实战 SRC / 众测 / Bug bounty 漏洞挖掘 Claude Code skill — 19 个攻击类 playbook、305 个结构化 payload、263 个 WAF/EDR 绕过、2887 份 HackerOne 真实案例、88,636 WooYun 案例统计
☆360May 24, 2026Updated 2 weeks ago
Alternatives and similar repositories for src-hunter-skill
Users that are interested in src-hunter-skill are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- 高版本java各种JNDI Bypass方法复现+相应RMI服务端代码☆14Mar 23, 2024Updated 2 years ago
- AutoFuzz是一款安全测试的辅助型BurpSuite插件,主要用于自动识别请求中的参数,根据预设的payload逐个发包测试,从而提高测试效率。☆117Jun 2, 2025Updated last year
- Use Rust to implement some Red Team techniques :)☆13Nov 11, 2024Updated last year
- 黑客神器,谁用谁知道!☆10Jul 10, 2019Updated 6 years ago
- Xia_Yue_Plus 瞎越 增强版☆77Aug 20, 2025Updated 9 months ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- 添加识别与检测异步js逻辑☆24Aug 26, 2025Updated 9 months ago
- Move 语言中文白皮书 以及各类Move相关中文白皮书☆12Sep 17, 2022Updated 3 years ago
- ☆32May 27, 2024Updated 2 years ago
- GoFinger是一款专为红队攻防和企业资产管理设计的下一代web指纹发现、指纹识别工具。基于 Go 语言开发,它不仅继承了传统指纹工具的识别能力,更在性能、可扩展性和输出质量上进行了深度优化。 它旨在帮助安全工程师和渗透测试人员快速、精准地识别网络资产指纹,并以美观、易…☆40Nov 27, 2025Updated 6 months ago
- SAMR修改域内主机密码☆10Feb 27, 2022Updated 4 years ago
- Fastjson姿势技巧集合☆13Sep 18, 2022Updated 3 years ago
- cobaltstrike4.5版本破解、去除checksum8特征、bypass BeaconEye、修复错误路径泄漏stage、增加totp双因子验证、修复CVE-2022-39197等☆18Sep 26, 2022Updated 3 years ago
- ☆11Jan 16, 2018Updated 8 years ago
- Directory Traversal Scanner 是一个高性能的目录遍历漏洞扫描工具,专门用于检测和验证 Web 应用程序中的路径遍历漏洞。通过异步并发扫描和智能 WAF 绕过技术,帮助安全研究人员快速发现潜在的安全隐患。Directory Traversal Sca…☆34Mar 28, 2025Updated last year
- Managed Kubernetes at scale on DigitalOcean • AdDigitalOcean Kubernetes includes the control plane, bandwidth allowance, container registry, automatic updates, and more for free.
- 🔍 CodeAuditAssistant - JetBrains Code Audit Plugin (Beta) ⚡ Deep Call-Chain Tracking | 🚀 Method/Class Search | 🔥 Prebuilt Vuln Sink…☆785Mar 14, 2026Updated 2 months ago
- 蓝队工具,一款小白都能用的Windows溯源Tools,支持AI一键分析☆67Nov 25, 2025Updated 6 months ago
- 用java实现构造openwire协议,利用activeMQ < 5.18.3 RCE 回显利用 内存马注入☆290Nov 20, 2023Updated 2 years ago
- ☆20Aug 27, 2024Updated last year
- 闭源系统半自动漏洞挖掘工具,针对 jar/war/zip 进行静态代码分析,输出从source到sink的可达路径。LLM将验证路径可达性,并根据上下文给出该路径可信分数☆508Jan 12, 2026Updated 4 months ago
- 基于python3编写的简易xss接受平台☆12May 3, 2025Updated last year
- a component of red teaming for generate route map.☆11Aug 30, 2024Updated last year
- Burpsuite验证码DOS攻击插件。☆21Oct 24, 2024Updated last year
- Script Hook☆81May 18, 2025Updated last year
- Managed Database hosting by DigitalOcean • AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- 一个轮子,用于渗透测试优化的 DNS/HTTP 日志工具,简洁、轻便、更易于使用。☆16Sep 29, 2024Updated last year
- 一个由AI运维的网络安全Skill知识库☆134May 16, 2026Updated 3 weeks ago
- riverPass 是一个用Go编写的瑞数WAF绕过工具。它利用了WebSocket协议,将请求发送的自身浏览器中,从而绕过了瑞数WAF的检测。☆234Oct 18, 2024Updated last year
- ☆11Jul 27, 2023Updated 2 years ago
- 命令执行不回显但DNS协议出网的命令回显场景解决方案(修改为使用ceye接收请求,添加自定义DNS服务器)☆292Aug 20, 2023Updated 2 years ago
- VMWare vRealize SSRF-CVE-2021-21975☆12Apr 2, 2021Updated 5 years ago
- 让"WAF绕过"变得简单☆437Jan 26, 2025Updated last year
- BpArsenal, a Burp Suite plugin that can quickly convert http requests into command-line tool execution, launch third-party tools and open…☆22Oct 31, 2025Updated 7 months ago
- javaeasyscanner - 富婆系列,代码审计辅助工具,致力于解放大脑,方便双手☆277Jun 18, 2024Updated last year
- GPUs on demand by Runpod - Special Offer Available • AdRun AI, ML, and HPC workloads on powerful cloud GPUs—without limits or wasted spend. Deploy GPUs in under a minute and pay by the second.
- 一个集合了多种语言的实战化Web靶场 | A practical Web shooting range that integrates multiple languages☆84Feb 10, 2026Updated 3 months ago
- 收集ctf题目☆24Dec 10, 2022Updated 3 years ago
- 腾讯安全沙龙 一 二 三 期PPT集合☆19May 24, 2025Updated last year
- golang 实现的windows and linux 端口复用工具。☆309Jan 30, 2024Updated 2 years ago
- burpsuit插件,解析swagger/openapi接口文档并进行请求,模拟参数方便渗透测试人员快速发现可用接口 (最新使用源码编译,release有时候没空搞)☆45Oct 23, 2025Updated 7 months ago
- v1版本 尚不成熟☆18Mar 26, 2024Updated 2 years ago
- Default locations for files on various Linux distros.☆10May 12, 2021Updated 5 years ago