Log4Shell CVE-2021-44228 JNDI LDAP/RMI/DNS Injection in HTTP Headers
This rule detects attempts to exploit the Log4Shell vulnerability (CVE-2021-44228) by monitoring HTTP headers (User-Agent, X-Forwarded-For, Referer) for JNDI lookup strings. The JNDI lookup mechanism in vulnerable Log4j libraries allows an attacker to execute arbitrary code by pointing the lookup to a malicious LDAP, RMI, or DNS server.
Suricata

