📦 GitHub 全球红队渗透资源中转站。
旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
⚠️ 本频道仅供安全研究与授权测试使用。
旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
⚠️ 本频道仅供安全研究与授权测试使用。
GitHub监控消息提醒!!!
更新了:绕过
描述:本软件首先集成危害性较大框架和部分主流cms的rce(无需登录,或者登录绕过执行rce)和反序列化(利用链简单)。傻瓜式导入url即可实现批量getshell。批量自动化测试。例如:Thinkphp,Struts2,weblogic。出现的最新漏洞进行实时跟踪并且更新例如:log4jRCE,向日葵RCE 等等.
URL:https://github.com/yishuifengxiao/wind-bell
标签:#绕过
更新了:绕过
描述:本软件首先集成危害性较大框架和部分主流cms的rce(无需登录,或者登录绕过执行rce)和反序列化(利用链简单)。傻瓜式导入url即可实现批量getshell。批量自动化测试。例如:Thinkphp,Struts2,weblogic。出现的最新漏洞进行实时跟踪并且更新例如:log4jRCE,向日葵RCE 等等.
URL:https://github.com/yishuifengxiao/wind-bell
标签:#绕过
GitHub监控消息提醒!!!
更新了:CVE-2022
描述:CVE-2022-0847 SUID Shell Backdoor
URL:https://github.com/notl0cal/dpipe
标签:#CVE-2022
更新了:CVE-2022
描述:CVE-2022-0847 SUID Shell Backdoor
URL:https://github.com/notl0cal/dpipe
标签:#CVE-2022
GitHub监控消息提醒!!!
更新了:CVE-2022
描述:A script to change OpenSSL versions on Ubuntu to 1.1.1q to protect against CVE-2022-2097.
URL:https://github.com/PeterThomasAwen/OpenSSLUpgrade1.1.1q-Ubuntu
标签:#CVE-2022
更新了:CVE-2022
描述:A script to change OpenSSL versions on Ubuntu to 1.1.1q to protect against CVE-2022-2097.
URL:https://github.com/PeterThomasAwen/OpenSSLUpgrade1.1.1q-Ubuntu
标签:#CVE-2022
GitHub监控消息提醒!!!
更新了:CVE-2022
描述:CVE-2022-32250 - Working Proof of Concept & Patch
URL:https://github.com/0dayCTF/CVE-2022-32250_PoC
标签:#CVE-2022
更新了:CVE-2022
描述:CVE-2022-32250 - Working Proof of Concept & Patch
URL:https://github.com/0dayCTF/CVE-2022-32250_PoC
标签:#CVE-2022
GitHub监控消息提醒!!!
更新了:Red Team
描述:Red Teaming & Active Directory Cheat Sheet
URL:https://github.com/expl0itabl3/Redsheet
标签:#Red Team
更新了:Red Team
描述:Red Teaming & Active Directory Cheat Sheet
URL:https://github.com/expl0itabl3/Redsheet
标签:#Red Team
GitHub监控消息提醒!!!
更新了:漏洞挖掘
描述:零基础入门V8引擎漏洞挖掘
URL:https://github.com/ErodedElk/Chaos-me-JavaScript-V8
标签:#漏洞挖掘
更新了:漏洞挖掘
描述:零基础入门V8引擎漏洞挖掘
URL:https://github.com/ErodedElk/Chaos-me-JavaScript-V8
标签:#漏洞挖掘
GitHub监控消息提醒!!!
更新了:CVE-2022
描述:Simple PoC-checker for CVE-2022-31749 by 1vere$k
URL:https://github.com/iveresk/cve-2022-31749
标签:#CVE-2022
更新了:CVE-2022
描述:Simple PoC-checker for CVE-2022-31749 by 1vere$k
URL:https://github.com/iveresk/cve-2022-31749
标签:#CVE-2022
GitHub监控消息提醒!!!
更新了:红队
描述:一款基于fofa api语句的资产收集工具,用于红队快速收集顶级域名或者ip相关关联的资产
URL:https://github.com/zhizhuoshuma/Assetstocollect
标签:#红队
更新了:红队
描述:一款基于fofa api语句的资产收集工具,用于红队快速收集顶级域名或者ip相关关联的资产
URL:https://github.com/zhizhuoshuma/Assetstocollect
标签:#红队
GitHub监控消息提醒!!!
更新了:CVE-2022
描述:Redis 沙盒逃逸(CVE-2022-0543)POC
URL:https://github.com/z92g/CVE-2022-0543
标签:#CVE-2022
更新了:CVE-2022
描述:Redis 沙盒逃逸(CVE-2022-0543)POC
URL:https://github.com/z92g/CVE-2022-0543
标签:#CVE-2022
GitHub监控消息提醒!!!
更新了:内存马
描述:websocket cmd内存马 wscmd.jsp websocket 代理内存马 wsproxy.jsp
URL:https://github.com/DayorNight/BLCS
标签:#内存马
更新了:内存马
描述:websocket cmd内存马 wscmd.jsp websocket 代理内存马 wsproxy.jsp
URL:https://github.com/DayorNight/BLCS
标签:#内存马
GitHub监控消息提醒!!!
更新了:反序列化
描述:一个针对shiro反序列化漏洞(CVE-2016-4437)的快速利用工具/A simple tool targeted at shiro framework attacks with ysoserial.
URL:https://github.com/4nth0ny1130/shisoserial
标签:#反序列化
更新了:反序列化
描述:一个针对shiro反序列化漏洞(CVE-2016-4437)的快速利用工具/A simple tool targeted at shiro framework attacks with ysoserial.
URL:https://github.com/4nth0ny1130/shisoserial
标签:#反序列化
GitHub监控消息提醒!!!
更新了:Cobalt Strike
描述:Public variation of Titan Loader. Tweaks Cobalt Strike's behavior with Import Address Table Hooks
URL:https://github.com/SecIdiot/TitanLdr
标签:#Cobalt Strike
更新了:Cobalt Strike
描述:Public variation of Titan Loader. Tweaks Cobalt Strike's behavior with Import Address Table Hooks
URL:https://github.com/SecIdiot/TitanLdr
标签:#Cobalt Strike
GitHub监控消息提醒!!!
更新了:CVE-2022
描述:Exploit code for Jira Mobile Rest Plugin SSRF (CVE-2022-26135)
URL:https://github.com/assetnote/jira-mobile-ssrf-exploit
标签:#CVE-2022
更新了:CVE-2022
描述:Exploit code for Jira Mobile Rest Plugin SSRF (CVE-2022-26135)
URL:https://github.com/assetnote/jira-mobile-ssrf-exploit
标签:#CVE-2022
GitHub监控消息提醒!!!
更新了:CVE-2022
描述:exp of CVE-2022-0847
URL:https://github.com/edr1412/Dirty-Pipe
标签:#CVE-2022
更新了:CVE-2022
描述:exp of CVE-2022-0847
URL:https://github.com/edr1412/Dirty-Pipe
标签:#CVE-2022