Venom. Venom - A Multi-hop Proxy for Penetration Testers
2.2kredis-rogue-server. Redis 4.x/5.x RCE
576DomainBorrowing. Domain Borrowing PoC
219SharpGPO. A Red Team tool for remotely manipulating Group Policy Object(GPO), Organizational Unit(OU), GPLink and Security Filtering
121IoT-Security. IoT Security Papers
48cve-2019-1040-scanner. Python
10Android-KeyLogger-Demo. Android KeyLogger Demo
9CVE-2024-49112. LdapNightmare is a PoC tool that tests a vulnerable Windows Server against CVE-2024-49112
61000php. 1000个PHP代码审计案例(2016.7以前乌云公开漏洞)
3rakkess. Review Access - kubectl plugin to show an access matrix for k8s server resources
3Blasting_dictionary. 爆破字典
3WinPwnage. 💻 Elevate, UAC bypass, persistence, privilege escalation, dll hijack techniques
3genpAss. 中国特色的弱口令生成器
3Red-Team-Infrastructure-Wiki. Wiki to collect Red Team infrastructure hardening resources
2RedTips. Red Team Tips as posted by @vysecurity on Twitter
2HeaderLessPE. C
2awesome-pentest. A collection of awesome penetration testing resources, tools and other shiny things
2awesome-windows-domain-hardening. A curated list of awesome Security Hardening techniques for Windows.
2Hacking-with-Go. Golang for Security Professionals
2The-Hacker-Playbook-3-Translation. 对 The Hacker Playbook 3 的翻译。
2LinuxKernelTravel. Linux 内核之旅公众号文章
2Virtualized_Learning. C
2AWSBucketDump. Security Tool to Look For Interesting Files in S3 Buckets
1J2EEScan. J2EEScan is a plugin for Burp Suite Proxy. The goal of this plugin is to improve the test coverage during web application penetration tests on J2EE applications.
1suricata-rules. Suricata IDS rules 用来检测红队渗透/恶意行为等,支持检测CobaltStrike/MSF/Empire/DNS隧道/Weevely/菜刀/冰蝎/挖矿/反弹shell/ICMP隧道等
1SharpWeb. 一个浏览器数据(密码|历史记录|Cookie|书签|下载记录)的导出工具,支持主流浏览器。
1Android_Code_Arbiter. 针对Android Studio的源码扫描工具
1aquatone. A Tool for Domain Flyovers
1shellen. Interactive shellcoding environment to easily craft shellcodes
1Java-Deserialization-Cheat-Sheet. The cheat sheet about Java Deserialization vulnerabilities
1ADModule. Microsoft signed ActiveDirectory PowerShell module
1embedded-toolkit. Prebuilt statically linked gdbserver and gawk executables for Linux on ARMEL, MIPS/MIPSEL and more platforms for use on embedded devices, including for systems with many different ABIs (including more than 20 statically linked gdbserver executables)
1Reverse-Engineearing. 软件逆向
1IntruderPayloads. A collection of Burpsuite Intruder payloads
1AggressiveProxy. Project to enumerate proxy configurations and generate shellcode from CobaltStrike
1lxhToolHTTPDecrypt. Simple Android/iOS protocol analysis and utilization tool
1monkey. Infection Monkey - An automated pentest tool
1pwn2exploit. all mine papers, pwn & exploit
1passive-scan-client. Burp被动扫描流量转发插件
1SharpPack. A collection of C# tools for various purposes (kerberoasting, tickets, mimikatz, privesc, domain enumeration and more)
1unveilr. 一款小程序安全评估工具
1awesome-incident-response. A curated list of tools for incident response
1Neo-reGeorg. Neo-reGeorg is a project that seeks to aggressively refactor reGeorg
1dirfuzz. 多线程网站目录穷举扫描
1Pentest. tools
1qemu_blog. A series of posts about QEMU internals
1GoScan. GoScan是采用Golang语言编写的一款分布式综合资产管理系统,适合红队、SRC等使用
1SSRFmap. Automatic SSRF fuzzer and exploitation tool
1fuzzdb. 一个fuzzdb扩展库
1