Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Onapsis-Mandiant-CVE-2025-31324-Vuln-Compromise-Assessment — CVE-2025-31324 & CVE-2025-42999 vulnerability and compromise assessment tool | Kitploit
Tools/GitHubGitHub/onapsis/onapsis-mandiant-cve-2025-31324-vuln-compromise-assessment
Indicator of Compromise (IOC) ManagementVulnerability AnalysisForensicsWeb SecurityCloud SecurityIncident ResponseLog Analysis
GitHubonapsis/onapsis-mandiant-cve-2025-31324-vuln-compromise-assessment

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Onapsis-Mandiant-CVE-2025-31324-Vuln-Compromise-Assessment

CVE-2025-31324 & CVE-2025-42999 vulnerability and compromise assessment tool

View RepositoryWebsite
9151 year agoNot yet reviewed

CVE-2025-31324 Zero-Day SAP Vulnerability & Compromise Assessment Tool

Joint Release by Onapsis & Mandiant

Onapsis and Mandiant have collaborated to release an open-source tool to assist SAP customers in identifying potential compromise related to CVE-2025-31324 and CVE-2025-42999, a critical 0-day vulnerability in SAP NetWeaver Java systems.

This tool is intended for local, white-box execution by system administrators with access to potentially affected environments. It supports vulnerability assessment, simple compromise assessment and artifact collection.

Features

This tool currently supports the following functionality:

  • Detects whether the system is vulnerable to CVE-2025-31324 and CVE-2025-42999
  • Identifies known Indicators of Compromise (IOCs)
  • Scans for unknown web-executable files in known exploit paths
  • Collects suspicious files into a structured ZIP archive with a manifest for future forensic analysis
  • Analyzes HTTP access logs for potential exploit and post-exploit activity
  • Analyzes JAVA Default Traces logs for exploitation activity
  • Exports log entries for matching responses in a CSV

LICENSE INFORMATION: This tool is released under the Apache 2.0 open source license. Please see bundled license information.

DISCLAIMER: This tool was developed to support urgent investigation and response efforts related to the active exploitation of CVE-2025-31324 and CVE-2025-42999. As of June 6, 2025, this tool is no longer under active development or monitoring. It remains available for future debugging and reference purposes; however, it will not receive further updates, enhancements, or ongoing support. Users should evaluate its applicability based on their current needs and use it at their own discretion.

This tool automates checking of vulnerability and IOC information running in live OS with the permissions of the user executing the script. This is NOT a substitute for forensic analysis or advanced incident response. Sophisticated attackers often clean up evidence of their intrusion while deploying rootkits and leveraging techniques to evade detection.

This tool is provided as-is, without warranty or liability. Use at your own risk.

Installation and Prerequisites

The scripts are developed in Python 3 and require you to install the following dependencies:

python3 -m venv .venv 
. .venv/bin/activate
pip install -r requirements.txt

Usage

Once you install the dependencies, you can use Python to run the scripts and get Help from the command line.

# Syntax: python3 <tool_name>.py <path> [--single] [--offline]

Scan Parameters:

  • <path> --- Refers to the root directory of the SAP application file system you want to scan. This should be the base of the SAP system, either from a mounted backup or a live environment.
  • --single --- Run a scan for a individual SID/Instance directory (not root or base SAP directory with multiple systems or instances)
  • --offline --- Run without internet connection (no check for upgrades against GitHub API)

For a full list of command line options and flags use --help parameter.

[!IMPORTANT] This tool scan for files under the JAVA server file system as specified in SAP Security Note 3593336:

  • C:\usr\sap\<SID>\<InstanceID>\j2ee\cluster\apps\sap.com\irj\servlet_jsp\irj\root
  • C:\usr\sap\<SID>\<InstanceID>\j2ee\cluster\apps\sap.com\irj\servlet_jsp\irj\work
  • C:\usr\sap\<SID>\<InstanceID>\j2ee\cluster\apps\sap.com\irj\servlet_jsp\irj\work\sync

If the path given is a root live file-system (for example / or C:\), the tool will expect /usr/sap standard SAP installation directory. Then the tool will scan all <SID>/<INSTANCE>/ sub-directories by default (using wildcards).

If doing a partial scan, use --single and specify the full path to the instance folder that contains the j2ee SAP Java directory.

[!CAUTION] This design is intended to scan all possible suspicious files in all SID / Instances, while avoiding incorrect detection of familiar files. Any file outside this standard folder structure will not be detected, and an error will be raised if j2ee sub-directory is not found.

The component manifest is also expected to be in j2ee/cluster/apps/sap.com/devserver_metadataupload_ear/ standard sub-directory. If not found, it will not be analyzed against vulnerable un-patched versions.

Expected Log path is j2ee/cluster/<SERVER>/log/system/httpaccess/, with files named responses and trc extension for SAP propietary log format. -clf suffix is expected for Common Log Format files. If not found, an error/warning message will be raised.

Tool Output

Linux example 1

Mounted filesystem at /mnt/sapserver (component vulnerable, single instance scan for SID J00):

python3 onapsis-mandiant-CVE-2025-31324-vuln-compromise-assessment.py /mnt/sapserver/usr/sap/SID/J00 --single

Download Tool