此配置文件直接在文件系统以及嵌入在WAR文件中扫描易受攻击的Log4j Core JAR文件版本。
git clone https://github.com/trickyearlobe/inspec-log4j
inspec exec inspec-log4j
确保目标上已为特权用户(如root)加载SSH密钥。 或者,查看CLI文档,了解如何使用Inspec与SUDO。
git clone https://github.com/trickyearlobe/inspec-log4j
inspec exec inspec-log4j -t ssh://root@host
git clone https://github.com/trickyearlobe/inspec-log4j
inspec archive inspec-log4j