log4j-scanner
log4j-scanner is a project derived from other members of the open-source community by CISA to help organizations identify potentially vulnerable web services affected by the log4j vulnerabilities. (by cisagov)
log4shell-scanner
Log4Shell scanner for Burp Suite (by PortSwigger)
log4j-scanner | log4shell-scanner | |
---|---|---|
9 | 1 | |
1,250 | 49 | |
- | - | |
4.7 | 4.6 | |
over 1 year ago | 7 months ago | |
Java | Kotlin | |
- | GNU General Public License v3.0 only |
The number of mentions indicates the total number of mentions that we've tracked plus the number of user suggested alternatives.
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
log4j-scanner
Posts with mentions or reviews of log4j-scanner.
We have used some of these posts to build our list of alternatives
and similar projects. The last one was on 2022-07-07.
-
Finding the "practical" component for my thesis on Log4Shell
https://github.com/cisagov/log4j-scanner https://github.com/fullhunt/log4j-scan https://github.com/portswigger/log4shell-scanner
- CISA log4j PS scanner
- So many different log4j scanner tools and scripts posted
-
Understanding and Exploiting Log4J Vulnerability
Alternately you can use cisagov/log4j-scanner to scan for log4j Vulnerability on your site.
- Log4PowerShell - A CVE-2021-44228 Proof of Concept / Demo I wrote in PowerShell
- Log4j scanners released by CISA, CrowdStrike
- GitHub - cisagov/log4j-scanner: log4j-scanner is a project derived from other members of the open-source community by CISA's Rapid Action Force team to help organizations identify potentially vulnerable web services affected by the log4j vulnerabilities.
- Log4j RCE Scanner
log4shell-scanner
Posts with mentions or reviews of log4shell-scanner.
We have used some of these posts to build our list of alternatives
and similar projects. The last one was on 2022-07-07.
-
Finding the "practical" component for my thesis on Log4Shell
https://github.com/cisagov/log4j-scanner https://github.com/fullhunt/log4j-scan https://github.com/portswigger/log4shell-scanner
What are some alternatives?
When comparing log4j-scanner and log4shell-scanner you can also consider the following projects:
CVE-2021-44228-Scanner - Vulnerability scanner and mitigation patch for Log4j2 CVE-2021-44228
log4j-tools
Log4jSherlock
Log4jAttackSurface
Log4PowerShell - A Log4j writeup and Docker based PoC written in PowerShell