irrik's Stars
sie504/Struts-S2-xxx
整理收集Struts2漏洞环境
m4p1e/php-exploit
some fun php exploits
Threekiii/Awesome-POC
一个漏洞POC知识库 目前数量 1000+
whwlsfb/JDumpSpider
HeapDump敏感信息提取工具
7BitsTeam/EDR-Bypass-demo
Some demos to bypass EDRs or AVs by 78itsT3@m
projectdiscovery/mapcidr
Utility program to perform multiple operations for a given subnet/CIDR ranges.
aleenzz/MSSQL_SQL_BYPASS_WIKI
MSSQL注入提权,bypass的一些总结
LoRexxar/Kunlun-M
KunLun-M是一个完全开源的静态白盒扫描工具,支持PHP、JavaScript的语义扫描,基础安全、组件安全扫描,Chrome Ext\Solidity的基础扫描。
LandGrey/webshell-detect-bypass
绕过专业工具检测的Webshell研究文章和免杀的Webshell
FunnyWolf/Caesar
一个全新的敏感文件发现工具
F6JO/RouteVulScan
Burpsuite - Route Vulnerable Scanning 递归式被动检测脆弱路径的burp插件
Acmesec/Sylas
新一代子域名主/被动收集工具 - Subdomain automatic/passive collection tool
TomAPU/ev
EV: IDS Evasion via Packet Manipulation
doocop/CVE-2022-1388-EXP
CVE-2022-1388 F5 BIG-IP RCE 批量检测
M1k0er/pentest-notes
记录自己在内网渗透学习中的一些心得和技巧,不定期记录中:)
Junehck/SQL-injection-bypass
记录实战中的各种sql注入绕过姿势
thezdi/PoC
Proofs-of-concept
iceyhexman/flask_memory_shell
Flask 内存马
orkestral/venom
Venom is a high-performance system developed with JavaScript to create a bot for WhatsApp, support for creating any interaction, such as customer service, media sending, sentence recognition based on artificial intelligence and all types of design architecture for WhatsApp.
bryandlee/animegan2-pytorch
PyTorch implementation of AnimeGANv2
gentilkiwi/mimikatz
A little tool to play with Windows security
wgpsec/fofa_viewer
A simple FOFA client written in JavaFX. Made by WgpSec, Maintained by f1ashine.
gh0stkey/CaA
CaA - Collector and Analyzer, Insight into information, exploring with intelligence in a thousand ways.
c0ny1/chunked-coding-converter
Burp suite 分块传输辅助插件
TrojanAZhen/BurpSuitePro-2.1
什么? 你想用免费的BurpSuitePro版本!!!
JoyChou93/java-sec-code
Java web common vulnerabilities and security code which is base on springboot and spring security
TideSec/BypassAntiVirus
远控免杀系列文章及配套工具,汇总测试了互联网上的几十种免杀工具、113种白名单免杀方式、8种代码编译免杀、若干免杀实战技术,并对免杀效果进行了一一测试,为远控的免杀和杀软对抗免杀提供参考。
DasSecurity-HatLab/AoiAWD
AoiAWD-专为比赛设计,便携性好,低权限运行的EDR系统。
Quitten/Autorize
Automatic authorization enforcement detection extension for burp suite written in Jython developed by Barak Tawily in order to ease application security people work and allow them perform an automatic authorization tests
shadow1ng/fscan
一款内网综合扫描工具,方便一键自动化、全方位漏扫扫描。