Ecosyste.ms: Awesome
An open API service indexing awesome lists of open source software.
awesome-hacking-lists
平常看到好的渗透hacking工具和多领域效率工具的集合
https://github.com/taielab/awesome-hacking-lists
Last synced: about 20 hours ago
JSON representation
-
C
- NoOne-hub/Beacon.dll - Beacon.dll reverse
- scythe-io/memory-module-loader - An implementation of a Windows loader that can load dynamic-linked libraries (DLLs) directly from memory
- slaeryan/DetectCobaltStomp - Detects Module Stomping as implemented by Cobalt Strike
- baidu/dperf - dperf is a 100Gbps network load tester.
- H4K6/CVE-2023-0179-PoC - 针对(CVE-2023-0179)漏洞利用 该漏洞被分配为CVE-2023-0179,影响了从5.5到6.2-rc3的所有Linux版本,该漏洞在6.1.6上被测试。 漏洞的细节和文章可以在os-security上找到。
- Impalabs/CVE-2023-27326 - VM Escape for Parallels Desktop <18.1.1
- libAudioFlux/audioFlux - A library for audio and music analysis, feature extraction.
- chompie1337/Windows_LPE_AFD_CVE-2023-21768 - LPE exploit for CVE-2023-21768
- xforcered/Windows_LPE_AFD_CVE-2023-21768 - LPE exploit for CVE-2023-21768
- Esonhugh/sshd_backdoor - /root/.ssh/authorized_keys evil file watchdog with ebpf tracepoint hook.
- MrEmpy/Pingoor - 「🚪」Linux Backdoor based on ICMP protocol
- nelhage/reptyr - Reparent a running program to a new terminal
- itm4n/PPLdump - Dump the memory of a PPL with a userland exploit
- zh-explorer/dirtycow - exploit for dirtycow
- Coldzer0/ReverseSock5Proxy - A tiny Reverse Sock5 Proxy written in C :V
- Cerbersec/KillDefenderBOF - Beacon Object File PoC implementation of KillDefender
- Kevin-sa/ebpf-supply-chain - 利用ebpf做pypi恶意包检测
- yukar1z0e/cloudswordtsh - 多用户版linux/freebsd/openbsd/netbsd/cygwin/sunos/irix/hpux/osf的远控tiny shell
- Octoberfest7/EventViewerUAC_BOF - Beacon Object File implementation of Event Viewer deserialization UAC bypass
- Rvn0xsy/SchtaskCreator - 远程创建任务计划工具
- Libraggbond/EventViewerBypassUacBof - EventViewer Bypass Uac Bof
- randorisec/CVE-2022-34918-LPE-PoC
- h3xduck/TripleCross - A Linux eBPF rootkit with a backdoor, C2, library injection, execution hijacking, persistence and stealth capabilities.
- pytorch/cpuinfo - CPU INFOrmation library (x86/x86-64/ARM/ARM64, Linux/Windows/Android/macOS/iOS)
- byt3bl33d3r/BOF-Zig - Cobalt Strike BOF with Zig!
- Cracked5pider/Ekko - Sleep Obfuscation
- helloexp/0day - 各种CMS、各种平台、各种系统、各种软件漏洞的EXP、POC ,该项目将持续更新
- tr3ee/CVE-2022-23222 - CVE-2022-23222: Linux Kernel eBPF Local Privilege Escalation
- synacktiv/ica2tcp - A SOCKS proxy for Citrix.
- thefLink/DeepSleep - A variant of Gargoyle for x64 to hide memory artifacts using ROP only and PIC
- q77190858/CVE-2021-3156 - sudo提权漏洞CVE-2021-3156复现代码
- nsacyber/Hardware-and-Firmware-Security-Guidance - Guidance for the Spectre, Meltdown, Speculative Store Bypass, Rogue System Register Read, Lazy FP State Restore, Bounds Check Bypass Store, TLBleed, and L1TF/Foreshadow vulnerabilities as well as gene
- nemo-wq/PrintNightmare-CVE-2021-34527 - PrintNightmare - Windows Print Spooler RCE/LPE Vulnerability (CVE-2021-34527, CVE-2021-1675) proof of concept exploits
- LDrakura/Remote_ShellcodeLoader - 远程shellcode加载&权限维持+小功能
- JDArmy/RPCSCAN - RPC远程主机信息匿名扫描工具
- jituo666/AndroidEventRecorder - A recorder used for recording user actions on Android platforms.
- liudf0716/xfrpc - The xfrpc project is a lightweight implementation of the FRP client written in C language for OpenWRT and IoT systems. It is designed to provide an efficient solution for resource-constrained devices
- Mr-Un1k0d3r/WindowsDllsExport - A list of all the DLLs export in C:\windows\system32\
- trustedsec/CS-Remote-OPs-BOF
- Threekiii/Awesome-Exploit - 一个漏洞利用工具仓库
- outflanknl/C2-Tool-Collection - A collection of tools which integrate with Cobalt Strike (and possibly other C2 frameworks) through BOF and reflective DLL loading techniques.
- rbsec/sslscan - sslscan tests SSL/TLS enabled services to discover supported cipher suites
- krisnova/boopkit - Linux eBPF backdoor over TCP. Spawn reverse shells, RCE, on prior privileged access. Less Honkin, More Tonkin.
- bytedance/bhook - :fire: ByteHook is an Android PLT hook library which supports armeabi-v7a, arm64-v8a, x86 and x86_64.
- r0ysue/AndroidFridaBeginnersBook - 《安卓Frida逆向与抓包实战》随书附件
- easychen/pushdeer - 开放源码的无App推送服务,iOS14+扫码即用。亦支持快应用/iOS和Mac客户端、Android客户端、自制设备
- emptymonkey/revsh - A reverse shell with terminal support, data tunneling, and advanced pivoting capabilities.
- Bonfee/CVE-2022-0995 - CVE-2022-0995 exploit
- RfidResearchGroup/proxmark3 - Iceman Fork - Proxmark3
- gojue/ecapture - Capturing SSL/TLS plaintext without a CA certificate using eBPF. Supported on Linux/Android kernels for amd64/arm64.
- ly4k/PwnKit - Self-contained exploit for CVE-2021-4034 - Pkexec Local Privilege Escalation
- AlexisAhmed/CVE-2022-0847-DirtyPipe-Exploits - A collection of exploits and documentation that can be used to exploit the Linux Dirty Pipe vulnerability.
- mponcet/subversive - x86_64 linux rootkit using debug registers
- therealdreg/lsrootkit - Rootkit Detector for UNIX
- Arinerron/CVE-2022-0847-DirtyPipe-Exploit - A root exploit for CVE-2022-0847 (Dirty Pipe)
- Bonfee/CVE-2022-25636 - CVE-2022-25636
- bopin2020/WindowsCamp - Windows Kernel Knowledge && Collect Resources on the wire && Nothing innovation by myself &&
- r4j0x00/exploits
- SentryPeer/SentryPeer - Protect your SIP Servers from bad actors at https://sentrypeer.org
- b1n4r1b01/n-days
- linux-lock/bpflock - bpflock - eBPF driven security for locking and auditing Linux machines
- Rvn0xsy/CVE-2021-4034 - CVE-2021-4034 Add Root User - Pkexec Local Privilege Escalation
- 0verSp4ce/CVE-2021-4034 - CVE-2021-4034, For Webshell Version.
- MichaelDim02/Narthex - Modular personalized dictionary generator.
- FlamingSpork/iptable_evil - An evil bit backdoor for iptables
- kyleavery/inject-assembly - Inject .NET assemblies into an existing process
- spieglt/whatfiles - Log what files are accessed by any Linux process
- berdav/CVE-2021-4034 - CVE-2021-4034 1day
- arthepsy/CVE-2021-4034 - PoC for PwnKit: Local Privilege Escalation Vulnerability in polkit’s pkexec (CVE-2021-4034)
- Ayrx/CVE-2021-4034 - Exploit for CVE-2021-4034
- aaaddress1/Skrull - Skrull is a malware DRM, that prevents Automatic Sample Submission by AV/EDR and Signature Scanning from Kernel. It generates launchers that can run malware on the victim using the Process Ghosting te
- thefLink/Hunt-Sleeping-Beacons - Aims to identify sleeping beacons
- Rvn0xsy/linux_dirty - 更改后的脏牛提权代码,可以往任意文件写入任意内容,去除交互过程
- revng/pagebuster - PageBuster - dump all executable pages of packed processes.
- screetsec/TheFatRat - Thefatrat a massive exploiting tool : Easy tool to generate backdoor and easy tool to post exploitation attack like browser attack and etc . This tool compiles a malware with popular payload and then
- f0rb1dd3n/Reptile - LKM Linux rootkit
- lcatro/qemu-fuzzer - Qemu Fuzzer.针对Qemu模拟设备的模糊测试工具,主要思路是Host生成种子Data,然后传递给Guest中转程序,由中转程序访问MMIO,以达到和模拟设备的交互,不同于qtest自带的fuzzer.
- chriskaliX/Hades - Hades is a Host-Based Intrusion Detection System based on eBPF(mainly)
- n0b0dyCN/redis-rogue-server - Redis(<=5.0.5) RCE
- wavestone-cdt/EDRSandblast
- OALabs/BlobRunner - Quickly debug shellcode extracted during malware analysis
- SweetIceLolly/Huorong_Vulnerabilities - Huorong Internet Security vulnerabilities 火绒安全软件漏洞
- scareing/cmd2shellcode - cmd2shellcode
- securifybv/Visual-Studio-BOF-template - A Visual Studio template used to create Cobalt Strike BOFs
- HexHive/USBFuzz - A Framework for fuzzing USB Drivers by Device Emulation
- fortra/nanodump - The swiss army knife of LSASS dumping
- Lakr233/Decrypter - An easy way to decrypt UIKit app.
- idealeer/xmap - XMap is a fast network scanner designed for performing Internet-wide IPv6 & IPv4 network research scanning.
- wolfpython/nids - 基于网络的入侵检测系统
- dismantl/ImprovedReflectiveDLLInjection - An improvement of the original reflective DLL injection technique by Stephen Fewer of Harmony Security
- aircrack-ng/mdk4 - MDK4
- boku7/injectEtwBypass - CobaltStrike BOF - Inject ETW Bypass into Remote Process via Syscalls (HellsGate|HalosGate)
- codewhitesec/HandleKatz - PIC lsass dumper using cloned handles
- gentilkiwi/kekeo - A little toolbox to play with Microsoft Kerberos in C
- EspressoCake/PPLDump_BOF - A faithful transposition of the key features/functionality of @itm4n's PPLDump project as a BOF.
- microsoft/omi - Open Management Infrastructure
- seL4/seL4 - The seL4 microkernel
- outflanknl/PrintNightmare
- cube0x0/SharpSystemTriggers - Collection of remote authentication triggers in C#
- paranoidninja/PIC-Get-Privileges - Building and Executing Position Independent Shellcode from Object Files in Memory
- SolomonSklash/SleepyCrypt - A shellcode function to encrypt a running process image when sleeping.
- limithit/NginxExecute - The NginxExecute module executes the shell command through GET POST and HEAD to display the result.
- o8oo8o/GoWebSSH - 功能强大,Go 实现的一个WebSSH,支持文件上传下载
- boku7/azureOutlookC2 - Azure Outlook Command & Control (C2) - Remotely control a compromised Windows Device from your Outlook mailbox. Threat Emulation Tool for North Korean APT InkySquid / ScarCruft / APT37. TTP: Use Micro
- cyberark/rdpfuzz - Tools for fuzzing RDP
- mprovost/NFStash - NFS client CLI toolkit
- aaaddress1/PR0CESS - some gadgets about windows process and ready to use :)
- superflexible/TGPuttyLib - An SFTP client shared library (dll/so/dylib) with bindings and classes for C++, Delphi and Free Pascal based on PuTTY
- ttdennis/fpicker - fpicker is a Frida-based fuzzing suite supporting various modes (including AFL++ in-process fuzzing)
- mgeeky/ElusiveMice - Cobalt Strike User-Defined Reflective Loader with AV/EDR Evasion in mind
- boku7/whereami - Cobalt Strike Beacon Object File (BOF) that uses handwritten shellcode to return the process Environment strings without touching any DLL's.
- frkngksl/Huan - Encrypted PE Loader Generator
- Yubico/yubico-c - YubiKey C low-level library (libyubikey)
- RUB-SysSec/Nyx - USENIX 2021 - Nyx: Greybox Hypervisor Fuzzing using Fast Snapshots and Affine Types
- glmcdona/Process-Dump - Windows tool for dumping malware PE files from memory back to disk for analysis.
- alfarom256/BOF-ForeignLsass
- knightswd/ProcessGhosting
- boku7/BokuLoader - A proof-of-concept Cobalt Strike Reflective Loader which aims to recreate, integrate, and enhance Cobalt Strike's evasion features!
- aqi00/advanceapp - 《Android App开发进阶与项目实战》随书源码
- horsicq/PDBRipper - PDBRipper is a utility for extract an information from PDB-files.
- Gui774ume/ebpfkit - ebpfkit is a rootkit powered by eBPF
- jrbrtsn/ban2fail - Simple & efficient log file scanning and iptable filtering
- cdpxe/NELphase - Network Environment Learning (NEL) Phase for Covert Channels (with a Feedback Channel)
- ZhangZhuoSJTU/StochFuzz - Sound and Cost-effective Fuzzing of Stripped Binaries by Incremental and Stochastic Rewriting
- connormcgarr/cThreadHijack - Beacon Object File (BOF) for remote process injection via thread hijacking
- boku7/injectAmsiBypass - Cobalt Strike BOF - Bypass AMSI in a remote process with code injection.
- LloydLabs/process-enumeration-stealth
- djkaty/Il2CppInspector - Powerful automated tool for reverse engineering Unity IL2CPP binaries
- merbanan/rtl_433 - Program to decode radio transmissions from devices on the ISM bands (and other frequencies)
- killvxk/Beacon - Lightweight, header-only C++ IPC library for Windows operating systems (Vista+) using advanced local procedure calls
- sliverarmory/COFFLoader
- joshfaust/Alaris - A protective and Low Level Shellcode Loader that defeats modern EDR systems.
- OWASP/IoTGoat - IoTGoat is a deliberately insecure firmware created to educate software developers and security professionals with testing commonly found vulnerabilities in IoT devices.
- ndilieto/uacme - ACMEv2 client written in plain C with minimal dependencies
- client9/libinjection - SQL / SQLI tokenizer parser analyzer
- alipay/ios-malicious-bithunter - iOS Malicious Bit Hunter is a malicious plug-in detection engine for iOS applications. It can analyze the head of the macho file of the injected dylib dynamic library based on runtime. If you are inte
- xuanxuan0/TiEtwAgent - PoC memory injection detection agent based on ETW, for offensive and defensive research purposes
- antonioCoco/RemotePotato0 - Windows Privilege Escalation from User to Domain Admin.
- greenbone/gvmd - Greenbone Vulnerability Manager - The database backend for the Greenbone Community Edition
- topotam/PetitPotam - PoC tool to coerce Windows hosts to authenticate to other machines via MS-EFSRPC EfsRpcOpenFileRaw or other functions.
- CCob/BOF.NET - A .NET Runtime for Cobalt Strike's Beacon Object Files
- 0xricksanchez/dlink-decrypt - D-Link firmware decryption PoC
- boku7/spawn - Cobalt Strike BOF that spawns a sacrificial process, injects it with shellcode, and executes payload. Built to evade EDR/UserLand hooks by spawning sacrificial process with Arbitrary Code Guard (ACG),
- xforcered/InlineExecute-Assembly - InlineExecute-Assembly is a proof of concept Beacon Object File (BOF) that allows security professionals to perform in process .NET assembly execution as an alternative to Cobalt Strikes traditional f
- inspiringz/CVE-2021-3493 - CVE-2021-3493 Ubuntu OverlayFS Local Privesc (Interactive Bash Shell & Execute Command Entered)
- wbenny/injdrv - proof-of-concept Windows Driver for injecting DLL into user-mode processes using APC
- CCob/SylantStrike - Simple EDR implementation to demonstrate bypass
- jattach/jattach - JVM Dynamic Attach utility
- anthemtotheego/InlineExecute-Assembly - InlineExecute-Assembly is a proof of concept Beacon Object File (BOF) that allows security professionals to perform in process .NET assembly execution as an alternative to Cobalt Strikes traditional f
- praetorian-inc/PortBender - TCP Port Redirection Utility
- hlldz/CVE-2021-1675-LPE - Local Privilege Escalation Edition for CVE-2021-1675/CVE-2021-34527
- blackorbird/PrintNightmare
- iqiyi/qnsm - QNSM is network security monitoring framework based on DPDK.
- Yaxser/Backstab - A tool to kill antimalware protected processes
- CaledoniaProject/rdpscan - RDP password verification tool - No external libraries required ;-P
- cgwalters/cve-2020-14386
- alipay/Owfuzz - Owfuzz: a WiFi protocol fuzzing tool
- passthehashbrowns/hook-integrity-checks
- kevmitch/win_battery_log - command line battery stats for MS Windows
- passthehashbrowns/hiding-your-syscalls - Some source code to demonstrate avoiding certain direct syscall detections by locating and JMPing to a legitimate syscall instruction within NTDLL.
- yarrick/iodine - Official git repo for iodine dns tunnel
- airbus-cyber/afl_ghidra_emu
- ApsaraDB/PolarDB-for-PostgreSQL - A cloud-native database based on PostgreSQL developed by Alibaba Cloud.
- season-lab/fuzzolic - fuzzing + concolic = fuzzolic :)
- djhohnstein/macos_shell_memory - Execute MachO binaries in memory using CGo
- ASkyeye/Zipper - Zipper, a CobaltStrike file and folder compression utility.
- pbek/loganalyzer - LogAnalyzer is a tool that helps you to analyze your log files by reducing the content with patterns you define.
- heiher/hev-socks5-core - A simple, lightweight socks5 library. (IPv4/IPv6/TCP/UDP/Client/Server)
- orangetw/tsh - Tiny SHell is an open-source UNIX backdoor.
- waldo-irc/CVE-2021-21551 - Exploit to SYSTEM for CVE-2021-21551
- Iansus/SilentLsassDump - VisualStudio port of https://github.com/guervild/BOFs/tree/dev/SilentLsassDump
- falcosecurity/pdig - ptrace-based event producer for udig
- svengong/xcubebase_riru - 基于magisk 和riru的frida持久化方案
- Al1ex/WindowsElevation - Windows Elevation(持续更新)
- Al1ex/LinuxEelvation - Linux Eelvation(持续更新)
- boazsegev/iodine - iodine - HTTP / WebSockets Server for Ruby with Pub/Sub support
- xforcered/CredBandit - Proof of concept Beacon Object File (BOF) that uses static x64 syscalls to perform a complete in memory dump of a process and send that back through your already existing Beacon communication channel
- dgoulet/kjackal - Linux Rootkit Scanner
- rsmudge/ZeroLogon-BOF
- pattern-f/TQ-pre-jailbreak - Hello from pattern-f.
- darvincisec/AntiDebugandMemoryDump - Anti-Debug and Anti-Memory Dump for Android
- decoder-it/juicy_2 - juicypotato for win10 > 1803 & win server 2019
- 9bie/exe2shellcode - Remote Download and Memory Execute for shellcode framework
- trustedsec/COFFLoader
- akopytov/sysbench - Scriptable database and system performance benchmark
- mtrojnar/osslsigncode - OpenSSL based Authenticode signing for PE/MSI/Java CAB files
- jmk-foofus/medusa - Medusa is a speedy, parallel, and modular, login brute-forcer.
- rewardone/OSCPRepo - A list of commands, scripts, resources, and more that I have gathered and attempted to consolidate for use as OSCP (and more) study material. Commands in 'Usefulcommands' Keepnote. Bookmarks and readi
- aaaddress1/sakeInject - Windows PE - TLS (Thread Local Storage) Injector in C/C++
- Rvn0xsy/CVE-2021-3156-plus - CVE-2021-3156非交互式执行命令
- blasty/CVE-2021-3156
- Mr-Un1k0d3r/RedTeamCCode - Red Team C code repo
- lockedbyte/CVE-Exploits - PoC exploits for software vulnerabilities
- mai1zhi2/ShellCodeFramework - 绕3环的shellcode免杀框架
- ea/bosch_headunit_root - Documentation and code for rooting and extending a Bosch car head unit (lcn2kai)
- LloydLabs/Windows-API-Hashing - This is a simple example and explanation of obfuscating API resolution via hashing
- LloydLabs/delete-self-poc - A way to delete a locked file, or current running executable, on disk.
- zznop/drow - Injects code into ELF executables post-build
- neil-wu/CatFrida - CatFrida is a macOS tool for inspecting a running iOS app.
- jsherman212/xnuspy - an iOS kernel function hooking framework for checkra1n'able devices
- rsmudge/unhook-bof - Remove API hooks from a Beacon process.
- dacade/tools - some tools
- lengjibo/FourEye - AV Evasion Tool For Red Team Ops
- AFLplusplus/AFLplusplus - The fuzzer afl++ is afl with community patches, qemu 5.1 upgrade, collision-free coverage, enhanced laf-intel & redqueen, AFLfast++ power schedules, MOpt mutators, unicorn_mode, and a lot more!
- ethereal-vx/Persistence - Recreating and reviewing the Windows persistence methods
- anantshri/Android_Security - This repository is a suplimentary material for Android Training's done by Anant Shrivastava from 2012-2017
- ajpc500/BOFs - Collection of Beacon Object Files
- tomcarver16/BOF-DLL-Inject - Manual Map DLL injection implemented with Cobalt Strike's Beacon Object Files.
- gnxbr/Fully-Undetectable-Techniques
- chroblert/JC-AntiPtrace - 安卓绕过ptrace反调试
- TannerJin/AntiMSHookFunction - AntiMSHookFunction (make MSHookFunction doesn't work)
- ntop/n2n - Peer-to-peer VPN
- gaffe23/linux-inject - Tool for injecting a shared object into a Linux process
- code-scan/ssh-inject-auto-find-libdl
- geommer/yabar - A modern and lightweight status bar for X window managers.
- strongcourage/uafuzz - UAFuzz: Binary-level Directed Fuzzing for Use-After-Free Vulnerabilities
- LloydLabs/wsb-detect - wsb-detect enables you to detect if you are running in Windows Sandbox ("WSB")
- g0dA/linuxStack - Linux技术栈
- 0voice/algorithm-structure - 2021年最新总结 500个常用数据结构,算法,算法导论,面试常用,大厂高级工程师整理总结
- GeoSn0w/Blizzard-Jailbreak - An Open-Source iOS 11.0 -> 11.4.1 (soon iOS 13) Jailbreak, made for teaching purposes.
- bytecode77/r77-rootkit - Fileless ring 3 rootkit with installer and persistence that hides processes, files, network connections, etc.
- ventoy/Ventoy - A new bootable USB solution.
- SkewwG/domainTools - 内网域渗透小工具
- StarCross-Tech/heap_exploit_2.31
- XiphosResearch/netelf - Run executables from memory, over the network, on Windows, Linux, OpenVMS... routers... spaceships... toasters etc.
- andreafioraldi/weizz-fuzzer
- hackerschoice/gsocket - Connect like there is no firewall. Securely.
- phra/PEzor - Open-Source Shellcode & PE Packer
- TimelifeCzy/Shell_Protect - VM一键加壳/脱壳,全压缩,反调试等
- ish-app/ish - Linux shell for iOS
- inspektor-gadget/inspektor-gadget - The eBPF tool and systems inspection framework for Kubernetes, containers and Linux hosts.
- gloxec/CrossC2 - generate CobaltStrike's cross-platform payload
- timwhitez/Cobalt-Strike-Aggressor-Scripts - Cobalt Strike Aggressor 插件包
- brendan-rius/c-jwt-cracker - JWT brute force cracker written in C
- bg6cq/whoisscanme
- aircrack-ng/rtl8188eus - RealTek RTL8188eus WiFi driver with monitor mode & frame injection support
- dtcooper/fakehostname - Run a command and fake your hostname.
- yifengyou/learn-kvm - Qemu KVM(Kernel Virtual Machine)学习笔记
- blendin/3snake - Tool for extracting information from newly spawned processes
- 0vercl0k/sic - Enumerate user mode shared memory mappings on Windows.
- CylanceVulnResearch/ReflectiveDLLRefresher - Universal Unhooking
- DoctorWkt/acwj - A Compiler Writing Journey
- limbenjamin/LogServiceCrash - POC code to crash Windows Event Logger Service
- nil0x42/duplicut - Remove duplicates from MASSIVE wordlist, without sorting it (for dictionary-based password cracking)
- blunderbuss-wctf/wacker - A WPA3 dictionary cracker
- uf0o/CVE-2020-17382 - PoC exploits for CVE-2020-17382
- libinjection/libinjection - SQL / SQLI tokenizer parser analyzer
- blackarrowsec/redteam-research - Collection of PoC and offensive techniques used by the BlackArrow Red Team
- chompie1337/s8_2019_2215_poc - PoC 2019-2215 exploit for S8/S8 active with DAC + SELinux + Knox/RKP bypass
- DerekSelander/yacd - Decrypts FairPlay applications on iOS 13.4.1 and lower, no jb required
- jvinet/knock - A port-knocking daemon
- ThunderGunExpress/UAC-TokenDuplication
- reactos/reactos - A free Windows-compatible Operating System
- MobileForensicsResearch/mem - Tool used for dumping memory from Android devices
- ARM-software/CSAL - Coresight Access Library
- webview/webview_csharp - C# bindings for webview/webview - Batteries included
- webview/webview - Tiny cross-platform webview library for C/C++. Uses WebKit (GTK/Cocoa) and Edge WebView2 (Windows).
- gabrielrcouto/awesome-php-ffi - PHP FFI examples and use cases
- bhassani/EternalBlueC - EternalBlue suite remade in C/C++ which includes: MS17-010 Exploit, EternalBlue vulnerability detector, DoublePulsar detector and DoublePulsar Shellcode & DLL uploader
- mdsecactivebreach/firewalker
- hzqst/VmwareHardenedLoader - Vmware Hardened VM detection mitigation loader (anti anti-vm)
- aligrudi/neatcc - A small arm/x86(-64) C compiler
- bkerler/opencl_brute - MD5,SHA1,SHA256,SHA512,HMAC,PBKDF2,SCrypt Bruteforcing tools using OpenCL (GPU, yay!) and Python
- marsyy/littl_tools
- n0b0dyCN/RedisModules-ExecuteCommand - Tools, utilities and scripts to help you write redis modules!
- vulhub/redis-rogue-getshell - redis 4.x/5.x master/slave getshell module
- google/sanitizers - AddressSanitizer, ThreadSanitizer, MemorySanitizer
- m57/cobaltstrike_bofs - My CobaltStrike BOFS
- anthemtotheego/C_Shot
- sailay1996/UAC_Bypass_In_The_Wild - Windows 10 UAC bypass for all executable files which are autoelevate true .
- a0rtega/pafish - Pafish is a testing tool that uses different techniques to detect virtual machines and malware analysis environments in the same way that malware families do
- github/securitylab - Resources related to GitHub Security Lab
- rvrsh3ll/BOF_Collection - Various Cobalt Strike BOFs
- sailay1996/RpcSsImpersonator - Privilege Escalation Via RpcSs svc
- libyal/liblnk - Library and tools to access the Windows Shortcut File (LNK) format
- NtRaiseHardError/NINA - NINA: No Injection, No Allocation x64 Process Injection Technique
- DanieleDeSensi/peafowl - High performance Deep Packet Inspection (DPI) framework to identify L7 protocols and extract and process data and metadata from network traffic.
- elfmaster/libelfmaster - Secure ELF parsing/loading library for forensics reconstruction of malware, and robust reverse engineering tools
- elfmaster/ftrace - POSIX Function tracing
- elfmaster/dsym_obfuscate - Obfuscates dynamic symbol table
- redplait/armpatched - clone of armadillo patched for windows
- dalvarezperez/CreateFile_based_rootkit
- mhaskar/Shellcode-In-Memory-Decoder - A simple C implementation to decoded your shellcode and writes it directly to memory
- meme/hotwax - Coverage-guided binary fuzzing powered by Frida Stalker
- avs333/Nougat_dlfunctions
- hack0z/byopen - 🎉A dlopen library that bypasses mobile system limitation
- ionescu007/faxhell - A Bind Shell Using the Fax Service and a DLL Hijack
- ph4ntonn/Impost3r - 👻Impost3r -- A linux password thief
- havocykp/Gh0st - 远控源码
- gentilkiwi/mimikatz - A little tool to play with Windows security
- itm4n/PrintSpoofer - Abusing impersonation privileges through the "Printer Bug"
- sandboxie/sandboxie - The Sandboxie application
- can1357/NtLua - Lua in kernel-mode because why not.
- 1d8/MailJack
- thebabush/bline - Naver LINE VoIP reversing stuff
- kingToolbox/WindTerm - A professional cross-platform SSH/Sftp/Shell/Telnet/Serial terminal.
- nccgroup/nccfsas - Information released publicly by NCC Group's Full Spectrum Attack Simulation (FSAS) team.
- a1exdandy/checkm8-a5 - checkm8 port for S5L8940X/S5L8942X/S5L8945X
- taviso/ctftool - Interactive CTF Exploration Tool
- YutaroHayakawa/ipftrace2 - A packet oriented Linux kernel function call tracer
- hasherezade/hollows_hunter - Scans all running processes. Recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks, in-memory patches).
- rxwx/spoolsystem - Print Spooler Named Pipe Impersonation for Cobalt Strike
- Katrovisch/KatroLogger - KeyLogger for Linux Systems
- bats3c/shad0w - A post exploitation framework designed to operate covertly on heavily monitored environments
- HyperDbg/HyperDbg - State-of-the-art native debugging tools
- AltraMayor/gatekeeper - The first open-source DDoS protection system
- V-E-O/PoC - PoC of CVE/Exploit
- vanhauser-thc/thc-hydra - hydra
- luke-goddard/enumy - Linux post exploitation privilege escalation enumeration
- oleavr/ios-inject-custom - Example showing how to use Frida for standalone injection of a custom payload
- zhuotong/Android_InlineHook - Android内联hook框架
- juuso/keychaindump - A proof-of-concept tool for reading OS X keychain passwords
- prbinu/tls-scan - An Internet scale, blazing fast SSL/TLS scanner ( non-blocking, event-driven )
- a2o/snoopy - Snoopy Command Logger is a small library that logs all program executions on your Linux/BSD system.
- gentilkiwi/kirandomtpm - Get random bytes from the TPM (tool + BCrypt RNG provider)
- wonderkun/CTFENV - 为应对CTF比赛而搭建的各种环境
- antonioCoco/RoguePotato - Another Windows Local Privilege Escalation from Service Account to System
- yusufqk/SystemToken - Steal privileged token to obtain SYSTEM shell
- uknowsec/getSystem - webshell下提权执行命令 Reference:https://github.com/yusufqk/SystemToken
- NLnetLabs/ldns - LDNS is a DNS library that facilitates DNS tool programming
- noptrix/lulzbuster - A very fast and smart web directory and file enumeration tool written in C.
- danigargu/CVE-2020-0796 - CVE-2020-0796 - Windows SMBv3 LPE exploit #SMBGhost
- twelvesec/passcat - Passwords Recovery Tool
- chroblert/domainWeakPasswdCheck - 内网安全·域账号弱口令审计
- chroblert/AssetManage
- paranoidninja/Shuriken - Offensive Android Kernel on Steroids - Shuriken is an Android kernel for Oneplus 5/5T which supports multiple features for pentesting.
- newsoft/adduser - Programmatically create an administrative user under Windows
- brainsmoke/ptrace-burrito - a friendly wrapper around ptrace
- Mr-Un1k0d3r/SCShell - Fileless lateral movement tool that relies on ChangeServiceConfigA to run command
- RITRedteam/Headshot - NGINX module to allow for RCE through a specific header
- Genymobile/scrcpy - Display and control your Android device
- bootleg/ret-sync - ret-sync is a set of plugins that helps to synchronize a debugging session (WinDbg/GDB/LLDB/OllyDbg2/x64dbg) with IDA/Ghidra/Binary Ninja disassemblers.
- outflanknl/Dumpert - LSASS memory dumper using direct system calls and API unhooking.
- jonathanmetzman/wasm-fuzzing-demo - Demos of and walkthroughs on in-browser fuzzing using WebAssembly
- Aekras1a/darkRat_HVNC - DarkRats Standalone HVNC
- SwiftLaTeX/SwiftLaTeX - SwiftLaTeX, a WYSIWYG Browser-based LaTeX Editor
- mohuihui/antispy - AntiSpy is a free but powerful anti virus and rootkits toolkit.It offers you the ability with the highest privileges that can detect,analyze and restore various kernel modifications and hooks.With its
- OWASP/igoat - OWASP iGoat - A Learning Tool for iOS App Pentesting and Security by Swaroop Yermalkar
- OWASP/iGoat-Swift - OWASP iGoat (Swift) - A Damn Vulnerable Swift Application for iOS
- hmgle/graftcp - A flexible tool for redirecting a given program's TCP traffic to SOCKS5 or HTTP proxy.
- blechschmidt/massdns - A high-performance DNS stub resolver for bulk lookups and reconnaissance (subdomain enumeration)
- abelcheung/rifiuti2 - Windows Recycle Bin analyser
- vmonaco/kloak - Keystroke-level online anonymization kernel: obfuscates typing behavior at the device level.
- robertdavidgraham/rdpscan - A quick scanner for the CVE-2019-0708 "BlueKeep" vulnerability.
- q3k/cve-2019-5736-poc - Unweaponized Proof of Concept for CVE-2019-5736 (Docker escape)
- gurnec/HashCheck - HashCheck Shell Extension for Windows with added SHA2, SHA3, and multithreading; originally from code.kliu.org
- skeeto/endlessh - SSH tarpit that slowly sends an endless banner
- Chion82/netfilter-full-cone-nat - A kernel module to turn MASQUERADE into full cone SNAT
- hacksysteam/HackSysExtremeVulnerableDriver - HackSys Extreme Vulnerable Driver (HEVD) - Windows & Linux
- y11en/BlockRDPBrute - [HIPS]RDP(3389)爆破防护
- klsfct/getshell - 各大平台提权工具
- Halbmond/Introduction-to-Computer-Systems - Course : Introduction to Computer Systems
- swaywm/sway - i3-compatible Wayland compositor
- ambrop72/badvpn - NCD scripting language, tun2socks proxifier, P2P VPN
- firebroo/UnixTools - 一些处理数据的Unix小工具,支持管道操作。
- meyerd/n2n - A development branch of the n2n p2p vpn software
- rosehgal/BinExp - Linux Binary Exploitation
- sfan5/fi6s - IPv6 network scanner designed to be fast
- silight-jp/MacType-Patch - MacType Patch for DirectWrite Hook
- andreiw/RaspberryPiPkg - DEPRECATED - DO NOT USE | Go here instead ->
- aarond10/https_dns_proxy - A lightweight DNS-over-HTTPS proxy.
- telekom-security/tpotce - 🍯 T-Pot - The All In One Multi Honeypot Platform 🐝
- lihaoyun6/axeldown-core - 基于axel-webm的优化项目. 通过webui调用axel进行下载
- suvllian/process-inject - 在Windows环境下的进程注入方法:远程线程注入、创建进程挂起注入、反射注入、APCInject、SetWindowHookEX注入
- sumatrapdfreader/sumatrapdf - SumatraPDF reader
- zogvm/zogvm - zogna video manager
- henkman/virgo - :virgo::computer::computer::computer::computer: Virtual desktops for Windows
- netdata/netdata - Architected for speed. Automated for easy. Monitoring and troubleshooting, transformed!
- RPISEC/MBE - Course materials for Modern Binary Exploitation by RPISEC
- saaramar/execve_exploit - Hardcore corruption of my execve() vulnerability in WSL
- Nat-Lab/eoip - EoIP/EoIPv6 for *nix.
- tcp-nanqinlang/general - general mode via module loading
- 3proxy/3proxy - 3proxy - tiny free proxy server
- coolstar/electra - Electra iOS 11.0 - 11.1.2 jailbreak toolkit based on async_awake
- dyne/dnscrypt-proxy - DNSCrypt-Proxy repository, frankly maintained for what it does (no new features planned)
- agile6v/awesome-nginx - A curated list of awesome Nginx distributions, 3rd party modules, Active developers, etc. :octocat:
- guanchao/AppProtect - 整理一些app常见的加固方法,包括java层、native层和资源文件加固等
- firmianay/CTF-All-In-One - CTF竞赛权威指南
- Wind4/vlmcsd - KMS Emulator in C (currently runs on Linux including Android, FreeBSD, Solaris, Minix, Mac OS, iOS, Windows with or without Cygwin)
- Motion-Project/motion - Motion, a software motion detector. Home page: https://motion-project.github.io/
- mpv-player/mpv - 🎥 Command line video player
- gsliepen/tinc - a VPN daemon
- hardenedlinux/linux-exploit-development-tutorial - a series tutorial for linux exploit development to newbie.
- NoahhhRyan/krackattacks-test
- hfiref0x/UACME - Defeating Windows User Account Control
- tinyproxy/tinyproxy - tinyproxy - a light-weight HTTP/HTTPS proxy daemon for POSIX operating systems
- mitchellkrogza/apache-ultimate-bad-bot-blocker - Apache Block Bad Bots, (Referer) Spam Referrer Blocker, Vulnerability Scanners, Malware, Adware, Ransomware, Malicious Sites, Wordpress Theme Detectors and Fail2Ban Jail for Repeat Offenders
- vanhoefm/krackattacks-scripts
- droberson/icmp-backdoor - Backdoor that listens for specially crafted ICMP packets and spawns reverse shells.
- giltu/KernelPCC - PCC is a new approach for TCP congestion control base on real-time performance analysis. This is a kernel implementation of it.
- madeye/tcp_china - TCP China congestion control algorithm
- gatieme/AderXCoding - 介绍各类语言,库,系统编程以及算法的学习
- session-replay-tools/tcpcopy - An online request replication and TCP stream replay tool, ideal for real testing, performance testing, stability testing, stress testing, load testing, smoke testing, and more.
- sudeshnapal12/Web-Application-Firewall - Designed and Implemented a Web Application Firewall as an Apache module that "sits" in-front of a web server. The WAF is designed to stop malicious requests from known attacks such as SQL Injection, X
- 50m30n3/dsptunnel - IP over audio tunnel
- usagiryu/unit - Unit 中文文档源,每 24 小时与官方同步。中文文档请点README_CN.md。
- dosgo/ngrok-c - ngrok client for c language,Due to the use of GO ngrok language development, porting to embedded devices some inconvenience, such as openwrt, so use C language rewrite a client. Very mini, the need to
- dlundquist/sniproxy - Proxies incoming HTTP and TLS connections based on the hostname contained in the initial request of the TCP session.
- haiwen/seafile - High performance file syncing and sharing, with also Markdown WYSIWYG editing, Wiki, file label and other knowledge management features.
- WireGuard/wireguard-monolithic-historical - Historical monolithic WireGuard repository, split into wireguard-tools, wireguard-linux, and wireguard-linux-compat.
- git-hulk/tcpkit - the tcpkit was designed to make network packets programable with Lua script
- snooda/net-speeder - net-speeder 在高延迟不稳定链路上优化单线程下载速度
- unamer/vmware_escape - VMware Escape Exploit before VMware WorkStation 12.5.5
- axel-download-accelerator/axel - Lightweight CLI download accelerator
- skywind3000/kcp - :zap: KCP - A Fast and Reliable ARQ Protocol
- osqzss/gps-sdr-sim - Software-Defined GPS Signal Simulator
- magkopian/keepassxc-debian - Debian source package for the KeePassXC password manager.
- axi0mX/ios-kexec-utils - boot LLB/iBoot/iBSS/iBEC image from a jailbroken iOS kernel
- santoru/filewatcher - A simple auditing utility for macOS
- Cn33liz/HSEVD-ArbitraryOverwrite - HackSys Extreme Vulnerable Driver - ArbitraryOverwrite Exploit
- c0d3z3r0/sudo-CVE-2017-1000367
- Chion82/kcptun-raw - Kcptun with raw socket and fake TCP headers.
- klsecservices/Invoke-Vnc - Powershell VNC injector
- shudo/shujit - Java Just-in-Time Compiler for x86 processors
- opsxcq/exploit-CVE-2017-7494 - SambaCry exploit and vulnerable container (CVE-2017-7494)
- raminfp/linux-4.8.0-netfilter_icmp - Anatomy of a linux kernel development
- ANSSI-FR/AD-control-paths - Active Directory Control Paths auditing and graphing tools
- ValdikSS/GoodbyeDPI - GoodbyeDPI — Deep Packet Inspection circumvention utility (for Windows)
- ufrisk/pcileech - Direct Memory Access (DMA) Attack Software
- Cybellum/DoubleAgent - Zero-Day Code Injection and Persistence Technique
- gentilkiwi/wanakiwi - Automated wanadecrypt with key recovery if lucky
- jtesta/ssh-mitm - SSH man-in-the-middle tool
- SecWiki/linux-kernel-exploits - linux-kernel-exploits Linux平台提权漏洞集合
- adafruit/Adafruit-GPIO-Halt - Press-to-halt program for headless Raspberry Pi. Similar functionality to the rpi_power_switch kernel module from the fbtft project, but easier to compile (no kernel headers needed).
- greensea/mptunnel - MPUDP Tunnel (User space MultiPath UDP)
- Riscure/Rhme-2016 - Rhme2 challenge (2016)
- leechristensen/UnmanagedPowerShell - Executes PowerShell from an unmanaged process
- peperunas/injectopi - A set of tutorials about code injection for Windows.
- hasherezade/demos - Demos of various injection techniques found in malware
- google/honggfuzz - Security oriented software fuzzer. Supports evolutionary, feedback-driven fuzzing based on code coverage (SW and HW based)
- mubix/post-exploitation - Post Exploitation Collection
- hxp2k6/smart7ec-scan-console - 基于Linux c开发的插件式扫描器(Python/lua)
- SpacehuhnTech/esp8266_deauther - Affordable WiFi hacking platform for testing and learning
- s0lst1c3/eaphammer - Targeted evil twin attacks against WPA2-Enterprise networks. Indirect wireless pivots using hostile portal attacks.
- LukaSikic/Unix-Privilege-Escalation-Exploits-Pack - Exploits for getting local root on Linux, BSD, AIX, HP-UX, Solaris, RHEL, SUSE etc.
- kala13x/scap - Network Sniffer (Scan and Capture Incoming Packets)
- nmap/ncrack - Ncrack network authentication tool
- laginimaineb/cve-2015-6639 - QSEE Privilege Escalation Exploit using PRDiag* commands (CVE-2015-6639)
- deamwork/inetutils - the copy of https://git.savannah.gnu.org/cgit/inetutils.git/ with knali support
- traviscross/mtr - Official repository for mtr, a network diagnostic tool
- kmyk/libproofofwork - Simple hash-mining c library and its python binding.
- boywhp/wifi_crack_windows - wifi crack project for windows
- zcgonvh/NTDSDumpEx - NTDS.dit offline dumper with non-elevated
- derrekr/android_security - Public Android Vulnerability Information (CVE PoCs etc)
- googleprojectzero/winafl - A fork of AFL for fuzzing Windows binaries
- F-Stack/f-stack - F-Stack is an user space network development kit with high performance based on DPDK, FreeBSD TCP/IP stack and coroutine API.
- mrschyte/pentestkoala - Modified dropbear server which acts as a client and allows authless login
- openwall/john - John the Ripper jumbo - advanced offline password cracker, which supports hundreds of hash and cipher types, and runs on many operating systems, CPUs, GPUs, and even some FPGAs
- netblue30/firejail - Linux namespaces and seccomp-bpf sandbox
- Azard/SE315-OperatingSystem - SJTU-SE315 Operating System labs from MIT 6.828, by a SE12er.
- gamelinux/passivedns - A network sniffer that logs all DNS server replies for use in a passive DNS setup
- spacehuhn/wifi_ducky - Upload, save and run keystroke injection payloads with an ESP8266 + ATMEGA32U4
- danieljiang0415/android_kernel_crash_poc
- robertfisk/USG - The USG is Good, not Bad
- ossec/ossec-hids - OSSEC is an Open Source Host-based Intrusion Detection System that performs log analysis, file integrity checking, policy monitoring, rootkit detection, real-time alerting and active response.
- iovisor/bcc - BCC - Tools for BPF-based Linux IO analysis, networking, monitoring, and more
- huntergregal/mimipenguin - A tool to dump the login password from the current linux user
- SamyPesse/How-to-Make-a-Computer-Operating-System - How to Make a Computer Operating System in C++
- nonstriater/Learn-Algorithms - 算法学习笔记
- wg/wrk - Modern HTTP benchmarking tool
- xbyl1234/android_analysis - a few android analysis tools, jni trace by native hook, libc hook, write log with caller's addr in file or AndroidLog
- GJDuck/e9patch - A powerful static binary rewriting tool
- Chuyu-Team/MINT - Contains the definitions for the Windows Internal UserMode API from ntdll.dll, samlib.dll and winsta.dll.
- git-for-windows/git-sdk-64 - A Git repository mirroring the current 64-bit Git for Windows SDK
- redcanaryco/atomic-red-team - Small and highly portable detection tests based on MITRE's ATT&CK.
- hlldz/Phant0m - Windows Event Log Killer
- P001water/yuze - A socksv5 proxy tool Written by CLang. 一款纯C实现的基于socks5协议的轻量内网穿透工具,支持ew的全部数据转发方式,支持跨平台使用
- OracleNep/Nday-Exploit-Plan - 历史漏洞的细节以及利用方法汇总收集
- kernweak/minicrypt - 基于MiniFilter和Sfilter的加解密
- esnet/iperf - iperf3: A TCP, UDP, and SCTP network bandwidth measurement tool
- qwqdanchun/HVNC - 基于Tinynuke修复得到的HVNC
- 3nock/OTE - OSINT Template Engine
- DataDog/security-labs-pocs - Proof of concept code for Datadog Security Labs referenced exploits.
- iridium-soda/container-escape-exploits - 整理容器逃逸相关的漏洞和exploits.
- baiyies/AutoMonitor - windows自动监控截图工具。 windows automatic screenshoter.
- h4ckm310n/Container-Vulnerability-Exploit - 容器安全漏洞的分析与复现
- m0nad/Diamorphine - LKM rootkit for Linux Kernels 2.6.x/3.x/4.x/5.x/6.x (x86/x86_64 and ARM64)
- PolarPeak/NIDS - 基于Suricata简单的网络入侵检测系统,也是我的垃圾毕业设计,目前仅仅是一个demo。
- evilashz/PigScheduleTask - 添加计划任务方法集合
- abcz316/rwProcMem33 - Linux ARM64内核硬件进程内存读写驱动、硬件断点调试驱动。硬件级读写Linux进程内存、硬件级下断点。
- ybdt/evasion-hub - 免杀、逆向、破解
- gtworek/PSBits - Simple (relatively) things allowing you to dig a bit deeper than usual.
- 0x25bit/darkRat_HVNC - DarkRats Standalone HVNC
- rip1s/vmware_escape - VMware Escape Exploit before VMware WorkStation 12.5.5
- Keysight/Rhme-2016 - Rhme2 challenge (2016)
- cribdragg3r/Alaris - A protective and Low Level Shellcode Loader that defeats modern EDR systems.
- david378/ssocks - build static ssocks by cmake,cross build ssocks
- seventeenman/noELF - Linux下用于远程加载可执行文件以达到内存加载的目的
- crisprss/PetitPotam - 替代PrintBug用于本地提权的新方式,主要利用MS-EFSR协议中的接口函数 借鉴了Potitpotam中对于EFSR协议的利用,实现了本地提权的一系列方式 Drawing on the use of the EFSR protocol in Potitpotam, a series of local rights escalation methods have been realized
- chicharitomu14/AndScanner - This is the project for the paper “Large-scale Security Measurements on the Android Firmware Ecosystem” in ICSE2022
- crisprss/PrintSpoofer - PrintSpoofer的反射dll实现,结合Cobalt Strike使用
- Lojii/Knot - 一款iOS端基于MITM(中间人攻击技术)实现的HTTPS抓包工具,完整的App,核心代码使用SwiftNIO实现
- 0671/RedisModules-ExecuteCommand-for-Windows - 可在Windows下执行系统命令的Redis模块,可用于Redis主从复制攻击。
- hasherezade/process_ghosting - Process Ghosting - a PE injection technique, similar to Process Doppelgänging, but using a delete-pending file instead of a transacted file
- wonderkun/go-packer - golang打包二进制进行免杀
- cbwang505/CVE-2019-0708-EXP-Windows - CVE-2019-0708-EXP-Windows版单文件exe版,运行后直接在当前控制台反弹System权限Shell
- Ascotbe/Kernelhub - :palm_tree:Linux、macOS、Windows Kernel privilege escalation vulnerability collection, with compilation environment, demo GIF map, vulnerability details, executable file (提权漏洞合集)
- AntSwordProject/ant_php_extension - PHP 扩展, 用于 PHP-FPM、FastCGI、LD_PRELOAD等模式下突破 disabled_functions
- qq4108863/hihttps - hihttps是一款完整源码的高性能web应用防火墙,既支持传统WAF的所有功能如SQL注入、XSS、恶意漏洞扫描、密码暴力破解、CC、DDOS等ModSecurity正则规则,又支持无监督机器学习,自主对抗未知攻击。
- Echocipher/AUTO-EARN - 一个利用OneForAll进行子域收集、Shodan API端口扫描、Xray漏洞Fuzz、Server酱的自动化漏洞扫描、即时通知提醒的漏洞挖掘辅助工具
- pymumu/smartdns - A local DNS server to obtain the fastest website IP for the best Internet experience, support DoT, DoH. 一个本地DNS服务器,获取最快的网站IP,获得最佳上网体验,支持DoH,DoT。
- csandker/inMemoryShellcode - A Collection of In-Memory Shellcode Execution Techniques for Windows
- NixOS/patchelf - A small utility to modify the dynamic linker and RPATH of ELF executables
- fancycode/MemoryModule - Library to load a DLL from memory.
- TheWover/donut - Generates x86, x64, or AMD64+x86 position-independent shellcode that loads .NET Assemblies, PE files, and other Windows payloads from memory and runs them with parameters
- ntop/nDPI - Open Source Deep Packet Inspection Software Toolkit
- titansec/OpenWAF - Web security protection system based on openresty
- yangyangwithgnu/bypass_disablefunc_via_LD_PRELOAD - bypass disable_functions via LD_PRELOA (no need /usr/sbin/sendmail)
- V-E-O/rdp2tcp - rdp2tcp: open tcp tunnel through remote desktop connection.
- turing-technician/FastHook - Android ART Hook
- ValdikSS/p0f-mtu - p0f with patches to save MTU value and export it via API (for VPN detection)
- Ridter/Pentest - tools
- ScottyBauer/Android_Kernel_CVE_POCs - A list of my CVE's with POCs
- DhavalKapil/icmptunnel - Transparently tunnel your IP traffic through ICMP echo and reply packets.
- DhavalKapil/heap-exploitation - This book on heap exploitation is a guide to understanding the internals of glibc's heap and various attacks possible on the heap structure.
- SecWiki/windows-kernel-exploits - windows-kernel-exploits Windows平台提权漏洞集合
- ele7enxxh/Android-Inline-Hook - thumb16 thumb32 arm32 inlineHook in Android
-
Others
- 12306Bro/Hunting-guide - Personal basics collection library
- InfosecHouse/InfosecHouse - Tools & Resources for Cyber Security Operations
- chefyuan/algorithm-base - 一位酷爱做饭的程序员,立志用动画将算法说的通俗易懂。我的面试网站 www.chengxuchu.com
- outflanknl/FindObjects-BOF - A Cobalt Strike Beacon Object File (BOF) project which uses direct system calls to enumerate processes for specific loaded modules or process handles.
- outflanknl/WdToggle - A Beacon Object File (BOF) for Cobalt Strike which uses direct system calls to enable WDigest credential caching.
- awesome-foss/awesome-sysadmin - A curated list of amazingly awesome open-source sysadmin resources.
- CnHack3r/Goby_PoC_RedTeam - 致力于收集Goby PoC,请勿用于非法操作,后果自负。
- Awrrays/FrameVul - POC集合,框架nday漏洞利用
- smallfox233/ExpToPocsuite3 - goby exp批量转换为pocsuite3 exp脚本
- Kamigami55/awesome-chatgpt - Curated list of ChatGPT related resource, tools, prompts, apps / ChatGPT 相關優質資源、工具、應用的精選清單。
- n0kovo/n0kovo_subdomains - An extremely effective subdomain enumeration wordlist of 3,000,000 lines, crafted by harvesting SSL certs from the entire IPv4 space.
- tdragon6/Supershell - Supershell C2 远控平台,基于反向SSH隧道获取完全交互式Shell
- darktohka/clean-flash-builds - Repository of clean Flash Player builds.
- trickest/wordlists - Real-world infosec wordlists, updated regularly
- zzzteph/probable_subdomains - Subdomains analysis and generation tool. Reveal the hidden!
- xx025/carrot - Free ChatGPT Site List 这儿为你准备了众多免费好用的ChatGPT镜像站点
- H4ckBu7eer-EX/h4tools - 一个安卓渗透工具盒子
- Dghpi9/NacosDefaultToken - Alibaba Nacos存在默认token.secret.key,导致远程攻击者可以绕过密钥认证接管Nacos
- AabyssZG/WebShell-Bypass-Guide - 从零学习Webshell免杀手册
- cseroad/Exp-Tools - 一款集成高危漏洞exp的实用性工具
- jatrost/awesome-detection-rules - This is a collection of threat detection rules / rules engines that I have come across.
- TakSec/chatgpt-prompts-bug-bounty - ChatGPT Prompts for Bug Bounty & Pentesting
- topscoder/lurk-sonar - Download source code of all projects in a SonarQube instance. #bugbounty #opsec #infosec #sonarqube
- MFMokbel/Crawlector - Crawlector is a threat hunting framework designed for scanning websites for malicious objects.
- burpheart/koko-moni - 一个基于网络空间搜索引擎的攻击面管理平台,可定时进行资产信息爬取,及时发现新增资产,本项目聚合了 Fofa、Hunter、Quake、Zoomeye 和 Threatbook 的数据源,并对获取到的数据进行去重与清洗
- Safe3/tianji - 天机办公安全平台(简称:TJOSG)是有安科技推出的一款全方位办公安全防护产品,包含SWG、CASB、FIDO2、PassKey、ZTNA、SASE、DLP等功能。
- elliot-bia/nessus - nessus crack for docker
- DevHackz/Android-Pentesting - Android Pentesting Zone
- darkarmorlab/video-api-check - check hikvision/ys7 api
- OffcierCia/On-Chain-Investigations-Tools-List - Here we discuss how one can investigate crypto hacks and security incidents, and collect all the possible tools and manuals! PRs are welcome! If any tool is missing - please open PR!
- apachecn/crack-tool-disk - :books: 磁盘取证工具集
- RowTeam/SharpExchangeKing - Exchange 服务器安全性的辅助测试工具
- cseroad/Webshell_Generate - 用于生成各类免杀webshell
- ExpLangcn/NucleiTP - 自动整合全网Nuclei的漏洞POC,实时同步更新最新POC!
- duc-nt/CVE-2022-44268-ImageMagick-Arbitrary-File-Read-PoC - CVE-2022-44268 ImageMagick Arbitrary File Read - Payload Generator
- bestspear/SharkOne - Cobalt Strike 二开项目
- PlexPt/awesome-chatgpt-prompts-zh - ChatGPT 中文调教指南。各种场景使用指南。学习怎么让它听你的话。
- yichensec/Yichen-GUI - 渗透测试工具箱框架,基于FreeGui二开,该工具箱,自由度较高,样式外观等皆可优化自己处理,同时具备保存笔记的优秀功能。
- A-poc/BlueTeam-Tools - Tools and Techniques for Blue Team / Incident Response
- rebeyond/JNDInjector - 一个高度可定制化的JNDI和Java反序列化利用工具
- bobby-lin/study-bug-bounty - Beginner Guide to Bug Hunting
- TryGOTry/CobaltStrike_Cat_4.5 - 猫猫Cs:基于Cobalt Strike[4.5]二开 (原dogcs二开移植)
- NHPT/Xray_Cracked - Update Xray1.9.11 Cracked for Windows,Linux and Mac OS.
- FridaZhbk/UrlRedirectScan
- komomon/CVE-2022-44877-RCE - CVE-2022-44877 Centos Web Panel 7 Unauthenticated Remote Code Execution
- numanturle/CVE-2022-44877
- A-poc/RedTeam-Tools - Tools and Techniques for Red Team / Penetration Testing
- SaiSathvik1/Linux-Privilege-Escalation-Notes - My Linux Privilege Escalation notes which is part of my OSCP Preperation
- CyberSecurityUP/Cloud-Security-Attacks - Azure and AWS Attacks
- AbelChe/macos-all - macos all, 关于macos的实用内容 不仅是macos...还有各种常用的渗透、命令行技巧
- Betsy0/CMSVulSource - CMS(内容管理系统)漏洞源码
- aliesbelik/load-testing-toolkit - Collection of open-source tools for debugging, benchmarking, load and stress testing your code or services.
- Bywalks/K8s-Mind-Map - K8S安全攻防思维导图 | Docker安全攻防思维导图
- xNaughty/BugBountyTips - BugBountyTips en Español
- bin-maker/EasyFish - 参考Gophish框架,重构的轻量级钓鱼追踪工具
- HackingCost/CyberSpace-Security-Learning - 网络安全学习wiki,包括Web安全、内网安全、云安全、免杀绕过等(持续更新)
- k88hudson/git-flight-rules - Flight rules for git
- itodaro/WhiteSharkSystem_cve
- wjl110/MacGosh-Pro - 将你的Mac打造成最强渗透测试装备--自用Mac渗透测试软件:App,框架,脚本,shell,编辑器等
- sulab999/AppMessenger - 一款适用于以APP病毒分析、APP漏洞挖掘、APP开发、HW行动/红队/渗透测试团队为场景的移动端(Android、iOS、鸿蒙)辅助分析工具
- Pik-sec/Payer - 子域名爆破神器
- RuanLang0777/CreateUser - 绕过360,火绒添加用户
- liangyimingcom/AWS-Security-Hub-usage-tutorial-and-effect-display - AWS Security Hub usage tutorial and effect display /AWS Security Hub安全合规中心使用教程和效果展示
- Proviesec/directory-files-payload-lists - Directory scans
- su18/hack-fastjson-1.2.80
- Mr-xn/BLACKHAT_USA2022 - BLACKHAT USA2022 PDF Public
- ExpLangcn/HvvInfo - 一款在红蓝对抗中快速对目标单位进行资产探测和基本扫描的工具
- Vu1nT0tal/IDA-Pro-tips - IDA Pro每周小技巧
- Kento-Sec/AsamF - AsamF是集成Fofa、Quake、Hunter、Shodan、Zoomeye、Chinaz、0.zone及爱企查的一站式企业信息资产收集、网络资产测绘工具。
- Junehck/SQL-injection-bypass - 记录实战中的各种sql注入绕过姿势
- mitre/cti - Cyber Threat Intelligence Repository expressed in STIX 2.0
- subhajit0x/Node-JS-Security-Tips - All the resources for code review ;)
- EnnioX/IPWarden - IPWarden(守望者)是一个IP资产风险巡查工具。持续发现系统、Web两个维度的资产和安全风险。所有扫描结果可通过API访问json数据,方便二次开发或数据整理。适合甲方安全人员用于监控管理公网/内网IP资产风险暴露面。
- CrackerCat/strongR-frida-android - An anti detection version frida-server for android.
- h33tlit/secret-regex-list - List of regex for scraping secret API keys and juicy information.
- zeroc00I/DNS-exfiltration-using-blind-xss- - These payloads will help u in your blind xss dumping cookies through dns exfiltration using subdomain dns queries
- trickest/resolvers - The most exhaustive list of reliable DNS resolvers.
- eryajf/Thanks-Mirror - 整理记录各个包管理器,系统镜像,以及常用软件的好用镜像,Thanks Mirror。 走过路过,如觉不错,麻烦点个赞👆🌟
- Ormicron/chatViewTool - 基于Java实现的图形化微信聊天记录解密查看器
- saeidshirazi/Awesome-Smart-Contract-Security - A curated list of Smart Contract Security materials and resources For Researchers
- Firebasky/ScanShiro - 一个批量扫描shiro漏洞的工具,支持AES/CMG
- TryGOTry/DogCs4.4 - cs4.4修改去特征狗狗版(美化ui,去除特征,自带bypass核晶截图等..)
- PeiQi0/PeiQi-WIKI-Book - 面向网络安全从业者的知识文库🍃
- httpwaf/httpwaf2.0 - httpwaf是一款永久免费的web应用防火墙,是最好用的waf。
- HackingLZ/ExtractedDefender
- samogod/bugradar - Advanced external automation on bug bounty programs by running the best set of tools to perform scanning and finding out vulnerabilities.
- d3ckx1/OLa
- coffeehb/nginx_swagger - 这个项目主要用于辅助测试Swagger的XSS漏洞
- ExpLangcn/InfoSearchAll - 为了方便安全从业人员在使用网络测绘平台进行信息搜集时的效率,本程序集合了多个网络测绘平台,可以快速在多个网络测绘平台搜索信息并且合并展示及导出。
- Y000o/Confluence-CVE-2022-26134
- achuna33/Memoryshell-JavaALL - 收集内存马打入方式
- sssqp/bypass-script - cobaltstrike免杀插件
- HackJava/JNDI - 《JNDI-深入理解Java万恶之源》
- birdhan/SecurityTools - 渗透测试工具包 | 开源安全测试工具 | 网络安全工具
- nomi-sec/CVE-Easy-List - 👀CVE Simple List
- DavidProbinsky/RedTeam-Physical-Tools - Red Team Toolkit - A curated list of tools that are commonly used in the field for Physical Security, Red Teaming, and Tactical Covert Entry.
- Getshell/PassiveScan - PassiveScan-被动扫描之巅
- sp4zcmd/WeblogicExploit-GUI - Weblogic漏洞利用图形化工具 支持注入内存马、一键上传webshell、命令执行
- komomon/POC_Collect - (持续更新)本项目为存储团队Bot小K每日监测到的最新POC,EXP,以及自己平时总结的POC,为了方便渗透测试过程中,漏洞查询,脱网环境的渗透测试。
- wangfly-me/Apache_Penetration_Tool - CVE-2021-41773&CVE-2021-42013图形化漏洞检测利用工具
- yuyan-sec/Doraemon - 渗透辅助 BurpSuite 小插件
- ExpLangcn/FuYao-Go - 自动化进行目标资产探测和安全漏洞扫描|适用于赏金活动、SRC活动、大规模使用、大范围使用|通过使用被动在线资源来发现网站的有效子域|通过强大且灵活的模板,模拟各种安全漏洞检查!Automate target asset detection and security vulnerability scanning | Suitable for bounty campaigns, SRC campaig
- q601333824/xray_crack - xray高级版本破解通用启动器
- cipher387/Dorks-collections-list - List of Github repositories and articles with list of dorks for different search engines
- litangbo/Android_Study - 《第一行代码 Android 第2版》学习笔记
- nascentxyz/simple-security-toolkit - A collection of practical security-focused guides and checklists for smart contract development
- mdecrevoisier/Microsoft-eventlog-mindmap - Set of Mindmaps providing a detailed overview of the different #Microsoft auditing capacities for Windows, Exchange, Azure,...
- hktalent/spring-spel-0day-poc - spring-cloud / spring-cloud-function,spring.cloud.function.routing-expression,RCE,0day,0-day,POC,EXP,CVE-2022-22963
- j5s/GetDomainAdmin - 获取域控权限方法枚举
- facert/awesome-spider - 爬虫集合
- Wechat-ggGitHub/Awesome-GitHub-Repo - 收集整理 GitHub 上高质量、有趣的开源项目。
- sottlmarek/DevSecOps - Ultimate DevSecOps library
- alt3kx/CVE-2022-1388_PoC - F5 BIG-IP RCE exploitation (CVE-2022-1388)
- shifa123/shodandorks
- ThestaRY7/supplier - 主流供应商的一些攻击性漏洞汇总
- Cobalt-Strike/beacon_health_check - This aggressor script uses a beacon's note field to indicate the health status of a beacon.
- JDArmy/DCSec - 域控安全one for all
- Ryze-T/Sylas - 数据库综合利用工具
- daffainfo/match-replace-burp - Useful "Match and Replace" burpsuite rules
- Bo0oM/fuzz.txt - Potentially dangerous files
- luckyfuture0177/VULOnceMore - 记录个人的漏洞复现过程
- Whitebird0/Vulnerability_Analysis - 恶意代码与漏洞
- reidmu/sec-note - 记录安全方面的笔记/工具/漏洞合集
- Threekiii/Awesome-POC - 一个漏洞POC知识库 目前数量 1000+
- Threekiii/Vulhub-Reproduce - 一个Vulhub漏洞复现知识库
- shengshengli/vulntarget - vulntarget靶场其中涵盖Web漏洞、主机漏洞、域漏洞、工控漏洞等等。
- For3stCo1d/myvulpoc - 漏洞复现,xraypoc编写
- 69337a398c/Zer0DayLab-SCAMMERS - Zer0Day Lab Are SCAMMERS
- ayadim/Nuclei-bug-hunter - i will upload more templates here to share with the comunity.
- Getshell/CobaltStrike - CobaltStrike资源大全
- f0ng/JavaFileDict - Java应用的一些配置文件字典,来源于公开的字典与平时收集
- zapstiko/Hacking-PDF - Here Are Some Popular Hacking PDF
- casbin/Summer2022 - 开源软件供应链点亮计划-暑期2022 for Casbin 【学生报名请加QQ群:540163681】
- slowmist/Cryptocurrency-Security-Audit-Guide
- phith0n/collision-webshell - A webshell and a normal file that have the same MD5
- wwl012345/Vuln-List - (持续更新)对网上出现的各种OA、中间件、CMS等漏洞进行整理,主要包括漏洞介绍、漏洞影响版本以及漏洞POC/EXP等,并且会持续更新。
- shirouQwQ/CVE-2022-2333 - SXF VPN RCE
- j2ekim/Security_Service_Interviews - 安服面经☞渗透测试/代码审计/安全研究
- biggerduck/RedTeamNotes - 红队笔记
- allanlw/svg-cheatsheet - A cheatsheet for exploiting server-side SVG processors.
- safe6Sec/command - 红队常用命令速查
- Dongdongshe/K-Scheduler - A universal seed scheduler for fuzzers (LibFuzzer and AFL havoc mode) and concolic execution engine (qsym).
- ra66itmachine/GetInfo - Windows Emergency Response (应急响应信息采集)
- RistBS/Awesome-RedTeam-Cheatsheet - Red Team Cheatsheet in constant expansion.
- nirajkharel/AD-Pentesting-Notes
- teamssix/awesome-cloud-security - awesome cloud security 收集一些国内外不错的云安全资源,该项目主要面向国内的安全人员
- slowmist/Blockchain-dark-forest-selfguard-handbook - Blockchain dark forest selfguard handbook. Master these, master the security of your cryptocurrency.
- mamba-2021/fscan-POC - 强化fscan的漏扫POC库
- prettyrecon/OSINT_Intel_Tracker - OSINT Intelligence for different areas ( useful for different type of investigations and learning etc)
- trickest/insiders - Archive of Potential Insider Threats
- cryptofinlabs/audit-checklist - A Solidity smart contract auditing checklist
- M1k0er/pentest-notes - 记录自己在内网渗透学习中的一些心得和技巧,不定期记录中:)
- sherlocksecurity/VMware-CVE-2022-22954 - POC for VMWARE CVE-2022-22954
- BlueTeamSteve/CVE-2021-41773 - Vulnerable docker images for CVE-2021-41773
- coffeehb/Spring4Shell - 一个Spring4Shell 被动式检测的Burp插件
- HuskyHacks/CobaltNotion - A spin-off research project. Cobalt Strike x Notion collab 2022
- makoto56/penetration-suite-toolkit - 本项目制作的初衷是帮助渗透新手快速搭建工作环境,工欲善其事,必先利其器。
- lu2ker/pentest-treasure - 打造一个渗透测试藏宝阁!
- kh4sh3i/Gitlab-CVE - a Curated list of gitlab vulnerability
- luckyfuture0177/ReZeroBypassAV - 从零开始学免杀
- Firebasky/CodeqlLearn - 记录学习codeql的过程
- mstxq17/SecurityArticleLogger - 分类和整理自己看过的所有文章,方便知识体系的建立和查漏补缺
- kensh1ro/flutter-ssl-bypass - Flutter SSL pinning bypass using IP forwarding
- delikely/Automotive-Security-Timeline - 汽车信息安全事件时间轴
- o1mate/AppLocker-Bypass - Bypassing AppLocker with C#
- CyberSecurityUP/Awesome-Cloud-PenTest
- MartinsAwojide/Process-System-Engineering-Catalogue - Catalogue of Articles, Projects, Papers and Resources relating to PSE
- admin360bug/Compendium-of-Materia-Medica - 本草纲目V1.4版本
- cyprosecurity/API-SecurityEmpire - API Security Project aims to present unique attack & defense methods in API Security field
- nhthongDfVn/File-Converter-Exploit - A small collection of File converter vulnerability
- gmh5225/awesome-llvm-security - awesome llvm security [Welcome to PR]
- safe6Sec/PentestDB - 各种数据库的利用姿势
- xmhwws/strongR-frida
- Y4er/dotnet-deserialization - dotnet 反序列化学习笔记
- ASTTeam/CodeQL - 《深入理解CodeQL》Finding vulnerabilities with CodeQL.
- AJMartel/MeGa-RAT-Pack - Remote Administration Tools & Remote access trojans in MEGA RAT PACK by B®AGA
- cider-security-research/top-10-cicd-security-risks
- twosmi1e/Static-Analysis-and-Automated-Code-Audit - 静态分析及代码审计自动化相关资料收集
- ics-iot-bootcamp/ICS_Awesome_List - Eclectic ICS (Industrial Control Systems) Resources & References
- mehgrmlhmpf/AttackGraphGeneratorMasterThesis - This work shows the viability of automatically generated attack graphs that are used for adversary behavior execution in industrial control system environments. This viability is evaluated and confirm
- kh4sh3i/ICS-Pentesting-Tools - A curated list of tools related to Industrial Control System (ICS) security and Penetration Testing
- paulveillard/cybersecurity-industrial-control-systems-security - A collection of awesome software, libraries, documents, books, resources and cool stuff about industrial control systems in cybersecurity.
- neutrinoguy/awesome-ics-writeups - Collection of writeups on ICS/SCADA security.
- lohitakshnandan/Bug-Bounty-Dorks - Bug Bounty Dorks
- krol3/container-security-checklist - Checklist for container security - devsecops practices
- CreditTone/studycrawler - 爬虫从入门到入土心得体会
- evilbuffer/malware-and-exploitdev-resources
- vvmdx/Sec-Interview-4-2023 - 一个2023届毕业生在毕业前持续更新、收集的安全岗面试题及面试经验分享~
- kenwoodjw/python_interview_question - 关于python的面试题
- jixing-lab/lbb - lbb是一个企业信息查询工具,可以帮助企业查询自身对外公开的应用、新媒体,网站等。
- lcvvvv/backway - backway是一款跨平台远程控制工具,在启动之后,会新建一个http服务,可通过该服务进行远程控制。
- ycdxsb/WindowsPrivilegeEscalation - Collection of Windows Privilege Escalation (Analyse/PoC/Exp...)
- allen1881996/WeChat-Data-Analysis - 微信聊天记录导出、数据库破解、数据分析 (iPhone & MacBook)
- Qihoo360/safe-rules - 详细的C/C++编程规范指南,由360质量工程部编著,适用于桌面、服务端及嵌入式软件系统。
- yavolo/eventlistener-xss-recon
- NineRiverSec/Mac_Tools - 为了方便Mac用户参与渗透工作而创建的项目
- snyk/zip-slip-vulnerability - Zip Slip Vulnerability (Arbitrary file write through archive extraction)
- 0range-x/Domain-penetration_one-stop - 域渗透一条龙
- Goqi/Banli - Banli-高危资产识别和高危漏洞扫描
- hluwa/Patchs - strongR-frida
- NyDubh3/Pentesting-Active-Directory-CN - 域渗透脑图中文翻译版
- Puliczek/awesome-list-of-secrets-in-environment-variables - 🦄🔒 Awesome list of secrets in environment variables 🖥️
- jsecurity101/MSRPC-to-ATTACK - A repository that maps commonly used attacks using MSRPC protocols to ATT&CK
- Wker666/wJa - java decompile audit tools
- Yihsiwei/GetOut360 - 强制关闭360 需要管理员权限
- 0xAwali/Blind-SSRF - Nuclei Templates to reproduce Cracking the lens's Research
- ahmetgurel/Pentest-Hints - Tips for Penetration Testing
- xen0vas/Pentest-Tips-and-Tricks - Tools and tricks gathered
- samirettali/bounty-notes - My bug bounty notes
- aetkrad/goby_poc - goby poc or exp,分享goby最新网络安全漏洞检测或利用代码
- arainho/awesome-api-security - A collection of awesome API Security tools and resources. The focus goes to open-source tools and resources that benefit all the community.
- SpiralBL0CK/Browser-Pwning- - A proper well structured documentation for getting started with chrome pwning & v8 pwning
- crisprss/goHashDumper - 用于Dump指定进程的内存,主要利用静默退出机制(SilentProcessExit)和Windows API(MiniDumpW)实现
- haby0/sec-note - 记录各语言、框架中危险的sink,个人代码审计、漏洞研究使用。
- aquasecurity/cloud-security-remediation-guides - Security Remediation Guides
- XTeam-Wing/Awesome-Jetbrains-Plugin - A series of useful idea plugins
- ak1t4/log4j-wordlists - headers
- atnetws/fail2ban-log4j - fail2ban filter that catches attacks againts log4j CVE-2021-44228
- google/clusterfuzzlite - ClusterFuzzLite - Simple continuous fuzzing that runs in CI.
- imfht/log4shell_payload_extract
- fastfire/deepdarkCTI - Collection of Cyber Threat Intelligence sources from the deep and dark web
- yanbo92/sonarqube-cn-docker - 基于代码扫描工具sonarqube社区版docker镜像集成一些常用插件以及PostgreSQL数据库的docker-compose项目
- ksoclabs/awesome-kubernetes-security - A curated list of awesome Kubernetes security resources
- LoRexxar/log_dependency_checklist - Dependencies with Log4j2 Checklist
- MohamedTarekq/log4j_Signature
- jas502n/woodpecker-plugins - woodpecker-plugins
- authomize/log4j-log4shell-affected - Lists of affected components and affected apps/vendors by CVE-2021-44228 (aka Log4shell or Log4j RCE). This list is meant as a resource for security responders to be able to find and address the vulne
- RedDrip7/Log4Shell_CVE-2021-44228_related_attacks_IOCs
- fengxuangit/log4j_vuln - log4j漏洞靶场docker-compose
- jas502n/Log4j2-CVE-2021-44228 - Remote Code Injection In Log4j
- YfryTchsGD/Log4jAttackSurface
- RabbyHub/Web3AppStoreProtocol - the first solution for the security and accessibility of Web3 Apps!
- star-sg/Presentations
- burpheart/PHPAuditGuideBook - 《PHP代码审计入门指南》 这本指南包含了我在学习PHP代码审计过程中整理出的一些技巧和对漏洞的一些理解
- sidxparab/Subdomain-Enumeration-Guide - This is a comprehensive Subdomain Enumeration Guide that traces back to my GitBook.
- kleiton0x00/Advanced-SQL-Injection-Cheatsheet - A cheat sheet that contains advanced queries for SQL Injection of all types.
- ColdFusionX/CVE-2021-26086 - Atlassian Jira Server/Data Center 8.4.0 - Arbitrary File read (CVE-2021-26086)
- CodingDocs/awesome-java - Collection of awesome Java project on Github(非常棒的 Java 开源项目集合).
- HTFTIMEONE/edusrcurl - 全国edu将近50万个域名
- Cyber-Guy1/theCyberGuy_Recon_V1.0
- A-D-Team/attackRmi
- l0ggg/VMware_vCenter - VMware vCenter 7.0.2.00100 unauth Arbitrary File Read + SSRF + Reflected XSS
- waterrr/BlackIP - 扫描CobaltStrike的恶意IP
- center-for-threat-informed-defense/attack_to_cve - 🚨ATTENTION🚨 The CVE mappings have migrated to the Center’s Mappings Explorer project. See README below. This repository is kept here as an archive.
- RoqueNight/Linux-Privilege-Escalation-Basics - Simple and accurate guide for linux privilege escalation tactics
- Karanxa/Bug-Bounty-Wordlists - A repository that includes all the important wordlists used while bug hunting.
- fangzesheng/free-api - 收集免费的接口服务,做一个api的搬运工
- crow821/vulntarget - vulntarget靶场系列
- xinxin999/My-Summarizing - 我自己的一些总结
- spring2go/cs_study_plan - 一份硬核(hardcore)计算机科学CS自学计划,偏向软件工程和系统架构方向
- sdslabs/recommends - A collection of resources and reading material that we recommend
- geeksonsecurity/vuln-web-apps - A curated list of vulnerable web applications.
- XRSec/AWVS-Update - Awvs Scanner、fahai
- Relkci/Zabbix_Nessus-Professional_Monitoring - Zabbix Nessus Professional Monitor (API)
- Liqunkit/LiqunKit_ - 下架
- diegolnasc/kubernetes-best-practices - A cookbook with the best practices to working with kubernetes.
- knownsec/Ethereum-Smart-Contracts-Security-CheckList - Ethereum Smart Contracts Security CheckList From Knownsec 404 Team
- i11us0ry/gofun - 一些内网渗透中可能用到的东拼西凑做出来的小工具
- ninoseki/phishing_kits_2021 - A dataset of phishing kits in the wild
- iceyhexman/flask_memory_shell - Flask 内存马
- HackJava/HackJava - 《Java安全-只有Java安全才能拯救宇宙》Only Java Security Can Save The Universe.
- fengupupup/RocB - 鹏 RocB - Java代码审计IDEA插件 SAST
- r0eXpeR/supplier - 主流供应商的一些攻击性漏洞汇总
- AndrewRathbun/DFIRMindMaps - A repository of DFIR-related Mind Maps geared towards the visual learners!
- bigsizeme/fastjson-check - fastjson 被动扫描、不出网payload生成
- daffainfo/all-about-apikey - Detailed information about API key / OAuth token (Description, Request, Response, Regex, Example)
- aufzayed/bugbounty - Bugbounty Resources
- Bo0oM/WAF-bypass-Cheat-Sheet - Another way to bypass WAF Cheat Sheet (draft)
- mobile-roadmap/android-developer-roadmap - Android Developer Roadmap 2020
- Y4er/CVE-2021-35215 - SolarWinds Orion Platform ActionPluginBaseView 反序列化RCE
- weartist/computer-book-list - 一个综合了豆瓣,goodreads综合评分的计算机书籍书单
- safe6Sec/PentestNote - 一些渗透姿势记录
- Vinum-Security/kubernetes-security-checklist - Kubernetes Security Checklist and Requirements - All in One (authentication, authorization, logging, secrets, configuration, network, workloads, dockerfile)
- httptoolkit/httptoolkit - HTTP Toolkit is a beautiful & open-source tool for debugging, testing and building with HTTP(S) on Windows, Linux & Mac :tada: Open an issue here to give feedback or ask for help.
- daem0nc0re/Abusing_Weak_ACL_on_Certificate_Templates - Investigation about ACL abusing for Active Directory Certificate Services (AD CS)
- Astartgo/easy-for-webscan - 根据WebBatchRequest图形化二次开发:增加了指纹识别模块,可识别大概上千条指纹,增加了IP段处理,支持C段和B段处理,增加了301处理,增加了去重空节点的功能,可节省内存消耗,推荐勾选此选项
- antonio-morales/Fuzzing101 - An step by step fuzzing tutorial. A GitHub Security Lab initiative
- lehui99/articles
- kingz40o/Aggressor_dingding - cobaltstrike 上线提醒
- clarkvoss/AEM-List
- Ignitetechnologies/Command-Control - This cheasheet is aimed at the Red Teamers to help them find diffent tools and methods to create a Commmand and Control Server and exploit remote session.
- hetmehtaa/bug-bounty-noob
- lintstar/About-Attack - 一个旨在通过应用场景 / 标签对 Github 红队向工具 / 资源进行分类收集,降低红队技术门槛的手册【持续更新】
- he1m4n6a/Go_Security_Study - golang安全学习总结
- Ignitetechnologies/Nmap-For-Pentester - This cheatsheet was created to assist Red Teamers and Penetration Testers in hunting down vulnerabilities using "Nmap."
- JoshuaProvoste/URL-Encode-Injection - URL Encode Injection List
- Zeyad-Azima/Offensive-Resources - A Huge Learning Resources with Labs For Offensive Security Players
- hmaverickadams/TCM-Security-Sample-Pentest-Report - Sample pentest report provided by TCM Security
- mstxq17/CVE-2021-1675_RDL_LPE - PrintNightMare LPE提权漏洞的CS 反射加载插件。开箱即用、通过内存加载、混淆加载的驱动名称来ByPass Defender/EDR。
- zhangxiangliang/civil-service-exam - 考试攻略 | 公务员 | 事业单位
- sigp/solidity-security-blog - Comprehensive list of known attack vectors and common anti-patterns
- NitinYadav00/My-Nuclei-Templates - Nuclei Templates - Here you will find the templates I use while hunting
- iamsarvagyaa/AndroidSecNotes - An actively maintained, Self curated notes related to android application security for security professionals, bugbounty hunters, pentesters, reverse engineer, and redteamers.
- thelikes/fuzzmost - all manner of wordlists
- vavkamil/awesome-vulnerable-apps - Awesome Vulnerable Applications
- Bhagavan-Bollina/BugBounty-Dorks - Highly recommended dorks for bug bounty
- 0xmaximus/Galaxy-Bugbounty-Checklist - Tips and Tutorials for Bug Bounty and also Penetration Tests.
- RiskySignal/Devil-Whisper-Attack - Devil-Whisper-Attack
- stratosphereips/awesome-ml-privacy-attacks - An awesome list of papers on privacy attacks against machine learning
- bkrem/awesome-solidity - ⟠ A curated list of awesome Solidity resources, libraries, tools and more
- ShutdownRepo/The-Hacker-Recipes - This project is aimed at freely providing technical guides on various hacking topics: Active Directory services, web services, servers, intelligence gathering, physical intrusion, phishing, mobile app
- pdelteil/BugBountyReportTemplates - List of reporting templates I have used since I started doing BBH.
- dorkerdevil/Azorult-hunter - Azorult C&C hunter with bash onliner and nuclei yaml rule
- Lz1y/SyncDog - Make bloodhound sync with cobaltstrike.
- vestjoe/cobaltstrike_services - AutoStart teamserver and listeners with services
- threatexpress/cobaltstrike_payload_generator - Quickly generate every payload type for each listener and optionally host via HTTP.
- rarecoil/pantagrule - large hashcat rulesets generated from real-world compromised passwords
- MountCloud/FireKylin - 🔥火麒麟-网络安全应急响应工具(系统痕迹采集)Cybersecurity emergency response tool.👍👍👍
- optiv/OSINT_Encyclopedia - Your go-to resource for all things OSINT
- the-xentropy/samlists - Free, libre, effective, and data-driven wordlists for all!
- flothrone/smm
- subat0mik/whoamsi - An effort to track security vendors' use of Microsoft's Antimalware Scan Interface
- eastlakeside/awesome-productivity-cn - 绝妙的个人生产力(Awesome Productivity - Chinese version)
- IT-Weekly/APP
- zwjjustdoit/Xstream-1.4.17 - XSTREAM<=1.4.17漏洞复现(CVE-2021-39141、CVE-2021-39144、CVE-2021-39150)
- galdeleon/Conferences
- optiv/Registry-Recon - Cobalt Strike Aggressor Script that Performs System/AV/EDR Recon
- baiduxlab/sgxray
- r0eXpeR/Online_Tools - 一些在线的工具,情报资源
- EdgeSecurityTeam/Eeyes - Eeyes(棱眼)-快速筛选真实IP并整理为C段
- Cobalt-Strike/teamserver-prop - TeamServer.prop is an optional properties file used by the Cobalt Strike teamserver to customize the settings used to validate screenshot and keylog callback data, which allows you to tweak the fix fo
- joswha/Secure-Coding-Handbook - Web Application Secure Coding Handbook resource.
- CnTransGroup/EffectiveModernCppChinese - 《Effective Modern C++》- 完成翻译
- cloudcommunity/Free-Certifications - A curated list of free courses & certifications.
- PhishyAlice/awesome-phishing - Collection of resources related to phishing
- nevillegrech/MadMax - Ethereum Static Vulnerability Detector for Gas-Focussed Vulnerabilities
- JerryLinLinLin/Huorong-HIPS-Rule-Schema - The project includes two json schemas of Huorong Host-based Intrusion Prevention System (HIPS) custom rule files (json). They can be used to validate Huorong HIPS rules and speed up editing.
- decalage2/awesome-security-hardening - A collection of awesome security hardening guides, tools and other resources
- taterbrown/cisco-secure-config - Security hardening for Cisco devices
- sametsazak/sysmon - Sysmon and wazuh integration with Sigma sysmon rules [updated]
- limiteci/sql-injection-payloads - simple markdown-list to operate SQL injections
- jamestiotio/NoMoreRansom - All-in-One Ransomware Decryption Tools (Unofficial Mirror)
- s4dhul4bs/vimana-framework - Vimana is an experimental security tool that aims to provide resources for auditing Python web applications.
- talsec/Free-RASP-Community - SDK providing app protection and threat monitoring for mobile devices, available for Flutter, Cordova, Android and iOS.
- xxycfhb/pku_exploit_files
- safe6Sec/Fastjson - Fastjson姿势技巧集合
- 404notf0und/AI-for-Security-Landing - 企业级安全智能化实践
- XTeam-Wing/SharpMimikatz - Csharp 反射加载dll
- phonchi/awesome-side-channel-attack - A curated list of awesome side-channel attack resources
- arialdomartini/Back-End-Developer-Interview-Questions - A list of back-end related questions you can be inspired from to interview potential candidates, test yourself or completely ignore
- magoo/ato-checklist - A checklist of practices for organizations dealing with account takeover (ATO)
- FDlucifer/DroidJack-cracked-version- - DroidJack (安卓远控神器 破解版)
- ch33r10/EnterprisePurpleTeaming - Purple Team Resources for Enterprise Purple Teaming: An Exploratory Qualitative Study by Xena Olsen.
- winezer0/burp-random-header-plus - Realize the dynamic modification of the request header,用于实现请求头的动态修改burp插件 。
- jaiswalakshansh/Facebook-BugBounty-Writeups - Collection of Facebook Bug Bounty Writeups
- S3cur3Th1sSh1t/LDAP-Signing-Scanner - A little scanner to check the LDAP Signing state
- payloadbox/xxe-injection-payload-list - 🎯 XML External Entity (XXE) Injection Payload List
- emadshanab/facebook-bug-bounty-writeups - Facebook Bug Bounties
- bilalmerokhel/bugbounty
- wangtielei/Slides - slides for conference talks
- WBGlIl/Beacon_re
- bohops/UltimateWDACBypassList - A centralized resource for previously documented WDAC bypass techniques
- cfalta/MicrosoftWontFixList - A list of vulnerabilities or design flaws that Microsoft does not intend to fix. Since the number is growing, I decided to make a list. This list covers only vulnerabilities that came up in July 2021
- cpkkcb/fuzzDicts - 渗透测试路径字典,爆破字典。内容来自互联网和实战积累。
- disclose/bug-bounty-platforms - A community-powered collection of all known bug bounty platforms, vulnerability disclosure platforms, and crowdsourced security platforms currently active on the Internet.
- glitchedgitz/cook-ingredients - The largest collection of wordlists in yaml for bug bounty tools
- shramos/Awesome-Cybersecurity-Datasets - A curated list of amazingly awesome Cybersecurity datasets
- kot-behemoth/awesome-joplin - 📒 A curated list of awesome Joplin themes and tools.
- tjnull/TJ-JPT - This repo contains my pentesting template that I have used in PWK and for current assessments. The template has been formatted to be used in Joplin
- daikerSec/windows_protocol
- murataydemir/CVE-2020-3452 - [CVE-2020-3452] Cisco Adaptive Security Appliance (ASA) & Cisco Firepower Threat Defense (FTD) Web Service Read-Only Directory Traversal
- MistSpark/DNS-Wordlists - part of my wordlist to bruteforce DNS to find subdoamains.
- sectool/redteam-hardware-toolkit - 🔺 Red Team Hardware Toolkit 🔺
- nccgroup/exploit_mitigations - Knowledge base of exploit mitigations available across numerous operating systems, architectures and applications and versions.
- vavkamil/awesome-bugbounty-tools - A curated list of various bug bounty tools
- emadshanab/Scan-Apple-ASN-for-vulnerabilities-and-leave-no-port
- sapegin/jest-cheat-sheet - Jest cheat sheet
- bkerler/Loaders - EDL Loaders
- XTeam-Wing/Active-Directory-Security-101 - Active-Directory-Security-101
- NagliNagli/Shockwave-OSS
- We5ter/Flerken - A Solution For Cross-Platform Obfuscated Commands Detection presented on CIS2019 China. 动静态Bash/CMD/PowerShell命令混淆检测框架 - CIS 2019大会
- RavikumarRamesh/hpAndro1337 - Repository for download all version of @hpAndro1337 (Android AppSec) application.
- BlackFan/content-type-research - Content-Type Research
- othneildrew/Best-README-Template - An awesome README template to jumpstart your projects!
- Avileox/BB-SH-B
- forced-request/xssValidator - This is a burp intruder extender that is designed for automation and validation of XSS vulnerabilities.
- wyzxxz/aksk_tool - AK资源管理工具,阿里云/腾讯云/华为云/AWS/UCLOUD/京东云/百度云/七牛云存储 AccessKey AccessKeySecret,利用AK获取资源信息和操作资源,ECS/CVM/E2/UHOST/ECI/BCC执行命令,OSS/COS/S3/BOS管理,RDS/DB管理,域名管理,添加RAM/CAM/IAM账号等
- awslabs/aws-security-analytics-bootstrap - AWS Security Analytics Bootstrap enables customers to perform security investigations on AWS service logs by providing an Amazon Athena analysis environment that's quick to deploy, ready to use, and e
- purabparihar/Web-Application-Pentest-Checklist
- 0voice/campus_recruitmen_questions - 2021年最新整理,5000道秋招/提前批/春招/常用面试题(含答案),包括leetcode,校招笔试题,面试题,算法题,语法题。
- binance/binance-spot-api-docs - Official Documentation for the Binance Spot APIs and Streams
- TROUBLE-1/Cloud-Pentesting - This repository is in progress, it will keep updating as I come across to new learning materials. Feel free to contribute.
- gh0stkey/Binary-Learning - 二进制安全相关的学习笔记,感谢滴水逆向的所有老师辛苦教学。
- FalconForceTeam/FalconFriday - Hunting queries and detections
- Ondrik8/byPass_AV
- PDWR/3vilMacro - This is a easy tool for gen VBA code, and bypass most antivirus
- wsummerhill/C2_RedTeam_CheatSheets - Useful C2 techniques and cheatsheets learned from engagements
- Green-m/msfvenom-zsh-completion - zsh completion for msfvenom in Metasploit
- boy-hack/go-strip - 清除Go编译时自带的信息
- mzlogin/awesome-adb - ADB Usage Complete / ADB 用法大全
- hhxy/e-message_exp - e-mesaage <=4.15 后台jar包上传exp
- adi0x90/attifyos - Attify OS - Distro for pentesting IoT devices
- TomBener/stay-away-from-wechat - 人生苦短,远离微信
- benjamin-schultz/wow-such-miner - A FPGA Dogecoin Miner
- ydycjz6j/VICIdial - Concept:
- emadshanab/admin-login
- SCUBSRGroup/Automatic-Exploit-Generation - Something about AEG
- emadshanab/Subdomains-brutforce-wordlists-collection
- emadshanab/Burp-Bounty-free-Profiles-Collection
- emadshanab/VOIP-Pentesting-checklist-Cheatsheet-Tools
- yuyan-sec/druid_sessions - 获取 alibaba druid 一些 sessions , sql , urls
- salmonx/dictionaries - Fuzzing dictionaries for afl-fuzz/LibFuzzer
- Ignitetechnologies/Credential-Dumping - This cheatsheet is aimed at the Red Teamers to help them understand the fundamentals of Credential Dumping (Sub Technique of Credential Access) with examples. There are multiple ways to perform the sa
- Ph4l4nx/CTF-s-Tools - Repository to index useful tools for CTF's
- SofianeHamlaoui/Pentest-Bookmarkz - A collection of useful links for Pentesters
- MustafaSky/Guide-to-SSRF - Guide to SSRF
- naozibuhao/fofatools
- obreinx/nuceli-templates - My Custom made Nuceli-Templates
- optiv/mobile-nuclei-templates
- geeknik/the-nuclei-templates - Nuclei templates written by us.
- woodpecker-framework/woodpecker-framework-release - 高危漏洞精准检测与深度利用框架
- Tencent/secguide - 面向开发人员梳理的代码安全指南
- dievus/printspoofer
- eastmountyxz/APT_Digital_Weapon - Indicators of compromise (IOCs) collected from public resources and categorized by Qi-AnXin.
- outflanknl/HelpColor - Agressor script that lists available Cobalt Strike beacon commands and colors them based on their type
- stackblitz/webcontainer-core - Dev environments. In your web app.
- samwcyo/CVE-2021-27651-PoC - RCE for Pega Infinity >= 8.2.1, Pega Infinity <= 8.5.2
- digitalarche/OnlineToolsForBlueTeam - By Categories all online tools for blueteam
- Securityinbits/cheatsheet - These are some of the commands which I use frequently during Malware Analysis and DFIR.
- scythe-io/purple-team-exercise-framework - Purple Team Exercise Framework
- Ershu1/2021_Hvv - 2021 hw
- dr0op/shiro-550-with-NoCC - Shiro-550 不依赖CC链利用工具
- twseptian/oneliner-bugbounty - oneliner commands for bug bounties
- MinoTauro2020/AndroidBugBounty - Find interesting things in APK
- XTeam-Wing/X-AV - X系列安全工具-AV免杀框架-BypassAV
- hmaverickadams/External-Pentest-Checklist
- halencarjunior/BugBuntu - BugBuntu Linux
- BushidoUK/CTI-Lexicon - Dictionary of CTI-related acronyms, terms, and jargon
- haidragon/study_Android_Mchange - android 系统定制(魔改)
- JeremyBlackthorne/Ghidra-Keybindings
- XTeam-Wing/Hunting-Active-Directory - 个人整理的一些域渗透Tricks,可能有一些错误。
- GetRektBoy724/MeterPwrShell - Automated Tool That Generates The Perfect Meterpreter Powershell Payload
- BBerastegui/fresh-dns-servers - Fresh DNS servers
- Kevin-Robertson/InveighZero - .NET IPv4/IPv6 machine-in-the-middle tool for penetration testers
- MoisesTapia/TWAPT - Deploy your own lab of web application penetration testing with docker and docker-compose, webgoat, dvwap, bwapp and Juice Shop
- ehsaanqazi/Bug-Bounty - Resources and Guides for Web Application Vulnerabilities
- r0eXpeR/pentest - 内网渗透中的一些工具及项目资料
- hslatman/awesome-threat-intelligence - A curated list of Awesome Threat Intelligence resources
- Richard-Tang/x1DecoderPlus - AntSword(蚁剑)全参数流量XOR和Base64加伪装WebShell
- EXHades/CyberSpaceSearchEngine-Research - 网络空间测绘/搜索引擎相关的资料
- maxandersen/internet-monitoring - Monitor your network and internet speed with Docker & Prometheus
- timwhitez/Doge-Defense-Evasion-Ref - Defense Evasion & Bypass AntiVirus reference
- Airboi/bypass-av-note - 免杀技术大杂烩---乱拳也打不死老师傅
- ftpmorph/ftprivacy - A collection of ad block lists for Pi Hole, AdGuard Home, pfBlockerNG, uBlock Origin, and more... - https://ftprivacy.cloud
- dsopas/MindAPI - Organize your API security assessment by using MindAPI. It's free and open for community collaboration.
- aahmad097/ZoomPersistence - Zoom Persistence Aggressor and Handler
- HolyBugx/HolyTips - A Collection of Notes, Checklists, Writeups on Bug Bounty Hunting and Web Application Security.
- Lotlab/Lot60-BLE-Keyboard - A 60% bluetooth keyboard (Hardware)
- onceupon/Bash-Oneliner - A collection of handy Bash One-Liners and terminal tricks for data processing and Linux system maintenance.
- preludeorg/operator-support - Operator: an autonomous red team command-and-control platform to make security testing more accessible.
- dustyfresh/PHP-vulnerability-audit-cheatsheet - This will assist you in the finding of potentially vulnerable PHP code. Each type of grep command is categorized in the type of vulnerabilities you generally find with that function.
- harsh-bothra/Security-Talks-Slides - This repository contains all the Talk slides that I have given at various security conferences, events & meetups.
- YinWC/Security_Learning - Security Learning For All~
- ruanbekker/ansible-docker-swarm - Initialize Docker Swarm with Ansible
- lokles/Web-Development-Interview-With-Java - Java 开发相关技术栈(大中厂)高频面试问题收录。
- w2n1ck/vulwiki - 常见漏洞知识库文档
- shifa123/bugbountyDorks - This repo contains all the Bug Bounty Dorks sourced from different awesome sources and compiled at one place
- kuchin/awesome-cto - A curated and opinionated list of resources for Chief Technology Officers, with the emphasis on startups
- FuzzySecurity/AzureWireGuard - Automated WireGuard Deployment on Azure
- taojintianxia/github-bookmark - 收集了Github上的优秀工具,框架,知识合集
- broken5/bscan
- WilliamL71Oi/FOFA_PRO_GUI - 用python做的十分好用且强大的FOFA的GUI版本,原创版本,点个star,谢谢支持
- TheCrysp/Gitty
- xalgord/Massive-Web-Application-Penetration-Testing-Bug-Bounty-Notes
- waylau/git-for-win - Git for Windows. 国内直接从官网下载比较困难,需要翻墙。这里提供一个国内的下载站,方便网友下载
- blockthreat/blocksec-ctfs - A curated list of blockchain security Capture the Flag (CTF) competitions
- PalindromeLabs/Java-Deserialization-CVEs - Compiled dataset of Java deserialization CVEs
- biws-byte/pdf - 上传资料文档
- evets007/OSCP-Prep-cheatsheet
- sourceincite/CVE-2021-26121
- KathanP19/OpenBB-Scope - OpenBugBounty - https://www.openbugbounty.org/ programs list
- TeraSecTeam/ary - Ary 是一个集成类工具,主要用于调用各种安全工具,从而形成便捷的一键式渗透。
- boh/RedCsharp - Collection of C# projects. Useful for pentesting and redteaming.
- bin-maker/BYPASS-CDN
- zhengmin1989/POP_AND_PUSH - A collection of POP exploits.
- ethicalhackingplayground/recon_db_scripts - Creating a Database for Mass Recon
- k8gege/KaliLadon - Ladon for Linux (Kali), Large Network Penetration Scanner, vulnerability / exploit / detection / MS17010 / password
- harsh-bothra/learn365 - This repository is about @harshbothra_'s 365 days of Learning Tweets & Mindmaps collection.
- e11i0t4lders0n/SAML-SSO
- Ignitetechnologies/bugbounty
- TheBinitGhimire/GitHub-Recon - GitHub Recon — and what you can achieve with it!
- novanazizr/10-Reset-Password-Flaws - 10 Reset Password Flaws Based on Web Application Security
- crisxuan/bestJavaer - 这是一个成为更好的Java程序员的系列教程
- lutfumertceylan/top25-parameter - For basic researches, top 25 vulnerability parameters that can be used in automation tools or manual recon. 🛡️⚔️🧙
- Al1ex/CVE-2020-13937 - Apache Kylin API Unauthorized Access
- Tas9er/RedisSSHKey - Code By:Tas9er / Redis未授权SSH协议公钥写入漏洞验证
- WillOram/cyber-incident-management - Notes on managing and coordinating the response to major cyber incidents
- aws-samples/aws-incident-response-playbooks
- tamimhasan404/Nmap-Cheat-Sheet - Here I am trying to show you some cheat-sheet of nmap. Which may help you on penetration testing and bug hunting.
- SnollyG0st3r/android-security-awesome - A collection of android security related resources
- SnollyG0st3r/android_app_security_checklist - Android App Security Checklist
- 997509/pentest-mobile-cheatsheet - The Mobile App Pentest cheat sheet was created to provide concise collection of high value information on specific mobile application penetration testing topics.
- kyawthiha7/Mobile-App-Pentest
- w0lfzhang/some_nday_bugs
- TheMRLL/WinXray - 支持Xray / V2Ray(vmess / vless),Shadowsocks,SSR,Trojan,NaïveProxy,Trojan-go通用客户端(Windows)!默认基于xray核心!本程序采用aardio设计与开发!
- Qftm/Information_Collection_Handbook - Handbook of information collection for penetration testing and src
- iamthefrogy/Web-Application-Pentest-Checklist - This is one of the largest checklist available so far on the Internet.
- chriskaliX/AD-Pentest-Notes - 用于记录内网渗透(域渗透)学习 :-)
- bg6cq/ITTS - Campus IT Technical Specifications
- mr-r3b00t/CVE-2021-3156
- novanazizr/BugBountyHunting - Some Tutorials and Things to Help Bug Hunter
- ClownQq/YDArk - X64内核小工具
- k-lazarev/joplin-ctf-template - Joplin template for CTF events / OSCP labs & exam
- WinkoErades/Joplin-note-taking-templates - Joplin note taking templates
- tess-ss/writeups
- dubey-amit/Web-Cheatsheet - Vulnerability Cheatsheet
- ffffffff0x/Pentest101 - 一些关于渗透测试的Tips
- Power7089/PenetrationTest-Tips - 渗透测试,渗透测试小技巧,渗透测试Tips,师傅们跟我一起维护更新吧~
- dloss/python-pentest-tools - Python tools for penetration testers
- mrtouch93/awesome-security-feed - A semi-curated list of Security Feeds
- security-cheatsheet/metasploit-cheat-sheet - Metasploit Cheat Sheet 💣
- cqsd/daily-commonspeak2 - commonspeak2 subdomains wordlist generated daily **DEPRECATED** The author(s) of commonspeak2 maintain an official repo with more lists. Please use it instead: https://github.com/assetnote/wordlists
- GrapheneOS/platform_manifest - Repo manifest for the GrapheneOS mobile privacy and security hardening project.
- Malayke/nofingerprint - remove common pentest tools fingerprint
- ayoubfathi/leaky-paths - A collection of special paths linked to common sensitive APIs, devops internals, frameworks conf, known misconfigurations, juicy APIs ..etc. It could be used as a part of web content discovery, to sca
- httpvoid/writeups
- sbousseaden/macOS-ATTACK-DATASET - JSON DataSet for macOS mapped to MITRE ATT&CK Tactics.
- assetnote/blind-ssrf-chains - An exhaustive list of all the possible ways you can chain your Blind SSRF vulnerability
- Al1ex/CVE-2020-36179 - CVE-2020-36179~82 Jackson-databind SSRF&RCE
- 418sec/huntr - Public Roadmap | huntr.dev
- Adminisme/SharpRDPLog - Windows rdp相关的登录记录导出工具,可用于后渗透中Windows服务器的信息收集阶段。输出内容包括:本地rdp端口、mstsc缓存、cmdkey缓存、登录成功、失败日志事件。
- R0X4R/D4rkXSS - A list of useful payloads and Bypass for Web Application Security and Bug Bounty/CTF
- ch1nghz/CVE-2020-11851 - Remote Code Execution vulnerability on ArcSight Logger
- aceld/golang - 《Golang修养之路》本书针对Golang专题性热门技术深入理解,修养在Golang领域深入话题,脱胎换骨。
- sjsdfg/effective-java-3rd-chinese
- uzzzval/CVE-2020-17530
- BrodieInfoSec/Gift
- thunderbarca/Caesar - 一个全新的敏感文件发现工具
- Quikko/Recon-Methodology - Recon Methodology
- TeraSecTeam/poc-collection - poc-collection 是对 github 上公开的 PoC 进行收集的一个项目。
- MichaelKoczwara/Awesome-CobaltStrike-Defence - Defences against Cobalt Strike
- Al1ex/CVE-2020-35728 - CVE-2020-35728 & Jackson-databind RCE
- attacker-codeninja/100DaysToLearnandImprove - My notes of Day1 Day2 will be posted here as journey
- RangerNJU/Static-Program-Analysis-Book - Getting started with static program analysis. 静态程序分析入门教程。
- chenjj/Awesome-HTTPRequestSmuggling - A curated list of awesome blogs and tools about HTTP request smuggling attacks. Feel free to contribute! 🍻
- birdbee44/Resources
- Proteas/apple-cve - apple cve list
- jas502n/CVE-2020-17008 - CVE-2020-17008 splWOW64 Elevation of Privilege
- attacker-codeninja/AllThingsBugHunting
- xfiftyone/xTools - xTools,一个辅助小工具
- gobysec/GobyExtension - Goby extension doc.
- tigerszk/aws_sec_traning
- IQTLabs/software-supply-chain-compromises - A dataset of software supply chain compromises. Please help us maintain it!
- cedowens/C2-JARM - A list of JARM hashes for different ssl implementations used by some C2/red team tools.
- RASSec/burpsuite-plugins-notes
- RedDrip7/APT_Digital_Weapon - Indicators of compromise (IOCs) collected from public resources and categorized by Qi-AnXin.
- doubleee/WebFuzzing - 自用字典,收集实战中遇到的奇特目录名、后门文件名等。不定期更新!
- qigpig/bypass-beacon-config-scan - Bypass cobaltstrike beacon config scan
- cypher3107/GF-Patterns
- Matir/gf-patterns
- r00tkie/grep-pattern - collection of various grep patterns collected from tomnomnom/gf and other places
- bp0lr/myGF_patterns
- bfuzzy/auditd-attack - A Linux Auditd rule set mapped to MITRE's Attack Framework
- oskarsve/ms-teams-rce
- r0eXpeR/redteam_vul - 红队作战中比较常遇到的一些重点系统漏洞整理。
- doyensec/awesome-electronjs-hacking - A curated list of awesome resources about Electron.js (in)security
- Nanguage/Rainbow-Fart-MBG - 程序员要讲码德,耗子尾汁,好好反思!
- Ignitetechnologies/Web-Application-Cheatsheet - This cheatsheet is aimed at the CTF Players and Beginners to help them understand Web Application Vulnerablity with examples.
- devsecops/awesome-devsecops - An authoritative list of awesome devsecops tools with the help from community experiments and contributions.
- ghsec/webHunt - Web App bug hunting
- secoba/SomePubRegex - Some useful regexes
- amrandazz/attack-guardduty-navigator - A MITRE ATT&CK Navigator export for AWS GuardDuty Findings
- ptswarm/ptswarm-twitter
- Y000o/Sql_injection_medium-advanced.md
- mark0smith/Kunlun-M-GUI - Kunlun-M 的GUI程序
- kallydev/privacy - 个人隐私泄露检测工具。
- ChandlerBang/awesome-graph-attack-papers - Adversarial attacks and defenses on Graph Neural Networks.
- disclose/resources - Tools, data, and contact lists relevant to The disclose.io Project.
- msaponja/Manual - The project is based on Ben Clark's book: Red Team Field Manual.
- 0x90n/InfoSec-Black-Friday - All the deals for InfoSec related software/tools this Black Friday
- mitre/advmlthreatmatrix - Adversarial Threat Landscape for AI Systems
- joker2a/OSCP - OSCP cheatsheet
- push0ebp/sig-database - IDA FLIRT Signature Database
- driverCzn/Glibc-source-browser - Multi-version glibc source browser based on code.woboq.org 's product.
- 0voice/expert_readed_books - 2021年最新总结,推荐工程师合适读本,计算机科学,软件技术,创业,思想类,数学类,人物传记书籍
- zer0yu/RedTeam_CheetSheets - RedTeam参考,修改自Ridter的https://github.com/Ridter/Intranet_Penetration_Tips
- hausec/Bloodhound-Custom-Queries - Custom Query list for the Bloodhound GUI based off my cheatsheet
- cyber-research/APTMalware - APT Malware Dataset Containing over 3,500 State-Sponsored Malware Samples
- whitespots/fast-security-scanners - Security checks for your researches
- CTF-MissFeng/nmaps - 采用Golang编写的新一代端口及指纹扫描器
- dgryski/awesome-go-style - A collection of Go style guides
- Ignitetechnologies/BurpSuite-For-Pentester - This cheatsheet is built for the Bug Bounty Hunters and penetration testers in order to help them hunt the vulnerabilities from P4 to P1 solely and completely with "BurpSuite".
- c0rdis/security-champions-playbook - Security Champions Playbook v 2.1
- ReconInfoSec/rhq - Recon Hunt Queries
- VillanCh/palm-kit-desktop - 发布 palm-kit 桌面版
- blanboom/awesome-home-networking-cn - 家庭网络知识整理
- ManuZhu0728/Windows-Terminal-beautify - Windows Terminal美化教程
- PolarisLab/AESGFIC - 互联网企业安全高级指南读书笔记脑图 - http://www.mottoin.com/95816.html & http://www.mottoin.com/95828.html Author:hblf@MottoIN Team
- irsl/apache-openoffice-rce-via-uno-links
- saeidshirazi/awesome-android-security - A curated list of Android Security materials and resources For Pentesters and Bug Hunters
- uknowsec/TailorScan - 自用缝合怪内网扫描器,支持端口扫描,识别服务,获取title,扫描多网卡,ms17010扫描,icmp存活探测。
- jas502n/database-jasypt - jasypt Decrypt Encrypt
- jas502n/oracleShell - oracle 数据库命令执行
- anhkgg/anhkgg-tools - Anhkgg's Tools
- WinMin/Protocol-Vul - Some Vulnerability in the some protocol are collected.
- Virdoexhunter/OneLinerBashrcCommands
- j1anFen/shiro_attack - shiro反序列化漏洞综合利用,包含(回显执行命令/注入内存马)
- HackerYunen/CTFWPS - All the writeups of www.ctfwp.com
- resumejob/interview-questions - Interview Questions for Google, Amazon, Apple, etc. 根据超过 2000 篇真实面经整理的腾讯,阿里,字节跳动,Shopee,美团,滴滴高频面试题
- kongsec/Wordpress-BruteForce-List - WordPress Bruteforce List, Default paths and endpoints
- hellodword/wechat-feeds - [已停止服务] 给微信公众号生成 RSS 订阅源
- xiaokanghub/Android - Android 加固应用Hook方式-Frida
- Purp1eW0lf/HackTheBoxWriteups - Writeups for the machines on ethical hacking site Hack the Box
- Neo23x0/vti-dorks - Awesome VirusTotal Intelligence Search Queries
- KingFalse/ojdk - 最新的JDK国内下载地址
- wcventure/FuzzingPaper - Recent Fuzzing Paper
- mahavivo/english-wordlists - 常用英语词汇表
- six2dez/pentest-book
- nil0x42/awesome-hacker-note-taking - Awesome note-taking apps for hackers & pentesters !
- k8gege/PasswordDic - 2011-2019年Top100弱口令密码字典 Top1000密码字典 服务器SSH/VPS密码字典 后台管理密码字典 数据库密码字典 子域名字典
- gtworek/Priv2Admin - Exploitation paths allowing you to (mis)use the Windows Privileges to elevate your rights within the OS.
- taielab/Taie-Bugbounty-killer - 挖掘国内外漏洞平台必备的自动化捡钱赏金技巧,看了并去做了捡钱如喝水。
- mishmashclone/GrrrDog-Java-Deserialization-Cheat-Sheet - https://github.com/GrrrDog/Java-Deserialization-Cheat-Sheet
- aleenzz/php_bug_wiki - 代码审计相关的一些知识
- Y000o/Payloads_xss_sql_bypass
- 0neb1n/CVE-2020-16947 - PoC of CVE-2020-16947 (Microsoft Outlook RCE vulnerablility)
- Imanfeng/Apache-Solr-RCE - Apache Solr Exploits 🌟
- foryujian/yujianportscan - 一个基于VB.NET + IOCP模型开发的高效端口扫描工具,支持IP区间合并,端口区间合并,端口指纹深度探测
- pyn3rd/my-presentation-slide
- RabiAPI/RabiAPI-Support - RabiAPI是一个开箱即用的Java接口文档生成工具,界面美观易用,支持多种框架注解。
- Fawadkhanfk/Hunting-Tips - Tips For Bug Bounty Hunters
- cvebase/cvebase.com - cvebase is a community-driven vulnerability data platform to discover the world's top security researchers and their latest disclosed vulnerabilities & PoCs
- decoder-it/whoami-priv-Hackinparis2019 - Slides from my talk in "Hackinparis" 2019 edition
- jas502n/Flink_RCE - Apache Flink Web Dashboard 未授权访问,上传恶意jar导致远程代码命令执行
- dr0op/CrossC2 - generate CobaltStrike's cross-platform payload
- jas502n/BurpSuite-icns - 制作BurpSuite icns 在Mac OS上
- droberson/rtfm - Cheat sheet and notes inspired by the book RTFM - Red Team Field Manual
- L1ves/windows-pentesting-resources
- chennylmf/OWASP-Web-App-Pentesting-checklists
- cranelab/webapp-tech
- ahmetumitbayram/kortto-admin-panel-finder-bypasser
- jas502n/Jboss_JMXInvokerServlet_Deserialization_RCE - Jboss_JMXInvokerServlet_Deserialization_RCE
- jas502n/JWT_Brute - JWT_Brute
- Flangvik/SharpCollection - Nightly builds of common C# offensive tools, fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.
- oracle/oraclejet - Oracle JET is a modular JavaScript Extension Toolkit for developers working on client-side applications.
- oskarkrawczyk/honukai-iterm-zsh - Honukai theme and colors for Oh My ZSH and iTerm
- LGBT-CN/LGBTQIA-In-China - 🏳️🌈 中国的性少数群体一直渴望着自由平等
- RASSec/Subdomain-Enumaration
- foryujian/yjdirscan - 御剑目录扫描专业版,简单实用的命令行网站目录扫描工具,支持爬虫、fuzz、自定义字典、字典变量、UA修改、假404自动过滤、扫描控速等功能。
- sillydadddy/huge-list-probed-BB-subdomains - List of nearly 7 lakhs subdomains in scope probed using httpx to feed to nuclei
- random-robbie/rb-recon
- paulmillr/encrypted-dns - DNS over HTTPS config profiles for iOS & macOS
- xairy/vmware-exploitation - A collection of links related to VMware escape exploits
- facyber/awesome-networking - A collection of awesome networking courses, books, tutorials and other resources
- tprynn/web-methodology - Methodology for high-quality web application security testing - https://github.com/tprynn/web-methodology/wiki
- dark-warlord14/crt.sh-one-liner - Updated crt.sh one liner to get subdomains
- fupinglee/JavaTools - 一些Java编写的小工具。
- JavierOlmedo/UltimateCMSWordlists - 📚 An ultimate collection wordlists of the best-known CMS
- Swordfish-Security/awesome-devsecops-russia - Awesome DevSecOps на русском языке
- mxm0z/awesome-sec-s3 - A collection of awesome AWS S3 tools that collects and enumerates exposed S3 buckets
- ghsec/ghsec-jaeles-signatures - Signatures for jaeles scanner by @j3ssie
- RogueSMG/PrivEscCon-Slides - Slide Deck I presented at PrivEscCon Webinar
- gitrobtest/Java-Security - Java Security Documents
- S3cur3Th1sSh1t/Amsi-Bypass-Powershell - This repo contains some Amsi Bypass methods i found on different Blog Posts.
- 1c3z/fileleak - 又一款敏感文件泄漏检测工具
- Sajibekanti/Bug_Bounty_List - Day by day Lots of Newbie Come into bug Bounty They ask Social Site about Bug Bounty Site, So That's why I open My Hunted All Site.
- cwkiller/Pentest_Dic - 自己收集整理自用的字典
- 0xtz/Enum_For_All
- balgan/binaryedge-cheatsheet - A list of queries and actions that I repeat over and over again
- 7hang/--Java - 代码审计知识点整理-Java
- 7azabet/light-map - A light-map tool is used to hack any website affected by sql and XSS exploit,light-map has many websites there are affected by sql and XSS exploit, and it have a sqlmap tool,you can download and insta
- correlatedsecurity/Awesome-SOAR - A curated Cyber "Security Orchestration, Automation and Response (SOAR)" awesome list.
- hudunkey/Red-Team-links - 2019年红队资源链接,资源不是本人整理出来,来自互联网,因为流传的少,特意在此做个备份,做个分享。
- geffner/CVE-2020-8289 - CVE-2020-8289 – Remote Code Execution as SYSTEM/root via Backblaze
- xx-zh/xx-zh-roadmap - 中文翻译 Road Map
- al0ne/suricata-rules - Suricata IDS rules 用来检测红队渗透/恶意行为等,支持检测CobaltStrike/MSF/Empire/DNS隧道/Weevely/菜刀/冰蝎/挖矿/反弹shell/ICMP隧道等
- daffainfo/AllAboutBugBounty - All about bug bounty (bypasses, payloads, and etc)
- hackerscrolls/SecurityTips
- radareorg/awesome-radare2 - A curated list of awesome projects, articles and the other materials powered by Radare2
- Neelakandan-A/BugBounty_CheatSheet - BugBounty_CheatSheet
- lz520520/railgun
- kleiton0x00/CRLF-one-liner - A simple Bash one liner with aim to automate CRLF vulnerability scanning.
- tennc/tips - 顾名思义,收集国内外各大佬的奇淫技巧
- Litch1-v/behinder-clone - 魔改的冰蝎,仅供测试连接内存webshell使用
- zhyee/Mysql8.0_Reference_Manual_Translation - MySQL8.0官方文档中文翻译
- pikvm/pikvm - Open and inexpensive DIY IP-KVM based on Raspberry Pi
- d1nfinite/sec-interview - 信息安全面试题汇总
- s0md3v/be-a-hacker - roadmap for a self-taught hacker
- irsdl/top10webseclist - Top Ten Web Hacking Techniques List
- Virdoexhunter/HowToHunt - Some Tutorials and Things to Do while Hunting That Vulnerability.
- lazaars/SAP-Pentest
- uknowsec/SharpToolsAggressor - 内网渗透中常用的c#程序整合成cs脚本,直接内存加载。持续更新~
- imran-parray/Mind-Maps - Mind-Maps of Several Things
- Fawadkhanfk/Check-List - Check List
- bighuang624/AI-research-tools - :hammer:AI 方向好用的科研工具
- KathanP19/HowToHunt - Collection of methodology and test case for various web vulnerabilities.
- ctfwiki/ctf_game_history - CTF题目缓存(题目信息及附件),用于题目复现和学习
- 0xthirteen/StayKit - Cobalt Strike kit for Persistence
- riusksk/BDOpener - 开启APK调试与备份选项的Xposed模块
- jfmaes/Red-Route53-Interactive
- jfmaes/Red-EC2 - Spin up RedTeam infrastructure on AWS via Ansible
- cpandya2909/CVE-2020-15778
- BeichenDream/Godzilla-Plugin-Store
- zhutougg/book_notes
- knownsec/404StarLink-Project - Focus on promoting the evolution of tools in different aspects of security research.专注于推动安全研究各个领域工具化.(项目收录逐步迁移至 https://github.com/knownsec/404StarLink)
- uknowsec/Fofa-gui - Fofa采集工具-自修改版本
- kobs0N/Hacking-Cheatsheet - List of commands and techniques to while conducting any kind of hacking :)
- security-cheatsheet/wireshark-cheatsheet - Wireshark Cheat Sheet
- morph3/Windows-Red-Team-Cheat-Sheet - Windows for Red Teamers
- random-robbie/wpa-cracking - Command List for Hashcat and default keyspaces.
- DasSecurity-HatLab/BlueRepli-Plus - BlueRepli-Plus
- HenJigg/CHINA.NET- - 提供各类.NET、C#学习资料、免费图书社区
- IoT-PTv/IoT-PT - A Virtual environment for Pentesting IoT Devices
- BeichenDream/Godzilla - 哥斯拉
- hasherezade/pe-bear-releases - PE-bear (builds only)
- dwisiswant0/awesome-oneliner-bugbounty - A collection of awesome one-liner scripts especially for bug bounty tips.
- Ka0sKl0wN/ICS-Security-Study-Resources - A curated list of resources that I recommend when asked about how to learn about Industrial Control Systems Cyber Security.
- T43cr0wl3r/OSINT-RECON - Open source intelligence tools and resources
- zer0yu/Awesome-CobaltStrike - List of Awesome CobaltStrike Resources
- TideSec/TideWave - 潮涌web漏洞自动化挖掘平台——自动化扫描全网或特定范围web资产,之后获取指纹信息、爬取页面url并提炼,最后进行特定payload测试。
- Virdoexhunter/CheckLists
- mcxiaoke/RxDocs - Rx和RxJava文档中文翻译项目
- warp682/SubdomainEnumeration - All about subdomain enumeration
- antonytuff/Red-Team-Notes - OSCP guide and Red Team assessment Guide
- chaitin/rad
- welk1n/FastjsonPocs - 一些结合第三方组件的Fastjson POC,在1.2.48以后版本中陆续被添加至黑名单。
- pyn3rd/Spring-Boot-Vulnerability
- NagliNagli/OneLiners - Simple bash Oneliners to make life easier
- jas502n/DBconfigReader - 泛微ecology OA系统接口存在数据库配置信息泄露漏洞
- ossf/wg-vulnerability-disclosures - The OpenSSF Vulnerability Disclosures Working Group seeks to help improve the overall security of the open source software ecosystem by helping mature and advocate well-managed vulnerability reporting
- ossf/wg-metrics-and-metadata - The purpose of the Metrics & Metadata (formerly Identifying Security Threats) working group is to enable stakeholders to have informed confidence in the security of open source projects. We do this by
- ossf/wg-security-tooling - OpenSSF Security Tooling Working Group
- Bypass007/Learn-security-from-0 - 从0开始学安全,注重实战+技巧的运用,分享各种安全攻防干货,包括但不限于:Web安全、代码审计 、内网渗透、企业安全等。
- Accept008/ubuntu-system-local-use-k8s-minikube - ubuntu系统上本地搭建单机版的Kubernetes集群minikube(笔记)
- privacycg/storage-partitioning - Client-Side Storage Partitioning
- stylersnico/nginx-secure-config - Nginx configuration file for optimized security and performance
- bugcrowd/bugcrowd_university - Open source education content for the researcher community
- piaolin/fofa2Xray - User fofa api get hosts and xray to webscan.
- Youlor/Youpk - 又一款基于ART的主动调用的脱壳机
- 1d8/Android-Analysis - Getting Genymotion & Burpsuite setup for Android Mobile App Analysis
- SwiftOnSecurity/sysmon-config - Sysmon configuration file template with default high-quality event tracing
- ArpitKubadia/RVDP-Programs - List of domains having RVDP programmes
- ring04h/iproxy - HTTP/HTTPS proxy server by golang [high performance version]
- qiyeboy/kill_webshell_detect - 总结了免杀webshell的方法论
- ezlkc/androidtrojan
- waylau/java-trusted-code-refactoring-exam
- ibr2/pwk-cheatsheet
- loecho-sec/CobaltStrike_Script_Wechat_Push - CobatStrike-Script, Beacon上线,微信实时推送!
- Mochazz/Struts2-Vuln - 关于Struts2框架的历史漏洞个人分析文章
- sbousseaden/PCAP-ATTACK - PCAP Samples for Different Post Exploitation Techniques
- gerryguy311/Free_CyberSecurity_Professional_Development_Resources - An awesome list of FREE resources for training, conferences, speaking, labs, reading, etc that are free. Originally built during COVID-19 for cybersecurity professionals with downtime can take advanta
- bit4woo/CVE-2020-13925
- 1ndianl33t/Bugbounty-Resources - A list of resources for those interested in getting started in bug bounties inspired from https://github.com/nahamsec/Resources-for-Beginner-Bug-Bounty-Hunters
- overnote/over-golang - Golang相关:[审稿进度80%]Go语法、Go并发思想、Go与web开发、Go微服务设施等
- 1ndianl33t/Bug-Bounty-Roadmaps - Bug Bounty Roadmaps
- xdmjun/mp-unpack
- aqiongbei/buy_pig_plan - 电话攻击(电话轰炸、可代替短信轰炸)、留言攻击工具 | 已删库
- ckxpress/blockchain-sociology - 區塊鏈社會學
- redhuntlabs/Awesome-Asset-Discovery - List of Awesome Asset Discovery Resources
- jiedeidei/Safety-baseline - 安全基线检查
- blackrosezy/gui-inspect-tool - Gui Inspect tool for Windows
- EvilAnne/Violation_Pnetest - 渗透红线Checklist
- 0xricksanchez/paper_collection - Academic papers related to fuzzing, binary analysis, and exploit dev, which I want to read or have already read
- Airboi/Citrix-ADC-RCE-CVE-2020-8193 - Citrix ADC从权限绕过到RCE
- ajdumanhug/oscp-practice - A random set of 5 machines for OSCP
- alphaSeclab/awesome-webshell - Awesome webshell collection. Including 150 Github repo, and 200+ blog posts.
- alphaSeclab/fuzzing-stuff - Resources About Fuzzing, For Multiple Platforms And All Popular Fuzzers. 500+ Open Source Tools Sorted By Star Count, 800+ Blog Posts Sorted By Publish Time.
- alphaSeclab/DBI-Stuff - Resources About Dynamic Binary Instrumentation and Dynamic Binary Analysis
- alphaSeclab/shellcode-resources - Resources About Shellcode
- alphaSeclab/android-security - Android Security Resources.
- alphaSeclab/anti-av - Resources About Anti-Virus and Anti-Anti-Virus, including 200+ tools and 1300+ posts
- alphaSeclab/obfuscation-stuff - Source Code Obfuscation And Binary Obfuscation, Multiple Languages And Multiple Platforms. Including 250+ Tools and 600+ Posts
- inferjay/AndroidDevTools - 收集整理Android开发所需的Android SDK、开发中用到的工具、Android开发教程、Android设计规范,免费的设计素材等。
- Pa55w0rd/Enterprise_-Security_tools - 企业安全建设中用到的开源or“免费”的工具
- MHaggis/sysmon-dfir - Sources, configuration and how to detect evil things utilizing Microsoft Sysmon.
- rootclay/windows_protocol
- hack2fun/BypassAV - Cobalt Strike插件,用于快速生成免杀的可执行文件
- WebBreacher/osinttools - A collection of random OSINT scripts
- juguangtool/iOSConfusion - iOS混淆 iOS代码混淆 iOS过审工具 iOS上架 iOS代码混淆工具 iOS工具 iOS马甲包 iOS马甲包工具 iOS混淆 iOS过4.3 iOS过审 iOS confuse iOS code confuse iOS2.3.1解决 iOS账号调查解决办法 iOS账号调查解决 iOS账号调查过审 OC代码混淆 IOS源码混淆 OC混淆 OC代码混淆 OC过审工具 OC代码混淆工具 OC工具
- funkyoummp/FunkProxy - 流量转发工具
- StabilityMan/StabilityGuide - 【稳定大于一切】打造国内稳定性领域知识库,让无法解决的问题少一点点,让世界的确定性多一点点。
- uknowsec/loginlog_windows - 读取登录过本机的登录失败或登录成功的所有计算机信息,在内网渗透中快速定位运维管理人员。
- gomex/docker-para-desenvolvedores - Código fonte do livro Docker para desenvolvedores
- jhaddix/tbhm - The Bug Hunters Methodology
- Maskhe/javasec - 自己学习java安全的一些总结,主要是安全审计相关
- xiaoy-sec/Pentest_Note - 渗透测试常规操作记录
- threatexpress/malleable-c2 - Cobalt Strike Malleable C2 Design and Reference Guide
- iGio90/DUCKWARRIORS_Frida_Wars_1 - challenge built for first frida wars
- ignis-sec/Pwdb-Public - A collection of all the data i could extract from 1 billion leaked credentials from internet.
- FULLSHADE/WindowsExploitationResources - Resources for Windows exploit development
- starnightcyber/subDomains - 互联网公司子域名收集
- cloudflare/sslconfig - Cloudflare's Internet facing SSL configuration
- platomav/CPUMicrocodes - Intel, AMD, VIA & Freescale CPU Microcode Repositories
- wh-Cyberspace/WH-Encryptor - WH-Encryptor Android + Windows with Extra tools and Features | antivirus Bypass 99% | wh-Cyberspace
- ryan412/ADLabsReview - Active Directory Labs/exams Review
- osamahamad/CVE-2020-5410-POC - CVE-2020-5410 Spring Cloud Config directory traversal vulnerability
- dafthack/CloudPentestCheatsheets - This repository contains a collection of cheatsheets I have put together for tools related to pentesting organizations that leverage cloud providers.
- 1ndianl33t/All-in-one_BugBounty_PDF_bundles
- Paper-Pen/GatherInfo - 信息收集 OR 信息搜集
- mrnitesh/apikey
- mirfansulaiman/Command-Mobile-Penetration-Testing-Cheatsheet - Mobile penetration testing android & iOS command cheatsheet
- alphaSeclab/hooking - Resources About Hooking. For All Platforms. Currently 300+ Tools And 600+ Posts.
- taielab/Taie-RedTeam-OS - 泰阿安全实验室-基于XUbuntu私人订制的红蓝对抗渗透操作系统
- SEC-GO/Red-vs-Blue - 红蓝对抗交流心得
- kleiton0x00/CORS-one-liner - A one liner Bash command which finds CORS in every possible endpoint.
- veeral-patel/how-to-secure-anything - How to systematically secure anything: a repository about security engineering
- r00tuser111/ActuatorExploitTools - 一款用于攻击spring boot actuator的集成环境,目前集成三种攻击方式,支持1.x、2.x
- zhengjim/Chinese-Security-RSS - 网络安全资讯的RSS订阅,网络安全博客的RSS订阅,网络安全公众号的RSS订阅
- alphaSeclab/persistence - Resources About Persistence, Multiple Platforms. Including ~80 Tools and 300+ Posts.
- alphaSeclab/cobalt-strike - Resources About Cobalt Strike. 100+ Tools And 200+ Posts.
- vulnerablecodes/vuln_uris
- dark-warlord14/ffufalias - Alias for storing ffuf results
- cephurs/wildcarded-citrix-2020 - Wildcard certificates which were on vulnerable Citrix servers in 2020
- emadshanab/subs_all - Subdomain Enumeration Wordlist. 8956437 unique words. Updated.
- prakharathreya/Struts2-RCE - A Burp Extender for checking for struts 2 RCE vulnerabilities.
- jas502n/SpringBoot_Actuator_RCE - SpringBoot_Actuator_RCE
- netbiosX/Checklists - Red Teaming & Pentesting checklists for various engagements
- h0nus/MyPayloads - Just a useless set of payload created by me. Saved here for remembrance.
- ngoclesydney/Cyber-Security-for-Mobile-Platforms - The subject provides an in-depth technical overview of mobile security architectures, new security risks and threats of modern mobile platforms and operating systems. Lab tutorials provide students wi
- random-robbie/bruteforce-lists - Some files for bruteforcing certain things.
- AndyFul/ConfigureDefender - Utility for configuring Windows 10 built-in Defender antivirus settings.
- Dormidera/WordList-Compendium - Personal compilation of wordlists & dictionaries for everything. Users, passwords, directories, files, vulnerabilities, fuzzing, injections, wordlists of tools, etc.
- al0ne/Nmap_Bypass_IDS - Nmap&Zmap特征识别,绕过IDS探测
- Echocipher/Resource-list - “网址”传输助手,记载一下平时用到好的在线网址。
- vegabird/xvna - Extreme Vulnerable Node Application
- delikely/OSINT-JUMP - 开源情报收集 导航及快速跳转的油候脚本
- ctfhub-team/ctfhub_base_image - Index of CTFHub Base Images
- Mad-robot/wordpress-exploits - All known and unknown public POC's for wordpress themes and plugins
- emadshanab/LFI-Payload-List - LFI Payloads List coolected from github repos
- 1ndianl33t/Gf-Patterns - GF Paterns For (ssrf,RCE,Lfi,sqli,ssti,idor,url redirection,debug_logic, interesting Subs) parameters grep
- JHUAPL/Beat-the-Machine - Reverse engineering basics in puzzle form
- vuepress/awesome-vuepress - 🎉 A curated list of awesome things related to VuePress
- dyweb/papers-notebook - :page_facing_up: :cn: :page_with_curl: 论文阅读笔记(分布式系统、虚拟化、机器学习)Papers Notebook (Distributed System, Virtualization, Machine Learning)
- BullsEye0/google_dork_list - Google Dorks | Google helps you to find Vulnerable Websites that Indexed in Google Search Results. Here is the latest collection of Google Dorks. A collection of 13.760 Dorks. Author: Jolanda de Koff
- iGotRootSRC/Dorkers - Dorks for Google, Shodan and BinaryEdge
- tunz/js-vuln-db - A collection of JavaScript engine CVEs with PoCs
- latestalexey/awesome-web-hacking - A list of web application security
- wyzxxz/shiro_rce_tool - shiro 反序列 命令执行辅助检测工具
- S1ckB0y1337/Active-Directory-Exploitation-Cheat-Sheet - A cheat sheet that contains common enumeration and attack methods for Windows Active Directory.
- jdonsec/AllThingsAndroid - A Collection of Android Pentest Learning Materials
- sundowndev/hacker-roadmap - A collection of hacking tools, resources and references to practice ethical hacking.
- TrojanAZhen/BurpSuitePro-2.1 - 什么? 你想用免费的BurpSuitePro版本!!!
- master3values/Attack-Cloud - Att&ck Cloud相关
- argowang/cyber-security-roadmap - A roadmap for learning cyber-security
- euphrat1ca/CVE-2020-0618 - SQL Server Reporting Services(CVE-2020-0618)中的RCE
- riramar/Web-Attack-Cheat-Sheet - Web Attack Cheat Sheet
- u-u-z/information-security-for-everyone - 写给大家看的信息安全手册
- mingcheng/deploy-k8s-within-aliyun-mirror - 使用阿里云镜像快速部署 Kubernetes 集群
- xuedingmiaojun/wxappUnpacker
- plenumlab/GQL-Helper - This is a small extension to make graphql readable
- yangchong211/YCBlogs - 技术博客笔记大汇总,包括Java基础,线程,并发,数据结构;Android技术博客等等;常用设计模式;常见的算法;网络协议知识点;部分flutter笔记;还包括平时开发中遇到的bug汇总,当然也在工作之余收集了大量的面试题,长期更新维护并且修正,持续完善……开源的文件是markdown格式的!转载请注明出处,谢谢!
- aquasecurity/vuln-list - NVD, Ubuntu, Alpine
- we1h0/awesome-java-security-checklist - awesome-java-security-checklist(关于Java安全方面,Java基础/审计/修复/设计/规范)
- qxl1231/2019-k8s-centos - 2019最新k8s集群搭建教程(centos/ubuntu)
- dsopas/assessment-mindset - Security Mindmap that could be useful for the infosec community when doing pentest, bug bounty or red-team assessments.
- six2dez/OSCP-Human-Guide - My own OSCP guide
- streaak/keyhacks - Keyhacks is a repository which shows quick ways in which API keys leaked by a bug bounty program can be checked to see if they're valid.
- Snowming04/CobaltStrike4.0_related - 破解的cs4.0、cs4.0官方手册翻译和一些笔记
- sushiwushi/bug-bounty-dorks - List of Google Dorks for sites that have responsible disclosure program / bug bounty program
- 1-2-3/hhkb_ydkb - HHKB 键盘 + YDKB 主控 = 完美键盘
- YasserGersy/cazador_unr - Hacking tools
- WooyunDota/DroidDrops - 梳理下自己之前写过的文章
- hereappdev/Here-Plugins - Plugins for Here App 🚀
- tianshanghong/awesome-anki - A curated list of awesome Anki add-ons, decks and resources
- nomi-sec/PoC-in-GitHub - 📡 PoC auto collect from GitHub. ⚠️ Be careful Malware.
- inonshk/31-days-of-API-Security-Tips - This challenge is Inon Shkedy's 31 days API Security Tips.
- wooyunwang/Fortify - 源代码漏洞の审计
- renzu0/nw-tips - win内网_域控安全
- proudwind/javasec_study - java代码审计学习笔记
- randorisec/MobileHackingCheatSheet - Basics on commands/tools/info on how to assess the security of mobile applications
- vaib25vicky/awesome-mobile-security - An effort to build a single place for all useful android and iOS security related stuff. All references and tools belong to their respective owners. I'm just maintaining it.
- randomuserid/Adama - Searches For Threat Hunting and Security Analytics
- rShetty/awesome-podcasts - Collection of awesome podcasts
- alphaSeclab/windows-security - Resources About Windows Security. 1100+ Open Source Tools. 3300+ Blog Post and Videos.
- alphaSeclab/all-my-collection-repos - All Security Resource Collections Repos That I Published.
- alphaSeclab/awesome-security-collection - 1000+ Github Security Resource Collection Repos.
- sv3nbeast/CVE-2019-1388 - guest→system(UAC手动提权)
- bh1xuw/mca-administrative - 中华人民共和国民政部全国行政区划信息。topojson/geojson格式,至县一级。
- sehno/Bug-bounty - Ressources for bug bounty hunting
- xiaolai/zuoxiangqicheng - 坐享其成——最简单的大脑锻炼方式
- zjdx1998/seucourseshare - 东南大学课程共享计划
- S3cur3Th1sSh1t/Pentest-Tools
- xinali/articles - Personal Blog/主记录漏洞挖掘相关研究(文章位于issues)
- nobleXu/jenkins - jenkins payload
- we1h0/redteam-tips - 关于红队方面的学习资料
- hackergrrl/art-of-readme - :love_letter: Things I've learned about writing good READMEs.
- Mochazz/ThinkPHP-Vuln - 关于ThinkPHP框架的历史漏洞分析集合
- robertdebock/ansible-role-dsvpn - Install and configure DSVPN on your system.
- dosec-cn/harbor-scanner - 一个免费的镜像漏洞扫描工具, 可以扫描镜像中已安装软件包的漏洞,支持中文漏洞库,可与 Harbor 无缝集成。
- slowmist/Ontology-Triones-Service-Node-security-checklist - Ontology Triones Service Node security checklist(本体北斗共识集群安全执行指南)
- slowmist/vechain-core-nodes-security-checklist - VeChain core nodes security checklist(唯链核心节点安全执行指南)
- slowmist/eos-bp-nodes-security-checklist - EOS bp nodes security checklist(EOS超级节点安全执行指南)
- 7kbstorm/smb_version_threadpool - 于几年前二次开发自 http://www.zcgonvh.com/post/CSharp_smb_version_Detection.html
- wisdom-projects/holer - Holer exposes local servers behind NATs and firewalls to the public internet over secure tunnels.
- sk3ptre/AndroidMalware_2019 - Popular Android threats in 2019
- alphaSeclab/awesome-burp-suite - Awesome Burp Suite Resources. 400+ open source Burp plugins, 400+ posts and videos.
- dackh/blog - ...
- jakejarvis/awesome-shodan-queries - 🔍 A collection of interesting, funny, and depressing search queries to plug into shodan.io 👩💻
- alphaSeclab/awesome-honeypot - Awesome Honeypot Resource Collection. Including 250+ Honeypot tools, and 350+ posts about Honeypot.
- shadow-horse/CVE-2019-17571 - Apache Log4j 1.2.X存在反序列化远程代码执行漏洞
- SecurityRiskAdvisors/VECTR - VECTR is a tool that facilitates tracking of your red and blue team testing activities to measure detection and prevention capabilities across different attack scenarios
- ReDTunnel/redtunnel
- alphaSeclab/awesome-forensics - Awesome Forensics Resources. Almost 300 open source forensics tools, and 600 blog posts about forensics.
- alphaSeclab/awesome-rat - RAT And C&C Resources. 250+ Open Source Projects, 1200+ RAT/C&C blog/video.
- dgryski/go-perfbook - Thoughts on Go performance optimization
- ripperhe/Bob - Bob 是一款 macOS 平台的翻译和 OCR 软件。
- l3m0n/WebFuzzAttack - web模糊测试 - 将漏洞可能性放大
- alphaSeclab/awesome-cyber-security - [Draft]Awesome Cyber Security Resource Collection. Currently contains 8000+ open source repositories, and not very well classified. For each repository, extra info included: star count, commit count,
- twelvesec/BearerAuthToken - This burpsuite extender provides a solution on testing Enterprise applications that involve security Authorization tokens into every HTTP requests.Furthermore, this solution provides a better approach
- nahamsec/Resources-for-Beginner-Bug-Bounty-Hunters - A list of resources for those interested in getting started in bug bounties
- 8enet/Charles-Crack - Removed according to DMCA.
- rizinorg/cutter-plugins - A curated list of Community Plugins and Scripts written for Cutter
- felixgr/secure-ios-app-dev - Collection of the most common vulnerabilities found in iOS applications
- 0xmachos/iOS-Security-Guides - Every iOS security guide
- indrarahul/d4rkc0de-Android-CTF - d4rkc0de Android CTF
- DataMaster-2501/DataMaster-Android-AdBlock-Hosts - Android AdBlock Hosts file for /etc/hosts
- XecLabs/Mobile - The repo hold all our (mobile security) & applications reports.
- enciphers-team/Mobexler
- psychsecurity/iOS-Pentesting - Wiki for Pentesting iOS apps
- ansjdnakjdnajkd/iOS - Most usable tools for iOS penetration testing
- xsleaks/xsleaks - A collection of browser-based side channel attack vectors.
- timip/OSWE - OSWE Preparation
- M507/AWAE-Preparation - This repository will contain all trainings and tutorials I have done/read to prepare for OSWE / AWAE.
- chicharitomu14/Android-Security-Notes-personal - 个人整理的Android安全学习笔记
- iwannabetop/Awesome-Android-Learning-Guide - 一份系统、全面的安卓进阶学习指南(更新中)
- pwstrick/daily - 一份搜集的前端面试题目清单、面试相关以及各类学习的资料(不局限于前端)
- alphaSeclab/sec-tool-list - More than 21K security related open source tools, sorted by star count. Both in markdown and json format.
- RASSec/ssrf-video-ffmpeg
- seecode-audit/seecode-audit - Distributed white box code scanning tool
- andrews1022/web-development-course-list - A list of Udemy courses from Brad Traversy's Web Development 2021 video
- alphaSeclab/awesome-reverse-engineering - Reverse Engineering Resources About All Platforms(Windows/Linux/macOS/Android/iOS/IoT) And Every Aspect! (More than 3500 open source tools and 2300 posts&videos)
- tangsilian/My-Github-Stars - My Github Stars
- fr0gger/awesome-ida-x64-olly-plugin - A curated list of IDA x64DBG, Ghidra and OllyDBG plugins.
- XIU2/TrackersListCollection - 🎈 Updated daily! A list of popular BitTorrent Trackers! / 每天更新!全网热门 BT Tracker 列表!
- basketwill/Z0BPcTools - 一个windows反汇编工具,界面风格防OllyDbg 利用业余开发了一款类似仿OLlyDbg界面的 IDA静态反编译工具,目前是1.0版本,功能不是很强大但是基本功能有了
- jobbole/awesome-go-cn - Go 资源大全中文版, 内容包括:Web框架、模板引擎、表单、身份认证、数据库、ORM框架、图片处理、文本处理、自然语言处理、机器学习、日志、代码分析、教程和(电子)书等。由「开源前哨」和「Go开发大全」微信团队维护。
- wyzxxz/jndi_tool - JNDI服务利用工具 RMI/LDAP,支持部分场景回显、内存shell,高版本JDK场景下利用等,fastjson rce命令执行,log4j rce命令执行 漏洞检测辅助工具
- ivRodriguezCA/RE-iOS-Apps - A completely free, open source and online course about Reverse Engineering iOS Applications.
- npubird/KnowledgeGraphCourse - 东南大学《知识图谱》研究生课程
- gozelus/iOSReview - 常见iOS面试中考察的知识点整理
- payloadbox/sql-injection-payload-list - 🎯 SQL Injection Payload List
- niezhiyang/open_source_team - 国内顶尖团队的开源地址
- jaegeral/security-apis - A collective list of public APIs for use in security. Contributions welcome
- dweinstein/awesome-frida - Awesome Frida - A curated list of Frida resources http://www.frida.re/ (https://github.com/frida/frida)
- veracode-research/solr-injection - Apache Solr Injection Research
- ffffffff0x/Digital-Privacy - Information Protection & OSINT resources | 一个关于数字隐私搜集、保护、清理集一体的方案,外加开源信息收集(OSINT)对抗
- yifeikong/reverse-interview-zh - 技术面试最后反问面试官的话
- jobbole/awesome-sysadmin-cn - 系统管理员资源大全中文版,备份/克隆软件、云计算/云存储、协作软件、配置管理、日志管理、监控、项目管理等
- hacklcx/HFish - 安全、可靠、简单、免费的企业级蜜罐
- Leezj9671/offensiveinterview - 翻译国外的@WebBreacher的安全/渗透测试/红队面试题,有部分参考作用
- olafhartong/ThreatHunting - A Splunk app mapped to MITRE ATT&CK to guide your threat hunts
- qingshuisiyuan/electron-ssr-backup - electron-ssr原作者删除了这个伟大的项目,故备份了下来,不继续开发,且用且珍惜
- the-champions-of-capua/pen-tool - 渗透工具使用教程,结合 vulhub, dvwa, metasploitable3 等靶场使用, 涵盖工具有菜刀,msf, sqlmap 等等。
- Raikia/Recon-NG-API-Key-Creation - One of the biggest annoyances of using Recon-ng is getting everything set up to use it. So here I’ll outline the different API keys it can use and where to get them yourself.
- qianguyihao/Mac-list - Mac软件清单、Mac使用技巧整理,正在不断完善中。努力做到最全。
- ffffffff0x/Dork-Admin - 盘点近年来的数据泄露、供应链污染事件
- joshuah345/linux-dotfiles - I configure lots of things, sorting them out here
- chenzhao2013/Translation-For-IoT-Penetration-Testing-Cookbook - 学习物联网渗透测试技术时,在Google上查到的一本英文书。看国内还未有该领域的书籍,因此将其翻译提供更多的同学学习。若有侵权,请联系删除。
- piglei/one-python-craftsman - 来自一位 Pythonista 的编程经验分享,内容涵盖编码技巧、最佳实践与思维模式等方面。
- Puuoi/SS-R-4in1 - 由于秋水逸冰网站国内无法访问,所以为有需要的朋友复制发布到github
- Quorafind/golang-developer-roadmap-cn - 在 2019 成为一名 Go 开发者的路线图。为学习 Go 的人而准备。
- hblvsjtu/StockTradingSignalSystem - 著名的投资大师巴菲特说"我始终知道我会富有",一开始我也想成为像巴同学那样的价值投资者,后来我发现价值投资在中国A股里面是走不通的,趋势投资才是王道。刚学投资的小白,想站在前人的基础上,开发基金股票买卖信号体系,在不浪费太多精力的同时获取超额收益,我知道我也终将富有^_ ^
- jiansiting/Decryption-Tools - Decryption-Tools
- xdd666t/MyData - 相关资料存放,noval为阅读书源,pic为Github图床
- 3had0w/Fuzzing-Dicts - Web Security Dictionary
- tiaotiaolong/sec_interview_know_list - 信息安全方面面试清单
- Smi1eSEC/Web-Security-Note - Record some common Web security sites
- yzddmr6/webshell-venom - 免杀webshell无限生成工具
- DrXie/OSFCC - 一个收集可用于中文字体排印的开源字体集合。
- nusr/hacker-laws-zh - 💻📖对开发人员有用的定律、理论、原则和模式。(Laws, Theories, Principles and Patterns that developers will find useful.)
- qdlaoyao/js-book - 《JavaScript 迷你书》,全面夯实基础
- infosecn1nja/Red-Teaming-Toolkit - This repository contains cutting-edge open-source security tools (OST) for a red teamer and threat hunter.
- aleenzz/MSSQL_SQL_BYPASS_WIKI - MSSQL注入提权,bypass的一些总结
- xiangbab/web-hack - 一份网络安全入门的资料。
- nusr/awesome-macos-command-line-zh - 用你的 macOS 终端搞事情。(Use your macOS terminal shell to do awesome things. )
- yeyintminthuhtut/Awesome-Advanced-Windows-Exploitation-References - List of Awesome Advanced Windows Exploitation References
- zhangyongcun/OpenCore-EFI
- Lucifer1993/cmsprint - CMS和中间件指纹库
- wsgzao/autoinstall - Autoinst索引
- ConnerLambdaAccount/T430-EFI - Hackintosh Install Tutorial for Lenovo Thinkpad T430
- lis912/Information-security-reinforcement-scheme - 等级保护安全加固方案
- coralfox/Confluence-Plugin-CN - 这是Confluence 插件Questions For Confluence的简体中文汉化文件
- euphrat1ca/Security-List - If you have any good suggestions or comments during the search process, please feedback some index experience in issues. Thank you for your participation.查阅过程中,如果有什么好的意见或建议,请在Issues反馈,感谢您的参与。
- chryzsh/DarthSidious - Building an Active Directory domain and hacking it
- we1h0/web-sec-interview - Information Security (Web Security/Penetration Testing Direction) Interview Questions/Solutions 信息安全(Web安全/渗透测试方向)面试题/解题思路
- visualbasic6/chatter - internet monitoring osint telegram bot for windows
- FeeiCN/SecurityInterviewGuide - 网络信息安全从业者面试指南
- ruanyf/document-style-guide - 中文技术文档的写作规范
- thanksdanny/tester-resource - 测试技术资源
- iBreaker/bjguahao - 北京市预约挂号统一平台挂号小助手
- hq450/fancyss_history_package - 科学上网插件的离线安装包储存在这里
- SkyBlueEternal/CVE-2018-1335-EXP-GUI - GUI版 EXP
- milabs/awesome-linux-rootkits - awesome-linux-rootkits
- yeyintminthuhtut/Awesome-Red-Teaming - List of Awesome Red Teaming Resources
- ngalongc/bug-bounty-reference - Inspired by https://github.com/djadmin/awesome-bug-bounty, a list of bug bounty write-up that is categorized by the bug nature
- infosecn1nja/AD-Attack-Defense - Attack and defend active directory using modern post exploitation adversary tradecraft activity
- yurii-yu/chitchat-on-translation - 翻译漫谈——我的翻译经验总结
- FunnyKun/NessusReportInChinese - 半自动化将 Nessus 英文报告(csv格式)生成中文 excel ,中文漏洞库已有700多条常见漏洞,后续再进一步加上新漏洞自动翻译,实现全自动化
- WebBreacher/orcs - OSINT Resource Classification System
- yangliang1415/awesome-risk-control - 风控知识总结
- 553899811/Java-Programmer-Advancement-Program - 📚 Java 技术体系进阶指南 ,总结职场经验及感悟,积累技术面试
- security-cheatsheet/reverse-shell-cheatsheet - 🙃 Reverse Shell Cheat Sheet 🙃
- LingCoder/OnJava8 - 《On Java 8》中文版
- enkomio/Taipan - Web application vulnerability scanner
- wtsxDev/Penetration-Testing - List of awesome penetration testing resources, tools and other shiny things
- clxering/Effective-Java-3rd-edition-Chinese-English-bilingual - Effective Java(第3版)各章节的中英文学习参考(已完成)
- exitmsconfig/engineering-Box - engineering Box (简称 - engineering) 是一个集合github平台上的安全行业从业者自研开源扫描器的仓库,包括子域名枚举、数据库漏洞扫描、弱口令或信息泄漏扫描、端口扫描、指纹识别以及其他大型扫描器或模块化扫描器,同时该仓库只收录各位安全行业从业者自己编写的一般性开源扫描器,类似awvs、nmap、w3af等知名扫描工具不收录,收集全球各位同仁爱好者维护项目
- Aptive/penetration-testing-tools - Penetration Testing tools - one repo to clone them all... containing latest pen testing tools
- thedaviddias/Front-End-Checklist - 🗂 The perfect Front-End Checklist for modern websites and meticulous developers
- hannoch/scaner - 扫描器是来自GitHub平台的开源扫描器的集合,包括子域枚举、数据库漏洞扫描器、弱密码或信息泄漏扫描器、端口扫描器、指纹扫描器以及其他大规模扫描仪、模块扫描器等。对于其他著名的扫描工具,如:awvs、nmap,w3af将不包含在集合范围内。
- payloadbox/xss-payload-list - 🎯 Cross Site Scripting ( XSS ) Vulnerability Payload List
- trimstray/the-practical-linux-hardening-guide - This guide details creating a secure Linux production system. OpenSCAP (C2S/CIS, STIG).
- hongriSec/AI-Machine-Learning-Security - 一个关于人工智能渗透测试分析系列
- guardrailsio/awesome-python-security - Awesome Python Security resources 🕶🐍🔐
- pe3zx/my-infosec-awesome - My curated list of awesome links, resources and tools on infosec related topics
- ityouknow/awesome-spring-boot - Spring Boot Resources
- leng-yue/Lengyue-Vcode - Project Stopped
- naototty/awesome-el-yum-repository-additional - awesome EL(centos,redhat) additional yum repository
- Ivan1ee/NET-Deserialize - 总结了20+.Net反序列化文章,持续更新
- tigercandy/go-read-recommend - :fire: 让阅读变成一件有意义的事。Golang好文推荐;收录平时阅读到的一些Go相关写的比较好、质量较高的干货文章.
- lyz8jj0/mapSource - java基础思维导图(还有mybatis,spring)
- 0xMJ/AI-Security-Learning - 自身学习的安全数据科学和算法的学习资料
- Binject/awesome-go-security - A dedicated place for cool golang security projects
- upan/cheat-sheet - 常用工具和开源项目链接收藏
- snoopysecurity/awesome-burp-extensions - A curated list of amazingly awesome Burp Extensions
- imthenachoman/How-To-Secure-A-Linux-Server - An evolving how-to guide for securing a Linux server.
- TideSec/Tide - 目前实现了网络空间资产探测、指纹检索、漏洞检测、漏洞全生命周期管理、poc定向检测、暗链检测、挂马监测、敏感字检测、DNS监测、网站可用性监测、漏洞库管理、安全预警等等~
- Ridter/Intranet_Penetration_Tips - 2018年初整理的一些内网渗透TIPS,后面更新的慢,所以整理出来希望跟小伙伴们一起更新维护~
- NewBee119/threat-intelligence - 收集的一些国外能提供提供威胁情报的公司,涵盖网络安全、工控安全、终端安全、移动安全等领域
- WalterInSH/risk-management-note - 🧯风险控制笔记,适用于互联网企业
- yujiangshui/A-Programmers-Guide-to-English - 专为程序员编写的英语学习指南 v1.2。在线版本请点 ->
- carpeventus/Interview-Notes - 秋招面试总结
- GitHubDaily/GitHubDaily - 坚持分享 GitHub 上高质量、有趣实用的开源技术教程、开发者工具、编程网站、技术资讯。A list cool, interesting projects of GitHub.
- cvkki/src - 日常src平台域名收集
- AV1080p/Hacking-With-Golang - Golang安全资源合集
- FEGuideTeam/FEGuide - 【前端面试题+前端学习+面试指南】 一份涵盖大部分前端工程师所需要掌握的核心知识。这个项目就是为了帮助那些找工作的前端开发工程师去回顾前端的基础知识,如果你不想找工作,也可以通过查看这些面试问题去巩固你的前端技能。
- Fndroid/clash_for_windows_pkg - A Windows/macOS GUI based on Clash
- T3st0r-Git/hack_postgres - 便捷地使用PostgreSQL自定义函数来执行系统命令,适用于数据库管理员知道postgres密码却不知道ssh或RDP密码的时候在服务器执行系统命令。
- bloodzer0/ossa - Open-Source Security Architecture | 开源安全架构
- nailperry-zd/The-Economist - The Economist 经济学人,持续更新
- guobinhit/intellij-idea-tutorial - 🌻 This is a tutorial of IntelliJ IDEA, you can know how to use IntelliJ IDEA better and better.
- rebeyond/Behinder - “冰蝎”动态二进制加密网站管理客户端
- SFLAQiu/web-develop - :seedling:《大话WEB开发》WEB开发相关经验总结分享
- enochtangg/quick-SQL-cheatsheet - A quick reminder of all SQL queries and examples on how to use them.
- xiaohuilam/laravel - Laravel 深入详解 —— 源代码解析,新手进阶指南
- Boreas813/Burp-Suite-2.0-chinese-document - 中文版burp2.0官方文档
- sjsdfg/CS-Notes-PDF - https://github.com/CyC2018/CS-Notes PDF版本离线阅读
- opendigg/awesome-github-vue - Vue相关开源项目库汇总
- EZLippi/practical-programming-books - 这里收录比较实用的计算机相关技术书籍,可以在短期之内入门的简单实用教程、一些技术网站以及一些写的比较好的博文,欢迎Fork,你也可以通过Pull Request参与编辑。
- 233boy/chinaip - 中国大陆 IP 列表(已优化)
- PansonPanson/Java-Notes - :books: 计算机科学基础知识、Java开发、后端/服务端、面试相关 :books: computer-science/Java-development/backend/interview
- technicaldada/BEST-HACKING-TOOLS - BEST HACKING TOOLS..For more tools visit our blog for Hackers
- leelikar/DeepWeb - 暗网网址大全TOR
- EarsEyesMouth/computerese-cross-references - 计算机专业术语中英文对照。
- slowmistio/2018-BlackHat-Tools-List - 2018 BlackHat Tools List
- luong-komorebi/Begin-Latex-in-minutes - 📜 Brief Intro to LaTeX for beginners that helps you use LaTeX with ease.
- songtianyi/landscape-of-programming - This repo aim to show you what to learn on the way to excellence.
- trimstray/iptables-essentials - Iptables Essentials: Common Firewall Rules and Commands.
- trimstray/the-book-of-secret-knowledge - A collection of inspiring lists, manuals, cheatsheets, blogs, hacks, one-liners, cli/web tools and more.
- spoock1024/web-security - Web安全中比较好的文章
- mdrights/antiG - Yet another live OS to resist Surveillance/Censorship and to protect digital privacy.
- SuJunming/mac-awesomeTools - mac常用软件等等,有你需要的!
- NtrQQ/download
- resumejob/awesome-resume - Resume,Resume Templates,程序员简历例句,简历模版,
- LandGrey/upload-labs-writeup - upload-labs writeup
- telegramlist/telegramlist - Telegram中文群索引列表(言论自由版)
- laylalaisy/TOEFL_laylalaisy - 备考托福的一丢丢经验+资料~祝小可爱和大佬们都早日和托福大魔王分手(o゜▽゜)o☆
- wangbjun/ubuntu-unity-setup - Ubuntu unity桌面的一些优化设置以及常用软件,完全使用Ubuntu作为日常生活工作系统攻略。
- dily3825002/awesome-blockchain - 区块链白皮书、书籍、交易所、币种、自媒体等资源汇总 💯
- cerebroapp/awesome-cerebro - Curated list of Cerebro plugins and resources
- sie504/Struts-S2-xxx - 整理收集Struts2漏洞环境
- Kutim/docker-security - docker 安全基线规范
- xitu/gold-miner - 🥇掘金翻译计划,可能是世界最大最好的英译中技术社区,最懂读者和译者的翻译平台:
- jobbole/awesome-javascript-cn - JavaScript 资源大全中文版,内容包括:包管理器、加载器、测试框架、运行器、QA、MVC框架和库、模板引擎等。由「开源前哨」和「前端大全」微信公号团队维护更新。
- renkun-ken/MacType.Decency - A MacType profile that provides decent solution to font rendering and font substitutions for Windows operating systems.
- xingshaocheng/architect-awesome - 后端架构师技术图谱
- ihtml5/50weekly - 50weekly 发现高质量的前端资源
- SwiftOldDriver/iOS-Weekly - 🇨🇳 老司机技术 iOS 周报
- sp4rkw/Cyberspace_Security_Learning - 在学习CTF、网络安全路上整合自己博客和一些资料,持续更新~
- zer0yu/CyberSecurityRSS - CyberSecurityRSS: A collection of cybersecurity rss to make you better!
- 1c7/chinese-independent-developer - 👩🏿💻👨🏾💻👩🏼💻👨🏽💻👩🏻💻中国独立开发者项目列表 -- 分享大家都在做什么
- dzharii/awesome-elasticsearch - A curated list of the most important and useful resources about elasticsearch: articles, videos, blogs, tips and tricks, use cases. All about Elasticsearch!
- l3m0n/linux_information - 自动化收集linux信息
- ohmyarch/fontconfig-zh-cn
- pengshp/rpi3-package - RaspberryPi3 with Raspbian
- upyun/upyun-resty - UPYUN's open source software for OpenResty development
- redhuntlabs/RedHunt-OS - Virtual Machine for Adversary Emulation and Threat Hunting
- ccloli/developer-roadmap-zh-CN - 在 2020 年成为 Web 开发工程师之路线图 | Roadmap to becoming a web developer in 2020
- goodjack/developer-roadmap-chinese - 2021 年成為 Web 開發人員的路線圖 台灣正體中文版
- CyC2018/CS-Notes - :books: 技术面试必备基础知识、Leetcode、计算机操作系统、计算机网络、系统设计
- Ridter/CS_Chinese_support - Cobalt strike 修改支持回显中文。
- Roave/SecurityAdvisories - :closed_lock_with_key: Security advisories as a simple composer exclusion list, updated daily
- hylinux1024/awesome-blockchain-articles - A collection of awesome blockchain articles. Good learning resources about blockchain.
- neoFelhz/various_domain_list - A various list of domain
- soulteary/tenant-point - 租房要点,适用于北上广深杭,欢迎补充。
- lmy375/awesome-vmp - 虚拟化保护(VMP壳)分析相关资料
- riusksk/secbook - 信息安全从业者书单推荐
- Dukewill/DaiseaX - 戴西之海 - 先进数字集群:技术作者自留地
- monklof/Back-End-Developer-Interview-Questions - 后端开发面试题,翻译自 https://github.com/arialdomartini/Back-End-Developer-Interview-Questions
- nanqinlang-mogic/v2ray - template with websocket+tls+nginx of v2ray
- swim2sun/spring-reference-docset - Spring Reference Documentation docset for Dash
- 521xueweihan/git-tips - :trollface:Git的奇技淫巧
- vysecurity/DomainFrontingLists - A list of Domain Frontable Domains by CDN
- evilsocket/bleah - This repository is DEPRECATED, please use bettercap as this tool has been ported to its BLE modules.
- enaqx/awesome-pentest - A collection of awesome penetration testing resources, tools and other shiny things
- Schm1tz1/awesome-rtl-sdr - Software (meta-)package for RTL-SDR with some additional scripts and installers
- guanchao/AndroidChecklist - Android应用审计checklist整理
- kbandla/APTnotes - Various public documents, whitepapers and articles about APT campaigns
- bit4woo/python_sec - python安全和代码审计相关资料收集 resource collection of python security and code review
- postlight/awesome-cms - 📚 A collection of open and closed source Content Management Systems (CMS) for your perusal.
- Gracker/Rss-IT - 这个项目记录了个人订阅的一些科技人的Blog地址,欢迎大家推荐,一起来完善! 欢迎自荐......
- HD421/Monitoring-Systems-Cheat-Sheet - A cheat sheet for pentesters and researchers about vulnerabilities in well-known monitoring systems.
- kai5263499/osx-security-awesome - A collection of OSX and iOS security resources
- tanprathan/MobileApp-Pentest-Cheatsheet - The Mobile App Pentest cheat sheet was created to provide concise collection of high value information on specific mobile application penetration testing topics.
- 0x4D31/awesome-threat-detection - ✨ A curated list of awesome threat detection and hunting resources 🕵️♂️
- Tim9Liu9/TimLiu-iOS - iOS开发常用三方库、插件、知名博客等等
- dat-ecosystem-archive/awesome-dat - Community curated resources for Dat Project [ DEPRECATED - More info on active projects and modules at https://dat-ecosystem.org/ ]
- ethereum/pyethereum - Next generation cryptocurrency network
- linonetwo/neo4j-tutorial-Chinese - 学图论数据库 Neo4j 的时候顺手翻译了它的在线课程
- ColorfulCat/AndroidLibs - :fire:正在成为史上最全分类 Android 开源大全~~~~(长期更新 Star 一下吧)
- Z4HD/coolq-telegram-bot-docker - 使用Docker容器化的QQ和Telegram的消息互转机器人。Source: jqqqqqqqqqq/coolq-telegram-bot
- marcan/speculation-bugs - Docs and resources on CPU Speculative Execution bugs
- l3m0n/pentest_study - 从零开始内网渗透学习
- l3m0n/XSS-Filter-Evasion-Cheat-Sheet-CN - XSS_Filter_Evasion_Cheat_Sheet 中文版
- hzlzh/Best-App - 收集&推荐优秀的 Apps/硬件/技巧/周边等
- aceimnorstuvwxz/awesome-chatbot-list - 深度学习聊天机器人资源集合 Awesome chatbot resource list
- abdelhai/awesome-bots - Awesome Links about bots.
- MiYogurt/network-security-mind-map - ☯️ 网络安全基础知识思维导图、大学笔记(Network security Mind Map)
- nebgnahz/awesome-iot-hacks - A Collection of Hacks in IoT Space so that we can address them (hopefully).
- madneal/articles-translator - :books:Translate the distinct technical blogs. Please star or watch. Welcome to join me.
- arkadiyt/bounty-targets-data - This repo contains hourly-updated data dumps of bug bounty platform scopes (like Hackerone/Bugcrowd/Intigriti/etc) that are eligible for reports
- vah13/OracleCVE - Vulnerabilities which found in Oracle products
- SangKa/PWA-Book-CN - 第一本 PWA 中文书
- IamHDT/Ecommerce-Website-Security-CheckList - List of considerations for commerce site auditing and security teams. This is summary of action points and areas that need to be built into the Techinical Specific Document, or will be checked in the
- tuteng/Best-websites-a-programmer-should-visit-zh - 程序员应该访问的最佳网站中文版
- tom0li/collection-document - Collection of quality safety articles. Awesome articles.
- onlurking/awesome-infosec - A curated list of awesome infosec courses and training resources.
- onethawt/reverseengineering-reading-list - A list of Reverse Engineering articles, books, and papers
- stamparm/ipsum - Daily feed of bad IPs (with blacklist hit scores)
- zbetcheckin/Security_list - Great security list for fun and profit
- googlehosts/hosts - 镜像:https://scaffrey.coding.net/p/hosts/git / https://git.qvq.network/googlehosts/hosts
- jhaddix/pentest-bookmarks - a collection of handy bookmarks
- vitalysim/Awesome-Hacking-Resources - A collection of hacking / penetration testing resources to make you better!
- Debian/raspi3-image-spec - contains the files to build the https://wiki.debian.org/RaspberryPi3 image
- skywalker512/FlarumChina - Flarum 中文优化版
- dataplane/serverhosting - Dataplane.org server hosting providers
- hangyan/docker-resources - Docker resources collection. docker资源汇总
- DieterReuter/workshop-raspberrypi-64bit-os - Workshop to build a 64bit Docker OS for the Raspberry Pi 3
- Kivy-CN/GlumPy-CN - A Chinese Translation of GlumPy Documents 中文翻译GlumPy文档
- tylerha97/awesome-reversing - A curated list of awesome reversing resources
- missdeer/avege - Yet Another Redsocks Golang Fork
- Hack-with-Github/Awesome-Security-Gists - A collection of various GitHub gists for hackers, pentesters and security researchers
- LJ147/Awesome-WeChat - 技术型干货分享公众号集合,点击公众号链接即可扫描快速二维码。
- nikitavoloboev/my-mac - List of applications and tools that make my macOS experience even more amazing
- coderzh/alfred-workflows
- waylau/spring-cloud-tutorial - Spring Cloud Tutorial.《Spring Cloud 教程》
- gongzisun/cnretroshare - RetroShare中文介绍、FAQ、教程
- wahyd4/aria2-ariang-x-docker-compose - Docker compose files for Aria2+ AriaNg+ filerun/ Nextcloud/ h5ai + Plex. 图形化BT,磁力,离线下载,文件管理,播放,投屏
- toolswatch/blackhat-arsenal-tools - Official Black Hat Arsenal Security Tools Repository
- jobbole/awesome-java-cn - Java资源大全中文版,包括开发库、开发工具、网站、博客、微信、微博等,由伯乐在线持续更新。
- jmpews/pwn2exploit - all mine papers, pwn & exploit
- GrrrDog/Java-Deserialization-Cheat-Sheet - The cheat sheet about Java Deserialization vulnerabilities
- onethawt/idaplugins-list - A list of IDA Plugins
- codingWang/LoveImageMore - 各种技能树/图的收集整理
- EdOverflow/bugbounty-cheatsheet - A list of interesting payloads, tips and tricks for bug bounty hunters.
- kahun/awesome-sysadmin - A curated list of amazingly awesome open source sysadmin resources inspired by Awesome PHP.
- geeeeeeeeek/git-recipes - 🥡 Git recipes in Chinese by Zhongyi Tong. 高质量的Git中文教程.
- 17mon/china_ip_list
- 3gstudent/CVE-2017-8464-EXP - Support x86 and x64
- ngosang/trackerslist - Updated list of public BitTorrent trackers
- wizardforcel/web-hacking-101-zh - :book: [译] Web Hacking 101 中文版
- sergey-pronin/Awesome-Vulnerability-Research - 🦄 A curated list of the awesome resources about the Vulnerability Research
- yeahwu/Google-IP-Range - 一个超大的 Google 全球 IP 扫描范围库
- muellerberndt/android_app_security_checklist - Android App Security Checklist
- hxy9243/whotofollow - Who to follow on Twitter/Telegram
- drduh/Debian-Privacy-Server-Guide - Guide to using a remote Debian server for security and privacy services
- scar45/conky_synthwave_neon - Synthwave-inspired Conky theme with weather support and a spiffy layout.
- erguotou520/bye - bye to yesterday and do yourself
- OneSecure/ShadowAgentNotes
- PaulSec/awesome-windows-domain-hardening - A curated list of awesome Security Hardening techniques for Windows.
- jxtsai/infographics - infographic
- ipfs/ipfs - Peer-to-peer hypermedia protocol
- chamuco/respin - Tool to backup and clone Ubuntu or Debian distros
- game-turn-over-skill-group/sync_hosts - 解除Resilio Sync/BTSync限制china地区 镜像:https://coding.net/u/renerli/p/sync_hosts/git
- mdrights/os-observe - 我的Linux / 隐私安全笔记
- uhub/awesome-c - A curated list of awesome C frameworks, libraries and software.
- sindresorhus/awesome-nodejs - :zap: Delightful Node.js packages and resources
- mawenjian/china-cdn-domain-whitelist - 中国CDN服务提供商域名白名单(China CDN Service Providers' Domain Whitelist)
- 3xp10it/php_cve-2014-8142_cve-2015-0231 - php_cve-2014-8142_cve-2015-0231的漏洞环境docker
- shieldfy/API-Security-Checklist - Checklist of the most important security countermeasures when designing, testing, and releasing your API
- m0l1ce/wooyunallbugs - wooyun_all_bugs
- gfwlist/gfwlist - The one and only one gfwlist here
- jinyu121/SurgeRule - Deprecate since 2016
- lu4nx/Exploit-Exercises-Nebula - Exploit-Exercises Nebula全攻略——Linux平台下的漏洞分析入门
- AonCyberLabs/Docker-Secure-Deployment-Guidelines - Deployment checklist for securely deploying Docker
- joyceqi/vulnerability-analysis-report - here records some personal vulnerability analysis reports
- vysecurity/RedTips - Red Team Tips as posted by @vysecurity on Twitter
- mandatoryprogrammer/RussiaDNSLeak - Summary and archives of leaked Russian TLD DNS data
- xiaolai/INB-Principles - Blockchain related ICO Investing Principles by INBlockchain
- hobby-kube/guide - Kubernetes clusters for the hobbyist.
- kailashahirwar/cheatsheets-ai - Essential Cheat Sheets for deep learning and machine learning researchers https://medium.com/@kailashahirwar/essential-cheat-sheets-for-machine-learning-and-deep-learning-researchers-efb6a8ebd2e5
- alexpate/awesome-design-systems - 💅🏻 ⚒ A collection of awesome design systems
- djadmin/awesome-bug-bounty - A comprehensive curated list of available Bug Bounty & Disclosure Programs and Write-ups.
- sdmg15/Best-websites-a-programmer-should-visit - :link: Some useful websites for programmers.
- mbasso/awesome-wasm - 😎 Curated list of awesome things regarding WebAssembly (wasm) ecosystem.
- FallibleInc/security-guide-for-developers - Security Guide for Developers (实用性开发人员安全须知)
- NotSoSecure/password_cracking_rules - One rule to crack all passwords. or atleast we hope so.
- Han0nly/SecurityRSS - 网络安全相关的RSS订阅列表
- exakat/php-static-analysis-tools - A reviewed list of useful PHP static analysis tools
- mikesiko/PracticalMalwareAnalysis-Labs - Binaries for the book Practical Malware Analysis
- coreb1t/awesome-pentest-cheat-sheets - Collection of the cheat sheets useful for pentesting
- ZonkSec/persistence-aggressor-script - initial commit
- virajkulkarni14/WebDeveloperSecurityChecklist - A checklist of important security issues you should consider when creating a web application.
- Security-Onion-Solutions/security-onion - Security Onion 16.04 - Linux distro for threat hunting, enterprise security monitoring, and log management
- embedded-boston/awesome-embedded-systems - A curated list of delightful Embedded Systems libraries, RTOSes, modules, references and more!
- jobbole/awesome-python-books - 如果有人让你推荐 Python 技术书,请让他看这个列表
- aalhour/awesome-compilers - :sunglasses: Curated list of awesome resources on Compilers, Interpreters and Runtimes
- sam-b/windows_kernel_resources - Papers, blogposts, tutorials etc for learning about Windows kernel exploitation, internals and (r|b)ootkits
- PolarisLab/SecPaper - SecurityPaper For www.polaris-lab.com
- secfigo/Awesome-Fuzzing - A curated list of fuzzing resources ( Books, courses - free and paid, videos, tools, tutorials and vulnerable applications to practice on ) for learning Fuzzing and initial phases of Exploit Developme
- michaelliao/awesome-python3-webapp - 小白的Python入门教程实战篇:网站+iOS App源码→ http://t.cn/R2PDyWN 赞助→ http://t.cn/R5bhVpf
- IVMachiavelli/OSINT_Team_Links - Links for the OSINT Team
- jivoi/awesome-ml-for-cybersecurity - :octocat: Machine Learning for Cyber Security
- vasanthk/web-security-basics - Web security concepts
- jynychen/pasc2at - 高级PHP应用程序漏洞审核技术 by 80vul
- PyroTek3/PowerShell-AD-Recon - PowerShell Scripts I find useful
- masatokinugawa/filterbypass - Browser's XSS Filter Bypass Cheat Sheet
- ludiosarchive/unfixed-security-bugs - A list of publicly known but unfixed security bugs
- futurice/android-best-practices - Do's and Don'ts for Android development, by Futurice developers
- infoslack/awesome-web-hacking - A list of web application security
- ranxian/xv6-chinese - 中文版的 MIT xv6 文档
- jonbruner/twitter-analysis - The original dataset for my 2013 article on Twitter's network patterns
- wsargent/docker-cheat-sheet - Docker Cheat Sheet
- BastilleResearch/mousejack - MouseJack device discovery and research tools
- toolinbox/iPic - iPic could automatically upload images and save Markdown links.
- orangetw/bug-bounty-reference - Inspired by https://github.com/djadmin/awesome-bug-bounty, a list of bug bounty write-up that is categorized by the bug nature
- SecYouth/sec-jobs - 信息安全实习和校招的面经、真题和资料 减少安全选手找实习/工作的痛苦
- Haixing-Hu/typesetting-standard - 中文排版所需遵循的标准和规范
- sparanoid/chinese-copywriting-guidelines - Chinese copywriting guidelines for better written communication/中文文案排版指北
- berzerk0/Probable-Wordlists - Version 2 is live! Wordlists sorted by probability originally created for password generation and testing - make sure your passwords aren't popular!
- endymecy/awesome-deeplearning-resources - Deep Learning and deep reinforcement learning research papers and some codes
- jaybosamiya/security-notes - :notebook: Some security related notes
- Cactus-proj/Reverse-Engineering-for-Beginners-CHS - Reverse Engineering for Beginners 这本书的翻译完善
- recdnsfp/recdnsfp.github.io
- xNymia/Suricata-Signatures - Suricata rules for Emerging Threats and funkyness
- Te-k/flexidie - Source code and binaries of FlexiSpy from the Flexidie dump
- jivoi/awesome-osint - :scream: A curated list of amazingly awesome OSINT
- qazbnm456/awesome-cve-poc - ✍️ A curated list of CVE PoCs.
- bluscreenofjeff/Red-Team-Infrastructure-Wiki - Wiki to collect Red Team infrastructure hardening resources
- Idnan/bash-guide - A guide to learn bash
- We5ter/Scanners-Box - A powerful and open-source toolkit for hackers and security automation - 安全行业从业者自研开源扫描器合辑
- angular-pakistan/ng-conf-2017 - Everything #ngConf2017 - talks - slides - resources
- wwj718/awesome-raspberry-pi-zh - 树莓派(Raspberry Pi )资源大全中文版 , 包括工具、项目、镜像、资源等
- michalmalik/osx-re-101 - A collection of resources for OSX/iOS reverse engineering.
- caomulaodao/XSS-Filter-Evasion-Cheat-Sheet-CN - XSS_Filter_Evasion_Cheat_Sheet 中文版
- cure53/XSSChallengeWiki - Welcome to the XSS Challenge Wiki!
- shmilylty/awesome-hacking - awesome hacking chinese version
- Hack-with-Github/Awesome-Hacking - A collection of various awesome lists for hackers, pentesters and security researchers
- Hack-with-Github/Free-Security-eBooks - Free Security and Hacking eBooks
- cn0xroot/RFSec-ToolKit - RFSec-ToolKit is a collection of Radio Frequency Communication Protocol Hacktools.无线通信协议相关的工具集,可借助SDR硬件+相关工具对无线通信进行研究。Collect with ♥ by HackSmith
- pillarjs/understanding-csrf - What are CSRF tokens and how do they work?
- automayt/FlowAnalysisDocker - A Dockerfile for creation of an Ubuntu Docker with SiLK/YAF/FlowBAT for testing.
- herrbischoff/awesome-macos-command-line - Use your macOS terminal shell to do awesome things.
- tiancode/learn-hacking - 开始学习Kali Linux 各种破解教程 渗透测试 逆向工程 HackThisSite挑战问题解答
- justjavac/Google-IPs - :us: Google 全球 IP 地址库
- exploitprotocol/IoT-Security-Wiki
- AntBranch/awesome-github - A curated list of awesome GitHub guides, articles, sites, tools, projects and resources. 收集这个列表,只是为了更好地使用GitHub,欢迎提交pr和issue。
- 1021683053/awesome-raspberry-pi-zh - 树莓派工具,镜像,教程,文章
- JaredCubilla/sublime - A collection of some of the best Sublime Text packages, themes, and goodies.
- BruceDone/awesome-crawler - A collection of awesome web crawler,spider in different languages
- PiPHP/Resources - A resource directory for PHP programming on a Raspberry Pi
- youyudehexie/node123 - node.js中文资料导航
- francistao/LearningNotes - Enjoy Learning.
- staticfile/static - 开放静态文件 - 为开源库提供稳定、快速的免费 CDN 服务
- jwasham/coding-interview-university - A complete computer science study plan to become a software engineer.
- fex-team/styleguide - 文档与源码编写风格
- ruanyf/jstraining - 全栈工程师培训材料
- hackstoic/golang-open-source-projects - 为互联网IT人打造的中文版awesome-go
- FrankFang/best-chinese-front-end-blogs - 收集优质的中文前端博客
- ZuzooVn/machine-learning-for-software-engineers - A complete daily plan for studying to become a machine learning engineer.
- qyuhen/book - 学习笔记
- facert/python-data-structure-cn - problem-solving-with-algorithms-and-data-structure-using-python 中文版
- shimohq/react-cookbook - 编写简洁漂亮,可维护的 React 应用
- a8m/golang-cheat-sheet - An overview of Go syntax and features.
- TonnyL/Awesome_APIs - :octocat: A collection of APIs
- judasn/IntelliJ-IDEA-Tutorial - IntelliJ IDEA 简体中文专题教程
- lxj616/docker-dvwa-wooyun - docker contained dvwa with wooyun plugin
- BuildHackSecure/gitscraper - A tool which scrapes public github repositories for common naming conventions in variables, folders and files
- pandasec888/taowu-cobalt_strike
- langsasec/c2-shellcode-py - 免杀360,火绒的Python-shellcode加载器,可直接生成可执行文件exe
- lucky-ecat/wechat_info_collect - 调查取证 | 针对微信客户端的信息收集工具, 自动化提取本地PC所有的微信信息, 包括微信号, 手机号等
- drduh/macOS-Security-and-Privacy-Guide - Guide to securing and improving privacy on macOS
- EAimTY/tuic
- immersive-translate/immersive-translate - 沉浸式双语网页翻译扩展 , 支持输入框翻译, 鼠标悬停翻译, PDF, Epub, 字幕文件, TXT 文件翻译 - Immersive Dual Web Page Translation Extension
- lensapp/lens - Lens - The way the world runs Kubernetes
- He1za1/FscanSnipaste - FscanSnipaste_1.8.2_001_内网快速连接工具
- Lotus6/ysoserial - ysoserial 图形化,探测 Gadget,探测 Class,命令执行,注入哥斯拉冰蝎内存马,加载字节码等
- m-sec-org/EZ - EZ是一款集信息收集、端口扫描、服务暴破、URL爬虫、指纹识别、被动扫描为一体的跨平台漏洞扫描器。
- AgentVirus/GoT - 漏洞poc指纹整合管理,漏洞扫描工具
- CllmsyK/YYBaby-Spring_Scan - 一款针对Spring框架的漏洞扫描及漏洞利用图形化工具
- Just-Hack-For-Fun/Linux-INCIDENT-RESPONSE-COOKBOOK - Linux 应急响应手册
- lintstar/CS-AutoPostChain - 基于 OPSEC 的 CobaltStrike 后渗透自动化链
- g1oves2ali/anti-anti-virus - 免杀知识库 | 开源免杀木马效果测试 360 火绒 卡巴斯基 Microsoft Defender | 免杀工具汇总
- veo/vshell - vshell 是一款安全对抗模拟、红队工具。提供隧道代理和隐蔽通道,模拟长期潜伏攻击者的策略和技术
- Lya0/Fofa_view_fingerprint - 魔改的fofa浏览器插件,能够进行自动调用指纹接口进行指纹识别。
- qiuluo-oss/Tiger - Tiger是一款在攻防演练中对目标资产重点系统指纹识别、精准漏扫的工具。是一款打点神器。
- twowb/zndb - 此工具用于快速准确的等保核查、端口扫描、组件识别、子域名扫描、目录扫描等功能
- DeEpinGh0st/MDUT-Extend-Release - MDUT-Extend(扩展版本)
- Ylarod/Florida - 基础反检测 frida-server / Basic anti-detection frida-server
- justjavac/awesome-wechat-weapp - 微信小程序开发资源汇总 :100:
- 0xgkd/awvs - A version of awvs docker based on Ubuntu 18.04
- Just-Hack-For-Fun/Windows-INCIDENT-RESPONSE-COOKBOOK - Windows 应急响应手册
- mifine666/miscan - 一款简单好用的漏洞管理工具,支持本地和协作两种模式。
- kkbo8005/mitan - 密探渗透测试工具包含资产信息收集,子域名爆破,搜索语法,资产测绘(FOFA,Hunter,quake, ZoomEye),指纹识别,敏感信息采集,文件扫描、密码字典等功能
- R4gd0ll/I-Wanna-Get-All - OA漏洞利用工具
- zangcc/Java_Risky_Functions - Java 代码审计-存在风险的函数汇总。方便我们日常代码审计过程中快速定位漏洞点,配合静态代码分析工具做到事半功倍。Java code audit - summary of risky functions. It is convenient for us to quickly locate vulnerability points in the daily code audit process,
- HotBoy-java/PotatoTool - 这款工具是一款功能强大的网络安全综合工具,旨在为安全从业者、红蓝对抗人员和网络安全爱好者提供全面的网络安全解决方案。它集成了多种实用功能,包括解密、分析、扫描、溯源等,为用户提供了便捷的操作界面和丰富的功能选择。This tool offers robust network security solutions for professionals and enthusiasts. With fea
- CTF-Archives/OMCTF2024 - 2024高校网络安全管理运维赛 附件归档 OMCTF2024(operation and maintenance)
- One-Fox-Security-Team/One-Fox-T00ls
- kong030813/Z-Godzilla_ekp - 哥斯拉webshell管理工具二次开发规避流量检测设备
- Byxs20/PuzzleSolver - 一款针对CTF竞赛MISC的工具~
- ProbiusOfficial/CTFtools-wiki - 【Hello CTF】录常用 / 优秀 的CTF工具项目及其文档,一个对各阶段CTFer都很友好的工具仓库,让所有的工具都发挥作用!
- ProbiusOfficial/CTF-OS - 【Hello CTF】专为CTF比赛封装的虚拟机,基于工具集封装多个版本和系统,更多选择,开箱即用。比赛愉快!
- abc123info/EquationToolsGUI - 本程序为美国NSA的方程式工具包图形界面版,由ABC_123于2017年开始编写,仅用来扫描和验证MS17-010、MS09-050、MS08-067漏洞,并可协助管理员修复系统漏洞。
- xjsafe/MimikatzBypass - 新免杀方向 Mimikatz(猕猴桃) 免杀 360,火绒,电脑管家,WindowsDefinder,详细使用教程请参考博客:https://www.vpss.cc/381.html
- W01fh4cker/LearnFastjsonVulnFromZero-Improvement - 【两万字原创】零基础学fastjson漏洞(提高篇),公众号:追梦信安
- charonlight/RuoYiExploitGUI - 若依最新定时任务SQL注入可导致RCE漏洞的一键利用工具
- wafinfo/DecryptTools - DecryptTools-综合解密
- charonlight/SpringExploitGUI - 一款Spring综合漏洞的利用工具,工具支持多个Spring相关漏洞的检测以及利用
- charonlight/JenkinsExploitGUI - Jenkins CLI 任意文件读取漏洞检查工具
- SexyBeast233/SecDictionary - 实战沉淀字典
- yingshang/CybersecurityNote - 信息安全笔记(JAVA安全、代码审计、红队攻防、渗透测试)
- luelueking/RuoYi-v4.7.8-RCE-POC
- xiaogang000/XG_NTAI - 用于Webshell木马免杀、流量加密传输,多多支持star
- W01fh4cker/LearnJavaMemshellFromZero - 【三万字原创】完全零基础从0到1掌握Java内存马,公众号:追梦信安
- FindAllTeam/FindAll - Automated analysis of network security emergency response tools.(自动化分析网络安全应急响应工具)
- iamHuFei/HVVault - 梳理【护网高利用率POC】并集成Nuclei模板仓库,针对解决网上同一资产漏洞一键检测工具参次不齐问题。
- pingcap/awesome-database-learning - A list of learning materials to understand databases internals
- abc123info/UserNameDictTools - 用户名密码字典生成工具(将中文汉字姓名转成14种格式的拼音、IP地址处理、网络设备密码生成)
- bcvgh/daydayExp-pocs - daydayExp的漏洞POC仓库,慢慢更新...
- WuFengXue/android-reverse - 安卓逆向工具汇总 / Awsome Android Reverse Tools
- W01fh4cker/LearnFastjsonVulnFromZero-Basic - 【两万字原创】零基础学fastjson漏洞(基础篇),公众号:追梦信安
- AD-Attacks/AD-Attacks-by-Service - Active Directory Penetration Testing for Red Teams
- z-bool/Venom-Transponder - 毒液流量转发器:自动化捡洞/打点/跳板必备神器,支持联动URL爬虫、各种被动扫描器。
- InQuest/awesome-yara - A curated list of awesome YARA rules, tools, and people.
- wy876/POC - 收集整理漏洞EXP/POC,大部分漏洞来源网络,目前收集整理了1000多个poc/exp,长期更新。
- xcanwin/CVE-2023-4357-Chrome-XXE - [漏洞复现] 全球首款单文件利用 CVE-2023-4357 Chrome XXE 漏洞 EXP, 实现对访客者本地文件窃取. Chrome XXE vulnerability EXP, allowing attackers to obtain local files of visitors.
- ProbiusOfficial/SecToolKit - Cybersecurity tool repository / Wiki 收录常用 / 前沿 的CTF和渗透工具以及其 官方/使用 文档,致力于让每个工具都能发挥作用ww,不管你是萌新还是领域从业者希望你都能在这里找到适合你的工具或者获得一定的启发。
- sfsm565826960/AutoPenetrationTesting - BurpSuite辅助渗透测试插件
- TargetPackage/api-key-impact - A list of different types of API keys and how to prove impact for bug bounty programs.
- dark-kingA/cloudTools - 云资产管理工具 目前工具定位是云安全相关工具,目前是两个模块 云存储工具、云服务工具, 云存储工具主要是针对oss存储、查看、删除、上传、下载、预览等等 云服务工具主要是针对rds、服务器的管理,查看、执行命令、接管等等
- itgoyo/TelegramGroup - 2024最新悄咪咪收集的10000+个Telegram群合集,附带全网最有趣最好用的机器人BOT🤖【tg百科】
- yzddmr6/Java-Js-Engine-Payloads - Java Js Engine Payloads All in one
- simplerhacking/Evilginx3-Phishlets - This repository provides penetration testers and red teams with an extensive collection of dynamic phishing templates designed specifically for use with Evilginx3. May be updated periodically.
- djytmdj/Network-security-study-notes - 主要记录网络安全学习笔记,包含WEB安全、提权、APP渗透、内网渗透、横向移动、红队、工具学习等
- TonyNPham/GodzillaPlugin-Suo5-MemProxy - 一款高性能 HTTP 内存代理 | 哥斯拉插件 | readteam | 红队 | 内存马 | Suo5 | Godzilla | 正向代理
- CuriousLearnerDev/Online_tools - 该工具是一个集成了非常多渗透测试工具,类似软件商城的工具可以进行工具下载,工具的更新,工具编写了自动化的安装脚本,不用担心工具跑不起来。
- doimet/AuxTools - 图形化渗透测试辅助工具
- merdw/iOS-Instagram-SSL-Pinning-Bypass - Bypass Instagram SSL pinning on iOS devices. Latest version Instagram 289.1
- yichensec/yichen_Password_dictionary - 逸尘的字典 渗透测试个人专用的字典,搜索网上,及自己平常收集的一些路径,其中信息包括HVV中常见的各大厂商的弱密码,web常见漏洞测试,会遇到的邮箱,密码,服务弱口令,中间件,子域名,漏洞路径,账户密码,等等,这些内容都是基于本人在实战中收集到的,其中包含Github上公布的密码字典整合,堪称最经典的字典,用这个足以满足日常src,渗透测试,资产梳理,红蓝对抗等前期探测工作。
- UltimateSec/ultimaste-nuclei-templates - 极致攻防实验室 nuclei 检测 POC
- merdw/Threads-SSLPinningBypass - Bypass Instagram new app Threads App SSL pinning
- outmansec/SelfIPAdressQuery - 一款基于javafx的自有IP地址查询工具(适用于重保、蓝队、攻防演习等场景)
- wafinfo/Hikvision - 海康威视综合安防平台后渗透利用工具
- FuzzySecurity/FuzzySecurity
- KuGmonkey/Vulnerability-mining - 综合利用各种技术和工具进行漏洞挖掘实践
- shockerli/mac-initialize - 💻 Mac 开光指南(V2),为你的新 Mac 系统提供一份快速食用方法
- Tsojan/TsojanScan - An integrated BurpSuite vulnerability detection plug-in.
- tib36/PhishingBook - 红蓝对抗:钓鱼演练资源汇总&备忘录
- KimJun1010/WeblogicTool - WeblogicTool,GUI漏洞利用工具,支持漏洞检测、命令执行、内存马注入、密码解密等(深信服深蓝实验室天威战队强力驱动)
- Funcy33/Vluninfo_Repo - 一些漏洞信息
- Ignitetechnologies/Mindmap - This repository will contain many mindmaps for cyber security technologies, methodologies, courses, and certifications in a tree structure to give brief details about them
- rissor41/SolarWinds-CVE-2021-35250
- tangxiaofeng7/Security_Q-A - 安全面试题
- J0o1ey/BountyHunterInChina - 重生之我在安全行业讨口子系列,分享在安全行业讨口子过程中,SRC、项目实战的有趣案例
- The-Hacker-Recipes/The-Hacker-Recipes - This project is aimed at freely providing technical guides on various hacking topics: Active Directory services, web services, servers, intelligence gathering, physical intrusion, phishing, mobile app
- roadwy/RIP
- frostbits-security/MITM-cheatsheet - All MITM attacks in one place.
- StyraInc/awesome-opa - A curated list of OPA related tools, frameworks and articles
- JakobTheDev/awesome-devsecops - Curating the best DevSecOps resources and tooling.
- deyaaahmed/light-map - A light-map tool is used to hack any website affected by sql and XSS exploit,light-map has many websites there are affected by sql and XSS exploit, and it have a sqlmap tool,you can download and insta
- safest-place/ExploitPcapCollection - collect some exploit traffic pcap
- nu11pointer/fuzzlists - A collection of useful lists for Penetration Testing & Bug Bounty - Content Discovery, Payloads, Variables, Sandbox Escaping, etc
- x364e3ab6/DudeSuite - Dude Suite Web Security Tools
- saisathvik1/Linux-Privilege-Escalation-Notes - My Linux Privilege Escalation notes which is part of my OSCP Preperation
- guchangan1/All-Defense-Tool - 本项目集成了全网优秀的攻防武器工具项目,包含自动化利用,子域名、目录扫描、端口扫描等信息收集工具,各大中间件、cms、OA漏洞利用工具,爆破工具、内网横向、免杀、社工钓鱼以及应急响应、甲方安全资料等其他安全攻防资料。
- 1n7erface/Template - Next generation RedTeam heuristic intranet scanning | 下一代RedTeam启发式内网扫描
- 0x783kb/Security-Operation-Book - 常见的攻击行为监测特征及方法,涵盖端点和流量,未包含PowerShell和Sysmon。预祝运营生活愉快!
- xdmjun/wxappUnpacker
- harismuneer/Ultimate-Social-Scrapers - 🤖 Top-rated tools to scrape all major sections from Facebook, Instagram, and Twitter (X) including posts (likes/comments), photos/videos, contact information, followers, following and much more.
- pandazheng/Mac-IOS-Security - Mac&IOS安全学习资料汇总
- perklet/reverse-interview-zh - 技术面试最后反问面试官的话
- lingcoder/OnJava8 - 《On Java 8》中文版
- skyw4tch3r/RootKits-List-Download - This is the list of all rootkits found so far on github and other sites.
- ihchiz/Awesome-Linux-Software-zh_CN - 🐧 一个 Linux 上超赞的应用,软件,工具以及其它资源的集中地。
- vuejs/awesome-vue - 🎉 A curated list of awesome things related to Vue.js
- chaosec2021/fscan-POC - 强化fscan的漏扫POC库
- wsummerhill/CobaltStrike_RedTeam_CheatSheet - Useful Cobalt Strike techniques learned from engagements
- bin-maker/2021CDN
- xuedingmiaojun/mp-unpack
- 12306Bro/Security-operation-book - 一些常见的安全检测规则及事件
- TaptuIT/awesome-devsecops - Curating the best DevSecOps resources and tooling.
- xiaolai/everyone-can-use-english - 人人都能用英语
- SeikoSrp/Pentest-Notes - 《内网安全攻防-渗透测试实战指南》一些技术点概括
- cpuu/awesome-fuzzing - A curated list of awesome Fuzzing(or Fuzz Testing) for software security
- stnv/pentest-playbook - Pentest Playbook - In other words, this is my hacking notebook where I write down all notes from my journey in cybersecurity.
- ziadoz/awesome-php - A curated list of amazingly awesome PHP libraries, resources and shiny things.
- funkyoummp/BurpSuiteCn - Burp Suite 汉化 中文
- ezlkc/androidantivirus
- LappleApple/awesome-leading-and-managing - Awesome List of resources on leading people and being a manager. Geared toward tech, but potentially useful to anyone.
- sbilly/awesome-security - A collection of awesome software, libraries, documents, books, resources and cools stuffs about security.
- fffaraz/awesome-cpp - A curated list of awesome C++ (or C) frameworks, libraries, resources, and shiny things. Inspired by awesome-... stuff.
- serhii-londar/open-source-mac-os-apps - 🚀 Awesome list of open source applications for macOS. https://t.me/s/opensourcemacosapps
- sdnds-tw/awesome-sdn - A awesome list about Software Defined Network (SDN)
- mezod/awesome-indie - Resources for independent developers to make money
- prakhar1989/awesome-courses - :books: List of awesome university courses for learning Computer Science!
- laylalaisy/GRE_laylalaisy - Toefl的姊妹篇lol GRE的一些资料~ 祝小可爱和大佬们早日和GRE巨型怪兽分手(o゜▽゜)o☆
- mafutian/software - 破解版工具/软件
- alebcay/awesome-shell - A curated list of awesome command-line frameworks, toolkits, guides and gizmos. Inspired by awesome-php.
- cryptoseb/CryptoPaper - Privacy, Security, and Anonymity For Every Internet User.
- tiimgreen/github-cheat-sheet - A list of cool features of Git and GitHub.
- sh4hin/Androl4b - A Virtual Machine For Assessing Android applications, Reverse Engineering and Malware Analysis
- Xel/Blockchain-stuff - Blockchain and Crytocurrency Resources
- rshipp/awesome-malware-analysis - Defund the Police.
- chentsulin/awesome-graphql - Awesome list of GraphQL
- akullpp/awesome-java - A curated list of awesome frameworks, libraries and software for the Java programming language.
- sublimino/awesome-funny-markov - A curated list of delightfully amusing and facetious Markov chain output.
- markets/awesome-ruby - 💎 A collection of awesome Ruby libraries, tools, frameworks and software
- carpedm20/awesome-hacking - A curated list of awesome Hacking tutorials, tools and resources
- BMaChina/cnvd_database
- mfornos/awesome-microservices - A curated list of Microservice Architecture related principles and technologies.
- veggiemonk/awesome-docker - :whale: A curated list of Docker resources and projects
- meirwah/awesome-incident-response - A curated list of tools for incident response
- megous/megatools - Open-source command line tools for accessing Mega.co.nz cloud storage.
- inputsh/awesome-linux - :penguin: A list of awesome projects and resources that make Linux even more awesome. :penguin:
- zudochkin/awesome-newsletters - A list of amazing Newsletters
- kdeldycke/awesome-iam - 👤 Identity and Access Management knowledge for cloud platforms
- qazbnm456/awesome-web-security - 🐶 A curated list of Web Security materials and resources.
- Rabb1tQ/SickleOfSkyCurtain - zoomeyeGUI
- bakke92/awesome-gdpr - Protection of natural persons with regard to the processing of personal data and on the free movement of such data.
- awesome-selfhosted/awesome-selfhosted - A list of Free Software network services and web applications which can be hosted on your own servers
- injectexpert/API-KEY-CHECKER - AIO API-KEY CHECKER|AWS|Twilio|Mailgun
- caesar0301/awesome-pcaptools - A collection of tools developed by other researchers in the Computer Science area to process network traces. All the right reserved for the original authors.
- packing-box/awesome-executable-packing - A curated list of awesome resources related to executable packing
- i11us0ry/goon - goon,集合了fscan和kscan等优秀工具功能的扫描爆破工具。功能包含:ip探活、port扫描、web指纹扫描、title扫描、压缩文件扫描、fofa获取、ms17010、mssql、mysql、postgres、redis、ssh、smb、rdp、telnet、tomcat等爆破以及如netbios探测等功能。
- xxjwxc/uber_go_guide_cn - Uber Go 语言编码规范中文版. The Uber Go Style Guide .
- itwanger/toBeBetterJavaer - 一份通俗易懂、风趣幽默的Java学习指南,内容涵盖Java基础、Java并发编程、Java虚拟机、Java企业级开发、Java面试等核心知识点。学Java,就认准二哥的Java进阶之路😄
- dark-kingA/arsenalTools - 桌面版本-superSearchPlus是聚合型信息收集插件,支持综合查询,资产测绘查询,信息收集 js敏感信息提取 注释资源扫描 目录扫描 整合了目前常见的资产测绘平台 同时支持数据导出
- HackingCost/AD_Pentest - 红队|域渗透重要漏洞汇总(持续更新)
- StarCrossPortal/scalpel - scalpel是一款命令行漏洞扫描工具,支持深度参数注入,拥有一个强大的数据解析和变异算法,可以将常见的数据格式(json, xml, form等)解析为树结构,然后根据poc中的规则,对树进行变异,包括对叶子节点和树结构 的变异。变异完成之后,将树结构还原为原始的数据格式。
- Liqunkit/webfinder-next - 对小米范webfinder http://www.cnblogs.com/SEC-fsq/p/5610981.html 进行了小修改
- malienist/lupo - Lupo - Malware IOC Extractor. Debugging module for Malware Analysis Automation
- zangcc/Aazhen-RexHa - 自研JavaFX图形化漏洞扫描工具,支持扫描的漏洞分别是: ThinkPHP-2.x-RCE, ThinkPHP-5.0.23-RCE, ThinkPHP5.0.x-5.0.23通杀RCE, ThinkPHP5-SQL注入&敏感信息泄露, ThinkPHP 3.x 日志泄露NO.1, ThinkPHP 3.x 日志泄露NO.2, ThinkPHP 5.x 数据库信息泄露的漏洞检测,以及批量检测的功
- geekan/HowToLiveLonger - 程序员延寿指南 | A programmer's guide to live longer
- d3ckx1/Fvuln - F-vuln(全称:Find-Vulnerability)是为了自己工作方便专门编写的一款自动化工具,主要适用于日常安全服务、渗透测试人员和RedTeam红队人员,它集合的功能包括:存活IP探测、开放端口探测、web服务探测、web漏洞扫描、smb爆破、ssh爆破、ftp爆破、mssql爆破等其他数据库爆破工作以及大量web漏洞检测模块。
- Tas9er/ByPassBehinder4J - 冰蝎Java WebShell自动化免杀生成
- binganao/vulns-2022 - 本项目用于搜集 2022 年的漏洞,注意:本项目并不刻意搜集 POC 或 EXP,主要以CVE-2021、CVE-2022 为关键词,包含但不限于漏洞资讯、漏洞复现、漏洞分析、漏洞验证、漏洞利用
- HackJava/Log4j2 - 《HackLog4j-永恒之恶龙》致敬全宇宙最无敌的Java日志库!Tribute to the most invincible Java logging library in the universe!
- flydoos/DingTalkRevokeMsgPatcher - 钉钉消息防撤回补丁PC版(原名:钉钉电脑版防撤回插件,也叫:钉钉防撤回补丁、钉钉消息防撤回补丁)由“吾乐吧软件站”开发制作,本程序用于钉钉电脑版6.0以上版本,主要功能如下:1、支持文字消息防撤回 2、支持图片消息防撤回,支持查看高清原图 3、支持文件识别、URL识别、卡片回复消息识别等 4、支持富文本消息防撤回 5、支持个人消息防撤回,以及群主或管理员消息防撤回 6、支持自己发送的消息
- yangyiRunning/Beijing-House - 面向北京码农同胞的从0开始的买房踩盘实录,目标只有一个: 每一分钱都花的明白(持续补充和完善ing…)
- BigGan/Windows-Hack-Programming - 《WINDOWS黑客编程技术详解》,作者甘迪文,2018年12月由人民邮电出版社出版,是一本面向黑客编程初学者的书,较为全面的地总结黑客编程技术。其内容重在实践,着重剖析技术实现原理,向读者讲解黑客编程技术的实现方法。
- spaze/hashes - Magic hashes – PHP hash "collisions"
- x1ah/gena-template - 一键生成导航网站(GitHub Template of generating personal start page)
- TimelifeCzy/Windows-emergency-servicetools - Windows一键检测应急响应服务工具/r3数据采集
- wyzxxz/heapdump_tool - heapdump敏感信息查询工具,例如查找 spring heapdump中的密码明文,AK,SK等
- bin-maker/apkshell - 实用的针对安卓应用加壳类型判断的小工具,涵盖各大商业、企业壳, 长期保持更新
- eastmountyxz/Sui-AIResearch - 该资源将应用人工智能技术研究水族文化、文字和古籍。为更好的抢救和保护濒危水族文字和非物质文化遗产,作者申请并开源了该项目,主要通过人工智能技术识别水书,构建与汉字的自动翻译系统,实现水族本体和文献知识图谱构建,挖掘新词并溯源民族变迁历史。作者回到家乡贵州教书以来,对利用AI抢救民族文物研究产生浓厚兴趣并后半生都将致力于该研究中,包括侗族大歌、苗族飞歌语音识别研究,王阳明文化研究,少数民族古籍文字保
- MountCloud/JavaDecompileTool-GUI - Java Decompile Tool GUI-JAVA反编译工具(界面版)
- nnjun/BlackBox - 黑盒BlackBox,是一款虚拟引擎,支持5.0~12.0,可以在Android上克隆、运行虚拟应用,拥有免安装运行能力,已集成Xposed框架。黑盒可以掌控被运行的虚拟应用,做任何想做的事情。
- eastmountyxz/CSDNBlog-Security-Based - 为了更好地管理博客文章,分享更好的知识,该系列资源为作者CSDN博客的备份文件。本资源为网络安全自学篇,包括作者安全工具利用、Web渗透、系统安全、CVE漏洞复现、安全论文及会议等知识,希望对您有所帮助!一起加油。
- Jewel591/Vulnerability-Summary - 常见漏洞描述、漏洞影响及修复建议,为规范的渗透测试报告提供参考 | Common vulnerability descriptions, vulnerability impacts and remediation recommendations for standardized penetration testing reports
- coder2gwy/coder2gwy - 互联网首份程序员考公指南,由3位已经进入体制内的前大厂程序员联合献上。
- FunnyWolf/Viper - Attack Surface Management & Red Team Simulation Platform 互联网攻击面管理&红队模拟平台
- xiaolai/spreadsheets-for-investors - 投资人必会知识 —— 电子表格简明进阶教程
- afatcoder/LeetcodeTop - 汇总各大互联网公司容易考察的高频leetcode题🔥
- pingfangx/jetbrains-in-chinese - JetBrains 系列软件汉化包 关键字: Android Studio 3.5 汉化包 CLion 2019.3 汉化包 DataGrip 2019.3 汉化包 GoLand 2019.3 汉化包 IntelliJ IDEA 2019.3 汉化包 PhpStorm 2019.3 汉化包 PyCharm 2019.3 汉化包 Rider 2019.3 汉化包 RubyMine 2019.3 汉化
- Ascotbe/HackerMind - 各种安全相关思维导图整理收集。渗透步骤,web安全,CTF,业务安全,人工智能,区块链安全,数据安全,安全开发,无线安全,社会工程学,二进制安全,移动安全,红蓝对抗,运维安全,风控安全,linux安全
- pwicherski/TestowanieOprogramowania - Testowanie oprogramowania - Książka dla początkujących testerów
- shack2/skyscorpion - 新版将不再对外公开发布。天蝎权限管理工具采用Java平台的JavaFX技术开发的桌面客户端,支持跨平台运行,目前基于JDK1.8开发,运行必须安装JDK或JRE 1.8,注意不能是open jdk,只能是oracle的jdk。 天蝎权限管理工具基于冰蝎加密流量进行WebShell通信管理的原理,目前实现了jsp、aspx、php、asp端的常用操作功能,在原基础上,优化了大文件上传下载、Socke
- xiaojiaqi/k8seasy_release_page - 一键安装kubernets(k8s)系统,已支持云环境的发布,可以在阿里云 azure 等云环境自主部署k8s系统,golang 编写 无需任何插件,无需翻墙下载任何内容,证书10年有效期,支持 单机 集群 生产环境的高可用 完全离线安装等标准。自带dashboard 监控,镜像仓库等内容,一键可用。
- alphaSeclab/injection-stuff - PE Injection、DLL Injection、Process Injection、Thread Injection、Code Injection、Shellcode Injection、ELF Injection、Dylib Injection, including 400+Tools and 350+posts
- satan1a/awesome-ios-security-cn - iOS安全资料整理(中文)
- lyshark/Windows-exploits - Windows 平台提权漏洞大合集,长期收集各种提权漏洞利用工具。 A large collection of rights raising vulnerabilities on the windows platform, which collects various rights raising vulnerability utilization tools for a long
- Ruturaj4/Mobile-Security-Paper_summaries - Papers summaries of some of the most important Mobile Security Papers 📃
- alphaSeclab/awesome-network-stuff - Resources about network security, including: Proxy/GFW/ReverseProxy/Tunnel/VPN/Tor/I2P, and MiTM/PortKnocking/NetworkSniff/NetworkAnalysis/etc。More than 1700 open source tools for now. Post incoming.
- freedom-is-life/crypto-exchange - 24mex,24MEX,24Mex,h5、网站app前后端源码下载。最火的差价合约交易所系统|指数型差价合约交易所系统、ICFD指数型差价合约交易所、BTC比特币杠杠交易、领先数字货币杠杆交易所(高达100倍杠杆),数字货币比特币 BTC 微盘交易系统开发、数字货币比特币 BTC 微交易系统,数字货币比特币 BTC 合约系统;
- starrtc/starrtc-android-demo - 🚀starRTC,即时通讯(IM)系统,免费IM系统(含单聊,群聊,聊天室,文件传输),免费一对一视频聊天,VOIP,语音对讲(回音消除),直播连麦,视频直播,RTSP拉流,RTMP推流,webRTC服务端,在线教育,白板,小班课,在线会议,视频会议,视频监控,局域网直连(无需服务器),兼容webRTC, 支持webRTC加速,P2P高清传输,安卓、iOS、web互通,支持门禁对讲,可视对讲,电视
- izombielandgit/CentOS7-Server-Configuration - CentOS7服务器的一些配置
- guardrailsio/awesome-golang-security - Awesome Golang Security resources 🕶🔐
- liuchengxu/git-commit-emoji-cn - 😁 git commit message emoji 使用指南
- aichinateam/chinese-ai-developer - 👩🏿💻👨🏾💻👩🏼💻👨🏽💻👩🏻💻中国 AI 开发者项目列表 -- 分享大家都在做什么
- iCHAIT/awesome-macOS - A curated list of awesome applications, softwares, tools and shiny things for macOS.
- tonghuaroot/Vulnerability-Env - 收集国内外开源CMS存在漏洞的各种版本
- jobbole/awesome-php-cn - PHP资源大全中文版,库、框架、模板、安全、代码分析、日志、第三方库、配置工具、Web 工具等
- jaredthecoder/awesome-vehicle-security - 🚗 A curated list of resources for learning about vehicle security and car hacking.
- geekcompany/ResumeSample - Resume template for Chinese programmers . 程序员简历模板系列。包括PHP程序员简历模板、iOS程序员简历模板、Android程序员简历模板、Web前端程序员简历模板、Java程序员简历模板、C/C++程序员简历模板、NodeJS程序员简历模板、架构师简历模板以及通用程序员简历模板
- programthink/sites - 【编程随想】收藏的各色网站
- Awesome-Windows/Awesome - :computer: 🎉 An awesome & curated list of best applications and tools for Windows.
- wainshine/Chinese-Names-Corpus - 中文人名语料库。人名生成器。中文姓名,姓氏,名字,称呼,日本人名,翻译人名,英文人名。可用于中文分词、人名实体识别。
- AV1080p/Benchmarks - 常用服务器、数据库、中间件安全配置基线 - 基本包括了所有的操作系统、数据库、中间件、网络设备、浏览器,安卓、IOS、云的安全配置 For benchmarks.cisecurity.org
- TuuuNya/fuzz_dict - 常用的一些fuzz及爆破字典,欢迎大神继续提供新的字典及分类。
- dodola/Gitbook - 收录找到的不错的文档
- 1n7erface/RequestTemplate - 双语双端内网扫描以及验证工具
- fabacab/awesome-cybersecurity-blueteam - :computer:🛡️ A curated collection of awesome resources, tools, and other shiny things for cybersecurity blue teams.
- reewardius/bbFuzzing.txt
- CVEProject/cvelist - Pilot program for CVE submission through GitHub. CVE Record Submission via Pilot PRs ending 6/30/2023
- Mel0day/RedTeam-BCS - BCS(北京网络安全大会)2019 红队行动会议重点内容
- cujanovic/Markdown-XSS-Payloads - XSS payloads for exploiting Markdown syntax
- marcosValle/awesome-windows-red-team - A curated list of awesome Windows frameworks, libraries, software and resources for Red Teams
- MyKings/security-study-tutorial - Summary of online learning materials
- OlivierLaflamme/Cheatsheet-God - Penetration Testing Reference Bank - OSCP / PTP & PTX Cheatsheet
- JnuSimba/AndroidSecNotes - some learning notes about Android Security
- zodiacon/AllTools - All reasonably stable tools
- jcesarstef/ghhdb-Github-Hacking-Database - Github Hacking Database - My personal collection of Github Dorks to search for Confidential Information (Yes, it's a Github version of Google Dorks)
- 0x4D31/awesome-oscp - A curated list of awesome OSCP resources
- tanprathan/OWASP-Testing-Checklist - OWASP based Web Application Security Testing Checklist is an Excel based checklist which helps you to track the status of completed and pending test cases.
- AllsafeCyberSecurity/awesome-ghidra - A curated list of awesome Ghidra materials
- CaledoniaProject/awesome-opensource-security - A list of interesting open-source security tools, mostly reviewed and commented by me.
- rsmudge/Malleable-C2-Profiles - Malleable C2 is a domain specific language to redefine indicators in Beacon's communication. This repository is a collection of Malleable C2 profiles that you may use. These profiles work with Cobalt
- SkyBlueEternal/thinkphp-RCE-POC-Collection - thinkphp v5.x 远程代码执行漏洞-POC集合
- RenwaX23/XSS-Payloads - List of XSS Vectors/Payloads
- maddiestone/AndroidAppRE - Android App Reverse Engineering Workshop
- jdonsec/AllThingsSSRF - This is a collection of writeups, cheatsheets, videos, books related to SSRF in one single location
- Brucetg/App_Security
- theLSA/CS-checklist - PC客户端(C-S架构)渗透测试checklist / Client side(C-S) penetration checklist
- uknowsec/SharpDecryptPwd - 对密码已保存在 Windwos 系统上的部分程序进行解析,包括:Navicat,TeamViewer,FileZilla,WinSCP,Xmangager系列产品(Xshell,Xftp)。源码:https://github.com/RowTeam/SharpDecryptPwd
- aozhimin/iOS-Debug-Hacks - :dart: Advanced debugging skills used in the iOS project development process, involves the dynamic debugging, static analysis and decompile of third-party libraries. iOS 项目开发过程中用到的高级调试技巧,涉及三方库动态调试、静态分
- B3nac/Android-Reports-and-Resources - A big list of Android Hackerone disclosed reports and other resources.
- stars-one/ASCToolJar - Android Signature Crack Tool Jar 破解APK签名验证的jar包
- blaCCkHatHacEEkr/PENTESTING-BIBLE - articles
- slowmist/Knowledge-Base - Knowledge Base 慢雾安全团队知识库
- CTFTraining/CTFTraining - CTF Training 经典赛题复现环境
- uknowsec/Active-Directory-Pentest-Notes - 个人域渗透学习笔记
- Bypass007/Safety-Project-Collection - 收集一些比较优秀的开源安全项目,以帮助甲方安全从业人员构建企业安全能力。
- AxtMueller/Windows-Kernel-Explorer - A free but powerful Windows kernel research tool.
- Bypass007/Emergency-Response-Notes - 应急响应实战笔记,一个安全工程师的自我修养。
- Jack-Liang/kalitools - Kali Linux工具清单
- l0ss/Grouper2 - Find vulnerabilities in AD Group Policy
- aleenzz/MYSQL_SQL_BYPASS_WIKI - mysql注入,bypass的一些心得
- jeansgit/RedTeam - RedTeam资料收集整理
- aleenzz/Cobalt_Strike_wiki - Cobalt Strike系列
- Escapingbug/awesome-browser-exploit - awesome list of browser exploitation tutorials
- Voorivex/pentest-guide - Penetration tests guide based on OWASP including test cases, resources and examples.
- Stardustsky/SaiDict - 弱口令,敏感目录,敏感文件等渗透测试常用攻击字典
- findneo/Newbie-Security-List - 网络安全学习资料,欢迎补充
- xuanhun/HackingResource - “玄魂工作室--安全圈” 知识星球内资源汇总
- Harmoc/CTFTools - Personal CTF Toolkit
- 1135/1135-CobaltStrike-ToolKit - about CobaltStrike
- Snowming04/The-Hacker-Playbook-3-Translation - 对 The Hacker Playbook 3 的翻译。
- byt3bl33d3r/AnsiblePlaybooks - A collection of Ansible Playbooks that configure Kali to use Fish & install a number of tools
- Leezj9671/Pentest_Interview - 个人准备渗透测试和安全面试的经验之谈,和去部分厂商的面试题,干货真的满满~
- Micropoor/Micro8 - Gitbook
- AnyeDuke/Enterprise-Security-Skill - 用于记录企业安全规划,建设,运营,攻防的相关资源
- crazywa1ker/DarthSidious-Chinese - DarthSidious 中文版
- danTaler/detectionString - list of sql-injection and XSS strings
- im-bug/BlockChain-Security-List
- JoyChou93/sks - Security Knowledge Structure(安全知识汇总)
- V33RU/IoTSecurity101 - A Curated list of IoT Security Resources
- smgorelik/Windows-RCE-exploits - The exploit samples database is a repository for **RCE** (remote code execution) exploits and Proof-of-Concepts for **WINDOWS**, the samples are uploaded for education purposes for red and blue teams.
- NoorQureshi/kali-linux-cheatsheet - Kali Linux Cheat Sheet for Penetration Testers
- DictionaryHouse/The-Security-Handbook-Kali-Linux - A useful reference guide and a handbook of security basics for those starting out.
- r0ysue/OSG-TranslationTeam - 看雪iOS安全小组的翻译团队作品集合,如有勘误,欢迎斧正!
- myndtt/CTF-Site - 介绍一些CTF训练的站点
- DropsOfZut/awesome-security-weixin-official-accounts - 网络安全类公众号推荐,欢迎大家推荐
- johnnyDEP/cobaltstrike - cobalt strike stuff I have gathered from around github
- FabioBaroni/awesome-chinese-infosec-websites - A curated list of Chinese websites and personal blogs about ethical hacking and pentesting
- jiangsir404/Audit-Learning - 记录自己对《代码审计》的理解和总结,对危险函数的深入分析以及在p牛的博客和代码审计圈的收获
- 3gstudent/Pentest-and-Development-Tips - A collection of pentest and development tips
- KiriKira/vTemplate - v2ray的模板们
- JnuSimba/LinuxSecNotes - some learning notes about Linux Security
- phith0n/Mind-Map - 各种安全相关思维导图整理收集
- HSIS007/Useful_Websites_For_Pentester - This repository is to make life of the pentester easy as it is a collection of the websites that can be used by pentesters for day to day studies and to remain updated.
- CHYbeta/Code-Audit-Challenges - Code-Audit-Challenges
- crownpku/Awesome-Chinese-NLP - A curated list of resources for Chinese NLP 中文自然语言处理相关资料
- xtiankisutsa/awesome-mobile-CTF - This is a curated list of mobile based CTFs, write-ups and vulnerable apps. Most of them are android based due to the popularity of the platform.
- Alvin9999/new-pac - 翻墙-科学上网、自由上网、免费科学上网、免费翻墙、油管youtube、fanqiang、软件、VPN、一键翻墙浏览器,vps一键搭建翻墙服务器脚本/教程,免费shadowsocks/ss/ssr/v2ray/goflyway账号/节点,翻墙梯子,电脑、手机、iOS、安卓、windows、Mac、Linux、路由器翻墙、科学上网、youtube视频下载、美区apple id共享账号
- iMeiji/shadowsocks_install - Auto install shadowsocks server,thanks 秋水逸冰
- XeusHack/Awesome-Hacking-Practice - A curated list of websites and apps to help you practice hacking
- ptresearch/AttackDetection - Attack Detection
- Jermic/Android-Crack-Tool - 🐞Android crack tool For Mac
- Ettack/WebshellCCL - A python script help with webshell bypassing.
- SecWiki/sec-chart - 安全思维导图集合
- d30sa1/RootKits-List-Download - This is the list of all rootkits found so far on github and other sites.
- Naetw/CTF-pwn-tips - Here record some tips about pwn. Something is obsoleted and won't be updated. Sorry about that.
- Hack-with-Github/Powerful-Plugins - Powerful plugins and add-ons for hackers
- pandazheng/Threat-Intelligence-Analyst - 威胁情报,恶意样本分析,开源Malware代码收集
- Cryptogenic/Exploit-Writeups - A collection where my current and future writeups for exploits/CTF will go
-
JavaScript
- xwiki-labs/cryptpad - Collaborative office suite, end-to-end encrypted and open-source.
- twngo/cryptpad - Unity is Strength - Collaboration is Key - CryptPad is the zero knowledge realtime collaborative editor.
- blinksocks/blinksocks - A framework for building composable proxy protocol stack.
- zhangjikai/tools - Some useful tools
- lqzhgood/Rss2Weibo - 将 rss 流同步到 微博. 如 twitter facebook 等
- Unitech/pm2 - Node.js Production Process Manager with a built-in Load Balancer.
- ssbc/patchwork - A decentralized messaging and sharing app built on top of Secure Scuttlebutt (SSB).
- sensepost/wsproxy - A websocket proxy
- imsun/gh-feed - Generate RSS feed from GitHub Issues
- medcl/elasticsearch-rtf - elasticsearch中文发行版,针对中文集成了相关插件,方便新手学习测试.
- homerchen19/nba-go - 🏀 💻 The finest NBA CLI.
- LandGrey/dnstricker - A simple dns resolver of dns-record and web-record log server for pentesting
- malaohu/squid-with-net-speeder - SQUID Proxy with net speed
- contiv/auth_proxy - A proxy + UI server for Contiv which handles authentication (local users/LDAP/AD) + authorization (RBAC)
- squidproxy/squidproxy - squid 技術部署、客戶端(原創)提供
- AnarchyLinux/installer - Anarchy Linux - A simple and intuitive Arch Linux installer. https://anarchyinstaller.org/
- ha7ilm/openwebrx - Open source, multi-user SDR receiver software with a web interface
- beakerbrowser/beaker - An experimental peer-to-peer Web browser
- borgbackup/borgweb - Web UI for Borg Backup
- hound-search/hound - Lightning fast code searching made easy
- Tschaul/twister-react - proxy-based Twister client written with react-js
- alibaba/anyproxy - A fully configurable http/https proxy in NodeJS
- AInoob/NooBoss - NooBoss is an extension that handles your extensions like a boss!
- machengwei1024/Hexo-Theme-Life - Hexo Theme
- Rotonde/beaker - Rotonde client with user account combined(deprecated)
- reruin/ServerStockCheck - 库存检查工具
- dannyti/seedbox-from-scratch - Creating a seedbox on a Linux server
- mengskysama/rain - http://rain.mengsky.net
- justjavac/Flarum - Flarum - 优雅自由的 PHP 轻社区
- mikeal/webtorrent-element - WebTorrent HTML element.
- Notos/seedbox-from-scratch - Creating a seedbox on a Linux server
- QuickBox/QB - QuickBox is much more than a ‘seedbox installer script’, it is a simplistic approach to achieving easy seedbox and services management from a beautifully designed dashboard. Allowing users the ability
- xavier84/RatXaBox - Auto installation de ruTorrent avec rTorrent. Version "Seedbox-Manager Workflow"
- Meshiest/mrseedbox - [unmaintained] A Containerized Seedbox with Embedded Media Player
- Kerwood/Rtorrent-LXC - A Docker container with Rtorrent + Rutorrent.
- xcatliu/cqc - Code Quality Checker - Check your code quality by running one command.
- listen1/listen1_chrome_extension - one for all free music in china (chrome extension, also works for firefox)
- mapbox/link-hijacker - Hijack clicks on and within links, probably for client-side routing
- evilcos/xssor2 - XSS'OR - Hack with JavaScript.
- bugbountyforum/XSS-Radar
- sakurity/securelogin - This version won't be maintained!
- anttiviljami/browser-autofill-phishing - A simple demo of phishing by abusing the browser autofill feature
- ChromeDevTools/debugger-protocol-viewer - DevTools Protocol API docs—its domains, methods, and events
- egoist/eme - Elegant Markdown Editor.
- bryanph/GeistMap - An experimental personal knowledge base with a focus on connections
- nccgroup/wssip - Application for capturing, modifying and sending custom WebSocket data from client to server and vice versa.
- xbotao/hexo-admin-qiniu - 根据[email protected]进行修改,添加粘贴图片上传至七牛
- platformio/platformio-atom-ide - PlatformIO IDE for Atom: The next generation integrated development environment for IoT
- n0mad01/node.bittrex.api - No longer maintained
- sghaskell/Clustered-Single-Value-Map-Visualization - Splunk Custom Visualization
- cure53/DOMPurify - DOMPurify - a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify works with a secure default, but offers a lot of configurability and hooks. Demo:
- IonicaBizau/git-unsaved - :mag_right: Scan your projects directory for dirty git repositories.
- ryanhanwu/How-To-Ask-Questions-The-Smart-Way - 本文原文由知名 Hacker Eric S. Raymond 所撰寫,教你如何正確的提出技術問題並獲得你滿意的答案。
- llh911001/mostly-adequate-guide-chinese - 函数式编程指南中文版
- trim21-archive/sdu-mirror-website - 山大镜像站首页
- zcgonvh/LinkedServerPwdDumper - SqlServer Linked Password Dumper.
- jikeytang/front-end-collect - 分享自己长期关注的前端开发相关的优秀网站、博客、以及活跃开发者
- aweary/tinytime - ⏰ A straightforward date and time formatter in <1kb
- le4f/pcap-analyzer - online pcap forensic
- monkeym4ster/DomainFuzz - Domain name permutation engine for detecting typo squatting, phishing and corporate espionage
- Formstone/Formstone - Library of modular front end components.
- marknote/TeleShellBot - A simple Telegram Bot to run shell commands remotely
- ElaWorkshop/awesome-cn-cafe - A curated list of awesome coffee places for work in China.
- ksco/reblog - A blog system using GitHub Issues, powered by React + Redux.
- malaohu/Dply-Autobuild-Server - Dply.co自动创建服务器
- denysdovhan/wtfjs - 🤪 A list of funny and tricky JavaScript examples
- rozbo/blog - A super blog lite -- just one page. use vue with github api !
- barretlee/cloudflare-proxy - Cloudflare Worker 代理请求 ChatGPT API,支持 Stream 流式输出
- justjavac/chatgpt - ChatGPT 从入门到精通
- tess-ss/recon-ninja - Recon-Ninja
- system-cpu/wxappUnpacker - 基于node反编译小程序 已经配置完成
- laozhou-in-germany/Chens_LMS_Public - The LMS (Life Management System) is a free tool for personal knowledge management and goal management based on Obsidian.md.
- obsidian-canzi/Enhanced-editing - 旨在增强Obsidian编辑功能的插件
- Ghr07h/Heimdallr - 一款完全被动监听的谷歌插件,用于高危指纹识别、蜜罐特征告警和拦截、机器特征对抗
- Cryptogenic/PS5-IPV6-Kernel-Exploit - An experimental webkit-based kernel exploit (Arb. R/W) for the PS5 on <= 4.51FW
- lijiejie/EasyPen - EasyPen is a GUI program which helps pentesters do target discovery, vulnerability scan and exploitation
- wuba/Antenna - Antenna是58同城安全团队打造的一款辅助安全从业人员验证网络中多种漏洞是否存在以及可利用性的工具。其基于带外应用安全测试(OAST)通过任务的形式,将不同漏洞场景检测能力通过插件的形式进行集合,通过与目标进行out-bind的数据通信方式进行辅助检测。
- hjmmc/reverse-sourcemap-image - 还原souremap资源图片
- 0x727/Space_view - Space_view 是一款Hunter(鹰图平台)或者FOFA平台 资产展示的浏览器油猴插件
- evenchan86/Auto_BaseSecurity - 基线漏洞修复
- emredavut/Chrome-Android-and-Windows-0day-RCE-SBX - Chrome Android and Windows 0day RCE+SBX.. DPRK
- bp2008/DahuaLoginBypass - Chrome extension that uses vulnerabilities CVE-2021-33044 and CVE-2021-33045 to log in to Dahua cameras without authentication.
- sepehrdaddev/zap-scripts - Zed Attack Proxy Scripts for finding CVEs and Secrets.
- micro-joan/Zphisher-GUI-Back_office - A Zphisher GUI Back-Office Plugin
- S2eTo/FlawPlatform - 基于 Docker 开发的:在线漏洞靶场。
- netease-im/electron-fulltext-search-demo - electron 全文搜索方案的一个 demo
- 0xdea/frida-scripts - A collection of my Frida.re instrumentation scripts to facilitate reverse engineering of mobile apps.
- mrd0x/BITB - Browser In The Browser (BITB) Templates
- fkling/astexplorer - A web tool to explore the ASTs generated by various parsers.
- lgh06/web-page-monitor - Web Site Page Changes Monitor. 网站网页页面更新变更监控提醒。
- arcaneiceman/kraken - Kraken: A multi-platform distributed brute-force password cracking system
- ElSicarius/findalllinks - A tool to extract all the urls and paths found in the content of a page (js sources included)
- ipfs/js-ipfs - IPFS implementation in JavaScript
- OhYee/hexo-theme-indigo - 这个只是我修改的别人的,大家fork去原项目啊
- VitthalS/ivna - Intentionally Vulnerable Nodejs Application & APIs
- ttttmr/spoof-wappalyzer - 欺骗wappalyzer插件指纹识别&XSS
- What-The-Commit/nft-marketplaces-offer-bot - Automated mass bidding on opensea nft collections, with optional filtering by traits
- rogerinn/codex - Endpoint enumeration
- jayus0821/Armor - Armor 浏览器反蜜罐插件 honeypot
- apachecn/re4e-zh
- lxraa/v8_exp
- Abbbbbi/Frida-Seccomp - 一个Android通用svc跟踪以及hook方案——Frida-Seccomp
- bojue/BaseMap - IDC管理2.5D底图绘制工具(Vue)
- seemoo-lab/apple-continuity-tools - Reverse engineering toolkit for Apple's wireless ecosystem
- hanbinglengyue/FridaManager - Frida持久化解决方案
- Studio-42/elFinder - 📁 Open-source file manager for web, written in JavaScript using jQuery and jQuery UI
- caoyu48/vue-g6-editor - vue+g6 3.0实现的editor 由于g6-editor不开源 自己撸了一个
- NotSoSecure/SerializedPayloadGenerator
- JSREI/ast-hook-for-js-RE - 浏览器内存漫游解决方案(探索中...)
- d0gkiller87/Frida-libcurlUnpinning - A Frida script to bypass libcurl (NDK) SSL-Pinning protection in Android apps.
- paazmaya/shuji - Reverse engineering JavaScript and CSS sources from sourcemaps
- pownjs/git - Assorted tools for security-related task for git repositories
- SiJiDo/H - H是一款强大的资产收集管理平台
- 1in9e/gosint - Gosint is a distributed asset information collection and vulnerability scanning platform
- mucoze/Umay - IoT Malware Similarity Analysis Platform
- spamscanner/spamscanner - Spam Scanner is a Node.js anti-spam, email filtering, and phishing prevention tool and service. Built for @ladjs, @forwardemail, @cabinjs, @breejs, and @lassjs.
- wetools/wept - 微信小程序多端实时运行工具
- cjxe/dex-crawler - 🕷️ Monitor prices of tokens in different DEXs.
- malwareinfosec/FiddleZAP
- Ch0pin/log4JFrida
- evildecay/etcdkeeper - web ui client for etcd
- Reamd7/notion-zh_CN - notion 中文化
- zenozeng/Free-Chinese-Fonts - 免费中文字体
- I2rys/subenujs - Website Subdomains enumeration writen in NodeJS.
- louislam/uptime-kuma - A fancy self-hosted monitoring tool
- tintinweb/solidity-shell - An interactive Solidity Shell
- tophat-cloud/cumulus - Cumulus is web application weakness monitoring, works with just 3 code lines
- zhengjim/camille - 基于Frida的Android App隐私合规检测辅助工具
- Mustard404/Savior - 渗透测试报告自动生成工具!
- Raz0r/ens-xss
- 1modm/petereport - PeTeReport is an open-source application vulnerability reporting tool.
- HeiSir2014/M3U8-Downloader - M3U8-Downloader 支持多线程、断点续传、加密视频下载缓存。
- AsaiKen/dom-based-xss-finder - Chrome extension that finds DOM based XSS vulnerabilities
- TIGMINT/TIGMINT - TIGMINT: OSINT (Open Source Intelligence) GUI software framework
- zzzteph/weakpass - Weakpass collection of tools for bruteforce and hashcracking
- louischatriot/nedb - The JavaScript Database, for Node.js, nw.js, electron and the browser
- knqyf263/CVE-2021-40346 - CVE-2021-40346 PoC (HAProxy HTTP Smuggling)
- hql7/wl-explorer - 用于vue框架的文件管理器插件,云盘、网盘。File manager plug-in for vue framework, cloud disk.
- c-f/lel - Visualization layer and helper for relevant IT related documentation and operation
- pwnedshell/Bugs-feed - Bug's feed is a local hosted portal where you can search for the latest news, videos, CVEs, vulnerabilities...
- SKVNDR/FastDork - ⚡Chrome extension allows you to create lists of Google and Github dork to open multiple tabs with one click, import "scope/out of scope" from #HackerOne #Bugcrowd #Intigriti ...
- dushixiang/next-terminal - Next Terminal是一个简单好用安全的开源交互审计系统,支持RDP、SSH、VNC、Telnet、Kubernetes协议。
- phwd/fb-ios-pinning-2021
- nickdeis/eslint-plugin-no-secrets - An eslint plugin to find strings that might be secrets/credentials
- ConsenSys/aragraph - Visualize your Aragon DAO Templates
- NodeSecure/js-x-ray - JavaScript & Node.js open-source SAST scanner. A static analyser for detecting most common malicious patterns 🔬.
- threatexpress/aggressor-scripts - Cobalt Strike Aggressor Scripts
- Simp1er/MobileSec - 记录一些我自己在学习Android逆向过程中的有意思的东西
- r0ysue/r0tracer - 安卓Java层多功能追踪脚本
- mandatoryprogrammer/xsshunter-express - An easy-to-setup version of XSS Hunter. Sets up in five minutes and requires no maintenance!
- redpwn/rctf - redpwn's CTF platform
- momosecurity/FindSomething - 基于chrome、firefox插件的被动式信息泄漏检测工具
- Vulnogram/Vulnogram - Vulnogram is a tool for creating and editing CVE information in CVE JSON format
- secureCodeBox/secureCodeBox - secureCodeBox (SCB) - continuous secure delivery out of the box
- c6fc/warcannon - High speed/Low cost CommonCrawl RegExp in Node.js
- justakazh/FreeDa - just show app list and run frida with js
- nancheung/notion-zh_CN - 对notion.so的汉化油猴脚本
- HaboobLab/CVE-2019-13764
- reconmap/reconmap - Vulnerability assessment and penetration testing automation and reporting platform for teams.
- nklayman/vue-cli-plugin-electron-builder - Easily Build Your Vue.js App For Desktop With Electron
- yuzutech/kroki - Creates diagrams from textual descriptions!
- rafeca/prettyjson - Package for formatting JSON data in a coloured YAML-style, perfect for CLI output
- Yeuoly/FxxkXSS - 将令你眼前一亮的XSS利用工具!
- aquasecurity/cloudsploit - Cloud Security Posture Management (CSPM)
- willnewii/qiniuClient - 云存储管理客户端。支持七牛云、腾讯云、青云、阿里云、又拍云、亚马逊S3、京东云,仿文件夹管理、图片预览、拖拽上传、文件夹上传、同步、批量导出URL等功能
- Tencent/wepy - 小程序组件化开发框架
- lochv/shellbin - The source code of https://rshell.dev
- r0zar/shellshock - Yet another bash-inside-node framework
- jehy/shodan - Advanced error monitoring using kibana logs
- RPwnage/pwn-my - iOS 14.5 WebKit/Safari based Jailbreak
- mhmdiaa/acumen - A clean UI with a modular structure to enhance security researchers' ability to work with data
- Medicean/AS_Out-of-Network - AntSword 出网探测插件
- qingyeyun/icp-extensions - icp备案查询谷歌插件
- motikan2010/CVE-2021-29447 - WordPress - Authenticated XXE (CVE-2021-29447)
- darryk10/CVE-2021-25735 - Exploit CVE-2021-25735: Kubernetes Validating Admission Webhook Bypass
- farisv/Moodle-CVE-2019-3810 - Moodle (< 3.6.2, < 3.5.4, < 3.4.7, < 3.1.16) XSS PoC for Privilege Escalation (Student to Admin)
- singularseclab/Browser_Exploits - A collection of browser exploitation codes from Singular Security Lab.
- ForbiddenProgrammer/CVE-2021-21315-PoC - CVE 2021-21315 PoC
- dxcweb/watermark - canvas图片水印,用于身份证等个人信息添加仅用于XXX等字样保护个人信息
- CapacitorSet/box-js - A tool for studying JavaScript malware.
- eciavatta/caronte - A tool to analyze the network flow during attack/defence Capture the Flag competitions
- rayhan0x01/nodejs-websocket-sqli - A simple NodeJS WebSocket WebApp vulnerable to blind SQL injection
- ElSicarius/UnCommenteR - A chrome extension to uncomment hidden stuff in the html
- WithSecureLabs/android-keystore-audit
- swoops/eval_villain - A Firefox Web Extension to improve the discovery of DOM XSS.
- liath/CVE-2020-10977 - Gitlab v12.4.0-8.1 RCE
- noobpk/frida-ios-hook - A tool that helps you easy trace classes, functions, and modify the return values of methods on iOS platform
- kylesmile1103/Learn-Frida - Modding Unity app with Frida tutorial.
- lijiejie/swagger-exp - A Swagger API Exploit
- davtur19/DotGit - An extension for checking if .git is exposed in visited websites
- okoala/egg-jwt - JWT authentication plugin for egg
- bhattsameer/devtool-snippets-forhacks - Collection of snippets for devtools.
- r3curs1v3-pr0xy/vajra - Vajra is a highly customizable target and scope based automated web hacking framework to automate boring recon tasks and same scans for multiple target during web applications penetration testing.
- NorthwaveSecurity/fridax - Fridax enables you to read variables and intercept/hook functions in Xamarin/Mono JIT and AOT compiled iOS/Android applications.
- fyr77/dns-mobileconfig - A simple website to create DoH and DoT config files for iOS
- hzdu/setprograms - NodeJS、JDK、Python开发环境设置工具
- notion-enhancer/notion-enhancer - An enhancer/customiser for the all-in-one productivity workspace Notion
- RenwaX23/XSSTRON - Electron JS Browser To Find XSS Vulnerabilities Automatically
- avwo/whistle - HTTP, HTTP2, HTTPS, Websocket debugging proxy
- dreamyguy/gitlogg - 💾 🧮 🤯 Parse the 'git log' of multiple repos to 'JSON'
- thunderbarca/BlackStone - 一个基于docker,开箱即用的CTF竞赛平台
- iot-onboarding/mud-visualizer - mud-visualizer is a tool to visualize MUD files
- egoist/docute - 📚 Effortless documentation, done right.
- neXenio/adb-util - Electron app for Android developers, providing a GUI for common ADB operations
- otale/tale - 🦄 Best beautiful java blog, worth a try
- jasonsheh/SiteScan - A tool help get the basic information of one site
- suoyuesmile/suo-blog - :fox_face:技术博客文章、笔记、实战、技术探讨、资源收集等等
- novnc/noVNC - VNC client web application
- s7ckTeam/LeakFinder - LeakFinder(觅露)为s7ck Team 红队云武器库F-Box里的一款信息泄露浏览搜集浏览器插件。
- MariaGarber/XSS-Scanner - XSS scanner that detects Cross-Site Scripting vulnerabilities in website by injecting malicious scripts
- vercel/update-check - Minimalistic update notifications for command line interfaces
- arachnys/cabot - Self-hosted, easily-deployable monitoring and alerts service - like a lightweight PagerDuty
- qeeqbox/social-analyzer - API, CLI, and Web App for analyzing and finding a person's profile in 1000 social media \ websites
- abhijithvijayan/stargazed - 📋 Creating your own Awesome List of GitHub stars!
- enovella/fridroid-unpacker - Defeat Java packers via Frida instrumentation
- m0bilesecurity/Frida-Mobile-Scripts - Collection of useful FRIDA Mobile Scripts
- coffeehb/FridaHook - 记录学习Frida Hook时的知识点和小脚本
- siyujie/OkHttpLogger-Frida - Frida 实现拦截okhttp的脚本
- timwhitez/Doge-XSS-Phishing - xss钓鱼,cna插件配合php后端收杆
- gh0stkey/avList - avList - 杀软进程对应杀软名称
- yzddmr6/As-Exploits - 中国蚁剑后渗透框架
- muraenateam/necrobrowser - necromantic session control
- iamadamdev/bypass-paywalls-chrome - Bypass Paywalls web browser extension for Chrome and Firefox.
- dmitriz/cpsfy - 🚀 Tiny goodies for Continuation-Passing-Style functions, fully tested
- advanced-rest-client/arc-electron - Advanced REST Client - Desktop application
- Medicean/VSCodeXssEncode - Converts characters from one encoding to another using a transformation. This tool will help you encode payloads in testing sql injections, XSS holes and site security.
- SukkaW/nali-cli - :anchor: Parse geoinfo of IP Address without leaving your terminal
- hizzgdev/jsmind - a mind mapping library built by javascript
- SoftSec-KAIST/Fuzzing-Survey - The Art, Science, and Engineering of Fuzzing: A Survey
- samyk/webscan - Browser-based network scanner & local-IP detection
- jeverd/lecture-experience - :books: Liteboard.io - A lightweight browser-based lecturing platform using WebRTC :pencil2:
- buffermet/bug-bounty-tools - Collection of HTTP scanners and fuzzers.
- bonino97/LemonBooster-v2 - Reestructured LemonBooster.
- anuraghazra/github-readme-stats - :zap: Dynamically generated stats for your github readmes
- zadam/trilium - Build your personal knowledge base with Trilium Notes
- pwndoc/pwndoc - Pentest Report Generator
- msrkp/PPScan - Client Side Prototype Pollution Scanner
- coderzh/hugo-rapid-theme - A hugo theme as
- CatTail/rssify - Convert anything to rss feed
- xiongwilee/iblog - 基于Gracejs及github issues的全功能博客方案,参考:
- bonino97/API-Monitoring - Monitoring Subdomains, improve your recon.
- lanyulei/ferry - 本系统是集工单统计、任务钩子、权限管理、灵活配置流程与模版等等于一身的开源工单系统,当然也可以称之为工作流引擎。 致力于减少跨部门之间的沟通,自动任务的执行,提升工作效率与工作质量,减少不必要的工作量与人为出错率。
- Ar3h/anti-honeypot - 一款可以检测WEB蜜罐并阻断请求的Chrome插件,能够识别并阻断长亭D-sensor、墨安幻阵的部分溯源api
- dream-num/Luckysheet - Luckysheet is an online spreadsheet like excel that is powerful, simple to configure, and completely open source.
- Tencent/cloudbase-framework - 腾讯云开发云原生一体化部署工具 🚀 CloudBase Framework:一键部署,不限框架语言,云端一体化开发,基于Serverless 架构。A front-end and back-end integrated deployment tool. One-click deploy to serverless architecture. https://docs.cloudbase.net/
- Cherrison/CrackMinApp - (反编译微信小程序)一键获取微信小程序源码(傻瓜式操作), 使用了C#加nodejs制作
- davisjam/safe-regex - Detect possibly catastrophic, exponential-time regular expressions
- jzillmann/pdf-to-markdown - A PDF to Markdown converter
- maple3142/cf-warp
- facundoolano/app-store-scraper - scrape data from the itunes app store
- YMFE/yapi - YApi 是一个可本地部署的、打通前后端及QA的、可视化的接口管理平台
- RomaneeSean/xss-flash-fishing
- mdnice/markdown-nice - 支持主题设计的 Markdown 编辑器,让排版变 Nice
- ajinabraham/njsscan - njsscan is a semantic aware SAST tool that can find insecure code patterns in your Node.js applications.
- mike-goodwin/owasp-threat-dragon - An open source, online threat modelling tool from OWASP
- maltek/swift-frida - Frida library for interacting with Swift programs. Superseded by https://github.com/frida/frida-swift-bridge
- jangxx/netflix-1080p - Chrome extension to play Netflix in 1080p and 5.1
- punishell/bbtips - BugBountyTips
- mark-zh/BugBountyTips - 记录一些国外漏洞赏金猎人的挖洞技巧和一些有意思的东西
- hexploitable/r2con2020_r2frida - This repository houses the materials, slides and exercises from the r2con 2020 walkthrough sessions.
- danny0838/content-farm-terminator - Content Farm Terminator browser extension/「終結內容農場」瀏覽器套件
- notilus67/frider - Dump unpacked dex, trace/intercept Java/native function. Frida + adb + React +Django
- timwhitez/about-anti-honeypot - 关于蜜罐的一些微小的统计工作
- timqian/chinese-independent-blogs - 中文独立博客列表
- KilledByAPixel/OS13k - A Tiny OS and Mini Game Engine
- cnrstar/anti-honeypot - 一款可以检测WEB蜜罐并阻断请求的Chrome插件
- D00MFist/PersistentJXA - Collection of macOS persistence methods and miscellaneous tools in JXA
- PerimeterX/CVE-2020-6519
- iiiusky/AntiHoneypot-Chrome-simple - Chrome 蜜罐检测插件
- ossf/wg-best-practices-os-developers - The Best Practices for OSS Developers working group is dedicated to raising awareness and education of secure code best practices for open source developers.
- alanpeng/docker-training-psweb - docker-training-psweb
- Koenkk/zigbee2mqtt - Zigbee 🐝 to MQTT bridge 🌉, get rid of your proprietary Zigbee bridges 🔨
- node-red/node-red - Low-code programming for event-driven applications
- eip-work/kuboard-press - Kuboard 是基于 Kubernetes 的微服务管理界面。同时提供 Kubernetes 免费中文教程,入门教程,最新版本的 Kubernetes v1.23.4 安装手册,(k8s install) 在线答疑,持续更新。
- vernesong/OpenClash - A Clash Client For OpenWrt
- kingbase/wechat_history_export - 从 PC 端 (Windows) 不那么狼狈的阅读或导出微信公众号的历史文章
- donot-wong/sensinfor - A chrome extension use to find leak file and backup file.
- nkzawa/ast-scope - A JavaScript AST scope analyzer
- lirantal/cwe-sdk - A Common Weakness Enumeration (CWE) Node.js SDK compliant with MITRE / CAPEC
- hyj1991/easy-monitor - 企业级 Node.js 应用性能监控与线上故障定位解决方案
- nccgroup/singularity - A DNS rebinding attack framework.
- kautukkundan/Awesome-Profile-README-templates - A collection of awesome readme templates to display on your profile
- smiegles/extract-relative-url-heapsnapshot - Extract relative urls from a heap snapshot
- stevenvachon/broken-link-checker - Find broken links, missing images, etc within your HTML.
- monkeylord/XposedFridaBridge - A frida script implement XposedBridge & load xposed modules, without installing xposed framwork.
- terjanq/Tiny-XSS-Payloads - A collection of tiny XSS Payloads that can be used in different contexts. https://tinyxss.terjanq.me
- RhinoSecurityLabs/Swagger-EZ - A tool geared towards pentesting APIs using OpenAPI definitions.
- mindedsecurity/behave - Behave! A monitoring browser extension for pages acting as "bad boi"
- kgretzky/pwndrop - Self-deployable file hosting service for red teamers, allowing to easily upload and share payloads over HTTP and WebDAV.
- satazor/js-spark-md5 - Lightning fast normal and incremental md5 for javascript
- onblog/BlogHelper - 帮助国内用户写作的托盘助手,一键发布本地文章到主流博客平台(知乎、简书、博客园、CSDN、SegmentFault、掘金、开源中国),剪贴板图片一键上传至图床(新浪、Github、图壳、腾讯云、阿里云、又拍云、七牛云)(欢迎Star,🚫禁止Fork)
- TheKingOfDuck/logonTracer - Windows系统安全登录日志分析工具logonTracer汉化修正版
- tdr130/assetnote - Push notifications for passive DNS data
- auth0/repo-supervisor - Scan your code for security misconfiguration, search for passwords and secrets. :mag:
- shadow1ng/vanscan
- Qihoo360/doraemon - Doraemon is a Prometheus based monitor system
- TheMMMdev/simple-middleman - Simple NodeJS server meant to handle logged url information (like with chromer).
- si9int/gDork - A Mozilla Firefox extension which allows quick access to your google-dorking result
- makuga01/dnsFookup - DNS rebinding toolkit
- KuroLabs/stegcloak - Hide secrets with invisible characters in plain text securely using passwords 🧙🏻♂️⭐
- yeswehack/PwnFox - PwnFox is a Firefox/Burp extension that provide usefull tools for your security audit.
- 0x742/noia - [WIP] Simple mobile applications sandbox file browser tool. Powered with [frida.re](https://www.frida.re).
- LeadroyaL/friposed - Write java hook with frida
- apiaryio/dredd - Language-agnostic HTTP API Testing Tool
- ehrishirajsharma/SwiftnessX - A cross-platform note-taking & target-tracking app for penetration testers.
- DavidCatalan/fridacov - JS modules for Frida based tools to add code coverage to your instrumentation scripts.
- ChiChou/bagbak - Yet another frida based iOS dumpdecrypted. Also decrypts app extensions
- hakimel/reveal.js - The HTML Presentation Framework
- monkeylord/XServer - A Xposed Module for Android Penetration Test, with NanoHttpd.
- lasting-yang/frida_hook_libart - Frida hook some jni functions
- lasting-yang/frida_dump - frida dump dex, frida dump so
- gchq/CyberChef - The Cyber Swiss Army Knife - a web app for encryption, encoding, compression and data analysis
- star7th/showdoc - ShowDoc is a tool greatly applicable for an IT team to share documents online一个非常适合IT团队的在线API文档、技术文档工具
- eth0izzle/shhgit - Ah shhgit! Find secrets in your code. Secrets detection for your GitHub, GitLab and Bitbucket repositories.
- m0bilesecurity/RMS-Runtime-Mobile-Security - Runtime Mobile Security (RMS) 📱🔥 - is a powerful web interface that helps you to manipulate Android and iOS Apps at Runtime
- samhaxr/XXRF-Shots - XXRF Shots - Useful for testing SSRF vulnerability
- jobertabma/transformations
- Passer6y/CrawlerVuln - 一个NodeJS实现的漏扫动态爬虫
- mandatoryprogrammer/CursedChrome - Chrome-extension implant that turns victim Chrome browsers into fully-functional HTTP proxies, allowing you to browse sites as your victims.
- opnsec/postMessage-logger - Simple "postMessage logger" Chrome extension
- fransr/postMessage-tracker - A Chrome Extension to track postMessage usage (url, domain and stack) both by logging using CORS and also visually as an extension-icon
- ericalexanderorg/should-i-trust - OSINT tool to evaluate the trustworthiness of a company
- atmoner/githubFind3r
- wuchangming/spy-debugger - 微信调试,各种WebView样式调试、手机浏览器的页面真机调试。便捷的远程调试手机页面、抓包工具,支持:HTTP/HTTPS,无需USB连接设备。
- 0x0FB0/pulsar - Network footprint scanner platform. Discover domains and run your custom checks periodically.
- Caratacus/Crown - Based on SpringBoot2, Crown builds a rapidly developed web application scaffolding.
- tacesrever/frida-tsplugin - typescript autocomplete plugin for frida's java warpper
- Werneror/pekja - SRC情报收集管理系统
- wiwikuan/fast-srt-subtitle - Make SRT Caption Fast!!!!
- rewanthtammana/vuln-headers-extension - Firefox extension which parses the headers of all the requests which are being flowing through your firefox browser to detect for vulnerabilities.
- juice-shop/multi-juicer - Host and manage multiple Juice Shop instances for security trainings and Capture The Flags
- rohanrhu/gdb-frontend - ☕ GDBFrontend is an easy, flexible and extensible gui debugger. Try it on https://debugme.dev
- mitre-attack/tram - Threat Report ATT&CK™ Mapping (TRAM) is a tool to aid analyst in mapping finished reports to ATT&CK.
- cliclitv/ClicliPure - :snowman: CliCli Whrite. clicli 纯白
- 88250/baidu-netdisk-downloaderx - ⚡️ 一款图形界面的百度网盘不限速下载器,支持 Windows、Linux 和 Mac。已于 2020 年 4 月 15 日正式停用,源码仅用于程序员交流学习,细节请查看:关于停用 BND 的说明 https://ld246.com/article/1586956316578
- 546669204/fuck-debugger-extensions - javascript anti-anti debugging
- hakluke/weaponised-XSS-payloads - XSS payloads designed to turn alert(1) into P1
- fcavallarin/domdig - DOM XSS scanner for Single Page Applications
- DockerSecurityPlayground/DSP - A Microservices-based framework for the study of Network Security and Penetration Test techniques
- grigoritchy/pocs
- david3107/squatm3gator - Squatm3gator is a complete web solution based on the python tool squatm3, designed to enumerate available domains generated modifying the original domain name through different cybersquatting techniqu
- fofapro/fofa_view - FOFA Pro view 是一款FOFA Pro 资产展示浏览器插件,目前兼容 Chrome、Firefox、Opera。
- logicalhacking/DVHMA - Damn Vulnerable Hybrid Mobile App (DVHMA) is an hybrid mobile app (for Android) that intentionally contains vulnerabilities.
- goabstract/Awesome-Design-Tools - The best design tools and plugins for everything 👉
- MichaelWayneLIU/InfoScraper - 一个基于Electron的自动化Web资产探测工具,用于渗透前期的信息搜集工作
- andreafioraldi/frida-fuzzer - This experimetal fuzzer is meant to be used for API in-memory fuzzing.
- wultra/powerauth-admin - This reporitory was moved to https://github.com/wultra/powerauth-server repository
- feedhenry/mobile-security - FeedHenry Mobile Security
- FrenchYeti/dexcalibur - [Official] Android reverse engineering tool focused on dynamic instrumentation automation leveraging Frida. It disassembles dex, analyzes it statically, generates hooks, discovers reflected methods, s
- iddoeldor/frida-snippets - Hand-crafted Frida examples
- vincentcox/StaCoAn - StaCoAn is a crossplatform tool which aids developers, bugbounty hunters and ethical hackers performing static code analysis on mobile applications.
- dpnishant/appmon - Documentation:
- ant4g0nist/vegvisir - A browser based GUI for **LLDB** Debugger.
- cloakware-ctf/idascripts - Some IDA Python scripts for auto-analysis and a Hive-plot visualizer.
- haozi/xss-demo - 👮🏻♂️ XSS attack playground,there are answers in issues. XSS 攻防靶场,issues 有答案
- JonComo/anim - Quick JS program for creating animations
- geemo/huobi-robot - 火币合约自动交易机器人
- ttop5/to-be-slack - !!!【接口已停,没有数据】今日热榜,摸鱼神器。支持全平台:Web、PC、Mobile 及 Chrome 插件。
- horsicq/Detect-It-Easy - Program for determining types of files for Windows, Linux and MacOS.
- naptha/tesseract.js - Pure Javascript OCR for more than 100 Languages 📖🎉🖥
- seccubus/seccubus - Easy automated vulnerability scanning, reporting and analysis
- abhi-r3v0/Adhrit - Android Security Suite for in-depth reconnaissance and static bytecode analysis based on Ghera benchmarks.
- radenvodka/massc - Subdomain Scanner Tools with word-lists
- SecurityPaper/SecurityPaper-web - Security Paper
- r00tSe7en/Fake-flash.cn - flash.cn钓鱼页(中文+英文)
- apachecn/howtodoinjava-zh - :book: [译] HowToDoInJava 中文系列教程
- cn-panda/JavaCodeAudit - Getting started with java code auditing 代码审计入门的小项目
- evil-huawei/evil-huawei - Evil Huawei - 华为作过的恶
- AloneMonkey/frida-ios-dump - pull decrypted ipa from jailbreak device
- aws-samples/aws-serverless-security-workshop - In this workshop, you will learn techniques to secure a serverless application built with AWS Lambda, Amazon API Gateway and RDS Aurora. We will cover AWS services and features you can leverage to imp
- axipo/pdfTranslator - 一个具有划词翻译功能的跨平台pdf阅读器,用着挺好用开源一下造福众科研人员,欢迎star
- viva-frida/Awesome-Frida-UI - this tool for beginner , and make easier to use this
- tobilg/aws-fullstack-website - Deploy your fullstack websites without all the hassle on AWS with CloudFront, S3, ACM, Route53, API Gateway and Lambda via Serverless.
- unbug/codelf - A search tool helps dev to solve the naming things problem.
- iptv-org/iptv - Collection of publicly available IPTV channels from all over the world
- fengbindev/Quella - Quella是基于SSM+shiro+redis开发的后台脚手架,集成了一些后台通用功能,并集成了一些常用的第三方服务。
- zhongshaofa/layuimini - 后台admin前端模板,基于 layui 编写的最简洁、易用的后台框架模板。只需提供一个接口就直接初始化整个框架,无需复杂操作。
- xiandanin/magnetW - [已失效,不再维护]
- phith0n/xray-poc-generation - 🧬 辅助生成 XRay YAML POC
- pownjs/duct - Essential tool for finding blind injection attacks.
- apachecn/calc4b-zh - :book: [译] MIT 18.03 面向初学者的微积分
- flutterchina/flutter-in-action - 《Flutter实战》书稿。第二版书稿已上传,请移步新Repo。
- xtuJSer/CoCoMusic - a simple music player built by electron and vue
- blinkfox/hexo-theme-matery - A beautiful hexo blog theme with material design and responsive design.一个基于材料设计和响应式设计而成的全面、美观的Hexo主题。国内访问:http://blinkfox.com
- TyCoding/boot-chat - :bookmark: 基于SpringBoot + WebSocket的在线聊天系统,实现单窗口消息推送、群消息推送、上线提醒、Redis会话消息储存
- wangai3176/webug4.0 - webug4.0
- jeffjose/tget - tget is wget for torrents
- makazeu/steam-key - Online activation tool for Steam.
- Magicskys/Kiddy - 被动式扫描器
- showdownjs/showdown - A bidirectional Markdown to HTML to Markdown converter written in Javascript
- Louiszhai/tool - 开发效率提升:Mac生产力工具链推荐
- lyricat/wechat-format - 微信公众号排版编辑器,转换 Markdown 到微信特制的 HTML
- gitalk/gitalk - Gitalk is a modern comment component based on Github Issue and Preact.
- jack-hoo/LiveRoomDemo_Client - 自己动手打造一个直播间(视频直播、聊天室、弹幕、多端适配)
- jack-hoo/LiveRoomDemo_Server - 自己动手打造一个直播间(视频直播、聊天室、弹幕、多端适配)
- virink/as_plugin_godofhacker - 黑客神器,谁用谁知道!
- starrtc/starrtc-edu-demo - web版本在线教育与白板演示示例,更多示例请参见:
- webxscan/linux_rat - LINUX集群控制(LINUX反弹式远控) LINUX反向链接运维 BY:QQ:879301117
- zhaoolee/ChromeAppHeroes - 🌈谷粒-Chrome插件英雄榜, 为优秀的Chrome插件写一本中文说明书, 让Chrome插件英雄们造福人类~ ChromePluginHeroes, Write a Chinese manual for the excellent Chrome plugin, let the Chrome plugin heroes benefit the human~ 公众号「0加1」同步更新
- lqs469/confluence-export - Export document from confluence with nice style
- nondanee/UnblockNeteaseMusic - Revive unavailable songs for Netease Cloud Music
- nondanee/vsc-netease-music - UNOFFICIAL Netease Music extension for Visual Studio Code
- Tinywan/H5-dash-hls-rtmp-webrtc - :sunflower: 传统直播:HTML5播放器、M3U8直播/点播、RTMP直播、低延迟、推流/播流地址鉴权。:green_apple: 实时直播:WebRTC
- gwuhaolin/reflv - react component wrap flv.js
- archerysec/archerysec - ASOC, ASPM, DevSecOps, Vulnerability Management Using ArcherySec.
- PrettyUp/Security-Baseline - Linux安全基线扫描、报告生成与自动修复程序
- s0md3v/AwesomeXSS - Awesome XSS stuff
- bilibili-helper/bilibili-helper-o - 哔哩哔哩 (bilibili.com) 辅助工具,可以替换播放器、推送通知并进行一些快捷操作
- foru17/front-end-collect - 分享自己长期关注的前端开发相关的优秀网站、博客、以及活跃开发者
- phodal/new-project-checklist - 🥳🥳🥳🥳 a checklist & tool for new project setup for developer. 新项目检查清单及其工具。
- agalwood/Motrix - A full-featured download manager.
- CAT-Team-mmc/lysec - 一个基于docker的安全培训系统
- 0verSp4ce/PoCBox - PoCBox - Vulnerability Test Aid Platform
- d2-projects/d2-admin - An elegant dashboard
- EmpireProject/Empire-GUI - Empire client application
- cbdyzj/cbdyzj.github.io - jianzhao.org
- r00tSe7en/GoogleHackingTool - 在线Google Hacking 小工具
- xiaohanyu/blog-html-to-pdf - [Fun] A sample program to convert blog website to merged pdf.
- VKSRC/Github-Monitor - Github Sensitive Information Leakage Monitor(Github信息泄漏监控系统)
- TerryZ/v-region - 提供 5 种应用形式的 4 级行政区划选择器 A simple region cascade selector, provide 4 levels Chinese administrative division data
- GitSquared/edex-ui - A cross-platform, customizable science fiction terminal emulator with advanced monitoring & touchscreen support.
- sherylynn/pdf-sync - PDF Reader in JavaScript with Sync
- stephentian/33-js-concepts - :scroll: 每个 JavaScript 工程师都应懂的33个概念 @leonardomso
- dongyuanxin/webpack-demos - 📦 Demos && Courses for Webpack 4
- izuolan/zresume - 程序员简历生成器(可导出静态页面、支持密码验证访问)
- HyperSimon/bookmarks-2-markdown - A Chrome extension for exporting bookmarks as markdown
- MrSorrow/taotao - IDEA版本淘淘商城
- TevinLi/amWiki - amWiki 是一款由 JS 开发、依赖 Atom 或 Nodejs-Npm 的 Markdown 轻量级前端化开源文库系统
- mengkunsoft/MKOnlineMusicPlayer - ⛔【停止维护】一个在线音乐播放器(仅 UI,无功能)
- hacksalot/HackMyResume - Generate polished résumés and CVs in HTML, Markdown, LaTeX, MS Word, PDF, plain text, JSON, XML, YAML, smoke signal, and carrier pigeon.
- OXOYO/bookmark2md - Convert chrome bookmarks to md files and push them to GitHub repository.
- apachecn/apachecn-algo-zh - ApacheCN 数据结构与算法译文集
- EthanLin-TWer/translation-spring-mvc-4-documentation - Spring MVC 4.2.4 RELEASE 中文文档完整翻译稿
- codeskyblue/gosuv - Deprecated!!! Process managerment writtern by golang, inspired by python-supervisor
- quincyyhuang/hexo-node-admin - A Hexo management tool with responsive UI designed to make it easier for you to compose.
- Medicean/GenShell - AntSword Generate Shell Plugin
- yincongcyincong/proxy-web - proxy-web is a webview proxy application written by Golang
- phpservermon/phpservermon - PHP Server Monitor
- kern/filepizza - :pizza: Peer-to-peer file transfers in your browser
- csbun/thal - 译文:Puppeteer 与 Chrome Headless —— 从入门到爬虫
- Tsuk1ko/pxder - 🖼 Download illusts from pixiv.net P站插画批量下载器
- aui/font-spider - Smart webfont compression and format conversion tool
- J3-Tech/Office-Document-Converter - Office Document Convertor (ODC) is an online convertor for office document which runs as a web service. Its aim is to provide the facility of converting almost all office documents into image which ma
- ning1022/SQLInjectionWiki - 一个专注于聚合和记录各种SQL注入方法的wiki
- RASSec/A_Scan_Framework - Network Security Vulnerability Manage
- RASSec/cve.wang - bug公开平台
- aksakalli/gtop - System monitoring dashboard for terminal
- WebGoat/WebGoat - WebGoat is a deliberately insecure application
- geeeeeeeeek/electronic-wechat - :speech_balloon: A better WeChat on macOS and Linux. Built with Electron by Zhongyi Tong.
- cablej/FileChangeMonitor - Continuous monitoring for JavaScript files
- Toninie/github-blog - blog base on Vue.js and Github API
- zmzhang8/Photon - A lightweight multi-threaded downloader based on aria2.
- mriiiron/salvia - A minimum-building static blog framework.
- ShawnZeng1996/Memory - A theme for wordpress.
- bingohuang/docker-labs - Docker在线实验室
- axt/cfg-explorer - CFG explorer for binaries
- carlos-wong/cerebro-codelf - ⭐️ 给变量起名的事情上,为你生命省 3s (Save 3 seconds of your life when naming things.)
- cerebroapp/cerebro - 🔵 Cerebro is an open-source launcher to improve your productivity and efficiency
- Warflop/FireShodanMap - FireShodanMap is a Realtime map that integrates Firebase, Google Maps and Shodan. A search is carried out using Shodan searching vulnerable devices and they are showed on the map for analysis. All dat
- hustcc/aliyun-oss-deploy - 🙈 一个 nodejs 命令行工具,用于部署静态资源到 aliyun oss,支持代码方式和 CLI 方式!
- noahziheng/sdeploy-cli - A light development tool using SCP,SFTP and RSync
- axetroy/blog - :open_book:基于Github API 的动态博客
- denghongcai/forsaken-mail - a self-hosted disposable mail service
- malaohu/forsaken-mail - a self-hosted disposable mail service
- runningcheese/RunningCheese-Firefox - A Graceful and Powerful Customized Firefox
- jae-jae/Camtd - Chrome multi-threaded download manager extension,based on Aria2 and AriaNg. Chrome多线程下载扩展。
- s9w/font_compare - Programming font comparison
- be5invis/Sarasa-Gothic - Sarasa Gothic / 更纱黑体 / 更紗黑體 / 更紗ゴシック / 사라사 고딕
- aliyun/oss-browser - OSS Browser 提供类似windows资源管理器功能。用户可以很方便的浏览文件,上传下载文件,支持断点续传等。
- geekcompany/DeerResume - MarkDown在线简历工具,可在线预览、编辑和生成PDF。[此项目已不再维护,建议使用 cv.ftqq.com 替代 ]
- marktext/marktext - 📝A simple and elegant markdown editor, available for Linux, macOS and Windows.
- UbuntuBar/userguide - Ubuntu 吧用户指南
- open-source-translation/AWVS11.X-Chinese-Version - AWVS11.X汉化包|AWVS11.X-Chinese-Version
- reruin/sharelist - 快速分享 GoogleDrive OneDrive
- liyangready/multiple-host - 虚拟host解决方案,轻松实现两套host环境
- listen1/listen1_desktop - one for all free music in china (Windows, Mac, Linux desktop)
- KaTeX/KaTeX - Fast math typesetting for the web.
- creditease-sec/insight - 洞察-宜信集应用系统资产管理、漏洞全生命周期管理、安全知识库管理三位一体的平台。
- IceEnd/Yosoro - :shaved_ice:Beautiful Markdown NoteBook. 🏖
- jax777/scan_monitor - ip 域名 端口扫描 服务刺探 单机版
- securing/gattacker - A Node.js package for BLE (Bluetooth Low Energy) security assessment using Man-in-the-Middle and other attacks
- chinese-poetry/chinese-poetry - The most comprehensive database of Chinese poetry 🧶最全中华古诗词数据库, 唐宋两朝近一万四千古诗人, 接近5.5万首唐诗加26万宋诗. 两宋时期1564位词人,21050首词。
- ALEXZZZ9/PS4-5.01-WebKit-Exploit-PoC - PS4 5.01 WebKit Exploit PoC
- brookhong/Surfingkeys - Map your keys for web surfing, expand your browser with javascript and keyboard.
- wspl/CIDR-in-Proxifier - :tea: A script for converting CIDRs list to configuration file segment of Proxifier.
- carbon-app/carbon - :black_heart: Create and share beautiful images of your source code
- lukechilds/reverse-shell - Reverse Shell as a Service
- neargle/win-powerup-exp-index - 🚄 火车上写的,2015年的代码和数据了
- chaozh/awesome-blockchain-cn - 收集所有区块链(BlockChain)技术开发相关资料,包括Fabric和Ethereum开发资料
- 0x0ade/rotonde-client - Rotonde Base Client
- Rotonde/rotonde-client - Rotonde Base Client
- zhuzhuyule/HexoEditor - this markdown Editor for hexo blog
- zkat/cipm - standalone ci-oriented package installer for npm projects (moved)
- amhoho/electron-cn-docs - Electron中文文档! 精心翻译,完美排版,实时同步更新!, 最后同步:2017-05-23(个人比较忙,本项目已经不再维护了)
- yuzd/ClearScript.Manager - Use tern.js in .netcontext 重构原有代码,require dll js等功能
- bradoyler/xmr-miner - Web-based Cryptocurrency miner, built with Vue.js
- lqmeta/Cube-In-Electron - :octocat:A cross-platform web music player in Electron.
- stkevintan/Cube - A cross-platform web music player in nw.js
- htfy96/v2ray-config-gen - V2Ray Configuration generator
- ciqulover/CMS-of-Blog - deprecated
- wpyok500/Google-IPs - :us: Google 全球 IP 地址库
- Or3stis/apparatus - A graphical security analysis tool for IoT networks
- dryabov/twister-webkit - webkit package for twister
- MobSF/Mobile-Security-Framework-MobSF - Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework capable of performing static and
- azu/codemirror-anywhere - [Greasemonkey] Use CodeMirror editor instead of textarea in anywhere
- frida/frida-java-bridge - Java runtime interop from Frida
- imsun/gitment - A comment system based on GitHub Issues.
- xsank/xpath_tester - Demo
- DIYgod/APlayer - :lollipop: Wow, such a beautiful HTML5 music player
- FrankFang/wheels - Create wheels in the dumbest way
- iagox86/h2gb-ui
- firesunCN/My_CTF_Challenges - :fire::sunny:
- leanote/leanote - Not Just A Notepad! (golang + mongodb) http://leanote.org
- lockfale/OSINT-Framework - OSINT Framework
- acgpiano/wooyun-node - wooyun.org
- kevana/ui-for-docker - A web interface for Docker, formerly known as DockerUI. This repo is not maintained
- MicrosoftEdge/magic-mirror-demo - A :zap:Magic Mirror:zap: powered by a UWP Hosted Web App :rocket:
- ziahamza/webui-aria2 - The aim for this project is to create the worlds best and hottest interface to interact with aria2. Very simple to use, just download and open index.html in any web browser.
- martinsbalodis/web-scraper-chrome-extension - Web data extraction tool implemented as chrome extension
- derhuerst/tcp-over-websockets - Tunnel TCP through WebSockets.
- e2email-org/e2email - E2EMail is a simple Chrome application - a Gmail client that exchanges OpenPGP mail.
- aimer1124/JianshuSpider - Use Node.js,HighChart,BootStrap,Mongo,Cucumber with Gulp to scrapy information from Jianshu.
- cnwhy/lib-qqwry - 用NodeJS解析纯真IP库(QQwry.dat) 支持IP段查询
- keeweb/keeweb - Free cross-platform password manager compatible with KeePass
- wzyy2/PiBox - PiBox is a web control Interface written to control Embedded Board(Raspberry Pi).
- 52cik/github-hans - [废弃] {官方中文马上就来了} GitHub 汉化插件,GitHub 中文化界面。 (GitHub Translation To Chinese)
- TingGe/calibration-box - 图片标定:一个 Fabric 的小插件,可用于标定图片中车辆、人、交通灯标识、区域等。
- gavinkwoe/weapp-ide-crack - 【应用号】IDE + 破解 + Demo
- google/WebFundamentals - Former git repo for WebFundamentals on developers.google.com
- FredWe/How-To-Ask-Questions-The-Smart-Way - Any update requests plz redirect to original --->
- Tencent/WeFlow - A web developer workflow tool by WeChat team based on tmt-workflow, with cross-platform supported and environment ready.
- jakubfiala/atrament.js - A small JS library for beautiful drawing and handwriting on the HTML Canvas.
- vuejs/vue-hackernews-2.0 - HackerNews clone built with Vue 2.0, vue-router & vuex, with server-side rendering
- shimohq/chinese-programmer-wrong-pronunciation - 中国程序员容易发音错误的单词
- aosabook/500lines - 500 Lines or Less
- Lmnoppy/Scrippy - Scrippy is a browser extension that holds sql statements (think clip board) to aid devlopers in the testing of websites for basic code injections.
- mandatoryprogrammer/xsshunter - The XSS Hunter service - a portable version of XSSHunter.com
- dragthor/xss-scanner - Cross-Site Scripting (XSS) scanner. This tool helps to find possible XSS vulnerabilities. Cross platform - macOS, Linux, and Windows.
- lixiangwei/xsser - xss监控(xss monitor)
- jiang890910bo/back_manager - Paladin是啥? 它是一个以JFinal为底层的java基础后台框架。 结合了以下第三方组件: Beetl、Druid、Shiro、Ehcache(JFinal自带有工具类)。 界面使用的拼图的后台模板,自己做了些优化和更改。 最初目的:为了学习jfinal,通过一点点的摸索,把它建立起来了。 最终理想:形成一个工作中比较通用的基础后台框架。 适用人群 刚入门JFinal的同学,
- ycosine/DataVistual - 数字校园项目-大数据可视化平台
- doumengyu/The-FlowingData-Guide - 自己整理的《鲜活的数据——数据可视化指南》一书的笔记,还有自己根据书中的讲解,整理出的各章代码。
- RodgerLai/nodejs-nedb-excel - 基于nodejs+webpack,以nosql轻量级嵌入式数据库nedb作为存储,页面渲染采用react+redux,样式框架为ant design,实现了excel表格上传导出以及可视化
- jinjianhua727/log-date-view - 日志数据可视化
- tutuxxx/csv2dv - 将csv数据转换成可视化所需的数据格式
- SunshowerC/lagou-spider-data-handle - 拉勾数据处理,echarts数据可视化
- walkdoer/Life-Time-Tracker - 个人时间跟踪,可视化个人活动数据,管理个人生活,利用过去来指导未来,基于柳比歇夫的统计方法
- yexiaochai/medlog - 数据可视化系统,持续迭代,包括前端采集+数据设计+大数据存储+可视化展示几个大块
- TingGe/data-visualization - 数据可视化
- Easonzero/Compiler - 哈工大编译原理实验,使用node语言,实现了基于状态转换机制的词法分析器,以及自顶而下分析的语法分析器,gui基于electron&angular制作,数据可视化使用的是d3.js。
- khrome/ascii-art - A Node.js library for ansi codes, figlet fonts, ascii art and other ASCII graphics
- TongchengOpenSource/AppScan - 安全隐私卫士(AppScan)一款免费的企业级自动化App隐私合规检测工具。
- OffcierCia/DeFi-Developer-Road-Map - DeFi Developer roadmap is a curated Developer handbook which includes a list of the best tools for DApps development, resources and references!
- projectdiscovery/nuclei-templates - Community curated list of templates for the nuclei engine to find security vulnerabilities.
- Johnng007/Live-Forensicator - A suite of Tools to aid Incidence Response and Live Forensics for - Windows (Powershell) | Linux (Bash) | MacOS (Shell)
- its-a-feature/Mythic - A collaborative, multi-platform, red teaming framework
- hug-sun/element3 - A Vue.js 3.0 UI Toolkit for IT Education. Build with JS&TS
- en0th/ElectricRat - 电气鼠靶场系统是一种带有漏洞的Web应用程序,旨在为Web安全渗透测试学习者提供学习和实践的机会。The Electrical Mouse Target Range System is a web application with vulnerabilities designed to provide learning and practice opportunities for web secu
- westinyang/unpacker-panel - 基于Youpk脱壳机的一键脱壳Web面板
- windy-purple/uni_app-Packet-capture - uni_app抓包脚本
- echo094/decode-js - JS混淆代码的AST分析工具 AST analysis tool for obfuscated JS code
- hacksysteam/CVE-2023-21608 - Adobe Acrobat Reader - CVE-2023-21608 - Remote Code Execution Exploit
- RASSec/MobileCTF - 体系化、实战化、step by step、目标清晰且具体的一个打怪升级、成长路径规划图
- harrozze/obsidian-section-collector - Obsidian user script to collect same section in notes into one view
- akl7777777/ShellGPT - **ShellGPT is a free chatgpt client, now Supported online search.no need for a key, no need to log in.Multi-node automatic speed measurement switch,Long text translation with no word limit, AI graphic
- tongcheng-security-team/NextScan - 飞刃是一套完整的企业级黑盒漏洞扫描系统,集成漏洞扫描、漏洞管理、扫描资产、爬虫等服务。 拥有强大的漏洞检测引擎和丰富的插件库,覆盖多种漏洞类型和应用程序框架。
- josStorer/chatGPTBox - Integrating ChatGPT into your browser deeply, everything you need is here
- Yuukimoe/report-helper - 提交漏洞报告小助手, 通过 URL 获取目标信息并自动填充到补天
- GhostTroops/AiCSA - GPT AiCSA(Code security audit),SAST(Static Application Security Testing,静态应用程序安全测试),JAR security analysis, static vulnerability and vulnerability analysis of various programming language codes
- karthi-the-hacker/crlfi - CRLF Bug scanner for WebPentesters and Bugbounty Hunters
- noobpk/frida-intercept-encrypted-api - A tool to help you intercept encrypted APIs in iOS or Android apps
- hanc00l/nemo_go - Nemo是用来进行自动化信息收集的一个简单平台,通过集成常用的信息收集工具和技术,实现对内网及互联网资产信息的自动收集,提高隐患排查和渗透测试的工作效率。
- openprotest/protest - A management base for System Admins
- Consensys/aragraph - Visualize your Aragon DAO Templates
- jychp/cloudflare-bypass - Bypass Coudflare bot protection using Cloudflare Workers
- rpwnage/pwn-my - iOS 14.5 WebKit/Safari based Jailbreak
- tcc0lin/Review_Reverse
- dolevf/Damn-Vulnerable-GraphQL-Application - Damn Vulnerable GraphQL Application is an intentionally vulnerable GraphQL service implementation designed for learning about and practising GraphQL Security.
- wrlu/FridaHookUniversal - An universal frida hook project
- ohroy/blog - A super blog lite -- just one page. use vue with github api !
- cryptpad/cryptpad - Collaborative office suite, end-to-end encrypted and open-source.
- jakubfiala/atrament - A small JS library for beautiful drawing and handwriting on the HTML Canvas.
- yetone/bob-plugin-openai-translator - 基于 ChatGPT API 的文本翻译、文本润色、语法纠错 Bob 插件,让我们一起迎接不需要巴别塔的新时代!
- jonathandata1/ios_15_rce - Remote Code Execution V1 For iOS 15 sent through airdrop after the device was connected to a trusted host
- apsdehal/awesome-ctf - A curated list of CTF frameworks, libraries, resources and softwares
- laulzgoay/BTPanel-DIY-Template - BTPanel-DIY-Template
- wappalyzer/wappalyzer - Identify technology on websites.
- src-kun/solr-sgk - 大数据社工裤 demo
- viatsko/awesome-vscode - 🎨 A curated list of delightful VS Code packages and resources.
- ooowennn/toolbox - 企业微信 ChatGPT 机器人
- iAJue/note - 萌音云笔记 - 一个高效的在线云笔记、专注技术文档在线创作、阅读、分享和托管
- jaywcjlove/awesome-mac - Now we have become very big, Different from the original idea. Collect premium software in various categories.
- lasting-yang/frida_bypass_ssl_example - frida 辅助抓包的一些技巧
- admin360bug/upload-labs - 原始靶场环境:https://github.com/c0ny1/upload-labs 此项目原始靶场环境的开普勒安全团队修改版,重新使用PHP7编写,并且保留了原版的风味!
- DragonJAR/Scripts - Una serie de scripts útiles en un proceso de pentesting.
- abhijithvijayan/web-extension-starter - 🖥🔋Web Extension starter to build "Write Once Run on Any Browser" extension
- CreditTone/hooker - 🔥🔥hooker是一个基于frida实现的逆向工具包。为逆向开发人员提供统一化的脚本包管理方式、通杀脚本、自动化生成hook脚本、内存漫游探测activity和service、firda版JustTrustMe、disable ssl pinning
- benso-io/posta - 🐙 Cross-document messaging security research tool powered by https://enso.security
- mickael-kerjean/filestash - 🦄 A file manager / web client for SFTP, S3, FTP, WebDAV, Git, Minio, LDAP, CalDAV, CardDAV, Mysql, Backblaze, ...
- jiangqizheng/BlueSea - BlueSea,一个有趣的英语学习扩展,支持划词翻译、单词高亮、单词弹幕、记忆曲线复习、词频统计...
- 675354981/JR-scan - 利用python3写的综合扫描工具,可“一键”实现基本信息收集(端口、敏感目录、WAF、服务、操作系统、子域名),支持POC扫描(可自行添加POC,操作简单),支持利用AWVS探测(需使用API接口),未来争取实现xray联动。
- zmister2016/MrDoc - mrdoc,online document system developed based on python. It is suitable for individuals and small teams to manage documents, wiki, knowledge and notes. 觅思文档,适合于个人和中小型团队的在线文档、知识库系统。
- openspug/spug - 开源运维平台:面向中小型企业设计的轻量级无Agent的自动化运维平台,整合了主机管理、主机批量执行、主机在线终端、文件在线上传下载、应用发布部署、在线任务计划、配置中心、监控、报警等一系列功能。
- lazy-luo/smarGate - 内网穿透,c++实现,无需公网IP,小巧,易用,快速,安全,最好的多链路聚合(p2p+proxy)模式,不做之一...这才是你真正想要的内网穿透工具!
- monkeym4ster/find-subdomains - Abusing Certificate Transparency logs for getting HTTPS websites subdomains. (通过 HTTPS 证书透明日志,以 **非字典爆破** 的方式获取网站子域名。)
- 78778443/permeate - 一个用于渗透透测试演练的WEB系统,用于提升寻找网站能力,也可以用于web安全教学
- 1c7/Crash-Course-Computer-Science-Chinese - :computer: 计算机速成课 | Crash Course 字幕组 (全40集 2018-5-1 精校完成) B站播放量 383万
- trazyn/ieaseMusic - 网易云音乐第三方
- njwangchuan/schoidbot - schoidbot is a twitter bot with rss feeds. 二次元Twitter新闻机器人
- mumuy/relationship - 中国亲戚关系计算器 - 家庭称谓/亲戚称呼/称呼计算/辈分计算/亲戚关系算法/親戚稱呼計算機_Chinese kinship system.
- fei-ke/WeiboImageReverse - Chrome 插件,反查微博图片po主
- overcache/VRouter - 一个基于 VirtualBox 和 openwrt 构建的项目, 旨在实现 macOS / Windows 平台的透明代理.
- martinzhou2015/SRCMS - SRCMS企业应急响应与缺陷管理系统
- veniversum/git-visualizer - 👁🗨:octocat:Visualizes directory structure of GitHub repos
- TuuuNya/GenPass - 用Vue.js给健忘的女票写的在线密码生成器。
- fwon/electron-anyproxy - 📢 A http/https proxy client, using to analyze and mock.
- eteplus/vue-sui-demo - 用vue 和 SUI-Mobile 写了一个移动端demo,用来反馈学习vue的成果(禁用了SUI自带的路由,使用vue-router, vue-resource, webpack)[a web app written by vue & sui-mobile]
- jichengyue/SailsAdmin - 利用nodejs sails框架搭建的权限管理系统和数据可视化界面的B/S
- noobpk/frida-ios-intercept-api - A tool to help you intercept encrypted APIs in iOS apps
- veniware/OpenProtest - A management base for System Admins and IT professionals. Provides tools for documentation and troubleshooting.
- resilience-jychp/cloudflare-bypass - Bypass Coudflare bot protection using Cloudflare Workers
- lateautumn4lin/Review_Reverse - :wave:2019年末总结下今年做过的逆向,整理代码,复习思路。:pray:拼夕夕Web端anti_content参数逆向分析:japanese_goblin: WEB淘宝sign逆向分析;:smiley_cat:努比亚Cookie生成逆向分析;:raised_hands:百度指数data加密逆向分析 :footprints:今日头条WEB端_signature、as、cp参数逆向分析:note
- p3nt4/Nuages - A modular C2 framework
- 0xSobky/HackVault - A container repository for my public web hacks!
- lucky-sideburn/kubeinvaders - Gamified Chaos Engineering Tool for Kubernetes
- smartdone/Frida-Scripts - 一些frida脚本
- WooyunDota/DroidSSLUnpinning - Android certificate pinning disable tools
- guyoung/CaptfEncoder - Captfencoder is opensource a rapid cross platform network security tool suite, providing network security related code conversion, classical cryptography, cryptography, asymmetric encryption, miscella
- lyxhh/lxhToolHTTPDecrypt - Simple Android/iOS protocol analysis and utilization tool
- AntSwordProject/ant - 实时上线的 XSS 盲打平台
- exodusintel/CVE-2019-5786 - FileReader Exploit
- KafuuChinoQ/V2RayGeoKit
- VoidSec/WebRTC-Leak - Check if your VPN leaks your IP address via the WebRTC technology
- knownsec/KCon - KCon is a famous Hacker Con powered by Knownsec Team.
- ciscocsirt/GOSINT - The GOSINT framework is a project used for collecting, processing, and exporting high quality indicators of compromise (IOCs).
- boy-hack/WebshellManager - w8ay 一句话WEB端管理工具
- VincentChanX/shadowsocks-over-websocket - 免费使用 Heroku 部署 shadowsocks
- OWASP/DVSA - a Damn Vulnerable Serverless Application
-
Go
- Ridter/DomainHiding - external c2 use domainhiding.
- Shivangx01b/BountyIt - A fuzzer made in golang for finding issues like xss, lfi, rce, ssti...that detects issues using change in content length and verify it using signatures
- StamusNetworks/gophercap - Accurate, modular, scalable PCAP manipulation tool written in Go.
- facebookincubator/nvdtools - A set of tools to work with the feeds (vulnerabilities, CPE dictionary etc.) distributed by National Vulnerability Database (NVD)
- hashicorp/waypoint - A tool to build, deploy, and release any application on any platform.
- nscuro/fdnssearch - Swiftly search FDNS datasets from Rapid7 Open Data
- jimen0/fdns - Concurrent Rapid7 FDNS dataset parser
- aquasecurity/tfsec - Tfsec is now part of Trivy
- rootless-containers/bypass4netns - [Experimental] Accelerates slirp4netns using SECCOMP_IOCTL_NOTIF_ADDFD. As fast as `--net=host`.
- mzfr/takeover - A tool for testing subdomain takeover possibilities at a mass scale.
- vsec7/urlive - Check url is live (*HTTP status code "200 ok" only*).
- valyala/fasthttp - Fast HTTP package for Go. Tuned for high performance. Zero memory allocations in hot paths. Up to 10x faster than net/http
- gwen001/github-subdomains - Find subdomains on GitHub.
- tstillz/webshell-analyzer - Web shell scanner and analyzer.
- C-Sto/gosecretsdump - Dump ntds.dit really fast
- GoogleContainerTools/kpt - Automate Kubernetes Configuration Editing
- berty/berty - Berty is a secure peer-to-peer messaging app that works with or without internet access, cellular data or trust in the network
- LukaSikic/subzy - Subdomain takeover vulnerability checker
- liamg/scout - 🔭 Lightweight URL fuzzer and spider: Discover a web server's undisclosed files, directories and VHOSTs
- OWASP/Go-SCP - Golang Secure Coding Practices guide
- bp0lr/wurl - A tool to test working urls.
- mergestat/mergestat-lite - Query git repositories with SQL. Generate reports, perform status checks, analyze codebases. 🔍 📊
- nkanaev/yarr - yet another rss reader
- sw33tLie/bcscope - Get the scope of your bugcrowd programs
- dstotijn/hetty - An HTTP toolkit for security research.
- liamg/gitjacker - 🔪 :octocat: Leak git repositories from misconfigured websites
- code-scan/s5_server
- dwisiswant0/go-stare - A fast & light web screenshot without headless browser but Chrome DevTools Protocol!
- crowdsecurity/crowdsec - CrowdSec - the open-source and participative security solution offering crowdsourced protection against malicious IPs and access to the most advanced real-world CTI.
- incogbyte/quickpress - Small tool to automate SSRF wordpress and XMLRPC finder
- RedTeamPentesting/monsoon - Fast HTTP enumerator
- harleo/asnip - ASN target organization IP range attack surface mapping for reconnaissance, fast and lightweight
- projectdiscovery/mapcidr - Utility program to perform multiple operations for a given subnet/CIDR ranges.
- Shpota/goxygen - Generate a modern Web project with Go and Angular, React, or Vue in seconds 🎲
- EddieIvan01/gld - Go shellcode LoaDer
- theblackturtle/wildcheck - A simple tool to detect wildcards domain based on Amass's wildcards detector.
- dwisiswant0/unew - A tool for append URLs, skipping duplicates/paths & combine parameters.
- 0xsha/CloudBrute - Awesome cloud enumerator
- Becivells/iconhash - fofa shodan favicon.ico hash icon ico 计算器
- shenwei356/rush - A cross-platform command-line tool for executing jobs in parallel
- mingrammer/go-web-framework-stars - :star: Web frameworks for Go, most starred on GitHub
- imroc/req - Simple Go HTTP client with Black Magic
- arminc/clair-scanner - Docker containers vulnerability scan
- FiloSottile/age - A simple, modern and secure encryption tool (and Go library) with small explicit keys, no config options, and UNIX-style composability.
- schollz/croc - Easily and securely send things from one computer to another :crocodile: :package:
- Ladicle/kubectl-rolesum - Summarize Kubernetes RBAC roles for the specified subjects.
- kalmhq/kalm - Kalm | Kubernetes AppLication Manager
- KathanP19/Gxss - A tool to check a bunch of URLs that contain reflecting params.
- lamoda/gonkey - Gonkey - a testing automation tool
- jcatala/gqm - Go quick message
- fanjq99/dnslog - dnslog reverse vul-verify 反连平台 漏洞验证
- chennqqi/godnslog - An exquisite dns&http log server for verify SSRF/XXE/RFI/RCE vulnerability
- ArturSS7/TukTuk - Tool for catching and logging different types of requests.
- ethicalhackingplayground/wordlistgen - Generates target specific word lists for Fuzzing with fuff
- BishopFox/smogcloud - Find cloud assets that no one wants exposed 🔎 ☁️
- containerd/stargz-snapshotter - Fast container image distribution plugin with lazy pulling
- ethicalhackingplayground/ssrf-tool
- chroblert/JCRandomProxy - 随机代理
- ethicalhackingplayground/dorkX - Pipe different tools with google dork Scanner
- ethicalhackingplayground/linkJS
- mhewedy/vermin - The smart virtual machines manager. A modern CLI for Vagrant Boxes.
- dwisiswant0/wadl-dumper - Dump all available paths and/or endpoints on WADL file.
- alfarom256/ExternalC2Go
- qq431169079/PortScanner-3 - golang 版本的分布式端口扫描器,可快速方便部署,扫描核心基于 masscan & nmap
- FunnyWolf/TFirewall - 防火墙出网探测工具,内网穿透型socks5代理
- mitchellh/gox - A dead simple, no frills Go cross compile tool
- projectcalico/calico - Cloud native networking and network security
- awake1t/PortBrute - 一款跨平台小巧的端口爆破工具,支持爆破FTP/SSH/SMB/MSSQL/MYSQL/POSTGRESQL/MONGOD / A cross-platform compact port blasting tool that supports blasting FTP/SSH/SMB/MSSQL/MYSQL/POSTGRESQL/MONGOD
- nerdswords/yet-another-cloudwatch-exporter - Prometheus exporter for AWS CloudWatch - Discovers services through AWS tags, gets CloudWatch metrics data and provides them as Prometheus metrics with AWS tags as labels
- codingo/bbr - An open source tool to aid in command line driven generation of bug bounty reports based on user provided templates.
- dwisiswant0/slackcat - A simple way of sending messages from the CLI output to your Slack with webhook.
- alexellis/registry-creds - Replicate Kubernetes ImagePullSecrets to all namespaces
- inguardians/peirates - Peirates - Kubernetes Penetration Testing tool
- Threagile/threagile - Agile Threat Modeling Toolkit
- knownsec/ksubdomain - 无状态子域名爆破工具
- tkmru/dumproid - Android process memory dump tool without ndk.
- pkujhd/goloader - load and run golang code at runtime.
- hirochachacha/go-smb2 - SMB2/3 client library written in Go.
- capnspacehook/rose
- burrowers/garble - Obfuscate Go builds
- dalconan/NaviPassRead - Read Navicat 12 Password
- thought-machine/dracon - Security scanning & static analysis tool
- optiv/Go365 - An Office365 User Attack Tool
- dwisiswant0/crlfuzz - A fast tool to scan CRLF vulnerability written in Go
- halfrost/LeetCode-Go - ✅ Solutions to LeetCode by Go, 100% test coverage, runtime beats 100% / LeetCode 题解
- MilindPurswani/whoxyrm - A reverse whois tool based on Whoxy API.
- ameenmaali/wordlistgen - Quickly generate context-specific wordlists for content discovery from lists of URLs or paths
- hasura/gitkube - Build and deploy docker images to Kubernetes using git push
- xct/xc - A small reverse shell for Linux & Windows
- impost0r/Misc-Tools - Miscellaneous tools I've developed over the years for help in infosec.
- openservicemesh/osm - Open Service Mesh (OSM) is a lightweight, extensible, cloud native service mesh that allows users to uniformly manage, secure, and get out-of-the-box observability features for highly dynamic microser
- Masterminds/sprig - Useful template functions for Go templates.
- C4o/Juggler - A system that may trick hackers. 针对黑客的拟态欺骗系统。
- zu1k/nali - An offline tool for querying IP geographic information and CDN provider. 一个查询IP地理信息和CDN服务提供商的离线终端工具.
- ayoul3/reflect-pe - Reflectively load PE
- vmware-archive/octant - Highly extensible platform for developers to better understand the complexity of Kubernetes clusters.
- CloudyKit/jet - Jet template engine
- moonD4rk/HackBrowserData - Extract and decrypt browser data, supporting multiple data types, runnable on various operating systems (macOS, Windows, Linux).
- lunixbochs/usercorn - dynamic binary analysis via platform emulation
- he1m4n6a/cve-db - 一个用于生成cve数据库的程序并提供简单的http协议查询接口
- sourcegraph/sourcegraph - Code Intelligence Platform
- jpillora/chisel - A fast TCP/UDP tunnel over HTTP
- riza/medusa - Fastest recursive HTTP fuzzer, like a Ferrari.
- sunshinev/go-sword - 【Go-sword】可视化CRUD管理后台生成工具
- paranoidninja/Boomerang - Boomerang is a tool to expose multiple internal servers to web/cloud. Agent & Server are pretty stable and can be used in Red Team for Multiple levels of Pivoting and exposing multiple internal servic
- ropnop/kerbrute - A tool to perform Kerberos pre-auth bruteforcing
- dwisiswant0/go-dork - The fastest dork scanner written in Go.
- hakluke/hakq - A basic golang server/client for distributing tasks over multiple systems.
- ctoyan/ponieproxy - Simple proxy which applies filters (default or custom) to your requests and responses, while you browse a website.
- greyireland/algorithm-pattern - 算法模板,最科学的刷题方式,最快速的刷题路径,你值得拥有~
- optiv/Talon - A password guessing tool that targets the Kerberos and LDAP services within the Windows Active Directory environment.
- lifei6671/interview-go - golang面试题集合
- hsiafan/httpdump - Capture and parse http traffics
- moloch--/leakdb - Web-Scale NoSQL Idempotent Cloud-Native Big-Data Serverless Plaintext Credential Search
- cybercdh/kitphishr - A tool designed to hunt for Phishing Kit source code
- gokrazy/gokrazy - turn your Go program(s) into an appliance running on the Raspberry Pi 3, Pi 4, Pi 5, Pi Zero 2 W, or amd64 PCs!
- aktsk/apk-medit - memory search and patch tool on debuggable apk without root & ndk
- sysdream/ligolo - Reverse Tunneling made easy for pentesters, by pentesters https://sysdream.com/
- kubernetes-sigs/kustomize - Customization of kubernetes YAML configurations
- Static-Flow/gofingerprint - GoFingerprint is a Go tool for taking a list of target web servers and matching their HTTP responses against a user defined list of fingerprints.
- aquasecurity/kube-bench - Checks whether Kubernetes is deployed according to security best practices as defined in the CIS Kubernetes Benchmark
- D00MFist/Go4aRun - Shellcode runner in GO that incorporates shellcode encryption, remote process injection, block dlls, and spoofed parent process
- jckuester/awsls - A list command for AWS resources
- go-rod/rod - A Chrome DevTools Protocol driver for web automation and scraping.
- mailhog/MailHog - Web and API based SMTP testing
- kinvolk/lokomotive - 🪦 DISCONTINUED Further Lokomotive development has been discontinued. Lokomotive is a 100% open-source, easy to use and secure Kubernetes distribution from the volks at Kinvolk
- stefanoj3/dirstalk - Modern alternative to dirbuster/dirb
- sethvargo/go-envconfig - A Go library for parsing struct tags from environment variables.
- ncarlier/feedpushr - A simple feed aggregator daemon with sugar on top.
- michelin/ChopChop - ChopChop is a CLI to help developers scanning endpoints and identifying exposition of sensitive services/files/folders.
- projectdiscovery/httpx - httpx is a fast and multi-purpose HTTP toolkit that allows running multiple probes using the retryablehttp library.
- lesnuages/go-execute-assembly - Allow a Go process to dynamically load .NET assemblies
- EddieIvan01/iox - Tool for port forwarding & intranet proxy
- TheMMMdev/addSome - Simple Go script to check if found domains in a file are already saved in your Findomain database
- fuzzitdev/fuzzit - CLI to integrate continuous fuzzing with Fuzzit (no longer available)
- 1ndianl33t/1ndiList - Recon Custom WordList Ganerator
- smallstep/autocert - ⚓ A kubernetes add-on that automatically injects TLS/HTTPS certificates into your containers
- ameenmaali/whoareyou - whoareyou is a tool to find the underlying technology/software used in a list of websites passed through stdin (using Wappalyzer dataset)
- ethicalhackingplayground/Zin - A Payload Injector for bugbounties written in go
- hakluke/haktldextract - Extract domains/subdomains from URLs en masse
- ngrok/sqlmw - Interceptors for database/sql
- hwholiday/gid - Golang 分布式ID生成系统,高性能、高可用、易扩展的id生成服务
- BishopFox/sliver - Adversary Emulation Framework
- projectdiscovery/chaos-client - Go client to communicate with Chaos DB API.
- projectdiscovery/naabu - A fast port scanner written in go with a focus on reliability and simplicity. Designed to be used in combination with other tools for attack surface discovery in bug bounties and pentests
- dwisiswant0/cf-check - CloudFlare Checker written in Go
- wunderwuzzi23/KoiPhish - A simple yet beautiful phishing proxy.
- caddyserver/forwardproxy - Forward proxy plugin for the Caddy web server
- Binject/backdoorfactory - A from-scratch rewrite of The Backdoor Factory - a MitM tool for inserting shellcode into all types of binaries on the wire.
- go-vgo/robotgo - RobotGo, Go Native cross-platform RPA and GUI automation @vcaesar
- random-robbie/ssrf-finder - Pass list of urls with FUZZ in and it will check if it has found a potential SSRF.
- 1ndianl33t/1ndi-hacks - Bug Bounty Tools
- gobysec/GobyVuls - Vulnerabilities of Goby supported with exploitation.
- projectdiscovery/public-bugbounty-programs - Community curated list of public bug bounty and responsible disclosure programs.
- tomnomnom/fff - The Fairly Fast Fetcher. Requests a bunch of URLs provided on stdin fairly quickly.
- praetorian-inc/slack-c2bot - Slack C2bot that executes commands and returns the output.
- esrrhs/pingtunnel - Pingtunnel is a tool that send TCP/UDP traffic over ICMP
- pry0cc/subgen - A really simple utility to concate wordlists to a domain name - to pipe into your favourite resolver!
- ctoyan/waybackcollector - Fetch wayback machine historical content for a given url
- cruise-automation/rbacsync - Automatically sync groups into Kubernetes RBAC
- uber-go/ratelimit - A Go blocking leaky-bucket rate limit implementation
- Shivangx01b/CorsMe - Cross Origin Resource Sharing MisConfiguration Scanner
- leobeosab/sharingan - Offensive Security recon tool
- Sh1Yo/rate-limit-checker - Check whether the domain has a rate limit enabled.
- asciimoo/wuzz - Interactive cli tool for HTTP inspection
- zmap/zgrab2 - Fast Go Application Scanner
- ndelphit/apkurlgrep - Extract endpoints from APK files
- chai2010/go-ast-book - :books: 《Go语言定制指南》(原名:Go语法树入门/开源免费图书/Go语言进阶/掌握抽象语法树/Go语言AST)
- tillson/git-hound - Reconnaissance tool for GitHub code search. Scans for exposed API keys across all of GitHub, not just known repos and orgs.
- ihaiker/sudis - Sudis !! Distributed supervisor process control system
- tailscale/tailscale - The easiest, most secure way to use WireGuard and 2FA.
- QSoloX/whoisyou - Take a list of domains and output the hostname and ip.
- heroku/terrier - Terrier is a Image and Container analysis tool that can be used to scan Images and Containers to identify and verify the presence of specific files according to their hashes.
- xfhg/intercept - INTERCEPT Code Compliance / Policy as Code Auditing / SAST & Runtime Code+API Check
- virink/xray-weblisten-ui - Xray 被动扫描管理
- Dliv3/Venom - Venom - A Multi-hop Proxy for Penetration Testers
- jjf012/gopoc - 用cel-go重现了长亭xray的poc检测功能的轮子
- tismayil/ohmybackup - Scan Victim Backup Directories & Backup Files
- drk1wi/Modlishka - Modlishka. Reverse Proxy.
- projectdiscovery/dnsprobe - DNSProb is a tool built on top of retryabledns that allows you to perform multiple dns queries of your choice with a list of user supplied resolvers.
- zmap/zdns - Fast DNS Lookup Library and CLI Tool
- jaeles-project/jaeles - The Swiss Army knife for automated Web Application Testing
- hahwul/dalfox - 🌙🦊 Dalfox is a powerful open-source XSS scanner and utility focused on automation.
- shomali11/go-interview - Collection of Technical Interview Questions solved with Go
- lc/gau - Fetch known URLs from AlienVault's Open Threat Exchange, the Wayback Machine, and Common Crawl.
- tuxotron/docker-image-generator - Customized docker images generation toolkit
- Adminisme/ServerScan - ServerScan一款使用Golang开发的高并发网络扫描、服务探测工具。
- projectdiscovery/nuclei - Fast and customizable vulnerability scanner based on simple YAML based DSL.
- argoproj/argo-workflows - Workflow Engine for Kubernetes
- theblackturtle/fprobe - Take a list of domains/subdomains and probe for working http/https server.
- madneal/gshark - Scan for sensitive information easily and effectively.
- ATpiu/asset-scan - asset-scan是一款适用甲方企业的外网资产周期性扫描监控系统
- jesseduffield/lazydocker - The lazier way to manage everything docker
- parsiya/Hacking-with-Go - Golang for Security Professionals
- projectdiscovery/shuffledns - MassDNS wrapper written in go to enumerate valid subdomains using active bruteforce as well as resolve subdomains with wildcard filtering and easy input-output support.
- rhaidiz/broxy - An HTTP/HTTPS intercept proxy written in Go.
- TheKingOfDuck/ReverseGoShell - A Golang Reverse Shell Tool With AES Dynamic Encryption
- darkr4y/geacon - Practice Go programming and implement CobaltStrike's Beacon in Go
- kozlice/slack-webm-sentinel - A bot that tracks .webm links and converts them to .mp4
- Go-zh/tour - 【已弃用】新版移至 website 代码仓库
- gophish/gophish - Open-Source Phishing Toolkit
- sensepost/gowitness - 🔍 gowitness - a golang, web screenshot utility using Chrome Headless
- xfiftyone/STS2G - Struts2漏洞扫描利用工具 - Golang版. Struts2 Scanner Written in Golang
- ZeroDream-CN/SakuraFrp - 基于 Frp 二次开发定制的版本,可实现多用户管理、限速等商业化功能
- phil-fly/goWeakPass - 使用golang编写的服务弱口令检测
- ph4ntonn/Stowaway - 👻Stowaway -- Multi-hop Proxy Tool for pentesters
- phuslu/iploc - Fastest IP To Country Library
- ac0d3r/Hyuga - Hyuga 是一个用来监控带外(Out-of-Band)流量的工具。🪤
- geph-official/geph2 - (ARCHIVED) Geph (迷霧通) is a modular Internet censorship circumvention system designed specifically to deal with national filtering.
- tomnomnom/hacks - A collection of hacks and one-off scripts
- tomnomnom/qsreplace - Accept URLs on stdin, replace all query string values with a user-supplied value
- hakluke/hakrevdns - Small, fast tool for performing reverse DNS lookups en masse.
- runZeroInc/runzero-tools - Open source tools, libraries, and datasets related to the runZero product and associated research
- hakluke/hakrawler - Simple, fast web crawler designed for easy, quick discovery of endpoints and assets within a web application
- yuxiaokui/gohtran - 反向socks5代理, 关键词: go htran 重复造轮子 ssocks ew
- sundowndev/phoneinfoga - Information gathering framework for phone numbers
- 40t/go-sniffer - 🔎Sniffing and parsing mysql,redis,http,mongodb etc protocol. 抓包截取项目中的数据库请求并解析成相应的语句。
- aquasecurity/trivy - Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more
- xxjwxc/gowp - golang worker pool , Concurrency limiting goroutine pool
- Qianlitp/crawlergo - A powerful browser crawler for web vulnerability scanners
- yakumioto/alkaid - Alkaid is a BaaS(Blockchan as a Service) service based on Hyperledger Fabric.
- TNK-Studio/gortal - 🚪A super lightweight jumpserver service developed using the Go language. 一个使用 Go 语言开发的,超级轻量的跳板机服务。
- kerbyj/goLazagne - Go library for credentials recovery
- squat/kilo - Kilo is a multi-cloud network overlay built on WireGuard and designed for Kubernetes (k8s + wg = kg)
- filebrowser/filebrowser - 📂 Web File Browser
- derailed/k9s - 🐶 Kubernetes CLI To Manage Your Clusters In Style!
- insidersec/insider - Static Application Security Testing (SAST) engine focused on covering the OWASP Top 10, to make source code analysis to find vulnerabilities right in the source code, focused on a agile and easy to im
- bnkamalesh/verifier - A minimal, customizable Go package for Email & Mobile number verification
- ahhh/nmap-to-netscan - A helper utility for turning nmap xml files into target lists for go-netscan
- openkruise/kruise - Automated management of large-scale applications on Kubernetes (incubating project under CNCF)
- guonaihong/gout - gout to become the Swiss Army Knife of the http client @^^@---> gout 是http client领域的瑞士军刀,小巧,强大,犀利。具体用法可看文档,如使用迷惑或者API用得不爽都可提issues
- wxbool/video-srt-windows - 这是一个可以识别视频语音自动生成字幕SRT文件的开源 Windows-GUI 软件工具。
- aau-network-security/haaukins - A Highly Accessible and Automated Virtualization Platform for Security Education
- crawlab-team/crawlab - Distributed web crawler admin platform for spiders management regardless of languages and frameworks. 分布式爬虫管理平台,支持任何语言和框架
- aquasecurity/tracee - Linux Runtime Security and Forensics using eBPF
- cbeuw/Cloak - A censorship circumvention tool to evade detection by authoritarian state adversaries
- gin-gonic/gin - Gin is a HTTP web framework written in Go (Golang). It features a Martini-like API with much better performance -- up to 40 times faster. If you need smashing performance, get yourself some Gin.
- kataras/iris - The fastest HTTP/2 Go Web Framework. New, modern and easy to learn. Fast development with Code you control. Unbeatable cost-performance ratio :rocket:
- github/gh-ost - GitHub's Online Schema-migration Tool for MySQL
- mehrdadrad/radvpn - Decentralized VPN
- LyricTian/gin-admin - A lightweight, flexible, elegant and full-featured RBAC scaffolding based on GIN + GORM 2.0 + Casbin 2.0 + Wire DI.
- TruthHun/BookStack - BookStack,基于MinDoc,使用Beego开发的在线文档管理系统,功能类似Gitbook和看云。
- thinkeridea/go-extend - go语言扩展包,收集一些常用的操作函数,辅助更快的完成开发工作,并减少重复代码
- zhshch2002/goribot - [Crawler/Scraper for Golang]🕷A lightweight distributed friendly Golang crawler framework.一个轻量的分布式友好的 Golang 爬虫框架。
- xinliangnote/go-gin-api - 基于 Gin 进行模块化设计的 API 框架,封装了常用功能,使用简单,致力于进行快速的业务研发。比如,支持 cors 跨域、jwt 签名验证、zap 日志收集、panic 异常捕获、trace 链路追踪、prometheus 监控指标、swagger 文档生成、viper 配置文件解析、gorm 数据库组件、gormgen 代码生成工具、graphql 查询语言、errno 统一定义错误码、gR
- eolinker/goku_lite - A Powerful HTTP API Gateway in pure golang!Goku API Gateway (中文名:悟空 API 网关)是一个基于 Golang开发的微服务网关,能够实现高性能 HTTP API 转发、服务编排、多租户管理、API 访问权限控制等目的,拥有强大的自定义插件系统可以自行扩展,并且提供友好的图形化配置界面,能够快速帮助企业进行 API 服务治理、提高 AP
- defenxor/dsiem - Security event correlation engine for ELK stack
- TeaWeb/build - TeaWeb-可视化的Web代理服务。DEMO: http://teaos.cn:7777
- gourouting/singo - Gin+Gorm开发Golang API快速开发脚手架
- nntaoli-project/goex - Cryptocurrency Exchange Rest API SDK For Golang Wrapper Support okx,huobi,binance
- sqshq/sampler - Tool for shell commands execution, visualization and alerting. Configured with a simple YAML file.
- mdsecactivebreach/o365-attack-toolkit - A toolkit to attack Office365
- OJ/gobuster - Directory/File, DNS and VHost busting tool written in Go
- netevert/delator - Golang-based subdomain miner leveraging certificate transparency logs
- tomnomnom/assetfinder - Find domains and subdomains related to a given domain
- astaxie/build-web-application-with-golang - A golang ebook intro how to build a web with golang
- myrual/mixin-network-snapshot-golang - crypto currency gateway plugin for web store
- hanxi/lemonade - Lemonade is a remote utility tool. (copy, paste and open browser) over TCP.
- txthinking/zoro - zoro can help you expose local server to external network. Support both TCP/UDP, of course support HTTP. Zero-Configuration.
- az0ne/Finder - 一款Go语言实现的端口扫描器.
- rancher/k3os - Purpose-built OS for Kubernetes, fully managed by Kubernetes.
- gcla/termshark - A terminal UI for tshark, inspired by Wireshark
- RickGray/vscan-go - golang version for nmap service and application version detection (without nmap installation)
- ffuf/ffuf - Fast web fuzzer written in Go
- lis912/CapOS - 等级保护测评windows工具源码
- netxfly/x-crack - x-crack - Weak password scanner, Support: FTP/SSH/SNMP/MSSQL/MYSQL/PostGreSQL/REDIS/ElasticSearch/MONGODB
- ice-ice/dnstunnel - dns tunnel backdoor DNS隧道后门
- future-architect/vuls - Agent-less vulnerability scanner for Linux, FreeBSD, Container, WordPress, Programming language libraries, Network devices
- milo2012/pathbrute - Pathbrute
- l3m0n/whatweb - 更快速的进行Web应用指纹识别
- gwuhaolin/livego - live video streaming server in golang
- meshbird/meshbird - Distributed private networking
- Q2h1Cg/dnsbrute - a fast domain brute tool
- marco-lancini/goscan - Interactive Network Scanner
- knownsec/gsm - 使用树莓派配合硬件来进行短信转发
- WangYihang/Platypus - :hammer: A modern multiple reverse shell sessions manager written in go
- jmpews/goscan - golang的扫描框架, 支持协程池和自动调节协程个数.
- coyim/coyim - coyim - a safe and secure chat client
- securego/gosec - Go security checker
- rockagen/cmus-lyric - cmus lyric viewer
- j3ssie/osmedeus - A Workflow Engine for Offensive Security
- maxmcd/webtty - Share a terminal session over WebRTC
- 0xDkd/auxpi - 🍭 集合多家 API 的新一代图床
- root-gg/plik - Plik is a temporary file upload system (Wetransfer like) in Go.
- mkchoi212/fac - Easy-to-use CUI for fixing git conflicts
- gogs/gogs - Gogs is a painless self-hosted Git service
- iwannay/jiacrontab - 简单可信赖的任务管理工具
- Releasel0ck/Blind-SQL-Injector - 手工盲注辅助注入工具
- netxfly/docker_ssh_honeypot - 安全开发教学 - 用Docker制作一个高交互ssh蜜罐
- jesseduffield/lazygit - simple terminal UI for git commands
- sipt/shuttle - A web proxy in Golang with amazing features.
- xo/usql - Universal command-line interface for SQL databases
- lixiangzhong/dnsutil - dns dig for golang
- cloverstd/tcping - ping over a tcp connection
- google/subcommands - Go subcommand library.
- fanpei91/torsniff - torsniff - a sniffer that sniffs torrents from BitTorrent network
- anshumanbh/merge-nmap-masscan - Merge results from NMAP and Masscan into one CSV file
- anoshop/BAT_Check_DomainName
- helloxz/zdir - A multifunctional private storage program that integrates file indexing, online preview, and sharing, supporting both WebDAV and cloud download.
- jimeh/tmux-themepack - A pack of various Tmux themes.
- miniflux/v2 - Minimalist and opinionated feed reader
- shawn1m/overture - A customized DNS relay server
- projectdiscovery/subfinder - Fast passive subdomain enumeration tool.
- claudiodangelis/qrcp - :zap: Transfer files over wifi from your computer to your mobile device by scanning a QR code without leaving the terminal.
- dsopas/rfd-checker - RFD Checker - security CLI tool to test Reflected File Download issues
- gilbertchen/duplicacy - A new generation cloud backup tool
- cbeuw/GoQuiet - A Shadowsocks obfuscation plugin utilising domain fronting to evade deep packet inspection
- haccer/subjack - Subdomain Takeover tool written in Go
- gwuhaolin/lightsocks - ⚡️一个轻巧的网络混淆代理🌏
- tiagorlampert/CHAOS - :fire: CHAOS is a free and open-source Remote Administration Tool that allow generate binaries to control remote operating systems.
- lyyyuna/godht
- shadowsocks/shadowsocks-go - go port of shadowsocks (Deprecated)
- mritd/idgen - 一个使用 golang 编写的大陆身份证生成器
- qax-os/ElasticHD - Elasticsearch 可视化DashBoard, 支持Es监控、实时搜索,Index template快捷替换修改,索引列表信息查看, SQL converts to DSL等
- gitleaks/gitleaks - Protect and discover secrets using Gitleaks 🔑
- cloudreve/Cloudreve - 🌩支持多家云存储的云盘系统 (Self-hosted file management and sharing system, supports multiple storage providers)
- Ice3man543/SubOver - A Powerful Subdomain Takeover Tool
- MiSecurity/x-patrol - github泄露扫描系统
- ginuerzh/gost - GO Simple Tunnel - a simple tunnel written in golang
- avast/apkverifier - APK Signature verification in Go. Supports scheme v1, v2 and v3 and passes Google apksig's testing suite.
- dzonerzy/goWAPT - Go Web Application Penetration Test
- timest/goscan - goscan is a simple and efficient IPv4 network scanner that discovers all active devices on local subnet.
- rgburke/grv - GRV is a terminal interface for viewing git repositories
- jiajunhuang/guard - NOT MAINTAINED! A generic high performance circuit breaker & proxy server written in Go
- random-robbie/AWS-Scanner - Scans a list of websites for Cloudfront or S3 Buckets
- DNSCrypt/dnscrypt-proxy - dnscrypt-proxy 2 - A flexible DNS proxy, with support for encrypted DNS protocols.
- malfunkt/hyperfox - HTTP/HTTPS MITM proxy and recorder.
- ghostunnel/ghostunnel - A simple SSL/TLS proxy with mutual authentication for securing non-TLS services.
- mmatczuk/go-http-tunnel - Fast and secure tunnels over HTTP/2
- mattn/ft - File Transferer
- ethereum/go-ethereum - Go implementation of the Ethereum protocol
- cookieY/Yearning - 🐳 A most popular sql audit platform for mysql
- fardog/secureoperator - A DNS-protocol proxy for DNS-over-HTTPS providers, such as Google and Cloudflare
- drish/ben - Your benchmark assistant, written in Go.
- Nhoya/gOSINT - OSINT Swiss Army Knife
- netxfly/xsec-proxy-scanner - xsec-proxy-scanner是一款速度超快、小巧的代理扫描器
- go-ignite/ignite - A SS(R) panel for managing multiple users, powered by Go & Docker.
- yinqiwen/gsnova - Private proxy solution & network troubleshooting tool.
- tam7t/hpkp - golang hpkp client library
- twitchyliquid64/subnet - Simple, auditable & elegant VPN, built with TLS mutual authentication and TUN.
- dreddsa5dies/goHackTools - Hacker tools on Go (Golang)
- rclone/rclone - "rsync for cloud storage" - Google Drive, S3, Dropbox, Backblaze B2, One Drive, Swift, Hubic, Wasabi, Google Cloud Storage, Azure Blob, Azure Files, Yandex Files
- moul/assh - :computer: make your ssh client smarter
- yangxuan8282/docker-image
- averagesecurityguy/searchscan - Search Nmap and Metasploit scanning scripts.
- netxfly/xsec-ip-database - xsec-ip-database为一个恶意IP和域名库(Malicious ip database)
- bynil/sov2ex - A site search for V2EX
- coyove/goflyway - An encrypted HTTP server
- junegunn/fzf - :cherry_blossom: A command-line fuzzy finder
- flynaj/kcptun - A Secure Tunnel Based On KCP with N:M Multiplexing
- inconshreveable/slt - A TLS reverse proxy with SNI multiplexing in Go
- diamondyuan-achieve/frp
- inconshreveable/ngrok - Unified ingress for developers
- moby/moby - The Moby Project - a collaborative project for the container ecosystem to assemble container-based systems
- gohugoio/hugo - The world’s fastest framework for building websites.
- jpillora/cloud-torrent - ☁️ Cloud Torrent: a self-hosted remote torrent client
- yeasy/docker_practice - Learn and understand Docker&Container technologies, with real DevOps practice!
- shunfei/cronsun - A Distributed, Fault-Tolerant Cron-Style Job System.
- shyiko/kubesec - Secure Secret management for Kubernetes (with gpg, Google Cloud KMS and AWS KMS backends)
- netxfly/xsec-dns-proxy - DNS代理服务器,可以记录log到数据库中
- shiyanhui/dht - BitTorrent DHT Protocol && DHT Spider.
- btcsuite/btcd - An alternative full node bitcoin implementation written in Go (golang)
- yinghuocho/firefly-proxy - A proxy software to help circumventing the Great Firewall.
- Kisesy/gscan_quic - Google Quic 扫描工具
- IDrinkMoreWater/fetchserver - phuslu删掉了fetchserver,我重新传一个
- nadoo/glider - glider is a forward proxy with multiple protocols support, and also a dns/dhcp server with ipset management features(like dnsmasq).
- txthinking/brook - A cross-platform programmable network tool
- caddyserver/caddy - Fast and extensible multi-platform HTTP/1-2-3 web server with automatic HTTPS
- evilsocket/xray - XRay is a tool for recon, mapping and OSINT gathering from public networks.
- apex/gh-polls - Polls for user feedback in GitHub issues
- rabbitstack/fibratus - Adversary tradecraft detection, protection, and hunting
- crazy-max/WindowsSpyBlocker - Block spying and tracking on Windows
- evilsocket/dnssearch - A subdomain enumeration tool.
- zmap/zgrab - **DEPRECATED** This project has been replaced by https://github.com/zmap/zgrab2
- evilsocket/brutemachine - A Go library which main purpose is giving an interface to loop over a dictionary and use those words/lines as input for some custom logic such as HTTP file bruteforcing, DNS bruteforcing, etc.
- rqlite/rqlite - The lightweight, user-friendly, distributed relational database built on SQLite.
- michenriksen/aquatone - A Tool for Domain Flyovers
- anshumanbh/git-all-secrets - A tool to capture all the git secrets by leveraging multiple open source git searching tools
- quay/clair - Vulnerability Static Analysis for Containers
- techjacker/repo-security-scanner - CLI tool that finds secrets accidentally committed to a git repo, eg passwords, private keys
- netxfly/crack_ssh - go写的协程版的ssh\redis\mongodb弱口令破解工具
- kashav/fsql - Search for files using a fun query language
- yeasy/blockchain_guide - Introduce blockchain related technologies, from theory to practice with bitcoin, ethereum and hyperledger.
- mysteriumnetwork/node - Mysterium Network Node - official implementation of distributed VPN network (dVPN) protocol
- early-return/ebreader - 一个让你可以在浏览器中阅读Epub电子书的CLI程序,使用Golang编写
- FeatureBaseDB/featurebase - A crazy fast analytical database, built on bitmaps. Perfect for ML applications. Learn more at: http://docs.featurebase.com/. Start a Docker instance: https://hub.docker.com/r/featurebasedb/featurebas
- kryptco/kr - DEPRECATED A dev tool for SSH auth + Git commit/tag signing using a key stored in Krypton.
- c0nrad/go-mbf - MongoDB Login Brute Forcer
- trufflesecurity/trufflehog - Find, verify, and analyze leaked credentials
- duolatech/xapimanager - XAPI MANAGER -专业实用的开源接口管理平台,为程序开发者提供一个灵活,方便,快捷的API管理工具,让API管理变的更加清晰、明朗。如果你觉得xApi对你有用的话,别忘了给我们点个赞哦^_^ !
- fatedier/frp - A fast reverse proxy to help you expose a local server behind a NAT or firewall to the internet.
- cilium/cilium - eBPF-based Networking, Security, and Observability
- 0x4D31/honeybits - A PoC tool designed to enhance the effectiveness of your traps by spreading breadcrumbs & honeytokens across your systems to lure the attacker toward your honeypots
- qiniu/qshell - Shell Tools for Qiniu Cloud
- gonet2/geoip - query geo-locations of ips
- michenriksen/gitrob - Reconnaissance tool for GitHub organizations
- huichen/wukong - 高度可定制的全文搜索引擎
- beego/beego - beego is an open-source, high-performance web framework for the Go programming language.
- linuxkit/linuxkit - A toolkit for building secure, portable and lean operating systems for containers
- weaveworks/scope - Monitoring, visualisation & management for Docker & Kubernetes
- prasmussen/gdrive - Google Drive CLI Client
- StackExchange/dnscontrol - Infrastructure as code for DNS!
- sensepost/ruler - A tool to abuse Exchange services
- xtaci/kcptun - A Quantum-Safe Secure Tunnel based on QPP, KCP, FEC, and N:M multiplexing.
- unknwon/the-way-to-go_ZH_CN - 《The Way to Go》中文译本,中文正式名《Go 入门指南》
- urfave/negroni - Idiomatic HTTP Middleware for Golang
- ajermakovics/jvm-mon - Console-based JVM monitoring tool
- flike/kingshard - A high-performance MySQL proxy
- x1sec/commit-stream - #OSINT tool for finding Github repositories by extracting commit logs in real time from the Github event API
- cloudflare/ebpf_exporter - Prometheus exporter for custom eBPF metrics
- lionsoul2014/ip2region - Ip2region (2.0 - xdb) is a offline IP address manager framework and locator, support billions of data segments, ten microsecond searching performance. xdb engine implementation for many programming la
- kost/dnstun - DNS tunnel library in Go
- kost/chashell - Chashell is a Go reverse shell that communicates over DNS. It can be used to bypass firewalls or tightly restricted networks.
- zan8in/pyxis - pyxis can automatically identify http and https requests, and get response headers, status codes, response size, response time, tools for fingerprinting (favicon has, service, CMS, framework, etc.)
- xiao-zhu-zhu/noterce - 一种另辟蹊径的免杀执行系统命令的木马
- Ggasdfg321/SmallProxyPool - 一个免费高质量的小代理池,解决一些站点有WAF的情况下,进行目录扫描或者字典爆破
- chushuai/wscan - Wscan is a web security scanner that focuses on web security, dedicated to making web security accessible to everyone.
- AbelChe/evil_minio - EXP for CVE-2023-28434 MinIO unauthorized to RCE
- Kento-Sec/chatGPT-CodeReview - 这是一个调用chatGPT进行代码审计的工具
- Mob2003/rakshasa - 基于go编写的跨平台、稳定、隐秘的多级代理内网穿透工具
- zema1/watchvuln - 一个高价值漏洞采集与推送服务 | collect valueable vulnerability and push it
- nirsarkar/vscan
- ifacker/cscan-go - cscan-go 版本,主要用于C段扫描,信息收集、红队横向渗透等...(相信我,点进来不会后悔的!)
- mmM1ku/Mscan - Mscan是一款基于go语言开发的内网资产探测工具。
- jhaddix/awsScrape - A tool to scrape the AWS ranges looking for a keyword in SSL certificate data.
- vitorfhc/queryxss - Tool for testing reflections in the HTTP responses
- allanpk716/xray_pool - 基于 Xray-core、glider 的代理池工具
- corunb/Dirscan - Dirscan是一款由go编写的高性能、高并发的目录扫描器,现在已经支持GET、HEAD、递归扫描、代理、爬虫等功能功能,后续努力实现更多功能。
- taythebot/archer - Distributed network and vulnerability scanner
- nu1r/GlangYsoserial.java - 一个生成JAVA反序列化流的GO库
- godzeo/go-gin-vul - GO语言漏洞靶场 GIN框架 支持docker一键启动
- xiaoyaochen/yscan - yscan是一款基于go写的端口扫描工具,集masscan+nmap+wappalyzer+证书于一体
- rustgopy/RGPScan - 红队渗透测试、内网资产探测、通用漏洞扫描、弱口令爆破
- XinRoom/go-portScan - High-performance port scanner. 高性能端口扫描器. syn scanner
- vitorfhc/hacks - Collection of scripts that I use while bug hunting
- SeeFlowerX/estrace - 基于eBPF的syscall追踪工具,适用于安卓平台
- kost/tty2web - Share your terminal as a web application in bind/reverse mode
- zt2/uncover-turbo - 一个简单的测绘引擎巴别塔
- SpenserCai/GoWxDump - SharpWxDump的Go语言版。微信客户端取证,获取信息(微信号、手机号、昵称),微信聊天记录分析(Top N聊天的人、统计聊天最频繁的好友排行、关键词列表搜索等)
- HZzz2/go-shellcode-loader - GO免杀shellcode加载器混淆AES加密
- Aur0ra-m/APIKiller - API Security DAST & Oprations
- WAY29/pocV - Compatible with xray and nuclei poc framework
- djun/wechatbot - 为个人微信接入ChatGPT
- ExpLangcn/EPScan - 被动收集资产并自动进行SQL注入检测(插件化 自动Bypass)、XSS检测、RCE检测、敏感信息检测
- pingc0y/go_proxy_pool - 无环境依赖开箱即用的代理IP池
- dhn/udon - A simple tool that helps to find assets/domains based on the Google Analytics ID.
- musana/mx-takeover - mx-takeover focuses DNS MX records and detects misconfigured MX records.
- google/kctf - kCTF is a Kubernetes-based infrastructure for CTF competitions. For documentation, see
- TD0U/WeaverScan - 泛微oa漏洞利用工具
- trickest/mkpath - Make URL path combinations using a wordlist
- Goqi/Cell - Cell-nuclei二开
- niudaii/crack - 弱口令爆破工具。Weak Password Blaster Tool.
- musana/fuzzuli - fuzzuli is a url fuzzing tool that aims to find critical backup files by creating a dynamic wordlist based on the domain.
- sh1yan/Lscan - 一款内网快速打点的辅助性扫描工具,方便红队人员在内网横向移动前期的信息搜集、漏洞探测利用环节的工作开展。其工具特性主要为支持一键化三个档位的便捷式信息与漏洞扫描或每个功能模块单独式扫描探测功能。
- seventeenman/Forest - 基于frp(0.44.0)二次开发,删除不必要功能,加密配置文件,修改流量以及文件特征
- Goqi/Erfrp - Erfrp-frp二开-免杀与隐藏
- ddosify/ddosify - High-performance load testing tool, written in Golang. For distributed and Geo-targeted load testing: Ddosify Cloud - https://ddosify.com 🚀
- kubesphere/kubeeye - KubeEye aims to find various problems on Kubernetes, such as application misconfiguration, unhealthy cluster components and node problems.
- edoardottt/csprecon - Discover new target domains using Content Security Policy
- wgpsec/CreateHiddenAccount - A tool for creating hidden accounts using the registry || 一个使用注册表创建隐藏帐户的工具
- hanc00l/pocGoby2Xray - 将Goby的json格式Poc转为xray的yaml格式Poc
- niudaii/zpscan - 一个有点好用的信息收集工具。A somewhat useful information gathering tool.
- ChineseSubFinder/ChineseSubFinder - 自动化中文字幕下载。字幕网站支持 shooter、xunlei、arrst、a4k、SubtitleBest 。支持 Emby、Jellyfin、Plex、Sonarr、Radarr、TMM
- sea-team/gofound - GoFound GoLang Full text search go语言全文检索引擎,毫秒级查询。 使用http接口调用,集成Admin管理界面,任何系统都可以使用。
- Lengso/iplookup - IP反查域名
- HavocFramework/Havoc - The Havoc Framework.
- Ptkatz/OrcaC2 - OrcaC2是一款基于Websocket加密通信的多功能C&C框架,使用Golang实现。
- Schira4396/VcenterKiller - 一款针对Vcenter的综合利用工具,包含目前最主流的CVE-2021-21972、CVE-2021-21985以及CVE-2021-22005、One Access的CVE-2022-22954、CVE-2022-22972/31656以及log4j,提供一键上传webshell,命令执行或者上传公钥使用SSH免密连接
- ItsIgnacioPortal/hacker-scoper - Automagically filter URLs with Bug Bounty program scope rules scraped from the internet.
- ffffffff0x/gendict - 字典生成工具
- MY0723/goby-poc - 451个goby poc,是否后门及重复自行判断,来源于网络收集的Goby&POC,不定时更新。
- chenjiandongx/bpfpinger - 🚥 A high-performance ICMP ping implementation build on top of BPF technology.
- lzzbb/Adinfo - 域信息收集工具
- Peony2022/shiro_killer - 批量ShiroKey检测爆破工具
- a1phaboy/MenoyGone - Attack cobalt strike server’s FCS by DoW
- 360quake/quake_go - Quake Command-Line Application With Golang
- CTF-MissFeng/mysql-check - mysql蜜罐检查小工具,输出mysql认证及认证后交互数据
- c3l3si4n/godeclutter - Declutters URLs in a fast and flexible way, for improving input for web hacking automations such as crawlers and vulnerability scans.
- TideSec/GoBypassAV - 整理了基于Go的16种API免杀测试、8种加密测试、反沙盒测试、编译混淆、加壳、资源修改等免杀技术,并搜集汇总了一些资料和工具。
- LubyRuffy/rproxy - 自动化的代理服务器
- boy-hack/ksubdomain - Subdomain enumeration tool, asynchronous dns packets, use pcap to scan 1600,000 subdomains in 1 second
- trickest/mksub - Generate tens of thousands of subdomain combinations in a matter of seconds
- pingc0y/URLFinder - 一款快速、全面、易用的页面信息提取工具,可快速发现和提取页面中的JS、URL和敏感信息。
- RedTeamPentesting/pretender - Your MitM sidekick for relaying attacks featuring DHCPv6 DNS takeover as well as mDNS, LLMNR and NetBIOS-NS spoofing.
- redhuntlabs/HTTPLoot - An automated tool which can simultaneously crawl, fill forms, trigger error/debug pages and "loot" secrets out of the client-facing code of sites.
- j5s/accelerator - Use Golang to batch analyze class files for Java security research
- u21h2/nacs - 事件驱动的渗透测试扫描器 Event-driven pentest scanner
- safe6Sec/GolangBypassAV - 研究利用golang各种姿势bypassAV
- merlinepedra25/SCA4ALL
- code-scan/Goal - Goal Go Red-Team 工具类
- jmoiron/sqlx - general purpose extensions to golang's database/sql
- inbug-team/SweetBabyScan - Red Tools 渗透测试
- daffainfo/apiguesser - Go script to guess an API key / OAuth token found during pentest. CLI version of https://github.com/daffainfo/apiguesser-web/
- 0xsha/ChainWalker - Rapid Smart Contract Crawler
- burpheart/cdnlookup - 一个使用 Edns-Client-Subnet(ECS) 遍历智能CDN节点IP地址的工具
- RicterZ/CVE-2021-3560-Authentication-Agent - PolicyKit CVE-2021-3560 Exploit (Authentication Agent)
- ofasgard/ungoliant - A web reconnaissance tool that proxies its results through Burp or ZAP.
- patrickhener/gonh - Nessus Parser and query tool written in go
- wikiZ/RedGuard - RedGuard is a C2 front flow control tool,Can avoid Blue Teams,AVs,EDRs check.
- alexbakker/log4shell-tools - Tool that runs a test to check whether one of your applications is affected by the recent vulnerabilities in log4j: CVE-2021-44228 and CVE-2021-45046
- kubernetes/minikube - Run Kubernetes locally
- tangxiaofeng7/zsxq_notice - 知识星球提醒
- zan8in/afrog - A Security Tool for Bug Bounty, Pentest and Red Teaming.
- deatil/lakego-admin - lakego-admin 是使用 gin、JWT 和 RBAC 的前后端分离的 go 后台管理系统。An admin api system with gin, JWT and RBAC.
- wrenchonline/glint - glint 是一款基于浏览器爬虫golang开发的web漏洞主动(被动)扫描器
- yarox24/EvtxHussar - Initial triage of Windows Event logs
- LubyRuffy/gofofa - fofa client in Go
- Yihsiwei/GoFileBinder - golang免杀捆绑器
- TryGOTry/xray_free_crack - xray_free_crack,通用xray白嫖高级版.
- chroblert/jishell - jishell - A powerful modern CLI and SHELL,with a msfconsole-like style
- optionalCTF/SSOh-No - User enumeration and password spraying tool for testing Azure AD
- openclarity/kubeclarity - KubeClarity is a tool for detection and management of Software Bill Of Materials (SBOM) and vulnerabilities of container images and filesystems
- 1ight-2020/GoRottenTomato - Go实现部分Rubeus功能,可执行asktgt, asktgs, s4u, describe ticket, renew ticket, asreproast等
- sealerio/sealer - Build, Share and Run Both Your Kubernetes Cluster and Distributed Applications (Project under CNCF)
- redcode-labs/GoSH - Golang reverse/bind shell generator
- s4hm4d/shodanidb - Fetch data (open ports, CVEs, CPEs, ...) from shodan internetDB API
- alanEG/Gosna - Dynamic url monitor
- cycraft-corp/Prometheus-Decryptor - Prometheus-Decryptor is a project to decrypt files encrypted by Prometheus ransomware.
- sourque/louis - Linux EDR written in Golang and based on eBPF.
- snehshah22/DNS_poison_attack - On-path DNS poisoning attack tool.
- Ciyfly/woodpecker - 兼容xray nuclei yaml格式 以及go代码格式的poc验证扫描器
- ac0d3r/xssfinder - XSS discovery tool
- xwjdsh/manssh - Manage your ssh alias configs easily.
- SummerSec/SpringExploit - 🚀 一款为了学习go而诞生的漏洞利用工具
- ExpLangcn/Aopo - 内网自动化快速打点工具|资产探测|漏洞扫描|服务扫描|弱口令爆破
- hakluke/hakoriginfinder - Tool for discovering the origin host behind a reverse proxy. Useful for bypassing cloud WAFs!
- mittwald/kubernetes-replicator - Kubernetes controller for synchronizing secrets & config maps across namespaces
- AlphabugX/Alphalog - DNSLOG、httplog、rmilog、ldaplog、jndi 等都支持,完全匿名 产品(fuzz.red),Alphalog与传统DNSLog不同,更快、更安全。
- ipfs/kubo - An IPFS implementation in Go
- j3ssie/cdnstrip - Striping CDN IPs from a list of IP Addresses
- ferreiraklet/airixss - Finding XSS during recon
- fuxiaohei/pugo - a simple site generator
- hakluke/hakip2host - hakip2host takes a list of IP addresses via stdin, then does a series of checks to return associated domain names.
- yuyan-sec/RedisEXP - Redis 漏洞利用工具
- lal0ne/vulnerability - 收集、整理、修改互联网上公开的漏洞POC
- ShangRui-hash/siusiu - 一款基于docker的渗透测试工具箱,致力于做到渗透工具随身携带、开箱即用、按需下载。
- google/licensecheck - The licensecheck package classifies license files and heuristically determines how well they correspond to known open source licenses.
- step-security/secure-repo - Orchestrate GitHub Actions Security
- brokercap/Bifrost - Bifrost ---- 面向生产环境的 MySQL,MariaDB,kafka 同步到Redis,MongoDB,ClickHouse,StarRocks,Doris,Kafka等服务的异构中间件
- learnerLj/geth-analyze - go-ethereum source code analyzation under the perspective of smart contract security
- sjatsh/unwxapkg - WeChat applet .wxapkg decoding tool
- wfinn/redirex - tool that generates bypasses for open redirects
- wfinn/ucors - tool that scans for CORS bypasses
- AidenPearce369/ADReaper - A fast enumeration tool for Windows Active Directory Pentesting written in Go
- six2dez/ipcdn - Check which CDN providers an IP list belongs to
- atsud0/frp-modify - frp0.38.1 支持域前置、远程加载配置文件、配置文件自删除、流量特征修改
- utkusen/wholeaked - a file-sharing tool that allows you to find the responsible person in case of a leakage
- corazawaf/coraza - OWASP Coraza WAF is a golang modsecurity compatible web application firewall library
- firefart/stunner - Stunner is a tool to test and exploit STUN, TURN and TURN over TCP servers.
- common-fate/granted - The easiest way to access your cloud.
- timwhitez/gobusterdns - lite version of gobuster. Only subdomain brute. 内网轻量化子域名爆破工具
- brentp/gargs - better(?) xargs in go
- login546/domainhouse - 子域名查询工具,接口来自【www.domainhouse.buzz】
- ZhuriLab/Starmap - 一个轮子融合的子域名收集小工具
- utkusen/socialhunter - crawls the website and finds broken social media links that can be hijacked
- bonjourmalware/melody - Melody is a transparent internet sensor built for threat intelligence. Supports custom tagging rules and vulnerable application simulation.
- ferreiraklet/Jeeves - Jeeves SQLI Finder
- codeyourweb/fastfinder - Incident Response - Fast suspicious file finder
- deepfence/PacketStreamer - :star: :star: Distributed tcpdump for cloud native environments :star: :star:
- tmoneypenny/conspirator - An enhanced collaborator-like standalone server
- takshal/freq - This is go CLI tool for send fast Multiple get HTTP request.
- MrTuxx/OffensiveGolang - A collection of offensive Go packages inspired by different Go repositories.
- mytechnotalent/turbo-attack - A turbo traffic generator pentesting tool to generate random traffic with random MAC and IP addresses in addition to random sequence numbers to a particular IP and port.
- mitchellh/golicense - Scan and analyze OSS dependencies and licenses from compiled Go binaries
- alist-org/alist - 🗂️A file list/WebDAV program that supports multiple storages, powered by Gin and Solidjs. / 一个支持多存储的文件列表/WebDAV程序,使用 Gin 和 Solidjs。
- damit5/gitdorks_go - 一款在github上发现敏感信息的自动化收集工具
- s0md3v/Smap - a drop-in replacement for Nmap powered by shodan.io
- ahhh/Ducky_Maker - A fun script to teach automation and create ducky scripts, from existing scripts or ASCII art files
- lithammer/fuzzysearch - :pig: Tiny and fast fuzzy search in Go
- pry0cc/tew - A quick ‘n dirty nmap parser written in Golang to convert nmap xml to IP:Port notation.
- binodlamsal/zerophish - Zero phish phishing simulated platform
- YaoApp/yao - :rocket: A performance app engine to create web services and applications in minutes.Suitable for AI, IoT, Industrial Internet, Connected Vehicles, DevOps, Energy, Finance and many other use-cases.
- Azure/AzureDefender-K8S-InClusterDefense
- hudangwei/codemillx - codemillx is a tool for CodeQL, extract the comments in the code and generate codeql module. 强化Go开源项目安全检测(内含开源项目漏洞挖掘方法)
- zombiezen/go-sqlite - Low-level Go interface to SQLite 3
- j3ssie/sdlookup - IP Lookups for Open Ports and Vulnerabilities from internetdb.shodan.io
- wumansgy/goEncrypt - go语言封装的各种对称加密和非对称加密,可以直接使用,包括3重DES,AES的CBC和CTR模式,还有RSA非对称加密,ECC椭圆曲线的加密和数字签名
- chaitin/veinmind-tools - veinmind-tools 是由长亭科技自研,基于 veinmind-sdk 打造的容器安全工具集
- projectdiscovery/uncover - Quickly discover exposed hosts on the internet using multiple search engines.
- JustinTimperio/gomap - A fully self-contained Nmap like parallel port scanning module in pure Golang that supports SYN-ACK (Silent Scans)
- bytedance/godlp - sensitive information protection toolkit
- goreleaser/goreleaser - Deliver Go binaries as fast and easily as possible
- tidwall/gjson - Get JSON values quickly - JSON parser for Go
- p7e4/dnsearch - using rapid7 open dns data search subdomain and reverse ip
- lprat/spyre - simple YARA-based IOC scanner (Forked project Spyre)
- bufsnake/aiqicha - 基于无头浏览器查询 爱企查 内的企业信息
- ffffffff0x/ones - 可用于多个网络资产测绘引擎 API 的命令行查询工具
- wagoodman/dive - A tool for exploring each layer in a docker image
- hahwul/authz0 - 🔑 Authz0 is an automated authorization test tool. Unauthorized access can be identified based on URLs and Roles & Credentials.
- Kevin-fqh/learning-k8s-source-code - k8s、docker源码分析、读书笔记
- naiba/nezha - :trollface: Self-hosted, lightweight server and website monitoring and O&M tool
- chroblert/JSigThief - Golang 版SigThief
- DataDog/stratus-red-team - :cloud: :zap: Granular, Actionable Adversary Emulation for the Cloud
- trufflesecurity/driftwood - Private key usage verification
- mhmdiaa/second-order - Second-order subdomain takeover scanner
- Le0nsec/SecCrawler - 一个方便安全研究人员获取每日安全日报的爬虫和推送程序,目前爬取范围包括先知社区、安全客、Seebug Paper、跳跳糖、奇安信攻防社区、棱角社区以及绿盟、腾讯玄武、天融信、360等实验室博客,持续更新中。
- feiyu563/nbping - nbping是为解决局域网大批量IP实例或主机探活,采用go协程并发处理,可以自定义并发的协程数量和输出结果.效率远高于现有的批量ping工具.
- antonmedv/fx - Terminal JSON viewer & processor
- wallarm/gotestwaf - An open-source project in Golang to asess different API Security tools and WAF for detection logic and bypasses
- kenjoe41/goSubsWordlist - Generate wordlist from already collected subdomains for bruteforcing purposes.
- aau-network-security/riotpot - IoT and Operational Technology Honeypot
- busterb/msmailprobe - Office 365 and Exchange Enumeration
- timwhitez/Doge-Gabh - GetProcAddressByHash/remap/full dll unhooking/Tartaru's Gate/Spoofing Gate/universal/Perun's Fart/Spoofing-Gate/EGG/RecycledGate/syswhisper/RefleXXion golang implementation
- bufsnake/blueming - 备份文件扫描,并自动进行下载
- fiatjaf/jiq - jid on jq - interactive JSON query tool using jq expressions
- phith0n/zkar - ZKar is a Java serialization protocol analysis tool implement in Go.
- shmilylty/netspy - netspy是一款快速探测内网可达网段工具(深信服深蓝实验室天威战队强力驱动)
- binganao/golang-shellcode-bypassav - 2021.12.9 使用go语言免杀360、微软、腾讯、火绒
- google/log4jscanner - A log4j vulnerability filesystem scanner and Go package for analyzing JAR files.
- xiecat/fofax - FOFAX是一个基于fofa.info的API命令行查询工具
- Hackmanit/Web-Cache-Vulnerability-Scanner - Web Cache Vulnerability Scanner is a Go-based CLI tool for testing for web cache poisoning. It is developed by Hackmanit GmbH (http://hackmanit.de/).
- ariary/TrojanSourceFinder - 🔎 Help find Trojan Source vulnerability in code 👀 . Useful for code review in project with multiple collaborators (CI/CD)
- 1ultimat3/tld-scan - Top level domain scanner in Go
- ravro-ir/log4shell-looker - log4jshell vulnerability scanner for bug bounty
- N0MoreSecr3ts/wraith - Uncover forgotten secrets and bring them back to life, haunting security and operations teams.
- panjf2000/gnet - 🚀 gnet is a high-performance, lightweight, non-blocking, event-driven networking framework written in pure Go.
- freshcn/qqwry - 纯真ip库的golang服务
- wolfeidau/golang-massl - Simple examples of configuring mutual authentication (MASSL)
- LeakIX/l9fuzz - Help fuzz various protocols and waits for ping backs Integrates LDAP server and JNDI payload
- hupe1980/scan4log4shell - Scanner to send specially crafted requests and catch callbacks of systems that are impacted by log4j log4shell vulnerability and to detect vulnerable log4j versions on your local file-system
- nodauf/GoMapEnum - User enumeration and password bruteforce on Azure, ADFS, OWA, O365, Teams and gather emails on Linkedin
- ariary/fileless-xec - Stealth dropper executing remote binaries without dropping them on disk .(HTTP3 support, ICMP support, invisible tracks, cross-platform,...)
- mmcdole/gofeed - Parse RSS, Atom and JSON feeds in Go
- palantir/log4j-sniffer - A tool that scans archives to check for vulnerable log4j versions
- 0xInfection/LogMePwn - A fully automated, reliable, super-fast, mass scanning and validation toolkit for the Log4J RCE CVE-2021-44228 vulnerability.
- proferosec/log4jScanner - log4jScanner provides the ability to scan internal subnets for vulnerable log4j web services
- 40a/go-powershell - Go wrapper for running PowerShell sessions
- containers/podman - Podman: A tool for managing OCI containers and pods.
- imgproxy/imgproxy - Fast and secure standalone server for resizing and converting remote images
- dvyukov/go-fuzz - Randomized testing for Go
- 0xInfection/PewSWITCH - A FreeSWITCH specific scanning and exploitation toolkit for CVE-2021-37624 and CVE-2021-41157.
- CTF-MissFeng/jsForward - 解决web及移动端H5数据加密Burp调试问题
- jas502n/Grafana-CVE-2021-43798 - Grafana Unauthorized arbitrary file reading vulnerability
- shirdonl/goWebActualCombat - 🔥🔥🔥🔥🔥🔥重磅!《Go Web编程实战派从入门到精通》随书源码开源啦,Go语言/Web开发/高并发/微服务/Gin/Redis/MongoDB/并发编程/Docker源码!欢迎star~
- krishpranav/webinfo - A web information gathering tool made in go - DNS / Subdomains / Ports / Directories enumeration
- lord3ver/gctsubdomains - Discover subdomains in Certificate Transparency logs using Google's Transparency Report
- byt3hx/gup - gup aka Get All Urls parameters to create wordlists for brute forcing parameters.
- lanyi1998/DNSlog-GO - DNSLog-GO 是一款golang编写的监控 DNS 解析记录的工具,自带WEB界面 / DNSLog-GO is a monitoring tool written in Golang that monitors DNS resolution records. It comes with a web interface.
- redtoolskobe/scaninfo - fast scan for redtools
- tomatome/grdp - pure golang rdp protocol
- code-scan/AutoSubtitles
- zyylhn/zscan - Zscan a scan blasting tool set
- zema1/yarx - An awesome reverse engine for xray poc. | 一个自动化根据 xray poc 生成对应靶站的工具
- NyDubh3/CuiRi - 一款红队专用免杀木马生成器,基于shellcode生成绕过所有杀软的木马。
- akkuman/toolset - 免杀小小工具集
- yqcs/ZheTian - ::ZheTian / 强大的免杀生成工具,Bypass All.
- NetSPI/goddi - goddi (go dump domain info) dumps Active Directory domain information
- botherder/androidqf - androidqf (Android Quick Forensics) helps quickly gathering forensic evidence from Android devices, in order to identify potential traces of compromise.
- tanc7/EXOCET-AV-Evasion - EXOCET - AV-evading, undetectable, payload delivery tool
- box/kube-applier - kube-applier enables automated deployment and declarative configuration for your Kubernetes cluster.
- lal0ne/monitor - 监控网站目录下的文件变更,通过钉钉机器人发送告警。
- vbouchaud/k8s-ldap-auth - Kubernetes webhook token authentication plugin implementation using ldap.
- mutagen-io/mutagen - Fast file synchronization and network forwarding for remote development
- p4gefau1t/trojan-go - Go实现的Trojan代理,支持多路复用/路由功能/CDN中转/Shadowsocks混淆插件,多平台,无依赖。A Trojan proxy written in Go. An unidentifiable mechanism that helps you bypass GFW. https://p4gefau1t.github.io/trojan-go/
- XiaoMi/soar - SQL Optimizer And Rewriter
- mainfunx/frpc_android - frpc_android 最新版本0.39.1
- lqqyt2423/go-mitmproxy - mitmproxy implemented with golang. 用 Golang 实现的中间人攻击(Man-in-the-middle),解析、监测、篡改 HTTP/HTTPS 流量。
- Maka8ka/NGLite - A major platform RAT Tool based by Blockchain/P2P.Now support Windows/Linux/MacOS
- lwch/natpass - 🔥居家办公,远程开发神器
- akkuman/gSigFlip - A SigFlip implement in golang
- IngoKl/HTTPUploadExfil - A simple HTTP server for delivering and exfiltrating files/data during, for example, CTFs.
- looCiprian/GC2-sheet - GC2 is a Command and Control application that allows an attacker to execute commands on the target machine using Google Sheet or Microsoft SharePoint List and exfiltrate files using Google Drive or Mi
- Rvn0xsy/zipcreater - ZipCreater主要应用于跨目录的文件上传漏洞的利用,它能够快速进行压缩包生成。
- Metarget/cloud-native-security-book - 《云原生安全:攻防实践与体系构建》资料仓库
- vyrus001/go-mimikatz - A wrapper around a pre-compiled version of the Mimikatz executable for the purpose of anti-virus evasion.
- cckuailong/hostscan - 自动化Host碰撞工具,帮助红队快速扩展网络边界,获取更多目标点
- R4yGM/dorkscout - DorkScout - Golang tool to automate google dork scan against the entiere internet or specific targets
- Tylous/ZipExec - A unique technique to execute binaries from a password protected zip
- akkuman/rotateproxy - 利用fofa搜索socks5开放代理进行代理池轮切的工具
- SkewwG/henggeFish - 自动化批量发送钓鱼邮件(横戈安全团队出品)
- super-l/codelines - 一款基于GO语言,支持跨平台,可以统计项目代码行数的软件(命令行软件,无界面),支持多种自定义过滤。 主要用于代码安全审计服务相关的费用评估。
- FourCoreLabs/EDRHunt - Scan installed EDRs and AVs on Windows
- openrdap/rdap - RDAP command line client
- Shu1L/avbypass - 简单go加载器实现免杀360 火绒
- glebarez/cero - Scrape domain names from SSL certificates of arbitrary hosts
- knes1/elktail - Command line utility to query, search and tail EL (elasticsearch, logstash) logs
- mhmdiaa/chronos - Wayback Machine OSINT Framework
- un4gi/fave - Search for vulnerabilities and exposures while filtering based on age, keywords, and other parameters.
- kirides/screencapture - This repository has been moved to https://github.com/kirides/go-d3d
- fuzz7j/cDogScan - 多服务口令爆破、内网常见服务未授权访问探测,端口扫描
- ariary/QueenSono - Golang binary for data exfiltration with ICMP protocol (+ ICMP bindshell, http over ICMP tunneling, ...)
- sh4hin/GoPurple - Yet another shellcode runner consists of different techniques for evaluating detection capabilities of endpoint security solutions
- raverrr/plution - Prototype pollution scanner using headless chrome
- Rvn0xsy/red-tldr - red-tldr is a lightweight text search tool, which is used to help red team staff quickly find the commands and key points they want to execute, so it is more suitable for use by red team personnel wit
- akkuman/EvilEye - A BeaconEye implement in Golang. It is used to detect the cobaltstrike beacon from memory and extract some configuration.
- galli-leo/emmutaler - A set of tools for fuzzing SecureROM. Managed to find and trigger checkm8.
- lucaslorentz/caddy-docker-proxy - Caddy as a reverse proxy for Docker
- yunginnanet/prox5 - 🧮 SOCKS5/4/4a 🌾 validating proxy pool and upstream SOCKS5 server for 🤽 LOLXDsoRANDum connections 🎋
- BishopFox/dufflebag - Search exposed EBS volumes for secrets
- drosseau/degob - Go library/tool for viewing and reversing Go gob data [Moved to GitLab]
- 0xERR0R/blocky - Fast and lightweight DNS proxy as ad-blocker for local network with many features
- xjasonlyu/tun2socks - tun2socks - powered by gVisor TCP/IP stack
- xiecat/goblin - 一款适用于红蓝对抗中的仿真钓鱼系统
- CasperGN/GoHead - Get interesting http headers, internal IPs, possible endpoints from target(s) and search JS files for juicy info
- harleo/knockknock - A simple reverse whois lookup tool which returns a list of domains owned by people or companies
- MPaandeey/dlevel - A tool get level of subdomain from 1....n
- i5nipe/nipejs - Simplify your life with leak detection in JavaScript. NipeJS streamlines the use of regex, making it effortless to uncover potential leaks.
- un4gi/dirtywords - A targeted word list generation tool
- incogbyte/gojsx - Find juicy information inside javascript files.
- FleexSecurity/fleex - Fleex makes it easy to create multiple VPS on cloud providers and use them to distribute workloads.
- 0xTeles/jsleak - a Go code to detect leaks in JS files via regex patterns
- cryonayes/GoFilter - A tool to filter URLs by parameter count or size
- thelikes/fuzznav - parse ffuf & map endpoints to wordlists
- dqcostin/fxr - 使用fscan联动Xray
- slimtoolkit/slim - Slim(toolkit): Don't change anything in your container image and minify it by up to 30x (and for compiled languages even more) making it secure too! (free and open source)
- haojie06/selfhelp-iptables - 通过http api自助添加iptables白名单与黑名单的工具,防止nmap等程序的端口扫描和恶意主动探测,防止ssh、mysql等敏感服务受到攻击,并能对探测进行记录。
- darkb1rd/DarkGld - A tool for quickly generating fishing Trojan horse.
- ethicalhackingplayground/tprox - TProx is a fast reverse proxy path traversal detector and directory bruteforcer.
- jakubd/apkreport - Generate CSV Reports of MobSF Results
- pwnesia/dnstake - DNSTake — A fast tool to check missing hosted DNS zones that can lead to subdomain takeover
- neex/http2smugl
- wrfly/gus-proxy - "打一枪换一个地方" 一个HTTP代理
- ossf/allstar - GitHub App to set and enforce security policies
- mosajjal/dnsmonster - Passive DNS Capture and Monitoring Toolkit
- j3ssie/goverview - goverview - Get an overview of the list of URLs
- alexzorin/cve-2021-34558
- JKme/cube - 内网渗透测试工具,弱密码爆破、信息收集和漏洞扫描
- 0voice/Introduction-to-Golang - 【未来服务器端编程语言】最全空降golang资料补给包(满血战斗),包含文章,书籍,作者论文,理论分析,开源框架,云原生,大佬视频,大厂实战分享ppt
- marv2097/siprocket - Fast SIP and SDP Parser
- desertbit/grumble - A powerful modern CLI and SHELL
- praetorian-inc/gokart - A static analysis tool for securing Go code
- Tylous/SourcePoint - SourcePoint is a C2 profile generator for Cobalt Strike command and control servers designed to ensure evasion.
- timwhitez/doge-getsys - An easy way to getsystem by golang.
- binwiederhier/replbot - Slack/Discord bot for running interactive REPLs and shells from a chat.
- sanity-io/litter - Litter is a pretty printer library for Go data structures to aid in debugging and testing.
- h0x0er/andromanifest - AndroidManifest.xml parser written in go
- krishpranav/sshpot - A simple ssh honey pot, fake ssh server that lets anyone to connect and monitor their activty
- ContainerSSH/ContainerSSH - ContainerSSH: Launch containers on demand
- goodwithtech/dockle - Container Image Linter for Security, Helping build the Best-Practice Docker Image, Easy to start
- saferwall/saferwall - :cloud: Collaborative Malware Analysis Platform at Scale
- kube-tarian/tarian - Protect your Cloud Native Applications running on Kubernetes from malicious attacks with pre-registered source code, pre-registered runtime processes monitoring, automated actions based on configure-a
- perlogix/cmon - NIST Information Security Continuous Monitoring (ISCM) and configuration baseline data collector
- VerSprite/alpnpass - This tool will listen on a given port, strip SSL encryption, forward traffic through a plain TCP proxy, then encrypt the returning traffic again and send it to the target of your choice. Unlike most S
- antihax/gambit - GaMBiT Honeypot
- octarinesec/kube-scan - kube-scan: Octarine k8s cluster risk assessment tool
- endorama/devid - Securely manage your developer personas
- aveyuan/icpquery - ICP备案查询库
- gofiber/fiber - ⚡️ Express inspired web framework written in Go
- KalbiProject/kalbi - Kalbi - Golang Session Initiated Protocol Framework
- iiiusky/webrtc-proxy - 反向代理+webrtc 神不知鬼不觉的获取真实IP
- EatonChips/wsh - Web shell generator and command line interface.
- k0kubun/pp - Colored pretty printer for Go language
- Rvn0xsy/goDomain - Windows活动目录中的LDAP信息收集工具
- Ne0nd0g/merlin - Merlin is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in golang.
- Dc4ts/ChangeTower - ChangeTower is intended to help you watch changes in webpages and get notified of any changes written in Go
- Ne0nd0g/go-shellcode - A repository of Windows Shellcode runners and supporting utilities. The applications load and execute Shellcode using various API calls or techniques.
- capnspacehook/taskmaster - Windows Task Scheduler Library for Go
- banzaicloud/dast-operator - Dynamic Application and API Security Testing
- jeessy2/ddns-go - Simple and easy to use DDNS. Support Aliyun, Tencent Cloud, Dnspod, Cloudflare, Callback, Huawei Cloud, Baidu Cloud, Porkbun, GoDaddy, Namecheap, NameSilo...
- haochen233/socks5 - A Go library about socks5, supports all socks5 commands. That Provides server and client and easy to use. Compatible with socks4 and socks4a.
- koho/frpmgr - Windows 平台的 FRP GUI 客户端 / A user-friendly desktop GUI client for FRP on Windows.
- daffainfo/Git-Secret - Go scripts for finding sensitive data like API key / some keywords in the github repository
- benmanns/goworker - goworker is a Go-based background worker that runs 10 to 100,000* times faster than Ruby-based workers.
- fullstorydev/grpcurl - Like cURL, but for gRPC: Command-line tool for interacting with gRPC servers
- miku/esbulk - Bulk indexing command line tool for elasticsearch.
- For-ACGN/MS17-010 - An EternalBlue exploit implementation in pure go
- cockroachdb/pebble - RocksDB/LevelDB inspired key-value database in Go
- derekparker/delve - Delve is a debugger for the Go programming language.
- m-mizutani/octovy - Trivy based vulnerability management service
- inspiringz/fofa - 一款 Go 语言编写的小巧、简洁、快速采集 fofa 数据导出到 Excel 表单的小工具。
- Li4n0/revsuit - RevSuit is a flexible and powerful reverse connection platform designed for receiving connection from target host in penetration.
- nicocha30/ligolo-ng - An advanced, yet simple, tunneling/pivoting tool that uses a TUN interface.
- fengziHK/bypass_go - bypass_go cs免杀
- Lmg66/shellcodeloading - shellcode加载器 golang 分离免杀
- TryGOTry/go-shellcode-webimg-load - golang shellcode loader 远程图片隐写加载执行 无文件落地
- projectdiscovery/simplehttpserver - Go alternative of python SimpleHTTPServer
- Josue87/roboxtractor - Extract endpoints marked as disallow in robots files to generate wordlists.
- daffainfo/Key-Checker - Go scripts for checking API key / access token validity
- lkarlslund/Adalanche - Active Directory ACL Visualizer and Explorer - who's really Domain Admin? (Commerical versions available from NetSection)
- kleiton0x00/ppmap - A scanner/exploitation tool written in GO, which leverages client-side Prototype Pollution to XSS by exploiting known gadgets.
- allyomalley/dnsobserver - A handy DNS service written in Go to aid in the detection of several types of blind vulnerabilities. It monitors a pentester's server for out-of-band DNS interactions and sends lookup notifications vi
- Ullaakut/Gorsair - Gorsair gives root access on remote docker containers that expose their APIs
- redcode-labs/neurax - A framework for constructing self-spreading binaries
- aktsk/ipa-medit - Memory modification tool for re-signed ipa supports iOS apps running on iPhone and Apple Silicon Mac without jailbreaking.
- immunIT/TeamsUserEnum - User enumeration with Microsoft Teams API
- lesnuages/hershell - Multiplatform reverse shell generator
- txthinking/tun2brook - Proxy all traffic just one line command. tun2socks, tun2brook. IPv4 and IPv6, TCP and UDP.
- ThreeDotsLabs/watermill - Building event-driven applications the easy way in Go.
- google/cel-spec - Common Expression Language -- specification and binary representation
- Fahrj/reverse-ssh - Statically-linked ssh server with reverse shell functionality for CTFs and such
- esrrhs/spp - A simple and powerful proxy
- daffainfo/bypass-403 - Go script for bypassing 403 forbidden
- Maka8ka/Faygo - A major platforms RAT Tools .High scalability.Now support Windows/Linux/MacOS
- xm1k3/cent - Community edition nuclei templates, a simple tool that allows you to organize all the Nuclei templates offered by the community in one place
- iammaguire/MeetC2 - Modular C2 framework aiming to ease post exploitation for red teamers.
- irsl/gcp-dhcp-takeover-code-exec - Google Compute Engine (GCE) VM takeover via DHCP flood - gain root access by getting SSH keys added by google_guest_agent
- ethicalhackingplayground/erebus - Erebus is a fast tool for parameter-based vulnerability scanning using a Yaml based template engine like nuclei.
- grines/scour
- edoardottt/cariddi - Take a list of domains, crawl urls and scan for endpoints, secrets, api keys, file extensions, tokens and more
- wahaha1573/ByPassAVAddUser
- KubeOperator/KubeOperator - KubeOperator 是一个开源的轻量级 Kubernetes 发行版,专注于帮助企业规划、部署和运营生产级别的 K8s 集群。
- spf13/viper - Go configuration with fangs
- ccfos/nightingale - An all-in-one observability solution which aims to combine the advantages of Prometheus and Grafana. It manages alert rules and visualizes metrics, logs, traces in a beautiful web UI.
- projectdiscovery/hmap - Hybrid memory/disk map
- SPuerBRead/mqtts - MQTT安全测试工具 (MQTT Security Tools)
- dumorewithcode/purl
- jafarlihi/rconn - rconn is a multiplatform program for creating generic reverse connections. Lets you consume services that are behind firewall or NAT without opening ports or port-forwarding.
- redcode-labs/UnChain - A tool to find redirection chains in multiple URLs
- xiaobaiTech/golangFamily - 【超全golang面试题合集+golang学习指南+golang知识图谱+入门成长路线】 一份涵盖大部分golang程序员所需要掌握的核心知识。常用第三方库(mysql,mq,es,redis等)+机器学习库+算法库+游戏库+开源框架+自然语言处理nlp库+网络库+视频库+微服务框架+视频教程+音频音乐库+图形图片库+物联网库+地理位置信息+嵌入式脚本库+编译器库+数据库+金融库+电子邮件库+电子
- yumusb/DNSLog-Platform-Golang - DNSLOG平台 golang
- redcode-labs/Coldfire - Golang malware development library
- sigstore/cosign - Code signing and transparency for containers and binaries
- zu1k/proxypool - Automatically crawls proxy nodes on the public internet, de-duplicates and tests for usability and then provides a list of nodes
- tenable/terrascan - Detect compliance and security violations across Infrastructure as Code to mitigate risk before provisioning cloud native infrastructure.
- adamyi/CTFProxy - Your ultimate infrastructure to run a CTF, with a BeyondCorp-like zero-trust network and simple infrastructure-as-code configuration.
- eikendev/hackenv - Manage and access your Kali Linux or Parrot Security VM from the terminal (SSH support + file sharing, especially convenient during CTFs, Hack The Box, etc.) :rocket::wrench:
- togettoyou/ipashare - 🚤 share and install your Apple ipa
- KCarretto/paragon - Red Team engagement platform with the goal of unifying offensive tools behind a simple UI
- spyse-com/go-spyse - The official wrapper for spyse.com API, written in Go, aimed to help developers build their integrations with Spyse.
- Daybr4ak/C2ReverseProxy - 一款可以在不出网的环境下进行反向代理及cs上线的工具
- jiaocoll/GoWebBanner - Go语言web指纹识别
- niudaii/webscan - web信息收集工具。Web Information Collection Tool.
- WhiteHSBG/fofaSearch-go - go实现的fofa搜索批量工具 需要高级会员
- canc3s/judas - 轻便的恶意反代
- idiotc4t/Reflective-HackBrowserData - HackBrowserData的反射模块
- marmotedu/iam - 企业级的 Go 语言实战项目:认证和授权系统(带配套课程)
- edoardottt/lit-bb-hack-tools - Little Bug Bounty & Hacking Tools⚔️
- kubecost/kubectl-cost - CLI for determining the cost of Kubernetes workloads
- ahmetak4n/radar - Scanner for misconfigured DevSecOps or Security tools on internet like SonarQube, GoPhish etc.
- TardC/fofadump - A small utility that calls fofa api to download data.
- koderover/zadig - Zadig is a cloud native, distributed, developer-oriented DevOps platform
- golang/vulndb - [mirror] The Go Vulnerability Database
- Josue87/AnalyticsRelationships - Get related domains / subdomains by looking at Google Analytics IDs
- umputun/reproxy - Simple edge server / reverse proxy
- ipinfo/cli - Official Command Line Interface for the IPinfo API (IP geolocation and other types of IP data)
- Sakurasan/scf-proxy - 云函数代理服务
- activecm/rita - Real Intelligence Threat Analytics (RITA) is a framework for detecting command and control communication through network traffic analysis.
- work-helper/command-search-alfred - alfred命令搜索workflow
- akavel/rsrc - Tool for embedding .ico & manifest resources in Go programs for Windows.
- jweny/pocassist - 傻瓜式漏洞PoC测试框架
- optiv/Dent - A framework for creating COM-based bypasses utilizing vulnerabilities in Microsoft's WDAPT sensors.
- TryGOTry/multiplexing_port_socks5 - 一款golang写的支持http与socks5的端口复用小工具,并且可以开启socks5代理。
- superfashi/pwnlib - A Go rewrite of pwntools.
- projectdiscovery/interactsh - An OOB interaction gathering server and client library
- hanc00l/TXPortMap - Port Scanner & Banner Identify From TianXiang
- 4dogs-cn/TXPortMap - Port Scanner & Banner Identify From TianXiang
- chenjia404/p2ptunnel - A p2p-based tcp, udp intranet penetration tunneling tool
- vugu/vugu - Vugu: A modern UI library for Go+WebAssembly (experimental)
- 1340691923/ElasticView - 这是一个简单好用的ElasticSearch可视化客户端,支持连接6,7,8版本的ES,不妨一试
- binyoucai/sec
- redcode-labs/GodSpeed - Fast and intuitive manager for multiple reverse shells
- 0xrawsec/whids - Open Source EDR for Windows
- k3s-io/kine - Run Kubernetes on MySQL, Postgres, sqlite, dqlite, not etcd.
- yunxu1/dnsub - dnsub一款好用且强大的子域名扫描工具
- Matrix86/flowdownloader - Simple software to download HLS encrypted files used by FlowPlayer video player
- charmbracelet/glow - Render markdown on the CLI, with pizzazz! 💅🏻
- inbug-team/InScan - 边界打点后的自动化渗透工具
- assetnote/kiterunner - Contextual Content Discovery Tool
- Alaa-abdulridha/SerpScan - Serpscan is a powerfull php script designed to allow you to leverage the power of dorking straight from the comfort of your command line.
- cyberark/kubesploit - Kubesploit is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in Golang, focused on containerized environments.
- redcode-labs/SNOWCRASH - A polyglot payload generator
- nyancrimew/goop - Yet another tool to dump a git repository from a website, focused on as-complete-as-possible dumps and handling weird edge-cases.
- glitchedgitz/cook - A wordlist framework to fullfill your kinks with your wordlists. For security researchers, bug bounty and hackers.
- rootklt/snowball - fofa+xray vul scan golang
- d3mondev/puredns - Puredns is a fast domain resolver and subdomain bruteforcing tool that can accurately filter out wildcard subdomains and DNS poisoned entries.
- genkiroid/cert - Cert is the Go tool to get TLS certificate information.
- kgoins/ldsview
- Tylous/Limelighter - A tool for generating fake code signing certificates or signing real ones
- riptl/cve-2021-3449 - CVE-2021-3449 OpenSSL denial-of-service exploit 👨🏻💻
- sw33tLie/bbscope - Scope gathering tool for HackerOne, Bugcrowd, Intigriti, YesWeHack, and Immunefi!
- kgretzky/evilginx2 - Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies, allowing for the bypass of 2-factor authentication
- muraenateam/muraena - Muraena is an almost-transparent reverse proxy aimed at automating phishing and post-phishing activities.
- hakluke/haktrails - Golang client for querying SecurityTrails API data
- evilsocket/stork - A small utility that aims to automate and simplify some tasks related to software release cycles.
- daehee/mildew - Dotmil subdomain discovery tool that scrapes domains from official DoD website directories and certificate transparency logs
- canc3s/cIPR - 将域名转为ip段权重
- staaldraad/turner - SOCKS5 and HTTP over TURN/STUN proxy
- joanbono/gap - Google Maps API checker
- AdguardTeam/dnsproxy - Simple DNS proxy with DoH, DoT, DoQ and DNSCrypt support
- canc3s/cSubsidiary - 利用天眼查查询企业子公司
- flavio/kube-image-bouncer - Simple endpoint for the ImagePolicyWebhook and the GenericAdmissionWebhook Kubernetes admission controllers
- canc3s/cDomain - 利用天眼查查询企业备案
- ZupIT/horusec - Horusec is an open source tool that improves identification of vulnerabilities in your project with just one command.
- kitabisa/mubeng - An incredibly fast proxy checker & IP rotator with ease.
- rakyll/hey - HTTP load generator, ApacheBench (ab) replacement
- 1ight-2020/Struts2Scanner - 一款Golang编写的Struts2漏洞检测和利用工具,支持并发批量检测
- M4DM0e/DirDar - DirDar is a tool that searches for (403-Forbidden) directories to break it and get dir listing on it
- gustavorobertux/gcs
- Rvn0xsy/Pricking - 基于反向代理的水坑部署工具
- optiv/CVE-2020-15931 - Netwrix Account Lockout Examiner 4.1 Domain Admin Account Credential Disclosure Vulnerability
- kost/revsocks - Reverse SOCKS5 implementation in Go
- kuriv/civil-service-exam - 公务员考试知识思维导图,我们岸上见!
- liamg/traitor - :arrow_up: :skull_and_crossbones: :fire: Automatic Linux privesc via exploitation of low-hanging fruit e.g. gtfobins, pwnkit, dirty pipe, +w docker.sock
- deepfence/SecretScanner - :unlock: :unlock: Find secrets and passwords in container images and file systems :unlock: :unlock:
- hahwul/backbomb - 💣 Dockerized penetration-testing/bugbounty/app-sec testing environment
- hahwul/gee - 🏵 Gee is tool of stdin to each files and stdout. It is similar to the tee command, but there are more functions for convenience. In addition, it was written as go
- ryandamour/ssrfuzz - SSRFuzz is a tool to find Server Side Request Forgery vulnerabilities, with CRLF chaining capabilities
- gustavorobertux/goshock - SonicWall VPN-SSL Exploit* using Golang ( * and other targets vulnerable to shellshock ).
- jaswdr/faker - :rocket: Ultimate fake data generator for Go with zero dependencies
- mehrdadrad/tcpdog - eBPF based TCP observability.
- R0X4R/ssrf-tool - An SSRF detector tool written in golang. I have fixed some errors and added some more payloads to it. But the tool credits go to z0idsec.
- runZeroInc/recog-go - Recog-Go: Pattern Recognition using Rapid7 Recog
- seventh-letter/DictGenerate - 使用Go语言编写的社工字典生成器(The social engineering dictionary generator written by Go)
- evilsocket/uroboros - A GNU/Linux monitoring and profiling tool focused on single processes.
- optiv/ScareCrow - ScareCrow - Payload creation framework designed around EDR bypass.
- evilsocket/ditto - A tool for IDN homograph attacks and detection.
- tehmoon/http-fuzzer
- n9e/k8s-mon - 滴滴夜莺Kubernetes monitor
- EdgeSecurityTeam/EHole - EHole(棱洞)3.0 重构版-红队重点攻击系统指纹探测工具
- juicedata/juicefs - JuiceFS is a distributed POSIX file system built on top of Redis and S3.
- doitintl/kubeip - Assign static public IPs to Kubernetes nodes (GKE, EKS)
- thibmaek/go-volumio-mqtt-proxy
- JavierOlmedo/ipdiscover - 🔍 A simple tool to obtain long lists of ips from domains using goroutines
- bytedance/Elkeid - Elkeid is an open source solution that can meet the security requirements of various workloads such as hosts, containers and K8s, and serverless. It is derived from ByteDance's internal best practices
- hahwul/MobileHackersWeapons - Mobile Hacker's Weapons / A collection of cool tools used by Mobile hackers. Happy hacking , Happy bug-hunting
- C4o/FBI-Analyzer - A Flexible Log Analysis System Based on Golang and Lua-Plugins. 插件化的准实时日志分析系统。
- moloch--/denim - Automated compiler obfuscation for nim
- alltom/dirgui - turn a directory into a GUI, slash example of VNC-based GUI
- gomodules/notify - Send notification via Email, SMS, Chat etc.
- 0xsapra/fuzzparam
- Charlie-belmer/nosqli - NoSql Injection CLI tool, for finding vulnerable websites using MongoDB.
- acme-dns/acme-dns-client - A client software for https://github.com/joohoi/acme-dns
- goretk/redress - Redress - A tool for analyzing stripped Go binaries
- riza/gigger - Git folder digger, I'm sure it's worthwhile stuff.
- alpkeskin/mosint - An automated e-mail OSINT tool
- nytr0gen/deduplicate - Remove duplicate urls from input
- edoardottt/scilla - Information Gathering tool - DNS / Subdomains / Ports / Directories enumeration
- m7shapan/querycsv - QueryCSV enables you to load CSV files and manipulate them using SQL queries then after you finish you can export the new values to a CSV file
- tomnomnom/meg - Fetch many paths for many hosts - without killing the hosts
- michenriksen/Amass - In-depth Attack Surface Mapping and Asset Discovery
- jm33-m0/emp3r0r - Linux/Windows post-exploitation framework made by linux user
- assetnote/commonspeak2 - Leverages publicly available datasets from Google BigQuery to generate content discovery and subdomain wordlists
- CTF-MissFeng/GoScan - GoScan是采用Golang语言编写的一款分布式综合资产管理系统,适合红队、SRC等使用
- posener/h2conn - HTTP2 client-server full-duplex connection
- Ridter/p12tool - A simple Go script to brute force or parse a password-protected PKCS#12 (PFX/P12) file.
- ranon-rat/sayBruh - its a rebuild of saycheese with golang
- mlcsec/headi - Customisable and automated HTTP header injection
- bp0lr/linkz
- netxfly/sec-dev-in-action-src - 《白帽子安全开发实战》配套代码
- pelaohxc/postMessageFinder
- C-Sto/GoGitDumper - Dump exposed HTTP .git fast
- sudosammy/knary - A simple HTTP(S) and DNS Canary bot with Slack/Discord/MS Teams/Lark/Telegram & Pushover support
- ameenmaali/qsfuzz - qsfuzz (Query String Fuzz) allows you to build your own rules to fuzz query strings and easily identify vulnerabilities.
- hahwul/mzap - ⚡️ Multiple target ZAP Scanning
- ezekg/git-hound - Git plugin that prevents sensitive data from being committed.
- root4loot/rescope - A scope generation tool for Burp Suite & ZAP
- awgh/madns - DNS server for pentesters
- braaaax/gfz
- gen2brain/url2img - HTTP server with API for capturing screenshots of websites
- arkrz/v2sub - 用于 linux 下订阅 v2ray 的小工具。
- jimareed/casbin-auth0-rbac-backend - Example RBAC implementation with Casbin and Auth0
- Hackl0us/GeoIP2-CN - 小巧精悍、准确、实用 GeoIP2 数据库
- bp0lr/dmut - A tool to perform permutations, mutations and alteration of subdomains in golang.
- tismayil/rsdl - Subdomain Scan With Ping Method.
- projectdiscovery/proxify - A versatile and portable proxy for capturing, manipulating, and replaying HTTP/HTTPS traffic on the go.
- rmb122/rogue_mysql_server - A rouge mysql server supports reading files from most mysql libraries of multiple programming languages.
- bp0lr/dnsfaster - Test the speed and reliability of a list of DNS servers
- projectdiscovery/cloudlist - Cloudlist is a tool for listing Assets from multiple Cloud Providers.
- mehrdadrad/tcpprobe - Modern TCP tool and service for network performance observability.
- ReddyyZ/urlbrute - Directory/Subdomain scanner developed in GoLang.
- fzakaria/autopatchelf
- dwisiswant0/galer - A fast tool to fetch URLs from HTML attributes by crawl-in.
- denandz/sourcemapper - Extract JavaScript source trees from Sourcemap files
- cloudquery/cloudquery - The open source high performance ELT framework powered by Apache Arrow
- FairwindsOps/nova - Find outdated or deprecated Helm charts running in your cluster.
- matryer/xbar - Put the output from any script or program into your macOS Menu Bar (the BitBar reboot)
- gorse-io/gorse - Gorse open source recommender system engine
- ribbybibby/ssl_exporter - Exports Prometheus metrics for TLS certificates
- sysdream/chashell - Chashell is a Go reverse shell that communicates over DNS. It can be used to bypass firewalls or tightly restricted networks.
- utkusen/urlhunter - a recon tool that allows searching on URLs that are exposed via shortener services
- lobuhi/byp4xx - 40X/HTTP bypasser in Go. Features: Verb tampering, headers, #bugbountytips, User-Agents, extensions, default credentials...
- Cgboal/exclude-cdn - Wraps projectdiscovery's cdncheck library to exclude CDN hosts from input passed over stdin
- ipipdotnet/ipdb-go - IPIP.net officially supported IP database ipdb format parsing library
- idoubi/goz - A fantastic HTTP request libarary used in Golang.
- MaxSecurity/BurpSuite-MacOS-Crack
- projectdiscovery/collaborator - BurpSuite Standard/Private Collaborator Library
- digininja/GitHunter - A tool for searching a Git repository for interesting content
- cdk-team/CDK - 📦 Make security testing of K8s, Docker, and Containerd easier.
- rvrsh3ll/RendezvousRAT - Self-healing RAT utilizing libp2p
- shadow1ng/fscan - 一款内网综合扫描工具,方便一键自动化、全方位漏扫扫描。
- xo/xo - Command line tool to generate idiomatic Go code for SQL databases supporting PostgreSQL, MySQL, SQLite, Oracle, and Microsoft SQL Server
- PaddlePaddle/PaddleCloud - PaddlePaddle Docker images and K8s operators for PaddleOCR/Detection developers to use on public/private cloud.
- uknowsec/keylogger - 键盘记录,支持定时回传
- aquasecurity/starboard - Moved to https://github.com/aquasecurity/trivy-operator
- ossf/scorecard - OpenSSF Scorecard - Security health metrics for Open Source
- yolossn/Prometheus-Basics - Prometheus-Basics is part of Prometheus Docs now, checkout 👇
- RedTeamPentesting/CVE-2020-13935 - Exploit for WebSocket Vulnerability in Apache Tomcat
- projectdiscovery/notify - Notify is a Go-based assistance package that enables you to stream the output of several tools (or read from a file) and publish it to a variety of supported platforms.
- ExploitBox/git-lfs-RCE-exploit-CVE-2020-27955-Go
- iiiusky/alicloud-tools - 阿里云ECS、策略组辅助小工具
- anchore/grype - A vulnerability scanner for container images and filesystems
- A-D-Team/grafanaExp - A exploit tool for Grafana Unauthorized arbitrary file reading vulnerability (CVE-2021-43798), it can burst plugins / extract secret_key / decrypt data_source info automatic.
- shadowabi/AutoDomain - 自动提取主域名/IP,并调用fofa、quake、hunter等网络资产测绘系统搜集子域名,可配合指纹扫描工具达到快速资产整理
- clevercoder91/Subanser - A simple Golang Script where you provide list of domains you want to check if webserver is running on that port or not . Give it a Try !!
- sneakerhax/C2PE - C2 and Post Exploitation Code
- KingOfBugbounty/KingOfBugBountyTips - Our main goal is to share tips from some well-known bughunters. Using recon methodology, we are able to find subdomains, apis, and tokens that are already exploitable, so we can report them. We wish t
- sa7mon/S3Scanner - Scan for misconfigured S3 buckets across S3-compatible APIs!
- x90skysn3k/brutespray - Bruteforcing from various scanner output - Automatically attempts default creds on found services.
- GDATASoftwareAG/vaas - Verdict-as-a-Service SDKs: Analyze files for malicious content
- mlogclub/bbs-go - 基于Golang的开源社区系统。简洁对话,高效互动,社区新体验!
- t94j0/gophish-notifier - Notification webhook for GoPhish
- kN6jq/fingerScan - ehole指纹识别重构版,优化多个功能
- musiclover789/luna - Luna-抗指纹浏览器|爬虫|防反爬虫框架|浏览器指纹|自动化浏览器|防识别|反识别|爬虫框架|自动化测试框架
- HackAllSec/hfinger - 一个用于web框架、CDN和CMS指纹识别的高性能命令行工具。A high-performance command-line tool for web framework, CDN and CMS fingerprinting.
- hanbufei/isCdn - 检查一个ip是否在cdn范围内
- bytedance/vArmor - vArmor is a cloud native container sandbox system based on AppArmor/BPF/Seccomp. It also includes multiple built-in protection rules that are ready to use out of the box.
- Night-Master/sdlc - sdlc 是一个基于 Go 语言构建的安全漏洞示范平台,旨在促进 DevSecOps 和安全开发生命周期 (SDLC) 实践。它通过模拟常见漏洞来增强开发人员的安全意识,除了可以用于devsecops以外,还可以用于安全行业从事者学习漏洞知识或者渗透知识,代码审计,提供了一个实践和学习的环境。本项目采用了前后端分离的设计模式,其中后端利用了轻量级框架 Gin,而前端则使用了 Vue 3。
- adeljck/MS17-010 - MS17-010 Exploits With Original NSA Tool(only for windows)
- gtqbhksl/xcosx - XC+OS(操作系统)+X(X卫士)。面向xc操作系统的容器、镜像、文件系统扫描工具。支持扫描敏感信息、软件包漏洞、webshell、弱口令等问题
- wuxler/ruasec - RuaSec 是一个安全扫描工具,用于扫描镜像、代码、制品等中的安全漏洞。
- YouChenJun/Keydd - 从流量包匹配敏感信息的工具-可用作bp、浏览器的下游代理。0感知、无卡顿,支持https。
- berryalen02/PECracker - 针对PE文件的分离的攻防对抗工具,红队、研究者的好帮手。目前支持文件头伪装、证书区段感染。A no-kill confrontation tool for the separation of PE files, a good helper for red teams and researchers. Currently, file header spoofing and certificate s
- sspsec/Spear - 基于GO的渗透工具箱框架
- CodeSecurityTeam/frp - 基于frp-0.58.1魔改二开,随机化socks5账户密码及端口、钉钉上线下线通知、配置文件oss加密读取、域前置防止溯源、源码替换/编译混淆等
- Ackites/KillWxapkg - 自动化反编译微信小程序,小程序安全评估工具,发现小程序安全问题,自动解密,解包,可还原工程目录,支持Hook,小程序修改
- qwe1433223/EHole_magic_magic - 可以指定状态码和标题以排除不想要的数据,支持从管道符传入参数,根据cms类型来做总结输出
- trap-bytes/403jump - HTTP 403 bypass tool
- Mayter/mssql-command-tool - xp_cmdshell与sp_oacreate执行命令回显和clr加载程序集执行相应操作,上传,job等相应操作。
- r00tSe7en/URLPath - 批量处理url链接,获取多级路径并打印
- TryGOTry/AutoGeaconC2 - AutoGeaconC2: 一键读取Profile自动化生成geacon实现跨平台上线CobaltStrike
- fdx-xdf/darkPulse - darkPulse是一个用go编写的shellcode Packer,用于生成各种各样的shellcode loader,免杀火绒,360核晶等国内常见杀软。
- wgpsec/EndpointSearch - EndpointSearch 是一个探测云服务端点的扫描器。Endpoint Search is a sophisticated reconnaissance utility designed to discreetly identify and enumerate endpoints within cloud services.
- wgpsec/lc - LC(List Cloud)是一个多云攻击面资产梳理工具
- qi4L/qscan - 轻量化全方位扫描器
- SleepingBag945/dddd - dddd是一款使用简单的批量信息收集,供应链漏洞探测工具,旨在优化红队工作流,减少伤肝的机械性操作。支持从Hunter、Fofa批量拉取目标
- yhy0/Jie - Jie stands out as a comprehensive security assessment and exploitation tool meticulously crafted for web applications. Its robust suite of features encompasses vulnerability scanning, information gath
- INotGreen/XiebroC2 - 渗透测试C2、支持Lua插件扩展、域前置/CDN上线、自定义profile、前置sRDI、文件管理、进程管理、内存加载、截图、反向代理
- sspsec/Scan-Spring-GO - 针对SpringBoot的渗透工具,Spring漏洞利用工具
- p1d3er/RemoteWebScreen - 本项目是一个远程控制应用,使用 Golang 开发,允许用户通过 Web 界面远程控制和屏幕监控其他计算机。主要功能包括屏幕共享、鼠标和键盘控制以及键盘记录。
- Pizz33/Qianji - 千机-红队免杀木马自动生成器 Bypass defender、火绒、360等国内主流杀软 随机加密混淆shellcode快速生成免杀马
- youki992/VscanPlus - [VscanPlus内外网漏洞扫描工具]已更新HW热门漏洞检测POC。基于veo师傅的漏扫工具vscan二次开发的版本,端口扫描、指纹检测、目录fuzz、漏洞扫描功能工具,批量快速检测网站安全隐患。An open-source, cross-platform website vulnerability scanning tool that helps you quickly detect web
- Ernket/ARL-Finger-ADD-Go - ARL(灯塔)批量添加指纹
- corunb/Split_tools - 分割小工具,可分割木马,一键生成写入、合并、追加命令
- wjlin0/CVE-2024-23897 - CVE-2024-23897 - Jenkins 任意文件读取 利用工具
- qi4L/Struts2Scan.go - 用golang实现的Struts2扫描工具
- Pwn3rzs/HAK5-C2-License-Toolkit - Golang tool to help in forcing a license for HAK5 C2 Tool
- zan8in/pxplan - CVE-2022-2022
- ad-calcium/CVE-2023-22515 - Confluence未授权添加管理员用户(CVE-2023-22515)漏洞利用工具
- z-bool/Venom-Crawler - 毒液爬行器:专为捡洞而生的爬虫神器
- ch3nnn/webstack-go - 基于Gin框架的网址导航项目,具备完整的前后台。您可以拿来制作自己平日收藏的网址导航。
- GhostTroops/ksubdomain - 子域名爆破,增加了智能爬虫功能
- Tp0t-Team/Tp0tOJ - A CTF online judge platform developed by Tp0t.
- ASkyeye/CVE-2023-21839 - Weblogic CVE-2023-21839 RCE (无需Java依赖一键RCE)
- Valerian7/dns_capture
- l3yx/Choccy - GitHub项目监控 && CodeQL自动扫描 (GitHub project monitoring && CodeQL automatic analysis)
- BBD-YZZ/hvv2023check - 2023hvv期间部分爆出漏洞的辅助扫描工具
- X1r0z/ActiveMQ-RCE - ActiveMQ RCE (CVE-2023-46604) 漏洞利用工具
- qiwentaidi/Slack - 安服集成化工具平台,帮助测试人员减少测试脚本多,使用繁琐问题
- wux1an/wxapkg - 微信小程序反编译工具,.wxapkg 文件扫描 + 解密 + 解包工具
- ttstormxx/lineadd - lineadd 渗透测试字典管理工具, 让字典管理生活轻松一点。Penetration test dictionary management tool, make dictionary management life a little easier.
- Mustard404/AceofHearts - 红桃A(AceofHearts)是一款专为渗透测试人员设计的实用工具,旨在简化渗透测试环境的搭建过程并提供便捷的部署解决方案。
- anchore/harbor-scanner-adapter - Harbor Scanner Adapter for Anchore Engine and Enterprise
- fin3ss3g0d/evilgophish - evilginx3 + gophish
- NHAS/reverse_ssh - SSH based reverse shell
- wjlab/Darksteel - 域内自动化信息搜集利用工具
- gdy666/lucky - 软硬路由公网神器,ipv6/ipv4 端口转发,反向代理,DDNS,WOL,ipv4 stun内网穿透,cron,acme,阿里云盘,ftp,webdav,filebrowser
- ZhuriLab/Yi - 项目监控工具 以及 Codeql 自动运行
- redhuntlabs/BucketLoot - BucketLoot is an automated S3-compatible bucket inspector that can help users extract assets, flag secret exposures and even search for custom keywords as well as Regular Expressions from publicly-exp
- qi4L/seeyonerExp - 致远OA利用工具
- novysodope/fupo_for_yonyou - 用友漏洞检测,持续更新漏洞检测模块
- lemonlove7/EHole_magic - EHole(棱洞)魔改。可对路径进行指纹识别;支持识别出来的重点资产进行漏洞检测(支持从hunter和fofa中提取资产)支持对ftp服务识别及爆破
- zhaoyumi/WeaverExploit_All - 泛微最近的漏洞利用工具(PS:2023)
- STRRL/cloudflare-tunnel-ingress-controller - 🚀 Expose the website directly into the internet! The Kuberntes Ingress Controller based on Cloudflare Tunnel.
- adeljck/QAX_VPN_Crack - 奇安信VPN任意用户密码重置
- chaitin/blazehttp - BlazeHTTP 是一款简单易用的 WAF 防护效果测试工具。BlazeHTTP stands as a user-friendly WAF protection efficacy evaluation tool.
- chainreactors/gogo - 面向红队的, 高度可控可拓展的自动化引擎
- yhy0/ChYing - 承影 - 一款安全工具箱,集成了目录扫描、JWT、Swagger 测试、编/解码、轻量级 BurpSuite、杀软辅助功能
- whoissecure/yaset - Yet Another Subdomain Enumeration Tool, a template based tool to enumerate subdomains passively.
- piaolin/DetectDee - DetectDee: Hunt down social media accounts by username, email or phone across social networks.
- kunwu2023/kunwu - kunwu是新一代webshell检测引擎,使用了内置了模糊规则、污点分析模拟执行、机器学习三种高效的检测策略
- yusinomy/Rpcon - 内网横向利用工具,用于ssh wmiexec等常规服务,也可以当作一个数据库执行命令工具
- Hel10-Web/Databasetools - 一款用Go语言编写的数据库自动化提权工具,支持Mysql、MSSQL、Postgresql、Oracle、Redis数据库提权、命令执行、爆破以及ssh连接
- praetorian-inc/NTLMRecon - A tool for performing light brute-forcing of HTTP servers to identify commonly accessible NTLM authentication endpoints.
- praetorian-inc/fingerprintx - Standalone utility for service discovery on open ports!
- 1dayluo/subnya - 基于go语言和subfinder实现的用配置文件自定义配置,并以数据库方式跟踪记录子域名的新增减少| A new subdomain monitor tool!
- minio/simdjson-go - Golang port of simdjson: parsing gigabytes of JSON per second
- ConnectAI-E/feishu-openai - 🎒 飞书 ×(GPT-4 + GPT-4V + DALL·E-3 + Whisper)= 飞一般的工作体验 🚀 语音对话、角色扮演、多话题讨论、图片创作、表格分析、文档导出 🚀
- sari3l/notify - 各端、平台快速消息通知程序,支持配置文件形式或API调用
- adminlove520/Poc-Monitor_v1.0.1 - 威胁情报-漏洞存储库
- qi4L/GlangYsoserial - A Go library for generating Java deserialization payloads.
- Goqi/Ni - Ni-nuclei二开
- getanteon/anteon - Anteon (formerly Ddosify) - Effortless Kubernetes Monitoring and Performance Testing. Available on CLI, Self-Hosted, and Cloud
- wenxi-3000/YNM3000 - 要你命三千,集多种渗透工具于一身的终极武器霸王。
- GhostTroops/scan4all - Official repository vuls Scan: 15000+PoCs; 23 kinds of application password crack; 7000+Web fingerprints; 146 protocols and 90000+ rules Port scanning; Fuzz, HW, awesome BugBounty( ͡° ͜ʖ ͡°)...
- openclarity/openclarity - OpenClarity is an open source tool built to enhance security and observability of cloud native applications and infrastructure
- threatcl/threatcl - Documenting your Threat Models with HCL
- devploit/nomore403 - Tool to bypass 403/40X response codes.
- HopopOps/k8s-ldap-auth - Kubernetes webhook token authentication plugin implementation using ldap.
- o8oo8o/WebSSH - 功能强大,Go 实现的一个WebSSH,支持文件上传下载
- hueristiq/xurlfind3r - A command-line interface (CLI) based passive URLs discovery utility. It is designed to efficiently identify known URLs of given domains by tapping into a multitude of curated online passive sources.
- activecm/rita-legacy - Real Intelligence Threat Analytics (RITA) is a framework for detecting command and control communication through network traffic analysis.
- k8gege/LadonGo - Ladon for Kali 全平台开源内网渗透扫描器,Windows/Linux/Mac/路由器内网渗透,使用它可轻松一键批量探测C段、B段、A段存活主机、高危漏洞检测MS17010、SmbGhost,远程执行SSH/Winrm,密码爆破SMB/SSH/FTP/Mysql/Mssql/Oracle/Winrm/HttpBasic/Redis,端口扫描服务识别PortScan指纹识别/HttpBa
- teler-sh/teler - Real-time HTTP Intrusion Detection
- ThreatUnknown/jsubfinder - jsubfinder searches webpages for javascript & analyzes them for hidden subdomains and secrets (wip).
- kptdev/kpt - Automate Kubernetes Configuration Editing
- PentestPad/subzy - Subdomain takeover vulnerability checker
- sourcegraph/sourcegraph-public-snapshot - Code AI platform with Code Search & Cody
- apache/incubator-seata-go - Go Implementation For Seata
- 05sec/Cardinal - CTF🚩 AWD (Attack with Defense) 线下赛平台 / AWD platform - 欢迎 Star~ ✨
- tair-opensource/RedisShake - RedisShake is a Redis data processing and migration tool.
- rockstar2046/cmus-lyric - cmus lyric viewer
- go-gitea/gitea - Git with a cup of tea! Painless self-hosted all-in-one software development service, including Git hosting, code review, team collaboration, package registry and CI/CD
- kitabisa/teler - Real-time HTTP Intrusion Detection
- seata/seata-go - Go Implementation For Seata
- chenjiandongx/yap - 🚥 Yet another pinger: A high-performance ICMP ping implementation build on top of BPF technology.
- devploit/dontgo403 - Tool to bypass 40X response codes.
- channyein1337/gup - gup aka Get All Urls parameters to create wordlists for brute forcing parameters.
- KalbiProject/kalbi - Kalbi - Golang Session Initiated Protocol Framework
- Mdxjj/ByPassAVAddUser
- terorie/cve-2021-3449 - CVE-2021-3449 OpenSSL denial-of-service exploit 👨🏻💻
- ThreatUnkown/jsubfinder - jsubfinder searches webpages for javascript & analyzes them for hidden subdomains and secrets (wip).
- hueristiq/hqurlfind3r - A passive reconnaissance tool for known URLs discovery.
- VulnTotal-Team/Vehicle-Security-Toolkit - 汽车/安卓/固件/代码安全测试工具集
- hashsecteam/scf-proxy
- falcosecurity/kilt - Kilt is a project that defines how to inject foreign apps into containers
- GREENHAT7/pxplan - CVE-2022-2022
- unp4ck/gospf - Golang tool to parse netblocks and domain names from SPF and get information about ASN.
- tooBugs/golang-ReflectiveDLLInjection - golang ReflectiveDLLInjection
- avelino/awesome-go - A curated list of awesome Go frameworks, libraries and software
- coreybutler/nvm-windows - A node.js version management utility for Windows. Ironically written in Go.
- optiv/Ivy - Ivy is a payload creation framework for the execution of arbitrary VBA (macro) source code directly in memory. Ivy’s loader does this by utilizing programmatical access in the VBA object environment t
- Ciyfly/microwaveo - 将dll exe 等转成shellcode 最后输出exe 可定制加载器模板 支持白文件的捆绑 shellcode 加密
- ShadowFl0w/YNM3000 - 要你命三千,集多种渗透工具于一身的终极武器霸王。
- mstxq17/MoreFind - 一款用于快速导出URL、Domain和IP的小工具
- hktalent/scan4all - Official repository vuls Scan: 15000+PoCs; 23 kinds of application password crack; 7000+Web fingerprints; 146 protocols and 90000+ rules Port scanning; Fuzz, HW, awesome BugBounty( ͡° ͜ʖ ͡°)...
- 779789571/rsasZipToExcel - RSAS绿盟科技漏洞扫描html报告转excel
- TryGOTry/edit-gencon - geacon:简单适配了一个profile配置文件,可直接拿来修改使用,用于cs上线linux.
- chaosblade-io/chaosblade - An easy to use and powerful chaos engineering experiment toolkit.(阿里巴巴开源的一款简单易用、功能强大的混沌实验注入工具)
- murphysecurity/murphysec - An open source tool focused on software supply chain security. 墨菲安全专注于软件供应链安全,具备专业的软件成分分析(SCA)、漏洞检测、专业漏洞库。
- wgpsec/ENScan_GO - 一款基于各大企业信息API的工具,解决在遇到的各种针对国内企业信息收集难题。一键收集控股公司ICP备案、APP、小程序、微信公众号等信息聚合导出。
- sairson/Yasso - 强大的内网渗透辅助工具集-让Yasso像风一样 支持rdp,ssh,redis,postgres,mongodb,mssql,mysql,winrm等服务爆破,快速的端口扫描,强大的web指纹识别,各种内置服务的一键利用(包括ssh完全交互式登陆,mssql提权,redis一键利用,mysql数据库查询,winrm横向利用,多种服务利用支持socks5代理执行)
- veo/vscan - 开源、轻量、快速、跨平台 的网站漏洞扫描工具,帮助您快速检测网站安全隐患。功能 端口扫描(port scan) 指纹识别(fingerprint) 漏洞检测(nday check) 智能爆破 (admin brute) 敏感文件扫描(file fuzz)
- zhzyker/dismap - Asset discovery and identification tools 快速识别 Web 指纹信息,定位资产类型。辅助红队快速定位目标资产信息,辅助蓝队发现疑似脆弱点
- seccome/Ehoney - 安全、快捷、高交互、企业级的蜜罐管理系统,护网;支持多种协议蜜罐、蜜签、诱饵等功能。A safe, fast, highly interactive and enterprise level honeypot management system, supports multiple protocol honeypots, honeytokens, baits and other functions
- FunnyWolf/ligolo - Ligolo : 用于内网渗透的反向隧道
- yonyoucloud/install_k8s - 一键安装kubernets(k8s)系统,采用RBAC模式运行(证书安全认证模式),既可以单台安装、也可以集群安装,并且完全是生产环境的安装标准。有疑问大家可以加我微信沟通:bsh888
- LearnGolang/365Golang - 《365天深入理解Go语言》Deep understanding of Golang.
- lcvvvv/kscan - Kscan是一款纯go开发的全方位扫描器,具备端口扫描、协议检测、指纹识别,暴力破解等功能。支持协议1200+,协议指纹10000+,应用指纹20000+,暴力破解协议10余种。
- cyal1/host_scan - 这是一个用于IP和域名碰撞匹配访问的小工具,旨意用来匹配出渗透过程中需要绑定hosts才能访问的弱主机或内部系统。https://github.com/fofapro/Hosts_scan implement in Go
- timwhitez/Doge-Loader - 🐶Cobalt Strike Shellcode Loader by Golang
- awake1t/linglong - 一款甲方资产巡航扫描系统。系统定位是发现资产,进行端口爆破。帮助企业更快发现弱口令问题。主要功能包括: 资产探测、端口爆破、定时任务、管理后台识别、报表展示
- hahwul/jwt-hack - 🔩 jwt-hack is tool for hacking / security testing to JWT. Supported for En/decoding JWT, Generate payload for JWT attack and very fast cracking(dict/brutefoce)
- CTF-MissFeng/NmapTools - Go语言练习,第一个小工具,nmaptools解析xml导出xlsx结果、进行web服务探测、进行socket数据探测等
- vidar-team/Cardinal - CTF🚩 AWD (Attack with Defense) 线下赛平台 / AWD platform - 欢迎 Star~ ✨
- xluohome/phonedata - 手机号码归属地信息库、手机号归属地查询 phone.dat 最后更新:2023年02月
- GameXG/TcpRoute2 - TcpRoute , TCP 层的路由器。对于 TCP 连接自动从多个线路(电信、联通、移动)、多个域名解析结果中选择最优线路。
- go-admin-team/go-admin - 基于Gin + Vue + Element UI & Arco Design & Ant Design 的前后端分离权限管理系统脚手架(包含了:多租户的支持,基础用户管理功能,jwt鉴权,代码生成器,RBAC资源控制,表单构建,定时任务等)3分钟构建自己的中后台项目;项目文档》:https://www.go-admin.pro V2 Demo: https://vue2.go-admin.d
- gudegg/yunSpider - 百度云网盘爬虫
- master-coder-ll/v2ray-web-manager - v2ray-web-manager 是一个v2ray的面板,也是一个集群的解决方案;同时增加了流量控制/账号管理/限速等功能。key: admin , panel ,web,cluster,集群,proxy
- dreamans/syncd - syncd是一款开源的代码部署工具,它具有简单、高效、易用等特点,可以提高团队的工作效率.
- flipped-aurora/gin-vue-admin - 🚀Vite+Vue3+Gin的开发基础平台,支持TS和JS混用。它集成了JWT鉴权、权限管理、动态路由、显隐可控组件、分页封装、多点登录拦截、资源权限、上传下载、代码生成器【可AI辅助】、表单生成器和可配置的导入导出等开发必备功能。
- yangwenmai/learning-golang - Go 学习之路:Go 开发者博客、Go 微信公众号、Go 学习资料(文档、书籍、视频)
- aceld/zinx - A lightweight concurrent server framework based on Golang.
- boy-hack/goWhatweb - [学习GO] go语言写的web指纹识别 - Identify websites by go language
- ffhelicopter/Go42 - 《Go语言四十二章经》详细讲述Go语言规范与语法细节及开发中常见的误区,通过研读标准库等经典代码设计模式,启发读者深刻理解Go语言的核心思维,进入Go语言开发的更高阶段。
- alibaba/RedisShake - redis-shake is a tool for Redis data migration and data filtering. redis-shake 是一个用于 Redis 数据迁移与过滤的工具。
- golang-china/awesome-go-zh - :books: Go资源精选中文版(含中文图书大全)
- ehang-io/nps - 一款轻量级、高性能、功能强大的内网穿透代理服务器。支持tcp、udp、socks5、http等几乎所有流量转发,可用来访问内网网站、本地支付接口调试、ssh访问、远程桌面,内网dns解析、内网socks5代理等等……,并带有功能强大的web管理端。a lightweight, high-performance, powerful intranet penetration proxy server,
- opensec-cn/kunpeng - kunpeng是一个Golang编写的开源POC框架/库,以动态链接库的形式提供各种语言调用,通过此项目可快速开发漏洞检测类的系统。
- TruthHun/DocHub - 参考百度文库,使用Beego(Golang)开发的开源文库系统
- snail007/goproxy - 🔥 Proxy is a high performance HTTP(S) proxies, SOCKS5 proxies,WEBSOCKET, TCP, UDP proxy server implemented by golang. Now, it supports chain-style proxies,nat forwarding in different lan,TCP/UDP port
- cointop-sh/cointop - A fast and lightweight interactive terminal based UI application for tracking cryptocurrencies 🚀
- crabkun/switcher - 一个多功能的端口转发/端口复用工具,支持转发本地或远程地址的端口,支持正则表达式转发(实现端口复用)。
- huacnlee/flora-kit - 💐 基于 shadowsocks-go 做的完善实现,自动网络分流,完全兼容 Surge 的配置文件。
- 4ra1n/CVE-2023-21839 - Weblogic CVE-2023-21839 RCE (无需Java依赖一键RCE)
- teamssix/cf - Cloud Exploitation Framework 云环境利用框架,方便安全人员在获得 AK 的后续工作
- baidu-security/app-env-docker - 基于 Docker 的真实应用测试环境
- xntrik/hcltm - Documenting your Threat Models with HCL
- EgeBalci/amber - Reflective PE packer.
- tomnomnom/gron - Make JSON greppable!
- C-Sto/recursebuster - rapid content discovery tool for recursively querying webservers, handy in pentesting and web application assessments
- erbbysam/DNSGrep - Quickly Search Large DNS Datasets
- joanbono/Gurp - Burp Commander written in Go
- lakevilladom/goSkylar - 基于Golang开发的企业级外网端口资产扫描
- Virus-V/arpZebra - ARP+DNS欺骗工具,网络安全第三次实验,课堂演示用,严禁非法用途。ARPSpoof,wifi hijack,dns spoof
- sensepost/godoh - 🕳 godoh - A DNS-over-HTTPS C2
- TimothyYe/godns - A dynamic DNS client tool that supports AliDNS, Cloudflare, Google Domains, DNSPod, HE.net & DuckDNS & DreamHost, etc, written in Go.
- AmyangXYZ/DNSSniffer - DNSQuery Sniffer in Golang
- OpenBazaar/go-onion-transport - Tor onion transport for IPFS
- GameXG/ProxyClient - golang 代理库,和net一致的API。支持 socks4、socks4a、socks5、http、https 等代理协议。
- LubyRuffy/tcptunnel - 将本地内网服务器映射到公网。
- cw1997/NATBypass - 一款lcx.exe在golang下的实现, 可用于内网穿透, 建立TCP反弹隧道用以绕过防火墙入站限制等, This tool is used to establish reverse tunnel in NAT network environment, it can bypass firewall inbound restriction, support all functions of lcx
- ARwMq9b6/dnsproxy - 防 DNS 缓存污染,兼顾查询质量与速度
- InsZVA/tap0901 - Go语言虚拟网卡库,可用于制作对战平台、加速器、防火墙、VPN等
- Shopify/toxiproxy - :alarm_clock: :fire: A TCP proxy to simulate network and system conditions for chaos and resiliency testing
-
Shell
- tianon/gosu - Simple Go-based setuid+setgid+setgroups+exec
- cisagov/ansible-role-cobalt-strike - An Ansible role for installing Cobalt Strike.
- LuD1161/HackingSimplified - This is where I share code/material shown in my videos
- moranbw/https-dns-proxy-docker - Docker container for https-dns-proxy
- Anon-Exploiter/subdomainsEnumerator - A docker image which will enumerate, sort, unique and resolve the results of various subdomains enumeration tools.
- pwnpad/pwnpad - 🐳 VMs are bloat. Dockerise your VAPT environment
- gpakosz/.tmux - 🇫🇷 Oh my tmux! My self-contained, pretty & versatile tmux configuration made with ❤️
- eslam3kl/3klCon - Automation Recon tool which works with Large & Medium scopes. It performs a lot of tasks and gets back all the results in separated files.
- lxhao61/integrated-examples - 以 V2Ray(v4 版) 或 Xray、Nginx 或 Caddy(v2 版)、Hysteria 等打造常用科学上网的最优组合示例及优化配置,且提供集成特定插件的 Caddy(v2 版) 文件,分享给大家食用及自己备份。
- yeahwu/check - Streaming Media Unlock Test
- kuletco/iso-helper - Ubuntu-20.04 Custom Helper Script
- shouyinji1/MyTorProxy - Tor SOCKS5代理工具
- retkoussa/reFresh - A bash tool used to install famous bug bounty tools. Mainly used when setting up a fresh environment.
- regorsec/Linux-Post-Exploitation - Tips, Tricks, and Scripts for Linux Post Exploitation
- teamssix/container-escape-check - docker container escape check || Docker 容器逃逸检测
- spiritLHLS/Oracle-server-keep-alive-script - 服务器资源占用脚本(甲骨文服务器保活脚本)(Oracle Server Keep Alive Script)
- youngyangyang04/leetcode-master - 《代码随想录》LeetCode 刷题攻略:200道经典题目刷题顺序,共60w字的详细图解,视频难点剖析,50余张思维导图,支持C++,Java,Python,Go,JavaScript等多语言版本,从此算法学习不再迷茫!🔥🔥 来看看,你会发现相见恨晚!🚀
- yeahwu/v2ray-wss
- stilleshan/frps - 基于原版 frp 内网穿透服务端 frps 的一键安装卸载脚本和 docker 镜像.支持 Linux 服务器和 docker 等多种环境安装部署.
- 9bie/sshdHooker - One-click injection into the SSHD process to record and send the password for ssh login
- OrangeHacking-CyberSecurity/kali-build-config - 构建基于gnome桌面模式的kali Linux
- rix4uni/SubDog - subdog is a subdomain enumeration tools, this tool collect number of different sources to create a list of root subdomains
- tom-snow/wechat-windows-versions - 保存微信历史版本
- whitehatsoumya/Nutoscan - An Automated Mass Network Vulnerability Scanner and Recon Tool
- cxf-boluo/magisk_All - magisk 一键集成环境,再也不用每次刷完机繁琐的配置环境了!
- 1N3/BruteX - Automatically brute force all services running on a target.
- haiwen/seafile-server-installer-cn - One script to install seafile server
- neargle/my-re0-k8s-security - :atom: [WIP] 整理过去的分享,从零开始的Kubernetes攻防 🧐
- z-shell/zi - ✨ A Swiss Army Knife for Zsh - Unix Shell
- makdosx/mip22 - :computer: :iphone: mip22 is a advanced phishing tool
- githubfoam/nmap-githubactions - nmap nse lua vulnerability scanner githubactions
- LeKlex/Attack-simulation-infrastructure - A small and simple network infrastructure with automated attacks on a VM server documented by tshark
- arget13/DDexec - A technique to run binaries filelessly and stealthily on Linux by "overwriting" the shell's process with another.
- lefayjey/linWinPwn - linWinPwn is a bash script that streamlines the use of a number of Active Directory tools
- snowyyowl/writeups
- JoyGhoshs/0install - A bash script that will automatically install Bug Hunting tools used for recon
- JoyGhoshs/BalerRecon - Baler Recon Script
- JoyGhoshs/Airattackit - Automated Wireless Attack Framework
- oxff644/Waf_auto_pretest - WAF自动化质量测试工具
- ViRb3/magisk-frida - 🔐 Run frida-server on boot with Magisk, always up-to-date
- basharkey/CVE-2022-0847-dirty-pipe-checker - Bash script to check for CVE-2022-0847 "Dirty Pipe"
- BytecodeDL/ByteCodeDL - A declarative static analysis tool for jvm bytecode based Datalog like CodeQL
- G4rb3n/Malbox - 恶意软件容器靶机
- philcryer/prickly-pete - A script using Docker to quickly bring up some honeypots exposing lots of services. For research, reconnaissance, and fun. (DISCLAIMER may not be fun, not to be taken internally, aim away from face)
- veerendra2/elasticsearch-deploy-notes - Elasticsearch deploy notes
- nightwatchcybersecurity/gitbleed_tools
- ffffffff0x/403-fuzz - 针对 403 页面的 fuzz 脚本
- wslutilities/wslu - A collection of utilities for Windows Subsystem for Linux
- v4d1/SpoofThatMail - Bash script to check if a domain or list of domains can be spoofed based in DMARC records
- 0xJin/awesome-bugbounty-builder - Awesome Bug bounty builder Project
- nyxnor/onionjuggler - Manage your Onion Services via CLI or TUI on Unix-like operating system with a POSIX compliant shell.
- MvsCode/frps-onekey - Frps 一键安装脚本&管理脚本 A tool to auto-compile & install frps on Linux
- adilsoybali/Log4j-RCE-Scanner - Remote command execution vulnerability scanner for Log4j.
- tangjie1/-Baseline-check - windows和linux基线检查,配套自动化检查脚本。纯手打。
- graphql/graphql-spec - GraphQL is a query language and execution engine tied to any backend service.
- juaromu/wazuh-log4j
- ssstonebraker/log4j-scan-turbo - Multithreaded log4j vulnerability scanner using only bash! Tests all JNDI protocols, HTTP GET/POST, and 84 headers.
- redcode-labs/AirStrike - Automatically grab and crack WPA-2 handshakes with distributed client-server architecture
- AlphabugX/csOnvps - CobaltStrike4.4 一键部署脚本 随机生成密码、key、端口号、证书等,解决cs4.x无法运行在Linux上报错问题 灰常银杏化设计
- santosomar/log4j-ioc-detector - A Simple Log4j Indicator of Compromise Linux Detector
- hackinghippo/log4shell_ioc_ips - log4j / log4shell IoCs from multiple sources put together in one big file (IPs) more coming soon (CVE-2021-44228)
- cisagov/log4j-affected-db - A community sourced list of log4j-affected software
- zhangyoufu/log4j2-without-jndi - log4j2-core JAR w/o JndiLookup.class
- sindresorhus/pure - Pretty, minimal and fast ZSH prompt
- Jonnyan404/zerotier-planet - 一分钟自建zerotier-planet
- bodsch/docker-jolokia - Docker Container with tomcat-9, jre and jolokia
- WeiyiGeek/SecOpsDev - 项目介绍: 自己闲来无事所写以及工作中抽取的安全/运维/开发方面的代码小脚本 ,希望大家多多star支持。
- DamonMohammadbagher/NativePayload_Image - Transferring Backdoor Payloads with BMP Image Pixels
- evanRubinsteinIT/BugBounty-Oneliners - A compilation of quick bash scripts I wrote to make life easier while bug bounty hunting
- mrtc0/kubectf - Kubernetes CTF
- mack-a/v2ray-agent - Xray、Tuic、hysteria2、sing-box 八合一一键脚本
- V1n1v131r4/webdiscover - The purpose of this script is to automate the web enumeration process and search for exploits
- Dheerajmadhukar/4-ZERO-3 - 403/401 Bypass Methods + Bash Automation + Your Support ;)
- HightechSec/scarce-apache2 - A framework for bug hunting or pentesting targeting websites that have CVE-2021-41773 Vulnerability in public
- TheLastVvV/CVE-2021-42013_Reverse-Shell - PoC CVE-2021-42013 reverse shell Apache 2.4.50 with CGI
- WithSecureLabs/LinuxCatScale - Incident Response collection and processing scripts with automated reporting scripts
- WSA-Community/WSAGAScript - Scripts to install Google Apps into a WSA image. Plus optional root
- profuzzbench/profuzzbench - ProFuzzBench - A Benchmark for Stateful Protocol Fuzzing
- darklotuskdb/SSTI-XSS-Finder - XSS Finder Via SSTI
- souravbaghz/Carpunk - The CAN Injection Toolkit
- DK9510/automate-with-actions
- dn0m1n8tor/project-morya - Project Morya is just a collection of bash scripts that runs iteratively to carry out various tools and recon process & store output in an organized way
- itboxltda/pentestlab - Script to manage and create local pentesting training virtual lab
- pdelteil/BugBountyHuntingScripts - I built some bash functions to help me while doing mundane and repetitive tasks using BBRF, Nuclei or other Bug bounty tool.
- honoki/bbrf-server - The Bug Bounty Reconnaissance Framework (BBRF) can help you coordinate your reconnaissance workflows across multiple devices
- YouGina/reconmaster - ReconMaster contest - scripts used and a write-up
- KingOfBugbounty/DockerHunt
- WoeUSB/WoeUSB - A Microsoft Windows® USB installation media preparer for GNU+Linux
- egrullon/Wounty - Wounty is a simple web enumeration script that makes use of other popular tools to automate the early stages of recognition in Bug Bounty processes. This tool is very important as part of the Bug Boun
- machine1337/reverse-shells - This tool will help in generating reverse shells easily for all types of OS.
- iamthefrogy/frogy - My subdomain enumeration script. It's unique in the way it is built upon.
- Markdown-Bug-Bounty-Recon/Markdown-Bug-Bounty-Recon - A recon Framework for Bug Bounty Hunters that would convert the output of a script into Markdown syntax document, which would help them to make better notes, have everything in one document, or concen
- R0X4R/scvault - Custom scripts for directory fuzzing, subdomain enumeration, and more.
- A3h1nt/gimmeSH - For pentesters who don't wanna leave their terminals.
- clu3bot/owt - Update Version 3.1 added free SMS messaging.
- trimstray/massh-enum - OpenSSH 2.3 up to 7.4 Mass Username Enumeration (CVE-2018-15473).
- xiaoyunjie/Shell_Script - Linux系统的安全,通过脚本对Linux系统进行一键检测和一键加固
- Dheerajmadhukar/karma_v2 - ⡷⠂𝚔𝚊𝚛𝚖𝚊 𝚟𝟸⠐⢾ is a Passive Open Source Intelligence (OSINT) Automated Reconnaissance (framework)
- shifa123/nuclei-templates-all - Bash Script to download all Nuclei Templates from different awesome sources
- dung-bycn/bycn-mobsf-scan
- D1rk9ghT/Recon - Bug Bounty Recon Tools
- slsa-framework/slsa - Supply-chain Levels for Software Artifacts
- k8sli/kubeplay - Deploy kubernetes by kubespray in offline
- B3nac/deeplink-fuzz.sh - A Bash wrapper for radamsa that can be used to fuzz exported activities and deep links.
- shk0x/PRTG-Network-Monitor-RCE - Remote code execution prtg network monitor cve2018-9276
- jay-johnson/owasp-jenkins - Want to test your applications using the latest OWASP security toolchains and the NIST National Vulnerability Database using Jenkins, Ansible and docker? :whale: :shield: :lock:
- BiasedRiot/Glanadh - Service to automatically remove Metadata from your files.
- alcideio/kaudit - Alcide Kubernetes Audit Log Analyzer - Alcide kAudit
- Mixeway/MixewayHub - Mixeway is security orchestrator for vulnerability scanners which enable easy plug in integration with CICD pipelines. MixewayHub project contain one click docker-compose file which configure and run
- thomasleplus/jwt-utils - A few utilities to work with JWTs.
- iamthefrogy/nerdbug - Full Nuclei automation script with logic explanation.
- wirefalls/geo-nft - Bash script to create nftables sets of country specific IP address ranges for use with firewall rulesets. The project provides a simple and flexible way to implement geolocation filtering with nftable
- konstruktoid/hardening - Hardening Ubuntu. Systemd edition.
- SDA-SE/cluster-image-scanner - Discover vulnerabilities and container image misconfiguration in production environments.
- H21lab/tsharkVM - tshark + ELK analytics virtual machine
- mviereck/x11docker - Run GUI applications and desktops in docker and podman containers. Focus on security.
- threeworld/Security-baseline - 安全基线
- oldboy21/LDAP-Password-Hunter - Password Hunter in Active Directory
- supr4s/WebHackingTools - Automatically install some web hacking/bug bounty tools.
- MacMiniVault/Mac-Scripts - Automation scripts focused around Mac OS X Server
- wazuh/wazuh-docker - Wazuh - Docker containers
- arismelachroinos/lscript - The LAZY script will make your life easier, and of course faster.
- sushant-kamble/kalioncloud - This is a shell script to install kali on cloud VPS server with a GUI.
- m3n0sd0n4ld/uDork - uDork is a script written in Bash Scripting that uses advanced Google search techniques to obtain sensitive information in files or directories, find IoT devices, detect versions of web applications,
- justmeandopensource/vagrant - Vagrant and corresponding Vagrantfiles
- takito1812/FireStorePwn - fsp - Firestore Database Vulnerability Scanner Using APKs
- A3h1nt/Dnsrr - DNSrr is a tool written in bash, used to enumerate all the juicy stuff from DNS.
- owerdogan/whoami-project - Whoami provides enhanced privacy, anonymity for Debian and Arch based linux distributions
- Cyber-Guy1/Subdomainer - Automated tool for domains & subdomains gathering
- cloudsec/brootkit - Lightweight rootkit implemented by bash shell scripts v0.10
- Dheerajmadhukar/karma_v1 - KARMA is a simple bash script automation that can hit Shodan Premium API and find active IPs, ASN, Common Vulnerabilities, CVEs & Open Ports.
- mvallim/live-custom-ubuntu-from-scratch - (Yes, the project is still alive 😃) This procedure shows how to create a bootable and installable Ubuntu Live (along with the automatic hardware detection and configuration) from scratch.
- swapravo/polkadots - CVE-2021-3560 Local PrivEsc Exploit
- R0X4R/Pinaak - A vulnerability fuzzing tool written in bash, it contains the most commonly used tools to perform vulnerability scan
- emadshanab/Gf-Patterns-Collection
- nankeen/pwndocker - Docker tools for CTF pwning 👩🏻💻👨🏻💻🚩
- ManasHarsh/Cobra - All in one tool to make your hacking easier.
- nikhil1232/Bucket-Flaws - Bucket Flaws ( S3 Bucket Mass Scanner ): A Simple Lightweight Script to Check for Common S3 Bucket Misconfigurations
- mrrobot1o1/asnips
- mdrights/LiveSlak - 中文化的隐私加强 GNU/Linux 系统 - Forked from Alien Bob's powerful building script for Slackware Live.
- pocdork/gitdomain - Discover endpoints using companies GitHub Repositories name
- mcnamee/huntkit - Docker - Ubuntu with a bunch of PenTesting tools and wordlists
- dreamer1eh/ultimate_bughunter_tools - Ultimate Package Of 50 Bug Bounty Hunting Tools
- matrix-ops/kbi - Kubernetes Binarization Installer
- Thrimbda/shell-set-up - my personal shell set up script-我的超好看的oh-my-zsh配置
- sansatart/scrapts - Scrapts Scrapts Scrapts
- shakalaca/MagiskOnEmulator - Install Magisk on Official Android Emulator
- Dheerajmadhukar/Lilly - Tool to find the real IP behind CDNs/WAFs like cloudflare using passive recon by retrieving the favicon hash. For the same hash value, all the possible IPs, PORTs and SSL/TLS Certs are searched to val
- NVISOsecurity/MagiskTrustUserCerts - A Magisk/KernelSU module that automatically adds user certificates to the system root CA store
- Aju100/VulWebaju - VulWebaju is a platform that automates setting up your pen-testing environment for learning purposes.
- phith0n/projector-runner - Run Swing based GUI application within the Docker container through the Jetbrains Projector, and access it from browsers.
- Dheerajmadhukar/back-me-up - This tool will check for Sensitive Data Leakage with some useful patterns/RegEx. The patterns are mostly targeted on waybackdata and filter everything accordingly.
- s0md3v/shades
- philips-labs/blackduck-scanner-action - BlackDuck GItHub Action
- zephrax/linux-pam-backdoor - Linux PAM Backdoor
- ArpitKubadia/JS-Secret-Finder
- 21y4d/nmapAutomator - A script that you can run in the background!
- openservicebrokerapi/servicebroker - Open Service Broker API Specification
- dalbonip/theGreatRecon
- iamthefrogy/bucketbunny - AWS S3 open bucket poc automated script.
- TheCrysp/Hackbuntu
- nitefood/asn - ASN / RPKI validity / BGP stats / IPv4v6 / Prefix / URL / ASPath / Organization / IP reputation / IP geolocation / IP fingerprinting / Network recon / lookup API server / Web traceroute server
- jotyGill/ezsh - quickly install zsh, oh-my-zsh with power-level-9k zsh-completions zsh-autosuggestions zsh-syntax-highlighting history-substring-search
- jorgebucaran/fisher - A plugin manager for Fish
- obheda12/MoneyScope - A Simple Tool to Pull Paid Bounty Scopes for Wide Recon Actvities
- ffffffff0x/f8x - 红/蓝队环境自动化部署工具 | Red/Blue team environment automation deployment tool
- shubhampathak/autosetup - Auto setup is a bash script compatible with Debian based distributions to install and setup necessary programs.
- 1N3/AttackSurfaceManagement - Discover the attack surface and prioritize risks with our continuous Attack Surface Management (ASM) platform - Sn1per Professional #pentest #redteam #bugbounty
- febinrev/quester - QUESTER is a Web Pentesting & Bug Bounty Recon tool which queries URLs / Subdomains from the given list of URLs or subdomains.
- effortlessdevsec/ApkRecon - Scanning APK file for URIs, endpoints & secrets.
- jinwyp/one_click_script - install latest or LTS linux kernel and enable BBR or BBR plus
- jiuqi9997/Xray-yes - Xray安装脚本 / Xray install script (VLESS TCP XTLS)
- woniuzfb/iptv - HAProxy / Docker / Traefik / Rclone / Calibre Web / Alist / FFmpeg / Nginx / Openresty / V2ray / Xray / Armbian / Proxmox VE / .. All In One Script
- vsec7/Command-Collections - Simple command shell collections
- taherio/redi - Automated script for setting up CobaltStrike redirectors (nginx reverse proxy, letsencrypt)
- vp777/surferFTP - SSRF to TCP Port Scanning, Banner and Private IP Disclosure by abusing the FTP protocol/clients
- kafroc/emergency-response-toolbox
- daffainfo/bash-bounty - Random Tools for Bug Bounty
- 2-alchemists/krossboard - 📊 Krossboard is a Multi-cluster, Cross-Cloud & Cross-Distribution Kubernetes Usage Accounting & Analytics. Actively tested against Amazon EKS, Microsoft AKS, Google GKE, Red Hat OpenShift, & vanilla d
- gibrown/bash-my-day - Bash scripts for my day
- cdpxe/nefias - Network Forensic & Anomaly Detection System; tailored for covert channel/network steganography detection
- k1LoW/wazuh-agent-debug - Wazuh agent binary for "Agent event queue is flooded" debug
- souravbaghz/RadareEye - Tool for especially scanning nearby devices and execute a given command on its own system while the target device comes in range.
- burhanxd/SimpleRecon - Simple Recon is just a simple bash script to automate my recon process.
- ArchStrike/ArchStrike - An Arch Linux repository for security professionals and enthusiasts. Done the Arch Way and optimized for i686, x86_64, ARMv6, ARMv7 and ARMv8.
- ev1lm0rty/Dump_Programs - Dump bug bounty scopes from bug crowd, hackerone etc.
- e-m-b-a/emba - EMBA - The firmware security analyzer
- dwisiswant0/continuous-nuclei - Running nuclei Continuously
- six2dez/reconftw - reconFTW is a tool designed to perform automated recon on a target domain by running the best set of tools to perform scanning and finding out vulnerabilities
- vincentcox/bypass-firewalls-by-DNS-history - Firewall bypass script based on DNS history records. This script will search for DNS A history records and check if the server replies for that domain. Handy for bugbounty hunters.
- stealthcopter/deepce - Docker Enumeration, Escalation of Privileges and Container Escapes (DEEPCE)
- MichaIng/DietPi - Lightweight justice for your single-board computer!
- darklotuskdb/CISCO-CVE-2020-3452-Scanner-Exploiter - CISCO CVE-2020-3452 Scanner & Exploiter
- sumerzhang/PhishingInstall - 发信平台自动化部署
- 3CORESec/PTRB - PTR Bouncer - Keeping legitimate Internet security scanners off of poor reputation IP lists
- Dheerajmadhukar/subzzZ - SubzzZ to find possible subdomains using passive recon. Tool also support Permutations, Mutations, Alterations.
- zeroc00I/AllVideoPocsFromHackerOne - This script grab public report from hacker one and make some folders with poc videos
- thewqer/recontooler
- Fadavvi/Sub-Drill - A very (very) FAST and simple subdomain finder based on online & free services. Without any configuration requirements.
- meltest/simple_shodan_recon
- giovanifss/Gitmails-sh - An information gathering tool to collect git emails in version control host services
- Nyr/wireguard-install - WireGuard road warrior installer for Ubuntu, Debian, AlmaLinux, Rocky Linux, CentOS and Fedora
- cve-search/CVE-Search-Docker - Docker Image for CVE-Search
- chromedp/docker-headless-shell - Minimal container for Chrome's headless shell, useful for automating / driving the web
- InGeek-IoV-Security-Research-RedTeam/IoV-Security-Wiki - Research sharing on offense and defense of IoV.
- starnightcyber/Miscellaneous - 百宝箱
- maaaaz/thc-hydra-windows - The great THC-HYDRA tool compiled for Windows
- iamj0ker/bypass-403 - A simple script just made for self use for bypassing 403
- th3hack3rwiz/Lazy-FuzzZ - Sometimes we want to fuzz a set of sub-domain URLs with a common wordlist. Fuzzing them one by one is a tedious task, not to mention the false positives we obtain in those results. To solve this probl
- tinyclub/open-c-book - 开源书籍:《C语言编程透视》,配套视频课程《360° 剖析 Linux ELF》已上线,视频讲解更为系统和深入,欢迎订阅:https://www.cctalk.com/m/group/88089283
- elreydetoda/packer-kali_linux - This is a repository that will be used to help create a process of a new kali vagrant box for hashicorp each week.
- theinfosecguy/QuickXSS - Automating XSS using Bash
- samhaxr/recox - Master script for web reconnaissance
- xiaoZ-hc/redtool - 日常积累的一些红队工具及自己写的脚本,更偏向于一些diy的好用的工具,并不是一些比较常用的msf/awvs/xray这种
- 0x25/useful - useful pentest note
- 1N3/MassBleed - MassBleed SSL Vulnerability Scanner
- Raywando/4xxbypass - 4xxbypass
- six2dez/OneListForAll - Rockyou for web fuzzing
- venom26/recon - information gathering
- pprietosanchez/CVE-2020-14750 - PoC para las vulnerabilidades CVE-2020-14750 y cve-2020-14882
- koutto/pi-pwnbox-rogueap - Homemade Pwnbox :rocket: / Rogue AP :satellite: based on Raspberry Pi — WiFi Hacking Cheatsheets + MindMap :bulb:
- KathanP19/JSFScan.sh - Automation for javascript recon in bug bounty.
- Ysurac/openmptcprouter-vps - OpenMPTCProuter VPS scripts
- vp777/procrustes - A bash script that automates the exfiltration of data over dns in case we have blind command execution on a server with egress filtering
- mvberg/ib-gateway-docker - Interactive Brokers Trading Gateway running in Docker
- aforensics/HiddenVM - HiddenVM — Use any desktop OS without leaving a trace.
- securfreakazoid/autoPhisher - Script to setup a phishing server on the cloud
- iamj0ker/Find-domains - This repo contain scripts written for finding subdomains using various available tools
- sickcodes/Docker-eyeOS - Run iPhone (xnu-arm64) in a Docker container! Supports KVM + iOS kernel debugging (GDB)! Run xnu-qemu-arm64 in Docker! Works on ANY device.
- mansoorr123/wp-file-manager-CVE-2020-25213 - https://medium.com/@mansoorr/exploiting-cve-2020-25213-wp-file-manager-wordpress-plugin-6-9-3f79241f0cd8
- SixArm/gitconfig-settings - gitconfig setttings, files, aliases, colors, branches, etc.
- wireghoul/htshells - Self contained htaccess shells and attacks
- QAX-A-Team/WeblogicEnvironment - Weblogic环境搭建工具
- IoT-PTv/List-of-Tools - List of the tools and usage
- tothi/ad-honeypot-autodeploy - Deploy a small, intentionally insecure, vulnerable Windows Domain for RDP Honeypot fully automatically.
- sup3r-b0y/mobi
- cheshireca7/smbAutoRelay - SMB Auto Relay provides the automation of SMB/NTLM Relay technique for pentesting and red teaming exercises in active directory environments.
- jaykali/maskphish - Introducing "URL Making Technology" to the world for the very FIRST TIME. Give a Mask to Phishing URL like a PRO.. A MUST have tool for Phishing.
- R0X4R/Garud - An automation tool that scans sub-domains, sub-domain takeover, then filters out XSS, SSTI, SSRF, and more injection point parameters and scans for some low hanging vulnerabilities automatically.
- robotshell/magicRecon - MagicRecon is a powerful shell script to maximize the recon and data collection process of an objective and finding common vulnerabilities, all this saving the results obtained in an organized way in
- osamahamad/CVE-2020-9484-Mass-Scan - CVE-2020-9484 Mass Scanner, Scan a list of urls for Apache Tomcat deserialization (CVE-2020-9484) which could lead to RCE
- chroblert/SecurityBaselineCheck
- ashishb/android-malware - Collection of android malware samples
- fundacaocerti/mobsf-action - GitHub Actions for MobSF
- Iamstanlee/bee - Bee Recon Framework
- tabbysable/POC-2020-8559 - Proof of Concept exploit for Kubernetes CVE-2020-8559
- Johnler/Wi-Ploit - Wi-Fi Exploit Tool
- m4xx101/subash
- redcode-labs/Citadel - Collection of pentesting scripts
- chvancooten/BugBountyScanner - A Bash script and Docker image for Bug Bounty reconnaissance. Intended for headless use.
- m4xx101/cacert-installer
- MS-WEB-BN/h4rpy - Automated WPA/WPA2 PSK attack tool.
- urakesh661/port-checker - Script for checking connection to ports using nc.
- fieu/discord.sh - Write-only command-line Discord webhooks integration written in 100% Bash script
- YashGoti/dac - Fetch ASN [Number] / CIDR [IP Range] from Domain, Fetch CIDR [IP Range] from ASN [Number] using https://ipinfo.io/ API
- l4yton/RegHex - A collection of regexes for every possbile use
- dwisiswant0/bounty-targets-alert - It's an watcher for new scopes added to bounty-targets-data and send you alert to Slack.
- dwisiswant0/gf-secrets - Secret and/or credential patterns used for gf.
- dirtyfilthy/siem-from-scratch - SIEM-From-Scratch is a drop-in ELK based SIEM component for your Vagrant infosec lab
- harsh-bothra/Bheem
- h0rv4th/c2matrix-analyzer - Basic c2-matrix analysis enviroment using Suricata + Wazuh + Elastic stack
- NullArray/SBD - Static Binary Deployer. Download and deploy *Nix utilities on a compromised system.
- TomAPU/poc_and_exp - 搜集的或者自己写的poc或者exp
- urbanadventurer/Android-PIN-Bruteforce - Unlock an Android phone (or device) by bruteforcing the lockscreen PIN. Turn your Kali Nethunter phone into a bruteforce PIN cracker for Android devices! (no root, no adb)
- triat/terraform-security-scan - Run a security scan on your terraform with the very nice https://github.com/aquasecurity/tfsec
- z0ph/aws-security-toolbox - AWS Security Tools (AST) in a simple Docker container. :package:
- KathanP19/bash_script_templates - Some Templates for Bash Scripting
- openbridge/ob_hacky_slack - Hacky Slack - a bash script that sends beautiful messages to Slack
- wunderwuzzi23/BashSpray - Password Spray Testing Tool in Bash
- PassZhang/ansible-install-k8s - 自动化部署kubernetes(支持版本1.18,1.17,1.16)
- wangao1236/k8s_single_deploy - 单节点部署 k8s 集群的相关脚本和文件,Master 和 Node 位于同一机器
- stoensin/K8s - k8s集群一键化,Kubernetesv1.13.2集群"真一键"离线安装,图形化菜单向导实测单机版支持腾讯云服务器
- sandflysecurity/sandfly-setup - Sandfly Security Agentless Compromise and Intrusion Detection System For Linux
- devploit/put2win - Script to automate PUT HTTP method exploitation to get shell
- MS-WEB-BN/t14m4t - Automated brute-forcing attack tool.
- abdulr7mann/hackerEnv
- ASHWIN990/ADB-Toolkit - ADB-Toolkit V2 for easy ADB tricks with many perks in all one. ENJOY!
- nagarajcruze/cruze-the-web - a simple script to do basic to advanced recon.... in simple words -> a script to automate all the lazy recon flow of the hunter with the tools great people have developed.
- rotemreiss/subvenom - Enumerate subdomains using multiple tools for bigger scope enumeration.
- Anof-cyber/pentest-recon - Web application pentesting recon