This is your work, valued
3000
Security-List. If you have any good suggestions or comments during the search process, please feedback some index experience in issues. Thank you for your participation.查阅过程中,如果有什么好的意见或建议,请在Issues反馈,感谢您的参与。
1.5kfuzzdb-collect. 网络上安全资源的搜集
940LayerDomainFinder. Layer子域名挖掘机
459CVE-2020-0618. SQL Server Reporting Services(CVE-2020-0618)中的RCE
196polar-scan. 北极熊扫描器(www.im-fox.com)
83hatchet. cknife(webshell manager)
27ICSwiki. ICSwiki
26SeaySourceCodeCheck. Seay源代码审计系统2.1源码
22CobaltstrikeWiki. collect
17redteam_vul. 红队作战中比较常遇到的一些重点系统漏洞整理。
16WebCruiserWVS. WebCruiserWVS 轻量级基于C#的扫描器,椰树扫描器的前身
11myMalwareSample. MalwareSample
11ms15-051. Windows 内核模式驱动程序中的漏洞可能允许特权提升
8yeezy-scan. C#
6Penetration_Testing_POC. 渗透测试有关的POC、EXP、脚本、提权、小工具等,欢迎补充、完善---About penetration-testing python-script poc getshell csrf xss cms php-getshell domainmod-xss penetration-testing-poc csrf-webshell cobub-razor cve rce sql sql-poc poc-exp bypass oa-getshell cve-cms
4K8tools. K8工具合集(内网渗透/提权工具/远程溢出/漏洞利用/扫描工具/密码破解/免杀工具/Exploit/APT/0day/Shellcode/Payload/priviledge/BypassUAC/OverFlow/WebShell/PenTest) Web GetShell Exploit(Struts2/Zimbra/Weblogic/Tomcat/Apache/Jboss/DotNetNuke/zabbix)
3MoAn_Honey_Pot_Urls. X安蜜罐用的一些存在JSonp劫持的API
3SpoofWeb. 一键部署HTTPS钓鱼站
3TailorScan. 自用缝合怪内网扫描器,支持端口扫描,识别服务,获取title,扫描多网卡,ms17010扫描,icmp存活探测。
3BypassAntiVirus. 远控免杀系列
2poc--exp. 常用渗透poc收集
2HatLab_IOT_Wiki. 海特实验室物联网安全知识库
2exploits. exploits and proof-of-concept vulnerability demonstration files from the team at Hacker House
2Ladon. Ladon一款用于大型网络渗透的多线程插件化综合扫描神器,含端口扫描、服务识别、网络资产、密码爆破、高危漏洞检测以及一键GetShell,支持批量A段/B段/C段以及跨网段扫描,支持URL、主机、域名列表扫描。5.5版本内置39个功能模块,通过多种协议以及方法快速获取目标网络存活主机IP、计算机名、工作组、共享资源、网卡地址、操作系统版本、网站、子域名、中间件、开放服务、路由器、数据库等信息,漏洞检测包含MS17010、Weblogic、ActiveMQ、Tomcat、Struts2等,密码爆破11种含数据库(Mysql、Oracle、MSSQL)、FTP、SSH(Linux主机)、VNC、Windows密码(IPC、WMI、SMB)、Weblogic后台、Rar压缩包密码等,Web指纹识别模块可识别75种(Web应用、中间件、脚本类型、页面类型)等,可高度自定义插件POC支持.NET程序集、DLL(C#/Delphi/VC)、PowerShell等语言编写的插件,支持通过配置INI批量调用任意外部程序或命令,EXP生成器可一键生成漏洞POC快速扩展扫描能力。Ladon支持Cobalt Strike插件化扫描快速拓展内网进行横向移动。
2Smartphone-Pentest-Framework. Repository for the Smartphone Pentest Framework (SPF)
2metasploit-framework. Metasploit Framework
2PRUBUnlimitedre. This project !replace! BurpUnlimited of depend (BurpSutie version 1.7.27). It is NOT intended to replace them!
2Scanners-Box. The toolbox of open source scanners - 安全行业从业者自研开源扫描器合辑
2shellcode-To-DLL. shellcode 异或加密并生成dll
1wiki_TipSkill. wiki_TipSkill
1Flash-Pop. Flash钓鱼弹窗优化版
1polarbearrepo. C++
1awd_attack_framework. awd攻防常用脚本+不死马+crontab+防御方法
1ICS-Security-Tools. Tools, tips, tricks, and more for exploring ICS Security.
1CVE-2016-5195. A CVE-2016-5195 exploit example.
1APT34-Jason. Use to perform Microsoft exchange account brute-force.
1fanqiang. 翻墙-科学上网
1openfire-webshell. openfire上传webshell插件
1Behinder. “冰蝎”动态二进制加密网站管理客户端
1ICS-pcap. A collection of ICS/SCADA PCAPs
1Erebus. CobaltStrike后渗透测试插件
1Mythic. A collaborative, multi-platform, red teaming framework
1Dork-Admin. 盘点近年来的数据泄露、供应链污染事件
1AoiAWD. AoiAWD-为CTFer准备的EDR,是AWD比赛利器
1SharpDecryptPwd. 对密码已保存在 Windwos 系统上的部分程序进行解析,包括:Navicat,TeamViewer,FileZilla,WinSCP,Xmangager系列产品(Xshell,Xftp)。
1NOE77101_Firmware. HTML
1XssPowerByTools. xss平台课程设计
1hashcat. World's fastest and most advanced password recovery utility
10day-security-software-vulnerability-analysis-technology. 0day安全_软件漏洞分析技术
1F-Scrack. F-Scrack is a single file bruteforcer supports multi-protocol
1bylibrary. 白阁文库内测版
1SiteScan. 资源收集
1antSword. AntSword is a cross-platform website management toolkit.
1