This is your work, valued
hackUtils. It is a hack tool kit for pentest and web security research.
519WinSystemHelper. A tool that checks and downloads scripts that will aid with privilege escalation on a Windows system.
172HackRequests. It is a dedicated requests lib that supports cookie, headers, get/post, etc. And it also supports rendering the response (e.g. Javascript, CSS, etc.) of GET requests by using PhantomJs enginee.
86WordPress_4.9.8_RCE_POC. A simple PoC for WordPress RCE (author priviledge), refer to CVE-2019-8942 and CVE-2019-8943.
74SambaHunter. It is a simple script to exploit RCE for Samba (CVE-2017-7494 ).
57ysoserial. A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.
48RootHelper. A Bash script that downloads and unzips scripts that will aid with privilege escalation on a Linux system.
47CVE-2018-11788. Apache Karaf XXE Vulnerability (CVE-2018-11788)
37S2-053-CVE-2017-12611. A simple script for exploit RCE for Struts 2 S2-053(CVE-2017-12611)
37myPadBuster. It is a Python+Perl script to exploit ASP.net Padding Oracle vulnerability.
18CVE-2017-4878-Samples. CVE-2017-4878 Samples - http://blog.talosintelligence.com/2018/02/group-123-goes-wild.html
17RTEmulation. It is a repository for Red Team emulation based on MITRE ATT&CK.
16S2-057-CVE-2018-11776. A simple exploit for Apache Struts RCE S2-057 (CVE-2018-11776)
16Mind-Map. 各种安全相关思维导图整理收集
12CVE-2016-0051. BSoD PoC for CVE-2016-0051 (MS-016)
10CVE-2018-11761. Apache Tika Denial of Service Vulnerability (CVE-2018-11761)
9openvpn-easy-config. openvpn easy config for Ubuntu ONLY
8Joomla3.7-SQLi-CVE-2017-8917. Joomla 3.7 SQL injection (CVE-2017-8917)
7BlueLotus_XSSReceiver. XSS平台 CTF工具 Web安全工具
7TechArticles. A set of tech articles.
7Magento-CVE-2016-4010. Magento Unauthorized Remote Code Execution (CVE-2016-4010)
6CVE-2019-6690. It is a simple PoC of Improper Input Validation in python-gnupg 0.4.3 (CVE-2019-6690).
6xsshunter. The XSS Hunter service - a portable version of XSSHunter.com
5cve-2006-6184. This is a python-based standalone exploit for CVE-2006-6184. This exploit triggers a stack-based buffer overflows in Allied Telesyn TFTP Server (AT-TFTP) 1.9, and possibly earlier, allow remote attackers to cause a denial of service or execute arbitrary code.
5Scanners-Box. 安全行业从业人员自研开源扫描器合集(不收录w3af、brakeman等知名扫描工具)
4fileBatchUpload. 基于菜刀PHP一句话实现单个文件批量上传
4Awesome-Red-Teaming. List of Awesome Red Teaming Resources
3DeathStar. Automate getting Domain Admin using Empire (https://github.com/EmpireProject/Empire)
3BlueKeep. Proof of concept for CVE-2019-0708
3checkVT. This is Python script to calculate SH256 for all files under the defined file path and check the scanning results on VirusTotal.com
3NagaScan. NagaScan is a distributed passive vulnerability scanner for Web application.
3awesome-jenkins-rce-2019. There is no pre-auth RCE in Jenkins since May 2017, but this is the one!
3AwesomeSOC. This repository is a set of articles about what SOC is and how SOC is working in a big Internet firm.
3awesome-pentest. A collection of awesome penetration testing resources, tools and other shiny things
2ctf-tools. Some setup scripts for security research tools.
2antSword. 中国蚁剑是一款跨平台的开源网站管理工具
2fame. FAME Automates Malware Evaluation
2jdwp-shellifier. Python
2awesome-python-cn. Python资源大全中文版,包括:Web框架、网络爬虫、模板引擎、数据库、数据可视化、图片处理等,由伯乐在线持续更新。
2assetnote. Push notifications for passive DNS data
2exploits. Python
2VulScritp. 内网渗透脚本
2QuasarRAT. Remote Administration Tool for Windows
2MS17-010. MS17-010
2Awsome-Redis-Rogue-Server. Redis-Rogue-Server Implement
2Java-Deserialization-Cheat-Sheet. The cheat sheet about Java Deserialization vulnerabilities
2Infosec_Reference. An Information Security Reference That Doesn't Suck
2pocscan. Will to be a niubility scan-framework
2CDK. CDK is an open-sourced container penetration toolkit, offering stable exploitation in different slimmed containers without any OS dependency. It comes with penetration tools and many powerful PoCs/EXPs helps you to escape container and takeover K8s cluster easily.
1CVE-2020-0683. CVE-2020-0683 - Windows MSI “Installer service” Elevation of Privilege
1security-research. This project hosts security advisories and their accompanying proof-of-concepts related to research conducted at Google which impact non-Google owned code.
1WMImplant. This is a PowerShell based tool that is designed to act like a RAT. Its interface is that of a shell where any command that is supported is translated into a WMI-equivalent for use on a network/remote machine. WMImplant is WMI based.
1PayloadsAllTheThings. A list of useful payloads and bypass for Web Application Security and Pentest/CTF
1XXEinjector. Tool for automatic exploitation of XXE vulnerability using direct and different out of band methods.
1meltdown-exploit. C
1process_doppelganging. My implementation of enSilo's Process Doppelganging (PE injection technique)
1red-team-scripts. A collection of Red Team focused tools, scripts, and notes
1monkey. Infection Monkey - An automated pentest tool
1