Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
APT-GUID — APT-GUID | Kitploit
工具/GitHubGitHub/al1ex/apt-guid
OSINT (开源情报)权限提升漏洞分析漏洞利用信息收集后渗透利用命令与控制社会工程学学习与教育红队精选资源
2312175年前Kitploit 审核通过

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享
GitHub
al1ex/apt-guid

APT-GUID

APT-GUID

查看仓库

项目介绍

整理APT领域的一些资料,涉及但不仅限于以下几个方面

  • APT攻击工具

  • APT分析报告

  • APT攻击技巧

工具整理

信息收集

主动情报收集
  • EyeWitness可以获取网站的屏幕快照,提供一些服务器信息,并在可能的情况下标识默认凭据 https://github.com/ChrisTruncer/EyeWitness
  • AWSBucketDump 可用于快速枚举AWS S3 Buckets以寻找战利品的工具 https://github.com/jordanpotti/AWSBucketDump
  • AQUATONE是用于对域名进行信息收集的工具 https://github.com/michenriksen/aquatone
  • Spoofcheck,用于检查是否可以欺骗域名,该程序检查SPF和DMARC记录中是否存在允许欺骗的弱配置 https://github.com/BishopFox/spoofcheck
  • Nmap用于发现计算机网络上的主机和服务 https://github.com/nmap/nmap
  • dnsrecon是一个DNS枚举脚本 https://github.com/darkoperator/dnsrecon
  • dirsearch是一个简单的命令行工具,爆破网站目录 https://github.com/maurosoria/dirsearch
  • Sn1per是一个自动化渗透工具 https://github.com/1N3/Sn1per
被动情报收集
  • Social Mapper OSINT社交媒体映射工具,获取用户名和图像(或LinkedIn公司名称)列表,并在多个社交媒体网站上进行大规模的自动目标搜索。不受API限制,因为它使用了Selenium。 https://github.com/SpiderLabs/social_mapper
  • skiptracer OSINT利用框架 https://github.com/xillwillx/skiptracer
  • FOCA主要用于在扫描的文档中查找元数据和隐藏信息。 https://github.com/ElevenPaths/FOCA
  • theHarvester用于从不同的公共来源收集子域名,电子邮件地址,虚拟主机,端口/banner和员工名称。 https://github.com/laramies/theHarvester
  • Metagoofil是用于提取目标网站中可用的公共文档(pdf,doc,xls,ppt等)的元数据的工具。 https://github.com/laramies/metagoofil
  • SimplyEmail电子邮件侦查。 https://github.com/killswitch-GUI/SimplyEmail
  • truffleHog在git仓库中搜索敏感数据,深入挖掘提交历史和分支。 https://github.com/dxa4481/truffleHog
  • Just-Metadata 收集和分析有关IP地址的元数据的工具。它尝试查找大型数据集中系统之间的关系。 https://github.com/ChrisTruncer/Just-Metadata
  • typofinder 显示IP地址所在国家/地区。 https://github.com/nccgroup/typofinder
  • pwnedOrNot是一个python脚本,用于检查电子邮件帐户是否因数据泄露而受到攻击;如果电子邮件帐户受到攻击,则它将继续查找该帐户的密码。 https://github.com/thewhiteh4t/pwnedOrNot
  • GitHarvester该工具用于从GitHub收集信息,例如google dork。 https://github.com/metac0rtex/GitHarvester
  • pwndb是一个python命令行工具,用于使用具有相同名称的Onion服务搜索泄漏的凭据。 https://github.com/davidtavarez/pwndb/
  • LinkedInt LinkedIn Recon工具。 https://github.com/vysecurity/LinkedInt
  • CrossLinked LinkedIn枚举工具,通过搜索引擎抓取从组织中提取有效的员工姓名。 https://github.com/m8r0wn/CrossLinked
  • findomain 快速子域名枚举工具,它使用证书的透明性日志和一些API。 https://github.com/Edu4rdSHL/findomain

漏洞利用

  • WinRAR Remote Code Execution Proof of Concept exploit for CVE-2018-20250. https://github.com/WyAtu/CVE-2018-20250
  • Composite Moniker Proof of Concept exploit for CVE-2017-8570. https://github.com/rxwx/CVE-2017-8570
  • Exploit toolkit CVE-2017-8759 https://github.com/bhdresh/CVE-2017-8759
  • CVE-2017-11882 Exploit https://github.com/unamer/CVE-2017-11882
  • Adobe Flash Exploit CVE-2018-4878. https://github.com/anbai-inc/CVE-2018-4878
  • Exploit toolkit CVE-2017-0199是一个方便的python脚本,为渗透测试人员和安全研究人员提供了一种快速有效的方法来测试Microsoft Office RCE。https://github.com/bhdresh/CVE-2017-0199
  • demiguise HTA加密工具 https://github.com/nccgroup/demiguise
  • Office-DDE-Payloads收集脚本和模板,生成嵌入了DDE(无宏命令执行技术)的Office文档。https://github.com/0xdeadbeefJERKY/Office-DDE-Payloads
  • CACTUSTORCH用于对手模拟的payload生成。https://github.com/mdsecactivebreach/CACTUSTORCH
  • SharpShooter是一个payload创建框架,用于执行任意CSharp源代码。https://github.com/mdsecactivebreach/SharpShooter
  • DKMC,这是一种生成混淆的shellcode的工具,该shellcode存储在图像中。该映像是100%有效的,也是100%有效的shellcode。https://github.com/Mr-Un1k0d3r/DKMC
  • 恶意宏生成器用于生成模糊的宏,其中还包括AV/沙箱转义机制。https://github.com/Mr-Un1k0d3r/MaliciousMacroGenerator
  • SCT-obfuscator Cobalt Strike SCT payload混淆器。https://github.com/Mr-Un1k0d3r/SCT-obfuscator
  • Invoke-Obfuscation PowerShell混淆器。https://github.com/danielbohannon/Invoke-Obfuscation
  • Invoke-CradleCrafter PowerShell远程下载的生成器和混淆器。https://github.com/danielbohannon/Invoke-CradleCrafter
  • Invoke-DOSfuscation cmd.exe命令混淆生成器和检测测试工具。https://github.com/danielbohannon/Invoke-DOSfuscation
  • morphHTA。https://github.com/vysec/morphHTA
  • Unicorn是使用PowerShell降级攻击并将shellcode直接注入内存的简单工具。https://github.com/trustedsec/unicorn
  • Shellter是一种动态的Shellcode注入工具,也是有史以来第一个真正的动态PE感染器。https://www.shellterproject.com/
  • EmbedInHTML嵌入和隐藏HTML中的任何文件。https://github.com/Arno0x/EmbedInHTML
  • SigThief窃取签名并制作一个无效签名。https://github.com/secretsquirrel/SigThief
  • Veil,https://github.com/Veil-Framework/Veil
  • CheckPlease用PowerShell,Python,Go,Ruby,C,C#,Perl和Rust编写的 Sandbox逃避模块。https://github.com/Arvanaghi/CheckPlease
  • Invoke-PSImage是一种将PowerShell脚本嵌入PNG文件的像素中并可以执行的工具。https://github.com/peewpw/Invoke-PSImage
  • LuckyStrike基于PowerShell的实用程序,用于创建恶意Office宏文档。仅用于渗透或教育目的。https://github.com/curi0usJack/luckystrike
  • ClickOnceGenerator https://github.com/Mr-Un1k0d3r/ClickOnceGenerator
  • macro_pack是@EmericNasi的工具,用于自动混淆和生成MS Office文档,VB脚本以及其他格式的渗透测试,演示和社会工程评估。https://github.com/sevagas/macro_pack
  • StarFighters一个基于JavaScript和VBScript的Empire Launcher。https://github.com/Cn33liz/StarFighters
  • nps_payload 该脚本将生成payload,以避免基本的入侵检测。它利用了来自多个不同来源的公开展示的技术。https://github.com/trustedsec/nps_payload
  • SocialEngineeringPay加载了一系列用于凭据盗窃和鱼叉式网络钓鱼攻击的社交工程技巧和payload。https://github.com/bhdresh/SocialEngineeringPayloads
  • Social-Engineer Toolkit是一个为社会工程设计的开源渗透测试框架。https://github.com/trustedsec/social-engineer-toolkit
  • phishery是一个简单的启用SSL的HTTP服务器,其主要目的是通过基本身份验证来进行网络钓鱼凭据。 https://github.com/ryhanson/phishery
  • PowerShdll与rundll32 一起运行PowerShell。绕过软件限制。https://github.com/p3nt4/PowerShdll
  • UltimateAppLockerByPassList记录绕过AppLocker的最常用技术。https://github.com/api0cradle/UltimateAppLockerByPassList
  • ruler,可让您通过MAPI / HTTP或RPC / HTTP协议与Exchange服务器进行远程交互。https://github.com/sensepost/ruler
  • Generate-Macro是一个独立的PowerShell脚本,它将生成具有指定payload和持久性方法的恶意Microsoft Office文档。https://github.com/enigma0x3/Generate-Macro
  • MaliciousMacroMSBuild生成恶意宏并通过MSBuild应用程序白名单绕过执行Powershell或Shellcode。https://github.com/infosecn1nja/MaliciousMacroMSBuild
  • Meta Twin 文件资源克隆器。从一个文件中提取包括数字签名在内的元数据,然后将其注入另一个文件中。https://github.com/threatexpress/metatwin
  • WePWNise生成独立于体系结构的VBA代码,以在Office文档或模板中使用,并自动绕过应用程序控制。https://github.com/mwrlabs/wePWNise
  • DotNetToJScript,用于创建一个JScript文件,该文件从内存中加载.NET v2程序集。https://github.com/tyranid/DotNetToJScript
  • PSAmsi是用于审核和破坏AMSI签名的工具。https://github.com/cobbr/PSAmsi
  • ReflectiveDLLInjection https://github.com/stephenfewer/ReflectiveDLLInjection
  • ps1encode用于生成和编码基于powershell的metasploit payload。https://github.com/CroweCybersecurity/ps1encode
  • Worse-PDF。用于从Windows机器上窃取Net-NTLM哈希。https://github.com/3gstudent/Worse-PDF
  • SpookFlare具有绕过安全措施的不同角度。https://github.com/hlldz/SpookFlare
  • GreatSCT是一个开源项目,用于生成应用程序白名单绕过。https://github.com/GreatSCT/GreatSCT
  • NPS在没有Powershell的情况下运行Powershell。https://github.com/Ben0xA/nps
  • Meterpreter_Paranoid_Mode.sh 保护Meterpreter的分阶段/无阶段连接。https://github.com/r00t-3xp10it/Meterpreter_Paranoid_Mode-SSL
  • backdoor-factory(BDF)将使用用户所需的shellcode修补可执行二进制文件,并继续正常执行预修补状态。https://github.com/secretsquirrel/the-backdoor-factory
  • MacroShop脚本集合,以帮助通过Office宏传递payload。https://github.com/khr0x40sh/MacroShop
  • UnmanagedPowerShell从非托管进程执行PowerShell。https://github.com/leechristensen/UnmanagedPowerShell
  • evil-ssdp Spoof SSDP会针对网络上的NTLM哈希回复网络钓鱼。创建一个伪造的UPNP设备,诱使用户访问恶意网页仿冒页面。https://gitlab.com/initstring/evil-ssdp
  • Ebowla用于制作环境关键payload的框架。https://github.com/Genetic-Malware/Ebowla
  • make-pdf嵌入式工具可用于创建带有嵌入式文件的PDF文档。https://github.com/DidierStevens/DidierStevensSuite/blob/master/make-pdf-embedded.py
  • avet(AntiVirusEvasionTool)使用不同的规避技术将Windows机器定位为具有可执行文件的计算机。https://github.com/govolution/avet
  • EvilClippy用于创建恶意MS Office文档的跨平台助手。可以隐藏VBA宏,混淆宏。在Linux,OSX和Windows上运行。https://github.com/outflanknl/EvilClippy
  • CallObfuscator从静态分析工具和调试器中混淆Windows API。https://github.com/d35ha/CallObfuscator
  • Donut是一个Shellcode生成工具,可从.NET程序集创建与位置无关的Shellcodepayload。此shellcode可用于将Assembly注入到任意Windows进程中。https://github.com/TheWover/donut

社工钓鱼

  • King Phisher https://github.com/securestate/king-phisher
  • FiercePhish https://github.com/Raikia/FiercePhish
  • ReelPhish https://github.com/fireeye/ReelPhish/
下载工具