Skip to content
View rabbitsafe's full-sized avatar

Block or report rabbitsafe

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
86 stars written in Python
Clear filter

大宝剑-边界资产梳理工具(红队、蓝队、企业组织架构、子域名、Web资产梳理、Web指纹识别、ICON_Hash资产匹配)

Python 918 144 Updated Feb 8, 2022

Threat Intelligence Gathering 威胁情报收集,旨在提高蓝队拿到攻击 IP 后对其进行威胁情报信息收集的效率。

Python 849 139 Updated Aug 10, 2023

目录扫描+JS文件中提取URL和子域+403状态绕过+指纹识别

Python 824 65 Updated Sep 30, 2025

集Fofa、Hunter鹰图、Shodan、360 quake、Zoomeye 钟馗之眼、censys 为一体的空间测绘gui图形界面化工具,支持一键采集爬取和导出fofa、shodan等数据,方便快捷查看

Python 776 77 Updated Feb 6, 2025

Issues has been disabled for these PoC's, as they are simply PoC, Public Domain and unsupported.

Python 760 308 Updated Jan 12, 2023

A fully automated, reliable, and accurate scanner for finding Spring4Shell and Spring Cloud RCE vulnerabilities

Python 659 113 Updated Apr 7, 2022

There is no pre-auth RCE in Jenkins since May 2017, but this is the one!

Python 605 132 Updated May 17, 2019

灯塔(最新版)指纹添加脚本!

Python 585 78 Updated Aug 12, 2021

轻量级知识库&POC管理平台

Python 579 214 Updated May 27, 2022

Apache Shiro 反序列化漏洞检测与利用工具

Python 565 123 Updated Jan 29, 2020

ICP备案查询,可查询企业或域名的ICP备案信息,自动完成滑动验证,保存结果到Excel表格,适用于新版的工信部备案管理系统网站,告别频繁拖动验证,以及某站*工具要开通VIP才可查看备案信息的坑

Python 561 92 Updated Nov 23, 2023

前端参数加密渗透测试通用解决方案

Python 561 76 Updated Oct 17, 2022

FrameScan-GUI 一款python3和Pyqt编写的具有图形化界面的cms漏洞检测框架。

Python 543 95 Updated Oct 9, 2024

A blind XXE injection callback handler. Uses HTTP and FTP to extract information. Originally written in Ruby by ONsec-Lab.

Python 518 89 Updated Jul 29, 2020

Cobalt Strike script for ScareCrow payloads intergration (EDR/AV evasion)

Python 466 68 Updated Jul 15, 2022

AWD攻防赛webshell批量利用框架

Python 410 86 Updated Jun 19, 2019

功能齐全的Web指纹识别和分享平台,基于vue3+django前后端分离的web架构,并集成了长亭出品的rad爬虫的功能,内置了一万多条互联网开源的指纹信息。

Python 388 62 Updated Jul 17, 2022

Issues with WebSocket reverse proxying allowing to smuggle HTTP requests

Python 380 59 Updated Aug 15, 2024

基于masscan和nmap的快速端口扫描和指纹识别工具,优化版本(获取标题,页面长度,过滤防火墙)

Python 348 50 Updated Jan 16, 2022

Hunter作为中通DevSecOps闭环方案中的一环,扮演着很重要的角色,开源之后希望能帮助到更多企业。

Python 345 123 Updated Dec 14, 2022

VulCan资产管理系统|漏洞扫描|资产探测|定时扫描

Python 329 54 Updated Dec 25, 2024

autoDecoder的用法及案例,包含加解密方法、绕waf、替换参数等操作。

Python 286 34 Updated Jul 28, 2024

常见的未授权漏洞检测

Python 267 44 Updated Apr 5, 2025

Shiro-721 RCE Via RememberMe Padding Oracle Attack

Python 266 55 Updated Oct 29, 2020

输入一个域名,输出ICP备案所有关联域名

Python 261 39 Updated Dec 4, 2022

敌后侦察

Python 235 37 Updated Dec 8, 2022

Simple Python 3 script to detect the "Log4j" Java library vulnerability (CVE-2021-44228) for a list of URLs with multithreading

Python 194 55 Updated Dec 13, 2021

PoC collection of Atlassian(Jira, Confluence, Bitbucket) products and Jenkins, Solr, Nexus

Python 180 46 Updated Sep 23, 2025

🐸Unauthorized Detection Framework未授权访问检测框架

Python 161 34 Updated Dec 15, 2023

未授权检测的命令行版,支持批量检测

Python 153 29 Updated Apr 5, 2025