
Collection of quality safety articles. Awesome articles.
Collection of quality safety articles(To be rebuilt)```
Some are inconvenient to release.
Some forget update,can see me star.
collection-document awesome
以前的链接中大多不是优质的
渗透测试部分不再更新
因精力有限,缓慢更新
Author: [tom0li]
Blog: https://tom0li.github.io
- [Project Description](#project-description)
- [Github-list](#github-list)
- [Awesome-list](#awesome-list)
- [Development](#开发)
- [Others](#其它)
- [Security](#安全)
- [Security list](#安全list)
- [Security Market Insights](#安全市场洞察)
- [Cloud Security](#云安全)
- [Cloud Basics](#云基础知识)
- [Cloud Native Security](#云原生安全)
- [Cloud Attack and Defense](#云上攻防)
- [VM](#vm)
- [vCenter](#vcenter)
- [SLP](#slp)
- [AI Security](#ai安全)
- [New Security Solutions](#新安全方案)
- [Building Next-Generation Security](#构建下一代安全)
- [Zero Trust](#零信任)
- [DevSecOps](#devsecops)
- [Threat Detection](#威胁检测)
- [RASP](#rasp)
- [HIDS](#hids)
- [WAF](#waf)
- [WAF Construction Guide](#waf建设指南)
- [BypassWAF](#bypasswaf)
- [Webshell Detection](#webshell检测)
- [Reverse Shell Detection](#反弹shell检测)
- [EDR](#edr)
- [AV](#av)
- [Lateral Movement Detection - Honeypot Approach](#横向移动检测-蜜罐思路)
- [Malicious Traffic Detection](#恶意流量检测)
- [IDS](#ids)
- [Text Detection](#文本检测)
- [Security Operations](#安全运营)
- [Data Security](#数据安全)
- [Network Mapping](#网络测绘)
- [Communication Security](#通信安全)
- [End-to-End Communication (First Edition)](#端对端通信初版)
- [SNI](#sni)
- [Personal Security](#个人安全)
- [APT Research](#apt研究)
- [Advanced Threat List](#高级威胁-list)
- [Threat Intelligence](#威胁情报)
- [Phishing](#钓鱼)
- [C2-RAT](#c2-rat)
- [Warning & Research](#预警研究)
- [ImageMagick](#imagemagick)
- [Exchange](#exchange)
- [Privilege-Escalation](#privilege-escalation)
- [VPN](#vpn)
- [Sangfor](#sangfor)
- [Pulse](#pulse)
- [Palo](#palo)
- [Fortigate](#fortigate)
- [Citrix Gateway/ADC](#citrix-gatewayadc)
- [Tomcat](#tomcat)
- [FUZZING](#fuzzing)
- [Code Audit - JAVA](#代码审计-java)
- [Deserialization - Others](#反序列化-其他)
- [RMI](#rmi)
- [Shiro](#shiro)
- [Fastjson](#fastjson)
- [Dubbo](#dubbo)
- [CAS](#cas)
- [Solr Template Injection](#solr模版注入)
- [Apache Skywalking](#apache-skywalking)
- [Spring](#spring)
- [Spring-boot](#spring-boot)
- [Spring-cloud](#spring-cloud)
- [Spring-data](#spring-data)
- [Blockchain](#区块链)
- [Penetration](#渗透)
- [Perimeter Penetration](#边界渗透)
- [Penetration Records and Summary](#渗透记录和总结)
- [Information Gathering](#信息收集)
- [Ranges](#靶场)
- [Penetration Techniques](#渗透技巧)
- [Intranet Penetration](#内网渗透)
- [Exchange Exploitation (Old)](#exchange利用旧)
- [hash ticket Credential](#hash-ticket-credential)
- [Proxy Forwarding and Port Reuse](#代理转发与端口复用)
- [Intranet Platform](#内网平台)
- [Intranet Techniques](#内网技巧)
- [Privilege Escalation Exploitation](#提权利用)
- [Bug_Bounty](#bug_bounty)
- [Web](#web)
- [XXE](#xxe)
- [XSS](#xss)
- [Jsonp](#jsonp)
- [CORS](#cors)
- [CSRF](#csrf)
- [SSRF](#ssrf)
- [SQL](#sql)
- [File Inclusion](#文件包含)
- [Upload](#上传)
- [Arbitrary File Read](#任意文件读取)
- [Web Cache Deception](#web缓存欺骗)
- [Web Cache Poisoning](#web缓存投毒)
- [SSI](#ssi)
- [SSTI](#ssti)
- [JS](#js)
- [DNS](#dns)
- [Others](#其他)
- [Git](#git)
- [QR Code](#二维码)
- [Crawler](#爬虫)
- [Efficiency](#效率)
- [Popular Science](#科普)
- [Contribute](#contribute)
- [Acknowledgments](#acknowledgments)
- [Star](#star)
## Github-list
### Awesome-list
* [awesome-web-security](https://github.com/qazbnm456/awesome-web-security)
* [Awesome-Hacking](https://github.com/Hack-with-Github/Awesome-Hacking) - 10k-star list
* [awesome-malware-analysis](https://github.com/rshipp/awesome-malware-analysis)
* [Android Security](https://github.com/ashishb/android-security-awesome) - Collection of Android security related resources.
* [Security](https://github.com/sbilly/awesome-security) - Software, libraries, documents, and other resources.
* [An Information Security Reference That Doesn't Suck](https://github.com/rmusser01/Infosec_Reference)
* [Security Talks](https://github.com/PaulSec/awesome-sec-talks) - Curated list of security conferences.
* [OSINT](https://github.com/jivoi/awesome-osint) - Awesome OSINT list containing great resources.
* [The toolbox of open source scanners](https://github.com/We5ter/Scanners-Box) - The toolbox of open source scanners
* [blackhat-arsenal-tools](https://github.com/toolswatch/blackhat-arsenal-tools) - Official Black Hat Arsenal Security Tools Repository
* [awesome-iot-hacks](https://github.com/nebgnahz/awesome-iot-hacks)
* [awesome-awesome](https://github.com/emijrp/awesome-awesome)
* [Curated list of awesome lists](https://github.com/sindresorhus/awesome)
* [Awesome Awesomness](https://github.com/bayandin/awesome-awesomeness) - The List of the Lists.
* [PENTESTING-BIBLE](https://github.com/blaCCkHatHacEEkr/PENTESTING-BIBLE) - Security related content
* [Web-Security-Learning](https://github.com/CHYbeta/Web-Security-Learning) - by CHYbeta
* [Software-Security-Learning](https://github.com/CHYbeta/Software-Security-Learning) - by CHYbeta
* [MiscSecNotes](https://github.com/JnuSimba/MiscSecNotes) - by JnuSimba notes
* [AndroidSecNotes](https://github.com/JnuSimba/AndroidSecNotes) - notes
* [LinuxSecNotes](https://github.com/JnuSimba/LinuxSecNotes) - notes
* [resource collection of python security and code review](https://github.com/bit4woo/python_sec)
* [Pentest_Interview](https://github.com/Leezj9671/Pentest_Interview)
* [tanjiti info source](https://github.com/tanjiti/sec_profile) - by Baidu tanjiti, daily crawled security information sources
* [CVE-Flow](https://github.com/404notf0und/CVE-Flow) - by 404notf0und, monitoring CVE incremental updates, CVE EXP prediction based on deep learning and automated push
* [security_w1k1](https://github.com/euphrat1ca/security_w1k1/) euphrat1ca's repository constantly updated with security-related content
### Development
* [Complete Guide to Advanced Java Knowledge for Internet Java Engineers](https://github.com/doocs/advanced-java)
* [Java Learning + Interview Guide: A guide covering the core knowledge that most Java programmers need to master](https://github.com/Snailclimb/JavaGuide)
* [Python Cheat Sheet ](https://github.com/crazyguitar/pysheeet)
* [A collection of full-stack resources for programmers.](https://github.com/charlax/professional-programming)
* [web, frontend, javascript, nodejs, electron, babel, webpack, rollup, react, vue ...](https://github.com/senntyou/blogs)
* [Python interview questions](https://github.com/taizilongxu/interview_python)
* [Python-100-Days](https://github.com/jackfrued/Python-100-Days)
* [python3-source-code-analysis](https://github.com/flaggo/python3-source-code-analysis)
* [Coding Interview University](https://github.com/jwasham/coding-interview-university)
* [tech-interview-handbook](https://github.com/yangshun/tech-interview-handbook) - good
* [Essential Basics for Interviews](https://github.com/CyC2018/CS-Notes)
* [CS Basics](https://github.com/selfboot/CS_Offer/)
* [Algorithm/Deep Learning/NLP Interview Notes](https://github.com/imhuay/Algorithm_Interview_Notes-Chinese)
* [Algorithm Handbook](https://github.com/labuladong/fucking-algorithm)
* [50 Code Implementations for Data Structures and Algorithms](https://github.com/wangzheng0822/algo)
* [interview_internal_reference](https://github.com/0voice/interview_internal_reference)
* [reverse-interview](https://github.com/yifeikong/reverse-interview-zh) - Questions to ask the interviewer at the end of a technical interview
### Others
* [Recommended Book List for Information Security Practitioners](https://github.com/riusksk/secbook)
* [English Learning Guide Specially Written for Programmers v1.2](https://github.com/yujiangshui/A-Programmers-Guide-to-English)
* [Words Chinese Programmers Often Mispronounce](https://github.com/shimohq/chinese-programmer-wrong-pronunciation)
* [Laws, Theories, Principles, and Patterns Useful for Developers](https://github.com/nusr/hacker-laws-zh)
* [SecLists](https://github.com/danielmiessler/SecLists) - Collection of multiple types of lists used during security assessments.
* [A collection of web attack payloads](https://github.com/foospidy/payloads) payloads collection
* [Collection of Security Mind Maps](https://github.com/phith0n/Mind-Map) - by p niu
* [Security Mind Map Collection](https://github.com/SecWiki/sec-chart) - by SecWiki
* [Android-Reports-and-Resources](https://github.com/B3nac/Android-Reports-and-Resources) - HackerOne Reports
* [AppSec](https://github.com/paragonie/awesome-appsec) - Resources for learning about application security.
* [Infosec](https://github.com/onlurking/awesome-infosec) - Information security resources for pentesting, forensics, and more.
* [YARA](https://github.com/InQuest/awesome-yara) - YARA rules, tools, and people.
* [macOS-Security-and-Privacy-Guide](https://github.com/drduh/macOS-Security-and-Privacy-Guide)
* [awesome-security-weixin-official-accounts](https://github.com/DropsOfZut/awesome-security-weixin-official-accounts)
* [2018-2020 Youth Security Circle - Active Technology Bloggers/Blogs](https://github.com/404notf0und/Security-Data-Analysis-and-Visualization) - by 404notf0und
* [996.Leave](https://github.com/623637646/996.Leave)
* [Renting Tips for Beijing, Shanghai, Guangzhou, Shenzhen, Hangzhou](https://github.com/soulteary/tenant-point)
* [Beijing House Buying](https://github.com/facert/beijing_house_knowledge)
* [Beijing House Buying Guide](https://github.com/yangyiRunning/Beijing-House)
* [Shanghai House Buying](https://github.com/ayuer/shanghai_house_knowledge)
* [Hangzhou House Buying](https://github.com/houshanren/hangzhou_house_knowledge)
* [awesome-macOS](https://github.com/iCHAIT/awesome-macOS) - mac software
* [awesome-mac](https://github.com/jaywcjlove/awesome-mac/blob/master/README-zh.md#%E5%BC%80%E5%8F%91%E8%80%85%E5%B7%A5%E5%85%B7) - mac software
* [ruanyf](https://github.com/ruanyf/weekly) - Technology Lovers Weekly
## Security
### Security list
* [arxiv.org](https://arxiv.org/) Paper library
* [404notf0und Learning Records](https://github.com/404notf0und/Always-Learning#APT%E6%A3%80%E6%B5%8B) Focus on the security detection part
* [Donot's collection of intrusion detection related content](https://github.com/donot-wong/SecAcademic)
* [Zheng Han - Blog](https://www.cnblogs.com/littlehann/) Browse through
* [cdxy - Blog](https://www.cdxy.me/) Very handsome
* [zuozuovera - Blog](https://www.zuozuovera.com/) Deft and skillful
* [Security Academic Circle 2018 Annual Summary](https://mp.weixin.qq.com/s/eQ5os0Fdb498BoQLKUDmrA) - WeChat official account Security Academic Circle
* [security-hardening](https://github.com/decalage2/awesome-security-hardening) Complete security hardening guide
### Security Market Insights
Introduces security market overview, trends, patterns. Domestic and foreign security vendors.
* [XDef Security Summit 2021](https://mp.weixin.qq.com/s/RlEu_qVaj1rIhBuf0vQp8g)
### Cloud Security
#### Cloud Basics
* [Introduction to Virtualization](https://yuvaly0.github.io/2020/06/19/introduction-to-virtualization.html)
* [kvm](https://github.com/yifengyou/learn-kvm) yifengyou's kvm notes
#### Cloud Native Security
* [Google: BeyondProd Model](https://cloud.google.com/security/beyondprod?hl=zh-cn)
* [Meituan Cloud Native Container Security Practice](https://tech.meituan.com/2020/03/12/cloud-native-security.html)
* [Cloud Native Intrusion Detection Trend Observation](https://xz.aliyun.com/t/7841)
* [Cloud Security Opportunities Brought by Cloud Native](https://www.freebuf.com/articles/network/242950.html) Cloud Native Security Market Overview (non-technical)
* [Alibaba Cloud Security White Paper](https://github.com/tom0li/collection-document/blob/master/%E9%98%BF%E9%87%8C%E4%BA%91%E5%AE%89%E5%85%A8%E7%99%BD%E7%9A%AE%E4%B9%A6.pdf)
#### Cloud Attack and Defense
* [Awesome-serverless](https://github.com/puresec/awesome-serverless-security/)
* [Cloud Native Penetration](https://mp.weixin.qq.com/s/Aq8RrH34PTkmF8lKzdY38g) neargle's records on cloud native penetration, introducing services that may be encountered during cloud native penetration and corresponding testing ideas, currently the most comprehensive public introduction to cloud native penetration in China
* [Red Teaming for Cloud](https://mp.weixin.qq.com/s/lUHd6lmFl3m9BMdSC2wwcw) Clearly explains what red team is and some typical cloud pentest paths
* [tom0li: Docker Escape Summary](https://tom0li.github.io/Docker%E9%80%83%E9%80%B8%E5%B0%8F%E7%BB%93%E7%AC%AC%E4%B8%80%E7%89%88/) Introduces 3 types of Docker escape methods from an attack perspective, introduces some escape real-world scenarios and attack methods for engineers
* [Kubernetes security](https://github.com/kabachook/k8s-security) This repo is a collection of kubernetes security stuff and research.
* [serverless functions attack and defense preliminary exploration](https://www.cdxy.me/?p=836) Introduces serverless functions attack paths and defense detection techniques
* [RDS Database Attack and Defense](https://xz.aliyun.com/t/8451) Using leaked non-sub ACCESSKEY, can be configured to connect to RDS externally
* [Collision of Containers and Cloud: A Test on MinIO](https://mp.weixin.qq.com/s/X04IhY9Oau-kDOVbok8wEw) Mainly MinIO object storage SSRF vulnerability, POST SSRF 307 redirect construction exploitation
* [Security Risks of Using Helm2 in Kubernetes](http://rui0.cn/archives/1573) Explains specific operations for obtaining secrets through Helm2
* [K8s 6443 Batch Intrusion Investigation](https://www.cdxy.me/?p=833) Improper authentication configuration allows anonymous users to make privileged requests to k8s API, request pod creation of docker, execute malicious commands in docker, delete created pods
* [K8s Penetration Testing Exploiting kube-apiserver](https://www.cdxy.me/?p=839) Introduces classic attack path, finding high-privilege service accounts in acquired pods
* [K8s Penetration Testing Exploiting etcd](https://www.cdxy.me/?p=827) Introduces commands for unauthorized etcd and attackers with cert to exploit, read service account token, cluster takeover
* [K8s Data Security Secrets Protection Scheme](https://www.cdxy.me/?p=832)
* [Fantastic Conditional Access Policies and how to bypass them](https://dirkjanm.io/assets/raw/fantastic_policies_cloud_roundup.pdf) Dirk-jan's Azure topic
* [I’m in your cloud: A year of hacking Azure AD](https://dirkjanm.io/assets/raw/Im%20in%20your%20cloud%20bluehat-v1.0.pdf) Dirk-jan's Azure topic
* [Istio Access Authorization Exposes High-Risk Vulnerability CVE-2020-8595 Again](https://mp.weixin.qq.com/s?__biz=MzIyODYzNTU2OA==&mid=2247487481&idx=1&sn=02a38db691331634fe41a413beb58694&chksm=e84fa926df382030ac57be9c1ee9cb8836ec37fc79e3a2cef68acb6945a51f0ed94882e39611) Istio exact match mode improper matching leads to unauthorized access
#### VM
##### vCenter
* [CVE-2021-21972 vCenter 6.5-7.0 RCE Vulnerability Analysis](http://noahblog.360.cn/vcenter-6-5-7-0-rce-lou-dong-fen-xi/)
* [VMware vCenter RCE Vulnerability Pitfall Record—What Knowledge Can a Simple RCE Vulnerability Dig Out?](https://mp.weixin.qq.com/s/eamNsLY0uKHXtUw_fiUYxQ) Explains why you cannot upload files by modifying packets in Burp
##### SLP
* [CVE-2020-3992 & CVE-2021-21974: Pre-Auth Remote Code Execution in VMware ESXi ](https://www.zerodayinitiative.com/blog/2021/3/1/cve-2020-3992-amp-cve-2021-21974-pre-auth-remote-code-execution-in-vmware-esxi) Introduces two CVEs: VMware's SLP maintained on top of openSLP has a UAF vulnerability and can bypass patches
### AI Security
* [AI-for-Security-Learning](https://github.com/404notf0und/AI-for-Security-Learning) The power of AI - by 404notf0und
* [0xMJ:AI-Security-Learning](https://github.com/0xMJ/AI-Security-Learning#webshell%E6%A3%80%E6%B5%8B)
* [Adversarial ML Threat Matrix](https://github.com/mitre/advmlthreatmatrix) Adversarial attacks against Machine Learning systems
* [Threat Risk Matrix for AI Security](https://ai.tencent.com/ailab/media/AI%E5%AE%89%E5%85%A8%E7%9A%84%E5%A8%81%E8%83%81%E9%A3%8E%E9%99%A9%E7%9F%A9%E9%98%B5.pdf)
* [Exploration of Machine Learning-Based Web Admin Background Identification Method](https://security.tencent.com/index.php/blog/msg/176) Introduces the design overview of Tencent's internal traffic system background identification module
### New Security Solutions
#### Building Next-Generation Security
* [Elastic Security Network - Building Next-Generation Secure Internet](https://mp.weixin.qq.com/s/epFSC88J7LF3BGwQdoZ-Rg)
#### Zero Trust
* [Zhang Ou: Trusted Network Practice for Digital Banks](https://mp.weixin.qq.com/s/VRG9LEbGTxhpMmCUTUSA8w) Zero trust concept
* [Zero Trust Proxy Tool](https://github.com/mandatoryprogrammer/CursedChrome/blob/master/README.md) Use Chrome as a proxy, can access web services that the victim can access through Chrome
#### DevSecOps
* [DevSecOps Concepts and Thoughts](https://mp.weixin.qq.com/s/_jBmFdtyXY5D_YrrTUP1iQ) Tencent Security Emergency Response Center
* [Awesome-DevSecOps](https://github.com/devsecops/awesome-devsecops)
### Threat Detection
* [Some Myths about Security Intelligence Applications](https://zhuanlan.zhihu.com/p/88042567)
#### RASP
* [Talking about RASP](https://lucifaer.com/2019/09/25/%E6%B5%85%E8%B0%88RASP/)
* [Based on OpenRASP - Elaborating on RASP Class Loading](https://xz.aliyun.com/t/8148)
#### HIDS
* [Distributed HIDS Cluster Architecture Design](https://www.cnxct.com/distributed-hids-cluster-architecture-design/) Meituan Technology Team
#### WAF
##### WAF Construction Guide
* [WAF Construction, Operation, and AI Application Practice](https://mp.weixin.qq.com/s?__biz=MjM5NzE1NjA0MQ==&mid=2651199346&idx=1&sn=99f470d46554149beebb8f89fbcb1578&chksm=bd2cf2d48a5b7bc2b3aecb501855cc2efedc60f6f01026543ac2df5fa138ab2bf424fc5ab2b0&scene=21#wechat_redirect)
##### BypassWAF
* [Menshen WAF Crowdtesting Summary](https://mp.weixin.qq.com/s/w5TwFl4Ac1jCTX0A1H_VbQ)
* [Personal Summary of WAF Bypass Injection Ideas (With 6 Common WAF Bypass Methods)](https://www.t00ls.net/viewthread.php?tid=43687&extra=&page=1)
* [Veteran Drives You Through Common WAF](https://www.secpulse.com/archives/69983.html)
* [Some Tips for SQL Injection ByPass](https://mp.weixin.qq.com/s/fSBZPkO0-HNYfLgmYWJKCg)
* [Bypassing WAF at the HTTP Protocol Level](https://www.freebuf.com/news/193659.html)
* [Using Chunked Transfer to Defeat All WAF](https://www.anquanke.com/post/id/169738)
* [Shortcuts and Methods for WAF Bypass](https://www.qiaoyue.net/2019/WAF%E7%BB%95%E8%BF%87%E7%9A%84%E6%8D%B7%E5%BE%84%E4%B8%8E%E6%96%B9%E6%B3%95/)
* [Some Understanding of Bypassing WAF](http://static.anquanke.com/download/b/security-geek-2019-q2/article-18.html)
* [WAF Bypass: Webshell Upload jsp and Tomcat](https://www.anquanke.com/post/id/210630#)
* [Various Ways jsp webshell](https://xz.aliyun.com/t/7798)
#### Webshell Detection
* [Killing Java web filter-type Memory Webshell](http://gv7.me/articles/2020/kill-java-web-filter-memshell/)
* [Scanning, Capturing, and Killing Filter/Servlet Type Memory Webshells](https://gv7.me/articles/2020/filter-servlet-type-memshell-scan-capture-and-kill/)
* [Miscellaneous Talk: Java Memory Webshell Attack and Defense](https://mp.weixin.qq.com/s/DRbGeVOcJ8m9xo7Gin45kQ)
* [JSP Webshell Those Things -- Attack Chapter](https://mp.weixin.qq.com/s/YhiOHWnqXVqvLNH7XSxC9w)
* [Webshell Attack and Defense PHP](https://github.com/qiyeboy/kill_webshell_detect/blob/master/%E7%9F%A5%E8%AF%86%E6%98%9F%E7%90%83-webshell%E6%94%BB%E4%B8%8E%E9%98%B2.pdf)
* [Application of Taint Tracking Theory in Webshell Detection - PHP Chapter](https://mp.weixin.qq.com/s/MFmSliCQaaVEQ0E66vN5Xg)
* [New Start: Webshell Detection](https://iami.xyz/New-Begin-For-Nothing/)
* [Inject Spring Memory Webshell Using Interceptor](https://github.com/LandGrey/webshell-detect-bypass/blob/master/docs/inject-interceptor-hide-webshell/inject-interceptor-hide-webshell.md) Article is from an attack exploitation perspective
#### Reverse Shell Detection
* [Reverse Shell Principle and Detection Technology Research](https://www.cnblogs.com/LittleHann/p/12038070.html) - by LittleHann
* [Reverse Shell Analysis](https://cloud.tencent.com/developer/article/1645464)
* [Detailed Explanation of Multi-dimensional Reverse Shell Detection Technology](https://www.freebuf.com/articles/network/263684.html)
#### EDR
* [Lets-create-an-edr-and-bypass](https://ethicalchaos.dev/2020/06/14/lets-create-an-edr-and-bypass-it-part-2/)
* [openedr](https://github.com/ComodoSecurity/openedr) Open source product edr
#### AV
* [exploiting-almost-every-antivirus-software](https://www.rack911labs.com/research/exploiting-almost-every-antivirus-software/) Counter AV, use link method to borrow AV high privilege to achieve arbitrary file deletion
* [Bypassing Windows Defender Runtime Scanning](https://labs.f-secure.com/blog/bypassing-windows-defender-runtime-scanning/) Enumerate and test which API calls trigger Defender detection. Found that creating CreateProcess and CreateRemoteThread triggers Defender. Proposes three solutions: rewrite API calls, add/modify instructions for dynamic decryption loading, make Defender not scan that area. Author analyzes Defender's scanning mechanism (virtual memory is large, only scans MEM_PRIVATE or RWX page permissions). When suspicious APIs are called, dynamically set PAGE_NOACCESS memory permission so Defender does not perform security scanning.
* [Engineering antivirus evasion](https://blog.scrt.ch/2020/06/19/engineering-antivirus-evasion/)
* [Bypass Windows Defender Attack Surface Reduction](https://data.hackinn.com/ppt/OffensiveCon2019/Bypass%20Windows%20Exploit%20Guard%20ASR.pdf)
* [Defender scanning filename issue](http://2016.eicar.org/85-0-Download.html)
* [herpaderping](https://github.com/jxy-s/herpaderping) A new type bypass defender
* [Implement a shellcodeLoader](https://paper.seebug.org/1413/) Introduces some shellcode execution methods, bypass sandbox methods
* [Malware_development_part](https://0xpat.github.io/Malware_development_part_5/) Malware series tutorial
* [Antivirus Detection and Its Hook Point List](https://github.com/D3VI5H4/Antivirus-Artifacts/blob/main/ANTIVURUS_ARTIFACTS.pdf)
#### Lateral Movement Detection - Honeypot Approach
* [Honeypots](https://github.com/paralax/awesome-honeypots) - Honeypots, tools, components, and more.
* [Hunting for Skeleton Key Implants](https://riccardoancarani.github.io/2020-08-08-hunting-for-skeleton-keys/) Detect Skeleton Key persistence
* [Creating Honeypot Accounts to Detect Kerberoast](https://www.pentestpartners.com/security-blog/honeyroasting-how-to-detect-kerberoast-breaches-with-honeypots/)
#### Malicious Traffic Detection
* [DataCon2020 Solution: Tracking Botnet via Honeypots and DNS Traffic](https://www.cdxy.me/?p=829)
* [DNS Tunnel Covert Communication Experiment && Attempt to Reproduce Feature Vectorization Detection Method](https://www.cnblogs.com/LittleHann/p/8656621.html#_label0)
* [maltrail](https://github.com/stamparm/maltrail#introduction) Open source traffic detection product
* [cobalt-strike-default-modules-via-named-pipe detection](https://labs.f-secure.com/blog/detecting-cobalt-strike-default-modules-via-named-pipe-analysis/) Detect memory pipe of CS default module after execution after shell
* [Using DNS Data for Threat Discovery](https://mp.weixin.qq.com/s/6CtRd7o4IjreLaU-hFt9vQ) Introduces 360 DNSMON using DNS monitoring to find skidmap backdoor, some analysis techniques
* [DNSMon: Using DNS Data for Threat Discovery](https://blog.netlab.360.com/use-dns-data-produce-threat-intelligence-2/) Monitor events through DNSMON, correlate analysis of events
* [evading-sysmon-dns-monitoring](https://blog.xpnsec.com/evading-sysmon-dns-monitoring/)
* [use-dns-data-produce-threat-intelligence](https://blog.netlab.360.com/use-dns-data-produce-threat-intelligence/)
#### IDS
* [Let's Talk About IDS Signatures](https://www.anquanke.com/post/id/102948#h2-0)
* [Out-of-Order TCP Packets](https://strcpy.me/index.php/archives/789/)
* [Some Explorations on Network Layer Bypassing IDS/IPS](https://paper.seebug.org/1173/)
#### Text Detection
* [Application of Machine Learning in Binary Code Similarity Analysis](https://mp.weixin.qq.com/s?__biz=MjM5NTc2MDYxMw==&mid=2458303210&idx=1&sn=345f8cec156ada8fa9bf6a6d6de83906&chksm=b1818a6086f60376e766baf472171d8e2c780b2913568b46b683e3112fcc5f86c9bf4c19e38b&mpshare=1&scene=1&srcid=&sharer_sharetime=1580984631757&sharer_shareid=5dc01f49f38fd64ff3e64844bc7d2ea7&exportkey=A0qHBeUryuXO6zhGWt5OJNw%3D&pass_ticket=gjTFXl4hPMTBWzlKpWZWqK8HivXQ8q7ChNndmw4I8JrdAK0jWWFvKIq7OMnO3BhL#rd)
### Security Operations
* [How to Evaluate the Quality of Security Work](https://zhuanlan.zhihu.com/p/226493047) Tencent 'Professional Owe Money' some sharing on upward management
### Data Security
* [Internet Enterprise Data Security System Construction](https://tech.meituan.com/2018/05/24/data-security-system-construction.html)
* [Talking about Data Security](https://iami.xyz/Talk-about-data-security/)
#### Network Mapping
* [Brief Discussion on the Art of Cyberspace Mapping](https://www.anquanke.com/post/id/226007)
* [Making Cyberspace Mapping Technology No Longer Unstable](https://mp.weixin.qq.com/s/lr39F9kNOfHlMimgymzVwg) by Zhao Wu, focus points of network mapping
* [Record Some Materials Related to Cyberspace Mapping/Search Engines](https://github.com/EXHades/CyberSpaceSearchEngine-Research)
### Communication Security
#### End-to-End Communication (First Edition)
* [The Most Comprehensive Introduction to Zoom Vulnerabilities and Fixes](https://mp.weixin.qq.com/s/a7mN0lTeXxA3YmZZxIGNRg)
* [Traffic Analysis Attack Against Secure Instant Messaging Software](https://www.anquanke.com/post/id/208678#)
* [Analysis of Data Confidentiality Principle of Shadowsocks Based on Secondary Obfuscation Encryption Transmission](https://www.secrss.com/articles/18469)
#### SNI
* [ESNI](https://www.cloudflare.com/zh-cn/learning/ssl/what-is-encrypted-sni/) what-is-encrypted-sni
* [encrypted-client-hello-the-future-of-esni-in-firefox](https://blog.mozilla.org/security/2021/01/07/encrypted-client-hello-the-future-of-esni-in-firefox/)
* [encrypted-client-hello](https://blog.cloudflare.com/encrypted-client-hello/)
### Personal Security* [Tor-0day-Finding-IP-Addresses](https://www.hackerfactor.com/blog/index.php?/archives/896-Tor-0day-Finding-IP-Addresses.html)
* [lcamtuf: Disaster Plan](https://lcamtuf.coredump.cx/prep/)
* [tom0li: Personal Privacy Protection](https://tom0li.github.io/%E4%B8%AA%E4%BA%BA%E9%9A%90%E7%A7%81%E4%BF%9D%E6%8A%A4/) Privacy protection ideas for ordinary people
* [Protect Privacy](https://github.com/No-Github/Digital-Privacy) A list of methods for digital privacy collection
* [Supercookie Browser Fingerprinting](https://supercookie.me/workwise) Supercookie uses favicons to assign a unique identifier to website visitors. Uses multiple visited URLs to distinguish users.
### APT Research
Most of the content listed earlier is offensive in nature, including APT tracking reports, etc.
#### Advanced Threat List
* [Red-Team-Infrastructure-Wiki](https://github.com/bluscreenofjeff/Red-Team-Infrastructure-Wiki)
* [Collection of APT Analysis Reports](https://github.com/CyberMonitor/APT_CyberCriminal_Campagin_Collections) Highly recommended
* [On the Nature of Advanced Threats and Quantitative Research on Attack Capabilities](http://www.vxjump.net/files/aptr/aptr.txt)
* [OffensiveCon Conference](https://www.offensivecon.org/) (Will not list them one by one)
* [ATT&CK](https://attack.mitre.org/matrices/enterprise/)
* [Red Team Practice and Thinking from 0 to 1](https://mp.weixin.qq.com/s/cyxC4Of4Ic9c_vujQayTLg) Introduces what Red Team is, suitable for internal red team building
* [MITRE | ATT&CK Chinese Site](https://huntingday.github.io) Knowledge map, no longer updated
* [FireEye Threat Research](https://www.fireeye.com/blog/threat-research.html) Well-known threat analysis company
* [red-team-and-the-next](https://devco.re/blog/2019/10/24/evolution-of-DEVCORE-red-team-and-the-next/) -by DEVCORE
Anti Threat articles by redrain and their team
* [Noah blog](http://noahblog.360.cn/) Anti Threat and Threat Actors through Noah Lab Analysts
* [Beacon Lab blog](https://blogs.360.cn/)
* [APT analysis and TTPs extraction](https://paper.seebug.org/1132/)
* [Discussion on ATT&CK/APT/Attribution](https://weibo.com/ttarticle/p/show?id=2309404450471736639616)
* [Legends Always Die -- Brief description of the League of Legends supply chain attack at FireEye Summit](https://card.weibo.com/article/m/show/id/2309404426957856047151) Tracing a supply chain attack, basic information such as domain/IP/email, linking to historical APT activities
* [XShellGhost Incident Technical Review Report](https://cert.360.cn/static/files/XShellGhost%E4%BA%8B%E4%BB%B6%E6%8A%80%E6%9C%AF%E5%9B%9E%E9%A1%BE%E6%8A%A5%E5%91%8A.pdf)
* [Kingslayer A supply chain attack](http://www.hackdog.me/article/Kingslayer-A_supply_chain_attack--Part_1.html)
SolarWinds Supply Chain Analysis
* [Looking at covert operations in APT activities from the SolarWinds supply chain attack (Golden Chain Bear)](https://mp.weixin.qq.com/s/UqXC1vovKUu97569LkYm2Q) Representing Qianxin's analysis of SolarWinds attack behavior
* [SolarWinds Analysis](https://go.recordedfuture.com/hubfs/reports/pov-2020-1230.pdf)
* [Highly Evasive Attacker Leverages SolarWinds Supply Chain to Compromise Multiple Global Victims With SUNBURST Backdoor](https://www.fireeye.com/blog/threat-research/2020/12/evasive-attacker-leverages-solarwinds-supply-chain-compromises-with-sunburst-backdoor.html)
* [SUNBURST analysis other details](https://www.fireeye.com/blog/threat-research/2020/12/sunburst-additional-technical-details.html)
#### Threat Intelligence
* [Indictment against North Korea](https://www.justice.gov/opa/press-release/file/1092091/download) A categorization process that took ten years
* [A brief discussion on 'attribution' of cyber attacks](https://www.secrss.com/articles/14864) Introduces some indicators and methods for APT attribution (reference Cyber Attribution documents) and some attribution documents
* [What is threat intelligence](https://www.secrss.com/articles/16577) Introduces the definition, classification, and indicators of threat intelligence, and explains the attribution and categorization process through some cases
#### Phishing
* [Introduction to SMTP user enumeration and related tools](http://www.freebuf.com/articles/web/182746.html) - Used to obtain user dictionary
* [Spear Phishing Attack](https://payloads.online/archivers/2020-02-05/1)
* [On how to counter hackers using AWVS](http://www.freebuf.com/news/136476.html)
* [The path of counterattack starting from MySQL](https://xz.aliyun.com/t/3277)
* [Mysql Client arbitrary file read attack chain expansion](https://paper.seebug.org/1112/)
* [Malicious MySQL Server reads files from MySQL Client](http://scz.617.cn/network/202001101612.txt)
* [https://github.com/BloodHoundAD/BloodHound/issues/267](https://github.com/BloodHoundAD/BloodHound/issues/267) -xss
* [Ghidra from XXE to RCE](https://xlab.tencent.com/cn/2019/03/18/ghidra-from-xxe-to-rce/) Targeting engineers
* [Security risks from WeChat cheats](https://xlab.tencent.com/cn/2018/10/23/weixin-cheater-risks/) Targeting individuals
* [Node.js repository phishing](https://www.cnblogs.com/index-html/p/npm_package_phishing.html) Targeting engineers
* [Creating malicious Visual Studio Code extensions](https://d0n9.github.io/2018/01/17/vscode%20extension%20%E9%92%93%E9%B1%BC/#) Targeting engineers
* [VS Code phishing](https://blog.doyensec.com/2020/03/16/vscode_codeexec.html) Targeting engineers
* [Python package phishing](https://paper.seebug.org/326/) Targeting engineers
* [Docker client phishing](https://www.blackhat.com/docs/us-17/thursday/us-17-Cherny-Well-That-Escalated-Quickly-How-Abusing-The-Docker-API-Led-To-Remote-Code-Execution-Same-Origin-Bypass-And-Persistence.pdf) Targeting engineers
* [Attacking local Xdebug using malicious pages](https://xlab.tencent.com/cn/2018/03/) Targeting engineers
* [Huawei HG532 router phishing RCE](https://xlab.tencent.com/cn/2018/01/05/a-new-way-to-exploit-cve-2017-17215/) Targeting individuals
* [Intranet phishing]()```
RMI反序列化
WIN远程连接漏洞CVE-2019-1333
Mysql读文件&反序列化
Dubbo反序列化
IDE反序列化
恶意vpn
恶意控件
笔记软件rce
社交软件rce
NodeJS库rce
Python package 钓鱼
VSCODE EXTENSION 钓鱼
VS Studio钓鱼
Twitter钓鱼
红包插件钓鱼防撤回插件
解压rce
破解软件钓鱼
docker客户端钓鱼
docker镜像钓鱼
Xdebug
Ghidra钓鱼
bloodhound钓鱼
AWVS钓鱼
蚁剑
浏览器插件
云盘污染
Email Spoofing
For now, just a simple listing
Some of the previously provided articles contain errors and need practical verification.
Recommend reading the official manuals
Previous ones will be added later
Old```
## Contribute
We welcome everyone to contribute,you can open an issue for this if you have some new idea about this project or you have found some quality safety articles,and then I will add your name to Acknowledgments.
## Acknowledgments
* @[tom0li](https://github.com/tom0li)
* @[neargle](https://github.com/neargle)
* @[r4v3zn](https://github.com/0nise)
## Star
Thanks for the stars
[](https://starchart.cc/tom0li/collection-document)
国外赏金之路 - 老司机赏金见解,历史赏金文章 list