Remote command execution vulnerability scanner for Log4j.

RCE scanner for Log4j

Using this tool, you can scan for remote command execution vulnerability CVE-2021-44228 on Apache Log4j at multiple addresses.

Affected versions < 2.15.0


  • It can scan according to the url list you provide.
  • It can scan all of them by finding the subdomains of the domain name you give.


  1. httpx
  2. curl

If you want to scan with a domain name, you must additionally install subfinder, assetfinder and amass.


  1. git clone https://github.com/adilsoybali/Log4j-RCE-Scanner.git
  2. cd Log4j-RCE-Scanner
  3. chmod +x log4j-rce-scanner.sh


./log4j-rce-scanner.sh -h

This will display help for the tool. Here are all the switches it supports.

-h, --help - Display help
-l, --url-list - List of domain/subdomain/ip to be used for scanning.
-d, --domain - The domain name to which all subdomains and itself will be checked.
-b, --burpcollabid - Burp collabrator client id address or interactsh domain address.

Example uses:
./log4j-rce-scanner.sh -l httpxsubdomains.txt -b yrt45r4sjyoj19617jem5briio3cs.burpcollaborator.net
./log4j-rce-scanner.sh -d adilsoybali.com -b yrt45r4sjyoj19617jem5briio3cs.burpcollaborator.net

Click here to go to Interactsh.


