<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Log4j in Panorama Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/panorama-discussions/log4j/m-p/454707#M588</link>
    <description>&lt;P&gt;What would I look for in logs if I were looking to see we had already been owned by this?&lt;/P&gt;</description>
    <pubDate>Tue, 21 Dec 2021 14:05:04 GMT</pubDate>
    <dc:creator>RobertShawver</dc:creator>
    <dc:date>2021-12-21T14:05:04Z</dc:date>
    <item>
      <title>Log4j</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/log4j/m-p/454707#M588</link>
      <description>&lt;P&gt;What would I look for in logs if I were looking to see we had already been owned by this?&lt;/P&gt;</description>
      <pubDate>Tue, 21 Dec 2021 14:05:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/log4j/m-p/454707#M588</guid>
      <dc:creator>RobertShawver</dc:creator>
      <dc:date>2021-12-21T14:05:04Z</dc:date>
    </item>
    <item>
      <title>Re: Log4j</title>
      <link>https://live.paloaltonetworks.com/t5/panorama-discussions/log4j/m-p/454730#M589</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The default action of the threat prevention profile was to drop the traffic that complied with the signature so you should be ok, however if looking for evidence for log4j traffic a good place to start would either LDAP or rmi traffic going either sourced from or directed to an untrusted network or any network that it shouldn't be, these are the mechanisms by which it was exploited, there is a video &lt;A title="Log4j Mitigation" href="https://youtu.be/4TF2ec8veYM" target="_blank" rel="noopener"&gt;here&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;please let me know if this is of any use.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Dec 2021 15:24:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/panorama-discussions/log4j/m-p/454730#M589</guid>
      <dc:creator>laurence64</dc:creator>
      <dc:date>2021-12-21T15:24:52Z</dc:date>
    </item>
  </channel>
</rss>

