> proof-of-concept (PoC) code has evidently been available since March of 2021
This Github repo was for an older vulnerability[1] (CVE-2019-17571).
> monitor web application logs for evidence of attempts to execute methods from remote codebases (i.e. looking for jndi:ldap strings)
As the templates are interpreted recursively, the payload can easily be obfuscated, e.g. using "${${lower:j}${lower:n}..."[2]. I saw e.g. binaryedge's scanner already use that trick.
[1] https://www.cnblogs.com/nice0e3/p/14531327.html [2] https://github.com/tangxiaofeng7/CVE-2021-44228-Apache-Log4j...