
CTF के लिए उपयोगी उपकरणों को अनुक्रमित करने के लिए रिपॉजिटरी
https://atenea.ccn-cert.cni.es/home
वेब हैकिंग चुनौतियाँ: http://webhacking.kr/
आधुनिक क्रिप्टोग्राफ़ी सीखने के लिए प्लेटफ़ॉर्म: https://cryptohack.org/
रिवर्सिंग प्लेटफ़ॉर्म: https://crackmes.one/
फोरेंसिक्स चुनौतियाँ: https://ctf.unizar.es/ && https://freetraining.dfirdiva.com/dfir-ctfs-challenges && https://socvel.com/
PicoCTF: https://play.picoctf.org/login
ब्लू टीम: https://letsdefend.io/
https://gchq.github.io/CyberChef/
https://www.dcode.fr/tools-list#cryptography
सिफर पहचानकर्ता और विश्लेषक: https://www.boxentriq.com/code-breaking/cipher-identifier
डेटा प्रारूप पहचानकर्ता: https://geocaching.dennistreysa.de/multisolver/
स्वचालित क्रिप्टोग्राम सॉल्वर (प्रतिस्थापन) https://quipqiup.com/
आवृत्ति विश्लेषण: https://crypto.interactive-maths.com/frequency-analysis-breaking-the-code.html
ब्रूट फोर्स विजेनेयर: https://guballa.de/vigenere-solver
RsaCtfTool: https://github.com/Ganapati/RsaCtfTool
इमोजी संदेशों को डिक्रिप्ट करें https://cryptoji.com/ & https://cryptii.com/pipes/morse-code-with-emojis
Padding-oracle-attacker: https://github.com/KishanBagaria/padding-oracle-attacker
समुद्री सिग्नल फ्लैग शब्दकोश: https://en.wikipedia.org/wiki/International_maritime_signal_flags
Enigma: https://cryptii.com/
गुणनखंडन: http://factordb.com/
क्रिप्टएनालिसिस संकलन: https://github.com/mindcrypt/Cryptanalysis
http://rumkin.com/tools/cipher/
रियल टाइम कनवर्टर: https://kt.gy/tools.html#conv/
टोर हिडन सर्विस डिस्क्रिप्टर या सार्वजनिक कुंजी से ओनियन पता गणना करने के लिए सरल स्क्रिप्ट: https://gist.github.com/DonnchaC/d6428881f451097f329e (ठीक से काम करने के लिए आपको लाइन 14 संशोधित करनी होगी "onion_address = hashlib.sha1(key.exportKey('DER')[22:]).digest()[:10]").
स्पीच टू टेक्स्ट: https://speech-to-text-demo.ng.bluemix.net/
गाने के बोल: https://codewithrockstar.com/online
स्ट्रिंग का ऑनलाइन MD5 हैश जनरेटर: http://www.md5.cz/
हैश डेटाबेस: https://crackstation.net/
Dehashed: https://www.dehashed.com/
हैश क्रैकिंग: http://rainbowtables.it64.com/
हैश डेटाबेस: https://www.onlinehashcrack.com/
हैश डेटाबेस: https://md5decrypt.net/en/
हैश डेटाबेस: https://hashkiller.io/
हैश डेटाबेस: https://hashes.com/en/decrypt/hash
Ook! गूढ़ प्रोग्रामिंग भाषा डिकोडर: https://www.dcode.fr/ook-language
Brainfuck गूढ़ प्रोग्रामिंग भाषा डिकोडर: https://www.dcode.fr/brainfuck-language
Malboge गूढ़ प्रोग्रामिंग भाषा डिकोडर: https://www.malbolge.doleczek.pl/
COW गूढ़ प्रोग्रामिंग भाषा: https://frank-buss.de/cow.html
Exiftool
Zsteg
Exiv2
Identify -verbose file
मैजिक नंबर सिग्नेचर: https://asecuritysite.com/forensics/magic && https://www.garykessler.net/library/file_sigs.html → Hexeditor
Binwalk -e image
Foremost -i image -o outdir
Steghide: http://steghide.sourceforge.net/documentation/manpage_es.php (उदा.: steghide extract -sf file , steghide info file)
Stegseek: https://github.com/RickdeJager/stegseek (Stegcracker से बेहतर)
StegCracker: https://github.com/Paradoxis/StegCracker
गहन स्टेग्नोग्राफ़ी विश्लेषण उपकरण: https://aperisolve.fr/
स्पेक्ट्रम विश्लेषक: https://academo.org/demos/spectrum-analyzer/
Stegsolve: https://github.com/zardus/ctf-tools/blob/master/stegsolve/install (चलाने के लिए: java -jar steg_solve.jar)
फूरियर ट्रांसफॉर्म: http://bigwww.epfl.ch/demo/ip/demos/FFT/ && https://github.com/0xcomposure/FFTStegPic
डिजिटल अदृश्य स्याही स्टेगो उपकरण: https://sourceforge.net/projects/diit/
8-बिट अटारी टर्बो कैसेट टेप से फ़ाइलें डिकोड करना: https://github.com/baktragh/turbodecoder
https://incoherency.co.uk/image-steganography/#unhide
https://stegonline.georgeom.net/upload
https://stylesuxx.github.io/steganography/
https://skynettools.com/free-online-steganography-tools/
मोर्स कोड अनुकूली ऑडियो डिकोडर: https://morsecode.world/international/decoder/audio-decoder-adaptive.html
Audacity (sudo apt-get install audacity) उदा.: https://www.hackiit.cf/write-up-hackiit-ctf-biological-hazard-ii/
AudioStego: https://github.com/danielcardeenas/AudioStego
स्टेगोमालवेयर का पता लगाने के लिए संदिग्ध फ़ाइलों और URL का विश्लेषण करें: https://stegoinspector.com/#/
ऑरेबेश अनुवादक: https://funtranslations.com/aurebesh
बिटकॉइन स्टेग्नोग्राफ़ी: https://incoherency.co.uk/stegoseed/
मोजीबेक स्टेग्नोग्राफ़ी: https://incoherency.co.uk/mojibake/
शतरंज स्टेग्नोग्राफ़ी : https://incoherency.co.uk/chess-steg/
मैजिक आई सॉल्वर / व्यूअर: https://magiceye.ecksdee.co.uk/
क्यूआर डिकोडर: https://online-barcode-reader.inliteresearch.com/ && https://zxing.org/w/decode.jspx
Stegosuite: http://manpages.ubuntu.com/manpages/bionic/man1/stegosuite.1.html
StegSecret: http://stegsecret.sourceforge.net/
Openstego: https://www.openstego.com/
Stegpic: https://domnit.org/stepic/doc/
https://www.bertnase.de/npiet/npiet-execute.php
छवियों की मरम्मत करें: https://online.officerecovery.com/es/pixrecovery/
पिक्सेलयुक्त स्क्रीनशॉट से पासवर्ड पुनर्प्राप्त करने का उपकरण: https://github.com/beurtschipper/Depix
फोरेंसिक छवि विश्लेषण: https://github.com/GuidoBartoli/sherloq
ज़ीरो-विड्थ वर्णों के साथ यूनिकोड स्टेग्नोग्राफ़ी: https://330k.github.io/misc_tools/unicode_steganography.html
Stegsnow(ज़ीरो-विड्थ वर्ण): https://pentesttools.net/hide-secret-messages-in-text-using-stegsnow-zero-width-characters/
स्पैम भाषा या PGP: https://www.spammimic.com/decode.shtml
f5stegojs: https://desudesutalk.github.io/f5stegojs/
लिंक अनशॉर्ट करें: https://unshorten.it/
PNG डंप: https://blog.didierstevens.com/2022/04/18/new-tool-pngdump-py-beta/
आईपी जानकारी: https://bgp.tools/
आईपी जानकारी: https://www.maxmind.com/en/geoip-demo
https://sitereport.netcraft.com/? && https://searchdns.netcraft.com/
GHDB (गूगल हैकिंग डेटाबेस): https://www.exploit-db.com/google-hacking-database
गूगल चीटशीट: https://gist.github.com/sundowndev/283efaddbcf896ab405488330d1bbc06
https://ciberpatrulla.com/links/
आपके OSINT शोध में सहायता के लिए उपकरण, फ़्लोचार्ट और चीटशीट: https://technisette.com/p/tools
संकलन: https://osint.link/
विश्व डोमेन डेटाबेस: http://web.archive.org/ && https://archive.eu/
DNS खोज: https://dns.coffee/
साइबर डिफेंस खोज: https://www.onyphe.io/
दुरुपयोग डोमेन, आईपी: https://www.abuseipdb.com/
https://www.brightcloud.com/tools/url-ip-lookup.php
प्रतिष्ठा URL जाँचकर्ता: https://www.urlvoid.com/
इंटरनेट ऑफ थिंग्स के लिए खोज इंजन: https://www.shodan.io/ && सभी फ़िल्टर चीटशीट: https://beta.shodan.io/search/filters
IVRE: https://ivre.rocks/
थ्रेट इंटेल उपकरण: https://cyberfive.uk/threat-intel-tools/
https://talosintelligence.com/
PGP वैश्विक निर्देशिका: https://keyserver2.pgp.com/vkd/GetWelcomeScreen.event
Hurricane Electric BGP: https://bgp.he.net/
Email2PhoneNumber: https://github.com/martinvigo/email2phonenumber
हनीपॉट या नहीं: https://honeyscore.shodan.io/
Pwn ईमेल DB TOR: http://pwndb2am4tzkvold.onion/
यह जाँचने की वेबसाइट कि ईमेल या पासवर्ड से समझौता हुआ है या नहीं: https://haveibeenpwned.com/
लीक: https://leaks.sh/
Pwn ईमेल DB: https://intelx.io/
Pwn ईमेल DB: https://cybernews.com/personal-data-leak-check/
PwnDB स्क्रिप्ट: https://github.com/davidtavarez/pwndb
प्लेन टेक्स्ट में फ़िल्टर किए गए क्रेडेंशियल्स खोजें: https://esgeeks.com/pwndb-buscar-credenciales-filtradas-texto-plano/
ईमेल जाँचकर्ता: https://toolbox.googleapps.com/apps/checkmx/
कार पहचान: https://carnet.ai/
तस्वीर का समय, सूर्य कैलकुलेटर: https://www.suncalc.org/#/27.6936,-97.5195,3/2024.01.09/09:23/1/3
सामान्य प्रयोजन: https://github.com/Moham3dRiahi/Th3inspector
विश्लेषण I: https://centralops.net/co/
विश्लेषण II: https://viewdns.info/
विश्लेषण III: https://sitereport.netcraft.com/
विश्लेषण IV: https://www.ipaddress.com/
मैलवेयर: https://www.virustotal.com/gui/home/upload & https://opentip.kaspersky.com/
प्रतिष्ठा: https://talosintelligence.com/, https://www.abuseipdb.com/
किसी डोमेन की तकनीक: https://builtwith.com/
URL के पुनर्निर्देशन पथों को ट्रैक करने का उपकरण: https://wheregoes.com/
किसी डोमेन का इतिहास: https://web.archive.org/
रीयल-टाइम ब्लैकहोल सूची, ASNs: https://bgp.he.net/
SSL प्रमाणपत्र: https://www.digicert.com/help/
पुनर्निर्देशन: https://lookyloo.circl.lu/
फ़िशिंग डोमेन डेटाबेस: http://phishtank.org/
फ़िशिंग डोमेन डेटाबेस: https://phishcheck.me/
फ़िशिंग डोमेन CSV: https://phishstats.info/
फ़िशिंग शोध: https://safeweb.norton.com/ , https://isitphishing.org/, https://openphish.com/ && https://opentip.kaspersky.com/.
संकलन: https://osintframework.com/
ईमेल खाता विश्लेषण: curl emailrep.io/john.[email protected]
ऑनलाइन PCAP विश्लेषण: https://lab.dynamite.ai/
PCAP से स्ट्रिंग्स पहचानने का उपकरण: https://github.com/bee-san/pyWhat. उदा.:python3 -m pywhat redteam_test03-10423dd9015c050a40b7ccf2a53f57a9.pcapng > output
उन्नत PCAP: https://www.kitploit.com/2023/08/bryobio-network-pcap-file-analysis.html
Wireshark. चीटशीट: https://cdn.comparitech.com/wp-content/uploads/2019/06/Wireshark-Cheat-Sheet-1.jpg
Volatility. चीटशीट: https://blog.onfvp.com/post/volatility-cheatsheet/ >>> Malfind, yarascan, Connscan और netscan
Foremost
Binwalk
Autopsy
PhotoRec: https://www.cgsecurity.org/wiki/PhotoRec
फोटो फोरेंसिक्स: https://29a.ch/photo-forensics/#forensic-magnifier
Recuva: https://www.ccleaner.com/recuva
कुंजियाँ: https://www.nirsoft.net/utils/product_cd_key_viewer.html
DDRescue. https://launchpad.net/ddrescue-gui
Rescuezilla: https://rescuezilla.com/
PolarProxy: https://www.netresec.com/?page=PolarProxy
MRC: https://www.magnetforensics.com/resources/magnet-ram-capture/
मीडिया अधिग्रहण (डिस्क से इमेज): https://guymager.sourceforge.io/
https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/
https://blog.didierstevens.com/programs/xorsearch/
फोरेंसिक्स संकलन: https://start.me/p/JDRmPO/recursos-forenses && https://start.me/p/q6mw4Q/forensics
Binwalk
Dotpeek (.NET)
Angr (डीऑबफस्केटेड कोड): https://angr.io/ && https://napongizero.github.io/blog/Defeating-Code-Obfuscation-with-Angr
GameBoy डिबगर: https://bgb.bircd.org/
IDA pro. चीटशीट: https://www.dragonjar.org/cheat-sheet-ida-pro-interactive-disassembler.xhtml
Ollydbg. चीटशीट: http://www.ollydbg.de/quickst.htm
GDB: https://gist.github.com/rkubik/b96c23bd8ed58333de37f2b8cd052c30
Radare2. चीटशीट: https://gist.github.com/williballenthin/6857590dab3e2a6559d7
Ghidra. चीटशीट: https://hackersfun.com/wp-content/uploads/2019/03/Ghidra-Cheat-Sheet.pdf
Immunity Debugger: https://www.immunityinc.com/products/debugger/
x64dbg
Binary Ninja: https://binary.ninja/
शुरुआती रिवर्सिंग उपकरण: https://exeinfo-pe.en.uptodown.com/windows
Regshot: https://sourceforge.net/projects/regshot/ (बायनेरी चलाने से पहले और बाद में)
CFF explorer: https://download.cnet.com/CFF-Explorer/3000-2383_4-10431156.html
ऑनलाइन डिसअसेंबलर: https://onlinedisassembler.com/static/home/index.html
python -c "print ('A' * 5100)"
सामान्य पोर्ट्स चीटशीट: https://packetlife.net/media/library/23/common_ports.pdf
एन्यूमरेशन चीटशीट: https://pentestwiki.org/enumeration-cheat-sheet/
Nmap. चीटशीट: https://highon.coffee/blog/nmap-cheat-sheet/ && https://scadahacker.com/library/Documents/Cheat_Sheets/Hacking%20-%20NMap%20Quick%20Reference%20Guide.pdf
ऑपरेटिंग सिस्टम रीकॉन: "सेवा का संस्करण https://launchpad.net/"
GUI-DNSRecon: https://www.kitploit.com/2023/02/dnsrecon-gui-dnsrecon-tool-with-gui-for.html
enum4linux - https://highon.coffee/blog/enum4linux-cheat-sheet/
wget -nd -r -P /save/location -A jpeg,jpg,bmp,gif,png http://www.somedomain.com
robots.txt को बायपास करते हुए रिकर्सिव फ़ाइल डाउनलोड: wget -e robots=off -drc -l5 domain* तृतीय पक्षों के साथ स्कैनिंग: https://hackertarget.com/nmap-online-port-scanner/, https://www.ipfingerprints.com/, https://spiderip.com/online-port-scan.php, https://portscanner.standingtech.com/ && https://www.yougetsignal.com/tools/open-ports/
Scanless प्रोजेक्ट: https://github.com/vesche/scanless
किसी डोमेन से ईमेल की सूची बनाएं: https://maildump.co/domain-search
किसी कंपनी के डोमेन की सूची बनाएं: Curl https://sonar.omnisint.io/tlds/
SPF,DKIM,DMARC: https://github.com/MattKeeley/Spoofy & https://www.kitploit.com/2023/02/email-vulnerablity-checker-find-email.html & https://github.com/magichk/magicspoofing && https://toolbox.googleapps.com/apps/checkmx/
कंपनी के हैश और पासवर्ड: https://www.dehashed.com/
dnsrecon -d dte.local -n IP - https://pentestlab.blog/2012/11/13/dns-reconnaissance-dnsrecon/
सबसे बड़ा DNS ऐतिहासिक डेटा: https://securitytrails.com/
DNS होस्ट रिकॉर्ड: https://hackertarget.com/find-dns-host-records/
HTTP हेडर विश्लेषण भेद्यता उपकरण: https://dnsdumpster.com/
ReconFTW: https://github.com/six2dez/reconftw
Autorecon: https://github.com/Tib3rius/AutoRecon
OSINT संग्रह उपकरण: https://github.com/s0md3v/Photon
OSINT संग्रह उपकरण: https://github.com/laramies/theHarvester
DNS रिज़ॉल्वर: https://github.com/d3mondev/puredns
Wappalyzer
whatweb -v -a 3 scanme.nmap.org
nmap -p 80 --script=http-*
HTTP हेडर विश्लेषण भेद्यता उपकरण: https://github.com/Aetsu/gethead/blob/gh-pages/gethead.py
Feroxbuster
Gobuster. चीट शीट: https://redteamtutorials.com/2018/11/19/gobuster-cheatsheet/
Burpsuite
OWASP ZAP, OpenVas, Sparta और Nikto. चीट शीट: https://cdn.comparitech.com/wp-content/uploads/2019/07/NIkto-Cheat-Sheet.webp
Hydra. चीट शीट: hydra -l admin -P /usr/share/wordlists/rockyou.txt IP http-post-form “__csrf_magic=sid%3Ae40fd9611063464c3ff346ffa53b7a28b3cd5971%2C1638348501&usernamefld=admin&passwordfld=^PASS^&login=Sign+In" || patator http_fuzz url=http://IP/ method=POST &usernamefld=admin&passwordfld=FILE0&login=Sign+In' 0=/usr/share/wordlists/rockyou.txt follow=1 accept_cookie=1 -x ignore:fgrep='Username or Password incorrect'
hydra -s 22 -l user -P /usr/share/wordlists/rockyou.txt IP -t 4 ssh
wfuzz. चीट शीट: https://book.hacktricks.xyz/pentesting-web/web-tool-wfuzz
2FA बाइपास: https://www.xmind.net/m/8Hkymg/
Linkfinder: https://github.com/GerbenJavado/LinkFinder
Dirsearch: https://github.com/maurosoria/dirsearch
स्वचालित ऑल-इन-वन OS कमांड इंजेक्शन और एक्सप्लॉइटेशन उपकरण: https://github.com/commixproject/commix
स्वचालित XSS उपकरण:
https://pentest-tools.com/home
https://github.com/blaCCkHatHacEEkr/PENTESTING-BIBLE
https://jorgectf.gitbook.io/awae-oswe-preparation-resources/
SearchSploit. चीट शीट: https://blog.ehcgroup.io/2018/11/27/01/00/39/4198/como-usar-searchsploit-para-encontrar-exploits/hacking/ehacking/
विशेषाधिकार एस्केलेशन: docker run -v /:/mnt --rm -it imagen chroot /mnt sh
ऑनलाइन रिवर्स शेल जनरेटर: https://www.revshells.com/
रिवर्स शेल चीटशीट: https://reconshell.com/reverse-shell-cheat-sheet/ && चीटशीट: https://github.com/swisskyrepo/PayloadsAllTheThings/blob/master/Methodology%20and%20Resources/Reverse%20Shell%20Cheatsheet.md
वेबशेल्स: https://github.com/BlackArch/webshells
पॉपशेल्स: https://github.com/0x00-0x00/ShellPop
साधारण शेल को पूरी तरह से इंटरैक्टिव TTY में अपग्रेड करना: https://blog.ropnop.com/upgrading-simple-shells-to-fully-interactive-ttys/
crackmapexec - https://cheatsheet.haax.fr/windows-systems/exploitation/crackmapexec/
Rundll32 कमांड उदाहरण: https://www.jesusninoc.com/04/12/rundll32-commands-for-windows/
rdesktop IP, proxychains IP
sqlmap - https://www.security-sleuth.com/sleuth-blog/2017/1/3/sqlmap-cheat-sheet
रिवर्स शेल पेलोड जनरेटर - Hoaxshell: https://github.com/t3l3machus/hoaxshell
Microsoft Exchange पर कमांड चलाना: https://github.com/WithSecureLabs/peas
Powerglot: https://github.com/mindcrypt/powerglot
नेटवर्क स्कैनर: https://www.softperfect.com/products/networkscanner/
linWinPwn: https://github.com/lefayjey/linWinPwn
Mimikatz: https://book.hacktricks.xyz/windows-hardening/stealing-credentials/credentials-mimikatz
Crackmapexec: https://cheatsheet.haax.fr/windows-systems/exploitation/crackmapexec/
LDAP एन्यूमरेशन: https://pentestwiki.org/enumeration-cheat-sheet/#h-ldap-enumeration
Seatbelt जाँच: https://github.com/GhostPack/Seatbelt
Bloodhound: https://bloodhound.readthedocs.io/en/latest/index.html
Adalanche: https://www.kitploit.com/2021/08/adalanche-active-directory-acl.html
sudo apt install peass
WinPEAS: https://github.com/carlospolop/privilege-escalation-awesome-scripts-suite/tree/master/winPEAS
Juicy potato: https://github.com/ohpe/juicy-potato
PowerUp: https://github.com/PowerShellMafia/PowerSploit/blob/dev/Privesc/PowerUp.ps1
LinPEAS: https://github.com/carlospolop/privilege-escalation-awesome-scripts-suite/tree/master/linPEAS
LinEnum: https://github.com/rebootuser/LinEnum/blob/master/LinEnum.sh
BeRoot: https://github.com/AlessandroZ/BeRoot/tree/master/Linux
Windows से Lolbas: https://lolbas-project.github.io/
यूनिक्स सिस्टम से GTFOBins: https://gtfobins.github.io/
बाइनरी के साथ Windows डिफेंडर को बायपास करें: https://github.com/Bl4ckM1rror/FUD-UUID-Shellcode
Shikata ga nai: https://github.com/EgeBalci/sgn
Shellter: https://www.kali.org/tools/shellter/
Metasploit. चीटशीट: https://github.com/k1000o23/cheat_sheets/blob/master/metasploit_cheat_sheet.pdf
Fsociety फ्रेमवर्क: https://github.com/Manisso/fsociety
Empire. चीटशीट: https://github.com/HarmJ0y/CheatSheets/blob/master/Empire.pdf
मोबाइल पेंटेस्ट चीटशीट: https://github.com/tanprathan/MobileApp-Pentest-Cheatsheet && https://github.com/randorisec/MobileHackingCheatSheet
स्वचालित मोबाइल उपकरण: https://github.com/MobSF/Mobile-Security-Framework-MobSF, https://github.com/SUPERAndroidAnalyzer/super
असुरक्षित Android अनुप्रयोगों की सूची: https://github.com/netbiosX/Pentest-Bookmarks/blob/master/Training-Labs/Mobile-Testing/Android-Applications.mdown
PcapDroid: https://play.google.com/store/apps/details?id=com.emanuelef.remote_capture&hl=es_419&gl=US
Fing ऐप्लिकेशन: https://www.fing.com/
वाई-फ़ाई विश्लेषक: https://play.google.com/store/apps/details?id=com.farproc.wifi.analyzer&hl=es&gl=US&pli=1
वाई-फ़ाई ऑडिटिंग: https://github.com/v1s1t0r1sh3r3/airgeddon
वाई-फ़ाई क्रैक: https://github.com/s4vitar/wifiCrack
EvilTrust: https://github.com/s4vitar/evilTrust
RomBuster: https://github.com/EntySec/RomBuster
Yersinia
Bettercap
Wifi Pineapple
https://linuxhint.com/how_to_aircrack_ng/
mount -t cifs IP/SharedResource /mnt/smbmounted -o vers=2.1 && * smbclient -U "" -N //IP/SharedResource
dpkg -l एक वर्चुअल मशीन में सभी स्थापित प्रोग्रामों की सूची बनाने के लिए। आउटपुट को पाइप करें ताकि आप जो चाहें खोज सकें।
Msfvenom: https://www.offensive-security.com/metasploit-unleashed/msfvenom/ & https://www.offensive-security.com/metasploit-unleashed/binary-payloads/
क्या आप ब्लॉक हैं?: https://ippsec.rocks/?#
OSCP-शैली: https://gist.github.com/s4vitar/b88fefd5d9fbbdcc5f30729f7e06826e
Pentest-book: https://pentestbook.six2dez.com/ && https://book.hacktricks.xyz/pentesting-methodology
सर्वश्रेष्ठ: https://omniasec.ai/
Virustotal: https://www.virustotal.com/gui/home/search
ऑनलाइन Cuckoo सैंडबॉक्स: https://sandbox.pikker.ee/
ब्राउज़र एक्सटेंशन: https://spin.ai/application-risk-assessment/
APK's: https://mobsf.live/ && https://koodous.com/
Joesandbox: https://www.joesandbox.com/#windows
Kaspersky: https://opentip.kaspersky.com/
Intezer: https://analyze.intezer.com/scan
Hybrid Analysis: https://www.hybrid-analysis.com/?lang=es
नकली-संबंधित वेबसाइटों का डेटाबेस: https://desenmascara.me/
ANY.RUN https://any.run/
https://metadefender.opswat.com/?lang=en
Windows-आधारित AI-संचालित रिवर्स इंजीनियरिंग टूलकिट: https://github.com/Jakiboy/ReVens
मैलवेयर की जाँच के लिए Linux डिस्ट्रो: https://docs.remnux.org/
मैलवेयर की जाँच के लिए Windows डिस्ट्रो: https://github.com/mandiant/flare-vm
https://github.com/LaurieWired/linux_malware_analysis_container
Sysinternals: https://docs.microsoft.com/en-us/sysinternals/
Systeminformer: https://systeminformer.sourceforge.io/
Detect it easy(पैकर डिटेक्टर): https://en.kali.tools/?p=1644
Sysinspector: https://support.eset.com/es/que-es-eset-sysinspector
एक निष्पादन योग्य फ़ाइल से Dependency walker: https://www.dependencywalker.com/
Autoruns: https://docs.microsoft.com/en-us/sysinternals/downloads/autoruns
RAM कैप्चरर: https://belkasoft.com/ram-capturer
रिवर्स इंजीनियर का टूलकिट: https://github.com/mentebinaria/retoolkit
PEstudio: https://www.winitor.com/
Malzilla: https://malzilla.org/
PROCMON+PCAP: https://www.procdot.com/
APK का विश्लेषण करें: https://github.com/quark-engine/quark-engine && https://github.com/mvt-project/mvt && https://github.com/pjlantz/droidbox
XORSearch: https://blog.didierstevens.com/programs/xorsearch/
DragonFly: https://dragonfly.certego.net/register
ऑफ़लाइन सैंडबॉक्स: https://sandboxie-plus.com/downloads/
रैंसमवेयर डिक्रिप्शन उपकरण: http://files-download.avg.com/util/avgrem/avg_decryptor_Legion.exe, https://success.trendmicro.com/solution/1114221-downloading-and-using-the-trend-micro-ransomware-file-decryptor, https://www.nomoreransom.org/es/decryption-tools.htmlm, https://www.avast.com/es-es/ransomware-decryption-tools , https://noransom.kaspersky.com/ , https://www.mcafee.com/enterprise/es-es/downloads/free-tools/ransomware-decryption.html, https://www.mcafee.com/enterprise/en-us/downloads/free-tools.html, https://www.emsisoft.com/ransomware-decryption-tools/, https://decoded.avast.io/threatresearch/decrypted-bianlian-ransomware/.
सामान्य अवलोकन: https://docs.google.com/spreadsheets/d/1TWS238xacAto-fLKh1n5uTsdijWdCEsGIM0Y0Hvmc5g/pubhtml#
रैंसमवेयर समूह: http://edteebo2w2bvwewbjb5wgwxksuwqutbg3lk34ln7jpf3obhy4cvkbuqd.onion/
इंटेलिजेंस: https://docs.google.com/spreadsheets/d/1H9_xaxQHpWaa4O_Son4Gx0YOIzlcBWMsdvePFX68EKU/pubhtml# && https://github.com/StrangerealIntel/EternalLiberty/blob/main/EternalLiberty.csv && https://xorl.wordpress.com/
थ्रेट एक्टर नॉलेज ग्राफ़: https://jupyter.securitybreak.io/graph_TA/index.html
क्या आप APT लक्ष्य हैं? -> https://lab52.io/
मैक्रोज़: https://blog.didierstevens.com/2021/01/19/video-maldoc-analysis-with-cyberchef/ && https://blog.nviso.eu/2022/04/06/analyzing-a-multilayer-maldoc-a-beginners-guide/
मैलवेयर उदाहरण/बाइनरीज़: https://bazaar.abuse.ch/, https://github.com/ytisf/theZoo & https://malshare.com/
कुछ फ़िल्टर किए गए पोर्ट को बायपास करने के लिए: nmap -sSV ...
zip2john backup.zip secret.hash
john --show secret.hash
Hexeditor
nc -nlvp URL port
Grep
rgrep (रिकर्सिव grep)
awk
perl
tail / head
curl -Llv domain | curl -b "protected=d41d8cd98f00b204e9800998ecf8427e"(cookie) "domain"
Identify -verbose
Hash-identifier
cat 'file' | md5sum, sha1sum,sha256sum...
echo "string" | base64 -d
Strings
File
Cewl. चीट शीट: https://null-byte.wonderhowto.com/how-to/hack-like-pro-crack-passwords-part-5-creating-custom-wordlist-with-cewl-0158855/
पासवर्ड पुनर्प्राप्ति ऑनलाइन : https://www.lostmypass.com/try/
कंप्यूटर में संग्रहीत पासवर्ड: https://github.com/AlessandroZ/LaZagne
डिस्क इमेज: https://www.datanumen.com/disk-image-download-thanks/
crackzip: https://github.com/Xpykerz/CrackZip
zip2john: https://github.com/openwall/john/blob/bleeding-jumbo/src/zip2john.c
सामान्य उपयोगकर्ता पासवर्ड प्रोफाइलर: https://github.com/Mebus/cupp और https://github.com/r3nt0n/bopscrk.
wget -nd -r -P /save/location -A jpeg,jpg,bmp,gif,png http://www.somedomain.com
https://github.com/JohnHammond/ctf-katana
https://github.com/OpenToAllCTF/Tips
रिवर्सिंग ट्यूटोरियल: https://github.com/mytechnotalent/Reverse-Engineering-Tutorial
https://apsdehal.in/awesome-ctf/
https://github.com/0e85dc6eaf/CTF-Writeups
https://github.com/RazviOverflow/ctfs
https://github.com/DEKRA-CTF/CTFs/tree/main/2020
https://medium.com/bugbountywriteup/tryhackme-reversing-elf-writeup-6fd006704148
https://github.com/W3rni0/ctf_writeups_archive/tree/master/castorsCTF_2020
गूगल इमेज सर्च: https://www.google.es/imghp?hl=es , यांडेक्स: https://yandex.com/images/ , बिंग: https://www.bing.com/?scope=images&nr=1&FORM=NOFORM
रिवर्स इमेज सर्च: https://tineye.com/
URL के पुनर्निर्देशन पथों को ट्रैक करने का उपकरण: https://wheregoes.com/
फ़िशिंग ऑनलाइन जाँचकर्ता: https://easydmarc.com/tools/phishing-url
फ़िशिंग डोमेन डेटाबेस: http://phishtank.org/
फ़िशिंग डोमेन डेटाबेस: https://phishcheck.me/
फ़िशिंग शोध: https://safeweb.norton.com/ , https://isitphishing.org/, https://openphish.com/ && https://opentip.kaspersky.com/.
Instagram: https://github.com/th3unkn0n/osi.ig
Censys: https://censys.io/ipv4
Zoomeye.org: https://www.zoomeye.org/
IVRE: https://ivre.rocks/
IoT खोज इंजन: https://www.thingful.net/
किसी डोमेन से संबंधित ईमेल पते खोजें: https://hunter.io/
लोगों की खोज इंजन: https://thatsthem.com/
Fofa खोज इंजन: https://fofa.so/ (Shodan के समान)
ग्राफ़िकल OSINT प्लेटफ़ॉर्म: https://www.spiderfoot.net/#
Fullhunt: https://fullhunt.io/
कोड खोज: https://grep.app/ && https://publicwww.com/
Natlas: https://natlas.io/
Spur: https://spur.us/
सार्वजनिक वाई-फाई डेटाबेस: https://www.mylnikov.org/
किसी डोमेन के HTTP हेडर: https://www.webconfs.com/http-header-check.php
सार्वजनिक दस्तावेज़ों के मेटाडेटा: https://github.com/Josue87/MetaFinder
अपना OWA (आउटलुक वेब एक्सेस) जाँचें: https://checkmyowa.unit221b.com/
Whatspp IP Leak: https://github.com/bhdresh/Whatsapp-IP-leak?s=09
विंडोज़ इवेंट लॉग्स में तेज़ी से खोज और हंट करें: https://github.com/countercept/chainsaw
AccessData FTK Imager
EnCase
EaseUS Data Recovery Wizard
MFT_Browser: https://github.com/kacos2000/MFT_Browser
पॉवरशेल डिकोडर: https://github.com/R3MRUM/PSDecode, https://github.com/JohnLaTwC/PyPowerShellXray और विश्लेषण जानकारी: https://darungrim.com/research/2019-10-01-analyzing-powershell-threats-using-powershell-debugging.html
PDF विश्लेषक: https://github.com/zbetcheckin/PDF_analysis, https://github.com/DidierStevens/DidierStevensSuite/blob/master/pdfid.py, https://github.com/DidierStevens/DidierStevensSuite/blob/master/pdf-parser.py और https://eternal-todo.com/tools/peepdf-pdf-analysis-tool.
Office विश्लेषक: https://github.com/DissectMalware/XLMMacroDeobfuscator, https://github.com/unixfreak0037/officeparser, https://github.com/decalage2/oletools, https://github.com/bontchev/pcodedmp, https://github.com/decalage2/ViperMonkey && https://blog.didierstevens.com/programs/oledump-py/.
किसी फ़ाइल से यूनिकोड-एन्कोडेड सामग्री निकालें: https://github.com/DidierStevens/DidierStevensSuite/blob/master/base64dump.py
DTMF टेलीफोन आवृत्ति: https://unframework.github.io/dtmf-detect/
WPA कुंजियों को डिक्रिप्ट करने के लिए: pyrit -r "capctura.pcap" analyze
Diskeditor: https://www.disk-editor.org/index.html
Passware एन्क्रिप्शन विश्लेषक: https://www.passware.com/encryption-analyzer/
विंडोज़ रजिस्ट्री पुनर्प्राप्ति: https://www.softpedia.com/get/Tweak/Registry-Tweak/Windows-Registry-Recovery.shtml
xxd कमांड
ब्लू टीम चीटशीट: https://itblogr.com/wp-content/uploads/2020/04/The-Concise-Blue-Team-cheat-Sheets.pdf
DFIR चीटशीट: https://www.jaiminton.com/cheatsheet/DFIR/#
यूज़र एजेंट पार्स करें: https://developers.whatismybrowser.com/useragents/parse/
ब्लॉग: https://www.osintme.com/
grep -Po " " के लिए नियमित अभिव्यक्तियाँ https://www.autoregex.xyz/ && https://regex101.com/ . चीटशीट: https://cheatography.com/davechild/cheat-sheets/regular-expressions/
DFIR चीटशीट: https://dfircheatsheet.github.io/
ऑनलाइन डीकंपाइलर एक्सप्लोरर: https://dogbolt.org/
ऑनलाइन कंपाइलर एक्सप्लोरर: https://godbolt.org/
ऑनलाइन .JAR और .Class से Java डीकंपाइलर: http://www.javadecompilers.com/
हेक्स एडिटर, डिस्क एडिटर और मेमोरी एडिटर: https://mh-nexus.de/en/downloads.php?product=HxD20
एंड्रॉइड डीकंपाइलर: https://ibotpeaches.github.io/Apktool/
एंड्रॉइड फ़ाइलें डीकंपाइल करें: https://github.com/skylot/jadx
Hopper डिसअसेंबलर: https://www.hopperapp.com/
डायनामिक निर्भरताएँ सूचीबद्ध करें: Ldd file
कुछ बायनेरिज़ अनपैक करना: Upx -d file
पैकर्स की पहचान करना: https://github.com/horsicq/Detect-It-Easy
सिद्धांत: https://0xinfection.github.io/reversing/
इंटेल® 64 और IA-32 आर्किटेक्चर सॉफ़्टवेयर डेवलपर मैनुअल: https://www.intel.com/content/dam/www/public/us/en/documents/manuals/64-ia-32-architectures-software-developer-instruction-set-reference-manual-325383.pdf
Sublist3r: https://github.com/aboul3la/Sublist3r
समाप्त डोमेन: https://www.expireddomains.net/
स्वचालित XSS उपकरण: https://github.com/ssl/ezXSS
SQL पेलोड उदाहरण: https://github.com/payloadbox/sql-injection-payload-list
कमांड इंजेक्शन: https://github.com/payloadbox/command-injection-payload-list
2021 में XSS: https://netsec.expert/posts/xss-in-2021/
WPscan
XSS फ़ायरफ़ॉक्स एक्सटेंशन खोजक: https://addons.mozilla.org/es/firefox/addon/knoxss-community-edition/
HTTP हेडर का निरीक्षण करें: https://requestbin.net/ && https://webhook.site/#!/75039a57-2015-4f74-9612-b762f4353b9b && https://securityheaders.com/?q=domain&followRedirects=on
RAT डिकोडर: https://github.com/kevthehermit/RATDecoders
Malwoverview: https://github.com/alexandreborges/malwoverview
बाइनरी स्ट्रिंग्स डिफ्यूज़र: https://github.com/fireeye/flare-floss
मैलवेयर का नेटवर्क विश्लेषण (HTTP सर्वर का अनुकरण करें): https://github.com/felixweyne/imaginaryC2
यह उपकरण आपको वैध नेटवर्क सेवाओं का अनुकरण करते हुए सभी या विशिष्ट नेटवर्क ट्रैफ़िक को इंटरसेप्ट और पुनर्निर्देशित करने की अनुमति देता है: https://github.com/mandiant/flare-fakenet-ng
robots.txt को बायपास करते हुए रिकर्सिव फ़ाइल डाउनलोड: wget -e robots=off -drc -l5 domain
[ICMP एक्सफ़िल्ट्रेशन] tshark -r 1pcap_test_1c.pcapng -Y "icmp" -Tjson | grep data.data | awk {'print $2'} | cut -c 2-3 | uniq | xxd -r -p
Google जानकारी:
