Forum Discussion
stmarko
Jan 12, 2022Copper Contributor
Can Defender for Endpoint detect JNDI Lookup workaround
Hi, can Defender for Endpoint detect, that JNDI lookup workaround was implemented on log4j library ? Will venerability disappear in venerability dashboard or device software inventory when J...
David_Caddick
Jan 12, 2022Brass Contributor
Here ya go:
https://www.microsoft.com/security/blog/2021/12/11/guidance-for-preventing-detecting-and-hunting-for-cve-2021-44228-log4j-2-exploitation/#TVM-mitigation
https://www.microsoft.com/security/blog/2021/12/11/guidance-for-preventing-detecting-and-hunting-for-cve-2021-44228-log4j-2-exploitation/#TVM-mitigation
- stmarkoJan 17, 2022Copper Contributor
Hi David, I think this Mitigation status works only when you click on Mitigation option in Defender and
Defender agent applies the JNDL lookup workaround.
My question was, can Defender detect when JNDL Lookup workaround is performed manually by server admins.