<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Java安全 :: 标签 :: x7peeps</title><link>https://x7peeps.com/tags/Java%E5%AE%89%E5%85%A8/index.html</link><description/><generator>Hugo</generator><language>zh-CN</language><lastBuildDate>Thu, 13 Aug 2026 13:03:16 +0000</lastBuildDate><atom:link href="https://x7peeps.com/tags/Java%E5%AE%89%E5%85%A8/index.xml" rel="self" type="application/rss+xml"/><item><title>Java 内存马应急检测实战：从手册到开源工具的全栈演进</title><link>https://x7peeps.com/%E5%AE%89%E5%85%A8/%E5%BA%94%E6%80%A5%E5%93%8D%E5%BA%94/Java%E5%86%85%E5%AD%98%E9%A9%AC%E5%BA%94%E6%80%A5%E6%A3%80%E6%B5%8B%E5%AE%9E%E6%88%98/index.html</link><pubDate>Thu, 13 Aug 2026 13:03:16 +0000</pubDate><guid>https://x7peeps.com/%E5%AE%89%E5%85%A8/%E5%BA%94%E6%80%A5%E5%93%8D%E5%BA%94/Java%E5%86%85%E5%AD%98%E9%A9%AC%E5%BA%94%E6%80%A5%E6%A3%80%E6%B5%8B%E5%AE%9E%E6%88%98/index.html</guid><description>Java 内存马应急检测实战：从手册到开源工具的全栈演进 摘要 内存马（Memory Shell）已成为攻陷 Java 应用后的首选持久化手段——它在 JVM 内存中动态注册恶意组件，磁盘无文件、进程无异常、杀软无感知，传统基于文件的检测体系完全失效。本文以实战视角完整呈现 Java 内存马的检测方法论、工具设计演进与取证闭环：从信号分级体系（A1-A5 强信号 + B1-B5 辅助信号）到开源工具 memshell-auditor 的落地，再到双程序防识别架构、类 Metasploit 特征库生态与 AI 增强分析。全部结论基于真实实验：用 java-memshell-generator（JMG）生成 7 种真实内存马载荷，注入 Tomcat 9/10 靶场逐一验证，检出率 100%。</description></item></channel></rss>