
airgeddon
This is a multi-use bash script for Linux systems to audit wireless networks.
Penetration testing methodologies, frameworks, reporting, and automation tools.

This is a multi-use bash script for Linux systems to audit wireless networks.

Multi-source subdomain enumeration tool with 50+ collection modules, DNS brute-force, passive DNS analysis, certificate transparency, search engine…

The Mobile App Pentest cheat sheet was created to provide concise collection of high value information on specific mobile application penetration…

Post-exploitation framework for automated network authentication testing, credential harvesting, and lateral movement across Windows/AD environments…

SpringBoot 相关漏洞学习资料,利用方法和技巧合集,黑盒安全评估 check list

一款长亭自研的完善的安全评估工具,支持常见 web 安全问题扫描和自定义 poc | 使用之前务必先阅读文档

A curated list of GPT agents for cybersecurity

⚔️ Web Hacker's Weapons / A collection of cool tools used by Web hackers. Happy hacking , Happy bug-hunting

Nishang - Offensive PowerShell for red team, penetration testing and offensive security.

reconFTW is a tool designed to perform automated recon on a target domain by running the best set of tools to perform scanning and finding out…

A fast port scanner written in go with a focus on reliability and simplicity. Designed to be used in combination with other tools for attack surface…

Nightly builds of common C# offensive tools, fresh from their respective master branches built and released in a CDI fashion using Azure DevOps…

Modlishka. Reverse Proxy.

A collection of Azure AD/Entra tools for offensive and defensive security purposes

Various tips & tricks

Copy Fail (CVE-2026-31431): 9-year-old Linux kernel LPE found by Theori's Xint Code

ffffffff0x 团队维护的安全知识框架,内容包括不仅限于 web安全、工控安全、取证、应急、蓝队设施部署、后渗透、Linux安全、各类靶机writup