# NCSC-NL/log4shell

Operational information regarding the log4shell vulnerabilities in the Log4j logging library.

Repository: https://github.com/NCSC-NL/log4shell
Canonical: https://ross.abutalabs.com/products/log4shell
Language: Python
License Family: other
Topics: cve-2021-44228, log4j, cve-2021-45046, cve-2021-45105, log4shell, vulnerability, cve-2021-4104
Archived: true
Last push: 2022-06-15T23:59:35+00:00

## Health v2 (maintenance only)
Score: 10/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 0, release rhythm 8, longevity 100
- inputs: {"age_days": 1725, "days_push": 1540, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: archived, no_license
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1883, forks 566 (observed 2026-08-28T04:05:48.808052+00:00)

## What it is
A repository of operational information from the Dutch National Cyber Security Centre about the Log4Shell vulnerabilities in the Log4j logging library. It aggregates indicators of compromise, detection regexes, mitigation guidance, vulnerable software lists, and scanning tools.

## Use cases
- find out if my software is affected by log4shell
- detect log4j exploitation attempts in logs
- get mitigation guidance for CVE-2021-44228
- find indicators of compromise for log4j scanning
- scan my infrastructure for the log4j vulnerability
- list of known vulnerable software for log4shell

## When to choose
- you need authoritative guidance and IOCs for Log4Shell incident response
- you want a curated list of vulnerable and patched software
- you need detection regexes and hunting resources for CVE-2021-44228

## When to avoid
- you need an actively maintained vulnerability scanner for new CVEs
- you need a general-purpose dependency audit tool rather than Log4j-specific info

## Facets
- artifact type: learning-resource
- maturity: maintenance
- function: security, vulnerability-scanning, developer-tools
- domain: security, developer-tools, self-hosted
- platform: cli, python, cross-platform
- tags: log4shell, cve-2021-44228, log4j, ioc, incident-response, mitigation, advisory

## Member repositories
- NCSC-NL/log4shell (main) score 10

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:05:48.808052+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T03:13:40.645752+00:00, confidence not recorded.
  - readme: https://github.com/NCSC-NL/log4shell (fetched 2026-08-28T04:05:48.808052+00:00, sha 110c3ef55792)
- Data as of 2026-08-30T08:39:29.467469+00:00.
