
AWSome-Pentesting
我的 AWS 基础设施渗透测试速查笔记

我的 AWS 基础设施渗透测试速查笔记

设计、测试和发布 API 时最重要的安全对策清单

🌴Linux、macOS、Windows Kernel privilege escalation vulnerability collection, with compilation environment, demo GIF map, vulnerability details,…

Here Are Some Bug Bounty Resource From Twitter

本仓库包含我为针对利用云服务提供商的组织进行渗透测试的相关工具整理的一系列速查表。

This repository is for Indicators of Compromise (IOCs) from Zscaler ThreatLabz public reports

来自 JPCERT/CC 的已确认钓鱼 URL 精选数据集,包括确认日期、完整 URL 和被仿冒品牌,用于威胁情报和钓鱼检测。

一份很棒的渗透测试工具和资源列表。

A collection of real-world threat model examples across various technologies, providing practical insights into identifying and mitigating security…

面向恶意文件检测与分类的精选签名规则集,通过模式匹配实现,并附带用于扫描文件和目录的CLI使用说明。

这些是不同类型的下载载体(download cradle),可以作为灵感来试验和创建新的下载载体,从而在下载载体检测的背景下绕过 AV/EPP/EDR。

每日 YARA 规则挑战与社区合集,恶意软件分析师在此分享检测模式、技巧及非常规 YARA 用法,以提升检测工程技能。

精选的进攻性安全会议幻灯片合集,涵盖内核与移动端漏洞利用、虚拟机/容器逃逸,以及模糊测试/漏洞研究。

Red Teaming & Pentesting checklists for various engagements

A list of cyber-chef recipes and curated links

This OSINT Notebook provides an overview of the tools, techniques, and resources that I use for a variety of situations when it comes to performing…

Twitter vulnerable snippets