#1用于识别、评估和优先处理系统和应用程序中安全漏洞的工具。
Kitploit 推荐

用于 AI 代理技能的安全扫描器。在安装 Claude Code、Codex 和 MCP 技能之前,检测其中的漏洞、恶意模式、安全风险、提示注入、数据外泄和供应链风险。
适用于 cnquery 和 cnspec 的 Linux、macOS 和 Windows 安装脚本

Terminal security for developers and AI agents. Intercepts homograph URLs, pipe-to-shell, ANSI injection, obfuscated payloads, data exfiltration, and…

Claude Code 技能包,专为漏洞挖掘和外部红队工作设计 - 包含82项技能、15个斜杠命令、681个已披露报告模式(精心整理自24个核心漏洞类别),以及企业身份与基础设施攻击矩阵。

一个强大且用户友好的二进制分析平台!

Lan Tian 的 NixOS 配置

TrustedRouter.com 仓库,用于安全的 LLM 代理


VampSecure Labs:FortiOS CVE 扫描器 (CVE-2018-13379, CVE-2022-40684, CVE-2023-27997, CVE-2024-21762)

测试你的提示词、代理和RAG。对AI进行红队测试/渗透测试/漏洞扫描。比较GPT、Claude、Gemini、DeepSeek等的性能。简单的声明式配置,支持命令行和CI/CD集成。被OpenAI和Anthropic使用。

Demonstrate the unauthenticated remote code execution vulnerability in the RSFiles! Joomla component through an arbitrary file upload.

Microsoft Sentinel SIEM 日志源分析器

通过准入控制、资源变更、后台扫描和容器镜像签名验证,在 Kubernetes 集群上强制执行安全与合规。


快速、零依赖的凭据测试工具,使用Go语言编写。支持SSH、MySQL、PostgreSQL、Redis、MongoDB、SMB等20多种协议的暴力破解。Hydra的替代品,并原生集成nerva/naabu管道。

用于附加到 MISP 事件或属性(如威胁行为者)的集群和元素

🧪 Collects CVE PoCs and backs them up to the Internet Archive when they are unavailable on GitHub.

Read-only AI agent that queries your cloud, code, and runtime infrastructure to surface misconfigurations, leaked secrets, and privilege escalation…