Log4Shell (CVE-2021-44228) — regulated company
When Log4Shell broke in 2021, CyStrat was on an incident response engagement at a regulated company within hours: analyzing which products contained affected Log4j versions and where they were running — through SIEM analytics as well as ad-hoc analysis scripts. Emergency use cases surfaced several affected systems, and on alert the exploit chain was broken in under five minutes.
- Exposure analysis via SIEM and ad-hoc scripts instead of guesswork
- Ad-hoc blocking from our own threat intelligence built on observed attack attempts
- Continuous monitoring and further ad-hoc response actions in the following weeks
- All attack attempts defended, kill chain stopped at "patient 0" — never a "patient 2", no data exfiltration