# veo/wsMemShell

WebSocket 内存马/Webshell，一种新型内存马/WebShell技术

Repository: https://github.com/veo/wsMemShell
Canonical: https://ross.abutalabs.com/products/wsmemshell
Homepage: https://veo.pub/2022/memshell/
Language: Java
License Family: other
Topics: memshell, webshell, websocket, proxy
Last push: 2023-04-10T06:43:06+00:00

## Health v2 (maintenance only)
Score: 32/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 0, release rhythm 35, longevity 100
- inputs: {"age_days": 1525, "days_push": 1241, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: no_releases, no_license
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1490, forks 228 (observed 2026-08-28T04:04:52.440803+00:00)

## What it is
A Java-based WebSocket memory webshell (memshell) tool that injects WebSocket endpoints into running application servers like Tomcat, Spring, Jetty, WebSphere, WebLogic, and Resin for covert command execution and proxying. It also includes variants that bypass Nginx/CDN WebSocket restrictions via JSP-based connections.

## Use cases
- inject a websocket memshell into tomcat
- bypass nginx websocket proxy restrictions
- establish covert c2 channel via websocket
- red team persistence in java application servers
- test memshell detection tools
- proxy traffic through websocket shell

## When to choose
- conducting authorized red team exercises against Java application servers
- researching memshell techniques and defenses
- testing detection coverage for WebSocket-based memory webshells

## When to avoid
- production systems without explicit authorization
- non-Java environments other than the tested servers
- projects requiring a maintained, licensed dependency

## Facets
- artifact type: library
- maturity: maintenance
- function: security, websocket, proxy, penetration-testing
- domain: security, penetration-testing, web-development
- platform: jvm
- tags: memshell, webshell, red-team, java, tomcat, spring, jetty, weblogic, nodejs

## Member repositories
- veo/wsMemShell (main) score 32

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:04:52.440803+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T04:33:38.373370+00:00, confidence not recorded.
  - readme: https://github.com/veo/wsMemShell (fetched 2026-08-28T04:04:52.440803+00:00, sha ca6fa77edd7c)
  - homepage: https://veo.pub/2022/memshell/ (fetched 2026-08-29T11:39:33.669132+00:00, sha fd6380ac4186)
  - site_page: https://veo.pub/about (fetched 2026-08-29T11:39:33.678297+00:00, sha 4e0e5814e6a0)
- Data as of 2026-08-30T08:39:29.467469+00:00.
