Determining Log4J's Impact and Monitoring for Active Exploits

Logo
Presented by

Sanjay Raja, VP Product Marketing and Solutions

About this talk

In early January the US FTC indicated they would significantly fine organizations that do not take steps to remediate the Log4J vulnerability. The problem is Log4J is included broadly in several products, applications, and systems, but the way it is embedded into software makes it difficult to detect whether it is present, can be exploited or is actively being exploited. Apache gave Log4Shell a CVSS severity rating of 10, the highest available score. The vulnerability takes advantage of Log4j's capability to allow requests to arbitrary LDAP and JNDI servers, allowing attackers to execute arbitrary code on a compromised machine. Our research team has broken down how Log4j works, but more importantly what you can do today to detect the vulnerabilities embedded in various systems, and whether they are actually being exploited in order to immediately begin remediation efforts. In the webinar we will cover: - A brief explanation of the Log4j vulnerability (how does it work, who/what is affected) - How to determine whether it is in your environment? - What actions you can take to protect your organization?
Related topics:

More from this channel

Upcoming talks (0)
On-demand talks (89)
Subscribers (6913)
Gurucul is a security analytics company founded in data science that delivers radical clarity about cyber risk. Our REVEAL platform analyzes enterprise data at scale using machine learning and artificial intelligence. Instead of useless alerts, you get real-time, actionable information about true threats and their associated risk. The platform is open, flexible, cloud native and cost optimized. Organizations can save 50% or more while achieving complete data control, visibility, searchability, and analytics within a single console. Industry analysts have recognized our platform as a Visionary in the 2024 Gartner(R) Market Quadrant(TM) for SIEM for the third-consecutive year. Our solutions are used by Global 1000 enterprises and government agencies to minimize their cybersecurity risk. To learn more, visit Gurucul.com and follow us on LinkedIn and Twitter.