Ross ROSS = Recommend OSS · open-source software intelligence for agents

abc123info/BlueTeamTools

蓝队分析研判工具箱,功能包括内存马反编译分析、各种代码格式化、网空资产测绘功能、溯源辅助、解密冰蝎流量、解密哥斯拉流量、解密Shiro/CAS/Log4j2的攻击payload、IP/端口连接分析、各种编码/解码功能、蓝队分析常用网址、java反序列化数据包分析、Java类名搜索、Fofa搜索、Hunter搜索等。 observed · 2026-08-28

github.com/abc123info/BlueTeamTools observed · 2026-08-28

Health v2 · maintenance only

91/100

  • Activity 94
  • Release rhythm 94
  • Longevity 78

Flags: no_license

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: 28.0
  • age_days: 1093
  • days_rel: 40
  • days_push: 40
  • n_releases_24m: 11

Full methodology

Adoption not part of the score

1859 stars · 109 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

BlueTeamTools is a Java-based GUI toolbox that aggregates utilities for blue-team security analysts, covering memory-shell decompilation, webshell traffic decryption (Behinder, Godzilla, AntSword), Shiro/CAS/Log4j2 payload decoding, pcap traffic analysis, and Java deserialization packet analysis. It also includes encoding/decoding helpers, cyberspace asset mapping via Fofa/Hunter search, IP/port connection analysis, and AI-assisted identification of malicious traffic and DGA domains.

Use cases

  • decrypt behinder or godzilla webshell traffic
  • analyze java deserialization attack payloads
  • decompile memory shell class files
  • analyze pcap traffic for attack behavior
  • decode shiro or log4j2 exploit payloads
  • search fofa and hunter for exposed assets
  • analyze ip and port connections during incident response
  • decode and encode various formats during security analysis

When to choose

  • you are a blue-team/SOC analyst triaging web attacks and webshell traffic
  • you need to decrypt or decompile memory shells and deserialization payloads
  • you want an all-in-one offline toolbox for pcap analysis and payload decoding

When to avoid

  • you need a red-team offensive toolkit rather than defensive analysis
  • you require a supported, licensed enterprise product with SLAs
  • you need a headless/CLI tool for automation pipelines

Facets

application · maturity active

security reverse-engineering parser search-engine developer-tools gui security developer-tools networking reverse-engineering windows jvm blue-team incident-response webshell-decryption traffic-analysis pcap-analysis memory-shell-analysis deserialization threat-hunting soc-tools java-gui linux macos desktop

1 source

Member repositories

RepositoryRoleHealth v2
abc123info/BlueTeamToolsmain91

For agents

markdown · JSON · MCP: product_card(name="abc123info/BlueTeamTools")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem