# pen4uin/java-memshell-generator

一款支持自定义的 Java 内存马生成工具｜A customizable Java in-memory webshell generation tool.

Repository: https://github.com/pen4uin/java-memshell-generator
Canonical: https://ross.abutalabs.com/products/java-memshell-generator
Language: Java
License: MIT
License Family: permissive
Topics: memshell, webshell, payload, java, real-world
Last push: 2025-08-21T10:21:10+00:00

## Health v2 (maintenance only)
Score: 37/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 38, release rhythm 8, longevity 84
- inputs: {"age_days": 1187, "days_push": 377, "days_rel": 609, "gap_med": null, "n_releases_24m": 1}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 2230, forks 232 (observed 2026-08-28T04:06:29.040677+00:00)

## What it is
A highly customizable Java in-memory webshell (memshell) generator supporting multiple middleware servers, frameworks, shell types, and output formats, with both GUI and command-line interfaces. It is intended for security research and penetration testing, with integration support for tools like AntSword, Behinder, Godzilla, Neo-reGeorg, and Suo5.

## Use cases
- generate java memshell payloads for tomcat or weblogic
- create in-memory webshells for penetration testing engagements
- generate listener or filter memshells compatible with antsword or behinder
- customize memshell payloads for spring webflux or undertow
- produce bcel or base64 encoded payload output for security research
- test web application defenses against in-memory webshell attacks

## When to choose
- you need a customizable memshell generator covering many Java middleware and frameworks
- you want payload output in multiple formats (BASE64, BCEL, CLASS, JAR, JSP) for different post-exploitation tools
- you prefer both GUI and CLI usage in red team or security research workflows

## When to avoid
- you need a defensive detection tool rather than an offensive payload generator
- your target stack is not Java-based
- you cannot legally or ethically use offensive security tooling in your jurisdiction

## Facets
- artifact type: cli-tool
- maturity: active
- function: penetration-testing, security, cli, gui
- domain: security, penetration-testing, developer-tools
- platform: jvm, cross-platform, cli
- tags: memshell, webshell, java-security, red-team, payload-generation, offensive-security, desktop

## Member repositories
- pen4uin/java-memshell-generator (main) score 37

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:06:29.040677+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T02:44:38.705503+00:00, confidence not recorded.
  - readme: https://github.com/pen4uin/java-memshell-generator (fetched 2026-08-28T04:06:29.040677+00:00, sha 44a32c705bb6)
- Data as of 2026-08-30T08:39:29.467469+00:00.
