please see this reply: https://learn.microsoft.com/en-us/answers/questions/1351962/log4j-vulnerability-exploit-aka-log4shell-ip-ioc
"Log4j vulnerability exploit aka Log4Shell IP IOC involving one user"

Zenzele Mdakane
20
Reputation points
Hi how do we go about resolving ( The detection rule "Log4j vulnerability exploit aka Log4Shell IP IOC involving one user" in Microsoft Sentinel identifies potential exploitation attempts of the Log4Shell vulnerability (CVE-2021-44228) by monitoring for indicators of compromise (IOCs) associated with a specific user account) Suspicious IP Address :185.220.101.25) will blocking the IP address, running full AV scan, request user to change password be the solution or what
Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
1,268 questions