For more information about real-world Java deserialization attacks, check out these links: Symantec: https://www.symantec.com/security_response/attacksignatures/detail.jsp?asid=30326 Foxglove Security: https://foxglovesecurity.com/2015/11/06/what-do-weblogic-websphere-jboss-jenkins-opennms-and-your-application-have-in-common-this-vulnerability/ To read more about this Burp plugin, check out https://blog.netspi.com/java-deserialization-attacks-burp/