全网首发!!!最全的网安面试题附参考答案(涵盖护网、红队、逆向、密码学、二进制、AI、区块链)
☆785Mar 11, 2026Updated 4 months ago
Alternatives and similar repositories for Sec-Interview
Users that are interested in Sec-Interview are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- 一款综合性网络安全检测和运维工具,旨在快速资产发现、识别、检测,构建基础资产信息库,协助甲方安全团队或者安全运维人员有效侦察和检索资产,发现存在的薄弱点和攻击面。☆4,065Updated this week
- Java Vulnerability Exploitation Platform☆2,132Apr 29, 2026Updated 3 months ago
- 一款面向SRC漏洞挖掘中,页面信息收集 场景的浏览器扩展,自动收集页面及相关资源中的敏感信息与可疑线索,支持基础扫描、深度递归扫描、批量 API 测试及结果导出与自定义正则配置☆672Jun 17, 2026Updated last month
- 一款用于网页敏感信息检测,指纹识别的chrome插件☆892Jan 13, 2026Updated 6 months ago
- 🚀 2024-至今 1Day 漏洞 PoC 深度研究与复现归档。涵盖 OA、ERP、安防、数通、大模型及容器等 高价值资产漏洞,实战导向,助力安全研究与合规检测。☆1,024Updated this week
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- 红队浏览器插件-检测VUE站点未授权漏洞☆903May 7, 2026Updated 2 months ago
- 专注于代码审计skill,最小化轻量化skill,只负责安全边界。☆980Jun 16, 2026Updated last month
- 自己收集和编制的红队面试题,不定期更新☆171Jul 21, 2025Updated last year
- 网络空间资产测绘、ICP备案、天眼查股权结构图、端口扫描、指纹识别、小程序敏感信息提取。☆1,364May 19, 2026Updated 2 months ago
- 备份的漏洞库,3月开始我们来维护☆2,105Jul 13, 2026Updated 2 weeks ago
- 前端加密对抗练习靶场,包含非对称加密、对称加密、加签以及禁止重放的测试场景,比如AES、DES、RSA,用于渗透测试练习☆576Jun 17, 2025Updated last year
- 《深入JDBC安全:特殊URL构造与不出网反序列化利用技术揭秘》对应研究总结项目 "Deep Dive into JDBC Security: Special URL Construction and Non-Networked Deserialization Explo…☆590Feb 7, 2026Updated 5 months ago
- 一款专注于 Java 主流 Web 中间件的内存马快速生成工具,致力于简化安全研究人员和红队成员的工作流程,提升攻防效率☆1,563Jul 16, 2026Updated last week
- 基于Memprocfs和Volatility的可视化内存取证工具☆1,710Jun 24, 2026Updated last month
- Managed Kubernetes at scale on DigitalOcean • AdDigitalOcean Kubernetes includes the control plane, bandwidth allowance, container registry, automatic updates, and more for free.
- 对Auth/Waf 自动化bypass的burpsuite插件☆1,299May 10, 2026Updated 2 months ago
- CryptoJS常规加解密自吐密钥、加解密方式,快速定位加解密位置(无视混淆)。SRC和常规渗透神器☆624Jul 20, 2026Updated last week
- A AI general-purpose state-space search engine, validated first on autonomous penetration testing.☆2,114Jul 15, 2026Updated last week
- LingJing 新一代本地桌面级网络安全靶场(支持Mac arm64、Windows amd64),能在 Mac M 系列芯片设备上启动 AMD64 架构靶机☆518Jun 2, 2026Updated last month
- 实战 SRC / 众测 / Bug bounty 漏洞挖掘 Claude Code skill — 19 个攻击类 playbook、305 个结构化 payload、263 个 WAF/EDR 绕过、2887 份 HackerOne 真实案例、88,636 WooYun …☆593May 24, 2026Updated 2 months ago
- 收集整理渗透测试、漏洞扫描、代码审计、CTF、逆向、安全研究 等网络安全相关的 Skills和MCP☆756Jul 6, 2026Updated 3 weeks ago
- a rep for documenting my study, may be from 0 to 0.1☆2,292Mar 25, 2026Updated 4 months ago
- FastJson全版本Docker漏洞环境(涵盖1.2.47/1.2.68/1.2.80等版本),主要包括JNDI注入及高版本绕过、waf绕过、文件读写、原生反序列化、利用链探测绕过、不出网利用等。从黑盒的角度覆盖FastJson深入利用☆1,242Jul 12, 2024Updated 2 years ago
- Linux权限维持☆1,114Jun 10, 2026Updated last month
- Virtual machines for every use case on DigitalOcean • AdGet dependable uptime with 99.99% SLA, simple security tools, and predictable monthly pricing with DigitalOcean's virtual machines, called Droplets.
- JavaScript Reverse Tools -- JS逆向工具☆2,059Jun 16, 2026Updated last month
- 微信小程序辅助渗透-自动化☆2,191May 26, 2026Updated 2 months ago
- pyjail (python jail) 绕过 一把梭 CTF 工具☆357May 6, 2026Updated 2 months ago
- DeepAudit:人人拥有的 AI 黑客战队,让漏洞挖掘触手可及。国内首个开源的代码漏洞挖掘多智能体系统。小白一键部署运行,自主协作审计 + 自动化沙箱 PoC 验证。支持 Ollama 私有部署 ,一键生成报告。支持中转站。让安全不再昂贵,让审计不再复杂。☆6,725Updated this week
- 浏览器存储桶配置漏洞检测插件☆273Nov 27, 2025Updated 8 months ago
- 腾讯云智能渗透黑客松 Official repository of Tencent Cloud Intelligent Penetration Hackathon. Showcasing top open-source projects of LLM-based auton…☆735Jul 15, 2026Updated 2 weeks ago
- 专为CTF设计的Jinja2 SSTI全自动绕WAF脚本 | A Jinja2 SSTI cracker for bypassing WAF, designed for CTF☆1,292Jul 22, 2026Updated last week
- 记录一下 Java 安全学习历程,也算是半条学习路线了☆1,378Jun 26, 2025Updated last year
- MaR - Matcher and Replacer, Perform intelligent replacement based on precise matching. 精准匹配,智能替换!☆371Jun 28, 2026Updated last month
- GPUs on demand by Runpod - Special Offer Available • AdRun AI, ML, and HPC workloads on powerful cloud GPUs—without limits or wasted spend. Deploy GPUs in under a minute and pay by the second.
- 【Hello-CTF labs】一个ssrf的综合靶场,包含RCE,SQL注入,Tomcat,Redis,MySQL提权等ssrf攻击场景☆83Mar 18, 2025Updated last year
- ARL官方仓库备份项目:ARL(Asset Reconnaissance Lighthouse)资产侦察灯塔系统旨在快速侦察与目标关联的互联网资产,构建基础资产信息库。 协助甲方安全团队或者渗透测试人员有效侦察和检索资产,发现存在的薄弱点和攻击面。☆2,025Jul 16, 2025Updated last year
- 蓝队分析研判工具箱,功能包括内存马反编译分析、各种代码格式化、网空资产测绘功能、溯源辅助、解密冰蝎流量、解密哥斯拉流量、解密Shiro/CAS/Log4j2的攻击payload、IP/端口连接分析、各种编码/解码功能、蓝队分析常用网址、java反序列化数据包分析、Java类…☆1,842Updated this week
- 实战沉淀字典☆1,572Mar 17, 2026Updated 4 months ago
- 网络安全面试总结☆257May 29, 2023Updated 3 years ago
- Everything for pentest. | 渗透测试知识库,以 AI Agent 可执行的格式沉淀安全方法论。☆1,619Jul 19, 2026Updated last week
- 一个用于测试文件上传功能安全性的 Burp Suite 插件。通过 Intruder 模块自动生成各类绕过 payload,覆盖常见的文件上传限制场景。共1000+条payload☆621Dec 24, 2025Updated 7 months ago