📦 GitHub 全球红队渗透资源中转站。
旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
⚠️ 本频道仅供安全研究与授权测试使用。
旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
⚠️ 本频道仅供安全研究与授权测试使用。
GitHub监控消息提醒!!!
更新了:渗透测试
描述:ClickHouse是一款开源的列式数据库,ClickHouse存在未授权访问漏洞,攻击者可利用该漏洞获取数据库的敏感信息,渗透测试poc
URL:https://github.com/FeiNiao/ClickHouse-database-unauthorized
标签:#渗透测试
更新了:渗透测试
描述:ClickHouse是一款开源的列式数据库,ClickHouse存在未授权访问漏洞,攻击者可利用该漏洞获取数据库的敏感信息,渗透测试poc
URL:https://github.com/FeiNiao/ClickHouse-database-unauthorized
标签:#渗透测试
GitHub监控消息提醒!!!
更新了:漏洞利用
描述:一款针对Shiro550漏洞进行快速漏洞利用工具。 对 @SummerSec 大佬的项目https://github.com/SummerSec/ShiroAttack2 进行了一些改进。
URL:https://github.com/altEr1125/ShiroAttack2
标签:#漏洞利用
更新了:漏洞利用
描述:一款针对Shiro550漏洞进行快速漏洞利用工具。 对 @SummerSec 大佬的项目https://github.com/SummerSec/ShiroAttack2 进行了一些改进。
URL:https://github.com/altEr1125/ShiroAttack2
标签:#漏洞利用
GitHub监控消息提醒!!!
更新了:CVE-2023
描述:An exploit of CVE-2023-0386, verified on 5.19.0-38-generic #39~22.04.1-Ubuntu
URL:https://github.com/JlSakuya/CVE-2023-0386
标签:#CVE-2023
更新了:CVE-2023
描述:An exploit of CVE-2023-0386, verified on 5.19.0-38-generic #39~22.04.1-Ubuntu
URL:https://github.com/JlSakuya/CVE-2023-0386
标签:#CVE-2023
GitHub监控消息提醒!!!
更新了:CVE-2023
描述:CVE-2023-29489 mass exploit
URL:https://github.com/1337r0j4n/CVE-2023-29489
标签:#CVE-2023
更新了:CVE-2023
描述:CVE-2023-29489 mass exploit
URL:https://github.com/1337r0j4n/CVE-2023-29489
标签:#CVE-2023
GitHub监控消息提醒!!!
更新了:漏洞检测
描述:飞刃是一套完整的企业级黑盒漏洞扫描系统,集成漏洞扫描、漏洞管理、扫描资产、爬虫等服务。 拥有强大的漏洞检测引擎和丰富的插件库,覆盖多种漏洞类型和应用程序框架。
URL:https://github.com/tongcheng-security-team/NextScan
标签:#漏洞检测
更新了:漏洞检测
描述:飞刃是一套完整的企业级黑盒漏洞扫描系统,集成漏洞扫描、漏洞管理、扫描资产、爬虫等服务。 拥有强大的漏洞检测引擎和丰富的插件库,覆盖多种漏洞类型和应用程序框架。
URL:https://github.com/tongcheng-security-team/NextScan
标签:#漏洞检测
GitHub监控消息提醒!!!
更新了:反序列化
描述:使用Tsql把Json反序列化成结果集
URL:https://github.com/Proud-Li/JsonConvertBysql
标签:#反序列化
更新了:反序列化
描述:使用Tsql把Json反序列化成结果集
URL:https://github.com/Proud-Li/JsonConvertBysql
标签:#反序列化
GitHub监控消息提醒!!!
更新了:CVE-2023
描述:CVE-2023-0386在ubuntu22.04上的提权
URL:https://github.com/xkaneiki/CVE-2023-0386
标签:#CVE-2023
更新了:CVE-2023
描述:CVE-2023-0386在ubuntu22.04上的提权
URL:https://github.com/xkaneiki/CVE-2023-0386
标签:#CVE-2023
GitHub监控消息提醒!!!
更新了:Red Team
描述:A cheatsheet of commands used to pass the CARTP (Certified Azure Red Team Professional) exam.
URL:https://github.com/sabrinalupsan/pentesting-azure-ad
标签:#Red Team
更新了:Red Team
描述:A cheatsheet of commands used to pass the CARTP (Certified Azure Red Team Professional) exam.
URL:https://github.com/sabrinalupsan/pentesting-azure-ad
标签:#Red Team
GitHub监控消息提醒!!!
更新了:CVE-2023
描述:A POC for the all new CVE-2023-27524 which allows for authentication bypass and gaining access to the admin dashboard.
URL:https://github.com/MaanVader/CVE-2023-27524-POC
标签:#CVE-2023
更新了:CVE-2023
描述:A POC for the all new CVE-2023-27524 which allows for authentication bypass and gaining access to the admin dashboard.
URL:https://github.com/MaanVader/CVE-2023-27524-POC
标签:#CVE-2023
GitHub监控消息提醒!!!
更新了:bypass av
描述:风暴免杀-bypass defender、360、vt
URL:https://github.com/StormEyePro/StormBypassAV
标签:#bypass av
更新了:bypass av
描述:风暴免杀-bypass defender、360、vt
URL:https://github.com/StormEyePro/StormBypassAV
标签:#bypass av
GitHub监控消息提醒!!!
更新了:webshell
描述:Scan IIS log for SQL injection, file inclusion and webshell attack.
URL:https://github.com/uaibol/logscanner
标签:#webshell
更新了:webshell
描述:Scan IIS log for SQL injection, file inclusion and webshell attack.
URL:https://github.com/uaibol/logscanner
标签:#webshell
GitHub监控消息提醒!!!
更新了:反序列化
描述:YJson是一个轻量级的 JSON 序列化/反序列化 C++ 库。 YJson is a lightweight JSON serialization/deserialization C++ library.
URL:https://github.com/Ybr2007/YJson
标签:#反序列化
更新了:反序列化
描述:YJson是一个轻量级的 JSON 序列化/反序列化 C++ 库。 YJson is a lightweight JSON serialization/deserialization C++ library.
URL:https://github.com/Ybr2007/YJson
标签:#反序列化
GitHub监控消息提醒!!!
更新了:代码审计
描述:基于原有的mysql_monitor项目进行的二次开发,更方便mysql的执行监控,提高代码审计效率
URL:https://github.com/littlepillow007/mysql_monitor_php
标签:#代码审计
更新了:代码审计
描述:基于原有的mysql_monitor项目进行的二次开发,更方便mysql的执行监控,提高代码审计效率
URL:https://github.com/littlepillow007/mysql_monitor_php
标签:#代码审计
GitHub监控消息提醒!!!
更新了:Red Team
描述:A folder to serve tools from during PT/Red Team engagements. Contains common executables and scripts for privesc, recon, pivoting and CVE exploitation.
URL:https://github.com/shanedle/trello-redesign
标签:#Red Team
更新了:Red Team
描述:A folder to serve tools from during PT/Red Team engagements. Contains common executables and scripts for privesc, recon, pivoting and CVE exploitation.
URL:https://github.com/shanedle/trello-redesign
标签:#Red Team