This is your work, valued
Erebus. CobaltStrike后渗透测试插件
1.6kMDUT-Extend-Release. MDUT-Extend(扩展版本)
932WindowsBaselineAssistant. Windows安全基线核查加固助手
568JDumpSpiderGUI. JDumpSpiderGUI 是一个用于 Java 堆转储文件分析的工具,支持命令行和 JavaFX 图形界面两种模式。该工具主要是在原工具上添加了图形化的界面
174Webshell-bypass-collection. 收集的一些各种语言的免杀webshell
105Browser-cookie-steal. Python script for steal browser cookies
67JetbrainsServerFinder. 一个利用Shodan搜索引擎查询Jetbrains系列产品激活服务器的网页端工具
61AutoRemove. Python script for auto remove AV
42GodzillaSource. Godzilla4.01 decompile code
29CVE-2022-28346. Django QuerySet.annotate(), aggregate(), extra() SQL 注入
24sRDI-nim. A nim implementation of sRDI
20safedog_bypass. a safedog fuzzing python script
18CVE-2022-22978. CVE-2022-22978 Spring-Security bypass Demo
15Mysqlmonitor. Mysql数据库执行监控
12PhpStudy-RCE-Tool. PhpStudy 命令执行工具
8Gadgets. 零碎的一些小玩意儿
6Siteserver-RTD. Siteserver 4.x-5.x RTD Getshell Tool
5TakeCareYourAss. 拯救你的屁股,别让你的椅子成为健康杀手。Take Care Your Ass!
5HideNimMain. Hide the exported NimMain in a DLL
5ysoserial. ysoserial4su18
4Red-Team-links. 2019年红队资源链接,资源不是本人整理出来,来自互联网,因为流传的少,特意在此做个备份,做个分享。
4Sangfor-edr-RCE. exp for sangfor edr
4NET-Deserialize. 总结了十篇.Net反序列化文章,持续更新
4BurpSuite-collections. BurpSuite收集:包括不限于 Burp 文章、破解版、插件(非BApp Store)、汉化等相关教程,欢迎添砖加瓦
4pochubs. PocHubs是为了整合网上知名开源框架的漏洞详细和POC
3HiveJack-Console. Console edition for hivejack , based on .net framework 2.0
3Cobalt_Strike_wiki. Cobalt Strike系列
3myfuzz. 从总多目录字典中合并提取的高效目录爆破字典
2AppLoader. 一个多jdk环境下jar程序加载器
2Apache-Flink-Exp. Apache Flink Exp
2ARL. ARL官方仓库备份项目:ARL(Asset Reconnaissance Lighthouse)资产侦察灯塔系统旨在快速侦察与目标关联的互联网资产,构建基础资产信息库。 协助甲方安全团队或者渗透测试人员有效侦察和检索资产,发现存在的薄弱点和攻击面。
2Pentest-and-Development-Tips. A collection of pentest and development tips
2Ai-Cheat. Csgo cheating demo based on yolov5
1CVE-2022-39197-patch. CVE-2022-39197 漏洞补丁. CVE-2022-39197 Vulnerability Patch.
1NjRat-2.3D-Rat. Latest version of NjRat 2.3D
1DeEpinGh0st. My personal repository
1freeproxy. 免费获取http代理并生成proxifier配置文件
1shiro_rce. shiro rce 反序列 命令执行 工具
1thinkphp-RCE-POC-Collection. thinkphp v5.x 远程代码执行漏洞-POC集合
1WebShell. Webshell && Backdoor Collection
1behinder_source. 冰蝎的源码(Decompile & Fixed)
1SpringCore0day. SpringCore0day from https://share.vx-underground.org/
1ARL-Finger-ADD-Go. ARL(灯塔)批量添加指纹
1FlipperZero-CN-Firmware. FlipperZero 中文固件(备份防丢)
1HVVExploitApply. 使用JAVAFX图形化界面检测对HVV中常见的重点CMS系统和OA系统的已公开的漏洞进行验证。
1Log4jAttackSurface.
1wiki. 漏洞文库备份 wiki.wy876.cn
1hide_execute_memory. 隐藏可执行内存
1v2ray. 最好用的 V2Ray 一键安装脚本 & 管理脚本
1deepingh0st.github.io. it's my personel blog
1JNDIExploit. 一款用于 JNDI注入 利用的工具,大量参考/引用了 Rogue JNDI 项目的代码,支持直接植入内存shell,并集成了常见的bypass 高版本JDK的方式,适用于与自动化工具配合使用。(from https://github.com/feihong-cs/JNDIExploit)
1JDSRC-Small-Classroom. 京东SRC小课堂系列文章
1