awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
wh1t3p1g avatar

wh1t3p1g/ysomap

0
View on GitHub↗
1,240 stars·149 forks·Java·Apache-2.0·9 views

Ysomap

A helpful Java Deserialization exploit framework.

Features

  • Deserialization Exploits - Tool for managing and generating deserialization payloads.
  • Deserialization Tools - Framework for dynamic Java deserialization payload generation.

Star history

Star history chart for wh1t3p1g/ysomapStar history chart for wh1t3p1g/ysomap

How this analysis was created: This summary and feature list are AI-generated from collected project material and can contain mistakes. Stars, license and language are imported from GitHub. Inclusion does not mean that we have tested or audited this project. Check the source documentation for any feature you depend on. Learn more on our About page.

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Start searching with AI

Projects sharing features with Ysomap

These projects share indexed features with Ysomap. Shared tags can include platform or build tooling; verify the primary use case before treating a result as a replacement.
  • mbechler/marshalsecmbechler avatar

    mbechler/marshalsec

    3,691View on GitHub↗

    Marshalsec is a toolkit designed for generating malicious serialized Java objects to achieve remote code execution during the unmarshalling process. It functions as a Java deserialization exploit tool and a framework for triggering Java Naming and Directory Interface lookups to remote servers. The project provides a JNDI redirector service that intercepts lookups and points targets toward a remote codebase. It includes utilities for crafting payloads that force Java applications to download and execute arbitrary classes from a remote URL. The toolset covers security analysis activities inclu

    Java
    View on GitHub↗3,691
  • qi4l/jysoqi4L avatar

    qi4L/JYso

    1,752View on GitHub↗

    JNDIExploit or a ysoserial.

    Javaattackgadgetjava
    View on GitHub↗1,752
  • frohoff/ysoserialfrohoff avatar

    frohoff/ysoserial

    8,750View on GitHub↗

    ysoserial is a security research tool and payload generator designed to identify and exploit insecure Java deserialization. It functions as a framework for creating malicious serialized objects that can trigger remote code execution on Java virtual machines. The project provides a library of known gadget chains, which are sequences of vulnerable class calls that achieve arbitrary command execution during the deserialization process. It automates the generation of these payloads by leveraging common third-party libraries. The tool covers capabilities for security penetration testing, Java app

    Javadeserializationexploitgadget
    View on GitHub↗8,750
  • y4er/ysoserialY

    Y4er/ysoserial

    0View on GitHub↗
    View on GitHub↗0
Compare all 20 related projects→

Frequently asked questions

What does wh1t3p1g/ysomap do?

A helpful Java Deserialization exploit framework.

What are the main features of wh1t3p1g/ysomap?

The main features of wh1t3p1g/ysomap are: Deserialization Exploits, Deserialization Tools.

Which projects share features with wh1t3p1g/ysomap?

Projects with overlapping indexed features include: qi4l/jyso — JNDIExploit or a ysoserial. y4er/ysoserial. frohoff/ysoserial — ysoserial is a security research tool and payload generator designed to identify and exploit insecure Java… mbechler/marshalsec — Marshalsec is a toolkit designed for generating malicious serialized Java objects to achieve remote code execution… deepingh0st/ysoserial. a-d-team/attackrmi.