Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Red-Team — Red-Team Attack Guid | Kitploit
Tools/GitHubGitHub/al1ex/red-team
ExploitationInformation GatheringWeb SecurityCTFPenetration TestingLearning & EducationRed TeamingCurated Resources
GitHubal1ex/red-team

Red-Team

Red-Team Attack Guid

View Repository
280675 years agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Project Introduction

This project is used to collect and summarize the following aspects of Red Team:

  • Red Team attack mindset

  • Red Team attack tools

  • Red Team attack methods

Highlights

  • https://mitre-attack.github.io/ MITRE's wiki summarizing attack techniques
  • https://huntingday.github.io MITRE | ATT&CK Chinese site
  • https://arxiv.org Cornell University open-access documents
  • http://www.owasp.org.cn/owasp-project/owasp-things OWASP project
  • http://www.irongeek.com/i.php?page=security/hackingillustrated Videos and documents from security conferences at home and abroad
  • https://github.com/knownsec/KCon KCon conference article PPTs
  • https://github.com/SecWiki/sec-chart Collection of various security-related mind maps
  • https://github.com/knownsec/RD_Checklist Knownsec skill checklist
  • https://github.com/ChrisLinn/greyhame-2017 Grey Robe skill book 2017 version
  • https://github.com/Hack-with-Github/Awesome-Hacking GitHub 10k-star recommendation: hacker growth technical checklist
  • https://github.com/k4m4/movies-for-hackers Security-related movies
  • https://github.com/jaredthecoder/awesome-vehicle-security Resource list for vehicle security and car hacking
  • https://www.jianshu.com/p/852e0fbe2f4c Security product vendor classification
  • https://www.reddit.com/r/Python/comments/a81mg3/the_entire_mit_intro_computer_science_class_using/ MIT machine learning video
  • https://github.com/fxsjy/jieba py, Jieba Chinese word segmentation
  • https://github.com/thunlp/THULAC-Python py, Tsinghua Chinese word segmentation
  • https://github.com/lancopku/PKUSeg-python py3, Peking University Chinese word segmentation
  • https://github.com/fengdu78/Coursera-ML-AndrewNg-Notes Andrew Ng machine learning Python notes
  • https://paperswithcode.com/sota Machine learning specific projects, demos, code
  • https://github.com/duoergun0729/nlp An open-source introductory book on NLP (Neuro-Linguistic Programming)
  • https://www.freebuf.com/articles/web/195304.html One-sentence webshell tricks

Attack & Defense Testing

Series Content

  • https://micropoor.blogspot.com/2019/01/php8.html PHP Security News 8 AM course series: Advanced Persistent Penetration -- Microporor
  • https://github.com/Micropoor/Micro8 Microporor 100 lessons on advanced attack & defense
  • https://github.com/maskhed/Papers Includes classic attack & defense teaching materials such as the 100 lessons, and security knowledge
  • https://github.com/infosecn1nja/AD-Attack-Defense Red/blue team attack & defense handbook
  • https://github.com/yeyintminthuhtut/Awesome-Red-Teaming Excellent Red Team resource list
  • https://github.com/foobarto/redteam-notebook Red Team standard penetration testing process + common commands
  • https://github.com/tom0li/collection-document Article collection: security department, SDL, SRC, penetration testing, exploit
  • https://github.com/kbandla/APTnotes Various public documents and related APT notes, plus software samples
  • https://wizardforcel.gitbooks.io/web-hacking-101/content Web Hacking 101 Chinese version
  • https://techvomit.net/web-application-penetration-testing-notes/ Web penetration testing notes
  • https://github.com/qazbnm456/awesome-web-security Web security materials and resource list
  • http://pentestmonkey.net/category/cheat-sheet Common penetration testing cheat sheets
  • https://github.com/demonsec666/Security-Toolkit Common tools and usage scenarios in the penetration attack chain
  • https://github.com/Kinimiwar/Penetration-Testing Excellent resource collection in the penetration testing field

Basic Security

  • https://book.yunzhan365.com/umta/rtnp/mobile/index.html Cybersecurity popular science booklet
  • http://sec.cuc.edu.cn/huangwei/textbook/ns/ Network security electronic textbook. CUC information security course website
  • https://mitre.github.io/attack-navigator/enterprise/ MITRE ATT&CK intrusion detection entries
  • https://github.com/danielmiessler/SecLists Lists include usernames, passwords, URLs, sensitive data patterns, fuzzing payloads, web shells, etc.
  • https://github.com/GitGuardian/APISecurityBestPractices API interface testing checklist
  • https://github.com/ym2011/SecurityManagement Shares the bits and pieces of building a security management system, ISO27001, classified protection, and security review processes
  • https://mp.weixin.qq.com/s/O36e0gl4cs0ErQPsb5L68Q Blockchain, Ethereum smart contract audit Checklist
  • https://github.com/slowmist/eos-bp-nodes-security-checklist Blockchain, EOS bp nodes security checklist (EOS super node security implementation guide)
  • https://xz.aliyun.com/t/2089 Fintech SDL security design checklist
  • https://github.com/juliocesarfort/public-pentesting-reports A list of public penetration testing reports released by several consulting firms and academic security organizations.
  • http://www.freebuf.com/articles/network/169632.html A checklist for building an SOC with open-source software
  • https://github.com/0xRadi/OWASP-Web-Checklist OWASP website check items
  • https://www.securitypaper.org/ SDL development security lifecycle management
  • https://github.com/Jsitech/JShielder One-click server hardening script for Linux

Study Handbooks

  • https://github.com/HarmJ0y/CheatSheets Cheat sheets for multiple projects (Beacon / Cobalt Strike, PowerView, PowerUp, Empire and PowerSploit)
  • https://wizardforcel.gitbooks.io/kali-linux-web-pentest-cookbook/content/ Kali Linux Web Penetration Testing Cookbook, Chinese version
  • https://github.com/louchaooo/kali-tools-zh Manual introducing tool usage under Kali
  • https://www.offensive-security.com/metasploit-unleashed/ Metasploit guidance notes by Offensive Security (Kali)
  • http://www.hackingarticles.in/comprehensive-guide-on-hydra-a-brute-forcing-tool/ Hydra usage manual
  • https://www.gitbook.com/book/t0data/burpsuite/details Burp Suite practical guide
  • https://zhuanlan.zhihu.com/p/26618074 How to use Nmap extension scripts (NSE)
  • https://somdev.me/21-things-xss/ 21 extended uses of XSS
  • https://www.netsparker.com/blog/web-security/sql-injection-cheat-sheet/ SQL injection cheat sheet
  • https://sqlwiki.netspi.com/ All the SQL injection knowledge points you need can be found here
  • https://github.com/kevins1022/SQLInjectionWiki A wiki focused on aggregating and documenting various SQL injection methods
  • https://github.com/hardenedlinux/linux-exploit-development-tutorial Linux exploit development introduction
  • https://wizardforcel.gitbooks.io/asani/content Android Security Made Simple, Chinese version
  • https://wizardforcel.gitbooks.io/lpad/content Android Penetration Testing Learning Manual, Chinese version

Practice Ranges

  • https://www.blackmoreops.com/2018/11/06/124-legal-hacking-websites-to-practice-and-learn/ 124 legal websites to practice and learn hacking techniques
  • https://www.zhihu.com/question/267204109 Where to find various practice ranges for learning web security?
  • https://www.vulnhub.com Collection of many CTF target machines
  • https://www.wechall.net World-renowned CTF aggregation and exchange website
  • https://www.xssgame.com Google XSS challenge
  • http://xss.tv Online practice range challenge
  • https://www.hackthebox.eu Online practice range challenge
  • https://www.root-me.org Online practice range challenge
  • http://www.itsecgames.com bWAPP, contains 100+ vulnerability environments
  • https://github.com/c0ny1/vulstudy Docker collection of various vulnerability reproduction systems
  • https://github.com/bkimminich/juice-shop Marketplace of common web security experiment practice ranges
  • https://github.com/ethicalhack3r/DVWA Web security experiment practice range
  • https://www.freebuf.com/articles/web/123779.html Beginner's guide: DVWA-1.9 all-level tutorial
  • https://github.com/78778443/permeate php, common vulnerability practice range
  • https://github.com/gh0stkey/DoraBox php, common vulnerability practice range
  • https://github.com/stamparm/DSVW py2, common vulnerability practice range
  • https://github.com/amolnaik4/bodhi py, common vulnerability practice range

Information Gathering

  • https://github.com/smicallef/spiderfoot Automates OSINT to find out target information, GUI interface, plugin-based
  • https://github.com/Nhoya/gOSINT go, automates information gathering using OSINT
  • https://github.com/laramies/theHarvester Monitors sensitive asset information of enterprises indexed by search engines: employee emails, subdomains, Hosts
  • https://github.com/guelfoweb/knock Obtains subdomains via brute force, can be used to find subdomain takeover vulnerabilities
  • https://github.com/aboul3la/Sublist3r Fast subdomain enumeration tool via search engines and brute force
  • https://github.com/Ice3man543/subfinder Sublist3r implemented in Go
  • https://github.com/yanxiu0614/subdomain3 py3, py2 subdomain, IP, CDN information, etc.
  • https://github.com/caffix/amass Go-based, subdomain enumeration, searches internet data sources, uses machine learning to guess subdomains
  • https://github.com/nahamsec/lazyrecon Automates the reconnaissance process, can automatically use Sublist3r/certspotter to obtain subdomains, and invoke nmap/dirsearch, etc.
  • https://github.com/s0md3v/ReconDog simple, Swiss Army knife for reconnaissance information
  • https://github.com/FeeiCN/ESD py3, brute-force subdomain gathering
  • https://github.com/alpha1e0/pentestdb Multipurpose integrated information gathering tool
  • https://github.com/se55i0n/PortScanner py2, fast TCP port scanning, banner recognition, CDN detection
  • https://github.com/lijiejie/subDomainsBrute A widely used subdomain brute-force enumeration tool developed by lijiejie
  • https://github.com/ring04h/wydomain A precise subdomain enumeration tool developed by zhuzhuxia with comprehensive domain collection

Information Leakage

  • https://github.com/Yelp/detect-secrets PY, prevents sensitive information such as passwords in code from being committed to the codebase, ensuring security without any impact on developer productivity
  • https://github.com/Acceis/leakScraper Processes and visualizes large-scale text files, finds sensitive information such as certificates
  • https://github.com/Raikia/CredNinja Multi-threaded user credential verification script, e.g., verifies whether a dumped hash belongs to this machine, uses port 445 for protocol verification
  • https://github.com/CERTCC/keyfinder Finds and analyzes private/public key files (in the file system), supports Android APK files
  • https://github.com/Ice3man543/hawkeye go, CLI, file system analysis tool that quickly finds SSH keys, log files, Sqlite databases, password files, etc. contained in files
  • https://github.com/FortyNorthSecurity/EyeWitness Takes screenshots of target websites, VNC, RDP services, attempts to obtain default credentials
  • https://github.com/D4Vinci/Cr3dOv3r Automatically searches for leaked password information based on an email address, and can also test whether account passwords work on major websites

Path Discovery

  • https://github.com/maurosoria/dirsearch Classic directory path scanning
  • https://github.com/TheM4hd1/PenCrawLer C# interface, web crawler and directory path brute-force tool, adds recursive brute-force mode in addition to regular scanning
  • https://github.com/Xyntax/DirBrute Directory path brute-force tool
  • https://github.com/abaykan/crawlbox Directory path scanner
  • https://github.com/deibit/cansina Directory path scanner
  • https://github.com/UltimateHackers/Breacher Multi-threaded backend path scanner, can also be used to discover Execution After Redirect vulnerabilities
  • https://github.com/fnk0c/cangibrina Cross-platform admin backend path scanner via dictionary brute force, Google, robots.txt, etc.
  • https://github.com/Go0s/SitePathScan Coroutine-based directory path brute-force tool; with aiohttp, path scanning is more than three times faster than before
  • https://github.com/secfree/bcrpscan Crawler-based web path scanner

Fingerprinting | Ports

  • https://github.com/nmap/nmap LUA, Nmap port scanner, has a powerful script engine framework
  • https://github.com/robertdavidgraham/masscan C, stateless scanning, can invoke nmap for fingerprinting
  • https://github.com/zmap/zmap C, stateless scanning, requires writing extension modules in C
  • https://github.com/zmap/zgrab go, fingerprinting and scheduling management based on the zmap scanner, can bypass CDN
  • https://github.com/chichou/grab.js Fast TCP fingerprint grabbing and parsing tool similar to zgrab, supports more protocols
  • https://github.com/johnnyxmas/scancannon shell, integrates masscan and nmap
  • https://github.com/OffensivePython/Nscan Network scanner based on Masscan and Zmap
  • https://github.com/ring04h/wyportmap Calls nmap target port scanning + system service fingerprinting
  • https://github.com/angryip/ipscan Angry IP Scanner, cross-platform GUI port scanner
  • https://github.com/EnableSecurity/wafw00f WAF product fingerprinting
  • https://github.com/rbsec/sslscan SSL type identification
  • https://github.com/urbanadventurer/whatweb Web fingerprinting
  • https://github.com/Rvn0xsy/FastWhatWebSearch whatweb tool results search platform
  • https://github.com/tanjiti/FingerPrint Web application fingerprinting
  • https://github.com/nanshihui/Scan-T Web crawler-style fingerprinting
  • https://github.com/ywolf/F-MiddlewareScan Middleware scanning service identification

File Inclusion

  • https://github.com/hvqzao/liffy Local File Inclusion vulnerability exploitation tool
  • https://github.com/D35m0nd142/Kadabra Local File Inclusion vulnerability scanning and exploitation tool
  • https://github.com/P0cL4bs/Kadimus Local File Inclusion vulnerability scanning and exploitation tool
  • https://github.com/D35m0nd142/LFISuite Local File Inclusion exploitation and scanning tool, supports reverse shell
  • https://github.com/OsandaMalith/LFiFreak Local File Inclusion exploitation and scanning tool, supports reverse shell

Upload Vulnerabilities

  • https://github.com/UltimateHackers/Arjun Scans web pages, uses regex brute forcing to find hidden GET/POST parameters
  • https://github.com/3xp10it/xupload Tool for automatically testing whether the upload functionality can upload a webshell
  • https://github.com/gunnerstahl/JQShell py3, CVE-2018-9206 jQuery File Upload exploitation tool
  • https://github.com/destine21/ZIPFileRaider Burp plugin, tests zip file upload vulnerabilities
  • https://github.com/jpiechowka/zip-shotgun py, tests zip file upload vulnerabilities

XSS Exploitation

  • https://github.com/UltimateHackers/AwesomeXSS XSS Awesome series
  • http://www.xss-payloads.com Very comprehensive XSS toolkit and resources
  • https://github.com/ismailtasdelen/xss-payload-list XSS vulnerability payload list
  • https://github.com/beefproject/beef Classic XSS exploitation framework
  • https://github.com/samdenty99/injectify XSS exploitation framework similar to beef
  • https://github.com/firesunCN/BlueLotus_XSSReceiver XSS exploitation framework built by the Blue-Lotus team for CTF
  • https://github.com/NytroRST/XSSFuzzer Generates XSS payloads based on specific tags
  • https://github.com/evilcos/xssor2 XSS exploitation aid written by Yuxi (cos)
  • https://github.com/UltimateHackers/XSStrike XSS scanning tool that can identify and bypass WAF
  • https://github.com/raz-varren/xsshell go, returns a JS interactive shell by exploiting XSS vulnerabilities
  • https://github.com/UltimateHackers/JShell Returns a JS interactive shell by exploiting XSS vulnerabilities
  • https://github.com/shawarkhanethicalhacker/BruteXSS An XSS scanner that can brute-force inject parameters
  • https://github.com/1N3/XSSTracer Small XSS scanner, can also detect CRLF, XSS, clickjacking
  • https://github.com/0x584A/fuzzXssPHP PHP version of reflected XSS scanning
  • https://github.com/chuhades/xss_scan Python script for batch XSS scanning
  • https://github.com/BlackHole1/autoFindXssAndCsrf Browser plugin that automatically detects whether pages have XSS and CSRF vulnerabilities

Credential Brute Forcing

  • https://github.com/vanhauser-thc/thc-hydra Supports cracking and brute force for multiple protocols, no Windows version provided since v8
  • https://github.com/nmap/ncrack c, supports cracking and brute force for multiple protocols
  • https://github.com/0pn1i9ht/F-Scrack ysrc's script for brute-forcing usernames and passwords of various services
  • https://github.com/TunisianEagles/SocialBox Script for brute-forcing usernames and passwords of fb, gmail, ins, twitter
  • https://github.com/lanjelot/patator Supports brute force across multiple protocols, modular design, flexible to use
  • https://github.com/m4ll0k/SMBrute Performs username and password brute force using the SMB service
  • https://github.com/netxfly/crack_ssh Coroutine-based ssh\redis\mongodb weak password cracking written in Go
  • https://github.com/UltimateHackers/Blazy Weak password detector that supports testing for CSRF, Clickjacking, Cloudflare and WAF
  • https://github.com/Moham3dRiahi/XBruteForcer CMS user password brute force for WordPress, Joomla, DruPal, OpenCart, Magento, etc.
  • https://github.com/shengqi158/weak_password_detect Uses nmap multi-threading to detect SSH weak passwords on Linux
  • https://github.com/ztgrace/changeme Weak password scanner that supports not only ordinary login pages but also components such as ssh and mongodb
  • https://github.com/lijiejie/htpwdScan simple, HTTP brute force and credential stuffing scripts
  • https://github.com/scu-igroup/ssh-scanner Integrates nmap and hydra for batch SSH brute forcing

Password Cracking

  • https://securityxploded.com/download.php Various small security tools related to passwords
  • https://github.com/bdutro/ibm_pw_clear IBM x3550/x3560 M3 BIOS password clear/reset tool
  • https://github.com/thehappydinoa/iOSRestrictionBruteForce py, iOS access restriction password cracking tool
  • https://github.com/hashcat/hashcat C, hash cracking
  • https://github.com/fireeye/gocrack GO, distributed password cracking tool based on hashcat 3.6.0+
  • https://github.com/s3inlc/hashtopolis PHP-based distributed cracking tool for hashcat, supports C# and Python clients
  • https://github.com/e-ago/bitcracker The first open-source BitLocker password cracking tool
  • https://www.ru.nl/publish/pages/909282/draft-paper.pdf Paper on cracking BitLocker used on SSDs
  • https://github.com/magnumripper/JohnTheRipper Password cracking software that attempts to recover plaintext when the ciphertext is known
  • https://github.com/shinnok/johnny GUI for JohnTheRipper password cracking, theoretically compatible with all features, includes a Windows interface
  • https://github.com/jmk-foofus/medusa Supports slightly fewer protocols than hydra, but is faster in some cases
  • https://github.com/MrSqar-Ye/wpCrack WordPress hash cracking
  • https://github.com/testsecer/Md5Decrypt C#, MD5 search tool based on online web APIs
  • https://github.com/s0md3v/Hash-Buster Smart tool that can call multiple APIs for hash cracking queries
  • https://www.52pojie.cn/thread-275945-1-1.html ARCHPR Pro 4.54 green Chinese cracked version. Archive password cracking; uses "known plaintext attack" to crack encrypted archives

Database Security

  • https://github.com/ron190/jsql-injection SQL injection tool written in Java
  • https://github.com/shack2/SuperSQLInjectionV1 A GUI injection tool by Anheng Hangniu
  • https://github.com/sqlmapproject/sqlmap SQL injection sqlmap
  • https://github.com/stamparm/DSSS SQL injection vulnerability scanner implemented in 99 lines of code
  • https://github.com/Hadesy2k/sqliv Search-engine-based batch SQL injection vulnerability scanner
  • https://github.com/quentinhardy/odat A very comprehensive tool specifically for Oracle penetration testing
  • https://github.com/m8r0wn/enumdb MySQL and MSSQL exploitation tool for post-brute-force, searching databases and extracting sensitive information.
  • https://github.com/LoRexxar/Feigong MySQL injection script that adapts freely to various situations
  • https://github.com/youngyangyang04/NoSQLAttack An attack tool targeting MongoDB
  • https://github.com/Neohapsis/bbqsql SQL blind injection exploitation framework
  • https://github.com/NetSPI/PowerUpSQL PowerShell-based SQL Server testing framework
  • http://www.4hou.com/system/14950.html Using PowerUpSQL, penetration testing technique: bypass SQL Server login trigger restrictions
  • https://github.com/WhitewidowScanner/whitewidow A database scanner
  • https://github.com/stampery/mongoaudit MongoDB audit and penetration tool
  • https://github.com/torque59/Nosql-Exploitation-Framework NoSQL scanning/brute-force tool
  • https://github.com/missDronio/blindy MySQL blind injection brute-force tool

Code Auditing- https://www.waitalone.cn/seay-source-code-auditv2.html Seay Source Code Audit System 2.1

  • https://github.com/pyupio/safety Check all installed Python packages for known security vulnerabilities
  • https://github.com/pumasecurity/puma-scan Real-time code audit, VS plugin
  • https://github.com/wufeifei/cobra White-box code security audit system
  • https://github.com/OneSourceCat/phpvulhunter Static PHP code audit
  • https://github.com/ripsscanner/rips PHP-based PHP code audit tool
  • https://github.com/Qihoo360/phptrace Tool for tracing and analyzing PHP runtime behavior
  • https://github.com/ajinabraham/NodeJsScan Node.JS application code audit
  • https://github.com/ctxis/beemka Exploitation toolkit for Electron apps
  • https://github.com/doyensec/electronegativity Electron application code audit, app misconfigurations and security issues
  • https://github.com/shengqi158/pyvulhunter Python application audit
  • https://github.com/securego/gosec Go language source code security analysis tool
  • https://github.com/GoSSIP-SJTU/TripleDoggy Clang-based C/C++/Objective-C source code detection framework with a large number of callable interfaces
  • https://github.com/ga0/pyprotect Encrypt Python code to prevent reverse engineering
  • https://github.com/presidentbeef/brakeman Static code analysis for Ruby on Rails applications
  • https://github.com/python-security/pyt Static analysis tool for detecting security vulnerabilities in Python web applications
  • https://github.com/m4ll0k/WPSploit WordPress plugin code security audit

Big Data Security

  • https://github.com/shouc/BDA Audit and detection for big data platforms such as Hadoop/Spark/MySQL
  • https://github.com/wavestone-cdt/hadoop-attack-library Hadoop testing methods and toolset

Vulnerability Reproduction

  • https://github.com/vulhub/vulhub Vulhub is an open-source vulnerability range for the general public. No Docker knowledge is required; just two commands compile and run a complete vulnerability range image.

  • https://github.com/Medicean/VulApps Collects various vulnerability environments, uniformly in Dockerfile format for convenience. It also collects security tool environments.

  • https://github.com/bingohuang/docker-labs Build an online Docker platform

Vulnerability Search

  • https://wooyun.kieran.top/#!/ WooYun Drops articles from before 2016, public vulnerability disclosure articles
  • https://wooyun.js.org/ WooYun Drops articles from before 2016, public vulnerability disclosure articles
  • https://dvpnet.io/list/index/state/3 Public vulnerability disclosure articles
  • https://sec.ly.com/bugs Tongcheng Security public vulnerability disclosure articles
  • http://ics.cnvd.org.cn China National Industrial Control Vulnerability Database
  • https://ics-cert.us-cert.gov/advisories US National Industrial Control Vulnerability Database
  • http://www.nsfocus.net/index.php?act=sec_bug NSFOCUS vulnerability database, including industrial control
  • http://ivd.winicssec.com/ Winicssec Industrial Control Vulnerability Database
  • http://cve.scap.org.cn/view/ics CVE Chinese industrial control vulnerability database
  • https://cve.mitre.org/cve/search_cve_list.html CVE vulnerability database maintained by MITRE Corporation in the US
  • https://www.exploit-db.com Exploit database by Offensive Security in the US
  • https://nvd.nist.gov/vuln/search US National Vulnerability Database

EXP&POC

  • https://github.com/Lcys/Python_PoC Python 3 quick PoC/EXP authoring templates, with many reference examples
  • https://github.com/raminfp/linux_exploit_development Linux exploit development handbook
  • https://github.com/mudongliang/LinuxFlaw Contains a list of software vulnerabilities on Linux
  • https://github.com/coffeehb/Some-PoC-oR-ExP Collection or authoring of various vulnerability PoCs and Exploits
  • https://github.com/userlandkernel/plataoplomo Sem Voigtländer publicly discloses various iOS vulnerabilities he found, including (Writeup/POC/Exploit)
  • https://github.com/coffeehb/Some-PoC-oR-ExP/blob/master/check_icmp_dos.py CVE-2018-4407, macOS/iOS buffer overflow that can cause system crashes
  • https://github.com/vulnersCom/getsploit Python 2, modeled after searchsploit, searches for payloads via official APIs of various databases
  • https://github.com/SecWiki/CMS-Hunter CMS vulnerability test case collection
  • https://github.com/Mr5m1th/0day Vulnerabilities and exploits for various versions of various open-source CMS
  • https://github.com/Al1ex/Heptagram Collection and categorization of exploits for various open-source CMS, Windows, Linux, applications, Email, etc.
  • https://github.com/w1109790800/penetration Collection table of exploits for new and old CMS versions and system vulnerabilities
  • https://github.com/blacknbunny/libSSH-Authentication-Bypass CVE-2018-10933, libssh server-side authentication bypass
  • https://github.com/leapsecurity/libssh-scanner CVE-2018-10933, libssh server-side authentication bypass
  • https://github.com/anbai-inc/CVE-2018-4878 Adobe Flash Exploit generates payloads

Java Vulnerabilities

  • https://github.com/brianwrf/hackUtils Java deserialization exploitation
  • https://github.com/GoSecure/break-fast-serial Tool that detects Java deserialization vulnerabilities via DNS resolution
  • https://github.com/s1kr10s/Apache-Struts-v3 Apache Struts exploitation tool
  • https://github.com/iBearcat/S2-057 Struts2 CVE-2018-11776 vulnerability detection tool
  • https://github.com/Ivan1ee/struts2-057-exp Struts2-057 exploitation script
  • https://github.com/theLSA/s2sniper Struts2 vulnerability detection tool
  • https://github.com/Lucifer1993/struts-scan Batch detection of Struts command execution vulnerabilities
  • https://github.com/lijiejie/struts2_045_scan Struts2-045 vulnerability batch scanning tool
  • https://github.com/riusksk/StrutScan Perl-based scanner for historical Struts2 vulnerabilities
  • https://github.com/Coalfire-Research/java-deserialization-exploits Collection of Java deserialization vulnerabilities
  • https://github.com/quentinhardy/jndiat WebLogic exploitation tool
  • https://github.com/jas502n/CVE-2018-3191 WebLogic CVE-2018-3191 remote code command execution
  • https://github.com/pyn3rd/CVE-2018-3245 WebLogic CVE-2018-2893 and CVE-2018-3245 remote code command execution
  • https://github.com/NickstaDB/BaRMIe Tool for Java Remote Method Invocation services / RMI enumeration and remote command execution
  • https://github.com/joaomatosf/jexboss Tool for verifying and exploiting JBoss and other Java serialization vulnerabilities

Office Vulnerabilities

  • https://github.com/Lz1y/CVE-2017-8759 .NET Framework newline vulnerability, CVE-2017-8759 perfect reproduction (also includes solution for HTA + PowerShell popup flicker) https://www.freebuf.com/vuls/147793.html
  • https://github.com/WyAtu/CVE-2018-8581 Exchange vulnerability using inbox rule creation for lateral movement and privilege escalation
  • https://github.com/dafthack/MailSniper PowerShell, used to search emails in Microsoft Exchange environments to find specific messages (passwords, network architecture info, etc.)
  • https://github.com/sensepost/ruler Go, interacts remotely with Exchange servers via MAPI/HTTP or RPC/HTTP protocols, remotely gets a shell through Outlook client features
  • https://github.com/3gstudent/Smbtouch-Scanner Scan the internal network for EternalBlue ETERNAL445 SMB family vulnerabilities
  • https://github.com/smgorelik/Windows-RCE-exploits Windows RCE vulnerability PoC samples, in both web and file forms
  • https://github.com/3gstudent/CVE-2017-8464-EXP CVE-2017-8464, Windows shortcut remote execution vulnerability
  • https://github.com/Lz1y/CVE-2018-8420 Windows MSXML parser vulnerability that can execute a backdoor via IE or VBS
  • https://www.anquanke.com/post/id/163000 Analysis of attack techniques using Excel 4.0 macros to evade antivirus detection
  • https://github.com/BuffaloWill/oxml_xxe XXE vulnerability exploitation
  • https://thief.one/2017/06/20/1/ A brief discussion on XXE vulnerability attacks and defense
  • https://github.com/thom-s/docx-embeddedhtml-injection Word 2016, PoC abusing the Word Online Video feature to execute malicious code
  • https://blog.cymulate.com/abusing-microsoft-office-online-video Word 2016, introduction to abusing the Word Online Video feature to execute malicious code

Other Vulnerabilities

  • https://github.com/shengqi158/svnhack .svn folder leak exploitation tool
  • https://www.waitalone.cn/seay-svn-poc-donw-20140505.html Seay-Svn source code leak exploit tool, 2014-05-05 version
  • https://github.com/BugScanTeam/GitHack .git file exploitation tool, improved version by lijiejie
  • https://github.com/lijiejie/GitHack .git file exploitation tool

Shell Management

  • http://www.bt.cn BaoTa Website Management System
  • https://github.com/AntSwordProject/antSword JavaScript, China AntSword, plugin-based development
  • https://github.com/Chora10/Cknife Java, China Chopper
  • https://github.com/naozibuhao/SecQuanCknife Java, upgraded version of China Chopper with added brute-force functionality
  • https://github.com/euphrat1ca/hatchet China Hatchet
  • https://github.com/tengzhangchao/PyCmd Python, one-liner webshell client program, currently supports PHP and JSP, encrypted client-server communication
  • https://github.com/epinna/weevely3 Python, manages websites using a specific one-liner script
  • https://github.com/nil0x42/phpsploit Python 3, manages websites using a specific one-liner script
  • https://github.com/wonderqs/Blade Python, manages websites using a specific one-liner script
  • https://github.com/anestisb/WeBaCoo Perl, manages websites using a specific one-liner script
  • https://github.com/keepwn/Altman .NET with Mono, a cross-platform China Chopper implementation
  • https://github.com/k4mpr3t/b4tm4n Integrates forged-email DDoS; bat.php webshell, originally by k4mpr3t
  • https://github.com/dotcppfile/DAws Firewall-bypassing webshell, POST pass=DAws
  • https://github.com/b374k/b374k PHP website management, default password b374k
  • https://github.com/wso-shell/WSO Webshell with file management, can disguise itself as a 404 page
  • https://github.com/UltimateHackers/nano PHP mini webshell, comes with a Python-written generator

Threat Intelligence

  • https://www.databases.today,https://publicdbhost.dmca.gripe/,http://www.wttech.org/,https://hashes.org/leaks.php,https://archive.org/search.php?query= Password leaks
  • https://www.threatcrowd.org/ Threat intelligence analysis platform
  • https://x.threatbook.cn/ ThreatBook | Threat Intelligence Analysis Platform - multi-engine online scanning, online malware detection
  • https://github.com/needmorecowbell/sniff-paste OSINT collection tool targeting Pastebin
  • https://talosintelligence.com/documents/ip-blacklist Malicious IP addresses
  • https://ransomwaretracker.abuse.ch/downloads/RW_IPBL.txt Malware IP addresses
  • https://check.torproject.org/cgi-bin/TorBulkExitList.py?ip=1.1.1.1 Tor exit relay nodes
  • https://isc.sans.edu/api/threatlist/shodan Shodan (Satan) scanner nodes
  • https://github.com/Te-k/harpoon CLI tool for OSINT and threat intelligence
  • https://trumail.io/ Verify whether a target email is a disposable mailbox; 1,000 free verifications per month
  • https://github.com/ChrisJohnRiley/Scythe Verify whether an account is a commonly used account
  • https://github.com/fireeye/GeoLogonalyzer Remote authentication geolocation analysis tool for distinguishing legitimate logins from malicious ones
  • https://github.com/target/strelka Python 3, threat intelligence analysis and real-time monitoring through real-time file scanning

Security Tools

Tool Collections

  • http://www.4hou.com/web/11241.html The most comprehensive roundup of attack simulation tools
  • https://github.com/infosecn1nja/Red-Teaming-Toolkit Information gathering, attack attempts to gain access, persistence control, privilege escalation, network information gathering, lateral movement, data analysis (then persistence control on top of that), and cleaning traces
  • https://github.com/toolswatch/blackhat-arsenal-tools Black Hat conference tools
  • https://www.cnblogs.com/k8gege K8 toolkit collection. Extraction passwords: Kk8team, Kk8gege
  • https://github.com/n00py/ReadingList/blob/master/gunsafe.txt Security toolset
  • https://github.com/Ridter/Pentest Security toolset
  • https://github.com/redcanaryco/atomic-red-team APT exploitation techniques, tactics, and toolkits for Windows, Linux, macOS, and more
  • https://github.com/Cooolis/Cooolis.github.io Cooolis is an OS command tricks cheat sheet, https://cooolis.payloads.online
  • https://github.com/LOLBAS-Project/LOLBAS Collection of scripts and binaries commonly exploited in penetration testing
  • https://www.owasp.org/index.php/File:CSRFTester-1.0.zip CSRF verification tool
  • https://github.com/ufrisk/MemProcFS Access physical memory like a file system; readable and writable, with an easy-to-use interface. Currently supports Windows
  • https://github.com/vletoux/SpoolerScanner Tool for detecting whether the Windows remote printer service (Print Spooler) is enabled
  • https://github.com/sirpsycho/firecall Send commands directly to Cisco ASA firewalls without needing to log in to the firewall to make changes

Other Tools

  • https://github.com/zaproxy/zaproxy A comprehensive penetration testing tool produced by The OWASP ZAP core project. Given its traffic proxying, request replay, and extensibility, it can also be used for fuzzing
  • https://github.com/x-Ai/BurpUnlimitedre Permanent cracked version of Burp Suite 1.7.27
  • https://github.com/andresriancho/w3af Well-known plugin-based scanner
  • https://github.com/juansacco/exploitpack Integrated penetration testing framework containing 38,000+ exploits
  • https://github.com/Lucifer1993/AngelSword Web application vulnerability scanning framework, Python 3, 300 PoCs
  • https://github.com/Xyntax/POC-T Plugin-based penetration testing scanning framework, comes with PoCs, concurrent scanning
  • https://github.com/knownsec/Pocsuite A standardized PoC/EXP exploitation framework maintained by Knownsec
  • https://github.com/leisurelicht/Pocsuite3 Pocsuite rewritten in Python 3
  • https://github.com/Eitenne/roxysploit Exploitation framework supporting direct EternalBlue exploitation
  • https://github.com/TophantTechnology/osprey A standardized PoC/EXP exploitation framework produced and long-term maintained by Tophant Capability Center
  • https://github.com/he1m4n6a/btScan DaHeiKuo's plugin-based vulnerability exploitation tool
  • https://github.com/boy-hack/w9scan Python, has 1200+ built-in plugins for large-scale website scanning
  • https://github.com/WooYun/TangScan A standardized PoC/EXP exploitation framework maintained by WooYun
  • https://github.com/n0tr00t/Beebeeto-framework Beebeeto is a standardized PoC/EXP exploitation framework jointly maintained by numerous security researchers

Common Plugins

AntSword
  • https://github.com/AntSword-Store/ China AntSword plugin marketplace
Kali Linux
  • https://github.com/secforce/sparta Python, GUI application integrating Nmap, Nikto, Hydra, and other tools
  • https://github.com/Manisso/fsociety One-click installer for a Kali-like toolkit on Linux
  • https://github.com/LionSec/katoolin Automatically install Kali toolkits using a Linux server
  • https://github.com/skavngr/rapidscan Python 2, simple vulnerability scanning tool integrating Kali tools
  • https://github.com/koenbuyens/kalirouter Set up Kali as a routing traffic analysis system
Nessus
  • https://www.tenable.com/downloads/nessus
  • https://github.com/se55i0n/Awvs_Nessus_Scanner_API API usage scripts for AWVS 11 and Nessus 7 scanners
  • https://github.com/DanMcInerney/msf-autoshell Perform Metasploit attacks based on Nessus scan results
  • https://github.com/MooseDojo/apt2 Integrate Nmap, Nessus, and other tools for security testing
AWVS
  • https://www.52pojie.cn/thread-214819-1-1.html AWVS 10.5 development framework cracked version
  • https://github.com/fnmsd/awvs_script_decode AWVS 10.5 rule scripts decrypted version, SDK, development manual
  • https://github.com/NS-Sp4ce/AWVS11.X-Chinese-Version AWVS 11 Chinese localization pack
Burp Suite
  • https://github.com/PortSwigger Official Burp Suite extension repository
  • https://github.com/snoopysecurity/awesome-burp-extensions The "awesome" series: Burp extensions
  • https://github.com/d3vilbug/HackBar Integrates HackBar
  • https://github.com/PortSwigger/turbo-intruder Faster than Burp's built-in Intruder, can make 16,100 requests per minute
  • https://github.com/Ebryx/AES-Killer Burp extension for cracking AES encryption
  • https://github.com/bugcrowd/HUNT Can make Burp Suite scanner capabilities even more powerful, also supports ZAP Proxy extensions
  • https://github.com/wagiro/BurpBounty Burp extension that enhances active and passive scanning
  • https://github.com/nccgroup/BurpSuiteHTTPSmuggler Burp extension that uses several techniques to bypass WAF
  • https://github.com/PortSwigger/command-injection-attacker Burp extension for command injection vulnerability detection
  • https://github.com/nccgroup/freddy Burp extension that automatically identifies deserialization vulnerabilities in Java/.NET applications
  • https://github.com/modzero/interestingFileScanner Burp extension that enhances sensitive file scanning
  • https://github.com/summitt/Burp-Non-HTTP-Extension Burp extension that sets up a DNS server to capture traffic
  • https://github.com/ilmila/J2EEScan Burp extension for scanning J2EE applications
  • https://github.com/JGillam/burp-co2 Integrates sqlmap, China Chopper, dictionary generation, etc.
  • https://github.com/swisskyrepo/SSRFmap Burp extension for detecting SSRF vulnerabilities
Sqlmap- https://github.com/codewatchorg/sqlipy Burp and sqlmap integration plugin
  • https://github.com/Hood3dRob1n/SQLMAP-Web-GUI Web GUI for sqlmap
  • https://github.com/KINGSABRI/sqlmap-tamper-api Write sqlmap tamper scripts in various languages
  • https://github.com/0xbug/SQLiScanner A passive SQL injection vulnerability scanner based on sqlmapapi and Charles
  • https://github.com/fengxuangit/Fox-scan A vulnerability scanner based on sqlmapapi for active and passive resource discovery
  • https://github.com/UltimateHackers/sqlmate Adds directory scanning, hash cracking, and other features on top of sqlmap
  • https://github.com/ysrc/GourdScanV2 A passive vulnerability scanner from ysrc, based on sqlmapapi
  • https://github.com/zt2/sqli-hunter A proxy-based vulnerability detection tool written in Ruby, based on sqlmapapi
  • https://github.com/jesuiscamille/AutoSQLi Uses DorkNet, Googler, Ddgr, WhatWaf, and sqlmap for automated injection
Nmap
  • https://github.com/Ullaakut/nmap Go, implements an Nmap invocation library
  • https://github.com/cldrn/nmap-nse-scripts NSE collection list
  • https://github.com/vulnersCom/nmap-vulners Use nmap to scan for common service vulnerabilities
  • https://github.com/s4n7h0/Halcyon Nmap Script (NSE) IDE editor
  • https://github.com/m4ll0k/AutoNSE NSE automated exploitation
  • https://github.com/Screetsec/Dracnmap Shell, integrates and simplifies Nmap's complex commands to a certain extent, making it easier for new users to get started.
  • https://github.com/cldrn/rainmap-lite Django, a web-based Nmap that can set up new scan servers and allows users to launch Nmap scans from their phone/tablet/web browser
  • https://github.com/trimstray/sandmap A Linux tool that supports network and system reconnaissance with extensive use of the Nmap engine
  • https://github.com/m0nad/HellRaiser A nmap-based scanner linked to CVE vulnerabilities
  • https://github.com/scipag/vulscan An advanced nmap-based vulnerability scanner for command-line environments
  • https://github.com/Rev3rseSecurity/WebMap A web viewer for nmap XML output
  • https://github.com/DanMcInerney/msf-autopwn Run an NMap scan or read scan results, then automatically use msf to attack hosts with common vulnerabilities
Metasploit
  • https://github.com/13o-bbr-bbq/machine_learning_security/tree/master/DeepExploit A fully automated testing tool combining machine learning with msf
  • https://github.com/r00t-3xp10it/Meterpreter_Paranoid_Mode-SSL A script that can create SSL/TLS shell connections
  • https://github.com/DanMcInerney/msf-netpwn Waits for an msf session and automatically elevates it to domain admin
  • https://www.exploit-db.com/exploits/45851/ msf plugin, uses Jira UPM upload for command execution
  • https://github.com/NullArray/AutoSploit Uses the Shodan search engine to gather targets and automatically invokes the configured msf modules to attack them
  • https://github.com/WazeHell/metateta Uses msf scripts to scan based on specific protocols
  • https://github.com/fbkcs/msf-elf-in-memory-execution Metasploit module for executing ELF files in memory
  • https://github.com/ElevenPaths/Eternalblue-Doublepulsar-Metasploit Metasploit EternalBlue-DoublePulsar exploit files
  • https://github.com/darkoperator/Metasploit-Plugins msf plugin for extended asset gathering and help
  • https://github.com/D4Vinci/One-Lin3r Metasploit and payload auxiliary query tool
  • https://github.com/shizzz477/msploitego Displays the msf database graphically with Maltego
  • https://github.com/scriptjunkie/msfgui A GUI for Metasploit. By the way, msf's Windows support is pretty good these days
CobaltStrike
  • https://github.com/Al1ex/CSPlugins Various CobaltStrike plugins

  • https://mp.weixin.qq.com/s/CEI1XYkq2PZmYsP0DRU7jg Using Aggressor scripts to sculpt Cobalt Strike

  • https://github.com/rsmudge/armitage CobaltStrike Community Edition, invokes msf, one-to-many with GUI

  • https://github.com/anbai-inc/CobaltStrike_Hanization CobaltStrike 2.5 Chinese localized version, based on the msf library, redesigned after 3.0

  • https://github.com/rsmudge/cortana-scripts Extensible plugins for CS 2.x and Armitage; for CS 3.x, they are AggressorScripts

  • https://github.com/harleyQu1nn/AggressorScripts Script collection for CS 3.0 and later

  • https://github.com/FortyNorthSecurity/AggressorAssessor Collection of automated attack scripts for CS 3.x

  • https://github.com/Ridter/CS_Chinese_support/ Chinese localization plugin for CS 3.0's transmitted information

  • https://github.com/verctor/CS_xor64 Generates the xor64.bin required by CobaltStrike

  • https://github.com/ryhanson/ExternalC2 A library for integrating communication channels with Cobalt Strike External C2 servers

  • https://github.com/threatexpress/cs2modrewrite A tool for converting Cobalt Strike configuration files into mod_rewrite scripts

  • https://github.com/Mr-Un1k0d3r/CatMyFish Searches categorized domains and sets up whitelist domains for Cobalt Strike beacon C&C

  • https://github.com/threatexpress/malleable-c2 Uses jQuery files for C2 communication, with JS obfuscation inside the files to bypass firewalls

Empire
  • https://paper.tuisec.win/detail/f3dce68a0b4baaa Use Empire to obtain domain controller privileges
  • https://github.com/EmpireProject/Empire-GUI Node.js interface for Empire
  • https://github.com/interference-security/empire-web Web interface for Empire
  • https://github.com/byt3bl33d3r/DeathStar py3, calls the Empire RESTful API to automate obtaining domain admin privileges
  • https://github.com/infosecn1nja/e2modrewrite Used to convert Empire configuration files into Apache mod_rewrite scripts
  • https://github.com/maxchehab/CSS-Keylogging Chrome extension and Express server that exploit CSS keylogging functionality.
  • https://github.com/evilcos/cookiehacker Chrome extension. JavaScript document.cookie / Wireshark Cookie
  • https://github.com/lfzark/cookie-injecting-tools Chrome extension, cookie injection tool including injecting, editing, adding, and deleting cookies

Internal Network Security

Recommended Content

  • https://attack.mitre.org/wiki/Lateral_Movement MITRE's summary of lateral movement

  • https://payloads.online/archivers/2018-11-30/1 Thoroughly Understanding Windows Authentication - Topic Analysis

  • https://github.com/klionsec/klionsec.github.io The learning journey of an intranet security expert

  • https://github.com/l3m0n/pentest_study Learning intranet penetration testing from scratch

  • https://github.com/Ridter/Intranet_Penetration_Tips Intranet penetration testing TIPS

  • https://github.com/OpenWireSec/metasploit Post-exploitation framework

  • https://github.com/EmpireProject/Empire PowerShell-based command execution framework

  • https://github.com/TheSecondSun/Bashark Post-exploitation framework written in pure Bash scripts, "Big Shark"

  • https://github.com/JusticeRage/FFM py3, post-exploitation framework with download and upload capabilities that generates executable Python script backdoors

  • https://github.com/DarkSpiritz/DarkSpiritz py2, post-exploitation framework

  • https://github.com/byt3bl33d3r/CrackMapExec The Swiss Army knife of network testing, includes Impacket, PowerSploit, and many other modules

  • https://github.com/SpiderLabs/scavenger Secondary wrapper development around CrackMapExec for scanning sensitive information on internal networks

  • https://github.com/jmortega/python-pentesting python-pentesting-tool, functional modules related to Python security tools

Forwarding | Proxy

  • https://github.com/fatedier/frp A high-performance reverse proxy application for intranet penetration, supports tcp, udp, http, https protocols
  • https://github.com/inconshreveable/ngrok Port forwarding, forward and reverse proxy, intranet penetration
  • http://ngrok.ciqiuwl.cn/ Online Xiaomiqiu ngrok
  • https://github.com/knownsec/rtcp Socket port forwarding for remote maintenance
  • https://github.com/davrodpin/mole SSH-based port forwarding
  • http://rootkiter.com/EarthWorm A tool for enabling SOCKS v5 proxy services, developed in standard C, providing cross-platform relay communication for data forwarding in complex network environments.
  • http://rootkiter.com/Termite/README.txt Upgraded version of EarthWorm, supports multi-node hopping
  • https://github.com/SECFORCE/Tunna Can tunnel any TCP communication through HTTP encapsulation, used to bypass network restrictions in firewall environments
  • https://github.com/fbkcs/thunderdns Forwards TCP traffic via the DNS protocol, no client or SOCKS5 support required
  • https://github.com/sensepost/reGeorg An upgraded version of reDuh, mainly forwards intranet server ports to the local machine through an HTTP/HTTPS tunnel, forming a loop. Used to connect to open internal ports on target servers when the target is on an intranet or has port policies in place (provides forward and reverse proxies for PHP, ASP, and JSP scripts)
  • https://github.com/SpiderClub/haipproxy py3, Scrapy and Redis, high-availability IP proxy pool
  • https://github.com/chenjiandongx/async-proxy-pool py3, asynchronous crawler IP proxy pool
  • https://github.com/audibleblink/doxycannon Uses an OpenVPN proxy pool, spawning a Docker container for each one; when one VPN is connected, the others do SOCKS5 forwarding for traffic distribution

Lateral Movement

  • http://www.oxid.it/cain.html Cain & Abel supports password recovery and ARP man-in-the-middle attacks
  • https://github.com/gentilkiwi/mimikatz The ultimate tool for lateral movement on Windows, focused on password harvesting
  • https://github.com/skelsec/pypykatz Mimikatz implemented in pure py3
  • https://github.com/eladshamir/Internal-Monologue Extracts content from LSASS process memory using Mimikatz without needing the LSASS process, extracting plaintext passwords, NTLM hashes, Kerberos tickets from memory, and performing pass-the-hash/pass-the-ticket attacks, etc.
  • https://github.com/AlessandroZ/LaZagne py3, credential harvesting tool
  • https://github.com/AlessandroZ/LaZagneForensic Upgraded version of LaZagne credential cracking, uses DPAPI; current drawback is it requires the Windows user password
  • https://github.com/twelvesec/passcat Credential harvesting tool for Windows
  • https://github.com/huntergregal/mimipenguin The ultimate tool for Linux password harvesting
  • https://github.com/quarkslab/quarkspwdump A credential harvesting tool from Quarkslab, no need to inject into any process
  • https://github.com/mthbernardes/sshLooter Steals usernames and passwords from SSH services
  • https://github.com/nettitude/Invoke-PowerThIEf Uses IE for post-exploitation, credential harvesting, redirecting, etc.
  • https://github.com/GhostPack/Rubeus A library for operating Kerberos, implements most of Kekeo's functionality, written in C#
  • https://github.com/m8r0wn/ldap_search Python, enumerates Windows domain information via LDAP (Lightweight Directory Access Protocol) authentication and brute-forces logins

Command and Control

  • https://github.com/malwaredllc/byob Botnet generation framework
  • https://github.com/proxycannon/proxycannon-ng Build an offensive botnet
  • https://github.com/deadPix3l/CryptSky/ Ransomware PoC
  • https://github.com/jgamblin/Mirai-Source-Code Worm virus PoC
  • https://github.com/AhMyth/AhMyth-Android-RAT Based on smali, Android RAT for Windows, one-to-many with GUI
  • https://github.com/ssooking/cobaltstrike3.12_cracked java1.8, remote control, phishing, intranet
  • https://github.com/Mr-Un1k0d3r/ThunderShell py2, CLI and web, in-memory webshell, RC4-encrypted HTTP transport
  • https://github.com/tiagorlampert/CHAOS Go, Windows RAT, bypasses most antivirus software
  • https://github.com/Ne0nd0g/merlin Go, C2 communication, one-to-many
  • https://github.com/0x09AL/Browser-C2 Go, uses Chrome to connect to C2 servers in the form of a browser
  • https://github.com/xdnice/PCShare C++, can monitor the target machine's screen, registry, file system, etc.
  • https://github.com/quasar/QuasarRAT C#, one-to-many, with GUI
  • https://github.com/TheM4hd1/Vayne-RaT C#, one-to-many, with GUI
  • https://github.com/nettitude/PoshC2 PowerShell, C#, remote control tool with Windows privilege escalation components
  • https://github.com/euphrat1ca/njRAT-v0.7d VB, common worm RAT with many variants, one-to-many with GUI
  • https://github.com/zerosum0x0/koadic py3, uses JScript/VBScript for control, "Big Sword"

Privilege Escalation

Linux Privilege Escalation
  • https://github.com/Al1ex/Heptagram/tree/master/Linux/Elevation Linux privilege escalation collection

  • https://github.com/AlessandroZ/BeRoot Python, finds privilege escalation methods by checking common misconfigurations. Supports Windows/Linux/Mac

  • https://github.com/mschwager/0wned Uses Python packages to create high-privilege users

  • https://github.com/mzet-/linux-exploit-suggester Script to find which patches are missing on Linux

  • https://github.com/belane/linux-soft-exploit-suggester Find vulnerable software on Linux

  • https://github.com/dirtycow/dirtycow.github.io Dirty COW privilege escalation exploit

  • https://github.com/FireFart/dirtycow Dirty COW privilege escalation exploit

  • https://github.com/stanleyb0y/sushell Uses an "su thief" to let low-privilege users steal the root password

  • https://github.com/jas502n/CVE-2018-17182/ Linux kernel VMA-UAF privilege escalation vulnerability CVE-2018-17182

  • https://github.com/jas502n/CVE-2018-14665 CVE-2018-14665, Xorg X server privilege escalation exploit for Linux

  • https://github.com/nmulasmajic/syscall_exploit_CVE-2018-8897 Linux system privilege escalation via Syscall

  • https://github.com/can1357/CVE-2018-8897 Linux system privilege escalation via Syscall

  • https://github.com/SecWiki/linux-kernel-exploits linux-kernel-exploits, collection of Linux platform privilege escalation vulnerabilities

Windows Privilege Escalation
  • https://github.com/Al1ex/Heptagram/tree/master/Windows/Elevation Windows privilege escalation collection
  • http://www.fuzzysecurity.com/tutorials/16.html Tutorial-level Windows privilege escalation reference article
  • https://github.com/SecWiki/windows-kernel-exploits Collection of Windows platform privilege escalation exploits
  • https://github.com/51x/WHP Various Windows privilege escalation and exploitation tools
  • https://github.com/rasta-mouse/Sherlock Windows privilege escalation vulnerability verification
  • https://github.com/WindowsExploits/Exploits Microsoft CVE-2012-0217, CVE-2016-3309, CVE-2016-3371, CVE-2016-7255, CVE-2017-0213 privilege escalation exploits
  • https://github.com/decoder-it/lonelypotato RottenPotatoNG variant, uses NBNS local name spoofing and WPAD proxy spoofing for privilege escalation
  • https://github.com/ohpe/juicy-potato RottenPotatoNG variant, uses COM objects and user tokens for privilege escalation
  • https://github.com/foxglovesec/Potato RottenPotatoNG variant, uses local name spoofing and proxy spoofing for privilege escalation
  • https://github.com/DanMcInerney/icebreaker When you are on an intranet but outside the AD environment, Icebreaker will help you obtain plaintext Active Directory credentials (the Active Directory stored on domain controllers can be used for privilege escalation)
  • https://github.com/hausec/ADAPE-Script Active Directory privilege escalation script
  • https://github.com/klionsec/BypassAV-AllThings Uses an ASPX one-liner combined with a privilege escalation payload
  • https://github.com/St0rn/Windows-10-Exploit msf plugin, Windows 10 UAC bypass
  • Exploits the Win32k.sys kernel vulnerability for privilege escalation, ms14-058

Bypass

Privilege Bypass

  • https://payloads.online/archivers/2018-12-22/1 DLL Hijacking & COM Hijacking Bypass UAC - Topic Analysis
  • https://github.com/tyranid/DotNetToJScript A tool that can use JS/VBS scripts to load .NET programs
  • https://github.com/mdsecactivebreach/SharpPack Bypass system application whitelisting to execute DotNet and PowerShell tools
  • https://github.com/rootm0s/WinPwnage py2, Windows privilege escalation, UAC bypass, DLL injection, etc.
  • https://github.com/hfiref0x/UACME Contains many methods for bypassing Windows User Account Control across multiple OS versions
  • https://github.com/Ben0xA/nps Implements executing PowerShell commands without using powershell.exe
  • https://github.com/Mr-Un1k0d3r/PowerLessShell Implements executing PowerShell commands without invoking powershell.exe
  • https://github.com/p3nt4/PowerShdll Uses rundll32 to run PowerShell, bypassing software restrictions
  • https://github.com/ionescu007/r0ak The Swiss Army knife of the kernel layer. Read/write/execute code in the Windows 10 kernel
  • https://github.com/leechristensen/UnmanagedPowerShell Executes PowerShell from an unmanaged program; with some modifications, it can be used to inject into other processes
  • https://github.com/stephenfewer/ReflectiveDLLInjection A library injection technique that lets a DLL map itself into the target process memory without using the LoadLibraryA function
  • https://github.com/ChrisAD/ads-payload Uses environment variables and destop.ini to bypass Palo Alto Traps endpoint protection software on Windows
  • https://github.com/Zer0Mem0ry/RunPE Reads content through memory and network transmission, and uses PE to execute shellcode

Sandbox Escape

  • https://github.com/hacksysteam/WpadEscape Uses WPAD for browser sandbox escape
  • https://github.com/unamer/vmware_escape VMware virtual machine escape. CVE-2017-4901, CVE-2018-6981, CVE-2018-6982
  • https://github.com/MorteNoir1/virtualbox_e1000_0day VirtualBox E1000 Guest-to-Host Escape. Tutorial
  • https://bugs.chromium.org/p/project-zero/issues/detail?id=1682&desc=2 Ghostscript: -dSAFER sandbox escape technique based on vulnerability CVE-2018-17961

Backdoor AV Evasion

  • https://www.shellterproject.com Antivirus bypass
  • https://github.com/trustedsec/unicorn Python, one-click generation of multiple backdoors
  • https://github.com/islamTaha12/Python-Rootkit Windows rootkit, reverse Meterpreter
  • https://github.com/n00py/Hwacha Quickly generate Meterpreter and various other payloads on Linux
  • https://github.com/Screetsec/Vegile msf AV evasion, process injection
  • https://github.com/MohamedNourTN/Terminator py2, msf AV evasion
  • https://github.com/Veil-Framework/Veil msf AV evasion
  • https://github.com/abedalqaderswedan1/aswcrypter Python, Bash, msf AV evasion
  • https://github.com/Screetsec/TheFatRat Java, msf AV evasion, uses searchsploit for quick searches
  • https://github.com/pasahitz/zirikatu msf AV evasion
  • https://github.com/govolution/avet msf AV evasion
  • https://github.com/GreatSCT/GreatSCT msf AV evasion
  • https://github.com/EgeBalci/HERCULES msf AV evasion
  • https://github.com/trustedsec/nps_payload msf AV evasion
  • https://github.com/4w4k3/Insanity-Framework Python, payload generation, bypass antivirus, VM detection, phishing, memory injection, etc.
  • https://github.com/hlldz/SpookFlare A generator of loaders/droppers for Meterpreter, Empire, Koadic, etc., can bypass endpoint policies for client-side and network-side detection
  • https://github.com/pasahitz/regsvr32 Uses C# + Empire to implement a minimal-size AV-evading backdoor

File Bundling

  • bat2exe.net Similarly, you can also use IExpress and WinRAR to generate self-extracting EXE executables
  • https://github.com/islamadel/bat2exe Convert bat files to EXE binaries
  • https://github.com/tywali/Bat2ExeConverter Convert bat files to EXE binaries
  • https://github.com/Juntalis/win32-bat2exe Convert bat files to EXE binaries
  • http://www.f2ko.de/downloads/Bat_To_Exe_Converter.zip Convert bat files to EXE binaries, can hide the window.
  • https://github.com/r00t-3xp10it/trojanizer Packages two executables into a self-extracting archive; the self-extracting file runs the executables when executed
  • https://github.com/r00t-3xp10it/backdoorppt Change the payload's icon
  • https://github.com/r00t-3xp10it/FakeImageExploiter Change the payload's icon. Requires Wine and Resource Hacker environments
  • https://github.com/DamonMohammadbagher/FakeFileMaker Change the icon and name
  • https://github.com/peewpw/Invoke-PSImage Hides a PowerShell script in PNG pixels and executes it with a single command
  • https://github.com/Mr-Un1k0d3r/DKMC "Don't Kill My Cat" - generates obfuscated shellcode and stores the shellcode in polyglot images
  • https://github.com/deepzec/Bad-Pdf Generates a PDF file containing a payload to steal Net-NTLM hashes on Windows
  • https://github.com/3gstudent/Worse-PDF Inserts malicious code into PDF files to steal Net-NTLM hashes on Windows

Identity Concealment

  • https://github.com/leitbogioro/Fuck_Aliyun Disable Alibaba Cloud monitoring services
  • https://github.com/Nummer/Destroy-Windows-10-Spying DWS disables Windows monitoring services
  • https://github.com/Rizer0/Log-killer Log clearing, for all Windows/Linux servers
  • https://github.com/360-A-Team/EventCleaner Log erasure tool
  • https://github.com/s-rah/onionscan Dark web crawler
  • https://github.com/globaleaks/Tor2web Dark web proxy server that turns onion services into ordinary services
  • https://github.com/milesrichardson/docker-onion-nmap Uses nmap to scan hidden "onion" services on the Tor network
  • https://github.com/GouveaHeitor/nipe A script that routes all traffic through the Tor network
  • https://github.com/trimstray/multitor Enables multiple Tor channels to forward traffic and sets up load balancing

Privacy and Anonymity

  • https://www.lshack.cn/118/ A large collection for online verification code reception/email/clipboard/file transfer.
  • http://bccto.me Disposable email
  • https://www.guerrillamail.com Disposable email
  • http://24mail.chacuo.net/ Disposable email
  • http://www.yopmail.com Disposable email
  • https://yandex.com/ Email without phone verification
  • https://mail.ru/ Email without phone verification
  • https://mail.protonmail.com/login Email without phone verification
  • https://github.com/walkor/workerman-chat PHP, online chat room, extensible
  • https://github.com/hack-chat https://hack.chat/?your-channel JS, online chat; your room name goes after the question mark
  • https://github.com/akaxincom/openzaly Java, chat room; Akaxin is the closed-source client
  • https://github.com/RocketChat/Rocket.Chat JS, online team chat server, https://rocket.chat/install
  • https://telegram.org
  • https://www.whatsapp.com
  • https://wire.com/en
  • https://signal.org
  • http://www.batmessenger.com
  • http://sid.co

Crawler Related- https://github.com/alphardex/looter Lightweight crawler framework, comparable to Scrapy

  • https://github.com/luyishisi/Anti-Anti-Spider Bypass anti-crawler measures
  • https://github.com/xchaoinfo/fuck-login Simulate login to some common websites
  • https://github.com/Maicius/InterestingCrawler Scrape QQ Zone post content and analyze it
  • https://github.com/xjr7670/QQzone_crawler QQ Zone feed crawler, uses cookie login to obtain the feeds of all accessible friend spaces and save them locally

Social Engineering Phishing

Recommended Content

  • https://github.com/brannondorsey/PassGAN py, deep learning, password dictionary sample generation
  • https://github.com/Mebus/cupp Generate weak password probes based on user habit passwords
  • https://github.com/Saferman/cupper Generate weak password probes based on user habit passwords, an upgrade of the one above
  • https://github.com/LandGrey/pydictor py3, specific password dictionary generation
  • https://github.com/mehulj94/Radium-Keylogger keyboard logging tool for python
  • https://github.com/threatexpress/domainhunter Check expired domains, bluecoat classification and Archive.org history to determine the domains most suitable for phishing and C2
  • https://github.com/Mr-Un1k0d3r/CatMyPhish Collect similar unregistered domains of the target
  • https://github.com/x0day/Multisearch-v2 Aggregated search across Bing, google, 360, zoomeye and other search engines, can be used to discover sensitive asset information of enterprises indexed by search engines
  • https://github.com/n0tr00t/Sreg Sreg can return all internet passport information registered by the user through input of email, phone, username.
  • https://github.com/SpiderLabs/social_mapper Social media enumeration and correlation tool, correlates people profiling through face recognition
  • https://github.com/vysec/MaiInt Company employee information gathering testing tool
  • https://github.com/jofpin/trape py, uses OSINT to track and locate people
  • https://github.com/famavott/osint-scraper Input a person's name or email address, automatically crawl information about this person from the internet
  • https://github.com/xHak9x/fbi py2, facebook information gathering tool

Website Cloning

  • http://www.httrack.com Website cloning/mirroring

Phishing Frameworks

  • https://github.com/bhdresh/SocialEngineeringPayloads Responsible for collecting social engineering techniques and payloads for credential theft and spear phishing attacks
  • https://github.com/trustedsec/social-engineer-toolkit Open source penetration testing framework designed specifically for social engineering
  • https://github.com/thelinuxchoice/blackeye One-click tool with more than thirty phishing templates including facebook, instagram, etc.
  • https://github.com/M4cs/BlackEye-Python Based on blackeye, with enhanced subdomain management
  • https://github.com/azizaltuntas/Camelishing py3, GUI-based social engineering attack auxiliary tool
  • https://github.com/JonCooperWorks/judas go, clone website phishing
  • https://github.com/gophish/gophish go, phishing system with online template design, sending lure ads and other functions
  • https://github.com/tatanus/SPF py2, phishing system on deefcon
  • https://github.com/MSG-maniac/mail_fishing Internal phishing system for Party A (the client)
  • https://github.com/samyoyo/weeman http server for phishing
  • https://github.com/Raikia/FiercePhish A complete phishing framework that can manage all phishing attacks, allows you to track individual phishing campaigns, send emails on schedule, etc.
  • https://github.com/securestate/king-phisher Visual phishing campaign toolkit
  • https://github.com/fireeye/ReelPhish Real-time two-factor phishing tool
  • https://github.com/kgretzky/evilginx Phishing framework that bypasses two-factor verification
  • https://github.com/kgretzky/evilginx2 MiTM framework, login page phishing, bypassing two-factor authentication, etc.

Traffic Hijacking

  • https://github.com/bettercap/bettercap Swiss Army knife for network attacks and monitoring. The tool supports multiple modules, such as ARP/DNS spoofing, TCP and packet proxying, etc.
  • https://github.com/mitmproxy/mitmproxy PY, supports SSL interception for https traffic proxying
  • https://github.com/qiyeboy/BaseProxy py3, asynchronous http/https proxy, simplified version of the one above. Can be used as a man-in-the-middle tool, e.g., replacing web page images
  • https://github.com/lgandx/Responder Used to sniff all NTLM, NTLMv1/v2, Net-NTLMv1/v2 packets in the network, spoof hosts in the network to obtain user hashes. a requests b while holding b's password, c tells a "I am b", and then c obtains b's password, https://www.secpulse.com/archives/65503.html [Pulse Translation Series] Penetration Tester's Guide to Responder.
  • https://github.com/Kevin-Robertson/Inveigh A PowerShell LLMNR / mDNS / NBNS spoofer and man-in-the-middle tool
  • https://github.com/LionSec/xerosploit Man-in-the-middle attack testing toolkit
  • https://github.com/AlsidOfficial/WSUSpendu Can autonomously create malicious updates, inject them into the WSUS server database, and then arbitrarily distribute these malicious updates
  • https://github.com/infobyte/evilgrade A modular scripting framework that allows attackers to inject malicious updates into user updates without their knowledge
  • https://github.com/quickbreach/smbetray Focuses on attacking clients through file content swapping and lnk swapping, as well as stealing any data transmitted in plaintext
  • https://github.com/mrexodia/haxxmap Man-in-the-middle attacks against IMAP servers

Traffic Analysis

  • https://github.com/wireshark/wireshark Protocol parsing, traffic analysis and restoration
  • https://github.com/CoreSecurity/impacket Impacket is a collection of Python toolkits for handling network protocols. In intranet environments it can be used for privilege escalation, e.g. wmiexec.py, NMB; SMB1-3 and MS-DCERPC provide low-level programming access to the protocol implementations themselves.
  • https://github.com/secdev/scapy Built-in interactive network packet processing, packet generator, network scanner, network discovery and packet sniffing tools, provides multiple protocol packet generation and parsing plugins, can flexibly generate protocol packets, and modify and parse them.
  • https://gitee.com/qielige/openQPA Open source code of the protocol analysis software QPA, featuring process packet capture and automatic feature analysis
  • https://github.com/jtpereyda/boofuzz Network protocol fuzz testing
  • https://www.jianshu.com/p/4dca12a35158 5 commonly used free packet libraries
  • https://github.com/zerbea/hcxdumptool Capture packets from Wlan devices
  • https://github.com/NytroRST/NetRipper Supports intercepting plaintext passwords in putty, winscp, mssql, chrome, firefox, outlook, https
  • https://github.com/shramos/polymorph Real-time network packet manipulation framework supporting almost all existing protocols
  • https://github.com/nospaceships/raw-socket-sniffer C, PS, capture Windows traffic without drivers

Wireless Security

Recommended Content

  • https://github.com/wi-fi-analyzer/fluxion Steal user wifi passwords by performing password replay attacks
  • https://github.com/0v3rl0w/e013 Steal Wifi passwords. VB script
  • https://github.com/cls1991/ng Get the password and ip of your currently connected wifi
  • https://github.com/wifiphisher/wifiphisher PY, man-in-the-middle attack, FakeAp malicious hotspot, WIFI phishing, credential theft
  • https://github.com/1N3/PRISM-AP Automatically deploy RogueAP (malicious hotspot) MITM attack framework
  • https://github.com/sensepost/mana Wifi hijacking tool, can monitor the Wifi communications of computers or other mobile devices, and can imitate that device
  • https://github.com/deltaxflux/fluxion bash and py, MiTM attacks against wireless networks using the WPA protocol
  • https://github.com/DanMcInerney/LANs.py ARP spoofing, wireless network hijacking

WIFI Defense

  • https://github.com/SYWorks/waidps PY, wireless network intrusion detection tool under Linux
  • https://github.com/SkypLabs/probequest Sniff and display Wifi Probe requests near the wireless network card
  • https://github.com/wangshub/hmpa-pi On Raspberry Pi or router, use Wireshark to scan nearby network WiFi devices, and when a phone or other Wi-Fi device is nearby, alert via email or WeChat
  • https://github.com/besimaltnok/PiFinger Check whether the wifi is a malicious hotspot opened by "Wifi-Pineapple"
  • https://github.com/WiPi-Hunter/PiSavar Uses PineAP to monitor FAKE AP false access points, such as "Wifi-Pineapple"

WIFI Audit

  • https://www.wifislax.com Spanish wifi audit system, domestic Chinese localized version is Wireless Innovation 5.1.1 Wifislax-WRC
  • https://cn.elcomsoft.com/ewsa.html ewsa, wifi sniffing, handshake packet password recovery, EWSA-173-HC1UW-L3EGT-FFJ3O-SOQB3
  • https://www.passcape.com wifipr, handshake packet password recovery, in addition there are many commercial Windows password recovery tools
  • https://github.com/MisterBianco/BoopSuite Wireless network audit tool, supports 2-5GHZ frequency bands
  • https://github.com/aircrack-ng/aircrack-ng Composed of a packet sniffer, detector, WPA / WPA2-PSK decryptor, WEP, and analysis tools for 802.11 wireless LANs
  • https://github.com/t6x/reaver-wps-fork-t6x wps pin code brute-force attack, a common wifi attack
  • https://github.com/derv82/wifite2 Upgraded version of the wifite wireless audit tool, integrated with aircrack-ng and reaver
  • https://github.com/savio-code/fern-wifi-cracker Wireless security audit tool
  • https://github.com/P0cL4bs/WiFi-Pumpkin Wireless security penetration testing suite
  • https://github.com/entropy1337/infernal-twin Automated wireless attack tool Infernal-Wireless
  • https://github.com/m4n3dw0lf/PytheM Python network/penetration testing tool
  • https://github.com/InfamousSYN/rogue Wireless network attack toolkit
  • https://github.com/cSploit/android Mobile WiFi penetration tool framework, can use msf
  • https://github.com/chrisk44/Hijacker Mobile wifi testing tool
  • https://andrax-pentest.org/ kali hunter mobile penetration testing system

Data Exfiltration

  • https://github.com/TryCatchHCF/Cloakify Evade DLP/MLS data leakage protection systems, break through data whitelist controls, evade AV detection for data theft
  • https://github.com/sensepost/DET Perform data exfiltration using single or multiple channels simultaneously
  • https://github.com/Arno0x/DNSExfiltrator Tool for covert data transmission using DNS resolution
  • https://github.com/ytisf/PyExfil Python package for data exfiltration
  • https://github.com/Arno0x/ReflectiveDnsExfiltrator Reflective DNS resolution covert channel for data leakage

Hardware Security

  • https://github.com/unprovable/PentestHardware Hardware penetration testing practical handbook
  • https://ducktoolkit.com/ Rubber Ducky, HID keyboard emulator
  • https://github.com/insecurityofthings/jackit Development code for Mousejack
  • https://github.com/samyk/magspoof Credit card information theft
  • https://github.com/mame82/P4wnP1_aloa Install commonly used test components on Raspberry Pi to build a mobile testing platform
  • https://www.freebuf.com/geek/195631.html Become a physical hacker! Use Raspberry Pi to implement the P4wnP1 project for penetration testing
  • https://github.com/mame82/P4wnP1 Install network hijacking keyboard injection (WHID) tool on Raspberry Pi
  • https://github.com/ebursztein/malusb Create cross-platform HID spoofing payloads and establish reverse TCP-shells on Windows and OSX
  • https://github.com/Orange-Cyberdefense/fenrir-ocd Main function and purpose is to bypass wired 802.1x protection and enable you to access the target network
  • https://github.com/360PegasusTeam/GhostTunnel Can use HID to generate a covert backdoor in isolated environments, and delete itself after releasing the payload
  • https://github.com/LennyLeng/RadioEye RFID used together with common NFC
  • https://github.com/Proxmark/proxmark3/ RFID artifact PM3
  • http://www.freebuf.com/news/others/605.html RFID Hacking - Resource Collection
  • https://github.com/UnicornTeam/HackCube-Special Unicorn Team hardware penetration testing platform

IoT Security

Recommended Content

  • https://github.com/w3h/icsmaster Consolidate industrial control security resources
  • https://github.com/V33RU/IoTSecurity101 Some articles and resources for learning IoT industrial control security and IoT security
  • http://www.freebuf.com/ics-articles Industrial control related
  • http://www.freebuf.com/sectool/174567.html Testing tools and security resources essential for industrial control system (ICS) security experts
  • http://www.freebuf.com/articles/ics-articles/178822.html Brief analysis of how coal enterprises conduct industrial control security construction
  • http://www.freebuf.com/articles/network/178251.html Experience from on-site industrial control security implementation - how industrial control systems can strengthen host protection
  • https://github.com/hslatman/awesome-industrial-control-system-security Excellent resource collection repository for industrial control system security
  • https://github.com/adi0x90/attifyos IoT integrated security testing system, with some commonly used software
  • https://github.com/moki-ics/moki One-click script to configure a kali-like industrial control penetration testing system,
  • https://gitlab.com/expliot_framework/expliot py3, industrial control security vulnerability testing framework
  • https://github.com/dark-lbp/isf py2, msf-like testing framework for industrial control
  • https://github.com/enddo/smod py2, uses the scapy module, mainly for modbus protocol testing
  • https://github.com/shodan-labs/iotdb nmap combined with shodan API to scan IoT devices
  • https://github.com/XHermitOne/icscanner ics scanner with a GUI

Camera Security

  • https://github.com/woj-ciech/kamerka Display the geographic locations of cameras scanned with the shodan API on a map
  • https://github.com/Ullaakut/cameradar GO, penetration testing against the camera RTSP protocol, with weak password dictionary attached
  • https://github.com/Ullaakut/camerattack GO, remotely disable cameras
  • https://github.com/NIteshx2/UltimateSecurityCam py3, camera software for monitoring outsiders, with anti-spoofing settings

Router Security

  • http://stascorp.com RouterScan, a router vulnerability exploitation tool developed by Russians, with a very powerful GUI
  • https://github.com/threat9/routersploit py3, msf-style router vulnerability exploitation framework
  • https://github.com/jh00nbr/Routerhunter-2.0 No longer updated, router vulnerability scanning and exploitation
  • https://github.com/googleinurl/RouterHunterBR php, router device vulnerability scanning and exploitation
  • https://github.com/scu-igroup/telnet-scanner Telnet service password credential stuffing

Fuzz Testing

  • http://www.freebuf.com/articles/rookie/169413.html A collection of resources for Fuzzing learning
  • https://github.com/secfigo/Awesome-Fuzzing Fuzz related learning materials
  • https://github.com/fuzzdb-project/fuzzdb fuzz data database
  • https://github.com/ivanfratric/winafl AFL for fuzzing Windows binaries, original technical analysis | AFL vulnerability discovery technology discussion
  • https://github.com/attekett/NodeFuzz a fuzzer harness for web browsers and browser like applications.
  • https://github.com/google/oss-fuzz Continuous Fuzzing for Open Source Software
  • http://blog.topsec.com.cn/ad_lab/alphafuzzer/ Vulnerability discovery tool focused on file formats
  • https://bbs.ichunqiu.com/thread-24898-1-1.html Test404 -HTTP Fuzzer V3.0
  • https://github.com/xmendez/wfuzz py, web security fuzzing tool, modular, can process requests and response packets captured by burp
  • https://github.com/1N3/BlackWidow A Web crawler implemented in Python, used to collect intelligence information on target websites and fuzz OWASP vulnerabilities
  • https://github.com/bunzen/pySSDeep py, a tool based on the Fuzzy Hashing algorithm. go, glaslos/ssdeep; C, ssdeep-project/ssdeep
  • https://github.com/googleprojectzero/winafl AFL for testing Windows binaries

Mobile Security

  • https://github.com/Brucetg/App_Security App security learning resources
  • https://github.com/rovo89/Xposed Modify the Android phone system as you wish
  • https://github.com/android-hacker/VirtualXposed An implementation of running Xposed modules in non-ROOT environments based on VirtualApp and epic
  • https://github.com/MobSF/Mobile-Security-Framework-MobSF Mobile security audit framework. android, ios, win
  • https://github.com/WooyunDota/DroidSSLUnpinning Tool for removing Android certificate pinning
  • https://github.com/nccgroup/house Runtime mobile App analysis toolkit, with Web GUI
  • https://github.com/UltimateHackers/Diggy Tool for extracting URLs from Apk files
  • https://github.com/nettitude/scrounger iOS and Android mobile application penetration testing framework
  • https://github.com/XekriCorp/LeakVM Android application security testing framework
  • https://github.com/zsdlove/ApkVulCheck Android vulnerability scanning tool
  • https://github.com/samyk/frisky Tools for sniffing/modifying/reverse engineering/injecting ios/macOS applications
  • https://github.com/GeoSn0w/OsirisJailbreak12 IOS12 incomplete jailbreak
  • https://github.com/chaitin/passionfruit iOS application reverse engineering and analysis tool, can greatly accelerate the iOS application security analysis process

Cloud Security

  • https://github.com/stuhirst/awssecurity/blob/master/arsenal.md Project list related to AWS security detection
  • https://github.com/toniblyx/my-arsenal-of-aws-security-tools AWS security toolset
  • https://github.com/sa7mon/S3Scanner Scan amazon public S3 buckets and dump
  • https://github.com/kromtech/s3-inspector Detect Amazon AWS S3 bucket permissions
  • https://github.com/jordanpotti/AWSBucketDump Enumerate AWS S3 buckets to find sensitive confidential files
  • https://github.com/sa7mon/S3Scanner Scan amazon public S3 buckets and dump
  • https://github.com/kromtech/s3-inspector Detect Amazon AWS S3 bucket permissions
  • https://github.com/jordanpotti/AWSBucketDump Enumerate AWS S3 buckets to find sensitive confidential files
  • https://github.com/Netflix/repokid AWS least privilege policy deployment tool
  • https://github.com/RhinoSecurityLabs/pacu AWS vulnerability detection framework
  • https://github.com/0xbug/Hawkeye GitHub leak monitoring system
  • https://github.com/neal1991/gshark github information leak detection
  • https://github.com/VKSRC/Github-Monitor GitHub monitoring, code information leakage, minute-level monitoring, email alerts
  • https://github.com/metac0rtex/GitHarvester github Repo information gathering tool
  • https://github.com/repoog/GitPrey GitHub sensitive information scanning tool
  • https://github.com/FeeiCN/GSIL py3, near real-time monitoring of Github sensitive information, and sends alert notifications.

Reverse Engineering

  • https://www.peerlyst.com/posts/resource-learning-how-to-reverse-malware-a-guide Collection of malware reverse engineering guides and tools
  • https://github.com/ReFirmLabs/binwalk Automated reverse engineering of binary files, with multiple plugins
  • https://github.com/angr/angr A binary analysis tool with dynamic symbolic execution and static analysis
  • https://github.com/endgameinc/xori Custom disassembly framework
  • https://down.52pojie.cn/ 吾爱破解 (52pojie) AiPan toolkit
  • https://github.com/blacknbunny/peanalyzer32 PE file analysis and disassembly tool
  • https://github.com/DominicBreuker/pspy Monitor process activity without root permission

CTF Related

  • https://ctf-wiki.github.io/ctf-wiki/ CTFwiki, covering Misc/Crypto/Web/Assembly/Executable/Reverse/Pwn/Android/ICS
  • https://github.com/adon90/pentest_compilation Common knowledge points and commands in ctf competitions and OSCP exams
  • https://github.com/gabemarshall/microctfs Small ctf image docker
  • https://github.com/giantbranch/pwn_deploy_chroot Deploy multiple pwn challenges into one docker container
  • https://github.com/facebook/fbctf CTF competition framework
  • https://github.com/0Chencc/CTFCrackTools CTF tool integration package
  • https://github.com/guyoung/CaptfEncoder CTF crypto encoding complete suite, also available as a mini program version
  • https://github.com/Gallopsled/pwntools pwn type, binary exploitation framework
  • https://github.com/ChrisTheCoolHut/Zeratool pwn type, binary exploitation framework
  • https://github.com/ChrisTheCoolHut/Rocket-Shot pwn, automatic attack script
  • https://0xrick.github.io/lists/stego/ Steganography tool collection, Steganography - A list of useful tools and resources
  • https://github.com/DominicBreuker/stego-toolkit Steganography toolkit
  • https://github.com/bugsafe/WeReport WeReport report assistant
  • https://github.com/PELock/CrackMeZ3S-CTF-CrackMe-Tutorial Writing CrackMe software for CTF competitions

Forensics Investigation

Recommended Content

  • https://www.freebuf.com/articles/rookie/195107.html Recording a WeChat database decryption process. The decryption password of WeChat's encrypted database is composed of "the device's IMEI(MEID) + the user's uin, hashed with MD5, then taking the first 7 lowercase letters"
  • https://www.audacityteam.org/ Audio file and waveform processing tool
  • http://www.sweetscape.com/010editor/ A hexadecimal editor that identifies different file formats (templates), with file repair functionality
  • http://www.magicexif.com/ Digitize the exif information in photo images
  • http://mediaarea.net/MediaInfo Similar to exiftool, for viewing content area and metadata information
  • https://www.sno.phy.queensu.ca/~phil/exiftool/ Check the exif metadata of image files
  • https://www.gimp.org/ Gimp provides the functionality to convert visual data of various image file types, and can also be used to confirm whether a file is an image file
  • https://github.com/volatilityfoundation/volatility windows memory forensics analysis
  • https://github.com/gleeda/memtriage Windows memory forensics analysis
  • https://github.com/SekoiaLab/Fastir_Collector Windows forensics/information collection, not limited to memory, registry, file information, etc.
  • https://github.com/Viralmaniar/Remote-Desktop-Caching- RDP information recovery, png image format
  • https://github.com/comaeio/LiveCloudKd C, memory forensics for Hyper-V -https://github.com/sevagas/swap_digger Forensic analysis tool for Linux swap
  • http://extundelete.sourceforge.net/ File recovery under linux
  • https://github.com/viaforensics/android-forensics Android forensics App and framework, can extract various information from Android devices

Sample Analysis

  • https://github.com/open-power-workgroup/Hospital National list of Putian-system hospitals
  • https://github.com/chenerlich/FCL Collection of command lines used by malicious code
  • https://paper.seebug.org/421 Common software collection and malware analysis
  • https://github.com/sapphirex00/Threat-Hunting APT malware samples
  • https://www.malware-traffic-analysis.net/ Malware samples
  • http://dasmalwerk.eu/ Malware samples
  • https://github.com/ytisf/theZoo Malware samples
  • https://github.com/mstfknn/malware-sample-library Malware samples
  • http://99.248.235.4/Library/ Malware sample library. ladder
  • https://github.com/robbyFux/Ragpicker Malware information crawling, aggregation and analysis
  • https://github.com/phage-nz/ph0neutria Malware information crawling, aggregation and analysis
  • https://github.com/JR0driguezB/malware_configs Common malware configuration files
  • https://github.com/sfaci/masc Scan websites for malware, plus some other website maintenance functions
  • https://github.com/Neo23x0/munin Tool that extracts information from various online malware scanning services based on file Hash
  • https://github.com/1lastBr3ath/drmine Tool to automatically detect whether a webpage contains mining scripts
  • https://github.com/KasperskyLab/klara Kaspersky's open source Yara-based distributed malware scanning system,
  • https://github.com/botherder/kraken go, implemented Yara malware scanner

Security Products

  • https://www.freebuf.com/sectool/135032.html Build a high-interaction honeypot that is hard to discover
  • https://bloodzer0.github.io/ossa/ Use open source files for open source security architecture. Hosts, scanners, ports, logs, protection devices, etc.
  • https://github.com/dvf/blockchain Create a blockchain from scratch with Python
  • https://github.com/crazywa1ker/DarthSidious-Chinese Start your domain penetration journey from 0, DarthSidious Chinese version
  • https://paper.seebug.org/772/ How to use KittyFuzzer combined with the industrial control protocol components in ISF to Fuzz industrial control protocols

Security Operations

Recommended Content- https://github.com/chaitin/cloudwalker CloudWalker (Muyun) server security management platform, progressively covering server asset management, threat scanning, Webshell detection and removal, baseline detection, and other functions.

  • https://github.com/mitre/caldera MITRE's simulated attack testing system, mainly for Windows
  • https://github.com/guardicore/monkey Assesses network security posture. It is divided into a scanner and C2C server, and uses default credentials and exploits to perform attack detection over protocols such as SSH and SMB.
  • https://github.com/grayddq/PublicSecScan Calls AWVS to perform distributed web security scanning on large volumes of WEB assets, discovering common security vulnerabilities in web environments.
  • https://github.com/jeffzh3ng/Fuxi-Scanner Asset management and vulnerability detection, integrating AWVS, Knownsec Pocsuite, nmap, and hydra.
  • https://github.com/infobyte/faraday Collaborative penetration testing and vulnerability management platform, integrating multiple tools.
  • https://github.com/DefectDojo/django-DefectDojo Django-based vulnerability and asset management platform.
  • https://github.com/creditease-sec/insight Web interface. Developed by CreditEase Security Department, it integrates application system asset management, full lifecycle vulnerability management, and security knowledge base management into a single management platform.
  • https://github.com/RASSec/A_Scan_Framework Vulnerability management, asset management, and task scanning system.
  • https://github.com/cea-sec/ivre Network asset fingerprint discovery; build your own Shodan and ZoomEye.
  • https://github.com/ysrc/xunfeng Web interface. Network asset identification engine and vulnerability detection engine developed by Tongcheng Security.
  • https://github.com/superhuahua/xunfengES Web interface, developed based on Xunfeng, One-person Security Department.
  • https://github.com/zhaoweiho/SecurityManageFramwork Python 3, Django. Enterprise intranet security management platform, including asset management, vulnerability management, account management, knowledge base management, and security scanning automation functional modules.

Webshell Detection and Removal

  • http://www.safedog.cn/ SafeDog web firewall
  • http://d99net.net/ Windows. D Shield firewall by A'D, includes WAF and webshell detection capabilities.
  • https://github.com/he1m4n6a/findWebshell Python. Webshell inspection tool that can add backdoor fingerprints later. Very powerful.
  • https://github.com/ym2011/ScanBackdoor A concise webshell scanning tool.
  • https://github.com/erevus-cn/scan_webshell Webshell scanning tool.
  • https://github.com/yassineaddi/BackdoorMan Can perform PHP webshell detection on specified directories.
  • https://github.com/nbs-system/php-malware-finder A high-efficiency PHP webshell scanning tool.
  • https://github.com/emposha/PHP-Shell-Detector Webshell detection tool with testing efficiency as high as 99%.
  • https://github.com/emposha/Shell-Detector Webshell scanning tool, supports PHP/Perl/ASP/ASPX webshell scanning.

Stress Testing

  • https://github.com/ywjt/Dshield DDoS protection
  • https://github.com/NewEraCracker/LOIC/ A network stress testing tool designed for Windows, now supports Mac OS — translator's note
  • https://github.com/649/Memcrashed-DDoS-Exploit DDoS attack tool that exploits Memcached servers, sending forged UDP packets to Memcached servers to make them reply with a large volume of packets to the attack target.
  • https://github.com/jseidl/GoldenEye Python, DoS testing.
  • https://github.com/mschwager/dhcpwn DHCP IP resource exhaustion attack tool.
  • https://github.com/Microsoft/Ethr Go, cross-platform. TCP, UDP, HTTP, HTTPS stress testing tool.

Honeypot Basics

  • https://github.com/paralax/awesome-honeypots Collection of open-source honeypot technologies.
  • https://github.com/threatstream/mhn Modern Honeynet. Integrates installation scripts for multiple honeypots, can be quickly deployed and used, and can also quickly collect data from nodes.
  • https://github.com/dtag-dev-sec/tpotce T-POT. Uses Docker technology to implement a combination of multiple honeypots, combined with ELK for research and data capture.
  • https://www.freebuf.com/sectool/190840.html Tips for using the T-Pot multi-honeypot platform
  • https://github.com/n3uz/t-pot-autoinstall Replaces the one-click install script of the forked T-POT honeypot with domestic accelerated mirrors.

Honeypots

  • https://github.com/micheloosterhof/cowrie Python 2. Uses ELK (ElasticSearch, LogStash, Kibana) for data analysis. Currently supports SSH, Telnet, SFTP and other protocols.
  • https://github.com/mushorg/snare Python 3. Web security honeypot that can clone specified web pages.
  • https://github.com/honeynet/beeswarm Python. Uses agent probes to interact with honeypots in real time to lure attackers.
  • https://github.com/thinkst/opencanary Python 2. Honeypot for SNMP\RDP\SAMBA.
  • https://github.com/p1r06u3/opencanary_web Python, Tornado. Intranet low-interaction honeypot. Supports automated installation and currently supports 16 common protocols. Currently uses a probe/honeypot-management architecture; it can be considered for secondary development into a probe-sandbox-management architecture.
  • https://github.com/p1r06u3/opencanary_web
  • https://github.com/Cymmetria Renowned deception defense honeypot organization. Emulation honeypots for Struct, WebLogic, Telnet, Cisco ASA, Micros, etc.
  • https://github.com/Cymmetria/honeycomb Cymmetria's open-source honeypot framework, low-interaction.
  • https://github.com/honeytrap/honeytrap Extensible honeypot framework, supports probe deployment and high-interaction honeypots.
  • https://gosecure.net/2018/12/19/rdp-man-in-the-middle-smile-youre-on-camera/ RDP MITM: build an RDP honeypot that can record images and keystrokes (https://github.com/gosecure/pyrdp)

Camera Honeypot

  • https://github.com/alexbredo/honeypot-camera Python. Camera honeypot. Tornado simulates a web service, images replace video. Consider adding more images and buttons later.
  • https://github.com/EasyDarwin/EasyIPCamera C. RTSP server component used to build camera honeypots.

Industrial Control Honeypots

  • https://github.com/sjhilt/GasPot Simulates oil, electric, and gas industrial control systems.
  • https://github.com/djformby/GRFICS IoT industrial simulation system framework, uses the MODBUS protocol to monitor and control PLC virtual machines.
  • https://github.com/RabitW/IoTSecurityNAT IoT testing system, convenient for quickly connecting various devices for security testing.
  • https://github.com/mushorg/conpot Low-interaction industrial control honeypot for ICS/SCADA, simulating Modbus and S7comm.

Security Defense

Recommended Content

  • https://github.com/baidu/AdvBox AdvBox is an AI model security toolbox supporting multiple deep learning platforms. It supports both white-box and black-box algorithms to generate adversarial examples, measure AI model robustness, and also supports common defense algorithms.
  • https://github.com/quoscient/octopus Blockchain smart contract security analysis tool.

Read more

Download Tool
  • https://github.com/jshaw87/Cheatsheets Penetration testing / security cheat sheets / notes
  • https://github.com/wstart/DB_BaseLine Database baseline check tool
  • https://github.com/writeups/ios iOS vulnerability writeup notes
  • http://blog.safebuff.com/2016/07/03/SSRF-Tips/ SSRF vulnerability exploitation manual
  • https://github.com/Safflower/Solve-Me php, source code of a Korean CTF practice range focused on code auditing
  • https://github.com/WebGoat/WebGoat One-click jar package, web security experiment practice range
  • https://github.com/Audi-1/sqli-labs SQLite-based SQL injection learning range
  • https://github.com/lcamry/sqli-labs Demonstrates MySQL-related injection techniques via sqli-labs
  • https://github.com/c0ny1/upload-labs A practice range that helps you summarize all types of upload vulnerabilities
  • https://github.com/LandGrey/upload-labs-writeup upload-labs guidance manual
  • https://github.com/Go0s/LFIboomCTF Local File Inclusion vulnerability && PHP exploitation protocols && practice source code
  • https://in.security/lin-security-practise-your-linux-privilege-escalation-foo/ A virtual machine file for Linux privilege escalation practice
  • https://github.com/OWASP/igoat Learning tool for iOS application testing and security
  • https://github.com/prateek147/DVIA-v2 Learning tool for iOS application testing and security
  • https://github.com/rapid7/metasploitable3 Metasploit practice system
  • https://github.com/rapid7/metasploit-vulnerability-emulator Perl-based Metasploit simulation environment for hands-on practice
  • https://github.com/chryzsh/DarthSidious AD domain environment setup, penetration, and defense
  • https://github.com/c0ny1/xxe-lab An XXE vulnerability demo including php, java, python, C# and other language versions
  • https://www.hackthebox.eu //Europe's HTB practice range, online real environment
  • https://www.root-me.org //Russia's root-me practice range. Online. Community edition
  • https://lab.pentestit.ru //Russian practice range, real environment. Online. Commercial edition.
  • https://www.offensive-security.com/information-security-certifications/ //Kali attack & defense technical certification. Commercial edition.
  • https://www.pentesteracademy.com //Tutorials + videos + labs + certification training all in one. Commercial edition.
  • https://www.cybrary.it //Cybersecurity engineer certification. CTF/Labs
  • https://www.wechall.net //World-renowned CTF aggregation and exchange website
  • https://www.ichunqiu.com/experiment/direction //iChunqiu Lab. Web/Host/Application/pwn tutorials
  • https://www.mozhe.cn/bug //Mozi Academy online practice range. Web/Host/Database/Forensics
  • https://www.xssgame.com //Google XSS challenge
  • http://xss.tv //Online practice range
  • https://github.com/n4xh4ck5/N4xD0rk Uses search engines to gather subdomains, supports searching in Spanish
  • https://github.com/vysec/DomLink py2, calls WHOXY.com for further gathering of emails and domains
  • https://github.com/jonluca/Anubis py3.6, subdomain brute force and information gathering
  • https://github.com/le4f/dnsmaper Web interface, subdomain enumeration/brute-force tool with map location marking
  • https://github.com/thewhiteh4t/seeker Tool for obtaining high-precision geolocation and device information
  • https://github.com/0xbug/orangescan Web interface, online subdomain information collection tool
  • https://github.com/TheRook/subbrute Subdomain brute-force API library commonly used in scanners
  • https://github.com/We5ter/GSDF Subdomain query script based on Google SSL Transparency certificates
  • https://github.com/mandatoryprogrammer/cloudflare_enum Uses CloudFlare DNS for subdomain enumeration
  • https://github.com/ultrasecurity/webkiller Penetration aid, py, IP info, port service fingerprinting, honeypot detection, bypass cloudflare
  • https://github.com/christophetd/CloudFlair Cloudflare bypass, obtains real IP, integrates censys
  • https://github.com/exp-db/PythonPool/tree/master/Tools/DomainSeeker Collects target subdomain information through multiple methods
  • https://github.com/code-scan/BroDomain Subdomain query
  • https://github.com/michenriksen/aquatone Subdomain enumeration and probing tool. Can be used for subdomain takeover vulnerability detection
  • https://github.com/chuhades/dnsbrute Go-based, efficient subdomain brute-force tool
  • https://github.com/evilsocket/dnssearch Go-based subdomain brute-force tool
  • https://github.com/OJ/gobuster Go-based tool for DNS-based subdomain querying and web directory brute forcing
  • https://github.com/reconned/domained A tool that can be used for subdomain collection
  • https://github.com/bit4woo/Teemo Multi-method domain collection and enumeration tool
  • https://github.com/swisskyrepo/Subdomino Subdomain enumeration, port scanning, service liveness confirmation
  • https://github.com/nmalcolm/Inventus Subdomain collection tool implemented via crawler
  • https://github.com/alienwithin/OWASP-mth3l3m3nt-framework Penetration aid, php, exploit hunting, payload and shell generation, information gathering
  • https://github.com/chrismaddalena/ODIN py3, simple, information gathering and post-exploitation
  • https://github.com/x0day/bannerscan C-segment/co-located site query and path scanning
  • https://github.com/Xyntax/BingC C-segment/co-located site query based on Bing search engine, multi-threaded, supports API
  • https://github.com/zer0h/httpscan Network segment web host discovery utility
  • https://github.com/lijiejie/BBScan Batch script for scanning website information leakage
  • https://github.com/aipengjie/sensitivefilescan Website sensitive file scanning tool
  • https://github.com/Mosuan/FileScan Website sensitive file scanning / secondary judgment reduces false positives / rule-based scan content / multi-directory scanning
  • https://github.com/Xyntax/FileSensor Website sensitive file detection tool
  • https://github.com/ring04h/weakfilescan Multi-threaded website leaked information detection tool
  • https://github.com/Viralmaniar/Passhunt simple, used to search for default credentials in network devices, web applications, etc. Contains 2,084 default credential sets from 523 vendors
  • https://github.com/yassineaboukir/Asnlookup simple, uses ASN to search for IPs owned by a specific organization, can integrate with nmap and masscan for further information scanning
  • https://github.com/lietdai/doom Distributed task-dispatching IP/port vulnerability scanner implemented on thorn
  • https://github.com/RASSec/RASscan Port service scanning
  • https://github.com/m3liot/shcheck Used to check the security of HTTP headers in web services
  • https://github.com/mozilla/ssh_scan Server SSH configuration information scanning
  • https://github.com/18F/domain-scan Asset data detection/scanning for domains and their subdomains, including HTTP/HTTPS detection, etc.
  • https://github.com/ggusoft/inforfinder Domain asset collection and fingerprinting tool
  • https://github.com/0xbug/Howl Network device web service fingerprint scanning and retrieval
  • https://github.com/mozilla/cipherscan Target host service SSL type identification
  • https://github.com/medbenali/CyberScan Penetration testing aid, supports packet analysis, decoding, port scanning, IP address analysis, etc.
  • https://github.com/jekyc/wig Web application information gathering tool
  • https://github.com/eldraco/domain_analyzer Gathers information about domains serving web services and scans for vulnerabilities such as "zone transfer", also supports port scanning of backend servers, etc.
  • https://github.com/cloudtracer/paskto Passive path scanning and information crawler based on Nikto scanning rules
  • https://github.com/zerokeeper/WebEye Quickly identifies web server types, CMS types, WAF types, WHOIS information, and language frameworks
  • https://github.com/n4xh4ck5/CMSsc4n CMS fingerprinting
  • https://github.com/HA71/WhatCMS CMS detection and exploitation script, based on Whatcms.org API
  • https://github.com/boy-hack/gwhatweb CMS identification implemented in Python gevent
  • https://github.com/wpscanteam/wpscan Basically the most useful tool for WordPress
  • https://github.com/swisskyrepo/Wordpresscan Optimized WordPress scanner based on WPScan and WPSeku
  • https://github.com/m4ll0k/WPSeku Streamlined WordPress scanning tool
  • https://github.com/rastating/wordpress-exploit-framework WordPress vulnerability exploitation framework
  • https://github.com/Jamalc0m/wphunter php, WordPress scanner
  • https://github.com/UltimateLabs/Zoom WordPress vulnerability scanner
  • https://github.com/immunIT/drupwn Drupal information gathering and exploitation tool
  • https://github.com/CHYbeta/cmsPoc CMS penetration testing framework
  • https://github.com/chuhades/CMS-Exploit-Framework CMS attack framework
  • https://github.com/Tuhinshubhra/CMSeeK Basic detection for 20+ CMS, WordPress exploitation, customizable modular brute-force functionality
  • https://github.com/Dionach/CMSmap Supports scanning WordPress, Joomla and Drupal
  • https://github.com/Moham3dRiahi/XAttacker Web CMS Exploit tool, contains 66 different exploits for mainstream CMS
  • https://github.com/code-scan/dzscan The first integrated Discuz scanning tool
  • https://github.com/shogunlab/shuriken Uses command line for batch XSS detection
  • https://github.com/stamparm/DSXS Efficient XSS scanner supporting GET and POST methods
  • https://github.com/bsmali4/xssfork If it doesn't work under Kali, please download the correct PhantomJS to the directory thirdparty/phantomjs/Linux
  • https://github.com/riusksk/FlashScanner Flash XSS scanning
  • https://github.com/Damian89/xssfinder Targets and detects reflected XSS in websites
  • https://github.com/BlackHole1/WebRtcXSS Automates XSS exploitation to infiltrate internal networks
  • https://github.com/JohnTroony/Blisqy Time-based blind injection brute-force tool for HTTP headers, targeting only MySQL/MariaDB
  • https://github.com/se55i0n/DBScanner Script that automatically scans common SQL and NoSQL databases in the internal network, including unauthorized access and common weak password detection
  • https://github.com/Turr0n/firebase Exploits improperly configured Firebase databases
  • https://github.com/elcodigok/wphardening Harden the security of any WordPress installation
  • https://github.com/RetireJS/grunt-retire Scan JS extension libraries for common vulnerabilities
  • https://github.com/coffeehb/SSTIF Semi-automated tool for server-side template injection vulnerabilities
  • https://github.com/tijme/angularjs-csti-scanner Tool for detecting client-side AngularJS template injection vulnerabilities
  • https://github.com/blackye/Jenkins Jenkins vulnerability detection, user harvesting, and brute-forcing
  • https://github.com/epinna/tplmap Server-side template injection vulnerability detection and exploitation tool
  • https://github.com/irsdl/IIS-ShortName-Scanner Java, IIS short filename brute-force enumeration exploit tool
  • https://github.com/lijiejie/IIS_shortname_Scanner Python 2, IIS short filename vulnerability scanner
  • https://github.com/rudSarkar/crlf-injector Batch scanning for CRLF injection vulnerabilities
  • https://github.com/hahwul/a2sv SSL vulnerability scanner, e.g., Heartbleed, etc.
  • https://github.com/jagracey/Regex-DoS RegEx denial-of-service scanner
  • https://github.com/Bo0oM/PHP_imap_open_exploit Exploit imap_open to bypass the disabled PHP exec function
  • https://www.anquanke.com/post/id/106488 Use malicious MySQL server-side configuration to read client files (How to use MySQL LOCAL INFILE to read client files, Read MySQL Client's File, [Technical Sharing] The Road of Counterattack Starting from MySQL)
  • https://www.waitalone.cn/awvs-poc.html CVE-2015-4027, AWVS 10 command execution vulnerability
  • http://an7isec.blogspot.com/2014/04/pown-noobs-acunetix-0day.html Pwn the n00bs - Acunetix 0day, AWVS 8 command execution vulnerability
  • https://github.com/numpy/numpy/issues/12759 RCE vulnerability in the scientific computing framework NumPy
  • https://github.com/petercunha/Jenkins-PreAuth-RCE-PoC Jenkins remote command execution
  • https://github.com/WyAtu/CVE-2018-20250 WinRAR execution vulnerability with usage introduction
  • https://github.com/frohoff/ysoserial Java deserialization exploitation tool
  • https://github.com/0xdeadbeefJERKY/Office-DDE-Payloads Execute commands in Word documents via DDE without enabling macros
  • http://www.freebuf.com/articles/terminal/150285.html Exploiting DDE in Word documents to execute commands without enabling macros
  • https://github.com/Ridter/CVE-2017-11882 Get a shell via RTF Word documents, https://evi1cg.me/archives/CVE_2017_11882_exp.html
  • https://github.com/Lz1y/CVE-2017-8759 Get a shell via HTA in Word documents, http://www.freebuf.com/vuls/147793.html
  • https://fuping.site/2017/04/18/CVE-2017-0199漏洞复现过程 CVE-2017-0199 vulnerability reproduction process: WORD RTF documents, exploited together with Metasploit
  • https://github.com/tezukanice/Office8570 Remote command execution via PPSX slide decks, https://github.com/rxwx/CVE-2017-8570
  • https://github.com/0x09AL/CVE-2018-8174-msf Currently supports 32-bit IE browser and 32-bit Office. Session comes online via webpage access; the shell stays alive even after the browser closes, http://www.freebuf.com/vuls/173727.html
  • http://www.4hou.com/technology/9405.html Hide attack payloads in Office document properties
  • https://evi1cg.me/archives/Create_PPSX.html Craft PPSX phishing files
  • https://github.com/enigma0x3/Generate-Macro PowerShell script that generates Microsoft Office documents containing malicious macros
  • https://github.com/mwrlabs/wePWNise Generates architecture-independent VBA code for Office documents or templates and automatically bypasses application controls
  • https://github.com/curi0usJack/luckystrike PowerShell-based, for creating malicious Office macro documents
  • https://github.com/sevagas/macro_pack Bundling payloads into MS Office documents, VBS format, and shortcuts
  • https://github.com/khr0x40sh/MacroShop A set of scripts for delivering payloads via Office macros
  • https://github.com/rebeyond/memShell A webshell that can be written into the memory of a Java web server
  • https://github.com/DXkite/freebuf-stream-shell PHP uses stream wrappers to implement WebShell. FreeBuf has detailed articles on it
  • https://xz.aliyun.com/t/2799 Implementing a new one-liner webshell with dynamic binary encryption: Client edition
  • https://github.com/rebeyond/Behinder "Behinder" (Ice Scorpion), dynamic binary encryption website management client
  • https://xz.aliyun.com/t/2744#toc-8 Implementing a new one-liner webshell with dynamic binary encryption: Java edition
  • https://xz.aliyun.com/t/2758#toc-4 Implementing a new one-liner webshell with dynamic binary encryption: .NET edition
  • https://xz.aliyun.com/t/2774#toc-4 Implementing a new one-liner webshell with dynamic binary encryption: PHP edition
  • https://github.com/jboss-javassist/javassist A bytecode manipulation framework that allows us to easily modify class files
  • https://github.com/ConsenSys/mythril-classic Security analysis tool for Ethereum smart contracts
  • https://github.com/a13xp0p0v/kconfig-hardened-check Script for checking security hardening options in Linux kernel configurations
  • https://github.com/lionsoul2014/ip2region IP address geolocation library supporting Python 3 and multiple interfaces. Comparable to GeoIP
  • https://github.com/m101/hsploit Rust-based HEVD exploit
  • https://github.com/ticarpi/jwt_tool Testing for JSON Web Tokens
  • https://github.com/clr2of8/DPAT Domain password configuration audit
  • https://github.com/chenjj/CORScanner CORS vulnerability, cross-origin scanner
  • https://github.com/dienuet/crossdomain CORS vulnerability, cross-origin scanner
  • https://github.com/sfan5/fi6s Fast IPv6 port scanner
  • https://github.com/lavalamp-/ipv666 Go, IPv6 address enumeration scanning
  • https://github.com/commixproject/commix Command injection vulnerability scanner
  • https://github.com/Graph-X/davscan DAVScan is a fast, lightweight WebDAV scanner designed to discover hidden files and folders on DAV-enabled web servers
  • https://github.com/jcesarstef/dotdotslash Directory traversal vulnerability testing
  • https://github.com/P3GLEG/WhaleTail Generate Dockerfiles from Docker images
  • https://github.com/cr0hn/dockerscan Docker scanning tool
  • https://github.com/utiso/dorkbot Search and scan for vulnerable pages via a customized Google search engine
  • https://github.com/NullArray/DorkNet Search-engine-based hunting for vulnerable web pages
  • https://github.com/panda-re/lava Large-scale automated injection of vulnerabilities into programs
  • https://github.com/woj-ciech/Danger-zone Correlates data across domains, IP addresses, and email addresses and visualizes the output
  • https://github.com/securemode/DefenderKeys Enumerates configurations excluded from Windows Defender scanning
  • https://github.com/D4Vinci/PasteJacker Clipboard hijacking exploitation tool
  • https://github.com/JusticeRage/freedomfighting Toolkit for log cleaning, file sharing, reverse shells, and a simple crawler
  • https://github.com/gh0stkey/PoCBox Auxiliary platform for vulnerability testing and verification: JSONP hijacking, CORS, Flash cross-domain resource reading, Google Hacking syntax generation, URL test dictionary generation, JavaScript URL redirects, 302 URL redirects
  • https://github.com/jakubroztocil/httpie HTTP debugging tool, similar to curl but with more complete features
  • https://www.getpostman.com/ HTTP debugging tool with a GUI
  • https://github.com/erevus-cn/pocscan An open-source PoC invocation framework that can easily call Pocsuite, Tangscan, Beebeeto, and older Knownsec PoCs; deployable with Docker
  • https://github.com/DavexPro/PocHunter A multi-exploitation-framework PoC adaptation framework inspired by pocscan
  • https://github.com/theInfectedDrake/TIDoS-Framework Covers everything from reconnaissance to vulnerability analysis
  • https://github.com/gyoisamurai/GyoiThon Penetration testing tool using deep learning, learning from each scan's data; the more it scans, the higher its detection accuracy
  • https://github.com/euphrat1ca/polar-scan Polar Bear scanner in E-language
  • https://github.com/euphrat1ca/yeezy-scan Yeezy 1.9 scanner
  • https://github.com/euphrat1ca/WebCruiserWVS Lightweight C#-based scanner, predecessor of the Yeezy scanner
  • https://github.com/Skycrab/leakScan Web interface, vulnerability scanning
  • https://github.com/az0ne/AZScanner Web interface, automated vulnerability scanner: subdomain brute-forcing, port scanning, directory brute-forcing, and common framework vulnerability detection
  • https://github.com/boy-hack/w8scan Web interface, scanner based on BugScan scanning and architecture philosophy
  • https://github.com/MiniSafe/microweb Web interface, based on BugScan, Django
  • https://github.com/taipan-scanner/Taipan Web interface, security scanner based on F# and C#
  • https://github.com/zhangzhenfeng/AnyScan Web interface, Python vulnerability scanner
  • https://github.com/Canbing007/wukong-agent Web interface, Python vulnerability scanner
  • https://github.com/dermotblair/webvulscan Web interface, PHP vulnerability scanner, supports PDF report output
  • https://github.com/jeffzh3ng/InsectsAwake Web interface, vulnerability scanning system based on the Flask application framework, also integrating port scanning, subdomain brute-forcing and other common penetration testing features; backend vulnerability scanning uses Pocsuite
  • https://github.com/0xInfection/TIDoS-Framework Python, Linux, website scanner
  • https://github.com/secdec/adapt Python, Linux, website scanner
  • https://github.com/sullo/nikto Perl, Linux, website scanner built into Kali
  • https://github.com/Ekultek/Zeus-Scanner Web scanner integrating Geckodriver, Nmap, and sqlmap
  • https://github.com/blackye/lalascan Distributed web vulnerability scanning framework combining OWASP Top 10 vulnerability scanning and perimeter asset discovery
  • https://github.com/blackye/BkScanner BkScanner: distributed, plugin-based web vulnerability scanner
  • https://github.com/tlkh/prowler Network vulnerability scanning tool based on a Raspberry Pi Cluster
  • https://github.com/netxfly/passive_scan HTTP-proxy-based web vulnerability scanner
  • https://github.com/1N3/Sn1per PHP, automated middleware scanning and device fingerprinting
  • https://github.com/Tuhinshubhra/RED_HAWK PHP, scanning tool integrating information gathering, vulnerability scanning, fingerprinting, etc.
  • https://github.com/m4ll0k/Spaghetti Web application scanner supporting fingerprinting, file/directory brute-forcing, and SQLi/XSS/RFI vulnerability scanning; can also be used directly for Struts, ShellShock, and other vulnerability scanning
  • https://github.com/v3n0m-Scanner/V3n0M-Scanner Scanner supporting detection of SQLi, XSS, LFI, RFI, and other vulnerabilities
  • https://github.com/Yukinoshita47/Yuki-Chan-The-Auto-Pentest Web application scanner integrating modules such as subdomain enumeration, Nmap, and WAF fingerprinting
  • https://github.com/RASSec/pentestEr_Fully-automatic-scanner Targeted automated testing tool
  • https://github.com/Fireflyi/lcyscan Python, plugin-based vulnerability scanner, supports report generation
  • https://github.com/Arachni/arachni Web application vulnerability scanning framework supporting REST, RPC, and other API calls
  • https://github.com/swisskyrepo/DamnWebScanner Passive vulnerability scanner based on Chrome/Opera extensions
  • https://github.com/0xsauby/yasuo Ruby, scans hosts for vulnerabilities in third-party web application services
  • https://github.com/yangbh/Hammer Web application vulnerability scanning
  • https://github.com/viraintel/OWASP-Nettacker Automated penetration testing framework
  • https://github.com/flipkart-incubator/watchdog Comprehensive web scanner and exploit tool
  • https://github.com/Fplyth0ner-Combie/Bug-Project-Framework E-language, Metasploit-style exploitation framework, comes with an exploit editor
  • https://github.com/PowerScript/KatanaFramework Python, Metasploit-style exploitation framework, also includes some SSH and archive cracking tools
  • https://github.com/m4ll0k/Galileo Python 2, website scanner
  • https://github.com/samhaxr/hackbox Python 2, simple, website scanner
  • https://github.com/secrary/EllaScanner Python 3, simple, passive vulnerability scanner, supports identification of historical CVE number vulnerabilities
  • https://github.com/m4ll0k/WAScan Python, simple: scans pages/links/scripts/forms, tests payloads, etc.
  • https://github.com/jiangsir404/S7scan Python, seven types of comprehensive detection
  • https://github.com/hatRiot/clusterd Python, simple, web vulnerability exploitation
  • https://github.com/M4cs/BabySploit Python, simple, mimics Metasploit
  • https://github.com/iceyhexman/onlinetools Simple, web interface: online CMS fingerprinting | same-server sites | C-segment | information disclosure | industrial control | systems | IoT security | CMS vulnerability scanning | port scanning | etc.
  • https://github.com/tulpar/tulpar Simple, supports scanning of multiple web vulnerabilities
  • https://github.com/UltimateHackers/Striker Simple: information gathering, CMS exploitation, and vulnerability scanning; reconnaissance bypasses Cloudflare
  • https://github.com/0x4D31/salt-scanner Linux vulnerability scanner based on Salt Open and the Vulners Linux Audit API, supports integration with JIRA and Slack
  • https://github.com/opensec-cn/kunpeng Go, PoC detection framework, provided in the form of a dynamic link library callable from various languages
  • https://github.com/dcsync/pycobalt py3, Python API for Cobalt Strike

  • https://www.cobaltstrike.com/aggressor-script/cobaltstrike.html CobaltStrike plugin development, one-to-many with GUI

  • https://github.com/0xdea/tactical-exploitation Collection of Python/PowerShell test scripts

  • https://github.com/PowerShellMafia/PowerSploit PowerShell test script collection and development framework summary

  • https://github.com/samratashok/nishang PowerShell script collection and exploitation framework

  • https://github.com/PowerShellEmpire/PowerTools PowerShell script collection, no longer updated

  • https://github.com/FuzzySecurity/PowerShell-Suite PowerShell script collection

  • https://github.com/rvrsh3ll/Misc-Powershell-Scripts PowerShell script collection

  • https://github.com/nccgroup/redsnarf Steal hashes, decrypt passwords, covertly invoke Mimikatz and other programs, multiple RDP exploitation methods, remotely launch shells, and clean up traces

  • https://github.com/BloodHoundAD/BloodHound A program for analyzing the relationships between domain members and users. It exports domain session, computer, group, user and other information via PowerShell scripts, and after importing it into a database, performs visual analysis to enable targeted attacks.

  • https://github.com/xorrior/RemoteRecon Uses DotNetToJScript for screenshots, keylogging, token theft, and DLL and malicious code injection

  • https://github.com/SkyLined/LocalNetworkScanner Exploits browser vulnerabilities; when the target opens a URL, it scans the target's intranet information

  • https://github.com/fdiskyou/hunter Calls Windows APIs to comprehensively collect intranet information

  • https://github.com/0xwindows/VulScritp Intranet penetration scripts, including banner scanning, port scanning, and exploitation of common vulnerabilities in phpMyAdmin, Jenkins, etc.

  • https://github.com/lcatro/network_backdoor_scanner Network traffic-based intranet detection framework

  • https://github.com/sowish/LNScan Detailed internal network information scanner

  • https://github.com/rootlabs/nWatch Integrates with nmap and scans the organization's intranet

  • https://github.com/m8r0wn/nullinux An internal penetration testing tool for Linux that can enumerate OS information, domain information, shares, directories and users via SMB.

  • https://github.com/zMarch/Orc bash, a collection of post-exploitation commands for Linux

  • https://github.com/decoder-it/psportfwd Port forwarding tool written in PowerShell, no admin privileges required
  • https://github.com/ls0f/gortcp Go, implements intranet penetration through master, relay, and controlled endpoints
  • https://github.com/Ridter/MyJSRat py2, uses JS backdoors; combined with CHM and HTA, can implement many backdoor methods. evi1cg.me/archives/chm_backdoor.html
  • https://github.com/its-a-feature/Apfell py3, JS backdoor exploitation for macOS and Linux, managed via web interface
  • https://github.com/peterpt/fuzzbunch py2, NSA exploit tool, with automated installation scripts and a GUI, RAT
  • https://github.com/n1nj4sec/pupy Python, cross-platform for Windows, Linux, OSX, Android, one-to-many
  • https://github.com/nathanlopez/Stitch Python, cross-platform for Windows, Mac OSX, Linux
  • https://github.com/neoneggplant/EggShell Python, macOS/OSX RAT, can generate HID code, one-to-many
  • https://github.com/Marten4n6/EvilOSX Python, macOS/OSX RAT, one-to-many
  • https://github.com/vesche/basicRAT py3, simple RAT, one-to-many
  • https://github.com/Viralmaniar/Powershell-RAT Python, screenshots sent via Gmail
  • https://github.com/byt3bl33d3r/gcat Python, uses Gmail as the C&C server
  • https://github.com/sweetsoftware/Ares Python, C2 communication, supports proxies
  • https://github.com/micle-fm/Parat Python, Windows remote control tool using Telegram
  • https://github.com/ahhh/Reverse_DNS_Shell Python, transmits via DNS
  • https://github.com/iagox86/dnscat2 Server is Ruby (Linux), client is C (Win/Linux), uses the DNS protocol for end-to-end transmission
  • https://github.com/deepzec/Grok-backdoor Python, backdoor using ngrok
  • https://github.com/trustedsec/trevorc2 Python, sets up a legitimate, browsable website to hide client/server communication for command execution
  • https://github.com/nilotpalbiswas/Auto-Root-Exploit Linux automated privilege escalation script

  • https://github.com/WazeHell/PE-Linux Linux privilege escalation tool

  • https://guif.re/linuxeop Linux privilege escalation command collection

  • https://github.com/sam-b/CVE-2014-4113
  • https://github.com/breenmachine/RottenPotatoNG Uses NBNS local name spoofing and WPAD proxy spoofing for privilege escalation
  • https://github.com/unamer/CVE-2018-8120 Affects the Win32k component, targets Windows 7 and Windows 2008 privilege escalation
  • https://github.com/alpha1ab/CVE-2018-8120 Adds Windows XP and Windows 2003 support on top of Windows 7 and Windows 2008
  • https://github.com/0xbadjuju/Tokenvator A tool that uses Windows tokens to elevate privileges, providing an interactive command-line interface
  • https://github.com/malcomvetter/UnstoppableService A program that installs itself as a Windows service that administrators cannot stop or pause. Written in C#
  • https://github.com/Cn33liz/StarFighters Based on DotNetToJScript, uses JavaScript and VBScript to execute the Empire Launcher
  • https://github.com/mdsecactivebreach/SharpShooter Based on DotNetToJScript using JS and VBS, a payload creation framework for retrieving and executing arbitrary C# source code
  • https://github.com/mdsecactivebreach/CACTUSTORCH Based on DotNetToJScript, uses JS and VBS to generate malicious payloads
  • https://github.com/OmerYa/Invisi-Shell Obfuscates PowerShell files
  • https://github.com/danielbohannon/Invoke-DOSfuscation Obfuscates PowerShell files, including encryption and re-encoding
  • https://github.com/danielbohannon/Invoke-Obfuscation Obfuscates PowerShell files, including encryption and re-encoding
  • https://github.com/Mr-Un1k0d3r/SCT-obfuscator Cobalt Strike SCT payload obfuscator
  • https://github.com/tokyoneon/Armor bash, generates encrypted payloads for reverse shells on macOS
  • https://github.com/Mr-Un1k0d3r/MaliciousMacroGenerator Macro obfuscation, which also includes AV/sandbox evasion mechanisms
  • https://github.com/Kkevsterrr/backdoorme py3, py2, multi-type backdoor and shell generation tool that can automatically maintain privileges
  • https://github.com/TestingPens/MalwarePersistenceScripts Windows privilege persistence scripts
  • https://github.com/mhaskar/Linux-Root-Kit Python, simple, Linux rootkit
  • https://github.com/PinkP4nther/Sutekh Simple rootkit that gives ordinary users a root shell
  • https://github.com/threatexpress/metatwin Extracts metadata, including digital signatures, from one file and injects it into another
  • https://github.com/Mr-Un1k0d3r/Windows-SignedBinary Can modify a binary file's hash while preserving the Microsoft Windows signature
  • https://github.com/secretsquirrel/SigThief Python, a script tool for hijacking legitimate digital signatures and bypassing Windows hash verification mechanisms
  • https://github.com/9aylas/Shortcut-Payload-Generator Shortcut (.lnk) file payload generator. Written in AutoIt
  • https://github.com/GuestGuri/Rootkit Initiates a reverse TCP connection and binds the process ID to an empty folder
  • https://github.com/secretsquirrel/the-backdoor-factory Can generate Win32 PE backdoor test programs, ELF file backdoor programs, etc.
  • https://github.com/initstring/linkedin2username Obtain the employee list of related companies via Linkedin
  • https://github.com/0x09AL/raven Linkedin information gathering tool under linux
  • https://github.com/Ridter/Mailget Guess corporate email addresses through Maimai users
  • https://github.com/haccer/tweep Use twitter API for information crawling and queries
  • https://github.com/MazenElzanaty/TwLocation py, get the addresses from which Twitter users tweet
  • https://github.com/vaguileradiaz/tinfoleak web interface, comprehensive intelligence analysis of someone's twitter
  • https://github.com/deepfakes Fake audio/video creation
  • https://www.jianshu.com/p/147cf5414851 Let's talk about those common detective-type APPs
  • https://github.com/thinkst/canarytokens Tracking and tracing of important files, beacon positioning (https://canarytokens.org/generate#)
  • https://github.com/ggerganov/kbd-audio c++, linux, uses microphone to monitor keyboard input and test input values
  • https://github.com/ustayready/CredSniper Phishing framework written with Flask and Jinja2 templates, supports capturing 2FA tokens
  • https://github.com/fireeye/PwnAuth OAuth abuse testing detection platform
  • https://github.com/n0pe-sled/Postfix-Server-Setup Automatically set up a phishing server
  • https://github.com/Dionach/PhEmail py2, phishing and email forgery
  • https://github.com/PHPMailer/PHPMailer The world's most popular PHP code for sending email
  • http://tool.chacuo.net/mailanonymous Online email forgery
  • http://ns4gov.000webhostapp.com Online email forgery
  • https://www.zimperium.com/zanti-mobile-penetration-testing Mobile wifi penetration tool
  • https://github.com/yanlinlin82/plcscan Identify PLC devices and other Modbus devices on the internet through TCP/102 and TCP/502
  • https://github.com/nsacyber/GRASSMARLIN NSA's ICS/SCADA situational awareness
  • https://github.com/nezza/scada-stuff Reverse engineering and attacking SCADA/ICS devices
  • https://github.com/yassineaboukir/CVE-2018-0296 Test the Cisco ASA path traversal vulnerability, can obtain detailed system information
  • https://github.com/seclab-ucr/tcp_exploit Exploit TCP vulnerability to cause privacy leakage in wireless routers
  • https://github.com/ezelf/CVE-2018-9995_dvr_credentials CVE-2018-9995 camera router, Get DVR Credentials
  • https://github.com/RUB-NDS/PRET Printer attack framework
  • https://github.com/rapid7/IoTSeeker IoT device default password scanning and detection tool
  • https://github.com/schutzwerk/CANalyzat0r Security analysis toolkit for proprietary automotive protocols
  • https://github.com/pasta-auto Smart vehicle testing
  • https://github.com/UnkL4b/GitMiner github sensitive content mining
  • https://github.com/dxa4481/truffleHog GitHub sensitive information scanning tool, including detecting commits, etc.
  • https://github.com/Hell0W0rld0/Github-Hunter github information monitoring script
  • https://github.com/awslabs/git-secrets Tool to prevent committing sensitive data to git repositories
  • https://github.com/zricethezav/gitleaks Go-based, checks password information and keys in git repos
  • https://github.com/davidmcgrew/joy A package used to capture and analyze internal and external network traffic data, mainly for network investigation, security monitoring and forensics
  • https://github.com/USArmyResearchLab/Dshell Extensible network forensics analysis framework, supports rapid plugin development and parsing of network packet captures
  • http://qpdf.sourceforge.net/ View pdf files and organize/extract information
  • http://zipinfo.com/ Lists the content information of zip files without extraction
  • http://f00l.de/pcapfix/ pcap file repair
  • https://www.cgsecurity.org/wiki/TestDisk Disk partition repair
  • https://github.com/decalage2/oletools py, used to analyze MS OLE2 files (structured storage, compound file binary format) and MS Office documents
  • https://www.xplico.org/download Memory forensics
  • https://github.com/google/bochspwn-reloaded Bochspwn Reloaded (kernel information leak detection) tool
  • https://github.com/abrignoni/DFIR-SQL-Query-Repo Collects SQL query templates for data forensics
  • https://www.freebuf.com/news/193684.html iOS forensics tip: completely export SQLite database without loss
  • https://github.com/alexandreborges/malwoverview simple, quickly classify malicious files
  • https://github.com/joxeankoret/pigaios Directly compare source code with compiled binary files
  • https://github.com/viper-framework py2, binary analysis and management framework, for analyzing malicious files
  • https://github.com/netxfly/sec_check Security detection through information collection (accounts, connections, ports, etc.) and yara scanning
  • https://github.com/nao-sec/tknk_scanner Malware identification framework based on the yara engine
  • https://github.com/felixweyne/ProcessSpawnControl powershell, detect and monitor malicious programs
  • https://github.com/Aurore54F/JaSt Uses syntax to detect malicious/obfuscated JS files, https://www.blackhoodie.re/assets/archive/JaSt_blackhoodie.pdf
  • http://edr.sangfor.com.cn/ win, Linux malware and webshell detection and removal tool
  • http://www.clamav.net/downloads Virus detection and removal software
  • http://www.chkrootkit.org/ rootkit detection tool
  • http://rootkit.nl/projects/rootkit_hunter.html rootkit detection tool
  • https://github.com/grayddq/PublicMonitors Performs port and service scanning on public IP lists to discover port/service changes over time and weak-password security risks. One-person Security Department.
  • https://github.com/grayddq/PubilcAssetInfo The main goal is to collect and discover an enterprise's domain names and server public IP assets as much as possible from the perspective of a client-side security professional, such as Baidu Cloud, Alibaba Cloud, Tencent Cloud, etc. One-person Security Department.
  • https://github.com/maya6/SiteScan Web interface, Python 3, Celery. Asset collection.
  • https://github.com/ywolf/F-NAScan Python 2.6. Collects and organizes network assets and port services, generates report display. Fast.
  • https://github.com/flipkart-incubator/RTA Scans all online devices within the company, provides an overall security view, and flags all security anomalies.
  • https://github.com/0xbug/Biu-framework Security scanning framework for basic services on enterprise intranets.