
品質の高い安全に関する記事のコレクション。素晴らしい記事。
品質・安全記事のコレクション(再構築予定)```
Some are inconvenient to release.
Some forget update,can see me star.
collection-document awesome
以前的链接中大多不是优质的
渗透测试部分不再更新
因精力有限,缓慢更新
Author: [tom0li]
Blog: https://tom0li.github.io
- [Project Description](#project-description)
- [Github-list](#github-list)
- [Awesome-list](#awesome-list)
- [開発](#开发)
- [その他](#其它)
- [セキュリティ](#安全)
- [セキュリティリスト](#安全list)
- [セキュリティ市場洞察](#安全市场洞察)
- [クラウドセキュリティ](#云安全)
- [クラウド基礎知識](#云基础知识)
- [クラウドネイティブセキュリティ](#云原生安全)
- [クラウド上の攻防](#云上攻防)
- [VM](#vm)
- [vCenter](#vcenter)
- [SLP](#slp)
- [AIセキュリティ](#ai安全)
- [新しいセキュリティソリューション](#新安全方案)
- [次世代セキュリティの構築](#构建下一代安全)
- [ゼロトラスト](#零信任)
- [DevSecOps](#devsecops)
- [脅威検出](#威胁检测)
- [RASP](#rasp)
- [HIDS](#hids)
- [WAF](#waf)
- [WAF構築ガイド](#waf建设指南)
- [BypassWAF](#bypasswaf)
- [Webshell検出](#webshell检测)
- [リバースシェル検出](#反弹shell检测)
- [EDR](#edr)
- [AV](#av)
- [横方向移動検出-ハニーポットのアイデア](#横向移动检测-蜜罐思路)
- [悪意トラフィック検出](#恶意流量检测)
- [IDS](#ids)
- [テキスト検出](#文本检测)
- [セキュリティ運用](#安全运营)
- [データセキュリティ](#数据安全)
- [ネットワークマッピング](#网络测绘)
- [通信セキュリティ](#通信安全)
- [エンドツーエンド通信(初版)](#端对端通信初版)
- [SNI](#sni)
- [個人セキュリティ](#个人安全)
- [APT研究](#apt研究)
- [高度脅威-list](#高级威胁-list)
- [脅威インテリジェンス](#威胁情报)
- [フィッシング](#钓鱼)
- [C2-RAT](#c2-rat)
- [警告&研究](#预警研究)
- [ImageMagick](#imagemagick)
- [Exchange](#exchange)
- [Privilege-Escalation](#privilege-escalation)
- [VPN](#vpn)
- [Sangfor](#sangfor)
- [Pulse](#pulse)
- [Palo](#palo)
- [Fortigate](#fortigate)
- [Citrix Gateway/ADC](#citrix-gatewayadc)
- [Tomcat](#tomcat)
- [FUZZING](#fuzzing)
- [コード監査-JAVA](#代码审计-java)
- [逆シリアル化-その他](#反序列化-其他)
- [RMI](#rmi)
- [Shiro](#shiro)
- [Fastjson](#fastjson)
- [Dubbo](#dubbo)
- [CAS](#cas)
- [Solrテンプレートインジェクション](#solr模版注入)
- [Apache Skywalking](#apache-skywalking)
- [Spring](#spring)
- [Spring-boot](#spring-boot)
- [Spring-cloud](#spring-cloud)
- [Spring-data](#spring-data)
- [ブロックチェーン](#区块链)
- [ペネトレーション](#渗透)
- [境界ペネトレーション](#边界渗透)
- [ペネトレーション記録とまとめ](#渗透记录和总结)
- [情報収集](#信息收集)
- [訓練場](#靶场)
- [ペネトレーションテクニック](#渗透技巧)
- [内部ネットワークペネトレーション](#内网渗透)
- [Exchange悪用(旧)](#exchange利用旧)
- [hash ticket Credential](#hash-ticket-credential)
- [プロキシ転送とポート再利用](#代理转发与端口复用)
- [内部ネットワークプラットフォーム](#内网平台)
- [内部ネットワークテクニック](#内网技巧)
- [権限昇格悪用](#提权利用)
- [Bug_Bounty](#bug_bounty)
- [Web](#web)
- [XXE](#xxe)
- [XSS](#xss)
- [Jsonp](#jsonp)
- [CORS](#cors)
- [CSRF](#csrf)
- [SSRF](#ssrf)
- [SQL](#sql)
- [ファイルインクルード](#文件包含)
- [アップロード](#上传)
- [任意ファイル読み取り](#任意文件读取)
- [Webキャッシュなりすまし](#web缓存欺骗)
- [Webキャッシュポイズニング](#web缓存投毒)
- [SSI](#ssi)
- [SSTI](#ssti)
- [JS](#js)
- [DNS](#dns)
- [その他](#其他)
- [Git](#git)
- [QRコード](#二维码)
- [クローラー](#爬虫)
- [効率](#效率)
- [科学普及](#科普)
- [Contribute](#contribute)
- [Acknowledgments](#acknowledgments)
- [Star](#star)
## Github-list
### Awesome-list
* [awesome-web-security](https://github.com/qazbnm456/awesome-web-security)
* [Awesome-Hacking](https://github.com/Hack-with-Github/Awesome-Hacking) - 万星リスト
* [awesome-malware-analysis](https://github.com/rshipp/awesome-malware-analysis)
* [Android Security](https://github.com/ashishb/android-security-awesome) - Collection of Android security related resources.
* [Security](https://github.com/sbilly/awesome-security) - Software, libraries, documents, and other resources.
* [An Information Security Reference That Doesn't Suck](https://github.com/rmusser01/Infosec_Reference)
* [Security Talks](https://github.com/PaulSec/awesome-sec-talks) - Curated list of security conferences.
* [OSINT](https://github.com/jivoi/awesome-osint) - Awesome OSINT list containing great resources.
* [The toolbox of open source scanners](https://github.com/We5ter/Scanners-Box) - The toolbox of open source scanners
* [blackhat-arsenal-tools](https://github.com/toolswatch/blackhat-arsenal-tools) - Official Black Hat Arsenal Security Tools Repository
* [awesome-iot-hacks](https://github.com/nebgnahz/awesome-iot-hacks)
* [awesome-awesome](https://github.com/emijrp/awesome-awesome)
* [Curated list of awesome lists](https://github.com/sindresorhus/awesome)
* [Awesome Awesomness](https://github.com/bayandin/awesome-awesomeness) - The List of the Lists.
* [PENTESTING-BIBLE](https://github.com/blaCCkHatHacEEkr/PENTESTING-BIBLE) - セキュリティ関連の内容
* [Web-Security-Learning](https://github.com/CHYbeta/Web-Security-Learning) - by CHYbeta
* [Software-Security-Learning](https://github.com/CHYbeta/Software-Security-Learning) - by CHYbeta
* [MiscSecNotes](https://github.com/JnuSimba/MiscSecNotes) - by JnuSimba notes
* [AndroidSecNotes](https://github.com/JnuSimba/AndroidSecNotes) - notes
* [LinuxSecNotes](https://github.com/JnuSimba/LinuxSecNotes) - notes
* [resource collection of python security and code review](https://github.com/bit4woo/python_sec)
* [Pentest_Interview](https://github.com/Leezj9671/Pentest_Interview)
* [tanjiti 情報源](https://github.com/tanjiti/sec_profile) - by 百度tanjiti 毎日クロールするセキュリティ情報源
* [CVE-Flow](https://github.com/404notf0und/CVE-Flow) - by 404notfound CVEのインクリメンタル更新の監視、深層学習に基づくCVE EXP予測と自動プッシュ
* [security_w1k1](https://github.com/euphrat1ca/security_w1k1/) euphrat1ca師匠が常に更新するセキュリティ関連のリポジトリ
### 開発
* [インターネットJavaエンジニアのステップアップ知識完全ガイド](https://github.com/doocs/advanced-java)
* [Java学習+面接ガイド ほとんどのJavaプログラマーが習得すべきコア知識を網羅](https://github.com/Snailclimb/JavaGuide)
* [Python Cheat Sheet ](https://github.com/crazyguitar/pysheeet)
* [A collection of full-stack resources for programmers.](https://github.com/charlax/professional-programming)
* [web, フロントエンド, javascript, nodejs, electron, babel, webpack, rollup, react, vue ...](https://github.com/senntyou/blogs)
* [Pythonに関する面接問題](https://github.com/taizilongxu/interview_python)
* [Python-100-Days](https://github.com/jackfrued/Python-100-Days)
* [python3-source-code-analysis](https://github.com/flaggo/python3-source-code-analysis)
* [Coding Interview University](https://github.com/jwasham/coding-interview-university)
* [tech-interview-handbook](https://github.com/yangshun/tech-interview-handbook) - good
* [面接必須基礎知識](https://github.com/CyC2018/CS-Notes)
* [CS基礎](https://github.com/selfboot/CS_Offer/)
* [アルゴリズム/深層学習/NLP面接ノート](https://github.com/imhuay/Algorithm_Interview_Notes-Chinese)
* [アルゴリズムノート](https://github.com/labuladong/fucking-algorithm)
* [データ構造とアルゴリズムの必知必会50コード実装](https://github.com/wangzheng0822/algo)
* [interview_internal_reference](https://github.com/0voice/interview_internal_reference)
* [reverse-interview](https://github.com/yifeikong/reverse-interview-zh) - 技術面接で最後に面接官に逆質問する言葉
### その他
* [情報セキュリティ従事者おすすめ書籍リスト](https://github.com/riusksk/secbook)
* [プログラマーのための英語学習ガイド v1.2](https://github.com/yujiangshui/A-Programmers-Guide-to-English)
* [中国人プログラマーが発音を間違えやすい英単語](https://github.com/shimohq/chinese-programmer-wrong-pronunciation)
* [開発者に役立つ法則、理論、原則、パターン](https://github.com/nusr/hacker-laws-zh)
* [SecLists](https://github.com/danielmiessler/SecLists) - Collection of multiple types of lists used during security assessments.
* [A collection of web attack payloads](https://github.com/foospidy/payloads) ペイロード集
* [セキュリティ関連マインドマップ整理収集](https://github.com/phith0n/Mind-Map) - by p牛
* [セキュリティマインドマップ集合](https://github.com/SecWiki/sec-chart) -by SecWiki
* [Android-Reports-and-Resources](https://github.com/B3nac/Android-Reports-and-Resources) - HackerOne Reports
* [AppSec](https://github.com/paragonie/awesome-appsec) - Resources for learning about application security.
* [Infosec](https://github.com/onlurking/awesome-infosec) - Information security resources for pentesting, forensics, and more.
* [YARA](https://github.com/InQuest/awesome-yara) - YARA rules, tools, and people.
* [macOS-Security-and-Privacy-Guide](https://github.com/drduh/macOS-Security-and-Privacy-Guide)
* [awesome-security-weixin-official-accounts](https://github.com/DropsOfZut/awesome-security-weixin-official-accounts)
* [2018-2020青年セキュリティサークル-アクティブな技術ブロガー/ブログ](https://github.com/404notf0und/Security-Data-Analysis-and-Visualization) - by 404notf0und
* [996.Leave](https://github.com/623637646/996.Leave)
* [賃貸のポイント、北京・上海・広州・深圳・杭州対応](https://github.com/soulteary/tenant-point)
* [北京の家購入](https://github.com/facert/beijing_house_knowledge)
* [北京の家購入図鑑](https://github.com/yangyiRunning/Beijing-House)
* [上海の家購入](https://github.com/ayuer/shanghai_house_knowledge)
* [杭州の家購入](https://github.com/houshanren/hangzhou_house_knowledge)
* [awesome-macOS](https://github.com/iCHAIT/awesome-macOS) - macソフトウェア
* [awesome-mac](https://github.com/jaywcjlove/awesome-mac/blob/master/README-zh.md#%E5%BC%80%E5%8F%91%E8%80%85%E5%B7%A5%E5%85%B7) - macソフトウェア
* [ruanyf](https://github.com/ruanyf/weekly) - テクノロジー愛好家週刊
## セキュリティ
### セキュリティlist
* [arxiv.org](https://arxiv.org/) 論文ライブラリ
* [404notf0und学習記録](https://github.com/404notf0und/Always-Learning#APT%E6%A3%80%E6%B5%8B) セキュリティ検出部分に注目
* [Donot師匠が収集した侵入検出関連の内容](https://github.com/donot-wong/SecAcademic)
* [鄭瀚-Blog](https://www.cnblogs.com/littlehann/) 全体を見る
* [cdxy-Blog](https://www.cdxy.me/) とてもかっこいい
* [zuozuovera-Blog](https://www.zuozuovera.com/) 器用で賢い
* [セキュリティ学術サークル2018年度まとめ](https://mp.weixin.qq.com/s/eQ5os0Fdb498BoQLKUDmrA) - WeChatアカウント:セキュリティ学術サークル
* [security-hardening](https://github.com/decalage2/awesome-security-hardening) セキュリティ強化大全
### セキュリティ市場洞察
セキュリティ市場の概要、トレンド、法則を紹介。国内外のセキュリティ事業ベンダー。
* [XDefセキュリティサミット2021](https://mp.weixin.qq.com/s/RlEu_qVaj1rIhBuf0vQp8g)
### クラウドセキュリティ
#### クラウド基礎知識
* [仮想化入門](https://yuvaly0.github.io/2020/06/19/introduction-to-virtualization.html)
* [kvm](https://github.com/yifengyou/learn-kvm) yifengyou師匠のKVMノート
#### クラウドネイティブセキュリティ
* [Google:BeyondProdモデル](https://cloud.google.com/security/beyondprod?hl=zh-cn)
* [美団クラウドネイティブのコンテナセキュリティ実践](https://tech.meituan.com/2020/03/12/cloud-native-security.html)
* [クラウドネイティブ侵入検出トレンド観察](https://xz.aliyun.com/t/7841)
* [クラウドネイティブがもたらすクラウドセキュリティの機会](https://www.freebuf.com/articles/network/242950.html) クラウドネイティブセキュリティ市場概要(非技術)
* [アリババクラウドセキュリティホワイトペーパー](https://github.com/tom0li/collection-document/blob/master/%E9%98%BF%E9%87%8C%E4%BA%91%E5%AE%89%E5%85%A8%E7%99%BD%E7%9A%AE%E4%B9%A6.pdf)
#### クラウド上の攻防
* [Awesome-serverless](https://github.com/puresec/awesome-serverless-security/)
* [クラウドネイティブペネトレーション](https://mp.weixin.qq.com/s/Aq8RrH34PTkmF8lKzdY38g) neargle師匠のクラウドネイティブペネトレーション記録。クラウドネイティブペネトレーションで遭遇する可能性のあるサービスと対応するテストの考え方を紹介。現在国内で公開されているクラウドネイティブペネトレーション概論の中で最も完全なもの。
* [Red Teaming for Cloud](https://mp.weixin.qq.com/s/lUHd6lmFl3m9BMdSC2wwcw) Red Teamとは何か、典型的なクラウドペンテストの経路を明確に説明
* [tom0li: Dockerエスケープまとめ](https://tom0li.github.io/Docker%E9%80%83%E9%80%B8%E5%B0%8F%E7%BB%93%E7%AC%AC%E4%B8%80%E7%89%88/) 攻撃の観点からDockerエスケープの3種類の方法を紹介。いくつかのエスケープの実際のシナリオとエンジニア向けの攻撃方法を紹介。
* [Kubernetes security](https://github.com/kabachook/k8s-security) This repo is a collection of kubernetes security stuff and research.
* [serverless functions攻防初探](https://www.cdxy.me/?p=836) serverless functionsの攻撃経路と防御検出手法を紹介
* [RDSデータベース攻防](https://xz.aliyun.com/t/8451) 情報漏洩による非子ACCESSKEYを介して、設定後外部ネットワークからRDS接続可能
* [容器与云的碰撞——一次对 MinIO 的测试](https://mp.weixin.qq.com/s/X04IhY9Oau-kDOVbok8wEw) 主にMinIOオブジェクトストレージのSSRF脆弱性、POST SSRF 307リダイレクトを利用
* [KubernetesにおけるHelm2のセキュリティリスク](http://rui0.cn/archives/1573) Helm2からシークレットを取得する具体的な操作を説明
* [K8s 6443バッチ侵入調査](https://www.cdxy.me/?p=833) 認証設定の不備により匿名ユーザーが特権でk8s APIにリクエスト可能、Pod作成でDockerを起動、特権Dockerを作成して悪意のあるコマンドを実行、作成したPodを削除
* [K8sペネトレーションテストのkube-apiserver悪用](https://www.cdxy.me/?p=839) 古典的な攻撃経路を紹介、取得したPod内で高権限のサービスアカウントを探す
* [K8sペネトレーションテストのetcd悪用](https://www.cdxy.me/?p=827) 未認証のetcdおよび攻撃者が証明書を持つ場合のペネトレーションコマンド、サービスアカウントトークンの読み取りコマンド、クラスタ乗っ取りコマンドを紹介
* [K8sデータセキュリティのSecrets保護対策](https://www.cdxy.me/?p=832)
* [Fantastic Conditional Access Policies and how to bypass them](https://dirkjanm.io/assets/raw/fantastic_policies_cloud_roundup.pdf) Dirk-jan師匠のAzureトピック
* [I’m in your cloud: A year of hacking Azure AD](https://dirkjanm.io/assets/raw/Im%20in%20your%20cloud%20bluehat-v1.0.pdf) Dirk-jan師匠のAzureトピック
* [Istioアクセス認可に再び高リスク脆弱性CVE-2020-8595](https://mp.weixin.qq.com/s?__biz=MzIyODYzNTU2OA==&mid=2247487481&idx=1&sn=02a38db691331634fe41a413beb58694&chksm=e84fa926df382030ac57be9c1ee9cb8836ec37fc79e3a2cef68acb6945a51f0ed94882e39611) Istio完全一致モードのexactマッチング不備による未認証アクセス
#### VM
##### vCenter
* [CVE-2021-21972 vCenter 6.5-7.0 RCE脆弱性分析](http://noahblog.360.cn/vcenter-6-5-7-0-rce-lou-dong-fen-xi/)
* [VMware vCenter RCE脆弱性踏み抜き実録——単純なRCE脆弱性からどれだけの知識を掘り出せるか](https://mp.weixin.qq.com/s/eamNsLY0uKHXtUw_fiUYxQ) なぜBurpでパケットを修正してファイルをアップロードできないのかを紹介
##### SLP
* [CVE-2020-3992 & CVE-2021-21974: Pre-Auth Remote Code Execution in VMware ESXi ](https://www.zerodayinitiative.com/blog/2021/3/1/cve-2020-3992-amp-cve-2021-21974-pre-auth-remote-code-execution-in-vmware-esxi) 2つのCVEを紹介、VM公式がopenSLPベースでメンテナンスしているSLPにUAF脆弱性があり、パッチを回避可能
### AIセキュリティ
* [AI-for-Security-Learning](https://github.com/404notf0und/AI-for-Security-Learning) AIの力 - by 404notf0und
* [0xMJ:AI-Security-Learning](https://github.com/0xMJ/AI-Security-Learning#webshell%E6%A3%80%E6%B5%8B)
* [Adversarial ML Threat Matrix](https://github.com/mitre/advmlthreatmatrix) 機械学習システムに対する対抗
* [AIセキュリティの脅威リスクマトリックス](https://ai.tencent.com/ailab/media/AI%E5%AE%89%E5%85%A8%E7%9A%84%E5%A8%81%E8%83%81%E9%A3%8E%E9%99%A9%E7%9F%A9%E9%98%B5.pdf)
* [機械学習に基づくWeb管理バックエンド識別方法の探求](https://security.tencent.com/index.php/blog/msg/176) テンセント内部のトラフィックシステムにおけるバックエンド識別モジュール設計の概要を紹介
### 新しいセキュリティソリューション
#### 次世代セキュリティの構築
* [弾性セキュリティネットワーク - 次世代セキュアインターネットの構築](https://mp.weixin.qq.com/s/epFSC88J7LF3BGwQdoZ-Rg)
#### ゼロトラスト
* [張欧:デジタル銀行信頼できるネットワーク実践](https://mp.weixin.qq.com/s/VRG9LEbGTxhpMmCUTUSA8w) ゼロトラストの理念
* [ゼロトラスト下のプロキシツール](https://github.com/mandatoryprogrammer/CursedChrome/blob/master/README.md) Chromeをプロキシとして使用し、被害者がアクセスできるWebサービスにChrome経由でアクセス可能
#### DevSecOps
* [DevSecOpsの理念と考察](https://mp.weixin.qq.com/s/_jBmFdtyXY5D_YrrTUP1iQ) テンセントセキュリティ緊急対応センター
* [Awesome-DevSecOps](https://github.com/devsecops/awesome-devsecops)
### 脅威検出
* [セキュリティインテリジェンスアプリケーションのいくつかの迷思](https://zhuanlan.zhihu.com/p/88042567)
#### RASP
* [RASPについての簡単な議論](https://lucifaer.com/2019/09/25/%E6%B5%85%E8%B0%88RASP/)
* [OpenRASPをベースにRASPのクラスローディングを展開](https://xz.aliyun.com/t/8148)
#### HIDS
* [分散HIDSクラスタアーキテクチャ設計](https://www.cnxct.com/distributed-hids-cluster-architecture-design/) 美団技術チーム
#### WAF
##### WAF構築ガイド
* [WAF構築運用及びAI応用実践](https://mp.weixin.qq.com/s?__biz=MjM5NzE1NjA0MQ==&mid=2651199346&idx=1&sn=99f470d46554149beebb8f89fbcb1578&chksm=bd2cf2d48a5b7bc2b3aecb501855cc2efedc60f6f01026543ac2df5fa138ab2bf424fc5ab2b0&scene=21#wechat_redirect)
##### BypassWAF
* [門神WAF衆測まとめ](https://mp.weixin.qq.com/s/w5TwFl4Ac1jCTX0A1H_VbQ)
* [個人がまとめたWAFバイパスインジェクションの考え方(6種類の一般的なWAFのバイパス方法付き)](https://www.t00ls.net/viewthread.php?tid=43687&extra=&page=1)
* [ベテランが導く通常のWAF突破](https://www.secpulse.com/archives/69983.html)
* [SQLインジェクションByPassのちょっとしたテクニック](https://mp.weixin.qq.com/s/fSBZPkO0-HNYfLgmYWJKCg)
* [HTTPプロトコルレベルでWAFをバイパス](https://www.freebuf.com/news/193659.html)
* [チャンク転送を利用して全てのWAFを打ち負かす](https://www.anquanke.com/post/id/169738)
* [WAFバイパスの近道と方法](https://www.qiaoyue.net/2019/WAF%E7%BB%95%E8%BF%87%E7%9A%84%E6%8D%B7%E5%BE%84%E4%B8%8E%E6%96%B9%E6%B3%95/)
* [WAF突破に関するいくつかの認識](http://static.anquanke.com/download/b/security-geek-2019-q2/article-18.html)
* [WAF Bypassのwebshellアップロードjspとtomcat](https://www.anquanke.com/post/id/210630#)
* [様々な姿勢のjsp webshell](https://xz.aliyun.com/t/7798)
#### Webshell検出
* [Java Web Filter型メモリシェルの検出と削除](http://gv7.me/articles/2020/kill-java-web-filter-memshell/)
* [Filter/Servlet型メモリシェルのスキャン、捕捉、削除](https://gv7.me/articles/2020/filter-servlet-type-memshell-scan-capture-and-kill/)
* [JavaメモリWebshellの攻防雑談](https://mp.weixin.qq.com/s/DRbGeVOcJ8m9xo7Gin45kQ)
* [JSP Webshellのあれこれ -- 攻撃編](https://mp.weixin.qq.com/s/YhiOHWnqXVqvLNH7XSxC9w)
* [Webshell攻防PHP](https://github.com/qiyeboy/kill_webshell_detect/blob/master/%E7%9F%A5%E8%AF%86%E6%98%9F%E7%90%83-webshell%E6%94%BB%E4%B8%8E%E9%98%B2.pdf)
* [汚染伝播理論のWebshell検出への応用 - PHP編](https://mp.weixin.qq.com/s/MFmSliCQaaVEQ0E66vN5Xg)
* [新たな始まり:Webshellの検出](https://iami.xyz/New-Begin-For-Nothing/)
* [interceptorを利用したSpringメモリwebshellの注入](https://github.com/LandGrey/webshell-detect-bypass/blob/master/docs/inject-interceptor-hide-webshell/inject-interceptor-hide-webshell.md) 記事は攻撃利用の観点
#### リバースシェル検出
* [リバースシェルの原理及び検出技術研究](https://www.cnblogs.com/LittleHann/p/12038070.html) -by LittleHann
* [リバースシェル解剖](https://cloud.tencent.com/developer/article/1645464)
* [リバースシェル多次元検出技術の詳細解説](https://www.freebuf.com/articles/network/263684.html)
#### EDR
* [Lets-create-an-edr-and-bypass](https://ethicalchaos.dev/2020/06/14/lets-create-an-edr-and-bypass-it-part-2/)
* [openedr](https://github.com/ComodoSecurity/openedr) オープンソース製品EDR
#### AV
* [exploiting-almost-every-antivirus-software](https://www.rack911labs.com/research/exploiting-almost-every-antivirus-software/) AVへの対抗、リンク方式を利用してAVの高権限を借り任意ファイル削除を実現
* [Bypassing Windows Defender Runtime Scanning](https://labs.f-secure.com/blog/bypassing-windows-defender-runtime-scanning/) Defenderの検出をトリガーするAPIを列挙しテスト。CreateProcessとCreateRemoteThreadの作成時にDefenderがトリガーされることを発見。3つの解決策を提案:API呼び出しの書き換え、命令の追加修正による動的解読ロード、Defenderにその領域をスキャンさせない。著者はDefenderのスキャン機構(仮想メモリが大きい場合、MEM_PRIVATEまたはRWXページ権限のみをスキャン)に対し、疑わしいAPIが呼び出されたときにPAGE_NOACCESSメモリ権限を動的に設定することでDefenderが安全スキャンを行わないようにする。
* [Engineering antivirus evasion](https://blog.scrt.ch/2020/06/19/engineering-antivirus-evasion/)
* [Bypass Windows DefenderAttack Surface Reduction](https://data.hackinn.com/ppt/OffensiveCon2019/Bypass%20Windows%20Exploit%20Guard%20ASR.pdf)
* [Defender スキャンファイル名問題](http://2016.eicar.org/85-0-Download.html)
* [herpaderping](https://github.com/jxy-s/herpaderping) 新しいタイプのDefenderバイパス
* [実装する shellcodeLoader](https://paper.seebug.org/1413/) shellcodeの実行方法、サンドボックスバイパス方法を紹介
* [Malware_development_part](https://0xpat.github.io/Malware_development_part_5/) マルウェアシリーズチュートリアル
* [アンチウイルス検出とそのHookポイントリスト](https://github.com/D3VI5H4/Antivirus-Artifacts/blob/main/ANTIVURUS_ARTIFACTS.pdf)
#### 横方向移動検出-ハニーポットのアイデア
* [Honeypots](https://github.com/paralax/awesome-honeypots) - Honeypots, tools, components, and more.
* [Hunting for Skeleton Key Implants](https://riccardoancarani.github.io/2020-08-08-hunting-for-skeleton-keys/) Skeleton Keyの永続化を検出
* [ハニーポットアカウントを作成してKerberoastを検出](https://www.pentestpartners.com/security-blog/honeyroasting-how-to-detect-kerberoast-breaches-with-honeypots/)
#### 悪意トラフィック検出
* [DataCon2020問題解決:ハニーポットとDNSトラフィックによるボットネット追跡](https://www.cdxy.me/?p=829)
* [DNSトンネル隠蔽通信実験 && 特徴ベクトル化思考方式の検出再現試行](https://www.cnblogs.com/LittleHann/p/8656621.html#_label0)
* [maltrail](https://github.com/stamparm/maltrail#introduction) オープンソーストラフィック検出製品
* [cobalt-strike-default-modules-via-named-pipe検出](https://labs.f-secure.com/blog/detecting-cobalt-strike-default-modules-via-named-pipe-analysis/) CS接続後にデフォルトモジュールを実行するメモリパイプを検出
* [DNSデータによる脅威発見](https://mp.weixin.qq.com/s/6CtRd7o4IjreLaU-hFt9vQ) 360DNSMONによるDNS監視を使ったskidmapバックドアの発見と分析手法を紹介
* [DNSMon: DNSデータによる脅威発見](https://blog.netlab.360.com/use-dns-data-produce-threat-intelligence-2/) DNSMONでイベントを監視し、関連分析
* [evading-sysmon-dns-monitoring](https://blog.xpnsec.com/evading-sysmon-dns-monitoring/)
* [use-dns-data-produce-threat-intelligence](https://blog.netlab.360.com/use-dns-data-produce-threat-intelligence/)
#### IDS
* [IDSシグネチャについて話しましょう](https://www.anquanke.com/post/id/102948#h2-0)
* [順序通りに来ないTCPパケット](https://strcpy.me/index.php/archives/789/)
* [ネットワーク層でIDS/IPSをバイパスする探求](https://paper.seebug.org/1173/)
#### テキスト検出
* [機械学習のバイナリコード類似性分析への応用](https://mp.weixin.qq.com/s?__biz=MjM5NTc2MDYxMw==&mid=2458303210&idx=1&sn=345f8cec156ada8fa9bf6a6d6de83906&chksm=b1818a6086f60376e766baf472171d8e2c780b2913568b46b683e3112fcc5f86c9bf4c19e38b&mpshare=1&scene=1&srcid=&sharer_sharetime=1580984631757&sharer_shareid=5dc01f49f38fd64ff3e64844bc7d2ea7&exportkey=A0qHBeUryuXO6zhGWt5OJNw%3D&pass_ticket=gjTFXl4hPMTBWzlKpWZWqK8HivXQ8q7ChNndmw4I8JrdAK0jWWFvKIq7OMnO3BhL#rd)
### セキュリティ運用
* [セキュリティ業務の良し悪しを評価する方法](https://zhuanlan.zhihu.com/p/226493047) テンセント'職業欠錢'の上向き管理のいくつかの共有
### データセキュリティ
* [インターネット企業データセキュリティシステム構築](https://tech.meituan.com/2018/05/24/data-security-system-construction.html)
* [データセキュリティについての簡単な議論](https://iami.xyz/Talk-about-data-security/)
#### ネットワークマッピング
* [ネットワーク空間マッピングの奥義を簡単に語る](https://www.anquanke.com/post/id/226007)
* [ネットワーク空間マッピング技術を揺るぎないものにする](https://mp.weixin.qq.com/s/lr39F9kNOfHlMimgymzVwg) by 趙武 ネットワークマッピングの注目点
* [ネットワーク空間マッピング/検索エンジン関連の資料を記録](https://github.com/EXHades/CyberSpaceSearchEngine-Research)
### 通信セキュリティ
#### エンドツーエンド通信(初版)
* [史上最も完全なZoom脆弱性と修正方法の紹介](https://mp.weixin.qq.com/s/a7mN0lTeXxA3YmZZxIGNRg)
* [安全なインスタントメッセージングソフトウェアへのトラフィック分析攻撃](https://www.anquanke.com/post/id/208678#)
* [Shadowsocksの二次難読化暗号化転送に基づくデータ秘匿性原理分析](https://www.secrss.com/articles/18469)
#### SNI
* [ESNI](https://www.cloudflare.com/zh-cn/learning/ssl/what-is-encrypted-sni/) what-is-encrypted-sni
* [encrypted-client-hello-the-future-of-esni-in-firefox](https://blog.mozilla.org/security/2021/01/07/encrypted-client-hello-the-future-of-esni-in-firefox/)
* [encrypted-client-hello](https://blog.cloudflare.com/encrypted-client-hello/)
### 個人セキュリティ* [Tor-0day-Finding-IP-Addresses](https://www.hackerfactor.com/blog/index.php?/archives/896-Tor-0day-Finding-IP-Addresses.html)
* [lcamtuf:災難計画](https://lcamtuf.coredump.cx/prep/)
* [tom0li:個人プライバシー保護](https://tom0li.github.io/%E4%B8%AA%E4%BA%BA%E9%9A%90%E7%A7%81%E4%BF%9D%E6%8A%A4/) 一般人のプライバシー保護の考え方
* [プライバシー保護](https://github.com/No-Github/Digital-Privacy) デジタルプライバシー収集方法リスト
* [Supercookieブラウザ指紋認証](https://supercookie.me/workwise) Supercookieはファビコンを使ってウェブサイト訪問者に一意なIDを割り当てます。複数のアクセスURLでユーザーを識別
### APT研究
前半で挙げたものはほとんど攻撃に関する内容で、APT追跡レポートなどが含まれます。
#### 高度な脅威-list
* [Red-Team-Infrastructure-Wiki](https://github.com/bluscreenofjeff/Red-Team-Infrastructure-Wiki)
* [APTレポートコレクション分析](https://github.com/CyberMonitor/APT_CyberCriminal_Campagin_Collections) 強く推奨
* [高度な脅威の本質と攻撃の定量化研究について](http://www.vxjump.net/files/aptr/aptr.txt)
* [OffensiveConカンファレンス](https://www.offensivecon.org/) 個別には表示しない
* [ATT&CK](https://attack.mitre.org/matrices/enterprise/)
* [Red Team 0から1への実践と考察](https://mp.weixin.qq.com/s/cyxC4Of4Ic9c_vujQayTLg) Red Teamとは何か、チーム内部でのレッド構築に適した内容を紹介
* [MITRE | ATT&CK 日本語サイト](https://huntingday.github.io) ナレッジマップ、更新は終了
* [fireeye 脅威研究](https://www.fireeye.com/blog/threat-research.html) 著名な脅威分析企業
* [red-team-and-the-next](https://devco.re/blog/2019/10/24/evolution-of-DEVCORE-red-team-and-the-next/) -by DEVCORE
redrainとそのチームのAnti Threat記事
* [Noah blog](http://noahblog.360.cn/) Noah LabアナリストによるAnti Threatおよび脅威アクター
* [烽火ラボ blog](https://blogs.360.cn/)
* [APT分析とTTPs抽出](https://paper.seebug.org/1132/)
* [ATT&CK/APT/帰属に関する議論](https://weibo.com/ttarticle/p/show?id=2309404450471736639616)
* [Legends Always Die -- FireEye Summitでのリーグ・オブ・レジェンドサプライチェーン攻撃概要](https://card.weibo.com/article/m/show/id/2309404426957856047151) サプライチェーン攻撃の追跡、基本情報(ドメイン/IP/メールなど)と過去のAPT活動との関連付け
* [XShellGhost事件技術回顧報告](https://cert.360.cn/static/files/XShellGhost%E4%BA%8B%E4%BB%B6%E6%8A%80%E6%9C%AF%E5%9B%9E%E9%A1%BE%E6%8A%A5%E5%91%8A.pdf)
* [Kingslayer A supply chain attack](http://www.hackdog.me/article/Kingslayer-A_supply_chain_attack--Part_1.html)
Solarwindsサプライチェーン分析
* [Solarwindsサプライチェーン攻撃(金鎖熊)から見るAPT作戦における隠密戦闘](https://mp.weixin.qq.com/s/UqXC1vovKUu97569LkYm2Q) qianxinによるSolarwinds攻撃行動分析
* [Solarwinds分析](https://go.recordedfuture.com/hubfs/reports/pov-2020-1230.pdf)
* [高度に回避的な攻撃者がSolarWindsサプライチェーンを悪用し、SUNBURSTバックドアで複数の世界的被害者を侵害](https://www.fireeye.com/blog/threat-research/2020/12/evasive-attacker-leverages-solarwinds-supply-chain-compromises-with-sunburst-backdoor.html)
* [SUNBURST分析その他の詳細](https://www.fireeye.com/blog/threat-research/2020/12/sunburst-additional-technical-details.html)
#### 脅威インテリジェンス
* [北朝鮮に対する起訴状](https://www.justice.gov/opa/press-release/file/1092091/download) 10年を費やした分類プロセス
* [ネット攻撃の「帰属」についての考察](https://www.secrss.com/articles/14864) APT帰属の指標・方法(Cyber Attribution文書参照)および一部の帰属文書を紹介
* [脅威インテリジェンスとは](https://www.secrss.com/articles/16577) 脅威インテリジェンスの定義、分類、指標を紹介。事例を通じて追跡・帰属のプロセスを解説
#### フィッシング
* [SMTPユーザ列挙の原理概要と関連ツール](http://www.freebuf.com/articles/web/182746.html) - ユーザ辞書の取得に使用
* [スピアフィッシング攻撃](https://payloads.online/archivers/2020-02-05/1)
* [AWVSを使うハッカーへの対抗方法について](http://www.freebuf.com/news/136476.html)
* [MySQLからの反撃の道](https://xz.aliyun.com/t/3277)
* [Mysql Client 任意ファイル読み取り攻撃チェーン拡張](https://paper.seebug.org/1112/)
* [悪意のあるMySQL ServerがMySQL Client側ファイルを読み取る](http://scz.617.cn/network/202001101612.txt)
* [https://github.com/BloodHoundAD/BloodHound/issues/267](https://github.com/BloodHoundAD/BloodHound/issues/267) -xss
* [Ghidra XXEからRCEへ](https://xlab.tencent.com/cn/2019/03/18/ghidra-from-xxe-to-rce/) エンジニア向け
* [WeChatエクスポージャーからのセキュリティリスク](https://xlab.tencent.com/cn/2018/10/23/weixin-cheater-risks/) 個人向け
* [nodejsリポジトリフィッシング](https://www.cnblogs.com/index-html/p/npm_package_phishing.html) エンジニア向け
* [Visual Studio Code悪意あるプラグインの作成](https://d0n9.github.io/2018/01/17/vscode%20extension%20%E9%92%93%E9%B1%BC/#) エンジニア向け
* [VS CODEフィッシング](https://blog.doyensec.com/2020/03/16/vscode_codeexec.html) エンジニア向け
* [Python package フィッシング](https://paper.seebug.org/326/) エンジニア向け
* [dockerクライアントフィッシング](https://www.blackhat.com/docs/us-17/thursday/us-17-Cherny-Well-That-Escalated-Quickly-How-Abusing-The-Docker-API-Led-To-Remote-Code-Execution-Same-Origin-Bypass-And-Persistence.pdf) エンジニア向け
* [悪意あるページを利用したローカルXdebug攻撃](https://xlab.tencent.com/cn/2018/03/) エンジニア向け
* [Huawei HG532ルーターフィッシングRCE](https://xlab.tencent.com/cn/2018/01/05/a-new-way-to-exploit-cve-2017-17215/) 個人向け
* [内部ネットワークフィッシング]()```
RMI反序列化
WIN远程连接漏洞CVE-2019-1333
Mysql读文件&反序列化
Dubbo反序列化
IDE反序列化
恶意vpn
恶意控件
笔记软件rce
社交软件rce
NodeJS库rce
Python package 钓鱼
VSCODE EXTENSION 钓鱼
VS Studio钓鱼
Twitter钓鱼
红包插件钓鱼防撤回插件
解压rce
破解软件钓鱼
docker客户端钓鱼
docker镜像钓鱼
Xdebug
Ghidra钓鱼
bloodhound钓鱼
AWVS钓鱼
蚁剑
浏览器插件
云盘污染
メール偽造
現時点では簡単に列挙するだけ
以前に挙げた記事には誤った内容が含まれている場合があるため、実践で検証が必要
公式マニュアルを参照推奨
之前的想起来补上
旧```
## 貢献
皆様の貢献を歓迎します。このプロジェクトについて新しいアイデアがある場合、または質の高いセキュリティ記事を見つけた場合は、Issueを開いてください。その際、謝辞にあなたの名前を追加します。
## 謝辞
* @[tom0li](https://github.com/tom0li)
* @[neargle](https://github.com/neargle)
* @[r4v3zn](https://github.com/0nise)
## スター
スターに感謝
[](https://starchart.cc/tom0li/collection-document)
国外赏金之路 - 老司机赏金见解,历史赏金文章 list