{"id":13841191,"url":"https://github.com/spoofzu/jvmxray","last_synced_at":"2026-03-05T17:57:03.251Z","repository":{"id":39577615,"uuid":"239575109","full_name":"spoofzu/jvmxray","owner":"spoofzu","description":"Externalize Java application access to protected resources as log messages.","archived":false,"fork":false,"pushed_at":"2026-01-21T18:21:16.000Z","size":1998,"stargazers_count":43,"open_issues_count":1,"forks_count":5,"subscribers_count":5,"default_branch":"master","last_synced_at":"2026-01-22T06:27:07.188Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":"","language":"Java","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"apache-2.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/spoofzu.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":"NOTICE","maintainers":null,"copyright":null,"agents":null,"dco":null,"cla":null}},"created_at":"2020-02-10T17:48:14.000Z","updated_at":"2026-01-21T19:36:24.000Z","dependencies_parsed_at":"2024-04-12T15:03:47.068Z","dependency_job_id":"77ed0307-5025-45fa-92a8-446d80a664bf","html_url":"https://github.com/spoofzu/jvmxray","commit_stats":null,"previous_names":[],"tags_count":4,"template":false,"template_full_name":null,"purl":"pkg:github/spoofzu/jvmxray","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/spoofzu%2Fjvmxray","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/spoofzu%2Fjvmxray/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/spoofzu%2Fjvmxray/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/spoofzu%2Fjvmxray/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/spoofzu","download_url":"https://codeload.github.com/spoofzu/jvmxray/tar.gz/refs/heads/master","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/spoofzu%2Fjvmxray/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":30140957,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-03-05T16:58:46.102Z","status":"ssl_error","status_checked_at":"2026-03-05T16:58:45.706Z","response_time":93,"last_error":"SSL_read: unexpected eof while reading","robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":false,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2024-08-04T17:01:04.076Z","updated_at":"2026-03-05T17:57:03.217Z","avatar_url":"https://github.com/spoofzu.png","language":"Java","funding_links":[],"categories":["Java","Java (504)"],"sub_categories":[],"readme":"\n# Welcome to JVMXRay\n\n[![Black Hat Arsenal](https://raw.githubusercontent.com/toolswatch/badges/master/arsenal/usa/2020.svg?sanitize=true)](https://www.toolswatch.org/blackhat-arsenal-us-2020-archive/)\n\n\u003cpicture\u003e\n  \u003csource srcset=\"https://github.com/spoofzu/jvmxray/blob/master/build/lightduke.png?raw=true\" media=\"(prefers-color-scheme: dark)\"\u003e\n  \u003csource srcset=\"https://github.com/spoofzu/jvmxray/blob/master/build/darkduke.png?raw=true\" media=\"(prefers-color-scheme: light)\"\u003e\n  \u003cimg src=\"https://github.com/spoofzu/jvmxray/blob/master/build/lightduke.png\" alt=\"Logo\" width=\"200\"\u003e\n\u003c/picture\u003e\n\n|                 \u0026nbsp;                         |  \u0026nbsp;                                                                                                                                                                                                                                                                                                     |\n|-----------------------------------------|------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|\n| **JVMXRay**                             | JVMXRay is a technology for monitoring access to protected system resources by your Java applications like files, sockets, classes, and more. It’s designed with an application security emphasis but there are benefits across other areas like software diagnostics, usage tracking, and auditing. |\n| \u0026nbsp;  |  \u0026nbsp;                                                                                                                                                                                                                                                              |\n| **NEWS**                                | \u0026nbsp;                                                                                                                                                                                                                                                                                               |\n| **Apr 23, 2025** Platform rearchitected | Architecture improved to remove deprecated SecurityManager and move to byte code injection approach.                                                                                                                                                                                                 |\n| **Feb 20, 2024** Improved architecture  | Improved documentation for new architecture. Site docs forthcoming.                                                                                                                                                                                                                                  |\n| **Apr 28, 2023** Documentation updated  | Improved documentation for new architecture.                                                                                                                                                                                                                                                         |\n| **Apr 5, 2023** Architectural overhaul  | The system has been simplified to a few components: 1) Injector that delivers a payload to a process by PID, 2) Java agent for monitoring code delivery, 3) the monitoring code itself. Initial wiki improvements have been applied with more to come.                                               |\n| **Jun 16, 2021** Architecture overhaul  | Many improvements delivered. Wiki update in progress to reflect improvements.                                                                                                                                                                                                                        |\n| **Feb 10, 2021** Many improvements      | See latest delivery notes and [updated project WIKI...](https://github.com/spoofzu/jvmxray/wiki)                                                                                                                                                                                                     |\n\n[Duke: Oracle's Java mascot...](https://wiki.openjdk.java.net/display/duke/Main)\n\n## Many Benefits\nFollowing are a quick list of important benefits.\n\n### :rocket: Monitor \u0026 identify application access to protected resources\nWhat is your application doing?  Monitor events of interest related to protected resources like: sockets, files, process execution, software supply chains, and more.\n\n### :rocket: Improve insights into your software supply chain\nJVMXRay doesn't require access to applications source code.  JVMXRay monitors your server including 3rd party libraries or commercial application where you may not have source code.\n\n### :rocket: Extreme flexiblity \u0026 versitily\nInternally JVMXRay supports logback logging.  Use standard logback configuration to specify types events and level of metadata captured, how, and where security events are logged.  Use your present centralized logging solution or handle security events distinctly.  Security event destinations are anywhere supported by the logback framework.  Connect RDBMs via JDBC, rolling text files, Flume, Kafka, JMS, NoSQL DBs like Cassandra/Mongo/CouchDB, SMTP email messges, *NIX syslogs, and your own custom solutions via HTTP, socket appenders, etc.  These are not JVMXRay features but are features of popular logging frameworks and leveraged by JVMXRay for security events.  No reason to reinvent the wheel.\n\n### :rocket: Low entry barrier: no code changes required, extensible, and open\nJVMXRay is easy to setup since it uses your current logging frameworks configuration.  Know how to setup a log4j2 or logback configuration file?  Your ready to start!100% Java code so it runs anywhere your Java apps run.\n\n```\nINFORMATION:\nConsider the project early stage code.\n```\n\n## Audience\nThe anticipated audience for JVMXRay is two-fold,\u003cbr/\u003e\n\n**Systems Administrators**\nIndividuals charged with system security and interested in new methods to gather security inteligence into Java applications.\n\n**Security Developers \u0026 Architects**\nIndiviudals interested in improved security intelligence about their applications.\n\n\u003c!-- TODO: // Update example\n# Deploying JVMXRay with Examples\nThe following provides some basic information to download and compile JVMXRay source on your computer.  Remainder of the video shows how to get JVMXRay working with Tomcat and work with Tomcat's examples.\n\n[![](http://img.youtube.com/vi/QxgTiTCorow/0.jpg)](http://www.youtube.com/watch?v=QxgTiTCorow \"JVMXRay Deploy\")\n--\u003e\n# Security Event Log Fragment...\n\nSecurity event destinations and formats are flexible but here's some sample messages from the projects unit tests.\n\n```\n...\n2025.04.23 at 16:38:52 CDT | jvmxray.sensor-1 |  INFO | org.jvmxray.events.io.filedelete |  | caller=java.io.File:1075, target=/Users/milton/.webgoat-2025.4-SNAPSHOT/webgoat.properties, status=successfully deleted\n2025.04.23 at 16:38:51 CDT | jvmxray.sensor-1 |  INFO | org.jvmxray.events.monitor |  | GCCount=1, ThreadNew=0, ThreadWaiting=2, ThreadTerminated=0, NonHeapUsed=11.6MB, GCTime=1ms, DeadlockedThreads=0, ProcessCpuLoad=0%, ThreadBlocked=0, MemoryFree=566.3MB, caller=java.lang.Thread:1575, OpenFiles=163, ThreadRunnable=2, MemoryMax=9GB, MemoryTotal=584MB\n2025.04.23 at 16:38:51 CDT | jvmxray.sensor-1 |  INFO | org.jvmxray.events.system.lib |  | method=static, jarPath=/Users/milton/.m2/repository/org/springframework/boot/spring-boot-configuration-metadata/3.4.3/spring-boot-configuration-metadata-3.4.3.jar, caller=sun.instrument.InstrumentationImpl:560\n2025.04.23 at 16:38:51 CDT | jvmxray.sensor-1 |  INFO | org.jvmxray.events.system.lib |  | method=dynamic, jarPath=/Users/milton/github/jvmxray/agent/target/agent-0.0.1-shaded.jar, caller=java.lang.Thread:1575\n...\n\n```\n\n## How it Works\nJVMXRay runs as a Java Agent and is injected at startup into your project via Java command line parameter.  When the Agent initializes, it installs sensors via byte-code injection monitoring access to protected resources (files, http connections, etc) by your program and third party programs. Event metadata is logged as a Logback log message.  Logback is a popular logging platform, very powerful and flexible, and facilites security event handling in many ways.  Tools and tip for configuring Logback are available widely and many books are available.  \n\n## Project Contributors(s)\nMilton Smith - Project creator, leader\n\nDisclosure(s):  The JVMXRay project is not, approved, endorsed by, or affiliated with Oracle Corporation.  Oracle is a long-time supporter of secure open source software and the Online Web Application Security(OWASP) project.  Milton Smith is active in the open source community and an employee of Oracle.\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fspoofzu%2Fjvmxray","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fspoofzu%2Fjvmxray","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fspoofzu%2Fjvmxray/lists"}