Starred repositories
Collection of Cyber Threat Intelligence sources from the deep and dark web
A tool to transform Chromium browsers into a C2 Implant
A repository for learning various heap exploitation techniques.
This repository contains a daily export of all IPs that have been targeting NetWatch sensors as well as all used usernames and passwords
domain_hunter的高级版本,SRC挖洞、HW打点之必备!自动化资产收集;快速Title获取;外部工具联动;等等
本程序为美国NSA的方程式工具包图形界面版,由ABC_123于2017年开始编写,仅用来扫描和验证MS17-010、MS09-050、MS08-067漏洞,并可协助管理员修复系统漏洞。
一款支持自定义的 Java 内存马生成工具|A customizable Java in-memory webshell generation tool.
《APT Individual Combat Guide》
MySQL Fake Server use to help MySQL Client File Reading and JDBC Client Java Deserialize
面向红队的, 高性能高度自由可拓展的自动化扫描引擎 | A highly controllable and extensionable automated scanning engine for red teams
Run macOS VM in a Docker! Run near native OSX-KVM in Docker! X11 Forwarding! CI/CD for OS X Security Research! Docker mac Containers.
WTF Solidity 极简入门教程,供小白们使用。Now supports English! 官网: https://wtf.academy
EyeWitness is designed to take screenshots of websites, provide some server header info, and identify default credentials if possible.
Mastering Ethereum, by Andreas M. Antonopoulos, Gavin Wood
Find, verify, and analyze leaked credentials
The fastest and complete solution for domain recognition. Supports screenshoting, port scan, HTTP check, data import from other tools, subdomain monitoring, alerts via Discord, Slack and Telegram, …
A collected list of awesome security talks
DNSGen is a powerful and flexible DNS name permutation tool designed for security researchers and penetration testers. It generates intelligent domain name variations to assist in subdomain discove…
纯 Java 实现的 MySQL Fake Server | 支持 GUI 版和命令行版 | 支持反序列化和文件读取的利用方式 | 支持常见的 GADGET 和自定义 GADGET 数据 | 根据目标环境自动生成匹配的 PAYLOAD | 支持 PGSQL 和 DERBY 的利用