life is fantastic. enjoy life.
afrog. A Security Tool for Bug Bounty, Pentest and Red Teaming.
4.3kafrog-pocs. afrog-pocs 是 afrog 漏洞检测工具的官方 PoCs(Proof of Concepts)库。
199masscan. Masscan is a golang library to run masscan scans, parse scan results.
118pyxis. pyxis can automatically identify http and https requests, and get response headers, status codes, response size, response time, tools for fingerprinting (favicon has, service, CMS, framework, etc.)
72pxplan. CVE-2022-2022
70leo. Leo is a network logon cracker which support many different services.
68aries. Aries is a free and open-source network scanner, support SYN scanning mode.
33velax. web crawler + Sensitive Information Identification
23pocwiki. 漏洞文库
22wy876-POC. 2023HW漏洞整理,收集整理漏洞EXp/POC,大部分漏洞来源网络,目前收集整理了200多个poc/exp
20venus. subdomain scanner
18shiro. Shiro Key Detect Tool
10POCS2024. 收集最新漏洞POC(Yaml\Python)
8vulnerability-paper. 收集的文章
7kenyon-wong-docs. 互联网数字垃圾回收专用废纸篓
6iotscan-web. 这是一个基于vue3+element-plus+vite4+pinia开发一个资产测绘平台+漏洞扫描的前端项目,提供多种自定义的开发,如果你的扫描器或资产测绘平台不追求UI仅仅是为了快速开发,可以参考此项目。
6Awesome-Redteam. 一个红队知识仓库
6pins. Common tools pins
4Lots-of-POC. Vulnerability POC/EXP Collection and Classification
4uncover. Quickly discover exposed hosts on the internet using multiple search engines.
4inhe. 银河
3zoomeye. zoomeye 是一款钟馗之眼平台数据导出工具
32022-HW-POC. 2022 护网行动 POC 整理
3zan8in.
3pavo. Cyberspace Mapping Lazy Package
2gologger. Go
2oobadapter. OOBAdapter is a framework that consolidates diverse Out-of-Band (OOB) tools into a unified interface.
2HVVault. 梳理【护网高利用率POC】并集成Nuclei模板仓库,针对解决网上同一资产漏洞一键检测工具参次不齐问题。
2networkpolicy. Network Policy Helper
1scan4all. Official repository vuls Scan: 15000+PoCs; 23 kinds of application password crack; 7000+Web fingerprints; 146 protocols and 90000+ rules Port scanning; Fuzz, HW, awesome BugBounty( ͡° ͜ʖ ͡°)...
1go-portScan. High-performance port scanner. 高性能端口扫描器. syn scanner
1wappalyzergo. A high performance go implementation of Wappalyzer Technology Detection Library
1Ajax. Ajax 是一款轻量级资产测绘工具
1FingerprintHub. 侦查守卫(ObserverWard)的指纹库
1dnsx. dnsx is a fast and multi-purpose DNS toolkit allow to run multiple DNS queries of your choice with a list of user-supplied resolvers.
1nuclei_poc. Nuclei POC,每日更新
1AboutSecurity. Everything for pentest. | 用于渗透测试的 payload 和 bypass 字典.
1Dictionary-Of-Pentesting. Dictionary collection project such as Pentesing, Fuzzing, Bruteforce and BugBounty. 渗透测试、SRC漏洞挖掘、爆破、Fuzzing等字典收集项目。
1blackrock. blackrock cipher based on masscan
1NucleiTP. 自动整合全网Nuclei的漏洞POC,实时同步更新最新POC!
1retryablehttp. Copy from https://github.com/projectdiscovery/retryablehttp-go
1HackReport. 渗透测试报告/资料文档/渗透经验文档/安全书籍
1rawhttp. copy from https://github.com/projectdiscovery/rawhttp
1vulnerability-wiki. 公开漏洞知识库整合:https://mrwq.github.io/vulnerability-wiki/#/
1afrog-docs. afrog docs
1mapcidr. Small utility program to perform multiple operations for a given subnet/CIDR ranges.
1Databasetools. 一款用Go语言编写的数据库自动化提权工具,支持Mysql、MSSQL、Postgresql、Oracle、Redis数据库提权、命令执行、爆破以及ssh连接
1retryabledns. retryabledns
10day. 各种CMS、各种平台、各种系统、各种软件漏洞的EXP、POC ,该项目将持续更新
1