# Schira4396/VcenterKiller

一款针对Vcenter的综合利用工具，包含目前最主流的CVE-2021-21972、CVE-2021-21985以及CVE-2021-22005、One Access的CVE-2022-22954、CVE-2022-22972/31656以及log4j，提供一键上传webshell，命令执行或者上传公钥使用SSH免密连接

Repository: https://github.com/Schira4396/VcenterKiller
Canonical: https://ross.abutalabs.com/products/vcenterkiller
Language: Go
License: Apache-2.0
License Family: permissive
Topics: go, golang, scan, vcenter, log4j, log4shell
Last push: 2024-04-25T06:09:38+00:00

## Health v2 (maintenance only)
Score: 23/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 0, release rhythm 8, longevity 100
- inputs: {"age_days": 1429, "days_push": 860, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1485, forks 164 (observed 2026-08-28T04:04:51.769528+00:00)

## What it is
A Go-based all-in-one exploitation and verification tool targeting VMware vCenter, covering major CVEs such as CVE-2021-21972, CVE-2021-21985, CVE-2021-22005, CVE-2022-22954, CVE-2022-22972/31656, and Log4j (Log4Shell). It supports one-click webshell upload, command execution with output, SSH public key upload, and reverse shell via RMI, designed for use from jump hosts during authorized engagements.

## Use cases
- exploit vcenter cve-2021-21972 to upload a webshell
- verify log4j log4shell vulnerability on vcenter and execute commands
- upload ssh public key to vcenter for passwordless access
- get authenticated cookie via cve-2022-22972 or cve-2022-31656
- run command execution against workspace one access cve-2022-22954
- obtain reverse shell from vcenter via cve-2021-21985 rmi

## When to choose
- you are doing authorized red team or penetration testing against vCenter infrastructure
- you need a single static binary that chains multiple vCenter CVE exploits without Python dependencies
- you want built-in log4j exploitation on vCenter without running a separate LDAP server

## When to avoid
- you need a general-purpose vulnerability scanner for broad network discovery rather than targeted exploitation
- your use is not legally authorized - this tool is for sanctioned security testing only
- you need stealthy or low-noise tooling, since these vCenter vulnerabilities are widely fingerprinted by defenders

## Facets
- artifact type: cli-tool
- maturity: active
- function: penetration-testing, vulnerability-scanning, security, http-client
- domain: security, penetration-testing, developer-tools
- platform: windows, cli, cross-platform
- tags: vcenter, vmware, exploitation, red-team, log4shell, cve-2021-21972, cve-2021-21985, cve-2021-22005, cve-2022-22954, webshell, offensive-security, linux, macos

## Member repositories
- Schira4396/VcenterKiller (main) score 23

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:04:51.769528+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T04:33:54.670218+00:00, confidence not recorded.
  - readme: https://github.com/Schira4396/VcenterKiller (fetched 2026-08-28T04:04:51.769528+00:00, sha fa489470a041)
- Data as of 2026-08-30T08:39:29.467469+00:00.
