用于辅助安全工程师漏洞挖掘、测试、复现,集合了mock、httplog、dns tools、xss,可用于测试各类无回显、无法直观判断或特定场景下的漏洞。
☆866Jul 21, 2019Updated 6 years ago
Alternatives and similar repositories for vtest
Users that are interested in vtest are comparing it to the libraries listed below
Sorting:
- 在渗透测试中快速检测常见中间件、组件的高危漏洞。☆728Mar 21, 2022Updated 3 years ago
- BCS(北京网络安全大会)2019 红队行动会议重点内容☆819Sep 4, 2019Updated 6 years ago
- 360/0Kee-Team/crawlergo动态爬虫结合长亭XRAY扫描器的被动扫描功能☆1,183Nov 10, 2021Updated 4 years ago
- 用于记录分享一些有趣的案例☆866Jan 10, 2022Updated 4 years ago
- 增强版WeblogicScan、检测结果更精确、插件化、添加CVE-2019-2618,CVE-2019-2729检测,Python3支持☆968Jun 16, 2024Updated last year
- 一个各种方式突破Disable_functions达到命令执行的shell☆1,198Oct 17, 2023Updated 2 years ago
- mysql注入,bypass的一些心得☆1,326Jun 25, 2024Updated last year
- Burp suite 分块传输辅助插件☆2,022Feb 23, 2022Updated 4 years ago
- Airbug(空气洞),收集漏洞poc用于安全产品☆354Sep 26, 2019Updated 6 years ago
- SRC子域名资产监控☆1,299Jan 14, 2021Updated 5 years ago
- 越权检测工具☆746Jun 17, 2022Updated 3 years ago
- 红队基础设施自动化部署工具☆852Jan 4, 2023Updated 3 years ago
- dynamic crawler for web vulnerability scanner☆252Mar 4, 2020Updated 5 years ago
- Burp被动扫描流量转发插件☆1,459Jun 17, 2024Updated last year
- 更快速的进行Web应用指纹识别☆170May 9, 2019Updated 6 years ago
- kunpeng是一个Golang编写的开源POC框架/库,以动态链接库的形式提供各种语言调用,通过此项目可快速开发漏洞检测类的系统。☆1,673Feb 25, 2023Updated 3 years ago
- 从wooyun中提取的payload,以及burp插件☆842Jun 17, 2022Updated 3 years ago
- Fastjson vulnerability quickly exploits the framework(fastjson漏洞快速利用框架)☆1,389Dec 16, 2022Updated 3 years ago
- Redis 4.x/5.x RCE☆975Nov 30, 2021Updated 4 years ago
- xss漏洞模糊测试payload的最佳集合 2020版☆511May 25, 2020Updated 5 years ago
- Cobalt Strike系列☆2,413Dec 3, 2023Updated 2 years ago
- Passive Security Scanner (被动式安全扫描器)☆1,947Feb 8, 2023Updated 3 years ago
- 免杀webshell无限生成工具☆1,288Apr 3, 2020Updated 5 years ago
- CVE-2019-2725 命令回显☆436May 8, 2023Updated 2 years ago
- 绕过专业工具检测的Webshell研究文章和免杀的Webshell☆1,733Nov 15, 2020Updated 5 years ago
- ☆404Feb 28, 2020Updated 6 years ago
- 此项目用来提取收集以往泄露的密码中符合条件的强弱密码☆1,133Apr 1, 2019Updated 6 years ago
- Enumeration sub domains(枚举子域名)☆1,066Dec 1, 2021Updated 4 years ago
- 渗透测试插件化并发框架 / Open-sourced remote vulnerability PoC/EXP framework☆1,953Mar 28, 2022Updated 3 years ago
- bayonet是一款src资产管理系统,从子域名、端口服务、漏洞、爬虫等一体化的资产管理系统☆1,507Nov 22, 2022Updated 3 years ago
- 渗透测试用到的东东☆428May 6, 2020Updated 5 years ago
- 自动扫描内网常见sql、no-sql数据库脚本(mysql、mssql、oracle、postgresql、redis、mongodb、memcached、elasticsearch),包含未授权访问及常规弱口令检测☆567Dec 1, 2017Updated 8 years ago
- vulscan 扫描系统:最新的poc&exp漏洞扫描,redis未授权、敏感文件、java反序列化、tomcat命令执行及各种未授权扫描等...☆630May 10, 2019Updated 6 years ago
- Python2编写的struts2漏洞全版本检测和利用工具☆1,419May 7, 2019Updated 6 years ago
- 本程序旨在为安全应急响应人员对Linux主机排查时提供便利,实现主机侧Checklist的自动全面化检测,根据检测结果自动数据聚合,进行黑客攻击路径溯源。☆2,807Aug 7, 2022Updated 3 years ago
- KunLun-M是一个完全开源的静态白盒扫描工具,支持PHP、JavaScript的语义扫描,基础安全、组件安全扫描,Chrome Ext\Solidity的基础扫描。☆2,379Jan 16, 2026Updated last month
- Collect JSP webshell of various implementation methods. 梳理和发现的JSP Webshell各种姿势☆1,404Jan 18, 2022Updated 4 years ago
- 一个利用OneForAll进行子域收集、Shodan API端口扫描、Xray漏洞Fuzz、Server酱的自动化漏洞扫描、即时通知提醒的漏洞挖掘辅助工具☆738Dec 8, 2022Updated 3 years ago
- 一个包含php,java,python,C#等各种语言版本的XXE漏洞Demo☆815Nov 28, 2022Updated 3 years ago