Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacyΒ© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
log4shell_sentinel β€” A Smart Log4Shell/Log4j/CVE-2021-44228 Scanner | Kitploit
Tools/GitHubGitHub/ossie-git/log4shell_sentinel
Vulnerability ScannersContainer SecurityVulnerability AnalysisForensicsIncident ResponseLog Analysis
GitHubossie-git/log4shell_sentinel

log4shell_sentinel

A Smart Log4Shell/Log4j/CVE-2021-44228 Scanner

View Repository
141264 years agoNot yet reviewed

Most Popular

View all β†’

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools β†’
Share

Log4Shell Sentinel - A Smart CVE-2021-44228 Scanner

Introduction

While there have some excellent tools released to help organizations scan their environments for applications vulnerable to the critical Log4J / CVE-2021-44228 vulnerability, I felt that:

  • none of the tools I ran into were made for analysts to track a given finding throughout the remediation process. Log4Shell Sentinel outputs its findings to CSV format in the expectation that an analyst will then slice and dice findings in Excel, add some findings to an ignore list and re-run the scan, compare scans, add data to scan results, etc.
  • file-based scanners leave a lot of work for analysts to do, especially in containerized environments

So Log4Shell Sentinel was born. Log4Shell Sentinel is a file-based scanner with some unique features. It isn't meant to replace all the other available tools but can compliment them.

Features

Log4Shell Sentinel is a file-based scanner. It searches for Java-based applications by scanning a target system for artifacts of the following file formats:

File TypeDetails
Simple jarThis is the case where the log4j-core file is not embedded.
Fat / Uber jarAn uber jar is a jar that contains both your classes / package and all your application's dependencies (libraries, resources and metadata files) within a single jar file. This is the most commonly used deployment option.
WARA war (Web Application Archive) file is a file that contains your JSP, HTML and JavaScript code in addition to your libraries and other resources. This format is less commonly used.
EARAn ear (Enterprise Application Archive) is another format that was more commonly used with Jakarta EE for deployments.

and searches for instances of vulnerable log4j-core jars. It then:

  • calculates a MD5 hash of the artifact. This allows an analyst to identify the same application running on different machines / containers and treat them as a single finding

  • for files determined to belong to a container such as: /var/lib/docker/overlay2/192768f471818601094bf4edd96d14bfc0e2b178a04a2efd00b2231ad4e46b33/merged/app/spring-boot-application.jar, it does the heavy lifting of mapping the file to the corresponding image. For example, it would translate the above to the following image: ghcr.io/christophetd/log4shell-vulnerable-app:latest. As the various container runtimes store this mapping in different ways, this can save an analyst hours of frustration. This also allows an analyst to treat a number of containers running a single application as a single finding.

  • it removes useless matches such as matches corresponding to containers that are currently not running including cached images. This allows an analyst to focus on what is important and again saves the analyst hours of needless work

  • it allows an analyst to ignore matches based on:

    • MD5 hash
    • file path
    • container image

    This allows the analyst to remove applications they know are not vulnerable or which correspond to CLI-based applications that do not pose a threat. For example, if an instance of Logstash is detected, an analyst can choose to ignore it if they do not run the tool or simply run it as from the CLI occasionally.

  • it is optimized to work with your configuration management tools such as Ansible, giving you the ability to quickly scan your environment in minutes

Metadata Enrichment

For details on the metadata enrichment added by Log4Shell Sentinel, refer to the my blog post.

Installation

The easiest way is to simply download the pre-compiled binary.

Building From Source

Again, this is straight-forward. However, you will likely want to build a statically compiled version to get around any GLIBC-related variations in your environment. The tool uses the following modules which use CGO by default:

  • os/user
  • net

To build a statically compiled version that uses the Go-versions of these libraries, simply clone the repo and then run:

$ CGO_ENABLED=0 go build -ldflags="-s -w"
$ ldd log4shell_sentinel
        not a dynamic executable

Usage

$ ./log4shell_sentinel -h
NAME:
   Log4Shell Sentinel - by Osama Elnaggar

USAGE:
   log4shell_sentinel [global options] command [command options] [arguments...]

VERSION:
   v1.0.0

COMMANDS:
   help, h  Shows a list of commands or help for one command

GLOBAL OPTIONS:
   --path value, -p value       Path to search (default: ".")
   --no-banner, --nb            Suppress banner (default: false)
   --no-messages, --nm          Suppress messages except for CSV output (default: false)
   --no-header, --nh            Suppress header in CSV output (default: false)
   --imd5 value, --im value     Ignore MD5 hashes. Refer to the GitHub page for expected format
   --ipath value, --ip value    Ignore file path matches. Refer to the GitHub page for expected format
   --icimage value, --ic value  Ignore container image matches. Refer to the GitHub page for expected format
   --print-headers, --ph        Print CSV Headers only (default: false)
   --help, -h                   show help (default: false)
   --version, -v                print the version (default: false)

Out of the box, a scan will simply scan the current directory. For example:

$ ./log4shell_sentinel

β–‘β–ˆβ–‘β–‘β–‘β–ˆβ–€β–ˆβ–‘β–ˆβ–€β–€β–‘β–ˆβ–‘β–ˆβ–‘β–ˆβ–€β–€β–‘β–ˆβ–‘β–ˆβ–‘β–ˆβ–€β–€β–‘β–ˆβ–‘β–‘β–‘β–ˆβ–‘β–‘β–‘β–‘β–‘β–ˆβ–€β–€β–‘β–ˆβ–€β–€β–‘β–ˆβ–€β–ˆβ–‘β–€β–ˆβ–€β–‘β–€β–ˆβ–€β–‘β–ˆβ–€β–ˆβ–‘β–ˆβ–€β–€β–‘β–ˆβ–‘β–‘
β–‘β–ˆβ–‘β–‘β–‘β–ˆβ–‘β–ˆβ–‘β–ˆβ–‘β–ˆβ–‘β–‘β–€β–ˆβ–‘β–€β–€β–ˆβ–‘β–ˆβ–€β–ˆβ–‘β–ˆβ–€β–€β–‘β–ˆβ–‘β–‘β–‘β–ˆβ–‘β–‘β–‘β–‘β–‘β–€β–€β–ˆβ–‘β–ˆβ–€β–€β–‘β–ˆβ–‘β–ˆβ–‘β–‘β–ˆβ–‘β–‘β–‘β–ˆβ–‘β–‘β–ˆβ–‘β–ˆβ–‘β–ˆβ–€β–€β–‘β–ˆβ–‘β–‘
β–‘β–€β–€β–€β–‘β–€β–€β–€β–‘β–€β–€β–€β–‘β–‘β–‘β–€β–‘β–€β–€β–€β–‘β–€β–‘β–€β–‘β–€β–€β–€β–‘β–€β–€β–€β–‘β–€β–€β–€β–‘β–‘β–‘β–€β–€β–€β–‘β–€β–€β–€β–‘β–€β–‘β–€β–‘β–‘β–€β–‘β–‘β–€β–€β–€β–‘β–€β–‘β–€β–‘β–€β–€β–€β–‘β–€β–€β–€

- A CVE-2021-44228/CVE-2021-45046/CVE-2021-45105 Scanner
- v1.0.0
- by Osama Elnaggar

[*] WARNING: Running as non-root user.
             Non-readable files / dirs will be skipped
             Container mapping will fail

[*] Starting shallow scan ............ [DONE]
[*] Starting deep scan ............... [DONE]
[*] Calculating MD5 hashes ........... [DONE]
[*] Performing container image lookups [DONE]
[*] Processing ignore list(s) ........ [DONE]
[*] Generating output ................ [DONE]

IP,Hostname,AppName,Team,Ignore (Y/N),Comments,MD5Hash,Timestamp,Container,ContainerImage,FullPath,Version
192.168.121.121,server3,,,,,4e615cd580758b70c49ade1f79103328,2021-12-21T07:38:09Z,true,ghcr.io/christophetd/log4shell-vulnerable-app:latest,/run/containerd/io.containerd.runtime.v2.task/k8s.io/dc2c9c214809f506283c917244cd126a9b056ac7274322d12b59c9196d95dd9b/rootfs/app/spring-boot-application.jar,log4j-core-2.14.1.jar

You'll immediately get a WARNING if you run it as a non-root user as it requires root permissions:

  • if you plan on scanning your entire filesystem (recommended)
  • if you plan on enriching performing container -> image lookups (access to the Docker daemon, config files, etc. is required)

It will still work without root privileges but may not give you the best results.

Understanding Findings

A sample finding looks like this:

IP,Hostname,AppName,Team,Ignore (Y/N),Comments,MD5Hash,Timestamp,Container,ContainerImage,FullPath,Version
192.168.121.121,server3,,,,,4e615cd580758b70c49ade1f79103328,2021-12-21T07:38:09Z,true,ghcr.io/christophetd/log4shell-vulnerable-app:latest,/run/containerd/io.containerd.runtime.v2.task/k8s.io/dc2c9c214809f506283c917244cd126a9b056ac7274322d12b59c9196d95dd9b/rootfs/app/spring-boot-application.jar,log4j-core-2.14.1.jar

Some fields are intentionally left empty and left for the analyst to fill in in Excel, etc. A short description of each field is shown below:

Download Tool