
log4shell-hotfix-side-effect
Test case to check if the Log4Shell/CVE-2021-44228 hotfix will raise any unexpected exceptions

Test case to check if the Log4Shell/CVE-2021-44228 hotfix will raise any unexpected exceptions


Runs Trivy as GitHub action to scan your Docker container image for vulnerabilities

general purpose workaround for the log4j CVE-2021-44228 vulnerability

Shell script to recursively scan folders for Go binaries using insecure pem.Decode function, detecting vulnerable or stripped binaries for…

Investigation into the XZ Utils backdoor (CVE-2024-3094): chronology, attack chain, risk to SSH, and supply-chain insights. Includes slides, sources,…

Read-only developer endpoint scanner for on-disk package, extension, and developer-tool metadata, built to check exposure to known software…

Automated supply chain security monitor that polls PyPI and npm registries, diffs new releases against predecessors, and uses LLM analysis to detect…

An agent to hotpatch the log4j RCE from CVE-2021-44228.

Shell-based scanner to detect the XZ Backdoor (CVE-2024-3094) vulnerability in files and directories, enabling rapid identification and mitigation of…

A Java Agent that disables Apache Log4J's JNDI Lookup to mitigate CVE-2021-44228 ("Log4Shell").

Shell script to detect the CVE-2024-3094 backdoor in XZ Utils by checking for malicious code in liblzma build artifacts and identifying affected…

A simple script to remove Log4J JndiLookup.class from jars in a given directory, to temporarily protect from CVE-2021-45046 and CVE-2021-44228.

Scanners for Jar files that may be vulnerable to CVE-2021-44228

Find vulnerable Log4j2 versions on disk and also inside Java Archive Files (Log4Shell CVE-2021-44228, CVE-2021-45046, CVE-2021-45105)

Hashes for vulnerable LOG4J versions

Tamper-evident audit trails for AI agents: hash-chained Runtime Records, dependency-free, verifiable by anyone.

This is an incident response playbook we created for the Vercel April 2026 compromise