SoryegeToon's Stars
baiyies/DamnPythonEvasion
That guy uses python to bypass anti-virus, goddamn!基于python pyd的shellcode免杀绕过
AabyssZG/Web-SurvivalScan
对Web渗透项目资产进行快速存活验证
sml2h3/ddddocr
带带弟弟 通用验证码识别OCR pypi版
HoAd-sc/R-dict
一些自己常用的渗透字典
Axx8/Bypass_AV
Bypass_AV msf免杀,ShellCode免杀加载器 ,免杀shellcode执行程序 ,360&火绒&Windows Defender
vladko312/SSTImap
Automatic SSTI detection tool with interactive interface
darkarp/chromepass
Chromepass - Hacking Chrome Saved Passwords
Asoh42/2022hw-vuln
2022hw漏洞消息与poc&exp分享
Axx8/ShellCode_Loader
ShellCode_Loader - Msf&CobaltStrike免杀ShellCode加载器、Shellcode_encryption - 免杀Shellcode加密生成工具,目前测试免杀360&火绒&电脑管家&Windows Defender(其他杀软未测试)。
crisprss/Shellcode_Memory_Loader
基于Golang实现的Shellcode内存加载器,共实现3中内存加载shellcode方式,UUID加载,MAC加载和IPv4加载,目前能过主流杀软(包括Windows Defender)
ghtwf01/excavator
Passive DAST Scanner(被动式黑盒漏洞扫描器)
taomujian/linbing
本系统是对Web中间件和Web框架进行自动化渗透的一个系统,根据扫描选项去自动化收集资产,然后进行POC扫描,POC扫描时会根据指纹选择POC插件去扫描,POC插件扫描用异步方式扫描.前端采用vue技术,后端采用python fastapi.
cloud-custodian/cel-python
Pure Python implementation of the Common Expression Language
LDrakura/DLLhijack-ShellcodeLoader
DLLhijack winmm.dll
SecuProject/DLLHijackingScanner
This is a PoC for bypassing UAC using DLL hijacking and abusing the "Trusted Directories" verification.
rtcatc/Packer-Fuzzer
Packer Fuzzer is a fast and efficient scanner for security detection of websites constructed by javascript module bundler such as Webpack.
1oid/AnyPocsYamlParser
Many yaml scanner plugin parser [nuclei-template, xray-poc, ez-poc] - for Python
HZzz2/go-shellcode-loader
GO免杀shellcode加载器混淆AES加密
pureqh/bypassAV
免杀shellcode加载器
retanoj/mysql_udf
mysql udf eval/cmd
iSafeBlue/TrackRay
溯光 (TrackRay) 3 beta⚡渗透测试框架(资产扫描|指纹识别|暴力破解|网页爬虫|端口扫描|漏洞扫描|代码审计|AWVS|NMAP|Metasploit|SQLMap)
m3rcer/Chisel-Strike
A .NET XOR encrypted cobalt strike aggressor implementation for chisel to utilize faster proxy and advanced socks5 capabilities.
chriskaliX/AD-Pentest-Notes
用于记录内网渗透(域渗透)学习 :-)
l3m0n/pentest_study
从零开始内网渗透学习
improsec/SharpEventPersist
Persistence by writing/reading shellcode from Event Log
merlinxcy/nmap_vscan3
nmap service and application version detection使用nmap的指纹库进行版本识别
Tas9er/ByPassBehinder
ByPassBehinder / 冰蝎WebShell免杀生成 / Code By:Tas9er
GhostPack/Seatbelt
Seatbelt is a C# project that performs a number of security oriented host-survey "safety checks" relevant from both offensive and defensive security perspectives.
yogeshojha/rengine
reNgine is an automated reconnaissance framework for web applications with a focus on highly configurable streamlined recon process via Engines, recon data correlation and organization, continuous monitoring, backed by a database, and simple yet intuitive User Interface. reNgine makes it easy for penetration testers to gather reconnaissance with minimal configuration and with the help of reNgine's correlation, it just makes recon effortless.
yqcs/heartsk_community
Hearts K-企业资产发现与脆弱性检查工具,自动化资产信息收集与漏洞扫描