Skip to content
View heh3's full-sized avatar

Block or report heh3

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse

Starred repositories

Showing results

Dictionary of attack patterns and primitives for black-box application fault injection and resource discovery.

PHP 8,756 2,127 Updated Nov 10, 2023

OneForAll是一款功能强大的子域收集工具

Python 9,488 1,412 Updated Sep 12, 2025

linux入侵排查脚本_整合版

Shell 5 1 Updated Oct 27, 2020

用于检测maven项目的第三方依赖组件是否存在安全漏洞。

Java 103 21 Updated Apr 12, 2022

FASTJSON 2.0.x has been released, faster and more secure, recommend you upgrade.

Java 25,736 6,467 Updated Jul 16, 2024

一款监控端口变化的系统——beholder_scanner端

Python 82 23 Updated Jul 10, 2024

An enterprise friendly way of detecting and preventing secrets in code.

Python 4,345 536 Updated Mar 13, 2025

资产端口实时监控系统,支持1-65525端口 7*24小时实时监控 ,支持异常发送邮件,邮箱hacker9090@126.com,作者:秋某人的傻逼[熊猫爱皮卡丘]

Python 6 2 Updated May 27, 2019

一个微小的服务端端口监控程序,带web界面,支持通过web重启服务器程序(需自定义配置)

Python 3 Updated Apr 18, 2018

对公网IP列表进行端口服务扫描,发现周期内的端口服务变化情况和弱口令安全风险

Python 609 181 Updated Apr 12, 2021

Proxy_Pool(代理资源池),一个小巧的代理ip抓取+评估+存储+展示的一体化的工具,包括了web展示和接口。

JavaScript 331 123 Updated Jun 22, 2020

A Workflow Engine for Offensive Security

Go 6,001 951 Updated Aug 8, 2025

Tentacle is a POC vulnerability verification and exploit framework. It supports free extension of exploits and uses POC scripts. It supports calls to zoomeye, fofa, shodan and other APIs to perform…

Python 376 112 Updated Mar 6, 2024

✍️ A curated list of CVE PoCs.

3,465 726 Updated Jan 4, 2022

A Burp Suite Extension that try to find all sub-domain, similar-domain and related-domain of an organization automatically! 基于流量自动收集整个企业或组织的子域名、相似域名、相关域名的burp插件

Java 675 130 Updated Jul 16, 2023

Tool for checking Whether a domain or its multiple sub-domains are up and running.

Python 72 22 Updated Jan 21, 2019

洞察-宜信集应用系统资产管理、漏洞全生命周期管理、安全知识库管理三位一体的平台。

JavaScript 1,183 445 Updated Jan 12, 2021

A .DS_Store file disclosure exploit. It parses .DS_Store file and downloads files recursively.

Python 1,701 296 Updated May 6, 2023

Six Degrees of Domain Admin

PowerShell 10,469 1,791 Updated Aug 1, 2025

CVE 2017-9805

Go 60 26 Updated Aug 31, 2020
1 Updated Sep 8, 2017
Python 714 180 Updated Jan 4, 2020

快速搭建各种漏洞环境(Various vulnerability environment)

Shell 3,778 992 Updated Oct 27, 2020

Execute DLL via the Excel.Application object's RegisterXLL() method

JavaScript 22 16 Updated Apr 17, 2021

A python3 program to filter Burp Suite log file.

Python 77 29 Updated May 26, 2016

Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework capable of performing static a…

JavaScript 20,030 3,544 Updated Dec 16, 2025

AndroidHttpCapture网络诊断工具 是一款Android手机抓包软件 主要功能包括:手机端抓包、PING/DNS/TraceRoute诊断、抓包HAR数据上传分享。你也可以看成是Android版的"Fiddler" \(^o^)/~

Java 4,627 863 Updated Jul 31, 2025

JumpServer is an open-source Privileged Access Management (PAM) platform that provides DevOps and IT teams with on-demand and secure access to SSH, RDP, Kubernetes, Database and RemoteApp endpoints…

Python 29,255 5,616 Updated Dec 22, 2025

A little tool to play with Windows security

C 21,124 4,012 Updated May 11, 2025

Windows Exploits

PowerShell 1,286 534 Updated May 29, 2020