一些关于渗透测试的Tips
☆613Dec 19, 2022Updated 3 years ago
Alternatives and similar repositories for Pentest101
Users that are interested in Pentest101 are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Everything for pentest. | 渗透测试知识库,以 AI Agent 可执行的格式沉淀安全方法论。☆1,335May 17, 2026Updated last week
- 各种数据库的利用姿势☆1,033Jan 3, 2025Updated last year
- 渗透测试,渗透测试小技巧,渗透测试Tips,师傅们跟我一起维护更新吧~☆882Jun 8, 2021Updated 4 years ago
- Fastjson姿势技巧集合☆1,846Oct 20, 2023Updated 2 years ago
- domain_hunter的高级版本,SRC挖洞、HW打点之必备!自动化资产收集;快速Title获取;外部工具联动;等等☆2,131Apr 10, 2026Updated last month
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- 针对目标已知信息的字典生成工具☆208Sep 21, 2022Updated 3 years ago
- 域控安全one for all☆739Sep 9, 2024Updated last year
- 红/蓝队环境自动化部署工具 | Red/Blue team environment automation deployment tool☆2,125May 5, 2026Updated 2 weeks ago
- 红队作战中比较常遇到的一些重点系统漏洞整理。☆2,519Jul 17, 2021Updated 4 years ago
- ffffffff0x 团队维护的安全知识框架,内容包括不仅限于 web安全、工控安全、取证、应急、蓝队设施部署、后渗透、Linux安全、各类靶机writup☆5,675Jun 6, 2024Updated last year
- JNDI服务利用工具 RMI/LDAP,支持部分场景回显、内存shell,高版本JDK场景下利用等,fastjson rce命令执行,log4j rce命令执行 漏洞检测辅助工具☆2,018May 21, 2024Updated 2 years ago
- 一款可以在不出网的环境下进行反向代理及cs上线的工具☆492Apr 26, 2023Updated 3 years ago
- 六大云存储,泄露利用检测工具☆1,254Mar 28, 2025Updated last year
- 一款针对Vcenter的综合利用工具,包含目前最主流的CVE-2021-21972、CVE-2021-21985以及CVE-2021-22005、One Access的CVE-2022-22954、CVE-2022-22972/31656以及log4j,提供一键上传webs…☆1,473Apr 25, 2024Updated 2 years ago
- Proton VPN Special Offer - Get 70% off • AdSpecial partner offer. Trusted by over 100 million users worldwide. Tested, Approved and Recommended by Experts.
- 红队行动中利用白利用、免杀、自动判断网络环境生成钓鱼可执行文件。☆369Jun 19, 2024Updated last year
- A Swagger API Exploit☆1,375Jun 7, 2024Updated last year
- 从零开始学免杀☆437Mar 30, 2022Updated 4 years ago
- 红队笔记☆2,148Mar 16, 2026Updated 2 months ago
- 解决FastJson、Jackson、Log4j2、原生JNDI注入漏洞的高版本JDKBypass利用,探测本地可用反序列化gadget达到命令执行、回显命令执行、内存马注入☆775Jan 26, 2022Updated 4 years ago
- 一款适用于红蓝对抗中的仿真钓鱼系统☆1,538May 30, 2023Updated 2 years ago
- 用于记录内网渗透(域渗透)学习 :-)☆1,245Nov 9, 2020Updated 5 years ago
- AK资源管理工具,阿里云/腾讯云/华为云/AWS/UCLOUD/京东云/百度云/七牛云存储/火山引擎 AccessKey AccessKeySecret,利用AK获取资源信息和操作资源,ECS/CVM/E2/UHOST/ECI/BCC执行命令,OSS/COS/S3/BOS…☆783Feb 13, 2025Updated last year
- 研究利用golang各种姿势bypassAV☆816Apr 11, 2022Updated 4 years ago
- Virtual machines for every use case on DigitalOcean • AdGet dependable uptime with 99.99% SLA, simple security tools, and predictable monthly pricing with DigitalOcean's virtual machines, called Droplets.
- netspy是一款快速探测内网可达网段工具(深信服深蓝实验室天威战队强力驱动)☆2,219Jul 25, 2023Updated 2 years ago
- 冰蝎Java WebShell自动化免杀生成☆781Mar 15, 2022Updated 4 years ago
- Packer Fuzzer is a fast and efficient scanner for security detection of websites constructed by javascript module bundler such as Webpack…☆3,234May 24, 2024Updated 2 years ago
- heapdump敏感信息查询工具,例如查找 spring heapdump中的密码明文,AK,SK等☆1,448May 21, 2024Updated 2 years ago
- Lateral Movement☆940Mar 24, 2026Updated 2 months ago
- 收集内存马打入方式☆507May 20, 2022Updated 4 years ago
- 主流供应商的一些攻击性漏洞汇总☆803Nov 8, 2021Updated 4 years ago
- 域渗透一条龙☆740Feb 16, 2022Updated 4 years ago
- 递归式寻找域名和api。☆724Aug 3, 2023Updated 2 years ago
- Managed Database hosting by DigitalOcean • AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- RedTeaming知识星球2020年安全知识汇总☆474May 5, 2021Updated 5 years ago
- 一款基于BurpSuite的被动式FastJson检测插件☆1,244Oct 1, 2022Updated 3 years ago
- 红队常用命令速查☆1,023Mar 17, 2026Updated 2 months ago
- CobaltStrike后渗透测试插件☆1,566Oct 28, 2021Updated 4 years ago
- 冰蝎 哥斯拉 WebShell bypass☆770Jan 15, 2026Updated 4 months ago
- fastjson漏洞burp插件,检测fastjson<1.2.68基于dnslog,fastjson<=1.2.24和1.2.33<=fatjson<=1.2.47的不出网检测和TomcatEcho,SpringEcho回显方案。☆126May 14, 2021Updated 5 years ago
- Java应用的一些配置文件字典,来源于公开的字典与平时收集☆320Feb 1, 2024Updated 2 years ago