一些关于渗透测试的Tips
☆611Dec 19, 2022Updated 3 years ago
Alternatives and similar repositories for Pentest101
Users that are interested in Pentest101 are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Everything for pentest. | 用于渗透测试的 payload 和 bypass 字典.☆1,078Jan 9, 2023Updated 3 years ago
- 各种数据库的利用姿势☆1,033Jan 3, 2025Updated last year
- 渗透测试,渗透测试小技巧,渗透测试Tips,师傅们跟我一起维护更新吧~☆878Jun 8, 2021Updated 4 years ago
- Fastjson姿势技巧集合☆1,833Oct 20, 2023Updated 2 years ago
- 针对目标已知信息的字典生成工具☆209Sep 21, 2022Updated 3 years ago
- domain_hunter的高级版本,SRC挖洞、HW打点之必备!自动化资产收集;快速Title获取;外部工具联动;等等☆2,118Mar 3, 2026Updated 3 weeks ago
- 域控安全one for all☆736Sep 9, 2024Updated last year
- 红/蓝队环境自动化部署工具 | Red/Blue team environment automation deployment tool☆2,099Mar 17, 2026Updated last week
- 红队作战中比较常遇到的一些重点系统漏洞整理。☆2,521Jul 17, 2021Updated 4 years ago
- ffffffff0x 团队维护的安全知识框架,内容包括不仅限于 web安全、工控安全、取证、应急、蓝队设施部署、后渗透、Linux安全、各类靶机writup☆5,651Jun 6, 2024Updated last year
- JNDI服务利用工具 RMI/LDAP,支持部分场景回显、内存shell,高版本JDK场景下利用等,fastjson rce命令执行,log4j rce命令执行 漏洞检测辅助工具☆2,014May 21, 2024Updated last year
- 六大云存储,泄露利用检测工具☆1,245Mar 28, 2025Updated 11 months ago
- 一款可以在不出网的环境下进行反向代理及cs上线的工具☆491Apr 26, 2023Updated 2 years ago
- 一款针对Vcenter的综合利用工具,包含目前最主流的CVE-2021-21972、CVE-2021-21985以及CVE-2021-22005、One Access的CVE-2022-22954、CVE-2022-22972/31656以及log4j,提供一键上传webs…☆1,470Apr 25, 2024Updated last year
- 红队行动中利用白利用、免杀、自动判断网络环境生成钓鱼可执行文件。☆366Jun 19, 2024Updated last year
- 从零开始学免杀☆439Mar 30, 2022Updated 3 years ago
- 红队笔记☆2,124Mar 16, 2026Updated last week
- 解决FastJson、Jackson、Log4j2、原生JNDI注入漏洞的高版本JDKBypass利用,探测本地可用反序列化gadget达到命令执行、回显命令执行、内存马注入☆772Jan 26, 2022Updated 4 years ago
- 一款适用于红蓝对抗中的仿真钓鱼系统☆1,537May 30, 2023Updated 2 years ago
- 用于记录内网渗透(域渗透)学习 :-)☆1,239Nov 9, 2020Updated 5 years ago
- AK资源管理工具,阿里云/腾讯云/华为云/AWS/UCLOUD/京东云/百度云/七牛云存储/火山引擎 AccessKey AccessKeySecret,利用AK获取资源信息和操作资源,ECS/CVM/E2/UHOST/ECI/BCC执行命令,OSS/COS/S3/BOS…☆779Feb 13, 2025Updated last year
- A Swagger API Exploit☆1,369Jun 7, 2024Updated last year
- 研究利用golang各种姿势bypassAV☆817Apr 11, 2022Updated 3 years ago
- 冰蝎Java WebShell自动化免杀生成☆783Mar 15, 2022Updated 4 years ago
- heapdump敏感信息查询工具,例如查找 spring heapdump中的密码明文,AK,SK等☆1,436May 21, 2024Updated last year
- netspy是一款快速探测内网可达网段工具(深信服深蓝实验室天威战队强力驱动)☆2,203Jul 25, 2023Updated 2 years ago
- Packer Fuzzer is a fast and efficient scanner for security detection of websites constructed by javascript module bundler such as Webpack…☆3,218May 24, 2024Updated last year
- Lateral Movement☆943Mar 13, 2026Updated last week
- 收集内存马打入方式☆507May 20, 2022Updated 3 years ago
- 主流供应商的一些攻击性漏洞汇总☆808Nov 8, 2021Updated 4 years ago
- 域渗透一条龙☆739Feb 16, 2022Updated 4 years ago
- 递归式寻找域名和api。☆722Aug 3, 2023Updated 2 years ago
- RedTeaming知识星球2020年安全知识汇总☆473May 5, 2021Updated 4 years ago
- 红队常用命令速查☆1,016Mar 17, 2026Updated last week
- 一款基于BurpSuite的被动式FastJson检测插件☆1,237Oct 1, 2022Updated 3 years ago
- 冰蝎 哥斯拉 WebShell bypass☆763Jan 15, 2026Updated 2 months ago
- CobaltStrike后渗透测试插件☆1,557Oct 28, 2021Updated 4 years ago
- fastjson漏洞burp插件,检测fastjson<1.2.68基于dnslog,fastjson<=1.2.24和1.2.33<=fatjson<=1.2.47的不出网检测和TomcatEcho,SpringEcho回显方案。☆125May 14, 2021Updated 4 years ago
- DNSLOG、httplog、rmilog、ldaplog、jndi 等都支持,完全匿名 产品(fuzz.red),Alphalog与传统DNSLog不同,更快、更安全。☆457Aug 20, 2025Updated 7 months ago