Skip to content
KitploitKITPLOIT
أدواتالمدونة
إرسال
أدواتالمدونة
إرسال

أدوات الاختراق واختبار الاختراق والأمن السيبراني لترسانتك الأمنية!

Kitploit هو دليل لأدوات الاختراق والأمن السيبراني واختبار الاختراق. اكتشف آخر تحديثات المشاريع للعثور على الثغرات وتحليل الأنظمة وأتمتة الاختبارات وتعزيز أمنك.

··الخلاصات·اتصال·الخصوصية·© 2026 Kitploit

دليل الأدوات

الفئات

عرض جميع الفئات
Loading categories
CTF-s-Tools — مستودع لفهرسة الأدوات المفيدة لمسابقات CTF | Kitploit
أدوات/GitHubGitHub/ph4l4nx/ctf-s-tools
الاستخبارات مفتوحة المصدر (OSINT)الاستغلالالهندسة العكسيةإخفاء المعلوماتتحليل البرمجيات الخبيثةالتحاليل الرقمية الجنائيةالتشفيرCTFاختبار الاختراقالتعلم والتعليمموارد منسقةمختبرات وتدريب عملي
295منذ 6 أشهرتمت المراجعة من قبل Kitploit

الأكثر شعبية

عرض الكل →

اكتشف الأدوات الأكثر استخدامًا من قبل مجتمعنا.

استكشف جميع الأدوات

تصفح مجموعتنا من الأدوات

عرض جميع الأدوات →
مشاركة
GitHubph4l4nx/ctf-s-tools

CTF-s-Tools

مستودع لفهرسة الأدوات المفيدة لمسابقات CTF

عرض المستودع

Repository to index interesting Capture The Flag tools and other stuff.

  • جدول المحتويات
    • منصات للممارسة
    • التشفير
      • رئيسي
      • ثانوي
      • التجزئة
      • اللغات الباطنية
    • إخفاء المعلومات
    • OSINT
      • مطاردة التهديدات
    • التحليل الجنائي
    • الهندسة العكسية
    • الاستغلال
    • اختبار الاختراق
      • الاستطلاع
      • الويب
      • قاعدة بيانات الإكسبلويت
      • Docker
      • بيانات الاعتماد
      • قاعدة بيانات ثغرات CVE
      • الاستغلال
      • Active Directory
      • تصعيد الامتيازات
        • ويندوز
        • لينكس
      • الملفات التنفيذية الشرعية في النظام
      • تجاوز AV
      • أطر عمل آلية
      • الأجهزة المحمولة
      • الواي فاي
      • أدوات مساعدة
    • البرمجيات الخبيثة
      • محركات عبر الإنترنت
      • توزيعات لتحليل البرمجيات الخبيثة
      • أدوات
      • مكافحات فيروسات و EDRs وصناديق رمل مجانية
      • برامج الفدية
      • APTs
      • مدونات ومعلومات
    • أدوات مساعدة
    • ويكيات
    • شروحات الحلول
    • أدوات أخرى

منصات للممارسة

https://ctftime.org/

https://www.hackthebox.eu/

https://atenea.ccn-cert.cni.es/home

https://tryhackme.com/

https://www.vulnhub.com/

  • تحديات اختراق الويب: http://webhacking.kr/

  • منصة لتعلّم التشفير الحديث: https://cryptohack.org/

  • منصة للهندسة العكسية: https://crackmes.one/

  • تحديات التحليل الجنائي: https://ctf.unizar.es/ && https://freetraining.dfirdiva.com/dfir-ctfs-challenges && https://socvel.com/

  • PicoCTF: https://play.picoctf.org/login

  • الفريق الأزرق: https://letsdefend.io/

التشفير

رئيسي

https://gchq.github.io/CyberChef/

https://www.dcode.fr/tools-list#cryptography

  • محدد ومحلل الشيفرات: https://www.boxentriq.com/code-breaking/cipher-identifier

  • محدد تنسيق البيانات: https://geocaching.dennistreysa.de/multisolver/

ثانوي

  • حل تلقائي للألغاز المشفرة (استبدال) https://quipqiup.com/

  • تحليل التردد: https://crypto.interactive-maths.com/frequency-analysis-breaking-the-code.html

  • القوة الغاشمة لشفرة فيجينير: https://guballa.de/vigenere-solver

  • RsaCtfTool: https://github.com/Ganapati/RsaCtfTool

  • فك تشفير رسائل الإيموجي https://cryptoji.com/ & https://cryptii.com/pipes/morse-code-with-emojis

  • Padding-oracle-attacker: https://github.com/KishanBagaria/padding-oracle-attacker

  • قاموس أعلام الإشارات البحرية: https://en.wikipedia.org/wiki/International_maritime_signal_flags

  • Enigma: https://cryptii.com/

  • تحليل العوامل: http://factordb.com/

  • تجميع للتحليل الشيفري: https://github.com/mindcrypt/Cryptanalysis

http://rumkin.com/tools/cipher/

  • محوّل في الوقت الفعلي: https://kt.gy/tools.html#conv/

  • نص برمجي بسيط لحساب عنوان البصل من موصّف خدمة Tor المخفية أو المفتاح العام: https://gist.github.com/DonnchaC/d6428881f451097f329e (تحتاج إلى تعديل السطر 14 ليعمل بشكل صحيح "onion_address = hashlib.sha1(key.exportKey('DER')[22:]).digest()[:10]").

  • تحويل الكلام إلى نص: https://speech-to-text-demo.ng.bluemix.net/

  • كلمات الأغاني: https://codewithrockstar.com/online

  • مولّد عبر الإنترنت لتجزئة MD5 لسلسلة نصية: http://www.md5.cz/

التجزئة

  • قاعدة بيانات التجزئة: https://crackstation.net/

  • Dehashed: https://www.dehashed.com/

  • كسر التجزئات: http://rainbowtables.it64.com/

  • قاعدة بيانات التجزئة: https://www.onlinehashcrack.com/

  • قاعدة بيانات التجزئة: https://md5decrypt.net/en/

  • قاعدة بيانات التجزئة: https://hashkiller.io/

  • قاعدة بيانات التجزئة: https://hashes.com/en/decrypt/hash

اللغات الباطنية

  • مفكك لغة البرمجة الباطنية Ook!: https://www.dcode.fr/ook-language

  • مفكك لغة البرمجة الباطنية Brainfuck: https://www.dcode.fr/brainfuck-language

  • مفكك لغة البرمجة الباطنية Malboge: https://www.malbolge.doleczek.pl/

  • لغة البرمجة الباطنية COW: https://frank-buss.de/cow.html

إخفاء المعلومات

  • Exiftool

  • Zsteg

  • Exiv2

  • Identify -verbose file

  • توقيعات الأرقام السحرية: https://asecuritysite.com/forensics/magic && https://www.garykessler.net/library/file_sigs.html → محرر سداسي عشري

  • Binwalk -e image

  • Foremost -i image -o outdir

  • Steghide: http://steghide.sourceforge.net/documentation/manpage_es.php (مثال: steghide extract -sf file , steghide info file)

  • Stegseek: https://github.com/RickdeJager/stegseek (أفضل من Stegcracker)

  • StegCracker: https://github.com/Paradoxis/StegCracker

  • أداة تحليل أعمق لإخفاء المعلومات: https://aperisolve.fr/

  • محلل الطيف: https://academo.org/demos/spectrum-analyzer/

  • Stegsolve: https://github.com/zardus/ctf-tools/blob/master/stegsolve/install (للتشغيل: java -jar steg_solve.jar)

  • تحويل فورييه: http://bigwww.epfl.ch/demo/ip/demos/FFT/ && https://github.com/0xcomposure/FFTStegPic

  • أداة إخفاء المعلومات بالحبر غير المرئي الرقمي: https://sourceforge.net/projects/diit/

  • فك ترميز الملفات من أشرطة كاسيت Atari توربو ذات 8 بت: https://github.com/baktragh/turbodecoder

https://incoherency.co.uk/image-steganography/#unhide

http://exif-viewer.com/

https://stegonline.georgeom.net/upload

https://stylesuxx.github.io/steganography/

https://skynettools.com/free-online-steganography-tools/

  • مفكك شيفرة مورس الصوتي التكيفي: https://morsecode.world/international/decoder/audio-decoder-adaptive.html

  • Audacity (sudo apt-get install audacity) مثال: https://www.hackiit.cf/write-up-hackiit-ctf-biological-hazard-ii/

  • AudioStego: https://github.com/danielcardeenas/AudioStego

  • تحليل الملفات والروابط المشبوهة لكشف البرمجيات الخبيثة المخفية (stegomalware): https://stegoinspector.com/#/

  • مترجم أوريبيش: https://funtranslations.com/aurebesh

  • إخفاء المعلومات في بيتكوين: https://incoherency.co.uk/stegoseed/

  • إخفاء المعلومات في Mojibake: https://incoherency.co.uk/mojibake/

  • إخفاء المعلومات في الشطرنج : https://incoherency.co.uk/chess-steg/

  • حلال/عارض Magic Eye: https://magiceye.ecksdee.co.uk/

  • مفكك رموز QR: https://online-barcode-reader.inliteresearch.com/ && https://zxing.org/w/decode.jspx

  • Stegosuite: http://manpages.ubuntu.com/manpages/bionic/man1/stegosuite.1.html

  • StegSpy: http://www.spy-hunter.com/stegspydownload.htm

  • StegSecret: http://stegsecret.sourceforge.net/

  • Openstego: https://www.openstego.com/

  • Stegpic: https://domnit.org/stepic/doc/

https://www.bertnase.de/npiet/npiet-execute.php

  • إصلاح الصور: https://online.officerecovery.com/es/pixrecovery/

  • أداة لاستعادة كلمات المرور من لقطات الشاشة المبكسلّة: https://github.com/beurtschipper/Depix

  • تحليل الصور الجنائي: https://github.com/GuidoBartoli/sherloq

  • إخفاء المعلومات في Unicode باستخدام أحرف صفر العرض: https://330k.github.io/misc_tools/unicode_steganography.html

  • Stegsnow(أحرف صفر العرض): https://pentesttools.net/hide-secret-messages-in-text-using-stegsnow-zero-width-characters/

  • لغة السبام أو PGP: https://www.spammimic.com/decode.shtml

  • f5stegojs: https://desudesutalk.github.io/f5stegojs/

  • فك اختصار الروابط: https://unshorten.it/

  • PNG dump: https://blog.didierstevens.com/2022/04/18/new-tool-pngdump-py-beta/

OSINT

  • معلومات IP: https://bgp.tools/

  • معلومات IP: https://www.maxmind.com/en/geoip-demo

https://sitereport.netcraft.com/? && https://searchdns.netcraft.com/

  • https://iocfeed.mrlooquer.com/

  • https://www.ipaddress.com/

  • GHDB (قاعدة بيانات القرصنة من جوجل): https://www.exploit-db.com/google-hacking-database

  • ورقة غش Google: https://gist.github.com/sundowndev/283efaddbcf896ab405488330d1bbc06

https://ciberpatrulla.com/links/

https://osintframework.com/

  • أدوات ومخططات وأوراق غش لمساعدتك في أبحاث OSINT: https://technisette.com/p/tools

  • تجميع: https://osint.link/

  • قاعدة بيانات النطاقات العالمية: http://web.archive.org/ && https://archive.eu/

  • بحث DNS: https://dns.coffee/

  • بحث الدفاع السيبراني: https://www.onyphe.io/

  • إساءة استخدام النطاق وIP: https://www.abuseipdb.com/

https://dns-lookup.jvns.ca/

https://www.greynoise.io/

https://www.brightcloud.com/tools/url-ip-lookup.php

  • فحص سمعة الرابط: https://www.urlvoid.com/

  • محرك البحث لإنترنت الأشياء: https://www.shodan.io/ && ورقة غش جميع الفلاتر: https://beta.shodan.io/search/filters

  • IVRE: https://ivre.rocks/

  • أدوات استخبارات التهديدات: https://cyberfive.uk/threat-intel-tools/

https://talosintelligence.com/

  • دليل PGP العالمي: https://keyserver2.pgp.com/vkd/GetWelcomeScreen.event

  • Hurricane Electric BGP: https://bgp.he.net/

  • Email2PhoneNumber: https://github.com/martinvigo/email2phonenumber

  • فحص ما إذا كان honeypot: https://honeyscore.shodan.io/

https://builtwith.com/

  • قاعدة بيانات البريد الإلكتروني المخترق TOR: http://pwndb2am4tzkvold.onion/

  • موقع للتحقق مما إذا كانت رسائل البريد الإلكتروني أو كلمات المرور قد تم اختراقها: https://haveibeenpwned.com/

  • التسريبات: https://leaks.sh/

  • Pwn DB: https://www.dehashed.com/?__cf_chl_jschl_tk__=ab484f797848c365ec48f7297ac4b9ba4587d775-1625827161-0-ARQgSNH3MSi0R4OUxmHmJCgUIz4nZrldFwXK6QZ21tONCEndyB_ypTCETLDm8vhRWeKD6v_ZraA5mbmvd03j1oeQb7QNsx5pg0lMhaNv2l7aw8DKR4a7ENkylr9knbiDx9X3RVn5AcH2uWuG_yRgk28j6x_zyccpXWc8LsTN9VxXZCZb16SEqwbuLdQ-JjWp0eQIgEMAPkLgosrsZyCdRa0A2mqMu8Mz4g-j4z8xR4v-4tqNwcP_TNtCK74-DIWZ80Zth2At6XizE72m_QifLrQH-gFUWPQ7hMzbNr5ONgZbyTZy_0YQA2SqHS5EUj5duq3WhbHdKEsRzXC6ch1EdQ5GagnSc8fH_NAqrI2aebrGF37HEXWkn7ZwxLGDLPAF63tV-77gQ4xhCnCDJp-vpcs

  • قاعدة بيانات البريد الإلكتروني المخترق: https://intelx.io/

  • قاعدة بيانات البريد الإلكتروني المخترق: https://cybernews.com/personal-data-leak-check/

  • PwnDB Script: https://github.com/davidtavarez/pwndb

  • ابحث عن بيانات الاعتماد المفلترة في نص عادي: https://esgeeks.com/pwndb-buscar-credenciales-filtradas-texto-plano/

  • فحص البريد الإلكتروني: https://toolbox.googleapps.com/apps/checkmx/

  • التعرف على السيارات: https://carnet.ai/

  • تحديد ساعة صورة، حاسبة الشمس: https://www.suncalc.org/#/27.6936,-97.5195,3/2024.01.09/09:23/1/3

مطاردة التهديدات

التحليل 1: https://centralops.net/co/

التحليل 2: https://viewdns.info/

التحليل 3: https://sitereport.netcraft.com/

التحليل 4: https://www.ipaddress.com/

البرمجيات الخبيثة: https://www.virustotal.com/gui/home/upload & https://opentip.kaspersky.com/

السمعة: https://talosintelligence.com/, https://www.abuseipdb.com/

تقنيات نطاق: https://builtwith.com/

أداة لتتبع مسارات إعادة توجيه الروابط: https://wheregoes.com/

سجل نطاق: https://web.archive.org/

قائمة الثقب الأسود الفورية، ASNs: https://bgp.he.net/

شهادات SSL: https://www.digicert.com/help/

عمليات إعادة التوجيه: https://lookyloo.circl.lu/

قاعدة بيانات نطاقات التصيد: http://phishtank.org/

قاعدة بيانات نطاقات التصيد: https://phishcheck.me/

نطاقات التصيد بصيغة CSV: https://phishstats.info/

أبحاث التصيد: https://safeweb.norton.com/ , https://isitphishing.org/, https://openphish.com/ && https://opentip.kaspersky.com/.

تجميع: https://osintframework.com/

تحليل حساب بريد إلكتروني: curl emailrep.io/john.[email protected]

التحليل الجنائي

  • تحليل PCAP عبر الإنترنت: https://lab.dynamite.ai/

  • أداة لتحديد النصوص من ملف pcap: https://github.com/bee-san/pyWhat. مثال: python3 -m pywhat redteam_test03-10423dd9015c050a40b7ccf2a53f57a9.pcapng > output

  • تحليل PCAP متقدم: https://www.kitploit.com/2023/08/bryobio-network-pcap-file-analysis.html

  • Wireshark. ورقة غش: https://cdn.comparitech.com/wp-content/uploads/2019/06/Wireshark-Cheat-Sheet-1.jpg

  • Volatility. ورقة غش: https://blog.onfvp.com/post/volatility-cheatsheet/ >>> Malfind,yarascan, Connscan و netscan

  • Foremost

  • Binwalk

  • Autopsy

  • PhotoRec: https://www.cgsecurity.org/wiki/PhotoRec

  • تحليل الصور الجنائي: https://29a.ch/photo-forensics/#forensic-magnifier

  • Recuva: https://www.ccleaner.com/recuva

  • المفاتيح: https://www.nirsoft.net/utils/product_cd_key_viewer.html

  • DDRescue. https://launchpad.net/ddrescue-gui

  • Rescuezilla: https://rescuezilla.com/

  • PolarProxy: https://www.netresec.com/?page=PolarProxy

  • MRC: https://www.magnetforensics.com/resources/magnet-ram-capture/

  • اكتساب الوسائط (من قرص إلى صورة): https://guymager.sourceforge.io/

https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/

https://blog.didierstevens.com/programs/xorsearch/

تجميع الأدلة الجنائية: https://start.me/p/JDRmPO/recursos-forenses && https://start.me/p/q6mw4Q/forensics

الهندسة العكسية

  • Binwalk

  • Dotpeek (.NET)

  • Angr(رمز بعد إزالة التعمية): https://angr.io/ && https://napongizero.github.io/blog/Defeating-Code-Obfuscation-with-Angr

  • مصحح أخطاء GameBoy: https://bgb.bircd.org/

  • IDA pro. ورقة غش: https://www.dragonjar.org/cheat-sheet-ida-pro-interactive-disassembler.xhtml

  • Ollydbg. ورقة غش: http://www.ollydbg.de/quickst.htm

  • GDB: https://gist.github.com/rkubik/b96c23bd8ed58333de37f2b8cd052c30

  • Radare2. ورقة غش: https://gist.github.com/williballenthin/6857590dab3e2a6559d7

  • Ghidra. ورقة غش: https://hackersfun.com/wp-content/uploads/2019/03/Ghidra-Cheat-Sheet.pdf

  • Immunity Debugger: https://www.immunityinc.com/products/debugger/

  • x64dbg

  • DnSpy https://github.com/dnSpy/dnSpy

  • Binary Ninja: https://binary.ninja/

  • أداة هندسة عكسية للمبتدئين: https://exeinfo-pe.en.uptodown.com/windows

  • Regshot: https://sourceforge.net/projects/regshot/ (قبل وبعد تشغيل ملف تنفيذي)

  • CFF explorer: https://download.cnet.com/CFF-Explorer/3000-2383_4-10431156.html

  • مفكك تجميع عبر الإنترنت: https://onlinedisassembler.com/static/home/index.html

الاستغلال

  • مثال 1: python -c "print 'A'*150" >>> ثم ./binario 150 A

python -c "print ('A' * 5100)"

  • مثال 2: (echo -e "\x31\xc0\x50\x68\x2f\x2f\x73\x68\x68\x2f\x62\x69\x6e\x89\xe3\x89\xc1\x89\xc2\xb0\x0b\xcd\x80\x31\xc0\x40\xcd\x80"; cat-) | ./binario (كود شيل لمعمارية x86 32 لينكس)

اختبار الاختراق

ورقة غش المنافذ الشائعة: https://packetlife.net/media/library/23/common_ports.pdf

ورقة غش تعداد الخدمات: https://pentestwiki.org/enumeration-cheat-sheet/

الاستطلاع

  • Nmap. ورقة غش: https://highon.coffee/blog/nmap-cheat-sheet/ && https://scadahacker.com/library/Documents/Cheat_Sheets/Hacking%20-%20NMap%20Quick%20Reference%20Guide.pdf

  • استطلاع نظام التشغيل: "إصدار خدمة https://launchpad.net/"

  • https://sitereport.netcraft.com/

  • GUI-DNSRecon: https://www.kitploit.com/2023/02/dnsrecon-gui-dnsrecon-tool-with-gui-for.html

  • enum4linux - https://highon.coffee/blog/enum4linux-cheat-sheet/

Dig: https://cheatography.com/tme520/cheat-sheets/dig/

wget -nd -r -P /save/location -A jpeg,jpg,bmp,gif,png http://www.somedomain.com

تنزيل ملفات تكراري مع تجاوز robots.txt: wget -e robots=off -drc -l5 domain* المسح بجهات خارجية: https://hackertarget.com/nmap-online-port-scanner/, https://www.ipfingerprints.com/, https://spiderip.com/online-port-scan.php, https://portscanner.standingtech.com/ && https://www.yougetsignal.com/tools/open-ports/

  • مشروع Scanless: https://github.com/vesche/scanless

  • قائمة رسائل البريد الإلكتروني من نطاق: https://maildump.co/domain-search

  • قائمة نطاقات شركة: Curl https://sonar.omnisint.io/tlds/

  • SPF,DKIM,DMARC: https://github.com/MattKeeley/Spoofy & https://www.kitploit.com/2023/02/email-vulnerablity-checker-find-email.html & https://github.com/magichk/magicspoofing && https://toolbox.googleapps.com/apps/checkmx/

  • تجزئات الشركة وكلمات المرور: https://www.dehashed.com/

  • dnsrecon -d dte.local -n IP - https://pentestlab.blog/2012/11/13/dns-reconnaissance-dnsrecon/

  • أكبر بيانات DNS تاريخية: https://securitytrails.com/

  • سجلات مضيف DNS: https://hackertarget.com/find-dns-host-records/

  • أداة تحليل ثغرات رؤوس HTTP: https://dnsdumpster.com/

  • ReconFTW: https://github.com/six2dez/reconftw

  • Autorecon: https://github.com/Tib3rius/AutoRecon

  • أداة جمع معلومات OSINT: https://github.com/s0md3v/Photon

  • أداة جمع معلومات OSINT: https://github.com/laramies/theHarvester

  • محلل DNS: https://github.com/d3mondev/puredns

الويب

  • Wappalyzer

  • whatweb -v -a 3 scanme.nmap.org

  • https://github.com/projectdiscovery/urlfinder

  • nmap -p 80 --script=http-*

  • أداة تحليل ثغرات رؤوس HTTP: https://github.com/Aetsu/gethead/blob/gh-pages/gethead.py

  • Feroxbuster

  • Gobuster. ورقة الغش: https://redteamtutorials.com/2018/11/19/gobuster-cheatsheet/

  • Burpsuite

  • OWASP ZAP وOpenVas وSparta وNikto. ورقة الغش: https://cdn.comparitech.com/wp-content/uploads/2019/07/NIkto-Cheat-Sheet.webp

  • Hydra. ورقة الغش: hydra -l admin -P /usr/share/wordlists/rockyou.txt IP http-post-form “__csrf_magic=sid%3Ae40fd9611063464c3ff346ffa53b7a28b3cd5971%2C1638348501&usernamefld=admin&passwordfld=^PASS^&login=Sign+In" || patator http_fuzz url=http://IP/ method=POST &usernamefld=admin&passwordfld=FILE0&login=Sign+In' 0=/usr/share/wordlists/rockyou.txt follow=1 accept_cookie=1 -x ignore:fgrep='Username or Password incorrect'

  • hydra -s 22 -l user -P /usr/share/wordlists/rockyou.txt IP -t 4 ssh

  • wfuzz. ورقة الغش: https://book.hacktricks.xyz/pentesting-web/web-tool-wfuzz

  • تجاوز المصادقة الثنائية 2FA: https://www.xmind.net/m/8Hkymg/

  • Dirbuster. https://mundo-hackers.weebly.com/dirbuster.html

  • Linkfinder: https://github.com/GerbenJavado/LinkFinder

  • Dirsearch: https://github.com/maurosoria/dirsearch

  • أداة تلقائية متكاملة لحقن أوامر نظام التشغيل واستغلالها: https://github.com/commixproject/commix

https://pentest-tools.com/home

https://book.hacktricks.xyz/

http://jsonviewer.stack.hu/

https://github.com/blaCCkHatHacEEkr/PENTESTING-BIBLE

https://jorgectf.gitbook.io/awae-oswe-preparation-resources/

  • نصائح الويب: https://www.nccgroup.com/globalassets/our-research/uk/images/common_security_issues_in_financially-orientated_web.pdf.pdf

قاعدة بيانات الاستغلالات

  • بحث CVE: https://github.com/Anonimo501/cve_search

  • https://www.exploit-db.com/

  • SearchSploit. ورقة الغش: https://blog.ehcgroup.io/2018/11/27/01/00/39/4198/como-usar-searchsploit-para-encontrar-exploits/hacking/ehacking/

  • https://cvexploits.io/

Docker

تصعيد الامتيازات: docker run -v /:/mnt --rm -it imagen chroot /mnt sh

بيانات الاعتماد

  • بيانات اعتماد IT الافتراضية: https://github.com/ihebski/DefaultCreds-cheat-sheet/blob/main/DefaultCreds-Cheat-Sheet.csv
  • بيانات اعتماد OT الافتراضية: https://www.icsrank.com/

قاعدة بيانات ثغرات CVE

https://vulners.com/

الاستغلال

  • مولّد Reverse Shell عبر الإنترنت: https://www.revshells.com/

  • ورقة الغش الخاصة بـ Reverse Shell: https://reconshell.com/reverse-shell-cheat-sheet/ && ورقة الغش: https://github.com/swisskyrepo/PayloadsAllTheThings/blob/master/Methodology%20and%20Resources/Reverse%20Shell%20Cheatsheet.md

  • Webshells: https://github.com/BlackArch/webshells

  • Popshells: https://github.com/0x00-0x00/ShellPop

  • ترقية القذائف البسيطة إلى محطات TTY تفاعلية بالكامل: https://blog.ropnop.com/upgrading-simple-shells-to-fully-interactive-ttys/

  • crackmapexec - https://cheatsheet.haax.fr/windows-systems/exploitation/crackmapexec/

  • أمثلة على أوامر Rundll32: https://www.jesusninoc.com/04/12/rundll32-commands-for-windows/

  • rdesktop IP, proxychains IP

  • sqlmap - https://www.security-sleuth.com/sleuth-blog/2017/1/3/sqlmap-cheat-sheet

  • مولّد حمولة Reverse Shell - Hoaxshell: https://github.com/t3l3machus/hoaxshell

  • تنفيذ الأوامر على Microsoft Exchange: https://github.com/WithSecureLabs/peas

  • Powerglot: https://github.com/mindcrypt/powerglot

Active Directory

  • ماسح الشبكة: https://www.softperfect.com/products/networkscanner/

  • linWinPwn: https://github.com/lefayjey/linWinPwn

  • Mimikatz: https://book.hacktricks.xyz/windows-hardening/stealing-credentials/credentials-mimikatz

  • Crackmapexec: https://cheatsheet.haax.fr/windows-systems/exploitation/crackmapexec/

  • تعداد LDAP: https://pentestwiki.org/enumeration-cheat-sheet/#h-ldap-enumeration

  • فحص Seatbelt: https://github.com/GhostPack/Seatbelt

  • Bloodhound: https://bloodhound.readthedocs.io/en/latest/index.html

  • Adalanche: https://www.kitploit.com/2021/08/adalanche-active-directory-acl.html

تصعيد الامتيازات

Windows

sudo apt install peass

  • WinPEAS: https://github.com/carlospolop/privilege-escalation-awesome-scripts-suite/tree/master/winPEAS

  • Juicy potato: https://github.com/ohpe/juicy-potato

  • PowerUp: https://github.com/PowerShellMafia/PowerSploit/blob/dev/Privesc/PowerUp.ps1

Linux

  • LinPEAS: https://github.com/carlospolop/privilege-escalation-awesome-scripts-suite/tree/master/linPEAS

  • LinEnum: https://github.com/rebootuser/LinEnum/blob/master/LinEnum.sh

  • BeRoot: https://github.com/AlessandroZ/BeRoot/tree/master/Linux

الملفات الثنائية الشرعية في النظام

  • Lolbas من Windows: https://lolbas-project.github.io/

  • GTFOBins لأنظمة Unix: https://gtfobins.github.io/

تجاوز برامج مكافحة الفيروسات

  • تجاوز Windows Defender باستخدام الملفات الثنائية: https://github.com/Bl4ckM1rror/FUD-UUID-Shellcode

  • Shikata ga nai: https://github.com/EgeBalci/sgn

  • مراوغة برامج مكافحة الفيروسات: https://github.com/Veil-Framework/Veil-Evasion

  • Shellter: https://www.kali.org/tools/shellter/

الأطر التلقائية

  • Metasploit. ورقة الغش: https://github.com/k1000o23/cheat_sheets/blob/master/metasploit_cheat_sheet.pdf

  • Kaboom: https://github.com/Leviathan36/kaboom

  • إطار عمل Fsociety: https://github.com/Manisso/fsociety

  • Empire. ورقة الغش: https://github.com/HarmJ0y/CheatSheets/blob/master/Empire.pdf

الجوال

  • ورقة الغش لاختبار اختراق الجوال: https://github.com/tanprathan/MobileApp-Pentest-Cheatsheet && https://github.com/randorisec/MobileHackingCheatSheet

  • أدوات الجوال التلقائية: https://github.com/MobSF/Mobile-Security-Framework-MobSF, https://github.com/SUPERAndroidAnalyzer/super

  • قائمة تطبيقات Android الضعيفة: https://github.com/netbiosX/Pentest-Bookmarks/blob/master/Training-Labs/Mobile-Testing/Android-Applications.mdown

  • PcapDroid: https://play.google.com/store/apps/details?id=com.emanuelef.remote_capture&hl=es_419&gl=US

الواي فاي

  • تطبيق Fing: https://www.fing.com/

  • محلل الواي فاي: https://play.google.com/store/apps/details?id=com.farproc.wifi.analyzer&hl=es&gl=US&pli=1

  • تدقيق الواي فاي: https://github.com/v1s1t0r1sh3r3/airgeddon

  • https://en.kali.tools/?p=244

  • اختراق الواي فاي: https://github.com/s4vitar/wifiCrack

  • Fern: https://github.com/savio-code/fern-wifi-cracker

  • EvilTrust: https://github.com/s4vitar/evilTrust

  • RomBuster: https://github.com/EntySec/RomBuster

Yersinia

Bettercap

Wifi Pineapple

https://linuxhint.com/how_to_aircrack_ng/

  • اختراق التقاطات PCAP: https://www.onlinehashcrack.com/

الأدوات المساعدة

  • mount -t cifs IP/SharedResource /mnt/smbmounted -o vers=2.1 && * smbclient -U "" -N //IP/SharedResource

  • dpkg -l لسرد جميع البرامج المثبتة في جهاز افتراضي. مرّر الإخراج للبحث عما تريد.

  • Msfvenom: https://www.offensive-security.com/metasploit-unleashed/msfvenom/ & https://www.offensive-security.com/metasploit-unleashed/binary-payloads/

  • Nishang: https://github.com/samratashok/nishang

  • هل أنت محظور؟: https://ippsec.rocks/?#

  • بأسلوب OSCP: https://gist.github.com/s4vitar/b88fefd5d9fbbdcc5f30729f7e06826e

  • Pentest-book: https://pentestbook.six2dez.com/ && https://book.hacktricks.xyz/pentesting-methodology

  • فيديوهات: https://www.youtube.com/c/S4viOnLive

البرمجيات الخبيثة

المحركات عبر الإنترنت

  • الأفضل: https://omniasec.ai/

  • https://www.filescan.io/

  • Virustotal: https://www.virustotal.com/gui/home/search

  • صندوق رمل Cuckoo عبر الإنترنت: https://sandbox.pikker.ee/

  • إضافات المتصفح: https://spin.ai/application-risk-assessment/

  • ملفات APK: https://mobsf.live/ && https://koodous.com/

  • Joesandbox: https://www.joesandbox.com/#windows

  • Kaspersky: https://opentip.kaspersky.com/

  • Intezer: https://analyze.intezer.com/scan

  • Hybrid Analysis: https://www.hybrid-analysis.com/?lang=es

  • قاعدة بيانات المواقع المتعلقة بالتزييف: https://desenmascara.me/

  • ANY.RUN https://any.run/

https://antiscan.me/

https://www.virscan.org/

  • Polyswarm: https://polyswarm.network

https://metadefender.opswat.com/?lang=en

توزيعات لتحليل البرمجيات الخبيثة

  • مجموعة أدوات هندسة عكسية مدعومة بالذكاء الاصطناعي تعمل على Windows: https://github.com/Jakiboy/ReVens

  • توزيعة Linux للتحقيق في البرمجيات الخبيثة: https://docs.remnux.org/

  • توزيعة Windows للتحقيق في البرمجيات الخبيثة: https://github.com/mandiant/flare-vm

  • https://github.com/LaurieWired/linux_malware_analysis_container

الأدوات

  • Sysinternals: https://docs.microsoft.com/en-us/sysinternals/

  • Systeminformer: https://systeminformer.sourceforge.io/

  • Capa: https://github.com/mandiant/capa

  • Detect it easy(كاشف أدوات التغليف): https://en.kali.tools/?p=1644

  • Sysinspector: https://support.eset.com/es/que-es-eset-sysinspector

  • Dependency Walker لملف تنفيذي: https://www.dependencywalker.com/

  • Autoruns: https://docs.microsoft.com/en-us/sysinternals/downloads/autoruns

  • أداة التقاط ذاكرة RAM: https://belkasoft.com/ram-capturer

  • تجميعة: https://github.com/rshipp/awesome-malware-analysis

  • مجموعة أدوات المهندس العكسي: https://github.com/mentebinaria/retoolkit

  • PEstudio: https://www.winitor.com/

  • Malzilla: https://malzilla.org/

  • PROCMON+PCAP: https://www.procdot.com/

  • تحليل ملفات APK: https://github.com/quark-engine/quark-engine && https://github.com/mvt-project/mvt && https://github.com/pjlantz/droidbox

  • XORSearch: https://blog.didierstevens.com/programs/xorsearch/

برامج مكافحة الفيروسات المجانية وأنظمة EDR وصناديق الرمل

  • ClamAV: https://www.clamav.net/downloads#otherversions

  • مكافح فيروسات MAC: https://www.pcrisk.es/mejores-programas-antivirus/8365-combo-cleaner-antivirus-and-system-optimizer-mac

  • صندوق الرمل: https://github.com/CERT-Polska/drakvuf-sandbox

  • DragonFly: https://dragonfly.certego.net/register

  • صندوق رمل دون اتصال: https://sandboxie-plus.com/downloads/

  • OpenEDR: https://github.com/ComodoSecurity/openedr

برامج الفدية

  • أدوات فك تشفير برامج الفدية: http://files-download.avg.com/util/avgrem/avg_decryptor_Legion.exe, https://success.trendmicro.com/solution/1114221-downloading-and-using-the-trend-micro-ransomware-file-decryptor, https://www.nomoreransom.org/es/decryption-tools.htmlm, https://www.avast.com/es-es/ransomware-decryption-tools , https://noransom.kaspersky.com/ , https://www.mcafee.com/enterprise/es-es/downloads/free-tools/ransomware-decryption.html, https://www.mcafee.com/enterprise/en-us/downloads/free-tools.html, https://www.emsisoft.com/ransomware-decryption-tools/, https://decoded.avast.io/threatresearch/decrypted-bianlian-ransomware/.

  • نظرة عامة: https://docs.google.com/spreadsheets/d/1TWS238xacAto-fLKh1n5uTsdijWdCEsGIM0Y0Hvmc5g/pubhtml#

  • مجموعات برامج الفدية: http://edteebo2w2bvwewbjb5wgwxksuwqutbg3lk34ln7jpf3obhy4cvkbuqd.onion/

APTs

  • استخبارات: https://docs.google.com/spreadsheets/d/1H9_xaxQHpWaa4O_Son4Gx0YOIzlcBWMsdvePFX68EKU/pubhtml# && https://github.com/StrangerealIntel/EternalLiberty/blob/main/EternalLiberty.csv && https://xorl.wordpress.com/

  • الرسم البياني المعرفي للجهات الفاعلة في التهديدات: https://jupyter.securitybreak.io/graph_TA/index.html

هل أنت هدف لـ APT؟ -> https://lab52.io/

  • محاكي APT: https://github.com/NextronSystems/APTSimulator

المدونات والمعلومات

  • الماكرو: https://blog.didierstevens.com/2021/01/19/video-maldoc-analysis-with-cyberchef/ && https://blog.nviso.eu/2022/04/06/analyzing-a-multilayer-maldoc-a-beginners-guide/

  • أمثلة/ملفات ثنائية للبرمجيات الخبيثة: https://bazaar.abuse.ch/, https://github.com/ytisf/theZoo & https://malshare.com/

الأدوات المساعدة

  • لتجاوز بعض المنافذ المفلترة: nmap -sSV ...

  • zip2john backup.zip secret.hash

  • john --show secret.hash

  • Hexeditor

  • nc -nlvp URL port

  • Grep

  • rgrep (grep تكراري)

  • awk

  • perl

  • tail / head

  • curl -Llv domain | curl -b "protected=d41d8cd98f00b204e9800998ecf8427e"(cookie) "domain"

  • Identify -verbose

  • Hash-identifier

  • cat 'file' | md5sum, sha1sum,sha256sum...

  • echo "string" | base64 -d

  • Strings

  • File

  • Cewl. ورقة الغش: https://null-byte.wonderhowto.com/how-to/hack-like-pro-crack-passwords-part-5-creating-custom-wordlist-with-cewl-0158855/

  • استعادة كلمة المرور عبر الإنترنت : https://www.lostmypass.com/try/

  • كلمات المرور المخزنة في جهاز كمبيوتر: https://github.com/AlessandroZ/LaZagne

  • صورة القرص: https://www.datanumen.com/disk-image-download-thanks/

  • crackzip: https://github.com/Xpykerz/CrackZip

  • zip2john: https://github.com/openwall/john/blob/bleeding-jumbo/src/zip2john.c

  • أداة إنشاء ملفات تعريف كلمات المرور الشائعة للمستخدمين: https://github.com/Mebus/cupp و https://github.com/r3nt0n/bopscrk.

  • Dig: https://cheatography.com/tme520/cheat-sheets/dig/

  • wget -nd -r -P /save/location -A jpeg,jpg,bmp,gif,png http://www.somedomain.com

الويكيات

https://github.com/JohnHammond/ctf-katana

https://github.com/OpenToAllCTF/Tips

درس في الهندسة العكسية: https://github.com/mytechnotalent/Reverse-Engineering-Tutorial

شروحات

https://ctftime.org/writeups

https://apsdehal.in/awesome-ctf/

https://jorgectf.gitlab.io/

https://github.com/0e85dc6eaf/CTF-Writeups

https://github.com/RazviOverflow/ctfs

https://github.com/DEKRA-CTF/CTFs/tree/main/2020

https://medium.com/bugbountywriteup/tryhackme-reversing-elf-writeup-6fd006704148

https://github.com/W3rni0/ctf_writeups_archive/tree/master/castorsCTF_2020

أدوات أخرى

https://github.com/zardus/ctf-tools

https://github.com/apsdehal/awesome-ctf

تنزيل الأداة
  • Bytehist: https://www.cert.at/en/downloads/software/software-bytehist

  • أغراض عامة: https://github.com/Moham3dRiahi/Th3inspector

  • بحث صور جوجل: https://www.google.es/imghp?hl=es , Yandex: https://yandex.com/images/ , Bing: https://www.bing.com/?scope=images&nr=1&FORM=NOFORM

  • البحث العكسي عن الصور: https://tineye.com/

  • أداة لتتبع مسارات إعادة توجيه الروابط: https://wheregoes.com/

  • فحص التصيد الاحتيالي عبر الإنترنت: https://easydmarc.com/tools/phishing-url

  • قاعدة بيانات نطاقات التصيد: http://phishtank.org/

  • قاعدة بيانات نطاقات التصيد: https://phishcheck.me/

  • أبحاث التصيد: https://safeweb.norton.com/ , https://isitphishing.org/, https://openphish.com/ && https://opentip.kaspersky.com/.

  • Instagram: https://github.com/th3unkn0n/osi.ig

  • Censys: https://censys.io/ipv4

  • Zoomeye.org: https://www.zoomeye.org/

  • IVRE: https://ivre.rocks/

  • محرك بحث إنترنت الأشياء: https://www.thingful.net/

  • اعثر على عناوين البريد الإلكتروني المرتبطة بنطاق: https://hunter.io/

  • محرك بحث عن الأشخاص: https://thatsthem.com/

  • محرك بحث Fofa: https://fofa.so/ (مشابه لـ Shodan)

  • منصة OSINT رسومية: https://www.spiderfoot.net/#

  • Fullhunt: https://fullhunt.io/

  • البحث في الأكواد البرمجية: https://grep.app/ && https://publicwww.com/

  • Natlas: https://natlas.io/

  • Spur: https://spur.us/

  • قاعدة بيانات الواي فاي العامة: https://www.mylnikov.org/

  • ترويسات HTTP لنطاق: https://www.webconfs.com/http-header-check.php

  • البيانات الوصفية للمستندات العامة: https://github.com/Josue87/MetaFinder

  • Twitter: https://github.com/twintproject/twint && https://tinfoleak.com/

  • https://github.com/Quantika14/osint-suite-tools

  • افحص OWA الخاص بك (Outlook Web Access): https://checkmyowa.unit221b.com/

  • Whatspp IP Leak: https://github.com/bhdresh/Whatsapp-IP-leak?s=09

  • كتاب: https://i-intelligence.eu/uploads/public-documents/OSINT_Handbook_2020.pdf

  • البحث والاصطياد السريع في سجلات أحداث Windows: https://github.com/countercept/chainsaw

  • AccessData FTK Imager

  • EnCase

  • EaseUS Data Recovery Wizard

  • Testdisk: https://www.cgsecurity.org/wiki/TestDisk_Download

  • MFT_Browser: https://github.com/kacos2000/MFT_Browser

  • Powershell Decoder: https://github.com/R3MRUM/PSDecode, https://github.com/JohnLaTwC/PyPowerShellXray ومعلومات التحليل: https://darungrim.com/research/2019-10-01-analyzing-powershell-threats-using-powershell-debugging.html

  • محلل PDF: https://github.com/zbetcheckin/PDF_analysis, https://github.com/DidierStevens/DidierStevensSuite/blob/master/pdfid.py, https://github.com/DidierStevens/DidierStevensSuite/blob/master/pdf-parser.py و https://eternal-todo.com/tools/peepdf-pdf-analysis-tool.

  • محلل ملفات Office: https://github.com/DissectMalware/XLMMacroDeobfuscator, https://github.com/unixfreak0037/officeparser, https://github.com/decalage2/oletools, https://github.com/bontchev/pcodedmp, https://github.com/decalage2/ViperMonkey && https://blog.didierstevens.com/programs/oledump-py/.

  • استخراج المحتوى المشفر بـ Unicode من ملف: https://github.com/DidierStevens/DidierStevensSuite/blob/master/base64dump.py

  • ترددات الهاتف DTMF: https://unframework.github.io/dtmf-detect/

  • لفك مفاتيح WPA: pyrit -r "capctura.pcap" analyze

  • Diskeditor: https://www.disk-editor.org/index.html

  • محلل تشفير Passware: https://www.passware.com/encryption-analyzer/

  • استعادة سجل Windows: https://www.softpedia.com/get/Tweak/Registry-Tweak/Windows-Registry-Recovery.shtml

  • أمر xxd

  • ورقة غش الفريق الأزرق: https://itblogr.com/wp-content/uploads/2020/04/The-Concise-Blue-Team-cheat-Sheets.pdf

  • ورقة غش DFIR: https://www.jaiminton.com/cheatsheet/DFIR/#

  • تحليل وكيل المستخدم: https://developers.whatismybrowser.com/useragents/parse/

  • ورقة غش grep: https://javiermartinalonso.github.io/linux/2018/01/15/linux-grep-patrones-debug.html

  • مدونة: https://www.osintme.com/

  • تعبيرات نمطية لـ grep -Po " " https://www.autoregex.xyz/ && https://regex101.com/ . ورقة غش: https://cheatography.com/davechild/cheat-sheets/regular-expressions/

  • ورقة غش DFIR: https://dfircheatsheet.github.io/

  • مستكشف مفكك الترجمة عبر الإنترنت: https://dogbolt.org/

  • مستكشف المترجمات عبر الإنترنت: https://godbolt.org/

  • محول .JAR و .Class إلى Java عبر الإنترنت: http://www.javadecompilers.com/

  • محرر سداسي عشري، ومحرر أقراص، ومحرر ذاكرة: https://mh-nexus.de/en/downloads.php?product=HxD20

  • مفكك تطبيقات أندرويد: https://ibotpeaches.github.io/Apktool/

  • فك تحويل ملفات أندرويد: https://github.com/skylot/jadx

  • Hopper disassembler: https://www.hopperapp.com/

  • سرد التبعيات الديناميكية: ldd file

  • فك تغليف بعض الملفات التنفيذية: upx -d file

  • تحديد أدوات التغليف: https://github.com/horsicq/Detect-It-Easy

  • نظرية: https://0xinfection.github.io/reversing/

  • دليل مطور البرمجيات لبنية Intel® 64 و IA-32: https://www.intel.com/content/dam/www/public/us/en/documents/manuals/64-ia-32-architectures-software-developer-instruction-set-reference-manual-325383.pdf

  • نصائح: https://blog.whtaguy.com/2020/04/guys-30-reverse-engineering-tips-tricks.html

  • Sublist3r: https://github.com/aboul3la/Sublist3r

  • Ffuf: https://github.com/ffuf/ffuf

  • Nuclei: https://github.com/projectdiscovery/nuclei

  • النطاقات المنتهية: https://www.expireddomains.net/

  • أداة XSS تلقائية: https://xsser.03c8.net/

  • أداة XSS تلقائية: https://github.com/ssl/ezXSS

  • RECOX: https://github.com/samhaxr/recox/blob/master/recox.sh

  • أمثلة على حمولات SQL: https://github.com/payloadbox/sql-injection-payload-list

  • حقن الأوامر: https://github.com/payloadbox/command-injection-payload-list

  • XSS في 2021: https://netsec.expert/posts/xss-in-2021/

  • ورقة الغش الخاصة بـ SSRF: https://highon.coffee/blog/ssrf-cheat-sheet/#curl-ssrf-wrappers--url-schema

  • WPscan

  • أداة البحث بإضافة فايرفوكس XSS: https://addons.mozilla.org/es/firefox/addon/knoxss-community-edition/

  • فحص رؤوس HTTP: https://requestbin.net/ && https://webhook.site/#!/75039a57-2015-4f74-9612-b762f4353b9b && https://securityheaders.com/?q=domain&followRedirects=on

  • مفكك ترميز RAT: https://github.com/kevthehermit/RATDecoders

  • Malwoverview: https://github.com/alexandreborges/malwoverview

  • مستخرج السلاسل النصية الثنائية: https://github.com/fireeye/flare-floss

  • تحليل الشبكة للبرمجيات الخبيثة (محاكاة خادم HTTP): https://github.com/felixweyne/imaginaryC2

  • تتيح لك هذه الأداة اعتراض وإعادة توجيه كل حركة مرور الشبكة أو جزء منها مع محاكاة خدمات شبكة مشروعة: https://github.com/mandiant/flare-fakenet-ng

  • تنزيل ملفات تكراري متجاوزًا robots.txt: wget -e robots=off -drc -l5 domain

  • [تسريب عبر ICMP] tshark -r 1pcap_test_1c.pcapng -Y "icmp" -Tjson | grep data.data | awk {'print $2'} | cut -c 2-3 | uniq | xxd -r -p

  • أوامر سطر واحد: https://linuxcommandlibrary.com/basic/oneliners.html

  • معلومات Google: image