Skip to content
KitploitKITPLOIT
ツールブログ
提出
ツールブログ
提出

ハッキング、侵入テスト、サイバーセキュリティツールをあなたのセキュリティアーセナルに!

Kitploitはハッキング、サイバーセキュリティ、ペネトレーションテストのツールディレクトリです。最新のプロジェクトアップデートを見つけて、脆弱性の発見、システム分析、テストの自動化、セキュリティの強化を行いましょう。

··フィード·お問い合わせ·プライバシー·© 2026 Kitploit

ツールディレクトリ

カテゴリ

すべてのカテゴリを見る
Loading categories
Red-Team — Red-Team Attack Guid | Kitploit
ツール/GitHubGitHub/al1ex/red-team
ExploitationInformation GatheringWeb SecurityCTFPenetration TestingLearning & EducationRed TeamingCurated Resources
GitHubal1ex/red-team

Red-Team

Red-Team Attack Guid

リポジトリを見る
280675年前Kitploit レビュー済み

人気

すべて見る →

コミュニティで最も使われているツールを見つけましょう。

すべてのツールを探索

ツールコレクションを閲覧

すべてのツールを見る →
共有

项目简介

项目用于收集和归纳Red Team的以下几个方面

  • Red Team攻击思维

  • Red Team攻击工具

  • Red Team攻击方法

精华内容

  • https://mitre-attack.github.io/ mitre科技机构对攻击技术的总结wiki
  • https://huntingday.github.io MITRE | ATT&CK 中文站
  • https://arxiv.org 康奈尔大学(Cornell University)开放文档
  • http://www.owasp.org.cn/owasp-project/owasp-things OWASP项目
  • http://www.irongeek.com/i.php?page=security/hackingillustrated 国内外安全大会相关视频与文档
  • https://github.com/knownsec/KCon KCon大会文章PPT
  • https://github.com/SecWiki/sec-chart 各种相关安全思维导图集合
  • https://github.com/knownsec/RD_Checklist 知道创宇技能列表
  • https://github.com/ChrisLinn/greyhame-2017 灰袍技能书2017版本
  • https://github.com/Hack-with-Github/Awesome-Hacking GitHub万星推荐:黑客成长技术清单
  • https://github.com/k4m4/movies-for-hackers 安全相关电影
  • https://github.com/jaredthecoder/awesome-vehicle-security 车辆安全和汽车黑客的资源清单
  • https://www.jianshu.com/p/852e0fbe2f4c 安全产品厂商分类
  • https://www.reddit.com/r/Python/comments/a81mg3/the_entire_mit_intro_computer_science_class_using/ 麻省理工机器学习视频
  • https://github.com/fxsjy/jieba py,结巴中文分词
  • https://github.com/thunlp/THULAC-Python py,清华中文分词
  • https://github.com/lancopku/PKUSeg-python py3,北大中文分词
  • https://github.com/fengdu78/Coursera-ML-AndrewNg-Notes 吴恩达机器学习python笔记
  • https://paperswithcode.com/sota 机器学习具体项目、演示、代码
  • https://github.com/duoergun0729/nlp 一本开源的NLP(神经语言程序学)入门书籍
  • https://www.freebuf.com/articles/web/195304.html 一句话木马的套路

攻防测试

系列内容

  • https://micropoor.blogspot.com/2019/01/php8.html PHP安全新闻早8点课程系列高持续渗透--Microporor
  • https://github.com/Micropoor/Micro8 Microporor高级攻防100课
  • https://github.com/maskhed/Papers 包含100课等经典攻防教材、安全知识
  • https://github.com/infosecn1nja/AD-Attack-Defense 红蓝方攻防手册
  • https://github.com/yeyintminthuhtut/Awesome-Red-Teaming 优秀红队资源列表
  • https://github.com/foobarto/redteam-notebook 红队标准渗透测试流程+常用命令
  • https://github.com/tom0li/collection-document 文章收集:安全部、SDL、src、渗透测试、漏洞利用
  • https://github.com/kbandla/APTnotes 各种公开的文件和相关的APT笔记,还有软件样本
  • https://wizardforcel.gitbooks.io/web-hacking-101/content Web Hacking 101 中文版
  • https://techvomit.net/web-application-penetration-testing-notes/ web渗透测试笔记
  • https://github.com/qazbnm456/awesome-web-security Web安全资料和资源列表
  • http://pentestmonkey.net/category/cheat-sheet 渗透测试常见条目
  • https://github.com/demonsec666/Security-Toolkit 渗透攻击链中常用工具及使用场景
  • https://github.com/Kinimiwar/Penetration-Testing 渗透测试方向优秀资源收集
  • https://github.com/jshaw87/Cheatsheets 渗透测试/安全秘籍/笔记

基础安全

  • https://book.yunzhan365.com/umta/rtnp/mobile/index.html 网络安全科普小册子
  • http://sec.cuc.edu.cn/huangwei/textbook/ns/ 网络安全电子版教材。中传信安课程网站
  • https://mitre.github.io/attack-navigator/enterprise/ mitre机构att&ck入侵检测条目
  • https://github.com/danielmiessler/SecLists 表类型包括用户名,密码,URL,敏感数据模式,模糊测试负载,Web shell等
  • https://github.com/GitGuardian/APISecurityBestPractices api接口测试checklist
  • https://github.com/ym2011/SecurityManagement 分享在建设安全管理体系、ISO27001、等级保护、安全评审过程中的点点滴滴
  • https://mp.weixin.qq.com/s/O36e0gl4cs0ErQPsb5L68Q 区块链,以太坊智能合约审计 CheckList
  • https://github.com/slowmist/eos-bp-nodes-security-checklist 区块链,EOS bp nodes security checklist(EOS超级节点安全执行指南)
  • https://xz.aliyun.com/t/2089 金融科技SDL安全设计checklist
  • https://github.com/juliocesarfort/public-pentesting-reports 由几家咨询公司和学术安全组织发布的公共渗透测试报告的列表。
  • http://www.freebuf.com/articles/network/169632.html 开源软件创建SOC的一份清单
  • https://github.com/0xRadi/OWASP-Web-Checklist owasp网站检查条目
  • https://www.securitypaper.org/ SDL开发安全生命周期管理
  • https://github.com/Jsitech/JShielder linux下服务器一键加固脚本
  • https://github.com/wstart/DB_BaseLine 数据库基线检查工具

学习手册

  • https://github.com/HarmJ0y/CheatSheets 多个项目的速查手册(Beacon / Cobalt Strike,PowerView,PowerUp,Empire和PowerSploit)
  • https://wizardforcel.gitbooks.io/kali-linux-web-pentest-cookbook/content/ Kali Linux Web渗透测试秘籍 中文版
  • https://github.com/louchaooo/kali-tools-zh kali下工具使用介绍手册
  • https://www.offensive-security.com/metasploit-unleashed/ kali出的metasploit指导笔记
  • http://www.hackingarticles.in/comprehensive-guide-on-hydra-a-brute-forcing-tool/ hydra使用手册
  • https://www.gitbook.com/book/t0data/burpsuite/details burpsuite实战指南
  • https://zhuanlan.zhihu.com/p/26618074 Nmap扩展脚本使用方法
  • https://somdev.me/21-things-xss/ XSS的21个扩展用途
  • https://www.netsparker.com/blog/web-security/sql-injection-cheat-sheet/ sql注入sheet表
  • https://sqlwiki.netspi.com/ 你要的sql注入知识点都能找到
  • https://github.com/kevins1022/SQLInjectionWiki 一个专注于聚合和记录各种SQL注入方法的wiki
  • https://github.com/hardenedlinux/linux-exploit-development-tutorial Linux exploit 开发入门
  • https://wizardforcel.gitbooks.io/asani/content 浅入浅出Android安全 中文版
  • https://wizardforcel.gitbooks.io/lpad/content Android 渗透测试学习手册 中文版
  • https://github.com/writeups/ios ios漏洞writeup笔记
  • http://blog.safebuff.com/2016/07/03/SSRF-Tips/ ssrf漏洞利用手册

学习靶场

  • https://www.blackmoreops.com/2018/11/06/124-legal-hacking-websites-to-practice-and-learn/ 124个合法的可以练习Hacking技术的网站
  • https://www.zhihu.com/question/267204109 学web安全去哪里找各种各样的靶场?
  • https://www.vulnhub.com 许多ctf靶机汇总
  • https://www.wechall.net 世界知名ctf汇总交流网站
  • https://www.xssgame.com 谷歌XSS挑战
  • http://xss.tv 在线靶场挑战
  • https://www.hackthebox.eu 在线靶场挑战
  • https://www.root-me.org 在线靶场挑战
  • http://www.itsecgames.com bWAPP,包含 100多种漏洞环境
  • https://github.com/c0ny1/vulstudy 多种漏洞复现系统的docker汇总
  • https://github.com/bkimminich/juice-shop 常见web安全实验靶场市场
  • https://github.com/ethicalhack3r/DVWA web安全实验靶场
  • https://www.freebuf.com/articles/web/123779.html 新手指南:DVWA-1.9全级别教程
  • https://github.com/78778443/permeate php,常见漏洞靶场
  • https://github.com/gh0stkey/DoraBox php,常见漏洞靶场
  • https://github.com/stamparm/DSVW py2,常见漏洞靶场
  • https://github.com/amolnaik4/bodhi py,常见漏洞靶场
  • https://github.com/Safflower/Solve-Me php,韩国一个偏代码审计的ctf靶场源码
  • https://github.com/WebGoat/WebGoat 一键jar包,web安全实验靶场
  • https://github.com/Audi-1/sqli-labs 基于SQLite的sql注入学习靶场

信息收集

  • https://github.com/smicallef/spiderfoot 利用OSINT自动化找出对方信息,gui界面,插件化
  • https://github.com/Nhoya/gOSINT go,利用OSINT自动化搜集信息
  • https://github.com/laramies/theHarvester 企业被搜索引擎收录敏感资产信息监控脚本:员工邮箱、子域名、Hosts
  • https://github.com/guelfoweb/knock 通过爆破进行子域名获取,可用于查找子域名接管漏洞
  • https://github.com/aboul3la/Sublist3r 通过搜索引擎与爆破快速子域枚举工具
  • https://github.com/Ice3man543/subfinder 基于go实现的Sublist3r
  • https://github.com/yanxiu0614/subdomain3 py3、py2的子域名,IP,CDN信息等
  • https://github.com/caffix/amass 基于go,子域名枚举, 搜索互联网数据源, 使用机器学习猜测子域名
  • https://github.com/nahamsec/lazyrecon 侦查reconnaissance过程自动化脚本, 可自动使用Sublist3r/certspotter获取子域名, 调用nmap/dirsearch等
  • https://github.com/s0md3v/ReconDog simple,侦查信息的瑞士军刀
  • https://github.com/FeeiCN/ESD py3,爆破搜集子域名
  • https://github.com/alpha1e0/pentestdb 多用途集成化信息搜集工具
  • https://github.com/se55i0n/PortScanner py2,目标tcp端口快速扫描、banner识别、cdn检测
  • https://github.com/lijiejie/subDomainsBrute lijiejie开发的一款使用广泛的子域名爆破枚举工具
  • https://github.com/ring04h/wydomain 猪猪侠开发的一款域名收集全面、精准的子域名枚举工具
  • https://github.com/n4xh4ck5/N4xD0rk 利用搜索引擎来搜集子域名,可以使用西班牙语搜集
  • https://github.com/vysec/DomLink py2,调用WHOXY.com,对邮箱和域名进行进一步的搜集
  • https://github.com/jonluca/Anubis py3.6,子域名爆破与信息搜集

信息泄露

  • https://github.com/Yelp/detect-secrets PY,防止代码中的密码等相关敏感信息被提交到代码库中,可以在保证安全性的同时不会给开发者的生产力带来任何影响
  • https://github.com/Acceis/leakScraper 处理和可视化大规模文本文件, 查找敏感信息, 例如证书
  • https://github.com/Raikia/CredNinja 多线程用户凭证验证脚本,比如验证dump的hash是否属于此机器,利用445端口进行协议验证
  • https://github.com/CERTCC/keyfinder 查找并分析私钥/公钥文件(文件系统中), 支持 Android APK 文件
  • https://github.com/Ice3man543/hawkeye go,cli端,文件系统分析工具,快速查找文件内包含的SSH密钥,日志文件,Sqlite数据库,密码文件等
  • https://github.com/FortyNorthSecurity/EyeWitness 获取目标网站截图、vnc、rdp服务,尝试获取默认凭证
  • https://github.com/D4Vinci/Cr3dOv3r 根据邮箱自动搜索泄漏的密码信息,也可测试账户密码在各大网站能否登录的工具

路径发现

  • https://github.com/maurosoria/dirsearch 经典目录路径扫描
  • https://github.com/TheM4hd1/PenCrawLer C#界面,web爬虫与目录路径爆破工具,除了常规扫描增加了递归爆破模式
  • https://github.com/Xyntax/DirBrute 目录路径爆破工具
  • https://github.com/abaykan/crawlbox 目录路径路径扫描器
  • https://github.com/deibit/cansina 目录路径路径扫描器
  • https://github.com/UltimateHackers/Breacher 多线程的后台路径扫描器,也可用于发现Execution After Redirect漏洞
  • https://github.com/fnk0c/cangibrina 通过字典穷举、google、robots.txt等途径的跨平台后台管理路径扫描器
  • https://github.com/Go0s/SitePathScan 基于协程的目录路径爆破工具,配合aiohttp扫描路径比之前快了三倍有余
  • https://github.com/secfree/bcrpscan 基于爬虫的web路径扫描器

指纹|端口

  • https://github.com/nmap/nmap LUA,Nmap端口扫描器,具有有强大的脚本引擎框架
  • https://github.com/robertdavidgraham/masscan C,无状态扫描,可以调用nmap进行指纹识别
  • https://github.com/zmap/zmap C,无状态扫描,需要用C编写扩展模块
  • https://github.com/zmap/zgrab go,基于zmap扫描器进行指纹识别、调度管理,可绕过CDN
  • https://github.com/chichou/grab.js 类似 zgrab 的快速 TCP 指纹抓取解析工具,支持更多协议
  • https://github.com/johnnyxmas/scancannon shell,联动masscan和nmap
  • https://github.com/OffensivePython/Nscan 基于Masscan和Zmap的网络扫描器
  • https://github.com/ring04h/wyportmap 调用nmap目标端口扫描+系统服务指纹识别
  • https://github.com/angryip/ipscan Angry IP Scanner,跨平台界面化端口扫描器
  • https://github.com/EnableSecurity/wafw00f WAF产品指纹识别
  • https://github.com/rbsec/sslscan ssl类型识别
  • https://github.com/urbanadventurer/whatweb web指纹识别
  • https://github.com/Rvn0xsy/FastWhatWebSearch whatweb工具结果搜索平台
  • https://github.com/tanjiti/FingerPrint web应用指纹识别
  • https://github.com/nanshihui/Scan-T 网络爬虫式指纹识别
  • https://github.com/ywolf/F-MiddlewareScan 中间件扫描服务识别
  • https://github.com/lietdai/doom thorn上实现的分布式任务分发的ip端口漏洞扫描器
  • https://github.com/RASSec/RASscan 端口服务扫描
  • https://github.com/m3liot/shcheck 用于检查web服务的http header的安全性

文件包含

  • https://github.com/hvqzao/liffy 本地文件包含漏洞利用工具
  • https://github.com/D35m0nd142/Kadabra 本地文件包含漏洞扫描和利用工具
  • https://github.com/P0cL4bs/Kadimus 本地文件包含漏洞扫描和利用工具
  • https://github.com/D35m0nd142/LFISuite 本地文件包含漏洞利用及扫描工具,支持反弹shell
  • https://github.com/OsandaMalith/LFiFreak 本地文件包含漏洞利用及扫描工具,支持反弹shell

上传漏洞

  • https://github.com/UltimateHackers/Arjun 扫描网页, 使用正则表达式爆破查找隐藏的GET/POST参数
  • https://github.com/3xp10it/xupload 用于自动测试上传功能是否可上传webshell的工具
  • https://github.com/gunnerstahl/JQShell py3,CVE-2018-9206 jQuery File Upload利用工具
  • https://github.com/destine21/ZIPFileRaider burp插件,测试zip文件上传漏洞
  • https://github.com/jpiechowka/zip-shotgun py,测试zip文件上传漏洞

XSS利用

  • https://github.com/UltimateHackers/AwesomeXSS XSS Awesome系列
  • http://www.xss-payloads.com 很全面的xss工具包与资料
  • https://github.com/ismailtasdelen/xss-payload-list XSS 漏洞Payload列表
  • https://github.com/beefproject/beef 经典的xss利用框架
  • https://github.com/samdenty99/injectify 类似beef的xss利用框架
  • https://github.com/firesunCN/BlueLotus_XSSReceiver 蓝莲花战队为CTF打造的xss利用框架
  • https://github.com/NytroRST/XSSFuzzer 根据特定标签生成xss payload
  • https://github.com/evilcos/xssor2 余弦写的xss利用辅助工具
  • https://github.com/UltimateHackers/XSStrike 可识别并绕过WAF的XSS扫描工具
  • https://github.com/raz-varren/xsshell go,利用xss漏洞返回一个js交互shell
  • https://github.com/UltimateHackers/JShell 利用xss漏洞返回一个js交互shell
  • https://github.com/shawarkhanethicalhacker/BruteXSS 一款XSS扫描器,可暴力注入参数
  • https://github.com/1N3/XSSTracer 小型XSS扫描器,也可检测CRLF、XSS、点击劫持的
  • https://github.com/0x584A/fuzzXssPHP PHP版本的反射型xss扫描
  • https://github.com/chuhades/xss_scan 批量扫描XSS的python脚本
  • https://github.com/BlackHole1/autoFindXssAndCsrf 自动化检测页面是否存在XSS和CSRF漏洞的浏览器插件
  • https://github.com/shogunlab/shuriken 使用命令行进行XSS批量检测
  • https://github.com/stamparm/DSXS 支持GET、POST方式的高效XSS扫描器
  • kali下无法使用的话,请下载正确的PhantomJS到目录thirdparty/phantomjs/Linux

口令爆破

  • https://github.com/vanhauser-thc/thc-hydra 支持多种协议方式的破解与爆破,v8以后就不提供windows版本了
  • https://github.com/nmap/ncrack c,支持多种协议的破解与爆破
  • https://github.com/0pn1i9ht/F-Scrack ysrc对各类服务用户名密码爆破的脚本
  • https://github.com/TunisianEagles/SocialBox 针对fb、gmail、ins、twitter的用户名密码爆破的脚本
  • https://github.com/lanjelot/patator 支持多种协议的爆破,采用模块化设计,使用灵活
  • https://github.com/m4ll0k/SMBrute 利用smb服务进行用户名密码爆破
  • https://github.com/netxfly/crack_ssh Go写的协程版的ssh\redis\mongodb弱口令破解
  • https://github.com/UltimateHackers/Blazy 支持测试 CSRF, Clickjacking, Cloudflare and WAF的弱口令探测器
  • https://github.com/Moham3dRiahi/XBruteForcer WordPress、Joomla、DruPal、OpenCart、Magento等CMS用户密码爆破
  • https://github.com/shengqi158/weak_password_detect Linux下利用nmap多线程探测ssh弱口令
  • https://github.com/ztgrace/changeme 弱口令扫描器,不仅支持普通登录页,也支持ssh、mongodb等组件
  • https://github.com/lijiejie/htpwdScan simple,http暴力破解、撞库攻击脚本
  • https://github.com/scu-igroup/ssh-scanner 联动nmap、hydra对ssh批量爆破

密码破解

  • https://securityxploded.com/download.php 各种密码方向安全小工具
  • https://github.com/bdutro/ibm_pw_clear IBM x3550/x3560 M3 bios密码清除重置工具
  • https://github.com/thehappydinoa/iOSRestrictionBruteForce py,实现的 ios 访问限制密码破解工具
  • https://github.com/hashcat/hashcat C,哈希破解
  • https://github.com/fireeye/gocrack GO,基于hashcat 3.6.0+的分布式密码破解工具
  • https://github.com/s3inlc/hashtopolis 基于php的hashcat的分布式破解工具,支持C#与python客户端
  • https://github.com/e-ago/bitcracker 首款开源的BitLocker密码破解工具
  • https://www.ru.nl/publish/pages/909282/draft-paper.pdf 破解SSD下使用BitLocker的论文
  • https://github.com/magnumripper/JohnTheRipper 已知密文的情况下尝试破解出明文的破解密码软件
  • https://github.com/shinnok/johnny JohnTheRipper密码破解的GUI界面,理论兼容所有功能,有windows界面
  • https://github.com/jmk-foofus/medusa 支持的协议会比hydra少一点,但是某些速度会快
  • https://github.com/MrSqar-Ye/wpCrack wordpress hash破解
  • https://github.com/testsecer/Md5Decrypt C#,基于网上web API的MD5搜索工具
  • https://github.com/s0md3v/Hash-Buster 能调用多个API进行hash破解查询的智能工具
  • https://www.52pojie.cn/thread-275945-1-1.html ARCHPR Pro4.54绿色中文破解版。压缩包密码破解,利用“已知明文攻击”破解加密的压缩文件

DB安全

  • https://github.com/ron190/jsql-injection Java 编写的SQL注入工具
  • https://github.com/shack2/SuperSQLInjectionV1 安恒航牛的一款界面化注入工具
  • https://github.com/sqlmapproject/sqlmap sql注入sqlmap
  • https://github.com/stamparm/DSSS 已用1,99行代码实现的sql注入漏洞扫描器
  • https://github.com/Hadesy2k/sqliv 已用1,基于搜索引擎的批量SQL注入漏洞扫描器
  • https://github.com/quentinhardy/odat 一款专门用于Oracle渗透的很全面的工具
  • https://github.com/m8r0wn/enumdb MySQL和MSSQL利用工具后期爆破、搜索数据库并提取敏感信息。
  • https://github.com/LoRexxar/Feigong 针对各种情况自由变化的MySQL注入脚本
  • https://github.com/youngyangyang04/NoSQLAttack 一款针对mongoDB的攻击工具
  • https://github.com/Neohapsis/bbqsql SQL盲注利用框架
  • https://github.com/NetSPI/PowerUpSQL 基于Powershell的sqlserver测试框架
  • http://www.4hou.com/system/14950.html 利用PowerUpSQL,渗透测试技巧:绕过SQL Server登录触发器限制
  • https://github.com/WhitewidowScanner/whitewidow 一款数据库扫描器
  • https://github.com/stampery/mongoaudit MongoDB审计及渗透工具
  • https://github.com/torque59/Nosql-Exploitation-Framework NoSQL扫描/爆破工具
  • https://github.com/missDronio/blindy MySQL盲注爆破工具
  • https://github.com/JohnTroony/Blisqy 用于http header中的时间盲注爆破工具,仅针对MySQL/MariaDB
  • https://github.com/se55i0n/DBScanner 自动扫描内网中常见sql、no-sql数据库脚本,包含未授权访问及常规弱口令检测

代码审计- https://www.waitalone.cn/seay-source-code-auditv2.html Seayソースコード監査システム2.1版

  • https://github.com/pyupio/safety インストール済みのすべてのPythonパッケージをチェックし、既知のセキュリティ脆弱性を検出する
  • https://github.com/pumasecurity/puma-scan リアルタイムコード監査、VSプラグイン
  • https://github.com/wufeifei/cobra ホワイトボックスコードセキュリティ監査システム
  • https://github.com/OneSourceCat/phpvulhunter 静的PHPコード監査
  • https://github.com/ripsscanner/rips PHPベースのPHPコード監査ツール
  • https://github.com/Qihoo360/phptrace PHPの実行状況を追跡・分析するツール
  • https://github.com/ajinabraham/NodeJsScan Node.JSアプリケーションのコード監査
  • https://github.com/ctxis/beemka Electronアプリ向けの脆弱性悪用ツールキット
  • https://github.com/doyensec/electronegativity Electronアプリのコード監査、アプリの設定ミスとセキュリティ問題
  • https://github.com/shengqi158/pyvulhunter Pythonアプリケーション監査
  • https://github.com/securego/gosec Go言語のソースコードセキュリティ解析ツール
  • https://github.com/GoSSIP-SJTU/TripleDoggy clangベースのC/C++/Objective-Cソースコード検出フレームワーク。多数のインターフェースを呼び出し可能
  • https://github.com/ga0/pyprotect Pythonコードを暗号化してリバースエンジニアリングを防止
  • https://github.com/presidentbeef/brakeman Ruby on Railsアプリの静的コード解析
  • https://github.com/python-security/pyt Python Webアプリケーションのセキュリティ脆弱性を検出するための静的解析ツール
  • https://github.com/m4ll0k/WPSploit Wordpressプラグインのコードセキュリティ監査
  • https://github.com/elcodigok/wphardening あらゆるWordPressインストールのセキュリティを強化

ビッグデータセキュリティ

  • https://github.com/shouc/BDA hadoop/spark/mysqlなどのビッグデータプラットフォーム向けの監査と検出
  • https://github.com/wavestone-cdt/hadoop-attack-library hadoopのテスト手法とツールセット

脆弱性再現

  • https://github.com/vulhub/vulhub Vulhubは一般向けのオープンソース脆弱性演習場。dockerの知識は不要で、2つのコマンドを実行するだけで完全な脆弱性演習場イメージをコンパイル・実行できる

  • https://github.com/Medicean/VulApps さまざまな脆弱性環境を収集。使いやすさのため、統一してDockerfile形式を採用。セキュリティツールの環境も収集している。

  • https://github.com/bingohuang/docker-labs オンラインdockerプラットフォームの制作

脆弱性検索

  • https://wooyun.kieran.top/#!/ 2016年以前の乌云(WooYun)Drops記事、公開された脆弱性詳細記事
  • https://wooyun.js.org/ 2016年以前の乌云(WooYun)Drops記事、公開された脆弱性詳細記事
  • https://dvpnet.io/list/index/state/3 公開された脆弱性詳細記事
  • https://sec.ly.com/bugs 同程安全の公開脆弱性詳細記事
  • http://ics.cnvd.org.cn 中国国家産業制御脆弱性データベース
  • https://ics-cert.us-cert.gov/advisories 米国国家産業制御脆弱性データベース
  • http://www.nsfocus.net/index.php?act=sec_bug 绿盟(NSFOCUS)脆弱性データベース、産業制御(ICS)含む
  • http://ivd.winicssec.com/ 威努特(WINICSSEC)産業制御脆弱性データベース
  • http://cve.scap.org.cn/view/ics CVE中国語産業制御脆弱性データベース
  • https://cve.mitre.org/cve/search_cve_list.html 米国MITRE社が維持管理するCVE脆弱性データベース
  • https://www.exploit-db.com 米国Offensive Securityの脆弱性データベース
  • https://nvd.nist.gov/vuln/search 米国国家情報セキュリティ脆弱性データベース

EXP&POC

  • https://github.com/Lcys/Python_PoC python3向けのpoc・expを素早く作成するテンプレート。多数の模範バージョンあり
  • https://github.com/raminfp/linux_exploit_development Linuxエクスプロイト開発マニュアル
  • https://github.com/mudongliang/LinuxFlaw Linux上のソフトウェア脆弱性リストを含む
  • https://github.com/coffeehb/Some-PoC-oR-ExP さまざまな脆弱性poc・Expの収集または作成
  • https://github.com/userlandkernel/plataoplomo Sem Voigtländerが発見したiOSのさまざまな脆弱性を公開(Writeup/POC/Exploitを含む)
  • https://github.com/coffeehb/Some-PoC-oR-ExP/blob/master/check_icmp_dos.py CVE-2018-4407、macOS/iOSのバッファオーバーフローによりシステムがクラッシュする可能性
  • https://github.com/vulnersCom/getsploit py2、searchsploitを模倣し、各種データベースの公式APIを通じてペイロードを検索
  • https://github.com/SecWiki/CMS-Hunter CMS脆弱性テストケース集
  • https://github.com/Mr5m1th/0day さまざまなオープンソースCMSの各バージョンの脆弱性とEXP
  • https://github.com/Al1ex/Heptagram 各種オープンソースCMS、Windows、Linux、アプリ、EmailなどのEXPを収集・整理
  • https://github.com/w1109790800/penetration CMS新旧バージョンのEXPとシステム脆弱性の収集表
  • https://github.com/blacknbunny/libSSH-Authentication-Bypass CVE-2018-10933、libsshサーバー側の認証バイパス
  • https://github.com/leapsecurity/libssh-scanner CVE-2018-10933、libsshサーバー側の認証バイパス
  • https://github.com/anbai-inc/CVE-2018-4878 Adobe Flash Exploitでペイロードを生成
  • https://github.com/RetireJS/grunt-retire JS拡張ライブラリの一般的な脆弱性をスキャン
  • https://github.com/coffeehb/SSTIF サーバーサイドテンプレートインジェクション脆弱性の半自動化ツール

JAVA脆弱性

  • https://github.com/brianwrf/hackUtils Javaデシリアライゼーションの悪用
  • https://github.com/GoSecure/break-fast-serial DNS解決を利用してJavaデシリアライゼーション脆弱性を検出するツール
  • https://github.com/s1kr10s/Apache-Struts-v3 Apache-Struts脆弱性悪用ツール
  • https://github.com/iBearcat/S2-057 struts2 CVE-2018-11776脆弱性検出ツール
  • https://github.com/Ivan1ee/struts2-057-exp struts2-057悪用スクリプト
  • https://github.com/theLSA/s2sniper struts2の脆弱性を検出するツール
  • https://github.com/Lucifer1993/struts-scan strutsのコマンド実行脆弱性を一括検出
  • https://github.com/lijiejie/struts2_045_scan Struts2-045脆弱性の一括スキャンツール
  • https://github.com/riusksk/StrutScan perlベースのstrut2の過去の脆弱性スキャン
  • https://github.com/Coalfire-Research/java-deserialization-exploits Javaデシリアライゼーション脆弱性の収集
  • https://github.com/quentinhardy/jndiat weblogic脆弱性悪用ツール
  • https://github.com/jas502n/CVE-2018-3191 Weblogic CVE-2018-3191リモートコードコマンド実行
  • https://github.com/pyn3rd/CVE-2018-3245 weblogic cve-2018-2893とcve-2018-3245のリモートコードコマンド実行
  • https://github.com/NickstaDB/BaRMIe Java Remote Method Invocationサービス用のツール / RMIの列挙とリモートコマンド実行
  • https://github.com/joaomatosf/jexboss JBossおよびその他のJavaシリアライゼーション脆弱性の検証・悪用ツール
  • https://github.com/frohoff/ysoserial Javaデシリアライゼーション悪用ツール

Office脆弱性

  • https://github.com/Lz1y/CVE-2017-8759 .NET Frameworkの改行文字の脆弱性、CVE-2017-8759の完全再現(別途、hta+powershellのポップアップちらつき解決策も添付)https://www.freebuf.com/vuls/147793.html
  • https://github.com/WyAtu/CVE-2018-8581 Exchangeの受信ルール追加操作を利用して横方向への侵入と権限昇格を行う脆弱性
  • https://github.com/dafthack/MailSniper PS、Microsoft Exchange環境で電子メールを検索し、特定のメール(パスワード、ネットワーク構成情報など)を探すために使用
  • https://github.com/sensepost/ruler GO、MAPI / HTTPまたはRPC / HTTPプロトコルを介してExchangeサーバーとリモートで対話し、Outlookクライアント機能を通じてリモートでシェルを取得
  • https://github.com/3gstudent/Smbtouch-Scanner イントラネットの永恒之蓝(EternalBlue)ETERNAL445SMBシリーズ脆弱性をスキャン
  • https://github.com/smgorelik/Windows-RCE-exploits Windowsコマンド実行RCE脆弱性のPOCサンプル。Webとファイルの2つの形式に分類
  • https://github.com/3gstudent/CVE-2017-8464-EXP CVE-2017-8464、Windowsショートカットのリモート実行脆弱性
  • https://github.com/Lz1y/CVE-2018-8420 Windowsのmsxmlパーサーの脆弱性。IEまたはVBSを通じてバックドアを実行可能
  • https://www.anquanke.com/post/id/163000 Excel 4.0マクロを利用してアンチウイルス検知を回避する攻撃技術の分析
  • https://github.com/BuffaloWill/oxml_xxe XXE脆弱性の悪用
  • https://thief.one/2017/06/20/1/ XXE脆弱性の攻撃と防御についての簡単な解説
  • https://github.com/thom-s/docx-embeddedhtml-injection Word2016、Wordオンラインビデオ機能を悪用して悪意のあるコードを実行するPoC
  • https://blog.cymulate.com/abusing-microsoft-office-online-video Word2016、Wordオンラインビデオ機能を悪用して悪意のあるコードを実行する手順の紹介
  • https://github.com/0xdeadbeefJERKY/Office-DDE-Payloads マクロを有効にしなくてもWord文書でDDEを利用してコマンドを実行
  • http://www.freebuf.com/articles/terminal/150285.html マクロを有効にしなくてもWord文書でDDEを利用してコマンドを実行する悪用手法

その他の脆弱性

  • https://github.com/shengqi158/svnhack .svnフォルダ漏えい悪用ツール
  • https://www.waitalone.cn/seay-svn-poc-donw-20140505.html Seay-Svnソースコード漏えい脆弱性悪用ツール、2014-05-05版
  • https://github.com/BugScanTeam/GitHack .gitファイル悪用ツール、lijiejie改良版
  • https://github.com/lijiejie/GitHack .gitファイル悪用ツール

Shell管理

  • http://www.bt.cn 宝塔(BaoTa)Webサイト管理システム
  • https://github.com/AntSwordProject/antSword js、中国蚁剑(AntSword)、プラグイン式開発
  • https://github.com/Chora10/Cknife java、中国菜刀(China Chopper)
  • https://github.com/naozibuhao/SecQuanCknife java、中国菜刀(China Chopper)のアップグレード版。ブルートフォース機能を追加
  • https://github.com/euphrat1ca/hatchet 中国大砍刀(China Hatchet)
  • https://github.com/tengzhangchao/PyCmd py、一句话木马(ワンライナーWebShell)クライアントプログラム。現在はphp・jspに対応、C/S間通信は暗号化
  • https://github.com/epinna/weevely3 py、特定の一句话脚本(ワンライナースクリプト)を利用してWebサイトを管理
  • https://github.com/nil0x42/phpsploit py3、特定の一句话脚本(ワンライナースクリプト)を利用してWebサイトを管理
  • https://github.com/wonderqs/Blade py、特定の一句话脚本(ワンライナースクリプト)を利用してWebサイトを管理
  • https://github.com/anestisb/WeBaCoo perl、特定の一句话脚本(ワンライナースクリプト)を利用してWebサイトを管理
  • https://github.com/keepwn/Altman .netとmonoを組み合わせて実装されたクロスプラットフォームの菜刀(China Chopper)
  • https://github.com/k4mpr3t/b4tm4n 偽造メールDDoSを統合、bat.phpのWebShell。初期版はk4mpr3t
  • https://github.com/dotcppfile/DAws ファイアウォールを回避するWebShell。post pass=DAws
  • https://github.com/b374k/b374k phpによるWebサイト管理、デフォルトパスワードはb374k
  • https://github.com/wso-shell/WSO ファイル管理機能付きWebShell。404ページに偽装可能
  • https://github.com/UltimateHackers/nano php小马(小型WebShell)、py製ジェネレーター付き
  • https://github.com/rebeyond/memShell Java Webサーバーのメモリに書き込むことができるWebShell
  • https://github.com/DXkite/freebuf-stream-shell PHPのストリームラッパーを使用してWebShellを実装。freebufに詳細な記事あり

脅威インテリジェンス

  • https://www.databases.today,https://publicdbhost.dmca.gripe/,http://www.wttech.org/,https://hashes.org/leaks.php,https://archive.org/search.php?query= パスワード漏えい
  • https://www.threatcrowd.org/ 脅威インテリジェンス分析プラットフォーム
  • https://x.threatbook.cn/ 微步在线(ThreatBook) | 脅威インテリジェンス分析プラットフォーム-ThreatBook-マルチエンジンオンラインスキャン、マルウェアのオンライン検出
  • https://github.com/needmorecowbell/sniff-paste Pastebin向けのオープンソースインテリジェンス(OSINT)収集ツール
  • https://talosintelligence.com/documents/ip-blacklist 悪意のあるIPアドレス
  • https://ransomwaretracker.abuse.ch/downloads/RW_IPBL.txt マルウェアのIPアドレス
  • https://check.torproject.org/cgi-bin/TorBulkExitList.py?ip=1.1.1.1 Tor(オニオンルーター)出口ノード
  • https://isc.sans.edu/api/threatlist/shodan shodanスキャナーノード
  • https://github.com/Te-k/harpoon オープンソースインテリジェンスと脅威インテリジェンスのためのCLIツール
  • https://trumail.io/ 相手のメールアドレスが使い捨てメールかどうかを検証。毎月1000回まで無料で検証可能
  • https://github.com/ChrisJohnRiley/Scythe アカウントが一般的な常用アカウントかどうかを検証
  • https://github.com/fireeye/GeoLogonalyzer リモート認証の地理位置情報分析ツール。正当なログインと悪意のあるログインを区別するために使用。
  • https://github.com/target/strelka py3、ファイルのリアルタイムスキャンによる脅威インテリジェンス分析とリアルタイム監視。

セキュリティツール

ツール集

  • http://www.4hou.com/web/11241.html 史上最も網羅的な攻撃シミュレーションツールの総まとめ
  • https://github.com/infosecn1nja/Red-Teaming-Toolkit 情報収集、攻撃による権限獲得の試行、永続性の確保、権限昇格、ネットワーク情報収集、横方向の移動(ラテラルムーブメント)、データ分析(その上でさらに永続性の確保を行う)、痕跡の除去
  • https://github.com/toolswatch/blackhat-arsenal-tools Black Hatカンファレンスのツール集
  • https://www.cnblogs.com/k8gege K8哥哥のツールパック集。解凍パスワードはKk8team、Kk8gege
  • https://github.com/n00py/ReadingList/blob/master/gunsafe.txt セキュリティツール集
  • https://github.com/Ridter/Pentest セキュリティツール集
  • https://github.com/redcanaryco/atomic-red-team win、linux、macなど多岐にわたるAPT悪用手段、技術、ツール集
  • https://github.com/Cooolis/Cooolis.github.io Cooolisはオペレーティングシステムのコマンドテクニックのメモ帳(チートシート)、https://cooolis.payloads.online
  • https://github.com/LOLBAS-Project/LOLBAS ペネトレーションテストでよく利用されるスクリプトとバイナリファイルの集合
  • https://www.owasp.org/index.php/File:CSRFTester-1.0.zip csrf検証ツール
  • https://github.com/ufrisk/MemProcFS ファイルシステムにアクセスするように物理メモリへアクセス可能。読み書き可、使いやすいインターフェースを搭載。現在はWindowsに対応
  • https://github.com/vletoux/SpoolerScanner Windowsのリモートプリンタサービスが有効かどうかを検出するツール
  • https://github.com/sirpsycho/firecall Cisco ASAファイアウォールに直接コマンドを送信。ログインして設定変更する必要はない
  • https://github.com/jboss-javassist/javassist バイトコードを操作できるフレームワーク。これによりclassコードファイルを簡単に改変できる
  • https://github.com/ConsenSys/mythril-classic イーサリアムのスマートコントラクトのセキュリティ解析ツール
  • https://github.com/a13xp0p0v/kconfig-hardened-check Linuxカーネル設定におけるセキュリティ強化オプションをチェックするスクリプト

その他のツール

  • https://github.com/zaproxy/zaproxy The OWASP ZAP core projectが開発した総合的なペネトレーションテストツール。トラフィックプロキシ、リクエストリプレイ、拡張性に優れているため、ファジングにも十分使用できる
  • https://github.com/x-Ai/BurpUnlimitedre burpsuite 1.7.27の永久クラック版
  • https://github.com/andresriancho/w3af 有名なプラグイン型スキャナー
  • https://github.com/juansacco/exploitpack ペネトレーションテスト統合フレームワーク。38,000以上のエクスプロイトを含む
  • https://github.com/Lucifer1993/AngelSword Webアプリケーション脆弱性スキャンフレームワーク、python3、300 poc
  • https://github.com/Xyntax/POC-T ペネトレーションテスト用プラグイン型スキャンフレームワーク。PoC内蔵、並行スキャン対応
  • https://github.com/knownsec/Pocsuite 知道创宇(Knownsec)がメンテナンスする標準化されたPOC/EXP利用フレームワーク
  • https://github.com/leisurelicht/Pocsuite3 Pocsuiteをpy3で書き直したもの
  • https://github.com/Eitenne/roxysploit エクスプロイトフレームワーク。永恒之蓝(EternalBlue)の直接悪用に対応
  • https://github.com/TophantTechnology/osprey 斗象(Tophant)能力センターが開発し、長期にわたりメンテナンスしている標準化されたPOC/EXP利用フレームワーク
  • https://github.com/he1m4n6a/btScan 大黑阔のプラグイン型脆弱性悪用ツール
  • https://github.com/boy-hack/w9scan python製。1200以上のプラグインを内蔵し、Webサイトに対する大規模な一斉検出が可能
  • https://github.com/WooYun/TangScan 乌云(WooYun)がメンテナンスする標準化されたPOC/EXP利用フレームワーク
  • https://github.com/n0tr00t/Beebeeto-framework Beebeetoは多数のセキュリティ研究者が共同でメンテナンスする標準化されたPOC/EXP利用フレームワーク
  • https://github.com/erevus-cn/pocscan オープンソースのPoC呼び出しフレームワーク。Pocsuite、Tangscan、Beebeeto、Knowsec旧バージョンのPOCを簡単に呼び出せる。dockerでデプロイ可能
  • https://github.com/DavexPro/PocHunter pocscanを参考にした、複数のエクスプロイトフレームワークに対応するPoC適応フレームワーク

よく使うプラグイン

蚁剑(AntSword)
  • https://github.com/AntSword-Store/ 中国蚁剑(AntSword)プラグインマーケット
kali linux
  • https://github.com/secforce/sparta py、Nmap、Nikto、Hydraなどのツールと連携するGUIアプリケーション
  • https://github.com/Manisso/fsociety linux上でkaliに類似したツールパックをワンクリックインストールするツール
  • https://github.com/LionSec/katoolin linuxサーバーを使用してkaliツールパックを自動インストール
  • https://github.com/skavngr/rapidscan py2、シンプル。kaliのツールと連携する脆弱性スキャンツール
  • https://github.com/koenbuyens/kalirouter kaliをルーティングトラフィック解析システムとして設定
Nessus
  • https://www.tenable.com/downloads/nessus
  • https://github.com/se55i0n/Awvs_Nessus_Scanner_API スキャナーAwvs 11とNessus 7のAPI利用スクリプト
  • https://github.com/DanMcInerney/msf-autoshell nessusのスキャン結果に合わせてmsf攻撃を実行
  • https://github.com/MooseDojo/apt2 nmap、nessusなどのツールと連携してセキュリティテストを実施
AWVS
  • https://www.52pojie.cn/thread-214819-1-1.html awvs10.5開発フレームワークのクラック版
  • https://github.com/fnmsd/awvs_script_decode awvs10.5のルールscripts復号版、SDK、開発マニュアル
  • https://github.com/NS-Sp4ce/AWVS11.X-Chinese-Version awvs11中国語化パック
burpsuite
  • https://github.com/PortSwigger burpsuite公式プラグインライブラリ
  • https://github.com/snoopysecurity/awesome-burp-extensions awesomeシリーズのburp拡張
  • https://github.com/d3vilbug/HackBar hackbarを統合
  • https://github.com/PortSwigger/turbo-intruder Burp標準搭載のIntruderより高速。1分間に1.61万回のリクエストを送信できる
  • https://github.com/Ebryx/AES-Killer burpプラグイン。AES暗号を解読するプラグイン
  • https://github.com/bugcrowd/HUNT burpsuiteスキャナーの機能をより強力に拡張できる。zapproxyの拡張にも対応
  • https://github.com/wagiro/BurpBounty burpプラグイン。アクティブ・パッシブスキャン機能を強化
  • https://github.com/nccgroup/BurpSuiteHTTPSmuggler Burp拡張機能。いくつかのテクニックを使用してWAFをバイパス
  • https://github.com/PortSwigger/command-injection-attacker burpプラグイン。コマンドインジェクション脆弱性の検出
  • https://github.com/nccgroup/freddy burpプラグイン。Java/.NETアプリケーションのデシリアライゼーション脆弱性を自動識別
  • https://github.com/modzero/interestingFileScanner burpプラグイン。機密ファイルのスキャンを強化
  • https://github.com/summitt/Burp-Non-HTTP-Extension burpプラグイン。DNSサーバーを配置してトラフィックをキャプチャ
  • https://github.com/ilmila/J2EEScan burp拡張機能。J2EEアプリケーションをスキャン
  • https://github.com/JGillam/burp-co2 sqlmap、菜刀(China Chopper)、辞書生成などを統合
  • https://github.com/swisskyrepo/SSRFmap burpプラグイン。ssrf脆弱性の検出
Sqlmap- https://github.com/codewatchorg/sqlipy Burpとsqlmapの連携プラグイン
  • https://github.com/Hood3dRob1n/SQLMAP-Web-GUI sqlmapのWeb GUI
  • https://github.com/KINGSABRI/sqlmap-tamper-api 様々な言語でsqlmapのTamperを作成
  • https://github.com/0xbug/SQLiScanner sqlmapapiとCharlesに基づく受動的SQLインジェクション脆弱性スキャナツール
  • https://github.com/fengxuangit/Fox-scan sqlmapapiに基づく能動的・受動的なリソース発見を行う脆弱性スキャナツール
  • https://github.com/UltimateHackers/sqlmate sqlmapをベースにディレクトリスキャン、ハッシュブルートフォースなどの機能を追加
  • https://github.com/ysrc/GourdScanV2 ysrc製の受動的脆弱性スキャナツール、sqlmapapiベース
  • https://github.com/zt2/sqli-hunter sqlmapapiベース、Rubyで書かれたプロキシ型脆弱性検出ツール
  • https://github.com/jesuiscamille/AutoSQLi DorkNet、Googler、Ddgr、WhatWaf、sqlmapを利用した自動インジェクション
Nmap
  • https://github.com/Ullaakut/nmap Goで実装されたNmap呼び出しライブラリ
  • https://github.com/cldrn/nmap-nse-scripts NSEスクリプト収集リスト
  • https://github.com/vulnersCom/nmap-vulners nmapを使用して一般的なサービス脆弱性をスキャン
  • https://github.com/s4n7h0/Halcyon Nmap Script (NSE)のIDEエディタ
  • https://github.com/m4ll0k/AutoNSE NSEの自動エクスプロイト
  • https://github.com/Screetsec/Dracnmap シェル。Nmapの複雑なコマンドを一定程度統合・簡素化し、初心者でも使いやすくする。
  • https://github.com/cldrn/rainmap-lite Django製のWeb版Nmap。新しいスキャンサーバーを構築でき、ユーザーはスマートフォン/タブレット/WebブラウザからNmapスキャンを開始できる
  • https://github.com/trimstray/sandmap LinuxでNmapエンジンを多用したネットワーク・システム偵察をサポートするツール
  • https://github.com/m0nad/HellRaiser nmapベースのスキャナ。CVE脆弱性と連携
  • https://github.com/scipag/vulscan nmapベースの高度な脆弱性スキャナ、コマンドライン環境で使用
  • https://github.com/Rev3rseSecurity/WebMap nmapのXMLをWebで表示するツール
  • https://github.com/DanMcInerney/msf-autopwn NMapスキャンを実行またはスキャン結果を読み取り、一般的な脆弱性を含むホストをmsfで自動攻撃する
Metasploit
  • https://github.com/13o-bbr-bbq/machine_learning_security/tree/master/DeepExploit 機械学習とmsfを組み合わせた全自動テストツール
  • https://github.com/r00t-3xp10it/Meterpreter_Paranoid_Mode-SSL SSL/TLSシェル接続を作成できるスクリプト
  • https://github.com/DanMcInerney/msf-netpwn msfのセッションを待機し、自動的にドメイン管理者へ権限昇格する
  • https://www.exploit-db.com/exploits/45851/ msfプラグイン。JiraのUPMアップロードを利用したコマンド実行
  • https://github.com/NullArray/AutoSploit Shodan検索エンジンを利用してターゲットを収集し、設定したmsfモジュールを自動呼び出して攻撃を仕掛ける
  • https://github.com/WazeHell/metateta msfスクリプトを使用し、特定のプロトコルに基づいてスキャンを実行
  • https://github.com/fbkcs/msf-elf-in-memory-execution メモリ内でELFファイルを実行するためのMetasploitモジュール
  • https://github.com/ElevenPaths/Eternalblue-Doublepulsar-Metasploit Eternalblue-Doublepulsar攻撃を利用したmetasploitエクスプロイトファイル
  • https://github.com/darkoperator/Metasploit-Plugins msfのアセット収集とヘルプを拡張するプラグイン
  • https://github.com/D4Vinci/One-Lin3r metasploit、payloadの補助検索ツール
  • https://github.com/shizzz477/msploitego msfデータベースをmaltegoでグラフィカルに表示
  • https://github.com/scriptjunkie/msfgui metasploitのGUI。ちなみに現在のmsfはWindowsサポートも良好
CobaltStrike
  • https://github.com/Al1ex/CSPlugins CobaltStrikeの各種プラグイン

  • https://mp.weixin.qq.com/s/CEI1XYkq2PZmYsP0DRU7jg Aggressorスクリプトを使用してCobalt Strikeをカスタマイズ

  • https://github.com/rsmudge/armitage CobaltStrikeコミュニティ版。msfを呼び出し、1対多のGUI付き

  • https://github.com/anbai-inc/CobaltStrike_Hanization CobaltStrike 2.5の中国語化版。msfライブラリをベースとしており、3.0以降でリニューアル

  • https://github.com/rsmudge/cortana-scripts cs2.xとarmitage用の拡張可能なプラグイン。cvs3.x用はAggressorScripts

  • https://github.com/harleyQu1nn/AggressorScripts cs3.0以降のスクリプト収集

  • https://github.com/FortyNorthSecurity/AggressorAssessor cs3.xの自動化攻撃スクリプト集

  • https://github.com/Ridter/CS_Chinese_support/ cs3.0の表示情報を中国語化するプラグイン

  • https://github.com/verctor/CS_xor64 cobaltstrikeに必要なxor64.binを生成

  • https://github.com/ryhanson/ExternalC2 通信チャネルとCobalt Strike External C2サーバーを統合するためのライブラリ

  • https://github.com/threatexpress/cs2modrewrite Cobalt Strikeの設定ファイルをmod_rewriteスクリプトに変換するツール

  • https://github.com/Mr-Un1k0d3r/CatMyFish 分類済みドメインを検索し、Cobalt Strike beacon C&C用にホワイトリストドメインを設定

  • https://github.com/threatexpress/malleable-c2 jqueryファイルを利用してC2通信を行い、ファイル内でJS難読化によりファイアウォールを回避

  • https://github.com/dcsync/pycobalt py3、Cobalt Strike用のPython API

  • https://www.cobaltstrike.com/aggressor-script/cobaltstrike.html CobaltStrike関連プラグインの作成、1対多のGUI付き

Empire
  • https://paper.tuisec.win/detail/f3dce68a0b4baaa Empireを利用してドメインコントローラ権限を取得
  • https://github.com/EmpireProject/Empire-GUI empireのnode.jsインターフェース
  • https://github.com/interference-security/empire-web empireのWebインターフェース
  • https://github.com/byt3bl33d3r/DeathStar py3、Empire RESTful APIを呼び出してドメイン管理者権限を自動取得するツール
  • https://github.com/infosecn1nja/e2modrewrite Empireの設定ファイルをApache mod_rewriteスクリプトに変換するツール
  • https://github.com/maxchehab/CSS-Keylogging Chrome拡張機能とExpressサーバーがCSSのキーロギング機能を利用する。
  • https://github.com/evilcos/cookiehacker Chrome拡張機能。JavaScriptのdocument.cookie / Wireshark Cookie
  • https://github.com/lfzark/cookie-injecting-tools Chrome拡張。Cookie注入ツールで、Cookieの注入、編集、追加、削除が可能

内部ネットワークセキュリティ

おすすめリソース

  • https://attack.mitre.org/wiki/Lateral_Movement mitre機構による横移動のまとめ

  • https://payloads.online/archivers/2018-11-30/1 Windows認証を徹底的に理解する - トピックの解説

  • https://github.com/klionsec/klionsec.github.io 内部ネットワークのエキスパートの学習の軌跡

  • https://github.com/l3m0n/pentest_study ゼロから始める内部ネットワークペネトレーション学習

  • https://github.com/Ridter/Intranet_Penetration_Tips 内部ネットワークペネトレーションTIPS

  • https://github.com/OpenWireSec/metasploit ポストエクスプロイテーションフレームワーク

  • https://github.com/EmpireProject/Empire PowerShellベースのコマンド実行フレームワーク

  • https://github.com/TheSecondSun/Bashark 純Bashスクリプトで書かれたポストエクスプロイテーションフレームワーク、大ザメ

  • https://github.com/JusticeRage/FFM py3、ダウンロード・アップロード機能を持ち、実行可能なpyスクリプトのバックドアを生成するポストエクスプロイテーションフレームワーク

  • https://github.com/DarkSpiritz/DarkSpiritz py2、ポストエクスプロイテーションフレームワーク

  • https://github.com/byt3bl33d3r/CrackMapExec ネットワークテストにおけるスイスアーミーナイフ。impacket、PowerSploitなど多種多様なモジュールを含む

  • https://github.com/SpiderLabs/scavenger CrackMapExecを二次開発してラップし、内部ネットワークの機密情報をスキャン

  • https://github.com/jmortega/python-pentesting python-pentesting-tool、Pythonセキュリティツール関連の機能モジュール

  • https://github.com/0xdea/tactical-exploitation Python/PowerShellのテストスクリプト集

  • https://github.com/PowerShellMafia/PowerSploit PowerShellテストスクリプト集と開発フレームワークのまとめ

転送|プロキシ

  • https://github.com/fatedier/frp 内部ネットワーク貫通のための高性能リバースプロキシアプリケーション。tcp、udp、http、httpsプロトコルに対応
  • https://github.com/inconshreveable/ngrok ポート転送、正・リバースプロキシ、内部ネットワーク貫通
  • http://ngrok.ciqiuwl.cn/ オンラインの小米球ngrok
  • https://github.com/knownsec/rtcp Socketポート転送、リモートメンテナンス用
  • https://github.com/davrodpin/mole sshベースのポート転送
  • http://rootkiter.com/EarthWorm SOCKS v5プロキシサービスを起動するためのツール。標準Cで開発され、複数プラットフォーム間の通信中継を提供し、複雑なネットワーク環境でのデータ転送に使用する。
  • http://rootkiter.com/Termite/README.txt EarthWormのアップグレード版。マルチノードジャンプを実現可能
  • https://github.com/SECFORCE/Tunna HTTPでラップして任意のTCPをトンネリング通信でき、ファイアウォール環境でのネットワーク制限を回避するために使用
  • https://github.com/fbkcs/thunderdns TCPトラフィックをDNSプロトコル経由で転送。クライアントとsocket5のサポートは不要
  • https://github.com/sensepost/reGeorg reDuhのアップグレード版。主に内部ネットワークサーバーのポートをhttp/httpsトンネルを介してローカルマシンに転送し、ループを形成する。ターゲットサーバーが内部ネットワークにある場合やポートポリシーが設定されている場合に、ターゲットサーバー内部の開放ポートへ接続するために使用(php、asp、jspスクリプトの正・リバースプロキシを提供)
  • https://github.com/SpiderClub/haipproxy py3、ScrapyとRedis、高可用性IPプロキシプール
  • https://github.com/chenjiandongx/async-proxy-pool py3、非同期クローラーのIPプロキシプール
  • https://github.com/audibleblink/doxycannon openvpnプロキシプールを使用し、それぞれに対してdockerを生成。特定のVPNに接続すると、他はsocks5転送でトラフィックを分散
  • https://github.com/decoder-it/psportfwd PowerShellで書かれたポート転送ツール、管理者権限は不要
  • https://github.com/ls0f/gortcp go、主制御端、中継、被制御端を介して内部ネットワーク貫通を実現

横移動

  • http://www.oxid.it/cain.html Cain & Abelはパスワードの復元、ARP中間者攻撃をサポート
  • https://github.com/gentilkiwi/mimikatz Windowsでのパスワード採取を中心とした横移動の神器
  • https://github.com/skelsec/pypykatz 純粋なpy3で実装されたmimikatz
  • https://github.com/eladshamir/Internal-Monologue LSASSプロセスを必要とせずに、Mimikatzの手法を用いてLSASSプロセスのメモリから情報を抽出する。メモリから平文パスワード、NTLMハッシュ、Kerberosチケットを抽出し、pass-the-hash/pass-the-ticket攻撃などを実行する
  • https://github.com/AlessandroZ/LaZagne py3、パスワード採取ツール
  • https://github.com/AlessandroZ/LaZagneForensic LaZagneのパスワードクラッキングアップグレード版。DPAPIを利用するが、現状の欠点はWindowsユーザーパスワードが必要なこと
  • https://github.com/twelvesec/passcat Windows向けのパスワード採取ツール
  • https://github.com/huntergregal/mimipenguin Linuxのパスワード採取の神器
  • https://github.com/quarkslab/quarkspwdump quarkslab製のパスワード採取ツール。プロセスへのインジェクションは不要
  • https://github.com/mthbernardes/sshLooter sshサービスからユーザー名とパスワードを窃取
  • https://github.com/nettitude/Invoke-PowerThIEf IEを利用したポストエクスプロイテーション、パスワードの採取、リダイレクトなど
  • https://github.com/GhostPack/Rubeus Kerberosを操作するライブラリ。Kekeoの大部分の機能を実装、C#で記述
  • https://github.com/m8r0wn/ldap_search PY、ldap(ライトウェイトディレクトリアクセスプロトコル)認証を介してWindowsドメイン情報を列挙し、ログインをブルートフォース

コマンド&コントロール

  • https://github.com/malwaredllc/byob ボットネット生成フレームワーク
  • https://github.com/proxycannon/proxycannon-ng 攻撃用ボットネットの構築
  • https://github.com/deadPix3l/CryptSky/ ランサムウェアのPoC
  • https://github.com/jgamblin/Mirai-Source-Code ワームウイルスのPoC
  • https://github.com/AhMyth/AhMyth-Android-RAT smaliベース、Windows向けAndroid遠隔操作、1対多のGUI付き
  • https://github.com/ssooking/cobaltstrike3.12_cracked java1.8、遠隔操作、フィッシング、内部ネットワーク
  • https://github.com/Mr-Un1k0d3r/ThunderShell py2、CLIとWebエンド、インメモリバックドア、RC4暗号化HTTP通信
  • https://github.com/tiagorlampert/CHAOS go、Windows遠隔操作、ほとんどのアンチウイルスソフトを回避可能
  • https://github.com/Ne0nd0g/merlin go、C2通信、1対多
  • https://github.com/0x09AL/Browser-C2 go、chromeを利用してブラウザの形式でC2サーバーに接続
  • https://github.com/xdnice/PCShare c++、ターゲットマシンの画面、レジストリ、ファイルシステムなどを監視可能
  • https://github.com/quasar/QuasarRAT c#、1対多、GUI
  • https://github.com/TheM4hd1/Vayne-RaT c#、1対多、GUI
  • https://github.com/nettitude/PoshC2 PowerShell、C#、遠隔操作ツール、Windows権限昇格コンポーネントあり
  • https://github.com/euphrat1ca/njRAT-v0.7d vb、よく見られるワーム型遠隔操作、多くの亜種が存在、1対多のGUI付き
  • https://github.com/zerosum0x0/koadic py3、JScript/VBScriptを利用して制御、通称「大剣」
  • https://github.com/Ridter/MyJSRat py2、jsバックドアを利用し、chm、htaと組み合わせることで多くのバックドア手法を実現可能。evi1cg.me/archives/chm_backdoor.html
  • py3、macOSとLinux向けのjsバックドア、Webインターフェースで管理

権限昇格

Linux権限昇格
  • https://github.com/Al1ex/Heptagram/tree/master/Linux/Elevation Linux権限昇格のまとめ

  • https://github.com/AlessandroZ/BeRoot py、一般的な誤設定をチェックして権限昇格方法を探す。Windows/Linux/Macに対応

  • https://github.com/mschwager/0wned pythonパッケージを利用して高権限ユーザーを作成

  • https://github.com/mzet-/linux-exploit-suggester Linuxに適用されていないパッチを探すスクリプト

  • https://github.com/belane/linux-soft-exploit-suggester Linuxに存在する脆弱性のあるソフトウェアを探す

  • https://github.com/dirtycow/dirtycow.github.io Dirty COW(ダーティ・カウ)権限昇格脆弱性エクスプロイト

  • https://github.com/FireFart/dirtycow Dirty COW(ダーティ・カウ)権限昇格脆弱性エクスプロイト

  • https://github.com/stanleyb0y/sushell suスニファを利用して低権限ユーザーがrootユーザーのパスワードを窃取

  • https://github.com/jas502n/CVE-2018-17182/ LinuxカーネルのVMA-UAF権限昇格脆弱性 CVE-2018-17182

  • https://github.com/jas502n/CVE-2018-14665 CVE-2018-14665、LinuxにおけるXorg Xサーバーの権限昇格エクスプロイト

  • https://github.com/nmulasmajic/syscall_exploit_CVE-2018-8897 LinuxシステムでSyscallを利用して権限昇格を実現

  • https://github.com/can1357/CVE-2018-8897 LinuxシステムでSyscallを利用して権限昇格を実現

  • https://github.com/SecWiki/linux-kernel-exploits linux-kernel-exploits、Linuxプラットフォームの権限昇格脆弱性エクスプロイト集

  • https://github.com/nilotpalbiswas/Auto-Root-Exploit Linux自動権限昇格スクリプト

  • https://github.com/WazeHell/PE-Linux Linux権限昇格ツール

Windows権限昇格
  • https://github.com/Al1ex/Heptagram/tree/master/Windows/Elevation Windows権限昇格のまとめ
  • http://www.fuzzysecurity.com/tutorials/16.html Windowsプラットフォームのチュートリアル級の権限昇格参考記事
  • https://github.com/SecWiki/windows-kernel-exploits Windowsプラットフォームの権限昇格脆弱性エクスプロイト集
  • https://github.com/51x/WHP Windows向けの各種権限昇格・エクスプロイトツール
  • https://github.com/rasta-mouse/Sherlock Windows権限昇格脆弱性の検証
  • https://github.com/WindowsExploits/Exploits マイクロソフトのCVE-2012-0217、CVE-2016-3309、CVE-2016-3371、CVE-2016-7255、CVE-2017-0213権限昇格エクスプロイト
  • https://github.com/decoder-it/lonelypotato RottenPotatoNGの変種。NBNSローカルドメイン名スプーフィングとWPADプロキシスプーフィングを利用して権限昇格
  • https://github.com/ohpe/juicy-potato RottenPotatoNGの変種。COMオブジェクト、ユーザートークンを利用して権限昇格
  • https://github.com/foxglovesec/Potato RottenPotatoNGの変種。ローカルドメイン名スプーフィングとプロキシスプーフィングを利用して権限昇格
  • https://github.com/DanMcInerney/icebreaker 内部ネットワーク環境にありながらAD環境の外にいる場合、icebreakerは平文のActive Directory資格情報の取得を支援する(Active Directoryはドメインコントローラサーバーに保存され、権限昇格に利用できる)
  • https://github.com/hausec/ADAPE-Script Active Directory権限昇格スクリプト
  • https://github.com/klionsec/BypassAV-AllThings aspxワンライナーと権限昇格payloadを組み合わせて権限昇格
  • https://github.com/St0rn/Windows-10-Exploit msfプラグイン、Windows 10のUACバイパス
  • https://github.com/sam-b/CVE-2014-4113 Win32k.sysカーネル脆弱性を利用して権限昇格、ms14-058
  • https://github.com/breenmachine/RottenPotatoNG NBNSローカルドメイン名スプーフィングとWPADプロキシスプーフィングを利用して権限昇格
  • https://github.com/unamer/CVE-2018-8120 Win32kコンポーネントに影響。win7とwin2008を対象とした権限昇格

Bypass

権限バイパス

  • https://payloads.online/archivers/2018-12-22/1 DLL Hijacking & COM HijackingによるUACバイパス - トピックの解説
  • https://github.com/tyranid/DotNetToJScript JS/Vbsスクリプトを利用して.Netプログラムを読み込むことができるツール
  • https://github.com/mdsecactivebreach/SharpPack システムのアプリケーションホワイトリストを回避してDotNetおよびPowerShellツールを実行
  • https://github.com/rootm0s/WinPwnage py2、Windowsでの権限昇格、UACバイパス、DLLインジェクションなど
  • https://github.com/hfiref0x/UACME 複数のOSバージョンでWindowsユーザーアカウント制御をバイパスするための多くの手法を含む
  • https://github.com/Ben0xA/nps powershell.exeを使用せずにPowerShellコマンドを実行することを実現
  • https://github.com/Mr-Un1k0d3r/PowerLessShell powershell.exeを呼び出さずにPowerShellコマンドを実行することを実現
  • https://github.com/p3nt4/PowerShdll rundll32を使用してPowerShellを実行し、ソフトウェア制限を回避
  • https://github.com/ionescu007/r0ak カーネルレベルのスイスアーミーナイフ。Windows 10カーネル内でコードの読み取り/書き込み/実行が可能
  • https://github.com/leechristensen/UnmanagedPowerShell アンマネージドプログラムからPowerShellを実行する。一部修正を加えることで他プロセスへのインジェクションに使用できる
  • https://github.com/stephenfewer/ReflectiveDLLInjection DLL自身がLoadLibraryA関数を使用せずに、ターゲットプロセスのメモリへ自身をマッピングするライブラリインジェクション技術
  • https://github.com/ChrisAD/ads-payload 環境変数とdestop.iniを利用してWindows上のPalo Alto Trapsエンドポイント保護ソフトウェアを回避
  • https://github.com/Zer0Mem0ry/RunPE メモリ読み取り、ネットワーク転送されたコンテンツを介して、PEによるshellcodeの実行を実現

サンドボックスエスケープ

  • https://github.com/hacksysteam/WpadEscape wpadを利用してブラウザのサンドボックスからエスケープ
  • https://github.com/unamer/vmware_escape vmware仮想マシンからのエスケープ。CVE-2017-4901、CVE-2018-6981、CVE-2018-6982
  • https://github.com/MorteNoir1/virtualbox_e1000_0day VirtualBox E1000 Guest-to-Host Escape。チュートリアル
  • https://bugs.chromium.org/p/project-zero/issues/detail?id=1682&desc=2 Ghostscript:脆弱性CVE-2018-17961に基づく-dSAFERサンドボックスエスケープ技術

バックドアのAV回避

  • https://www.shellterproject.com アンチウイルスソフトの回避
  • https://github.com/trustedsec/unicorn py、ワンクリックで多種多様なバックドアを生成
  • https://github.com/islamTaha12/Python-Rootkit Windows向けrootkit、meterpreterのリバースシェル
  • https://github.com/n00py/Hwacha Linuxでmetepreterなど多種のpayloadを迅速に生成
  • https://github.com/Screetsec/Vegile msfのAV回避、プロセスインジェクション
  • https://github.com/MohamedNourTN/Terminator py2、msfのAV回避
  • https://github.com/Veil-Framework/Veil msfのAV回避
  • https://github.com/abedalqaderswedan1/aswcrypter py、bash、msfのAV回避
  • https://github.com/Screetsec/TheFatRat java、msfのAV回避、searchsploitを利用した高速検索
  • https://github.com/pasahitz/zirikatu msfのAV回避
  • https://github.com/govolution/avet msfのAV回避
  • https://github.com/GreatSCT/GreatSCT msfのAV回避
  • https://github.com/EgeBalci/HERCULES msfのAV回避
  • https://github.com/trustedsec/nps_payload msfのAV回避
  • https://github.com/4w4k3/Insanity-Framework py、payload生成、アンチウイルス回避、仮想マシン検出、フィッシング、メモリインジェクションなど
  • https://github.com/hlldz/SpookFlare Meterpreter、Empire、Koadicなどのloader/dropper生成器。クライアント側検出とネットワーク側検出のエンドポイントポリシーを回避可能
  • https://github.com/pasahitz/regsvr32 C#+Empireを使用して最小サイズのAV回避バックドアを実現
  • https://github.com/malcomvetter/UnstoppableService 自身をWindowsサービスとしてインストールし、管理者がサービスを停止/一時停止できないようにするプログラム。C#で記述

ソーシャルエンジニアリング・フィッシング

おすすめコンテンツ

  • https://github.com/brannondorsey/PassGAN py、深層学習、パスワード辞書サンプル生成
  • https://github.com/Mebus/cupp ユーザーのパスワード習慣に基づき弱いパスワードの検出用辞書を生成
  • https://github.com/Saferman/cupper ユーザーのパスワード習慣に基づき弱いパスワードの検出用辞書を生成、上記のアップグレード版
  • https://github.com/LandGrey/pydictor py3、特定パスワード辞書の生成
  • https://github.com/mehulj94/Radium-Keylogger Python製キーロガーツール
  • https://github.com/threatexpress/domainhunter 期限切れドメイン、Bluecoat分類、Archive.orgの履歴をチェックし、フィッシングやC2に最も適したドメインを特定する
  • https://github.com/Mr-Un1k0d3r/CatMyPhish 標的と類似した未登録ドメインを収集する
  • https://github.com/x0day/Multisearch-v2 Bing、Google、360、ZoomEyeなどの検索エンジンを集約する検索。企業の機密資産情報が検索エンジンに収録されているかを発見するために使用可能
  • https://github.com/n0tr00t/Sreg Sregは、ユーザーがemail、phone、usernameを入力することで、そのユーザーが登録しているすべてのインターネット上のパスポート情報を返すことができる
  • https://github.com/SpiderLabs/social_mapper ソーシャルメディア列挙・関連付けツール。顔認識によって人物のプロファイリングを関連付ける
  • https://github.com/vysec/MaiInt 企業従業員情報収集テストツール
  • https://github.com/jofpin/trape py、OSINTを利用した人物の追跡・位置特定
  • https://github.com/famavott/osint-scraper 人名やメールアドレスを入力すると、インターネットからその人に関する情報を自動的にクロールする
  • https://github.com/xHak9x/fbi py2、Facebook情報収集ツール
  • https://github.com/initstring/linkedin2username LinkedInを介して関連企業の従業員リストを取得する
  • https://github.com/0x09AL/raven Linux向けLinkedIn情報収集ツール
  • https://github.com/Ridter/Mailget 脉脉(マイマイ)ユーザーを通じて企業メールアドレスを推測する

サイトクローン

  • http://www.httrack.com Webサイトクローン・ミラー

フィッシングフレームワーク

  • https://github.com/bhdresh/SocialEngineeringPayloads 証明書窃取とスピアフィッシング攻撃に使用されるソーシャルエンジニアリングのテクニックとペイロードを収集する
  • https://github.com/trustedsec/social-engineer-toolkit ソーシャルエンジニアリング専用に設計されたオープンソースのペネトレーションテストフレームワーク
  • https://github.com/thelinuxchoice/blackeye Facebook、Instagramなど30以上のフィッシングテンプレートを備えたワンクリック起動ツール
  • https://github.com/M4cs/BlackEye-Python blackeyeをベースにサブドメイン管理を強化
  • https://github.com/azizaltuntas/Camelishing py3、GUI化されたソーシャルエンジニアリング攻撃支援ツール
  • https://github.com/JonCooperWorks/judas go、Webサイトクローンによるフィッシング
  • https://github.com/gophish/gophish go、オンラインテンプレート設計、騙しの広告送信などの機能を備えたフィッシングシステム
  • https://github.com/tatanus/SPF py2、deefcon上のフィッシングシステム
  • https://github.com/MSG-maniac/mail_fishing クライアント社内フィッシングシステム
  • https://github.com/samyoyo/weeman フィッシング用HTTPサーバー
  • https://github.com/Raikia/FiercePhish すべてのフィッシング攻撃を管理できる完全なフィッシングフレームワーク。個々のフィッシングキャンペーンの追跡、電子メールの定期送信などが可能
  • https://github.com/securestate/king-phisher 視覚化されたフィッシングキャンペーンツールキット
  • https://github.com/fireeye/ReelPhish リアルタイム2要素認証フィッシングツール
  • https://github.com/kgretzky/evilginx 2要素認証をバイパスするフィッシングフレームワーク
  • https://github.com/kgretzky/evilginx2 MiTMフレームワーク、ログインページフィッシング、2要素認証のバイパスなど
  • https://github.com/ustayready/CredSniper FlaskとJinja2テンプレートで書かれたフィッシングフレームワーク。2FAトークンのキャプチャに対応
  • https://github.com/fireeye/PwnAuth OAuth乱用テスト検出プラットフォーム

トラフィックハイジャック

  • https://github.com/bettercap/bettercap ネットワーク攻撃と監視のスイスアーミーナイフ。ARP/DNSスプーフィング、TCP、パケットプロキシなどの複数のモジュールをサポート
  • https://github.com/mitmproxy/mitmproxy PY、SSLインターセプトをサポートし、HTTPSトラフィックをプロキシする
  • https://github.com/qiyeboy/BaseProxy py3、非同期HTTP/HTTPSプロキシ、上記の簡易版。URLや画像の置換など中間人ツールとして使用可能
  • https://github.com/lgandx/Responder ネットワーク内のすべてのNTLM、NTLMv1/v2、Net-NTLMv1/v2パケットをスニッフィングし、ネットワーク内のホストを騙してユーザーハッシュを取得する。AがBのパスワードを持ってBに要求し、CがAに対して「私はBだ」と応答すると、CはBのパスワードを取得する。https://www.secpulse.com/archives/65503.html 【SecPulse翻訳シリーズ】ペネトレーターガイドのResponder
  • https://github.com/Kevin-Robertson/Inveigh PowerShell製のLLMNR/mDNS/NBNSスプーファー兼中間人ツール
  • https://github.com/LionSec/xerosploit 中間人攻撃テストツールキット
  • https://github.com/AlsidOfficial/WSUSpendu 悪意のある更新プログラムを自動作成し、WSUSサーバーデータベースに注入して、それらの悪意のある更新を任意に配布できる
  • https://github.com/infobyte/evilgrade モジュール式スクリプトフレームワーク。攻撃者がユーザーに気付かれずに悪意のあるアップデートをユーザーの更新に注入できる
  • https://github.com/quickbreach/smbetray ファイルコンテンツの交換、LNK交換によるクライアントへの攻撃と、平文で転送されるデータの窃取に焦点を当てる
  • https://github.com/mrexodia/haxxmap IMAPサーバーに対する中間人攻撃を実行

トラフィック分析

  • https://github.com/wireshark/wireshark プロトコル解析・トラフィック分析・復元
  • https://github.com/CoreSecurity/impacket Impacketはネットワークプロトコルを扱うためのPythonツール群の集合。内網では権限昇格などに使用でき、例えばwmiexec.py、NMB、SMB1-3、MS-DCERPCを通じてプロトコル実装自体への低レベルプログラミングアクセスを提供する
  • https://github.com/secdev/scapy インタラクティブなネットワークパケット処理、パケットジェネレーター、ネットワークスキャナー、ネットワークディスカバリー、パケットスニッフィングツールを内蔵。多種のプロトコルパケット生成・解析プラグインを提供し、プロトコルパケットを柔軟に生成、変更、解析できる
  • https://gitee.com/qielige/openQPA プロトコル解析ソフトウェアQPAのオープンソースコード。プロセス単位のパケットキャプチャと特徴の自動分析が特徴
  • https://github.com/jtpereyda/boofuzz ネットワークプロトコルのファズテスト
  • https://www.jianshu.com/p/4dca12a35158 よく使われる無料のパケットライブラリ5選
  • https://github.com/zerbea/hcxdumptool WLANデバイスからパケットをキャプチャする
  • https://github.com/NytroRST/NetRipper putty、winscp、mssql、chrome、firefox、outlook、https内の平文パスワードの傍受をサポート
  • https://github.com/shramos/polymorph ほぼすべての既存プロトコルをサポートするリアルタイムネットワークパケット操作フレームワーク
  • https://github.com/nospaceships/raw-socket-sniffer C、PS、ドライバ不要でWindowsトラフィックをキャプチャ

ワイヤレスセキュリティ

おすすめコンテンツ

  • https://github.com/wi-fi-analyzer/fluxion ユーザーのWi-Fiパスワードを窃取するパスワードリプレイ攻撃
  • https://github.com/0v3rl0w/e013 Wi-Fiパスワードを窃取するVBスクリプト
  • https://github.com/cls1991/ng 現在接続中のWi-FiのパスワードとIPを取得
  • https://github.com/wifiphisher/wifiphisher PY、中間人攻撃、Fake AP悪意あるホットスポット、Wi-Fiフィッシング、認証情報窃取
  • https://github.com/1N3/PRISM-AP Rogue AP(悪意あるホットスポット)を自動展開するMITM攻撃フレームワーク
  • https://github.com/sensepost/mana Wi-Fiハイジャックツール。コンピューターや他のモバイルデバイスのWi-Fi通信を傍受し、そのデバイスを模倣できる
  • https://github.com/deltaxflux/fluxion bashとpy、WPAプロトコルを使用するワイヤレスネットワークに対するMiTM攻撃
  • https://github.com/DanMcInerney/LANs.py ARPスプーフィング、ワイヤレスネットワークのハイジャック

WIFI防御

  • https://github.com/SYWorks/waidps PY、Linux向けワイヤレスネットワーク侵入検知ツール
  • https://github.com/SkypLabs/probequest 無線LANカード周辺のWi-Fi Probeリクエストをスニッフィングして表示する
  • https://github.com/wangshub/hmpa-pi Raspberry Piやルーター上でWiresharkを利用して周辺のWi-Fiデバイスをスキャンし、スマートフォンや他のWi-Fiデバイスが近くにあるときにメールまたはWeChatで通知する
  • https://github.com/besimaltnok/PiFinger Wi-Fiが「WiFi Pineapple(大菠萝)」によって開放された悪意あるホットスポットかどうかを検査する
  • https://github.com/WiPi-Hunter/PiSavar PineAPを利用して、FAKE AP(偽のアクセスポイント)、例えば「WiFi Pineapple(大菠萝)」を監視する

WIFI監査

  • https://www.wifislax.com スペインのWi-Fi監査システム。中国国内の漢化版は無線革新5.1.1 Wifislax-WRC
  • https://cn.elcomsoft.com/ewsa.html ewsa、Wi-Fiスニッフィング、ハンドシェイクパケットのパスワード復元、EWSA-173-HC1UW-L3EGT-FFJ3O-SOQB3
  • https://www.passcape.com wifipr、ハンドシェイクパケットのパスワード復元。他にもWindows向け商用版のパスワード復元ツールが多数ある
  • https://github.com/MisterBianco/BoopSuite ワイヤレスネットワーク監査ツール、2-5GHz帯域をサポート
  • https://github.com/aircrack-ng/aircrack-ng パケットスニファー、検出器、WPA/WPA2-PSK解読器、WEP、802.11ワイヤレスLAN用分析ツールで構成される
  • https://github.com/t6x/reaver-wps-fork-t6x WPSのPINコード総当たり攻撃、一般的なWi-Fi攻撃
  • https://github.com/derv82/wifite2 wifiteワイヤレス監査ツールのアップグレード版。aircrack-ngとreaverを連携
  • https://github.com/savio-code/fern-wifi-cracker ワイヤレスセキュリティ監査ツール
  • https://github.com/P0cL4bs/WiFi-Pumpkin ワイヤレスセキュリティペネトレーションテストスイート
  • https://github.com/entropy1337/infernal-twin 自動化ワイヤレス攻撃ツールInfernal-Wireless
  • https://github.com/m4n3dw0lf/PytheM Pythonネットワーク/ペネトレーションテストツール
  • https://github.com/InfamousSYN/rogue ワイヤレスネットワーク攻撃ツールキット
  • https://github.com/cSploit/android スマートフォンWi-Fiペネトレーションツールフレームワーク、msfを使用可能
  • https://github.com/chrisk44/Hijacker スマートフォンWi-Fiテストツール
  • https://andrax-pentest.org/ Kali Hunterスマートフォンペネトレーションテストシステム
  • https://www.zimperium.com/zanti-mobile-penetration-testing スマートフォンWi-Fiペネトレーションツール

データ持ち出し

  • https://github.com/TryCatchHCF/Cloakify DLP/MLSデータ漏えい防止システムを回避し、データホワイトリスト制御を突破し、AV検出を回避してデータを窃取する
  • https://github.com/sensepost/DET 単一または複数のチャネルを使用して同時にデータの持ち出しを実行する
  • https://github.com/Arno0x/DNSExfiltrator DNS解決を利用してデータを隠密に転送するツール
  • https://github.com/ytisf/PyExfil データ持ち出し用のPythonパッケージ
  • https://github.com/Arno0x/ReflectiveDnsExfiltrator リフレクティブDNS解決の隠蔽チャネルによるデータ漏えい

ハードウェアセキュリティ

  • https://github.com/unprovable/PentestHardware ハードウェアペネトレーションテスト実用マニュアル
  • https://ducktoolkit.com/ Rubber Ducky、HIDキーボードシミュレーター
  • https://github.com/insecurityofthings/jackit Mousejack用の開発コード
  • https://github.com/samyk/magspoof クレジットカード情報の窃取
  • https://github.com/mame82/P4wnP1_aloa Raspberry Pi上に一般的なテストコンポーネントをインストールし、モバイルテストプラットフォームを構築する
  • https://www.freebuf.com/geek/195631.html 物理ハッカーになろう!Raspberry PiでP4wnP1プロジェクトを実現してペネトレーションテストを行う
  • https://github.com/mame82/P4wnP1 Raspberry Piにネットワークハイジャック・キーボードインジェクション(WHID)ツールをインストール
  • https://github.com/ebursztein/malusb クロスプラットフォームなHIDスプーフィングペイロードを作成し、WindowsとOSX上でリバースTCPシェルを確立する
  • https://github.com/Orange-Cyberdefense/fenrir-ocd 主な機能と用途は、有線802.1x保護をバイパスして対象ネットワークへのアクセスを可能にすること
  • https://github.com/360PegasusTeam/GhostTunnel 隔離環境でHIDを使用して隠蔽バックドアを生成し、ペイロードを解放した後に自身を削除する
  • https://github.com/LennyLeng/RadioEye RFIDを一般的なNFCと組み合わせて使用
  • https://github.com/Proxmark/proxmark3/ RFIDの神器PM3
  • http://www.freebuf.com/news/others/605.html RFID Hacking – リソース大合集
  • https://github.com/UnicornTeam/HackCube-Special UnicornTeam(独角兽实验室)のハードウェアペネトレーションテストプラットフォーム

IoTセキュリティ

おすすめコンテンツ

  • https://github.com/w3h/icsmaster 産業制御セキュリティリソースを統合
  • https://github.com/V33RU/IoTSecurity101 IoT・産業制御セキュリティとモノのインターネットセキュリティ学習用の記事とリソース
  • http://www.freebuf.com/ics-articles 産業制御関連
  • http://www.freebuf.com/sectool/174567.html 産業制御システム(ICS)セキュリティ専門家に必須のテストツールとセキュリティリソース
  • http://www.freebuf.com/articles/ics-articles/178822.html 石炭企業がどのように産業制御セキュリティを構築すべきかの簡単な分析
  • http://www.freebuf.com/articles/network/178251.html 産業制御セキュリティの現場実装経験談:産業制御システムでホスト保護を強化する方法
  • https://github.com/hslatman/awesome-industrial-control-system-security 産業制御システムセキュリティ分野の優れたリソース収集リポジトリ
  • https://github.com/adi0x90/attifyos IoT統合セキュリティテストシステム、いくつかの一般的なソフトウェアを同梱
  • https://github.com/moki-ics/moki Kaliに似た産業制御ペネトレーションテストシステムをワンクリックで構成するスクリプト
  • https://gitlab.com/expliot_framework/expliot py3、産業制御セキュリティ脆弱性テストフレームワーク
  • https://github.com/dark-lbp/isf py2、産業制御分野でmsfに似たテストフレームワーク
  • https://github.com/enddo/smod py2、scapyモジュールを使用し、主にModbusプロトコルのテストを対象とする
  • https://github.com/shodan-labs/iotdb nmapとShodan APIを組み合わせてIoTデバイスをスキャン
  • https://github.com/XHermitOne/icscanner GUI付きICSスキャナー
  • https://github.com/yanlinlin82/plcscan TCP/102とTCP/502を介してインターネット上のPLCデバイスや他のModbusデバイスを識別する
  • https://github.com/nsacyber/GRASSMARLIN NSA傘下のICS/SCADA状況認識
  • https://github.com/nezza/scada-stuff SCADA/ICSデバイスに対するリバースエンジニアリングと攻撃

カメラセキュリティ

  • https://github.com/woj-ciech/kamerka Shodan APIでスキャンしたカメラの地理位置情報を地図上に表示する
  • https://github.com/Ullaakut/cameradar GO、カメラのRTSPプロトコルに対するペネトレーションテスト、弱いパスワード辞書付き
  • https://github.com/Ullaakut/camerattack GO、カメラのリモート無効化
  • https://github.com/NIteshx2/UltimateSecurityCam py3、カメラで侵入者を監視するソフトウェア、スプーフィング防止設定あり

ルーターセキュリティ

  • http://stascorp.com RouterScan、ロシア製のルーター脆弱性悪用ツール、GUIが非常に強力
  • https://github.com/threat9/routersploit py3、msfを模したルーター脆弱性悪用フレームワーク
  • https://github.com/jh00nbr/Routerhunter-2.0 更新停止済み、ルーター脆弱性のスキャンと悪用
  • https://github.com/googleinurl/RouterHunterBR php、ルーター機器の脆弱性スキャンと悪用
  • https://github.com/scu-igroup/telnet-scanner Telnetサービスのパスワードリスト攻撃

ファズテスト

  • http://www.freebuf.com/articles/rookie/169413.html Fuzzing学習用のリソースまとめ
  • https://github.com/secfigo/Awesome-Fuzzing Fuzz関連の学習資料
  • https://github.com/fuzzdb-project/fuzzdb fuzzデータベース
  • https://github.com/ivanfratric/winafl AFL for fuzzing Windows binaries、オリジナル技術分析 | AFL脆弱性発見技術漫談
  • https://github.com/attekett/NodeFuzz a fuzzer harness for web browsers and browser like applications.
  • https://github.com/google/oss-fuzz Continuous Fuzzing for Open Source Software
  • http://blog.topsec.com.cn/ad_lab/alphafuzzer/ ファイル形式を中心とした脆弱性発見ツール
  • https://bbs.ichunqiu.com/thread-24898-1-1.html Test404 -HTTP Fuzzer V3.0
  • https://github.com/xmendez/wfuzz py、Webセキュリティファジングツール。モジュール化されており、Burpがキャプチャしたリクエストとレスポンスメッセージを処理できる
  • https://github.com/1N3/BlackWidow PythonベースのWebクローラー。対象Webサイトの情報収集とOWASP脆弱性のファジングに使用
  • https://github.com/bunzen/pySSDeep py、ファジーハッシュ(Fuzzy Hashing)アルゴリズムに基づくツール。go、glaslos/ssdeep;C、ssdeep-project/ssdeep
  • https://github.com/googleprojectzero/winafl Windowsバイナリを対象としたAFLテスト

モバイルセキュリティ

  • https://github.com/Brucetg/App_Security Appセキュリティ学習リソース
  • https://github.com/rovo89/Xposed Androidスマホシステムを自由自在に改変する
  • https://github.com/android-hacker/VirtualXposed VirtualAppとepicに基づき、非ROOT環境でXposedモジュールを実行する実装
  • https://github.com/MobSF/Mobile-Security-Framework-MobSF モバイルセキュリティ監査フレームワーク。Android、iOS、Windows
  • https://github.com/WooyunDota/DroidSSLUnpinning Android証明書ピン留め解除ツール
  • https://github.com/nccgroup/house 実行時モバイルApp分析ツールキット、Web GUI付き
  • https://github.com/UltimateHackers/Diggy APKファイルからURLを抽出するツール
  • https://github.com/nettitude/scrounger iOSおよびAndroidモバイルアプリケーションペネトレーションテストフレームワーク
  • https://github.com/XekriCorp/LeakVM Androidアプリセキュリティテストフレームワーク
  • https://github.com/zsdlove/ApkVulCheck Android脆弱性スキャンツール
  • https://github.com/samyk/frisky iOS/macOSアプリ向けのスニッフィング/改変/リバースエンジニアリング/インジェクション等のツール
  • https://github.com/GeoSn0w/OsirisJailbreak12 iOS 12不完全脱獄
  • https://github.com/chaitin/passionfruit iOSアプリのリバースエンジニアリングと分析ツール。iOSアプリのセキュリティ分析プロセスを大幅に高速化できる

クラウドセキュリティ

  • https://github.com/stuhirst/awssecurity/blob/master/arsenal.md AWSセキュリティ検出関連のプロジェクトリスト
  • https://github.com/toniblyx/my-arsenal-of-aws-security-tools AWSセキュリティツール集
  • https://github.com/sa7mon/S3Scanner Amazonの公開S3バケットとダンプをスキャンする
  • https://github.com/kromtech/s3-inspector Amazon AWS S3バケットのパーミッションを検出する
  • https://github.com/jordanpotti/AWSBucketDump AWS S3バケットを列挙して機密ファイルを探す
  • https://github.com/sa7mon/S3Scanner Amazonの公開S3バケットとダンプをスキャンする
  • https://github.com/kromtech/s3-inspector Amazon AWS S3バケットのパーミッションを検出する
  • https://github.com/jordanpotti/AWSBucketDump AWS S3バケットを列挙して機密ファイルを探す
  • https://github.com/Netflix/repokid AWS最小権限ポリシー展開ツール
  • https://github.com/RhinoSecurityLabs/pacu AWS脆弱性検出フレームワーク
  • https://github.com/0xbug/Hawkeye GitHub漏えい監視システム
  • https://github.com/neal1991/gshark GitHub情報漏えい検出
  • https://github.com/VKSRC/Github-Monitor GitHub監視、コード情報漏えい、分単位の監視、メール警告
  • https://github.com/metac0rtex/GitHarvester GitHubリポジトリ情報収集ツール
  • https://github.com/repoog/GitPrey GitHub機密情報スキャンツール
  • https://github.com/FeeiCN/GSIL py3、GitHubの機密情報をニアリアルタイムで監視し、アラート通知を送信する
  • https://github.com/UnkL4b/GitMiner GitHubの機密コンテンツの発掘
  • https://github.com/dxa4481/truffleHog GitHub機密情報スキャンツール、commit検出などを含む

リバースエンジニアリング

  • https://www.peerlyst.com/posts/resource-learning-how-to-reverse-malware-a-guide マルウェアリバースエンジニアリングガイドとツールの集合
  • https://github.com/ReFirmLabs/binwalk バイナリpwnファイルの自動リバースエンジニアリング、多種のプラグインを持つ
  • https://github.com/angr/angr 動的シンボリック実行と静的解析を備えたバイナリ分析ツール
  • https://github.com/endgameinc/xori カスタム逆アセンブルフレームワーク
  • https://down.52pojie.cn/ 吾爱破解の愛盤ツールキット
  • https://github.com/blacknbunny/peanalyzer32 PEファイル分析および逆アセンブルツール
  • https://github.com/DominicBreuker/pspy root権限なしでプロセスの実行を監視できる

CTF関連

  • https://ctf-wiki.github.io/ctf-wiki/ CTFwiki、Misc/Crypto/Web/Assembly/Executable/Reverse/Pwn/Android/ICS
  • https://github.com/adon90/pentest_compilation CTFコンペとOSCP試験でよく出る知識ポイントとコマンド
  • https://github.com/gabemarshall/microctfs 小型CTFイメージのDocker
  • https://github.com/giantbranch/pwn_deploy_chroot 複数のpwn問題を1つのDockerコンテナにデプロイする
  • https://github.com/facebook/fbctf CTFコンペフレームワーク
  • https://github.com/0Chencc/CTFCrackTools CTFツール統合パック
  • https://github.com/guyoung/CaptfEncoder CTF暗号・エンコードオールインワンパック、ミニアプリ版もある
  • https://github.com/Gallopsled/pwntools pwn系、バイナリエクスプロイトフレームワーク
  • https://github.com/ChrisTheCoolHut/Zeratool pwn系、バイナリエクスプロイトフレームワーク
  • https://github.com/ChrisTheCoolHut/Rocket-Shot pwn、自動攻撃スクリプト
  • https://0xrick.github.io/lists/stego/ ステガノグラフィーツール集、Steganography - A list of useful tools and resources
  • https://github.com/DominicBreuker/stego-toolkit ステガノグラフィーツールキット
  • https://github.com/bugsafe/WeReport WeReportレポートアシスタント
  • https://github.com/PELock/CrackMeZ3S-CTF-CrackMe-Tutorial CTFコンペ向けCrackMeソフトウェアの作成

フォレンジック調査

おすすめコンテンツ

  • https://www.freebuf.com/articles/rookie/195107.html 微信(WeChat)データベースの復号プロセスを記録する。WeChatの暗号化データベースの復号パスワードは「デバイスのIMEI(MEID)+ユーザーのuinをMD5し、その先頭7桁の小文字」で構成される
  • https://www.audacityteam.org/ 音声ファイルと波形を処理するツール
  • http://www.sweetscape.com/010editor/ さまざまなファイル形式(テンプレート)を識別する16進エディタ、ファイル修復機能付き
  • http://www.magicexif.com/ 写真画像内のEXIF情報をデータ化する
  • http://mediaarea.net/MediaInfo exiftoolに似て、コンテンツ領域とメタデータ情報を確認する
  • https://www.sno.phy.queensu.ca/~phil/exiftool/ 画像ファイルのEXIFメタデータを検査する
  • https://www.gimp.org/ Gimpはさまざまな画像ファイルの可視化データ変換機能を提供し、ファイルが画像ファイルであるかを確認するためにも使用できる
  • https://github.com/volatilityfoundation/volatility Windowsメモリフォレンジック分析
  • https://github.com/gleeda/memtriage Windowsメモリフォレンジック分析
  • https://github.com/SekoiaLab/Fastir_Collector Windowsフォレンジック/情報収集。メモリ、レジストリ、ファイル情報などに限定されない
  • https://github.com/Viralmaniar/Remote-Desktop-Caching- RDP情報の復元、PNG画像形式
  • https://github.com/comaeio/LiveCloudKd C、Hyper-V向けメモリフォレンジック -https://github.com/sevagas/swap_digger Linux swapに対するフォレンジック分析ツール
  • http://extundelete.sourceforge.net/ Linux向けファイル復旧
  • https://github.com/viaforensics/android-forensics AndroidフォレンジックAppとフレームワーク。Androidデバイス内のさまざまな情報を抽出できる
  • https://github.com/davidmcgrew/joy 内外ネットワークのトラフィックデータをキャプチャ・分析するためのパッケージ。主にネットワーク調査、セキュリティ監視、フォレンジックに使用
  • https://github.com/USArmyResearchLab/Dshell 拡張可能なネットワークフォレンジック分析フレームワーク。プラグインの迅速な開発とネットワークパケットキャプチャの解析をサポート

サンプル分析

  • https://github.com/open-power-workgroup/Hospital 全国の莆田系病院リスト
  • https://github.com/chenerlich/FCL マルウェアが使用するコマンドラインの収集
  • https://paper.seebug.org/421 一般的なソフトウェアコレクションとマルウェア分析
  • https://github.com/sapphirex00/Threat-Hunting APTマルウェアサンプル
  • https://www.malware-traffic-analysis.net/ マルウェアサンプル
  • http://dasmalwerk.eu/ マルウェアサンプル
  • https://github.com/ytisf/theZoo マルウェアサンプル
  • https://github.com/mstfknn/malware-sample-library マルウェアサンプル
  • http://99.248.235.4/Library/ マルウェアサンプルライブラリ。ladder
  • https://github.com/robbyFux/Ragpicker マルウェア情報のクロール・集約・分析
  • https://github.com/phage-nz/ph0neutria マルウェア情報のクロール・集約・分析
  • https://github.com/JR0driguezB/malware_configs 一般的なマルウェア設定ファイル
  • https://github.com/sfaci/masc Webサイト内のマルウェアをスキャンする。その他いくつかのWebサイトメンテナンス機能も含む
  • https://github.com/Neo23x0/munin ファイルハッシュに基づいて、さまざまなオンラインマルウェアスキャンサービスから情報を抽出するツール
  • https://github.com/1lastBr3ath/drmine Webページにマイニングスクリプトが含まれているかを自動検出するツール
  • https://github.com/KasperskyLab/klara Kasperskyがオープンソース化したYaraベースの分散マルウェアスキャンシステム
  • https://github.com/botherder/kraken go、実装されたYaraマルウェアスキャナー
  • https://github.com/alexandreborges/malwoverview simple、悪意のあるファイルをすばやく分類する
  • ソースコードとコンパイル済みバイナリファイルを直接比較する

セキュリティ製品

  • https://www.freebuf.com/sectool/135032.html 高対話型で発見されにくいハニーポットを構築する
  • https://bloodzer0.github.io/ossa/ オープンソースファイルを利用したオープンソースセキュリティアーキテクチャ。ホスト、スキャナー、ポート、ログ、防御デバイスなど
  • https://github.com/dvf/blockchain Pythonでゼロからブロックチェーンを作成する
  • https://github.com/crazywa1ker/DarthSidious-Chinese ゼロから始めるドメイン侵入の旅、DarthSidious 中国語版
  • https://paper.seebug.org/772/ KittyFuzzer と ISF の産業制御プロトコルコンポーネントを組み合わせて産業制御プロトコルを Fuzz する方法

セキュリティ運用

おすすめコンテンツ- https://github.com/chaitin/cloudwalker CloudWalker(牧云)サーバーセキュリティ管理プラットフォーム。サーバー資産管理、脅威スキャン、Webshell 検出・駆除、ベースライン検出などの機能を段階的にカバーします。

  • https://github.com/mitre/caldera MITRE社の攻撃シミュレーションテストシステム。主にWindows向けです。
  • https://github.com/guardicore/monkey ネットワークセキュリティ状況を評価するツールで、スキャナーとC2サーバーに分かれています。デフォルトのパスワードとエクスプロイトを利用してSSH、SMBなど複数のプロトコル方式で攻撃検出を行います。
  • https://github.com/grayddq/PublicSecScan AWVSを呼び出して大量のWEB資産に対して分散WEBセキュリティスキャンを実行し、Web環境における一般的なセキュリティ脆弱性を発見します。

Read more

ツールをダウンロード
  • https://github.com/lcamry/sqli-labs 通过sqli-labs演示mysql相关的注入手法
  • https://github.com/c0ny1/upload-labs 一个帮你总结所有类型的上传漏洞的靶场
  • https://github.com/LandGrey/upload-labs-writeup upload-labs指导手册
  • https://github.com/Go0s/LFIboomCTF 本地文件包含漏洞&&PHP利用协议&&实践源码
  • https://in.security/lin-security-practise-your-linux-privilege-escalation-foo/ 一个虚拟机文件用于linux提权练习
  • https://github.com/OWASP/igoat 适用于ios应用程序测试和安全性的学习工具
  • https://github.com/prateek147/DVIA-v2 适用于ios应用程序测试和安全性的学习工具
  • https://github.com/rapid7/metasploitable3 metasploit练习系统
  • https://github.com/rapid7/metasploit-vulnerability-emulator 基于perl的metasploit模拟环境,练习操作
  • https://github.com/chryzsh/DarthSidious AD域环境的搭建、渗透、防护
  • https://github.com/c0ny1/xxe-lab 一个包含php,java,python,C#等各种语言版本的XXE漏洞Demo
  • https://www.hackthebox.eu //欧洲HTB靶场,在线真实环境
  • https://www.root-me.org //俄罗斯root me靶场。在线。社区版
  • https://lab.pentestit.ru //俄罗斯靶场,真实环境。在线。商业版。
  • https://www.offensive-security.com/information-security-certifications/ //kali攻防技术认证。商业版。
  • https://www.pentesteracademy.com //教程+视频+实验室+认证培训一套。商业版。
  • https://www.cybrary.it //网络安全工程师认证。CTF/Labs
  • https://www.wechall.net //世界知名ctf汇总交流网站
  • https://www.ichunqiu.com/experiment/direction //i春秋实验室。Web/主机/应用/pwn教程
  • https://www.mozhe.cn/bug //墨者学院在线靶场。Web/主机/数据库/取证
  • https://www.xssgame.com //谷歌XSS挑战
  • http://xss.tv //在线靶场
  • https://github.com/le4f/dnsmaper web界面,子域名枚举爆破工具以及地图位置标记
  • https://github.com/thewhiteh4t/seeker 获取高精度地理信息和设备信息的工具
  • https://github.com/0xbug/orangescan web界面,的在线子域名信息收集工具
  • https://github.com/TheRook/subbrute 扫描器中常用的子域名爆破API库
  • https://github.com/We5ter/GSDF 基于谷歌SSL透明证书的子域名查询脚本
  • https://github.com/mandatoryprogrammer/cloudflare_enum 利用CloudFlare的dns进行子域名枚举
  • https://github.com/ultrasecurity/webkiller 渗透辅助,py,ip信息、端口服务指纹、蜜罐探测、bypass cloudflare
  • https://github.com/christophetd/CloudFlair cloudflare绕过,获取真实ip,集成censys
  • https://github.com/exp-db/PythonPool/tree/master/Tools/DomainSeeker 多方式收集目标子域名信息
  • https://github.com/code-scan/BroDomain 子域名查询
  • https://github.com/michenriksen/aquatone 子域名枚举、探测工具。可用于子域名接管漏洞探测
  • https://github.com/chuhades/dnsbrute 基于go,高效的子域名爆破工具
  • https://github.com/evilsocket/dnssearch 基于go,一款子域名爆破工具
  • https://github.com/OJ/gobuster 基于go,根据dns查询子域名和web目录爆破的工具
  • https://github.com/reconned/domained 可用于子域名收集的一款工具
  • https://github.com/bit4woo/Teemo 多方式域名收集及枚举工具
  • https://github.com/swisskyrepo/Subdomino 子域名枚举,端口扫描,服务存活确认
  • https://github.com/nmalcolm/Inventus 通过爬虫实现的子域名收集工具
  • https://github.com/alienwithin/OWASP-mth3l3m3nt-framework 渗透辅助,php,exp搜寻、payload与shell生产、信息搜集
  • https://github.com/chrismaddalena/ODIN py3,simple,信息搜集与后期漏洞利用
  • https://github.com/x0day/bannerscan C段/旁站查询与路径扫描
  • https://github.com/Xyntax/BingC 基于Bing搜索引擎的C段/旁站查询,多线程,支持API
  • https://github.com/zer0h/httpscan 网段Web主机发现小工具
  • https://github.com/lijiejie/BBScan 网站信息泄漏批量扫描脚本
  • https://github.com/aipengjie/sensitivefilescan 网站敏感文件扫描工具
  • https://github.com/Mosuan/FileScan 网站敏感文件扫描 / 二次判断降低误报率 / 扫描内容规则化 / 多目录扫描
  • https://github.com/Xyntax/FileSensor 网站敏感文件探测工具
  • https://github.com/ring04h/weakfilescan 多线程网站泄露信息检测工具
  • https://github.com/Viralmaniar/Passhunt simple,用于搜索网络设备Web应用程序等的默认凭证。包含523个厂家的2084组默认密码
  • https://github.com/yassineaboukir/Asnlookup simple,利用ASN搜索特定组织拥有ip,可联动nmap、masscan进行进一步信息扫描
  • https://github.com/mozilla/ssh_scan 服务器ssh配置信息扫描
  • https://github.com/18F/domain-scan 针对域名及其子域名的资产数据检测/扫描,包括http/https检测等
  • https://github.com/ggusoft/inforfinder 域名资产收集及指纹识别工具
  • https://github.com/0xbug/Howl 网络设备 web 服务指纹扫描与检索
  • https://github.com/mozilla/cipherscan 目标主机服务ssl类型识别
  • https://github.com/medbenali/CyberScan 渗透测试辅助工具,支持分析数据包、解码、端口扫描、IP地址分析等
  • https://github.com/jekyc/wig web应用信息搜集工具
  • https://github.com/eldraco/domain_analyzer 围绕web服务的域名进行信息收集和"域传送"等漏洞扫描,也支持针对背后的服务器端口扫描等
  • https://github.com/cloudtracer/paskto 基于Nikto扫描规则的被动式路径扫描以及信息爬虫
  • https://github.com/zerokeeper/WebEye 快速识别WEB服务器类型、CMS类型、WAF类型、WHOIS信息、以及语言框架
  • https://github.com/n4xh4ck5/CMSsc4n CMS指纹识别
  • https://github.com/HA71/WhatCMS CMS检测和漏洞利用脚本, 基于Whatcms.org API
  • https://github.com/boy-hack/gwhatweb CMS识别 python gevent实现
  • https://github.com/wpscanteam/wpscan 基本算是word press下最好用的工具了
  • https://github.com/swisskyrepo/Wordpresscan 基于WPScan以及WPSeku的优化版wordpress扫描器
  • https://github.com/m4ll0k/WPSeku 精简的wordpress扫描工具
  • https://github.com/rastating/wordpress-exploit-framework wordpress漏洞利用框架
  • https://github.com/Jamalc0m/wphunter php,wordpress扫描器
  • https://github.com/UltimateLabs/Zoom wordpress漏洞扫描器
  • https://github.com/immunIT/drupwn Drupal 信息收集与漏洞利用工具
  • https://github.com/CHYbeta/cmsPoc CMS渗透测试框架
  • https://github.com/chuhades/CMS-Exploit-Framework CMS攻击框架
  • https://github.com/Tuhinshubhra/CMSeeK 20多种CMS的基本检测,针对wp利用、可定制模块化爆破功能
  • https://github.com/Dionach/CMSmap 支持WordPress,Joomla和Drupal扫描
  • https://github.com/Moham3dRiahi/XAttacker Web CMS Exploit 工具,包含针对主流 CMS 的 66 个不同的 Exploits
  • https://github.com/code-scan/dzscan 首款集成化的Discuz扫描工具
  • https://github.com/bsmali4/xssfork
  • https://github.com/riusksk/FlashScanner flash xss扫描
  • https://github.com/Damian89/xssfinder 针对检测网站中的反射XSS
  • https://github.com/BlackHole1/WebRtcXSS 自动化利用XSS入侵内网
  • https://github.com/Turr0n/firebase 对没有正确配置的firebase数据库进行利用
  • https://github.com/tijme/angularjs-csti-scanner クライアント側AngularJSテンプレートインジェクション脆弱性を検出するツール
  • https://github.com/blackye/Jenkins Jenkins脆弱性の検出、ユーザー収集・ブルートフォース
  • https://github.com/epinna/tplmap サーバーサイドテンプレートインジェクション脆弱性の検出・悪用ツール
  • https://github.com/irsdl/IIS-ShortName-Scanner Java、IIS短ファイル名のブルートフォース列挙エクスプロイトツール
  • https://github.com/lijiejie/IIS_shortname_Scanner py2、IIS短ファイル名の脆弱性スキャン
  • https://github.com/rudSarkar/crlf-injector CRLFインジェクション脆弱性の一括スキャン
  • https://github.com/hahwul/a2sv SSL脆弱性スキャン。例:心脏滴血(Heartbleed)脆弱性など
  • https://github.com/jagracey/Regex-DoS RegExサービス拒否(DoS)スキャナー
  • https://github.com/Bo0oM/PHP_imap_open_exploit imap_openを利用してphpのexec関数無効化をバイパス
  • https://www.anquanke.com/post/id/106488 mysqlサーバー側の悪意ある設定を利用してクライアントファイルを読み取る(MySQL LOCAL INFILEを利用してクライアントファイルを読み取る方法、Read MySQL Client's File、【技術共有】MySQLを起点とした反撃の道)
  • https://www.waitalone.cn/awvs-poc.html CVE-2015-4027、AWVS10コマンド実行の脆弱性
  • http://an7isec.blogspot.com/2014/04/pown-noobs-acunetix-0day.html Pwn the n00bs - Acunetix 0day、awvs8コマンド実行の脆弱性
  • https://github.com/numpy/numpy/issues/12759 科学計算フレームワークnumpyのコマンド実行RCE脆弱性
  • https://github.com/petercunha/Jenkins-PreAuth-RCE-PoC jenkinsリモートコマンド実行
  • https://github.com/WyAtu/CVE-2018-20250 WinRar実行の脆弱性と使用方法の紹介
  • https://github.com/Ridter/CVE-2017-11882 Word文書のRTFを利用してシェルを取得、https://evi1cg.me/archives/CVE_2017_11882_exp.html
  • https://github.com/Lz1y/CVE-2017-8759 Word文書のHTAを利用してシェルを取得、http://www.freebuf.com/vuls/147793.html
  • https://fuping.site/2017/04/18/CVE-2017-0199漏洞复现过程 CVE-2017-0199脆弱性の再現手順。WORD RTF文書、msfと組み合わせて利用
  • https://github.com/tezukanice/Office8570 ppsxスライドを利用したリモートコマンド実行、https://github.com/rxwx/CVE-2017-8570
  • https://github.com/0x09AL/CVE-2018-8174-msf 現在対応しているバージョンは32ビット版IEブラウザと32ビット版Office。Webページにアクセスするとセッションが確立され、ブラウザを閉じてもシェルは生存し続ける、http://www.freebuf.com/vuls/173727.html
  • http://www.4hou.com/technology/9405.html Office文書のプロパティに攻撃ペイロードを隠す
  • https://evi1cg.me/archives/Create_PPSX.html PPSXフィッシングファイルを構築
  • https://github.com/enigma0x3/Generate-Macro PowerShellスクリプト。悪意のあるマクロを含むMicrosoft Office文書を生成
  • https://github.com/mwrlabs/wePWNise アーキテクチャ非依存のVBAコードを生成し、Office文書またはテンプレートに使用。アプリケーション制御を自動的にバイパス
  • https://github.com/curi0usJack/luckystrike PSベース。悪意のあるOfficeマクロ文書の作成に使用
  • https://github.com/sevagas/macro_pack MS Office文書、VBS形式、ショートカットへのペイロードバンドル
  • https://github.com/khr0x40sh/MacroShop Officeマクロを介してペイロードを配信する一連のスクリプト
  • https://xz.aliyun.com/t/2799 動的バイナリ暗号化を利用した新型一句话木马(ワンライナーWebShell)の実装、クライアント編
  • https://github.com/rebeyond/Behinder 「冰蝎(Behinder)」動的バイナリ暗号化によるWebサイト管理クライアント
  • https://xz.aliyun.com/t/2744#toc-8 動的バイナリ暗号化を利用した新型一句话木马(ワンライナーWebShell)の実装、Java編
  • https://xz.aliyun.com/t/2758#toc-4 動的バイナリ暗号化を利用した新型一句话木马(ワンライナーWebShell)の実装、.NET編
  • https://xz.aliyun.com/t/2774#toc-4 動的バイナリ暗号化を利用した新型一句话木马(ワンライナーWebShell)の実装、PHP編
  • https://github.com/lionsoul2014/ip2region IPアドレス位置特定ライブラリ。python3など複数のインターフェースに対応。geoipに類似
  • https://github.com/m101/hsploit RustベースのHEVDエクスプロイトプログラム
  • https://github.com/ticarpi/jwt_tool JSON Web Token(JWT)の検査
  • https://github.com/clr2of8/DPAT ドメインパスワード構成の監査
  • https://github.com/chenjj/CORScanner CORS(クロスオリジン)脆弱性、クロスドメインスキャナー
  • https://github.com/dienuet/crossdomain CORS(クロスオリジン)脆弱性、クロスドメインスキャナー
  • https://github.com/sfan5/fi6s ipv6ポート高速スキャナー
  • https://github.com/lavalamp-/ipv666 go、ipv6アドレス列挙スキャン
  • https://github.com/commixproject/commix コマンドインジェクション脆弱性のスキャン
  • https://github.com/Graph-X/davscan DAVScanは高速かつ軽量なwebdavスキャナーで、DAVが有効なWebサーバー上の隠しファイルやフォルダを発見することを目的とする
  • https://github.com/jcesarstef/dotdotslash ディレクトリトラバーサル脆弱性のテスト
  • https://github.com/P3GLEG/WhaleTail dockerイメージからdockerfileを生成
  • https://github.com/cr0hn/dockerscan dockerスキャンツール
  • https://github.com/utiso/dorkbot カスタマイズしたGoogle検索エンジンを使用して脆弱性ページの検索・スキャンを行う
  • https://github.com/NullArray/DorkNet 検索エンジンベースの脆弱性Webページ探索
  • https://github.com/panda-re/lava 大規模にプログラムへ悪意のあるプログラムを埋め込む
  • https://github.com/woj-ciech/Danger-zone ドメイン、IP、電子メールアドレス間のデータを関連付け、可視化して出力
  • https://github.com/securemode/DefenderKeys Windows Defenderのスキャン除外設定を列挙
  • https://github.com/D4Vinci/PasteJacker クリップボードハイジャック悪用ツール
  • https://github.com/JusticeRage/freedomfighting ログ消去、ファイル共有、リバースシェル、簡易クローラーのツールキット
  • https://github.com/gh0stkey/PoCBox 脆弱性テスト検証の補助プラットフォーム。SONPハイジャック、CORS、Flashクロスドメインリソース読み取り、Google Hack構文の生成、URLテスト辞書の生成、JavaScript URLリダイレクト、302 URLリダイレクト
  • https://github.com/jakubroztocil/httpie HTTPデバッグツール。curlに似ているが、より機能が充実
  • https://www.getpostman.com/ HTTPデバッグツール、GUI付き
  • https://github.com/theInfectedDrake/TIDoS-Framework 偵察から脆弱性分析までのすべてをカバー
  • https://github.com/gyoisamurai/GyoiThon ディープラーニングを使用したペネトレーションテストツール。毎回のスキャンデータから学習し、スキャン回数が多いほど検出精度が高くなる
  • https://github.com/euphrat1ca/polar-scan 易语言(E-language)製の北极熊(ポーラーベア)スキャナー
  • https://github.com/euphrat1ca/yeezy-scan 椰树(ココナッツツリー)1.9スキャナー
  • https://github.com/euphrat1ca/WebCruiserWVS 軽量なC#ベースのスキャナー。椰树スキャナーの前身
  • https://github.com/Skycrab/leakScan Webインターフェース、脆弱性スキャン
  • https://github.com/az0ne/AZScanner Webインターフェースの自動脆弱性スキャナー。サブドメインのブルートフォース、ポートスキャン、ディレクトリのブルートフォース、一般的なフレームワークの脆弱性検出
  • https://github.com/boy-hack/w8scan Webインターフェース。bugscanのスキャン方式とアーキテクチャ思想に基づくスキャナー
  • https://github.com/MiniSafe/microweb Webインターフェース、bugscanベース、django
  • https://github.com/taipan-scanner/Taipan Webインターフェース、F#とC#に基づくセキュリティスキャナー
  • https://github.com/zhangzhenfeng/AnyScan Webインターフェース、python脆弱性スキャナー
  • https://github.com/Canbing007/wukong-agent Webインターフェース、python脆弱性スキャナー
  • https://github.com/dermotblair/webvulscan Webインターフェース、php、脆弱性スキャナー、PDFレポート出力に対応
  • https://github.com/jeffzh3ng/InsectsAwake Webインターフェース。Flaskアプリケーションフレームワークに基づく脆弱性スキャンシステム。ペネトレーションテストでよく使われるポートスキャン、サブドメインブルートフォースなどの機能も統合。バックエンドの脆弱性スキャンにはPocsuiteを採用
  • https://github.com/0xInfection/TIDoS-Framework py、linux、Webサイトスキャナー
  • https://github.com/secdec/adapt py、linux、Webサイトスキャナー
  • https://github.com/sullo/nikto perl、linux、kaliに組み込まれたWebサイトスキャナー
  • https://github.com/Ekultek/Zeus-Scanner Webスキャナー。Geckodriver、nmap、sqlmapと連携
  • https://github.com/blackye/lalascan OWASP Top 10脆弱性スキャンと境界資産発見機能を統合した分散型Web脆弱性スキャンフレームワーク
  • https://github.com/blackye/BkScanner BkScanner:分散型・プラグイン型のWeb脆弱性スキャナー
  • https://github.com/tlkh/prowler Raspberry Pi Clusterに基づくネットワーク脆弱性スキャンツール
  • https://github.com/netxfly/passive_scan httpプロキシベースのWeb脆弱性スキャナー
  • https://github.com/1N3/Sn1per php、自動化されたミドルウェアスキャンとデバイスフィンガープリント識別
  • https://github.com/Tuhinshubhra/RED_HAWK php、情報収集、脆弱性スキャン、フィンガープリント識別などを統合したスキャンツール
  • https://github.com/m4ll0k/Spaghetti Webアプリケーションスキャナー。フィンガープリント識別、ファイル・ディレクトリのブルートフォース、SQL/XSS/RFIなどの脆弱性スキャンに対応。struts、ShellShockなどの脆弱性スキャンにも直接使用可能
  • https://github.com/v3n0m-Scanner/V3n0M-Scanner SQLi/XSS/LFI/RFIなどの脆弱性の検出に対応したスキャナー
  • https://github.com/Yukinoshita47/Yuki-Chan-The-Auto-Pentest サブドメイン列挙、nmap、WAFフィンガープリント識別などのモジュールを統合したWebアプリケーションスキャナー
  • https://github.com/RASSec/pentestEr_Fully-automatic-scanner 標的を定めた自動テストツール
  • https://github.com/Fireflyi/lcyscan py、プラグイン型脆弱性スキャナー。レポート生成に対応
  • https://github.com/Arachni/arachni Webアプリケーション脆弱性スキャンフレームワーク。REST、RPCなどのAPI呼び出しに対応
  • https://github.com/swisskyrepo/DamnWebScanner chrome/operaプラグインに基づくパッシブ型脆弱性スキャン
  • https://github.com/0xsauby/yasuo ruby、ホスト上のサードパーティWebアプリケーションサービスの脆弱性をスキャン
  • https://github.com/yangbh/Hammer Webアプリケーションの脆弱性スキャン
  • https://github.com/viraintel/OWASP-Nettacker 自動化ペネトレーションテストフレームワーク
  • https://github.com/flipkart-incubator/watchdog 総合的なWebスキャナー兼脆弱性悪用ツール
  • https://github.com/Fplyth0ner-Combie/Bug-Project-Framework 易语言(E-language)、msfを模倣したエクスプロイトフレームワーク。EXPエディター内蔵
  • https://github.com/PowerScript/KatanaFramework py、msfを模倣したエクスプロイトフレームワーク。sshや圧縮ファイルのクラックツールも含む
  • https://github.com/m4ll0k/Galileo py2、Webサイトスキャナー
  • https://github.com/samhaxr/hackbox py2、シンプルなWebサイトスキャナー
  • https://github.com/secrary/EllaScanner py3、シンプルなパッシブ型脆弱性スキャン。過去のCVE番号脆弱性の識別に対応
  • https://github.com/m4ll0k/WAScan py、シンプル。ページ/リンク/スクリプト/フォームをスキャンし、ペイロードなどをテスト
  • https://github.com/jiangsir404/S7scan py、已用1、7種類の総合検出
  • https://github.com/hatRiot/clusterd py、シンプル、Web脆弱性の悪用
  • https://github.com/M4cs/BabySploit py、シンプル、msfを模倣
  • https://github.com/iceyhexman/onlinetools シンプル、Webインターフェース。オンラインCMSフィンガープリント識別|旁站(同一サーバーサイト)|Cセグメント|情報漏えい|産業制御(ICS)|システム|IoTセキュリティ|CMS脆弱性スキャン|ポートスキャン|など
  • https://github.com/tulpar/tulpar シンプル、さまざまなWeb脆弱性スキャンに対応
  • https://github.com/UltimateHackers/Striker シンプル。情報収集、CMSの悪用と脆弱性スキャン。Cloudflareをバイパスした偵察
  • https://github.com/0x4D31/salt-scanner Salt OpenとVulners Linux Audit APIに基づくLinux脆弱性スキャナー。JIRA、slackプラットフォームとの連携に対応
  • https://github.com/opensec-cn/kunpeng go、POC検出フレームワーク。動的リンクライブラリの形式で提供され、さまざまな言語から呼び出し可能
  • https://github.com/samratashok/nishang PowerShellスクリプト集とエクスプロイトフレームワーク

  • https://github.com/PowerShellEmpire/PowerTools PowerShellスクリプト集、更新停止

  • https://github.com/FuzzySecurity/PowerShell-Suite PowerShellスクリプト集

  • https://github.com/rvrsh3ll/Misc-Powershell-Scripts PowerShellスクリプト集

  • https://github.com/nccgroup/redsnarf ハッシュの窃取、パスワードの復号、キウイ(mimikatz)などのプログラムを密かに呼び出し、RDPの多様な利用方法、リモートでのシェル起動、痕跡の消去

  • https://github.com/BloodHoundAD/BloodHound ドメインメンバーとユーザー間の関係を分析するプログラム。PowerShellスクリプトを使用してドメイン内のsession、computer、group、userなどの情報をエクスポートし、データベースに格納して可視化分析することで、ピンポイント攻撃が可能になる。

  • https://github.com/xorrior/RemoteRecon DotNetToJScriptを利用して、スクリーンショット、キーロギング、トークン窃取、DLLと悪意のあるコードの注入を実行

  • https://github.com/SkyLined/LocalNetworkScanner ブラウザの脆弱性を利用し、相手がURLを開いたときに相手の内部ネットワーク情報をスキャン

  • https://github.com/fdiskyou/hunter Windows APIを呼び出して内部ネットワーク情報を包括的に収集

  • https://github.com/0xwindows/VulScritp 内部ネットワークペネトレーションスクリプト。バナースキャン、ポートスキャン、phpmyadmin、jenkinsなどの一般的な脆弱性エクスプロイトを含む

  • https://github.com/lcatro/network_backdoor_scanner ネットワークトラフィックに基づく内部ネットワーク探索フレームワーク

  • https://github.com/sowish/LNScan 詳細な内部ネットワーク情報スキャナ

  • https://github.com/rootlabs/nWatch nmapと連携し、組織の内部ネットワークをスキャン

  • https://github.com/m8r0wn/nullinux Linux用の内部ペネトレーションテストツール。SMBを介してOS情報、ドメイン情報、共有、ディレクトリ、ユーザーを列挙できる。

  • https://github.com/zMarch/Orc bash、Linux向けのポストエクスプロイテーションコマンド集

  • https://github.com/its-a-feature/Apfell
  • https://github.com/peterpt/fuzzbunch py2、NSAの脆弱性悪用ツール。自動インストールスクリプトとGUIを備えた遠隔操作RAT
  • https://github.com/n1nj4sec/pupy py、Windows、Linux、OSX、Androidのクロスプラットフォーム、1対多
  • https://github.com/nathanlopez/Stitch py、Windows、Mac OSX、Linuxのクロスプラットフォーム
  • https://github.com/neoneggplant/EggShell py、macOS/OSX遠隔操作、HIDコードの生成が可能、1対多
  • https://github.com/Marten4n6/EvilOSX py、macOS/OSX遠隔操作、1対多
  • https://github.com/vesche/basicRAT py3、シンプルな遠隔操作、1対多
  • https://github.com/Viralmaniar/Powershell-RAT py、スクリーンショットをgmail経由で転送
  • https://github.com/byt3bl33d3r/gcat py、gmailをC&Cサーバーとして使用
  • https://github.com/sweetsoftware/Ares py、C2通信、プロキシ対応
  • https://github.com/micle-fm/Parat py、telegramを利用したWindows向けリモートコントロールツール
  • https://github.com/ahhh/Reverse_DNS_Shell py、DNS経由で転送
  • https://github.com/iagox86/dnscat2 サーバー側はruby(Linux)、クライアント側はC(Windows/Linux)。DNSプロトコルを利用したエンドツーエンド転送
  • https://github.com/deepzec/Grok-backdoor py、ngrokを利用したバックドア
  • https://github.com/trustedsec/trevorc2 py、正規のWebサイト(閲覧可能)を構築し、コマンド実行のクライアント/サーバー通信を隠蔽
  • https://guif.re/linuxeop Linux権限昇格コマンド集

  • https://github.com/alpha1ab/CVE-2018-8120 win7とwin2k8に加えて、winXPとwin2k3にも対応
  • https://github.com/0xbadjuju/Tokenvator Windowsトークンを使用して権限を昇格するツール。対話型コマンドラインインターフェースを提供
  • https://github.com/Cn33liz/StarFighters DotNetToJScriptベース。JavaScriptとVBScriptを利用してEmpire Launcherを実行
  • https://github.com/mdsecactivebreach/SharpShooter DotNetToJScriptベースでjs、vbsを使用し、任意のCSharpソースコードを取得・実行するためのpayload作成フレームワーク
  • https://github.com/mdsecactivebreach/CACTUSTORCH DotNetToJScriptベースでjs、vbsを使用して悪意のあるpayloadを生成
  • https://github.com/OmerYa/Invisi-Shell PowerShellファイルを難読化
  • https://github.com/danielbohannon/Invoke-DOSfuscation PowerShellファイルの難読化、暗号化操作、再エンコーディング
  • https://github.com/danielbohannon/Invoke-Obfuscation PowerShellファイルの難読化、暗号化操作、再エンコーディング
  • https://github.com/Mr-Un1k0d3r/SCT-obfuscator Cobalt Strike SCTペイロード難読化ツール
  • https://github.com/tokyoneon/Armor bash、暗号化されたPayloadを生成してmacOS上でリバースシェルを取得
  • https://github.com/Mr-Un1k0d3r/MaliciousMacroGenerator マクロ難読化。AV/サンドボックス回避メカニズムも含む
  • https://github.com/Kkevsterrr/backdoorme py3、py2の多種多様なバックドア、シェル生成ツール。権限を自動的に永続化できる
  • https://github.com/TestingPens/MalwarePersistenceScripts Windows向け権限永続化スクリプト
  • https://github.com/mhaskar/Linux-Root-Kit py、シンプル、Linux向けrootkit
  • https://github.com/PinkP4nther/Sutekh シンプルなrootkit。一般ユーザーにrootシェルを取得させる
  • https://github.com/threatexpress/metatwin あるファイルからデジタル署名を含むメタデータを抽出し、別のファイルに注入する
  • https://github.com/Mr-Un1k0d3r/Windows-SignedBinary バイナリファイルのHASHを変更しつつ、Microsoft Windowsの署名を保持できる
  • https://github.com/secretsquirrel/Sig- https://github.com/alphardex/looter 軽量クローラーフレームワーク、Scrapyに類似
  • https://github.com/luyishisi/Anti-Anti-Spider アンチクローリング対策の回避
  • https://github.com/xchaoinfo/fuck-login 一般的なWebサイトのログインをシミュレート
  • https://github.com/Maicius/InterestingCrawler QQ空間のつぶやき(说说)コンテンツをクロールして分析する
  • https://github.com/xjr7670/QQzone_crawler QQ空間タイムラインクローラー。cookieログインを利用して、アクセス可能な友人の空間のタイムラインをすべて取得しローカルに保存
  • https://github.com/haccer/tweep Twitter APIを使用した情報のクロール・クエリ
  • https://github.com/MazenElzanaty/TwLocation py、Twitterユーザーのツイート投稿場所を取得
  • https://github.com/vaguileradiaz/tinfoleak Webインターフェース、特定の人物のTwitterを全面的にインテリジェンス分析する
  • https://github.com/deepfakes 偽の音声・動画の作成
  • https://www.jianshu.com/p/147cf5414851 よくある偵察系アプリについて語る
  • https://github.com/thinkst/canarytokens 重要ファイルの追跡・発信元特定、ビーコン位置特定(https://canarytokens.org/generate#)
  • https://github.com/ggerganov/kbd-audio c++、Linux、マイクを利用してキーボード入力を監視し入力値をテストする
  • https://github.com/n0pe-sled/Postfix-Server-Setup フィッシングサーバーを自動構築する
  • https://github.com/Dionach/PhEmail py2、フィッシングとメール偽装
  • https://github.com/PHPMailer/PHPMailer 世界で最も人気のあるPHPメール送信コード
  • http://tool.chacuo.net/mailanonymous オンラインメール偽装
  • http://ns4gov.000webhostapp.com オンラインメール偽装
  • https://github.com/yassineaboukir/CVE-2018-0296 Cisco ASAのパストラバーサル脆弱性をテストし、システムの詳細情報を取得できる
  • https://github.com/seclab-ucr/tcp_exploit TCPの脆弱性を利用してワイヤレスルーターにプライバシー漏えいを引き起こす
  • https://github.com/ezelf/CVE-2018-9995_dvr_credentials CVE-2018-9995カメラルーター、Get DVR Credentials
  • https://github.com/RUB-NDS/PRET プリンター攻撃フレームワーク
  • https://github.com/rapid7/IoTSeeker IoTデバイスのデフォルトパスワードスキャン検出ツール
  • https://github.com/schutzwerk/CANalyzat0r 専用自動車プロトコルのセキュリティ分析ツールキット
  • https://github.com/pasta-auto スマートカー試験
  • https://github.com/Hell0W0rld0/Github-Hunter GitHub情報監視スクリプト
  • https://github.com/awslabs/git-secrets 機密データがgitリポジトリにコミットされるのを防ぐツール
  • https://github.com/zricethezav/gitleaks goベース、gitリポジトリ内のパスワード情報とキーを検査
  • http://qpdf.sourceforge.net/ PDFファイルを表示し情報を整理・抽出する
  • http://zipinfo.com/ 解凍せずにzipファイルの内容情報を一覧表示する
  • http://f00l.de/pcapfix/ pcapファイルの修復
  • https://www.cgsecurity.org/wiki/TestDisk ディスクパーティションの修復
  • https://github.com/decalage2/oletools py、MS OLE2ファイル(構造化ストレージ、複合ファイルバイナリ形式)およびMS Officeドキュメントの分析用
  • https://www.xplico.org/download メモリフォレンジック
  • https://github.com/google/bochspwn-reloaded Bochspwn Reloaded(カーネル情報漏えい検出)ツール
  • https://github.com/abrignoni/DFIR-SQL-Query-Repo データフォレンジック用のSQLクエリテンプレートを収集
  • https://www.freebuf.com/news/193684.html iOSフォレンジックのテクニック:無損失でSQLiteデータベースを完全にエクスポートする
  • https://github.com/joxeankoret/pigaios
  • https://github.com/viper-framework py2、バイナリ分析・管理フレームワーク、悪意のあるファイルの分析用
  • https://github.com/netxfly/sec_check 情報収集(アカウント、接続、ポートなど)とYaraスキャンによるセキュリティ検出
  • https://github.com/nao-sec/tknk_scanner Yaraエンジンをベースにしたマルウェア識別フレームワーク
  • https://github.com/felixweyne/ProcessSpawnControl PowerShell、悪意のあるプロセスの検出と監視
  • https://github.com/Aurore54F/JaSt 構文を使用して悪意のある/難読化されたJSファイルを検出する、https://www.blackhoodie.re/assets/archive/JaSt_blackhoodie.pdf
  • http://edr.sangfor.com.cn/ Windows、Linux向けマルウェア、Webshell検出・駆除ツール
  • http://www.clamav.net/downloads ウイルス検出・駆除ソフトウェア
  • http://www.chkrootkit.org/ rootkit検出ツール
  • http://rootkit.nl/projects/rootkit_hunter.html rootkit検出ツール