A fully automated, accurate, and extensive scanner for finding log4j RCE CVE-2021-44228
The main features of fullhunt/log4j-scan are: Reconnaissance and Discovery.
Open-source alternatives to fullhunt/log4j-scan include: elevenpaths/foca — FOCA is a digital forensics metadata analyzer and open-source intelligence tool used to extract hidden information… epi052/feroxbuster — Feroxbuster is an HTTP directory brute forcer and web resource enumerator designed to discover hidden files and… evyatarmeged/raccoon — A high performance offensive security tool for reconnaissance and vulnerability scanning. ffuf/ffuf — This tool is a command-line utility designed for automated web resource discovery, fuzzing, and application structure… findomain/findomain — Findomain is a subdomain discovery tool and DNS resolver used for mapping an organization's external attack surface.… devanshbatham/paramspider — Mining URLs from dark corners of Web Archives for bug hunting/fuzzing/further probing.
FOCA is a digital forensics metadata analyzer and open-source intelligence tool used to extract hidden information from various document types. It functions as a metadata extraction tool that isolates technical data and EXIF information from PDFs, office documents, and SVG files. The system integrates an open-source intelligence scanner that identifies and downloads target files from the web using multiple search engine APIs. This allows for the automated discovery and acquisition of remote web assets for batch analysis and digital evidence gathering. The software provides capabilities for d
Feroxbuster is an HTTP directory brute forcer and web resource enumerator designed to discover hidden files and directories on web servers. It functions as a recursive URL scanner that identifies unlinked endpoints and API resources by combining wordlist-based scanning with automated crawling. The tool operates as a proxy-aware fuzzer, allowing network requests to be routed through HTTP or SOCKS proxies for traffic interception or anonymity. It utilizes recursive directory crawling to automatically queue discovered paths and find nested content. The system includes capabilities for discovery
A high performance offensive security tool for reconnaissance and vulnerability scanning
Mining URLs from dark corners of Web Archives for bug hunting/fuzzing/further probing