{"adoption": {"forks": 109, "observed_at": "2026-08-28T04:05:45.252830+00:00", "stars": 1859}, "canonical_url": "https://ross.abutalabs.com/products/blueteamtools", "card": {"archived": false, "artifact_type": "application", "description": "蓝队分析研判工具箱，功能包括内存马反编译分析、各种代码格式化、网空资产测绘功能、溯源辅助、解密冰蝎流量、解密哥斯拉流量、解密Shiro/CAS/Log4j2的攻击payload、IP/端口连接分析、各种编码/解码功能、蓝队分析常用网址、java反序列化数据包分析、Java类名搜索、Fofa搜索、Hunter搜索等。", "domain": ["security", "developer-tools", "networking", "reverse-engineering"], "enriched": true, "function": ["security", "reverse-engineering", "parser", "search-engine", "developer-tools", "gui"], "health_score": 96, "homepage": null, "language": null, "license": null, "license_family": "other", "maturity": "active", "member_repos": ["abc123info/BlueTeamTools"], "name": "abc123info/BlueTeamTools", "platform": ["windows", "jvm"], "pushed_at": "2026-07-25T01:38:41+00:00", "repo": "abc123info/BlueTeamTools", "stars": 1859, "tags": ["blue-team", "incident-response", "webshell-decryption", "traffic-analysis", "pcap-analysis", "memory-shell-analysis", "deserialization", "threat-hunting", "soc-tools", "java-gui", "linux", "macos", "desktop"], "topics": [], "urls": [], "use_cases": ["decrypt behinder or godzilla webshell traffic", "analyze java deserialization attack payloads", "decompile memory shell class files", "analyze pcap traffic for attack behavior", "decode shiro or log4j2 exploit payloads", "search fofa and hunter for exposed assets", "analyze ip and port connections during incident response", "decode and encode various formats during security analysis"], "what_it_is": "BlueTeamTools is a Java-based GUI toolbox that aggregates utilities for blue-team security analysts, covering memory-shell decompilation, webshell traffic decryption (Behinder, Godzilla, AntSword), Shiro/CAS/Log4j2 payload decoding, pcap traffic analysis, and Java deserialization packet analysis. It also includes encoding/decoding helpers, cyberspace asset mapping via Fofa/Hunter search, IP/port connection analysis, and AI-assisted identification of malicious traffic and DGA domains.", "when_to_avoid": ["you need a red-team offensive toolkit rather than defensive analysis", "you require a supported, licensed enterprise product with SLAs", "you need a headless/CLI tool for automation pipelines"], "when_to_choose": ["you are a blue-team/SOC analyst triaging web attacks and webshell traffic", "you need to decrypt or decompile memory shells and deserialization payloads", "you want an all-in-one offline toolbox for pcap analysis and payload decoding"]}, "data_as_of": "2026-08-30T08:39:29.467469+00:00", "members": [{"path": "/products/blueteamtools", "repo": "abc123info/BlueTeamTools", "role": "main", "score": 91}], "provenance": {"archived": {"kind": "observed", "observed_at": "2026-08-28T04:05:45.252830+00:00", "source": "github"}, "artifact_type": {"confidence": null, "enriched_at": "2026-08-30T03:15:58.369875+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "f85f44a914ed742c819d177a00e4a680d9de2adee205b8bbae2818ca54f00605", "fetched_at": "2026-08-28T04:05:45.252830+00:00", "kind": "readme", "missing": false, "url": "https://github.com/abc123info/BlueTeamTools"}], "taxonomy_version": 1}, "description": {"kind": "observed", "observed_at": "2026-08-28T04:05:45.252830+00:00", "source": "github"}, "domain": {"confidence": null, "enriched_at": "2026-08-30T03:15:58.369875+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "f85f44a914ed742c819d177a00e4a680d9de2adee205b8bbae2818ca54f00605", "fetched_at": "2026-08-28T04:05:45.252830+00:00", "kind": "readme", "missing": false, "url": "https://github.com/abc123info/BlueTeamTools"}], "taxonomy_version": 1}, "enriched": {"inputs": [], "kind": "computed", "method": "enrichment_status"}, "function": {"confidence": null, "enriched_at": "2026-08-30T03:15:58.369875+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "f85f44a914ed742c819d177a00e4a680d9de2adee205b8bbae2818ca54f00605", "fetched_at": "2026-08-28T04:05:45.252830+00:00", "kind": "readme", "missing": false, "url": "https://github.com/abc123info/BlueTeamTools"}], "taxonomy_version": 1}, "health_score": {"inputs": ["days_since_push", "days_since_release", "archived"], "kind": "computed", "method": "health_v1"}, "homepage": {"kind": "observed", "observed_at": "2026-08-28T04:05:45.252830+00:00", "source": "github"}, "language": {"kind": "observed", "observed_at": "2026-08-28T04:05:45.252830+00:00", "source": "github"}, "license": {"kind": "observed", "observed_at": "2026-08-28T04:05:45.252830+00:00", "source": "github"}, "license_family": {"inputs": ["license"], "kind": "computed", "method": "license_family"}, "maturity": {"confidence": null, "enriched_at": "2026-08-30T03:15:58.369875+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "f85f44a914ed742c819d177a00e4a680d9de2adee205b8bbae2818ca54f00605", "fetched_at": "2026-08-28T04:05:45.252830+00:00", "kind": "readme", "missing": false, "url": "https://github.com/abc123info/BlueTeamTools"}], "taxonomy_version": 1}, "member_repos": {"kind": "observed", "observed_at": "2026-08-28T04:05:45.252830+00:00", "source": "github"}, "name": {"kind": "observed", "observed_at": "2026-08-28T04:05:45.252830+00:00", "source": "github"}, "platform": {"confidence": null, "enriched_at": "2026-08-30T03:15:58.369875+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "f85f44a914ed742c819d177a00e4a680d9de2adee205b8bbae2818ca54f00605", "fetched_at": "2026-08-28T04:05:45.252830+00:00", "kind": "readme", "missing": false, "url": "https://github.com/abc123info/BlueTeamTools"}], "taxonomy_version": 1}, "pushed_at": {"kind": "observed", "observed_at": "2026-08-28T04:05:45.252830+00:00", "source": "github"}, "repo": {"kind": "observed", "observed_at": "2026-08-28T04:05:45.252830+00:00", "source": "github"}, "stars": {"kind": "observed", "observed_at": "2026-08-28T04:05:45.252830+00:00", "source": "github"}, "tags": {"confidence": null, "enriched_at": "2026-08-30T03:15:58.369875+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "f85f44a914ed742c819d177a00e4a680d9de2adee205b8bbae2818ca54f00605", "fetched_at": "2026-08-28T04:05:45.252830+00:00", "kind": "readme", "missing": false, "url": "https://github.com/abc123info/BlueTeamTools"}], "taxonomy_version": 1}, "topics": {"kind": "observed", "observed_at": "2026-08-28T04:05:45.252830+00:00", "source": "github"}, "urls": {"kind": "observed", "observed_at": "2026-08-28T04:05:45.252830+00:00", "source": "github"}, "use_cases": {"confidence": null, "enriched_at": "2026-08-30T03:15:58.369875+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "f85f44a914ed742c819d177a00e4a680d9de2adee205b8bbae2818ca54f00605", "fetched_at": "2026-08-28T04:05:45.252830+00:00", "kind": "readme", "missing": false, "url": "https://github.com/abc123info/BlueTeamTools"}], "taxonomy_version": 1}, "what_it_is": {"confidence": null, "enriched_at": "2026-08-30T03:15:58.369875+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "f85f44a914ed742c819d177a00e4a680d9de2adee205b8bbae2818ca54f00605", "fetched_at": "2026-08-28T04:05:45.252830+00:00", "kind": "readme", "missing": false, "url": "https://github.com/abc123info/BlueTeamTools"}], "taxonomy_version": 1}, "when_to_avoid": {"confidence": null, "enriched_at": "2026-08-30T03:15:58.369875+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "f85f44a914ed742c819d177a00e4a680d9de2adee205b8bbae2818ca54f00605", "fetched_at": "2026-08-28T04:05:45.252830+00:00", "kind": "readme", "missing": false, "url": "https://github.com/abc123info/BlueTeamTools"}], "taxonomy_version": 1}, "when_to_choose": {"confidence": null, "enriched_at": "2026-08-30T03:15:58.369875+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "f85f44a914ed742c819d177a00e4a680d9de2adee205b8bbae2818ca54f00605", "fetched_at": "2026-08-28T04:05:45.252830+00:00", "kind": "readme", "missing": false, "url": "https://github.com/abc123info/BlueTeamTools"}], "taxonomy_version": 1}}, "score": {"components": {"activity": 94, "longevity": 78, "rhythm": 94}, "computed_at": "2026-09-03T02:20:16.233290+00:00", "flags": ["no_license"], "formula": "round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)", "inputs": {"age_days": 1093, "days_push": 40, "days_rel": 40, "gap_med": 28.0, "n_releases_24m": 11}, "score": 91, "version": 2}, "staleness": {"enrichment_outdated": false, "low_confidence": false, "scrape_days": 9, "stale_scrape": false}}