Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Tools/GitHubGitHub/qtc-de/beanshooter
Vulnerability AnalysisExploitationPenetration Testing
GitHubqtc-de/beanshooter

beanshooter

JMX enumeration and attacking tool.

View Repository
50955513 years agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

beanshooter


beanshooter is a JMX enumeration and attacking tool, which helps to identify common vulnerabilities on JMX endpoints.

https://user-images.githubusercontent.com/49147108/183278179-4a5566a7-5af8-4ce8-a73d-1016876a36d5.mp4

Installation


beanshooter is a maven project and installation should be straight forward. With maven installed, just execute the following commands to create an executable .jar file:

[qtc@devbox ~]$ git clone https://github.com/qtc-de/beanshooter
[qtc@devbox ~]$ cd beanshooter
[qtc@devbox ~]$ mvn package

You can also use prebuild packages that are created for each release. Prebuild packages for the development branch are created automatically and can be found on the GitHub actions page. Also a prebuild docker image for running beanshooter is available.

beanshooter does not include ysoserial as a dependency. To enable ysoserial support, you need either specify the path to your ysoserial.jar file as additional argument (e.g. --yso /opt/ysoserial.jar) or you change the default path within the beanshooter configuration file before building the project.

beanshooter supports autocompletion for bash. To take advantage of autocompletion, you need to have the completion-helpers project installed. If setup correctly, just copying the completion script to your ~/.bash_completion.d folder enables autocompletion.

[qtc@devbox ~]$ cp resources/bash_completion.d/beanshooter ~/bash_completion.d/

Table of Contents


  • Supported Operations
    • Basic Operations
      • attr
      • brute
      • deploy
      • enum
      • info
      • invoke
      • jolokia
      • list
      • model
      • serial
      • stager
      • standard
      • undeploy
    • MBean Operations
      • generic
        • attr
        • info
        • invoke
        • stats
        • status
        • export
        • deploy
        • undeploy
      • diagnostic
        • read
        • load
        • logfile
        • nolog
        • cmdline
        • props
      • hotspot
        • dump
        • list
        • get
        • set
      • mlet
        • load
      • recorder
        • new
        • start
        • stop
        • read
        • dump
      • tomcat
        • dump
        • list
        • write
      • tonka
        • exec
        • execarray
        • shell
        • upload
        • download
  • JMXMP
  • Jolokia Support
  • Docker Image
  • Example Server

Supported Operations


The different beanshooter operations can be divided into two groups: basic operations and MBean operations. Whereas basic operations are used to perform general operations on a JMX endpoint, MBean operations target a specific MBean to interact with. For more details, check the usage examples in the following sections.

[qtc@devbox ~]$ beanshooter -h
usage: beanshooter [-h]   ...

beanshooter v3.0.0 - a JMX enumeration and attacking tool

positional arguments:

 Basic Operations
    attr                 set or get MBean attributes
    brute                bruteforce JMX credentials
    deploy               deploys the specified MBean on the JMX server
    enum                 enumerate the JMX service for common vulnerabilities
    info                 display method and attribute information on an MBean
    invoke               invoke the specified method on the specified MBean
    list                 list available MBEans on the remote MBean server
    serial               perform a deserialization attack
    stager               start a stager server to deliver MBeans
    undeploy             undeploys the specified MBEAN from the JMX server

 MBean Operations
    diagnostic           Diagnostic Command MBean
    hotspot              HotSpot Diagnostic MBean
    mlet                 default JMX bean that can be used to load additional beans dynamically
    recorder             jfr Flight Recorder MBean
    tomcat               tomcat MemoryUserDatabaseMBean used for user management
    tonka                general purpose bean for executing commands and uploading or download files

named arguments:
  -h, --help             show this help message and exit

Basic Operations


Basic operations are general purpose operations that can be performed on a JMX service. These are usually operations that do not target a specific MBean or that target an MBean with no builtin support by beanshooter.

Attr

The attr action can be used to get or set attributes on a specified MBean. To obtain available attributes, the info action should be used:

[qtc@devbox ~]$ beanshooter info 172.17.0.2 9010
...
[+] MBean Class: sun.management.MemoryImpl
[+] ObjectName: java.lang:type=Memory
[+]
[+]     Attributes:
[+]         Verbose (type: boolean , writable: true)
[+]         ObjectPendingFinalizationCount (type: int , writable: false)
[+]         HeapMemoryUsage (type: javax.management.openmbean.CompositeData , writable: false)
[+]         NonHeapMemoryUsage (type: javax.management.openmbean.CompositeData , writable: false)
[+]         ObjectName (type: javax.management.ObjectName , writable: false)
[+]
[+]     Operations:
[+]         void gc()

When just the attribute name is specified, beanshooter obtains and displays the current attribute value:

[qtc@devbox ~]$ beanshooter attr 172.17.0.2 9010 java.lang:type=Memory Verbose
false

When an additional value is specified, beanshooter attempts to set the corresponding attribute. For attributes that have a different type than String, specifying the attribute type using the --type option is required:

[qtc@devbox ~]$ beanshooter attr 172.17.0.2 9010 java.lang:type=Memory Verbose true --type boolean
[qtc@devbox ~]$ beanshooter attr 172.17.0.2 9010 java.lang:type=Memory Verbose
true

Brute

Download Tool