Skip to content
KitploitKITPLOIT
工具博客
提交
工具博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
Scanners-Box — A powerful and open-source toolkit for hackers and security automation - 安全行业从业者自研开源扫描器合辑 | Kitploit
工具/GitHubGitHub/we5ter/scanners-box
漏洞扫描器物联网安全Web安全渗透测试移动安全二进制分析学习与教育精选资源AI 安全
GitHubwe5ter/scanners-box

Scanners-Box

A powerful and open-source toolkit for hackers and security automation - 安全行业从业者自研开源扫描器合辑

查看仓库
9.0k2.4k9天前Kitploit 审核通过

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享

English | 简体中文 | Español

version license scanners ScanCodex MCP Server

简介

Scanners Box 是一个精心策划的 9000+ ⭐ 开源网络安全百宝箱——重点关注 AI 自动化安全 Agent 与红蓝队对抗工具。所有工具全部源代码开放,涵盖 10+ 个类别:子域名枚举、IoT 审计、移动端分析、智能合约扫描、云端安全等。

Project A³C

A³C — 自主 AI 认证计划

状态: 活跃 类型: 开源项目

A³C Scanner-Box 认证

展示 A³C 徽章 的项目,即代表已通过 Scanners Box 官方认证,为活跃可信的 AI 驱动的自主项目。

A³C 徽章 是 Scanners Box 对开源 AI 驱动的自主项目的官方认证——经审核的活跃可信前沿工具。

Visit Project A³C

目录

[!IMPORTANT] ❋⚛🐋 For AI

  • AI自主网络安全Agent
  • LLM驱动的漏洞扫描器
  • AI应用安全审计
  • AI Agent运行时管控
  • Agent技能安全审计
  • 自主漏洞发现与修复技能
  • 智能合约漏洞扫描器
  • 红蓝对抗
  • 移动应用包文件分析
  • 二进制可执行文件分析
  • 隐私合规
  • 子域名爆破枚举或接管
  • 数据库注入漏洞或认证爆破
  • 网站弱用户名或弱口令枚举爆破
  • IoT设备审计
  • 多类型跨站脚本漏洞检测
  • 企业敏感信息泄露检测
  • 木马检测
  • 中间件漏洞评估
  • 特定Web漏洞类型扫描器
  • 动态或静态代码审计
  • 模块化设计扫描器或漏洞评估框架
  • 定向APT攻击检测

AI自主网络安全Agent

  • https://github.com/oritera/Cairn - 通用状态空间搜索引擎,率先在自主渗透测试上验证——无角色限制,无工作流约束,给定起终点后自主寻路

A³C 认证 GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/KeygraphHQ/shannon - 面向 Web 应用与 API 的自主白盒 AI 渗透测试工具,分析源代码、识别攻击向量并自动执行真实漏洞利用

A³C 认证 GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/SickHackPark/SickHackShark - AI 多智能体 CTF 全流程自动化平台,覆盖信息收集、扫描、漏洞利用与 flag 获取

A³C 认证 GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/SanMuzZzZz/LuaN1aoAgent - LuaN1ao(鸾鸟)—— 新一代基于 LLM 的自主渗透测试 Agent,创新融合 P-E-R Agent 协作框架与因果图推理,模拟安全专家攻防思维

A³C 认证 GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/Ed1s0nZ/CyberStrikeAI - AI 原生安全测试平台(Go 实现),集成 100+ 安全工具、智能编排引擎、角色化测试、技能系统与全生命周期管理,内置轻量级 C2 框架,通过 MCP 协议与 AI Agent 实现端到端自动化安全测试

A³C 认证 GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/ASCIT31/Dark-Moon - 自主 AI 渗透测试引擎,持续对 Web、云、AD 和 Kubernetes 执行攻击面安全测试,运用智能体推理、真实漏洞利用执行和攻击路径分析提供基于证据的漏洞发现

GitHub language count GitHub last commit GitHub stars GitHub

LLM驱动的漏洞扫描器

  • https://github.com/weareaisle/nano-analyzer - AISLE 开发的基于LLM的极简0day漏洞扫描器

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/vercel-labs/deepsec - 基于 Agent 的漏洞扫描器,针对大规模代码仓库进行按需审查,发现长期潜伏在应用中的深层次安全问题

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/vigolium/vigolium - 融合 Agentic AI 与原生速度、模块化和精准度的高保真漏洞扫描器

GitHub language count GitHub last commit GitHub stars GitHub

AI应用安全审计

  • https://github.com/leondz/garak - 用于监测大模型数据泄露、提示注入、错误信息、投毒、越狱和许多其他风险的扫描工具

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/protectai/rebuff - 保护 AI 应用程序免受即时注入 (PI) 攻击

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/mnns/LLMFuzzer - 大模型模糊测试框架

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/Tencent/AI-Infra-Guard - AI红队平台,集成了AI基础设施漏洞扫描、MCP Server风险检测、LLM安全评估等功能

GitHub language count GitHub last commit GitHub stars GitHub

AI Agent运行时管控

  • https://github.com/agentkitai/agentgate - AI Agent 行为审批工作流引擎——通过策略自动放行安全操作、拦截危险操作,其余路由给人工通过 Dashboard、Slack、Discord 或 Email 审批

GitHub language count GitHub last commit GitHub stars GitHub

Agent技能安全审计

  • https://github.com/NVIDIA/SkillSpector - AI Agent 技能安全扫描器——在安装 Agent 技能(Claude Code、Codex CLI、Gemini CLI 等)之前检测漏洞、恶意模式与安全风险

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/cisco-ai-defense/skill-scanner - AI Agent 技能安全扫描器(尽力而为)——检测提示注入、数据泄露和恶意代码模式,结合模式匹配(YAML+YARA)、LLM 评审与行为数据流分析。支持 OpenAI Codex Skills、Cursor Agent Skills 及 Claude Code 命令格式。

GitHub language count GitHub last commit GitHub stars GitHub

自主漏洞发现与修复技能

  • https://github.com/anthropics/defending-code-reference-harness - 威胁建模、扫描、分类、修复一体化技能集,提供可自定义的自主扫描框架,实现端到端漏洞生命周期管理

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/cloudflare/security-audit-skill - 多阶段安全审计的编码 Agent 技能——侦察、狩猎、对抗性验证、报告生成、结构化输出与独立验证,产出机器可读的发现报告

GitHub language count GitHub last commit GitHub stars GitHub

智能合约漏洞扫描器

  • https://github.com/ConsenSys/mythril - EVM字节码审计工具,使用符号执行、污点分析来检测以太坊、Hedera等区块链的安全漏洞

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/enzymefinance/oyente - EVM字节码审计工具,用于检测智能合约中的安全漏洞

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/eth-sri/securify2 - 由以太坊官方组织认证的智能合约安全扫描工具

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/smartdec/smartcheck - 针对Solidity程序的静态代码分析工具

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/ivicanikolicsg/MAIAN - 用于在以太坊智能合约中查找漏洞的工具

GitHub language count GitHub last commit GitHub stars GitHub

红蓝对抗

软件供应链分析

  • https://github.com/murphysecurity/murphysec - 软件供应链攻击分析工具

GitHub language count GitHub last commit GitHub stars GitHub

容器和集群

  • https://github.com/cdk-team/CDK - 容器/集群信息收集工具及漏洞利用工具

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/cr0hn/dockerscan - Docker容器集群安全评估及利用工具

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/armosec/kubescape - 第一款用于测试k8s是否按照NSA和CISA的Kubernetes安全指南部署的工具

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/chaitin/veinmind-tools - 容器安全扫描工具,针对弱口令、恶意文件、后门、敏感信息等问题

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/deepfence/ThreatMapper - 云原生(k8s/AWS/GKE等)漏洞扫描和攻击面枚举

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/deepfence/SecretScanner - 扫描容器和主机文件系统以检测未受保护的密钥、API令牌和密码

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/cyberark/KubiScan - k8s集群错误权限配置扫描检查工具

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/kvesta/vesta - 集容器扫描,Docker和Kubernetes配置基线检查于一身的工具

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/anchore/grype - 针对容器镜像和文件系统的漏洞扫描器

GitHub language count GitHub last commit GitHub stars GitHub

服务指纹探测

  • https://github.com/EdgeSecurityTeam/EHole - 红队重点攻击系统指纹探测工具

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/opabravo/mass-bruter - 红队端口协议和默认口令探测工具

GitHub language count GitHub last commit GitHub stars GitHub

中间人劫持

  • https://github.com/niloofarkheirkhah/nili - 网络扫描,中间人攻击,协议检测与逆向

GitHub language count GitHub last commit GitHub stars GitHub

框架类

  • https://github.com/m4n3dw0lf/PytheM - 支持ARP欺骗、中间人攻击等多种攻击的网络渗透测试套件

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/FunnyWolf/Viper - 图形化、武器化以及模块化的内网渗透工具

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/P1-Team/AlliN - 多用于渗透前资产收集和渗透后内网横向渗透

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/k8gege/LadonGo - 适用于Windows/Linux/Mac内网环境的渗透工具

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/shmilylty/netspy - 快速探测内网可达网段工具

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/byt3bl33d3r/CrackMapExec - 针对windows-AD域的后渗透的工具

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/u21h2/nacs - 事件驱动的内网渗透测试扫描器

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/h4wkst3r/SCMKit - 针对GitHub Enterprise, GitLab Enterprise and Bitbucket Server的源代码平台攻击工具

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/lijiejie/MisConfig_HTTP_Proxy_Scanner - 用于扫描企业错误配置的直通内网的反向代理服务器和错误配置的正向代理服务器

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/chainreactors/gogo - 面向红队的, 高度可控可拓展的自动化引擎

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/freelabz/secator - 一款方便渗透测试的工具,集成了数十种知名的安全工具

GitHub language count GitHub last commit GitHub stars GitHub

无线网络渗透

  • https://github.com/savio-code/fern-wifi-cracker - 无线安全审计工具

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/P0cL4bs/WiFi-Pumpkin - 无线安全渗透测试套件

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/MisterBianco/BoopSuite - 无线网络审计工具,支持2-5GHZ频段

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/besimaltnok/PiFinger - 检查WIFI是否是"大菠萝"所开放的热点,并给予网络评分

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/derv82/wifite2 - 自动化无线网络攻击工具Wifite的重构版本

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/D3Ext/WEF - 支持2.4GHz以及5GHz的WI-FI攻击框架

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/pinecone-wifi/pinecone - 红队WLAN渗透框架

GitHub language count GitHub last commit GitHub stars GitHub

移动应用包文件分析

  • https://github.com/dwisiswant0/apkleaks - 扫描APK文件中的URL、接口与密钥泄露等风险

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/kelvinBen/AppInfoScanner - APK文件信息搜集工具,支持自定义规则

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/maaaaz/androwarn - 安卓应用静态代码扫描工具

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/quark-engine/quark-engine - 安卓恶意分析扫描工具

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/droidefense/engine - 高级安卓木马病毒分析框架

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/abhi-r3v0/Adhrit - 安卓安全套件,基于Ghera benchmarks进行静态字节码分析

GitHub language count GitHub last commit GitHub stars GitHub BlackHatUSA-arsenal-2022

  • https://github.com/pascal-lab/Tai-e - “易学易用” 同时 “性能出色” 的通用型Java静态分析框架,比较适用于安卓代码分析

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/Cyber-Buddy/APKHunt - 基于OWASP MASVS框架的Android应用静态代码分析工具

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/cryptax/droidlysis - Android 应用程序的预分析工具:用于通常在逆向工程开始时执行的重复且无聊的任务

GitHub language count GitHub last commit GitHub stars GitHub

二进制可执行文件分析

  • https://github.com/m4rco-/dorothy2 - 一款木马、僵尸网络分析框架

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/Tencent/HaboMalHunter - 哈勃分析系统,Linux系统病毒分析及安全检测

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/KeenSecurityLab/BinAbsInspector - 科恩出品,用于自动逆向工程和二进制文件漏洞扫描

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/fkie-cad/cwe_checker - 二进制文件常见漏洞扫描(CWEs)

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/airbus-seclab/bincat - 基于污点分析的二进制代码静态分析器,可作为IDA插件使用

GitHub language count GitHub last commit GitHub stars GitHub

隐私合规

  • https://github.com/riskscanner/riskscanner - RiskScanner 是开源的多云安全合规扫描平台,通过 Cloud Custodian 的 YAML DSL 定义扫描规则

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/momosecurity/bombus - 企业安全与隐私合规审计平台

GitHub language count GitHub last commit GitHub stars GitHub

子域名爆破枚举或接管

  • https://github.com/lijiejie/subDomainsBrute - Lijiejie开发的一款使用广泛的子域名爆破枚举工具

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/ring04h/wydomain - 猪猪侠开发的一款域名收集全面、精准的子域名枚举工具

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/le4f/dnsmaper - 子域名枚举爆破工具以及地图位置标记

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/TheRook/subbrute - 高效精准的子域名爆破工具,同时也是扫描器中最常用的子域名API库

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/We5ter/GSDF - 基于谷歌SSL透明证书的子域名查询脚本

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/mandatoryprogrammer/cloudflare_enum - 使用CloudFlare进行子域名枚举的脚本

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/guelfoweb/knock - Knock子域名获取,可用于查找子域名接管漏洞

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/exp-db/PythonPool/tree/master/Tools/DomainSeeker - 多方式收集目标子域名信息

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/code-scan/BroDomain - 兄弟域名查询

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/chuhades/dnsbrute - 高效的子域名爆破工具

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/yanxiu0614/subdomain3 - 一款便捷高效的子域名爆破工具

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/michenriksen/aquatone - 子域名枚举、探测工具。可用于子域名接管漏洞探测

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/evilsocket/dnssearch - 一款子域名爆破工具

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/reconned/domained - 可用于子域名收集的一款工具

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/bit4woo/Teemo - 域名邮箱等信息收集及枚举工具

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/laramies/theHarvester - 邮箱、服务器信息收集及子域名枚举工具

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/nmalcolm/Inventus - 通过爬虫实现的子域名收集工具

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/aboul3la/Sublist3r - 强大的快速子域枚举工具

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/jonluca/Anubis - 子域名枚举及信息搜集工具

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/n4xh4ck5/N4xD0rk - 子域名查询工具

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/infosec-au/altdns - 通过字符串组合排列的高效子域名爆破工具

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/FeeiCN/ESD - 基于AsyncIO协程以及非重复字典的子域名爆破工具

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/UnaPibaGeek/ctfr - 通过域名透明证书记录获取子域名

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/giovanifss/Dumb - 灵活扩展的子域名爆破工具

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/OWASP/Amass - Go语言攻击面与域名资产发现

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/Ice3man543/subfinder - 继承于Sublist3r项目的模块化体系结构,一个强劲的子域名枚举工具

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/Ice3man543/SubOver - 一款精准的子域名结构检测工具

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/janniskirschner/horn3t - 带有网页截图功能的子可视化域名枚举工具

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/yunxu1/dnsub - 基于Go语言的高并发和跨平台子域名扫描工具

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/shmilylty/OneForAll - 集成了多款子域名扫描工具的终极版子域名扫描器

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/knownsec/ksubdomain - 一款跨平台且无状态子域名爆破工具,Mac和Windows上理论最大发包速度在30w/s,linux上为160w/s

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/gwen001/github-subdomains - 在Github上搜索目标子域名

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/bit4woo/domain_hunter_pro - 目标管理、自动化的信息收集、与burp无缝衔接

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/m4ll0k/takeover - 子域名劫持扫描器

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/v4d1/Dome - 主动与被动扫描相结合的子域名扫描,也支持开放端口检测

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/cramppet/regulator - 通过自学习正则表达式在被动DNS中获得子域名

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/hadriansecurity/subwiz - 轻量级 GPT 模型,用于发现子域名

GitHub language count GitHub last commit GitHub stars GitHub

数据库注入漏洞或认证爆破

  • https://github.com/0xbug/SQLiScanner - 一款基于SQLMAP和Charles的被动SQL注入漏洞扫描工具

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/stamparm/DSSS - 99行代码实现的sql注入漏洞扫描器

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/youngyangyang04/NoSQLAttack - 一款针对mongoDB的攻击工具

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/Neohapsis/bbqsql - SQL盲注利用框架

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/NetSPI/PowerUpSQL - 攻击SQLSERVER的Powershell脚本框架

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/WhitewidowScanner/whitewidow - 一款数据库扫描器

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/stampery/mongoaudit - MongoDB审计及渗透工具

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/torque59/Nosql-Exploitation-Framework - NoSQL扫描、爆破工具

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/missDronio/blindy - MySQL盲注爆破工具

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/fengxuangit/Fox-scan - 基于SQLMAP的主动和被动资源发现的漏洞扫描工具

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/JohnTroony/Blisqy - 用于http header中的时间盲注爆破工具,仅针对MySQL/MariaDB

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/ron190/jsql-injection - Java 编写的SQL注入工具

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/Hadesy2k/sqliv - 基于搜索引擎的批量SQL注入漏洞扫描器

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/s0md3v/sqlmate - 在SQLMAP基础上变SQLMAP得更加易用和便捷

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/m8r0wn/enumdb - MySQL以及MSSQL爆破脱裤工具

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/tariqhawis/injectbot - 一个基于Web的SQL注入扫描程序和漏洞利用工具

GitHub language count GitHub last commit GitHub stars GitHub

网站弱用户名或弱口令枚举爆破

  • https://github.com/lijiejie/htpwdScan - 一个简单的HTTP暴力破解、撞库攻击脚本

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/netxfly/crack_ssh - Go写的协程版的SSH、Redis、mongoDB弱口令破解工具

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/shengqi158/weak_password_detect - 多线程探测弱口令

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/s0md3v/Blazy - 支持测试 CSRF, Clickjacking, Cloudflare 和 WAF识别的弱口令探测器

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/MooseDojo/myBFF - 对CiscoVPN、Citrix Gateway等各类服务进行弱口令检测的脚本

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/TideSec/web_pwd_common_crack - 一款通用的web弱口令破解脚本,可批量检测没有验证码的管理后台。

GitHub language count GitHub last commit GitHub stars GitHub

IoT设备审计

  • https://github.com/rapid7/IoTSeeker - 物联网设备默认密码扫描检测工具

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/shodan-labs/iotdb - 使用nmap扫描IoT设备

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/googleinurl/RouterHunterBR - 路由器设备漏洞扫描利用

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/scu-igroup/telnet-scanner - Telnet服务密码撞库

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/viraintel/OWASP-Nettacker - 自动化信息搜集及渗透测试工具,比较适用于IoT扫描

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/threat9/routersploit - 嵌入式设备漏洞扫描及利用工具

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/w3h/icsmaster/tree/master/nse - 数字化工控设备认证爆破工具

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/firmianay/firmeye - IDA 插件,基于敏感函数参数回溯来辅助漏洞挖掘

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/bahaabdelwahed/st - 用于审查和检测 IoT(物联网)设备使用的复杂协议中的威胁

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/vulmon/Vulmap - Linux以及Windows服务器本地漏洞扫描

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/0x4D31/salt-scanner - 基于Salt Open以及Vulners Linux Audit API的linux漏洞扫描器,支持与JIRA、slack平台结合使用

GitHub language count GitHub last commit GitHub stars GitHub

多类型跨站脚本漏洞检测

  • https://github.com/0x584A/fuzzXssPHP - PHP版本的反射型XSS扫描

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/chuhades/xss_scan - 批量扫描XSS的Python脚本

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/BlackHole1/autoFindXssAndCsrf - 自动化检测页面是否存在XSS和CSRF漏洞的浏览器插件

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/shogunlab/shuriken - 使用命令行进行XSS批量检测

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/s0md3v/XSStrike - 可识别并绕过WAF的XSS扫描工具

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/stamparm/DSXS - 支持GET、POST方式的高效XSS扫描器

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/fcavallarin/domdig - 基于Chrome headless的DOM-XSS扫描器

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/lwzSoviet/NoXss - 基于Phantomjs的DOM-XSS和反射型XSS扫描器

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/pwn0sec/PwnXSS - 基于Python 3.7的多线程XSS扫描器

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/hahwul/dalfox - 基于golang的参数分析和XSS扫描工具

GitHub language count GitHub last commit GitHub stars GitHub

企业敏感信息泄露检测

  • https://github.com/x0day/Multisearch-v2 - Bing、Google、360、Zoomeye等搜索引擎聚合搜索,可用于发现企业被搜索引擎收录的敏感资产信息

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/Ekultek/Zeus-Scanner - 集成化的综合搜索引擎,能够抓取被搜索引擎隐藏的url,并交由sqlmap、nmap扫描

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/metac0rtex/GitHarvester - Github repos信息搜集工具

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/repoog/GitPrey - GitHub敏感信息扫描工具

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/0xbug/Hawkeye - 企业资产、敏感信息GitHub泄露监控系统

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/UnkL4b/GitMiner - Github敏感信息搜索工具

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/dxa4481/truffleHog - GitHub敏感信息扫描工具,包括检测commit等

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/1N3/Goohak - 自动化对指定域名进行Google hacking搜索并收集信息

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/UKHomeOffice/repo-security-scanner - 用于搜索git commit中的敏感信息,例如密码、私钥等的客户端工具

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/FeeiCN/GSIL - Github敏感信息泄露扫描

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/MiSecurity/x-patrol - Github泄露检测巡航工具

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/anshumanbh/git-all-secrets - 集合多个开源GitHub敏感信息扫描的企业信息泄露巡航工具

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/VKSRC/Github-Monitor - 由vipkid SRC开发的Github信息泄漏监控系统

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/eth0izzle/shhgit - 基于Docker和Web的Github敏感信息泄漏监控系统

GitHub language count GitHub last commit GitHub stars GitHub

  • https://github.com/SAP/credential-digger - 基于机器学习去除误报的Github敏感信息泄漏扫描系统

Read more

下载工具