Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Log4ShellAuditor — An autonomous reflective Go agent for full-cycle security auditing, WAF evasion, OOB LDAP verification, self-remediation (auto-patching), and compliance reporting for CVE-2021-44228 (Log4Shell). | Kitploit
Tools/GitHubGitHub/c00ln3t/log4shellauditor
Vulnerability ScannersPayload GenerationPort ScanningExploitationWeb Application ExploitationWAF BypassPenetration TestingDevSecOpsLabs & Practice
GitHubc00ln3t/log4shellauditor

Log4ShellAuditor

An autonomous reflective Go agent for full-cycle security auditing, WAF evasion, OOB LDAP verification, self-remediation (auto-patching), and compliance reporting for CVE-2021-44228 (Log4Shell).

1251 month agoNot yet reviewed
View Repository

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

AUTO AUDIT Banner

🤖 AUTO AUDIT

Isolated demonstration testbed of an autonomous reflexive executor agent (Go/Java)

Русский 🇷🇺 • English 🇬🇧 • 中文 🇨🇳 • Español 🇪🇸 • Deutsch 🇩🇪 • Italiano 🇮🇹 • العربية 🇸🇦

Go Version Java Version Maven License Views Clones


🧭 Overview

[!NOTE] AUTO AUDIT is a software suite demonstrating a 100% autonomous closed loop (Sense-Think-Act) for detection, verification, exploitation, automatic remediation (Self-Healing / Auto-Remediation), and compliance reporting for the critical vulnerability Log4Shell (CVE-2021-44228 / БДУ ФСТЭК:2021-06103).

The testbed deploys a local web application based on Java Spring Boot, a built-in LDAP TCP Callback Listener, and the cognitive core of a Go agent that makes decisions under partial observability of the external environment (Partially Observable Markov Decision Process — POMDP).```mermaid %%{init: { 'theme': 'dark', 'themeVariables': { 'background': '#0f172a', 'primaryColor': '#1e293b', 'primaryTextColor': '#cbd5e1', 'primaryBorderColor': '#3b82f6', 'lineColor': '#38bdf8', 'secondaryColor': '#1e1b4b', 'tertiaryColor': '#0f172a', 'edgeLabelBackground': '#0f172a' } }}%% graph TD classDef sense fill:#0284c7,stroke:#0ea5e9,stroke-width:2px,color:#fff; classDef think fill:#4f46e5,stroke:#6366f1,stroke-width:2px,color:#fff; classDef act fill:#059669,stroke:#10b981,stroke-width:2px,color:#fff; classDef target fill:#dc2626,stroke:#ef4444,stroke-width:2px,color:#fff;

subgraph Sense ["🔍 СЕНСОРНЫЙ АНАЛИЗ (Sense)"]
    A[Внешние отклики / TCP-коллбеки]:::sense --> B(Обновление Базы Знаний):::sense
end
subgraph Think ["🧠 КОГНИТИВНОЕ ЯДРО (Think)"]
    B --> C{Вычисление Utility Policy}:::think
    C -->|Рефлексивный вывод| D[Выбор эффектора из реестра]:::think
end
subgraph subgraph_Act ["⚡ ИСПОЛНЕНИЕ (Act)"]
    D --> E[Выполнение Tool.Execute]:::act
    E -->|Воздействие| F((Java Spring Boot Target)):::target
    F -.->|Обратный канал OOB| A
end
---

## 🛠️ Technical Architecture and Components

The agent's software structure is designed according to the principles of clean architecture (*Hexagonal Architecture / Ports and Adapters*), SOLID, and TDD:

* 📂 **[cmd/agent/main.go](https://github.com/c00ln3t/log4shellauditor/blob/main/cmd/agent/main.go)** — Entry point. Manages the lifecycle of background processes and coordinates the startup of the agent goroutine.
* 📂 **`internal/`** — Core business logic of the cognitive loop:
  * 🧠 **[agent/agent.go](https://github.com/c00ln3t/log4shellauditor/blob/main/internal/agent/agent.go)** — Cognitive loop. Implements the control cycle and the decision rule for strategy selection `Think()`.
  * 💾 **[core/model.go](https://github.com/c00ln3t/log4shellauditor/blob/main/internal/core/model.go)** — Thread-safe knowledge base (`KnowledgeBase` / LTM) based on `sync.RWMutex`.
  * 🔌 **[core/effector.go](https://github.com/c00ln3t/log4shellauditor/blob/main/internal/core/effector.go)** — `Tool` interface for effectors.
  * ⚙️ **[effectors/](https://github.com/c00ln3t/log4shellauditor/blob/main/internal/effectors)** — Registry of polymorphic effectors (tools):
    * 🔍 `ToolPortScanner` — Network perimeter reconnaissance.
    * 🌐 `ToolDiscovery` — Search for articulation points and input vectors (`X-Api-Version`).
    * 🔬 `ToolPayloadGenerator` — Synthesis of the JNDI signature vector.
    * 🚀 `ToolProber` — Vulnerability verification using out-of-band (Out-of-Band) tracing.
    * 🛡️ `ToolSemanticFuzzer` — Bypass of filtering classifiers (WAF Evasion) using nested syntactic mutations.
    * 🩹 `ToolRemediator` — Automatic patching (Self-Healing).
    * 📄 `ToolReporter` — Report generation in accordance with GOST R 56939-2016.
* 📂 **`pkg/`** — Utility packages and libraries:
  * 📡 **[oob/](https://github.com/c00ln3t/log4shellauditor/blob/main/pkg/oob)** — Out-of-band listeners (LDAP and HTTP).
  * ☕ **[jvm/](https://github.com/c00ln3t/log4shellauditor/blob/main/pkg/jvm)** — Lifecycle management and restart of a local Java target.
* 📂 **[deployments/](https://github.com/c00ln3t/log4shellauditor/blob/main/deployments)** — Configuration files for deployment (Docker, Compose).
* 📂 **[test/vulnerable-app/](https://github.com/c00ln3t/log4shellauditor/blob/main/test/vulnerable-app)** — Vulnerable test Java Spring Boot application.

---

## 🎯 Mathematical Apparatus and Specification of the Cognitive Cycle (Think-Act Loop)

Agent decision-making is formalized as a **partially observable Markov decision process (POMDP)**, described by the tuple $\langle S, A, T, R, \Omega, O, \gamma \rangle$:
* $S$ — discrete space of hidden states of the target environment (port availability, presence of vulnerable parameters, WAF activity, compromise status, patching status, presence of a compliance report).
* $A$ — action space of effectors (tool invocations: `port_scanner`, `discovery`, `payload_generator`, `prober`, `semantic_fuzzer`, `remediator`, `reporter`, `stop`).
* $\Omega$ — observation space (received HTTP responses, OOB TCP callbacks, file system records).
* $O(o \mid s', a)$ — observation function defining the probability of receiving a response $o \in \Omega$.
Download Tool