
품질 안전 기사 모음. 훌륭한 기사들.
양질의 보안 기사 모음(재구축 예정)```
Some are inconvenient to release.
Some forget update,can see me star.
collection-document awesome
以前的链接中大多不是优质的
渗透测试部分不再更新
因精力有限,缓慢更新
Author: [tom0li]
Blog: https://tom0li.github.io
- [프로젝트 설명](#project-description)
- [Github-list](#github-list)
- [Awesome-list](#awesome-list)
- [개발](#개발)
- [기타](#기타)
- [보안](#보안)
- [보안 list](#보안-list)
- [보안 시장 인사이트](#보안-시장-인사이트)
- [클라우드 보안](#클라우드-보안)
- [클라우드 기초 지식](#클라우드-기초-지식)
- [클라우드 네이티브 보안](#클라우드-네이티브-보안)
- [클라우드 공격 및 방어](#클라우드-공격-및-방어)
- [VM](#vm)
- [vCenter](#vcenter)
- [SLP](#slp)
- [AI 보안](#ai-보안)
- [새로운 보안 솔루션](#새로운-보안-솔루션)
- [차세대 보안 구축](#차세대-보안-구축)
- [제로 트러스트](#제로-트러스트)
- [DevSecOps](#devsecops)
- [위협 탐지](#위협-탐지)
- [RASP](#rasp)
- [HIDS](#hids)
- [WAF](#waf)
- [WAF 구축 가이드](#waf-구축-가이드)
- [BypassWAF](#bypasswaf)
- [Webshell 탐지](#webshell-탐지)
- [리버스 쉘 탐지](#리버스-쉘-탐지)
- [EDR](#edr)
- [AV](#av)
- [수평 이동 탐지 - 허니팟 접근법](#수평-이동-탐지---허니팟-접근법)
- [악성 트래픽 탐지](#악성-트래픽-탐지)
- [IDS](#ids)
- [텍스트 탐지](#텍스트-탐지)
- [보안 운영](#보안-운영)
- [데이터 보안](#데이터-보안)
- [네트워크 매핑](#네트워크-매핑)
- [통신 보안](#통신-보안)
- [종단 간 통신(초판)](#종단-간-통신초판)
- [SNI](#sni)
- [개인 보안](#개인-보안)
- [APT 연구](#apt-연구)
- [고급 위협-list](#고급-위협-list)
- [위협 인텔리전스](#위협-인텔리전스)
- [피싱](#피싱)
- [C2-RAT](#c2-rat)
- [경고 및 연구](#경고-및-연구)
- [ImageMagick](#imagemagick)
- [Exchange](#exchange)
- [Privilege-Escalation](#privilege-escalation)
- [VPN](#vpn)
- [Sangfor](#sangfor)
- [Pulse](#pulse)
- [Palo](#palo)
- [Fortigate](#fortigate)
- [Citrix Gateway/ADC](#citrix-gatewayadc)
- [Tomcat](#tomcat)
- [FUZZING](#fuzzing)
- [코드 감사-JAVA](#코드-감사-java)
- [역직렬화-기타](#역직렬화-기타)
- [RMI](#rmi)
- [Shiro](#shiro)
- [Fastjson](#fastjson)
- [Dubbo](#dubbo)
- [CAS](#cas)
- [Solr 템플릿 인젝션](#solr-템플릿-인젝션)
- [Apache Skywalking](#apache-skywalking)
- [Spring](#spring)
- [Spring-boot](#spring-boot)
- [Spring-cloud](#spring-cloud)
- [Spring-data](#spring-data)
- [블록체인](#블록체인)
- [침투](#침투)
- [경계 침투](#경계-침투)
- [침투 기록 및 요약](#침투-기록-및-요약)
- [정보 수집](#정보-수집)
- [연습장](#연습장)
- [침투 기술](#침투-기술)
- [내부 네트워크 침투](#내부-네트워크-침투)
- [Exchange 활용(구)](#exchange-활용구)
- [hash ticket Credential](#hash-ticket-credential)
- [프록시 전달 및 포트 재사용](#프록시-전달-및-포트-재사용)
- [내부 네트워크 플랫폼](#내부-네트워크-플랫폼)
- [내부 네트워크 기술](#내부-네트워크-기술)
- [권한 상승 활용](#권한-상승-활용)
- [Bug_Bounty](#bug_bounty)
- [Web](#web)
- [XXE](#xxe)
- [XSS](#xss)
- [Jsonp](#jsonp)
- [CORS](#cors)
- [CSRF](#csrf)
- [SSRF](#ssrf)
- [SQL](#sql)
- [파일 포함](#파일-포함)
- [업로드](#업로드)
- [임의 파일 읽기](#임의-파일-읽기)
- [웹 캐시 사기](#웹-캐시-사기)
- [웹 캐시 중독](#웹-캐시-중독)
- [SSI](#ssi)
- [SSTI](#ssti)
- [JS](#js)
- [DNS](#dns)
- [기타](#기타)
- [Git](#git)
- [QR 코드](#qr-코드)
- [크롤러](#크롤러)
- [효율](#효율)
- [과학 대중화](#과학-대중화)
- [Contribute](#contribute)
- [Acknowledgments](#acknowledgments)
- [Star](#star)
## Github-list
### Awesome-list
* [awesome-web-security](https://github.com/qazbnm456/awesome-web-security)
* [Awesome-Hacking](https://github.com/Hack-with-Github/Awesome-Hacking) - 만성 list
* [awesome-malware-analysis](https://github.com/rshipp/awesome-malware-analysis)
* [Android Security](https://github.com/ashishb/android-security-awesome) - Android 보안 관련 리소스 모음.
* [Security](https://github.com/sbilly/awesome-security) - 소프트웨어, 라이브러리, 문서 및 기타 리소스.
* [An Information Security Reference That Doesn't Suck](https://github.com/rmusser01/Infosec_Reference)
* [Security Talks](https://github.com/PaulSec/awesome-sec-talks) - 엄선된 보안 컨퍼런스 목록.
* [OSINT](https://github.com/jivoi/awesome-osint) - 훌륭한 리소스를 포함하는 OSINT 목록.
* [The toolbox of open source scanners](https://github.com/We5ter/Scanners-Box) - 오픈 소스 스캐너 도구 상자
* [blackhat-arsenal-tools](https://github.com/toolswatch/blackhat-arsenal-tools) - 공식 Black Hat Arsenal 보안 도구 리포지토리
* [awesome-iot-hacks](https://github.com/nebgnahz/awesome-iot-hacks)
* [awesome-awesome](https://github.com/emijrp/awesome-awesome)
* [Curated list of awesome lists](https://github.com/sindresorhus/awesome)
* [Awesome Awesomness](https://github.com/bayandin/awesome-awesomeness) - 목록의 목록.
* [PENTESTING-BIBLE](https://github.com/blaCCkHatHacEEkr/PENTESTING-BIBLE) - 보안 관련 콘텐츠
* [Web-Security-Learning](https://github.com/CHYbeta/Web-Security-Learning) - by CHYbeta
* [Software-Security-Learning](https://github.com/CHYbeta/Software-Security-Learning) - by CHYbeta
* [MiscSecNotes](https://github.com/JnuSimba/MiscSecNotes) - by JnuSimba notes
* [AndroidSecNotes](https://github.com/JnuSimba/AndroidSecNotes) - notes
* [LinuxSecNotes](https://github.com/JnuSimba/LinuxSecNotes) - notes
* [resource collection of python security and code review](https://github.com/bit4woo/python_sec)
* [Pentest_Interview](https://github.com/Leezj9671/Pentest_Interview)
* [tanjiti 정보 소스](https://github.com/tanjiti/sec_profile) - by 바이두 tanjiti 매일 크롤링하는 보안 정보 소스
* [CVE-Flow](https://github.com/404notf0und/CVE-Flow) - by 404notfound CVE 증분 업데이트 모니터링, 딥러닝 기반 CVE EXP 예측 및 자동 푸시
* [security_w1k1](https://github.com/euphrat1ca/security_w1k1/) euphrat1ca 님이 항상 업데이트하는 보안 관련 리포지토리
### 개발
* [인터넷 Java 엔지니어 고급 지식 완전 정복](https://github.com/doocs/advanced-java)
* [Java 학습+면접 가이드: 대부분의 Java 프로그래머가 알아야 할 핵심 지식을 포괄하는 가이드](https://github.com/Snailclimb/JavaGuide)
* [Python Cheat Sheet ](https://github.com/crazyguitar/pysheeet)
* [A collection of full-stack resources for programmers.](https://github.com/charlax/professional-programming)
* [web, 프론트엔드, javascript, nodejs, electron, babel, webpack, rollup, react, vue ...](https://github.com/senntyou/blogs)
* [Python 면접 문제](https://github.com/taizilongxu/interview_python)
* [Python-100-Days](https://github.com/jackfrued/Python-100-Days)
* [python3-source-code-analysis](https://github.com/flaggo/python3-source-code-analysis)
* [Coding Interview University](https://github.com/jwasham/coding-interview-university)
* [tech-interview-handbook](https://github.com/yangshun/tech-interview-handbook) - good
* [면접 필수 기초 지식](https://github.com/CyC2018/CS-Notes)
* [컴퓨터 과학 기초](https://github.com/selfboot/CS_Offer/)
* [알고리즘/딥러닝/NLP 면접 노트](https://github.com/imhuay/Algorithm_Interview_Notes-Chinese)
* [알고리즘 수기](https://github.com/labuladong/fucking-algorithm)
* [데이터 구조 및 알고리즘 필수 50개 코드 구현](https://github.com/wangzheng0822/algo)
* [interview_internal_reference](https://github.com/0voice/interview_internal_reference)
* [reverse-interview](https://github.com/yifeikong/reverse-interview-zh) - 기술 면접 마지막에 면접관에게 역으로 묻는 질문
### 기타
* [정보보안 종사자 추천 도서](https://github.com/riusksk/secbook)
* [프로그래머를 위한 영어 학습 가이드 v1.2](https://github.com/yujiangshui/A-Programmers-Guide-to-English)
* [중국 프로그래머가 자주 발음 실수하는 단어](https://github.com/shimohq/chinese-programmer-wrong-pronunciation)
* [개발자에게 유용한 법칙, 이론, 원리 및 패턴](https://github.com/nusr/hacker-laws-zh)
* [SecLists](https://github.com/danielmiessler/SecLists) - 보안 평가 중 사용되는 여러 유형의 목록 모음.
* [A collection of web attack payloads](https://github.com/foospidy/payloads) payloads 모음
* [보안 관련 마인드맵 정리 수집](https://github.com/phith0n/Mind-Map) - by p소
* [보안 마인드맵 모음](https://github.com/SecWiki/sec-chart) -by SecWiki
* [Android-Reports-and-Resources](https://github.com/B3nac/Android-Reports-and-Resources) - HackerOne Reports
* [AppSec](https://github.com/paragonie/awesome-appsec) - 애플리케이션 보안 학습을 위한 리소스.
* [Infosec](https://github.com/onlurking/awesome-infosec) - 침투 테스트, 포렌식 등을 위한 정보 보안 리소스.
* [YARA](https://github.com/InQuest/awesome-yara) - YARA 규칙, 도구 및 사람.
* [macOS-Security-and-Privacy-Guide](https://github.com/drduh/macOS-Security-and-Privacy-Guide)
* [awesome-security-weixin-official-accounts](https://github.com/DropsOfZut/awesome-security-weixin-official-accounts)
* [2018-2020 청년 보안계 - 활동적인 기술 블로거/블로그](https://github.com/404notf0und/Security-Data-Analysis-and-Visualization) - by 404notf0und
* [996.Leave](https://github.com/623637646/996.Leave)
* [집 구하기 요점, 베이징 상하이 광저우 선전 항저우에 적용](https://github.com/soulteary/tenant-point)
* [베이징 주택 구매](https://github.com/facert/beijing_house_knowledge)
* [베이징 주택 구매 가이드맵](https://github.com/yangyiRunning/Beijing-House)
* [상하이 주택 구매](https://github.com/ayuer/shanghai_house_knowledge)
* [항저우 주택 구매](https://github.com/houshanren/hangzhou_house_knowledge)
* [awesome-macOS](https://github.com/iCHAIT/awesome-macOS) - mac 소프트웨어
* [awesome-mac](https://github.com/jaywcjlove/awesome-mac/blob/master/README-zh.md#%E5%BC%80%E5%8F%91%E8%80%85%E5%B7%A5%E5%85%B7) - mac 소프트웨어
* [ruanyf](https://github.com/ruanyf/weekly) - 기술 애호가 주간
## 보안
### 보안 list
* [arxiv.org](https://arxiv.org/) 논문 라이브러리
* [404notf0und 학습 기록](https://github.com/404notf0und/Always-Learning#APT%E6%A3%80%E6%B5%8B) 보안 탐지 부분 참고
* [Donot 님이 수집한 침입 탐지 관련 콘텐츠](https://github.com/donot-wong/SecAcademic)
* [Jung Han-Blog](https://www.cnblogs.com/littlehann/) 전체 탐색
* [cdxy-Blog](https://www.cdxy.me/) 너무 멋짐
* [zuozuovera-Blog](https://www.zuozuovera.com/) 손재주가 좋음
* [보안 학계 2018년 연간 요약](https://mp.weixin.qq.com/s/eQ5os0Fdb498BoQLKUDmrA) - 위챗 공식계정 보안 학계
* [security-hardening](https://github.com/decalage2/awesome-security-hardening) 보안 강화 종합
### 보안 시장 인사이트
보안 시장 개요, 트렌드, 패턴 소개. 국내외 보안 사업 회사
* [XDef 보안 정상회의 2021](https://mp.weixin.qq.com/s/RlEu_qVaj1rIhBuf0vQp8g)
### 클라우드 보안
#### 클라우드 기초 지식
* [가상화 소개](https://yuvaly0.github.io/2020/06/19/introduction-to-virtualization.html)
* [kvm](https://github.com/yifengyou/learn-kvm) yifengyou 님 kvm 노트
#### 클라우드 네이티브 보안
* [Google: BeyondProd 모델](https://cloud.google.com/security/beyondprod?hl=zh-cn)
* [메이투안 클라우드 네이티브 컨테이너 보안 실무](https://tech.meituan.com/2020/03/12/cloud-native-security.html)
* [클라우드 네이티브 침입 탐지 트렌드 관찰](https://xz.aliyun.com/t/7841)
* [클라우드 네이티브가 가져온 클라우드 보안 기회](https://www.freebuf.com/articles/network/242950.html) 클라우드 네이티브 보안 시장 개요(비기술)
* [알리바바 클라우드 보안 백서](https://github.com/tom0li/collection-document/blob/master/%E9%98%BF%E9%87%8C%E4%BA%91%E5%AE%89%E5%85%A8%E7%99%BD%E7%9A%AE%E4%B9%A6.pdf)
#### 클라우드 공격 및 방어
* [Awesome-serverless](https://github.com/puresec/awesome-serverless-security/)
* [클라우드 네이티브 침투](https://mp.weixin.qq.com/s/Aq8RrH34PTkmF8lKzdY38g) neargle 님의 클라우드 네이티브 침투 기록, 클라우드 네이티브 침투 시 만날 수 있는 서비스 및 해당 테스트 방법 소개, 현재까지 국내에서 공개된 클라우드 네이티브 개론 침투 설명 중 가장 완전함
* [Red Teaming for Cloud](https://mp.weixin.qq.com/s/lUHd6lmFl3m9BMdSC2wwcw) red team이 무엇인지 명확히 설명, 일부 전형적인 cloud pentest 경로
* [tom0li: docker 이스케이프 요약](https://tom0li.github.io/Docker%E9%80%83%E9%80%B8%E5%B0%8F%E7%BB%93%E7%AC%AC%E4%B8%80%E7%89%88/) 공격 관점에서 docker 이스케이프 3가지 방법 소개, 이스케이프 실제 시나리오 및 엔지니어 공격 방법 소개
* [Kubernetes security](https://github.com/kabachook/k8s-security) 이 저장소는 kubernetes 보안 관련 자료와 연구를 모아놓은 것입니다.
* [serverless functions 공방 초탐](https://www.cdxy.me/?p=836) serverless functions 공격 경로 및 방어 탐지 기법 소개
* [RDS 데이터베이스 공방](https://xz.aliyun.com/t/8451) 정보 유출로 인한 비자식 ACCESSKEY를 통해 외부 네트워크에서 RDS에 연결 가능
* [컨테이너와 클라우드의 충돌 — MinIO 테스트](https://mp.weixin.qq.com/s/X04IhY9Oau-kDOVbok8wEw) 주로 MinIO 객체 스토리지의 SSRF 취약점, POST SSRF 307 우회를 통한 공격 구성
* [Kubernetes에서 Helm2 사용 시 보안 위험](http://rui0.cn/archives/1573) Helm2를 통해 secrets를 획득하는 구체적인 작업 설명
* [K8s 6443 대량 침입 조사](https://www.cdxy.me/?p=833) 인증 설정 부적절, 익명 사용자가 권한 상승된 요청으로 k8s api 호출 가능, pod 생성 docker 요청, docker 내에서 권한 상승된 docker 생성 및 악성 명령 실행, 생성된 pod 삭제
* [K8s 침투 테스트 kube-apiserver 활용](https://www.cdxy.me/?p=839) 고전적인 공격 경로 소개, 획득한 pod에서 높은 권한 service account 찾기
* [K8s 침투 테스트 etcd 활용](https://www.cdxy.me/?p=827) 비인가 etcd와 공격자가 cert 보유 시 침투 명령 소개, service account token 읽기 명령, 클러스터 장악 명령
* [K8s 데이터 보안 Secrets 보호 방안](https://www.cdxy.me/?p=832)
* [Fantastic Conditional Access Policies and how to bypass them](https://dirkjanm.io/assets/raw/fantastic_policies_cloud_roundup.pdf) Dirk-jan 님의 Azure 주제
* [I’m in your cloud: A year of hacking Azure AD](https://dirkjanm.io/assets/raw/Im%20in%20your%20cloud%20bluehat-v1.0.pdf) Dirk-jan 님의 Azure 주제
* [Istio 접근 인가에서 다시 고위험 취약점 CVE-2020-8595 발견](https://mp.weixin.qq.com/s?__biz=MzIyODYzNTU2OA==&mid=2247487481&idx=1&sn=02a38db691331634fe41a413beb58694&chksm=e84fa926df382030ac57be9c1ee9cb8836ec37fc79e3a2cef68acb6945a51f0ed94882e39611) Istio 완전 일치 모드 exact 매칭 부적절로 인한 비인가 접근
#### VM
##### vCenter
* [CVE-2021-21972 vCenter 6.5-7.0 RCE 취약점 분석](http://noahblog.360.cn/vcenter-6-5-7-0-rce-lou-dong-fen-xi/)
* [VMware vCenter RCE 취약점 삽질 기록 - 간단한 RCE 취약점이 무엇을 알려줄 수 있는가](https://mp.weixin.qq.com/s/eamNsLY0uKHXtUw_fiUYxQ) burp에서 데이터 패킷을 수정하여 파일을 업로드할 수 없는 이유 설명
##### SLP
* [CVE-2020-3992 & CVE-2021-21974: Pre-Auth Remote Code Execution in VMware ESXi ](https://www.zerodayinitiative.com/blog/2021/3/1/cve-2020-3992-amp-cve-2021-21974-pre-auth-remote-code-execution-in-vmware-esxi) 두 개의 cve 소개, VM 공식이 openSLP 기반으로 유지보수하는 SLP에 UAF 취약점이 있으며 패치 우회 가능
### AI 보안
* [AI-for-Security-Learning](https://github.com/404notf0und/AI-for-Security-Learning) AI의 힘 - by 404notf0und
* [0xMJ:AI-Security-Learning](https://github.com/0xMJ/AI-Security-Learning#webshell%E6%A3%80%E6%B5%8B)
* [Adversarial ML Threat Matrix](https://github.com/mitre/advmlthreatmatrix) Machine Learning 시스템에 대한 적대적 공격
* [AI 보안 위험 위협 매트릭스](https://ai.tencent.com/ailab/media/AI%E5%AE%89%E5%85%A8%E7%9A%84%E5%A8%81%E8%83%81%E9%A3%8E%E9%99%A9%E7%9F%A9%E9%98%B5.pdf)
* [머신러닝 기반 웹 관리 백엔드 식별 방법 탐구](https://security.tencent.com/index.php/blog/msg/176) 텐센트 내부 트래픽 시스템 백엔드 식별 모듈 설계 개요 소개
### 새로운 보안 솔루션
#### 차세대 보안 구축
* [탄력적 보안 네트워크 - 차세대 보안 인터넷 구축](https://mp.weixin.qq.com/s/epFSC88J7LF3BGwQdoZ-Rg)
#### 제로 트러스트
* [장오: 디지털 은행 신뢰할 수 있는 네트워크 실무](https://mp.weixin.qq.com/s/VRG9LEbGTxhpMmCUTUSA8w) 제로 트러스트 개념
* [제로 트러스트 환경의 프록시 도구](https://github.com/mandatoryprogrammer/CursedChrome/blob/master/README.md) chrome을 프록시로 사용하여 피해자가 접근 가능한 웹 서비스에 접근 가능
#### DevSecOps
* [DevSecOps 개념 및 고찰](https://mp.weixin.qq.com/s/_jBmFdtyXY5D_YrrTUP1iQ) 텐센트 보안 응급 대응 센터
* [Awesome-DevSecOps](https://github.com/devsecops/awesome-devsecops)
### 위협 탐지
* [보안 지능 애플리케이션에 대한 몇 가지 오해](https://zhuanlan.zhihu.com/p/88042567)
#### RASP
* [RASP에 대한 간단한 논의](https://lucifaer.com/2019/09/25/%E6%B5%85%E8%B0%88RASP/)
* [OpenRASP를 기반으로 RASP의 클래스 로딩 이야기](https://xz.aliyun.com/t/8148)
#### HIDS
* [분산 HIDS 클러스터 아키텍처 설계](https://www.cnxct.com/distributed-hids-cluster-architecture-design/) 메이투안 기술 팀
#### WAF
##### WAF 구축 가이드
* [WAF 구축 운영 및 AI 응용 실무](https://mp.weixin.qq.com/s?__biz=MjM5NzE1NjA0MQ==&mid=2651199346&idx=1&sn=99f470d46554149beebb8f89fbcb1578&chksm=bd2cf2d48a5b7bc2b3aecb501855cc2efedc60f6f01026543ac2df5fa138ab2bf424fc5ab2b0&scene=21#wechat_redirect)
##### BypassWAF
* [문신 WAF 공공 테스트 요약](https://mp.weixin.qq.com/s/w5TwFl4Ac1jCTX0A1H_VbQ)
* [개인적으로 정리한 waf 우회 인젝션 방법 (6가지 일반적인 waf 우회 방법 포함)](https://www.t00ls.net/viewthread.php?tid=43687&extra=&page=1)
* [고인물과 함께하는 일반 WAF 우회](https://www.secpulse.com/archives/69983.html)
* [SQL 인젝션 ByPass를 위한 몇 가지 팁](https://mp.weixin.qq.com/s/fSBZPkO0-HNYfLgmYWJKCg)
* [HTTP 프로토콜 레벨에서 WAF 우회](https://www.freebuf.com/news/193659.html)
* [청크 전송을 이용한 모든 WAF 무력화](https://www.anquanke.com/post/id/169738)
* [WAF 우회의 지름길과 방법](https://www.qiaoyue.net/2019/WAF%E7%BB%95%E8%BF%87%E7%9A%84%E6%8D%B7%E5%BE%84%E4%B8%8E%E6%96%B9%E6%B3%95/)
* [WAF 우회에 대한 몇 가지 인식](http://static.anquanke.com/download/b/security-geek-2019-q2/article-18.html)
* [WAF Bypass webshell 업로드 jsp와 tomcat](https://www.anquanke.com/post/id/210630#)
* [다양한 방식의 jsp webshell](https://xz.aliyun.com/t/7798)
#### Webshell 탐지
* [Java web filter 형 메모리 쉘 탐지 및 제거](http://gv7.me/articles/2020/kill-java-web-filter-memshell/)
* [Filter/Servlet 형 메모리 쉘 스캔, 포착 및 제거](https://gv7.me/articles/2020/filter-servlet-type-memshell-scan-capture-and-kill/)
* [Java 메모리 Webshell의 공격과 방어에 대한 잡담](https://mp.weixin.qq.com/s/DRbGeVOcJ8m9xo7Gin45kQ)
* [JSP Webshell 이야기 -- 공격편](https://mp.weixin.qq.com/s/YhiOHWnqXVqvLNH7XSxC9w)
* [Webshell 공격과 방어 PHP](https://github.com/qiyeboy/kill_webshell_detect/blob/master/%E7%9F%A5%E8%AF%86%E6%98%9F%E7%90%83-webshell%E6%94%BB%E4%B8%8E%E9%98%B2.pdf)
* [오염 전파 이론의 Webshell 탐지 응용 - PHP편](https://mp.weixin.qq.com/s/MFmSliCQaaVEQ0E66vN5Xg)
* [새로운 시작: webshell 탐지](https://iami.xyz/New-Begin-For-Nothing/)
* [intercetor를 이용한 spring 메모리 webshell 인젝션](https://github.com/LandGrey/webshell-detect-bypass/blob/master/docs/inject-interceptor-hide-webshell/inject-interceptor-hide-webshell.md) 공격 활용 관점의 글
#### 리버스 쉘 탐지
* [리버스 쉘 원리 및 탐지 기술 연구](https://www.cnblogs.com/LittleHann/p/12038070.html) -by LittleHann
* [리버스 쉘 분석](https://cloud.tencent.com/developer/article/1645464)
* [리버스 쉘 다차원 탐지 기술 상세 설명](https://www.freebuf.com/articles/network/263684.html)
#### EDR
* [Lets-create-an-edr-and-bypass](https://ethicalchaos.dev/2020/06/14/lets-create-an-edr-and-bypass-it-part-2/)
* [openedr](https://github.com/ComodoSecurity/openedr) 오픈소스 제품 edr
#### AV
* [exploiting-almost-every-antivirus-software](https://www.rack911labs.com/research/exploiting-almost-every-antivirus-software/) av 대응, 링크 방식을 이용하여 av의 높은 권한을 빌려 임의 파일 삭제 달성
* [Bypassing Windows Defender Runtime Scanning](https://labs.f-secure.com/blog/bypassing-windows-defender-runtime-scanning/) 어떤 API 호출이 Defender 탐지를 트리거하는지 열거 테스트, CreateProcess 및 CreateRemoteThread 생성 시 Defender 트리거 발견, 세 가지 해결 방법 제시: API 호출 재작성, 명령어 수정/동적 복호화 로딩 추가, Defender가 해당 영역을 스캔하지 않도록 설정. 저자는 Defender 스캔 메커니즘(가상 메모리가 큰 경우 MEM_PRIVATE 또는 RWX 페이지 권한만 스캔)을 분석, 의심스러운 API 호출 시 동적으로 PAGE_NOACCESS 메모리 권한을 설정하면 Defender가 보안 스캔을 수행하지 않음
* [Engineering antivirus evasion](https://blog.scrt.ch/2020/06/19/engineering-antivirus-evasion/)
* [Bypass Windows DefenderAttack Surface Reduction](https://data.hackinn.com/ppt/OffensiveCon2019/Bypass%20Windows%20Exploit%20Guard%20ASR.pdf)
* [Defender 스캔 파일명 문제](http://2016.eicar.org/85-0-Download.html)
* [herpaderping](https://github.com/jxy-s/herpaderping) 새로운 유형의 bypass defender
* [shellcodeLoader 구현](https://paper.seebug.org/1413/) 몇 가지 shellcode 실행 방법, bypass sandbox 방법 소개
* [Malware_development_part](https://0xpat.github.io/Malware_development_part_5/) 악성 소프트웨어 시리즈 튜토리얼
* [백신 탐지 및 Hook 포인트 목록](https://github.com/D3VI5H4/Antivirus-Artifacts/blob/main/ANTIVURUS_ARTIFACTS.pdf)
#### 수평 이동 탐지 - 허니팟 접근법
* [Honeypots](https://github.com/paralax/awesome-honeypots) - Honeypots, 도구, 구성 요소 등.
* [Hunting for Skeleton Key Implants](https://riccardoancarani.github.io/2020-08-08-hunting-for-skeleton-keys/) Skeleton Key 지속성 탐지
* [허니팟 계정 생성으로 Kerberoast 탐지](https://www.pentestpartners.com/security-blog/honeyroasting-how-to-detect-kerberoast-breaches-with-honeypots/)
#### 악성 트래픽 탐지
* [DataCon2020 풀이: 허니팟과 DNS 트래픽을 통한 Botnet 추적](https://www.cdxy.me/?p=829)
* [DNS Tunnel 터널 은닉 통신 실험 && 특성 벡터화 방식 탐지 시도](https://www.cnblogs.com/LittleHann/p/8656621.html#_label0)
* [maltrail](https://github.com/stamparm/maltrail#introduction) 오픈소스 트래픽 탐지 제품
* [cobalt-strike-default-modules-via-named-pipe 탐지](https://labs.f-secure.com/blog/detecting-cobalt-strike-default-modules-via-named-pipe-analysis/) CS가 기본 모듈을 실행한 후 메모리 pipe 탐지
* [DNS 데이터를 이용한 위협 발견](https://mp.weixin.qq.com/s/6CtRd7o4IjreLaU-hFt9vQ) 360DNSMON이 skidmap 백도어를 발견한 과정 및 분석 기법 소개
* [DNSMon: DNS 데이터를 이용한 위협 발견](https://blog.netlab.360.com/use-dns-data-produce-threat-intelligence-2/) DNSMON을 통해 이벤트 모니터링, 연관 분석
* [evading-sysmon-dns-monitoring](https://blog.xpnsec.com/evading-sysmon-dns-monitoring/)
* [use-dns-data-produce-threat-intelligence](https://blog.netlab.360.com/use-dns-data-produce-threat-intelligence/)
#### IDS
* [IDS 시그니처에 대해 이야기해보자](https://www.anquanke.com/post/id/102948#h2-0)
* [순서대로 오지 않는 TCP 패킷](https://strcpy.me/index.php/archives/789/)
* [네트워크 계층에서 IDS/IPS 우회에 대한 몇 가지 탐구](https://paper.seebug.org/1173/)
#### 텍스트 탐지
* [머신러닝의 바이너리 코드 유사성 분석 응용](https://mp.weixin.qq.com/s?__biz=MjM5NTc2MDYxMw==&mid=2458303210&idx=1&sn=345f8cec156ada8fa9bf6a6d6de83906&chksm=b1818a6086f60376e766baf472171d8e2c780b2913568b46b683e3112fcc5f86c9bf4c19e38b&mpshare=1&scene=1&srcid=&sharer_sharetime=1580984631757&sharer_shareid=5dc01f49f38fd64ff3e64844bc7d2ea7&exportkey=A0qHBeUryuXO6zhGWt5OJNw%3D&pass_ticket=gjTFXl4hPMTBWzlKpWZWqK8HivXQ8q7ChNndmw4I8JrdAK0jWWFvKIq7OMnO3BhL#rd)
### 보안 운영
* [보안 업무의 좋고 나쁨을 어떻게 평가할 것인가](https://zhuanlan.zhihu.com/p/226493047) 텐센트 '직업欠钱'의 상향 관리에 대한 공유
### 데이터 보안
* [인터넷 기업 데이터 보안 시스템 구축](https://tech.meituan.com/2018/05/24/data-security-system-construction.html)
* [데이터 보안에 대한 얕은 이야기](https://iami.xyz/Talk-about-data-security/)
#### 네트워크 매핑
* [네트워크 공간 매핑의 종횡에 대해 간단히 이야기](https://www.anquanke.com/post/id/226007)
* [네트워크 공간 매핑 기술을 더 이상 흔들리지 않게](https://mp.weixin.qq.com/s/lr39F9kNOfHlMimgymzVwg) by 조무 네트워크 매핑 관심 포인트
* [네트워크 공간 매핑/검색 엔진 관련 자료 기록](https://github.com/EXHades/CyberSpaceSearchEngine-Research)
### 통신 보안
#### 종단 간 통신(초판)
* [역대 가장 완벽한 zoom 취약점 및 수정 방안 소개](https://mp.weixin.qq.com/s/a7mN0lTeXxA3YmZZxIGNRg)
* [안전한 인스턴트 메신저의 트래픽 분석 공격](https://www.anquanke.com/post/id/208678#)
* [Shadowsocks의 이중 난독화 암호화 전송 기반 데이터 기밀성 원리 분석](https://www.secrss.com/articles/18469)
#### SNI
* [ESNI](https://www.cloudflare.com/zh-cn/learning/ssl/what-is-encrypted-sni/) what-is-encrypted-sni
* [encrypted-client-hello-the-future-of-esni-in-firefox](https://blog.mozilla.org/security/2021/01/07/encrypted-client-hello-the-future-of-esni-in-firefox/)
* [encrypted-client-hello](https://blog.cloudflare.com/encrypted-client-hello/)
### 개인 보안* [Tor-0day-Finding-IP-Addresses](https://www.hackerfactor.com/blog/index.php?/archives/896-Tor-0day-Finding-IP-Addresses.html)
* [lcamtuf: 재난 계획](https://lcamtuf.coredump.cx/prep/)
* [tom0li: 개인정보 보호](https://tom0li.github.io/%E4%B8%AA%E4%BA%BA%E9%9A%90%E7%A7%81%E4%BF%9D%E6%8A%A4/) 일반인을 위한 개인정보 보호 방법
* [개인정보 보호](https://github.com/No-Github/Digital-Privacy) 디지털 프라이버시 수집 방법 목록
* [Supercookie 브라우저 접속 지문 인식](https://supercookie.me/workwise) Supercookie uses favicons to assign a unique identifier to website visitors. 여러 방문 URL을 사용하여 사용자를 구분
### APT 연구
앞서 나열한 대부분은 공격 내용으로, APT 추적 보고서 등이 포함됩니다.
#### 고급 위협 목록
* [Red-Team-Infrastructure-Wiki](https://github.com/bluscreenofjeff/Red-Team-Infrastructure-Wiki)
* [APT 분석 보고서 모음](https://github.com/CyberMonitor/APT_CyberCriminal_Campagin_Collections) 강력 추천
* [고급 위협의 본질과 공격력 정량화 연구](http://www.vxjump.net/files/aptr/aptr.txt)
* [OffensiveCon 컨퍼런스](https://www.offensivecon.org/) 더 이상 하나씩 보여주지 않음
* [ATT&CK](https://attack.mitre.org/matrices/enterprise/)
* [Red Team 0에서 1까지의 실천과思考](https://mp.weixin.qq.com/s/cyxC4Of4Ic9c_vujQayTLg) Red Team이 무엇인지 소개하며, 팀 내부의 레드 팀 구축에 적합함
* [MITRE | ATT&CK 중국어 사이트](https://huntingday.github.io) 지식 맵, 더 이상 업데이트되지 않음
* [fireeye 위협 연구](https://www.fireeye.com/blog/threat-research.html) 유명 위협 분석 회사
* [red-team-and-the-next](https://devco.re/blog/2019/10/24/evolution-of-DEVCORE-red-team-and-the-next/) -by DEVCORE
redrain과 그의 팀의 Anti Threat 기사
* [Noah blog](http://noahblog.360.cn/) Anti Threat and Threat Actors through Noah Lab Analysts
* [烽火实验室 blog](https://blogs.360.cn/)
* [APT 분석 및 TTPs 추출](https://paper.seebug.org/1132/)
* [ATT&CK/APT/귀인에 대한 논의](https://weibo.com/ttarticle/p/show?id=2309404450471736639616)
* [Legends Always Die -- FireEye Summit에서 리그 오브 레전드 공급망 공격 요약](https://card.weibo.com/article/m/show/id/2309404426957856047151) 한 건의 공급망 공격에 대한 추적으로, 도메인/IP/이메일 같은 기본 정보와 역사적인 APT 활동 연계
* [XShellGhost 사건 기술 회고 보고서](https://cert.360.cn/static/files/XShellGhost%E4%BA%8B%E4%BB%B6%E6%8A%80%E6%9C%AF%E5%9B%9E%E9%A1%BE%E6%8A%A5%E5%91%8A.pdf)
* [Kingslayer A supply chain attack](http://www.hackdog.me/article/Kingslayer-A_supply_chain_attack--Part_1.html)
Solarwinds 공급망 분석
* [Solarwinds 공급망 공격(골든체인 베어)에서 APT 작전 중 은밀한 전술을 살펴보다](https://mp.weixin.qq.com/s/UqXC1vovKUu97569LkYm2Q) qianxin을 대표하여 Solarwinds 공격 행위 분석
* [Solarwinds 분석](https://go.recordedfuture.com/hubfs/reports/pov-2020-1230.pdf)
* [Highly Evasive Attacker Leverages SolarWinds Supply Chain to Compromise Multiple Global Victims With SUNBURST Backdoor](https://www.fireeye.com/blog/threat-research/2020/12/evasive-attacker-leverages-solarwinds-supply-chain-compromises-with-sunburst-backdoor.html)
* [SUNBURST 추가 세부 분석](https://www.fireeye.com/blog/threat-research/2020/12/sunburst-additional-technical-details.html)
#### 위협 인텔리전스
* [북한 기소장](https://www.justice.gov/opa/press-release/file/1092091/download) 10년에 걸친 분류 과정
* [네트워크 공격의 '귀인'에 대한 소고](https://www.secrss.com/articles/14864) APT 분류의 지표, 방법(Cyber Attribution 문서 참고) 및 분류 문서 소개
* [위협 인텔리전스란?](https://www.secrss.com/articles/16577) 위협 인텔리전스의 정의, 분류, 지표를 소개하고, 사례를 통해 추적 및 분류 과정 설명
#### 피싱
* [SMTP 사용자 열거 원리 소개 및 관련 도구](http://www.freebuf.com/articles/web/182746.html) - 사용자 사전 획득에 사용
* [스피어 피싱 공격](https://payloads.online/archivers/2020-02-05/1)
* [AWVS를 사용하는 해커를 반격하는 방법](http://www.freebuf.com/news/136476.html)
* [MySQL에서 출발한 반격의 길](https://xz.aliyun.com/t/3277)
* [MySQL 클라이언트 임의 파일 읽기 공격 체인 확장](https://paper.seebug.org/1112/)
* [악성 MySQL 서버가 MySQL 클라이언트 파일 읽기](http://scz.617.cn/network/202001101612.txt)
* [https://github.com/BloodHoundAD/BloodHound/issues/267](https://github.com/BloodHoundAD/BloodHound/issues/267) -xss
* [Ghidra XXE에서 RCE로](https://xlab.tencent.com/cn/2019/03/18/ghidra-from-xxe-to-rce/) 엔지니어 대상
* [WeChat 외부 프로그램의 보안 위험](https://xlab.tencent.com/cn/2018/10/23/weixin-cheater-risks/) 개인 대상
* [nodejs 저장소 피싱](https://www.cnblogs.com/index-html/p/npm_package_phishing.html) 엔지니어 대상
* [Visual Studio Code 악성 확장 프로그램 제작](https://d0n9.github.io/2018/01/17/vscode%20extension%20%E9%92%93%E9%B1%BC/#) 엔지니어 대상
* [VS CODE 피싱](https://blog.doyensec.com/2020/03/16/vscode_codeexec.html) 엔지니어 대상
* [Python 패키지 피싱](https://paper.seebug.org/326/) 엔지니어 대상
* [Docker 클라이언트 피싱](https://www.blackhat.com/docs/us-17/thursday/us-17-Cherny-Well-That-Escalated-Quickly-How-Abusing-The-Docker-API-Led-To-Remote-Code-Execution-Same-Origin-Bypass-And-Persistence.pdf) 엔지니어 대상
* [악성 페이지를 이용한 로컬 Xdebug 공격](https://xlab.tencent.com/cn/2018/03/) 엔지니어 대상
* [Huawei HG532 라우터 피싱 RCE](https://xlab.tencent.com/cn/2018/01/05/a-new-way-to-exploit-cve-2017-17215/) 개인 대상
* [내부 네트워크 피싱]()```
RMI反序列化
WIN远程连接漏洞CVE-2019-1333
Mysql读文件&反序列化
Dubbo反序列化
IDE反序列化
恶意vpn
恶意控件
笔记软件rce
社交软件rce
NodeJS库rce
Python package 钓鱼
VSCODE EXTENSION 钓鱼
VS Studio钓鱼
Twitter钓鱼
红包插件钓鱼防撤回插件
解压rce
破解软件钓鱼
docker客户端钓鱼
docker镜像钓鱼
Xdebug
Ghidra钓鱼
bloodhound钓鱼
AWVS钓鱼
蚁剑
浏览器插件
云盘污染
이메일 위조
현재는 간단히 나열만 함
이전에 제공된 글 중 일부 내용에 오류가 있음, 실습으로 확인 필요
공식 매뉴얼 참고 권장
이전 생각나면 보충
구```
## 기여하기
모든 분의 기여를 환영합니다. 이 프로젝트에 대한 새로운 아이디어가 있거나 양질의 보안 관련 글을 발견하셨다면 이슈를 열어주세요. 그러면 감사의 말에 이름을 추가하겠습니다.
## 감사의 말
* @[tom0li](https://github.com/tom0li)
* @[neargle](https://github.com/neargle)
* @[r4v3zn](https://github.com/0nise)
## Star
Star를 주셔서 감사합니다
[](https://starchart.cc/tom0li/collection-document)
国外赏金之路 - 老司机赏金见解,历史赏金文章 list