
Sammlung von qualitativ hochwertigen Sicherheitsartikeln. Fantastische Artikel.
Sammlung von hochwertigen Sicherheitsartikeln (wird neu aufgebaut)```
Some are inconvenient to release.
Some forget update,can see me star.
collection-document awesome
以前的链接中大多不是优质的
渗透测试部分不再更新
因精力有限,缓慢更新
Author: [tom0li]
Blog: https://tom0li.github.io
- [Projektbeschreibung](#project-description)
- [Github-Liste](#github-list)
- [Awesome-Liste](#awesome-list)
- [Entwicklung](#entwicklung)
- [Sonstiges](#sonstiges)
- [Sicherheit](#sicherheit)
- [Sicherheitsliste](#sicherheitsliste)
- [Sicherheitsmarkteinblicke](#sicherheitsmarkteinblicke)
- [Cloud-Sicherheit](#cloud-sicherheit)
- [Cloud-Grundlagen](#cloud-grundlagen)
- [Cloud-native Sicherheit](#cloud-native-sicherheit)
- [Angriff und Verteidigung in der Cloud](#angriff-und-verteidigung-in-der-cloud)
- [VM](#vm)
- [vCenter](#vcenter)
- [SLP](#slp)
- [KI-Sicherheit](#ki-sicherheit)
- [Neue Sicherheitslösungen](#neue-sicherheitslösungen)
- [Aufbau der nächsten Generation von Sicherheit](#aufbau-der-nächsten-generation-von-sicherheit)
- [Zero Trust](#zero-trust)
- [DevSecOps](#devsecops)
- [Bedrohungserkennung](#bedrohungserkennung)
- [RASP](#rasp)
- [HIDS](#hids)
- [WAF](#waf)
- [Leitfaden zum Aufbau von WAF](#leitfaden-zum-aufbau-von-waf)
- [BypassWAF](#bypasswaf)
- [Webshell-Erkennung](#webshell-erkennung)
- [Reverse-Shell-Erkennung](#reverse-shell-erkennung)
- [EDR](#edr)
- [AV](#av)
- [Erkennung lateraler Bewegung – Honeypot-Ansatz](#erkennung-lateraler-bewegung--honeypot-ansatz)
- [Erkennung bösartigen Datenverkehrs](#erkennung-bösartigen-datenverkehrs)
- [IDS](#ids)
- [Texterkennung](#texterkennung)
- [Sicherheitsbetrieb](#sicherheitsbetrieb)
- [Datensicherheit](#datensicherheit)
- [Netzwerkkartierung](#netzwerkkartierung)
- [Kommunikationssicherheit](#kommunikationssicherheit)
- [Ende-zu-Ende-Kommunikation (Erstversion)](#ende-zu-ende-kommunikation-erstversion)
- [SNI](#sni)
- [Persönliche Sicherheit](#persönliche-sicherheit)
- [APT-Forschung](#apt-forschung)
- [Erweiterte Bedrohungen-Liste](#erweiterte-bedrohungen-liste)
- [Bedrohungsinformationen](#bedrohungsinformationen)
- [Phishing](#phishing)
- [C2-RAT](#c2-rat)
- [Warnung & Forschung](#warnung--forschung)
- [ImageMagick](#imagemagick)
- [Exchange](#exchange)
- [Privilege Escalation](#privilege-escalation)
- [VPN](#vpn)
- [Sangfor](#sangfor)
- [Pulse](#pulse)
- [Palo](#palo)
- [Fortigate](#fortigate)
- [Citrix Gateway/ADC](#citrix-gatewayadc)
- [Tomcat](#tomcat)
- [FUZZING](#fuzzing)
- [Code-Audit-JAVA](#code-audit-java)
- [Deserialisierung – Sonstiges](#deserialisierung--sonstiges)
- [RMI](#rmi)
- [Shiro](#shiro)
- [Fastjson](#fastjson)
- [Dubbo](#dubbo)
- [CAS](#cas)
- [Solr-Vorlageninjektion](#solr-vorlageninjektion)
- [Apache Skywalking](#apache-skywalking)
- [Spring](#spring)
- [Spring Boot](#spring-boot)
- [Spring Cloud](#spring-cloud)
- [Spring Data](#spring-data)
- [Blockchain](#blockchain)
- [Penetration](#penetration)
- [Perimeter-Penetration](#perimeter-penetration)
- [Penetrationsaufzeichnungen und Zusammenfassungen](#penetrationsaufzeichnungen-und-zusammenfassungen)
- [Informationssammlung](#informationssammlung)
- [Übungsplätze](#übungsplätze)
- [Penetrationstechniken](#penetrationstechniken)
- [Intranet-Penetration](#intranet-penetration)
- [Exchange-Ausnutzung (alt)](#exchange-ausnutzung-alt)
- [Hash-Ticket-Credential](#hash-ticket-credential)
- [Proxy-Weiterleitung und Port-Wiederverwendung](#proxy-weiterleitung-und-port-wiederverwendung)
- [Intranet-Plattform](#intranet-plattform)
- [Intranet-Tipps](#intranet-tipps)
- [Privilegienausweitung](#privilegienausweitung)
- [Bug Bounty](#bug-bounty)
- [Web](#web)
- [XXE](#xxe)
- [XSS](#xss)
- [JSONP](#jsonp)
- [CORS](#cors)
- [CSRF](#csrf)
- [SSRF](#ssrf)
- [SQL](#sql)
- [Dateieinschluss](#dateieinschluss)
- [Upload](#upload)
- [Beliebiger Dateilesezugriff](#beliebiger-dateilesezugriff)
- [Web-Cache-Täuschung](#web-cache-täuschung)
- [Web-Cache-Vergiftung](#web-cache-vergiftung)
- [SSI](#ssi)
- [SSTI](#ssti)
- [JS](#js)
- [DNS](#dns)
- [Sonstiges](#sonstiges-1)
- [Git](#git)
- [QR-Code](#qr-code)
- [Webcrawler](#webcrawler)
- [Effizienz](#effizienz)
- [Populärwissenschaft](#populärwissenschaft)
- [Beitragen](#beitragen)
- [Danksagungen](#danksagungen)
- [Stern](#stern)
## Github-Liste
### Awesome-Liste
* [awesome-web-security](https://github.com/qazbnm456/awesome-web-security)
* [Awesome-Hacking](https://github.com/Hack-with-Github/Awesome-Hacking) – Liste mit zehntausend Sternen
* [awesome-malware-analysis](https://github.com/rshipp/awesome-malware-analysis)
* [Android Security](https://github.com/ashishb/android-security-awesome) – Sammlung von Android-Sicherheitsressourcen.
* [Security](https://github.com/sbilly/awesome-security) – Software, Bibliotheken, Dokumente und andere Ressourcen.
* [An Information Security Reference That Doesn't Suck](https://github.com/rmusser01/Infosec_Reference)
* [Security Talks](https://github.com/PaulSec/awesome-sec-talks) – Kuratierte Liste von Sicherheitskonferenzen.
* [OSINT](https://github.com/jivoi/awesome-osint) – Tolle OSINT-Liste mit großartigen Ressourcen.
* [The toolbox of open source scanners](https://github.com/We5ter/Scanners-Box) – Werkzeugkiste mit Open-Source-Scannern
* [blackhat-arsenal-tools](https://github.com/toolswatch/blackhat-arsenal-tools) – Offizielles Repository der Black Hat Arsenal Security Tools
* [awesome-iot-hacks](https://github.com/nebgnahz/awesome-iot-hacks)
* [awesome-awesome](https://github.com/emijrp/awesome-awesome)
* [Curated list of awesome lists](https://github.com/sindresorhus/awesome)
* [Awesome Awesomness](https://github.com/bayandin/awesome-awesomeness) – Die Liste der Listen.
* [PENTESTING-BIBLE](https://github.com/blaCCkHatHacEEkr/PENTESTING-BIBLE) – Sicherheitsbezogene Inhalte
* [Web-Security-Learning](https://github.com/CHYbeta/Web-Security-Learning) – von CHYbeta
* [Software-Security-Learning](https://github.com/CHYbeta/Software-Security-Learning) – von CHYbeta
* [MiscSecNotes](https://github.com/JnuSimba/MiscSecNotes) – Notizen von JnuSimba
* [AndroidSecNotes](https://github.com/JnuSimba/AndroidSecNotes) – Notizen
* [LinuxSecNotes](https://github.com/JnuSimba/LinuxSecNotes) – Notizen
* [resource collection of python security and code review](https://github.com/bit4woo/python_sec)
* [Pentest_Interview](https://github.com/Leezj9671/Pentest_Interview)
* [tanjiti 信息源](https://github.com/tanjiti/sec_profile) – von Baidu tanjiti, täglich gescrapte Sicherheitsinformationsquellen
* [CVE-Flow](https://github.com/404notf0und/CVE-Flow) – von 404notfound, überwacht inkrementelle CVE-Updates, CVE-EXP-Vorhersage basierend auf Deep Learning und automatische Push-Benachrichtigungen
* [security_w1k1](https://github.com/euphrat1ca/security_w1k1/) – Meister euphrat1ca aktualisiert ständig sicherheitsbezogene Repositories
### Entwicklung
* [互联网 Java 工程师进阶知识完全扫盲](https://github.com/doocs/advanced-java)
* [Java学习+面试指南 一份涵盖大部分Java程序员所需要掌握的核心知识](https://github.com/Snailclimb/JavaGuide)
* [Python Cheat Sheet](https://github.com/crazyguitar/pysheeet)
* [A collection of full-stack resources for programmers.](https://github.com/charlax/professional-programming)
* [web, 前端, javascript, nodejs, electron, babel, webpack, rollup, react, vue ...](https://github.com/senntyou/blogs)
* [关于Python的面试题](https://github.com/taizilongxu/interview_python)
* [Python-100-Days](https://github.com/jackfrued/Python-100-Days)
* [python3-source-code-analysis](https://github.com/flaggo/python3-source-code-analysis)
* [Coding Interview University](https://github.com/jwasham/coding-interview-university)
* [tech-interview-handbook](https://github.com/yangshun/tech-interview-handbook) – gut
* [面试必备基础知识](https://github.com/CyC2018/CS-Notes)
* [CS基础](https://github.com/selfboot/CS_Offer/)
* [算法/深度学习/NLP面试笔记](https://github.com/imhuay/Algorithm_Interview_Notes-Chinese)
* [算法手记](https://github.com/labuladong/fucking-algorithm)
* [数据结构和算法必知必会的50个代码实现](https://github.com/wangzheng0822/algo)
* [interview_internal_reference](https://github.com/0voice/interview_internal_reference)
* [reverse-interview](https://github.com/yifeikong/reverse-interview-zh) – Fragen, die man am Ende eines technischen Vorstellungsgesprächs dem Interviewer stellen kann
### Sonstiges
* [信息安全从业者书单推荐](https://github.com/riusksk/secbook)
* [专为程序员编写的英语学习指南 v1.2](https://github.com/yujiangshui/A-Programmers-Guide-to-English)
* [中国程序员容易发音错误的单词](https://github.com/shimohq/chinese-programmer-wrong-pronunciation)
* [对开发人员有用的定律、理论、原则和模式](https://github.com/nusr/hacker-laws-zh)
* [SecLists](https://github.com/danielmiessler/SecLists) – Sammlung verschiedener Arten von Listen, die bei Sicherheitsbewertungen verwendet werden.
* [A collection of web attack payloads](https://github.com/foospidy/payloads) – Sammlung von Payloads
* [安全相关思维导图整理收集](https://github.com/phith0n/Mind-Map) – von P-Niu
* [安全思维导图集合](https://github.com/SecWiki/sec-chart) – von SecWiki
* [Android-Reports-and-Resources](https://github.com/B3nac/Android-Reports-and-Resources) – HackerOne-Berichte
* [AppSec](https://github.com/paragonie/awesome-appsec) – Ressourcen zum Erlernen von Anwendungssicherheit.
* [Infosec](https://github.com/onlurking/awesome-infosec) – Informationssicherheitsressourcen für Pentesting, Forensik und mehr.
* [YARA](https://github.com/InQuest/awesome-yara) – YARA-Regeln, Werkzeuge und Personen.
* [macOS-Security-and-Privacy-Guide](https://github.com/drduh/macOS-Security-and-Privacy-Guide)
* [awesome-security-weixin-official-accounts](https://github.com/DropsOfZut/awesome-security-weixin-official-accounts)
* [2018-2020青年安全圈-活跃技术博主/博客](https://github.com/404notf0und/Security-Data-Analysis-and-Visualization) – von 404notf0und
* [996.Leave](https://github.com/623637646/996.Leave)
* [租房要点,适用于北上广深杭](https://github.com/soulteary/tenant-point)
* [北京买房](https://github.com/facert/beijing_house_knowledge)
* [北京买房图鉴](https://github.com/yangyiRunning/Beijing-House)
* [上海买房](https://github.com/ayuer/shanghai_house_knowledge)
* [杭州买房](https://github.com/houshanren/hangzhou_house_knowledge)
* [awesome-macOS](https://github.com/iCHAIT/awesome-macOS) – Mac-Software
* [awesome-mac](https://github.com/jaywcjlove/awesome-mac/blob/master/README-zh.md#%E5%BC%80%E5%8F%91%E8%80%85%E5%B7%A5%E5%85%B7) – Mac-Software
* [ruanyf](https://github.com/ruanyf/weekly) – Wochenrückblick für Technikbegeisterte
## Sicherheit
### Sicherheitsliste
* [arxiv.org](https://arxiv.org/) – Paper-Datenbank
* [404notf0und学习记录](https://github.com/404notf0und/Always-Learning#APT%E6%A3%80%E6%B5%8B) – Fokus auf Sicherheitserkennung
* [Donot师傅收集的入侵检测相关的内容](https://github.com/donot-wong/SecAcademic)
* [郑瀚-Blog](https://www.cnblogs.com/littlehann/) – Alles durchgehen
* [cdxy-Blog](https://www.cdxy.me/) – Sehr cool
* [zuozuovera-Blog](https://www.zuozuovera.com/) – Geschickt
* [安全学术圈2018年度总结](https://mp.weixin.qq.com/s/eQ5os0Fdb498BoQLKUDmrA) – WeChat-Konto: Sicherheitsakademiker
* [security-hardening](https://github.com/decalage2/awesome-security-hardening) – Umfassende Sicherheitshärtung
### Sicherheitsmarkteinblicke
Einführung in die Übersicht, Trends und Gesetzmäßigkeiten des Sicherheitsmarktes. In- und ausländische Anbieter mit Sicherheitsgeschäften.
* [XDef安全峰会2021](https://mp.weixin.qq.com/s/RlEu_qVaj1rIhBuf0vQp8g)
### Cloud-Sicherheit
#### Cloud-Grundlagen
* [虚拟化简介](https://yuvaly0.github.io/2020/06/19/introduction-to-virtualization.html)
* [kvm](https://github.com/yifengyou/learn-kvm) – yifengyou, KVM-Notizen
#### Cloud-native Sicherheit
* [Google:BeyondProd模型](https://cloud.google.com/security/beyondprod?hl=zh-cn)
* [美团云原生之容器安全实践](https://tech.meituan.com/2020/03/12/cloud-native-security.html)
* [云原生入侵检测趋势观察](https://xz.aliyun.com/t/7841)
* [云原生带来的云安全机遇](https://www.freebuf.com/articles/network/242950.html) – Cloud-native Sicherheitsmarktübersicht (nicht technisch)
* [阿里云安全白皮书](https://github.com/tom0li/collection-document/blob/master/%E9%98%BF%E9%87%8C%E4%BA%91%E5%AE%89%E5%85%A8%E7%99%BD%E7%9A%AE%E4%B9%A6.pdf)
#### Angriff und Verteidigung in der Cloud
* [Awesome-serverless](https://github.com/puresec/awesome-serverless-security/)
* [云原生渗透](https://mp.weixin.qq.com/s/Aq8RrH34PTkmF8lKzdY38g) – Aufzeichnungen von Meister neargle über Cloud-native Penetration, stellt Dienste vor, die bei Cloud-nativen Penetrationstests auftreten können, und die entsprechenden Testansätze. Derzeit die umfassendste öffentliche Einführung in Cloud-native Penetration in China.
* [Red Teaming for Cloud](https://mp.weixin.qq.com/s/lUHd6lmFl3m9BMdSC2wwcw) – Klare Erklärung, was Red Team ist, einige typische Cloud-Pentest-Pfade.
* [tom0li: docker逃逸小结](https://tom0li.github.io/Docker%E9%80%83%E9%80%B8%E5%B0%8F%E7%BB%93%E7%AC%AC%E4%B8%80%E7%89%88/) – Stellt aus Angriffsperspektive drei Methoden zum Docker-Escape vor, erklärt einige reale Escape-Szenarien und Angriffsmethoden gegen Ingenieure.
* [Kubernetes security](https://github.com/kabachook/k8s-security) – Dieses Repository ist eine Sammlung von Kubernetes-Sicherheitsmaterialien und -Forschung.
* [serverless functions攻防初探](https://www.cdxy.me/?p=836) – Einführung in Angriffspfade und Verteidigungs- bzw. Erkennungsmethoden für serverlose Funktionen.
* [RDS数据库攻防](https://xz.aliyun.com/t/8451) – Durch Informationsleck nicht untergeordneter ACCESSKEY, Konfiguration ermöglicht externe Netzwerkverbindung zu RDS.
* [容器与云的碰撞——一次对 MinIO 的测试](https://mp.weixin.qq.com/s/X04IhY9Oau-kDOVbok8wEw) – Hauptsächlich SSRF-Schwachstelle in MinIO-Objektspeicher, POST-SSRF 307-Umleitung zur Konstruktion und Ausnutzung.
* [Kubernetes中使用Helm2的安全风险](http://rui0.cn/archives/1573) – Erläutert spezifische Vorgehensweise zum Erlangen von Secrets über Helm2.
* [K8s 6443批量入侵调查](https://www.cdxy.me/?p=833) – Fehlkonfiguration der Authentifizierung, ermöglicht anonymen Benutzern privilegierte Anfragen an die K8s-API, Aufforderung zur Pod-Erstellung in Docker, Ausführung von Befehlen in Docker unter Erstellung privilegierter Docker-Container, Löschung des erstellten Pods.
* [K8s渗透测试之kube-apiserver利用](https://www.cdxy.me/?p=839) – Stellt klassische Angriffspfade vor: Suche nach hochprivilegierten Service-Accounts in erlangten Pods.
* [K8s渗透测试etcd的利用](https://www.cdxy.me/?p=827) – Stellt Penetrationsbefehle für nicht autorisiertes etcd und Angreifer mit Zertifikat vor, einschließlich Befehle zum Lesen von Service-Account-Tokens und zur Übernahme des Clusters.
* [K8s数据安全之Secrets防护方案](https://www.cdxy.me/?p=832)
* [Fantastic Conditional Access Policies and how to bypass them](https://dirkjanm.io/assets/raw/fantastic_policies_cloud_roundup.pdf) – Dirk-jans Azure-Thema
* [I’m in your cloud: A year of hacking Azure AD](https://dirkjanm.io/assets/raw/Im%20in%20your%20cloud%20bluehat-v1.0.pdf) – Dirk-jans Azure-Thema
* [Istio访问授权再曝高危漏洞CVE-2020-8595](https://mp.weixin.qq.com/s?__biz=MzIyODYzNTU2OA==&mid=2247487481&idx=1&sn=02a38db691331634fe41a413beb58694&chksm=e84fa926df382030ac57be9c1ee9cb8836ec37fc79e3a2cef68acb6945a51f0ed94882e39611) – Fehlkonfiguration des Istio-Exact-Matching-Modus führt zu nicht autorisiertem Zugriff.
#### VM
##### vCenter
* [CVE-2021-21972 vCenter 6.5-7.0 RCE 漏洞分析](http://noahblog.360.cn/vcenter-6-5-7-0-rce-lou-dong-fen-xi/)
* [VMware vCenter RCE 漏洞踩坑实录——一个简单的RCE漏洞到底能挖出什么知识](https://mp.weixin.qq.com/s/eamNsLY0uKHXtUw_fiUYxQ) – Erklärt, warum Datenpakete nicht in Burp modifiziert werden können, um Dateien hochzuladen.
##### SLP
* [CVE-2020-3992 & CVE-2021-21974: Pre-Auth Remote Code Execution in VMware ESXi](https://www.zerodayinitiative.com/blog/2021/3/1/cve-2020-3992-amp-cve-2021-21974-pre-auth-remote-code-execution-in-vmware-esxi) – Stellt zwei CVEs vor: VM-Offizielles SLP basierend auf openSLP hat UAF-Schwachstelle und kann Patch umgehen.
### KI-Sicherheit
* [AI-for-Security-Learning](https://github.com/404notf0und/AI-for-Security-Learning) – Die Macht der KI – von 404notf0und
* [0xMJ:AI-Security-Learning](https://github.com/0xMJ/AI-Security-Learning#webshell%E6%A3%80%E6%B5%8B)
* [Adversarial ML Threat Matrix](https://github.com/mitre/advmlthreatmatrix) – Gegnerische Angriffe auf Machine-Learning-Systeme
* [AI安全的威胁风险矩阵](https://ai.tencent.com/ailab/media/AI%E5%AE%89%E5%85%A8%E7%9A%84%E5%A8%81%E8%83%81%E9%A3%8E%E9%99%A9%E7%9F%A9%E9%98%B5.pdf)
* [基于机器学习的Web管理后台识别方法探索](https://security.tencent.com/index.php/blog/msg/176) – Stellt den Entwurf des Backend-Erkennungsmoduls im internen Traffic-System von Tencent vor.
### Neue Sicherheitslösungen
#### Aufbau der nächsten Generation von Sicherheit
* [弹性安全网络 - 构建下一代安全的互联网](https://mp.weixin.qq.com/s/epFSC88J7LF3BGwQdoZ-Rg)
#### Zero Trust
* [张欧:数字银行可信网络实践](https://mp.weixin.qq.com/s/VRG9LEbGTxhpMmCUTUSA8w) – Zero-Trust-Konzept
* [零信任下代理工具](https://github.com/mandatoryprogrammer/CursedChrome/blob/master/README.md) – Nutzt Chrome als Proxy, ermöglicht Zugriff auf Webdienste, die für das Opfer zugänglich sind.
#### DevSecOps
* [DevSecOps理念及思考](https://mp.weixin.qq.com/s/_jBmFdtyXY5D_YrrTUP1iQ) – Tencent Security Response Center
* [Awesome-DevSecOps](https://github.com/devsecops/awesome-devsecops)
### Bedrohungserkennung
* [安全智能应用的一些迷思](https://zhuanlan.zhihu.com/p/88042567)
#### RASP
* [浅谈RASP](https://lucifaer.com/2019/09/25/%E6%B5%85%E8%B0%88RASP/)
* [以OpenRASP为基础-展开来港港RASP的类加载](https://xz.aliyun.com/t/8148)
#### HIDS
* [分布式HIDS集群架构设计](https://www.cnxct.com/distributed-hids-cluster-architecture-design/) – Team von Meituan Technology
#### WAF
##### Leitfaden zum Aufbau von WAF
* [WAF建设运营及AI应用实践](https://mp.weixin.qq.com/s?__biz=MjM5NzE1NjA0MQ==&mid=2651199346&idx=1&sn=99f470d46554149beebb8f89fbcb1578&chksm=bd2cf2d48a5b7bc2b3aecb501855cc2efedc60f6f01026543ac2df5fa138ab2bf424fc5ab2b0&scene=21#wechat_redirect)
##### BypassWAF
* [门神WAF众测总结](https://mp.weixin.qq.com/s/w5TwFl4Ac1jCTX0A1H_VbQ)
* [个人总结的waf绕过注入思路(附带6种常见waf的绕过方法)](https://www.t00ls.net/viewthread.php?tid=43687&extra=&page=1)
* [老司机带你过常规WAF](https://www.secpulse.com/archives/69983.html)
* [SQL注入ByPass的一些小技巧](https://mp.weixin.qq.com/s/fSBZPkO0-HNYfLgmYWJKCg)
* [在HTTP协议层面绕过WAF](https://www.freebuf.com/news/193659.html)
* [利用分块传输吊打所有WAF](https://www.anquanke.com/post/id/169738)
* [WAF绕过的捷径与方法](https://www.qiaoyue.net/2019/WAF%E7%BB%95%E8%BF%87%E7%9A%84%E6%8D%B7%E5%BE%84%E4%B8%8E%E6%96%B9%E6%B3%95/)
* [对过WAF的一些认知](http://static.anquanke.com/download/b/security-geek-2019-q2/article-18.html)
* [WAF Bypass之webshell上传jsp与tomcat](https://www.anquanke.com/post/id/210630#)
* [各种姿势jsp webshell](https://xz.aliyun.com/t/7798)
#### Webshell-Erkennung
* [查杀Java web filter型内存马](http://gv7.me/articles/2020/kill-java-web-filter-memshell/)
* [Filter/Servlet型内存马的扫描抓捕与查杀](https://gv7.me/articles/2020/filter-servlet-type-memshell-scan-capture-and-kill/)
* [杂谈Java内存Webshell的攻与防](https://mp.weixin.qq.com/s/DRbGeVOcJ8m9xo7Gin45kQ)
* [JSP Webshell那些事 -- 攻击篇](https://mp.weixin.qq.com/s/YhiOHWnqXVqvLNH7XSxC9w)
* [Webshell攻与防PHP](https://github.com/qiyeboy/kill_webshell_detect/blob/master/%E7%9F%A5%E8%AF%86%E6%98%9F%E7%90%83-webshell%E6%94%BB%E4%B8%8E%E9%98%B2.pdf)
* [污点传递理论在Webshell检测中的应用 - PHP篇](https://mp.weixin.qq.com/s/MFmSliCQaaVEQ0E66vN5Xg)
* [新开始:webshell的检测](https://iami.xyz/New-Begin-For-Nothing/)
* [利用 intercetor 注入 spring 内存 webshell](https://github.com/LandGrey/webshell-detect-bypass/blob/master/docs/inject-interceptor-hide-webshell/inject-interceptor-hide-webshell.md) – Artikel aus Angriffsperspektive
#### Reverse-Shell-Erkennung
* [反弹Shell原理及检测技术研究](https://www.cnblogs.com/LittleHann/p/12038070.html) – von LittleHann
* [反弹Shell剖析](https://cloud.tencent.com/developer/article/1645464)
* [详解反弹shell多维检测技术](https://www.freebuf.com/articles/network/263684.html)
#### EDR
* [Lets-create-an-edr-and-bypass](https://ethicalchaos.dev/2020/06/14/lets-create-an-edr-and-bypass-it-part-2/)
* [openedr](https://github.com/ComodoSecurity/openedr) – Open-Source-EDR-Produkt
#### AV
* [exploiting-almost-every-antivirus-software](https://www.rack911labs.com/research/exploiting-almost-every-antivirus-software/) – Gegenmaßnahme gegen AV: Verwendung von Verknüpfungen, um über AV-Hohe-Rechte beliebige Dateien zu löschen.
* [Bypassing Windows Defender Runtime Scanning](https://labs.f-secure.com/blog/bypassing-windows-defender-runtime-scanning/) – Aufzählungstests, welche API-Aufrufe die Defender-Erkennung auslösen: Feststellung, dass CreateProcess und CreateRemoteThread Defender auslösen. Drei Lösungen: API-Aufrufe neu schreiben, Anweisungen ändern und dynamisch entschlüsseln laden, oder den Bereich von Defender nicht scannen lassen. Autor nutzt Defender-Scanmechanismus (nur MEM_PRIVATE oder RWX-Seitenberechtigungen scannen bei großem virtuellem Speicher), setzt dynamisch PAGE_NOACCESS-Speicherberechtigung, wenn verdächtige APIs aufgerufen werden, sodass Defender keine Sicherheitsprüfung durchführt.
* [Engineering antivirus evasion](https://blog.scrt.ch/2020/06/19/engineering-antivirus-evasion/)
* [Bypass Windows DefenderAttack Surface Reduction](https://data.hackinn.com/ppt/OffensiveCon2019/Bypass%20Windows%20Exploit%20Guard%20ASR.pdf)
* [Defender 扫描文件名问题](http://2016.eicar.org/85-0-Download.html)
* [herpaderping](https://github.com/jxy-s/herpaderping) – Eine neue Methode zum Umgehen von Defender
* [实现一款 shellcodeLoader](https://paper.seebug.org/1413/) – Stellt einige Methoden zur Shellcode-Ausführung und zum Umgehen von Sandboxen vor.
* [Malware_development_part](https://0xpat.github.io/Malware_development_part_5/) – Tutorial-Reihe zur Malware-Entwicklung
* [杀软检测及其Hook点list](https://github.com/D3VI5H4/Antivirus-Artifacts/blob/main/ANTIVURUS_ARTIFACTS.pdf)
#### Erkennung lateraler Bewegung – Honeypot-Ansatz
* [Honeypots](https://github.com/paralax/awesome-honeypots) – Honeypots, Werkzeuge, Komponenten und mehr.
* [Hunting for Skeleton Key Implants](https://riccardoancarani.github.io/2020-08-08-hunting-for-skeleton-keys/) – Erkennung von Skeleton Key-Persistenz
* [创建蜜罐账户检测Kerberoast](https://www.pentestpartners.com/security-blog/honeyroasting-how-to-detect-kerberoast-breaches-with-honeypots/)
#### Erkennung bösartigen Datenverkehrs
* [DataCon2020题解:通过蜜罐与DNS流量追踪Botnet](https://www.cdxy.me/?p=829)
* [DNS Tunnel隧道隐蔽通信实验 && 尝试复现特征向量化思维方式检测](https://www.cnblogs.com/LittleHann/p/8656621.html#_label0)
* [maltrail](https://github.com/stamparm/maltrail#introduction) – Open-Source-Traffic-Erkennungsprodukt
* [cobalt-strike-default-modules-via-named-pipe检测](https://labs.f-secure.com/blog/detecting-cobalt-strike-default-modules-via-named-pipe-analysis/) – Erkennung der Named-Pipe der CS-Standardmodule nach dem Auschecken
* [用DNS数据进行威胁发现](https://mp.weixin.qq.com/s/6CtRd7o4IjreLaU-hFt9vQ) – Stellt 360DNSMON vor, das mit DNS-Überwachung Skidmap-Backdoor und einige Analysemethoden entdeckt.
* [DNSMon: 用DNS数据进行威胁发现](https://blog.netlab.360.com/use-dns-data-produce-threat-intelligence-2/) – Überwachung von Ereignissen über DNSMON und Korrelationsanalyse.
* [evading-sysmon-dns-monitoring](https://blog.xpnsec.com/evading-sysmon-dns-monitoring/)
* [use-dns-data-produce-threat-intelligence](https://blog.netlab.360.com/use-dns-data-produce-threat-intelligence/)
#### IDS
* [我们来谈一谈IDS签名](https://www.anquanke.com/post/id/102948#h2-0)
* [不按顺序来的 TCP 包](https://strcpy.me/index.php/archives/789/)
* [网络层绕过 IDS/IPS 的一些探索](https://paper.seebug.org/1173/)
#### Texterkennung
* [机器学习在二进制代码相似性分析中的应用](https://mp.weixin.qq.com/s?__biz=MjM5NTc2MDYxMw==&mid=2458303210&idx=1&sn=345f8cec156ada8fa9bf6a6d6de83906&chksm=b1818a6086f60376e766baf472171d8e2c780b2913568b46b683e3112fcc5f86c9bf4c19e38b&mpshare=1&scene=1&srcid=&sharer_sharetime=1580984631757&sharer_shareid=5dc01f49f38fd64ff3e64844bc7d2ea7&exportkey=A0qHBeUryuXO6zhGWt5OJNw%3D&pass_ticket=gjTFXl4hPMTBWzlKpWZWqK8HivXQ8q7ChNndmw4I8JrdAK0jWWFvKIq7OMnO3BhL#rd)
### Sicherheitsbetrieb
* [如何评价安全工作的好坏](https://zhuanlan.zhihu.com/p/226493047) – Einige Upward-Management-Erkenntnisse von Tencent „Berufsschuld“
### Datensicherheit
* [互联网企业数据安全体系建设](https://tech.meituan.com/2018/05/24/data-security-system-construction.html)
* [浅谈数据安全](https://iami.xyz/Talk-about-data-security/)
#### Netzwerkkartierung
* [简单聊聊网络空间测绘纵横之道](https://www.anquanke.com/post/id/226007)
* [让网络空间测绘技术不再那么飘忽不定](https://mp.weixin.qq.com/s/lr39F9kNOfHlMimgymzVwg) – von Zhao Wu, Schwerpunkte der Netzwerkkartierung
* [记录一些网络空间测绘/搜索引擎相关的资料](https://github.com/EXHades/CyberSpaceSearchEngine-Research)
### Kommunikationssicherheit
#### Ende-zu-Ende-Kommunikation (Erstversion)
* [史上最全的zoom漏洞和修复方案介绍](https://mp.weixin.qq.com/s/a7mN0lTeXxA3YmZZxIGNRg)
* [对安全即时通讯软件的流量分析攻击](https://www.anquanke.com/post/id/208678#)
* [Shadowsocks基于二次混淆加密传输的数据保密性原理分析](https://www.secrss.com/articles/18469)
#### SNI
* [ESNI](https://www.cloudflare.com/zh-cn/learning/ssl/what-is-encrypted-sni/) – Was ist verschlüsseltes SNI?
* [encrypted-client-hello-the-future-of-esni-in-firefox](https://blog.mozilla.org/security/2021/01/07/encrypted-client-hello-the-future-of-esni-in-firefox/)
* [encrypted-client-hello](https://blog.cloudflare.com/encrypted-client-hello/)
### Persönliche Sicherheit* [Tor-0day-Finding-IP-Addresses](https://www.hackerfactor.com/blog/index.php?/archives/896-Tor-0day-Finding-IP-Addresses.html)
* [lcamtuf: Katastrophenplan](https://lcamtuf.coredump.cx/prep/)
* [tom0li: Persönlicher Datenschutz](https://tom0li.github.io/%E4%B8%AA%E4%BA%BA%E9%9A%90%E7%A7%81%E4%BF%9D%E6%8A%A4/) Gedanken zum Schutz der Privatsphäre für normale Menschen
* [Datenschutz](https://github.com/No-Github/Digital-Privacy) Liste mit Methoden zum Sammeln digitaler Privatsphäre
* [Supercookie Browser-Fingerprinting](https://supercookie.me/workwise) Supercookie uses favicons to assign a unique identifier to website visitors. Verwendet mehrere Zugriffs-URLs zur Unterscheidung von Benutzern
### APT-Forschung
Der Großteil des vorherigen Abschnitts behandelt Angriffsinhalte, einschließlich APT-Tracking-Berichte usw.
#### Fortgeschrittene Bedrohungen - Liste
* [Red-Team-Infrastructure-Wiki](https://github.com/bluscreenofjeff/Red-Team-Infrastructure-Wiki)
* [Sammlung von APT-Berichtsanalysen](https://github.com/CyberMonitor/APT_CyberCriminal_Campagin_Collections) Stark empfohlen
* [Über die Natur fortgeschrittener Bedrohungen und die Quantifizierung von Angriffen](http://www.vxjump.net/files/aptr/aptr.txt)
* [OffensiveCon Konferenz](https://www.offensivecon.org/) Nicht einzeln aufgeführt
* [ATT&CK](https://attack.mitre.org/matrices/enterprise/)
* [Red Team von 0 bis 1: Praxis und Überlegungen](https://mp.weixin.qq.com/s/cyxC4Of4Ic9c_vujQayTLg) Einführung, was Red Team ist, geeignet für den Aufbau von Red-Team-Infrastruktur im Team
* [MITRE | ATT&CK (Chinesisch)](https://huntingday.github.io) Wissenslandkarte, wird nicht mehr aktualisiert
* [FireEye Bedrohungsforschung](https://www.fireeye.com/blog/threat-research.html) Bekanntes Bedrohungsanalyseunternehmen
* [red-team-and-the-next](https://devco.re/blog/2019/10/24/evolution-of-DEVCORE-red-team-and-the-next/) – von DEVCORE
Anti-Threat-Artikel von redrain und seinem Team
* [Noah Blog](http://noahblog.360.cn/) Anti Threat and Threat Actors through Noah Lab Analysts
* [FengHuo Lab Blog](https://blogs.360.cn/)
* [APT-Analyse und TTPs-Extraktion](https://paper.seebug.org/1132/)
* [Diskussion über ATT&CK/APT/Attribution](https://weibo.com/ttarticle/p/show?id=2309404450471736639616)
* [Legends Always Die – Kurze Beschreibung des Supply-Chain-Angriffs auf League of Legends beim FireEye Summit](https://card.weibo.com/article/m/show/id/2309404426957856047151) Rückverfolgung eines Supply-Chain-Angriffs, Basisinformationen wie Domains/IPs/E-Mails, Verknüpfung mit vergangenen APT-Aktivitäten
* [Technischer Rückblickbericht zum XShellGhost-Vorfall](https://cert.360.cn/static/files/XShellGhost%E4%BA%8B%E4%BB%B6%E6%8A%80%E6%9C%AF%E5%9B%9E%E9%A1%BE%E6%8A%A5%E5%91%8A.pdf)
* [Kingslayer: A supply chain attack](http://www.hackdog.me/article/Kingslayer-A_supply_chain_attack--Part_1.html)
SolarWinds Supply-Chain-Analyse
* [Vom SolarWinds Supply-Chain-Angriff (Goldene Kettenbär) zur verdeckten Operation in APT-Aktionen](https://mp.weixin.qq.com/s/UqXC1vovKUu97569LkYm2Q) Von Qianxin verfasste Analyse des SolarWinds-Angriffs
* [SolarWinds-Analyse](https://go.recordedfuture.com/hubfs/reports/pov-2020-1230.pdf)
* [Highly Evasive Attacker Leverages SolarWinds Supply Chain to Compromise Multiple Global Victims With SUNBURST Backdoor](https://www.fireeye.com/blog/threat-research/2020/12/evasive-attacker-leverages-solarwinds-supply-chain-compromises-with-sunburst-backdoor.html)
* [Weitere technische Details zu SUNBURST](https://www.fireeye.com/blog/threat-research/2020/12/sunburst-additional-technical-details.html)
#### Bedrohungsinformationen
* [Anklageschrift gegen Nordkorea](https://www.justice.gov/opa/press-release/file/1092091/download) Zehn Jahre dauernder Klassifizierungsprozess
* [Eine kurze Einführung in die Attribution von Cyberangriffen](https://www.secrss.com/articles/14864) Einführung von Indikatoren und Methoden der APT-Klassifizierung (mit Bezug auf Cyber Attribution Dokumente) sowie einige Klassifizierungsdokumente
* [Was sind Bedrohungsinformationen?](https://www.secrss.com/articles/16577) Definition, Klassifizierung, Indikatoren und Fallbeispiele zur Rückverfolgung und Klassifizierung
#### Phishing
* [Einführung in das Prinzip der SMTP-Benutzersammlung und verwandte Tools](http://www.freebuf.com/articles/web/182746.html) – Zum Erhalten von Benutzerwörterbüchern
* [Spear-Phishing](https://payloads.online/archivers/2020-02-05/1)
* [Wie man Hacker zurückschlägt, die AWVS verwenden](http://www.freebuf.com/news/136476.html)
* [Gegenangriff ausgehend von MySQL](https://xz.aliyun.com/t/3277)
* [Erweiterung der Angriffskette zum Lesen beliebiger Dateien über MySQL Client](https://paper.seebug.org/1112/)
* [Bösartiger MySQL-Server liest Dateien des MySQL-Clients](http://scz.617.cn/network/202001101612.txt)
* [https://github.com/BloodHoundAD/BloodHound/issues/267](https://github.com/BloodHoundAD/BloodHound/issues/267) – XSS
* [Ghidra von XXE zu RCE](https://xlab.tencent.com/cn/2019/03/18/ghidra-from-xxe-to-rce/) Gegen Ingenieure
* [Sicherheitsrisiken durch WeChat-Plugins](https://xlab.tencent.com/cn/2018/10/23/weixin-cheater-risks/) Gegen Einzelpersonen
* [Node.js Package-Phishing](https://www.cnblogs.com/index-html/p/npm_package_phishing.html) Gegen Ingenieure
* [Erstellen bösartiger Visual Studio Code-Erweiterungen](https://d0n9.github.io/2018/01/17/vscode%20extension%20%E9%92%93%E9%B1%BC/#) Gegen Ingenieure
* [VS Code Phishing](https://blog.doyensec.com/2020/03/16/vscode_codeexec.html) Gegen Ingenieure
* [Python Package Phishing](https://paper.seebug.org/326/) Gegen Ingenieure
* [Docker-Client-Phishing](https://www.blackhat.com/docs/us-17/thursday/us-17-Cherny-Well-That-Escalated-Quickly-How-Abusing-The-Docker-API-Led-To-Remote-Code-Execution-Same-Origin-Bypass-And-Persistence.pdf) Gegen Ingenieure
* [Angriff auf lokales Xdebug mit bösartigen Seiten](https://xlab.tencent.com/cn/2018/03/) Gegen Ingenieure
* [Phishing-RCE über Huawei HG532 Router](https://xlab.tencent.com/cn/2018/01/05/a-new-way-to-exploit-cve-2017-17215/) Gegen Einzelpersonen
* [Internes Netzwerk Phishing]()```
RMI反序列化
WIN远程连接漏洞CVE-2019-1333
Mysql读文件&反序列化
Dubbo反序列化
IDE反序列化
恶意vpn
恶意控件
笔记软件rce
社交软件rce
NodeJS库rce
Python package 钓鱼
VSCODE EXTENSION 钓鱼
VS Studio钓鱼
Twitter钓鱼
红包插件钓鱼防撤回插件
解压rce
破解软件钓鱼
docker客户端钓鱼
docker镜像钓鱼
Xdebug
Ghidra钓鱼
bloodhound钓鱼
AWVS钓鱼
蚁剑
浏览器插件
云盘污染
E-Mail-Fälschung
Derzeit nur eine einfache Auflistung
Einige der zuvor genannten Artikel enthalten Fehler – Praxisprüfung erforderlich
Offizielle Handbücher werden empfohlen
Frühere werde ich später ergänzen
Alt```
## Mitwirken
Wir begrüßen alle, die einen Beitrag leisten möchten. Sie können dazu ein Issue eröffnen, wenn Sie eine neue Idee für dieses Projekt haben oder qualitativ hochwertige Sicherheitsartikel gefunden haben. Ich werde dann Ihren Namen in die Danksagungen aufnehmen.
## Danksagungen
* @[tom0li](https://github.com/tom0li)
* @[neargle](https://github.com/neargle)
* @[r4v3zn](https://github.com/0nise)
## Star
Danke für die Sterne
[](https://starchart.cc/tom0li/collection-document)
国外赏金之路 - 老司机赏金见解,历史赏金文章 list