Skip to content
KitploitKITPLOIT
工具博客
提交
工具博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
CTF-s-Tools — 用于索引 CTF 实用工具的仓库 | Kitploit
工具/GitHubGitHub/ph4l4nx/ctf-s-tools
OSINT (开源情报)漏洞利用逆向工程隐写术恶意软件分析数字取证密码学CTF渗透测试学习与教育精选资源实验室与实践
2956个月前Kitploit 审核通过

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享
GitHub
ph4l4nx/ctf-s-tools

CTF-s-Tools

用于索引 CTF 实用工具的仓库

查看仓库

Repository to index interesting Capture The Flag tools and other stuff.

  • Table of Contents
    • Platforms to practice
    • Cryptography
      • Main
      • Secondary
      • Hashes
      • Esoteric Languages
    • Steganography
    • OSINT
      • Threat Hunting
    • Forensics
    • Reversing
    • Exploiting
    • Pentesting
      • Recon
      • Web
      • Exploit Database
      • Docker
      • Credentials
      • CVE Database Vulnerabilities
      • Exploitation
      • Active Directory
      • Privilege Escalation
        • Windows
        • Linux
      • Legit binaries in a system
      • AV bypass
      • Automatic Frameworks
      • Mobile
      • Wifi
      • Utility
    • Malware
      • Online engines
      • Distros to analyze malware
      • Tools
      • Free AVs EDRs and sandboxes
      • Ransomware
      • APTs
      • Blogs and Information
    • Utility
    • Wikis
    • Write-Ups
    • Other tools

练习平台

https://ctftime.org/

https://www.hackthebox.eu/

https://atenea.ccn-cert.cni.es/home

https://tryhackme.com/

https://www.vulnhub.com/

  • Web 黑客挑战:http://webhacking.kr/

  • 学习现代密码学的平台:https://cryptohack.org/

  • 逆向平台:https://crackmes.one/

  • 取证挑战:https://ctf.unizar.es/ && https://freetraining.dfirdiva.com/dfir-ctfs-challenges && https://socvel.com/

  • PicoCTF:https://play.picoctf.org/login

  • 蓝队:https://letsdefend.io/

密码学

主要

https://gchq.github.io/CyberChef/

https://www.dcode.fr/tools-list#cryptography

  • 密码标识符与分析器:https://www.boxentriq.com/code-breaking/cipher-identifier

  • 数据格式识别器:https://geocaching.dennistreysa.de/multisolver/

次要

  • 自动密码谜题求解器(替换密码) https://quipqiup.com/

  • 频率分析:https://crypto.interactive-maths.com/frequency-analysis-breaking-the-code.html

  • 维吉尼亚密码暴力破解:https://guballa.de/vigenere-solver

  • RsaCtfTool:https://github.com/Ganapati/RsaCtfTool

  • 解密表情符号消息 https://cryptoji.com/ & https://cryptii.com/pipes/morse-code-with-emojis

  • Padding-oracle-attacker:https://github.com/KishanBagaria/padding-oracle-attacker

  • 海上信号旗字典:https://en.wikipedia.org/wiki/International_maritime_signal_flags

  • 恩尼格玛机:https://cryptii.com/

  • 因数分解:http://factordb.com/

  • 密码分析资源汇总:https://github.com/mindcrypt/Cryptanalysis

http://rumkin.com/tools/cipher/

  • 实时转换器:https://kt.gy/tools.html#conv/

  • 用于从 Tor 隐藏服务描述符或公钥计算洋葱地址的简单脚本:https://gist.github.com/DonnchaC/d6428881f451097f329e (你需要修改第 14 行才能正常工作 "onion_address = hashlib.sha1(key.exportKey('DER')[22:]).digest()[:10]")。

  • 语音转文字:https://speech-to-text-demo.ng.bluemix.net/

  • 歌词(Rockstar 语言):https://codewithrockstar.com/online

  • 在线生成字符串 MD5 哈希:http://www.md5.cz/

哈希

  • 哈希数据库:https://crackstation.net/

  • Dehashed:https://www.dehashed.com/

  • 哈希破解:http://rainbowtables.it64.com/

  • 哈希数据库:https://www.onlinehashcrack.com/

  • 哈希数据库:https://md5decrypt.net/en/

  • 哈希数据库:https://hashkiller.io/

  • 哈希数据库:https://hashes.com/en/decrypt/hash

深奥语言

  • Ook! 深奥编程语言解码器:https://www.dcode.fr/ook-language

  • Brainfuck 深奥编程语言解码器:https://www.dcode.fr/brainfuck-language

  • Malbolge 深奥编程语言解码器:https://www.malbolge.doleczek.pl/

  • COW 深奥编程语言:https://frank-buss.de/cow.html

隐写术

  • Exiftool

  • Zsteg

  • Exiv2

  • Identify -verbose file

  • 魔数签名:https://asecuritysite.com/forensics/magic && https://www.garykessler.net/library/file_sigs.html → Hexeditor

  • Binwalk -e image

  • Foremost -i image -o outdir

  • Steghide:http://steghide.sourceforge.net/documentation/manpage_es.php (例如:steghide extract -sf file , steghide info file)

  • Stegseek:https://github.com/RickdeJager/stegseek (优于 Stegcracker)

  • StegCracker:https://github.com/Paradoxis/StegCracker

  • 更深入的隐写分析工具:https://aperisolve.fr/

  • 频谱分析仪:https://academo.org/demos/spectrum-analyzer/

  • Stegsolve:https://github.com/zardus/ctf-tools/blob/master/stegsolve/install (运行:java -jar steg_solve.jar)

  • 傅里叶变换:http://bigwww.epfl.ch/demo/ip/demos/FFT/ && https://github.com/0xcomposure/FFTStegPic

  • 数字隐形墨水隐写工具:https://sourceforge.net/projects/diit/

  • 从 8 位 Atari 高速磁带中解码文件:https://github.com/baktragh/turbodecoder

https://incoherency.co.uk/image-steganography/#unhide

http://exif-viewer.com/

https://stegonline.georgeom.net/upload

https://stylesuxx.github.io/steganography/

https://skynettools.com/free-online-steganography-tools/

  • 摩斯码自适应音频解码器:https://morsecode.world/international/decoder/audio-decoder-adaptive.html

  • Audacity(sudo apt-get install audacity)例如:https://www.hackiit.cf/write-up-hackiit-ctf-biological-hazard-ii/

  • AudioStego:https://github.com/danielcardeenas/AudioStego

  • 分析可疑文件和 URL 以检测隐写恶意软件:https://stegoinspector.com/#/

  • 奥雷贝什文字翻译器:https://funtranslations.com/aurebesh

  • 比特币隐写术:https://incoherency.co.uk/stegoseed/

  • 乱码隐写术:https://incoherency.co.uk/mojibake/

  • 国际象棋隐写术:https://incoherency.co.uk/chess-steg/

  • 魔眼求解器/查看器:https://magiceye.ecksdee.co.uk/

  • QR 码解码器:https://online-barcode-reader.inliteresearch.com/ && https://zxing.org/w/decode.jspx

  • Stegosuite: http://manpages.ubuntu.com/manpages/bionic/man1/stegosuite.1.html

  • StegSpy:http://www.spy-hunter.com/stegspydownload.htm

  • StegSecret:http://stegsecret.sourceforge.net/

  • Openstego:https://www.openstego.com/

  • Stegpic:https://domnit.org/stepic/doc/

  • Bytehist:https://www.cert.at/en/downloads/software/software-bytehist

https://www.bertnase.de/npiet/npiet-execute.php

  • 修复图片:https://online.officerecovery.com/es/pixrecovery/

  • 从像素化截图中恢复密码的工具:https://github.com/beurtschipper/Depix

  • 取证图像分析:https://github.com/GuidoBartoli/sherloq

  • 使用零宽字符的 Unicode 隐写术:https://330k.github.io/misc_tools/unicode_steganography.html

  • Stegsnow(零宽字符):https://pentesttools.net/hide-secret-messages-in-text-using-stegsnow-zero-width-characters/

  • SPAM 语言或 PGP:https://www.spammimic.com/decode.shtml

  • f5stegojs:https://desudesutalk.github.io/f5stegojs/

  • 解短链接:https://unshorten.it/

  • PNG 转储:https://blog.didierstevens.com/2022/04/18/new-tool-pngdump-py-beta/

开源情报

  • IP 信息:https://bgp.tools/

  • IP 信息:https://www.maxmind.com/en/geoip-demo

https://sitereport.netcraft.com/? && https://searchdns.netcraft.com/

  • https://iocfeed.mrlooquer.com/

  • https://www.ipaddress.com/

  • GHDB(Google 黑客数据库):https://www.exploit-db.com/google-hacking-database

  • Google 速查表:https://gist.github.com/sundowndev/283efaddbcf896ab405488330d1bbc06

https://ciberpatrulla.com/links/

https://osintframework.com/

  • 帮助你进行 OSINT 研究的工具、流程图和速查表: https://technisette.com/p/tools

  • 资源汇总:https://osint.link/

  • 全球域名数据库:http://web.archive.org/ && https://archive.eu/

  • DNS 搜索:https://dns.coffee/

  • 网络防御搜索:https://www.onyphe.io/

  • 滥用域名/IP:https://www.abuseipdb.com/

https://dns-lookup.jvns.ca/

https://www.greynoise.io/

https://www.brightcloud.com/tools/url-ip-lookup.php

  • URL 信誉检查器:https://www.urlvoid.com/

  • 物联网搜索引擎:https://www.shodan.io/ && 所有过滤器速查表:https://beta.shodan.io/search/filters

  • IVRE:https://ivre.rocks/

  • 威胁情报工具:https://cyberfive.uk/threat-intel-tools/

https://talosintelligence.com/

  • PGP 全球目录:https://keyserver2.pgp.com/vkd/GetWelcomeScreen.event

  • Hurricane Electric BGP:https://bgp.he.net/

  • Email2PhoneNumber:https://github.com/martinvigo/email2phonenumber

  • 蜜罐检测:https://honeyscore.shodan.io/

https://builtwith.com/

  • Pwn 邮箱数据库(TOR): http://pwndb2am4tzkvold.onion/

  • 检查邮箱或密码是否已泄露的网站:https://haveibeenpwned.com/

  • 泄露数据:https://leaks.sh/

  • Pwn DB:https://www.dehashed.com/?__cf_chl_jschl_tk__=ab484f797848c365ec48f7297ac4b9ba4587d775-1625827161-0-ARQgSNH3MSi0R4OUxmHmJCgUIz4nZrldFwXK6QZ21tONCEndyB_ypTCETLDm8vhRWeKD6v_ZraA5mbmvd03j1oeQb7QNsx5pg0lMhaNv2l7aw8DKR4a7ENkylr9knbiDx9X3RVn5AcH2uWuG_yRgk28j6x_zyccpXWc8LsTN9VxXZCZb16SEqwbuLdQ-JjWp0eQIgEMAPkLgosrsZyCdRa0A2mqMu8Mz4g-j4z8xR4v-4tqNwcP_TNtCK74-DIWZ80Zth2At6XizE72m_QifLrQH-gFUWPQ7hMzbNr5ONgZbyTZy_0YQA2SqHS5EUj5duq3WhbHdKEsRzXC6ch1EdQ5GagnSc8fH_NAqrI2aebrGF37HEXWkn7ZwxLGDLPAF63tV-77gQ4xhCnCDJp-vpcs

  • Pwn 邮箱数据库:https://intelx.io/

  • Pwn 邮箱数据库:https://cybernews.com/personal-data-leak-check/

  • PwnDB 脚本:https://github.com/davidtavarez/pwndb

  • 搜索明文过滤凭据:https://esgeeks.com/pwndb-buscar-credenciales-filtradas-texto-plano/

  • 邮箱检查器:https://toolbox.googleapps.com/apps/checkmx/

  • 车辆识别:https://carnet.ai/

  • 图片拍摄时间、太阳位置计算器:https://www.suncalc.org/#/27.6936,-97.5195,3/2024.01.09/09:23/1/3

  • 通用信息收集:https://github.com/Moham3dRiahi/Th3inspector

  • Google 图片搜索: , Yandex: , Bing:

威胁狩猎

分析 I:https://centralops.net/co/

分析 II:https://viewdns.info/

分析 III:https://sitereport.netcraft.com/

分析 IV:https://www.ipaddress.com/

恶意软件:https://www.virustotal.com/gui/home/upload & https://opentip.kaspersky.com/

信誉:https://talosintelligence.com/, https://www.abuseipdb.com/

域名技术信息:https://builtwith.com/

跟踪 URL 重定向路径的工具:https://wheregoes.com/

域名历史:https://web.archive.org/

实时黑洞列表、ASN:https://bgp.he.net/

SSL 证书:https://www.digicert.com/help/

重定向:https://lookyloo.circl.lu/

网络钓鱼域名数据库:http://phishtank.org/

网络钓鱼域名数据库:https://phishcheck.me/

网络钓鱼域名 CSV:https://phishstats.info/

网络钓鱼研究:https://safeweb.norton.com/ , https://isitphishing.org/, https://openphish.com/ && https://opentip.kaspersky.com/.

资源汇总:https://osintframework.com/

邮箱账户分析:curl emailrep.io/john.[email protected]

取证

  • 在线 PCAP 分析:https://lab.dynamite.ai/

  • 从 pcap 中识别字符串的工具:https://github.com/bee-san/pyWhat。示例:python3 -m pywhat redteam_test03-10423dd9015c050a40b7ccf2a53f57a9.pcapng > output

  • 高级 PCAP 分析:https://www.kitploit.com/2023/08/bryobio-network-pcap-file-analysis.html

  • Wireshark。速查表:https://cdn.comparitech.com/wp-content/uploads/2019/06/Wireshark-Cheat-Sheet-1.jpg

  • Volatility。速查表:https://blog.onfvp.com/post/volatility-cheatsheet/ >>> Malfind、yarascan、Connscan 和 netscan

  • Foremost

  • Binwalk

  • Autopsy

  • PhotoRec:https://www.cgsecurity.org/wiki/PhotoRec

  • 照片取证:https://29a.ch/photo-forensics/#forensic-magnifier

  • Recuva:https://www.ccleaner.com/recuva

  • 密钥:https://www.nirsoft.net/utils/product_cd_key_viewer.html

  • DDRescue。https://launchpad.net/ddrescue-gui

  • Rescuezilla:https://rescuezilla.com/

  • PolarProxy:https://www.netresec.com/?page=PolarProxy

  • MRC:https://www.magnetforensics.com/resources/magnet-ram-capture/

  • 介质获取(磁盘到镜像):https://guymager.sourceforge.io/

  • 快速搜索和追踪 Windows 事件日志:

https://www.ultimatewindowssecurity.com/securitylog/encyclopedia/

https://blog.didierstevens.com/programs/xorsearch/

取证资源汇总:https://start.me/p/JDRmPO/recursos-forenses && https://start.me/p/q6mw4Q/forensics

逆向

  • Binwalk

  • Dotpeek (.NET)

  • Angr(反混淆代码):https://angr.io/ && https://napongizero.github.io/blog/Defeating-Code-Obfuscation-with-Angr

  • GameBoy 调试器:https://bgb.bircd.org/

  • IDA Pro。速查表:https://www.dragonjar.org/cheat-sheet-ida-pro-interactive-disassembler.xhtml

  • OllyDbg。速查表:http://www.ollydbg.de/quickst.htm

  • GDB: https://gist.github.com/rkubik/b96c23bd8ed58333de37f2b8cd052c30

  • Radare2。速查表:https://gist.github.com/williballenthin/6857590dab3e2a6559d7

  • Ghidra。速查表:https://hackersfun.com/wp-content/uploads/2019/03/Ghidra-Cheat-Sheet.pdf

  • Immunity Debugger:https://www.immunityinc.com/products/debugger/

  • x64dbg

  • DnSpy https://github.com/dnSpy/dnSpy

  • Binary Ninja:https://binary.ninja/

  • 初学者逆向工具:https://exeinfo-pe.en.uptodown.com/windows

  • Regshot: https://sourceforge.net/projects/regshot/ (运行二进制文件前后对比)

  • CFF Explorer:https://download.cnet.com/CFF-Explorer/3000-2383_4-10431156.html

  • 在线反汇编器:https://onlinedisassembler.com/static/home/index.html

漏洞利用

  • 示例 1:python -c "print 'A'*150" >>> 然后 ./binario 150 A

python -c "print ('A' * 5100)"

  • 示例 2:(echo -e "\x31\xc0\x50\x68\x2f\x2f\x73\x68\x68\x2f\x62\x69\x6e\x89\xe3\x89\xc1\x89\xc2\xb0\x0b\xcd\x80\x31\xc0\x40\xcd\x80"; cat-) | ./binario (x86 32 位 Linux 的 Shellcode)

渗透测试

常见端口速查表:https://packetlife.net/media/library/23/common_ports.pdf

枚举速查表:https://pentestwiki.org/enumeration-cheat-sheet/

侦察

  • Nmap。速查表:https://highon.coffee/blog/nmap-cheat-sheet/ && https://scadahacker.com/library/Documents/Cheat_Sheets/Hacking%20-%20NMap%20Quick%20Reference%20Guide.pdf

  • 操作系统侦察:"服务版本 https://launchpad.net/"

  • https://sitereport.netcraft.com/

  • GUI-DNSRecon:https://www.kitploit.com/2023/02/dnsrecon-gui-dnsrecon-tool-with-gui-for.html

  • enum4linux - https://highon.coffee/blog/enum4linux-cheat-sheet/

Dig:https://cheatography.com/tme520/cheat-sheets/dig/

wget -nd -r -P /save/location -A jpeg,jpg,bmp,gif,png http://www.somedomain.com

递归下载文件并绕过 robots.txt:wget -e robots=off -drc -l5 domain* 使用第三方服务扫描:https://hackertarget.com/nmap-online-port-scanner/, https://www.ipfingerprints.com/, https://spiderip.com/online-port-scan.php, https://portscanner.standingtech.com/ && https://www.yougetsignal.com/tools/open-ports/

  • Scanless 项目:https://github.com/vesche/scanless

  • 列出某个域名的电子邮件:https://maildump.co/domain-search

  • 列出某公司的域名:Curl https://sonar.omnisint.io/tlds/

  • SPF,DKIM,DMARC:https://github.com/MattKeeley/Spoofy & https://www.kitploit.com/2023/02/email-vulnerablity-checker-find-email.html & https://github.com/magichk/magicspoofing && https://toolbox.googleapps.com/apps/checkmx/

  • 公司哈希与密码:https://www.dehashed.com/

  • dnsrecon -d dte.local -n IP - https://pentestlab.blog/2012/11/13/dns-reconnaissance-dnsrecon/

  • 最大的 DNS 历史数据:https://securitytrails.com/

  • DNS 主机记录:https://hackertarget.com/find-dns-host-records/

  • HTTP 标头分析漏洞工具:https://dnsdumpster.com/

  • ReconFTW:https://github.com/six2dez/reconftw

  • Autorecon:https://github.com/Tib3rius/AutoRecon

  • OSINT 收集工具:https://github.com/s0md3v/Photon

  • OSINT 收集工具:https://github.com/laramies/theHarvester

  • DNS 解析器:https://github.com/d3mondev/puredns

  • Sublist3r:https://github.com/aboul3la/Sublist3r

Web

  • Wappalyzer

  • whatweb -v -a 3 scanme.nmap.org

  • https://github.com/projectdiscovery/urlfinder

  • nmap -p 80 --script=http-*

  • HTTP 标头分析漏洞工具:https://github.com/Aetsu/gethead/blob/gh-pages/gethead.py

  • Feroxbuster

  • Gobuster。速查表:https://redteamtutorials.com/2018/11/19/gobuster-cheatsheet/

  • Burpsuite

  • OWASP ZAP, OpenVas, Sparta & Nikto。速查表:https://cdn.comparitech.com/wp-content/uploads/2019/07/NIkto-Cheat-Sheet.webp

  • Hydra。速查表:hydra -l admin -P /usr/share/wordlists/rockyou.txt IP http-post-form “__csrf_magic=sid%3Ae40fd9611063464c3ff346ffa53b7a28b3cd5971%2C1638348501&usernamefld=admin&passwordfld=^PASS^&login=Sign+In" || patator http_fuzz url=http://IP/ method=POST &usernamefld=admin&passwordfld=FILE0&login=Sign+In' 0=/usr/share/wordlists/rockyou.txt follow=1 accept_cookie=1 -x ignore:fgrep='Username or Password incorrect'

  • hydra -s 22 -l user -P /usr/share/wordlists/rockyou.txt IP -t 4 ssh

  • wfuzz。速查表:https://book.hacktricks.xyz/pentesting-web/web-tool-wfuzz

  • 2FA 绕过:https://www.xmind.net/m/8Hkymg/

  • Dirbuster。https://mundo-hackers.weebly.com/dirbuster.html

  • Linkfinder:https://github.com/GerbenJavado/LinkFinder

  • Dirsearch:https://github.com/maurosoria/dirsearch

  • 自动化的一体化 OS 命令注入与漏洞利用工具:https://github.com/commixproject/commix

  • 自动化 XSS 工具:https://xsser.03c8.net/

https://pentest-tools.com/home

https://book.hacktricks.xyz/

http://jsonviewer.stack.hu/

https://github.com/blaCCkHatHacEEkr/PENTESTING-BIBLE

https://jorgectf.gitbook.io/awae-oswe-preparation-resources/

  • Web 技巧:https://www.nccgroup.com/globalassets/our-research/uk/images/common_security_issues_in_financially-orientated_web.pdf.pdf

Exploit Database

  • CVE 搜索:https://github.com/Anonimo501/cve_search

  • https://www.exploit-db.com/

  • SearchSploit。速查表:https://blog.ehcgroup.io/2018/11/27/01/00/39/4198/como-usar-searchsploit-para-encontrar-exploits/hacking/ehacking/

  • https://cvexploits.io/

Docker

权限提升:docker run -v /:/mnt --rm -it imagen chroot /mnt sh

Credentials

  • IT 默认凭据:https://github.com/ihebski/DefaultCreds-cheat-sheet/blob/main/DefaultCreds-Cheat-Sheet.csv

  • OT 默认凭据:https://www.icsrank.com/

CVE Database Vulnerabilities

https://vulners.com/

Exploitation

  • 在线反向 Shell 生成器:https://www.revshells.com/

  • 反向 Shell 速查表:https://reconshell.com/reverse-shell-cheat-sheet/ && 速查表:https://github.com/swisskyrepo/PayloadsAllTheThings/blob/master/Methodology%20and%20Resources/Reverse%20Shell%20Cheatsheet.md

  • Webshells:https://github.com/BlackArch/webshells

  • Popshells:https://github.com/0x00-0x00/ShellPop

  • 将简单 Shell 升级为完全交互式 TTY:https://blog.ropnop.com/upgrading-simple-shells-to-fully-interactive-ttys/

  • crackmapexec - https://cheatsheet.haax.fr/windows-systems/exploitation/crackmapexec/

  • Rundll32 命令示例:https://www.jesusninoc.com/04/12/rundll32-commands-for-windows/

  • rdesktop IP, proxychains IP

  • sqlmap - https://www.security-sleuth.com/sleuth-blog/2017/1/3/sqlmap-cheat-sheet

  • 反向 Shell payload 生成器 - Hoaxshell:https://github.com/t3l3machus/hoaxshell

  • 在 Microsoft Exchange 上运行命令:https://github.com/WithSecureLabs/peas

  • Powerglot:https://github.com/mindcrypt/powerglot

Active Directory

  • 网络扫描器:https://www.softperfect.com/products/networkscanner/

  • linWinPwn:https://github.com/lefayjey/linWinPwn

  • Mimikatz:https://book.hacktricks.xyz/windows-hardening/stealing-credentials/credentials-mimikatz

  • Crackmapexec:https://cheatsheet.haax.fr/windows-systems/exploitation/crackmapexec/

  • LDAP 枚举:https://pentestwiki.org/enumeration-cheat-sheet/#h-ldap-enumeration

  • Seatbelt 检查:https://github.com/GhostPack/Seatbelt

  • Bloodhound:https://bloodhound.readthedocs.io/en/latest/index.html

  • Adalanche:https://www.kitploit.com/2021/08/adalanche-active-directory-acl.html

Privilege Escalation

Windows

sudo apt install peass

  • WinPEAS: https://github.com/carlospolop/privilege-escalation-awesome-scripts-suite/tree/master/winPEAS

  • Juicy potato: https://github.com/ohpe/juicy-potato

  • PowerUp: https://github.com/PowerShellMafia/PowerSploit/blob/dev/Privesc/PowerUp.ps1

Linux

  • LinPEAS: https://github.com/carlospolop/privilege-escalation-awesome-scripts-suite/tree/master/linPEAS

  • LinEnum: https://github.com/rebootuser/LinEnum/blob/master/LinEnum.sh

  • BeRoot: https://github.com/AlessandroZ/BeRoot/tree/master/Linux

Legit binaries in a system

  • 来自 Windows 的 Lolbas:https://lolbas-project.github.io/

  • 来自 Unix 系统的 GTFOBins:https://gtfobins.github.io/

AV bypass

  • 使用二进制文件绕过 Windows Defender:https://github.com/Bl4ckM1rror/FUD-UUID-Shellcode

  • Shikata ga nai: https://github.com/EgeBalci/sgn

  • AV 规避:https://github.com/Veil-Framework/Veil-Evasion

  • Shellter: https://www.kali.org/tools/shellter/

Automatic Frameworks

  • Metasploit。速查表:https://github.com/k1000o23/cheat_sheets/blob/master/metasploit_cheat_sheet.pdf

  • Kaboom: https://github.com/Leviathan36/kaboom

  • Fsociety 框架:https://github.com/Manisso/fsociety

  • Empire。速查表:https://github.com/HarmJ0y/CheatSheets/blob/master/Empire.pdf

Mobile

  • 移动端渗透测试速查表:https://github.com/tanprathan/MobileApp-Pentest-Cheatsheet && https://github.com/randorisec/MobileHackingCheatSheet

  • 自动化 移动端工具:https://github.com/MobSF/Mobile-Security-Framework-MobSF, https://github.com/SUPERAndroidAnalyzer/super

  • 存在漏洞的 Android 应用列表:https://github.com/netbiosX/Pentest-Bookmarks/blob/master/Training-Labs/Mobile-Testing/Android-Applications.mdown

  • PcapDroid: https://play.google.com/store/apps/details?id=com.emanuelef.remote_capture&hl=es_419&gl=US

Wifi

  • Fing 应用:https://www.fing.com/

  • Wifi 分析器:https://play.google.com/store/apps/details?id=com.farproc.wifi.analyzer&hl=es&gl=US&pli=1

  • Wifi 审计:https://github.com/v1s1t0r1sh3r3/airgeddon

  • https://en.kali.tools/?p=244

  • Wifi 破解:https://github.com/s4vitar/wifiCrack

  • Fern: https://github.com/savio-code/fern-wifi-cracker

  • EvilTrust: https://github.com/s4vitar/evilTrust

  • RomBuster: https://github.com/EntySec/RomBuster

Yersinia

Bettercap

Wifi Pineapple

https://linuxhint.com/how_to_aircrack_ng/

  • PCAP 捕获破解:https://www.onlinehashcrack.com/

Utility

  • mount -t cifs IP/SharedResource /mnt/smbmounted -o vers=2.1 && * smbclient -U "" -N //IP/SharedResource

  • dpkg -l 列出虚拟机中安装的所有程序。将输出通过管道处理以搜索你想要的内容。

  • Msfvenom: https://www.offensive-security.com/metasploit-unleashed/msfvenom/ & https://www.offensive-security.com/metasploit-unleashed/binary-payloads/

  • Nishang: https://github.com/samratashok/nishang

  • 你被卡住了吗?:https://ippsec.rocks/?#

  • OSCP 风格:https://gist.github.com/s4vitar/b88fefd5d9fbbdcc5f30729f7e06826e

  • Pentest-book: https://pentestbook.six2dez.com/ && https://book.hacktricks.xyz/pentesting-methodology

  • 视频:https://www.youtube.com/c/S4viOnLive

Malware

Online engines

  • 最佳:https://omniasec.ai/

  • https://www.filescan.io/

  • Virustotal: https://www.virustotal.com/gui/home/search

  • 在线 Cuckoo Sandbox:https://sandbox.pikker.ee/

  • 浏览器扩展程序:https://spin.ai/application-risk-assessment/

  • APK's:https://mobsf.live/ && https://koodous.com/

  • Joesandbox: https://www.joesandbox.com/#windows

  • Kaspersky: https://opentip.kaspersky.com/

  • Intezer: https://analyze.intezer.com/scan

  • Hybrid Analysis: https://www.hybrid-analysis.com/?lang=es

  • 假冒相关网站数据库:https://desenmascara.me/

  • ANY.RUN https://any.run/

https://antiscan.me/

https://www.virscan.org/

  • Polyswarm: https://polyswarm.network

https://metadefender.opswat.com/?lang=en

Distros to analyze malware

  • 基于 Windows 的 AI 驱动逆向工程工具包:https://github.com/Jakiboy/ReVens

  • 用于调查恶意软件的 Linux 发行版:https://docs.remnux.org/

  • 用于调查恶意软件的 Windows 发行版:https://github.com/mandiant/flare-vm

  • https://github.com/LaurieWired/linux_malware_analysis_container

Tools

  • Sysinternals: https://docs.microsoft.com/en-us/sysinternals/

  • Systeminformer: https://systeminformer.sourceforge.io/

  • Capa: https://github.com/mandiant/capa

  • Detect it easy(加壳检测器):https://en.kali.tools/?p=1644

  • Sysinspector: https://support.eset.com/es/que-es-eset-sysinspector

  • Dependency Walker(可执行文件依赖查看器):https://www.dependencywalker.com/

  • Autoruns: https://docs.microsoft.com/en-us/sysinternals/downloads/autoruns

  • 内存捕获工具:https://belkasoft.com/ram-capturer

  • 资源合集:https://github.com/rshipp/awesome-malware-analysis

  • 逆向工程师工具包:https://github.com/mentebinaria/retoolkit

  • PEstudio: https://www.winitor.com/

  • Malzilla: https://malzilla.org/

  • PROCMON+PCAP: https://www.procdot.com/

  • 分析 APK:https://github.com/quark-engine/quark-engine && https://github.com/mvt-project/mvt && https://github.com/pjlantz/droidbox

  • XORSearch: https://blog.didierstevens.com/programs/xorsearch/

  • RAT 解码器:https://github.com/kevthehermit/RATDecoders

Free AVs EDRs and Sandboxes

  • ClamAV: https://www.clamav.net/downloads#otherversions

  • MAC AV:https://www.pcrisk.es/mejores-programas-antivirus/8365-combo-cleaner-antivirus-and-system-optimizer-mac

  • 沙箱:https://github.com/CERT-Polska/drakvuf-sandbox

  • DragonFly: https://dragonfly.certego.net/register

  • 离线沙箱:https://sandboxie-plus.com/downloads/

  • OpenEDR: https://github.com/ComodoSecurity/openedr

Ransomware

  • 勒索软件解密工具:http://files-download.avg.com/util/avgrem/avg_decryptor_Legion.exe, https://success.trendmicro.com/solution/1114221-downloading-and-using-the-trend-micro-ransomware-file-decryptor, https://www.nomoreransom.org/es/decryption-tools.htmlm, https://www.avast.com/es-es/ransomware-decryption-tools , https://noransom.kaspersky.com/ , https://www.mcafee.com/enterprise/es-es/downloads/free-tools/ransomware-decryption.html, https://www.mcafee.com/enterprise/en-us/downloads/free-tools.html, https://www.emsisoft.com/ransomware-decryption-tools/, https://decoded.avast.io/threatresearch/decrypted-bianlian-ransomware/.

  • 总体概览:https://docs.google.com/spreadsheets/d/1TWS238xacAto-fLKh1n5uTsdijWdCEsGIM0Y0Hvmc5g/pubhtml#

  • 勒索软件团体:http://edteebo2w2bvwewbjb5wgwxksuwqutbg3lk34ln7jpf3obhy4cvkbuqd.onion/

APTs

  • 情报:https://docs.google.com/spreadsheets/d/1H9_xaxQHpWaa4O_Son4Gx0YOIzlcBWMsdvePFX68EKU/pubhtml# && https://github.com/StrangerealIntel/EternalLiberty/blob/main/EternalLiberty.csv && https://xorl.wordpress.com/

  • 威胁行为者知识图谱:https://jupyter.securitybreak.io/graph_TA/index.html

你是 APT 的目标吗? -> https://lab52.io/

  • APT 模拟器:https://github.com/NextronSystems/APTSimulator

Blogs and Information

  • 宏:https://blog.didierstevens.com/2021/01/19/video-maldoc-analysis-with-cyberchef/ && https://blog.nviso.eu/2022/04/06/analyzing-a-multilayer-maldoc-a-beginners-guide/

  • 恶意软件示例/二进制样本:https://bazaar.abuse.ch/, https://github.com/ytisf/theZoo & https://malshare.com/

实用工具

  • 绕过某些被过滤的端口:nmap -sSV ...

  • zip2john backup.zip secret.hash

  • john --show secret.hash

  • Hexeditor

  • nc -nlvp URL port

  • Grep

  • rgrep(递归 grep)

  • awk

  • perl

  • tail / head

  • curl -Llv domain | curl -b "protected=d41d8cd98f00b204e9800998ecf8427e"(cookie) "domain"

  • Identify -verbose

  • Hash-identifier

  • cat 'file' | md5sum, sha1sum,sha256sum...

  • echo "string" | base64 -d

  • Strings

  • File

  • Cewl。速查表:https://null-byte.wonderhowto.com/how-to/hack-like-pro-crack-passwords-part-5-creating-custom-wordlist-with-cewl-0158855/

  • 在线密码恢复 :https://www.lostmypass.com/try/

  • 计算机中存储的密码:https://github.com/AlessandroZ/LaZagne

  • 磁盘镜像:https://www.datanumen.com/disk-image-download-thanks/

  • crackzip: https://github.com/Xpykerz/CrackZip

  • zip2john: https://github.com/openwall/john/blob/bleeding-jumbo/src/zip2john.c

  • 常见用户密码分析器:https://github.com/Mebus/cupp 和 https://github.com/r3nt0n/bopscrk.

  • Dig: https://cheatography.com/tme520/cheat-sheets/dig/

  • wget -nd -r -P /save/location -A jpeg,jpg,bmp,gif,png http://www.somedomain.com

  • 递归下载文件并绕过 robots.txt:wget -e robots=off -drc -l5 domain

Wikis

https://github.com/JohnHammond/ctf-katana

https://github.com/OpenToAllCTF/Tips

逆向工程教程:https://github.com/mytechnotalent/Reverse-Engineering-Tutorial

Write-Ups

https://ctftime.org/writeups

https://apsdehal.in/awesome-ctf/

https://jorgectf.gitlab.io/

https://github.com/0e85dc6eaf/CTF-Writeups

https://github.com/RazviOverflow/ctfs

https://github.com/DEKRA-CTF/CTFs/tree/main/2020

https://medium.com/bugbountywriteup/tryhackme-reversing-elf-writeup-6fd006704148

https://github.com/W3rni0/ctf_writeups_archive/tree/master/castorsCTF_2020

Other tools

https://github.com/zardus/ctf-tools

https://github.com/apsdehal/awesome-ctf

下载工具
https://www.google.es/imghp?hl=es
https://yandex.com/images/
https://www.bing.com/?scope=images&nr=1&FORM=NOFORM
  • 反向图片搜索:https://tineye.com/

  • 跟踪 URL 重定向路径的工具:https://wheregoes.com/

  • 在线网络钓鱼检查器:https://easydmarc.com/tools/phishing-url

  • 网络钓鱼域名数据库:http://phishtank.org/

  • 网络钓鱼域名数据库:https://phishcheck.me/

  • 网络钓鱼研究:https://safeweb.norton.com/ , https://isitphishing.org/, https://openphish.com/ && https://opentip.kaspersky.com/.

  • Instagram:https://github.com/th3unkn0n/osi.ig

  • Censys:https://censys.io/ipv4

  • Zoomeye.org:https://www.zoomeye.org/

  • IVRE:https://ivre.rocks/

  • 物联网搜索引擎:https://www.thingful.net/

  • 查找与域名相关的邮箱地址:https://hunter.io/

  • 人员搜索引擎:https://thatsthem.com/

  • Fofa 搜索引擎:https://fofa.so/ (类似于 Shodan)

  • 图形化 OSINT 平台:https://www.spiderfoot.net/#

  • Fullhunt:https://fullhunt.io/

  • 代码搜索:https://grep.app/ && https://publicwww.com/

  • Natlas:https://natlas.io/

  • Spur:https://spur.us/

  • 公共 Wi-Fi 数据库:https://www.mylnikov.org/

  • 域名的 HTTP 头信息:https://www.webconfs.com/http-header-check.php

  • 公共文档的元数据:https://github.com/Josue87/MetaFinder

  • Twitter:https://github.com/twintproject/twint && https://tinfoleak.com/

  • https://github.com/Quantika14/osint-suite-tools

  • 检查你的 OWA(Outlook Web Access):https://checkmyowa.unit221b.com/

  • WhatsApp IP 泄露:https://github.com/bhdresh/Whatsapp-IP-leak?s=09

  • 手册:https://i-intelligence.eu/uploads/public-documents/OSINT_Handbook_2020.pdf

  • https://github.com/countercept/chainsaw
  • AccessData FTK Imager

  • EnCase

  • EaseUS Data Recovery Wizard

  • Testdisk:https://www.cgsecurity.org/wiki/TestDisk_Download

  • MFT_Browser:https://github.com/kacos2000/MFT_Browser

  • Powershell 解码器:https://github.com/R3MRUM/PSDecode, https://github.com/JohnLaTwC/PyPowerShellXray 和分析信息:https://darungrim.com/research/2019-10-01-analyzing-powershell-threats-using-powershell-debugging.html

  • PDF 分析器:https://github.com/zbetcheckin/PDF_analysis, https://github.com/DidierStevens/DidierStevensSuite/blob/master/pdfid.py, https://github.com/DidierStevens/DidierStevensSuite/blob/master/pdf-parser.py 和 https://eternal-todo.com/tools/peepdf-pdf-analysis-tool.

  • Office 分析器:https://github.com/DissectMalware/XLMMacroDeobfuscator, https://github.com/unixfreak0037/officeparser, https://github.com/decalage2/oletools, https://github.com/bontchev/pcodedmp, https://github.com/decalage2/ViperMonkey && https://blog.didierstevens.com/programs/oledump-py/.

  • 从文件中提取 Unicode 编码内容:https://github.com/DidierStevens/DidierStevensSuite/blob/master/base64dump.py

  • DTMF 电话频率:https://unframework.github.io/dtmf-detect/

  • 解密 WPA 密钥:pyrit -r "capctura.pcap" analyze

  • Diskeditor:https://www.disk-editor.org/index.html

  • Passware 加密分析器:https://www.passware.com/encryption-analyzer/

  • Windows 注册表恢复:https://www.softpedia.com/get/Tweak/Registry-Tweak/Windows-Registry-Recovery.shtml

  • xxd 命令

  • 蓝队速查表:https://itblogr.com/wp-content/uploads/2020/04/The-Concise-Blue-Team-cheat-Sheets.pdf

  • DFIR 速查表:https://www.jaiminton.com/cheatsheet/DFIR/#

  • 解析用户代理:https://developers.whatismybrowser.com/useragents/parse/

  • Grep 速查表:https://javiermartinalonso.github.io/linux/2018/01/15/linux-grep-patrones-debug.html

  • 博客:https://www.osintme.com/

  • 正则表达式(用于 grep -Po " ") https://www.autoregex.xyz/ && https://regex101.com/ 。速查表:https://cheatography.com/davechild/cheat-sheets/regular-expressions/

  • DFIR 速查表:https://dfircheatsheet.github.io/

  • 在线反编译器浏览器:https://dogbolt.org/

  • 在线编译器浏览器:https://godbolt.org/

  • 在线 .JAR 和 .Class 转 Java 反编译器: http://www.javadecompilers.com/

  • 十六进制编辑器、磁盘编辑器和内存编辑器:https://mh-nexus.de/en/downloads.php?product=HxD20

  • Android 反编译器:https://ibotpeaches.github.io/Apktool/

  • 反编译 Android 文件:https://github.com/skylot/jadx

  • Hopper 反汇编器:https://www.hopperapp.com/

  • 列出动态依赖:Ldd file

  • 解包某些二进制文件:Upx -d file

  • 识别加壳工具:https://github.com/horsicq/Detect-It-Easy

  • 理论:https://0xinfection.github.io/reversing/

  • Intel® 64 和 IA-32 架构软件开发人员手册:https://www.intel.com/content/dam/www/public/us/en/documents/manuals/64-ia-32-architectures-software-developer-instruction-set-reference-manual-325383.pdf

  • 技巧:https://blog.whtaguy.com/2020/04/guys-30-reverse-engineering-tips-tricks.html

  • Ffuf:https://github.com/ffuf/ffuf

  • Nuclei:https://github.com/projectdiscovery/nuclei

  • 过期域名:https://www.expireddomains.net/

  • 自动化 XSS 工具:https://github.com/ssl/ezXSS

  • RECOX:https://github.com/samhaxr/recox/blob/master/recox.sh

  • SQL payload 示例:https://github.com/payloadbox/sql-injection-payload-list

  • 命令注入:https://github.com/payloadbox/command-injection-payload-list

  • 2021 年的 XSS:https://netsec.expert/posts/xss-in-2021/

  • SSRF 速查表:https://highon.coffee/blog/ssrf-cheat-sheet/#curl-ssrf-wrappers--url-schema

  • WPscan

  • XSS firefox 扩展搜索器:https://addons.mozilla.org/es/firefox/addon/knoxss-community-edition/

  • 检查 HTTP 标头:https://requestbin.net/ && https://webhook.site/#!/75039a57-2015-4f74-9612-b762f4353b9b && https://securityheaders.com/?q=domain&followRedirects=on

  • Malwoverview: https://github.com/alexandreborges/malwoverview

  • 二进制字符串解混淆器:https://github.com/fireeye/flare-floss

  • 恶意软件网络分析(模拟 HTTP 服务器):https://github.com/felixweyne/imaginaryC2

  • 该工具允许你在模拟合法网络服务的同时,拦截并重定向全部或特定网络流量:https://github.com/mandiant/flare-fakenet-ng

  • [ICMP 渗出] tshark -r 1pcap_test_1c.pcapng -Y "icmp" -Tjson | grep data.data | awk {'print $2'} | cut -c 2-3 | uniq | xxd -r -p

  • 单行命令:https://linuxcommandlibrary.com/basic/oneliners.html

  • Google 信息: image