Starred repositories
A list of useful payloads and bypass for Web Application Security and Pentest/CTF
E-mails, subdomains and names Harvester - OSINT
Impacket is a collection of Python classes for working with network protocols.
Python version of the Playwright testing and automation library.
Exploitation Framework for Embedded Devices
The OWASP Mobile Application Security Testing Guide (MASTG) is a comprehensive manual for mobile app security testing and reverse engineering. It describes technical processes for verifying the OWA…
Fast subdomains enumeration tool for penetration testers
QUANTAXIS 支持任务调度 分布式部署的 股票/期货/期权 数据/回测/模拟/交易/可视化/多账户 纯本地量化解决方案
An open-source post-exploitation framework for students, researchers and developers.
Pupy is an opensource, cross-platform (Windows, Linux, OSX, Android) C2 and post-exploitation framework written in python and C
The Penetration Testers Framework (PTF) is a way for modular support for up-to-date tools.
Exphub[漏洞利用脚本库] 包括Webloigc、Struts2、Tomcat、Nexus、Solr、Jboss、Drupal的漏洞利用脚本,最新添加CVE-2020-14882、CVE-2020-11444、CVE-2020-10204、CVE-2020-10199、CVE-2020-1938、CVE-2020-2551、CVE-2020-2555、CVE-2020-2883、CVE-…
Printer Exploitation Toolkit - The tool that made dumpster diving obsolete.
pocsuite3 is an open-sourced remote vulnerability testing framework developed by the Knownsec 404 Team.
A powerful and useful hacker dictionary builder for a brute-force attack
A fast sub domain brute tool for pentesters
Automatic SSRF fuzzer and exploitation tool
An advanced web directory & file scanning tool that will be more powerful than DirBuster, Dirsearch, cansina, and Yu Jian.一个高级web目录、文件扫描工具,功能将会强于DirBuster、Dirsearch、cansina、御剑。
JSFinder is a tool for quickly extracting URLs and subdomains from JS files on a website.
Automated Security Testing For REST API's
A fast vulnerability scanner helps pentesters pinpoint possibly vulnerable targets from a large number of web servers
weblogic 漏洞扫描工具。目前包含对以下漏洞的检测能力:CVE-2014-4210、CVE-2016-0638、CVE-2016-3510、CVE-2017-3248、CVE-2017-3506、CVE-2017-10271、CVE-2018-2628、CVE-2018-2893、CVE-2018-2894、CVE-2018-3191、CVE-2018-3245、CVE-2018-32…
WebCrack是一款web后台弱口令/万能密码批量检测工具,在工具中导入后台地址即可进行自动化检测。
