CopyA's Stars
carlospolop/Auto_Wordlists
rebootuser/LinEnum
Scripted Local Linux Enumeration & Privilege Escalation Checks
peass-ng/PEASS-ng
PEASS - Privilege Escalation Awesome Scripts SUITE (with colors)
ZachL1/Bilibili-plus
课程视频、PPT和源代码:侯捷C++系列;台大郭彦甫MATLAB
gentilkiwi/mimikatz
A little tool to play with Windows security
ExpLangcn/NucleiTP
自动整合全网Nuclei的漏洞POC,实时同步更新最新POC!
zorox0x/chaospy
Small Tool written based on chaos from projectdiscovery.io
github/codeql
CodeQL: the libraries and queries that power security researchers around the world, as well as code scanning in GitHub Advanced Security
github/vscode-codeql-starter
Starter workspace to use with the CodeQL extension for Visual Studio Code.
pmiaowu/HostCollision
用于host碰撞而生的小工具,专门检测渗透中需要绑定hosts才能访问的主机或内部系统
robertdavidgraham/masscan
TCP port scanner, spews SYN packets asynchronously, scanning entire Internet in under 5 minutes.
bcit-ci/CodeIgniter
Open Source PHP Framework (originally from EllisLab)
HXSecurity/DongTai
Dongtai IAST is an open-source Interactive Application Security Testing (IAST) tool that enables real-time detection of common vulnerabilities in Java applications and third-party components through passive instrumentation. It is particularly suitable for use in the testing phase of the development pipeline.
sml2h3/ddddocr
带带弟弟 通用验证码识别OCR pypi版
jhao104/proxy_pool
Python ProxyPool for web spider
LangziFun/LangSrcCurise
SRC子域名资产监控
ghealer/GUI_Tools
一个由各种图形化渗透工具组成的工具集
J0o1ey/BountyHunterInChina
重生之我在安全行业讨口子系列,分享在安全行业讨口子过程中,SRC、项目实战的有趣案例
smxiazi/xia_sql
xia SQL (瞎注) burp 插件 ,在每个参数后面填加一个单引号,两个单引号,一个简单的判断注入小插件。
F6JO/RouteVulScan
Burpsuite - Route Vulnerable Scanning 递归式被动检测脆弱路径的burp插件
lucsemassa/burp_bug_finder
Automatic Bug finder with buprsuite
pmiaowu/BurpShiroPassiveScan
一款基于BurpSuite的被动式shiro检测插件
bit4woo/knife
A burp extension that add some useful function to Context Menu 添加一些右键菜单让burp用起来更顺畅
c0ny1/captcha-killer
burp验证码识别接口调用插件
zgjx6/SocialEngineeringDictionaryGenerator
社会工程学密码生成器,是一个利用个人信息生成密码的工具
theLSA/burp-sensitive-param-extractor
burpsuite extension for check and extract sensitive request parameter
nahamsec/Resources-for-Beginner-Bug-Bounty-Hunters
A list of resources for those interested in getting started in bug bounties
reddelexc/hackerone-reports
Top disclosed reports from HackerOne
test502git/awvs14-scan
针对 Acunetix AWVS扫描器开发的批量扫描脚本,支持log4j漏洞、SpringShell、SQL注入、XSS、弱口令等专项,支持联动xray、burp、w13scan等被动批量
eslint/eslint
Find and fix problems in your JavaScript code.