Skip to content
View notwhy's full-sized avatar

Block or report notwhy

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Please don't include any personal information such as legal names or email addresses. Maximum 100 characters, markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse

Starred repositories

Showing results

📦 Make security testing of K8s, Docker, and Containerd easier.

Go 3,975 548 Updated Nov 15, 2024

利用 Exchange 服务器 Web 接口爆破邮箱账户 | Brute force email accounts using Exchange server web endpoints

Go 84 8 Updated Sep 13, 2024

内网渗透过程中搜寻指定文件内容,从而找到突破口的一个小工具

Python 292 24 Updated Aug 12, 2024

给woodpecker框架量身定制的ysoserial

Java 532 71 Updated Oct 26, 2022

ARL官方仓库备份项目:ARL(Asset Reconnaissance Lighthouse)资产侦察灯塔系统旨在快速侦察与目标关联的互联网资产,构建基础资产信息库。 协助甲方安全团队或者渗透测试人员有效侦察和检索资产,发现存在的薄弱点和攻击面。

Python 1,179 576 Updated Dec 7, 2024

基于ARL-V2.6.2修改后的版本

Shell 774 122 Updated Nov 8, 2024

Linux应急处置/信息搜集/漏洞检测工具,支持基础配置/网络流量/任务计划/环境变量/用户信息/Services/bash/恶意文件/内核Rootkit/SSH/Webshell/挖矿文件/挖矿进程/供应链/服务器风险等13类70+项检查

Shell 1,841 399 Updated Jun 19, 2024

Neo-reGeorg is a project that seeks to aggressively refactor reGeorg

Python 2,925 448 Updated Sep 23, 2024

蓝队应急工具

YARA 452 48 Updated Jun 10, 2024

Jar Analyzer - 一个JAR包分析工具,批量分析,SCA漏洞分析,方法调用关系搜索,字符串搜索,Spring组件分析,信息泄露检查,CFG程序分析,JVM栈帧分析,进阶表达式搜索,字节码指令级的动态调试分析,反编译JAR包一键导出,一键提取序列化数据恶意代码,一键分析BCEL字节码

Java 1,228 108 Updated Dec 8, 2024

对原版https://github.com/feihong-cs/JNDIExploit 进行了实用化修改

Java 17 Updated Apr 19, 2022

80+ Gadgets(30 More than ysoserial). JNDI-Injection-Exploit-Plus is a tool for generating workable JNDI links and provide background services by starting RMI server,LDAP server and HTTP server.

Java 735 99 Updated Jun 24, 2024
Python 140 31 Updated Nov 14, 2020

Burp extension to evade TLS fingerprinting. Bypass WAF, spoof any browser.

Java 1,279 78 Updated Nov 10, 2024

Memshell-攻防内存马研究

Java 671 90 Updated Mar 1, 2024

FastJson全版本Docker漏洞环境(涵盖1.2.47/1.2.68/1.2.80等版本),主要包括JNDI注入及高版本绕过、waf绕过、文件读写、原生反序列化、利用链探测绕过、不出网利用等。从黑盒的角度覆盖FastJson深入利用

Python 888 108 Updated Jul 12, 2024

🐱‍💻 ✂️ 🤬 CVE-2021-44228 - LOG4J Java exploit - WAF bypass tricks

Java 935 142 Updated Jan 15, 2022

通过jsp脚本扫描java web Filter/Servlet型内存马

Java 856 123 Updated Mar 9, 2023

Find secrets in your codebase

Python 121 35 Updated Nov 6, 2024

Webshell

PHP 140 133 Updated Nov 21, 2016

fastjson利用,支持tomcat、spring回显,哥斯拉内存马;回显利用链为dhcp、ibatis、c3p0。

258 12 Updated Mar 15, 2022

ThinkPHP漏洞综合利用工具, 图形化界面, 命令执行, 一键getshell, 批量检测, 日志遍历, session包含,宝塔绕过

PHP 691 101 Updated Jul 2, 2022

Subdomain enumeration tool, asynchronous dns packets, use pcap to scan 1600,000 subdomains in 1 second

Go 894 132 Updated Aug 31, 2024

A fast, simple, recursive content discovery tool written in Rust.

Rust 6,058 504 Updated Sep 15, 2024

captcha-killer的修改版,支持关键词识别base64编码的图片,添加免费ocr库,用于验证码爆破,适配新版Burpsuite

Java 1,541 147 Updated Nov 20, 2024

一款支持自定义的 Java 内存马生成工具|A customizable Java in-memory webshell generation tool.

Java 1,720 193 Updated Nov 16, 2024

渗透测试、红蓝攻防、代码审计基础环境搭建

72 12 Updated Oct 24, 2024
Python 31 4 Updated Dec 28, 2023

A subdomain fuzzing tool

Python 150 35 Updated Jun 1, 2024

CaA - Collector and Analyzer, Insight into information, exploring with intelligence in a thousand ways.

Java 849 55 Updated Sep 26, 2024
Next