Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
log4shell-finder — Fastest filesystem scanner for log4shell (CVE-2021-44228, CVE-2021-45046) and other vulnerable (CVE-2017-5645, CVE-2019-17571, CVE-2022-23305, CVE-2022-23307 ... ) instances of log4j library. Excellent performance and low memory footprint. | Kitploit
Tools/GitHubGitHub/hynekpetrak/log4shell-finder
Static AnalysisVulnerability ScannersVulnerability AnalysisCode AnalysisSupply Chain SecurityMisconfiguration
GitHubhynekpetrak/log4shell-finder

log4shell-finder

Fastest filesystem scanner for log4shell (CVE-2021-44228, CVE-2021-45046) and other vulnerable (CVE-2017-5645, CVE-2019-17571, CVE-2022-23305, CVE-2022-23307 ... ) instances of log4j library. Excellent performance and low memory footprint.

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
View Repository
3913123 years agoReviewed by Kitploit
Share

log4shell-finder - Fastest file system scanner for log4j instances

Python port of https://github.com/mergebase/log4j-detector log4j-detector is copyright (C) Copyright 2021 Mergebase Software Inc. https://mergebase.com/ Licensed via GPLv3.

Motivation for porting to Python was to improve perfomance, reduce memory consumption and increase code readability. See below section about performance comparism.

And it seems this is the fastest scanning tool with lowest memory requirement

Identifies log4j (1.x), reload4j (1.2.18+) and log4j-core (2.x) versions on your file-system vulnerable to CVE-2021-44228, CVE-2021-45046 and many others - see table below. It is able to find instances embedded in larger applications several layers deep. Works on Linux, Windows, Mac or anywhere else Python 3.8+ runs.

Can correctly detect log4j inside executable spring-boot jars/wars, dependencies blended into uber jars, shaded jars, and even exploded jar files just sitting uncompressed on the file-system (aka *.class).
It can also handle shaded class files - extensions .esclazz (elastic) and .classdata (Azure).

Java archive extensions searched: .zip, .jar, .war, .ear, .aar, .jpi, .hpi, .rar, .nar, .wab, .eba, .ejb, .sar, .apk, .par, .kar

Detected vulnerabilities

DetectsCVECVSSv3SeverityJavaVuln fromVulnerable toFixed inlibrary
YESCVE-2021-4422810.0Critical82.0-beta92.14.12.15.0log4jv2
YESCVE-2017-56459.8Critical72.0-alpha12.8.12.8.2log4jv2
YESCVE-2019-175719.8Critical1.2.01.2.17nofixlog4jv1
YESCVE-2021-450469.0Critical7/82.0-beta92.15.0 excluding 2.12.22.12.2/2.16.0log4jv2
YESCVE-2022-233059.8Critical1.2.01.2.17nofix / 1.2.18.1log4jv1, reload4j
YESCVE-2022-233079.8Critical1.2.01.2.17nofix / 1.2.18.1log4jv1, reload4j
YESCVE-2022-233028.8High1.01.2.17nofix / 1.2.18.1log4jv1, reload4j
YESCVE-2021-41047.5High-1.01.2.17nofixlog4jv1
YESCVE-2021-448326.6Medium6/7/82.0-alpha72.17.0, excluding 2.3.2/2.12.42.3.2/2.12.4/2.17.1log4jv2
-CVE-2021-425506.6Medium-1.01.2.71.2.8logback
YESCVE-2021-451055.9Medium6/7/82.0-beta92.16.0, excluding 2.12.32.3.1/2.12.3/2.17.0log4jv2
-CVE-2020-94883.7Low7/82.0-alpha12.13.12.12.3/2.13.2log4jv2

Each instance is reported with apropriate list of CVEs. For each CVE log4j library file is being analyzed whether the recommended workarounds (e.g. JndiLookup.class or JMSAppender.class removed) has been applied and in that case is considered as non-vulnerable. Status STRANGE is reported for archives with log4j-core pom.properties file, but without actual bytecode classes, ususally those are source packages and can be ignored.

Warning --fix feature is experimental, use it on your own risk, make sure you backup your jar files prior using it.

Argument --fix attempts to rename instances of JndiLookup.class into JndiLookup.vulne, thus preventing the class from loading. Within Java archives it's done via in place rename, does not require re-zipping of the archive and is instant fast.

Binaries are available for Linux 64bit, MS Windows 64bit and 32bit - see Releases

Minimum supported Python version is 3.8. According to my testing Python 3.6 zip implementation cannot open many .jar files from my test data.

Performance

log4shell finder is optimized for performance and low memory footprint.

Updated on 23.1.2022, performance measured on a directory with 26237 files in 2005 folders.

Runtime reduced by half, memory consumtion by 2/3, file system reads byt at least 90%

log4shell-finder (this tool)

Command being timed: "./test_log4shell.py /home/hynek/war/ --exclude-dirs /mnt --same-fs"
User time (seconds): 17.68
System time (seconds): 1.20
Percent of CPU this job got: 127%
Elapsed (wall clock) time (h:mm:ss or m:ss): 0:14.47
Maximum resident set size (kbytes): 64144
File system inputs: 114424

log4j-finder (https://github.com/fox-it/log4j-finder)

Command being timed: "./log4j-finder.py /home/hynek/war/"
User time (seconds): 23.59
System time (seconds): 1.09
Percent of CPU this job got: 99%
Elapsed (wall clock) time (h:mm:ss or m:ss): 0:26.18
Maximum resident set size (kbytes): 38604
File system inputs: 142824

log4j-detector (https://github.com/mergebase/log4j-detector)

Command being timed: "java -jar log4j-detector-latest.jar /home/hynek/war"
User time (seconds): 30.56
System time (seconds): 1.39
Percent of CPU this job got: 113%
Elapsed (wall clock) time (h:mm:ss or m:ss): 0:28.26
Maximum resident set size (kbytes): 214116
File system inputs: 14416

log4j2-scan (https://github.com/logpresso/CVE-2021-44228-Scanner)

Command being timed: "./log4j2-scan /home/hynek/war --scan-log4j1 --scan-zip"
User time (seconds): 52.05
System time (seconds): 25.32
Percent of CPU this job got: 88%
Elapsed (wall clock) time (h:mm:ss or m:ss): 1:27.86
Maximum resident set size (kbytes): 593080
File system inputs: 215416

Changelog

Version 1.22-20220222

  • Added: Reading library version and name (log4j, log4j-core, reload4j) from MANIFEST.MF as well as from pom.properties
  • Performance improvements by additional 15%
  • Added: Autodetecting all local drives in mswin with all parameter
  • Added: --no-csv-header to omit csv header to allow easier merging of results from multiple hosts
  • Added: Detecting CVE-2017-5645 (9.8), CVE-2019-17571 (9.8), CVE-2022-23307 (8.1), CVE-2022-23305 (9.8), CVE-2022-23305 (9.8), CVE-2022-23302 (8.1), improved detection of CVE-2017-5645
  • Added: --threads parameter to manually tune number of scanning threads
  • Added: --cvs-clean parameter in order to write "CLEAN" line to csv output in case no log4j library detected
  • Added: --cvs-stats parameter in order to write "STATS" line to csv output with runtime in seconds and number of files and folders scanned

Version 1.21-20220109

  • Fixed bug: --fix command in version 1.19 and 1.20 could corrupt .jar archives.

For previous changes see Release Notes

Usage

Either run from a python interpreter or use the Windows/Linux binaries from the dist folder.

Beware to run it as a user with access (at least read-only) to the whole filesystem. log4shell-finder traverses just folders it can access to, not reporting permission denied errors.

Download Tool