trackscorer's Stars
swisskyrepo/PayloadsAllTheThings
A list of useful payloads and bypass for Web Application Security and Pentest/CTF
mitmproxy/mitmproxy
An interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers.
antlr/antlr4
ANTLR (ANother Tool for Language Recognition) is a powerful parser generator for reading, processing, executing, or translating structured text or binary files.
SpecterOps/BloodHound-Legacy
Six Degrees of Domain Admin
fuzzdb-project/fuzzdb
Dictionary of attack patterns and primitives for black-box application fault injection and resource discovery.
frohoff/ysoserial
A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.
GreyDGL/PentestGPT
A GPT-empowered penetration testing tool
Mr-xn/Penetration_Testing_POC
渗透测试有关的POC、EXP、脚本、提权、小工具等---About penetration-testing python-script poc getshell csrf xss cms php-getshell domainmod-xss csrf-webshell cobub-razor cve rce sql sql-poc poc-exp bypass oa-getshell cve-cms
LandGrey/SpringBootVulExploit
SpringBoot 相关漏洞学习资料,利用方法和技巧合集,黑盒安全评估 check list
guelfoweb/knock
Knock Subdomain Scan
JerBouma/FinanceDatabase
This is a database of 300.000+ symbols containing Equities, ETFs, Funds, Indices, Currencies, Cryptocurrencies and Money Markets.
lijiejie/subDomainsBrute
A fast sub domain brute tool for pentesters
snoopysecurity/awesome-burp-extensions
A curated list of amazingly awesome Burp Extensions
chipsec/chipsec
Platform Security Assessment Framework
tarunkant/Gopherus
This tool generates gopher link for exploiting SSRF and gaining RCE in various servers
welk1n/JNDI-Injection-Exploit
JNDI注入测试工具(A tool which generates JNDI links can start several servers to exploit JNDI Injection vulnerability,like Jackson,Fastjson,etc)
Y4tacker/JavaSec
a rep for documenting my study, may be from 0 to 0.1
GitHubDaily/ChatGPT-Prompt-Engineering-for-Developers-in-Chinese
《面向开发者的 ChatGPT 提示词工程》非官方版中英双语字幕 Unofficial subtitles of "ChatGPT Prompt Engineering for Developers"
WhiteHSBG/JNDIExploit
对原版https://github.com/feihong-cs/JNDIExploit 进行了实用化修改
fnmsd/MySQL_Fake_Server
MySQL Fake Server use to help MySQL Client File Reading and JDBC Client Java Deserialize
Ershu1/2021_Hvv
2021 hw
googleprojectzero/Jackalope
Binary, coverage-guided fuzzer for Windows, macOS, Linux and Android
tls-attacker/TLS-Attacker
TLS-Attacker is a Java-based framework for analyzing TLS libraries. It can be used to manually test TLS clients and servers or as as a software library for more advanced tools.
Metarget/cloud-native-security-book
《云原生安全:攻防实践与体系构建》资料仓库
ewilded/shelling
SHELLING - a comprehensive OS command injection payload generator
meliht/Mr.SIP
SIP-Based Audit and Attack Tool
quarkslab/titanm
This repository contains the tools we used in our research on the Google Titan M chip
YDCloudSecurity/cloud-security-guides
LS95/gopher-redis-auth
This tool generates gopher link for exploiting SSRF and gaining RCE in redis with password.用于生成附带密码认证的gopher内容,用于SSRF等利用。
tunnelvisionlabs/antlr4
The highly-optimized fork of ANTLR 4 (see README)