Ross ROSS = Recommend OSS · open-source software intelligence for agents

pen4uin/java-memshell-generator

一款支持自定义的 Java 内存马生成工具|A customizable Java in-memory webshell generation tool. observed · 2026-08-28

github.com/pen4uin/java-memshell-generator · Java · MIT (permissive) observed · 2026-08-28

Health v2 · maintenance only

37/100

  • Activity 38
  • Release rhythm 8
  • Longevity 84
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 1187
  • days_rel: 609
  • days_push: 377
  • n_releases_24m: 1

Full methodology

Adoption not part of the score

2230 stars · 232 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

A highly customizable Java in-memory webshell (memshell) generator supporting multiple middleware servers, frameworks, shell types, and output formats, with both GUI and command-line interfaces. It is intended for security research and penetration testing, with integration support for tools like AntSword, Behinder, Godzilla, Neo-reGeorg, and Suo5.

Use cases

  • generate java memshell payloads for tomcat or weblogic
  • create in-memory webshells for penetration testing engagements
  • generate listener or filter memshells compatible with antsword or behinder
  • customize memshell payloads for spring webflux or undertow
  • produce bcel or base64 encoded payload output for security research
  • test web application defenses against in-memory webshell attacks

When to choose

  • you need a customizable memshell generator covering many Java middleware and frameworks
  • you want payload output in multiple formats (BASE64, BCEL, CLASS, JAR, JSP) for different post-exploitation tools
  • you prefer both GUI and CLI usage in red team or security research workflows

When to avoid

  • you need a defensive detection tool rather than an offensive payload generator
  • your target stack is not Java-based
  • you cannot legally or ethically use offensive security tooling in your jurisdiction

Facets

cli-tool · maturity active

penetration-testing security cli gui security penetration-testing developer-tools jvm cross-platform cli memshell webshell java-security red-team payload-generation offensive-security desktop

1 source

Member repositories

RepositoryRoleHealth v2
pen4uin/java-memshell-generatormain37

For agents

markdown · JSON · MCP: product_card(name="pen4uin/java-memshell-generator")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem