log4shell-hunter. Scanner that scans local files for log4shell vulnerability. Does bytecode analysis so it does not rely on metadata. Will find vulnerable log4j even it has been self-compiled/repackaged/shaded/nested (e.g. uberjar, fatjar) and even obfuscated.

github.com/pfichtner/log4shell-hunter

Vaya's read on this project

Problem, audience, market, and the verdict — sign in to see it.

Updates

No recent activity.