log4j-scanner
log4j-scanner is a project derived from other members of the open-source community by CISA to help organizations identify potentially vulnerable web services affected by the log4j vulnerabilities. (by cisagov)
log4j-scanner | log4j-tools | |
---|---|---|
9 | 9 | |
1,250 | 169 | |
- | -0.6% | |
4.7 | 0.0 | |
over 1 year ago | about 2 years ago | |
Java | Java | |
- | Apache License 2.0 |
The number of mentions indicates the total number of mentions that we've tracked plus the number of user suggested alternatives.
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
log4j-scanner
Posts with mentions or reviews of log4j-scanner.
We have used some of these posts to build our list of alternatives
and similar projects. The last one was on 2022-07-07.
-
Finding the "practical" component for my thesis on Log4Shell
https://github.com/cisagov/log4j-scanner https://github.com/fullhunt/log4j-scan https://github.com/portswigger/log4shell-scanner
- CISA log4j PS scanner
- So many different log4j scanner tools and scripts posted
-
Understanding and Exploiting Log4J Vulnerability
Alternately you can use cisagov/log4j-scanner to scan for log4j Vulnerability on your site.
- Log4PowerShell - A CVE-2021-44228 Proof of Concept / Demo I wrote in PowerShell
- Log4j scanners released by CISA, CrowdStrike
- GitHub - cisagov/log4j-scanner: log4j-scanner is a project derived from other members of the open-source community by CISA's Rapid Action Force team to help organizations identify potentially vulnerable web services affected by the log4j vulnerabilities.
- Log4j RCE Scanner
log4j-tools
Posts with mentions or reviews of log4j-tools.
We have used some of these posts to build our list of alternatives
and similar projects. The last one was on 2022-07-07.
-
Finding the "practical" component for my thesis on Log4Shell
Something like this https://github.com/jfrog/log4j-tools
- Log4j Vulnerability Scanning Tool from Jfrog
-
What I Learned About the Log4j Vulnerability
Use an open source vulnerability scanning tool to figure out if specific systems are affected. Jfrog released a tool that can help you determine if your code includes Log4j and a script that helps you find where Log4j is within your code.
-
Log4j - Realworld experiences?
JFrog has released one of the few tools which scans for it properly here - https://github.com/jfrog/log4j-tools
-
OSS Log4j Vulnerability Scanning Tools
TLDR: Download the OSS Log4j Vulnerability Scanning Tools from the JFrog GitHub repository to assess potential Log4j vulnerabilities in your source code or binaries
- jfrog/log4j-tools: tools for finding log4shell in jars and source
- Tools for finding log4shell in jars and source
- Scan your jars - log4j is everywhere
What are some alternatives?
When comparing log4j-scanner and log4j-tools you can also consider the following projects:
CVE-2021-44228-Scanner - Vulnerability scanner and mitigation patch for Log4j2 CVE-2021-44228
grype - A vulnerability scanner for container images and filesystems
Log4jSherlock
log4j-scan - A fully automated, accurate, and extensive scanner for finding log4j RCE CVE-2021-44228
Log4jAttackSurface
log4shell-scanner - Log4Shell scanner for Burp Suite
Log4PowerShell - A Log4j writeup and Docker based PoC written in PowerShell