Skip to content
KitploitKITPLOIT
도구익스플로잇블로그
Log in
제출
도구익스플로잇블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

··피드·문의·개인정보·© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
collection-document — 품질 안전 기사 모음. 훌륭한 기사들. | Kitploit
도구/GitHubGitHub/tom0li/collection-document
OSINT (Open Source Intelligence)Vulnerability AnalysisWeb SecurityFuzzingMalware AnalysisPenetration TestingCloud SecurityDevSecOpsMobile SecurityThreat IntelligenceLearning & EducationCurated Resources
2.1k507645년 전Kitploit 검토 완료

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유
GitHubtom0li/collection-document

collection-document

품질 안전 기사 모음. 훌륭한 기사들.

저장소 보기웹사이트

프로젝트 설명

양질의 보안 기사 모음(재구축 예정)``` Some are inconvenient to release.
Some forget update,can see me star.
collection-document awesome 以前的链接中大多不是优质的
渗透测试部分不再更新
因精力有限,缓慢更新
Author: [tom0li]
Blog: https://tom0li.github.io

- [프로젝트 설명](#project-description)
  - [Github-list](#github-list)
    - [Awesome-list](#awesome-list)
    - [개발](#개발)
    - [기타](#기타)
  - [보안](#보안)
    - [보안 list](#보안-list)
    - [보안 시장 인사이트](#보안-시장-인사이트)
    - [클라우드 보안](#클라우드-보안)
      - [클라우드 기초 지식](#클라우드-기초-지식)
      - [클라우드 네이티브 보안](#클라우드-네이티브-보안)
      - [클라우드 공격 및 방어](#클라우드-공격-및-방어)
      - [VM](#vm)
        - [vCenter](#vcenter)
        - [SLP](#slp)
    - [AI 보안](#ai-보안)
    - [새로운 보안 솔루션](#새로운-보안-솔루션)
      - [차세대 보안 구축](#차세대-보안-구축)
      - [제로 트러스트](#제로-트러스트)
      - [DevSecOps](#devsecops)
    - [위협 탐지](#위협-탐지)
      - [RASP](#rasp)
      - [HIDS](#hids)
      - [WAF](#waf)
        - [WAF 구축 가이드](#waf-구축-가이드)
        - [BypassWAF](#bypasswaf)
      - [Webshell 탐지](#webshell-탐지)
      - [리버스 쉘 탐지](#리버스-쉘-탐지)
      - [EDR](#edr)
      - [AV](#av)
      - [수평 이동 탐지 - 허니팟 접근법](#수평-이동-탐지---허니팟-접근법)
      - [악성 트래픽 탐지](#악성-트래픽-탐지)
      - [IDS](#ids)
      - [텍스트 탐지](#텍스트-탐지)
    - [보안 운영](#보안-운영)
    - [데이터 보안](#데이터-보안)
      - [네트워크 매핑](#네트워크-매핑)
    - [통신 보안](#통신-보안)
      - [종단 간 통신(초판)](#종단-간-통신초판)
      - [SNI](#sni)
    - [개인 보안](#개인-보안)
    - [APT 연구](#apt-연구)
      - [고급 위협-list](#고급-위협-list)
      - [위협 인텔리전스](#위협-인텔리전스)
      - [피싱](#피싱)
      - [C2-RAT](#c2-rat)
  - [경고 및 연구](#경고-및-연구)
    - [ImageMagick](#imagemagick)
    - [Exchange](#exchange)
    - [Privilege-Escalation](#privilege-escalation)
    - [VPN](#vpn)
      - [Sangfor](#sangfor)
      - [Pulse](#pulse)
      - [Palo](#palo)
      - [Fortigate](#fortigate)
      - [Citrix Gateway/ADC](#citrix-gatewayadc)
    - [Tomcat](#tomcat)
    - [FUZZING](#fuzzing)
  - [코드 감사-JAVA](#코드-감사-java)
    - [역직렬화-기타](#역직렬화-기타)
    - [RMI](#rmi)
    - [Shiro](#shiro)
    - [Fastjson](#fastjson)
    - [Dubbo](#dubbo)
    - [CAS](#cas)
    - [Solr 템플릿 인젝션](#solr-템플릿-인젝션)
    - [Apache Skywalking](#apache-skywalking)
    - [Spring](#spring)
      - [Spring-boot](#spring-boot)
      - [Spring-cloud](#spring-cloud)
      - [Spring-data](#spring-data)
  - [블록체인](#블록체인)
  - [침투](#침투)
    - [경계 침투](#경계-침투)
      - [침투 기록 및 요약](#침투-기록-및-요약)
      - [정보 수집](#정보-수집)
      - [연습장](#연습장)
      - [침투 기술](#침투-기술)
    - [내부 네트워크 침투](#내부-네트워크-침투)
      - [Exchange 활용(구)](#exchange-활용구)
      - [hash ticket Credential](#hash-ticket-credential)
      - [프록시 전달 및 포트 재사용](#프록시-전달-및-포트-재사용)
      - [내부 네트워크 플랫폼](#내부-네트워크-플랫폼)
      - [내부 네트워크 기술](#내부-네트워크-기술)
      - [권한 상승 활용](#권한-상승-활용)
  - [Bug_Bounty](#bug_bounty)
  - [Web](#web)
    - [XXE](#xxe)
    - [XSS](#xss)
    - [Jsonp](#jsonp)
    - [CORS](#cors)
    - [CSRF](#csrf)
    - [SSRF](#ssrf)
    - [SQL](#sql)
    - [파일 포함](#파일-포함)
    - [업로드](#업로드)
    - [임의 파일 읽기](#임의-파일-읽기)
    - [웹 캐시 사기](#웹-캐시-사기)
    - [웹 캐시 중독](#웹-캐시-중독)
    - [SSI](#ssi)
    - [SSTI](#ssti)
    - [JS](#js)
    - [DNS](#dns)
  - [기타](#기타)
      - [Git](#git)
      - [QR 코드](#qr-코드)
      - [크롤러](#크롤러)
      - [효율](#효율)
      - [과학 대중화](#과학-대중화)
  - [Contribute](#contribute)
  - [Acknowledgments](#acknowledgments)
  - [Star](#star)

## Github-list
### Awesome-list

* [awesome-web-security](https://github.com/qazbnm456/awesome-web-security) 
* [Awesome-Hacking](https://github.com/Hack-with-Github/Awesome-Hacking) - 만성 list 
* [awesome-malware-analysis](https://github.com/rshipp/awesome-malware-analysis)
* [Android Security](https://github.com/ashishb/android-security-awesome) - Android 보안 관련 리소스 모음.
* [Security](https://github.com/sbilly/awesome-security) - 소프트웨어, 라이브러리, 문서 및 기타 리소스.
* [An Information Security Reference That Doesn't Suck](https://github.com/rmusser01/Infosec_Reference)
* [Security Talks](https://github.com/PaulSec/awesome-sec-talks) - 엄선된 보안 컨퍼런스 목록.
* [OSINT](https://github.com/jivoi/awesome-osint) - 훌륭한 리소스를 포함하는 OSINT 목록.
* [The toolbox of open source scanners](https://github.com/We5ter/Scanners-Box) - 오픈 소스 스캐너 도구 상자
* [blackhat-arsenal-tools](https://github.com/toolswatch/blackhat-arsenal-tools) - 공식 Black Hat Arsenal 보안 도구 리포지토리
* [awesome-iot-hacks](https://github.com/nebgnahz/awesome-iot-hacks)
* [awesome-awesome](https://github.com/emijrp/awesome-awesome)
* [Curated list of awesome lists](https://github.com/sindresorhus/awesome)
* [Awesome Awesomness](https://github.com/bayandin/awesome-awesomeness) - 목록의 목록.
* [PENTESTING-BIBLE](https://github.com/blaCCkHatHacEEkr/PENTESTING-BIBLE) - 보안 관련 콘텐츠
* [Web-Security-Learning](https://github.com/CHYbeta/Web-Security-Learning) - by CHYbeta
* [Software-Security-Learning](https://github.com/CHYbeta/Software-Security-Learning) - by CHYbeta
* [MiscSecNotes](https://github.com/JnuSimba/MiscSecNotes) - by JnuSimba notes 
* [AndroidSecNotes](https://github.com/JnuSimba/AndroidSecNotes) - notes
* [LinuxSecNotes](https://github.com/JnuSimba/LinuxSecNotes) - notes
* [resource collection of python security and code review](https://github.com/bit4woo/python_sec)
* [Pentest_Interview](https://github.com/Leezj9671/Pentest_Interview)
* [tanjiti 정보 소스](https://github.com/tanjiti/sec_profile) - by 바이두 tanjiti 매일 크롤링하는 보안 정보 소스
* [CVE-Flow](https://github.com/404notf0und/CVE-Flow) - by 404notfound CVE 증분 업데이트 모니터링, 딥러닝 기반 CVE EXP 예측 및 자동 푸시
* [security_w1k1](https://github.com/euphrat1ca/security_w1k1/) euphrat1ca 님이 항상 업데이트하는 보안 관련 리포지토리

### 개발

* [인터넷 Java 엔지니어 고급 지식 완전 정복](https://github.com/doocs/advanced-java)
* [Java 학습+면접 가이드: 대부분의 Java 프로그래머가 알아야 할 핵심 지식을 포괄하는 가이드](https://github.com/Snailclimb/JavaGuide)
* [Python Cheat Sheet ](https://github.com/crazyguitar/pysheeet)
* [A collection of full-stack resources for programmers.](https://github.com/charlax/professional-programming)
* [web, 프론트엔드, javascript, nodejs, electron, babel, webpack, rollup, react, vue ...](https://github.com/senntyou/blogs)
* [Python 면접 문제](https://github.com/taizilongxu/interview_python)
* [Python-100-Days](https://github.com/jackfrued/Python-100-Days)
* [python3-source-code-analysis](https://github.com/flaggo/python3-source-code-analysis)
* [Coding Interview University](https://github.com/jwasham/coding-interview-university)
* [tech-interview-handbook](https://github.com/yangshun/tech-interview-handbook) - good
* [면접 필수 기초 지식](https://github.com/CyC2018/CS-Notes)
* [컴퓨터 과학 기초](https://github.com/selfboot/CS_Offer/)
* [알고리즘/딥러닝/NLP 면접 노트](https://github.com/imhuay/Algorithm_Interview_Notes-Chinese)
* [알고리즘 수기](https://github.com/labuladong/fucking-algorithm)
* [데이터 구조 및 알고리즘 필수 50개 코드 구현](https://github.com/wangzheng0822/algo)
* [interview_internal_reference](https://github.com/0voice/interview_internal_reference) 
* [reverse-interview](https://github.com/yifeikong/reverse-interview-zh) - 기술 면접 마지막에 면접관에게 역으로 묻는 질문

### 기타
도구 다운로드