Ross ROSS = Recommend OSS · open-source software intelligence for agents

veo/wsMemShell

WebSocket 内存马/Webshell,一种新型内存马/WebShell技术 observed · 2026-08-28

github.com/veo/wsMemShell · homepage · Java observed · 2026-08-28

Health v2 · maintenance only

32/100

  • Activity 0
  • Release rhythm 35
  • Longevity 100

Flags: no_releases no_license

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 1525
  • days_rel: n/a
  • days_push: 1241
  • n_releases_24m: 0

Full methodology

Adoption not part of the score

1490 stars · 228 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

A Java-based WebSocket memory webshell (memshell) tool that injects WebSocket endpoints into running application servers like Tomcat, Spring, Jetty, WebSphere, WebLogic, and Resin for covert command execution and proxying. It also includes variants that bypass Nginx/CDN WebSocket restrictions via JSP-based connections.

Use cases

  • inject a websocket memshell into tomcat
  • bypass nginx websocket proxy restrictions
  • establish covert c2 channel via websocket
  • red team persistence in java application servers
  • test memshell detection tools
  • proxy traffic through websocket shell

When to choose

  • conducting authorized red team exercises against Java application servers
  • researching memshell techniques and defenses
  • testing detection coverage for WebSocket-based memory webshells

When to avoid

  • production systems without explicit authorization
  • non-Java environments other than the tested servers
  • projects requiring a maintained, licensed dependency

Facets

library · maturity maintenance

security websocket proxy penetration-testing security penetration-testing web-development jvm memshell webshell red-team java tomcat spring jetty weblogic nodejs

3 sources

Member repositories

RepositoryRoleHealth v2
veo/wsMemShellmain32

For agents

markdown · JSON · MCP: product_card(name="veo/wsMemShell")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem