Skip to content
View h3ak's full-sized avatar

Block or report h3ak

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse

Starred repositories

Showing results

A high-speed tool for passively gathering URLs, optimized for efficient and comprehensive web asset discovery without active scanning.

Go 818 65 Updated Dec 15, 2025

一款快速、全面、易用的页面信息提取工具,可快速发现和提取页面中的JS、URL和敏感信息。

Go 3,068 227 Updated Jan 5, 2024

Vue框架未授权接口扫描工具

70 4 Updated May 28, 2025

oss存储桶遍历漏洞利用脚本

Python 90 5 Updated Nov 23, 2024

网络安全 · 攻防对抗 · 蓝队清单,中文版

HTML 922 124 Updated Dec 3, 2023

reconFTW is a tool designed to perform automated recon on a target domain by running the best set of tools to perform scanning and finding out vulnerabilities

Shell 6,993 1,101 Updated Dec 11, 2025

Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the …

Go 26,141 3,015 Updated Dec 20, 2025

云资产管理工具 目前工具定位是云安全相关工具,目前是两个模块 云存储工具、云服务工具, 云存储工具主要是针对oss存储、查看、删除、上传、下载、预览等等 云服务工具主要是针对rds、服务器的管理,查看、执行命令、接管等等

1,114 77 Updated Nov 28, 2024

Windows应急响应工具---Hawkeye(鹰眼)。集Windows日志分析,进程扫描,主机信息于一体的综合应急响应分析工具

628 28 Updated Jul 13, 2025

Linux应急处置/信息搜集/漏洞检测工具,支持基础配置/网络流量/任务计划/环境变量/用户信息/Services/bash/恶意文件/内核Rootkit/SSH/Webshell/挖矿文件/挖矿进程/供应链/服务器风险等13类70+项检查

Shell 2,020 419 Updated Jun 19, 2024

Find vulnerabilities, misconfigurations, secrets, SBOM in containers, Kubernetes, code repositories, clouds and more

Go 30,554 2,847 Updated Dec 19, 2025

Find, verify, and analyze leaked credentials

Go 23,849 2,163 Updated Dec 20, 2025

Cloud Native Runtime Security

C++ 8,505 972 Updated Dec 19, 2025

一款内网综合扫描工具,方便一键自动化、全方位漏扫扫描。

Go 13,132 1,832 Updated Dec 20, 2025

deadpool代理池工具,可从hunter、quake、fofa等网络空间测绘平台取高质量socks5代理,或本地导入socks5代理,轮询使用代理进行流量转发。

Go 651 81 Updated Apr 21, 2025

备份的漏洞库,3月开始我们来维护

1,721 472 Updated Dec 11, 2025

ScopeSentry-Cyberspace mapping, subdomain enumeration, port scanning, sensitive information discovery, vulnerability scanning, distributed nodes

Go 1,415 195 Updated Dec 18, 2025

dirsx 是一款能够自动化过滤扫描结果的目录扫描工具

349 16 Updated Nov 18, 2025

best tool for finding SQLi,CRLF,XSS,LFi,OpenRedirect

Python 1,464 327 Updated Dec 7, 2025

NSudo - A Powerful System Administration Tool

C++ 20 23 Updated Feb 6, 2015

KCon is a famous Hacker Con powered by Knownsec Team.

JavaScript 4,658 1,404 Updated Aug 28, 2024

一款用于安全测试中信息收集的自动化工具

Go 144 10 Updated Aug 6, 2024

面向红队的, 高性能高度自由可拓展的自动化扫描引擎 | A highly controllable and extensionable automated scanning engine for red teams

Go 1,971 182 Updated Dec 16, 2025

Wscan is a web security scanner that focuses on web security, dedicated to making web security accessible to everyone.

Go 687 83 Updated Jul 19, 2025

一款支持自定义的 Java 内存马生成工具|A customizable Java in-memory webshell generation tool.

Java 2,125 233 Updated Aug 21, 2025

Gather and update all available and newest CVEs with their PoC.

HTML 7,450 947 Updated Dec 20, 2025

Burp插件,根据自定义来达到对数据包的处理(适用于加解密、爆破等),类似mitmproxy,不同点在于经过了burp中转,在自动加解密的基础上,不影响APP、网站加解密正常逻辑等。

Java 1,281 94 Updated Dec 14, 2025

远程调用(rpc)浏览器方法,免去抠代码补环境

Go 2,069 429 Updated Nov 22, 2025

Community curated list of templates for the nuclei engine to find security vulnerabilities.

JavaScript 11,695 3,235 Updated Dec 20, 2025