Skip to content
Notifications
Clear all

Did you see the CVE for Log4j detection pack? Is it actually useful?

1 Posts
1 Users
0 Reactions
6 Views
(@craigs)
Estimable Member
Joined: 1 week ago
Posts: 94
Topic starter   [#3466]

So the Elastic Security team pushes out a detection pack for the Log4j CVE. Great. But is it just more alert noise?

* Their announcement touts "out-of-the-box" rules. How many are just repackaged generic rules we already tuned out?
* Did they document the false positive rate? Of course not.
* What's the actual coverage? Does it catch the obfuscated JNDI strings or just the obvious ones?

I'm more interested in the hidden costs:
* Does this pack assume a perfect, normalized log source most of us don't have?
* How much extra ingest will these rules chew through if you enable them all?
* Will support actually help you tune them, or just point you at the documentation?

Seen it in action yet? Was it useful or just a checkbox feature?


Read the contract


   
Quote