LightONEWAY's Stars
FeeiCN/SecurityInterviewGuide
网络信息安全从业者面试指南
OpenCTI-Platform/opencti
Open Cyber Threat Intelligence Platform
RemusDBD/ctftools-all-in-one
市场上虽然存在大量的网络安全工具和软件,但它们大多针对某一特定领域或功能,缺乏一个统一的、集成的、易于使用的综合工具平台。这导致参赛者在CTF竞赛中需要频繁切换不同的工具,不仅降低了工作效率,还增加了操作失误的风险。由gitee转发 ↓
CloudExplorer-Dev/CloudExplorer-Lite
开源的轻量级云管平台
fit2cloud/riskscanner
RiskScanner 是开源的多云安全合规扫描平台,基于 Cloud Custodian 和 Nuclei 引擎,实现对主流公(私)有云资源的安全合规扫描和漏洞扫描。
tdragon6/Supershell
Supershell C2 远控平台,基于反向SSH隧道获取完全交互式Shell
SpecterOps/Nemesis
An offensive data enrichment pipeline
VisionRush/DeepFakeDefenders
Image forgery recognition algorithm
BishopFox/sliver
Adversary Emulation Framework
uknowsec/Active-Directory-Pentest-Notes
个人域渗透学习笔记
Threekiii/Awesome-Redteam
一个攻防知识仓库 Red Teaming and Offensive Security
BC-SECURITY/Empire
Empire is a post-exploitation and adversary emulation framework that is used to aid Red Teams and Penetration Testers.
darmado/Atomic-Red-Team-C2
ARTi-C2 is a post-exploitation framework used to execute Atomic Red Team test cases with rapid payload deployment and execution capabilities via .NET's DLR.
mitre/caldera
Automated Adversary Emulation Platform
redcanaryco/atomic-red-team
Small and highly portable detection tests based on MITRE's ATT&CK.
jonrau1/ElectricEye
ElectricEye is a multi-cloud, multi-SaaS Python CLI tool for Asset Management, Security Posture Management & Attack Surface Monitoring supporting 100s of services and evaluations to harden your CSP & SaaS environments with controls mapped to over 20 industry, regulatory, and best practice controls frameworks
someengineering/cloud-security-list
A list of cloud security tools and vendors.
owasp-amass/amass
In-depth attack surface mapping and asset discovery
Autumn-27/ScopeSentry
ScopeSentry-网络空间测绘、子域名枚举、端口扫描、敏感信息发现、漏洞扫描、分布式节点
XTeam-Wing/X-Marshal
Marshal-EASM 攻击面管理系统-社区版
burpheart/koko-moni
一个基于网络空间搜索引擎的攻击面管理平台,可定时进行资产信息爬取,及时发现新增资产,本项目聚合了 Fofa、Hunter、Quake、Zoomeye 和 Threatbook 的数据源,并对获取到的数据进行去重与清洗
fr0gger/Awesome-GPT-Agents
A curated list of GPT agents for cybersecurity
Symph0nia/CyberEdge
互联网资产综合扫描/攻击面测绘
knownsec/404StarLink
404StarLink - 推荐优质、有意义、有趣、坚持维护的安全开源项目
FunnyWolf/Viper
Attack Surface Management & Red Team Simulation Platform 互联网攻击面管理&红队模拟平台
0xbug/biu
网络资产攻击面梳理
holyshell/Books
Some special ebooks
atiilla/geospy
Python tool using Graylark's AI-powered geo-location service to uncover the location where photos were taken.
cloud-custodian/cloud-custodian
Rules engine for cloud security, cost optimization, and governance, DSL in yaml for policies to query, filter, and take actions on resources
cloudquery/cloudquery
The open source high performance ELT framework powered by Apache Arrow