Lists (29)
Sort Name ascending (A-Z)
AD域渗透
Android渗透
BurpSuite插件
C2框架+免杀
C2框架、后门相关学习资料Chrome插件
CobaltStrike插件
IMOO破解
小天才产品破解IOT渗透
IR应急响应
K8s+云服务渗透
LLM安全
Magisk模块
Payload+账号密码字典
POC+EXP集合
RootKit权限维持
权限维持Scan指纹+漏洞
SOC安全运营
安全防御、安全监控、基线检测SSDLC研发安全
研发过程安全工具vCenter渗透
VPN+代理隧道
Webshell管理
Web漏洞利用
Wx小程序渗透
微信小程序渗透工具Xposed模块
基础运维
学习资料
日常办公
本地提权
社会工程学
Stars
BloodyAD is an Active Directory Privilege Escalation Framework
An advanced [Finder | Checker | Server] tool for proxy servers, supporting both HTTP(S) and SOCKS protocols. 🎭
Attempt at Obfuscated version of SharpCollection
Collection of Beacon Object Files (BOF) for Cobalt Strike
Nightly builds of common C# offensive tools, fresh from their respective master branches built and released in a CDI fashion using Azure DevOps release pipelines.
A tool that helps you find the real IP addresses hiding behind Cloudflare by checking subdomains.
🎮 An open-source game speed modifier.[一款开源的游戏变速器]
Collection of extracted System Prompts from popular chatbots like ChatGPT, Claude & Gemini
This is just an semi-automated fully working, no-bs, non-metasploit version of the public exploit code for MS17-010
Windows software for sharing locally connected USB devices to other machines, including Hyper-V guests and WSL 2.
Moriarty is designed to enumerate missing KBs, detect various vulnerabilities, and suggest potential exploits for Privilege Escalation in Windows environments.
wgpsec / penetration
Forked from az0ne/Permeable渗透 超全面的渗透资料💯 包含:0day,xss,sql注入,提权……
Kerberos manipulation library in pure Python
Cameradar hacks its way into RTSP videosurveillance cameras
一款基于各大企业信息API的工具,解决在遇到的各种针对国内企业信息收集难题。一键收集控股公司ICP备案、APP、小程序、微信公众号等信息聚合导出。支持MCP接入
Frida scripts to rewrite mobile applications at runtime to directly MitM all HTTPS traffic
Xray panel supporting multi-protocol multi-user expire day & traffic & IP limit (Vmess, Vless, Trojan, ShadowSocks, Wireguard, Tunnel, Mixed, HTTP, Tun)
ripgrep recursively searches directories for a regex pattern while respecting your gitignore
A python script to automatically coerce a Windows server to authenticate on an arbitrary machine through 12 methods.
⬆️ ☠️ 🔥 Automatic Linux privesc via exploitation of low-hanging fruit e.g. gtfobins, pwnkit, dirty pipe, +w docker.sock
A python script to scan for Apache Tomcat server vulnerabilities.
🐢 Open-Source Evaluation & Testing library for LLM Agents