NagaScan is a distributed passive scanner for Web application.
weblogic t3 deserialization rce
一款开源指纹识别工具。
一个爬虫式的网段Web主机发现小工具 # A HTTP Service detector with a crawler from IP/CIDR
A Domain Collection Tool
Feigong,针对各种情况自由变化的mysql注入脚本,In view of the different things freely change the mysql injection script
一个高级web目录扫描工具,功能将会强于DirBuster、Dirsearch、cansina、御剑
List of Awesome Asset Discovery Resources
用于辅助安全工程师漏洞挖掘、测试、复现,集合了mock、httplog、dns tools、xss,可用于测试各类无回显、无法直观判断或特定场景下的漏洞。
CMS和中间件指纹库
对全国edu域名以及其二级域名进行的一次Sql注入,预计花费时间为三天,结束时候将提交至漏洞平台
一款轻量级、功能强大的内网穿透代理服务器。支持tcp、udp流量转发,支持内网http代理、内网socks5代理,同时支持snappy压缩、站点保护、加密传输、多路复用、header修改等。支持web图形化管理,集成多用户模式。
GyoiThon for intelligence gatering.
通过BurpSuite来构建自己的爆破字典,可以通过字典爆破来发现隐藏资产。
github泄露扫描系统
扫描器Awvs 11和Nessus 7 Api利用脚本
xsec-ip-database为一个恶意IP和域名库(Malicious ip database)
Exploit code for CVE-2016-9066
A Java Rasp Demo
Automatic Server-Side Template Injection Detection and Exploitation Tool
New On Live Web Vul Scan
目标系统信息收集组件
APT, Cyber warfare, Penetration testing, Zero-day,Exploiting,Fuzzing,Privilege-Escalation,browser-security,Spyware,Malwres evade anti-virus detection, Rookit CYPTER, Antiviruses Bypassing-av, social engineering,WORMS,Sandbox-Escape, Memory-injection, Ethical,Gray,White,RedTeam,Bugbounty,bug hunter,Cheat Sheet...
对 The Hacker Playbook 3 的翻译。
K8工具(内网渗透/提权工具/远程溢出/漏洞利用/Exploit/APT/0day/Shellcode/Payload/priviledge/OverFlow/WebShell/PenTest)
Vagrant provider for libvirt.
Perun是一款主要适用于乙方安服、渗透测试人员和甲方RedTeam红队人员的网络资产漏洞扫描器/扫描框架
开源项目挣钱实用手册
Demos for Presentation on Windows Runtime Security
Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies, alowing to bypass 2-factor authentication.
CVE-2018-2893 PoC
Network Security Vulnerability Scanner
一个对常见的web日志进行解析处理的粗糙DEMO
a pentest scanner, To make excellent tools / 一个集七种功能的漏洞综合检测利用工具, 希望可以打造出一款优秀的渗透工具
洞察-宜信集应用系统资产管理、漏洞全生命周期管理、安全知识库管理三位一体的平台。
DNSLog 是一款监控 DNS 解析记录和 HTTP 访问记录的工具。
爬虫集合
Python3编写的CMS漏洞检测框架
《白帽子讲Web扫描》书籍参考代码
Open-Source Phishing Toolkit
2018-2020青年安全圈-活跃技术博主/博客
A network sniffer that logs all DNS server replies for use in a passive DNS setup
go编写的区块链入门级项目
网页相似度判断:根据网页结构判断页面相似性 ,可用于相似度计算、越权检测等(Determine page similarity based on HTML page structure)
A tool to identify and exploit sudo rules' misconfigurations and vulnerabilities within sudo
golang Aho-Corasick for byte strings
QNSM is network security monitoring framework based on DPDK.
Console progress bar for Golang
A Fast & free Windows remote administration tool.
Biu-framework🚀 Security Scan Framework For Enterprise Intranet Based Services(企业内网基础服务安全扫描框架)
DrSemu - Malware Detection and Classification Tool Based on Dynamic Behavior [The tool is in the early development stage]
This tool compares a targets patch levels against the Microsoft vulnerability database in order to detect potential missing patches on the target. It also notifies the user if there are public exploits and Metasploit modules available for the missing bulletins.
收集一些比较优秀的开源安全项目,以帮助甲方安全从业人员构建企业安全能力。
使用MFC编写的病毒技术合集
gin+gorm开发的视频网站示例
Pwn stuff.
渗透 超全面的渗透资料💯 包含:0day,xss,sql注入,提权……
Write and publish your own blockchain in less than 200 lines of Go
LimeRAT | Simple, yet powerful remote administration tool for Windows (RAT)
Cscan 5.0 & Cobalt Strike 大型内网渗透自定义插件化扫描器(附C#/VC/Delphi/Python插件Demo源码) 程序采用多线程批量扫描大型内网多个IP段C段主机,目前插件包含: C段旁注扫描、子域名扫描、Ftp密码爆破、Mysql密码爆破、Oracle密码爆破、MSSQL密码爆破、Windows/Linux系统密码爆破、存活主机扫描、端口扫描、Web信息探测、操作系统版本探测、Cisco思科设备扫描等,支持调用任意外部程序或脚本
Process Monitor Library (based on Apple's new Endpoint Security Framework)
HTTP/HTTPS/DNS inspector (windows driver)
脚本工具
PortTran (.NET版端口转发工具 支持任意权限下转发)
backdoor
个人域渗透学习笔记
alternative to procdump
ATT&CK实操
simple tcp port scanner + banner grabber
dnscrypt-proxy 2 - A flexible DNS proxy, with support for encrypted DNS protocols.
Web安全相关内容
This tool is used to map out the network data flow to help penetration testers identify potentially valuable targets.
oracle 数据库命令执行
这是一个用于IP和域名碰撞匹配访问的小工具,旨意用来匹配出渗透过程中需要绑定hosts才能访问的弱主机或内部系统。
越权检测工具
Custom Command and Control (C3). A framework for rapid prototyping of custom C2 channels, while still providing integration with existing offensive toolkits.
JSFinder is a tool for quickly extracting URLs and subdomains from JS files on a website.
一款采用Telegram类似的安全加密方案实现的保护个人隐私安全的微信聊天插件。
A proof of concept OS written in Go
JustTrustMe的二次开发版本,用于禁用SSL证书校验,扩展了原来程序的功能。
go-masscan is a golang library to run masscan scans, parse scan results.
a PoC for Linux to get around agents that log commands being executed, without root privilege. Linux低权限模糊化执行的程序名和参数,避开基于execve系统调用监控的命令日志
BCS(北京网络安全大会)2019 红队行动会议重点内容
A rule-based tunnel in Go.
Windows 10 LPE (UAC Bypass) in Windows Store (WSReset.exe)
The fastest and cross-platform subdomain enumerator, don't waste your time.
[4I402] PNL : Programmation Noyau Linux
OneForAll是一款强大的子域收集神器
获取系统KB补丁对于的MS号
🎯 HackerTarget ToolKit - Tools And Network Intelligence To Help Organizations With Attack Surface Discovery 🎯
Anti DDOS | Bash Script
🎯 Command Injection Payload List
jon 是一款LINUX系统攻防工具箱,包含扫描,入侵,痕迹清理,木马,网站测试等各种黑客工具。
Hollow Process / Dynamic Forking / RunPE injection technique implemented in Python
Hollowfind is a Volatility plugin to detect different types of process hollowing techniques used in the wild to bypass, confuse, deflect and divert the forensic analysis techniques. The plugin detects such attacks by finding discrepancy in the VAD and PEB, it also disassembles the address of entry point to detect any redirection attempts and also reports any suspicious memory regions which should help in detecting any injected code.
Process Hollowing
webanalyzer wip
An Open Source Multi Site Automated Social Media Phishing Framework
Web Pentesting Fuzz 字典,一个就够了。
免杀webshell无限生成工具(免杀一句话生成|免杀D盾|免杀安全狗护卫神河马查杀等一切waf)
Pre-compiled tools to tunnel TCP over RDP Connections
京东SRC小课堂系列文章
Cisco Talos MBR Filter Driver
Dark Web OSINT Tool
A gevent spider ,support webkit for dom parsing.
share some useful archives about vm and qemu escape exploit.
reuse tcp/udp ports in golang
Low performance loss and by LKM technology HIDS tool.from Dianrong InfoSEC team.
C# Script used for Red Team
《30天自制操作系统》源码中文版。自己制作一个操作系统(OSASK)的过程
Pythonic HTML Parsing for Humans™
Privilege Escalation Enumeration Toolkit (ELF 64/32 ) , fast , intelligent enumeration with Web API integration . Mastering Your Own Finding
fastjson漏洞快速利用框架
Simple php backdoor based on extension
Kayak is a CAN bus analysis tool based on SocketCAN
Resident (inotify) Anti-Malware Scanner using rules from Linux Malware Detect project
Base on crawler result web path scanner.
Dytan Taint Analysis Framework on Linux 64-bit
Random Forest implemtation in GoLang
Golang Mini LFI (Local File Inclusion) Tester
Linux Kernel Rootkit - To hide modules and ssh service
A kernel level anti-rootkit tool which runs on the windows platform.
class project to replace 'the' with 'she' for files named 'unix.txt' as a kernel module intercepting sys_read
Decoding a User Space Encoded PHP Script
Prevoty node.js bindings
A lightweight web application firewall module for nginx, which is already used in the production environment.
A Sample SearchEngine
MySQL proxy with hook system written in python 2
Sentinel is a command line tool able to protect Windows 32 bit programs against exploits targeted by attackers or viruses. It can protect your programs against 0-day attacks or publicly known bugs.
Directed graph or "digraph" implementation, written in Go. MIT Licensed.
NOT MY CODE! Zeus trojan horse - leaked in 2011, I am not the author. I have created this repository to make the access for study as easy as possible.
NetCat for Windows
a pure python Aho-corasick algorithm implementation
Linux kernel rootkit to hide certain files and processes.
Minemu is a minimal emulator for dynamic taint analysis ( this is a mirror of https://minemu.org/code/minemu.git )
Small Backdoor/rootkit for linux kernel
Xss Scaner
A PHP Extension for trace/debug/monitor
A Linux kernel module that locates the system call table in memory and hooks uname. Contributions welcome!
The sandbox libraries (libsandbox & pysandbox) are an open-source suite of software components for C/C++ and Python developers to create automated profiling tools and watchdog programs. The API's are designed for executing and instrumenting simple (single process) tasks, featuring policy-based behavioral auditing, resource quota, and statistics collecting.
A high-performant Logging Foundation for Go Applications. X3 faster than the rest leveled loggers.
Pure-Go HBase client
Automatically exported from code.google.com/p/httpsqs
A pretty chrome extension for altering host headers.
Automatically exported from code.google.com/p/php-httpsqs-client
Safing UI
POC of spectre in Golang
优雅的go协程库,轻松控制并发数
Noodles(面条)是一款超轻量级分布式任务调度类库(太轻量级了,谈不上框架),类似于python的celery,大量参考benmanns的goworker.
一个专门用于安全工具开发的HTTP类库.
go-nmap is a golang library to run nmap scans, parse scan results.
List of awesome penetration testing resources, tools and other shiny things
Legion is an open source, easy-to-use, super-extensible and semi-automated network penetration testing tool that aids in discovery, reconnaissance and exploitation of information systems.
Spring Data Commons RCE 远程命令执行漏洞
Website Sensitive Personal Information Hunter 网站个人敏感信息文件扫描器
IDS using a port mirror, Snort and an alert -> RESTCONF utility
Unbelievably space efficient data structures in Golang.
🚇暗网中文网监控爬虫
Windows Exploit Suggester - Next Generation
Analyses your Java and Python applications for open-source dependencies with known vulnerabilities, using both static analysis and testing to determine code context and usage for greater accuracy. https://sap.github.io/vulnerability-assessment-tool/
PHP Runtime Vulnerability Detection
专为程序员编写的英语学习指南。v1.0
A collection of Red Team focused tools, scripts, and notes
A safe, extensible ORM and Query Builder for Rust
File Inclusion & Directory Traversal fuzzing, enumeration & exploitation tool.
This is a PowerShell based tool that is designed to act like a RAT. Its interface is that of a shell where any command that is supported is translated into a WMI-equivalent for use on a network/remote machine. WMImplant is WMI based.
Share a terminal session over WebRTC
An open source, cloud native toolkit for threat detection and mitigation
Throttle the CPU usage to a maximum
A repository of sysmon configuration modules
平时抓包写的suricata规则,会慢慢更新
我在学习浏览器安全过程中整理的漏洞分析笔记与相关的学习资料
🤖 Python examples of popular machine learning algorithms with interactive Jupyter demos and math being explained
PowerShell rebuilt in C# for Red Teaming purposes
A tool to perform Kerberos pre-auth bruteforcing
Static Analyzer for Solidity
Security proxy server for Exchange server
Security Research from the Microsoft Security Response Center (MSRC)
Asynchronous MSF RPC API wrapper
Bypassing disabled exec functions in PHP via imap_open
process info/monitoring library for macOS
A golang HTTP client library. Salute to python requests.
dynamic binary analysis via platform emulation
A distributed nmap scanning framework
SharpSploit is a .NET post-exploitation library written in C#
SharpDump is a C# port of PowerSploit's Out-Minidump.ps1 functionality.
🍻 Fast CORS misconfiguration vulnerabilities scanner
在Windows环境下的进程注入方法:远程线程注入、创建进程挂起注入、反射注入、APCInject、SetWindowHookEX注入
Platform Security Assessment Framework
BitCracker is the first open source password cracking tool for memory units encrypted with BitLocker
Melkor is a very intuitive and easy-to-use ELF file format fuzzer to find functional and security bugs in ELF parsers.
Mobile Device Management server
超级弱口令检查工具是一款Windows平台的弱口令审计工具,支持批量多线程检查,可快速发现弱密码、弱口令账号,密码支持和用户名结合进行检查,大大提高成功率,支持自定义服务端口和字典。
Configuration guidance for implementing the Windows 10 and Windows Server 2016 DoD Secure Host Baseline settings. #nsacyber
Automatic extract anomalious Web attack Payloads with Unsupervised Machine Learning algorithms
The system call intercepting library
Building an Active Directory domain and hacking it
tamper resistant audit log
Go语言实现DPoS共识算法
VeChain core nodes security checklist(唯链核心节点安全执行指南)
Application layer scanner that operates with ZMap
A Microservices-based framework for the study of network security
An ext for php to decode some phpjiami
kubeaudit helps you audit your Kubernetes clusters against common security controls
Simple PowerShell enumeration script to look for interesting files
The GOSINT framework is a project used for collecting, processing, and exporting high quality indicators of compromise (IOCs).
Nishang - Offensive PowerShell for penetration testing and offensive security.
兜哥出品 <一本开源的NLP入门书籍>
Python bindings for iptables
CVE-2018-8174 - VBScript memory corruption exploit.
Yet Another MOnitoring Tool
AD LDAP Command Line Searching that doesn't suck.
Python AV evasion tool capable to generate FUD executable even with the most common 32 bit metasploit payload(exe/elf/dmg/apk)
Burp Suite Collaborator HTTP API
Red Team Tips as posted by @vysecurity on Twitter
数据库基线检查工具
《企业安全建设入门:基于开源软件打造企业网络安全》
A static analysis security vulnerability scanner for Ruby on Rails applications
Go-deliver is a payload delivery tool coded in Go.
Tools to gather subdomains from Bug Bounty programs
Simple reverse ICMP shell
Tiny Linux distro that runs the entire OS as Docker containers
Direct Memory Access (DMA) Attack Software
PoC of Remote Command Execution via Log injection on SAP NetWeaver AS JAVA CRM
PHP Foreign Function Interface
Devestating and awesome Linux X86_64 ELF Virus
MemoryReadWrite InlineAsm Managed/UnmanagedInject
A curated list of resources (books, tutorials, courses, tools and vulnerable applications) for learning about Exploit Development
event shipper for Carbon Black Defense notifications
Open Source Deep Packet Inspection Software Toolkit
Windows passwords decryption from dump files
CVE-2018-6546-Exploit
Exploit code developed by me to check few famous vulnerabilities
Linux 0.01源码及注释
A simple AntiVirus-as-a-Service implementation using ClamAV
Linux Kernel Defence Map
ELF anti-forensics exec, for injecting full dynamic executables into process image (With thread injection)
Automate Pentest Tool
Linux服务器信息收集脚本
DockerXScan——Docker镜像漏洞扫描器
A Powerful Subdomain Takeover Tool
Some tools for CTF off line
OSINT framework in Go
Damn Vulnerable iOS App (DVIA) is an iOS application that is damn vulnerable. Its main goal is to provide a platform to mobile security enthusiasts/professionals or students to test their iOS penetration testing skills in a legal environment. This project is developed and maintained by @prateekg147. The vulnerabilities and solutions covered in this app are tested up to iOS 11. The current version is writen in Swift and has the following vulnerabilities.
MIT课程《Distributed Systems 》学习和翻译
use python to parse nginx
Use powershell to list the RDP Connections History of logged-in users or all users
麻省理工公开课-线性代数-完整笔记
DomainPasswordSpray is a tool written in PowerShell to perform a password spray attack against users of a domain. By default it will automatically generate the userlist from the domain. BE VERY CAREFUL NOT TO LOCKOUT ACCOUNTS!
Advanced Honeypot framework.
The state of the art network attack and monitoring framework.
Engine for capturing, parsing and replaying DNS
Enumeration sub domains(枚举子域名)
GoodbyeDPI—Passive Deep Packet Inspection blocker and Active DPI circumvention utility (for Windows)
Scanning process memory
a pass-the-hash tool
CVE-2018-4878 样本
a fast domain brute tool
Go package for parsing Apache logs.
Versatile resource statistics tool
ODAT: Oracle Database Attacking Tool
PS4 5.01 WebKit Exploit PoC
A Parser for PHP written in Go
a php nsq client write by c extension,the fastest nsq client
以太坊智能合约检查
This is a web-penetration testing toolkit, presently suited for reconnaissance purposes.
一个色情小说检测项目
Wafid identify and fingerprint Web Application Firewall (WAF) products.
Cuckoo Sandbox is an automated dynamic malware analysis system
some exploits
PHP底层内核源码分析和扩展开发
Chrome extension and Express server that exploits keylogging abilities of CSS.
设计模式 Golang实现-《研磨设计模式》读书笔记
CLI tool for open source and threat intelligence
Fast directory traversal for Golang
Static unpacker for FinSpy VM
Combining Unit Tests, Fuzzing, and AI
Stealing CSRF tokens with CSS injection (without iFrames)
一款由 YSRC 开源的主机入侵检测系统
A toolset to make a system look as if it was the victim of an APT attack
Detecting malicious WiFi with mining cryptocurrency.
Passive DNS collection using Bro
svn>1.7时,dump源码工具
Logstash 日志安全攻击分析插件
Blackbox tool to disable SSL certificate validation - including certificate pinning - within iOS and OS X Apps
Open Source Vulnerability Assessment and Management helps developers and pentesters to perform scans and manage vulnerabilities.
WebLogic Exploit
CVE-2017-4878 Samples - http://blog.talosintelligence.com/2018/02/group-123-goes-wild.html
This program locally checks for signs of a rootkit. 'Forked' to fix false-positive for SucKIT rootkit
Generic scripts for public consumption
metasploit中文wiki
Zero trust system
A tiny container
LuLu is the free open-source macOS firewall that aims to block unauthorized (outgoing) network traffic 开源macOS防火墙
A SDK for access control policies: authorization for the microservice and IoT age. Inspired by AWS IAM policies. Written for Go.
A fast, hackable and simple x64 VT-x hypervisor for Windows and Linux. Builtin userspace sandbox and introspection engine.
Cross-platform utility that uncovers the technologies used on websites.
A little tool for detecting suspicious privileged NTLM connections, in particular Pass-The-Hash attack, based on event viewer logs.
Generate unicode evil domains for IDN Homograph Attack and detect them.
Two different gadgets to bypass the blacklist in jackson-databind for RCE
Gives you one-liners that aids in penetration testing operations
Hacker101
GoLismero - The Web Knife
EasyHook - The reinvention of Windows API Hooking
Egressbuster is a method to check egress filtering and identify if ports are allowed. If they are, you can automatically spawn a shell.
Tiny little reverse socks5 client & server
内网穿透、远程文件上传下载、命令执行
This tool will setting up your backdoor/rootkits when backdoor already setup it will be hidden your spesisifc process,unlimited your session in metasploit and transparent. Even when it killed, it will re-run again. There always be a procces which while run another process,So we can assume that this procces is unstopable like a Ghost in The Shell
psutil for golang
A utility to generate malicious network traffic and evaluate controls
数据可视化
MFS (Minio Federation Service) is a namespace, identity and access management server for Minio Servers
A cheat sheet for pentesters and researchers about vulnerabilities in well-known monitoring systems.
An Apache 2.4.x module for authenticating requests from the ScaleFT Access Fabric
Protocol Learning and Stateful Fuzzing
An example project that exploits the default typing issue in Jackson-databind via Spring application contexts and expressions
Your Everyday Threat Intelligence
Aho-Corasick Automaton with Double Array Trie (Multi-pattern substitute in go)
整理收集Struts2漏洞环境
Open source Active Directory security audit framework.
java agent demo
MySQL and MSSQL brute force and post exploitation tool to search through databases and extract sensitive information.
First IDE for Nmap Script (NSE) Development.
A BeyondCorp/Zero Trust Identity & Access Proxy (IAP) built on top of OAuth2 and ORY Hydra.
监测分析、异常监测、广告验证、访客唯一标识
逆向火绒安全软件驱动——sysdiag
Automated Penetration Testing Framework
The Nmap Scanner for Telco
Meltdown/Spectre PoC src collection.
Internal penetration testing tool for Linux that can be used to enumerate OS information, domain information, shares, directories, and users through SMB.
pyHIDS is a HIDS (host-based intrusion detection system) for verifying the integrity of a system. It uses an RSA signature to check the integrity of its database. Alerts are written in the logs of the system and can be sent via email to a list of users. You can define rules to specify files to be checked periodically.
Introspected tunnels to localhost
网络安全态势感知新闻平台(前台)
An Out-of-Band XXE server for retrieving file contents over FTP.
Port knocking daemon with web interface
Web path scanner
各种开源CMS 各种版本的漏洞以及EXP 该项目将不断更新
docker 安全基线规范
X Attacker Tool ☣ Website Vulnerability Scanner & Auto Exploiter
x-crack - Weak password scanner, Support: FTP/SSH/MSSQL/MYSQL/PostGreSQL/REDIS/ElasticSearch/MONGODB
A framework for developing alerting and detection strategies for incident response.
使用LSTM模型检测DGA域名
Detect and bypass web application firewalls and protection systems
blacksheepwall is a hostname reconnaissance tool子域名爆破工具
dns tunnel dectect with CNN
Linux下常用工具及其命令介绍
Go packages to interact with QEMU using the QEMU Machine Protocol (QMP). Apache 2.0 Licensed.
Gogs is a painless self-hosted Git service.
A service for thousands regex finder with Intel's hyperscan.(海量正则快速匹配,给定一行字符串,能够从海量的正则里快速匹配到是否有符合条件的正则)
Golang - 获取Windows & Linux登录日志并正则解析
proxy是golang实现的高性能http,https,websocket,tcp,socks5代理服务器,支持正向代理和内网穿透.程序本身可以作为一级代理,如果设置了上级代理那么可以作为二级代理,乃至N级代理.如果程序不是一级代理,而且上级代理也是本程序,那么可以加密和上级代理之间的通讯,采用底层tls高强度加密,安全无特征.代理时会自动判断访问的网站是否屏蔽,如果被屏蔽那么就会使用上级代理(前提是配置了上级代理)访问网站;如果访问的网站没有被屏蔽,为了加速访问,代理会直接访问网站,不使用上级代理.另外可以设置域名黑白名单,更加自由的控制网站的访问方式。下载地址:https://github.com/snail007/goproxy/releases 官方QQ交流群:189618940
人脸识别库
用于检测攻击的第三方库
Lex machinary for go.
A Deep Learning Approach for Password Guessing (https://arxiv.org/abs/1709.00440)
Suricata git repository maintained by the OISF
Empire is a PowerShell and Python post-exploitation agent.
Capsule8: open-source cloud-native behavioral security monitoring
SSRF Proxy facilitates tunneling HTTP communications through servers vulnerable to Server-Side Request Forgery.
A cross-platform python based utility to penetrate websites and test them with approximately every angle.
一款拥有完整交互界面与驱动级拦截能力的开源杀毒软件
Another php debug tool.
基于Golang、WebSocket、xTermJS 的 Web SSH 远程终端
Official Black Hat Arsenal Security Tools Repository
golang版的dsinff-webspy
Demo about realtime analytics of user behavior using elk stack/apache spark streaming+mllib/redis/slamdata用户行为分析
Struts2の脆弱性S2-045, S2-055 および Jackson の脆弱性 CVE-2017-7525, CVE-2017-15095 の調査報告
A Suricata based IDS/IPS distro
Share your terminal as a web application
An automation framework for running multiple open sourced subdomain bruteforcing tools (in parallel) using your own wordlists via Docker Compose
锁主页驱动
Extended Differential Fuzzing Framework
恶意流量分析程序
kiwi:安全源码审计工具
Automatically brute force all services running on a target.
CLI tool that finds secrets accidentally committed to a git repo, eg passwords, private keys
SQL注入工具
自动扫描内网常见sql、no-sql数据库脚本(mysql、mssql、oracle、postgresql、redis、mongodb、memcached、elasticsearch),包含未授权访问及常规弱口令检测
Python script to scan Git repos for interesting strings
CMS渗透测试框架-A CMS Exploit Framework
Signature base for my scanner tools
Subdomain enumeration and information gathering tool
A Python Framework For NoSQL Scanning and Exploitation
Fastjson 反序列化漏洞利用工具
Example of hooking a linux systemcall
Go interface to NTDLL functions
区块链存证
Simple Solution for Multi-Criteria Chinese Word Segmentation
binary patching from Python
解密好的AWVS10.5 data/script/目录下的脚本
Security-related PHP7 OPcache abuse tools and demo
Exploit toolkit CVE-2017-0199 - v4.0 is a handy python script which provides pentesters and security researchers a quick and effective way to test Microsoft Office RCE. It could generate a malicious RTF/PPSX file and deliver metasploit / meterpreter / other payload to victim without any complex configuration.
Koadic C3 COM Command & Control - JScript RAT
逆向小红伞杀毒软件驱动——avkmgr
A post-exploitation powershell tool for extracting juicy info from memory.
java source code danger function identify prog
Android Remote Administration Tool
Damn Vulnerable NodeJS Application
Malcom - Malware Communications Analyzer
psad: Intrusion Detection and Log Analysis with iptables
DNSQuery Sniffer in Golang
Linux Rootkit Scanner
使用minifilter编写的透明加解密驱动。
Dshell is a network forensic analysis framework.
爆破字典
Git All the Payloads! A collection of web attack payloads.
Unicorn CPU emulator framework (ARM, AArch64, M68K, Mips, Sparc, X86)
BeyondCorp-style SSH ProxyCommand, allowing for federated SSH clients
Web scan foundation framework
CeWL is a Custom Word List Generator
Isolation forest implementation in Go
Tensorflow实战学习笔记
Network traffic sniffer, decoder and mirror
Analyze the security of any domain by finding all the information possible. Made in python.
goworker is a Go-based background worker that runs 10 to 100,000* times faster than Ruby-based workers.
Docker Firewall Framework
Distributed private networking
LKM Linux rootkit
Yet Another Source Code Analyzer
记录与分享PHP WebShell 绕过WAF 的一些经验 Share some experience about PHP WebShell bypass WAF
DNS-Shell is an interactive Shell over DNS channel
A programming language prototype implemented in C with an AST, Compiler, and Virtual Machine \@TODO Garbage Collection
🔐 A concurrent, command-line AWS S3 Fuzzer. Written in Go.
Linux baseline scan,make sure the host security
This tool was written as PoC to article https://waf.ninja/libinjection-fuzz-to-bypass/
Proof-of-concept codes created as part of security research done by Google Security Team.
Detecting Lateral Movement with Machine Learning
一款lcx在golang下的实现
Hostile Subdomain Takeover tool written in Go
goscan is a simple and efficient IPv4 network scanner that discovers all active devices on local subnet.
获取腾讯企业邮箱通讯录
Malicious PDF document parsing tool
File upload vulnerability scanner and exploitation tool.
Listens for Firewall rule match events generated by Microsoft Hyper-V Virtual Filter Protocol (VFP) extension.
《Web安全之深度学习与实战》
Burp plugin able to find reflected XSS on page in real-time while browsing on site
Scan .onion hidden services with nmap using Tor, proxychains and dnsmasq in a minimal alpine Docker container.
go-audit is an alternative to the auditd daemon that ships with many distros
A mini cryptocurrency in Ruby
A burp extender that reconginze CAPTCHA and use for intruder payload
:book: [译] 写给人类的机器学习
Package lmsensors provides access to Linux monitoring sensors data, such as temperatures, voltage, and fan speeds. MIT Licensed.
Python AST-based static analyzer from OpenStack Security Group
Java RMI enumeration and attack tool.
Nzyme collects 802.11 management frames directly from the air and sends them to a Graylog (Open Source log management) setup for WiFi IDS, monitoring, and incident response. It only needs a JVM and a WiFi adapter that supports monitor mode.
Windows log and threat hunting with powershell
Burplay is a Burp Extension allowing for replaying any number of requests using same modifications definition. Its main purpose is to aid in searching for Privilege Escalation issues.
SSRF (Server Side Request Forgery) testing resources
Netbyte is a Netcat-style tool that facilitates probing proprietary TCP and UDP services. It is lightweight, fully interactive and provides formatted output in both hexadecimal and ASCII.
"星云"业务风控系统
DOM fuzzer
cgroups package for Go
Scan and edit memory using WinAPI functions such as ReadProcessMemory and WriteProcessMemory
Create randomly insecure VMs
端口复用工具,能让HTTP/HTTPS/SSH/RDP/SOCKS5/HTTPProxy/Other跑在同一个端口上,支持复用本地或远程端口
WikiLeaks Vault 7 CIA Hacking Tools
Deserialization payload generator for a variety of .NET formatters
PyJFuzz - Python JSON Fuzzer
Exploit Time-based blind-SQL injection in HTTP-Headers (MySQL/MariaDB).
Another web vulnerabilities scanner, this extension works on Chrome and Opera
Faster and more efficient stateless SYN scanner and banner grabber due to userland TCP/IP stack usage.
Tool for advanced mining for content on Github
A Github organization reconnaissance tool.
Parser for PHP written in Go
Stealth post-exploitation framework
Complete container management platform
Automatic SQL injection with Charles and sqlmap api
A DNS tunnel utilizing the Burp Collaborator
Linux LD_PRELOAD rootkit (x86 and x86_64 architectures)
Pure HTTP and DNS Botnet written in Golang for Windows.
Zero-downtime restarts in Go
DBC2 (DropboxC2) is a modular post-exploitation tool, composed of an agent running on the victim's machine, a controler, running on any machine, powershell modules, and Dropbox servers as a means of communication.
Collaborative Penetration Test and Vulnerability Management Platform
JWT brute force cracker written in C
High-performance lock-free queue (Disruptor 1400/s)
linux-kernel-exploits Linux平台提权漏洞集合
Software Defined Security Service
Intrusion Prevention System to dynamically add firewall rules to block malicious traffic detected by IDS system implemented on Software Defined Networl (SDN). Alternatively, the malicious traffic can be redirected to a Honeypot Server. OpenFlow protocol used for SDN. Snort used for IDS (Intrusion Detection System).
Daemon to ban hosts that cause multiple authentication errors
A tiny and cute URL fuzzer
Example code for our book Introduction to Artificial Intelligence for Security Professionals
SAML2 Burp Extension
:books: 免费的计算机编程类中文书籍,欢迎投稿
This is a webshell open source project
Safing Notify
基于WFP(Windows Filter Platform)的个人防火墙系统
Web-based OSINT and active reconaissance suite
SecLists is the security tester's companion. It is a collection of multiple types of lists used during security assessments. List types include usernames, passwords, URLs, sensitive data grep strings, fuzzing payloads, and many more.
Spaghetti - Web Application Security Scanner
SQL Injection Exploitation Tool
a little task queue for python
A bunch of proof-of-concept exploits for the Linux kernel
WAFW00F allows one to identify and fingerprint Web Application Firewall (WAF) products protecting a website.
Docker management website
Triton is a Dynamic Binary Analysis (DBA) framework. It provides internal components like a Dynamic Symbolic Execution (DSE) engine, a Taint Engine, AST representations of the x86 and the x86-64 instructions set semantics, SMT simplification passes, an SMT Solver Interface and, the last but not least, Python bindings.
MS17-010
Client and Gateway Modules for Software Defined Perimeter (SDP)
OpenSource My ImageMagick Fuzzer ..
psychoPATH - hunting file uploads & LFI in the dark. This tool is a highly configurable payload generator detecting LFI & web root file uploads. Involves advanced path traversal evasive techniques, dynamic web root list generation, output encoding, site map-searching payload generator, LFI mode, nix & windows support, single byte generator. Now available in the Burp App Store!
A high-performance DNS stub resolver for bulk lookups
[FOS:RASP-PHP] PHP Demo Vulnerable Application to test SQL injection vulnerability and patch it using RASP (Runtime Application Self-Protection)
Babel Scripting Framework
Perform a variety of tests to discover what an unknown rendering engine supports
Bug Hunting Recon Script
This tool can be used to brute discover GET and POST parameters
CAN analysis - Use your car as a gamepad!
Find broken links, missing images, etc in your HTML.
Hacker tools on Go (Golang)
ShadowSocks(SS) traffic sniffer
A Burp Suite extender that search sub domain and similar domain from sitemap
Perform timing attacks against web applications
Vulnerability scanner based on vulners.com search API
:herb: NodeJS PHP Parser - extract AST or tokens (PHP5 and PHP7)
Linux Malware Detection (LMD)
A collection of Ansible roles for automating infosec builds.
A Burp Suite Pro extension which augments your proxy traffic by injecting non-invasive headers designed to reveal backend systems by causing pingbacks to Burp Collaborator
This repository contains all the material from the talk "Esoteric sub-domain enumeration techniques" given at Bucrowd LevelUp 2017 virtual conference
Write JavaScript alert(1) with Katakana characters only
netflowAnalyser
一个多线程WEB源码泄漏检测工具
Searches through git repositories for high entropy strings, digging deep into commit history
:traffic_light: Port mapping library for Go supporting NAT-PMP and UPnP
Java serialization brute force attack tool.
用于探测公司用户是否存在弱口令
Rust code to show how hooking in rust with a dll works.
本地文件包含利用工具
A golang DNS monitor inspired by https://github.com/gamelinux/passivedns
Modular file scanning/analysis framework
Recon Dog is an all in one tool for all your basic information gathering needs.
Utilize misconfigured DNS and old database records to find hidden IP's behind the CloudFlare network
EyeWitness is designed to take screenshots of websites, provide some server header info, and identify default credentials if possible.
A pipeline for scanning domains to measure things like speed, accessibility, and HTTPS.
A tool that can help detect and takeover subdomains with dead DNS records
An open autonomous driving platform
Deep Learning Book Chinese Translation
基于机器学习的分布式webshell检测系统
Pocs for Antivirus Software‘s Kernel Vulnerabilities
PHP7内核剖析
Pupy is an opensource, cross-platform (Windows, Linux, OSX, Android) remote administration and post-exploitation tool mainly written in python
x86 emulator by Golang
A list of my CVE's with POCs
Pinpoint is an open source APM (Application Performance Management) tool for large-scale distributed systems written in Java.
A collection of malware samples caught by several honeypots i manage
Capture and parse http traffics
A series of python scripts for generating weird character combinations for bypassing web application firewalls (WAF) and XSS blockers
A curated list of awesome malware analysis tools and resources
Enumerate subdomains through Virustotal
XSStrike is a program which can fuzz and bruteforce parameters for XSS. It can also detect and bypass WAFs.
A Python RESTful API framework for online malware and URL analysis services.
Brute-Forcing from Nmap output - Automatically attempts default creds on found services.
Mirror of http://www.openwall.com/php_mt_seed/
adding more exploits and tools
libnids
分布式系统的跟踪系统 |Open Source APM (application performance management)
Your interpreter isn’t safe anymore — The PHP module rootkit
Web&Browser Security
A lightweight batch scanning framework based on gevent.
PCShare是一款强大的远程控制软件,可以监视目标机器屏幕、注册表、文件系统等。
crawl hackerone reports
GoReplay is an open-source tool for capturing and replaying live HTTP traffic into a test environment in order to continuously test your system with real data. It can be used to increase confidence in code deployments, configuration changes and infrastructure changes.
fast TCP banner grabbing with node.js
Finds unknown classes of injection vulnerabilities
Nginx configuration static analyzer
BruteSploit is a collection of method for automated Generate, Bruteforce and Manipulation wordlist with interactive shell. That can be used during a penetration test to enumerate and maybe can be used in CTF for manipulation,combine,transform and permutation some words or file text :p
Simply generates a wordpress plugin that will grant you a reverse shell once uploaded. I reccomend installing Kali Linux, as msfvenom is used to generate the payload.
Build self-defending applications through real-time event detection and response
常用服务器、数据库、中间件安全配置基线 - 基本包括了所有的操作系统、数据库、中间件、网络设备、浏览器,安卓、IOS、云的安全配置 For benchmarks.cisecurity.org
KVM-based Virtual Machine Introspection
Gives context to a system. Uses EQGRP shadow broker leaked list to give some descriptions to processes.
A Ruby framework for developing and using modules which aid in the penetration testing of WordPress powered websites and systems.
WPSeku - Wordpress Security Scanner
PHP Internals Book
A python script that finds endpoints in JavaScript files
Checks expired domains, bluecoat categorization, and Archive.org history to determine good candidates for phishing and C2 domain names
Framework for Testing WAFs (FTW!)
Tamper Chrome is a Chrome extension that allows you to modify HTTP requests on the fly and aid on web security testing. Tamper Chrome works across all operating systems (including Chrome OS).
Automated Pentest Recon Scanner
A Burp Extension to test applications for vulnerability to the Web Cache Deception attack
An SSRF-preventing wrapper around Python's requests library
Simple Wordpress Security Scanner
Windows exploits, mostly precompiled.
T-Pot Image Creator
A simple and fast sub domain brute tool for pentesters
Security-focused static analysis for the Phoenix Framework
Rust bindings for iptables
This is the list of all rootkits found so far on github and othersites.
Proof-of-concept program that is able to to hijack/hook/proxy Python module(s) thanks to $PYTHONPATH variable
基于docker虚拟化的恶意代码沙箱
Advanced vulnerability scanning with Nmap NSE
A python2 script for sweeping a network to find windows systems compromised with the DOUBLEPULSAR implant.
Source code and binaries of FlexiSpy from the Flexidie dump
Dawn is a static analysis security scanner for ruby written web applications. It supports Sinatra, Padrino and Ruby on Rails frameworks.
Command-line utility to scan the system and report on potential vulnerabilities, based on public CVE data
Decrypted content of eqgrp-auction-file.tar.xz
security technology documents
An Easy and Simple Anti-DDoS solution for VPS,Dedicated Servers and IoT devices
KVM-based virtual machine introspection for malware analysis
A tool to dump the login password from the current linux user
中国网络安全技术对抗赛代码
一个各种方式突破Disable_functions达到命令执行的shell
A library for python-based application logging and data collection
🐶 A curated list of Web Security materials and resources.
Yet Another Web Spider
Non-HTTP Protocol Extension (NoPE) Proxy and DNS for Burp Suite.
DNS Replay Tool
Data extraction tool for Docker Registry API
开源php加密运行扩展,基于screw二次开发,暂时只能在linux下运行
TinyAntivirus is an open source antivirus engine designed for detecting polymorphic virus and disinfecting it.
GRR Rapid Response: remote live forensics for incident response
Tool for injecting a shared object into a Linux process
JavaScript engine & DOM fuzzers
A static byte code analyzer for Java deserialization gadget research
Agentless network interfaces monitor for GNU/Linux firewalls/servers
Veil Evasion is no longer supported, use Veil 3.0!
A list of publicly known but unfixed security bugs
Clone repository for Source Code secret anti-forensic tools Marble Framework CIA, Leaked by WikiLeaks.
NSA finest tool
a very fast brute force webshell password tool
一个半自动化命令注入漏洞Fuzz工具(One Semi-automation command injection vulnerability Fuzz tool)
Azazel is a userland rootkit based off of the original LD_PRELOAD technique from Jynx rootkit. It is more robust and has additional features, and focuses heavily around anti-debugging and anti-detection.
Just a scan by Z3r0yu
A tool to surface security issues in python code
醉考拉tomcat后台弱口令扫描器,命令行版+图形界面版。
PyMultitor - Python Multi Threaded Tor Proxy
基于SmartQQ(WebQQ)的QQ机器人 / a qq robot based on smartqq(webqq) api
中文人名语料库
softScheck Cloud Fuzzing Framework
End-to-End encrypted Tor2Web gateway
准确率99.9%的ip地址定位库,0.0x毫秒级查询,数据库文件大小只有1.5M,提供了java,php,c,python,nodejs,golang查询绑定和Binary,B树,内存三种查询算法,妈妈再也不用担心我的ip地址定位!
CVE-2017-7269 回显PoC ,用于远程漏洞检测..
Artificial intelligence-driven Web Firewall
Docker in Docker
Patch iOS Apps, The Easy Way, Without Jailbreak.
Complete Cisco Adaptive Security Appliances shellcode support versions 8.0 through version 8.4 PLEASE USE RESPONSIBLY
Exploits and Security Tools Framework 1.0.3
.git 泄漏利用工具,可还原历史版本
Second Version of The GoBot Botnet, But more advanced.
PACK (Password Analysis and Cracking Kit)
HaboMalHunter is a sub-project of Habo Malware Analysis System (https://habo.qq.com), which can be used for automated malware analysis and security assessment on the Linux system.
Bypass CloudFlare with Ruby
security-101-for-saas-startups 的中文翻译,原仓库 https://github.com/forter/security-101-for-saas-startups
Blind Attacking Framework
httponly下的xss利用
A plugin-based scanner that aids security researchers in identifying issues with several CMSs, mainly Drupal & Silverstripe.
A little word cloud generator in Python
The cheat sheet about Java Deserialization vulnerabilities
阿里聚安全算法挑战赛
超级SQL注入工具 简介: 超级SQL注入工具(SSQLInjection)是一款基于HTTP协议自组包的SQL注入工具,采用C#开发,程序采用自写代码来操作HTTP交互,支持出现在HTTP协议任意位置的SQL注入,支持各种类型的SQL注入,支持HTTPS模式注入;支持以盲注、错误显示、Union注入等方式来获取数据;支持Access/MySQL/SQLServer/Oracle等数据库;支持手动灵活的进行SQL注入绕过,可自定义进行字符替换等绕过注入防护。本工具为渗透测试人员、信息安全工程师等掌握SQL注入技能的人员设计,需要使用人员对SQL注入有一定了解。 工具特点: 1.支持任意地点出现的任意SQL注入 2.支持全自动识别注入标记,也可人工识别注入并标记。 3.支持各种语言环境。大多数注入工具在盲注下,无法获取中文等多字节编码字符内容,本工具可完美解决。 4.支持注入数据发包记录。让你了解程序是如何注入,有助于快速学习和找出注入问题。 5.依靠关键字/时间等进行盲注,可通过HTTP相应状态码判断,还可以通过关键字取反功能,反过来取关键字。 6.程序采用自编码操作HTTP请求,HTTP发包和获取速度较快。
Belle (Burp Suite 非公式日本語化ツール)
Kokkuri
Weaponized web shell
Repository for materials of "Modern fuzzing of C/C++ Projects" workshop.
为各位出色的渗透工程师提供攻击目标。
A Domain Name Collection Tool
LuaJIT FFI bindings for libinjection
SMBMap is a handy SMB enumeration tool
Mobile Security Framework is an intelligent, all-in-one open source mobile application (Android/iOS/Windows) automated pen-testing framework capable of performing static, dynamic analysis and web API testing.
w8ay专属扫描器
Local File Inclusion Exploitation Tool (mirror)
阿里聚安全算法挑战赛 赛题二:《SQL注入检测》
Python Remote Administration Tool (RAT)
netlink inet_diag in rust
:speech_balloon: A better WeChat on macOS and Linux. Built with Electron by Zhongyi Tong.
NodeJsScan is a static security code scanner for Node.js applications.
A collection of Java Deserialization Exploits
Browser Vulnerability Exploit DB(浏览器漏洞PoC数据库)
Content for Udacity's Machine Learning curriculum
A DNS meta-query spider that enumerates DNS records, and subdomains.
简易爬虫代理池
Analysing parameters with all payloads' bypass methods, aiming at benchmarking security solutions like WAF.
Scout Ruby Application Monitoring Agent
A filesystem sandbox for Linux using syscall intercepts.
The FindBugs plugin for security audits of Java web applications and Android applications. (Also work with Scala projects)
golang的扫描框架, 支持协程池和自动调节协程个数.
渗透测试插件化并发框架
w8ay 一句话WEB端管理工具
Dirty COW
A list of useful payloads and bypass for Web Application Security and Pentest/CTF
This code is vulnerable to SQL Injection and having SQLite database. For SQLite database, SQL Injection payloads are different so it is for fun. Just enjoy it \m/
Machine learning driven web application firewall to detect malicious queries with high accuracy.
使用rust开发lkm
Contents for Node.Js Security Course
Detect and prevent crypto malware as it encrypts files
My Thesis dealing with detecting Evolutionary Algorithms for Application-Layer Web Attacks
Automated All-in-One OS command injection and exploitation tool.
A collection of rules and samples to detect Magento malware
waf自动爆破(绕过)工具
The branch of ngx_php7, Track php7 script, opcode, function stack for nginx-module.
Bash autoinstaller (any versions 4) + all patches + syslog module (with real username)
Script to extract malicious payload and decoy document from CVE-2015-1641 exploit documents
x64 Kernel Hooks Detection
linux netfilter下修改网关,劫持404页面
RouterExploit
Popular Pentesting scanner in Python3.5 for SQLi/XSS/LFI/RFI and other Vulns
Designed and Implemented a Web Application Firewall as an Apache module that "sits" in-front of a web server. The WAF is designed to stop malicious requests from known attacks such as SQL Injection, XSS attacks and from unknown attacks by learning the legitimate traffic.
A tool used to check if a CNAME resolves to the scope adress. If the CNAME resolves to a non-scope adress it might be worth checking out if subdomain takeover is possible.
Leaked Mirai Source Code for Research/IoC Development Purposes
A tool to perform various OSINT techniques, aggregate all the raw data, visualise it on a dashboard, and facilitate alerting and monitoring on the data.
A script that monitors and extracts requested URLs and clients connected to the service by exploiting publicly accessible Apache server-status instances.
PAM layer for implementing your own pam library
HTML5 Security Cheatsheet - A collection of HTML5 related XSS attack vectors
Exploring the use of decision trees to detect domain names generated by domain generation algorithms (DGA)
Assets View资产发现、网络拓扑管理系统
Rip web accessible (distributed) version control systems: SVN/GIT/HG...
“六道”实时业务风控系统
Database firewall written in Go
VMI on BitVisor to detect hidden rootkits.
code-searching tool and static analysis - Beta, at construction
Server-side request forgery detector
A fake SSH server that lets everyone in and logs their activity
Linux malware analysis based on Cuckoo Sandbox.
网络安全相关的RSS订阅列表
Service management for Linux (systemd, upstart, sys-v), Darwin (launchd) and Windows. Forked from https://bitbucket.org/kardianos/service/
Cyber security geoip attack map that follows syslog and parses IPs/port numbers to visualize attackers in real time.
Searching sensitive files and contents in GitHub associated to company name or other key words
minicap, minitouch, UIAutomator etc... wraps
OWASP Directory Access scanner
A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.
libinjection PHP wrapper
机器学习资源大全中文版,包括机器学习领域的框架、库以及软件
wiki.wooyun.org的部分快照网页
LeanEngine performance monitoring for Node.js application
Port scanner, written in golang
Tools for auditing WAFS
分布式弱口令扫描
Ransomware Detection and Mitigation Software
F-Scrack is a single file bruteforcer supports multi-protocol
Source code for the Mirai botnet - Not going anywhere anytime soon
A Go library for reading and parsing ELF files
A C# based memory editing library targeting Windows applications, offering various functions to extract and inject data and codes into remote processes to allow interoperability.
Raptor - WAF - Web application firewall using DFA [ Current version ] - Beta
Direct shell in C. Reverse shell in C. Both over TCP.
自动化恶意软件分析
多线程批量扫描ssrf漏洞
C++ learning project to write a dummy PHP AST builder
It's bloody scantastic
基于Docker的蜜罐系统
美国国家安全局NSA下属方程式黑客组织(Equation Group)被The Shadow Brokers(影子经纪人)hack出来的并免费分享的源码
A python web fetcher using phantomjs to mock browser
A python library for genetic algorithms
OWASP Xenotix XSS Exploit Framework is an advanced Cross Site Scripting (XSS) vulnerability detection and exploitation framework.
Tunnel IP over ICMP.
A robust, reliable, easy-configure virtual private network (linux/macOS)
java unserialize vul for weblogic exploit
Libinjection in Java
Light System Examination Toolkit (LISET) - logs & activity & configuration gathering utility that comes handy in fast Windows incident response (either forensic or malware oriented).
NSQ Local and Simple Version
HackingLab定制版Mobile Safe Framework
poc from bugscan beebeeto
linux下实现进程隐藏
Proxy [Finder | Checker | Server]. HTTP(S) & SOCKS
Redis protocol parser in golang
comma.ai for the people to experiment with
Linux v4.x.x Rootkit
Virus scanner (PE classifier) based on rb-libsvm and pedump
A port scanner written in Rust, as an exercise to learn more about Rust! MIT Licensed.
CodeIgniter <=2.1.4 session cookie decryption vulnerability
It's an ezine: DO NOT FUCK WITH A HACKER
各种漏洞poc、Exp的收集或编写
High-interaction MitM SSH honeypot
Just a proof of concept Linux rootkit that reads from syscalls.
Linux honeypot system
Windows Event Forwarding for Active Directory Security Logs
小型主动防御引擎
php
Small C application designed to detect LD_PRELOAD malware via the libdl library functions.
Vulnerability Scanner
go wrapper for libssh (both client and server side)
本地文件包含利用工具
An example of web spider using aiohttp
VisualCodeGrepper - Code security scanning tool.
The Bug Hunters Methodology
基于Twisted实现的智能dns系统
YSOSERIAL Integration with burp suite
在Spark环境下,利用Flask框架,采用Mongodb设计的一个在线电影推荐系统的演示demo
Shell Detector – is a application that helps you find and identify php/cgi(perl)/asp/aspx shells. Shell Detector has a “web shells” signature database that helps to identify “web shell” up to 99%.
Collection of bypass gadgets to extend and wrap ysoserial payloads
基于Go语言的棋牌游戏框架
a web crawler
Proof of concept real time bidding library.
docker 未授权访问漏洞利用脚本
Limon is a sandbox developed as a research project written in python, which automatically collects, analyzes, and reports on the run time indicators of Linux malware. It allows one to inspect Linux malware before execution, during execution, and after execution (post-mortem analysis) by performing static, dynamic and memory analysis using open source tools
Go bindings for dpdk (http://dpdk.org/).
A sample apm system
总结一些渗透中值得关注的默认端口
Duncan - Blind SQL injector skeleton
Pentest tool for antivirus evasion and running arbitrary payload on target Wintel host
Acunetix 0day RCE
A wrapper around a pre-compiled version of the Mimikatz executable for the purpose of anti-virus evasion.
基于LD_PRELOAD的ring3 rootkit
Docker security hole, allow to execute a script on the host from a container.
An automated script that download potential exploit for linux kernel from exploitdb, and compile them automatically
A tool for covert execution in Linux.
Rust bindings for libnetlink
远程控制项目
A tiny Batch weB vulnerability Scanner
Bashistdb saves and retrieves your bash history into a local or remote SQLite database.
Spy - Watches for file changes, restarts stuff
从零开始内网渗透学习
A XSS mind map ;)
Interactive sip toolkit for packet manipulations, sniffing, man in the middle attacks, fuzzing, simulating of dos attacks.
This is a bundle of python and bash penetration testing tools for recon and information gathering.
GO - Minimal parser for .DS_Store files
A simple attack against gcc and Python via kernel module, with highly detailed comments.
Converts the Clamav Virus Database definitions to YARA rules [GOLANG]
Push notifications for passive DNS data
This repository based on Andrej Karpathy char-rnn https://github.com/karpathy/char-rnn. Developed to research the possibility of applying LSTM neural network to detect and classify malicious domains.
awvs python library
Getting started with CLR Profiling API
Python 探针实现原理
A simple Apache module with implementation of LibInjection
A simple kernel-land keylogger
:penguin: A collection of linux kernel modules that harden the kernel
Some ideas around spoofing and detecting user agents.
PHP APM (Alternative PHP Monitor)
BkScanner 分布式、插件化web漏洞扫描器
This is an Internet Behavior Management System.
Beyond APM is a .Net CLR Profiler dedicated to .Net Application Performance Monitor and offering AOP and Tracing capabilities to your code without modification of original source codes
查看被删的微信好友
Script to run wvs in queue, and send mails to you on ending.
A PoC WMI backdoor presented at Black Hat 2015
Control the Windows Firewall from Go, supports Windows XP API and Advanced Security COM API
SQL Parser from https://github.com/youtube/vitess/tree/master/go/vt/sqlparser
A novel SQL injection detection engine built on top of SQL tokenizing and syntax analysis.
Automatic XSS filter bypass
Fast SNMP brute force, enumeration, CISCO config downloader and password cracking script.
Rust library integrated into a PHP extension
A python reverse shell that uses DNS as the c2 channel
LCXL影子系统
Go bindings for libnetfilter_queue
Replay MySQL Traffic
Web Shell Detector – is a php script that helps you find and identify php/cgi(perl)/asp/aspx shells. Web Shell Detector has a “web shells” signature database that helps to identify “web shell” up to 99%.
php扩展开发笔记
Linux user password expiration check
port knocking by otp auth
Nodejs Application Monitor
Linux kernel module netfilter backdoor demo
a MySQL proxy powered by Go
The Byzantine General Problem
Implementation of simple bug prediction hotspot heuristic
Bugscan Web Vulnerability Scaner Online System
浏览器用户全部信息收集js
Attack Community Graphs through Event Clustering
python utilities related to dylib hijacking on OS X
Docker firewall manager
TeamTalk is a solution for enterprise IM
中科大13级计算机病毒分析与WindowsAPI编程 授课老师:郭大侠
Security information and event management, masters's diploma
Linux kernel rootkit using kprobes (From http://phrack.org/issues/67/6.html)
x86_x64 emulator
a dns zone transfer vulnerability scanner
Automatic XSS Reflected Scan
code for kaggle competition Microsoft malware classification
a javascript static security analysis tool
A Python network recon framework, based on Nmap, Bro & p0f with MongoDB backend.
A Rust version of the Weenix OS
A python HTTP weak pass scanner
Golang bindings for libinjection
Web Fuzzer
A static security scanner for PHP
内部函数监控扩展
A scanner named pecker, written in php,It can check dangerous functions with lexical analysis.
Create tar/zip archives that can exploit directory traversal vulnerabilities
Automatically exported from code.google.com/p/mysql-proxy-python
SRCMS(轻响应)企业应急响应中心开发框架模版
A ctf competition program.
Ruby wrapper around Client9's libinjection
Kernel Based Root ToolKit Samples
A series of labs that will help users apply various data science techniques to security related data.
最好的 YAF 入门 DEMO, 看过就会用 !
port scan detection
A tool that can scan php vulnerabilities automatically using static analysis methods
Network Microsegmentation for Docker container deployments
用于扫描git,svn泄露
结合swoole扩展和Yaf框架,使用swoole的内置http_server
A simple interactive Go interpreter built on go-eval with some readline-like refinements
Splunk Web Shell
A simple Zoomeye written by python,more details click this link: http://blog.csdn.net/u011721501/article/details/41967847
Static DOM XSS Scanner is a Static Analysis tool written in python that will iterate through all the JavaScript and HTML files under the given directory and will list out all the possible sources and sinks that may cause DOM XSS. At the end of the scan, the tool will generate an HTML report.
:evergreen_tree: Generate the Abstract Syntax Tree (AST) of a Bash command.
thrift golang unix domain socket
AST parser and inference engine for PowerShell language
Welcome to the XSS Challenge Wiki!
Chrome extension Exploitation Framework
http://x0day.me/archives/bannerscan-py.html
Minimal AXIS2 webshell
CPULimit for multiple processes (limits ALL of them, not just the first)
A Platform for Web Pentest From China
Mysql test sniffer to audit simple queries
Nscan: Fast internet-wide scanner
APM (Alternative PHP Monitor) web frontend
使用PHP+Swoole实现的网页即时聊天工具
Elasticsearch River for NSQ
Smart DLL execution for malware analysis in sandbox systems
Detects DLL hijacking in running processes on Windows systems
A hidden Markov model implementation
Basic implementation of web request filtering under IIS 7.0+; capable of stopping sql injection and file incursion attacks
LFI Scan & Exploit Tool
Vipasyin Webshell detector (golang)
a pure go lsof
Basic MachineLearning algorithm
python native library for network device.
Smart DNS Brute Forcer
a privilege escalation detection and prevention system for GNU/Linux hosts
OpenDPI v.3.10
A UDF library with functions to interact with the operating system. These functions allow you to interact with the execution environment in which MySQL runs.
Linux Hook Detection
webshell writen in python
GetHooks is a program designed for the passive detection and monitoring of hooks from a limited user account.
go bindings to pacman's libalpm
一款支持HMVC、数据库主从分离、多项目的PHP框架
PHP extension for web-application dynamic analysis.
PHP Markup Language
NIDS based around hooking yara into callbacks
A PHP code transformer to provide protection against injection attacks
Fork of Codeword from http://code.google.com/p/codeword/
database firewall
webhandler
Web application security scanner created by lcamtuf for google - Unofficial Mirror
阿里云安全恶意程序检测比赛
exploit for fastjson remote code execution vulnerability
A curated list of awesome resources related to Mitre ATT&CK™ Framework
A framework for identifying and launching exploits against internal network hosts. Works via WebRTC IP enumeration combined with WebSockets and external resource fingerprinting.
根据关键字与 hosts 生成的关键词,利用 github 提供的 api,监控 git 泄漏。
a traefik / nginx companion to create an identity aware proxy like beyondcorp
A js infomation dig tool.
Redis 4.x/5.x RCE
企业级url监控
从零开始研究外挂设计原理
Wappalyzer implementation in Go
Log all none root Linux kernel EXEC calls. pid, uid, host and cmdline are written with rsyslog in JSON format.
python3写的综合扫描工具,主要用来敏感文件探测(目录扫描与js泄露接口),WAF/CDN识别,端口扫描,指纹/服务识别,操作系统识别,弱口令探测,POC扫描,SQL注入,绕过CDN,查询旁站等功能,主要用来甲方自测或乙方授权测试,请勿用来搞破坏。
This repo contains some Amsi Bypass methods i found on different Blog Posts.
本程序旨在为安全应急响应人员对Linux主机排查时提供便利,实现主机侧Checklist的自动全面化检测,根据检测结果自动数据聚合,进行黑客攻击路径溯源。
陌陌风控系统静态规则引擎,零基础简易便捷的配置多种复杂规则,实时高效管控用户异常行为。
An adversarial examples toolbox for constructing attacks, building defenses, and Measuring robustness of AI model
风险控制笔记,适用于互联网企业
DLL Hijacking Detection Tool
https://www.cdxy.me/?p=806
datacon比赛方向三-攻击源与攻击者分析writeup
弱口令,敏感目录,敏感文件等渗透测试常用攻击字典
复现过的AI安全检测的项目集合
深入Go并发编程研讨课
Anomaly detection framework @ PayPal
自己为了方便收集的小工具
m3u8 downloader with golang
Scanner PoC for CVE-2019-0708 RDP RCE vuln
Discuz backend getshell
Celery Distributed Task Queue in Go
MemConn is an in-memory network stack for Go.
linux安全检查
Web application fuzzer
Fast web fuzzer written in Go
🔥 A curated list of awesome web-app firewall (WAF) stuff.
为漏扫动态爬虫定制的浏览器
Easy automated vulnerability scanning, reporting and analysis
🚀 A simple asset discovery engine for cybersecurity. (网络资产发现引擎)
Free Malware Training Datasets for Machine Learning
Fileless Linux Malware Framework
A Linux Auditd rule set mapped to MITRE's Attack Framework
Remote Administration Tool For Windows C# (RAT)
Fast browser-based network discovery module
基于burpsuite headless 的代理式被动扫描系统
The Penetration Testers Framework (PTF) is a way for modular support for up-to-date tools.
一款Go语言实现的端口扫描器.
ARP+DNS欺骗工具,网络安全第三次实验,课堂演示用,严禁非法用途。ARPSpoof,wifi hijack,dns spoof
ReSwitched's work-in-progress launcher for one of the Tegra X1 bootROM exploits(switch root)
A simple fast, easy use distributed file system written by golang.
A simple fast, easy use distributed file system written by golang(similar fastdfs).go-fastdfs 是一个简单的分布式文件存储,具有高性能,高可靠,免维护等优点,支持断点续传,分块上传,小文件合并,自动同步,自动修复。
30 Days of Vue
基于Golang开发的企业级外网端口资产扫描
代码审计入坑
Brings SQL and AI together.
LINUX集群控制(LINUX反弹式远控) LINUX反向链接运维 BY:QQ:879301117
乌云tangscan扫描器插件
Tentacle is a POC vulnerability verification and exploit framework. It supports free extension of exploits and uses POC scripts. It supports calls to zooeyem, fofa, shodan and other APIs to perform bulk vulnerability verification for multiple targets.
List of Awesome Advanced Windows Exploitation References
go-querystring is Go library for encoding structs into URL query parameters.
This script will create a POC that will steal NTML hashes from a remote computer. Do not use this for illegal purposes.The author does not keep responsibility for any illegal action you do.
Work with Windows containers and LCOW on Mac/Linux/Windows
🕹️ A basic gameboy emulator with terminal "Cloud Gaming" support
Linux Basics for Hackers
WEB指纹识别 - gowap基础上修改的golang版本
御剑RDP爆破工具
Interactive Network Scanner
A keygen for Navicat
PHP function tracker
Log newly created WMI consumers and processes to the Windows Application event log
SQLi scanner to detect SQL vulns
安卓内核提权漏洞分析
Cobalt Strike系列
vulscan 扫描系统:最新的poc&exp漏洞扫描,redis未授权、敏感文件、java反序列化、tomcat命令执行及各种未授权扫描等...
mysql注入,bypass的一些心得
A terminal UI for tshark, inspired by Wireshark
Multi-platform agent written in Golang. TCP forwarding, socks5, tunneling, pivoting, shell, download, exec
UAC bypass techniques implemented and written in Go
驱动层拦截web访问源码
[Linux] Two Privilege Escalation techniques abusing sudo token
Gogs CVEs
Keyboard Weak Password
uilive is a go library for updating terminal output in realtime
dump mysql client password from memory
A collection of awesome penetration testing resources, tools and other shiny things
Standalone Executable to Check for Simple Privilege Escalation Vectors on Windows Systems
PowerShell based Active Directory Honey User Account Management with Universal Dashboards
Snort rules
ics security tools
Chinese-specific configuration to improve your favorite DNS server. Best partner for chnroutes.
此项目用来提取收集以往泄露的密码中符合条件的强弱密码
Webshell Detection Based on Deep Learning
Capture packet by process info in Windows System
一款基于机器学习的Web日志统计分析与异常检测命令行工具
人人都能用英语
Selenium/Webdriver client for Go
grep rough audit - source code auditing tool
sniffer http data by go
堡垒机-麒麟堡垒机,集堡垒机、SSLVPN-堡垒机内置、动态口令-堡垒机内置、应用审计-堡垒机内置、数据库审计-堡垒机内置、CA证书-堡垒机内置-堡垒机内置、云桌面-堡垒机内置、密码自动修改为一体的堡垒机系统
A powerful target reconnaissance framework powered by graph theory.
Beagle is an incident response and digital forensics tool which transforms security logs and data into graphs.
Run PowerShell with rundll32. Bypass software restrictions.
The perfect emulation setup to study and modify the Linux kernel, kernel modules, QEMU and gem5. Highly automated. Thoroughly documented. GDB step debug and KGDB just work. Automated tests. Powered by Buildroot. "Tested" in Ubuntu 18.04 host, x86_64, ARMv7 and ARMv8 guests with kernel v5.0.
SharPyShell - tiny and obfuscated ASP.NET webshell for C# web applications
小型网络空间搜索引擎
SIP-Based Audit and Attack Tool
Web版中国菜刀
python3写的一个小工具,主要用于端口扫描,服务识别。
Boilerplate C2 written in Go for red teams
Sublert is a security and reconnaissance tool which leverages certificate transparency to automatically monitor new subdomains deployed by specific organizations and issued TLS/SSL certificate.
甲方安全工程师必备,内部钓鱼系统
XRay is a tool for recon, mapping and OSINT gathering from public networks.
参考《利用分块传输吊打所有WAF》修改的requests的Adapter
MySQL实时监控工具(黑盒测试辅助工具)
一个关于人工智能渗透测试分析系列
QAQ Just study unserialize vulnerabilities in Java :)
Responsive dashboard templates for Bootstrap 📊✨
Modern phishing tool with advanced functionality [ Termux-Support Available ]
Ethereum Virtual Machine (EVM) disassembler and assembler
ICMP ping library for Go inspired by AnyEvent::FastPing Perl module
This is repo of antivirus which uses machine learning to classify viruses from legitimate files.
awesome-linux-rootkits
Windows 10 and Server 2016 Secure Baseline Group Policy
VulDeePecker: A Deep Learning-Based System for Vulnerability Detection
红队基础设施自动化部署工具
Configuration guidance for implementing Pass-the-Hash mitigations. #nsacyber
Reflective DLL injection is a library injection technique in which the concept of reflective programming is employed to perform the loading of a library from memory into a host process.
Easy files and payloads delivery over DNS
Golang IPv6 address enumeration
个人准备渗透测试和安全面试的经验,和部分厂商的面试题
Reconnecting Websocket Client Golang Library
Nmap Web Dashboard and Reporting
分析web访问日志以及web目录文件属性,用于根据查找可疑后门文件的相关脚本。
Anti Cheat i made in my free time. Credits to everyone who helped are in the files and some are in the code. I will definitely improve this Anti Cheat along the way, now its just beta. Enjoy.
Shared Blogs and Notebooks
Common library for Go GUI apps on Windows
Venom - A Multi-hop Proxy for Penetration Testers Written in Go
netlink connector library for Go
一个专门用于开发安全工具的HTTP类库.
Constrained Language Mode + AMSI bypass all in one
low level netlink library for rust
Malware sample library.
PIOF - PHP Instrumentation Open Framework - A dynamic and modulable instrumentation framework for PHP language.
trace exec() calls system-wide
Security with Go, published by Packt
How to Zeek Sysmon Logs!
Falco: Container Native Runtime Security
Jenkins RCE PoC. From unauthenticated user to remote code execution - it's a hacker's dream! (Chaining CVE-2019-1003000, CVE-2018-1999002, and more)
Stealthy DDE Exploit Payload generator and injector for DOCX files
ZGrab 2.0 Framework
Chashell is a Go reverse shell that communicates over DNS. It can be used to bypass firewalls or tightly restricted networks.
Package to create apps with GO, HTML and CSS. golang gui
Powershell Threat Hunting Module
Package pe implements access to the Portable Executable (PE) file format.
k-modes and k-prototypes clustering algorithms implementation in Go
致力于将李航博士《统计学习方法》一书中所有算法实现一遍
自身学习的安全数据科学和ai安全算法的学习资料
从shodan获取使用了相同favicon.ico的网站
javaweb-codereview
An evolving how-to guide for securing a Linux server.
Full port of LIBSVM in the Go programming language
154个英雄联盟中的英雄和中立生物的3D模型(带动画)演示。https://tengge1.github.io/lol-model-viewer
:notebook_with_decorative_cover: 在学院的书架上发现了一本不带脑子就能看懂的书《Python数据挖掘与实战》
一个基于docker的安全培训系统
《Mastering GO》中文译本,暂时命名为《玩转 GO》。阅读本书之前,您应该阅读有关Go的介绍性书籍,或者已经完成了Go By Example。本书的内容包括但不限于并发、网络编程、垃圾回收、组合、GO UNIX系统编程、基本数据类型(Array,Slice,Map)、GO源码、反射,接口,类型方法等高级概念。阅读本书需要一定的编程经验。如果你在工作中使用Go或者业余时间爱好GO,那么这本书一定会让你对GO的理解更上一层楼。
Linux kernel HTTP filtering netfilter module
Open Source Threat Intelligence Chat Bot
The request.bin of DNS request
分布式WEB指纹识别平台 Distributed WEB fingerprint identification platform
kunpeng是一个Golang编写的开源POC检测框架,以动态链接库的形式提供各种语言调用,通过此项目可快速对目标进行安全漏洞检测,比攻击者快一步发现风险漏洞。
bindings for libcgroup
2018年初整理的一些内网渗透TIPS,后面更新的慢,所以公开出来希望跟小伙伴们一起更新维护~
Channel-based CPU usage limiter
My BBScan rules
RedTeam资料收集整理
SpoolSample -> Responder w/NetNTLM Downgrade -> NetNTLMv1 -> NTLM -> Kerberos Silver Ticket
scanproxy is auto scan IP & port,and check that is proxy if port is open...(scanproxy是一个自动扫描端口,并且检测是否是代理服务器的程序)
A tcp syn flood attack tool
This is a collection of social engineering tricks and payloads being used for credential theft and spear phishing attacks.
100-Days-Of-ML-Code中文版
MITRE’s Adversarial Tactics, Techniques, and Common Knowledge (ATT&CK)
convert sql to elasticsearch DSL in golang(go)
Elasticsearch 可视化DashBoard, 支持Es监控、实时搜索,Index template快捷替换修改,索引列表信息查看, SQL converts to DSL等
DGA Domains detection
web日志分析工具
Load shellcode into a new process
javascript function hook
Basic Machine Learning and Deep Learning
个人学习
Pure Python parser for recent Windows Event Log files (.evtx)
An industrial deep learning framework for high-dimension sparse data
My AI security testing project
DarthSidious 中文版
PowerShell Runspace Post Exploitation Toolkit
Windows 8.1 and 10 UAC bypass abusing WinSxS in "dccw.exe".
Dzscan
IsolationForest wiht Sk-learn
Antivirus Killer
Github信息泄漏监控系统
Keylogger written in C#
:book: [译] SploitFun Linux x86 Exploit 开发系列教程
404notfound的知识体系
Responder is a LLMNR, NBT-NS and MDNS poisoner, with built-in HTTP/SMB/MSSQL/FTP/LDAP rogue authentication server supporting NTLMv1/NTLMv2/LMv2, Extended Security NTLMSSP and Basic HTTP authentication.
Sample DGA classifier
A tool to find subdomains and interesting things hidden inside and external Javascript files of page.
😮😮秒杀系统设计与实现.互联网工程师进阶与分析🙋🐓
bits of sklearn ported to Go #golang
exp of CVE-2018-15982
PLEASE USE NEW VERSION: https://github.com/kgretzky/evilginx2
大安全各领域各公司各会议分享的PPT及行业合规、安全认证、安全书籍汇总
一些阅读源码和Fuzzing 的经验..
数据库和其他服务的弱端口的弱口令检测以及未授权访问的集成检测工具。 Weak password blasting of weak ports and integrated detection tools for unauthorized access.
Perform a MitM attack and extract clear text credentials from RDP connections
C# Clipboard Monitor
私有区块链
ml webshellgg project
This Repository contains the stuff related to windows Active directory environment exploitation
Vba2Graph - Generate call graphs from VBA code, for easier analysis of malicious documents.
WebBorer is a directory-enumeration tool written in Go.
Active Directory ACL exploitation with BloodHound
linikatz is a tool to attack AD on UNIX
🤖 Geetest3 Distributed Cracking Platform 极验3代分布式破解平台
API samples for the Universal Windows Platform.
A Splunk app mapped to MITRE ATT&CK to guide your threat hunts
Github Desktop PoC
The Simplest Way to Manage Your Entire Dev Infrastructure!
openzaly 是 Akaxin 的服务器源代码,用以搭建私有聊天服务器。 服务器安装教程:https://www.akaxin.com/docs/install/index.html QQ群: 655249600
a mini tool to dump password and NTLM hash from WDigest & MSV1_0 & tspkg, as a result of study of mimikatz
Small and highly portable detection tests based on MITRE's ATT&CK.
Generates Malicious Macro and Execute Powershell or Shellcode via MSBuild Application Whitelisting Bypass.
Malicious Macro Generator
Kernel-Mode Rootkit Hunter
GTRS - Google Translator Reverse Shell
Click Security Data Hacking Project
微信电脑客户端多开工具,支持防消息撤销
Python implementation of RSA reverse shell.
go windows 库,主要实现 "golang.org/x/sys/windows" 库未包含的api。
Next generation web scanner
Potentially dangerous files
An XSS reverse shell framework
Encoded Reverse Shell Generator With Techniques To Bypass AV's
Trace system calls from Docker containers running on the system
Host-based Intrusion Detection System for Linux Containers
Artifact analysis tools by JPCERT/CC Analysis Center
SecurityManageFramwork是一款适用于企业内网安全管理平台,包含资产管理,漏洞管理,账号管理,知识库管、安全扫描自动化功能模块,可用于企业内部的安全管理。 本平台旨在帮助安全人员少,业务线繁杂,周期巡检困难,自动化程度低的甲方,更好的实现企业内部的安全管理。
PDNS Monitors network for malicious activities domain
These are the vulnerabilities discovered by Galaxy Lab.
A collection of awesome web crawler,spider in different languages
Detect kerberos attacks in pcap files
Post module for Metasploit to execute ELF in memory
A free, powerful, multi-purpose tool that helps you monitor system resources, debug software and detect malware.
Library for creating interactive cli applications.
安全场景、基于AI的安全算法和安全数据分析学习资料整理
collection poc use pocsuite framework 收集一些 poc with pocsuite框架
提供微信终端版本、微信命令行版本聊天功能、微信机器人
🦉SOAP package for Go
Machine Learning for Go
This repo records all the vulnerabilities of linux software I have reproduced in my local workspace
Active Directory Security For Red & Blue Team
中文暗网爬虫
基于DPoS算法、P2P对等网络的简易区块链Go语言实现。
Repo with various Red Team scripts
Dump TeamViewer ID and password from memory. Works much better than other tools.
CACTUSTORCH: Payload Generation for Adversary Simulations
The python client of passivedns.cn
List of Awesome Red Teaming Resources
Sreg可对使用者通过输入email、phone、username的返回用户注册的所有互联网护照信息。
Jieba 分词 Go 语言版
:kissing_closed_eyes::kissing_closed_eyes: 通过与女朋友聊天获取她的实时情绪波动图谱。 Analyze her mood through her girlfriend's words ·
Snyk Node Runtime Agent
Ethereum Smart Contracts Security CheckList From Knownsec 404 Team
htcap is a web application scanner able to crawl single page application (SPA) in a recursive manner by intercepting ajax calls and DOM changes.
:snowflake: PcapXray - A Network Forensics Tool - To visualize a Packet Capture offline as a Network Diagram including device identification, highlight important communication and file extraction
USB键盘流量包取证工具 , 用于恢复用户的击键信息
weblogic 漏洞扫描工具
A Pwn2Own exploit chain
A quick and dirty .NET "Deserialize_*" fuzzer based on James Forshaw's (@tiraniddo) DotNetToJScript.
BlockChain-Security-List
Inject a .NET assembly into a native process using the CLR Hosting API
MITRE ATT&CK Windows Logging Cheat Sheets
A simple HTTP message queue written in Go with goleveldb, just like httpsqs written in C with Tokyo Cabinet.
Write PHP extension using go/golang. Zend API wrapper for go/golang.
LevelDB key/value database in Go.
A Powershell client for dnscat2, an encrypted DNS command and control tool.
Run executables from memory, over the network, on Windows, Linux, OpenVMS... routers... spaceships... toasters etc.
Executes PowerShell from an unmanaged process
an asynchronous target enumeration tool
The high-scalability sFlow/NetFlow/IPFIX collector used internally at Cloudflare.
Fuzzing Browsers
A Linux version of the ProcDump Sysinternals tool
Automatic reversed shell detacting and defensing
Sandbox to execute php or bash code
Command line monitoring for goroutines
Decision tree in Go based on @random-forests example
Multi-platform Nintendo Game Boy Color emulator written in go
A collection of resources for linux reverse engineering
CobaltStrike 2.5中文汉化版
pure Go implementation of prediction part for GBRT (Gradient Boosting Regression Trees) models from popular frameworks
Transparent SSL/TLS interception
Automates credential skimming from service accounts in Windows Registry
Anomaly detection in Go with isolation forests.
Pure Python implementation of machine learning algorithms
Visualizing malware behavior, and proactive protection using GANs against zero-day attacks.
Golang hardware discovery/inspection library
:mailbox: The Phishing Intelligence Engine - An Active Defense PowerShell Framework for Phishing Defense with Office 365
Decensoring Hentai with Deep Neural Networks
The world's simplest facial recognition api for Python and the command line
Face recognition with deep neural networks.
基于 SeetaFace 的人脸识别服务, By and For Golang
Automated Mass Exploiter
A POC Windows crypto-ransomware (Academic)
A terminal based graphical activity monitor inspired by gtop and vtop
A simple Blockchain implementation in Go
:innocent: A Powershell exploit, windows native service with no virus signature that open a reverse http connection via meterpreter
A little bit about a linux kernel
a tool to facilitate sharing of secrets using SSH keys
Source code about machine learning and security.
SAIVS (Spider Artificial Intelligence Vulnerability Scanner).
A practical guide to securing macOS.
Reverse Shell as a Service
:hammer: A modern multiple reverse shell sessions manager written in go
Code search and intelligence, self-hosted and scalable
FUSE library for Go. go get bazil.org/fuse
Full exploit of CVE-2016-6754(BadKernel) and slide of SyScan360 2016
Encrypted overlay filesystem written in Go.
A .NET library to subscribe for Windows operating system global user actions such mouse, keyboard, clipboard & print events
This project contains pocs and exploits for android vulneribilities
Graceful process restarts in Go
这是一个实验性的PHP扩展,加载这个扩展后,每次请求将可以执行一段自己的PHP代码。
提供可视化界面的任务调度工具
Linux Exploit Development Techniques
Spawn to shell without any credentials by using CVE-2018-10933
Predicting malicious behaviour in programs by studying patterns of API Call graphs
A curated list of tools for incident response
LiME (formerly DMD) is a Loadable Kernel Module (LKM), which allows the acquisition of volatile memory from Linux and Linux-based devices, such as those powered by Android. The tool supports acquiring memory either to the file system of the device or over the network. LiME is unique in that it is the first tool that allows full memory captures from Android devices. It also minimizes its interaction between user and kernel space processes during acquisition, which allows it to produce memory captures that are more forensically sound than those of other tools designed for Linux memory acquisition.
Ssdt Hook Detection tool
逆向小红伞杀毒软件驱动——avdevprot
windows syscall table from xp ~ 10 rs4
Automatic SSRF fuzzer and exploitation tool
Windows核心编程(第5版中文版)
A function hooking library for the Rust programming language
`go-hook`provides low level keyboard and mouse hook for Windows.
x86 WinAPI hook written in pure Go
Auto Root Exploit Tool
A (partial) Python rewriting of PowerSploit's PowerView
Windows DPAPI laboratory
Python library using ctypes to search/edit windows / linux / macOS / SunOS programs memory
Credentials recovery project
🔎Sniffing and parsing mysql,redis,http,mongodb etc protocol. 抓包截取项目中的数据库请求并解析成相应的语句。
Proof of Concept of Winbox Critical Vulnerability (CVE-2018-14847)
Impacket is a collection of Python classes for working with network protocols.
Powershell攻击指南----黑客后渗透之道
multiOTP Credential Provider is a V2 Credential Provider for Windows 7/8/8.1/10/2012(R2)/2016 with options like RDP only and UPN name support
第三届阿里云安全算法挑战赛冠军代码
A reverse PTY shell in C
Recursively exploit path traversal vulnerability
Secure ELF parsing/loading library for forensics reconstruction of malware, and robust reverse engineering tools
Be able to execute memory snapshots so they can start running where they left off.
anti virus 32bit. my first attempt (in 2008) to write prototype for detecting/disinfecting unix ELF viruses
An utility like pkg-audit for Arch Linux. Based on Arch Security Team data
Docker containers vulnerability scan
External pentest tool that performs subdomain enumeration through various techniques. In addition, SubScraper will provide information such as HTTP & DNS lookups to aid in potential next steps.
Aron is a GO script for finding hidden GET & POST parameters
Anti-ransomware in linux, Decoy, Protect file, Protect drectory, Auto backup
A curated list of awesome forensic analysis tools and resources
Burp plugin to decrypt AES Encrypted traffic of mobile apps on fly
An Open-Source Pre and Post Callback-Based Framework for macOS Kernel Monitoring.
A forensic evidence collection & analysis toolkit for OS X
来自Freebuf评论区,一个UEFI马.
Rekall is an endpoint security solution.
Rekall Memory Forensic Framework
rVMI - A New Paradigm For Full System Analysis
Wouldn't the world be better with more iptables wrappers? WIP
Network capture utility designed specifically for DNS traffic
Lynis - Security auditing tool for Linux, macOS, and UNIX-based systems. Assists with compliance testing (HIPAA/ISO27001/PCI DSS) and system hardening. Agentless, and installation optional.
Distributed alerting for the masses!
NodeXP - A Server Side Javascript Injection tool capable of detecting and exploiting Node.js vulnerabilities
Experimental tool for ROP-shellcode detection
RopGun is a Linux implementation of a transparent ROP mitigation technique based on runtime detection of abnormal control transfers using hardware performance counters.
大数据威胁态势感知,图标实时展示攻击状态
A simple Rust wrapper around LibVMI for virtual machine introspection (very incomplete)
Teleport is a versatile, high-performance and flexible socket framework. It can be used for RPC, micro services, peer-peer, push services, game services and so on.
Log malicious IP security analysis
A framework for stealthy domain reconnaissance
Zero-cost asynchronous programming in Rust
An OSINT tool that discovers sub-domains by searching Certificate Transparency logs
Disk encryption with strong security based on TrueCrypt
The Windows Library for Intel Process Trace (WinIPT) is a project that leverages the new Intel Processor Trace functionality exposed by Windows 10 Redstone 5 (1809), through a set of libraries and a command-line tool.
From IoT Pentesting to IoT Security
CloudWalker Platform
pam_abl auto blacklisting PAM module
audit installed packages on Arch Linux against known vulnerabilities
Golang wrappers for glibc crypt(3)
Duo two-factor authentication for Unix systems
Foreign LINUX - Run unmodified Linux applications inside Windows.
Shellz is a small utility to keep track of your SSH identities, servers and run commands on multiple machines at once.
Privilege guard blocks common local privilege escalation in Linux Kernel
Linux 内核VMA-UAF 提权漏洞(CVE-2018-17182),0day
Lightweight rootkit implemented by bash shell scripts v0.10
Rust bindings for netlink communication
A process monitoring library for rust
Golang netlink implementation
The original sources of MS-DOS 1.25 and 2.0, for reference purposes
ZeroAccess v3 toolkit
一个Web版的docker管理程序,可以用来运行各种docker漏洞环境和CTF环境。
BYOB (Build Your Own Botnet)
A UI library by WeChat official design team, includes the most useful widgets/modules.
Powershell-based Windows Security Auditing Toolbox
OpenVAS remote network security scanner
Linux 内核揭密
一款插件化的密码爆破框架
Open source version of Google Authenticator (except the Android app)
Moloch is an open source, large scale, full packet capturing, indexing, and database system.
SocialBox is a Bruteforce Attack Framework [ Facebook , Gmail , Instagram ,Twitter ] , Coded By Belahsan Ouerghi
mirrored from https://cr.deepin.io/#/admin/projects/go-lib
Various C# projects for offensive security
Polymorph is a real-time network packet manipulation framework with support for almost all existing protocols
Framework for running BPF programs with rules on Linux as a daemon. Container aware.
Aurora Remote Administration Tool
一个用于加密传输爆破的Burp Suite插件
Cross platform security detection tool
目标tcp端口快速扫描、banner识别、cdn检测
Very powerful server agent for collecting & sending logs & metrics with an easy-to-use web console.
This repository will be updated with all the examples and links that I can find with relevant knowledge & information about CP in MS Windows vista up to version 10.
An example implementation of a windows credential provider that is tightly connected with logon system
A Windows Credential Provider written in C#
pGina: Open Source Windows Authentication
Software & Patch management for Mac OS X
an osquery fleet manager
An information security preparedness tool to do adversarial simulation.
PoC code for crashing windows active directory
Ethereum smart contract reverse engineering
Central Application Tracking
A port-knocking daemon
一个能够 Hook 绝大多数函数/类、部分 opcode 的 PHP7 扩展
uber's ssh certificate pam module
This repo contains driver samples prepared for use with Microsoft Visual Studio and the Windows Driver Kit (WDK). It contains both Universal Windows Driver and desktop-only driver samples.
pefile is a Python module to read and work with PE (Portable Executable) files
威胁情报,恶意样本分析,开源Malware代码收集
Fast HTTP parser
一款简易的插件化的漏洞扫描器框架
Go bindings to systemd socket activation, journal, D-Bus, and unit files
Detect x86 shellcode in files and traffic.
Cisco IOS SNMP RCE PoC
Lilith, The Open Source C++ Remote Administration Tool (RAT)
A PowerShell example of the Windows zero day priv esc
a SQL Database on Blockchain
http request/response parser for c
分享在建设安全管理体系、ISO27001、等级保护、安全评审过程中的点点滴滴
各大平台提权工具
Unofficial MaxMind GeoIP2 Reader for Go
Rhino Security Labs' AWS penetration testing toolkit
Drltrace is a library calls tracer for Windows and Linux applications.
Oriana is a threat hunting tool that leverages a subset of Windows events to build relationships, calculate totals and run analytics. The results are presented in a Web layer to help defenders identify outliers and suspicious behavior on corporate environments.
:hammer: A multiple reverse shell session/client manager via terminal
Generate OpenConnect CSD files to bypass Cisco AnyConnect hostscan requirements
Server Side Request Forgery services enumeration tool.
Containing Self Made Perl Reproducers / PoC Codes
A list of ReDoS vulnerabilities in npm modules found by the Software Lab at TU Darmstadt. For each vulnerability, there is a proof-of-concept exploit, showing how the slowdown may occur. The resources in this repository are provided for research purpose only. Please read below for more details.
A script to mine email addresses in the Github repository.
Cowrie SSH/Telnet Honeypot
Collection of scripts that aid in penetration testing of JSON Web Tokens
Baseline Security Configuration For MacOS
SSDEEP hash lib in Golang
Oops, It's funny to detect a webshell
A curated list of Rust code and resources.
Replacement for bytes.Buffer that you can use in a performace-sensitive parts or your Go programs
[beta] Guardian Agent: secure ssh-agent forwarding for Mosh and SSH
EGESPLOIT is a golang library for malware development
GoldenEye Layer 7 (KeepAlive+NoCache) DoS Test Tool
The Prometheus monitoring system and time series database.
A Windows API wrapper package for the Go Programming Language
Libnids is an implementation of an E-component of Network Intrusion Detection System. It emulates the IP stack of Linux 2.0.x. Libnids offers IP defragmentation, TCP stream assembly and TCP port scan detection.
Linux Privilege Escalation Tool By WazeHell
WMI for Go
基于opencanary的蜜罐web服务端|The Web App of opencanary secondary development
Go module to monitor TCP connections using linux's ip_conntrack kernel module
This is a collection of #botnet source codes, unorganized. For EDUCATIONAL PURPOSES ONLY
Cross-platform Yara scanner written in Go
Zabbix vulnerability assessment plugin
Collect autorun records from running system
Grumpy is a Python to Go source code transcompiler and runtime.
An Bash&Python Script For Generating Payloads that Bypasses All Antivirus so far [FUD]
Linux Exploit Suggester; based on operating system release number
In-Depth DNS Enumeration written in Go
A repository for using osquery for incident detection and response
Sysmon configuration file template with default high-quality event tracing
:zap: 百度网盘不限速下载器 BND,支持 Windows、Mac 和 Linux。
Easy parallel execution of commands with live feedback
Public rules and samples for various automations through LimaCharlie.io
Hidden Markov Models in Python, with scikit-learn like API
一个 Git 源码泄露利用工具 , 可恢复整个 Git 仓库 , 用于白盒审计以及分析开发者的思维
Machine Learning Based Botnet Detection is a tool to classify network traffic as being botnet affected or not based on the network traffic flows. It involves various classifiers including Neural Networks, Decision Tree, SVM, Naive Bayes, Logistic Regression, k-Nearest Neighbours.
Rdp client on pure GoLang
安全开发教学 - 用Docker制作一个高交互ssh蜜罐
Information Gathering tool for a Website or IP address
Arduino Rubber Ducky Framework
advanced network reconnaissance toolkit
Imaginary C2 is a python tool which aims to help in the behavioral (network) analysis of malware. Imaginary C2 hosts a HTTP server which captures HTTP requests towards selectively chosen domains/IPs. Additionally, the tool aims to make it easy to replay captured Command-and-Control responses/served payloads.
PowerShell Obfuscation Detection Framework
A curated list of awesome threat detection and hunting resources
Database encryption proxy for data-driven apps: strong selective encryption, SQL injections prevention, intrusion detection, honeypots.
BSM based intrusion detection system
Using LibVMI to detect malware
A free, powerful, multi-purpose tool that helps you monitor system resources, debug software and detect malware—mirror of https://github.com/processhacker2/processhacker.git
An open-source antivirus for windows
Windows API tracer for malware (oldname: unitracer)
PyAna - Analyzing the Windows shellcode
Rust bindings for the unicorn CPU emulator
KicomAV is an open source (GPL v2) antivirus engine designed for detecting malware and disinfecting it.
Capturing, analysing and responding to cyber attacks
Unicorn is a simple tool for using a PowerShell downgrade attack and inject shellcode straight into memory. Based on Matthew Graeber's powershell attacks and the powershell bypass technique presented by David Kennedy (TrustedSec) and Josh Kelly at Defcon 18.
:vertical_traffic_light:Web Application Firewall or API Gateway(应用防火墙/API网关)
Go Evtx sigNature Engine
NetRipper - Smart traffic sniffing for penetration testers
A simple C++ interpreter written in JavaScript
ueditor .net getshell
Web App Monitor
Win32 API bindings for the Go programming language.
Bindings for WinDivert in Go
This repository is a demonstration of the functionalities of kubernetes network policies together with egress network policy (open vSwitch).
container crash reporting + security and reliability countermeasures
Distributed & real time digital forensics at the speed of the cloud
a logging package for golang similar to log4j or log4c++ supporting console, file and network.
Privilege Escalation Project - Windows / Linux / Mac
The Docker Bench for Security is a script that checks for dozens of common best-practices around deploying Docker containers in production.
Security Scanning Utility for Twistlock and Nexus IQ for use in Codefresh Builds
Currently not updated for WMIEvent module...
A module for managing checks and fixes for the 'dirty cow' kernel bug
Lightweight Endpoint Detection & Response (EDR) Framework
Connection pool for Go's net.Conn interface
Suricata and Snort IDS rule and pcap testing system
Iptables Essentials: Common Firewall Rules and Commands.
ONAP vFirewall Use Case
Butterfly connects Virtual Machines and control their traffic flow
Cloud-Native Firewall Virtual Network Function
A platform for developing cloud-native VNFs
A virtual intrusion prevention system to detect and prevent DDoS/DoS attacks. Provides Firewall Options too.
译文:Puppeteer 与 Chrome Headless —— 从入门到爬虫
proxy-web是用go语言写的,基于snail007/goproxy完成的可视化网页应用
A flexible tool for redirecting a given program's TCP traffic to SOCKS5 proxy.
GopherLua: VM and compiler for Lua in Go
🔍 gowitness - a golang, web screenshot utility using Chrome Headless
Port knocking in go
Charles 破解工具
AntiVirus Evasion Tool
An extension for BurpSuite that highlights SSO messages in Burp's proxy window..
A fork and successor of the Sulley Fuzzing Framework
A toy JVM written in Go
A tool to abuse Exchange services
Hawkeye filesystem analysis tool
This tool generates gopher link for doing SSRF and RCE in various servers
Structured, pluggable logging for Go.
This is a library dedicated to adversarial machine learning. Its purpose is to allow rapid crafting and analysis of attacks and defense methods for machine learning models. The Adversarial Robustness Toolbox provides an implementation for many state-of-the-art methods for attacking and defending classifiers. https://developer.ibm.com/code/open/projects/adversarial-robustness-toolbox/
DejaVU - Open Source Deception Framework
Cloud Security Suite - One stop tool for auditing the security posture of AWS & GCP infrastructure.
ANWI - All New Wireless IDS
PowerUpSQL: A PowerShell Toolkit for Attacking SQL Server
a CLI for ephemeral penetration testing
OWASP dependency-check is a software composition analysis utility that detects publicly disclosed vulnerabilities in application dependencies.
使用arima_lstm完成容量分析预测(cpu、内存、磁盘)
SMB MiTM tool with a focus on attacking clients through file content swapping, lnk swapping, as well as compromising any data passed over the wire in cleartext.
通过脉脉用户猜测企业邮箱
I will publish some Linux kernel exploits for various real world kernel vulnerabilities here. the samples are uploaded for education purposes for red and blue teams.
A lightweight flow-control library providing high-available protection and monitoring (高可用防护的流量管理框架)
A tool mainly to erase specified records from Windows event logs, with additional functionalities.
GO Simple Tunnel - a simple tunnel written in golang
A virtual host scanner that performs reverse lookups, can be used with pivot tools, detect catch-all scenarios, aliases and dynamic default pages.
Run-time trojan attack on neural networks
漏洞利用框架模块分享仓库
p2p tunnel,(udp mode work with kcp,https://github.com/skywind3000/kcp)
A zero trust swiss army knife for working with X509, OAuth, JWT, OATH OTP, etc.
The offensive web application penetration testing framework.
Python client for Firefox Send
Six Degrees of Domain Admin
WEB渗透测试数据库
100 Days of ML Coding
wide range mass audit toolkit
ndpi-netfilter
port of mimipenguin.sh in python with some additional protection features
A high performance offensive security tool for reconnaissance and vulnerability scanning
HTTP Botnet Project
swap_digger is a tool used to automate Linux swap analysis during post-exploitation or forensics. It automates swap extraction and searches for Linux user credentials, web forms credentials, web forms emails, http basic authentication, Wifi SSID and keys, etc.
Social Engineering Tool
A Commander for modern Go CLI interactions
Real Intelligence Threat Analytics
Bruteforce HTTP Authentication
An authoritative list of awesome devsecops tools with the help from community experiments and contributions.
A mini webserver with FTP support for XXE payloads
OSINT Organization Employee Profiling Tool for MaiMai
A cross platform http sniffer with a web UI
An evil RAT (Remote Administration Tool) for macOS / OS X.
ph0neutria is a malware zoo builder that sources samples straight from the wild. Everything is stored in Viper for ease of access and manageability.
Distributed filesystem scanner
IPv4 and IPv6 userland network stack
A tool to list and diagnose Go processes currently running on your system
Janusec Application Gateway, an application security solutions which provides WAF (Web Application Firewall), unified web administration portal, private key protection, web routing and scalable load balancing.
Red-team tool to hook libc read syscall with a buffer overflow vulnerability.
A fast utility for scanning tcp ports on servers
Zero-copy sockets for Linux in Golang
go-sysinfo is a library for collecting system information.
Official Go client library for Elasticsearch
go-libaudit is a library for communicating with the Linux Audit Framework.
go-windows provides Go wrappers for Windows APIs.
experimental support for firewall controls for MIG. unused & unsupported.
Rust bindings to libiptc
libiptc bindings for Go language. Object-oriented design, supports IPv6 and same wait locking mechanism as iptables/ip6tables.
Bindings for some functions of libiptc
在线cms识别|旁站|c段|信息泄露|工控|系统|物联网安全|cms漏洞扫描|端口扫描|待续..
Find web directories without bruteforce
erlang software defined perimeter
A blazing fast and lightweight C asymmetric coroutine library 💎 ⛅🚀⛅🌞
A place to store my toy linux-security modules.
Linux Rootkits (4.x Kernel)
Tool Information Gathering Write By Python.
Blackowl is a simple tool to gather information, based on Operative-Framework
Automate SSH communication with firewalls, switches, etc.
常用系统服务默认端口列表
CVE-2018-2894 WebLogic 未授权访问致任意文件上传/RCE漏洞检查脚本
A TCP SYN flood client written in Rust, powered by libpnet
Package raw enables reading and writing data at the device driver level for a network interface. MIT Licensed.
Package alg provides access to Linux AF_ALG sockets for communication with the Linux kernel crypto API. MIT Licensed.
Package genetlink implements generic netlink interactions and data types. MIT Licensed.
Package vsock provides access to Linux VM sockets (AF_VSOCK) for communication between a hypervisor and its virtual machines. MIT Licensed.
Wechat App(微信小程序,.wxapkg)解包及相关文件(.wxss,.json,.wxs,.wxml)还原工具
CVE-2018-2628 & CVE-2018-2893
Type-safe Redis client for Golang
goim
Merge results from NMAP and Masscan into one CSV file
A PowerShell tool which provides an easy way to check for shared passwords between Windows Active Directory accounts
PoCs of Vulnerabilities on Bluedroid
跟踪真实漏洞相关靶场环境搭建
A Web Malware Scanner
用于监控系统的日志采集agent,可无缝对接open-falcon
Some codes for bypassing Oracle WebLogic CVE-2018-2628 patch
jsonp隐私泄漏发现
A tool to create a JScript file which loads a .NET v2 assembly from memory.
CMS (Content Management Systems) Detection and Exploitation suite
:incoming_envelope: sql based firewall event logging via nflog netlink and ulogd2 userspace daemon. improved sql scheme for space efficient storage. multi-host log aggregation using dedicated sql-users.
An Analysis Tool for Smart Contracts
ODPS Python SDK and data analysis framework
pure-Go small home internet router
Minimalistic DNS logging tool
Linux Audit Plugin for heka written using netlink Protocol in golang and Lua
IEEE 802.15.4/ZigBee Security Research Toolkit
A Penetration Testing Framework created for Hackers / Pentester / Bug Hunter
Package netlink provides low-level access to Linux netlink sockets. MIT Licensed.
Test Blue Team detections without running any attack.
A plugin to check xss by useing chrome_headless
互联网漏洞管理、资产管理、任务扫描、todoLIST
A golang SQL expression VM. Library to build query engine based functionality.
Classy web framework for Go
A friend of SQLmap which will do what you always expected from SQLmap.
HTTP file upload scanner for Burp Proxy
Lasercrack-可扩展的Ruby暴力破解框架
Web application security scanner
HORSEPILL rootkit PoC
A JavaScript interpreter in Go (golang)
Go seccomp parser and compiler
The Rogue Toolkit: An extensible toolkit aimed at providing penetration testers an easy-to-use platform to deploy Access Points for the purpose of conducting penetration testing and red team engagements.
Simple Go-based setuid+setgid+setgroups+exec
EXIF information viewer(读取照片中隐藏的各类信息)
A golang ebook intro how to build a web with golang
Analyzes resource usage and performance characteristics of running containers.
netlink with inet_diag
Tool that will request the public disclosures on a specific HackerOne program and show them in a localhost webserver.
Package libvirt provides a pure Go interface for interacting with Libvirt. Apache 2.0 Licensed.
Python编写的可视化的离线数据包分析器
Amazon Elastic Container Service Agent
A library for communicating with Linux netfilter subsystems over netlink sockets.
This repo contains a collection of smart contract honeypots.
A Fast & Secure Tunnel Based On KCP with N:M Multiplexing
Go bindings for osquery
Simple netlink library for go.
Monitor linux processes without root permissions
DNS Rebinding Exploitation Framework
Knowledge Base
asp 应用服务器,十年前的项目,一直有用户希望开源
A collection of open source and commercial tools that aid in red team operations.
DEPRECATED - replaced with "monitor"
Malware Behavior Analyzer
The beginning of a x86_64 emulator written in Rust
Antivirus on-access scanning for Linux using ClamAV and Fanotify
A toolkit for building secure, portable and lean operating systems for containers
The modular distributed fingerprinting engine
An HTTP proxy library for Go
LKM rootkit for Linux Kernels 2.6.x/3.x/4.x (x86 and x86_64)
SubFinder is a subdomain discovery tool that can discover massive amounts of valid subdomains for any target. It has a simple modular architecture and has been aimed as a successor to sublist3r project.
Automatically exported from code.google.com/p/unix-privesc-check
--= Xt9 - Anti - Rootkit =-- beta v0.11 by xti9er
Hash Buster is a program which uses several APIs to perform hash lookups.
GoLang Windows API wrappers for System Info / User Management
Headless chrome/chromium automation library (unofficial port of puppeteer)
一个多功能心跳发送包,可以实现服务发现、健康监测、集群数据采集等功能
Parse a dockerfile into a high-level representation using the official go parser
Malicious traffic detection system
APT & CyberCriminal Campaign Collection
Mirror of Apache Spot
A very simple modify for RAT Njrat 0.7D
Nikto web server scanner
A python library for visualizing Artificial Neural Networks (ANN)
An example rootkit that gives a root shell
Dependency-Track is an intelligent Software Composition Analysis (SCA) platform that allows organizations to identify and reduce risk from the use of third-party and open source components.
PROJECT DELTA: SDN SECURITY EVALUATION FRAMEWORK
BadMod detect websites cms & auto exploit :D
Active Directory information dumper via LDAP
参考百度文库,使用Beego(Golang)开发的开源文库系统
快速搭建各种漏洞环境(Various vulnerability environment)
Parses the captcha in vtop beta
A blind XXE injection callback handler. Uses HTTP and FTP to extract information. Originally written in Ruby by ONsec-Lab.
This tool is for sensitive information searching on Github.
Linux privilege escalation auditing tool
Drupal enumeration & exploitation tool
PowerSploit - A PowerShell Post-Exploitation Framework
enhanced fork of libFuzzer
This repository includes resources related to ethical hacking / penetration testing, digital forensics and incident response (DFIR), vulnerability research, exploit development, reverse engineering, and more.
Simple module integrating libinjection as a request filter
Distributed Network Vulnerability Scanner
Golang client for NATS, the cloud native messaging system.
Generic Signature Format for SIEM Systems
collection of articles/books about programing
非法域名挖掘与画像系统。
Tunna is a set of tools which will wrap and tunnel any TCP communication over HTTP. It can be used to bypass network restrictions in fully firewalled environments.
linux elf injector for x86 x86_64 arm arm64
对公网IP列表进行端口服务扫描,发现周期内的端口服务变化情况和弱口令安全风险
Linux vulnerability scanner based on Salt Open and Vulners audit API, with Slack notifications and JIRA integration
HTTPoxy Exploit Scanner by 1N3 @CrowdShield
"Can I take over XYZ?" — a list of services and how to claim (sub)domains with dangling DNS records.
《python数据分析与挖掘实战》的代码笔记
Steal Net-NTLM Hashes using Bad-PDF
XSS payloads for exploiting Markdown syntax
做过的实验,踩过的坑
Go package for reading from continously updated files (tail -f)
Mimikatz implementation in pure Python
一个帮你总结所有类型的上传漏洞的靶场
unix wildcard attacks
Extract all forensic interesting information of Firefox, Iceweasel and Seamonkey browsers
Galileo - Web Application Audit Framework
How to Make a Computer Operating System in C++
Automated security reporting from markdown templates (HackerOne is currently the platform supported)
Find known vulnerabilities in WordPress plugins and themes using Burp Suite proxy. WPScan like plugin for Burp.
Patchman is a Linux Patch Status Monitoring System
Investigate malicious Windows logon by visualizing and analyzing Windows event log
DNS Botnet Server and Client
Google App Engine - Remote Code Execution bug ($36k bug bounty)
The exploit samples database is a repository for **RCE** (remote code execution) exploits and Proof-of-Concepts for **WINDOWS**, the samples are uploaded for education purposes for red and blue teams.
Get website IP address by scanning the entire net 通过扫描全网绕过CDN获取网站IP地址
Vulnerability Static Analysis for Containers
Hdiv CE | Application Self-Protection
WeirdAAL (AWS Attack Library)
OWASP Web Application Security Testing Checklist
PoC code to extract private keys from Windows 10's built in ssh-agent service
Detect it Easy
OK now. Let's hijack github user's custom domain.
Linux Binary Exploitation
Watchdog - A Comprehensive Security Scanning and a Vulnerability Management Tool.
手机号码归属地信息库、手机号归属地查询 phone.dat 最后更新:2018年4月
端口扫描器
Rust 程序设计语言(第二版)
ReverShellGenerator - A tool to generate various ways to do a reverse shell
Simple HTML5 WebSocket fuzzer
A tool to hunt for publicly accessible DigitalOcean Spaces
An IDA Pro plugin to examine the glibc heap, focused on exploit development
A Rust based DNS client, server, and resolver
Scirius is a web application for Suricata ruleset management.
A stats collection and distributed tracing framework
GoKu API Gateway CE,悟空API网关(开源版),是国内首个开源go语言API网关,帮助企业进行API服务治理与API性能安全维护,为企业数字化赋能。
IPv6 network scanner designed to be fast
Infection Monkey - An automated pentest tool
the world famous rkhunter
PHP 白盒分析工具,结合AST 和数据流跟踪分析代码,达到自动化白盒审计功能
Arbitrary code execution with kernel privileges using CVE-2018-8897.
🤓 Build your own (insert technology here)
A free and open source command-line shell and scripting language designed especially for security testing
This is the native Python implementation of CPT(compact Prediction Tree)
Fetch all public IP addresses tied to your AWS account. Works with IPv4/IPv6, Classic/VPC networking, and across all AWS services
CLI tool for spawning and running containers on Windows according to the OCI specification
Reverse Shell as a Service
自动化运维平台:CMDB、CD、DevOps、资产管理、任务编排、持续交付、系统监控、运维管理、配置管理
LinearGo (Go wrapper for LIBLINEAR): A Library for Large Linear Classification
基于Inception的可视化web端sql审核平台
Python api for usage with cobalt strike's External C2 specification
A Docker container in your browser.
A tool for identifying misconfigured CloudFront domains
An extenisble and concurrency pentest framework in Go
A "malicious" DNS server for executing DNS Rebinding attacks on the fly (public instance running on rebind.network:53)
(CVE-2018-9995) Get DVR Credentials
Container Runtime Sandbox
The New Hacking Framework
云集分布式全链路压测军演系统
后端架构师技术图谱
Network Vulnerability Scanner
A tool to link a domain with registered organisation names and emails, to other domains.
路由器漏洞利用框架
A static analyzer for Java, C, C++, and Objective-C
Build cross platform GUI apps with GO and HTML/JS/CSS (powered by Electron)
Cheetah GUI
《自己动手写Java虚拟机》源代码
Rust language pcap library
Simple nDPI wrapper in GO
A collection of resources for Threat Hunters
Fresh Onions is an open source TOR spider / hidden service onion crawler hosted at zlal32teyptf4tvi.onion
自动化收集linux信息
a monitor for getting machine system info alarming
🛡 Block spying and tracking on Windows
第二届阿里云安全算法挑战赛 MJ_3DSUN 队解题方法
CVE-2017-9506 - SSRF
Tiny SHell is an open-source UNIX backdoor.
Simulating Adversary Operations
一款开源指纹识别工具。
An authorization library that supports access control models like ACL, RBAC, ABAC in Golang
A collection of templates for bug bounty reporting
一个物联网(IoT)开发的入门教程。涉及单片机、上位机、移动应用、服务器后台开发的知识。以及蓝牙4.0、以太网模块的使用实例。
Attack Detection
Brute forcing DNS Subdomains -- a demo for DNS over HTTPS
Exploit for Drupal v7.x + v8.x (Drupalgeddon 2 / CVE-2018-7600 / SA-CORE-2018-002)
PenTest Tools
一句话脱裤
Golang logging library
GyoiThon is a growing penetration test tool using Machine Learning.
Seebug、structs、cve漏洞实时监控推送系统
基于Strom的日志实时流量分析主动防御(CCFirewall)系统
Simple, scalable and secure application segmentation
Netlink APIs in Go
goddi (go dump domain info) dumps Active Directory domain information
efficient linux endpoint telemetry solution
php扩展,监视PHP服务器的运行状况,并提供后台修改,实时防护
Java SpEL、Ognl、MVEL2表达式Hook并记录小项目
Quickjack is a point-and-click tool for intuitively producing advanced clickjacking and frame slicing attacks.
The best way to scan for weak ssh passwords on your network
Tools for parsing rulesets using the exact grammar as YARA. Written in Go.
Tests for race conditions in web applications. Includes a RESTful API to integrate into a continuous integration pipeline.
Go AST Scanner
syzkaller is an unsupervised, coverage-guided kernel fuzzer
A plug-in of sublime 2/3 which is able to find PHP vulnerabilities
Golang for Security Professionals
JXWAF(锦衣盾)是一款基于openresty(nginx+lua)开发的下一代web应用防火墙
Poodle (Padding Oracle On Downgraded Legacy Encryption) attack
使用rust开发windows驱动
Redox: A Rust Operating System
Sandboxed, Rust-based, Windows Defender Client
An example sandbox using AppContainer (Windows 8+)
A virtual file system for sandboxing
OZ: a sandboxing system targeting everyday workstation applications
Exploit for CVE-2018-7600 Drupal SA-CORE-2018-002. PoC (Proof-of-Concept).
DNS Enumeration Script
跨平台 webshell 静态扫描器
A Golang implementation of the Aho-Corasick string matching algorithm
A lightweight sandbox for Windows application
Peter's Network Scanner
Sandbox d'analyse de malware pour Windows 7 avec un client TCP en mode noyau
为互联网IT人打造的中文版awesome-go
ActiveScan++ Burp Suite Plugin
It can detect and decode encoded strings, recursively.
RFD Checker - security CLI tool to test Reflected File Download issues
CVE-2018-6794 IDS Bypass PoC server
Linux distro for IDS, NSM, and Log Management
an IIS shortname Scanner
Record some Vulnerabilities
:fire: CHAOS allow generate payloads and control remote Windows systems.
Elegant Scraper and Crawler Framework for Golang
The tiny neural network library
Visual Basic GUI: A Tool to Inject Keystrokes on a SSH Client via an X11 Forwarded Session
A Windows Remote Administration Tool in Visual Basic
.NET Deserialization Passive Scanner
php-fpm源码分析
Paskto - Passive Web Scanner
Go vendor tool that works with the standard vendor file.
Maltego library in Go
Remote Administration Tool for Windows
Kaspersky's GReAT KLara
Shocker / Docker Breakout PoC
mackerel-agent is an agent program to post your hosts' metrics to mackerel.io.
Time Series Alerting Framework
Go bindings for virtio and Hyper-V sockets
Golang library to proxy ssh connections
Custom network stack in Go
Mass scanning the internet (http and https) using a raw tcpstack.
A Sniffer for Open-WLAN
OpenSnitch is a GNU/Linux port of the Little Snitch application firewall.
A regular-expression based python MITM DNS server with support for DNS Rebinding attacks
The Source Code Sniffer is a poor man’s static code analysis tool (SCA) that leverages regular expressions. Designed to highlight high risk functions (Injection, LFI/RFI, file uploads etc) across multiple languages (ASP, Java, CSharp, PHP, Perl, Python, JavaScript, HTML etc) in a highly configurable manner.
My musings with PowerShell
PyRat,a rat by python xmlrpc
Open source RASP solution
Scan for open S3 buckets and dump
Android application fuzzing framework with fuzzers and crash monitor.
Get Subject Alt Name from SSL Certificates
Find, list, and inspect processes from Go (golang).
A fast and powerful alternative to grep
Decode the cookies set by balancer F5, and disclousure all pool ip
Python based backdoor that uses Gmail to exfiltrate data through attachment. This RAT will help during red team engagements to backdoor any Windows machines. It tracks the user activity using screen capture and sends it to an attacker as an e-mail attachment.
E-mails, subdomains and names Harvester - OSINT
Style transfer, deep learning, feature transform
Working POC of Mikrotik exploit from Vault 7 CIA Leaks
ezXSS is an easy way to test (blind) XSS
A tool to scan for .DS_Store files on webservers
Random repo of machine learning ideas orchestrated in python
乙方安全,入侵分析时发现的backdoor
🔪 Universal Cross-site Scripting DB [+ other browser vulnerabilities]
Merlin is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in golang.
Various Tools and Docker Images
A library for parsing .DS_Store files and extracting file names
A tool to help you write binary exploits
Python Remote Administration Tool (RAT) to gain meterpreter session
The Minimalistic x86/x64 API Hooking Library for Windows
A Python Package for the Google Chrome Dev Protocol [threading base]
Subdomain Enumeration in Go
DDoS attack tool for sending forged UDP packets to vulnerable Memcached servers obtained using Shodan API
The Hunting ELK
a golang dynamic loader
OSINT Tool: Generate username lists for companies on LinkedIn
Arjun is a python script for finding hidden GET & POST parameters.
Abusing Certificate Transparency logs for getting HTTPS websites subdomains.
XSS hunter 收集Webview 页面上存在的反射,储存型XSS ,方便应急APP 和前端页面在发布时遇到XSS 安全问题..
Python netlink library — Linux network setup and monitoring
netshell features all in version 2 powershell
C language Bitcoin Network Eclipse Attack Simulator
Undetectable Windows Payload Generation
Android certificate pinning disable tools
FakeNet-NG - Next Generation Dynamic Network Analysis Tool
nextnet is a pivot point discovery tool written in Go.
综合了资产检测,主机扫描,流量分析等技术,通过这些技术取得网络资产,脆弱性,威胁等指标,从而根据这些指标计算出当前网络的网络安全态势。
Next Generation Firewall Audit and Bypass Tool
NGFW src
Perform advanced MiTM attacks on websites with ease. https://injectify.js.org
CloudMapper creates network diagrams of AWS environments
A curated list of fuzzing resources ( Books, courses - free and paid, videos, tools, tutorials and vulnerable applications to practice on ) for learning Fuzzing and initial phases of Exploit Development like root cause analysis.
Memcache 反射攻击 nodejs ddos
Passhunt is a simple tool for searching of default credentials for network devices, web applications and more. Search through 523 vendors and their 2084 default passwords.
收集所有区块链(BlockChain)技术开发相关资料,包括Fabric和Ethereum开发资料
Java-Web-Security - Sichere Webanwendungen mit Java entwickeln
Dictionary of attack patterns and primitives for black-box application fault injection and resource discovery.
A script to enumerate virtual hosts on a server.
<<自己动手写docker>> 源码
微盾®VirtualWall®防火墙整套源代码
SRCHunter一款基于python的开源扫描器
Network topology discovery uses C language by SNMP protocol and nmap(7.12) to realize network assets topology discovery!
Phishing on Twitter
Simple program for detecting if host(s) are vulnerable to SMB exploit(MS17-010)
Distributed crawler powered by Headless Chrome
Searches full repo history for secrets and keys 🔑
Generates permutations, alterations and mutations of subdomains and then resolves them
GM SM2/3/4 library based on Golang (基于Go语言的国密SM2/SM3/SM4算法库)
双因素钓鱼
exploit for ImageMagick's uninitialized memory disclosure in gif coder
漏洞检测Vulnerability scanner for Linux/FreeBSD, agentless, written in Go
A Go library for making HTTP requests with complete control
The Safing Core https://safing.me 基于golang的防火墙
OWASP Joomla Vulnerability Scanner Project
An LKM rootkit targeting Linux 2.6/3.x on x86(_64), and ARM
FISCO BCOS 知识库 区块链
Kaggle | Web Traffic Forecasting 📈
Bugcrowd’s baseline priority ratings for common security vulnerabilities
WebLogic wls-wsat RCE CVE-2017-10271
🔥 A curated list of awesome links related to application/API security in NGINX environment.
各种滑动验证码识别 [腾讯云] [阿里云]
Nginx module for authenticating requests from the ScaleFT Access Fabric
BeyondCorp-style federated access proxy
BeyondCorp-inspired Access Proxy in Go. Secure internal services outside your VPN/perimeter network during a zero-trust transition.
Go Web Application Penetration Test
A utility to score network traffic and identify security threats
mod_rootme patched for apache 2.2
Panoptic is an open source penetration testing tool that automates the process of search and retrieval of content for common log and config files through path traversal vulnerabilities.
基于golang的远程控制
漏洞测试工具
机器学习笔记
*nux metric collector
Medfusion 4000 Security Research
(DOM-)XSS fuzzer based on phantomjs and go.
Archive of leaked Equation Group materials
DNS代理服务器,可以记录log到数据库中
Github Sensitive Information Leakage(Github敏感信息泄露)
njRAT SRC Extract
Server Side Includes in Python's SimpleHTTPServer
NFS遍历目录探测
Medusa is a speedy, parallel, and modular, login brute-forcer.
web敏感目录、信息泄漏批量扫描脚本,结合爬虫、目录深度遍历。
Apache module which provides a random-based UUID environment variable for each request
Advanced reconnaissance utility
一款兼容bugscan插件的扫描器
Striker is an offensive information and vulnerability scanner.
PHP class for the CVSS v3 (Common Vulnerability Scoring System)
naive go bindings to the CPython C-API
Open Redirect Payloads
FastNetMon community - very fast DDoS analyzer with sflow/netflow/mirror support
Machinery is an asynchronous task queue/job queue based on distributed message passing.
A Chinese Nature Language Toolkit
Linux服务器命令监控辅助脚本,ElasticSearch + Logstash + Kibana + Redis + Auditd
S3 bucket enumerator
A collection where my current and future writeups for exploits/CTF will go
YANFF - Yet Another Network Function Framework
A fully implemented kernel exploit for the PS4 on 4.05FW
cloud access security broker for uploads (e.g. FTP) to basic web hosting
Windows memory hacking library
Common User Passwords Profiler (CUPP)
Transform regular expressions into finite state machines and output Go source code
luna webscanner
Vagrant & Packer scripts to build a lab environment complete with security tooling and logging best practices
Docker security analysis & hacking tools
A bunch of links related to Linux kernel fuzzing and exploitation
WhichCDN allows to detect if a given website is protected by a Content Delivery Network
fuzz
an open source browser fuzzing framework for fun.
Grinder is a system to automate the fuzzing of web browsers and the management of a large number of crashes.
Scripted Local Linux Enumeration & Privilege Escalation Checks
Proof of concept written in Python to show that in some situations a SSRF vulnerability can be used to steal NTLMv1/v2 hashes.
Deep Learning model to analyze a large corpus of clear text passwords.
Go bindings for YARA
Detect potentially malicious PHP files
Machine Learning in Action(机器学习实战)
GoLang Binding of HyperScan https://01.org/hyperscan
A proof of concept injectable C++ dll, that uses naked inline hooking and direct memory modification to change your TeamViewer permissions.
An hourly updated list of subdomains gathered from certificate transparency logs
linux 核心模組, 使用 netfilter IPv4 hook 監聽和分析 DNS 請求和回應封包.
poc or exp of android vulnerability
XssPy - Web Application XSS Scanner
xsec-proxy-scanner是一款速度超快、小巧的代理扫描器
TheHive: a Scalable, Open Source and Free Security Incident Response Platform
Sample Rootkit for Linux
JavaScript Secure Coding Practices guide
A big list of Android Hackerone disclosed reports and other resources.
自己动手写Docker
Pouch is an open-source project created to promote the container technology movement.
Bypass SSL certificate pinning for most applications
百合网运维综合管理平台(python+flask框架+cmdb+scheduler+salt),已经成功运行2年有余,基本能够实现日常运维80%以上的重复工作。因本系统依赖底层数据和众多第三方模块,部署运行难度比较大,建议仅用于研究代码!
Domain name permutation engine for detecting typo squatting, phishing and corporate espionage
Linux rootkit for Ubuntu 16.04 and 10.04 (Linux Kernels 4.4.0 and 2.6.32), both i386 and amd64
FAME Automates Malware Evaluation
About 3,000 Free Yara rules created by
kernel privilege escalation enumeration and exploitation framework
A simple dns resolver of dns-record and web-record log server for pentesting
本项目致力于收集网上公开来源的威胁情报,主要关注信誉类威胁情报(如IP/域名等),以及事件类威胁情报。
Collection of scripts and templates to generate Office documents embedded with the DDE, macro-less command execution technique.
CVE-2017-8759 - A vulnerability in the SOAP WDSL parser.
FindMalware
基于行为的Ransomware检测原型
白盒源代码审计工具-白帽子版
open redirect subdomains scanner
:honeybee: Deception based detection techniques mapped to the MITRE’s ATT&CK framework
Manage your website via terminal
VulHint是辅助代码审计的 sublime text 3 插件
使用机器学习识别WebShell
webshell sample
a implement of LSTM using Keras for time series prediction regression problem
WebMalwareScanner - A simple malware scanner
A curated list of awesome YARA rules, tools, and people.
Go Open Source, Distributed, Simple and efficient Search Engine
This is a backdoor about discover network device ,and it can hidden reverse connecting the hacker's server with encrypt commuication 后渗透后门程序,适合在已经攻陷的内网中做下一步的网络信息扫描..
Multi-layer RNN building Wang Feng style lyric
Aktaion: Open Source ML tool and data samples for Exploit and Phishing Research
Slides from my ShellCon Talk, OSINT for Pen Tests, given 10/19.
虚拟机带外内存监控
The official home of the LibVMI project is at https://github.com/libvmi/libvmi.
CyberScan
A curated list of awesome malware analysis tools and resources
基于启发式特征的钓鱼网站检测系统
基于url特征的轻量级的恶意页面检测
通付盾第一代安全加固方案
sample code for educate myself-_-
:globe_with_meridians: Network intrusion detection systems simulator. RHAPIS provides a simulation environment through which user is able to execute any IDS operation.
a hook for the sys_connect using kprobes
Automatic authorization enforcement detection extension for burp suite written in Jython developed by Barak Tawily in order to ease application security people work and allow them perform an automatic authorization tests
hook: linux kernel syscall hijack
rootkit sample code of my tutorials on Freebuf.com
Linux backdoor using ICMP payload for activation
struts2漏洞全版本检测和利用工具
Exploits for getting local root on Linux, BSD, AIX, HP-UX, Solaris, RHEL, SUSE etc.
Simple rootkit hunter
BEURK Experimental Unix RootKit
LKM rootkit for Linux x86 with the 2.6 kernel. It inserts salts inside system_call and sysenter_entry.
PRISM is an user space stealth reverse shell backdoor, written in pure C.
LibZeroEvil & the Research Rootkit project.
A rootkit for linux kernel >= 3.0
just a basic rootkit for learning how to playing sys_call_table
Anti live forensic linux LKM rootkit
A script that clones Github repositories of users and organizations.
Collection of github dorks and helper tool to automate the process of checking dorks
A tool to capture all the git secrets by leveraging multiple open source git searching tools
(SQLiv) massive SQL injection vulnerability scanner
Antivirus for Linux operating system
《Web安全之机器学习入门》
Using artificial intelligence and genetic algorithms to automatically write programs. Tutorial: http://www.primaryobjects.com/cms/article149
利用 Python 的 Socket 端口转发,用于远程维护
ISF(Industrial Security Framework),基于Python的工控漏洞利用框架
A php.ini scanner for best security practices
Burp Suite plugin created for using Collaborator tool during manual testing
security machine learning
ETW Python Library
✍️ A curated list of CVE PoCs.
A toolkit for controlling Euro Truck Simulator 2 with python to develop self-driving algorithms.
githubscan
PHP Fval(say F-word to eval) extension used to disable unsafe functions/eval with E_FATAL.
XSS_Filter_Evasion_Cheat_Sheet 中文版
Running CVE-2017-8759 exploit sample.
Code-Audit-Challenges
High-performance WAF built on the OpenResty stack
Improving security in software defined networks using firewall security mechanism and mitigation of attacks
An OpenFlow Network Controller in Go
Ryu component-based software defined networking framework
OpenFlow DDoS mitigation Ryu controller
Source Code Security Audit (源代码安全审计)
盘丝洞 - 自动化WEB漏洞扫描器
TensorFlowOnSpark brings TensorFlow programs onto Apache Spark clusters
A PHP parser written in PHP
A Static Analysis Tool for Detecting Security Vulnerabilities in Python Web Applications
Wireless Auditing, Intrusion Detection & Prevention System
Provides packet processing capabilities for Go
Go wrapper around iptables utility
ISF(Industrial Exploitation Framework),基于Python的工控漏洞利用框架
HTTPLeaks - All possible ways, a website can leak HTTP requests
中文文档simhash值计算
DropboxC2C is a post-exploitation agent which uses Dropbox Infrastructure for command and control operations.
The GA-IDS is a full-fledged host based intrusion detection system developed using the Java programming language to help detect packets having spoofed IP addresses. It first and foremost sniffs the incoming packets on the host system and there after analyzes them in order to detect an intrusion. Considering the fact that this sniffing process is a low level operation, the java application makes use of the Java Packet Capturing Library (JpCap) which works in conjunction with the Windows Packet Capturing Library (WinpCap).
WPScan rewritten in Python + some WPSeku ideas
LinuxShell编程笔记
A high interaction SSH honeypot
Golang bindings to the CPython C-API
A little tool to play with Windows security
TIH is an intelligence tool that helps you in searching for IOCs across multiple openly available security feeds and some well known APIs. The idea behind the tool is to facilitate searching and storing of frequently added IOCs for creating your own local database of indicators.
An independent, student-led replication of DeepMind's 2016 Nature publication, "Mastering the game of Go with deep neural networks and tree search" (Nature 529, 484-489, 28 Jan 2016), details of which can be found on their website https://deepmind.com/publications.html.
A simple tool designed to enhance the effectiveness of your traps by spreading breadcrumbs & honeytokens across your production servers and workstations to lure the attacker toward your honeypots
IP/TCP/UDP数据包分析及解析
A Suite of Tools written in Python for wireless auditing and security testing.
Docker implemented in around 100 lines of bash
A graphical security analysis tool for IoT networks
Python script for generating bypass of your attack
a passive scanner based on Mitmproxy and Arachni
AUDIT Plugin for MySQL. See wiki and readme for description. If you find the plugin useful, please star us on GitHub. We love stars and it's a great way to show your feedback.
mysql-sniffer is a network traffic analyzer tool for mysql, it is developed by Qihoo DBA and infrastructure team
security and hacking tools, exploits, proof of concepts, shellcodes, scripts
信安之路上涉及的一些脚本
Provides situational awareness of Industrial Control Systems (ICS) and Supervisory Control and Data Acquisition (SCADA) networks in support of network security assessments. iadgov
A powerful and useful hacker dictionary builder for a brute-force attack
This is the code that runs the demo site for rpc4django
A modern vulnerable web app
Tool for automatic exploitation of XXE vulnerability using direct and different out of band methods.
Satori 是一个 LeanCloud 维护的监控系统,inspired by Open-Falcon
阿里云安全算法挑战赛代码(第29名,共936支队伍报名)
PHP Frontend to work with the SQLMAP JSON API Server (sqlmapapi.py) to allow for a Web GUI to drive near full functionality of SQLMAP!
A simple exploit to execute system command on codiad
DevSec Linux Baseline - InSpec Profile
MicroScan 基于B/S架构微扫描器
A toy example for RNN in Python
Deep learnning for detection with xss
Advanced Web Shell
WEB SERVICE SECURITY ASSESSMENT TOOL
Web Sight Docker Deployment
Offensive Web Testing Framework (OWTF), is an OWASP+PTES focused try to unite great tools and make pen testing more efficient, written mostly in Python @owtfp http://owtf.org
Fuzzapi is a tool used for REST API pentesting and uses API_Fuzzer gem
Burp and ZAP plugin to analyse Content-Security-Policy headers or generate template CSP configuration from crawling a Website
A ruby script that scans for vulnerable & exploitable 3rd-party web applications on a network
MailSniper is a penetration testing tool for searching through email in a Microsoft Exchange environment for specific terms (passwords, insider intel, network architecture information, etc.). It can be used as a non-administrative user to search their own email, or by an administrator to search the mailboxes of every user in a domain.
Phishing Campaign Toolkit
Search engine for web assets
悟空扫描器
Automated client-side template injection (sandbox escape/bypass) detection for AngularJS.
Webshell && Backdoor Collection
VMware Escape Exploit before VMware WorkStation 12.5.5
The Social-Engineer Toolkit (SET) repository from TrustedSec - All new versions of SET will be deployed here.
Directory/file & DNS busting tool written in Go
The glorious recon-ng project, which is super cool! This is an older unmaintained release of the popular scanner. Possibly no longer works.
Setup script for Regon-ng
GitHub 泄露监控系统
FiercePhish is a full-fledged phishing framework to manage all phishing engagements. It allows you to track separate phishing campaigns, schedule sending of emails, and much more.
Wordpress Attack Suite
A prototype SSH configuration and policy scanner (Blog: https://mozilla.github.io/ssh_scan/)
SQL Vulnerability Scanner
General SQL Parser(http://www.sqlparser.com) lua module
An automated XSS payload generator written in python.
Shodan API client
数据挖掘/关联规则挖掘/fpgrowth
此项目是我在学习《机器学习实战》这本书时的代码记录情况,用python实现,当然也会包括一些其他的机器学习算法,使用Python实现
python remote access trojan
由Python实现的频繁项集挖掘Apriori算法
inspectIT is the leading Open Source APM (Application Performance Management) tool for analyzing your Java (EE) applications.
AWS Auditing & Hardening Tool
A REST API security testing framework.
一款模仿bugscan的漏洞扫描器
A subdomain enumeration tool.
Remote Desktop Protocol in Twisted Python
Inject code into running Python processes
A Tool for Domain Flyovers
spring mvc cve-2014-3625
Fast and powerful SSL/TLS server scanning library.
RED HAWK is An All In One Tool For Information Gathering, SQL Vulnerability Scanning and Crawling. Coded In PHP
Golang application performance data monitoring.
Puma Scan is the leading software security Visual Studio analyzer extension. Built on top of Roslyn, the open-source .NET Compiler Platform, Puma Scan provides real time, continuous source code analysis as development teams write code. Vulnerabilities are immediately displayed in the development environment as spell check and compiler warnings, preventing security bugs from entering your applications.
simple script to extract all web resources by means of .SVN folder exposed over network.
BlindRef serves as the basis for an automated Blind-Based XXE Exploitation Framework
A tool for embedding XXE/XML exploits into different filetypes
C in four functions
CMS识别 python gevent实现
It comes!!
BadCode is a signature database for static source code scanner that identify bad security practices.
[BASH] Wordpress bruteforce
fastjson remote code execute poc 直接用intellij IDEA打开即可 首先编译得到Test.class,然后运行Poc.java
A web crawler that gathers more than you can imagine.
Inspired by https://github.com/djadmin/awesome-bug-bounty, a list of bug bounty write-up that is categorized by the bug nature
Creating a simple Java Agent
A collection of various awesome lists for hackers, pentesters and security researchers
JexBoss: Jboss (and Java Deserialization Vulnerabilities) verify and EXploitation Tool
安全思维导图集合
All-in-one plugin for Burp Suite for the detection and the exploitation of Java deserialization vulnerabilities
Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in Microsoft Windows Server 2003 R2 allows remote attackers to execute arbitrary code via a long header beginning with "If: <http://" in a PROPFIND request, as exploited in the wild in July or August 2016.
A proof of concept that demonstrates asynchronous scanning for Java deserialization bugs
Zero-Day Code Injection and Persistence Technique
1000个PHP代码审计案例(2016.7以前乌云公开漏洞)
RubySec Field Guide
Immunio's XSS Fuzzer tool
网站漏洞扫描平台
BruteXSS - Cross-Site Scripting Bruteforcer
Free web-application vulnerability and version scanner
Discover your attack surface!
telnet服务密码撞库
This framework is for fuzzing OSX kernel vulnerability based on passive inline hook mechanism in kernel mode.
Machine Learning and Security | Using machine learning to detect malicious URLs
一个简易的ssh密码防暴力破解程序
a demo of logistic regression
a little tips in my code career
J2EEScan is a plugin for Burp Suite Proxy. The goal of this plugin is to improve the test coverage during web application penetration tests on J2EE applications.
Cloudflare DNS Enumeration Tool for Pentesters
浏览器XSS 过滤器Fuzzing 框架 (browser xss aduit fuzzing framework )..
Web security protection system based on openresty
A .DS_Store file disclosure exploit. It parse .DS_Store file and download files recursively.
A BurpSuite plugin to detect Same Origin Method Execution vulnerabilities
source code for yunsuo nginx plugin
WS-Attacker is a modular framework for web services penetration testing. It is developed by the Chair of Network and Data Security, Ruhr University Bochum (http://nds.rub.de/ ) and the Hackmanit GmbH (http://hackmanit.de/).
Reconnaissance tool for GitHub organizations
SQL / SQLI tokenizer parser analyzer
APMonitor Optimization Suite in Python
通过劫持Zend底层opcode编译,可以分析php执行的代码,从而达到还原一切混淆加密的php源码,并且可以根据自定义规则,审计代码安全。
forced-evolution
proxy for save db data. support mysql、sqlite、mongodb
A high-performance MySQL proxy
PHP扩展练习
扫描器合集
定向全自动化渗透测试
域名绑定dns解析搜扫
内网端口极速扫描器
:octocat: Machine Learning for Cyber Security
Advance URL Fuzzing + Whois Domain running on python
滑动验证码破解示例
The XSS Hunter service - a portable version of XSSHunter.com
A simple but flexible plugin system for Python.
From XSS to RCE 2.5 - Black Hat Europe Arsenal 2016
OnionScan is a free and open source tool for investigating the Dark Web.
A Python library and command line tools to provide interactive log visualization.
A simple example for using Flask + Celery
PyMySQL fork for Tornado
Reference: http://www.secgeek.net/bookfresh-vulnerability/
python spider and test basic xss
A python/scrapy based xss website scanner
Smashing The Browser: From Vulnerability Discovery To Exploit
BFAC (Backup File Artifacts Checker): An automated tool that checks for backup artifacts that may discloses the web-application's source code.
An easy to use Discord bot framework in NodeJS
code for running Model and code for Not Suitable for Work (NSFW) classification using deep neural network Caffe models
AuthMatrix is a Burp Suite extension that provides a simple way to test authorization in web applications and web services.
A collection of Burpsuite Intruder payloads, fuzz lists and file uploads
A harvest of the Disallowed directories from the robots.txt files of the world's top websites.
Look for SQL injection attacks in python source code
python audit tool 审计 注入 inject
Knock Subdomain Scan
Proxying And Recording HTTP/HTTPs and Socks5, Save To Mysql Database.
工控安全
Python Plugins that power IronWASP
jSQL Injection is a Java application for automatic SQL database injection.
A Go API client for HackerOne (api.hackerone.com)
SpiderFoot, the open source footprinting and intelligence-gathering tool.
WebPwn3r - Web Applications Security Scanner.
Fast subdomains enumeration tool for penetration testers
A blind mode exploit framework (a dns server and a web app) that like wvs's AcuMonitor Service or burpsuite's collabrator or cloudeye
eagleEyeAgent 的agent支持部分,提供premain和agentmain两种入口
各种安全相关思维导图整理收集
基于http代理的web漏洞扫描器的实现
中国特色的弱口令生成器
The fastest blog system by the fastest framework
some extensions for php framework YAF(https://github.com/laruence/php-yaf)
动态多线程敏感信息泄露检测工具
fofa website
A framework used for Vulnerability scanning
编程语言 | 排名 | 好于 | 星星数 |
---|---|---|---|
Python | 1831 | 97.98% | 117 |
PHP | 2388 | 90.98% | 6 |
Go | 3068 | 90.97% | 4 |
Java | 3153 | 96.50% | 68 |
HTML | 6280 | 89.85% | 2 |