Skip to content
KitploitKITPLOIT
ツールエクスプロイトブログ
Log in
提出
ツールエクスプロイトブログ
提出

ハッキング、侵入テスト、サイバーセキュリティツールをあなたのセキュリティアーセナルに!

Kitploitはハッキング、サイバーセキュリティ、ペネトレーションテストのツールディレクトリです。最新のプロジェクトアップデートを見つけて、脆弱性の発見、システム分析、テストの自動化、セキュリティの強化を行いましょう。

··フィード·お問い合わせ·プライバシー·© 2026 Kitploit

ツールディレクトリ

カテゴリ

すべてのカテゴリを見る
Loading categories
Red-Team — Red-Team攻撃ガイド | Kitploit
ツール/GitHubGitHub/al1ex/red-team
エクスプロイト情報収集ウェブセキュリティCTFペネトレーションテスト学習と教育レッドチーミング厳選リソース
GitHubal1ex/red-team

Red-Team

Red-Team攻撃ガイド

リポジトリを見る
28067165年前Kitploit レビュー済み

人気

すべて見る →

コミュニティで最も使われているツールを見つけましょう。

すべてのツールを探索

ツールコレクションを閲覧

すべてのツールを見る →
共有

项目简介

项目用于收集和归纳Red Team的以下几个方面

  • Red Team攻击思维

  • Red Team攻击工具

  • Red Team攻击方法

精华内容

  • https://mitre-attack.github.io/ mitre科技机构对攻击技术的总结wiki
  • https://huntingday.github.io MITRE | ATT&CK 中文站
  • https://arxiv.org 康奈尔大学(Cornell University)开放文档
  • http://www.owasp.org.cn/owasp-project/owasp-things OWASP项目
  • http://www.irongeek.com/i.php?page=security/hackingillustrated 国内外安全大会相关视频与文档
  • https://github.com/knownsec/KCon KCon大会文章PPT
  • https://github.com/SecWiki/sec-chart 各种相关安全思维导图集合
  • https://github.com/knownsec/RD_Checklist 知道创宇技能列表
  • https://github.com/ChrisLinn/greyhame-2017 灰袍技能书2017版本
  • https://github.com/Hack-with-Github/Awesome-Hacking GitHub万星推荐:黑客成长技术清单
  • https://github.com/k4m4/movies-for-hackers 安全相关电影
  • https://github.com/jaredthecoder/awesome-vehicle-security 车辆安全和汽车黑客的资源清单
  • https://www.jianshu.com/p/852e0fbe2f4c 安全产品厂商分类
  • https://www.reddit.com/r/Python/comments/a81mg3/the_entire_mit_intro_computer_science_class_using/ 麻省理工机器学习视频
  • https://github.com/fxsjy/jieba py,结巴中文分词
  • https://github.com/thunlp/THULAC-Python py,清华中文分词
  • https://github.com/lancopku/PKUSeg-python py3,北大中文分词
  • https://github.com/fengdu78/Coursera-ML-AndrewNg-Notes 吴恩达机器学习python笔记
  • https://paperswithcode.com/sota 机器学习具体项目、演示、代码
  • https://github.com/duoergun0729/nlp 一本开源的NLP(神经语言程序学)入门书籍
  • https://www.freebuf.com/articles/web/195304.html 一句话木马的套路

攻防测试

系列内容

  • https://micropoor.blogspot.com/2019/01/php8.html PHP安全新闻早8点课程系列高持续渗透--Microporor
  • https://github.com/Micropoor/Micro8 Microporor高级攻防100课
  • https://github.com/maskhed/Papers 包含100课等经典攻防教材、安全知识
  • https://github.com/infosecn1nja/AD-Attack-Defense 红蓝方攻防手册
  • https://github.com/yeyintminthuhtut/Awesome-Red-Teaming 优秀红队资源列表
  • https://github.com/foobarto/redteam-notebook 红队标准渗透测试流程+常用命令
  • https://github.com/tom0li/collection-document 文章收集:安全部、SDL、src、渗透测试、漏洞利用
  • https://github.com/kbandla/APTnotes 各种公开的文件和相关的APT笔记,还有软件样本
  • https://wizardforcel.gitbooks.io/web-hacking-101/content Web Hacking 101 中文版
  • https://techvomit.net/web-application-penetration-testing-notes/ web渗透测试笔记
  • https://github.com/qazbnm456/awesome-web-security Web安全资料和资源列表
  • http://pentestmonkey.net/category/cheat-sheet 渗透测试常见条目
  • https://github.com/demonsec666/Security-Toolkit 渗透攻击链中常用工具及使用场景
  • https://github.com/Kinimiwar/Penetration-Testing 渗透测试方向优秀资源收集
  • https://github.com/jshaw87/Cheatsheets 渗透测试/安全秘籍/笔记

基础安全

  • https://book.yunzhan365.com/umta/rtnp/mobile/index.html 网络安全科普小册子
  • http://sec.cuc.edu.cn/huangwei/textbook/ns/ 网络安全电子版教材。中传信安课程网站
  • https://mitre.github.io/attack-navigator/enterprise/ mitre机构att&ck入侵检测条目
  • https://github.com/danielmiessler/SecLists 表类型包括用户名,密码,URL,敏感数据模式,模糊测试负载,Web shell等
  • https://github.com/GitGuardian/APISecurityBestPractices api接口测试checklist
  • https://github.com/ym2011/SecurityManagement 分享在建设安全管理体系、ISO27001、等级保护、安全评审过程中的点点滴滴
  • https://mp.weixin.qq.com/s/O36e0gl4cs0ErQPsb5L68Q 区块链,以太坊智能合约审计 CheckList
  • https://github.com/slowmist/eos-bp-nodes-security-checklist 区块链,EOS bp nodes security checklist(EOS超级节点安全执行指南)
  • https://xz.aliyun.com/t/2089 金融科技SDL安全设计checklist
  • https://github.com/juliocesarfort/public-pentesting-reports 由几家咨询公司和学术安全组织发布的公共渗透测试报告的列表。
  • http://www.freebuf.com/articles/network/169632.html 开源软件创建SOC的一份清单
  • https://github.com/0xRadi/OWASP-Web-Checklist owasp网站检查条目
  • https://www.securitypaper.org/ SDL开发安全生命周期管理
  • https://github.com/Jsitech/JShielder linux下服务器一键加固脚本
  • https://github.com/wstart/DB_BaseLine 数据库基线检查工具

学习手册

  • https://github.com/HarmJ0y/CheatSheets 多个项目的速查手册(Beacon / Cobalt Strike,PowerView,PowerUp,Empire和PowerSploit)
  • https://wizardforcel.gitbooks.io/kali-linux-web-pentest-cookbook/content/ Kali Linux Web渗透测试秘籍 中文版
  • https://github.com/louchaooo/kali-tools-zh kali下工具使用介绍手册
  • https://www.offensive-security.com/metasploit-unleashed/ kali出的metasploit指导笔记
  • http://www.hackingarticles.in/comprehensive-guide-on-hydra-a-brute-forcing-tool/ hydra使用手册
  • https://www.gitbook.com/book/t0data/burpsuite/details burpsuite实战指南
  • https://zhuanlan.zhihu.com/p/26618074 Nmap扩展脚本使用方法
  • https://somdev.me/21-things-xss/ XSS的21个扩展用途
  • https://www.netsparker.com/blog/web-security/sql-injection-cheat-sheet/ sql注入sheet表
  • https://sqlwiki.netspi.com/ 你要的sql注入知识点都能找到
  • https://github.com/kevins1022/SQLInjectionWiki 一个专注于聚合和记录各种SQL注入方法的wiki
  • https://github.com/hardenedlinux/linux-exploit-development-tutorial Linux exploit 开发入门
  • https://wizardforcel.gitbooks.io/asani/content 浅入浅出Android安全 中文版
  • https://wizardforcel.gitbooks.io/lpad/content Android 渗透测试学习手册 中文版
  • https://github.com/writeups/ios ios漏洞writeup笔记
  • http://blog.safebuff.com/2016/07/03/SSRF-Tips/ ssrf漏洞利用手册

学习靶场

  • https://www.blackmoreops.com/2018/11/06/124-legal-hacking-websites-to-practice-and-learn/ 124个合法的可以练习Hacking技术的网站
  • https://www.zhihu.com/question/267204109 学web安全去哪里找各种各样的靶场?
  • https://www.vulnhub.com 许多ctf靶机汇总
  • https://www.wechall.net 世界知名ctf汇总交流网站
  • https://www.xssgame.com 谷歌XSS挑战
  • http://xss.tv 在线靶场挑战
  • https://www.hackthebox.eu 在线靶场挑战
  • https://www.root-me.org 在线靶场挑战
  • http://www.itsecgames.com bWAPP,包含 100多种漏洞环境
  • https://github.com/c0ny1/vulstudy 多种漏洞复现系统的docker汇总
  • https://github.com/bkimminich/juice-shop 常见web安全实验靶场市场
  • https://github.com/ethicalhack3r/DVWA web安全实验靶场
  • https://www.freebuf.com/articles/web/123779.html 新手指南:DVWA-1.9全级别教程
  • https://github.com/78778443/permeate php,常见漏洞靶场
  • https://github.com/gh0stkey/DoraBox php,常见漏洞靶场
  • https://github.com/stamparm/DSVW py2,常见漏洞靶场
  • https://github.com/amolnaik4/bodhi py,常见漏洞靶场
  • https://github.com/Safflower/Solve-Me php,韩国一个偏代码审计的ctf靶场源码
  • https://github.com/WebGoat/WebGoat 一键jar包,web安全实验靶场
  • https://github.com/Audi-1/sqli-labs 基于SQLite的sql注入学习靶场
  • https://github.com/lcamry/sqli-labs 通过sqli-labs演示mysql相关的注入手法
  • https://github.com/c0ny1/upload-labs 一个帮你总结所有类型的上传漏洞的靶场
  • https://github.com/LandGrey/upload-labs-writeup upload-labs指导手册
  • https://github.com/Go0s/LFIboomCTF 本地文件包含漏洞&&PHP利用协议&&实践源码
  • https://in.security/lin-security-practise-your-linux-privilege-escalation-foo/ 一个虚拟机文件用于linux提权练习
  • https://github.com/OWASP/igoat 适用于ios应用程序测试和安全性的学习工具
  • https://github.com/prateek147/DVIA-v2 适用于ios应用程序测试和安全性的学习工具
  • https://github.com/rapid7/metasploitable3 metasploit练习系统
  • https://github.com/rapid7/metasploit-vulnerability-emulator 基于perl的metasploit模拟环境,练习操作
  • https://github.com/chryzsh/DarthSidious AD域环境的搭建、渗透、防护
  • https://github.com/c0ny1/xxe-lab 一个包含php,java,python,C#等各种语言版本的XXE漏洞Demo
  • https://www.hackthebox.eu //欧洲HTB靶场,在线真实环境
  • https://www.root-me.org //俄罗斯root me靶场。在线。社区版
  • https://lab.pentestit.ru //俄罗斯靶场,真实环境。在线。商业版。
  • https://www.offensive-security.com/information-security-certifications/ //kali攻防技术认证。商业版。
  • https://www.pentesteracademy.com //教程+视频+实验室+认证培训一套。商业版。
  • https://www.cybrary.it //网络安全工程师认证。CTF/Labs
  • https://www.wechall.net //世界知名ctf汇总交流网站
  • https://www.ichunqiu.com/experiment/direction //i春秋实验室。Web/主机/应用/pwn教程
  • https://www.mozhe.cn/bug //墨者学院在线靶场。Web/主机/数据库/取证
  • https://www.xssgame.com //谷歌XSS挑战
  • http://xss.tv //在线靶场

信息收集

ツールをダウンロード