# ReaJason/MemShellParty

一款专注于 Java 主流 Web 中间件的内存马快速生成工具，致力于简化安全研究人员和红队成员的工作流程，提升攻防效率

Repository: https://github.com/ReaJason/MemShellParty
Canonical: https://ross.abutalabs.com/products/memshellparty
Homepage: https://party.mem.mk
Language: Java
License: MIT
License Family: permissive
Topics: asm, bytebuddy, javasecurity, javaweb, memshell, payload, webshell, javaagent, javassist
Last push: 2026-08-26T10:17:34+00:00

## Health v2 (maintenance only)
Score: 89/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 99, release rhythm 96, longevity 52
- inputs: {"age_days": 731, "days_push": 7, "days_rel": 30, "gap_med": 13.0, "n_releases_24m": 29}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1581, forks 160 (observed 2026-08-28T04:05:06.925508+00:00)

## What it is
MemShellParty is a self-hosted, visual tool for rapidly generating Java memory shells (fileless webshells) for mainstream web middleware and frameworks like Tomcat, Spring, and GlassFish. It supports generating payloads for Godzilla, Behinder, AntSword, Suo5, and Neo-reGeorg, plus probe shells and exploit payloads for expression injection, deserialization, and SSTI vulnerabilities.

## Use cases
- generate java memory shells for tomcat
- create fileless webshell payloads for red team engagements
- generate godzilla or behinder memshell payloads
- build java agent memshells with small bytecode size
- generate probe shells to detect middleware type
- create payloads for expression injection and deserialization exploits
- self-host a memshell generation platform for authorized testing

## When to choose
- you are a security researcher or red teamer needing reliable, tested Java memshell payloads across many middleware versions
- you want a visual, one-click generator with a compatibility matrix and automated testing
- you need lightweight payloads compatible with JDK 6 through 21

## When to avoid
- you need webshells for non-Java stacks like PHP or ASP
- you are looking for a defensive detection tool rather than an offensive payload generator
- unauthorized use - it is strictly for authorized security testing and research

## Facets
- artifact type: application
- maturity: active
- function: security, developer-tools, self-hosted, gui, testing
- domain: security, penetration-testing, web-development, developer-tools, self-hosted
- platform: self-hosted, jvm, cross-platform
- tags: memshell, webshell, red-team, java-agent, payload-generation, bytecode-generation, asm, bytebuddy, offensive-security, middleware, docker, web-server

## Member repositories
- ReaJason/MemShellParty (main) score 89

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:05:06.925508+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T03:56:21.245225+00:00, confidence not recorded.
  - readme: https://github.com/ReaJason/MemShellParty (fetched 2026-08-28T04:05:06.925508+00:00, sha db0b677fc96d)
  - homepage: https://party.mem.mk (fetched 2026-08-29T11:26:40.694922+00:00, sha 68767122190f)
  - site_page: https://party.mem.mk/ui/docs (fetched 2026-08-29T11:26:40.703845+00:00, sha 929ebdfb0c94)
  - site_page: https://party.mem.mk/ui/about (fetched 2026-08-29T11:26:40.705915+00:00, sha 803e000accc7)
- Data as of 2026-08-30T08:39:29.467469+00:00.
