<?xml version="1.0"?>
<rss version="2.0">
   <channel>
      <title>Log4j CVE-2021-44228 by </title>
      <link>https://padlet.com/hsbjtq26mq/uuux6oa1eem04zou</link>
      <description>Organisations Vulnerability Response </description>
      <language>en-us</language>
      <pubDate>2022-04-23 12:35:36 UTC</pubDate>
      <lastBuildDate>2022-04-25 12:26:27 UTC</lastBuildDate>
      <webMaster>hello@padlet.com</webMaster>
      <image>
         <url>https://padlet.net/icons/png/1f575-2642.png</url>
      </image>
      <item>
         <title>Back Up Data </title>
         <author>hsbjtq26mq</author>
         <link>https://padlet.com/hsbjtq26mq/uuux6oa1eem04zou/wish/2154539144</link>
         <description><![CDATA[<div>If data is kept by attackers for ransomeware, a good back up will deter this. </div>]]></description>
         <enclosure url="" />
         <pubDate>2022-04-23 12:41:39 UTC</pubDate>
         <guid>https://padlet.com/hsbjtq26mq/uuux6oa1eem04zou/wish/2154539144</guid>
      </item>
      <item>
         <title>Staff Training  </title>
         <author>hsbjtq26mq</author>
         <link>https://padlet.com/hsbjtq26mq/uuux6oa1eem04zou/wish/2154539969</link>
         <description><![CDATA[<div>Staff should be aware to spot key signatures of Log4j attacks </div>]]></description>
         <enclosure url="" />
         <pubDate>2022-04-23 12:43:32 UTC</pubDate>
         <guid>https://padlet.com/hsbjtq26mq/uuux6oa1eem04zou/wish/2154539969</guid>
      </item>
      <item>
         <title>CVE 2021-44228:</title>
         <author>hsbjtq26mq</author>
         <link>https://padlet.com/hsbjtq26mq/uuux6oa1eem04zou/wish/2154540348</link>
         <description><![CDATA[<div>&nbsp;Log4Shell - can be exploited from remote by an unauthenticated adversary to executed arbitrary code (remote code execution – RCE)CRITICALITY - score of 10 (out of 10)</div>]]></description>
         <enclosure url="" />
         <pubDate>2022-04-23 12:44:23 UTC</pubDate>
         <guid>https://padlet.com/hsbjtq26mq/uuux6oa1eem04zou/wish/2154540348</guid>
      </item>
      <item>
         <title>Restricted PowerShell </title>
         <author>hsbjtq26mq</author>
         <link>https://padlet.com/hsbjtq26mq/uuux6oa1eem04zou/wish/2154540906</link>
         <description><![CDATA[<div>Restrict the powerful commands that can be used in the power shell on workstations. </div>]]></description>
         <enclosure url="" />
         <pubDate>2022-04-23 12:45:40 UTC</pubDate>
         <guid>https://padlet.com/hsbjtq26mq/uuux6oa1eem04zou/wish/2154540906</guid>
      </item>
      <item>
         <title>Employ Back up Servers</title>
         <author>hsbjtq26mq</author>
         <link>https://padlet.com/hsbjtq26mq/uuux6oa1eem04zou/wish/2154543953</link>
         <description><![CDATA[<div>If Web servers are attacked, they may become non-operational or the digital forensic team will need to shut them down for evidence collection<br><br></div>]]></description>
         <enclosure url="" />
         <pubDate>2022-04-23 12:52:20 UTC</pubDate>
         <guid>https://padlet.com/hsbjtq26mq/uuux6oa1eem04zou/wish/2154543953</guid>
      </item>
      <item>
         <title>Check Public Internet Exposure to Java software</title>
         <author>hsbjtq26mq</author>
         <link>https://padlet.com/hsbjtq26mq/uuux6oa1eem04zou/wish/2154548296</link>
         <description><![CDATA[<div>Are the Java processes using these libraries directly accessible from the internet?</div>]]></description>
         <enclosure url="" />
         <pubDate>2022-04-23 13:01:04 UTC</pubDate>
         <guid>https://padlet.com/hsbjtq26mq/uuux6oa1eem04zou/wish/2154548296</guid>
      </item>
      <item>
         <title>Sensitive Data Access</title>
         <author>hsbjtq26mq</author>
         <link>https://padlet.com/hsbjtq26mq/uuux6oa1eem04zou/wish/2154548499</link>
         <description><![CDATA[<div>Do the vulnerable Java processes access critical databases or file systems in the environment?</div>]]></description>
         <enclosure url="" />
         <pubDate>2022-04-23 13:01:30 UTC</pubDate>
         <guid>https://padlet.com/hsbjtq26mq/uuux6oa1eem04zou/wish/2154548499</guid>
      </item>
      <item>
         <title>Create an Application List</title>
         <author>hsbjtq26mq</author>
         <link>https://padlet.com/hsbjtq26mq/uuux6oa1eem04zou/wish/2154548689</link>
         <description><![CDATA[<div>Which applications use these java log4j libraries?</div>]]></description>
         <enclosure url="" />
         <pubDate>2022-04-23 13:01:56 UTC</pubDate>
         <guid>https://padlet.com/hsbjtq26mq/uuux6oa1eem04zou/wish/2154548689</guid>
      </item>
      <item>
         <title>Look for Java Making Network Connections</title>
         <author>hsbjtq26mq</author>
         <link>https://padlet.com/hsbjtq26mq/uuux6oa1eem04zou/wish/2154549699</link>
         <description><![CDATA[<div>&nbsp;QQL queries in Qualys EDR can isolate hosts which have these types of connection</div>]]></description>
         <enclosure url="" />
         <pubDate>2022-04-23 13:04:15 UTC</pubDate>
         <guid>https://padlet.com/hsbjtq26mq/uuux6oa1eem04zou/wish/2154549699</guid>
      </item>
      <item>
         <title>Look for Java Calling Suspicious Processes</title>
         <author>hsbjtq26mq</author>
         <link>https://padlet.com/hsbjtq26mq/uuux6oa1eem04zou/wish/2154552607</link>
         <description><![CDATA[<div>Commonly you will see something such as scripting languages or data transfer utilities to call for processes. QQL queries can be used to find such activity</div>]]></description>
         <enclosure url="" />
         <pubDate>2022-04-23 13:09:31 UTC</pubDate>
         <guid>https://padlet.com/hsbjtq26mq/uuux6oa1eem04zou/wish/2154552607</guid>
      </item>
      <item>
         <title>Microsoft 365 Defender</title>
         <author>hsbjtq26mq</author>
         <link>https://padlet.com/hsbjtq26mq/uuux6oa1eem04zou/wish/2154553297</link>
         <description><![CDATA[<div>Microsoft 365 Defender coordinates multiple security solutions that detect components of observed attacks taking advantage of this vulnerability, from exploitation attempts to remote code execution and post-exploitation activity.</div>]]></description>
         <enclosure url="https://padlet-uploads.storage.googleapis.com/1675643565/3a1a4563310c48fcfd0443ad5a89601f/Screenshot_2022_04_23_at_14_10_42.png" />
         <pubDate>2022-04-23 13:10:52 UTC</pubDate>
         <guid>https://padlet.com/hsbjtq26mq/uuux6oa1eem04zou/wish/2154553297</guid>
      </item>
      <item>
         <title>Microsoft Defender For End-Point</title>
         <author>hsbjtq26mq</author>
         <link>https://padlet.com/hsbjtq26mq/uuux6oa1eem04zou/wish/2154554676</link>
         <description><![CDATA[<div>Users of Microsoft Defender for Endpoint can turn on the following attack surface reduction rule to block or audit some observed activity associated with this threat.<br><br><br></div>]]></description>
         <enclosure url="" />
         <pubDate>2022-04-23 13:13:26 UTC</pubDate>
         <guid>https://padlet.com/hsbjtq26mq/uuux6oa1eem04zou/wish/2154554676</guid>
      </item>
      <item>
         <title>Use a log inspection rule</title>
         <author>hsbjtq26mq</author>
         <link>https://padlet.com/hsbjtq26mq/uuux6oa1eem04zou/wish/2154555133</link>
         <description><![CDATA[<div><strong>consists of a list of files to monitor for changes and a set of conditions to be met for the rule to trigger</strong>.&nbsp;<br><br>The log inspection rule 1011241 – Apache Log4j Remote Code Execution Vulnerability (CVE-2021-44228) looks for JNDI payloads in the access logs, with the default path being /var/log/*/access. log.</div>]]></description>
         <enclosure url="" />
         <pubDate>2022-04-23 13:14:14 UTC</pubDate>
         <guid>https://padlet.com/hsbjtq26mq/uuux6oa1eem04zou/wish/2154555133</guid>
      </item>
      <item>
         <title>Check Indicators of Compromise </title>
         <author>hsbjtq26mq</author>
         <link>https://padlet.com/hsbjtq26mq/uuux6oa1eem04zou/wish/2154556285</link>
         <description><![CDATA[<div>Infoblox provides the following list of indicators of compromise (IOCs) related to Log4j exploitation activity.</div>]]></description>
         <enclosure url="https://blogs.infoblox.com/cyber-threat-intelligence/cyber-campaign-briefs/log4j-indicators-of-compromise-to-date/" />
         <pubDate>2022-04-23 13:16:06 UTC</pubDate>
         <guid>https://padlet.com/hsbjtq26mq/uuux6oa1eem04zou/wish/2154556285</guid>
      </item>
      <item>
         <title>Apache Tomcat servers</title>
         <author>hsbjtq26mq</author>
         <link>https://padlet.com/hsbjtq26mq/uuux6oa1eem04zou/wish/2154561772</link>
         <description><![CDATA[<div>Allows for redirection of traffic and remote access to server. <br><br><strong><em>Version &lt; 9.X was vulnerable.</em></strong></div>]]></description>
         <enclosure url="https://www.tomitribe.com/blog/cve-2021-44228-log4shell-vulnerability/" />
         <pubDate>2022-04-23 13:25:05 UTC</pubDate>
         <guid>https://padlet.com/hsbjtq26mq/uuux6oa1eem04zou/wish/2154561772</guid>
      </item>
      <item>
         <title>Cisco Firewall Threat Defence (FTD)</title>
         <author>hsbjtq26mq</author>
         <link>https://padlet.com/hsbjtq26mq/uuux6oa1eem04zou/wish/2154562977</link>
         <description><![CDATA[<div>Attacks on this would allow attackers to disable firewalls to allow all traffic entering the network. <br><br><strong><em>Version 6.6.0 is vulnerable to log4shell</em></strong></div>]]></description>
         <enclosure url="https://advancedfirewallsolutions.com/cisco-vulnerable-to-log4j-patch/" />
         <pubDate>2022-04-23 13:27:09 UTC</pubDate>
         <guid>https://padlet.com/hsbjtq26mq/uuux6oa1eem04zou/wish/2154562977</guid>
      </item>
      <item>
         <title>Dell EMC Connectrix </title>
         <author>hsbjtq26mq</author>
         <link>https://padlet.com/hsbjtq26mq/uuux6oa1eem04zou/wish/2154563998</link>
         <description><![CDATA[<div><strong><em>Version &lt; 3 are vulnerable to log4shell</em></strong></div>]]></description>
         <enclosure url="https://www.dell.com/support/kbdoc/en-uk/000194414/dell-response-to-apache-log4j-remote-code-execution-vulnerability" />
         <pubDate>2022-04-23 13:29:04 UTC</pubDate>
         <guid>https://padlet.com/hsbjtq26mq/uuux6oa1eem04zou/wish/2154563998</guid>
      </item>
      <item>
         <title>AWS Servers</title>
         <author>hsbjtq26mq</author>
         <link>https://padlet.com/hsbjtq26mq/uuux6oa1eem04zou/wish/2154564624</link>
         <description><![CDATA[<div>Allowed for full host take over, meaning data can be stolen or the integrity can be changed.<br><br><strong><em>Version&nbsp; &lt; 2.5 Vulnerable to Log4shell</em></strong></div>]]></description>
         <enclosure url="https://portswigger.net/daily-swig/vulnerability-aws-log4shell-hot-patch-allowed-full-host-takeover" />
         <pubDate>2022-04-23 13:30:16 UTC</pubDate>
         <guid>https://padlet.com/hsbjtq26mq/uuux6oa1eem04zou/wish/2154564624</guid>
      </item>
      <item>
         <title>Adobe Coldfusion</title>
         <author>hsbjtq26mq</author>
         <link>https://padlet.com/hsbjtq26mq/uuux6oa1eem04zou/wish/2154565425</link>
         <description><![CDATA[<div>Allowed for remote access to workstations.<br><br><strong><em>Vulnerable&nbsp; version &lt; 1.2.15</em></strong></div>]]></description>
         <enclosure url="https://helpx.adobe.com/coldfusion/kb/log4j-vulnerability-coldfusion.html" />
         <pubDate>2022-04-23 13:31:53 UTC</pubDate>
         <guid>https://padlet.com/hsbjtq26mq/uuux6oa1eem04zou/wish/2154565425</guid>
      </item>
      <item>
         <title>Apache Tomcat</title>
         <author>hsbjtq26mq</author>
         <link>https://padlet.com/hsbjtq26mq/uuux6oa1eem04zou/wish/2154566416</link>
         <description><![CDATA[<div>Vulnerability Fixed in Apache Tomcat versions 9.x</div>]]></description>
         <enclosure url="https://tomcat.apache.org/security-9.html" />
         <pubDate>2022-04-23 13:33:52 UTC</pubDate>
         <guid>https://padlet.com/hsbjtq26mq/uuux6oa1eem04zou/wish/2154566416</guid>
      </item>
      <item>
         <title>Cisco </title>
         <author>hsbjtq26mq</author>
         <link>https://padlet.com/hsbjtq26mq/uuux6oa1eem04zou/wish/2154567350</link>
         <description><![CDATA[<div>Developer response, all Cisco products have been updated </div>]]></description>
         <enclosure url="https://blogs.cisco.com/developer/log4jdevresponse01" />
         <pubDate>2022-04-23 13:35:51 UTC</pubDate>
         <guid>https://padlet.com/hsbjtq26mq/uuux6oa1eem04zou/wish/2154567350</guid>
      </item>
      <item>
         <title>Dell Response </title>
         <author>hsbjtq26mq</author>
         <link>https://padlet.com/hsbjtq26mq/uuux6oa1eem04zou/wish/2154567722</link>
         <description><![CDATA[]]></description>
         <enclosure url="https://www.dell.com/support/kbdoc/en-uk/000194414/dell-response-to-apache-log4j-remote-code-execution-vulnerability" />
         <pubDate>2022-04-23 13:36:39 UTC</pubDate>
         <guid>https://padlet.com/hsbjtq26mq/uuux6oa1eem04zou/wish/2154567722</guid>
      </item>
      <item>
         <title>AWS Servers Response</title>
         <author>hsbjtq26mq</author>
         <link>https://padlet.com/hsbjtq26mq/uuux6oa1eem04zou/wish/2154568183</link>
         <description><![CDATA[<div>Version 6 was the latest update implemented to deal with CVE-2021-44288</div>]]></description>
         <enclosure url="https://aws.amazon.com/security/security-bulletins/AWS-2021-006/" />
         <pubDate>2022-04-23 13:37:42 UTC</pubDate>
         <guid>https://padlet.com/hsbjtq26mq/uuux6oa1eem04zou/wish/2154568183</guid>
      </item>
      <item>
         <title>Adobe Coldfusion Response </title>
         <author>hsbjtq26mq</author>
         <link>https://padlet.com/hsbjtq26mq/uuux6oa1eem04zou/wish/2154568561</link>
         <description><![CDATA[]]></description>
         <enclosure url="https://helpx.adobe.com/coldfusion/kb/log4j-vulnerability-coldfusion.html" />
         <pubDate>2022-04-23 13:38:31 UTC</pubDate>
         <guid>https://padlet.com/hsbjtq26mq/uuux6oa1eem04zou/wish/2154568561</guid>
      </item>
      <item>
         <title>Are the organization&#39;s products with Log4j are vulnerable?</title>
         <author>hsbjtq26mq</author>
         <link>https://padlet.com/hsbjtq26mq/uuux6oa1eem04zou/wish/2154572387</link>
         <description><![CDATA[<div>Check Here</div>]]></description>
         <enclosure url="https://github.com/cisagov/log4j-affected-db" />
         <pubDate>2022-04-23 13:46:05 UTC</pubDate>
         <guid>https://padlet.com/hsbjtq26mq/uuux6oa1eem04zou/wish/2154572387</guid>
      </item>
      <item>
         <title>Restrict egress capabilities from applications and servers.</title>
         <author>hsbjtq26mq</author>
         <link>https://padlet.com/hsbjtq26mq/uuux6oa1eem04zou/wish/2154573366</link>
         <description><![CDATA[<div>This step will&nbsp; prevent the Java service from having the ability to download a malicious class file via LDAP, LDAPS, RMI, or DNS.</div>]]></description>
         <enclosure url="" />
         <pubDate>2022-04-23 13:47:53 UTC</pubDate>
         <guid>https://padlet.com/hsbjtq26mq/uuux6oa1eem04zou/wish/2154573366</guid>
      </item>
      <item>
         <title>Reduce attack surface on applications running impacted software. </title>
         <author>hsbjtq26mq</author>
         <link>https://padlet.com/hsbjtq26mq/uuux6oa1eem04zou/wish/2154575006</link>
         <description><![CDATA[<div>Limit applications interfaces to prevent leveraging of interfaces </div>]]></description>
         <enclosure url="" />
         <pubDate>2022-04-23 13:50:54 UTC</pubDate>
         <guid>https://padlet.com/hsbjtq26mq/uuux6oa1eem04zou/wish/2154575006</guid>
      </item>
      <item>
         <title>Implement Current Patches For All Software </title>
         <author>hsbjtq26mq</author>
         <link>https://padlet.com/hsbjtq26mq/uuux6oa1eem04zou/wish/2154575425</link>
         <description><![CDATA[]]></description>
         <enclosure url="" />
         <pubDate>2022-04-23 13:51:44 UTC</pubDate>
         <guid>https://padlet.com/hsbjtq26mq/uuux6oa1eem04zou/wish/2154575425</guid>
      </item>
      <item>
         <title>Isolate System </title>
         <author>hsbjtq26mq</author>
         <link>https://padlet.com/hsbjtq26mq/uuux6oa1eem04zou/wish/2154576038</link>
         <description><![CDATA[<div>Affected software should be powered off and removed from the network to prevent the spreading of the attack</div>]]></description>
         <enclosure url="" />
         <pubDate>2022-04-23 13:52:53 UTC</pubDate>
         <guid>https://padlet.com/hsbjtq26mq/uuux6oa1eem04zou/wish/2154576038</guid>
      </item>
      <item>
         <title>Apply latest patches to software</title>
         <author>hsbjtq26mq</author>
         <link>https://padlet.com/hsbjtq26mq/uuux6oa1eem04zou/wish/2154576266</link>
         <description><![CDATA[]]></description>
         <enclosure url="" />
         <pubDate>2022-04-23 13:53:15 UTC</pubDate>
         <guid>https://padlet.com/hsbjtq26mq/uuux6oa1eem04zou/wish/2154576266</guid>
      </item>
      <item>
         <title>Virtual Machines</title>
         <author>hsbjtq26mq</author>
         <link>https://padlet.com/hsbjtq26mq/uuux6oa1eem04zou/wish/2154577021</link>
         <description><![CDATA[<div>Power Down Virtual Machine and prepare a clone of current state for evidence. If possible restore Virtual machine from the last known good screenshot. </div>]]></description>
         <enclosure url="" />
         <pubDate>2022-04-23 13:54:42 UTC</pubDate>
         <guid>https://padlet.com/hsbjtq26mq/uuux6oa1eem04zou/wish/2154577021</guid>
      </item>
      <item>
         <title>Minimize the attack area</title>
         <author>hsbjtq26mq</author>
         <link>https://padlet.com/hsbjtq26mq/uuux6oa1eem04zou/wish/2154580379</link>
         <description><![CDATA[<div>- Switch to a virtual machine&nbsp;<br><br>- Or use an account with the least amount of privileges </div>]]></description>
         <enclosure url="" />
         <pubDate>2022-04-23 14:00:49 UTC</pubDate>
         <guid>https://padlet.com/hsbjtq26mq/uuux6oa1eem04zou/wish/2154580379</guid>
      </item>
      <item>
         <title>Install Firewall</title>
         <author>hsbjtq26mq</author>
         <link>https://padlet.com/hsbjtq26mq/uuux6oa1eem04zou/wish/2154580682</link>
         <description><![CDATA[<div>Use firewalls to isolate the environment </div>]]></description>
         <enclosure url="" />
         <pubDate>2022-04-23 14:01:22 UTC</pubDate>
         <guid>https://padlet.com/hsbjtq26mq/uuux6oa1eem04zou/wish/2154580682</guid>
      </item>
      <item>
         <title>Install Recent Patches</title>
         <author>hsbjtq26mq</author>
         <link>https://padlet.com/hsbjtq26mq/uuux6oa1eem04zou/wish/2154580916</link>
         <description><![CDATA[]]></description>
         <enclosure url="" />
         <pubDate>2022-04-23 14:01:48 UTC</pubDate>
         <guid>https://padlet.com/hsbjtq26mq/uuux6oa1eem04zou/wish/2154580916</guid>
      </item>
      <item>
         <title>Import Back-ups</title>
         <author>hsbjtq26mq</author>
         <link>https://padlet.com/hsbjtq26mq/uuux6oa1eem04zou/wish/2154583511</link>
         <description><![CDATA[<div>Import back up webservers, data and other information</div>]]></description>
         <enclosure url="" />
         <pubDate>2022-04-23 14:06:16 UTC</pubDate>
         <guid>https://padlet.com/hsbjtq26mq/uuux6oa1eem04zou/wish/2154583511</guid>
      </item>
      <item>
         <title>Monitor Network</title>
         <author>hsbjtq26mq</author>
         <link>https://padlet.com/hsbjtq26mq/uuux6oa1eem04zou/wish/2154584347</link>
         <description><![CDATA[<div>Monitor Network for any unknown packets, abnormal hosts or network activity. </div>]]></description>
         <enclosure url="" />
         <pubDate>2022-04-23 14:07:44 UTC</pubDate>
         <guid>https://padlet.com/hsbjtq26mq/uuux6oa1eem04zou/wish/2154584347</guid>
      </item>
      <item>
         <title>Employ Active Defence</title>
         <author>hsbjtq26mq</author>
         <link>https://padlet.com/hsbjtq26mq/uuux6oa1eem04zou/wish/2154585964</link>
         <description><![CDATA[<div>These can include:<br><br>- Boarder Gateway Protocol Monitoring&nbsp;<br><br>- Honeypot used to trick attackers to targeting a fake system  </div>]]></description>
         <enclosure url="" />
         <pubDate>2022-04-23 14:10:34 UTC</pubDate>
         <guid>https://padlet.com/hsbjtq26mq/uuux6oa1eem04zou/wish/2154585964</guid>
      </item>
      <item>
         <title>Check For Any EDR/XDR Detections Frequently </title>
         <author>hsbjtq26mq</author>
         <link>https://padlet.com/hsbjtq26mq/uuux6oa1eem04zou/wish/2154587149</link>
         <description><![CDATA[]]></description>
         <enclosure url="" />
         <pubDate>2022-04-23 14:12:45 UTC</pubDate>
         <guid>https://padlet.com/hsbjtq26mq/uuux6oa1eem04zou/wish/2154587149</guid>
      </item>
      <item>
         <title>Dealing with Evidence </title>
         <author>hsbjtq26mq</author>
         <link>https://padlet.com/hsbjtq26mq/uuux6oa1eem04zou/wish/2154589349</link>
         <description><![CDATA[<div>- Record Cryptographic hash of system <br>- Switch systems to backup (if possible)&nbsp;<br>- Disconnect System from network&nbsp;<br>- Leave systems in the state they're in for evidence collection<br>- Document process&nbsp;<br><br></div>]]></description>
         <enclosure url="" />
         <pubDate>2022-04-23 14:16:40 UTC</pubDate>
         <guid>https://padlet.com/hsbjtq26mq/uuux6oa1eem04zou/wish/2154589349</guid>
      </item>
      <item>
         <title>Evidence Storing </title>
         <author>hsbjtq26mq</author>
         <link>https://padlet.com/hsbjtq26mq/uuux6oa1eem04zou/wish/2154589753</link>
         <description><![CDATA[<div>- Stored in a room with proper physical security </div>]]></description>
         <enclosure url="" />
         <pubDate>2022-04-23 14:17:19 UTC</pubDate>
         <guid>https://padlet.com/hsbjtq26mq/uuux6oa1eem04zou/wish/2154589753</guid>
      </item>
      <item>
         <title>Copying Digital Evidence</title>
         <author>hsbjtq26mq</author>
         <link>https://padlet.com/hsbjtq26mq/uuux6oa1eem04zou/wish/2154590787</link>
         <description><![CDATA[<div>- Digital Forensics team will use hard-drive duplicators or software imaging tools to clone the entire hard drive for analysis.&nbsp;<br><br>-&nbsp; The copy must be stored on another form of media to keep the original integrity.<br><br>- Must be stored on "clean" media that doesn't contain information already </div>]]></description>
         <enclosure url="" />
         <pubDate>2022-04-23 14:19:00 UTC</pubDate>
         <guid>https://padlet.com/hsbjtq26mq/uuux6oa1eem04zou/wish/2154590787</guid>
      </item>
      <item>
         <title>Install Write-blockers </title>
         <author>hsbjtq26mq</author>
         <link>https://padlet.com/hsbjtq26mq/uuux6oa1eem04zou/wish/2154591359</link>
         <description><![CDATA[<div>&nbsp;<br>prevent any change to the data on the device or media, so that data may be viewed but nothing can be changed or added.</div>]]></description>
         <enclosure url="" />
         <pubDate>2022-04-23 14:20:05 UTC</pubDate>
         <guid>https://padlet.com/hsbjtq26mq/uuux6oa1eem04zou/wish/2154591359</guid>
      </item>
      <item>
         <title>Disconnect Devices/Services </title>
         <author>hsbjtq26mq</author>
         <link>https://padlet.com/hsbjtq26mq/uuux6oa1eem04zou/wish/2154592708</link>
         <description><![CDATA[<div>- Wireless devices must be examined in isolation chamber (or faraday bag) to prevent any contamination&nbsp;<br><br>- Device must be connected to analyse software in chamber</div>]]></description>
         <enclosure url="" />
         <pubDate>2022-04-23 14:22:18 UTC</pubDate>
         <guid>https://padlet.com/hsbjtq26mq/uuux6oa1eem04zou/wish/2154592708</guid>
      </item>
      <item>
         <title>Extraction Methods</title>
         <author>hsbjtq26mq</author>
         <link>https://padlet.com/hsbjtq26mq/uuux6oa1eem04zou/wish/2154595537</link>
         <description><![CDATA[<div>Determines highly on the data, software and hardware the attack has happened on. </div>]]></description>
         <enclosure url="" />
         <pubDate>2022-04-23 14:25:39 UTC</pubDate>
         <guid>https://padlet.com/hsbjtq26mq/uuux6oa1eem04zou/wish/2154595537</guid>
      </item>
      <item>
         <title>Analyse Methods</title>
         <author>hsbjtq26mq</author>
         <link>https://padlet.com/hsbjtq26mq/uuux6oa1eem04zou/wish/2154599879</link>
         <description><![CDATA[<div>Disk can be forensically analysed using specialised software.&nbsp;This could include FTK imager, Autopsy or commercial products that will scan your network and detect any red flags </div>]]></description>
         <enclosure url="" />
         <pubDate>2022-04-23 14:32:35 UTC</pubDate>
         <guid>https://padlet.com/hsbjtq26mq/uuux6oa1eem04zou/wish/2154599879</guid>
      </item>
      <item>
         <title>Log4j Vulnerability Scanner </title>
         <author>hsbjtq26mq</author>
         <link>https://padlet.com/hsbjtq26mq/uuux6oa1eem04zou/wish/2154608466</link>
         <description><![CDATA[]]></description>
         <enclosure url="https://github.com/cisagov/log4j-scanner" />
         <pubDate>2022-04-23 14:47:49 UTC</pubDate>
         <guid>https://padlet.com/hsbjtq26mq/uuux6oa1eem04zou/wish/2154608466</guid>
      </item>
      <item>
         <title>How Log4shell works </title>
         <author>hsbjtq26mq</author>
         <link>https://padlet.com/hsbjtq26mq/uuux6oa1eem04zou/wish/2154610570</link>
         <description><![CDATA[<div>How the attacks abuses the vulnerability </div>]]></description>
         <enclosure url="https://www.kratikal.com/blog/wp-content/uploads/2021/12/Log4j-Shell.jpg" />
         <pubDate>2022-04-23 14:51:47 UTC</pubDate>
         <guid>https://padlet.com/hsbjtq26mq/uuux6oa1eem04zou/wish/2154610570</guid>
      </item>
      <item>
         <title>Are You Vulnerable ?</title>
         <author>hsbjtq26mq</author>
         <link>https://padlet.com/hsbjtq26mq/uuux6oa1eem04zou/wish/2154611050</link>
         <description><![CDATA[]]></description>
         <enclosure url="https://board.flexibleir.com/cfs/files/attachments/EkB9AcpzmuAMaZGiF/1639922328803-mindmap.jfif?token=eyJhdXRoVG9rZW4iOiIifQ%3D%3D" />
         <pubDate>2022-04-23 14:52:39 UTC</pubDate>
         <guid>https://padlet.com/hsbjtq26mq/uuux6oa1eem04zou/wish/2154611050</guid>
      </item>
      <item>
         <title>Vulnerability Scanner for Organisations Services</title>
         <author>hsbjtq26mq</author>
         <link>https://padlet.com/hsbjtq26mq/uuux6oa1eem04zou/wish/2156384890</link>
         <description><![CDATA[]]></description>
         <enclosure url="https://github.com/silentsignal/burp-log4shell" />
         <pubDate>2022-04-25 12:00:26 UTC</pubDate>
         <guid>https://padlet.com/hsbjtq26mq/uuux6oa1eem04zou/wish/2156384890</guid>
      </item>
      <item>
         <title>Tenable Scanner</title>
         <author>hsbjtq26mq</author>
         <link>https://padlet.com/hsbjtq26mq/uuux6oa1eem04zou/wish/2156385964</link>
         <description><![CDATA[]]></description>
         <enclosure url="https://community.tenable.com/s/article/Log4Shell-FAQs" />
         <pubDate>2022-04-25 12:01:15 UTC</pubDate>
         <guid>https://padlet.com/hsbjtq26mq/uuux6oa1eem04zou/wish/2156385964</guid>
      </item>
      <item>
         <title>Log4shell FAQ</title>
         <author>hsbjtq26mq</author>
         <link>https://padlet.com/hsbjtq26mq/uuux6oa1eem04zou/wish/2156386879</link>
         <description><![CDATA[]]></description>
         <enclosure url="https://community.tenable.com/s/article/Log4Shell-FAQs" />
         <pubDate>2022-04-25 12:01:59 UTC</pubDate>
         <guid>https://padlet.com/hsbjtq26mq/uuux6oa1eem04zou/wish/2156386879</guid>
      </item>
      <item>
         <title>Greenbone Log4shell Scanner</title>
         <author>hsbjtq26mq</author>
         <link>https://padlet.com/hsbjtq26mq/uuux6oa1eem04zou/wish/2156387754</link>
         <description><![CDATA[]]></description>
         <enclosure url="https://www.greenbone.net/en/scanning-for-vulnerabilities-like-log4shell/" />
         <pubDate>2022-04-25 12:02:46 UTC</pubDate>
         <guid>https://padlet.com/hsbjtq26mq/uuux6oa1eem04zou/wish/2156387754</guid>
      </item>
      <item>
         <title>List of Indicators of Compromise</title>
         <author>hsbjtq26mq</author>
         <link>https://padlet.com/hsbjtq26mq/uuux6oa1eem04zou/wish/2156421656</link>
         <description><![CDATA[]]></description>
         <enclosure url="https://www.nozominetworks.com/blog/critical-log4shell-apache-log4j-zero-day-attack-analysis/" />
         <pubDate>2022-04-25 12:26:19 UTC</pubDate>
         <guid>https://padlet.com/hsbjtq26mq/uuux6oa1eem04zou/wish/2156421656</guid>
      </item>
   </channel>
</rss>
