Stars
Reverse engineering and pentesting for Android applications
Semgrep Community Edition rules, maintained by Semgrep and the community. Free to use under the Semgrep Rules License.
The LLVM Project is a collection of modular and reusable compiler and toolchain technologies.
基础反检测 frida-server / Basic anti-detection frida-server
Allows you to emulate an Android native library, and an experimental iOS emulation
🔥🔥 hooker is a Frida-based reverse engineering toolkit for Android. It offers a user-friendly CLI, universal scripts, auto hook generation, memory roaming to detect activities/services, one-click S…
Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework capable of performing static a…
scanner detecting the use of JavaScript libraries with known vulnerabilities. Can also generate an SBOM of the libraries it finds.
Nuclei POC,每2小时更新 | 每日自动采集、验证、去重并发布 25 万+ 漏洞 PoC,保存已被删除的POC | 通过批量克隆Github项目,获取Nuclei POC,并将POC按类别分类存放,使用Github Action实现。
SpiderFoot automates OSINT for threat intelligence and mapping your attack surface.
(持续更新)对网上出现的各种OA、中间件、CMS等漏洞进行整理,主要包括漏洞介绍、漏洞影响版本以及漏洞POC/EXP等,并且会持续更新。
The best IP Toolbox. Check your IP address & geolocation, test IP for WebRTC and DNS IP leaks, run an IP quality check, browser fingerprint check, website availability check, network speed test, gl…
Automated & Manual Wordlists provided by Assetnote
SecLists is the security tester's companion. It's a collection of multiple types of lists used during security assessments, collected in one place. List types include usernames, passwords, URLs, se…
JSFinder is a tool for quickly extracting URLs and subdomains from JS files on a website.
Top disclosed reports from HackerOne
Fast subdomains enumeration tool for penetration testers