Skip to content
KitploitKITPLOIT
도구블로그
제출
도구블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

··피드·문의·개인정보·© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
Red-Team — Red-Team Attack Guid | Kitploit
도구/GitHubGitHub/al1ex/red-team
ExploitationInformation GatheringWeb SecurityCTFPenetration TestingLearning & EducationRed TeamingCurated Resources
GitHubal1ex/red-team

Red-Team

Red-Team Attack Guid

저장소 보기
280675년 전Kitploit 검토 완료

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유

프로젝트 소개

이 프로젝트는 Red Team의 다음 측면들을 수집하고 정리하는 데 사용됩니다.

  • Red Team 공격 사고방식

  • Red Team 공격 도구

  • Red Team 공격 방법

핵심 콘텐츠

  • https://mitre-attack.github.io/ mitre 기관의 공격 기술 정리 wiki
  • https://huntingday.github.io MITRE | ATT&CK 중국어 사이트
  • https://arxiv.org 코넬 대학교(Cornell University) 오픈 문서
  • http://www.owasp.org.cn/owasp-project/owasp-things OWASP 프로젝트
  • http://www.irongeek.com/i.php?page=security/hackingillustrated 국내외 보안 컨퍼런스 관련 동영상 및 문서
  • https://github.com/knownsec/KCon KCon 컨퍼런스 발표 PPT
  • https://github.com/SecWiki/sec-chart 각종 보안 관련 마인드맵 모음
  • https://github.com/knownsec/RD_Checklist Knownsec(知道创宇) 스킬 목록
  • https://github.com/ChrisLinn/greyhame-2017 그레이 로브(灰袍) 스킬북 2017 버전
  • https://github.com/Hack-with-Github/Awesome-Hacking GitHub 1만 스타 추천: 해커 성장 기술 체크리스트
  • https://github.com/k4m4/movies-for-hackers 보안 관련 영화
  • https://github.com/jaredthecoder/awesome-vehicle-security 차량 보안 및 자동차 해킹 리소스 목록
  • https://www.jianshu.com/p/852e0fbe2f4c 보안 제품 업체 분류
  • https://www.reddit.com/r/Python/comments/a81mg3/the_entire_mit_intro_computer_science_class_using/ MIT(매사추세츠공과대학교) 머신러닝 동영상
  • https://github.com/fxsjy/jieba py, jieba(结巴) 중국어 단어 분리
  • https://github.com/thunlp/THULAC-Python py, 칭화대(清华) 중국어 단어 분리
  • https://github.com/lancopku/PKUSeg-python py3, 베이징대(北大) 중국어 단어 분리
  • https://github.com/fengdu78/Coursera-ML-AndrewNg-Notes 앤드류 응(吴恩达) 머신러닝 python 노트
  • https://paperswithcode.com/sota 머신러닝 구체적 프로젝트, 데모, 코드
  • https://github.com/duoergun0729/nlp 오픈소스 NLP(신경 언어 프로그래밍) 입문서
  • https://www.freebuf.com/articles/web/195304.html 한 줄 웹쉘(一句话木马)의 요령

공격·방어 테스트

시리즈 콘텐츠

  • https://micropoor.blogspot.com/2019/01/php8.html PHP 보안 뉴스 8시 강좌 시리즈: 고지속성 침투 -- Micropoor
  • https://github.com/Micropoor/Micro8 Micropoor 고급 공격·방어 100강
  • https://github.com/maskhed/Papers 100강 등 고전 공격·방어 교재 및 보안 지식 포함
  • https://github.com/infosecn1nja/AD-Attack-Defense 레드/블루 팀 공격·방어 매뉴얼
  • https://github.com/yeyintminthuhtut/Awesome-Red-Teaming 우수 레드 팀 리소스 목록
  • https://github.com/foobarto/redteam-notebook 레드 팀 표준 침투 테스트 프로세스 + 자주 쓰는 명령어
  • https://github.com/tom0li/collection-document 문서 모음: 보안 부서, SDL, SRC, 침투 테스트, 취약점 공격
  • https://github.com/kbandla/APTnotes 각종 공개 문서와 관련 APT 노트, 소프트웨어 샘플 포함
  • https://wizardforcel.gitbooks.io/web-hacking-101/content Web Hacking 101 중국어판
  • https://techvomit.net/web-application-penetration-testing-notes/ 웹 침투 테스트 노트
  • https://github.com/qazbnm456/awesome-web-security 웹 보안 자료 및 리소스 목록
  • http://pentestmonkey.net/category/cheat-sheet 침투 테스트에 자주 쓰이는 치트시트
  • https://github.com/demonsec666/Security-Toolkit 침투 공격 체인에서 자주 쓰는 도구 및 사용 시나리오
  • https://github.com/Kinimiwar/Penetration-Testing 침투 테스트 분야 우수 리소스 모음
  • https://github.com/jshaw87/Cheatsheets 침투 테스트/보안 치트시트/노트

기초 보안

  • https://book.yunzhan365.com/umta/rtnp/mobile/index.html 사이버 보안 대중화 소책자
  • http://sec.cuc.edu.cn/huangwei/textbook/ns/ 사이버 보안 전자 교재. CUC(중국전매대학) 정보보안 강좌 웹사이트
  • https://mitre.github.io/attack-navigator/enterprise/ mitre 기관 att&ck 침입 탐지 항목
  • https://github.com/danielmiessler/SecLists 테이블 유형에는 사용자 이름, 비밀번호, URL, 민감 데이터 패턴, 퍼징 페이로드, Web shell 등이 포함됨
  • https://github.com/GitGuardian/APISecurityBestPractices api 인터페이스 테스트 checklist
  • https://github.com/ym2011/SecurityManagement 보안 관리 체계 구축, ISO27001, 등급 보호(等级保护), 보안 심사 과정의 세세한 경험을 공유
  • https://mp.weixin.qq.com/s/O36e0gl4cs0ErQPsb5L68Q 블록체인, 이더리움 스마트 컨트랙트 감사 CheckList
  • https://github.com/slowmist/eos-bp-nodes-security-checklist 블록체인, EOS bp nodes security checklist(EOS 슈퍼노드 보안 실행 가이드)
  • https://xz.aliyun.com/t/2089 핀테크 SDL 보안 설계 checklist
  • https://github.com/juliocesarfort/public-pentesting-reports 여러 컨설팅 회사와 학술 보안 기관이 발표한 공개 침투 테스트 보고서 목록.
  • http://www.freebuf.com/articles/network/169632.html 오픈소스 소프트웨어로 SOC를 구축하기 위한 체크리스트
  • https://github.com/0xRadi/OWASP-Web-Checklist owasp 웹사이트 점검 항목
  • https://www.securitypaper.org/ SDL 개발 보안 수명주기 관리
  • https://github.com/Jsitech/JShielder linux 서버 원클릭 보안 강화 스크립트
  • https://github.com/wstart/DB_BaseLine 데이터베이스 베이스라인 점검 도구

학습 매뉴얼

  • https://github.com/HarmJ0y/CheatSheets 여러 프로젝트의 퀵 레퍼런스(Beacon / Cobalt Strike, PowerView, PowerUp, Empire 및 PowerSploit)
  • https://wizardforcel.gitbooks.io/kali-linux-web-pentest-cookbook/content/ Kali Linux 웹 침투 테스트 쿡북 중국어판
  • https://github.com/louchaooo/kali-tools-zh kali 도구 사용법 소개 매뉴얼
  • https://www.offensive-security.com/metasploit-unleashed/ kali가 제공하는 metasploit 가이드 노트
  • http://www.hackingarticles.in/comprehensive-guide-on-hydra-a-brute-forcing-tool/ hydra 사용 매뉴얼
  • https://www.gitbook.com/book/t0data/burpsuite/details burpsuite 실전 가이드
  • https://zhuanlan.zhihu.com/p/26618074 Nmap 확장 스크립트 사용 방법
  • https://somdev.me/21-things-xss/ XSS의 21가지 확장 용도
  • https://www.netsparker.com/blog/web-security/sql-injection-cheat-sheet/ sql 인젝션 치트시트
  • https://sqlwiki.netspi.com/ 필요한 sql 인젝션 지식 포인트는 모두 찾을 수 있음
  • https://github.com/kevins1022/SQLInjectionWiki 다양한 SQL 인젝션 기법을 집계·기록하는 데 특화된 wiki
  • https://github.com/hardenedlinux/linux-exploit-development-tutorial Linux exploit 개발 입문
  • https://wizardforcel.gitbooks.io/asani/content 浅入浅出 Android 보안 중국어판
  • https://wizardforcel.gitbooks.io/lpad/content Android 침투 테스트 학습 매뉴얼 중국어판
  • https://github.com/writeups/ios ios 취약점 writeup 노트
  • http://blog.safebuff.com/2016/07/03/SSRF-Tips/ ssrf 취약점 공격 매뉴얼

학습 랩

  • https://www.blackmoreops.com/2018/11/06/124-legal-hacking-websites-to-practice-and-learn/ 해킹 기술을 연습할 수 있는 합법적인 웹사이트 124곳
  • https://www.zhihu.com/question/267204109 웹 보안을 배울 때 다양한 랩(靶场)은 어디서 찾을 수 있을까?
  • https://www.vulnhub.com 다수의 CTF 타깃 머신 모음
  • https://www.wechall.net 세계적으로 유명한 CTF 집계·교류 웹사이트
  • https://www.xssgame.com Google XSS 챌린지
  • http://xss.tv 온라인 랩 챌린지
  • https://www.hackthebox.eu 온라인 랩 챌린지
  • https://www.root-me.org 온라인 랩 챌린지
  • http://www.itsecgames.com bWAPP, 100가지 이상의 취약점 환경 포함
  • https://github.com/c0ny1/vulstudy 다양한 취약점 재현 시스템의 docker 모음
  • https://github.com/bkimminich/juice-shop 일반적인 웹 보안 실험 랩 마켓
  • https://github.com/ethicalhack3r/DVWA 웹 보안 실험 랩
  • https://www.freebuf.com/articles/web/123779.html 초보자 가이드: DVWA-1.9 전체 레벨 튜토리얼
  • https://github.com/78778443/permeate php, 일반적인 취약점 랩
  • https://github.com/gh0stkey/DoraBox php, 일반적인 취약점 랩
  • https://github.com/stamparm/DSVW py2, 일반적인 취약점 랩
  • https://github.com/amolnaik4/bodhi py, 일반적인 취약점 랩
  • https://github.com/Safflower/Solve-Me php, 코드 감사 중심의 한국 CTF 랩 소스코드
  • https://github.com/WebGoat/WebGoat 원클릭 jar 패키지, 웹 보안 실험 랩

정보 수집

  • https://github.com/smicallef/spiderfoot OSINT를 이용해 대상 정보를 자동으로 파악, gui 인터페이스, 플러그인 방식
  • https://github.com/Nhoya/gOSINT go, OSINT를 이용한 정보 자동 수집
  • https://github.com/laramies/theHarvester 검색 엔진에 수집된 기업의 민감 자산 정보 모니터링 스크립트: 직원 이메일, 서브도메인, Hosts
  • https://github.com/guelfoweb/knock 브루트포스로 서브도메인 획득, 서브도메인 탈취 취약점 탐색에 사용 가능
  • https://github.com/aboul3la/Sublist3r 검색 엔진과 브루트포스를 통한 빠른 서브도메인 열거 도구
  • https://github.com/Ice3man543/subfinder go로 구현된 Sublist3r
  • https://github.com/yanxiu0614/subdomain3 py3, py2 기반 서브도메인, IP, CDN 정보 등
  • https://github.com/caffix/amass go 기반, 서브도메인 열거, 인터넷 데이터 소스 검색, 머신러닝으로 서브도메인 추측
  • https://github.com/nahamsec/lazyrecon 정찰(reconnaissance) 과정 자동화 스크립트, Sublist3r/certspotter로 서브도메인 자동 획득, nmap/dirsearch 등 호출
  • https://github.com/s0md3v/ReconDog simple, 정찰 정보의 스위스 아미 나이프
  • https://github.com/FeeiCN/ESD py3, 브루트포스 서브도메인 수집
  • https://github.com/alpha1e0/pentestdb 다목적 통합 정보 수집 도구
  • https://github.com/se55i0n/PortScanner py2, 대상 tcp 포트 고속 스캔, banner 식별, cdn 감지
  • https://github.com/lijiejie/subDomainsBrute lijiejie가 개발한 널리 쓰이는 서브도메인 브루트포스 열거 도구
  • https://github.com/ring04h/wydomain 주주샤(猪猪侠)가 개발한 도메인 수집이 포괄적이고 정밀한 서브도메인 열거 도구
  • https://github.com/n4xh4ck5/N4xD0rk 검색 엔진으로 서브도메인 수집, 스페인어로도 검색 가능
  • https://github.com/vysec/DomLink py2, WHOXY.com을 호출하여 이메일과 도메인 추가 수집

정보 유출

  • https://github.com/Yelp/detect-secrets PY, 코드의 비밀번호 등 민감 정보가 코드베이스에 커밋되는 것을 방지, 보안성을 유지하면서 개발자 생산성에는 영향을 주지 않음
  • https://github.com/Acceis/leakScraper 대규모 텍스트 파일을 처리·시각화하여 인증서 등 민감 정보 탐색
  • https://github.com/Raikia/CredNinja 멀티스레드 사용자 자격 증명 검증 스크립트, 예: 덤프된 hash가 해당 머신에 속하는지 검증, 445 포트로 프로토콜 검증
  • https://github.com/CERTCC/keyfinder 파일 시스템에서 개인키/공개키 파일 탐색·분석, Android APK 파일 지원
  • https://github.com/Ice3man543/hawkeye go, cli 기반 파일 시스템 분석 도구, 파일에 포함된 SSH 키, 로그 파일, Sqlite 데이터베이스, 비밀번호 파일 등을 빠르게 탐색
  • https://github.com/FortyNorthSecurity/EyeWitness 대상 웹사이트 스크린샷, vnc, rdp 서비스 획득, 기본 자격 증명 획득 시도
  • https://github.com/D4Vinci/Cr3dOv3r 이메일로 유출된 비밀번호 정보를 자동 검색하고, 주요 웹사이트에서 계정 비밀번호 로그인 가능 여부도 테스트하는 도구

경로 탐색

  • https://github.com/maurosoria/dirsearch 클래식 디렉터리 경로 스캔
  • https://github.com/TheM4hd1/PenCrawLer C# 인터페이스, 웹 크롤러와 디렉터리 경로 브루트포스 도구, 일반 스캔 외에 재귀 브루트포스 모드 추가
  • https://github.com/Xyntax/DirBrute 디렉터리 경로 브루트포스 도구
  • https://github.com/abaykan/crawlbox 디렉터리 경로 스캐너
  • https://github.com/deibit/cansina 디렉터리 경로 스캐너
  • https://github.com/UltimateHackers/Breacher 멀티스레드 백그라운드 경로 스캐너, Execution After Redirect 취약점 발견에도 사용 가능
  • https://github.com/fnk0c/cangibrina 사전 대입, google, robots.txt 등을 통한 크로스 플랫폼 백엔드 관리 경로 스캐너
  • https://github.com/Go0s/SitePathScan 코루틴 기반 디렉터리 경로 브루트포스 도구, aiohttp와 함께 사용하면 이전보다 3배 이상 빠른 경로 스캔
  • https://github.com/secfree/bcrpscan 크롤러 기반 웹 경로 스캐너

핑거프린트 | 포트

  • https://github.com/nmap/nmap LUA, Nmap 포트 스캐너, 강력한 스크립트 엔진 프레임워크 보유
  • https://github.com/robertdavidgraham/masscan C, 무상태(stateless) 스캔, nmap을 호출하여 핑거프린트 식별 가능
  • https://github.com/zmap/zmap C, 무상태 스캔, C로 확장 모듈 작성 필요
  • https://github.com/zmap/zgrab go, zmap 스캐너 기반 핑거프린트 식별·스케줄링 관리, CDN 우회 가능
  • https://github.com/chichou/grab.js zgrab와 유사한 고속 TCP 핑거프린트 획득·파싱 도구, 더 많은 프로토콜 지원
  • https://github.com/johnnyxmas/scancannon shell, masscan과 nmap 연동
  • https://github.com/OffensivePython/Nscan Masscan과 Zmap 기반 네트워크 스캐너
  • https://github.com/ring04h/wyportmap nmap 호출 대상 포트 스캔 + 시스템 서비스 핑거프린트 식별
  • https://github.com/angryip/ipscan Angry IP Scanner, 크로스 플랫폼 GUI 포트 스캐너
  • https://github.com/EnableSecurity/wafw00f WAF 제품 핑거프린트 식별
  • https://github.com/rbsec/sslscan ssl 유형 식별
  • https://github.com/urbanadventurer/whatweb 웹 핑거프린트 식별
  • https://github.com/Rvn0xsy/FastWhatWebSearch whatweb 도구 결과 검색 플랫폼
  • https://github.com/tanjiti/FingerPrint 웹 애플리케이션 핑거프린트 식별
  • https://github.com/nanshihui/Scan-T 웹 크롤러 방식 핑거프린트 식별
  • https://github.com/ywolf/F-MiddlewareScan 미들웨어 스캔 서비스 식별
  • https://github.com/lietdai/doom thorn에서 구현된 분산 작업 배포 ip 포트 취약점 스캐너
  • https://github.com/RASSec/RASscan 포트 서비스 스캔

파일 포함

  • https://github.com/hvqzao/liffy 로컬 파일 포함(LFI) 취약점 공격 도구
  • https://github.com/D35m0nd142/Kadabra 로컬 파일 포함(LFI) 취약점 스캔 및 공격 도구
  • https://github.com/P0cL4bs/Kadimus 로컬 파일 포함(LFI) 취약점 스캔 및 공격 도구
  • https://github.com/D35m0nd142/LFISuite 로컬 파일 포함(LFI) 취약점 공격 및 스캔 도구, 리버스 셸 지원
  • https://github.com/OsandaMalith/LFiFreak 로컬 파일 포함(LFI) 취약점 공격 및 스캔 도구, 리버스 셸 지원

업로드 취약점

  • https://github.com/UltimateHackers/Arjun 웹 페이지를 스캔하고 정규표현식 브루트포스로 숨겨진 GET/POST 파라미터 탐색
  • https://github.com/3xp10it/xupload 업로드 기능에서 webshell 업로드가 가능한지 자동으로 테스트하는 도구
  • https://github.com/gunnerstahl/JQShell py3, CVE-2018-9206 jQuery File Upload 공격 도구
  • https://github.com/destine21/ZIPFileRaider burp 플러그인, zip 파일 업로드 취약점 테스트
  • https://github.com/jpiechowka/zip-shotgun py, zip 파일 업로드 취약점 테스트

XSS 공격

  • https://github.com/UltimateHackers/AwesomeXSS XSS Awesome 시리즈
  • http://www.xss-payloads.com 매우 포괄적인 xss 툴킷과 자료
  • https://github.com/ismailtasdelen/xss-payload-list XSS 취약점 Payload 목록
  • https://github.com/beefproject/beef 클래식 xss 공격 프레임워크
  • https://github.com/samdenty99/injectify beef와 유사한 xss 공격 프레임워크
  • https://github.com/firesunCN/BlueLotus_XSSReceiver Blue Lotus(蓝莲花) 팀이 CTF를 위해 만든 xss 공격 프레임워크
  • https://github.com/NytroRST/XSSFuzzer 특정 태그에 따라 xss payload 생성
  • https://github.com/evilcos/xssor2 여현(余弦, evilcos)이 작성한 xss 공격 보조 도구
  • https://github.com/UltimateHackers/XSStrike WAF를 식별하고 우회할 수 있는 XSS 스캔 도구
  • https://github.com/raz-varren/xsshell go, xss 취약점을 이용해 js 인터랙티브 셸 반환
  • https://github.com/UltimateHackers/JShell xss 취약점을 이용해 js 인터랙티브 셸 반환
  • https://github.com/shawarkhanethicalhacker/BruteXSS XSS 스캐너, 파라미터 무차별 주입 가능
  • https://github.com/1N3/XSSTracer 소형 XSS 스캐너, CRLF, XSS, 클릭재킹도 탐지
  • https://github.com/0x584A/fuzzXssPHP PHP 버전의 반사형 xss 스캔
  • https://github.com/chuhades/xss_scan XSS를 배치 스캔하는 python 스크립트
  • https://github.com/BlackHole1/autoFindXssAndCsrf 페이지에 XSS 및 CSRF 취약점이 존재하는지 자동으로 탐지하는 브라우저 플러그인
  • https://github.com/shogunlab/shuriken 명령줄로 XSS 배치 탐지
  • https://github.com/stamparm/DSXS GET, POST 방식을 지원하는 고효율 XSS 스캐너

비밀번호 브루트포스

  • https://github.com/vanhauser-thc/thc-hydra 다양한 프로토콜 방식의 크래킹·브루트포스 지원, v8 이후로는 windows 버전 미제공
  • https://github.com/nmap/ncrack c, 다양한 프로토콜의 크래킹·브루트포스 지원
  • https://github.com/0pn1i9ht/F-Scrack ysrc의 각종 서비스 사용자 이름·비밀번호 브루트포스 스크립트
  • https://github.com/TunisianEagles/SocialBox fb, gmail, ins, twitter 대상 사용자 이름·비밀번호 브루트포스 스크립트
  • https://github.com/lanjelot/patator 다양한 프로토콜 브루트포스 지원, 모듈식 설계로 유연하게 사용
  • https://github.com/m4ll0k/SMBrute smb 서비스를 이용한 사용자 이름·비밀번호 브루트포스
  • https://github.com/netxfly/crack_ssh Go로 작성된 코루틴 버전 ssh\redis\mongodb 약한 비밀번호 크래킹
  • https://github.com/UltimateHackers/Blazy CSRF, Clickjacking, Cloudflare 및 WAF 테스트를 지원하는 약한 비밀번호 탐지기
  • https://github.com/Moham3dRiahi/XBruteForcer WordPress, Joomla, DruPal, OpenCart, Magento 등 CMS 사용자 비밀번호 브루트포스
  • https://github.com/shengqi158/weak_password_detect Linux에서 nmap을 이용한 멀티스레드 ssh 약한 비밀번호 탐지
  • https://github.com/ztgrace/changeme 약한 비밀번호 스캐너, 일반 로그인 페이지뿐 아니라 ssh, mongodb 등 컴포넌트도 지원
  • https://github.com/lijiejie/htpwdScan simple, http 무차별 대입, 크리덴셜 스터핑(撞库) 공격 스크립트
  • https://github.com/scu-igroup/ssh-scanner nmap, hydra와 연동한 ssh 배치 브루트포스

비밀번호 크래킹

  • https://securityxploded.com/download.php 비밀번호 분야의 각종 보안 소형 도구
  • https://github.com/bdutro/ibm_pw_clear IBM x3550/x3560 M3 bios 비밀번호 제거·초기화 도구
  • https://github.com/thehappydinoa/iOSRestrictionBruteForce py, iOS 접근 제한 비밀번호 크래킹 도구
  • https://github.com/hashcat/hashcat C, 해시 크래킹
  • https://github.com/fireeye/gocrack GO, hashcat 3.6.0+ 기반 분산 비밀번호 크래킹 도구
  • https://github.com/s3inlc/hashtopolis php 기반 hashcat 분산 크래킹 도구, C#과 python 클라이언트 지원
  • https://github.com/e-ago/bitcracker 최초의 오픈소스 BitLocker 비밀번호 크래킹 도구
  • https://www.ru.nl/publish/pages/909282/draft-paper.pdf SSD에서 BitLocker를 크래킹하는 논문
  • https://github.com/magnumripper/JohnTheRipper 알려진 암호문으로 평문 크래킹을 시도하는 비밀번호 크래킹 소프트웨어
  • https://github.com/shinnok/johnny JohnTheRipper 비밀번호 크래킹의 GUI 인터페이스, 이론상 모든 기능 호환, windows 인터페이스 제공
  • https://github.com/jmk-foofus/medusa 지원 프로토콜은 hydra보다 약간 적지만, 일부 속도는 더 빠름
  • https://github.com/MrSqar-Ye/wpCrack wordpress hash 크래킹
  • https://github.com/testsecer/Md5Decrypt C#, 인터넷 웹 API 기반 MD5 검색 도구
  • https://github.com/s0md3v/Hash-Buster 여러 API를 호출해 hash 크래킹을 조회하는 스마트 도구
  • https://www.52pojie.cn/thread-275945-1-1.html ARCHPR Pro4.54 포터블 중국어 크랙 버전. 압축 파일 비밀번호 크래킹, "알려진 평문 공격"을 이용해 암호화된 압축 파일 크랙

DB 보안

  • https://github.com/ron190/jsql-injection Java로 작성된 SQL 인젝션 도구
  • https://github.com/shack2/SuperSQLInjectionV1 안헝 항뉴(安恒航牛)의 GUI 기반 인젝션 도구
  • https://github.com/sqlmapproject/sqlmap sql 인젝션 sqlmap
  • https://github.com/stamparm/DSSS 단 199줄의 코드로 구현된 sql 인젝션 취약점 스캐너
  • https://github.com/Hadesy2k/sqliv 검색 엔진 기반 배치 SQL 인젝션 취약점 스캐너
  • https://github.com/quentinhardy/odat Oracle 침투 전용으로 매우 포괄적인 도구
  • https://github.com/m8r0wn/enumdb MySQL 및 MSSQL 공격 도구. 사후 브루트포스, 데이터베이스 검색 및 민감 정보 추출.
  • https://github.com/LoRexxar/Feigong 다양한 상황에 맞춰 자유롭게 변화하는 MySQL 인젝션 스크립트
  • https://github.com/youngyangyang04/NoSQLAttack mongoDB를 대상으로 한 공격 도구
  • https://github.com/Neohapsis/bbqsql SQL 블라인드 인젝션 공격 프레임워크
  • https://github.com/NetSPI/PowerUpSQL Powershell 기반 sqlserver 테스트 프레임워크
  • http://www.4hou.com/system/14950.html PowerUpSQL 활용, 침투 테스트 팁: SQL Server 로그인 트리거 제한 우회
  • https://github.com/WhitewidowScanner/whitewidow 데이터베이스 스캐너
  • https://github.com/stampery/mongoaudit MongoDB 감사 및 침투 도구
  • https://github.com/torque59/Nosql-Exploitation-Framework NoSQL 스캔/브루트포스 도구
  • https://github.com/missDronio/blindy MySQL 블라인드 인젝션 브루트포스 도구
  • https://github.com/JohnTroony/Blisqy http header의 시간 기반 블라인드 인젝션 브루트포스 도구, MySQL/MariaDB 전용
  • https://github.com/se55i0n/DBScanner 내부 네트워크의 일반적인 sql, no-sql 데이터베이스를 자동 스캔하는 스크립트, 무단 접근 및 일반적인 약한 비밀번호 탐지 포함

코드 감사- https://www.waitalone.cn/seay-source-code-auditv2.html Seay 소스코드 감사 시스템 2.1 버전

  • https://github.com/pyupio/safety 설치된 모든 Python 패키지를 검사하여 알려진 보안 취약점 탐색
  • https://github.com/pumasecurity/puma-scan 실시간 코드 감사, VS 플러그인
  • https://github.com/wufeifei/cobra 화이트박스 코드 보안 감사 시스템
  • https://github.com/OneSourceCat/phpvulhunter 정적 php 코드 감사
  • https://github.com/ripsscanner/rips php 기반 php 코드 감사 도구
  • https://github.com/Qihoo360/phptrace php 실행 상태를 추적·분석하는 도구
  • https://github.com/ajinabraham/NodeJsScan Node.JS 애플리케이션 코드 감사
  • https://github.com/ctxis/beemka Electron App 대상 취약점 활용 도구 키트
  • https://github.com/doyensec/electronegativity Electron 애플리케이션 코드 감사, App의 잘못된 구성 및 보안 문제
  • https://github.com/shengqi158/pyvulhunter Python 애플리케이션 감사
  • https://github.com/securego/gosec Go 언어 소스코드 보안 분석 도구
  • https://github.com/GoSSIP-SJTU/TripleDoggy clang 기반 c/c++/object-c 소스코드 탐지 프레임워크, 호출 가능한 인터페이스 다수
  • https://github.com/ga0/pyprotect python 코드를 암호화하여 리버스 엔지니어링 방지
  • https://github.com/presidentbeef/brakeman Ruby on Rails 애플리케이션 정적 코드 분석
  • https://github.com/python-security/pyt Python 웹 애플리케이션의 보안 취약점 탐지를 위한 정적 분석 도구
  • https://github.com/m4ll0k/WPSploit Wordpress 플러그인 코드 보안 감사
  • https://github.com/elcodigok/wphardening 모든 WordPress 설치의 보안 강화

빅데이터 보안

  • https://github.com/shouc/BDA hadoop/spark/mysql 등 빅데이터 플랫폼에 대한 감사 및 탐지
  • https://github.com/wavestone-cdt/hadoop-attack-library hadoop 테스트 방법 및 도구 모음

취약점 재현

  • https://github.com/vulhub/vulhub Vulhub는 대중을 위해 만들어진 오픈소스 취약점 실습 환경으로, docker 지식 없이 두 가지 명령만 실행하면 완전한 취약점 실습 환경 이미지를 컴파일·실행할 수 있음

  • https://github.com/Medicean/VulApps 다양한 취약점 환경을 수집하며, 사용 편의를 위해 모두 Dockerfile 형식으로 통일. 보안 도구 환경도 함께 수집

  • https://github.com/bingohuang/docker-labs 온라인 docker 플랫폼 제작

취약점 조회

  • https://wooyun.kieran.top/#!/ 2016년 이전, WooYun Drops 기사, 공개 취약점 상세 기사
  • https://wooyun.js.org/ 2016년 이전, WooYun Drops 기사, 공개 취약점 상세 기사
  • https://dvpnet.io/list/index/state/3 공개 취약점 상세 기사
  • https://sec.ly.com/bugs Tongcheng(동청) Security 공개 취약점 상세 기사
  • http://ics.cnvd.org.cn 중국 국가 산업제어(ICS) 취약점 데이터베이스
  • https://ics-cert.us-cert.gov/advisories 미국 국가 산업제어(ICS) 취약점 데이터베이스
  • http://www.nsfocus.net/index.php?act=sec_bug NSFOCUS(녹맹) 취약점 데이터베이스, ICS 포함
  • http://ivd.winicssec.com/ Winicssec(위누트) 산업제어 취약점 데이터베이스
  • http://cve.scap.org.cn/view/ics CVE 중국어 산업제어 취약점 데이터베이스
  • https://cve.mitre.org/cve/search_cve_list.html 미국 MITRE 사가 유지관리하는 CVE 취약점 데이터베이스
  • https://www.exploit-db.com 미국 Offensive Security의 취약점 데이터베이스
  • https://nvd.nist.gov/vuln/search 미국 국가 정보보안 취약점 데이터베이스

EXP&POC

  • https://github.com/Lcys/Python_PoC python3용 POC·EXP 빠른 작성 템플릿, 다양한 모범 버전 보유
  • https://github.com/raminfp/linux_exploit_development linux 취약점 익스플로잇 개발 매뉴얼
  • https://github.com/mudongliang/LinuxFlaw linux 소프트웨어 취약점 목록 포함
  • https://github.com/coffeehb/Some-PoC-oR-ExP 다양한 취약점 POC·EXP 수집 또는 작성
  • https://github.com/userlandkernel/plataoplomo Sem Voigtländer가 발견한 iOS 내 다양한 취약점 공개 (Writeup/POC/Exploit 포함)
  • https://github.com/coffeehb/Some-PoC-oR-ExP/blob/master/check_icmp_dos.py CVE-2018-4407, macos/ios 버퍼 오버플로우로 시스템 충돌 유발 가능
  • https://github.com/vulnersCom/getsploit py2, searchsploit을 본떠 다양한 데이터베이스의 공식 API를 통해 payload 검색
  • https://github.com/SecWiki/CMS-Hunter CMS 취약점 테스트 케이스 모음
  • https://github.com/Mr5m1th/0day 다양한 오픈소스 CMS의 각 버전 취약점 및 EXP
  • https://github.com/Al1ex/Heptagram 다양한 오픈소스 CMS, Windows, Linux, 애플리케이션, Email 등 EXP 수집·정리
  • https://github.com/w1109790800/penetration CMS 구버전·신버전 EXP와 시스템 취약점 수집표
  • https://github.com/blacknbunny/libSSH-Authentication-Bypass CVE-2018-10933, libssh 서버 측 인증 우회
  • https://github.com/leapsecurity/libssh-scanner CVE-2018-10933, libssh 서버 측 인증 우회
  • https://github.com/anbai-inc/CVE-2018-4878 Adobe Flash Exploit, payload 생성
  • https://github.com/RetireJS/grunt-retire js 확장 라이브러리의 일반적인 취약점 스캔
  • https://github.com/coffeehb/SSTIF 서버 측 템플릿 주입(SSTI) 취약점 반자동화 도구

JAVA 취약점

  • https://github.com/brianwrf/hackUtils java 역직렬화 활용
  • https://github.com/GoSecure/break-fast-serial DNS 해석을 이용해 Java 역직렬화 취약점을 탐지하는 도구
  • https://github.com/s1kr10s/Apache-Struts-v3 Apache-Struts 취약점 활용 도구
  • https://github.com/iBearcat/S2-057 struts2 CVE-2018-11776 취약점 탐지 도구
  • https://github.com/Ivan1ee/struts2-057-exp struts2-057 활용 스크립트
  • https://github.com/theLSA/s2sniper- https://github.com/codewatchorg/sqlipy burp와 sqlmap 연동 플러그인
  • https://github.com/Hood3dRob1n/SQLMAP-Web-GUI sqlmap 웹 GUI
  • https://github.com/KINGSABRI/sqlmap-tamper-api 다양한 언어를 사용하여 sqlmap Tamper 작성
  • https://github.com/0xbug/SQLiScanner sqlmapapi와 Charles 기반의 패시브 SQL 인젝션 취약점 스캐너 도구
  • https://github.com/fengxuangit/Fox-scan sqlmapapi 기반의 액티브/패시브 리소스 발견 취약점 스캐너 도구
  • https://github.com/UltimateHackers/sqlmate sqlmap을 기반으로 디렉터리 스캔, 해시 브루트포스 등의 기능 추가
  • https://github.com/ysrc/GourdScanV2 ysrc에서 만든 패시브 취약점 스캐너 도구, sqlmapapi 기반
  • https://github.com/zt2/sqli-hunter sqlmapapi 기반, Ruby로 작성된 프록시형 취약점 탐지 도구
  • https://github.com/jesuiscamille/AutoSQLi DorkNet, Googler, Ddgr, WhatWaf 및 sqlmap을 활용한 자동 인젝션
Nmap
  • https://github.com/Ullaakut/nmap GO로 구현된 Nmap 호출 라이브러리
  • https://github.com/cldrn/nmap-nse-scripts NSE 수집 목록
  • https://github.com/vulnersCom/nmap-vulners nmap을 사용하여 일반적인 서비스 취약점 스캔
  • https://github.com/s4n7h0/Halcyon Nmap Script (NSE) IDE 편집기
  • https://github.com/m4ll0k/AutoNSE NSE 자동화 활용
  • https://github.com/Screetsec/Dracnmap shell, Nmap의 복잡한 명령을 일정 수준 통합·단순화하여 신규 사용자가 더 쉽게 사용할 수 있게 함
  • https://github.com/cldrn/rainmap-lite Django, 웹 버전 Nmap. 새로운 스캔 서버를 구축할 수 있으며 사용자가 휴대폰/태블릿/웹 브라우저에서 Nmap 스캔을 시작할 수 있음
  • https://github.com/trimstray/sandmap Linux에서 대량의 Nmap 엔진을 사용한 네트워크 및 시스템 정찰을 지원하는 도구
  • https://github.com/m0nad/HellRaiser nmap 기반 스캐너, CVE 취약점과 연계
  • https://github.com/scipag/vulscan nmap 기반의 고급 취약점 스캐너, 명령줄 환경에서 사용
  • https://github.com/Rev3rseSecurity/WebMap nmap의 XML 웹 뷰어
  • https://github.com/DanMcInerney/msf-autopwn NMap 스캔을 실행하거나 스캔 결과를 읽은 후 자동으로 msf를 사용하여 일반적인 취약점이 있는 호스트 공격
Metasploit
  • https://github.com/13o-bbr-bbq/machine_learning_security/tree/master/DeepExploit 머신러닝과 msf를 결합한 완전 자동 테스트 도구
  • https://github.com/r00t-3xp10it/Meterpreter_Paranoid_Mode-SSL SSL/TLS 셸 연결을 생성할 수 있는 스크립트
  • https://github.com/DanMcInerney/msf-netpwn msf 세션을 기다렸다가 자동으로 도메인 관리자 권한으로 승격
  • https://www.exploit-db.com/exploits/45851/ msf 플러그인, JIRA UPM 업로드를 이용한 명령 실행
  • https://github.com/NullArray/AutoSploit Shodan 검색 엔진을 활용하여 대상을 수집하고 설정된 msf 모듈을 자동으로 호출하여 대상 공격
  • https://github.com/WazeHell/metateta msf 스크립트를 사용하여 특정 프로토콜에 따라 스캔 수행
  • https://github.com/fbkcs/msf-elf-in-memory-execution Metasploit 모듈, 메모리에서 ELF 파일을 실행하는 데 사용
  • https://github.com/ElevenPaths/Eternalblue-Doublepulsar-Metasploit metasploit 이터널블루/더블펄서 공격 익스플로잇 파일
  • https://github.com/darkoperator/Metasploit-Plugins msf 자산 수집 및 도움말 확장 플러그인
  • https://github.com/D4Vinci/One-Lin3r metasploit, payload 보조 조회 도구
  • https://github.com/shizzz477/msploitego msf 데이터베이스와 Maltego를 그래픽으로 시각화
  • https://github.com/scriptjunkie/msfgui metasploit의 GUI 인터페이스. 참고로 현재 msf는 Windows 지원도 꽤 괜찮음
CobaltStrike
  • https://github.com/Al1ex/CSPlugins CobaltStrike 다양한 플러그인

  • https://mp.weixin.qq.com/s/CEI1XYkq2PZmYsP0DRU7jg Aggressor 스크립트를 사용하여 Cobalt Strike 커스터마이징

  • https://github.com/rsmudge/armitage CobaltStrike 커뮤니티 버전, msf 호출, 일대다 GUI 지원

  • https://github.com/anbai-inc/CobaltStrike_Hanization CobaltStrike 2.5 중문화 버전, msf 라이브러리 기반, 3.0 이후 개편됨

  • https://github.com/rsmudge/cortana-scripts cs2.x 및 armitage용 확장 가능한 플러그인, cs3.x용은 AggressorScripts

  • https://github.com/harleyQu1nn/AggressorScripts cs3.0 이후 스크립트 모음

  • https://github.com/FortyNorthSecurity/AggressorAssessor cs3.x 자동화 공격 스크립트 모음

  • https://github.com/Ridter/CS_Chinese_support/ cs3.0 전송 정보 중문화 플러그인

  • https://github.com/verctor/CS_xor64 cobaltstrike에 필요한 xor64.bin 생성

  • https://github.com/ryhanson/ExternalC2 Cobalt Strike External C2 서버와 통신 채널을 통합하기 위한 라이브러리

  • https://github.com/threatexpress/cs2modrewrite Cobalt Strike 구성 파일을 mod_rewrite 스크립트로 변환하는 도구

  • https://github.com/Mr-Un1k0d3r/CatMyFish 분류 도메인을 검색하여 Cobalt Strike beacon C&C용 화이트리스트 도메인 설정

  • https://github.com/threatexpress/malleable-c2 jquery 파일을 이용한 C2 통신, 파일 내에서 JS 난독화로 방화벽 우회

  • https://github.com/dcsync/pycobalt py3, Cobalt Strike용 Python API

  • https://www.cobaltstrike.com/aggressor-script/cobaltstrike.html CobaltStrike 관련 플러그인 작성, 일대다 GUI 지원

Empire
  • https://paper.tuisec.win/detail/f3dce68a0b4baaa Empire를 활용한 도메인 컨트롤러 권한 획득
  • https://github.com/EmpireProject/Empire-GUI empire의 node.js 인터페이스
  • https://github.com/interference-security/empire-web empire의 웹 인터페이스
  • https://github.com/byt3bl33d3r/DeathStar py3, Empire RESTful API를 호출하여 자동으로 도메인 관리자 권한 획득
  • https://github.com/infosecn1nja/e2modrewrite Empire 구성 파일을 Apache mod_rewrite 스크립트로 변환하는 데 사용
  • https://github.com/maxchehab/CSS-Keylogging Chrome 확장 프로그램과 Express 서버가 CSS의 키로깅 기능을 활용
  • https://github.com/evilcos/cookiehacker Chrome 확장 프로그램. JavaScript document.cookie / Wireshark Cookie
  • https://github.com/lfzark/cookie-injecting-tools Chrome 확장 프로그램, 쿠키 주입 도구로 쿠키 주입, 편집, 추가 및 삭제 포함

내부 네트워크 보안

추천 콘텐츠

  • https://attack.mitre.org/wiki/Lateral_Movement mitre 기관의 횡적 이동(Lateral Movement)에 대한 정리

  • https://payloads.online/archivers/2018-11-30/1 Windows 인증 완전 이해 - 주제 해설

  • https://github.com/klionsec/klionsec.github.io 내부 네트워크 고수의 학습 과정

  • https://github.com/l3m0n/pentest_study 제로부터 시작하는 내부 네트워크 침투 학습

  • https://github.com/Ridter/Intranet_Penetration_Tips 내부 네트워크 침투 TIPS

  • https://github.com/OpenWireSec/metasploit 포스트 익스플로잇 프레임워크

  • https://github.com/EmpireProject/Empire PowerShell 기반 명령 실행 프레임워크

  • https://github.com/TheSecondSun/Bashark 순수 Bash 스크립트로 작성된 포스트 익스플로잇 프레임워크, 큰 상어

  • https://github.com/JusticeRage/FFM py3, 다운로드/업로드 기능을 갖추고 실행 가능한 py 스크립트 백도어를 생성하는 포스트 익스플로잇 프레임워크

  • https://github.com/DarkSpiritz/DarkSpiritz py2, 포스트 익스플로잇 프레임워크

  • https://github.com/byt3bl33d3r/CrackMapExec 네트워크 테스트계의 스위스 아미 나이프, impacket, PowerSploit 등 다양한 모듈 포함

  • https://github.com/SpiderLabs/scavenger CrackMapExec를 2차 래핑하여 내부 네트워크 민감 정보 스캔

  • https://github.com/jmortega/python-pentesting python-pentesting-tool 파이썬 보안 도구 관련 기능 모듈

  • https://github.com/0xdea/tactical-exploitation Python/PowerShell 테스트 스크립트 모음

  • https://github.com/PowerShellMafia/PowerSploit PowerShell 테스트 스크립트 모음 및 개발 프레임워크 종합

포워딩 | 프록시

  • https://github.com/fatedier/frp 내부 네트워크 침투용 고성능 리버스 프록시 애플리케이션, tcp, udp, http, https 프로토콜 지원
  • https://github.com/inconshreveable/ngrok 포트 포워딩, 정방향/역방향 프록시, 내부 네트워크 침투
  • http://ngrok.ciqiuwl.cn/ 온라인 샤오미추 ngrok
  • https://github.com/knownsec/rtcp Socket 포트 포워딩, 원격 유지보수용
  • https://github.com/davrodpin/mole SSH 기반 포트 포워딩
  • http://rootkiter.com/EarthWorm SOCKS v5 프록시 서비스를 시작하는 도구. 표준 C 기반으로 개발되었으며, 다중 플랫폼 간 중계 통신을 제공하여 복잡한 네트워크 환경에서의 데이터 전달에 사용
  • http://rootkiter.com/Termite/README.txt EarthWorm 업그레이드 버전, 다중 노드 점프 구현 가능
  • https://github.com/SECFORCE/Tunna HTTP를 통해 모든 TCP를 터널링할 수 있으며 방화벽 환경의 네트워크 제한을 우회하는 데 사용
  • https://github.com/fbkcs/thunderdns TCP 트래픽을 DNS 프로토콜로 전달, 클라이언트와 SOCKS5 지원 불필요
  • https://github.com/sensepost/reGeorg reDuh의 업그레이드 버전. 주로 내부 네트워크 서버의 포트를 http/https 터널을 통해 로컬로 전달하여 루프를 형성함. 대상 서버가 내부 네트워크에 있거나 포트 정책이 적용된 경우 대상 서버 내부의 개방 포트에 연결하는 데 사용 (php, asp, jsp 스크립트의 정방향/역방향 프록시 제공)
  • https://github.com/SpiderClub/haipproxy py3, Scrapy and Redis, 고가용성 IP 프록시 풀
  • https://github.com/chenjiandongx/async-proxy-pool py3 비동기 크롤러 IP 프록시 풀
  • https://github.com/audibleblink/doxycannon OpenVPN 프록시 풀을 사용하여 각각에 대해 Docker를 생성하고, 특정 VPN에 연결되면 나머지가 SOCKS5 포워딩으로 트래픽 분산
  • https://github.com/decoder-it/psportfwd PowerShell로 작성된 포트 포워딩 도구, admin 권한 불필요
  • https://github.com/ls0f/gortcp go, 제어단, 중계단, 피제어단을 통해 내부 네트워크 침투 구현

횡적 이동

  • http://www.oxid.it/cain.html Cain & Abel 비밀번호 복원, ARP 중간자 공격 지원
  • https://github.com/gentilkiwi/mimikatz Windows에서 비밀번호 탈취 중심의 횡적 이동 필수 도구
  • https://github.com/skelsec/pypykatz 순수 py3로 구현된 mimikatz
  • https://github.com/eladshamir/Internal-Monologue LSASS 프로세스 없이 Mimikatz를 사용하여 LSASS 프로세스 메모리에서 내용을 추출하고, 메모리에서 평문 비밀번호, NTLM 해시, Kerberos ticket을 추출하며 pass-the-hash/pass-the-ticket 공격 등 실행
  • https://github.com/AlessandroZ/LaZagne py3, 비밀번호 탈취 도구
  • https://github.com/AlessandroZ/LaZagneForensic LaZagne 비밀번호 크래킹 업그레이드 버전, DPAPI 활용, 현재 단점은 Windows 사용자 비밀번호가 필요하다는 것
  • https://github.com/twelvesec/passcat Windows용 비밀번호 탈취 도구
  • https://github.com/huntergregal/mimipenguin Linux 비밀번호 탈취 필수 도구
  • https://github.com/quarkslab/quarkspwdump quarkslab에서 만든 비밀번호 탈취 도구, 어떤 프로세스에도 주입할 필요 없음
  • https://github.com/mthbernardes/sshLooter SSH 서비스에서 사용자 이름과 비밀번호 탈취
  • https://github.com/nettitude/Invoke-PowerThIEf IE를 활용한 포스트 익스플로잇, 비밀번호 탈취, 리다이렉션 등
  • https://github.com/GhostPack/Rubeus Kerberos를 조작하는 라이브러리, Kekeo의 대부분 기능 구현, C# 작성
  • https://github.com/m8r0wn/ldap_search PY, LDAP(경량 디렉터리 액세스 프로토콜) 인증을 통해 Windows 도메인 정보를 열거하고 로그인 브루트포스

명령 제어

  • https://github.com/malwaredllc/byob 봇넷 생성 프레임워크
  • https://github.com/proxycannon/proxycannon-ng 공격용 봇넷 구축
  • https://github.com/deadPix3l/CryptSky/ 랜섬웨어 PoC
  • https://github.com/jgamblin/Mirai-Source-Code 웜 바이러스 PoC
  • https://github.com/AhMyth/AhMyth-Android-RAT smali 기반, Windows에서 동작하는 Android 원격 제어, 일대다 GUI 지원
  • https://github.com/ssooking/cobaltstrike3.12_cracked java1.8, 원격 제어, 피싱, 내부 네트워크
  • https://github.com/Mr-Un1k0d3r/ThunderShell py2, CLI 및 웹 엔드, 인메모리 웹셸, RC4 암호화 HTTP 전송
  • https://github.com/tiagorlampert/CHAOS go, Windows 원격 제어, 대부분의 백신 우회 가능
  • https://github.com/Ne0nd0g/merlin go, C2 통신, 일대다
  • https://github.com/0x09AL/Browser-C2 go, Chrome을 활용하여 브라우저 형태로 C2 서버에 연결
  • https://github.com/xdnice/PCShare c++, 대상 머신의 화면, 레지스트리, 파일 시스템 등 모니터링 가능
  • https://github.com/quasar/QuasarRAT c#, 일대다, GUI
  • https://github.com/TheM4hd1/Vayne-RaT c#, 일대다, GUI
  • https://github.com/nettitude/PoshC2 PowerShell, C#, 원격 제어 도구, Windows 권한 상승 구성 요소 포함
  • https://github.com/euphrat1ca/njRAT-v0.7d vb, 흔한 웜형 원격 제어, 변종이 많음, 일대다 GUI 지원
  • https://github.com/zerosum0x0/koadic py3, JScript/VBScript를 활용한 제어, 대검
  • https://github.com/Ridter/MyJSRat py2, JS 백도어 활용, chm, hta와 함께 사용하면 다양한 백도어 방식 구현 가능. evi1cg.me/archives/chm_backdoor.html

권한 상승

Linux 권한 상승
  • https://github.com/Al1ex/Heptagram/tree/master/Linux/Elevation Linux 권한 상승 기법 모음

  • https://github.com/AlessandroZ/BeRoot py, 일반적인 오설정을 검사하여 권한 상승 방법을 찾음. Windows/Linux/Mac 지원

  • https://github.com/mschwager/0wned Python 패키지를 이용한 높은 권한 사용자 생성

  • https://github.com/mzet-/linux-exploit-suggester Linux에 설치되지 않은 패치를 찾는 스크립트

  • https://github.com/belane/linux-soft-exploit-suggester Linux에서 취약한 소프트웨어를 찾는 도구

  • https://github.com/dirtycow/dirtycow.github.io Dirty Cow 권한 상승 취약점 익스플로잇

  • https://github.com/FireFart/dirtycow Dirty Cow 권한 상승 취약점 익스플로잇

  • https://github.com/stanleyb0y/sushell su 도둑을 활용하여 저권한 사용자가 root 사용자 암호 탈취 구현

  • https://github.com/jas502n/CVE-2018-17182/ Linux 커널 VMA-UAF 권한 상승 취약점 CVE-2018-17182

  • https://github.com/jas502n/CVE-2018-14665 CVE-2018-14665, Linux에서 Xorg X 서버 권한 상승 익스플로잇

  • https://github.com/nmulasmajic/syscall_exploit_CVE-2018-8897 Linux 시스템에서 Syscall을 이용한 권한 상승 구현

  • https://github.com/can1357/CVE-2018-8897 Linux 시스템에서 Syscall을 이용한 권한 상승 구현

  • https://github.com/SecWiki/linux-kernel-exploits linux-kernel-exploits Linux 플랫폼 권한 상승 취약점 모음

  • https://github.com/nilotpalbiswas/Auto-Root-Exploit Linux 자동 권한 상승 스크립트

  • https://github.com/WazeHell/PE-Linux Linux 권한 상승 도구

Windows 권한 상승
  • https://github.com/Al1ex/Heptagram/tree/master/Windows/Elevation Windows 권한 상승 기법 모음
  • http://www.fuzzysecurity.com/tutorials/16.html Windows 플랫폼 튜토리얼 수준의 권한 상승 참고 문서
  • https://github.com/SecWiki/windows-kernel-exploits Windows 플랫폼 권한 상승 취약점 익스플로잇 모음
  • https://github.com/51x/WHP Windows용 다양한 권한 상승 및 익스플로잇 도구
  • https://github.com/rasta-mouse/Sherlock Windows 권한 상승 취약점 검증
  • https://github.com/WindowsExploits/Exploits Microsoft CVE-2012-0217, CVE-2016-3309, CVE-2016-3371, CVE-2016-7255, CVE-2017-0213 권한 상승 익스플로잇
  • https://github.com/decoder-it/lonelypotato RottenPotatoNG 변종, NBNS 로컬 도메인 스푸핑 및 WPAD 프록시 스푸핑을 이용한 권한 상승
  • https://github.com/ohpe/juicy-potato RottenPotatoNG 변종, COM 객체와 사용자 토큰을 이용한 권한 상승
  • https://github.com/foxglovesec/Potato RottenPotatoNG 변종, 로컬 도메인 스푸핑과 프록시 스푸핑을 이용한 권한 상승
  • https://github.com/DanMcInerney/icebreaker 내부 네트워크 환경에 있지만 AD 환경 밖에 있을 때, icebreaker는 평문 Active Directory 자격 증명을 획득하는 데 도움을 줌 (활성 디렉터리는 도메인 컨트롤러 서버에 저장되며 권한 상승에 사용될 수 있음)
  • https://github.com/hausec/ADAPE-Script Active Directory 권한 상승 스크립트
  • https://github.com/klionsec/BypassAV-AllThings aspx 원라이너 웹셸과 권한 상승 payload를 조합한 권한 상승
  • https://github.com/St0rn/Windows-10-Exploit msf 플러그인, Windows 10 UAC 우회
  • https://github.com/sam-b/CVE-2014-4113 Win32k.sys 커널 취약점을 이용한 권한 상승, MS14-058
  • https://github.com/breenmachine/RottenPotatoNG NBNS 로컬 도메인 스푸핑 및 WPAD 프록시 스푸핑을 이용한 권한 상승
  • https://github.com/unamer/CVE-2018-8120 Win32k 구성 요소에 영향, win7 및 win2008 대상 권한 상승

Bypass

권한 우회

  • https://payloads.online/archivers/2018-12-22/1 DLL Hijacking & COM Hijacking ByPass UAC - 주제 해설
  • https://github.com/tyranid/DotNetToJScript JS/VBS 스크립트로 .Net 프로그램을 로드할 수 있는 도구
  • https://github.com/mdsecactivebreach/SharpPack 시스템 애플리케이션 화이트리스트를 우회하여 DotNet 및 PowerShell 도구 실행
  • https://github.com/rootm0s/WinPwnage py2, Windows 권한 상승, UAC 우회, DLL 주입 등
  • https://github.com/hfiref0x/UACME 여러 버전의 운영체제에서 Windows 사용자 계정 컨트롤(UAC)을 우회하는 다양한 방법 포함
  • https://github.com/Ben0xA/nps powershell.exe를 사용하지 않고 PowerShell 명령을 실행하는 구현
  • https://github.com/Mr-Un1k0d3r/PowerLessShell powershell.exe를 호출하지 않고 PowerShell 명령을 실행하는 구현
  • https://github.com/p3nt4/PowerShdll rundll32를 사용하여 PowerShell 실행, 소프트웨어 제한 우회
  • https://github.com/ionescu007/r0ak 커널 영역의 스위스 아미 나이프. Windows 10 커널에서 코드 읽기/쓰기/실행
  • https://github.com/leechristensen/UnmanagedPowerShell 비관리 프로그램에서 PowerShell을 실행하며, 약간의 수정 후 다른 프로세스에 주입하는 데 사용할 수 있음
  • https://github.com/stephenfewer/ReflectiveDLLInjection 라이브러리 주입 기술로, DLL 자체가 LoadLibraryA 함수를 사용하지 않고 자신을 대상 프로세스 메모리에 매핑
  • https://github.com/ChrisAD/ads-payload 환경 변수와 destop.ini를 활용하여 Windows의 Palo Alto Traps 엔드포인트 보안 소프트웨어 우회
  • https://github.com/Zer0Mem0ry/RunPE 메모리 읽기, 네트워크 전송 콘텐츠를 통해 PE를 활용하여 shellcode 실행

샌드박스 탈출

  • https://github.com/hacksysteam/WpadEscape wpad를 이용한 브라우저 샌드박스 탈출
  • https://github.com/unamer/vmware_escape VMware 가상 머신 탈출. CVE-2017-4901, CVE-2018-6981, CVE-2018-6982
  • https://github.com/MorteNoir1/virtualbox_e1000_0day VirtualBox E1000 Guest-to-Host Escape 탈출. 튜토리얼
  • https://bugs.chromium.org/p/project-zero/issues/detail?id=1682&desc=2 Ghostscript: 취약점 CVE-2018-17961 기반의 -dSAFER 샌드박스 탈출 기술

백도어 AV 우회

  • https://www.shellterproject.com 백신 소프트웨어 우회
  • https://github.com/trustedsec/unicorn py, 원클릭으로 다양한 백도어 생성
  • https://github.com/islamTaha12/Python-Rootkit Windows용 rootkit, Meterpreter 리버스 연결
  • https://github.com/n00py/Hwacha Linux에서 Meterpreter 등 다양한 payload를 빠르게 생성
  • https://github.com/Screetsec/Vegile msf AV 우회, 프로그램 주입
  • https://github.com/MohamedNourTN/Terminator py2, msf AV 우회
  • https://github.com/Veil-Framework/Veil msf AV 우회
  • https://github.com/abedalqaderswedan1/aswcrypter py, bash, msf AV 우회
  • https://github.com/Screetsec/TheFatRat java, msf AV 우회, searchsploit을 이용한 빠른 검색
  • https://github.com/pasahitz/zirikatu msf AV 우회
  • https://github.com/govolution/avet msf AV 우회
  • https://github.com/GreatSCT/GreatSCT msf AV 우회
  • https://github.com/EgeBalci/HERCULES msf AV 우회
  • https://github.com/trustedsec/nps_payload msf AV 우회
  • https://github.com/4w4k3/Insanity-Framework py, payload 생성, 백신 우회, 가상 머신 탐지, 피싱, 메모리 주입 등
  • https://github.com/hlldz/SpookFlare Meterpreter, Empire, Koadic 등 loader/dropper 생성기. 클라이언트 측 탐지 및 네트워크 측 탐지 엔드포인트 정책을 우회할 수 있음
  • https://github.com/pasahitz/regsvr32 C# + Empire로 최소 크기 AV 우회 백도어 구현
  • https://github.com/malcomvetter/UnstoppableService 자체를 Windows 서비스로 설치하고 관리자가 서비스를 중지/일시 중지할 수 없는 프로그램. C# 작성

파일 번들링

  • bat2exe.net 유사한 도구로, iexpress와 winrar를 활용하여 자동 압축 해제 exe 실행 파일을 생성할 수도 있음
  • https://github.com/islamadel/bat2exe bat 파일을 exe 바이너리 파일로 변환
  • https://github.com/tywali/Bat2ExeConverter bat 파일을 exe 바이너리 파일로 변환
  • https://github.com/Juntalis/win32-bat2exe bat 파일을 exe 바이너리 파일로 변환
  • http://www.f2ko.de/downloads/Bat_To_Exe_Converter.zip bat 파일을 exe 바이너리 파일로 변환, 창 숨김 가능
  • https://github.com/r00t-3xp10it/trojanizer 두 개의 실행 파일을 자동 압축 해제 파일로 패키징하며, 자동 압축 해제 파일이 실행될 때 실행 파일을 실행함
  • https://github.com/r00t-3xp10it/backdoorppt payload 아이콘 변경
  • https://github.com/r00t-3xp10it/FakeImageExploiter payload 아이콘 변경. wine과 resourcehacker 환경 필요
  • https://github.com/DamonMohammadbagher/FakeFileMaker 아이콘과 이름 변경
  • https://github.com/peewpw/Invoke-PSImage PS 스크립트를 PNG 픽셀에 숨기고 한 줄의 명령으로 실행
  • https://github.com/Mr-Un1k0d3r/DKMC Don't kill my cat, 난독화된 shellcode를 생성하고 shellcode를 다국어 이미지에 저장
  • https://github.com/deepzec/Bad-Pdf payload가 포함된 PDF 파일을 생성하여 Windows에서 Net-NTLM 해시 탈취
  • https://github.com/3gstudent/Worse-PDF PDF 파일에 악성 코드를 삽입하여 Windows에서 Net-NTLM 해시 탈취

신원 은닉

  • https://github.com/leitbogioro/Fuck_Aliyun Aliyun 모니터링 서비스 비활성화
  • https://github.com/Nummer/Destroy-Windows-10-Spying DWS, Windows 모니터링 서비스 비활성화
  • https://github.com/Rizer0/Log-killer 로그 삭제, Windows/Linux 서버 내 모든 로그
  • https://github.com/360-A-Team/EventCleaner 로그 삭제 도구
  • https://github.com/s-rah/onionscan 다크웹 크롤러
  • https://github.com/globaleaks/Tor2web 다크웹 프록시 서버, onion 서비스를 일반 서비스로 변환
  • https://github.com/milesrichardson/docker-onion-nmap nmap을 사용하여 Tor 네트워크에 숨겨진 "onion" 서비스 스캔
  • https://github.com/GouveaHeitor/nipe 모든 트래픽을 Tor 네트워크를 통해 보내는 스크립트
  • https://github.com/trimstray/multitor 여러 Tor 채널을 활성화하여 트래픽을 전달하고 로드 밸런싱 설정

프라이버시 익명성

  • https://www.lshack.cn/118/ 온라인 인증번호 수신/이메일/클립보드/파일 전송 대모음
  • http://bccto.me 일회용 이메일
  • https://www.guerrillamail.com 일회용 이메일
  • http://24mail.chacuo.net/ 일회용 이메일
  • http://www.yopmail.com 일회용 이메일
  • https://yandex.com/ 휴대폰 번호 불필요 이메일
  • https://mail.ru/ 휴대폰 번호 불필요 이메일
  • https://mail.protonmail.com/login 휴대폰 번호 불필요 이메일
  • https://github.com/walkor/workerman-chat php, 온라인 채팅방, 확장 가능
  • https://github.com/hack-chat https://hack.chat/?your-channel js, 온라인 채팅, 물음표 뒤에 방 이름 입력
  • https://github.com/akaxincom/openzaly java, 채팅방, Akaxin은 클라이언트가 클로즈드 소스
  • https://github.com/RocketChat/Rocket.Chat js, 온라인 팀 채팅 서버, https://rocket.chat/install
  • https://telegram.org
  • https://www.whatsapp.com
  • https://wire.com/en
  • https://signal.org
  • http://www.batmessenger.com
  • http://sid.co

크롤러 관련- https://github.com/alphardex/looter 경량 크롤러 프레임워크, Scrapy와 유사

  • https://github.com/luyishisi/Anti-Anti-Spider 안티 크롤러(anti-crawler) 우회
  • https://github.com/xchaoinfo/fuck-login 일반적인 웹사이트의 로그인 시뮬레이션
  • https://github.com/Maicius/InterestingCrawler QQ 공간 피드(说说) 콘텐츠를 크롤링하여 분석
  • https://github.com/xjr7670/QQzone_crawler QQ 공간 피드 크롤러, cookie 로그인으로 접근 가능한 모든 친구 공간의 피드를 수집하여 로컬에 저장

사회공학 피싱

추천 콘텐츠

  • https://github.com/brannondorsey/PassGAN py, 딥러닝, 비밀번호 사전 샘플 생성
  • https://github.com/Mebus/cupp 사용자의 비밀번호 습관을 기반으로 약한 패스워드 탐지용 사전 생성
  • https://github.com/Saferman/cupper 사용자의 비밀번호 습관을 기반으로 약한 패스워드 탐지용 사전 생성, 위 항목의 업그레이드 버전
  • https://github.com/LandGrey/pydictor py3, 특정 비밀번호 사전 생성
  • https://github.com/mehulj94/Radium-Keylogger python 기반 키로거(keylogger) 도구
  • https://github.com/threatexpress/domainhunter 만료 도메인, Bluecoat 분류 및 Archive.org 기록을 확인하여 피싱 및 C2에 가장 적합한 도메인을 결정
  • https://github.com/Mr-Un1k0d3r/CatMyPhish 대상과 유사한 미등록 도메인 수집
  • https://github.com/x0day/Multisearch-v2 Bing, Google, 360, ZoomEye 등 검색 엔진 통합 검색, 검색 엔진에 색인된 기업의 민감 자산 정보를 발견하는 데 사용 가능
  • https://github.com/n0tr00t/Sreg Sreg는 사용자가 email, phone, username을 입력하면 해당 사용자가 등록한 모든 인터넷 패스포트(passport) 정보를 반환한다.
  • https://github.com/SpiderLabs/social_mapper 소셜 미디어 계정 열거 및 연관 도구, 얼굴 인식을 통해 인물 프로필을 연관
  • https://github.com/vysec/MaiInt 기업 직원 정보 수집 테스트 도구
  • https://github.com/jofpin/trape py, OSINT를 이용한 인물 추적 및 위치 파악
  • https://github.com/famavott/osint-scraper 이름이나 이메일 주소를 입력하면 인터넷에서 해당 인물에 대한 정보를 자동으로 크롤링
  • https://github.com/xHak9x/fbi py2, Facebook(페이스북) 정보 수집 도구
  • https://github.com/initstring/linkedin2username LinkedIn(링크드인)을 통해 관련 회사 직원 목록 획득
  • https://github.com/0x09AL/raven linux용 LinkedIn(링크드인) 정보 수집 도구
  • https://github.com/Ridter/Mailget 脉脉(Maimai) 사용자 정보를 통해 기업 이메일 유추

웹사이트 클로닝

  • http://www.httrack.com 웹사이트 클로닝 미러

피싱 프레임워크

  • https://github.com/bhdresh/SocialEngineeringPayloads 자격 증명 탈취 및 스피어 피싱 공격에 사용되는 사회공학 기법과 payload 수집
  • https://github.com/trustedsec/social-engineer-toolkit 사회공학 전용으로 설계된 오픈소스 침투 테스트 프레임워크
  • https://github.com/thelinuxchoice/blackeye Facebook, Instagram 등 30여 개의 피싱 템플릿을 보유한 원클릭 실행 도구
  • https://github.com/M4cs/BlackEye-Python blackeye를 기반으로 서브도메인 관리를 강화
  • https://github.com/azizaltuntas/Camelishing py3, GUI 기반 사회공학 공격 보조 도구
  • https://github.com/JonCooperWorks/judas go, 웹사이트 클로닝 피싱
  • https://github.com/gophish/gophish go, 온라인 템플릿 디자인, 유인 메일 발송 등의 기능을 갖춘 피싱 시스템
  • https://github.com/tatanus/SPF py2, deefcon 기반 피싱 시스템
  • https://github.com/MSG-maniac/mail_fishing 甲方(발주사) 내부 피싱 시스템
  • https://github.com/samyoyo/weeman 피싱용 HTTP 서버
  • https://github.com/Raikia/FiercePhish 모든 피싱 공격을 관리할 수 있는 완전한 피싱 프레임워크, 개별 피싱 캠페인 추적, 예약 이메일 발송 등을 지원
  • https://github.com/securestate/king-phisher 시각화된 피싱 캠페인 도구 키트
  • https://github.com/fireeye/ReelPhish 실시간 2FA(이중 인증) 피싱 도구
  • https://github.com/kgretzky/evilginx 2FA(이중 인증)를 우회하는 피싱 프레임워크
  • https://github.com/kgretzky/evilginx2 MiTM 프레임워크, 로그인 페이지 피싱, 2FA(이중 인증) 우회 등
  • https://github.com/ustayready/CredSniper Flask와 Jinja2 템플릿으로 작성된 피싱 프레임워크, 2FA 토큰 캡처 지원
  • https://github.com/fireeye/PwnAuth OAuth 남용 테스트 탐지 플랫폼

트래픽 하이재킹

  • https://github.com/bettercap/bettercap 네트워크 공격 및 모니터링의 스위스 아미 나이프. ARP/DNS 스푸핑, TCP 및 패킷 프록시 등 다양한 모듈을 지원
  • https://github.com/mitmproxy/mitmproxy PY, SSL 인터셉트를 지원하여 HTTPS 트래픽 프록시 수행
  • https://github.com/qiyeboy/BaseProxy py3, 비동기 HTTP/HTTPS 프록시, 위 항목의 간소화 버전. URL 이미지 교체 등 중간자(MITM) 도구로 사용 가능
  • https://github.com/lgandx/Responder 네트워크 내 모든 NTLM, NTLMv1/v2, Net-NTLMv1/v2 패킷을 스니핑하고, 네트워크 내 호스트를 속여 사용자 hash를 획득. a가 b의 비밀번호를 사용해 b에게 요청하면, c가 a에게 "나는 b다"라고 속여 c가 b의 비밀번호를 획득하는 방식, https://www.secpulse.com/archives/65503.html 【SecPulse 번역 시리즈】침투 테스터 가이드 - Responder
  • https://github.com/Kevin-Robertson/Inveigh PowerShell 기반 LLMNR / mDNS / NBNS 스푸퍼 및 중간자(MITM) 도구
  • https://github.com/LionSec/xerosploit 중간자(MITM) 공격 테스트 도구 키트
  • https://github.com/AlsidOfficial/WSUSpendu 악성 업데이트를 자체 생성하여 WSUS 서버 데이터베이스에 주입한 뒤, 해당 악성 업데이트를 마음대로 배포할 수 있음
  • https://github.com/infobyte/evilgrade 공격자가 사용자 모르게 악성 업데이트를 사용자의 업데이트에 주입할 수 있는 모듈식 스크립트 프레임워크
  • https://github.com/quickbreach/smbetray 파일 콘텐츠 교환, lnk 교환을 통한 클라이언트 공격과 평문으로 전송되는 모든 데이터 탈취에 특화
  • https://github.com/mrexodia/haxxmap IMAP 서버에 대한 중간자(MITM) 공격

트래픽 분석

  • https://github.com/wireshark/wireshark 프로토콜 파싱, 트래픽 분석 및 복원
  • https://github.com/CoreSecurity/impacket Impacket은 네트워크 프로토콜 처리를 위한 Python 도구 모음으로, 내부 네트워크에서 wmiexec.py, NMB 등을 이용한 권한 상승에 사용할 수 있으며, SMB1-3 및 MS-DCERPC에 대해 프로토콜 구현 자체에 대한 저수준 프로그래밍 접근을 제공
  • https://github.com/secdev/scapy 대화형 네트워크 패킷 처리, 패킷 생성기, 네트워크 스캐너, 네트워크 디스커버리 및 패킷 스니핑 도구를 내장하며, 다양한 프로토콜 패킷 생성·파싱 플러그인을 제공하여 프로토콜 데이터 패킷을 유연하게 생성하고 수정·파싱할 수 있음
  • https://gitee.com/qielige/openQPA 프로토콜 분석 소프트웨어 QPA의 오픈소스 코드, 프로세스 패킷 캡처와 자동 특성 분석이 특징
  • https://github.com/jtpereyda/boofuzz 네트워크 프로토콜 퍼징 테스트
  • https://www.jianshu.com/p/4dca12a35158 자주 쓰이는 무료 패킷 라이브러리 5선
  • https://github.com/zerbea/hcxdumptool WLAN 장치에서 데이터 패킷 캡처
  • https://github.com/NytroRST/NetRipper putty, winscp, mssql, chrome, firefox, outlook, https 등에서 평문 비밀번호를 가로채는 것을 지원
  • https://github.com/shramos/polymorph 거의 모든 기존 프로토콜을 지원하는 실시간 네트워크 패킷 조작 프레임워크
  • https://github.com/nospaceships/raw-socket-sniffer C, PS, 드라이버 없이 Windows 트래픽 캡처

무선 보안

추천 콘텐츠

  • https://github.com/wi-fi-analyzer/fluxion 사용자 WiFi 비밀번호를 탈취하여 비밀번호 재전송(리플레이) 공격 수행
  • https://github.com/0v3rl0w/e013 WiFi 비밀번호 탈취. VB 스크립트
  • https://github.com/cls1991/ng 현재 연결된 WiFi의 비밀번호와 IP 획득
  • https://github.com/wifiphisher/wifiphisher PY, 중간자(MITM) 공격, FakeAP 악성 핫스팟, WiFi 피싱, 자격 증명 탈취
  • https://github.com/1N3/PRISM-AP RogueAP(악성 핫스팟)을 자동으로 배포하는 MITM 공격 프레임워크
  • https://github.com/sensepost/mana WiFi 하이재킹 도구, 컴퓨터나 기타 모바일 기기의 WiFi 통신을 모니터링하고 해당 기기를 모방할 수 있음
  • https://github.com/deltaxflux/fluxion bash 및 py, WPA 프로토콜을 사용하는 무선 네트워크에 대한 MiTM 공격
  • https://github.com/DanMcInerney/LANs.py ARP 스푸핑, 무선 네트워크 하이재킹

WIFI 방어

  • https://github.com/SYWorks/waidps PY, Linux용 무선 네트워크 침입 탐지 도구
  • https://github.com/SkypLabs/probequest 무선 랜카드 주변의 WiFi Probe 요청을 스니핑하여 표시
  • https://github.com/wangshub/hmpa-pi 라즈베리파이 또는 라우터에서 Wireshark를 이용해 주변 네트워크의 WiFi 장치를 스캔하고, 주변에 휴대폰이나 기타 Wi-Fi 장치가 있으면 이메일 또는 위챗(WeChat)으로 알림
  • https://github.com/besimaltnok/PiFinger WiFi가 "Wifi-Pineapple 대파인애플(大菠萝)"이 연 악성 핫스팟인지 확인
  • https://github.com/WiPi-Hunter/PiSavar PineAP를 이용해 "Wifi-Pineapple 대파인애플(大菠萝)"과 같은 FAKE AP(가짜 액세스 포인트)를 탐지

WIFI 감사

  • https://www.wifislax.com 스페인 WiFi 감사 시스템, 중국어 현지화 버전은 무선혁신(无线革新) 5.1.1 Wifislax-WRC
  • https://cn.elcomsoft.com/ewsa.html ewsa, WiFi 스니핑, 핸드셰이크 패킷 비밀번호 복구, EWSA-173-HC1UW-L3EGT-FFJ3O-SOQB3
  • https://www.passcape.com wifipr, 핸드셰이크 패킷 비밀번호 복구, 이 외에도 Windows용 상업용 비밀번호 복구 도구가 다수 포함
  • https://github.com/MisterBianco/BoopSuite 무선 네트워크 감사 도구, 2-5GHz 대역 지원
  • https://github.com/aircrack-ng/aircrack-ng 패킷 스니퍼, 탐지기, WPA / WPA2-PSK 복호화기, WEP 및 802.11 무선 LAN용 분석 도구로 구성
  • https://github.com/t6x/reaver-wps-fork-t6x WPS PIN 코드 크래킹 공격, 일반적인 WiFi 공격
  • https://github.com/derv82/wifite2 wifite 무선 감사 도구 업그레이드 버전, aircrack-ng 및 reaver 연동
  • https://github.com/savio-code/fern-wifi-cracker 무선 보안 감사 도구
  • https://github.com/P0cL4bs/WiFi-Pumpkin 무선 보안 침투 테스트 스위트
  • https://github.com/entropy1337/infernal-twin 자동화 무선 공격 도구 Infernal-Wireless
  • https://github.com/m4n3dw0lf/PytheM Python 네트워크/침투 테스트 도구
  • https://github.com/InfamousSYN/rogue 무선 네트워크 공격 도구 키트
  • https://github.com/cSploit/android 모바일 WiFi 침투 도구 프레임워크, msf 사용 가능
  • https://github.com/chrisk44/Hijacker 모바일 WiFi 테스트 도구
  • https://andrax-pentest.org/ kali hunter 모바일 침투 테스트 시스템
  • https://www.zimperium.com/zanti-mobile-penetration-testing 모바일 WiFi 침투 도구

데이터 반출

  • https://github.com/TryCatchHCF/Cloakify DLP/MLS 데이터 유출 방지 시스템을 회피하고, 데이터 화이트리스트 제어를 우회하며, AV 탐지를 피해 데이터를 탈취
  • https://github.com/sensepost/DET 단일 또는 다중 채널로 동시에 데이터 반출 수행
  • https://github.com/Arno0x/DNSExfiltrator DNS 해석을 이용해 데이터를 은밀하게 전송하는 도구
  • https://github.com/ytisf/PyExfil 데이터 반출용 Python 패키지
  • https://github.com/Arno0x/ReflectiveDnsExfiltrator 리플렉티브(reflective) DNS 해석 은닉 채널을 통한 데이터 유출

하드웨어 보안

  • https://github.com/unprovable/PentestHardware 하드웨어 침투 테스트 실용 매뉴얼
  • https://ducktoolkit.com/ 러버덕(USB Rubber Ducky), HID 키보드 에뮬레이터
  • https://github.com/insecurityofthings/jackit Mousejack용 개발 코드
  • https://github.com/samyk/magspoof 신용카드 정보 탈취
  • https://github.com/mame82/P4wnP1_aloa 라즈베리파이(Raspberry Pi)에 자주 쓰이는 테스트 구성 요소를 설치하여 모바일 테스트 플랫폼 구축
  • https://www.freebuf.com/geek/195631.html 피지컬 해커가 되어보자! 라즈베리파이로 P4wnP1 프로젝트를 구현하여 침투 테스트 수행
  • https://github.com/mame82/P4wnP1 라즈베리파이에 네트워크 하이재킹 키보드 인젝션(WHID) 도구 설치
  • https://github.com/ebursztein/malusb 크로스 플랫폼 HID 스푸핑 payload를 생성하고 Windows 및 OSX에서 리버스 TCP 셸 구축
  • https://github.com/Orange-Cyberdefense/fenrir-ocd 주요 기능은 유선 802.1x 보호를 우회하여 대상 네트워크에 접근할 수 있게 하는 것
  • https://github.com/360PegasusTeam/GhostTunnel 격리된 환경에서 HID를 사용하여 은닉 백도어를 생성하고, payload를 방출한 뒤 스스로를 삭제
  • https://github.com/LennyLeng/RadioEye RFID를 일반적인 NFC와 함께 사용
  • https://github.com/Proxmark/proxmark3/ RFID 필수 장비 PM3
  • http://www.freebuf.com/news/others/605.html RFID Hacking – 리소스 대모음
  • https://github.com/UnicornTeam/HackCube-Special 유니콘 랩(UnicornTeam) 하드웨어 침투 테스트 플랫폼

IoT 보안

추천 콘텐츠

  • https://github.com/w3h/icsmaster 산업제어(ICS) 보안 리소스 통합
  • https://github.com/V33RU/IoTSecurity101 IoT 산업제어 보안 및 사물인터넷(IoT) 보안 학습용 문서와 리소스
  • http://www.freebuf.com/ics-articles 산업제어(ICS) 관련
  • http://www.freebuf.com/sectool/174567.html 산업제어시스템(ICS) 보안 전문가에게 필수적인 테스트 도구 및 보안 리소스
  • http://www.freebuf.com/articles/ics-articles/178822.html 석탄 기업의 산업제어 보안 체계 구축 방법 간단 분석
  • http://www.freebuf.com/articles/network/178251.html 산업제어 보안 현장 구현 경험담: 산업제어 시스템의 호스트 보호 강화 방법
  • https://github.com/hslatman/awesome-industrial-control-system-security 산업제어 시스템 보안 분야 우수 리소스 수집 저장소
  • https://github.com/adi0x90/attifyos IoT 통합 보안 테스트 시스템, 자주 쓰이는 일부 소프트웨어 포함
  • https://github.com/moki-ics/moki kali와 유사한 산업제어 침투 테스트 시스템을 원클릭으로 구성하는 스크립트,
  • https://gitlab.com/expliot_framework/expliot py3, 산업제어 보안 취약점 테스트 프레임워크
  • https://github.com/dark-lbp/isf py2, 산업제어 분야의 msf 유사 테스트 프레임워크
  • https://github.com/enddo/smod py2, scapy 모듈을 사용하며 주로 Modbus 프로토콜 테스트에 특화
  • https://github.com/shodan-labs/iotdb nmap과 shodan API를 연동하여 IoT 장치 스캔
  • https://github.com/XHermitOne/icscanner GUI가 있는 ICS 스캐너
  • https://github.com/yanlinlin82/plcscan TCP/102 및 TCP/502를 통해 인터넷상의 PLC 장치 및 기타 Modbus 장치 식별
  • https://github.com/nsacyber/GRASSMARLIN NSA 산하 ICS/SCADA 상황 인식(Situational Awareness) 도구
  • https://github.com/nezza/scada-stuff SCADA/ICS 장치에 대한 리버스 엔지니어링 및 공격

카메라 보안

  • https://github.com/woj-ciech/kamerka shodan API로 스캔한 카메라의 지리적 위치를 지도에 표시
  • https://github.com/Ullaakut/cameradar GO, 카메라 RTSP 프로토콜 침투 테스트, 약한 패스워드 사전 포함
  • https://github.com/Ullaakut/camerattack GO, 카메라 원격 비활성화
  • https://github.com/NIteshx2/UltimateSecurityCam py3, 카메라로 외부인을 감시하는 소프트웨어, 안티 스푸핑 설정 포함

라우터 보안

  • http://stascorp.com RouterScan, 러시아 개발자가 만든 라우터 취약점 이용 도구, 매우 강력한 GUI
  • https://github.com/threat9/routersploit py3, msf를 본뜬 라우터 취약점 이용 프레임워크
  • https://github.com/jh00nbr/Routerhunter-2.0 업데이트 중단, 라우터 취약점 스캔·이용
  • https://github.com/googleinurl/RouterHunterBR php, 라우터 장치 취약점 스캔·이용
  • https://github.com/scu-igroup/telnet-scanner Telnet 서비스 비밀번호 대입 공격(크리덴셜 스터핑)

퍼징(FUZZ) 테스트

  • http://www.freebuf.com/articles/rookie/169413.html Fuzzing 학습을 위한 리소스 총정리
  • https://github.com/secfigo/Awesome-Fuzzing Fuzz 관련 학습 자료
  • https://github.com/fuzzdb-project/fuzzdb fuzz 자료 데이터베이스
  • https://github.com/ivanfratric/winafl Windows 바이너리 퍼징용 AFL, 오리지널 기술 분석 | AFL 취약점 발굴 기술 담론
  • https://github.com/attekett/NodeFuzz a fuzzer harness for web browsers and browser like applications.
  • https://github.com/google/oss-fuzz Continuous Fuzzing for Open Source Software
  • http://blog.topsec.com.cn/ad_lab/alphafuzzer/ 파일 형식 위주의 취약점 발굴 도구
  • https://bbs.ichunqiu.com/thread-24898-1-1.html Test404 - HTTP Fuzzer V3.0
  • https://github.com/xmendez/wfuzz py, 웹 보안 퍼징 테스트 도구, 모듈식으로 burp에서 캡처한 요청·응답 패킷 처리 가능
  • https://github.com/1N3/BlackWidow Python 기반 웹 크롤러, 대상 웹사이트의 인텔리전스 정보를 수집하고 OWASP 취약점을 퍼징
  • https://github.com/bunzen/pySSDeep py, 퍼지 해싱(Fuzzy Hashing) 알고리즘 기반 도구. go: glaslos/ssdeep; C: ssdeep-project/ssdeep
  • https://github.com/googleprojectzero/winafl Windows 바이너리를 대상으로 하는 AFL 테스트

모바일 보안

  • https://github.com/Brucetg/App_Security App 보안 학습 리소스
  • https://github.com/rovo89/Xposed 안드로이드 폰 시스템을 자유자재로 수정
  • https://github.com/android-hacker/VirtualXposed VirtualApp과 epic 기반으로 비 ROOT 환경에서 Xposed 모듈을 실행하는 구현
  • https://github.com/MobSF/Mobile-Security-Framework-MobSF 모바일 보안 감사 프레임워크. android, ios, win
  • https://github.com/WooyunDota/DroidSSLUnpinning 안드로이드 인증서 고정(SSL Pinning) 해제 도구
  • https://github.com/nccgroup/house 런타임 모바일 앱 분석 도구 키트, Web GUI 포함
  • https://github.com/UltimateHackers/Diggy APK 파일에서 URL을 추출하는 도구
  • https://github.com/nettitude/scrounger iOS 및 Android 모바일 애플리케이션 침투 테스트 프레임워크
  • https://github.com/XekriCorp/LeakVM 안드로이드 앱 보안 테스트 프레임워크
  • https://github.com/zsdlove/ApkVulCheck 안드로이드 취약점 스캔 도구
  • https://github.com/samyk/frisky iOS/macOS 앱 대상 스니핑/수정/리버스 엔지니어링/인젝션 등 도구
  • https://github.com/GeoSn0w/OsirisJailbreak12 IOS12 불완전 탈옥
  • https://github.com/chaitin/passionfruit iOS 앱 리버스 엔지니어링·분석 도구, iOS 앱 보안 분석 과정을 크게 가속화

클라우드 보안

  • https://github.com/stuhirst/awssecurity/blob/master/arsenal.md AWS 보안 탐지 관련 프로젝트 목록
  • https://github.com/toniblyx/my-arsenal-of-aws-security-tools AWS 보안 도구 모음
  • https://github.com/sa7mon/S3Scanner Amazon 공개 S3 버킷 및 덤프 스캔
  • https://github.com/kromtech/s3-inspector Amazon AWS S3 버킷 권한(permissions) 탐지
  • https://github.com/jordanpotti/AWSBucketDump AWS S3 버킷을 열거하여 민감한 기밀 파일 검색
  • https://github.com/sa7mon/S3Scanner Amazon 공개 S3 버킷 및 덤프 스캔
  • https://github.com/kromtech/s3-inspector Amazon AWS S3 버킷 권한(permissions) 탐지
  • https://github.com/jordanpotti/AWSBucketDump AWS S3 버킷을 열거하여 민감한 기밀 파일 검색
  • https://github.com/Netflix/repokid AWS 최소 권한(least privilege) 정책 배포 도구
  • https://github.com/RhinoSecurityLabs/pacu AWS 취약점 탐지 프레임워크
  • https://github.com/0xbug/Hawkeye GitHub 유출 모니터링 시스템
  • https://github.com/neal1991/gshark GitHub 정보 유출 탐지
  • https://github.com/VKSRC/Github-Monitor GitHub 모니터링, 코드 정보 유출, 분 단위 모니터링, 이메일 경고
  • https://github.com/metac0rtex/GitHarvester GitHub Repo 정보 수집 도구
  • https://github.com/repoog/GitPrey GitHub 민감 정보 스캔 도구
  • https://github.com/FeeiCN/GSIL py3, GitHub 민감 정보를 준실시간으로 모니터링하고 경고 알림 전송.
  • https://github.com/UnkL4b/GitMiner GitHub 민감 콘텐츠 마이닝
  • https://github.com/dxa4481/truffleHog GitHub 민감 정보 스캔 도구, commit 탐지 등 포함

리버스 엔지니어링

  • https://www.peerlyst.com/posts/resource-learning-how-to-reverse-malware-a-guide 악성코드 리버스 엔지니어링 가이드 및 도구 모음
  • https://github.com/ReFirmLabs/binwalk 바이너리·펌웨어 파일 자동 리버스 엔지니어링, 다양한 플러그인 보유
  • https://github.com/angr/angr 동적 기호 실행(symbolic execution) 및 정적 분석 기능을 갖춘 바이너리 분석 도구
  • https://github.com/endgameinc/xori 커스텀 디스어셈블리 프레임워크
  • https://down.52pojie.cn/ 우아이포지에(吾爱破解) 아이판(爱盘) 도구 키트
  • https://github.com/blacknbunny/peanalyzer32 PE 파일 분석 및 디스어셈블리 도구
  • https://github.com/DominicBreuker/pspy root 권한 없이 프로세스 실행 모니터링

CTF 관련

  • https://ctf-wiki.github.io/ctf-wiki/ CTFwiki, Misc/Crypto/Web/Assembly/Executable/Reverse/Pwn/Android/ICS
  • https://github.com/adon90/pentest_compilation CTF 대회와 OSCP 시험에서 자주 나오는 지식 포인트 및 명령어
  • https://github.com/gabemarshall/microctfs 소형 CTF 이미지 docker
  • https://github.com/giantbranch/pwn_deploy_chroot 여러 pwn 문제를 하나의 docker 컨테이너에 배포
  • https://github.com/facebook/fbctf CTF 대회 프레임워크
  • https://github.com/0Chencc/CTFCrackTools CTF 도구 통합 패키지
  • https://github.com/guyoung/CaptfEncoder CTF 암호·인코딩 올인원 패키지, 미니 프로그램 버전도 있음
  • https://github.com/Gallopsled/pwntools pwn 유형, 바이너리 익스플로잇 프레임워크
  • https://github.com/ChrisTheCoolHut/Zeratool pwn 유형, 바이너리 익스플로잇 프레임워크
  • https://github.com/ChrisTheCoolHut/Rocket-Shot pwn, 자동 공격 스크립트
  • https://0xrick.github.io/lists/stego/ 스테가노그래피 도구 모음, Steganography - A list of useful tools and resources
  • https://github.com/DominicBreuker/stego-toolkit 스테가노그래피 도구 키트
  • https://github.com/bugsafe/WeReport WeReport 리포트 도우미
  • https://github.com/PELock/CrackMeZ3S-CTF-CrackMe-Tutorial CTF 대회용 CrackMe 소프트웨어 작성

포렌식 조사

추천 콘텐츠

  • https://www.freebuf.com/articles/rookie/195107.html 위챗(WeChat) 데이터베이스 복호화 과정 기록. 위챗 암호화 데이터베이스의 복호화 비밀번호는 “기기 IMEI(MEID) + 사용자 uin을 MD5로 해시한 후 앞 7자리 소문자”로 구성됨
  • https://www.audacityteam.org/ 오디오 파일 및 파형(waveform) 처리 도구
  • http://www.sweetscape.com/010editor/ 다양한 파일 형식(템플릿)을 식별하는 16진수 편집기, 파일 복구 기능 보유
  • http://www.magicexif.com/ 사진 이미지의 EXIF 정보를 데이터화
  • http://mediaarea.net/MediaInfo exiftool과 유사하게 콘텐츠 영역 및 메타데이터 정보 확인
  • https://www.sno.phy.queensu.ca/~phil/exiftool/ 이미지 파일의 EXIF 메타데이터 검사
  • https://www.gimp.org/ Gimp는 다양한 이미지 파일의 시각적 데이터 변환 기능을 제공하며, 파일이 실제 이미지 파일인지 확인하는 데에도 사용 가능
  • https://github.com/volatilityfoundation/volatility Windows 메모리 포렌식 분석
  • https://github.com/gleeda/memtriage Windows 메모리 포렌식 분석
  • https://github.com/SekoiaLab/Fastir_Collector Windows 포렌식/정보 수집, 메모리, 레지스트리, 파일 정보 등에 국한되지 않음
  • https://github.com/Viralmaniar/Remote-Desktop-Caching- RDP 정보 복원, png 이미지 형식
  • https://github.com/comaeio/LiveCloudKd C, Hyper-V 대상 메모리 포렌식 -https://github.com/sevagas/swap_digger Linux swap 대상 포렌식 분석 도구
  • http://extundelete.sourceforge.net/ Linux 파일 복구
  • https://github.com/viaforensics/android-forensics 안드로이드 포렌식 앱 및 프레임워크, 안드로이드 기기 내 다양한 정보 추출 가능
  • https://github.com/davidmcgrew/joy 내·외부 네트워크 트래픽 데이터를 캡처하고 분석하는 도구, 주로 네트워크 조사, 보안 모니터링, 포렌식에 사용
  • https://github.com/USArmyResearchLab/Dshell 확장 가능한 네트워크 포렌식 분석 프레임워크, 플러그인 신속 개발과 네트워크 패킷 캡처 파싱 지원

샘플 분석

  • https://github.com/open-power-workgroup/Hospital 전국 푸톈계(莆田系) 병원 명단
  • https://github.com/chenerlich/FCL 악성코드가 사용하는 명령줄(command line) 수집
  • https://paper.seebug.org/421 일반 소프트웨어 모음 및 악성코드 분석
  • https://github.com/sapphirex00/Threat-Hunting apt 악성코드 샘플
  • https://www.malware-traffic-analysis.net/ 악성코드 샘플
  • http://dasmalwerk.eu/ 악성코드 샘플
  • https://github.com/ytisf/theZoo 악성코드 샘플
  • https://github.com/mstfknn/malware-sample-library 악성코드 샘플
  • http://99.248.235.4/Library/ 악성코드 샘플 라이브러리. ladder
  • https://github.com/robbyFux/Ragpicker 악성코드 정보 크롤링 및 종합 분석
  • https://github.com/phage-nz/ph0neutria 악성코드 정보 크롤링 및 종합 분석
  • https://github.com/JR0driguezB/malware_configs 일반적인 악성 설정 파일
  • https://github.com/sfaci/masc 웹사이트 내 악성코드 스캔 및 기타 웹사이트 유지보수 기능
  • https://github.com/Neo23x0/munin 파일 Hash를 기반으로 다양한 온라인 악성코드 스캔 서비스에서 정보를 추출하는 도구
  • https://github.com/1lastBr3ath/drmine 웹페이지에 채굴(마이닝) 스크립트가 포함되어 있는지 자동 탐지하는 도구
  • https://github.com/KasperskyLab/klara 카스퍼스키(Kaspersky) 오픈소스 Yara 기반 분산 악성코드 스캔 시스템,
  • https://github.com/botherder/kraken go, Yara 악성코드 스캐너 구현
  • https://github.com/alexandreborges/malwoverview simple, 악성 파일을 신속하게 분류
  • https://github.com/joxeankoret/pigaios 소스 코드와 컴파일된 바이너리를 직접 비교

보안 제품

  • https://www.freebuf.com/sectool/135032.html 탐지하기 어려운 고상호작용형(high-interaction) 허니팟 구축
  • https://bloodzer0.github.io/ossa/ 오픈소스 자료를 활용한 오픈소스 보안 아키텍처. 호스트, 스캐너, 포트, 로그, 보호 장치 등
  • https://github.com/dvf/blockchain Python으로 블록체인을 처음부터 구현
  • https://github.com/crazywa1ker/DarthSidious-Chinese 0부터 시작하는 도메인 침투 여정, DarthSidious 중국어 버전
  • https://paper.seebug.org/772/ ISF의 산업제어 프로토콜 구성 요소와 KittyFuzzer를 결합하여 산업제어 프로토콜을 Fuzz하는 방법

보안 운영

추천 콘텐츠- https://github.com/chaitin/cloudwalker CloudWalker(牧云)서버 보안 관리 플랫폼으로, 서버 자산 관리, 위협 스캔, Webshell 탐지·치료, 기준선 점검 등의 기능을 점차적으로 지원합니다.

  • https://github.com/mitre/caldera mitre사의 공격 시뮬레이션 테스트 시스템으로, 주로 Windows에서 사용됩니다.
  • https://github.com/guardicore/monkey 네트워크 보안 상태를 평가하며, 스캐너와 C2C 서버로 구성됩니다. 기본 비밀번호와 exp를 이용해 ssh, smb 등 다양한 프로토콜 방식으로 공격 탐지를 수행합니다.
  • https://github.com/grayddq/PublicSecScan awvs를 호출하여 대량의 WEB 자산에 대해 분산형 WEB 보안 스캔을 수행하고, 웹 환경에서 흔히 발생하는 보안 취약점을 발견합니다.
  • https://github.com/jeffzh3ng/Fuxi-Scanner 자산 관리, 취약점 탐지에 awvs, 创宇 Pocsuite, nmap, hydra를 통합합니다.
  • https://github.com/infobyte/faraday 협업 침투 테스트 및 취약점 관리 플랫폼으로, 다양한 도구를 통합합니다.
  • https://github.com/DefectDojo/django-DefectDojo django 기반의 취약점 자산 관리 플랫폼
  • https://github.com/creditease-sec/insight web 인터페이스. 宜信(CreditEase) 보안부에서 개발했으며, 애플리케이션 시스템 자산 관리, 취약점 전체 수명주기 관리, 보안 지식베이스 관리를 통합한 삼위일체 관리 플랫폼입니다.
  • https://github.com/RASSec/A_Scan_Framework 취약점 관리, 자산 관리, 작업 스캔 시스템
  • https://github.com/cea-sec/ivre 네트워크 자산 핑거프린트 발견. 자신만의 shodan과 zoomeye를 구축할 수 있습니다.
  • https://github.com/ysrc/xunfeng web 인터페이스. 同程 보안에서 개발한 네트워크 자산 식별 엔진, 취약점 탐지 엔진
  • https://github.com/superhuahua/xunfengES web 인터페이스. 巡风(xunfeng) 기반으로 개발. 한 사람의 보안부
  • https://github.com/zhaoweiho/SecurityManageFramwork py3, django. 기업 내부 네트워크 보안 관리 플랫폼으로, 자산 관리, 취약점 관리, 계정 관리, 지식베이스 관리, 보안 스캔 자동화 기능 모듈을 포함합니다.
  • https://github.com/grayddq/PublicMonitors 공인 IP 목록에 대해 포트 서비스 스캔을 수행하여, 주기 내 포트 서비스 변화 상황과 취약한 비밀번호 보안 위험을 발견합니다. 한 사람의 보안부
  • https://github.com/grayddq/PubilcAssetInfo 주요 목표는 발주 기관(甲方) 보안 담당자의 관점에서 기업의 도메인과 서버 공인 IP 자산을 최대한 수집·발견하는 것입니다. 예: 바이두 클라우드, 알리바바 클라우드, 텐센트 클라우드 등. 한 사람의 보안부
  • https://github.com/maya6/SiteScan web 인터페이스, py3 celery. 자산 수집

셸 탐지·치료

  • http://www.safedog.cn/ 安全狗(SafeDog) 웹 방화벽
  • http://d99net.net/ win, 啊D 제작 D盾(D-Shield) 방화벽. WAF와 webshell 탐지 기능 포함
  • https://github.com/he1m4n6a/findWebshell py, webshell 점검 도구. 추후 백도어 핑거프린트를 추가할 수 있어 매우 강력함
  • https://github.com/ym2011/ScanBackdoor 간결한 Webshell 스캔 도구
  • https://github.com/erevus-cn/scan_webshell webshell 스캔 도구
  • https://github.com/yassineaddi/BackdoorMan 지정된 디렉터리에서 php webshell을 탐지할 수 있음
  • https://github.com/nbs-system/php-malware-finder 고효율 PHP-webshell 스캔 도구
  • https://github.com/emposha/PHP-Shell-Detector 탐지 효율이 무려 99%에 달하는 webshell 탐지 도구
  • https://github.com/emposha/Shell-Detector Webshell 스캔 도구. php/perl/asp/aspx webshell 스캔 지원

부하 테스트

  • https://github.com/ywjt/Dshield DDOS 방어
  • https://github.com/NewEraCracker/LOIC/ Windows용으로 설계된 네트워크 부하 테스트 도구. 현재는 Mac OS도 지원함——역자 주
  • https://github.com/649/Memcrashed-DDoS-Exploit Memcached 서버를 악용한 DDoS 공격 도구. Memcached 서버에 위조된 UDP 패킷을 보내 공격 대상에게 대량의 패킷을 응답하게 함
  • https://github.com/jseidl/GoldenEye py, DOS 테스트
  • https://github.com/mschwager/dhcpwn DHCP IP 리소스 고갈 공격 도구
  • https://github.com/Microsoft/Ethr GO, 크로스 플랫폼, TCP, UDP, HTTP, HTTPS 부하 테스트 도구

허니팟 기초

  • https://github.com/paralax/awesome-honeypots 허니팟 오픈소스 기술 모음
  • https://github.com/threatstream/mhn 현대적 허니넷. 다양한 허니팟 설치 스크립트를 통합하여 빠르게 배포·사용할 수 있고, 노드에서 데이터도 빠르게 수집할 수 있음
  • https://github.com/dtag-dev-sec/tpotce T-POT. docker 기술로 여러 허니팟을 조합하며, ELK와 함께 연구 및 데이터 캡처를 수행
  • https://www.freebuf.com/sectool/190840.html T-Pot 다중 허니팟 플랫폼 사용 노하우
  • https://github.com/n3uz/t-pot-autoinstall fork한 T-POT 허니팟의 원클릭 설치 스크립트를 중국 내 가속 미러로 교체

허니팟 점검

  • https://github.com/micheloosterhof/cowrie py2, ELK(ElasticSearch,LogStash,Kibana)로 데이터 분석을 수행. 현재 ssh, telnet, sftp 등 프로토콜 지원
  • https://github.com/mushorg/snare py3, 웹 보안 허니팟. 지정된 웹 페이지를 클론할 수 있음
  • https://github.com/honeynet/beeswarm py, agent 프로브와 허니팟의 실시간 상호작용으로 공격자를 유인
  • https://github.com/thinkst/opencanary PY2,SNMP\RDP\SAMBA 허니팟
  • https://github.com/p1r06u3/opencanary_web PY, TORNADO, 내부 네트워크 저상호작용 허니팟. 자동 설치를 지원하며 현재 일반적인 16가지 프로토콜을 지원. 현재는 프로브/허니팟-관리 아키텍처이며, 프로브-샌드박스-관리 아키텍처로 2차 개발을 고려할 수 있음
  • https://github.com/p1r06u3/opencanary_web
  • https://github.com/Cymmetria 유명한 디셉션 방어(deception defense) 허니팟 조직. Struct, weblogic, telnet, Cisco ASA, Micros 등 시뮬레이션 허니팟
  • https://github.com/Cymmetria/honeycomb Cymmetria 사의 오픈소스 허니팟 프레임워크, 저상호작용
  • https://github.com/honeytrap/honeytrap 확장 가능한 허니팟 프레임워크. 프로브 배포와 고상호작용 허니팟 지원
  • https://gosecure.net/2018/12/19/rdp-man-in-the-middle-smile-youre-on-camera/ RDP MITM. 이미지와 키 입력을 기록할 수 있는 RDP 허니팟 구축(https://github.com/gosecure/pyrdp)

카메라 허니팟

  • https://github.com/alexbredo/honeypot-camera py, 카메라 허니팟. tornado로 WEB 서비스를 시뮬레이션하고 이미지가 비디오를 대체함. 추후 이미지와 버튼을 더 추가하는 것을 고려할 수 있음
  • https://github.com/EasyDarwin/EasyIPCamera C, RTSP 서버 컴포넌트로 카메라 허니팟 구축에 사용

산업제어 허니팟

  • https://github.com/sjhilt/GasPot 석유·전력·가스 산업제어 시스템 시뮬레이션
  • https://github.com/djformby/GRFICS IoT 산업 시뮬레이션 시스템 모의 프레임워크. MODBUS 프로토콜로 PLC 가상 머신을 감시·제어
  • https://github.com/RabitW/IoTSecurityNAT IoT 테스트 시스템. 다양한 장치를 빠르게 연결하여 보안 테스트를 수행하기 편리함
  • https://github.com/mushorg/conpot ICS/SCADA를 대상으로 하는 저상호작용 산업제어 허니팟. Modbus와 S7comm 시뮬레이션

보안 방어

추천 콘텐츠

  • https://github.com/baidu/Advbox Advbox는 여러 딥러닝 플랫폼을 지원하는 AI 모델 보안 툴박스입니다. 화이트박스·블랙박스 알고리즘으로 적대적 샘플(adversarial sample)을 생성하여 AI 모델의 강건성(robustness)을 측정할 수 있고, 일반적인 방어 알고리즘도 지원합니다.
  • https://github.com/quoscient/octopus 블록체인 스마트 계약 보안 분석 도구
  • https://github.com/Cyb3rWard0g/HELK 고급 분석 기능을 갖춘 위협 헌팅 ELK
  • https://github.com/trimstray/otseca linux 시스템 감사 도구. 시스템 구성을 내보내고 보고서를 생성할 수 있음
  • https://github.com/BugScanTeam/DNSLog django 기반으로 DNS 해석 기록과 HTTP 접근 기록을 모니터링하는 도구. 블라인드 인젝션, xss, 상대방 실제 IP 확인 등에 활용할 수 있음
  • https://github.com/mwrlabs/dref DNS 리바인딩 활용 프레임워크
  • https://github.com/chengr28/Pcap_DNSProxy/blob/master/README.zh-Hans.md Pcap_DNSProxy는 WinPcap/LibPcap 기반으로 DNS 스푸핑 오염을 필터링하는 도구입니다.
  • https://github.com/PlagueScanner/PlagueScanner python으로 구현한 ClamAV, ESET, Bitdefender 통합 안티바이러스 엔진
  • https://github.com/m4rco-/dorothy2 트로이 목마·봇넷 분석 프레임워크
  • http://github.com/jumpserver/jumpserver Python3 기반의 오픈소스 배스천 호스트
  • https://github.com/github/glb-director 로드 밸런싱 컴포넌트 GLB. 데이터 처리에 dpdk 사용
  • https://github.com/processhacker/processhacker 시스템 리소스 모니터링, 소프트웨어 디버깅, 악성 소프트웨어 탐지, 프로세스 관리
  • https://github.com/TKCERT/mail-security-tester 메일 보호·필터링 시스템을 테스트하는 프레임워크
  • https://github.com/chaitin/sqlchop-http-proxy HTTP 리버스 프록시를 활용하며, SQLChop를 SQL 인젝션 공격 탐지 모듈로 내장하여 SQL 인젝션 트래픽은 차단하고 정상 트래픽은 통과시킵니다.
  • https://github.com/OWASP/SecureTea-Project 누군가 허락 없이 컴퓨터 마우스나 터치패드를 만지면 경보를 울립니다.
보안 장비
  • https://github.com/baidu/openrasp RASP, Runtime Application Self-Protection, 실시간 애플리케이션 자가 보호. 더 지능적이며 언어별로 맞춤 제작됩니다.
  • https://github.com/snort3/snort3 snort는 가장 유명한 오픈소스 IDS 침입 탐지 시스템입니다.
  • https://github.com/chaitin/yanshi 长亭(Chaitin) 偃师(yanshi), 雷池(SafeLine) 방화벽 코어 엔진에 사용되는 코드 생성 도구
  • https://github.com/SpiderLabs/ModSecurity C, 크로스 플랫폼. Apache, IIS 및 Nginx용 WAF 엔진
  • https://github.com/klaubert/waf-fle ModSecurity 웹 콘솔
  • https://github.com/xsec-lab/x-waf 중소기업에 적합한 클라우드 WAF
  • https://github.com/jx-sec/jxwaf openresty/nginx+lua 기반으로 개발. 독자적인 비즈니스 로직 보호 엔진과 머신러닝 엔진으로 기존 WAF가 비즈니스 보안을 보호하지 못하는 문제점을 해결합니다.
  • https://github.com/loveshell/ngx_lua_waf lua-nginx-module(openresty) 기반의 웹 애플리케이션 방화벽
  • https://github.com/Janusec/janusec Golang 기반으로 개발된 애플리케이션 보안 게이트웨이. WAF, CC 공격 방어, 인증서 개인키 암호화, 로드 밸런싱, 통합 웹 관리 등의 기능을 갖추고 있습니다.
  • https://github.com/SpiderLabs/owasp-modsecurity-crs a set of generic attack detection rules for use with ModSecurity or compatible web application firewalls
  • https://github.com/kirillwow/ids_bypass IDS 우회 스크립트
  • https://github.com/milo2012/ipv4bypass ipV6 주소를 이용한 WAF 우회
  • https://github.com/3xp10it/bypass_waf 방화벽 우회 스크립트
  • https://github.com/m0rtem/CloudFail Cloudfail 대상, CDN 뒤에 있는 웹사이트의 실제 IP 찾기
  • https://github.com/Nitr4x/whichCDN CDN 식별·탐지
  • https://github.com/3xp10it/xcdn cdn 뒤의 실제 IP를 찾으려고 시도. 3xp10it.github.io 블로그

침입 탐지

  • https://github.com/Neo23x0/Loki APT 침입 흔적 스캐너
  • https://github.com/ossec/ossec-hids 오픈소스 HIDS 배스천 호스트
  • https://github.com/grayddq/HIDS hids, 호스트 기반 침입 탐지 시스템(HIDS). 한 사람의 보안부
  • https://github.com/ysrc/yulong-hids Yulong(驭龙) HIDS는 YSRC가 오픈소스로 공개한 침입 탐지 시스템입니다.
  • https://github.com/DianrongSecurity/AgentSmith-HIDS 点融(Dianrong)이 오픈소스로 공개한 HIDS. 오픈소스 부분은 호스트 정보 수집 도구
  • https://github.com/Tencent/HaboMalHunter Habo(哈勃) 분석 시스템. linux 시스템 바이러스 분석 및 보안 테스트
  • https://github.com/JPCERTCC/LogonTracer Windows 로그인 기록 로그를 분석하여 악성 로그인 행위를 그래픽으로 표시
  • https://github.com/anwi-wips/anwi 무선 IDS, 저비용 Wi-Fi 모듈(ESP8266) 기반
  • https://github.com/Security-Onion-Solutions/security-onion ubuntu 기반의 침입 탐지, 네트워크 보안 모니터링, 로그 관리용으로 분산 아키텍처를 사용
  • https://github.com/jpcertcc/sysmonsearch Sysmon의 로그 결과를 시각화
  • http://m.imooc.com/article/21236 컴퓨터가 해커에게 침입당했는지 빠르게 자가 점검(Windows 버전)
  • http://www.freebuf.com/articles/system/157597.html 컴퓨터가 해커에게 침입당했는지 빠르게 자가 점검(Linux 버전)
  • http://www.freebuf.com/rookie/179638.html 서버 침입 출처 추적(forensics) 팁 모음
  • https://github.com/zhanghaoyil/Hawk-I 비지도 머신러닝 알고리즘 기반으로 Web 로그에서 공격 Payload를 자동 추출

기타 콘텐츠

온라인 리소스

  • https://github.com/DoubleLabyrinth/navicat-keygen navicat 키젠
  • https://github.com/DoubleLabyrinth/MobaXterm-keygen MobaXterm 키젠
  • http://www.zdfans.com zd423 - 소프트웨어 공유 플랫폼 선두주자
  • https://www.flaticon.com 무료 아이콘 웹사이트
  • https://msdn.itellyou.cn 순정(오리지널) 이미지
  • https://www.freenom.com 무료 도메인 등록, DNS 해석
  • https://codebeautify.org 온라인 코드 미화
  • http://patorjk.com Text to ASCII Art Generator
  • https://www.seopojie.com SPAM,SEO

오피스 제품군

  • https://sadd.io/ 온라인 운영체제
  • https://github.com/zyx0814/dzzoffice 온라인 오피스 제품군. DEMO 사이트: demo.dzzoffice.com
  • https://github.com/RobbieHan/gistandard py, Django 기반, OA 티켓 사무 관리 시스템
  • https://github.com/pavanw3b/sh00t PY3, DJANGO, 보안 테스트 티켓 관리
  • https://github.com/chaitin/strapdown-zeta strapdown.js 기반, 长亭(Chaitin)이 2차 개발한 오픈소스 Wiki 시스템. markdown 지원
  • https://etherpad.net/ 온라인 편집 가능 메모장
  • https://www.upload.ee/ 파일 공유 플랫폼
  • https://github.com/micahflee/onionshare onion(양파) 서버를 이용한 익명 파일 공유
  • https://github.com/filebrowser/filebrowser GO, Caddy 프레임워크 기반의 클라우드 드라이브
  • https://github.com/nextcloud/server php, 사설 클라우드 드라이브. owncloud 포크(fork)
  • https://github.com/owncloud/core php, 사설 클라우드 드라이브. 인터페이스가 예쁘지 않음
  • https://github.com/haiwen/seafile C, 사설 클라우드 드라이브. 속도는 빠르지만 기능이 적음
  • https://github.com/ymfe/yapi API 관리 도구
  • https://thyrsi.com/ 이미지 업로드·공유 도구

온라인 서비스

  • https://github.com/Kickball/awesome-selfhosted awesome 시리즈 중 자체 호스팅(self-hosted) 애플리케이션
  • https://github.com/littlecodersh/itchat 위챗 개인 계정 인터페이스, 위챗 봇, 명령줄 위챗
  • https://github.com/sym233/core-values-encoder js, 사회주의 핵심 가치관 암호화, https://sym233.github.io/core-values-encoder/
  • https://github.com/valentinxxx/nginxconfig.io/ 온라인 nginx 설정 파일 생성. 데모 사이트 https://nginxconfig.io
  • https://github.com/asciimoo/searx 자신만의 검색 엔진 구축. DEMO 사이트 https://searx.me/
  • http://sc.ftqq.com/3.version server酱(ServerChan) 위챗 알림
  • https://osint.link Open Source Intelligence (OSINT) Tools & Resources
  • https://www.wolframalpha.com 질문에 대해 바로 답을 제시하는 웹사이트
  • shodan.io 인터넷 인식 엔진
  • fofa.so 白帽汇 NOSEC
  • https://www.oshadan.com 傻蛋(Shadan) 인터넷 연결 장치 검색_湖南安数网络
  • zoomeye.org 知道创宇(Knownsec) 인터넷 인식 엔진
  • https://sms.cngrok.com/receiving-sms SMS 가상번호 수신
  • https://www.pdflibr.com/ SMS 가상번호 수신
  • https://www.fakenamegenerator.com 다국적 신원 정보 생성기
  • https://recruitin.net Easily use Google to search profiles on LinkedIn
  • https://www.truthfinder.com 미국 시민 정보 조회
  • https://verify-email.org 이메일 진위(유효성) 검증
  • https://safeweb.norton.com 노턴 웹사이트 보안 검사
  • http://www.vuln.cn/tools/ftp 온라인 FTP 로그인

개인이 유지관리하는 보안 경보 위키입니다. 중화인민공화국 《네트워크 보안법》 관련 정책 규정에 따라, 본 문서는 보안 경보 목적으로만 제공되며 본 문서의 기술적 수단을 통한 불법 행위는 허용되지 않습니다. 기술 사용에 따른 위험은 사용자 본인이 부담합니다.

도구 다운로드
  • https://github.com/Audi-1/sqli-labs SQLite 기반 sql 인젝션 학습 랩
  • https://github.com/lcamry/sqli-labs sqli-labs로 mysql 관련 인젝션 기법 시연
  • https://github.com/c0ny1/upload-labs 모든 유형의 업로드 취약점을 정리해 주는 랩
  • https://github.com/LandGrey/upload-labs-writeup upload-labs 가이드 매뉴얼
  • https://github.com/Go0s/LFIboomCTF 로컬 파일 포함(LFI) 취약점 && PHP 활용 프로토콜 && 실습 소스코드
  • https://in.security/lin-security-practise-your-linux-privilege-escalation-foo/ linux 권한 상승 연습용 가상 머신 파일
  • https://github.com/OWASP/igoat ios 애플리케이션 테스트 및 보안에 적합한 학습 도구
  • https://github.com/prateek147/DVIA-v2 ios 애플리케이션 테스트 및 보안에 적합한 학습 도구
  • https://github.com/rapid7/metasploitable3 metasploit 연습 시스템
  • https://github.com/rapid7/metasploit-vulnerability-emulator perl 기반 metasploit 시뮬레이션 환경, 조작 연습
  • https://github.com/chryzsh/DarthSidious AD 도메인 환경 구축, 침투, 방어
  • https://github.com/c0ny1/xxe-lab php, java, python, C# 등 다양한 언어 버전의 XXE 취약점 Demo 포함
  • https://www.hackthebox.eu //유럽 HTB 랩, 온라인 실제 환경
  • https://www.root-me.org //러시아 Root-Me 랩. 온라인. 커뮤니티 버전
  • https://lab.pentestit.ru //러시아 랩, 실제 환경. 온라인. 상업용 버전.
  • https://www.offensive-security.com/information-security-certifications/ //kali 공격·방어 기술 인증. 상업용 버전.
  • https://www.pentesteracademy.com //튜토리얼+비디오+랩+인증 교육 원패키지. 상업용 버전.
  • https://www.cybrary.it //사이버 보안 엔지니어 인증. CTF/Labs
  • https://www.wechall.net //세계적으로 유명한 CTF 집계·교류 웹사이트
  • https://www.ichunqiu.com/experiment/direction //i春秋(아이춘추) 연구소. Web/호스트/애플리케이션/pwn 튜토리얼
  • https://www.mozhe.cn/bug //Mozhe Academy(墨者学院) 온라인 랩. Web/호스트/데이터베이스/포렌식
  • https://www.xssgame.com //Google XSS 챌린지
  • http://xss.tv //온라인 랩
  • https://github.com/jonluca/Anubis py3.6, 서브도메인 브루트포스와 정보 수집
  • https://github.com/le4f/dnsmaper 웹 인터페이스, 서브도메인 열거·브루트포스 도구 및 지도 위치 표시
  • https://github.com/thewhiteh4t/seeker 고정밀 지리 정보와 기기 정보를 획득하는 도구
  • https://github.com/0xbug/orangescan 웹 인터페이스, 온라인 서브도메인 정보 수집 도구
  • https://github.com/TheRook/subbrute 스캐너에서 자주 쓰이는 서브도메인 브루트포스 API 라이브러리
  • https://github.com/We5ter/GSDF Google SSL 투명성 인증서 기반 서브도메인 조회 스크립트
  • https://github.com/mandatoryprogrammer/cloudflare_enum CloudFlare의 dns를 이용한 서브도메인 열거
  • https://github.com/ultrasecurity/webkiller 침투 보조, py, ip 정보, 포트 서비스 핑거프린트, 허니팟 탐지, bypass cloudflare
  • https://github.com/christophetd/CloudFlair cloudflare 우회, 실제 ip 획득, censys 통합
  • https://github.com/exp-db/PythonPool/tree/master/Tools/DomainSeeker 다중 방식으로 대상 서브도메인 정보 수집
  • https://github.com/code-scan/BroDomain 서브도메인 조회
  • https://github.com/michenriksen/aquatone 서브도메인 열거·탐지 도구. 서브도메인 탈취 취약점 탐지에 사용 가능
  • https://github.com/chuhades/dnsbrute go 기반, 고효율 서브도메인 브루트포스 도구
  • https://github.com/evilsocket/dnssearch go 기반 서브도메인 브루트포스 도구
  • https://github.com/OJ/gobuster go 기반, dns 조회로 서브도메인과 웹 디렉터리를 브루트포스하는 도구
  • https://github.com/reconned/domained 서브도메인 수집에 사용할 수 있는 도구
  • https://github.com/bit4woo/Teemo 다중 방식 도메인 수집 및 열거 도구
  • https://github.com/swisskyrepo/Subdomino 서브도메인 열거, 포트 스캔, 서비스 활성 여부 확인
  • https://github.com/nmalcolm/Inventus 크롤러로 구현된 서브도메인 수집 도구
  • https://github.com/alienwithin/OWASP-mth3l3m3nt-framework 침투 보조, php, exp 탐색, payload·shell 생성, 정보 수집
  • https://github.com/chrismaddalena/ODIN py3, simple, 정보 수집 및 사후 공격(post-exploitation)
  • https://github.com/x0day/bannerscan C세그먼트/동일 서버 사이트(旁站) 조회 및 경로 스캔
  • https://github.com/Xyntax/BingC Bing 검색 엔진 기반 C세그먼트/동일 서버 사이트 조회, 멀티스레드, API 지원
  • https://github.com/zer0h/httpscan 네트워크 세그먼트 Web 호스트 발견 소형 도구
  • https://github.com/lijiejie/BBScan 웹사이트 정보 유출 배치 스캔 스크립트
  • https://github.com/aipengjie/sensitivefilescan 웹사이트 민감 파일 스캔 도구
  • https://github.com/Mosuan/FileScan 웹사이트 민감 파일 스캔 / 2차 판정으로 오탐률 감소 / 스캔 내용 규격화 / 다중 디렉터리 스캔
  • https://github.com/Xyntax/FileSensor 웹사이트 민감 파일 탐지 도구
  • https://github.com/ring04h/weakfilescan 멀티스레드 웹사이트 정보 유출 감지 도구
  • https://github.com/Viralmaniar/Passhunt simple, 네트워크 장비, 웹 애플리케이션 등의 기본 자격 증명 검색용. 523개 업체의 2084개 기본 비밀번호 포함
  • https://github.com/yassineaboukir/Asnlookup simple, ASN으로 특정 조직이 보유한 ip 검색, nmap·masscan 연동으로 추가 정보 스캔 가능
  • https://github.com/m3liot/shcheck 웹 서비스의 http header 보안성 점검용
  • https://github.com/mozilla/ssh_scan 서버 ssh 구성 정보 스캔
  • https://github.com/18F/domain-scan 도메인 및 서브도메인의 자산 데이터 검사/스캔, http/https 감지 등 포함
  • https://github.com/ggusoft/inforfinder 도메인 자산 수집 및 핑거프린트 식별 도구
  • https://github.com/0xbug/Howl 네트워크 장비 웹 서비스 핑거프린트 스캔 및 검색
  • https://github.com/mozilla/cipherscan 대상 호스트 서비스 ssl 유형 식별
  • https://github.com/medbenali/CyberScan 침투 테스트 보조 도구, 패킷 분석, 디코딩, 포트 스캔, IP 주소 분석 등 지원
  • https://github.com/jekyc/wig 웹 애플리케이션 정보 수집 도구
  • https://github.com/eldraco/domain_analyzer 웹 서비스 도메인을 중심으로 정보 수집과 "도메인 전송(域传送)" 등 취약점 스캔, 백엔드 서버 포트 스캔 등도 지원
  • https://github.com/cloudtracer/paskto Nikto 스캔 규칙 기반 패시브 경로 스캔 및 정보 크롤러
  • https://github.com/zerokeeper/WebEye WEB 서버 유형, CMS 유형, WAF 유형, WHOIS 정보 및 언어 프레임워크를 빠르게 식별
  • https://github.com/n4xh4ck5/CMSsc4n CMS 핑거프린트 식별
  • https://github.com/HA71/WhatCMS CMS 탐지 및 취약점 공격 스크립트, Whatcms.org API 기반
  • https://github.com/boy-hack/gwhatweb CMS 식별, python gevent 구현
  • https://github.com/wpscanteam/wpscan 사실상 word press에서 가장 쓸 만한 도구
  • https://github.com/swisskyrepo/Wordpresscan WPScan 및 WPSeku 기반 최적화된 wordpress 스캐너
  • https://github.com/m4ll0k/WPSeku 간결한 wordpress 스캔 도구
  • https://github.com/rastating/wordpress-exploit-framework wordpress 취약점 공격 프레임워크
  • https://github.com/Jamalc0m/wphunter php, wordpress 스캐너
  • https://github.com/UltimateLabs/Zoom wordpress 취약점 스캐너
  • https://github.com/immunIT/drupwn Drupal 정보 수집 및 취약점 공격 도구
  • https://github.com/CHYbeta/cmsPoc CMS 침투 테스트 프레임워크
  • https://github.com/chuhades/CMS-Exploit-Framework CMS 공격 프레임워크
  • https://github.com/Tuhinshubhra/CMSeeK 20여 종 CMS 기본 탐지, wp 공격에 특화, 맞춤형 모듈식 브루트포스 기능
  • https://github.com/Dionach/CMSmap WordPress, Joomla, Drupal 스캔 지원
  • https://github.com/Moham3dRiahi/XAttacker Web CMS Exploit 도구, 주요 CMS 대상 66개의 서로 다른 Exploit 포함
  • https://github.com/code-scan/dzscan 최초의 통합형 Discuz 스캔 도구
  • https://github.com/bsmali4/xssfork kali에서 사용할 수 없다면 올바른 PhantomJS를 디렉터리 thirdparty/phantomjs/Linux에 다운로드하세요
  • https://github.com/riusksk/FlashScanner flash xss 스캔
  • https://github.com/Damian89/xssfinder 웹사이트 내 반사형 XSS 탐지에 특화
  • https://github.com/BlackHole1/WebRtcXSS XSS를 자동으로 악용해 내부 네트워크 침투
  • https://github.com/Turr0n/firebase 올바르게 구성되지 않은 firebase 데이터베이스 공격
  • https://github.com/tijme/angularjs-csti-scanner 클라이언트 측 AngularJS 템플릿 주입 취약점 탐지 도구
  • https://github.com/blackye/Jenkins Jenkins 취약점 탐지, 사용자 수집 및 무차별 대입
  • https://github.com/epinna/tplmap 서버 측 템플릿 주입 취약점 탐지 및 활용 도구
  • https://github.com/irsdl/IIS-ShortName-Scanner Java, IIS 짧은 파일명 무차별 열거 취약점 활용 도구
  • https://github.com/lijiejie/IIS_shortname_Scanner py2, IIS 짧은 파일명 취약점 스캔
  • https://github.com/rudSarkar/crlf-injector CRLF 주입 취약점 대량 스캔
  • https://github.com/hahwul/a2sv SSL 취약점 스캔, 예: Heartbleed(하트블리드) 취약점 등
  • https://github.com/jagracey/Regex-DoS RegEx DoS(서비스 거부) 스캐너
  • https://github.com/Bo0oM/PHP_imap_open_exploit imap_open을 이용해 php exec 함수 비활성화 우회
  • https://www.anquanke.com/post/id/106488 mysql 서버 측 악성 구성을 이용해 클라이언트 파일 읽기, (MySQL LOCAL INFILE로 클라이언트 파일을 읽는 방법, Read MySQL Client's File, 【기술 공유】MySQL에서 시작하는 반격의 길)
  • https://www.waitalone.cn/awvs-poc.html CVE-2015-4027, AWVS10 명령 실행 취약점
  • http://an7isec.blogspot.com/2014/04/pown-noobs-acunetix-0day.html Pwn the n00bs - Acunetix 0day, awvs8 명령 실행 취약점
  • https://github.com/numpy/numpy/issues/12759 과학 계산 프레임워크 numpy 명령 실행 RCE 취약점
  • https://github.com/petercunha/Jenkins-PreAuth-RCE-PoC jenkins 원격 명령 실행
  • https://github.com/WyAtu/CVE-2018-20250 WinRar 실행 취약점 및 사용법 소개
  • https://github.com/samratashok/nishang PowerShell 스크립트 모음 및 익스플로잇 프레임워크

  • https://github.com/PowerShellEmpire/PowerTools PowerShell 스크립트 모음, 업데이트 중단

  • https://github.com/FuzzySecurity/PowerShell-Suite PowerShell 스크립트 모음

  • https://github.com/rvrsh3ll/Misc-Powershell-Scripts PowerShell 스크립트 모음

  • https://github.com/nccgroup/redsnarf 해시 탈취, 비밀번호 복호화, 몰래 mimikatz 등 프로그램 호출, RDP 다중 방법 활용, 원격 셸 실행, 흔적 정리

  • https://github.com/BloodHoundAD/BloodHound 도메인 구성원과 사용자 관계를 분석하는 프로그램. PowerShell 스크립트로 도메인 내 session, computer, group, user 등의 정보를 내보낸 후 DB에 저장하고 시각화 분석을 통해 표적 공격 가능

  • https://github.com/xorrior/RemoteRecon DotNetToJScript를 활용한 스크린샷, 키로깅, 토큰 탈취, DLL 및 악성 코드 주입

  • https://github.com/SkyLined/LocalNetworkScanner 브라우저 취약점을 활용하여 상대방이 URL을 열면 상대방의 내부 네트워크 정보 스캔

  • https://github.com/fdiskyou/hunter Windows API를 호출하여 내부 네트워크 정보를 매우 포괄적으로 수집

  • https://github.com/0xwindows/VulScritp 내부 네트워크 침투 스크립트, 배너 스캔, 포트 스캔, phpmyadmin, jenkins 등 일반적인 취약점 익스플로잇 포함

  • https://github.com/lcatro/network_backdoor_scanner 네트워크 트래픽 기반 내부 네트워크 탐지 프레임워크

  • https://github.com/sowish/LNScan 상세한 내부 네트워크 정보 스캐너

  • https://github.com/rootlabs/nWatch nmap과 연동하여 조직 내부 네트워크 스캔

  • https://github.com/m8r0wn/nullinux Linux용 내부 침투 테스트 도구, SMB를 통해 운영체제 정보, 도메인 정보, 공유, 디렉터리 및 사용자 열거에 사용 가능

  • https://github.com/zMarch/Orc bash, Linux 포스트 익스플로잇 명령 모음

  • https://github.com/its-a-feature/Apfell py3, macOS 및 Linux에서 JS 백도어 활용, 웹 인터페이스 관리
  • https://github.com/peterpt/fuzzbunch py2, NSA 취약점 익스플로잇 도구, 자동 설치 스크립트와 GUI 인터페이스 제공, 원격 제어 RAT
  • https://github.com/n1nj4sec/pupy py, Windows, Linux, OSX, Android 크로스 플랫폼, 일대다
  • https://github.com/nathanlopez/Stitch py, Windows, Mac OSX, Linux 크로스 플랫폼
  • https://github.com/neoneggplant/EggShell py, macOS/OSX 원격 제어, HID 코드 생성 가능, 일대다
  • https://github.com/Marten4n6/EvilOSX py, macOS/OSX 원격 제어, 일대다
  • https://github.com/vesche/basicRAT py3, 심플한 원격 제어, 일대다
  • https://github.com/Viralmaniar/Powershell-RAT py, 스크린샷을 Gmail로 전송
  • https://github.com/byt3bl33d3r/gcat py, Gmail을 C&C 서버로 사용
  • https://github.com/sweetsoftware/Ares py, C2 통신, 프록시 지원
  • https://github.com/micle-fm/Parat py, Telegram 활용, Windows용 원격 제어 도구
  • https://github.com/ahhh/Reverse_DNS_Shell py, DNS를 통한 전송
  • https://github.com/iagox86/dnscat2 서버는 ruby(Linux), 클라이언트는 C(win/Linux), DNS 프로토콜을 이용한 종단 간 전송
  • https://github.com/deepzec/Grok-backdoor py, ngrok을 활용한 백도어
  • https://github.com/trustedsec/trevorc2 py, 합법적인(탐색 가능한) 웹사이트를 구축하여 명령 실행을 위한 클라이언트/서버 통신을 숨기는 데 사용
  • https://guif.re/linuxeop Linux 권한 상승 명령 모음

  • https://github.com/alpha1ab/CVE-2018-8120 win7과 win2k8을 기반으로 winXP와 win2k3 지원 추가
  • https://github.com/0xbadjuju/Tokenvator Windows 토큰을 사용하여 권한을 상승시키는 도구, 대화형 명령줄 인터페이스 제공
  • https://github.com/Cn33liz/StarFighters DotNetToJScript 기반, JavaScript와 VBScript를 이용한 Empire Launcher 실행
  • https://github.com/mdsecactivebreach/SharpShooter DotNetToJScript 기반으로 js, vbs를 사용하여 임의의 CSharp 소스 코드를 검색·실행하는 payload 생성 프레임워크
  • https://github.com/mdsecactivebreach/CACTUSTORCH DotNetToJScript 기반으로 js, vbs를 사용하여 악성 payload 생성
  • https://github.com/OmerYa/Invisi-Shell PowerShell 파일 난독화
  • https://github.com/danielbohannon/Invoke-DOSfuscation PowerShell 파일 난독화, 암호화 작업 및 재인코딩
  • https://github.com/danielbohannon/Invoke-Obfuscation PowerShell 파일 난독화, 암호화 작업 및 재인코딩
  • https://github.com/Mr-Un1k0d3r/SCT-obfuscator Cobalt Strike SCT payload 난독화기
  • https://github.com/tokyoneon/Armor bash, 암호화된 Payload를 생성하여 macOS에서 리버스 셸 실행
  • https://github.com/Mr-Un1k0d3r/MaliciousMacroGenerator 매크로 난독화, AV/샌드박스 회피 메커니즘 포함
  • https://github.com/Kkevsterrr/backdoorme py3, py2, 다양한 유형의 백도어/셸 생성 도구, 권한을 자동으로 유지할 수 있음
  • https://github.com/TestingPens/MalwarePersistenceScripts Windows 권한 유지 스크립트
  • https://github.com/mhaskar/Linux-Root-Kit py, simple, Linux용 rootkit
  • https://github.com/PinkP4nther/Sutekh simple, rootkit, 일반 사용자가 root 셸을 획득하게 함
  • https://github.com/threatexpress/metatwin 한 파일에서 디지털 서명을 포함한 메타데이터를 추출하여 다른 파일에 주입
  • https://github.com/Mr-Un1k0d3r/Windows-SignedBinary 바이너리 파일의 HASH를 수정하면서 Microsoft Windows의 서명을 유지할 수 있음
  • https://github.com/secretsquirrel/SigThief py, 합법적인 디지털 서명을 하이재킹하고 Windows의 해시 검증 메커니즘을 우회하는 스크립트 도구
  • https://github.com/9aylas/Shortcut-Payload-Generator 바로가기(.lnk) 파일 Payload 생성기. AutoIt 작성
  • https://github.com/GuestGuri/Rootkit TCP 연결을 리버스하고 프로세스 ID를 빈 폴더에 바인딩
  • https://github.com/secretsquirrel/the-backdoor-factory win32 PE 백도어 테스트 프로그램, ELF 파일 백도어 프로그램 등을 생성할 수 있음
  • https://github.com/haccer/tweep Twitter API를 사용한 정보 크롤링 및 조회
  • https://github.com/MazenElzanaty/TwLocation py, Twitter 사용자가 트윗을 올린 위치 획득
  • https://github.com/vaguileradiaz/tinfoleak web 인터페이스, 특정인의 Twitter에 대한 포괄적인 인텔리전스 분석
  • https://github.com/deepfakes 가짜(deepfake) 오디오·비디오 제작
  • https://www.jianshu.com/p/147cf5414851 흔한 탐정류 앱에 대해 이야기
  • https://github.com/thinkst/canarytokens 중요 파일의 추적·출처 확인, 비콘 위치 파악(https://canarytokens.org/generate#)
  • https://github.com/ggerganov/kbd-audio c++, linux, 마이크를 이용한 키보드 입력 모니터링, 입력 값 테스트
  • https://github.com/n0pe-sled/Postfix-Server-Setup 피싱 서버 자동 구축
  • https://github.com/Dionach/PhEmail py2, 피싱 및 이메일 위조
  • https://github.com/PHPMailer/PHPMailer 세계에서 가장 널리 사용되는 PHP 이메일 발송 코드
  • http://tool.chacuo.net/mailanonymous 온라인 이메일 위조
  • http://ns4gov.000webhostapp.com 온라인 이메일 위조
  • https://github.com/yassineaboukir/CVE-2018-0296 Cisco ASA 경로 탐색(path traversal) 취약점 테스트, 시스템 상세 정보 획득 가능
  • https://github.com/seclab-ucr/tcp_exploit TCP 취약점을 이용해 무선 라우터의 개인정보 유출 유발
  • https://github.com/ezelf/CVE-2018-9995_dvr_credentials CVE-2018-9995 카메라·라우터, DVR 자격 증명(Credentials) 획득
  • https://github.com/RUB-NDS/PRET 프린터 공격 프레임워크
  • https://github.com/rapid7/IoTSeeker IoT 장치 기본 비밀번호 스캔·탐지 도구
  • https://github.com/schutzwerk/CANalyzat0r 자동차 전용 프로토콜 보안 분석 도구 키트
  • https://github.com/pasta-auto 스마트카 테스트
  • https://github.com/Hell0W0rld0/Github-Hunter GitHub 정보 모니터링 스크립트
  • https://github.com/awslabs/git-secrets 민감한 데이터가 git 저장소에 커밋되는 것을 방지하는 도구
  • https://github.com/zricethezav/gitleaks go 기반, git repo 내 비밀번호 정보 및 키 검사
  • http://qpdf.sourceforge.net/ PDF 파일을 확인하고 정보를 정리·추출
  • http://zipinfo.com/ 압축 해제 없이 zip 파일의 콘텐츠 정보를 나열
  • http://f00l.de/pcapfix/ pcap 파일 복구
  • https://www.cgsecurity.org/wiki/TestDisk 디스크 파티션 복구
  • https://github.com/decalage2/oletools py, MS OLE2 파일(구조화 저장소, 복합 파일 바이너리 형식) 및 MS Office 문서 분석용
  • https://www.xplico.org/download 메모리 포렌식
  • https://github.com/google/bochspwn-reloaded Bochspwn Reloaded(커널 정보 유출 탐지) 도구
  • https://github.com/abrignoni/DFIR-SQL-Query-Repo 데이터 포렌식에 사용되는 SQL 쿼리 템플릿 모음
  • https://www.freebuf.com/news/193684.html iOS 포렌식 팁: 무손실 방식으로 SQLite 데이터베이스 전체 내보내기
  • https://github.com/viper-framework py2, 바이너리 분석·관리 프레임워크, 악성 파일 분석
  • https://github.com/netxfly/sec_check 정보 수집(계정, 연결, 포트 등) 및 yara 스캔을 통한 보안 탐지
  • https://github.com/nao-sec/tknk_scanner yara 엔진 기반 악성코드 식별 프레임워크
  • https://github.com/felixweyne/ProcessSpawnControl powershell, 악성 프로그램 탐지 및 모니터링
  • https://github.com/Aurore54F/JaSt 구문 분석을 통해 악성/난독화된 JS 파일 탐지, https://www.blackhoodie.re/assets/archive/JaSt_blackhoodie.pdf
  • http://edr.sangfor.com.cn/ win, Linux용 악성코드·webshell 탐지 및 치료 도구
  • http://www.clamav.net/downloads 바이러스 탐지·치료 소프트웨어
  • http://www.chkrootkit.org/ rootkit 탐지 도구
  • http://rootkit.nl/projects/rootkit_hunter.html rootkit 탐지 도구
  • https://github.com/ywolf/F-NAScan py2.6, 네트워크 자산·포트 서비스 수집 정리, 보고서 생성 표시. 빠름
  • https://github.com/flipkart-incubator/RTA 회사 내부의 모든 온라인 장치를 스캔하여 전체 보안 뷰를 제공하고 모든 보안 이상 징후를 표시합니다.
  • https://github.com/0xbug/Biu-framework 기업 내부 네트워크 기반 서비스 보안 스캔 프레임워크
  • http://www.link114.cn/title/ 웹사이트 제목 일괄 조회
  • https://www.whatweb.net/ 온라인 웹 핑거프린트 식별
  • https://hackertarget.com/ip-tools/ api 제공, ip 관련 도구, 온라인 스캐너
  • http://www.webscan.cc/ 동일 IP 웹사이트 조회, C 대역 조회, IP 역조회 도메인, C 대역 旁注(같은 서버 사이트 조회), 旁注 도구
  • https://www.phpinfo.me/bing.php 온라인 旁站(같은 서버 사이트) 조회|C 대역 조회|Bing 인터페이스 C 대역 조회
  • https://www.phpinfo.me/domain/ 온라인 서브도메인 브루트포스
  • https://www.dnsdb.io DNS 조회, 서브도메인 조회, IP 조회, A 레코드 조회, 도메인 해석, 旁站(같은 서버 사이트) 조회
  • https://dnsdumpster.com/ dns recon and research, find and lookup dns records
  • http://ip.chaxun.la/ ip 역조회 도메인---查询啦
  • https://habo.qq.com 온라인 악성 파일 탐지
  • https://www.virustotal.com 악성 소프트웨어 탐지
  • http://r.virscan.org/ 악성 소프트웨어 탐지
  • https://www.appscan.io 모바일 앱 온라인 탐지
  • https://www.nomoreransom.org 일반적인 랜섬웨어 분석·복구
  • https://www.cmd5.com/ HASH 비밀번호 온라인 크래킹
  • https://www.onlinehashcrack.com 비밀번호 해시 온라인 크래킹, 이메일 알림