Skip to main content
FSM_FTNT
Staff
Staff
December 14, 2021

Technical Tip: How to use FortiSIEM to detect activities related to the log4shell vulnerability CVE-2021-44228

  • December 14, 2021
  • 0 replies
  • 5443 views
Description

This article describes how to use custom Rules and Reports to help detect activity related to the log4j vulnerability CVE-2021-44228.

 

What is included in Fortinet_FortiSIEM-log4j-Detection-v1.zip?


1) FortiSIEM_log4j_Rules_v2.xml.


These Rules help identify exploit attempts detected by FortiGate's IPS, or Events categorised as Permitted Traffic with the URI or HTTP content (see rules for specific attributes) that match a particular regex pattern.

 

2) FortiSIEM_log4j_Reports_v2.1.xml.

 

These Reports can be run on a schedule or on-demand and help identify exploit attempts detected by FortiGate's IPS, or Events categorised as Permitted Traffic with the URI or HTTP content (see rules for specific attributes) that match a particular regex pattern.

 

For more information about this attack, see the following FortiGuard Outbreak Alert: FortiGuard Outbreak Alert - Log4j2 Vulnerability

 

Updated: 2021-12-17 - revision 2, changes to the "Log4J Exploit Request Detected By Regex" Rule to increase the scope and reduce false positives.

Updated: 2021-12-20 - no change in content, but revised Report file naming to v2 in line with Solution steps below. The report content remains the same.

Updated: 2021-12-20 - updated Reports to version 2.1. Provides better support for import on some FortiSIEM versions.

Scope The custom Rules and Reports provided can be used in FortiSIEM 6.x.
Solution

All screenshots provided below for illustration purposes are taken from FortiSIEM 6.3.2.

 

1) Download the Fortinet_FortiSIEM-log4j-Detection-v2.zip file (contains 2 file).

 

2) Unzip Fortinet_FortiSIEM-log4j-Detection-v2.zip

 

3) Use FortiSIEM_log4j_Reports_v2.1.xml  as the file to import the Reports
- Navigate to Resource / Reports.
- It is recommended to create a new group under Resource / Reports / Security called 'log4j Exploit Detection' and import reports to this group.
- Select the Import option under More.
- Select FortiSIEM_log4j_Reports_v2.1.xml  and import.

 

4) Use FortiSIEM_log4j_Rules_v2.xml  as the file to import the Rules
- Navigate to Resource / Rules.
- It is recommended to create a new group under Resource / Rules / Security / Threat Hunting is created called 'log4 Exploit Detection' and import the rules to this group.
- Select the Import.
- Select FortiSIEM_log4j_Rules_v2.xml  and import.
- Filter the rules on log4j and ensure it is enabled.

 

 

Imported and enabled Rules

log4j_Rules_v1.png

 

Imported Reports

log4j_Reports_v1.png

 

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!