cwkiller / Pentest_DicView external linksLinks
自己收集整理自用的字典
☆239Jun 9, 2023Updated 2 years ago
Alternatives and similar repositories for Pentest_Dic
Users that are interested in Pentest_Dic are comparing it to the libraries listed below
Sorting:
- 参数 | 字典 collections☆671Apr 20, 2021Updated 4 years ago
- 对目标域名进行快速的存活扫描、简单的指纹识别、目录扫描☆915Dec 8, 2022Updated 3 years ago
- 递归式寻找域名和api。☆724Aug 3, 2023Updated 2 years ago
- 构建优化高效的渗透 fuzz 字典合集☆1,883Jun 17, 2025Updated 7 months ago
- 通达OA综合利用工具☆516Mar 17, 2021Updated 4 years ago
- JNDI服务利用工具 RMI/LDAP,支持部分场景回显、内存shell,高版本JDK场景下利用等,fastjson rce命令执行,log4j rce命令执行 漏洞检测辅助工具☆2,011May 21, 2024Updated last year
- Bypass firewall for traffic forwarding using webshell☆1,432Sep 29, 2021Updated 4 years ago
- 扫描常见未授权访问(redis、mongodb、memcached、elasticsearch、zookeeper、ftp、CouchDB、docker、Hadoop)☆191Apr 24, 2020Updated 5 years ago
- 一款针对向日葵的识别码和验证码提取工具☆923Nov 1, 2021Updated 4 years ago
- GoScan是采用Golang语言编写的一款分布式综合资产管理系统,适合红队、SRC等使用☆717May 6, 2021Updated 4 years ago
- Collect JSP webshell of various implementation methods. 梳理和发现的JSP Webshell各种姿势☆1,404Jan 18, 2022Updated 4 years ago
- fastjson漏洞burp插件,检测fastjson<1.2.68基于dnslog,fastjson<=1.2.24和1.2.33<=fatjson<=1.2.47的不出网检测和TomcatEcho,SpringEcho回显方案。☆124May 14, 2021Updated 4 years ago
- 渗透测试,渗透测试小技巧,渗透测试Tips,师傅们跟我一起维护更新吧~☆876Jun 8, 2021Updated 4 years ago
- 对密码已保存在 Windwos 系统上的部分程序进行解析,包括:Navicat,TeamViewer,FileZilla,WinSCP,Xmangager系列产品(Xshell,Xftp)。源码:https://github.com/RowTeam/SharpDecrypt…☆1,261Mar 16, 2022Updated 3 years ago
- 一款可以在不出网的环境下进行反向代理及cs上线的工具☆491Apr 26, 2023Updated 2 years ago
- Web Fuzzing Box - Web 模糊测试字典与一些Payloads☆2,442May 28, 2025Updated 8 months ago
- 一个全新的敏感文件发现工具☆28Jan 7, 2021Updated 5 years ago
- Dictionary collection project such as Pentesing, Fuzzing, Bruteforce and BugBounty. 渗透测试、SRC漏洞挖掘、爆破、Fuzzing等字典收集项目。☆2,028Jul 21, 2023Updated 2 years ago
- 将域名转为ip段权重☆215Mar 14, 2023Updated 2 years ago
- 上传漏洞fuzz字典生成脚本☆1,271Apr 1, 2021Updated 4 years ago
- 一个简单的现代化公司域名使用规律预测及生成工具☆390Feb 24, 2022Updated 3 years ago
- Shiro<=1.2.4反序列化,一键检测工具☆989Mar 4, 2021Updated 4 years ago
- Ary 是一个集成类工具,主要用于调用各种安全工具,从而形成便捷的一键式渗透。☆341Feb 15, 2021Updated 4 years ago
- CobaltStrike后渗透测试插件☆1,554Oct 28, 2021Updated 4 years ago
- 这是一个用于IP和域名碰撞匹配访问的小工具,旨意用来匹配出渗透过程中需要绑定hosts才能访问的弱主机或内部系统。☆1,189Apr 30, 2019Updated 6 years ago
- domain_hunter的高级版本,SRC挖洞、HW打点之必备!自动化资产收集;快速Title获取;外部工具联动;等等☆2,116Jan 23, 2026Updated 3 weeks ago
- AK资源管理工具,阿里云/腾讯云/华为云/AWS/UCLOUD/京东云/百度云/七牛云存储/火山引擎 AccessKey AccessKeySecret,利用AK获取资源信息和操作资源,ECS/CVM/E2/UHOST/ECI/BCC执行命令,OSS/COS/S3/BOS…☆775Feb 13, 2025Updated last year
- A Swagger API Exploit☆1,371Jun 7, 2024Updated last year
- 红队综合渗透框架☆1,179May 11, 2023Updated 2 years ago
- 致远OA综合利用工具☆418Jun 3, 2021Updated 4 years ago
- 服务端配置错误情况下用于伪造ip地址进行测试的Burp Suite插件☆1,640Sep 29, 2022Updated 3 years ago
- 影子用户 克隆☆232Dec 30, 2021Updated 4 years ago
- BurpBounty 魔改版本☆418Mar 21, 2022Updated 3 years ago
- 弱口令,敏感目录,敏感文件等渗透测试常用攻击字典☆1,204Dec 16, 2021Updated 4 years ago
- 记录自己编写、修改的部分工具☆1,462Oct 19, 2025Updated 3 months ago
- 修改的SweetPotato,使之可以用于CobaltStrike v4.0☆246Apr 30, 2020Updated 5 years ago
- 绕过专业工具检测的Webshell研究文章和免杀的Webshell☆1,732Nov 15, 2020Updated 5 years ago
- 使用windows api添加用户,可用于net无法使用 时.分为nim版,c++版本,RDI版,BOF版。☆421Sep 29, 2021Updated 4 years ago
- 红队作战中比较常遇到的一些重点系统漏洞整理。☆2,521Jul 17, 2021Updated 4 years ago