploited : blueteamsec

https://www.reddit.com/r/blueteamsec/comments/rd38z9/log4j_0day_being_exploited/
Log4j 0day being exploited : blueteamsec

Zero-Day Exploit Targeting Popular Java Library Log4j

https://www.govcert.ch/blog/zero-day-exploit-targeting-popular-java-library-log4j/
Zero-Day Exploit Targeting Popular Java Library Log4j

Tweet / Twitter

https://twitter.com/theasf/status/1400875147163279374
Tweet / Twitter

sAMAccountName spoofing - The Hacker Recipes

https://www.thehacker.recipes/ad/movement/kerberos/samaccountname-spoofing
sAMAccountName spoofing - The Hacker Recipes

Splunk Security Advisory for Apache Log4j (CVE-2021-44228, CVE-2021-45046 and others) | Splunk

https://www.splunk.com/en_us/blog/bulletins/splunk-security-advisory-for-apache-log4j-cve-2021-44228.html
Splunk Security Advisory for Apache Log4j (CVE-2021-44228, CVE-2021-45046 and others) | Splunk

BlueTeam CheatSheet * Log4Shell* | Last updated: 2021-12-20 2238 UTC · GitHub

https://gist.github.com/SwitHak/b66db3a06c2955a9cb71a8718970c592
BlueTeam CheatSheet * Log4Shell* | Last updated: 2021-12-20 2238 UTC · GitHub

Statement from CISA Director Easterly on “Log4j” Vulnerability | CISA

https://www.cisa.gov/news/2021/12/11/statement-cisa-director-easterly-log4j-vulnerability
Statement from CISA Director Easterly on “Log4j” Vulnerability | CISA

Zero-Day Exploit Targeting Popular Java Library Log4j

https://www.govcert.admin.ch/blog/zero-day-exploit-targeting-popular-java-library-log4j/
Zero-Day Exploit Targeting Popular Java Library Log4j

Invoke-noPac.ps1 · GitHub

https://gist.github.com/S3cur3Th1sSh1t/0ed2fb0b5ae485b68cbc50e89581baa6
Invoke-noPac.ps1 · GitHub

Canarytokens

https://canarytokens.org
Canarytokens

Environment variables to configure the AWS CLI - AWS Command Line Interface

https://docs.aws.amazon.com/cli/latest/userguide/cli-configure-envvars.html
Environment variables to configure the AWS CLI - AWS Command Line Interface

Guidance for preventing, detecting, and hunting for exploitation of the Log4j 2 vulnerability - Microsoft Security Blog

https://www.microsoft.com/security/blog/2021/12/11/guidance-for-preventing-detecting-and-hunting-for-cve-2021-44228-log4j-2-exploitation/
Guidance for preventing, detecting, and hunting for exploitation of the Log4j 2 vulnerability - Microsoft Security Blog