log4j-core › JndiManager.lookup() › attempt: process launch
BLOCKED BEFORE EXECUTION
CODE CONTEXT: FULL ✓
/ 01
Your code has readers. They don't all work for you.
Much of the code running on your servers is open source. Attackers can study the same code your business depends on. AI helps them find and test new ways in.
Same code. Stronger attackers.
/ 02 — THE GAP
On the server. Still a stranger to the code.
Installing EDR on a server doesn't give it an understanding of the application inside. It can flag suspicious activity without identifying the code that caused it.
That gap costs you twice: an attack can blend into normal activity, and the alert can still leave you hunting for the responsible code.
An agent should earn its footprint.
If it uses your server's resources, it should tell you what your code is doing.
Raven connects sensitive activity to the library, function and execution path behind it. That context drives detection, prevention and investigation.
RAVEN VIEW — INSIDE THE SAME PROCESS
REC
java · PID 4211 · opened
log4j-core
jackson
spring-web
openssl
netty
guava
log4j-core
›
JndiManager.lookup()
›
attempted process creation
Blocked by runtime policy · responsible code identified
WHAT MATTER
WHAT MATTERSTYPICAL EDR FOCUSS
RAVEN ADR + RUNTIME PREVENTION
What it sees
Processes, files, memory and network activity
Libraries and functions behind sensitive activity
What triggers detection
Suspicious endpoint and process behavior
Abnormal library behavior and execution paths
What informs blocking
Endpoint behavior and process controls
Library context and policies for sensitive operations
What you investigate
Host and process evidence; code detail varies
Responsible library, function and call path
EDR capabilities vary by vendor, platform and configuration. Blocking uses Raven Runtime Prevention.
/ 04 — PROOF
AI found the opening. Raven blocked the exploit.
CONTROLLED APPLICATION TEST
In a controlled application test, Raven reproduced an AI-discovered Log4j filter bypass and blocked the attempted process creation. No prior knowledge of the exploit. No rule written for it.