Tentacle. Tentacle is a POC vulnerability verification and exploit framework. It supports free extension of exploits and uses POC scripts. It supports calls to zoomeye, fofa, shodan and other APIs to perform bulk vulnerability verification for multiple targets.
376Hamster. Hamster是基于mitmproxy开发的异步被动扫描框架,基于http代理进行被动扫描,主要功能为重写数据包、签名、漏洞扫描、敏感参数收集等功能(开发中)。
68Celestion. Celestion 是一个无回显漏洞测试辅助平台,平台使用flask编写,提供DNSLOG,HTTPLOG等功能。 (界面懒得弄,后续有需要再说)。
28BurpCollect. 基于BurpCollector的二次开发, 记录Burpsuite Site Map记录的里的数据包中的目录路径参数名信息,并存入Sqlite,并可导出txt文件。
25srcscan. SRCScan(submon) is a SRC assistant tool that periodically scans subdomains and requests WEB services on port 80/443 to check if it is available, and send result to you by e-mail.
18Jsockproxy. Jsockproxy是Java版反向socks代理,适用于内网穿透。
8NsaCheckTool. NsaCheckTool
7ShellcodeLoader. 该项目为Shellocde加载器,详细介绍了我们如何绕过防病毒软件,以及该工具如何使用
6OrcaC2. OrcaC2是一款基于Websocket加密通信的多功能C&C框架,使用Golang实现。
3filemonitor. Python
2nemo_go. Nemo是用来进行自动化信息收集的一个简单平台,通过集成常用的信息收集工具和技术,实现对内网及互联网资产信息的自动收集,提高隐患排查和渗透测试的工作效率,用Go语言完全重构了原Python版本。
2orleven.github.io. orleven' blog
1hack-fastjson-1.2.80.
1OSSTunnel. 基于亚马逊S3\阿里云OSS\腾讯COS通信隧道的远程管理工具
1AniYa. 免杀框架
1rsocx. A bind/reverse Socks5 proxy server.
1fapro. Fake Protocol Server
1