
Log4Shell (CVE-2021-44228) research report — technical breakdown, root cause analysis, and end-to-end lab-reproduced exploit chain with evidence screenshots.
A self-contained technical report on Log4Shell, the critical Remote Code Execution vulnerability in Apache Log4j 2 disclosed in December 2021. Covers root cause analysis, the full attack chain, detection/mitigation guidance, and an end-to-end exploit reproduction carried out in an isolated local lab, with terminal and log evidence.
JndiLookup.java and the four-step attack flowmarshalsec), payload class, and triggerchristophetd/log4shell-vulnerable-app (Log4j 2.14.1)mbechler/marshalsecJust open the file in a browser — no server required:
git clone https://github.com/sanasimran1403-jpg/log4shell-report-with-evidence.git
cd log4shell-report-with-evidence
open index.html # or double-click it
This report and its accompanying lab reproduction are for educational and authorized security research purposes only. All exploitation shown was performed against a deliberately vulnerable application in an isolated local Docker environment controlled by the author. Testing systems without explicit written authorization is illegal under the CFAA, UK Computer Misuse Act, and equivalent laws elsewhere.
Author: Sana Simran — S&S Independent Security Research, 2026