zan8in

Expert
@zan8in

life is fantastic. enjoy life.

afrog. A Security Tool for Bug Bounty, Pentest and Red Teaming.

4.3k

afrog-pocs. afrog-pocs 是 afrog 漏洞检测工具的官方 PoCs(Proof of Concepts)库。

199

masscan. Masscan is a golang library to run masscan scans, parse scan results.

118

pyxis. pyxis can automatically identify http and https requests, and get response headers, status codes, response size, response time, tools for fingerprinting (favicon has, service, CMS, framework, etc.)

72

pxplan. CVE-2022-2022

70

leo. Leo is a network logon cracker which support many different services.

68

aries. Aries is a free and open-source network scanner, support SYN scanning mode.

33

velax. web crawler + Sensitive Information Identification

23

pocwiki. 漏洞文库

22

wy876-POC. 2023HW漏洞整理,收集整理漏洞EXp/POC,大部分漏洞来源网络,目前收集整理了200多个poc/exp

20

venus. subdomain scanner

18

shiro. Shiro Key Detect Tool

10

POCS2024. 收集最新漏洞POC(Yaml\Python)

8

vulnerability-paper. 收集的文章

7

kenyon-wong-docs. 互联网数字垃圾回收专用废纸篓

6

iotscan-web. 这是一个基于vue3+element-plus+vite4+pinia开发一个资产测绘平台+漏洞扫描的前端项目,提供多种自定义的开发,如果你的扫描器或资产测绘平台不追求UI仅仅是为了快速开发,可以参考此项目。

6

Awesome-Redteam. 一个红队知识仓库

6

pins. Common tools pins

4

Lots-of-POC. Vulnerability POC/EXP Collection and Classification

4

uncover. Quickly discover exposed hosts on the internet using multiple search engines.

4

inhe. 银河

3

zoomeye. zoomeye 是一款钟馗之眼平台数据导出工具

3

2022-HW-POC. 2022 护网行动 POC 整理

3

zan8in.

3

pavo. Cyberspace Mapping Lazy Package

2

gologger. Go

2

oobadapter. OOBAdapter is a framework that consolidates diverse Out-of-Band (OOB) tools into a unified interface.

2

HVVault. 梳理【护网高利用率POC】并集成Nuclei模板仓库,针对解决网上同一资产漏洞一键检测工具参次不齐问题。

2

networkpolicy. Network Policy Helper

1

scan4all. Official repository vuls Scan: 15000+PoCs; 23 kinds of application password crack; 7000+Web fingerprints; 146 protocols and 90000+ rules Port scanning; Fuzz, HW, awesome BugBounty( ͡° ͜ʖ ͡°)...

1

go-portScan. High-performance port scanner. 高性能端口扫描器. syn scanner

1

wappalyzergo. A high performance go implementation of Wappalyzer Technology Detection Library

1

Ajax. Ajax 是一款轻量级资产测绘工具

1

FingerprintHub. 侦查守卫(ObserverWard)的指纹库

1

dnsx. dnsx is a fast and multi-purpose DNS toolkit allow to run multiple DNS queries of your choice with a list of user-supplied resolvers.

1

nuclei_poc. Nuclei POC,每日更新

1

AboutSecurity. Everything for pentest. | 用于渗透测试的 payload 和 bypass 字典.

1

Dictionary-Of-Pentesting. Dictionary collection project such as Pentesing, Fuzzing, Bruteforce and BugBounty. 渗透测试、SRC漏洞挖掘、爆破、Fuzzing等字典收集项目。

1

blackrock. blackrock cipher based on masscan

1

NucleiTP. 自动整合全网Nuclei的漏洞POC,实时同步更新最新POC!

1

retryablehttp. Copy from https://github.com/projectdiscovery/retryablehttp-go

1

HackReport. 渗透测试报告/资料文档/渗透经验文档/安全书籍

1

rawhttp. copy from https://github.com/projectdiscovery/rawhttp

1

vulnerability-wiki. 公开漏洞知识库整合:https://mrwq.github.io/vulnerability-wiki/#/

1

afrog-docs. afrog docs

1

mapcidr. Small utility program to perform multiple operations for a given subnet/CIDR ranges.

1

Databasetools. 一款用Go语言编写的数据库自动化提权工具,支持Mysql、MSSQL、Postgresql、Oracle、Redis数据库提权、命令执行、爆破以及ssh连接

1

retryabledns. retryabledns

1

0day. 各种CMS、各种平台、各种系统、各种软件漏洞的EXP、POC ,该项目将持续更新

1
49
Apply