
مجموعة من المقالات الأمنية عالية الجودة. مقالات رائعة.
مجموعة من المقالات عالية الجودة حول السلامة (سيتم إعادة بناؤها)```
Some are inconvenient to release.
Some forget update,can see me star.
collection-document awesome
以前的链接中大多不是优质的
渗透测试部分不再更新
因精力有限,缓慢更新
Author: [tom0li]
Blog: https://tom0li.github.io
- [وصف المشروع](#project-description)
- [قائمة جيتهاب](#github-list)
- [قائمة رائعة](#awesome-list)
- [تطوير](#开发)
- [أخرى](#其它)
- [الأمان](#安全)
- [قائمة الأمان](#安全list)
- [رؤى سوق الأمان](#安全市场洞察)
- [أمان السحابة](#云安全)
- [أساسيات السحابة](#云基础知识)
- [أمان السحابة الأصلية](#云原生安全)
- [الهجوم والدفاع على السحابة](#云上攻防)
- [VM](#vm)
- [vCenter](#vcenter)
- [SLP](#slp)
- [أمان الذكاء الاصطناعي](#ai安全)
- [حلول الأمان الجديدة](#新安全方案)
- [بناء الجيل التالي من الأمان](#构建下一代安全)
- [الثقة الصفرية](#零信任)
- [DevSecOps](#devsecops)
- [كشف التهديدات](#威胁检测)
- [RASP](#rasp)
- [HIDS](#hids)
- [WAF](#waf)
- [دليل بناء WAF](#waf建设指南)
- [BypassWAF](#bypasswaf)
- [كشف Webshell](#webshell检测)
- [كشف الصدى العكسي](#反弹shell检测)
- [EDR](#edr)
- [AV](#av)
- [كشف الحركة الجانبية – أفكار HoneyPot](#横向移动检测-蜜罐思路)
- [كشف حركة المرور الضارة](#恶意流量检测)
- [IDS](#ids)
- [كشف النصوص](#文本检测)
- [عمليات الأمان](#安全运营)
- [أمان البيانات](#数据安全)
- [مسح الشبكة](#网络测绘)
- [أمان الاتصالات](#通信安全)
- [اتصال نهاية إلى نهاية (إصدار أولي)](#端对端通信初版)
- [SNI](#sni)
- [الأمان الشخصي](#个人安全)
- [أبحاث APT](#apt研究)
- [قائمة التهديدات المتقدمة](#高级威胁-list)
- [استخبارات التهديدات](#威胁情报)
- [التصيد](#钓鱼)
- [C2-RAT](#c2-rat)
- [التحذير والبحث](#预警研究)
- [ImageMagick](#imagemagick)
- [Exchange](#exchange)
- [Privilege-Escalation](#privilege-escalation)
- [VPN](#vpn)
- [Sangfor](#sangfor)
- [Pulse](#pulse)
- [Palo](#palo)
- [Fortigate](#fortigate)
- [Citrix Gateway/ADC](#citrix-gatewayadc)
- [Tomcat](#tomcat)
- [FUZZING](#fuzzing)
- [مراجعة الكود - JAVA](#代码审计-java)
- [إلغاء التسلسل - أخرى](#反序列化-其他)
- [RMI](#rmi)
- [Shiro](#shiro)
- [Fastjson](#fastjson)
- [Dubbo](#dubbo)
- [CAS](#cas)
- [حقن قالب Solr](#solr模版注入)
- [Apache Skywalking](#apache-skywalking)
- [Spring](#spring)
- [Spring-boot](#spring-boot)
- [Spring-cloud](#spring-cloud)
- [Spring-data](#spring-data)
- [سلسلة الكتل](#区块链)
- [الاختراق](#渗透)
- [اختراق الحدود](#边界渗透)
- [سجلات الاختراق وملخصات](#渗透记录和总结)
- [جمع المعلومات](#信息收集)
- [ميدان التدريب](#靶场)
- [تقنيات الاختراق](#渗透技巧)
- [اختراق الشبكة الداخلية](#内网渗透)
- [استغلال Exchange (قديم)](#exchange利用旧)
- [hash ticket Credential](#hash-ticket-credential)
- [الوكالة وإعادة توجيه المنافذ وإعادة استخدام المنافذ](#代理转发与端口复用)
- [منصات الشبكة الداخلية](#内网平台)
- [تقنيات الشبكة الداخلية](#内网技巧)
- [استغلال رفع الامتيازات](#提权利用)
- [Bug_Bounty](#bug_bounty)
- [Web](#web)
- [XXE](#xxe)
- [XSS](#xss)
- [Jsonp](#jsonp)
- [CORS](#cors)
- [CSRF](#csrf)
- [SSRF](#ssrf)
- [SQL](#sql)
- [تضمين الملفات](#文件包含)
- [رفع](#上传)
- [قراءة ملفات عشوائية](#任意文件读取)
- [خداع ذاكرة التخزين المؤقت للويب](#web缓存欺骗)
- [تسميم ذاكرة التخزين المؤقت للويب](#web缓存投毒)
- [SSI](#ssi)
- [SSTI](#ssti)
- [JS](#js)
- [DNS](#dns)
- [أخرى](#其他)
- [Git](#git)
- [رمز QR](#二维码)
- [الزاحف](#爬虫)
- [الكفاءة](#效率)
- [تبسيط العلوم](#科普)
- [ساهم](#contribute)
- [شكر وتقدير](#acknowledgments)
- [نجمة](#star)
## قائمة جيتهاب
### قائمة رائعة
* [awesome-web-security](https://github.com/qazbnm456/awesome-web-security)
* [Awesome-Hacking](https://github.com/Hack-with-Github/Awesome-Hacking) - قائمة بألف نجم
* [awesome-malware-analysis](https://github.com/rshipp/awesome-malware-analysis)
* [Android Security](https://github.com/ashishb/android-security-awesome) - مجموعة من الموارد المتعلقة بأمان Android.
* [Security](https://github.com/sbilly/awesome-security) - برامج، مكتبات، وثائق، وموارد أخرى.
* [An Information Security Reference That Doesn't Suck](https://github.com/rmusser01/Infosec_Reference)
* [Security Talks](https://github.com/PaulSec/awesome-sec-talks) - قائمة مختارة من مؤتمرات الأمان.
* [OSINT](https://github.com/jivoi/awesome-osint) - قائمة رائعة تحتوي على موارد عظيمة.
* [The toolbox of open source scanners](https://github.com/We5ter/Scanners-Box) - صندوق أدوات الماسحات الضوئية مفتوحة المصدر
* [blackhat-arsenal-tools](https://github.com/toolswatch/blackhat-arsenal-tools) - مستودع أدوات أسلحة بلاك هات الرسمية
* [awesome-iot-hacks](https://github.com/nebgnahz/awesome-iot-hacks)
* [awesome-awesome](https://github.com/emijrp/awesome-awesome)
* [Curated list of awesome lists](https://github.com/sindresorhus/awesome)
* [Awesome Awesomness](https://github.com/bayandin/awesome-awesomeness) - قائمة القوائم.
* [PENTESTING-BIBLE](https://github.com/blaCCkHatHacEEkr/PENTESTING-BIBLE) - محتوى متعلق بالأمان
* [Web-Security-Learning](https://github.com/CHYbeta/Web-Security-Learning) - بواسطة CHYbeta
* [Software-Security-Learning](https://github.com/CHYbeta/Software-Security-Learning) - بواسطة CHYbeta
* [MiscSecNotes](https://github.com/JnuSimba/MiscSecNotes) - ملاحظات JnuSimba
* [AndroidSecNotes](https://github.com/JnuSimba/AndroidSecNotes) - ملاحظات
* [LinuxSecNotes](https://github.com/JnuSimba/LinuxSecNotes) - ملاحظات
* [resource collection of python security and code review](https://github.com/bit4woo/python_sec)
* [Pentest_Interview](https://github.com/Leezj9671/Pentest_Interview)
* [مصادر معلومات tanjiti](https://github.com/tanjiti/sec_profile) - بواسطة tanjiti من بايدو، مصادر معلومات أمان يومية ممسوحة
* [CVE-Flow](https://github.com/404notf0und/CVE-Flow) - بواسطة 404notfound، مراقبة تحديثات CVE المتزايدة، تنبؤ CVE EXP قائم على التعلم العميق ودفع آلي
* [security_w1k1](https://github.com/euphrat1ca/security_w1k1/) euphrat1ca يحدث المخازن المتعلقة بالأمان باستمرار
### تطوير
* [مسح شامل للمعرفة المتقدمة لمهندس Java عبر الإنترنت](https://github.com/doocs/advanced-java)
* [دليل تعلم Java + مقابلة: يغطي المعرفة الأساسية التي يحتاج معظم مبرمجي Java إتقانها](https://github.com/Snailclimb/JavaGuide)
* [Python Cheat Sheet ](https://github.com/crazyguitar/pysheeet)
* [مجموعة من الموارد الشاملة للمبرمجين](https://github.com/charlax/professional-programming)
* [web, frontend, javascript, nodejs, electron, babel, webpack, rollup, react, vue ...](https://github.com/senntyou/blogs)
* [أسئلة مقابلة حول Python](https://github.com/taizilongxu/interview_python)
* [Python-100-Days](https://github.com/jackfrued/Python-100-Days)
* [python3-source-code-analysis](https://github.com/flaggo/python3-source-code-analysis)
* [Coding Interview University](https://github.com/jwasham/coding-interview-university)
* [tech-interview-handbook](https://github.com/yangshun/tech-interview-handbook) - جيد
* [المعرفة الأساسية اللازمة للمقابلات](https://github.com/CyC2018/CS-Notes)
* [أساسيات CS](https://github.com/selfboot/CS_Offer/)
* [ملاحظات مقابلة حول الخوارزميات/التعلم العميق/NLP](https://github.com/imhuay/Algorithm_Interview_Notes-Chinese)
* [مذكرة الخوارزميات](https://github.com/labuladong/fucking-algorithm)
* [50 تنفيذ كود يجب معرفته لهياكل البيانات والخوارزميات](https://github.com/wangzheng0822/algo)
* [interview_internal_reference](https://github.com/0voice/interview_internal_reference)
* [reverse-interview](https://github.com/yifeikong/reverse-interview-zh) - أسئلة لطرحها على القائم بالمقابلة في نهاية المقابلة الفنية
### أخرى