Pain4ever's Stars
HotBoy-java/PotatoTool
这款工具是一款功能强大的网络安全综合工具,旨在为安全从业者、红蓝对抗人员和网络安全爱好者提供全面的网络安全解决方案。它集成了多种实用功能,包括解密、分析、扫描、溯源等,为用户提供了便捷的操作界面和丰富的功能选择。This tool offers robust network security solutions for professionals and enthusiasts. With features like decryption, analysis, scanning, and traceability, it provides a user-friendly interface and diverse functionality.
pmiaowu/HostCollision
用于host碰撞而生的小工具,专门检测渗透中需要绑定hosts才能访问的主机或内部系统
wh1t3zer/SpringBootVul-GUI
一个半自动化springboot打点工具,内置目前springboot所有漏洞
LasCC/HackTools
The all-in-one browser extension for offensive security professionals 🛠
P001water/P1soda
一款更高、更快、更强的全方位内网扫描工具
frohoff/ysoserial
A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.
Graylog2/graylog2-server
Free and open log management
RuoJi6/HackerPermKeeper
Linux权限维持
FeeiCN/SecurityInterviewGuide
网络信息安全从业者面试指南
clash-verge-rev/clash-verge-rev
Continuation of Clash Verge - A Clash Meta GUI based on Tauri (Windows, MacOS, Linux)
spyboy-productions/CloakQuest3r
Uncover the true IP address of websites safeguarded by Cloudflare & Others
Lotus6/ConfluenceMemshell
Confluence CVE 2021,2022,2023 利用工具,支持命令执行,哥斯拉,冰蝎 内存马注入
peass-ng/PEASS-ng
PEASS - Privilege Escalation Awesome Scripts SUITE (with colors)
rustdesk/rustdesk
An open-source remote desktop application designed for self-hosting, as an alternative to TeamViewer.
SkyBlueEternal/thinkphp-RCE-POC-Collection
thinkphp v5.x 远程代码执行漏洞-POC集合
Sharpforce/XSS-Exploitation-Tool
An XSS Exploitation Tool
cyberark/KubiScan
A tool to scan Kubernetes cluster for risky permissions
We5ter/Scanners-Box
A powerful and open-source toolkit for hackers and security automation - 安全行业从业者自研开源扫描器合辑
safe6Sec/Fastjson
Fastjson姿势技巧集合
netdata/netdata
Architected for speed. Automated for easy. Monitoring and troubleshooting, transformed!
wafinfo/NCTOOls
一款针对用友NC综合漏洞利用工具
10cks/fofaEX
FOFA EX 是一款基于fofa api(也可导入鹰图、夸克文件)实现的红队综合利用工具,可基于模板把工具作为插件进行集成,自动化进行资产探测,目前提供的插件功能如下:探活、 nuclei 模板扫描、IP反查域名、域名反查 ICP 备案、dismap 指纹扫描
HKEcho5213/HKEcho_Nacos
API-Security/APIKit
APIKit:Discovery, Scan and Audit APIs Toolkit All In One.
bit4woo/domain_hunter_pro
domain_hunter的高级版本,SRC挖洞、HW打点之必备!自动化资产收集;快速Title获取;外部工具联动;等等
GhostTroops/scan4all
Official repository vuls Scan: 15000+PoCs; 23 kinds of application password crack; 7000+Web fingerprints; 146 protocols and 90000+ rules Port scanning; Fuzz, HW, awesome BugBounty( ͡° ͜ʖ ͡°)...
yaklang/yakit
Cyber Security ALL-IN-ONE Platform
AdminTest0/SharpWxDump
微信客户端取证,可获取用户个人信息(昵称/账号/手机/邮箱/数据库密钥(用来解密聊天记录));支持获取多用户信息,不定期更新新版本偏移,目前支持所有新版本、正式版本
pureqh/Hyacinth
一款java漏洞集合工具
jayus0821/swagger-hack
自动化爬取并自动测试所有swagger接口