Lists (14)
Sort Name ascending (A-Z)
📱Android
安卓渗透,逆向🎯Burp插件
收集好用的burp插件神器🔥POC&EXP
0day+Nday!!!🚀免杀
Fuck 360🧠内网渗透
Cobalt Strike,隧道,代理,后渗透利器🎃字典
收集渗透测试中常用字典📕学习资料
漏洞学习,安全研究,漏洞复现...... 卷不动了,学习资料都在这里啦💉实用工具
安全相关工具Stars
为GPT/GLM等LLM大语言模型提供实用化交互接口,特别优化论文阅读/润色/写作体验,模块化设计,支持自定义快捷按钮&函数插件,支持Python和C++等项目剖析&自译解功能,PDF/LaTex论文翻译&总结功能,支持并行问询多种LLM模型,支持chatglm3等本地模型。接入通义千问, deepseekcoder, 讯飞星火, 文心一言, llama2, rwkv, claude2, m…
🚀AI拟声: 5秒内克隆您的声音并生成任意语音内容 Clone a voice in 5 seconds to generate arbitrary speech in real-time
Automatic SQL injection and database takeover tool
🚀 Level up your GitHub profile readme with customizable cards including LOC statistics!
A swiss army knife for pentesting networks
You Know, For WEB Fuzzing ! 日站用的字典。
One place for all the default credentials to assist the Blue/Red teamers identifying devices with default password 🛡️
WAFW00F allows one to identify and fingerprint Web Application Firewall (WAF) products protecting a website.
Top disclosed reports from HackerOne
Exphub[漏洞利用脚本库] 包括Webloigc、Struts2、Tomcat、Nexus、Solr、Jboss、Drupal的漏洞利用脚本,最新添加CVE-2020-14882、CVE-2020-11444、CVE-2020-10204、CVE-2020-10199、CVE-2020-1938、CVE-2020-2551、CVE-2020-2555、CVE-2020-2883、CVE-…
一个攻防知识库。A knowledge base for red teaming and offensive security.
WeChatOpenDevTool 微信小程序强制开启开发者工具
pocsuite3 is an open-sourced remote vulnerability testing framework developed by the Knownsec 404 Team.
一款适用于以HW行动/红队/渗透测试团队为场景的移动端(Android、iOS、WEB、H5、静态网站)信息收集扫描工具,可以帮助渗透测试工程师、攻击队成员、红队成员快速收集到移动端或者静态WEB站点中关键的资产信息并提供基本的信息输出,如:Title、Domain、CDN、指纹信息、状态信息等。
A fully automated, accurate, and extensive scanner for finding log4j RCE CVE-2021-44228
Automatic SSRF fuzzer and exploitation tool
An advanced web directory & file scanning tool that will be more powerful than DirBuster, Dirsearch, cansina, and Yu Jian.一个高级web目录、文件扫描工具,功能将会强于DirBuster、Dirsearch、cansina、御剑。
Neo-reGeorg is a project that seeks to aggressively refactor reGeorg
This tool generates gopher link for exploiting SSRF and gaining RCE in various servers
Packer Fuzzer is a fast and efficient scanner for security detection of websites constructed by javascript module bundler such as Webpack.
本程序旨在为安全应急响应人员对Linux主机排查时提供便利,实现主机侧Checklist的自动全面化检测,根据检测结果自动数据聚合,进行黑客攻击路径溯源。
SSRF (Server Side Request Forgery) testing resources