-
[34521星][14d] [C++] x64dbg/x64dbg Windows平台x32/x64调试器
-
[33781星][8d] [Py] minimaxir/big-list-of-naughty-strings “淘气”的字符串列表,当作为用户输入时很容易引发问题
-
[32724星][2m] hack-with-github/awesome-hacking A collection of various awesome lists for hackers, pentesters and security researchers
-
[30396星][12d] [Go] fatedier/frp 快速的反向代理, 将NAT或防火墙之后的本地服务器暴露到公网
-
[25942星][7d] [Py] certbot/certbot Certbot is EFF's tool to obtain certs from Let's Encrypt and (optionally) auto-enable HTTPS on your server. It can also act as a client for any other CA that uses the ACME protocol.
-
[25522星][26d] [Swift] shadowsocks/shadowsocksx-ng Next Generation of ShadowsocksX
-
[25087星][13d] [Go] v2ray/v2ray-core A platform for building proxies to bypass network restrictions.
-
[24589星][7d] trimstray/the-book-of-secret-knowledge A collection of inspiring lists, manuals, cheatsheets, blogs, hacks, one-liners, cli/web tools and more.
-
[22517星][12d] [Shell] mathiasbynens/dotfiles
-
[21751星][7d] [PHP] danielmiessler/seclists 多种类型资源收集:用户名、密码、URL、敏感数据类型、Fuzzing Payload、WebShell等
-
[21668星][10d] [Go] filosottile/mkcert A simple zero-config tool to make locally trusted development certificates with any names you'd like.
-
[20619星][9d] [Java] skylot/jadx dex 转 java 的反编译器
-
[20089星][2m] [Shell] streisandeffect/streisand Streisand sets up a new server running your choice of WireGuard, OpenConnect, OpenSSH, OpenVPN, Shadowsocks, sslh, Stunnel, or a Tor bridge. It also generates custom instructions for all of these services. At the end of the run you are given an HTML file with instructions that can be shared with friends, family members, and fellow activists.
-
[19651星][2m] [Jupyter Notebook] camdavidsonpilon/probabilistic-programming-and-bayesian-methods-for-hackers aka "Bayesian Methods for Hackers": An introduction to Bayesian methods + probabilistic programming with a computation/understanding-first, mathematics-second point of view. All in pure Python ;)
-
[18996星][7d] [Ruby] rapid7/metasploit-framework Metasploit Framework
-
[18648星][3y] fallibleinc/security-guide-for-developers Security Guide for Developers (实用性开发人员安全须知)
-
[18381星][7d] [Java] nationalsecurityagency/ghidra 软件逆向框架
-
[18220星][8d] [Java] alibaba/arthas Alibaba Java诊断利器Arthas
-
[17555星][4y] [Go] inconshreveable/ngrok 反向代理,在公网终端和本地服务之间创建安全的隧道
-
[16951星][14d] [Py] mitmproxy/mitmproxy An interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers.
-
[16681星][7d] [C#] powershell/powershell PowerShell for every system!
-
[15756星][8d] [Py] sqlmapproject/sqlmap Automatic SQL injection and database takeover tool
-
[15694星][9m] micropoor/micro8 从业10年渗透笔记
-
[15627星][7d] [C] curl/curl A command line tool and library for transferring data with URL syntax, supporting HTTP, HTTPS, FTP, FTPS, GOPHER, TFTP, SCP, SFTP, SMB, TELNET, DICT, LDAP, LDAPS, FILE, IMAP, SMTP, POP3, RTSP and RTMP. libcurl offers a myriad of powerful features
-
[14661星][1m] gfwlist/gfwlist gfwlist
-
[14478星][26d] [Java] tencent/tinker Tinker is a hot-fix solution library for Android, it supports dex, library and resources update without reinstall apk.
-
[13627星][9m] [JS] bannedbook/fanqiang 翻墙-科学上网
-
[13183星][26d] [Py] corentinj/real-time-voice-cloning Clone a voice in 5 seconds to generate arbitrary speech in real-time
-
[13081星][17d] [Go] jesseduffield/lazydocker The lazier way to manage everything docker
-
[12920星][10d] [Py] cool-rr/pysnooper Never use print for debugging again
-
[12641星][9d] [C] shadowsocks/shadowsocks-libev libev port of shadowsocks
-
[12453星][7d] [C#] 0xd4d/dnspy .NET debugger and assembly editor
-
[12203星][14d] [Java] signalapp/signal-android A private messenger for Android.
-
[11935星][1m] [Go] buger/goreplay 实时捕获HTTP流量并输入测试环境,以便持续使用真实数据测试你的系统
-
[11829星][17d] [C] openssl/openssl TLS/SSL and crypto library
-
[11490星][7d] [C] radareorg/radare2 unix-like reverse engineering framework and commandline tools
-
[11361星][3m] [C] robertdavidgraham/masscan masscan:世界上最快的互联网端口扫描器,号称可6分钟内扫描整个互联网
-
[11246星][1m] facert/awesome-spider 爬虫集合
-
[11225星][13d] getlantern/download Lantern官方版本下载 蓝灯 翻墙 科学上网 外网 加速器 梯子 路由
-
[11174星][7d] [Java] oracle/graal Run Programs Faster Anywhere
-
[11106星][2m] [Jupyter Notebook] selfteaching/the-craft-of-selfteaching One has no future if one couldn't teach themself.
-
[11047星][7d] [Py] swisskyrepo/payloadsallthethings A list of useful payloads and bypass for Web Application Security and Pentest/CTF
-
[11013星][2y] [Objective-C] bang590/jspatch JSPatch bridge Objective-C and Javascript using the Objective-C runtime. You can call any Objective-C class and method in JavaScript by just including a small engine. JSPatch is generally used to hotfix iOS App.
-
[11008星][8d] [Py] owasp/cheatsheetseries The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.
-
[10902星][12d] [Objective-C] flipboard/flex An in-app debugging and exploration tool for iOS
-
[10886星][2m] [CSS] hacker0x01/hacker101 Hacker101
-
[10761星][2y] [CoffeeScript] dropbox/zxcvbn Low-Budget Password Strength Estimation
-
[10742星][13d] enaqx/awesome-pentest 渗透测试资源/工具集
-
[10738星][17d] [Java] konloch/bytecode-viewer A Java 8+ Jar & Android APK Reverse Engineering Suite (Decompiler, Editor, Debugger & More)
-
[10107星][8d] [Go] goharbor/harbor An open source trusted cloud native registry project that stores, signs, and scans content.
-
[9844星][11d] ruanyf/weekly 科技爱好者周刊,每周五发布
-
[9804星][8m] imthenachoman/how-to-secure-a-linux-server An evolving how-to guide for securing a Linux server.
-
[9349星][12d] [Ruby] postalhq/postal 全功能邮件服务器
-
[9229星][3m] [JS] localtunnel/localtunnel expose yourself
-
[9182星][8d] [Go] cnlh/nps 一款轻量级、功能强大的内网穿透代理服务器。支持tcp、udp流量转发,支持内网http代理、内网socks5代理,同时支持snappy压缩、站点保护、加密传输、多路复用、header修改等。支持web图形化管理,集成多用户模式。
-
[9178星][10d] [Java] ibotpeaches/apktool A tool for reverse engineering Android apk files
-
[9141星][8d] [C#] icsharpcode/ilspy .NET Decompiler
-
[9064星][27d] [JS] valve/fingerprintjs2 Modern & flexible browser fingerprinting library
-
[9003星][9d] [PowerShell] lukesampson/scoop A command-line installer for Windows.
-
[8995星][2m] vitalysim/awesome-hacking-resources A collection of hacking / penetration testing resources to make you better!
-
[8988星][9d] [Py] sherlock-project/sherlock Find Usernames Across Social Networks
-
[8847星][6m] [Go] rkt/rkt rkt is a pod-native container engine for Linux. It is composable, secure, and built on standards.
-
[8712星][15d] [C] gentilkiwi/mimikatz A little tool to play with Windows security
-
[8597星][26d] [Java] android-hacker/virtualxposed A simple app to use Xposed without root, unlock the bootloader or modify system image, etc.
-
[8495星][1m] microsoft/wsl Issues found on WSL
-
[8408星][2y] brannondorsey/wifi-cracking 破解WPA/WPA2 Wi-Fi 路由器
-
[8399星][27d] [Py] wifiphisher/wifiphisher 流氓AP框架, 用于RedTeam和Wi-Fi安全测试
-
[8033星][7d] trimstray/the-practical-linux-hardening-guide This guide details creating a secure Linux production system. OpenSCAP (C2S/CIS, STIG).
-
[7992星][2m] [Py] facebook/chisel Chisel is a collection of LLDB commands to assist debugging iOS apps.
-
[7952星][3y] [Go] cyfdecyf/cow HTTP proxy written in Go. COW can automatically identify blocked sites and use parent proxies to access.
-
[7936星][4y] [Objective-C] shadowsocks/shadowsocks-ios Removed according to regulations.
-
[7806星][3m] [C++] shiqiyu/libfacedetection An open source library for face detection in images. The face detection speed can reach 1500FPS.
-
[7696星][7d] [JS] gchq/cyberchef The Cyber Swiss Army Knife - a web app for encryption, encoding, compression and data analysis
-
[7685星][7d] [Go] git-lfs/git-lfs Git extension for versioning large files
-
[7628星][22d] [Java] java-decompiler/jd-gui A standalone Java Decompiler GUI
-
[7498星][27d] [Py] threat9/routersploit Exploitation Framework for Embedded Devices
-
[7371星][12d] [Go] snail007/goproxy Proxy是高性能全功能的http代理、https代理、socks5代理、内网穿透、内网穿透p2p、内网穿透代理、内网穿透反向代理、内网穿透服务器、Websocket代理、TCP代理、UDP代理、DNS代理、DNS加密代理,代理API认证,全能跨平台代理服务器。
-
[7365星][1m] [Py] s0md3v/xsstrike Most advanced XSS scanner.
-
[7205星][17d] [Java] lionsoul2014/ip2region Ip2region is a offline IP location library with accuracy rate of 99.9% and 0.0x millseconds searching performance. DB file is less then 5Mb with all ip address stored. binding for Java,PHP,C,Python,Nodejs,Golang,C#,lua. Binary,B-tree,Memory searching algorithm
-
[7174星][7m] [Shell] teddysun/shadowsocks_install Auto Install Shadowsocks Server for CentOS/Debian/Ubuntu
-
[6994星][14d] [Go] future-architect/vuls 针对Linux/FreeBSD 编写的漏洞扫描器. Go 语言编写
-
[6968星][2m] [JS] cs01/gdbgui Browser-based frontend to gdb (gnu debugger). Add breakpoints, view the stack, visualize data structures, and more in C, C++, Go, Rust, and Fortran. Run gdbgui from the terminal and a new tab will open in your browser.
-
[6956星][10d] [C] hashcat/hashcat 世界上最快最先进的密码恢复工具
-
[6954星][13d] [Go] nats-io/nats-server High-Performance server for NATS, the cloud native messaging system.
-
[6950星][9d] greatfire/wiki 自由浏览
-
[6917星][3m] [Java] pxb1988/dex2jar Tools to work with android .dex and java .class files
-
[6844星][2m] [Go] sqshq/sampler A tool for shell commands execution, visualization and alerting. Configured with a simple YAML file.
-
[6788星][17d] [Shell] awslabs/git-secrets Prevents you from committing secrets and credentials into git repositories
-
[6708星][9m] [Java] amitshekhariitbhu/android-debug-database A library for debugging android databases and shared preferences - Make Debugging Great Again
-
[6678星][3y] [C++] alibaba/andfix AndFix is a library that offer hot-fix for Android App.
-
[6639星][9d] [Java] zaproxy/zaproxy 在开发和测试Web App时自动发现安全漏洞
-
[6557星][11d] [Py] networkx/networkx 用于创建、操纵和研究复杂网络的结构,Python包
-
[6455星][1m] [Py] h2y/shadowrocket-adblock-rules 提供多款 Shadowrocket 规则,带广告过滤功能。用于 iOS 未越狱设备选择性地自动翻墙。
-
[6449星][11d] [Shell] cisofy/lynis Security auditing tool for Linux, macOS, and UNIX-based systems. Assists with compliance testing (HIPAA/ISO27001/PCI DSS) and system hardening. Agentless, and installation optional.
-
[6440星][9m] [HTML] open-power-workgroup/hospital OpenPower工作组收集汇总的医院开放数据
-
[6413星][15d] [Go] bettercap/bettercap 新版的bettercap, Go 编写. bettercap 是强大的、模块化、可移植且易于扩展的 MITM 框架, 旧版用 Ruby 编写
-
[6284星][27d] [Py] seatgeek/fuzzywuzzy Fuzzy String Matching in Python
-
[6182星][2m] [Py] yandex/gixy Nginx 配置静态分析工具,防止配置错误导致安全问题,自动化错误配置检测
-
[6170星][6m] rmerl/asuswrt-merlin Enhanced version of Asus's router firmware (Asuswrt) (legacy code base)
-
[6158星][3y] [PowerShell] powershellmafia/powersploit PowerSploit - A PowerShell Post-Exploitation Framework
-
[6130星][1y] [Hack] facebook/fbctf Platform to host Capture the Flag competitions
-
[6124星][9m] [Py] schollz/howmanypeoplearearound 检测 Wifi 信号统计你周围的人数
-
[6100星][7d] [JS] avwo/whistle 基于Node实现的跨平台抓包调试代理工具(HTTP, HTTP2, HTTPS, Websocket)
-
[6061星][2y] [C] jgamblin/mirai-source-code Leaked Mirai Source Code for Research/IoC Development Purposes
-
[6025星][14d] [Go] quay/clair Vulnerability Static Analysis for Containers
-
[6025星][14d] [Go] quay/clair clair:容器(appc、docker)漏洞静态分析工具。
-
[6002星][11d] [Py] cyrus-and/gdb-dashboard Modular visual interface for GDB in Python
-
[5996星][20d] berzerk0/probable-wordlists Version 2 is live! Wordlists sorted by probability originally created for password generation and testing - make sure your passwords aren't popular!
-
[5948星][2m] [Java] google/android-classyshark 分析基于Android/Java的App或游戏
-
[5935星][29d] [Py] gallopsled/pwntools CTF framework and exploit development library
-
[5870星][6m] [JS] haotian-wang/google-access-helper 谷歌访问助手破解版
-
[5850星][8d] [C++] radareorg/cutter 逆向框架 radare2的Qt界面,iaito的升级版
-
[5845星][2m] [Gnuplot] nasa-jpl/open-source-rover A build-it-yourself, 6-wheel rover based on the rovers on Mars!
-
[5811星][7m] [JS] sindresorhus/fkill-cli Fabulously kill processes. Cross-platform.
-
[5764星][3m] [Objective-C] square/ponydebugger Remote network and data debugging for your native iOS app using Chrome Developer Tools
-
[5738星][1y] qinyuhang/shadowsocksx-ng-r Next Generation of ShadowsocksX
-
[5738星][2y] [Py] newsapps/beeswithmachineguns 创建多个micro EC2实例, 攻击指定Web App
-
[5719星][2m] [C] spacehuhn/esp8266_deauther 使用ESP8266 制作Wifi干扰器
-
[5715星][8m] [C] xoreaxeaxeax/movfuscator C编译器,编译的二进制文件只有1个代码块。
-
[5674星][22d] [JS] swagger-api/swagger-editor Swagger Editor
-
[5653星][16d] [Go] casbin/casbin An authorization library that supports access control models like ACL, RBAC, ABAC in Golang
-
[5605星][1m] [C] rofl0r/proxychains-ng proxychains ng (new generation) - a preloader which hooks calls to sockets in dynamically linked programs and redirects it through one or more socks/http proxies. continuation of the unmaintained proxychains project. the sf.net page is currently not updated, use releases from github release page instead.
-
[5578星][8d] [Ruby] presidentbeef/brakeman ROR程序的静态分析工具
-
[5521星][18d] rshipp/awesome-malware-analysis A curated list of awesome malware analysis tools and resources.
-
[5517星][27d] [Roff] max2max/freess 免费ss账号 免费shadowsocks账号 免费v2ray账号 (长期更新)
-
[5456星][8m] carpedm20/awesome-hacking Hacking教程、工具和资源
-
[5417星][2y] [Rust] autumnai/leaf Open Machine Intelligence Framework for Hackers. (GPU/CPU)
-
[5392星][2m] [Py] axi0mx/ipwndfu open-source jailbreaking tool for many iOS devices
-
[5353星][5m] [C] pwn20wndstuff/undecimus unc0ver jailbreak for iOS 11.0 - 12.4
-
[5317星][7d] [Py] mlflow/mlflow Open source platform for the machine learning lifecycle
-
[5307星][9d] [Go] zricethezav/gitleaks Audit git repos for secrets
-
[5207星][7m] [Py] usarmyresearchlab/dshell 网络审计分析
-
[5165星][1m] [Py] refirmlabs/binwalk 固件分析工具(命令行+IDA插件)
-
[5165星][1y] [JS] samyk/poisontap Exploits locked/password protected computers over USB, drops persistent WebSocket-based backdoor, exposes internal router, and siphons cookies using Raspberry Pi Zero & Node.js.
-
[5163星][3m] [Py] ytisf/thezoo A repository of LIVE malwares for your own joy and pleasure. theZoo is a project created to make the possibility of malware analysis open and available to the public.
-
[5121星][13d] [PHP] tennc/webshell webshell收集
-
[5111星][18d] [Shell] vulhub/vulhub Pre-Built Vulnerable Environments Based on Docker-Compose
-
[5096星][4m] [Py] n1nj4sec/pupy Pupy is an opensource, cross-platform (Windows, Linux, OSX, Android) remote administration and post-exploitation tool mainly written in python
-
[5092星][19d] [C++] avast/retdec 基于 LLVM 的可重定位机器码反编译器, 可检测壳、检测和重构C++类继承、重构函数/类型/结构体等、可反编译为 C 或 Python 2种高级语言格式
-
[5067星][2m] sbilly/awesome-security 与安全相关的软件、库、文档、书籍、资源和工具等收集
-
[5054星][2m] [Shell] stackexchange/blackbox 文件使用PGP加密后隐藏在Git/Mercurial/Subversion
-
[5036星][8d] [Go] dnscrypt/dnscrypt-proxy 灵活的DNS代理,支持现代的加密DNS协议,例如:DNS protocols such as DNSCrypt v2, DNS-over-HTTPS and Anonymized DNSCrypt.
-
[5028星][1m] [Java] meituan-dianping/walle Android Signature V2 Scheme签名下的新一代渠道包打包神器
-
[5026星][4y] [Py] shadowsocksr-backup/shadowsocksr Python port of ShadowsocksR
-
[5023星][4m] [PowerShell] empireproject/empire 后渗透框架. Windows客户端用PowerShell, Linux/OSX用Python. 之前PowerShell Empire和Python EmPyre的组合
-
[5010星][15d] [HTML] owasp/owasp-mstg 关于移动App安全开发、测试和逆向的相近手册
-
[4990星][1m] [Py] snare/voltron A hacky debugger UI for hackers
-
[4941星][10d] [Go] inlets/inlets Expose your local endpoints to the Internet
-
[4928星][13d] [ASP] hq450/fancyss fancyss is a project providing tools to across the GFW on asuswrt/merlin based router.
-
[4924星][20d] [Py] trustedsec/social-engineer-toolkit The Social-Engineer Toolkit (SET) repository from TrustedSec - All new versions of SET will be deployed here.
-
[4909星][1y] [Go] yinghuocho/firefly-proxy A proxy software to help circumventing the Great Firewall.
-
[4892星][11m] [Go] bitly/oauth2_proxy 反向代理,静态文件服务器,提供Providers(Google/Github)认证
-
[4872星][2m] [Rust] sharkdp/hexyl 命令行中查看hex
-
[4872星][7m] [Java] guardianproject/haven 通过Android应用和设备上的传感器保护自己的个人空间和财产而又不损害
-
[4868星][9d] [Shell] denisidoro/navi An interactive cheatsheet tool for the command-line
-
[4862星][7d] [JS] mobsf/mobile-security-framework-mobsf Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis.
-
[4838星][10d] [Go] gcla/termshark A terminal UI for tshark, inspired by Wireshark
-
[4835星][8d] [Py] alessandroz/lazagne Credentials recovery project
-
[4816星][10d] [C] offensive-security/exploitdb The official Exploit Database repository
-
[4793星][8m] [Py] 10se1ucgo/disablewintracking Uses some known methods that attempt to minimize tracking in Windows 10
-
[4771星][7d] [C] google/oss-fuzz 开源软件fuzzing
-
[4752星][7d] [C++] facebook/redex Android App字节码优化器
-
[4717星][7d] [Swift] yanue/v2rayu V2rayU,基于v2ray核心的mac版客户端,用于科学上网,使用swift编写,支持vmess,shadowsocks,socks5等服务协议,支持订阅, 支持二维码,剪贴板导入,手动配置,二维码分享等
-
[4710星][8d] [C++] paddlepaddle/paddle-lite Multi-platform high performance deep learning inference engine (『飞桨』多平台高性能深度学习预测引擎)
-
[4675星][7d] [C++] coatisoftware/sourcetrail Sourcetrail - free and open-source interactive source explorer
-
[4651星][7d] [Py] manisso/fsociety fsociety Hacking Tools Pack – A Penetration Testing Framework
-
[4630星][6m] powershell/win32-openssh Win32 port of OpenSSH
-
[4627星][16d] [C] google/ios-webkit-debug-proxy A DevTools proxy (Chrome Remote Debugging Protocol) for iOS devices (Safari Remote Web Inspector).
-
[4616星][8d] [JS] beefproject/beef The Browser Exploitation Framework Project
-
[4611星][19d] [Py] secdev/scapy 交互式数据包操作, Python, 命令行+库
-
[4575星][11m] [Py] ecthros/uncaptcha2 defeating the latest version of ReCaptcha with 91% accuracy
-
[4574星][10d] [Go] ginuerzh/gost GO语言实现的安全隧道
-
[4551星][1y] [C] upx/upx UPX - the Ultimate Packer for eXecutables
-
[4549星][8d] [C++] mozilla/rr 记录与重放App的调试执行过程
-
[4526星][10d] [Ruby] wpscanteam/wpscan WPScan is a free, for non-commercial use, black box WordPress Vulnerability Scanner written for security professionals and blog maintainers to test the security of their WordPress websites.
-
[4523星][12d] [C] jedisct1/dsvpn A Dead Simple VPN.
-
[4485星][18d] [TypeScript] apis-guru/graphql-voyager
-
[4454星][1y] [Go] wallix/awless A Mighty CLI for AWS
-
[4444星][16d] [Py] jopohl/urh Universal Radio Hacker: investigate wireless protocols like a boss
-
[4426星][22d] [Py] jofpin/trape 学习在互联网上跟踪别人,获取其详细信息,并避免被别人跟踪
-
[4398星][9d] [Makefile] frida/frida Clone this repo to build Frida
-
[4387星][2m] [Shell] zardus/ctf-tools Some setup scripts for security research tools.
-
[4343星][13d] [Swift] signalapp/signal-ios A private messenger for iOS.
-
[4339星][12m] [Py] lennylxx/ipv6-hosts Fork of
-
[4310星][29d] [JS] cure53/dompurify a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify works with a secure default, but offers a lot of configurability and hooks. Demo:
-
[4307星][5m] [Py] diafygi/acme-tiny A tiny script to issue and renew TLS certs from Let's Encrypt
-
[4262星][1m] [Py] tensorflow/cleverhans Python库,基准测试(benchmark)机器学习系统的漏洞生成(to)对抗样本(adversarial examples)
-
[4261星][1m] [Shell] ashishb/android-security-awesome A collection of android security related resources
-
[4256星][11m] [JS] butterproject/butter-desktop All the free parts of Popcorn Time
-
[4243星][9d] [Rust] timvisee/ffsend Easily and securely share files from the command line
-
[4210星][4m] [Py] dxa4481/trufflehog Searches through git repositories for high entropy strings and secrets, digging deep into commit history
-
[4195星][16d] [Go] gophish/gophish 网络钓鱼工具包
-
[4195星][2m] [Py] evilsocket/opensnitch opensnitch:Little Snitch 应用程序防火墙的 GNU/Linux 版本。(Little Snitch:Mac操作系统的应用程序防火墙,能防止应用程序在你不知道的情况下自动访问网络)
-
[4190星][7m] [Objective-C] alonemonkey/monkeydev CaptainHook Tweak、Logos Tweak and Command-line Tool、Patch iOS Apps, Without Jailbreak.
-
[4186星][9d] qazbnm456/awesome-web-security web 安全资源列表
-
[4183星][1y] [Go] michenriksen/gitrob 查找push到公开的Github repo中的敏感信息
-
[4175星][11d] we5ter/scanners-box 安全行业从业者自研开源扫描器合辑
-
[4165星][2y] forter/security-101-for-saas-startups 初学者安全小窍门
-
[4148星][12m] [JS] kdzwinel/betwixt Betwixt will help you analyze web traffic outside the browser using familiar Chrome DevTools interface.
-
[4105星][5m] [Py] spiderclub/haipproxy
-
[4092星][2m] [Py] aboul3la/sublist3r Fast subdomains enumeration tool for penetration testers
-
[4091星][7d] [Java] spring-projects/spring-security Spring Security
-
[4083星][2y] [Py] xoreaxeaxeax/sandsifter sandsifter:x86 处理器 Fuzzer,查找 Intel 的隐藏指令和 CPU bug
-
[4069星][9m] wtsxdev/reverse-engineering List of awesome reverse engineering resources
-
[4039星][1m] [JS] sigalor/whatsapp-web-reveng WhatsApp Web API逆向与重新实现
-
[4033星][7d] [Py] google/clusterfuzz Scalable fuzzing infrastructure.
-
[4023星][2m] [Java] jesusfreke/smali smali/baksmali
-
[4015星][3m] [JS] cuckoosandbox/cuckoo Cuckoo Sandbox is an automated dynamic malware analysis system
-
[3989星][1y] [JS] travist/jsencrypt A Javascript library to perform OpenSSL RSA Encryption, Decryption, and Key Generation.
-
[3985星][20d] drduh/yubikey-guide Guide to using YubiKey for GPG and SSH
-
[3955星][3m] [Py] nullarray/autosploit Automated Mass Exploiter
-
[3936星][13d] [Go] dexidp/dex OpenID Connect Identity (OIDC) and OAuth 2.0 Provider with Pluggable Connectors
-
[3929星][2m] [JS] apsdehal/awesome-ctf A curated list of CTF frameworks, libraries, resources and softwares
-
[3929星][2m] [JS] apsdehal/awesome-ctf A curated list of CTF frameworks, libraries, resources and softwares
-
[3925星][4m] [PHP] paragonie/awesome-appsec A curated list of resources for learning about application security
-
[3916星][7d] [Py] angr/angr A powerful and user-friendly binary analysis platform!
-
[3908星][14d] [Rust] svenstaro/genact a nonsense activity generator
-
[3907星][1m] [C] aquynh/capstone Capstone disassembly/disassembler framework: Core (Arm, Arm64, BPF, EVM, M68K, M680X, MOS65xx, Mips, PPC, RISCV, Sparc, SystemZ, TMS320C64x, Web Assembly, X86, X86_64, XCore) + bindings.
-
[3896星][2y] [C#] shadowsocksr-backup/shadowsocksr-csharp
-
[3876星][7d] [C++] baldurk/renderdoc RenderDoc is a stand-alone graphics debugging tool.
-
[3856星][2m] [PHP] fuzzdb-project/fuzzdb 通过动态App安全测试来查找App安全漏洞, 算是不带扫描器的漏洞扫描器
-
[3841星][8m] [Go] eranyanay/1m-go-websockets handling 1M websockets connections in Go
-
[3837星][15d] [JS] shadowsocks/shadowsocks-manager A shadowsocks manager tool for multi user and traffic control.
-
[3836星][11d] [Py] secureauthcorp/impacket Python类收集, 用于与网络协议交互
-
[3832星][2m] [Objective-C] sveinbjornt/sloth Mac app that shows all open files, directories and sockets in use by all running processes. Nice GUI for lsof.
-
[3825星][4y] iosre/iosappreverseengineering The world’s 1st book of very detailed iOS App reverse engineering skills :)
-
[3781星][13d] hq450/fancyss_history_package 科学上网插件的离线安装包储存在这里
-
[3770星][30d] jivoi/awesome-osint OSINT资源收集
-
[3763星][5y] shadowsocksr-backup/shadowsocks-rss ShadowsocksR update rss, SSR organization
-
[3754星][10m] [Py] longld/peda Python Exploit Development Assistance for GDB
-
[3749星][2m] [Go] microsoft/ethr Ethr is a Network Performance Measurement Tool for TCP, UDP & HTTP.
-
[3739星][2m] [PHP] ethicalhack3r/dvwa Damn Vulnerable Web Application (DVWA)
-
[3739星][2m] [Py] paralax/awesome-honeypots an awesome list of honeypot resources
-
[3731星][1m] [C] iaik/meltdown This repository contains several applications, demonstrating the Meltdown bug.
-
[3731星][13d] [Go] hashicorp/consul-template Template rendering, notifier, and supervisor for
-
[3718星][4m] [Py] malwaredllc/byob BYOB (Build Your Own Botnet)
-
[3681星][11d] jjqqkk/chromium Chromium browser with SSL VPN. Use this browser to unblock websites.
-
[3679星][2y] [JS] samyk/evercookie JavaScript API,在浏览器中创建超级顽固的cookie,在标准Cookie、Flask Cookie等被清除之后依然能够识别客户端
-
[3675星][8d] [HTML] hamukazu/lets-get-arrested This project is intended to protest against the police in Japan
-
[3660星][1y] [Py] misterch0c/shadowbroker 方程式最新泄露
-
[3653星][4m] [C] facebook/fishhook A library that enables dynamically rebinding symbols in Mach-O binaries running on iOS.
-
[3647星][8d] [JS] lesspass/lesspass
-
[3645星][26d] [C#] 0xd4d/de4dot .NET deobfuscator and unpacker.
-
[3640星][4m] [C] secwiki/windows-kernel-exploits windows-kernel-exploits Windows平台提权漏洞集合
-
[3639星][2y] [Py] qiyeboy/ipproxypool IPProxyPool代理池项目,提供代理ip
-
[3624星][29d] acl4ssr/acl4ssr SSR 去广告ACL规则/SS完整GFWList规则,Telegram频道订阅地址
-
[3621星][2m] [C] atmosphere-nx/atmosphere Atmosphère is a work-in-progress customized firmware for the Nintendo Switch.
-
[3615星][5y] [C#] brandonlw/psychson Phison 2251-03 (2303) Custom Firmware & Existing Firmware Patches (BadUSB)
-
[3612星][17d] [HTML] consensys/smart-contract-best-practices A guide to smart contract security best practices
-
[3598星][8d] [TypeScript] javascript-obfuscator/javascript-obfuscator A powerful obfuscator for JavaScript and Node.js
-
[3597星][1y] [C#] nummer/destroy-windows-10-spying Destroy Windows Spying tool
-
[3594星][2m] [Java] ffay/lanproxy lanproxy是一个将局域网个人电脑、服务器代理到公网的内网穿透工具,支持tcp流量转发,可支持任何tcp上层协议(访问内网网站、本地支付接口调试、ssh访问、远程桌面...)。目前市面上提供类似服务的有花生壳、TeamView、GoToMyCloud等等,但要使用第三方的公网服务器就必须为第三方付费,并且这些服务都有各种各样的限制,此外,由于数据包会流经第三方,因此对数据安全也是一大隐患。技术交流QQ群 946273429
-
[3591星][3y] [Perl] x0rz/eqgrp Decrypted content of eqgrp-auction-file.tar.xz
-
[3587星][2m] [PowerShell] bloodhoundad/bloodhound a single page Javascript web application, uses graph theory to reveal the hidden and often unintended relationships within an Active Directory environment.
-
[3578星][24d] [C++] anbox/anbox 在常规GNU / Linux系统上引导完整的Android系统,基于容器
-
[3565星][7d] [Shell] drwetter/testssl.sh 检查服务器任意端口对 TLS/SSL 的支持、协议以及一些加密缺陷,命令行工具
-
[3560星][17d] [C] nmap/nmap Nmap
-
[3544星][6y] [R] johnmyleswhite/ml_for_hackers 《Machine Learning for Hackers》随书代码
-
[3538星][4m] [Shell] chengr28/revokechinacerts Revoke Chinese certificates.
-
[3525星][8d] [Pascal] cheat-engine/cheat-engine Cheat Engine. A development environment focused on modding
-
[3503星][14d] [JS] aol/moloch 数据包捕获、索引工具,支持数据库
-
[3494星][8m] [Go] fanpei91/torsniff torsniff - a sniffer that sniffs torrents from BitTorrent network
-
[3494星][8m] [Go] fanpei91/torsniff 从BitTorrent网络嗅探种子
-
[3493星][3y] [C] hak5darren/usb-rubber-ducky
-
[3482星][9m] [C] rpisec/mbe Course materials for Modern Binary Exploitation by RPISEC
-
[3481星][13d] blacckhathaceekr/pentesting-bible links reaches 10000 links & 10000 pdf files .Learn Ethical Hacking and penetration testing .hundreds of ethical hacking & penetration testing & red team & cyber security & computer science resources.
-
[3468星][5m] [PHP] hanc00l/wooyun_public This repo is archived. Thanks for wooyun! 乌云公开漏洞、知识库爬虫和搜索 crawl and search for wooyun.org public bug(vulnerability) and drops
-
[3464星][15d] [C] cyan4973/xxhash Extremely fast non-cryptographic hash algorithm
-
[3436星][7d] [C] shellphish/how2heap 学习各种堆利用技巧的repo
-
[3431星][13d] [Java] meituan-dianping/robust Robust is an Android HotFix solution with high compatibility and high stability. Robust can fix bugs immediately without a reboot.
-
[3421星][13d] [Perl] sullo/nikto Nikto web server scanner
-
[3412星][25d] icodesign/potatso Potatso is an iOS client that implements different proxies with the leverage of NetworkExtension framework in iOS 10+.
-
[3392星][5m] [Go] jpillora/chisel 基于HTTP的快速 TCP 隧道
-
[3387星][2y] shadowsocksrr/shadowsocks-rss ShadowsocksR update rss, SSR organization
-
[3383星][22d] [PowerShell] samratashok/nishang 渗透框架,脚本和Payload收集,主要是PowerShell,涵盖渗透的各个阶段
-
[3326星][13d] [Py] google/grr remote live forensics for incident response
-
[3325星][5m] [C++] wangyu-/udp2raw-tunnel udp 打洞。通过raw socket给UDP包加上TCP或ICMP header,进而绕过UDP屏蔽或QoS,或在UDP不稳定的环境下提升稳定性
-
[3325星][7d] jivoi/awesome-ml-for-cybersecurity 针对网络安全的机器学习资源列表
-
[3317星][7d] [Py] stamparm/maltrail 恶意网络流量检测系统
-
[3317星][2y] scanate/ethlist The Comprehensive Ethereum Reading List
-
[3316星][2m] [C] screetsec/thefatrat Thefatrat a massive exploiting tool : Easy tool to generate backdoor and easy tool to post exploitation attack like browser attack and etc . This tool compiles a malware with popular payload and then the compiled malware can be execute on windows, android, mac . The malware that created with this tool also have an ability to bypass most AV softw…
-
[3282星][8d] [Smarty] anankke/sspanel-uim 专为 Shadowsocks / ShadowsocksR / V2Ray 设计的多用户管理面板
-
[3280星][2m] [Swift] yagiz/bagel a little native network debugging tool for iOS
-
[3280星][20d] [C] vanhauser-thc/thc-hydra 网络登录破解,支持多种服务
-
[3269星][27d] [C] microsoft/windows-driver-samples This repo contains driver samples prepared for use with Microsoft Visual Studio and the Windows Driver Kit (WDK). It contains both Universal Windows Driver and desktop-only driver samples.
-
[3267星][3m] [C] nbs-system/naxsi NAXSI is an open-source, high performance, low rules maintenance WAF for NGINX
-
[3266星][12d] [C] virustotal/yara The pattern matching swiss knife
-
[3258星][2m] [Py] volatilityfoundation/volatility An advanced memory forensics framework
-
[3258星][5y] [C++] google/lmctfy lmctfy is the open source version of Google’s container stack, which provides Linux application containers.
-
[3255星][7d] [C] mikebrady/shairport-sync AirPlay audio player. Shairport Sync adds multi-room capability with Audio Synchronisation
-
[3253星][7m] [JS] sindresorhus/speed-test Test your internet connection speed and ping using speedtest.net from the CLI
-
[3234星][8d] [Java] oldmanpushcart/greys-anatomy Java诊断工具
-
[3234星][2y] [CSS] jbtronics/crookedstylesheets 使用纯CSS收集网页/用户信息
-
[3232星][5m] [Go] meshbird/meshbird cloud-native multi-region multi-cloud decentralized private networking
-
[3230星][2m] [Objective-C] objective-see/lulu LuLu is the free macOS firewall
-
[3225星][18d] [Shell] toniblyx/my-arsenal-of-aws-security-tools List of open source tools for AWS security: defensive, offensive, auditing, DFIR, etc.
-
[3216星][14d] [Py] laramies/theharvester E-mails, subdomains and names Harvester - OSINT
-
[3215星][27d] [JS] koenkk/zigbee2mqtt Zigbee
-
[3214星][4y] [C] shadowsocks/chinadns Protect yourself against DNS poisoning in China.
-
[3214星][2m] [Go] dvyukov/go-fuzz Randomized testing for Go
-
[3210星][11d] [C] tmate-io/tmate Instant Terminal Sharing
-
[3210星][1m] [TypeScript] google/incremental-dom An in-place DOM diffing library
-
[3209星][8d] [C] betaflight/betaflight Open Source Flight Controller Firmware
-
[3205星][2m] [Shell] gfw-breaker/ssr-accounts 一键部署Shadowsocks服务;免费Shadowsocks账号分享;免费SS账号分享; 翻墙;无界,自由门,SquirrelVPN
-
[3202星][4m] [Objective-C] naituw/ipapatch Patch iOS Apps, The Easy Way, Without Jailbreak.
-
[3201星][7m] [HTML] leizongmin/js-xss Sanitize untrusted HTML (to prevent XSS) with a configuration specified by a Whitelist
-
[3184星][7d] [Go] mozilla/sops Simple and flexible tool for managing secrets
-
[3182星][3m] [C] yarrick/iodine 通过DNS服务器传输(tunnel)IPV4数据
-
[3182星][1y] [Py] kootenpv/whereami 使用Wifi信号和机器学习预测你的位置,精确度2-10米
-
[3180星][13d] [Py] maurosoria/dirsearch Web path scanner
-
[3174星][8d] [Rich Text Format] the-art-of-hacking/h4cker 资源收集:hacking、渗透、数字取证、事件响应、漏洞研究、漏洞开发、逆向
-
[3168星][1m] [C++] spiderlabs/modsecurity ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx that is developed by Trustwave's SpiderLabs. It has a robust event-based programming language which provides protection from a range of attacks against web applications and allows for HTTP traffic monitoring, logging and real-time analys…
-
[3164星][6m] hslatman/awesome-threat-intelligence A curated list of Awesome Threat Intelligence resources
-
[3163星][24d] [C] magnumripper/johntheripper This is the official repo for John the Ripper, "Jumbo" version. The "bleeding-jumbo" branch is based on 1.9.0-Jumbo-1 which was released on May 14, 2019. An import of the "core" version of john this jumbo was based on (or newer) is found in the "master" branch (CVS:
-
[3156星][1m] [C] valdikss/goodbyedpi GoodbyeDPI—Passive Deep Packet Inspection blocker and Active DPI circumvention utility (for Windows)
-
[3145星][1y] [Shell] toyodadoubi/doubi 一个逗比写的各种逗比脚本~
-
[3128星][2y] shadowsocksr-backup/shadowsocksr-android A ShadowsocksR client for Android
-
[3120星][10d] [C] meetecho/janus-gateway Janus WebRTC Server
-
[3113星][28d] [CSS] readthedocs/sphinx_rtd_theme Sphinx theme for readthedocs.org
-
[3112星][2m] [C++] trojan-gfw/trojan An unidentifiable mechanism that helps you bypass GFW.
-
[3109星][7d] [Shell] speed47/spectre-meltdown-checker 检查 Linux 主机是否受处理器漏洞Spectre & Meltdown 的影响
-
[3109星][2m] [PowerShell] fireeye/commando-vm Complete Mandiant Offensive VM (Commando VM), a fully customizable Windows-based pentesting virtual machine distribution. commandovm@fireeye.com
-
[3108星][4m] [C++] px4/firmware PX4 Autopilot Software
-
[3106星][7d] [C] qemu/qemu Official QEMU mirror. Please see
-
[3103星][16d] [Shell] 1n3/sn1per 自动化渗透测试框架
-
[3102星][7d] [JS] duo-labs/cloudmapper 生成AWS环境的网络拓扑图
-
[3096星][28d] meirwah/awesome-incident-response A curated list of tools for incident response
-
[3094星][2m] [Py] byt3bl33d3r/crackmapexec 后渗透工具,自动化评估大型Active Directory网络的安全性
-
[3091星][1m] [Java] deathmarine/luyten An Open Source Java Decompiler Gui for Procyon
-
[3085星][10d] [Shell] trimstray/htrace.sh My simple Swiss Army knife for http/https troubleshooting and profiling.
-
[3084星][11d] [Py] tribler/tribler Privacy enhanced BitTorrent client with P2P content discovery
-
[3084星][8d] [Shell] softwaredownload/openwrt-fanqiang 最好的路由器翻墙、科学上网教程—OpenWrt—shadowsocks
-
[3069星][9m] [JS] jipegit/osxauditor OS X Auditor is a free Mac OS X computer forensics tool
-
[3066星][3m] [C] zmap/zmap ZMap is a fast single packet network scanner designed for Internet-wide network surveys.
-
[3065星][9d] [Go] tencent/bk-cmdb 蓝鲸智云配置平台(BlueKing CMDB)
-
[3062星][1y] [Swift] zhuhaow/spechtlite A rule-based proxy for macOS
-
[3061星][20d] [C] unicorn-engine/unicorn Unicorn CPU emulator framework (ARM, AArch64, M68K, Mips, Sparc, X86)
-
[3059星][1m] [Java] calebfenton/simplify Generic Android Deobfuscator
-
[3058星][7m] [Go] michenriksen/aquatone 子域名枚举工具。除了经典的爆破枚举之外,还利用多种开源工具和在线服务大幅度增加发现子域名的数量。
-
[3046星][4m] [C++] google/robotstxt The repository contains Google's robots.txt parser and matcher as a C++ library (compliant to C++11).
-
[3041星][2m] [JS] valve/fingerprintjs Anonymous browser fingerprint
-
[3039星][3m] [Py] spiderlabs/responder LLMNR/NBT-NS/MDNS投毒,内置HTTP/SMB/MSSQL/FTP/LDAP认证服务器, 支持NTLMv1/NTLMv2/LMv2
-
[3007星][9m] [C] secwiki/linux-kernel-exploits linux-kernel-exploits Linux平台提权漏洞集合
-
[2991星][1y] [PHP] owner888/phpspider 《我用爬虫一天时间“偷了”知乎一百万用户,只为证明PHP是世界上最好的语言 》所使用的程序
-
[2983星][2m] [Go] gwuhaolin/lightsocks 轻量级网络混淆代理,基于 SOCKS5 协议,可用来代替 Shadowsocks
-
[2982星][7d] [Lua] ntop/ntopng 基于Web的流量监控工具
-
[2978星][7d] [Py] guardicore/monkey 自动化渗透测试工具, 测试数据中心的弹性, 以防范周边(perimeter)泄漏和内部服务器感染
-
[2962星][14d] [Objective-C] google/santa 用于Mac系统的二进制文件白名单/黑名单系统
-
[2947星][27d] [Go] cookiey/yearning A most popular sql audit platform for mysql
-
[2937星][13d] [JS] webgoat/webgoat 带漏洞WebApp
-
[2937星][2y] phith0n/mind-map 各种安全相关思维导图整理收集
-
[2936星][1m] [Py] andresriancho/w3af Web App安全扫描器, 辅助开发者和渗透测试人员识别和利用Web App中的漏洞
-
[2935星][19d] [Py] cowrie/cowrie 中型/交互型 SSH/Telnet 蜜罐,
-
[2930星][1y] [Py] danmcinerney/wifijammer 持续劫持范围内的Wifi客户端和AP
-
[2930星][11m] [Shell] 91yun/serverspeeder 锐速破解版
-
[2927星][7d] [Zeek] zeek/zeek Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.
-
[2916星][15d] [Py] twintproject/twint An advanced Twitter scraping & OSINT tool written in Python that doesn't use Twitter's API, allowing you to scrape a user's followers, following, Tweets and more while evading most API limitations.
-
[2912星][2m] [Dockerfile] thinkdevelop/free-ss-ssr SS账号、SSR账号、V2Ray账号
-
[2907星][21d] [Go] securego/gosec Golang security checker
-
[2897星][1y] [Py] byt3bl33d3r/mitmf Framework for Man-In-The-Middle attacks
-
[2895星][10d] [C] libfuse/sshfs A network filesystem client to connect to SSH servers
-
[2892星][11d] secfigo/awesome-fuzzing A curated list of fuzzing resources ( Books, courses - free and paid, videos, tools, tutorials and vulnerable applications to practice on ) for learning Fuzzing and initial phases of Exploit Development like root cause analysis.
-
[2891星][20d] [Py] trustedsec/ptf 创建基于Debian/Ubuntu/ArchLinux的渗透测试环境
-
[2876星][7m] [C] p-h-c/phc-winner-argon2 The password hash Argon2, winner of PHC
-
[2874星][4y] [Objective-C] maciekish/iresign iReSign allows iDevice app bundles (.ipa) files to be signed or resigned with a digital certificate from Apple for distribution. This tool is aimed at enterprises users, for enterprise deployment, when the person signing the app is different than the person(s) developing it.
-
[2851星][10d] [JS] evilsocket/pwnagotchi 深度学习+Bettercap,基于A2C,从周围的WiFi环境中学习,以最大程度地利用捕获的WPA关键信息
-
[2850星][8d] [C] lxc/lxc LXC - Linux Containers
-
[2840星][5m] [Py] instantbox/instantbox Get a clean, ready-to-go Linux box in seconds.
-
[2838星][11d] [Objective-C] facebook/idb idb is a flexible command line interface for automating iOS simulators and devices
-
[2834星][8m] [C++] wangyu-/udpspeeder A Tunnel which Improves your Network Quality on a High-latency Lossy Link by using Forward Error Correction,for All Traffics(TCP/UDP/ICMP)
-
[2830星][9d] [HTML] ctf-wiki/ctf-wiki CTF Wiki Online. Come and join us, we need you!
-
[2829星][21d] [C] ossec/ossec-hids 入侵检测系统
-
[2825星][15d] [Py] espressif/esptool ESP8266 and ESP32 serial bootloader utility
-
[2825星][8m] [Shell] goreliu/wsl-terminal Terminal emulator for Windows Subsystem for Linux (WSL)
-
[2823星][12d] [Go] 99designs/aws-vault A vault for securely storing and accessing AWS credentials in development environments
-
[2820星][1m] [Assembly] cirosantilli/x86-bare-metal-examples 几十个用于学习 x86 系统编程的小型操作系统
-
[2819星][2y] [CSS] maxchehab/css-keylogging Chrome extension and Express server that exploits keylogging abilities of CSS.
-
[2815星][4m] [C] juliocesarfort/public-pentesting-reports Curated list of public penetration test reports released by several consulting firms and academic security groups
-
[2810星][28d] [C] tmk/tmk_keyboard Atmel AVR 和 Cortex-M键盘固件收集
-
[2810星][2m] infosecn1nja/red-teaming-toolkit A collection of open source and commercial tools that aid in red team operations.
-
[2805星][1m] paulsec/awesome-sec-talks A collected list of awesome security talks
-
[2804星][8m] [C#] quasar/quasarrat Remote Administration Tool for Windows
-
[2802星][9m] [Py] plasma-disassembler/plasma Plasma is an interactive disassembler for x86/ARM/MIPS. It can generates indented pseudo-code with colored syntax.
-
[2787星][17d] [Py] androguard/androguard Reverse engineering, Malware and goodware analysis of Android applications ... and more (ninja !)
-
[2783星][2y] [C] seclab-ucr/intang research project for circumventing the "TCP reset attack" from the Great Firewall of China (GFW) by disrupting/desynchronizing the TCP Control Block (TCB) on the censorship devices.
-
[2779星][28d] [Makefile] shadowsocks/openwrt-shadowsocks Shadowsocks-libev for OpenWrt/LEDE
-
[2776星][4y] [Lua] loveshell/ngx_lua_waf ngx_lua_waf是一个基于lua-nginx-module(openresty)的web应用防火墙
-
[2767星][2m] [Go] kgretzky/evilginx2 独立的MITM攻击工具,用于登录凭证钓鱼,可绕过双因素认证
-
[2763星][1m] [JS] trufflesuite/ganache-cli Fast Ethereum RPC client for testing and development
-
[2761星][10d] [Py] jrohy/multi-v2ray v2ray easy delpoy & manage tool, support multiple user & protocol manage
-
[2755星][7d] [C++] qtox/qtox qTox is a chat, voice, video, and file transfer IM client using the encrypted peer-to-peer Tox protocol.
-
[2746星][8d] [C] processhacker/processhacker A free, powerful, multi-purpose tool that helps you monitor system resources, debug software and detect malware.
-
[2736星][8m] [Py] p0cl4bs/wifi-pumpkin AP攻击框架, 创建虚假网络, 取消验证攻击、请求和凭证监控、透明代理、Windows更新攻击、钓鱼管理、ARP投毒、DNS嗅探、Pumpkin代理、动态图片捕获等
-
[2736星][1y] [C] vanhoefm/krackattacks-scripts 检测客户端和AP是否受KRACK漏洞影响
-
[2735星][7d] [TypeScript] webhintio/hint
-
[2731星][22d] [Makefile] theos/theos A cross-platform suite of tools for building and deploying software for iOS and other platforms.
-
[2727星][2m] secwiki/sec-chart 安全思维导图集合
-
[2727星][3y] [Py] hephaest0s/usbkill 反取证开关. 监控USB端口变化, 有变化时立即关闭计算机
-
[2726星][16d] [JS] cyu/rack-cors Rack Middleware for handling Cross-Origin Resource Sharing (CORS), which makes cross-origin AJAX possible.
-
[2715星][21d] [JS] s0md3v/awesomexss Awesome XSS stuff
-
[2701星][3y] [Eagle] samyk/magspoof 信用卡/磁条欺骗
-
[2700星][1m] [C] taviso/loadlibrary 使 Linux系统加载并调用 Windows DLL
-
[2683星][4m] [Objective-C] dantheman827/ios-app-signer This is an app for OS X that can (re)sign apps and bundle them into ipa files that are ready to be installed on an iOS device.
-
[2681星][1m] [Objective-C] kjcracks/clutch Fast iOS executable dumper
-
[2665星][7d] [Go] google/syzkaller 一个unsupervised、以 coverage 为导向的Linux 系统调用fuzzer
-
[2660星][7d] [PowerShell] redcanaryco/atomic-red-team Small and highly portable detection tests based on MITRE's ATT&CK.
-
[2660星][1y] [Py] mame82/p4wnp1 基于Raspberry Pi Zero 或 Raspberry Pi Zero W 的USB攻击平台, 高度的可定制性
-
[2658星][12d] [Go] aquasecurity/trivy A Simple and Comprehensive Vulnerability Scanner for Containers, Suitable for CI
-
[2648星][3m] [Py] drivendata/cookiecutter-data-science A logical, reasonably standardized, but flexible project structure for doing and sharing data science work.
-
[2643星][2m] rmusser01/infosec_reference An Information Security Reference That Doesn't Suck
-
[2638星][3m] [Java] frohoff/ysoserial 生成会利用不安全的Java对象反序列化的Payload
-
[2634星][2m] xairy/linux-kernel-exploitation Linux 内核 Fuzz 和漏洞利用的资源收集
-
[2633星][3m] [Java] teevity/ice AWS Usage Tool
-
[2633星][1y] [HTML] chybeta/web-security-learning Web-Security-Learning
-
[2622星][15d] [JS] bkimminich/juice-shop OWASP Juice Shop: Probably the most modern and sophisticated insecure web application
-
[2619星][8m] leandromoreira/linux-network-performance-parameters Learn where some of the network sysctl variables fit into the Linux/Kernel network flow
-
[2610星][2m] [Swift] zhuhaow/nekit A toolkit for Network Extension Framework
-
[2601星][3y] [Ruby] arachni/arachni Web Application Security Scanner Framework
-
[2600星][21d] [JS] knownsec/kcon KCon is a famous Hacker Con powered by Knownsec Team.
-
[2598星][8d] [JS] popcorn-official/popcorn-desktop Popcorn Time is a multi-platform, free software BitTorrent client that includes an integrated media player. Desktop ( Windows / Mac / Linux ) a Butter-Project Fork
-
[2589星][19d] [C++] fanout/pushpin Reverse proxy for realtime web services
-
[2588星][1m] pditommaso/awesome-pipeline A curated list of awesome pipeline toolkits inspired by Awesome Sysadmin
-
[2570星][2m] [C] huntergregal/mimipenguin dump 当前Linux用户的登录密码
-
[2565星][1m] [Shell] medicean/vulapps 快速搭建各种漏洞环境(Various vulnerability environment)
-
[2564星][8y] [C] id-software/quake Quake GPL Source Release
-
[2563星][5m] [Java] google/binnavi 二进制分析IDE, 对反汇编代码的控制流程图和调用图进行探查/导航/编辑/注释.(IDA插件的作用是导出反汇编)
-
[2555星][1m] [C] esnet/iperf A TCP, UDP, and SCTP network bandwidth measurement tool
-
[2554星][2y] evilsocket/bettercap 中间人攻击框架,功能完整,模块化设计,轻便且易于扩展。
-
[2547星][3m] [Py] greenwolf/social_mapper 对多个社交网站的用户Profile图片进行大规模的人脸识别
-
[2537星][6m] [C] geohot/qira QEMU Interactive Runtime Analyser
-
[2533星][2y] [Py] google/nogotofail 网络安全测试, 辅助定位和修复弱TLS/SSL连接和敏感明文流量
-
[2532星][8m] offensive-security/kali-nethunter The Kali NetHunter Project
-
[2530星][17d] [Py] hugsy/gef gdb增强工具,使用Python API,用于漏洞开发和逆向分析。
-
[2521星][21d] [Go] drk1wi/modlishka Modlishka. Reverse Proxy.
-
[2520星][3y] [HTML] dirtycow/dirtycow.github.io Dirty COW
-
[2515星][24d] [C] yrutschle/sslh Applicative Protocol Multiplexer (e.g. share SSH and HTTPS on the same port)
-
[2510星][11d] [Shell] teddysun/across This is a shell script for configure and start WireGuard VPN server
-
[2505星][3m] kbandla/aptnotes Various public documents, whitepapers and articles about APT campaigns
-
[2505星][3y] [C] dhavalkapil/icmptunnel Transparently tunnel your IP traffic through ICMP echo and reply packets.
-
[2503星][7m] [C++] chengr28/pcap_dnsproxy Pcap_DNSProxy, a local DNS server based on packet capturing
-
[2495星][2m] [Java] jboss-javassist/javassist Java bytecode engineering toolkit
-
[2488星][1y] onlurking/awesome-infosec A curated list of awesome infosec courses and training resources.
-
[2486星][26d] [Py] ysrc/xunfeng 巡风是一款适用于企业内网的漏洞快速应急,巡航扫描系统。
-
[2481星][5m] [Go] oj/gobuster Directory/File, DNS and VHost busting tool written in Go
-
[2480星][8d] [Go] adguardteam/adguardhome Network-wide ads & trackers blocking DNS server
-
[2480星][2y] [Py] feross/spoofmac 伪造MAC地址(OS X, Windows, Linux)
-
[2473星][5y] [PHP] audi-1/sqli-labs SQLI labs to test error based, Blind boolean based, Time based.
-
[2472星][11m] [JS] weixin/miaow A set of plugins for Sketch include drawing links & marks, UI Kit & Color sync, font & text replacing.
-
[2470星][6m] taichi-framework/taichi A framework to use Xposed module with or without Root/Unlock bootloader, supportting Android 5.0 ~ 10.0
-
[2463星][13d] [JS] vitaly-t/pg-promise PostgreSQL interface for Node.js
-
[2458星][3m] [C] martin-ger/esp_wifi_repeater A full functional WiFi Repeater (correctly: a WiFi NAT Router)
-
[2456星][4m] [Go] ne0nd0g/merlin Merlin is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in golang.
-
[2454星][24d] [C++] pavel-odintsov/fastnetmon 快速 DDoS 检测/分析工具,支持 sflow/netflow/mirror
-
[2453星][11m] [C#] yck1509/confuserex An open-source, free protector for .NET applications
-
[2451星][3y] [Py] google/enjarify 将Dalvik字节码转换为对应的Java字节码
-
[2441星][28d] [Py] smicallef/spiderfoot 自动收集指定目标的信息:IP、域名、主机名、网络子网、ASN、邮件地址、用户名
-
[2424星][7d] [PHP] misp/misp MISP (core software) - Open Source Threat Intelligence and Sharing Platform (formely known as Malware Information Sharing Platform)
-
[2420星][19d] [Shell] rebootuser/linenum Scripted Local Linux Enumeration & Privilege Escalation Checks
-
[2415星][1m] [Py] 0xinfection/awesome-waf
-
[2412星][23d] [Py] pwndbg/pwndbg GDB插件,辅助漏洞开发和逆向
-
[2411星][3y] [Py] arthepsy/ssh-audit SSH server auditing (banner, key exchange, encryption, mac, compression, compatibility, security, etc)
-
[2407星][1m] [TSQL] rapid7/metasploitable3 Metasploitable3 is a VM that is built from the ground up with a large amount of security vulnerabilities.
-
[2404星][24d] [Py] infobyte/faraday 渗透测试和漏洞管理平台
-
[2399星][3y] rpisec/malware Course materials for Malware Analysis by RPISEC
-
[2395星][3y] [OCaml] facebookarchive/pfff 一堆工具的集合,用于执行静态分析、代码可视化、代码导航、保持格式的源码转换(例如:源码重构)。完美支持C、Java、JS、PHP,后续将支持其他一大堆语言。
-
[2395星][24d] [Py] xmendez/wfuzz Web application fuzzer
-
[2391星][8m] [Py] lionsec/katoolin Automatically install all Kali linux tools
-
[2381星][2y] [Py] secretsquirrel/the-backdoor-factory 为PE, ELF, Mach-O二进制文件添加Shellcode后门
-
[2375星][1y] [Py] danmcinerney/lans.py Inject code and spy on wifi users
-
[2369星][2m] [TeX] crypto101/book Crypto 101, the introductory book on cryptography.
-
[2368星][7d] [C] wireshark/wireshark Read-only mirror of Wireshark's Git repository. GitHub won't let us disable pull requests. ☞ THEY WILL BE IGNORED HERE ☜ Please upload them at
-
[2366星][7d] [Java] mock-server/mockserver MockServer enables easy mocking of any system you integrate with via HTTP or HTTPS with clients written in Java, JavaScript and Ruby. MockServer also includes a proxy that introspects all proxied traffic including encrypted SSL traffic and supports Port Forwarding, Web Proxying (i.e. HTTP proxy), HTTPS Tunneling Proxying (using HTTP CONNECT) and…
-
[2366星][11m] [C] haad/proxychains a tool that forces any TCP connection made by any given application to follow through proxy like TOR or any other SOCKS4, SOCKS5 or HTTP(S) proxy. Supported auth-types: "user/pass" for SOCKS4/5, "basic" for HTTP.
-
[2359星][1m] [Lua] snabbco/snabb Simple and fast packet networking
-
[2359星][13d] security-onion-solutions/security-onion Linux distro for intrusion detection, enterprise security monitoring, and log management
-
[2359星][4m] [Go] mlabouardy/komiser
-
[2351星][8d] [C] domoticz/domoticz monitor and configure various devices like: Lights, Switches, various sensors/meters like Temperature, Rain, Wind, UV, Electra, Gas, Water and much more
-
[2350星][1m] [Py] ab77/netflix-proxy Smart DNS proxy to watch Netflix
-
[2342星][3m] [Go] vuvuzela/vuvuzela Private messaging system that hides metadata
-
[2342星][12d] [Go] owasp/amass In-depth Attack Surface Mapping and Asset Discovery
-
[2338星][6y] [C] stefanesser/dumpdecrypted Dumps decrypted mach-o files from encrypted iPhone applications from memory to disk. This tool is necessary for security researchers to be able to look under the hood of encryption.
-
[2335星][11m] hack-with-github/free-security-ebooks Free Security and Hacking eBooks
-
[2332星][1m] [Py] ctfd/ctfd CTFs as you need them
-
[2330星][1m] [JS] pa11y/pa11y Pa11y is your automated accessibility testing pal
-
[2324星][30d] [C] hfiref0x/uacme Defeating Windows User Account Control
-
[2317星][10d] [C] tsl0922/ttyd Share your terminal over the web
-
[2316星][5y] [C] abrasive/shairport Airtunes emulator! Shairport is no longer maintained.
-
[2302星][11m] yeyintminthuhtut/awesome-red-teaming List of Awesome Red Teaming Resources
-
[2302星][1y] [Java] csploit/android cSploit - The most complete and advanced IT security professional toolkit on Android.
-
[2291星][3y] [Py] lmacken/pyrasite 向运行中的 Python进程注入代码
-
[2277星][3m] [JS] retirejs/retire.js scanner detecting the use of JavaScript libraries with known vulnerabilities
-
[2272星][3y] [Py] therook/subbrute A DNS meta-query spider that enumerates DNS records, and subdomains.
-
[2272星][1m] [C] moby/hyperkit A toolkit for embedding hypervisor capabilities in your application
-
[2271星][22d] [JS] talkingdata/inmap 大数据地理可视化
-
[2271星][2y] [Py] rootphantomer/blasting_dictionary 爆破字典
-
[2267星][1m] [C] aurorawright/luma3ds Noob-proof (N)3DS "Custom Firmware"
-
[2246星][16d] dumb-password-rules/dumb-password-rules Shaming sites with dumb password rules.
-
[2244星][2y] [Go] mehrdadrad/mylg 网络诊断工具
-
[2242星][1m] [Shell] v1s1t0r1sh3r3/airgeddon This is a multi-use bash script for Linux systems to audit wireless networks.
-
[2241星][13d] [HTML] tikam02/devops-guide DevOps Guide from basic to advanced with Interview Questions and Notes
-
[2241星][3m] [Py] novnc/websockify Websockify is a WebSocket to TCP proxy/bridge. This allows a browser to connect to any application/server/service. Implementations in Python, C, Node.js and Ruby.
-
[2235星][1m] [Shell] eliaskotlyar/xiaomi-dafang-hacks
-
[2226星][5y] [Go] filosottile/heartbleed A checker (site and tool) for CVE-2014-0160
-
[2222星][8d] [C#] netchx/netch Game accelerator. Support Socks5, Shadowsocks, ShadowsocksR, V2Ray protocol. UDP NAT FullCone
-
[2218星][7d] [Py] cloudflare/flan A pretty sweet vulnerability scanner
-
[2215星][6y] [C++] codebutler/firesheep 演示HTTP会话劫持攻击的Firefox扩展
-
[2211星][1y] [JS] cure53/h5sc HTML5 Security Cheatsheet - A collection of HTML5 related XSS attack vectors
-
[2204星][10d] [PowerShell] k8gege/k8tools K8工具合集(内网渗透/提权工具/远程溢出/漏洞利用/扫描工具/密码破解/免杀工具/Exploit/APT/0day/Shellcode/Payload/priviledge/BypassUAC/OverFlow/WebShell/PenTest) Web GetShell Exploit(Struts2/Zimbra/Weblogic/Tomcat/Apache/Jboss/DotNetNuke/zabbix)
-
[2203星][1m] [C] texane/stlink stm32 discovery line linux programmer
-
[2201星][11d] [Go] google/mtail extract whitebox monitoring data from application logs for collection in a timeseries database
-
[2187星][21d] [C++] google/bloaty Bloaty McBloatface: a size profiler for binaries
-
[2184星][3y] enddo/awesome-windows-exploitation A curated list of awesome Windows Exploitation resources, and shiny things. Inspired by awesom
-
[2182星][1y] [Py] datasploit/datasploit 对指定目标执行多种侦查技术:企业、人、电话号码、比特币地址等
-
[2177星][1m] [JS] secgroundzero/warberry WarBerryPi - Tactical Exploitation
-
[2171星][14d] [C] armmbed/mbedtls An open source, portable, easy to use, readable and flexible SSL library
-
[2168星][16d] getlantern/lantern-binaries Lantern installers binary downloads.
-
[2167星][29d] sobolevn/awesome-cryptography A curated list of cryptography resources and links.
-
[2158星][2m] [Go] mmatczuk/go-http-tunnel Fast and secure tunnels over HTTP/2
-
[2156星][1m] [C] conorpp/u2f-zero U2F USB token optimized for physical security, affordability, and style
-
[2155星][1y] [C++] maestron/botnets This is a collection of #botnet source codes, unorganized. For EDUCATIONAL PURPOSES ONLY
-
[2153星][6y] [Ruby] plamoni/siriproxy A (tampering) proxy server for Apple's Siri
-
[2152星][29d] [Py] commixproject/commix Automated All-in-One OS command injection and exploitation tool.
-
[2151星][9m] exakat/php-static-analysis-tools A reviewed list of useful PHP static analysis tools
-
[2146星][14d] [Java] google/wycheproof Project Wycheproof tests crypto libraries against known attacks.
-
[2127星][1m] [Py] jonathansalwan/ropgadget This tool lets you search your gadgets on your binaries to facilitate your ROP exploitation. ROPgadget supports ELF, PE and Mach-O format on x86, x64, ARM, ARM64, PowerPC, SPARC and MIPS architectures.
-
[2124星][2m] [Py] trustedsec/unicorn 通过PowerShell降级攻击, 直接将Shellcode注入到内存
-
[2123星][16d] [Assembly] pret/pokered disassembly of Pokémon Red/Blue
-
[2114星][7m] [Py] calebmadrigal/trackerjacker 映射你没连接到的Wifi网络, 类似于NMap, 另外可以追踪设备
-
[2112星][1y] [Py] rub-nds/pret Printer Exploitation Toolkit - The tool that made dumpster diving obsolete.
-
[2107星][4y] [C] hashcat/hashcat-legacy Advanced CPU-based password recovery utility
-
[2105星][7d] goq/telegram-list List of telegram groups, channels & bots // Список интересных групп, каналов и ботов телеграма // Список чатов для программистов
-
[2105星][1m] [Py] elceef/dnstwist 域名置换引擎,用于检测打字错误,网络钓鱼和企业间谍活动
-
[2103星][8m] [Py] linkedin/qark 查找Android App的漏洞, 支持源码或APK文件
-
[2098星][19d] [Py] fortynorthsecurity/eyewitness 给网站做快照,提供服务器Header信息,识别默认凭证等
-
[2098星][21d] infoslack/awesome-web-hacking A list of web application security
-
[2090星][3m] yeahhub/hacking-security-ebooks Top 100 Hacking & Security E-Books (Free Download)
-
[2081星][8d] [C] flatpak/flatpak Linux application sandboxing and distribution framework
-
[2071星][30d] [Go] theupdateframework/notary Notary is a project that allows anyone to have trust over arbitrary collections of data
-
[2069星][20d] [Ruby] urbanadventurer/whatweb Next generation web scanner
-
[2062星][9m] jermic/android-crack-tool
-
[2051星][4m] [Py] whaleshark-team/cobra Source Code Security Audit (源代码安全审计)
-
[2049星][1y] bluscreenofjeff/red-team-infrastructure-wiki Wiki to collect Red Team infrastructure hardening resources
-
[2047星][6m] [Go] maxmcd/webtty Share a terminal session over WebRTC
-
[2041星][2y] [Py] derv82/wifite 自动化无线攻击工具
-
[2037星][10d] [Py] nabla-c0d3/sslyze SSL/TLS服务器扫描
-
[2036星][2m] [C++] lordnoteworthy/al-khaser Public malware techniques used in the wild: Virtual Machine, Emulation, Debuggers, Sandbox detection.
-
[2035星][2m] tanprathan/mobileapp-pentest-cheatsheet The Mobile App Pentest cheat sheet was created to provide concise collection of high value information on specific mobile application penetration testing topics.
-
[2035星][8m] [Shell] foospidy/payloads web 攻击 Payload 集合
-
[2032星][7d] [C++] openthread/openthread OpenThread released by Google is an open-source implementation of the Thread networking protocol
-
[2032星][1m] edoverflow/bugbounty-cheatsheet A list of interesting payloads, tips and tricks for bug bounty hunters.
-
[2024星][5y] [CoffeeScript] shadowsocks/shadowsocks-gui Shadowsocks GUI client
-
[2020星][20d] [Objective-C] ios-control/ios-deploy Install and debug iPhone apps from the command line, without using Xcode
-
[2017星][3m] [C++] darthton/blackbone Windows memory hacking library
-
[2016星][3y] [Swift] urinx/iosapphook 专注于非越狱环境下iOS应用逆向研究,从dylib注入,应用重签名到App Hook
-
[2014星][8d] [Py] sensepost/objection runtimemobile exploration
-
[2012星][1y] [C] xoreaxeaxeax/rosenbridge Hardware backdoors in some x86 CPUs
-
[2006星][9m] [C] dekunukem/nintendo_switch_reverse_engineering A look at inner workings of Joycon and Nintendo Switch
-
[2004星][4y] [C] probablycorey/wax Wax is now being maintained by alibaba
-
[1999星][8d] [Java] jeremylong/dependencycheck OWASP dependency-check is a software composition analysis utility that detects publicly disclosed vulnerabilities in application dependencies.
-
[1998星][13d] [Shell] wulabing/v2ray_ws-tls_bash_onekey V2Ray Nginx+vmess+ws+tls/ http2 over tls 一键安装脚本
-
[1992星][25d] [Swift] github/softu2f Software U2F authenticator for macOS
-
[1991星][29d] qazbnm456/awesome-cve-poc CVE PoC列表
-
[1990星][4m] swiftonsecurity/sysmon-config Sysmon configuration file template with default high-quality event tracing
-
[1988星][4y] [Go] yahoo/gryffin Gryffin is a large scale web security scanning platform.
-
[1987星][7m] [Py] fsecurelabs/drozer The Leading Security Assessment Framework for Android.
-
[1983星][2y] dloss/python-pentest-tools 可用于渗透测试的Python工具收集
-
[1983星][2m] [C++] asmjit/asmjit Complete x86/x64 JIT and AOT Assembler for C++
-
[1976星][3m] infosecn1nja/ad-attack-defense Attack and defend active directory using modern post exploitation adversary tradecraft activity
-
[1967星][26d] [Java] genymobile/gnirehtet Gnirehtet provides reverse tethering for Android
-
[1965星][9m] [JS] weichiachang/stacks-cli Check website stack from the terminal
-
[1963星][11d] [HTML] gtfobins/gtfobins.github.io Curated list of Unix binaries that can be exploited to bypass system security restrictions
-
[1963星][27d] [Java] elderdrivers/edxposed Elder driver Xposed Framework.
-
[1962星][1m] [Py] momosecurity/aswan 陌陌风控系统静态规则引擎,零基础简易便捷的配置多种复杂规则,实时高效管控用户异常行为。
-
[1958星][26d] [C#] mathewsachin/captura Capture Screen, Audio, Cursor, Mouse Clicks and Keystrokes
-
[1957星][9d] [Go] ullaakut/cameradar Cameradar hacks its way into RTSP videosurveillance cameras
-
[1954星][1y] [BitBake] 1n3/intruderpayloads A collection of Burpsuite Intruder payloads, BurpBounty payloads, fuzz lists, malicious file uploads and web pentesting methodologies and checklists.
-
[1946星][2y] obfuscator-llvm/obfuscator Obfuscator-LLVM
-
[1945星][7d] [Perl] spiderlabs/owasp-modsecurity-crs OWASP ModSecurity Core Rule Set (CRS) Project (Official Repository)
-
[1940星][3y] [C#] lazocoder/windows-hacks Creative and unusual things that can be done with the Windows API.
-
[1939星][2m] [C] microsoft/procdump-for-linux Linux 版本的 ProcDump
-
[1938星][27d] [Py] nixawk/pentest-wiki PENTEST-WIKI is a free online security knowledge library for pentesters / researchers. If you have a good idea, please share it with others.
-
[1938星][14d] [Py] cea-sec/miasm Reverse engineering framework in Python
-
[1926星][17d] [Go] mpolden/echoip IP address lookup service
-
[1913星][5m] [C] darkk/redsocks transparent TCP-to-proxy redirector
-
[1912星][3m] toolswatch/blackhat-arsenal-tools Black Hat 武器库
-
[1911星][3y] [Py] aoncyberlabs/windows-exploit-suggester This tool compares a targets patch levels against the Microsoft vulnerability database in order to detect potential missing patches on the target. It also notifies the user if there are public exploits and Metasploit modules available for the missing bulletins.
-
[1911星][8d] [C] ntop/ndpi Open Source Deep Packet Inspection Software Toolkit
-
[1909星][3d] [Go] projectdiscovery/subfinder Subfinder is a subdomain discovery tool that discovers valid subdomains for websites. Designed as a passive framework to be useful for bug bounties and safe for penetration testing.
-
[1909星][9d] [Py] j3ssie/osmedeus Fully automated offensive security framework for reconnaissance and vulnerability scanning
-
[1908星][7d] [C++] powerdns/pdns PowerDNS
-
[1907星][16d] [Py] lanjelot/patator Patator is a multi-purpose brute-forcer, with a modular design and a flexible usage.
-
[1906星][13d] [CSS] cyb3rward0g/helk 对ELK栈进行分析,具备多种高级功能,例如SQL声明性语言,图形,结构化流,机器学习等
-
[1902星][7d] [Go] solo-io/gloo An Envoy-Powered API Gateway
-
[1901星][3m] [Go] minishift/minishift Run OpenShift 3.x locally
-
[1892星][19d] [C] chipsec/chipsec 分析PC平台的安全性, 包括硬件、系统固件(BIOS/UEFI)和平台组件
-
[1891星][7d] [Py] mozilla/mozdef Mozilla Enterprise Defense Platform
-
[1886星][8d] [Go] chaitin/xray xray 安全评估工具 | 使用之前务必先阅读文档
-
[1880星][14d] [C++] mhammond/pywin32 Python for Windows (pywin32) Extensions
-
[1878星][4m] [C] shadowsocks/simple-obfs A simple obfuscating tool (Deprecated)
-
[1876星][7d] [Shell] toniblyx/prowler AWS Security Best Practices Assessment, Auditing, Hardening and Forensics Readiness Tool. It follows guidelines of the CIS Amazon Web Services Foundations Benchmark and DOZENS of additional checks including GDPR and HIPAA (+100). Official CIS for AWS guide:
-
[1876星][5y] [C++] tum-vision/lsd_slam LSD-SLAM
-
[1876星][4m] [Py] python-security/pyt Python Web App 安全漏洞检测和静态分析工具
-
[1876星][6m] [Java] fuzion24/justtrustme An xposed module that disables SSL certificate checking for the purposes of auditing an app with cert pinning
-
[1876星][1y] [Py] aploium/zmirror The next-gen reverse proxy for full site mirroring
-
[1869星][13d] [YARA] yara-rules/rules Repository of yara rules
-
[1868星][1y] [Py] derv82/wifite2 无线网络审计工具wifite 的升级版/重制版
-
[1867星][2m] [Py] pycqa/bandit 在Python代码中查找常见的安全问题
-
[1864星][7d] [C] merbanan/rtl_433 Program to decode traffic from Devices that are broadcasting on 433.9 MHz like temperature sensors
-
[1863星][4y] [Objective-C] xcodeghostsource/xcodeghost "XcodeGhost" Source
-
[1861星][10m] [PHP] bartblaze/php-backdoors A collection of PHP backdoors. For educational or testing purposes only.
-
[1861星][4m] [Java] adoptopenjdk/jitwatch Log analyser / visualiser for Java HotSpot JIT compiler. Inspect inlining decisions, hot methods, bytecode, and assembly. View results in the JavaFX user interface.
-
[1858星][10d] [Py] aquasecurity/kube-hunter Hunt for security weaknesses in Kubernetes clusters
-
[1857星][21d] [C] tinyproxy/tinyproxy a light-weight HTTP/HTTPS proxy daemon for POSIX operating systems
-
[1857星][7d] olivierlaflamme/cheatsheet-god Penetration Testing Reference Bank - OSCP / PTP & PTX Cheatsheet
-
[1849星][11m] [C++] googlecreativelab/open-nsynth-super Open NSynth Super is an experimental physical interface for the NSynth algorithm
-
[1848星][29d] [C] github/glb-director GitHub Load Balancer Director and supporting tooling.
-
[1846星][8m] [Py] netflix-skunkworks/stethoscope Personalized, user-focused recommendations for employee information security.
-
[1845星][2m] [Py] pwnlandia/mhn 蜜罐网络
-
[1844星][8d] [TypeScript] snyk/snyk CLI and build-time tool to find & fix known vulnerabilities in open-source dependencies
-
[1842星][1y] [Java] jindrapetrik/jpexs-decompiler JPEXS Free Flash Decompiler
-
[1841星][13d] [C++] acidanthera/lilu Arbitrary kext and process patching on macOS
-
[1841星][2m] [C] retroplasma/earth-reverse-engineering Reversing Google's 3D satellite mode
-
[1839星][4m] bypass007/emergency-response-notes 应急响应实战笔记,一个安全工程师的自我修养。
-
[1837星][4m] [Lua] vulnerscom/nmap-vulners NSE script based on Vulners.com API
-
[1836星][3y] [Java] chora10/cknife Cknife
-
[1835星][1y] [Java] yeriomin/yalpstore Download apks from Google Play Store
-
[1833星][25d] hmaverickadams/beginner-network-pentesting Notes for Beginner Network Pentesting Course
-
[1832星][4m] [Shell] arismelachroinos/lscript 自动化无线渗透和Hacking 任务的脚本
-
[1830星][7d] [C++] pytorch/glow Compiler for Neural Network hardware accelerators
-
[1829星][1y] [Py] jinnlynn/genpac PAC/Dnsmasq/Wingy file Generator, working with gfwlist, support custom rules.
-
[1827星][1m] [Jupyter Notebook] hunters-forge/threathunter-playbook A Threat hunter's playbook to aid the development of techniques and hypothesis for hunting campaigns.
-
[1827星][2m] [Go] influxdata/kapacitor Open source framework for processing, monitoring, and alerting on time series data
-
[1827星][1y] [CSS] ctfs/write-ups-2015 Wiki-like CTF write-ups repository, maintained by the community. 2015
-
[1819星][13d] [Py] trailofbits/manticore 动态二进制分析工具,支持符号执行(symbolic execution)、污点分析(taint analysis)、运行时修改。
-
[1816星][19d] [C] mgba-emu/mgba mGBA Game Boy Advance Emulator
-
[1814星][7d] [Py] bregman-arie/devops-interview-questions Linux, Jenkins, AWS, SRE, Prometheus, Docker, Python, Ansible, Git, Kubernetes, Terraform, OpenStack, SQL, NoSQL, Azure, GCP, DNS, Elastic
-
[1808星][6m] [C++] iagox86/dnscat2 在 DNS 协议上创建加密的 C&C channel
-
[1806星][5m] [Py] veil-framework/veil generate metasploit payloads that bypass common anti-virus solutions
-
[1801星][3y] [Objective-C] kpwn/yalu102 incomplete iOS 10.2 jailbreak for 64 bit devices by qwertyoruiopz and marcograssi
-
[1801星][2m] djadmin/awesome-bug-bounty A comprehensive curated list of available Bug Bounty & Disclosure Programs and Write-ups.
-
[1788星][28d] [Go] gdamore/tcell Tcell is an alternate terminal package, similar in some ways to termbox, but better in others.
-
[1785星][11m] [Py] ctfs/write-ups-2017 Wiki-like CTF write-ups repository, maintained by the community. 2017
-
[1784星][7d] [C#] hmbsbige/shadowsocksr-windows 【自用】Bug-Oriented Programming
-
[1783星][7m] [Py] lijiejie/subdomainsbrute 子域名爆破
-
[1777星][18d] [PHP] ezyang/htmlpurifier Standards compliant HTML filter written in PHP
-
[1776星][13d] [C++] apitrace/apitrace Tools for tracing OpenGL, Direct3D, and other graphics APIs
-
[1775星][4y] caesar0301/awesome-pcaptools A collection of tools developed by other researchers in the Computer Science area to process network traces. All the right reserved for the original authors.
-
[1774星][1y] aozhimin/ios-monitor-platform
-
[1770星][3y] [Objective-C] alibaba/wax Wax is a framework that lets you write native iPhone apps in Lua.
-
[1768星][13d] [Shell] leebaird/discover 自定义的bash脚本, 用于自动化多个渗透测试任务, 包括: 侦查、扫描、解析、在Metasploit中创建恶意Payload和Listener
-
[1764星][3m] [Py] epinna/weevely3 Weaponized web shell
-
[1759星][12d] [C] google/wuffs Wrangling Untrusted File Formats Safely
-
[1757星][7m] [C++] wrbug/dumpdex Android脱壳
-
[1757星][2y] [CSS] b374k/b374k PHP Webshell with handy features
-
[1749星][2m] onethawt/idaplugins-list IDA插件收集
-
[1747星][8d] 17mon/china_ip_list
-
[1743星][12m] [JS] puppeteer/examples Use case-driven examples for using Puppeteer and headless chrome
-
[1740星][8d] [PHP] wordpress/wordpress-coding-standards PHP_CodeSniffer rules (sniffs) to enforce WordPress coding conventions
-
[1738星][2y] [Go] vzex/dog-tunnel p2p tunnel,(udp mode work with kcp,
-
[1734星][3m] tunz/js-vuln-db A collection of JavaScript engine CVEs with PoCs
-
[1732星][1y] coreb1t/awesome-pentest-cheat-sheets Collection of the cheat sheets useful for pentesting
-
[1727星][2m] [PHP] orangetw/my-ctf-web-challenges Collection of CTF Web challenges I made
-
[1726星][3y] [Go] s-rah/onionscan OnionScan is a free and open source tool for investigating the Dark Web.
-
[1723星][6m] [Smali] ahmyth/ahmyth-android-rat Android Remote Administration Tool
-
[1722星][1y] [PowerShell] fuzzysecurity/powershell-suite My musings with PowerShell
-
[1720星][19d] ngalongc/bug-bounty-reference Inspired by
-
[1718星][1m] [PowerShell] fireeye/flare-vm 火眼发布用于 Windows 恶意代码分析的虚拟机:FLARE VM
-
[1717星][7d] [C] google/honggfuzz Security oriented fuzzer with powerful analysis options. Supports evolutionary, feedback-driven fuzzing based on code coverage (software- and hardware-based)
-
[1714星][2m] [Go] subfinder/subfinder 使用Passive Sources, Search Engines, Pastebins, Internet Archives等查找子域名
-
[1709星][9m] [Py] constverum/proxybroker Proxy [Finder | Checker | Server]. HTTP(S) & SOCKS
-
[1708星][10d] [Ruby] cliffe/secgen Create randomly insecure VMs
-
[1705星][4m] [Py] lgandx/responder Responder is a LLMNR, NBT-NS and MDNS poisoner, with built-in HTTP/SMB/MSSQL/FTP/LDAP rogue authentication server supporting NTLMv1/NTLMv2/LMv2, Extended Security NTLMSSP and Basic HTTP authentication.
-
[1702星][1y] [Java] ac-pm/inspeckage Android Package Inspector - dynamic analysis with api hooks, start unexported activities and more. (Xposed Module)
-
[1695星][1m] [Go] eth0izzle/shhgit 监听Github Event API,实时查找Github代码和Gist中的secret和敏感文件
-
[1694星][3m] [PHP] xtr4nge/fruitywifi FruityWiFi is a wireless network auditing tool. The application can be installed in any Debian based system (Jessie) adding the extra packages. Tested in Debian, Kali Linux, Kali Linux ARM (Raspberry Pi), Raspbian (Raspberry Pi), Pwnpi (Raspberry Pi), Bugtraq, NetHunter.
-
[1694星][3y] [CoffeeScript] okturtles/dnschain A blockchain-based DNS + HTTP server that fixes HTTPS security, and more!
-
[1694星][1y] [Swift] haxpor/potatso Potatso is an iOS client that implements Shadowsocks proxy with the leverage of NetworkExtension framework. ***This project is unmaintained, try taking a look at this fork
-
[1694星][14d] [Go] hashicorp/memberlist Golang package for gossip based membership and failure detection
-
[1693星][8m] [Py] guelfoweb/knock 使用 Wordlist 枚举子域名
-
[1693星][7d] [TSQL] brentozarultd/sql-server-first-responder-kit sp_Blitz, sp_BlitzCache, sp_BlitzFirst, sp_BlitzIndex, and other SQL Server scripts for health checks and performance tuning.
-
[1693星][3m] [Py] anorov/cloudflare-scrape A Python module to bypass Cloudflare's anti-bot page.
-
[1691星][6m] [Py] yelp/osxcollector A forensic evidence collection & analysis toolkit for OS X
-
[1687星][4m] [JS] expressjs/csurf CSRF token middleware
-
[1685星][5m] [C] networkprotocol/netcode.io A protocol for secure client/server connections over UDP
-
[1682星][8m] [Makefile] raspberrypi/noobs NOOBS (New Out Of Box Software) - An easy Operating System install manager for the Raspberry Pi
-
[1682星][1y] owasp/devguide The OWASP Guide
-
[1681星][13d] [HTML] chromium/badssl.com
-
[1681星][9m] [CSS] bagder/http2-explained A detailed document explaining and documenting HTTP/2, the successor to the widely popular HTTP/1.1 protocol
-
[1676星][28d] [Swift] pmusolino/wormholy iOS network debugging, like a wizard 🧙♂️
-
[1675星][4m] [R] briatte/awesome-network-analysis A curated list of awesome network analysis resources.
-
[1674星][2m] [Py] rootm0s/winpwnage UAC bypass, Elevate, Persistence and Execution methods
-
[1668星][7m] [C++] yegord/snowman Snowman反编译器,支持x86, AMD64, ARM。有独立的GUI工具、命令行工具、IDA/Radare2/x64dbg插件,也可以作为库使用
-
[1665星][6m] [C++] microsoft/detours Detours is a software package for monitoring and instrumenting API calls on Windows. It is distributed in source code form.
-
[1662星][12d] selierlin/share-ssr-v2ray
-
[1662星][4y] [Java] dodola/hotfix 安卓App热补丁动态修复框架
-
[1659星][7d] [Java] apache/geode Apache Geode
-
[1655星][6m] [C] easyhook/easyhook The reinvention of Windows API Hooking
-
[1654星][3m] [JS] tylerbrock/mongo-hacker MongoDB Shell Enhancements for Hackers
-
[1653星][2m] [NSIS] angryip/ipscan Angry IP Scanner - fast and friendly network scanner
-
[1651星][7d] [Py] cea-sec/ivre Network recon framework.
-
[1650星][2y] [Shell] juude/droidreverse android 逆向工程工具集
-
[1649星][10m] [JS] evilcos/xssor2 XSS'OR - Hack with JavaScript.
-
[1647星][3m] [Py] boppreh/keyboard Hook and simulate global keyboard events on Windows and Linux.
-
[1646星][8d] roave/securityadvisories ensures that your application doesn't have installed dependencies with known security vulnerabilities
-
[1646星][8d] [JS] ghacksuserjs/ghacks-user.js An ongoing comprehensive user.js template for configuring and hardening Firefox privacy, security and anti-fingerprinting
-
[1645星][3y] [JS] camwiegert/baffle A tiny javascript library for obfuscating and revealing text in DOM elements.
-
[1643星][1m] [C#] jbevain/cecil C#库, 探查/修改/生成 .NET App/库
-
[1641星][1y] [Py] evyatarmeged/raccoon 高性能的侦查和漏洞扫描工具
-
[1641星][6m] dsasmblr/game-hacking Tutorials, tools, and more as related to reverse engineering video games.
-
[1639星][1m] [Py] ehco1996/django-sspanel 用diango开发的全新的shadowsocks网络面板
-
[1637星][13d] [HTML] clong/detectionlab Vagrant & Packer scripts to build a lab environment complete with security tooling and logging best practices
-
[1636星][11m] [Java] fesh0r/fernflower Unofficial mirror of FernFlower Java decompiler (All pulls should be submitted upstream)
-
[1635星][4y] [Py] ctfs/write-ups-2014 Wiki-like CTF write-ups repository, maintained by the community. 2014
-
[1635星][4m] [Java] jaredrummler/androidprocesses DEPRECATED
-
[1635星][4y] [Py] ctfs/write-ups-2014 Wiki-like CTF write-ups repository, maintained by the community. 2014
-
[1629星][9m] tylerha97/awesome-reversing A curated list of awesome reversing resources
-
[1627星][12d] [Go] awnumar/memguard 处理内存中敏感的值,纯Go语言编写。
-
[1627星][9d] sarojaba/awesome-devblog 어썸데브블로그. 국내 개발 블로그 모음(only 실명으로).
-
[1620星][14d] [JS] efforg/privacybadger Privacy Badger is a browser extension that automatically learns to block invisible trackers.
-
[1616星][2y] jhaddix/tbhm The Bug Hunters Methodology
-
[1614星][2m] [Shell] internetwache/gittools find websites with their .git repository available to the public
-
[1612星][4m] [CSS] functionclub/v2ray.fun 正在开发的全新 V2ray.Fun
-
[1611星][2m] [Go] ysrc/yulong-hids 一款由 YSRC 开源的主机入侵检测系统
-
[1610星][7m] [Go] sipt/shuttle A web proxy in Golang with amazing features.
-
[1608星][2y] [JS] addyosmani/a11y Accessibility audit tooling for the web (beta)
-
[1607星][3y] [Makefile] drizzlerisk/drizzledumper 是一款基于内存搜索的Android脱壳工具。
-
[1605星][27d] [PHP] c0ny1/upload-labs 一个帮你总结所有类型的上传漏洞的靶场
-
[1604星][10m] [C] nmikhailov/validity90 Reverse engineering of Validity/Synaptics 138a:0090, 138a:0094, 138a:0097, 06cb:0081, 06cb:009a fingerprint readers protocol
-
[1602星][1y] [Py] nccgroup/scout2 Security auditing tool for AWS environments
-
[1602星][6m] [Py] w1109790800/penetration 渗透 超全面的渗透资料
-
[1600星][8d] [C++] lief-project/lief Library to Instrument Executable Formats
-
[1599星][9m] [JS] localtunnel/server server for localtunnel.me
-
[1596星][5m] [Py] mozilla/cipherscan 查找指定目标支持的SSL ciphersuites
-
[1596星][3m] [Py] knownsec/pocsuite This project has stopped to maintenance, please to
-
[1593星][26d] [Java] tiann/epic Dynamic java method AOP hook for Android(continution of Dexposed on ART), Supporting 4.0~10.0
-
[1588星][13d] [Java] spotbugs/spotbugs SpotBugs is FindBugs' successor. A tool for static analysis to look for bugs in Java code.
-
[1583星][6m] [Ruby] brunofacca/zen-rails-security-checklist Checklist of security precautions for Ruby on Rails applications.
-
[1580星][1y] [C] qihoo360/phptrace A tracing and troubleshooting tool for PHP scripts.
-
[1580星][7d] [Go] bitnami-labs/sealed-secrets A Kubernetes controller and tool for one-way encrypted Secrets
-
[1577星][4y] l3m0n/pentest_study 从零开始内网渗透学习
-
[1577星][1m] [Objective-C] ealeksandrov/provisionql Quick Look plugin for apps and provisioning profile files
-
[1575星][26d] [C] ntop/n2n Peer-to-peer VPN
-
[1574星][22d] ivrodriguezca/re-ios-apps A completely free, open source and online course about Reverse Engineering iOS Applications.
-
[1563星][2y] [C] samyk/pwnat The only tool and technique to punch holes through firewalls/NATs where both clients and server can be behind separate NATs without any 3rd party involvement. Pwnat uses a newly developed technique, exploiting a property of NAT translation tables, with no 3rd party, port forwarding, DMZ, router administrative requirements, STUN/TURN/UPnP/ICE, or…
-
[1563星][12d] [C] codahale/bcrypt-ruby Ruby binding for the OpenBSD bcrypt() password hashing algorithm, allowing you to easily store a secure hash of your users' passwords.
-
[1562星][17d] [C] p-gen/smenu Terminal utility that reads words from standard input or from a file and creates an interactive selection window just below the cursor. The selected word(s) are sent to standard output for further processing.
-
[1560星][14d] [Java] gchq/gaffer A large-scale entity and relation database supporting aggregation of properties
-
[1557星][2m] [C] firmianay/ctf-all-in-one CTF竞赛入门指南
-
[1556星][12d] [Go] caffix/amass 子域名枚举, 搜索互联网数据源, 使用机器学习猜测子域名. Go语言
-
[1555星][1y] [Py] unkl4b/gitminer Github内容挖掘
-
[1552星][12d] [Py] k4m4/kickthemout 使用ARP欺骗,将设备从网络中踢出去
-
[1550星][8m] [Py] m4ll0k/wascan WAScan - Web Application Scanner
-
[1547星][1y] [C] ctfs/write-ups-2016 Wiki-like CTF write-ups repository, maintained by the community. 2016
-
[1545星][6y] [Py] google/pyringe Debugger capable of attaching to and injecting code into python processes.
-
[1544星][1m] [Shell] mzet-/linux-exploit-suggester Linux privilege escalation auditing tool
-
[1544星][3m] [PHP] mewebstudio/captcha Captcha for Laravel 5 & 6
-
[1542星][1m] [Py] joxeankoret/diaphora program diffing
-
[1540星][2y] [C++] hteso/iaito Radare2 GUI,使用Qt和C++
-
[1536星][2y] [Py] awolfly9/ipproxytool python ip proxy tool scrapy crawl. 抓取大量免费代理 ip,提取有效 ip 使用
-
[1533星][2y] [C] ezlippi/webbench Webbench是Radim Kolar在1997年写的一个在linux下使用的非常简单的网站压测工具。它使用fork()模拟多个客户端同时访问我们设定的URL,测试网站在压力下工作的性能,最多可以模拟3万个并发连接去测试网站的负载能力。官网地址:
-
[1532星][13d] [C] raspberrypi/userland Source code for ARM side libraries for interfacing to Raspberry Pi GPU.
-
[1531星][7d] [Py] lifting-bits/mcsema 将x86, amd64, aarch64二进制文件转换成LLVM字节码
-
[1530星][7d] [Go] juju/juju Simple, secure devops tooling built to manage today's complex applications wherever you run your software.
-
[1528星][3y] [Py] x0rz/eqgrp_lost_in_translation ShadowBrokers泄漏
-
[1527星][11d] emijrp/awesome-awesome A curated list of awesome curated lists of many topics.
-
[1525星][10d] [Java] ukanth/afwall AFWall+ (Android Firewall +) - iptables based firewall for Android
-
[1521星][1y] [HTML] qiwihui/hiwifi-ss 极路由+ss配置
-
[1520星][4m] [TypeScript] spring-guides/tut-spring-security-and-angular-js Spring Security and Angular:: A tutorial on how to use Spring Security with a single page application with various backend architectures, ranging from a simple single server to an API gateway with OAuth2 authentication.
-
[1520星][20d] [C++] nmap/npcap Nmap Project's packet sniffing library for Windows, based on WinPcap/Libpcap improved with NDIS 6 and LWF.
-
[1519星][10m] [PowerShell] joefitzgerald/packer-windows 使用Packer创建Vagrant boxes的模板
-
[1516星][9m] [Py] google/rekall Rekall Memory Forensic Framework
-
[1510星][1y] dripcap/dripcap
-
[1509星][21d] [Py] zerosum0x0/koadic 类似于Meterpreter、Powershell Empire 的post-exploitation rootkit,区别在于其大多数操作都是由 Windows 脚本主机 JScript/VBScript 执行
-
[1506星][3y] [Py] sensepost/regeorg The successor to reDuh, pwn a bastion webserver and create SOCKS proxies through the DMZ. Pivot and pwn.
-
[1504星][5m] snowming04/the-hacker-playbook-3-translation 对 The Hacker Playbook 3 的翻译。
-
[1503星][2y] [Py] eldraco/domain_analyzer 通过查找所有能够查找的信息,来分析任意域名的安全性
-
[1501星][25d] [Py] hannob/snallygaster Python脚本, 扫描HTTP服务器"秘密文件"
-
[1500星][2m] [Shell] haugene/docker-transmission-openvpn Docker container running Transmission torrent client with WebUI over an OpenVPN tunnel
-
[1491星][4m] [Py] epinna/tplmap 代码注入和服务器端模板注入(Server-Side Template Injection)漏洞利用,若干沙箱逃逸技巧。
-
[1490星][10d] [YARA] cybermonitor/apt_cybercriminal_campagin_collections APT & CyberCriminal Campaign Collection
-
[1487星][7m] [Py] ahupp/python-magic A python wrapper for libmagic
-
[1485星][2y] [Kotlin] gh0u1l5/wechatmagician WechatMagician is a Xposed module written in Kotlin, that allows you to completely control your Wechat.
-
[1482星][7m] [C++] wangyu-/tinyfecvpn A VPN Designed for Lossy Links, with Build-in Forward Error Correction(FEC) Support. Improves your Network Quality on a High-latency Lossy Link.
-
[1478星][7d] [C] sleuthkit/sleuthkit The Sleuth Kit® (TSK) is a library and collection of command line digital forensics tools that allow you to investigate volume and file system data. The library can be incorporated into larger digital forensics tools and the command line tools can be directly used to find evidence.
-
[1475星][12d] [Py] bitsadmin/wesng Windows Exploit Suggester - Next Generation
-
[1474星][1y] [C++] f1xpl/openauto AndroidAuto headunit emulator
-
[1472星][7d] [Shell] blackarch/blackarch BlackArch Linux is an Arch Linux-based distribution for penetration testers and security researchers.
-
[1468星][16d] [Go] google/keytransparency A transparent and secure way to look up public keys.
-
[1468星][3m] [C] iqiyi/xhook a PLT (Procedure Linkage Table) hook library for Android native ELF
-
[1466星][2m] [C++] jmpews/hookzz a hook framework for arm/arm64/ios/android, and [dev] branch is being refactored.
-
[1465星][3y] [Py] veil-framework/veil-evasion a tool designed to generate metasploit payloads that bypass common anti-virus solutions.
-
[1465星][25d] minimaxir/hacker-news-undocumented Some of the hidden norms about Hacker News not otherwise covered in the Guidelines and the FAQ.
-
[1462星][6y] [C] alibaba/lvs A distribution of Linux Virtual Server with some advanced features. It introduces a new packet forwarding method - FULLNAT other than NAT/Tunneling/DirectRouting, and defense mechanism against synflooding attack - SYNPROXY.
-
[1460星][14d] [C] ufrisk/pcileech 直接内存访问(DMA:Direct Memory Access)攻击工具。通过 PCIe 硬件设备使用 DMA,直接读写目标系统的内存。目标系统不需要安装驱动。
-
[1457星][1y] [C++] acaudwell/logstalgia a visualization tool that replays or streams web server access logs as a retro arcade game simulation.
-
[1456星][27d] [Go] neex/phuip-fpizdam Exploit for CVE-2019-11043
-
[1450星][1y] [Py] d4vinci/cr3dov3r Know the dangers of credential reuse attacks.
-
[1448星][6m] [Py] enablesecurity/wafw00f 识别保护网站的WAF产品
-
[1447星][3m] edoverflow/can-i-take-over-xyz "Can I take over XYZ?" — a list of services and how to claim (sub)domains with dangling DNS records.
-
[1446星][11d] [C++] srslte/srslte Open source SDR LTE software suite from Software Radio Systems (SRS)
-
[1442星][6m] [Py] oros42/imsi-catcher This program show you IMSI numbers of cellphones around you.
-
[1441星][19d] [C] tianocore/edk2 A modern, feature-rich, cross-platform firmware development environment for the UEFI and PI specifications
-
[1441星][1m] [C] ctcaer/hekate Nintendo Switch Bootloader - CTCaer mod
-
[1439星][3y] tiancode/learn-hacking 开始学习Kali Linux 各种破解教程 渗透测试 逆向工程 HackThisSite挑战问题解答
-
[1439星][3y] tiancode/learn-hacking 开始学习Kali Linux 各种破解教程 渗透测试 逆向工程 HackThisSite挑战问题解答
-
[1438星][3m] [C++] vaibhavpandeyvpz/apkstudio Open-source, cross platform Qt based IDE for reverse-engineering Android application packages.
-
[1433星][18d] [Go] skydive-project/skydive An open source real-time network topology and protocols analyzer
-
[1433星][1y] [TypeScript] pedronauck/reworm
-
[1433星][12d] [C++] microsoft/seal Microsoft SEAL is an easy-to-use and powerful homomorphic encryption library.
-
[1430星][7d] [Go] google/gapid Graphics API Debugger
-
[1428星][7d] [Py] rocky/python-uncompyle6 Python反编译器,跨平台
-
[1427星][6m] [C++] x64dbg/scyllahide Advanced usermode anti-anti-debugger
-
[1425星][3m] [Go] google/stenographer Stenographer is a packet capture solution which aims to quickly spool all packets to disk, then provide simple, fast access to subsets of those packets. Discussion/announcements at stenographer@googlegroups.com
-
[1423星][8y] [Py] moxie0/sslstrip A tool for exploiting Moxie Marlinspike's SSL "stripping" attack.
-
[1423星][18d] [Kotlin] cypherpunkarmory/userland The easiest way to run a Linux distribution or application on Android
-
[1422星][2m] [C] feralinteractive/gamemode Optimise Linux system performance on demand
-
[1421星][3y] mandatoryprogrammer/northkoreadnsleak Snapshot of North Korea's DNS data taken from zone transfers.
-
[1421星][4y] [C++] aappleby/smhasher Automatically exported from code.google.com/p/smhasher
-
[1420星][10m] [Java] aslody/legend (Android)无需Root即可Hook Java方法的框架, 支持Dalvik和Art环境
-
[1419星][2m] [Py] neo23x0/loki Loki - Simple IOC and Incident Response Scanner
-
[1419星][3y] [Py] nathanlopez/stitch Python Remote Administration Tool (RAT)
-
[1419星][12d] [Go] google/google-ctf Google CTF
-
[1419星][5y] [C++] gdbinit/machoview MachOView fork
-
[1417星][1m] [Py] xdavidhu/mitmap
-
[1417星][5m] [PHP] s4n7h0/xvwa XVWA is a badly coded web application written in PHP/MySQL that helps security enthusiasts to learn application security.
-
[1416星][1m] [Go] barnybug/cli53 Command line tool for Amazon Route 53
-
[1415星][3y] [C] antirez/dump1090 Dump1090 is a simple Mode S decoder for RTLSDR devices
-
[1413星][7m] [Objective-C] nabla-c0d3/ssl-kill-switch2 Blackbox tool to disable SSL certificate validation - including certificate pinning - within iOS and OS X Apps
-
[1411星][11d] [C] ettercap/ettercap Ettercap Project
-
[1410星][8d] [Go] cosmos72/gomacro Interactive Go interpreter and debugger with REPL, Eval, generics and Lisp-like macros
-
[1409星][4m] yadox666/the-hackers-hardware-toolkit The best hacker's gadgets for Red Team pentesters and security researchers.
-
[1408星][22d] [Java] chrisk44/hijacker Aircrack, Airodump, Aireplay, MDK3 and Reaver GUI Application for Android
-
[1407星][7d] [C] namhyung/uftrace Function (graph) tracer for user-space
-
[1406星][1m] [C++] google/nsjail A light-weight process isolation tool, making use of Linux namespaces and seccomp-bpf syscall filters (with help of the kafel bpf language)
-
[1402星][5m] gitguardian/apisecuritybestpractices Resources to help you keep secrets (API keys, database credentials, certificates, ...) out of source code and remediate the issue in case of a leaked API key. Made available by GitGuardian.
-
[1402星][7d] [C++] eteran/edb-debugger edb is a cross platform AArch32/x86/x86-64 debugger.
-
[1401星][9m] [JS] anttiviljami/browser-autofill-phishing A simple demo of phishing by abusing the browser autofill feature
-
[1400星][3m] [HTML] owasp/top10 Official OWASP Top 10 Document Repository
-
[1400星][1y] [C++] dotnet/llilc This repo contains LLILC, an LLVM based compiler for .NET Core. It includes a set of cross-platform .NET code generation tools that enables compilation of MSIL byte code to LLVM supported platforms.
-
[1399星][25d] [Go] crazy-max/windowsspyblocker
-
[1399星][7d] [Java] chinashiyu/gfw.press GFW.Press新一代军用级高强度加密抗干扰网络数据高速传输软件
-
[1397星][7d] [Rust] shadowsocks/shadowsocks-rust A Rust port of shadowsocks
-
[1395星][1y] [Go] filosottile/whosthere A ssh server that knows who you are
-
[1393星][25d] [C] quiet/org.quietmodem.quiet Quiet for Android - TCP over sound
-
[1393星][3y] [PowerShell] putterpanda/mimikittenz A post-exploitation powershell tool for extracting juicy info from memory.
-
[1391星][22d] [XSLT] lolbas-project/lolbas Living Off The Land Binaries And Scripts - (LOLBins and LOLScripts)
-
[1388星][14d] [Swift] johnno1962/injectioniii Re-write of Injection for Xcode in (mostly) Swift4
-
[1387星][1y] [HTML] gwuhaolin/blog 浩麟的技术博客
-
[1387星][2y] [JS] sqren/fb-sleep-stats 使用Facebook追踪用户的睡觉习惯
-
[1386星][18d] [C++] plasma-umass/coz Finding Code that Counts with Causal Profiling
-
[1384星][4y] [PHP] johntroony/php-webshells Common php webshells. Do not host the file(s) on your server!
-
[1383星][14d] [C++] jonathansalwan/triton Triton is a Dynamic Binary Analysis (DBA) framework. It provides internal components like a Dynamic Symbolic Execution (DSE) engine, a dynamic taint engine, AST representations of the x86, x86-64 and AArch64 Instructions Set Architecture (ISA), SMT simplification passes, an SMT solver interface and, the last but not least, Python bindings.
-
[1383星][8d] [Py] ekultek/whatwaf Detect and bypass web application firewalls and protection systems
-
[1381星][11m] [Py] eth0izzle/bucket-stream 通过certstream 监控多种证书 transparency 日志, 进而查找有趣的 Amazon S3 Buckets
-
[1380星][2m] [C] z3apa3a/3proxy 3proxy - tiny free proxy server
-
[1380星][11d] [Shell] drduh/pwd.sh GPG symmetric password manager
-
[1377星][11d] [OCaml] mirage/mirage MirageOS is a library operating system that constructs unikernels
-
[1376星][6m] [Py] almandin/fuxploider 文件上传漏洞扫描和利用工具
-
[1375星][10m] [JS] intika/librefox Firefox with privacy enhancements
-
[1374星][4y] [C++] valvesoftware/vogl OpenGL capture / playback debugger.
-
[1373星][13d] [C] dynamorio/drmemory Memory Debugger for Windows, Linux, Mac, and Android
-
[1365星][9m] [PowerShell] danielbohannon/invoke-obfuscation PowerShell Obfuscator
-
[1364星][5m] [Py] s0md3v/striker Striker is an offensive information and vulnerability scanner.
-
[1363星][29d] [C] zyantific/zydis 快速的轻量级x86/x86-64 反汇编库
-
[1361星][3y] [C++] aslody/turbodex 在内存中快速加载dex
-
[1360星][6m] [Py] vulnerscom/getsploit Command line utility for searching and downloading exploits
-
[1360星][2m] [Py] fireeye/flare-floss 自动从恶意代码中提取反混淆后的字符串
-
[1358星][7d] [Go] cortesi/modd A flexible developer tool that runs processes and responds to filesystem changes
-
[1357星][24d] [JS] lockfale/osint-framework OSINT Framework
-
[1355星][6m] [C++] phpv8/v8js V8 Javascript Engine for PHP — This PHP extension embeds the Google V8 Javascript Engine
-
[1355星][1m] grrrdog/java-deserialization-cheat-sheet The cheat sheet about Java Deserialization vulnerabilities
-
[1355星][2m] [C] googleprojectzero/winafl A fork of AFL for fuzzing Windows binaries
-
[1348星][23d] [C] x64dbg/x64dbgpy Automating x64dbg using Python, Snapshots:
-
[1348星][4m] [C] taviso/ctftool Interactive CTF Exploration Tool
-
[1348星][3y] [Py] joaomatosf/jexboss Jboss (and Java Deserialization Vulnerabilities) verify and EXploitation Tool
-
[1347星][13d] [Go] unrolled/secure HTTP middleware for Go that facilitates some quick security wins.
-
[1347星][3m] [C++] raspberrypi/tools
-
[1347星][11m] [Rust] das-labor/panopticon A libre cross-platform disassembler.
-
[1346星][3y] [Py] ddevault/evilpass Slightly evil password strength checker
-
[1346星][2y] [HTML] daxeel/blockshell 用于学习区块链技术概念的命令行工具, 例如 likechaining, mining,proof of work 等
-
[1344星][10m] [HTML] thelinuxchoice/blackeye The most complete Phishing Tool, with 32 templates +1 customizable
-
[1343星][5m] [Py] lijiejie/githack git泄露利用脚本,通过泄露的.git文件夹下的文件,重建还原工程源代码
-
[1343星][3m] [Go] hellogcc/100-gdb-tips A collection of gdb tips. 100 maybe just mean many here.
-
[1342星][7d] [Py] mitre/caldera 自动化 adversary emulation 系统
-
[1341星][10d] [Go] securitywithoutborders/hardentools 禁用许多有危险的Windows功能
-
[1341星][2m] [Go] davrodpin/mole cli app to create ssh tunnels
-
[1339星][21d] [Py] s0md3v/arjun HTTP parameter discovery suite.
-
[1339星][12m] [XSLT] api0cradle/lolbas Living Off The Land Binaries And Scripts - (LOLBins and LOLScripts)
-
[1338星][21d] [Go] microcosm-cc/bluemonday a fast golang HTML sanitizer (inspired by the OWASP Java HTML Sanitizer) to scrub user generated content of XSS
-
[1338星][7m] [Py] feeicn/gsil GitHub敏感信息泄露监控,几乎实时监控,发送警告
-
[1337星][1y] [Py] carmaa/inception 利用基于PCI的DMA实现物理内存的操纵与Hacking,可以攻击FireWire,Thunderbolt,ExpressCard,PC Card和任何其他PCI / PCIe硬件接口
-
[1336星][6y] [Perl] intelisecurelabs/linux_exploit_suggester Linux Exploit Suggester; based on operating system release number
-
[1336星][3m] [Py] maratyszcza/peachpy x86-64 assembler embedded in Python
-
[1333星][17d] [C++] rikkaapps/riru Inject zygote process by replace libmemtrack
-
[1331星][2m] [C++] mfontanini/libtins High-level, multiplatform C++ network packet sniffing and crafting library.
-
[1331星][1y] [C] gamelinux/passivedns A network sniffer that logs all DNS server replies for use in a passive DNS setup
-
[1329星][1m] [CSS] undeadsec/socialfish 网络钓鱼培训与信息收集
-
[1329星][10m] rebeyond/behinder “冰蝎”动态二进制加密网站管理客户端
-
[1329星][1y] kirikira/vtemplate v2ray的模板们
-
[1328星][1y] [C] madeye/proxydroid Global Proxy for Android
-
[1326星][11d] [C++] purplei2p/i2pd a full-featured C++ implementation of I2P client
-
[1324星][2y] [CoffeeScript] atmos/camo all about making insecure assets look secure
-
[1323星][1y] [Py] marten4n6/evilosx An evil RAT (Remote Administration Tool) for macOS / OS X.
-
[1322星][3m] [HTML] thehive-project/thehive a Scalable, Open Source and Free Security Incident Response Platform
-
[1321星][6m] [Go] ssllabs/ssllabs-scan A command-line reference-implementation client for SSL Labs APIs, designed for automated and/or bulk testing.
-
[1321星][1y] [C++] rehints/hexrayscodexplorer 反编译插件, 多功能
查看详情
- 自动类型重建 - 虚表识别/导航(反编译窗口) - C-tree可视化与导出 - 对象浏览 </details> -
[1318星][2m] jaredthecoder/awesome-vehicle-security
-
[1315星][1y] mortenoir1/virtualbox_e1000_0day VirtualBox E1000 Guest-to-Host Escape
-
[1312星][12d] [C] oisf/suricata a network IDS, IPS and NSM engine
-
[1311星][2y] [Py] worawit/ms17-010 MS17-010
-
[1311星][18d] [C] intel/haxm Intel 开源的英特尔硬件加速执行管理器,通过硬件辅助的虚拟化引擎,加速 Windows/macOS 主机上的 IA emulation((x86/ x86_64) )
-
[1310星][3m] [PowerShell] peewpw/invoke-psimage Encodes a PowerShell script in the pixels of a PNG file and generates a oneliner to execute
-
[1310星][10m] [C] fancycode/memorymodule Library to load a DLL from memory.
-
[1309星][10m] [C#] cenmrev/v2rayw GUI for v2ray-core on Windows
-
[1305星][12m] [Py] xyntax/poc-t 脚本调用框架,用于渗透测试中 采集|爬虫|爆破|批量PoC 等需要并发的任务
-
[1305星][3m] [Lua] scipag/vulscan Nmap 模块,将 Nmap 转化为高级漏洞扫描器
-
[1305星][18d] [C] dtag-dev-sec/tpotce 创建多蜜罐平台T-Pot ISO 镜像
-
[1303星][17d] [Py] consensys/mythril Security analysis tool for EVM bytecode. Supports smart contracts built for Ethereum, Quorum, Vechain, Roostock, Tron and other EVM-compatible blockchains.
-
[1303星][15d] nikitavoloboev/privacy-respecting PrivacyRespecting 服务和软件列表
-
[1303星][4m] [C++] klee/klee 基于 LLVM 的 symbolic 虚拟机
-
[1300星][18d] [C] cisco-talos/pyrebox 逆向沙箱,基于QEMU,Python Scriptable
-
[1297星][1y] [Go] evilsocket/xray 自动化执行一些信息收集、网络映射的初始化工作
-
[1293星][1y] [Shell] dana-at-cp/backdoor-apk backdoor-apk is a shell script that simplifies the process of adding a backdoor to any Android APK file. Users of this shell script should have working knowledge of Linux, Bash, Metasploit, Apktool, the Android SDK, smali, etc. This shell script is provided as-is without warranty of any kind and is intended for educational purposes only.
-
[1291星][27d] [Java] android-hacker/exposed A library to use Xposed without root or recovery(or modify system image etc..).
-
[1290星][2y] [Go] malfunkt/hyperfox 在局域网上代理和记录 HTTP 和 HTTPs 通信
-
[1289星][2m] [C] traviscross/mtr Official repository for mtr, a network diagnostic tool
-
[1288星][4y] [C++] microsoft/microsoft-pdb Microsoft提供的有关PDB格式的信息
-
[1287星][19d] [JS] icymind/vrouter 一个基于 VirtualBox 和 openwrt 构建的项目, 旨在实现 macOS / Windows 平台的透明代理.
-
[1284星][2m] [Py] virtualabs/btlejack Bluetooth Low Energy Swiss-army knife
-
[1284星][5m] [JS] feross/spoof Easily spoof your MAC address in macOS, Windows, & Linux!
-
[1278星][9m] michalmalik/linux-re-101 Linux逆向资源收集
-
[1278星][4y] [Py] elvanderb/tcp-32764 some codes and notes about the backdoor listening on TCP-32764 in linksys WAG200G.
-
[1277星][10d] [PHP] friendsofphp/security-advisories A database of PHP security advisories
-
[1277星][27d] [Go] dreadl0ck/netcap A framework for secure and scalable network traffic analysis -
-
[1275星][24d] [Py] viper-framework/viper Binary analysis and management framework
-
[1273星][1m] [Py] pyauth/pyotp Python One-Time Password Library
-
[1273星][2m] [Py] codingo/reconnoitre A security tool for multithreaded information gathering and service enumeration whilst building directory structures to store results, along with writing out recommendations for further testing.
-
[1272星][1y] [JS] sakurity/securelogin 针对网站和App的去中心化的认证协议
-
[1270星][2m] [C] seemoo-lab/nexmon The C-based Firmware Patching Framework for Broadcom/Cypress WiFi Chips that enables Monitor Mode, Frame Injection and much more
-
[1270星][1y] [PowerShell] dafthack/mailsniper 在Microsoft Exchange环境中搜索邮件中包含的指定内容:密码、insider intel、网络架构信息等
-
[1270星][1m] [Py] bethgelab/foolbox Python toolbox to create adversarial examples that fool neural networks in PyTorch, TensorFlow, Keras, …
-
[1268星][2m] [Java] googlearchive/android-runtimepermissions This sample has been deprecated/archived. Check this repo for related samples:
-
[1268星][1y] [Py] ethereum/pyethapp
-
[1266星][2m] [Py] ganapati/rsactftool RSA攻击工具,主要用于CTF,从弱公钥和/或uncipher数据中回复私钥
-
[1265星][9d] [Shell] firehol/blocklist-ipsets ipsets dynamically updated with firehol's update-ipsets.sh script
-
[1265星][9d] [Shell] firehol/blocklist-ipsets ipsets dynamically updated with firehol's update-ipsets.sh script
-
[1262星][3m] [Go] solo-io/squash The debugger for microservices
-
[1261星][3m] [Py] alessandroz/beroot Privilege Escalation Project - Windows / Linux / Mac
-
[1259星][11m] [Py] unapibageek/ctfr Abusing Certificate Transparency logs for getting HTTPS websites subdomains.
-
[1255星][7m] [PHP] ganlvtech/down_52pojie_cn A single page file explorer that can be hosted on static website. 吾爱破解论坛 爱盘
-
[1255星][13d] [C] aircrack-ng/aircrack-ng WiFi security auditing tools suite
-
[1253星][2y] [JS] samyk/skyjack A drone engineered to autonomously seek out, hack, and wirelessly take full control over any other Parrot or 3DR drones within wireless or flying distance, creating an army of zombie drones under your control.
-
[1250星][1m] [PowerShell] hak5/bashbunny-payloads The Official Bash Bunny Payload Repository
-
[1248星][2y] [Py] vaguileradiaz/tinfoleak Twitter 智能分析工具
-
[1248星][4m] [JS] bubenshchykov/ngrok Expose your localhost to the web. Node wrapper for ngrok.
-
[1245星][2m] [Go] xiaoming2028/freenet 科学上网/梯子/自由上网/翻墙 SSR/V2Ray/Brook 最全搭建教程
-
[1245星][15d] [JS] archerysec/archerysec Centralize Vulnerability Assessment and Management for DevSecOps Team
-
[1244星][2y] [Objective-C] krausefx/detect.location An easy way to access the user's iOS location data without actually having access
-
[1242星][4y] firesuncn/bluelotus_xssreceiver XSS平台 CTF工具 Web安全工具
-
[1242星][1m] [Vue] chaitin/passionfruit iOSapp 黑盒评估工具。功能丰富,自带基于web的 GUI
-
[1241星][1y] [Ruby] eliotsykes/rails-security-checklist
-
[1240星][10m] [C] a0rtega/pafish Pafish is a demonstration tool that employs several techniques to detect sandboxes and analysis environments in the same way as malware families do.
-
[1239星][2m] michalmalik/osx-re-101 OSX/iOS逆向资源收集
-
[1235星][1m] [Go] hacklcx/hfish 扩展企业安全测试主动诱导型开源蜜罐框架系统,记录黑客攻击手段
-
[1235星][2m] [Go] google/martian Martian is a library for building custom HTTP/S proxies
-
[1232星][3m] [Shell] rootsongjc/kubernetes-vagrant-centos-cluster Setting up a distributed Kubernetes cluster along with Istio service mesh locally with Vagrant and VirtualBox, only PoC or Demo use.
-
[1231星][3y] [Py] desaster/kippo Kippo - SSH Honeypot
-
[1230星][7d] [Shell] mitchellkrogza/nginx-ultimate-bad-bot-blocker Nginx Block Bad Bots, Spam Referrer Blocker, Vulnerability Scanners, User-Agents, Malware, Adware, Ransomware, Malicious Sites, with anti-DDOS, Wordpress Theme Detector Blocking and Fail2Ban Jail for Repeat Offenders
-
[1230星][5m] chalker/notes Some public notes
-
[1228星][1y] [Kotlin] gh0u1l5/wechatspellbook 一个使用Kotlin编写的开源微信插件框架,底层需要 Xposed 或 VirtualXposed 等Hooking框架的支持,而顶层可以轻松对接Java、Kotlin、Scala等JVM系语言。让程序员能够在几分钟内编写出简单的微信插件,随意揉捏微信的内部逻辑。
-
[1228星][8m] [Py] flipkart-incubator/astra 自动化的REST API安全测试脚本
-
[1224星][1m] [C] datatheorem/trustkit Easy SSL pinning validation and reporting for iOS, macOS, tvOS and watchOS.
-
[1223星][3y] [CoffeeScript] shadowsocks/shadowsocks-nodejs
-
[1222星][3y] [C] tsudakageyu/minhook The Minimalistic x86/x64 API Hooking Library for Windows
-
[1222星][27d] [C++] nasa-sw-vnv/ikos Static analyzer for C/C++ based on the theory of Abstract Interpretation.
-
[1222星][1y] [Py] danmcinerney/net-creds Sniffs sensitive data from interface or pcap
-
[1220星][1y] [Go] cloudflare/redoctober Go server for two-man rule style file encryption and decryption.
-
[1219星][5y] cure53/xsschallengewiki Welcome to the XSS Challenge Wiki!
-
[1219星][4m] [Py] owtf/owtf 进攻性 Web 测试框架。着重于 OWASP + PTES,尝试统合强大的工具,提高渗透测试的效率。大部分以Python 编写
-
[1218星][11d] [Py] google/timesketch Collaborative forensic timeline analysis
-
[1218星][26d] [Java] find-sec-bugs/find-sec-bugs The SpotBugs plugin for security audits of Java web applications and Android applications. (Also work with Kotlin, Groovy and Scala projects)
-
[1218星][5y] cure53/xsschallengewiki Welcome to the XSS Challenge Wiki!
-
[1217星][1y] [C#] cn33liz/p0wnedshell PowerShell Runspace Post Exploitation Toolkit
-
[1216星][26d] [Go] jsha/minica minica is a small, simple CA intended for use in situations where the CA operator also operates each host where a certificate will be used.
-
[1212星][10d] [C] dynamorio/dynamorio Dynamic Instrumentation Tool Platform
-
[1207星][8d] [JS] jpcertcc/logontracer 通过可视化和分析Windows事件日志来调查恶意的Windows登录
-
[1205星][3m] [Java] javiersantos/piracychecker An Android library that prevents your app from being pirated / cracked using Google Play Licensing (LVL), APK signature protection and more. API 14+ required.
-
[1204星][7d] [Objective-C] onionbrowser/onionbrowser An open-source, privacy-enhancing web browser for iOS, utilizing the Tor anonymity network
-
[1204星][3m] [JS] davidbau/seedrandom seeded random number generator for Javascript
-
[1203星][30d] [Py] codingo/nosqlmap Automated NoSQL database enumeration and web application exploitation tool.
-
[1201星][7d] [Java] linkedin/dexmaker A utility for doing compile or runtime code generation targeting Android's Dalvik VM
-
[1200星][3m] [C] droe/sslsplit 透明SSL/TLS拦截
-
[1199星][1y] felixgr/secure-ios-app-dev iOSApp 最常见漏洞收集
-
[1198星][24d] [Py] thekingofduck/fuzzdicts Web Pentesting Fuzz 字典,一个就够了。
-
[1196星][1y] [Go] rancher/convoy A Docker volume plugin, managing persistent container volumes.
-
[1194星][2y] [C] saminiir/level-ip a Linux userspace TCP/IP stack, implemented with TUN/TAP devices.
-
[1194星][7m] riusksk/secbook 信息安全从业者书单推荐
-
[1193星][18d] [Py] cve-search/cve-search 导入CVE/CPE 到本地 MongoDB 数据库,以便后续在本地进行搜索和处理
-
[1192星][17d] [YARA] horsicq/detect-it-easy Program for determining types of files for Windows, Linux and MacOS.
-
[1191星][6y] gdbinit/gdbinit Gdbinit for OS X, iOS and others - x86, x86_64 and ARM
Folders and files
| Name | Name | Last commit date | ||
|---|---|---|---|---|