Schira4396/VcenterKiller
一款针对Vcenter的综合利用工具,包含目前最主流的CVE-2021-21972、CVE-2021-21985以及CVE-2021-22005、One Access的CVE-2022-22954、CVE-2022-22972/31656以及log4j,提供一键上传webshell,命令执行或者上传公钥使用SSH免密连接 observed · 2026-08-28
Health v2 · maintenance only
23/100
- Activity 0
- Release rhythm 8
- Longevity 100
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.
- gap_med: n/a
- age_days: 1429
- days_rel: n/a
- days_push: 860
- n_releases_24m: 0
Adoption not part of the score
1485 stars · 164 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded
A Go-based all-in-one exploitation and verification tool targeting VMware vCenter, covering major CVEs such as CVE-2021-21972, CVE-2021-21985, CVE-2021-22005, CVE-2022-22954, CVE-2022-22972/31656, and Log4j (Log4Shell). It supports one-click webshell upload, command execution with output, SSH public key upload, and reverse shell via RMI, designed for use from jump hosts during authorized engagements.
Use cases
- exploit vcenter cve-2021-21972 to upload a webshell
- verify log4j log4shell vulnerability on vcenter and execute commands
- upload ssh public key to vcenter for passwordless access
- get authenticated cookie via cve-2022-22972 or cve-2022-31656
- run command execution against workspace one access cve-2022-22954
- obtain reverse shell from vcenter via cve-2021-21985 rmi
When to choose
- you are doing authorized red team or penetration testing against vCenter infrastructure
- you need a single static binary that chains multiple vCenter CVE exploits without Python dependencies
- you want built-in log4j exploitation on vCenter without running a separate LDAP server
When to avoid
- you need a general-purpose vulnerability scanner for broad network discovery rather than targeted exploitation
- your use is not legally authorized - this tool is for sanctioned security testing only
- you need stealthy or low-noise tooling, since these vCenter vulnerabilities are widely fingerprinted by defenders
Facets
cli-tool · maturity active
penetration-testing vulnerability-scanning security http-client security penetration-testing developer-tools windows cli cross-platform vcenter vmware exploitation red-team log4shell cve-2021-21972 cve-2021-21985 cve-2021-22005 cve-2022-22954 webshell offensive-security linux macos
1 source
- readme: https://github.com/Schira4396/VcenterKiller · fetched 2026-08-28 · fa489470a041
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| Schira4396/VcenterKiller | main | 23 |
For agents
markdown · JSON · MCP: product_card(name="Schira4396/VcenterKiller")
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem