Skip to content
KitploitKITPLOIT
工具博客
提交
工具博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
Red-Teaming-Toolkit — 该仓库包含面向红队成员和威胁猎手的尖端开源安全工具(OST)。 | Kitploit
工具/GitHubGitHub/infosecn1nja/red-teaming-toolkit
侦察横向移动后渗透利用钓鱼攻击渗透测试命令与控制红队精选资源Payload 开发
GitHubinfosecn1nja/red-teaming-toolkit

Red-Teaming-Toolkit

该仓库包含面向红队成员和威胁猎手的尖端开源安全工具(OST)。

查看仓库
10.6k2.4k564个月前Kitploit 审核通过

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享

Red Teaming 工具包

本仓库包含尖端的开源安全工具(OST),这些工具将在对抗模拟期间为您提供帮助,并且作为面向威胁猎手的信息,可以使检测和预防控制更加容易。以下工具列表可能被 APT 和人为操作勒索软件(HumOR)等威胁行为者滥用。如果您想为此列表做出贡献,请向我发送拉取请求。


目录

  • 侦察
  • 初始访问
  • 投递
  • 态势感知
  • 凭据转储
  • 权限提升
  • 防御规避
  • 持久化
  • 横向移动
  • 外传
  • 杂项

侦察

名称描述URL
RustScan现代端口扫描器。快速发现端口(最快 3 秒)。通过我们的脚本引擎运行脚本(支持 Python、Lua、Shell)。https://github.com/RustScan/RustScan
Amass深入的攻击面映射和资产发现https://github.com/OWASP/Amass
gitleaksGitleaks 是一个 SAST 工具,用于检测 Git 仓库中硬编码的机密信息,如密码、API 密钥和令牌。https://github.com/zricethezav/gitleaks
S3Scanner扫描开放的 S3 存储桶并转储内容https://github.com/sa7mon/S3Scanner
cloud_enum多云 OSINT 工具。枚举 AWS、Azure 和 Google Cloud 中的公共资源。https://github.com/initstring/cloud_enum
Recon-ng开源情报收集工具,旨在减少从公开来源收集信息所花费的时间。https://github.com/lanmaster53/recon-ng
buster用于电子邮件侦察的高级工具https://github.com/sham00n/buster
linkedin2usernameOSINT 工具:为 LinkedIn 上的公司生成用户名列表https://github.com/initstring/linkedin2username
WitnessMeWeb 资产清单工具,使用 Pyppeteer(无头 Chrome/Chromium)截取网页截图,并提供一些额外的功能以简化操作。https://github.com/byt3bl33d3r/WitnessMe
pagodopagodo(被动 Google 搜索)——自动化 Google 黑客数据库的抓取和搜索https://github.com/opsdisk/pagodo
AttackSurfaceMapperAttackSurfaceMapper 是一个旨在自动化侦察过程的工具。https://github.com/superhedgy/AttackSurfaceMapper
SpiderFootSpiderFoot 是一个开源情报(OSINT)自动化工具。它集成了几乎所有可用的数据源,并利用多种数据分析方法,使数据易于浏览。https://github.com/smicallef/spiderfoot
dnscandnscan 是一个基于 Python 单词表的 DNS 子域名扫描器。

初始访问

暴力破解

载荷开发

投递

钓鱼

水坑攻击

名称描述URL
BeEFBeEF 是 Browser Exploitation Framework 的缩写。它是一个专注于 Web 浏览器的渗透测试工具https://github.com/beefproject/beef

命令与控制

远程访问工具(RAT)

暂存

日志聚合

态势感知

主机态势感知

凭据转储

权限提升

防御规避

持久化

横向移动

隧道

杂项

威胁情报防御

名称描述URL
Tidal CyberTidal Cyber 帮助企业组织定义、衡量和改进其防御措施,以应对对其最关键的对手行为。https://app.tidalcyber.com
控制验证指南威胁建模辅助与紫队内容仓库,为安全和情报团队提供 10,000 多个公开可用的技术和策略控制项以及 2,100 多个进攻性安全测试,与近 600 种常见攻击者技术对齐。https://controlcompass.github.io

云

Amazon Web Services (AWS)

Azure

对手仿真

AI 红队

进攻性 AI 代理

利用合法工具

红队脚本

红队基础设施

名称描述URL
红队基础设施 Wiki用于收集红队基础设施加固资源的 Wikihttps://github.com/bluscreenofjeff/Red-Team-Infrastructure-Wiki

DevOps

名称描述URL
NemesisNemesis 是一个进攻性数据富化管道和操作员支持系统。https://github.com/SpecterOps/Nemesis

报告与追踪

威胁情报

许可证

CC0

在法律允许的范围内,Rahmat Nurfauzi "@infosecn1nja" 已放弃此作品的所有版权及相关或相邻权利。

下载工具
https://github.com/rbsec/dnscan
spoofcheck一个检查域是否可被欺骗的程序。该程序检查 SPF 和 DMARC 记录中是否存在允许欺骗的弱配置。https://github.com/BishopFox/spoofcheck
LinkedIntLinkedIn 侦察工具https://github.com/vysecurity/LinkedInt
BBOT递归互联网扫描器,灵感来自 Spiderfoot,但设计得更快、更可靠,对渗透测试人员、漏洞赏金猎人和开发者更友好。https://github.com/blacklanternsecurity/bbot
Gato(GitHub 攻击工具包)Gato 或 GitHub 攻击工具包,是一个枚举和攻击工具,允许蓝队和进攻性安全从业者识别和利用 GitHub 组织公共和私有仓库中的管道漏洞。https://github.com/praetorian-inc/gato
名称描述URL
SprayingToolkit用于更快、更轻松、更高效地对 Lync/S4B、OWA 和 O365 进行密码喷洒攻击的脚本https://github.com/byt3bl33d3r/SprayingToolkit
o365recon通过有效的凭据从 O365 中检索信息https://github.com/nyxgeek/o365recon
CredMaster重构并改进的 CredKing 密码喷洒工具,使用 FireProx API 轮换 IP 地址、保持匿名并突破速率限制https://github.com/knavesec/CredMaster
名称描述URL
IvyIvy 是一个载荷创建框架,用于在内存中直接执行任意 VBA(宏)源代码。https://github.com/optiv/Ivy
PEzor开源 PE 加壳工具https://github.com/phra/PEzor
GadgetToJScript一个工具,用于生成 .NET 序列化小工具,当从 JS/VBS/VBA 脚本中使用 BinaryFormatter 反序列化时,可以触发 .NET 程序集加载/执行。https://github.com/med0x2e/GadgetToJScript
ScareCrow围绕 EDR 绕过设计的载荷创建框架。https://github.com/optiv/ScareCrow
DonutDonut 是一个位置无关代码,可实现 VBScript、JScript、EXE、DLL 文件和 .NET 程序集的内存执行。https://github.com/TheWover/donut
MystikalmacOS 初始访问载荷生成器https://github.com/D00MFist/Mystikal
charlotte完全不被检测的 c++ shellcode 加载器 ;)https://github.com/9emin1/charlotte
InvisibilityCloak用于 C# 后渗透工具的概念验证混淆工具包。它将为 C# Visual Studio 项目执行以下操作。https://github.com/xforcered/InvisibilityCloak
DendrobateDendrobate 是一个框架,便于开发通过托管 .NET 代码挂钩非托管代码的载荷。https://github.com/FuzzySecurity/Dendrobate
Offensive VBA and XLS Entanglement此仓库提供 VBA 如何用于进攻性目的(不仅仅是简单的投放器或 shell 注入器)的示例。随着我们开发更多用例,仓库将不断更新。https://github.com/BC-SECURITY/Offensive-VBA-and-XLS-Entanglement
xlsGen微型 Excel BIFF8 生成器,用于在 *.xls 中嵌入 4.0 宏https://github.com/aaaddress1/xlsGen
darkarmourWindows 防病毒规避https://github.com/bats3c/darkarmour
InlineWhispers用于在 Cobalt Strike 的 Beacon 对象文件(BOF)中处理直接系统调用的工具https://github.com/outflanknl/InlineWhispers
EvilClippy一个跨平台助手,用于创建恶意的 MS Office 文档。可以隐藏 VBA 宏、校验 VBA 代码(通过 P-Code)并混淆宏分析工具。运行于 Linux、OSX 和 Windows。https://github.com/outflanknl/EvilClippy
OfficePurge使用 OfficePurge 从 Office 文档中清除 VBA。VBA 清除会从 Office 文档的模块流中移除 P-Code。https://github.com/fireeye/OfficePurge
ThreatCheck标识 Microsoft Defender / AMSI 消费者标记的字节。https://github.com/rasta-mouse/ThreatCheck
CrossC2生成 CobaltStrike 的跨平台载荷https://github.com/gloxec/CrossC2
RulerRuler 是一个工具,允许您通过 MAPI/HTTP 或 RPC/HTTP 协议远程与 Exchange 服务器交互。https://github.com/sensepost/ruler
DueDLLigence用于应用程序白名单绕过和 DLL 侧加载的 Shellcode 运行器框架。该项目中包含的 Shellcode 会生成 calc.exe。https://github.com/fireeye/DueDLLigence
RuralBishopRuralBishop 实际上是 b33f 的 UrbanBishop 的副本,但所有 P/Invoke 调用已被替换为 D/Invoke。https://github.com/rasta-mouse/RuralBishop
TikiTorchTikiTorch 以致敬 Vincent Yiu 的 CACTUSTORCH 而命名。CACTUSTORCH 的基本概念是它生成一个新进程,分配一块内存区域,然后使用 CreateRemoteThread 在该目标进程中运行所需的 shellcode。进程和 shellcode 均由用户指定。https://github.com/rasta-mouse/TikiTorch
SharpShooterSharpShooter 是一个用于检索和执行任意 CSharp 源代码的载荷创建框架。SharpShooter 能够以多种格式创建载荷,包括 HTA、JS、VBS 和 WSF。https://github.com/mdsecactivebreach/SharpShooter
SharpSploitSharpSploit 是一个用 C# 编写的 .NET 后渗透库https://github.com/cobbr/SharpSploit
MSBuildAPICaller无需 MSBuild.exe 即可调用 MSBuild APIhttps://github.com/rvrsh3ll/MSBuildAPICaller
macro_packmacro_pack 是 @EmericNasi 开发的一个工具,用于自动化混淆和生成 MS Office 文档、VB 脚本以及其他格式,适用于渗透测试、演示和社会工程评估。https://github.com/sevagas/macro_pack
inceptor模板驱动的 AV/EDR 规避框架https://github.com/klezVirus/inceptor
mortar规避技术,用于击败和规避安全产品(AV/EDR/XDR)的检测和预防https://github.com/0xsp-SRD/mortar
ProtectMyTooling多打包器封装工具,允许我们将各种打包器、混淆器和其他红队导向武器串联起来。特色包括工件水印、IOC 收集和 PE 后门植入。您提供植入物,它进行大量隐蔽操作并输出混淆后的可执行文件。https://github.com/mgeeky/ProtectMyTooling
FreezeFreeze 是一个载荷工具包,用于通过挂起进程、直接系统调用和替代执行方法来绕过 EDR。https://github.com/optiv/Freeze
ShhhloaderShhhloader 是一个正在开发中的 shellcode 加载器。它接收原始 shellcode 作为输入,并编译一个 C++ 存根,该存根执行许多不同的操作以尝试绕过 AV/EDRhttps://github.com/icyguider/Shhhloader
DllShimmer轻松武器化 DLL 劫持。对任何 DLL 中的任意函数植入后门。https://github.com/Print3M/DllShimmer
名称描述URL
o365-attack-toolkit用于攻击 Office365 的工具包https://github.com/mdsecactivebreach/o365-attack-toolkit
Evilginx2Evilginx2 是一个中间人攻击框架,用于钓鱼任何网络服务的凭据和会话 Cookie。https://github.com/kgretzky/evilginx2
GophishGophish 是一个开源钓鱼工具包,专为企业和渗透测试人员设计。它提供快速轻松地设置和执行钓鱼演练及安全培训的能力。https://github.com/gophish/gophish
PwnAuthPwnAuth 是一个用于启动和管理 OAuth 滥用活动的 Web 应用程序框架。https://github.com/fireeye/PwnAuth
ModlishkaModlishka 是一个灵活且强大的反向代理,可将您的道德钓鱼活动提升到一个新的水平。https://github.com/drk1wi/Modlishka
名称描述URL
Cobalt StrikeCobalt Strike 是用于对抗模拟和红队行动的软件。https://cobaltstrike.com/
SpecterInsightSpecterInsight 是一个基于 .NET 的跨平台后渗透命令与控制框架,适用于红队演练、威胁仿真和培训。它开箱即用提供各种混淆载荷,并将规避检测作为核心功能。命令输出以 JSON 格式返回,并导出到 ELK 进行分析,通过预构建仪表板进行操作分析。https://practicalsecurityanalytics.com/specterinsight/
Brute Ratel C4Brute Ratel 是当前 C2 市场中最先进的红队和对抗模拟软件。https://bruteratel.com/
EmpireEmpire 5 是一个后渗透框架,包含纯 PowerShell Windows 代理,并兼容 Python 3.x Linux/OS X 代理。https://github.com/BC-SECURITY/Empire
PoshC2PoshC2 是一个代理感知的 C2 框架,用于帮助渗透测试人员进行红队行动、后渗透和横向移动。https://github.com/nettitude/PoshC2
KoadicKoadic C3 COM 命令与控制 - JScript RAThttps://github.com/zerosum0x0/koadic
merlinMerlin 是一个用 Go 编写的跨平台后渗透命令与控制服务器和代理。https://github.com/Ne0nd0g/merlin
Mythic一个跨平台、后渗透、红队框架,使用 python3、docker、docker-compose 和 Web 浏览器 UI 构建。https://github.com/its-a-feature/Mythic
CovenantCovenant 是一个 .NET 命令与控制框架,旨在突出 .NET 的攻击面,使进攻性 .NET 技术的使用更容易,并作为红队人员的协作命令与控制平台。https://github.com/cobbr/Covenant
shad0w一个后渗透框架,设计用于在被严密监控的环境中隐蔽操作https://github.com/bats3c/shad0w
SliverSliver 是一个通用跨平台植入框架,支持通过 Mutual-TLS、HTTP(S) 和 DNS 进行 C2。https://github.com/BishopFox/sliver
SILENTTRINITY一个由 Python 和 .NET 的 DLR 驱动的异步、协作式后渗透代理https://github.com/byt3bl33d3r/SILENTTRINITY
PupyPupy 是一个开源、跨平台(Windows、Linux、OSX、Android)的远程管理和后渗透工具,主要用 Python 编写https://github.com/n1nj4sec/pupy
HavocHavoc 是一个现代且可塑的后渗透命令与控制框架,由 @C5pider 创建。https://github.com/HavocFramework/Havoc
NimPlant一个用 Nim 和 Python 编写的轻量级第一阶段 C2 植入https://github.com/chvancooten/NimPlant
SharpC2SharpC2 是一个用 C# 编写的命令与控制(C2)框架。它包含一个 ASP.NET Core 团队服务器、一个 .NET Framework 植入和一个 .NET MAUI 客户端。https://github.com/rasta-mouse/SharpC2
LokiNode.js 命令与控制,用于脚本劫持易受攻击的 Electron 应用程序https://github.com/boku7/Loki
AdaptixC2Adaptix 是一个可扩展的后渗透和对抗仿真框架,专为渗透测试人员设计。Adaptix 服务器用 Golang 编写,以提供操作灵活性。https://github.com/Adaptix-Framework/AdaptixC2
Nimhawk一个用 Nim 编写的强大、模块化、轻量级且高效的命令与控制框架。https://github.com/hdbreaker/Nimhawk
名称描述URL
pwndrop红队人员可自行部署的文件托管服务,方便通过 HTTP 和 WebDAV 上传和共享载荷。https://github.com/kgretzky/pwndrop
C2concealer一个命令行工具,用于为 Cobalt Strike 生成随机化的 C2 可塑配置文件。https://github.com/FortyNorthSecurity/C2concealer
FindFrontableDomains搜索潜在的可前端域https://github.com/rvrsh3ll/FindFrontableDomains
Domain Hunter检查过期域名的分类/声誉和 Archive.org 历史记录,以确定用于钓鱼和 C2 域名的良好候选。https://github.com/threatexpress/domainhunter
RedWarden灵活的 CobaltStrike 可塑重定向器https://github.com/mgeeky/RedWarden
AzureC2RelayAzureC2Relay 是一个 Azure 函数,通过根据 Cobalt Strike 可塑 C2 配置文件验证传入请求来验证和转发 Cobalt Strike beacon 流量。https://github.com/Flangvik/AzureC2Relay
C3C3(自定义命令与控制)是一个允许红队快速开发和利用非传统命令与控制通道(C2)的工具。https://github.com/FSecureLABS/C3
Chameleon一个用于规避代理分类的工具https://github.com/mdsecactivebreach/Chameleon
Cobalt Strike Malleable C2 Design and Reference GuideCobalt Strike 可塑 C2 设计和参考指南https://github.com/threatexpress/malleable-c2/
redirect.rules快速且粗略的动态 redirect.rules 生成器https://github.com/0xZDH/redirect.rules
CobaltBusCobalt Strike External C2 与 Azure Servicebus 集成,C2 流量通过 Azure Servicebushttps://github.com/Flangvik/CobaltBus
SourcePointSourcePoint 是一个为 Cobalt Strike 命令与控制服务器设计的 C2 配置文件生成器,旨在确保规避。https://github.com/Tylous/SourcePoint
RedGuardRedGuard 是一个 C2 前端流量控制工具,可以避免蓝队、防病毒软件、EDR 的检查。https://github.com/wikiZ/RedGuard
skyhook一个往返混淆的 HTTP 文件传输设置,旨在绕过 IDS 检测。https://github.com/blackhillsinfosec/skyhook
GraphStrike通过 Microsoft Graph API 的 Cobalt Strike HTTPS beaconinghttps://github.com/RedSiege/GraphStrike
名称描述URL
RedELK红队 SIEM——用于红队的工具,用于跟踪和警报蓝队活动,并提高长期操作的可用性。https://github.com/outflanknl/RedELK
Elastic for Red Teaming用于配置红队 SIEM 的资源仓库(使用 Elastic)。https://github.com/SecurityRiskAdvisors/RedTeamSIEM
RedEyeRedEye 是一个支持红队和蓝队操作的视觉分析工具https://github.com/cisagov/RedEye
名称描述URL
AggressiveProxyAggressiveProxy 是一个 .NET 3.5 二进制文件(LetMeOutSharp)和一个 Cobalt Strike 攻击脚本(AggressiveProxy.cna)的组合。当 LetMeOutSharp 在工作站上执行时,它会尝试枚举所有可用的代理配置,并使用已识别的代理配置通过 HTTP(s) 与 Cobalt Strike 服务器通信。https://github.com/EncodeGroup/AggressiveProxy
Gopher用于发现低挂果实的 C# 工具https://github.com/EncodeGroup/Gopher
SharpEDRChecker检查正在运行的进程、进程元数据、加载到当前进程中的 DLL 以及每个 DLL 的元数据、常见的安装目录、已安装的服务及每个服务二进制文件的元数据、已安装的驱动程序及每个驱动程序的元数据,所有这些用于检测已知的防御产品,如防病毒、EDR 和日志工具。https://github.com/PwnDexter/SharpEDRChecker
Situational Awareness BOF此仓库旨在实现两个目的。首先,它提供了一组用 BOF 实现的基本态势感知命令。https://github.com/trustedsec/CS-Situational-Awareness-BOF
SeatbeltSeatbelt 是一个 C# 项目,执行一系列面向安全的主机调查“安全检查”,这些检查从进攻和防御安全角度都有意义。https://github.com/GhostPack/Seatbelt
SauronEyeSauronEye 是一个搜索工具,旨在帮助红队查找包含特定关键字的文件。https://github.com/vivami/SauronEye
SharpShares多线程 C# .NET 程序集,用于枚举域中可访问的网络共享https://github.com/mitchmoser/SharpShares
SharpAppLockerC# 移植的 Get-AppLockerPolicy PowerShell cmdlet,具有扩展功能。包括过滤和搜索特定类型规则和操作的能力。https://github.com/Flangvik/SharpAppLocker/
SharpPrinterPrinter 是 ListNetworks 的修改版和控制台版本https://github.com/rvrsh3ll/SharpPrinter
名称描述URL
--------------------
StandInStandIn 是一个小型 AD 后渗透工具包。StandIn 的出现是因为最近在 xforcered,我们需要一个 .NET 原生解决方案来执行基于资源的约束性委派。https://github.com/FuzzySecurity/StandIn
Recon-AD基于 ADSI 和反射 DLL 的 AD 侦察工具https://github.com/outflanknl/Recon-AD
BloodHound域管理的六度分隔https://github.com/BloodHoundAD/BloodHound
PSPKIAudit用于审计 Active Directory 证书服务 (AD CS) 的 PowerShell 工具包。https://github.com/GhostPack/PSPKIAudit
SharpViewharmj0y 的 PowerView 的 C# 实现https://github.com/tevora-threat/SharpView
RubeusRubeus 是一个用于原始 Kerberos 交互和滥用的 C# 工具集。它大量改编自 Benjamin Delpy 的 Kekeo 项目(CC BY-NC-SA 4.0 许可证)和 Vincent LE TOUX 的 MakeMeEnterpriseAdmin 项目(GPL v3.0 许可证)。https://github.com/GhostPack/Rubeus
nanorobeus用于管理 Kerberos 票据的最小化工具。支持红队框架。https://github.com/wavvs/nanorobeus
Grouper用于帮助查找 AD 组策略中易受攻击设置的 PowerShell 脚本。(已弃用,请改用 Grouper2!)https://github.com/l0ss/Grouper
ImproHound识别 BloodHound 中破坏 AD 层级划分的攻击路径https://github.com/improsec/ImproHound
ADReconADRecon 是一个收集 Active Directory 信息并生成报告的工具,该报告可以提供目标 AD 环境当前状态的全局视图。https://github.com/adrecon/ADRecon
ADCSPwn一个通过强制机器账户认证(Petitpotam)并将其中继到证书服务来在 Active Directory 网络中提升权限的工具。https://github.com/bats3c/ADCSPwn
名称描述URL
MimikatzMimikatz 是一个开源应用程序,允许用户查看和保存身份验证凭据,如 Kerberos 票据。https://github.com/gentilkiwi/mimikatz
Dumpert使用直接系统调用和 API 挂钩解除的 LSASS 内存转储器。https://github.com/outflanknl/Dumpert
CredBanditCredBandit 是一个概念验证的 Beacon 对象文件 (BOF),它使用静态 x64 系统调用来完整地内存转储一个进程,并通过现有 Beacon 通信通道发送回来。https://github.com/xforcered/CredBandit
CloneVaultCloneVault 允许红队操作员导出和导入包括 Windows 凭据管理器属性的条目。https://github.com/mdsecactivebreach/CloneVault
SharpLAPS从 LDAP 检索 LAPS 密码https://github.com/swisskyrepo/SharpLAPS
SharpDPAPISharpDPAPI 是来自 @gentilkiwi 的 Mimikatz 项目中某些 DPAPI 功能的 C# 移植。https://github.com/GhostPack/SharpDPAPI
KeeThief允许从内存中提取 KeePass 2.X 密钥材料,以及后门和枚举 KeePass 触发器系统。https://github.com/GhostPack/KeeThief
SafetyKatzSafetyKatz 是 @gentilkiwi 的 Mimikatz 项目的略微修改版本与 @subtee 的 .NET PE 加载器的组合。https://github.com/GhostPack/SafetyKatz
forkatz使用 forshaw 技术并利用 SeTrustedCredmanAccessPrivilege 进行凭据转储https://github.com/Barbarisch/forkatz
PPLKiller绕过 LSA 保护(又名受保护的进程轻量级)的工具https://github.com/RedCursorSecurityConsulting/PPLKiller
LaZagneLaZagne 项目是一个开源应用程序,用于检索存储在本地计算机上的大量密码。https://github.com/AlessandroZ/LaZagne
AndrewSpecialAndrewSpecial,自 2019 年起隐秘地转储 lsass 内存并绕过 "Cilence"。https://github.com/hoangprod/AndrewSpecial
Net-GPPPasswordGet-GPPPassword 的 .NET 实现。检索通过组策略首选项推送的账户的明文密码和其他信息。https://github.com/outflanknl/Net-GPPPassword
SharpChromium用于检索 Chromium 数据(如 Cookie、历史和已保存的登录信息)的 .NET 4.0 CLR 项目。https://github.com/djhohnstein/SharpChromium
ChloniumChlonium 是一个用于克隆 Chromium Cookie 的应用程序。https://github.com/rxwx/chlonium
SharpCloudSharpCloud 是一个简单的 C# 工具,用于检查与 Amazon Web Services、Microsoft Azure 和 Google Compute 相关的凭据文件是否存在。https://github.com/chrismaddalena/SharpCloud
pypykatz用纯 Python 实现的 Mimikatz。至少是它的一部分 :)https://github.com/skelsec/pypykatz
nanodump一个创建 LSASS 进程小型转储的 Beacon 对象文件。https://github.com/helpsystems/nanodump
KohKoh 是一个 C# 和 Beacon 对象文件 (BOF) 工具集,允许通过有意的令牌/登录会话泄漏来捕获用户凭据材料。https://github.com/GhostPack/Koh
PPLBlade受保护的进程转储工具,支持混淆内存转储并将其传输到远程工作站,无需将其写入磁盘。https://github.com/tastypepperoni/PPLBlade
TrickDump仅使用 NTAPI 转储 lsass,运行 3 个程序创建 3 个 JSON 和 1 个 ZIP 文件... 然后生成 Minidump!https://github.com/ricardojoserf/TrickDump
RemoteMonologueRemoteMonologue 是一种 Windows 凭据劫持技术,通过利用 Interactive User RunAs 键并通过 DCOM 强制 NTLM 认证来远程危害用户。https://github.com/3lp4tr0n/RemoteMonologue
名称描述URL
ElevateKitElevate Kit 演示了如何使用第三方权限提升攻击与 Cobalt Strike 的 Beacon 载荷。https://github.com/rsmudge/ElevateKit
WatsonWatson 是一个 .NET 工具,用于枚举缺失的 KB 并建议权限提升漏洞的利用方法。https://github.com/rasta-mouse/Watson
SharpUpSharpUp 是各种 PowerUp 功能的 C# 移植。目前,仅移植了最常见的检查;尚未实现任何武器化功能。https://github.com/GhostPack/SharpUp
dazzleUP一个检测由错误配置和缺失更新引起的 Windows 操作系统权限提升漏洞的工具。dazzleUP 检测以下漏洞。https://github.com/hlldz/dazzleUP
PEASS权限提升 Awesome 脚本套件(带颜色)https://github.com/carlospolop/PEASS-ng
SweetPotato从服务账户到 SYSTEM 的各种原生 Windows 权限提升技术集合https://github.com/CCob/SweetPotato
MultiPotato另一个通过 SeImpersonate 权限获取 SYSTEM 的 Potatohttps://github.com/S3cur3Th1sSh1t/MultiPotato
KrbRelayUp一个在未强制执行 LDAP 签名(默认设置)的 Windows 域环境中实现通用无需修复的本地权限提升工具。https://github.com/Dec0ne/KrbRelayUp
GodPotato只要你拥有 ImpersonatePrivilege 权限,你就是 SYSTEM!https://github.com/BeichenDream/GodPotato
PrivKitPrivKit 是一个简单的 Beacon 对象文件,用于检测由 Windows 操作系统错误配置引起的权限提升漏洞。https://github.com/mertdas/PrivKit
名称描述URL
RefleXXionRefleXXion 是一个旨在帮助绕过 AV/EPP/EDR 等使用的用户模式钩子的实用程序。https://github.com/hlldz/RefleXXion
EDRSandBlastEDRSandBlast 是一个用 C 编写的工具,它利用有漏洞的签名驱动程序来绕过 EDR 检测(内核回调和 ETW TI 提供程序)和 LSASS 保护。https://github.com/wavestone-cdt/EDRSandblast
unDefender通过滥用本机符号链接和 NT 路径来杀死你偏好的反恶意软件。https://github.com/APTortellini/unDefender
Backstab一个杀死反恶意软件受保护进程的工具https://github.com/Yaxser/Backstab
SPAWN - Cobalt Strike BOFCobalt Strike BOF,生成一个牺牲进程,向其注入 shellcode,并执行载荷。通过使用任意代码防护 (ACG)、BlockDll 和 PPID 欺骗生成牺牲进程来规避 EDR/用户态钩子。https://github.com/boku7/spawn
BOF.NET - A .NET Runtime for Cobalt Strike's Beacon Object FilesBOF.NET 是一个小型本机 BOF 对象与 BOF.NET 托管运行时结合,使得可以直接在 .NET 中开发 Cobalt Strike BOF。BOF.NET 消除了本机编译的复杂性以及手动导入本机 API 的麻烦。https://github.com/CCob/BOF.NET
NetLoader从文件路径或 URL 加载任何 C# 二进制文件,运行时修补 AMSI 并绕过 Windows Defender。https://github.com/Flangvik/NetLoader
FindObjects-BOF一个 Cobalt Strike Beacon 对象文件 (BOF) 项目,使用直接系统调用枚举进程以查找特定模块或进程句柄。https://github.com/outflanknl/FindObjects-BOF
SharpUnhooker基于 C# 的通用 API 解除挂钩器 - 自动解除 API 钩子(ntdll.dll、kernel32.dll、user32.dll、advapi32.dll 和 kernelbase.dll)。https://github.com/GetRektBoy724/SharpUnhooker
EvtMute对 Windows 事件日志报告的事件应用过滤器https://github.com/bats3c/EvtMute
InlineExecute-AssemblyInlineExecute-Assembly 是一个概念验证的 Beacon 对象文件 (BOF),允许安全专业人员进行进程内 .NET 程序集执行,作为 Cobalt Strike 传统 fork-and-run execute-assembly 模块的替代方案。https://github.com/xforcered/InlineExecute-Assembly
Phant0mWindows 事件日志杀手https://github.com/hlldz/Phant0m
SharpBlock一种通过阻止入口点执行来绕过 EDR 主动投影 DLL 的方法。https://github.com/CCob/SharpBlock
NtdllUnpatcherEDR 绕过的示例代码,请用于测试蓝队检测此类绕过 EDR 用户态钩子的恶意软件的能力。https://github.com/Kharos102/NtdllUnpatcher
DarkLoadLibrary用于进攻性操作的 LoadLibrary。https://github.com/bats3c/DarkLoadLibrary
BlockETW用于阻止进程中的 ETW 遥测的 .Net 3.5 / 4.5 程序集https://github.com/Soledge/BlockEtw
firewalker此仓库包含一个简单库,可用于向现有代码添加 FireWalker 钩子绕过功能https://github.com/mdsecactivebreach/firewalker
KillDefenderBOFKillDefender 的 Beacon 对象文件 PoC 实现https://github.com/Cerbersec/KillDefenderBOF
MangleMangle 是一个操作编译可执行文件(.exe 或 DLL)方面以逃避 EDR 检测的工具https://github.com/optiv/Mangle
AceLdr用于内存扫描器规避的 Cobalt Strike UDRL。https://github.com/kyleavery/AceLdr
AtomLdr具有高级规避功能的 CA DLL 加载器https://github.com/NUL0x4C/AtomLdr
Inline-Execute-PE在 CobaltStrike Beacons 中执行非托管 Windows 可执行文件https://github.com/Octoberfest7/Inline-Execute-PE
SigFlipSigFlip 是一个用于修补经过 Authenticode 签名的 PE 文件(exe、dll、sys 等)而不使现有签名失效或破坏它的工具。https://github.com/med0x2e/SigFlip
Blackout杀死反恶意软件受保护进程(BYOVD)https://github.com/ZeroMemoryEx/Blackout
ShellGhost一种基于内存的规避技术,使 shellcode 从进程开始到结束都不可见。https://github.com/lem0nSec/ShellGhost
PoolPartyBof由 @SafeBreach 和 @0xDeku 提出的 PoolParty 进程注入技术的 Beacon 对象文件实现,该技术滥用 Windows 线程池。https://github.com/0xEr3bus/PoolPartyBof
EDRSilencer一个使用 Windows 筛选平台 (WFP) 阻止端点检测和响应 (EDR) 代理向服务器报告安全事件的工具https://github.com/netero1010/EDRSilencer
EDR-FreezeEDR-Freeze 是一个将 EDR、反恶意软件的进程置于昏迷状态的工具。https://github.com/TwoSevenOneT/EDR-Freeze
名称描述URL
SharpStay用于安装持久化的 .NET 项目https://github.com/0xthirteen/SharpStay
SharPersist用 C# 编写的 Windows 持久化工具包。https://github.com/fireeye/SharPersist
SharpHide创建隐藏注册表项的工具。https://github.com/outflanknl/SharpHide
DoUCMe利用 NetUserAdd Win32 API 创建新的计算机账户。通过将 USER_INFO_1 类型的 usri1_priv 设置为 0x1000 来实现。https://github.com/Ben0xA/DoUCMe
A Black Path Toward The Sun(用于 Web 应用服务器的 HTTP TCP 隧道)https://github.com/nccgroup/ABPTTS
pivotnacci通过 HTTP 代理创建 socks 连接的工具https://github.com/blackarrowsec/pivotnacci
reGeorgreDuh 的后继者,攻破堡垒 Web 服务器并通过 DMZ 创建 SOCKS 代理。横向移动并攻陷。https://github.com/sensepost/reGeorg
DAMP自由访问控制列表修改项目:通过基于主机的安全描述符修改实现持久化。https://github.com/HarmJ0y/DAMP
IIS-RaidMicrosoft IIS(互联网信息服务)的本机后门模块https://github.com/0x09AL/IIS-Raid
SharPyShell用于 C# Web 应用程序的小型且混淆的 ASP.NET webshellhttps://github.com/antonioCoco/SharPyShell
ScheduleRunner一个 C# 工具,具有更大灵活性来定制计划任务,用于红队行动中的持久化和横向移动https://github.com/netero1010/ScheduleRunner
SharpEventPersist通过从事件日志写入/读取 shellcode 实现持久化https://github.com/improsec/SharpEventPersist
KrakenKraken,一个由 @secu_x11 编写的模块化多语言 webshell。https://github.com/kraken-ng/Kraken
HiddenDesktop用于 Cobalt Strike 的 HVNChttps://github.com/WKL-Sec/HiddenDesktop
名称描述URL
Liquid SnakeLiquidSnake 是一个允许操作员使用 WMI 事件订阅和 GadgetToJScript 执行无文件横向移动的工具https://github.com/RiccardoAncarani/LiquidSnake
PowerUpSQL用于攻击 SQL Server 的 PowerShell 工具包https://github.com/NetSPI/PowerUpSQL
SQLRecon一个专为进攻性侦察和后渗透设计的 C# MS SQL 工具包。https://github.com/skahwah/SQLRecon
SCShell无文件横向移动工具,依赖 ChangeServiceConfigA 来运行命令https://github.com/Mr-Un1k0d3r/SCShell
SharpRDP用于经过身份验证的命令执行的远程桌面协议控制台应用程序https://github.com/0xthirteen/SharpRDP
MoveKitMovekit 是 Cobalt Strike 内置横向移动的扩展,通过利用 execute_assembly 函数与 SharpMove 和 SharpRDP .NET 程序集实现。https://github.com/0xthirteen/MoveKit
SharpNoPSExec用于横向移动的无文件命令执行。https://github.com/juliourena/SharpNoPSExec
Responder/MultiRelayLLMNR/NBT-NS/mDNS 投毒者和 NTLMv1/2 中继。https://github.com/lgandx/Responder
impacketImpacket 是一个用于处理网络协议的 Python 类集合。Impacket 专注于提供对数据包的低级编程访问,对于某些协议(例如 SMB1-3 和 MSRPC),还提供了协议实现本身。https://github.com/SecureAuthCorp/impacket
FarmerFarmer 是一个用于在 Windows 域中收集 NetNTLM 哈希的项目。https://github.com/mdsecactivebreach/Farmer
CIMplantWMImplant 的 C# 移植,使用 CIM 或 WMI 查询远程系统。可以使用提供的凭据或当前用户的会话。https://github.com/FortyNorthSecurity/CIMplant
PowerLessShellPowerLessShell 依赖 MSBuild.exe 远程执行 PowerShell 脚本和命令,而无需生成 powershell.exe。您还可以使用相同的方法执行原始 shellcode。https://github.com/Mr-Un1k0d3r/PowerLessShell
SharpGPOAbuseSharpGPOAbuse 是一个用 C# 编写的 .NET 应用程序,可用于利用用户在组策略对象 (GPO) 上的编辑权限,以破坏该 GPO 控制的对象。https://github.com/FSecureLABS/SharpGPOAbuse
kerbrute通过 Kerberos 预认证快速暴力破解和枚举有效 Active Directory 账户的工具https://github.com/ropnop/kerbrute
mssqlproxymssqlproxy 是一个工具包,旨在通过受损的 Microsoft SQL Server 通过套接字重用,在受限环境中执行横向移动https://github.com/blackarrowsec/mssqlproxy
Invoke-TheHashPowerShell 传递哈希实用程序https://github.com/Kevin-Robertson/Invoke-TheHash
InveighZero用于渗透测试人员的 .NET IPv4/IPv6 中间人工具https://github.com/Kevin-Robertson/InveighZero
SharpSpraySharpSpray 是一个简单的代码集,用于使用 LDAP 对域的所有用户执行密码喷洒攻击,并且与 Cobalt Strike 兼容。https://github.com/jnqpblc/SharpSpray
CrackMapExec用于渗透测试网络的多功能工具https://github.com/byt3bl33d3r/CrackMapExec
SharpAllowedToAct基于资源约束委派 (msDS-AllowedToActOnBehalfOfOtherIdentity) 的计算机对象接管 C# 实现,基于 @elad_shamir 的研究。https://github.com/pkb1s/SharpAllowedToAct
SharpRDPHijackSharp RDP Hijack 是一个概念验证的 .NET/C# 远程桌面协议 (RDP) 会话劫持工具,用于已断开的会话https://github.com/bohops/SharpRDPHijack
CheeseTools此仓库基于已有的 MiscTool 构建,因此向 rasta-mouse 致敬,感谢他发布了这些工具并给予我处理它们的正确动力。https://github.com/klezVirus/CheeseTools
LatLoader用于演示使用 Havoc C2 框架进行自动横向移动的 PoC 模块。https://github.com/icyguider/LatLoader
SharpSpraySharpSpray 是一个用 .NET C# 编写的 Windows 域密码喷洒工具。https://github.com/iomoath/SharpSpray
MalSCCM此工具允许您滥用本地或远程 SCCM 服务器,向其管理的宿主机部署恶意应用程序。https://github.com/nettitude/MalSCCM
Coercer一个 Python 脚本,通过 9 种方法自动强制 Windows 服务器向任意机器进行身份验证。https://github.com/p0dalirius/Coercer
SharpSploitSharpSploit 是一个用 C# 编写的 .NET 后渗透库,旨在突出 .NET 的攻击面,并让红队人员更容易使用进攻性 .NET。https://github.com/cobbr/SharpSploit
orpheus通过修改 KDC 选项和加密类型绕过 Kerberoast 检测https://github.com/trustedsec/orpheus
goexecGoExec 是对用于在 Windows 设备上获得远程执行的一些方法的全新尝试。GoExec 实现了许多尚未实现的执行方法,并在总体上提供了显著的 OPSEC 改进。https://github.com/FalconOpsLLC/goexec
BitlockMove通过 Bitlocker DCOM 接口和 COM 劫持实现横向移动https://github.com/rtecCyberSec/BitlockMove
名称描述URL
ChiselChisel 是一个快速的 TCP/UDP 隧道,通过 HTTP 传输,经 SSH 安全。单个可执行文件同时包含客户端和服务器。https://github.com/jpillora/chisel
frpfrp 是一个快速反向代理,允许您将位于 NAT 或防火墙后面的本地服务器暴露到互联网。https://github.com/fatedier/frp
ligolo-ng一个先进但简单的隧道工具,使用 TUN 接口。https://github.com/nicocha30/ligolo-ng
SockTailSockTail 是一个小型二进制文件,它将设备加入 Tailscale 网络并在端口 1080 上暴露本地 SOCKS5 代理。它用于红队行动,您需要网络访问目标系统,而无需设置繁琐的端口转发、持久的守护进程或嘈杂的隧道。https://github.com/Yeeb1/SockTail
名称描述URL
--------------------
SharpExfiltrate模块化 C# 框架,用于通过安全且可信的通道外泄战利品。https://github.com/Flangvik/SharpExfiltrate
DNSExfiltrator通过 DNS 请求隐蔽通道进行数据外泄https://github.com/Arno0x/DNSExfiltrator
Egress-Assess用于测试出口数据检测能力的工具。https://github.com/FortyNorthSecurity/Egress-Assess
VeilTransfer一款数据外泄工具,旨在测试和增强检测能力。该工具模拟高级威胁行为者使用的真实数据外泄技术,帮助组织评估和改进其安全态势。https://github.com/infosecn1nja/VeilTransfer
名称描述URL
pacuAWS 利用框架,专为测试 Amazon Web Services 环境的安全性而设计。https://github.com/RhinoSecurityLabs/pacu
CloudMapperCloudMapper 帮助你分析 Amazon Web Services (AWS) 环境。https://github.com/duo-labs/cloudmapper
枚举 IAM 权限枚举与 AWS 凭据集关联的权限https://github.com/andresriancho/enumerate-iam
名称描述URL
Azure AD Connect 密码提取该工具包提供多种方法,用于从 Azure AD Connect 服务器提取和解密存储的 Azure AD 和 Active Directory 凭据。https://github.com/fox-it/adconnectdump
Storm SpotterAzure 红队工具,用于绘制 Azure 和 Azure Active Directory 对象图https://github.com/Azure/Stormspotter
ROADtoolsAzure AD 探索框架。https://github.com/dirkjanm/ROADtools
MicroBurst:攻击 Azure 的 PowerShell 工具包用于评估 Microsoft Azure 安全性的脚本集合https://github.com/NetSPI/MicroBurst
AADInternals用于管理 Azure AD 和 Office 365 的 AADInternals PowerShell 模块https://github.com/Gerenios/AADInternals
TeamFiltration跨平台框架,用于枚举、喷射、外泄和后门植入 O365 AAD 账户。https://github.com/Flangvik/TeamFiltration
MAAD 攻击框架用于简单、快速、有效测试 M365 和 Azure AD 安全性的攻击工具。https://github.com/vectra-ai-research/MAAD-AF
GraphRunner用于与 Microsoft Graph API 交互的后利用工具集https://github.com/dafthack/GraphRunner/
ADOKitADOKit 是一个工具包,可利用 Azure DevOps Services 的 REST API 对其进行攻击。https://github.com/xforcered/ADOKit
TokenTacticsAzure JWT 令牌操作工具集https://github.com/rvrsh3ll/TokenTactics
MaestroMaestro 是一款后利用工具,旨在通过用户工作站上的 C2 代理与 Intune/EntraID 交互,无需知道用户密码或 Azure 认证流程,支持令牌操作和基于 Web 的管理控制台。https://github.com/Mayyhem/Maestro
名称描述URL
Stratus Red TeamStratus Red Team 是云端的“原子红队”,允许以细粒度且自包含的方式模拟进攻性攻击技术。https://github.com/DataDog/stratus-red-team
Prelude Operator面向开发者的高级安全平台。通过模仿真实敌对攻击来保护你的组织。https://www.preludesecurity.com/products/operator
Prelude Build一个开源 IDE,用于编写、测试和验证生产级安全测试。https://www.preludesecurity.com/products/build
Caldera自动化对手仿真系统,可在 Windows 企业网络内执行后入侵敌对行为。https://github.com/mitre/caldera
APTSimulator一个 Windows 批处理脚本,使用一组工具和输出文件使系统看起来像被入侵过。https://github.com/NextronSystems/APTSimulator
原子红队小型且高度可移植的检测测试,映射到 Mitre ATT&CK 框架。https://github.com/redcanaryco/atomic-red-team
网络飞行模拟器flightsim 是一个轻量级工具,用于生成恶意网络流量,帮助安全团队评估安全控制和网络可见性。https://github.com/alphasoc/flightsim
Metta一个用于敌对仿真的安全准备工具。https://github.com/uber-common/metta
红队自动化 (RTA)RTA 提供了一套脚本框架,允许蓝队测试其针对恶意手法(基于 MITRE ATT&CK)的检测能力。https://github.com/endgameinc/RTA
TTPForgeTTPForge 是一个框架,旨在促进战术、技术和程序 (TTP) 的开发、自动化和执行。https://github.com/facebookincubator/TTPForge
名称描述URL
promptfoo用于评估、测试和红队 LLM 应用及提示的 CLI 和框架。https://github.com/promptfoo/promptfoo
GarakLLM 漏洞扫描器,旨在探测语言模型中的弱点、越狱和不安全行为。https://github.com/NVIDIA/garak
deepevalDeepEval 是一个简单易用的开源 LLM 评估框架,用于评估大型语言模型系统。https://github.com/confident-ai/deepeval
PyRIT生成式 AI 风险识别工具 (PyRIT) 是一个开源框架,旨在帮助安全专业人员和工程师主动识别生成式 AI 系统中的风险。https://github.com/microsoft/PyRIT
FuzzyAIFuzzyAI 模糊测试器是一款用于自动化 LLM 模糊测试的强大工具。旨在帮助开发者和安全研究人员识别越狱行为并缓解其 LLM API 中的潜在安全漏洞。https://github.com/cyberark/FuzzyAI
名称描述URL
PentAGI能够执行复杂渗透测试任务的完全自主 AI 代理系统。https://github.com/vxcontrol/pentagi
HexStrike AI一款先进的 MCP 服务器,让 AI 代理能够自主运行 150 多种网络安全工具,实现自动化渗透测试、漏洞发现、漏洞赏金自动化和安全研究。https://github.com/0x4m4/hexstrike-ai
CAI一个轻量级开源框架,赋能安全专业人员构建和部署 AI 驱动的进攻与防御自动化。https://github.com/aliasrobotics/CAI
RedAmon一个基于 AI 的自动化红队框架,从侦察到利用再到后利用,全程无需人工干预,实现进攻性安全操作自动化。https://github.com/samugit83/redamon
raptorRaptor 将 Claude Code 转变为一个通用型 AI 进攻/防御安全代理。https://github.com/gadievron/raptor
名称描述URL
Living Off The Land Drivers攻击者用于绕过安全控制并实施攻击的 Windows 驱动程序精选列表https://www.loldrivers.io/
GTFOBins可用于在配置不当的系统中绕过本地安全限制的 Unix 二进制文件精选列表https://gtfobins.github.io
LOLBASLOLBAS 项目的目标是记录每一个可用于“利用合法工具”技术的二进制文件、脚本和库https://lolbas-project.github.io/
Living Off Trusted Sites (LOTS) Project攻击者在进行钓鱼、C&C、外泄和下载工具时,利用流行的合法域名以逃避检测。以下网站列表允许攻击者使用其域名或子域名https://lots-project.com
Filesec及时了解攻击者使用的最新文件扩展名。https://filesec.io/
LOOBins"果园中的合法工具":macOS 二进制文件 (LOOBins) 旨在提供有关各种内置 macOS 二进制文件的详细信息,以及威胁行为者如何将其用于恶意目的。https://www.loobins.io/
WTFBinsWTFBin(n):一个行为完全像恶意软件却不知何故不是的二进制文件?该项目旨在编录表现出可疑行为的良性应用程序。这些二进制文件可能在威胁狩猎和自动化检测中产生噪音和误报。https://wtfbins.wtf/
Hijack Libs该项目提供一份 DLL 劫持候选清单https://hijacklibs.net
名称描述URL
RedTeamCCode红队 C 代码仓库https://github.com/Mr-Un1k0d3r/RedTeamCCode
EDRs该仓库包含红队演练中可能有用的 EDR 信息。https://github.com/Mr-Un1k0d3r/EDRs
Cobalt Strike 社区工具包社区工具包是一个由用户社区编写的扩展中央仓库,用于扩展 Cobalt Strike 的功能。https://cobalt-strike.github.io/community_kit/
名称描述URL
GhostwriterGhostwriter 是一个基于 Django 的 Web 应用程序,专为个人或红队操作员团队设计。https://github.com/GhostManager/Ghostwriter
VECTRVECTR 是一个工具,可帮助追踪你的红蓝队测试活动,以衡量不同攻击场景下的检测和预防能力https://github.com/SecurityRiskAdvisors/VECTR
PurpleOps一个开源、自托管的紫队管理 Web 应用程序。https://github.com/CyberCX-STA/PurpleOps
名称描述URL
APT 报告有趣的 APT 报告收集及一些特殊 IOChttps://github.com/blackorbird/APT_REPORT
Awesome 威胁情报精心整理的 Awesome 威胁情报资源列表https://github.com/hslatman/awesome-threat-intelligence
deepdarkCTI来自深网和暗网的网络威胁情报源集合https://github.com/fastfire/deepdarkCTI
CTI 仪表板实时了解网络安全威胁!一站式获取来自多家威胁情报供应商的报告及有用的资源。https://start.me/p/wMrA5z/cyber-threat-intelligence
Hudson Rock免费的网络犯罪情报工具集,用于检查电子邮件地址或域名是否在信息窃取恶意软件攻击中遭到泄露https://www.hudsonrock.com/threat-intelligence-cybercrime-tools