EsdEnumeration sub domains(枚举子域名)
Rapidscan🆕 The Multi-Tool Web Vulnerability Scanner.
Dumpsterfire"Security Incidents In A Box!" A modular, menu-driven, cross-platform tool for building customized, time-delayed, distributed security events. Easily create custom event chains for Blue- & Red Team drills and sensor / alert mapping. Red Teams can create decoy incidents, distractions, and lures to support and scale their operations. Build event sequences ("narratives") to simulate realistic scenarios and generate corresponding network and filesystem artifacts.
EvillimiterTool that monitors, analyzes and limits the bandwidth of devices on the local network without administrative access.
VhostscanA virtual host scanner that performs reverse lookups, can be used with pivot tools, detect catch-all scenarios, work around wildcards, aliases and dynamic default pages.
InterlaceEasily turn single threaded command line applications into a fast, multi-threaded application with CIDR and glob support.
ScapyScapy: the Python-based interactive packet manipulation program & library. Supports Python 2 & Python 3.
Grauditgrep rough audit - source code auditing tool
Bypass Firewalls By Dns HistoryFirewall bypass script based on DNS history records. This script will search for DNS A history records and check if the server replies for that domain. Handy for bugbounty hunters.
BluespawnAn Active Defense and EDR software to empower Blue Teams
BrakemanA static analysis security vulnerability scanner for Ruby on Rails applications
DiamorphineLKM rootkit for Linux Kernels 2.6.x/3.x/4.x/5.x (x86/x86_64 and ARM64)
ExploitpackExploit Pack -The next generation exploit framework
InqlInQL - A Burp Extension for GraphQL Security Testing
Fail2banDaemon to ban hosts that cause multiple authentication errors
Gg ShieldDetect secret in source code, scan your repo for leaks. Find secrets with GitGuardian and prevent leaked credentials. GitGuardian is an automated secrets detection & remediation service.
StacoanStaCoAn is a crossplatform tool which aids developers, bugbounty hunters and ethical hackers performing static code analysis on mobile applications.
R0akr0ak ("roak") is the Ring 0 Army Knife -- A Command Line Utility To Read/Write/Execute Ring Zero on for Windows 10 Systems
WhalerProgram to reverse Docker images into Dockerfiles
Sentinel AttackTools to rapidly deploy a threat hunting capability on Azure Sentinel that leverages Sysmon and MITRE ATT&CK
SwiftnessxA cross-platform note-taking & target-tracking app for penetration testers.
Red BaronAutomate creating resilient, disposable, secure and agile infrastructure for Red Teams.
Jok3rJok3r v3 BETA 2 - Network and Web Pentest Automation Framework
Embaemba - An analyzer for Linux-based firmware of embedded devices.
Articles Translator📚Translate the distinct technical blogs. Please star or watch. Welcome to join me.
Git HoundReconnaissance tool for GitHub code search. Finds exposed API keys using pattern matching, commit history searching, and a unique result scoring system.
HashviewA web front-end for password cracking and analytics
Terraform Aws Secure BaselineTerraform module to set up your AWS account with the secure baseline configuration based on CIS Amazon Web Services Foundations and AWS Foundational Security Best Practices.
MonkeyInfection Monkey - An automated pentest tool
Kube Scankube-scan: Octarine k8s cluster risk assessment tool
IosMost usable tools for iOS penetration testing
Jsprimea javascript static security analysis tool
CyphonOpen source incident management and response platform.
SipviciousSIPVicious OSS is a set of security tools that can be used to audit SIP based VoIP systems.
SkyarkSkyArk helps to discover, assess and secure the most privileged entities in Azure and AWS
Dexcalibur[Official] Android reverse engineering tool focused on dynamic instrumentation automation. Powered by Frida. It disassembles dex, analyzes it statically, generates hooks, discovers reflected methods, stores intercepted data and does new things from it. Its aim is to be an all-in-one Android reverse engineering platform.
Npq🎖safely* install packages with npm or yarn by auditing them as part of your install process
YasuoA ruby script that scans for vulnerable & exploitable 3rd-party web applications on a network
Security ToolsCollection of small security tools, mostly in Bash and Python. CTFs, Bug Bounty and other stuff.
Stowaway👻Stowaway -- Multi-hop Proxy Tool for pentesters
MxtractmXtract - Memory Extractor & Analyzer
Vulscanvulscan 扫描系统:最新的poc&exp漏洞扫描,redis未授权、敏感文件、java反序列化、tomcat命令执行及各种未授权扫描等...
GobyAttack surface mapping
TracyA tool designed to assist with finding all sinks and sources of a web application and display these results in a digestible manner.
SalusSecurity scanner coordinator