diff --git a/Readme.md b/Readme.md index 19ac917..0336e43 100644 --- a/Readme.md +++ b/Readme.md @@ -3,924 +3,995 @@ - 因Github Readme显示行数有限, 当前页面显示的为不完整版, 只显示了星数最高的前1000个工具. [点击查看完整版](https://github.com/alphaSeclab/sec-tool-list/blob/master/Readme_full.md) # 工具列表 -- [**34521**星][14d] [C++] [x64dbg/x64dbg](https://github.com/x64dbg/x64dbg) Windows平台x32/x64调试器 -- [**33781**星][8d] [Py] [minimaxir/big-list-of-naughty-strings](https://github.com/minimaxir/big-list-of-naughty-strings) “淘气”的字符串列表,当作为用户输入时很容易引发问题 -- [**32724**星][2m] [hack-with-github/awesome-hacking](https://github.com/hack-with-github/awesome-hacking) A collection of various awesome lists for hackers, pentesters and security researchers -- [**30396**星][12d] [Go] [fatedier/frp](https://github.com/fatedier/frp) 快速的反向代理, 将NAT或防火墙之后的本地服务器暴露到公网 -- [**25942**星][7d] [Py] [certbot/certbot](https://github.com/certbot/certbot) Certbot is EFF's tool to obtain certs from Let's Encrypt and (optionally) auto-enable HTTPS on your server. It can also act as a client for any other CA that uses the ACME protocol. -- [**25522**星][26d] [Swift] [shadowsocks/shadowsocksx-ng](https://github.com/shadowsocks/shadowsocksx-ng) Next Generation of ShadowsocksX -- [**25087**星][13d] [Go] [v2ray/v2ray-core](https://github.com/v2ray/v2ray-core) A platform for building proxies to bypass network restrictions. -- [**24589**星][7d] [trimstray/the-book-of-secret-knowledge](https://github.com/trimstray/the-book-of-secret-knowledge) A collection of inspiring lists, manuals, cheatsheets, blogs, hacks, one-liners, cli/web tools and more. -- [**22517**星][12d] [Shell] [mathiasbynens/dotfiles](https://github.com/mathiasbynens/dotfiles) -- [**21751**星][7d] [PHP] [danielmiessler/seclists](https://github.com/danielmiessler/seclists) 多种类型资源收集:用户名、密码、URL、敏感数据类型、Fuzzing Payload、WebShell等 -- [**21668**星][10d] [Go] [filosottile/mkcert](https://github.com/filosottile/mkcert) A simple zero-config tool to make locally trusted development certificates with any names you'd like. -- [**20619**星][9d] [Java] [skylot/jadx](https://github.com/skylot/jadx) dex 转 java 的反编译器 -- [**20089**星][2m] [Shell] [streisandeffect/streisand](https://github.com/StreisandEffect/streisand) Streisand sets up a new server running your choice of WireGuard, OpenConnect, OpenSSH, OpenVPN, Shadowsocks, sslh, Stunnel, or a Tor bridge. It also generates custom instructions for all of these services. At the end of the run you are given an HTML file with instructions that can be shared with friends, family members, and fellow activists. -- [**19651**星][2m] [Jupyter Notebook] [camdavidsonpilon/probabilistic-programming-and-bayesian-methods-for-hackers](https://github.com/camdavidsonpilon/probabilistic-programming-and-bayesian-methods-for-hackers) aka "Bayesian Methods for Hackers": An introduction to Bayesian methods + probabilistic programming with a computation/understanding-first, mathematics-second point of view. All in pure Python ;) -- [**18996**星][7d] [Ruby] [rapid7/metasploit-framework](https://github.com/rapid7/metasploit-framework) Metasploit Framework -- [**18648**星][3y] [fallibleinc/security-guide-for-developers](https://github.com/fallibleinc/security-guide-for-developers) Security Guide for Developers (实用性开发人员安全须知) -- [**18381**星][7d] [Java] [nationalsecurityagency/ghidra](https://github.com/nationalsecurityagency/ghidra) 软件逆向框架 -- [**18220**星][8d] [Java] [alibaba/arthas](https://github.com/alibaba/arthas) Alibaba Java诊断利器Arthas -- [**17555**星][4y] [Go] [inconshreveable/ngrok](https://github.com/inconshreveable/ngrok) 反向代理,在公网终端和本地服务之间创建安全的隧道 -- [**16951**星][14d] [Py] [mitmproxy/mitmproxy](https://github.com/mitmproxy/mitmproxy) An interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers. -- [**16681**星][7d] [C#] [powershell/powershell](https://github.com/powershell/powershell) PowerShell for every system! -- [**15756**星][8d] [Py] [sqlmapproject/sqlmap](https://github.com/sqlmapproject/sqlmap) Automatic SQL injection and database takeover tool -- [**15694**星][9m] [micropoor/micro8](https://github.com/micropoor/micro8) 从业10年渗透笔记 -- [**15627**星][7d] [C] [curl/curl](https://github.com/curl/curl) A command line tool and library for transferring data with URL syntax, supporting HTTP, HTTPS, FTP, FTPS, GOPHER, TFTP, SCP, SFTP, SMB, TELNET, DICT, LDAP, LDAPS, FILE, IMAP, SMTP, POP3, RTSP and RTMP. libcurl offers a myriad of powerful features -- [**14661**星][1m] [gfwlist/gfwlist](https://github.com/gfwlist/gfwlist) gfwlist -- [**14478**星][26d] [Java] [tencent/tinker](https://github.com/tencent/tinker) Tinker is a hot-fix solution library for Android, it supports dex, library and resources update without reinstall apk. -- [**13627**星][9m] [JS] [bannedbook/fanqiang](https://github.com/bannedbook/fanqiang) 翻墙-科学上网 -- [**13183**星][26d] [Py] [corentinj/real-time-voice-cloning](https://github.com/corentinj/real-time-voice-cloning) Clone a voice in 5 seconds to generate arbitrary speech in real-time -- [**13081**星][17d] [Go] [jesseduffield/lazydocker](https://github.com/jesseduffield/lazydocker) The lazier way to manage everything docker -- [**12920**星][10d] [Py] [cool-rr/pysnooper](https://github.com/cool-rr/pysnooper) Never use print for debugging again -- [**12641**星][9d] [C] [shadowsocks/shadowsocks-libev](https://github.com/shadowsocks/shadowsocks-libev) libev port of shadowsocks -- [**12453**星][7d] [C#] [0xd4d/dnspy](https://github.com/0xd4d/dnspy) .NET debugger and assembly editor -- [**12203**星][14d] [Java] [signalapp/signal-android](https://github.com/signalapp/Signal-Android) A private messenger for Android. -- [**11935**星][1m] [Go] [buger/goreplay](https://github.com/buger/goreplay) 实时捕获HTTP流量并输入测试环境,以便持续使用真实数据测试你的系统 -- [**11829**星][17d] [C] [openssl/openssl](https://github.com/openssl/openssl) TLS/SSL and crypto library -- [**11490**星][7d] [C] [radareorg/radare2](https://github.com/radareorg/radare2) unix-like reverse engineering framework and commandline tools -- [**11361**星][3m] [C] [robertdavidgraham/masscan](https://github.com/robertdavidgraham/masscan) masscan:世界上最快的互联网端口扫描器,号称可6分钟内扫描整个互联网 -- [**11246**星][1m] [facert/awesome-spider](https://github.com/facert/awesome-spider) 爬虫集合 -- [**11225**星][13d] [getlantern/download](https://github.com/getlantern/download) Lantern官方版本下载 蓝灯 翻墙 科学上网 外网 加速器 梯子 路由 -- [**11174**星][7d] [Java] [oracle/graal](https://github.com/oracle/graal) Run Programs Faster Anywhere -- [**11106**星][2m] [Jupyter Notebook] [selfteaching/the-craft-of-selfteaching](https://github.com/selfteaching/the-craft-of-selfteaching) One has no future if one couldn't teach themself. -- [**11047**星][7d] [Py] [swisskyrepo/payloadsallthethings](https://github.com/swisskyrepo/payloadsallthethings) A list of useful payloads and bypass for Web Application Security and Pentest/CTF -- [**11013**星][2y] [Objective-C] [bang590/jspatch](https://github.com/bang590/jspatch) JSPatch bridge Objective-C and Javascript using the Objective-C runtime. You can call any Objective-C class and method in JavaScript by just including a small engine. JSPatch is generally used to hotfix iOS App. -- [**11008**星][8d] [Py] [owasp/cheatsheetseries](https://github.com/owasp/cheatsheetseries) The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics. -- [**10902**星][12d] [Objective-C] [flipboard/flex](https://github.com/flipboard/flex) An in-app debugging and exploration tool for iOS -- [**10886**星][2m] [CSS] [hacker0x01/hacker101](https://github.com/hacker0x01/hacker101) Hacker101 -- [**10761**星][2y] [CoffeeScript] [dropbox/zxcvbn](https://github.com/dropbox/zxcvbn) Low-Budget Password Strength Estimation -- [**10742**星][13d] [enaqx/awesome-pentest](https://github.com/enaqx/awesome-pentest) 渗透测试资源/工具集 -- [**10738**星][17d] [Java] [konloch/bytecode-viewer](https://github.com/konloch/bytecode-viewer) A Java 8+ Jar & Android APK Reverse Engineering Suite (Decompiler, Editor, Debugger & More) -- [**10107**星][8d] [Go] [goharbor/harbor](https://github.com/goharbor/harbor) An open source trusted cloud native registry project that stores, signs, and scans content. -- [**9844**星][11d] [ruanyf/weekly](https://github.com/ruanyf/weekly) 科技爱好者周刊,每周五发布 -- [**9804**星][8m] [imthenachoman/how-to-secure-a-linux-server](https://github.com/imthenachoman/how-to-secure-a-linux-server) An evolving how-to guide for securing a Linux server. -- [**9349**星][12d] [Ruby] [postalhq/postal](https://github.com/postalhq/postal) 全功能邮件服务器 -- [**9229**星][3m] [JS] [localtunnel/localtunnel](https://github.com/localtunnel/localtunnel) expose yourself -- [**9182**星][8d] [Go] [cnlh/nps](https://github.com/cnlh/nps) 一款轻量级、功能强大的内网穿透代理服务器。支持tcp、udp流量转发,支持内网http代理、内网socks5代理,同时支持snappy压缩、站点保护、加密传输、多路复用、header修改等。支持web图形化管理,集成多用户模式。 -- [**9178**星][10d] [Java] [ibotpeaches/apktool](https://github.com/ibotpeaches/apktool) A tool for reverse engineering Android apk files -- [**9141**星][8d] [C#] [icsharpcode/ilspy](https://github.com/icsharpcode/ilspy) .NET Decompiler -- [**9064**星][27d] [JS] [valve/fingerprintjs2](https://github.com/valve/fingerprintjs2) Modern & flexible browser fingerprinting library -- [**9003**星][9d] [PowerShell] [lukesampson/scoop](https://github.com/lukesampson/scoop) A command-line installer for Windows. -- [**8995**星][2m] [vitalysim/awesome-hacking-resources](https://github.com/vitalysim/awesome-hacking-resources) A collection of hacking / penetration testing resources to make you better! -- [**8988**星][9d] [Py] [sherlock-project/sherlock](https://github.com/sherlock-project/sherlock) Find Usernames Across Social Networks -- [**8847**星][6m] [Go] [rkt/rkt](https://github.com/rkt/rkt) rkt is a pod-native container engine for Linux. It is composable, secure, and built on standards. -- [**8712**星][15d] [C] [gentilkiwi/mimikatz](https://github.com/gentilkiwi/mimikatz) A little tool to play with Windows security -- [**8597**星][26d] [Java] [android-hacker/virtualxposed](https://github.com/android-hacker/virtualxposed) A simple app to use Xposed without root, unlock the bootloader or modify system image, etc. -- [**8495**星][1m] [microsoft/wsl](https://github.com/microsoft/WSL) Issues found on WSL -- [**8408**星][2y] [brannondorsey/wifi-cracking](https://github.com/brannondorsey/wifi-cracking) 破解WPA/WPA2 Wi-Fi 路由器 -- [**8399**星][27d] [Py] [wifiphisher/wifiphisher](https://github.com/wifiphisher/wifiphisher) 流氓AP框架, 用于RedTeam和Wi-Fi安全测试 -- [**8033**星][7d] [trimstray/the-practical-linux-hardening-guide](https://github.com/trimstray/the-practical-linux-hardening-guide) This guide details creating a secure Linux production system. OpenSCAP (C2S/CIS, STIG). -- [**7992**星][2m] [Py] [facebook/chisel](https://github.com/facebook/chisel) Chisel is a collection of LLDB commands to assist debugging iOS apps. -- [**7952**星][3y] [Go] [cyfdecyf/cow](https://github.com/cyfdecyf/cow) HTTP proxy written in Go. COW can automatically identify blocked sites and use parent proxies to access. -- [**7936**星][4y] [Objective-C] [shadowsocks/shadowsocks-ios](https://github.com/shadowsocks/shadowsocks-ios) Removed according to regulations. -- [**7806**星][3m] [C++] [shiqiyu/libfacedetection](https://github.com/shiqiyu/libfacedetection) An open source library for face detection in images. The face detection speed can reach 1500FPS. -- [**7696**星][7d] [JS] [gchq/cyberchef](https://github.com/gchq/cyberchef) The Cyber Swiss Army Knife - a web app for encryption, encoding, compression and data analysis -- [**7685**星][7d] [Go] [git-lfs/git-lfs](https://github.com/git-lfs/git-lfs) Git extension for versioning large files -- [**7628**星][22d] [Java] [java-decompiler/jd-gui](https://github.com/java-decompiler/jd-gui) A standalone Java Decompiler GUI -- [**7498**星][27d] [Py] [threat9/routersploit](https://github.com/threat9/routersploit) Exploitation Framework for Embedded Devices -- [**7371**星][12d] [Go] [snail007/goproxy](https://github.com/snail007/goproxy) Proxy是高性能全功能的http代理、https代理、socks5代理、内网穿透、内网穿透p2p、内网穿透代理、内网穿透反向代理、内网穿透服务器、Websocket代理、TCP代理、UDP代理、DNS代理、DNS加密代理,代理API认证,全能跨平台代理服务器。 -- [**7365**星][1m] [Py] [s0md3v/xsstrike](https://github.com/s0md3v/XSStrike) Most advanced XSS scanner. -- [**7205**星][17d] [Java] [lionsoul2014/ip2region](https://github.com/lionsoul2014/ip2region) Ip2region is a offline IP location library with accuracy rate of 99.9% and 0.0x millseconds searching performance. DB file is less then 5Mb with all ip address stored. binding for Java,PHP,C,Python,Nodejs,Golang,C#,lua. Binary,B-tree,Memory searching algorithm -- [**7174**星][7m] [Shell] [teddysun/shadowsocks_install](https://github.com/teddysun/shadowsocks_install) Auto Install Shadowsocks Server for CentOS/Debian/Ubuntu -- [**6994**星][14d] [Go] [future-architect/vuls](https://github.com/future-architect/vuls) 针对Linux/FreeBSD 编写的漏洞扫描器. Go 语言编写 -- [**6968**星][2m] [JS] [cs01/gdbgui](https://github.com/cs01/gdbgui) Browser-based frontend to gdb (gnu debugger). Add breakpoints, view the stack, visualize data structures, and more in C, C++, Go, Rust, and Fortran. Run gdbgui from the terminal and a new tab will open in your browser. -- [**6956**星][10d] [C] [hashcat/hashcat](https://github.com/hashcat/hashcat) 世界上最快最先进的密码恢复工具 -- [**6954**星][13d] [Go] [nats-io/nats-server](https://github.com/nats-io/nats-server) High-Performance server for NATS, the cloud native messaging system. -- [**6950**星][9d] [greatfire/wiki](https://github.com/greatfire/wiki) 自由浏览 -- [**6917**星][3m] [Java] [pxb1988/dex2jar](https://github.com/pxb1988/dex2jar) Tools to work with android .dex and java .class files -- [**6844**星][2m] [Go] [sqshq/sampler](https://github.com/sqshq/sampler) A tool for shell commands execution, visualization and alerting. Configured with a simple YAML file. -- [**6788**星][17d] [Shell] [awslabs/git-secrets](https://github.com/awslabs/git-secrets) Prevents you from committing secrets and credentials into git repositories -- [**6708**星][9m] [Java] [amitshekhariitbhu/android-debug-database](https://github.com/amitshekhariitbhu/android-debug-database) A library for debugging android databases and shared preferences - Make Debugging Great Again -- [**6678**星][3y] [C++] [alibaba/andfix](https://github.com/alibaba/andfix) AndFix is a library that offer hot-fix for Android App. -- [**6639**星][9d] [Java] [zaproxy/zaproxy](https://github.com/zaproxy/zaproxy) 在开发和测试Web App时自动发现安全漏洞 -- [**6557**星][11d] [Py] [networkx/networkx](https://github.com/networkx/networkx) 用于创建、操纵和研究复杂网络的结构,Python包 -- [**6455**星][1m] [Py] [h2y/shadowrocket-adblock-rules](https://github.com/h2y/shadowrocket-adblock-rules) 提供多款 Shadowrocket 规则,带广告过滤功能。用于 iOS 未越狱设备选择性地自动翻墙。 -- [**6449**星][11d] [Shell] [cisofy/lynis](https://github.com/cisofy/lynis) Security auditing tool for Linux, macOS, and UNIX-based systems. Assists with compliance testing (HIPAA/ISO27001/PCI DSS) and system hardening. Agentless, and installation optional. -- [**6440**星][9m] [HTML] [open-power-workgroup/hospital](https://github.com/open-power-workgroup/hospital) OpenPower工作组收集汇总的医院开放数据 -- [**6413**星][15d] [Go] [bettercap/bettercap](https://github.com/bettercap/bettercap) 新版的bettercap, Go 编写. bettercap 是强大的、模块化、可移植且易于扩展的 MITM 框架, 旧版用 Ruby 编写 -- [**6284**星][27d] [Py] [seatgeek/fuzzywuzzy](https://github.com/seatgeek/fuzzywuzzy) Fuzzy String Matching in Python -- [**6182**星][2m] [Py] [yandex/gixy](https://github.com/yandex/gixy) Nginx 配置静态分析工具,防止配置错误导致安全问题,自动化错误配置检测 -- [**6170**星][6m] [rmerl/asuswrt-merlin](https://github.com/rmerl/asuswrt-merlin) Enhanced version of Asus's router firmware (Asuswrt) (legacy code base) -- [**6158**星][3y] [PowerShell] [powershellmafia/powersploit](https://github.com/PowerShellMafia/PowerSploit) PowerSploit - A PowerShell Post-Exploitation Framework -- [**6130**星][1y] [Hack] [facebook/fbctf](https://github.com/facebook/fbctf) Platform to host Capture the Flag competitions -- [**6124**星][9m] [Py] [schollz/howmanypeoplearearound](https://github.com/schollz/howmanypeoplearearound) 检测 Wifi 信号统计你周围的人数 -- [**6100**星][7d] [JS] [avwo/whistle](https://github.com/avwo/whistle) 基于Node实现的跨平台抓包调试代理工具(HTTP, HTTP2, HTTPS, Websocket) -- [**6061**星][2y] [C] [jgamblin/mirai-source-code](https://github.com/jgamblin/mirai-source-code) Leaked Mirai Source Code for Research/IoC Development Purposes -- [**6025**星][14d] [Go] [quay/clair](https://github.com/quay/clair) Vulnerability Static Analysis for Containers -- [**6025**星][14d] [Go] [quay/clair](https://github.com/quay/clair) clair:容器(appc、docker)漏洞静态分析工具。 -- [**6002**星][11d] [Py] [cyrus-and/gdb-dashboard](https://github.com/cyrus-and/gdb-dashboard) Modular visual interface for GDB in Python -- [**5996**星][20d] [berzerk0/probable-wordlists](https://github.com/berzerk0/probable-wordlists) Version 2 is live! Wordlists sorted by probability originally created for password generation and testing - make sure your passwords aren't popular! -- [**5948**星][2m] [Java] [google/android-classyshark](https://github.com/google/android-classyshark) 分析基于Android/Java的App或游戏 -- [**5935**星][29d] [Py] [gallopsled/pwntools](https://github.com/gallopsled/pwntools) CTF framework and exploit development library -- [**5870**星][6m] [JS] [haotian-wang/google-access-helper](https://github.com/haotian-wang/google-access-helper) 谷歌访问助手破解版 -- [**5850**星][8d] [C++] [radareorg/cutter](https://github.com/radareorg/cutter) 逆向框架 radare2的Qt界面,iaito的升级版 -- [**5845**星][2m] [Gnuplot] [nasa-jpl/open-source-rover](https://github.com/nasa-jpl/open-source-rover) A build-it-yourself, 6-wheel rover based on the rovers on Mars! -- [**5811**星][7m] [JS] [sindresorhus/fkill-cli](https://github.com/sindresorhus/fkill-cli) Fabulously kill processes. Cross-platform. -- [**5764**星][3m] [Objective-C] [square/ponydebugger](https://github.com/square/ponydebugger) Remote network and data debugging for your native iOS app using Chrome Developer Tools -- [**5738**星][1y] [qinyuhang/shadowsocksx-ng-r](https://github.com/qinyuhang/shadowsocksx-ng-r) Next Generation of ShadowsocksX -- [**5738**星][2y] [Py] [newsapps/beeswithmachineguns](https://github.com/newsapps/beeswithmachineguns) 创建多个micro EC2实例, 攻击指定Web App -- [**5719**星][2m] [C] [spacehuhn/esp8266_deauther](https://github.com/spacehuhn/esp8266_deauther) 使用ESP8266 制作Wifi干扰器 -- [**5715**星][8m] [C] [xoreaxeaxeax/movfuscator](https://github.com/xoreaxeaxeax/movfuscator) C编译器,编译的二进制文件只有1个代码块。 -- [**5674**星][22d] [JS] [swagger-api/swagger-editor](https://github.com/swagger-api/swagger-editor) Swagger Editor -- [**5653**星][16d] [Go] [casbin/casbin](https://github.com/casbin/casbin) An authorization library that supports access control models like ACL, RBAC, ABAC in Golang -- [**5605**星][1m] [C] [rofl0r/proxychains-ng](https://github.com/rofl0r/proxychains-ng) proxychains ng (new generation) - a preloader which hooks calls to sockets in dynamically linked programs and redirects it through one or more socks/http proxies. continuation of the unmaintained proxychains project. the sf.net page is currently not updated, use releases from github release page instead. -- [**5578**星][8d] [Ruby] [presidentbeef/brakeman](https://github.com/presidentbeef/brakeman) ROR程序的静态分析工具 -- [**5521**星][18d] [rshipp/awesome-malware-analysis](https://github.com/rshipp/awesome-malware-analysis) A curated list of awesome malware analysis tools and resources. -- [**5517**星][27d] [Roff] [max2max/freess](https://github.com/max2max/freess) 免费ss账号 免费shadowsocks账号 免费v2ray账号 (长期更新) -- [**5456**星][8m] [carpedm20/awesome-hacking](https://github.com/carpedm20/awesome-hacking) Hacking教程、工具和资源 -- [**5417**星][2y] [Rust] [autumnai/leaf](https://github.com/autumnai/leaf) Open Machine Intelligence Framework for Hackers. (GPU/CPU) -- [**5392**星][2m] [Py] [axi0mx/ipwndfu](https://github.com/axi0mx/ipwndfu) open-source jailbreaking tool for many iOS devices -- [**5353**星][5m] [C] [pwn20wndstuff/undecimus](https://github.com/pwn20wndstuff/undecimus) unc0ver jailbreak for iOS 11.0 - 12.4 -- [**5317**星][7d] [Py] [mlflow/mlflow](https://github.com/mlflow/mlflow) Open source platform for the machine learning lifecycle -- [**5307**星][9d] [Go] [zricethezav/gitleaks](https://github.com/zricethezav/gitleaks) Audit git repos for secrets -- [**5207**星][7m] [Py] [usarmyresearchlab/dshell](https://github.com/usarmyresearchlab/dshell) 网络审计分析 -- [**5165**星][1m] [Py] [refirmlabs/binwalk](https://github.com/ReFirmLabs/binwalk) 固件分析工具(命令行+IDA插件) +- [**45523**星][11d] [C#] [shadowsocks/shadowsocks-windows](https://github.com/shadowsocks/shadowsocks-windows) If you want to keep a secret, you must also hide it from yourself. +- [**34554**星][16d] [C++] [x64dbg/x64dbg](https://github.com/x64dbg/x64dbg) Windows平台x32/x64调试器 +- [**33926**星][10d] [Py] [minimaxir/big-list-of-naughty-strings](https://github.com/minimaxir/big-list-of-naughty-strings) “淘气”的字符串列表,当作为用户输入时很容易引发问题 +- [**32844**星][2m] [hack-with-github/awesome-hacking](https://github.com/hack-with-github/awesome-hacking) A collection of various awesome lists for hackers, pentesters and security researchers +- [**32022**星][4y] [Py] [shadowsocks/shadowsocks](https://github.com/shadowsocks/shadowsocks) +- [**30689**星][14d] [Go] [fatedier/frp](https://github.com/fatedier/frp) 快速的反向代理, 将NAT或防火墙之后的本地服务器暴露到公网 +- [**27836**星][2d] [Kotlin] [shadowsocks/shadowsocks-android](https://github.com/shadowsocks/shadowsocks-android) A shadowsocks client for Android +- [**25977**星][2d] [Py] [certbot/certbot](https://github.com/certbot/certbot) Certbot is EFF's tool to obtain certs from Let's Encrypt and (optionally) auto-enable HTTPS on your server. It can also act as a client for any other CA that uses the ACME protocol. +- [**25643**星][28d] [Swift] [shadowsocks/shadowsocksx-ng](https://github.com/shadowsocks/shadowsocksx-ng) Next Generation of ShadowsocksX +- [**25330**星][3d] [Go] [v2ray/v2ray-core](https://github.com/v2ray/v2ray-core) A platform for building proxies to bypass network restrictions. +- [**24826**星][2d] [xitu/gold-miner](https://github.com/xitu/gold-miner) +- [**24727**星][5d] [trimstray/the-book-of-secret-knowledge](https://github.com/trimstray/the-book-of-secret-knowledge) A collection of inspiring lists, manuals, cheatsheets, blogs, hacks, one-liners, cli/web tools and more. +- [**22556**星][14d] [Shell] [mathiasbynens/dotfiles](https://github.com/mathiasbynens/dotfiles) +- [**21874**星][9d] [PHP] [danielmiessler/seclists](https://github.com/danielmiessler/seclists) 多种类型资源收集:用户名、密码、URL、敏感数据类型、Fuzzing Payload、WebShell等 +- [**21778**星][12d] [Go] [filosottile/mkcert](https://github.com/filosottile/mkcert) A simple zero-config tool to make locally trusted development certificates with any names you'd like. +- [**20680**星][5d] [Java] [skylot/jadx](https://github.com/skylot/jadx) dex 转 java 的反编译器 +- [**20159**星][5d] [Shell] [streisandeffect/streisand](https://github.com/StreisandEffect/streisand) Streisand sets up a new server running your choice of WireGuard, OpenConnect, OpenSSH, OpenVPN, Shadowsocks, sslh, Stunnel, or a Tor bridge. It also generates custom instructions for all of these services. At the end of the run you are given an HTML file with instructions that can be shared with friends, family members, and fellow activists. +- [**19692**星][2m] [Jupyter Notebook] [camdavidsonpilon/probabilistic-programming-and-bayesian-methods-for-hackers](https://github.com/camdavidsonpilon/probabilistic-programming-and-bayesian-methods-for-hackers) aka "Bayesian Methods for Hackers": An introduction to Bayesian methods + probabilistic programming with a computation/understanding-first, mathematics-second point of view. All in pure Python ;) +- [**19212**星][1y] [alvin9999/new-pac](https://github.com/alvin9999/new-pac) 科学/自由上网,免费ss/ssr/v2ray/goflyway账号,搭建教程 +- [**19076**星][2d] [Ruby] [rapid7/metasploit-framework](https://github.com/rapid7/metasploit-framework) Metasploit Framework +- [**18676**星][3y] [fallibleinc/security-guide-for-developers](https://github.com/fallibleinc/security-guide-for-developers) Security Guide for Developers (实用性开发人员安全须知) +- [**18476**星][2d] [Java] [nationalsecurityagency/ghidra](https://github.com/nationalsecurityagency/ghidra) 软件逆向框架 +- [**18390**星][3d] [Java] [alibaba/arthas](https://github.com/alibaba/arthas) Alibaba Java诊断利器Arthas +- [**17641**星][4y] [Go] [inconshreveable/ngrok](https://github.com/inconshreveable/ngrok) 反向代理,在公网终端和本地服务之间创建安全的隧道 +- [**17069**星][6d] [Py] [mitmproxy/mitmproxy](https://github.com/mitmproxy/mitmproxy) An interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers. +- [**16769**星][2d] [C#] [powershell/powershell](https://github.com/powershell/powershell) PowerShell for every system! +- [**15824**星][2d] [Py] [sqlmapproject/sqlmap](https://github.com/sqlmapproject/sqlmap) Automatic SQL injection and database takeover tool +- [**15731**星][9m] [micropoor/micro8](https://github.com/micropoor/micro8) 从业10年渗透笔记 +- [**15718**星][3d] [C] [curl/curl](https://github.com/curl/curl) A command line tool and library for transferring data with URL syntax, supporting HTTP, HTTPS, FTP, FTPS, GOPHER, TFTP, SCP, SFTP, SMB, TELNET, DICT, LDAP, LDAPS, FILE, IMAP, SMTP, POP3, RTSP and RTMP. libcurl offers a myriad of powerful features +- [**15363**星][21d] [Py] [drduh/macos-security-and-privacy-guide](https://github.com/drduh/macOS-Security-and-Privacy-Guide) Guide to securing and improving privacy on macOS +- [**14744**星][1m] [gfwlist/gfwlist](https://github.com/gfwlist/gfwlist) gfwlist +- [**14518**星][7d] [Java] [tencent/tinker](https://github.com/tencent/tinker) Tinker is a hot-fix solution library for Android, it supports dex, library and resources update without reinstall apk. +- [**13736**星][9m] [JS] [bannedbook/fanqiang](https://github.com/bannedbook/fanqiang) 翻墙-科学上网 +- [**13548**星][28d] [Py] [corentinj/real-time-voice-cloning](https://github.com/corentinj/real-time-voice-cloning) Clone a voice in 5 seconds to generate arbitrary speech in real-time +- [**13241**星][19d] [Go] [jesseduffield/lazydocker](https://github.com/jesseduffield/lazydocker) The lazier way to manage everything docker +- [**12966**星][12d] [Py] [cool-rr/pysnooper](https://github.com/cool-rr/pysnooper) Never use print for debugging again +- [**12742**星][3d] [Vue] [liyasthomas/postwoman](https://github.com/liyasthomas/postwoman) +- [**12693**星][8d] [C] [shadowsocks/shadowsocks-libev](https://github.com/shadowsocks/shadowsocks-libev) libev port of shadowsocks +- [**12544**星][9d] [C#] [0xd4d/dnspy](https://github.com/0xd4d/dnspy) .NET debugger and assembly editor +- [**12325**星][2m] [Ruby] [diaspora/diaspora](https://github.com/diaspora/diaspora) A privacy-aware, distributed, open source social network. +- [**12241**星][5d] [Java] [signalapp/signal-android](https://github.com/signalapp/Signal-Android) A private messenger for Android. +- [**11977**星][1m] [Go] [buger/goreplay](https://github.com/buger/goreplay) 实时捕获HTTP流量并输入测试环境,以便持续使用真实数据测试你的系统 +- [**11890**星][6d] [C] [openssl/openssl](https://github.com/openssl/openssl) TLS/SSL and crypto library +- [**11530**星][2d] [C] [radareorg/radare2](https://github.com/radareorg/radare2) unix-like reverse engineering framework and commandline tools +- [**11418**星][3m] [C] [robertdavidgraham/masscan](https://github.com/robertdavidgraham/masscan) masscan:世界上最快的互联网端口扫描器,号称可6分钟内扫描整个互联网 +- [**11404**星][2d] [getlantern/download](https://github.com/getlantern/download) Lantern官方版本下载 蓝灯 翻墙 科学上网 外网 加速器 梯子 路由 +- [**11342**星][1m] [facert/awesome-spider](https://github.com/facert/awesome-spider) 爬虫集合 +- [**11278**星][2d] [Java] [oracle/graal](https://github.com/oracle/graal) Run Programs Faster Anywhere +- [**11200**星][5d] [Py] [swisskyrepo/payloadsallthethings](https://github.com/swisskyrepo/payloadsallthethings) A list of useful payloads and bypass for Web Application Security and Pentest/CTF +- [**11143**星][2m] [Jupyter Notebook] [selfteaching/the-craft-of-selfteaching](https://github.com/selfteaching/the-craft-of-selfteaching) One has no future if one couldn't teach themself. +- [**11110**星][5d] [Py] [owasp/cheatsheetseries](https://github.com/owasp/cheatsheetseries) The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics. +- [**11016**星][2y] [ObjC] [bang590/jspatch](https://github.com/bang590/jspatch) JSPatch bridge Objective-C and Javascript using the Objective-C runtime. You can call any Objective-C class and method in JavaScript by just including a small engine. JSPatch is generally used to hotfix iOS App. +- [**10925**星][2d] [ObjC] [flipboard/flex](https://github.com/flipboard/flex) An in-app debugging and exploration tool for iOS +- [**10907**星][2m] [CSS] [hacker0x01/hacker101](https://github.com/hacker0x01/hacker101) Hacker101 +- [**10830**星][15d] [enaqx/awesome-pentest](https://github.com/enaqx/awesome-pentest) 渗透测试资源/工具集 +- [**10780**星][2y] [CoffeeScript] [dropbox/zxcvbn](https://github.com/dropbox/zxcvbn) Low-Budget Password Strength Estimation +- [**10757**星][19d] [Java] [konloch/bytecode-viewer](https://github.com/konloch/bytecode-viewer) A Java 8+ Jar & Android APK Reverse Engineering Suite (Decompiler, Editor, Debugger & More) +- [**10318**星][5d] [ruanyf/weekly](https://github.com/ruanyf/weekly) 科技爱好者周刊,每周五发布 +- [**10226**星][3d] [Go] [goharbor/harbor](https://github.com/goharbor/harbor) An open source trusted cloud native registry project that stores, signs, and scans content. +- [**9830**星][8m] [imthenachoman/how-to-secure-a-linux-server](https://github.com/imthenachoman/how-to-secure-a-linux-server) An evolving how-to guide for securing a Linux server. +- [**9613**星][4d] [Py] [sherlock-project/sherlock](https://github.com/sherlock-project/sherlock) Find Usernames Across Social Networks +- [**9389**星][3d] [Go] [cnlh/nps](https://github.com/cnlh/nps) 一款轻量级、功能强大的内网穿透代理服务器。支持tcp、udp流量转发,支持内网http代理、内网socks5代理,同时支持snappy压缩、站点保护、加密传输、多路复用、header修改等。支持web图形化管理,集成多用户模式。 +- [**9358**星][6d] [Ruby] [postalhq/postal](https://github.com/postalhq/postal) 全功能邮件服务器 +- [**9266**星][3m] [JS] [localtunnel/localtunnel](https://github.com/localtunnel/localtunnel) expose yourself +- [**9229**星][12d] [Java] [ibotpeaches/apktool](https://github.com/ibotpeaches/apktool) A tool for reverse engineering Android apk files +- [**9185**星][2d] [C#] [icsharpcode/ilspy](https://github.com/icsharpcode/ilspy) .NET Decompiler +- [**9148**星][29d] [JS] [valve/fingerprintjs2](https://github.com/valve/fingerprintjs2) Modern & flexible browser fingerprinting library +- [**9069**星][11d] [PS] [lukesampson/scoop](https://github.com/lukesampson/scoop) A command-line installer for Windows. +- [**9015**星][2m] [vitalysim/awesome-hacking-resources](https://github.com/vitalysim/awesome-hacking-resources) A collection of hacking / penetration testing resources to make you better! +- [**8854**星][6m] [Go] [rkt/rkt](https://github.com/rkt/rkt) rkt is a pod-native container engine for Linux. It is composable, secure, and built on standards. +- [**8739**星][17d] [C] [gentilkiwi/mimikatz](https://github.com/gentilkiwi/mimikatz) A little tool to play with Windows security +- [**8646**星][28d] [Java] [android-hacker/virtualxposed](https://github.com/android-hacker/virtualxposed) A simple app to use Xposed without root, unlock the bootloader or modify system image, etc. +- [**8525**星][1m] [microsoft/wsl](https://github.com/microsoft/WSL) Issues found on WSL +- [**8443**星][7m] [Shell] [233boy/v2ray](https://github.com/233boy/v2ray) 最好用的 V2Ray 一键安装脚本 & 管理脚本 +- [**8424**星][2d] [Py] [wifiphisher/wifiphisher](https://github.com/wifiphisher/wifiphisher) 流氓AP框架, 用于RedTeam和Wi-Fi安全测试 +- [**8420**星][2y] [brannondorsey/wifi-cracking](https://github.com/brannondorsey/wifi-cracking) 破解WPA/WPA2 Wi-Fi 路由器 +- [**8044**星][9d] [trimstray/the-practical-linux-hardening-guide](https://github.com/trimstray/the-practical-linux-hardening-guide) This guide details creating a secure Linux production system. OpenSCAP (C2S/CIS, STIG). +- [**8002**星][2m] [Py] [facebook/chisel](https://github.com/facebook/chisel) Chisel is a collection of LLDB commands to assist debugging iOS apps. +- [**7986**星][1m] [Py] [mailpile/mailpile](https://github.com/mailpile/mailpile) A free & open modern, fast email client with user-friendly encryption and privacy features +- [**7965**星][3y] [Go] [cyfdecyf/cow](https://github.com/cyfdecyf/cow) HTTP proxy written in Go. COW can automatically identify blocked sites and use parent proxies to access. +- [**7945**星][4y] [ObjC] [shadowsocks/shadowsocks-ios](https://github.com/shadowsocks/shadowsocks-ios) Removed according to regulations. +- [**7840**星][6d] [C++] [shiqiyu/libfacedetection](https://github.com/shiqiyu/libfacedetection) An open source library for face detection in images. The face detection speed can reach 1500FPS. +- [**7731**星][3d] [JS] [gchq/cyberchef](https://github.com/gchq/cyberchef) The Cyber Swiss Army Knife - a web app for encryption, encoding, compression and data analysis +- [**7712**星][2d] [Go] [git-lfs/git-lfs](https://github.com/git-lfs/git-lfs) Git extension for versioning large files +- [**7670**星][24d] [Java] [java-decompiler/jd-gui](https://github.com/java-decompiler/jd-gui) A standalone Java Decompiler GUI +- [**7524**星][29d] [Py] [threat9/routersploit](https://github.com/threat9/routersploit) Exploitation Framework for Embedded Devices +- [**7474**星][9d] [Go] [snail007/goproxy](https://github.com/snail007/goproxy) Proxy是高性能全功能的http代理、https代理、socks5代理、内网穿透、内网穿透p2p、内网穿透代理、内网穿透反向代理、内网穿透服务器、Websocket代理、TCP代理、UDP代理、DNS代理、DNS加密代理,代理API认证,全能跨平台代理服务器。 +- [**7412**星][1m] [C++] [shadowsocks/shadowsocks-qt5](https://github.com/shadowsocks/shadowsocks-qt5) A cross-platform shadowsocks GUI client +- [**7397**星][1m] [Py] [s0md3v/xsstrike](https://github.com/s0md3v/XSStrike) Most advanced XSS scanner. +- [**7246**星][19d] [Java] [lionsoul2014/ip2region](https://github.com/lionsoul2014/ip2region) Ip2region is a offline IP location library with accuracy rate of 99.9% and 0.0x millseconds searching performance. DB file is less then 5Mb with all ip address stored. binding for Java,PHP,C,Python,Nodejs,Golang,C#,lua. Binary,B-tree,Memory searching algorithm +- [**7186**星][7m] [Shell] [teddysun/shadowsocks_install](https://github.com/teddysun/shadowsocks_install) Auto Install Shadowsocks Server for CentOS/Debian/Ubuntu +- [**7017**星][16d] [Go] [future-architect/vuls](https://github.com/future-architect/vuls) 针对Linux/FreeBSD 编写的漏洞扫描器. Go 语言编写 +- [**6989**星][5d] [C] [hashcat/hashcat](https://github.com/hashcat/hashcat) 世界上最快最先进的密码恢复工具 +- [**6984**星][2d] [Go] [nats-io/nats-server](https://github.com/nats-io/nats-server) High-Performance server for NATS, the cloud native messaging system. +- [**6984**星][2m] [JS] [cs01/gdbgui](https://github.com/cs01/gdbgui) Browser-based frontend to gdb (gnu debugger). Add breakpoints, view the stack, visualize data structures, and more in C, C++, Go, Rust, and Fortran. Run gdbgui from the terminal and a new tab will open in your browser. +- [**6957**星][11d] [greatfire/wiki](https://github.com/greatfire/wiki) 自由浏览 +- [**6949**星][3m] [Java] [pxb1988/dex2jar](https://github.com/pxb1988/dex2jar) Tools to work with android .dex and java .class files +- [**6869**星][2m] [Go] [sqshq/sampler](https://github.com/sqshq/sampler) A tool for shell commands execution, visualization and alerting. Configured with a simple YAML file. +- [**6812**星][19d] [Shell] [awslabs/git-secrets](https://github.com/awslabs/git-secrets) Prevents you from committing secrets and credentials into git repositories +- [**6732**星][9m] [Java] [amitshekhariitbhu/android-debug-database](https://github.com/amitshekhariitbhu/android-debug-database) A library for debugging android databases and shared preferences - Make Debugging Great Again +- [**6683**星][3d] [Java] [zaproxy/zaproxy](https://github.com/zaproxy/zaproxy) 在开发和测试Web App时自动发现安全漏洞 +- [**6682**星][3y] [C++] [alibaba/andfix](https://github.com/alibaba/andfix) AndFix is a library that offer hot-fix for Android App. +- [**6668**星][12d] [C++] [keepassxreboot/keepassxc](https://github.com/keepassxreboot/keepassxc) KeePassXC is a cross-platform community-driven port of the Windows application “Keepass Password Safe”. +- [**6595**星][3d] [Py] [networkx/networkx](https://github.com/networkx/networkx) 用于创建、操纵和研究复杂网络的结构,Python包 +- [**6555**星][6m] [Go] [shadowsocks/shadowsocks-go](https://github.com/shadowsocks/shadowsocks-go) go port of shadowsocks (Deprecated) +- [**6518**星][1m] [Py] [h2y/shadowrocket-adblock-rules](https://github.com/h2y/shadowrocket-adblock-rules) 提供多款 Shadowrocket 规则,带广告过滤功能。用于 iOS 未越狱设备选择性地自动翻墙。 +- [**6462**星][5d] [Shell] [cisofy/lynis](https://github.com/cisofy/lynis) Security auditing tool for Linux, macOS, and UNIX-based systems. Assists with compliance testing (HIPAA/ISO27001/PCI DSS) and system hardening. Agentless, and installation optional. +- [**6451**星][17d] [Go] [bettercap/bettercap](https://github.com/bettercap/bettercap) 新版的bettercap, Go 编写. bettercap 是强大的、模块化、可移植且易于扩展的 MITM 框架, 旧版用 Ruby 编写 +- [**6448**星][9m] [HTML] [open-power-workgroup/hospital](https://github.com/open-power-workgroup/hospital) OpenPower工作组收集汇总的医院开放数据 +- [**6310**星][29d] [Py] [seatgeek/fuzzywuzzy](https://github.com/seatgeek/fuzzywuzzy) Fuzzy String Matching in Python +- [**6197**星][2m] [ObjC] [johnno1962/injectionforxcode](https://github.com/johnno1962/injectionforxcode) Runtime Code Injection for Objective-C & Swift +- [**6194**星][3y] [PS] [powershellmafia/powersploit](https://github.com/PowerShellMafia/PowerSploit) PowerSploit - A PowerShell Post-Exploitation Framework +- [**6192**星][2m] [Py] [yandex/gixy](https://github.com/yandex/gixy) Nginx 配置静态分析工具,防止配置错误导致安全问题,自动化错误配置检测 +- [**6187**星][6m] [rmerl/asuswrt-merlin](https://github.com/rmerl/asuswrt-merlin) Enhanced version of Asus's router firmware (Asuswrt) (legacy code base) +- [**6146**星][2d] [JS] [avwo/whistle](https://github.com/avwo/whistle) 基于Node实现的跨平台抓包调试代理工具(HTTP, HTTP2, HTTPS, Websocket) +- [**6137**星][1y] [Hack] [facebook/fbctf](https://github.com/facebook/fbctf) Platform to host Capture the Flag competitions +- [**6128**星][9m] [Py] [schollz/howmanypeoplearearound](https://github.com/schollz/howmanypeoplearearound) 检测 Wifi 信号统计你周围的人数 +- [**6092**星][15d] [Go] [usefathom/fathom](https://github.com/usefathom/fathom) Fathom Lite. Simple, privacy-focused website analytics. Built with Golang & Preact. +- [**6074**星][16d] [Go] [quay/clair](https://github.com/quay/clair) Vulnerability Static Analysis for Containers +- [**6074**星][16d] [Go] [quay/clair](https://github.com/quay/clair) clair:容器(appc、docker)漏洞静态分析工具。 +- [**6073**星][5m] [Java] [qihoo360/replugin](https://github.com/qihoo360/replugin) RePlugin - A flexible, stable, easy-to-use Android Plug-in Framework +- [**6070**星][2y] [C] [jgamblin/mirai-source-code](https://github.com/jgamblin/mirai-source-code) Leaked Mirai Source Code for Research/IoC Development Purposes +- [**6021**星][3d] [Py] [cyrus-and/gdb-dashboard](https://github.com/cyrus-and/gdb-dashboard) Modular visual interface for GDB in Python +- [**6017**星][7d] [berzerk0/probable-wordlists](https://github.com/berzerk0/probable-wordlists) Version 2 is live! Wordlists sorted by probability originally created for password generation and testing - make sure your passwords aren't popular! +- [**5972**星][2m] [Java] [google/android-classyshark](https://github.com/google/android-classyshark) 分析基于Android/Java的App或游戏 +- [**5968**星][2d] [Py] [gallopsled/pwntools](https://github.com/gallopsled/pwntools) CTF framework and exploit development library +- [**5942**星][6m] [JS] [haotian-wang/google-access-helper](https://github.com/haotian-wang/google-access-helper) 谷歌访问助手破解版 +- [**5888**星][2d] [Py] [asciimoo/searx](https://github.com/asciimoo/searx) searx:网络元数据搜索引擎。汇总70 多个搜索引擎的搜素结果,避免用户被追踪或者被分析。可与 Tor 结合使用 +- [**5879**星][2d] [C++] [radareorg/cutter](https://github.com/radareorg/cutter) 逆向框架 radare2的Qt界面,iaito的升级版 +- [**5871**星][2m] [Gnuplot] [nasa-jpl/open-source-rover](https://github.com/nasa-jpl/open-source-rover) A build-it-yourself, 6-wheel rover based on the rovers on Mars! +- [**5815**星][7m] [JS] [sindresorhus/fkill-cli](https://github.com/sindresorhus/fkill-cli) Fabulously kill processes. Cross-platform. +- [**5773**星][1y] [qinyuhang/shadowsocksx-ng-r](https://github.com/qinyuhang/shadowsocksx-ng-r) Next Generation of ShadowsocksX +- [**5766**星][3m] [ObjC] [square/ponydebugger](https://github.com/square/ponydebugger) Remote network and data debugging for your native iOS app using Chrome Developer Tools +- [**5762**星][2m] [C] [spacehuhn/esp8266_deauther](https://github.com/spacehuhn/esp8266_deauther) 使用ESP8266 制作Wifi干扰器 +- [**5742**星][2y] [Py] [newsapps/beeswithmachineguns](https://github.com/newsapps/beeswithmachineguns) 创建多个micro EC2实例, 攻击指定Web App +- [**5740**星][8m] [C] [xoreaxeaxeax/movfuscator](https://github.com/xoreaxeaxeax/movfuscator) C编译器,编译的二进制文件只有1个代码块。 +- [**5694**星][9d] [JS] [swagger-api/swagger-editor](https://github.com/swagger-api/swagger-editor) Swagger Editor +- [**5693**星][2d] [Go] [casbin/casbin](https://github.com/casbin/casbin) An authorization library that supports access control models like ACL, RBAC, ABAC in Golang +- [**5626**星][1m] [C] [rofl0r/proxychains-ng](https://github.com/rofl0r/proxychains-ng) proxychains ng (new generation) - a preloader which hooks calls to sockets in dynamically linked programs and redirects it through one or more socks/http proxies. continuation of the unmaintained proxychains project. the sf.net page is currently not updated, use releases from github release page instead. +- [**5593**星][10d] [Ruby] [presidentbeef/brakeman](https://github.com/presidentbeef/brakeman) ROR程序的静态分析工具 +- [**5565**星][29d] [Roff] [max2max/freess](https://github.com/max2max/freess) 免费ss账号 免费shadowsocks账号 免费v2ray账号 (长期更新) +- [**5540**星][20d] [rshipp/awesome-malware-analysis](https://github.com/rshipp/awesome-malware-analysis) A curated list of awesome malware analysis tools and resources. +- [**5476**星][8m] [carpedm20/awesome-hacking](https://github.com/carpedm20/awesome-hacking) Hacking教程、工具和资源 +- [**5417**星][2m] [Py] [axi0mx/ipwndfu](https://github.com/axi0mx/ipwndfu) open-source jailbreaking tool for many iOS devices +- [**5413**星][2y] [Rust] [autumnai/leaf](https://github.com/autumnai/leaf) Open Machine Intelligence Framework for Hackers. (GPU/CPU) +- [**5371**星][5m] [C] [pwn20wndstuff/undecimus](https://github.com/pwn20wndstuff/undecimus) unc0ver jailbreak for iOS 11.0 - 12.4 +- [**5371**星][2d] [Py] [mlflow/mlflow](https://github.com/mlflow/mlflow) Open source platform for the machine learning lifecycle +- [**5324**星][4d] [Go] [zricethezav/gitleaks](https://github.com/zricethezav/gitleaks) Audit git repos for secrets +- [**5205**星][7m] [Py] [usarmyresearchlab/dshell](https://github.com/usarmyresearchlab/dshell) 网络审计分析 +- [**5196**星][3m] [Py] [ytisf/thezoo](https://github.com/ytisf/thezoo) A repository of LIVE malwares for your own joy and pleasure. theZoo is a project created to make the possibility of malware analysis open and available to the public. +- [**5192**星][1m] [Py] [refirmlabs/binwalk](https://github.com/ReFirmLabs/binwalk) 固件分析工具(命令行+IDA插件) - [IDA插件](https://github.com/ReFirmLabs/binwalk/tree/master/src/scripts) - [binwalk](https://github.com/ReFirmLabs/binwalk/tree/master/src/binwalk) -- [**5165**星][1y] [JS] [samyk/poisontap](https://github.com/samyk/poisontap) Exploits locked/password protected computers over USB, drops persistent WebSocket-based backdoor, exposes internal router, and siphons cookies using Raspberry Pi Zero & Node.js. -- [**5163**星][3m] [Py] [ytisf/thezoo](https://github.com/ytisf/thezoo) A repository of LIVE malwares for your own joy and pleasure. theZoo is a project created to make the possibility of malware analysis open and available to the public. -- [**5121**星][13d] [PHP] [tennc/webshell](https://github.com/tennc/webshell) webshell收集 -- [**5111**星][18d] [Shell] [vulhub/vulhub](https://github.com/vulhub/vulhub) Pre-Built Vulnerable Environments Based on Docker-Compose -- [**5096**星][4m] [Py] [n1nj4sec/pupy](https://github.com/n1nj4sec/pupy) Pupy is an opensource, cross-platform (Windows, Linux, OSX, Android) remote administration and post-exploitation tool mainly written in python -- [**5092**星][19d] [C++] [avast/retdec](https://github.com/avast/retdec) 基于 LLVM 的可重定位机器码反编译器, 可检测壳、检测和重构C++类继承、重构函数/类型/结构体等、可反编译为 C 或 Python 2种高级语言格式 -- [**5067**星][2m] [sbilly/awesome-security](https://github.com/sbilly/awesome-security) 与安全相关的软件、库、文档、书籍、资源和工具等收集 -- [**5054**星][2m] [Shell] [stackexchange/blackbox](https://github.com/stackexchange/blackbox) 文件使用PGP加密后隐藏在Git/Mercurial/Subversion -- [**5036**星][8d] [Go] [dnscrypt/dnscrypt-proxy](https://github.com/DNSCrypt/dnscrypt-proxy) 灵活的DNS代理,支持现代的加密DNS协议,例如:DNS protocols such as DNSCrypt v2, DNS-over-HTTPS and Anonymized DNSCrypt. -- [**5028**星][1m] [Java] [meituan-dianping/walle](https://github.com/meituan-dianping/walle) Android Signature V2 Scheme签名下的新一代渠道包打包神器 -- [**5026**星][4y] [Py] [shadowsocksr-backup/shadowsocksr](https://github.com/shadowsocksr-backup/shadowsocksr) Python port of ShadowsocksR -- [**5023**星][4m] [PowerShell] [empireproject/empire](https://github.com/EmpireProject/Empire) 后渗透框架. Windows客户端用PowerShell, Linux/OSX用Python. 之前PowerShell Empire和Python EmPyre的组合 -- [**5010**星][15d] [HTML] [owasp/owasp-mstg](https://github.com/owasp/owasp-mstg) 关于移动App安全开发、测试和逆向的相近手册 -- [**4990**星][1m] [Py] [snare/voltron](https://github.com/snare/voltron) A hacky debugger UI for hackers -- [**4941**星][10d] [Go] [inlets/inlets](https://github.com/inlets/inlets) Expose your local endpoints to the Internet -- [**4928**星][13d] [ASP] [hq450/fancyss](https://github.com/hq450/fancyss) fancyss is a project providing tools to across the GFW on asuswrt/merlin based router. -- [**4924**星][20d] [Py] [trustedsec/social-engineer-toolkit](https://github.com/trustedsec/social-engineer-toolkit) The Social-Engineer Toolkit (SET) repository from TrustedSec - All new versions of SET will be deployed here. -- [**4909**星][1y] [Go] [yinghuocho/firefly-proxy](https://github.com/yinghuocho/firefly-proxy) A proxy software to help circumventing the Great Firewall. -- [**4892**星][11m] [Go] [bitly/oauth2_proxy](https://github.com/bitly/oauth2_proxy) 反向代理,静态文件服务器,提供Providers(Google/Github)认证 -- [**4872**星][2m] [Rust] [sharkdp/hexyl](https://github.com/sharkdp/hexyl) 命令行中查看hex -- [**4872**星][7m] [Java] [guardianproject/haven](https://github.com/guardianproject/haven) 通过Android应用和设备上的传感器保护自己的个人空间和财产而又不损害 -- [**4868**星][9d] [Shell] [denisidoro/navi](https://github.com/denisidoro/navi) An interactive cheatsheet tool for the command-line -- [**4862**星][7d] [JS] [mobsf/mobile-security-framework-mobsf](https://github.com/MobSF/Mobile-Security-Framework-MobSF) Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis. -- [**4838**星][10d] [Go] [gcla/termshark](https://github.com/gcla/termshark) A terminal UI for tshark, inspired by Wireshark -- [**4835**星][8d] [Py] [alessandroz/lazagne](https://github.com/alessandroz/lazagne) Credentials recovery project -- [**4816**星][10d] [C] [offensive-security/exploitdb](https://github.com/offensive-security/exploitdb) The official Exploit Database repository -- [**4793**星][8m] [Py] [10se1ucgo/disablewintracking](https://github.com/10se1ucgo/disablewintracking) Uses some known methods that attempt to minimize tracking in Windows 10 -- [**4771**星][7d] [C] [google/oss-fuzz](https://github.com/google/oss-fuzz) 开源软件fuzzing -- [**4752**星][7d] [C++] [facebook/redex](https://github.com/facebook/redex) Android App字节码优化器 -- [**4717**星][7d] [Swift] [yanue/v2rayu](https://github.com/yanue/v2rayu) V2rayU,基于v2ray核心的mac版客户端,用于科学上网,使用swift编写,支持vmess,shadowsocks,socks5等服务协议,支持订阅, 支持二维码,剪贴板导入,手动配置,二维码分享等 -- [**4710**星][8d] [C++] [paddlepaddle/paddle-lite](https://github.com/PaddlePaddle/Paddle-Lite) Multi-platform high performance deep learning inference engine (『飞桨』多平台高性能深度学习预测引擎) -- [**4675**星][7d] [C++] [coatisoftware/sourcetrail](https://github.com/coatisoftware/sourcetrail) Sourcetrail - free and open-source interactive source explorer -- [**4651**星][7d] [Py] [manisso/fsociety](https://github.com/manisso/fsociety) fsociety Hacking Tools Pack – A Penetration Testing Framework -- [**4630**星][6m] [powershell/win32-openssh](https://github.com/powershell/win32-openssh) Win32 port of OpenSSH -- [**4627**星][16d] [C] [google/ios-webkit-debug-proxy](https://github.com/google/ios-webkit-debug-proxy) A DevTools proxy (Chrome Remote Debugging Protocol) for iOS devices (Safari Remote Web Inspector). -- [**4616**星][8d] [JS] [beefproject/beef](https://github.com/beefproject/beef) The Browser Exploitation Framework Project -- [**4611**星][19d] [Py] [secdev/scapy](https://github.com/secdev/scapy) 交互式数据包操作, Python, 命令行+库 -- [**4575**星][11m] [Py] [ecthros/uncaptcha2](https://github.com/ecthros/uncaptcha2) defeating the latest version of ReCaptcha with 91% accuracy -- [**4574**星][10d] [Go] [ginuerzh/gost](https://github.com/ginuerzh/gost) GO语言实现的安全隧道 -- [**4551**星][1y] [C] [upx/upx](https://github.com/upx/upx) UPX - the Ultimate Packer for eXecutables -- [**4549**星][8d] [C++] [mozilla/rr](https://github.com/mozilla/rr) 记录与重放App的调试执行过程 -- [**4526**星][10d] [Ruby] [wpscanteam/wpscan](https://github.com/wpscanteam/wpscan) WPScan is a free, for non-commercial use, black box WordPress Vulnerability Scanner written for security professionals and blog maintainers to test the security of their WordPress websites. -- [**4523**星][12d] [C] [jedisct1/dsvpn](https://github.com/jedisct1/dsvpn) A Dead Simple VPN. -- [**4485**星][18d] [TypeScript] [apis-guru/graphql-voyager](https://github.com/apis-guru/graphql-voyager) -- [**4454**星][1y] [Go] [wallix/awless](https://github.com/wallix/awless) A Mighty CLI for AWS -- [**4444**星][16d] [Py] [jopohl/urh](https://github.com/jopohl/urh) Universal Radio Hacker: investigate wireless protocols like a boss -- [**4426**星][22d] [Py] [jofpin/trape](https://github.com/jofpin/trape) 学习在互联网上跟踪别人,获取其详细信息,并避免被别人跟踪 -- [**4398**星][9d] [Makefile] [frida/frida](https://github.com/frida/frida) Clone this repo to build Frida -- [**4387**星][2m] [Shell] [zardus/ctf-tools](https://github.com/zardus/ctf-tools) Some setup scripts for security research tools. -- [**4343**星][13d] [Swift] [signalapp/signal-ios](https://github.com/signalapp/Signal-iOS) A private messenger for iOS. -- [**4339**星][12m] [Py] [lennylxx/ipv6-hosts](https://github.com/lennylxx/ipv6-hosts) Fork of -- [**4310**星][29d] [JS] [cure53/dompurify](https://github.com/cure53/dompurify) a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify works with a secure default, but offers a lot of configurability and hooks. Demo: -- [**4307**星][5m] [Py] [diafygi/acme-tiny](https://github.com/diafygi/acme-tiny) A tiny script to issue and renew TLS certs from Let's Encrypt -- [**4262**星][1m] [Py] [tensorflow/cleverhans](https://github.com/tensorflow/cleverhans) Python库,基准测试(benchmark)机器学习系统的漏洞生成(to)对抗样本(adversarial examples) -- [**4261**星][1m] [Shell] [ashishb/android-security-awesome](https://github.com/ashishb/android-security-awesome) A collection of android security related resources -- [**4256**星][11m] [JS] [butterproject/butter-desktop](https://github.com/butterproject/butter-desktop) All the free parts of Popcorn Time -- [**4243**星][9d] [Rust] [timvisee/ffsend](https://github.com/timvisee/ffsend) Easily and securely share files from the command line -- [**4210**星][4m] [Py] [dxa4481/trufflehog](https://github.com/dxa4481/trufflehog) Searches through git repositories for high entropy strings and secrets, digging deep into commit history -- [**4195**星][16d] [Go] [gophish/gophish](https://github.com/gophish/gophish) 网络钓鱼工具包 -- [**4195**星][2m] [Py] [evilsocket/opensnitch](https://github.com/evilsocket/opensnitch) opensnitch:Little Snitch 应用程序防火墙的 GNU/Linux 版本。(Little Snitch:Mac操作系统的应用程序防火墙,能防止应用程序在你不知道的情况下自动访问网络) -- [**4190**星][7m] [Objective-C] [alonemonkey/monkeydev](https://github.com/alonemonkey/monkeydev) CaptainHook Tweak、Logos Tweak and Command-line Tool、Patch iOS Apps, Without Jailbreak. -- [**4186**星][9d] [qazbnm456/awesome-web-security](https://github.com/qazbnm456/awesome-web-security) web 安全资源列表 -- [**4183**星][1y] [Go] [michenriksen/gitrob](https://github.com/michenriksen/gitrob) 查找push到公开的Github repo中的敏感信息 -- [**4175**星][11d] [we5ter/scanners-box](https://github.com/we5ter/scanners-box) 安全行业从业者自研开源扫描器合辑 -- [**4165**星][2y] [forter/security-101-for-saas-startups](https://github.com/forter/security-101-for-saas-startups) 初学者安全小窍门 -- [**4148**星][12m] [JS] [kdzwinel/betwixt](https://github.com/kdzwinel/betwixt) Betwixt will help you analyze web traffic outside the browser using familiar Chrome DevTools interface. -- [**4105**星][5m] [Py] [spiderclub/haipproxy](https://github.com/spiderclub/haipproxy) -- [**4092**星][2m] [Py] [aboul3la/sublist3r](https://github.com/aboul3la/sublist3r) Fast subdomains enumeration tool for penetration testers -- [**4091**星][7d] [Java] [spring-projects/spring-security](https://github.com/spring-projects/spring-security) Spring Security -- [**4083**星][2y] [Py] [xoreaxeaxeax/sandsifter](https://github.com/xoreaxeaxeax/sandsifter) sandsifter:x86 处理器 Fuzzer,查找 Intel 的隐藏指令和 CPU bug -- [**4069**星][9m] [wtsxdev/reverse-engineering](https://github.com/wtsxdev/reverse-engineering) List of awesome reverse engineering resources -- [**4039**星][1m] [JS] [sigalor/whatsapp-web-reveng](https://github.com/sigalor/whatsapp-web-reveng) WhatsApp Web API逆向与重新实现 -- [**4033**星][7d] [Py] [google/clusterfuzz](https://github.com/google/clusterfuzz) Scalable fuzzing infrastructure. -- [**4023**星][2m] [Java] [jesusfreke/smali](https://github.com/jesusfreke/smali) smali/baksmali -- [**4015**星][3m] [JS] [cuckoosandbox/cuckoo](https://github.com/cuckoosandbox/cuckoo) Cuckoo Sandbox is an automated dynamic malware analysis system -- [**3989**星][1y] [JS] [travist/jsencrypt](https://github.com/travist/jsencrypt) A Javascript library to perform OpenSSL RSA Encryption, Decryption, and Key Generation. -- [**3985**星][20d] [drduh/yubikey-guide](https://github.com/drduh/yubikey-guide) Guide to using YubiKey for GPG and SSH -- [**3955**星][3m] [Py] [nullarray/autosploit](https://github.com/nullarray/autosploit) Automated Mass Exploiter -- [**3936**星][13d] [Go] [dexidp/dex](https://github.com/dexidp/dex) OpenID Connect Identity (OIDC) and OAuth 2.0 Provider with Pluggable Connectors -- [**3929**星][2m] [JS] [apsdehal/awesome-ctf](https://github.com/apsdehal/awesome-ctf) A curated list of CTF frameworks, libraries, resources and softwares -- [**3929**星][2m] [JS] [apsdehal/awesome-ctf](https://github.com/apsdehal/awesome-ctf) A curated list of CTF frameworks, libraries, resources and softwares -- [**3925**星][4m] [PHP] [paragonie/awesome-appsec](https://github.com/paragonie/awesome-appsec) A curated list of resources for learning about application security -- [**3916**星][7d] [Py] [angr/angr](https://github.com/angr/angr) A powerful and user-friendly binary analysis platform! -- [**3908**星][14d] [Rust] [svenstaro/genact](https://github.com/svenstaro/genact) a nonsense activity generator -- [**3907**星][1m] [C] [aquynh/capstone](https://github.com/aquynh/capstone) Capstone disassembly/disassembler framework: Core (Arm, Arm64, BPF, EVM, M68K, M680X, MOS65xx, Mips, PPC, RISCV, Sparc, SystemZ, TMS320C64x, Web Assembly, X86, X86_64, XCore) + bindings. -- [**3896**星][2y] [C#] [shadowsocksr-backup/shadowsocksr-csharp](https://github.com/shadowsocksr-backup/shadowsocksr-csharp) -- [**3876**星][7d] [C++] [baldurk/renderdoc](https://github.com/baldurk/renderdoc) RenderDoc is a stand-alone graphics debugging tool. -- [**3856**星][2m] [PHP] [fuzzdb-project/fuzzdb](https://github.com/fuzzdb-project/fuzzdb) 通过动态App安全测试来查找App安全漏洞, 算是不带扫描器的漏洞扫描器 -- [**3841**星][8m] [Go] [eranyanay/1m-go-websockets](https://github.com/eranyanay/1m-go-websockets) handling 1M websockets connections in Go -- [**3837**星][15d] [JS] [shadowsocks/shadowsocks-manager](https://github.com/shadowsocks/shadowsocks-manager) A shadowsocks manager tool for multi user and traffic control. -- [**3836**星][11d] [Py] [secureauthcorp/impacket](https://github.com/SecureAuthCorp/impacket) Python类收集, 用于与网络协议交互 -- [**3832**星][2m] [Objective-C] [sveinbjornt/sloth](https://github.com/sveinbjornt/sloth) Mac app that shows all open files, directories and sockets in use by all running processes. Nice GUI for lsof. -- [**3825**星][4y] [iosre/iosappreverseengineering](https://github.com/iosre/iosappreverseengineering) The world’s 1st book of very detailed iOS App reverse engineering skills :) -- [**3781**星][13d] [hq450/fancyss_history_package](https://github.com/hq450/fancyss_history_package) 科学上网插件的离线安装包储存在这里 -- [**3770**星][30d] [jivoi/awesome-osint](https://github.com/jivoi/awesome-osint) OSINT资源收集 -- [**3763**星][5y] [shadowsocksr-backup/shadowsocks-rss](https://github.com/shadowsocksr-backup/shadowsocks-rss) ShadowsocksR update rss, SSR organization -- [**3754**星][10m] [Py] [longld/peda](https://github.com/longld/peda) Python Exploit Development Assistance for GDB -- [**3749**星][2m] [Go] [microsoft/ethr](https://github.com/microsoft/ethr) Ethr is a Network Performance Measurement Tool for TCP, UDP & HTTP. -- [**3739**星][2m] [PHP] [ethicalhack3r/dvwa](https://github.com/ethicalhack3r/DVWA) Damn Vulnerable Web Application (DVWA) -- [**3739**星][2m] [Py] [paralax/awesome-honeypots](https://github.com/paralax/awesome-honeypots) an awesome list of honeypot resources -- [**3731**星][1m] [C] [iaik/meltdown](https://github.com/iaik/meltdown) This repository contains several applications, demonstrating the Meltdown bug. -- [**3731**星][13d] [Go] [hashicorp/consul-template](https://github.com/hashicorp/consul-template) Template rendering, notifier, and supervisor for -- [**3718**星][4m] [Py] [malwaredllc/byob](https://github.com/malwaredllc/byob) BYOB (Build Your Own Botnet) -- [**3681**星][11d] [jjqqkk/chromium](https://github.com/jjqqkk/chromium) Chromium browser with SSL VPN. Use this browser to unblock websites. -- [**3679**星][2y] [JS] [samyk/evercookie](https://github.com/samyk/evercookie) JavaScript API,在浏览器中创建超级顽固的cookie,在标准Cookie、Flask Cookie等被清除之后依然能够识别客户端 -- [**3675**星][8d] [HTML] [hamukazu/lets-get-arrested](https://github.com/hamukazu/lets-get-arrested) This project is intended to protest against the police in Japan -- [**3660**星][1y] [Py] [misterch0c/shadowbroker](https://github.com/misterch0c/shadowbroker) 方程式最新泄露 -- [**3653**星][4m] [C] [facebook/fishhook](https://github.com/facebook/fishhook) A library that enables dynamically rebinding symbols in Mach-O binaries running on iOS. -- [**3647**星][8d] [JS] [lesspass/lesspass](https://github.com/lesspass/lesspass) -- [**3645**星][26d] [C#] [0xd4d/de4dot](https://github.com/0xd4d/de4dot) .NET deobfuscator and unpacker. -- [**3640**星][4m] [C] [secwiki/windows-kernel-exploits](https://github.com/secwiki/windows-kernel-exploits) windows-kernel-exploits Windows平台提权漏洞集合 -- [**3639**星][2y] [Py] [qiyeboy/ipproxypool](https://github.com/qiyeboy/ipproxypool) IPProxyPool代理池项目,提供代理ip -- [**3624**星][29d] [acl4ssr/acl4ssr](https://github.com/acl4ssr/acl4ssr) SSR 去广告ACL规则/SS完整GFWList规则,Telegram频道订阅地址 -- [**3621**星][2m] [C] [atmosphere-nx/atmosphere](https://github.com/atmosphere-nx/atmosphere) Atmosphère is a work-in-progress customized firmware for the Nintendo Switch. -- [**3615**星][5y] [C#] [brandonlw/psychson](https://github.com/brandonlw/Psychson) Phison 2251-03 (2303) Custom Firmware & Existing Firmware Patches (BadUSB) -- [**3612**星][17d] [HTML] [consensys/smart-contract-best-practices](https://github.com/consensys/smart-contract-best-practices) A guide to smart contract security best practices -- [**3598**星][8d] [TypeScript] [javascript-obfuscator/javascript-obfuscator](https://github.com/javascript-obfuscator/javascript-obfuscator) A powerful obfuscator for JavaScript and Node.js +- [**5167**星][20d] [Shell] [vulhub/vulhub](https://github.com/vulhub/vulhub) Pre-Built Vulnerable Environments Based on Docker-Compose +- [**5167**星][1y] [JS] [samyk/poisontap](https://github.com/samyk/poisontap) Exploits locked/password protected computers over USB, drops persistent WebSocket-based backdoor, exposes internal router, and siphons cookies using Raspberry Pi Zero & Node.js. +- [**5148**星][6d] [PHP] [tennc/webshell](https://github.com/tennc/webshell) webshell收集 +- [**5123**星][21d] [C++] [avast/retdec](https://github.com/avast/retdec) 基于 LLVM 的可重定位机器码反编译器, 可检测壳、检测和重构C++类继承、重构函数/类型/结构体等、可反编译为 C 或 Python 2种高级语言格式 +- [**5118**星][15d] [ObjC] [macpass/macpass](https://github.com/MacPass/MacPass) A native OS X KeePass client +- [**5118**星][4m] [Py] [n1nj4sec/pupy](https://github.com/n1nj4sec/pupy) Pupy is an opensource, cross-platform (Windows, Linux, OSX, Android) remote administration and post-exploitation tool mainly written in python +- [**5089**星][2d] [Go] [dnscrypt/dnscrypt-proxy](https://github.com/DNSCrypt/dnscrypt-proxy) 灵活的DNS代理,支持现代的加密DNS协议,例如:DNS protocols such as DNSCrypt v2, DNS-over-HTTPS and Anonymized DNSCrypt. +- [**5082**星][2m] [sbilly/awesome-security](https://github.com/sbilly/awesome-security) 与安全相关的软件、库、文档、书籍、资源和工具等收集 +- [**5065**星][2m] [Shell] [stackexchange/blackbox](https://github.com/stackexchange/blackbox) 文件使用PGP加密后隐藏在Git/Mercurial/Subversion +- [**5059**星][1m] [Java] [meituan-dianping/walle](https://github.com/meituan-dianping/walle) Android Signature V2 Scheme签名下的新一代渠道包打包神器 +- [**5054**星][4y] [Py] [shadowsocksr-backup/shadowsocksr](https://github.com/shadowsocksr-backup/shadowsocksr) Python port of ShadowsocksR +- [**5042**星][2d] [HTML] [owasp/owasp-mstg](https://github.com/owasp/owasp-mstg) 关于移动App安全开发、测试和逆向的相近手册 +- [**5037**星][4m] [PS] [empireproject/empire](https://github.com/EmpireProject/Empire) 后渗透框架. Windows客户端用PowerShell, Linux/OSX用Python. 之前PowerShell Empire和Python EmPyre的组合 +- [**5021**星][2d] [Py] [mobsf/mobile-security-framework-mobsf](https://github.com/MobSF/Mobile-Security-Framework-MobSF) Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis. +- [**5005**星][2d] [C++] [coatisoftware/sourcetrail](https://github.com/coatisoftware/sourcetrail) Sourcetrail - free and open-source interactive source explorer +- [**4996**星][2d] [ASP] [hq450/fancyss](https://github.com/hq450/fancyss) fancyss is a project providing tools to across the GFW on asuswrt/merlin based router. +- [**4996**星][6d] [Go] [inlets/inlets](https://github.com/inlets/inlets) Expose your local endpoints to the Internet +- [**4994**星][1m] [Py] [snare/voltron](https://github.com/snare/voltron) A hacky debugger UI for hackers +- [**4953**星][22d] [Py] [trustedsec/social-engineer-toolkit](https://github.com/trustedsec/social-engineer-toolkit) The Social-Engineer Toolkit (SET) repository from TrustedSec - All new versions of SET will be deployed here. +- [**4920**星][2d] [TS] [jigsaw-code/outline-client](https://github.com/jigsaw-code/outline-client) Outline clients, developed by Jigsaw. The Outline clients use the popular Shadowsocks protocol, and lean on the Cordova and Electron frameworks to support Windows, Android / ChromeOS, Linux, iOS and macOS. +- [**4913**星][1y] [Go] [yinghuocho/firefly-proxy](https://github.com/yinghuocho/firefly-proxy) A proxy software to help circumventing the Great Firewall. +- [**4909**星][2d] [Shell] [denisidoro/navi](https://github.com/denisidoro/navi) An interactive cheatsheet tool for the command-line +- [**4897**星][11m] [Go] [bitly/oauth2_proxy](https://github.com/bitly/oauth2_proxy) 反向代理,静态文件服务器,提供Providers(Google/Github)认证 +- [**4883**星][2m] [Rust] [sharkdp/hexyl](https://github.com/sharkdp/hexyl) 命令行中查看hex +- [**4881**星][5d] [Java] [guardianproject/haven](https://github.com/guardianproject/haven) 通过Android应用和设备上的传感器保护自己的个人空间和财产而又不损害 +- [**4869**星][2d] [Swift] [yanue/v2rayu](https://github.com/yanue/v2rayu) V2rayU,基于v2ray核心的mac版客户端,用于科学上网,使用swift编写,支持vmess,shadowsocks,socks5等服务协议,支持订阅, 支持二维码,剪贴板导入,手动配置,二维码分享等 +- [**4867**星][10d] [Py] [alessandroz/lazagne](https://github.com/alessandroz/lazagne) Credentials recovery project +- [**4847**星][3d] [Go] [gcla/termshark](https://github.com/gcla/termshark) A terminal UI for tshark, inspired by Wireshark +- [**4841**星][2d] [C] [offensive-security/exploitdb](https://github.com/offensive-security/exploitdb) The official Exploit Database repository +- [**4803**星][8m] [Py] [10se1ucgo/disablewintracking](https://github.com/10se1ucgo/disablewintracking) Uses some known methods that attempt to minimize tracking in Windows 10 +- [**4782**星][2d] [C] [google/oss-fuzz](https://github.com/google/oss-fuzz) 开源软件fuzzing +- [**4761**星][2d] [C++] [facebook/redex](https://github.com/facebook/redex) Android App字节码优化器 +- [**4724**星][2d] [C++] [paddlepaddle/paddle-lite](https://github.com/PaddlePaddle/Paddle-Lite) Multi-platform high performance deep learning inference engine (『飞桨』多平台高性能深度学习预测引擎) +- [**4691**星][9d] [Py] [manisso/fsociety](https://github.com/manisso/fsociety) fsociety Hacking Tools Pack – A Penetration Testing Framework +- [**4639**星][3d] [Py] [secdev/scapy](https://github.com/secdev/scapy) 交互式数据包操作, Python, 命令行+库 +- [**4638**星][18d] [C] [google/ios-webkit-debug-proxy](https://github.com/google/ios-webkit-debug-proxy) A DevTools proxy (Chrome Remote Debugging Protocol) for iOS devices (Safari Remote Web Inspector). +- [**4637**星][6m] [powershell/win32-openssh](https://github.com/powershell/win32-openssh) Win32 port of OpenSSH +- [**4633**星][2d] [JS] [beefproject/beef](https://github.com/beefproject/beef) The Browser Exploitation Framework Project +- [**4615**星][12d] [Go] [ginuerzh/gost](https://github.com/ginuerzh/gost) GO语言实现的安全隧道 +- [**4589**星][11m] [Py] [ecthros/uncaptcha2](https://github.com/ecthros/uncaptcha2) defeating the latest version of ReCaptcha with 91% accuracy +- [**4583**星][1y] [C] [upx/upx](https://github.com/upx/upx) UPX - the Ultimate Packer for eXecutables +- [**4575**星][4d] [C++] [mozilla/rr](https://github.com/mozilla/rr) 记录与重放App的调试执行过程 +- [**4543**星][4d] [Ruby] [wpscanteam/wpscan](https://github.com/wpscanteam/wpscan) WPScan is a free, for non-commercial use, black box WordPress Vulnerability Scanner written for security professionals and blog maintainers to test the security of their WordPress websites. +- [**4529**星][6d] [C] [jedisct1/dsvpn](https://github.com/jedisct1/dsvpn) A Dead Simple VPN. +- [**4498**星][6d] [TS] [apis-guru/graphql-voyager](https://github.com/apis-guru/graphql-voyager) +- [**4459**星][8d] [Py] [jopohl/urh](https://github.com/jopohl/urh) Universal Radio Hacker: investigate wireless protocols like a boss +- [**4458**星][1y] [Go] [wallix/awless](https://github.com/wallix/awless) A Mighty CLI for AWS +- [**4449**星][3d] [Go] [dragonflyoss/dragonfly](https://github.com/dragonflyoss/Dragonfly) Dragonfly is an intelligent P2P based image and file distribution system. +- [**4446**星][2d] [Makefile] [frida/frida](https://github.com/frida/frida) Clone this repo to build Frida +- [**4443**星][24d] [Py] [jofpin/trape](https://github.com/jofpin/trape) 学习在互联网上跟踪别人,获取其详细信息,并避免被别人跟踪 +- [**4411**星][2m] [Shell] [zardus/ctf-tools](https://github.com/zardus/ctf-tools) Some setup scripts for security research tools. +- [**4359**星][6d] [Swift] [signalapp/signal-ios](https://github.com/signalapp/Signal-iOS) A private messenger for iOS. +- [**4346**星][1m] [JS] [cure53/dompurify](https://github.com/cure53/dompurify) a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify works with a secure default, but offers a lot of configurability and hooks. Demo: +- [**4344**星][12m] [Py] [lennylxx/ipv6-hosts](https://github.com/lennylxx/ipv6-hosts) Fork of +- [**4313**星][5m] [Py] [diafygi/acme-tiny](https://github.com/diafygi/acme-tiny) A tiny script to issue and renew TLS certs from Let's Encrypt +- [**4283**星][7d] [Py] [tensorflow/cleverhans](https://github.com/tensorflow/cleverhans) Python库,基准测试(benchmark)机器学习系统的漏洞生成(to)对抗样本(adversarial examples) +- [**4280**星][1m] [Shell] [ashishb/android-security-awesome](https://github.com/ashishb/android-security-awesome) A collection of android security related resources +- [**4261**星][5d] [Rust] [timvisee/ffsend](https://github.com/timvisee/ffsend) Easily and securely share files from the command line +- [**4258**星][11m] [JS] [butterproject/butter-desktop](https://github.com/butterproject/butter-desktop) All the free parts of Popcorn Time +- [**4244**星][2y] [imeiji/shadowsocks_install](https://github.com/imeiji/shadowsocks_install) Auto install shadowsocks server,thanks 秋水逸冰 +- [**4241**星][4m] [Py] [dxa4481/trufflehog](https://github.com/dxa4481/trufflehog) Searches through git repositories for high entropy strings and secrets, digging deep into commit history +- [**4215**星][7m] [ObjC] [alonemonkey/monkeydev](https://github.com/alonemonkey/monkeydev) CaptainHook Tweak、Logos Tweak and Command-line Tool、Patch iOS Apps, Without Jailbreak. +- [**4211**星][9d] [Go] [gophish/gophish](https://github.com/gophish/gophish) 网络钓鱼工具包 +- [**4205**星][11d] [qazbnm456/awesome-web-security](https://github.com/qazbnm456/awesome-web-security) web 安全资源列表 +- [**4204**星][1y] [Go] [michenriksen/gitrob](https://github.com/michenriksen/gitrob) 查找push到公开的Github repo中的敏感信息 +- [**4202**星][2m] [Py] [evilsocket/opensnitch](https://github.com/evilsocket/opensnitch) opensnitch:Little Snitch 应用程序防火墙的 GNU/Linux 版本。(Little Snitch:Mac操作系统的应用程序防火墙,能防止应用程序在你不知道的情况下自动访问网络) +- [**4198**星][2d] [Py] [openmined/pysyft](https://github.com/openmined/pysyft) A library for encrypted, privacy preserving machine learning +- [**4190**星][13d] [we5ter/scanners-box](https://github.com/we5ter/scanners-box) 安全行业从业者自研开源扫描器合辑 +- [**4171**星][2y] [forter/security-101-for-saas-startups](https://github.com/forter/security-101-for-saas-startups) 初学者安全小窍门 +- [**4149**星][12m] [JS] [kdzwinel/betwixt](https://github.com/kdzwinel/betwixt) Betwixt will help you analyze web traffic outside the browser using familiar Chrome DevTools interface. +- [**4131**星][5d] [Java] [spring-projects/spring-security](https://github.com/spring-projects/spring-security) Spring Security +- [**4120**星][5m] [Py] [spiderclub/haipproxy](https://github.com/spiderclub/haipproxy) +- [**4120**星][2m] [Py] [aboul3la/sublist3r](https://github.com/aboul3la/sublist3r) Fast subdomains enumeration tool for penetration testers +- [**4096**星][2y] [Py] [xoreaxeaxeax/sandsifter](https://github.com/xoreaxeaxeax/sandsifter) sandsifter:x86 处理器 Fuzzer,查找 Intel 的隐藏指令和 CPU bug +- [**4092**星][9m] [wtsxdev/reverse-engineering](https://github.com/wtsxdev/reverse-engineering) List of awesome reverse engineering resources +- [**4046**星][1m] [JS] [sigalor/whatsapp-web-reveng](https://github.com/sigalor/whatsapp-web-reveng) WhatsApp Web API逆向与重新实现 +- [**4045**星][2m] [Java] [jesusfreke/smali](https://github.com/jesusfreke/smali) smali/baksmali +- [**4044**星][2d] [Py] [google/clusterfuzz](https://github.com/google/clusterfuzz) Scalable fuzzing infrastructure. +- [**4022**星][22d] [drduh/yubikey-guide](https://github.com/drduh/yubikey-guide) Guide to using YubiKey for GPG and SSH +- [**4021**星][3m] [JS] [cuckoosandbox/cuckoo](https://github.com/cuckoosandbox/cuckoo) Cuckoo Sandbox is an automated dynamic malware analysis system +- [**4000**星][1y] [JS] [travist/jsencrypt](https://github.com/travist/jsencrypt) A Javascript library to perform OpenSSL RSA Encryption, Decryption, and Key Generation. +- [**3967**星][3m] [Py] [nullarray/autosploit](https://github.com/nullarray/autosploit) Automated Mass Exploiter +- [**3961**星][5d] [Go] [dexidp/dex](https://github.com/dexidp/dex) OpenID Connect Identity (OIDC) and OAuth 2.0 Provider with Pluggable Connectors +- [**3953**星][2m] [JS] [apsdehal/awesome-ctf](https://github.com/apsdehal/awesome-ctf) A curated list of CTF frameworks, libraries, resources and softwares +- [**3953**星][2m] [JS] [apsdehal/awesome-ctf](https://github.com/apsdehal/awesome-ctf) A curated list of CTF frameworks, libraries, resources and softwares +- [**3937**星][3d] [Py] [angr/angr](https://github.com/angr/angr) A powerful and user-friendly binary analysis platform! +- [**3935**星][4m] [PHP] [paragonie/awesome-appsec](https://github.com/paragonie/awesome-appsec) A curated list of resources for learning about application security +- [**3933**星][8m] [Go] [eranyanay/1m-go-websockets](https://github.com/eranyanay/1m-go-websockets) handling 1M websockets connections in Go +- [**3923**星][1m] [C] [aquynh/capstone](https://github.com/aquynh/capstone) Capstone disassembly/disassembler framework: Core (Arm, Arm64, BPF, EVM, M68K, M680X, MOS65xx, Mips, PPC, RISCV, Sparc, SystemZ, TMS320C64x, Web Assembly, X86, X86_64, XCore) + bindings. +- [**3920**星][2y] [C#] [shadowsocksr-backup/shadowsocksr-csharp](https://github.com/shadowsocksr-backup/shadowsocksr-csharp) +- [**3915**星][16d] [Rust] [svenstaro/genact](https://github.com/svenstaro/genact) a nonsense activity generator +- [**3893**星][2d] [C++] [baldurk/renderdoc](https://github.com/baldurk/renderdoc) RenderDoc is a stand-alone graphics debugging tool. +- [**3878**星][2m] [PHP] [fuzzdb-project/fuzzdb](https://github.com/fuzzdb-project/fuzzdb) 通过动态App安全测试来查找App安全漏洞, 算是不带扫描器的漏洞扫描器 +- [**3869**星][2d] [Py] [secureauthcorp/impacket](https://github.com/SecureAuthCorp/impacket) Python类收集, 用于与网络协议交互 +- [**3848**星][7d] [JS] [shadowsocks/shadowsocks-manager](https://github.com/shadowsocks/shadowsocks-manager) A shadowsocks manager tool for multi user and traffic control. +- [**3845**星][2d] [hq450/fancyss_history_package](https://github.com/hq450/fancyss_history_package) 科学上网插件的离线安装包储存在这里 +- [**3838**星][2m] [ObjC] [sveinbjornt/sloth](https://github.com/sveinbjornt/sloth) Mac app that shows all open files, directories and sockets in use by all running processes. Nice GUI for lsof. +- [**3831**星][4y] [iosre/iosappreverseengineering](https://github.com/iosre/iosappreverseengineering) The world’s 1st book of very detailed iOS App reverse engineering skills :) +- [**3813**星][1m] [jivoi/awesome-osint](https://github.com/jivoi/awesome-osint) OSINT资源收集 +- [**3799**星][5y] [shadowsocksr-backup/shadowsocks-rss](https://github.com/shadowsocksr-backup/shadowsocks-rss) ShadowsocksR update rss, SSR organization +- [**3767**星][10m] [Py] [longld/peda](https://github.com/longld/peda) Python Exploit Development Assistance for GDB +- [**3763**星][2m] [Py] [paralax/awesome-honeypots](https://github.com/paralax/awesome-honeypots) an awesome list of honeypot resources +- [**3755**星][2m] [PHP] [ethicalhack3r/dvwa](https://github.com/ethicalhack3r/DVWA) Damn Vulnerable Web Application (DVWA) +- [**3752**星][2m] [Go] [microsoft/ethr](https://github.com/microsoft/ethr) Ethr is a Network Performance Measurement Tool for TCP, UDP & HTTP. +- [**3736**星][8d] [Go] [hashicorp/consul-template](https://github.com/hashicorp/consul-template) Template rendering, notifier, and supervisor for +- [**3733**星][2m] [C] [iaik/meltdown](https://github.com/iaik/meltdown) This repository contains several applications, demonstrating the Meltdown bug. +- [**3730**星][4m] [Py] [malwaredllc/byob](https://github.com/malwaredllc/byob) BYOB (Build Your Own Botnet) +- [**3719**星][6d] [jjqqkk/chromium](https://github.com/jjqqkk/chromium) Chromium browser with SSL VPN. Use this browser to unblock websites. +- [**3713**星][2d] [C] [atmosphere-nx/atmosphere](https://github.com/atmosphere-nx/atmosphere) Atmosphère is a work-in-progress customized firmware for the Nintendo Switch. +- [**3684**星][2y] [JS] [samyk/evercookie](https://github.com/samyk/evercookie) JavaScript API,在浏览器中创建超级顽固的cookie,在标准Cookie、Flask Cookie等被清除之后依然能够识别客户端 +- [**3682**星][10d] [HTML] [hamukazu/lets-get-arrested](https://github.com/hamukazu/lets-get-arrested) This project is intended to protest against the police in Japan +- [**3670**星][2d] [JS] [lesspass/lesspass](https://github.com/lesspass/lesspass) +- [**3668**星][8d] [C#] [0xd4d/de4dot](https://github.com/0xd4d/de4dot) .NET deobfuscator and unpacker. +- [**3667**星][1y] [Py] [misterch0c/shadowbroker](https://github.com/misterch0c/shadowbroker) 方程式最新泄露 +- [**3666**星][5m] [C] [secwiki/windows-kernel-exploits](https://github.com/secwiki/windows-kernel-exploits) windows-kernel-exploits Windows平台提权漏洞集合 +- [**3663**星][4m] [C] [facebook/fishhook](https://github.com/facebook/fishhook) A library that enables dynamically rebinding symbols in Mach-O binaries running on iOS. +- [**3652**星][4d] [acl4ssr/acl4ssr](https://github.com/acl4ssr/acl4ssr) SSR 去广告ACL规则/SS完整GFWList规则,Telegram频道订阅地址 +- [**3647**星][2y] [Py] [qiyeboy/ipproxypool](https://github.com/qiyeboy/ipproxypool) IPProxyPool代理池项目,提供代理ip +- [**3622**星][6d] [TS] [javascript-obfuscator/javascript-obfuscator](https://github.com/javascript-obfuscator/javascript-obfuscator) A powerful obfuscator for JavaScript and Node.js +- [**3621**星][7d] [HTML] [consensys/smart-contract-best-practices](https://github.com/consensys/smart-contract-best-practices) A guide to smart contract security best practices +- [**3619**星][5y] [C#] [brandonlw/psychson](https://github.com/brandonlw/Psychson) Phison 2251-03 (2303) Custom Firmware & Existing Firmware Patches (BadUSB) +- [**3611**星][2m] [Java] [ffay/lanproxy](https://github.com/ffay/lanproxy) lanproxy是一个将局域网个人电脑、服务器代理到公网的内网穿透工具,支持tcp流量转发,可支持任何tcp上层协议(访问内网网站、本地支付接口调试、ssh访问、远程桌面...)。目前市面上提供类似服务的有花生壳、TeamView、GoToMyCloud等等,但要使用第三方的公网服务器就必须为第三方付费,并且这些服务都有各种各样的限制,此外,由于数据包会流经第三方,因此对数据安全也是一大隐患。技术交流QQ群 946273429 +- [**3604**星][8d] [PS] [bloodhoundad/bloodhound](https://github.com/BloodHoundAD/BloodHound) a single page Javascript web application, uses graph theory to reveal the hidden and often unintended relationships within an Active Directory environment. +- [**3598**星][26d] [C++] [anbox/anbox](https://github.com/anbox/anbox) 在常规GNU / Linux系统上引导完整的Android系统,基于容器 - [**3597**星][1y] [C#] [nummer/destroy-windows-10-spying](https://github.com/nummer/destroy-windows-10-spying) Destroy Windows Spying tool -- [**3594**星][2m] [Java] [ffay/lanproxy](https://github.com/ffay/lanproxy) lanproxy是一个将局域网个人电脑、服务器代理到公网的内网穿透工具,支持tcp流量转发,可支持任何tcp上层协议(访问内网网站、本地支付接口调试、ssh访问、远程桌面...)。目前市面上提供类似服务的有花生壳、TeamView、GoToMyCloud等等,但要使用第三方的公网服务器就必须为第三方付费,并且这些服务都有各种各样的限制,此外,由于数据包会流经第三方,因此对数据安全也是一大隐患。技术交流QQ群 946273429 -- [**3591**星][3y] [Perl] [x0rz/eqgrp](https://github.com/x0rz/eqgrp) Decrypted content of eqgrp-auction-file.tar.xz -- [**3587**星][2m] [PowerShell] [bloodhoundad/bloodhound](https://github.com/BloodHoundAD/BloodHound) a single page Javascript web application, uses graph theory to reveal the hidden and often unintended relationships within an Active Directory environment. -- [**3578**星][24d] [C++] [anbox/anbox](https://github.com/anbox/anbox) 在常规GNU / Linux系统上引导完整的Android系统,基于容器 -- [**3565**星][7d] [Shell] [drwetter/testssl.sh](https://github.com/drwetter/testssl.sh) 检查服务器任意端口对 TLS/SSL 的支持、协议以及一些加密缺陷,命令行工具 -- [**3560**星][17d] [C] [nmap/nmap](https://github.com/nmap/nmap) Nmap -- [**3544**星][6y] [R] [johnmyleswhite/ml_for_hackers](https://github.com/johnmyleswhite/ml_for_hackers) 《Machine Learning for Hackers》随书代码 +- [**3595**星][3y] [Perl] [x0rz/eqgrp](https://github.com/x0rz/eqgrp) Decrypted content of eqgrp-auction-file.tar.xz +- [**3583**星][3d] [Shell] [drwetter/testssl.sh](https://github.com/drwetter/testssl.sh) 检查服务器任意端口对 TLS/SSL 的支持、协议以及一些加密缺陷,命令行工具 +- [**3580**星][5d] [C] [nmap/nmap](https://github.com/nmap/nmap) Nmap +- [**3562**星][5d] [Pascal] [cheat-engine/cheat-engine](https://github.com/cheat-engine/cheat-engine) Cheat Engine. A development environment focused on modding +- [**3542**星][6y] [R] [johnmyleswhite/ml_for_hackers](https://github.com/johnmyleswhite/ml_for_hackers) 《Machine Learning for Hackers》随书代码 +- [**3540**星][6d] [blacckhathaceekr/pentesting-bible](https://github.com/blacckhathaceekr/pentesting-bible) links reaches 10000 links & 10000 pdf files .Learn Ethical Hacking and penetration testing .hundreds of ethical hacking & penetration testing & red team & cyber security & computer science resources. - [**3538**星][4m] [Shell] [chengr28/revokechinacerts](https://github.com/chengr28/revokechinacerts) Revoke Chinese certificates. -- [**3525**星][8d] [Pascal] [cheat-engine/cheat-engine](https://github.com/cheat-engine/cheat-engine) Cheat Engine. A development environment focused on modding -- [**3503**星][14d] [JS] [aol/moloch](https://github.com/aol/moloch) 数据包捕获、索引工具,支持数据库 -- [**3494**星][8m] [Go] [fanpei91/torsniff](https://github.com/fanpei91/torsniff) torsniff - a sniffer that sniffs torrents from BitTorrent network -- [**3494**星][8m] [Go] [fanpei91/torsniff](https://github.com/fanpei91/torsniff) 从BitTorrent网络嗅探种子 -- [**3493**星][3y] [C] [hak5darren/usb-rubber-ducky](https://github.com/hak5darren/usb-rubber-ducky) -- [**3482**星][9m] [C] [rpisec/mbe](https://github.com/rpisec/mbe) Course materials for Modern Binary Exploitation by RPISEC -- [**3481**星][13d] [blacckhathaceekr/pentesting-bible](https://github.com/blacckhathaceekr/pentesting-bible) links reaches 10000 links & 10000 pdf files .Learn Ethical Hacking and penetration testing .hundreds of ethical hacking & penetration testing & red team & cyber security & computer science resources. -- [**3468**星][5m] [PHP] [hanc00l/wooyun_public](https://github.com/hanc00l/wooyun_public) This repo is archived. Thanks for wooyun! 乌云公开漏洞、知识库爬虫和搜索 crawl and search for wooyun.org public bug(vulnerability) and drops -- [**3464**星][15d] [C] [cyan4973/xxhash](https://github.com/cyan4973/xxhash) Extremely fast non-cryptographic hash algorithm -- [**3436**星][7d] [C] [shellphish/how2heap](https://github.com/shellphish/how2heap) 学习各种堆利用技巧的repo -- [**3431**星][13d] [Java] [meituan-dianping/robust](https://github.com/meituan-dianping/robust) Robust is an Android HotFix solution with high compatibility and high stability. Robust can fix bugs immediately without a reboot. -- [**3421**星][13d] [Perl] [sullo/nikto](https://github.com/sullo/nikto) Nikto web server scanner -- [**3412**星][25d] [icodesign/potatso](https://github.com/icodesign/Potatso) Potatso is an iOS client that implements different proxies with the leverage of NetworkExtension framework in iOS 10+. -- [**3392**星][5m] [Go] [jpillora/chisel](https://github.com/jpillora/chisel) 基于HTTP的快速 TCP 隧道 -- [**3387**星][2y] [shadowsocksrr/shadowsocks-rss](https://github.com/shadowsocksrr/shadowsocks-rss) ShadowsocksR update rss, SSR organization -- [**3383**星][22d] [PowerShell] [samratashok/nishang](https://github.com/samratashok/nishang) 渗透框架,脚本和Payload收集,主要是PowerShell,涵盖渗透的各个阶段 -- [**3326**星][13d] [Py] [google/grr](https://github.com/google/grr) remote live forensics for incident response -- [**3325**星][5m] [C++] [wangyu-/udp2raw-tunnel](https://github.com/wangyu-/udp2raw-tunnel) udp 打洞。通过raw socket给UDP包加上TCP或ICMP header,进而绕过UDP屏蔽或QoS,或在UDP不稳定的环境下提升稳定性 -- [**3325**星][7d] [jivoi/awesome-ml-for-cybersecurity](https://github.com/jivoi/awesome-ml-for-cybersecurity) 针对网络安全的机器学习资源列表 -- [**3317**星][7d] [Py] [stamparm/maltrail](https://github.com/stamparm/maltrail) 恶意网络流量检测系统 -- [**3317**星][2y] [scanate/ethlist](https://github.com/scanate/ethlist) The Comprehensive Ethereum Reading List -- [**3316**星][2m] [C] [screetsec/thefatrat](https://github.com/screetsec/thefatrat) Thefatrat a massive exploiting tool : Easy tool to generate backdoor and easy tool to post exploitation attack like browser attack and etc . This tool compiles a malware with popular payload and then the compiled malware can be execute on windows, android, mac . The malware that created with this tool also have an ability to bypass most AV softw… -- [**3282**星][8d] [Smarty] [anankke/sspanel-uim](https://github.com/anankke/sspanel-uim) 专为 Shadowsocks / ShadowsocksR / V2Ray 设计的多用户管理面板 -- [**3280**星][2m] [Swift] [yagiz/bagel](https://github.com/yagiz/bagel) a little native network debugging tool for iOS -- [**3280**星][20d] [C] [vanhauser-thc/thc-hydra](https://github.com/vanhauser-thc/thc-hydra) 网络登录破解,支持多种服务 -- [**3269**星][27d] [C] [microsoft/windows-driver-samples](https://github.com/microsoft/windows-driver-samples) This repo contains driver samples prepared for use with Microsoft Visual Studio and the Windows Driver Kit (WDK). It contains both Universal Windows Driver and desktop-only driver samples. -- [**3267**星][3m] [C] [nbs-system/naxsi](https://github.com/nbs-system/naxsi) NAXSI is an open-source, high performance, low rules maintenance WAF for NGINX -- [**3266**星][12d] [C] [virustotal/yara](https://github.com/virustotal/yara) The pattern matching swiss knife -- [**3258**星][2m] [Py] [volatilityfoundation/volatility](https://github.com/volatilityfoundation/volatility) An advanced memory forensics framework -- [**3258**星][5y] [C++] [google/lmctfy](https://github.com/google/lmctfy) lmctfy is the open source version of Google’s container stack, which provides Linux application containers. -- [**3255**星][7d] [C] [mikebrady/shairport-sync](https://github.com/mikebrady/shairport-sync) AirPlay audio player. Shairport Sync adds multi-room capability with Audio Synchronisation -- [**3253**星][7m] [JS] [sindresorhus/speed-test](https://github.com/sindresorhus/speed-test) Test your internet connection speed and ping using speedtest.net from the CLI -- [**3234**星][8d] [Java] [oldmanpushcart/greys-anatomy](https://github.com/oldmanpushcart/greys-anatomy) Java诊断工具 +- [**3533**星][14d] [C] [tencent/tencentos-tiny](https://github.com/tencent/tencentos-tiny) 腾讯物联网终端操作系统 +- [**3514**星][3y] [C] [hak5darren/usb-rubber-ducky](https://github.com/hak5darren/usb-rubber-ducky) +- [**3510**星][2d] [JS] [aol/moloch](https://github.com/aol/moloch) 数据包捕获、索引工具,支持数据库 +- [**3501**星][8m] [Go] [fanpei91/torsniff](https://github.com/fanpei91/torsniff) torsniff - a sniffer that sniffs torrents from BitTorrent network +- [**3501**星][8m] [Go] [fanpei91/torsniff](https://github.com/fanpei91/torsniff) 从BitTorrent网络嗅探种子 +- [**3493**星][9m] [C] [rpisec/mbe](https://github.com/rpisec/mbe) Course materials for Modern Binary Exploitation by RPISEC +- [**3485**星][5m] [PHP] [hanc00l/wooyun_public](https://github.com/hanc00l/wooyun_public) This repo is archived. Thanks for wooyun! 乌云公开漏洞、知识库爬虫和搜索 crawl and search for wooyun.org public bug(vulnerability) and drops +- [**3481**星][8d] [C] [cyan4973/xxhash](https://github.com/cyan4973/xxhash) Extremely fast non-cryptographic hash algorithm +- [**3471**星][2m] [C++] [trojan-gfw/trojan](https://github.com/trojan-gfw/trojan) An unidentifiable mechanism that helps you bypass GFW. +- [**3442**星][9d] [C] [shellphish/how2heap](https://github.com/shellphish/how2heap) 学习各种堆利用技巧的repo +- [**3442**星][8d] [Java] [meituan-dianping/robust](https://github.com/meituan-dianping/robust) Robust is an Android HotFix solution with high compatibility and high stability. Robust can fix bugs immediately without a reboot. +- [**3441**星][15d] [Perl] [sullo/nikto](https://github.com/sullo/nikto) Nikto web server scanner +- [**3419**星][9d] [C] [mikebrady/shairport-sync](https://github.com/mikebrady/shairport-sync) AirPlay audio player. Shairport Sync adds multi-room capability with Audio Synchronisation +- [**3412**星][27d] [icodesign/potatso](https://github.com/icodesign/Potatso) Potatso is an iOS client that implements different proxies with the leverage of NetworkExtension framework in iOS 10+. +- [**3410**星][5m] [Go] [jpillora/chisel](https://github.com/jpillora/chisel) 基于HTTP的快速 TCP 隧道 +- [**3408**星][24d] [PS] [samratashok/nishang](https://github.com/samratashok/nishang) 渗透框架,脚本和Payload收集,主要是PowerShell,涵盖渗透的各个阶段 +- [**3397**星][2y] [shadowsocksrr/shadowsocks-rss](https://github.com/shadowsocksrr/shadowsocks-rss) ShadowsocksR update rss, SSR organization +- [**3344**星][2d] [jivoi/awesome-ml-for-cybersecurity](https://github.com/jivoi/awesome-ml-for-cybersecurity) 针对网络安全的机器学习资源列表 +- [**3343**星][6d] [C] [screetsec/thefatrat](https://github.com/screetsec/thefatrat) Thefatrat a massive exploiting tool : Easy tool to generate backdoor and easy tool to post exploitation attack like browser attack and etc . This tool compiles a malware with popular payload and then the compiled malware can be execute on windows, android, mac . The malware that created with this tool also have an ability to bypass most AV softw… +- [**3340**星][5m] [C++] [wangyu-/udp2raw-tunnel](https://github.com/wangyu-/udp2raw-tunnel) udp 打洞。通过raw socket给UDP包加上TCP或ICMP header,进而绕过UDP屏蔽或QoS,或在UDP不稳定的环境下提升稳定性 +- [**3334**星][10d] [Smarty] [anankke/sspanel-uim](https://github.com/anankke/sspanel-uim) 专为 Shadowsocks / ShadowsocksR / V2Ray 设计的多用户管理面板 +- [**3331**星][15d] [Py] [google/grr](https://github.com/google/grr) remote live forensics for incident response +- [**3330**星][2d] [Py] [stamparm/maltrail](https://github.com/stamparm/maltrail) 恶意网络流量检测系统 +- [**3319**星][2y] [scanate/ethlist](https://github.com/scanate/ethlist) The Comprehensive Ethereum Reading List +- [**3303**星][22d] [C] [vanhauser-thc/thc-hydra](https://github.com/vanhauser-thc/thc-hydra) 网络登录破解,支持多种服务 +- [**3301**星][2m] [Swift] [yagiz/bagel](https://github.com/yagiz/bagel) a little native network debugging tool for iOS +- [**3298**星][9d] [C++] [fireice-uk/xmr-stak](https://github.com/fireice-uk/xmr-stak) Free Monero RandomX Miner and unified CryptoNight miner +- [**3285**星][7d] [C] [microsoft/windows-driver-samples](https://github.com/microsoft/windows-driver-samples) This repo contains driver samples prepared for use with Microsoft Visual Studio and the Windows Driver Kit (WDK). It contains both Universal Windows Driver and desktop-only driver samples. +- [**3278**星][6d] [C] [virustotal/yara](https://github.com/virustotal/yara) The pattern matching swiss knife +- [**3276**星][3m] [C] [nbs-system/naxsi](https://github.com/nbs-system/naxsi) NAXSI is an open-source, high performance, low rules maintenance WAF for NGINX +- [**3263**星][10d] [Java] [oldmanpushcart/greys-anatomy](https://github.com/oldmanpushcart/greys-anatomy) Java诊断工具 +- [**3262**星][2m] [Py] [volatilityfoundation/volatility](https://github.com/volatilityfoundation/volatility) An advanced memory forensics framework +- [**3260**星][8d] [Shell] [toniblyx/my-arsenal-of-aws-security-tools](https://github.com/toniblyx/my-arsenal-of-aws-security-tools) List of open source tools for AWS security: defensive, offensive, auditing, DFIR, etc. +- [**3260**星][5y] [C++] [google/lmctfy](https://github.com/google/lmctfy) lmctfy is the open source version of Google’s container stack, which provides Linux application containers. +- [**3259**星][7m] [JS] [sindresorhus/speed-test](https://github.com/sindresorhus/speed-test) Test your internet connection speed and ping using speedtest.net from the CLI +- [**3255**星][4d] [ObjC] [objective-see/lulu](https://github.com/objective-see/lulu) LuLu is the free macOS firewall +- [**3247**星][29d] [JS] [koenkk/zigbee2mqtt](https://github.com/koenkk/zigbee2mqtt) Zigbee +- [**3242**星][16d] [Py] [laramies/theharvester](https://github.com/laramies/theharvester) E-mails, subdomains and names Harvester - OSINT +- [**3238**星][2d] [TS] [jigsaw-code/outline-server](https://github.com/jigsaw-code/outline-server) Outline Manager, developed by Jigsaw. The Outline Manager application creates and manages Outline servers, powered by Shadowsocks. It uses the Electron framework to offer support for Windows, macOS and Linux. +- [**3236**星][5m] [Go] [meshbird/meshbird](https://github.com/meshbird/meshbird) cloud-native multi-region multi-cloud decentralized private networking - [**3234**星][2y] [CSS] [jbtronics/crookedstylesheets](https://github.com/jbtronics/crookedstylesheets) 使用纯CSS收集网页/用户信息 -- [**3232**星][5m] [Go] [meshbird/meshbird](https://github.com/meshbird/meshbird) cloud-native multi-region multi-cloud decentralized private networking -- [**3230**星][2m] [Objective-C] [objective-see/lulu](https://github.com/objective-see/lulu) LuLu is the free macOS firewall -- [**3225**星][18d] [Shell] [toniblyx/my-arsenal-of-aws-security-tools](https://github.com/toniblyx/my-arsenal-of-aws-security-tools) List of open source tools for AWS security: defensive, offensive, auditing, DFIR, etc. -- [**3216**星][14d] [Py] [laramies/theharvester](https://github.com/laramies/theharvester) E-mails, subdomains and names Harvester - OSINT -- [**3215**星][27d] [JS] [koenkk/zigbee2mqtt](https://github.com/koenkk/zigbee2mqtt) Zigbee -- [**3214**星][4y] [C] [shadowsocks/chinadns](https://github.com/shadowsocks/chinadns) Protect yourself against DNS poisoning in China. -- [**3214**星][2m] [Go] [dvyukov/go-fuzz](https://github.com/dvyukov/go-fuzz) Randomized testing for Go -- [**3210**星][11d] [C] [tmate-io/tmate](https://github.com/tmate-io/tmate) Instant Terminal Sharing -- [**3210**星][1m] [TypeScript] [google/incremental-dom](https://github.com/google/incremental-dom) An in-place DOM diffing library -- [**3209**星][8d] [C] [betaflight/betaflight](https://github.com/betaflight/betaflight) Open Source Flight Controller Firmware -- [**3205**星][2m] [Shell] [gfw-breaker/ssr-accounts](https://github.com/gfw-breaker/ssr-accounts) 一键部署Shadowsocks服务;免费Shadowsocks账号分享;免费SS账号分享; 翻墙;无界,自由门,SquirrelVPN -- [**3202**星][4m] [Objective-C] [naituw/ipapatch](https://github.com/naituw/ipapatch) Patch iOS Apps, The Easy Way, Without Jailbreak. -- [**3201**星][7m] [HTML] [leizongmin/js-xss](https://github.com/leizongmin/js-xss) Sanitize untrusted HTML (to prevent XSS) with a configuration specified by a Whitelist -- [**3184**星][7d] [Go] [mozilla/sops](https://github.com/mozilla/sops) Simple and flexible tool for managing secrets -- [**3182**星][3m] [C] [yarrick/iodine](https://github.com/yarrick/iodine) 通过DNS服务器传输(tunnel)IPV4数据 -- [**3182**星][1y] [Py] [kootenpv/whereami](https://github.com/kootenpv/whereami) 使用Wifi信号和机器学习预测你的位置,精确度2-10米 -- [**3180**星][13d] [Py] [maurosoria/dirsearch](https://github.com/maurosoria/dirsearch) Web path scanner -- [**3174**星][8d] [Rich Text Format] [the-art-of-hacking/h4cker](https://github.com/The-Art-of-Hacking/h4cker) 资源收集:hacking、渗透、数字取证、事件响应、漏洞研究、漏洞开发、逆向 -- [**3168**星][1m] [C++] [spiderlabs/modsecurity](https://github.com/spiderlabs/modsecurity) ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx that is developed by Trustwave's SpiderLabs. It has a robust event-based programming language which provides protection from a range of attacks against web applications and allows for HTTP traffic monitoring, logging and real-time analys… -- [**3164**星][6m] [hslatman/awesome-threat-intelligence](https://github.com/hslatman/awesome-threat-intelligence) A curated list of Awesome Threat Intelligence resources -- [**3163**星][24d] [C] [magnumripper/johntheripper](https://github.com/magnumripper/johntheripper) This is the official repo for John the Ripper, "Jumbo" version. The "bleeding-jumbo" branch is based on 1.9.0-Jumbo-1 which was released on May 14, 2019. An import of the "core" version of john this jumbo was based on (or newer) is found in the "master" branch (CVS: -- [**3156**星][1m] [C] [valdikss/goodbyedpi](https://github.com/valdikss/goodbyedpi) GoodbyeDPI—Passive Deep Packet Inspection blocker and Active DPI circumvention utility (for Windows) -- [**3145**星][1y] [Shell] [toyodadoubi/doubi](https://github.com/toyodadoubi/doubi) 一个逗比写的各种逗比脚本~ -- [**3128**星][2y] [shadowsocksr-backup/shadowsocksr-android](https://github.com/shadowsocksr-backup/shadowsocksr-android) A ShadowsocksR client for Android -- [**3120**星][10d] [C] [meetecho/janus-gateway](https://github.com/meetecho/janus-gateway) Janus WebRTC Server -- [**3113**星][28d] [CSS] [readthedocs/sphinx_rtd_theme](https://github.com/readthedocs/sphinx_rtd_theme) Sphinx theme for readthedocs.org -- [**3112**星][2m] [C++] [trojan-gfw/trojan](https://github.com/trojan-gfw/trojan) An unidentifiable mechanism that helps you bypass GFW. -- [**3109**星][7d] [Shell] [speed47/spectre-meltdown-checker](https://github.com/speed47/spectre-meltdown-checker) 检查 Linux 主机是否受处理器漏洞Spectre & Meltdown 的影响 -- [**3109**星][2m] [PowerShell] [fireeye/commando-vm](https://github.com/fireeye/commando-vm) Complete Mandiant Offensive VM (Commando VM), a fully customizable Windows-based pentesting virtual machine distribution. commandovm@fireeye.com -- [**3108**星][4m] [C++] [px4/firmware](https://github.com/px4/firmware) PX4 Autopilot Software -- [**3106**星][7d] [C] [qemu/qemu](https://github.com/qemu/qemu) Official QEMU mirror. Please see -- [**3103**星][16d] [Shell] [1n3/sn1per](https://github.com/1n3/sn1per) 自动化渗透测试框架 -- [**3102**星][7d] [JS] [duo-labs/cloudmapper](https://github.com/duo-labs/cloudmapper) 生成AWS环境的网络拓扑图 -- [**3096**星][28d] [meirwah/awesome-incident-response](https://github.com/meirwah/awesome-incident-response) A curated list of tools for incident response -- [**3094**星][2m] [Py] [byt3bl33d3r/crackmapexec](https://github.com/byt3bl33d3r/crackmapexec) 后渗透工具,自动化评估大型Active Directory网络的安全性 -- [**3091**星][1m] [Java] [deathmarine/luyten](https://github.com/deathmarine/luyten) An Open Source Java Decompiler Gui for Procyon -- [**3085**星][10d] [Shell] [trimstray/htrace.sh](https://github.com/trimstray/htrace.sh) My simple Swiss Army knife for http/https troubleshooting and profiling. -- [**3084**星][11d] [Py] [tribler/tribler](https://github.com/tribler/tribler) Privacy enhanced BitTorrent client with P2P content discovery -- [**3084**星][8d] [Shell] [softwaredownload/openwrt-fanqiang](https://github.com/softwaredownload/openwrt-fanqiang) 最好的路由器翻墙、科学上网教程—OpenWrt—shadowsocks -- [**3069**星][9m] [JS] [jipegit/osxauditor](https://github.com/jipegit/osxauditor) OS X Auditor is a free Mac OS X computer forensics tool -- [**3066**星][3m] [C] [zmap/zmap](https://github.com/zmap/zmap) ZMap is a fast single packet network scanner designed for Internet-wide network surveys. -- [**3065**星][9d] [Go] [tencent/bk-cmdb](https://github.com/tencent/bk-cmdb) 蓝鲸智云配置平台(BlueKing CMDB) -- [**3062**星][1y] [Swift] [zhuhaow/spechtlite](https://github.com/zhuhaow/spechtlite) A rule-based proxy for macOS -- [**3061**星][20d] [C] [unicorn-engine/unicorn](https://github.com/unicorn-engine/unicorn) Unicorn CPU emulator framework (ARM, AArch64, M68K, Mips, Sparc, X86) -- [**3059**星][1m] [Java] [calebfenton/simplify](https://github.com/calebfenton/simplify) Generic Android Deobfuscator -- [**3058**星][7m] [Go] [michenriksen/aquatone](https://github.com/michenriksen/aquatone) 子域名枚举工具。除了经典的爆破枚举之外,还利用多种开源工具和在线服务大幅度增加发现子域名的数量。 -- [**3046**星][4m] [C++] [google/robotstxt](https://github.com/google/robotstxt) The repository contains Google's robots.txt parser and matcher as a C++ library (compliant to C++11). -- [**3041**星][2m] [JS] [valve/fingerprintjs](https://github.com/valve/fingerprintjs) Anonymous browser fingerprint -- [**3039**星][3m] [Py] [spiderlabs/responder](https://github.com/spiderlabs/responder) LLMNR/NBT-NS/MDNS投毒,内置HTTP/SMB/MSSQL/FTP/LDAP认证服务器, 支持NTLMv1/NTLMv2/LMv2 -- [**3007**星][9m] [C] [secwiki/linux-kernel-exploits](https://github.com/secwiki/linux-kernel-exploits) linux-kernel-exploits Linux平台提权漏洞集合 -- [**2991**星][1y] [PHP] [owner888/phpspider](https://github.com/owner888/phpspider) 《我用爬虫一天时间“偷了”知乎一百万用户,只为证明PHP是世界上最好的语言 》所使用的程序 -- [**2983**星][2m] [Go] [gwuhaolin/lightsocks](https://github.com/gwuhaolin/lightsocks) 轻量级网络混淆代理,基于 SOCKS5 协议,可用来代替 Shadowsocks -- [**2982**星][7d] [Lua] [ntop/ntopng](https://github.com/ntop/ntopng) 基于Web的流量监控工具 -- [**2978**星][7d] [Py] [guardicore/monkey](https://github.com/guardicore/monkey) 自动化渗透测试工具, 测试数据中心的弹性, 以防范周边(perimeter)泄漏和内部服务器感染 -- [**2962**星][14d] [Objective-C] [google/santa](https://github.com/google/santa) 用于Mac系统的二进制文件白名单/黑名单系统 -- [**2947**星][27d] [Go] [cookiey/yearning](https://github.com/cookiey/yearning) A most popular sql audit platform for mysql -- [**2937**星][13d] [JS] [webgoat/webgoat](https://github.com/webgoat/webgoat) 带漏洞WebApp -- [**2937**星][2y] [phith0n/mind-map](https://github.com/phith0n/mind-map) 各种安全相关思维导图整理收集 -- [**2936**星][1m] [Py] [andresriancho/w3af](https://github.com/andresriancho/w3af) Web App安全扫描器, 辅助开发者和渗透测试人员识别和利用Web App中的漏洞 -- [**2935**星][19d] [Py] [cowrie/cowrie](https://github.com/cowrie/cowrie) 中型/交互型 SSH/Telnet 蜜罐, -- [**2930**星][1y] [Py] [danmcinerney/wifijammer](https://github.com/danmcinerney/wifijammer) 持续劫持范围内的Wifi客户端和AP -- [**2930**星][11m] [Shell] [91yun/serverspeeder](https://github.com/91yun/serverspeeder) 锐速破解版 -- [**2927**星][7d] [Zeek] [zeek/zeek](https://github.com/zeek/zeek) Zeek is a powerful network analysis framework that is much different from the typical IDS you may know. -- [**2916**星][15d] [Py] [twintproject/twint](https://github.com/twintproject/twint) An advanced Twitter scraping & OSINT tool written in Python that doesn't use Twitter's API, allowing you to scrape a user's followers, following, Tweets and more while evading most API limitations. -- [**2912**星][2m] [Dockerfile] [thinkdevelop/free-ss-ssr](https://github.com/thinkdevelop/free-ss-ssr) SS账号、SSR账号、V2Ray账号 -- [**2907**星][21d] [Go] [securego/gosec](https://github.com/securego/gosec) Golang security checker -- [**2897**星][1y] [Py] [byt3bl33d3r/mitmf](https://github.com/byt3bl33d3r/mitmf) Framework for Man-In-The-Middle attacks -- [**2895**星][10d] [C] [libfuse/sshfs](https://github.com/libfuse/sshfs) A network filesystem client to connect to SSH servers -- [**2892**星][11d] [secfigo/awesome-fuzzing](https://github.com/secfigo/awesome-fuzzing) A curated list of fuzzing resources ( Books, courses - free and paid, videos, tools, tutorials and vulnerable applications to practice on ) for learning Fuzzing and initial phases of Exploit Development like root cause analysis. -- [**2891**星][20d] [Py] [trustedsec/ptf](https://github.com/trustedsec/ptf) 创建基于Debian/Ubuntu/ArchLinux的渗透测试环境 -- [**2876**星][7m] [C] [p-h-c/phc-winner-argon2](https://github.com/p-h-c/phc-winner-argon2) The password hash Argon2, winner of PHC -- [**2874**星][4y] [Objective-C] [maciekish/iresign](https://github.com/maciekish/iresign) iReSign allows iDevice app bundles (.ipa) files to be signed or resigned with a digital certificate from Apple for distribution. This tool is aimed at enterprises users, for enterprise deployment, when the person signing the app is different than the person(s) developing it. -- [**2851**星][10d] [JS] [evilsocket/pwnagotchi](https://github.com/evilsocket/pwnagotchi) 深度学习+Bettercap,基于A2C,从周围的WiFi环境中学习,以最大程度地利用捕获的WPA关键信息 -- [**2850**星][8d] [C] [lxc/lxc](https://github.com/lxc/lxc) LXC - Linux Containers -- [**2840**星][5m] [Py] [instantbox/instantbox](https://github.com/instantbox/instantbox) Get a clean, ready-to-go Linux box in seconds. -- [**2838**星][11d] [Objective-C] [facebook/idb](https://github.com/facebook/idb) idb is a flexible command line interface for automating iOS simulators and devices -- [**2834**星][8m] [C++] [wangyu-/udpspeeder](https://github.com/wangyu-/udpspeeder) A Tunnel which Improves your Network Quality on a High-latency Lossy Link by using Forward Error Correction,for All Traffics(TCP/UDP/ICMP) -- [**2830**星][9d] [HTML] [ctf-wiki/ctf-wiki](https://github.com/ctf-wiki/ctf-wiki) CTF Wiki Online. Come and join us, we need you! -- [**2829**星][21d] [C] [ossec/ossec-hids](https://github.com/ossec/ossec-hids) 入侵检测系统 -- [**2825**星][15d] [Py] [espressif/esptool](https://github.com/espressif/esptool) ESP8266 and ESP32 serial bootloader utility -- [**2825**星][8m] [Shell] [goreliu/wsl-terminal](https://github.com/goreliu/wsl-terminal) Terminal emulator for Windows Subsystem for Linux (WSL) -- [**2823**星][12d] [Go] [99designs/aws-vault](https://github.com/99designs/aws-vault) A vault for securely storing and accessing AWS credentials in development environments -- [**2820**星][1m] [Assembly] [cirosantilli/x86-bare-metal-examples](https://github.com/cirosantilli/x86-bare-metal-examples) 几十个用于学习 x86 系统编程的小型操作系统 -- [**2819**星][2y] [CSS] [maxchehab/css-keylogging](https://github.com/maxchehab/css-keylogging) Chrome extension and Express server that exploits keylogging abilities of CSS. -- [**2815**星][4m] [C] [juliocesarfort/public-pentesting-reports](https://github.com/juliocesarfort/public-pentesting-reports) Curated list of public penetration test reports released by several consulting firms and academic security groups -- [**2810**星][28d] [C] [tmk/tmk_keyboard](https://github.com/tmk/tmk_keyboard) Atmel AVR 和 Cortex-M键盘固件收集 -- [**2810**星][2m] [infosecn1nja/red-teaming-toolkit](https://github.com/infosecn1nja/red-teaming-toolkit) A collection of open source and commercial tools that aid in red team operations. -- [**2805**星][1m] [paulsec/awesome-sec-talks](https://github.com/paulsec/awesome-sec-talks) A collected list of awesome security talks -- [**2804**星][8m] [C#] [quasar/quasarrat](https://github.com/quasar/quasarrat) Remote Administration Tool for Windows -- [**2802**星][9m] [Py] [plasma-disassembler/plasma](https://github.com/plasma-disassembler/plasma) Plasma is an interactive disassembler for x86/ARM/MIPS. It can generates indented pseudo-code with colored syntax. -- [**2787**星][17d] [Py] [androguard/androguard](https://github.com/androguard/androguard) Reverse engineering, Malware and goodware analysis of Android applications ... and more (ninja !) -- [**2783**星][2y] [C] [seclab-ucr/intang](https://github.com/seclab-ucr/intang) research project for circumventing the "TCP reset attack" from the Great Firewall of China (GFW) by disrupting/desynchronizing the TCP Control Block (TCB) on the censorship devices. -- [**2779**星][28d] [Makefile] [shadowsocks/openwrt-shadowsocks](https://github.com/shadowsocks/openwrt-shadowsocks) Shadowsocks-libev for OpenWrt/LEDE -- [**2776**星][4y] [Lua] [loveshell/ngx_lua_waf](https://github.com/loveshell/ngx_lua_waf) ngx_lua_waf是一个基于lua-nginx-module(openresty)的web应用防火墙 -- [**2767**星][2m] [Go] [kgretzky/evilginx2](https://github.com/kgretzky/evilginx2) 独立的MITM攻击工具,用于登录凭证钓鱼,可绕过双因素认证 -- [**2763**星][1m] [JS] [trufflesuite/ganache-cli](https://github.com/trufflesuite/ganache-cli) Fast Ethereum RPC client for testing and development -- [**2761**星][10d] [Py] [jrohy/multi-v2ray](https://github.com/jrohy/multi-v2ray) v2ray easy delpoy & manage tool, support multiple user & protocol manage -- [**2755**星][7d] [C++] [qtox/qtox](https://github.com/qtox/qtox) qTox is a chat, voice, video, and file transfer IM client using the encrypted peer-to-peer Tox protocol. -- [**2746**星][8d] [C] [processhacker/processhacker](https://github.com/processhacker/processhacker) A free, powerful, multi-purpose tool that helps you monitor system resources, debug software and detect malware. -- [**2736**星][8m] [Py] [p0cl4bs/wifi-pumpkin](https://github.com/P0cL4bs/WiFi-Pumpkin) AP攻击框架, 创建虚假网络, 取消验证攻击、请求和凭证监控、透明代理、Windows更新攻击、钓鱼管理、ARP投毒、DNS嗅探、Pumpkin代理、动态图片捕获等 -- [**2736**星][1y] [C] [vanhoefm/krackattacks-scripts](https://github.com/vanhoefm/krackattacks-scripts) 检测客户端和AP是否受KRACK漏洞影响 -- [**2735**星][7d] [TypeScript] [webhintio/hint](https://github.com/webhintio/hint) -- [**2731**星][22d] [Makefile] [theos/theos](https://github.com/theos/theos) A cross-platform suite of tools for building and deploying software for iOS and other platforms. -- [**2727**星][2m] [secwiki/sec-chart](https://github.com/secwiki/sec-chart) 安全思维导图集合 -- [**2727**星][3y] [Py] [hephaest0s/usbkill](https://github.com/hephaest0s/usbkill) 反取证开关. 监控USB端口变化, 有变化时立即关闭计算机 -- [**2726**星][16d] [JS] [cyu/rack-cors](https://github.com/cyu/rack-cors) Rack Middleware for handling Cross-Origin Resource Sharing (CORS), which makes cross-origin AJAX possible. -- [**2715**星][21d] [JS] [s0md3v/awesomexss](https://github.com/s0md3v/AwesomeXSS) Awesome XSS stuff -- [**2701**星][3y] [Eagle] [samyk/magspoof](https://github.com/samyk/magspoof) 信用卡/磁条欺骗 -- [**2700**星][1m] [C] [taviso/loadlibrary](https://github.com/taviso/loadlibrary) 使 Linux系统加载并调用 Windows DLL -- [**2683**星][4m] [Objective-C] [dantheman827/ios-app-signer](https://github.com/dantheman827/ios-app-signer) This is an app for OS X that can (re)sign apps and bundle them into ipa files that are ready to be installed on an iOS device. -- [**2681**星][1m] [Objective-C] [kjcracks/clutch](https://github.com/kjcracks/clutch) Fast iOS executable dumper -- [**2665**星][7d] [Go] [google/syzkaller](https://github.com/google/syzkaller) 一个unsupervised、以 coverage 为导向的Linux 系统调用fuzzer -- [**2660**星][7d] [PowerShell] [redcanaryco/atomic-red-team](https://github.com/redcanaryco/atomic-red-team) Small and highly portable detection tests based on MITRE's ATT&CK. -- [**2660**星][1y] [Py] [mame82/p4wnp1](https://github.com/mame82/p4wnp1) 基于Raspberry Pi Zero 或 Raspberry Pi Zero W 的USB攻击平台, 高度的可定制性 -- [**2658**星][12d] [Go] [aquasecurity/trivy](https://github.com/aquasecurity/trivy) A Simple and Comprehensive Vulnerability Scanner for Containers, Suitable for CI -- [**2648**星][3m] [Py] [drivendata/cookiecutter-data-science](https://github.com/drivendata/cookiecutter-data-science) A logical, reasonably standardized, but flexible project structure for doing and sharing data science work. -- [**2643**星][2m] [rmusser01/infosec_reference](https://github.com/rmusser01/infosec_reference) An Information Security Reference That Doesn't Suck -- [**2638**星][3m] [Java] [frohoff/ysoserial](https://github.com/frohoff/ysoserial) 生成会利用不安全的Java对象反序列化的Payload -- [**2634**星][2m] [xairy/linux-kernel-exploitation](https://github.com/xairy/linux-kernel-exploitation) Linux 内核 Fuzz 和漏洞利用的资源收集 -- [**2633**星][3m] [Java] [teevity/ice](https://github.com/teevity/ice) AWS Usage Tool -- [**2633**星][1y] [HTML] [chybeta/web-security-learning](https://github.com/chybeta/web-security-learning) Web-Security-Learning -- [**2622**星][15d] [JS] [bkimminich/juice-shop](https://github.com/bkimminich/juice-shop) OWASP Juice Shop: Probably the most modern and sophisticated insecure web application -- [**2619**星][8m] [leandromoreira/linux-network-performance-parameters](https://github.com/leandromoreira/linux-network-performance-parameters) Learn where some of the network sysctl variables fit into the Linux/Kernel network flow -- [**2610**星][2m] [Swift] [zhuhaow/nekit](https://github.com/zhuhaow/nekit) A toolkit for Network Extension Framework -- [**2601**星][3y] [Ruby] [arachni/arachni](https://github.com/arachni/arachni) Web Application Security Scanner Framework -- [**2600**星][21d] [JS] [knownsec/kcon](https://github.com/knownsec/kcon) KCon is a famous Hacker Con powered by Knownsec Team. -- [**2598**星][8d] [JS] [popcorn-official/popcorn-desktop](https://github.com/popcorn-official/popcorn-desktop) Popcorn Time is a multi-platform, free software BitTorrent client that includes an integrated media player. Desktop ( Windows / Mac / Linux ) a Butter-Project Fork -- [**2589**星][19d] [C++] [fanout/pushpin](https://github.com/fanout/pushpin) Reverse proxy for realtime web services -- [**2588**星][1m] [pditommaso/awesome-pipeline](https://github.com/pditommaso/awesome-pipeline) A curated list of awesome pipeline toolkits inspired by Awesome Sysadmin -- [**2570**星][2m] [C] [huntergregal/mimipenguin](https://github.com/huntergregal/mimipenguin) dump 当前Linux用户的登录密码 -- [**2565**星][1m] [Shell] [medicean/vulapps](https://github.com/medicean/vulapps) 快速搭建各种漏洞环境(Various vulnerability environment) -- [**2564**星][8y] [C] [id-software/quake](https://github.com/id-software/quake) Quake GPL Source Release -- [**2563**星][5m] [Java] [google/binnavi](https://github.com/google/binnavi) 二进制分析IDE, 对反汇编代码的控制流程图和调用图进行探查/导航/编辑/注释.(IDA插件的作用是导出反汇编) -- [**2555**星][1m] [C] [esnet/iperf](https://github.com/esnet/iperf) A TCP, UDP, and SCTP network bandwidth measurement tool -- [**2554**星][2y] [evilsocket/bettercap](https://github.com/evilsocket/bettercap) 中间人攻击框架,功能完整,模块化设计,轻便且易于扩展。 -- [**2547**星][3m] [Py] [greenwolf/social_mapper](https://github.com/Greenwolf/social_mapper) 对多个社交网站的用户Profile图片进行大规模的人脸识别 -- [**2537**星][6m] [C] [geohot/qira](https://github.com/geohot/qira) QEMU Interactive Runtime Analyser +- [**3233**星][9d] [Go] [mozilla/sops](https://github.com/mozilla/sops) Simple and flexible tool for managing secrets +- [**3228**星][2d] [C] [betaflight/betaflight](https://github.com/betaflight/betaflight) Open Source Flight Controller Firmware +- [**3223**星][2m] [Shell] [gfw-breaker/ssr-accounts](https://github.com/gfw-breaker/ssr-accounts) 一键部署Shadowsocks服务;免费Shadowsocks账号分享;免费SS账号分享; 翻墙;无界,自由门,SquirrelVPN +- [**3222**星][6d] [C] [tmate-io/tmate](https://github.com/tmate-io/tmate) Instant Terminal Sharing +- [**3222**星][6d] [Go] [dvyukov/go-fuzz](https://github.com/dvyukov/go-fuzz) Randomized testing for Go +- [**3221**星][4y] [C] [shadowsocks/chinadns](https://github.com/shadowsocks/chinadns) Protect yourself against DNS poisoning in China. +- [**3213**星][1m] [TS] [google/incremental-dom](https://github.com/google/incremental-dom) An in-place DOM diffing library +- [**3210**星][7m] [HTML] [leizongmin/js-xss](https://github.com/leizongmin/js-xss) Sanitize untrusted HTML (to prevent XSS) with a configuration specified by a Whitelist +- [**3209**星][5m] [ObjC] [naituw/ipapatch](https://github.com/naituw/ipapatch) Patch iOS Apps, The Easy Way, Without Jailbreak. +- [**3208**星][4m] [C] [yarrick/iodine](https://github.com/yarrick/iodine) 通过DNS服务器传输(tunnel)IPV4数据 +- [**3205**星][15d] [Py] [maurosoria/dirsearch](https://github.com/maurosoria/dirsearch) Web path scanner +- [**3202**星][10d] [Rich Text Format] [the-art-of-hacking/h4cker](https://github.com/The-Art-of-Hacking/h4cker) 资源收集:hacking、渗透、数字取证、事件响应、漏洞研究、漏洞开发、逆向 +- [**3187**星][1y] [Py] [kootenpv/whereami](https://github.com/kootenpv/whereami) 使用Wifi信号和机器学习预测你的位置,精确度2-10米 +- [**3187**星][6m] [hslatman/awesome-threat-intelligence](https://github.com/hslatman/awesome-threat-intelligence) A curated list of Awesome Threat Intelligence resources +- [**3186**星][1m] [C++] [spiderlabs/modsecurity](https://github.com/spiderlabs/modsecurity) ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx that is developed by Trustwave's SpiderLabs. It has a robust event-based programming language which provides protection from a range of attacks against web applications and allows for HTTP traffic monitoring, logging and real-time analys… +- [**3180**星][27d] [C] [magnumripper/johntheripper](https://github.com/magnumripper/johntheripper) This is the official repo for John the Ripper, "Jumbo" version. The "bleeding-jumbo" branch is based on 1.9.0-Jumbo-1 which was released on May 14, 2019. An import of the "core" version of john this jumbo was based on (or newer) is found in the "master" branch (CVS: +- [**3169**星][1m] [C] [valdikss/goodbyedpi](https://github.com/valdikss/goodbyedpi) GoodbyeDPI—Passive Deep Packet Inspection blocker and Active DPI circumvention utility (for Windows) +- [**3162**星][1y] [Shell] [toyodadoubi/doubi](https://github.com/toyodadoubi/doubi) 一个逗比写的各种逗比脚本~ +- [**3159**星][3d] [JS] [minbrowser/min](https://github.com/minbrowser/min) A fast, minimal browser that protects your privacy +- [**3140**星][6d] [C] [meetecho/janus-gateway](https://github.com/meetecho/janus-gateway) Janus WebRTC Server +- [**3137**星][2y] [shadowsocksr-backup/shadowsocksr-android](https://github.com/shadowsocksr-backup/shadowsocksr-android) A ShadowsocksR client for Android +- [**3134**星][2d] [C++] [px4/firmware](https://github.com/px4/firmware) PX4 Autopilot Software +- [**3125**星][3d] [Shell] [1n3/sn1per](https://github.com/1n3/sn1per) 自动化渗透测试框架 +- [**3123**星][30d] [meirwah/awesome-incident-response](https://github.com/meirwah/awesome-incident-response) A curated list of tools for incident response +- [**3123**星][2m] [PS] [fireeye/commando-vm](https://github.com/fireeye/commando-vm) Complete Mandiant Offensive VM (Commando VM), a fully customizable Windows-based pentesting virtual machine distribution. commandovm@fireeye.com +- [**3122**星][5d] [Go] [uber/kraken](https://github.com/uber/kraken) P2P Docker registry capable of distributing TBs of data in seconds +- [**3121**星][30d] [CSS] [readthedocs/sphinx_rtd_theme](https://github.com/readthedocs/sphinx_rtd_theme) Sphinx theme for readthedocs.org +- [**3121**星][8d] [JS] [duo-labs/cloudmapper](https://github.com/duo-labs/cloudmapper) 生成AWS环境的网络拓扑图 +- [**3118**星][3d] [Shell] [speed47/spectre-meltdown-checker](https://github.com/speed47/spectre-meltdown-checker) 检查 Linux 主机是否受处理器漏洞Spectre & Meltdown 的影响 +- [**3113**星][2d] [C] [qemu/qemu](https://github.com/qemu/qemu) Official QEMU mirror. Please see +- [**3107**星][2m] [Py] [byt3bl33d3r/crackmapexec](https://github.com/byt3bl33d3r/crackmapexec) 后渗透工具,自动化评估大型Active Directory网络的安全性 +- [**3106**星][7d] [Java] [deathmarine/luyten](https://github.com/deathmarine/luyten) An Open Source Java Decompiler Gui for Procyon +- [**3105**星][10d] [Shell] [softwaredownload/openwrt-fanqiang](https://github.com/softwaredownload/openwrt-fanqiang) 最好的路由器翻墙、科学上网教程—OpenWrt—shadowsocks +- [**3088**星][9d] [Shell] [trimstray/htrace.sh](https://github.com/trimstray/htrace.sh) My simple Swiss Army knife for http/https troubleshooting and profiling. +- [**3087**星][3d] [Py] [tribler/tribler](https://github.com/tribler/tribler) Privacy enhanced BitTorrent client with P2P content discovery +- [**3085**星][11d] [Go] [tencent/bk-cmdb](https://github.com/tencent/bk-cmdb) 蓝鲸智云配置平台(BlueKing CMDB) +- [**3084**星][22d] [C] [unicorn-engine/unicorn](https://github.com/unicorn-engine/unicorn) Unicorn CPU emulator framework (ARM, AArch64, M68K, Mips, Sparc, X86) +- [**3080**星][3m] [C] [zmap/zmap](https://github.com/zmap/zmap) ZMap is a fast single packet network scanner designed for Internet-wide network surveys. +- [**3076**星][7m] [Go] [michenriksen/aquatone](https://github.com/michenriksen/aquatone) 子域名枚举工具。除了经典的爆破枚举之外,还利用多种开源工具和在线服务大幅度增加发现子域名的数量。 +- [**3071**星][9m] [JS] [jipegit/osxauditor](https://github.com/jipegit/osxauditor) OS X Auditor is a free Mac OS X computer forensics tool +- [**3065**星][1m] [Java] [calebfenton/simplify](https://github.com/calebfenton/simplify) Generic Android Deobfuscator +- [**3063**星][1y] [Swift] [zhuhaow/spechtlite](https://github.com/zhuhaow/spechtlite) A rule-based proxy for macOS +- [**3052**星][2m] [JS] [valve/fingerprintjs](https://github.com/valve/fingerprintjs) Anonymous browser fingerprint +- [**3049**星][4m] [C++] [google/robotstxt](https://github.com/google/robotstxt) The repository contains Google's robots.txt parser and matcher as a C++ library (compliant to C++11). +- [**3043**星][3m] [Py] [spiderlabs/responder](https://github.com/spiderlabs/responder) LLMNR/NBT-NS/MDNS投毒,内置HTTP/SMB/MSSQL/FTP/LDAP认证服务器, 支持NTLMv1/NTLMv2/LMv2 +- [**3029**星][2m] [Go] [gwuhaolin/lightsocks](https://github.com/gwuhaolin/lightsocks) 轻量级网络混淆代理,基于 SOCKS5 协议,可用来代替 Shadowsocks +- [**3027**星][9m] [C] [secwiki/linux-kernel-exploits](https://github.com/secwiki/linux-kernel-exploits) linux-kernel-exploits Linux平台提权漏洞集合 +- [**3001**星][1y] [PHP] [owner888/phpspider](https://github.com/owner888/phpspider) 《我用爬虫一天时间“偷了”知乎一百万用户,只为证明PHP是世界上最好的语言 》所使用的程序 +- [**2991**星][2d] [JS] [ntop/ntopng](https://github.com/ntop/ntopng) 基于Web的流量监控工具 +- [**2986**星][7d] [Py] [guardicore/monkey](https://github.com/guardicore/monkey) 自动化渗透测试工具, 测试数据中心的弹性, 以防范周边(perimeter)泄漏和内部服务器感染 +- [**2969**星][29d] [Go] [cookiey/yearning](https://github.com/cookiey/yearning) A most popular sql audit platform for mysql +- [**2968**星][2d] [ObjC] [google/santa](https://github.com/google/santa) 用于Mac系统的二进制文件白名单/黑名单系统 +- [**2955**星][4d] [Py] [twintproject/twint](https://github.com/twintproject/twint) An advanced Twitter scraping & OSINT tool written in Python that doesn't use Twitter's API, allowing you to scrape a user's followers, following, Tweets and more while evading most API limitations. +- [**2955**星][11d] [Go] [dominikh/go-tools](https://github.com/dominikh/go-tools) Staticcheck – a collection of static analysis tools for working with Go code +- [**2949**星][8d] [JS] [webgoat/webgoat](https://github.com/webgoat/webgoat) 带漏洞WebApp +- [**2948**星][2m] [Dockerfile] [thinkdevelop/free-ss-ssr](https://github.com/thinkdevelop/free-ss-ssr) SS账号、SSR账号、V2Ray账号 +- [**2947**星][1m] [Py] [andresriancho/w3af](https://github.com/andresriancho/w3af) Web App安全扫描器, 辅助开发者和渗透测试人员识别和利用Web App中的漏洞 +- [**2945**星][2y] [phith0n/mind-map](https://github.com/phith0n/mind-map) 各种安全相关思维导图整理收集 +- [**2942**星][21d] [Py] [cowrie/cowrie](https://github.com/cowrie/cowrie) 中型/交互型 SSH/Telnet 蜜罐, +- [**2936**星][1y] [Py] [danmcinerney/wifijammer](https://github.com/danmcinerney/wifijammer) 持续劫持范围内的Wifi客户端和AP +- [**2933**星][2d] [Zeek] [zeek/zeek](https://github.com/zeek/zeek) Zeek is a powerful network analysis framework that is much different from the typical IDS you may know. +- [**2932**星][11m] [Shell] [91yun/serverspeeder](https://github.com/91yun/serverspeeder) 锐速破解版 +- [**2920**星][23d] [Go] [securego/gosec](https://github.com/securego/gosec) Golang security checker +- [**2916**星][2d] [JS] [evilsocket/pwnagotchi](https://github.com/evilsocket/pwnagotchi) 深度学习+Bettercap,基于A2C,从周围的WiFi环境中学习,以最大程度地利用捕获的WPA关键信息 +- [**2915**星][12d] [C] [libfuse/sshfs](https://github.com/libfuse/sshfs) A network filesystem client to connect to SSH servers +- [**2909**星][2d] [Py] [trustedsec/ptf](https://github.com/trustedsec/ptf) 创建基于Debian/Ubuntu/ArchLinux的渗透测试环境 +- [**2901**星][1y] [Py] [byt3bl33d3r/mitmf](https://github.com/byt3bl33d3r/mitmf) Framework for Man-In-The-Middle attacks +- [**2897**星][3d] [secfigo/awesome-fuzzing](https://github.com/secfigo/awesome-fuzzing) A curated list of fuzzing resources ( Books, courses - free and paid, videos, tools, tutorials and vulnerable applications to practice on ) for learning Fuzzing and initial phases of Exploit Development like root cause analysis. +- [**2883**星][7m] [C] [p-h-c/phc-winner-argon2](https://github.com/p-h-c/phc-winner-argon2) The password hash Argon2, winner of PHC +- [**2877**星][4y] [ObjC] [maciekish/iresign](https://github.com/maciekish/iresign) iReSign allows iDevice app bundles (.ipa) files to be signed or resigned with a digital certificate from Apple for distribution. This tool is aimed at enterprises users, for enterprise deployment, when the person signing the app is different than the person(s) developing it. +- [**2858**星][2d] [C] [lxc/lxc](https://github.com/lxc/lxc) LXC - Linux Containers +- [**2850**星][2d] [HTML] [ctf-wiki/ctf-wiki](https://github.com/ctf-wiki/ctf-wiki) CTF Wiki Online. Come and join us, we need you! +- [**2850**星][4d] [Go] [99designs/aws-vault](https://github.com/99designs/aws-vault) A vault for securely storing and accessing AWS credentials in development environments +- [**2845**星][2d] [ObjC] [facebook/idb](https://github.com/facebook/idb) idb is a flexible command line interface for automating iOS simulators and devices +- [**2842**星][5m] [Py] [instantbox/instantbox](https://github.com/instantbox/instantbox) Get a clean, ready-to-go Linux box in seconds. +- [**2840**星][23d] [C] [ossec/ossec-hids](https://github.com/ossec/ossec-hids) 入侵检测系统 +- [**2840**星][2m] [infosecn1nja/red-teaming-toolkit](https://github.com/infosecn1nja/red-teaming-toolkit) A collection of open source and commercial tools that aid in red team operations. +- [**2839**星][8m] [C++] [wangyu-/udpspeeder](https://github.com/wangyu-/udpspeeder) A Tunnel which Improves your Network Quality on a High-latency Lossy Link by using Forward Error Correction,for All Traffics(TCP/UDP/ICMP) +- [**2837**星][17d] [Py] [espressif/esptool](https://github.com/espressif/esptool) ESP8266 and ESP32 serial bootloader utility +- [**2834**星][8m] [Shell] [goreliu/wsl-terminal](https://github.com/goreliu/wsl-terminal) Terminal emulator for Windows Subsystem for Linux (WSL) +- [**2829**星][4m] [C] [juliocesarfort/public-pentesting-reports](https://github.com/juliocesarfort/public-pentesting-reports) Curated list of public penetration test reports released by several consulting firms and academic security groups +- [**2829**星][1m] [Assembly] [cirosantilli/x86-bare-metal-examples](https://github.com/cirosantilli/x86-bare-metal-examples) 几十个用于学习 x86 系统编程的小型操作系统 +- [**2823**星][2y] [CSS] [maxchehab/css-keylogging](https://github.com/maxchehab/css-keylogging) Chrome extension and Express server that exploits keylogging abilities of CSS. +- [**2820**星][7d] [C] [tmk/tmk_keyboard](https://github.com/tmk/tmk_keyboard) Atmel AVR 和 Cortex-M键盘固件收集 +- [**2814**星][8m] [C#] [quasar/quasarrat](https://github.com/quasar/quasarrat) Remote Administration Tool for Windows +- [**2814**星][5d] [Py] [jrohy/multi-v2ray](https://github.com/jrohy/multi-v2ray) v2ray easy delpoy & manage tool, support multiple user & protocol manage +- [**2808**星][2m] [paulsec/awesome-sec-talks](https://github.com/paulsec/awesome-sec-talks) A collected list of awesome security talks +- [**2803**星][9m] [Py] [plasma-disassembler/plasma](https://github.com/plasma-disassembler/plasma) Plasma is an interactive disassembler for x86/ARM/MIPS. It can generates indented pseudo-code with colored syntax. +- [**2798**星][19d] [Py] [androguard/androguard](https://github.com/androguard/androguard) Reverse engineering, Malware and goodware analysis of Android applications ... and more (ninja !) +- [**2793**星][6d] [C] [klange/toaruos](https://github.com/klange/toaruos) A completely-from-scratch hobby operating system: bootloader, kernel, drivers, C library, and userspace including a composited graphical UI, dynamic linker, syntax-highlighting text editor, network stack, etc. +- [**2793**星][2m] [Go] [kgretzky/evilginx2](https://github.com/kgretzky/evilginx2) 独立的MITM攻击工具,用于登录凭证钓鱼,可绕过双因素认证 +- [**2791**星][7d] [C++] [xmrig/xmrig](https://github.com/xmrig/xmrig) xmrig: 门罗币挖矿代码 CPU 版 +- [**2789**星][4y] [Lua] [loveshell/ngx_lua_waf](https://github.com/loveshell/ngx_lua_waf) ngx_lua_waf是一个基于lua-nginx-module(openresty)的web应用防火墙 +- [**2783**星][30d] [Makefile] [shadowsocks/openwrt-shadowsocks](https://github.com/shadowsocks/openwrt-shadowsocks) Shadowsocks-libev for OpenWrt/LEDE +- [**2782**星][2y] [C] [seclab-ucr/intang](https://github.com/seclab-ucr/intang) research project for circumventing the "TCP reset attack" from the Great Firewall of China (GFW) by disrupting/desynchronizing the TCP Control Block (TCB) on the censorship devices. +- [**2777**星][9d] [C++] [qtox/qtox](https://github.com/qtox/qtox) qTox is a chat, voice, video, and file transfer IM client using the encrypted peer-to-peer Tox protocol. +- [**2769**星][4d] [C] [processhacker/processhacker](https://github.com/processhacker/processhacker) A free, powerful, multi-purpose tool that helps you monitor system resources, debug software and detect malware. +- [**2766**星][1m] [JS] [trufflesuite/ganache-cli](https://github.com/trufflesuite/ganache-cli) Fast Ethereum RPC client for testing and development +- [**2756**星][2m] [secwiki/sec-chart](https://github.com/secwiki/sec-chart) 安全思维导图集合 +- [**2742**星][5d] [TS] [webhintio/hint](https://github.com/webhintio/hint) +- [**2742**星][24d] [Makefile] [theos/theos](https://github.com/theos/theos) A cross-platform suite of tools for building and deploying software for iOS and other platforms. +- [**2741**星][8m] [Py] [p0cl4bs/wifi-pumpkin](https://github.com/P0cL4bs/WiFi-Pumpkin) AP攻击框架, 创建虚假网络, 取消验证攻击、请求和凭证监控、透明代理、Windows更新攻击、钓鱼管理、ARP投毒、DNS嗅探、Pumpkin代理、动态图片捕获等 +- [**2739**星][23d] [JS] [s0md3v/awesomexss](https://github.com/s0md3v/AwesomeXSS) Awesome XSS stuff +- [**2737**星][1y] [C] [vanhoefm/krackattacks-scripts](https://github.com/vanhoefm/krackattacks-scripts) 检测客户端和AP是否受KRACK漏洞影响 +- [**2735**星][18d] [JS] [cyu/rack-cors](https://github.com/cyu/rack-cors) Rack Middleware for handling Cross-Origin Resource Sharing (CORS), which makes cross-origin AJAX possible. +- [**2730**星][3y] [Py] [hephaest0s/usbkill](https://github.com/hephaest0s/usbkill) 反取证开关. 监控USB端口变化, 有变化时立即关闭计算机 +- [**2717**星][2d] [PS] [redcanaryco/atomic-red-team](https://github.com/redcanaryco/atomic-red-team) Small and highly portable detection tests based on MITRE's ATT&CK. +- [**2713**星][1m] [C] [taviso/loadlibrary](https://github.com/taviso/loadlibrary) 使 Linux系统加载并调用 Windows DLL +- [**2703**星][3y] [Eagle] [samyk/magspoof](https://github.com/samyk/magspoof) 信用卡/磁条欺骗 +- [**2701**星][3d] [Go] [aquasecurity/trivy](https://github.com/aquasecurity/trivy) A Simple and Comprehensive Vulnerability Scanner for Containers, Suitable for CI +- [**2698**星][7d] [ObjC] [dantheman827/ios-app-signer](https://github.com/dantheman827/ios-app-signer) This is an app for OS X that can (re)sign apps and bundle them into ipa files that are ready to be installed on an iOS device. +- [**2690**星][1m] [ObjC] [kjcracks/clutch](https://github.com/kjcracks/clutch) Fast iOS executable dumper +- [**2682**星][22d] [Go] [google/syzkaller](https://github.com/google/syzkaller) 一个unsupervised、以 coverage 为导向的Linux 系统调用fuzzer +- [**2681**星][1y] [Py] [mame82/p4wnp1](https://github.com/mame82/p4wnp1) 基于Raspberry Pi Zero 或 Raspberry Pi Zero W 的USB攻击平台, 高度的可定制性 +- [**2674**星][3m] [Py] [drivendata/cookiecutter-data-science](https://github.com/drivendata/cookiecutter-data-science) A logical, reasonably standardized, but flexible project structure for doing and sharing data science work. +- [**2662**星][2m] [rmusser01/infosec_reference](https://github.com/rmusser01/infosec_reference) An Information Security Reference That Doesn't Suck +- [**2654**星][17d] [JS] [bkimminich/juice-shop](https://github.com/bkimminich/juice-shop) OWASP Juice Shop: Probably the most modern and sophisticated insecure web application +- [**2652**星][3m] [Java] [frohoff/ysoserial](https://github.com/frohoff/ysoserial) 生成会利用不安全的Java对象反序列化的Payload +- [**2645**星][2m] [xairy/linux-kernel-exploitation](https://github.com/xairy/linux-kernel-exploitation) Linux 内核 Fuzz 和漏洞利用的资源收集 +- [**2645**星][1y] [HTML] [chybeta/web-security-learning](https://github.com/chybeta/web-security-learning) Web-Security-Learning +- [**2641**星][1y] [C] [ckolivas/cgminer](https://github.com/ckolivas/cgminer) ASIC and FPGA miner in c for bitcoin +- [**2640**星][2d] [Go] [slackhq/nebula](https://github.com/slackhq/nebula) A scalable overlay networking tool with a focus on performance, simplicity and security +- [**2637**星][4m] [Java] [teevity/ice](https://github.com/teevity/ice) AWS Usage Tool +- [**2625**星][8m] [leandromoreira/linux-network-performance-parameters](https://github.com/leandromoreira/linux-network-performance-parameters) Learn where some of the network sysctl variables fit into the Linux/Kernel network flow +- [**2615**星][2m] [Swift] [zhuhaow/nekit](https://github.com/zhuhaow/nekit) A toolkit for Network Extension Framework +- [**2612**星][4d] [JS] [popcorn-official/popcorn-desktop](https://github.com/popcorn-official/popcorn-desktop) Popcorn Time is a multi-platform, free software BitTorrent client that includes an integrated media player. Desktop ( Windows / Mac / Linux ) a Butter-Project Fork +- [**2607**星][3y] [Ruby] [arachni/arachni](https://github.com/arachni/arachni) Web Application Security Scanner Framework +- [**2603**星][23d] [JS] [knownsec/kcon](https://github.com/knownsec/kcon) KCon is a famous Hacker Con powered by Knownsec Team. +- [**2601**星][1m] [pditommaso/awesome-pipeline](https://github.com/pditommaso/awesome-pipeline) A curated list of awesome pipeline toolkits inspired by Awesome Sysadmin +- [**2596**星][21d] [C++] [fanout/pushpin](https://github.com/fanout/pushpin) Reverse proxy for realtime web services +- [**2581**星][3d] [Go] [adguardteam/adguardhome](https://github.com/adguardteam/adguardhome) Network-wide ads & trackers blocking DNS server +- [**2581**星][1m] [Shell] [medicean/vulapps](https://github.com/medicean/vulapps) 快速搭建各种漏洞环境(Various vulnerability environment) +- [**2575**星][2m] [C] [huntergregal/mimipenguin](https://github.com/huntergregal/mimipenguin) dump 当前Linux用户的登录密码 +- [**2574**星][8y] [C] [id-software/quake](https://github.com/id-software/quake) Quake GPL Source Release +- [**2568**星][1m] [C] [esnet/iperf](https://github.com/esnet/iperf) A TCP, UDP, and SCTP network bandwidth measurement tool +- [**2566**星][2d] [C++] [danmar/cppcheck](https://github.com/danmar/cppcheck) static analysis of C/C++ code +- [**2565**星][5m] [Java] [google/binnavi](https://github.com/google/binnavi) 二进制分析IDE, 对反汇编代码的控制流程图和调用图进行探查/导航/编辑/注释.(IDA插件的作用是导出反汇编) +- [**2562**星][3m] [Py] [greenwolf/social_mapper](https://github.com/Greenwolf/social_mapper) 对多个社交网站的用户Profile图片进行大规模的人脸识别 +- [**2553**星][2y] [evilsocket/bettercap](https://github.com/evilsocket/bettercap) 中间人攻击框架,功能完整,模块化设计,轻便且易于扩展。 +- [**2551**星][9d] [Py] [cloudflare/flan](https://github.com/cloudflare/flan) A pretty sweet vulnerability scanner +- [**2549**星][6m] [C] [geohot/qira](https://github.com/geohot/qira) QEMU Interactive Runtime Analyser +- [**2543**星][19d] [Py] [hugsy/gef](https://github.com/hugsy/gef) gdb增强工具,使用Python API,用于漏洞开发和逆向分析。 +- [**2542**星][23d] [Go] [drk1wi/modlishka](https://github.com/drk1wi/modlishka) Modlishka. Reverse Proxy. +- [**2533**星][8m] [offensive-security/kali-nethunter](https://github.com/offensive-security/kali-nethunter) The Kali NetHunter Project - [**2533**星][2y] [Py] [google/nogotofail](https://github.com/google/nogotofail) 网络安全测试, 辅助定位和修复弱TLS/SSL连接和敏感明文流量 -- [**2532**星][8m] [offensive-security/kali-nethunter](https://github.com/offensive-security/kali-nethunter) The Kali NetHunter Project -- [**2530**星][17d] [Py] [hugsy/gef](https://github.com/hugsy/gef) gdb增强工具,使用Python API,用于漏洞开发和逆向分析。 -- [**2521**星][21d] [Go] [drk1wi/modlishka](https://github.com/drk1wi/modlishka) Modlishka. Reverse Proxy. -- [**2520**星][3y] [HTML] [dirtycow/dirtycow.github.io](https://github.com/dirtycow/dirtycow.github.io) Dirty COW -- [**2515**星][24d] [C] [yrutschle/sslh](https://github.com/yrutschle/sslh) Applicative Protocol Multiplexer (e.g. share SSH and HTTPS on the same port) -- [**2510**星][11d] [Shell] [teddysun/across](https://github.com/teddysun/across) This is a shell script for configure and start WireGuard VPN server -- [**2505**星][3m] [kbandla/aptnotes](https://github.com/kbandla/aptnotes) Various public documents, whitepapers and articles about APT campaigns -- [**2505**星][3y] [C] [dhavalkapil/icmptunnel](https://github.com/dhavalkapil/icmptunnel) Transparently tunnel your IP traffic through ICMP echo and reply packets. +- [**2526**星][2d] [Shell] [teddysun/across](https://github.com/teddysun/across) This is a shell script for configure and start WireGuard VPN server +- [**2525**星][3y] [HTML] [dirtycow/dirtycow.github.io](https://github.com/dirtycow/dirtycow.github.io) Dirty COW +- [**2522**星][26d] [C] [yrutschle/sslh](https://github.com/yrutschle/sslh) Applicative Protocol Multiplexer (e.g. share SSH and HTTPS on the same port) +- [**2516**星][3m] [kbandla/aptnotes](https://github.com/kbandla/aptnotes) Various public documents, whitepapers and articles about APT campaigns +- [**2508**星][5m] [Go] [oj/gobuster](https://github.com/oj/gobuster) Directory/File, DNS and VHost busting tool written in Go +- [**2507**星][2m] [Java] [jboss-javassist/javassist](https://github.com/jboss-javassist/javassist) Java bytecode engineering toolkit +- [**2507**星][3y] [C] [dhavalkapil/icmptunnel](https://github.com/dhavalkapil/icmptunnel) Transparently tunnel your IP traffic through ICMP echo and reply packets. - [**2503**星][7m] [C++] [chengr28/pcap_dnsproxy](https://github.com/chengr28/pcap_dnsproxy) Pcap_DNSProxy, a local DNS server based on packet capturing -- [**2495**星][2m] [Java] [jboss-javassist/javassist](https://github.com/jboss-javassist/javassist) Java bytecode engineering toolkit -- [**2488**星][1y] [onlurking/awesome-infosec](https://github.com/onlurking/awesome-infosec) A curated list of awesome infosec courses and training resources. -- [**2486**星][26d] [Py] [ysrc/xunfeng](https://github.com/ysrc/xunfeng) 巡风是一款适用于企业内网的漏洞快速应急,巡航扫描系统。 -- [**2481**星][5m] [Go] [oj/gobuster](https://github.com/oj/gobuster) Directory/File, DNS and VHost busting tool written in Go -- [**2480**星][8d] [Go] [adguardteam/adguardhome](https://github.com/adguardteam/adguardhome) Network-wide ads & trackers blocking DNS server +- [**2501**星][28d] [Py] [ysrc/xunfeng](https://github.com/ysrc/xunfeng) 巡风是一款适用于企业内网的漏洞快速应急,巡航扫描系统。 +- [**2498**星][6m] [taichi-framework/taichi](https://github.com/taichi-framework/taichi) A framework to use Xposed module with or without Root/Unlock bootloader, supportting Android 5.0 ~ 10.0 +- [**2497**星][6d] [onlurking/awesome-infosec](https://github.com/onlurking/awesome-infosec) A curated list of awesome infosec courses and training resources. +- [**2488**星][5y] [PHP] [audi-1/sqli-labs](https://github.com/audi-1/sqli-labs) SQLI labs to test error based, Blind boolean based, Time based. - [**2480**星][2y] [Py] [feross/spoofmac](https://github.com/feross/spoofmac) 伪造MAC地址(OS X, Windows, Linux) -- [**2473**星][5y] [PHP] [audi-1/sqli-labs](https://github.com/audi-1/sqli-labs) SQLI labs to test error based, Blind boolean based, Time based. -- [**2472**星][11m] [JS] [weixin/miaow](https://github.com/weixin/Miaow) A set of plugins for Sketch include drawing links & marks, UI Kit & Color sync, font & text replacing. -- [**2470**星][6m] [taichi-framework/taichi](https://github.com/taichi-framework/taichi) A framework to use Xposed module with or without Root/Unlock bootloader, supportting Android 5.0 ~ 10.0 -- [**2463**星][13d] [JS] [vitaly-t/pg-promise](https://github.com/vitaly-t/pg-promise) PostgreSQL interface for Node.js -- [**2458**星][3m] [C] [martin-ger/esp_wifi_repeater](https://github.com/martin-ger/esp_wifi_repeater) A full functional WiFi Repeater (correctly: a WiFi NAT Router) -- [**2456**星][4m] [Go] [ne0nd0g/merlin](https://github.com/ne0nd0g/merlin) Merlin is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in golang. -- [**2454**星][24d] [C++] [pavel-odintsov/fastnetmon](https://github.com/pavel-odintsov/fastnetmon) 快速 DDoS 检测/分析工具,支持 sflow/netflow/mirror -- [**2453**星][11m] [C#] [yck1509/confuserex](https://github.com/yck1509/confuserex) An open-source, free protector for .NET applications +- [**2476**星][11m] [JS] [weixin/miaow](https://github.com/weixin/Miaow) A set of plugins for Sketch include drawing links & marks, UI Kit & Color sync, font & text replacing. +- [**2476**星][4m] [Go] [ne0nd0g/merlin](https://github.com/ne0nd0g/merlin) Merlin is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in golang. +- [**2469**星][6d] [JS] [vitaly-t/pg-promise](https://github.com/vitaly-t/pg-promise) PostgreSQL interface for Node.js +- [**2466**星][30d] [Py] [smicallef/spiderfoot](https://github.com/smicallef/spiderfoot) 自动收集指定目标的信息:IP、域名、主机名、网络子网、ASN、邮件地址、用户名 +- [**2464**星][3m] [C] [martin-ger/esp_wifi_repeater](https://github.com/martin-ger/esp_wifi_repeater) A full functional WiFi Repeater (correctly: a WiFi NAT Router) +- [**2461**星][11m] [C#] [yck1509/confuserex](https://github.com/yck1509/confuserex) An open-source, free protector for .NET applications +- [**2461**星][26d] [C++] [pavel-odintsov/fastnetmon](https://github.com/pavel-odintsov/fastnetmon) 快速 DDoS 检测/分析工具,支持 sflow/netflow/mirror +- [**2454**星][21d] [Shell] [rebootuser/linenum](https://github.com/rebootuser/linenum) Scripted Local Linux Enumeration & Privilege Escalation Checks - [**2451**星][3y] [Py] [google/enjarify](https://github.com/google/enjarify) 将Dalvik字节码转换为对应的Java字节码 -- [**2441**星][28d] [Py] [smicallef/spiderfoot](https://github.com/smicallef/spiderfoot) 自动收集指定目标的信息:IP、域名、主机名、网络子网、ASN、邮件地址、用户名 -- [**2424**星][7d] [PHP] [misp/misp](https://github.com/misp/misp) MISP (core software) - Open Source Threat Intelligence and Sharing Platform (formely known as Malware Information Sharing Platform) -- [**2420**星][19d] [Shell] [rebootuser/linenum](https://github.com/rebootuser/linenum) Scripted Local Linux Enumeration & Privilege Escalation Checks -- [**2415**星][1m] [Py] [0xinfection/awesome-waf](https://github.com/0xinfection/awesome-waf) -- [**2412**星][23d] [Py] [pwndbg/pwndbg](https://github.com/pwndbg/pwndbg) GDB插件,辅助漏洞开发和逆向 -- [**2411**星][3y] [Py] [arthepsy/ssh-audit](https://github.com/arthepsy/ssh-audit) SSH server auditing (banner, key exchange, encryption, mac, compression, compatibility, security, etc) -- [**2407**星][1m] [TSQL] [rapid7/metasploitable3](https://github.com/rapid7/metasploitable3) Metasploitable3 is a VM that is built from the ground up with a large amount of security vulnerabilities. -- [**2404**星][24d] [Py] [infobyte/faraday](https://github.com/infobyte/faraday) 渗透测试和漏洞管理平台 -- [**2399**星][3y] [rpisec/malware](https://github.com/rpisec/malware) Course materials for Malware Analysis by RPISEC +- [**2444**星][2d] [PHP] [misp/misp](https://github.com/misp/misp) MISP (core software) - Open Source Threat Intelligence and Sharing Platform (formely known as Malware Information Sharing Platform) +- [**2429**星][1m] [Py] [0xinfection/awesome-waf](https://github.com/0xinfection/awesome-waf) +- [**2423**星][2d] [Py] [pwndbg/pwndbg](https://github.com/pwndbg/pwndbg) GDB插件,辅助漏洞开发和逆向 +- [**2420**星][1m] [TSQL] [rapid7/metasploitable3](https://github.com/rapid7/metasploitable3) Metasploitable3 is a VM that is built from the ground up with a large amount of security vulnerabilities. +- [**2417**星][26d] [Py] [infobyte/faraday](https://github.com/infobyte/faraday) 渗透测试和漏洞管理平台 +- [**2416**星][3y] [Py] [arthepsy/ssh-audit](https://github.com/arthepsy/ssh-audit) SSH server auditing (banner, key exchange, encryption, mac, compression, compatibility, security, etc) +- [**2411**星][26d] [Py] [xmendez/wfuzz](https://github.com/xmendez/wfuzz) Web application fuzzer +- [**2410**星][8m] [Py] [lionsec/katoolin](https://github.com/lionsec/katoolin) Automatically install all Kali linux tools +- [**2407**星][3y] [rpisec/malware](https://github.com/rpisec/malware) Course materials for Malware Analysis by RPISEC +- [**2404**星][20d] [Java] [m66b/netguard](https://github.com/m66b/netguard) A simple way to block access to the internet per app - [**2395**星][3y] [OCaml] [facebookarchive/pfff](https://github.com/facebookarchive/pfff) 一堆工具的集合,用于执行静态分析、代码可视化、代码导航、保持格式的源码转换(例如:源码重构)。完美支持C、Java、JS、PHP,后续将支持其他一大堆语言。 -- [**2395**星][24d] [Py] [xmendez/wfuzz](https://github.com/xmendez/wfuzz) Web application fuzzer -- [**2391**星][8m] [Py] [lionsec/katoolin](https://github.com/lionsec/katoolin) Automatically install all Kali linux tools -- [**2381**星][2y] [Py] [secretsquirrel/the-backdoor-factory](https://github.com/secretsquirrel/the-backdoor-factory) 为PE, ELF, Mach-O二进制文件添加Shellcode后门 -- [**2375**星][1y] [Py] [danmcinerney/lans.py](https://github.com/danmcinerney/lans.py) Inject code and spy on wifi users +- [**2392**星][1m] [Go] [xtaci/kcp-go](https://github.com/xtaci/kcp-go) provide a smooth, resilient, ordered, error-checked and anonymous delivery of streams over UDP packets, +- [**2389**星][8d] [C] [wireshark/wireshark](https://github.com/wireshark/wireshark) Read-only mirror of Wireshark's Git repository. GitHub won't let us disable pull requests. ☞ THEY WILL BE IGNORED HERE ☜ Please upload them at +- [**2386**星][2y] [Py] [secretsquirrel/the-backdoor-factory](https://github.com/secretsquirrel/the-backdoor-factory) 为PE, ELF, Mach-O二进制文件添加Shellcode后门 +- [**2384**星][2d] [Go] [owasp/amass](https://github.com/owasp/amass) In-depth Attack Surface Mapping and Asset Discovery +- [**2381**星][11m] [C] [haad/proxychains](https://github.com/haad/proxychains) a tool that forces any TCP connection made by any given application to follow through proxy like TOR or any other SOCKS4, SOCKS5 or HTTP(S) proxy. Supported auth-types: "user/pass" for SOCKS4/5, "basic" for HTTP. +- [**2376**星][2d] [Java] [mock-server/mockserver](https://github.com/mock-server/mockserver) MockServer enables easy mocking of any system you integrate with via HTTP or HTTPS with clients written in Java, JavaScript and Ruby. MockServer also includes a proxy that introspects all proxied traffic including encrypted SSL traffic and supports Port Forwarding, Web Proxying (i.e. HTTP proxy), HTTPS Tunneling Proxying (using HTTP CONNECT) and… +- [**2376**星][1y] [Py] [danmcinerney/lans.py](https://github.com/danmcinerney/lans.py) Inject code and spy on wifi users +- [**2369**星][7d] [security-onion-solutions/security-onion](https://github.com/security-onion-solutions/security-onion) Linux distro for intrusion detection, enterprise security monitoring, and log management - [**2369**星][2m] [TeX] [crypto101/book](https://github.com/crypto101/book) Crypto 101, the introductory book on cryptography. -- [**2368**星][7d] [C] [wireshark/wireshark](https://github.com/wireshark/wireshark) Read-only mirror of Wireshark's Git repository. GitHub won't let us disable pull requests. ☞ THEY WILL BE IGNORED HERE ☜ Please upload them at -- [**2366**星][7d] [Java] [mock-server/mockserver](https://github.com/mock-server/mockserver) MockServer enables easy mocking of any system you integrate with via HTTP or HTTPS with clients written in Java, JavaScript and Ruby. MockServer also includes a proxy that introspects all proxied traffic including encrypted SSL traffic and supports Port Forwarding, Web Proxying (i.e. HTTP proxy), HTTPS Tunneling Proxying (using HTTP CONNECT) and… -- [**2366**星][11m] [C] [haad/proxychains](https://github.com/haad/proxychains) a tool that forces any TCP connection made by any given application to follow through proxy like TOR or any other SOCKS4, SOCKS5 or HTTP(S) proxy. Supported auth-types: "user/pass" for SOCKS4/5, "basic" for HTTP. -- [**2359**星][1m] [Lua] [snabbco/snabb](https://github.com/snabbco/snabb) Simple and fast packet networking -- [**2359**星][13d] [security-onion-solutions/security-onion](https://github.com/security-onion-solutions/security-onion) Linux distro for intrusion detection, enterprise security monitoring, and log management -- [**2359**星][4m] [Go] [mlabouardy/komiser](https://github.com/mlabouardy/komiser) -- [**2351**星][8d] [C] [domoticz/domoticz](https://github.com/domoticz/domoticz) monitor and configure various devices like: Lights, Switches, various sensors/meters like Temperature, Rain, Wind, UV, Electra, Gas, Water and much more -- [**2350**星][1m] [Py] [ab77/netflix-proxy](https://github.com/ab77/netflix-proxy) Smart DNS proxy to watch Netflix +- [**2366**星][4m] [Go] [mlabouardy/komiser](https://github.com/mlabouardy/komiser) +- [**2364**星][2m] [Py] [ab77/netflix-proxy](https://github.com/ab77/netflix-proxy) Smart DNS proxy to watch Netflix +- [**2362**星][1m] [Lua] [snabbco/snabb](https://github.com/snabbco/snabb) Simple and fast packet networking +- [**2357**星][2d] [C] [domoticz/domoticz](https://github.com/domoticz/domoticz) monitor and configure various devices like: Lights, Switches, various sensors/meters like Temperature, Rain, Wind, UV, Electra, Gas, Water and much more +- [**2352**星][1m] [Py] [ctfd/ctfd](https://github.com/CTFd/CTFd) CTFs as you need them +- [**2349**星][11m] [hack-with-github/free-security-ebooks](https://github.com/hack-with-github/free-security-ebooks) Free Security and Hacking eBooks - [**2342**星][3m] [Go] [vuvuzela/vuvuzela](https://github.com/vuvuzela/vuvuzela) Private messaging system that hides metadata -- [**2342**星][12d] [Go] [owasp/amass](https://github.com/owasp/amass) In-depth Attack Surface Mapping and Asset Discovery -- [**2338**星][6y] [C] [stefanesser/dumpdecrypted](https://github.com/stefanesser/dumpdecrypted) Dumps decrypted mach-o files from encrypted iPhone applications from memory to disk. This tool is necessary for security researchers to be able to look under the hood of encryption. -- [**2335**星][11m] [hack-with-github/free-security-ebooks](https://github.com/hack-with-github/free-security-ebooks) Free Security and Hacking eBooks -- [**2332**星][1m] [Py] [ctfd/ctfd](https://github.com/CTFd/CTFd) CTFs as you need them -- [**2330**星][1m] [JS] [pa11y/pa11y](https://github.com/pa11y/pa11y) Pa11y is your automated accessibility testing pal -- [**2324**星][30d] [C] [hfiref0x/uacme](https://github.com/hfiref0x/uacme) Defeating Windows User Account Control -- [**2317**星][10d] [C] [tsl0922/ttyd](https://github.com/tsl0922/ttyd) Share your terminal over the web -- [**2316**星][5y] [C] [abrasive/shairport](https://github.com/abrasive/shairport) Airtunes emulator! Shairport is no longer maintained. -- [**2302**星][11m] [yeyintminthuhtut/awesome-red-teaming](https://github.com/yeyintminthuhtut/awesome-red-teaming) List of Awesome Red Teaming Resources -- [**2302**星][1y] [Java] [csploit/android](https://github.com/csploit/android) cSploit - The most complete and advanced IT security professional toolkit on Android. -- [**2291**星][3y] [Py] [lmacken/pyrasite](https://github.com/lmacken/pyrasite) 向运行中的 Python进程注入代码 -- [**2277**星][3m] [JS] [retirejs/retire.js](https://github.com/retirejs/retire.js) scanner detecting the use of JavaScript libraries with known vulnerabilities -- [**2272**星][3y] [Py] [therook/subbrute](https://github.com/therook/subbrute) A DNS meta-query spider that enumerates DNS records, and subdomains. -- [**2272**星][1m] [C] [moby/hyperkit](https://github.com/moby/hyperkit) A toolkit for embedding hypervisor capabilities in your application -- [**2271**星][22d] [JS] [talkingdata/inmap](https://github.com/talkingdata/inmap) 大数据地理可视化 -- [**2271**星][2y] [Py] [rootphantomer/blasting_dictionary](https://github.com/rootphantomer/blasting_dictionary) 爆破字典 -- [**2267**星][1m] [C] [aurorawright/luma3ds](https://github.com/aurorawright/luma3ds) Noob-proof (N)3DS "Custom Firmware" -- [**2246**星][16d] [dumb-password-rules/dumb-password-rules](https://github.com/dumb-password-rules/dumb-password-rules) Shaming sites with dumb password rules. -- [**2244**星][2y] [Go] [mehrdadrad/mylg](https://github.com/mehrdadrad/mylg) 网络诊断工具 -- [**2242**星][1m] [Shell] [v1s1t0r1sh3r3/airgeddon](https://github.com/v1s1t0r1sh3r3/airgeddon) This is a multi-use bash script for Linux systems to audit wireless networks. -- [**2241**星][13d] [HTML] [tikam02/devops-guide](https://github.com/tikam02/devops-guide) DevOps Guide from basic to advanced with Interview Questions and Notes -- [**2241**星][3m] [Py] [novnc/websockify](https://github.com/novnc/websockify) Websockify is a WebSocket to TCP proxy/bridge. This allows a browser to connect to any application/server/service. Implementations in Python, C, Node.js and Ruby. -- [**2235**星][1m] [Shell] [eliaskotlyar/xiaomi-dafang-hacks](https://github.com/eliaskotlyar/xiaomi-dafang-hacks) +- [**2340**星][6y] [C] [stefanesser/dumpdecrypted](https://github.com/stefanesser/dumpdecrypted) Dumps decrypted mach-o files from encrypted iPhone applications from memory to disk. This tool is necessary for security researchers to be able to look under the hood of encryption. +- [**2340**星][1m] [C] [hfiref0x/uacme](https://github.com/hfiref0x/uacme) Defeating Windows User Account Control +- [**2337**星][1m] [JS] [pa11y/pa11y](https://github.com/pa11y/pa11y) Pa11y is your automated accessibility testing pal +- [**2335**星][3d] [C] [tsl0922/ttyd](https://github.com/tsl0922/ttyd) Share your terminal over the web +- [**2323**星][3d] [C#] [netchx/netch](https://github.com/netchx/netch) Game accelerator. Support Socks5, Shadowsocks, ShadowsocksR, V2Ray protocol. UDP NAT FullCone +- [**2321**星][11m] [yeyintminthuhtut/awesome-red-teaming](https://github.com/yeyintminthuhtut/awesome-red-teaming) List of Awesome Red Teaming Resources +- [**2318**星][5y] [C] [abrasive/shairport](https://github.com/abrasive/shairport) Airtunes emulator! Shairport is no longer maintained. +- [**2304**星][1y] [Java] [csploit/android](https://github.com/csploit/android) cSploit - The most complete and advanced IT security professional toolkit on Android. +- [**2301**星][15d] [HTML] [tikam02/devops-guide](https://github.com/tikam02/devops-guide) DevOps Guide from basic to advanced with Interview Questions and Notes +- [**2295**星][3y] [Py] [lmacken/pyrasite](https://github.com/lmacken/pyrasite) 向运行中的 Python进程注入代码 +- [**2287**星][2y] [Py] [rootphantomer/blasting_dictionary](https://github.com/rootphantomer/blasting_dictionary) 爆破字典 +- [**2284**星][1m] [C] [moby/hyperkit](https://github.com/moby/hyperkit) A toolkit for embedding hypervisor capabilities in your application +- [**2283**星][5m] [Py] [guohongze/adminset](https://github.com/guohongze/adminset) 自动化运维平台:CMDB、CD、DevOps、资产管理、任务编排、持续交付、系统监控、运维管理、配置管理 +- [**2282**星][3y] [Py] [therook/subbrute](https://github.com/therook/subbrute) A DNS meta-query spider that enumerates DNS records, and subdomains. +- [**2281**星][3m] [JS] [retirejs/retire.js](https://github.com/retirejs/retire.js) scanner detecting the use of JavaScript libraries with known vulnerabilities +- [**2276**星][24d] [JS] [talkingdata/inmap](https://github.com/talkingdata/inmap) 大数据地理可视化 +- [**2274**星][1m] [Shell] [v1s1t0r1sh3r3/airgeddon](https://github.com/v1s1t0r1sh3r3/airgeddon) This is a multi-use bash script for Linux systems to audit wireless networks. +- [**2270**星][1m] [C] [aurorawright/luma3ds](https://github.com/aurorawright/luma3ds) Noob-proof (N)3DS "Custom Firmware" +- [**2255**星][3m] [Py] [novnc/websockify](https://github.com/novnc/websockify) Websockify is a WebSocket to TCP proxy/bridge. This allows a browser to connect to any application/server/service. Implementations in Python, C, Node.js and Ruby. +- [**2252**星][18d] [dumb-password-rules/dumb-password-rules](https://github.com/dumb-password-rules/dumb-password-rules) Shaming sites with dumb password rules. +- [**2252**星][1m] [Shell] [eliaskotlyar/xiaomi-dafang-hacks](https://github.com/eliaskotlyar/xiaomi-dafang-hacks) +- [**2248**星][12d] [PS] [k8gege/k8tools](https://github.com/k8gege/k8tools) K8工具合集(内网渗透/提权工具/远程溢出/漏洞利用/扫描工具/密码破解/免杀工具/Exploit/APT/0day/Shellcode/Payload/priviledge/BypassUAC/OverFlow/WebShell/PenTest) Web GetShell Exploit(Struts2/Zimbra/Weblogic/Tomcat/Apache/Jboss/DotNetNuke/zabbix) +- [**2245**星][2y] [Go] [mehrdadrad/mylg](https://github.com/mehrdadrad/mylg) 网络诊断工具 - [**2226**星][5y] [Go] [filosottile/heartbleed](https://github.com/filosottile/heartbleed) A checker (site and tool) for CVE-2014-0160 -- [**2222**星][8d] [C#] [netchx/netch](https://github.com/netchx/netch) Game accelerator. Support Socks5, Shadowsocks, ShadowsocksR, V2Ray protocol. UDP NAT FullCone -- [**2218**星][7d] [Py] [cloudflare/flan](https://github.com/cloudflare/flan) A pretty sweet vulnerability scanner +- [**2217**星][1y] [JS] [cure53/h5sc](https://github.com/cure53/h5sc) HTML5 Security Cheatsheet - A collection of HTML5 related XSS attack vectors - [**2215**星][6y] [C++] [codebutler/firesheep](https://github.com/codebutler/firesheep) 演示HTTP会话劫持攻击的Firefox扩展 -- [**2211**星][1y] [JS] [cure53/h5sc](https://github.com/cure53/h5sc) HTML5 Security Cheatsheet - A collection of HTML5 related XSS attack vectors -- [**2204**星][10d] [PowerShell] [k8gege/k8tools](https://github.com/k8gege/k8tools) K8工具合集(内网渗透/提权工具/远程溢出/漏洞利用/扫描工具/密码破解/免杀工具/Exploit/APT/0day/Shellcode/Payload/priviledge/BypassUAC/OverFlow/WebShell/PenTest) Web GetShell Exploit(Struts2/Zimbra/Weblogic/Tomcat/Apache/Jboss/DotNetNuke/zabbix) -- [**2203**星][1m] [C] [texane/stlink](https://github.com/texane/stlink) stm32 discovery line linux programmer -- [**2201**星][11d] [Go] [google/mtail](https://github.com/google/mtail) extract whitebox monitoring data from application logs for collection in a timeseries database -- [**2187**星][21d] [C++] [google/bloaty](https://github.com/google/bloaty) Bloaty McBloatface: a size profiler for binaries +- [**2213**星][2d] [Go] [aquasecurity/kube-bench](https://github.com/aquasecurity/kube-bench) Checks whether Kubernetes is deployed according to security best practices as defined in the CIS Kubernetes Benchmark +- [**2211**星][1m] [C] [texane/stlink](https://github.com/texane/stlink) stm32 discovery line linux programmer +- [**2211**星][6d] [Go] [google/mtail](https://github.com/google/mtail) extract whitebox monitoring data from application logs for collection in a timeseries database +- [**2209**星][22d] [Rust] [cloudflare/boringtun](https://github.com/cloudflare/boringtun) an implementation of the WireGuard® protocol designed for portability and speed. +- [**2192**星][23d] [C++] [google/bloaty](https://github.com/google/bloaty) Bloaty McBloatface: a size profiler for binaries +- [**2189**星][1m] [sobolevn/awesome-cryptography](https://github.com/sobolevn/awesome-cryptography) A curated list of cryptography resources and links. +- [**2187**星][7d] [getlantern/lantern-binaries](https://github.com/getlantern/lantern-binaries) Lantern installers binary downloads. +- [**2186**星][1y] [Py] [datasploit/datasploit](https://github.com/DataSploit/datasploit) 对指定目标执行多种侦查技术:企业、人、电话号码、比特币地址等 - [**2184**星][3y] [enddo/awesome-windows-exploitation](https://github.com/enddo/awesome-windows-exploitation) A curated list of awesome Windows Exploitation resources, and shiny things. Inspired by awesom -- [**2182**星][1y] [Py] [datasploit/datasploit](https://github.com/DataSploit/datasploit) 对指定目标执行多种侦查技术:企业、人、电话号码、比特币地址等 -- [**2177**星][1m] [JS] [secgroundzero/warberry](https://github.com/secgroundzero/warberry) WarBerryPi - Tactical Exploitation -- [**2171**星][14d] [C] [armmbed/mbedtls](https://github.com/armmbed/mbedtls) An open source, portable, easy to use, readable and flexible SSL library -- [**2168**星][16d] [getlantern/lantern-binaries](https://github.com/getlantern/lantern-binaries) Lantern installers binary downloads. -- [**2167**星][29d] [sobolevn/awesome-cryptography](https://github.com/sobolevn/awesome-cryptography) A curated list of cryptography resources and links. -- [**2158**星][2m] [Go] [mmatczuk/go-http-tunnel](https://github.com/mmatczuk/go-http-tunnel) Fast and secure tunnels over HTTP/2 -- [**2156**星][1m] [C] [conorpp/u2f-zero](https://github.com/conorpp/u2f-zero) U2F USB token optimized for physical security, affordability, and style -- [**2155**星][1y] [C++] [maestron/botnets](https://github.com/maestron/botnets) This is a collection of #botnet source codes, unorganized. For EDUCATIONAL PURPOSES ONLY +- [**2183**星][2d] [C] [armmbed/mbedtls](https://github.com/armmbed/mbedtls) An open source, portable, easy to use, readable and flexible SSL library +- [**2179**星][1m] [JS] [secgroundzero/warberry](https://github.com/secgroundzero/warberry) WarBerryPi - Tactical Exploitation +- [**2173**星][1y] [JS] [iam4x/pokemongo-webspoof](https://github.com/iam4x/pokemongo-webspoof) +- [**2163**星][2m] [Go] [mmatczuk/go-http-tunnel](https://github.com/mmatczuk/go-http-tunnel) Fast and secure tunnels over HTTP/2 +- [**2162**星][1y] [C++] [maestron/botnets](https://github.com/maestron/botnets) This is a collection of #botnet source codes, unorganized. For EDUCATIONAL PURPOSES ONLY +- [**2159**星][1m] [Py] [commixproject/commix](https://github.com/commixproject/commix) Automated All-in-One OS command injection and exploitation tool. +- [**2158**星][9m] [exakat/php-static-analysis-tools](https://github.com/exakat/php-static-analysis-tools) A reviewed list of useful PHP static analysis tools +- [**2158**星][1m] [C] [conorpp/u2f-zero](https://github.com/conorpp/u2f-zero) U2F USB token optimized for physical security, affordability, and style +- [**2158**星][2m] [PHP] [antonioribeiro/tracker](https://github.com/antonioribeiro/tracker) Tracker gathers a lot of information from your requests to identify and store - [**2153**星][6y] [Ruby] [plamoni/siriproxy](https://github.com/plamoni/siriproxy) A (tampering) proxy server for Apple's Siri -- [**2152**星][29d] [Py] [commixproject/commix](https://github.com/commixproject/commix) Automated All-in-One OS command injection and exploitation tool. -- [**2151**星][9m] [exakat/php-static-analysis-tools](https://github.com/exakat/php-static-analysis-tools) A reviewed list of useful PHP static analysis tools -- [**2146**星][14d] [Java] [google/wycheproof](https://github.com/google/wycheproof) Project Wycheproof tests crypto libraries against known attacks. -- [**2127**星][1m] [Py] [jonathansalwan/ropgadget](https://github.com/jonathansalwan/ropgadget) This tool lets you search your gadgets on your binaries to facilitate your ROP exploitation. ROPgadget supports ELF, PE and Mach-O format on x86, x64, ARM, ARM64, PowerPC, SPARC and MIPS architectures. -- [**2124**星][2m] [Py] [trustedsec/unicorn](https://github.com/trustedsec/unicorn) 通过PowerShell降级攻击, 直接将Shellcode注入到内存 -- [**2123**星][16d] [Assembly] [pret/pokered](https://github.com/pret/pokered) disassembly of Pokémon Red/Blue -- [**2114**星][7m] [Py] [calebmadrigal/trackerjacker](https://github.com/calebmadrigal/trackerjacker) 映射你没连接到的Wifi网络, 类似于NMap, 另外可以追踪设备 -- [**2112**星][1y] [Py] [rub-nds/pret](https://github.com/rub-nds/pret) Printer Exploitation Toolkit - The tool that made dumpster diving obsolete. +- [**2149**星][8d] [Java] [google/wycheproof](https://github.com/google/wycheproof) Project Wycheproof tests crypto libraries against known attacks. +- [**2138**星][2m] [Py] [trustedsec/unicorn](https://github.com/trustedsec/unicorn) 通过PowerShell降级攻击, 直接将Shellcode注入到内存 +- [**2132**星][1m] [Py] [jonathansalwan/ropgadget](https://github.com/jonathansalwan/ropgadget) This tool lets you search your gadgets on your binaries to facilitate your ROP exploitation. ROPgadget supports ELF, PE and Mach-O format on x86, x64, ARM, ARM64, PowerPC, SPARC and MIPS architectures. +- [**2127**星][18d] [Assembly] [pret/pokered](https://github.com/pret/pokered) disassembly of Pokémon Red/Blue +- [**2122**星][2y] [Py] [rub-nds/pret](https://github.com/rub-nds/pret) Printer Exploitation Toolkit - The tool that made dumpster diving obsolete. +- [**2118**星][4d] [goq/telegram-list](https://github.com/goq/telegram-list) List of telegram groups, channels & bots // Список интересных групп, каналов и ботов телеграма // Список чатов для программистов +- [**2117**星][1m] [Py] [elceef/dnstwist](https://github.com/elceef/dnstwist) 域名置换引擎,用于检测打字错误,网络钓鱼和企业间谍活动 +- [**2116**星][7m] [Py] [calebmadrigal/trackerjacker](https://github.com/calebmadrigal/trackerjacker) 映射你没连接到的Wifi网络, 类似于NMap, 另外可以追踪设备 +- [**2115**星][2d] [Py] [fortynorthsecurity/eyewitness](https://github.com/FortyNorthSecurity/EyeWitness) 给网站做快照,提供服务器Header信息,识别默认凭证等 +- [**2114**星][7y] [C++] [lloyd/node-memwatch](https://github.com/lloyd/node-memwatch) A NodeJS library to keep an eye on your memory usage, and discover and isolate leaks. - [**2107**星][4y] [C] [hashcat/hashcat-legacy](https://github.com/hashcat/hashcat-legacy) Advanced CPU-based password recovery utility -- [**2105**星][7d] [goq/telegram-list](https://github.com/goq/telegram-list) List of telegram groups, channels & bots // Список интересных групп, каналов и ботов телеграма // Список чатов для программистов -- [**2105**星][1m] [Py] [elceef/dnstwist](https://github.com/elceef/dnstwist) 域名置换引擎,用于检测打字错误,网络钓鱼和企业间谍活动 -- [**2103**星][8m] [Py] [linkedin/qark](https://github.com/linkedin/qark) 查找Android App的漏洞, 支持源码或APK文件 -- [**2098**星][19d] [Py] [fortynorthsecurity/eyewitness](https://github.com/FortyNorthSecurity/EyeWitness) 给网站做快照,提供服务器Header信息,识别默认凭证等 -- [**2098**星][21d] [infoslack/awesome-web-hacking](https://github.com/infoslack/awesome-web-hacking) A list of web application security -- [**2090**星][3m] [yeahhub/hacking-security-ebooks](https://github.com/yeahhub/hacking-security-ebooks) Top 100 Hacking & Security E-Books (Free Download) -- [**2081**星][8d] [C] [flatpak/flatpak](https://github.com/flatpak/flatpak) Linux application sandboxing and distribution framework -- [**2071**星][30d] [Go] [theupdateframework/notary](https://github.com/theupdateframework/notary) Notary is a project that allows anyone to have trust over arbitrary collections of data -- [**2069**星][20d] [Ruby] [urbanadventurer/whatweb](https://github.com/urbanadventurer/whatweb) Next generation web scanner -- [**2062**星][9m] [jermic/android-crack-tool](https://github.com/jermic/android-crack-tool) -- [**2051**星][4m] [Py] [whaleshark-team/cobra](https://github.com/WhaleShark-Team/cobra) Source Code Security Audit (源代码安全审计) -- [**2049**星][1y] [bluscreenofjeff/red-team-infrastructure-wiki](https://github.com/bluscreenofjeff/red-team-infrastructure-wiki) Wiki to collect Red Team infrastructure hardening resources -- [**2047**星][6m] [Go] [maxmcd/webtty](https://github.com/maxmcd/webtty) Share a terminal session over WebRTC -- [**2041**星][2y] [Py] [derv82/wifite](https://github.com/derv82/wifite) 自动化无线攻击工具 -- [**2037**星][10d] [Py] [nabla-c0d3/sslyze](https://github.com/nabla-c0d3/sslyze) SSL/TLS服务器扫描 -- [**2036**星][2m] [C++] [lordnoteworthy/al-khaser](https://github.com/lordnoteworthy/al-khaser) Public malware techniques used in the wild: Virtual Machine, Emulation, Debuggers, Sandbox detection. -- [**2035**星][2m] [tanprathan/mobileapp-pentest-cheatsheet](https://github.com/tanprathan/mobileapp-pentest-cheatsheet) The Mobile App Pentest cheat sheet was created to provide concise collection of high value information on specific mobile application penetration testing topics. -- [**2035**星][8m] [Shell] [foospidy/payloads](https://github.com/foospidy/payloads) web 攻击 Payload 集合 -- [**2032**星][7d] [C++] [openthread/openthread](https://github.com/openthread/openthread) OpenThread released by Google is an open-source implementation of the Thread networking protocol -- [**2032**星][1m] [edoverflow/bugbounty-cheatsheet](https://github.com/edoverflow/bugbounty-cheatsheet) A list of interesting payloads, tips and tricks for bug bounty hunters. -- [**2024**星][5y] [CoffeeScript] [shadowsocks/shadowsocks-gui](https://github.com/shadowsocks/shadowsocks-gui) Shadowsocks GUI client -- [**2020**星][20d] [Objective-C] [ios-control/ios-deploy](https://github.com/ios-control/ios-deploy) Install and debug iPhone apps from the command line, without using Xcode -- [**2017**星][3m] [C++] [darthton/blackbone](https://github.com/darthton/blackbone) Windows memory hacking library -- [**2016**星][3y] [Swift] [urinx/iosapphook](https://github.com/urinx/iosapphook) 专注于非越狱环境下iOS应用逆向研究,从dylib注入,应用重签名到App Hook -- [**2014**星][8d] [Py] [sensepost/objection](https://github.com/sensepost/objection) runtimemobile exploration -- [**2012**星][1y] [C] [xoreaxeaxeax/rosenbridge](https://github.com/xoreaxeaxeax/rosenbridge) Hardware backdoors in some x86 CPUs -- [**2006**星][9m] [C] [dekunukem/nintendo_switch_reverse_engineering](https://github.com/dekunukem/nintendo_switch_reverse_engineering) A look at inner workings of Joycon and Nintendo Switch -- [**2004**星][4y] [C] [probablycorey/wax](https://github.com/probablycorey/wax) Wax is now being maintained by alibaba -- [**1999**星][8d] [Java] [jeremylong/dependencycheck](https://github.com/jeremylong/dependencycheck) OWASP dependency-check is a software composition analysis utility that detects publicly disclosed vulnerabilities in application dependencies. -- [**1998**星][13d] [Shell] [wulabing/v2ray_ws-tls_bash_onekey](https://github.com/wulabing/v2ray_ws-tls_bash_onekey) V2Ray Nginx+vmess+ws+tls/ http2 over tls 一键安装脚本 -- [**1992**星][25d] [Swift] [github/softu2f](https://github.com/github/softu2f) Software U2F authenticator for macOS -- [**1991**星][29d] [qazbnm456/awesome-cve-poc](https://github.com/qazbnm456/awesome-cve-poc) CVE PoC列表 -- [**1990**星][4m] [swiftonsecurity/sysmon-config](https://github.com/swiftonsecurity/sysmon-config) Sysmon configuration file template with default high-quality event tracing -- [**1988**星][4y] [Go] [yahoo/gryffin](https://github.com/yahoo/gryffin) Gryffin is a large scale web security scanning platform. -- [**1987**星][7m] [Py] [fsecurelabs/drozer](https://github.com/FSecureLABS/drozer) The Leading Security Assessment Framework for Android. -- [**1983**星][2y] [dloss/python-pentest-tools](https://github.com/dloss/python-pentest-tools) 可用于渗透测试的Python工具收集 -- [**1983**星][2m] [C++] [asmjit/asmjit](https://github.com/asmjit/asmjit) Complete x86/x64 JIT and AOT Assembler for C++ -- [**1976**星][3m] [infosecn1nja/ad-attack-defense](https://github.com/infosecn1nja/ad-attack-defense) Attack and defend active directory using modern post exploitation adversary tradecraft activity -- [**1967**星][26d] [Java] [genymobile/gnirehtet](https://github.com/genymobile/gnirehtet) Gnirehtet provides reverse tethering for Android -- [**1965**星][9m] [JS] [weichiachang/stacks-cli](https://github.com/weichiachang/stacks-cli) Check website stack from the terminal -- [**1963**星][11d] [HTML] [gtfobins/gtfobins.github.io](https://github.com/gtfobins/gtfobins.github.io) Curated list of Unix binaries that can be exploited to bypass system security restrictions -- [**1963**星][27d] [Java] [elderdrivers/edxposed](https://github.com/elderdrivers/edxposed) Elder driver Xposed Framework. -- [**1962**星][1m] [Py] [momosecurity/aswan](https://github.com/momosecurity/aswan) 陌陌风控系统静态规则引擎,零基础简易便捷的配置多种复杂规则,实时高效管控用户异常行为。 -- [**1958**星][26d] [C#] [mathewsachin/captura](https://github.com/mathewsachin/captura) Capture Screen, Audio, Cursor, Mouse Clicks and Keystrokes -- [**1957**星][9d] [Go] [ullaakut/cameradar](https://github.com/Ullaakut/cameradar) Cameradar hacks its way into RTSP videosurveillance cameras -- [**1954**星][1y] [BitBake] [1n3/intruderpayloads](https://github.com/1n3/intruderpayloads) A collection of Burpsuite Intruder payloads, BurpBounty payloads, fuzz lists, malicious file uploads and web pentesting methodologies and checklists. -- [**1946**星][2y] [obfuscator-llvm/obfuscator](https://github.com/obfuscator-llvm/obfuscator) Obfuscator-LLVM -- [**1945**星][7d] [Perl] [spiderlabs/owasp-modsecurity-crs](https://github.com/spiderlabs/owasp-modsecurity-crs) OWASP ModSecurity Core Rule Set (CRS) Project (Official Repository) -- [**1940**星][3y] [C#] [lazocoder/windows-hacks](https://github.com/lazocoder/windows-hacks) Creative and unusual things that can be done with the Windows API. -- [**1939**星][2m] [C] [microsoft/procdump-for-linux](https://github.com/microsoft/procdump-for-linux) Linux 版本的 ProcDump -- [**1938**星][27d] [Py] [nixawk/pentest-wiki](https://github.com/nixawk/pentest-wiki) PENTEST-WIKI is a free online security knowledge library for pentesters / researchers. If you have a good idea, please share it with others. -- [**1938**星][14d] [Py] [cea-sec/miasm](https://github.com/cea-sec/miasm) Reverse engineering framework in Python -- [**1926**星][17d] [Go] [mpolden/echoip](https://github.com/mpolden/echoip) IP address lookup service -- [**1913**星][5m] [C] [darkk/redsocks](https://github.com/darkk/redsocks) transparent TCP-to-proxy redirector -- [**1912**星][3m] [toolswatch/blackhat-arsenal-tools](https://github.com/toolswatch/blackhat-arsenal-tools) Black Hat 武器库 -- [**1911**星][3y] [Py] [aoncyberlabs/windows-exploit-suggester](https://github.com/AonCyberLabs/Windows-Exploit-Suggester) This tool compares a targets patch levels against the Microsoft vulnerability database in order to detect potential missing patches on the target. It also notifies the user if there are public exploits and Metasploit modules available for the missing bulletins. -- [**1911**星][8d] [C] [ntop/ndpi](https://github.com/ntop/ndpi) Open Source Deep Packet Inspection Software Toolkit -- [**1909**星][3d] [Go] [projectdiscovery/subfinder](https://github.com/projectdiscovery/subfinder) Subfinder is a subdomain discovery tool that discovers valid subdomains for websites. Designed as a passive framework to be useful for bug bounties and safe for penetration testing. -- [**1909**星][9d] [Py] [j3ssie/osmedeus](https://github.com/j3ssie/osmedeus) Fully automated offensive security framework for reconnaissance and vulnerability scanning -- [**1908**星][7d] [C++] [powerdns/pdns](https://github.com/powerdns/pdns) PowerDNS -- [**1907**星][16d] [Py] [lanjelot/patator](https://github.com/lanjelot/patator) Patator is a multi-purpose brute-forcer, with a modular design and a flexible usage. -- [**1906**星][13d] [CSS] [cyb3rward0g/helk](https://github.com/cyb3rward0g/helk) 对ELK栈进行分析,具备多种高级功能,例如SQL声明性语言,图形,结构化流,机器学习等 -- [**1902**星][7d] [Go] [solo-io/gloo](https://github.com/solo-io/gloo) An Envoy-Powered API Gateway -- [**1901**星][3m] [Go] [minishift/minishift](https://github.com/minishift/minishift) Run OpenShift 3.x locally -- [**1892**星][19d] [C] [chipsec/chipsec](https://github.com/chipsec/chipsec) 分析PC平台的安全性, 包括硬件、系统固件(BIOS/UEFI)和平台组件 -- [**1891**星][7d] [Py] [mozilla/mozdef](https://github.com/mozilla/mozdef) Mozilla Enterprise Defense Platform -- [**1886**星][8d] [Go] [chaitin/xray](https://github.com/chaitin/xray) xray 安全评估工具 | 使用之前务必先阅读文档 -- [**1880**星][14d] [C++] [mhammond/pywin32](https://github.com/mhammond/pywin32) Python for Windows (pywin32) Extensions -- [**1878**星][4m] [C] [shadowsocks/simple-obfs](https://github.com/shadowsocks/simple-obfs) A simple obfuscating tool (Deprecated) -- [**1876**星][7d] [Shell] [toniblyx/prowler](https://github.com/toniblyx/prowler) AWS Security Best Practices Assessment, Auditing, Hardening and Forensics Readiness Tool. It follows guidelines of the CIS Amazon Web Services Foundations Benchmark and DOZENS of additional checks including GDPR and HIPAA (+100). Official CIS for AWS guide: -- [**1876**星][5y] [C++] [tum-vision/lsd_slam](https://github.com/tum-vision/lsd_slam) LSD-SLAM -- [**1876**星][4m] [Py] [python-security/pyt](https://github.com/python-security/pyt) Python Web App 安全漏洞检测和静态分析工具 -- [**1876**星][6m] [Java] [fuzion24/justtrustme](https://github.com/fuzion24/justtrustme) An xposed module that disables SSL certificate checking for the purposes of auditing an app with cert pinning -- [**1876**星][1y] [Py] [aploium/zmirror](https://github.com/aploium/zmirror) The next-gen reverse proxy for full site mirroring -- [**1869**星][13d] [YARA] [yara-rules/rules](https://github.com/yara-rules/rules) Repository of yara rules -- [**1868**星][1y] [Py] [derv82/wifite2](https://github.com/derv82/wifite2) 无线网络审计工具wifite 的升级版/重制版 -- [**1867**星][2m] [Py] [pycqa/bandit](https://github.com/pycqa/bandit) 在Python代码中查找常见的安全问题 -- [**1864**星][7d] [C] [merbanan/rtl_433](https://github.com/merbanan/rtl_433) Program to decode traffic from Devices that are broadcasting on 433.9 MHz like temperature sensors -- [**1863**星][4y] [Objective-C] [xcodeghostsource/xcodeghost](https://github.com/xcodeghostsource/xcodeghost) "XcodeGhost" Source -- [**1861**星][10m] [PHP] [bartblaze/php-backdoors](https://github.com/bartblaze/php-backdoors) A collection of PHP backdoors. For educational or testing purposes only. -- [**1861**星][4m] [Java] [adoptopenjdk/jitwatch](https://github.com/adoptopenjdk/jitwatch) Log analyser / visualiser for Java HotSpot JIT compiler. Inspect inlining decisions, hot methods, bytecode, and assembly. View results in the JavaFX user interface. -- [**1858**星][10d] [Py] [aquasecurity/kube-hunter](https://github.com/aquasecurity/kube-hunter) Hunt for security weaknesses in Kubernetes clusters -- [**1857**星][21d] [C] [tinyproxy/tinyproxy](https://github.com/tinyproxy/tinyproxy) a light-weight HTTP/HTTPS proxy daemon for POSIX operating systems -- [**1857**星][7d] [olivierlaflamme/cheatsheet-god](https://github.com/olivierlaflamme/cheatsheet-god) Penetration Testing Reference Bank - OSCP / PTP & PTX Cheatsheet -- [**1849**星][11m] [C++] [googlecreativelab/open-nsynth-super](https://github.com/googlecreativelab/open-nsynth-super) Open NSynth Super is an experimental physical interface for the NSynth algorithm -- [**1848**星][29d] [C] [github/glb-director](https://github.com/github/glb-director) GitHub Load Balancer Director and supporting tooling. -- [**1846**星][8m] [Py] [netflix-skunkworks/stethoscope](https://github.com/Netflix-Skunkworks/stethoscope) Personalized, user-focused recommendations for employee information security. -- [**1845**星][2m] [Py] [pwnlandia/mhn](https://github.com/pwnlandia/mhn) 蜜罐网络 -- [**1844**星][8d] [TypeScript] [snyk/snyk](https://github.com/snyk/snyk) CLI and build-time tool to find & fix known vulnerabilities in open-source dependencies -- [**1842**星][1y] [Java] [jindrapetrik/jpexs-decompiler](https://github.com/jindrapetrik/jpexs-decompiler) JPEXS Free Flash Decompiler -- [**1841**星][13d] [C++] [acidanthera/lilu](https://github.com/acidanthera/Lilu) Arbitrary kext and process patching on macOS +- [**2105**星][8m] [Py] [linkedin/qark](https://github.com/linkedin/qark) 查找Android App的漏洞, 支持源码或APK文件 +- [**2103**星][3m] [yeahhub/hacking-security-ebooks](https://github.com/yeahhub/hacking-security-ebooks) Top 100 Hacking & Security E-Books (Free Download) +- [**2103**星][23d] [infoslack/awesome-web-hacking](https://github.com/infoslack/awesome-web-hacking) A list of web application security +- [**2095**星][2d] [C] [wireguard/wireguard](https://github.com/wireguard/wireguard) fast, modern, secure kernel VPN tunnel +- [**2093**星][22d] [Ruby] [urbanadventurer/whatweb](https://github.com/urbanadventurer/whatweb) Next generation web scanner +- [**2084**星][5d] [C] [flatpak/flatpak](https://github.com/flatpak/flatpak) Linux application sandboxing and distribution framework +- [**2078**星][1m] [Go] [theupdateframework/notary](https://github.com/theupdateframework/notary) Notary is a project that allows anyone to have trust over arbitrary collections of data +- [**2071**星][15d] [Shell] [wulabing/v2ray_ws-tls_bash_onekey](https://github.com/wulabing/v2ray_ws-tls_bash_onekey) V2Ray Nginx+vmess+ws+tls/ http2 over tls 一键安装脚本 +- [**2066**星][9m] [jermic/android-crack-tool](https://github.com/jermic/android-crack-tool) +- [**2058**星][4m] [Py] [whaleshark-team/cobra](https://github.com/WhaleShark-Team/cobra) Source Code Security Audit (源代码安全审计) +- [**2057**星][1y] [bluscreenofjeff/red-team-infrastructure-wiki](https://github.com/bluscreenofjeff/red-team-infrastructure-wiki) Wiki to collect Red Team infrastructure hardening resources +- [**2054**星][7d] [swiftonsecurity/sysmon-config](https://github.com/swiftonsecurity/sysmon-config) Sysmon configuration file template with default high-quality event tracing +- [**2051**星][2m] [tanprathan/mobileapp-pentest-cheatsheet](https://github.com/tanprathan/mobileapp-pentest-cheatsheet) The Mobile App Pentest cheat sheet was created to provide concise collection of high value information on specific mobile application penetration testing topics. +- [**2048**星][6m] [Go] [maxmcd/webtty](https://github.com/maxmcd/webtty) Share a terminal session over WebRTC +- [**2047**星][1m] [edoverflow/bugbounty-cheatsheet](https://github.com/edoverflow/bugbounty-cheatsheet) A list of interesting payloads, tips and tricks for bug bounty hunters. +- [**2045**星][2m] [C++] [lordnoteworthy/al-khaser](https://github.com/lordnoteworthy/al-khaser) 在野恶意软件使用的技术:虚拟机,仿真,调试器,沙盒检测。 +- [**2045**星][8m] [Shell] [foospidy/payloads](https://github.com/foospidy/payloads) web 攻击 Payload 集合 +- [**2043**星][12d] [Py] [nabla-c0d3/sslyze](https://github.com/nabla-c0d3/sslyze) SSL/TLS服务器扫描 +- [**2042**星][2y] [Py] [derv82/wifite](https://github.com/derv82/wifite) 自动化无线攻击工具 +- [**2039**星][5d] [C++] [openthread/openthread](https://github.com/openthread/openthread) OpenThread released by Google is an open-source implementation of the Thread networking protocol +- [**2033**星][2d] [ObjC] [ios-control/ios-deploy](https://github.com/ios-control/ios-deploy) Install and debug iPhone apps from the command line, without using Xcode +- [**2033**星][2d] [Py] [sensepost/objection](https://github.com/sensepost/objection) runtimemobile exploration +- [**2029**星][3d] [Go] [goodrain/rainbond](https://github.com/goodrain/rainbond) Enterprise application cloud operating system(企业应用云操作系统) +- [**2025**星][5y] [CoffeeScript] [shadowsocks/shadowsocks-gui](https://github.com/shadowsocks/shadowsocks-gui) Shadowsocks GUI client +- [**2024**星][2d] [C++] [darthton/blackbone](https://github.com/darthton/blackbone) Windows memory hacking library +- [**2017**星][3y] [Swift] [urinx/iosapphook](https://github.com/urinx/iosapphook) 专注于非越狱环境下iOS应用逆向研究,从dylib注入,应用重签名到App Hook +- [**2016**星][23d] [Java] [genymobile/gnirehtet](https://github.com/genymobile/gnirehtet) Gnirehtet provides reverse tethering for Android +- [**2016**星][9m] [C] [dekunukem/nintendo_switch_reverse_engineering](https://github.com/dekunukem/nintendo_switch_reverse_engineering) A look at inner workings of Joycon and Nintendo Switch +- [**2014**星][1y] [C] [xoreaxeaxeax/rosenbridge](https://github.com/xoreaxeaxeax/rosenbridge) Hardware backdoors in some x86 CPUs +- [**2014**星][5d] [Java] [jeremylong/dependencycheck](https://github.com/jeremylong/dependencycheck) OWASP dependency-check is a software composition analysis utility that detects publicly disclosed vulnerabilities in application dependencies. +- [**2005**星][4y] [C] [probablycorey/wax](https://github.com/probablycorey/wax) Wax is now being maintained by alibaba +- [**2003**星][2m] [Go] [skynetservices/skydns](https://github.com/skynetservices/skydns) DNS service discovery for etcd +- [**2000**星][1m] [qazbnm456/awesome-cve-poc](https://github.com/qazbnm456/awesome-cve-poc) CVE PoC列表 +- [**1996**星][29d] [Java] [elderdrivers/edxposed](https://github.com/elderdrivers/edxposed) Elder driver Xposed Framework. +- [**1994**星][7m] [Py] [fsecurelabs/drozer](https://github.com/FSecureLABS/drozer) The Leading Security Assessment Framework for Android. +- [**1994**星][3m] [infosecn1nja/ad-attack-defense](https://github.com/infosecn1nja/ad-attack-defense) Attack and defend active directory using modern post exploitation adversary tradecraft activity +- [**1994**星][27d] [Swift] [github/softu2f](https://github.com/github/softu2f) Software U2F authenticator for macOS +- [**1992**星][5d] [C#] [mathewsachin/captura](https://github.com/mathewsachin/captura) Capture Screen, Audio, Cursor, Mouse Clicks and Keystrokes +- [**1990**星][8d] [HTML] [gtfobins/gtfobins.github.io](https://github.com/gtfobins/gtfobins.github.io) Curated list of Unix binaries that can be exploited to bypass system security restrictions +- [**1989**星][4y] [Go] [yahoo/gryffin](https://github.com/yahoo/gryffin) Gryffin is a large scale web security scanning platform. +- [**1989**星][2m] [C++] [asmjit/asmjit](https://github.com/asmjit/asmjit) Complete x86/x64 JIT and AOT Assembler for C++ +- [**1987**星][2y] [dloss/python-pentest-tools](https://github.com/dloss/python-pentest-tools) 可用于渗透测试的Python工具收集 +- [**1977**星][5d] [Go] [projectdiscovery/subfinder](https://github.com/projectdiscovery/subfinder) Subfinder is a subdomain discovery tool that discovers valid subdomains for websites. Designed as a passive framework to be useful for bug bounties and safe for penetration testing. +- [**1977**星][5d] [Go] [projectdiscovery/subfinder](https://github.com/projectdiscovery/subfinder) 使用Passive Sources, Search Engines, Pastebins, Internet Archives等查找子域名 +- [**1972**星][1m] [Py] [momosecurity/aswan](https://github.com/momosecurity/aswan) 陌陌风控系统静态规则引擎,零基础简易便捷的配置多种复杂规则,实时高效管控用户异常行为。 +- [**1971**星][5d] [Py] [j3ssie/osmedeus](https://github.com/j3ssie/osmedeus) Fully automated offensive security framework for reconnaissance and vulnerability scanning +- [**1966**星][11d] [Go] [ullaakut/cameradar](https://github.com/Ullaakut/cameradar) Cameradar hacks its way into RTSP videosurveillance cameras +- [**1966**星][9m] [JS] [weichiachang/stacks-cli](https://github.com/weichiachang/stacks-cli) Check website stack from the terminal +- [**1966**星][1y] [BitBake] [1n3/intruderpayloads](https://github.com/1n3/intruderpayloads) A collection of Burpsuite Intruder payloads, BurpBounty payloads, fuzz lists, malicious file uploads and web pentesting methodologies and checklists. +- [**1955**星][7d] [Perl] [spiderlabs/owasp-modsecurity-crs](https://github.com/spiderlabs/owasp-modsecurity-crs) OWASP ModSecurity Core Rule Set (CRS) Project (Official Repository) +- [**1953**星][2y] [obfuscator-llvm/obfuscator](https://github.com/obfuscator-llvm/obfuscator) Obfuscator-LLVM +- [**1952**星][1y] [Go] [hyperhq/hyperd](https://github.com/hyperhq/hyperd) HyperContainer Daemon +- [**1951**星][8d] [Py] [cea-sec/miasm](https://github.com/cea-sec/miasm) Reverse engineering framework in Python +- [**1947**星][29d] [Py] [nixawk/pentest-wiki](https://github.com/nixawk/pentest-wiki) PENTEST-WIKI is a free online security knowledge library for pentesters / researchers. If you have a good idea, please share it with others. +- [**1945**星][5d] [C] [microsoft/procdump-for-linux](https://github.com/microsoft/procdump-for-linux) Linux 版本的 ProcDump +- [**1942**星][3y] [C#] [lazocoder/windows-hacks](https://github.com/lazocoder/windows-hacks) Creative and unusual things that can be done with the Windows API. +- [**1938**星][4m] [C] [meituan-dianping/logan](https://github.com/meituan-dianping/logan) Logan is a lightweight case logging system based on mobile platform. +- [**1938**星][7d] [Go] [zalando/skipper](https://github.com/zalando/skipper) An HTTP router and reverse proxy for service composition, including use cases like Kubernetes Ingress +- [**1935**星][19d] [Go] [mpolden/echoip](https://github.com/mpolden/echoip) IP address lookup service +- [**1933**星][5m] [C] [darkk/redsocks](https://github.com/darkk/redsocks) transparent TCP-to-proxy redirector +- [**1923**星][3y] [Py] [aoncyberlabs/windows-exploit-suggester](https://github.com/AonCyberLabs/Windows-Exploit-Suggester) This tool compares a targets patch levels against the Microsoft vulnerability database in order to detect potential missing patches on the target. It also notifies the user if there are public exploits and Metasploit modules available for the missing bulletins. +- [**1920**星][4y] [Py] [ziggear/shadowsocks](https://github.com/ziggear/shadowsocks) backup of +- [**1920**星][2d] [C++] [powerdns/pdns](https://github.com/powerdns/pdns) PowerDNS +- [**1920**星][9d] [CSS] [cyb3rward0g/helk](https://github.com/cyb3rward0g/helk) 对ELK栈进行分析,具备多种高级功能,例如SQL声明性语言,图形,结构化流,机器学习等 +- [**1918**星][3m] [toolswatch/blackhat-arsenal-tools](https://github.com/toolswatch/blackhat-arsenal-tools) Black Hat 武器库 +- [**1917**星][2d] [C] [ntop/ndpi](https://github.com/ntop/ndpi) Open Source Deep Packet Inspection Software Toolkit +- [**1915**星][18d] [Py] [lanjelot/patator](https://github.com/lanjelot/patator) Patator is a multi-purpose brute-forcer, with a modular design and a flexible usage. +- [**1914**星][7d] [Go] [solo-io/gloo](https://github.com/solo-io/gloo) An Envoy-Powered API Gateway +- [**1914**星][2d] [chaitin/xray](https://github.com/chaitin/xray) xray 安全评估工具 | 使用之前务必先阅读文档 +- [**1903**星][3m] [Go] [minishift/minishift](https://github.com/minishift/minishift) Run OpenShift 3.x locally +- [**1901**星][9d] [C] [chipsec/chipsec](https://github.com/chipsec/chipsec) 分析PC平台的安全性, 包括硬件、系统固件(BIOS/UEFI)和平台组件 +- [**1900**星][1y] [Py] [derv82/wifite2](https://github.com/derv82/wifite2) 无线网络审计工具wifite 的升级版/重制版 +- [**1898**星][3d] [C++] [mhammond/pywin32](https://github.com/mhammond/pywin32) Python for Windows (pywin32) Extensions +- [**1896**星][7d] [Shell] [toniblyx/prowler](https://github.com/toniblyx/prowler) AWS Security Best Practices Assessment, Auditing, Hardening and Forensics Readiness Tool. It follows guidelines of the CIS Amazon Web Services Foundations Benchmark and DOZENS of additional checks including GDPR and HIPAA (+100). Official CIS for AWS guide: +- [**1893**星][6d] [Py] [mozilla/mozdef](https://github.com/mozilla/mozdef) Mozilla Enterprise Defense Platform +- [**1893**星][6m] [Java] [fuzion24/justtrustme](https://github.com/fuzion24/justtrustme) An xposed module that disables SSL certificate checking for the purposes of auditing an app with cert pinning +- [**1886**星][4m] [C] [shadowsocks/simple-obfs](https://github.com/shadowsocks/simple-obfs) A simple obfuscating tool (Deprecated) +- [**1884**星][1y] [Py] [aploium/zmirror](https://github.com/aploium/zmirror) The next-gen reverse proxy for full site mirroring +- [**1880**星][4m] [Py] [python-security/pyt](https://github.com/python-security/pyt) Python Web App 安全漏洞检测和静态分析工具 +- [**1878**星][16d] [YARA] [yara-rules/rules](https://github.com/yara-rules/rules) Repository of yara rules +- [**1878**星][5y] [C++] [tum-vision/lsd_slam](https://github.com/tum-vision/lsd_slam) LSD-SLAM +- [**1878**星][2m] [Py] [pycqa/bandit](https://github.com/pycqa/bandit) 在Python代码中查找常见的安全问题 +- [**1877**星][2d] [C] [merbanan/rtl_433](https://github.com/merbanan/rtl_433) Program to decode traffic from Devices that are broadcasting on 433.9 MHz like temperature sensors +- [**1876**星][9d] [olivierlaflamme/cheatsheet-god](https://github.com/olivierlaflamme/cheatsheet-god) Penetration Testing Reference Bank - OSCP / PTP & PTX Cheatsheet +- [**1876**星][27d] [hmaverickadams/beginner-network-pentesting](https://github.com/hmaverickadams/beginner-network-pentesting) Notes for Beginner Network Pentesting Course +- [**1873**星][12d] [Py] [aquasecurity/kube-hunter](https://github.com/aquasecurity/kube-hunter) Hunt for security weaknesses in Kubernetes clusters +- [**1870**星][5d] [C#] [hmbsbige/shadowsocksr-windows](https://github.com/hmbsbige/shadowsocksr-windows) 【自用】Bug-Oriented Programming +- [**1869**星][6d] [Java] [adoptopenjdk/jitwatch](https://github.com/adoptopenjdk/jitwatch) Log analyser / visualiser for Java HotSpot JIT compiler. Inspect inlining decisions, hot methods, bytecode, and assembly. View results in the JavaFX user interface. +- [**1865**星][6d] [C++] [acidanthera/lilu](https://github.com/acidanthera/Lilu) Arbitrary kext and process patching on macOS +- [**1865**星][10m] [PHP] [bartblaze/php-backdoors](https://github.com/bartblaze/php-backdoors) A collection of PHP backdoors. For educational or testing purposes only. +- [**1864**星][23d] [C] [tinyproxy/tinyproxy](https://github.com/tinyproxy/tinyproxy) a light-weight HTTP/HTTPS proxy daemon for POSIX operating systems +- [**1862**星][4y] [ObjC] [xcodeghostsource/xcodeghost](https://github.com/xcodeghostsource/xcodeghost) "XcodeGhost" Source +- [**1860**星][9d] [Lua] [vulnerscom/nmap-vulners](https://github.com/vulnerscom/nmap-vulners) NSE script based on Vulners.com API +- [**1857**星][5m] [bypass007/emergency-response-notes](https://github.com/bypass007/emergency-response-notes) 应急响应实战笔记,一个安全工程师的自我修养。 +- [**1855**星][2m] [Py] [pwnlandia/mhn](https://github.com/pwnlandia/mhn) 蜜罐网络 +- [**1854**星][5d] [TS] [snyk/snyk](https://github.com/snyk/snyk) CLI and build-time tool to find & fix known vulnerabilities in open-source dependencies +- [**1854**星][11m] [C++] [googlecreativelab/open-nsynth-super](https://github.com/googlecreativelab/open-nsynth-super) Open NSynth Super is an experimental physical interface for the NSynth algorithm +- [**1853**星][2d] [Py] [bregman-arie/devops-interview-questions](https://github.com/bregman-arie/devops-interview-questions) Linux, Jenkins, AWS, SRE, Prometheus, Docker, Python, Ansible, Git, Kubernetes, Terraform, OpenStack, SQL, NoSQL, Azure, GCP, DNS, Elastic +- [**1853**星][4m] [Shell] [arismelachroinos/lscript](https://github.com/arismelachroinos/lscript) 自动化无线渗透和Hacking 任务的脚本 +- [**1852**星][3d] [C] [github/glb-director](https://github.com/github/glb-director) GitHub Load Balancer Director and supporting tooling. +- [**1851**星][1y] [Java] [jindrapetrik/jpexs-decompiler](https://github.com/jindrapetrik/jpexs-decompiler) JPEXS Free Flash Decompiler +- [**1848**星][6m] [Assembly] [pooler/cpuminer](https://github.com/pooler/cpuminer) cpuminer:莱特币和比特币的多线程 CPU 矿机 +- [**1847**星][8m] [Py] [netflix-skunkworks/stethoscope](https://github.com/Netflix-Skunkworks/stethoscope) Personalized, user-focused recommendations for employee information security. +- [**1842**星][1m] [Jupyter Notebook] [hunters-forge/threathunter-playbook](https://github.com/hunters-forge/ThreatHunter-Playbook) A Threat hunter's playbook to aid the development of techniques and hypothesis for hunting campaigns. +- [**1842**星][1y] [Java] [yeriomin/yalpstore](https://github.com/yeriomin/yalpstore) Download apks from Google Play Store +- [**1842**星][2d] [C++] [pytorch/glow](https://github.com/pytorch/glow) Compiler for Neural Network hardware accelerators - [**1841**星][2m] [C] [retroplasma/earth-reverse-engineering](https://github.com/retroplasma/earth-reverse-engineering) Reversing Google's 3D satellite mode -- [**1839**星][4m] [bypass007/emergency-response-notes](https://github.com/bypass007/emergency-response-notes) 应急响应实战笔记,一个安全工程师的自我修养。 -- [**1837**星][4m] [Lua] [vulnerscom/nmap-vulners](https://github.com/vulnerscom/nmap-vulners) NSE script based on Vulners.com API -- [**1836**星][3y] [Java] [chora10/cknife](https://github.com/chora10/cknife) Cknife -- [**1835**星][1y] [Java] [yeriomin/yalpstore](https://github.com/yeriomin/yalpstore) Download apks from Google Play Store -- [**1833**星][25d] [hmaverickadams/beginner-network-pentesting](https://github.com/hmaverickadams/beginner-network-pentesting) Notes for Beginner Network Pentesting Course -- [**1832**星][4m] [Shell] [arismelachroinos/lscript](https://github.com/arismelachroinos/lscript) 自动化无线渗透和Hacking 任务的脚本 -- [**1830**星][7d] [C++] [pytorch/glow](https://github.com/pytorch/glow) Compiler for Neural Network hardware accelerators -- [**1829**星][1y] [Py] [jinnlynn/genpac](https://github.com/jinnlynn/genpac) PAC/Dnsmasq/Wingy file Generator, working with gfwlist, support custom rules. -- [**1827**星][1m] [Jupyter Notebook] [hunters-forge/threathunter-playbook](https://github.com/hunters-forge/ThreatHunter-Playbook) A Threat hunter's playbook to aid the development of techniques and hypothesis for hunting campaigns. -- [**1827**星][2m] [Go] [influxdata/kapacitor](https://github.com/influxdata/kapacitor) Open source framework for processing, monitoring, and alerting on time series data -- [**1827**星][1y] [CSS] [ctfs/write-ups-2015](https://github.com/ctfs/write-ups-2015) Wiki-like CTF write-ups repository, maintained by the community. 2015 -- [**1819**星][13d] [Py] [trailofbits/manticore](https://github.com/trailofbits/manticore) 动态二进制分析工具,支持符号执行(symbolic execution)、污点分析(taint analysis)、运行时修改。 -- [**1816**星][19d] [C] [mgba-emu/mgba](https://github.com/mgba-emu/mgba) mGBA Game Boy Advance Emulator -- [**1814**星][7d] [Py] [bregman-arie/devops-interview-questions](https://github.com/bregman-arie/devops-interview-questions) Linux, Jenkins, AWS, SRE, Prometheus, Docker, Python, Ansible, Git, Kubernetes, Terraform, OpenStack, SQL, NoSQL, Azure, GCP, DNS, Elastic -- [**1808**星][6m] [C++] [iagox86/dnscat2](https://github.com/iagox86/dnscat2) 在 DNS 协议上创建加密的 C&C channel -- [**1806**星][5m] [Py] [veil-framework/veil](https://github.com/veil-framework/veil) generate metasploit payloads that bypass common anti-virus solutions -- [**1801**星][3y] [Objective-C] [kpwn/yalu102](https://github.com/kpwn/yalu102) incomplete iOS 10.2 jailbreak for 64 bit devices by qwertyoruiopz and marcograssi -- [**1801**星][2m] [djadmin/awesome-bug-bounty](https://github.com/djadmin/awesome-bug-bounty) A comprehensive curated list of available Bug Bounty & Disclosure Programs and Write-ups. -- [**1788**星][28d] [Go] [gdamore/tcell](https://github.com/gdamore/tcell) Tcell is an alternate terminal package, similar in some ways to termbox, but better in others. -- [**1785**星][11m] [Py] [ctfs/write-ups-2017](https://github.com/ctfs/write-ups-2017) Wiki-like CTF write-ups repository, maintained by the community. 2017 -- [**1784**星][7d] [C#] [hmbsbige/shadowsocksr-windows](https://github.com/hmbsbige/shadowsocksr-windows) 【自用】Bug-Oriented Programming -- [**1783**星][7m] [Py] [lijiejie/subdomainsbrute](https://github.com/lijiejie/subdomainsbrute) 子域名爆破 -- [**1777**星][18d] [PHP] [ezyang/htmlpurifier](https://github.com/ezyang/htmlpurifier) Standards compliant HTML filter written in PHP -- [**1776**星][13d] [C++] [apitrace/apitrace](https://github.com/apitrace/apitrace) Tools for tracing OpenGL, Direct3D, and other graphics APIs -- [**1775**星][4y] [caesar0301/awesome-pcaptools](https://github.com/caesar0301/awesome-pcaptools) A collection of tools developed by other researchers in the Computer Science area to process network traces. All the right reserved for the original authors. -- [**1774**星][1y] [aozhimin/ios-monitor-platform](https://github.com/aozhimin/ios-monitor-platform) -- [**1770**星][3y] [Objective-C] [alibaba/wax](https://github.com/alibaba/wax) Wax is a framework that lets you write native iPhone apps in Lua. -- [**1768**星][13d] [Shell] [leebaird/discover](https://github.com/leebaird/discover) 自定义的bash脚本, 用于自动化多个渗透测试任务, 包括: 侦查、扫描、解析、在Metasploit中创建恶意Payload和Listener -- [**1764**星][3m] [Py] [epinna/weevely3](https://github.com/epinna/weevely3) Weaponized web shell -- [**1759**星][12d] [C] [google/wuffs](https://github.com/google/wuffs) Wrangling Untrusted File Formats Safely -- [**1757**星][7m] [C++] [wrbug/dumpdex](https://github.com/wrbug/dumpdex) Android脱壳 -- [**1757**星][2y] [CSS] [b374k/b374k](https://github.com/b374k/b374k) PHP Webshell with handy features -- [**1749**星][2m] [onethawt/idaplugins-list](https://github.com/onethawt/idaplugins-list) IDA插件收集 -- [**1747**星][8d] [17mon/china_ip_list](https://github.com/17mon/china_ip_list) -- [**1743**星][12m] [JS] [puppeteer/examples](https://github.com/puppeteer/examples) Use case-driven examples for using Puppeteer and headless chrome -- [**1740**星][8d] [PHP] [wordpress/wordpress-coding-standards](https://github.com/wordpress/wordpress-coding-standards) PHP_CodeSniffer rules (sniffs) to enforce WordPress coding conventions +- [**1839**星][3y] [Java] [chora10/cknife](https://github.com/chora10/cknife) Cknife +- [**1838**星][1y] [Py] [jinnlynn/genpac](https://github.com/jinnlynn/genpac) PAC/Dnsmasq/Wingy file Generator, working with gfwlist, support custom rules. +- [**1830**星][2m] [Go] [influxdata/kapacitor](https://github.com/influxdata/kapacitor) Open source framework for processing, monitoring, and alerting on time series data +- [**1828**星][3m] [JS] [coreybutler/node-windows](https://github.com/coreybutler/node-windows) Windows support for Node.JS scripts (daemons, eventlog, UAC, etc). +- [**1828**星][1y] [CSS] [ctfs/write-ups-2015](https://github.com/ctfs/write-ups-2015) Wiki-like CTF write-ups repository, maintained by the community. 2015 +- [**1824**星][5d] [Py] [trailofbits/manticore](https://github.com/trailofbits/manticore) 动态二进制分析工具,支持符号执行(symbolic execution)、污点分析(taint analysis)、运行时修改。 +- [**1819**星][6d] [C] [mgba-emu/mgba](https://github.com/mgba-emu/mgba) mGBA Game Boy Advance Emulator +- [**1818**星][2m] [djadmin/awesome-bug-bounty](https://github.com/djadmin/awesome-bug-bounty) A comprehensive curated list of available Bug Bounty & Disclosure Programs and Write-ups. +- [**1815**星][5m] [Py] [veil-framework/veil](https://github.com/veil-framework/veil) generate metasploit payloads that bypass common anti-virus solutions +- [**1814**星][6m] [C++] [iagox86/dnscat2](https://github.com/iagox86/dnscat2) 在 DNS 协议上创建加密的 C&C channel +- [**1804**星][10d] [Go] [gdamore/tcell](https://github.com/gdamore/tcell) Tcell is an alternate terminal package, similar in some ways to termbox, but better in others. +- [**1801**星][12m] [Go] [intelsdi-x/snap](https://github.com/intelsdi-x/snap) an open telemetry framework designed to simplify the collection, processing and publishing of system data through a single API. +- [**1800**星][3y] [ObjC] [kpwn/yalu102](https://github.com/kpwn/yalu102) incomplete iOS 10.2 jailbreak for 64 bit devices by qwertyoruiopz and marcograssi +- [**1795**星][7m] [Py] [lijiejie/subdomainsbrute](https://github.com/lijiejie/subdomainsbrute) 子域名爆破 +- [**1790**星][12m] [Py] [ctfs/write-ups-2017](https://github.com/ctfs/write-ups-2017) Wiki-like CTF write-ups repository, maintained by the community. 2017 +- [**1785**星][1y] [aozhimin/ios-monitor-platform](https://github.com/aozhimin/ios-monitor-platform) +- [**1784**星][16d] [Shell] [pirate/wireguard-docs](https://github.com/pirate/wireguard-docs) +- [**1781**星][15d] [Shell] [leebaird/discover](https://github.com/leebaird/discover) 自定义的bash脚本, 用于自动化多个渗透测试任务, 包括: 侦查、扫描、解析、在Metasploit中创建恶意Payload和Listener +- [**1779**星][4y] [caesar0301/awesome-pcaptools](https://github.com/caesar0301/awesome-pcaptools) A collection of tools developed by other researchers in the Computer Science area to process network traces. All the right reserved for the original authors. +- [**1778**星][15d] [C++] [apitrace/apitrace](https://github.com/apitrace/apitrace) Tools for tracing OpenGL, Direct3D, and other graphics APIs +- [**1777**星][7m] [C++] [wrbug/dumpdex](https://github.com/wrbug/dumpdex) Android脱壳 +- [**1777**星][7d] [PHP] [ezyang/htmlpurifier](https://github.com/ezyang/htmlpurifier) Standards compliant HTML filter written in PHP +- [**1777**星][5d] [Go] [convox/rack](https://github.com/convox/rack) Private PaaS built on native AWS services for maximum privacy and minimum upkeep +- [**1774**星][3y] [ObjC] [tapwork/heapinspector-for-ios](https://github.com/tapwork/heapinspector-for-ios) Find memory issues & leaks in your iOS app without instruments +- [**1774**星][3m] [Py] [epinna/weevely3](https://github.com/epinna/weevely3) Weaponized web shell +- [**1772**星][2y] [JS] [cazala/coin-hive](https://github.com/cazala/coin-hive) CoinHive cryptocurrency miner for node.js +- [**1770**星][3y] [ObjC] [alibaba/wax](https://github.com/alibaba/wax) Wax is a framework that lets you write native iPhone apps in Lua. +- [**1761**星][6d] [C] [google/wuffs](https://github.com/google/wuffs) Wrangling Untrusted File Formats Safely +- [**1761**星][2y] [CSS] [b374k/b374k](https://github.com/b374k/b374k) PHP Webshell with handy features +- [**1760**星][3y] [Go] [elastic/logstash-forwarder](https://github.com/elastic/logstash-forwarder) An experiment to cut logs in preparation for processing elsewhere. Replaced by Filebeat: +- [**1758**星][12m] [JS] [puppeteer/examples](https://github.com/puppeteer/examples) Use case-driven examples for using Puppeteer and headless chrome +- [**1756**星][10d] [17mon/china_ip_list](https://github.com/17mon/china_ip_list) +- [**1754**星][2m] [onethawt/idaplugins-list](https://github.com/onethawt/idaplugins-list) IDA插件收集 +- [**1747**星][2d] [PHP] [wordpress/wordpress-coding-standards](https://github.com/wordpress/wordpress-coding-standards) PHP_CodeSniffer rules (sniffs) to enforce WordPress coding conventions +- [**1745**星][1y] [PS] [fuzzysecurity/powershell-suite](https://github.com/fuzzysecurity/powershell-suite) My musings with PowerShell +- [**1744**星][1y] [coreb1t/awesome-pentest-cheat-sheets](https://github.com/coreb1t/awesome-pentest-cheat-sheets) Collection of the cheat sheets useful for pentesting +- [**1742**星][3m] [tunz/js-vuln-db](https://github.com/tunz/js-vuln-db) A collection of JavaScript engine CVEs with PoCs +- [**1739**星][21d] [ngalongc/bug-bounty-reference](https://github.com/ngalongc/bug-bounty-reference) Inspired by - [**1738**星][2y] [Go] [vzex/dog-tunnel](https://github.com/vzex/dog-tunnel) p2p tunnel,(udp mode work with kcp, -- [**1734**星][3m] [tunz/js-vuln-db](https://github.com/tunz/js-vuln-db) A collection of JavaScript engine CVEs with PoCs -- [**1732**星][1y] [coreb1t/awesome-pentest-cheat-sheets](https://github.com/coreb1t/awesome-pentest-cheat-sheets) Collection of the cheat sheets useful for pentesting -- [**1727**星][2m] [PHP] [orangetw/my-ctf-web-challenges](https://github.com/orangetw/my-ctf-web-challenges) Collection of CTF Web challenges I made -- [**1726**星][3y] [Go] [s-rah/onionscan](https://github.com/s-rah/onionscan) OnionScan is a free and open source tool for investigating the Dark Web. -- [**1723**星][6m] [Smali] [ahmyth/ahmyth-android-rat](https://github.com/ahmyth/ahmyth-android-rat) Android Remote Administration Tool -- [**1722**星][1y] [PowerShell] [fuzzysecurity/powershell-suite](https://github.com/fuzzysecurity/powershell-suite) My musings with PowerShell -- [**1720**星][19d] [ngalongc/bug-bounty-reference](https://github.com/ngalongc/bug-bounty-reference) Inspired by -- [**1718**星][1m] [PowerShell] [fireeye/flare-vm](https://github.com/fireeye/flare-vm) 火眼发布用于 Windows 恶意代码分析的虚拟机:FLARE VM -- [**1717**星][7d] [C] [google/honggfuzz](https://github.com/google/honggfuzz) Security oriented fuzzer with powerful analysis options. Supports evolutionary, feedback-driven fuzzing based on code coverage (software- and hardware-based) -- [**1714**星][2m] [Go] [subfinder/subfinder](https://github.com/subfinder/subfinder) 使用Passive Sources, Search Engines, Pastebins, Internet Archives等查找子域名 -- [**1709**星][9m] [Py] [constverum/proxybroker](https://github.com/constverum/proxybroker) Proxy [Finder | Checker | Server]. HTTP(S) & SOCKS -- [**1708**星][10d] [Ruby] [cliffe/secgen](https://github.com/cliffe/secgen) Create randomly insecure VMs -- [**1705**星][4m] [Py] [lgandx/responder](https://github.com/lgandx/responder) Responder is a LLMNR, NBT-NS and MDNS poisoner, with built-in HTTP/SMB/MSSQL/FTP/LDAP rogue authentication server supporting NTLMv1/NTLMv2/LMv2, Extended Security NTLMSSP and Basic HTTP authentication. -- [**1702**星][1y] [Java] [ac-pm/inspeckage](https://github.com/ac-pm/inspeckage) Android Package Inspector - dynamic analysis with api hooks, start unexported activities and more. (Xposed Module) -- [**1695**星][1m] [Go] [eth0izzle/shhgit](https://github.com/eth0izzle/shhgit) 监听Github Event API,实时查找Github代码和Gist中的secret和敏感文件 -- [**1694**星][3m] [PHP] [xtr4nge/fruitywifi](https://github.com/xtr4nge/fruitywifi) FruityWiFi is a wireless network auditing tool. The application can be installed in any Debian based system (Jessie) adding the extra packages. Tested in Debian, Kali Linux, Kali Linux ARM (Raspberry Pi), Raspbian (Raspberry Pi), Pwnpi (Raspberry Pi), Bugtraq, NetHunter. -- [**1694**星][3y] [CoffeeScript] [okturtles/dnschain](https://github.com/okturtles/dnschain) A blockchain-based DNS + HTTP server that fixes HTTPS security, and more! -- [**1694**星][1y] [Swift] [haxpor/potatso](https://github.com/haxpor/potatso) Potatso is an iOS client that implements Shadowsocks proxy with the leverage of NetworkExtension framework. ***This project is unmaintained, try taking a look at this fork -- [**1694**星][14d] [Go] [hashicorp/memberlist](https://github.com/hashicorp/memberlist) Golang package for gossip based membership and failure detection -- [**1693**星][8m] [Py] [guelfoweb/knock](https://github.com/guelfoweb/knock) 使用 Wordlist 枚举子域名 -- [**1693**星][7d] [TSQL] [brentozarultd/sql-server-first-responder-kit](https://github.com/brentozarultd/sql-server-first-responder-kit) sp_Blitz, sp_BlitzCache, sp_BlitzFirst, sp_BlitzIndex, and other SQL Server scripts for health checks and performance tuning. -- [**1693**星][3m] [Py] [anorov/cloudflare-scrape](https://github.com/anorov/cloudflare-scrape) A Python module to bypass Cloudflare's anti-bot page. -- [**1691**星][6m] [Py] [yelp/osxcollector](https://github.com/yelp/osxcollector) A forensic evidence collection & analysis toolkit for OS X -- [**1687**星][4m] [JS] [expressjs/csurf](https://github.com/expressjs/csurf) CSRF token middleware -- [**1685**星][5m] [C] [networkprotocol/netcode.io](https://github.com/networkprotocol/netcode.io) A protocol for secure client/server connections over UDP -- [**1682**星][8m] [Makefile] [raspberrypi/noobs](https://github.com/raspberrypi/noobs) NOOBS (New Out Of Box Software) - An easy Operating System install manager for the Raspberry Pi -- [**1682**星][1y] [owasp/devguide](https://github.com/owasp/devguide) The OWASP Guide -- [**1681**星][13d] [HTML] [chromium/badssl.com](https://github.com/chromium/badssl.com) -- [**1681**星][9m] [CSS] [bagder/http2-explained](https://github.com/bagder/http2-explained) A detailed document explaining and documenting HTTP/2, the successor to the widely popular HTTP/1.1 protocol -- [**1676**星][28d] [Swift] [pmusolino/wormholy](https://github.com/pmusolino/wormholy) iOS network debugging, like a wizard 🧙‍♂️ -- [**1675**星][4m] [R] [briatte/awesome-network-analysis](https://github.com/briatte/awesome-network-analysis) A curated list of awesome network analysis resources. -- [**1674**星][2m] [Py] [rootm0s/winpwnage](https://github.com/rootm0s/winpwnage) UAC bypass, Elevate, Persistence and Execution methods -- [**1668**星][7m] [C++] [yegord/snowman](https://github.com/yegord/snowman) Snowman反编译器,支持x86, AMD64, ARM。有独立的GUI工具、命令行工具、IDA/Radare2/x64dbg插件,也可以作为库使用 +- [**1735**星][2m] [PHP] [orangetw/my-ctf-web-challenges](https://github.com/orangetw/my-ctf-web-challenges) Collection of CTF Web challenges I made +- [**1731**星][1m] [PS] [fireeye/flare-vm](https://github.com/fireeye/flare-vm) 火眼发布用于 Windows 恶意代码分析的虚拟机:FLARE VM +- [**1730**星][3y] [Go] [s-rah/onionscan](https://github.com/s-rah/onionscan) OnionScan is a free and open source tool for investigating the Dark Web. +- [**1730**星][6m] [Smali] [ahmyth/ahmyth-android-rat](https://github.com/ahmyth/ahmyth-android-rat) Android Remote Administration Tool +- [**1723**星][14d] [selierlin/share-ssr-v2ray](https://github.com/selierlin/share-ssr-v2ray) +- [**1719**星][4d] [C] [google/honggfuzz](https://github.com/google/honggfuzz) Security oriented fuzzer with powerful analysis options. Supports evolutionary, feedback-driven fuzzing based on code coverage (software- and hardware-based) +- [**1718**星][9m] [Py] [constverum/proxybroker](https://github.com/constverum/proxybroker) Proxy [Finder | Checker | Server]. HTTP(S) & SOCKS +- [**1717**星][4m] [Py] [lgandx/responder](https://github.com/lgandx/responder) Responder is a LLMNR, NBT-NS and MDNS poisoner, with built-in HTTP/SMB/MSSQL/FTP/LDAP rogue authentication server supporting NTLMv1/NTLMv2/LMv2, Extended Security NTLMSSP and Basic HTTP authentication. +- [**1714**星][5d] [Ruby] [cliffe/secgen](https://github.com/cliffe/secgen) Create randomly insecure VMs +- [**1710**星][1m] [Go] [eth0izzle/shhgit](https://github.com/eth0izzle/shhgit) 监听Github Event API,实时查找Github代码和Gist中的secret和敏感文件 +- [**1709**星][3m] [Py] [anorov/cloudflare-scrape](https://github.com/anorov/cloudflare-scrape) A Python module to bypass Cloudflare's anti-bot page. +- [**1709**星][1y] [Java] [ac-pm/inspeckage](https://github.com/ac-pm/inspeckage) Android Package Inspector - dynamic analysis with api hooks, start unexported activities and more. (Xposed Module) +- [**1707**星][3d] [TSQL] [brentozarultd/sql-server-first-responder-kit](https://github.com/brentozarultd/sql-server-first-responder-kit) sp_Blitz, sp_BlitzCache, sp_BlitzFirst, sp_BlitzIndex, and other SQL Server scripts for health checks and performance tuning. +- [**1706**星][16d] [Go] [hashicorp/memberlist](https://github.com/hashicorp/memberlist) Golang package for gossip based membership and failure detection +- [**1700**星][8m] [Py] [guelfoweb/knock](https://github.com/guelfoweb/knock) 使用 Wordlist 枚举子域名 +- [**1697**星][9m] [CSS] [bagder/http2-explained](https://github.com/bagder/http2-explained) A detailed document explaining and documenting HTTP/2, the successor to the widely popular HTTP/1.1 protocol +- [**1696**星][3m] [PHP] [xtr4nge/fruitywifi](https://github.com/xtr4nge/fruitywifi) FruityWiFi is a wireless network auditing tool. The application can be installed in any Debian based system (Jessie) adding the extra packages. Tested in Debian, Kali Linux, Kali Linux ARM (Raspberry Pi), Raspbian (Raspberry Pi), Pwnpi (Raspberry Pi), Bugtraq, NetHunter. +- [**1696**星][1y] [Swift] [haxpor/potatso](https://github.com/haxpor/potatso) Potatso is an iOS client that implements Shadowsocks proxy with the leverage of NetworkExtension framework. ***This project is unmaintained, try taking a look at this fork +- [**1695**星][6m] [Py] [yelp/osxcollector](https://github.com/yelp/osxcollector) A forensic evidence collection & analysis toolkit for OS X +- [**1695**星][3y] [CoffeeScript] [okturtles/dnschain](https://github.com/okturtles/dnschain) A blockchain-based DNS + HTTP server that fixes HTTPS security, and more! +- [**1689**星][5m] [C] [networkprotocol/netcode.io](https://github.com/networkprotocol/netcode.io) A protocol for secure client/server connections over UDP +- [**1687**星][5m] [JS] [expressjs/csurf](https://github.com/expressjs/csurf) CSRF token middleware +- [**1687**星][15d] [HTML] [chromium/badssl.com](https://github.com/chromium/badssl.com) +- [**1686**星][8m] [Makefile] [raspberrypi/noobs](https://github.com/raspberrypi/noobs) NOOBS (New Out Of Box Software) - An easy Operating System install manager for the Raspberry Pi +- [**1685**星][4m] [R] [briatte/awesome-network-analysis](https://github.com/briatte/awesome-network-analysis) A curated list of awesome network analysis resources. +- [**1683**星][1y] [owasp/devguide](https://github.com/owasp/devguide) The OWASP Guide +- [**1682**星][3m] [Py] [rootm0s/winpwnage](https://github.com/rootm0s/winpwnage) UAC bypass, Elevate, Persistence and Execution methods +- [**1677**星][30d] [Swift] [pmusolino/wormholy](https://github.com/pmusolino/wormholy) iOS network debugging, like a wizard 🧙‍♂️ +- [**1674**星][2d] [C++] [microsoft/detours](https://github.com/microsoft/detours) Detours is a software package for monitoring and instrumenting API calls on Windows. It is distributed in source code form. +- [**1671**星][7m] [C++] [yegord/snowman](https://github.com/yegord/snowman) Snowman反编译器,支持x86, AMD64, ARM。有独立的GUI工具、命令行工具、IDA/Radare2/x64dbg插件,也可以作为库使用 - [IDA插件](https://github.com/yegord/snowman/tree/master/src/ida-plugin) - [snowman](https://github.com/yegord/snowman/tree/master/src/snowman) QT界面 - [nocode](https://github.com/yegord/snowman/tree/master/src/nocode) 命令行工具 - [nc](https://github.com/yegord/snowman/tree/master/src/nc) 核心代码,可作为库使用 -- [**1665**星][6m] [C++] [microsoft/detours](https://github.com/microsoft/detours) Detours is a software package for monitoring and instrumenting API calls on Windows. It is distributed in source code form. -- [**1662**星][12d] [selierlin/share-ssr-v2ray](https://github.com/selierlin/share-ssr-v2ray) -- [**1662**星][4y] [Java] [dodola/hotfix](https://github.com/dodola/hotfix) 安卓App热补丁动态修复框架 -- [**1659**星][7d] [Java] [apache/geode](https://github.com/apache/geode) Apache Geode -- [**1655**星][6m] [C] [easyhook/easyhook](https://github.com/easyhook/easyhook) The reinvention of Windows API Hooking -- [**1654**星][3m] [JS] [tylerbrock/mongo-hacker](https://github.com/tylerbrock/mongo-hacker) MongoDB Shell Enhancements for Hackers -- [**1653**星][2m] [NSIS] [angryip/ipscan](https://github.com/angryip/ipscan) Angry IP Scanner - fast and friendly network scanner -- [**1651**星][7d] [Py] [cea-sec/ivre](https://github.com/cea-sec/ivre) Network recon framework. -- [**1650**星][2y] [Shell] [juude/droidreverse](https://github.com/juude/droidreverse) android 逆向工程工具集 -- [**1649**星][10m] [JS] [evilcos/xssor2](https://github.com/evilcos/xssor2) XSS'OR - Hack with JavaScript. -- [**1647**星][3m] [Py] [boppreh/keyboard](https://github.com/boppreh/keyboard) Hook and simulate global keyboard events on Windows and Linux. -- [**1646**星][8d] [roave/securityadvisories](https://github.com/roave/securityadvisories) ensures that your application doesn't have installed dependencies with known security vulnerabilities -- [**1646**星][8d] [JS] [ghacksuserjs/ghacks-user.js](https://github.com/ghacksuserjs/ghacks-user.js) An ongoing comprehensive user.js template for configuring and hardening Firefox privacy, security and anti-fingerprinting +- [**1668**星][2m] [NSIS] [angryip/ipscan](https://github.com/angryip/ipscan) Angry IP Scanner - fast and friendly network scanner +- [**1666**星][2d] [Java] [apache/geode](https://github.com/apache/geode) Apache Geode +- [**1663**星][4y] [Java] [dodola/hotfix](https://github.com/dodola/hotfix) 安卓App热补丁动态修复框架 +- [**1661**星][6m] [C] [easyhook/easyhook](https://github.com/easyhook/easyhook) The reinvention of Windows API Hooking +- [**1661**星][2d] [Py] [cea-sec/ivre](https://github.com/cea-sec/ivre) Network recon framework. +- [**1659**星][10d] [roave/securityadvisories](https://github.com/roave/securityadvisories) ensures that your application doesn't have installed dependencies with known security vulnerabilities +- [**1656**星][6d] [JS] [tylerbrock/mongo-hacker](https://github.com/tylerbrock/mongo-hacker) MongoDB Shell Enhancements for Hackers +- [**1655**星][3m] [Py] [boppreh/keyboard](https://github.com/boppreh/keyboard) Hook and simulate global keyboard events on Windows and Linux. +- [**1654**星][2d] [JS] [ghacksuserjs/ghacks-user.js](https://github.com/ghacksuserjs/ghacks-user.js) An ongoing comprehensive user.js template for configuring and hardening Firefox privacy, security and anti-fingerprinting +- [**1652**星][2y] [Shell] [juude/droidreverse](https://github.com/juude/droidreverse) android 逆向工程工具集 +- [**1652**星][7m] [dsasmblr/game-hacking](https://github.com/dsasmblr/game-hacking) Tutorials, tools, and more as related to reverse engineering video games. +- [**1651**星][10m] [JS] [evilcos/xssor2](https://github.com/evilcos/xssor2) XSS'OR - Hack with JavaScript. +- [**1650**星][1m] [Py] [ehco1996/django-sspanel](https://github.com/ehco1996/django-sspanel) 用diango开发的全新的shadowsocks网络面板 +- [**1650**星][7d] [HTML] [clong/detectionlab](https://github.com/clong/detectionlab) Vagrant & Packer scripts to build a lab environment complete with security tooling and logging best practices +- [**1649**星][1y] [Py] [evyatarmeged/raccoon](https://github.com/evyatarmeged/raccoon) 高性能的侦查和漏洞扫描工具 +- [**1648**星][2d] [C#] [jbevain/cecil](https://github.com/jbevain/cecil) C#库, 探查/修改/生成 .NET App/库 - [**1645**星][3y] [JS] [camwiegert/baffle](https://github.com/camwiegert/baffle) A tiny javascript library for obfuscating and revealing text in DOM elements. -- [**1643**星][1m] [C#] [jbevain/cecil](https://github.com/jbevain/cecil) C#库, 探查/修改/生成 .NET App/库 -- [**1641**星][1y] [Py] [evyatarmeged/raccoon](https://github.com/evyatarmeged/raccoon) 高性能的侦查和漏洞扫描工具 -- [**1641**星][6m] [dsasmblr/game-hacking](https://github.com/dsasmblr/game-hacking) Tutorials, tools, and more as related to reverse engineering video games. -- [**1639**星][1m] [Py] [ehco1996/django-sspanel](https://github.com/ehco1996/django-sspanel) 用diango开发的全新的shadowsocks网络面板 -- [**1637**星][13d] [HTML] [clong/detectionlab](https://github.com/clong/detectionlab) Vagrant & Packer scripts to build a lab environment complete with security tooling and logging best practices -- [**1636**星][11m] [Java] [fesh0r/fernflower](https://github.com/fesh0r/fernflower) Unofficial mirror of FernFlower Java decompiler (All pulls should be submitted upstream) -- [**1635**星][4y] [Py] [ctfs/write-ups-2014](https://github.com/ctfs/write-ups-2014) Wiki-like CTF write-ups repository, maintained by the community. 2014 -- [**1635**星][4m] [Java] [jaredrummler/androidprocesses](https://github.com/jaredrummler/androidprocesses) DEPRECATED -- [**1635**星][4y] [Py] [ctfs/write-ups-2014](https://github.com/ctfs/write-ups-2014) Wiki-like CTF write-ups repository, maintained by the community. 2014 -- [**1629**星][9m] [tylerha97/awesome-reversing](https://github.com/tylerha97/awesome-reversing) A curated list of awesome reversing resources -- [**1627**星][12d] [Go] [awnumar/memguard](https://github.com/awnumar/memguard) 处理内存中敏感的值,纯Go语言编写。 -- [**1627**星][9d] [sarojaba/awesome-devblog](https://github.com/sarojaba/awesome-devblog) 어썸데브블로그. 국내 개발 블로그 모음(only 실명으로). -- [**1620**星][14d] [JS] [efforg/privacybadger](https://github.com/efforg/privacybadger) Privacy Badger is a browser extension that automatically learns to block invisible trackers. -- [**1616**星][2y] [jhaddix/tbhm](https://github.com/jhaddix/tbhm) The Bug Hunters Methodology -- [**1614**星][2m] [Shell] [internetwache/gittools](https://github.com/internetwache/gittools) find websites with their .git repository available to the public -- [**1612**星][4m] [CSS] [functionclub/v2ray.fun](https://github.com/functionclub/v2ray.fun) 正在开发的全新 V2ray.Fun -- [**1611**星][2m] [Go] [ysrc/yulong-hids](https://github.com/ysrc/yulong-hids) 一款由 YSRC 开源的主机入侵检测系统 -- [**1610**星][7m] [Go] [sipt/shuttle](https://github.com/sipt/shuttle) A web proxy in Golang with amazing features. -- [**1608**星][2y] [JS] [addyosmani/a11y](https://github.com/addyosmani/a11y) Accessibility audit tooling for the web (beta) -- [**1607**星][3y] [Makefile] [drizzlerisk/drizzledumper](https://github.com/drizzlerisk/drizzledumper) 是一款基于内存搜索的Android脱壳工具。 -- [**1605**星][27d] [PHP] [c0ny1/upload-labs](https://github.com/c0ny1/upload-labs) 一个帮你总结所有类型的上传漏洞的靶场 -- [**1604**星][10m] [C] [nmikhailov/validity90](https://github.com/nmikhailov/validity90) Reverse engineering of Validity/Synaptics 138a:0090, 138a:0094, 138a:0097, 06cb:0081, 06cb:009a fingerprint readers protocol -- [**1602**星][1y] [Py] [nccgroup/scout2](https://github.com/nccgroup/Scout2) Security auditing tool for AWS environments +- [**1643**星][9m] [tylerha97/awesome-reversing](https://github.com/tylerha97/awesome-reversing) A curated list of awesome reversing resources +- [**1643**星][11m] [Java] [fesh0r/fernflower](https://github.com/fesh0r/fernflower) Unofficial mirror of FernFlower Java decompiler (All pulls should be submitted upstream) +- [**1638**星][4y] [Py] [ctfs/write-ups-2014](https://github.com/ctfs/write-ups-2014) Wiki-like CTF write-ups repository, maintained by the community. 2014 +- [**1638**星][11m] [C] [dlundquist/sniproxy](https://github.com/dlundquist/sniproxy) Proxies incoming HTTP and TLS connections based on the hostname contained in the initial request of the TCP session. +- [**1638**星][4y] [Py] [ctfs/write-ups-2014](https://github.com/ctfs/write-ups-2014) Wiki-like CTF write-ups repository, maintained by the community. 2014 +- [**1636**星][4m] [Java] [jaredrummler/androidprocesses](https://github.com/jaredrummler/androidprocesses) DEPRECATED +- [**1634**星][14d] [Go] [awnumar/memguard](https://github.com/awnumar/memguard) 处理内存中敏感的值,纯Go语言编写。 +- [**1631**星][6m] [Objective-C++] [tencent/oomdetector](https://github.com/tencent/oomdetector) OOMDetector is a memory monitoring component for iOS which provides you with OOM monitoring, memory allocation monitoring, memory leak detection and other functions. +- [**1630**星][6d] [JS] [efforg/privacybadger](https://github.com/efforg/privacybadger) Privacy Badger is a browser extension that automatically learns to block invisible trackers. +- [**1630**星][29d] [PHP] [c0ny1/upload-labs](https://github.com/c0ny1/upload-labs) 一个帮你总结所有类型的上传漏洞的靶场 +- [**1629**星][5d] [sarojaba/awesome-devblog](https://github.com/sarojaba/awesome-devblog) 어썸데브블로그. 국내 개발 블로그 모음(only 실명으로). +- [**1624**星][2y] [jhaddix/tbhm](https://github.com/jhaddix/tbhm) The Bug Hunters Methodology +- [**1624**星][4m] [CSS] [functionclub/v2ray.fun](https://github.com/functionclub/v2ray.fun) 正在开发的全新 V2ray.Fun +- [**1621**星][2m] [Shell] [internetwache/gittools](https://github.com/internetwache/gittools) find websites with their .git repository available to the public +- [**1618**星][28d] [Java] [tiann/epic](https://github.com/tiann/epic) Dynamic java method AOP hook for Android(continution of Dexposed on ART), Supporting 4.0~10.0 +- [**1615**星][2y] [JS] [addyosmani/a11y](https://github.com/addyosmani/a11y) Accessibility audit tooling for the web (beta) +- [**1614**星][2m] [Go] [ysrc/yulong-hids](https://github.com/ysrc/yulong-hids) 一款由 YSRC 开源的主机入侵检测系统 +- [**1614**星][7m] [Go] [sipt/shuttle](https://github.com/sipt/shuttle) A web proxy in Golang with amazing features. +- [**1612**星][3y] [Makefile] [drizzlerisk/drizzledumper](https://github.com/drizzlerisk/drizzledumper) 是一款基于内存搜索的Android脱壳工具。 +- [**1608**星][9m] [JS] [localtunnel/server](https://github.com/localtunnel/server) server for localtunnel.me +- [**1608**星][10m] [C] [nmikhailov/validity90](https://github.com/nmikhailov/validity90) Reverse engineering of Validity/Synaptics 138a:0090, 138a:0094, 138a:0097, 06cb:0081, 06cb:009a fingerprint readers protocol +- [**1606**星][2d] [C++] [lief-project/lief](https://github.com/lief-project/lief) Library to Instrument Executable Formats - [**1602**星][6m] [Py] [w1109790800/penetration](https://github.com/w1109790800/penetration) 渗透 超全面的渗透资料 -- [**1600**星][8d] [C++] [lief-project/lief](https://github.com/lief-project/lief) Library to Instrument Executable Formats -- [**1599**星][9m] [JS] [localtunnel/server](https://github.com/localtunnel/server) server for localtunnel.me -- [**1596**星][5m] [Py] [mozilla/cipherscan](https://github.com/mozilla/cipherscan) 查找指定目标支持的SSL ciphersuites -- [**1596**星][3m] [Py] [knownsec/pocsuite](https://github.com/knownsec/pocsuite) This project has stopped to maintenance, please to -- [**1593**星][26d] [Java] [tiann/epic](https://github.com/tiann/epic) Dynamic java method AOP hook for Android(continution of Dexposed on ART), Supporting 4.0~10.0 -- [**1588**星][13d] [Java] [spotbugs/spotbugs](https://github.com/spotbugs/spotbugs) SpotBugs is FindBugs' successor. A tool for static analysis to look for bugs in Java code. -- [**1583**星][6m] [Ruby] [brunofacca/zen-rails-security-checklist](https://github.com/brunofacca/zen-rails-security-checklist) Checklist of security precautions for Ruby on Rails applications. -- [**1580**星][1y] [C] [qihoo360/phptrace](https://github.com/qihoo360/phptrace) A tracing and troubleshooting tool for PHP scripts. -- [**1580**星][7d] [Go] [bitnami-labs/sealed-secrets](https://github.com/bitnami-labs/sealed-secrets) A Kubernetes controller and tool for one-way encrypted Secrets -- [**1577**星][4y] [l3m0n/pentest_study](https://github.com/l3m0n/pentest_study) 从零开始内网渗透学习 -- [**1577**星][1m] [Objective-C] [ealeksandrov/provisionql](https://github.com/ealeksandrov/provisionql) Quick Look plugin for apps and provisioning profile files -- [**1575**星][26d] [C] [ntop/n2n](https://github.com/ntop/n2n) Peer-to-peer VPN -- [**1574**星][22d] [ivrodriguezca/re-ios-apps](https://github.com/ivrodriguezca/re-ios-apps) A completely free, open source and online course about Reverse Engineering iOS Applications. -- [**1563**星][2y] [C] [samyk/pwnat](https://github.com/samyk/pwnat) The only tool and technique to punch holes through firewalls/NATs where both clients and server can be behind separate NATs without any 3rd party involvement. Pwnat uses a newly developed technique, exploiting a property of NAT translation tables, with no 3rd party, port forwarding, DMZ, router administrative requirements, STUN/TURN/UPnP/ICE, or… -- [**1563**星][12d] [C] [codahale/bcrypt-ruby](https://github.com/codahale/bcrypt-ruby) Ruby binding for the OpenBSD bcrypt() password hashing algorithm, allowing you to easily store a secure hash of your users' passwords. -- [**1562**星][17d] [C] [p-gen/smenu](https://github.com/p-gen/smenu) Terminal utility that reads words from standard input or from a file and creates an interactive selection window just below the cursor. The selected word(s) are sent to standard output for further processing. -- [**1560**星][14d] [Java] [gchq/gaffer](https://github.com/gchq/Gaffer) A large-scale entity and relation database supporting aggregation of properties -- [**1557**星][2m] [C] [firmianay/ctf-all-in-one](https://github.com/firmianay/ctf-all-in-one) CTF竞赛入门指南 -- [**1556**星][12d] [Go] [caffix/amass](https://github.com/caffix/amass) 子域名枚举, 搜索互联网数据源, 使用机器学习猜测子域名. Go语言 -- [**1555**星][1y] [Py] [unkl4b/gitminer](https://github.com/unkl4b/gitminer) Github内容挖掘 -- [**1552**星][12d] [Py] [k4m4/kickthemout](https://github.com/k4m4/kickthemout) 使用ARP欺骗,将设备从网络中踢出去 -- [**1550**星][8m] [Py] [m4ll0k/wascan](https://github.com/m4ll0k/WAScan) WAScan - Web Application Scanner -- [**1547**星][1y] [C] [ctfs/write-ups-2016](https://github.com/ctfs/write-ups-2016) Wiki-like CTF write-ups repository, maintained by the community. 2016 -- [**1545**星][6y] [Py] [google/pyringe](https://github.com/google/pyringe) Debugger capable of attaching to and injecting code into python processes. -- [**1544**星][1m] [Shell] [mzet-/linux-exploit-suggester](https://github.com/mzet-/linux-exploit-suggester) Linux privilege escalation auditing tool -- [**1544**星][3m] [PHP] [mewebstudio/captcha](https://github.com/mewebstudio/captcha) Captcha for Laravel 5 & 6 -- [**1542**星][1m] [Py] [joxeankoret/diaphora](https://github.com/joxeankoret/diaphora) program diffing +- [**1601**星][1y] [Py] [nccgroup/scout2](https://github.com/nccgroup/Scout2) Security auditing tool for AWS environments +- [**1601**星][5m] [Py] [mozilla/cipherscan](https://github.com/mozilla/cipherscan) 查找指定目标支持的SSL ciphersuites +- [**1600**星][5d] [Go] [bitnami-labs/sealed-secrets](https://github.com/bitnami-labs/sealed-secrets) A Kubernetes controller and tool for one-way encrypted Secrets +- [**1599**星][2y] [JS] [keraf/nocoin](https://github.com/keraf/nocoin) No Coin is a tiny browser extension aiming to block coin miners such as Coinhive. +- [**1598**星][15d] [Java] [spotbugs/spotbugs](https://github.com/spotbugs/spotbugs) SpotBugs is FindBugs' successor. A tool for static analysis to look for bugs in Java code. +- [**1597**星][3m] [Py] [knownsec/pocsuite](https://github.com/knownsec/pocsuite) This project has stopped to maintenance, please to +- [**1591**星][28d] [C] [ntop/n2n](https://github.com/ntop/n2n) Peer-to-peer VPN +- [**1591**星][24d] [ivrodriguezca/re-ios-apps](https://github.com/ivrodriguezca/re-ios-apps) A completely free, open source and online course about Reverse Engineering iOS Applications. +- [**1584**星][6m] [Ruby] [brunofacca/zen-rails-security-checklist](https://github.com/brunofacca/zen-rails-security-checklist) Checklist of security precautions for Ruby on Rails applications. +- [**1583**星][4y] [l3m0n/pentest_study](https://github.com/l3m0n/pentest_study) 从零开始内网渗透学习 +- [**1582**星][1m] [ObjC] [ealeksandrov/provisionql](https://github.com/ealeksandrov/provisionql) Quick Look plugin for apps and provisioning profile files +- [**1581**星][1y] [C] [qihoo360/phptrace](https://github.com/qihoo360/phptrace) A tracing and troubleshooting tool for PHP scripts. +- [**1570**星][2m] [C] [firmianay/ctf-all-in-one](https://github.com/firmianay/ctf-all-in-one) CTF竞赛入门指南 +- [**1569**星][2y] [C] [samyk/pwnat](https://github.com/samyk/pwnat) The only tool and technique to punch holes through firewalls/NATs where both clients and server can be behind separate NATs without any 3rd party involvement. Pwnat uses a newly developed technique, exploiting a property of NAT translation tables, with no 3rd party, port forwarding, DMZ, router administrative requirements, STUN/TURN/UPnP/ICE, or… +- [**1569**星][29d] [Py] [opendevops-cn/opendevops](https://github.com/opendevops-cn/opendevops) CODO是一款为用户提供企业多混合云、一站式DevOps、自动化运维、完全开源的云管理平台、自动化运维平台 +- [**1566**星][14d] [C] [codahale/bcrypt-ruby](https://github.com/codahale/bcrypt-ruby) Ruby binding for the OpenBSD bcrypt() password hashing algorithm, allowing you to easily store a secure hash of your users' passwords. +- [**1565**星][17d] [Go] [sofastack/sofa-mosn](https://github.com/sofastack/sofa-mosn) 使用 Go 语言开发的网络代理软件,作为云原生的网络数据平面,旨在为服务提供多协议,模块化,智能化,安全的代理能力 +- [**1562**星][19d] [C] [p-gen/smenu](https://github.com/p-gen/smenu) Terminal utility that reads words from standard input or from a file and creates an interactive selection window just below the cursor. The selected word(s) are sent to standard output for further processing. +- [**1562**星][14d] [Py] [k4m4/kickthemout](https://github.com/k4m4/kickthemout) 使用ARP欺骗,将设备从网络中踢出去 +- [**1561**星][16d] [Java] [gchq/gaffer](https://github.com/gchq/Gaffer) A large-scale entity and relation database supporting aggregation of properties +- [**1560**星][1y] [Py] [unkl4b/gitminer](https://github.com/unkl4b/gitminer) Github内容挖掘 +- [**1560**星][6d] [Go] [caffix/amass](https://github.com/caffix/amass) 子域名枚举, 搜索互联网数据源, 使用机器学习猜测子域名. Go语言 +- [**1557**星][8m] [Py] [m4ll0k/wascan](https://github.com/m4ll0k/WAScan) WAScan - Web Application Scanner +- [**1556**星][15d] [Go] [eolinker/goku-api-gateway](https://github.com/eolinker/goku-api-gateway) A Powerful HTTP API Gateway in pure golang!Goku API Gateway (中文名:悟空 API 网关)是一个基于 Golang开发的微服务网关,能够实现高性能 HTTP API 转发、服务编排、多租户管理、API 访问权限控制等目的,拥有强大的自定义插件系统可以自行扩展,并且提供友好的图形化配置界面,能够快速帮助企业进行 API 服务治理、提高 API 服务的稳定性和安全性。 +- [**1555**星][1m] [Shell] [mzet-/linux-exploit-suggester](https://github.com/mzet-/linux-exploit-suggester) Linux privilege escalation auditing tool +- [**1549**星][7d] [PHP] [mewebstudio/captcha](https://github.com/mewebstudio/captcha) Captcha for Laravel 5 & 6 +- [**1549**星][1m] [Py] [joxeankoret/diaphora](https://github.com/joxeankoret/diaphora) program diffing +- [**1548**星][1y] [C] [ctfs/write-ups-2016](https://github.com/ctfs/write-ups-2016) Wiki-like CTF write-ups repository, maintained by the community. 2016 +- [**1544**星][15d] [C] [raspberrypi/userland](https://github.com/raspberrypi/userland) Source code for ARM side libraries for interfacing to Raspberry Pi GPU. +- [**1544**星][6y] [Py] [google/pyringe](https://github.com/google/pyringe) Debugger capable of attaching to and injecting code into python processes. +- [**1543**星][2d] [Go] [juju/juju](https://github.com/juju/juju) Simple, secure devops tooling built to manage today's complex applications wherever you run your software. +- [**1541**星][2y] [Py] [awolfly9/ipproxytool](https://github.com/awolfly9/ipproxytool) python ip proxy tool scrapy crawl. 抓取大量免费代理 ip,提取有效 ip 使用 - [**1540**星][2y] [C++] [hteso/iaito](https://github.com/hteso/iaito) Radare2 GUI,使用Qt和C++ -- [**1536**星][2y] [Py] [awolfly9/ipproxytool](https://github.com/awolfly9/ipproxytool) python ip proxy tool scrapy crawl. 抓取大量免费代理 ip,提取有效 ip 使用 -- [**1533**星][2y] [C] [ezlippi/webbench](https://github.com/ezlippi/webbench) Webbench是Radim Kolar在1997年写的一个在linux下使用的非常简单的网站压测工具。它使用fork()模拟多个客户端同时访问我们设定的URL,测试网站在压力下工作的性能,最多可以模拟3万个并发连接去测试网站的负载能力。官网地址: -- [**1532**星][13d] [C] [raspberrypi/userland](https://github.com/raspberrypi/userland) Source code for ARM side libraries for interfacing to Raspberry Pi GPU. -- [**1531**星][7d] [Py] [lifting-bits/mcsema](https://github.com/lifting-bits/mcsema) 将x86, amd64, aarch64二进制文件转换成LLVM字节码 +- [**1539**星][2y] [C] [ezlippi/webbench](https://github.com/ezlippi/webbench) Webbench是Radim Kolar在1997年写的一个在linux下使用的非常简单的网站压测工具。它使用fork()模拟多个客户端同时访问我们设定的URL,测试网站在压力下工作的性能,最多可以模拟3万个并发连接去测试网站的负载能力。官网地址: +- [**1537**星][9d] [Py] [lifting-bits/mcsema](https://github.com/lifting-bits/mcsema) 将x86, amd64, aarch64二进制文件转换成LLVM字节码 - [IDA7插件](https://github.com/lifting-bits/mcsema/tree/master/tools/mcsema_disass/ida7) 用于反汇编二进制文件并生成控制流程图 - [IDA插件](https://github.com/lifting-bits/mcsema/tree/master/tools/mcsema_disass/ida) 用于反汇编二进制文件并生成控制流程图 - [Binja插件](https://github.com/lifting-bits/mcsema/tree/master/tools/mcsema_disass/binja) 用于反汇编二进制文件并生成控制流程图 - [mcsema](https://github.com/lifting-bits/mcsema/tree/master/mcsema) -- [**1530**星][7d] [Go] [juju/juju](https://github.com/juju/juju) Simple, secure devops tooling built to manage today's complex applications wherever you run your software. -- [**1528**星][3y] [Py] [x0rz/eqgrp_lost_in_translation](https://github.com/x0rz/eqgrp_lost_in_translation) ShadowBrokers泄漏 -- [**1527**星][11d] [emijrp/awesome-awesome](https://github.com/emijrp/awesome-awesome) A curated list of awesome curated lists of many topics. -- [**1525**星][10d] [Java] [ukanth/afwall](https://github.com/ukanth/afwall) AFWall+ (Android Firewall +) - iptables based firewall for Android -- [**1521**星][1y] [HTML] [qiwihui/hiwifi-ss](https://github.com/qiwihui/hiwifi-ss) 极路由+ss配置 -- [**1520**星][4m] [TypeScript] [spring-guides/tut-spring-security-and-angular-js](https://github.com/spring-guides/tut-spring-security-and-angular-js) Spring Security and Angular:: A tutorial on how to use Spring Security with a single page application with various backend architectures, ranging from a simple single server to an API gateway with OAuth2 authentication. -- [**1520**星][20d] [C++] [nmap/npcap](https://github.com/nmap/npcap) Nmap Project's packet sniffing library for Windows, based on WinPcap/Libpcap improved with NDIS 6 and LWF. -- [**1519**星][10m] [PowerShell] [joefitzgerald/packer-windows](https://github.com/joefitzgerald/packer-windows) 使用Packer创建Vagrant boxes的模板 -- [**1516**星][9m] [Py] [google/rekall](https://github.com/google/rekall) Rekall Memory Forensic Framework +- [**1536**星][4d] [Java] [ukanth/afwall](https://github.com/ukanth/afwall) AFWall+ (Android Firewall +) - iptables based firewall for Android +- [**1533**星][13d] [emijrp/awesome-awesome](https://github.com/emijrp/awesome-awesome) A curated list of awesome curated lists of many topics. +- [**1532**星][3y] [Py] [x0rz/eqgrp_lost_in_translation](https://github.com/x0rz/eqgrp_lost_in_translation) ShadowBrokers泄漏 +- [**1526**星][2d] [C++] [nmap/npcap](https://github.com/nmap/npcap) Nmap Project's packet sniffing library for Windows, based on WinPcap/Libpcap improved with NDIS 6 and LWF. +- [**1522**星][1y] [HTML] [qiwihui/hiwifi-ss](https://github.com/qiwihui/hiwifi-ss) 极路由+ss配置 +- [**1521**星][4m] [TS] [spring-guides/tut-spring-security-and-angular-js](https://github.com/spring-guides/tut-spring-security-and-angular-js) Spring Security and Angular:: A tutorial on how to use Spring Security with a single page application with various backend architectures, ranging from a simple single server to an API gateway with OAuth2 authentication. +- [**1521**星][3d] [C] [jiangwenyuan/nuster](https://github.com/jiangwenyuan/nuster) A high performance HTTP proxy cache server and RESTful NoSQL cache server based on HAProxy +- [**1519**星][10m] [PS] [joefitzgerald/packer-windows](https://github.com/joefitzgerald/packer-windows) 使用Packer创建Vagrant boxes的模板 +- [**1518**星][9m] [Py] [google/rekall](https://github.com/google/rekall) Rekall Memory Forensic Framework +- [**1517**星][8d] [Py] [zerosum0x0/koadic](https://github.com/zerosum0x0/koadic) 类似于Meterpreter、Powershell Empire 的post-exploitation rootkit,区别在于其大多数操作都是由 Windows 脚本主机 JScript/VBScript 执行 +- [**1516**星][5m] [snowming04/the-hacker-playbook-3-translation](https://github.com/snowming04/the-hacker-playbook-3-translation) 对 The Hacker Playbook 3 的翻译。 +- [**1514**星][3y] [Py] [sensepost/regeorg](https://github.com/sensepost/regeorg) The successor to reDuh, pwn a bastion webserver and create SOCKS proxies through the DMZ. Pivot and pwn. - [**1510**星][1y] [dripcap/dripcap](https://github.com/dripcap/dripcap) -- [**1509**星][21d] [Py] [zerosum0x0/koadic](https://github.com/zerosum0x0/koadic) 类似于Meterpreter、Powershell Empire 的post-exploitation rootkit,区别在于其大多数操作都是由 Windows 脚本主机 JScript/VBScript 执行 -- [**1506**星][3y] [Py] [sensepost/regeorg](https://github.com/sensepost/regeorg) The successor to reDuh, pwn a bastion webserver and create SOCKS proxies through the DMZ. Pivot and pwn. -- [**1504**星][5m] [snowming04/the-hacker-playbook-3-translation](https://github.com/snowming04/the-hacker-playbook-3-translation) 对 The Hacker Playbook 3 的翻译。 -- [**1503**星][2y] [Py] [eldraco/domain_analyzer](https://github.com/eldraco/domain_analyzer) 通过查找所有能够查找的信息,来分析任意域名的安全性 -- [**1501**星][25d] [Py] [hannob/snallygaster](https://github.com/hannob/snallygaster) Python脚本, 扫描HTTP服务器"秘密文件" -- [**1500**星][2m] [Shell] [haugene/docker-transmission-openvpn](https://github.com/haugene/docker-transmission-openvpn) Docker container running Transmission torrent client with WebUI over an OpenVPN tunnel -- [**1491**星][4m] [Py] [epinna/tplmap](https://github.com/epinna/tplmap) 代码注入和服务器端模板注入(Server-Side Template Injection)漏洞利用,若干沙箱逃逸技巧。 -- [**1490**星][10d] [YARA] [cybermonitor/apt_cybercriminal_campagin_collections](https://github.com/cybermonitor/apt_cybercriminal_campagin_collections) APT & CyberCriminal Campaign Collection -- [**1487**星][7m] [Py] [ahupp/python-magic](https://github.com/ahupp/python-magic) A python wrapper for libmagic -- [**1485**星][2y] [Kotlin] [gh0u1l5/wechatmagician](https://github.com/gh0u1l5/wechatmagician) WechatMagician is a Xposed module written in Kotlin, that allows you to completely control your Wechat. -- [**1482**星][7m] [C++] [wangyu-/tinyfecvpn](https://github.com/wangyu-/tinyfecvpn) A VPN Designed for Lossy Links, with Build-in Forward Error Correction(FEC) Support. Improves your Network Quality on a High-latency Lossy Link. -- [**1478**星][7d] [C] [sleuthkit/sleuthkit](https://github.com/sleuthkit/sleuthkit) The Sleuth Kit® (TSK) is a library and collection of command line digital forensics tools that allow you to investigate volume and file system data. The library can be incorporated into larger digital forensics tools and the command line tools can be directly used to find evidence. -- [**1475**星][12d] [Py] [bitsadmin/wesng](https://github.com/bitsadmin/wesng) Windows Exploit Suggester - Next Generation -- [**1474**星][1y] [C++] [f1xpl/openauto](https://github.com/f1xpl/openauto) AndroidAuto headunit emulator -- [**1472**星][7d] [Shell] [blackarch/blackarch](https://github.com/blackarch/blackarch) BlackArch Linux is an Arch Linux-based distribution for penetration testers and security researchers. -- [**1468**星][16d] [Go] [google/keytransparency](https://github.com/google/keytransparency) A transparent and secure way to look up public keys. -- [**1468**星][3m] [C] [iqiyi/xhook](https://github.com/iqiyi/xhook) a PLT (Procedure Linkage Table) hook library for Android native ELF -- [**1466**星][2m] [C++] [jmpews/hookzz](https://github.com/jmpews/hookzz) a hook framework for arm/arm64/ios/android, and [dev] branch is being refactored. -- [**1465**星][3y] [Py] [veil-framework/veil-evasion](https://github.com/Veil-Framework/Veil-Evasion) a tool designed to generate metasploit payloads that bypass common anti-virus solutions. -- [**1465**星][25d] [minimaxir/hacker-news-undocumented](https://github.com/minimaxir/hacker-news-undocumented) Some of the hidden norms about Hacker News not otherwise covered in the Guidelines and the FAQ. -- [**1462**星][6y] [C] [alibaba/lvs](https://github.com/alibaba/lvs) A distribution of Linux Virtual Server with some advanced features. It introduces a new packet forwarding method - FULLNAT other than NAT/Tunneling/DirectRouting, and defense mechanism against synflooding attack - SYNPROXY. -- [**1460**星][14d] [C] [ufrisk/pcileech](https://github.com/ufrisk/pcileech) 直接内存访问(DMA:Direct Memory Access)攻击工具。通过 PCIe 硬件设备使用 DMA,直接读写目标系统的内存。目标系统不需要安装驱动。 -- [**1457**星][1y] [C++] [acaudwell/logstalgia](https://github.com/acaudwell/logstalgia) a visualization tool that replays or streams web server access logs as a retro arcade game simulation. -- [**1456**星][27d] [Go] [neex/phuip-fpizdam](https://github.com/neex/phuip-fpizdam) Exploit for CVE-2019-11043 -- [**1450**星][1y] [Py] [d4vinci/cr3dov3r](https://github.com/d4vinci/cr3dov3r) Know the dangers of credential reuse attacks. -- [**1448**星][6m] [Py] [enablesecurity/wafw00f](https://github.com/enablesecurity/wafw00f) 识别保护网站的WAF产品 -- [**1447**星][3m] [edoverflow/can-i-take-over-xyz](https://github.com/edoverflow/can-i-take-over-xyz) "Can I take over XYZ?" — a list of services and how to claim (sub)domains with dangling DNS records. -- [**1446**星][11d] [C++] [srslte/srslte](https://github.com/srslte/srslte) Open source SDR LTE software suite from Software Radio Systems (SRS) -- [**1442**星][6m] [Py] [oros42/imsi-catcher](https://github.com/oros42/imsi-catcher) This program show you IMSI numbers of cellphones around you. -- [**1441**星][19d] [C] [tianocore/edk2](https://github.com/tianocore/edk2) A modern, feature-rich, cross-platform firmware development environment for the UEFI and PI specifications -- [**1441**星][1m] [C] [ctcaer/hekate](https://github.com/ctcaer/hekate) Nintendo Switch Bootloader - CTCaer mod -- [**1439**星][3y] [tiancode/learn-hacking](https://github.com/tiancode/learn-hacking) 开始学习Kali Linux 各种破解教程 渗透测试 逆向工程 HackThisSite挑战问题解答 -- [**1439**星][3y] [tiancode/learn-hacking](https://github.com/tiancode/learn-hacking) 开始学习Kali Linux 各种破解教程 渗透测试 逆向工程 HackThisSite挑战问题解答 -- [**1438**星][3m] [C++] [vaibhavpandeyvpz/apkstudio](https://github.com/vaibhavpandeyvpz/apkstudio) Open-source, cross platform Qt based IDE for reverse-engineering Android application packages. -- [**1433**星][18d] [Go] [skydive-project/skydive](https://github.com/skydive-project/skydive) An open source real-time network topology and protocols analyzer -- [**1433**星][1y] [TypeScript] [pedronauck/reworm](https://github.com/pedronauck/reworm) -- [**1433**星][12d] [C++] [microsoft/seal](https://github.com/microsoft/seal) Microsoft SEAL is an easy-to-use and powerful homomorphic encryption library. -- [**1430**星][7d] [Go] [google/gapid](https://github.com/google/gapid) Graphics API Debugger -- [**1428**星][7d] [Py] [rocky/python-uncompyle6](https://github.com/rocky/python-uncompyle6) Python反编译器,跨平台 -- [**1427**星][6m] [C++] [x64dbg/scyllahide](https://github.com/x64dbg/scyllahide) Advanced usermode anti-anti-debugger +- [**1508**星][2m] [Shell] [haugene/docker-transmission-openvpn](https://github.com/haugene/docker-transmission-openvpn) Docker container running Transmission torrent client with WebUI over an OpenVPN tunnel +- [**1505**星][2y] [Py] [eldraco/domain_analyzer](https://github.com/eldraco/domain_analyzer) 通过查找所有能够查找的信息,来分析任意域名的安全性 +- [**1504**星][27d] [Py] [hannob/snallygaster](https://github.com/hannob/snallygaster) Python脚本, 扫描HTTP服务器"秘密文件" +- [**1499**星][5d] [YARA] [cybermonitor/apt_cybercriminal_campagin_collections](https://github.com/cybermonitor/apt_cybercriminal_campagin_collections) APT & CyberCriminal Campaign Collection +- [**1497**星][4m] [Py] [epinna/tplmap](https://github.com/epinna/tplmap) 代码注入和服务器端模板注入(Server-Side Template Injection)漏洞利用,若干沙箱逃逸技巧。 +- [**1489**星][5d] [Py] [ahupp/python-magic](https://github.com/ahupp/python-magic) A python wrapper for libmagic +- [**1486**星][2y] [Kotlin] [gh0u1l5/wechatmagician](https://github.com/gh0u1l5/wechatmagician) WechatMagician is a Xposed module written in Kotlin, that allows you to completely control your Wechat. +- [**1485**星][7m] [C++] [wangyu-/tinyfecvpn](https://github.com/wangyu-/tinyfecvpn) A VPN Designed for Lossy Links, with Build-in Forward Error Correction(FEC) Support. Improves your Network Quality on a High-latency Lossy Link. +- [**1482**星][7d] [Py] [bitsadmin/wesng](https://github.com/bitsadmin/wesng) Windows Exploit Suggester - Next Generation +- [**1481**星][2d] [C] [sleuthkit/sleuthkit](https://github.com/sleuthkit/sleuthkit) The Sleuth Kit® (TSK) is a library and collection of command line digital forensics tools that allow you to investigate volume and file system data. The library can be incorporated into larger digital forensics tools and the command line tools can be directly used to find evidence. +- [**1480**星][1y] [C++] [f1xpl/openauto](https://github.com/f1xpl/openauto) AndroidAuto headunit emulator +- [**1479**星][3d] [C] [ctcaer/hekate](https://github.com/ctcaer/hekate) Nintendo Switch Bootloader - CTCaer mod +- [**1478**星][8d] [C] [iqiyi/xhook](https://github.com/iqiyi/xhook) a PLT (Procedure Linkage Table) hook library for Android native ELF +- [**1477**星][2d] [Shell] [blackarch/blackarch](https://github.com/blackarch/blackarch) BlackArch Linux is an Arch Linux-based distribution for penetration testers and security researchers. +- [**1476**星][2m] [C++] [jmpews/hookzz](https://github.com/jmpews/hookzz) a hook framework for arm/arm64/ios/android, and [dev] branch is being refactored. +- [**1471**星][27d] [minimaxir/hacker-news-undocumented](https://github.com/minimaxir/hacker-news-undocumented) Some of the hidden norms about Hacker News not otherwise covered in the Guidelines and the FAQ. +- [**1470**星][3y] [Py] [veil-framework/veil-evasion](https://github.com/Veil-Framework/Veil-Evasion) a tool designed to generate metasploit payloads that bypass common anti-virus solutions. +- [**1470**星][2d] [Go] [google/keytransparency](https://github.com/google/keytransparency) A transparent and secure way to look up public keys. +- [**1469**星][6y] [C] [alibaba/lvs](https://github.com/alibaba/lvs) A distribution of Linux Virtual Server with some advanced features. It introduces a new packet forwarding method - FULLNAT other than NAT/Tunneling/DirectRouting, and defense mechanism against synflooding attack - SYNPROXY. +- [**1466**星][29d] [Go] [neex/phuip-fpizdam](https://github.com/neex/phuip-fpizdam) Exploit for CVE-2019-11043 +- [**1464**星][6m] [Py] [oros42/imsi-catcher](https://github.com/oros42/imsi-catcher) This program show you IMSI numbers of cellphones around you. +- [**1463**星][7d] [C] [ufrisk/pcileech](https://github.com/ufrisk/pcileech) DMA攻击工具。通过 PCIe 硬件设备使用 DMA,直接读写目标系统的内存。目标系统不需要安装驱动。 +- [**1462**星][9d] [edoverflow/can-i-take-over-xyz](https://github.com/edoverflow/can-i-take-over-xyz) "Can I take over XYZ?" — a list of services and how to claim (sub)domains with dangling DNS records. +- [**1459**星][3d] [Py] [enablesecurity/wafw00f](https://github.com/enablesecurity/wafw00f) 识别保护网站的WAF产品 +- [**1458**星][1y] [C++] [acaudwell/logstalgia](https://github.com/acaudwell/logstalgia) a visualization tool that replays or streams web server access logs as a retro arcade game simulation. +- [**1455**星][1y] [Py] [d4vinci/cr3dov3r](https://github.com/d4vinci/cr3dov3r) Know the dangers of credential reuse attacks. +- [**1453**星][13d] [C++] [srslte/srslte](https://github.com/srslte/srslte) Open source SDR LTE software suite from Software Radio Systems (SRS) +- [**1451**星][2d] [Py] [rocky/python-uncompyle6](https://github.com/rocky/python-uncompyle6) Python反编译器,跨平台 +- [**1447**星][3y] [tiancode/learn-hacking](https://github.com/tiancode/learn-hacking) 开始学习Kali Linux 各种破解教程 渗透测试 逆向工程 HackThisSite挑战问题解答 +- [**1447**星][3y] [tiancode/learn-hacking](https://github.com/tiancode/learn-hacking) 开始学习Kali Linux 各种破解教程 渗透测试 逆向工程 HackThisSite挑战问题解答 +- [**1447**星][2m] [Py] [neo23x0/loki](https://github.com/neo23x0/loki) Loki - Simple IOC and Incident Response Scanner +- [**1446**星][5d] [C] [tianocore/edk2](https://github.com/tianocore/edk2) A modern, feature-rich, cross-platform firmware development environment for the UEFI and PI specifications +- [**1446**星][20d] [Go] [skydive-project/skydive](https://github.com/skydive-project/skydive) An open source real-time network topology and protocols analyzer +- [**1446**星][14d] [C++] [microsoft/seal](https://github.com/microsoft/seal) Microsoft SEAL is an easy-to-use and powerful homomorphic encryption library. +- [**1445**星][3m] [C++] [vaibhavpandeyvpz/apkstudio](https://github.com/vaibhavpandeyvpz/apkstudio) Open-source, cross platform Qt based IDE for reverse-engineering Android application packages. +- [**1437**星][5d] [Go] [google/gapid](https://github.com/google/gapid) Graphics API Debugger +- [**1436**星][20d] [Kotlin] [cypherpunkarmory/userland](https://github.com/cypherpunkarmory/userland) The easiest way to run a Linux distribution or application on Android +- [**1433**星][11m] [C] [tpruvot/ccminer](https://github.com/tpruvot/ccminer) CUDA Open Source miner project, for most nvidia cards +- [**1433**星][1y] [TS] [pedronauck/reworm](https://github.com/pedronauck/reworm) +- [**1432**星][6m] [C++] [x64dbg/scyllahide](https://github.com/x64dbg/scyllahide) Advanced usermode anti-anti-debugger +- [**1432**星][2m] [C] [feralinteractive/gamemode](https://github.com/feralinteractive/gamemode) Optimise Linux system performance on demand +- [**1429**星][5y] [C++] [gdbinit/machoview](https://github.com/gdbinit/machoview) MachOView fork +- [**1427**星][9d] [ObjC] [nabla-c0d3/ssl-kill-switch2](https://github.com/nabla-c0d3/ssl-kill-switch2) Blackbox tool to disable SSL certificate validation - including certificate pinning - within iOS and OS X Apps +- [**1426**星][20d] [C++] [plasma-umass/coz](https://github.com/plasma-umass/coz) Finding Code that Counts with Causal Profiling +- [**1426**星][4y] [C++] [aappleby/smhasher](https://github.com/aappleby/smhasher) Automatically exported from code.google.com/p/smhasher - [**1425**星][3m] [Go] [google/stenographer](https://github.com/google/stenographer) Stenographer is a packet capture solution which aims to quickly spool all packets to disk, then provide simple, fast access to subsets of those packets. Discussion/announcements at stenographer@googlegroups.com -- [**1423**星][8y] [Py] [moxie0/sslstrip](https://github.com/moxie0/sslstrip) A tool for exploiting Moxie Marlinspike's SSL "stripping" attack. -- [**1423**星][18d] [Kotlin] [cypherpunkarmory/userland](https://github.com/cypherpunkarmory/userland) The easiest way to run a Linux distribution or application on Android -- [**1422**星][2m] [C] [feralinteractive/gamemode](https://github.com/feralinteractive/gamemode) Optimise Linux system performance on demand -- [**1421**星][3y] [mandatoryprogrammer/northkoreadnsleak](https://github.com/mandatoryprogrammer/northkoreadnsleak) Snapshot of North Korea's DNS data taken from zone transfers. -- [**1421**星][4y] [C++] [aappleby/smhasher](https://github.com/aappleby/smhasher) Automatically exported from code.google.com/p/smhasher -- [**1420**星][10m] [Java] [aslody/legend](https://github.com/aslody/legend) (Android)无需Root即可Hook Java方法的框架, 支持Dalvik和Art环境 -- [**1419**星][2m] [Py] [neo23x0/loki](https://github.com/neo23x0/loki) Loki - Simple IOC and Incident Response Scanner -- [**1419**星][3y] [Py] [nathanlopez/stitch](https://github.com/nathanlopez/stitch) Python Remote Administration Tool (RAT) -- [**1419**星][12d] [Go] [google/google-ctf](https://github.com/google/google-ctf) Google CTF -- [**1419**星][5y] [C++] [gdbinit/machoview](https://github.com/gdbinit/machoview) MachOView fork -- [**1417**星][1m] [Py] [xdavidhu/mitmap](https://github.com/xdavidhu/mitmap) -- [**1417**星][5m] [PHP] [s4n7h0/xvwa](https://github.com/s4n7h0/xvwa) XVWA is a badly coded web application written in PHP/MySQL that helps security enthusiasts to learn application security. -- [**1416**星][1m] [Go] [barnybug/cli53](https://github.com/barnybug/cli53) Command line tool for Amazon Route 53 -- [**1415**星][3y] [C] [antirez/dump1090](https://github.com/antirez/dump1090) Dump1090 is a simple Mode S decoder for RTLSDR devices -- [**1413**星][7m] [Objective-C] [nabla-c0d3/ssl-kill-switch2](https://github.com/nabla-c0d3/ssl-kill-switch2) Blackbox tool to disable SSL certificate validation - including certificate pinning - within iOS and OS X Apps -- [**1411**星][11d] [C] [ettercap/ettercap](https://github.com/ettercap/ettercap) Ettercap Project -- [**1410**星][8d] [Go] [cosmos72/gomacro](https://github.com/cosmos72/gomacro) Interactive Go interpreter and debugger with REPL, Eval, generics and Lisp-like macros -- [**1409**星][4m] [yadox666/the-hackers-hardware-toolkit](https://github.com/yadox666/the-hackers-hardware-toolkit) The best hacker's gadgets for Red Team pentesters and security researchers. -- [**1408**星][22d] [Java] [chrisk44/hijacker](https://github.com/chrisk44/hijacker) Aircrack, Airodump, Aireplay, MDK3 and Reaver GUI Application for Android -- [**1407**星][7d] [C] [namhyung/uftrace](https://github.com/namhyung/uftrace) Function (graph) tracer for user-space -- [**1406**星][1m] [C++] [google/nsjail](https://github.com/google/nsjail) A light-weight process isolation tool, making use of Linux namespaces and seccomp-bpf syscall filters (with help of the kafel bpf language) -- [**1402**星][5m] [gitguardian/apisecuritybestpractices](https://github.com/gitguardian/apisecuritybestpractices) Resources to help you keep secrets (API keys, database credentials, certificates, ...) out of source code and remediate the issue in case of a leaked API key. Made available by GitGuardian. -- [**1402**星][7d] [C++] [eteran/edb-debugger](https://github.com/eteran/edb-debugger) edb is a cross platform AArch32/x86/x86-64 debugger. +- [**1424**星][8y] [Py] [moxie0/sslstrip](https://github.com/moxie0/sslstrip) A tool for exploiting Moxie Marlinspike's SSL "stripping" attack. +- [**1424**星][11m] [Java] [aslody/legend](https://github.com/aslody/legend) (Android)无需Root即可Hook Java方法的框架, 支持Dalvik和Art环境 +- [**1423**星][14d] [Go] [google/google-ctf](https://github.com/google/google-ctf) Google CTF +- [**1422**星][3y] [Py] [nathanlopez/stitch](https://github.com/nathanlopez/stitch) Python Remote Administration Tool (RAT) +- [**1422**星][3y] [mandatoryprogrammer/northkoreadnsleak](https://github.com/mandatoryprogrammer/northkoreadnsleak) Snapshot of North Korea's DNS data taken from zone transfers. +- [**1419**星][1m] [Py] [xdavidhu/mitmap](https://github.com/xdavidhu/mitmap) +- [**1419**星][3y] [C] [antirez/dump1090](https://github.com/antirez/dump1090) Dump1090 is a simple Mode S decoder for RTLSDR devices +- [**1418**星][5m] [PHP] [s4n7h0/xvwa](https://github.com/s4n7h0/xvwa) XVWA is a badly coded web application written in PHP/MySQL that helps security enthusiasts to learn application security. +- [**1417**星][4m] [yadox666/the-hackers-hardware-toolkit](https://github.com/yadox666/the-hackers-hardware-toolkit) 用于Red Team、渗透、安全研究的最佳硬件产品集合 +- [**1417**星][4d] [Rust] [shadowsocks/shadowsocks-rust](https://github.com/shadowsocks/shadowsocks-rust) A Rust port of shadowsocks +- [**1417**星][1m] [Go] [barnybug/cli53](https://github.com/barnybug/cli53) Command line tool for Amazon Route 53 +- [**1415**星][7d] [C] [z3apa3a/3proxy](https://github.com/z3apa3a/3proxy) 3proxy - tiny free proxy server +- [**1414**星][8d] [C] [ettercap/ettercap](https://github.com/ettercap/ettercap) Ettercap Project +- [**1413**星][24d] [XSLT] [lolbas-project/lolbas](https://github.com/lolbas-project/lolbas) Living Off The Land Binaries And Scripts - (LOLBins and LOLScripts) +- [**1413**星][24d] [Java] [chrisk44/hijacker](https://github.com/chrisk44/hijacker) Aircrack, Airodump, Aireplay, MDK3 and Reaver GUI Application for Android +- [**1412**星][9d] [C] [namhyung/uftrace](https://github.com/namhyung/uftrace) Function (graph) tracer for user-space +- [**1412**星][5m] [gitguardian/apisecuritybestpractices](https://github.com/gitguardian/apisecuritybestpractices) Resources to help you keep secrets (API keys, database credentials, certificates, ...) out of source code and remediate the issue in case of a leaked API key. Made available by GitGuardian. +- [**1411**星][7d] [C++] [eteran/edb-debugger](https://github.com/eteran/edb-debugger) edb is a cross platform AArch32/x86/x86-64 debugger. +- [**1411**星][3d] [Go] [cosmos72/gomacro](https://github.com/cosmos72/gomacro) Interactive Go interpreter and debugger with REPL, Eval, generics and Lisp-like macros +- [**1410**星][3m] [Go] [hellogcc/100-gdb-tips](https://github.com/hellogcc/100-gdb-tips) A collection of gdb tips. 100 maybe just mean many here. +- [**1408**星][3m] [HTML] [owasp/top10](https://github.com/owasp/top10) Official OWASP Top 10 Document Repository +- [**1407**星][4d] [C++] [google/nsjail](https://github.com/google/nsjail) A light-weight process isolation tool, making use of Linux namespaces and seccomp-bpf syscall filters (with help of the kafel bpf language) +- [**1405**星][1y] [HTML] [gwuhaolin/blog](https://github.com/gwuhaolin/blog) 浩麟的技术博客 +- [**1405**星][1y] [C++] [dotnet/llilc](https://github.com/dotnet/llilc) This repo contains LLILC, an LLVM based compiler for .NET Core. It includes a set of cross-platform .NET code generation tools that enables compilation of MSIL byte code to LLVM supported platforms. +- [**1404**星][7d] [Java] [chinashiyu/gfw.press](https://github.com/chinashiyu/gfw.press) GFW.Press新一代军用级高强度加密抗干扰网络数据高速传输软件 +- [**1403**星][2d] [Go] [crazy-max/windowsspyblocker](https://github.com/crazy-max/windowsspyblocker) - [**1401**星][9m] [JS] [anttiviljami/browser-autofill-phishing](https://github.com/anttiviljami/browser-autofill-phishing) A simple demo of phishing by abusing the browser autofill feature -- [**1400**星][3m] [HTML] [owasp/top10](https://github.com/owasp/top10) Official OWASP Top 10 Document Repository -- [**1400**星][1y] [C++] [dotnet/llilc](https://github.com/dotnet/llilc) This repo contains LLILC, an LLVM based compiler for .NET Core. It includes a set of cross-platform .NET code generation tools that enables compilation of MSIL byte code to LLVM supported platforms. -- [**1399**星][25d] [Go] [crazy-max/windowsspyblocker](https://github.com/crazy-max/windowsspyblocker) -- [**1399**星][7d] [Java] [chinashiyu/gfw.press](https://github.com/chinashiyu/gfw.press) GFW.Press新一代军用级高强度加密抗干扰网络数据高速传输软件 -- [**1397**星][7d] [Rust] [shadowsocks/shadowsocks-rust](https://github.com/shadowsocks/shadowsocks-rust) A Rust port of shadowsocks -- [**1395**星][1y] [Go] [filosottile/whosthere](https://github.com/filosottile/whosthere) A ssh server that knows who you are -- [**1393**星][25d] [C] [quiet/org.quietmodem.quiet](https://github.com/quiet/org.quietmodem.quiet) Quiet for Android - TCP over sound -- [**1393**星][3y] [PowerShell] [putterpanda/mimikittenz](https://github.com/putterpanda/mimikittenz) A post-exploitation powershell tool for extracting juicy info from memory. -- [**1391**星][22d] [XSLT] [lolbas-project/lolbas](https://github.com/lolbas-project/lolbas) Living Off The Land Binaries And Scripts - (LOLBins and LOLScripts) -- [**1388**星][14d] [Swift] [johnno1962/injectioniii](https://github.com/johnno1962/injectioniii) Re-write of Injection for Xcode in (mostly) Swift4 -- [**1387**星][1y] [HTML] [gwuhaolin/blog](https://github.com/gwuhaolin/blog) 浩麟的技术博客 -- [**1387**星][2y] [JS] [sqren/fb-sleep-stats](https://github.com/sqren/fb-sleep-stats) 使用Facebook追踪用户的睡觉习惯 -- [**1386**星][18d] [C++] [plasma-umass/coz](https://github.com/plasma-umass/coz) Finding Code that Counts with Causal Profiling -- [**1384**星][4y] [PHP] [johntroony/php-webshells](https://github.com/johntroony/php-webshells) Common php webshells. Do not host the file(s) on your server! -- [**1383**星][14d] [C++] [jonathansalwan/triton](https://github.com/jonathansalwan/triton) Triton is a Dynamic Binary Analysis (DBA) framework. It provides internal components like a Dynamic Symbolic Execution (DSE) engine, a dynamic taint engine, AST representations of the x86, x86-64 and AArch64 Instructions Set Architecture (ISA), SMT simplification passes, an SMT solver interface and, the last but not least, Python bindings. -- [**1383**星][8d] [Py] [ekultek/whatwaf](https://github.com/ekultek/whatwaf) Detect and bypass web application firewalls and protection systems -- [**1381**星][11m] [Py] [eth0izzle/bucket-stream](https://github.com/eth0izzle/bucket-stream) 通过certstream 监控多种证书 transparency 日志, 进而查找有趣的 Amazon S3 Buckets -- [**1380**星][2m] [C] [z3apa3a/3proxy](https://github.com/z3apa3a/3proxy) 3proxy - tiny free proxy server -- [**1380**星][11d] [Shell] [drduh/pwd.sh](https://github.com/drduh/pwd.sh) GPG symmetric password manager -- [**1377**星][11d] [OCaml] [mirage/mirage](https://github.com/mirage/mirage) MirageOS is a library operating system that constructs unikernels -- [**1376**星][6m] [Py] [almandin/fuxploider](https://github.com/almandin/fuxploider) 文件上传漏洞扫描和利用工具 -- [**1375**星][10m] [JS] [intika/librefox](https://github.com/intika/librefox) Firefox with privacy enhancements +- [**1399**星][16d] [Swift] [johnno1962/injectioniii](https://github.com/johnno1962/injectioniii) Re-write of Injection for Xcode in (mostly) Swift4 +- [**1397**星][1y] [Go] [filosottile/whosthere](https://github.com/filosottile/whosthere) A ssh server that knows who you are +- [**1396**星][3y] [PS] [putterpanda/mimikittenz](https://github.com/putterpanda/mimikittenz) A post-exploitation powershell tool for extracting juicy info from memory. +- [**1395**星][27d] [C] [quiet/org.quietmodem.quiet](https://github.com/quiet/org.quietmodem.quiet) Quiet for Android - TCP over sound +- [**1393**星][4d] [atarity/deploy-your-own-saas](https://github.com/atarity/deploy-your-own-saas) List of "only yours" cloud services for everyday needs +- [**1393**星][9d] [Py] [ekultek/whatwaf](https://github.com/ekultek/whatwaf) 检测并绕过WAF和保护系统 +- [**1392**星][16d] [C++] [jonathansalwan/triton](https://github.com/jonathansalwan/triton) Triton is a Dynamic Binary Analysis (DBA) framework. It provides internal components like a Dynamic Symbolic Execution (DSE) engine, a dynamic taint engine, AST representations of the x86, x86-64 and AArch64 Instructions Set Architecture (ISA), SMT simplification passes, an SMT solver interface and, the last but not least, Python bindings. +- [**1388**星][4y] [PHP] [johntroony/php-webshells](https://github.com/johntroony/php-webshells) Common php webshells. Do not host the file(s) on your server! +- [**1387**星][11m] [Py] [eth0izzle/bucket-stream](https://github.com/eth0izzle/bucket-stream) 通过certstream 监控多种证书 transparency 日志, 进而查找有趣的 Amazon S3 Buckets +- [**1386**星][2y] [JS] [sqren/fb-sleep-stats](https://github.com/sqren/fb-sleep-stats) 使用Facebook追踪用户的睡觉习惯 +- [**1384**星][5d] [JS] [ix64/unlock-music](https://github.com/ix64/unlock-music) Unlock encrypted music file in browser. 在浏览器中解锁加密的音乐文件。 +- [**1381**星][6m] [Py] [almandin/fuxploider](https://github.com/almandin/fuxploider) 文件上传漏洞扫描和利用工具 +- [**1380**星][15d] [C] [dynamorio/drmemory](https://github.com/dynamorio/drmemory) Memory Debugger for Windows, Linux, Mac, and Android +- [**1380**星][13d] [Shell] [drduh/pwd.sh](https://github.com/drduh/pwd.sh) GPG symmetric password manager +- [**1378**星][13d] [OCaml] [mirage/mirage](https://github.com/mirage/mirage) MirageOS is a library operating system that constructs unikernels +- [**1378**星][2d] [JS] [lockfale/osint-framework](https://github.com/lockfale/osint-framework) OSINT Framework +- [**1375**星][15d] [Go] [unrolled/secure](https://github.com/unrolled/secure) HTTP middleware for Go that facilitates some quick security wins. +- [**1375**星][11m] [JS] [intika/librefox](https://github.com/intika/librefox) Firefox with privacy enhancements - [**1374**星][4y] [C++] [valvesoftware/vogl](https://github.com/valvesoftware/vogl) OpenGL capture / playback debugger. -- [**1373**星][13d] [C] [dynamorio/drmemory](https://github.com/dynamorio/drmemory) Memory Debugger for Windows, Linux, Mac, and Android -- [**1365**星][9m] [PowerShell] [danielbohannon/invoke-obfuscation](https://github.com/danielbohannon/invoke-obfuscation) PowerShell Obfuscator -- [**1364**星][5m] [Py] [s0md3v/striker](https://github.com/s0md3v/Striker) Striker is an offensive information and vulnerability scanner. -- [**1363**星][29d] [C] [zyantific/zydis](https://github.com/zyantific/zydis) 快速的轻量级x86/x86-64 反汇编库 -- [**1361**星][3y] [C++] [aslody/turbodex](https://github.com/aslody/turbodex) 在内存中快速加载dex -- [**1360**星][6m] [Py] [vulnerscom/getsploit](https://github.com/vulnerscom/getsploit) Command line utility for searching and downloading exploits -- [**1360**星][2m] [Py] [fireeye/flare-floss](https://github.com/fireeye/flare-floss) 自动从恶意代码中提取反混淆后的字符串 +- [**1373**星][5m] [Py] [s0md3v/striker](https://github.com/s0md3v/Striker) Striker is an offensive information and vulnerability scanner. +- [**1373**星][9m] [PS] [danielbohannon/invoke-obfuscation](https://github.com/danielbohannon/invoke-obfuscation) PowerShell Obfuscator +- [**1371**星][1m] [C] [zyantific/zydis](https://github.com/zyantific/zydis) 快速的轻量级x86/x86-64 反汇编库 +- [**1365**星][9d] [Go] [cortesi/modd](https://github.com/cortesi/modd) A flexible developer tool that runs processes and responds to filesystem changes +- [**1363**星][2m] [Py] [fireeye/flare-floss](https://github.com/fireeye/flare-floss) 自动从恶意代码中提取反混淆后的字符串 - [floss](https://github.com/fireeye/flare-floss/tree/master/floss) - [IDA插件](https://github.com/fireeye/flare-floss/blob/master/scripts/idaplugin.py) -- [**1358**星][7d] [Go] [cortesi/modd](https://github.com/cortesi/modd) A flexible developer tool that runs processes and responds to filesystem changes -- [**1357**星][24d] [JS] [lockfale/osint-framework](https://github.com/lockfale/osint-framework) OSINT Framework -- [**1355**星][6m] [C++] [phpv8/v8js](https://github.com/phpv8/v8js) V8 Javascript Engine for PHP — This PHP extension embeds the Google V8 Javascript Engine -- [**1355**星][1m] [grrrdog/java-deserialization-cheat-sheet](https://github.com/grrrdog/java-deserialization-cheat-sheet) The cheat sheet about Java Deserialization vulnerabilities -- [**1355**星][2m] [C] [googleprojectzero/winafl](https://github.com/googleprojectzero/winafl) A fork of AFL for fuzzing Windows binaries -- [**1348**星][23d] [C] [x64dbg/x64dbgpy](https://github.com/x64dbg/x64dbgpy) Automating x64dbg using Python, Snapshots: -- [**1348**星][4m] [C] [taviso/ctftool](https://github.com/taviso/ctftool) Interactive CTF Exploration Tool -- [**1348**星][3y] [Py] [joaomatosf/jexboss](https://github.com/joaomatosf/jexboss) Jboss (and Java Deserialization Vulnerabilities) verify and EXploitation Tool -- [**1347**星][13d] [Go] [unrolled/secure](https://github.com/unrolled/secure) HTTP middleware for Go that facilitates some quick security wins. -- [**1347**星][3m] [C++] [raspberrypi/tools](https://github.com/raspberrypi/tools) +- [**1363**星][3y] [C++] [aslody/turbodex](https://github.com/aslody/turbodex) 在内存中快速加载dex +- [**1362**星][1m] [grrrdog/java-deserialization-cheat-sheet](https://github.com/grrrdog/java-deserialization-cheat-sheet) The cheat sheet about Java Deserialization vulnerabilities +- [**1361**星][7m] [Py] [vulnerscom/getsploit](https://github.com/vulnerscom/getsploit) Command line utility for searching and downloading exploits +- [**1361**星][6m] [C++] [phpv8/v8js](https://github.com/phpv8/v8js) V8 Javascript Engine for PHP — This PHP extension embeds the Google V8 Javascript Engine +- [**1359**星][2m] [C] [googleprojectzero/winafl](https://github.com/googleprojectzero/winafl) A fork of AFL for fuzzing Windows binaries +- [**1355**星][10m] [HTML] [thelinuxchoice/blackeye](https://github.com/thelinuxchoice/blackeye) The most complete Phishing Tool, with 32 templates +1 customizable +- [**1354**星][2d] [Py] [mitre/caldera](https://github.com/mitre/caldera) 自动化 adversary emulation 系统 +- [**1352**星][3y] [Py] [joaomatosf/jexboss](https://github.com/joaomatosf/jexboss) Jboss (and Java Deserialization Vulnerabilities) verify and EXploitation Tool +- [**1351**星][3m] [C++] [raspberrypi/tools](https://github.com/raspberrypi/tools) +- [**1350**星][4m] [C] [taviso/ctftool](https://github.com/taviso/ctftool) Interactive CTF Exploration Tool +- [**1349**星][3y] [Py] [ddevault/evilpass](https://github.com/ddevault/evilpass) Slightly evil password strength checker +- [**1349**星][19d] [C++] [rikkaapps/riru](https://github.com/rikkaapps/riru) Inject zygote process by replace libmemtrack +- [**1349**星][5m] [Py] [lijiejie/githack](https://github.com/lijiejie/githack) git泄露利用脚本,通过泄露的.git文件夹下的文件,重建还原工程源代码 +- [**1348**星][10m] [rebeyond/behinder](https://github.com/rebeyond/behinder) “冰蝎”动态二进制加密网站管理客户端 - [**1347**星][11m] [Rust] [das-labor/panopticon](https://github.com/das-labor/panopticon) A libre cross-platform disassembler. -- [**1346**星][3y] [Py] [ddevault/evilpass](https://github.com/ddevault/evilpass) Slightly evil password strength checker - [**1346**星][2y] [HTML] [daxeel/blockshell](https://github.com/daxeel/blockshell) 用于学习区块链技术概念的命令行工具, 例如 likechaining, mining,proof of work 等 -- [**1344**星][10m] [HTML] [thelinuxchoice/blackeye](https://github.com/thelinuxchoice/blackeye) The most complete Phishing Tool, with 32 templates +1 customizable -- [**1343**星][5m] [Py] [lijiejie/githack](https://github.com/lijiejie/githack) git泄露利用脚本,通过泄露的.git文件夹下的文件,重建还原工程源代码 -- [**1343**星][3m] [Go] [hellogcc/100-gdb-tips](https://github.com/hellogcc/100-gdb-tips) A collection of gdb tips. 100 maybe just mean many here. -- [**1342**星][7d] [Py] [mitre/caldera](https://github.com/mitre/caldera) 自动化 adversary emulation 系统 -- [**1341**星][10d] [Go] [securitywithoutborders/hardentools](https://github.com/securitywithoutborders/hardentools) 禁用许多有危险的Windows功能 -- [**1341**星][2m] [Go] [davrodpin/mole](https://github.com/davrodpin/mole) cli app to create ssh tunnels -- [**1339**星][21d] [Py] [s0md3v/arjun](https://github.com/s0md3v/Arjun) HTTP parameter discovery suite. -- [**1339**星][12m] [XSLT] [api0cradle/lolbas](https://github.com/api0cradle/lolbas) Living Off The Land Binaries And Scripts - (LOLBins and LOLScripts) -- [**1338**星][21d] [Go] [microcosm-cc/bluemonday](https://github.com/microcosm-cc/bluemonday) a fast golang HTML sanitizer (inspired by the OWASP Java HTML Sanitizer) to scrub user generated content of XSS -- [**1338**星][7m] [Py] [feeicn/gsil](https://github.com/feeicn/gsil) GitHub敏感信息泄露监控,几乎实时监控,发送警告 -- [**1337**星][1y] [Py] [carmaa/inception](https://github.com/carmaa/inception) 利用基于PCI的DMA实现物理内存的操纵与Hacking,可以攻击FireWire,Thunderbolt,ExpressCard,PC Card和任何其他PCI / PCIe硬件接口 -- [**1336**星][6y] [Perl] [intelisecurelabs/linux_exploit_suggester](https://github.com/InteliSecureLabs/Linux_Exploit_Suggester) Linux Exploit Suggester; based on operating system release number -- [**1336**星][3m] [Py] [maratyszcza/peachpy](https://github.com/maratyszcza/peachpy) x86-64 assembler embedded in Python -- [**1333**星][17d] [C++] [rikkaapps/riru](https://github.com/rikkaapps/riru) Inject zygote process by replace libmemtrack -- [**1331**星][2m] [C++] [mfontanini/libtins](https://github.com/mfontanini/libtins) High-level, multiplatform C++ network packet sniffing and crafting library. -- [**1331**星][1y] [C] [gamelinux/passivedns](https://github.com/gamelinux/passivedns) A network sniffer that logs all DNS server replies for use in a passive DNS setup -- [**1329**星][1m] [CSS] [undeadsec/socialfish](https://github.com/undeadsec/socialfish) 网络钓鱼培训与信息收集 -- [**1329**星][10m] [rebeyond/behinder](https://github.com/rebeyond/behinder) “冰蝎”动态二进制加密网站管理客户端 -- [**1329**星][1y] [kirikira/vtemplate](https://github.com/kirikira/vtemplate) v2ray的模板们 -- [**1328**星][1y] [C] [madeye/proxydroid](https://github.com/madeye/proxydroid) Global Proxy for Android -- [**1326**星][11d] [C++] [purplei2p/i2pd](https://github.com/purplei2p/i2pd) a full-featured C++ implementation of I2P client -- [**1324**星][2y] [CoffeeScript] [atmos/camo](https://github.com/atmos/camo) all about making insecure assets look secure -- [**1323**星][1y] [Py] [marten4n6/evilosx](https://github.com/marten4n6/evilosx) An evil RAT (Remote Administration Tool) for macOS / OS X. -- [**1322**星][3m] [HTML] [thehive-project/thehive](https://github.com/thehive-project/thehive) a Scalable, Open Source and Free Security Incident Response Platform -- [**1321**星][6m] [Go] [ssllabs/ssllabs-scan](https://github.com/ssllabs/ssllabs-scan) A command-line reference-implementation client for SSL Labs APIs, designed for automated and/or bulk testing. -- [**1321**星][1y] [C++] [rehints/hexrayscodexplorer](https://github.com/rehints/hexrayscodexplorer) 反编译插件, 多功能 +- [**1345**星][25d] [C] [x64dbg/x64dbgpy](https://github.com/x64dbg/x64dbgpy) Automating x64dbg using Python, Snapshots: +- [**1345**星][12d] [Go] [securitywithoutborders/hardentools](https://github.com/securitywithoutborders/hardentools) 禁用许多有危险的Windows功能 +- [**1344**星][23d] [Go] [microcosm-cc/bluemonday](https://github.com/microcosm-cc/bluemonday) a fast golang HTML sanitizer (inspired by the OWASP Java HTML Sanitizer) to scrub user generated content of XSS +- [**1343**星][23d] [Py] [s0md3v/arjun](https://github.com/s0md3v/Arjun) HTTP parameter discovery suite. +- [**1342**星][12m] [C] [luke-jr/bfgminer](https://github.com/luke-jr/bfgminer) Modular ASIC/FPGA miner written in C, featuring overclocking, monitoring, fan speed control and remote interface capabilities. +- [**1342**星][2m] [Go] [davrodpin/mole](https://github.com/davrodpin/mole) cli app to create ssh tunnels +- [**1342**星][1y] [Py] [carmaa/inception](https://github.com/carmaa/inception) 利用基于PCI的DMA实现物理内存的操纵与Hacking,可以攻击FireWire,Thunderbolt,ExpressCard,PC Card和任何其他PCI / PCIe硬件接口 +- [**1341**星][3m] [Py] [maratyszcza/peachpy](https://github.com/maratyszcza/peachpy) x86-64 assembler embedded in Python +- [**1341**星][1y] [XSLT] [api0cradle/lolbas](https://github.com/api0cradle/lolbas) Living Off The Land Binaries And Scripts - (LOLBins and LOLScripts) +- [**1340**星][1y] [kirikira/vtemplate](https://github.com/kirikira/vtemplate) v2ray的模板们 +- [**1340**星][7m] [Py] [feeicn/gsil](https://github.com/feeicn/gsil) GitHub敏感信息泄露监控,几乎实时监控,发送警告 +- [**1339**星][6y] [Perl] [intelisecurelabs/linux_exploit_suggester](https://github.com/InteliSecureLabs/Linux_Exploit_Suggester) Linux Exploit Suggester; based on operating system release number +- [**1338**星][1m] [CSS] [undeadsec/socialfish](https://github.com/undeadsec/socialfish) 网络钓鱼培训与信息收集 +- [**1337**星][1y] [C] [madeye/proxydroid](https://github.com/madeye/proxydroid) Global Proxy for Android +- [**1336**星][3m] [HTML] [thehive-project/thehive](https://github.com/thehive-project/thehive) a Scalable, Open Source and Free Security Incident Response Platform +- [**1335**星][2m] [C++] [mfontanini/libtins](https://github.com/mfontanini/libtins) High-level, multiplatform C++ network packet sniffing and crafting library. +- [**1334**星][4y] [mengskysama/shadowsocks](https://github.com/mengskysama/shadowsocks) A fast tunnel proxy that helps you bypass firewalls +- [**1333**星][1y] [C] [gamelinux/passivedns](https://github.com/gamelinux/passivedns) A network sniffer that logs all DNS server replies for use in a passive DNS setup +- [**1328**星][2d] [C++] [purplei2p/i2pd](https://github.com/purplei2p/i2pd) a full-featured C++ implementation of I2P client +- [**1328**星][1y] [Py] [marten4n6/evilosx](https://github.com/marten4n6/evilosx) An evil RAT (Remote Administration Tool) for macOS / OS X. +- [**1328**星][2y] [CoffeeScript] [atmos/camo](https://github.com/atmos/camo) all about making insecure assets look secure +- [**1327**星][7m] [Go] [ssllabs/ssllabs-scan](https://github.com/ssllabs/ssllabs-scan) A command-line reference-implementation client for SSL Labs APIs, designed for automated and/or bulk testing. +- [**1327**星][3d] [C] [intel/haxm](https://github.com/intel/haxm) Intel 开源的英特尔硬件加速执行管理器,通过硬件辅助的虚拟化引擎,加速 Windows/macOS 主机上的 IA emulation((x86/ x86_64) ) +- [**1327**星][10m] [C#] [cenmrev/v2rayw](https://github.com/cenmrev/v2rayw) GUI for v2ray-core on Windows +- [**1325**星][21d] [C] [dtag-dev-sec/tpotce](https://github.com/dtag-dev-sec/tpotce) 创建多蜜罐平台T-Pot ISO 镜像 +- [**1324**星][1y] [C++] [rehints/hexrayscodexplorer](https://github.com/rehints/hexrayscodexplorer) 反编译插件, 多功能
查看详情 @@ -932,97 +1003,26 @@
-- [**1318**星][2m] [jaredthecoder/awesome-vehicle-security](https://github.com/jaredthecoder/awesome-vehicle-security) -- [**1315**星][1y] [mortenoir1/virtualbox_e1000_0day](https://github.com/mortenoir1/virtualbox_e1000_0day) VirtualBox E1000 Guest-to-Host Escape -- [**1312**星][12d] [C] [oisf/suricata](https://github.com/OISF/suricata) a network IDS, IPS and NSM engine -- [**1311**星][2y] [Py] [worawit/ms17-010](https://github.com/worawit/ms17-010) MS17-010 -- [**1311**星][18d] [C] [intel/haxm](https://github.com/intel/haxm) Intel 开源的英特尔硬件加速执行管理器,通过硬件辅助的虚拟化引擎,加速 Windows/macOS 主机上的 IA emulation((x86/ x86_64) ) -- [**1310**星][3m] [PowerShell] [peewpw/invoke-psimage](https://github.com/peewpw/invoke-psimage) Encodes a PowerShell script in the pixels of a PNG file and generates a oneliner to execute -- [**1310**星][10m] [C] [fancycode/memorymodule](https://github.com/fancycode/memorymodule) Library to load a DLL from memory. -- [**1309**星][10m] [C#] [cenmrev/v2rayw](https://github.com/cenmrev/v2rayw) GUI for v2ray-core on Windows -- [**1305**星][12m] [Py] [xyntax/poc-t](https://github.com/xyntax/poc-t) 脚本调用框架,用于渗透测试中 采集|爬虫|爆破|批量PoC 等需要并发的任务 -- [**1305**星][3m] [Lua] [scipag/vulscan](https://github.com/scipag/vulscan) Nmap 模块,将 Nmap 转化为高级漏洞扫描器 -- [**1305**星][18d] [C] [dtag-dev-sec/tpotce](https://github.com/dtag-dev-sec/tpotce) 创建多蜜罐平台T-Pot ISO 镜像 -- [**1303**星][17d] [Py] [consensys/mythril](https://github.com/ConsenSys/mythril) Security analysis tool for EVM bytecode. Supports smart contracts built for Ethereum, Quorum, Vechain, Roostock, Tron and other EVM-compatible blockchains. -- [**1303**星][15d] [nikitavoloboev/privacy-respecting](https://github.com/nikitavoloboev/privacy-respecting) PrivacyRespecting 服务和软件列表 +- [**1323**星][2d] [Go] [xiaoming2028/freenet](https://github.com/xiaoming2028/freenet) 科学上网/梯子/自由上网/翻墙 SS/SSR/V2Ray/Brook 搭建教程 +- [**1323**星][2m] [jaredthecoder/awesome-vehicle-security](https://github.com/jaredthecoder/awesome-vehicle-security) +- [**1322**星][3d] [C] [oisf/suricata](https://github.com/OISF/suricata) a network IDS, IPS and NSM engine +- [**1319**星][2y] [Py] [worawit/ms17-010](https://github.com/worawit/ms17-010) MS17-010 +- [**1317**星][1y] [mortenoir1/virtualbox_e1000_0day](https://github.com/mortenoir1/virtualbox_e1000_0day) VirtualBox E1000 Guest-to-Host Escape +- [**1316**星][3m] [PS] [peewpw/invoke-psimage](https://github.com/peewpw/invoke-psimage) Encodes a PowerShell script in the pixels of a PNG file and generates a oneliner to execute +- [**1314**星][10m] [C] [fancycode/memorymodule](https://github.com/fancycode/memorymodule) Library to load a DLL from memory. +- [**1311**星][1m] [C++] [shadowsocks/libqtshadowsocks](https://github.com/shadowsocks/libqtshadowsocks) A lightweight and ultra-fast shadowsocks library written in C++14 with Qt framework +- [**1309**星][12m] [Py] [xyntax/poc-t](https://github.com/xyntax/poc-t) 脚本调用框架,用于渗透测试中 采集|爬虫|爆破|批量PoC 等需要并发的任务 +- [**1309**星][3m] [Lua] [scipag/vulscan](https://github.com/scipag/vulscan) Nmap 模块,将 Nmap 转化为高级漏洞扫描器 +- [**1307**星][19d] [Py] [consensys/mythril](https://github.com/ConsenSys/mythril) Security analysis tool for EVM bytecode. Supports smart contracts built for Ethereum, Quorum, Vechain, Roostock, Tron and other EVM-compatible blockchains. +- [**1307**星][27d] [C] [boywhp/fcn](https://github.com/boywhp/fcn) free connect your private network from anywhere +- [**1304**星][17d] [nikitavoloboev/privacy-respecting](https://github.com/nikitavoloboev/privacy-respecting) PrivacyRespecting 服务和软件列表 +- [**1304**星][7d] [C] [cisco-talos/pyrebox](https://github.com/cisco-talos/pyrebox) 逆向沙箱,基于QEMU,Python Scriptable - [**1303**星][4m] [C++] [klee/klee](https://github.com/klee/klee) 基于 LLVM 的 symbolic 虚拟机 -- [**1300**星][18d] [C] [cisco-talos/pyrebox](https://github.com/cisco-talos/pyrebox) 逆向沙箱,基于QEMU,Python Scriptable -- [**1297**星][1y] [Go] [evilsocket/xray](https://github.com/evilsocket/xray) 自动化执行一些信息收集、网络映射的初始化工作 -- [**1293**星][1y] [Shell] [dana-at-cp/backdoor-apk](https://github.com/dana-at-cp/backdoor-apk) backdoor-apk is a shell script that simplifies the process of adding a backdoor to any Android APK file. Users of this shell script should have working knowledge of Linux, Bash, Metasploit, Apktool, the Android SDK, smali, etc. This shell script is provided as-is without warranty of any kind and is intended for educational purposes only. -- [**1291**星][27d] [Java] [android-hacker/exposed](https://github.com/android-hacker/exposed) A library to use Xposed without root or recovery(or modify system image etc..). -- [**1290**星][2y] [Go] [malfunkt/hyperfox](https://github.com/malfunkt/hyperfox) 在局域网上代理和记录 HTTP 和 HTTPs 通信 -- [**1289**星][2m] [C] [traviscross/mtr](https://github.com/traviscross/mtr) Official repository for mtr, a network diagnostic tool -- [**1288**星][4y] [C++] [microsoft/microsoft-pdb](https://github.com/microsoft/microsoft-pdb) Microsoft提供的有关PDB格式的信息 -- [**1287**星][19d] [JS] [icymind/vrouter](https://github.com/icymind/vrouter) 一个基于 VirtualBox 和 openwrt 构建的项目, 旨在实现 macOS / Windows 平台的透明代理. -- [**1284**星][2m] [Py] [virtualabs/btlejack](https://github.com/virtualabs/btlejack) Bluetooth Low Energy Swiss-army knife -- [**1284**星][5m] [JS] [feross/spoof](https://github.com/feross/spoof) Easily spoof your MAC address in macOS, Windows, & Linux! -- [**1278**星][9m] [michalmalik/linux-re-101](https://github.com/michalmalik/linux-re-101) Linux逆向资源收集 -- [**1278**星][4y] [Py] [elvanderb/tcp-32764](https://github.com/elvanderb/tcp-32764) some codes and notes about the backdoor listening on TCP-32764 in linksys WAG200G. -- [**1277**星][10d] [PHP] [friendsofphp/security-advisories](https://github.com/friendsofphp/security-advisories) A database of PHP security advisories -- [**1277**星][27d] [Go] [dreadl0ck/netcap](https://github.com/dreadl0ck/netcap) A framework for secure and scalable network traffic analysis - -- [**1275**星][24d] [Py] [viper-framework/viper](https://github.com/viper-framework/viper) Binary analysis and management framework -- [**1273**星][1m] [Py] [pyauth/pyotp](https://github.com/pyauth/pyotp) Python One-Time Password Library -- [**1273**星][2m] [Py] [codingo/reconnoitre](https://github.com/codingo/reconnoitre) A security tool for multithreaded information gathering and service enumeration whilst building directory structures to store results, along with writing out recommendations for further testing. -- [**1272**星][1y] [JS] [sakurity/securelogin](https://github.com/sakurity/securelogin) 针对网站和App的去中心化的认证协议 -- [**1270**星][2m] [C] [seemoo-lab/nexmon](https://github.com/seemoo-lab/nexmon) The C-based Firmware Patching Framework for Broadcom/Cypress WiFi Chips that enables Monitor Mode, Frame Injection and much more -- [**1270**星][1y] [PowerShell] [dafthack/mailsniper](https://github.com/dafthack/mailsniper) 在Microsoft Exchange环境中搜索邮件中包含的指定内容:密码、insider intel、网络架构信息等 -- [**1270**星][1m] [Py] [bethgelab/foolbox](https://github.com/bethgelab/foolbox) Python toolbox to create adversarial examples that fool neural networks in PyTorch, TensorFlow, Keras, … -- [**1268**星][2m] [Java] [googlearchive/android-runtimepermissions](https://github.com/googlearchive/android-RuntimePermissions) This sample has been deprecated/archived. Check this repo for related samples: -- [**1268**星][1y] [Py] [ethereum/pyethapp](https://github.com/ethereum/pyethapp) -- [**1266**星][2m] [Py] [ganapati/rsactftool](https://github.com/ganapati/rsactftool) RSA攻击工具,主要用于CTF,从弱公钥和/或uncipher数据中回复私钥 -- [**1265**星][9d] [Shell] [firehol/blocklist-ipsets](https://github.com/firehol/blocklist-ipsets) ipsets dynamically updated with firehol's update-ipsets.sh script -- [**1265**星][9d] [Shell] [firehol/blocklist-ipsets](https://github.com/firehol/blocklist-ipsets) ipsets dynamically updated with firehol's update-ipsets.sh script -- [**1262**星][3m] [Go] [solo-io/squash](https://github.com/solo-io/squash) The debugger for microservices -- [**1261**星][3m] [Py] [alessandroz/beroot](https://github.com/alessandroz/beroot) Privilege Escalation Project - Windows / Linux / Mac -- [**1259**星][11m] [Py] [unapibageek/ctfr](https://github.com/unapibageek/ctfr) Abusing Certificate Transparency logs for getting HTTPS websites subdomains. -- [**1255**星][7m] [PHP] [ganlvtech/down_52pojie_cn](https://github.com/ganlvtech/down_52pojie_cn) A single page file explorer that can be hosted on static website. 吾爱破解论坛 爱盘 -- [**1255**星][13d] [C] [aircrack-ng/aircrack-ng](https://github.com/aircrack-ng/aircrack-ng) WiFi security auditing tools suite -- [**1253**星][2y] [JS] [samyk/skyjack](https://github.com/samyk/skyjack) A drone engineered to autonomously seek out, hack, and wirelessly take full control over any other Parrot or 3DR drones within wireless or flying distance, creating an army of zombie drones under your control. -- [**1250**星][1m] [PowerShell] [hak5/bashbunny-payloads](https://github.com/hak5/bashbunny-payloads) The Official Bash Bunny Payload Repository -- [**1248**星][2y] [Py] [vaguileradiaz/tinfoleak](https://github.com/vaguileradiaz/tinfoleak) Twitter 智能分析工具 -- [**1248**星][4m] [JS] [bubenshchykov/ngrok](https://github.com/bubenshchykov/ngrok) Expose your localhost to the web. Node wrapper for ngrok. -- [**1245**星][2m] [Go] [xiaoming2028/freenet](https://github.com/xiaoming2028/freenet) 科学上网/梯子/自由上网/翻墙 SSR/V2Ray/Brook 最全搭建教程 -- [**1245**星][15d] [JS] [archerysec/archerysec](https://github.com/archerysec/archerysec) Centralize Vulnerability Assessment and Management for DevSecOps Team -- [**1244**星][2y] [Objective-C] [krausefx/detect.location](https://github.com/krausefx/detect.location) An easy way to access the user's iOS location data without actually having access -- [**1242**星][4y] [firesuncn/bluelotus_xssreceiver](https://github.com/firesuncn/bluelotus_xssreceiver) XSS平台 CTF工具 Web安全工具 -- [**1242**星][1m] [Vue] [chaitin/passionfruit](https://github.com/chaitin/passionfruit) iOSapp 黑盒评估工具。功能丰富,自带基于web的 GUI -- [**1241**星][1y] [Ruby] [eliotsykes/rails-security-checklist](https://github.com/eliotsykes/rails-security-checklist) -- [**1240**星][10m] [C] [a0rtega/pafish](https://github.com/a0rtega/pafish) Pafish is a demonstration tool that employs several techniques to detect sandboxes and analysis environments in the same way as malware families do. -- [**1239**星][2m] [michalmalik/osx-re-101](https://github.com/michalmalik/osx-re-101) OSX/iOS逆向资源收集 -- [**1235**星][1m] [Go] [hacklcx/hfish](https://github.com/hacklcx/hfish) 扩展企业安全测试主动诱导型开源蜜罐框架系统,记录黑客攻击手段 -- [**1235**星][2m] [Go] [google/martian](https://github.com/google/martian) Martian is a library for building custom HTTP/S proxies -- [**1232**星][3m] [Shell] [rootsongjc/kubernetes-vagrant-centos-cluster](https://github.com/rootsongjc/kubernetes-vagrant-centos-cluster) Setting up a distributed Kubernetes cluster along with Istio service mesh locally with Vagrant and VirtualBox, only PoC or Demo use. -- [**1231**星][3y] [Py] [desaster/kippo](https://github.com/desaster/kippo) Kippo - SSH Honeypot -- [**1230**星][7d] [Shell] [mitchellkrogza/nginx-ultimate-bad-bot-blocker](https://github.com/mitchellkrogza/nginx-ultimate-bad-bot-blocker) Nginx Block Bad Bots, Spam Referrer Blocker, Vulnerability Scanners, User-Agents, Malware, Adware, Ransomware, Malicious Sites, with anti-DDOS, Wordpress Theme Detector Blocking and Fail2Ban Jail for Repeat Offenders -- [**1230**星][5m] [chalker/notes](https://github.com/chalker/notes) Some public notes -- [**1228**星][1y] [Kotlin] [gh0u1l5/wechatspellbook](https://github.com/gh0u1l5/wechatspellbook) 一个使用Kotlin编写的开源微信插件框架,底层需要 Xposed 或 VirtualXposed 等Hooking框架的支持,而顶层可以轻松对接Java、Kotlin、Scala等JVM系语言。让程序员能够在几分钟内编写出简单的微信插件,随意揉捏微信的内部逻辑。 -- [**1228**星][8m] [Py] [flipkart-incubator/astra](https://github.com/flipkart-incubator/astra) 自动化的REST API安全测试脚本 -- [**1224**星][1m] [C] [datatheorem/trustkit](https://github.com/datatheorem/trustkit) Easy SSL pinning validation and reporting for iOS, macOS, tvOS and watchOS. -- [**1223**星][3y] [CoffeeScript] [shadowsocks/shadowsocks-nodejs](https://github.com/shadowsocks/shadowsocks-nodejs) -- [**1222**星][3y] [C] [tsudakageyu/minhook](https://github.com/tsudakageyu/minhook) The Minimalistic x86/x64 API Hooking Library for Windows -- [**1222**星][27d] [C++] [nasa-sw-vnv/ikos](https://github.com/nasa-sw-vnv/ikos) Static analyzer for C/C++ based on the theory of Abstract Interpretation. -- [**1222**星][1y] [Py] [danmcinerney/net-creds](https://github.com/danmcinerney/net-creds) Sniffs sensitive data from interface or pcap -- [**1220**星][1y] [Go] [cloudflare/redoctober](https://github.com/cloudflare/redoctober) Go server for two-man rule style file encryption and decryption. -- [**1219**星][5y] [cure53/xsschallengewiki](https://github.com/cure53/XSSChallengeWiki) Welcome to the XSS Challenge Wiki! -- [**1219**星][4m] [Py] [owtf/owtf](https://github.com/owtf/owtf) 进攻性 Web 测试框架。着重于 OWASP + PTES,尝试统合强大的工具,提高渗透测试的效率。大部分以Python 编写 -- [**1218**星][11d] [Py] [google/timesketch](https://github.com/google/timesketch) Collaborative forensic timeline analysis -- [**1218**星][26d] [Java] [find-sec-bugs/find-sec-bugs](https://github.com/find-sec-bugs/find-sec-bugs) The SpotBugs plugin for security audits of Java web applications and Android applications. (Also work with Kotlin, Groovy and Scala projects) -- [**1218**星][5y] [cure53/xsschallengewiki](https://github.com/cure53/xsschallengewiki) Welcome to the XSS Challenge Wiki! -- [**1217**星][1y] [C#] [cn33liz/p0wnedshell](https://github.com/cn33liz/p0wnedshell) PowerShell Runspace Post Exploitation Toolkit -- [**1216**星][26d] [Go] [jsha/minica](https://github.com/jsha/minica) minica is a small, simple CA intended for use in situations where the CA operator also operates each host where a certificate will be used. -- [**1212**星][10d] [C] [dynamorio/dynamorio](https://github.com/dynamorio/dynamorio) Dynamic Instrumentation Tool Platform -- [**1207**星][8d] [JS] [jpcertcc/logontracer](https://github.com/jpcertcc/logontracer) 通过可视化和分析Windows事件日志来调查恶意的Windows登录 -- [**1205**星][3m] [Java] [javiersantos/piracychecker](https://github.com/javiersantos/piracychecker) An Android library that prevents your app from being pirated / cracked using Google Play Licensing (LVL), APK signature protection and more. API 14+ required. -- [**1204**星][7d] [Objective-C] [onionbrowser/onionbrowser](https://github.com/onionbrowser/onionbrowser) An open-source, privacy-enhancing web browser for iOS, utilizing the Tor anonymity network -- [**1204**星][3m] [JS] [davidbau/seedrandom](https://github.com/davidbau/seedrandom) seeded random number generator for Javascript -- [**1203**星][30d] [Py] [codingo/nosqlmap](https://github.com/codingo/NoSQLMap) Automated NoSQL database enumeration and web application exploitation tool. -- [**1201**星][7d] [Java] [linkedin/dexmaker](https://github.com/linkedin/dexmaker) A utility for doing compile or runtime code generation targeting Android's Dalvik VM -- [**1200**星][3m] [C] [droe/sslsplit](https://github.com/droe/sslsplit) 透明SSL/TLS拦截 -- [**1199**星][1y] [felixgr/secure-ios-app-dev](https://github.com/felixgr/secure-ios-app-dev) iOSApp 最常见漏洞收集 -- [**1198**星][24d] [Py] [thekingofduck/fuzzdicts](https://github.com/thekingofduck/fuzzdicts) Web Pentesting Fuzz 字典,一个就够了。 -- [**1196**星][1y] [Go] [rancher/convoy](https://github.com/rancher/convoy) A Docker volume plugin, managing persistent container volumes. -- [**1194**星][2y] [C] [saminiir/level-ip](https://github.com/saminiir/level-ip) a Linux userspace TCP/IP stack, implemented with TUN/TAP devices. -- [**1194**星][7m] [riusksk/secbook](https://github.com/riusksk/secbook) 信息安全从业者书单推荐 -- [**1193**星][18d] [Py] [cve-search/cve-search](https://github.com/cve-search/cve-search) 导入CVE/CPE 到本地 MongoDB 数据库,以便后续在本地进行搜索和处理 -- [**1192**星][17d] [YARA] [horsicq/detect-it-easy](https://github.com/horsicq/detect-it-easy) Program for determining types of files for Windows, Linux and MacOS. -- [**1191**星][6y] [gdbinit/gdbinit](https://github.com/gdbinit/gdbinit) Gdbinit for OS X, iOS and others - x86, x86_64 and ARM \ No newline at end of file +- [**1300**星][1y] [Shell] [dana-at-cp/backdoor-apk](https://github.com/dana-at-cp/backdoor-apk) backdoor-apk is a shell script that simplifies the process of adding a backdoor to any Android APK file. Users of this shell script should have working knowledge of Linux, Bash, Metasploit, Apktool, the Android SDK, smali, etc. This shell script is provided as-is without warranty of any kind and is intended for educational purposes only. +- [**1299**星][6d] [Go] [hacklcx/hfish](https://github.com/hacklcx/hfish) 扩展企业安全测试主动诱导型开源蜜罐框架系统,记录黑客攻击手段 +- [**1298**星][1y] [Go] [evilsocket/xray](https://github.com/evilsocket/xray) 自动化执行一些信息收集、网络映射的初始化工作 +- [**1293**星][4y] [C++] [microsoft/microsoft-pdb](https://github.com/microsoft/microsoft-pdb) Microsoft提供的有关PDB格式的信息 +- [**1293**星][5m] [JS] [feross/spoof](https://github.com/feross/spoof) Easily spoof your MAC address in macOS, Windows, & Linux! +- [**1293**星][29d] [Java] [android-hacker/exposed](https://github.com/android-hacker/exposed) A library to use Xposed without root or recovery(or modify system image etc..). +- [**1291**星][6d] [C] [traviscross/mtr](https://github.com/traviscross/mtr) Official repository for mtr, a network diagnostic tool +- [**1291**星][2y] [Go] [malfunkt/hyperfox](https://github.com/malfunkt/hyperfox) 在局域网上代理和记录 HTTP 和 HTTPs 通信 \ No newline at end of file diff --git a/Readme_en.md b/Readme_en.md index ed65ea5..f6b74df 100644 --- a/Readme_en.md +++ b/Readme_en.md @@ -3,924 +3,995 @@ - Because Github can not show all lines, this page only show the first 1000 tools sorted by star count. [Read Full Version Here](https://github.com/alphaSeclab/sec-tool-list/blob/master/Readme_full_en.md) # Tool List -- [**34521**Star][14d] [C++] [x64dbg/x64dbg](https://github.com/x64dbg/x64dbg) An open-source x64/x32 debugger for windows. -- [**33781**Star][8d] [Py] [minimaxir/big-list-of-naughty-strings](https://github.com/minimaxir/big-list-of-naughty-strings) The Big List of Naughty Strings is a list of strings which have a high probability of causing issues when used as user-input data. -- [**32724**Star][2m] [hack-with-github/awesome-hacking](https://github.com/hack-with-github/awesome-hacking) A collection of various awesome lists for hackers, pentesters and security researchers -- [**30396**Star][12d] [Go] [fatedier/frp](https://github.com/fatedier/frp) A fast reverse proxy to help you expose a local server behind a NAT or firewall to the internet. -- [**25942**Star][7d] [Py] [certbot/certbot](https://github.com/certbot/certbot) Certbot is EFF's tool to obtain certs from Let's Encrypt and (optionally) auto-enable HTTPS on your server. It can also act as a client for any other CA that uses the ACME protocol. -- [**25522**Star][26d] [Swift] [shadowsocks/shadowsocksx-ng](https://github.com/shadowsocks/shadowsocksx-ng) Next Generation of ShadowsocksX -- [**25087**Star][13d] [Go] [v2ray/v2ray-core](https://github.com/v2ray/v2ray-core) A platform for building proxies to bypass network restrictions. -- [**24589**Star][7d] [trimstray/the-book-of-secret-knowledge](https://github.com/trimstray/the-book-of-secret-knowledge) A collection of inspiring lists, manuals, cheatsheets, blogs, hacks, one-liners, cli/web tools and more. -- [**22517**Star][12d] [Shell] [mathiasbynens/dotfiles](https://github.com/mathiasbynens/dotfiles) -- [**21751**Star][7d] [PHP] [danielmiessler/seclists](https://github.com/danielmiessler/seclists) SecLists is the security tester's companion. It's a collection of multiple types of lists used during security assessments, collected in one place. List types include usernames, passwords, URLs, sensitive data patterns, fuzzing payloads, web shells, and many more. -- [**21668**Star][10d] [Go] [filosottile/mkcert](https://github.com/filosottile/mkcert) A simple zero-config tool to make locally trusted development certificates with any names you'd like. -- [**20619**Star][9d] [Java] [skylot/jadx](https://github.com/skylot/jadx) Dex to Java decompiler -- [**20089**Star][2m] [Shell] [streisandeffect/streisand](https://github.com/StreisandEffect/streisand) Streisand sets up a new server running your choice of WireGuard, OpenConnect, OpenSSH, OpenVPN, Shadowsocks, sslh, Stunnel, or a Tor bridge. It also generates custom instructions for all of these services. At the end of the run you are given an HTML file with instructions that can be shared with friends, family members, and fellow activists. -- [**19651**Star][2m] [Jupyter Notebook] [camdavidsonpilon/probabilistic-programming-and-bayesian-methods-for-hackers](https://github.com/camdavidsonpilon/probabilistic-programming-and-bayesian-methods-for-hackers) aka "Bayesian Methods for Hackers": An introduction to Bayesian methods + probabilistic programming with a computation/understanding-first, mathematics-second point of view. All in pure Python ;) -- [**18996**Star][7d] [Ruby] [rapid7/metasploit-framework](https://github.com/rapid7/metasploit-framework) Metasploit Framework -- [**18648**Star][3y] [fallibleinc/security-guide-for-developers](https://github.com/fallibleinc/security-guide-for-developers) Security Guide for Developers (实用性开发人员安全须知) -- [**18381**Star][7d] [Java] [nationalsecurityagency/ghidra](https://github.com/nationalsecurityagency/ghidra) Ghidra is a software reverse engineering (SRE) framework -- [**18220**Star][8d] [Java] [alibaba/arthas](https://github.com/alibaba/arthas) Alibaba Java Diagnostic Tool Arthas -- [**17555**Star][4y] [Go] [inconshreveable/ngrok](https://github.com/inconshreveable/ngrok) Introspected tunnels to localhost -- [**16951**Star][14d] [Py] [mitmproxy/mitmproxy](https://github.com/mitmproxy/mitmproxy) An interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers. -- [**16681**Star][7d] [C#] [powershell/powershell](https://github.com/powershell/powershell) PowerShell for every system! -- [**15756**Star][8d] [Py] [sqlmapproject/sqlmap](https://github.com/sqlmapproject/sqlmap) Automatic SQL injection and database takeover tool -- [**15694**Star][9m] [micropoor/micro8](https://github.com/micropoor/micro8) Gitbook -- [**15627**Star][7d] [C] [curl/curl](https://github.com/curl/curl) A command line tool and library for transferring data with URL syntax, supporting HTTP, HTTPS, FTP, FTPS, GOPHER, TFTP, SCP, SFTP, SMB, TELNET, DICT, LDAP, LDAPS, FILE, IMAP, SMTP, POP3, RTSP and RTMP. libcurl offers a myriad of powerful features -- [**14661**Star][1m] [gfwlist/gfwlist](https://github.com/gfwlist/gfwlist) gfwlist -- [**14478**Star][26d] [Java] [tencent/tinker](https://github.com/tencent/tinker) Tinker is a hot-fix solution library for Android, it supports dex, library and resources update without reinstall apk. -- [**13627**Star][9m] [JS] [bannedbook/fanqiang](https://github.com/bannedbook/fanqiang) 翻墙-科学上网 -- [**13183**Star][26d] [Py] [corentinj/real-time-voice-cloning](https://github.com/corentinj/real-time-voice-cloning) Clone a voice in 5 seconds to generate arbitrary speech in real-time -- [**13081**Star][17d] [Go] [jesseduffield/lazydocker](https://github.com/jesseduffield/lazydocker) The lazier way to manage everything docker -- [**12920**Star][10d] [Py] [cool-rr/pysnooper](https://github.com/cool-rr/pysnooper) Never use print for debugging again -- [**12641**Star][9d] [C] [shadowsocks/shadowsocks-libev](https://github.com/shadowsocks/shadowsocks-libev) libev port of shadowsocks -- [**12453**Star][7d] [C#] [0xd4d/dnspy](https://github.com/0xd4d/dnspy) .NET debugger and assembly editor -- [**12203**Star][14d] [Java] [signalapp/signal-android](https://github.com/signalapp/Signal-Android) A private messenger for Android. -- [**11935**Star][1m] [Go] [buger/goreplay](https://github.com/buger/goreplay) capturing and replaying live HTTP traffic into a test environment in order to continuously test your system with real data. It can be used to increase confidence in code deployments, configuration changes and infrastructure changes. -- [**11829**Star][17d] [C] [openssl/openssl](https://github.com/openssl/openssl) TLS/SSL and crypto library -- [**11490**Star][7d] [C] [radareorg/radare2](https://github.com/radareorg/radare2) unix-like reverse engineering framework and commandline tools -- [**11361**Star][3m] [C] [robertdavidgraham/masscan](https://github.com/robertdavidgraham/masscan) TCP port scanner, spews SYN packets asynchronously, scanning entire Internet in under 5 minutes. -- [**11246**Star][1m] [facert/awesome-spider](https://github.com/facert/awesome-spider) 爬虫集合 -- [**11225**Star][13d] [getlantern/download](https://github.com/getlantern/download) Lantern官方版本下载 蓝灯 翻墙 科学上网 外网 加速器 梯子 路由 -- [**11174**Star][7d] [Java] [oracle/graal](https://github.com/oracle/graal) Run Programs Faster Anywhere -- [**11106**Star][2m] [Jupyter Notebook] [selfteaching/the-craft-of-selfteaching](https://github.com/selfteaching/the-craft-of-selfteaching) One has no future if one couldn't teach themself. -- [**11047**Star][7d] [Py] [swisskyrepo/payloadsallthethings](https://github.com/swisskyrepo/payloadsallthethings) A list of useful payloads and bypass for Web Application Security and Pentest/CTF -- [**11013**Star][2y] [Objective-C] [bang590/jspatch](https://github.com/bang590/jspatch) JSPatch bridge Objective-C and Javascript using the Objective-C runtime. You can call any Objective-C class and method in JavaScript by just including a small engine. JSPatch is generally used to hotfix iOS App. -- [**11008**Star][8d] [Py] [owasp/cheatsheetseries](https://github.com/owasp/cheatsheetseries) The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics. -- [**10902**Star][12d] [Objective-C] [flipboard/flex](https://github.com/flipboard/flex) An in-app debugging and exploration tool for iOS -- [**10886**Star][2m] [CSS] [hacker0x01/hacker101](https://github.com/hacker0x01/hacker101) Hacker101 -- [**10761**Star][2y] [CoffeeScript] [dropbox/zxcvbn](https://github.com/dropbox/zxcvbn) Low-Budget Password Strength Estimation -- [**10742**Star][13d] [enaqx/awesome-pentest](https://github.com/enaqx/awesome-pentest) A collection of awesome penetration testing resources, tools and other shiny things -- [**10738**Star][17d] [Java] [konloch/bytecode-viewer](https://github.com/konloch/bytecode-viewer) A Java 8+ Jar & Android APK Reverse Engineering Suite (Decompiler, Editor, Debugger & More) -- [**10107**Star][8d] [Go] [goharbor/harbor](https://github.com/goharbor/harbor) An open source trusted cloud native registry project that stores, signs, and scans content. -- [**9844**Star][11d] [ruanyf/weekly](https://github.com/ruanyf/weekly) 科技爱好者周刊,每周五发布 -- [**9804**Star][8m] [imthenachoman/how-to-secure-a-linux-server](https://github.com/imthenachoman/how-to-secure-a-linux-server) An evolving how-to guide for securing a Linux server. -- [**9349**Star][12d] [Ruby] [postalhq/postal](https://github.com/postalhq/postal) complete and fully featured mail server for use by websites & web servers -- [**9229**Star][3m] [JS] [localtunnel/localtunnel](https://github.com/localtunnel/localtunnel) expose yourself -- [**9182**Star][8d] [Go] [cnlh/nps](https://github.com/cnlh/nps) 一款轻量级、功能强大的内网穿透代理服务器。支持tcp、udp流量转发,支持内网http代理、内网socks5代理,同时支持snappy压缩、站点保护、加密传输、多路复用、header修改等。支持web图形化管理,集成多用户模式。 -- [**9178**Star][10d] [Java] [ibotpeaches/apktool](https://github.com/ibotpeaches/apktool) A tool for reverse engineering Android apk files -- [**9141**Star][8d] [C#] [icsharpcode/ilspy](https://github.com/icsharpcode/ilspy) .NET Decompiler -- [**9064**Star][27d] [JS] [valve/fingerprintjs2](https://github.com/valve/fingerprintjs2) Modern & flexible browser fingerprinting library -- [**9003**Star][9d] [PowerShell] [lukesampson/scoop](https://github.com/lukesampson/scoop) A command-line installer for Windows. -- [**8995**Star][2m] [vitalysim/awesome-hacking-resources](https://github.com/vitalysim/awesome-hacking-resources) A collection of hacking / penetration testing resources to make you better! -- [**8988**Star][9d] [Py] [sherlock-project/sherlock](https://github.com/sherlock-project/sherlock) Find Usernames Across Social Networks -- [**8847**Star][6m] [Go] [rkt/rkt](https://github.com/rkt/rkt) rkt is a pod-native container engine for Linux. It is composable, secure, and built on standards. -- [**8712**Star][15d] [C] [gentilkiwi/mimikatz](https://github.com/gentilkiwi/mimikatz) A little tool to play with Windows security -- [**8597**Star][26d] [Java] [android-hacker/virtualxposed](https://github.com/android-hacker/virtualxposed) A simple app to use Xposed without root, unlock the bootloader or modify system image, etc. -- [**8495**Star][1m] [microsoft/wsl](https://github.com/microsoft/WSL) Issues found on WSL -- [**8408**Star][2y] [brannondorsey/wifi-cracking](https://github.com/brannondorsey/wifi-cracking) Crack WPA/WPA2 Wi-Fi Routers with Airodump-ng and Aircrack-ng/Hashcat -- [**8399**Star][27d] [Py] [wifiphisher/wifiphisher](https://github.com/wifiphisher/wifiphisher) 流氓AP框架, 用于RedTeam和Wi-Fi安全测试 -- [**8033**Star][7d] [trimstray/the-practical-linux-hardening-guide](https://github.com/trimstray/the-practical-linux-hardening-guide) This guide details creating a secure Linux production system. OpenSCAP (C2S/CIS, STIG). -- [**7992**Star][2m] [Py] [facebook/chisel](https://github.com/facebook/chisel) Chisel is a collection of LLDB commands to assist debugging iOS apps. -- [**7952**Star][3y] [Go] [cyfdecyf/cow](https://github.com/cyfdecyf/cow) HTTP proxy written in Go. COW can automatically identify blocked sites and use parent proxies to access. -- [**7936**Star][4y] [Objective-C] [shadowsocks/shadowsocks-ios](https://github.com/shadowsocks/shadowsocks-ios) Removed according to regulations. -- [**7806**Star][3m] [C++] [shiqiyu/libfacedetection](https://github.com/shiqiyu/libfacedetection) An open source library for face detection in images. The face detection speed can reach 1500FPS. -- [**7696**Star][7d] [JS] [gchq/cyberchef](https://github.com/gchq/cyberchef) The Cyber Swiss Army Knife - a web app for encryption, encoding, compression and data analysis -- [**7685**Star][7d] [Go] [git-lfs/git-lfs](https://github.com/git-lfs/git-lfs) Git extension for versioning large files -- [**7628**Star][22d] [Java] [java-decompiler/jd-gui](https://github.com/java-decompiler/jd-gui) A standalone Java Decompiler GUI -- [**7498**Star][27d] [Py] [threat9/routersploit](https://github.com/threat9/routersploit) Exploitation Framework for Embedded Devices -- [**7371**Star][12d] [Go] [snail007/goproxy](https://github.com/snail007/goproxy) Proxy是高性能全功能的http代理、https代理、socks5代理、内网穿透、内网穿透p2p、内网穿透代理、内网穿透反向代理、内网穿透服务器、Websocket代理、TCP代理、UDP代理、DNS代理、DNS加密代理,代理API认证,全能跨平台代理服务器。 -- [**7365**Star][1m] [Py] [s0md3v/xsstrike](https://github.com/s0md3v/XSStrike) Most advanced XSS scanner. -- [**7205**Star][17d] [Java] [lionsoul2014/ip2region](https://github.com/lionsoul2014/ip2region) Ip2region is a offline IP location library with accuracy rate of 99.9% and 0.0x millseconds searching performance. DB file is less then 5Mb with all ip address stored. binding for Java,PHP,C,Python,Nodejs,Golang,C#,lua. Binary,B-tree,Memory searching algorithm -- [**7174**Star][7m] [Shell] [teddysun/shadowsocks_install](https://github.com/teddysun/shadowsocks_install) Auto Install Shadowsocks Server for CentOS/Debian/Ubuntu -- [**6994**Star][14d] [Go] [future-architect/vuls](https://github.com/future-architect/vuls) Agent-less vulnerability scanner for Linux, FreeBSD, Container Image, Running Container, WordPress, Programming language libraries, Network devices -- [**6968**Star][2m] [JS] [cs01/gdbgui](https://github.com/cs01/gdbgui) Browser-based frontend to gdb (gnu debugger). Add breakpoints, view the stack, visualize data structures, and more in C, C++, Go, Rust, and Fortran. Run gdbgui from the terminal and a new tab will open in your browser. -- [**6956**Star][10d] [C] [hashcat/hashcat](https://github.com/hashcat/hashcat) World's fastest and most advanced password recovery utility -- [**6954**Star][13d] [Go] [nats-io/nats-server](https://github.com/nats-io/nats-server) High-Performance server for NATS, the cloud native messaging system. -- [**6950**Star][9d] [greatfire/wiki](https://github.com/greatfire/wiki) 自由浏览 -- [**6917**Star][3m] [Java] [pxb1988/dex2jar](https://github.com/pxb1988/dex2jar) Tools to work with android .dex and java .class files -- [**6844**Star][2m] [Go] [sqshq/sampler](https://github.com/sqshq/sampler) A tool for shell commands execution, visualization and alerting. Configured with a simple YAML file. -- [**6788**Star][17d] [Shell] [awslabs/git-secrets](https://github.com/awslabs/git-secrets) Prevents you from committing secrets and credentials into git repositories -- [**6708**Star][9m] [Java] [amitshekhariitbhu/android-debug-database](https://github.com/amitshekhariitbhu/android-debug-database) A library for debugging android databases and shared preferences - Make Debugging Great Again -- [**6678**Star][3y] [C++] [alibaba/andfix](https://github.com/alibaba/andfix) AndFix is a library that offer hot-fix for Android App. -- [**6639**Star][9d] [Java] [zaproxy/zaproxy](https://github.com/zaproxy/zaproxy) The OWASP ZAP core project -- [**6557**Star][11d] [Py] [networkx/networkx](https://github.com/networkx/networkx) Official NetworkX source code repository. -- [**6455**Star][1m] [Py] [h2y/shadowrocket-adblock-rules](https://github.com/h2y/shadowrocket-adblock-rules) 提供多款 Shadowrocket 规则,带广告过滤功能。用于 iOS 未越狱设备选择性地自动翻墙。 -- [**6449**Star][11d] [Shell] [cisofy/lynis](https://github.com/cisofy/lynis) Security auditing tool for Linux, macOS, and UNIX-based systems. Assists with compliance testing (HIPAA/ISO27001/PCI DSS) and system hardening. Agentless, and installation optional. -- [**6440**Star][9m] [HTML] [open-power-workgroup/hospital](https://github.com/open-power-workgroup/hospital) OpenPower工作组收集汇总的医院开放数据 -- [**6413**Star][15d] [Go] [bettercap/bettercap](https://github.com/bettercap/bettercap) The Swiss Army knife for 802.11, BLE and Ethernet networks reconnaissance and MITM attacks. -- [**6284**Star][27d] [Py] [seatgeek/fuzzywuzzy](https://github.com/seatgeek/fuzzywuzzy) Fuzzy String Matching in Python -- [**6182**Star][2m] [Py] [yandex/gixy](https://github.com/yandex/gixy) Nginx configuration static analyzer -- [**6170**Star][6m] [rmerl/asuswrt-merlin](https://github.com/rmerl/asuswrt-merlin) Enhanced version of Asus's router firmware (Asuswrt) (legacy code base) -- [**6158**Star][3y] [PowerShell] [powershellmafia/powersploit](https://github.com/PowerShellMafia/PowerSploit) PowerSploit - A PowerShell Post-Exploitation Framework -- [**6130**Star][1y] [Hack] [facebook/fbctf](https://github.com/facebook/fbctf) Platform to host Capture the Flag competitions -- [**6124**Star][9m] [Py] [schollz/howmanypeoplearearound](https://github.com/schollz/howmanypeoplearearound) Count the number of people around you -- [**6100**Star][7d] [JS] [avwo/whistle](https://github.com/avwo/whistle) HTTP, HTTP2, HTTPS, Websocket debugging proxy -- [**6061**Star][2y] [C] [jgamblin/mirai-source-code](https://github.com/jgamblin/mirai-source-code) Leaked Mirai Source Code for Research/IoC Development Purposes -- [**6025**Star][14d] [Go] [quay/clair](https://github.com/quay/clair) Vulnerability Static Analysis for Containers -- [**6025**Star][14d] [Go] [quay/clair](https://github.com/quay/clair) Vulnerability Static Analysis for Containers -- [**6002**Star][11d] [Py] [cyrus-and/gdb-dashboard](https://github.com/cyrus-and/gdb-dashboard) Modular visual interface for GDB in Python -- [**5996**Star][20d] [berzerk0/probable-wordlists](https://github.com/berzerk0/probable-wordlists) Version 2 is live! Wordlists sorted by probability originally created for password generation and testing - make sure your passwords aren't popular! -- [**5948**Star][2m] [Java] [google/android-classyshark](https://github.com/google/android-classyshark) Analyze any Android/Java based app or game -- [**5935**Star][29d] [Py] [gallopsled/pwntools](https://github.com/gallopsled/pwntools) CTF framework and exploit development library -- [**5870**Star][6m] [JS] [haotian-wang/google-access-helper](https://github.com/haotian-wang/google-access-helper) 谷歌访问助手破解版 -- [**5850**Star][8d] [C++] [radareorg/cutter](https://github.com/radareorg/cutter) Reverse Engineering Platform powered by radare2 -- [**5845**Star][2m] [Gnuplot] [nasa-jpl/open-source-rover](https://github.com/nasa-jpl/open-source-rover) A build-it-yourself, 6-wheel rover based on the rovers on Mars! -- [**5811**Star][7m] [JS] [sindresorhus/fkill-cli](https://github.com/sindresorhus/fkill-cli) Fabulously kill processes. Cross-platform. -- [**5764**Star][3m] [Objective-C] [square/ponydebugger](https://github.com/square/ponydebugger) Remote network and data debugging for your native iOS app using Chrome Developer Tools -- [**5738**Star][1y] [qinyuhang/shadowsocksx-ng-r](https://github.com/qinyuhang/shadowsocksx-ng-r) Next Generation of ShadowsocksX -- [**5738**Star][2y] [Py] [newsapps/beeswithmachineguns](https://github.com/newsapps/beeswithmachineguns) A utility for arming (creating) many bees (micro EC2 instances) to attack (load test) targets (web applications). -- [**5719**Star][2m] [C] [spacehuhn/esp8266_deauther](https://github.com/spacehuhn/esp8266_deauther) Cheap WiFi hacks -- [**5715**Star][8m] [C] [xoreaxeaxeax/movfuscator](https://github.com/xoreaxeaxeax/movfuscator) The single instruction C compiler -- [**5674**Star][22d] [JS] [swagger-api/swagger-editor](https://github.com/swagger-api/swagger-editor) Swagger Editor -- [**5653**Star][16d] [Go] [casbin/casbin](https://github.com/casbin/casbin) An authorization library that supports access control models like ACL, RBAC, ABAC in Golang -- [**5605**Star][1m] [C] [rofl0r/proxychains-ng](https://github.com/rofl0r/proxychains-ng) proxychains ng (new generation) - a preloader which hooks calls to sockets in dynamically linked programs and redirects it through one or more socks/http proxies. continuation of the unmaintained proxychains project. the sf.net page is currently not updated, use releases from github release page instead. -- [**5578**Star][8d] [Ruby] [presidentbeef/brakeman](https://github.com/presidentbeef/brakeman) A static analysis security vulnerability scanner for Ruby on Rails applications -- [**5521**Star][18d] [rshipp/awesome-malware-analysis](https://github.com/rshipp/awesome-malware-analysis) A curated list of awesome malware analysis tools and resources. -- [**5517**Star][27d] [Roff] [max2max/freess](https://github.com/max2max/freess) 免费ss账号 免费shadowsocks账号 免费v2ray账号 (长期更新) -- [**5456**Star][8m] [carpedm20/awesome-hacking](https://github.com/carpedm20/awesome-hacking) A curated list of awesome Hacking tutorials, tools and resources -- [**5417**Star][2y] [Rust] [autumnai/leaf](https://github.com/autumnai/leaf) Open Machine Intelligence Framework for Hackers. (GPU/CPU) -- [**5392**Star][2m] [Py] [axi0mx/ipwndfu](https://github.com/axi0mx/ipwndfu) open-source jailbreaking tool for many iOS devices -- [**5353**Star][5m] [C] [pwn20wndstuff/undecimus](https://github.com/pwn20wndstuff/undecimus) unc0ver jailbreak for iOS 11.0 - 12.4 -- [**5317**Star][7d] [Py] [mlflow/mlflow](https://github.com/mlflow/mlflow) Open source platform for the machine learning lifecycle -- [**5307**Star][9d] [Go] [zricethezav/gitleaks](https://github.com/zricethezav/gitleaks) Audit git repos for secrets -- [**5207**Star][7m] [Py] [usarmyresearchlab/dshell](https://github.com/usarmyresearchlab/dshell) Dshell is a network forensic analysis framework. -- [**5165**Star][1m] [Py] [refirmlabs/binwalk](https://github.com/ReFirmLabs/binwalk) a fast, easy to use tool for analyzing, reverse engineering, and extracting firmware images. +- [**45523**Star][11d] [C#] [shadowsocks/shadowsocks-windows](https://github.com/shadowsocks/shadowsocks-windows) If you want to keep a secret, you must also hide it from yourself. +- [**34554**Star][16d] [C++] [x64dbg/x64dbg](https://github.com/x64dbg/x64dbg) An open-source x64/x32 debugger for windows. +- [**33926**Star][10d] [Py] [minimaxir/big-list-of-naughty-strings](https://github.com/minimaxir/big-list-of-naughty-strings) The Big List of Naughty Strings is a list of strings which have a high probability of causing issues when used as user-input data. +- [**32844**Star][2m] [hack-with-github/awesome-hacking](https://github.com/hack-with-github/awesome-hacking) A collection of various awesome lists for hackers, pentesters and security researchers +- [**32022**Star][4y] [Py] [shadowsocks/shadowsocks](https://github.com/shadowsocks/shadowsocks) +- [**30689**Star][14d] [Go] [fatedier/frp](https://github.com/fatedier/frp) A fast reverse proxy to help you expose a local server behind a NAT or firewall to the internet. +- [**27836**Star][2d] [Kotlin] [shadowsocks/shadowsocks-android](https://github.com/shadowsocks/shadowsocks-android) A shadowsocks client for Android +- [**25977**Star][2d] [Py] [certbot/certbot](https://github.com/certbot/certbot) Certbot is EFF's tool to obtain certs from Let's Encrypt and (optionally) auto-enable HTTPS on your server. It can also act as a client for any other CA that uses the ACME protocol. +- [**25643**Star][28d] [Swift] [shadowsocks/shadowsocksx-ng](https://github.com/shadowsocks/shadowsocksx-ng) Next Generation of ShadowsocksX +- [**25330**Star][3d] [Go] [v2ray/v2ray-core](https://github.com/v2ray/v2ray-core) A platform for building proxies to bypass network restrictions. +- [**24826**Star][2d] [xitu/gold-miner](https://github.com/xitu/gold-miner) +- [**24727**Star][5d] [trimstray/the-book-of-secret-knowledge](https://github.com/trimstray/the-book-of-secret-knowledge) A collection of inspiring lists, manuals, cheatsheets, blogs, hacks, one-liners, cli/web tools and more. +- [**22556**Star][14d] [Shell] [mathiasbynens/dotfiles](https://github.com/mathiasbynens/dotfiles) +- [**21874**Star][9d] [PHP] [danielmiessler/seclists](https://github.com/danielmiessler/seclists) SecLists is the security tester's companion. It's a collection of multiple types of lists used during security assessments, collected in one place. List types include usernames, passwords, URLs, sensitive data patterns, fuzzing payloads, web shells, and many more. +- [**21778**Star][12d] [Go] [filosottile/mkcert](https://github.com/filosottile/mkcert) A simple zero-config tool to make locally trusted development certificates with any names you'd like. +- [**20680**Star][5d] [Java] [skylot/jadx](https://github.com/skylot/jadx) Dex to Java decompiler +- [**20159**Star][5d] [Shell] [streisandeffect/streisand](https://github.com/StreisandEffect/streisand) Streisand sets up a new server running your choice of WireGuard, OpenConnect, OpenSSH, OpenVPN, Shadowsocks, sslh, Stunnel, or a Tor bridge. It also generates custom instructions for all of these services. At the end of the run you are given an HTML file with instructions that can be shared with friends, family members, and fellow activists. +- [**19692**Star][2m] [Jupyter Notebook] [camdavidsonpilon/probabilistic-programming-and-bayesian-methods-for-hackers](https://github.com/camdavidsonpilon/probabilistic-programming-and-bayesian-methods-for-hackers) aka "Bayesian Methods for Hackers": An introduction to Bayesian methods + probabilistic programming with a computation/understanding-first, mathematics-second point of view. All in pure Python ;) +- [**19212**Star][1y] [alvin9999/new-pac](https://github.com/alvin9999/new-pac) 科学/自由上网,免费ss/ssr/v2ray/goflyway账号,搭建教程 +- [**19076**Star][2d] [Ruby] [rapid7/metasploit-framework](https://github.com/rapid7/metasploit-framework) Metasploit Framework +- [**18676**Star][3y] [fallibleinc/security-guide-for-developers](https://github.com/fallibleinc/security-guide-for-developers) Security Guide for Developers (实用性开发人员安全须知) +- [**18476**Star][2d] [Java] [nationalsecurityagency/ghidra](https://github.com/nationalsecurityagency/ghidra) Ghidra is a software reverse engineering (SRE) framework +- [**18390**Star][3d] [Java] [alibaba/arthas](https://github.com/alibaba/arthas) Alibaba Java Diagnostic Tool Arthas +- [**17641**Star][4y] [Go] [inconshreveable/ngrok](https://github.com/inconshreveable/ngrok) Introspected tunnels to localhost +- [**17069**Star][6d] [Py] [mitmproxy/mitmproxy](https://github.com/mitmproxy/mitmproxy) An interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers. +- [**16769**Star][2d] [C#] [powershell/powershell](https://github.com/powershell/powershell) PowerShell for every system! +- [**15824**Star][2d] [Py] [sqlmapproject/sqlmap](https://github.com/sqlmapproject/sqlmap) Automatic SQL injection and database takeover tool +- [**15731**Star][9m] [micropoor/micro8](https://github.com/micropoor/micro8) Gitbook +- [**15718**Star][3d] [C] [curl/curl](https://github.com/curl/curl) A command line tool and library for transferring data with URL syntax, supporting HTTP, HTTPS, FTP, FTPS, GOPHER, TFTP, SCP, SFTP, SMB, TELNET, DICT, LDAP, LDAPS, FILE, IMAP, SMTP, POP3, RTSP and RTMP. libcurl offers a myriad of powerful features +- [**15363**Star][21d] [Py] [drduh/macos-security-and-privacy-guide](https://github.com/drduh/macOS-Security-and-Privacy-Guide) Guide to securing and improving privacy on macOS +- [**14744**Star][1m] [gfwlist/gfwlist](https://github.com/gfwlist/gfwlist) gfwlist +- [**14518**Star][7d] [Java] [tencent/tinker](https://github.com/tencent/tinker) Tinker is a hot-fix solution library for Android, it supports dex, library and resources update without reinstall apk. +- [**13736**Star][9m] [JS] [bannedbook/fanqiang](https://github.com/bannedbook/fanqiang) 翻墙-科学上网 +- [**13548**Star][28d] [Py] [corentinj/real-time-voice-cloning](https://github.com/corentinj/real-time-voice-cloning) Clone a voice in 5 seconds to generate arbitrary speech in real-time +- [**13241**Star][19d] [Go] [jesseduffield/lazydocker](https://github.com/jesseduffield/lazydocker) The lazier way to manage everything docker +- [**12966**Star][12d] [Py] [cool-rr/pysnooper](https://github.com/cool-rr/pysnooper) Never use print for debugging again +- [**12742**Star][3d] [Vue] [liyasthomas/postwoman](https://github.com/liyasthomas/postwoman) +- [**12693**Star][8d] [C] [shadowsocks/shadowsocks-libev](https://github.com/shadowsocks/shadowsocks-libev) libev port of shadowsocks +- [**12544**Star][9d] [C#] [0xd4d/dnspy](https://github.com/0xd4d/dnspy) .NET debugger and assembly editor +- [**12325**Star][2m] [Ruby] [diaspora/diaspora](https://github.com/diaspora/diaspora) A privacy-aware, distributed, open source social network. +- [**12241**Star][5d] [Java] [signalapp/signal-android](https://github.com/signalapp/Signal-Android) A private messenger for Android. +- [**11977**Star][1m] [Go] [buger/goreplay](https://github.com/buger/goreplay) capturing and replaying live HTTP traffic into a test environment in order to continuously test your system with real data. It can be used to increase confidence in code deployments, configuration changes and infrastructure changes. +- [**11890**Star][6d] [C] [openssl/openssl](https://github.com/openssl/openssl) TLS/SSL and crypto library +- [**11530**Star][2d] [C] [radareorg/radare2](https://github.com/radareorg/radare2) unix-like reverse engineering framework and commandline tools +- [**11418**Star][3m] [C] [robertdavidgraham/masscan](https://github.com/robertdavidgraham/masscan) TCP port scanner, spews SYN packets asynchronously, scanning entire Internet in under 5 minutes. +- [**11404**Star][2d] [getlantern/download](https://github.com/getlantern/download) Lantern官方版本下载 蓝灯 翻墙 科学上网 外网 加速器 梯子 路由 +- [**11342**Star][1m] [facert/awesome-spider](https://github.com/facert/awesome-spider) 爬虫集合 +- [**11278**Star][2d] [Java] [oracle/graal](https://github.com/oracle/graal) Run Programs Faster Anywhere +- [**11200**Star][5d] [Py] [swisskyrepo/payloadsallthethings](https://github.com/swisskyrepo/payloadsallthethings) A list of useful payloads and bypass for Web Application Security and Pentest/CTF +- [**11143**Star][2m] [Jupyter Notebook] [selfteaching/the-craft-of-selfteaching](https://github.com/selfteaching/the-craft-of-selfteaching) One has no future if one couldn't teach themself. +- [**11110**Star][5d] [Py] [owasp/cheatsheetseries](https://github.com/owasp/cheatsheetseries) The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics. +- [**11016**Star][2y] [ObjC] [bang590/jspatch](https://github.com/bang590/jspatch) JSPatch bridge Objective-C and Javascript using the Objective-C runtime. You can call any Objective-C class and method in JavaScript by just including a small engine. JSPatch is generally used to hotfix iOS App. +- [**10925**Star][2d] [ObjC] [flipboard/flex](https://github.com/flipboard/flex) An in-app debugging and exploration tool for iOS +- [**10907**Star][2m] [CSS] [hacker0x01/hacker101](https://github.com/hacker0x01/hacker101) Hacker101 +- [**10830**Star][15d] [enaqx/awesome-pentest](https://github.com/enaqx/awesome-pentest) A collection of awesome penetration testing resources, tools and other shiny things +- [**10780**Star][2y] [CoffeeScript] [dropbox/zxcvbn](https://github.com/dropbox/zxcvbn) Low-Budget Password Strength Estimation +- [**10757**Star][19d] [Java] [konloch/bytecode-viewer](https://github.com/konloch/bytecode-viewer) A Java 8+ Jar & Android APK Reverse Engineering Suite (Decompiler, Editor, Debugger & More) +- [**10318**Star][5d] [ruanyf/weekly](https://github.com/ruanyf/weekly) 科技爱好者周刊,每周五发布 +- [**10226**Star][3d] [Go] [goharbor/harbor](https://github.com/goharbor/harbor) An open source trusted cloud native registry project that stores, signs, and scans content. +- [**9830**Star][8m] [imthenachoman/how-to-secure-a-linux-server](https://github.com/imthenachoman/how-to-secure-a-linux-server) An evolving how-to guide for securing a Linux server. +- [**9613**Star][4d] [Py] [sherlock-project/sherlock](https://github.com/sherlock-project/sherlock) Find Usernames Across Social Networks +- [**9389**Star][3d] [Go] [cnlh/nps](https://github.com/cnlh/nps) 一款轻量级、功能强大的内网穿透代理服务器。支持tcp、udp流量转发,支持内网http代理、内网socks5代理,同时支持snappy压缩、站点保护、加密传输、多路复用、header修改等。支持web图形化管理,集成多用户模式。 +- [**9358**Star][6d] [Ruby] [postalhq/postal](https://github.com/postalhq/postal) complete and fully featured mail server for use by websites & web servers +- [**9266**Star][3m] [JS] [localtunnel/localtunnel](https://github.com/localtunnel/localtunnel) expose yourself +- [**9229**Star][12d] [Java] [ibotpeaches/apktool](https://github.com/ibotpeaches/apktool) A tool for reverse engineering Android apk files +- [**9185**Star][2d] [C#] [icsharpcode/ilspy](https://github.com/icsharpcode/ilspy) .NET Decompiler +- [**9148**Star][29d] [JS] [valve/fingerprintjs2](https://github.com/valve/fingerprintjs2) Modern & flexible browser fingerprinting library +- [**9069**Star][11d] [PS] [lukesampson/scoop](https://github.com/lukesampson/scoop) A command-line installer for Windows. +- [**9015**Star][2m] [vitalysim/awesome-hacking-resources](https://github.com/vitalysim/awesome-hacking-resources) A collection of hacking / penetration testing resources to make you better! +- [**8854**Star][6m] [Go] [rkt/rkt](https://github.com/rkt/rkt) rkt is a pod-native container engine for Linux. It is composable, secure, and built on standards. +- [**8739**Star][17d] [C] [gentilkiwi/mimikatz](https://github.com/gentilkiwi/mimikatz) A little tool to play with Windows security +- [**8646**Star][28d] [Java] [android-hacker/virtualxposed](https://github.com/android-hacker/virtualxposed) A simple app to use Xposed without root, unlock the bootloader or modify system image, etc. +- [**8525**Star][1m] [microsoft/wsl](https://github.com/microsoft/WSL) Issues found on WSL +- [**8443**Star][7m] [Shell] [233boy/v2ray](https://github.com/233boy/v2ray) 最好用的 V2Ray 一键安装脚本 & 管理脚本 +- [**8424**Star][2d] [Py] [wifiphisher/wifiphisher](https://github.com/wifiphisher/wifiphisher) 流氓AP框架, 用于RedTeam和Wi-Fi安全测试 +- [**8420**Star][2y] [brannondorsey/wifi-cracking](https://github.com/brannondorsey/wifi-cracking) Crack WPA/WPA2 Wi-Fi Routers with Airodump-ng and Aircrack-ng/Hashcat +- [**8044**Star][9d] [trimstray/the-practical-linux-hardening-guide](https://github.com/trimstray/the-practical-linux-hardening-guide) This guide details creating a secure Linux production system. OpenSCAP (C2S/CIS, STIG). +- [**8002**Star][2m] [Py] [facebook/chisel](https://github.com/facebook/chisel) Chisel is a collection of LLDB commands to assist debugging iOS apps. +- [**7986**Star][1m] [Py] [mailpile/mailpile](https://github.com/mailpile/mailpile) A free & open modern, fast email client with user-friendly encryption and privacy features +- [**7965**Star][3y] [Go] [cyfdecyf/cow](https://github.com/cyfdecyf/cow) HTTP proxy written in Go. COW can automatically identify blocked sites and use parent proxies to access. +- [**7945**Star][4y] [ObjC] [shadowsocks/shadowsocks-ios](https://github.com/shadowsocks/shadowsocks-ios) Removed according to regulations. +- [**7840**Star][6d] [C++] [shiqiyu/libfacedetection](https://github.com/shiqiyu/libfacedetection) An open source library for face detection in images. The face detection speed can reach 1500FPS. +- [**7731**Star][3d] [JS] [gchq/cyberchef](https://github.com/gchq/cyberchef) The Cyber Swiss Army Knife - a web app for encryption, encoding, compression and data analysis +- [**7712**Star][2d] [Go] [git-lfs/git-lfs](https://github.com/git-lfs/git-lfs) Git extension for versioning large files +- [**7670**Star][24d] [Java] [java-decompiler/jd-gui](https://github.com/java-decompiler/jd-gui) A standalone Java Decompiler GUI +- [**7524**Star][29d] [Py] [threat9/routersploit](https://github.com/threat9/routersploit) Exploitation Framework for Embedded Devices +- [**7474**Star][9d] [Go] [snail007/goproxy](https://github.com/snail007/goproxy) Proxy是高性能全功能的http代理、https代理、socks5代理、内网穿透、内网穿透p2p、内网穿透代理、内网穿透反向代理、内网穿透服务器、Websocket代理、TCP代理、UDP代理、DNS代理、DNS加密代理,代理API认证,全能跨平台代理服务器。 +- [**7412**Star][1m] [C++] [shadowsocks/shadowsocks-qt5](https://github.com/shadowsocks/shadowsocks-qt5) A cross-platform shadowsocks GUI client +- [**7397**Star][1m] [Py] [s0md3v/xsstrike](https://github.com/s0md3v/XSStrike) Most advanced XSS scanner. +- [**7246**Star][19d] [Java] [lionsoul2014/ip2region](https://github.com/lionsoul2014/ip2region) Ip2region is a offline IP location library with accuracy rate of 99.9% and 0.0x millseconds searching performance. DB file is less then 5Mb with all ip address stored. binding for Java,PHP,C,Python,Nodejs,Golang,C#,lua. Binary,B-tree,Memory searching algorithm +- [**7186**Star][7m] [Shell] [teddysun/shadowsocks_install](https://github.com/teddysun/shadowsocks_install) Auto Install Shadowsocks Server for CentOS/Debian/Ubuntu +- [**7017**Star][16d] [Go] [future-architect/vuls](https://github.com/future-architect/vuls) Agent-less vulnerability scanner for Linux, FreeBSD, Container Image, Running Container, WordPress, Programming language libraries, Network devices +- [**6989**Star][5d] [C] [hashcat/hashcat](https://github.com/hashcat/hashcat) World's fastest and most advanced password recovery utility +- [**6984**Star][2d] [Go] [nats-io/nats-server](https://github.com/nats-io/nats-server) High-Performance server for NATS, the cloud native messaging system. +- [**6984**Star][2m] [JS] [cs01/gdbgui](https://github.com/cs01/gdbgui) Browser-based frontend to gdb (gnu debugger). Add breakpoints, view the stack, visualize data structures, and more in C, C++, Go, Rust, and Fortran. Run gdbgui from the terminal and a new tab will open in your browser. +- [**6957**Star][11d] [greatfire/wiki](https://github.com/greatfire/wiki) 自由浏览 +- [**6949**Star][3m] [Java] [pxb1988/dex2jar](https://github.com/pxb1988/dex2jar) Tools to work with android .dex and java .class files +- [**6869**Star][2m] [Go] [sqshq/sampler](https://github.com/sqshq/sampler) A tool for shell commands execution, visualization and alerting. Configured with a simple YAML file. +- [**6812**Star][19d] [Shell] [awslabs/git-secrets](https://github.com/awslabs/git-secrets) Prevents you from committing secrets and credentials into git repositories +- [**6732**Star][9m] [Java] [amitshekhariitbhu/android-debug-database](https://github.com/amitshekhariitbhu/android-debug-database) A library for debugging android databases and shared preferences - Make Debugging Great Again +- [**6683**Star][3d] [Java] [zaproxy/zaproxy](https://github.com/zaproxy/zaproxy) The OWASP ZAP core project +- [**6682**Star][3y] [C++] [alibaba/andfix](https://github.com/alibaba/andfix) AndFix is a library that offer hot-fix for Android App. +- [**6668**Star][12d] [C++] [keepassxreboot/keepassxc](https://github.com/keepassxreboot/keepassxc) KeePassXC is a cross-platform community-driven port of the Windows application “Keepass Password Safe”. +- [**6595**Star][3d] [Py] [networkx/networkx](https://github.com/networkx/networkx) Official NetworkX source code repository. +- [**6555**Star][6m] [Go] [shadowsocks/shadowsocks-go](https://github.com/shadowsocks/shadowsocks-go) go port of shadowsocks (Deprecated) +- [**6518**Star][1m] [Py] [h2y/shadowrocket-adblock-rules](https://github.com/h2y/shadowrocket-adblock-rules) 提供多款 Shadowrocket 规则,带广告过滤功能。用于 iOS 未越狱设备选择性地自动翻墙。 +- [**6462**Star][5d] [Shell] [cisofy/lynis](https://github.com/cisofy/lynis) Security auditing tool for Linux, macOS, and UNIX-based systems. Assists with compliance testing (HIPAA/ISO27001/PCI DSS) and system hardening. Agentless, and installation optional. +- [**6451**Star][17d] [Go] [bettercap/bettercap](https://github.com/bettercap/bettercap) The Swiss Army knife for 802.11, BLE and Ethernet networks reconnaissance and MITM attacks. +- [**6448**Star][9m] [HTML] [open-power-workgroup/hospital](https://github.com/open-power-workgroup/hospital) OpenPower工作组收集汇总的医院开放数据 +- [**6310**Star][29d] [Py] [seatgeek/fuzzywuzzy](https://github.com/seatgeek/fuzzywuzzy) Fuzzy String Matching in Python +- [**6197**Star][2m] [ObjC] [johnno1962/injectionforxcode](https://github.com/johnno1962/injectionforxcode) Runtime Code Injection for Objective-C & Swift +- [**6194**Star][3y] [PS] [powershellmafia/powersploit](https://github.com/PowerShellMafia/PowerSploit) PowerSploit - A PowerShell Post-Exploitation Framework +- [**6192**Star][2m] [Py] [yandex/gixy](https://github.com/yandex/gixy) Nginx configuration static analyzer +- [**6187**Star][6m] [rmerl/asuswrt-merlin](https://github.com/rmerl/asuswrt-merlin) Enhanced version of Asus's router firmware (Asuswrt) (legacy code base) +- [**6146**Star][2d] [JS] [avwo/whistle](https://github.com/avwo/whistle) HTTP, HTTP2, HTTPS, Websocket debugging proxy +- [**6137**Star][1y] [Hack] [facebook/fbctf](https://github.com/facebook/fbctf) Platform to host Capture the Flag competitions +- [**6128**Star][9m] [Py] [schollz/howmanypeoplearearound](https://github.com/schollz/howmanypeoplearearound) Count the number of people around you +- [**6092**Star][15d] [Go] [usefathom/fathom](https://github.com/usefathom/fathom) Fathom Lite. Simple, privacy-focused website analytics. Built with Golang & Preact. +- [**6074**Star][16d] [Go] [quay/clair](https://github.com/quay/clair) Vulnerability Static Analysis for Containers +- [**6074**Star][16d] [Go] [quay/clair](https://github.com/quay/clair) Vulnerability Static Analysis for Containers +- [**6073**Star][5m] [Java] [qihoo360/replugin](https://github.com/qihoo360/replugin) RePlugin - A flexible, stable, easy-to-use Android Plug-in Framework +- [**6070**Star][2y] [C] [jgamblin/mirai-source-code](https://github.com/jgamblin/mirai-source-code) Leaked Mirai Source Code for Research/IoC Development Purposes +- [**6021**Star][3d] [Py] [cyrus-and/gdb-dashboard](https://github.com/cyrus-and/gdb-dashboard) Modular visual interface for GDB in Python +- [**6017**Star][7d] [berzerk0/probable-wordlists](https://github.com/berzerk0/probable-wordlists) Version 2 is live! Wordlists sorted by probability originally created for password generation and testing - make sure your passwords aren't popular! +- [**5972**Star][2m] [Java] [google/android-classyshark](https://github.com/google/android-classyshark) Analyze any Android/Java based app or game +- [**5968**Star][2d] [Py] [gallopsled/pwntools](https://github.com/gallopsled/pwntools) CTF framework and exploit development library +- [**5942**Star][6m] [JS] [haotian-wang/google-access-helper](https://github.com/haotian-wang/google-access-helper) 谷歌访问助手破解版 +- [**5888**Star][2d] [Py] [asciimoo/searx](https://github.com/asciimoo/searx) searx:网络元数据搜索引擎。汇总70 多个搜索引擎的搜素结果,避免用户被追踪或者被分析。可与 Tor 结合使用 +- [**5879**Star][2d] [C++] [radareorg/cutter](https://github.com/radareorg/cutter) Reverse Engineering Platform powered by radare2 +- [**5871**Star][2m] [Gnuplot] [nasa-jpl/open-source-rover](https://github.com/nasa-jpl/open-source-rover) A build-it-yourself, 6-wheel rover based on the rovers on Mars! +- [**5815**Star][7m] [JS] [sindresorhus/fkill-cli](https://github.com/sindresorhus/fkill-cli) Fabulously kill processes. Cross-platform. +- [**5773**Star][1y] [qinyuhang/shadowsocksx-ng-r](https://github.com/qinyuhang/shadowsocksx-ng-r) Next Generation of ShadowsocksX +- [**5766**Star][3m] [ObjC] [square/ponydebugger](https://github.com/square/ponydebugger) Remote network and data debugging for your native iOS app using Chrome Developer Tools +- [**5762**Star][2m] [C] [spacehuhn/esp8266_deauther](https://github.com/spacehuhn/esp8266_deauther) Cheap WiFi hacks +- [**5742**Star][2y] [Py] [newsapps/beeswithmachineguns](https://github.com/newsapps/beeswithmachineguns) A utility for arming (creating) many bees (micro EC2 instances) to attack (load test) targets (web applications). +- [**5740**Star][8m] [C] [xoreaxeaxeax/movfuscator](https://github.com/xoreaxeaxeax/movfuscator) The single instruction C compiler +- [**5694**Star][9d] [JS] [swagger-api/swagger-editor](https://github.com/swagger-api/swagger-editor) Swagger Editor +- [**5693**Star][2d] [Go] [casbin/casbin](https://github.com/casbin/casbin) An authorization library that supports access control models like ACL, RBAC, ABAC in Golang +- [**5626**Star][1m] [C] [rofl0r/proxychains-ng](https://github.com/rofl0r/proxychains-ng) proxychains ng (new generation) - a preloader which hooks calls to sockets in dynamically linked programs and redirects it through one or more socks/http proxies. continuation of the unmaintained proxychains project. the sf.net page is currently not updated, use releases from github release page instead. +- [**5593**Star][10d] [Ruby] [presidentbeef/brakeman](https://github.com/presidentbeef/brakeman) A static analysis security vulnerability scanner for Ruby on Rails applications +- [**5565**Star][29d] [Roff] [max2max/freess](https://github.com/max2max/freess) 免费ss账号 免费shadowsocks账号 免费v2ray账号 (长期更新) +- [**5540**Star][20d] [rshipp/awesome-malware-analysis](https://github.com/rshipp/awesome-malware-analysis) A curated list of awesome malware analysis tools and resources. +- [**5476**Star][8m] [carpedm20/awesome-hacking](https://github.com/carpedm20/awesome-hacking) A curated list of awesome Hacking tutorials, tools and resources +- [**5417**Star][2m] [Py] [axi0mx/ipwndfu](https://github.com/axi0mx/ipwndfu) open-source jailbreaking tool for many iOS devices +- [**5413**Star][2y] [Rust] [autumnai/leaf](https://github.com/autumnai/leaf) Open Machine Intelligence Framework for Hackers. (GPU/CPU) +- [**5371**Star][5m] [C] [pwn20wndstuff/undecimus](https://github.com/pwn20wndstuff/undecimus) unc0ver jailbreak for iOS 11.0 - 12.4 +- [**5371**Star][2d] [Py] [mlflow/mlflow](https://github.com/mlflow/mlflow) Open source platform for the machine learning lifecycle +- [**5324**Star][4d] [Go] [zricethezav/gitleaks](https://github.com/zricethezav/gitleaks) Audit git repos for secrets +- [**5205**Star][7m] [Py] [usarmyresearchlab/dshell](https://github.com/usarmyresearchlab/dshell) Dshell is a network forensic analysis framework. +- [**5196**Star][3m] [Py] [ytisf/thezoo](https://github.com/ytisf/thezoo) A repository of LIVE malwares for your own joy and pleasure. theZoo is a project created to make the possibility of malware analysis open and available to the public. +- [**5192**Star][1m] [Py] [refirmlabs/binwalk](https://github.com/ReFirmLabs/binwalk) a fast, easy to use tool for analyzing, reverse engineering, and extracting firmware images. - [IDA插件](https://github.com/ReFirmLabs/binwalk/tree/master/src/scripts) - [binwalk](https://github.com/ReFirmLabs/binwalk/tree/master/src/binwalk) -- [**5165**Star][1y] [JS] [samyk/poisontap](https://github.com/samyk/poisontap) Exploits locked/password protected computers over USB, drops persistent WebSocket-based backdoor, exposes internal router, and siphons cookies using Raspberry Pi Zero & Node.js. -- [**5163**Star][3m] [Py] [ytisf/thezoo](https://github.com/ytisf/thezoo) A repository of LIVE malwares for your own joy and pleasure. theZoo is a project created to make the possibility of malware analysis open and available to the public. -- [**5121**Star][13d] [PHP] [tennc/webshell](https://github.com/tennc/webshell) This is a webshell open source project -- [**5111**Star][18d] [Shell] [vulhub/vulhub](https://github.com/vulhub/vulhub) Pre-Built Vulnerable Environments Based on Docker-Compose -- [**5096**Star][4m] [Py] [n1nj4sec/pupy](https://github.com/n1nj4sec/pupy) Pupy is an opensource, cross-platform (Windows, Linux, OSX, Android) remote administration and post-exploitation tool mainly written in python -- [**5092**Star][19d] [C++] [avast/retdec](https://github.com/avast/retdec) RetDec is a retargetable machine-code decompiler based on LLVM. -- [**5067**Star][2m] [sbilly/awesome-security](https://github.com/sbilly/awesome-security) A collection of awesome software, libraries, documents, books, resources and cools stuffs about security. -- [**5054**Star][2m] [Shell] [stackexchange/blackbox](https://github.com/stackexchange/blackbox) Safely store secrets in Git/Mercurial/Subversion -- [**5036**Star][8d] [Go] [dnscrypt/dnscrypt-proxy](https://github.com/DNSCrypt/dnscrypt-proxy) dnscrypt-proxy 2 - A flexible DNS proxy, with support for encrypted DNS protocols. -- [**5028**Star][1m] [Java] [meituan-dianping/walle](https://github.com/meituan-dianping/walle) Android Signature V2 Scheme签名下的新一代渠道包打包神器 -- [**5026**Star][4y] [Py] [shadowsocksr-backup/shadowsocksr](https://github.com/shadowsocksr-backup/shadowsocksr) Python port of ShadowsocksR -- [**5023**Star][4m] [PowerShell] [empireproject/empire](https://github.com/EmpireProject/Empire) 后渗透框架. Windows客户端用PowerShell, Linux/OSX用Python. 之前PowerShell Empire和Python EmPyre的组合 -- [**5010**Star][15d] [HTML] [owasp/owasp-mstg](https://github.com/owasp/owasp-mstg) The Mobile Security Testing Guide (MSTG) is a comprehensive manual for mobile app security development, testing and reverse engineering. -- [**4990**Star][1m] [Py] [snare/voltron](https://github.com/snare/voltron) A hacky debugger UI for hackers -- [**4941**Star][10d] [Go] [inlets/inlets](https://github.com/inlets/inlets) Expose your local endpoints to the Internet -- [**4928**Star][13d] [ASP] [hq450/fancyss](https://github.com/hq450/fancyss) fancyss is a project providing tools to across the GFW on asuswrt/merlin based router. -- [**4924**Star][20d] [Py] [trustedsec/social-engineer-toolkit](https://github.com/trustedsec/social-engineer-toolkit) The Social-Engineer Toolkit (SET) repository from TrustedSec - All new versions of SET will be deployed here. -- [**4909**Star][1y] [Go] [yinghuocho/firefly-proxy](https://github.com/yinghuocho/firefly-proxy) A proxy software to help circumventing the Great Firewall. -- [**4892**Star][11m] [Go] [bitly/oauth2_proxy](https://github.com/bitly/oauth2_proxy) A reverse proxy that provides authentication with Google, Github or other provider -- [**4872**Star][2m] [Rust] [sharkdp/hexyl](https://github.com/sharkdp/hexyl) A command-line hex viewer -- [**4872**Star][7m] [Java] [guardianproject/haven](https://github.com/guardianproject/haven) Haven is for people who need a way to protect their personal spaces and possessions without compromising their own privacy, through an Android app and on-device sensors -- [**4868**Star][9d] [Shell] [denisidoro/navi](https://github.com/denisidoro/navi) An interactive cheatsheet tool for the command-line -- [**4862**Star][7d] [JS] [mobsf/mobile-security-framework-mobsf](https://github.com/MobSF/Mobile-Security-Framework-MobSF) Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis. -- [**4838**Star][10d] [Go] [gcla/termshark](https://github.com/gcla/termshark) A terminal UI for tshark, inspired by Wireshark -- [**4835**Star][8d] [Py] [alessandroz/lazagne](https://github.com/alessandroz/lazagne) Credentials recovery project -- [**4816**Star][10d] [C] [offensive-security/exploitdb](https://github.com/offensive-security/exploitdb) The official Exploit Database repository -- [**4793**Star][8m] [Py] [10se1ucgo/disablewintracking](https://github.com/10se1ucgo/disablewintracking) Uses some known methods that attempt to minimize tracking in Windows 10 -- [**4771**Star][7d] [C] [google/oss-fuzz](https://github.com/google/oss-fuzz) OSS-Fuzz - continuous fuzzing of open source software. -- [**4752**Star][7d] [C++] [facebook/redex](https://github.com/facebook/redex) A bytecode optimizer for Android apps -- [**4717**Star][7d] [Swift] [yanue/v2rayu](https://github.com/yanue/v2rayu) V2rayU,基于v2ray核心的mac版客户端,用于科学上网,使用swift编写,支持vmess,shadowsocks,socks5等服务协议,支持订阅, 支持二维码,剪贴板导入,手动配置,二维码分享等 -- [**4710**Star][8d] [C++] [paddlepaddle/paddle-lite](https://github.com/PaddlePaddle/Paddle-Lite) Multi-platform high performance deep learning inference engine (『飞桨』多平台高性能深度学习预测引擎) -- [**4675**Star][7d] [C++] [coatisoftware/sourcetrail](https://github.com/coatisoftware/sourcetrail) Sourcetrail - free and open-source interactive source explorer -- [**4651**Star][7d] [Py] [manisso/fsociety](https://github.com/manisso/fsociety) fsociety Hacking Tools Pack – A Penetration Testing Framework -- [**4630**Star][6m] [powershell/win32-openssh](https://github.com/powershell/win32-openssh) Win32 port of OpenSSH -- [**4627**Star][16d] [C] [google/ios-webkit-debug-proxy](https://github.com/google/ios-webkit-debug-proxy) A DevTools proxy (Chrome Remote Debugging Protocol) for iOS devices (Safari Remote Web Inspector). -- [**4616**Star][8d] [JS] [beefproject/beef](https://github.com/beefproject/beef) The Browser Exploitation Framework Project -- [**4611**Star][19d] [Py] [secdev/scapy](https://github.com/secdev/scapy) Scapy: the Python-based interactive packet manipulation program & library. Supports Python 2 & Python 3. -- [**4575**Star][11m] [Py] [ecthros/uncaptcha2](https://github.com/ecthros/uncaptcha2) defeating the latest version of ReCaptcha with 91% accuracy -- [**4574**Star][10d] [Go] [ginuerzh/gost](https://github.com/ginuerzh/gost) GO Simple Tunnel - a simple tunnel written in golang -- [**4551**Star][1y] [C] [upx/upx](https://github.com/upx/upx) UPX - the Ultimate Packer for eXecutables -- [**4549**Star][8d] [C++] [mozilla/rr](https://github.com/mozilla/rr) Record and Replay Framework -- [**4526**Star][10d] [Ruby] [wpscanteam/wpscan](https://github.com/wpscanteam/wpscan) WPScan is a free, for non-commercial use, black box WordPress Vulnerability Scanner written for security professionals and blog maintainers to test the security of their WordPress websites. -- [**4523**Star][12d] [C] [jedisct1/dsvpn](https://github.com/jedisct1/dsvpn) A Dead Simple VPN. -- [**4485**Star][18d] [TypeScript] [apis-guru/graphql-voyager](https://github.com/apis-guru/graphql-voyager) -- [**4454**Star][1y] [Go] [wallix/awless](https://github.com/wallix/awless) A Mighty CLI for AWS -- [**4444**Star][16d] [Py] [jopohl/urh](https://github.com/jopohl/urh) Universal Radio Hacker: investigate wireless protocols like a boss -- [**4426**Star][22d] [Py] [jofpin/trape](https://github.com/jofpin/trape) People tracker on the Internet: OSINT analysis and research tool by Jose Pino -- [**4398**Star][9d] [Makefile] [frida/frida](https://github.com/frida/frida) Clone this repo to build Frida -- [**4387**Star][2m] [Shell] [zardus/ctf-tools](https://github.com/zardus/ctf-tools) Some setup scripts for security research tools. -- [**4343**Star][13d] [Swift] [signalapp/signal-ios](https://github.com/signalapp/Signal-iOS) A private messenger for iOS. -- [**4339**Star][12m] [Py] [lennylxx/ipv6-hosts](https://github.com/lennylxx/ipv6-hosts) Fork of -- [**4310**Star][29d] [JS] [cure53/dompurify](https://github.com/cure53/dompurify) a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify works with a secure default, but offers a lot of configurability and hooks. Demo: -- [**4307**Star][5m] [Py] [diafygi/acme-tiny](https://github.com/diafygi/acme-tiny) A tiny script to issue and renew TLS certs from Let's Encrypt -- [**4262**Star][1m] [Py] [tensorflow/cleverhans](https://github.com/tensorflow/cleverhans) An adversarial example library for constructing attacks, building defenses, and benchmarking both -- [**4261**Star][1m] [Shell] [ashishb/android-security-awesome](https://github.com/ashishb/android-security-awesome) A collection of android security related resources -- [**4256**Star][11m] [JS] [butterproject/butter-desktop](https://github.com/butterproject/butter-desktop) All the free parts of Popcorn Time -- [**4243**Star][9d] [Rust] [timvisee/ffsend](https://github.com/timvisee/ffsend) Easily and securely share files from the command line -- [**4210**Star][4m] [Py] [dxa4481/trufflehog](https://github.com/dxa4481/trufflehog) Searches through git repositories for high entropy strings and secrets, digging deep into commit history -- [**4195**Star][16d] [Go] [gophish/gophish](https://github.com/gophish/gophish) Open-Source Phishing Toolkit -- [**4195**Star][2m] [Py] [evilsocket/opensnitch](https://github.com/evilsocket/opensnitch) a GNU/Linux port of the Little Snitch application firewall -- [**4190**Star][7m] [Objective-C] [alonemonkey/monkeydev](https://github.com/alonemonkey/monkeydev) CaptainHook Tweak、Logos Tweak and Command-line Tool、Patch iOS Apps, Without Jailbreak. -- [**4186**Star][9d] [qazbnm456/awesome-web-security](https://github.com/qazbnm456/awesome-web-security) Curated list of Web Security materials and resources -- [**4183**Star][1y] [Go] [michenriksen/gitrob](https://github.com/michenriksen/gitrob) Reconnaissance tool for GitHub organizations -- [**4175**Star][11d] [we5ter/scanners-box](https://github.com/we5ter/scanners-box) A powerful hacker toolkit collected more than 10 categories of open source scanners from Github - 安全行业从业者自研开源扫描器合辑 -- [**4165**Star][2y] [forter/security-101-for-saas-startups](https://github.com/forter/security-101-for-saas-startups) security tips for startups -- [**4148**Star][12m] [JS] [kdzwinel/betwixt](https://github.com/kdzwinel/betwixt) Betwixt will help you analyze web traffic outside the browser using familiar Chrome DevTools interface. -- [**4105**Star][5m] [Py] [spiderclub/haipproxy](https://github.com/spiderclub/haipproxy) -- [**4092**Star][2m] [Py] [aboul3la/sublist3r](https://github.com/aboul3la/sublist3r) Fast subdomains enumeration tool for penetration testers -- [**4091**Star][7d] [Java] [spring-projects/spring-security](https://github.com/spring-projects/spring-security) Spring Security -- [**4083**Star][2y] [Py] [xoreaxeaxeax/sandsifter](https://github.com/xoreaxeaxeax/sandsifter) sandsifter:x86 处理器 Fuzzer,查找 Intel 的隐藏指令和 CPU bug -- [**4069**Star][9m] [wtsxdev/reverse-engineering](https://github.com/wtsxdev/reverse-engineering) List of awesome reverse engineering resources -- [**4039**Star][1m] [JS] [sigalor/whatsapp-web-reveng](https://github.com/sigalor/whatsapp-web-reveng) Reverse engineering WhatsApp Web. -- [**4033**Star][7d] [Py] [google/clusterfuzz](https://github.com/google/clusterfuzz) Scalable fuzzing infrastructure. -- [**4023**Star][2m] [Java] [jesusfreke/smali](https://github.com/jesusfreke/smali) smali/baksmali -- [**4015**Star][3m] [JS] [cuckoosandbox/cuckoo](https://github.com/cuckoosandbox/cuckoo) Cuckoo Sandbox is an automated dynamic malware analysis system -- [**3989**Star][1y] [JS] [travist/jsencrypt](https://github.com/travist/jsencrypt) A Javascript library to perform OpenSSL RSA Encryption, Decryption, and Key Generation. -- [**3985**Star][20d] [drduh/yubikey-guide](https://github.com/drduh/yubikey-guide) Guide to using YubiKey for GPG and SSH -- [**3955**Star][3m] [Py] [nullarray/autosploit](https://github.com/nullarray/autosploit) Automated Mass Exploiter -- [**3936**Star][13d] [Go] [dexidp/dex](https://github.com/dexidp/dex) OpenID Connect Identity (OIDC) and OAuth 2.0 Provider with Pluggable Connectors -- [**3929**Star][2m] [JS] [apsdehal/awesome-ctf](https://github.com/apsdehal/awesome-ctf) A curated list of CTF frameworks, libraries, resources and softwares -- [**3929**Star][2m] [JS] [apsdehal/awesome-ctf](https://github.com/apsdehal/awesome-ctf) A curated list of CTF frameworks, libraries, resources and softwares -- [**3925**Star][4m] [PHP] [paragonie/awesome-appsec](https://github.com/paragonie/awesome-appsec) A curated list of resources for learning about application security -- [**3916**Star][7d] [Py] [angr/angr](https://github.com/angr/angr) A powerful and user-friendly binary analysis platform! -- [**3908**Star][14d] [Rust] [svenstaro/genact](https://github.com/svenstaro/genact) a nonsense activity generator -- [**3907**Star][1m] [C] [aquynh/capstone](https://github.com/aquynh/capstone) Capstone disassembly/disassembler framework: Core (Arm, Arm64, BPF, EVM, M68K, M680X, MOS65xx, Mips, PPC, RISCV, Sparc, SystemZ, TMS320C64x, Web Assembly, X86, X86_64, XCore) + bindings. -- [**3896**Star][2y] [C#] [shadowsocksr-backup/shadowsocksr-csharp](https://github.com/shadowsocksr-backup/shadowsocksr-csharp) -- [**3876**Star][7d] [C++] [baldurk/renderdoc](https://github.com/baldurk/renderdoc) RenderDoc is a stand-alone graphics debugging tool. -- [**3856**Star][2m] [PHP] [fuzzdb-project/fuzzdb](https://github.com/fuzzdb-project/fuzzdb) Dictionary of attack patterns and primitives for black-box application fault injection and resource discovery. -- [**3841**Star][8m] [Go] [eranyanay/1m-go-websockets](https://github.com/eranyanay/1m-go-websockets) handling 1M websockets connections in Go -- [**3837**Star][15d] [JS] [shadowsocks/shadowsocks-manager](https://github.com/shadowsocks/shadowsocks-manager) A shadowsocks manager tool for multi user and traffic control. -- [**3836**Star][11d] [Py] [secureauthcorp/impacket](https://github.com/SecureAuthCorp/impacket) Impacket is a collection of Python classes for working with network protocols. -- [**3832**Star][2m] [Objective-C] [sveinbjornt/sloth](https://github.com/sveinbjornt/sloth) Mac app that shows all open files, directories and sockets in use by all running processes. Nice GUI for lsof. -- [**3825**Star][4y] [iosre/iosappreverseengineering](https://github.com/iosre/iosappreverseengineering) The world’s 1st book of very detailed iOS App reverse engineering skills :) -- [**3781**Star][13d] [hq450/fancyss_history_package](https://github.com/hq450/fancyss_history_package) 科学上网插件的离线安装包储存在这里 -- [**3770**Star][30d] [jivoi/awesome-osint](https://github.com/jivoi/awesome-osint) A curated list of amazingly awesome open source intelligence tools and resources -- [**3763**Star][5y] [shadowsocksr-backup/shadowsocks-rss](https://github.com/shadowsocksr-backup/shadowsocks-rss) ShadowsocksR update rss, SSR organization -- [**3754**Star][10m] [Py] [longld/peda](https://github.com/longld/peda) Python Exploit Development Assistance for GDB -- [**3749**Star][2m] [Go] [microsoft/ethr](https://github.com/microsoft/ethr) Ethr is a Network Performance Measurement Tool for TCP, UDP & HTTP. -- [**3739**Star][2m] [PHP] [ethicalhack3r/dvwa](https://github.com/ethicalhack3r/DVWA) Damn Vulnerable Web Application (DVWA) -- [**3739**Star][2m] [Py] [paralax/awesome-honeypots](https://github.com/paralax/awesome-honeypots) an awesome list of honeypot resources -- [**3731**Star][1m] [C] [iaik/meltdown](https://github.com/iaik/meltdown) This repository contains several applications, demonstrating the Meltdown bug. -- [**3731**Star][13d] [Go] [hashicorp/consul-template](https://github.com/hashicorp/consul-template) Template rendering, notifier, and supervisor for -- [**3718**Star][4m] [Py] [malwaredllc/byob](https://github.com/malwaredllc/byob) BYOB (Build Your Own Botnet) -- [**3681**Star][11d] [jjqqkk/chromium](https://github.com/jjqqkk/chromium) Chromium browser with SSL VPN. Use this browser to unblock websites. -- [**3679**Star][2y] [JS] [samyk/evercookie](https://github.com/samyk/evercookie) Produces persistent, respawning "super" cookies in a browser, abusing over a dozen techniques. Its goal is to identify users after they've removed standard cookies and other privacy data such as Flash cookies (LSOs), HTML5 storage, SilverLight storage, and others. -- [**3675**Star][8d] [HTML] [hamukazu/lets-get-arrested](https://github.com/hamukazu/lets-get-arrested) This project is intended to protest against the police in Japan -- [**3660**Star][1y] [Py] [misterch0c/shadowbroker](https://github.com/misterch0c/shadowbroker) The Shadow Brokers "Lost In Translation" leak -- [**3653**Star][4m] [C] [facebook/fishhook](https://github.com/facebook/fishhook) A library that enables dynamically rebinding symbols in Mach-O binaries running on iOS. -- [**3647**Star][8d] [JS] [lesspass/lesspass](https://github.com/lesspass/lesspass) -- [**3645**Star][26d] [C#] [0xd4d/de4dot](https://github.com/0xd4d/de4dot) .NET deobfuscator and unpacker. -- [**3640**Star][4m] [C] [secwiki/windows-kernel-exploits](https://github.com/secwiki/windows-kernel-exploits) windows-kernel-exploits Windows平台提权漏洞集合 -- [**3639**Star][2y] [Py] [qiyeboy/ipproxypool](https://github.com/qiyeboy/ipproxypool) IPProxyPool代理池项目,提供代理ip -- [**3624**Star][29d] [acl4ssr/acl4ssr](https://github.com/acl4ssr/acl4ssr) SSR 去广告ACL规则/SS完整GFWList规则,Telegram频道订阅地址 -- [**3621**Star][2m] [C] [atmosphere-nx/atmosphere](https://github.com/atmosphere-nx/atmosphere) Atmosphère is a work-in-progress customized firmware for the Nintendo Switch. -- [**3615**Star][5y] [C#] [brandonlw/psychson](https://github.com/brandonlw/Psychson) Phison 2251-03 (2303) Custom Firmware & Existing Firmware Patches (BadUSB) -- [**3612**Star][17d] [HTML] [consensys/smart-contract-best-practices](https://github.com/consensys/smart-contract-best-practices) A guide to smart contract security best practices -- [**3598**Star][8d] [TypeScript] [javascript-obfuscator/javascript-obfuscator](https://github.com/javascript-obfuscator/javascript-obfuscator) A powerful obfuscator for JavaScript and Node.js +- [**5167**Star][20d] [Shell] [vulhub/vulhub](https://github.com/vulhub/vulhub) Pre-Built Vulnerable Environments Based on Docker-Compose +- [**5167**Star][1y] [JS] [samyk/poisontap](https://github.com/samyk/poisontap) Exploits locked/password protected computers over USB, drops persistent WebSocket-based backdoor, exposes internal router, and siphons cookies using Raspberry Pi Zero & Node.js. +- [**5148**Star][6d] [PHP] [tennc/webshell](https://github.com/tennc/webshell) This is a webshell open source project +- [**5123**Star][21d] [C++] [avast/retdec](https://github.com/avast/retdec) RetDec is a retargetable machine-code decompiler based on LLVM. +- [**5118**Star][15d] [ObjC] [macpass/macpass](https://github.com/MacPass/MacPass) A native OS X KeePass client +- [**5118**Star][4m] [Py] [n1nj4sec/pupy](https://github.com/n1nj4sec/pupy) Pupy is an opensource, cross-platform (Windows, Linux, OSX, Android) remote administration and post-exploitation tool mainly written in python +- [**5089**Star][2d] [Go] [dnscrypt/dnscrypt-proxy](https://github.com/DNSCrypt/dnscrypt-proxy) dnscrypt-proxy 2 - A flexible DNS proxy, with support for encrypted DNS protocols. +- [**5082**Star][2m] [sbilly/awesome-security](https://github.com/sbilly/awesome-security) A collection of awesome software, libraries, documents, books, resources and cools stuffs about security. +- [**5065**Star][2m] [Shell] [stackexchange/blackbox](https://github.com/stackexchange/blackbox) Safely store secrets in Git/Mercurial/Subversion +- [**5059**Star][1m] [Java] [meituan-dianping/walle](https://github.com/meituan-dianping/walle) Android Signature V2 Scheme签名下的新一代渠道包打包神器 +- [**5054**Star][4y] [Py] [shadowsocksr-backup/shadowsocksr](https://github.com/shadowsocksr-backup/shadowsocksr) Python port of ShadowsocksR +- [**5042**Star][2d] [HTML] [owasp/owasp-mstg](https://github.com/owasp/owasp-mstg) The Mobile Security Testing Guide (MSTG) is a comprehensive manual for mobile app security development, testing and reverse engineering. +- [**5037**Star][4m] [PS] [empireproject/empire](https://github.com/EmpireProject/Empire) 后渗透框架. Windows客户端用PowerShell, Linux/OSX用Python. 之前PowerShell Empire和Python EmPyre的组合 +- [**5021**Star][2d] [Py] [mobsf/mobile-security-framework-mobsf](https://github.com/MobSF/Mobile-Security-Framework-MobSF) Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis. +- [**5005**Star][2d] [C++] [coatisoftware/sourcetrail](https://github.com/coatisoftware/sourcetrail) Sourcetrail - free and open-source interactive source explorer +- [**4996**Star][2d] [ASP] [hq450/fancyss](https://github.com/hq450/fancyss) fancyss is a project providing tools to across the GFW on asuswrt/merlin based router. +- [**4996**Star][6d] [Go] [inlets/inlets](https://github.com/inlets/inlets) Expose your local endpoints to the Internet +- [**4994**Star][1m] [Py] [snare/voltron](https://github.com/snare/voltron) A hacky debugger UI for hackers +- [**4953**Star][22d] [Py] [trustedsec/social-engineer-toolkit](https://github.com/trustedsec/social-engineer-toolkit) The Social-Engineer Toolkit (SET) repository from TrustedSec - All new versions of SET will be deployed here. +- [**4920**Star][2d] [TS] [jigsaw-code/outline-client](https://github.com/jigsaw-code/outline-client) Outline clients, developed by Jigsaw. The Outline clients use the popular Shadowsocks protocol, and lean on the Cordova and Electron frameworks to support Windows, Android / ChromeOS, Linux, iOS and macOS. +- [**4913**Star][1y] [Go] [yinghuocho/firefly-proxy](https://github.com/yinghuocho/firefly-proxy) A proxy software to help circumventing the Great Firewall. +- [**4909**Star][2d] [Shell] [denisidoro/navi](https://github.com/denisidoro/navi) An interactive cheatsheet tool for the command-line +- [**4897**Star][11m] [Go] [bitly/oauth2_proxy](https://github.com/bitly/oauth2_proxy) A reverse proxy that provides authentication with Google, Github or other provider +- [**4883**Star][2m] [Rust] [sharkdp/hexyl](https://github.com/sharkdp/hexyl) A command-line hex viewer +- [**4881**Star][5d] [Java] [guardianproject/haven](https://github.com/guardianproject/haven) Haven is for people who need a way to protect their personal spaces and possessions without compromising their own privacy, through an Android app and on-device sensors +- [**4869**Star][2d] [Swift] [yanue/v2rayu](https://github.com/yanue/v2rayu) V2rayU,基于v2ray核心的mac版客户端,用于科学上网,使用swift编写,支持vmess,shadowsocks,socks5等服务协议,支持订阅, 支持二维码,剪贴板导入,手动配置,二维码分享等 +- [**4867**Star][10d] [Py] [alessandroz/lazagne](https://github.com/alessandroz/lazagne) Credentials recovery project +- [**4847**Star][3d] [Go] [gcla/termshark](https://github.com/gcla/termshark) A terminal UI for tshark, inspired by Wireshark +- [**4841**Star][2d] [C] [offensive-security/exploitdb](https://github.com/offensive-security/exploitdb) The official Exploit Database repository +- [**4803**Star][8m] [Py] [10se1ucgo/disablewintracking](https://github.com/10se1ucgo/disablewintracking) Uses some known methods that attempt to minimize tracking in Windows 10 +- [**4782**Star][2d] [C] [google/oss-fuzz](https://github.com/google/oss-fuzz) OSS-Fuzz - continuous fuzzing of open source software. +- [**4761**Star][2d] [C++] [facebook/redex](https://github.com/facebook/redex) A bytecode optimizer for Android apps +- [**4724**Star][2d] [C++] [paddlepaddle/paddle-lite](https://github.com/PaddlePaddle/Paddle-Lite) Multi-platform high performance deep learning inference engine (『飞桨』多平台高性能深度学习预测引擎) +- [**4691**Star][9d] [Py] [manisso/fsociety](https://github.com/manisso/fsociety) fsociety Hacking Tools Pack – A Penetration Testing Framework +- [**4639**Star][3d] [Py] [secdev/scapy](https://github.com/secdev/scapy) Scapy: the Python-based interactive packet manipulation program & library. Supports Python 2 & Python 3. +- [**4638**Star][18d] [C] [google/ios-webkit-debug-proxy](https://github.com/google/ios-webkit-debug-proxy) A DevTools proxy (Chrome Remote Debugging Protocol) for iOS devices (Safari Remote Web Inspector). +- [**4637**Star][6m] [powershell/win32-openssh](https://github.com/powershell/win32-openssh) Win32 port of OpenSSH +- [**4633**Star][2d] [JS] [beefproject/beef](https://github.com/beefproject/beef) The Browser Exploitation Framework Project +- [**4615**Star][12d] [Go] [ginuerzh/gost](https://github.com/ginuerzh/gost) GO Simple Tunnel - a simple tunnel written in golang +- [**4589**Star][11m] [Py] [ecthros/uncaptcha2](https://github.com/ecthros/uncaptcha2) defeating the latest version of ReCaptcha with 91% accuracy +- [**4583**Star][1y] [C] [upx/upx](https://github.com/upx/upx) UPX - the Ultimate Packer for eXecutables +- [**4575**Star][4d] [C++] [mozilla/rr](https://github.com/mozilla/rr) Record and Replay Framework +- [**4543**Star][4d] [Ruby] [wpscanteam/wpscan](https://github.com/wpscanteam/wpscan) WPScan is a free, for non-commercial use, black box WordPress Vulnerability Scanner written for security professionals and blog maintainers to test the security of their WordPress websites. +- [**4529**Star][6d] [C] [jedisct1/dsvpn](https://github.com/jedisct1/dsvpn) A Dead Simple VPN. +- [**4498**Star][6d] [TS] [apis-guru/graphql-voyager](https://github.com/apis-guru/graphql-voyager) +- [**4459**Star][8d] [Py] [jopohl/urh](https://github.com/jopohl/urh) Universal Radio Hacker: investigate wireless protocols like a boss +- [**4458**Star][1y] [Go] [wallix/awless](https://github.com/wallix/awless) A Mighty CLI for AWS +- [**4449**Star][3d] [Go] [dragonflyoss/dragonfly](https://github.com/dragonflyoss/Dragonfly) Dragonfly is an intelligent P2P based image and file distribution system. +- [**4446**Star][2d] [Makefile] [frida/frida](https://github.com/frida/frida) Clone this repo to build Frida +- [**4443**Star][24d] [Py] [jofpin/trape](https://github.com/jofpin/trape) People tracker on the Internet: OSINT analysis and research tool by Jose Pino +- [**4411**Star][2m] [Shell] [zardus/ctf-tools](https://github.com/zardus/ctf-tools) Some setup scripts for security research tools. +- [**4359**Star][6d] [Swift] [signalapp/signal-ios](https://github.com/signalapp/Signal-iOS) A private messenger for iOS. +- [**4346**Star][1m] [JS] [cure53/dompurify](https://github.com/cure53/dompurify) a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify works with a secure default, but offers a lot of configurability and hooks. Demo: +- [**4344**Star][12m] [Py] [lennylxx/ipv6-hosts](https://github.com/lennylxx/ipv6-hosts) Fork of +- [**4313**Star][5m] [Py] [diafygi/acme-tiny](https://github.com/diafygi/acme-tiny) A tiny script to issue and renew TLS certs from Let's Encrypt +- [**4283**Star][7d] [Py] [tensorflow/cleverhans](https://github.com/tensorflow/cleverhans) An adversarial example library for constructing attacks, building defenses, and benchmarking both +- [**4280**Star][1m] [Shell] [ashishb/android-security-awesome](https://github.com/ashishb/android-security-awesome) A collection of android security related resources +- [**4261**Star][5d] [Rust] [timvisee/ffsend](https://github.com/timvisee/ffsend) Easily and securely share files from the command line +- [**4258**Star][11m] [JS] [butterproject/butter-desktop](https://github.com/butterproject/butter-desktop) All the free parts of Popcorn Time +- [**4244**Star][2y] [imeiji/shadowsocks_install](https://github.com/imeiji/shadowsocks_install) Auto install shadowsocks server,thanks 秋水逸冰 +- [**4241**Star][4m] [Py] [dxa4481/trufflehog](https://github.com/dxa4481/trufflehog) Searches through git repositories for high entropy strings and secrets, digging deep into commit history +- [**4215**Star][7m] [ObjC] [alonemonkey/monkeydev](https://github.com/alonemonkey/monkeydev) CaptainHook Tweak、Logos Tweak and Command-line Tool、Patch iOS Apps, Without Jailbreak. +- [**4211**Star][9d] [Go] [gophish/gophish](https://github.com/gophish/gophish) Open-Source Phishing Toolkit +- [**4205**Star][11d] [qazbnm456/awesome-web-security](https://github.com/qazbnm456/awesome-web-security) Curated list of Web Security materials and resources +- [**4204**Star][1y] [Go] [michenriksen/gitrob](https://github.com/michenriksen/gitrob) Reconnaissance tool for GitHub organizations +- [**4202**Star][2m] [Py] [evilsocket/opensnitch](https://github.com/evilsocket/opensnitch) a GNU/Linux port of the Little Snitch application firewall +- [**4198**Star][2d] [Py] [openmined/pysyft](https://github.com/openmined/pysyft) A library for encrypted, privacy preserving machine learning +- [**4190**Star][13d] [we5ter/scanners-box](https://github.com/we5ter/scanners-box) A powerful hacker toolkit collected more than 10 categories of open source scanners from Github - 安全行业从业者自研开源扫描器合辑 +- [**4171**Star][2y] [forter/security-101-for-saas-startups](https://github.com/forter/security-101-for-saas-startups) security tips for startups +- [**4149**Star][12m] [JS] [kdzwinel/betwixt](https://github.com/kdzwinel/betwixt) Betwixt will help you analyze web traffic outside the browser using familiar Chrome DevTools interface. +- [**4131**Star][5d] [Java] [spring-projects/spring-security](https://github.com/spring-projects/spring-security) Spring Security +- [**4120**Star][5m] [Py] [spiderclub/haipproxy](https://github.com/spiderclub/haipproxy) +- [**4120**Star][2m] [Py] [aboul3la/sublist3r](https://github.com/aboul3la/sublist3r) Fast subdomains enumeration tool for penetration testers +- [**4096**Star][2y] [Py] [xoreaxeaxeax/sandsifter](https://github.com/xoreaxeaxeax/sandsifter) sandsifter:x86 处理器 Fuzzer,查找 Intel 的隐藏指令和 CPU bug +- [**4092**Star][9m] [wtsxdev/reverse-engineering](https://github.com/wtsxdev/reverse-engineering) List of awesome reverse engineering resources +- [**4046**Star][1m] [JS] [sigalor/whatsapp-web-reveng](https://github.com/sigalor/whatsapp-web-reveng) Reverse engineering WhatsApp Web. +- [**4045**Star][2m] [Java] [jesusfreke/smali](https://github.com/jesusfreke/smali) smali/baksmali +- [**4044**Star][2d] [Py] [google/clusterfuzz](https://github.com/google/clusterfuzz) Scalable fuzzing infrastructure. +- [**4022**Star][22d] [drduh/yubikey-guide](https://github.com/drduh/yubikey-guide) Guide to using YubiKey for GPG and SSH +- [**4021**Star][3m] [JS] [cuckoosandbox/cuckoo](https://github.com/cuckoosandbox/cuckoo) Cuckoo Sandbox is an automated dynamic malware analysis system +- [**4000**Star][1y] [JS] [travist/jsencrypt](https://github.com/travist/jsencrypt) A Javascript library to perform OpenSSL RSA Encryption, Decryption, and Key Generation. +- [**3967**Star][3m] [Py] [nullarray/autosploit](https://github.com/nullarray/autosploit) Automated Mass Exploiter +- [**3961**Star][5d] [Go] [dexidp/dex](https://github.com/dexidp/dex) OpenID Connect Identity (OIDC) and OAuth 2.0 Provider with Pluggable Connectors +- [**3953**Star][2m] [JS] [apsdehal/awesome-ctf](https://github.com/apsdehal/awesome-ctf) A curated list of CTF frameworks, libraries, resources and softwares +- [**3953**Star][2m] [JS] [apsdehal/awesome-ctf](https://github.com/apsdehal/awesome-ctf) A curated list of CTF frameworks, libraries, resources and softwares +- [**3937**Star][3d] [Py] [angr/angr](https://github.com/angr/angr) A powerful and user-friendly binary analysis platform! +- [**3935**Star][4m] [PHP] [paragonie/awesome-appsec](https://github.com/paragonie/awesome-appsec) A curated list of resources for learning about application security +- [**3933**Star][8m] [Go] [eranyanay/1m-go-websockets](https://github.com/eranyanay/1m-go-websockets) handling 1M websockets connections in Go +- [**3923**Star][1m] [C] [aquynh/capstone](https://github.com/aquynh/capstone) Capstone disassembly/disassembler framework: Core (Arm, Arm64, BPF, EVM, M68K, M680X, MOS65xx, Mips, PPC, RISCV, Sparc, SystemZ, TMS320C64x, Web Assembly, X86, X86_64, XCore) + bindings. +- [**3920**Star][2y] [C#] [shadowsocksr-backup/shadowsocksr-csharp](https://github.com/shadowsocksr-backup/shadowsocksr-csharp) +- [**3915**Star][16d] [Rust] [svenstaro/genact](https://github.com/svenstaro/genact) a nonsense activity generator +- [**3893**Star][2d] [C++] [baldurk/renderdoc](https://github.com/baldurk/renderdoc) RenderDoc is a stand-alone graphics debugging tool. +- [**3878**Star][2m] [PHP] [fuzzdb-project/fuzzdb](https://github.com/fuzzdb-project/fuzzdb) Dictionary of attack patterns and primitives for black-box application fault injection and resource discovery. +- [**3869**Star][2d] [Py] [secureauthcorp/impacket](https://github.com/SecureAuthCorp/impacket) Impacket is a collection of Python classes for working with network protocols. +- [**3848**Star][7d] [JS] [shadowsocks/shadowsocks-manager](https://github.com/shadowsocks/shadowsocks-manager) A shadowsocks manager tool for multi user and traffic control. +- [**3845**Star][2d] [hq450/fancyss_history_package](https://github.com/hq450/fancyss_history_package) 科学上网插件的离线安装包储存在这里 +- [**3838**Star][2m] [ObjC] [sveinbjornt/sloth](https://github.com/sveinbjornt/sloth) Mac app that shows all open files, directories and sockets in use by all running processes. Nice GUI for lsof. +- [**3831**Star][4y] [iosre/iosappreverseengineering](https://github.com/iosre/iosappreverseengineering) The world’s 1st book of very detailed iOS App reverse engineering skills :) +- [**3813**Star][1m] [jivoi/awesome-osint](https://github.com/jivoi/awesome-osint) A curated list of amazingly awesome open source intelligence tools and resources +- [**3799**Star][5y] [shadowsocksr-backup/shadowsocks-rss](https://github.com/shadowsocksr-backup/shadowsocks-rss) ShadowsocksR update rss, SSR organization +- [**3767**Star][10m] [Py] [longld/peda](https://github.com/longld/peda) Python Exploit Development Assistance for GDB +- [**3763**Star][2m] [Py] [paralax/awesome-honeypots](https://github.com/paralax/awesome-honeypots) an awesome list of honeypot resources +- [**3755**Star][2m] [PHP] [ethicalhack3r/dvwa](https://github.com/ethicalhack3r/DVWA) Damn Vulnerable Web Application (DVWA) +- [**3752**Star][2m] [Go] [microsoft/ethr](https://github.com/microsoft/ethr) Ethr is a Network Performance Measurement Tool for TCP, UDP & HTTP. +- [**3736**Star][8d] [Go] [hashicorp/consul-template](https://github.com/hashicorp/consul-template) Template rendering, notifier, and supervisor for +- [**3733**Star][2m] [C] [iaik/meltdown](https://github.com/iaik/meltdown) This repository contains several applications, demonstrating the Meltdown bug. +- [**3730**Star][4m] [Py] [malwaredllc/byob](https://github.com/malwaredllc/byob) BYOB (Build Your Own Botnet) +- [**3719**Star][6d] [jjqqkk/chromium](https://github.com/jjqqkk/chromium) Chromium browser with SSL VPN. Use this browser to unblock websites. +- [**3713**Star][2d] [C] [atmosphere-nx/atmosphere](https://github.com/atmosphere-nx/atmosphere) Atmosphère is a work-in-progress customized firmware for the Nintendo Switch. +- [**3684**Star][2y] [JS] [samyk/evercookie](https://github.com/samyk/evercookie) Produces persistent, respawning "super" cookies in a browser, abusing over a dozen techniques. Its goal is to identify users after they've removed standard cookies and other privacy data such as Flash cookies (LSOs), HTML5 storage, SilverLight storage, and others. +- [**3682**Star][10d] [HTML] [hamukazu/lets-get-arrested](https://github.com/hamukazu/lets-get-arrested) This project is intended to protest against the police in Japan +- [**3670**Star][2d] [JS] [lesspass/lesspass](https://github.com/lesspass/lesspass) +- [**3668**Star][8d] [C#] [0xd4d/de4dot](https://github.com/0xd4d/de4dot) .NET deobfuscator and unpacker. +- [**3667**Star][1y] [Py] [misterch0c/shadowbroker](https://github.com/misterch0c/shadowbroker) The Shadow Brokers "Lost In Translation" leak +- [**3666**Star][5m] [C] [secwiki/windows-kernel-exploits](https://github.com/secwiki/windows-kernel-exploits) windows-kernel-exploits Windows平台提权漏洞集合 +- [**3663**Star][4m] [C] [facebook/fishhook](https://github.com/facebook/fishhook) A library that enables dynamically rebinding symbols in Mach-O binaries running on iOS. +- [**3652**Star][4d] [acl4ssr/acl4ssr](https://github.com/acl4ssr/acl4ssr) SSR 去广告ACL规则/SS完整GFWList规则,Telegram频道订阅地址 +- [**3647**Star][2y] [Py] [qiyeboy/ipproxypool](https://github.com/qiyeboy/ipproxypool) IPProxyPool代理池项目,提供代理ip +- [**3622**Star][6d] [TS] [javascript-obfuscator/javascript-obfuscator](https://github.com/javascript-obfuscator/javascript-obfuscator) A powerful obfuscator for JavaScript and Node.js +- [**3621**Star][7d] [HTML] [consensys/smart-contract-best-practices](https://github.com/consensys/smart-contract-best-practices) A guide to smart contract security best practices +- [**3619**Star][5y] [C#] [brandonlw/psychson](https://github.com/brandonlw/Psychson) Phison 2251-03 (2303) Custom Firmware & Existing Firmware Patches (BadUSB) +- [**3611**Star][2m] [Java] [ffay/lanproxy](https://github.com/ffay/lanproxy) lanproxy是一个将局域网个人电脑、服务器代理到公网的内网穿透工具,支持tcp流量转发,可支持任何tcp上层协议(访问内网网站、本地支付接口调试、ssh访问、远程桌面...)。目前市面上提供类似服务的有花生壳、TeamView、GoToMyCloud等等,但要使用第三方的公网服务器就必须为第三方付费,并且这些服务都有各种各样的限制,此外,由于数据包会流经第三方,因此对数据安全也是一大隐患。技术交流QQ群 946273429 +- [**3604**Star][8d] [PS] [bloodhoundad/bloodhound](https://github.com/BloodHoundAD/BloodHound) a single page Javascript web application, uses graph theory to reveal the hidden and often unintended relationships within an Active Directory environment. +- [**3598**Star][26d] [C++] [anbox/anbox](https://github.com/anbox/anbox) a container-based approach to boot a full Android system on a regular GNU/Linux system - [**3597**Star][1y] [C#] [nummer/destroy-windows-10-spying](https://github.com/nummer/destroy-windows-10-spying) Destroy Windows Spying tool -- [**3594**Star][2m] [Java] [ffay/lanproxy](https://github.com/ffay/lanproxy) lanproxy是一个将局域网个人电脑、服务器代理到公网的内网穿透工具,支持tcp流量转发,可支持任何tcp上层协议(访问内网网站、本地支付接口调试、ssh访问、远程桌面...)。目前市面上提供类似服务的有花生壳、TeamView、GoToMyCloud等等,但要使用第三方的公网服务器就必须为第三方付费,并且这些服务都有各种各样的限制,此外,由于数据包会流经第三方,因此对数据安全也是一大隐患。技术交流QQ群 946273429 -- [**3591**Star][3y] [Perl] [x0rz/eqgrp](https://github.com/x0rz/eqgrp) Decrypted content of eqgrp-auction-file.tar.xz -- [**3587**Star][2m] [PowerShell] [bloodhoundad/bloodhound](https://github.com/BloodHoundAD/BloodHound) a single page Javascript web application, uses graph theory to reveal the hidden and often unintended relationships within an Active Directory environment. -- [**3578**Star][24d] [C++] [anbox/anbox](https://github.com/anbox/anbox) a container-based approach to boot a full Android system on a regular GNU/Linux system -- [**3565**Star][7d] [Shell] [drwetter/testssl.sh](https://github.com/drwetter/testssl.sh) Testing TLS/SSL encryption anywhere on any port -- [**3560**Star][17d] [C] [nmap/nmap](https://github.com/nmap/nmap) Nmap - the Network Mapper. Github mirror of official SVN repository. -- [**3544**Star][6y] [R] [johnmyleswhite/ml_for_hackers](https://github.com/johnmyleswhite/ml_for_hackers) Code accompanying the book "Machine Learning for Hackers" +- [**3595**Star][3y] [Perl] [x0rz/eqgrp](https://github.com/x0rz/eqgrp) Decrypted content of eqgrp-auction-file.tar.xz +- [**3583**Star][3d] [Shell] [drwetter/testssl.sh](https://github.com/drwetter/testssl.sh) Testing TLS/SSL encryption anywhere on any port +- [**3580**Star][5d] [C] [nmap/nmap](https://github.com/nmap/nmap) Nmap - the Network Mapper. Github mirror of official SVN repository. +- [**3562**Star][5d] [Pascal] [cheat-engine/cheat-engine](https://github.com/cheat-engine/cheat-engine) Cheat Engine. A development environment focused on modding +- [**3542**Star][6y] [R] [johnmyleswhite/ml_for_hackers](https://github.com/johnmyleswhite/ml_for_hackers) Code accompanying the book "Machine Learning for Hackers" +- [**3540**Star][6d] [blacckhathaceekr/pentesting-bible](https://github.com/blacckhathaceekr/pentesting-bible) links reaches 10000 links & 10000 pdf files .Learn Ethical Hacking and penetration testing .hundreds of ethical hacking & penetration testing & red team & cyber security & computer science resources. - [**3538**Star][4m] [Shell] [chengr28/revokechinacerts](https://github.com/chengr28/revokechinacerts) Revoke Chinese certificates. -- [**3525**Star][8d] [Pascal] [cheat-engine/cheat-engine](https://github.com/cheat-engine/cheat-engine) Cheat Engine. A development environment focused on modding -- [**3503**Star][14d] [JS] [aol/moloch](https://github.com/aol/moloch) large scale, full packet capturing, indexing, and database system. -- [**3494**Star][8m] [Go] [fanpei91/torsniff](https://github.com/fanpei91/torsniff) torsniff - a sniffer that sniffs torrents from BitTorrent network -- [**3494**Star][8m] [Go] [fanpei91/torsniff](https://github.com/fanpei91/torsniff) a sniffer that sniffs torrents from BitTorrent network -- [**3493**Star][3y] [C] [hak5darren/usb-rubber-ducky](https://github.com/hak5darren/usb-rubber-ducky) -- [**3482**Star][9m] [C] [rpisec/mbe](https://github.com/rpisec/mbe) Course materials for Modern Binary Exploitation by RPISEC -- [**3481**Star][13d] [blacckhathaceekr/pentesting-bible](https://github.com/blacckhathaceekr/pentesting-bible) links reaches 10000 links & 10000 pdf files .Learn Ethical Hacking and penetration testing .hundreds of ethical hacking & penetration testing & red team & cyber security & computer science resources. -- [**3468**Star][5m] [PHP] [hanc00l/wooyun_public](https://github.com/hanc00l/wooyun_public) This repo is archived. Thanks for wooyun! 乌云公开漏洞、知识库爬虫和搜索 crawl and search for wooyun.org public bug(vulnerability) and drops -- [**3464**Star][15d] [C] [cyan4973/xxhash](https://github.com/cyan4973/xxhash) Extremely fast non-cryptographic hash algorithm -- [**3436**Star][7d] [C] [shellphish/how2heap](https://github.com/shellphish/how2heap) A repository for learning various heap exploitation techniques. -- [**3431**Star][13d] [Java] [meituan-dianping/robust](https://github.com/meituan-dianping/robust) Robust is an Android HotFix solution with high compatibility and high stability. Robust can fix bugs immediately without a reboot. -- [**3421**Star][13d] [Perl] [sullo/nikto](https://github.com/sullo/nikto) Nikto web server scanner -- [**3412**Star][25d] [icodesign/potatso](https://github.com/icodesign/Potatso) Potatso is an iOS client that implements different proxies with the leverage of NetworkExtension framework in iOS 10+. -- [**3392**Star][5m] [Go] [jpillora/chisel](https://github.com/jpillora/chisel) A fast TCP tunnel over HTTP -- [**3387**Star][2y] [shadowsocksrr/shadowsocks-rss](https://github.com/shadowsocksrr/shadowsocks-rss) ShadowsocksR update rss, SSR organization -- [**3383**Star][22d] [PowerShell] [samratashok/nishang](https://github.com/samratashok/nishang) Offensive PowerShell for red team, penetration testing and offensive security. -- [**3326**Star][13d] [Py] [google/grr](https://github.com/google/grr) remote live forensics for incident response -- [**3325**Star][5m] [C++] [wangyu-/udp2raw-tunnel](https://github.com/wangyu-/udp2raw-tunnel) A Tunnel which Turns UDP Traffic into Encrypted UDP/FakeTCP/ICMP Traffic by using Raw Socket,helps you Bypass UDP FireWalls(or Unstable UDP Environment) -- [**3325**Star][7d] [jivoi/awesome-ml-for-cybersecurity](https://github.com/jivoi/awesome-ml-for-cybersecurity) Awesome Machine Learning for Cyber Security -- [**3317**Star][7d] [Py] [stamparm/maltrail](https://github.com/stamparm/maltrail) Malicious traffic detection system -- [**3317**Star][2y] [scanate/ethlist](https://github.com/scanate/ethlist) The Comprehensive Ethereum Reading List -- [**3316**Star][2m] [C] [screetsec/thefatrat](https://github.com/screetsec/thefatrat) Thefatrat a massive exploiting tool : Easy tool to generate backdoor and easy tool to post exploitation attack like browser attack and etc . This tool compiles a malware with popular payload and then the compiled malware can be execute on windows, android, mac . The malware that created with this tool also have an ability to bypass most AV softw… -- [**3282**Star][8d] [Smarty] [anankke/sspanel-uim](https://github.com/anankke/sspanel-uim) Across the Great Wall we can reach every corner in the world -- [**3280**Star][2m] [Swift] [yagiz/bagel](https://github.com/yagiz/bagel) a little native network debugging tool for iOS -- [**3280**Star][20d] [C] [vanhauser-thc/thc-hydra](https://github.com/vanhauser-thc/thc-hydra) hydra -- [**3269**Star][27d] [C] [microsoft/windows-driver-samples](https://github.com/microsoft/windows-driver-samples) This repo contains driver samples prepared for use with Microsoft Visual Studio and the Windows Driver Kit (WDK). It contains both Universal Windows Driver and desktop-only driver samples. -- [**3267**Star][3m] [C] [nbs-system/naxsi](https://github.com/nbs-system/naxsi) NAXSI is an open-source, high performance, low rules maintenance WAF for NGINX -- [**3266**Star][12d] [C] [virustotal/yara](https://github.com/virustotal/yara) The pattern matching swiss knife -- [**3258**Star][2m] [Py] [volatilityfoundation/volatility](https://github.com/volatilityfoundation/volatility) An advanced memory forensics framework -- [**3258**Star][5y] [C++] [google/lmctfy](https://github.com/google/lmctfy) lmctfy is the open source version of Google’s container stack, which provides Linux application containers. -- [**3255**Star][7d] [C] [mikebrady/shairport-sync](https://github.com/mikebrady/shairport-sync) AirPlay audio player. Shairport Sync adds multi-room capability with Audio Synchronisation -- [**3253**Star][7m] [JS] [sindresorhus/speed-test](https://github.com/sindresorhus/speed-test) Test your internet connection speed and ping using speedtest.net from the CLI -- [**3234**Star][8d] [Java] [oldmanpushcart/greys-anatomy](https://github.com/oldmanpushcart/greys-anatomy) Java诊断工具 +- [**3533**Star][14d] [C] [tencent/tencentos-tiny](https://github.com/tencent/tencentos-tiny) 腾讯物联网终端操作系统 +- [**3514**Star][3y] [C] [hak5darren/usb-rubber-ducky](https://github.com/hak5darren/usb-rubber-ducky) +- [**3510**Star][2d] [JS] [aol/moloch](https://github.com/aol/moloch) large scale, full packet capturing, indexing, and database system. +- [**3501**Star][8m] [Go] [fanpei91/torsniff](https://github.com/fanpei91/torsniff) torsniff - a sniffer that sniffs torrents from BitTorrent network +- [**3501**Star][8m] [Go] [fanpei91/torsniff](https://github.com/fanpei91/torsniff) a sniffer that sniffs torrents from BitTorrent network +- [**3493**Star][9m] [C] [rpisec/mbe](https://github.com/rpisec/mbe) Course materials for Modern Binary Exploitation by RPISEC +- [**3485**Star][5m] [PHP] [hanc00l/wooyun_public](https://github.com/hanc00l/wooyun_public) This repo is archived. Thanks for wooyun! 乌云公开漏洞、知识库爬虫和搜索 crawl and search for wooyun.org public bug(vulnerability) and drops +- [**3481**Star][8d] [C] [cyan4973/xxhash](https://github.com/cyan4973/xxhash) Extremely fast non-cryptographic hash algorithm +- [**3471**Star][2m] [C++] [trojan-gfw/trojan](https://github.com/trojan-gfw/trojan) An unidentifiable mechanism that helps you bypass GFW. +- [**3442**Star][9d] [C] [shellphish/how2heap](https://github.com/shellphish/how2heap) A repository for learning various heap exploitation techniques. +- [**3442**Star][8d] [Java] [meituan-dianping/robust](https://github.com/meituan-dianping/robust) Robust is an Android HotFix solution with high compatibility and high stability. Robust can fix bugs immediately without a reboot. +- [**3441**Star][15d] [Perl] [sullo/nikto](https://github.com/sullo/nikto) Nikto web server scanner +- [**3419**Star][9d] [C] [mikebrady/shairport-sync](https://github.com/mikebrady/shairport-sync) AirPlay audio player. Shairport Sync adds multi-room capability with Audio Synchronisation +- [**3412**Star][27d] [icodesign/potatso](https://github.com/icodesign/Potatso) Potatso is an iOS client that implements different proxies with the leverage of NetworkExtension framework in iOS 10+. +- [**3410**Star][5m] [Go] [jpillora/chisel](https://github.com/jpillora/chisel) A fast TCP tunnel over HTTP +- [**3408**Star][24d] [PS] [samratashok/nishang](https://github.com/samratashok/nishang) Offensive PowerShell for red team, penetration testing and offensive security. +- [**3397**Star][2y] [shadowsocksrr/shadowsocks-rss](https://github.com/shadowsocksrr/shadowsocks-rss) ShadowsocksR update rss, SSR organization +- [**3344**Star][2d] [jivoi/awesome-ml-for-cybersecurity](https://github.com/jivoi/awesome-ml-for-cybersecurity) Awesome Machine Learning for Cyber Security +- [**3343**Star][6d] [C] [screetsec/thefatrat](https://github.com/screetsec/thefatrat) Thefatrat a massive exploiting tool : Easy tool to generate backdoor and easy tool to post exploitation attack like browser attack and etc . This tool compiles a malware with popular payload and then the compiled malware can be execute on windows, android, mac . The malware that created with this tool also have an ability to bypass most AV softw… +- [**3340**Star][5m] [C++] [wangyu-/udp2raw-tunnel](https://github.com/wangyu-/udp2raw-tunnel) A Tunnel which Turns UDP Traffic into Encrypted UDP/FakeTCP/ICMP Traffic by using Raw Socket,helps you Bypass UDP FireWalls(or Unstable UDP Environment) +- [**3334**Star][10d] [Smarty] [anankke/sspanel-uim](https://github.com/anankke/sspanel-uim) Across the Great Wall we can reach every corner in the world +- [**3331**Star][15d] [Py] [google/grr](https://github.com/google/grr) remote live forensics for incident response +- [**3330**Star][2d] [Py] [stamparm/maltrail](https://github.com/stamparm/maltrail) Malicious traffic detection system +- [**3319**Star][2y] [scanate/ethlist](https://github.com/scanate/ethlist) The Comprehensive Ethereum Reading List +- [**3303**Star][22d] [C] [vanhauser-thc/thc-hydra](https://github.com/vanhauser-thc/thc-hydra) hydra +- [**3301**Star][2m] [Swift] [yagiz/bagel](https://github.com/yagiz/bagel) a little native network debugging tool for iOS +- [**3298**Star][9d] [C++] [fireice-uk/xmr-stak](https://github.com/fireice-uk/xmr-stak) Free Monero RandomX Miner and unified CryptoNight miner +- [**3285**Star][7d] [C] [microsoft/windows-driver-samples](https://github.com/microsoft/windows-driver-samples) This repo contains driver samples prepared for use with Microsoft Visual Studio and the Windows Driver Kit (WDK). It contains both Universal Windows Driver and desktop-only driver samples. +- [**3278**Star][6d] [C] [virustotal/yara](https://github.com/virustotal/yara) The pattern matching swiss knife +- [**3276**Star][3m] [C] [nbs-system/naxsi](https://github.com/nbs-system/naxsi) NAXSI is an open-source, high performance, low rules maintenance WAF for NGINX +- [**3263**Star][10d] [Java] [oldmanpushcart/greys-anatomy](https://github.com/oldmanpushcart/greys-anatomy) Java诊断工具 +- [**3262**Star][2m] [Py] [volatilityfoundation/volatility](https://github.com/volatilityfoundation/volatility) An advanced memory forensics framework +- [**3260**Star][8d] [Shell] [toniblyx/my-arsenal-of-aws-security-tools](https://github.com/toniblyx/my-arsenal-of-aws-security-tools) List of open source tools for AWS security: defensive, offensive, auditing, DFIR, etc. +- [**3260**Star][5y] [C++] [google/lmctfy](https://github.com/google/lmctfy) lmctfy is the open source version of Google’s container stack, which provides Linux application containers. +- [**3259**Star][7m] [JS] [sindresorhus/speed-test](https://github.com/sindresorhus/speed-test) Test your internet connection speed and ping using speedtest.net from the CLI +- [**3255**Star][4d] [ObjC] [objective-see/lulu](https://github.com/objective-see/lulu) LuLu is the free macOS firewall +- [**3247**Star][29d] [JS] [koenkk/zigbee2mqtt](https://github.com/koenkk/zigbee2mqtt) Zigbee +- [**3242**Star][16d] [Py] [laramies/theharvester](https://github.com/laramies/theharvester) E-mails, subdomains and names Harvester - OSINT +- [**3238**Star][2d] [TS] [jigsaw-code/outline-server](https://github.com/jigsaw-code/outline-server) Outline Manager, developed by Jigsaw. The Outline Manager application creates and manages Outline servers, powered by Shadowsocks. It uses the Electron framework to offer support for Windows, macOS and Linux. +- [**3236**Star][5m] [Go] [meshbird/meshbird](https://github.com/meshbird/meshbird) cloud-native multi-region multi-cloud decentralized private networking - [**3234**Star][2y] [CSS] [jbtronics/crookedstylesheets](https://github.com/jbtronics/crookedstylesheets) Webpage tracking only using CSS (and no JS) -- [**3232**Star][5m] [Go] [meshbird/meshbird](https://github.com/meshbird/meshbird) cloud-native multi-region multi-cloud decentralized private networking -- [**3230**Star][2m] [Objective-C] [objective-see/lulu](https://github.com/objective-see/lulu) LuLu is the free macOS firewall -- [**3225**Star][18d] [Shell] [toniblyx/my-arsenal-of-aws-security-tools](https://github.com/toniblyx/my-arsenal-of-aws-security-tools) List of open source tools for AWS security: defensive, offensive, auditing, DFIR, etc. -- [**3216**Star][14d] [Py] [laramies/theharvester](https://github.com/laramies/theharvester) E-mails, subdomains and names Harvester - OSINT -- [**3215**Star][27d] [JS] [koenkk/zigbee2mqtt](https://github.com/koenkk/zigbee2mqtt) Zigbee -- [**3214**Star][4y] [C] [shadowsocks/chinadns](https://github.com/shadowsocks/chinadns) Protect yourself against DNS poisoning in China. -- [**3214**Star][2m] [Go] [dvyukov/go-fuzz](https://github.com/dvyukov/go-fuzz) Randomized testing for Go -- [**3210**Star][11d] [C] [tmate-io/tmate](https://github.com/tmate-io/tmate) Instant Terminal Sharing -- [**3210**Star][1m] [TypeScript] [google/incremental-dom](https://github.com/google/incremental-dom) An in-place DOM diffing library -- [**3209**Star][8d] [C] [betaflight/betaflight](https://github.com/betaflight/betaflight) Open Source Flight Controller Firmware -- [**3205**Star][2m] [Shell] [gfw-breaker/ssr-accounts](https://github.com/gfw-breaker/ssr-accounts) 一键部署Shadowsocks服务;免费Shadowsocks账号分享;免费SS账号分享; 翻墙;无界,自由门,SquirrelVPN -- [**3202**Star][4m] [Objective-C] [naituw/ipapatch](https://github.com/naituw/ipapatch) Patch iOS Apps, The Easy Way, Without Jailbreak. -- [**3201**Star][7m] [HTML] [leizongmin/js-xss](https://github.com/leizongmin/js-xss) Sanitize untrusted HTML (to prevent XSS) with a configuration specified by a Whitelist -- [**3184**Star][7d] [Go] [mozilla/sops](https://github.com/mozilla/sops) Simple and flexible tool for managing secrets -- [**3182**Star][3m] [C] [yarrick/iodine](https://github.com/yarrick/iodine) Official git repo for iodine dns tunnel -- [**3182**Star][1y] [Py] [kootenpv/whereami](https://github.com/kootenpv/whereami) Uses WiFi signals and machine learning (sklearn's RandomForest) to predict where you are. -- [**3180**Star][13d] [Py] [maurosoria/dirsearch](https://github.com/maurosoria/dirsearch) Web path scanner -- [**3174**Star][8d] [Rich Text Format] [the-art-of-hacking/h4cker](https://github.com/The-Art-of-Hacking/h4cker) 资源收集:hacking、渗透、数字取证、事件响应、漏洞研究、漏洞开发、逆向 -- [**3168**Star][1m] [C++] [spiderlabs/modsecurity](https://github.com/spiderlabs/modsecurity) ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx that is developed by Trustwave's SpiderLabs. It has a robust event-based programming language which provides protection from a range of attacks against web applications and allows for HTTP traffic monitoring, logging and real-time analys… -- [**3164**Star][6m] [hslatman/awesome-threat-intelligence](https://github.com/hslatman/awesome-threat-intelligence) A curated list of Awesome Threat Intelligence resources -- [**3163**Star][24d] [C] [magnumripper/johntheripper](https://github.com/magnumripper/johntheripper) This is the official repo for John the Ripper, "Jumbo" version. The "bleeding-jumbo" branch is based on 1.9.0-Jumbo-1 which was released on May 14, 2019. An import of the "core" version of john this jumbo was based on (or newer) is found in the "master" branch (CVS: -- [**3156**Star][1m] [C] [valdikss/goodbyedpi](https://github.com/valdikss/goodbyedpi) GoodbyeDPI—Passive Deep Packet Inspection blocker and Active DPI circumvention utility (for Windows) -- [**3145**Star][1y] [Shell] [toyodadoubi/doubi](https://github.com/toyodadoubi/doubi) 一个逗比写的各种逗比脚本~ -- [**3128**Star][2y] [shadowsocksr-backup/shadowsocksr-android](https://github.com/shadowsocksr-backup/shadowsocksr-android) A ShadowsocksR client for Android -- [**3120**Star][10d] [C] [meetecho/janus-gateway](https://github.com/meetecho/janus-gateway) Janus WebRTC Server -- [**3113**Star][28d] [CSS] [readthedocs/sphinx_rtd_theme](https://github.com/readthedocs/sphinx_rtd_theme) Sphinx theme for readthedocs.org -- [**3112**Star][2m] [C++] [trojan-gfw/trojan](https://github.com/trojan-gfw/trojan) An unidentifiable mechanism that helps you bypass GFW. -- [**3109**Star][7d] [Shell] [speed47/spectre-meltdown-checker](https://github.com/speed47/spectre-meltdown-checker) Spectre, Meltdown, Foreshadow, Fallout, RIDL, ZombieLoad vulnerability/mitigation checker for Linux & BSD -- [**3109**Star][2m] [PowerShell] [fireeye/commando-vm](https://github.com/fireeye/commando-vm) Complete Mandiant Offensive VM (Commando VM), a fully customizable Windows-based pentesting virtual machine distribution. commandovm@fireeye.com -- [**3108**Star][4m] [C++] [px4/firmware](https://github.com/px4/firmware) PX4 Autopilot Software -- [**3106**Star][7d] [C] [qemu/qemu](https://github.com/qemu/qemu) Official QEMU mirror. Please see -- [**3103**Star][16d] [Shell] [1n3/sn1per](https://github.com/1n3/sn1per) Automated pentest framework for offensive security experts -- [**3102**Star][7d] [JS] [duo-labs/cloudmapper](https://github.com/duo-labs/cloudmapper) CloudMapper helps you analyze your Amazon Web Services (AWS) environments. -- [**3096**Star][28d] [meirwah/awesome-incident-response](https://github.com/meirwah/awesome-incident-response) A curated list of tools for incident response -- [**3094**Star][2m] [Py] [byt3bl33d3r/crackmapexec](https://github.com/byt3bl33d3r/crackmapexec) A swiss army knife for pentesting networks -- [**3091**Star][1m] [Java] [deathmarine/luyten](https://github.com/deathmarine/luyten) An Open Source Java Decompiler Gui for Procyon -- [**3085**Star][10d] [Shell] [trimstray/htrace.sh](https://github.com/trimstray/htrace.sh) My simple Swiss Army knife for http/https troubleshooting and profiling. -- [**3084**Star][11d] [Py] [tribler/tribler](https://github.com/tribler/tribler) Privacy enhanced BitTorrent client with P2P content discovery -- [**3084**Star][8d] [Shell] [softwaredownload/openwrt-fanqiang](https://github.com/softwaredownload/openwrt-fanqiang) 最好的路由器翻墙、科学上网教程—OpenWrt—shadowsocks -- [**3069**Star][9m] [JS] [jipegit/osxauditor](https://github.com/jipegit/osxauditor) OS X Auditor is a free Mac OS X computer forensics tool -- [**3066**Star][3m] [C] [zmap/zmap](https://github.com/zmap/zmap) ZMap is a fast single packet network scanner designed for Internet-wide network surveys. -- [**3065**Star][9d] [Go] [tencent/bk-cmdb](https://github.com/tencent/bk-cmdb) 蓝鲸智云配置平台(BlueKing CMDB) -- [**3062**Star][1y] [Swift] [zhuhaow/spechtlite](https://github.com/zhuhaow/spechtlite) A rule-based proxy for macOS -- [**3061**Star][20d] [C] [unicorn-engine/unicorn](https://github.com/unicorn-engine/unicorn) Unicorn CPU emulator framework (ARM, AArch64, M68K, Mips, Sparc, X86) -- [**3059**Star][1m] [Java] [calebfenton/simplify](https://github.com/calebfenton/simplify) Generic Android Deobfuscator -- [**3058**Star][7m] [Go] [michenriksen/aquatone](https://github.com/michenriksen/aquatone) A Tool for Domain Flyovers -- [**3046**Star][4m] [C++] [google/robotstxt](https://github.com/google/robotstxt) The repository contains Google's robots.txt parser and matcher as a C++ library (compliant to C++11). -- [**3041**Star][2m] [JS] [valve/fingerprintjs](https://github.com/valve/fingerprintjs) Anonymous browser fingerprint -- [**3039**Star][3m] [Py] [spiderlabs/responder](https://github.com/spiderlabs/responder) a LLMNR, NBT-NS and MDNS poisoner, with built-in HTTP/SMB/MSSQL/FTP/LDAP rogue authentication server supporting NTLMv1/NTLMv2/LMv2, Extended Security NTLMSSP and Basic HTTP authentication. -- [**3007**Star][9m] [C] [secwiki/linux-kernel-exploits](https://github.com/secwiki/linux-kernel-exploits) linux-kernel-exploits Linux平台提权漏洞集合 -- [**2991**Star][1y] [PHP] [owner888/phpspider](https://github.com/owner888/phpspider) 《我用爬虫一天时间“偷了”知乎一百万用户,只为证明PHP是世界上最好的语言 》所使用的程序 -- [**2983**Star][2m] [Go] [gwuhaolin/lightsocks](https://github.com/gwuhaolin/lightsocks) lightweight network obfuscate proxy, based on socks5, to replace shadowsocks -- [**2982**Star][7d] [Lua] [ntop/ntopng](https://github.com/ntop/ntopng) Web-based Traffic and Security Network Traffic Monitoring -- [**2978**Star][7d] [Py] [guardicore/monkey](https://github.com/guardicore/monkey) Infection Monkey - An automated pentest tool -- [**2962**Star][14d] [Objective-C] [google/santa](https://github.com/google/santa) A binary whitelisting/blacklisting system for macOS -- [**2947**Star][27d] [Go] [cookiey/yearning](https://github.com/cookiey/yearning) A most popular sql audit platform for mysql -- [**2937**Star][13d] [JS] [webgoat/webgoat](https://github.com/webgoat/webgoat) A deliberately insecure Web Application -- [**2937**Star][2y] [phith0n/mind-map](https://github.com/phith0n/mind-map) 各种安全相关思维导图整理收集 -- [**2936**Star][1m] [Py] [andresriancho/w3af](https://github.com/andresriancho/w3af) web application attack and audit framework, the open source web vulnerability scanner. -- [**2935**Star][19d] [Py] [cowrie/cowrie](https://github.com/cowrie/cowrie) Cowrie SSH/Telnet Honeypot -- [**2930**Star][1y] [Py] [danmcinerney/wifijammer](https://github.com/danmcinerney/wifijammer) Continuously jam all wifi clients/routers -- [**2930**Star][11m] [Shell] [91yun/serverspeeder](https://github.com/91yun/serverspeeder) 锐速破解版 -- [**2927**Star][7d] [Zeek] [zeek/zeek](https://github.com/zeek/zeek) Zeek is a powerful network analysis framework that is much different from the typical IDS you may know. -- [**2916**Star][15d] [Py] [twintproject/twint](https://github.com/twintproject/twint) An advanced Twitter scraping & OSINT tool written in Python that doesn't use Twitter's API, allowing you to scrape a user's followers, following, Tweets and more while evading most API limitations. -- [**2912**Star][2m] [Dockerfile] [thinkdevelop/free-ss-ssr](https://github.com/thinkdevelop/free-ss-ssr) SS账号、SSR账号、V2Ray账号 -- [**2907**Star][21d] [Go] [securego/gosec](https://github.com/securego/gosec) Golang security checker -- [**2897**Star][1y] [Py] [byt3bl33d3r/mitmf](https://github.com/byt3bl33d3r/mitmf) Framework for Man-In-The-Middle attacks -- [**2895**Star][10d] [C] [libfuse/sshfs](https://github.com/libfuse/sshfs) A network filesystem client to connect to SSH servers -- [**2892**Star][11d] [secfigo/awesome-fuzzing](https://github.com/secfigo/awesome-fuzzing) A curated list of fuzzing resources ( Books, courses - free and paid, videos, tools, tutorials and vulnerable applications to practice on ) for learning Fuzzing and initial phases of Exploit Development like root cause analysis. -- [**2891**Star][20d] [Py] [trustedsec/ptf](https://github.com/trustedsec/ptf) a way for modular support for up-to-date tools. -- [**2876**Star][7m] [C] [p-h-c/phc-winner-argon2](https://github.com/p-h-c/phc-winner-argon2) The password hash Argon2, winner of PHC -- [**2874**Star][4y] [Objective-C] [maciekish/iresign](https://github.com/maciekish/iresign) iReSign allows iDevice app bundles (.ipa) files to be signed or resigned with a digital certificate from Apple for distribution. This tool is aimed at enterprises users, for enterprise deployment, when the person signing the app is different than the person(s) developing it. -- [**2851**Star][10d] [JS] [evilsocket/pwnagotchi](https://github.com/evilsocket/pwnagotchi) Deep Reinforcement Learning instrumenting bettercap for WiFi pwning. -- [**2850**Star][8d] [C] [lxc/lxc](https://github.com/lxc/lxc) LXC - Linux Containers -- [**2840**Star][5m] [Py] [instantbox/instantbox](https://github.com/instantbox/instantbox) Get a clean, ready-to-go Linux box in seconds. -- [**2838**Star][11d] [Objective-C] [facebook/idb](https://github.com/facebook/idb) idb is a flexible command line interface for automating iOS simulators and devices -- [**2834**Star][8m] [C++] [wangyu-/udpspeeder](https://github.com/wangyu-/udpspeeder) A Tunnel which Improves your Network Quality on a High-latency Lossy Link by using Forward Error Correction,for All Traffics(TCP/UDP/ICMP) -- [**2830**Star][9d] [HTML] [ctf-wiki/ctf-wiki](https://github.com/ctf-wiki/ctf-wiki) CTF Wiki Online. Come and join us, we need you! -- [**2829**Star][21d] [C] [ossec/ossec-hids](https://github.com/ossec/ossec-hids) Host-based Intrusion Detection System that performs log analysis, file integrity checking, policy monitoring, rootkit detection, real-time alerting and active response. -- [**2825**Star][15d] [Py] [espressif/esptool](https://github.com/espressif/esptool) ESP8266 and ESP32 serial bootloader utility -- [**2825**Star][8m] [Shell] [goreliu/wsl-terminal](https://github.com/goreliu/wsl-terminal) Terminal emulator for Windows Subsystem for Linux (WSL) -- [**2823**Star][12d] [Go] [99designs/aws-vault](https://github.com/99designs/aws-vault) A vault for securely storing and accessing AWS credentials in development environments -- [**2820**Star][1m] [Assembly] [cirosantilli/x86-bare-metal-examples](https://github.com/cirosantilli/x86-bare-metal-examples) Dozens of minimal operating systems to learn x86 system programming. Tested on Ubuntu 17.10 host in QEMU 2.10 and real hardware. Userland cheat at: -- [**2819**Star][2y] [CSS] [maxchehab/css-keylogging](https://github.com/maxchehab/css-keylogging) Chrome extension and Express server that exploits keylogging abilities of CSS. -- [**2815**Star][4m] [C] [juliocesarfort/public-pentesting-reports](https://github.com/juliocesarfort/public-pentesting-reports) Curated list of public penetration test reports released by several consulting firms and academic security groups -- [**2810**Star][28d] [C] [tmk/tmk_keyboard](https://github.com/tmk/tmk_keyboard) Keyboard firmwares for Atmel AVR and Cortex-M -- [**2810**Star][2m] [infosecn1nja/red-teaming-toolkit](https://github.com/infosecn1nja/red-teaming-toolkit) A collection of open source and commercial tools that aid in red team operations. -- [**2805**Star][1m] [paulsec/awesome-sec-talks](https://github.com/paulsec/awesome-sec-talks) A collected list of awesome security talks -- [**2804**Star][8m] [C#] [quasar/quasarrat](https://github.com/quasar/quasarrat) Remote Administration Tool for Windows -- [**2802**Star][9m] [Py] [plasma-disassembler/plasma](https://github.com/plasma-disassembler/plasma) Plasma is an interactive disassembler for x86/ARM/MIPS. It can generates indented pseudo-code with colored syntax. -- [**2787**Star][17d] [Py] [androguard/androguard](https://github.com/androguard/androguard) Reverse engineering, Malware and goodware analysis of Android applications ... and more (ninja !) -- [**2783**Star][2y] [C] [seclab-ucr/intang](https://github.com/seclab-ucr/intang) research project for circumventing the "TCP reset attack" from the Great Firewall of China (GFW) by disrupting/desynchronizing the TCP Control Block (TCB) on the censorship devices. -- [**2779**Star][28d] [Makefile] [shadowsocks/openwrt-shadowsocks](https://github.com/shadowsocks/openwrt-shadowsocks) Shadowsocks-libev for OpenWrt/LEDE -- [**2776**Star][4y] [Lua] [loveshell/ngx_lua_waf](https://github.com/loveshell/ngx_lua_waf) ngx_lua_waf是一个基于lua-nginx-module(openresty)的web应用防火墙 -- [**2767**Star][2m] [Go] [kgretzky/evilginx2](https://github.com/kgretzky/evilginx2) Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies, allowing for the bypass of 2-factor authentication -- [**2763**Star][1m] [JS] [trufflesuite/ganache-cli](https://github.com/trufflesuite/ganache-cli) Fast Ethereum RPC client for testing and development -- [**2761**Star][10d] [Py] [jrohy/multi-v2ray](https://github.com/jrohy/multi-v2ray) v2ray easy delpoy & manage tool, support multiple user & protocol manage -- [**2755**Star][7d] [C++] [qtox/qtox](https://github.com/qtox/qtox) qTox is a chat, voice, video, and file transfer IM client using the encrypted peer-to-peer Tox protocol. -- [**2746**Star][8d] [C] [processhacker/processhacker](https://github.com/processhacker/processhacker) A free, powerful, multi-purpose tool that helps you monitor system resources, debug software and detect malware. -- [**2736**Star][8m] [Py] [p0cl4bs/wifi-pumpkin](https://github.com/P0cL4bs/WiFi-Pumpkin) Framework for Rogue Wi-Fi Access Point Attack -- [**2736**Star][1y] [C] [vanhoefm/krackattacks-scripts](https://github.com/vanhoefm/krackattacks-scripts) test if clients or access points (APs) are affected by the KRACK attack against WPA2 -- [**2735**Star][7d] [TypeScript] [webhintio/hint](https://github.com/webhintio/hint) -- [**2731**Star][22d] [Makefile] [theos/theos](https://github.com/theos/theos) A cross-platform suite of tools for building and deploying software for iOS and other platforms. -- [**2727**Star][2m] [secwiki/sec-chart](https://github.com/secwiki/sec-chart) 安全思维导图集合 -- [**2727**Star][3y] [Py] [hephaest0s/usbkill](https://github.com/hephaest0s/usbkill) an anti-forensic kill-switch that waits for a change on your USB ports and then immediately shuts down your computer. -- [**2726**Star][16d] [JS] [cyu/rack-cors](https://github.com/cyu/rack-cors) Rack Middleware for handling Cross-Origin Resource Sharing (CORS), which makes cross-origin AJAX possible. -- [**2715**Star][21d] [JS] [s0md3v/awesomexss](https://github.com/s0md3v/AwesomeXSS) Awesome XSS stuff -- [**2701**Star][3y] [Eagle] [samyk/magspoof](https://github.com/samyk/magspoof) A portable device that can spoof/emulate any magnetic stripe, credit card or hotel card "wirelessly", even on standard magstripe (non-NFC/RFID) readers. It can disable Chip&PIN and predict AMEX card numbers with 100% accuracy. -- [**2700**Star][1m] [C] [taviso/loadlibrary](https://github.com/taviso/loadlibrary) Porting Windows Dynamic Link Libraries to Linux -- [**2683**Star][4m] [Objective-C] [dantheman827/ios-app-signer](https://github.com/dantheman827/ios-app-signer) This is an app for OS X that can (re)sign apps and bundle them into ipa files that are ready to be installed on an iOS device. -- [**2681**Star][1m] [Objective-C] [kjcracks/clutch](https://github.com/kjcracks/clutch) Fast iOS executable dumper -- [**2665**Star][7d] [Go] [google/syzkaller](https://github.com/google/syzkaller) syzkaller is an unsupervised coverage-guided kernel fuzzer -- [**2660**Star][7d] [PowerShell] [redcanaryco/atomic-red-team](https://github.com/redcanaryco/atomic-red-team) Small and highly portable detection tests based on MITRE's ATT&CK. -- [**2660**Star][1y] [Py] [mame82/p4wnp1](https://github.com/mame82/p4wnp1) P4wnP1 is a highly customizable USB attack platform, based on a low cost Raspberry Pi Zero or Raspberry Pi Zero W. -- [**2658**Star][12d] [Go] [aquasecurity/trivy](https://github.com/aquasecurity/trivy) A Simple and Comprehensive Vulnerability Scanner for Containers, Suitable for CI -- [**2648**Star][3m] [Py] [drivendata/cookiecutter-data-science](https://github.com/drivendata/cookiecutter-data-science) A logical, reasonably standardized, but flexible project structure for doing and sharing data science work. -- [**2643**Star][2m] [rmusser01/infosec_reference](https://github.com/rmusser01/infosec_reference) An Information Security Reference That Doesn't Suck -- [**2638**Star][3m] [Java] [frohoff/ysoserial](https://github.com/frohoff/ysoserial) A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization. -- [**2634**Star][2m] [xairy/linux-kernel-exploitation](https://github.com/xairy/linux-kernel-exploitation) A bunch of links related to Linux kernel exploitation -- [**2633**Star][3m] [Java] [teevity/ice](https://github.com/teevity/ice) AWS Usage Tool -- [**2633**Star][1y] [HTML] [chybeta/web-security-learning](https://github.com/chybeta/web-security-learning) Web-Security-Learning -- [**2622**Star][15d] [JS] [bkimminich/juice-shop](https://github.com/bkimminich/juice-shop) OWASP Juice Shop: Probably the most modern and sophisticated insecure web application -- [**2619**Star][8m] [leandromoreira/linux-network-performance-parameters](https://github.com/leandromoreira/linux-network-performance-parameters) Learn where some of the network sysctl variables fit into the Linux/Kernel network flow -- [**2610**Star][2m] [Swift] [zhuhaow/nekit](https://github.com/zhuhaow/nekit) A toolkit for Network Extension Framework -- [**2601**Star][3y] [Ruby] [arachni/arachni](https://github.com/arachni/arachni) Web Application Security Scanner Framework -- [**2600**Star][21d] [JS] [knownsec/kcon](https://github.com/knownsec/kcon) KCon is a famous Hacker Con powered by Knownsec Team. -- [**2598**Star][8d] [JS] [popcorn-official/popcorn-desktop](https://github.com/popcorn-official/popcorn-desktop) Popcorn Time is a multi-platform, free software BitTorrent client that includes an integrated media player. Desktop ( Windows / Mac / Linux ) a Butter-Project Fork -- [**2589**Star][19d] [C++] [fanout/pushpin](https://github.com/fanout/pushpin) Reverse proxy for realtime web services -- [**2588**Star][1m] [pditommaso/awesome-pipeline](https://github.com/pditommaso/awesome-pipeline) A curated list of awesome pipeline toolkits inspired by Awesome Sysadmin -- [**2570**Star][2m] [C] [huntergregal/mimipenguin](https://github.com/huntergregal/mimipenguin) dump 当前Linux用户的登录密码 -- [**2565**Star][1m] [Shell] [medicean/vulapps](https://github.com/medicean/vulapps) 快速搭建各种漏洞环境(Various vulnerability environment) -- [**2564**Star][8y] [C] [id-software/quake](https://github.com/id-software/quake) Quake GPL Source Release -- [**2563**Star][5m] [Java] [google/binnavi](https://github.com/google/binnavi) a binary analysis IDE that allows to inspect, navigate, edit and annotate control flow graphs and call graphs of disassembled code. -- [**2555**Star][1m] [C] [esnet/iperf](https://github.com/esnet/iperf) A TCP, UDP, and SCTP network bandwidth measurement tool -- [**2554**Star][2y] [evilsocket/bettercap](https://github.com/evilsocket/bettercap) DEPRECATED, bettercap developement moved here: -- [**2547**Star][3m] [Py] [greenwolf/social_mapper](https://github.com/Greenwolf/social_mapper) 对多个社交网站的用户Profile图片进行大规模的人脸识别 -- [**2537**Star][6m] [C] [geohot/qira](https://github.com/geohot/qira) QEMU Interactive Runtime Analyser +- [**3233**Star][9d] [Go] [mozilla/sops](https://github.com/mozilla/sops) Simple and flexible tool for managing secrets +- [**3228**Star][2d] [C] [betaflight/betaflight](https://github.com/betaflight/betaflight) Open Source Flight Controller Firmware +- [**3223**Star][2m] [Shell] [gfw-breaker/ssr-accounts](https://github.com/gfw-breaker/ssr-accounts) 一键部署Shadowsocks服务;免费Shadowsocks账号分享;免费SS账号分享; 翻墙;无界,自由门,SquirrelVPN +- [**3222**Star][6d] [C] [tmate-io/tmate](https://github.com/tmate-io/tmate) Instant Terminal Sharing +- [**3222**Star][6d] [Go] [dvyukov/go-fuzz](https://github.com/dvyukov/go-fuzz) Randomized testing for Go +- [**3221**Star][4y] [C] [shadowsocks/chinadns](https://github.com/shadowsocks/chinadns) Protect yourself against DNS poisoning in China. +- [**3213**Star][1m] [TS] [google/incremental-dom](https://github.com/google/incremental-dom) An in-place DOM diffing library +- [**3210**Star][7m] [HTML] [leizongmin/js-xss](https://github.com/leizongmin/js-xss) Sanitize untrusted HTML (to prevent XSS) with a configuration specified by a Whitelist +- [**3209**Star][5m] [ObjC] [naituw/ipapatch](https://github.com/naituw/ipapatch) Patch iOS Apps, The Easy Way, Without Jailbreak. +- [**3208**Star][4m] [C] [yarrick/iodine](https://github.com/yarrick/iodine) Official git repo for iodine dns tunnel +- [**3205**Star][15d] [Py] [maurosoria/dirsearch](https://github.com/maurosoria/dirsearch) Web path scanner +- [**3202**Star][10d] [Rich Text Format] [the-art-of-hacking/h4cker](https://github.com/The-Art-of-Hacking/h4cker) 资源收集:hacking、渗透、数字取证、事件响应、漏洞研究、漏洞开发、逆向 +- [**3187**Star][1y] [Py] [kootenpv/whereami](https://github.com/kootenpv/whereami) Uses WiFi signals and machine learning (sklearn's RandomForest) to predict where you are. +- [**3187**Star][6m] [hslatman/awesome-threat-intelligence](https://github.com/hslatman/awesome-threat-intelligence) A curated list of Awesome Threat Intelligence resources +- [**3186**Star][1m] [C++] [spiderlabs/modsecurity](https://github.com/spiderlabs/modsecurity) ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx that is developed by Trustwave's SpiderLabs. It has a robust event-based programming language which provides protection from a range of attacks against web applications and allows for HTTP traffic monitoring, logging and real-time analys… +- [**3180**Star][27d] [C] [magnumripper/johntheripper](https://github.com/magnumripper/johntheripper) This is the official repo for John the Ripper, "Jumbo" version. The "bleeding-jumbo" branch is based on 1.9.0-Jumbo-1 which was released on May 14, 2019. An import of the "core" version of john this jumbo was based on (or newer) is found in the "master" branch (CVS: +- [**3169**Star][1m] [C] [valdikss/goodbyedpi](https://github.com/valdikss/goodbyedpi) GoodbyeDPI—Passive Deep Packet Inspection blocker and Active DPI circumvention utility (for Windows) +- [**3162**Star][1y] [Shell] [toyodadoubi/doubi](https://github.com/toyodadoubi/doubi) 一个逗比写的各种逗比脚本~ +- [**3159**Star][3d] [JS] [minbrowser/min](https://github.com/minbrowser/min) A fast, minimal browser that protects your privacy +- [**3140**Star][6d] [C] [meetecho/janus-gateway](https://github.com/meetecho/janus-gateway) Janus WebRTC Server +- [**3137**Star][2y] [shadowsocksr-backup/shadowsocksr-android](https://github.com/shadowsocksr-backup/shadowsocksr-android) A ShadowsocksR client for Android +- [**3134**Star][2d] [C++] [px4/firmware](https://github.com/px4/firmware) PX4 Autopilot Software +- [**3125**Star][3d] [Shell] [1n3/sn1per](https://github.com/1n3/sn1per) Automated pentest framework for offensive security experts +- [**3123**Star][30d] [meirwah/awesome-incident-response](https://github.com/meirwah/awesome-incident-response) A curated list of tools for incident response +- [**3123**Star][2m] [PS] [fireeye/commando-vm](https://github.com/fireeye/commando-vm) Complete Mandiant Offensive VM (Commando VM), a fully customizable Windows-based pentesting virtual machine distribution. commandovm@fireeye.com +- [**3122**Star][5d] [Go] [uber/kraken](https://github.com/uber/kraken) P2P Docker registry capable of distributing TBs of data in seconds +- [**3121**Star][30d] [CSS] [readthedocs/sphinx_rtd_theme](https://github.com/readthedocs/sphinx_rtd_theme) Sphinx theme for readthedocs.org +- [**3121**Star][8d] [JS] [duo-labs/cloudmapper](https://github.com/duo-labs/cloudmapper) CloudMapper helps you analyze your Amazon Web Services (AWS) environments. +- [**3118**Star][3d] [Shell] [speed47/spectre-meltdown-checker](https://github.com/speed47/spectre-meltdown-checker) Spectre, Meltdown, Foreshadow, Fallout, RIDL, ZombieLoad vulnerability/mitigation checker for Linux & BSD +- [**3113**Star][2d] [C] [qemu/qemu](https://github.com/qemu/qemu) Official QEMU mirror. Please see +- [**3107**Star][2m] [Py] [byt3bl33d3r/crackmapexec](https://github.com/byt3bl33d3r/crackmapexec) A swiss army knife for pentesting networks +- [**3106**Star][7d] [Java] [deathmarine/luyten](https://github.com/deathmarine/luyten) An Open Source Java Decompiler Gui for Procyon +- [**3105**Star][10d] [Shell] [softwaredownload/openwrt-fanqiang](https://github.com/softwaredownload/openwrt-fanqiang) 最好的路由器翻墙、科学上网教程—OpenWrt—shadowsocks +- [**3088**Star][9d] [Shell] [trimstray/htrace.sh](https://github.com/trimstray/htrace.sh) My simple Swiss Army knife for http/https troubleshooting and profiling. +- [**3087**Star][3d] [Py] [tribler/tribler](https://github.com/tribler/tribler) Privacy enhanced BitTorrent client with P2P content discovery +- [**3085**Star][11d] [Go] [tencent/bk-cmdb](https://github.com/tencent/bk-cmdb) 蓝鲸智云配置平台(BlueKing CMDB) +- [**3084**Star][22d] [C] [unicorn-engine/unicorn](https://github.com/unicorn-engine/unicorn) Unicorn CPU emulator framework (ARM, AArch64, M68K, Mips, Sparc, X86) +- [**3080**Star][3m] [C] [zmap/zmap](https://github.com/zmap/zmap) ZMap is a fast single packet network scanner designed for Internet-wide network surveys. +- [**3076**Star][7m] [Go] [michenriksen/aquatone](https://github.com/michenriksen/aquatone) A Tool for Domain Flyovers +- [**3071**Star][9m] [JS] [jipegit/osxauditor](https://github.com/jipegit/osxauditor) OS X Auditor is a free Mac OS X computer forensics tool +- [**3065**Star][1m] [Java] [calebfenton/simplify](https://github.com/calebfenton/simplify) Generic Android Deobfuscator +- [**3063**Star][1y] [Swift] [zhuhaow/spechtlite](https://github.com/zhuhaow/spechtlite) A rule-based proxy for macOS +- [**3052**Star][2m] [JS] [valve/fingerprintjs](https://github.com/valve/fingerprintjs) Anonymous browser fingerprint +- [**3049**Star][4m] [C++] [google/robotstxt](https://github.com/google/robotstxt) The repository contains Google's robots.txt parser and matcher as a C++ library (compliant to C++11). +- [**3043**Star][3m] [Py] [spiderlabs/responder](https://github.com/spiderlabs/responder) a LLMNR, NBT-NS and MDNS poisoner, with built-in HTTP/SMB/MSSQL/FTP/LDAP rogue authentication server supporting NTLMv1/NTLMv2/LMv2, Extended Security NTLMSSP and Basic HTTP authentication. +- [**3029**Star][2m] [Go] [gwuhaolin/lightsocks](https://github.com/gwuhaolin/lightsocks) lightweight network obfuscate proxy, based on socks5, to replace shadowsocks +- [**3027**Star][9m] [C] [secwiki/linux-kernel-exploits](https://github.com/secwiki/linux-kernel-exploits) linux-kernel-exploits Linux平台提权漏洞集合 +- [**3001**Star][1y] [PHP] [owner888/phpspider](https://github.com/owner888/phpspider) 《我用爬虫一天时间“偷了”知乎一百万用户,只为证明PHP是世界上最好的语言 》所使用的程序 +- [**2991**Star][2d] [JS] [ntop/ntopng](https://github.com/ntop/ntopng) Web-based Traffic and Security Network Traffic Monitoring +- [**2986**Star][7d] [Py] [guardicore/monkey](https://github.com/guardicore/monkey) Infection Monkey - An automated pentest tool +- [**2969**Star][29d] [Go] [cookiey/yearning](https://github.com/cookiey/yearning) A most popular sql audit platform for mysql +- [**2968**Star][2d] [ObjC] [google/santa](https://github.com/google/santa) A binary whitelisting/blacklisting system for macOS +- [**2955**Star][4d] [Py] [twintproject/twint](https://github.com/twintproject/twint) An advanced Twitter scraping & OSINT tool written in Python that doesn't use Twitter's API, allowing you to scrape a user's followers, following, Tweets and more while evading most API limitations. +- [**2955**Star][11d] [Go] [dominikh/go-tools](https://github.com/dominikh/go-tools) Staticcheck – a collection of static analysis tools for working with Go code +- [**2949**Star][8d] [JS] [webgoat/webgoat](https://github.com/webgoat/webgoat) A deliberately insecure Web Application +- [**2948**Star][2m] [Dockerfile] [thinkdevelop/free-ss-ssr](https://github.com/thinkdevelop/free-ss-ssr) SS账号、SSR账号、V2Ray账号 +- [**2947**Star][1m] [Py] [andresriancho/w3af](https://github.com/andresriancho/w3af) web application attack and audit framework, the open source web vulnerability scanner. +- [**2945**Star][2y] [phith0n/mind-map](https://github.com/phith0n/mind-map) 各种安全相关思维导图整理收集 +- [**2942**Star][21d] [Py] [cowrie/cowrie](https://github.com/cowrie/cowrie) Cowrie SSH/Telnet Honeypot +- [**2936**Star][1y] [Py] [danmcinerney/wifijammer](https://github.com/danmcinerney/wifijammer) Continuously jam all wifi clients/routers +- [**2933**Star][2d] [Zeek] [zeek/zeek](https://github.com/zeek/zeek) Zeek is a powerful network analysis framework that is much different from the typical IDS you may know. +- [**2932**Star][11m] [Shell] [91yun/serverspeeder](https://github.com/91yun/serverspeeder) 锐速破解版 +- [**2920**Star][23d] [Go] [securego/gosec](https://github.com/securego/gosec) Golang security checker +- [**2916**Star][2d] [JS] [evilsocket/pwnagotchi](https://github.com/evilsocket/pwnagotchi) Deep Reinforcement Learning instrumenting bettercap for WiFi pwning. +- [**2915**Star][12d] [C] [libfuse/sshfs](https://github.com/libfuse/sshfs) A network filesystem client to connect to SSH servers +- [**2909**Star][2d] [Py] [trustedsec/ptf](https://github.com/trustedsec/ptf) a way for modular support for up-to-date tools. +- [**2901**Star][1y] [Py] [byt3bl33d3r/mitmf](https://github.com/byt3bl33d3r/mitmf) Framework for Man-In-The-Middle attacks +- [**2897**Star][3d] [secfigo/awesome-fuzzing](https://github.com/secfigo/awesome-fuzzing) A curated list of fuzzing resources ( Books, courses - free and paid, videos, tools, tutorials and vulnerable applications to practice on ) for learning Fuzzing and initial phases of Exploit Development like root cause analysis. +- [**2883**Star][7m] [C] [p-h-c/phc-winner-argon2](https://github.com/p-h-c/phc-winner-argon2) The password hash Argon2, winner of PHC +- [**2877**Star][4y] [ObjC] [maciekish/iresign](https://github.com/maciekish/iresign) iReSign allows iDevice app bundles (.ipa) files to be signed or resigned with a digital certificate from Apple for distribution. This tool is aimed at enterprises users, for enterprise deployment, when the person signing the app is different than the person(s) developing it. +- [**2858**Star][2d] [C] [lxc/lxc](https://github.com/lxc/lxc) LXC - Linux Containers +- [**2850**Star][2d] [HTML] [ctf-wiki/ctf-wiki](https://github.com/ctf-wiki/ctf-wiki) CTF Wiki Online. Come and join us, we need you! +- [**2850**Star][4d] [Go] [99designs/aws-vault](https://github.com/99designs/aws-vault) A vault for securely storing and accessing AWS credentials in development environments +- [**2845**Star][2d] [ObjC] [facebook/idb](https://github.com/facebook/idb) idb is a flexible command line interface for automating iOS simulators and devices +- [**2842**Star][5m] [Py] [instantbox/instantbox](https://github.com/instantbox/instantbox) Get a clean, ready-to-go Linux box in seconds. +- [**2840**Star][23d] [C] [ossec/ossec-hids](https://github.com/ossec/ossec-hids) Host-based Intrusion Detection System that performs log analysis, file integrity checking, policy monitoring, rootkit detection, real-time alerting and active response. +- [**2840**Star][2m] [infosecn1nja/red-teaming-toolkit](https://github.com/infosecn1nja/red-teaming-toolkit) A collection of open source and commercial tools that aid in red team operations. +- [**2839**Star][8m] [C++] [wangyu-/udpspeeder](https://github.com/wangyu-/udpspeeder) A Tunnel which Improves your Network Quality on a High-latency Lossy Link by using Forward Error Correction,for All Traffics(TCP/UDP/ICMP) +- [**2837**Star][17d] [Py] [espressif/esptool](https://github.com/espressif/esptool) ESP8266 and ESP32 serial bootloader utility +- [**2834**Star][8m] [Shell] [goreliu/wsl-terminal](https://github.com/goreliu/wsl-terminal) Terminal emulator for Windows Subsystem for Linux (WSL) +- [**2829**Star][4m] [C] [juliocesarfort/public-pentesting-reports](https://github.com/juliocesarfort/public-pentesting-reports) Curated list of public penetration test reports released by several consulting firms and academic security groups +- [**2829**Star][1m] [Assembly] [cirosantilli/x86-bare-metal-examples](https://github.com/cirosantilli/x86-bare-metal-examples) Dozens of minimal operating systems to learn x86 system programming. Tested on Ubuntu 17.10 host in QEMU 2.10 and real hardware. Userland cheat at: +- [**2823**Star][2y] [CSS] [maxchehab/css-keylogging](https://github.com/maxchehab/css-keylogging) Chrome extension and Express server that exploits keylogging abilities of CSS. +- [**2820**Star][7d] [C] [tmk/tmk_keyboard](https://github.com/tmk/tmk_keyboard) Keyboard firmwares for Atmel AVR and Cortex-M +- [**2814**Star][8m] [C#] [quasar/quasarrat](https://github.com/quasar/quasarrat) Remote Administration Tool for Windows +- [**2814**Star][5d] [Py] [jrohy/multi-v2ray](https://github.com/jrohy/multi-v2ray) v2ray easy delpoy & manage tool, support multiple user & protocol manage +- [**2808**Star][2m] [paulsec/awesome-sec-talks](https://github.com/paulsec/awesome-sec-talks) A collected list of awesome security talks +- [**2803**Star][9m] [Py] [plasma-disassembler/plasma](https://github.com/plasma-disassembler/plasma) Plasma is an interactive disassembler for x86/ARM/MIPS. It can generates indented pseudo-code with colored syntax. +- [**2798**Star][19d] [Py] [androguard/androguard](https://github.com/androguard/androguard) Reverse engineering, Malware and goodware analysis of Android applications ... and more (ninja !) +- [**2793**Star][6d] [C] [klange/toaruos](https://github.com/klange/toaruos) A completely-from-scratch hobby operating system: bootloader, kernel, drivers, C library, and userspace including a composited graphical UI, dynamic linker, syntax-highlighting text editor, network stack, etc. +- [**2793**Star][2m] [Go] [kgretzky/evilginx2](https://github.com/kgretzky/evilginx2) Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies, allowing for the bypass of 2-factor authentication +- [**2791**Star][7d] [C++] [xmrig/xmrig](https://github.com/xmrig/xmrig) xmrig: 门罗币挖矿代码 CPU 版 +- [**2789**Star][4y] [Lua] [loveshell/ngx_lua_waf](https://github.com/loveshell/ngx_lua_waf) ngx_lua_waf是一个基于lua-nginx-module(openresty)的web应用防火墙 +- [**2783**Star][30d] [Makefile] [shadowsocks/openwrt-shadowsocks](https://github.com/shadowsocks/openwrt-shadowsocks) Shadowsocks-libev for OpenWrt/LEDE +- [**2782**Star][2y] [C] [seclab-ucr/intang](https://github.com/seclab-ucr/intang) research project for circumventing the "TCP reset attack" from the Great Firewall of China (GFW) by disrupting/desynchronizing the TCP Control Block (TCB) on the censorship devices. +- [**2777**Star][9d] [C++] [qtox/qtox](https://github.com/qtox/qtox) qTox is a chat, voice, video, and file transfer IM client using the encrypted peer-to-peer Tox protocol. +- [**2769**Star][4d] [C] [processhacker/processhacker](https://github.com/processhacker/processhacker) A free, powerful, multi-purpose tool that helps you monitor system resources, debug software and detect malware. +- [**2766**Star][1m] [JS] [trufflesuite/ganache-cli](https://github.com/trufflesuite/ganache-cli) Fast Ethereum RPC client for testing and development +- [**2756**Star][2m] [secwiki/sec-chart](https://github.com/secwiki/sec-chart) 安全思维导图集合 +- [**2742**Star][5d] [TS] [webhintio/hint](https://github.com/webhintio/hint) +- [**2742**Star][24d] [Makefile] [theos/theos](https://github.com/theos/theos) A cross-platform suite of tools for building and deploying software for iOS and other platforms. +- [**2741**Star][8m] [Py] [p0cl4bs/wifi-pumpkin](https://github.com/P0cL4bs/WiFi-Pumpkin) Framework for Rogue Wi-Fi Access Point Attack +- [**2739**Star][23d] [JS] [s0md3v/awesomexss](https://github.com/s0md3v/AwesomeXSS) Awesome XSS stuff +- [**2737**Star][1y] [C] [vanhoefm/krackattacks-scripts](https://github.com/vanhoefm/krackattacks-scripts) test if clients or access points (APs) are affected by the KRACK attack against WPA2 +- [**2735**Star][18d] [JS] [cyu/rack-cors](https://github.com/cyu/rack-cors) Rack Middleware for handling Cross-Origin Resource Sharing (CORS), which makes cross-origin AJAX possible. +- [**2730**Star][3y] [Py] [hephaest0s/usbkill](https://github.com/hephaest0s/usbkill) an anti-forensic kill-switch that waits for a change on your USB ports and then immediately shuts down your computer. +- [**2717**Star][2d] [PS] [redcanaryco/atomic-red-team](https://github.com/redcanaryco/atomic-red-team) Small and highly portable detection tests based on MITRE's ATT&CK. +- [**2713**Star][1m] [C] [taviso/loadlibrary](https://github.com/taviso/loadlibrary) Porting Windows Dynamic Link Libraries to Linux +- [**2703**Star][3y] [Eagle] [samyk/magspoof](https://github.com/samyk/magspoof) A portable device that can spoof/emulate any magnetic stripe, credit card or hotel card "wirelessly", even on standard magstripe (non-NFC/RFID) readers. It can disable Chip&PIN and predict AMEX card numbers with 100% accuracy. +- [**2701**Star][3d] [Go] [aquasecurity/trivy](https://github.com/aquasecurity/trivy) A Simple and Comprehensive Vulnerability Scanner for Containers, Suitable for CI +- [**2698**Star][7d] [ObjC] [dantheman827/ios-app-signer](https://github.com/dantheman827/ios-app-signer) This is an app for OS X that can (re)sign apps and bundle them into ipa files that are ready to be installed on an iOS device. +- [**2690**Star][1m] [ObjC] [kjcracks/clutch](https://github.com/kjcracks/clutch) Fast iOS executable dumper +- [**2682**Star][22d] [Go] [google/syzkaller](https://github.com/google/syzkaller) syzkaller is an unsupervised coverage-guided kernel fuzzer +- [**2681**Star][1y] [Py] [mame82/p4wnp1](https://github.com/mame82/p4wnp1) P4wnP1 is a highly customizable USB attack platform, based on a low cost Raspberry Pi Zero or Raspberry Pi Zero W. +- [**2674**Star][3m] [Py] [drivendata/cookiecutter-data-science](https://github.com/drivendata/cookiecutter-data-science) A logical, reasonably standardized, but flexible project structure for doing and sharing data science work. +- [**2662**Star][2m] [rmusser01/infosec_reference](https://github.com/rmusser01/infosec_reference) An Information Security Reference That Doesn't Suck +- [**2654**Star][17d] [JS] [bkimminich/juice-shop](https://github.com/bkimminich/juice-shop) OWASP Juice Shop: Probably the most modern and sophisticated insecure web application +- [**2652**Star][3m] [Java] [frohoff/ysoserial](https://github.com/frohoff/ysoserial) A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization. +- [**2645**Star][2m] [xairy/linux-kernel-exploitation](https://github.com/xairy/linux-kernel-exploitation) A bunch of links related to Linux kernel exploitation +- [**2645**Star][1y] [HTML] [chybeta/web-security-learning](https://github.com/chybeta/web-security-learning) Web-Security-Learning +- [**2641**Star][1y] [C] [ckolivas/cgminer](https://github.com/ckolivas/cgminer) ASIC and FPGA miner in c for bitcoin +- [**2640**Star][2d] [Go] [slackhq/nebula](https://github.com/slackhq/nebula) A scalable overlay networking tool with a focus on performance, simplicity and security +- [**2637**Star][4m] [Java] [teevity/ice](https://github.com/teevity/ice) AWS Usage Tool +- [**2625**Star][8m] [leandromoreira/linux-network-performance-parameters](https://github.com/leandromoreira/linux-network-performance-parameters) Learn where some of the network sysctl variables fit into the Linux/Kernel network flow +- [**2615**Star][2m] [Swift] [zhuhaow/nekit](https://github.com/zhuhaow/nekit) A toolkit for Network Extension Framework +- [**2612**Star][4d] [JS] [popcorn-official/popcorn-desktop](https://github.com/popcorn-official/popcorn-desktop) Popcorn Time is a multi-platform, free software BitTorrent client that includes an integrated media player. Desktop ( Windows / Mac / Linux ) a Butter-Project Fork +- [**2607**Star][3y] [Ruby] [arachni/arachni](https://github.com/arachni/arachni) Web Application Security Scanner Framework +- [**2603**Star][23d] [JS] [knownsec/kcon](https://github.com/knownsec/kcon) KCon is a famous Hacker Con powered by Knownsec Team. +- [**2601**Star][1m] [pditommaso/awesome-pipeline](https://github.com/pditommaso/awesome-pipeline) A curated list of awesome pipeline toolkits inspired by Awesome Sysadmin +- [**2596**Star][21d] [C++] [fanout/pushpin](https://github.com/fanout/pushpin) Reverse proxy for realtime web services +- [**2581**Star][3d] [Go] [adguardteam/adguardhome](https://github.com/adguardteam/adguardhome) Network-wide ads & trackers blocking DNS server +- [**2581**Star][1m] [Shell] [medicean/vulapps](https://github.com/medicean/vulapps) 快速搭建各种漏洞环境(Various vulnerability environment) +- [**2575**Star][2m] [C] [huntergregal/mimipenguin](https://github.com/huntergregal/mimipenguin) dump 当前Linux用户的登录密码 +- [**2574**Star][8y] [C] [id-software/quake](https://github.com/id-software/quake) Quake GPL Source Release +- [**2568**Star][1m] [C] [esnet/iperf](https://github.com/esnet/iperf) A TCP, UDP, and SCTP network bandwidth measurement tool +- [**2566**Star][2d] [C++] [danmar/cppcheck](https://github.com/danmar/cppcheck) static analysis of C/C++ code +- [**2565**Star][5m] [Java] [google/binnavi](https://github.com/google/binnavi) a binary analysis IDE that allows to inspect, navigate, edit and annotate control flow graphs and call graphs of disassembled code. +- [**2562**Star][3m] [Py] [greenwolf/social_mapper](https://github.com/Greenwolf/social_mapper) 对多个社交网站的用户Profile图片进行大规模的人脸识别 +- [**2553**Star][2y] [evilsocket/bettercap](https://github.com/evilsocket/bettercap) DEPRECATED, bettercap developement moved here: +- [**2551**Star][9d] [Py] [cloudflare/flan](https://github.com/cloudflare/flan) A pretty sweet vulnerability scanner +- [**2549**Star][6m] [C] [geohot/qira](https://github.com/geohot/qira) QEMU Interactive Runtime Analyser +- [**2543**Star][19d] [Py] [hugsy/gef](https://github.com/hugsy/gef) GDB Enhanced Features for exploit devs & reversers +- [**2542**Star][23d] [Go] [drk1wi/modlishka](https://github.com/drk1wi/modlishka) Modlishka. Reverse Proxy. +- [**2533**Star][8m] [offensive-security/kali-nethunter](https://github.com/offensive-security/kali-nethunter) The Kali NetHunter Project - [**2533**Star][2y] [Py] [google/nogotofail](https://github.com/google/nogotofail) An on-path blackbox network traffic security testing tool -- [**2532**Star][8m] [offensive-security/kali-nethunter](https://github.com/offensive-security/kali-nethunter) The Kali NetHunter Project -- [**2530**Star][17d] [Py] [hugsy/gef](https://github.com/hugsy/gef) GDB Enhanced Features for exploit devs & reversers -- [**2521**Star][21d] [Go] [drk1wi/modlishka](https://github.com/drk1wi/modlishka) Modlishka. Reverse Proxy. -- [**2520**Star][3y] [HTML] [dirtycow/dirtycow.github.io](https://github.com/dirtycow/dirtycow.github.io) Dirty COW -- [**2515**Star][24d] [C] [yrutschle/sslh](https://github.com/yrutschle/sslh) Applicative Protocol Multiplexer (e.g. share SSH and HTTPS on the same port) -- [**2510**Star][11d] [Shell] [teddysun/across](https://github.com/teddysun/across) This is a shell script for configure and start WireGuard VPN server -- [**2505**Star][3m] [kbandla/aptnotes](https://github.com/kbandla/aptnotes) Various public documents, whitepapers and articles about APT campaigns -- [**2505**Star][3y] [C] [dhavalkapil/icmptunnel](https://github.com/dhavalkapil/icmptunnel) Transparently tunnel your IP traffic through ICMP echo and reply packets. +- [**2526**Star][2d] [Shell] [teddysun/across](https://github.com/teddysun/across) This is a shell script for configure and start WireGuard VPN server +- [**2525**Star][3y] [HTML] [dirtycow/dirtycow.github.io](https://github.com/dirtycow/dirtycow.github.io) Dirty COW +- [**2522**Star][26d] [C] [yrutschle/sslh](https://github.com/yrutschle/sslh) Applicative Protocol Multiplexer (e.g. share SSH and HTTPS on the same port) +- [**2516**Star][3m] [kbandla/aptnotes](https://github.com/kbandla/aptnotes) Various public documents, whitepapers and articles about APT campaigns +- [**2508**Star][5m] [Go] [oj/gobuster](https://github.com/oj/gobuster) Directory/File, DNS and VHost busting tool written in Go +- [**2507**Star][2m] [Java] [jboss-javassist/javassist](https://github.com/jboss-javassist/javassist) Java bytecode engineering toolkit +- [**2507**Star][3y] [C] [dhavalkapil/icmptunnel](https://github.com/dhavalkapil/icmptunnel) Transparently tunnel your IP traffic through ICMP echo and reply packets. - [**2503**Star][7m] [C++] [chengr28/pcap_dnsproxy](https://github.com/chengr28/pcap_dnsproxy) Pcap_DNSProxy, a local DNS server based on packet capturing -- [**2495**Star][2m] [Java] [jboss-javassist/javassist](https://github.com/jboss-javassist/javassist) Java bytecode engineering toolkit -- [**2488**Star][1y] [onlurking/awesome-infosec](https://github.com/onlurking/awesome-infosec) A curated list of awesome infosec courses and training resources. -- [**2486**Star][26d] [Py] [ysrc/xunfeng](https://github.com/ysrc/xunfeng) 巡风是一款适用于企业内网的漏洞快速应急,巡航扫描系统。 -- [**2481**Star][5m] [Go] [oj/gobuster](https://github.com/oj/gobuster) Directory/File, DNS and VHost busting tool written in Go -- [**2480**Star][8d] [Go] [adguardteam/adguardhome](https://github.com/adguardteam/adguardhome) Network-wide ads & trackers blocking DNS server +- [**2501**Star][28d] [Py] [ysrc/xunfeng](https://github.com/ysrc/xunfeng) 巡风是一款适用于企业内网的漏洞快速应急,巡航扫描系统。 +- [**2498**Star][6m] [taichi-framework/taichi](https://github.com/taichi-framework/taichi) A framework to use Xposed module with or without Root/Unlock bootloader, supportting Android 5.0 ~ 10.0 +- [**2497**Star][6d] [onlurking/awesome-infosec](https://github.com/onlurking/awesome-infosec) A curated list of awesome infosec courses and training resources. +- [**2488**Star][5y] [PHP] [audi-1/sqli-labs](https://github.com/audi-1/sqli-labs) SQLI labs to test error based, Blind boolean based, Time based. - [**2480**Star][2y] [Py] [feross/spoofmac](https://github.com/feross/spoofmac) Spoof your MAC address -- [**2473**Star][5y] [PHP] [audi-1/sqli-labs](https://github.com/audi-1/sqli-labs) SQLI labs to test error based, Blind boolean based, Time based. -- [**2472**Star][11m] [JS] [weixin/miaow](https://github.com/weixin/Miaow) A set of plugins for Sketch include drawing links & marks, UI Kit & Color sync, font & text replacing. -- [**2470**Star][6m] [taichi-framework/taichi](https://github.com/taichi-framework/taichi) A framework to use Xposed module with or without Root/Unlock bootloader, supportting Android 5.0 ~ 10.0 -- [**2463**Star][13d] [JS] [vitaly-t/pg-promise](https://github.com/vitaly-t/pg-promise) PostgreSQL interface for Node.js -- [**2458**Star][3m] [C] [martin-ger/esp_wifi_repeater](https://github.com/martin-ger/esp_wifi_repeater) A full functional WiFi Repeater (correctly: a WiFi NAT Router) -- [**2456**Star][4m] [Go] [ne0nd0g/merlin](https://github.com/ne0nd0g/merlin) Merlin is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in golang. -- [**2454**Star][24d] [C++] [pavel-odintsov/fastnetmon](https://github.com/pavel-odintsov/fastnetmon) very fast DDoS analyzer with sflow/netflow/mirror support -- [**2453**Star][11m] [C#] [yck1509/confuserex](https://github.com/yck1509/confuserex) An open-source, free protector for .NET applications +- [**2476**Star][11m] [JS] [weixin/miaow](https://github.com/weixin/Miaow) A set of plugins for Sketch include drawing links & marks, UI Kit & Color sync, font & text replacing. +- [**2476**Star][4m] [Go] [ne0nd0g/merlin](https://github.com/ne0nd0g/merlin) Merlin is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in golang. +- [**2469**Star][6d] [JS] [vitaly-t/pg-promise](https://github.com/vitaly-t/pg-promise) PostgreSQL interface for Node.js +- [**2466**Star][30d] [Py] [smicallef/spiderfoot](https://github.com/smicallef/spiderfoot) SpiderFoot, the most complete OSINT collection and reconnaissance tool. +- [**2464**Star][3m] [C] [martin-ger/esp_wifi_repeater](https://github.com/martin-ger/esp_wifi_repeater) A full functional WiFi Repeater (correctly: a WiFi NAT Router) +- [**2461**Star][11m] [C#] [yck1509/confuserex](https://github.com/yck1509/confuserex) An open-source, free protector for .NET applications +- [**2461**Star][26d] [C++] [pavel-odintsov/fastnetmon](https://github.com/pavel-odintsov/fastnetmon) very fast DDoS analyzer with sflow/netflow/mirror support +- [**2454**Star][21d] [Shell] [rebootuser/linenum](https://github.com/rebootuser/linenum) Scripted Local Linux Enumeration & Privilege Escalation Checks - [**2451**Star][3y] [Py] [google/enjarify](https://github.com/google/enjarify) a tool for translating Dalvik bytecode to equivalent Java bytecode. -- [**2441**Star][28d] [Py] [smicallef/spiderfoot](https://github.com/smicallef/spiderfoot) SpiderFoot, the most complete OSINT collection and reconnaissance tool. -- [**2424**Star][7d] [PHP] [misp/misp](https://github.com/misp/misp) MISP (core software) - Open Source Threat Intelligence and Sharing Platform (formely known as Malware Information Sharing Platform) -- [**2420**Star][19d] [Shell] [rebootuser/linenum](https://github.com/rebootuser/linenum) Scripted Local Linux Enumeration & Privilege Escalation Checks -- [**2415**Star][1m] [Py] [0xinfection/awesome-waf](https://github.com/0xinfection/awesome-waf) -- [**2412**Star][23d] [Py] [pwndbg/pwndbg](https://github.com/pwndbg/pwndbg) Exploit Development and Reverse Engineering with GDB Made Easy -- [**2411**Star][3y] [Py] [arthepsy/ssh-audit](https://github.com/arthepsy/ssh-audit) SSH server auditing (banner, key exchange, encryption, mac, compression, compatibility, security, etc) -- [**2407**Star][1m] [TSQL] [rapid7/metasploitable3](https://github.com/rapid7/metasploitable3) Metasploitable3 is a VM that is built from the ground up with a large amount of security vulnerabilities. -- [**2404**Star][24d] [Py] [infobyte/faraday](https://github.com/infobyte/faraday) Collaborative Penetration Test and Vulnerability Management Platform -- [**2399**Star][3y] [rpisec/malware](https://github.com/rpisec/malware) Course materials for Malware Analysis by RPISEC +- [**2444**Star][2d] [PHP] [misp/misp](https://github.com/misp/misp) MISP (core software) - Open Source Threat Intelligence and Sharing Platform (formely known as Malware Information Sharing Platform) +- [**2429**Star][1m] [Py] [0xinfection/awesome-waf](https://github.com/0xinfection/awesome-waf) +- [**2423**Star][2d] [Py] [pwndbg/pwndbg](https://github.com/pwndbg/pwndbg) Exploit Development and Reverse Engineering with GDB Made Easy +- [**2420**Star][1m] [TSQL] [rapid7/metasploitable3](https://github.com/rapid7/metasploitable3) Metasploitable3 is a VM that is built from the ground up with a large amount of security vulnerabilities. +- [**2417**Star][26d] [Py] [infobyte/faraday](https://github.com/infobyte/faraday) Collaborative Penetration Test and Vulnerability Management Platform +- [**2416**Star][3y] [Py] [arthepsy/ssh-audit](https://github.com/arthepsy/ssh-audit) SSH server auditing (banner, key exchange, encryption, mac, compression, compatibility, security, etc) +- [**2411**Star][26d] [Py] [xmendez/wfuzz](https://github.com/xmendez/wfuzz) Web application fuzzer +- [**2410**Star][8m] [Py] [lionsec/katoolin](https://github.com/lionsec/katoolin) Automatically install all Kali linux tools +- [**2407**Star][3y] [rpisec/malware](https://github.com/rpisec/malware) Course materials for Malware Analysis by RPISEC +- [**2404**Star][20d] [Java] [m66b/netguard](https://github.com/m66b/netguard) A simple way to block access to the internet per app - [**2395**Star][3y] [OCaml] [facebookarchive/pfff](https://github.com/facebookarchive/pfff) Tools for code analysis, visualizations, or style-preserving source transformation. -- [**2395**Star][24d] [Py] [xmendez/wfuzz](https://github.com/xmendez/wfuzz) Web application fuzzer -- [**2391**Star][8m] [Py] [lionsec/katoolin](https://github.com/lionsec/katoolin) Automatically install all Kali linux tools -- [**2381**Star][2y] [Py] [secretsquirrel/the-backdoor-factory](https://github.com/secretsquirrel/the-backdoor-factory) Patch PE, ELF, Mach-O binaries with shellcode (NOT Supported) -- [**2375**Star][1y] [Py] [danmcinerney/lans.py](https://github.com/danmcinerney/lans.py) Inject code and spy on wifi users +- [**2392**Star][1m] [Go] [xtaci/kcp-go](https://github.com/xtaci/kcp-go) A Crypto-Secure, Production-Grade Reliable-UDP Library for golang with FEC +- [**2389**Star][8d] [C] [wireshark/wireshark](https://github.com/wireshark/wireshark) Read-only mirror of Wireshark's Git repository. GitHub won't let us disable pull requests. ☞ THEY WILL BE IGNORED HERE ☜ Please upload them at +- [**2386**Star][2y] [Py] [secretsquirrel/the-backdoor-factory](https://github.com/secretsquirrel/the-backdoor-factory) Patch PE, ELF, Mach-O binaries with shellcode (NOT Supported) +- [**2384**Star][2d] [Go] [owasp/amass](https://github.com/owasp/amass) In-depth Attack Surface Mapping and Asset Discovery +- [**2381**Star][11m] [C] [haad/proxychains](https://github.com/haad/proxychains) a tool that forces any TCP connection made by any given application to follow through proxy like TOR or any other SOCKS4, SOCKS5 or HTTP(S) proxy. Supported auth-types: "user/pass" for SOCKS4/5, "basic" for HTTP. +- [**2376**Star][2d] [Java] [mock-server/mockserver](https://github.com/mock-server/mockserver) MockServer enables easy mocking of any system you integrate with via HTTP or HTTPS with clients written in Java, JavaScript and Ruby. MockServer also includes a proxy that introspects all proxied traffic including encrypted SSL traffic and supports Port Forwarding, Web Proxying (i.e. HTTP proxy), HTTPS Tunneling Proxying (using HTTP CONNECT) and… +- [**2376**Star][1y] [Py] [danmcinerney/lans.py](https://github.com/danmcinerney/lans.py) Inject code and spy on wifi users +- [**2369**Star][7d] [security-onion-solutions/security-onion](https://github.com/security-onion-solutions/security-onion) Linux distro for intrusion detection, enterprise security monitoring, and log management - [**2369**Star][2m] [TeX] [crypto101/book](https://github.com/crypto101/book) Crypto 101, the introductory book on cryptography. -- [**2368**Star][7d] [C] [wireshark/wireshark](https://github.com/wireshark/wireshark) Read-only mirror of Wireshark's Git repository. GitHub won't let us disable pull requests. ☞ THEY WILL BE IGNORED HERE ☜ Please upload them at -- [**2366**Star][7d] [Java] [mock-server/mockserver](https://github.com/mock-server/mockserver) MockServer enables easy mocking of any system you integrate with via HTTP or HTTPS with clients written in Java, JavaScript and Ruby. MockServer also includes a proxy that introspects all proxied traffic including encrypted SSL traffic and supports Port Forwarding, Web Proxying (i.e. HTTP proxy), HTTPS Tunneling Proxying (using HTTP CONNECT) and… -- [**2366**Star][11m] [C] [haad/proxychains](https://github.com/haad/proxychains) a tool that forces any TCP connection made by any given application to follow through proxy like TOR or any other SOCKS4, SOCKS5 or HTTP(S) proxy. Supported auth-types: "user/pass" for SOCKS4/5, "basic" for HTTP. -- [**2359**Star][1m] [Lua] [snabbco/snabb](https://github.com/snabbco/snabb) Simple and fast packet networking -- [**2359**Star][13d] [security-onion-solutions/security-onion](https://github.com/security-onion-solutions/security-onion) Linux distro for intrusion detection, enterprise security monitoring, and log management -- [**2359**Star][4m] [Go] [mlabouardy/komiser](https://github.com/mlabouardy/komiser) -- [**2351**Star][8d] [C] [domoticz/domoticz](https://github.com/domoticz/domoticz) monitor and configure various devices like: Lights, Switches, various sensors/meters like Temperature, Rain, Wind, UV, Electra, Gas, Water and much more -- [**2350**Star][1m] [Py] [ab77/netflix-proxy](https://github.com/ab77/netflix-proxy) Smart DNS proxy to watch Netflix +- [**2366**Star][4m] [Go] [mlabouardy/komiser](https://github.com/mlabouardy/komiser) +- [**2364**Star][2m] [Py] [ab77/netflix-proxy](https://github.com/ab77/netflix-proxy) Smart DNS proxy to watch Netflix +- [**2362**Star][1m] [Lua] [snabbco/snabb](https://github.com/snabbco/snabb) Simple and fast packet networking +- [**2357**Star][2d] [C] [domoticz/domoticz](https://github.com/domoticz/domoticz) monitor and configure various devices like: Lights, Switches, various sensors/meters like Temperature, Rain, Wind, UV, Electra, Gas, Water and much more +- [**2352**Star][1m] [Py] [ctfd/ctfd](https://github.com/CTFd/CTFd) CTFs as you need them +- [**2349**Star][11m] [hack-with-github/free-security-ebooks](https://github.com/hack-with-github/free-security-ebooks) Free Security and Hacking eBooks - [**2342**Star][3m] [Go] [vuvuzela/vuvuzela](https://github.com/vuvuzela/vuvuzela) Private messaging system that hides metadata -- [**2342**Star][12d] [Go] [owasp/amass](https://github.com/owasp/amass) In-depth Attack Surface Mapping and Asset Discovery -- [**2338**Star][6y] [C] [stefanesser/dumpdecrypted](https://github.com/stefanesser/dumpdecrypted) Dumps decrypted mach-o files from encrypted iPhone applications from memory to disk. This tool is necessary for security researchers to be able to look under the hood of encryption. -- [**2335**Star][11m] [hack-with-github/free-security-ebooks](https://github.com/hack-with-github/free-security-ebooks) Free Security and Hacking eBooks -- [**2332**Star][1m] [Py] [ctfd/ctfd](https://github.com/CTFd/CTFd) CTFs as you need them -- [**2330**Star][1m] [JS] [pa11y/pa11y](https://github.com/pa11y/pa11y) Pa11y is your automated accessibility testing pal -- [**2324**Star][30d] [C] [hfiref0x/uacme](https://github.com/hfiref0x/uacme) Defeating Windows User Account Control -- [**2317**Star][10d] [C] [tsl0922/ttyd](https://github.com/tsl0922/ttyd) Share your terminal over the web -- [**2316**Star][5y] [C] [abrasive/shairport](https://github.com/abrasive/shairport) Airtunes emulator! Shairport is no longer maintained. -- [**2302**Star][11m] [yeyintminthuhtut/awesome-red-teaming](https://github.com/yeyintminthuhtut/awesome-red-teaming) List of Awesome Red Teaming Resources -- [**2302**Star][1y] [Java] [csploit/android](https://github.com/csploit/android) cSploit - The most complete and advanced IT security professional toolkit on Android. -- [**2291**Star][3y] [Py] [lmacken/pyrasite](https://github.com/lmacken/pyrasite) Inject code into running Python processes -- [**2277**Star][3m] [JS] [retirejs/retire.js](https://github.com/retirejs/retire.js) scanner detecting the use of JavaScript libraries with known vulnerabilities -- [**2272**Star][3y] [Py] [therook/subbrute](https://github.com/therook/subbrute) A DNS meta-query spider that enumerates DNS records, and subdomains. -- [**2272**Star][1m] [C] [moby/hyperkit](https://github.com/moby/hyperkit) A toolkit for embedding hypervisor capabilities in your application -- [**2271**Star][22d] [JS] [talkingdata/inmap](https://github.com/talkingdata/inmap) 大数据地理可视化 -- [**2271**Star][2y] [Py] [rootphantomer/blasting_dictionary](https://github.com/rootphantomer/blasting_dictionary) 爆破字典 -- [**2267**Star][1m] [C] [aurorawright/luma3ds](https://github.com/aurorawright/luma3ds) Noob-proof (N)3DS "Custom Firmware" -- [**2246**Star][16d] [dumb-password-rules/dumb-password-rules](https://github.com/dumb-password-rules/dumb-password-rules) Shaming sites with dumb password rules. -- [**2244**Star][2y] [Go] [mehrdadrad/mylg](https://github.com/mehrdadrad/mylg) Network Diagnostic Tool -- [**2242**Star][1m] [Shell] [v1s1t0r1sh3r3/airgeddon](https://github.com/v1s1t0r1sh3r3/airgeddon) This is a multi-use bash script for Linux systems to audit wireless networks. -- [**2241**Star][13d] [HTML] [tikam02/devops-guide](https://github.com/tikam02/devops-guide) DevOps Guide from basic to advanced with Interview Questions and Notes -- [**2241**Star][3m] [Py] [novnc/websockify](https://github.com/novnc/websockify) Websockify is a WebSocket to TCP proxy/bridge. This allows a browser to connect to any application/server/service. Implementations in Python, C, Node.js and Ruby. -- [**2235**Star][1m] [Shell] [eliaskotlyar/xiaomi-dafang-hacks](https://github.com/eliaskotlyar/xiaomi-dafang-hacks) +- [**2340**Star][6y] [C] [stefanesser/dumpdecrypted](https://github.com/stefanesser/dumpdecrypted) Dumps decrypted mach-o files from encrypted iPhone applications from memory to disk. This tool is necessary for security researchers to be able to look under the hood of encryption. +- [**2340**Star][1m] [C] [hfiref0x/uacme](https://github.com/hfiref0x/uacme) Defeating Windows User Account Control +- [**2337**Star][1m] [JS] [pa11y/pa11y](https://github.com/pa11y/pa11y) Pa11y is your automated accessibility testing pal +- [**2335**Star][3d] [C] [tsl0922/ttyd](https://github.com/tsl0922/ttyd) Share your terminal over the web +- [**2323**Star][3d] [C#] [netchx/netch](https://github.com/netchx/netch) Game accelerator. Support Socks5, Shadowsocks, ShadowsocksR, V2Ray protocol. UDP NAT FullCone +- [**2321**Star][11m] [yeyintminthuhtut/awesome-red-teaming](https://github.com/yeyintminthuhtut/awesome-red-teaming) List of Awesome Red Teaming Resources +- [**2318**Star][5y] [C] [abrasive/shairport](https://github.com/abrasive/shairport) Airtunes emulator! Shairport is no longer maintained. +- [**2304**Star][1y] [Java] [csploit/android](https://github.com/csploit/android) cSploit - The most complete and advanced IT security professional toolkit on Android. +- [**2301**Star][15d] [HTML] [tikam02/devops-guide](https://github.com/tikam02/devops-guide) DevOps Guide from basic to advanced with Interview Questions and Notes +- [**2295**Star][3y] [Py] [lmacken/pyrasite](https://github.com/lmacken/pyrasite) Inject code into running Python processes +- [**2287**Star][2y] [Py] [rootphantomer/blasting_dictionary](https://github.com/rootphantomer/blasting_dictionary) 爆破字典 +- [**2284**Star][1m] [C] [moby/hyperkit](https://github.com/moby/hyperkit) A toolkit for embedding hypervisor capabilities in your application +- [**2283**Star][5m] [Py] [guohongze/adminset](https://github.com/guohongze/adminset) 自动化运维平台:CMDB、CD、DevOps、资产管理、任务编排、持续交付、系统监控、运维管理、配置管理 +- [**2282**Star][3y] [Py] [therook/subbrute](https://github.com/therook/subbrute) A DNS meta-query spider that enumerates DNS records, and subdomains. +- [**2281**Star][3m] [JS] [retirejs/retire.js](https://github.com/retirejs/retire.js) scanner detecting the use of JavaScript libraries with known vulnerabilities +- [**2276**Star][24d] [JS] [talkingdata/inmap](https://github.com/talkingdata/inmap) 大数据地理可视化 +- [**2274**Star][1m] [Shell] [v1s1t0r1sh3r3/airgeddon](https://github.com/v1s1t0r1sh3r3/airgeddon) This is a multi-use bash script for Linux systems to audit wireless networks. +- [**2270**Star][1m] [C] [aurorawright/luma3ds](https://github.com/aurorawright/luma3ds) Noob-proof (N)3DS "Custom Firmware" +- [**2255**Star][3m] [Py] [novnc/websockify](https://github.com/novnc/websockify) Websockify is a WebSocket to TCP proxy/bridge. This allows a browser to connect to any application/server/service. Implementations in Python, C, Node.js and Ruby. +- [**2252**Star][18d] [dumb-password-rules/dumb-password-rules](https://github.com/dumb-password-rules/dumb-password-rules) Shaming sites with dumb password rules. +- [**2252**Star][1m] [Shell] [eliaskotlyar/xiaomi-dafang-hacks](https://github.com/eliaskotlyar/xiaomi-dafang-hacks) +- [**2248**Star][12d] [PS] [k8gege/k8tools](https://github.com/k8gege/k8tools) K8工具合集(内网渗透/提权工具/远程溢出/漏洞利用/扫描工具/密码破解/免杀工具/Exploit/APT/0day/Shellcode/Payload/priviledge/BypassUAC/OverFlow/WebShell/PenTest) Web GetShell Exploit(Struts2/Zimbra/Weblogic/Tomcat/Apache/Jboss/DotNetNuke/zabbix) +- [**2245**Star][2y] [Go] [mehrdadrad/mylg](https://github.com/mehrdadrad/mylg) Network Diagnostic Tool - [**2226**Star][5y] [Go] [filosottile/heartbleed](https://github.com/filosottile/heartbleed) A checker (site and tool) for CVE-2014-0160 -- [**2222**Star][8d] [C#] [netchx/netch](https://github.com/netchx/netch) Game accelerator. Support Socks5, Shadowsocks, ShadowsocksR, V2Ray protocol. UDP NAT FullCone -- [**2218**Star][7d] [Py] [cloudflare/flan](https://github.com/cloudflare/flan) A pretty sweet vulnerability scanner +- [**2217**Star][1y] [JS] [cure53/h5sc](https://github.com/cure53/h5sc) HTML5 Security Cheatsheet - A collection of HTML5 related XSS attack vectors - [**2215**Star][6y] [C++] [codebutler/firesheep](https://github.com/codebutler/firesheep) A Firefox extension that demonstrates HTTP session hijacking attacks. -- [**2211**Star][1y] [JS] [cure53/h5sc](https://github.com/cure53/h5sc) HTML5 Security Cheatsheet - A collection of HTML5 related XSS attack vectors -- [**2204**Star][10d] [PowerShell] [k8gege/k8tools](https://github.com/k8gege/k8tools) K8工具合集(内网渗透/提权工具/远程溢出/漏洞利用/扫描工具/密码破解/免杀工具/Exploit/APT/0day/Shellcode/Payload/priviledge/BypassUAC/OverFlow/WebShell/PenTest) Web GetShell Exploit(Struts2/Zimbra/Weblogic/Tomcat/Apache/Jboss/DotNetNuke/zabbix) -- [**2203**Star][1m] [C] [texane/stlink](https://github.com/texane/stlink) stm32 discovery line linux programmer -- [**2201**Star][11d] [Go] [google/mtail](https://github.com/google/mtail) extract whitebox monitoring data from application logs for collection in a timeseries database -- [**2187**Star][21d] [C++] [google/bloaty](https://github.com/google/bloaty) Bloaty McBloatface: a size profiler for binaries +- [**2213**Star][2d] [Go] [aquasecurity/kube-bench](https://github.com/aquasecurity/kube-bench) Checks whether Kubernetes is deployed according to security best practices as defined in the CIS Kubernetes Benchmark +- [**2211**Star][1m] [C] [texane/stlink](https://github.com/texane/stlink) stm32 discovery line linux programmer +- [**2211**Star][6d] [Go] [google/mtail](https://github.com/google/mtail) extract whitebox monitoring data from application logs for collection in a timeseries database +- [**2209**Star][22d] [Rust] [cloudflare/boringtun](https://github.com/cloudflare/boringtun) an implementation of the WireGuard® protocol designed for portability and speed. +- [**2192**Star][23d] [C++] [google/bloaty](https://github.com/google/bloaty) Bloaty McBloatface: a size profiler for binaries +- [**2189**Star][1m] [sobolevn/awesome-cryptography](https://github.com/sobolevn/awesome-cryptography) A curated list of cryptography resources and links. +- [**2187**Star][7d] [getlantern/lantern-binaries](https://github.com/getlantern/lantern-binaries) Lantern installers binary downloads. +- [**2186**Star][1y] [Py] [datasploit/datasploit](https://github.com/DataSploit/datasploit) 对指定目标执行多种侦查技术:企业、人、电话号码、比特币地址等 - [**2184**Star][3y] [enddo/awesome-windows-exploitation](https://github.com/enddo/awesome-windows-exploitation) A curated list of awesome Windows Exploitation resources, and shiny things. Inspired by awesom -- [**2182**Star][1y] [Py] [datasploit/datasploit](https://github.com/DataSploit/datasploit) 对指定目标执行多种侦查技术:企业、人、电话号码、比特币地址等 -- [**2177**Star][1m] [JS] [secgroundzero/warberry](https://github.com/secgroundzero/warberry) WarBerryPi - Tactical Exploitation -- [**2171**Star][14d] [C] [armmbed/mbedtls](https://github.com/armmbed/mbedtls) An open source, portable, easy to use, readable and flexible SSL library -- [**2168**Star][16d] [getlantern/lantern-binaries](https://github.com/getlantern/lantern-binaries) Lantern installers binary downloads. -- [**2167**Star][29d] [sobolevn/awesome-cryptography](https://github.com/sobolevn/awesome-cryptography) A curated list of cryptography resources and links. -- [**2158**Star][2m] [Go] [mmatczuk/go-http-tunnel](https://github.com/mmatczuk/go-http-tunnel) Fast and secure tunnels over HTTP/2 -- [**2156**Star][1m] [C] [conorpp/u2f-zero](https://github.com/conorpp/u2f-zero) U2F USB token optimized for physical security, affordability, and style -- [**2155**Star][1y] [C++] [maestron/botnets](https://github.com/maestron/botnets) This is a collection of #botnet source codes, unorganized. For EDUCATIONAL PURPOSES ONLY +- [**2183**Star][2d] [C] [armmbed/mbedtls](https://github.com/armmbed/mbedtls) An open source, portable, easy to use, readable and flexible SSL library +- [**2179**Star][1m] [JS] [secgroundzero/warberry](https://github.com/secgroundzero/warberry) WarBerryPi - Tactical Exploitation +- [**2173**Star][1y] [JS] [iam4x/pokemongo-webspoof](https://github.com/iam4x/pokemongo-webspoof) +- [**2163**Star][2m] [Go] [mmatczuk/go-http-tunnel](https://github.com/mmatczuk/go-http-tunnel) Fast and secure tunnels over HTTP/2 +- [**2162**Star][1y] [C++] [maestron/botnets](https://github.com/maestron/botnets) This is a collection of #botnet source codes, unorganized. For EDUCATIONAL PURPOSES ONLY +- [**2159**Star][1m] [Py] [commixproject/commix](https://github.com/commixproject/commix) Automated All-in-One OS command injection and exploitation tool. +- [**2158**Star][9m] [exakat/php-static-analysis-tools](https://github.com/exakat/php-static-analysis-tools) A reviewed list of useful PHP static analysis tools +- [**2158**Star][1m] [C] [conorpp/u2f-zero](https://github.com/conorpp/u2f-zero) U2F USB token optimized for physical security, affordability, and style +- [**2158**Star][2m] [PHP] [antonioribeiro/tracker](https://github.com/antonioribeiro/tracker) Tracker gathers a lot of information from your requests to identify and store - [**2153**Star][6y] [Ruby] [plamoni/siriproxy](https://github.com/plamoni/siriproxy) A (tampering) proxy server for Apple's Siri -- [**2152**Star][29d] [Py] [commixproject/commix](https://github.com/commixproject/commix) Automated All-in-One OS command injection and exploitation tool. -- [**2151**Star][9m] [exakat/php-static-analysis-tools](https://github.com/exakat/php-static-analysis-tools) A reviewed list of useful PHP static analysis tools -- [**2146**Star][14d] [Java] [google/wycheproof](https://github.com/google/wycheproof) Project Wycheproof tests crypto libraries against known attacks. -- [**2127**Star][1m] [Py] [jonathansalwan/ropgadget](https://github.com/jonathansalwan/ropgadget) This tool lets you search your gadgets on your binaries to facilitate your ROP exploitation. ROPgadget supports ELF, PE and Mach-O format on x86, x64, ARM, ARM64, PowerPC, SPARC and MIPS architectures. -- [**2124**Star][2m] [Py] [trustedsec/unicorn](https://github.com/trustedsec/unicorn) Unicorn is a simple tool for using a PowerShell downgrade attack and inject shellcode straight into memory. Based on Matthew Graeber's powershell attacks and the powershell bypass technique presented by David Kennedy (TrustedSec) and Josh Kelly at Defcon 18. -- [**2123**Star][16d] [Assembly] [pret/pokered](https://github.com/pret/pokered) disassembly of Pokémon Red/Blue -- [**2114**Star][7m] [Py] [calebmadrigal/trackerjacker](https://github.com/calebmadrigal/trackerjacker) Like nmap for mapping wifi networks you're not connected to, plus device tracking -- [**2112**Star][1y] [Py] [rub-nds/pret](https://github.com/rub-nds/pret) Printer Exploitation Toolkit - The tool that made dumpster diving obsolete. +- [**2149**Star][8d] [Java] [google/wycheproof](https://github.com/google/wycheproof) Project Wycheproof tests crypto libraries against known attacks. +- [**2138**Star][2m] [Py] [trustedsec/unicorn](https://github.com/trustedsec/unicorn) Unicorn is a simple tool for using a PowerShell downgrade attack and inject shellcode straight into memory. Based on Matthew Graeber's powershell attacks and the powershell bypass technique presented by David Kennedy (TrustedSec) and Josh Kelly at Defcon 18. +- [**2132**Star][1m] [Py] [jonathansalwan/ropgadget](https://github.com/jonathansalwan/ropgadget) This tool lets you search your gadgets on your binaries to facilitate your ROP exploitation. ROPgadget supports ELF, PE and Mach-O format on x86, x64, ARM, ARM64, PowerPC, SPARC and MIPS architectures. +- [**2127**Star][18d] [Assembly] [pret/pokered](https://github.com/pret/pokered) disassembly of Pokémon Red/Blue +- [**2122**Star][2y] [Py] [rub-nds/pret](https://github.com/rub-nds/pret) Printer Exploitation Toolkit - The tool that made dumpster diving obsolete. +- [**2118**Star][4d] [goq/telegram-list](https://github.com/goq/telegram-list) List of telegram groups, channels & bots // Список интересных групп, каналов и ботов телеграма // Список чатов для программистов +- [**2117**Star][1m] [Py] [elceef/dnstwist](https://github.com/elceef/dnstwist) Domain name permutation engine for detecting typo squatting, phishing and corporate espionage +- [**2116**Star][7m] [Py] [calebmadrigal/trackerjacker](https://github.com/calebmadrigal/trackerjacker) Like nmap for mapping wifi networks you're not connected to, plus device tracking +- [**2115**Star][2d] [Py] [fortynorthsecurity/eyewitness](https://github.com/FortyNorthSecurity/EyeWitness) EyeWitness is designed to take screenshots of websites, provide some server header info, and identify default credentials if possible. +- [**2114**Star][7y] [C++] [lloyd/node-memwatch](https://github.com/lloyd/node-memwatch) A NodeJS library to keep an eye on your memory usage, and discover and isolate leaks. - [**2107**Star][4y] [C] [hashcat/hashcat-legacy](https://github.com/hashcat/hashcat-legacy) Advanced CPU-based password recovery utility -- [**2105**Star][7d] [goq/telegram-list](https://github.com/goq/telegram-list) List of telegram groups, channels & bots // Список интересных групп, каналов и ботов телеграма // Список чатов для программистов -- [**2105**Star][1m] [Py] [elceef/dnstwist](https://github.com/elceef/dnstwist) Domain name permutation engine for detecting typo squatting, phishing and corporate espionage -- [**2103**Star][8m] [Py] [linkedin/qark](https://github.com/linkedin/qark) Tool to look for several security related Android application vulnerabilities -- [**2098**Star][19d] [Py] [fortynorthsecurity/eyewitness](https://github.com/FortyNorthSecurity/EyeWitness) EyeWitness is designed to take screenshots of websites, provide some server header info, and identify default credentials if possible. -- [**2098**Star][21d] [infoslack/awesome-web-hacking](https://github.com/infoslack/awesome-web-hacking) A list of web application security -- [**2090**Star][3m] [yeahhub/hacking-security-ebooks](https://github.com/yeahhub/hacking-security-ebooks) Top 100 Hacking & Security E-Books (Free Download) -- [**2081**Star][8d] [C] [flatpak/flatpak](https://github.com/flatpak/flatpak) Linux application sandboxing and distribution framework -- [**2071**Star][30d] [Go] [theupdateframework/notary](https://github.com/theupdateframework/notary) Notary is a project that allows anyone to have trust over arbitrary collections of data -- [**2069**Star][20d] [Ruby] [urbanadventurer/whatweb](https://github.com/urbanadventurer/whatweb) Next generation web scanner -- [**2062**Star][9m] [jermic/android-crack-tool](https://github.com/jermic/android-crack-tool) -- [**2051**Star][4m] [Py] [whaleshark-team/cobra](https://github.com/WhaleShark-Team/cobra) Source Code Security Audit (源代码安全审计) -- [**2049**Star][1y] [bluscreenofjeff/red-team-infrastructure-wiki](https://github.com/bluscreenofjeff/red-team-infrastructure-wiki) Wiki to collect Red Team infrastructure hardening resources -- [**2047**Star][6m] [Go] [maxmcd/webtty](https://github.com/maxmcd/webtty) Share a terminal session over WebRTC -- [**2041**Star][2y] [Py] [derv82/wifite](https://github.com/derv82/wifite) an automated wireless attack tool. -- [**2037**Star][10d] [Py] [nabla-c0d3/sslyze](https://github.com/nabla-c0d3/sslyze) Fast and powerful SSL/TLS server scanning library. -- [**2036**Star][2m] [C++] [lordnoteworthy/al-khaser](https://github.com/lordnoteworthy/al-khaser) Public malware techniques used in the wild: Virtual Machine, Emulation, Debuggers, Sandbox detection. -- [**2035**Star][2m] [tanprathan/mobileapp-pentest-cheatsheet](https://github.com/tanprathan/mobileapp-pentest-cheatsheet) The Mobile App Pentest cheat sheet was created to provide concise collection of high value information on specific mobile application penetration testing topics. -- [**2035**Star][8m] [Shell] [foospidy/payloads](https://github.com/foospidy/payloads) Git All the Payloads! A collection of web attack payloads. -- [**2032**Star][7d] [C++] [openthread/openthread](https://github.com/openthread/openthread) OpenThread released by Google is an open-source implementation of the Thread networking protocol -- [**2032**Star][1m] [edoverflow/bugbounty-cheatsheet](https://github.com/edoverflow/bugbounty-cheatsheet) A list of interesting payloads, tips and tricks for bug bounty hunters. -- [**2024**Star][5y] [CoffeeScript] [shadowsocks/shadowsocks-gui](https://github.com/shadowsocks/shadowsocks-gui) Shadowsocks GUI client -- [**2020**Star][20d] [Objective-C] [ios-control/ios-deploy](https://github.com/ios-control/ios-deploy) Install and debug iPhone apps from the command line, without using Xcode -- [**2017**Star][3m] [C++] [darthton/blackbone](https://github.com/darthton/blackbone) Windows memory hacking library -- [**2016**Star][3y] [Swift] [urinx/iosapphook](https://github.com/urinx/iosapphook) 专注于非越狱环境下iOS应用逆向研究,从dylib注入,应用重签名到App Hook -- [**2014**Star][8d] [Py] [sensepost/objection](https://github.com/sensepost/objection) runtimemobile exploration -- [**2012**Star][1y] [C] [xoreaxeaxeax/rosenbridge](https://github.com/xoreaxeaxeax/rosenbridge) Hardware backdoors in some x86 CPUs -- [**2006**Star][9m] [C] [dekunukem/nintendo_switch_reverse_engineering](https://github.com/dekunukem/nintendo_switch_reverse_engineering) A look at inner workings of Joycon and Nintendo Switch -- [**2004**Star][4y] [C] [probablycorey/wax](https://github.com/probablycorey/wax) Wax is now being maintained by alibaba -- [**1999**Star][8d] [Java] [jeremylong/dependencycheck](https://github.com/jeremylong/dependencycheck) OWASP dependency-check is a software composition analysis utility that detects publicly disclosed vulnerabilities in application dependencies. -- [**1998**Star][13d] [Shell] [wulabing/v2ray_ws-tls_bash_onekey](https://github.com/wulabing/v2ray_ws-tls_bash_onekey) V2Ray Nginx+vmess+ws+tls/ http2 over tls 一键安装脚本 -- [**1992**Star][25d] [Swift] [github/softu2f](https://github.com/github/softu2f) Software U2F authenticator for macOS -- [**1991**Star][29d] [qazbnm456/awesome-cve-poc](https://github.com/qazbnm456/awesome-cve-poc) A curated list of CVE PoCs. -- [**1990**Star][4m] [swiftonsecurity/sysmon-config](https://github.com/swiftonsecurity/sysmon-config) Sysmon configuration file template with default high-quality event tracing -- [**1988**Star][4y] [Go] [yahoo/gryffin](https://github.com/yahoo/gryffin) Gryffin is a large scale web security scanning platform. -- [**1987**Star][7m] [Py] [fsecurelabs/drozer](https://github.com/FSecureLABS/drozer) The Leading Security Assessment Framework for Android. -- [**1983**Star][2y] [dloss/python-pentest-tools](https://github.com/dloss/python-pentest-tools) Python tools for penetration testers -- [**1983**Star][2m] [C++] [asmjit/asmjit](https://github.com/asmjit/asmjit) Complete x86/x64 JIT and AOT Assembler for C++ -- [**1976**Star][3m] [infosecn1nja/ad-attack-defense](https://github.com/infosecn1nja/ad-attack-defense) Attack and defend active directory using modern post exploitation adversary tradecraft activity -- [**1967**Star][26d] [Java] [genymobile/gnirehtet](https://github.com/genymobile/gnirehtet) Gnirehtet provides reverse tethering for Android -- [**1965**Star][9m] [JS] [weichiachang/stacks-cli](https://github.com/weichiachang/stacks-cli) Check website stack from the terminal -- [**1963**Star][11d] [HTML] [gtfobins/gtfobins.github.io](https://github.com/gtfobins/gtfobins.github.io) Curated list of Unix binaries that can be exploited to bypass system security restrictions -- [**1963**Star][27d] [Java] [elderdrivers/edxposed](https://github.com/elderdrivers/edxposed) Elder driver Xposed Framework. -- [**1962**Star][1m] [Py] [momosecurity/aswan](https://github.com/momosecurity/aswan) 陌陌风控系统静态规则引擎,零基础简易便捷的配置多种复杂规则,实时高效管控用户异常行为。 -- [**1958**Star][26d] [C#] [mathewsachin/captura](https://github.com/mathewsachin/captura) Capture Screen, Audio, Cursor, Mouse Clicks and Keystrokes -- [**1957**Star][9d] [Go] [ullaakut/cameradar](https://github.com/Ullaakut/cameradar) Cameradar hacks its way into RTSP videosurveillance cameras -- [**1954**Star][1y] [BitBake] [1n3/intruderpayloads](https://github.com/1n3/intruderpayloads) A collection of Burpsuite Intruder payloads, BurpBounty payloads, fuzz lists, malicious file uploads and web pentesting methodologies and checklists. -- [**1946**Star][2y] [obfuscator-llvm/obfuscator](https://github.com/obfuscator-llvm/obfuscator) Obfuscator-LLVM -- [**1945**Star][7d] [Perl] [spiderlabs/owasp-modsecurity-crs](https://github.com/spiderlabs/owasp-modsecurity-crs) OWASP ModSecurity Core Rule Set (CRS) Project (Official Repository) -- [**1940**Star][3y] [C#] [lazocoder/windows-hacks](https://github.com/lazocoder/windows-hacks) Creative and unusual things that can be done with the Windows API. -- [**1939**Star][2m] [C] [microsoft/procdump-for-linux](https://github.com/microsoft/procdump-for-linux) A Linux version of the ProcDump Sysinternals tool -- [**1938**Star][27d] [Py] [nixawk/pentest-wiki](https://github.com/nixawk/pentest-wiki) PENTEST-WIKI is a free online security knowledge library for pentesters / researchers. If you have a good idea, please share it with others. -- [**1938**Star][14d] [Py] [cea-sec/miasm](https://github.com/cea-sec/miasm) Reverse engineering framework in Python -- [**1926**Star][17d] [Go] [mpolden/echoip](https://github.com/mpolden/echoip) IP address lookup service -- [**1913**Star][5m] [C] [darkk/redsocks](https://github.com/darkk/redsocks) transparent TCP-to-proxy redirector -- [**1912**Star][3m] [toolswatch/blackhat-arsenal-tools](https://github.com/toolswatch/blackhat-arsenal-tools) Official Black Hat Arsenal Security Tools Repository -- [**1911**Star][3y] [Py] [aoncyberlabs/windows-exploit-suggester](https://github.com/AonCyberLabs/Windows-Exploit-Suggester) This tool compares a targets patch levels against the Microsoft vulnerability database in order to detect potential missing patches on the target. It also notifies the user if there are public exploits and Metasploit modules available for the missing bulletins. -- [**1911**Star][8d] [C] [ntop/ndpi](https://github.com/ntop/ndpi) Open Source Deep Packet Inspection Software Toolkit -- [**1909**Star][3d] [Go] [projectdiscovery/subfinder](https://github.com/projectdiscovery/subfinder) Subfinder is a subdomain discovery tool that discovers valid subdomains for websites. Designed as a passive framework to be useful for bug bounties and safe for penetration testing. -- [**1909**Star][9d] [Py] [j3ssie/osmedeus](https://github.com/j3ssie/osmedeus) Fully automated offensive security framework for reconnaissance and vulnerability scanning -- [**1908**Star][7d] [C++] [powerdns/pdns](https://github.com/powerdns/pdns) PowerDNS -- [**1907**Star][16d] [Py] [lanjelot/patator](https://github.com/lanjelot/patator) Patator is a multi-purpose brute-forcer, with a modular design and a flexible usage. -- [**1906**Star][13d] [CSS] [cyb3rward0g/helk](https://github.com/cyb3rward0g/helk) The Hunting ELK -- [**1902**Star][7d] [Go] [solo-io/gloo](https://github.com/solo-io/gloo) An Envoy-Powered API Gateway -- [**1901**Star][3m] [Go] [minishift/minishift](https://github.com/minishift/minishift) Run OpenShift 3.x locally -- [**1892**Star][19d] [C] [chipsec/chipsec](https://github.com/chipsec/chipsec) Platform Security Assessment Framework -- [**1891**Star][7d] [Py] [mozilla/mozdef](https://github.com/mozilla/mozdef) Mozilla Enterprise Defense Platform -- [**1886**Star][8d] [Go] [chaitin/xray](https://github.com/chaitin/xray) xray 安全评估工具 | 使用之前务必先阅读文档 -- [**1880**Star][14d] [C++] [mhammond/pywin32](https://github.com/mhammond/pywin32) Python for Windows (pywin32) Extensions -- [**1878**Star][4m] [C] [shadowsocks/simple-obfs](https://github.com/shadowsocks/simple-obfs) A simple obfuscating tool (Deprecated) -- [**1876**Star][7d] [Shell] [toniblyx/prowler](https://github.com/toniblyx/prowler) AWS Security Best Practices Assessment, Auditing, Hardening and Forensics Readiness Tool. It follows guidelines of the CIS Amazon Web Services Foundations Benchmark and DOZENS of additional checks including GDPR and HIPAA (+100). Official CIS for AWS guide: -- [**1876**Star][5y] [C++] [tum-vision/lsd_slam](https://github.com/tum-vision/lsd_slam) LSD-SLAM -- [**1876**Star][4m] [Py] [python-security/pyt](https://github.com/python-security/pyt) A Static Analysis Tool for Detecting Security Vulnerabilities in Python Web Applications -- [**1876**Star][6m] [Java] [fuzion24/justtrustme](https://github.com/fuzion24/justtrustme) An xposed module that disables SSL certificate checking for the purposes of auditing an app with cert pinning -- [**1876**Star][1y] [Py] [aploium/zmirror](https://github.com/aploium/zmirror) The next-gen reverse proxy for full site mirroring -- [**1869**Star][13d] [YARA] [yara-rules/rules](https://github.com/yara-rules/rules) Repository of yara rules -- [**1868**Star][1y] [Py] [derv82/wifite2](https://github.com/derv82/wifite2) Rewrite of the popular wireless network auditor, "wifite" -- [**1867**Star][2m] [Py] [pycqa/bandit](https://github.com/pycqa/bandit) find common security issues in Python code. -- [**1864**Star][7d] [C] [merbanan/rtl_433](https://github.com/merbanan/rtl_433) Program to decode traffic from Devices that are broadcasting on 433.9 MHz like temperature sensors -- [**1863**Star][4y] [Objective-C] [xcodeghostsource/xcodeghost](https://github.com/xcodeghostsource/xcodeghost) "XcodeGhost" Source -- [**1861**Star][10m] [PHP] [bartblaze/php-backdoors](https://github.com/bartblaze/php-backdoors) A collection of PHP backdoors. For educational or testing purposes only. -- [**1861**Star][4m] [Java] [adoptopenjdk/jitwatch](https://github.com/adoptopenjdk/jitwatch) Log analyser / visualiser for Java HotSpot JIT compiler. Inspect inlining decisions, hot methods, bytecode, and assembly. View results in the JavaFX user interface. -- [**1858**Star][10d] [Py] [aquasecurity/kube-hunter](https://github.com/aquasecurity/kube-hunter) Hunt for security weaknesses in Kubernetes clusters -- [**1857**Star][21d] [C] [tinyproxy/tinyproxy](https://github.com/tinyproxy/tinyproxy) a light-weight HTTP/HTTPS proxy daemon for POSIX operating systems -- [**1857**Star][7d] [olivierlaflamme/cheatsheet-god](https://github.com/olivierlaflamme/cheatsheet-god) Penetration Testing Reference Bank - OSCP / PTP & PTX Cheatsheet -- [**1849**Star][11m] [C++] [googlecreativelab/open-nsynth-super](https://github.com/googlecreativelab/open-nsynth-super) Open NSynth Super is an experimental physical interface for the NSynth algorithm -- [**1848**Star][29d] [C] [github/glb-director](https://github.com/github/glb-director) GitHub Load Balancer Director and supporting tooling. -- [**1846**Star][8m] [Py] [netflix-skunkworks/stethoscope](https://github.com/Netflix-Skunkworks/stethoscope) Personalized, user-focused recommendations for employee information security. -- [**1845**Star][2m] [Py] [pwnlandia/mhn](https://github.com/pwnlandia/mhn) Modern Honey Network -- [**1844**Star][8d] [TypeScript] [snyk/snyk](https://github.com/snyk/snyk) CLI and build-time tool to find & fix known vulnerabilities in open-source dependencies -- [**1842**Star][1y] [Java] [jindrapetrik/jpexs-decompiler](https://github.com/jindrapetrik/jpexs-decompiler) JPEXS Free Flash Decompiler -- [**1841**Star][13d] [C++] [acidanthera/lilu](https://github.com/acidanthera/Lilu) Arbitrary kext and process patching on macOS +- [**2105**Star][8m] [Py] [linkedin/qark](https://github.com/linkedin/qark) Tool to look for several security related Android application vulnerabilities +- [**2103**Star][3m] [yeahhub/hacking-security-ebooks](https://github.com/yeahhub/hacking-security-ebooks) Top 100 Hacking & Security E-Books (Free Download) +- [**2103**Star][23d] [infoslack/awesome-web-hacking](https://github.com/infoslack/awesome-web-hacking) A list of web application security +- [**2095**Star][2d] [C] [wireguard/wireguard](https://github.com/wireguard/wireguard) fast, modern, secure kernel VPN tunnel +- [**2093**Star][22d] [Ruby] [urbanadventurer/whatweb](https://github.com/urbanadventurer/whatweb) Next generation web scanner +- [**2084**Star][5d] [C] [flatpak/flatpak](https://github.com/flatpak/flatpak) Linux application sandboxing and distribution framework +- [**2078**Star][1m] [Go] [theupdateframework/notary](https://github.com/theupdateframework/notary) Notary is a project that allows anyone to have trust over arbitrary collections of data +- [**2071**Star][15d] [Shell] [wulabing/v2ray_ws-tls_bash_onekey](https://github.com/wulabing/v2ray_ws-tls_bash_onekey) V2Ray Nginx+vmess+ws+tls/ http2 over tls 一键安装脚本 +- [**2066**Star][9m] [jermic/android-crack-tool](https://github.com/jermic/android-crack-tool) +- [**2058**Star][4m] [Py] [whaleshark-team/cobra](https://github.com/WhaleShark-Team/cobra) Source Code Security Audit (源代码安全审计) +- [**2057**Star][1y] [bluscreenofjeff/red-team-infrastructure-wiki](https://github.com/bluscreenofjeff/red-team-infrastructure-wiki) Wiki to collect Red Team infrastructure hardening resources +- [**2054**Star][7d] [swiftonsecurity/sysmon-config](https://github.com/swiftonsecurity/sysmon-config) Sysmon configuration file template with default high-quality event tracing +- [**2051**Star][2m] [tanprathan/mobileapp-pentest-cheatsheet](https://github.com/tanprathan/mobileapp-pentest-cheatsheet) The Mobile App Pentest cheat sheet was created to provide concise collection of high value information on specific mobile application penetration testing topics. +- [**2048**Star][6m] [Go] [maxmcd/webtty](https://github.com/maxmcd/webtty) Share a terminal session over WebRTC +- [**2047**Star][1m] [edoverflow/bugbounty-cheatsheet](https://github.com/edoverflow/bugbounty-cheatsheet) A list of interesting payloads, tips and tricks for bug bounty hunters. +- [**2045**Star][2m] [C++] [lordnoteworthy/al-khaser](https://github.com/lordnoteworthy/al-khaser) Public malware techniques used in the wild: Virtual Machine, Emulation, Debuggers, Sandbox detection. +- [**2045**Star][8m] [Shell] [foospidy/payloads](https://github.com/foospidy/payloads) Git All the Payloads! A collection of web attack payloads. +- [**2043**Star][12d] [Py] [nabla-c0d3/sslyze](https://github.com/nabla-c0d3/sslyze) Fast and powerful SSL/TLS server scanning library. +- [**2042**Star][2y] [Py] [derv82/wifite](https://github.com/derv82/wifite) an automated wireless attack tool. +- [**2039**Star][5d] [C++] [openthread/openthread](https://github.com/openthread/openthread) OpenThread released by Google is an open-source implementation of the Thread networking protocol +- [**2033**Star][2d] [ObjC] [ios-control/ios-deploy](https://github.com/ios-control/ios-deploy) Install and debug iPhone apps from the command line, without using Xcode +- [**2033**Star][2d] [Py] [sensepost/objection](https://github.com/sensepost/objection) runtimemobile exploration +- [**2029**Star][3d] [Go] [goodrain/rainbond](https://github.com/goodrain/rainbond) Enterprise application cloud operating system(企业应用云操作系统) +- [**2025**Star][5y] [CoffeeScript] [shadowsocks/shadowsocks-gui](https://github.com/shadowsocks/shadowsocks-gui) Shadowsocks GUI client +- [**2024**Star][2d] [C++] [darthton/blackbone](https://github.com/darthton/blackbone) Windows memory hacking library +- [**2017**Star][3y] [Swift] [urinx/iosapphook](https://github.com/urinx/iosapphook) 专注于非越狱环境下iOS应用逆向研究,从dylib注入,应用重签名到App Hook +- [**2016**Star][23d] [Java] [genymobile/gnirehtet](https://github.com/genymobile/gnirehtet) Gnirehtet provides reverse tethering for Android +- [**2016**Star][9m] [C] [dekunukem/nintendo_switch_reverse_engineering](https://github.com/dekunukem/nintendo_switch_reverse_engineering) A look at inner workings of Joycon and Nintendo Switch +- [**2014**Star][1y] [C] [xoreaxeaxeax/rosenbridge](https://github.com/xoreaxeaxeax/rosenbridge) Hardware backdoors in some x86 CPUs +- [**2014**Star][5d] [Java] [jeremylong/dependencycheck](https://github.com/jeremylong/dependencycheck) OWASP dependency-check is a software composition analysis utility that detects publicly disclosed vulnerabilities in application dependencies. +- [**2005**Star][4y] [C] [probablycorey/wax](https://github.com/probablycorey/wax) Wax is now being maintained by alibaba +- [**2003**Star][2m] [Go] [skynetservices/skydns](https://github.com/skynetservices/skydns) DNS service discovery for etcd +- [**2000**Star][1m] [qazbnm456/awesome-cve-poc](https://github.com/qazbnm456/awesome-cve-poc) A curated list of CVE PoCs. +- [**1996**Star][29d] [Java] [elderdrivers/edxposed](https://github.com/elderdrivers/edxposed) Elder driver Xposed Framework. +- [**1994**Star][7m] [Py] [fsecurelabs/drozer](https://github.com/FSecureLABS/drozer) The Leading Security Assessment Framework for Android. +- [**1994**Star][3m] [infosecn1nja/ad-attack-defense](https://github.com/infosecn1nja/ad-attack-defense) Attack and defend active directory using modern post exploitation adversary tradecraft activity +- [**1994**Star][27d] [Swift] [github/softu2f](https://github.com/github/softu2f) Software U2F authenticator for macOS +- [**1992**Star][5d] [C#] [mathewsachin/captura](https://github.com/mathewsachin/captura) Capture Screen, Audio, Cursor, Mouse Clicks and Keystrokes +- [**1990**Star][8d] [HTML] [gtfobins/gtfobins.github.io](https://github.com/gtfobins/gtfobins.github.io) Curated list of Unix binaries that can be exploited to bypass system security restrictions +- [**1989**Star][4y] [Go] [yahoo/gryffin](https://github.com/yahoo/gryffin) Gryffin is a large scale web security scanning platform. +- [**1989**Star][2m] [C++] [asmjit/asmjit](https://github.com/asmjit/asmjit) Complete x86/x64 JIT and AOT Assembler for C++ +- [**1987**Star][2y] [dloss/python-pentest-tools](https://github.com/dloss/python-pentest-tools) Python tools for penetration testers +- [**1977**Star][5d] [Go] [projectdiscovery/subfinder](https://github.com/projectdiscovery/subfinder) Subfinder is a subdomain discovery tool that discovers valid subdomains for websites. Designed as a passive framework to be useful for bug bounties and safe for penetration testing. +- [**1977**Star][5d] [Go] [projectdiscovery/subfinder](https://github.com/projectdiscovery/subfinder) 使用Passive Sources, Search Engines, Pastebins, Internet Archives等查找子域名 +- [**1972**Star][1m] [Py] [momosecurity/aswan](https://github.com/momosecurity/aswan) 陌陌风控系统静态规则引擎,零基础简易便捷的配置多种复杂规则,实时高效管控用户异常行为。 +- [**1971**Star][5d] [Py] [j3ssie/osmedeus](https://github.com/j3ssie/osmedeus) Fully automated offensive security framework for reconnaissance and vulnerability scanning +- [**1966**Star][11d] [Go] [ullaakut/cameradar](https://github.com/Ullaakut/cameradar) Cameradar hacks its way into RTSP videosurveillance cameras +- [**1966**Star][9m] [JS] [weichiachang/stacks-cli](https://github.com/weichiachang/stacks-cli) Check website stack from the terminal +- [**1966**Star][1y] [BitBake] [1n3/intruderpayloads](https://github.com/1n3/intruderpayloads) A collection of Burpsuite Intruder payloads, BurpBounty payloads, fuzz lists, malicious file uploads and web pentesting methodologies and checklists. +- [**1955**Star][7d] [Perl] [spiderlabs/owasp-modsecurity-crs](https://github.com/spiderlabs/owasp-modsecurity-crs) OWASP ModSecurity Core Rule Set (CRS) Project (Official Repository) +- [**1953**Star][2y] [obfuscator-llvm/obfuscator](https://github.com/obfuscator-llvm/obfuscator) Obfuscator-LLVM +- [**1952**Star][1y] [Go] [hyperhq/hyperd](https://github.com/hyperhq/hyperd) HyperContainer Daemon +- [**1951**Star][8d] [Py] [cea-sec/miasm](https://github.com/cea-sec/miasm) Reverse engineering framework in Python +- [**1947**Star][29d] [Py] [nixawk/pentest-wiki](https://github.com/nixawk/pentest-wiki) PENTEST-WIKI is a free online security knowledge library for pentesters / researchers. If you have a good idea, please share it with others. +- [**1945**Star][5d] [C] [microsoft/procdump-for-linux](https://github.com/microsoft/procdump-for-linux) A Linux version of the ProcDump Sysinternals tool +- [**1942**Star][3y] [C#] [lazocoder/windows-hacks](https://github.com/lazocoder/windows-hacks) Creative and unusual things that can be done with the Windows API. +- [**1938**Star][4m] [C] [meituan-dianping/logan](https://github.com/meituan-dianping/logan) Logan is a lightweight case logging system based on mobile platform. +- [**1938**Star][7d] [Go] [zalando/skipper](https://github.com/zalando/skipper) An HTTP router and reverse proxy for service composition, including use cases like Kubernetes Ingress +- [**1935**Star][19d] [Go] [mpolden/echoip](https://github.com/mpolden/echoip) IP address lookup service +- [**1933**Star][5m] [C] [darkk/redsocks](https://github.com/darkk/redsocks) transparent TCP-to-proxy redirector +- [**1923**Star][3y] [Py] [aoncyberlabs/windows-exploit-suggester](https://github.com/AonCyberLabs/Windows-Exploit-Suggester) This tool compares a targets patch levels against the Microsoft vulnerability database in order to detect potential missing patches on the target. It also notifies the user if there are public exploits and Metasploit modules available for the missing bulletins. +- [**1920**Star][4y] [Py] [ziggear/shadowsocks](https://github.com/ziggear/shadowsocks) backup of +- [**1920**Star][2d] [C++] [powerdns/pdns](https://github.com/powerdns/pdns) PowerDNS +- [**1920**Star][9d] [CSS] [cyb3rward0g/helk](https://github.com/cyb3rward0g/helk) The Hunting ELK +- [**1918**Star][3m] [toolswatch/blackhat-arsenal-tools](https://github.com/toolswatch/blackhat-arsenal-tools) Official Black Hat Arsenal Security Tools Repository +- [**1917**Star][2d] [C] [ntop/ndpi](https://github.com/ntop/ndpi) Open Source Deep Packet Inspection Software Toolkit +- [**1915**Star][18d] [Py] [lanjelot/patator](https://github.com/lanjelot/patator) Patator is a multi-purpose brute-forcer, with a modular design and a flexible usage. +- [**1914**Star][7d] [Go] [solo-io/gloo](https://github.com/solo-io/gloo) An Envoy-Powered API Gateway +- [**1914**Star][2d] [chaitin/xray](https://github.com/chaitin/xray) xray 安全评估工具 | 使用之前务必先阅读文档 +- [**1903**Star][3m] [Go] [minishift/minishift](https://github.com/minishift/minishift) Run OpenShift 3.x locally +- [**1901**Star][9d] [C] [chipsec/chipsec](https://github.com/chipsec/chipsec) Platform Security Assessment Framework +- [**1900**Star][1y] [Py] [derv82/wifite2](https://github.com/derv82/wifite2) Rewrite of the popular wireless network auditor, "wifite" +- [**1898**Star][3d] [C++] [mhammond/pywin32](https://github.com/mhammond/pywin32) Python for Windows (pywin32) Extensions +- [**1896**Star][7d] [Shell] [toniblyx/prowler](https://github.com/toniblyx/prowler) AWS Security Best Practices Assessment, Auditing, Hardening and Forensics Readiness Tool. It follows guidelines of the CIS Amazon Web Services Foundations Benchmark and DOZENS of additional checks including GDPR and HIPAA (+100). Official CIS for AWS guide: +- [**1893**Star][6d] [Py] [mozilla/mozdef](https://github.com/mozilla/mozdef) Mozilla Enterprise Defense Platform +- [**1893**Star][6m] [Java] [fuzion24/justtrustme](https://github.com/fuzion24/justtrustme) An xposed module that disables SSL certificate checking for the purposes of auditing an app with cert pinning +- [**1886**Star][4m] [C] [shadowsocks/simple-obfs](https://github.com/shadowsocks/simple-obfs) A simple obfuscating tool (Deprecated) +- [**1884**Star][1y] [Py] [aploium/zmirror](https://github.com/aploium/zmirror) The next-gen reverse proxy for full site mirroring +- [**1880**Star][4m] [Py] [python-security/pyt](https://github.com/python-security/pyt) A Static Analysis Tool for Detecting Security Vulnerabilities in Python Web Applications +- [**1878**Star][16d] [YARA] [yara-rules/rules](https://github.com/yara-rules/rules) Repository of yara rules +- [**1878**Star][5y] [C++] [tum-vision/lsd_slam](https://github.com/tum-vision/lsd_slam) LSD-SLAM +- [**1878**Star][2m] [Py] [pycqa/bandit](https://github.com/pycqa/bandit) find common security issues in Python code. +- [**1877**Star][2d] [C] [merbanan/rtl_433](https://github.com/merbanan/rtl_433) Program to decode traffic from Devices that are broadcasting on 433.9 MHz like temperature sensors +- [**1876**Star][9d] [olivierlaflamme/cheatsheet-god](https://github.com/olivierlaflamme/cheatsheet-god) Penetration Testing Reference Bank - OSCP / PTP & PTX Cheatsheet +- [**1876**Star][27d] [hmaverickadams/beginner-network-pentesting](https://github.com/hmaverickadams/beginner-network-pentesting) Notes for Beginner Network Pentesting Course +- [**1873**Star][12d] [Py] [aquasecurity/kube-hunter](https://github.com/aquasecurity/kube-hunter) Hunt for security weaknesses in Kubernetes clusters +- [**1870**Star][5d] [C#] [hmbsbige/shadowsocksr-windows](https://github.com/hmbsbige/shadowsocksr-windows) 【自用】Bug-Oriented Programming +- [**1869**Star][6d] [Java] [adoptopenjdk/jitwatch](https://github.com/adoptopenjdk/jitwatch) Log analyser / visualiser for Java HotSpot JIT compiler. Inspect inlining decisions, hot methods, bytecode, and assembly. View results in the JavaFX user interface. +- [**1865**Star][6d] [C++] [acidanthera/lilu](https://github.com/acidanthera/Lilu) Arbitrary kext and process patching on macOS +- [**1865**Star][10m] [PHP] [bartblaze/php-backdoors](https://github.com/bartblaze/php-backdoors) A collection of PHP backdoors. For educational or testing purposes only. +- [**1864**Star][23d] [C] [tinyproxy/tinyproxy](https://github.com/tinyproxy/tinyproxy) a light-weight HTTP/HTTPS proxy daemon for POSIX operating systems +- [**1862**Star][4y] [ObjC] [xcodeghostsource/xcodeghost](https://github.com/xcodeghostsource/xcodeghost) "XcodeGhost" Source +- [**1860**Star][9d] [Lua] [vulnerscom/nmap-vulners](https://github.com/vulnerscom/nmap-vulners) NSE script based on Vulners.com API +- [**1857**Star][5m] [bypass007/emergency-response-notes](https://github.com/bypass007/emergency-response-notes) 应急响应实战笔记,一个安全工程师的自我修养。 +- [**1855**Star][2m] [Py] [pwnlandia/mhn](https://github.com/pwnlandia/mhn) Modern Honey Network +- [**1854**Star][5d] [TS] [snyk/snyk](https://github.com/snyk/snyk) CLI and build-time tool to find & fix known vulnerabilities in open-source dependencies +- [**1854**Star][11m] [C++] [googlecreativelab/open-nsynth-super](https://github.com/googlecreativelab/open-nsynth-super) Open NSynth Super is an experimental physical interface for the NSynth algorithm +- [**1853**Star][2d] [Py] [bregman-arie/devops-interview-questions](https://github.com/bregman-arie/devops-interview-questions) Linux, Jenkins, AWS, SRE, Prometheus, Docker, Python, Ansible, Git, Kubernetes, Terraform, OpenStack, SQL, NoSQL, Azure, GCP, DNS, Elastic +- [**1853**Star][4m] [Shell] [arismelachroinos/lscript](https://github.com/arismelachroinos/lscript) The LAZY script will make your life easier, and of course faster. +- [**1852**Star][3d] [C] [github/glb-director](https://github.com/github/glb-director) GitHub Load Balancer Director and supporting tooling. +- [**1851**Star][1y] [Java] [jindrapetrik/jpexs-decompiler](https://github.com/jindrapetrik/jpexs-decompiler) JPEXS Free Flash Decompiler +- [**1848**Star][6m] [Assembly] [pooler/cpuminer](https://github.com/pooler/cpuminer) cpuminer:莱特币和比特币的多线程 CPU 矿机 +- [**1847**Star][8m] [Py] [netflix-skunkworks/stethoscope](https://github.com/Netflix-Skunkworks/stethoscope) Personalized, user-focused recommendations for employee information security. +- [**1842**Star][1m] [Jupyter Notebook] [hunters-forge/threathunter-playbook](https://github.com/hunters-forge/ThreatHunter-Playbook) A Threat hunter's playbook to aid the development of techniques and hypothesis for hunting campaigns. +- [**1842**Star][1y] [Java] [yeriomin/yalpstore](https://github.com/yeriomin/yalpstore) Download apks from Google Play Store +- [**1842**Star][2d] [C++] [pytorch/glow](https://github.com/pytorch/glow) Compiler for Neural Network hardware accelerators - [**1841**Star][2m] [C] [retroplasma/earth-reverse-engineering](https://github.com/retroplasma/earth-reverse-engineering) Reversing Google's 3D satellite mode -- [**1839**Star][4m] [bypass007/emergency-response-notes](https://github.com/bypass007/emergency-response-notes) 应急响应实战笔记,一个安全工程师的自我修养。 -- [**1837**Star][4m] [Lua] [vulnerscom/nmap-vulners](https://github.com/vulnerscom/nmap-vulners) NSE script based on Vulners.com API -- [**1836**Star][3y] [Java] [chora10/cknife](https://github.com/chora10/cknife) Cknife -- [**1835**Star][1y] [Java] [yeriomin/yalpstore](https://github.com/yeriomin/yalpstore) Download apks from Google Play Store -- [**1833**Star][25d] [hmaverickadams/beginner-network-pentesting](https://github.com/hmaverickadams/beginner-network-pentesting) Notes for Beginner Network Pentesting Course -- [**1832**Star][4m] [Shell] [arismelachroinos/lscript](https://github.com/arismelachroinos/lscript) The LAZY script will make your life easier, and of course faster. -- [**1830**Star][7d] [C++] [pytorch/glow](https://github.com/pytorch/glow) Compiler for Neural Network hardware accelerators -- [**1829**Star][1y] [Py] [jinnlynn/genpac](https://github.com/jinnlynn/genpac) PAC/Dnsmasq/Wingy file Generator, working with gfwlist, support custom rules. -- [**1827**Star][1m] [Jupyter Notebook] [hunters-forge/threathunter-playbook](https://github.com/hunters-forge/ThreatHunter-Playbook) A Threat hunter's playbook to aid the development of techniques and hypothesis for hunting campaigns. -- [**1827**Star][2m] [Go] [influxdata/kapacitor](https://github.com/influxdata/kapacitor) Open source framework for processing, monitoring, and alerting on time series data -- [**1827**Star][1y] [CSS] [ctfs/write-ups-2015](https://github.com/ctfs/write-ups-2015) Wiki-like CTF write-ups repository, maintained by the community. 2015 -- [**1819**Star][13d] [Py] [trailofbits/manticore](https://github.com/trailofbits/manticore) Symbolic execution tool -- [**1816**Star][19d] [C] [mgba-emu/mgba](https://github.com/mgba-emu/mgba) mGBA Game Boy Advance Emulator -- [**1814**Star][7d] [Py] [bregman-arie/devops-interview-questions](https://github.com/bregman-arie/devops-interview-questions) Linux, Jenkins, AWS, SRE, Prometheus, Docker, Python, Ansible, Git, Kubernetes, Terraform, OpenStack, SQL, NoSQL, Azure, GCP, DNS, Elastic -- [**1808**Star][6m] [C++] [iagox86/dnscat2](https://github.com/iagox86/dnscat2) create an encrypted command-and-control (C&C) channel over the DNS protocol, which is an effective tunnel out of almost every network. -- [**1806**Star][5m] [Py] [veil-framework/veil](https://github.com/veil-framework/veil) generate metasploit payloads that bypass common anti-virus solutions -- [**1801**Star][3y] [Objective-C] [kpwn/yalu102](https://github.com/kpwn/yalu102) incomplete iOS 10.2 jailbreak for 64 bit devices by qwertyoruiopz and marcograssi -- [**1801**Star][2m] [djadmin/awesome-bug-bounty](https://github.com/djadmin/awesome-bug-bounty) A comprehensive curated list of available Bug Bounty & Disclosure Programs and Write-ups. -- [**1788**Star][28d] [Go] [gdamore/tcell](https://github.com/gdamore/tcell) Tcell is an alternate terminal package, similar in some ways to termbox, but better in others. -- [**1785**Star][11m] [Py] [ctfs/write-ups-2017](https://github.com/ctfs/write-ups-2017) Wiki-like CTF write-ups repository, maintained by the community. 2017 -- [**1784**Star][7d] [C#] [hmbsbige/shadowsocksr-windows](https://github.com/hmbsbige/shadowsocksr-windows) 【自用】Bug-Oriented Programming -- [**1783**Star][7m] [Py] [lijiejie/subdomainsbrute](https://github.com/lijiejie/subdomainsbrute) A fast sub domain brute tool for pentesters -- [**1777**Star][18d] [PHP] [ezyang/htmlpurifier](https://github.com/ezyang/htmlpurifier) Standards compliant HTML filter written in PHP -- [**1776**Star][13d] [C++] [apitrace/apitrace](https://github.com/apitrace/apitrace) Tools for tracing OpenGL, Direct3D, and other graphics APIs -- [**1775**Star][4y] [caesar0301/awesome-pcaptools](https://github.com/caesar0301/awesome-pcaptools) A collection of tools developed by other researchers in the Computer Science area to process network traces. All the right reserved for the original authors. -- [**1774**Star][1y] [aozhimin/ios-monitor-platform](https://github.com/aozhimin/ios-monitor-platform) -- [**1770**Star][3y] [Objective-C] [alibaba/wax](https://github.com/alibaba/wax) Wax is a framework that lets you write native iPhone apps in Lua. -- [**1768**Star][13d] [Shell] [leebaird/discover](https://github.com/leebaird/discover) Custom bash scripts used to automate various penetration testing tasks including recon, scanning, parsing, and creating malicious payloads and listeners with Metasploit. -- [**1764**Star][3m] [Py] [epinna/weevely3](https://github.com/epinna/weevely3) Weaponized web shell -- [**1759**Star][12d] [C] [google/wuffs](https://github.com/google/wuffs) Wrangling Untrusted File Formats Safely -- [**1757**Star][7m] [C++] [wrbug/dumpdex](https://github.com/wrbug/dumpdex) Android unpack -- [**1757**Star][2y] [CSS] [b374k/b374k](https://github.com/b374k/b374k) PHP Webshell with handy features -- [**1749**Star][2m] [onethawt/idaplugins-list](https://github.com/onethawt/idaplugins-list) A list of IDA Plugins -- [**1747**Star][8d] [17mon/china_ip_list](https://github.com/17mon/china_ip_list) -- [**1743**Star][12m] [JS] [puppeteer/examples](https://github.com/puppeteer/examples) Use case-driven examples for using Puppeteer and headless chrome -- [**1740**Star][8d] [PHP] [wordpress/wordpress-coding-standards](https://github.com/wordpress/wordpress-coding-standards) PHP_CodeSniffer rules (sniffs) to enforce WordPress coding conventions +- [**1839**Star][3y] [Java] [chora10/cknife](https://github.com/chora10/cknife) Cknife +- [**1838**Star][1y] [Py] [jinnlynn/genpac](https://github.com/jinnlynn/genpac) PAC/Dnsmasq/Wingy file Generator, working with gfwlist, support custom rules. +- [**1830**Star][2m] [Go] [influxdata/kapacitor](https://github.com/influxdata/kapacitor) Open source framework for processing, monitoring, and alerting on time series data +- [**1828**Star][3m] [JS] [coreybutler/node-windows](https://github.com/coreybutler/node-windows) Windows support for Node.JS scripts (daemons, eventlog, UAC, etc). +- [**1828**Star][1y] [CSS] [ctfs/write-ups-2015](https://github.com/ctfs/write-ups-2015) Wiki-like CTF write-ups repository, maintained by the community. 2015 +- [**1824**Star][5d] [Py] [trailofbits/manticore](https://github.com/trailofbits/manticore) Symbolic execution tool +- [**1819**Star][6d] [C] [mgba-emu/mgba](https://github.com/mgba-emu/mgba) mGBA Game Boy Advance Emulator +- [**1818**Star][2m] [djadmin/awesome-bug-bounty](https://github.com/djadmin/awesome-bug-bounty) A comprehensive curated list of available Bug Bounty & Disclosure Programs and Write-ups. +- [**1815**Star][5m] [Py] [veil-framework/veil](https://github.com/veil-framework/veil) generate metasploit payloads that bypass common anti-virus solutions +- [**1814**Star][6m] [C++] [iagox86/dnscat2](https://github.com/iagox86/dnscat2) create an encrypted command-and-control (C&C) channel over the DNS protocol, which is an effective tunnel out of almost every network. +- [**1804**Star][10d] [Go] [gdamore/tcell](https://github.com/gdamore/tcell) Tcell is an alternate terminal package, similar in some ways to termbox, but better in others. +- [**1801**Star][12m] [Go] [intelsdi-x/snap](https://github.com/intelsdi-x/snap) an open telemetry framework designed to simplify the collection, processing and publishing of system data through a single API. +- [**1800**Star][3y] [ObjC] [kpwn/yalu102](https://github.com/kpwn/yalu102) incomplete iOS 10.2 jailbreak for 64 bit devices by qwertyoruiopz and marcograssi +- [**1795**Star][7m] [Py] [lijiejie/subdomainsbrute](https://github.com/lijiejie/subdomainsbrute) A fast sub domain brute tool for pentesters +- [**1790**Star][12m] [Py] [ctfs/write-ups-2017](https://github.com/ctfs/write-ups-2017) Wiki-like CTF write-ups repository, maintained by the community. 2017 +- [**1785**Star][1y] [aozhimin/ios-monitor-platform](https://github.com/aozhimin/ios-monitor-platform) +- [**1784**Star][16d] [Shell] [pirate/wireguard-docs](https://github.com/pirate/wireguard-docs) +- [**1781**Star][15d] [Shell] [leebaird/discover](https://github.com/leebaird/discover) Custom bash scripts used to automate various penetration testing tasks including recon, scanning, parsing, and creating malicious payloads and listeners with Metasploit. +- [**1779**Star][4y] [caesar0301/awesome-pcaptools](https://github.com/caesar0301/awesome-pcaptools) A collection of tools developed by other researchers in the Computer Science area to process network traces. All the right reserved for the original authors. +- [**1778**Star][15d] [C++] [apitrace/apitrace](https://github.com/apitrace/apitrace) Tools for tracing OpenGL, Direct3D, and other graphics APIs +- [**1777**Star][7m] [C++] [wrbug/dumpdex](https://github.com/wrbug/dumpdex) Android unpack +- [**1777**Star][7d] [PHP] [ezyang/htmlpurifier](https://github.com/ezyang/htmlpurifier) Standards compliant HTML filter written in PHP +- [**1777**Star][5d] [Go] [convox/rack](https://github.com/convox/rack) Private PaaS built on native AWS services for maximum privacy and minimum upkeep +- [**1774**Star][3y] [ObjC] [tapwork/heapinspector-for-ios](https://github.com/tapwork/heapinspector-for-ios) Find memory issues & leaks in your iOS app without instruments +- [**1774**Star][3m] [Py] [epinna/weevely3](https://github.com/epinna/weevely3) Weaponized web shell +- [**1772**Star][2y] [JS] [cazala/coin-hive](https://github.com/cazala/coin-hive) CoinHive cryptocurrency miner for node.js +- [**1770**Star][3y] [ObjC] [alibaba/wax](https://github.com/alibaba/wax) Wax is a framework that lets you write native iPhone apps in Lua. +- [**1761**Star][6d] [C] [google/wuffs](https://github.com/google/wuffs) Wrangling Untrusted File Formats Safely +- [**1761**Star][2y] [CSS] [b374k/b374k](https://github.com/b374k/b374k) PHP Webshell with handy features +- [**1760**Star][3y] [Go] [elastic/logstash-forwarder](https://github.com/elastic/logstash-forwarder) An experiment to cut logs in preparation for processing elsewhere. Replaced by Filebeat: +- [**1758**Star][12m] [JS] [puppeteer/examples](https://github.com/puppeteer/examples) Use case-driven examples for using Puppeteer and headless chrome +- [**1756**Star][10d] [17mon/china_ip_list](https://github.com/17mon/china_ip_list) +- [**1754**Star][2m] [onethawt/idaplugins-list](https://github.com/onethawt/idaplugins-list) A list of IDA Plugins +- [**1747**Star][2d] [PHP] [wordpress/wordpress-coding-standards](https://github.com/wordpress/wordpress-coding-standards) PHP_CodeSniffer rules (sniffs) to enforce WordPress coding conventions +- [**1745**Star][1y] [PS] [fuzzysecurity/powershell-suite](https://github.com/fuzzysecurity/powershell-suite) My musings with PowerShell +- [**1744**Star][1y] [coreb1t/awesome-pentest-cheat-sheets](https://github.com/coreb1t/awesome-pentest-cheat-sheets) Collection of the cheat sheets useful for pentesting +- [**1742**Star][3m] [tunz/js-vuln-db](https://github.com/tunz/js-vuln-db) A collection of JavaScript engine CVEs with PoCs +- [**1739**Star][21d] [ngalongc/bug-bounty-reference](https://github.com/ngalongc/bug-bounty-reference) Inspired by - [**1738**Star][2y] [Go] [vzex/dog-tunnel](https://github.com/vzex/dog-tunnel) p2p tunnel,(udp mode work with kcp, -- [**1734**Star][3m] [tunz/js-vuln-db](https://github.com/tunz/js-vuln-db) A collection of JavaScript engine CVEs with PoCs -- [**1732**Star][1y] [coreb1t/awesome-pentest-cheat-sheets](https://github.com/coreb1t/awesome-pentest-cheat-sheets) Collection of the cheat sheets useful for pentesting -- [**1727**Star][2m] [PHP] [orangetw/my-ctf-web-challenges](https://github.com/orangetw/my-ctf-web-challenges) Collection of CTF Web challenges I made -- [**1726**Star][3y] [Go] [s-rah/onionscan](https://github.com/s-rah/onionscan) OnionScan is a free and open source tool for investigating the Dark Web. -- [**1723**Star][6m] [Smali] [ahmyth/ahmyth-android-rat](https://github.com/ahmyth/ahmyth-android-rat) Android Remote Administration Tool -- [**1722**Star][1y] [PowerShell] [fuzzysecurity/powershell-suite](https://github.com/fuzzysecurity/powershell-suite) My musings with PowerShell -- [**1720**Star][19d] [ngalongc/bug-bounty-reference](https://github.com/ngalongc/bug-bounty-reference) Inspired by -- [**1718**Star][1m] [PowerShell] [fireeye/flare-vm](https://github.com/fireeye/flare-vm) FireEye Labs Advanced Reverse Engineering -- [**1717**Star][7d] [C] [google/honggfuzz](https://github.com/google/honggfuzz) Security oriented fuzzer with powerful analysis options. Supports evolutionary, feedback-driven fuzzing based on code coverage (software- and hardware-based) -- [**1714**Star][2m] [Go] [subfinder/subfinder](https://github.com/subfinder/subfinder) 使用Passive Sources, Search Engines, Pastebins, Internet Archives等查找子域名 -- [**1709**Star][9m] [Py] [constverum/proxybroker](https://github.com/constverum/proxybroker) Proxy [Finder | Checker | Server]. HTTP(S) & SOCKS -- [**1708**Star][10d] [Ruby] [cliffe/secgen](https://github.com/cliffe/secgen) Create randomly insecure VMs -- [**1705**Star][4m] [Py] [lgandx/responder](https://github.com/lgandx/responder) Responder is a LLMNR, NBT-NS and MDNS poisoner, with built-in HTTP/SMB/MSSQL/FTP/LDAP rogue authentication server supporting NTLMv1/NTLMv2/LMv2, Extended Security NTLMSSP and Basic HTTP authentication. -- [**1702**Star][1y] [Java] [ac-pm/inspeckage](https://github.com/ac-pm/inspeckage) Android Package Inspector - dynamic analysis with api hooks, start unexported activities and more. (Xposed Module) -- [**1695**Star][1m] [Go] [eth0izzle/shhgit](https://github.com/eth0izzle/shhgit) Find GitHub secrets in real time -- [**1694**Star][3m] [PHP] [xtr4nge/fruitywifi](https://github.com/xtr4nge/fruitywifi) FruityWiFi is a wireless network auditing tool. The application can be installed in any Debian based system (Jessie) adding the extra packages. Tested in Debian, Kali Linux, Kali Linux ARM (Raspberry Pi), Raspbian (Raspberry Pi), Pwnpi (Raspberry Pi), Bugtraq, NetHunter. -- [**1694**Star][3y] [CoffeeScript] [okturtles/dnschain](https://github.com/okturtles/dnschain) A blockchain-based DNS + HTTP server that fixes HTTPS security, and more! -- [**1694**Star][1y] [Swift] [haxpor/potatso](https://github.com/haxpor/potatso) Potatso is an iOS client that implements Shadowsocks proxy with the leverage of NetworkExtension framework. ***This project is unmaintained, try taking a look at this fork -- [**1694**Star][14d] [Go] [hashicorp/memberlist](https://github.com/hashicorp/memberlist) Golang package for gossip based membership and failure detection -- [**1693**Star][8m] [Py] [guelfoweb/knock](https://github.com/guelfoweb/knock) Knock Subdomain Scan -- [**1693**Star][7d] [TSQL] [brentozarultd/sql-server-first-responder-kit](https://github.com/brentozarultd/sql-server-first-responder-kit) sp_Blitz, sp_BlitzCache, sp_BlitzFirst, sp_BlitzIndex, and other SQL Server scripts for health checks and performance tuning. -- [**1693**Star][3m] [Py] [anorov/cloudflare-scrape](https://github.com/anorov/cloudflare-scrape) A Python module to bypass Cloudflare's anti-bot page. -- [**1691**Star][6m] [Py] [yelp/osxcollector](https://github.com/yelp/osxcollector) A forensic evidence collection & analysis toolkit for OS X -- [**1687**Star][4m] [JS] [expressjs/csurf](https://github.com/expressjs/csurf) CSRF token middleware -- [**1685**Star][5m] [C] [networkprotocol/netcode.io](https://github.com/networkprotocol/netcode.io) A protocol for secure client/server connections over UDP -- [**1682**Star][8m] [Makefile] [raspberrypi/noobs](https://github.com/raspberrypi/noobs) NOOBS (New Out Of Box Software) - An easy Operating System install manager for the Raspberry Pi -- [**1682**Star][1y] [owasp/devguide](https://github.com/owasp/devguide) The OWASP Guide -- [**1681**Star][13d] [HTML] [chromium/badssl.com](https://github.com/chromium/badssl.com) -- [**1681**Star][9m] [CSS] [bagder/http2-explained](https://github.com/bagder/http2-explained) A detailed document explaining and documenting HTTP/2, the successor to the widely popular HTTP/1.1 protocol -- [**1676**Star][28d] [Swift] [pmusolino/wormholy](https://github.com/pmusolino/wormholy) iOS network debugging, like a wizard 🧙‍♂️ -- [**1675**Star][4m] [R] [briatte/awesome-network-analysis](https://github.com/briatte/awesome-network-analysis) A curated list of awesome network analysis resources. -- [**1674**Star][2m] [Py] [rootm0s/winpwnage](https://github.com/rootm0s/winpwnage) UAC bypass, Elevate, Persistence and Execution methods -- [**1668**Star][7m] [C++] [yegord/snowman](https://github.com/yegord/snowman) a native code to C/C++ decompiler, supporting x86, AMD64, and ARM architectures +- [**1735**Star][2m] [PHP] [orangetw/my-ctf-web-challenges](https://github.com/orangetw/my-ctf-web-challenges) Collection of CTF Web challenges I made +- [**1731**Star][1m] [PS] [fireeye/flare-vm](https://github.com/fireeye/flare-vm) FireEye Labs Advanced Reverse Engineering +- [**1730**Star][3y] [Go] [s-rah/onionscan](https://github.com/s-rah/onionscan) OnionScan is a free and open source tool for investigating the Dark Web. +- [**1730**Star][6m] [Smali] [ahmyth/ahmyth-android-rat](https://github.com/ahmyth/ahmyth-android-rat) Android Remote Administration Tool +- [**1723**Star][14d] [selierlin/share-ssr-v2ray](https://github.com/selierlin/share-ssr-v2ray) +- [**1719**Star][4d] [C] [google/honggfuzz](https://github.com/google/honggfuzz) Security oriented fuzzer with powerful analysis options. Supports evolutionary, feedback-driven fuzzing based on code coverage (software- and hardware-based) +- [**1718**Star][9m] [Py] [constverum/proxybroker](https://github.com/constverum/proxybroker) Proxy [Finder | Checker | Server]. HTTP(S) & SOCKS +- [**1717**Star][4m] [Py] [lgandx/responder](https://github.com/lgandx/responder) Responder is a LLMNR, NBT-NS and MDNS poisoner, with built-in HTTP/SMB/MSSQL/FTP/LDAP rogue authentication server supporting NTLMv1/NTLMv2/LMv2, Extended Security NTLMSSP and Basic HTTP authentication. +- [**1714**Star][5d] [Ruby] [cliffe/secgen](https://github.com/cliffe/secgen) Create randomly insecure VMs +- [**1710**Star][1m] [Go] [eth0izzle/shhgit](https://github.com/eth0izzle/shhgit) Find GitHub secrets in real time +- [**1709**Star][3m] [Py] [anorov/cloudflare-scrape](https://github.com/anorov/cloudflare-scrape) A Python module to bypass Cloudflare's anti-bot page. +- [**1709**Star][1y] [Java] [ac-pm/inspeckage](https://github.com/ac-pm/inspeckage) Android Package Inspector - dynamic analysis with api hooks, start unexported activities and more. (Xposed Module) +- [**1707**Star][3d] [TSQL] [brentozarultd/sql-server-first-responder-kit](https://github.com/brentozarultd/sql-server-first-responder-kit) sp_Blitz, sp_BlitzCache, sp_BlitzFirst, sp_BlitzIndex, and other SQL Server scripts for health checks and performance tuning. +- [**1706**Star][16d] [Go] [hashicorp/memberlist](https://github.com/hashicorp/memberlist) Golang package for gossip based membership and failure detection +- [**1700**Star][8m] [Py] [guelfoweb/knock](https://github.com/guelfoweb/knock) Knock Subdomain Scan +- [**1697**Star][9m] [CSS] [bagder/http2-explained](https://github.com/bagder/http2-explained) A detailed document explaining and documenting HTTP/2, the successor to the widely popular HTTP/1.1 protocol +- [**1696**Star][3m] [PHP] [xtr4nge/fruitywifi](https://github.com/xtr4nge/fruitywifi) FruityWiFi is a wireless network auditing tool. The application can be installed in any Debian based system (Jessie) adding the extra packages. Tested in Debian, Kali Linux, Kali Linux ARM (Raspberry Pi), Raspbian (Raspberry Pi), Pwnpi (Raspberry Pi), Bugtraq, NetHunter. +- [**1696**Star][1y] [Swift] [haxpor/potatso](https://github.com/haxpor/potatso) Potatso is an iOS client that implements Shadowsocks proxy with the leverage of NetworkExtension framework. ***This project is unmaintained, try taking a look at this fork +- [**1695**Star][6m] [Py] [yelp/osxcollector](https://github.com/yelp/osxcollector) A forensic evidence collection & analysis toolkit for OS X +- [**1695**Star][3y] [CoffeeScript] [okturtles/dnschain](https://github.com/okturtles/dnschain) A blockchain-based DNS + HTTP server that fixes HTTPS security, and more! +- [**1689**Star][5m] [C] [networkprotocol/netcode.io](https://github.com/networkprotocol/netcode.io) A protocol for secure client/server connections over UDP +- [**1687**Star][5m] [JS] [expressjs/csurf](https://github.com/expressjs/csurf) CSRF token middleware +- [**1687**Star][15d] [HTML] [chromium/badssl.com](https://github.com/chromium/badssl.com) +- [**1686**Star][8m] [Makefile] [raspberrypi/noobs](https://github.com/raspberrypi/noobs) NOOBS (New Out Of Box Software) - An easy Operating System install manager for the Raspberry Pi +- [**1685**Star][4m] [R] [briatte/awesome-network-analysis](https://github.com/briatte/awesome-network-analysis) A curated list of awesome network analysis resources. +- [**1683**Star][1y] [owasp/devguide](https://github.com/owasp/devguide) The OWASP Guide +- [**1682**Star][3m] [Py] [rootm0s/winpwnage](https://github.com/rootm0s/winpwnage) UAC bypass, Elevate, Persistence and Execution methods +- [**1677**Star][30d] [Swift] [pmusolino/wormholy](https://github.com/pmusolino/wormholy) iOS network debugging, like a wizard 🧙‍♂️ +- [**1674**Star][2d] [C++] [microsoft/detours](https://github.com/microsoft/detours) Detours is a software package for monitoring and instrumenting API calls on Windows. It is distributed in source code form. +- [**1671**Star][7m] [C++] [yegord/snowman](https://github.com/yegord/snowman) a native code to C/C++ decompiler, supporting x86, AMD64, and ARM architectures - [IDA插件](https://github.com/yegord/snowman/tree/master/src/ida-plugin) - [snowman](https://github.com/yegord/snowman/tree/master/src/snowman) QT界面 - [nocode](https://github.com/yegord/snowman/tree/master/src/nocode) 命令行工具 - [nc](https://github.com/yegord/snowman/tree/master/src/nc) 核心代码,可作为库使用 -- [**1665**Star][6m] [C++] [microsoft/detours](https://github.com/microsoft/detours) Detours is a software package for monitoring and instrumenting API calls on Windows. It is distributed in source code form. -- [**1662**Star][12d] [selierlin/share-ssr-v2ray](https://github.com/selierlin/share-ssr-v2ray) -- [**1662**Star][4y] [Java] [dodola/hotfix](https://github.com/dodola/hotfix) 安卓App热补丁动态修复框架 -- [**1659**Star][7d] [Java] [apache/geode](https://github.com/apache/geode) Apache Geode -- [**1655**Star][6m] [C] [easyhook/easyhook](https://github.com/easyhook/easyhook) The reinvention of Windows API Hooking -- [**1654**Star][3m] [JS] [tylerbrock/mongo-hacker](https://github.com/tylerbrock/mongo-hacker) MongoDB Shell Enhancements for Hackers -- [**1653**Star][2m] [NSIS] [angryip/ipscan](https://github.com/angryip/ipscan) Angry IP Scanner - fast and friendly network scanner -- [**1651**Star][7d] [Py] [cea-sec/ivre](https://github.com/cea-sec/ivre) Network recon framework. -- [**1650**Star][2y] [Shell] [juude/droidreverse](https://github.com/juude/droidreverse) reverse engineering tools for android -- [**1649**Star][10m] [JS] [evilcos/xssor2](https://github.com/evilcos/xssor2) XSS'OR - Hack with JavaScript. -- [**1647**Star][3m] [Py] [boppreh/keyboard](https://github.com/boppreh/keyboard) Hook and simulate global keyboard events on Windows and Linux. -- [**1646**Star][8d] [roave/securityadvisories](https://github.com/roave/securityadvisories) ensures that your application doesn't have installed dependencies with known security vulnerabilities -- [**1646**Star][8d] [JS] [ghacksuserjs/ghacks-user.js](https://github.com/ghacksuserjs/ghacks-user.js) An ongoing comprehensive user.js template for configuring and hardening Firefox privacy, security and anti-fingerprinting +- [**1668**Star][2m] [NSIS] [angryip/ipscan](https://github.com/angryip/ipscan) Angry IP Scanner - fast and friendly network scanner +- [**1666**Star][2d] [Java] [apache/geode](https://github.com/apache/geode) Apache Geode +- [**1663**Star][4y] [Java] [dodola/hotfix](https://github.com/dodola/hotfix) 安卓App热补丁动态修复框架 +- [**1661**Star][6m] [C] [easyhook/easyhook](https://github.com/easyhook/easyhook) The reinvention of Windows API Hooking +- [**1661**Star][2d] [Py] [cea-sec/ivre](https://github.com/cea-sec/ivre) Network recon framework. +- [**1659**Star][10d] [roave/securityadvisories](https://github.com/roave/securityadvisories) ensures that your application doesn't have installed dependencies with known security vulnerabilities +- [**1656**Star][6d] [JS] [tylerbrock/mongo-hacker](https://github.com/tylerbrock/mongo-hacker) MongoDB Shell Enhancements for Hackers +- [**1655**Star][3m] [Py] [boppreh/keyboard](https://github.com/boppreh/keyboard) Hook and simulate global keyboard events on Windows and Linux. +- [**1654**Star][2d] [JS] [ghacksuserjs/ghacks-user.js](https://github.com/ghacksuserjs/ghacks-user.js) An ongoing comprehensive user.js template for configuring and hardening Firefox privacy, security and anti-fingerprinting +- [**1652**Star][2y] [Shell] [juude/droidreverse](https://github.com/juude/droidreverse) reverse engineering tools for android +- [**1652**Star][7m] [dsasmblr/game-hacking](https://github.com/dsasmblr/game-hacking) Tutorials, tools, and more as related to reverse engineering video games. +- [**1651**Star][10m] [JS] [evilcos/xssor2](https://github.com/evilcos/xssor2) XSS'OR - Hack with JavaScript. +- [**1650**Star][1m] [Py] [ehco1996/django-sspanel](https://github.com/ehco1996/django-sspanel) 用diango开发的全新的shadowsocks网络面板 +- [**1650**Star][7d] [HTML] [clong/detectionlab](https://github.com/clong/detectionlab) Vagrant & Packer scripts to build a lab environment complete with security tooling and logging best practices +- [**1649**Star][1y] [Py] [evyatarmeged/raccoon](https://github.com/evyatarmeged/raccoon) A high performance offensive security tool for reconnaissance and vulnerability scanning +- [**1648**Star][2d] [C#] [jbevain/cecil](https://github.com/jbevain/cecil) Cecil is a library to inspect, modify and create .NET programs and libraries. - [**1645**Star][3y] [JS] [camwiegert/baffle](https://github.com/camwiegert/baffle) A tiny javascript library for obfuscating and revealing text in DOM elements. -- [**1643**Star][1m] [C#] [jbevain/cecil](https://github.com/jbevain/cecil) Cecil is a library to inspect, modify and create .NET programs and libraries. -- [**1641**Star][1y] [Py] [evyatarmeged/raccoon](https://github.com/evyatarmeged/raccoon) A high performance offensive security tool for reconnaissance and vulnerability scanning -- [**1641**Star][6m] [dsasmblr/game-hacking](https://github.com/dsasmblr/game-hacking) Tutorials, tools, and more as related to reverse engineering video games. -- [**1639**Star][1m] [Py] [ehco1996/django-sspanel](https://github.com/ehco1996/django-sspanel) 用diango开发的全新的shadowsocks网络面板 -- [**1637**Star][13d] [HTML] [clong/detectionlab](https://github.com/clong/detectionlab) Vagrant & Packer scripts to build a lab environment complete with security tooling and logging best practices -- [**1636**Star][11m] [Java] [fesh0r/fernflower](https://github.com/fesh0r/fernflower) Unofficial mirror of FernFlower Java decompiler (All pulls should be submitted upstream) -- [**1635**Star][4y] [Py] [ctfs/write-ups-2014](https://github.com/ctfs/write-ups-2014) Wiki-like CTF write-ups repository, maintained by the community. 2014 -- [**1635**Star][4m] [Java] [jaredrummler/androidprocesses](https://github.com/jaredrummler/androidprocesses) DEPRECATED -- [**1635**Star][4y] [Py] [ctfs/write-ups-2014](https://github.com/ctfs/write-ups-2014) Wiki-like CTF write-ups repository, maintained by the community. 2014 -- [**1629**Star][9m] [tylerha97/awesome-reversing](https://github.com/tylerha97/awesome-reversing) A curated list of awesome reversing resources -- [**1627**Star][12d] [Go] [awnumar/memguard](https://github.com/awnumar/memguard) Secure software enclave for storage of sensitive information in memory. -- [**1627**Star][9d] [sarojaba/awesome-devblog](https://github.com/sarojaba/awesome-devblog) 어썸데브블로그. 국내 개발 블로그 모음(only 실명으로). -- [**1620**Star][14d] [JS] [efforg/privacybadger](https://github.com/efforg/privacybadger) Privacy Badger is a browser extension that automatically learns to block invisible trackers. -- [**1616**Star][2y] [jhaddix/tbhm](https://github.com/jhaddix/tbhm) The Bug Hunters Methodology -- [**1614**Star][2m] [Shell] [internetwache/gittools](https://github.com/internetwache/gittools) find websites with their .git repository available to the public -- [**1612**Star][4m] [CSS] [functionclub/v2ray.fun](https://github.com/functionclub/v2ray.fun) 正在开发的全新 V2ray.Fun -- [**1611**Star][2m] [Go] [ysrc/yulong-hids](https://github.com/ysrc/yulong-hids) 一款由 YSRC 开源的主机入侵检测系统 -- [**1610**Star][7m] [Go] [sipt/shuttle](https://github.com/sipt/shuttle) A web proxy in Golang with amazing features. -- [**1608**Star][2y] [JS] [addyosmani/a11y](https://github.com/addyosmani/a11y) Accessibility audit tooling for the web (beta) -- [**1607**Star][3y] [Makefile] [drizzlerisk/drizzledumper](https://github.com/drizzlerisk/drizzledumper) a memory-search-based Android unpack tool. -- [**1605**Star][27d] [PHP] [c0ny1/upload-labs](https://github.com/c0ny1/upload-labs) 一个帮你总结所有类型的上传漏洞的靶场 -- [**1604**Star][10m] [C] [nmikhailov/validity90](https://github.com/nmikhailov/validity90) Reverse engineering of Validity/Synaptics 138a:0090, 138a:0094, 138a:0097, 06cb:0081, 06cb:009a fingerprint readers protocol -- [**1602**Star][1y] [Py] [nccgroup/scout2](https://github.com/nccgroup/Scout2) Security auditing tool for AWS environments +- [**1643**Star][9m] [tylerha97/awesome-reversing](https://github.com/tylerha97/awesome-reversing) A curated list of awesome reversing resources +- [**1643**Star][11m] [Java] [fesh0r/fernflower](https://github.com/fesh0r/fernflower) Unofficial mirror of FernFlower Java decompiler (All pulls should be submitted upstream) +- [**1638**Star][4y] [Py] [ctfs/write-ups-2014](https://github.com/ctfs/write-ups-2014) Wiki-like CTF write-ups repository, maintained by the community. 2014 +- [**1638**Star][11m] [C] [dlundquist/sniproxy](https://github.com/dlundquist/sniproxy) Proxies incoming HTTP and TLS connections based on the hostname contained in the initial request of the TCP session. +- [**1638**Star][4y] [Py] [ctfs/write-ups-2014](https://github.com/ctfs/write-ups-2014) Wiki-like CTF write-ups repository, maintained by the community. 2014 +- [**1636**Star][4m] [Java] [jaredrummler/androidprocesses](https://github.com/jaredrummler/androidprocesses) DEPRECATED +- [**1634**Star][14d] [Go] [awnumar/memguard](https://github.com/awnumar/memguard) Secure software enclave for storage of sensitive information in memory. +- [**1631**Star][6m] [Objective-C++] [tencent/oomdetector](https://github.com/tencent/oomdetector) OOMDetector is a memory monitoring component for iOS which provides you with OOM monitoring, memory allocation monitoring, memory leak detection and other functions. +- [**1630**Star][6d] [JS] [efforg/privacybadger](https://github.com/efforg/privacybadger) Privacy Badger is a browser extension that automatically learns to block invisible trackers. +- [**1630**Star][29d] [PHP] [c0ny1/upload-labs](https://github.com/c0ny1/upload-labs) 一个帮你总结所有类型的上传漏洞的靶场 +- [**1629**Star][5d] [sarojaba/awesome-devblog](https://github.com/sarojaba/awesome-devblog) 어썸데브블로그. 국내 개발 블로그 모음(only 실명으로). +- [**1624**Star][2y] [jhaddix/tbhm](https://github.com/jhaddix/tbhm) The Bug Hunters Methodology +- [**1624**Star][4m] [CSS] [functionclub/v2ray.fun](https://github.com/functionclub/v2ray.fun) 正在开发的全新 V2ray.Fun +- [**1621**Star][2m] [Shell] [internetwache/gittools](https://github.com/internetwache/gittools) find websites with their .git repository available to the public +- [**1618**Star][28d] [Java] [tiann/epic](https://github.com/tiann/epic) Dynamic java method AOP hook for Android(continution of Dexposed on ART), Supporting 4.0~10.0 +- [**1615**Star][2y] [JS] [addyosmani/a11y](https://github.com/addyosmani/a11y) Accessibility audit tooling for the web (beta) +- [**1614**Star][2m] [Go] [ysrc/yulong-hids](https://github.com/ysrc/yulong-hids) 一款由 YSRC 开源的主机入侵检测系统 +- [**1614**Star][7m] [Go] [sipt/shuttle](https://github.com/sipt/shuttle) A web proxy in Golang with amazing features. +- [**1612**Star][3y] [Makefile] [drizzlerisk/drizzledumper](https://github.com/drizzlerisk/drizzledumper) a memory-search-based Android unpack tool. +- [**1608**Star][9m] [JS] [localtunnel/server](https://github.com/localtunnel/server) server for localtunnel.me +- [**1608**Star][10m] [C] [nmikhailov/validity90](https://github.com/nmikhailov/validity90) Reverse engineering of Validity/Synaptics 138a:0090, 138a:0094, 138a:0097, 06cb:0081, 06cb:009a fingerprint readers protocol +- [**1606**Star][2d] [C++] [lief-project/lief](https://github.com/lief-project/lief) Library to Instrument Executable Formats - [**1602**Star][6m] [Py] [w1109790800/penetration](https://github.com/w1109790800/penetration) 渗透 超全面的渗透资料 -- [**1600**Star][8d] [C++] [lief-project/lief](https://github.com/lief-project/lief) Library to Instrument Executable Formats -- [**1599**Star][9m] [JS] [localtunnel/server](https://github.com/localtunnel/server) server for localtunnel.me -- [**1596**Star][5m] [Py] [mozilla/cipherscan](https://github.com/mozilla/cipherscan) A very simple way to find out which SSL ciphersuites are supported by a target. -- [**1596**Star][3m] [Py] [knownsec/pocsuite](https://github.com/knownsec/pocsuite) This project has stopped to maintenance, please to -- [**1593**Star][26d] [Java] [tiann/epic](https://github.com/tiann/epic) Dynamic java method AOP hook for Android(continution of Dexposed on ART), Supporting 4.0~10.0 -- [**1588**Star][13d] [Java] [spotbugs/spotbugs](https://github.com/spotbugs/spotbugs) SpotBugs is FindBugs' successor. A tool for static analysis to look for bugs in Java code. -- [**1583**Star][6m] [Ruby] [brunofacca/zen-rails-security-checklist](https://github.com/brunofacca/zen-rails-security-checklist) Checklist of security precautions for Ruby on Rails applications. -- [**1580**Star][1y] [C] [qihoo360/phptrace](https://github.com/qihoo360/phptrace) A tracing and troubleshooting tool for PHP scripts. -- [**1580**Star][7d] [Go] [bitnami-labs/sealed-secrets](https://github.com/bitnami-labs/sealed-secrets) A Kubernetes controller and tool for one-way encrypted Secrets -- [**1577**Star][4y] [l3m0n/pentest_study](https://github.com/l3m0n/pentest_study) 从零开始内网渗透学习 -- [**1577**Star][1m] [Objective-C] [ealeksandrov/provisionql](https://github.com/ealeksandrov/provisionql) Quick Look plugin for apps and provisioning profile files -- [**1575**Star][26d] [C] [ntop/n2n](https://github.com/ntop/n2n) Peer-to-peer VPN -- [**1574**Star][22d] [ivrodriguezca/re-ios-apps](https://github.com/ivrodriguezca/re-ios-apps) A completely free, open source and online course about Reverse Engineering iOS Applications. -- [**1563**Star][2y] [C] [samyk/pwnat](https://github.com/samyk/pwnat) The only tool and technique to punch holes through firewalls/NATs where both clients and server can be behind separate NATs without any 3rd party involvement. Pwnat uses a newly developed technique, exploiting a property of NAT translation tables, with no 3rd party, port forwarding, DMZ, router administrative requirements, STUN/TURN/UPnP/ICE, or… -- [**1563**Star][12d] [C] [codahale/bcrypt-ruby](https://github.com/codahale/bcrypt-ruby) Ruby binding for the OpenBSD bcrypt() password hashing algorithm, allowing you to easily store a secure hash of your users' passwords. -- [**1562**Star][17d] [C] [p-gen/smenu](https://github.com/p-gen/smenu) Terminal utility that reads words from standard input or from a file and creates an interactive selection window just below the cursor. The selected word(s) are sent to standard output for further processing. -- [**1560**Star][14d] [Java] [gchq/gaffer](https://github.com/gchq/Gaffer) A large-scale entity and relation database supporting aggregation of properties -- [**1557**Star][2m] [C] [firmianay/ctf-all-in-one](https://github.com/firmianay/ctf-all-in-one) CTF竞赛入门指南 -- [**1556**Star][12d] [Go] [caffix/amass](https://github.com/caffix/amass) In-depth Attack Surface Mapping and Asset Discovery -- [**1555**Star][1y] [Py] [unkl4b/gitminer](https://github.com/unkl4b/gitminer) Tool for advanced mining for content on Github -- [**1552**Star][12d] [Py] [k4m4/kickthemout](https://github.com/k4m4/kickthemout) kick devices out of your network and enjoy all the bandwidth for yourself. -- [**1550**Star][8m] [Py] [m4ll0k/wascan](https://github.com/m4ll0k/WAScan) WAScan - Web Application Scanner -- [**1547**Star][1y] [C] [ctfs/write-ups-2016](https://github.com/ctfs/write-ups-2016) Wiki-like CTF write-ups repository, maintained by the community. 2016 -- [**1545**Star][6y] [Py] [google/pyringe](https://github.com/google/pyringe) Debugger capable of attaching to and injecting code into python processes. -- [**1544**Star][1m] [Shell] [mzet-/linux-exploit-suggester](https://github.com/mzet-/linux-exploit-suggester) Linux privilege escalation auditing tool -- [**1544**Star][3m] [PHP] [mewebstudio/captcha](https://github.com/mewebstudio/captcha) Captcha for Laravel 5 & 6 -- [**1542**Star][1m] [Py] [joxeankoret/diaphora](https://github.com/joxeankoret/diaphora) program diffing +- [**1601**Star][1y] [Py] [nccgroup/scout2](https://github.com/nccgroup/Scout2) Security auditing tool for AWS environments +- [**1601**Star][5m] [Py] [mozilla/cipherscan](https://github.com/mozilla/cipherscan) A very simple way to find out which SSL ciphersuites are supported by a target. +- [**1600**Star][5d] [Go] [bitnami-labs/sealed-secrets](https://github.com/bitnami-labs/sealed-secrets) A Kubernetes controller and tool for one-way encrypted Secrets +- [**1599**Star][2y] [JS] [keraf/nocoin](https://github.com/keraf/nocoin) No Coin is a tiny browser extension aiming to block coin miners such as Coinhive. +- [**1598**Star][15d] [Java] [spotbugs/spotbugs](https://github.com/spotbugs/spotbugs) SpotBugs is FindBugs' successor. A tool for static analysis to look for bugs in Java code. +- [**1597**Star][3m] [Py] [knownsec/pocsuite](https://github.com/knownsec/pocsuite) This project has stopped to maintenance, please to +- [**1591**Star][28d] [C] [ntop/n2n](https://github.com/ntop/n2n) Peer-to-peer VPN +- [**1591**Star][24d] [ivrodriguezca/re-ios-apps](https://github.com/ivrodriguezca/re-ios-apps) A completely free, open source and online course about Reverse Engineering iOS Applications. +- [**1584**Star][6m] [Ruby] [brunofacca/zen-rails-security-checklist](https://github.com/brunofacca/zen-rails-security-checklist) Checklist of security precautions for Ruby on Rails applications. +- [**1583**Star][4y] [l3m0n/pentest_study](https://github.com/l3m0n/pentest_study) 从零开始内网渗透学习 +- [**1582**Star][1m] [ObjC] [ealeksandrov/provisionql](https://github.com/ealeksandrov/provisionql) Quick Look plugin for apps and provisioning profile files +- [**1581**Star][1y] [C] [qihoo360/phptrace](https://github.com/qihoo360/phptrace) A tracing and troubleshooting tool for PHP scripts. +- [**1570**Star][2m] [C] [firmianay/ctf-all-in-one](https://github.com/firmianay/ctf-all-in-one) CTF竞赛入门指南 +- [**1569**Star][2y] [C] [samyk/pwnat](https://github.com/samyk/pwnat) The only tool and technique to punch holes through firewalls/NATs where both clients and server can be behind separate NATs without any 3rd party involvement. Pwnat uses a newly developed technique, exploiting a property of NAT translation tables, with no 3rd party, port forwarding, DMZ, router administrative requirements, STUN/TURN/UPnP/ICE, or… +- [**1569**Star][29d] [Py] [opendevops-cn/opendevops](https://github.com/opendevops-cn/opendevops) CODO是一款为用户提供企业多混合云、一站式DevOps、自动化运维、完全开源的云管理平台、自动化运维平台 +- [**1566**Star][14d] [C] [codahale/bcrypt-ruby](https://github.com/codahale/bcrypt-ruby) Ruby binding for the OpenBSD bcrypt() password hashing algorithm, allowing you to easily store a secure hash of your users' passwords. +- [**1565**Star][17d] [Go] [sofastack/sofa-mosn](https://github.com/sofastack/sofa-mosn) MOSN is a modular observable smart network which can be used in service mesh deployed as a data plane sidecar. +- [**1562**Star][19d] [C] [p-gen/smenu](https://github.com/p-gen/smenu) Terminal utility that reads words from standard input or from a file and creates an interactive selection window just below the cursor. The selected word(s) are sent to standard output for further processing. +- [**1562**Star][14d] [Py] [k4m4/kickthemout](https://github.com/k4m4/kickthemout) kick devices out of your network and enjoy all the bandwidth for yourself. +- [**1561**Star][16d] [Java] [gchq/gaffer](https://github.com/gchq/Gaffer) A large-scale entity and relation database supporting aggregation of properties +- [**1560**Star][1y] [Py] [unkl4b/gitminer](https://github.com/unkl4b/gitminer) Tool for advanced mining for content on Github +- [**1560**Star][6d] [Go] [caffix/amass](https://github.com/caffix/amass) In-depth Attack Surface Mapping and Asset Discovery +- [**1557**Star][8m] [Py] [m4ll0k/wascan](https://github.com/m4ll0k/WAScan) WAScan - Web Application Scanner +- [**1556**Star][15d] [Go] [eolinker/goku-api-gateway](https://github.com/eolinker/goku-api-gateway) A Powerful HTTP API Gateway in pure golang!Goku API Gateway (中文名:悟空 API 网关)是一个基于 Golang开发的微服务网关,能够实现高性能 HTTP API 转发、服务编排、多租户管理、API 访问权限控制等目的,拥有强大的自定义插件系统可以自行扩展,并且提供友好的图形化配置界面,能够快速帮助企业进行 API 服务治理、提高 API 服务的稳定性和安全性。 +- [**1555**Star][1m] [Shell] [mzet-/linux-exploit-suggester](https://github.com/mzet-/linux-exploit-suggester) Linux privilege escalation auditing tool +- [**1549**Star][7d] [PHP] [mewebstudio/captcha](https://github.com/mewebstudio/captcha) Captcha for Laravel 5 & 6 +- [**1549**Star][1m] [Py] [joxeankoret/diaphora](https://github.com/joxeankoret/diaphora) program diffing +- [**1548**Star][1y] [C] [ctfs/write-ups-2016](https://github.com/ctfs/write-ups-2016) Wiki-like CTF write-ups repository, maintained by the community. 2016 +- [**1544**Star][15d] [C] [raspberrypi/userland](https://github.com/raspberrypi/userland) Source code for ARM side libraries for interfacing to Raspberry Pi GPU. +- [**1544**Star][6y] [Py] [google/pyringe](https://github.com/google/pyringe) Debugger capable of attaching to and injecting code into python processes. +- [**1543**Star][2d] [Go] [juju/juju](https://github.com/juju/juju) Simple, secure devops tooling built to manage today's complex applications wherever you run your software. +- [**1541**Star][2y] [Py] [awolfly9/ipproxytool](https://github.com/awolfly9/ipproxytool) python ip proxy tool scrapy crawl. 抓取大量免费代理 ip,提取有效 ip 使用 - [**1540**Star][2y] [C++] [hteso/iaito](https://github.com/hteso/iaito) A Qt and C++ GUI for radare2 reverse engineering framework -- [**1536**Star][2y] [Py] [awolfly9/ipproxytool](https://github.com/awolfly9/ipproxytool) python ip proxy tool scrapy crawl. 抓取大量免费代理 ip,提取有效 ip 使用 -- [**1533**Star][2y] [C] [ezlippi/webbench](https://github.com/ezlippi/webbench) Webbench是Radim Kolar在1997年写的一个在linux下使用的非常简单的网站压测工具。它使用fork()模拟多个客户端同时访问我们设定的URL,测试网站在压力下工作的性能,最多可以模拟3万个并发连接去测试网站的负载能力。官网地址: -- [**1532**Star][13d] [C] [raspberrypi/userland](https://github.com/raspberrypi/userland) Source code for ARM side libraries for interfacing to Raspberry Pi GPU. -- [**1531**Star][7d] [Py] [lifting-bits/mcsema](https://github.com/lifting-bits/mcsema) Framework for lifting x86, amd64, and aarch64 program binaries to LLVM bitcode +- [**1539**Star][2y] [C] [ezlippi/webbench](https://github.com/ezlippi/webbench) Webbench是Radim Kolar在1997年写的一个在linux下使用的非常简单的网站压测工具。它使用fork()模拟多个客户端同时访问我们设定的URL,测试网站在压力下工作的性能,最多可以模拟3万个并发连接去测试网站的负载能力。官网地址: +- [**1537**Star][9d] [Py] [lifting-bits/mcsema](https://github.com/lifting-bits/mcsema) Framework for lifting x86, amd64, and aarch64 program binaries to LLVM bitcode - [IDA7插件](https://github.com/lifting-bits/mcsema/tree/master/tools/mcsema_disass/ida7) 用于反汇编二进制文件并生成控制流程图 - [IDA插件](https://github.com/lifting-bits/mcsema/tree/master/tools/mcsema_disass/ida) 用于反汇编二进制文件并生成控制流程图 - [Binja插件](https://github.com/lifting-bits/mcsema/tree/master/tools/mcsema_disass/binja) 用于反汇编二进制文件并生成控制流程图 - [mcsema](https://github.com/lifting-bits/mcsema/tree/master/mcsema) -- [**1530**Star][7d] [Go] [juju/juju](https://github.com/juju/juju) Simple, secure devops tooling built to manage today's complex applications wherever you run your software. -- [**1528**Star][3y] [Py] [x0rz/eqgrp_lost_in_translation](https://github.com/x0rz/eqgrp_lost_in_translation) Decrypted content of odd.tar.xz.gpg, swift.tar.xz.gpg and windows.tar.xz.gpg -- [**1527**Star][11d] [emijrp/awesome-awesome](https://github.com/emijrp/awesome-awesome) A curated list of awesome curated lists of many topics. -- [**1525**Star][10d] [Java] [ukanth/afwall](https://github.com/ukanth/afwall) AFWall+ (Android Firewall +) - iptables based firewall for Android -- [**1521**Star][1y] [HTML] [qiwihui/hiwifi-ss](https://github.com/qiwihui/hiwifi-ss) 极路由+ss配置 -- [**1520**Star][4m] [TypeScript] [spring-guides/tut-spring-security-and-angular-js](https://github.com/spring-guides/tut-spring-security-and-angular-js) Spring Security and Angular:: A tutorial on how to use Spring Security with a single page application with various backend architectures, ranging from a simple single server to an API gateway with OAuth2 authentication. -- [**1520**Star][20d] [C++] [nmap/npcap](https://github.com/nmap/npcap) Nmap Project's packet sniffing library for Windows, based on WinPcap/Libpcap improved with NDIS 6 and LWF. -- [**1519**Star][10m] [PowerShell] [joefitzgerald/packer-windows](https://github.com/joefitzgerald/packer-windows) Windows templates that can be used to create boxes for Vagrant using Packer -- [**1516**Star][9m] [Py] [google/rekall](https://github.com/google/rekall) Rekall Memory Forensic Framework +- [**1536**Star][4d] [Java] [ukanth/afwall](https://github.com/ukanth/afwall) AFWall+ (Android Firewall +) - iptables based firewall for Android +- [**1533**Star][13d] [emijrp/awesome-awesome](https://github.com/emijrp/awesome-awesome) A curated list of awesome curated lists of many topics. +- [**1532**Star][3y] [Py] [x0rz/eqgrp_lost_in_translation](https://github.com/x0rz/eqgrp_lost_in_translation) Decrypted content of odd.tar.xz.gpg, swift.tar.xz.gpg and windows.tar.xz.gpg +- [**1526**Star][2d] [C++] [nmap/npcap](https://github.com/nmap/npcap) Nmap Project's packet sniffing library for Windows, based on WinPcap/Libpcap improved with NDIS 6 and LWF. +- [**1522**Star][1y] [HTML] [qiwihui/hiwifi-ss](https://github.com/qiwihui/hiwifi-ss) 极路由+ss配置 +- [**1521**Star][4m] [TS] [spring-guides/tut-spring-security-and-angular-js](https://github.com/spring-guides/tut-spring-security-and-angular-js) Spring Security and Angular:: A tutorial on how to use Spring Security with a single page application with various backend architectures, ranging from a simple single server to an API gateway with OAuth2 authentication. +- [**1521**Star][3d] [C] [jiangwenyuan/nuster](https://github.com/jiangwenyuan/nuster) A high performance HTTP proxy cache server and RESTful NoSQL cache server based on HAProxy +- [**1519**Star][10m] [PS] [joefitzgerald/packer-windows](https://github.com/joefitzgerald/packer-windows) Windows templates that can be used to create boxes for Vagrant using Packer +- [**1518**Star][9m] [Py] [google/rekall](https://github.com/google/rekall) Rekall Memory Forensic Framework +- [**1517**Star][8d] [Py] [zerosum0x0/koadic](https://github.com/zerosum0x0/koadic) Koadic C3 COM Command & Control - JScript RAT +- [**1516**Star][5m] [snowming04/the-hacker-playbook-3-translation](https://github.com/snowming04/the-hacker-playbook-3-translation) 对 The Hacker Playbook 3 的翻译。 +- [**1514**Star][3y] [Py] [sensepost/regeorg](https://github.com/sensepost/regeorg) The successor to reDuh, pwn a bastion webserver and create SOCKS proxies through the DMZ. Pivot and pwn. - [**1510**Star][1y] [dripcap/dripcap](https://github.com/dripcap/dripcap) -- [**1509**Star][21d] [Py] [zerosum0x0/koadic](https://github.com/zerosum0x0/koadic) Koadic C3 COM Command & Control - JScript RAT -- [**1506**Star][3y] [Py] [sensepost/regeorg](https://github.com/sensepost/regeorg) The successor to reDuh, pwn a bastion webserver and create SOCKS proxies through the DMZ. Pivot and pwn. -- [**1504**Star][5m] [snowming04/the-hacker-playbook-3-translation](https://github.com/snowming04/the-hacker-playbook-3-translation) 对 The Hacker Playbook 3 的翻译。 -- [**1503**Star][2y] [Py] [eldraco/domain_analyzer](https://github.com/eldraco/domain_analyzer) Analyze the security of any domain by finding all the information possible. Made in python. -- [**1501**Star][25d] [Py] [hannob/snallygaster](https://github.com/hannob/snallygaster) Tool to scan for secret files on HTTP servers -- [**1500**Star][2m] [Shell] [haugene/docker-transmission-openvpn](https://github.com/haugene/docker-transmission-openvpn) Docker container running Transmission torrent client with WebUI over an OpenVPN tunnel -- [**1491**Star][4m] [Py] [epinna/tplmap](https://github.com/epinna/tplmap) Server-Side Template Injection and Code Injection Detection and Exploitation Tool -- [**1490**Star][10d] [YARA] [cybermonitor/apt_cybercriminal_campagin_collections](https://github.com/cybermonitor/apt_cybercriminal_campagin_collections) APT & CyberCriminal Campaign Collection -- [**1487**Star][7m] [Py] [ahupp/python-magic](https://github.com/ahupp/python-magic) A python wrapper for libmagic -- [**1485**Star][2y] [Kotlin] [gh0u1l5/wechatmagician](https://github.com/gh0u1l5/wechatmagician) WechatMagician is a Xposed module written in Kotlin, that allows you to completely control your Wechat. -- [**1482**Star][7m] [C++] [wangyu-/tinyfecvpn](https://github.com/wangyu-/tinyfecvpn) A VPN Designed for Lossy Links, with Build-in Forward Error Correction(FEC) Support. Improves your Network Quality on a High-latency Lossy Link. -- [**1478**Star][7d] [C] [sleuthkit/sleuthkit](https://github.com/sleuthkit/sleuthkit) The Sleuth Kit® (TSK) is a library and collection of command line digital forensics tools that allow you to investigate volume and file system data. The library can be incorporated into larger digital forensics tools and the command line tools can be directly used to find evidence. -- [**1475**Star][12d] [Py] [bitsadmin/wesng](https://github.com/bitsadmin/wesng) Windows Exploit Suggester - Next Generation -- [**1474**Star][1y] [C++] [f1xpl/openauto](https://github.com/f1xpl/openauto) AndroidAuto headunit emulator -- [**1472**Star][7d] [Shell] [blackarch/blackarch](https://github.com/blackarch/blackarch) BlackArch Linux is an Arch Linux-based distribution for penetration testers and security researchers. -- [**1468**Star][16d] [Go] [google/keytransparency](https://github.com/google/keytransparency) A transparent and secure way to look up public keys. -- [**1468**Star][3m] [C] [iqiyi/xhook](https://github.com/iqiyi/xhook) a PLT (Procedure Linkage Table) hook library for Android native ELF -- [**1466**Star][2m] [C++] [jmpews/hookzz](https://github.com/jmpews/hookzz) a hook framework for arm/arm64/ios/android, and [dev] branch is being refactored. -- [**1465**Star][3y] [Py] [veil-framework/veil-evasion](https://github.com/Veil-Framework/Veil-Evasion) a tool designed to generate metasploit payloads that bypass common anti-virus solutions. -- [**1465**Star][25d] [minimaxir/hacker-news-undocumented](https://github.com/minimaxir/hacker-news-undocumented) Some of the hidden norms about Hacker News not otherwise covered in the Guidelines and the FAQ. -- [**1462**Star][6y] [C] [alibaba/lvs](https://github.com/alibaba/lvs) A distribution of Linux Virtual Server with some advanced features. It introduces a new packet forwarding method - FULLNAT other than NAT/Tunneling/DirectRouting, and defense mechanism against synflooding attack - SYNPROXY. -- [**1460**Star][14d] [C] [ufrisk/pcileech](https://github.com/ufrisk/pcileech) Direct Memory Access (DMA) Attack Software -- [**1457**Star][1y] [C++] [acaudwell/logstalgia](https://github.com/acaudwell/logstalgia) a visualization tool that replays or streams web server access logs as a retro arcade game simulation. -- [**1456**Star][27d] [Go] [neex/phuip-fpizdam](https://github.com/neex/phuip-fpizdam) Exploit for CVE-2019-11043 -- [**1450**Star][1y] [Py] [d4vinci/cr3dov3r](https://github.com/d4vinci/cr3dov3r) Know the dangers of credential reuse attacks. -- [**1448**Star][6m] [Py] [enablesecurity/wafw00f](https://github.com/enablesecurity/wafw00f) identify and fingerprint Web Application Firewall (WAF) products protecting a website. -- [**1447**Star][3m] [edoverflow/can-i-take-over-xyz](https://github.com/edoverflow/can-i-take-over-xyz) "Can I take over XYZ?" — a list of services and how to claim (sub)domains with dangling DNS records. -- [**1446**Star][11d] [C++] [srslte/srslte](https://github.com/srslte/srslte) Open source SDR LTE software suite from Software Radio Systems (SRS) -- [**1442**Star][6m] [Py] [oros42/imsi-catcher](https://github.com/oros42/imsi-catcher) This program show you IMSI numbers of cellphones around you. -- [**1441**Star][19d] [C] [tianocore/edk2](https://github.com/tianocore/edk2) A modern, feature-rich, cross-platform firmware development environment for the UEFI and PI specifications -- [**1441**Star][1m] [C] [ctcaer/hekate](https://github.com/ctcaer/hekate) Nintendo Switch Bootloader - CTCaer mod -- [**1439**Star][3y] [tiancode/learn-hacking](https://github.com/tiancode/learn-hacking) 开始学习Kali Linux 各种破解教程 渗透测试 逆向工程 HackThisSite挑战问题解答 -- [**1439**Star][3y] [tiancode/learn-hacking](https://github.com/tiancode/learn-hacking) 开始学习Kali Linux 各种破解教程 渗透测试 逆向工程 HackThisSite挑战问题解答 -- [**1438**Star][3m] [C++] [vaibhavpandeyvpz/apkstudio](https://github.com/vaibhavpandeyvpz/apkstudio) Open-source, cross platform Qt based IDE for reverse-engineering Android application packages. -- [**1433**Star][18d] [Go] [skydive-project/skydive](https://github.com/skydive-project/skydive) An open source real-time network topology and protocols analyzer -- [**1433**Star][1y] [TypeScript] [pedronauck/reworm](https://github.com/pedronauck/reworm) -- [**1433**Star][12d] [C++] [microsoft/seal](https://github.com/microsoft/seal) Microsoft SEAL is an easy-to-use and powerful homomorphic encryption library. -- [**1430**Star][7d] [Go] [google/gapid](https://github.com/google/gapid) Graphics API Debugger -- [**1428**Star][7d] [Py] [rocky/python-uncompyle6](https://github.com/rocky/python-uncompyle6) A cross-version Python bytecode decompiler -- [**1427**Star][6m] [C++] [x64dbg/scyllahide](https://github.com/x64dbg/scyllahide) Advanced usermode anti-anti-debugger +- [**1508**Star][2m] [Shell] [haugene/docker-transmission-openvpn](https://github.com/haugene/docker-transmission-openvpn) Docker container running Transmission torrent client with WebUI over an OpenVPN tunnel +- [**1505**Star][2y] [Py] [eldraco/domain_analyzer](https://github.com/eldraco/domain_analyzer) Analyze the security of any domain by finding all the information possible. Made in python. +- [**1504**Star][27d] [Py] [hannob/snallygaster](https://github.com/hannob/snallygaster) Tool to scan for secret files on HTTP servers +- [**1499**Star][5d] [YARA] [cybermonitor/apt_cybercriminal_campagin_collections](https://github.com/cybermonitor/apt_cybercriminal_campagin_collections) APT & CyberCriminal Campaign Collection +- [**1497**Star][4m] [Py] [epinna/tplmap](https://github.com/epinna/tplmap) Server-Side Template Injection and Code Injection Detection and Exploitation Tool +- [**1489**Star][5d] [Py] [ahupp/python-magic](https://github.com/ahupp/python-magic) A python wrapper for libmagic +- [**1486**Star][2y] [Kotlin] [gh0u1l5/wechatmagician](https://github.com/gh0u1l5/wechatmagician) WechatMagician is a Xposed module written in Kotlin, that allows you to completely control your Wechat. +- [**1485**Star][7m] [C++] [wangyu-/tinyfecvpn](https://github.com/wangyu-/tinyfecvpn) A VPN Designed for Lossy Links, with Build-in Forward Error Correction(FEC) Support. Improves your Network Quality on a High-latency Lossy Link. +- [**1482**Star][7d] [Py] [bitsadmin/wesng](https://github.com/bitsadmin/wesng) Windows Exploit Suggester - Next Generation +- [**1481**Star][2d] [C] [sleuthkit/sleuthkit](https://github.com/sleuthkit/sleuthkit) The Sleuth Kit® (TSK) is a library and collection of command line digital forensics tools that allow you to investigate volume and file system data. The library can be incorporated into larger digital forensics tools and the command line tools can be directly used to find evidence. +- [**1480**Star][1y] [C++] [f1xpl/openauto](https://github.com/f1xpl/openauto) AndroidAuto headunit emulator +- [**1479**Star][3d] [C] [ctcaer/hekate](https://github.com/ctcaer/hekate) Nintendo Switch Bootloader - CTCaer mod +- [**1478**Star][8d] [C] [iqiyi/xhook](https://github.com/iqiyi/xhook) a PLT (Procedure Linkage Table) hook library for Android native ELF +- [**1477**Star][2d] [Shell] [blackarch/blackarch](https://github.com/blackarch/blackarch) BlackArch Linux is an Arch Linux-based distribution for penetration testers and security researchers. +- [**1476**Star][2m] [C++] [jmpews/hookzz](https://github.com/jmpews/hookzz) a hook framework for arm/arm64/ios/android, and [dev] branch is being refactored. +- [**1471**Star][27d] [minimaxir/hacker-news-undocumented](https://github.com/minimaxir/hacker-news-undocumented) Some of the hidden norms about Hacker News not otherwise covered in the Guidelines and the FAQ. +- [**1470**Star][3y] [Py] [veil-framework/veil-evasion](https://github.com/Veil-Framework/Veil-Evasion) a tool designed to generate metasploit payloads that bypass common anti-virus solutions. +- [**1470**Star][2d] [Go] [google/keytransparency](https://github.com/google/keytransparency) A transparent and secure way to look up public keys. +- [**1469**Star][6y] [C] [alibaba/lvs](https://github.com/alibaba/lvs) A distribution of Linux Virtual Server with some advanced features. It introduces a new packet forwarding method - FULLNAT other than NAT/Tunneling/DirectRouting, and defense mechanism against synflooding attack - SYNPROXY. +- [**1466**Star][29d] [Go] [neex/phuip-fpizdam](https://github.com/neex/phuip-fpizdam) Exploit for CVE-2019-11043 +- [**1464**Star][6m] [Py] [oros42/imsi-catcher](https://github.com/oros42/imsi-catcher) This program show you IMSI numbers of cellphones around you. +- [**1463**Star][7d] [C] [ufrisk/pcileech](https://github.com/ufrisk/pcileech) Direct Memory Access (DMA) Attack Software +- [**1462**Star][9d] [edoverflow/can-i-take-over-xyz](https://github.com/edoverflow/can-i-take-over-xyz) "Can I take over XYZ?" — a list of services and how to claim (sub)domains with dangling DNS records. +- [**1459**Star][3d] [Py] [enablesecurity/wafw00f](https://github.com/enablesecurity/wafw00f) identify and fingerprint Web Application Firewall (WAF) products protecting a website. +- [**1458**Star][1y] [C++] [acaudwell/logstalgia](https://github.com/acaudwell/logstalgia) a visualization tool that replays or streams web server access logs as a retro arcade game simulation. +- [**1455**Star][1y] [Py] [d4vinci/cr3dov3r](https://github.com/d4vinci/cr3dov3r) Know the dangers of credential reuse attacks. +- [**1453**Star][13d] [C++] [srslte/srslte](https://github.com/srslte/srslte) Open source SDR LTE software suite from Software Radio Systems (SRS) +- [**1451**Star][2d] [Py] [rocky/python-uncompyle6](https://github.com/rocky/python-uncompyle6) A cross-version Python bytecode decompiler +- [**1447**Star][3y] [tiancode/learn-hacking](https://github.com/tiancode/learn-hacking) 开始学习Kali Linux 各种破解教程 渗透测试 逆向工程 HackThisSite挑战问题解答 +- [**1447**Star][3y] [tiancode/learn-hacking](https://github.com/tiancode/learn-hacking) 开始学习Kali Linux 各种破解教程 渗透测试 逆向工程 HackThisSite挑战问题解答 +- [**1447**Star][2m] [Py] [neo23x0/loki](https://github.com/neo23x0/loki) Loki - Simple IOC and Incident Response Scanner +- [**1446**Star][5d] [C] [tianocore/edk2](https://github.com/tianocore/edk2) A modern, feature-rich, cross-platform firmware development environment for the UEFI and PI specifications +- [**1446**Star][20d] [Go] [skydive-project/skydive](https://github.com/skydive-project/skydive) An open source real-time network topology and protocols analyzer +- [**1446**Star][14d] [C++] [microsoft/seal](https://github.com/microsoft/seal) Microsoft SEAL is an easy-to-use and powerful homomorphic encryption library. +- [**1445**Star][3m] [C++] [vaibhavpandeyvpz/apkstudio](https://github.com/vaibhavpandeyvpz/apkstudio) Open-source, cross platform Qt based IDE for reverse-engineering Android application packages. +- [**1437**Star][5d] [Go] [google/gapid](https://github.com/google/gapid) Graphics API Debugger +- [**1436**Star][20d] [Kotlin] [cypherpunkarmory/userland](https://github.com/cypherpunkarmory/userland) The easiest way to run a Linux distribution or application on Android +- [**1433**Star][11m] [C] [tpruvot/ccminer](https://github.com/tpruvot/ccminer) CUDA Open Source miner project, for most nvidia cards +- [**1433**Star][1y] [TS] [pedronauck/reworm](https://github.com/pedronauck/reworm) +- [**1432**Star][6m] [C++] [x64dbg/scyllahide](https://github.com/x64dbg/scyllahide) Advanced usermode anti-anti-debugger +- [**1432**Star][2m] [C] [feralinteractive/gamemode](https://github.com/feralinteractive/gamemode) Optimise Linux system performance on demand +- [**1429**Star][5y] [C++] [gdbinit/machoview](https://github.com/gdbinit/machoview) MachOView fork +- [**1427**Star][9d] [ObjC] [nabla-c0d3/ssl-kill-switch2](https://github.com/nabla-c0d3/ssl-kill-switch2) Blackbox tool to disable SSL certificate validation - including certificate pinning - within iOS and OS X Apps +- [**1426**Star][20d] [C++] [plasma-umass/coz](https://github.com/plasma-umass/coz) Finding Code that Counts with Causal Profiling +- [**1426**Star][4y] [C++] [aappleby/smhasher](https://github.com/aappleby/smhasher) Automatically exported from code.google.com/p/smhasher - [**1425**Star][3m] [Go] [google/stenographer](https://github.com/google/stenographer) Stenographer is a packet capture solution which aims to quickly spool all packets to disk, then provide simple, fast access to subsets of those packets. Discussion/announcements at stenographer@googlegroups.com -- [**1423**Star][8y] [Py] [moxie0/sslstrip](https://github.com/moxie0/sslstrip) A tool for exploiting Moxie Marlinspike's SSL "stripping" attack. -- [**1423**Star][18d] [Kotlin] [cypherpunkarmory/userland](https://github.com/cypherpunkarmory/userland) The easiest way to run a Linux distribution or application on Android -- [**1422**Star][2m] [C] [feralinteractive/gamemode](https://github.com/feralinteractive/gamemode) Optimise Linux system performance on demand -- [**1421**Star][3y] [mandatoryprogrammer/northkoreadnsleak](https://github.com/mandatoryprogrammer/northkoreadnsleak) Snapshot of North Korea's DNS data taken from zone transfers. -- [**1421**Star][4y] [C++] [aappleby/smhasher](https://github.com/aappleby/smhasher) Automatically exported from code.google.com/p/smhasher -- [**1420**Star][10m] [Java] [aslody/legend](https://github.com/aslody/legend) A framework for hook java methods. -- [**1419**Star][2m] [Py] [neo23x0/loki](https://github.com/neo23x0/loki) Loki - Simple IOC and Incident Response Scanner -- [**1419**Star][3y] [Py] [nathanlopez/stitch](https://github.com/nathanlopez/stitch) Python Remote Administration Tool (RAT) -- [**1419**Star][12d] [Go] [google/google-ctf](https://github.com/google/google-ctf) Google CTF -- [**1419**Star][5y] [C++] [gdbinit/machoview](https://github.com/gdbinit/machoview) MachOView fork -- [**1417**Star][1m] [Py] [xdavidhu/mitmap](https://github.com/xdavidhu/mitmap) -- [**1417**Star][5m] [PHP] [s4n7h0/xvwa](https://github.com/s4n7h0/xvwa) XVWA is a badly coded web application written in PHP/MySQL that helps security enthusiasts to learn application security. -- [**1416**Star][1m] [Go] [barnybug/cli53](https://github.com/barnybug/cli53) Command line tool for Amazon Route 53 -- [**1415**Star][3y] [C] [antirez/dump1090](https://github.com/antirez/dump1090) Dump1090 is a simple Mode S decoder for RTLSDR devices -- [**1413**Star][7m] [Objective-C] [nabla-c0d3/ssl-kill-switch2](https://github.com/nabla-c0d3/ssl-kill-switch2) Blackbox tool to disable SSL certificate validation - including certificate pinning - within iOS and OS X Apps -- [**1411**Star][11d] [C] [ettercap/ettercap](https://github.com/ettercap/ettercap) Ettercap Project -- [**1410**Star][8d] [Go] [cosmos72/gomacro](https://github.com/cosmos72/gomacro) Interactive Go interpreter and debugger with REPL, Eval, generics and Lisp-like macros -- [**1409**Star][4m] [yadox666/the-hackers-hardware-toolkit](https://github.com/yadox666/the-hackers-hardware-toolkit) The best hacker's gadgets for Red Team pentesters and security researchers. -- [**1408**Star][22d] [Java] [chrisk44/hijacker](https://github.com/chrisk44/hijacker) Aircrack, Airodump, Aireplay, MDK3 and Reaver GUI Application for Android -- [**1407**Star][7d] [C] [namhyung/uftrace](https://github.com/namhyung/uftrace) Function (graph) tracer for user-space -- [**1406**Star][1m] [C++] [google/nsjail](https://github.com/google/nsjail) A light-weight process isolation tool, making use of Linux namespaces and seccomp-bpf syscall filters (with help of the kafel bpf language) -- [**1402**Star][5m] [gitguardian/apisecuritybestpractices](https://github.com/gitguardian/apisecuritybestpractices) Resources to help you keep secrets (API keys, database credentials, certificates, ...) out of source code and remediate the issue in case of a leaked API key. Made available by GitGuardian. -- [**1402**Star][7d] [C++] [eteran/edb-debugger](https://github.com/eteran/edb-debugger) edb is a cross platform AArch32/x86/x86-64 debugger. +- [**1424**Star][8y] [Py] [moxie0/sslstrip](https://github.com/moxie0/sslstrip) A tool for exploiting Moxie Marlinspike's SSL "stripping" attack. +- [**1424**Star][11m] [Java] [aslody/legend](https://github.com/aslody/legend) A framework for hook java methods. +- [**1423**Star][14d] [Go] [google/google-ctf](https://github.com/google/google-ctf) Google CTF +- [**1422**Star][3y] [Py] [nathanlopez/stitch](https://github.com/nathanlopez/stitch) Python Remote Administration Tool (RAT) +- [**1422**Star][3y] [mandatoryprogrammer/northkoreadnsleak](https://github.com/mandatoryprogrammer/northkoreadnsleak) Snapshot of North Korea's DNS data taken from zone transfers. +- [**1419**Star][1m] [Py] [xdavidhu/mitmap](https://github.com/xdavidhu/mitmap) +- [**1419**Star][3y] [C] [antirez/dump1090](https://github.com/antirez/dump1090) Dump1090 is a simple Mode S decoder for RTLSDR devices +- [**1418**Star][5m] [PHP] [s4n7h0/xvwa](https://github.com/s4n7h0/xvwa) XVWA is a badly coded web application written in PHP/MySQL that helps security enthusiasts to learn application security. +- [**1417**Star][4m] [yadox666/the-hackers-hardware-toolkit](https://github.com/yadox666/the-hackers-hardware-toolkit) The best hacker's gadgets for Red Team pentesters and security researchers. +- [**1417**Star][4d] [Rust] [shadowsocks/shadowsocks-rust](https://github.com/shadowsocks/shadowsocks-rust) A Rust port of shadowsocks +- [**1417**Star][1m] [Go] [barnybug/cli53](https://github.com/barnybug/cli53) Command line tool for Amazon Route 53 +- [**1415**Star][7d] [C] [z3apa3a/3proxy](https://github.com/z3apa3a/3proxy) 3proxy - tiny free proxy server +- [**1414**Star][8d] [C] [ettercap/ettercap](https://github.com/ettercap/ettercap) Ettercap Project +- [**1413**Star][24d] [XSLT] [lolbas-project/lolbas](https://github.com/lolbas-project/lolbas) Living Off The Land Binaries And Scripts - (LOLBins and LOLScripts) +- [**1413**Star][24d] [Java] [chrisk44/hijacker](https://github.com/chrisk44/hijacker) Aircrack, Airodump, Aireplay, MDK3 and Reaver GUI Application for Android +- [**1412**Star][9d] [C] [namhyung/uftrace](https://github.com/namhyung/uftrace) Function (graph) tracer for user-space +- [**1412**Star][5m] [gitguardian/apisecuritybestpractices](https://github.com/gitguardian/apisecuritybestpractices) Resources to help you keep secrets (API keys, database credentials, certificates, ...) out of source code and remediate the issue in case of a leaked API key. Made available by GitGuardian. +- [**1411**Star][7d] [C++] [eteran/edb-debugger](https://github.com/eteran/edb-debugger) edb is a cross platform AArch32/x86/x86-64 debugger. +- [**1411**Star][3d] [Go] [cosmos72/gomacro](https://github.com/cosmos72/gomacro) Interactive Go interpreter and debugger with REPL, Eval, generics and Lisp-like macros +- [**1410**Star][3m] [Go] [hellogcc/100-gdb-tips](https://github.com/hellogcc/100-gdb-tips) A collection of gdb tips. 100 maybe just mean many here. +- [**1408**Star][3m] [HTML] [owasp/top10](https://github.com/owasp/top10) Official OWASP Top 10 Document Repository +- [**1407**Star][4d] [C++] [google/nsjail](https://github.com/google/nsjail) A light-weight process isolation tool, making use of Linux namespaces and seccomp-bpf syscall filters (with help of the kafel bpf language) +- [**1405**Star][1y] [HTML] [gwuhaolin/blog](https://github.com/gwuhaolin/blog) 浩麟的技术博客 +- [**1405**Star][1y] [C++] [dotnet/llilc](https://github.com/dotnet/llilc) This repo contains LLILC, an LLVM based compiler for .NET Core. It includes a set of cross-platform .NET code generation tools that enables compilation of MSIL byte code to LLVM supported platforms. +- [**1404**Star][7d] [Java] [chinashiyu/gfw.press](https://github.com/chinashiyu/gfw.press) GFW.Press新一代军用级高强度加密抗干扰网络数据高速传输软件 +- [**1403**Star][2d] [Go] [crazy-max/windowsspyblocker](https://github.com/crazy-max/windowsspyblocker) - [**1401**Star][9m] [JS] [anttiviljami/browser-autofill-phishing](https://github.com/anttiviljami/browser-autofill-phishing) A simple demo of phishing by abusing the browser autofill feature -- [**1400**Star][3m] [HTML] [owasp/top10](https://github.com/owasp/top10) Official OWASP Top 10 Document Repository -- [**1400**Star][1y] [C++] [dotnet/llilc](https://github.com/dotnet/llilc) This repo contains LLILC, an LLVM based compiler for .NET Core. It includes a set of cross-platform .NET code generation tools that enables compilation of MSIL byte code to LLVM supported platforms. -- [**1399**Star][25d] [Go] [crazy-max/windowsspyblocker](https://github.com/crazy-max/windowsspyblocker) -- [**1399**Star][7d] [Java] [chinashiyu/gfw.press](https://github.com/chinashiyu/gfw.press) GFW.Press新一代军用级高强度加密抗干扰网络数据高速传输软件 -- [**1397**Star][7d] [Rust] [shadowsocks/shadowsocks-rust](https://github.com/shadowsocks/shadowsocks-rust) A Rust port of shadowsocks -- [**1395**Star][1y] [Go] [filosottile/whosthere](https://github.com/filosottile/whosthere) A ssh server that knows who you are -- [**1393**Star][25d] [C] [quiet/org.quietmodem.quiet](https://github.com/quiet/org.quietmodem.quiet) Quiet for Android - TCP over sound -- [**1393**Star][3y] [PowerShell] [putterpanda/mimikittenz](https://github.com/putterpanda/mimikittenz) A post-exploitation powershell tool for extracting juicy info from memory. -- [**1391**Star][22d] [XSLT] [lolbas-project/lolbas](https://github.com/lolbas-project/lolbas) Living Off The Land Binaries And Scripts - (LOLBins and LOLScripts) -- [**1388**Star][14d] [Swift] [johnno1962/injectioniii](https://github.com/johnno1962/injectioniii) Re-write of Injection for Xcode in (mostly) Swift4 -- [**1387**Star][1y] [HTML] [gwuhaolin/blog](https://github.com/gwuhaolin/blog) 浩麟的技术博客 -- [**1387**Star][2y] [JS] [sqren/fb-sleep-stats](https://github.com/sqren/fb-sleep-stats) Use Facebook to track your friends’ sleeping habits -- [**1386**Star][18d] [C++] [plasma-umass/coz](https://github.com/plasma-umass/coz) Finding Code that Counts with Causal Profiling -- [**1384**Star][4y] [PHP] [johntroony/php-webshells](https://github.com/johntroony/php-webshells) Common php webshells. Do not host the file(s) on your server! -- [**1383**Star][14d] [C++] [jonathansalwan/triton](https://github.com/jonathansalwan/triton) Triton is a Dynamic Binary Analysis (DBA) framework. It provides internal components like a Dynamic Symbolic Execution (DSE) engine, a dynamic taint engine, AST representations of the x86, x86-64 and AArch64 Instructions Set Architecture (ISA), SMT simplification passes, an SMT solver interface and, the last but not least, Python bindings. -- [**1383**Star][8d] [Py] [ekultek/whatwaf](https://github.com/ekultek/whatwaf) Detect and bypass web application firewalls and protection systems -- [**1381**Star][11m] [Py] [eth0izzle/bucket-stream](https://github.com/eth0izzle/bucket-stream) Find interesting Amazon S3 Buckets by watching certificate transparency logs. -- [**1380**Star][2m] [C] [z3apa3a/3proxy](https://github.com/z3apa3a/3proxy) 3proxy - tiny free proxy server -- [**1380**Star][11d] [Shell] [drduh/pwd.sh](https://github.com/drduh/pwd.sh) GPG symmetric password manager -- [**1377**Star][11d] [OCaml] [mirage/mirage](https://github.com/mirage/mirage) MirageOS is a library operating system that constructs unikernels -- [**1376**Star][6m] [Py] [almandin/fuxploider](https://github.com/almandin/fuxploider) File upload vulnerability scanner and exploitation tool. -- [**1375**Star][10m] [JS] [intika/librefox](https://github.com/intika/librefox) Firefox with privacy enhancements +- [**1399**Star][16d] [Swift] [johnno1962/injectioniii](https://github.com/johnno1962/injectioniii) Re-write of Injection for Xcode in (mostly) Swift4 +- [**1397**Star][1y] [Go] [filosottile/whosthere](https://github.com/filosottile/whosthere) A ssh server that knows who you are +- [**1396**Star][3y] [PS] [putterpanda/mimikittenz](https://github.com/putterpanda/mimikittenz) A post-exploitation powershell tool for extracting juicy info from memory. +- [**1395**Star][27d] [C] [quiet/org.quietmodem.quiet](https://github.com/quiet/org.quietmodem.quiet) Quiet for Android - TCP over sound +- [**1393**Star][4d] [atarity/deploy-your-own-saas](https://github.com/atarity/deploy-your-own-saas) List of "only yours" cloud services for everyday needs +- [**1393**Star][9d] [Py] [ekultek/whatwaf](https://github.com/ekultek/whatwaf) Detect and bypass web application firewalls and protection systems +- [**1392**Star][16d] [C++] [jonathansalwan/triton](https://github.com/jonathansalwan/triton) Triton is a Dynamic Binary Analysis (DBA) framework. It provides internal components like a Dynamic Symbolic Execution (DSE) engine, a dynamic taint engine, AST representations of the x86, x86-64 and AArch64 Instructions Set Architecture (ISA), SMT simplification passes, an SMT solver interface and, the last but not least, Python bindings. +- [**1388**Star][4y] [PHP] [johntroony/php-webshells](https://github.com/johntroony/php-webshells) Common php webshells. Do not host the file(s) on your server! +- [**1387**Star][11m] [Py] [eth0izzle/bucket-stream](https://github.com/eth0izzle/bucket-stream) Find interesting Amazon S3 Buckets by watching certificate transparency logs. +- [**1386**Star][2y] [JS] [sqren/fb-sleep-stats](https://github.com/sqren/fb-sleep-stats) Use Facebook to track your friends’ sleeping habits +- [**1384**Star][5d] [JS] [ix64/unlock-music](https://github.com/ix64/unlock-music) Unlock encrypted music file in browser. 在浏览器中解锁加密的音乐文件。 +- [**1381**Star][6m] [Py] [almandin/fuxploider](https://github.com/almandin/fuxploider) File upload vulnerability scanner and exploitation tool. +- [**1380**Star][15d] [C] [dynamorio/drmemory](https://github.com/dynamorio/drmemory) Memory Debugger for Windows, Linux, Mac, and Android +- [**1380**Star][13d] [Shell] [drduh/pwd.sh](https://github.com/drduh/pwd.sh) GPG symmetric password manager +- [**1378**Star][13d] [OCaml] [mirage/mirage](https://github.com/mirage/mirage) MirageOS is a library operating system that constructs unikernels +- [**1378**Star][2d] [JS] [lockfale/osint-framework](https://github.com/lockfale/osint-framework) OSINT Framework +- [**1375**Star][15d] [Go] [unrolled/secure](https://github.com/unrolled/secure) HTTP middleware for Go that facilitates some quick security wins. +- [**1375**Star][11m] [JS] [intika/librefox](https://github.com/intika/librefox) Firefox with privacy enhancements - [**1374**Star][4y] [C++] [valvesoftware/vogl](https://github.com/valvesoftware/vogl) OpenGL capture / playback debugger. -- [**1373**Star][13d] [C] [dynamorio/drmemory](https://github.com/dynamorio/drmemory) Memory Debugger for Windows, Linux, Mac, and Android -- [**1365**Star][9m] [PowerShell] [danielbohannon/invoke-obfuscation](https://github.com/danielbohannon/invoke-obfuscation) PowerShell Obfuscator -- [**1364**Star][5m] [Py] [s0md3v/striker](https://github.com/s0md3v/Striker) Striker is an offensive information and vulnerability scanner. -- [**1363**Star][29d] [C] [zyantific/zydis](https://github.com/zyantific/zydis) Fast and lightweight x86/x86-64 disassembler library -- [**1361**Star][3y] [C++] [aslody/turbodex](https://github.com/aslody/turbodex) fast load dex in memory. -- [**1360**Star][6m] [Py] [vulnerscom/getsploit](https://github.com/vulnerscom/getsploit) Command line utility for searching and downloading exploits -- [**1360**Star][2m] [Py] [fireeye/flare-floss](https://github.com/fireeye/flare-floss) Automatically extract obfuscated strings from malware. +- [**1373**Star][5m] [Py] [s0md3v/striker](https://github.com/s0md3v/Striker) Striker is an offensive information and vulnerability scanner. +- [**1373**Star][9m] [PS] [danielbohannon/invoke-obfuscation](https://github.com/danielbohannon/invoke-obfuscation) PowerShell Obfuscator +- [**1371**Star][1m] [C] [zyantific/zydis](https://github.com/zyantific/zydis) Fast and lightweight x86/x86-64 disassembler library +- [**1365**Star][9d] [Go] [cortesi/modd](https://github.com/cortesi/modd) A flexible developer tool that runs processes and responds to filesystem changes +- [**1363**Star][2m] [Py] [fireeye/flare-floss](https://github.com/fireeye/flare-floss) Automatically extract obfuscated strings from malware. - [floss](https://github.com/fireeye/flare-floss/tree/master/floss) - [IDA插件](https://github.com/fireeye/flare-floss/blob/master/scripts/idaplugin.py) -- [**1358**Star][7d] [Go] [cortesi/modd](https://github.com/cortesi/modd) A flexible developer tool that runs processes and responds to filesystem changes -- [**1357**Star][24d] [JS] [lockfale/osint-framework](https://github.com/lockfale/osint-framework) OSINT Framework -- [**1355**Star][6m] [C++] [phpv8/v8js](https://github.com/phpv8/v8js) V8 Javascript Engine for PHP — This PHP extension embeds the Google V8 Javascript Engine -- [**1355**Star][1m] [grrrdog/java-deserialization-cheat-sheet](https://github.com/grrrdog/java-deserialization-cheat-sheet) The cheat sheet about Java Deserialization vulnerabilities -- [**1355**Star][2m] [C] [googleprojectzero/winafl](https://github.com/googleprojectzero/winafl) A fork of AFL for fuzzing Windows binaries -- [**1348**Star][23d] [C] [x64dbg/x64dbgpy](https://github.com/x64dbg/x64dbgpy) Automating x64dbg using Python, Snapshots: -- [**1348**Star][4m] [C] [taviso/ctftool](https://github.com/taviso/ctftool) Interactive CTF Exploration Tool -- [**1348**Star][3y] [Py] [joaomatosf/jexboss](https://github.com/joaomatosf/jexboss) Jboss (and Java Deserialization Vulnerabilities) verify and EXploitation Tool -- [**1347**Star][13d] [Go] [unrolled/secure](https://github.com/unrolled/secure) HTTP middleware for Go that facilitates some quick security wins. -- [**1347**Star][3m] [C++] [raspberrypi/tools](https://github.com/raspberrypi/tools) +- [**1363**Star][3y] [C++] [aslody/turbodex](https://github.com/aslody/turbodex) fast load dex in memory. +- [**1362**Star][1m] [grrrdog/java-deserialization-cheat-sheet](https://github.com/grrrdog/java-deserialization-cheat-sheet) The cheat sheet about Java Deserialization vulnerabilities +- [**1361**Star][7m] [Py] [vulnerscom/getsploit](https://github.com/vulnerscom/getsploit) Command line utility for searching and downloading exploits +- [**1361**Star][6m] [C++] [phpv8/v8js](https://github.com/phpv8/v8js) V8 Javascript Engine for PHP — This PHP extension embeds the Google V8 Javascript Engine +- [**1359**Star][2m] [C] [googleprojectzero/winafl](https://github.com/googleprojectzero/winafl) A fork of AFL for fuzzing Windows binaries +- [**1355**Star][10m] [HTML] [thelinuxchoice/blackeye](https://github.com/thelinuxchoice/blackeye) The most complete Phishing Tool, with 32 templates +1 customizable +- [**1354**Star][2d] [Py] [mitre/caldera](https://github.com/mitre/caldera) Automated Adversary Emulation +- [**1352**Star][3y] [Py] [joaomatosf/jexboss](https://github.com/joaomatosf/jexboss) Jboss (and Java Deserialization Vulnerabilities) verify and EXploitation Tool +- [**1351**Star][3m] [C++] [raspberrypi/tools](https://github.com/raspberrypi/tools) +- [**1350**Star][4m] [C] [taviso/ctftool](https://github.com/taviso/ctftool) Interactive CTF Exploration Tool +- [**1349**Star][3y] [Py] [ddevault/evilpass](https://github.com/ddevault/evilpass) Slightly evil password strength checker +- [**1349**Star][19d] [C++] [rikkaapps/riru](https://github.com/rikkaapps/riru) Inject zygote process by replace libmemtrack +- [**1349**Star][5m] [Py] [lijiejie/githack](https://github.com/lijiejie/githack) A `.git` folder disclosure exploit +- [**1348**Star][10m] [rebeyond/behinder](https://github.com/rebeyond/behinder) “冰蝎”动态二进制加密网站管理客户端 - [**1347**Star][11m] [Rust] [das-labor/panopticon](https://github.com/das-labor/panopticon) A libre cross-platform disassembler. -- [**1346**Star][3y] [Py] [ddevault/evilpass](https://github.com/ddevault/evilpass) Slightly evil password strength checker - [**1346**Star][2y] [HTML] [daxeel/blockshell](https://github.com/daxeel/blockshell) A command line utility for learning Blockchain technical concepts likechaining, mining, proof of work etc. -- [**1344**Star][10m] [HTML] [thelinuxchoice/blackeye](https://github.com/thelinuxchoice/blackeye) The most complete Phishing Tool, with 32 templates +1 customizable -- [**1343**Star][5m] [Py] [lijiejie/githack](https://github.com/lijiejie/githack) A `.git` folder disclosure exploit -- [**1343**Star][3m] [Go] [hellogcc/100-gdb-tips](https://github.com/hellogcc/100-gdb-tips) A collection of gdb tips. 100 maybe just mean many here. -- [**1342**Star][7d] [Py] [mitre/caldera](https://github.com/mitre/caldera) Automated Adversary Emulation -- [**1341**Star][10d] [Go] [securitywithoutborders/hardentools](https://github.com/securitywithoutborders/hardentools) Hardentools is a utility that disables a number of risky Windows features. -- [**1341**Star][2m] [Go] [davrodpin/mole](https://github.com/davrodpin/mole) cli app to create ssh tunnels -- [**1339**Star][21d] [Py] [s0md3v/arjun](https://github.com/s0md3v/Arjun) HTTP parameter discovery suite. -- [**1339**Star][12m] [XSLT] [api0cradle/lolbas](https://github.com/api0cradle/lolbas) Living Off The Land Binaries And Scripts - (LOLBins and LOLScripts) -- [**1338**Star][21d] [Go] [microcosm-cc/bluemonday](https://github.com/microcosm-cc/bluemonday) a fast golang HTML sanitizer (inspired by the OWASP Java HTML Sanitizer) to scrub user generated content of XSS -- [**1338**Star][7m] [Py] [feeicn/gsil](https://github.com/feeicn/gsil) GitHub Sensitive Information Leakage -- [**1337**Star][1y] [Py] [carmaa/inception](https://github.com/carmaa/inception) a physical memory manipulation and hacking tool exploiting PCI-based DMA. The tool can attack over FireWire, Thunderbolt, ExpressCard, PC Card and any other PCI/PCIe interfaces. -- [**1336**Star][6y] [Perl] [intelisecurelabs/linux_exploit_suggester](https://github.com/InteliSecureLabs/Linux_Exploit_Suggester) Linux Exploit Suggester; based on operating system release number -- [**1336**Star][3m] [Py] [maratyszcza/peachpy](https://github.com/maratyszcza/peachpy) x86-64 assembler embedded in Python -- [**1333**Star][17d] [C++] [rikkaapps/riru](https://github.com/rikkaapps/riru) Inject zygote process by replace libmemtrack -- [**1331**Star][2m] [C++] [mfontanini/libtins](https://github.com/mfontanini/libtins) High-level, multiplatform C++ network packet sniffing and crafting library. -- [**1331**Star][1y] [C] [gamelinux/passivedns](https://github.com/gamelinux/passivedns) A network sniffer that logs all DNS server replies for use in a passive DNS setup -- [**1329**Star][1m] [CSS] [undeadsec/socialfish](https://github.com/undeadsec/socialfish) Educational Phishing Tool & Information Collector -- [**1329**Star][10m] [rebeyond/behinder](https://github.com/rebeyond/behinder) “冰蝎”动态二进制加密网站管理客户端 -- [**1329**Star][1y] [kirikira/vtemplate](https://github.com/kirikira/vtemplate) v2ray的模板们 -- [**1328**Star][1y] [C] [madeye/proxydroid](https://github.com/madeye/proxydroid) Global Proxy for Android -- [**1326**Star][11d] [C++] [purplei2p/i2pd](https://github.com/purplei2p/i2pd) a full-featured C++ implementation of I2P client -- [**1324**Star][2y] [CoffeeScript] [atmos/camo](https://github.com/atmos/camo) all about making insecure assets look secure -- [**1323**Star][1y] [Py] [marten4n6/evilosx](https://github.com/marten4n6/evilosx) An evil RAT (Remote Administration Tool) for macOS / OS X. -- [**1322**Star][3m] [HTML] [thehive-project/thehive](https://github.com/thehive-project/thehive) a Scalable, Open Source and Free Security Incident Response Platform -- [**1321**Star][6m] [Go] [ssllabs/ssllabs-scan](https://github.com/ssllabs/ssllabs-scan) A command-line reference-implementation client for SSL Labs APIs, designed for automated and/or bulk testing. -- [**1321**Star][1y] [C++] [rehints/hexrayscodexplorer](https://github.com/rehints/hexrayscodexplorer) Hex-Rays Decompiler plugin for better code navigation +- [**1345**Star][25d] [C] [x64dbg/x64dbgpy](https://github.com/x64dbg/x64dbgpy) Automating x64dbg using Python, Snapshots: +- [**1345**Star][12d] [Go] [securitywithoutborders/hardentools](https://github.com/securitywithoutborders/hardentools) Hardentools is a utility that disables a number of risky Windows features. +- [**1344**Star][23d] [Go] [microcosm-cc/bluemonday](https://github.com/microcosm-cc/bluemonday) a fast golang HTML sanitizer (inspired by the OWASP Java HTML Sanitizer) to scrub user generated content of XSS +- [**1343**Star][23d] [Py] [s0md3v/arjun](https://github.com/s0md3v/Arjun) HTTP parameter discovery suite. +- [**1342**Star][12m] [C] [luke-jr/bfgminer](https://github.com/luke-jr/bfgminer) Modular ASIC/FPGA miner written in C, featuring overclocking, monitoring, fan speed control and remote interface capabilities. +- [**1342**Star][2m] [Go] [davrodpin/mole](https://github.com/davrodpin/mole) cli app to create ssh tunnels +- [**1342**Star][1y] [Py] [carmaa/inception](https://github.com/carmaa/inception) a physical memory manipulation and hacking tool exploiting PCI-based DMA. The tool can attack over FireWire, Thunderbolt, ExpressCard, PC Card and any other PCI/PCIe interfaces. +- [**1341**Star][3m] [Py] [maratyszcza/peachpy](https://github.com/maratyszcza/peachpy) x86-64 assembler embedded in Python +- [**1341**Star][1y] [XSLT] [api0cradle/lolbas](https://github.com/api0cradle/lolbas) Living Off The Land Binaries And Scripts - (LOLBins and LOLScripts) +- [**1340**Star][1y] [kirikira/vtemplate](https://github.com/kirikira/vtemplate) v2ray的模板们 +- [**1340**Star][7m] [Py] [feeicn/gsil](https://github.com/feeicn/gsil) GitHub Sensitive Information Leakage +- [**1339**Star][6y] [Perl] [intelisecurelabs/linux_exploit_suggester](https://github.com/InteliSecureLabs/Linux_Exploit_Suggester) Linux Exploit Suggester; based on operating system release number +- [**1338**Star][1m] [CSS] [undeadsec/socialfish](https://github.com/undeadsec/socialfish) Educational Phishing Tool & Information Collector +- [**1337**Star][1y] [C] [madeye/proxydroid](https://github.com/madeye/proxydroid) Global Proxy for Android +- [**1336**Star][3m] [HTML] [thehive-project/thehive](https://github.com/thehive-project/thehive) a Scalable, Open Source and Free Security Incident Response Platform +- [**1335**Star][2m] [C++] [mfontanini/libtins](https://github.com/mfontanini/libtins) High-level, multiplatform C++ network packet sniffing and crafting library. +- [**1334**Star][4y] [mengskysama/shadowsocks](https://github.com/mengskysama/shadowsocks) A fast tunnel proxy that helps you bypass firewalls +- [**1333**Star][1y] [C] [gamelinux/passivedns](https://github.com/gamelinux/passivedns) A network sniffer that logs all DNS server replies for use in a passive DNS setup +- [**1328**Star][2d] [C++] [purplei2p/i2pd](https://github.com/purplei2p/i2pd) a full-featured C++ implementation of I2P client +- [**1328**Star][1y] [Py] [marten4n6/evilosx](https://github.com/marten4n6/evilosx) An evil RAT (Remote Administration Tool) for macOS / OS X. +- [**1328**Star][2y] [CoffeeScript] [atmos/camo](https://github.com/atmos/camo) all about making insecure assets look secure +- [**1327**Star][7m] [Go] [ssllabs/ssllabs-scan](https://github.com/ssllabs/ssllabs-scan) A command-line reference-implementation client for SSL Labs APIs, designed for automated and/or bulk testing. +- [**1327**Star][3d] [C] [intel/haxm](https://github.com/intel/haxm) cross-platform hardware-assisted virtualization engine (hypervisor), widely used as an accelerator for Android Emulator and QEMU +- [**1327**Star][10m] [C#] [cenmrev/v2rayw](https://github.com/cenmrev/v2rayw) GUI for v2ray-core on Windows +- [**1325**Star][21d] [C] [dtag-dev-sec/tpotce](https://github.com/dtag-dev-sec/tpotce) 创建多蜜罐平台T-Pot ISO 镜像 +- [**1324**Star][1y] [C++] [rehints/hexrayscodexplorer](https://github.com/rehints/hexrayscodexplorer) Hex-Rays Decompiler plugin for better code navigation
View Details @@ -932,97 +1003,26 @@
-- [**1318**Star][2m] [jaredthecoder/awesome-vehicle-security](https://github.com/jaredthecoder/awesome-vehicle-security) -- [**1315**Star][1y] [mortenoir1/virtualbox_e1000_0day](https://github.com/mortenoir1/virtualbox_e1000_0day) VirtualBox E1000 Guest-to-Host Escape -- [**1312**Star][12d] [C] [oisf/suricata](https://github.com/OISF/suricata) a network IDS, IPS and NSM engine -- [**1311**Star][2y] [Py] [worawit/ms17-010](https://github.com/worawit/ms17-010) MS17-010 -- [**1311**Star][18d] [C] [intel/haxm](https://github.com/intel/haxm) cross-platform hardware-assisted virtualization engine (hypervisor), widely used as an accelerator for Android Emulator and QEMU -- [**1310**Star][3m] [PowerShell] [peewpw/invoke-psimage](https://github.com/peewpw/invoke-psimage) Encodes a PowerShell script in the pixels of a PNG file and generates a oneliner to execute -- [**1310**Star][10m] [C] [fancycode/memorymodule](https://github.com/fancycode/memorymodule) Library to load a DLL from memory. -- [**1309**Star][10m] [C#] [cenmrev/v2rayw](https://github.com/cenmrev/v2rayw) GUI for v2ray-core on Windows -- [**1305**Star][12m] [Py] [xyntax/poc-t](https://github.com/xyntax/poc-t) remote vulnerability PoC/EXP framework -- [**1305**Star][3m] [Lua] [scipag/vulscan](https://github.com/scipag/vulscan) Advanced vulnerability scanning with Nmap NSE -- [**1305**Star][18d] [C] [dtag-dev-sec/tpotce](https://github.com/dtag-dev-sec/tpotce) 创建多蜜罐平台T-Pot ISO 镜像 -- [**1303**Star][17d] [Py] [consensys/mythril](https://github.com/ConsenSys/mythril) Security analysis tool for EVM bytecode. Supports smart contracts built for Ethereum, Quorum, Vechain, Roostock, Tron and other EVM-compatible blockchains. -- [**1303**Star][15d] [nikitavoloboev/privacy-respecting](https://github.com/nikitavoloboev/privacy-respecting) Curated List of Privacy Respecting Services and Software +- [**1323**Star][2d] [Go] [xiaoming2028/freenet](https://github.com/xiaoming2028/freenet) 科学上网/梯子/自由上网/翻墙 SS/SSR/V2Ray/Brook 搭建教程 +- [**1323**Star][2m] [jaredthecoder/awesome-vehicle-security](https://github.com/jaredthecoder/awesome-vehicle-security) +- [**1322**Star][3d] [C] [oisf/suricata](https://github.com/OISF/suricata) a network IDS, IPS and NSM engine +- [**1319**Star][2y] [Py] [worawit/ms17-010](https://github.com/worawit/ms17-010) MS17-010 +- [**1317**Star][1y] [mortenoir1/virtualbox_e1000_0day](https://github.com/mortenoir1/virtualbox_e1000_0day) VirtualBox E1000 Guest-to-Host Escape +- [**1316**Star][3m] [PS] [peewpw/invoke-psimage](https://github.com/peewpw/invoke-psimage) Encodes a PowerShell script in the pixels of a PNG file and generates a oneliner to execute +- [**1314**Star][10m] [C] [fancycode/memorymodule](https://github.com/fancycode/memorymodule) Library to load a DLL from memory. +- [**1311**Star][1m] [C++] [shadowsocks/libqtshadowsocks](https://github.com/shadowsocks/libqtshadowsocks) A lightweight and ultra-fast shadowsocks library written in C++14 with Qt framework +- [**1309**Star][12m] [Py] [xyntax/poc-t](https://github.com/xyntax/poc-t) remote vulnerability PoC/EXP framework +- [**1309**Star][3m] [Lua] [scipag/vulscan](https://github.com/scipag/vulscan) Advanced vulnerability scanning with Nmap NSE +- [**1307**Star][19d] [Py] [consensys/mythril](https://github.com/ConsenSys/mythril) Security analysis tool for EVM bytecode. Supports smart contracts built for Ethereum, Quorum, Vechain, Roostock, Tron and other EVM-compatible blockchains. +- [**1307**Star][27d] [C] [boywhp/fcn](https://github.com/boywhp/fcn) free connect your private network from anywhere +- [**1304**Star][17d] [nikitavoloboev/privacy-respecting](https://github.com/nikitavoloboev/privacy-respecting) Curated List of Privacy Respecting Services and Software +- [**1304**Star][7d] [C] [cisco-talos/pyrebox](https://github.com/cisco-talos/pyrebox) Python scriptable Reverse Engineering Sandbox, a Virtual Machine instrumentation and inspection framework based on QEMU - [**1303**Star][4m] [C++] [klee/klee](https://github.com/klee/klee) KLEE Symbolic Execution Engine -- [**1300**Star][18d] [C] [cisco-talos/pyrebox](https://github.com/cisco-talos/pyrebox) Python scriptable Reverse Engineering Sandbox, a Virtual Machine instrumentation and inspection framework based on QEMU -- [**1297**Star][1y] [Go] [evilsocket/xray](https://github.com/evilsocket/xray) XRay is a tool for recon, mapping and OSINT gathering from public networks. -- [**1293**Star][1y] [Shell] [dana-at-cp/backdoor-apk](https://github.com/dana-at-cp/backdoor-apk) backdoor-apk is a shell script that simplifies the process of adding a backdoor to any Android APK file. Users of this shell script should have working knowledge of Linux, Bash, Metasploit, Apktool, the Android SDK, smali, etc. This shell script is provided as-is without warranty of any kind and is intended for educational purposes only. -- [**1291**Star][27d] [Java] [android-hacker/exposed](https://github.com/android-hacker/exposed) A library to use Xposed without root or recovery(or modify system image etc..). -- [**1290**Star][2y] [Go] [malfunkt/hyperfox](https://github.com/malfunkt/hyperfox) HTTP/HTTPs MITM proxy and traffic recorder with on-the-fly TLS cert generation. -- [**1289**Star][2m] [C] [traviscross/mtr](https://github.com/traviscross/mtr) Official repository for mtr, a network diagnostic tool -- [**1288**Star][4y] [C++] [microsoft/microsoft-pdb](https://github.com/microsoft/microsoft-pdb) Information from Microsoft about the PDB format. We'll try to keep this up to date. Just trying to help the CLANG/LLVM community get onto Windows. -- [**1287**Star][19d] [JS] [icymind/vrouter](https://github.com/icymind/vrouter) 一个基于 VirtualBox 和 openwrt 构建的项目, 旨在实现 macOS / Windows 平台的透明代理. -- [**1284**Star][2m] [Py] [virtualabs/btlejack](https://github.com/virtualabs/btlejack) Bluetooth Low Energy Swiss-army knife -- [**1284**Star][5m] [JS] [feross/spoof](https://github.com/feross/spoof) Easily spoof your MAC address in macOS, Windows, & Linux! -- [**1278**Star][9m] [michalmalik/linux-re-101](https://github.com/michalmalik/linux-re-101) A collection of resources for linux reverse engineering -- [**1278**Star][4y] [Py] [elvanderb/tcp-32764](https://github.com/elvanderb/tcp-32764) some codes and notes about the backdoor listening on TCP-32764 in linksys WAG200G. -- [**1277**Star][10d] [PHP] [friendsofphp/security-advisories](https://github.com/friendsofphp/security-advisories) A database of PHP security advisories -- [**1277**Star][27d] [Go] [dreadl0ck/netcap](https://github.com/dreadl0ck/netcap) A framework for secure and scalable network traffic analysis - -- [**1275**Star][24d] [Py] [viper-framework/viper](https://github.com/viper-framework/viper) Binary analysis and management framework -- [**1273**Star][1m] [Py] [pyauth/pyotp](https://github.com/pyauth/pyotp) Python One-Time Password Library -- [**1273**Star][2m] [Py] [codingo/reconnoitre](https://github.com/codingo/reconnoitre) A security tool for multithreaded information gathering and service enumeration whilst building directory structures to store results, along with writing out recommendations for further testing. -- [**1272**Star][1y] [JS] [sakurity/securelogin](https://github.com/sakurity/securelogin) a decentralized authentication protocol for websites and apps -- [**1270**Star][2m] [C] [seemoo-lab/nexmon](https://github.com/seemoo-lab/nexmon) The C-based Firmware Patching Framework for Broadcom/Cypress WiFi Chips that enables Monitor Mode, Frame Injection and much more -- [**1270**Star][1y] [PowerShell] [dafthack/mailsniper](https://github.com/dafthack/mailsniper) a penetration testing tool for searching through email in a Microsoft Exchange environment for specific terms (passwords, insider intel, network architecture information, etc.). It can be used as a non-administrative user to search their own email, or by an administrator to search the mailboxes of every user in a domain. -- [**1270**Star][1m] [Py] [bethgelab/foolbox](https://github.com/bethgelab/foolbox) Python toolbox to create adversarial examples that fool neural networks in PyTorch, TensorFlow, Keras, … -- [**1268**Star][2m] [Java] [googlearchive/android-runtimepermissions](https://github.com/googlearchive/android-RuntimePermissions) This sample has been deprecated/archived. Check this repo for related samples: -- [**1268**Star][1y] [Py] [ethereum/pyethapp](https://github.com/ethereum/pyethapp) -- [**1266**Star][2m] [Py] [ganapati/rsactftool](https://github.com/ganapati/rsactftool) RSA attack tool (mainly for ctf) - retreive private key from weak public key and/or uncipher data -- [**1265**Star][9d] [Shell] [firehol/blocklist-ipsets](https://github.com/firehol/blocklist-ipsets) ipsets dynamically updated with firehol's update-ipsets.sh script -- [**1265**Star][9d] [Shell] [firehol/blocklist-ipsets](https://github.com/firehol/blocklist-ipsets) ipsets dynamically updated with firehol's update-ipsets.sh script -- [**1262**Star][3m] [Go] [solo-io/squash](https://github.com/solo-io/squash) The debugger for microservices -- [**1261**Star][3m] [Py] [alessandroz/beroot](https://github.com/alessandroz/beroot) Privilege Escalation Project - Windows / Linux / Mac -- [**1259**Star][11m] [Py] [unapibageek/ctfr](https://github.com/unapibageek/ctfr) Abusing Certificate Transparency logs for getting HTTPS websites subdomains. -- [**1255**Star][7m] [PHP] [ganlvtech/down_52pojie_cn](https://github.com/ganlvtech/down_52pojie_cn) A single page file explorer that can be hosted on static website. 吾爱破解论坛 爱盘 -- [**1255**Star][13d] [C] [aircrack-ng/aircrack-ng](https://github.com/aircrack-ng/aircrack-ng) WiFi security auditing tools suite -- [**1253**Star][2y] [JS] [samyk/skyjack](https://github.com/samyk/skyjack) A drone engineered to autonomously seek out, hack, and wirelessly take full control over any other Parrot or 3DR drones within wireless or flying distance, creating an army of zombie drones under your control. -- [**1250**Star][1m] [PowerShell] [hak5/bashbunny-payloads](https://github.com/hak5/bashbunny-payloads) The Official Bash Bunny Payload Repository -- [**1248**Star][2y] [Py] [vaguileradiaz/tinfoleak](https://github.com/vaguileradiaz/tinfoleak) The most complete open-source tool for Twitter intelligence analysis -- [**1248**Star][4m] [JS] [bubenshchykov/ngrok](https://github.com/bubenshchykov/ngrok) Expose your localhost to the web. Node wrapper for ngrok. -- [**1245**Star][2m] [Go] [xiaoming2028/freenet](https://github.com/xiaoming2028/freenet) 科学上网/梯子/自由上网/翻墙 SSR/V2Ray/Brook 最全搭建教程 -- [**1245**Star][15d] [JS] [archerysec/archerysec](https://github.com/archerysec/archerysec) Centralize Vulnerability Assessment and Management for DevSecOps Team -- [**1244**Star][2y] [Objective-C] [krausefx/detect.location](https://github.com/krausefx/detect.location) An easy way to access the user's iOS location data without actually having access -- [**1242**Star][4y] [firesuncn/bluelotus_xssreceiver](https://github.com/firesuncn/bluelotus_xssreceiver) XSS平台 CTF工具 Web安全工具 -- [**1242**Star][1m] [Vue] [chaitin/passionfruit](https://github.com/chaitin/passionfruit) [WIP] Crappy iOS app analyzer -- [**1241**Star][1y] [Ruby] [eliotsykes/rails-security-checklist](https://github.com/eliotsykes/rails-security-checklist) -- [**1240**Star][10m] [C] [a0rtega/pafish](https://github.com/a0rtega/pafish) Pafish is a demonstration tool that employs several techniques to detect sandboxes and analysis environments in the same way as malware families do. -- [**1239**Star][2m] [michalmalik/osx-re-101](https://github.com/michalmalik/osx-re-101) A collection of resources for OSX/iOS reverse engineering. -- [**1235**Star][1m] [Go] [hacklcx/hfish](https://github.com/hacklcx/hfish) Extend the enterprise security test open source honeypot system , Record hacker attacks. 扩展企业安全测试主动诱导型开源蜜罐框架系统,记录黑客攻击手段 -- [**1235**Star][2m] [Go] [google/martian](https://github.com/google/martian) Martian is a library for building custom HTTP/S proxies -- [**1232**Star][3m] [Shell] [rootsongjc/kubernetes-vagrant-centos-cluster](https://github.com/rootsongjc/kubernetes-vagrant-centos-cluster) Setting up a distributed Kubernetes cluster along with Istio service mesh locally with Vagrant and VirtualBox, only PoC or Demo use. -- [**1231**Star][3y] [Py] [desaster/kippo](https://github.com/desaster/kippo) Kippo - SSH Honeypot -- [**1230**Star][7d] [Shell] [mitchellkrogza/nginx-ultimate-bad-bot-blocker](https://github.com/mitchellkrogza/nginx-ultimate-bad-bot-blocker) Nginx Block Bad Bots, Spam Referrer Blocker, Vulnerability Scanners, User-Agents, Malware, Adware, Ransomware, Malicious Sites, with anti-DDOS, Wordpress Theme Detector Blocking and Fail2Ban Jail for Repeat Offenders -- [**1230**Star][5m] [chalker/notes](https://github.com/chalker/notes) Some public notes -- [**1228**Star][1y] [Kotlin] [gh0u1l5/wechatspellbook](https://github.com/gh0u1l5/wechatspellbook) 使用Kotlin编写的开源微信插件框架,底层需要 Xposed 或 VirtualXposed 等Hooking框架的支持,而顶层可以轻松对接Java、Kotlin、Scala等JVM系语言。让程序员能够在几分钟内编写出简单的微信插件,随意揉捏微信的内部逻辑。 -- [**1228**Star][8m] [Py] [flipkart-incubator/astra](https://github.com/flipkart-incubator/astra) Automated Security Testing For REST API's -- [**1224**Star][1m] [C] [datatheorem/trustkit](https://github.com/datatheorem/trustkit) Easy SSL pinning validation and reporting for iOS, macOS, tvOS and watchOS. -- [**1223**Star][3y] [CoffeeScript] [shadowsocks/shadowsocks-nodejs](https://github.com/shadowsocks/shadowsocks-nodejs) -- [**1222**Star][3y] [C] [tsudakageyu/minhook](https://github.com/tsudakageyu/minhook) The Minimalistic x86/x64 API Hooking Library for Windows -- [**1222**Star][27d] [C++] [nasa-sw-vnv/ikos](https://github.com/nasa-sw-vnv/ikos) Static analyzer for C/C++ based on the theory of Abstract Interpretation. -- [**1222**Star][1y] [Py] [danmcinerney/net-creds](https://github.com/danmcinerney/net-creds) Sniffs sensitive data from interface or pcap -- [**1220**Star][1y] [Go] [cloudflare/redoctober](https://github.com/cloudflare/redoctober) Go server for two-man rule style file encryption and decryption. -- [**1219**Star][5y] [cure53/xsschallengewiki](https://github.com/cure53/XSSChallengeWiki) Welcome to the XSS Challenge Wiki! -- [**1219**Star][4m] [Py] [owtf/owtf](https://github.com/owtf/owtf) a framework which tries to unite great tools and make pen testing more efficient -- [**1218**Star][11d] [Py] [google/timesketch](https://github.com/google/timesketch) Collaborative forensic timeline analysis -- [**1218**Star][26d] [Java] [find-sec-bugs/find-sec-bugs](https://github.com/find-sec-bugs/find-sec-bugs) The SpotBugs plugin for security audits of Java web applications and Android applications. (Also work with Kotlin, Groovy and Scala projects) -- [**1218**Star][5y] [cure53/xsschallengewiki](https://github.com/cure53/xsschallengewiki) Welcome to the XSS Challenge Wiki! -- [**1217**Star][1y] [C#] [cn33liz/p0wnedshell](https://github.com/cn33liz/p0wnedshell) PowerShell Runspace Post Exploitation Toolkit -- [**1216**Star][26d] [Go] [jsha/minica](https://github.com/jsha/minica) minica is a small, simple CA intended for use in situations where the CA operator also operates each host where a certificate will be used. -- [**1212**Star][10d] [C] [dynamorio/dynamorio](https://github.com/dynamorio/dynamorio) Dynamic Instrumentation Tool Platform -- [**1207**Star][8d] [JS] [jpcertcc/logontracer](https://github.com/jpcertcc/logontracer) Investigate malicious Windows logon by visualizing and analyzing Windows event log -- [**1205**Star][3m] [Java] [javiersantos/piracychecker](https://github.com/javiersantos/piracychecker) An Android library that prevents your app from being pirated / cracked using Google Play Licensing (LVL), APK signature protection and more. API 14+ required. -- [**1204**Star][7d] [Objective-C] [onionbrowser/onionbrowser](https://github.com/onionbrowser/onionbrowser) An open-source, privacy-enhancing web browser for iOS, utilizing the Tor anonymity network -- [**1204**Star][3m] [JS] [davidbau/seedrandom](https://github.com/davidbau/seedrandom) seeded random number generator for Javascript -- [**1203**Star][30d] [Py] [codingo/nosqlmap](https://github.com/codingo/NoSQLMap) Automated NoSQL database enumeration and web application exploitation tool. -- [**1201**Star][7d] [Java] [linkedin/dexmaker](https://github.com/linkedin/dexmaker) A utility for doing compile or runtime code generation targeting Android's Dalvik VM -- [**1200**Star][3m] [C] [droe/sslsplit](https://github.com/droe/sslsplit) Transparent SSL/TLS interception -- [**1199**Star][1y] [felixgr/secure-ios-app-dev](https://github.com/felixgr/secure-ios-app-dev) Collection of the most common vulnerabilities found in iOS applications -- [**1198**Star][24d] [Py] [thekingofduck/fuzzdicts](https://github.com/thekingofduck/fuzzdicts) Web Pentesting Fuzz 字典,一个就够了。 -- [**1196**Star][1y] [Go] [rancher/convoy](https://github.com/rancher/convoy) A Docker volume plugin, managing persistent container volumes. -- [**1194**Star][2y] [C] [saminiir/level-ip](https://github.com/saminiir/level-ip) a Linux userspace TCP/IP stack, implemented with TUN/TAP devices. -- [**1194**Star][7m] [riusksk/secbook](https://github.com/riusksk/secbook) 信息安全从业者书单推荐 -- [**1193**Star][18d] [Py] [cve-search/cve-search](https://github.com/cve-search/cve-search) perform local searches for known vulnerabilities -- [**1192**Star][17d] [YARA] [horsicq/detect-it-easy](https://github.com/horsicq/detect-it-easy) Program for determining types of files for Windows, Linux and MacOS. -- [**1191**Star][6y] [gdbinit/gdbinit](https://github.com/gdbinit/gdbinit) Gdbinit for OS X, iOS and others - x86, x86_64 and ARM \ No newline at end of file +- [**1300**Star][1y] [Shell] [dana-at-cp/backdoor-apk](https://github.com/dana-at-cp/backdoor-apk) backdoor-apk is a shell script that simplifies the process of adding a backdoor to any Android APK file. Users of this shell script should have working knowledge of Linux, Bash, Metasploit, Apktool, the Android SDK, smali, etc. This shell script is provided as-is without warranty of any kind and is intended for educational purposes only. +- [**1299**Star][6d] [Go] [hacklcx/hfish](https://github.com/hacklcx/hfish) Extend the enterprise security test open source honeypot system , Record hacker attacks. 扩展企业安全测试主动诱导型开源蜜罐框架系统,记录黑客攻击手段 +- [**1298**Star][1y] [Go] [evilsocket/xray](https://github.com/evilsocket/xray) XRay is a tool for recon, mapping and OSINT gathering from public networks. +- [**1293**Star][4y] [C++] [microsoft/microsoft-pdb](https://github.com/microsoft/microsoft-pdb) Information from Microsoft about the PDB format. We'll try to keep this up to date. Just trying to help the CLANG/LLVM community get onto Windows. +- [**1293**Star][5m] [JS] [feross/spoof](https://github.com/feross/spoof) Easily spoof your MAC address in macOS, Windows, & Linux! +- [**1293**Star][29d] [Java] [android-hacker/exposed](https://github.com/android-hacker/exposed) A library to use Xposed without root or recovery(or modify system image etc..). +- [**1291**Star][6d] [C] [traviscross/mtr](https://github.com/traviscross/mtr) Official repository for mtr, a network diagnostic tool +- [**1291**Star][2y] [Go] [malfunkt/hyperfox](https://github.com/malfunkt/hyperfox) HTTP/HTTPs MITM proxy and traffic recorder with on-the-fly TLS cert generation. \ No newline at end of file diff --git a/Readme_full.md b/Readme_full.md index c23bd1e..68eaced 100644 --- a/Readme_full.md +++ b/Readme_full.md @@ -2,926 +2,996 @@ - [英文版本](https://github.com/alphaSeclab/sec-tool-list/blob/master/Readme_en.md) - 因Github Readme显示行数有限, 当前页面显示的为不完整版, 只显示了星数最高的前1000个工具. [点击查看完整版](https://github.com/alphaSeclab/sec-tool-list/blob/master/Readme_full.md) - # 工具列表 -- [**34521**星][14d] [C++] [x64dbg/x64dbg](https://github.com/x64dbg/x64dbg) Windows平台x32/x64调试器 -- [**33781**星][8d] [Py] [minimaxir/big-list-of-naughty-strings](https://github.com/minimaxir/big-list-of-naughty-strings) “淘气”的字符串列表,当作为用户输入时很容易引发问题 -- [**32724**星][2m] [hack-with-github/awesome-hacking](https://github.com/hack-with-github/awesome-hacking) A collection of various awesome lists for hackers, pentesters and security researchers -- [**30396**星][12d] [Go] [fatedier/frp](https://github.com/fatedier/frp) 快速的反向代理, 将NAT或防火墙之后的本地服务器暴露到公网 -- [**25942**星][7d] [Py] [certbot/certbot](https://github.com/certbot/certbot) Certbot is EFF's tool to obtain certs from Let's Encrypt and (optionally) auto-enable HTTPS on your server. It can also act as a client for any other CA that uses the ACME protocol. -- [**25522**星][26d] [Swift] [shadowsocks/shadowsocksx-ng](https://github.com/shadowsocks/shadowsocksx-ng) Next Generation of ShadowsocksX -- [**25087**星][13d] [Go] [v2ray/v2ray-core](https://github.com/v2ray/v2ray-core) A platform for building proxies to bypass network restrictions. -- [**24589**星][7d] [trimstray/the-book-of-secret-knowledge](https://github.com/trimstray/the-book-of-secret-knowledge) A collection of inspiring lists, manuals, cheatsheets, blogs, hacks, one-liners, cli/web tools and more. -- [**22517**星][12d] [Shell] [mathiasbynens/dotfiles](https://github.com/mathiasbynens/dotfiles) -- [**21751**星][7d] [PHP] [danielmiessler/seclists](https://github.com/danielmiessler/seclists) 多种类型资源收集:用户名、密码、URL、敏感数据类型、Fuzzing Payload、WebShell等 -- [**21668**星][10d] [Go] [filosottile/mkcert](https://github.com/filosottile/mkcert) A simple zero-config tool to make locally trusted development certificates with any names you'd like. -- [**20619**星][9d] [Java] [skylot/jadx](https://github.com/skylot/jadx) dex 转 java 的反编译器 -- [**20089**星][2m] [Shell] [streisandeffect/streisand](https://github.com/StreisandEffect/streisand) Streisand sets up a new server running your choice of WireGuard, OpenConnect, OpenSSH, OpenVPN, Shadowsocks, sslh, Stunnel, or a Tor bridge. It also generates custom instructions for all of these services. At the end of the run you are given an HTML file with instructions that can be shared with friends, family members, and fellow activists. -- [**19651**星][2m] [Jupyter Notebook] [camdavidsonpilon/probabilistic-programming-and-bayesian-methods-for-hackers](https://github.com/camdavidsonpilon/probabilistic-programming-and-bayesian-methods-for-hackers) aka "Bayesian Methods for Hackers": An introduction to Bayesian methods + probabilistic programming with a computation/understanding-first, mathematics-second point of view. All in pure Python ;) -- [**18996**星][7d] [Ruby] [rapid7/metasploit-framework](https://github.com/rapid7/metasploit-framework) Metasploit Framework -- [**18648**星][3y] [fallibleinc/security-guide-for-developers](https://github.com/fallibleinc/security-guide-for-developers) Security Guide for Developers (实用性开发人员安全须知) -- [**18381**星][7d] [Java] [nationalsecurityagency/ghidra](https://github.com/nationalsecurityagency/ghidra) 软件逆向框架 -- [**18220**星][8d] [Java] [alibaba/arthas](https://github.com/alibaba/arthas) Alibaba Java诊断利器Arthas -- [**17555**星][4y] [Go] [inconshreveable/ngrok](https://github.com/inconshreveable/ngrok) 反向代理,在公网终端和本地服务之间创建安全的隧道 -- [**16951**星][14d] [Py] [mitmproxy/mitmproxy](https://github.com/mitmproxy/mitmproxy) An interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers. -- [**16681**星][7d] [C#] [powershell/powershell](https://github.com/powershell/powershell) PowerShell for every system! -- [**15756**星][8d] [Py] [sqlmapproject/sqlmap](https://github.com/sqlmapproject/sqlmap) Automatic SQL injection and database takeover tool -- [**15694**星][9m] [micropoor/micro8](https://github.com/micropoor/micro8) 从业10年渗透笔记 -- [**15627**星][7d] [C] [curl/curl](https://github.com/curl/curl) A command line tool and library for transferring data with URL syntax, supporting HTTP, HTTPS, FTP, FTPS, GOPHER, TFTP, SCP, SFTP, SMB, TELNET, DICT, LDAP, LDAPS, FILE, IMAP, SMTP, POP3, RTSP and RTMP. libcurl offers a myriad of powerful features -- [**14661**星][1m] [gfwlist/gfwlist](https://github.com/gfwlist/gfwlist) gfwlist -- [**14478**星][26d] [Java] [tencent/tinker](https://github.com/tencent/tinker) Tinker is a hot-fix solution library for Android, it supports dex, library and resources update without reinstall apk. -- [**13627**星][9m] [JS] [bannedbook/fanqiang](https://github.com/bannedbook/fanqiang) 翻墙-科学上网 -- [**13183**星][26d] [Py] [corentinj/real-time-voice-cloning](https://github.com/corentinj/real-time-voice-cloning) Clone a voice in 5 seconds to generate arbitrary speech in real-time -- [**13081**星][17d] [Go] [jesseduffield/lazydocker](https://github.com/jesseduffield/lazydocker) The lazier way to manage everything docker -- [**12920**星][10d] [Py] [cool-rr/pysnooper](https://github.com/cool-rr/pysnooper) Never use print for debugging again -- [**12641**星][9d] [C] [shadowsocks/shadowsocks-libev](https://github.com/shadowsocks/shadowsocks-libev) libev port of shadowsocks -- [**12453**星][7d] [C#] [0xd4d/dnspy](https://github.com/0xd4d/dnspy) .NET debugger and assembly editor -- [**12203**星][14d] [Java] [signalapp/signal-android](https://github.com/signalapp/Signal-Android) A private messenger for Android. -- [**11935**星][1m] [Go] [buger/goreplay](https://github.com/buger/goreplay) 实时捕获HTTP流量并输入测试环境,以便持续使用真实数据测试你的系统 -- [**11829**星][17d] [C] [openssl/openssl](https://github.com/openssl/openssl) TLS/SSL and crypto library -- [**11490**星][7d] [C] [radareorg/radare2](https://github.com/radareorg/radare2) unix-like reverse engineering framework and commandline tools -- [**11361**星][3m] [C] [robertdavidgraham/masscan](https://github.com/robertdavidgraham/masscan) masscan:世界上最快的互联网端口扫描器,号称可6分钟内扫描整个互联网 -- [**11246**星][1m] [facert/awesome-spider](https://github.com/facert/awesome-spider) 爬虫集合 -- [**11225**星][13d] [getlantern/download](https://github.com/getlantern/download) Lantern官方版本下载 蓝灯 翻墙 科学上网 外网 加速器 梯子 路由 -- [**11174**星][7d] [Java] [oracle/graal](https://github.com/oracle/graal) Run Programs Faster Anywhere -- [**11106**星][2m] [Jupyter Notebook] [selfteaching/the-craft-of-selfteaching](https://github.com/selfteaching/the-craft-of-selfteaching) One has no future if one couldn't teach themself. -- [**11047**星][7d] [Py] [swisskyrepo/payloadsallthethings](https://github.com/swisskyrepo/payloadsallthethings) A list of useful payloads and bypass for Web Application Security and Pentest/CTF -- [**11013**星][2y] [Objective-C] [bang590/jspatch](https://github.com/bang590/jspatch) JSPatch bridge Objective-C and Javascript using the Objective-C runtime. You can call any Objective-C class and method in JavaScript by just including a small engine. JSPatch is generally used to hotfix iOS App. -- [**11008**星][8d] [Py] [owasp/cheatsheetseries](https://github.com/owasp/cheatsheetseries) The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics. -- [**10902**星][12d] [Objective-C] [flipboard/flex](https://github.com/flipboard/flex) An in-app debugging and exploration tool for iOS -- [**10886**星][2m] [CSS] [hacker0x01/hacker101](https://github.com/hacker0x01/hacker101) Hacker101 -- [**10761**星][2y] [CoffeeScript] [dropbox/zxcvbn](https://github.com/dropbox/zxcvbn) Low-Budget Password Strength Estimation -- [**10742**星][13d] [enaqx/awesome-pentest](https://github.com/enaqx/awesome-pentest) 渗透测试资源/工具集 -- [**10738**星][17d] [Java] [konloch/bytecode-viewer](https://github.com/konloch/bytecode-viewer) A Java 8+ Jar & Android APK Reverse Engineering Suite (Decompiler, Editor, Debugger & More) -- [**10107**星][8d] [Go] [goharbor/harbor](https://github.com/goharbor/harbor) An open source trusted cloud native registry project that stores, signs, and scans content. -- [**9844**星][11d] [ruanyf/weekly](https://github.com/ruanyf/weekly) 科技爱好者周刊,每周五发布 -- [**9804**星][8m] [imthenachoman/how-to-secure-a-linux-server](https://github.com/imthenachoman/how-to-secure-a-linux-server) An evolving how-to guide for securing a Linux server. -- [**9349**星][12d] [Ruby] [postalhq/postal](https://github.com/postalhq/postal) 全功能邮件服务器 -- [**9229**星][3m] [JS] [localtunnel/localtunnel](https://github.com/localtunnel/localtunnel) expose yourself -- [**9182**星][8d] [Go] [cnlh/nps](https://github.com/cnlh/nps) 一款轻量级、功能强大的内网穿透代理服务器。支持tcp、udp流量转发,支持内网http代理、内网socks5代理,同时支持snappy压缩、站点保护、加密传输、多路复用、header修改等。支持web图形化管理,集成多用户模式。 -- [**9178**星][10d] [Java] [ibotpeaches/apktool](https://github.com/ibotpeaches/apktool) A tool for reverse engineering Android apk files -- [**9141**星][8d] [C#] [icsharpcode/ilspy](https://github.com/icsharpcode/ilspy) .NET Decompiler -- [**9064**星][27d] [JS] [valve/fingerprintjs2](https://github.com/valve/fingerprintjs2) Modern & flexible browser fingerprinting library -- [**9003**星][9d] [PowerShell] [lukesampson/scoop](https://github.com/lukesampson/scoop) A command-line installer for Windows. -- [**8995**星][2m] [vitalysim/awesome-hacking-resources](https://github.com/vitalysim/awesome-hacking-resources) A collection of hacking / penetration testing resources to make you better! -- [**8988**星][9d] [Py] [sherlock-project/sherlock](https://github.com/sherlock-project/sherlock) Find Usernames Across Social Networks -- [**8847**星][6m] [Go] [rkt/rkt](https://github.com/rkt/rkt) rkt is a pod-native container engine for Linux. It is composable, secure, and built on standards. -- [**8712**星][15d] [C] [gentilkiwi/mimikatz](https://github.com/gentilkiwi/mimikatz) A little tool to play with Windows security -- [**8597**星][26d] [Java] [android-hacker/virtualxposed](https://github.com/android-hacker/virtualxposed) A simple app to use Xposed without root, unlock the bootloader or modify system image, etc. -- [**8495**星][1m] [microsoft/wsl](https://github.com/microsoft/WSL) Issues found on WSL -- [**8408**星][2y] [brannondorsey/wifi-cracking](https://github.com/brannondorsey/wifi-cracking) 破解WPA/WPA2 Wi-Fi 路由器 -- [**8399**星][27d] [Py] [wifiphisher/wifiphisher](https://github.com/wifiphisher/wifiphisher) 流氓AP框架, 用于RedTeam和Wi-Fi安全测试 -- [**8033**星][7d] [trimstray/the-practical-linux-hardening-guide](https://github.com/trimstray/the-practical-linux-hardening-guide) This guide details creating a secure Linux production system. OpenSCAP (C2S/CIS, STIG). -- [**7992**星][2m] [Py] [facebook/chisel](https://github.com/facebook/chisel) Chisel is a collection of LLDB commands to assist debugging iOS apps. -- [**7952**星][3y] [Go] [cyfdecyf/cow](https://github.com/cyfdecyf/cow) HTTP proxy written in Go. COW can automatically identify blocked sites and use parent proxies to access. -- [**7936**星][4y] [Objective-C] [shadowsocks/shadowsocks-ios](https://github.com/shadowsocks/shadowsocks-ios) Removed according to regulations. -- [**7806**星][3m] [C++] [shiqiyu/libfacedetection](https://github.com/shiqiyu/libfacedetection) An open source library for face detection in images. The face detection speed can reach 1500FPS. -- [**7696**星][7d] [JS] [gchq/cyberchef](https://github.com/gchq/cyberchef) The Cyber Swiss Army Knife - a web app for encryption, encoding, compression and data analysis -- [**7685**星][7d] [Go] [git-lfs/git-lfs](https://github.com/git-lfs/git-lfs) Git extension for versioning large files -- [**7628**星][22d] [Java] [java-decompiler/jd-gui](https://github.com/java-decompiler/jd-gui) A standalone Java Decompiler GUI -- [**7498**星][27d] [Py] [threat9/routersploit](https://github.com/threat9/routersploit) Exploitation Framework for Embedded Devices -- [**7371**星][12d] [Go] [snail007/goproxy](https://github.com/snail007/goproxy) Proxy是高性能全功能的http代理、https代理、socks5代理、内网穿透、内网穿透p2p、内网穿透代理、内网穿透反向代理、内网穿透服务器、Websocket代理、TCP代理、UDP代理、DNS代理、DNS加密代理,代理API认证,全能跨平台代理服务器。 -- [**7365**星][1m] [Py] [s0md3v/xsstrike](https://github.com/s0md3v/XSStrike) Most advanced XSS scanner. -- [**7205**星][17d] [Java] [lionsoul2014/ip2region](https://github.com/lionsoul2014/ip2region) Ip2region is a offline IP location library with accuracy rate of 99.9% and 0.0x millseconds searching performance. DB file is less then 5Mb with all ip address stored. binding for Java,PHP,C,Python,Nodejs,Golang,C#,lua. Binary,B-tree,Memory searching algorithm -- [**7174**星][7m] [Shell] [teddysun/shadowsocks_install](https://github.com/teddysun/shadowsocks_install) Auto Install Shadowsocks Server for CentOS/Debian/Ubuntu -- [**6994**星][14d] [Go] [future-architect/vuls](https://github.com/future-architect/vuls) 针对Linux/FreeBSD 编写的漏洞扫描器. Go 语言编写 -- [**6968**星][2m] [JS] [cs01/gdbgui](https://github.com/cs01/gdbgui) Browser-based frontend to gdb (gnu debugger). Add breakpoints, view the stack, visualize data structures, and more in C, C++, Go, Rust, and Fortran. Run gdbgui from the terminal and a new tab will open in your browser. -- [**6956**星][10d] [C] [hashcat/hashcat](https://github.com/hashcat/hashcat) 世界上最快最先进的密码恢复工具 -- [**6954**星][13d] [Go] [nats-io/nats-server](https://github.com/nats-io/nats-server) High-Performance server for NATS, the cloud native messaging system. -- [**6950**星][9d] [greatfire/wiki](https://github.com/greatfire/wiki) 自由浏览 -- [**6917**星][3m] [Java] [pxb1988/dex2jar](https://github.com/pxb1988/dex2jar) Tools to work with android .dex and java .class files -- [**6844**星][2m] [Go] [sqshq/sampler](https://github.com/sqshq/sampler) A tool for shell commands execution, visualization and alerting. Configured with a simple YAML file. -- [**6788**星][17d] [Shell] [awslabs/git-secrets](https://github.com/awslabs/git-secrets) Prevents you from committing secrets and credentials into git repositories -- [**6708**星][9m] [Java] [amitshekhariitbhu/android-debug-database](https://github.com/amitshekhariitbhu/android-debug-database) A library for debugging android databases and shared preferences - Make Debugging Great Again -- [**6678**星][3y] [C++] [alibaba/andfix](https://github.com/alibaba/andfix) AndFix is a library that offer hot-fix for Android App. -- [**6639**星][9d] [Java] [zaproxy/zaproxy](https://github.com/zaproxy/zaproxy) 在开发和测试Web App时自动发现安全漏洞 -- [**6557**星][11d] [Py] [networkx/networkx](https://github.com/networkx/networkx) 用于创建、操纵和研究复杂网络的结构,Python包 -- [**6455**星][1m] [Py] [h2y/shadowrocket-adblock-rules](https://github.com/h2y/shadowrocket-adblock-rules) 提供多款 Shadowrocket 规则,带广告过滤功能。用于 iOS 未越狱设备选择性地自动翻墙。 -- [**6449**星][11d] [Shell] [cisofy/lynis](https://github.com/cisofy/lynis) Security auditing tool for Linux, macOS, and UNIX-based systems. Assists with compliance testing (HIPAA/ISO27001/PCI DSS) and system hardening. Agentless, and installation optional. -- [**6440**星][9m] [HTML] [open-power-workgroup/hospital](https://github.com/open-power-workgroup/hospital) OpenPower工作组收集汇总的医院开放数据 -- [**6413**星][15d] [Go] [bettercap/bettercap](https://github.com/bettercap/bettercap) 新版的bettercap, Go 编写. bettercap 是强大的、模块化、可移植且易于扩展的 MITM 框架, 旧版用 Ruby 编写 -- [**6284**星][27d] [Py] [seatgeek/fuzzywuzzy](https://github.com/seatgeek/fuzzywuzzy) Fuzzy String Matching in Python -- [**6182**星][2m] [Py] [yandex/gixy](https://github.com/yandex/gixy) Nginx 配置静态分析工具,防止配置错误导致安全问题,自动化错误配置检测 -- [**6170**星][6m] [rmerl/asuswrt-merlin](https://github.com/rmerl/asuswrt-merlin) Enhanced version of Asus's router firmware (Asuswrt) (legacy code base) -- [**6158**星][3y] [PowerShell] [powershellmafia/powersploit](https://github.com/PowerShellMafia/PowerSploit) PowerSploit - A PowerShell Post-Exploitation Framework -- [**6130**星][1y] [Hack] [facebook/fbctf](https://github.com/facebook/fbctf) Platform to host Capture the Flag competitions -- [**6124**星][9m] [Py] [schollz/howmanypeoplearearound](https://github.com/schollz/howmanypeoplearearound) 检测 Wifi 信号统计你周围的人数 -- [**6100**星][7d] [JS] [avwo/whistle](https://github.com/avwo/whistle) 基于Node实现的跨平台抓包调试代理工具(HTTP, HTTP2, HTTPS, Websocket) -- [**6061**星][2y] [C] [jgamblin/mirai-source-code](https://github.com/jgamblin/mirai-source-code) Leaked Mirai Source Code for Research/IoC Development Purposes -- [**6025**星][14d] [Go] [quay/clair](https://github.com/quay/clair) Vulnerability Static Analysis for Containers -- [**6025**星][14d] [Go] [quay/clair](https://github.com/quay/clair) clair:容器(appc、docker)漏洞静态分析工具。 -- [**6002**星][11d] [Py] [cyrus-and/gdb-dashboard](https://github.com/cyrus-and/gdb-dashboard) Modular visual interface for GDB in Python -- [**5996**星][20d] [berzerk0/probable-wordlists](https://github.com/berzerk0/probable-wordlists) Version 2 is live! Wordlists sorted by probability originally created for password generation and testing - make sure your passwords aren't popular! -- [**5948**星][2m] [Java] [google/android-classyshark](https://github.com/google/android-classyshark) 分析基于Android/Java的App或游戏 -- [**5935**星][29d] [Py] [gallopsled/pwntools](https://github.com/gallopsled/pwntools) CTF framework and exploit development library -- [**5870**星][6m] [JS] [haotian-wang/google-access-helper](https://github.com/haotian-wang/google-access-helper) 谷歌访问助手破解版 -- [**5850**星][8d] [C++] [radareorg/cutter](https://github.com/radareorg/cutter) 逆向框架 radare2的Qt界面,iaito的升级版 -- [**5845**星][2m] [Gnuplot] [nasa-jpl/open-source-rover](https://github.com/nasa-jpl/open-source-rover) A build-it-yourself, 6-wheel rover based on the rovers on Mars! -- [**5811**星][7m] [JS] [sindresorhus/fkill-cli](https://github.com/sindresorhus/fkill-cli) Fabulously kill processes. Cross-platform. -- [**5764**星][3m] [Objective-C] [square/ponydebugger](https://github.com/square/ponydebugger) Remote network and data debugging for your native iOS app using Chrome Developer Tools -- [**5738**星][1y] [qinyuhang/shadowsocksx-ng-r](https://github.com/qinyuhang/shadowsocksx-ng-r) Next Generation of ShadowsocksX -- [**5738**星][2y] [Py] [newsapps/beeswithmachineguns](https://github.com/newsapps/beeswithmachineguns) 创建多个micro EC2实例, 攻击指定Web App -- [**5719**星][2m] [C] [spacehuhn/esp8266_deauther](https://github.com/spacehuhn/esp8266_deauther) 使用ESP8266 制作Wifi干扰器 -- [**5715**星][8m] [C] [xoreaxeaxeax/movfuscator](https://github.com/xoreaxeaxeax/movfuscator) C编译器,编译的二进制文件只有1个代码块。 -- [**5674**星][22d] [JS] [swagger-api/swagger-editor](https://github.com/swagger-api/swagger-editor) Swagger Editor -- [**5653**星][16d] [Go] [casbin/casbin](https://github.com/casbin/casbin) An authorization library that supports access control models like ACL, RBAC, ABAC in Golang -- [**5605**星][1m] [C] [rofl0r/proxychains-ng](https://github.com/rofl0r/proxychains-ng) proxychains ng (new generation) - a preloader which hooks calls to sockets in dynamically linked programs and redirects it through one or more socks/http proxies. continuation of the unmaintained proxychains project. the sf.net page is currently not updated, use releases from github release page instead. -- [**5578**星][8d] [Ruby] [presidentbeef/brakeman](https://github.com/presidentbeef/brakeman) ROR程序的静态分析工具 -- [**5521**星][18d] [rshipp/awesome-malware-analysis](https://github.com/rshipp/awesome-malware-analysis) A curated list of awesome malware analysis tools and resources. -- [**5517**星][27d] [Roff] [max2max/freess](https://github.com/max2max/freess) 免费ss账号 免费shadowsocks账号 免费v2ray账号 (长期更新) -- [**5456**星][8m] [carpedm20/awesome-hacking](https://github.com/carpedm20/awesome-hacking) Hacking教程、工具和资源 -- [**5417**星][2y] [Rust] [autumnai/leaf](https://github.com/autumnai/leaf) Open Machine Intelligence Framework for Hackers. (GPU/CPU) -- [**5392**星][2m] [Py] [axi0mx/ipwndfu](https://github.com/axi0mx/ipwndfu) open-source jailbreaking tool for many iOS devices -- [**5353**星][5m] [C] [pwn20wndstuff/undecimus](https://github.com/pwn20wndstuff/undecimus) unc0ver jailbreak for iOS 11.0 - 12.4 -- [**5317**星][7d] [Py] [mlflow/mlflow](https://github.com/mlflow/mlflow) Open source platform for the machine learning lifecycle -- [**5307**星][9d] [Go] [zricethezav/gitleaks](https://github.com/zricethezav/gitleaks) Audit git repos for secrets -- [**5207**星][7m] [Py] [usarmyresearchlab/dshell](https://github.com/usarmyresearchlab/dshell) 网络审计分析 -- [**5165**星][1m] [Py] [refirmlabs/binwalk](https://github.com/ReFirmLabs/binwalk) 固件分析工具(命令行+IDA插件) +- [**45523**星][11d] [C#] [shadowsocks/shadowsocks-windows](https://github.com/shadowsocks/shadowsocks-windows) If you want to keep a secret, you must also hide it from yourself. +- [**34554**星][16d] [C++] [x64dbg/x64dbg](https://github.com/x64dbg/x64dbg) Windows平台x32/x64调试器 +- [**33926**星][10d] [Py] [minimaxir/big-list-of-naughty-strings](https://github.com/minimaxir/big-list-of-naughty-strings) “淘气”的字符串列表,当作为用户输入时很容易引发问题 +- [**32844**星][2m] [hack-with-github/awesome-hacking](https://github.com/hack-with-github/awesome-hacking) A collection of various awesome lists for hackers, pentesters and security researchers +- [**32022**星][4y] [Py] [shadowsocks/shadowsocks](https://github.com/shadowsocks/shadowsocks) +- [**30689**星][14d] [Go] [fatedier/frp](https://github.com/fatedier/frp) 快速的反向代理, 将NAT或防火墙之后的本地服务器暴露到公网 +- [**27836**星][2d] [Kotlin] [shadowsocks/shadowsocks-android](https://github.com/shadowsocks/shadowsocks-android) A shadowsocks client for Android +- [**25977**星][2d] [Py] [certbot/certbot](https://github.com/certbot/certbot) Certbot is EFF's tool to obtain certs from Let's Encrypt and (optionally) auto-enable HTTPS on your server. It can also act as a client for any other CA that uses the ACME protocol. +- [**25643**星][28d] [Swift] [shadowsocks/shadowsocksx-ng](https://github.com/shadowsocks/shadowsocksx-ng) Next Generation of ShadowsocksX +- [**25330**星][3d] [Go] [v2ray/v2ray-core](https://github.com/v2ray/v2ray-core) A platform for building proxies to bypass network restrictions. +- [**24826**星][2d] [xitu/gold-miner](https://github.com/xitu/gold-miner) +- [**24727**星][5d] [trimstray/the-book-of-secret-knowledge](https://github.com/trimstray/the-book-of-secret-knowledge) A collection of inspiring lists, manuals, cheatsheets, blogs, hacks, one-liners, cli/web tools and more. +- [**22556**星][14d] [Shell] [mathiasbynens/dotfiles](https://github.com/mathiasbynens/dotfiles) +- [**21874**星][9d] [PHP] [danielmiessler/seclists](https://github.com/danielmiessler/seclists) 多种类型资源收集:用户名、密码、URL、敏感数据类型、Fuzzing Payload、WebShell等 +- [**21778**星][12d] [Go] [filosottile/mkcert](https://github.com/filosottile/mkcert) A simple zero-config tool to make locally trusted development certificates with any names you'd like. +- [**20680**星][5d] [Java] [skylot/jadx](https://github.com/skylot/jadx) dex 转 java 的反编译器 +- [**20159**星][5d] [Shell] [streisandeffect/streisand](https://github.com/StreisandEffect/streisand) Streisand sets up a new server running your choice of WireGuard, OpenConnect, OpenSSH, OpenVPN, Shadowsocks, sslh, Stunnel, or a Tor bridge. It also generates custom instructions for all of these services. At the end of the run you are given an HTML file with instructions that can be shared with friends, family members, and fellow activists. +- [**19692**星][2m] [Jupyter Notebook] [camdavidsonpilon/probabilistic-programming-and-bayesian-methods-for-hackers](https://github.com/camdavidsonpilon/probabilistic-programming-and-bayesian-methods-for-hackers) aka "Bayesian Methods for Hackers": An introduction to Bayesian methods + probabilistic programming with a computation/understanding-first, mathematics-second point of view. All in pure Python ;) +- [**19212**星][1y] [alvin9999/new-pac](https://github.com/alvin9999/new-pac) 科学/自由上网,免费ss/ssr/v2ray/goflyway账号,搭建教程 +- [**19076**星][2d] [Ruby] [rapid7/metasploit-framework](https://github.com/rapid7/metasploit-framework) Metasploit Framework +- [**18676**星][3y] [fallibleinc/security-guide-for-developers](https://github.com/fallibleinc/security-guide-for-developers) Security Guide for Developers (实用性开发人员安全须知) +- [**18476**星][2d] [Java] [nationalsecurityagency/ghidra](https://github.com/nationalsecurityagency/ghidra) 软件逆向框架 +- [**18390**星][3d] [Java] [alibaba/arthas](https://github.com/alibaba/arthas) Alibaba Java诊断利器Arthas +- [**17641**星][4y] [Go] [inconshreveable/ngrok](https://github.com/inconshreveable/ngrok) 反向代理,在公网终端和本地服务之间创建安全的隧道 +- [**17069**星][6d] [Py] [mitmproxy/mitmproxy](https://github.com/mitmproxy/mitmproxy) An interactive TLS-capable intercepting HTTP proxy for penetration testers and software developers. +- [**16769**星][2d] [C#] [powershell/powershell](https://github.com/powershell/powershell) PowerShell for every system! +- [**15824**星][2d] [Py] [sqlmapproject/sqlmap](https://github.com/sqlmapproject/sqlmap) Automatic SQL injection and database takeover tool +- [**15731**星][9m] [micropoor/micro8](https://github.com/micropoor/micro8) 从业10年渗透笔记 +- [**15718**星][3d] [C] [curl/curl](https://github.com/curl/curl) A command line tool and library for transferring data with URL syntax, supporting HTTP, HTTPS, FTP, FTPS, GOPHER, TFTP, SCP, SFTP, SMB, TELNET, DICT, LDAP, LDAPS, FILE, IMAP, SMTP, POP3, RTSP and RTMP. libcurl offers a myriad of powerful features +- [**15363**星][21d] [Py] [drduh/macos-security-and-privacy-guide](https://github.com/drduh/macOS-Security-and-Privacy-Guide) Guide to securing and improving privacy on macOS +- [**14744**星][1m] [gfwlist/gfwlist](https://github.com/gfwlist/gfwlist) gfwlist +- [**14518**星][7d] [Java] [tencent/tinker](https://github.com/tencent/tinker) Tinker is a hot-fix solution library for Android, it supports dex, library and resources update without reinstall apk. +- [**13736**星][9m] [JS] [bannedbook/fanqiang](https://github.com/bannedbook/fanqiang) 翻墙-科学上网 +- [**13548**星][28d] [Py] [corentinj/real-time-voice-cloning](https://github.com/corentinj/real-time-voice-cloning) Clone a voice in 5 seconds to generate arbitrary speech in real-time +- [**13241**星][19d] [Go] [jesseduffield/lazydocker](https://github.com/jesseduffield/lazydocker) The lazier way to manage everything docker +- [**12966**星][12d] [Py] [cool-rr/pysnooper](https://github.com/cool-rr/pysnooper) Never use print for debugging again +- [**12742**星][3d] [Vue] [liyasthomas/postwoman](https://github.com/liyasthomas/postwoman) +- [**12693**星][8d] [C] [shadowsocks/shadowsocks-libev](https://github.com/shadowsocks/shadowsocks-libev) libev port of shadowsocks +- [**12544**星][9d] [C#] [0xd4d/dnspy](https://github.com/0xd4d/dnspy) .NET debugger and assembly editor +- [**12325**星][2m] [Ruby] [diaspora/diaspora](https://github.com/diaspora/diaspora) A privacy-aware, distributed, open source social network. +- [**12241**星][5d] [Java] [signalapp/signal-android](https://github.com/signalapp/Signal-Android) A private messenger for Android. +- [**11977**星][1m] [Go] [buger/goreplay](https://github.com/buger/goreplay) 实时捕获HTTP流量并输入测试环境,以便持续使用真实数据测试你的系统 +- [**11890**星][6d] [C] [openssl/openssl](https://github.com/openssl/openssl) TLS/SSL and crypto library +- [**11530**星][2d] [C] [radareorg/radare2](https://github.com/radareorg/radare2) unix-like reverse engineering framework and commandline tools +- [**11418**星][3m] [C] [robertdavidgraham/masscan](https://github.com/robertdavidgraham/masscan) masscan:世界上最快的互联网端口扫描器,号称可6分钟内扫描整个互联网 +- [**11404**星][2d] [getlantern/download](https://github.com/getlantern/download) Lantern官方版本下载 蓝灯 翻墙 科学上网 外网 加速器 梯子 路由 +- [**11342**星][1m] [facert/awesome-spider](https://github.com/facert/awesome-spider) 爬虫集合 +- [**11278**星][2d] [Java] [oracle/graal](https://github.com/oracle/graal) Run Programs Faster Anywhere +- [**11200**星][5d] [Py] [swisskyrepo/payloadsallthethings](https://github.com/swisskyrepo/payloadsallthethings) A list of useful payloads and bypass for Web Application Security and Pentest/CTF +- [**11143**星][2m] [Jupyter Notebook] [selfteaching/the-craft-of-selfteaching](https://github.com/selfteaching/the-craft-of-selfteaching) One has no future if one couldn't teach themself. +- [**11110**星][5d] [Py] [owasp/cheatsheetseries](https://github.com/owasp/cheatsheetseries) The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics. +- [**11016**星][2y] [ObjC] [bang590/jspatch](https://github.com/bang590/jspatch) JSPatch bridge Objective-C and Javascript using the Objective-C runtime. You can call any Objective-C class and method in JavaScript by just including a small engine. JSPatch is generally used to hotfix iOS App. +- [**10925**星][2d] [ObjC] [flipboard/flex](https://github.com/flipboard/flex) An in-app debugging and exploration tool for iOS +- [**10907**星][2m] [CSS] [hacker0x01/hacker101](https://github.com/hacker0x01/hacker101) Hacker101 +- [**10830**星][15d] [enaqx/awesome-pentest](https://github.com/enaqx/awesome-pentest) 渗透测试资源/工具集 +- [**10780**星][2y] [CoffeeScript] [dropbox/zxcvbn](https://github.com/dropbox/zxcvbn) Low-Budget Password Strength Estimation +- [**10757**星][19d] [Java] [konloch/bytecode-viewer](https://github.com/konloch/bytecode-viewer) A Java 8+ Jar & Android APK Reverse Engineering Suite (Decompiler, Editor, Debugger & More) +- [**10318**星][5d] [ruanyf/weekly](https://github.com/ruanyf/weekly) 科技爱好者周刊,每周五发布 +- [**10226**星][3d] [Go] [goharbor/harbor](https://github.com/goharbor/harbor) An open source trusted cloud native registry project that stores, signs, and scans content. +- [**9830**星][8m] [imthenachoman/how-to-secure-a-linux-server](https://github.com/imthenachoman/how-to-secure-a-linux-server) An evolving how-to guide for securing a Linux server. +- [**9613**星][4d] [Py] [sherlock-project/sherlock](https://github.com/sherlock-project/sherlock) Find Usernames Across Social Networks +- [**9389**星][3d] [Go] [cnlh/nps](https://github.com/cnlh/nps) 一款轻量级、功能强大的内网穿透代理服务器。支持tcp、udp流量转发,支持内网http代理、内网socks5代理,同时支持snappy压缩、站点保护、加密传输、多路复用、header修改等。支持web图形化管理,集成多用户模式。 +- [**9358**星][6d] [Ruby] [postalhq/postal](https://github.com/postalhq/postal) 全功能邮件服务器 +- [**9266**星][3m] [JS] [localtunnel/localtunnel](https://github.com/localtunnel/localtunnel) expose yourself +- [**9229**星][12d] [Java] [ibotpeaches/apktool](https://github.com/ibotpeaches/apktool) A tool for reverse engineering Android apk files +- [**9185**星][2d] [C#] [icsharpcode/ilspy](https://github.com/icsharpcode/ilspy) .NET Decompiler +- [**9148**星][29d] [JS] [valve/fingerprintjs2](https://github.com/valve/fingerprintjs2) Modern & flexible browser fingerprinting library +- [**9069**星][11d] [PS] [lukesampson/scoop](https://github.com/lukesampson/scoop) A command-line installer for Windows. +- [**9015**星][2m] [vitalysim/awesome-hacking-resources](https://github.com/vitalysim/awesome-hacking-resources) A collection of hacking / penetration testing resources to make you better! +- [**8854**星][6m] [Go] [rkt/rkt](https://github.com/rkt/rkt) rkt is a pod-native container engine for Linux. It is composable, secure, and built on standards. +- [**8739**星][17d] [C] [gentilkiwi/mimikatz](https://github.com/gentilkiwi/mimikatz) A little tool to play with Windows security +- [**8646**星][28d] [Java] [android-hacker/virtualxposed](https://github.com/android-hacker/virtualxposed) A simple app to use Xposed without root, unlock the bootloader or modify system image, etc. +- [**8525**星][1m] [microsoft/wsl](https://github.com/microsoft/WSL) Issues found on WSL +- [**8443**星][7m] [Shell] [233boy/v2ray](https://github.com/233boy/v2ray) 最好用的 V2Ray 一键安装脚本 & 管理脚本 +- [**8424**星][2d] [Py] [wifiphisher/wifiphisher](https://github.com/wifiphisher/wifiphisher) 流氓AP框架, 用于RedTeam和Wi-Fi安全测试 +- [**8420**星][2y] [brannondorsey/wifi-cracking](https://github.com/brannondorsey/wifi-cracking) 破解WPA/WPA2 Wi-Fi 路由器 +- [**8044**星][9d] [trimstray/the-practical-linux-hardening-guide](https://github.com/trimstray/the-practical-linux-hardening-guide) This guide details creating a secure Linux production system. OpenSCAP (C2S/CIS, STIG). +- [**8002**星][2m] [Py] [facebook/chisel](https://github.com/facebook/chisel) Chisel is a collection of LLDB commands to assist debugging iOS apps. +- [**7986**星][1m] [Py] [mailpile/mailpile](https://github.com/mailpile/mailpile) A free & open modern, fast email client with user-friendly encryption and privacy features +- [**7965**星][3y] [Go] [cyfdecyf/cow](https://github.com/cyfdecyf/cow) HTTP proxy written in Go. COW can automatically identify blocked sites and use parent proxies to access. +- [**7945**星][4y] [ObjC] [shadowsocks/shadowsocks-ios](https://github.com/shadowsocks/shadowsocks-ios) Removed according to regulations. +- [**7840**星][6d] [C++] [shiqiyu/libfacedetection](https://github.com/shiqiyu/libfacedetection) An open source library for face detection in images. The face detection speed can reach 1500FPS. +- [**7731**星][3d] [JS] [gchq/cyberchef](https://github.com/gchq/cyberchef) The Cyber Swiss Army Knife - a web app for encryption, encoding, compression and data analysis +- [**7712**星][2d] [Go] [git-lfs/git-lfs](https://github.com/git-lfs/git-lfs) Git extension for versioning large files +- [**7670**星][24d] [Java] [java-decompiler/jd-gui](https://github.com/java-decompiler/jd-gui) A standalone Java Decompiler GUI +- [**7524**星][29d] [Py] [threat9/routersploit](https://github.com/threat9/routersploit) Exploitation Framework for Embedded Devices +- [**7474**星][9d] [Go] [snail007/goproxy](https://github.com/snail007/goproxy) Proxy是高性能全功能的http代理、https代理、socks5代理、内网穿透、内网穿透p2p、内网穿透代理、内网穿透反向代理、内网穿透服务器、Websocket代理、TCP代理、UDP代理、DNS代理、DNS加密代理,代理API认证,全能跨平台代理服务器。 +- [**7412**星][1m] [C++] [shadowsocks/shadowsocks-qt5](https://github.com/shadowsocks/shadowsocks-qt5) A cross-platform shadowsocks GUI client +- [**7397**星][1m] [Py] [s0md3v/xsstrike](https://github.com/s0md3v/XSStrike) Most advanced XSS scanner. +- [**7246**星][19d] [Java] [lionsoul2014/ip2region](https://github.com/lionsoul2014/ip2region) Ip2region is a offline IP location library with accuracy rate of 99.9% and 0.0x millseconds searching performance. DB file is less then 5Mb with all ip address stored. binding for Java,PHP,C,Python,Nodejs,Golang,C#,lua. Binary,B-tree,Memory searching algorithm +- [**7186**星][7m] [Shell] [teddysun/shadowsocks_install](https://github.com/teddysun/shadowsocks_install) Auto Install Shadowsocks Server for CentOS/Debian/Ubuntu +- [**7017**星][16d] [Go] [future-architect/vuls](https://github.com/future-architect/vuls) 针对Linux/FreeBSD 编写的漏洞扫描器. Go 语言编写 +- [**6989**星][5d] [C] [hashcat/hashcat](https://github.com/hashcat/hashcat) 世界上最快最先进的密码恢复工具 +- [**6984**星][2d] [Go] [nats-io/nats-server](https://github.com/nats-io/nats-server) High-Performance server for NATS, the cloud native messaging system. +- [**6984**星][2m] [JS] [cs01/gdbgui](https://github.com/cs01/gdbgui) Browser-based frontend to gdb (gnu debugger). Add breakpoints, view the stack, visualize data structures, and more in C, C++, Go, Rust, and Fortran. Run gdbgui from the terminal and a new tab will open in your browser. +- [**6957**星][11d] [greatfire/wiki](https://github.com/greatfire/wiki) 自由浏览 +- [**6949**星][3m] [Java] [pxb1988/dex2jar](https://github.com/pxb1988/dex2jar) Tools to work with android .dex and java .class files +- [**6869**星][2m] [Go] [sqshq/sampler](https://github.com/sqshq/sampler) A tool for shell commands execution, visualization and alerting. Configured with a simple YAML file. +- [**6812**星][19d] [Shell] [awslabs/git-secrets](https://github.com/awslabs/git-secrets) Prevents you from committing secrets and credentials into git repositories +- [**6732**星][9m] [Java] [amitshekhariitbhu/android-debug-database](https://github.com/amitshekhariitbhu/android-debug-database) A library for debugging android databases and shared preferences - Make Debugging Great Again +- [**6683**星][3d] [Java] [zaproxy/zaproxy](https://github.com/zaproxy/zaproxy) 在开发和测试Web App时自动发现安全漏洞 +- [**6682**星][3y] [C++] [alibaba/andfix](https://github.com/alibaba/andfix) AndFix is a library that offer hot-fix for Android App. +- [**6668**星][12d] [C++] [keepassxreboot/keepassxc](https://github.com/keepassxreboot/keepassxc) KeePassXC is a cross-platform community-driven port of the Windows application “Keepass Password Safe”. +- [**6595**星][3d] [Py] [networkx/networkx](https://github.com/networkx/networkx) 用于创建、操纵和研究复杂网络的结构,Python包 +- [**6555**星][6m] [Go] [shadowsocks/shadowsocks-go](https://github.com/shadowsocks/shadowsocks-go) go port of shadowsocks (Deprecated) +- [**6518**星][1m] [Py] [h2y/shadowrocket-adblock-rules](https://github.com/h2y/shadowrocket-adblock-rules) 提供多款 Shadowrocket 规则,带广告过滤功能。用于 iOS 未越狱设备选择性地自动翻墙。 +- [**6462**星][5d] [Shell] [cisofy/lynis](https://github.com/cisofy/lynis) Security auditing tool for Linux, macOS, and UNIX-based systems. Assists with compliance testing (HIPAA/ISO27001/PCI DSS) and system hardening. Agentless, and installation optional. +- [**6451**星][17d] [Go] [bettercap/bettercap](https://github.com/bettercap/bettercap) 新版的bettercap, Go 编写. bettercap 是强大的、模块化、可移植且易于扩展的 MITM 框架, 旧版用 Ruby 编写 +- [**6448**星][9m] [HTML] [open-power-workgroup/hospital](https://github.com/open-power-workgroup/hospital) OpenPower工作组收集汇总的医院开放数据 +- [**6310**星][29d] [Py] [seatgeek/fuzzywuzzy](https://github.com/seatgeek/fuzzywuzzy) Fuzzy String Matching in Python +- [**6197**星][2m] [ObjC] [johnno1962/injectionforxcode](https://github.com/johnno1962/injectionforxcode) Runtime Code Injection for Objective-C & Swift +- [**6194**星][3y] [PS] [powershellmafia/powersploit](https://github.com/PowerShellMafia/PowerSploit) PowerSploit - A PowerShell Post-Exploitation Framework +- [**6192**星][2m] [Py] [yandex/gixy](https://github.com/yandex/gixy) Nginx 配置静态分析工具,防止配置错误导致安全问题,自动化错误配置检测 +- [**6187**星][6m] [rmerl/asuswrt-merlin](https://github.com/rmerl/asuswrt-merlin) Enhanced version of Asus's router firmware (Asuswrt) (legacy code base) +- [**6146**星][2d] [JS] [avwo/whistle](https://github.com/avwo/whistle) 基于Node实现的跨平台抓包调试代理工具(HTTP, HTTP2, HTTPS, Websocket) +- [**6137**星][1y] [Hack] [facebook/fbctf](https://github.com/facebook/fbctf) Platform to host Capture the Flag competitions +- [**6128**星][9m] [Py] [schollz/howmanypeoplearearound](https://github.com/schollz/howmanypeoplearearound) 检测 Wifi 信号统计你周围的人数 +- [**6092**星][15d] [Go] [usefathom/fathom](https://github.com/usefathom/fathom) Fathom Lite. Simple, privacy-focused website analytics. Built with Golang & Preact. +- [**6074**星][16d] [Go] [quay/clair](https://github.com/quay/clair) Vulnerability Static Analysis for Containers +- [**6074**星][16d] [Go] [quay/clair](https://github.com/quay/clair) clair:容器(appc、docker)漏洞静态分析工具。 +- [**6073**星][5m] [Java] [qihoo360/replugin](https://github.com/qihoo360/replugin) RePlugin - A flexible, stable, easy-to-use Android Plug-in Framework +- [**6070**星][2y] [C] [jgamblin/mirai-source-code](https://github.com/jgamblin/mirai-source-code) Leaked Mirai Source Code for Research/IoC Development Purposes +- [**6021**星][3d] [Py] [cyrus-and/gdb-dashboard](https://github.com/cyrus-and/gdb-dashboard) Modular visual interface for GDB in Python +- [**6017**星][7d] [berzerk0/probable-wordlists](https://github.com/berzerk0/probable-wordlists) Version 2 is live! Wordlists sorted by probability originally created for password generation and testing - make sure your passwords aren't popular! +- [**5972**星][2m] [Java] [google/android-classyshark](https://github.com/google/android-classyshark) 分析基于Android/Java的App或游戏 +- [**5968**星][2d] [Py] [gallopsled/pwntools](https://github.com/gallopsled/pwntools) CTF framework and exploit development library +- [**5942**星][6m] [JS] [haotian-wang/google-access-helper](https://github.com/haotian-wang/google-access-helper) 谷歌访问助手破解版 +- [**5888**星][2d] [Py] [asciimoo/searx](https://github.com/asciimoo/searx) searx:网络元数据搜索引擎。汇总70 多个搜索引擎的搜素结果,避免用户被追踪或者被分析。可与 Tor 结合使用 +- [**5879**星][2d] [C++] [radareorg/cutter](https://github.com/radareorg/cutter) 逆向框架 radare2的Qt界面,iaito的升级版 +- [**5871**星][2m] [Gnuplot] [nasa-jpl/open-source-rover](https://github.com/nasa-jpl/open-source-rover) A build-it-yourself, 6-wheel rover based on the rovers on Mars! +- [**5815**星][7m] [JS] [sindresorhus/fkill-cli](https://github.com/sindresorhus/fkill-cli) Fabulously kill processes. Cross-platform. +- [**5773**星][1y] [qinyuhang/shadowsocksx-ng-r](https://github.com/qinyuhang/shadowsocksx-ng-r) Next Generation of ShadowsocksX +- [**5766**星][3m] [ObjC] [square/ponydebugger](https://github.com/square/ponydebugger) Remote network and data debugging for your native iOS app using Chrome Developer Tools +- [**5762**星][2m] [C] [spacehuhn/esp8266_deauther](https://github.com/spacehuhn/esp8266_deauther) 使用ESP8266 制作Wifi干扰器 +- [**5742**星][2y] [Py] [newsapps/beeswithmachineguns](https://github.com/newsapps/beeswithmachineguns) 创建多个micro EC2实例, 攻击指定Web App +- [**5740**星][8m] [C] [xoreaxeaxeax/movfuscator](https://github.com/xoreaxeaxeax/movfuscator) C编译器,编译的二进制文件只有1个代码块。 +- [**5694**星][9d] [JS] [swagger-api/swagger-editor](https://github.com/swagger-api/swagger-editor) Swagger Editor +- [**5693**星][2d] [Go] [casbin/casbin](https://github.com/casbin/casbin) An authorization library that supports access control models like ACL, RBAC, ABAC in Golang +- [**5626**星][1m] [C] [rofl0r/proxychains-ng](https://github.com/rofl0r/proxychains-ng) proxychains ng (new generation) - a preloader which hooks calls to sockets in dynamically linked programs and redirects it through one or more socks/http proxies. continuation of the unmaintained proxychains project. the sf.net page is currently not updated, use releases from github release page instead. +- [**5593**星][10d] [Ruby] [presidentbeef/brakeman](https://github.com/presidentbeef/brakeman) ROR程序的静态分析工具 +- [**5565**星][29d] [Roff] [max2max/freess](https://github.com/max2max/freess) 免费ss账号 免费shadowsocks账号 免费v2ray账号 (长期更新) +- [**5540**星][20d] [rshipp/awesome-malware-analysis](https://github.com/rshipp/awesome-malware-analysis) A curated list of awesome malware analysis tools and resources. +- [**5476**星][8m] [carpedm20/awesome-hacking](https://github.com/carpedm20/awesome-hacking) Hacking教程、工具和资源 +- [**5417**星][2m] [Py] [axi0mx/ipwndfu](https://github.com/axi0mx/ipwndfu) open-source jailbreaking tool for many iOS devices +- [**5413**星][2y] [Rust] [autumnai/leaf](https://github.com/autumnai/leaf) Open Machine Intelligence Framework for Hackers. (GPU/CPU) +- [**5371**星][5m] [C] [pwn20wndstuff/undecimus](https://github.com/pwn20wndstuff/undecimus) unc0ver jailbreak for iOS 11.0 - 12.4 +- [**5371**星][2d] [Py] [mlflow/mlflow](https://github.com/mlflow/mlflow) Open source platform for the machine learning lifecycle +- [**5324**星][4d] [Go] [zricethezav/gitleaks](https://github.com/zricethezav/gitleaks) Audit git repos for secrets +- [**5205**星][7m] [Py] [usarmyresearchlab/dshell](https://github.com/usarmyresearchlab/dshell) 网络审计分析 +- [**5196**星][3m] [Py] [ytisf/thezoo](https://github.com/ytisf/thezoo) A repository of LIVE malwares for your own joy and pleasure. theZoo is a project created to make the possibility of malware analysis open and available to the public. +- [**5192**星][1m] [Py] [refirmlabs/binwalk](https://github.com/ReFirmLabs/binwalk) 固件分析工具(命令行+IDA插件) - [IDA插件](https://github.com/ReFirmLabs/binwalk/tree/master/src/scripts) - [binwalk](https://github.com/ReFirmLabs/binwalk/tree/master/src/binwalk) -- [**5165**星][1y] [JS] [samyk/poisontap](https://github.com/samyk/poisontap) Exploits locked/password protected computers over USB, drops persistent WebSocket-based backdoor, exposes internal router, and siphons cookies using Raspberry Pi Zero & Node.js. -- [**5163**星][3m] [Py] [ytisf/thezoo](https://github.com/ytisf/thezoo) A repository of LIVE malwares for your own joy and pleasure. theZoo is a project created to make the possibility of malware analysis open and available to the public. -- [**5121**星][13d] [PHP] [tennc/webshell](https://github.com/tennc/webshell) webshell收集 -- [**5111**星][18d] [Shell] [vulhub/vulhub](https://github.com/vulhub/vulhub) Pre-Built Vulnerable Environments Based on Docker-Compose -- [**5096**星][4m] [Py] [n1nj4sec/pupy](https://github.com/n1nj4sec/pupy) Pupy is an opensource, cross-platform (Windows, Linux, OSX, Android) remote administration and post-exploitation tool mainly written in python -- [**5092**星][19d] [C++] [avast/retdec](https://github.com/avast/retdec) 基于 LLVM 的可重定位机器码反编译器, 可检测壳、检测和重构C++类继承、重构函数/类型/结构体等、可反编译为 C 或 Python 2种高级语言格式 -- [**5067**星][2m] [sbilly/awesome-security](https://github.com/sbilly/awesome-security) 与安全相关的软件、库、文档、书籍、资源和工具等收集 -- [**5054**星][2m] [Shell] [stackexchange/blackbox](https://github.com/stackexchange/blackbox) 文件使用PGP加密后隐藏在Git/Mercurial/Subversion -- [**5036**星][8d] [Go] [dnscrypt/dnscrypt-proxy](https://github.com/DNSCrypt/dnscrypt-proxy) 灵活的DNS代理,支持现代的加密DNS协议,例如:DNS protocols such as DNSCrypt v2, DNS-over-HTTPS and Anonymized DNSCrypt. -- [**5028**星][1m] [Java] [meituan-dianping/walle](https://github.com/meituan-dianping/walle) Android Signature V2 Scheme签名下的新一代渠道包打包神器 -- [**5026**星][4y] [Py] [shadowsocksr-backup/shadowsocksr](https://github.com/shadowsocksr-backup/shadowsocksr) Python port of ShadowsocksR -- [**5023**星][4m] [PowerShell] [empireproject/empire](https://github.com/EmpireProject/Empire) 后渗透框架. Windows客户端用PowerShell, Linux/OSX用Python. 之前PowerShell Empire和Python EmPyre的组合 -- [**5010**星][15d] [HTML] [owasp/owasp-mstg](https://github.com/owasp/owasp-mstg) 关于移动App安全开发、测试和逆向的相近手册 -- [**4990**星][1m] [Py] [snare/voltron](https://github.com/snare/voltron) A hacky debugger UI for hackers -- [**4941**星][10d] [Go] [inlets/inlets](https://github.com/inlets/inlets) Expose your local endpoints to the Internet -- [**4928**星][13d] [ASP] [hq450/fancyss](https://github.com/hq450/fancyss) fancyss is a project providing tools to across the GFW on asuswrt/merlin based router. -- [**4924**星][20d] [Py] [trustedsec/social-engineer-toolkit](https://github.com/trustedsec/social-engineer-toolkit) The Social-Engineer Toolkit (SET) repository from TrustedSec - All new versions of SET will be deployed here. -- [**4909**星][1y] [Go] [yinghuocho/firefly-proxy](https://github.com/yinghuocho/firefly-proxy) A proxy software to help circumventing the Great Firewall. -- [**4892**星][11m] [Go] [bitly/oauth2_proxy](https://github.com/bitly/oauth2_proxy) 反向代理,静态文件服务器,提供Providers(Google/Github)认证 -- [**4872**星][2m] [Rust] [sharkdp/hexyl](https://github.com/sharkdp/hexyl) 命令行中查看hex -- [**4872**星][7m] [Java] [guardianproject/haven](https://github.com/guardianproject/haven) 通过Android应用和设备上的传感器保护自己的个人空间和财产而又不损害 -- [**4868**星][9d] [Shell] [denisidoro/navi](https://github.com/denisidoro/navi) An interactive cheatsheet tool for the command-line -- [**4862**星][7d] [JS] [mobsf/mobile-security-framework-mobsf](https://github.com/MobSF/Mobile-Security-Framework-MobSF) Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis. -- [**4838**星][10d] [Go] [gcla/termshark](https://github.com/gcla/termshark) A terminal UI for tshark, inspired by Wireshark -- [**4835**星][8d] [Py] [alessandroz/lazagne](https://github.com/alessandroz/lazagne) Credentials recovery project -- [**4816**星][10d] [C] [offensive-security/exploitdb](https://github.com/offensive-security/exploitdb) The official Exploit Database repository -- [**4793**星][8m] [Py] [10se1ucgo/disablewintracking](https://github.com/10se1ucgo/disablewintracking) Uses some known methods that attempt to minimize tracking in Windows 10 -- [**4771**星][7d] [C] [google/oss-fuzz](https://github.com/google/oss-fuzz) 开源软件fuzzing -- [**4752**星][7d] [C++] [facebook/redex](https://github.com/facebook/redex) Android App字节码优化器 -- [**4717**星][7d] [Swift] [yanue/v2rayu](https://github.com/yanue/v2rayu) V2rayU,基于v2ray核心的mac版客户端,用于科学上网,使用swift编写,支持vmess,shadowsocks,socks5等服务协议,支持订阅, 支持二维码,剪贴板导入,手动配置,二维码分享等 -- [**4710**星][8d] [C++] [paddlepaddle/paddle-lite](https://github.com/PaddlePaddle/Paddle-Lite) Multi-platform high performance deep learning inference engine (『飞桨』多平台高性能深度学习预测引擎) -- [**4675**星][7d] [C++] [coatisoftware/sourcetrail](https://github.com/coatisoftware/sourcetrail) Sourcetrail - free and open-source interactive source explorer -- [**4651**星][7d] [Py] [manisso/fsociety](https://github.com/manisso/fsociety) fsociety Hacking Tools Pack – A Penetration Testing Framework -- [**4630**星][6m] [powershell/win32-openssh](https://github.com/powershell/win32-openssh) Win32 port of OpenSSH -- [**4627**星][16d] [C] [google/ios-webkit-debug-proxy](https://github.com/google/ios-webkit-debug-proxy) A DevTools proxy (Chrome Remote Debugging Protocol) for iOS devices (Safari Remote Web Inspector). -- [**4616**星][8d] [JS] [beefproject/beef](https://github.com/beefproject/beef) The Browser Exploitation Framework Project -- [**4611**星][19d] [Py] [secdev/scapy](https://github.com/secdev/scapy) 交互式数据包操作, Python, 命令行+库 -- [**4575**星][11m] [Py] [ecthros/uncaptcha2](https://github.com/ecthros/uncaptcha2) defeating the latest version of ReCaptcha with 91% accuracy -- [**4574**星][10d] [Go] [ginuerzh/gost](https://github.com/ginuerzh/gost) GO语言实现的安全隧道 -- [**4551**星][1y] [C] [upx/upx](https://github.com/upx/upx) UPX - the Ultimate Packer for eXecutables -- [**4549**星][8d] [C++] [mozilla/rr](https://github.com/mozilla/rr) 记录与重放App的调试执行过程 -- [**4526**星][10d] [Ruby] [wpscanteam/wpscan](https://github.com/wpscanteam/wpscan) WPScan is a free, for non-commercial use, black box WordPress Vulnerability Scanner written for security professionals and blog maintainers to test the security of their WordPress websites. -- [**4523**星][12d] [C] [jedisct1/dsvpn](https://github.com/jedisct1/dsvpn) A Dead Simple VPN. -- [**4485**星][18d] [TypeScript] [apis-guru/graphql-voyager](https://github.com/apis-guru/graphql-voyager) -- [**4454**星][1y] [Go] [wallix/awless](https://github.com/wallix/awless) A Mighty CLI for AWS -- [**4444**星][16d] [Py] [jopohl/urh](https://github.com/jopohl/urh) Universal Radio Hacker: investigate wireless protocols like a boss -- [**4426**星][22d] [Py] [jofpin/trape](https://github.com/jofpin/trape) 学习在互联网上跟踪别人,获取其详细信息,并避免被别人跟踪 -- [**4398**星][9d] [Makefile] [frida/frida](https://github.com/frida/frida) Clone this repo to build Frida -- [**4387**星][2m] [Shell] [zardus/ctf-tools](https://github.com/zardus/ctf-tools) Some setup scripts for security research tools. -- [**4343**星][13d] [Swift] [signalapp/signal-ios](https://github.com/signalapp/Signal-iOS) A private messenger for iOS. -- [**4339**星][12m] [Py] [lennylxx/ipv6-hosts](https://github.com/lennylxx/ipv6-hosts) Fork of -- [**4310**星][29d] [JS] [cure53/dompurify](https://github.com/cure53/dompurify) a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify works with a secure default, but offers a lot of configurability and hooks. Demo: -- [**4307**星][5m] [Py] [diafygi/acme-tiny](https://github.com/diafygi/acme-tiny) A tiny script to issue and renew TLS certs from Let's Encrypt -- [**4262**星][1m] [Py] [tensorflow/cleverhans](https://github.com/tensorflow/cleverhans) Python库,基准测试(benchmark)机器学习系统的漏洞生成(to)对抗样本(adversarial examples) -- [**4261**星][1m] [Shell] [ashishb/android-security-awesome](https://github.com/ashishb/android-security-awesome) A collection of android security related resources -- [**4256**星][11m] [JS] [butterproject/butter-desktop](https://github.com/butterproject/butter-desktop) All the free parts of Popcorn Time -- [**4243**星][9d] [Rust] [timvisee/ffsend](https://github.com/timvisee/ffsend) Easily and securely share files from the command line -- [**4210**星][4m] [Py] [dxa4481/trufflehog](https://github.com/dxa4481/trufflehog) Searches through git repositories for high entropy strings and secrets, digging deep into commit history -- [**4195**星][16d] [Go] [gophish/gophish](https://github.com/gophish/gophish) 网络钓鱼工具包 -- [**4195**星][2m] [Py] [evilsocket/opensnitch](https://github.com/evilsocket/opensnitch) opensnitch:Little Snitch 应用程序防火墙的 GNU/Linux 版本。(Little Snitch:Mac操作系统的应用程序防火墙,能防止应用程序在你不知道的情况下自动访问网络) -- [**4190**星][7m] [Objective-C] [alonemonkey/monkeydev](https://github.com/alonemonkey/monkeydev) CaptainHook Tweak、Logos Tweak and Command-line Tool、Patch iOS Apps, Without Jailbreak. -- [**4186**星][9d] [qazbnm456/awesome-web-security](https://github.com/qazbnm456/awesome-web-security) web 安全资源列表 -- [**4183**星][1y] [Go] [michenriksen/gitrob](https://github.com/michenriksen/gitrob) 查找push到公开的Github repo中的敏感信息 -- [**4175**星][11d] [we5ter/scanners-box](https://github.com/we5ter/scanners-box) 安全行业从业者自研开源扫描器合辑 -- [**4165**星][2y] [forter/security-101-for-saas-startups](https://github.com/forter/security-101-for-saas-startups) 初学者安全小窍门 -- [**4148**星][12m] [JS] [kdzwinel/betwixt](https://github.com/kdzwinel/betwixt) Betwixt will help you analyze web traffic outside the browser using familiar Chrome DevTools interface. -- [**4105**星][5m] [Py] [spiderclub/haipproxy](https://github.com/spiderclub/haipproxy) -- [**4092**星][2m] [Py] [aboul3la/sublist3r](https://github.com/aboul3la/sublist3r) Fast subdomains enumeration tool for penetration testers -- [**4091**星][7d] [Java] [spring-projects/spring-security](https://github.com/spring-projects/spring-security) Spring Security -- [**4083**星][2y] [Py] [xoreaxeaxeax/sandsifter](https://github.com/xoreaxeaxeax/sandsifter) sandsifter:x86 处理器 Fuzzer,查找 Intel 的隐藏指令和 CPU bug -- [**4069**星][9m] [wtsxdev/reverse-engineering](https://github.com/wtsxdev/reverse-engineering) List of awesome reverse engineering resources -- [**4039**星][1m] [JS] [sigalor/whatsapp-web-reveng](https://github.com/sigalor/whatsapp-web-reveng) WhatsApp Web API逆向与重新实现 -- [**4033**星][7d] [Py] [google/clusterfuzz](https://github.com/google/clusterfuzz) Scalable fuzzing infrastructure. -- [**4023**星][2m] [Java] [jesusfreke/smali](https://github.com/jesusfreke/smali) smali/baksmali -- [**4015**星][3m] [JS] [cuckoosandbox/cuckoo](https://github.com/cuckoosandbox/cuckoo) Cuckoo Sandbox is an automated dynamic malware analysis system -- [**3989**星][1y] [JS] [travist/jsencrypt](https://github.com/travist/jsencrypt) A Javascript library to perform OpenSSL RSA Encryption, Decryption, and Key Generation. -- [**3985**星][20d] [drduh/yubikey-guide](https://github.com/drduh/yubikey-guide) Guide to using YubiKey for GPG and SSH -- [**3955**星][3m] [Py] [nullarray/autosploit](https://github.com/nullarray/autosploit) Automated Mass Exploiter -- [**3936**星][13d] [Go] [dexidp/dex](https://github.com/dexidp/dex) OpenID Connect Identity (OIDC) and OAuth 2.0 Provider with Pluggable Connectors -- [**3929**星][2m] [JS] [apsdehal/awesome-ctf](https://github.com/apsdehal/awesome-ctf) A curated list of CTF frameworks, libraries, resources and softwares -- [**3929**星][2m] [JS] [apsdehal/awesome-ctf](https://github.com/apsdehal/awesome-ctf) A curated list of CTF frameworks, libraries, resources and softwares -- [**3925**星][4m] [PHP] [paragonie/awesome-appsec](https://github.com/paragonie/awesome-appsec) A curated list of resources for learning about application security -- [**3916**星][7d] [Py] [angr/angr](https://github.com/angr/angr) A powerful and user-friendly binary analysis platform! -- [**3908**星][14d] [Rust] [svenstaro/genact](https://github.com/svenstaro/genact) a nonsense activity generator -- [**3907**星][1m] [C] [aquynh/capstone](https://github.com/aquynh/capstone) Capstone disassembly/disassembler framework: Core (Arm, Arm64, BPF, EVM, M68K, M680X, MOS65xx, Mips, PPC, RISCV, Sparc, SystemZ, TMS320C64x, Web Assembly, X86, X86_64, XCore) + bindings. -- [**3896**星][2y] [C#] [shadowsocksr-backup/shadowsocksr-csharp](https://github.com/shadowsocksr-backup/shadowsocksr-csharp) -- [**3876**星][7d] [C++] [baldurk/renderdoc](https://github.com/baldurk/renderdoc) RenderDoc is a stand-alone graphics debugging tool. -- [**3856**星][2m] [PHP] [fuzzdb-project/fuzzdb](https://github.com/fuzzdb-project/fuzzdb) 通过动态App安全测试来查找App安全漏洞, 算是不带扫描器的漏洞扫描器 -- [**3841**星][8m] [Go] [eranyanay/1m-go-websockets](https://github.com/eranyanay/1m-go-websockets) handling 1M websockets connections in Go -- [**3837**星][15d] [JS] [shadowsocks/shadowsocks-manager](https://github.com/shadowsocks/shadowsocks-manager) A shadowsocks manager tool for multi user and traffic control. -- [**3836**星][11d] [Py] [secureauthcorp/impacket](https://github.com/SecureAuthCorp/impacket) Python类收集, 用于与网络协议交互 -- [**3832**星][2m] [Objective-C] [sveinbjornt/sloth](https://github.com/sveinbjornt/sloth) Mac app that shows all open files, directories and sockets in use by all running processes. Nice GUI for lsof. -- [**3825**星][4y] [iosre/iosappreverseengineering](https://github.com/iosre/iosappreverseengineering) The world’s 1st book of very detailed iOS App reverse engineering skills :) -- [**3781**星][13d] [hq450/fancyss_history_package](https://github.com/hq450/fancyss_history_package) 科学上网插件的离线安装包储存在这里 -- [**3770**星][30d] [jivoi/awesome-osint](https://github.com/jivoi/awesome-osint) OSINT资源收集 -- [**3763**星][5y] [shadowsocksr-backup/shadowsocks-rss](https://github.com/shadowsocksr-backup/shadowsocks-rss) ShadowsocksR update rss, SSR organization -- [**3754**星][10m] [Py] [longld/peda](https://github.com/longld/peda) Python Exploit Development Assistance for GDB -- [**3749**星][2m] [Go] [microsoft/ethr](https://github.com/microsoft/ethr) Ethr is a Network Performance Measurement Tool for TCP, UDP & HTTP. -- [**3739**星][2m] [PHP] [ethicalhack3r/dvwa](https://github.com/ethicalhack3r/DVWA) Damn Vulnerable Web Application (DVWA) -- [**3739**星][2m] [Py] [paralax/awesome-honeypots](https://github.com/paralax/awesome-honeypots) an awesome list of honeypot resources -- [**3731**星][1m] [C] [iaik/meltdown](https://github.com/iaik/meltdown) This repository contains several applications, demonstrating the Meltdown bug. -- [**3731**星][13d] [Go] [hashicorp/consul-template](https://github.com/hashicorp/consul-template) Template rendering, notifier, and supervisor for -- [**3718**星][4m] [Py] [malwaredllc/byob](https://github.com/malwaredllc/byob) BYOB (Build Your Own Botnet) -- [**3681**星][11d] [jjqqkk/chromium](https://github.com/jjqqkk/chromium) Chromium browser with SSL VPN. Use this browser to unblock websites. -- [**3679**星][2y] [JS] [samyk/evercookie](https://github.com/samyk/evercookie) JavaScript API,在浏览器中创建超级顽固的cookie,在标准Cookie、Flask Cookie等被清除之后依然能够识别客户端 -- [**3675**星][8d] [HTML] [hamukazu/lets-get-arrested](https://github.com/hamukazu/lets-get-arrested) This project is intended to protest against the police in Japan -- [**3660**星][1y] [Py] [misterch0c/shadowbroker](https://github.com/misterch0c/shadowbroker) 方程式最新泄露 -- [**3653**星][4m] [C] [facebook/fishhook](https://github.com/facebook/fishhook) A library that enables dynamically rebinding symbols in Mach-O binaries running on iOS. -- [**3647**星][8d] [JS] [lesspass/lesspass](https://github.com/lesspass/lesspass) -- [**3645**星][26d] [C#] [0xd4d/de4dot](https://github.com/0xd4d/de4dot) .NET deobfuscator and unpacker. -- [**3640**星][4m] [C] [secwiki/windows-kernel-exploits](https://github.com/secwiki/windows-kernel-exploits) windows-kernel-exploits Windows平台提权漏洞集合 -- [**3639**星][2y] [Py] [qiyeboy/ipproxypool](https://github.com/qiyeboy/ipproxypool) IPProxyPool代理池项目,提供代理ip -- [**3624**星][29d] [acl4ssr/acl4ssr](https://github.com/acl4ssr/acl4ssr) SSR 去广告ACL规则/SS完整GFWList规则,Telegram频道订阅地址 -- [**3621**星][2m] [C] [atmosphere-nx/atmosphere](https://github.com/atmosphere-nx/atmosphere) Atmosphère is a work-in-progress customized firmware for the Nintendo Switch. -- [**3615**星][5y] [C#] [brandonlw/psychson](https://github.com/brandonlw/Psychson) Phison 2251-03 (2303) Custom Firmware & Existing Firmware Patches (BadUSB) -- [**3612**星][17d] [HTML] [consensys/smart-contract-best-practices](https://github.com/consensys/smart-contract-best-practices) A guide to smart contract security best practices -- [**3598**星][8d] [TypeScript] [javascript-obfuscator/javascript-obfuscator](https://github.com/javascript-obfuscator/javascript-obfuscator) A powerful obfuscator for JavaScript and Node.js +- [**5167**星][20d] [Shell] [vulhub/vulhub](https://github.com/vulhub/vulhub) Pre-Built Vulnerable Environments Based on Docker-Compose +- [**5167**星][1y] [JS] [samyk/poisontap](https://github.com/samyk/poisontap) Exploits locked/password protected computers over USB, drops persistent WebSocket-based backdoor, exposes internal router, and siphons cookies using Raspberry Pi Zero & Node.js. +- [**5148**星][6d] [PHP] [tennc/webshell](https://github.com/tennc/webshell) webshell收集 +- [**5123**星][21d] [C++] [avast/retdec](https://github.com/avast/retdec) 基于 LLVM 的可重定位机器码反编译器, 可检测壳、检测和重构C++类继承、重构函数/类型/结构体等、可反编译为 C 或 Python 2种高级语言格式 +- [**5118**星][15d] [ObjC] [macpass/macpass](https://github.com/MacPass/MacPass) A native OS X KeePass client +- [**5118**星][4m] [Py] [n1nj4sec/pupy](https://github.com/n1nj4sec/pupy) Pupy is an opensource, cross-platform (Windows, Linux, OSX, Android) remote administration and post-exploitation tool mainly written in python +- [**5089**星][2d] [Go] [dnscrypt/dnscrypt-proxy](https://github.com/DNSCrypt/dnscrypt-proxy) 灵活的DNS代理,支持现代的加密DNS协议,例如:DNS protocols such as DNSCrypt v2, DNS-over-HTTPS and Anonymized DNSCrypt. +- [**5082**星][2m] [sbilly/awesome-security](https://github.com/sbilly/awesome-security) 与安全相关的软件、库、文档、书籍、资源和工具等收集 +- [**5065**星][2m] [Shell] [stackexchange/blackbox](https://github.com/stackexchange/blackbox) 文件使用PGP加密后隐藏在Git/Mercurial/Subversion +- [**5059**星][1m] [Java] [meituan-dianping/walle](https://github.com/meituan-dianping/walle) Android Signature V2 Scheme签名下的新一代渠道包打包神器 +- [**5054**星][4y] [Py] [shadowsocksr-backup/shadowsocksr](https://github.com/shadowsocksr-backup/shadowsocksr) Python port of ShadowsocksR +- [**5042**星][2d] [HTML] [owasp/owasp-mstg](https://github.com/owasp/owasp-mstg) 关于移动App安全开发、测试和逆向的相近手册 +- [**5037**星][4m] [PS] [empireproject/empire](https://github.com/EmpireProject/Empire) 后渗透框架. Windows客户端用PowerShell, Linux/OSX用Python. 之前PowerShell Empire和Python EmPyre的组合 +- [**5021**星][2d] [Py] [mobsf/mobile-security-framework-mobsf](https://github.com/MobSF/Mobile-Security-Framework-MobSF) Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis. +- [**5005**星][2d] [C++] [coatisoftware/sourcetrail](https://github.com/coatisoftware/sourcetrail) Sourcetrail - free and open-source interactive source explorer +- [**4996**星][2d] [ASP] [hq450/fancyss](https://github.com/hq450/fancyss) fancyss is a project providing tools to across the GFW on asuswrt/merlin based router. +- [**4996**星][6d] [Go] [inlets/inlets](https://github.com/inlets/inlets) Expose your local endpoints to the Internet +- [**4994**星][1m] [Py] [snare/voltron](https://github.com/snare/voltron) A hacky debugger UI for hackers +- [**4953**星][22d] [Py] [trustedsec/social-engineer-toolkit](https://github.com/trustedsec/social-engineer-toolkit) The Social-Engineer Toolkit (SET) repository from TrustedSec - All new versions of SET will be deployed here. +- [**4920**星][2d] [TS] [jigsaw-code/outline-client](https://github.com/jigsaw-code/outline-client) Outline clients, developed by Jigsaw. The Outline clients use the popular Shadowsocks protocol, and lean on the Cordova and Electron frameworks to support Windows, Android / ChromeOS, Linux, iOS and macOS. +- [**4913**星][1y] [Go] [yinghuocho/firefly-proxy](https://github.com/yinghuocho/firefly-proxy) A proxy software to help circumventing the Great Firewall. +- [**4909**星][2d] [Shell] [denisidoro/navi](https://github.com/denisidoro/navi) An interactive cheatsheet tool for the command-line +- [**4897**星][11m] [Go] [bitly/oauth2_proxy](https://github.com/bitly/oauth2_proxy) 反向代理,静态文件服务器,提供Providers(Google/Github)认证 +- [**4883**星][2m] [Rust] [sharkdp/hexyl](https://github.com/sharkdp/hexyl) 命令行中查看hex +- [**4881**星][5d] [Java] [guardianproject/haven](https://github.com/guardianproject/haven) 通过Android应用和设备上的传感器保护自己的个人空间和财产而又不损害 +- [**4869**星][2d] [Swift] [yanue/v2rayu](https://github.com/yanue/v2rayu) V2rayU,基于v2ray核心的mac版客户端,用于科学上网,使用swift编写,支持vmess,shadowsocks,socks5等服务协议,支持订阅, 支持二维码,剪贴板导入,手动配置,二维码分享等 +- [**4867**星][10d] [Py] [alessandroz/lazagne](https://github.com/alessandroz/lazagne) Credentials recovery project +- [**4847**星][3d] [Go] [gcla/termshark](https://github.com/gcla/termshark) A terminal UI for tshark, inspired by Wireshark +- [**4841**星][2d] [C] [offensive-security/exploitdb](https://github.com/offensive-security/exploitdb) The official Exploit Database repository +- [**4803**星][8m] [Py] [10se1ucgo/disablewintracking](https://github.com/10se1ucgo/disablewintracking) Uses some known methods that attempt to minimize tracking in Windows 10 +- [**4782**星][2d] [C] [google/oss-fuzz](https://github.com/google/oss-fuzz) 开源软件fuzzing +- [**4761**星][2d] [C++] [facebook/redex](https://github.com/facebook/redex) Android App字节码优化器 +- [**4724**星][2d] [C++] [paddlepaddle/paddle-lite](https://github.com/PaddlePaddle/Paddle-Lite) Multi-platform high performance deep learning inference engine (『飞桨』多平台高性能深度学习预测引擎) +- [**4691**星][9d] [Py] [manisso/fsociety](https://github.com/manisso/fsociety) fsociety Hacking Tools Pack – A Penetration Testing Framework +- [**4639**星][3d] [Py] [secdev/scapy](https://github.com/secdev/scapy) 交互式数据包操作, Python, 命令行+库 +- [**4638**星][18d] [C] [google/ios-webkit-debug-proxy](https://github.com/google/ios-webkit-debug-proxy) A DevTools proxy (Chrome Remote Debugging Protocol) for iOS devices (Safari Remote Web Inspector). +- [**4637**星][6m] [powershell/win32-openssh](https://github.com/powershell/win32-openssh) Win32 port of OpenSSH +- [**4633**星][2d] [JS] [beefproject/beef](https://github.com/beefproject/beef) The Browser Exploitation Framework Project +- [**4615**星][12d] [Go] [ginuerzh/gost](https://github.com/ginuerzh/gost) GO语言实现的安全隧道 +- [**4589**星][11m] [Py] [ecthros/uncaptcha2](https://github.com/ecthros/uncaptcha2) defeating the latest version of ReCaptcha with 91% accuracy +- [**4583**星][1y] [C] [upx/upx](https://github.com/upx/upx) UPX - the Ultimate Packer for eXecutables +- [**4575**星][4d] [C++] [mozilla/rr](https://github.com/mozilla/rr) 记录与重放App的调试执行过程 +- [**4543**星][4d] [Ruby] [wpscanteam/wpscan](https://github.com/wpscanteam/wpscan) WPScan is a free, for non-commercial use, black box WordPress Vulnerability Scanner written for security professionals and blog maintainers to test the security of their WordPress websites. +- [**4529**星][6d] [C] [jedisct1/dsvpn](https://github.com/jedisct1/dsvpn) A Dead Simple VPN. +- [**4498**星][6d] [TS] [apis-guru/graphql-voyager](https://github.com/apis-guru/graphql-voyager) +- [**4459**星][8d] [Py] [jopohl/urh](https://github.com/jopohl/urh) Universal Radio Hacker: investigate wireless protocols like a boss +- [**4458**星][1y] [Go] [wallix/awless](https://github.com/wallix/awless) A Mighty CLI for AWS +- [**4449**星][3d] [Go] [dragonflyoss/dragonfly](https://github.com/dragonflyoss/Dragonfly) Dragonfly is an intelligent P2P based image and file distribution system. +- [**4446**星][2d] [Makefile] [frida/frida](https://github.com/frida/frida) Clone this repo to build Frida +- [**4443**星][24d] [Py] [jofpin/trape](https://github.com/jofpin/trape) 学习在互联网上跟踪别人,获取其详细信息,并避免被别人跟踪 +- [**4411**星][2m] [Shell] [zardus/ctf-tools](https://github.com/zardus/ctf-tools) Some setup scripts for security research tools. +- [**4359**星][6d] [Swift] [signalapp/signal-ios](https://github.com/signalapp/Signal-iOS) A private messenger for iOS. +- [**4346**星][1m] [JS] [cure53/dompurify](https://github.com/cure53/dompurify) a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG. DOMPurify works with a secure default, but offers a lot of configurability and hooks. Demo: +- [**4344**星][12m] [Py] [lennylxx/ipv6-hosts](https://github.com/lennylxx/ipv6-hosts) Fork of +- [**4313**星][5m] [Py] [diafygi/acme-tiny](https://github.com/diafygi/acme-tiny) A tiny script to issue and renew TLS certs from Let's Encrypt +- [**4283**星][7d] [Py] [tensorflow/cleverhans](https://github.com/tensorflow/cleverhans) Python库,基准测试(benchmark)机器学习系统的漏洞生成(to)对抗样本(adversarial examples) +- [**4280**星][1m] [Shell] [ashishb/android-security-awesome](https://github.com/ashishb/android-security-awesome) A collection of android security related resources +- [**4261**星][5d] [Rust] [timvisee/ffsend](https://github.com/timvisee/ffsend) Easily and securely share files from the command line +- [**4258**星][11m] [JS] [butterproject/butter-desktop](https://github.com/butterproject/butter-desktop) All the free parts of Popcorn Time +- [**4244**星][2y] [imeiji/shadowsocks_install](https://github.com/imeiji/shadowsocks_install) Auto install shadowsocks server,thanks 秋水逸冰 +- [**4241**星][4m] [Py] [dxa4481/trufflehog](https://github.com/dxa4481/trufflehog) Searches through git repositories for high entropy strings and secrets, digging deep into commit history +- [**4215**星][7m] [ObjC] [alonemonkey/monkeydev](https://github.com/alonemonkey/monkeydev) CaptainHook Tweak、Logos Tweak and Command-line Tool、Patch iOS Apps, Without Jailbreak. +- [**4211**星][9d] [Go] [gophish/gophish](https://github.com/gophish/gophish) 网络钓鱼工具包 +- [**4205**星][11d] [qazbnm456/awesome-web-security](https://github.com/qazbnm456/awesome-web-security) web 安全资源列表 +- [**4204**星][1y] [Go] [michenriksen/gitrob](https://github.com/michenriksen/gitrob) 查找push到公开的Github repo中的敏感信息 +- [**4202**星][2m] [Py] [evilsocket/opensnitch](https://github.com/evilsocket/opensnitch) opensnitch:Little Snitch 应用程序防火墙的 GNU/Linux 版本。(Little Snitch:Mac操作系统的应用程序防火墙,能防止应用程序在你不知道的情况下自动访问网络) +- [**4198**星][2d] [Py] [openmined/pysyft](https://github.com/openmined/pysyft) A library for encrypted, privacy preserving machine learning +- [**4190**星][13d] [we5ter/scanners-box](https://github.com/we5ter/scanners-box) 安全行业从业者自研开源扫描器合辑 +- [**4171**星][2y] [forter/security-101-for-saas-startups](https://github.com/forter/security-101-for-saas-startups) 初学者安全小窍门 +- [**4149**星][12m] [JS] [kdzwinel/betwixt](https://github.com/kdzwinel/betwixt) Betwixt will help you analyze web traffic outside the browser using familiar Chrome DevTools interface. +- [**4131**星][5d] [Java] [spring-projects/spring-security](https://github.com/spring-projects/spring-security) Spring Security +- [**4120**星][5m] [Py] [spiderclub/haipproxy](https://github.com/spiderclub/haipproxy) +- [**4120**星][2m] [Py] [aboul3la/sublist3r](https://github.com/aboul3la/sublist3r) Fast subdomains enumeration tool for penetration testers +- [**4096**星][2y] [Py] [xoreaxeaxeax/sandsifter](https://github.com/xoreaxeaxeax/sandsifter) sandsifter:x86 处理器 Fuzzer,查找 Intel 的隐藏指令和 CPU bug +- [**4092**星][9m] [wtsxdev/reverse-engineering](https://github.com/wtsxdev/reverse-engineering) List of awesome reverse engineering resources +- [**4046**星][1m] [JS] [sigalor/whatsapp-web-reveng](https://github.com/sigalor/whatsapp-web-reveng) WhatsApp Web API逆向与重新实现 +- [**4045**星][2m] [Java] [jesusfreke/smali](https://github.com/jesusfreke/smali) smali/baksmali +- [**4044**星][2d] [Py] [google/clusterfuzz](https://github.com/google/clusterfuzz) Scalable fuzzing infrastructure. +- [**4022**星][22d] [drduh/yubikey-guide](https://github.com/drduh/yubikey-guide) Guide to using YubiKey for GPG and SSH +- [**4021**星][3m] [JS] [cuckoosandbox/cuckoo](https://github.com/cuckoosandbox/cuckoo) Cuckoo Sandbox is an automated dynamic malware analysis system +- [**4000**星][1y] [JS] [travist/jsencrypt](https://github.com/travist/jsencrypt) A Javascript library to perform OpenSSL RSA Encryption, Decryption, and Key Generation. +- [**3967**星][3m] [Py] [nullarray/autosploit](https://github.com/nullarray/autosploit) Automated Mass Exploiter +- [**3961**星][5d] [Go] [dexidp/dex](https://github.com/dexidp/dex) OpenID Connect Identity (OIDC) and OAuth 2.0 Provider with Pluggable Connectors +- [**3953**星][2m] [JS] [apsdehal/awesome-ctf](https://github.com/apsdehal/awesome-ctf) A curated list of CTF frameworks, libraries, resources and softwares +- [**3953**星][2m] [JS] [apsdehal/awesome-ctf](https://github.com/apsdehal/awesome-ctf) A curated list of CTF frameworks, libraries, resources and softwares +- [**3937**星][3d] [Py] [angr/angr](https://github.com/angr/angr) A powerful and user-friendly binary analysis platform! +- [**3935**星][4m] [PHP] [paragonie/awesome-appsec](https://github.com/paragonie/awesome-appsec) A curated list of resources for learning about application security +- [**3933**星][8m] [Go] [eranyanay/1m-go-websockets](https://github.com/eranyanay/1m-go-websockets) handling 1M websockets connections in Go +- [**3923**星][1m] [C] [aquynh/capstone](https://github.com/aquynh/capstone) Capstone disassembly/disassembler framework: Core (Arm, Arm64, BPF, EVM, M68K, M680X, MOS65xx, Mips, PPC, RISCV, Sparc, SystemZ, TMS320C64x, Web Assembly, X86, X86_64, XCore) + bindings. +- [**3920**星][2y] [C#] [shadowsocksr-backup/shadowsocksr-csharp](https://github.com/shadowsocksr-backup/shadowsocksr-csharp) +- [**3915**星][16d] [Rust] [svenstaro/genact](https://github.com/svenstaro/genact) a nonsense activity generator +- [**3893**星][2d] [C++] [baldurk/renderdoc](https://github.com/baldurk/renderdoc) RenderDoc is a stand-alone graphics debugging tool. +- [**3878**星][2m] [PHP] [fuzzdb-project/fuzzdb](https://github.com/fuzzdb-project/fuzzdb) 通过动态App安全测试来查找App安全漏洞, 算是不带扫描器的漏洞扫描器 +- [**3869**星][2d] [Py] [secureauthcorp/impacket](https://github.com/SecureAuthCorp/impacket) Python类收集, 用于与网络协议交互 +- [**3848**星][7d] [JS] [shadowsocks/shadowsocks-manager](https://github.com/shadowsocks/shadowsocks-manager) A shadowsocks manager tool for multi user and traffic control. +- [**3845**星][2d] [hq450/fancyss_history_package](https://github.com/hq450/fancyss_history_package) 科学上网插件的离线安装包储存在这里 +- [**3838**星][2m] [ObjC] [sveinbjornt/sloth](https://github.com/sveinbjornt/sloth) Mac app that shows all open files, directories and sockets in use by all running processes. Nice GUI for lsof. +- [**3831**星][4y] [iosre/iosappreverseengineering](https://github.com/iosre/iosappreverseengineering) The world’s 1st book of very detailed iOS App reverse engineering skills :) +- [**3813**星][1m] [jivoi/awesome-osint](https://github.com/jivoi/awesome-osint) OSINT资源收集 +- [**3799**星][5y] [shadowsocksr-backup/shadowsocks-rss](https://github.com/shadowsocksr-backup/shadowsocks-rss) ShadowsocksR update rss, SSR organization +- [**3767**星][10m] [Py] [longld/peda](https://github.com/longld/peda) Python Exploit Development Assistance for GDB +- [**3763**星][2m] [Py] [paralax/awesome-honeypots](https://github.com/paralax/awesome-honeypots) an awesome list of honeypot resources +- [**3755**星][2m] [PHP] [ethicalhack3r/dvwa](https://github.com/ethicalhack3r/DVWA) Damn Vulnerable Web Application (DVWA) +- [**3752**星][2m] [Go] [microsoft/ethr](https://github.com/microsoft/ethr) Ethr is a Network Performance Measurement Tool for TCP, UDP & HTTP. +- [**3736**星][8d] [Go] [hashicorp/consul-template](https://github.com/hashicorp/consul-template) Template rendering, notifier, and supervisor for +- [**3733**星][2m] [C] [iaik/meltdown](https://github.com/iaik/meltdown) This repository contains several applications, demonstrating the Meltdown bug. +- [**3730**星][4m] [Py] [malwaredllc/byob](https://github.com/malwaredllc/byob) BYOB (Build Your Own Botnet) +- [**3719**星][6d] [jjqqkk/chromium](https://github.com/jjqqkk/chromium) Chromium browser with SSL VPN. Use this browser to unblock websites. +- [**3713**星][2d] [C] [atmosphere-nx/atmosphere](https://github.com/atmosphere-nx/atmosphere) Atmosphère is a work-in-progress customized firmware for the Nintendo Switch. +- [**3684**星][2y] [JS] [samyk/evercookie](https://github.com/samyk/evercookie) JavaScript API,在浏览器中创建超级顽固的cookie,在标准Cookie、Flask Cookie等被清除之后依然能够识别客户端 +- [**3682**星][10d] [HTML] [hamukazu/lets-get-arrested](https://github.com/hamukazu/lets-get-arrested) This project is intended to protest against the police in Japan +- [**3670**星][2d] [JS] [lesspass/lesspass](https://github.com/lesspass/lesspass) +- [**3668**星][8d] [C#] [0xd4d/de4dot](https://github.com/0xd4d/de4dot) .NET deobfuscator and unpacker. +- [**3667**星][1y] [Py] [misterch0c/shadowbroker](https://github.com/misterch0c/shadowbroker) 方程式最新泄露 +- [**3666**星][5m] [C] [secwiki/windows-kernel-exploits](https://github.com/secwiki/windows-kernel-exploits) windows-kernel-exploits Windows平台提权漏洞集合 +- [**3663**星][4m] [C] [facebook/fishhook](https://github.com/facebook/fishhook) A library that enables dynamically rebinding symbols in Mach-O binaries running on iOS. +- [**3652**星][4d] [acl4ssr/acl4ssr](https://github.com/acl4ssr/acl4ssr) SSR 去广告ACL规则/SS完整GFWList规则,Telegram频道订阅地址 +- [**3647**星][2y] [Py] [qiyeboy/ipproxypool](https://github.com/qiyeboy/ipproxypool) IPProxyPool代理池项目,提供代理ip +- [**3622**星][6d] [TS] [javascript-obfuscator/javascript-obfuscator](https://github.com/javascript-obfuscator/javascript-obfuscator) A powerful obfuscator for JavaScript and Node.js +- [**3621**星][7d] [HTML] [consensys/smart-contract-best-practices](https://github.com/consensys/smart-contract-best-practices) A guide to smart contract security best practices +- [**3619**星][5y] [C#] [brandonlw/psychson](https://github.com/brandonlw/Psychson) Phison 2251-03 (2303) Custom Firmware & Existing Firmware Patches (BadUSB) +- [**3611**星][2m] [Java] [ffay/lanproxy](https://github.com/ffay/lanproxy) lanproxy是一个将局域网个人电脑、服务器代理到公网的内网穿透工具,支持tcp流量转发,可支持任何tcp上层协议(访问内网网站、本地支付接口调试、ssh访问、远程桌面...)。目前市面上提供类似服务的有花生壳、TeamView、GoToMyCloud等等,但要使用第三方的公网服务器就必须为第三方付费,并且这些服务都有各种各样的限制,此外,由于数据包会流经第三方,因此对数据安全也是一大隐患。技术交流QQ群 946273429 +- [**3604**星][8d] [PS] [bloodhoundad/bloodhound](https://github.com/BloodHoundAD/BloodHound) a single page Javascript web application, uses graph theory to reveal the hidden and often unintended relationships within an Active Directory environment. +- [**3598**星][26d] [C++] [anbox/anbox](https://github.com/anbox/anbox) 在常规GNU / Linux系统上引导完整的Android系统,基于容器 - [**3597**星][1y] [C#] [nummer/destroy-windows-10-spying](https://github.com/nummer/destroy-windows-10-spying) Destroy Windows Spying tool -- [**3594**星][2m] [Java] [ffay/lanproxy](https://github.com/ffay/lanproxy) lanproxy是一个将局域网个人电脑、服务器代理到公网的内网穿透工具,支持tcp流量转发,可支持任何tcp上层协议(访问内网网站、本地支付接口调试、ssh访问、远程桌面...)。目前市面上提供类似服务的有花生壳、TeamView、GoToMyCloud等等,但要使用第三方的公网服务器就必须为第三方付费,并且这些服务都有各种各样的限制,此外,由于数据包会流经第三方,因此对数据安全也是一大隐患。技术交流QQ群 946273429 -- [**3591**星][3y] [Perl] [x0rz/eqgrp](https://github.com/x0rz/eqgrp) Decrypted content of eqgrp-auction-file.tar.xz -- [**3587**星][2m] [PowerShell] [bloodhoundad/bloodhound](https://github.com/BloodHoundAD/BloodHound) a single page Javascript web application, uses graph theory to reveal the hidden and often unintended relationships within an Active Directory environment. -- [**3578**星][24d] [C++] [anbox/anbox](https://github.com/anbox/anbox) 在常规GNU / Linux系统上引导完整的Android系统,基于容器 -- [**3565**星][7d] [Shell] [drwetter/testssl.sh](https://github.com/drwetter/testssl.sh) 检查服务器任意端口对 TLS/SSL 的支持、协议以及一些加密缺陷,命令行工具 -- [**3560**星][17d] [C] [nmap/nmap](https://github.com/nmap/nmap) Nmap -- [**3544**星][6y] [R] [johnmyleswhite/ml_for_hackers](https://github.com/johnmyleswhite/ml_for_hackers) 《Machine Learning for Hackers》随书代码 +- [**3595**星][3y] [Perl] [x0rz/eqgrp](https://github.com/x0rz/eqgrp) Decrypted content of eqgrp-auction-file.tar.xz +- [**3583**星][3d] [Shell] [drwetter/testssl.sh](https://github.com/drwetter/testssl.sh) 检查服务器任意端口对 TLS/SSL 的支持、协议以及一些加密缺陷,命令行工具 +- [**3580**星][5d] [C] [nmap/nmap](https://github.com/nmap/nmap) Nmap +- [**3562**星][5d] [Pascal] [cheat-engine/cheat-engine](https://github.com/cheat-engine/cheat-engine) Cheat Engine. A development environment focused on modding +- [**3542**星][6y] [R] [johnmyleswhite/ml_for_hackers](https://github.com/johnmyleswhite/ml_for_hackers) 《Machine Learning for Hackers》随书代码 +- [**3540**星][6d] [blacckhathaceekr/pentesting-bible](https://github.com/blacckhathaceekr/pentesting-bible) links reaches 10000 links & 10000 pdf files .Learn Ethical Hacking and penetration testing .hundreds of ethical hacking & penetration testing & red team & cyber security & computer science resources. - [**3538**星][4m] [Shell] [chengr28/revokechinacerts](https://github.com/chengr28/revokechinacerts) Revoke Chinese certificates. -- [**3525**星][8d] [Pascal] [cheat-engine/cheat-engine](https://github.com/cheat-engine/cheat-engine) Cheat Engine. A development environment focused on modding -- [**3503**星][14d] [JS] [aol/moloch](https://github.com/aol/moloch) 数据包捕获、索引工具,支持数据库 -- [**3494**星][8m] [Go] [fanpei91/torsniff](https://github.com/fanpei91/torsniff) torsniff - a sniffer that sniffs torrents from BitTorrent network -- [**3494**星][8m] [Go] [fanpei91/torsniff](https://github.com/fanpei91/torsniff) 从BitTorrent网络嗅探种子 -- [**3493**星][3y] [C] [hak5darren/usb-rubber-ducky](https://github.com/hak5darren/usb-rubber-ducky) -- [**3482**星][9m] [C] [rpisec/mbe](https://github.com/rpisec/mbe) Course materials for Modern Binary Exploitation by RPISEC -- [**3481**星][13d] [blacckhathaceekr/pentesting-bible](https://github.com/blacckhathaceekr/pentesting-bible) links reaches 10000 links & 10000 pdf files .Learn Ethical Hacking and penetration testing .hundreds of ethical hacking & penetration testing & red team & cyber security & computer science resources. -- [**3468**星][5m] [PHP] [hanc00l/wooyun_public](https://github.com/hanc00l/wooyun_public) This repo is archived. Thanks for wooyun! 乌云公开漏洞、知识库爬虫和搜索 crawl and search for wooyun.org public bug(vulnerability) and drops -- [**3464**星][15d] [C] [cyan4973/xxhash](https://github.com/cyan4973/xxhash) Extremely fast non-cryptographic hash algorithm -- [**3436**星][7d] [C] [shellphish/how2heap](https://github.com/shellphish/how2heap) 学习各种堆利用技巧的repo -- [**3431**星][13d] [Java] [meituan-dianping/robust](https://github.com/meituan-dianping/robust) Robust is an Android HotFix solution with high compatibility and high stability. Robust can fix bugs immediately without a reboot. -- [**3421**星][13d] [Perl] [sullo/nikto](https://github.com/sullo/nikto) Nikto web server scanner -- [**3412**星][25d] [icodesign/potatso](https://github.com/icodesign/Potatso) Potatso is an iOS client that implements different proxies with the leverage of NetworkExtension framework in iOS 10+. -- [**3392**星][5m] [Go] [jpillora/chisel](https://github.com/jpillora/chisel) 基于HTTP的快速 TCP 隧道 -- [**3387**星][2y] [shadowsocksrr/shadowsocks-rss](https://github.com/shadowsocksrr/shadowsocks-rss) ShadowsocksR update rss, SSR organization -- [**3383**星][22d] [PowerShell] [samratashok/nishang](https://github.com/samratashok/nishang) 渗透框架,脚本和Payload收集,主要是PowerShell,涵盖渗透的各个阶段 -- [**3326**星][13d] [Py] [google/grr](https://github.com/google/grr) remote live forensics for incident response -- [**3325**星][5m] [C++] [wangyu-/udp2raw-tunnel](https://github.com/wangyu-/udp2raw-tunnel) udp 打洞。通过raw socket给UDP包加上TCP或ICMP header,进而绕过UDP屏蔽或QoS,或在UDP不稳定的环境下提升稳定性 -- [**3325**星][7d] [jivoi/awesome-ml-for-cybersecurity](https://github.com/jivoi/awesome-ml-for-cybersecurity) 针对网络安全的机器学习资源列表 -- [**3317**星][7d] [Py] [stamparm/maltrail](https://github.com/stamparm/maltrail) 恶意网络流量检测系统 -- [**3317**星][2y] [scanate/ethlist](https://github.com/scanate/ethlist) The Comprehensive Ethereum Reading List -- [**3316**星][2m] [C] [screetsec/thefatrat](https://github.com/screetsec/thefatrat) Thefatrat a massive exploiting tool : Easy tool to generate backdoor and easy tool to post exploitation attack like browser attack and etc . This tool compiles a malware with popular payload and then the compiled malware can be execute on windows, android, mac . The malware that created with this tool also have an ability to bypass most AV softw… -- [**3282**星][8d] [Smarty] [anankke/sspanel-uim](https://github.com/anankke/sspanel-uim) 专为 Shadowsocks / ShadowsocksR / V2Ray 设计的多用户管理面板 -- [**3280**星][2m] [Swift] [yagiz/bagel](https://github.com/yagiz/bagel) a little native network debugging tool for iOS -- [**3280**星][20d] [C] [vanhauser-thc/thc-hydra](https://github.com/vanhauser-thc/thc-hydra) 网络登录破解,支持多种服务 -- [**3269**星][27d] [C] [microsoft/windows-driver-samples](https://github.com/microsoft/windows-driver-samples) This repo contains driver samples prepared for use with Microsoft Visual Studio and the Windows Driver Kit (WDK). It contains both Universal Windows Driver and desktop-only driver samples. -- [**3267**星][3m] [C] [nbs-system/naxsi](https://github.com/nbs-system/naxsi) NAXSI is an open-source, high performance, low rules maintenance WAF for NGINX -- [**3266**星][12d] [C] [virustotal/yara](https://github.com/virustotal/yara) The pattern matching swiss knife -- [**3258**星][2m] [Py] [volatilityfoundation/volatility](https://github.com/volatilityfoundation/volatility) An advanced memory forensics framework -- [**3258**星][5y] [C++] [google/lmctfy](https://github.com/google/lmctfy) lmctfy is the open source version of Google’s container stack, which provides Linux application containers. -- [**3255**星][7d] [C] [mikebrady/shairport-sync](https://github.com/mikebrady/shairport-sync) AirPlay audio player. Shairport Sync adds multi-room capability with Audio Synchronisation -- [**3253**星][7m] [JS] [sindresorhus/speed-test](https://github.com/sindresorhus/speed-test) Test your internet connection speed and ping using speedtest.net from the CLI -- [**3234**星][8d] [Java] [oldmanpushcart/greys-anatomy](https://github.com/oldmanpushcart/greys-anatomy) Java诊断工具 +- [**3533**星][14d] [C] [tencent/tencentos-tiny](https://github.com/tencent/tencentos-tiny) 腾讯物联网终端操作系统 +- [**3514**星][3y] [C] [hak5darren/usb-rubber-ducky](https://github.com/hak5darren/usb-rubber-ducky) +- [**3510**星][2d] [JS] [aol/moloch](https://github.com/aol/moloch) 数据包捕获、索引工具,支持数据库 +- [**3501**星][8m] [Go] [fanpei91/torsniff](https://github.com/fanpei91/torsniff) torsniff - a sniffer that sniffs torrents from BitTorrent network +- [**3501**星][8m] [Go] [fanpei91/torsniff](https://github.com/fanpei91/torsniff) 从BitTorrent网络嗅探种子 +- [**3493**星][9m] [C] [rpisec/mbe](https://github.com/rpisec/mbe) Course materials for Modern Binary Exploitation by RPISEC +- [**3485**星][5m] [PHP] [hanc00l/wooyun_public](https://github.com/hanc00l/wooyun_public) This repo is archived. Thanks for wooyun! 乌云公开漏洞、知识库爬虫和搜索 crawl and search for wooyun.org public bug(vulnerability) and drops +- [**3481**星][8d] [C] [cyan4973/xxhash](https://github.com/cyan4973/xxhash) Extremely fast non-cryptographic hash algorithm +- [**3471**星][2m] [C++] [trojan-gfw/trojan](https://github.com/trojan-gfw/trojan) An unidentifiable mechanism that helps you bypass GFW. +- [**3442**星][9d] [C] [shellphish/how2heap](https://github.com/shellphish/how2heap) 学习各种堆利用技巧的repo +- [**3442**星][8d] [Java] [meituan-dianping/robust](https://github.com/meituan-dianping/robust) Robust is an Android HotFix solution with high compatibility and high stability. Robust can fix bugs immediately without a reboot. +- [**3441**星][15d] [Perl] [sullo/nikto](https://github.com/sullo/nikto) Nikto web server scanner +- [**3419**星][9d] [C] [mikebrady/shairport-sync](https://github.com/mikebrady/shairport-sync) AirPlay audio player. Shairport Sync adds multi-room capability with Audio Synchronisation +- [**3412**星][27d] [icodesign/potatso](https://github.com/icodesign/Potatso) Potatso is an iOS client that implements different proxies with the leverage of NetworkExtension framework in iOS 10+. +- [**3410**星][5m] [Go] [jpillora/chisel](https://github.com/jpillora/chisel) 基于HTTP的快速 TCP 隧道 +- [**3408**星][24d] [PS] [samratashok/nishang](https://github.com/samratashok/nishang) 渗透框架,脚本和Payload收集,主要是PowerShell,涵盖渗透的各个阶段 +- [**3397**星][2y] [shadowsocksrr/shadowsocks-rss](https://github.com/shadowsocksrr/shadowsocks-rss) ShadowsocksR update rss, SSR organization +- [**3344**星][2d] [jivoi/awesome-ml-for-cybersecurity](https://github.com/jivoi/awesome-ml-for-cybersecurity) 针对网络安全的机器学习资源列表 +- [**3343**星][6d] [C] [screetsec/thefatrat](https://github.com/screetsec/thefatrat) Thefatrat a massive exploiting tool : Easy tool to generate backdoor and easy tool to post exploitation attack like browser attack and etc . This tool compiles a malware with popular payload and then the compiled malware can be execute on windows, android, mac . The malware that created with this tool also have an ability to bypass most AV softw… +- [**3340**星][5m] [C++] [wangyu-/udp2raw-tunnel](https://github.com/wangyu-/udp2raw-tunnel) udp 打洞。通过raw socket给UDP包加上TCP或ICMP header,进而绕过UDP屏蔽或QoS,或在UDP不稳定的环境下提升稳定性 +- [**3334**星][10d] [Smarty] [anankke/sspanel-uim](https://github.com/anankke/sspanel-uim) 专为 Shadowsocks / ShadowsocksR / V2Ray 设计的多用户管理面板 +- [**3331**星][15d] [Py] [google/grr](https://github.com/google/grr) remote live forensics for incident response +- [**3330**星][2d] [Py] [stamparm/maltrail](https://github.com/stamparm/maltrail) 恶意网络流量检测系统 +- [**3319**星][2y] [scanate/ethlist](https://github.com/scanate/ethlist) The Comprehensive Ethereum Reading List +- [**3303**星][22d] [C] [vanhauser-thc/thc-hydra](https://github.com/vanhauser-thc/thc-hydra) 网络登录破解,支持多种服务 +- [**3301**星][2m] [Swift] [yagiz/bagel](https://github.com/yagiz/bagel) a little native network debugging tool for iOS +- [**3298**星][9d] [C++] [fireice-uk/xmr-stak](https://github.com/fireice-uk/xmr-stak) Free Monero RandomX Miner and unified CryptoNight miner +- [**3285**星][7d] [C] [microsoft/windows-driver-samples](https://github.com/microsoft/windows-driver-samples) This repo contains driver samples prepared for use with Microsoft Visual Studio and the Windows Driver Kit (WDK). It contains both Universal Windows Driver and desktop-only driver samples. +- [**3278**星][6d] [C] [virustotal/yara](https://github.com/virustotal/yara) The pattern matching swiss knife +- [**3276**星][3m] [C] [nbs-system/naxsi](https://github.com/nbs-system/naxsi) NAXSI is an open-source, high performance, low rules maintenance WAF for NGINX +- [**3263**星][10d] [Java] [oldmanpushcart/greys-anatomy](https://github.com/oldmanpushcart/greys-anatomy) Java诊断工具 +- [**3262**星][2m] [Py] [volatilityfoundation/volatility](https://github.com/volatilityfoundation/volatility) An advanced memory forensics framework +- [**3260**星][8d] [Shell] [toniblyx/my-arsenal-of-aws-security-tools](https://github.com/toniblyx/my-arsenal-of-aws-security-tools) List of open source tools for AWS security: defensive, offensive, auditing, DFIR, etc. +- [**3260**星][5y] [C++] [google/lmctfy](https://github.com/google/lmctfy) lmctfy is the open source version of Google’s container stack, which provides Linux application containers. +- [**3259**星][7m] [JS] [sindresorhus/speed-test](https://github.com/sindresorhus/speed-test) Test your internet connection speed and ping using speedtest.net from the CLI +- [**3255**星][4d] [ObjC] [objective-see/lulu](https://github.com/objective-see/lulu) LuLu is the free macOS firewall +- [**3247**星][29d] [JS] [koenkk/zigbee2mqtt](https://github.com/koenkk/zigbee2mqtt) Zigbee +- [**3242**星][16d] [Py] [laramies/theharvester](https://github.com/laramies/theharvester) E-mails, subdomains and names Harvester - OSINT +- [**3238**星][2d] [TS] [jigsaw-code/outline-server](https://github.com/jigsaw-code/outline-server) Outline Manager, developed by Jigsaw. The Outline Manager application creates and manages Outline servers, powered by Shadowsocks. It uses the Electron framework to offer support for Windows, macOS and Linux. +- [**3236**星][5m] [Go] [meshbird/meshbird](https://github.com/meshbird/meshbird) cloud-native multi-region multi-cloud decentralized private networking - [**3234**星][2y] [CSS] [jbtronics/crookedstylesheets](https://github.com/jbtronics/crookedstylesheets) 使用纯CSS收集网页/用户信息 -- [**3232**星][5m] [Go] [meshbird/meshbird](https://github.com/meshbird/meshbird) cloud-native multi-region multi-cloud decentralized private networking -- [**3230**星][2m] [Objective-C] [objective-see/lulu](https://github.com/objective-see/lulu) LuLu is the free macOS firewall -- [**3225**星][18d] [Shell] [toniblyx/my-arsenal-of-aws-security-tools](https://github.com/toniblyx/my-arsenal-of-aws-security-tools) List of open source tools for AWS security: defensive, offensive, auditing, DFIR, etc. -- [**3216**星][14d] [Py] [laramies/theharvester](https://github.com/laramies/theharvester) E-mails, subdomains and names Harvester - OSINT -- [**3215**星][27d] [JS] [koenkk/zigbee2mqtt](https://github.com/koenkk/zigbee2mqtt) Zigbee -- [**3214**星][4y] [C] [shadowsocks/chinadns](https://github.com/shadowsocks/chinadns) Protect yourself against DNS poisoning in China. -- [**3214**星][2m] [Go] [dvyukov/go-fuzz](https://github.com/dvyukov/go-fuzz) Randomized testing for Go -- [**3210**星][11d] [C] [tmate-io/tmate](https://github.com/tmate-io/tmate) Instant Terminal Sharing -- [**3210**星][1m] [TypeScript] [google/incremental-dom](https://github.com/google/incremental-dom) An in-place DOM diffing library -- [**3209**星][8d] [C] [betaflight/betaflight](https://github.com/betaflight/betaflight) Open Source Flight Controller Firmware -- [**3205**星][2m] [Shell] [gfw-breaker/ssr-accounts](https://github.com/gfw-breaker/ssr-accounts) 一键部署Shadowsocks服务;免费Shadowsocks账号分享;免费SS账号分享; 翻墙;无界,自由门,SquirrelVPN -- [**3202**星][4m] [Objective-C] [naituw/ipapatch](https://github.com/naituw/ipapatch) Patch iOS Apps, The Easy Way, Without Jailbreak. -- [**3201**星][7m] [HTML] [leizongmin/js-xss](https://github.com/leizongmin/js-xss) Sanitize untrusted HTML (to prevent XSS) with a configuration specified by a Whitelist -- [**3184**星][7d] [Go] [mozilla/sops](https://github.com/mozilla/sops) Simple and flexible tool for managing secrets -- [**3182**星][3m] [C] [yarrick/iodine](https://github.com/yarrick/iodine) 通过DNS服务器传输(tunnel)IPV4数据 -- [**3182**星][1y] [Py] [kootenpv/whereami](https://github.com/kootenpv/whereami) 使用Wifi信号和机器学习预测你的位置,精确度2-10米 -- [**3180**星][13d] [Py] [maurosoria/dirsearch](https://github.com/maurosoria/dirsearch) Web path scanner -- [**3174**星][8d] [Rich Text Format] [the-art-of-hacking/h4cker](https://github.com/The-Art-of-Hacking/h4cker) 资源收集:hacking、渗透、数字取证、事件响应、漏洞研究、漏洞开发、逆向 -- [**3168**星][1m] [C++] [spiderlabs/modsecurity](https://github.com/spiderlabs/modsecurity) ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx that is developed by Trustwave's SpiderLabs. It has a robust event-based programming language which provides protection from a range of attacks against web applications and allows for HTTP traffic monitoring, logging and real-time analys… -- [**3164**星][6m] [hslatman/awesome-threat-intelligence](https://github.com/hslatman/awesome-threat-intelligence) A curated list of Awesome Threat Intelligence resources -- [**3163**星][24d] [C] [magnumripper/johntheripper](https://github.com/magnumripper/johntheripper) This is the official repo for John the Ripper, "Jumbo" version. The "bleeding-jumbo" branch is based on 1.9.0-Jumbo-1 which was released on May 14, 2019. An import of the "core" version of john this jumbo was based on (or newer) is found in the "master" branch (CVS: -- [**3156**星][1m] [C] [valdikss/goodbyedpi](https://github.com/valdikss/goodbyedpi) GoodbyeDPI—Passive Deep Packet Inspection blocker and Active DPI circumvention utility (for Windows) -- [**3145**星][1y] [Shell] [toyodadoubi/doubi](https://github.com/toyodadoubi/doubi) 一个逗比写的各种逗比脚本~ -- [**3128**星][2y] [shadowsocksr-backup/shadowsocksr-android](https://github.com/shadowsocksr-backup/shadowsocksr-android) A ShadowsocksR client for Android -- [**3120**星][10d] [C] [meetecho/janus-gateway](https://github.com/meetecho/janus-gateway) Janus WebRTC Server -- [**3113**星][28d] [CSS] [readthedocs/sphinx_rtd_theme](https://github.com/readthedocs/sphinx_rtd_theme) Sphinx theme for readthedocs.org -- [**3112**星][2m] [C++] [trojan-gfw/trojan](https://github.com/trojan-gfw/trojan) An unidentifiable mechanism that helps you bypass GFW. -- [**3109**星][7d] [Shell] [speed47/spectre-meltdown-checker](https://github.com/speed47/spectre-meltdown-checker) 检查 Linux 主机是否受处理器漏洞Spectre & Meltdown 的影响 -- [**3109**星][2m] [PowerShell] [fireeye/commando-vm](https://github.com/fireeye/commando-vm) Complete Mandiant Offensive VM (Commando VM), a fully customizable Windows-based pentesting virtual machine distribution. commandovm@fireeye.com -- [**3108**星][4m] [C++] [px4/firmware](https://github.com/px4/firmware) PX4 Autopilot Software -- [**3106**星][7d] [C] [qemu/qemu](https://github.com/qemu/qemu) Official QEMU mirror. Please see -- [**3103**星][16d] [Shell] [1n3/sn1per](https://github.com/1n3/sn1per) 自动化渗透测试框架 -- [**3102**星][7d] [JS] [duo-labs/cloudmapper](https://github.com/duo-labs/cloudmapper) 生成AWS环境的网络拓扑图 -- [**3096**星][28d] [meirwah/awesome-incident-response](https://github.com/meirwah/awesome-incident-response) A curated list of tools for incident response -- [**3094**星][2m] [Py] [byt3bl33d3r/crackmapexec](https://github.com/byt3bl33d3r/crackmapexec) 后渗透工具,自动化评估大型Active Directory网络的安全性 -- [**3091**星][1m] [Java] [deathmarine/luyten](https://github.com/deathmarine/luyten) An Open Source Java Decompiler Gui for Procyon -- [**3085**星][10d] [Shell] [trimstray/htrace.sh](https://github.com/trimstray/htrace.sh) My simple Swiss Army knife for http/https troubleshooting and profiling. -- [**3084**星][11d] [Py] [tribler/tribler](https://github.com/tribler/tribler) Privacy enhanced BitTorrent client with P2P content discovery -- [**3084**星][8d] [Shell] [softwaredownload/openwrt-fanqiang](https://github.com/softwaredownload/openwrt-fanqiang) 最好的路由器翻墙、科学上网教程—OpenWrt—shadowsocks -- [**3069**星][9m] [JS] [jipegit/osxauditor](https://github.com/jipegit/osxauditor) OS X Auditor is a free Mac OS X computer forensics tool -- [**3066**星][3m] [C] [zmap/zmap](https://github.com/zmap/zmap) ZMap is a fast single packet network scanner designed for Internet-wide network surveys. -- [**3065**星][9d] [Go] [tencent/bk-cmdb](https://github.com/tencent/bk-cmdb) 蓝鲸智云配置平台(BlueKing CMDB) -- [**3062**星][1y] [Swift] [zhuhaow/spechtlite](https://github.com/zhuhaow/spechtlite) A rule-based proxy for macOS -- [**3061**星][20d] [C] [unicorn-engine/unicorn](https://github.com/unicorn-engine/unicorn) Unicorn CPU emulator framework (ARM, AArch64, M68K, Mips, Sparc, X86) -- [**3059**星][1m] [Java] [calebfenton/simplify](https://github.com/calebfenton/simplify) Generic Android Deobfuscator -- [**3058**星][7m] [Go] [michenriksen/aquatone](https://github.com/michenriksen/aquatone) 子域名枚举工具。除了经典的爆破枚举之外,还利用多种开源工具和在线服务大幅度增加发现子域名的数量。 -- [**3046**星][4m] [C++] [google/robotstxt](https://github.com/google/robotstxt) The repository contains Google's robots.txt parser and matcher as a C++ library (compliant to C++11). -- [**3041**星][2m] [JS] [valve/fingerprintjs](https://github.com/valve/fingerprintjs) Anonymous browser fingerprint -- [**3039**星][3m] [Py] [spiderlabs/responder](https://github.com/spiderlabs/responder) LLMNR/NBT-NS/MDNS投毒,内置HTTP/SMB/MSSQL/FTP/LDAP认证服务器, 支持NTLMv1/NTLMv2/LMv2 -- [**3007**星][9m] [C] [secwiki/linux-kernel-exploits](https://github.com/secwiki/linux-kernel-exploits) linux-kernel-exploits Linux平台提权漏洞集合 -- [**2991**星][1y] [PHP] [owner888/phpspider](https://github.com/owner888/phpspider) 《我用爬虫一天时间“偷了”知乎一百万用户,只为证明PHP是世界上最好的语言 》所使用的程序 -- [**2983**星][2m] [Go] [gwuhaolin/lightsocks](https://github.com/gwuhaolin/lightsocks) 轻量级网络混淆代理,基于 SOCKS5 协议,可用来代替 Shadowsocks -- [**2982**星][7d] [Lua] [ntop/ntopng](https://github.com/ntop/ntopng) 基于Web的流量监控工具 -- [**2978**星][7d] [Py] [guardicore/monkey](https://github.com/guardicore/monkey) 自动化渗透测试工具, 测试数据中心的弹性, 以防范周边(perimeter)泄漏和内部服务器感染 -- [**2962**星][14d] [Objective-C] [google/santa](https://github.com/google/santa) 用于Mac系统的二进制文件白名单/黑名单系统 -- [**2947**星][27d] [Go] [cookiey/yearning](https://github.com/cookiey/yearning) A most popular sql audit platform for mysql -- [**2937**星][13d] [JS] [webgoat/webgoat](https://github.com/webgoat/webgoat) 带漏洞WebApp -- [**2937**星][2y] [phith0n/mind-map](https://github.com/phith0n/mind-map) 各种安全相关思维导图整理收集 -- [**2936**星][1m] [Py] [andresriancho/w3af](https://github.com/andresriancho/w3af) Web App安全扫描器, 辅助开发者和渗透测试人员识别和利用Web App中的漏洞 -- [**2935**星][19d] [Py] [cowrie/cowrie](https://github.com/cowrie/cowrie) 中型/交互型 SSH/Telnet 蜜罐, -- [**2930**星][1y] [Py] [danmcinerney/wifijammer](https://github.com/danmcinerney/wifijammer) 持续劫持范围内的Wifi客户端和AP -- [**2930**星][11m] [Shell] [91yun/serverspeeder](https://github.com/91yun/serverspeeder) 锐速破解版 -- [**2927**星][7d] [Zeek] [zeek/zeek](https://github.com/zeek/zeek) Zeek is a powerful network analysis framework that is much different from the typical IDS you may know. -- [**2916**星][15d] [Py] [twintproject/twint](https://github.com/twintproject/twint) An advanced Twitter scraping & OSINT tool written in Python that doesn't use Twitter's API, allowing you to scrape a user's followers, following, Tweets and more while evading most API limitations. -- [**2912**星][2m] [Dockerfile] [thinkdevelop/free-ss-ssr](https://github.com/thinkdevelop/free-ss-ssr) SS账号、SSR账号、V2Ray账号 -- [**2907**星][21d] [Go] [securego/gosec](https://github.com/securego/gosec) Golang security checker -- [**2897**星][1y] [Py] [byt3bl33d3r/mitmf](https://github.com/byt3bl33d3r/mitmf) Framework for Man-In-The-Middle attacks -- [**2895**星][10d] [C] [libfuse/sshfs](https://github.com/libfuse/sshfs) A network filesystem client to connect to SSH servers -- [**2892**星][11d] [secfigo/awesome-fuzzing](https://github.com/secfigo/awesome-fuzzing) A curated list of fuzzing resources ( Books, courses - free and paid, videos, tools, tutorials and vulnerable applications to practice on ) for learning Fuzzing and initial phases of Exploit Development like root cause analysis. -- [**2891**星][20d] [Py] [trustedsec/ptf](https://github.com/trustedsec/ptf) 创建基于Debian/Ubuntu/ArchLinux的渗透测试环境 -- [**2876**星][7m] [C] [p-h-c/phc-winner-argon2](https://github.com/p-h-c/phc-winner-argon2) The password hash Argon2, winner of PHC -- [**2874**星][4y] [Objective-C] [maciekish/iresign](https://github.com/maciekish/iresign) iReSign allows iDevice app bundles (.ipa) files to be signed or resigned with a digital certificate from Apple for distribution. This tool is aimed at enterprises users, for enterprise deployment, when the person signing the app is different than the person(s) developing it. -- [**2851**星][10d] [JS] [evilsocket/pwnagotchi](https://github.com/evilsocket/pwnagotchi) 深度学习+Bettercap,基于A2C,从周围的WiFi环境中学习,以最大程度地利用捕获的WPA关键信息 -- [**2850**星][8d] [C] [lxc/lxc](https://github.com/lxc/lxc) LXC - Linux Containers -- [**2840**星][5m] [Py] [instantbox/instantbox](https://github.com/instantbox/instantbox) Get a clean, ready-to-go Linux box in seconds. -- [**2838**星][11d] [Objective-C] [facebook/idb](https://github.com/facebook/idb) idb is a flexible command line interface for automating iOS simulators and devices -- [**2834**星][8m] [C++] [wangyu-/udpspeeder](https://github.com/wangyu-/udpspeeder) A Tunnel which Improves your Network Quality on a High-latency Lossy Link by using Forward Error Correction,for All Traffics(TCP/UDP/ICMP) -- [**2830**星][9d] [HTML] [ctf-wiki/ctf-wiki](https://github.com/ctf-wiki/ctf-wiki) CTF Wiki Online. Come and join us, we need you! -- [**2829**星][21d] [C] [ossec/ossec-hids](https://github.com/ossec/ossec-hids) 入侵检测系统 -- [**2825**星][15d] [Py] [espressif/esptool](https://github.com/espressif/esptool) ESP8266 and ESP32 serial bootloader utility -- [**2825**星][8m] [Shell] [goreliu/wsl-terminal](https://github.com/goreliu/wsl-terminal) Terminal emulator for Windows Subsystem for Linux (WSL) -- [**2823**星][12d] [Go] [99designs/aws-vault](https://github.com/99designs/aws-vault) A vault for securely storing and accessing AWS credentials in development environments -- [**2820**星][1m] [Assembly] [cirosantilli/x86-bare-metal-examples](https://github.com/cirosantilli/x86-bare-metal-examples) 几十个用于学习 x86 系统编程的小型操作系统 -- [**2819**星][2y] [CSS] [maxchehab/css-keylogging](https://github.com/maxchehab/css-keylogging) Chrome extension and Express server that exploits keylogging abilities of CSS. -- [**2815**星][4m] [C] [juliocesarfort/public-pentesting-reports](https://github.com/juliocesarfort/public-pentesting-reports) Curated list of public penetration test reports released by several consulting firms and academic security groups -- [**2810**星][28d] [C] [tmk/tmk_keyboard](https://github.com/tmk/tmk_keyboard) Atmel AVR 和 Cortex-M键盘固件收集 -- [**2810**星][2m] [infosecn1nja/red-teaming-toolkit](https://github.com/infosecn1nja/red-teaming-toolkit) A collection of open source and commercial tools that aid in red team operations. -- [**2805**星][1m] [paulsec/awesome-sec-talks](https://github.com/paulsec/awesome-sec-talks) A collected list of awesome security talks -- [**2804**星][8m] [C#] [quasar/quasarrat](https://github.com/quasar/quasarrat) Remote Administration Tool for Windows -- [**2802**星][9m] [Py] [plasma-disassembler/plasma](https://github.com/plasma-disassembler/plasma) Plasma is an interactive disassembler for x86/ARM/MIPS. It can generates indented pseudo-code with colored syntax. -- [**2787**星][17d] [Py] [androguard/androguard](https://github.com/androguard/androguard) Reverse engineering, Malware and goodware analysis of Android applications ... and more (ninja !) -- [**2783**星][2y] [C] [seclab-ucr/intang](https://github.com/seclab-ucr/intang) research project for circumventing the "TCP reset attack" from the Great Firewall of China (GFW) by disrupting/desynchronizing the TCP Control Block (TCB) on the censorship devices. -- [**2779**星][28d] [Makefile] [shadowsocks/openwrt-shadowsocks](https://github.com/shadowsocks/openwrt-shadowsocks) Shadowsocks-libev for OpenWrt/LEDE -- [**2776**星][4y] [Lua] [loveshell/ngx_lua_waf](https://github.com/loveshell/ngx_lua_waf) ngx_lua_waf是一个基于lua-nginx-module(openresty)的web应用防火墙 -- [**2767**星][2m] [Go] [kgretzky/evilginx2](https://github.com/kgretzky/evilginx2) 独立的MITM攻击工具,用于登录凭证钓鱼,可绕过双因素认证 -- [**2763**星][1m] [JS] [trufflesuite/ganache-cli](https://github.com/trufflesuite/ganache-cli) Fast Ethereum RPC client for testing and development -- [**2761**星][10d] [Py] [jrohy/multi-v2ray](https://github.com/jrohy/multi-v2ray) v2ray easy delpoy & manage tool, support multiple user & protocol manage -- [**2755**星][7d] [C++] [qtox/qtox](https://github.com/qtox/qtox) qTox is a chat, voice, video, and file transfer IM client using the encrypted peer-to-peer Tox protocol. -- [**2746**星][8d] [C] [processhacker/processhacker](https://github.com/processhacker/processhacker) A free, powerful, multi-purpose tool that helps you monitor system resources, debug software and detect malware. -- [**2736**星][8m] [Py] [p0cl4bs/wifi-pumpkin](https://github.com/P0cL4bs/WiFi-Pumpkin) AP攻击框架, 创建虚假网络, 取消验证攻击、请求和凭证监控、透明代理、Windows更新攻击、钓鱼管理、ARP投毒、DNS嗅探、Pumpkin代理、动态图片捕获等 -- [**2736**星][1y] [C] [vanhoefm/krackattacks-scripts](https://github.com/vanhoefm/krackattacks-scripts) 检测客户端和AP是否受KRACK漏洞影响 -- [**2735**星][7d] [TypeScript] [webhintio/hint](https://github.com/webhintio/hint) -- [**2731**星][22d] [Makefile] [theos/theos](https://github.com/theos/theos) A cross-platform suite of tools for building and deploying software for iOS and other platforms. -- [**2727**星][2m] [secwiki/sec-chart](https://github.com/secwiki/sec-chart) 安全思维导图集合 -- [**2727**星][3y] [Py] [hephaest0s/usbkill](https://github.com/hephaest0s/usbkill) 反取证开关. 监控USB端口变化, 有变化时立即关闭计算机 -- [**2726**星][16d] [JS] [cyu/rack-cors](https://github.com/cyu/rack-cors) Rack Middleware for handling Cross-Origin Resource Sharing (CORS), which makes cross-origin AJAX possible. -- [**2715**星][21d] [JS] [s0md3v/awesomexss](https://github.com/s0md3v/AwesomeXSS) Awesome XSS stuff -- [**2701**星][3y] [Eagle] [samyk/magspoof](https://github.com/samyk/magspoof) 信用卡/磁条欺骗 -- [**2700**星][1m] [C] [taviso/loadlibrary](https://github.com/taviso/loadlibrary) 使 Linux系统加载并调用 Windows DLL -- [**2683**星][4m] [Objective-C] [dantheman827/ios-app-signer](https://github.com/dantheman827/ios-app-signer) This is an app for OS X that can (re)sign apps and bundle them into ipa files that are ready to be installed on an iOS device. -- [**2681**星][1m] [Objective-C] [kjcracks/clutch](https://github.com/kjcracks/clutch) Fast iOS executable dumper -- [**2665**星][7d] [Go] [google/syzkaller](https://github.com/google/syzkaller) 一个unsupervised、以 coverage 为导向的Linux 系统调用fuzzer -- [**2660**星][7d] [PowerShell] [redcanaryco/atomic-red-team](https://github.com/redcanaryco/atomic-red-team) Small and highly portable detection tests based on MITRE's ATT&CK. -- [**2660**星][1y] [Py] [mame82/p4wnp1](https://github.com/mame82/p4wnp1) 基于Raspberry Pi Zero 或 Raspberry Pi Zero W 的USB攻击平台, 高度的可定制性 -- [**2658**星][12d] [Go] [aquasecurity/trivy](https://github.com/aquasecurity/trivy) A Simple and Comprehensive Vulnerability Scanner for Containers, Suitable for CI -- [**2648**星][3m] [Py] [drivendata/cookiecutter-data-science](https://github.com/drivendata/cookiecutter-data-science) A logical, reasonably standardized, but flexible project structure for doing and sharing data science work. -- [**2643**星][2m] [rmusser01/infosec_reference](https://github.com/rmusser01/infosec_reference) An Information Security Reference That Doesn't Suck -- [**2638**星][3m] [Java] [frohoff/ysoserial](https://github.com/frohoff/ysoserial) 生成会利用不安全的Java对象反序列化的Payload -- [**2634**星][2m] [xairy/linux-kernel-exploitation](https://github.com/xairy/linux-kernel-exploitation) Linux 内核 Fuzz 和漏洞利用的资源收集 -- [**2633**星][3m] [Java] [teevity/ice](https://github.com/teevity/ice) AWS Usage Tool -- [**2633**星][1y] [HTML] [chybeta/web-security-learning](https://github.com/chybeta/web-security-learning) Web-Security-Learning -- [**2622**星][15d] [JS] [bkimminich/juice-shop](https://github.com/bkimminich/juice-shop) OWASP Juice Shop: Probably the most modern and sophisticated insecure web application -- [**2619**星][8m] [leandromoreira/linux-network-performance-parameters](https://github.com/leandromoreira/linux-network-performance-parameters) Learn where some of the network sysctl variables fit into the Linux/Kernel network flow -- [**2610**星][2m] [Swift] [zhuhaow/nekit](https://github.com/zhuhaow/nekit) A toolkit for Network Extension Framework -- [**2601**星][3y] [Ruby] [arachni/arachni](https://github.com/arachni/arachni) Web Application Security Scanner Framework -- [**2600**星][21d] [JS] [knownsec/kcon](https://github.com/knownsec/kcon) KCon is a famous Hacker Con powered by Knownsec Team. -- [**2598**星][8d] [JS] [popcorn-official/popcorn-desktop](https://github.com/popcorn-official/popcorn-desktop) Popcorn Time is a multi-platform, free software BitTorrent client that includes an integrated media player. Desktop ( Windows / Mac / Linux ) a Butter-Project Fork -- [**2589**星][19d] [C++] [fanout/pushpin](https://github.com/fanout/pushpin) Reverse proxy for realtime web services -- [**2588**星][1m] [pditommaso/awesome-pipeline](https://github.com/pditommaso/awesome-pipeline) A curated list of awesome pipeline toolkits inspired by Awesome Sysadmin -- [**2570**星][2m] [C] [huntergregal/mimipenguin](https://github.com/huntergregal/mimipenguin) dump 当前Linux用户的登录密码 -- [**2565**星][1m] [Shell] [medicean/vulapps](https://github.com/medicean/vulapps) 快速搭建各种漏洞环境(Various vulnerability environment) -- [**2564**星][8y] [C] [id-software/quake](https://github.com/id-software/quake) Quake GPL Source Release -- [**2563**星][5m] [Java] [google/binnavi](https://github.com/google/binnavi) 二进制分析IDE, 对反汇编代码的控制流程图和调用图进行探查/导航/编辑/注释.(IDA插件的作用是导出反汇编) -- [**2555**星][1m] [C] [esnet/iperf](https://github.com/esnet/iperf) A TCP, UDP, and SCTP network bandwidth measurement tool -- [**2554**星][2y] [evilsocket/bettercap](https://github.com/evilsocket/bettercap) 中间人攻击框架,功能完整,模块化设计,轻便且易于扩展。 -- [**2547**星][3m] [Py] [greenwolf/social_mapper](https://github.com/Greenwolf/social_mapper) 对多个社交网站的用户Profile图片进行大规模的人脸识别 -- [**2537**星][6m] [C] [geohot/qira](https://github.com/geohot/qira) QEMU Interactive Runtime Analyser +- [**3233**星][9d] [Go] [mozilla/sops](https://github.com/mozilla/sops) Simple and flexible tool for managing secrets +- [**3228**星][2d] [C] [betaflight/betaflight](https://github.com/betaflight/betaflight) Open Source Flight Controller Firmware +- [**3223**星][2m] [Shell] [gfw-breaker/ssr-accounts](https://github.com/gfw-breaker/ssr-accounts) 一键部署Shadowsocks服务;免费Shadowsocks账号分享;免费SS账号分享; 翻墙;无界,自由门,SquirrelVPN +- [**3222**星][6d] [C] [tmate-io/tmate](https://github.com/tmate-io/tmate) Instant Terminal Sharing +- [**3222**星][6d] [Go] [dvyukov/go-fuzz](https://github.com/dvyukov/go-fuzz) Randomized testing for Go +- [**3221**星][4y] [C] [shadowsocks/chinadns](https://github.com/shadowsocks/chinadns) Protect yourself against DNS poisoning in China. +- [**3213**星][1m] [TS] [google/incremental-dom](https://github.com/google/incremental-dom) An in-place DOM diffing library +- [**3210**星][7m] [HTML] [leizongmin/js-xss](https://github.com/leizongmin/js-xss) Sanitize untrusted HTML (to prevent XSS) with a configuration specified by a Whitelist +- [**3209**星][5m] [ObjC] [naituw/ipapatch](https://github.com/naituw/ipapatch) Patch iOS Apps, The Easy Way, Without Jailbreak. +- [**3208**星][4m] [C] [yarrick/iodine](https://github.com/yarrick/iodine) 通过DNS服务器传输(tunnel)IPV4数据 +- [**3205**星][15d] [Py] [maurosoria/dirsearch](https://github.com/maurosoria/dirsearch) Web path scanner +- [**3202**星][10d] [Rich Text Format] [the-art-of-hacking/h4cker](https://github.com/The-Art-of-Hacking/h4cker) 资源收集:hacking、渗透、数字取证、事件响应、漏洞研究、漏洞开发、逆向 +- [**3187**星][1y] [Py] [kootenpv/whereami](https://github.com/kootenpv/whereami) 使用Wifi信号和机器学习预测你的位置,精确度2-10米 +- [**3187**星][6m] [hslatman/awesome-threat-intelligence](https://github.com/hslatman/awesome-threat-intelligence) A curated list of Awesome Threat Intelligence resources +- [**3186**星][1m] [C++] [spiderlabs/modsecurity](https://github.com/spiderlabs/modsecurity) ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx that is developed by Trustwave's SpiderLabs. It has a robust event-based programming language which provides protection from a range of attacks against web applications and allows for HTTP traffic monitoring, logging and real-time analys… +- [**3180**星][27d] [C] [magnumripper/johntheripper](https://github.com/magnumripper/johntheripper) This is the official repo for John the Ripper, "Jumbo" version. The "bleeding-jumbo" branch is based on 1.9.0-Jumbo-1 which was released on May 14, 2019. An import of the "core" version of john this jumbo was based on (or newer) is found in the "master" branch (CVS: +- [**3169**星][1m] [C] [valdikss/goodbyedpi](https://github.com/valdikss/goodbyedpi) GoodbyeDPI—Passive Deep Packet Inspection blocker and Active DPI circumvention utility (for Windows) +- [**3162**星][1y] [Shell] [toyodadoubi/doubi](https://github.com/toyodadoubi/doubi) 一个逗比写的各种逗比脚本~ +- [**3159**星][3d] [JS] [minbrowser/min](https://github.com/minbrowser/min) A fast, minimal browser that protects your privacy +- [**3140**星][6d] [C] [meetecho/janus-gateway](https://github.com/meetecho/janus-gateway) Janus WebRTC Server +- [**3137**星][2y] [shadowsocksr-backup/shadowsocksr-android](https://github.com/shadowsocksr-backup/shadowsocksr-android) A ShadowsocksR client for Android +- [**3134**星][2d] [C++] [px4/firmware](https://github.com/px4/firmware) PX4 Autopilot Software +- [**3125**星][3d] [Shell] [1n3/sn1per](https://github.com/1n3/sn1per) 自动化渗透测试框架 +- [**3123**星][30d] [meirwah/awesome-incident-response](https://github.com/meirwah/awesome-incident-response) A curated list of tools for incident response +- [**3123**星][2m] [PS] [fireeye/commando-vm](https://github.com/fireeye/commando-vm) Complete Mandiant Offensive VM (Commando VM), a fully customizable Windows-based pentesting virtual machine distribution. commandovm@fireeye.com +- [**3122**星][5d] [Go] [uber/kraken](https://github.com/uber/kraken) P2P Docker registry capable of distributing TBs of data in seconds +- [**3121**星][30d] [CSS] [readthedocs/sphinx_rtd_theme](https://github.com/readthedocs/sphinx_rtd_theme) Sphinx theme for readthedocs.org +- [**3121**星][8d] [JS] [duo-labs/cloudmapper](https://github.com/duo-labs/cloudmapper) 生成AWS环境的网络拓扑图 +- [**3118**星][3d] [Shell] [speed47/spectre-meltdown-checker](https://github.com/speed47/spectre-meltdown-checker) 检查 Linux 主机是否受处理器漏洞Spectre & Meltdown 的影响 +- [**3113**星][2d] [C] [qemu/qemu](https://github.com/qemu/qemu) Official QEMU mirror. Please see +- [**3107**星][2m] [Py] [byt3bl33d3r/crackmapexec](https://github.com/byt3bl33d3r/crackmapexec) 后渗透工具,自动化评估大型Active Directory网络的安全性 +- [**3106**星][7d] [Java] [deathmarine/luyten](https://github.com/deathmarine/luyten) An Open Source Java Decompiler Gui for Procyon +- [**3105**星][10d] [Shell] [softwaredownload/openwrt-fanqiang](https://github.com/softwaredownload/openwrt-fanqiang) 最好的路由器翻墙、科学上网教程—OpenWrt—shadowsocks +- [**3088**星][9d] [Shell] [trimstray/htrace.sh](https://github.com/trimstray/htrace.sh) My simple Swiss Army knife for http/https troubleshooting and profiling. +- [**3087**星][3d] [Py] [tribler/tribler](https://github.com/tribler/tribler) Privacy enhanced BitTorrent client with P2P content discovery +- [**3085**星][11d] [Go] [tencent/bk-cmdb](https://github.com/tencent/bk-cmdb) 蓝鲸智云配置平台(BlueKing CMDB) +- [**3084**星][22d] [C] [unicorn-engine/unicorn](https://github.com/unicorn-engine/unicorn) Unicorn CPU emulator framework (ARM, AArch64, M68K, Mips, Sparc, X86) +- [**3080**星][3m] [C] [zmap/zmap](https://github.com/zmap/zmap) ZMap is a fast single packet network scanner designed for Internet-wide network surveys. +- [**3076**星][7m] [Go] [michenriksen/aquatone](https://github.com/michenriksen/aquatone) 子域名枚举工具。除了经典的爆破枚举之外,还利用多种开源工具和在线服务大幅度增加发现子域名的数量。 +- [**3071**星][9m] [JS] [jipegit/osxauditor](https://github.com/jipegit/osxauditor) OS X Auditor is a free Mac OS X computer forensics tool +- [**3065**星][1m] [Java] [calebfenton/simplify](https://github.com/calebfenton/simplify) Generic Android Deobfuscator +- [**3063**星][1y] [Swift] [zhuhaow/spechtlite](https://github.com/zhuhaow/spechtlite) A rule-based proxy for macOS +- [**3052**星][2m] [JS] [valve/fingerprintjs](https://github.com/valve/fingerprintjs) Anonymous browser fingerprint +- [**3049**星][4m] [C++] [google/robotstxt](https://github.com/google/robotstxt) The repository contains Google's robots.txt parser and matcher as a C++ library (compliant to C++11). +- [**3043**星][3m] [Py] [spiderlabs/responder](https://github.com/spiderlabs/responder) LLMNR/NBT-NS/MDNS投毒,内置HTTP/SMB/MSSQL/FTP/LDAP认证服务器, 支持NTLMv1/NTLMv2/LMv2 +- [**3029**星][2m] [Go] [gwuhaolin/lightsocks](https://github.com/gwuhaolin/lightsocks) 轻量级网络混淆代理,基于 SOCKS5 协议,可用来代替 Shadowsocks +- [**3027**星][9m] [C] [secwiki/linux-kernel-exploits](https://github.com/secwiki/linux-kernel-exploits) linux-kernel-exploits Linux平台提权漏洞集合 +- [**3001**星][1y] [PHP] [owner888/phpspider](https://github.com/owner888/phpspider) 《我用爬虫一天时间“偷了”知乎一百万用户,只为证明PHP是世界上最好的语言 》所使用的程序 +- [**2991**星][2d] [JS] [ntop/ntopng](https://github.com/ntop/ntopng) 基于Web的流量监控工具 +- [**2986**星][7d] [Py] [guardicore/monkey](https://github.com/guardicore/monkey) 自动化渗透测试工具, 测试数据中心的弹性, 以防范周边(perimeter)泄漏和内部服务器感染 +- [**2969**星][29d] [Go] [cookiey/yearning](https://github.com/cookiey/yearning) A most popular sql audit platform for mysql +- [**2968**星][2d] [ObjC] [google/santa](https://github.com/google/santa) 用于Mac系统的二进制文件白名单/黑名单系统 +- [**2955**星][4d] [Py] [twintproject/twint](https://github.com/twintproject/twint) An advanced Twitter scraping & OSINT tool written in Python that doesn't use Twitter's API, allowing you to scrape a user's followers, following, Tweets and more while evading most API limitations. +- [**2955**星][11d] [Go] [dominikh/go-tools](https://github.com/dominikh/go-tools) Staticcheck – a collection of static analysis tools for working with Go code +- [**2949**星][8d] [JS] [webgoat/webgoat](https://github.com/webgoat/webgoat) 带漏洞WebApp +- [**2948**星][2m] [Dockerfile] [thinkdevelop/free-ss-ssr](https://github.com/thinkdevelop/free-ss-ssr) SS账号、SSR账号、V2Ray账号 +- [**2947**星][1m] [Py] [andresriancho/w3af](https://github.com/andresriancho/w3af) Web App安全扫描器, 辅助开发者和渗透测试人员识别和利用Web App中的漏洞 +- [**2945**星][2y] [phith0n/mind-map](https://github.com/phith0n/mind-map) 各种安全相关思维导图整理收集 +- [**2942**星][21d] [Py] [cowrie/cowrie](https://github.com/cowrie/cowrie) 中型/交互型 SSH/Telnet 蜜罐, +- [**2936**星][1y] [Py] [danmcinerney/wifijammer](https://github.com/danmcinerney/wifijammer) 持续劫持范围内的Wifi客户端和AP +- [**2933**星][2d] [Zeek] [zeek/zeek](https://github.com/zeek/zeek) Zeek is a powerful network analysis framework that is much different from the typical IDS you may know. +- [**2932**星][11m] [Shell] [91yun/serverspeeder](https://github.com/91yun/serverspeeder) 锐速破解版 +- [**2920**星][23d] [Go] [securego/gosec](https://github.com/securego/gosec) Golang security checker +- [**2916**星][2d] [JS] [evilsocket/pwnagotchi](https://github.com/evilsocket/pwnagotchi) 深度学习+Bettercap,基于A2C,从周围的WiFi环境中学习,以最大程度地利用捕获的WPA关键信息 +- [**2915**星][12d] [C] [libfuse/sshfs](https://github.com/libfuse/sshfs) A network filesystem client to connect to SSH servers +- [**2909**星][2d] [Py] [trustedsec/ptf](https://github.com/trustedsec/ptf) 创建基于Debian/Ubuntu/ArchLinux的渗透测试环境 +- [**2901**星][1y] [Py] [byt3bl33d3r/mitmf](https://github.com/byt3bl33d3r/mitmf) Framework for Man-In-The-Middle attacks +- [**2897**星][3d] [secfigo/awesome-fuzzing](https://github.com/secfigo/awesome-fuzzing) A curated list of fuzzing resources ( Books, courses - free and paid, videos, tools, tutorials and vulnerable applications to practice on ) for learning Fuzzing and initial phases of Exploit Development like root cause analysis. +- [**2883**星][7m] [C] [p-h-c/phc-winner-argon2](https://github.com/p-h-c/phc-winner-argon2) The password hash Argon2, winner of PHC +- [**2877**星][4y] [ObjC] [maciekish/iresign](https://github.com/maciekish/iresign) iReSign allows iDevice app bundles (.ipa) files to be signed or resigned with a digital certificate from Apple for distribution. This tool is aimed at enterprises users, for enterprise deployment, when the person signing the app is different than the person(s) developing it. +- [**2858**星][2d] [C] [lxc/lxc](https://github.com/lxc/lxc) LXC - Linux Containers +- [**2850**星][2d] [HTML] [ctf-wiki/ctf-wiki](https://github.com/ctf-wiki/ctf-wiki) CTF Wiki Online. Come and join us, we need you! +- [**2850**星][4d] [Go] [99designs/aws-vault](https://github.com/99designs/aws-vault) A vault for securely storing and accessing AWS credentials in development environments +- [**2845**星][2d] [ObjC] [facebook/idb](https://github.com/facebook/idb) idb is a flexible command line interface for automating iOS simulators and devices +- [**2842**星][5m] [Py] [instantbox/instantbox](https://github.com/instantbox/instantbox) Get a clean, ready-to-go Linux box in seconds. +- [**2840**星][23d] [C] [ossec/ossec-hids](https://github.com/ossec/ossec-hids) 入侵检测系统 +- [**2840**星][2m] [infosecn1nja/red-teaming-toolkit](https://github.com/infosecn1nja/red-teaming-toolkit) A collection of open source and commercial tools that aid in red team operations. +- [**2839**星][8m] [C++] [wangyu-/udpspeeder](https://github.com/wangyu-/udpspeeder) A Tunnel which Improves your Network Quality on a High-latency Lossy Link by using Forward Error Correction,for All Traffics(TCP/UDP/ICMP) +- [**2837**星][17d] [Py] [espressif/esptool](https://github.com/espressif/esptool) ESP8266 and ESP32 serial bootloader utility +- [**2834**星][8m] [Shell] [goreliu/wsl-terminal](https://github.com/goreliu/wsl-terminal) Terminal emulator for Windows Subsystem for Linux (WSL) +- [**2829**星][4m] [C] [juliocesarfort/public-pentesting-reports](https://github.com/juliocesarfort/public-pentesting-reports) Curated list of public penetration test reports released by several consulting firms and academic security groups +- [**2829**星][1m] [Assembly] [cirosantilli/x86-bare-metal-examples](https://github.com/cirosantilli/x86-bare-metal-examples) 几十个用于学习 x86 系统编程的小型操作系统 +- [**2823**星][2y] [CSS] [maxchehab/css-keylogging](https://github.com/maxchehab/css-keylogging) Chrome extension and Express server that exploits keylogging abilities of CSS. +- [**2820**星][7d] [C] [tmk/tmk_keyboard](https://github.com/tmk/tmk_keyboard) Atmel AVR 和 Cortex-M键盘固件收集 +- [**2814**星][8m] [C#] [quasar/quasarrat](https://github.com/quasar/quasarrat) Remote Administration Tool for Windows +- [**2814**星][5d] [Py] [jrohy/multi-v2ray](https://github.com/jrohy/multi-v2ray) v2ray easy delpoy & manage tool, support multiple user & protocol manage +- [**2808**星][2m] [paulsec/awesome-sec-talks](https://github.com/paulsec/awesome-sec-talks) A collected list of awesome security talks +- [**2803**星][9m] [Py] [plasma-disassembler/plasma](https://github.com/plasma-disassembler/plasma) Plasma is an interactive disassembler for x86/ARM/MIPS. It can generates indented pseudo-code with colored syntax. +- [**2798**星][19d] [Py] [androguard/androguard](https://github.com/androguard/androguard) Reverse engineering, Malware and goodware analysis of Android applications ... and more (ninja !) +- [**2793**星][6d] [C] [klange/toaruos](https://github.com/klange/toaruos) A completely-from-scratch hobby operating system: bootloader, kernel, drivers, C library, and userspace including a composited graphical UI, dynamic linker, syntax-highlighting text editor, network stack, etc. +- [**2793**星][2m] [Go] [kgretzky/evilginx2](https://github.com/kgretzky/evilginx2) 独立的MITM攻击工具,用于登录凭证钓鱼,可绕过双因素认证 +- [**2791**星][7d] [C++] [xmrig/xmrig](https://github.com/xmrig/xmrig) xmrig: 门罗币挖矿代码 CPU 版 +- [**2789**星][4y] [Lua] [loveshell/ngx_lua_waf](https://github.com/loveshell/ngx_lua_waf) ngx_lua_waf是一个基于lua-nginx-module(openresty)的web应用防火墙 +- [**2783**星][30d] [Makefile] [shadowsocks/openwrt-shadowsocks](https://github.com/shadowsocks/openwrt-shadowsocks) Shadowsocks-libev for OpenWrt/LEDE +- [**2782**星][2y] [C] [seclab-ucr/intang](https://github.com/seclab-ucr/intang) research project for circumventing the "TCP reset attack" from the Great Firewall of China (GFW) by disrupting/desynchronizing the TCP Control Block (TCB) on the censorship devices. +- [**2777**星][9d] [C++] [qtox/qtox](https://github.com/qtox/qtox) qTox is a chat, voice, video, and file transfer IM client using the encrypted peer-to-peer Tox protocol. +- [**2769**星][4d] [C] [processhacker/processhacker](https://github.com/processhacker/processhacker) A free, powerful, multi-purpose tool that helps you monitor system resources, debug software and detect malware. +- [**2766**星][1m] [JS] [trufflesuite/ganache-cli](https://github.com/trufflesuite/ganache-cli) Fast Ethereum RPC client for testing and development +- [**2756**星][2m] [secwiki/sec-chart](https://github.com/secwiki/sec-chart) 安全思维导图集合 +- [**2742**星][5d] [TS] [webhintio/hint](https://github.com/webhintio/hint) +- [**2742**星][24d] [Makefile] [theos/theos](https://github.com/theos/theos) A cross-platform suite of tools for building and deploying software for iOS and other platforms. +- [**2741**星][8m] [Py] [p0cl4bs/wifi-pumpkin](https://github.com/P0cL4bs/WiFi-Pumpkin) AP攻击框架, 创建虚假网络, 取消验证攻击、请求和凭证监控、透明代理、Windows更新攻击、钓鱼管理、ARP投毒、DNS嗅探、Pumpkin代理、动态图片捕获等 +- [**2739**星][23d] [JS] [s0md3v/awesomexss](https://github.com/s0md3v/AwesomeXSS) Awesome XSS stuff +- [**2737**星][1y] [C] [vanhoefm/krackattacks-scripts](https://github.com/vanhoefm/krackattacks-scripts) 检测客户端和AP是否受KRACK漏洞影响 +- [**2735**星][18d] [JS] [cyu/rack-cors](https://github.com/cyu/rack-cors) Rack Middleware for handling Cross-Origin Resource Sharing (CORS), which makes cross-origin AJAX possible. +- [**2730**星][3y] [Py] [hephaest0s/usbkill](https://github.com/hephaest0s/usbkill) 反取证开关. 监控USB端口变化, 有变化时立即关闭计算机 +- [**2717**星][2d] [PS] [redcanaryco/atomic-red-team](https://github.com/redcanaryco/atomic-red-team) Small and highly portable detection tests based on MITRE's ATT&CK. +- [**2713**星][1m] [C] [taviso/loadlibrary](https://github.com/taviso/loadlibrary) 使 Linux系统加载并调用 Windows DLL +- [**2703**星][3y] [Eagle] [samyk/magspoof](https://github.com/samyk/magspoof) 信用卡/磁条欺骗 +- [**2701**星][3d] [Go] [aquasecurity/trivy](https://github.com/aquasecurity/trivy) A Simple and Comprehensive Vulnerability Scanner for Containers, Suitable for CI +- [**2698**星][7d] [ObjC] [dantheman827/ios-app-signer](https://github.com/dantheman827/ios-app-signer) This is an app for OS X that can (re)sign apps and bundle them into ipa files that are ready to be installed on an iOS device. +- [**2690**星][1m] [ObjC] [kjcracks/clutch](https://github.com/kjcracks/clutch) Fast iOS executable dumper +- [**2682**星][22d] [Go] [google/syzkaller](https://github.com/google/syzkaller) 一个unsupervised、以 coverage 为导向的Linux 系统调用fuzzer +- [**2681**星][1y] [Py] [mame82/p4wnp1](https://github.com/mame82/p4wnp1) 基于Raspberry Pi Zero 或 Raspberry Pi Zero W 的USB攻击平台, 高度的可定制性 +- [**2674**星][3m] [Py] [drivendata/cookiecutter-data-science](https://github.com/drivendata/cookiecutter-data-science) A logical, reasonably standardized, but flexible project structure for doing and sharing data science work. +- [**2662**星][2m] [rmusser01/infosec_reference](https://github.com/rmusser01/infosec_reference) An Information Security Reference That Doesn't Suck +- [**2654**星][17d] [JS] [bkimminich/juice-shop](https://github.com/bkimminich/juice-shop) OWASP Juice Shop: Probably the most modern and sophisticated insecure web application +- [**2652**星][3m] [Java] [frohoff/ysoserial](https://github.com/frohoff/ysoserial) 生成会利用不安全的Java对象反序列化的Payload +- [**2645**星][2m] [xairy/linux-kernel-exploitation](https://github.com/xairy/linux-kernel-exploitation) Linux 内核 Fuzz 和漏洞利用的资源收集 +- [**2645**星][1y] [HTML] [chybeta/web-security-learning](https://github.com/chybeta/web-security-learning) Web-Security-Learning +- [**2641**星][1y] [C] [ckolivas/cgminer](https://github.com/ckolivas/cgminer) ASIC and FPGA miner in c for bitcoin +- [**2640**星][2d] [Go] [slackhq/nebula](https://github.com/slackhq/nebula) A scalable overlay networking tool with a focus on performance, simplicity and security +- [**2637**星][4m] [Java] [teevity/ice](https://github.com/teevity/ice) AWS Usage Tool +- [**2625**星][8m] [leandromoreira/linux-network-performance-parameters](https://github.com/leandromoreira/linux-network-performance-parameters) Learn where some of the network sysctl variables fit into the Linux/Kernel network flow +- [**2615**星][2m] [Swift] [zhuhaow/nekit](https://github.com/zhuhaow/nekit) A toolkit for Network Extension Framework +- [**2612**星][4d] [JS] [popcorn-official/popcorn-desktop](https://github.com/popcorn-official/popcorn-desktop) Popcorn Time is a multi-platform, free software BitTorrent client that includes an integrated media player. Desktop ( Windows / Mac / Linux ) a Butter-Project Fork +- [**2607**星][3y] [Ruby] [arachni/arachni](https://github.com/arachni/arachni) Web Application Security Scanner Framework +- [**2603**星][23d] [JS] [knownsec/kcon](https://github.com/knownsec/kcon) KCon is a famous Hacker Con powered by Knownsec Team. +- [**2601**星][1m] [pditommaso/awesome-pipeline](https://github.com/pditommaso/awesome-pipeline) A curated list of awesome pipeline toolkits inspired by Awesome Sysadmin +- [**2596**星][21d] [C++] [fanout/pushpin](https://github.com/fanout/pushpin) Reverse proxy for realtime web services +- [**2581**星][3d] [Go] [adguardteam/adguardhome](https://github.com/adguardteam/adguardhome) Network-wide ads & trackers blocking DNS server +- [**2581**星][1m] [Shell] [medicean/vulapps](https://github.com/medicean/vulapps) 快速搭建各种漏洞环境(Various vulnerability environment) +- [**2575**星][2m] [C] [huntergregal/mimipenguin](https://github.com/huntergregal/mimipenguin) dump 当前Linux用户的登录密码 +- [**2574**星][8y] [C] [id-software/quake](https://github.com/id-software/quake) Quake GPL Source Release +- [**2568**星][1m] [C] [esnet/iperf](https://github.com/esnet/iperf) A TCP, UDP, and SCTP network bandwidth measurement tool +- [**2566**星][2d] [C++] [danmar/cppcheck](https://github.com/danmar/cppcheck) static analysis of C/C++ code +- [**2565**星][5m] [Java] [google/binnavi](https://github.com/google/binnavi) 二进制分析IDE, 对反汇编代码的控制流程图和调用图进行探查/导航/编辑/注释.(IDA插件的作用是导出反汇编) +- [**2562**星][3m] [Py] [greenwolf/social_mapper](https://github.com/Greenwolf/social_mapper) 对多个社交网站的用户Profile图片进行大规模的人脸识别 +- [**2553**星][2y] [evilsocket/bettercap](https://github.com/evilsocket/bettercap) 中间人攻击框架,功能完整,模块化设计,轻便且易于扩展。 +- [**2551**星][9d] [Py] [cloudflare/flan](https://github.com/cloudflare/flan) A pretty sweet vulnerability scanner +- [**2549**星][6m] [C] [geohot/qira](https://github.com/geohot/qira) QEMU Interactive Runtime Analyser +- [**2543**星][19d] [Py] [hugsy/gef](https://github.com/hugsy/gef) gdb增强工具,使用Python API,用于漏洞开发和逆向分析。 +- [**2542**星][23d] [Go] [drk1wi/modlishka](https://github.com/drk1wi/modlishka) Modlishka. Reverse Proxy. +- [**2533**星][8m] [offensive-security/kali-nethunter](https://github.com/offensive-security/kali-nethunter) The Kali NetHunter Project - [**2533**星][2y] [Py] [google/nogotofail](https://github.com/google/nogotofail) 网络安全测试, 辅助定位和修复弱TLS/SSL连接和敏感明文流量 -- [**2532**星][8m] [offensive-security/kali-nethunter](https://github.com/offensive-security/kali-nethunter) The Kali NetHunter Project -- [**2530**星][17d] [Py] [hugsy/gef](https://github.com/hugsy/gef) gdb增强工具,使用Python API,用于漏洞开发和逆向分析。 -- [**2521**星][21d] [Go] [drk1wi/modlishka](https://github.com/drk1wi/modlishka) Modlishka. Reverse Proxy. -- [**2520**星][3y] [HTML] [dirtycow/dirtycow.github.io](https://github.com/dirtycow/dirtycow.github.io) Dirty COW -- [**2515**星][24d] [C] [yrutschle/sslh](https://github.com/yrutschle/sslh) Applicative Protocol Multiplexer (e.g. share SSH and HTTPS on the same port) -- [**2510**星][11d] [Shell] [teddysun/across](https://github.com/teddysun/across) This is a shell script for configure and start WireGuard VPN server -- [**2505**星][3m] [kbandla/aptnotes](https://github.com/kbandla/aptnotes) Various public documents, whitepapers and articles about APT campaigns -- [**2505**星][3y] [C] [dhavalkapil/icmptunnel](https://github.com/dhavalkapil/icmptunnel) Transparently tunnel your IP traffic through ICMP echo and reply packets. +- [**2526**星][2d] [Shell] [teddysun/across](https://github.com/teddysun/across) This is a shell script for configure and start WireGuard VPN server +- [**2525**星][3y] [HTML] [dirtycow/dirtycow.github.io](https://github.com/dirtycow/dirtycow.github.io) Dirty COW +- [**2522**星][26d] [C] [yrutschle/sslh](https://github.com/yrutschle/sslh) Applicative Protocol Multiplexer (e.g. share SSH and HTTPS on the same port) +- [**2516**星][3m] [kbandla/aptnotes](https://github.com/kbandla/aptnotes) Various public documents, whitepapers and articles about APT campaigns +- [**2508**星][5m] [Go] [oj/gobuster](https://github.com/oj/gobuster) Directory/File, DNS and VHost busting tool written in Go +- [**2507**星][2m] [Java] [jboss-javassist/javassist](https://github.com/jboss-javassist/javassist) Java bytecode engineering toolkit +- [**2507**星][3y] [C] [dhavalkapil/icmptunnel](https://github.com/dhavalkapil/icmptunnel) Transparently tunnel your IP traffic through ICMP echo and reply packets. - [**2503**星][7m] [C++] [chengr28/pcap_dnsproxy](https://github.com/chengr28/pcap_dnsproxy) Pcap_DNSProxy, a local DNS server based on packet capturing -- [**2495**星][2m] [Java] [jboss-javassist/javassist](https://github.com/jboss-javassist/javassist) Java bytecode engineering toolkit -- [**2488**星][1y] [onlurking/awesome-infosec](https://github.com/onlurking/awesome-infosec) A curated list of awesome infosec courses and training resources. -- [**2486**星][26d] [Py] [ysrc/xunfeng](https://github.com/ysrc/xunfeng) 巡风是一款适用于企业内网的漏洞快速应急,巡航扫描系统。 -- [**2481**星][5m] [Go] [oj/gobuster](https://github.com/oj/gobuster) Directory/File, DNS and VHost busting tool written in Go -- [**2480**星][8d] [Go] [adguardteam/adguardhome](https://github.com/adguardteam/adguardhome) Network-wide ads & trackers blocking DNS server +- [**2501**星][28d] [Py] [ysrc/xunfeng](https://github.com/ysrc/xunfeng) 巡风是一款适用于企业内网的漏洞快速应急,巡航扫描系统。 +- [**2498**星][6m] [taichi-framework/taichi](https://github.com/taichi-framework/taichi) A framework to use Xposed module with or without Root/Unlock bootloader, supportting Android 5.0 ~ 10.0 +- [**2497**星][6d] [onlurking/awesome-infosec](https://github.com/onlurking/awesome-infosec) A curated list of awesome infosec courses and training resources. +- [**2488**星][5y] [PHP] [audi-1/sqli-labs](https://github.com/audi-1/sqli-labs) SQLI labs to test error based, Blind boolean based, Time based. - [**2480**星][2y] [Py] [feross/spoofmac](https://github.com/feross/spoofmac) 伪造MAC地址(OS X, Windows, Linux) -- [**2473**星][5y] [PHP] [audi-1/sqli-labs](https://github.com/audi-1/sqli-labs) SQLI labs to test error based, Blind boolean based, Time based. -- [**2472**星][11m] [JS] [weixin/miaow](https://github.com/weixin/Miaow) A set of plugins for Sketch include drawing links & marks, UI Kit & Color sync, font & text replacing. -- [**2470**星][6m] [taichi-framework/taichi](https://github.com/taichi-framework/taichi) A framework to use Xposed module with or without Root/Unlock bootloader, supportting Android 5.0 ~ 10.0 -- [**2463**星][13d] [JS] [vitaly-t/pg-promise](https://github.com/vitaly-t/pg-promise) PostgreSQL interface for Node.js -- [**2458**星][3m] [C] [martin-ger/esp_wifi_repeater](https://github.com/martin-ger/esp_wifi_repeater) A full functional WiFi Repeater (correctly: a WiFi NAT Router) -- [**2456**星][4m] [Go] [ne0nd0g/merlin](https://github.com/ne0nd0g/merlin) Merlin is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in golang. -- [**2454**星][24d] [C++] [pavel-odintsov/fastnetmon](https://github.com/pavel-odintsov/fastnetmon) 快速 DDoS 检测/分析工具,支持 sflow/netflow/mirror -- [**2453**星][11m] [C#] [yck1509/confuserex](https://github.com/yck1509/confuserex) An open-source, free protector for .NET applications +- [**2476**星][11m] [JS] [weixin/miaow](https://github.com/weixin/Miaow) A set of plugins for Sketch include drawing links & marks, UI Kit & Color sync, font & text replacing. +- [**2476**星][4m] [Go] [ne0nd0g/merlin](https://github.com/ne0nd0g/merlin) Merlin is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in golang. +- [**2469**星][6d] [JS] [vitaly-t/pg-promise](https://github.com/vitaly-t/pg-promise) PostgreSQL interface for Node.js +- [**2466**星][30d] [Py] [smicallef/spiderfoot](https://github.com/smicallef/spiderfoot) 自动收集指定目标的信息:IP、域名、主机名、网络子网、ASN、邮件地址、用户名 +- [**2464**星][3m] [C] [martin-ger/esp_wifi_repeater](https://github.com/martin-ger/esp_wifi_repeater) A full functional WiFi Repeater (correctly: a WiFi NAT Router) +- [**2461**星][11m] [C#] [yck1509/confuserex](https://github.com/yck1509/confuserex) An open-source, free protector for .NET applications +- [**2461**星][26d] [C++] [pavel-odintsov/fastnetmon](https://github.com/pavel-odintsov/fastnetmon) 快速 DDoS 检测/分析工具,支持 sflow/netflow/mirror +- [**2454**星][21d] [Shell] [rebootuser/linenum](https://github.com/rebootuser/linenum) Scripted Local Linux Enumeration & Privilege Escalation Checks - [**2451**星][3y] [Py] [google/enjarify](https://github.com/google/enjarify) 将Dalvik字节码转换为对应的Java字节码 -- [**2441**星][28d] [Py] [smicallef/spiderfoot](https://github.com/smicallef/spiderfoot) 自动收集指定目标的信息:IP、域名、主机名、网络子网、ASN、邮件地址、用户名 -- [**2424**星][7d] [PHP] [misp/misp](https://github.com/misp/misp) MISP (core software) - Open Source Threat Intelligence and Sharing Platform (formely known as Malware Information Sharing Platform) -- [**2420**星][19d] [Shell] [rebootuser/linenum](https://github.com/rebootuser/linenum) Scripted Local Linux Enumeration & Privilege Escalation Checks -- [**2415**星][1m] [Py] [0xinfection/awesome-waf](https://github.com/0xinfection/awesome-waf) -- [**2412**星][23d] [Py] [pwndbg/pwndbg](https://github.com/pwndbg/pwndbg) GDB插件,辅助漏洞开发和逆向 -- [**2411**星][3y] [Py] [arthepsy/ssh-audit](https://github.com/arthepsy/ssh-audit) SSH server auditing (banner, key exchange, encryption, mac, compression, compatibility, security, etc) -- [**2407**星][1m] [TSQL] [rapid7/metasploitable3](https://github.com/rapid7/metasploitable3) Metasploitable3 is a VM that is built from the ground up with a large amount of security vulnerabilities. -- [**2404**星][24d] [Py] [infobyte/faraday](https://github.com/infobyte/faraday) 渗透测试和漏洞管理平台 -- [**2399**星][3y] [rpisec/malware](https://github.com/rpisec/malware) Course materials for Malware Analysis by RPISEC +- [**2444**星][2d] [PHP] [misp/misp](https://github.com/misp/misp) MISP (core software) - Open Source Threat Intelligence and Sharing Platform (formely known as Malware Information Sharing Platform) +- [**2429**星][1m] [Py] [0xinfection/awesome-waf](https://github.com/0xinfection/awesome-waf) +- [**2423**星][2d] [Py] [pwndbg/pwndbg](https://github.com/pwndbg/pwndbg) GDB插件,辅助漏洞开发和逆向 +- [**2420**星][1m] [TSQL] [rapid7/metasploitable3](https://github.com/rapid7/metasploitable3) Metasploitable3 is a VM that is built from the ground up with a large amount of security vulnerabilities. +- [**2417**星][26d] [Py] [infobyte/faraday](https://github.com/infobyte/faraday) 渗透测试和漏洞管理平台 +- [**2416**星][3y] [Py] [arthepsy/ssh-audit](https://github.com/arthepsy/ssh-audit) SSH server auditing (banner, key exchange, encryption, mac, compression, compatibility, security, etc) +- [**2411**星][26d] [Py] [xmendez/wfuzz](https://github.com/xmendez/wfuzz) Web application fuzzer +- [**2410**星][8m] [Py] [lionsec/katoolin](https://github.com/lionsec/katoolin) Automatically install all Kali linux tools +- [**2407**星][3y] [rpisec/malware](https://github.com/rpisec/malware) Course materials for Malware Analysis by RPISEC +- [**2404**星][20d] [Java] [m66b/netguard](https://github.com/m66b/netguard) A simple way to block access to the internet per app - [**2395**星][3y] [OCaml] [facebookarchive/pfff](https://github.com/facebookarchive/pfff) 一堆工具的集合,用于执行静态分析、代码可视化、代码导航、保持格式的源码转换(例如:源码重构)。完美支持C、Java、JS、PHP,后续将支持其他一大堆语言。 -- [**2395**星][24d] [Py] [xmendez/wfuzz](https://github.com/xmendez/wfuzz) Web application fuzzer -- [**2391**星][8m] [Py] [lionsec/katoolin](https://github.com/lionsec/katoolin) Automatically install all Kali linux tools -- [**2381**星][2y] [Py] [secretsquirrel/the-backdoor-factory](https://github.com/secretsquirrel/the-backdoor-factory) 为PE, ELF, Mach-O二进制文件添加Shellcode后门 -- [**2375**星][1y] [Py] [danmcinerney/lans.py](https://github.com/danmcinerney/lans.py) Inject code and spy on wifi users +- [**2392**星][1m] [Go] [xtaci/kcp-go](https://github.com/xtaci/kcp-go) provide a smooth, resilient, ordered, error-checked and anonymous delivery of streams over UDP packets, +- [**2389**星][8d] [C] [wireshark/wireshark](https://github.com/wireshark/wireshark) Read-only mirror of Wireshark's Git repository. GitHub won't let us disable pull requests. ☞ THEY WILL BE IGNORED HERE ☜ Please upload them at +- [**2386**星][2y] [Py] [secretsquirrel/the-backdoor-factory](https://github.com/secretsquirrel/the-backdoor-factory) 为PE, ELF, Mach-O二进制文件添加Shellcode后门 +- [**2384**星][2d] [Go] [owasp/amass](https://github.com/owasp/amass) In-depth Attack Surface Mapping and Asset Discovery +- [**2381**星][11m] [C] [haad/proxychains](https://github.com/haad/proxychains) a tool that forces any TCP connection made by any given application to follow through proxy like TOR or any other SOCKS4, SOCKS5 or HTTP(S) proxy. Supported auth-types: "user/pass" for SOCKS4/5, "basic" for HTTP. +- [**2376**星][2d] [Java] [mock-server/mockserver](https://github.com/mock-server/mockserver) MockServer enables easy mocking of any system you integrate with via HTTP or HTTPS with clients written in Java, JavaScript and Ruby. MockServer also includes a proxy that introspects all proxied traffic including encrypted SSL traffic and supports Port Forwarding, Web Proxying (i.e. HTTP proxy), HTTPS Tunneling Proxying (using HTTP CONNECT) and… +- [**2376**星][1y] [Py] [danmcinerney/lans.py](https://github.com/danmcinerney/lans.py) Inject code and spy on wifi users +- [**2369**星][7d] [security-onion-solutions/security-onion](https://github.com/security-onion-solutions/security-onion) Linux distro for intrusion detection, enterprise security monitoring, and log management - [**2369**星][2m] [TeX] [crypto101/book](https://github.com/crypto101/book) Crypto 101, the introductory book on cryptography. -- [**2368**星][7d] [C] [wireshark/wireshark](https://github.com/wireshark/wireshark) Read-only mirror of Wireshark's Git repository. GitHub won't let us disable pull requests. ☞ THEY WILL BE IGNORED HERE ☜ Please upload them at -- [**2366**星][7d] [Java] [mock-server/mockserver](https://github.com/mock-server/mockserver) MockServer enables easy mocking of any system you integrate with via HTTP or HTTPS with clients written in Java, JavaScript and Ruby. MockServer also includes a proxy that introspects all proxied traffic including encrypted SSL traffic and supports Port Forwarding, Web Proxying (i.e. HTTP proxy), HTTPS Tunneling Proxying (using HTTP CONNECT) and… -- [**2366**星][11m] [C] [haad/proxychains](https://github.com/haad/proxychains) a tool that forces any TCP connection made by any given application to follow through proxy like TOR or any other SOCKS4, SOCKS5 or HTTP(S) proxy. Supported auth-types: "user/pass" for SOCKS4/5, "basic" for HTTP. -- [**2359**星][1m] [Lua] [snabbco/snabb](https://github.com/snabbco/snabb) Simple and fast packet networking -- [**2359**星][13d] [security-onion-solutions/security-onion](https://github.com/security-onion-solutions/security-onion) Linux distro for intrusion detection, enterprise security monitoring, and log management -- [**2359**星][4m] [Go] [mlabouardy/komiser](https://github.com/mlabouardy/komiser) -- [**2351**星][8d] [C] [domoticz/domoticz](https://github.com/domoticz/domoticz) monitor and configure various devices like: Lights, Switches, various sensors/meters like Temperature, Rain, Wind, UV, Electra, Gas, Water and much more -- [**2350**星][1m] [Py] [ab77/netflix-proxy](https://github.com/ab77/netflix-proxy) Smart DNS proxy to watch Netflix +- [**2366**星][4m] [Go] [mlabouardy/komiser](https://github.com/mlabouardy/komiser) +- [**2364**星][2m] [Py] [ab77/netflix-proxy](https://github.com/ab77/netflix-proxy) Smart DNS proxy to watch Netflix +- [**2362**星][1m] [Lua] [snabbco/snabb](https://github.com/snabbco/snabb) Simple and fast packet networking +- [**2357**星][2d] [C] [domoticz/domoticz](https://github.com/domoticz/domoticz) monitor and configure various devices like: Lights, Switches, various sensors/meters like Temperature, Rain, Wind, UV, Electra, Gas, Water and much more +- [**2352**星][1m] [Py] [ctfd/ctfd](https://github.com/CTFd/CTFd) CTFs as you need them +- [**2349**星][11m] [hack-with-github/free-security-ebooks](https://github.com/hack-with-github/free-security-ebooks) Free Security and Hacking eBooks - [**2342**星][3m] [Go] [vuvuzela/vuvuzela](https://github.com/vuvuzela/vuvuzela) Private messaging system that hides metadata -- [**2342**星][12d] [Go] [owasp/amass](https://github.com/owasp/amass) In-depth Attack Surface Mapping and Asset Discovery -- [**2338**星][6y] [C] [stefanesser/dumpdecrypted](https://github.com/stefanesser/dumpdecrypted) Dumps decrypted mach-o files from encrypted iPhone applications from memory to disk. This tool is necessary for security researchers to be able to look under the hood of encryption. -- [**2335**星][11m] [hack-with-github/free-security-ebooks](https://github.com/hack-with-github/free-security-ebooks) Free Security and Hacking eBooks -- [**2332**星][1m] [Py] [ctfd/ctfd](https://github.com/CTFd/CTFd) CTFs as you need them -- [**2330**星][1m] [JS] [pa11y/pa11y](https://github.com/pa11y/pa11y) Pa11y is your automated accessibility testing pal -- [**2324**星][30d] [C] [hfiref0x/uacme](https://github.com/hfiref0x/uacme) Defeating Windows User Account Control -- [**2317**星][10d] [C] [tsl0922/ttyd](https://github.com/tsl0922/ttyd) Share your terminal over the web -- [**2316**星][5y] [C] [abrasive/shairport](https://github.com/abrasive/shairport) Airtunes emulator! Shairport is no longer maintained. -- [**2302**星][11m] [yeyintminthuhtut/awesome-red-teaming](https://github.com/yeyintminthuhtut/awesome-red-teaming) List of Awesome Red Teaming Resources -- [**2302**星][1y] [Java] [csploit/android](https://github.com/csploit/android) cSploit - The most complete and advanced IT security professional toolkit on Android. -- [**2291**星][3y] [Py] [lmacken/pyrasite](https://github.com/lmacken/pyrasite) 向运行中的 Python进程注入代码 -- [**2277**星][3m] [JS] [retirejs/retire.js](https://github.com/retirejs/retire.js) scanner detecting the use of JavaScript libraries with known vulnerabilities -- [**2272**星][3y] [Py] [therook/subbrute](https://github.com/therook/subbrute) A DNS meta-query spider that enumerates DNS records, and subdomains. -- [**2272**星][1m] [C] [moby/hyperkit](https://github.com/moby/hyperkit) A toolkit for embedding hypervisor capabilities in your application -- [**2271**星][22d] [JS] [talkingdata/inmap](https://github.com/talkingdata/inmap) 大数据地理可视化 -- [**2271**星][2y] [Py] [rootphantomer/blasting_dictionary](https://github.com/rootphantomer/blasting_dictionary) 爆破字典 -- [**2267**星][1m] [C] [aurorawright/luma3ds](https://github.com/aurorawright/luma3ds) Noob-proof (N)3DS "Custom Firmware" -- [**2246**星][16d] [dumb-password-rules/dumb-password-rules](https://github.com/dumb-password-rules/dumb-password-rules) Shaming sites with dumb password rules. -- [**2244**星][2y] [Go] [mehrdadrad/mylg](https://github.com/mehrdadrad/mylg) 网络诊断工具 -- [**2242**星][1m] [Shell] [v1s1t0r1sh3r3/airgeddon](https://github.com/v1s1t0r1sh3r3/airgeddon) This is a multi-use bash script for Linux systems to audit wireless networks. -- [**2241**星][13d] [HTML] [tikam02/devops-guide](https://github.com/tikam02/devops-guide) DevOps Guide from basic to advanced with Interview Questions and Notes -- [**2241**星][3m] [Py] [novnc/websockify](https://github.com/novnc/websockify) Websockify is a WebSocket to TCP proxy/bridge. This allows a browser to connect to any application/server/service. Implementations in Python, C, Node.js and Ruby. -- [**2235**星][1m] [Shell] [eliaskotlyar/xiaomi-dafang-hacks](https://github.com/eliaskotlyar/xiaomi-dafang-hacks) +- [**2340**星][6y] [C] [stefanesser/dumpdecrypted](https://github.com/stefanesser/dumpdecrypted) Dumps decrypted mach-o files from encrypted iPhone applications from memory to disk. This tool is necessary for security researchers to be able to look under the hood of encryption. +- [**2340**星][1m] [C] [hfiref0x/uacme](https://github.com/hfiref0x/uacme) Defeating Windows User Account Control +- [**2337**星][1m] [JS] [pa11y/pa11y](https://github.com/pa11y/pa11y) Pa11y is your automated accessibility testing pal +- [**2335**星][3d] [C] [tsl0922/ttyd](https://github.com/tsl0922/ttyd) Share your terminal over the web +- [**2323**星][3d] [C#] [netchx/netch](https://github.com/netchx/netch) Game accelerator. Support Socks5, Shadowsocks, ShadowsocksR, V2Ray protocol. UDP NAT FullCone +- [**2321**星][11m] [yeyintminthuhtut/awesome-red-teaming](https://github.com/yeyintminthuhtut/awesome-red-teaming) List of Awesome Red Teaming Resources +- [**2318**星][5y] [C] [abrasive/shairport](https://github.com/abrasive/shairport) Airtunes emulator! Shairport is no longer maintained. +- [**2304**星][1y] [Java] [csploit/android](https://github.com/csploit/android) cSploit - The most complete and advanced IT security professional toolkit on Android. +- [**2301**星][15d] [HTML] [tikam02/devops-guide](https://github.com/tikam02/devops-guide) DevOps Guide from basic to advanced with Interview Questions and Notes +- [**2295**星][3y] [Py] [lmacken/pyrasite](https://github.com/lmacken/pyrasite) 向运行中的 Python进程注入代码 +- [**2287**星][2y] [Py] [rootphantomer/blasting_dictionary](https://github.com/rootphantomer/blasting_dictionary) 爆破字典 +- [**2284**星][1m] [C] [moby/hyperkit](https://github.com/moby/hyperkit) A toolkit for embedding hypervisor capabilities in your application +- [**2283**星][5m] [Py] [guohongze/adminset](https://github.com/guohongze/adminset) 自动化运维平台:CMDB、CD、DevOps、资产管理、任务编排、持续交付、系统监控、运维管理、配置管理 +- [**2282**星][3y] [Py] [therook/subbrute](https://github.com/therook/subbrute) A DNS meta-query spider that enumerates DNS records, and subdomains. +- [**2281**星][3m] [JS] [retirejs/retire.js](https://github.com/retirejs/retire.js) scanner detecting the use of JavaScript libraries with known vulnerabilities +- [**2276**星][24d] [JS] [talkingdata/inmap](https://github.com/talkingdata/inmap) 大数据地理可视化 +- [**2274**星][1m] [Shell] [v1s1t0r1sh3r3/airgeddon](https://github.com/v1s1t0r1sh3r3/airgeddon) This is a multi-use bash script for Linux systems to audit wireless networks. +- [**2270**星][1m] [C] [aurorawright/luma3ds](https://github.com/aurorawright/luma3ds) Noob-proof (N)3DS "Custom Firmware" +- [**2255**星][3m] [Py] [novnc/websockify](https://github.com/novnc/websockify) Websockify is a WebSocket to TCP proxy/bridge. This allows a browser to connect to any application/server/service. Implementations in Python, C, Node.js and Ruby. +- [**2252**星][18d] [dumb-password-rules/dumb-password-rules](https://github.com/dumb-password-rules/dumb-password-rules) Shaming sites with dumb password rules. +- [**2252**星][1m] [Shell] [eliaskotlyar/xiaomi-dafang-hacks](https://github.com/eliaskotlyar/xiaomi-dafang-hacks) +- [**2248**星][12d] [PS] [k8gege/k8tools](https://github.com/k8gege/k8tools) K8工具合集(内网渗透/提权工具/远程溢出/漏洞利用/扫描工具/密码破解/免杀工具/Exploit/APT/0day/Shellcode/Payload/priviledge/BypassUAC/OverFlow/WebShell/PenTest) Web GetShell Exploit(Struts2/Zimbra/Weblogic/Tomcat/Apache/Jboss/DotNetNuke/zabbix) +- [**2245**星][2y] [Go] [mehrdadrad/mylg](https://github.com/mehrdadrad/mylg) 网络诊断工具 - [**2226**星][5y] [Go] [filosottile/heartbleed](https://github.com/filosottile/heartbleed) A checker (site and tool) for CVE-2014-0160 -- [**2222**星][8d] [C#] [netchx/netch](https://github.com/netchx/netch) Game accelerator. Support Socks5, Shadowsocks, ShadowsocksR, V2Ray protocol. UDP NAT FullCone -- [**2218**星][7d] [Py] [cloudflare/flan](https://github.com/cloudflare/flan) A pretty sweet vulnerability scanner +- [**2217**星][1y] [JS] [cure53/h5sc](https://github.com/cure53/h5sc) HTML5 Security Cheatsheet - A collection of HTML5 related XSS attack vectors - [**2215**星][6y] [C++] [codebutler/firesheep](https://github.com/codebutler/firesheep) 演示HTTP会话劫持攻击的Firefox扩展 -- [**2211**星][1y] [JS] [cure53/h5sc](https://github.com/cure53/h5sc) HTML5 Security Cheatsheet - A collection of HTML5 related XSS attack vectors -- [**2204**星][10d] [PowerShell] [k8gege/k8tools](https://github.com/k8gege/k8tools) K8工具合集(内网渗透/提权工具/远程溢出/漏洞利用/扫描工具/密码破解/免杀工具/Exploit/APT/0day/Shellcode/Payload/priviledge/BypassUAC/OverFlow/WebShell/PenTest) Web GetShell Exploit(Struts2/Zimbra/Weblogic/Tomcat/Apache/Jboss/DotNetNuke/zabbix) -- [**2203**星][1m] [C] [texane/stlink](https://github.com/texane/stlink) stm32 discovery line linux programmer -- [**2201**星][11d] [Go] [google/mtail](https://github.com/google/mtail) extract whitebox monitoring data from application logs for collection in a timeseries database -- [**2187**星][21d] [C++] [google/bloaty](https://github.com/google/bloaty) Bloaty McBloatface: a size profiler for binaries +- [**2213**星][2d] [Go] [aquasecurity/kube-bench](https://github.com/aquasecurity/kube-bench) Checks whether Kubernetes is deployed according to security best practices as defined in the CIS Kubernetes Benchmark +- [**2211**星][1m] [C] [texane/stlink](https://github.com/texane/stlink) stm32 discovery line linux programmer +- [**2211**星][6d] [Go] [google/mtail](https://github.com/google/mtail) extract whitebox monitoring data from application logs for collection in a timeseries database +- [**2209**星][22d] [Rust] [cloudflare/boringtun](https://github.com/cloudflare/boringtun) an implementation of the WireGuard® protocol designed for portability and speed. +- [**2192**星][23d] [C++] [google/bloaty](https://github.com/google/bloaty) Bloaty McBloatface: a size profiler for binaries +- [**2189**星][1m] [sobolevn/awesome-cryptography](https://github.com/sobolevn/awesome-cryptography) A curated list of cryptography resources and links. +- [**2187**星][7d] [getlantern/lantern-binaries](https://github.com/getlantern/lantern-binaries) Lantern installers binary downloads. +- [**2186**星][1y] [Py] [datasploit/datasploit](https://github.com/DataSploit/datasploit) 对指定目标执行多种侦查技术:企业、人、电话号码、比特币地址等 - [**2184**星][3y] [enddo/awesome-windows-exploitation](https://github.com/enddo/awesome-windows-exploitation) A curated list of awesome Windows Exploitation resources, and shiny things. Inspired by awesom -- [**2182**星][1y] [Py] [datasploit/datasploit](https://github.com/DataSploit/datasploit) 对指定目标执行多种侦查技术:企业、人、电话号码、比特币地址等 -- [**2177**星][1m] [JS] [secgroundzero/warberry](https://github.com/secgroundzero/warberry) WarBerryPi - Tactical Exploitation -- [**2171**星][14d] [C] [armmbed/mbedtls](https://github.com/armmbed/mbedtls) An open source, portable, easy to use, readable and flexible SSL library -- [**2168**星][16d] [getlantern/lantern-binaries](https://github.com/getlantern/lantern-binaries) Lantern installers binary downloads. -- [**2167**星][29d] [sobolevn/awesome-cryptography](https://github.com/sobolevn/awesome-cryptography) A curated list of cryptography resources and links. -- [**2158**星][2m] [Go] [mmatczuk/go-http-tunnel](https://github.com/mmatczuk/go-http-tunnel) Fast and secure tunnels over HTTP/2 -- [**2156**星][1m] [C] [conorpp/u2f-zero](https://github.com/conorpp/u2f-zero) U2F USB token optimized for physical security, affordability, and style -- [**2155**星][1y] [C++] [maestron/botnets](https://github.com/maestron/botnets) This is a collection of #botnet source codes, unorganized. For EDUCATIONAL PURPOSES ONLY +- [**2183**星][2d] [C] [armmbed/mbedtls](https://github.com/armmbed/mbedtls) An open source, portable, easy to use, readable and flexible SSL library +- [**2179**星][1m] [JS] [secgroundzero/warberry](https://github.com/secgroundzero/warberry) WarBerryPi - Tactical Exploitation +- [**2173**星][1y] [JS] [iam4x/pokemongo-webspoof](https://github.com/iam4x/pokemongo-webspoof) +- [**2163**星][2m] [Go] [mmatczuk/go-http-tunnel](https://github.com/mmatczuk/go-http-tunnel) Fast and secure tunnels over HTTP/2 +- [**2162**星][1y] [C++] [maestron/botnets](https://github.com/maestron/botnets) This is a collection of #botnet source codes, unorganized. For EDUCATIONAL PURPOSES ONLY +- [**2159**星][1m] [Py] [commixproject/commix](https://github.com/commixproject/commix) Automated All-in-One OS command injection and exploitation tool. +- [**2158**星][9m] [exakat/php-static-analysis-tools](https://github.com/exakat/php-static-analysis-tools) A reviewed list of useful PHP static analysis tools +- [**2158**星][1m] [C] [conorpp/u2f-zero](https://github.com/conorpp/u2f-zero) U2F USB token optimized for physical security, affordability, and style +- [**2158**星][2m] [PHP] [antonioribeiro/tracker](https://github.com/antonioribeiro/tracker) Tracker gathers a lot of information from your requests to identify and store - [**2153**星][6y] [Ruby] [plamoni/siriproxy](https://github.com/plamoni/siriproxy) A (tampering) proxy server for Apple's Siri -- [**2152**星][29d] [Py] [commixproject/commix](https://github.com/commixproject/commix) Automated All-in-One OS command injection and exploitation tool. -- [**2151**星][9m] [exakat/php-static-analysis-tools](https://github.com/exakat/php-static-analysis-tools) A reviewed list of useful PHP static analysis tools -- [**2146**星][14d] [Java] [google/wycheproof](https://github.com/google/wycheproof) Project Wycheproof tests crypto libraries against known attacks. -- [**2127**星][1m] [Py] [jonathansalwan/ropgadget](https://github.com/jonathansalwan/ropgadget) This tool lets you search your gadgets on your binaries to facilitate your ROP exploitation. ROPgadget supports ELF, PE and Mach-O format on x86, x64, ARM, ARM64, PowerPC, SPARC and MIPS architectures. -- [**2124**星][2m] [Py] [trustedsec/unicorn](https://github.com/trustedsec/unicorn) 通过PowerShell降级攻击, 直接将Shellcode注入到内存 -- [**2123**星][16d] [Assembly] [pret/pokered](https://github.com/pret/pokered) disassembly of Pokémon Red/Blue -- [**2114**星][7m] [Py] [calebmadrigal/trackerjacker](https://github.com/calebmadrigal/trackerjacker) 映射你没连接到的Wifi网络, 类似于NMap, 另外可以追踪设备 -- [**2112**星][1y] [Py] [rub-nds/pret](https://github.com/rub-nds/pret) Printer Exploitation Toolkit - The tool that made dumpster diving obsolete. +- [**2149**星][8d] [Java] [google/wycheproof](https://github.com/google/wycheproof) Project Wycheproof tests crypto libraries against known attacks. +- [**2138**星][2m] [Py] [trustedsec/unicorn](https://github.com/trustedsec/unicorn) 通过PowerShell降级攻击, 直接将Shellcode注入到内存 +- [**2132**星][1m] [Py] [jonathansalwan/ropgadget](https://github.com/jonathansalwan/ropgadget) This tool lets you search your gadgets on your binaries to facilitate your ROP exploitation. ROPgadget supports ELF, PE and Mach-O format on x86, x64, ARM, ARM64, PowerPC, SPARC and MIPS architectures. +- [**2127**星][18d] [Assembly] [pret/pokered](https://github.com/pret/pokered) disassembly of Pokémon Red/Blue +- [**2122**星][2y] [Py] [rub-nds/pret](https://github.com/rub-nds/pret) Printer Exploitation Toolkit - The tool that made dumpster diving obsolete. +- [**2118**星][4d] [goq/telegram-list](https://github.com/goq/telegram-list) List of telegram groups, channels & bots // Список интересных групп, каналов и ботов телеграма // Список чатов для программистов +- [**2117**星][1m] [Py] [elceef/dnstwist](https://github.com/elceef/dnstwist) 域名置换引擎,用于检测打字错误,网络钓鱼和企业间谍活动 +- [**2116**星][7m] [Py] [calebmadrigal/trackerjacker](https://github.com/calebmadrigal/trackerjacker) 映射你没连接到的Wifi网络, 类似于NMap, 另外可以追踪设备 +- [**2115**星][2d] [Py] [fortynorthsecurity/eyewitness](https://github.com/FortyNorthSecurity/EyeWitness) 给网站做快照,提供服务器Header信息,识别默认凭证等 +- [**2114**星][7y] [C++] [lloyd/node-memwatch](https://github.com/lloyd/node-memwatch) A NodeJS library to keep an eye on your memory usage, and discover and isolate leaks. - [**2107**星][4y] [C] [hashcat/hashcat-legacy](https://github.com/hashcat/hashcat-legacy) Advanced CPU-based password recovery utility -- [**2105**星][7d] [goq/telegram-list](https://github.com/goq/telegram-list) List of telegram groups, channels & bots // Список интересных групп, каналов и ботов телеграма // Список чатов для программистов -- [**2105**星][1m] [Py] [elceef/dnstwist](https://github.com/elceef/dnstwist) 域名置换引擎,用于检测打字错误,网络钓鱼和企业间谍活动 -- [**2103**星][8m] [Py] [linkedin/qark](https://github.com/linkedin/qark) 查找Android App的漏洞, 支持源码或APK文件 -- [**2098**星][19d] [Py] [fortynorthsecurity/eyewitness](https://github.com/FortyNorthSecurity/EyeWitness) 给网站做快照,提供服务器Header信息,识别默认凭证等 -- [**2098**星][21d] [infoslack/awesome-web-hacking](https://github.com/infoslack/awesome-web-hacking) A list of web application security -- [**2090**星][3m] [yeahhub/hacking-security-ebooks](https://github.com/yeahhub/hacking-security-ebooks) Top 100 Hacking & Security E-Books (Free Download) -- [**2081**星][8d] [C] [flatpak/flatpak](https://github.com/flatpak/flatpak) Linux application sandboxing and distribution framework -- [**2071**星][30d] [Go] [theupdateframework/notary](https://github.com/theupdateframework/notary) Notary is a project that allows anyone to have trust over arbitrary collections of data -- [**2069**星][20d] [Ruby] [urbanadventurer/whatweb](https://github.com/urbanadventurer/whatweb) Next generation web scanner -- [**2062**星][9m] [jermic/android-crack-tool](https://github.com/jermic/android-crack-tool) -- [**2051**星][4m] [Py] [whaleshark-team/cobra](https://github.com/WhaleShark-Team/cobra) Source Code Security Audit (源代码安全审计) -- [**2049**星][1y] [bluscreenofjeff/red-team-infrastructure-wiki](https://github.com/bluscreenofjeff/red-team-infrastructure-wiki) Wiki to collect Red Team infrastructure hardening resources -- [**2047**星][6m] [Go] [maxmcd/webtty](https://github.com/maxmcd/webtty) Share a terminal session over WebRTC -- [**2041**星][2y] [Py] [derv82/wifite](https://github.com/derv82/wifite) 自动化无线攻击工具 -- [**2037**星][10d] [Py] [nabla-c0d3/sslyze](https://github.com/nabla-c0d3/sslyze) SSL/TLS服务器扫描 -- [**2036**星][2m] [C++] [lordnoteworthy/al-khaser](https://github.com/lordnoteworthy/al-khaser) Public malware techniques used in the wild: Virtual Machine, Emulation, Debuggers, Sandbox detection. -- [**2035**星][2m] [tanprathan/mobileapp-pentest-cheatsheet](https://github.com/tanprathan/mobileapp-pentest-cheatsheet) The Mobile App Pentest cheat sheet was created to provide concise collection of high value information on specific mobile application penetration testing topics. -- [**2035**星][8m] [Shell] [foospidy/payloads](https://github.com/foospidy/payloads) web 攻击 Payload 集合 -- [**2032**星][7d] [C++] [openthread/openthread](https://github.com/openthread/openthread) OpenThread released by Google is an open-source implementation of the Thread networking protocol -- [**2032**星][1m] [edoverflow/bugbounty-cheatsheet](https://github.com/edoverflow/bugbounty-cheatsheet) A list of interesting payloads, tips and tricks for bug bounty hunters. -- [**2024**星][5y] [CoffeeScript] [shadowsocks/shadowsocks-gui](https://github.com/shadowsocks/shadowsocks-gui) Shadowsocks GUI client -- [**2020**星][20d] [Objective-C] [ios-control/ios-deploy](https://github.com/ios-control/ios-deploy) Install and debug iPhone apps from the command line, without using Xcode -- [**2017**星][3m] [C++] [darthton/blackbone](https://github.com/darthton/blackbone) Windows memory hacking library -- [**2016**星][3y] [Swift] [urinx/iosapphook](https://github.com/urinx/iosapphook) 专注于非越狱环境下iOS应用逆向研究,从dylib注入,应用重签名到App Hook -- [**2014**星][8d] [Py] [sensepost/objection](https://github.com/sensepost/objection) runtimemobile exploration -- [**2012**星][1y] [C] [xoreaxeaxeax/rosenbridge](https://github.com/xoreaxeaxeax/rosenbridge) Hardware backdoors in some x86 CPUs -- [**2006**星][9m] [C] [dekunukem/nintendo_switch_reverse_engineering](https://github.com/dekunukem/nintendo_switch_reverse_engineering) A look at inner workings of Joycon and Nintendo Switch -- [**2004**星][4y] [C] [probablycorey/wax](https://github.com/probablycorey/wax) Wax is now being maintained by alibaba -- [**1999**星][8d] [Java] [jeremylong/dependencycheck](https://github.com/jeremylong/dependencycheck) OWASP dependency-check is a software composition analysis utility that detects publicly disclosed vulnerabilities in application dependencies. -- [**1998**星][13d] [Shell] [wulabing/v2ray_ws-tls_bash_onekey](https://github.com/wulabing/v2ray_ws-tls_bash_onekey) V2Ray Nginx+vmess+ws+tls/ http2 over tls 一键安装脚本 -- [**1992**星][25d] [Swift] [github/softu2f](https://github.com/github/softu2f) Software U2F authenticator for macOS -- [**1991**星][29d] [qazbnm456/awesome-cve-poc](https://github.com/qazbnm456/awesome-cve-poc) CVE PoC列表 -- [**1990**星][4m] [swiftonsecurity/sysmon-config](https://github.com/swiftonsecurity/sysmon-config) Sysmon configuration file template with default high-quality event tracing -- [**1988**星][4y] [Go] [yahoo/gryffin](https://github.com/yahoo/gryffin) Gryffin is a large scale web security scanning platform. -- [**1987**星][7m] [Py] [fsecurelabs/drozer](https://github.com/FSecureLABS/drozer) The Leading Security Assessment Framework for Android. -- [**1983**星][2y] [dloss/python-pentest-tools](https://github.com/dloss/python-pentest-tools) 可用于渗透测试的Python工具收集 -- [**1983**星][2m] [C++] [asmjit/asmjit](https://github.com/asmjit/asmjit) Complete x86/x64 JIT and AOT Assembler for C++ -- [**1976**星][3m] [infosecn1nja/ad-attack-defense](https://github.com/infosecn1nja/ad-attack-defense) Attack and defend active directory using modern post exploitation adversary tradecraft activity -- [**1967**星][26d] [Java] [genymobile/gnirehtet](https://github.com/genymobile/gnirehtet) Gnirehtet provides reverse tethering for Android -- [**1965**星][9m] [JS] [weichiachang/stacks-cli](https://github.com/weichiachang/stacks-cli) Check website stack from the terminal -- [**1963**星][11d] [HTML] [gtfobins/gtfobins.github.io](https://github.com/gtfobins/gtfobins.github.io) Curated list of Unix binaries that can be exploited to bypass system security restrictions -- [**1963**星][27d] [Java] [elderdrivers/edxposed](https://github.com/elderdrivers/edxposed) Elder driver Xposed Framework. -- [**1962**星][1m] [Py] [momosecurity/aswan](https://github.com/momosecurity/aswan) 陌陌风控系统静态规则引擎,零基础简易便捷的配置多种复杂规则,实时高效管控用户异常行为。 -- [**1958**星][26d] [C#] [mathewsachin/captura](https://github.com/mathewsachin/captura) Capture Screen, Audio, Cursor, Mouse Clicks and Keystrokes -- [**1957**星][9d] [Go] [ullaakut/cameradar](https://github.com/Ullaakut/cameradar) Cameradar hacks its way into RTSP videosurveillance cameras -- [**1954**星][1y] [BitBake] [1n3/intruderpayloads](https://github.com/1n3/intruderpayloads) A collection of Burpsuite Intruder payloads, BurpBounty payloads, fuzz lists, malicious file uploads and web pentesting methodologies and checklists. -- [**1946**星][2y] [obfuscator-llvm/obfuscator](https://github.com/obfuscator-llvm/obfuscator) Obfuscator-LLVM -- [**1945**星][7d] [Perl] [spiderlabs/owasp-modsecurity-crs](https://github.com/spiderlabs/owasp-modsecurity-crs) OWASP ModSecurity Core Rule Set (CRS) Project (Official Repository) -- [**1940**星][3y] [C#] [lazocoder/windows-hacks](https://github.com/lazocoder/windows-hacks) Creative and unusual things that can be done with the Windows API. -- [**1939**星][2m] [C] [microsoft/procdump-for-linux](https://github.com/microsoft/procdump-for-linux) Linux 版本的 ProcDump -- [**1938**星][27d] [Py] [nixawk/pentest-wiki](https://github.com/nixawk/pentest-wiki) PENTEST-WIKI is a free online security knowledge library for pentesters / researchers. If you have a good idea, please share it with others. -- [**1938**星][14d] [Py] [cea-sec/miasm](https://github.com/cea-sec/miasm) Reverse engineering framework in Python -- [**1926**星][17d] [Go] [mpolden/echoip](https://github.com/mpolden/echoip) IP address lookup service -- [**1913**星][5m] [C] [darkk/redsocks](https://github.com/darkk/redsocks) transparent TCP-to-proxy redirector -- [**1912**星][3m] [toolswatch/blackhat-arsenal-tools](https://github.com/toolswatch/blackhat-arsenal-tools) Black Hat 武器库 -- [**1911**星][3y] [Py] [aoncyberlabs/windows-exploit-suggester](https://github.com/AonCyberLabs/Windows-Exploit-Suggester) This tool compares a targets patch levels against the Microsoft vulnerability database in order to detect potential missing patches on the target. It also notifies the user if there are public exploits and Metasploit modules available for the missing bulletins. -- [**1911**星][8d] [C] [ntop/ndpi](https://github.com/ntop/ndpi) Open Source Deep Packet Inspection Software Toolkit -- [**1909**星][3d] [Go] [projectdiscovery/subfinder](https://github.com/projectdiscovery/subfinder) Subfinder is a subdomain discovery tool that discovers valid subdomains for websites. Designed as a passive framework to be useful for bug bounties and safe for penetration testing. -- [**1909**星][9d] [Py] [j3ssie/osmedeus](https://github.com/j3ssie/osmedeus) Fully automated offensive security framework for reconnaissance and vulnerability scanning -- [**1908**星][7d] [C++] [powerdns/pdns](https://github.com/powerdns/pdns) PowerDNS -- [**1907**星][16d] [Py] [lanjelot/patator](https://github.com/lanjelot/patator) Patator is a multi-purpose brute-forcer, with a modular design and a flexible usage. -- [**1906**星][13d] [CSS] [cyb3rward0g/helk](https://github.com/cyb3rward0g/helk) 对ELK栈进行分析,具备多种高级功能,例如SQL声明性语言,图形,结构化流,机器学习等 -- [**1902**星][7d] [Go] [solo-io/gloo](https://github.com/solo-io/gloo) An Envoy-Powered API Gateway -- [**1901**星][3m] [Go] [minishift/minishift](https://github.com/minishift/minishift) Run OpenShift 3.x locally -- [**1892**星][19d] [C] [chipsec/chipsec](https://github.com/chipsec/chipsec) 分析PC平台的安全性, 包括硬件、系统固件(BIOS/UEFI)和平台组件 -- [**1891**星][7d] [Py] [mozilla/mozdef](https://github.com/mozilla/mozdef) Mozilla Enterprise Defense Platform -- [**1886**星][8d] [Go] [chaitin/xray](https://github.com/chaitin/xray) xray 安全评估工具 | 使用之前务必先阅读文档 -- [**1880**星][14d] [C++] [mhammond/pywin32](https://github.com/mhammond/pywin32) Python for Windows (pywin32) Extensions -- [**1878**星][4m] [C] [shadowsocks/simple-obfs](https://github.com/shadowsocks/simple-obfs) A simple obfuscating tool (Deprecated) -- [**1876**星][7d] [Shell] [toniblyx/prowler](https://github.com/toniblyx/prowler) AWS Security Best Practices Assessment, Auditing, Hardening and Forensics Readiness Tool. It follows guidelines of the CIS Amazon Web Services Foundations Benchmark and DOZENS of additional checks including GDPR and HIPAA (+100). Official CIS for AWS guide: -- [**1876**星][5y] [C++] [tum-vision/lsd_slam](https://github.com/tum-vision/lsd_slam) LSD-SLAM -- [**1876**星][4m] [Py] [python-security/pyt](https://github.com/python-security/pyt) Python Web App 安全漏洞检测和静态分析工具 -- [**1876**星][6m] [Java] [fuzion24/justtrustme](https://github.com/fuzion24/justtrustme) An xposed module that disables SSL certificate checking for the purposes of auditing an app with cert pinning -- [**1876**星][1y] [Py] [aploium/zmirror](https://github.com/aploium/zmirror) The next-gen reverse proxy for full site mirroring -- [**1869**星][13d] [YARA] [yara-rules/rules](https://github.com/yara-rules/rules) Repository of yara rules -- [**1868**星][1y] [Py] [derv82/wifite2](https://github.com/derv82/wifite2) 无线网络审计工具wifite 的升级版/重制版 -- [**1867**星][2m] [Py] [pycqa/bandit](https://github.com/pycqa/bandit) 在Python代码中查找常见的安全问题 -- [**1864**星][7d] [C] [merbanan/rtl_433](https://github.com/merbanan/rtl_433) Program to decode traffic from Devices that are broadcasting on 433.9 MHz like temperature sensors -- [**1863**星][4y] [Objective-C] [xcodeghostsource/xcodeghost](https://github.com/xcodeghostsource/xcodeghost) "XcodeGhost" Source -- [**1861**星][10m] [PHP] [bartblaze/php-backdoors](https://github.com/bartblaze/php-backdoors) A collection of PHP backdoors. For educational or testing purposes only. -- [**1861**星][4m] [Java] [adoptopenjdk/jitwatch](https://github.com/adoptopenjdk/jitwatch) Log analyser / visualiser for Java HotSpot JIT compiler. Inspect inlining decisions, hot methods, bytecode, and assembly. View results in the JavaFX user interface. -- [**1858**星][10d] [Py] [aquasecurity/kube-hunter](https://github.com/aquasecurity/kube-hunter) Hunt for security weaknesses in Kubernetes clusters -- [**1857**星][21d] [C] [tinyproxy/tinyproxy](https://github.com/tinyproxy/tinyproxy) a light-weight HTTP/HTTPS proxy daemon for POSIX operating systems -- [**1857**星][7d] [olivierlaflamme/cheatsheet-god](https://github.com/olivierlaflamme/cheatsheet-god) Penetration Testing Reference Bank - OSCP / PTP & PTX Cheatsheet -- [**1849**星][11m] [C++] [googlecreativelab/open-nsynth-super](https://github.com/googlecreativelab/open-nsynth-super) Open NSynth Super is an experimental physical interface for the NSynth algorithm -- [**1848**星][29d] [C] [github/glb-director](https://github.com/github/glb-director) GitHub Load Balancer Director and supporting tooling. -- [**1846**星][8m] [Py] [netflix-skunkworks/stethoscope](https://github.com/Netflix-Skunkworks/stethoscope) Personalized, user-focused recommendations for employee information security. -- [**1845**星][2m] [Py] [pwnlandia/mhn](https://github.com/pwnlandia/mhn) 蜜罐网络 -- [**1844**星][8d] [TypeScript] [snyk/snyk](https://github.com/snyk/snyk) CLI and build-time tool to find & fix known vulnerabilities in open-source dependencies -- [**1842**星][1y] [Java] [jindrapetrik/jpexs-decompiler](https://github.com/jindrapetrik/jpexs-decompiler) JPEXS Free Flash Decompiler -- [**1841**星][13d] [C++] [acidanthera/lilu](https://github.com/acidanthera/Lilu) Arbitrary kext and process patching on macOS +- [**2105**星][8m] [Py] [linkedin/qark](https://github.com/linkedin/qark) 查找Android App的漏洞, 支持源码或APK文件 +- [**2103**星][3m] [yeahhub/hacking-security-ebooks](https://github.com/yeahhub/hacking-security-ebooks) Top 100 Hacking & Security E-Books (Free Download) +- [**2103**星][23d] [infoslack/awesome-web-hacking](https://github.com/infoslack/awesome-web-hacking) A list of web application security +- [**2095**星][2d] [C] [wireguard/wireguard](https://github.com/wireguard/wireguard) fast, modern, secure kernel VPN tunnel +- [**2093**星][22d] [Ruby] [urbanadventurer/whatweb](https://github.com/urbanadventurer/whatweb) Next generation web scanner +- [**2084**星][5d] [C] [flatpak/flatpak](https://github.com/flatpak/flatpak) Linux application sandboxing and distribution framework +- [**2078**星][1m] [Go] [theupdateframework/notary](https://github.com/theupdateframework/notary) Notary is a project that allows anyone to have trust over arbitrary collections of data +- [**2071**星][15d] [Shell] [wulabing/v2ray_ws-tls_bash_onekey](https://github.com/wulabing/v2ray_ws-tls_bash_onekey) V2Ray Nginx+vmess+ws+tls/ http2 over tls 一键安装脚本 +- [**2066**星][9m] [jermic/android-crack-tool](https://github.com/jermic/android-crack-tool) +- [**2058**星][4m] [Py] [whaleshark-team/cobra](https://github.com/WhaleShark-Team/cobra) Source Code Security Audit (源代码安全审计) +- [**2057**星][1y] [bluscreenofjeff/red-team-infrastructure-wiki](https://github.com/bluscreenofjeff/red-team-infrastructure-wiki) Wiki to collect Red Team infrastructure hardening resources +- [**2054**星][7d] [swiftonsecurity/sysmon-config](https://github.com/swiftonsecurity/sysmon-config) Sysmon configuration file template with default high-quality event tracing +- [**2051**星][2m] [tanprathan/mobileapp-pentest-cheatsheet](https://github.com/tanprathan/mobileapp-pentest-cheatsheet) The Mobile App Pentest cheat sheet was created to provide concise collection of high value information on specific mobile application penetration testing topics. +- [**2048**星][6m] [Go] [maxmcd/webtty](https://github.com/maxmcd/webtty) Share a terminal session over WebRTC +- [**2047**星][1m] [edoverflow/bugbounty-cheatsheet](https://github.com/edoverflow/bugbounty-cheatsheet) A list of interesting payloads, tips and tricks for bug bounty hunters. +- [**2045**星][2m] [C++] [lordnoteworthy/al-khaser](https://github.com/lordnoteworthy/al-khaser) 在野恶意软件使用的技术:虚拟机,仿真,调试器,沙盒检测。 +- [**2045**星][8m] [Shell] [foospidy/payloads](https://github.com/foospidy/payloads) web 攻击 Payload 集合 +- [**2043**星][12d] [Py] [nabla-c0d3/sslyze](https://github.com/nabla-c0d3/sslyze) SSL/TLS服务器扫描 +- [**2042**星][2y] [Py] [derv82/wifite](https://github.com/derv82/wifite) 自动化无线攻击工具 +- [**2039**星][5d] [C++] [openthread/openthread](https://github.com/openthread/openthread) OpenThread released by Google is an open-source implementation of the Thread networking protocol +- [**2033**星][2d] [ObjC] [ios-control/ios-deploy](https://github.com/ios-control/ios-deploy) Install and debug iPhone apps from the command line, without using Xcode +- [**2033**星][2d] [Py] [sensepost/objection](https://github.com/sensepost/objection) runtimemobile exploration +- [**2029**星][3d] [Go] [goodrain/rainbond](https://github.com/goodrain/rainbond) Enterprise application cloud operating system(企业应用云操作系统) +- [**2025**星][5y] [CoffeeScript] [shadowsocks/shadowsocks-gui](https://github.com/shadowsocks/shadowsocks-gui) Shadowsocks GUI client +- [**2024**星][2d] [C++] [darthton/blackbone](https://github.com/darthton/blackbone) Windows memory hacking library +- [**2017**星][3y] [Swift] [urinx/iosapphook](https://github.com/urinx/iosapphook) 专注于非越狱环境下iOS应用逆向研究,从dylib注入,应用重签名到App Hook +- [**2016**星][23d] [Java] [genymobile/gnirehtet](https://github.com/genymobile/gnirehtet) Gnirehtet provides reverse tethering for Android +- [**2016**星][9m] [C] [dekunukem/nintendo_switch_reverse_engineering](https://github.com/dekunukem/nintendo_switch_reverse_engineering) A look at inner workings of Joycon and Nintendo Switch +- [**2014**星][1y] [C] [xoreaxeaxeax/rosenbridge](https://github.com/xoreaxeaxeax/rosenbridge) Hardware backdoors in some x86 CPUs +- [**2014**星][5d] [Java] [jeremylong/dependencycheck](https://github.com/jeremylong/dependencycheck) OWASP dependency-check is a software composition analysis utility that detects publicly disclosed vulnerabilities in application dependencies. +- [**2005**星][4y] [C] [probablycorey/wax](https://github.com/probablycorey/wax) Wax is now being maintained by alibaba +- [**2003**星][2m] [Go] [skynetservices/skydns](https://github.com/skynetservices/skydns) DNS service discovery for etcd +- [**2000**星][1m] [qazbnm456/awesome-cve-poc](https://github.com/qazbnm456/awesome-cve-poc) CVE PoC列表 +- [**1996**星][29d] [Java] [elderdrivers/edxposed](https://github.com/elderdrivers/edxposed) Elder driver Xposed Framework. +- [**1994**星][7m] [Py] [fsecurelabs/drozer](https://github.com/FSecureLABS/drozer) The Leading Security Assessment Framework for Android. +- [**1994**星][3m] [infosecn1nja/ad-attack-defense](https://github.com/infosecn1nja/ad-attack-defense) Attack and defend active directory using modern post exploitation adversary tradecraft activity +- [**1994**星][27d] [Swift] [github/softu2f](https://github.com/github/softu2f) Software U2F authenticator for macOS +- [**1992**星][5d] [C#] [mathewsachin/captura](https://github.com/mathewsachin/captura) Capture Screen, Audio, Cursor, Mouse Clicks and Keystrokes +- [**1990**星][8d] [HTML] [gtfobins/gtfobins.github.io](https://github.com/gtfobins/gtfobins.github.io) Curated list of Unix binaries that can be exploited to bypass system security restrictions +- [**1989**星][4y] [Go] [yahoo/gryffin](https://github.com/yahoo/gryffin) Gryffin is a large scale web security scanning platform. +- [**1989**星][2m] [C++] [asmjit/asmjit](https://github.com/asmjit/asmjit) Complete x86/x64 JIT and AOT Assembler for C++ +- [**1987**星][2y] [dloss/python-pentest-tools](https://github.com/dloss/python-pentest-tools) 可用于渗透测试的Python工具收集 +- [**1977**星][5d] [Go] [projectdiscovery/subfinder](https://github.com/projectdiscovery/subfinder) Subfinder is a subdomain discovery tool that discovers valid subdomains for websites. Designed as a passive framework to be useful for bug bounties and safe for penetration testing. +- [**1977**星][5d] [Go] [projectdiscovery/subfinder](https://github.com/projectdiscovery/subfinder) 使用Passive Sources, Search Engines, Pastebins, Internet Archives等查找子域名 +- [**1972**星][1m] [Py] [momosecurity/aswan](https://github.com/momosecurity/aswan) 陌陌风控系统静态规则引擎,零基础简易便捷的配置多种复杂规则,实时高效管控用户异常行为。 +- [**1971**星][5d] [Py] [j3ssie/osmedeus](https://github.com/j3ssie/osmedeus) Fully automated offensive security framework for reconnaissance and vulnerability scanning +- [**1966**星][11d] [Go] [ullaakut/cameradar](https://github.com/Ullaakut/cameradar) Cameradar hacks its way into RTSP videosurveillance cameras +- [**1966**星][9m] [JS] [weichiachang/stacks-cli](https://github.com/weichiachang/stacks-cli) Check website stack from the terminal +- [**1966**星][1y] [BitBake] [1n3/intruderpayloads](https://github.com/1n3/intruderpayloads) A collection of Burpsuite Intruder payloads, BurpBounty payloads, fuzz lists, malicious file uploads and web pentesting methodologies and checklists. +- [**1955**星][7d] [Perl] [spiderlabs/owasp-modsecurity-crs](https://github.com/spiderlabs/owasp-modsecurity-crs) OWASP ModSecurity Core Rule Set (CRS) Project (Official Repository) +- [**1953**星][2y] [obfuscator-llvm/obfuscator](https://github.com/obfuscator-llvm/obfuscator) Obfuscator-LLVM +- [**1952**星][1y] [Go] [hyperhq/hyperd](https://github.com/hyperhq/hyperd) HyperContainer Daemon +- [**1951**星][8d] [Py] [cea-sec/miasm](https://github.com/cea-sec/miasm) Reverse engineering framework in Python +- [**1947**星][29d] [Py] [nixawk/pentest-wiki](https://github.com/nixawk/pentest-wiki) PENTEST-WIKI is a free online security knowledge library for pentesters / researchers. If you have a good idea, please share it with others. +- [**1945**星][5d] [C] [microsoft/procdump-for-linux](https://github.com/microsoft/procdump-for-linux) Linux 版本的 ProcDump +- [**1942**星][3y] [C#] [lazocoder/windows-hacks](https://github.com/lazocoder/windows-hacks) Creative and unusual things that can be done with the Windows API. +- [**1938**星][4m] [C] [meituan-dianping/logan](https://github.com/meituan-dianping/logan) Logan is a lightweight case logging system based on mobile platform. +- [**1938**星][7d] [Go] [zalando/skipper](https://github.com/zalando/skipper) An HTTP router and reverse proxy for service composition, including use cases like Kubernetes Ingress +- [**1935**星][19d] [Go] [mpolden/echoip](https://github.com/mpolden/echoip) IP address lookup service +- [**1933**星][5m] [C] [darkk/redsocks](https://github.com/darkk/redsocks) transparent TCP-to-proxy redirector +- [**1923**星][3y] [Py] [aoncyberlabs/windows-exploit-suggester](https://github.com/AonCyberLabs/Windows-Exploit-Suggester) This tool compares a targets patch levels against the Microsoft vulnerability database in order to detect potential missing patches on the target. It also notifies the user if there are public exploits and Metasploit modules available for the missing bulletins. +- [**1920**星][4y] [Py] [ziggear/shadowsocks](https://github.com/ziggear/shadowsocks) backup of +- [**1920**星][2d] [C++] [powerdns/pdns](https://github.com/powerdns/pdns) PowerDNS +- [**1920**星][9d] [CSS] [cyb3rward0g/helk](https://github.com/cyb3rward0g/helk) 对ELK栈进行分析,具备多种高级功能,例如SQL声明性语言,图形,结构化流,机器学习等 +- [**1918**星][3m] [toolswatch/blackhat-arsenal-tools](https://github.com/toolswatch/blackhat-arsenal-tools) Black Hat 武器库 +- [**1917**星][2d] [C] [ntop/ndpi](https://github.com/ntop/ndpi) Open Source Deep Packet Inspection Software Toolkit +- [**1915**星][18d] [Py] [lanjelot/patator](https://github.com/lanjelot/patator) Patator is a multi-purpose brute-forcer, with a modular design and a flexible usage. +- [**1914**星][7d] [Go] [solo-io/gloo](https://github.com/solo-io/gloo) An Envoy-Powered API Gateway +- [**1914**星][2d] [chaitin/xray](https://github.com/chaitin/xray) xray 安全评估工具 | 使用之前务必先阅读文档 +- [**1903**星][3m] [Go] [minishift/minishift](https://github.com/minishift/minishift) Run OpenShift 3.x locally +- [**1901**星][9d] [C] [chipsec/chipsec](https://github.com/chipsec/chipsec) 分析PC平台的安全性, 包括硬件、系统固件(BIOS/UEFI)和平台组件 +- [**1900**星][1y] [Py] [derv82/wifite2](https://github.com/derv82/wifite2) 无线网络审计工具wifite 的升级版/重制版 +- [**1898**星][3d] [C++] [mhammond/pywin32](https://github.com/mhammond/pywin32) Python for Windows (pywin32) Extensions +- [**1896**星][7d] [Shell] [toniblyx/prowler](https://github.com/toniblyx/prowler) AWS Security Best Practices Assessment, Auditing, Hardening and Forensics Readiness Tool. It follows guidelines of the CIS Amazon Web Services Foundations Benchmark and DOZENS of additional checks including GDPR and HIPAA (+100). Official CIS for AWS guide: +- [**1893**星][6d] [Py] [mozilla/mozdef](https://github.com/mozilla/mozdef) Mozilla Enterprise Defense Platform +- [**1893**星][6m] [Java] [fuzion24/justtrustme](https://github.com/fuzion24/justtrustme) An xposed module that disables SSL certificate checking for the purposes of auditing an app with cert pinning +- [**1886**星][4m] [C] [shadowsocks/simple-obfs](https://github.com/shadowsocks/simple-obfs) A simple obfuscating tool (Deprecated) +- [**1884**星][1y] [Py] [aploium/zmirror](https://github.com/aploium/zmirror) The next-gen reverse proxy for full site mirroring +- [**1880**星][4m] [Py] [python-security/pyt](https://github.com/python-security/pyt) Python Web App 安全漏洞检测和静态分析工具 +- [**1878**星][16d] [YARA] [yara-rules/rules](https://github.com/yara-rules/rules) Repository of yara rules +- [**1878**星][5y] [C++] [tum-vision/lsd_slam](https://github.com/tum-vision/lsd_slam) LSD-SLAM +- [**1878**星][2m] [Py] [pycqa/bandit](https://github.com/pycqa/bandit) 在Python代码中查找常见的安全问题 +- [**1877**星][2d] [C] [merbanan/rtl_433](https://github.com/merbanan/rtl_433) Program to decode traffic from Devices that are broadcasting on 433.9 MHz like temperature sensors +- [**1876**星][9d] [olivierlaflamme/cheatsheet-god](https://github.com/olivierlaflamme/cheatsheet-god) Penetration Testing Reference Bank - OSCP / PTP & PTX Cheatsheet +- [**1876**星][27d] [hmaverickadams/beginner-network-pentesting](https://github.com/hmaverickadams/beginner-network-pentesting) Notes for Beginner Network Pentesting Course +- [**1873**星][12d] [Py] [aquasecurity/kube-hunter](https://github.com/aquasecurity/kube-hunter) Hunt for security weaknesses in Kubernetes clusters +- [**1870**星][5d] [C#] [hmbsbige/shadowsocksr-windows](https://github.com/hmbsbige/shadowsocksr-windows) 【自用】Bug-Oriented Programming +- [**1869**星][6d] [Java] [adoptopenjdk/jitwatch](https://github.com/adoptopenjdk/jitwatch) Log analyser / visualiser for Java HotSpot JIT compiler. Inspect inlining decisions, hot methods, bytecode, and assembly. View results in the JavaFX user interface. +- [**1865**星][6d] [C++] [acidanthera/lilu](https://github.com/acidanthera/Lilu) Arbitrary kext and process patching on macOS +- [**1865**星][10m] [PHP] [bartblaze/php-backdoors](https://github.com/bartblaze/php-backdoors) A collection of PHP backdoors. For educational or testing purposes only. +- [**1864**星][23d] [C] [tinyproxy/tinyproxy](https://github.com/tinyproxy/tinyproxy) a light-weight HTTP/HTTPS proxy daemon for POSIX operating systems +- [**1862**星][4y] [ObjC] [xcodeghostsource/xcodeghost](https://github.com/xcodeghostsource/xcodeghost) "XcodeGhost" Source +- [**1860**星][9d] [Lua] [vulnerscom/nmap-vulners](https://github.com/vulnerscom/nmap-vulners) NSE script based on Vulners.com API +- [**1857**星][5m] [bypass007/emergency-response-notes](https://github.com/bypass007/emergency-response-notes) 应急响应实战笔记,一个安全工程师的自我修养。 +- [**1855**星][2m] [Py] [pwnlandia/mhn](https://github.com/pwnlandia/mhn) 蜜罐网络 +- [**1854**星][5d] [TS] [snyk/snyk](https://github.com/snyk/snyk) CLI and build-time tool to find & fix known vulnerabilities in open-source dependencies +- [**1854**星][11m] [C++] [googlecreativelab/open-nsynth-super](https://github.com/googlecreativelab/open-nsynth-super) Open NSynth Super is an experimental physical interface for the NSynth algorithm +- [**1853**星][2d] [Py] [bregman-arie/devops-interview-questions](https://github.com/bregman-arie/devops-interview-questions) Linux, Jenkins, AWS, SRE, Prometheus, Docker, Python, Ansible, Git, Kubernetes, Terraform, OpenStack, SQL, NoSQL, Azure, GCP, DNS, Elastic +- [**1853**星][4m] [Shell] [arismelachroinos/lscript](https://github.com/arismelachroinos/lscript) 自动化无线渗透和Hacking 任务的脚本 +- [**1852**星][3d] [C] [github/glb-director](https://github.com/github/glb-director) GitHub Load Balancer Director and supporting tooling. +- [**1851**星][1y] [Java] [jindrapetrik/jpexs-decompiler](https://github.com/jindrapetrik/jpexs-decompiler) JPEXS Free Flash Decompiler +- [**1848**星][6m] [Assembly] [pooler/cpuminer](https://github.com/pooler/cpuminer) cpuminer:莱特币和比特币的多线程 CPU 矿机 +- [**1847**星][8m] [Py] [netflix-skunkworks/stethoscope](https://github.com/Netflix-Skunkworks/stethoscope) Personalized, user-focused recommendations for employee information security. +- [**1842**星][1m] [Jupyter Notebook] [hunters-forge/threathunter-playbook](https://github.com/hunters-forge/ThreatHunter-Playbook) A Threat hunter's playbook to aid the development of techniques and hypothesis for hunting campaigns. +- [**1842**星][1y] [Java] [yeriomin/yalpstore](https://github.com/yeriomin/yalpstore) Download apks from Google Play Store +- [**1842**星][2d] [C++] [pytorch/glow](https://github.com/pytorch/glow) Compiler for Neural Network hardware accelerators - [**1841**星][2m] [C] [retroplasma/earth-reverse-engineering](https://github.com/retroplasma/earth-reverse-engineering) Reversing Google's 3D satellite mode -- [**1839**星][4m] [bypass007/emergency-response-notes](https://github.com/bypass007/emergency-response-notes) 应急响应实战笔记,一个安全工程师的自我修养。 -- [**1837**星][4m] [Lua] [vulnerscom/nmap-vulners](https://github.com/vulnerscom/nmap-vulners) NSE script based on Vulners.com API -- [**1836**星][3y] [Java] [chora10/cknife](https://github.com/chora10/cknife) Cknife -- [**1835**星][1y] [Java] [yeriomin/yalpstore](https://github.com/yeriomin/yalpstore) Download apks from Google Play Store -- [**1833**星][25d] [hmaverickadams/beginner-network-pentesting](https://github.com/hmaverickadams/beginner-network-pentesting) Notes for Beginner Network Pentesting Course -- [**1832**星][4m] [Shell] [arismelachroinos/lscript](https://github.com/arismelachroinos/lscript) 自动化无线渗透和Hacking 任务的脚本 -- [**1830**星][7d] [C++] [pytorch/glow](https://github.com/pytorch/glow) Compiler for Neural Network hardware accelerators -- [**1829**星][1y] [Py] [jinnlynn/genpac](https://github.com/jinnlynn/genpac) PAC/Dnsmasq/Wingy file Generator, working with gfwlist, support custom rules. -- [**1827**星][1m] [Jupyter Notebook] [hunters-forge/threathunter-playbook](https://github.com/hunters-forge/ThreatHunter-Playbook) A Threat hunter's playbook to aid the development of techniques and hypothesis for hunting campaigns. -- [**1827**星][2m] [Go] [influxdata/kapacitor](https://github.com/influxdata/kapacitor) Open source framework for processing, monitoring, and alerting on time series data -- [**1827**星][1y] [CSS] [ctfs/write-ups-2015](https://github.com/ctfs/write-ups-2015) Wiki-like CTF write-ups repository, maintained by the community. 2015 -- [**1819**星][13d] [Py] [trailofbits/manticore](https://github.com/trailofbits/manticore) 动态二进制分析工具,支持符号执行(symbolic execution)、污点分析(taint analysis)、运行时修改。 -- [**1816**星][19d] [C] [mgba-emu/mgba](https://github.com/mgba-emu/mgba) mGBA Game Boy Advance Emulator -- [**1814**星][7d] [Py] [bregman-arie/devops-interview-questions](https://github.com/bregman-arie/devops-interview-questions) Linux, Jenkins, AWS, SRE, Prometheus, Docker, Python, Ansible, Git, Kubernetes, Terraform, OpenStack, SQL, NoSQL, Azure, GCP, DNS, Elastic -- [**1808**星][6m] [C++] [iagox86/dnscat2](https://github.com/iagox86/dnscat2) 在 DNS 协议上创建加密的 C&C channel -- [**1806**星][5m] [Py] [veil-framework/veil](https://github.com/veil-framework/veil) generate metasploit payloads that bypass common anti-virus solutions -- [**1801**星][3y] [Objective-C] [kpwn/yalu102](https://github.com/kpwn/yalu102) incomplete iOS 10.2 jailbreak for 64 bit devices by qwertyoruiopz and marcograssi -- [**1801**星][2m] [djadmin/awesome-bug-bounty](https://github.com/djadmin/awesome-bug-bounty) A comprehensive curated list of available Bug Bounty & Disclosure Programs and Write-ups. -- [**1788**星][28d] [Go] [gdamore/tcell](https://github.com/gdamore/tcell) Tcell is an alternate terminal package, similar in some ways to termbox, but better in others. -- [**1785**星][11m] [Py] [ctfs/write-ups-2017](https://github.com/ctfs/write-ups-2017) Wiki-like CTF write-ups repository, maintained by the community. 2017 -- [**1784**星][7d] [C#] [hmbsbige/shadowsocksr-windows](https://github.com/hmbsbige/shadowsocksr-windows) 【自用】Bug-Oriented Programming -- [**1783**星][7m] [Py] [lijiejie/subdomainsbrute](https://github.com/lijiejie/subdomainsbrute) 子域名爆破 -- [**1777**星][18d] [PHP] [ezyang/htmlpurifier](https://github.com/ezyang/htmlpurifier) Standards compliant HTML filter written in PHP -- [**1776**星][13d] [C++] [apitrace/apitrace](https://github.com/apitrace/apitrace) Tools for tracing OpenGL, Direct3D, and other graphics APIs -- [**1775**星][4y] [caesar0301/awesome-pcaptools](https://github.com/caesar0301/awesome-pcaptools) A collection of tools developed by other researchers in the Computer Science area to process network traces. All the right reserved for the original authors. -- [**1774**星][1y] [aozhimin/ios-monitor-platform](https://github.com/aozhimin/ios-monitor-platform) -- [**1770**星][3y] [Objective-C] [alibaba/wax](https://github.com/alibaba/wax) Wax is a framework that lets you write native iPhone apps in Lua. -- [**1768**星][13d] [Shell] [leebaird/discover](https://github.com/leebaird/discover) 自定义的bash脚本, 用于自动化多个渗透测试任务, 包括: 侦查、扫描、解析、在Metasploit中创建恶意Payload和Listener -- [**1764**星][3m] [Py] [epinna/weevely3](https://github.com/epinna/weevely3) Weaponized web shell -- [**1759**星][12d] [C] [google/wuffs](https://github.com/google/wuffs) Wrangling Untrusted File Formats Safely -- [**1757**星][7m] [C++] [wrbug/dumpdex](https://github.com/wrbug/dumpdex) Android脱壳 -- [**1757**星][2y] [CSS] [b374k/b374k](https://github.com/b374k/b374k) PHP Webshell with handy features -- [**1749**星][2m] [onethawt/idaplugins-list](https://github.com/onethawt/idaplugins-list) IDA插件收集 -- [**1747**星][8d] [17mon/china_ip_list](https://github.com/17mon/china_ip_list) -- [**1743**星][12m] [JS] [puppeteer/examples](https://github.com/puppeteer/examples) Use case-driven examples for using Puppeteer and headless chrome -- [**1740**星][8d] [PHP] [wordpress/wordpress-coding-standards](https://github.com/wordpress/wordpress-coding-standards) PHP_CodeSniffer rules (sniffs) to enforce WordPress coding conventions +- [**1839**星][3y] [Java] [chora10/cknife](https://github.com/chora10/cknife) Cknife +- [**1838**星][1y] [Py] [jinnlynn/genpac](https://github.com/jinnlynn/genpac) PAC/Dnsmasq/Wingy file Generator, working with gfwlist, support custom rules. +- [**1830**星][2m] [Go] [influxdata/kapacitor](https://github.com/influxdata/kapacitor) Open source framework for processing, monitoring, and alerting on time series data +- [**1828**星][3m] [JS] [coreybutler/node-windows](https://github.com/coreybutler/node-windows) Windows support for Node.JS scripts (daemons, eventlog, UAC, etc). +- [**1828**星][1y] [CSS] [ctfs/write-ups-2015](https://github.com/ctfs/write-ups-2015) Wiki-like CTF write-ups repository, maintained by the community. 2015 +- [**1824**星][5d] [Py] [trailofbits/manticore](https://github.com/trailofbits/manticore) 动态二进制分析工具,支持符号执行(symbolic execution)、污点分析(taint analysis)、运行时修改。 +- [**1819**星][6d] [C] [mgba-emu/mgba](https://github.com/mgba-emu/mgba) mGBA Game Boy Advance Emulator +- [**1818**星][2m] [djadmin/awesome-bug-bounty](https://github.com/djadmin/awesome-bug-bounty) A comprehensive curated list of available Bug Bounty & Disclosure Programs and Write-ups. +- [**1815**星][5m] [Py] [veil-framework/veil](https://github.com/veil-framework/veil) generate metasploit payloads that bypass common anti-virus solutions +- [**1814**星][6m] [C++] [iagox86/dnscat2](https://github.com/iagox86/dnscat2) 在 DNS 协议上创建加密的 C&C channel +- [**1804**星][10d] [Go] [gdamore/tcell](https://github.com/gdamore/tcell) Tcell is an alternate terminal package, similar in some ways to termbox, but better in others. +- [**1801**星][12m] [Go] [intelsdi-x/snap](https://github.com/intelsdi-x/snap) an open telemetry framework designed to simplify the collection, processing and publishing of system data through a single API. +- [**1800**星][3y] [ObjC] [kpwn/yalu102](https://github.com/kpwn/yalu102) incomplete iOS 10.2 jailbreak for 64 bit devices by qwertyoruiopz and marcograssi +- [**1795**星][7m] [Py] [lijiejie/subdomainsbrute](https://github.com/lijiejie/subdomainsbrute) 子域名爆破 +- [**1790**星][12m] [Py] [ctfs/write-ups-2017](https://github.com/ctfs/write-ups-2017) Wiki-like CTF write-ups repository, maintained by the community. 2017 +- [**1785**星][1y] [aozhimin/ios-monitor-platform](https://github.com/aozhimin/ios-monitor-platform) +- [**1784**星][16d] [Shell] [pirate/wireguard-docs](https://github.com/pirate/wireguard-docs) +- [**1781**星][15d] [Shell] [leebaird/discover](https://github.com/leebaird/discover) 自定义的bash脚本, 用于自动化多个渗透测试任务, 包括: 侦查、扫描、解析、在Metasploit中创建恶意Payload和Listener +- [**1779**星][4y] [caesar0301/awesome-pcaptools](https://github.com/caesar0301/awesome-pcaptools) A collection of tools developed by other researchers in the Computer Science area to process network traces. All the right reserved for the original authors. +- [**1778**星][15d] [C++] [apitrace/apitrace](https://github.com/apitrace/apitrace) Tools for tracing OpenGL, Direct3D, and other graphics APIs +- [**1777**星][7m] [C++] [wrbug/dumpdex](https://github.com/wrbug/dumpdex) Android脱壳 +- [**1777**星][7d] [PHP] [ezyang/htmlpurifier](https://github.com/ezyang/htmlpurifier) Standards compliant HTML filter written in PHP +- [**1777**星][5d] [Go] [convox/rack](https://github.com/convox/rack) Private PaaS built on native AWS services for maximum privacy and minimum upkeep +- [**1774**星][3y] [ObjC] [tapwork/heapinspector-for-ios](https://github.com/tapwork/heapinspector-for-ios) Find memory issues & leaks in your iOS app without instruments +- [**1774**星][3m] [Py] [epinna/weevely3](https://github.com/epinna/weevely3) Weaponized web shell +- [**1772**星][2y] [JS] [cazala/coin-hive](https://github.com/cazala/coin-hive) CoinHive cryptocurrency miner for node.js +- [**1770**星][3y] [ObjC] [alibaba/wax](https://github.com/alibaba/wax) Wax is a framework that lets you write native iPhone apps in Lua. +- [**1761**星][6d] [C] [google/wuffs](https://github.com/google/wuffs) Wrangling Untrusted File Formats Safely +- [**1761**星][2y] [CSS] [b374k/b374k](https://github.com/b374k/b374k) PHP Webshell with handy features +- [**1760**星][3y] [Go] [elastic/logstash-forwarder](https://github.com/elastic/logstash-forwarder) An experiment to cut logs in preparation for processing elsewhere. Replaced by Filebeat: +- [**1758**星][12m] [JS] [puppeteer/examples](https://github.com/puppeteer/examples) Use case-driven examples for using Puppeteer and headless chrome +- [**1756**星][10d] [17mon/china_ip_list](https://github.com/17mon/china_ip_list) +- [**1754**星][2m] [onethawt/idaplugins-list](https://github.com/onethawt/idaplugins-list) IDA插件收集 +- [**1747**星][2d] [PHP] [wordpress/wordpress-coding-standards](https://github.com/wordpress/wordpress-coding-standards) PHP_CodeSniffer rules (sniffs) to enforce WordPress coding conventions +- [**1745**星][1y] [PS] [fuzzysecurity/powershell-suite](https://github.com/fuzzysecurity/powershell-suite) My musings with PowerShell +- [**1744**星][1y] [coreb1t/awesome-pentest-cheat-sheets](https://github.com/coreb1t/awesome-pentest-cheat-sheets) Collection of the cheat sheets useful for pentesting +- [**1742**星][3m] [tunz/js-vuln-db](https://github.com/tunz/js-vuln-db) A collection of JavaScript engine CVEs with PoCs +- [**1739**星][21d] [ngalongc/bug-bounty-reference](https://github.com/ngalongc/bug-bounty-reference) Inspired by - [**1738**星][2y] [Go] [vzex/dog-tunnel](https://github.com/vzex/dog-tunnel) p2p tunnel,(udp mode work with kcp, -- [**1734**星][3m] [tunz/js-vuln-db](https://github.com/tunz/js-vuln-db) A collection of JavaScript engine CVEs with PoCs -- [**1732**星][1y] [coreb1t/awesome-pentest-cheat-sheets](https://github.com/coreb1t/awesome-pentest-cheat-sheets) Collection of the cheat sheets useful for pentesting -- [**1727**星][2m] [PHP] [orangetw/my-ctf-web-challenges](https://github.com/orangetw/my-ctf-web-challenges) Collection of CTF Web challenges I made -- [**1726**星][3y] [Go] [s-rah/onionscan](https://github.com/s-rah/onionscan) OnionScan is a free and open source tool for investigating the Dark Web. -- [**1723**星][6m] [Smali] [ahmyth/ahmyth-android-rat](https://github.com/ahmyth/ahmyth-android-rat) Android Remote Administration Tool -- [**1722**星][1y] [PowerShell] [fuzzysecurity/powershell-suite](https://github.com/fuzzysecurity/powershell-suite) My musings with PowerShell -- [**1720**星][19d] [ngalongc/bug-bounty-reference](https://github.com/ngalongc/bug-bounty-reference) Inspired by -- [**1718**星][1m] [PowerShell] [fireeye/flare-vm](https://github.com/fireeye/flare-vm) 火眼发布用于 Windows 恶意代码分析的虚拟机:FLARE VM -- [**1717**星][7d] [C] [google/honggfuzz](https://github.com/google/honggfuzz) Security oriented fuzzer with powerful analysis options. Supports evolutionary, feedback-driven fuzzing based on code coverage (software- and hardware-based) -- [**1714**星][2m] [Go] [subfinder/subfinder](https://github.com/subfinder/subfinder) 使用Passive Sources, Search Engines, Pastebins, Internet Archives等查找子域名 -- [**1709**星][9m] [Py] [constverum/proxybroker](https://github.com/constverum/proxybroker) Proxy [Finder | Checker | Server]. HTTP(S) & SOCKS -- [**1708**星][10d] [Ruby] [cliffe/secgen](https://github.com/cliffe/secgen) Create randomly insecure VMs -- [**1705**星][4m] [Py] [lgandx/responder](https://github.com/lgandx/responder) Responder is a LLMNR, NBT-NS and MDNS poisoner, with built-in HTTP/SMB/MSSQL/FTP/LDAP rogue authentication server supporting NTLMv1/NTLMv2/LMv2, Extended Security NTLMSSP and Basic HTTP authentication. -- [**1702**星][1y] [Java] [ac-pm/inspeckage](https://github.com/ac-pm/inspeckage) Android Package Inspector - dynamic analysis with api hooks, start unexported activities and more. (Xposed Module) -- [**1695**星][1m] [Go] [eth0izzle/shhgit](https://github.com/eth0izzle/shhgit) 监听Github Event API,实时查找Github代码和Gist中的secret和敏感文件 -- [**1694**星][3m] [PHP] [xtr4nge/fruitywifi](https://github.com/xtr4nge/fruitywifi) FruityWiFi is a wireless network auditing tool. The application can be installed in any Debian based system (Jessie) adding the extra packages. Tested in Debian, Kali Linux, Kali Linux ARM (Raspberry Pi), Raspbian (Raspberry Pi), Pwnpi (Raspberry Pi), Bugtraq, NetHunter. -- [**1694**星][3y] [CoffeeScript] [okturtles/dnschain](https://github.com/okturtles/dnschain) A blockchain-based DNS + HTTP server that fixes HTTPS security, and more! -- [**1694**星][1y] [Swift] [haxpor/potatso](https://github.com/haxpor/potatso) Potatso is an iOS client that implements Shadowsocks proxy with the leverage of NetworkExtension framework. ***This project is unmaintained, try taking a look at this fork -- [**1694**星][14d] [Go] [hashicorp/memberlist](https://github.com/hashicorp/memberlist) Golang package for gossip based membership and failure detection -- [**1693**星][8m] [Py] [guelfoweb/knock](https://github.com/guelfoweb/knock) 使用 Wordlist 枚举子域名 -- [**1693**星][7d] [TSQL] [brentozarultd/sql-server-first-responder-kit](https://github.com/brentozarultd/sql-server-first-responder-kit) sp_Blitz, sp_BlitzCache, sp_BlitzFirst, sp_BlitzIndex, and other SQL Server scripts for health checks and performance tuning. -- [**1693**星][3m] [Py] [anorov/cloudflare-scrape](https://github.com/anorov/cloudflare-scrape) A Python module to bypass Cloudflare's anti-bot page. -- [**1691**星][6m] [Py] [yelp/osxcollector](https://github.com/yelp/osxcollector) A forensic evidence collection & analysis toolkit for OS X -- [**1687**星][4m] [JS] [expressjs/csurf](https://github.com/expressjs/csurf) CSRF token middleware -- [**1685**星][5m] [C] [networkprotocol/netcode.io](https://github.com/networkprotocol/netcode.io) A protocol for secure client/server connections over UDP -- [**1682**星][8m] [Makefile] [raspberrypi/noobs](https://github.com/raspberrypi/noobs) NOOBS (New Out Of Box Software) - An easy Operating System install manager for the Raspberry Pi -- [**1682**星][1y] [owasp/devguide](https://github.com/owasp/devguide) The OWASP Guide -- [**1681**星][13d] [HTML] [chromium/badssl.com](https://github.com/chromium/badssl.com) -- [**1681**星][9m] [CSS] [bagder/http2-explained](https://github.com/bagder/http2-explained) A detailed document explaining and documenting HTTP/2, the successor to the widely popular HTTP/1.1 protocol -- [**1676**星][28d] [Swift] [pmusolino/wormholy](https://github.com/pmusolino/wormholy) iOS network debugging, like a wizard 🧙‍♂️ -- [**1675**星][4m] [R] [briatte/awesome-network-analysis](https://github.com/briatte/awesome-network-analysis) A curated list of awesome network analysis resources. -- [**1674**星][2m] [Py] [rootm0s/winpwnage](https://github.com/rootm0s/winpwnage) UAC bypass, Elevate, Persistence and Execution methods -- [**1668**星][7m] [C++] [yegord/snowman](https://github.com/yegord/snowman) Snowman反编译器,支持x86, AMD64, ARM。有独立的GUI工具、命令行工具、IDA/Radare2/x64dbg插件,也可以作为库使用 +- [**1735**星][2m] [PHP] [orangetw/my-ctf-web-challenges](https://github.com/orangetw/my-ctf-web-challenges) Collection of CTF Web challenges I made +- [**1731**星][1m] [PS] [fireeye/flare-vm](https://github.com/fireeye/flare-vm) 火眼发布用于 Windows 恶意代码分析的虚拟机:FLARE VM +- [**1730**星][3y] [Go] [s-rah/onionscan](https://github.com/s-rah/onionscan) OnionScan is a free and open source tool for investigating the Dark Web. +- [**1730**星][6m] [Smali] [ahmyth/ahmyth-android-rat](https://github.com/ahmyth/ahmyth-android-rat) Android Remote Administration Tool +- [**1723**星][14d] [selierlin/share-ssr-v2ray](https://github.com/selierlin/share-ssr-v2ray) +- [**1719**星][4d] [C] [google/honggfuzz](https://github.com/google/honggfuzz) Security oriented fuzzer with powerful analysis options. Supports evolutionary, feedback-driven fuzzing based on code coverage (software- and hardware-based) +- [**1718**星][9m] [Py] [constverum/proxybroker](https://github.com/constverum/proxybroker) Proxy [Finder | Checker | Server]. HTTP(S) & SOCKS +- [**1717**星][4m] [Py] [lgandx/responder](https://github.com/lgandx/responder) Responder is a LLMNR, NBT-NS and MDNS poisoner, with built-in HTTP/SMB/MSSQL/FTP/LDAP rogue authentication server supporting NTLMv1/NTLMv2/LMv2, Extended Security NTLMSSP and Basic HTTP authentication. +- [**1714**星][5d] [Ruby] [cliffe/secgen](https://github.com/cliffe/secgen) Create randomly insecure VMs +- [**1710**星][1m] [Go] [eth0izzle/shhgit](https://github.com/eth0izzle/shhgit) 监听Github Event API,实时查找Github代码和Gist中的secret和敏感文件 +- [**1709**星][3m] [Py] [anorov/cloudflare-scrape](https://github.com/anorov/cloudflare-scrape) A Python module to bypass Cloudflare's anti-bot page. +- [**1709**星][1y] [Java] [ac-pm/inspeckage](https://github.com/ac-pm/inspeckage) Android Package Inspector - dynamic analysis with api hooks, start unexported activities and more. (Xposed Module) +- [**1707**星][3d] [TSQL] [brentozarultd/sql-server-first-responder-kit](https://github.com/brentozarultd/sql-server-first-responder-kit) sp_Blitz, sp_BlitzCache, sp_BlitzFirst, sp_BlitzIndex, and other SQL Server scripts for health checks and performance tuning. +- [**1706**星][16d] [Go] [hashicorp/memberlist](https://github.com/hashicorp/memberlist) Golang package for gossip based membership and failure detection +- [**1700**星][8m] [Py] [guelfoweb/knock](https://github.com/guelfoweb/knock) 使用 Wordlist 枚举子域名 +- [**1697**星][9m] [CSS] [bagder/http2-explained](https://github.com/bagder/http2-explained) A detailed document explaining and documenting HTTP/2, the successor to the widely popular HTTP/1.1 protocol +- [**1696**星][3m] [PHP] [xtr4nge/fruitywifi](https://github.com/xtr4nge/fruitywifi) FruityWiFi is a wireless network auditing tool. The application can be installed in any Debian based system (Jessie) adding the extra packages. Tested in Debian, Kali Linux, Kali Linux ARM (Raspberry Pi), Raspbian (Raspberry Pi), Pwnpi (Raspberry Pi), Bugtraq, NetHunter. +- [**1696**星][1y] [Swift] [haxpor/potatso](https://github.com/haxpor/potatso) Potatso is an iOS client that implements Shadowsocks proxy with the leverage of NetworkExtension framework. ***This project is unmaintained, try taking a look at this fork +- [**1695**星][6m] [Py] [yelp/osxcollector](https://github.com/yelp/osxcollector) A forensic evidence collection & analysis toolkit for OS X +- [**1695**星][3y] [CoffeeScript] [okturtles/dnschain](https://github.com/okturtles/dnschain) A blockchain-based DNS + HTTP server that fixes HTTPS security, and more! +- [**1689**星][5m] [C] [networkprotocol/netcode.io](https://github.com/networkprotocol/netcode.io) A protocol for secure client/server connections over UDP +- [**1687**星][5m] [JS] [expressjs/csurf](https://github.com/expressjs/csurf) CSRF token middleware +- [**1687**星][15d] [HTML] [chromium/badssl.com](https://github.com/chromium/badssl.com) +- [**1686**星][8m] [Makefile] [raspberrypi/noobs](https://github.com/raspberrypi/noobs) NOOBS (New Out Of Box Software) - An easy Operating System install manager for the Raspberry Pi +- [**1685**星][4m] [R] [briatte/awesome-network-analysis](https://github.com/briatte/awesome-network-analysis) A curated list of awesome network analysis resources. +- [**1683**星][1y] [owasp/devguide](https://github.com/owasp/devguide) The OWASP Guide +- [**1682**星][3m] [Py] [rootm0s/winpwnage](https://github.com/rootm0s/winpwnage) UAC bypass, Elevate, Persistence and Execution methods +- [**1677**星][30d] [Swift] [pmusolino/wormholy](https://github.com/pmusolino/wormholy) iOS network debugging, like a wizard 🧙‍♂️ +- [**1674**星][2d] [C++] [microsoft/detours](https://github.com/microsoft/detours) Detours is a software package for monitoring and instrumenting API calls on Windows. It is distributed in source code form. +- [**1671**星][7m] [C++] [yegord/snowman](https://github.com/yegord/snowman) Snowman反编译器,支持x86, AMD64, ARM。有独立的GUI工具、命令行工具、IDA/Radare2/x64dbg插件,也可以作为库使用 - [IDA插件](https://github.com/yegord/snowman/tree/master/src/ida-plugin) - [snowman](https://github.com/yegord/snowman/tree/master/src/snowman) QT界面 - [nocode](https://github.com/yegord/snowman/tree/master/src/nocode) 命令行工具 - [nc](https://github.com/yegord/snowman/tree/master/src/nc) 核心代码,可作为库使用 -- [**1665**星][6m] [C++] [microsoft/detours](https://github.com/microsoft/detours) Detours is a software package for monitoring and instrumenting API calls on Windows. It is distributed in source code form. -- [**1662**星][12d] [selierlin/share-ssr-v2ray](https://github.com/selierlin/share-ssr-v2ray) -- [**1662**星][4y] [Java] [dodola/hotfix](https://github.com/dodola/hotfix) 安卓App热补丁动态修复框架 -- [**1659**星][7d] [Java] [apache/geode](https://github.com/apache/geode) Apache Geode -- [**1655**星][6m] [C] [easyhook/easyhook](https://github.com/easyhook/easyhook) The reinvention of Windows API Hooking -- [**1654**星][3m] [JS] [tylerbrock/mongo-hacker](https://github.com/tylerbrock/mongo-hacker) MongoDB Shell Enhancements for Hackers -- [**1653**星][2m] [NSIS] [angryip/ipscan](https://github.com/angryip/ipscan) Angry IP Scanner - fast and friendly network scanner -- [**1651**星][7d] [Py] [cea-sec/ivre](https://github.com/cea-sec/ivre) Network recon framework. -- [**1650**星][2y] [Shell] [juude/droidreverse](https://github.com/juude/droidreverse) android 逆向工程工具集 -- [**1649**星][10m] [JS] [evilcos/xssor2](https://github.com/evilcos/xssor2) XSS'OR - Hack with JavaScript. -- [**1647**星][3m] [Py] [boppreh/keyboard](https://github.com/boppreh/keyboard) Hook and simulate global keyboard events on Windows and Linux. -- [**1646**星][8d] [roave/securityadvisories](https://github.com/roave/securityadvisories) ensures that your application doesn't have installed dependencies with known security vulnerabilities -- [**1646**星][8d] [JS] [ghacksuserjs/ghacks-user.js](https://github.com/ghacksuserjs/ghacks-user.js) An ongoing comprehensive user.js template for configuring and hardening Firefox privacy, security and anti-fingerprinting +- [**1668**星][2m] [NSIS] [angryip/ipscan](https://github.com/angryip/ipscan) Angry IP Scanner - fast and friendly network scanner +- [**1666**星][2d] [Java] [apache/geode](https://github.com/apache/geode) Apache Geode +- [**1663**星][4y] [Java] [dodola/hotfix](https://github.com/dodola/hotfix) 安卓App热补丁动态修复框架 +- [**1661**星][6m] [C] [easyhook/easyhook](https://github.com/easyhook/easyhook) The reinvention of Windows API Hooking +- [**1661**星][2d] [Py] [cea-sec/ivre](https://github.com/cea-sec/ivre) Network recon framework. +- [**1659**星][10d] [roave/securityadvisories](https://github.com/roave/securityadvisories) ensures that your application doesn't have installed dependencies with known security vulnerabilities +- [**1656**星][6d] [JS] [tylerbrock/mongo-hacker](https://github.com/tylerbrock/mongo-hacker) MongoDB Shell Enhancements for Hackers +- [**1655**星][3m] [Py] [boppreh/keyboard](https://github.com/boppreh/keyboard) Hook and simulate global keyboard events on Windows and Linux. +- [**1654**星][2d] [JS] [ghacksuserjs/ghacks-user.js](https://github.com/ghacksuserjs/ghacks-user.js) An ongoing comprehensive user.js template for configuring and hardening Firefox privacy, security and anti-fingerprinting +- [**1652**星][2y] [Shell] [juude/droidreverse](https://github.com/juude/droidreverse) android 逆向工程工具集 +- [**1652**星][7m] [dsasmblr/game-hacking](https://github.com/dsasmblr/game-hacking) Tutorials, tools, and more as related to reverse engineering video games. +- [**1651**星][10m] [JS] [evilcos/xssor2](https://github.com/evilcos/xssor2) XSS'OR - Hack with JavaScript. +- [**1650**星][1m] [Py] [ehco1996/django-sspanel](https://github.com/ehco1996/django-sspanel) 用diango开发的全新的shadowsocks网络面板 +- [**1650**星][7d] [HTML] [clong/detectionlab](https://github.com/clong/detectionlab) Vagrant & Packer scripts to build a lab environment complete with security tooling and logging best practices +- [**1649**星][1y] [Py] [evyatarmeged/raccoon](https://github.com/evyatarmeged/raccoon) 高性能的侦查和漏洞扫描工具 +- [**1648**星][2d] [C#] [jbevain/cecil](https://github.com/jbevain/cecil) C#库, 探查/修改/生成 .NET App/库 - [**1645**星][3y] [JS] [camwiegert/baffle](https://github.com/camwiegert/baffle) A tiny javascript library for obfuscating and revealing text in DOM elements. -- [**1643**星][1m] [C#] [jbevain/cecil](https://github.com/jbevain/cecil) C#库, 探查/修改/生成 .NET App/库 -- [**1641**星][1y] [Py] [evyatarmeged/raccoon](https://github.com/evyatarmeged/raccoon) 高性能的侦查和漏洞扫描工具 -- [**1641**星][6m] [dsasmblr/game-hacking](https://github.com/dsasmblr/game-hacking) Tutorials, tools, and more as related to reverse engineering video games. -- [**1639**星][1m] [Py] [ehco1996/django-sspanel](https://github.com/ehco1996/django-sspanel) 用diango开发的全新的shadowsocks网络面板 -- [**1637**星][13d] [HTML] [clong/detectionlab](https://github.com/clong/detectionlab) Vagrant & Packer scripts to build a lab environment complete with security tooling and logging best practices -- [**1636**星][11m] [Java] [fesh0r/fernflower](https://github.com/fesh0r/fernflower) Unofficial mirror of FernFlower Java decompiler (All pulls should be submitted upstream) -- [**1635**星][4y] [Py] [ctfs/write-ups-2014](https://github.com/ctfs/write-ups-2014) Wiki-like CTF write-ups repository, maintained by the community. 2014 -- [**1635**星][4m] [Java] [jaredrummler/androidprocesses](https://github.com/jaredrummler/androidprocesses) DEPRECATED -- [**1635**星][4y] [Py] [ctfs/write-ups-2014](https://github.com/ctfs/write-ups-2014) Wiki-like CTF write-ups repository, maintained by the community. 2014 -- [**1629**星][9m] [tylerha97/awesome-reversing](https://github.com/tylerha97/awesome-reversing) A curated list of awesome reversing resources -- [**1627**星][12d] [Go] [awnumar/memguard](https://github.com/awnumar/memguard) 处理内存中敏感的值,纯Go语言编写。 -- [**1627**星][9d] [sarojaba/awesome-devblog](https://github.com/sarojaba/awesome-devblog) 어썸데브블로그. 국내 개발 블로그 모음(only 실명으로). -- [**1620**星][14d] [JS] [efforg/privacybadger](https://github.com/efforg/privacybadger) Privacy Badger is a browser extension that automatically learns to block invisible trackers. -- [**1616**星][2y] [jhaddix/tbhm](https://github.com/jhaddix/tbhm) The Bug Hunters Methodology -- [**1614**星][2m] [Shell] [internetwache/gittools](https://github.com/internetwache/gittools) find websites with their .git repository available to the public -- [**1612**星][4m] [CSS] [functionclub/v2ray.fun](https://github.com/functionclub/v2ray.fun) 正在开发的全新 V2ray.Fun -- [**1611**星][2m] [Go] [ysrc/yulong-hids](https://github.com/ysrc/yulong-hids) 一款由 YSRC 开源的主机入侵检测系统 -- [**1610**星][7m] [Go] [sipt/shuttle](https://github.com/sipt/shuttle) A web proxy in Golang with amazing features. -- [**1608**星][2y] [JS] [addyosmani/a11y](https://github.com/addyosmani/a11y) Accessibility audit tooling for the web (beta) -- [**1607**星][3y] [Makefile] [drizzlerisk/drizzledumper](https://github.com/drizzlerisk/drizzledumper) 是一款基于内存搜索的Android脱壳工具。 -- [**1605**星][27d] [PHP] [c0ny1/upload-labs](https://github.com/c0ny1/upload-labs) 一个帮你总结所有类型的上传漏洞的靶场 -- [**1604**星][10m] [C] [nmikhailov/validity90](https://github.com/nmikhailov/validity90) Reverse engineering of Validity/Synaptics 138a:0090, 138a:0094, 138a:0097, 06cb:0081, 06cb:009a fingerprint readers protocol -- [**1602**星][1y] [Py] [nccgroup/scout2](https://github.com/nccgroup/Scout2) Security auditing tool for AWS environments +- [**1643**星][9m] [tylerha97/awesome-reversing](https://github.com/tylerha97/awesome-reversing) A curated list of awesome reversing resources +- [**1643**星][11m] [Java] [fesh0r/fernflower](https://github.com/fesh0r/fernflower) Unofficial mirror of FernFlower Java decompiler (All pulls should be submitted upstream) +- [**1638**星][4y] [Py] [ctfs/write-ups-2014](https://github.com/ctfs/write-ups-2014) Wiki-like CTF write-ups repository, maintained by the community. 2014 +- [**1638**星][11m] [C] [dlundquist/sniproxy](https://github.com/dlundquist/sniproxy) Proxies incoming HTTP and TLS connections based on the hostname contained in the initial request of the TCP session. +- [**1638**星][4y] [Py] [ctfs/write-ups-2014](https://github.com/ctfs/write-ups-2014) Wiki-like CTF write-ups repository, maintained by the community. 2014 +- [**1636**星][4m] [Java] [jaredrummler/androidprocesses](https://github.com/jaredrummler/androidprocesses) DEPRECATED +- [**1634**星][14d] [Go] [awnumar/memguard](https://github.com/awnumar/memguard) 处理内存中敏感的值,纯Go语言编写。 +- [**1631**星][6m] [Objective-C++] [tencent/oomdetector](https://github.com/tencent/oomdetector) OOMDetector is a memory monitoring component for iOS which provides you with OOM monitoring, memory allocation monitoring, memory leak detection and other functions. +- [**1630**星][6d] [JS] [efforg/privacybadger](https://github.com/efforg/privacybadger) Privacy Badger is a browser extension that automatically learns to block invisible trackers. +- [**1630**星][29d] [PHP] [c0ny1/upload-labs](https://github.com/c0ny1/upload-labs) 一个帮你总结所有类型的上传漏洞的靶场 +- [**1629**星][5d] [sarojaba/awesome-devblog](https://github.com/sarojaba/awesome-devblog) 어썸데브블로그. 국내 개발 블로그 모음(only 실명으로). +- [**1624**星][2y] [jhaddix/tbhm](https://github.com/jhaddix/tbhm) The Bug Hunters Methodology +- [**1624**星][4m] [CSS] [functionclub/v2ray.fun](https://github.com/functionclub/v2ray.fun) 正在开发的全新 V2ray.Fun +- [**1621**星][2m] [Shell] [internetwache/gittools](https://github.com/internetwache/gittools) find websites with their .git repository available to the public +- [**1618**星][28d] [Java] [tiann/epic](https://github.com/tiann/epic) Dynamic java method AOP hook for Android(continution of Dexposed on ART), Supporting 4.0~10.0 +- [**1615**星][2y] [JS] [addyosmani/a11y](https://github.com/addyosmani/a11y) Accessibility audit tooling for the web (beta) +- [**1614**星][2m] [Go] [ysrc/yulong-hids](https://github.com/ysrc/yulong-hids) 一款由 YSRC 开源的主机入侵检测系统 +- [**1614**星][7m] [Go] [sipt/shuttle](https://github.com/sipt/shuttle) A web proxy in Golang with amazing features. +- [**1612**星][3y] [Makefile] [drizzlerisk/drizzledumper](https://github.com/drizzlerisk/drizzledumper) 是一款基于内存搜索的Android脱壳工具。 +- [**1608**星][9m] [JS] [localtunnel/server](https://github.com/localtunnel/server) server for localtunnel.me +- [**1608**星][10m] [C] [nmikhailov/validity90](https://github.com/nmikhailov/validity90) Reverse engineering of Validity/Synaptics 138a:0090, 138a:0094, 138a:0097, 06cb:0081, 06cb:009a fingerprint readers protocol +- [**1606**星][2d] [C++] [lief-project/lief](https://github.com/lief-project/lief) Library to Instrument Executable Formats - [**1602**星][6m] [Py] [w1109790800/penetration](https://github.com/w1109790800/penetration) 渗透 超全面的渗透资料 -- [**1600**星][8d] [C++] [lief-project/lief](https://github.com/lief-project/lief) Library to Instrument Executable Formats -- [**1599**星][9m] [JS] [localtunnel/server](https://github.com/localtunnel/server) server for localtunnel.me -- [**1596**星][5m] [Py] [mozilla/cipherscan](https://github.com/mozilla/cipherscan) 查找指定目标支持的SSL ciphersuites -- [**1596**星][3m] [Py] [knownsec/pocsuite](https://github.com/knownsec/pocsuite) This project has stopped to maintenance, please to -- [**1593**星][26d] [Java] [tiann/epic](https://github.com/tiann/epic) Dynamic java method AOP hook for Android(continution of Dexposed on ART), Supporting 4.0~10.0 -- [**1588**星][13d] [Java] [spotbugs/spotbugs](https://github.com/spotbugs/spotbugs) SpotBugs is FindBugs' successor. A tool for static analysis to look for bugs in Java code. -- [**1583**星][6m] [Ruby] [brunofacca/zen-rails-security-checklist](https://github.com/brunofacca/zen-rails-security-checklist) Checklist of security precautions for Ruby on Rails applications. -- [**1580**星][1y] [C] [qihoo360/phptrace](https://github.com/qihoo360/phptrace) A tracing and troubleshooting tool for PHP scripts. -- [**1580**星][7d] [Go] [bitnami-labs/sealed-secrets](https://github.com/bitnami-labs/sealed-secrets) A Kubernetes controller and tool for one-way encrypted Secrets -- [**1577**星][4y] [l3m0n/pentest_study](https://github.com/l3m0n/pentest_study) 从零开始内网渗透学习 -- [**1577**星][1m] [Objective-C] [ealeksandrov/provisionql](https://github.com/ealeksandrov/provisionql) Quick Look plugin for apps and provisioning profile files -- [**1575**星][26d] [C] [ntop/n2n](https://github.com/ntop/n2n) Peer-to-peer VPN -- [**1574**星][22d] [ivrodriguezca/re-ios-apps](https://github.com/ivrodriguezca/re-ios-apps) A completely free, open source and online course about Reverse Engineering iOS Applications. -- [**1563**星][2y] [C] [samyk/pwnat](https://github.com/samyk/pwnat) The only tool and technique to punch holes through firewalls/NATs where both clients and server can be behind separate NATs without any 3rd party involvement. Pwnat uses a newly developed technique, exploiting a property of NAT translation tables, with no 3rd party, port forwarding, DMZ, router administrative requirements, STUN/TURN/UPnP/ICE, or… -- [**1563**星][12d] [C] [codahale/bcrypt-ruby](https://github.com/codahale/bcrypt-ruby) Ruby binding for the OpenBSD bcrypt() password hashing algorithm, allowing you to easily store a secure hash of your users' passwords. -- [**1562**星][17d] [C] [p-gen/smenu](https://github.com/p-gen/smenu) Terminal utility that reads words from standard input or from a file and creates an interactive selection window just below the cursor. The selected word(s) are sent to standard output for further processing. -- [**1560**星][14d] [Java] [gchq/gaffer](https://github.com/gchq/Gaffer) A large-scale entity and relation database supporting aggregation of properties -- [**1557**星][2m] [C] [firmianay/ctf-all-in-one](https://github.com/firmianay/ctf-all-in-one) CTF竞赛入门指南 -- [**1556**星][12d] [Go] [caffix/amass](https://github.com/caffix/amass) 子域名枚举, 搜索互联网数据源, 使用机器学习猜测子域名. Go语言 -- [**1555**星][1y] [Py] [unkl4b/gitminer](https://github.com/unkl4b/gitminer) Github内容挖掘 -- [**1552**星][12d] [Py] [k4m4/kickthemout](https://github.com/k4m4/kickthemout) 使用ARP欺骗,将设备从网络中踢出去 -- [**1550**星][8m] [Py] [m4ll0k/wascan](https://github.com/m4ll0k/WAScan) WAScan - Web Application Scanner -- [**1547**星][1y] [C] [ctfs/write-ups-2016](https://github.com/ctfs/write-ups-2016) Wiki-like CTF write-ups repository, maintained by the community. 2016 -- [**1545**星][6y] [Py] [google/pyringe](https://github.com/google/pyringe) Debugger capable of attaching to and injecting code into python processes. -- [**1544**星][1m] [Shell] [mzet-/linux-exploit-suggester](https://github.com/mzet-/linux-exploit-suggester) Linux privilege escalation auditing tool -- [**1544**星][3m] [PHP] [mewebstudio/captcha](https://github.com/mewebstudio/captcha) Captcha for Laravel 5 & 6 -- [**1542**星][1m] [Py] [joxeankoret/diaphora](https://github.com/joxeankoret/diaphora) program diffing +- [**1601**星][1y] [Py] [nccgroup/scout2](https://github.com/nccgroup/Scout2) Security auditing tool for AWS environments +- [**1601**星][5m] [Py] [mozilla/cipherscan](https://github.com/mozilla/cipherscan) 查找指定目标支持的SSL ciphersuites +- [**1600**星][5d] [Go] [bitnami-labs/sealed-secrets](https://github.com/bitnami-labs/sealed-secrets) A Kubernetes controller and tool for one-way encrypted Secrets +- [**1599**星][2y] [JS] [keraf/nocoin](https://github.com/keraf/nocoin) No Coin is a tiny browser extension aiming to block coin miners such as Coinhive. +- [**1598**星][15d] [Java] [spotbugs/spotbugs](https://github.com/spotbugs/spotbugs) SpotBugs is FindBugs' successor. A tool for static analysis to look for bugs in Java code. +- [**1597**星][3m] [Py] [knownsec/pocsuite](https://github.com/knownsec/pocsuite) This project has stopped to maintenance, please to +- [**1591**星][28d] [C] [ntop/n2n](https://github.com/ntop/n2n) Peer-to-peer VPN +- [**1591**星][24d] [ivrodriguezca/re-ios-apps](https://github.com/ivrodriguezca/re-ios-apps) A completely free, open source and online course about Reverse Engineering iOS Applications. +- [**1584**星][6m] [Ruby] [brunofacca/zen-rails-security-checklist](https://github.com/brunofacca/zen-rails-security-checklist) Checklist of security precautions for Ruby on Rails applications. +- [**1583**星][4y] [l3m0n/pentest_study](https://github.com/l3m0n/pentest_study) 从零开始内网渗透学习 +- [**1582**星][1m] [ObjC] [ealeksandrov/provisionql](https://github.com/ealeksandrov/provisionql) Quick Look plugin for apps and provisioning profile files +- [**1581**星][1y] [C] [qihoo360/phptrace](https://github.com/qihoo360/phptrace) A tracing and troubleshooting tool for PHP scripts. +- [**1570**星][2m] [C] [firmianay/ctf-all-in-one](https://github.com/firmianay/ctf-all-in-one) CTF竞赛入门指南 +- [**1569**星][2y] [C] [samyk/pwnat](https://github.com/samyk/pwnat) The only tool and technique to punch holes through firewalls/NATs where both clients and server can be behind separate NATs without any 3rd party involvement. Pwnat uses a newly developed technique, exploiting a property of NAT translation tables, with no 3rd party, port forwarding, DMZ, router administrative requirements, STUN/TURN/UPnP/ICE, or… +- [**1569**星][29d] [Py] [opendevops-cn/opendevops](https://github.com/opendevops-cn/opendevops) CODO是一款为用户提供企业多混合云、一站式DevOps、自动化运维、完全开源的云管理平台、自动化运维平台 +- [**1566**星][14d] [C] [codahale/bcrypt-ruby](https://github.com/codahale/bcrypt-ruby) Ruby binding for the OpenBSD bcrypt() password hashing algorithm, allowing you to easily store a secure hash of your users' passwords. +- [**1565**星][17d] [Go] [sofastack/sofa-mosn](https://github.com/sofastack/sofa-mosn) 使用 Go 语言开发的网络代理软件,作为云原生的网络数据平面,旨在为服务提供多协议,模块化,智能化,安全的代理能力 +- [**1562**星][19d] [C] [p-gen/smenu](https://github.com/p-gen/smenu) Terminal utility that reads words from standard input or from a file and creates an interactive selection window just below the cursor. The selected word(s) are sent to standard output for further processing. +- [**1562**星][14d] [Py] [k4m4/kickthemout](https://github.com/k4m4/kickthemout) 使用ARP欺骗,将设备从网络中踢出去 +- [**1561**星][16d] [Java] [gchq/gaffer](https://github.com/gchq/Gaffer) A large-scale entity and relation database supporting aggregation of properties +- [**1560**星][1y] [Py] [unkl4b/gitminer](https://github.com/unkl4b/gitminer) Github内容挖掘 +- [**1560**星][6d] [Go] [caffix/amass](https://github.com/caffix/amass) 子域名枚举, 搜索互联网数据源, 使用机器学习猜测子域名. Go语言 +- [**1557**星][8m] [Py] [m4ll0k/wascan](https://github.com/m4ll0k/WAScan) WAScan - Web Application Scanner +- [**1556**星][15d] [Go] [eolinker/goku-api-gateway](https://github.com/eolinker/goku-api-gateway) A Powerful HTTP API Gateway in pure golang!Goku API Gateway (中文名:悟空 API 网关)是一个基于 Golang开发的微服务网关,能够实现高性能 HTTP API 转发、服务编排、多租户管理、API 访问权限控制等目的,拥有强大的自定义插件系统可以自行扩展,并且提供友好的图形化配置界面,能够快速帮助企业进行 API 服务治理、提高 API 服务的稳定性和安全性。 +- [**1555**星][1m] [Shell] [mzet-/linux-exploit-suggester](https://github.com/mzet-/linux-exploit-suggester) Linux privilege escalation auditing tool +- [**1549**星][7d] [PHP] [mewebstudio/captcha](https://github.com/mewebstudio/captcha) Captcha for Laravel 5 & 6 +- [**1549**星][1m] [Py] [joxeankoret/diaphora](https://github.com/joxeankoret/diaphora) program diffing +- [**1548**星][1y] [C] [ctfs/write-ups-2016](https://github.com/ctfs/write-ups-2016) Wiki-like CTF write-ups repository, maintained by the community. 2016 +- [**1544**星][15d] [C] [raspberrypi/userland](https://github.com/raspberrypi/userland) Source code for ARM side libraries for interfacing to Raspberry Pi GPU. +- [**1544**星][6y] [Py] [google/pyringe](https://github.com/google/pyringe) Debugger capable of attaching to and injecting code into python processes. +- [**1543**星][2d] [Go] [juju/juju](https://github.com/juju/juju) Simple, secure devops tooling built to manage today's complex applications wherever you run your software. +- [**1541**星][2y] [Py] [awolfly9/ipproxytool](https://github.com/awolfly9/ipproxytool) python ip proxy tool scrapy crawl. 抓取大量免费代理 ip,提取有效 ip 使用 - [**1540**星][2y] [C++] [hteso/iaito](https://github.com/hteso/iaito) Radare2 GUI,使用Qt和C++ -- [**1536**星][2y] [Py] [awolfly9/ipproxytool](https://github.com/awolfly9/ipproxytool) python ip proxy tool scrapy crawl. 抓取大量免费代理 ip,提取有效 ip 使用 -- [**1533**星][2y] [C] [ezlippi/webbench](https://github.com/ezlippi/webbench) Webbench是Radim Kolar在1997年写的一个在linux下使用的非常简单的网站压测工具。它使用fork()模拟多个客户端同时访问我们设定的URL,测试网站在压力下工作的性能,最多可以模拟3万个并发连接去测试网站的负载能力。官网地址: -- [**1532**星][13d] [C] [raspberrypi/userland](https://github.com/raspberrypi/userland) Source code for ARM side libraries for interfacing to Raspberry Pi GPU. -- [**1531**星][7d] [Py] [lifting-bits/mcsema](https://github.com/lifting-bits/mcsema) 将x86, amd64, aarch64二进制文件转换成LLVM字节码 +- [**1539**星][2y] [C] [ezlippi/webbench](https://github.com/ezlippi/webbench) Webbench是Radim Kolar在1997年写的一个在linux下使用的非常简单的网站压测工具。它使用fork()模拟多个客户端同时访问我们设定的URL,测试网站在压力下工作的性能,最多可以模拟3万个并发连接去测试网站的负载能力。官网地址: +- [**1537**星][9d] [Py] [lifting-bits/mcsema](https://github.com/lifting-bits/mcsema) 将x86, amd64, aarch64二进制文件转换成LLVM字节码 - [IDA7插件](https://github.com/lifting-bits/mcsema/tree/master/tools/mcsema_disass/ida7) 用于反汇编二进制文件并生成控制流程图 - [IDA插件](https://github.com/lifting-bits/mcsema/tree/master/tools/mcsema_disass/ida) 用于反汇编二进制文件并生成控制流程图 - [Binja插件](https://github.com/lifting-bits/mcsema/tree/master/tools/mcsema_disass/binja) 用于反汇编二进制文件并生成控制流程图 - [mcsema](https://github.com/lifting-bits/mcsema/tree/master/mcsema) -- [**1530**星][7d] [Go] [juju/juju](https://github.com/juju/juju) Simple, secure devops tooling built to manage today's complex applications wherever you run your software. -- [**1528**星][3y] [Py] [x0rz/eqgrp_lost_in_translation](https://github.com/x0rz/eqgrp_lost_in_translation) ShadowBrokers泄漏 -- [**1527**星][11d] [emijrp/awesome-awesome](https://github.com/emijrp/awesome-awesome) A curated list of awesome curated lists of many topics. -- [**1525**星][10d] [Java] [ukanth/afwall](https://github.com/ukanth/afwall) AFWall+ (Android Firewall +) - iptables based firewall for Android -- [**1521**星][1y] [HTML] [qiwihui/hiwifi-ss](https://github.com/qiwihui/hiwifi-ss) 极路由+ss配置 -- [**1520**星][4m] [TypeScript] [spring-guides/tut-spring-security-and-angular-js](https://github.com/spring-guides/tut-spring-security-and-angular-js) Spring Security and Angular:: A tutorial on how to use Spring Security with a single page application with various backend architectures, ranging from a simple single server to an API gateway with OAuth2 authentication. -- [**1520**星][20d] [C++] [nmap/npcap](https://github.com/nmap/npcap) Nmap Project's packet sniffing library for Windows, based on WinPcap/Libpcap improved with NDIS 6 and LWF. -- [**1519**星][10m] [PowerShell] [joefitzgerald/packer-windows](https://github.com/joefitzgerald/packer-windows) 使用Packer创建Vagrant boxes的模板 -- [**1516**星][9m] [Py] [google/rekall](https://github.com/google/rekall) Rekall Memory Forensic Framework +- [**1536**星][4d] [Java] [ukanth/afwall](https://github.com/ukanth/afwall) AFWall+ (Android Firewall +) - iptables based firewall for Android +- [**1533**星][13d] [emijrp/awesome-awesome](https://github.com/emijrp/awesome-awesome) A curated list of awesome curated lists of many topics. +- [**1532**星][3y] [Py] [x0rz/eqgrp_lost_in_translation](https://github.com/x0rz/eqgrp_lost_in_translation) ShadowBrokers泄漏 +- [**1526**星][2d] [C++] [nmap/npcap](https://github.com/nmap/npcap) Nmap Project's packet sniffing library for Windows, based on WinPcap/Libpcap improved with NDIS 6 and LWF. +- [**1522**星][1y] [HTML] [qiwihui/hiwifi-ss](https://github.com/qiwihui/hiwifi-ss) 极路由+ss配置 +- [**1521**星][4m] [TS] [spring-guides/tut-spring-security-and-angular-js](https://github.com/spring-guides/tut-spring-security-and-angular-js) Spring Security and Angular:: A tutorial on how to use Spring Security with a single page application with various backend architectures, ranging from a simple single server to an API gateway with OAuth2 authentication. +- [**1521**星][3d] [C] [jiangwenyuan/nuster](https://github.com/jiangwenyuan/nuster) A high performance HTTP proxy cache server and RESTful NoSQL cache server based on HAProxy +- [**1519**星][10m] [PS] [joefitzgerald/packer-windows](https://github.com/joefitzgerald/packer-windows) 使用Packer创建Vagrant boxes的模板 +- [**1518**星][9m] [Py] [google/rekall](https://github.com/google/rekall) Rekall Memory Forensic Framework +- [**1517**星][8d] [Py] [zerosum0x0/koadic](https://github.com/zerosum0x0/koadic) 类似于Meterpreter、Powershell Empire 的post-exploitation rootkit,区别在于其大多数操作都是由 Windows 脚本主机 JScript/VBScript 执行 +- [**1516**星][5m] [snowming04/the-hacker-playbook-3-translation](https://github.com/snowming04/the-hacker-playbook-3-translation) 对 The Hacker Playbook 3 的翻译。 +- [**1514**星][3y] [Py] [sensepost/regeorg](https://github.com/sensepost/regeorg) The successor to reDuh, pwn a bastion webserver and create SOCKS proxies through the DMZ. Pivot and pwn. - [**1510**星][1y] [dripcap/dripcap](https://github.com/dripcap/dripcap) -- [**1509**星][21d] [Py] [zerosum0x0/koadic](https://github.com/zerosum0x0/koadic) 类似于Meterpreter、Powershell Empire 的post-exploitation rootkit,区别在于其大多数操作都是由 Windows 脚本主机 JScript/VBScript 执行 -- [**1506**星][3y] [Py] [sensepost/regeorg](https://github.com/sensepost/regeorg) The successor to reDuh, pwn a bastion webserver and create SOCKS proxies through the DMZ. Pivot and pwn. -- [**1504**星][5m] [snowming04/the-hacker-playbook-3-translation](https://github.com/snowming04/the-hacker-playbook-3-translation) 对 The Hacker Playbook 3 的翻译。 -- [**1503**星][2y] [Py] [eldraco/domain_analyzer](https://github.com/eldraco/domain_analyzer) 通过查找所有能够查找的信息,来分析任意域名的安全性 -- [**1501**星][25d] [Py] [hannob/snallygaster](https://github.com/hannob/snallygaster) Python脚本, 扫描HTTP服务器"秘密文件" -- [**1500**星][2m] [Shell] [haugene/docker-transmission-openvpn](https://github.com/haugene/docker-transmission-openvpn) Docker container running Transmission torrent client with WebUI over an OpenVPN tunnel -- [**1491**星][4m] [Py] [epinna/tplmap](https://github.com/epinna/tplmap) 代码注入和服务器端模板注入(Server-Side Template Injection)漏洞利用,若干沙箱逃逸技巧。 -- [**1490**星][10d] [YARA] [cybermonitor/apt_cybercriminal_campagin_collections](https://github.com/cybermonitor/apt_cybercriminal_campagin_collections) APT & CyberCriminal Campaign Collection -- [**1487**星][7m] [Py] [ahupp/python-magic](https://github.com/ahupp/python-magic) A python wrapper for libmagic -- [**1485**星][2y] [Kotlin] [gh0u1l5/wechatmagician](https://github.com/gh0u1l5/wechatmagician) WechatMagician is a Xposed module written in Kotlin, that allows you to completely control your Wechat. -- [**1482**星][7m] [C++] [wangyu-/tinyfecvpn](https://github.com/wangyu-/tinyfecvpn) A VPN Designed for Lossy Links, with Build-in Forward Error Correction(FEC) Support. Improves your Network Quality on a High-latency Lossy Link. -- [**1478**星][7d] [C] [sleuthkit/sleuthkit](https://github.com/sleuthkit/sleuthkit) The Sleuth Kit® (TSK) is a library and collection of command line digital forensics tools that allow you to investigate volume and file system data. The library can be incorporated into larger digital forensics tools and the command line tools can be directly used to find evidence. -- [**1475**星][12d] [Py] [bitsadmin/wesng](https://github.com/bitsadmin/wesng) Windows Exploit Suggester - Next Generation -- [**1474**星][1y] [C++] [f1xpl/openauto](https://github.com/f1xpl/openauto) AndroidAuto headunit emulator -- [**1472**星][7d] [Shell] [blackarch/blackarch](https://github.com/blackarch/blackarch) BlackArch Linux is an Arch Linux-based distribution for penetration testers and security researchers. -- [**1468**星][16d] [Go] [google/keytransparency](https://github.com/google/keytransparency) A transparent and secure way to look up public keys. -- [**1468**星][3m] [C] [iqiyi/xhook](https://github.com/iqiyi/xhook) a PLT (Procedure Linkage Table) hook library for Android native ELF -- [**1466**星][2m] [C++] [jmpews/hookzz](https://github.com/jmpews/hookzz) a hook framework for arm/arm64/ios/android, and [dev] branch is being refactored. -- [**1465**星][3y] [Py] [veil-framework/veil-evasion](https://github.com/Veil-Framework/Veil-Evasion) a tool designed to generate metasploit payloads that bypass common anti-virus solutions. -- [**1465**星][25d] [minimaxir/hacker-news-undocumented](https://github.com/minimaxir/hacker-news-undocumented) Some of the hidden norms about Hacker News not otherwise covered in the Guidelines and the FAQ. -- [**1462**星][6y] [C] [alibaba/lvs](https://github.com/alibaba/lvs) A distribution of Linux Virtual Server with some advanced features. It introduces a new packet forwarding method - FULLNAT other than NAT/Tunneling/DirectRouting, and defense mechanism against synflooding attack - SYNPROXY. -- [**1460**星][14d] [C] [ufrisk/pcileech](https://github.com/ufrisk/pcileech) 直接内存访问(DMA:Direct Memory Access)攻击工具。通过 PCIe 硬件设备使用 DMA,直接读写目标系统的内存。目标系统不需要安装驱动。 -- [**1457**星][1y] [C++] [acaudwell/logstalgia](https://github.com/acaudwell/logstalgia) a visualization tool that replays or streams web server access logs as a retro arcade game simulation. -- [**1456**星][27d] [Go] [neex/phuip-fpizdam](https://github.com/neex/phuip-fpizdam) Exploit for CVE-2019-11043 -- [**1450**星][1y] [Py] [d4vinci/cr3dov3r](https://github.com/d4vinci/cr3dov3r) Know the dangers of credential reuse attacks. -- [**1448**星][6m] [Py] [enablesecurity/wafw00f](https://github.com/enablesecurity/wafw00f) 识别保护网站的WAF产品 -- [**1447**星][3m] [edoverflow/can-i-take-over-xyz](https://github.com/edoverflow/can-i-take-over-xyz) "Can I take over XYZ?" — a list of services and how to claim (sub)domains with dangling DNS records. -- [**1446**星][11d] [C++] [srslte/srslte](https://github.com/srslte/srslte) Open source SDR LTE software suite from Software Radio Systems (SRS) -- [**1442**星][6m] [Py] [oros42/imsi-catcher](https://github.com/oros42/imsi-catcher) This program show you IMSI numbers of cellphones around you. -- [**1441**星][19d] [C] [tianocore/edk2](https://github.com/tianocore/edk2) A modern, feature-rich, cross-platform firmware development environment for the UEFI and PI specifications -- [**1441**星][1m] [C] [ctcaer/hekate](https://github.com/ctcaer/hekate) Nintendo Switch Bootloader - CTCaer mod -- [**1439**星][3y] [tiancode/learn-hacking](https://github.com/tiancode/learn-hacking) 开始学习Kali Linux 各种破解教程 渗透测试 逆向工程 HackThisSite挑战问题解答 -- [**1439**星][3y] [tiancode/learn-hacking](https://github.com/tiancode/learn-hacking) 开始学习Kali Linux 各种破解教程 渗透测试 逆向工程 HackThisSite挑战问题解答 -- [**1438**星][3m] [C++] [vaibhavpandeyvpz/apkstudio](https://github.com/vaibhavpandeyvpz/apkstudio) Open-source, cross platform Qt based IDE for reverse-engineering Android application packages. -- [**1433**星][18d] [Go] [skydive-project/skydive](https://github.com/skydive-project/skydive) An open source real-time network topology and protocols analyzer -- [**1433**星][1y] [TypeScript] [pedronauck/reworm](https://github.com/pedronauck/reworm) -- [**1433**星][12d] [C++] [microsoft/seal](https://github.com/microsoft/seal) Microsoft SEAL is an easy-to-use and powerful homomorphic encryption library. -- [**1430**星][7d] [Go] [google/gapid](https://github.com/google/gapid) Graphics API Debugger -- [**1428**星][7d] [Py] [rocky/python-uncompyle6](https://github.com/rocky/python-uncompyle6) Python反编译器,跨平台 -- [**1427**星][6m] [C++] [x64dbg/scyllahide](https://github.com/x64dbg/scyllahide) Advanced usermode anti-anti-debugger +- [**1508**星][2m] [Shell] [haugene/docker-transmission-openvpn](https://github.com/haugene/docker-transmission-openvpn) Docker container running Transmission torrent client with WebUI over an OpenVPN tunnel +- [**1505**星][2y] [Py] [eldraco/domain_analyzer](https://github.com/eldraco/domain_analyzer) 通过查找所有能够查找的信息,来分析任意域名的安全性 +- [**1504**星][27d] [Py] [hannob/snallygaster](https://github.com/hannob/snallygaster) Python脚本, 扫描HTTP服务器"秘密文件" +- [**1499**星][5d] [YARA] [cybermonitor/apt_cybercriminal_campagin_collections](https://github.com/cybermonitor/apt_cybercriminal_campagin_collections) APT & CyberCriminal Campaign Collection +- [**1497**星][4m] [Py] [epinna/tplmap](https://github.com/epinna/tplmap) 代码注入和服务器端模板注入(Server-Side Template Injection)漏洞利用,若干沙箱逃逸技巧。 +- [**1489**星][5d] [Py] [ahupp/python-magic](https://github.com/ahupp/python-magic) A python wrapper for libmagic +- [**1486**星][2y] [Kotlin] [gh0u1l5/wechatmagician](https://github.com/gh0u1l5/wechatmagician) WechatMagician is a Xposed module written in Kotlin, that allows you to completely control your Wechat. +- [**1485**星][7m] [C++] [wangyu-/tinyfecvpn](https://github.com/wangyu-/tinyfecvpn) A VPN Designed for Lossy Links, with Build-in Forward Error Correction(FEC) Support. Improves your Network Quality on a High-latency Lossy Link. +- [**1482**星][7d] [Py] [bitsadmin/wesng](https://github.com/bitsadmin/wesng) Windows Exploit Suggester - Next Generation +- [**1481**星][2d] [C] [sleuthkit/sleuthkit](https://github.com/sleuthkit/sleuthkit) The Sleuth Kit® (TSK) is a library and collection of command line digital forensics tools that allow you to investigate volume and file system data. The library can be incorporated into larger digital forensics tools and the command line tools can be directly used to find evidence. +- [**1480**星][1y] [C++] [f1xpl/openauto](https://github.com/f1xpl/openauto) AndroidAuto headunit emulator +- [**1479**星][3d] [C] [ctcaer/hekate](https://github.com/ctcaer/hekate) Nintendo Switch Bootloader - CTCaer mod +- [**1478**星][8d] [C] [iqiyi/xhook](https://github.com/iqiyi/xhook) a PLT (Procedure Linkage Table) hook library for Android native ELF +- [**1477**星][2d] [Shell] [blackarch/blackarch](https://github.com/blackarch/blackarch) BlackArch Linux is an Arch Linux-based distribution for penetration testers and security researchers. +- [**1476**星][2m] [C++] [jmpews/hookzz](https://github.com/jmpews/hookzz) a hook framework for arm/arm64/ios/android, and [dev] branch is being refactored. +- [**1471**星][27d] [minimaxir/hacker-news-undocumented](https://github.com/minimaxir/hacker-news-undocumented) Some of the hidden norms about Hacker News not otherwise covered in the Guidelines and the FAQ. +- [**1470**星][3y] [Py] [veil-framework/veil-evasion](https://github.com/Veil-Framework/Veil-Evasion) a tool designed to generate metasploit payloads that bypass common anti-virus solutions. +- [**1470**星][2d] [Go] [google/keytransparency](https://github.com/google/keytransparency) A transparent and secure way to look up public keys. +- [**1469**星][6y] [C] [alibaba/lvs](https://github.com/alibaba/lvs) A distribution of Linux Virtual Server with some advanced features. It introduces a new packet forwarding method - FULLNAT other than NAT/Tunneling/DirectRouting, and defense mechanism against synflooding attack - SYNPROXY. +- [**1466**星][29d] [Go] [neex/phuip-fpizdam](https://github.com/neex/phuip-fpizdam) Exploit for CVE-2019-11043 +- [**1464**星][6m] [Py] [oros42/imsi-catcher](https://github.com/oros42/imsi-catcher) This program show you IMSI numbers of cellphones around you. +- [**1463**星][7d] [C] [ufrisk/pcileech](https://github.com/ufrisk/pcileech) DMA攻击工具。通过 PCIe 硬件设备使用 DMA,直接读写目标系统的内存。目标系统不需要安装驱动。 +- [**1462**星][9d] [edoverflow/can-i-take-over-xyz](https://github.com/edoverflow/can-i-take-over-xyz) "Can I take over XYZ?" — a list of services and how to claim (sub)domains with dangling DNS records. +- [**1459**星][3d] [Py] [enablesecurity/wafw00f](https://github.com/enablesecurity/wafw00f) 识别保护网站的WAF产品 +- [**1458**星][1y] [C++] [acaudwell/logstalgia](https://github.com/acaudwell/logstalgia) a visualization tool that replays or streams web server access logs as a retro arcade game simulation. +- [**1455**星][1y] [Py] [d4vinci/cr3dov3r](https://github.com/d4vinci/cr3dov3r) Know the dangers of credential reuse attacks. +- [**1453**星][13d] [C++] [srslte/srslte](https://github.com/srslte/srslte) Open source SDR LTE software suite from Software Radio Systems (SRS) +- [**1451**星][2d] [Py] [rocky/python-uncompyle6](https://github.com/rocky/python-uncompyle6) Python反编译器,跨平台 +- [**1447**星][3y] [tiancode/learn-hacking](https://github.com/tiancode/learn-hacking) 开始学习Kali Linux 各种破解教程 渗透测试 逆向工程 HackThisSite挑战问题解答 +- [**1447**星][3y] [tiancode/learn-hacking](https://github.com/tiancode/learn-hacking) 开始学习Kali Linux 各种破解教程 渗透测试 逆向工程 HackThisSite挑战问题解答 +- [**1447**星][2m] [Py] [neo23x0/loki](https://github.com/neo23x0/loki) Loki - Simple IOC and Incident Response Scanner +- [**1446**星][5d] [C] [tianocore/edk2](https://github.com/tianocore/edk2) A modern, feature-rich, cross-platform firmware development environment for the UEFI and PI specifications +- [**1446**星][20d] [Go] [skydive-project/skydive](https://github.com/skydive-project/skydive) An open source real-time network topology and protocols analyzer +- [**1446**星][14d] [C++] [microsoft/seal](https://github.com/microsoft/seal) Microsoft SEAL is an easy-to-use and powerful homomorphic encryption library. +- [**1445**星][3m] [C++] [vaibhavpandeyvpz/apkstudio](https://github.com/vaibhavpandeyvpz/apkstudio) Open-source, cross platform Qt based IDE for reverse-engineering Android application packages. +- [**1437**星][5d] [Go] [google/gapid](https://github.com/google/gapid) Graphics API Debugger +- [**1436**星][20d] [Kotlin] [cypherpunkarmory/userland](https://github.com/cypherpunkarmory/userland) The easiest way to run a Linux distribution or application on Android +- [**1433**星][11m] [C] [tpruvot/ccminer](https://github.com/tpruvot/ccminer) CUDA Open Source miner project, for most nvidia cards +- [**1433**星][1y] [TS] [pedronauck/reworm](https://github.com/pedronauck/reworm) +- [**1432**星][6m] [C++] [x64dbg/scyllahide](https://github.com/x64dbg/scyllahide) Advanced usermode anti-anti-debugger +- [**1432**星][2m] [C] [feralinteractive/gamemode](https://github.com/feralinteractive/gamemode) Optimise Linux system performance on demand +- [**1429**星][5y] [C++] [gdbinit/machoview](https://github.com/gdbinit/machoview) MachOView fork +- [**1427**星][9d] [ObjC] [nabla-c0d3/ssl-kill-switch2](https://github.com/nabla-c0d3/ssl-kill-switch2) Blackbox tool to disable SSL certificate validation - including certificate pinning - within iOS and OS X Apps +- [**1426**星][20d] [C++] [plasma-umass/coz](https://github.com/plasma-umass/coz) Finding Code that Counts with Causal Profiling +- [**1426**星][4y] [C++] [aappleby/smhasher](https://github.com/aappleby/smhasher) Automatically exported from code.google.com/p/smhasher - [**1425**星][3m] [Go] [google/stenographer](https://github.com/google/stenographer) Stenographer is a packet capture solution which aims to quickly spool all packets to disk, then provide simple, fast access to subsets of those packets. Discussion/announcements at stenographer@googlegroups.com -- [**1423**星][8y] [Py] [moxie0/sslstrip](https://github.com/moxie0/sslstrip) A tool for exploiting Moxie Marlinspike's SSL "stripping" attack. -- [**1423**星][18d] [Kotlin] [cypherpunkarmory/userland](https://github.com/cypherpunkarmory/userland) The easiest way to run a Linux distribution or application on Android -- [**1422**星][2m] [C] [feralinteractive/gamemode](https://github.com/feralinteractive/gamemode) Optimise Linux system performance on demand -- [**1421**星][3y] [mandatoryprogrammer/northkoreadnsleak](https://github.com/mandatoryprogrammer/northkoreadnsleak) Snapshot of North Korea's DNS data taken from zone transfers. -- [**1421**星][4y] [C++] [aappleby/smhasher](https://github.com/aappleby/smhasher) Automatically exported from code.google.com/p/smhasher -- [**1420**星][10m] [Java] [aslody/legend](https://github.com/aslody/legend) (Android)无需Root即可Hook Java方法的框架, 支持Dalvik和Art环境 -- [**1419**星][2m] [Py] [neo23x0/loki](https://github.com/neo23x0/loki) Loki - Simple IOC and Incident Response Scanner -- [**1419**星][3y] [Py] [nathanlopez/stitch](https://github.com/nathanlopez/stitch) Python Remote Administration Tool (RAT) -- [**1419**星][12d] [Go] [google/google-ctf](https://github.com/google/google-ctf) Google CTF -- [**1419**星][5y] [C++] [gdbinit/machoview](https://github.com/gdbinit/machoview) MachOView fork -- [**1417**星][1m] [Py] [xdavidhu/mitmap](https://github.com/xdavidhu/mitmap) -- [**1417**星][5m] [PHP] [s4n7h0/xvwa](https://github.com/s4n7h0/xvwa) XVWA is a badly coded web application written in PHP/MySQL that helps security enthusiasts to learn application security. -- [**1416**星][1m] [Go] [barnybug/cli53](https://github.com/barnybug/cli53) Command line tool for Amazon Route 53 -- [**1415**星][3y] [C] [antirez/dump1090](https://github.com/antirez/dump1090) Dump1090 is a simple Mode S decoder for RTLSDR devices -- [**1413**星][7m] [Objective-C] [nabla-c0d3/ssl-kill-switch2](https://github.com/nabla-c0d3/ssl-kill-switch2) Blackbox tool to disable SSL certificate validation - including certificate pinning - within iOS and OS X Apps -- [**1411**星][11d] [C] [ettercap/ettercap](https://github.com/ettercap/ettercap) Ettercap Project -- [**1410**星][8d] [Go] [cosmos72/gomacro](https://github.com/cosmos72/gomacro) Interactive Go interpreter and debugger with REPL, Eval, generics and Lisp-like macros -- [**1409**星][4m] [yadox666/the-hackers-hardware-toolkit](https://github.com/yadox666/the-hackers-hardware-toolkit) The best hacker's gadgets for Red Team pentesters and security researchers. -- [**1408**星][22d] [Java] [chrisk44/hijacker](https://github.com/chrisk44/hijacker) Aircrack, Airodump, Aireplay, MDK3 and Reaver GUI Application for Android -- [**1407**星][7d] [C] [namhyung/uftrace](https://github.com/namhyung/uftrace) Function (graph) tracer for user-space -- [**1406**星][1m] [C++] [google/nsjail](https://github.com/google/nsjail) A light-weight process isolation tool, making use of Linux namespaces and seccomp-bpf syscall filters (with help of the kafel bpf language) -- [**1402**星][5m] [gitguardian/apisecuritybestpractices](https://github.com/gitguardian/apisecuritybestpractices) Resources to help you keep secrets (API keys, database credentials, certificates, ...) out of source code and remediate the issue in case of a leaked API key. Made available by GitGuardian. -- [**1402**星][7d] [C++] [eteran/edb-debugger](https://github.com/eteran/edb-debugger) edb is a cross platform AArch32/x86/x86-64 debugger. +- [**1424**星][8y] [Py] [moxie0/sslstrip](https://github.com/moxie0/sslstrip) A tool for exploiting Moxie Marlinspike's SSL "stripping" attack. +- [**1424**星][11m] [Java] [aslody/legend](https://github.com/aslody/legend) (Android)无需Root即可Hook Java方法的框架, 支持Dalvik和Art环境 +- [**1423**星][14d] [Go] [google/google-ctf](https://github.com/google/google-ctf) Google CTF +- [**1422**星][3y] [Py] [nathanlopez/stitch](https://github.com/nathanlopez/stitch) Python Remote Administration Tool (RAT) +- [**1422**星][3y] [mandatoryprogrammer/northkoreadnsleak](https://github.com/mandatoryprogrammer/northkoreadnsleak) Snapshot of North Korea's DNS data taken from zone transfers. +- [**1419**星][1m] [Py] [xdavidhu/mitmap](https://github.com/xdavidhu/mitmap) +- [**1419**星][3y] [C] [antirez/dump1090](https://github.com/antirez/dump1090) Dump1090 is a simple Mode S decoder for RTLSDR devices +- [**1418**星][5m] [PHP] [s4n7h0/xvwa](https://github.com/s4n7h0/xvwa) XVWA is a badly coded web application written in PHP/MySQL that helps security enthusiasts to learn application security. +- [**1417**星][4m] [yadox666/the-hackers-hardware-toolkit](https://github.com/yadox666/the-hackers-hardware-toolkit) 用于Red Team、渗透、安全研究的最佳硬件产品集合 +- [**1417**星][4d] [Rust] [shadowsocks/shadowsocks-rust](https://github.com/shadowsocks/shadowsocks-rust) A Rust port of shadowsocks +- [**1417**星][1m] [Go] [barnybug/cli53](https://github.com/barnybug/cli53) Command line tool for Amazon Route 53 +- [**1415**星][7d] [C] [z3apa3a/3proxy](https://github.com/z3apa3a/3proxy) 3proxy - tiny free proxy server +- [**1414**星][8d] [C] [ettercap/ettercap](https://github.com/ettercap/ettercap) Ettercap Project +- [**1413**星][24d] [XSLT] [lolbas-project/lolbas](https://github.com/lolbas-project/lolbas) Living Off The Land Binaries And Scripts - (LOLBins and LOLScripts) +- [**1413**星][24d] [Java] [chrisk44/hijacker](https://github.com/chrisk44/hijacker) Aircrack, Airodump, Aireplay, MDK3 and Reaver GUI Application for Android +- [**1412**星][9d] [C] [namhyung/uftrace](https://github.com/namhyung/uftrace) Function (graph) tracer for user-space +- [**1412**星][5m] [gitguardian/apisecuritybestpractices](https://github.com/gitguardian/apisecuritybestpractices) Resources to help you keep secrets (API keys, database credentials, certificates, ...) out of source code and remediate the issue in case of a leaked API key. Made available by GitGuardian. +- [**1411**星][7d] [C++] [eteran/edb-debugger](https://github.com/eteran/edb-debugger) edb is a cross platform AArch32/x86/x86-64 debugger. +- [**1411**星][3d] [Go] [cosmos72/gomacro](https://github.com/cosmos72/gomacro) Interactive Go interpreter and debugger with REPL, Eval, generics and Lisp-like macros +- [**1410**星][3m] [Go] [hellogcc/100-gdb-tips](https://github.com/hellogcc/100-gdb-tips) A collection of gdb tips. 100 maybe just mean many here. +- [**1408**星][3m] [HTML] [owasp/top10](https://github.com/owasp/top10) Official OWASP Top 10 Document Repository +- [**1407**星][4d] [C++] [google/nsjail](https://github.com/google/nsjail) A light-weight process isolation tool, making use of Linux namespaces and seccomp-bpf syscall filters (with help of the kafel bpf language) +- [**1405**星][1y] [HTML] [gwuhaolin/blog](https://github.com/gwuhaolin/blog) 浩麟的技术博客 +- [**1405**星][1y] [C++] [dotnet/llilc](https://github.com/dotnet/llilc) This repo contains LLILC, an LLVM based compiler for .NET Core. It includes a set of cross-platform .NET code generation tools that enables compilation of MSIL byte code to LLVM supported platforms. +- [**1404**星][7d] [Java] [chinashiyu/gfw.press](https://github.com/chinashiyu/gfw.press) GFW.Press新一代军用级高强度加密抗干扰网络数据高速传输软件 +- [**1403**星][2d] [Go] [crazy-max/windowsspyblocker](https://github.com/crazy-max/windowsspyblocker) - [**1401**星][9m] [JS] [anttiviljami/browser-autofill-phishing](https://github.com/anttiviljami/browser-autofill-phishing) A simple demo of phishing by abusing the browser autofill feature -- [**1400**星][3m] [HTML] [owasp/top10](https://github.com/owasp/top10) Official OWASP Top 10 Document Repository -- [**1400**星][1y] [C++] [dotnet/llilc](https://github.com/dotnet/llilc) This repo contains LLILC, an LLVM based compiler for .NET Core. It includes a set of cross-platform .NET code generation tools that enables compilation of MSIL byte code to LLVM supported platforms. -- [**1399**星][25d] [Go] [crazy-max/windowsspyblocker](https://github.com/crazy-max/windowsspyblocker) -- [**1399**星][7d] [Java] [chinashiyu/gfw.press](https://github.com/chinashiyu/gfw.press) GFW.Press新一代军用级高强度加密抗干扰网络数据高速传输软件 -- [**1397**星][7d] [Rust] [shadowsocks/shadowsocks-rust](https://github.com/shadowsocks/shadowsocks-rust) A Rust port of shadowsocks -- [**1395**星][1y] [Go] [filosottile/whosthere](https://github.com/filosottile/whosthere) A ssh server that knows who you are -- [**1393**星][25d] [C] [quiet/org.quietmodem.quiet](https://github.com/quiet/org.quietmodem.quiet) Quiet for Android - TCP over sound -- [**1393**星][3y] [PowerShell] [putterpanda/mimikittenz](https://github.com/putterpanda/mimikittenz) A post-exploitation powershell tool for extracting juicy info from memory. -- [**1391**星][22d] [XSLT] [lolbas-project/lolbas](https://github.com/lolbas-project/lolbas) Living Off The Land Binaries And Scripts - (LOLBins and LOLScripts) -- [**1388**星][14d] [Swift] [johnno1962/injectioniii](https://github.com/johnno1962/injectioniii) Re-write of Injection for Xcode in (mostly) Swift4 -- [**1387**星][1y] [HTML] [gwuhaolin/blog](https://github.com/gwuhaolin/blog) 浩麟的技术博客 -- [**1387**星][2y] [JS] [sqren/fb-sleep-stats](https://github.com/sqren/fb-sleep-stats) 使用Facebook追踪用户的睡觉习惯 -- [**1386**星][18d] [C++] [plasma-umass/coz](https://github.com/plasma-umass/coz) Finding Code that Counts with Causal Profiling -- [**1384**星][4y] [PHP] [johntroony/php-webshells](https://github.com/johntroony/php-webshells) Common php webshells. Do not host the file(s) on your server! -- [**1383**星][14d] [C++] [jonathansalwan/triton](https://github.com/jonathansalwan/triton) Triton is a Dynamic Binary Analysis (DBA) framework. It provides internal components like a Dynamic Symbolic Execution (DSE) engine, a dynamic taint engine, AST representations of the x86, x86-64 and AArch64 Instructions Set Architecture (ISA), SMT simplification passes, an SMT solver interface and, the last but not least, Python bindings. -- [**1383**星][8d] [Py] [ekultek/whatwaf](https://github.com/ekultek/whatwaf) Detect and bypass web application firewalls and protection systems -- [**1381**星][11m] [Py] [eth0izzle/bucket-stream](https://github.com/eth0izzle/bucket-stream) 通过certstream 监控多种证书 transparency 日志, 进而查找有趣的 Amazon S3 Buckets -- [**1380**星][2m] [C] [z3apa3a/3proxy](https://github.com/z3apa3a/3proxy) 3proxy - tiny free proxy server -- [**1380**星][11d] [Shell] [drduh/pwd.sh](https://github.com/drduh/pwd.sh) GPG symmetric password manager -- [**1377**星][11d] [OCaml] [mirage/mirage](https://github.com/mirage/mirage) MirageOS is a library operating system that constructs unikernels -- [**1376**星][6m] [Py] [almandin/fuxploider](https://github.com/almandin/fuxploider) 文件上传漏洞扫描和利用工具 -- [**1375**星][10m] [JS] [intika/librefox](https://github.com/intika/librefox) Firefox with privacy enhancements +- [**1399**星][16d] [Swift] [johnno1962/injectioniii](https://github.com/johnno1962/injectioniii) Re-write of Injection for Xcode in (mostly) Swift4 +- [**1397**星][1y] [Go] [filosottile/whosthere](https://github.com/filosottile/whosthere) A ssh server that knows who you are +- [**1396**星][3y] [PS] [putterpanda/mimikittenz](https://github.com/putterpanda/mimikittenz) A post-exploitation powershell tool for extracting juicy info from memory. +- [**1395**星][27d] [C] [quiet/org.quietmodem.quiet](https://github.com/quiet/org.quietmodem.quiet) Quiet for Android - TCP over sound +- [**1393**星][4d] [atarity/deploy-your-own-saas](https://github.com/atarity/deploy-your-own-saas) List of "only yours" cloud services for everyday needs +- [**1393**星][9d] [Py] [ekultek/whatwaf](https://github.com/ekultek/whatwaf) 检测并绕过WAF和保护系统 +- [**1392**星][16d] [C++] [jonathansalwan/triton](https://github.com/jonathansalwan/triton) Triton is a Dynamic Binary Analysis (DBA) framework. It provides internal components like a Dynamic Symbolic Execution (DSE) engine, a dynamic taint engine, AST representations of the x86, x86-64 and AArch64 Instructions Set Architecture (ISA), SMT simplification passes, an SMT solver interface and, the last but not least, Python bindings. +- [**1388**星][4y] [PHP] [johntroony/php-webshells](https://github.com/johntroony/php-webshells) Common php webshells. Do not host the file(s) on your server! +- [**1387**星][11m] [Py] [eth0izzle/bucket-stream](https://github.com/eth0izzle/bucket-stream) 通过certstream 监控多种证书 transparency 日志, 进而查找有趣的 Amazon S3 Buckets +- [**1386**星][2y] [JS] [sqren/fb-sleep-stats](https://github.com/sqren/fb-sleep-stats) 使用Facebook追踪用户的睡觉习惯 +- [**1384**星][5d] [JS] [ix64/unlock-music](https://github.com/ix64/unlock-music) Unlock encrypted music file in browser. 在浏览器中解锁加密的音乐文件。 +- [**1381**星][6m] [Py] [almandin/fuxploider](https://github.com/almandin/fuxploider) 文件上传漏洞扫描和利用工具 +- [**1380**星][15d] [C] [dynamorio/drmemory](https://github.com/dynamorio/drmemory) Memory Debugger for Windows, Linux, Mac, and Android +- [**1380**星][13d] [Shell] [drduh/pwd.sh](https://github.com/drduh/pwd.sh) GPG symmetric password manager +- [**1378**星][13d] [OCaml] [mirage/mirage](https://github.com/mirage/mirage) MirageOS is a library operating system that constructs unikernels +- [**1378**星][2d] [JS] [lockfale/osint-framework](https://github.com/lockfale/osint-framework) OSINT Framework +- [**1375**星][15d] [Go] [unrolled/secure](https://github.com/unrolled/secure) HTTP middleware for Go that facilitates some quick security wins. +- [**1375**星][11m] [JS] [intika/librefox](https://github.com/intika/librefox) Firefox with privacy enhancements - [**1374**星][4y] [C++] [valvesoftware/vogl](https://github.com/valvesoftware/vogl) OpenGL capture / playback debugger. -- [**1373**星][13d] [C] [dynamorio/drmemory](https://github.com/dynamorio/drmemory) Memory Debugger for Windows, Linux, Mac, and Android -- [**1365**星][9m] [PowerShell] [danielbohannon/invoke-obfuscation](https://github.com/danielbohannon/invoke-obfuscation) PowerShell Obfuscator -- [**1364**星][5m] [Py] [s0md3v/striker](https://github.com/s0md3v/Striker) Striker is an offensive information and vulnerability scanner. -- [**1363**星][29d] [C] [zyantific/zydis](https://github.com/zyantific/zydis) 快速的轻量级x86/x86-64 反汇编库 -- [**1361**星][3y] [C++] [aslody/turbodex](https://github.com/aslody/turbodex) 在内存中快速加载dex -- [**1360**星][6m] [Py] [vulnerscom/getsploit](https://github.com/vulnerscom/getsploit) Command line utility for searching and downloading exploits -- [**1360**星][2m] [Py] [fireeye/flare-floss](https://github.com/fireeye/flare-floss) 自动从恶意代码中提取反混淆后的字符串 +- [**1373**星][5m] [Py] [s0md3v/striker](https://github.com/s0md3v/Striker) Striker is an offensive information and vulnerability scanner. +- [**1373**星][9m] [PS] [danielbohannon/invoke-obfuscation](https://github.com/danielbohannon/invoke-obfuscation) PowerShell Obfuscator +- [**1371**星][1m] [C] [zyantific/zydis](https://github.com/zyantific/zydis) 快速的轻量级x86/x86-64 反汇编库 +- [**1365**星][9d] [Go] [cortesi/modd](https://github.com/cortesi/modd) A flexible developer tool that runs processes and responds to filesystem changes +- [**1363**星][2m] [Py] [fireeye/flare-floss](https://github.com/fireeye/flare-floss) 自动从恶意代码中提取反混淆后的字符串 - [floss](https://github.com/fireeye/flare-floss/tree/master/floss) - [IDA插件](https://github.com/fireeye/flare-floss/blob/master/scripts/idaplugin.py) -- [**1358**星][7d] [Go] [cortesi/modd](https://github.com/cortesi/modd) A flexible developer tool that runs processes and responds to filesystem changes -- [**1357**星][24d] [JS] [lockfale/osint-framework](https://github.com/lockfale/osint-framework) OSINT Framework -- [**1355**星][6m] [C++] [phpv8/v8js](https://github.com/phpv8/v8js) V8 Javascript Engine for PHP — This PHP extension embeds the Google V8 Javascript Engine -- [**1355**星][1m] [grrrdog/java-deserialization-cheat-sheet](https://github.com/grrrdog/java-deserialization-cheat-sheet) The cheat sheet about Java Deserialization vulnerabilities -- [**1355**星][2m] [C] [googleprojectzero/winafl](https://github.com/googleprojectzero/winafl) A fork of AFL for fuzzing Windows binaries -- [**1348**星][23d] [C] [x64dbg/x64dbgpy](https://github.com/x64dbg/x64dbgpy) Automating x64dbg using Python, Snapshots: -- [**1348**星][4m] [C] [taviso/ctftool](https://github.com/taviso/ctftool) Interactive CTF Exploration Tool -- [**1348**星][3y] [Py] [joaomatosf/jexboss](https://github.com/joaomatosf/jexboss) Jboss (and Java Deserialization Vulnerabilities) verify and EXploitation Tool -- [**1347**星][13d] [Go] [unrolled/secure](https://github.com/unrolled/secure) HTTP middleware for Go that facilitates some quick security wins. -- [**1347**星][3m] [C++] [raspberrypi/tools](https://github.com/raspberrypi/tools) +- [**1363**星][3y] [C++] [aslody/turbodex](https://github.com/aslody/turbodex) 在内存中快速加载dex +- [**1362**星][1m] [grrrdog/java-deserialization-cheat-sheet](https://github.com/grrrdog/java-deserialization-cheat-sheet) The cheat sheet about Java Deserialization vulnerabilities +- [**1361**星][7m] [Py] [vulnerscom/getsploit](https://github.com/vulnerscom/getsploit) Command line utility for searching and downloading exploits +- [**1361**星][6m] [C++] [phpv8/v8js](https://github.com/phpv8/v8js) V8 Javascript Engine for PHP — This PHP extension embeds the Google V8 Javascript Engine +- [**1359**星][2m] [C] [googleprojectzero/winafl](https://github.com/googleprojectzero/winafl) A fork of AFL for fuzzing Windows binaries +- [**1355**星][10m] [HTML] [thelinuxchoice/blackeye](https://github.com/thelinuxchoice/blackeye) The most complete Phishing Tool, with 32 templates +1 customizable +- [**1354**星][2d] [Py] [mitre/caldera](https://github.com/mitre/caldera) 自动化 adversary emulation 系统 +- [**1352**星][3y] [Py] [joaomatosf/jexboss](https://github.com/joaomatosf/jexboss) Jboss (and Java Deserialization Vulnerabilities) verify and EXploitation Tool +- [**1351**星][3m] [C++] [raspberrypi/tools](https://github.com/raspberrypi/tools) +- [**1350**星][4m] [C] [taviso/ctftool](https://github.com/taviso/ctftool) Interactive CTF Exploration Tool +- [**1349**星][3y] [Py] [ddevault/evilpass](https://github.com/ddevault/evilpass) Slightly evil password strength checker +- [**1349**星][19d] [C++] [rikkaapps/riru](https://github.com/rikkaapps/riru) Inject zygote process by replace libmemtrack +- [**1349**星][5m] [Py] [lijiejie/githack](https://github.com/lijiejie/githack) git泄露利用脚本,通过泄露的.git文件夹下的文件,重建还原工程源代码 +- [**1348**星][10m] [rebeyond/behinder](https://github.com/rebeyond/behinder) “冰蝎”动态二进制加密网站管理客户端 - [**1347**星][11m] [Rust] [das-labor/panopticon](https://github.com/das-labor/panopticon) A libre cross-platform disassembler. -- [**1346**星][3y] [Py] [ddevault/evilpass](https://github.com/ddevault/evilpass) Slightly evil password strength checker - [**1346**星][2y] [HTML] [daxeel/blockshell](https://github.com/daxeel/blockshell) 用于学习区块链技术概念的命令行工具, 例如 likechaining, mining,proof of work 等 -- [**1344**星][10m] [HTML] [thelinuxchoice/blackeye](https://github.com/thelinuxchoice/blackeye) The most complete Phishing Tool, with 32 templates +1 customizable -- [**1343**星][5m] [Py] [lijiejie/githack](https://github.com/lijiejie/githack) git泄露利用脚本,通过泄露的.git文件夹下的文件,重建还原工程源代码 -- [**1343**星][3m] [Go] [hellogcc/100-gdb-tips](https://github.com/hellogcc/100-gdb-tips) A collection of gdb tips. 100 maybe just mean many here. -- [**1342**星][7d] [Py] [mitre/caldera](https://github.com/mitre/caldera) 自动化 adversary emulation 系统 -- [**1341**星][10d] [Go] [securitywithoutborders/hardentools](https://github.com/securitywithoutborders/hardentools) 禁用许多有危险的Windows功能 -- [**1341**星][2m] [Go] [davrodpin/mole](https://github.com/davrodpin/mole) cli app to create ssh tunnels -- [**1339**星][21d] [Py] [s0md3v/arjun](https://github.com/s0md3v/Arjun) HTTP parameter discovery suite. -- [**1339**星][12m] [XSLT] [api0cradle/lolbas](https://github.com/api0cradle/lolbas) Living Off The Land Binaries And Scripts - (LOLBins and LOLScripts) -- [**1338**星][21d] [Go] [microcosm-cc/bluemonday](https://github.com/microcosm-cc/bluemonday) a fast golang HTML sanitizer (inspired by the OWASP Java HTML Sanitizer) to scrub user generated content of XSS -- [**1338**星][7m] [Py] [feeicn/gsil](https://github.com/feeicn/gsil) GitHub敏感信息泄露监控,几乎实时监控,发送警告 -- [**1337**星][1y] [Py] [carmaa/inception](https://github.com/carmaa/inception) 利用基于PCI的DMA实现物理内存的操纵与Hacking,可以攻击FireWire,Thunderbolt,ExpressCard,PC Card和任何其他PCI / PCIe硬件接口 -- [**1336**星][6y] [Perl] [intelisecurelabs/linux_exploit_suggester](https://github.com/InteliSecureLabs/Linux_Exploit_Suggester) Linux Exploit Suggester; based on operating system release number -- [**1336**星][3m] [Py] [maratyszcza/peachpy](https://github.com/maratyszcza/peachpy) x86-64 assembler embedded in Python -- [**1333**星][17d] [C++] [rikkaapps/riru](https://github.com/rikkaapps/riru) Inject zygote process by replace libmemtrack -- [**1331**星][2m] [C++] [mfontanini/libtins](https://github.com/mfontanini/libtins) High-level, multiplatform C++ network packet sniffing and crafting library. -- [**1331**星][1y] [C] [gamelinux/passivedns](https://github.com/gamelinux/passivedns) A network sniffer that logs all DNS server replies for use in a passive DNS setup -- [**1329**星][1m] [CSS] [undeadsec/socialfish](https://github.com/undeadsec/socialfish) 网络钓鱼培训与信息收集 -- [**1329**星][10m] [rebeyond/behinder](https://github.com/rebeyond/behinder) “冰蝎”动态二进制加密网站管理客户端 -- [**1329**星][1y] [kirikira/vtemplate](https://github.com/kirikira/vtemplate) v2ray的模板们 -- [**1328**星][1y] [C] [madeye/proxydroid](https://github.com/madeye/proxydroid) Global Proxy for Android -- [**1326**星][11d] [C++] [purplei2p/i2pd](https://github.com/purplei2p/i2pd) a full-featured C++ implementation of I2P client -- [**1324**星][2y] [CoffeeScript] [atmos/camo](https://github.com/atmos/camo) all about making insecure assets look secure -- [**1323**星][1y] [Py] [marten4n6/evilosx](https://github.com/marten4n6/evilosx) An evil RAT (Remote Administration Tool) for macOS / OS X. -- [**1322**星][3m] [HTML] [thehive-project/thehive](https://github.com/thehive-project/thehive) a Scalable, Open Source and Free Security Incident Response Platform -- [**1321**星][6m] [Go] [ssllabs/ssllabs-scan](https://github.com/ssllabs/ssllabs-scan) A command-line reference-implementation client for SSL Labs APIs, designed for automated and/or bulk testing. -- [**1321**星][1y] [C++] [rehints/hexrayscodexplorer](https://github.com/rehints/hexrayscodexplorer) 反编译插件, 多功能 +- [**1345**星][25d] [C] [x64dbg/x64dbgpy](https://github.com/x64dbg/x64dbgpy) Automating x64dbg using Python, Snapshots: +- [**1345**星][12d] [Go] [securitywithoutborders/hardentools](https://github.com/securitywithoutborders/hardentools) 禁用许多有危险的Windows功能 +- [**1344**星][23d] [Go] [microcosm-cc/bluemonday](https://github.com/microcosm-cc/bluemonday) a fast golang HTML sanitizer (inspired by the OWASP Java HTML Sanitizer) to scrub user generated content of XSS +- [**1343**星][23d] [Py] [s0md3v/arjun](https://github.com/s0md3v/Arjun) HTTP parameter discovery suite. +- [**1342**星][12m] [C] [luke-jr/bfgminer](https://github.com/luke-jr/bfgminer) Modular ASIC/FPGA miner written in C, featuring overclocking, monitoring, fan speed control and remote interface capabilities. +- [**1342**星][2m] [Go] [davrodpin/mole](https://github.com/davrodpin/mole) cli app to create ssh tunnels +- [**1342**星][1y] [Py] [carmaa/inception](https://github.com/carmaa/inception) 利用基于PCI的DMA实现物理内存的操纵与Hacking,可以攻击FireWire,Thunderbolt,ExpressCard,PC Card和任何其他PCI / PCIe硬件接口 +- [**1341**星][3m] [Py] [maratyszcza/peachpy](https://github.com/maratyszcza/peachpy) x86-64 assembler embedded in Python +- [**1341**星][1y] [XSLT] [api0cradle/lolbas](https://github.com/api0cradle/lolbas) Living Off The Land Binaries And Scripts - (LOLBins and LOLScripts) +- [**1340**星][1y] [kirikira/vtemplate](https://github.com/kirikira/vtemplate) v2ray的模板们 +- [**1340**星][7m] [Py] [feeicn/gsil](https://github.com/feeicn/gsil) GitHub敏感信息泄露监控,几乎实时监控,发送警告 +- [**1339**星][6y] [Perl] [intelisecurelabs/linux_exploit_suggester](https://github.com/InteliSecureLabs/Linux_Exploit_Suggester) Linux Exploit Suggester; based on operating system release number +- [**1338**星][1m] [CSS] [undeadsec/socialfish](https://github.com/undeadsec/socialfish) 网络钓鱼培训与信息收集 +- [**1337**星][1y] [C] [madeye/proxydroid](https://github.com/madeye/proxydroid) Global Proxy for Android +- [**1336**星][3m] [HTML] [thehive-project/thehive](https://github.com/thehive-project/thehive) a Scalable, Open Source and Free Security Incident Response Platform +- [**1335**星][2m] [C++] [mfontanini/libtins](https://github.com/mfontanini/libtins) High-level, multiplatform C++ network packet sniffing and crafting library. +- [**1334**星][4y] [mengskysama/shadowsocks](https://github.com/mengskysama/shadowsocks) A fast tunnel proxy that helps you bypass firewalls +- [**1333**星][1y] [C] [gamelinux/passivedns](https://github.com/gamelinux/passivedns) A network sniffer that logs all DNS server replies for use in a passive DNS setup +- [**1328**星][2d] [C++] [purplei2p/i2pd](https://github.com/purplei2p/i2pd) a full-featured C++ implementation of I2P client +- [**1328**星][1y] [Py] [marten4n6/evilosx](https://github.com/marten4n6/evilosx) An evil RAT (Remote Administration Tool) for macOS / OS X. +- [**1328**星][2y] [CoffeeScript] [atmos/camo](https://github.com/atmos/camo) all about making insecure assets look secure +- [**1327**星][7m] [Go] [ssllabs/ssllabs-scan](https://github.com/ssllabs/ssllabs-scan) A command-line reference-implementation client for SSL Labs APIs, designed for automated and/or bulk testing. +- [**1327**星][3d] [C] [intel/haxm](https://github.com/intel/haxm) Intel 开源的英特尔硬件加速执行管理器,通过硬件辅助的虚拟化引擎,加速 Windows/macOS 主机上的 IA emulation((x86/ x86_64) ) +- [**1327**星][10m] [C#] [cenmrev/v2rayw](https://github.com/cenmrev/v2rayw) GUI for v2ray-core on Windows +- [**1325**星][21d] [C] [dtag-dev-sec/tpotce](https://github.com/dtag-dev-sec/tpotce) 创建多蜜罐平台T-Pot ISO 镜像 +- [**1324**星][1y] [C++] [rehints/hexrayscodexplorer](https://github.com/rehints/hexrayscodexplorer) 反编译插件, 多功能
查看详情 @@ -933,142 +1003,143 @@
-- [**1318**星][2m] [jaredthecoder/awesome-vehicle-security](https://github.com/jaredthecoder/awesome-vehicle-security) -- [**1315**星][1y] [mortenoir1/virtualbox_e1000_0day](https://github.com/mortenoir1/virtualbox_e1000_0day) VirtualBox E1000 Guest-to-Host Escape -- [**1312**星][12d] [C] [oisf/suricata](https://github.com/OISF/suricata) a network IDS, IPS and NSM engine -- [**1311**星][2y] [Py] [worawit/ms17-010](https://github.com/worawit/ms17-010) MS17-010 -- [**1311**星][18d] [C] [intel/haxm](https://github.com/intel/haxm) Intel 开源的英特尔硬件加速执行管理器,通过硬件辅助的虚拟化引擎,加速 Windows/macOS 主机上的 IA emulation((x86/ x86_64) ) -- [**1310**星][3m] [PowerShell] [peewpw/invoke-psimage](https://github.com/peewpw/invoke-psimage) Encodes a PowerShell script in the pixels of a PNG file and generates a oneliner to execute -- [**1310**星][10m] [C] [fancycode/memorymodule](https://github.com/fancycode/memorymodule) Library to load a DLL from memory. -- [**1309**星][10m] [C#] [cenmrev/v2rayw](https://github.com/cenmrev/v2rayw) GUI for v2ray-core on Windows -- [**1305**星][12m] [Py] [xyntax/poc-t](https://github.com/xyntax/poc-t) 脚本调用框架,用于渗透测试中 采集|爬虫|爆破|批量PoC 等需要并发的任务 -- [**1305**星][3m] [Lua] [scipag/vulscan](https://github.com/scipag/vulscan) Nmap 模块,将 Nmap 转化为高级漏洞扫描器 -- [**1305**星][18d] [C] [dtag-dev-sec/tpotce](https://github.com/dtag-dev-sec/tpotce) 创建多蜜罐平台T-Pot ISO 镜像 -- [**1303**星][17d] [Py] [consensys/mythril](https://github.com/ConsenSys/mythril) Security analysis tool for EVM bytecode. Supports smart contracts built for Ethereum, Quorum, Vechain, Roostock, Tron and other EVM-compatible blockchains. -- [**1303**星][15d] [nikitavoloboev/privacy-respecting](https://github.com/nikitavoloboev/privacy-respecting) PrivacyRespecting 服务和软件列表 +- [**1323**星][2d] [Go] [xiaoming2028/freenet](https://github.com/xiaoming2028/freenet) 科学上网/梯子/自由上网/翻墙 SS/SSR/V2Ray/Brook 搭建教程 +- [**1323**星][2m] [jaredthecoder/awesome-vehicle-security](https://github.com/jaredthecoder/awesome-vehicle-security) +- [**1322**星][3d] [C] [oisf/suricata](https://github.com/OISF/suricata) a network IDS, IPS and NSM engine +- [**1319**星][2y] [Py] [worawit/ms17-010](https://github.com/worawit/ms17-010) MS17-010 +- [**1317**星][1y] [mortenoir1/virtualbox_e1000_0day](https://github.com/mortenoir1/virtualbox_e1000_0day) VirtualBox E1000 Guest-to-Host Escape +- [**1316**星][3m] [PS] [peewpw/invoke-psimage](https://github.com/peewpw/invoke-psimage) Encodes a PowerShell script in the pixels of a PNG file and generates a oneliner to execute +- [**1314**星][10m] [C] [fancycode/memorymodule](https://github.com/fancycode/memorymodule) Library to load a DLL from memory. +- [**1311**星][1m] [C++] [shadowsocks/libqtshadowsocks](https://github.com/shadowsocks/libqtshadowsocks) A lightweight and ultra-fast shadowsocks library written in C++14 with Qt framework +- [**1309**星][12m] [Py] [xyntax/poc-t](https://github.com/xyntax/poc-t) 脚本调用框架,用于渗透测试中 采集|爬虫|爆破|批量PoC 等需要并发的任务 +- [**1309**星][3m] [Lua] [scipag/vulscan](https://github.com/scipag/vulscan) Nmap 模块,将 Nmap 转化为高级漏洞扫描器 +- [**1307**星][19d] [Py] [consensys/mythril](https://github.com/ConsenSys/mythril) Security analysis tool for EVM bytecode. Supports smart contracts built for Ethereum, Quorum, Vechain, Roostock, Tron and other EVM-compatible blockchains. +- [**1307**星][27d] [C] [boywhp/fcn](https://github.com/boywhp/fcn) free connect your private network from anywhere +- [**1304**星][17d] [nikitavoloboev/privacy-respecting](https://github.com/nikitavoloboev/privacy-respecting) PrivacyRespecting 服务和软件列表 +- [**1304**星][7d] [C] [cisco-talos/pyrebox](https://github.com/cisco-talos/pyrebox) 逆向沙箱,基于QEMU,Python Scriptable - [**1303**星][4m] [C++] [klee/klee](https://github.com/klee/klee) 基于 LLVM 的 symbolic 虚拟机 -- [**1300**星][18d] [C] [cisco-talos/pyrebox](https://github.com/cisco-talos/pyrebox) 逆向沙箱,基于QEMU,Python Scriptable -- [**1297**星][1y] [Go] [evilsocket/xray](https://github.com/evilsocket/xray) 自动化执行一些信息收集、网络映射的初始化工作 -- [**1293**星][1y] [Shell] [dana-at-cp/backdoor-apk](https://github.com/dana-at-cp/backdoor-apk) backdoor-apk is a shell script that simplifies the process of adding a backdoor to any Android APK file. Users of this shell script should have working knowledge of Linux, Bash, Metasploit, Apktool, the Android SDK, smali, etc. This shell script is provided as-is without warranty of any kind and is intended for educational purposes only. -- [**1291**星][27d] [Java] [android-hacker/exposed](https://github.com/android-hacker/exposed) A library to use Xposed without root or recovery(or modify system image etc..). -- [**1290**星][2y] [Go] [malfunkt/hyperfox](https://github.com/malfunkt/hyperfox) 在局域网上代理和记录 HTTP 和 HTTPs 通信 -- [**1289**星][2m] [C] [traviscross/mtr](https://github.com/traviscross/mtr) Official repository for mtr, a network diagnostic tool -- [**1288**星][4y] [C++] [microsoft/microsoft-pdb](https://github.com/microsoft/microsoft-pdb) Microsoft提供的有关PDB格式的信息 -- [**1287**星][19d] [JS] [icymind/vrouter](https://github.com/icymind/vrouter) 一个基于 VirtualBox 和 openwrt 构建的项目, 旨在实现 macOS / Windows 平台的透明代理. -- [**1284**星][2m] [Py] [virtualabs/btlejack](https://github.com/virtualabs/btlejack) Bluetooth Low Energy Swiss-army knife -- [**1284**星][5m] [JS] [feross/spoof](https://github.com/feross/spoof) Easily spoof your MAC address in macOS, Windows, & Linux! -- [**1278**星][9m] [michalmalik/linux-re-101](https://github.com/michalmalik/linux-re-101) Linux逆向资源收集 -- [**1278**星][4y] [Py] [elvanderb/tcp-32764](https://github.com/elvanderb/tcp-32764) some codes and notes about the backdoor listening on TCP-32764 in linksys WAG200G. -- [**1277**星][10d] [PHP] [friendsofphp/security-advisories](https://github.com/friendsofphp/security-advisories) A database of PHP security advisories -- [**1277**星][27d] [Go] [dreadl0ck/netcap](https://github.com/dreadl0ck/netcap) A framework for secure and scalable network traffic analysis - -- [**1275**星][24d] [Py] [viper-framework/viper](https://github.com/viper-framework/viper) Binary analysis and management framework -- [**1273**星][1m] [Py] [pyauth/pyotp](https://github.com/pyauth/pyotp) Python One-Time Password Library -- [**1273**星][2m] [Py] [codingo/reconnoitre](https://github.com/codingo/reconnoitre) A security tool for multithreaded information gathering and service enumeration whilst building directory structures to store results, along with writing out recommendations for further testing. -- [**1272**星][1y] [JS] [sakurity/securelogin](https://github.com/sakurity/securelogin) 针对网站和App的去中心化的认证协议 -- [**1270**星][2m] [C] [seemoo-lab/nexmon](https://github.com/seemoo-lab/nexmon) The C-based Firmware Patching Framework for Broadcom/Cypress WiFi Chips that enables Monitor Mode, Frame Injection and much more -- [**1270**星][1y] [PowerShell] [dafthack/mailsniper](https://github.com/dafthack/mailsniper) 在Microsoft Exchange环境中搜索邮件中包含的指定内容:密码、insider intel、网络架构信息等 -- [**1270**星][1m] [Py] [bethgelab/foolbox](https://github.com/bethgelab/foolbox) Python toolbox to create adversarial examples that fool neural networks in PyTorch, TensorFlow, Keras, … -- [**1268**星][2m] [Java] [googlearchive/android-runtimepermissions](https://github.com/googlearchive/android-RuntimePermissions) This sample has been deprecated/archived. Check this repo for related samples: -- [**1268**星][1y] [Py] [ethereum/pyethapp](https://github.com/ethereum/pyethapp) -- [**1266**星][2m] [Py] [ganapati/rsactftool](https://github.com/ganapati/rsactftool) RSA攻击工具,主要用于CTF,从弱公钥和/或uncipher数据中回复私钥 -- [**1265**星][9d] [Shell] [firehol/blocklist-ipsets](https://github.com/firehol/blocklist-ipsets) ipsets dynamically updated with firehol's update-ipsets.sh script -- [**1265**星][9d] [Shell] [firehol/blocklist-ipsets](https://github.com/firehol/blocklist-ipsets) ipsets dynamically updated with firehol's update-ipsets.sh script -- [**1262**星][3m] [Go] [solo-io/squash](https://github.com/solo-io/squash) The debugger for microservices -- [**1261**星][3m] [Py] [alessandroz/beroot](https://github.com/alessandroz/beroot) Privilege Escalation Project - Windows / Linux / Mac -- [**1259**星][11m] [Py] [unapibageek/ctfr](https://github.com/unapibageek/ctfr) Abusing Certificate Transparency logs for getting HTTPS websites subdomains. -- [**1255**星][7m] [PHP] [ganlvtech/down_52pojie_cn](https://github.com/ganlvtech/down_52pojie_cn) A single page file explorer that can be hosted on static website. 吾爱破解论坛 爱盘 -- [**1255**星][13d] [C] [aircrack-ng/aircrack-ng](https://github.com/aircrack-ng/aircrack-ng) WiFi security auditing tools suite -- [**1253**星][2y] [JS] [samyk/skyjack](https://github.com/samyk/skyjack) A drone engineered to autonomously seek out, hack, and wirelessly take full control over any other Parrot or 3DR drones within wireless or flying distance, creating an army of zombie drones under your control. -- [**1250**星][1m] [PowerShell] [hak5/bashbunny-payloads](https://github.com/hak5/bashbunny-payloads) The Official Bash Bunny Payload Repository -- [**1248**星][2y] [Py] [vaguileradiaz/tinfoleak](https://github.com/vaguileradiaz/tinfoleak) Twitter 智能分析工具 -- [**1248**星][4m] [JS] [bubenshchykov/ngrok](https://github.com/bubenshchykov/ngrok) Expose your localhost to the web. Node wrapper for ngrok. -- [**1245**星][2m] [Go] [xiaoming2028/freenet](https://github.com/xiaoming2028/freenet) 科学上网/梯子/自由上网/翻墙 SSR/V2Ray/Brook 最全搭建教程 -- [**1245**星][15d] [JS] [archerysec/archerysec](https://github.com/archerysec/archerysec) Centralize Vulnerability Assessment and Management for DevSecOps Team -- [**1244**星][2y] [Objective-C] [krausefx/detect.location](https://github.com/krausefx/detect.location) An easy way to access the user's iOS location data without actually having access -- [**1242**星][4y] [firesuncn/bluelotus_xssreceiver](https://github.com/firesuncn/bluelotus_xssreceiver) XSS平台 CTF工具 Web安全工具 -- [**1242**星][1m] [Vue] [chaitin/passionfruit](https://github.com/chaitin/passionfruit) iOSapp 黑盒评估工具。功能丰富,自带基于web的 GUI +- [**1300**星][1y] [Shell] [dana-at-cp/backdoor-apk](https://github.com/dana-at-cp/backdoor-apk) backdoor-apk is a shell script that simplifies the process of adding a backdoor to any Android APK file. Users of this shell script should have working knowledge of Linux, Bash, Metasploit, Apktool, the Android SDK, smali, etc. This shell script is provided as-is without warranty of any kind and is intended for educational purposes only. +- [**1299**星][6d] [Go] [hacklcx/hfish](https://github.com/hacklcx/hfish) 扩展企业安全测试主动诱导型开源蜜罐框架系统,记录黑客攻击手段 +- [**1298**星][1y] [Go] [evilsocket/xray](https://github.com/evilsocket/xray) 自动化执行一些信息收集、网络映射的初始化工作 +- [**1293**星][4y] [C++] [microsoft/microsoft-pdb](https://github.com/microsoft/microsoft-pdb) Microsoft提供的有关PDB格式的信息 +- [**1293**星][5m] [JS] [feross/spoof](https://github.com/feross/spoof) Easily spoof your MAC address in macOS, Windows, & Linux! +- [**1293**星][29d] [Java] [android-hacker/exposed](https://github.com/android-hacker/exposed) A library to use Xposed without root or recovery(or modify system image etc..). +- [**1291**星][6d] [C] [traviscross/mtr](https://github.com/traviscross/mtr) Official repository for mtr, a network diagnostic tool +- [**1291**星][2y] [Go] [malfunkt/hyperfox](https://github.com/malfunkt/hyperfox) 在局域网上代理和记录 HTTP 和 HTTPs 通信 +- [**1289**星][2m] [Py] [virtualabs/btlejack](https://github.com/virtualabs/btlejack) Bluetooth Low Energy Swiss-army knife +- [**1289**星][21d] [JS] [icymind/vrouter](https://github.com/icymind/vrouter) 一个基于 VirtualBox 和 openwrt 构建的项目, 旨在实现 macOS / Windows 平台的透明代理. +- [**1285**星][12d] [PHP] [friendsofphp/security-advisories](https://github.com/friendsofphp/security-advisories) A database of PHP security advisories +- [**1283**星][9m] [michalmalik/linux-re-101](https://github.com/michalmalik/linux-re-101) Linux逆向资源收集 +- [**1283**星][2m] [Py] [codingo/reconnoitre](https://github.com/codingo/reconnoitre) A security tool for multithreaded information gathering and service enumeration whilst building directory structures to store results, along with writing out recommendations for further testing. +- [**1279**星][2m] [C] [seemoo-lab/nexmon](https://github.com/seemoo-lab/nexmon) The C-based Firmware Patching Framework for Broadcom/Cypress WiFi Chips that enables Monitor Mode, Frame Injection and much more +- [**1279**星][9m] [Go] [perlin-network/noise](https://github.com/perlin-network/noise) A decentralized P2P networking stack written in Go. +- [**1279**星][4y] [Py] [elvanderb/tcp-32764](https://github.com/elvanderb/tcp-32764) some codes and notes about the backdoor listening on TCP-32764 in linksys WAG200G. +- [**1278**星][26d] [Py] [viper-framework/viper](https://github.com/viper-framework/viper) Binary analysis and management framework +- [**1277**星][4d] [Shell] [firehol/blocklist-ipsets](https://github.com/firehol/blocklist-ipsets) ipsets dynamically updated with firehol's update-ipsets.sh script +- [**1277**星][8d] [Py] [pyauth/pyotp](https://github.com/pyauth/pyotp) Python One-Time Password Library +- [**1277**星][4d] [Shell] [firehol/blocklist-ipsets](https://github.com/firehol/blocklist-ipsets) ipsets dynamically updated with firehol's update-ipsets.sh script +- [**1277**星][29d] [Go] [dreadl0ck/netcap](https://github.com/dreadl0ck/netcap) A framework for secure and scalable network traffic analysis - +- [**1277**星][1m] [Py] [bethgelab/foolbox](https://github.com/bethgelab/foolbox) Python toolbox to create adversarial examples that fool neural networks in PyTorch, TensorFlow, Keras, … +- [**1273**星][1y] [PS] [dafthack/mailsniper](https://github.com/dafthack/mailsniper) 在Microsoft Exchange环境中搜索邮件中包含的指定内容:密码、insider intel、网络架构信息等 +- [**1271**星][1y] [JS] [sakurity/securelogin](https://github.com/sakurity/securelogin) 针对网站和App的去中心化的认证协议 +- [**1271**星][2m] [Py] [ganapati/rsactftool](https://github.com/ganapati/rsactftool) RSA攻击工具,主要用于CTF,从弱公钥和/或uncipher数据中回复私钥 +- [**1270**星][3m] [Py] [alessandroz/beroot](https://github.com/alessandroz/beroot) Privilege Escalation Project - Windows / Linux / Mac +- [**1269**星][3m] [Java] [googlearchive/android-runtimepermissions](https://github.com/googlearchive/android-RuntimePermissions) This sample has been deprecated/archived. Check this repo for related samples: +- [**1269**星][3m] [Go] [solo-io/squash](https://github.com/solo-io/squash) The debugger for microservices +- [**1269**星][1y] [Py] [ethereum/pyethapp](https://github.com/ethereum/pyethapp) +- [**1267**星][7m] [PHP] [ganlvtech/down_52pojie_cn](https://github.com/ganlvtech/down_52pojie_cn) A single page file explorer that can be hosted on static website. 吾爱破解论坛 爱盘 +- [**1267**星][2d] [C] [aircrack-ng/aircrack-ng](https://github.com/aircrack-ng/aircrack-ng) WiFi security auditing tools suite +- [**1263**星][4d] [JS] [forwardemail/free-email-forwarding](https://github.com/forwardemail/free-email-forwarding) +- [**1261**星][11m] [Py] [unapibageek/ctfr](https://github.com/unapibageek/ctfr) Abusing Certificate Transparency logs for getting HTTPS websites subdomains. +- [**1260**星][12m] [PHP] [you2php/delete](https://github.com/you2php/delete) (迫于压力,本项目停止维护,请尽快fork代码。1月1日之后删除项目)[免翻墙工具]A free and open-source youtube video proxy script [Written in PHP] +- [**1256**星][1m] [PS] [hak5/bashbunny-payloads](https://github.com/hak5/bashbunny-payloads) The Official Bash Bunny Payload Repository +- [**1255**星][2y] [JS] [samyk/skyjack](https://github.com/samyk/skyjack) A drone engineered to autonomously seek out, hack, and wirelessly take full control over any other Parrot or 3DR drones within wireless or flying distance, creating an army of zombie drones under your control. +- [**1253**星][4d] [JS] [archerysec/archerysec](https://github.com/archerysec/archerysec) Centralize Vulnerability Assessment and Management for DevSecOps Team +- [**1253**星][4m] [JS] [bubenshchykov/ngrok](https://github.com/bubenshchykov/ngrok) Expose your localhost to the web. Node wrapper for ngrok. +- [**1251**星][3d] [Shell] [mitchellkrogza/nginx-ultimate-bad-bot-blocker](https://github.com/mitchellkrogza/nginx-ultimate-bad-bot-blocker) Nginx Block Bad Bots, Spam Referrer Blocker, Vulnerability Scanners, User-Agents, Malware, Adware, Ransomware, Malicious Sites, with anti-DDOS, Wordpress Theme Detector Blocking and Fail2Ban Jail for Repeat Offenders +- [**1250**星][2y] [Py] [vaguileradiaz/tinfoleak](https://github.com/vaguileradiaz/tinfoleak) Twitter 智能分析工具 +- [**1247**星][1m] [Vue] [chaitin/passionfruit](https://github.com/chaitin/passionfruit) iOSapp 黑盒评估工具。功能丰富,自带基于web的 GUI +- [**1244**星][3m] [michalmalik/osx-re-101](https://github.com/michalmalik/osx-re-101) OSX/iOS逆向资源收集 +- [**1244**星][2y] [ObjC] [krausefx/detect.location](https://github.com/krausefx/detect.location) An easy way to access the user's iOS location data without actually having access +- [**1243**星][3m] [Shell] [rootsongjc/kubernetes-vagrant-centos-cluster](https://github.com/rootsongjc/kubernetes-vagrant-centos-cluster) Setting up a distributed Kubernetes cluster along with Istio service mesh locally with Vagrant and VirtualBox, only PoC or Demo use. +- [**1243**星][10m] [C] [a0rtega/pafish](https://github.com/a0rtega/pafish) Pafish is a demonstration tool that employs several techniques to detect sandboxes and analysis environments in the same way as malware families do. +- [**1242**星][9d] [Py] [thekingofduck/fuzzdicts](https://github.com/thekingofduck/fuzzdicts) Web Pentesting Fuzz 字典,一个就够了。 +- [**1241**星][4y] [firesuncn/bluelotus_xssreceiver](https://github.com/firesuncn/bluelotus_xssreceiver) XSS平台 CTF工具 Web安全工具 - [**1241**星][1y] [Ruby] [eliotsykes/rails-security-checklist](https://github.com/eliotsykes/rails-security-checklist) -- [**1240**星][10m] [C] [a0rtega/pafish](https://github.com/a0rtega/pafish) Pafish is a demonstration tool that employs several techniques to detect sandboxes and analysis environments in the same way as malware families do. -- [**1239**星][2m] [michalmalik/osx-re-101](https://github.com/michalmalik/osx-re-101) OSX/iOS逆向资源收集 -- [**1235**星][1m] [Go] [hacklcx/hfish](https://github.com/hacklcx/hfish) 扩展企业安全测试主动诱导型开源蜜罐框架系统,记录黑客攻击手段 -- [**1235**星][2m] [Go] [google/martian](https://github.com/google/martian) Martian is a library for building custom HTTP/S proxies -- [**1232**星][3m] [Shell] [rootsongjc/kubernetes-vagrant-centos-cluster](https://github.com/rootsongjc/kubernetes-vagrant-centos-cluster) Setting up a distributed Kubernetes cluster along with Istio service mesh locally with Vagrant and VirtualBox, only PoC or Demo use. -- [**1231**星][3y] [Py] [desaster/kippo](https://github.com/desaster/kippo) Kippo - SSH Honeypot -- [**1230**星][7d] [Shell] [mitchellkrogza/nginx-ultimate-bad-bot-blocker](https://github.com/mitchellkrogza/nginx-ultimate-bad-bot-blocker) Nginx Block Bad Bots, Spam Referrer Blocker, Vulnerability Scanners, User-Agents, Malware, Adware, Ransomware, Malicious Sites, with anti-DDOS, Wordpress Theme Detector Blocking and Fail2Ban Jail for Repeat Offenders -- [**1230**星][5m] [chalker/notes](https://github.com/chalker/notes) Some public notes -- [**1228**星][1y] [Kotlin] [gh0u1l5/wechatspellbook](https://github.com/gh0u1l5/wechatspellbook) 一个使用Kotlin编写的开源微信插件框架,底层需要 Xposed 或 VirtualXposed 等Hooking框架的支持,而顶层可以轻松对接Java、Kotlin、Scala等JVM系语言。让程序员能够在几分钟内编写出简单的微信插件,随意揉捏微信的内部逻辑。 -- [**1228**星][8m] [Py] [flipkart-incubator/astra](https://github.com/flipkart-incubator/astra) 自动化的REST API安全测试脚本 -- [**1224**星][1m] [C] [datatheorem/trustkit](https://github.com/datatheorem/trustkit) Easy SSL pinning validation and reporting for iOS, macOS, tvOS and watchOS. -- [**1223**星][3y] [CoffeeScript] [shadowsocks/shadowsocks-nodejs](https://github.com/shadowsocks/shadowsocks-nodejs) -- [**1222**星][3y] [C] [tsudakageyu/minhook](https://github.com/tsudakageyu/minhook) The Minimalistic x86/x64 API Hooking Library for Windows -- [**1222**星][27d] [C++] [nasa-sw-vnv/ikos](https://github.com/nasa-sw-vnv/ikos) Static analyzer for C/C++ based on the theory of Abstract Interpretation. -- [**1222**星][1y] [Py] [danmcinerney/net-creds](https://github.com/danmcinerney/net-creds) Sniffs sensitive data from interface or pcap -- [**1220**星][1y] [Go] [cloudflare/redoctober](https://github.com/cloudflare/redoctober) Go server for two-man rule style file encryption and decryption. -- [**1219**星][5y] [cure53/xsschallengewiki](https://github.com/cure53/XSSChallengeWiki) Welcome to the XSS Challenge Wiki! -- [**1219**星][4m] [Py] [owtf/owtf](https://github.com/owtf/owtf) 进攻性 Web 测试框架。着重于 OWASP + PTES,尝试统合强大的工具,提高渗透测试的效率。大部分以Python 编写 -- [**1218**星][11d] [Py] [google/timesketch](https://github.com/google/timesketch) Collaborative forensic timeline analysis -- [**1218**星][26d] [Java] [find-sec-bugs/find-sec-bugs](https://github.com/find-sec-bugs/find-sec-bugs) The SpotBugs plugin for security audits of Java web applications and Android applications. (Also work with Kotlin, Groovy and Scala projects) -- [**1218**星][5y] [cure53/xsschallengewiki](https://github.com/cure53/xsschallengewiki) Welcome to the XSS Challenge Wiki! -- [**1217**星][1y] [C#] [cn33liz/p0wnedshell](https://github.com/cn33liz/p0wnedshell) PowerShell Runspace Post Exploitation Toolkit -- [**1216**星][26d] [Go] [jsha/minica](https://github.com/jsha/minica) minica is a small, simple CA intended for use in situations where the CA operator also operates each host where a certificate will be used. -- [**1212**星][10d] [C] [dynamorio/dynamorio](https://github.com/dynamorio/dynamorio) Dynamic Instrumentation Tool Platform -- [**1207**星][8d] [JS] [jpcertcc/logontracer](https://github.com/jpcertcc/logontracer) 通过可视化和分析Windows事件日志来调查恶意的Windows登录 -- [**1205**星][3m] [Java] [javiersantos/piracychecker](https://github.com/javiersantos/piracychecker) An Android library that prevents your app from being pirated / cracked using Google Play Licensing (LVL), APK signature protection and more. API 14+ required. -- [**1204**星][7d] [Objective-C] [onionbrowser/onionbrowser](https://github.com/onionbrowser/onionbrowser) An open-source, privacy-enhancing web browser for iOS, utilizing the Tor anonymity network -- [**1204**星][3m] [JS] [davidbau/seedrandom](https://github.com/davidbau/seedrandom) seeded random number generator for Javascript -- [**1203**星][30d] [Py] [codingo/nosqlmap](https://github.com/codingo/NoSQLMap) Automated NoSQL database enumeration and web application exploitation tool. -- [**1201**星][7d] [Java] [linkedin/dexmaker](https://github.com/linkedin/dexmaker) A utility for doing compile or runtime code generation targeting Android's Dalvik VM -- [**1200**星][3m] [C] [droe/sslsplit](https://github.com/droe/sslsplit) 透明SSL/TLS拦截 -- [**1199**星][1y] [felixgr/secure-ios-app-dev](https://github.com/felixgr/secure-ios-app-dev) iOSApp 最常见漏洞收集 -- [**1198**星][24d] [Py] [thekingofduck/fuzzdicts](https://github.com/thekingofduck/fuzzdicts) Web Pentesting Fuzz 字典,一个就够了。 -- [**1196**星][1y] [Go] [rancher/convoy](https://github.com/rancher/convoy) A Docker volume plugin, managing persistent container volumes. -- [**1194**星][2y] [C] [saminiir/level-ip](https://github.com/saminiir/level-ip) a Linux userspace TCP/IP stack, implemented with TUN/TAP devices. -- [**1194**星][7m] [riusksk/secbook](https://github.com/riusksk/secbook) 信息安全从业者书单推荐 -- [**1193**星][18d] [Py] [cve-search/cve-search](https://github.com/cve-search/cve-search) 导入CVE/CPE 到本地 MongoDB 数据库,以便后续在本地进行搜索和处理 -- [**1192**星][17d] [YARA] [horsicq/detect-it-easy](https://github.com/horsicq/detect-it-easy) Program for determining types of files for Windows, Linux and MacOS. -- [**1191**星][6y] [gdbinit/gdbinit](https://github.com/gdbinit/gdbinit) Gdbinit for OS X, iOS and others - x86, x86_64 and ARM -- [**1191**星][9m] [C] [f0rb1dd3n/reptile](https://github.com/f0rb1dd3n/reptile) LKM Linux rootkit -- [**1190**星][3m] [Py] [jtesta/ssh-mitm](https://github.com/jtesta/ssh-mitm) SSH 中间人攻击工具 +- [**1240**星][2m] [Go] [google/martian](https://github.com/google/martian) Martian is a library for building custom HTTP/S proxies +- [**1238**星][1y] [Kotlin] [gh0u1l5/wechatspellbook](https://github.com/gh0u1l5/wechatspellbook) 一个使用Kotlin编写的开源微信插件框架,底层需要 Xposed 或 VirtualXposed 等Hooking框架的支持,而顶层可以轻松对接Java、Kotlin、Scala等JVM系语言。让程序员能够在几分钟内编写出简单的微信插件,随意揉捏微信的内部逻辑。 +- [**1233**星][3y] [Py] [desaster/kippo](https://github.com/desaster/kippo) Kippo - SSH Honeypot +- [**1230**星][8m] [Py] [flipkart-incubator/astra](https://github.com/flipkart-incubator/astra) 自动化的REST API安全测试脚本 +- [**1229**星][5m] [chalker/notes](https://github.com/chalker/notes) Some public notes +- [**1228**星][3y] [C] [tsudakageyu/minhook](https://github.com/tsudakageyu/minhook) The Minimalistic x86/x64 API Hooking Library for Windows +- [**1228**星][3d] [C++] [nasa-sw-vnv/ikos](https://github.com/nasa-sw-vnv/ikos) Static analyzer for C/C++ based on the theory of Abstract Interpretation. +- [**1227**星][6d] [C] [datatheorem/trustkit](https://github.com/datatheorem/trustkit) Easy SSL pinning validation and reporting for iOS, macOS, tvOS and watchOS. +- [**1227**星][1y] [Py] [danmcinerney/net-creds](https://github.com/danmcinerney/net-creds) Sniffs sensitive data from interface or pcap +- [**1225**星][28d] [Java] [find-sec-bugs/find-sec-bugs](https://github.com/find-sec-bugs/find-sec-bugs) The SpotBugs plugin for security audits of Java web applications and Android applications. (Also work with Kotlin, Groovy and Scala projects) +- [**1224**星][3y] [CoffeeScript] [shadowsocks/shadowsocks-nodejs](https://github.com/shadowsocks/shadowsocks-nodejs) +- [**1223**星][28d] [Go] [jsha/minica](https://github.com/jsha/minica) minica is a small, simple CA intended for use in situations where the CA operator also operates each host where a certificate will be used. +- [**1222**星][5y] [cure53/xsschallengewiki](https://github.com/cure53/XSSChallengeWiki) Welcome to the XSS Challenge Wiki! +- [**1222**星][4m] [Py] [owtf/owtf](https://github.com/owtf/owtf) 进攻性 Web 测试框架。着重于 OWASP + PTES,尝试统合强大的工具,提高渗透测试的效率。大部分以Python 编写 +- [**1222**星][5y] [cure53/xsschallengewiki](https://github.com/cure53/xsschallengewiki) Welcome to the XSS Challenge Wiki! +- [**1221**星][5d] [Py] [harismuneer/ultimate-facebook-scraper](https://github.com/harismuneer/ultimate-facebook-scraper) +- [**1221**星][13d] [Py] [google/timesketch](https://github.com/google/timesketch) Collaborative forensic timeline analysis +- [**1221**星][1y] [Go] [cloudflare/redoctober](https://github.com/cloudflare/redoctober) Go server for two-man rule style file encryption and decryption. +- [**1220**星][1y] [C#] [cn33liz/p0wnedshell](https://github.com/cn33liz/p0wnedshell) PowerShell Runspace Post Exploitation Toolkit +- [**1215**星][6d] [C] [dynamorio/dynamorio](https://github.com/dynamorio/dynamorio) Dynamic Instrumentation Tool Platform +- [**1213**星][10d] [JS] [jpcertcc/logontracer](https://github.com/jpcertcc/logontracer) 通过可视化和分析Windows事件日志来调查恶意的Windows登录 +- [**1209**星][1m] [Py] [codingo/nosqlmap](https://github.com/codingo/NoSQLMap) Automated NoSQL database enumeration and web application exploitation tool. +- [**1208**星][6d] [ObjC] [onionbrowser/onionbrowser](https://github.com/onionbrowser/onionbrowser) An open-source, privacy-enhancing web browser for iOS, utilizing the Tor anonymity network +- [**1207**星][7m] [riusksk/secbook](https://github.com/riusksk/secbook) 信息安全从业者书单推荐 +- [**1206**星][7d] [Java] [linkedin/dexmaker](https://github.com/linkedin/dexmaker) A utility for doing compile or runtime code generation targeting Android's Dalvik VM +- [**1206**星][3m] [Java] [javiersantos/piracychecker](https://github.com/javiersantos/piracychecker) An Android library that prevents your app from being pirated / cracked using Google Play Licensing (LVL), APK signature protection and more. API 14+ required. +- [**1206**星][3m] [JS] [davidbau/seedrandom](https://github.com/davidbau/seedrandom) seeded random number generator for Javascript +- [**1205**星][4d] [YARA] [horsicq/detect-it-easy](https://github.com/horsicq/detect-it-easy) Program for determining types of files for Windows, Linux and MacOS. +- [**1204**星][5d] [dweinstein/awesome-frida](https://github.com/dweinstein/awesome-frida) frida 资源列表 +- [**1202**星][1y] [felixgr/secure-ios-app-dev](https://github.com/felixgr/secure-ios-app-dev) iOSApp 最常见漏洞收集 +- [**1202**星][3m] [C] [droe/sslsplit](https://github.com/droe/sslsplit) 透明SSL/TLS拦截 +- [**1201**星][2y] [C] [saminiir/level-ip](https://github.com/saminiir/level-ip) a Linux userspace TCP/IP stack, implemented with TUN/TAP devices. +- [**1201**星][3m] [C] [dgiese/dustcloud](https://github.com/dgiese/dustcloud) Xiaomi Smart Home Device Reverse Engineering and Hacking +- [**1201**星][23d] [Py] [achillean/shodan-python](https://github.com/achillean/shodan-python) The official Python library for Shodan +- [**1200**星][11m] [JS] [mame82/p4wnp1_aloa](https://github.com/mame82/p4wnp1_aloa) 将 Rapsberry Pi Zero W 转变成灵活的渗透平台 +- [**1198**星][1y] [Go] [rancher/convoy](https://github.com/rancher/convoy) A Docker volume plugin, managing persistent container volumes. +- [**1198**星][8m] [joe-shenouda/awesome-cyber-skills](https://github.com/joe-shenouda/awesome-cyber-skills) A curated list of hacking environments where you can train your cyber skills legally and safely +- [**1198**星][20d] [Py] [cve-search/cve-search](https://github.com/cve-search/cve-search) 导入CVE/CPE 到本地 MongoDB 数据库,以便后续在本地进行搜索和处理 +- [**1197**星][9m] [C] [f0rb1dd3n/reptile](https://github.com/f0rb1dd3n/reptile) LKM Linux rootkit +- [**1192**星][1m] [Go] [smallstep/certificates](https://github.com/smallstep/certificates) 私有的证书颁发机构(X.509和SSH)和ACME服务器,用于安全的自动证书管理,因此您可以在SSH和SSO处使用TLS +- [**1192**星][7y] [Py] [mothran/mongol](https://github.com/mothran/mongol) A simple python tool to pinpoint the IP addresses of machines working for the Great Firewall of China. +- [**1192**星][6y] [gdbinit/gdbinit](https://github.com/gdbinit/gdbinit) Gdbinit for OS X, iOS and others - x86, x86_64 and ARM +- [**1191**星][3m] [Py] [jtesta/ssh-mitm](https://github.com/jtesta/ssh-mitm) SSH 中间人攻击工具 - [**1189**星][3y] [Roff] [matiasinsaurralde/facebook-tunnel](https://github.com/matiasinsaurralde/facebook-tunnel) Tunneling Internet traffic over Facebook chat. -- [**1189**星][8m] [joe-shenouda/awesome-cyber-skills](https://github.com/joe-shenouda/awesome-cyber-skills) A curated list of hacking environments where you can train your cyber skills legally and safely -- [**1188**星][4m] [dweinstein/awesome-frida](https://github.com/dweinstein/awesome-frida) frida 资源列表 -- [**1187**星][7y] [Py] [mothran/mongol](https://github.com/mothran/mongol) A simple python tool to pinpoint the IP addresses of machines working for the Great Firewall of China. -- [**1186**星][21d] [Py] [achillean/shodan-python](https://github.com/achillean/shodan-python) The official Python library for Shodan -- [**1185**星][14d] [C] [luigirizzo/netmap](https://github.com/luigirizzo/netmap) an framework for very fast packet I/O from userspace -- [**1182**星][3m] [C] [dgiese/dustcloud](https://github.com/dgiese/dustcloud) Xiaomi Smart Home Device Reverse Engineering and Hacking -- [**1182**星][10m] [C] [blechschmidt/massdns](https://github.com/blechschmidt/massdns) A high-performance DNS stub resolver for bulk lookups and reconnaissance (subdomain enumeration) -- [**1180**星][2y] [Java] [weexteam/hackernews-app-powered-by-apache-weex](https://github.com/weexteam/hackernews-App-powered-by-Apache-Weex) 首个使用 Weex 和 Vue 开发的 Hacker News 原生应用。 -- [**1180**星][7m] [ssrarchive/shadowsocks-rss](https://github.com/ssrarchive/shadowsocks-rss) Shadowsocksr project backup -- [**1180**星][12d] [Py] [lyft/cartography](https://github.com/lyft/cartography) Cartography is a Python tool that consolidates infrastructure assets and the relationships between them in an intuitive graph view powered by a Neo4j database. -- [**1179**星][2y] [C] [mubix/post-exploitation](https://github.com/mubix/post-exploitation) post-exploitation工具收集 -- [**1175**星][1m] [Go] [smallstep/certificates](https://github.com/smallstep/certificates) 私有的证书颁发机构(X.509和SSH)和ACME服务器,用于安全的自动证书管理,因此您可以在SSH和SSO处使用TLS -- [**1174**星][2m] [jadagates/shadowsocksbio](https://github.com/jadagates/shadowsocksbio) 记录一下SS的前世今生,以及一个简单的教程总结 -- [**1174**星][5y] [Py] [hackappcom/ibrute](https://github.com/hackappcom/ibrute) AppleID bruteforce p0c -- [**1174**星][23d] [Shell] [anudeepnd/whitelist](https://github.com/anudeepnd/whitelist) A simple tool to add commonly white listed domains to your Pi-Hole setup. -- [**1172**星][12d] [C] [the-tcpdump-group/tcpdump](https://github.com/the-tcpdump-group/tcpdump) the TCPdump network dissector -- [**1165**星][20d] [Go] [genuinetools/reg](https://github.com/genuinetools/reg) Docker registry v2 command line client and repo listing generator with security checks. -- [**1165**星][26d] [Py] [cujanovic/ssrf-testing](https://github.com/cujanovic/ssrf-testing) SSRF (Server Side Request Forgery) testing resources -- [**1163**星][15d] [Py] [programa-stic/barf-project](https://github.com/programa-stic/barf-project) A multiplatform open source Binary Analysis and Reverse engineering Framework -- [**1158**星][6y] [PHP] [lucb1e/cookielesscookies](https://github.com/lucb1e/cookielesscookies) Demo of tracking using etags instead of cookies (or localstorage or anything else) -- [**1155**星][4m] [C] [skeeto/endlessh](https://github.com/skeeto/endlessh) SSH tarpit that slowly sends an endless banner -- [**1155**星][11m] [JS] [mame82/p4wnp1_aloa](https://github.com/mame82/p4wnp1_aloa) 将 Rapsberry Pi Zero W 转变成灵活的渗透平台 -- [**1154**星][3m] [Go] [mozilla/mig](https://github.com/mozilla/mig) 分布式实时数字取证和研究平台 -- [**1152**星][20d] [m4ll0k/awesome-hacking-tools](https://github.com/m4ll0k/awesome-hacking-tools) Awesome Hacking Tools -- [**1151**星][8d] [JS] [lirantal/is-website-vulnerable](https://github.com/lirantal/is-website-vulnerable) finds publicly known security vulnerabilities in a website's frontend JavaScript libraries -- [**1151**星][12d] [Py] [p4-team/ctf](https://github.com/p4-team/ctf) Ctf solutions from p4 team -- [**1150**星][3m] [Go] [shadowsocks/v2ray-plugin](https://github.com/shadowsocks/v2ray-plugin) A SIP003 plugin based on v2ray -- [**1150**星][24d] [JS] [alonemonkey/frida-ios-dump](https://github.com/alonemonkey/frida-ios-dump) pull decrypted ipa from jailbreak device -- [**1149**星][7m] [Py] [mebus/cupp](https://github.com/mebus/cupp) Common User Passwords Profiler (CUPP) -- [**1145**星][1y] [HTML] [nsacyber/windows-secure-host-baseline](https://github.com/nsacyber/Windows-Secure-Host-Baseline) Windows 10和Windows Server 2016 DoD 安全主机基准设置的配置指南 -- [**1145**星][13d] [Go] [pusher/oauth2_proxy](https://github.com/pusher/oauth2_proxy) A reverse proxy that provides authentication with Google, Github or other providers. -- [**1142**星][4m] [C++] [cgdb/cgdb](https://github.com/cgdb/cgdb) Console front-end to the GNU debugger -- [**1141**星][3y] [PowerShell] [powershellempire/powertools](https://github.com/powershellempire/powertools) PowerTools is a collection of PowerShell projects with a focus on offensive operations. -- [**1140**星][2m] [HTML] [cure53/httpleaks](https://github.com/cure53/httpleaks) HTTPLeaks - All possible ways, a website can leak HTTP requests -- [**1138**星][11m] [Py] [certsocietegenerale/fir](https://github.com/certsocietegenerale/fir) Fast Incident Response -- [**1137**星][1m] [TypeScript] [mgechev/ngrev](https://github.com/mgechev/ngrev) Tool for reverse engineering of Angular applications -- [**1136**星][7m] [hikariobfuscator/hikari](https://github.com/HikariObfuscator/Hikari) LLVM Obfuscator -- [**1136**星][2y] [Py] [hackathonhackers/personal-sites](https://github.com/hackathonhackers/personal-sites) List of Hackathon Hackers' personal sites. -- [**1134**星][20d] [Py] [13o-bbr-bbq/machine_learning_security](https://github.com/13o-bbr-bbq/machine_learning_security) 机器学习与安全的几个Topic +- [**1189**星][10m] [C] [blechschmidt/massdns](https://github.com/blechschmidt/massdns) A high-performance DNS stub resolver for bulk lookups and reconnaissance (subdomain enumeration) +- [**1189**星][25d] [Shell] [anudeepnd/whitelist](https://github.com/anudeepnd/whitelist) A simple tool to add commonly white listed domains to your Pi-Hole setup. +- [**1188**星][2m] [jadagates/shadowsocksbio](https://github.com/jadagates/shadowsocksbio) 记录一下SS的前世今生,以及一个简单的教程总结 +- [**1187**星][6d] [Py] [lyft/cartography](https://github.com/lyft/cartography) Cartography is a Python tool that consolidates infrastructure assets and the relationships between them in an intuitive graph view powered by a Neo4j database. +- [**1186**星][3d] [C] [luigirizzo/netmap](https://github.com/luigirizzo/netmap) an framework for very fast packet I/O from userspace +- [**1185**星][2y] [C] [mubix/post-exploitation](https://github.com/mubix/post-exploitation) post-exploitation工具收集 +- [**1181**星][8d] [C] [the-tcpdump-group/tcpdump](https://github.com/the-tcpdump-group/tcpdump) the TCPdump network dissector +- [**1179**星][2y] [Java] [weexteam/hackernews-app-powered-by-apache-weex](https://github.com/weexteam/hackernews-App-powered-by-Apache-Weex) 首个使用 Weex 和 Vue 开发的 Hacker News 原生应用。 +- [**1178**星][4m] [C] [ambrop72/badvpn](https://github.com/ambrop72/badvpn) NCD scripting language, tun2socks proxifier, P2P VPN +- [**1177**星][7m] [ssrarchive/shadowsocks-rss](https://github.com/ssrarchive/shadowsocks-rss) Shadowsocksr project backup +- [**1175**星][5y] [Py] [hackappcom/ibrute](https://github.com/hackappcom/ibrute) AppleID bruteforce p0c +- [**1174**星][28d] [Py] [cujanovic/ssrf-testing](https://github.com/cujanovic/ssrf-testing) SSRF (Server Side Request Forgery) testing resources +- [**1173**星][3m] [Go] [shadowsocks/v2ray-plugin](https://github.com/shadowsocks/v2ray-plugin) A SIP003 plugin based on v2ray +- [**1171**星][6d] [JS] [lirantal/is-website-vulnerable](https://github.com/lirantal/is-website-vulnerable) finds publicly known security vulnerabilities in a website's frontend JavaScript libraries +- [**1168**星][22d] [Go] [genuinetools/reg](https://github.com/genuinetools/reg) Docker registry v2 command line client and repo listing generator with security checks. +- [**1166**星][1m] [Go] [shawn1m/overture](https://github.com/shawn1m/overture) A customized DNS forwarder written in Go +- [**1165**星][26d] [JS] [alonemonkey/frida-ios-dump](https://github.com/alonemonkey/frida-ios-dump) pull decrypted ipa from jailbreak device +- [**1164**星][17d] [Py] [programa-stic/barf-project](https://github.com/programa-stic/barf-project) A multiplatform open source Binary Analysis and Reverse engineering Framework +- [**1164**星][4y] [Ruby] [cryptosphere/cryptosphere](https://github.com/cryptosphere/cryptosphere) Encrypted peer-to-peer web application platform for decentralized, privacy-preserving applications +- [**1162**星][4m] [C] [skeeto/endlessh](https://github.com/skeeto/endlessh) SSH tarpit that slowly sends an endless banner +- [**1162**星][15d] [Go] [pusher/oauth2_proxy](https://github.com/pusher/oauth2_proxy) A reverse proxy that provides authentication with Google, Github or other providers. +- [**1162**星][1m] [TS] [mgechev/ngrev](https://github.com/mgechev/ngrev) Tool for reverse engineering of Angular applications +- [**1159**星][6y] [PHP] [lucb1e/cookielesscookies](https://github.com/lucb1e/cookielesscookies) Demo of tracking using etags instead of cookies (or localstorage or anything else) +- [**1158**星][22d] [m4ll0k/awesome-hacking-tools](https://github.com/m4ll0k/awesome-hacking-tools) Awesome Hacking Tools +- [**1156**星][7d] [Py] [p4-team/ctf](https://github.com/p4-team/ctf) Ctf solutions from p4 team +- [**1155**星][3m] [Go] [mozilla/mig](https://github.com/mozilla/mig) 分布式实时数字取证和研究平台 +- [**1151**星][8m] [Py] [mebus/cupp](https://github.com/mebus/cupp) Common User Passwords Profiler (CUPP) +- [**1150**星][1y] [HTML] [nsacyber/windows-secure-host-baseline](https://github.com/nsacyber/Windows-Secure-Host-Baseline) Windows 10和Windows Server 2016 DoD 安全主机基准设置的配置指南 +- [**1147**星][1m] [Jupyter Notebook] [ibm/adversarial-robustness-toolbox](https://github.com/ibm/adversarial-robustness-toolbox) Python library for adversarial machine learning, attacks and defences for neural networks, logistic regression, decision trees, SVM, gradient boosted trees, Gaussian processes and more with multiple framework support +- [**1145**星][22d] [Py] [13o-bbr-bbq/machine_learning_security](https://github.com/13o-bbr-bbq/machine_learning_security) 机器学习与安全的几个Topic - [Security_and_MachineLearning](https://github.com/13o-bbr-bbq/machine_learning_security/tree/master/Security_and_MachineLearning) 网络安全与机器学习课程 - [Vulnerabilities_of_ML](https://github.com/13o-bbr-bbq/machine_learning_security/blob/master/Vulnerabilities_of_ML/) 机器学习漏洞的汇总 - [Analytics](https://github.com/13o-bbr-bbq/machine_learning_security/tree/master/Analytics) 使用k-means分析捕获的数据包 @@ -1077,97 +1148,113 @@ - [Generator](https://github.com/13o-bbr-bbq/machine_learning_security/tree/master/Generator) 使用遗传算法和生成对抗网络,全自动生成大量用于Web应用程序评估的注入代码。 - [Recommender](https://github.com/13o-bbr-bbq/machine_learning_security/tree/master/Recommender) 推荐用于检测Web应用程序漏洞的最佳注入代码。 - [Saivs](https://github.com/13o-bbr-bbq/machine_learning_security/tree/master/Saivs) 发现Web应用程序中的漏洞的AI -- [**1133**星][10d] [C] [xroche/httrack](https://github.com/xroche/httrack) download a World Wide website from the Internet to a local directory, building recursively all directories, getting html, images, and other files from the server to your computer. -- [**1133**星][19d] [Batchfile] [ckjbug/hacking](https://github.com/ckjbug/hacking) +- [**1144**星][3y] [PS] [powershellempire/powertools](https://github.com/powershellempire/powertools) PowerShell项目的集合,重点是进攻性操作 + - [PewPewPew](https://github.com/powershellempire/powertools/tree/master/PewPewPew) scripts that utilize a common pattern to host a script on a PowerShell webserver, invoke the IEX download cradle to download/execute the target code and post the results back to the server, and then post-process any results. + - [PowerBreach](https://github.com/powershellempire/powertools/tree/master/PowerBreach) a backdoor toolkit that aims to provide the user a wide variety of methods to backdoor a system. + - [PowerPick](https://github.com/powershellempire/powertools/tree/master/PowerPick) allowing the execution of Powershell functionality without the use of Powershell.exe +- [**1143**星][2d] [C] [nethack/nethack](https://github.com/nethack/nethack) Official NetHack Git Repository +- [**1143**星][4m] [C++] [cgdb/cgdb](https://github.com/cgdb/cgdb) Console front-end to the GNU debugger +- [**1142**星][7m] [hikariobfuscator/hikari](https://github.com/HikariObfuscator/Hikari) LLVM Obfuscator +- [**1140**星][5d] [w00t3k/awesome-cellular-hacking](https://github.com/w00t3k/awesome-cellular-hacking) Awesome-Cellular-Hacking +- [**1140**星][2m] [HTML] [cure53/httpleaks](https://github.com/cure53/httpleaks) HTTPLeaks - All possible ways, a website can leak HTTP requests +- [**1139**星][12d] [C] [xroche/httrack](https://github.com/xroche/httrack) download a World Wide website from the Internet to a local directory, building recursively all directories, getting html, images, and other files from the server to your computer. +- [**1139**星][4m] [Py] [rhinosecuritylabs/pacu](https://github.com/rhinosecuritylabs/pacu) The AWS exploitation framework, designed for testing the security of Amazon Web Services environments. +- [**1139**星][21d] [Batchfile] [ckjbug/hacking](https://github.com/ckjbug/hacking) +- [**1139**星][11m] [Py] [certsocietegenerale/fir](https://github.com/certsocietegenerale/fir) Fast Incident Response +- [**1138**星][2d] [C] [shadowsocksr-live/shadowsocksr-native](https://github.com/shadowsocksr-live/shadowsocksr-native) 从容翻越党国敏感日 ShadowsocksR (SSR) native implementation for all platforms, GFW terminator +- [**1138**星][2y] [Py] [hackathonhackers/personal-sites](https://github.com/hackathonhackers/personal-sites) List of Hackathon Hackers' personal sites. +- [**1138**星][5d] [Py] [darkoperator/dnsrecon](https://github.com/darkoperator/dnsrecon) DNS 枚举脚本 +- [**1135**星][6m] [nebgnahz/awesome-iot-hacks](https://github.com/nebgnahz/awesome-iot-hacks) A Collection of Hacks in IoT Space so that we can address them (hopefully). +- [**1134**星][4m] [Vue] [0xbug/hawkeye](https://github.com/0xbug/hawkeye) GitHub 泄露监控系统(GitHub Sensitive Information Leakage Monitor Spider) - [**1132**星][2y] [C++] [x64dbg/gleebug](https://github.com/x64dbg/gleebug) Debugging Framework for Windows. -- [**1132**星][6m] [nebgnahz/awesome-iot-hacks](https://github.com/nebgnahz/awesome-iot-hacks) A Collection of Hacks in IoT Space so that we can address them (hopefully). -- [**1132**星][1m] [Jupyter Notebook] [ibm/adversarial-robustness-toolbox](https://github.com/ibm/adversarial-robustness-toolbox) Python library for adversarial machine learning, attacks and defences for neural networks, logistic regression, decision trees, SVM, gradient boosted trees, Gaussian processes and more with multiple framework support -- [**1131**星][2y] [Py] [out0fmemory/goagent-always-available](https://github.com/out0fmemory/goagent-always-available) 一直可用的GoAgent,会定时扫描可用的google gae ip,提供可自动化获取ip运行的版本 -- [**1130**星][7d] [C] [nethack/nethack](https://github.com/nethack/nethack) Official NetHack Git Repository -- [**1130**星][8m] [Py] [darkoperator/dnsrecon](https://github.com/darkoperator/dnsrecon) DNS 枚举脚本 -- [**1129**星][4m] [Py] [rhinosecuritylabs/pacu](https://github.com/rhinosecuritylabs/pacu) The AWS exploitation framework, designed for testing the security of Amazon Web Services environments. -- [**1128**星][5m] [Py] [qyriad/fusee-launcher](https://github.com/Qyriad/fusee-launcher) NVIDIA Tegra X1处理器Fusée Gelée漏洞exploit的launcher. (Fusée Gelée: 冷启动漏洞,允许在bootROM早期, 通过NVIDIA Tegra系列嵌入式处理器上的Tegra恢复模式(RCM)执行完整、未经验证的任意代码) -- [**1125**星][2m] [Go] [mmcloughlin/avo](https://github.com/mmcloughlin/avo) Generate x86 Assembly with Go -- [**1125**星][8m] [C++] [cppcon/cppcon2018](https://github.com/cppcon/cppcon2018) Slides and other materials from CppCon 2018 -- [**1124**星][20d] [HTML] [securitytxt/security-txt](https://github.com/securitytxt/security-txt) 网站定义安全策略的“标准” -- [**1124**星][12d] [C++] [crosire/reshade](https://github.com/crosire/reshade) A generic post-processing injector for games and video software. -- [**1124**星][4m] [Vue] [0xbug/hawkeye](https://github.com/0xbug/hawkeye) GitHub 泄露监控系统(GitHub Sensitive Information Leakage Monitor Spider) -- [**1122**星][3m] [Py] [openai/neural-mmo](https://github.com/openai/neural-mmo) Code for the paper "Neural MMO: A Massively Multiagent Game Environment for Training and Evaluating Intelligent Agents" -- [**1121**星][8m] [majikarp/awesome-programming-books](https://github.com/majikarp/awesome-programming-books) -- [**1117**星][10m] [Py] [openrce/sulley](https://github.com/openrce/sulley) A pure-python fully automated and unattended fuzzing framework. -- [**1117**星][10m] [evilsocket/bleah](https://github.com/evilsocket/bleah) 低功耗蓝牙扫描器 -- [**1116**星][3m] [Py] [thoughtfuldev/eagleeye](https://github.com/thoughtfuldev/eagleeye) Stalk your Friends. Find their Instagram, FB and Twitter Profiles using Image Recognition and Reverse Image Search. -- [**1116**星][1m] [bo0om/fuzz.txt](https://github.com/bo0om/fuzz.txt) Potentially dangerous files -- [**1114**星][1y] [Objective-C] [yulingtianxia/fishchat](https://github.com/yulingtianxia/fishchat) Hook WeChat.app on non-jailbroken devices. -- [**1114**星][28d] [w00t3k/awesome-cellular-hacking](https://github.com/w00t3k/awesome-cellular-hacking) Awesome-Cellular-Hacking -- [**1114**星][11d] [Java] [huangyz0918/androidwm](https://github.com/huangyz0918/androidwm) 一个支持不可见数字水印(隐写术)的android图像水印库。 -- [**1113**星][1y] [aoh/radamsa](https://github.com/aoh/radamsa) a general-purpose fuzzer -- [**1111**星][5m] [Java] [manbanggroup/phantom](https://github.com/manbanggroup/phantom) 唯一零 Hook 稳定占坑类 Android 热更新插件化方案 -- [**1110**星][14d] [PowerShell] [microsoftdocs/virtualization-documentation](https://github.com/MicrosoftDocs/Virtualization-Documentation) Place to store our documentation, code samples, etc for public consumption. -- [**1110**星][3y] [Objective-C] [dyci/dyci-main](https://github.com/dyci/dyci-main) Dynamic Code Injection Tool for Objective-C -- [**1110**星][18d] [C] [blacksphere/blackmagic](https://github.com/blacksphere/blackmagic) In application debugger for ARM Cortex microcontrollers. -- [**1109**星][18d] [C++] [keystone-engine/keystone](https://github.com/keystone-engine/keystone) Keystone assembler framework: Core (Arm, Arm64, Hexagon, Mips, PowerPC, Sparc, SystemZ & X86) + bindings -- [**1109**星][2m] [Py] [john-kurkowski/tldextract](https://github.com/john-kurkowski/tldextract) Accurately separate the TLD from the registered domain and subdomains of a URL, using the Public Suffix List. -- [**1109**星][3y] [Shell] [fritz-smh/yi-hack](https://github.com/fritz-smh/yi-hack) Xiaomi Yi Ants camera hack +- [**1132**星][2y] [Py] [out0fmemory/goagent-always-available](https://github.com/out0fmemory/goagent-always-available) 一直可用的GoAgent,会定时扫描可用的google gae ip,提供可自动化获取ip运行的版本 +- [**1131**星][5m] [Py] [qyriad/fusee-launcher](https://github.com/Qyriad/fusee-launcher) NVIDIA Tegra X1处理器Fusée Gelée漏洞exploit的launcher. (Fusée Gelée: 冷启动漏洞,允许在bootROM早期, 通过NVIDIA Tegra系列嵌入式处理器上的Tegra恢复模式(RCM)执行完整、未经验证的任意代码) +- [**1130**星][8m] [majikarp/awesome-programming-books](https://github.com/majikarp/awesome-programming-books) +- [**1130**星][2d] [C++] [crosire/reshade](https://github.com/crosire/reshade) A generic post-processing injector for games and video software. +- [**1129**星][22d] [HTML] [securitytxt/security-txt](https://github.com/securitytxt/security-txt) 网站定义安全策略的“标准” +- [**1128**星][8m] [C++] [cppcon/cppcon2018](https://github.com/cppcon/cppcon2018) Slides and other materials from CppCon 2018 +- [**1127**星][3m] [Go] [mmcloughlin/avo](https://github.com/mmcloughlin/avo) Generate x86 Assembly with Go +- [**1125**星][3m] [Py] [openai/neural-mmo](https://github.com/openai/neural-mmo) Code for the paper "Neural MMO: A Massively Multiagent Game Environment for Training and Evaluating Intelligent Agents" +- [**1123**星][7d] [C#] [nicehash/nicehashminer](https://github.com/nicehash/NiceHashMiner) NiceHash Miner +- [**1122**星][13d] [Java] [huangyz0918/androidwm](https://github.com/huangyz0918/androidwm) 一个支持不可见数字水印(隐写术)的android图像水印库。 +- [**1120**星][3m] [Py] [thoughtfuldev/eagleeye](https://github.com/thoughtfuldev/eagleeye) Stalk your Friends. Find their Instagram, FB and Twitter Profiles using Image Recognition and Reverse Image Search. +- [**1120**星][2m] [bo0om/fuzz.txt](https://github.com/bo0om/fuzz.txt) Potentially dangerous files +- [**1118**星][10m] [Py] [openrce/sulley](https://github.com/openrce/sulley) A pure-python fully automated and unattended fuzzing framework. +- [**1117**星][1y] [paulsec/awesome-windows-domain-hardening](https://github.com/PaulSec/awesome-windows-domain-hardening) A curated list of awesome Security Hardening techniques for Windows. +- [**1117**星][3d] [C] [blacksphere/blackmagic](https://github.com/blacksphere/blackmagic) In application debugger for ARM Cortex microcontrollers. +- [**1116**星][6d] [PS] [microsoftdocs/virtualization-documentation](https://github.com/MicrosoftDocs/Virtualization-Documentation) Place to store our documentation, code samples, etc for public consumption. +- [**1115**星][1y] [ObjC] [yulingtianxia/fishchat](https://github.com/yulingtianxia/fishchat) Hook WeChat.app on non-jailbroken devices. +- [**1115**星][10m] [evilsocket/bleah](https://github.com/evilsocket/bleah) 低功耗蓝牙扫描器 +- [**1115**星][1y] [aoh/radamsa](https://github.com/aoh/radamsa) a general-purpose fuzzer +- [**1114**星][3d] [Py] [hhyo/archery](https://github.com/hhyo/archery) SQL 审核查询平台 +- [**1113**星][5m] [Java] [manbanggroup/phantom](https://github.com/manbanggroup/phantom) 唯一零 Hook 稳定占坑类 Android 热更新插件化方案 +- [**1113**星][20d] [C++] [keystone-engine/keystone](https://github.com/keystone-engine/keystone) Keystone assembler framework: Core (Arm, Arm64, Hexagon, Mips, PowerPC, Sparc, SystemZ & X86) + bindings +- [**1113**星][2m] [Py] [john-kurkowski/tldextract](https://github.com/john-kurkowski/tldextract) Accurately separate the TLD from the registered domain and subdomains of a URL, using the Public Suffix List. +- [**1110**星][3y] [Shell] [fritz-smh/yi-hack](https://github.com/fritz-smh/yi-hack) Xiaomi Yi Ants camera hack +- [**1110**星][3y] [ObjC] [dyci/dyci-main](https://github.com/dyci/dyci-main) Dynamic Code Injection Tool for Objective-C +- [**1110**星][8m] [Py] [0x00-0x00/shellpop](https://github.com/0x00-0x00/shellpop) 在渗透中生产简易的/复杂的反向/绑定Shell +- [**1109**星][1y] [Py] [wibiti/uncompyle2](https://github.com/wibiti/uncompyle2) Python 2.7 decompiler +- [**1108**星][2d] [C++] [facebookincubator/oomd](https://github.com/facebookincubator/oomd) A userspace out-of-memory killer - [**1108**星][1y] [Py] [byt3bl33d3r/gcat](https://github.com/byt3bl33d3r/gcat) A PoC backdoor that uses Gmail as a C&C server -- [**1106**星][1y] [Py] [wibiti/uncompyle2](https://github.com/wibiti/uncompyle2) Python 2.7 decompiler -- [**1104**星][7d] [C++] [facebookincubator/oomd](https://github.com/facebookincubator/oomd) A userspace out-of-memory killer -- [**1102**星][21d] [slowmist/knowledge-base](https://github.com/slowmist/knowledge-base) Knowledge Base 慢雾安全团队知识库 -- [**1102**星][8d] [C++] [google/sandboxed-api](https://github.com/google/sandboxed-api) Sandboxed API automatically generates sandboxes for C/C++ libraries -- [**1101**星][1y] [paulsec/awesome-windows-domain-hardening](https://github.com/PaulSec/awesome-windows-domain-hardening) A curated list of awesome Security Hardening techniques for Windows. -- [**1101**星][8m] [Py] [0x00-0x00/shellpop](https://github.com/0x00-0x00/shellpop) 在渗透中生产简易的/复杂的反向/绑定Shell -- [**1099**星][5m] [zbetcheckin/security_list](https://github.com/zbetcheckin/security_list) Great security list for fun and profit -- [**1098**星][1y] [Objective-C] [neoneggplant/eggshell](https://github.com/neoneggplant/eggshell) iOS/macOS/Linux Remote Administration Tool -- [**1097**星][1y] [Py] [bugcrowd/hunt](https://github.com/bugcrowd/HUNT) Burp和ZAP的扩展收集 -- [**1097**星][5m] [Py] [coffeehb/some-poc-or-exp](https://github.com/coffeehb/some-poc-or-exp) 各种漏洞poc、Exp的收集或编写 -- [**1096**星][2y] [Py] [ring04h/wydomain](https://github.com/ring04h/wydomain) to discover subdomains of your target domain -- [**1095**星][2m] [PHP] [tuhinshubhra/red_hawk](https://github.com/tuhinshubhra/red_hawk) 信息收集、漏洞扫描、爬虫多合一 -- [**1094**星][8d] [C] [solokeys/solo](https://github.com/solokeys/solo) open security key supporting FIDO2 & U2F over USB + NFC -- [**1094**星][17d] [Go] [sensepost/ruler](https://github.com/sensepost/ruler) 自动化利用Exchange 服务的repo -- [**1093**星][1y] [PowerShell] [rasta-mouse/sherlock](https://github.com/rasta-mouse/sherlock) PowerShell script to quickly find missing software patches for local privilege escalation vulnerabilities. -- [**1092**星][8m] [Ruby] [lionsec/xerosploit](https://github.com/lionsec/xerosploit) Efficient and advanced man in the middle framework -- [**1092**星][18d] [OCaml] [binaryanalysisplatform/bap](https://github.com/binaryanalysisplatform/bap) Binary Analysis Platform -- [**1087**星][10m] [Py] [secforce/sparta](https://github.com/secforce/sparta) 网络基础架构渗透测试 -- [**1084**星][13d] [C] [containers/bubblewrap](https://github.com/containers/bubblewrap) Unprivileged sandboxing tool -- [**1083**星][11d] [Py] [gerbenjavado/linkfinder](https://github.com/gerbenjavado/linkfinder) A python script that finds endpoints in JavaScript files -- [**1083**星][8d] [C++] [cxbx-reloaded/cxbx-reloaded](https://github.com/cxbx-reloaded/cxbx-reloaded) Xbox (Original) Emulator -- [**1081**星][26d] [Go] [looterz/grimd](https://github.com/looterz/grimd) Fast dns proxy that can run anywhere, built to black-hole internet advertisements and malware servers. -- [**1081**星][22d] [Verilog] [cliffordwolf/picorv32](https://github.com/cliffordwolf/picorv32) PicoRV32 - A Size-Optimized RISC-V CPU -- [**1080**星][10d] [Py] [harismuneer/ultimate-facebook-scraper](https://github.com/harismuneer/ultimate-facebook-scraper) -- [**1080**星][2m] [Go] [nadoo/glider](https://github.com/nadoo/glider) 正向代理,支持若干协议 -- [**1077**星][6y] [C] [stephenfewer/reflectivedllinjection](https://github.com/stephenfewer/reflectivedllinjection) Reflective DLL injection is a library injection technique in which the concept of reflective programming is employed to perform the loading of a library from memory into a host process. -- [**1076**星][1m] [snoopysecurity/awesome-burp-extensions](https://github.com/snoopysecurity/awesome-burp-extensions) Burp扩展收集 -- [**1075**星][3m] [Py] [storyyeller/krakatau](https://github.com/storyyeller/krakatau) Java decompiler, assembler, and disassembler -- [**1074**星][8m] [Go] [sevlyar/go-daemon](https://github.com/sevlyar/go-daemon) A library for writing system daemons in golang. -- [**1074**星][2m] [Py] [stampery/mongoaudit](https://github.com/stampery/mongoaudit) -- [**1074**星][7d] [PHP] [automattic/jetpack](https://github.com/automattic/jetpack) Increase your traffic, view your stats, speed up your site, and protect yourself from hackers with Jetpack. -- [**1073**星][2m] [PHP] [nbs-system/php-malware-finder](https://github.com/nbs-system/php-malware-finder) Detect potentially malicious PHP files +- [**1105**星][5m] [zbetcheckin/security_list](https://github.com/zbetcheckin/security_list) Great security list for fun and profit +- [**1103**星][10d] [C] [solokeys/solo](https://github.com/solokeys/solo) open security key supporting FIDO2 & U2F over USB + NFC +- [**1103**星][23d] [slowmist/knowledge-base](https://github.com/slowmist/knowledge-base) Knowledge Base 慢雾安全团队知识库 +- [**1103**星][1y] [ObjC] [neoneggplant/eggshell](https://github.com/neoneggplant/eggshell) iOS/macOS/Linux Remote Administration Tool +- [**1103**星][7d] [C++] [google/sandboxed-api](https://github.com/google/sandboxed-api) Sandboxed API automatically generates sandboxes for C/C++ libraries +- [**1102**星][1y] [Py] [bugcrowd/hunt](https://github.com/bugcrowd/HUNT) Burp和ZAP的扩展收集 +- [**1100**星][13d] [Py] [gerbenjavado/linkfinder](https://github.com/gerbenjavado/linkfinder) A python script that finds endpoints in JavaScript files +- [**1100**星][5m] [Py] [coffeehb/some-poc-or-exp](https://github.com/coffeehb/some-poc-or-exp) 各种漏洞poc、Exp的收集或编写 +- [**1099**星][19d] [Go] [sensepost/ruler](https://github.com/sensepost/ruler) 自动化利用Exchange 服务的repo +- [**1097**星][2y] [Py] [ring04h/wydomain](https://github.com/ring04h/wydomain) to discover subdomains of your target domain +- [**1097**星][7d] [OCaml] [binaryanalysisplatform/bap](https://github.com/binaryanalysisplatform/bap) Binary Analysis Platform +- [**1097**星][9m] [C] [baoleiji/qilinbaoleiji](https://github.com/baoleiji/qilinbaoleiji) 堡垒机-麒麟堡垒机,集堡垒机、SSLVPN-堡垒机内置、动态口令-堡垒机内置、应用审计-堡垒机内置、数据库审计-堡垒机内置、CA证书-堡垒机内置-堡垒机内置、云桌面-堡垒机内置、密码自动修改为一体的堡垒机系统 +- [**1096**星][2m] [PHP] [tuhinshubhra/red_hawk](https://github.com/tuhinshubhra/red_hawk) 信息收集、漏洞扫描、爬虫多合一 +- [**1096**星][1y] [PS] [rasta-mouse/sherlock](https://github.com/rasta-mouse/sherlock) PowerShell script to quickly find missing software patches for local privilege escalation vulnerabilities. +- [**1095**星][8m] [Ruby] [lionsec/xerosploit](https://github.com/lionsec/xerosploit) Efficient and advanced man in the middle framework +- [**1092**星][10m] [Py] [secforce/sparta](https://github.com/secforce/sparta) 网络基础架构渗透测试 +- [**1091**星][3m] [JS] [leng-yue/lengyue-vcode](https://github.com/leng-yue/lengyue-vcode) 各种滑动验证码识别 [腾讯云] [易盾] [Vaptcha] [Geetest] [极验] 各种网站破解 +- [**1090**星][15d] [C] [containers/bubblewrap](https://github.com/containers/bubblewrap) Unprivileged sandboxing tool +- [**1090**星][1m] [snoopysecurity/awesome-burp-extensions](https://github.com/snoopysecurity/awesome-burp-extensions) Burp扩展收集 +- [**1090**星][24d] [Verilog] [cliffordwolf/picorv32](https://github.com/cliffordwolf/picorv32) PicoRV32 - A Size-Optimized RISC-V CPU +- [**1088**星][28d] [Go] [looterz/grimd](https://github.com/looterz/grimd) Fast dns proxy that can run anywhere, built to black-hole internet advertisements and malware servers. +- [**1087**星][10d] [C++] [cxbx-reloaded/cxbx-reloaded](https://github.com/cxbx-reloaded/cxbx-reloaded) Xbox (Original) Emulator +- [**1086**星][6y] [C] [stephenfewer/reflectivedllinjection](https://github.com/stephenfewer/reflectivedllinjection) Reflective DLL injection is a library injection technique in which the concept of reflective programming is employed to perform the loading of a library from memory into a host process. +- [**1084**星][2m] [Go] [nadoo/glider](https://github.com/nadoo/glider) 正向代理,支持若干协议 +- [**1083**星][3m] [Py] [landgrey/pydictor](https://github.com/landgrey/pydictor) A powerful and useful hacker dictionary builder for a brute-force attack +- [**1082**星][8m] [Go] [sevlyar/go-daemon](https://github.com/sevlyar/go-daemon) A library for writing system daemons in golang. +- [**1080**星][2m] [PHP] [nbs-system/php-malware-finder](https://github.com/nbs-system/php-malware-finder) Detect potentially malicious PHP files +- [**1078**星][2d] [PHP] [automattic/jetpack](https://github.com/automattic/jetpack) Increase your traffic, view your stats, speed up your site, and protect yourself from hackers with Jetpack. +- [**1077**星][3m] [Py] [storyyeller/krakatau](https://github.com/storyyeller/krakatau) Java decompiler, assembler, and disassembler +- [**1076**星][2m] [Py] [stampery/mongoaudit](https://github.com/stampery/mongoaudit) +- [**1075**星][3d] [Py] [offensive-security/exploitdb-bin-sploits](https://github.com/offensive-security/exploitdb-bin-sploits) Exploit Database binary exploits located in the /sploits directory +- [**1073**星][3m] [C] [tpruvot/cpuminer-multi](https://github.com/tpruvot/cpuminer-multi) crypto cpuminer (linux + windows) +- [**1073**星][1m] [guardrailsio/awesome-golang-security](https://github.com/guardrailsio/awesome-golang-security) Awesome Golang Security resources +- [**1072**星][1m] [C++] [whitequark/unfork](https://github.com/whitequark/unfork) unfork(2) is the inverse of fork(2). sort of. - [**1072**星][2y] [C++] [fireice-uk/xmr-stak-cpu](https://github.com/fireice-uk/xmr-stak-cpu) Monero CPU miner -- [**1071**星][3m] [C] [tpruvot/cpuminer-multi](https://github.com/tpruvot/cpuminer-multi) crypto cpuminer (linux + windows) -- [**1070**星][3m] [Py] [landgrey/pydictor](https://github.com/landgrey/pydictor) A powerful and useful hacker dictionary builder for a brute-force attack +- [**1071**星][3d] [Py] [googleprojectzero/domato](https://github.com/googleprojectzero/domato) ProjectZero 开源的 DOM fuzzer +- [**1071**星][6m] [C] [tcurdt/iproxy](https://github.com/tcurdt/iproxy) Let's you connect your laptop to the iPhone to surf the web. +- [**1071**星][5m] [Py] [nccgroup/winpayloads](https://github.com/nccgroup/winpayloads) Undetectable Windows Payload Generation +- [**1071**星][7m] [Py] [lucifer1993/struts-scan](https://github.com/lucifer1993/struts-scan) struts2漏洞全版本检测和利用工具 - [**1070**星][3y] [C] [citusdata/pg_shard](https://github.com/citusdata/pg_shard) ATTENTION: pg_shard is superseded by Citus, its more powerful replacement -- [**1066**星][5m] [Py] [nccgroup/winpayloads](https://github.com/nccgroup/winpayloads) Undetectable Windows Payload Generation -- [**1066**星][7m] [Py] [lucifer1993/struts-scan](https://github.com/lucifer1993/struts-scan) struts2漏洞全版本检测和利用工具 -- [**1065**星][1m] [C++] [whitequark/unfork](https://github.com/whitequark/unfork) unfork(2) is the inverse of fork(2). sort of. -- [**1063**星][14d] [Py] [offensive-security/exploitdb-bin-sploits](https://github.com/offensive-security/exploitdb-bin-sploits) Exploit Database binary exploits located in the /sploits directory -- [**1063**星][29d] [guardrailsio/awesome-golang-security](https://github.com/guardrailsio/awesome-golang-security) Awesome Golang Security resources -- [**1062**星][3m] [C] [zerosum0x0/cve-2019-0708](https://github.com/zerosum0x0/cve-2019-0708) Scanner PoC for CVE-2019-0708 RDP RCE vuln -- [**1060**星][2y] [wtsxdev/machine-learning-for-cyber-security](https://github.com/wtsxdev/machine-learning-for-cyber-security) Curated list of tools and resources related to the use of machine learning for cyber security -- [**1060**星][11d] [C] [shadowsocksr-live/shadowsocksr-native](https://github.com/shadowsocksr-live/shadowsocksr-native) 从容翻越党国敏感日 ShadowsocksR (SSR) native implementation for all platforms, GFW terminator -- [**1060**星][7m] [PowerShell] [nytrorst/netripper](https://github.com/nytrorst/netripper) 后渗透工具,针对Windows, 使用API Hooking拦截网络流量和加密相关函数, 可捕获明文和加密前后的内容 -- [**1059**星][2m] [Py] [googleprojectzero/domato](https://github.com/googleprojectzero/domato) ProjectZero 开源的 DOM fuzzer -- [**1057**星][3m] [Py] [infosec-au/altdns](https://github.com/infosec-au/altdns) Generates permutations, alterations and mutations of subdomains and then resolves them -- [**1055**星][25d] [C] [quiet/quiet](https://github.com/quiet/quiet) Transmit data with sound. Includes binaries for soundcards and .wav files. -- [**1053**星][3y] [Perl] [samyk/usbdriveby](https://github.com/samyk/usbdriveby) USBdriveby exploits the trust of USB devices by emulating an HID keyboard and mouse, installing a cross-platform firewall-evading backdoor, and rerouting DNS within seconds of plugging it in. -- [**1052**星][7d] [Py] [forseti-security/forseti-security](https://github.com/forseti-security/forseti-security) A community-driven collection of open source tools to improve the security of your Google Cloud Platform environments -- [**1052**星][5m] [C] [tcurdt/iproxy](https://github.com/tcurdt/iproxy) Let's you connect your laptop to the iPhone to surf the web. -- [**1052**星][20d] [Rust] [fgribreau/mailchecker](https://github.com/fgribreau/mailchecker) 邮件检测库,跨语言。覆盖33078虚假邮件提供者 -- [**1051**星][2m] [Kotlin] [ingokegel/jclasslib](https://github.com/ingokegel/jclasslib) jclasslib bytecode viewer is a tool that visualizes all aspects of compiled Java class files and the contained bytecode. -- [**1051**星][7m] [C] [cr-marcstevens/sha1collisiondetection](https://github.com/cr-marcstevens/sha1collisiondetection) Library and command line tool to detect SHA-1 collision in a file -- [**1049**星][13d] [C++] [simsong/tcpflow](https://github.com/simsong/tcpflow) TCP/IP packet demultiplexer. Download from: -- [**1048**星][7d] [Py] [yelp/detect-secrets](https://github.com/yelp/detect-secrets) An enterprise friendly way of detecting and preventing secrets in code. -- [**1046**星][1m] [Boo] [byt3bl33d3r/silenttrinity](https://github.com/byt3bl33d3r/silenttrinity) An asynchronous, collaborative post-exploitation agent powered by Python and .NET's DLR -- [**1044**星][13d] [Py] [fireeye/flare-ida](https://github.com/fireeye/flare-ida) 多工具 +- [**1068**星][5y] [Py] [observerss/textfilter](https://github.com/observerss/textfilter) 敏感词过滤的几种实现+某1w词敏感词库 +- [**1065**星][3m] [C] [zerosum0x0/cve-2019-0708](https://github.com/zerosum0x0/cve-2019-0708) Scanner PoC for CVE-2019-0708 RDP RCE vuln +- [**1065**星][7m] [PS] [nytrorst/netripper](https://github.com/nytrorst/netripper) 后渗透工具,针对Windows, 使用API Hooking拦截网络流量和加密相关函数, 可捕获明文和加密前后的内容 +- [**1063**星][2y] [wtsxdev/machine-learning-for-cyber-security](https://github.com/wtsxdev/machine-learning-for-cyber-security) Curated list of tools and resources related to the use of machine learning for cyber security +- [**1062**星][27d] [C] [quiet/quiet](https://github.com/quiet/quiet) Transmit data with sound. Includes binaries for soundcards and .wav files. +- [**1061**星][3m] [Py] [infosec-au/altdns](https://github.com/infosec-au/altdns) Generates permutations, alterations and mutations of subdomains and then resolves them +- [**1060**星][2d] [Py] [forseti-security/forseti-security](https://github.com/forseti-security/forseti-security) A community-driven collection of open source tools to improve the security of your Google Cloud Platform environments +- [**1057**星][3y] [Perl] [samyk/usbdriveby](https://github.com/samyk/usbdriveby) USBdriveby exploits the trust of USB devices by emulating an HID keyboard and mouse, installing a cross-platform firewall-evading backdoor, and rerouting DNS within seconds of plugging it in. +- [**1056**星][9d] [Py] [yelp/detect-secrets](https://github.com/yelp/detect-secrets) An enterprise friendly way of detecting and preventing secrets in code. +- [**1056**星][9d] [Kotlin] [ingokegel/jclasslib](https://github.com/ingokegel/jclasslib) jclasslib bytecode viewer is a tool that visualizes all aspects of compiled Java class files and the contained bytecode. +- [**1056**星][5d] [Rust] [fgribreau/mailchecker](https://github.com/fgribreau/mailchecker) 邮件检测库,跨语言。覆盖33078虚假邮件提供者 +- [**1054**星][9d] [C++] [simsong/tcpflow](https://github.com/simsong/tcpflow) TCP/IP packet demultiplexer. Download from: +- [**1052**星][7m] [C] [cr-marcstevens/sha1collisiondetection](https://github.com/cr-marcstevens/sha1collisiondetection) Library and command line tool to detect SHA-1 collision in a file +- [**1052**星][2m] [Boo] [byt3bl33d3r/silenttrinity](https://github.com/byt3bl33d3r/silenttrinity) An asynchronous, collaborative post-exploitation agent powered by Python and .NET's DLR +- [**1051**星][9d] [C++] [wavm/wavm](https://github.com/WAVM/WAVM) WebAssembly Virtual Machine +- [**1051**星][27d] [Py] [sundowndev/phoneinfoga](https://github.com/sundowndev/phoneinfoga) Advanced information gathering & OSINT tool for phone numbers +- [**1050**星][3d] [Rust] [zboxfs/zbox](https://github.com/zboxfs/zbox) Zero-details, privacy-focused in-app file system. +- [**1049**星][14d] [Py] [yzddmr6/webshell-venom](https://github.com/yzddmr6/webshell-venom) 免杀webshell无限生成工具(利用随机异或无限免杀D盾) +- [**1048**星][15d] [Py] [fireeye/flare-ida](https://github.com/fireeye/flare-ida) 多工具 - [StackStrings](https://github.com/fireeye/flare-ida/blob/master/plugins/stackstrings_plugin.py) 自动恢复手动构造的字符串 - [Struct Typer](https://github.com/fireeye/flare-ida/blob/master/plugins/struct_typer_plugin.py) implements the struct typing described [here](https://www.mandiant.com/blog/applying-function-types-structure-fields-ida/) - [ApplyCalleeType](https://github.com/fireeye/flare-ida/blob/master/python/flare/apply_callee_type.py) specify or choose a function type for indirect calls as described [here](https://www.fireeye.com/blog/threat-research/2015/04/flare_ida_pro_script.html) @@ -1177,497 +1264,526 @@ - [MSDN Annotations](https://github.com/fireeye/flare-ida/tree/master/python/flare/IDB_MSDN_Annotator) 从XML文件中提取MSDN信息,添加到IDB数据库中 - [ironstrings](https://github.com/fireeye/flare-ida/tree/master/python/flare/ironstrings) 使用代码模拟执行(flare-emu), 恢复构造的字符串 - [Shellcode Hashes](https://github.com/fireeye/flare-ida/tree/master/shellcode_hashes) 生成Hash数据库 -- [**1040**星][2m] [C] [trailofbits/ctf](https://github.com/trailofbits/ctf) CTF Field Guide -- [**1039**星][12d] [C++] [wavm/wavm](https://github.com/WAVM/WAVM) WebAssembly Virtual Machine -- [**1039**星][5m] [Py] [woj-ciech/kamerka](https://github.com/woj-ciech/kamerka) 利用Shodan构建交互式摄像头地图 -- [**1038**星][8m] [Py] [lucifer1993/angelsword](https://github.com/lucifer1993/angelsword) Python3编写的CMS漏洞检测框架 -- [**1038**星][9m] [Shell] [firehol/firehol](https://github.com/firehol/firehol) A firewall for humans... -- [**1037**星][12d] [Py] [yzddmr6/webshell-venom](https://github.com/yzddmr6/webshell-venom) 免杀webshell无限生成工具(利用随机异或无限免杀D盾) -- [**1035**星][1y] [Batchfile] [nextronsystems/aptsimulator](https://github.com/NextronSystems/APTSimulator) A toolset to make a system look as if it was the victim of an APT attack -- [**1034**星][2m] [C] [xairy/kernel-exploits](https://github.com/xairy/kernel-exploits) My proof-of-concept exploits for the Linux kernel -- [**1034**星][1m] [C] [t6x/reaver-wps-fork-t6x](https://github.com/t6x/reaver-wps-fork-t6x) 攻击 Wi-Fi Protected Setup (WPS), 恢复 WPA/WPA2 密码 -- [**1033**星][7m] [HTML] [sindresorhus/devtools-detect](https://github.com/sindresorhus/devtools-detect) Detect if DevTools is open and its orientation -- [**1032**星][3m] [Py] [h4ckforjob/dirmap](https://github.com/h4ckforjob/dirmap) 一个高级web目录、文件扫描工具,功能将会强于DirBuster、Dirsearch、cansina、御剑。 -- [**1032**星][13d] [HTML] [defectdojo/django-defectdojo](https://github.com/defectdojo/django-defectdojo) DefectDojo is an open-source application vulnerability correlation and security orchestration tool. -- [**1032**星][4y] [C] [crmulliner/adbi](https://github.com/crmulliner/adbi) Android Dynamic Binary Instrumentation Toolkit -- [**1031**星][4m] [PowerShell] [kevin-robertson/inveigh](https://github.com/kevin-robertson/inveigh) Windows PowerShell ADIDNS/LLMNR/mDNS/NBNS spoofer/man-in-the-middle tool -- [**1031**星][1y] [PowerShell] [danmcinerney/icebreaker](https://github.com/danmcinerney/icebreaker) Gets plaintext Active Directory credentials if you're on the internal network but outside the AD environment -- [**1029**星][2y] [PowerShell] [nccgroup/redsnarf](https://github.com/nccgroup/redsnarf) 渗透测试工具,使用OpSec Safe 技术从 Windows 工作站,服务器和域控制器提取 hash 和凭据 -- [**1028**星][3y] [C++] [zyq8709/dexhunter](https://github.com/zyq8709/dexhunter) General Automatic Unpacking Tool for Android Dex Files -- [**1024**星][2y] [Objective-C] [zhengmin1989/ios_ice_and_fire](https://github.com/zhengmin1989/ios_ice_and_fire) iOS冰与火之歌 -- [**1023**星][6m] [stephenturner/oneliners](https://github.com/stephenturner/oneliners) Useful bash one-liners for bioinformatics. -- [**1022**星][5m] [C] [govolution/avet](https://github.com/govolution/avet) 免杀工具 -- [**1019**星][1y] [naetw/ctf-pwn-tips](https://github.com/naetw/ctf-pwn-tips) Here record some tips about pwn. Something is obsoleted and won't be updated. Sorry about that. -- [**1019**星][3m] [Py] [byt3bl33d3r/deathstar](https://github.com/byt3bl33d3r/deathstar) 在Active Directory环境中使用Empire自动获取域管理员权限 -- [**1017**星][25d] [Py] [sundowndev/phoneinfoga](https://github.com/sundowndev/phoneinfoga) Advanced information gathering & OSINT tool for phone numbers -- [**1015**星][29d] [C] [s0lst1c3/eaphammer](https://github.com/s0lst1c3/eaphammer) 针对WPA2-Enterprise 网络的定向双重攻击(evil twin attacks) +- [**1046**星][20d] [denji/awesome-http-benchmark](https://github.com/denji/awesome-http-benchmark) HTTP(S) benchmark tools, testing/debugging, & restAPI (RESTful) +- [**1045**星][5m] [Py] [woj-ciech/kamerka](https://github.com/woj-ciech/kamerka) 利用Shodan构建交互式摄像头地图 +- [**1044**星][9m] [Shell] [firehol/firehol](https://github.com/firehol/firehol) A firewall for humans... +- [**1041**星][2m] [C] [trailofbits/ctf](https://github.com/trailofbits/ctf) CTF Field Guide +- [**1041**星][3m] [Py] [h4ckforjob/dirmap](https://github.com/h4ckforjob/dirmap) 一个高级web目录、文件扫描工具,功能将会强于DirBuster、Dirsearch、cansina、御剑。 +- [**1040**星][8m] [Py] [lucifer1993/angelsword](https://github.com/lucifer1993/angelsword) Python3编写的CMS漏洞检测框架 +- [**1040**星][4m] [PS] [kevin-robertson/inveigh](https://github.com/kevin-robertson/inveigh) Windows PowerShell ADIDNS/LLMNR/mDNS/NBNS spoofer/man-in-the-middle tool +- [**1040**星][2m] [JS] [freetubeapp/freetube](https://github.com/freetubeapp/freetube) An Open Source YouTube app for privacy +- [**1040**星][1m] [Py] [ezaquarii/vpn-at-home](https://github.com/ezaquarii/vpn-at-home) 1-click, self-hosted deployment of OpenVPN with DNS ad blocking sinkhole +- [**1039**星][1y] [Batchfile] [nextronsystems/aptsimulator](https://github.com/NextronSystems/APTSimulator) A toolset to make a system look as if it was the victim of an APT attack +- [**1038**星][1m] [C] [t6x/reaver-wps-fork-t6x](https://github.com/t6x/reaver-wps-fork-t6x) 攻击 Wi-Fi Protected Setup (WPS), 恢复 WPA/WPA2 密码 +- [**1038**星][7m] [nanopool/claymore-dual-miner](https://github.com/nanopool/claymore-dual-miner) Claymore's Dual Ethereum+Decred_Siacoin_Lbry AMD+NVIDIA GPU Miner +- [**1037**星][2m] [C] [xairy/kernel-exploits](https://github.com/xairy/kernel-exploits) My proof-of-concept exploits for the Linux kernel +- [**1037**星][7m] [HTML] [sindresorhus/devtools-detect](https://github.com/sindresorhus/devtools-detect) Detect if DevTools is open and its orientation +- [**1036**星][15d] [HTML] [defectdojo/django-defectdojo](https://github.com/defectdojo/django-defectdojo) DefectDojo is an open-source application vulnerability correlation and security orchestration tool. +- [**1036**星][5y] [C] [crmulliner/adbi](https://github.com/crmulliner/adbi) Android Dynamic Binary Instrumentation Toolkit +- [**1032**星][3y] [C++] [zyq8709/dexhunter](https://github.com/zyq8709/dexhunter) General Automatic Unpacking Tool for Android Dex Files +- [**1032**星][1y] [PS] [danmcinerney/icebreaker](https://github.com/danmcinerney/icebreaker) Gets plaintext Active Directory credentials if you're on the internal network but outside the AD environment +- [**1029**星][20d] [Py] [nccgroup/scoutsuite](https://github.com/nccgroup/scoutsuite) Multi-Cloud Security Auditing Tool +- [**1029**星][2y] [PS] [nccgroup/redsnarf](https://github.com/nccgroup/redsnarf) 渗透测试工具,使用OpSec Safe 技术从 Windows 工作站,服务器和域控制器提取 hash 和凭据 +- [**1029**星][5m] [C] [govolution/avet](https://github.com/govolution/avet) 免杀工具 +- [**1029**星][29d] [denji/nginx-tuning](https://github.com/denji/nginx-tuning) NGINX tuning for best performance +- [**1028**星][18d] [Py] [ct-open-source/tuya-convert](https://github.com/ct-open-source/tuya-convert) A collection of scripts to flash Tuya IoT devices to alternative firmwares +- [**1025**星][6m] [stephenturner/oneliners](https://github.com/stephenturner/oneliners) Useful bash one-liners for bioinformatics. +- [**1025**星][2y] [ObjC] [zhengmin1989/ios_ice_and_fire](https://github.com/zhengmin1989/ios_ice_and_fire) iOS冰与火之歌 +- [**1024**星][12m] [Go] [twitchyliquid64/subnet](https://github.com/twitchyliquid64/subnet) Simple, auditable & elegant VPN, built with TLS mutual authentication and TUN. +- [**1024**星][1y] [naetw/ctf-pwn-tips](https://github.com/naetw/ctf-pwn-tips) Here record some tips about pwn. Something is obsoleted and won't be updated. Sorry about that. +- [**1021**星][3m] [Py] [byt3bl33d3r/deathstar](https://github.com/byt3bl33d3r/deathstar) 在Active Directory环境中使用Empire自动获取域管理员权限 +- [**1019**星][27d] [Shell] [trimstray/sandmap](https://github.com/trimstray/sandmap) 使用NMap引擎, 辅助网络和系统侦查(reconnaissance) +- [**1018**星][1m] [C] [s0lst1c3/eaphammer](https://github.com/s0lst1c3/eaphammer) 针对WPA2-Enterprise 网络的定向双重攻击(evil twin attacks) +- [**1018**星][9m] [Go] [maliceio/malice](https://github.com/maliceio/malice) 开源版的VirusTotal +- [**1014**星][3m] [HTML] [owasp/nodegoat](https://github.com/owasp/nodegoat) 学习OWASP安全威胁Top10如何应用到Web App的,以及如何处理 - [**1014**星][2y] [JS] [umpox/zero-width-detection](https://github.com/umpox/zero-width-detection) Fingerprinting小技巧 -- [**1014**星][18d] [Py] [nccgroup/scoutsuite](https://github.com/nccgroup/scoutsuite) Multi-Cloud Security Auditing Tool +- [**1014**星][11d] [Py] [securestate/king-phisher](https://github.com/securestate/king-phisher) Phishing Campaign Toolkit +- [**1014**星][5m] [C++] [everdox/infinityhook](https://github.com/everdox/infinityhook) Hook system calls, context switches, page faults and more. +- [**1014**星][1y] [Py] [d4vinci/dr0p1t-framework](https://github.com/d4vinci/dr0p1t-framework) 创建免杀的Dropper - [**1014**星][3y] [C++] [aguinet/wannakey](https://github.com/aguinet/wannakey) XP 系统从内存中恢复 Wanacry 最初使用 RSA 私钥(要求主机感染后未重启) -- [**1012**星][25d] [Shell] [trimstray/sandmap](https://github.com/trimstray/sandmap) 使用NMap引擎, 辅助网络和系统侦查(reconnaissance) -- [**1012**星][1y] [Py] [d4vinci/dr0p1t-framework](https://github.com/d4vinci/dr0p1t-framework) 创建免杀的Dropper -- [**1011**星][3m] [HTML] [owasp/nodegoat](https://github.com/owasp/nodegoat) 学习OWASP安全威胁Top10如何应用到Web App的,以及如何处理 -- [**1010**星][9m] [Go] [maliceio/malice](https://github.com/maliceio/malice) 开源版的VirusTotal -- [**1006**星][1m] [Go] [justinas/nosurf](https://github.com/justinas/nosurf) CSRF protection middleware for Go. -- [**1005**星][1y] [JS] [0xsobky/hackvault](https://github.com/0xsobky/hackvault) A container repository for my public web hacks! -- [**1004**星][9d] [Py] [securestate/king-phisher](https://github.com/securestate/king-phisher) Phishing Campaign Toolkit -- [**1004**星][5m] [C++] [everdox/infinityhook](https://github.com/everdox/infinityhook) Hook system calls, context switches, page faults and more. +- [**1011**星][8d] [Rich Text Format] [decalage2/oletools](https://github.com/decalage2/oletools) oletools - python tools to analyze MS OLE2 files (Structured Storage, Compound File Binary Format) and MS Office documents, for malware analysis, forensics and debugging. +- [**1009**星][1y] [C] [ionescu007/simplevisor](https://github.com/ionescu007/simplevisor) 英特尔VT-x虚拟机管理程序,简单、可移植。支持Windows和UEFI +- [**1008**星][24d] [Swift] [rockbruno/swiftshield](https://github.com/rockbruno/swiftshield) wift/OBJ-C Obfuscator +- [**1008**星][5d] [JS] [monzo/response](https://github.com/monzo/response) Monzo's real-time incident response and reporting tool +- [**1008**星][1y] [JS] [0xsobky/hackvault](https://github.com/0xsobky/hackvault) A container repository for my public web hacks! +- [**1007**星][1m] [Go] [justinas/nosurf](https://github.com/justinas/nosurf) CSRF protection middleware for Go. - [**1004**星][1y] [Py] [entropy1337/infernal-twin](https://github.com/entropy1337/infernal-twin) 自动化无线Hack 工具 -- [**1003**星][1y] [C] [ionescu007/simplevisor](https://github.com/ionescu007/simplevisor) 英特尔VT-x虚拟机管理程序,简单、可移植。支持Windows和UEFI -- [**1001**星][11m] [Batchfile] [sagishahar-zz/lpeworkshop](https://github.com/sagishahar-zz/lpeworkshop) Windows / Linux Local Privilege Escalation Workshop +- [**1002**星][24d] [C] [hacksysteam/hacksysextremevulnerabledriver](https://github.com/hacksysteam/hacksysextremevulnerabledriver) HackSys Extreme Vulnerable Windows Driver +- [**1002**星][1m] [C] [google/fuzzer-test-suite](https://github.com/google/fuzzer-test-suite) Set of tests for fuzzing engines +- [**1001**星][7m] [sundowndev/hacker-roadmap](https://github.com/sundowndev/hacker-roadmap) +- [**1001**星][9m] [onethawt/reverseengineering-reading-list](https://github.com/onethawt/reverseengineering-reading-list) A list of Reverse Engineering articles, books, and papers +- [**1000**星][11m] [Batchfile] [sagishahar-zz/lpeworkshop](https://github.com/sagishahar-zz/lpeworkshop) Windows / Linux Local Privilege Escalation Workshop - [**1000**星][5m] [adolfintel/windows10-privacy](https://github.com/adolfintel/windows10-privacy) Win10隐私指南 -- [**999**星][1m] [C] [google/fuzzer-test-suite](https://github.com/google/fuzzer-test-suite) Set of tests for fuzzing engines -- [**999**星][16d] [Py] [ct-open-source/tuya-convert](https://github.com/ct-open-source/tuya-convert) A collection of scripts to flash Tuya IoT devices to alternative firmwares +- [**999**星][28d] [C] [bt3gl/pentesting-toolkit](https://github.com/bt3gl/Pentesting-Toolkit) 渗透测试,CTF和战争游戏的工具收集 +- [**999**星][2m] [ObjC] [lmirosevic/gbdeviceinfo](https://github.com/lmirosevic/gbdeviceinfo) Detects the hardware, software and display of the current iOS or Mac OS X device at runtime. - [**999**星][8m] [Go] [adtac/autovpn](https://github.com/adtac/autovpn) THIS PROJECT IS UNMAINTAINED. -- [**997**星][5m] [Ruby] [mdp/rotp](https://github.com/mdp/rotp) Ruby One Time Password library -- [**997**星][22d] [C] [hacksysteam/hacksysextremevulnerabledriver](https://github.com/hacksysteam/hacksysextremevulnerabledriver) HackSys Extreme Vulnerable Windows Driver -- [**997**星][2y] [Py] [danmcinerney/xsscrapy](https://github.com/danmcinerney/xsscrapy) XSS spider - 66/66 wavsep XSS detected -- [**996**星][2m] [Objective-C] [lmirosevic/gbdeviceinfo](https://github.com/lmirosevic/gbdeviceinfo) Detects the hardware, software and display of the current iOS or Mac OS X device at runtime. -- [**994**星][9m] [Go] [gencebay/httplive](https://github.com/gencebay/httplive) HTTP Request & Response Service, Mock HTTP -- [**993**星][1m] [Py] [x0rz/phishing_catcher](https://github.com/x0rz/phishing_catcher) 使用Certstream 捕获钓鱼域名 -- [**993**星][21d] [JS] [monzo/response](https://github.com/monzo/response) Monzo's real-time incident response and reporting tool -- [**992**星][9m] [onethawt/reverseengineering-reading-list](https://github.com/onethawt/reverseengineering-reading-list) A list of Reverse Engineering articles, books, and papers -- [**992**星][12m] [C#] [kenvix/usbcopyer](https://github.com/kenvix/usbcopyer) 插上U盘自动按需复制文件 -- [**990**星][3y] [JS] [yahooarchive/xss-filters](https://github.com/YahooArchive/xss-filters) Secure XSS Filters. +- [**998**星][5m] [Ruby] [mdp/rotp](https://github.com/mdp/rotp) Ruby One Time Password library +- [**998**星][12m] [C#] [kenvix/usbcopyer](https://github.com/kenvix/usbcopyer) 插上U盘自动按需复制文件 +- [**998**星][2y] [Py] [danmcinerney/xsscrapy](https://github.com/danmcinerney/xsscrapy) XSS spider - 66/66 wavsep XSS detected +- [**997**星][12m] [PHP] [secwiki/cms-hunter](https://github.com/secwiki/cms-hunter) CMS漏洞测试用例集合 +- [**996**星][1m] [Py] [x0rz/phishing_catcher](https://github.com/x0rz/phishing_catcher) 使用Certstream 捕获钓鱼域名 +- [**995**星][9m] [Go] [gencebay/httplive](https://github.com/gencebay/httplive) HTTP Request & Response Service, Mock HTTP +- [**992**星][4m] [C] [gsliepen/tinc](https://github.com/gsliepen/tinc) a VPN daemon - [**990**星][1y] [Py] [tylous/sniffair](https://github.com/tylous/sniffair) 无线渗透框架. 解析被动收集的无线数据, 执行复杂的无线攻击 -- [**990**星][10d] [Rich Text Format] [decalage2/oletools](https://github.com/decalage2/oletools) oletools - python tools to analyze MS OLE2 files (Structured Storage, Compound File Binary Format) and MS Office documents, for malware analysis, forensics and debugging. -- [**989**星][12m] [PHP] [secwiki/cms-hunter](https://github.com/secwiki/cms-hunter) CMS漏洞测试用例集合 -- [**985**星][10m] [Py] [xiphosresearch/exploits](https://github.com/xiphosresearch/exploits) Miscellaneous exploit code -- [**984**星][1m] [C] [wiire-a/pixiewps](https://github.com/wiire-a/pixiewps) An offline Wi-Fi Protected Setup brute-force utility -- [**984**星][22d] [Swift] [rockbruno/swiftshield](https://github.com/rockbruno/swiftshield) wift/OBJ-C Obfuscator -- [**983**星][1y] [HTML] [sensepost/mana](https://github.com/sensepost/mana) *DEPRECATED* mana toolkit for wifi rogue AP attacks and MitM -- [**983**星][10d] [Py] [jekil/awesome-hacking](https://github.com/jekil/awesome-hacking) Awesome hacking is an awesome collection of hacking tools. -- [**981**星][3m] [Py] [ekultek/bluekeep](https://github.com/ekultek/bluekeep) Proof of concept for CVE-2019-0708 -- [**980**星][7m] [sundowndev/hacker-roadmap](https://github.com/sundowndev/hacker-roadmap) -- [**978**星][1m] [C] [zardus/preeny](https://github.com/zardus/preeny) Some helpful preload libraries for pwning stuff. -- [**978**星][1m] [Py] [syss-research/seth](https://github.com/syss-research/seth) Perform a MitM attack and extract clear text credentials from RDP connections -- [**977**星][1y] [Py] [fsecurelabs/needle](https://github.com/FSecureLABS/needle) The iOS Security Testing Framework -- [**977**星][4m] [Go] [nosequeldeebee/blockchain-tutorial](https://github.com/nosequeldeebee/blockchain-tutorial) Write and publish your own blockchain in less than 200 lines of Go -- [**976**星][21d] [JS] [lukechilds/reverse-shell](https://github.com/lukechilds/reverse-shell) Reverse Shell as a Service +- [**988**星][3d] [C#] [k8gege/ladon](https://github.com/k8gege/ladon) 大型内网渗透扫描器&Cobalt Strike,包含信息收集/端口扫描/服务识别/网络资产/密码爆破/漏洞检测/漏洞利用。漏洞检测含MS17010、Weblogic、ActiveMQ、Tomcat等,密码口令爆破含(Mysql、Oracle、MSSQL)、FTP、SSH(Linux)、VNC、Windows(IPC、WMI、SMB)等,可高度自定义插件支持.NET程序集、DLL(C#/Delphi/VC)、PowerShell等语言编写的插件,支持通过配置INI批量调用任意外部程序或命令,EXP生成器一键生成Web漏洞POC,可快速扩展扫描或利用能力。支持Cobalt Strike插件化直接内存加载Ladon扫描快速拓展内网横向移动 +- [**988**星][3y] [JS] [yahooarchive/xss-filters](https://github.com/YahooArchive/xss-filters) Secure XSS Filters. +- [**988**星][4m] [Go] [nosequeldeebee/blockchain-tutorial](https://github.com/nosequeldeebee/blockchain-tutorial) Write and publish your own blockchain in less than 200 lines of Go +- [**987**星][10m] [Py] [xiphosresearch/exploits](https://github.com/xiphosresearch/exploits) Miscellaneous exploit code +- [**987**星][3d] [Py] [jekil/awesome-hacking](https://github.com/jekil/awesome-hacking) Awesome hacking is an awesome collection of hacking tools. +- [**986**星][1m] [C] [wiire-a/pixiewps](https://github.com/wiire-a/pixiewps) An offline Wi-Fi Protected Setup brute-force utility +- [**986**星][1y] [HTML] [sensepost/mana](https://github.com/sensepost/mana) *DEPRECATED* mana toolkit for wifi rogue AP attacks and MitM +- [**986**星][3m] [Py] [ekultek/bluekeep](https://github.com/ekultek/bluekeep) Proof of concept for CVE-2019-0708 +- [**981**星][1y] [Py] [fsecurelabs/needle](https://github.com/FSecureLABS/needle) The iOS Security Testing Framework +- [**980**星][1m] [C] [zardus/preeny](https://github.com/zardus/preeny) Some helpful preload libraries for pwning stuff. +- [**980**星][2m] [Py] [syss-research/seth](https://github.com/syss-research/seth) Perform a MitM attack and extract clear text credentials from RDP connections +- [**979**星][1m] [hoshsadiq/adblock-nocoin-list](https://github.com/hoshsadiq/adblock-nocoin-list) Block lists to prevent JavaScript miners +- [**978**星][23d] [JS] [lukechilds/reverse-shell](https://github.com/lukechilds/reverse-shell) Reverse Shell as a Service +- [**978**星][12d] [Py] [kiminewt/pyshark](https://github.com/kiminewt/pyshark) Python wrapper for tshark, allowing python packet parsing using wireshark dissectors +- [**978**星][2m] [Jupyter Notebook] [hyperparticle/one-pixel-attack-keras](https://github.com/hyperparticle/one-pixel-attack-keras) Keras implementation of "One pixel attack for fooling deep neural networks" using differential evolution on Cifar10 and ImageNet +- [**978**星][3y] [Py] [dowsnature/dowsdns](https://github.com/dowsnature/dowsdns) 快速翻跃中国防火墙 +- [**978**星][26d] [Jupyter Notebook] [aarshayj/analytics_vidhya](https://github.com/aarshayj/analytics_vidhya) Codes related to activities on AV including articles, hackathons and discussions. +- [**976**星][7m] [0x4d31/awesome-threat-detection](https://github.com/0x4d31/awesome-threat-detection) A curated list of awesome threat detection and hunting resources +- [**975**星][3y] [Py] [synack/knockknock](https://github.com/synack/knockknock) displays persistent items (scripts, commands, binaries, etc.), that are set to execute automatically on OS X - [**975**星][2y] [Py] [moosedojo/apt2](https://github.com/moosedojo/apt2) 自动化渗透测试工具包。执行NMap扫描, 或者导入Nexpose, Nessus, NMap扫描结果 -- [**975**星][24d] [Jupyter Notebook] [aarshayj/analytics_vidhya](https://github.com/aarshayj/analytics_vidhya) Codes related to activities on AV including articles, hackathons and discussions. -- [**974**星][3y] [Py] [synack/knockknock](https://github.com/synack/knockknock) displays persistent items (scripts, commands, binaries, etc.), that are set to execute automatically on OS X -- [**974**星][2m] [Jupyter Notebook] [hyperparticle/one-pixel-attack-keras](https://github.com/hyperparticle/one-pixel-attack-keras) Keras implementation of "One pixel attack for fooling deep neural networks" using differential evolution on Cifar10 and ImageNet -- [**973**星][10d] [Py] [kiminewt/pyshark](https://github.com/kiminewt/pyshark) Python wrapper for tshark, allowing python packet parsing using wireshark dissectors -- [**971**星][27d] [Py] [x64dbg/docs](https://github.com/x64dbg/docs) x64dbg文档 -- [**971**星][7m] [Py] [m57/dnsteal](https://github.com/m57/dnsteal) DNS Exfiltration tool for stealthily sending files over DNS requests. -- [**969**星][1m] [HTML] [n0tr00t/sreg](https://github.com/n0tr00t/sreg) 可对使用者通过输入email、phone、username的返回用户注册的所有互联网护照信息。 -- [**969**星][3m] [ctfs/resources](https://github.com/ctfs/resources) A general collection of information, tools, and tips regarding CTFs and similar security competitions -- [**968**星][7m] [0x4d31/awesome-threat-detection](https://github.com/0x4d31/awesome-threat-detection) A curated list of awesome threat detection and hunting resources -- [**967**星][3y] [Java] [androidvts/android-vts](https://github.com/androidvts/android-vts) Android Vulnerability Test Suite - In the spirit of open data collection, and with the help of the community, let's take a pulse on the state of Android security. NowSecure presents an on-device app to test for recent device vulnerabilities. -- [**966**星][2m] [Go] [vishvananda/netlink](https://github.com/vishvananda/netlink) Simple netlink library for go. -- [**966**星][2m] [C] [olimex/olinuxino](https://github.com/olimex/olinuxino) OLINUXINO is Open Source / Open Hardware, low cost from EUR 24 Linux Industrial grade Single Board Computer capable to operate -25+85C +- [**974**星][24d] [Rust] [sozu-proxy/sozu](https://github.com/sozu-proxy/sozu) Sōzu HTTP reverse proxy, configurable at runtime, fast and safe, built in Rust. It is awesome! Ping us on gitter to know more +- [**973**星][2m] [Py] [ondyari/faceforensics](https://github.com/ondyari/faceforensics) Github of the FaceForensics dataset +- [**973**星][1m] [HTML] [n0tr00t/sreg](https://github.com/n0tr00t/sreg) 可对使用者通过输入email、phone、username的返回用户注册的所有互联网护照信息。 +- [**973**星][7m] [Py] [m57/dnsteal](https://github.com/m57/dnsteal) DNS Exfiltration tool for stealthily sending files over DNS requests. +- [**973**星][12m] [Java] [huolizhuminh/networkpacketcapture](https://github.com/huolizhuminh/networkpacketcapture) It is used to capture network packet via Android VPN. +- [**972**星][6d] [C++] [herumi/xbyak](https://github.com/herumi/xbyak) a JIT assembler for x86(IA-32)/x64(AMD64, x86-64) MMX/SSE/SSE2/SSE3/SSSE3/SSE4/FPU/AVX/AVX2/AVX-512 by C++ header +- [**971**星][29d] [Py] [x64dbg/docs](https://github.com/x64dbg/docs) x64dbg文档 +- [**971**星][27d] [Go] [vishvananda/netlink](https://github.com/vishvananda/netlink) Simple netlink library for go. +- [**971**星][3m] [ctfs/resources](https://github.com/ctfs/resources) A general collection of information, tools, and tips regarding CTFs and similar security competitions +- [**969**星][4m] [Assembly] [corkami/pocs](https://github.com/corkami/pocs) Proof of Concepts (PE, PDF...) +- [**968**星][5m] [C] [rbsec/sslscan](https://github.com/rbsec/sslscan) 测试启用SSL/TLS的服务,发现其支持的cipher suites +- [**968**星][2m] [C] [olimex/olinuxino](https://github.com/olimex/olinuxino) OLINUXINO is Open Source / Open Hardware, low cost from EUR 24 Linux Industrial grade Single Board Computer capable to operate -25+85C +- [**967**星][8m] [Py] [selwin/python-user-agents](https://github.com/selwin/python-user-agents) A Python library that provides an easy way to identify devices like mobile phones, tablets and their capabilities by parsing (browser) user agent strings. +- [**967**星][4m] [Go] [dominicbreuker/pspy](https://github.com/dominicbreuker/pspy) 一个命令行工具, 无需根权限就可以窥探Linux进程 - [**966**星][3y] [C] [cybellum/doubleagent](https://github.com/cybellum/doubleagent) Zero-Day Code Injection and Persistence Technique -- [**966**星][4m] [Assembly] [corkami/pocs](https://github.com/corkami/pocs) Proof of Concepts (PE, PDF...) -- [**965**星][5m] [C] [rbsec/sslscan](https://github.com/rbsec/sslscan) 测试启用SSL/TLS的服务,发现其支持的cipher suites -- [**964**星][8m] [Py] [selwin/python-user-agents](https://github.com/selwin/python-user-agents) A Python library that provides an easy way to identify devices like mobile phones, tablets and their capabilities by parsing (browser) user agent strings. -- [**963**星][11d] [C++] [herumi/xbyak](https://github.com/herumi/xbyak) a JIT assembler for x86(IA-32)/x64(AMD64, x86-64) MMX/SSE/SSE2/SSE3/SSSE3/SSE4/FPU/AVX/AVX2/AVX-512 by C++ header -- [**963**星][4m] [Go] [dominicbreuker/pspy](https://github.com/dominicbreuker/pspy) Monitor linux processes without root permissions -- [**961**星][19d] [C] [bt3gl/pentesting-toolkit](https://github.com/bt3gl/Pentesting-Toolkit) Tools for pentesting, CTFs & wargames. +- [**966**星][3y] [Java] [androidvts/android-vts](https://github.com/androidvts/android-vts) Android Vulnerability Test Suite - In the spirit of open data collection, and with the help of the community, let's take a pulse on the state of Android security. NowSecure presents an on-device app to test for recent device vulnerabilities. +- [**965**星][5d] [C++] [dvorka/mindforger](https://github.com/dvorka/mindforger) Thinking notebook and Markdown IDE. +- [**965**星][1m] [C#] [cobbr/covenant](https://github.com/cobbr/covenant) Covenant is a collaborative .NET C2 framework for red teamers. +- [**964**星][7m] [PHP] [jenssegers/optimus](https://github.com/jenssegers/optimus) id transformation With this library, you can transform your internal id's to obfuscated integers based on Knuth's integer has和 +- [**962**星][4m] [Py] [0xinfection/tidos-framework](https://github.com/0xInfection/TIDoS-Framework) Web App渗透测试框架, 攻击性, 手动 +- [**962**星][3d] [bromite/bromite](https://github.com/bromite/bromite) Bromite is Chromium plus ad blocking and privacy enhancements; take back your browser! +- [**962**星][3y] [Py] [abatchy17/windowsexploits](https://github.com/abatchy17/windowsexploits) Windows exploits, mostly precompiled. Not being updated. Check +- [**961**星][4y] [pillarjs/understanding-csrf](https://github.com/pillarjs/understanding-csrf) What are CSRF tokens and how do they work? +- [**961**星][1m] [PS] [netspi/powerupsql](https://github.com/netspi/powerupsql) 攻击SQL服务器的PowerShell工具箱 - [**961**星][3y] [Go] [jaksi/sshesame](https://github.com/jaksi/sshesame) A fake SSH server that lets everyone in and logs their activity -- [**960**星][7m] [PHP] [jenssegers/optimus](https://github.com/jenssegers/optimus) id transformation With this library, you can transform your internal id's to obfuscated integers based on Knuth's integer has和 -- [**960**星][9m] [C++] [dvorka/mindforger](https://github.com/dvorka/mindforger) Thinking notebook and Markdown IDE. -- [**959**星][4y] [pillarjs/understanding-csrf](https://github.com/pillarjs/understanding-csrf) What are CSRF tokens and how do they work? -- [**958**星][4m] [Py] [0xinfection/tidos-framework](https://github.com/0xInfection/TIDoS-Framework) Web App渗透测试框架, 攻击性, 手动 -- [**956**星][2m] [Py] [ondyari/faceforensics](https://github.com/ondyari/faceforensics) Github of the FaceForensics dataset -- [**956**星][3y] [Py] [abatchy17/windowsexploits](https://github.com/abatchy17/windowsexploits) Windows exploits, mostly precompiled. Not being updated. Check -- [**955**星][2m] [JS] [pillarjs/cookies](https://github.com/pillarjs/cookies) Signed and unsigned cookies based on Keygrip +- [**957**星][2m] [JS] [pillarjs/cookies](https://github.com/pillarjs/cookies) Signed and unsigned cookies based on Keygrip +- [**956**星][2d] [Py] [shmilylty/oneforall](https://github.com/shmilylty/oneforall) 子域收集工具 +- [**956**星][27d] [Py] [fireeye/flare-fakenet-ng](https://github.com/fireeye/flare-fakenet-ng) 下一代动态网络分析工具 +- [**955**星][7d] [C++] [hasherezade/pe-sieve](https://github.com/hasherezade/pe-sieve) Scans a given process. Recognizes and dumps a variety of potentially malicious implants (replaced/injected PEs, shellcodes, hooks, in-memory patches). - [**953**星][4m] [Py] [hatriot/zarp](https://github.com/hatriot/zarp) 网络攻击工具,主要是本地网络攻击 -- [**953**星][25d] [Py] [fireeye/flare-fakenet-ng](https://github.com/fireeye/flare-fakenet-ng) 下一代动态网络分析工具 -- [**952**星][1m] [PowerShell] [netspi/powerupsql](https://github.com/netspi/powerupsql) 攻击SQL服务器的PowerShell工具箱 -- [**952**星][1m] [C#] [cobbr/covenant](https://github.com/cobbr/covenant) Covenant is a collaborative .NET C2 framework for red teamers. -- [**950**星][8d] [C++] [hasherezade/pe-sieve](https://github.com/hasherezade/pe-sieve) Scans a given process. Recognizes and dumps a variety of potentially malicious implants (replaced/injected PEs, shellcodes, hooks, in-memory patches). -- [**947**星][2y] [Py] [arnaucube/coffeeminer](https://github.com/arnaucube/coffeeMiner) collaborative (mitm) cryptocurrency mining pool in wifi networks -- [**947**星][1y] [JS] [fabienvauchelles/scrapoxy](https://github.com/fabienvauchelles/scrapoxy) Scrapoxy hides your scraper behind a cloud. It starts a pool of proxies to send your requests. Now, you can crawl without thinking about blacklisting! +- [**952**星][12d] [HTML] [sprov065/v2-ui](https://github.com/sprov065/v2-ui) 支持多协议多用户的 v2ray 面板,Support multi-protocol multi-user v2ray panel +- [**952**星][1y] [JS] [fabienvauchelles/scrapoxy](https://github.com/fabienvauchelles/scrapoxy) Scrapoxy hides your scraper behind a cloud. It starts a pool of proxies to send your requests. Now, you can crawl without thinking about blacklisting! +- [**951**星][8d] [Py] [mozilla/openwpm](https://github.com/mozilla/OpenWPM) A web privacy measurement framework +- [**951**星][2y] [C] [fdiskyou/injectallthethings](https://github.com/fdiskyou/injectallthethings) Seven different DLL injection techniques in one single project. +- [**950**星][2y] [Py] [trycatchhcf/cloakify](https://github.com/trycatchhcf/cloakify) CloakifyFactory - Data Exfiltration & Infiltration In Plain Sight; Convert any filetype into list of everyday strings, using Text-Based Steganography; Evade DLP/MLS Devices, Defeat Data Whitelisting Controls, Social Engineering of Analysts, Evade AV Detection +- [**948**星][2y] [Py] [arnaucube/coffeeminer](https://github.com/arnaucube/coffeeMiner) collaborative (mitm) cryptocurrency mining pool in wifi networks - [**947**星][6m] [C] [dhavalkapil/heap-exploitation](https://github.com/dhavalkapil/heap-exploitation) This book on heap exploitation is a guide to understanding the internals of glibc's heap and various attacks possible on the heap structure. -- [**946**星][10d] [C#] [k8gege/ladon](https://github.com/k8gege/ladon) 大型内网渗透扫描器&Cobalt Strike,包含信息收集/端口扫描/服务识别/网络资产/密码爆破/漏洞检测/漏洞利用。漏洞检测含MS17010、Weblogic、ActiveMQ、Tomcat等,密码口令爆破含(Mysql、Oracle、MSSQL)、FTP、SSH(Linux)、VNC、Windows(IPC、WMI、SMB)等,可高度自定义插件支持.NET程序集、DLL(C#/Delphi/VC)、PowerShell等语言编写的插件,支持通过配置INI批量调用任意外部程序或命令,EXP生成器一键生成Web漏洞POC,可快速扩展扫描或利用能力。支持Cobalt Strike插件化直接内存加载Ladon扫描快速拓展内网横向移动 -- [**945**星][17d] [Py] [mozilla/openwpm](https://github.com/mozilla/OpenWPM) A web privacy measurement framework -- [**945**星][2y] [Py] [trycatchhcf/cloakify](https://github.com/trycatchhcf/cloakify) CloakifyFactory - Data Exfiltration & Infiltration In Plain Sight; Convert any filetype into list of everyday strings, using Text-Based Steganography; Evade DLP/MLS Devices, Defeat Data Whitelisting Controls, Social Engineering of Analysts, Evade AV Detection -- [**943**星][2y] [C] [fdiskyou/injectallthethings](https://github.com/fdiskyou/injectallthethings) Seven different DLL injection techniques in one single project. -- [**942**星][4m] [Py] [intelxed/xed](https://github.com/intelxed/xed) x86 encoder decoder -- [**942**星][9d] [bromite/bromite](https://github.com/bromite/bromite) Bromite is Chromium plus ad blocking and privacy enhancements; take back your browser! +- [**947**星][8d] [HTML] [darksecdevelopers/hiddeneye](https://github.com/darksecdevelopers/hiddeneye) Modern Phishing Tool With Advanced Functionality And Multiple Tunnelling Services [ Android-Support-Available ] +- [**946**星][9d] [Py] [sashs/ropper](https://github.com/sashs/ropper) Display information about files in different file formats and find gadgets to build rop chains for different architectures (x86/x86_64, ARM/ARM64, MIPS, PowerPC, SPARC64). For disassembly ropper uses the awesome Capstone Framework. +- [**946**星][4d] [Go] [ffuf/ffuf](https://github.com/ffuf/ffuf) Fast web fuzzer written in Go +- [**946**星][2m] [C] [basil00/divert](https://github.com/basil00/divert) 用户模式数据包拦截库,适用于Win 7/8/10 +- [**944**星][2m] [C++] [cisco-talos/clamav-devel](https://github.com/Cisco-Talos/clamav-devel) ClamAV Development - FAQ is here: +- [**944**星][2y] [C#] [invoke-ir/powerforensics](https://github.com/invoke-ir/powerforensics) PowerForensics provides an all in one platform for live disk forensic analysis +- [**944**星][4m] [Py] [intelxed/xed](https://github.com/intelxed/xed) x86 encoder decoder +- [**943**星][13d] [Py] [theupdateframework/tuf](https://github.com/theupdateframework/tuf) A framework for securing software update systems +- [**942**星][2y] [HTML] [chybeta/software-security-learning](https://github.com/chybeta/software-security-learning) Software-Security-Learning +- [**941**星][3m] [zhaoweih/shadowsocks-tutorial](https://github.com/zhaoweih/shadowsocks-tutorial) - [**940**星][5y] [Py] [mothran/bunny](https://github.com/mothran/bunny) Bunny is a wireless. meshing, darknet that uses 802.11 to hide its communications -- [**940**星][28d] [Py] [sashs/ropper](https://github.com/sashs/ropper) Display information about files in different file formats and find gadgets to build rop chains for different architectures (x86/x86_64, ARM/ARM64, MIPS, PowerPC, SPARC64). For disassembly ropper uses the awesome Capstone Framework. -- [**940**星][2y] [C#] [invoke-ir/powerforensics](https://github.com/invoke-ir/powerforensics) PowerForensics provides an all in one platform for live disk forensic analysis -- [**940**星][2m] [C] [basil00/divert](https://github.com/basil00/divert) 用户模式数据包拦截库,适用于Win 7/8/10 +- [**940**星][10m] [Shell] [1n3/findsploit](https://github.com/1n3/findsploit) Find exploits in local and online databases instantly - [**939**星][1y] [JS] [netflix-skunkworks/sleepy-puppy](https://github.com/Netflix-Skunkworks/sleepy-puppy) Sleepy Puppy XSS Payload Management Framework -- [**939**星][3y] [Py] [countercept/doublepulsar-detection-script](https://github.com/countercept/doublepulsar-detection-script) python脚本,用于扫描网络中感染DOUBLEPULSAR的操作系统。 -- [**938**星][2m] [C++] [cisco-talos/clamav-devel](https://github.com/Cisco-Talos/clamav-devel) ClamAV Development - FAQ is here: -- [**937**星][2y] [Perl] [infobyte/evilgrade](https://github.com/infobyte/evilgrade) 供应链攻击: 注入虚假的update -- [**937**星][2y] [HTML] [chybeta/software-security-learning](https://github.com/chybeta/software-security-learning) Software-Security-Learning -- [**936**星][11d] [Py] [theupdateframework/tuf](https://github.com/theupdateframework/tuf) A framework for securing software update systems -- [**935**星][1y] [Java] [google/firing-range](https://github.com/google/firing-range) a test bed for web application security scanners, providing synthetic, wide coverage for an array of vulnerabilities. -- [**935**星][3m] [Py] [christophetd/cloudflair](https://github.com/christophetd/cloudflair) a tool to find origin servers of websites protected by CloudFlare who are publicly exposed and don't restrict network access to the CloudFlare IP ranges as they should -- [**935**星][10m] [Shell] [1n3/findsploit](https://github.com/1n3/findsploit) Find exploits in local and online databases instantly -- [**933**星][9d] [Py] [shmilylty/oneforall](https://github.com/shmilylty/oneforall) 子域收集工具 -- [**933**星][12m] [Py] [gaasedelen/lighthouse](https://github.com/gaasedelen/lighthouse) 从DBI中收集代码覆盖情况,在IDA/Binja中映射、浏览、查看 +- [**939**星][12m] [Py] [gaasedelen/lighthouse](https://github.com/gaasedelen/lighthouse) 从DBI中收集代码覆盖情况,在IDA/Binja中映射、浏览、查看 - [coverage-frida](https://github.com/gaasedelen/lighthouse/blob/master/coverage/frida/README.md) 使用Frida收集信息 - [coverage-pin](https://github.com/gaasedelen/lighthouse/blob/master/coverage/pin/README.md) 使用Pin收集覆盖信息 - [插件](https://github.com/gaasedelen/lighthouse/blob/master/plugin/lighthouse_plugin.py) 支持IDA和BinNinja -- [**932**星][2y] [C++] [securesocketfunneling/ssf](https://github.com/securesocketfunneling/ssf) 网络工具包:TCP 和 UDP 端口转发、SOCKS 代理、远程 shell,跨平台 -- [**931**星][2y] [deepspaceharbor/awesome-ai-security](https://github.com/DeepSpaceHarbor/Awesome-AI-Security) -- [**931**星][2y] [Py] [tomchop/malcom](https://github.com/tomchop/malcom) Malcom - Malware Communications Analyzer -- [**930**星][7d] [C++] [kde/heaptrack](https://github.com/kde/heaptrack) A heap memory profiler for Linux -- [**930**星][2m] [Py] [d4vinci/one-lin3r](https://github.com/d4vinci/one-lin3r) 轻量级框架,提供在渗透测试中需要的所有one-liners -- [**928**星][7m] [Py] [osirislab/hack-night](https://github.com/osirislab/Hack-Night) a sobering introduction to offensive security +- [**939**星][3y] [Py] [countercept/doublepulsar-detection-script](https://github.com/countercept/doublepulsar-detection-script) python脚本,用于扫描网络中感染DOUBLEPULSAR的操作系统。 +- [**939**星][3m] [Py] [christophetd/cloudflair](https://github.com/christophetd/cloudflair) a tool to find origin servers of websites protected by CloudFlare who are publicly exposed and don't restrict network access to the CloudFlare IP ranges as they should +- [**939**星][4m] [bugcrowd/bugcrowd_university](https://github.com/bugcrowd/bugcrowd_university) 研究者社区的教育内容 +- [**938**星][9m] [wtsxdev/penetration-testing](https://github.com/wtsxdev/penetration-testing) List of awesome penetration testing resources, tools and other shiny things +- [**938**星][17d] [Py] [knownsec/pocsuite3](https://github.com/knownsec/pocsuite3) 远程漏洞测试与PoC开发框架 +- [**938**星][2y] [Perl] [infobyte/evilgrade](https://github.com/infobyte/evilgrade) 供应链攻击: 注入虚假的update +- [**936**星][2y] [deepspaceharbor/awesome-ai-security](https://github.com/DeepSpaceHarbor/Awesome-AI-Security) +- [**936**星][2y] [C++] [securesocketfunneling/ssf](https://github.com/securesocketfunneling/ssf) 网络工具包:TCP 和 UDP 端口转发、SOCKS 代理、远程 shell,跨平台 +- [**935**星][1y] [Java] [google/firing-range](https://github.com/google/firing-range) a test bed for web application security scanners, providing synthetic, wide coverage for an array of vulnerabilities. +- [**935**星][2m] [Py] [d4vinci/one-lin3r](https://github.com/d4vinci/one-lin3r) 轻量级框架,提供在渗透测试中需要的所有one-liners +- [**934**星][13d] [Ruby] [david942j/one_gadget](https://github.com/david942j/one_gadget) The best tool for finding one gadget RCE in libc.so.6 +- [**933**星][2y] [Py] [tomchop/malcom](https://github.com/tomchop/malcom) Malcom - Malware Communications Analyzer +- [**931**星][30d] [Py] [nullsecuritynet/tools](https://github.com/nullsecuritynet/tools) Security and Hacking Tools, Exploits, Proof of Concepts, Shellcodes, Scripts. +- [**930**星][5m] [threathuntingproject/threathunting](https://github.com/threathuntingproject/threathunting) An informational repo about hunting for adversaries in your IT environment. +- [**930**星][7d] [C++] [kde/heaptrack](https://github.com/kde/heaptrack) Linux的堆内存分析器 +- [**930**星][6d] [OCaml] [airbus-seclab/bincat](https://github.com/airbus-seclab/bincat) 二进制代码静态分析工具。值分析(寄存器、内存)、污点分析、类型重建和传播(propagation)、前向/后向分析 +- [**929**星][7m] [Py] [osirislab/hack-night](https://github.com/osirislab/Hack-Night) a sobering introduction to offensive security +- [**928**星][3y] [C] [tyilo/insert_dylib](https://github.com/tyilo/insert_dylib) Command line utility for inserting a dylib load command into a Mach-O binary - [**928**星][9m] [C] [microsoft/windows-driver-frameworks](https://github.com/microsoft/windows-driver-frameworks) Windows驱动框架(WDF) -- [**928**星][11d] [Ruby] [david942j/one_gadget](https://github.com/david942j/one_gadget) The best tool for finding one gadget RCE in libc.so.6 -- [**927**星][28d] [Py] [nullsecuritynet/tools](https://github.com/nullsecuritynet/tools) Security and Hacking Tools, Exploits, Proof of Concepts, Shellcodes, Scripts. -- [**927**星][12d] [OCaml] [airbus-seclab/bincat](https://github.com/airbus-seclab/bincat) 二进制代码静态分析工具。值分析(寄存器、内存)、污点分析、类型重建和传播(propagation)、前向/后向分析 +- [**927**星][2y] [C++] [genoil/cpp-ethereum](https://github.com/genoil/cpp-ethereum) [Warning: Repo inactive] Ethereum GPU miner with OpenCL, CUDA and stratum support +- [**927**星][1y] [Py] [m4n3dw0lf/pythem](https://github.com/m4n3dw0lf/pythem) 多功能渗透测试框架 - [**927**星][4m] [Py] [airbnb/binaryalert](https://github.com/airbnb/binaryalert) 实时恶意代码检测,无需服务器 -- [**926**星][4m] [threathuntingproject/threathunting](https://github.com/threathuntingproject/threathunting) An informational repo about hunting for adversaries in your IT environment. -- [**925**星][9m] [wtsxdev/penetration-testing](https://github.com/wtsxdev/penetration-testing) List of awesome penetration testing resources, tools and other shiny things -- [**924**星][3y] [C] [tyilo/insert_dylib](https://github.com/tyilo/insert_dylib) Command line utility for inserting a dylib load command into a Mach-O binary -- [**924**星][1y] [Py] [m4n3dw0lf/pythem](https://github.com/m4n3dw0lf/pythem) 多功能渗透测试框架 -- [**923**星][3m] [zhaoweih/shadowsocks-tutorial](https://github.com/zhaoweih/shadowsocks-tutorial) -- [**923**星][3y] [Eagle] [samyk/keysweeper](https://github.com/samyk/keysweeper) KeySweeper is a stealthy Arduino-based device, camouflaged as a functioning USB wall charger, that wirelessly and passively sniffs, decrypts, logs and reports back (over GSM) all keystrokes from any Microsoft wireless keyboard in the vicinity. -- [**923**星][4m] [bugcrowd/bugcrowd_university](https://github.com/bugcrowd/bugcrowd_university) Open source education content for the researcher community +- [**926**星][3y] [Eagle] [samyk/keysweeper](https://github.com/samyk/keysweeper) KeySweeper is a stealthy Arduino-based device, camouflaged as a functioning USB wall charger, that wirelessly and passively sniffs, decrypts, logs and reports back (over GSM) all keystrokes from any Microsoft wireless keyboard in the vicinity. +- [**925**星][8m] [JS] [song-li/cross_browser](https://github.com/song-li/cross_browser) cross_browser_fingerprinting +- [**924**星][5m] [PHP] [tidesec/wdscanner](https://github.com/tidesec/wdscanner) 分布式web漏洞扫描、客户管理、漏洞定期扫描、子域名枚举、端口扫描、网站爬虫、暗链检测、坏链检测、网站指纹搜集、专项漏洞检测、代理搜集及部署等功能。 +- [**924**星][1y] [C++] [miek/inspectrum](https://github.com/miek/inspectrum) analysing captured signals, primarily from software-defined radio receivers. +- [**924**星][3d] [Py] [eliben/pyelftools](https://github.com/eliben/pyelftools) Parsing ELF and DWARF in Python +- [**923**星][3m] [Ruby] [weppos/whois](https://github.com/weppos/whois) An intelligent — pure Ruby — WHOIS client and parser. +- [**923**星][2m] [Py] [tuhinshubhra/cmseek](https://github.com/tuhinshubhra/cmseek) CMS Detection and Exploitation suite - Scan WordPress, Joomla, Drupal and over 170 other CMSs +- [**923**星][3m] [Py] [sa7mon/s3scanner](https://github.com/sa7mon/s3scanner) Scan for open AWS S3 buckets and dump the contents - [**922**星][1y] [Shell] [ywb94/openwrt-ssr](https://github.com/ywb94/openwrt-ssr) ShadowsocksR-libev for OpenWrt -- [**922**星][8m] [JS] [song-li/cross_browser](https://github.com/song-li/cross_browser) cross_browser_fingerprinting -- [**922**星][15d] [Py] [knownsec/pocsuite3](https://github.com/knownsec/pocsuite3) 远程漏洞测试与PoC开发框架 -- [**922**星][2y] [JS] [diracdeltas/sniffly](https://github.com/diracdeltas/sniffly) Sniffing browser history using HSTS -- [**921**星][3m] [Ruby] [weppos/whois](https://github.com/weppos/whois) An intelligent — pure Ruby — WHOIS client and parser. -- [**920**星][2m] [Py] [tuhinshubhra/cmseek](https://github.com/tuhinshubhra/cmseek) CMS Detection and Exploitation suite - Scan WordPress, Joomla, Drupal and over 170 other CMSs -- [**920**星][2y] [HTML] [snorby/snorby](https://github.com/snorby/snorby) Ruby On Rails Application For Network Security Monitoring -- [**919**星][2y] [C#] [jaredhaight/psattack](https://github.com/jaredhaight/psattack) 组合知名的PowerShell安全工具,生成自包含/自定义的PowerShell控制台,简化在渗透中PowerShell命令的使用。支持提权、侦查、数据渗透等。 -- [**919**星][17d] [HTML] [darksecdevelopers/hiddeneye](https://github.com/darksecdevelopers/hiddeneye) Modern Phishing Tool With Advanced Functionality And Multiple Tunnelling Services [ Android-Support-Available ] -- [**918**星][6m] [JS] [reswitched/pegaswitch](https://github.com/reswitched/pegaswitch) PegaSwitch is an exploit toolkit for the Nintendo Switch -- [**918**星][1m] [Py] [eliben/pyelftools](https://github.com/eliben/pyelftools) Parsing ELF and DWARF in Python -- [**916**星][1y] [C++] [miek/inspectrum](https://github.com/miek/inspectrum) analysing captured signals, primarily from software-defined radio receivers. -- [**915**星][1m] [Go] [opensec-cn/kunpeng](https://github.com/opensec-cn/kunpeng) Golang编写的开源POC框架/库,以动态链接库的形式提供各种语言调用,通过此项目可快速开发漏洞检测类的系统。 -- [**915**星][19d] [Go] [grafeas/grafeas](https://github.com/grafeas/grafeas) Artifact Metadata API -- [**914**星][14d] [C#] [googleprojectzero/sandbox-attacksurface-analysis-tools](https://github.com/googleprojectzero/sandbox-attacksurface-analysis-tools) 沙箱攻击面(Attack Surface)分析工具,用于测试 Windows 上沙箱的各种属性 -- [**914**星][2m] [Py] [sa7mon/s3scanner](https://github.com/sa7mon/s3scanner) Scan for open AWS S3 buckets and dump the contents -- [**914**星][7y] [designativedave/androrat](https://github.com/designativedave/androrat) Remote Administration Tool for Android devices -- [**914**星][6m] [PowerShell] [api0cradle/ultimateapplockerbypasslist](https://github.com/api0cradle/ultimateapplockerbypasslist) The goal of this repository is to document the most common techniques to bypass AppLocker. -- [**913**星][5m] [PHP] [tidesec/wdscanner](https://github.com/tidesec/wdscanner) 分布式web漏洞扫描、客户管理、漏洞定期扫描、子域名枚举、端口扫描、网站爬虫、暗链检测、坏链检测、网站指纹搜集、专项漏洞检测、代理搜集及部署等功能。 -- [**912**星][1m] [tom0li/collection-document](https://github.com/tom0li/collection-document) Collection of quality safety articles -- [**912**星][8m] [C] [0x90/wifi-arsenal](https://github.com/0x90/wifi-arsenal) WiFi arsenal -- [**911**星][2m] [TeX] [ethereum/yellowpaper](https://github.com/ethereum/yellowpaper) The "Yellow Paper": Ethereum's formal specification -- [**911**星][18d] [C#] [elevenpaths/foca](https://github.com/elevenpaths/foca) Tool to find metadata and hidden information in the documents. -- [**909**星][10d] [HTML] [sprov065/v2-ui](https://github.com/sprov065/v2-ui) 支持多协议多用户的 v2ray 面板,Support multi-protocol multi-user v2ray panel +- [**922**星][2y] [C#] [jaredhaight/psattack](https://github.com/jaredhaight/psattack) 组合知名的PowerShell安全工具,生成自包含/自定义的PowerShell控制台,简化在渗透中PowerShell命令的使用。支持提权、侦查、数据渗透等。 +- [**921**星][2d] [Go] [grafeas/grafeas](https://github.com/grafeas/grafeas) Artifact Metadata API +- [**921**星][2y] [JS] [diracdeltas/sniffly](https://github.com/diracdeltas/sniffly) Sniffing browser history using HSTS +- [**919**星][2y] [HTML] [snorby/snorby](https://github.com/snorby/snorby) Ruby On Rails Application For Network Security Monitoring +- [**918**星][2d] [C#] [googleprojectzero/sandbox-attacksurface-analysis-tools](https://github.com/googleprojectzero/sandbox-attacksurface-analysis-tools) 沙箱攻击面(Attack Surface)分析工具,用于测试 Windows 上沙箱的各种属性 +- [**918**星][1m] [Go] [opensec-cn/kunpeng](https://github.com/opensec-cn/kunpeng) Golang编写的开源POC框架/库,以动态链接库的形式提供各种语言调用,通过此项目可快速开发漏洞检测类的系统。 +- [**918**星][6m] [PS] [api0cradle/ultimateapplockerbypasslist](https://github.com/api0cradle/ultimateapplockerbypasslist) The goal of this repository is to document the most common techniques to bypass AppLocker. +- [**917**星][1m] [tom0li/collection-document](https://github.com/tom0li/collection-document) Collection of quality safety articles +- [**917**星][6m] [JS] [reswitched/pegaswitch](https://github.com/reswitched/pegaswitch) PegaSwitch is an exploit toolkit for the Nintendo Switch +- [**916**星][7y] [designativedave/androrat](https://github.com/designativedave/androrat) Remote Administration Tool for Android devices +- [**914**星][8m] [C] [0x90/wifi-arsenal](https://github.com/0x90/wifi-arsenal) WiFi arsenal +- [**913**星][23d] [Go] [square/ghostunnel](https://github.com/square/ghostunnel) A simple SSL/TLS proxy with mutual authentication for securing non-TLS services +- [**912**星][8m] [ObjC] [tobefuturer/restore-symbol](https://github.com/tobefuturer/restore-symbol) A reverse engineering tool to restore stripped symbol table for iOS app. +- [**912**星][2m] [TeX] [ethereum/yellowpaper](https://github.com/ethereum/yellowpaper) The "Yellow Paper": Ethereum's formal specification +- [**912**星][7d] [C#] [elevenpaths/foca](https://github.com/elevenpaths/foca) Tool to find metadata and hidden information in the documents. +- [**912**星][3y] [Rust] [dagenix/rust-crypto](https://github.com/dagenix/rust-crypto) A (mostly) pure-Rust implementation of various cryptographic algorithms. +- [**912**星][7m] [cn0xroot/rfsec-toolkit](https://github.com/cn0xroot/rfsec-toolkit) RFSec-ToolKit is a collection of Radio Frequency Communication Protocol Hacktools.无线通信协议相关的工具集,可借助SDR硬件+相关工具对无线通信进行研究。Collect with ♥ by HackSmith +- [**910**星][8m] [HTML] [thelinuxchoice/shellphish](https://github.com/thelinuxchoice/shellphish) 针对18个社交媒体的钓鱼工具:Instagram, Facebook, Snapchat, Github, Twitter, Yahoo, Protonmail, Spotify, Netflix, Linkedin, Wordpress, Origin, Steam, Microsoft, InstaFollowers, Gitlab, Pinterest +- [**910**星][9m] [Shell] [ivanilves/xiringuito](https://github.com/ivanilves/xiringuito) SSH-based "VPN for poors" +- [**910**星][8d] [C] [arm-software/arm-trusted-firmware](https://github.com/arm-software/arm-trusted-firmware) Arm A-Profile体系结构(Armv8-A和Armv7-A)的安全世界软件的参考实现,其中包括Exception Level 3(EL3)安全监视器。 +- [**909**星][2y] [Py] [sweetsoftware/ares](https://github.com/sweetsoftware/ares) Python botnet and backdoor - [**909**星][7y] [Java] [sonyxperiadev/apkanalyser](https://github.com/sonyxperiadev/apkanalyser) -- [**909**星][6m] [cn0xroot/rfsec-toolkit](https://github.com/cn0xroot/rfsec-toolkit) RFSec-ToolKit is a collection of Radio Frequency Communication Protocol Hacktools.无线通信协议相关的工具集,可借助SDR硬件+相关工具对无线通信进行研究。Collect with ♥ by HackSmith -- [**908**星][2y] [Py] [sweetsoftware/ares](https://github.com/sweetsoftware/ares) Python botnet and backdoor -- [**908**星][1y] [Swift] [skreweverything/swift-keylogger](https://github.com/skreweverything/swift-keylogger) Keylogger for mac written in Swift using HID -- [**907**星][5y] [Py] [pwnieexpress/raspberry_pwn](https://github.com/pwnieexpress/raspberry_pwn) 树莓派渗透测试套件 -- [**907**星][3y] [Rust] [dagenix/rust-crypto](https://github.com/dagenix/rust-crypto) A (mostly) pure-Rust implementation of various cryptographic algorithms. +- [**909**星][1y] [Swift] [skreweverything/swift-keylogger](https://github.com/skreweverything/swift-keylogger) Keylogger for mac written in Swift using HID +- [**908**星][5y] [Py] [pwnieexpress/raspberry_pwn](https://github.com/pwnieexpress/raspberry_pwn) 树莓派渗透测试套件 +- [**907**星][7y] [C] [jbangert/trapcc](https://github.com/jbangert/trapcc) Computing with traps - [**906**星][7m] [C++] [dfhack/dfhack](https://github.com/DFHack/dfhack) Memory hacking library for Dwarf Fortress and a set of tools that use it -- [**906**星][8m] [Objective-C] [tobefuturer/restore-symbol](https://github.com/tobefuturer/restore-symbol) A reverse engineering tool to restore stripped symbol table for iOS app. -- [**906**星][7y] [C] [jbangert/trapcc](https://github.com/jbangert/trapcc) Computing with traps -- [**906**星][11d] [C] [arm-software/arm-trusted-firmware](https://github.com/arm-software/arm-trusted-firmware) Read-only mirror of Trusted Firmware-A -- [**904**星][3y] [Java] [summitt/burp-non-http-extension](https://github.com/summitt/burp-non-http-extension) Non-HTTP Protocol Extension (NoPE) Proxy and DNS for Burp Suite. -- [**904**星][3m] [Objective-C] [ptoomey3/keychain-dumper](https://github.com/ptoomey3/keychain-dumper) A tool to check which keychain items are available to an attacker once an iOS device has been jailbroken -- [**903**星][21d] [Go] [square/ghostunnel](https://github.com/square/ghostunnel) A simple SSL/TLS proxy with mutual authentication for securing non-TLS services -- [**903**星][17d] [Py] [mschwager/fierce](https://github.com/mschwager/fierce) A DNS reconnaissance tool for locating non-contiguous IP space. -- [**902**星][8m] [HTML] [thelinuxchoice/shellphish](https://github.com/thelinuxchoice/shellphish) 针对18个社交媒体的钓鱼工具:Instagram, Facebook, Snapchat, Github, Twitter, Yahoo, Protonmail, Spotify, Netflix, Linkedin, Wordpress, Origin, Steam, Microsoft, InstaFollowers, Gitlab, Pinterest -- [**902**星][1y] [Go] [huacnlee/flora-kit](https://github.com/huacnlee/flora-kit) 基于 shadowsocks-go 做的完善实现,完全兼容 Surge 的配置文件 +- [**906**星][3y] [Java] [summitt/burp-non-http-extension](https://github.com/summitt/burp-non-http-extension) Non-HTTP Protocol Extension (NoPE) Proxy and DNS for Burp Suite. +- [**906**星][19d] [Py] [mschwager/fierce](https://github.com/mschwager/fierce) A DNS reconnaissance tool for locating non-contiguous IP space. +- [**906**星][5m] [Py] [m0rtem/cloudfail](https://github.com/m0rtem/cloudfail) 通过错误配置的DNS和老数据库,发现CloudFlare网络后面的隐藏IP +- [**905**星][2d] [C++] [seladb/pcapplusplus](https://github.com/seladb/pcapplusplus) PcapPlusPlus is a multiplatform C++ library for capturing, parsing and crafting of network packets. It is designed to be efficient, powerful and easy to use. It provides C++ wrappers for the most popular packet processing engines such as libpcap, WinPcap, DPDK and PF_RING. +- [**904**星][3m] [ObjC] [ptoomey3/keychain-dumper](https://github.com/ptoomey3/keychain-dumper) A tool to check which keychain items are available to an attacker once an iOS device has been jailbroken +- [**904**星][1y] [Go] [huacnlee/flora-kit](https://github.com/huacnlee/flora-kit) 基于 shadowsocks-go 做的完善实现,完全兼容 Surge 的配置文件 +- [**903**星][6y] [C] [visgean/zeus](https://github.com/visgean/zeus) NOT MY CODE! Zeus trojan horse - leaked in 2011, I am not the author. I have created this repository to make the access for study as easy as possible. +- [**903**星][6d] [C] [cossacklabs/themis](https://github.com/cossacklabs/themis) 用于存储或通信的加密库,可用于Swift, ObjC, Android, С++, JS, Python, Ruby, PHP, Go。 +- [**902**星][28d] [Go] [mehrdadrad/radvpn](https://github.com/mehrdadrad/radvpn) Decentralized VPN +- [**901**星][8d] [Py] [hasecuritysolutions/vulnwhisperer](https://github.com/HASecuritySolutions/VulnWhisperer) Create actionable data from your Vulnerability Scans - [**901**星][1y] [Py] [nixawk/labs](https://github.com/nixawk/labs) 漏洞分析实验室。包含若干CVE 漏洞(CVE-2016-6277、CVE-2017-5689…) -- [**899**星][6y] [C] [visgean/zeus](https://github.com/visgean/zeus) NOT MY CODE! Zeus trojan horse - leaked in 2011, I am not the author. I have created this repository to make the access for study as easy as possible. -- [**899**星][10d] [C] [cossacklabs/themis](https://github.com/cossacklabs/themis) 用于存储或通信的加密库,可用于Swift, ObjC, Android, С++, JS, Python, Ruby, PHP, Go。 -- [**897**星][3m] [Py] [hasecuritysolutions/vulnwhisperer](https://github.com/HASecuritySolutions/VulnWhisperer) Create actionable data from your Vulnerability Scans - [**897**星][5y] [Java] [wszf/androrat](https://github.com/wszf/androrat) Remote Administration Tool for Android -- [**896**星][2y] [Ruby] [whitewidowscanner/whitewidow](https://github.com/whitewidowscanner/whitewidow) SQL Vulnerability Scanner -- [**896**星][5m] [Py] [m0rtem/cloudfail](https://github.com/m0rtem/cloudfail) 通过错误配置的DNS和老数据库,发现CloudFlare网络后面的隐藏IP -- [**895**星][10m] [C++] [secrary/injectproc](https://github.com/secrary/injectproc) Process Injection Techniques [This project is not maintained anymore] -- [**893**星][12d] [C++] [adafruit/adafruit_ssd1306](https://github.com/adafruit/adafruit_ssd1306) Arduino library for SSD1306 monochrome 128x64 and 128x32 OLEDs -- [**892**星][1m] [Py] [woj-ciech/leaklooker](https://github.com/woj-ciech/leaklooker) Find open databases - Powered by Binaryedge.io -- [**891**星][11m] [JS] [levskaya/jslinux-deobfuscated](https://github.com/levskaya/jslinux-deobfuscated) An old version of Mr. Bellard's JSLinux rewritten to be human readable, hand deobfuscated and annotated. -- [**888**星][11d] [Shell] [dominicbreuker/stego-toolkit](https://github.com/dominicbreuker/stego-toolkit) Collection of steganography tools - helps with CTF challenges +- [**897**星][13d] [Shell] [dominicbreuker/stego-toolkit](https://github.com/dominicbreuker/stego-toolkit) Collection of steganography tools - helps with CTF challenges +- [**896**星][1m] [Py] [woj-ciech/leaklooker](https://github.com/woj-ciech/leaklooker) Find open databases - Powered by Binaryedge.io +- [**896**星][10m] [C++] [secrary/injectproc](https://github.com/secrary/injectproc) Process Injection Techniques [This project is not maintained anymore] +- [**896**星][14d] [C++] [adafruit/adafruit_ssd1306](https://github.com/adafruit/adafruit_ssd1306) Arduino library for SSD1306 monochrome 128x64 and 128x32 OLEDs +- [**894**星][2y] [Ruby] [whitewidowscanner/whitewidow](https://github.com/whitewidowscanner/whitewidow) SQL Vulnerability Scanner +- [**894**星][3m] [Py] [trustedsec/hate_crack](https://github.com/trustedsec/hate_crack) 使用HashCat 的自动哈希破解工具 +- [**893**星][11m] [JS] [levskaya/jslinux-deobfuscated](https://github.com/levskaya/jslinux-deobfuscated) An old version of Mr. Bellard's JSLinux rewritten to be human readable, hand deobfuscated and annotated. +- [**891**星][4m] [derpopo/uabe](https://github.com/derpopo/uabe) Unity Assets Bundle Extractor +- [**890**星][30d] [Go] [smallstep/cli](https://github.com/smallstep/cli) 🧰 A zero trust swiss army knife for working with X509, OAuth, JWT, OATH OTP, etc. +- [**889**星][9d] [Py] [swisskyrepo/ssrfmap](https://github.com/swisskyrepo/ssrfmap) Automatic SSRF fuzzer and exploitation tool +- [**888**星][11d] [C] [buserror/simavr](https://github.com/buserror/simavr) simavr is a lean, mean and hackable AVR simulator for linux & OSX - [**887**星][12m] [Py] [rev3rsesecurity/webmap](https://github.com/rev3rsesecurity/webmap) Nmap Web Dashboard and Reporting -- [**886**星][2m] [Py] [trustedsec/hate_crack](https://github.com/trustedsec/hate_crack) 使用HashCat 的自动哈希破解工具 +- [**887**星][2y] [Perl] [p0pr0ck5/lua-resty-waf](https://github.com/p0pr0ck5/lua-resty-waf) High-performance WAF built on the OpenResty stack +- [**886**星][2y] [PS] [windowsexploits/exploits](https://github.com/windowsexploits/exploits) Windows Exploits +- [**886**星][9d] [Py] [ajinabraham/nodejsscan](https://github.com/ajinabraham/nodejsscan) NodeJsScan is a static security code scanner for Node.js applications. - [**885**星][4m] [C] [theofficialflow/h-encore](https://github.com/theofficialflow/h-encore) Fully chained kernel exploit for the PS Vita on firmwares 3.65-3.68 -- [**885**星][4m] [derpopo/uabe](https://github.com/derpopo/uabe) Unity Assets Bundle Extractor +- [**885**星][5m] [JS] [dpnishant/appmon](https://github.com/dpnishant/appmon) 用于监视和篡改本地macOS,iOS和android应用程序的系统API调用的自动化框架。基于Frida。 - [**884**星][2y] [Py] [nsacyber/gosecure](https://github.com/nsacyber/goSecure) An easy to use and portable Virtual Private Network (VPN) system built with Linux and a Raspberry Pi. #nsacyber -- [**884**星][8d] [C] [buserror/simavr](https://github.com/buserror/simavr) simavr is a lean, mean and hackable AVR simulator for linux & OSX -- [**883**星][2y] [Perl] [p0pr0ck5/lua-resty-waf](https://github.com/p0pr0ck5/lua-resty-waf) High-performance WAF built on the OpenResty stack -- [**882**星][28d] [Go] [smallstep/cli](https://github.com/smallstep/cli) 🧰 A zero trust swiss army knife for working with X509, OAuth, JWT, OATH OTP, etc. -- [**881**星][2y] [PowerShell] [windowsexploits/exploits](https://github.com/windowsexploits/exploits) Windows Exploits -- [**880**星][1m] [Py] [swisskyrepo/ssrfmap](https://github.com/swisskyrepo/ssrfmap) Automatic SSRF fuzzer and exploitation tool -- [**880**星][5m] [JS] [dpnishant/appmon](https://github.com/dpnishant/appmon) Documentation: -- [**880**星][7d] [Py] [ajinabraham/nodejsscan](https://github.com/ajinabraham/nodejsscan) NodeJsScan is a static security code scanner for Node.js applications. -- [**877**星][25d] [C++] [whid-injector/whid](https://github.com/whid-injector/whid) WiFi HID Injector - An USB Rubberducky / BadUSB On Steroids. +- [**884**星][27d] [C++] [whid-injector/whid](https://github.com/whid-injector/whid) WiFi HID Injector - An USB Rubberducky / BadUSB On Steroids. +- [**882**星][4m] [Kotlin] [eycorsican/kitsunebi-android](https://github.com/eycorsican/kitsunebi-android) A fully-featured V2Ray client for Android. +- [**879**星][5d] [Py] [derekselander/lldb](https://github.com/derekselander/lldb) A collection of LLDB aliases/regexes and Python scripts to aid in your debugging sessions +- [**879**星][7d] [C] [apple/cups](https://github.com/apple/cups) a standards-based, open source printing system +- [**878**星][3d] [JS] [opencti-platform/opencti](https://github.com/opencti-platform/opencti) Open Cyber Threat Intelligence Platform +- [**878**星][3y] [bastilleresearch/mousejack](https://github.com/bastilleresearch/mousejack) MouseJack device discovery and research tools +- [**878**星][21d] [aptnotes/data](https://github.com/aptnotes/data) APTnotes data +- [**877**星][1m] [HTML] [hookmaster/frida-all-in-one](https://github.com/hookmaster/frida-all-in-one) 《FRIDA操作手册》by +- [**877**星][2m] [C] [504ensicslabs/lime](https://github.com/504ensicslabs/lime) LiME (formerly DMD) is a Loadable Kernel Module (LKM), which allows the acquisition of volatile memory from Linux and Linux-based devices, such as those powered by Android. The tool supports acquiring memory either to the file system of the device or over the network. LiME is unique in that it is the first tool that allows full memory captures f… +- [**876**星][2d] [C] [u-boot/u-boot](https://github.com/u-boot/u-boot) "Das U-Boot" Source Tree +- [**876**星][4m] [CSS] [outflanknl/redelk](https://github.com/outflanknl/redelk) 跟踪和警告Blue Team活动以及长期运营中的更高可用性 +- [**875**星][10m] [C++] [wisk/medusa](https://github.com/wisk/medusa) An open source interactive disassembler +- [**875**星][2m] [Ruby] [w181496/web-ctf-cheatsheet](https://github.com/w181496/web-ctf-cheatsheet) Web CTF CheatSheet - [**875**星][2y] [Py] [marcwebbie/passpie](https://github.com/marcwebbie/passpie) 命令行中管理密码 -- [**875**星][3y] [bastilleresearch/mousejack](https://github.com/bastilleresearch/mousejack) MouseJack device discovery and research tools -- [**874**星][10m] [C++] [wisk/medusa](https://github.com/wisk/medusa) An open source interactive disassembler -- [**873**星][2y] [C] [paboldin/meltdown-exploit](https://github.com/paboldin/meltdown-exploit) Meltdown exploit -- [**873**星][4m] [CSS] [outflanknl/redelk](https://github.com/outflanknl/redelk) Red Team's SIEM - tool for Red Teams used for tracking and alarming about Blue Team activities as well as better usability in long term operations. -- [**873**星][2m] [C] [504ensicslabs/lime](https://github.com/504ensicslabs/lime) LiME (formerly DMD) is a Loadable Kernel Module (LKM), which allows the acquisition of volatile memory from Linux and Linux-based devices, such as those powered by Android. The tool supports acquiring memory either to the file system of the device or over the network. LiME is unique in that it is the first tool that allows full memory captures f… -- [**872**星][12d] [C] [u-boot/u-boot](https://github.com/u-boot/u-boot) "Das U-Boot" Source Tree -- [**872**星][7d] [JS] [opencti-platform/opencti](https://github.com/opencti-platform/opencti) Open Cyber Threat Intelligence Platform -- [**872**星][7d] [C] [apple/cups](https://github.com/apple/cups) a standards-based, open source printing system -- [**871**星][7m] [Py] [erocarrera/pefile](https://github.com/erocarrera/pefile) pefile is a Python module to read and work with PE (Portable Executable) files -- [**871**星][19d] [aptnotes/data](https://github.com/aptnotes/data) APTnotes data -- [**870**星][8m] [Py] [redacted/xkcd-password-generator](https://github.com/redacted/xkcd-password-generator) Generate secure multiword passwords/passphrases, inspired by XKCD -- [**869**星][3m] [Py] [w-digital-scanner/w9scan](https://github.com/w-digital-scanner/w9scan) Plug-in type web vulnerability scanner -- [**869**星][18d] [Go] [itchyny/bed](https://github.com/itchyny/bed) Binary editor written in Go -- [**868**星][2y] [C] [aircrack-ng/aircrack-ng-archive](https://github.com/aircrack-ng/aircrack-ng-archive) Pre-migration repository. New repository ➙ -- [**868**星][5m] [Py] [derekselander/lldb](https://github.com/derekselander/lldb) A collection of LLDB aliases/regexes and Python scripts to aid in your debugging sessions -- [**867**星][1m] [C] [cisco/joy](https://github.com/cisco/joy) 捕获和分析网络流数据和intraflow数据,用于网络研究、取证和安全监视 +- [**875**星][7m] [Py] [erocarrera/pefile](https://github.com/erocarrera/pefile) pefile is a Python module to read and work with PE (Portable Executable) files +- [**874**星][3m] [Py] [w-digital-scanner/w9scan](https://github.com/w-digital-scanner/w9scan) Plug-in type web vulnerability scanner +- [**874**星][8m] [Py] [redacted/xkcd-password-generator](https://github.com/redacted/xkcd-password-generator) Generate secure multiword passwords/passphrases, inspired by XKCD +- [**872**星][1m] [C] [cisco/joy](https://github.com/cisco/joy) 捕获和分析网络流数据和intraflow数据,用于网络研究、取证和安全监视 +- [**871**星][2y] [C] [paboldin/meltdown-exploit](https://github.com/paboldin/meltdown-exploit) Meltdown exploit +- [**871**星][3m] [escapingbug/awesome-browser-exploit](https://github.com/escapingbug/awesome-browser-exploit) awesome list of browser exploitation tutorials +- [**870**星][1m] [C] [zhaojh329/rtty](https://github.com/zhaojh329/rtty) Access your device's terminal from anywhere via the web. +- [**870**星][20d] [Go] [itchyny/bed](https://github.com/itchyny/bed) Binary editor written in Go +- [**870**星][1m] [Py] [al0ne/vxscan](https://github.com/al0ne/vxscan) python3写的综合扫描工具,主要用来存活验证,敏感文件探测(目录扫描/js泄露接口/html注释泄露),WAF/CDN识别,端口扫描,指纹/服务识别,操作系统识别,POC扫描,SQL注入,绕过CDN,查询旁站等功能,主要用来甲方自测或乙方授权测试,请勿用来搞破坏。 +- [**870**星][6m] [Go] [40t/go-sniffer](https://github.com/40t/go-sniffer) +- [**867**星][2y] [C] [aircrack-ng/aircrack-ng-archive](https://github.com/aircrack-ng/aircrack-ng-archive) Pre-migration repository. New repository ➙ - [**867**星][3m] [Java] [googlearchive/android-bluetoothlegatt](https://github.com/googlearchive/android-BluetoothLeGatt) Migrated: -- [**867**星][1m] [HTML] [hookmaster/frida-all-in-one](https://github.com/hookmaster/frida-all-in-one) 《FRIDA操作手册》by -- [**866**星][1m] [C] [zhaojh329/rtty](https://github.com/zhaojh329/rtty) Access your device's terminal from anywhere via the web. -- [**865**星][2m] [Ruby] [w181496/web-ctf-cheatsheet](https://github.com/w181496/web-ctf-cheatsheet) Web CTF CheatSheet -- [**864**星][2y] [C++] [illera88/ponce](https://github.com/illera88/ponce) 简化污点分析+符号执行 -- [**864**星][10m] [Shell] [esc0rtd3w/wifi-hacker](https://github.com/esc0rtd3w/wifi-hacker) Shell Script For Attacking Wireless Connections Using Built-In Kali Tools. Supports All Securities (WEP, WPS, WPA, WPA2) -- [**863**星][8m] [C++] [google/security-research-pocs](https://github.com/google/security-research-pocs) Proof-of-concept codes created as part of security research done by Google Security Team. -- [**863**星][4m] [Go] [fireeye/gocrack](https://github.com/fireeye/gocrack) 火眼开源的密码破解工具,可以跨多个 GPU 服务器执行任务 -- [**863**星][3m] [escapingbug/awesome-browser-exploit](https://github.com/escapingbug/awesome-browser-exploit) awesome list of browser exploitation tutorials -- [**862**星][4m] [Kotlin] [eycorsican/kitsunebi-android](https://github.com/eycorsican/kitsunebi-android) A fully-featured V2Ray client for Android. -- [**862**星][10m] [Visual Basic] [mdsecactivebreach/sharpshooter](https://github.com/mdsecactivebreach/sharpshooter) Payload Generation Framework +- [**867**星][8m] [C++] [google/security-research-pocs](https://github.com/google/security-research-pocs) Proof-of-concept codes created as part of security research done by Google Security Team. +- [**867**星][4m] [Go] [fireeye/gocrack](https://github.com/fireeye/gocrack) 火眼开源的密码破解工具,可以跨多个 GPU 服务器执行任务 +- [**866**星][10m] [Shell] [esc0rtd3w/wifi-hacker](https://github.com/esc0rtd3w/wifi-hacker) Shell Script For Attacking Wireless Connections Using Built-In Kali Tools. Supports All Securities (WEP, WPS, WPA, WPA2) +- [**865**星][10m] [Visual Basic .NET] [mdsecactivebreach/sharpshooter](https://github.com/mdsecactivebreach/sharpshooter) Payload Generation Framework +- [**865**星][2y] [C++] [illera88/ponce](https://github.com/illera88/ponce) 简化污点分析+符号执行 +- [**865**星][8d] [PHP] [ambionics/phpggc](https://github.com/ambionics/phpggc) PHPGGC is a library of PHP unserialize() payloads along with a tool to generate them, from command line or programmatically. +- [**863**星][9d] [Batchfile] [mr-xn/burpsuite-collections](https://github.com/mr-xn/burpsuite-collections) BurpSuite收集:包括不限于 Burp 文章、破解版、插件(非BApp Store)、汉化等相关教程,欢迎添砖加瓦---burpsuite-pro burpsuite-extender burpsuite cracked-version hackbar hacktools fuzzing fuzz-testing burp-plugin burp-extensions bapp-store brute-force-attacks brute-force-passwords waf sqlmap jar +- [**863**星][15d] [Java] [lamster2018/easyprotector](https://github.com/lamster2018/easyprotector) 一行代码检测XP/调试/多开/模拟器/root +- [**862**星][3d] [explife0011/awesome-windows-kernel-security-development](https://github.com/explife0011/awesome-windows-kernel-security-development) windows kernel security development +- [**861**星][10d] [Py] [jimmy201602/webterminal](https://github.com/jimmy201602/webterminal) ssh rdp vnc telnet sftp bastion/jump web putty xshell terminal jumpserver audit realtime monitor rz/sz 堡垒机 云桌面 linux devops sftp websocket file management rz/sz 自动化运维 审计 录像 文件管理 sftp上传 实时监控 录像回放 网页版rz/sz上传下载 django - [**860**星][2m] [jonascz/how-to-prevent-scraping](https://github.com/jonascz/how-to-prevent-scraping) The ultimate guide on preventing Website Scraping -- [**859**星][6m] [Go] [40t/go-sniffer](https://github.com/40t/go-sniffer) -- [**857**星][7m] [Py] [s0md3v/recondog](https://github.com/s0md3v/ReconDog) Reconnaissance Swiss Army Knife -- [**857**星][1m] [Py] [al0ne/vxscan](https://github.com/al0ne/vxscan) python3写的综合扫描工具,主要用来存活验证,敏感文件探测(目录扫描/js泄露接口/html注释泄露),WAF/CDN识别,端口扫描,指纹/服务识别,操作系统识别,POC扫描,SQL注入,绕过CDN,查询旁站等功能,主要用来甲方自测或乙方授权测试,请勿用来搞破坏。 -- [**856**星][1y] [Ruby] [enjoiz/xxeinjector](https://github.com/enjoiz/xxeinjector) Tool for automatic exploitation of XXE vulnerability using direct and different out of band methods. -- [**855**星][8d] [explife0011/awesome-windows-kernel-security-development](https://github.com/explife0011/awesome-windows-kernel-security-development) windows kernel security development -- [**854**星][10m] [Shell] [shadowsocks/luci-app-shadowsocks](https://github.com/shadowsocks/luci-app-shadowsocks) OpenWrt/LEDE LuCI for Shadowsocks-libev -- [**854**星][2y] [CoffeeScript] [onplus/shadowsocks-heroku](https://github.com/onplus/shadowsocks-heroku) 一键部署 Free Shadowsocks-Heroku -- [**853**星][4m] [Py] [lijiejie/bbscan](https://github.com/lijiejie/bbscan) A vulnerability scanner focus on scanning large number of targets in short time with a minimal set of rules. -- [**852**星][1m] [ignitetechnologies/privilege-escalation](https://github.com/ignitetechnologies/privilege-escalation) This cheasheet is aimed at the CTF Players and Beginners to help them understand the fundamentals of Privilege Escalation with examples. -- [**852**星][7d] [Py] [circl/ail-framework](https://github.com/circl/ail-framework) AIL framework - Analysis Information Leak framework +- [**860**星][7m] [Py] [s0md3v/recondog](https://github.com/s0md3v/ReconDog) Reconnaissance Swiss Army Knife +- [**858**星][10m] [Shell] [shadowsocks/luci-app-shadowsocks](https://github.com/shadowsocks/luci-app-shadowsocks) OpenWrt/LEDE LuCI for Shadowsocks-libev +- [**858**星][18d] [Py] [ticarpi/jwt_tool](https://github.com/ticarpi/jwt_tool) 测试,调整和破解JSON Web Token 的工具包 +- [**858**星][2m] [ignitetechnologies/privilege-escalation](https://github.com/ignitetechnologies/privilege-escalation) This cheasheet is aimed at the CTF Players and Beginners to help them understand the fundamentals of Privilege Escalation with examples. +- [**858**星][1y] [Ruby] [enjoiz/xxeinjector](https://github.com/enjoiz/xxeinjector) Tool for automatic exploitation of XXE vulnerability using direct and different out of band methods. +- [**857**星][4d] [JS] [mellow-io/mellow](https://github.com/mellow-io/mellow) Mellow is a rule-based global transparent proxy client for Windows, macOS and Linux. +- [**857**星][2d] [Py] [circl/ail-framework](https://github.com/circl/ail-framework) AIL framework - Analysis Information Leak framework +- [**856**星][4m] [Py] [lijiejie/bbscan](https://github.com/lijiejie/bbscan) A vulnerability scanner focus on scanning large number of targets in short time with a minimal set of rules. +- [**855**星][2y] [CoffeeScript] [onplus/shadowsocks-heroku](https://github.com/onplus/shadowsocks-heroku) 一键部署 Free Shadowsocks-Heroku +- [**855**星][3d] [C++] [google/uiforetw](https://github.com/google/uiforetw) User interface for recording and managing ETW traces +- [**854**星][10m] [Shell] [thelinuxchoice/userrecon](https://github.com/thelinuxchoice/userrecon) Find usernames across over 75 social networks +- [**854**星][3m] [Py] [649/memcrashed-ddos-exploit](https://github.com/649/memcrashed-ddos-exploit) DDoS attack tool for sending forged UDP packets to vulnerable Memcached servers obtained using Shodan API +- [**853**星][2y] [PS] [curi0usjack/luckystrike](https://github.com/curi0usJack/luckystrike) A PowerShell based utility for the creation of malicious Office macro documents. +- [**853**星][2m] [JS] [vksrc/github-monitor](https://github.com/vksrc/github-monitor) Github Sensitive Information Leakage Monitor(Github信息泄漏监控系统) +- [**853**星][2m] [Go] [ukhomeoffice/repo-security-scanner](https://github.com/ukhomeoffice/repo-security-scanner) CLI tool that finds secrets accidentally committed to a git repo, eg passwords, private keys +- [**853**星][7m] [Go] [misecurity/x-patrol](https://github.com/misecurity/x-patrol) github泄露扫描系统 +- [**852**星][2d] [C++] [henrypp/simplewall](https://github.com/henrypp/simplewall) 为Windows 过滤平台提供的配置界面 +- [**852**星][3y] [C++] [0vercl0k/rp](https://github.com/0vercl0k/rp) rp++ is a full-cpp written tool that aims to find ROP sequences in PE/Elf/Mach-O x86/x64 binaries. It is open-source and has been tested on several OS: Debian / Windows 8.1 / Mac OSX Lion (10.7.3). Moreover, it is x64 compatible and supports Intel syntax. Standalone executables can also be directly downloaded. - [**851**星][1m] [Go] [sahilm/fuzzy](https://github.com/sahilm/fuzzy) Go library that provides fuzzy string matching optimized for filenames and code symbols in the style of Sublime Text, VSCode, IntelliJ IDEA et al. -- [**851**星][7m] [Go] [misecurity/x-patrol](https://github.com/misecurity/x-patrol) github泄露扫描系统 -- [**851**星][3m] [Py] [649/memcrashed-ddos-exploit](https://github.com/649/memcrashed-ddos-exploit) DDoS attack tool for sending forged UDP packets to vulnerable Memcached servers obtained using Shodan API -- [**850**星][2m] [Go] [ukhomeoffice/repo-security-scanner](https://github.com/ukhomeoffice/repo-security-scanner) CLI tool that finds secrets accidentally committed to a git repo, eg passwords, private keys -- [**850**星][3y] [Py] [hubert3/isniff-gps](https://github.com/hubert3/isniff-gps) Passive sniffing tool for capturing and visualising WiFi location data disclosed by iOS devices -- [**850**星][15d] [PHP] [ambionics/phpggc](https://github.com/ambionics/phpggc) PHPGGC is a library of PHP unserialize() payloads along with a tool to generate them, from command line or programmatically. -- [**849**星][2y] [PowerShell] [curi0usjack/luckystrike](https://github.com/curi0usJack/luckystrike) A PowerShell based utility for the creation of malicious Office macro documents. -- [**849**星][10m] [Shell] [thelinuxchoice/userrecon](https://github.com/thelinuxchoice/userrecon) Find usernames across over 75 social networks -- [**847**星][12m] [PHP] [walkor/shadowsocks-php](https://github.com/walkor/shadowsocks-php) A php port of shadowsocks based on workerman. A socks5 proxy written in PHP. -- [**847**星][2m] [JS] [vksrc/github-monitor](https://github.com/vksrc/github-monitor) Github Sensitive Information Leakage Monitor(Github信息泄漏监控系统) +- [**851**星][13d] [Py] [nil0x42/phpsploit](https://github.com/nil0x42/phpsploit) Stealth post-exploitation framework +- [**851**星][3y] [Py] [hubert3/isniff-gps](https://github.com/hubert3/isniff-gps) Passive sniffing tool for capturing and visualising WiFi location data disclosed by iOS devices +- [**851**星][7d] [JS] [cloudsploit/scans](https://github.com/cloudsploit/scans) Cloud security configuration checks +- [**850**星][1m] [C] [spacehuhn/wifi_ducky](https://github.com/spacehuhn/wifi_ducky) Upload, save and run keystroke injection payloads with an ESP8266 + ATMEGA32U4 +- [**849**星][3d] [C] [zerbea/hcxtools](https://github.com/zerbea/hcxtools) Portable solution for capturing wlan traffic and conversion to hashcat formats (recommended by hashcat) and to John the Ripper formats. hcx: h = hash, c = capture, convert and calculate candidates, x = different hashtypes +- [**849**星][29d] [Roff] [slimm609/checksec.sh](https://github.com/slimm609/checksec.sh) 检查可执行文件(PIE, RELRO, PaX, Canaries, ASLR, Fortify Source)属性的 bash 脚本 +- [**849**星][5d] [Py] [lylemi/learn-web-hacking](https://github.com/lylemi/learn-web-hacking) Web安全学习笔记 +- [**848**星][12m] [PHP] [walkor/shadowsocks-php](https://github.com/walkor/shadowsocks-php) A php port of shadowsocks based on workerman. A socks5 proxy written in PHP. - [**847**星][4y] [utkusen/hidden-tear](https://github.com/utkusen/hidden-tear) an open source ransomware honeypot -- [**846**星][11d] [Py] [nil0x42/phpsploit](https://github.com/nil0x42/phpsploit) Stealth post-exploitation framework -- [**846**星][13d] [Java] [lamster2018/easyprotector](https://github.com/lamster2018/easyprotector) 一行代码检测XP/调试/多开/模拟器/root -- [**846**星][17d] [JS] [cloudsploit/scans](https://github.com/cloudsploit/scans) Cloud security configuration checks -- [**846**星][3y] [C++] [0vercl0k/rp](https://github.com/0vercl0k/rp) rp++ is a full-cpp written tool that aims to find ROP sequences in PE/Elf/Mach-O x86/x64 binaries. It is open-source and has been tested on several OS: Debian / Windows 8.1 / Mac OSX Lion (10.7.3). Moreover, it is x64 compatible and supports Intel syntax. Standalone executables can also be directly downloaded. +- [**847**星][2y] [Py] [nccgroup/demiguise](https://github.com/nccgroup/demiguise) HTA加密 +- [**847**星][3m] [Py] [anorov/pysocks](https://github.com/anorov/pysocks) A SOCKS proxy client and wrapper for Python. +- [**846**星][2d] [Shell] [firmadyne/firmadyne](https://github.com/firmadyne/firmadyne) Platform for emulation and dynamic analysis of Linux-based firmware +- [**846**星][3y] [C] [examplecode/mproxy](https://github.com/examplecode/mproxy) c 语言实现的一个最小的http代理,支持翻墙 - [**845**星][1y] [Py] [kgretzky/evilginx](https://github.com/kgretzky/evilginx) man-in-the-middle attack framework used for phishing credentials and session cookies of any web service -- [**845**星][3m] [Py] [anorov/pysocks](https://github.com/anorov/pysocks) A SOCKS proxy client and wrapper for Python. -- [**844**星][2y] [Py] [nccgroup/demiguise](https://github.com/nccgroup/demiguise) HTA encryption tool for RedTeams -- [**843**星][1m] [C] [spacehuhn/wifi_ducky](https://github.com/spacehuhn/wifi_ducky) Upload, save and run keystroke injection payloads with an ESP8266 + ATMEGA32U4 -- [**843**星][8m] [JS] [serpicoproject/serpico](https://github.com/serpicoproject/serpico) SimplE RePort wrIting and COllaboration tool -- [**842**星][10d] [Py] [lylemi/learn-web-hacking](https://github.com/lylemi/learn-web-hacking) Study Notes For Web Hacking / Web安全学习笔记 +- [**844**星][3m] [Py] [x90skysn3k/brutespray](https://github.com/x90skysn3k/brutespray) 获取 nmapGNMAP 输出,自动调用 Medusa 使用默认证书爆破服务(brute-forces services) +- [**844**星][8m] [JS] [serpicoproject/serpico](https://github.com/serpicoproject/serpico) 渗透测试报告生成和协作工具 +- [**844**星][3d] [C++] [openzwave/open-zwave](https://github.com/openzwave/open-zwave) a C++ library to control Z-Wave Networks via a USB Z-Wave Controller. +- [**844**星][3d] [YARA] [neo23x0/signature-base](https://github.com/neo23x0/signature-base) Signature base for my scanner tools +- [**843**星][6m] [C] [brendan-rius/c-jwt-cracker](https://github.com/brendan-rius/c-jwt-cracker) C 语言编写的 JWT 爆破工具 - [**842**星][3y] [Shell] [hellofwy/ss-bash](https://github.com/hellofwy/ss-bash) Shadowsocks流量管理脚本 -- [**842**星][30d] [C++] [google/uiforetw](https://github.com/google/uiforetw) User interface for recording and managing ETW traces -- [**842**星][15d] [C] [emsec/chameleonmini](https://github.com/emsec/chameleonmini) The ChameleonMini is a versatile contactless smartcard emulator compliant to NFC. The ChameleonMini was developed by -- [**841**星][27d] [Roff] [slimm609/checksec.sh](https://github.com/slimm609/checksec.sh) 检查可执行文件(PIE, RELRO, PaX, Canaries, ASLR, Fortify Source)属性的 bash 脚本 -- [**841**星][8d] [C++] [openzwave/open-zwave](https://github.com/openzwave/open-zwave) a C++ library to control Z-Wave Networks via a USB Z-Wave Controller. -- [**841**星][3y] [C] [gurnec/hashcheck](https://github.com/gurnec/hashcheck) HashCheck Shell Extension for Windows with added SHA2, SHA3, and multithreading; originally from code.kliu.org -- [**840**星][12d] [C++] [seladb/pcapplusplus](https://github.com/seladb/pcapplusplus) PcapPlusPlus is a multiplatform C++ library for capturing, parsing and crafting of network packets. It is designed to be efficient, powerful and easy to use. It provides C++ wrappers for the most popular packet processing engines such as libpcap, WinPcap, DPDK and PF_RING. -- [**840**星][21d] [C++] [henrypp/simplewall](https://github.com/henrypp/simplewall) 为Windows 过滤平台提供的配置界面 -- [**840**星][3m] [Shell] [firmadyne/firmadyne](https://github.com/firmadyne/firmadyne) Platform for emulation and dynamic analysis of Linux-based firmware -- [**838**星][26d] [YARA] [neo23x0/signature-base](https://github.com/neo23x0/signature-base) Signature base for my scanner tools -- [**837**星][10d] [C] [zerbea/hcxtools](https://github.com/zerbea/hcxtools) Portable solution for capturing wlan traffic and conversion to hashcat formats (recommended by hashcat) and to John the Ripper formats. hcx: h = hash, c = capture, convert and calculate candidates, x = different hashtypes -- [**837**星][3m] [Py] [x90skysn3k/brutespray](https://github.com/x90skysn3k/brutespray) 获取 nmapGNMAP 输出,自动调用 Medusa 使用默认证书爆破服务(brute-forces services) -- [**837**星][2m] [Go] [henson/proxypool](https://github.com/henson/proxypool) Golang实现的IP代理池 -- [**836**星][1m] [C] [facebook/transform360](https://github.com/facebook/transform360) Transform360 is an equirectangular to cubemap transform for 360 video. -- [**836**星][1y] [HTML] [ustayready/credsniper](https://github.com/ustayready/credsniper) CredSniper is a phishing framework written with the Python micro-framework Flask and Jinja2 templating which supports capturing 2FA tokens. -- [**836**星][7d] [trimstray/iptables-essentials](https://github.com/trimstray/iptables-essentials) Common Firewall Rules and Commands. -- [**836**星][16d] [Py] [ticarpi/jwt_tool](https://github.com/ticarpi/jwt_tool) 测试,调整和破解JSON Web Token 的工具包 -- [**835**星][7d] [Java] [sleuthkit/autopsy](https://github.com/sleuthkit/autopsy) Autopsy® is a digital forensics platform and graphical interface to The Sleuth Kit® and other digital forensics tools. It can be used by law enforcement, military, and corporate examiners to investigate what happened on a computer. You can even use it to recover photos from your camera's memory card. -- [**835**星][3y] [Py] [ring04h/weakfilescan](https://github.com/ring04h/weakfilescan) 动态多线程敏感信息泄露检测工具 -- [**835**星][7m] [Shell] [niklasb/libc-database](https://github.com/niklasb/libc-database) Build a database of libc offsets to simplify exploitation -- [**835**星][1y] [Shell] [kpwn/iosre](https://github.com/kpwn/iosre) iOS Reverse Engineering -- [**835**星][13d] [Py] [jordanpotti/awsbucketdump](https://github.com/jordanpotti/awsbucketdump) 快速枚举 AWS S3 Buckets,查找感兴趣的文件。类似于子域名爆破,但针对S3 Bucket,有额外功能,例如下载文件等 -- [**834**星][25d] [PHP] [raikia/fiercephish](https://github.com/Raikia/FiercePhish) FiercePhish is a full-fledged phishing framework to manage all phishing engagements. It allows you to track separate phishing campaigns, schedule sending of emails, and much more. -- [**834**星][6m] [C] [brendan-rius/c-jwt-cracker](https://github.com/brendan-rius/c-jwt-cracker) C 语言编写的 JWT 爆破工具 -- [**834**星][26d] [C#] [borntoberoot/networkmanager](https://github.com/borntoberoot/networkmanager) A powerful tool for managing networks and troubleshoot network problems! -- [**833**星][7m] [Objective-C] [sevenbits/mac-linux-usb-loader](https://github.com/sevenbits/mac-linux-usb-loader) Boot Linux on your Mac, easily -- [**833**星][5y] [Py] [pentestmonkey/windows-privesc-check](https://github.com/pentestmonkey/windows-privesc-check) 独立工具,查找Windows系统上可导致本地提权的错误配置 -- [**833**星][3m] [JS] [creditease-sec/insight](https://github.com/creditease-sec/insight) 洞察-宜信集应用系统资产管理、漏洞全生命周期管理、安全知识库管理三位一体的平台。 -- [**832**星][13d] [Haskell] [galoisinc/cryptol](https://github.com/galoisinc/cryptol) The Language of Cryptography -- [**831**星][12d] [v33ru/iotsecurity101](https://github.com/v33ru/iotsecurity101) From IoT Pentesting to IoT Security -- [**830**星][25d] [Batchfile] [mr-xn/burpsuite-collections](https://github.com/mr-xn/burpsuite-collections) BurpSuite收集:包括不限于 Burp 文章、破解版、插件(非BApp Store)、汉化等相关教程,欢迎添砖加瓦---burpsuite-pro burpsuite-extender burpsuite cracked-version hackbar hacktools fuzzing fuzz-testing burp-plugin burp-extensions bapp-store brute-force-attacks brute-force-passwords waf sqlmap jar -- [**830**星][1m] [cugu/awesome-forensics](https://github.com/cugu/awesome-forensics) A curated list of awesome forensic analysis tools and resources -- [**829**星][5m] [Py] [ma1co/sony-pmca-re](https://github.com/ma1co/sony-pmca-re) Reverse engineering Sony PlayMemories Camera Apps +- [**842**星][3y] [C] [gurnec/hashcheck](https://github.com/gurnec/hashcheck) HashCheck Shell Extension for Windows with added SHA2, SHA3, and multithreading; originally from code.kliu.org +- [**842**星][5d] [C] [emsec/chameleonmini](https://github.com/emsec/chameleonmini) The ChameleonMini is a versatile contactless smartcard emulator compliant to NFC. The ChameleonMini was developed by +- [**841**星][9d] [trimstray/iptables-essentials](https://github.com/trimstray/iptables-essentials) Common Firewall Rules and Commands. +- [**841**星][3y] [Py] [ring04h/weakfilescan](https://github.com/ring04h/weakfilescan) 动态多线程敏感信息泄露检测工具 +- [**840**星][2m] [Go] [henson/proxypool](https://github.com/henson/proxypool) Golang实现的IP代理池 +- [**840**星][5m] [Java] [dragonite-network/dragonite-java](https://github.com/dragonite-network/dragonite-java) A reliable application level data transport protocol based on UDP, highly optimized for lossy & unstable networks. (Java version) +- [**840**星][28d] [C#] [borntoberoot/networkmanager](https://github.com/borntoberoot/networkmanager) A powerful tool for managing networks and troubleshoot network problems! +- [**839**星][15d] [Py] [jordanpotti/awsbucketdump](https://github.com/jordanpotti/awsbucketdump) 快速枚举 AWS S3 Buckets,查找感兴趣的文件。类似于子域名爆破,但针对S3 Bucket,有额外功能,例如下载文件等 +- [**838**星][1m] [C] [facebook/transform360](https://github.com/facebook/transform360) Transform360 is an equirectangular to cubemap transform for 360 video. +- [**838**星][1y] [HTML] [ustayready/credsniper](https://github.com/ustayready/credsniper) CredSniper is a phishing framework written with the Python micro-framework Flask and Jinja2 templating which supports capturing 2FA tokens. +- [**837**星][27d] [PHP] [raikia/fiercephish](https://github.com/Raikia/FiercePhish) FiercePhish is a full-fledged phishing framework to manage all phishing engagements. It allows you to track separate phishing campaigns, schedule sending of emails, and much more. +- [**837**星][5y] [Py] [pentestmonkey/windows-privesc-check](https://github.com/pentestmonkey/windows-privesc-check) 独立工具,查找Windows系统上可导致本地提权的错误配置 +- [**837**星][3m] [JS] [creditease-sec/insight](https://github.com/creditease-sec/insight) 洞察-宜信集应用系统资产管理、漏洞全生命周期管理、安全知识库管理三位一体的平台。 +- [**836**星][2d] [Java] [sleuthkit/autopsy](https://github.com/sleuthkit/autopsy) Autopsy® is a digital forensics platform and graphical interface to The Sleuth Kit® and other digital forensics tools. It can be used by law enforcement, military, and corporate examiners to investigate what happened on a computer. You can even use it to recover photos from your camera's memory card. +- [**836**星][7m] [Shell] [niklasb/libc-database](https://github.com/niklasb/libc-database) Build a database of libc offsets to simplify exploitation +- [**836**星][1y] [Shell] [kpwn/iosre](https://github.com/kpwn/iosre) iOS Reverse Engineering +- [**833**星][14d] [v33ru/iotsecurity101](https://github.com/v33ru/iotsecurity101) From IoT Pentesting to IoT Security +- [**833**星][7m] [ObjC] [sevenbits/mac-linux-usb-loader](https://github.com/sevenbits/mac-linux-usb-loader) Boot Linux on your Mac, easily +- [**832**星][5d] [Haskell] [galoisinc/cryptol](https://github.com/galoisinc/cryptol) The Language of Cryptography +- [**832**星][1m] [cugu/awesome-forensics](https://github.com/cugu/awesome-forensics) A curated list of awesome forensic analysis tools and resources +- [**831**星][17d] [C#] [pwntester/ysoserial.net](https://github.com/pwntester/ysoserial.net) 生成Payload,恶意利用不安全的 .NET 对象反序列化 +- [**831**星][5m] [Py] [ma1co/sony-pmca-re](https://github.com/ma1co/sony-pmca-re) Reverse engineering Sony PlayMemories Camera Apps +- [**830**星][2d] [C++] [tasvideos/bizhawk](https://github.com/tasvideos/bizhawk) BizHawk is a multi-system emulator written in C#. BizHawk provides nice features for casual gamers such as full screen, and joypad support in addition to full rerecording and debugging tools for all system cores. +- [**830**星][24d] [redhuntlabs/redhunt-os](https://github.com/redhuntlabs/redhunt-os) Virtual Machine for Adversary Emulation and Threat Hunting +- [**830**星][9m] [Py] [ietf-wg-acme/acme](https://github.com/ietf-wg-acme/acme) A protocol for automating certificate issuance +- [**829**星][5y] [halfkiss/zjdroid](https://github.com/halfkiss/zjdroid) 基于Xposed Framewrok的动态逆向分析模块 +- [**828**星][4y] [etsy/midas](https://github.com/etsy/midas) Mac入侵检测分析系统 +- [**827**星][7m] [Go] [tiagorlampert/chaos](https://github.com/tiagorlampert/chaos) a PoC that allow generate payloads and control remote operating system - [**827**星][11m] [sandboxescaper/randomrepo](https://github.com/sandboxescaper/randomrepo) Repo for random stuff -- [**827**星][23d] [Go] [ffuf/ffuf](https://github.com/ffuf/ffuf) Fast web fuzzer written in Go -- [**826**星][22d] [redhuntlabs/redhunt-os](https://github.com/redhuntlabs/redhunt-os) Virtual Machine for Adversary Emulation and Threat Hunting -- [**826**星][4y] [etsy/midas](https://github.com/etsy/midas) Mac Intrusion Detection Analysis System +- [**826**星][7m] [Batchfile] [kkkgo/kms_vl_all](https://github.com/kkkgo/kms_vl_all) +- [**826**星][9d] [JS] [cypress-io/cypress-example-recipes](https://github.com/cypress-io/cypress-example-recipes) Various recipes for testing common scenarios with Cypress - [**825**星][2y] [PHP] [zhufaner/shadowsocks-manage-system](https://github.com/zhufaner/shadowsocks-manage-system) 科学上网管理系统 -- [**824**星][27d] [Py] [salesforce/ja3](https://github.com/salesforce/ja3) SSL/TLS 客户端指纹,用于恶意代码检测 -- [**824**星][9m] [Py] [ietf-wg-acme/acme](https://github.com/ietf-wg-acme/acme) A protocol for automating certificate issuance -- [**823**星][2m] [C++] [redasmorg/redasm](https://github.com/redasmorg/redasm) The OpenSource Disassembler -- [**823**星][5y] [halfkiss/zjdroid](https://github.com/halfkiss/zjdroid) 基于Xposed Framewrok的动态逆向分析模块 -- [**822**星][7d] [C++] [tasvideos/bizhawk](https://github.com/tasvideos/bizhawk) BizHawk is a multi-system emulator written in C#. BizHawk provides nice features for casual gamers such as full screen, and joypad support in addition to full rerecording and debugging tools for all system cores. -- [**822**星][4y] [PowerShell] [clymb3r/powershell](https://github.com/clymb3r/powershell) Useful PowerShell scripts -- [**821**星][7m] [Go] [tiagorlampert/chaos](https://github.com/tiagorlampert/chaos) a PoC that allow generate payloads and control remote operating system -- [**820**星][1m] [Py] [corelan/mona](https://github.com/corelan/mona) Corelan Repository for mona.py -- [**819**星][6y] [Py] [ilektrojohn/creepy](https://github.com/ilektrojohn/creepy) A geolocation OSINT tool. Offers geolocation information gathering through social networking platforms. -- [**819**星][16d] [Py] [yampelo/beagle](https://github.com/yampelo/beagle) Beagle is an incident response and digital forensics tool which transforms security logs and data into graphs. -- [**819**星][7d] [GLSL] [khronosgroup/spirv-cross](https://github.com/khronosgroup/spirv-cross) a practical tool and library for performing reflection on SPIR-V and disassembling SPIR-V back to high level languages. -- [**818**星][15d] [C#] [pwntester/ysoserial.net](https://github.com/pwntester/ysoserial.net) 生成Payload,恶意利用不安全的 .NET 对象反序列化 -- [**818**星][21d] [C] [emmericp/ixy](https://github.com/emmericp/ixy) Simple userspace packet processing for educational purposes -- [**817**星][6m] [numirias/security](https://github.com/numirias/security) Some of my security stuff and vulnerabilities. Nothing advanced. More to come. -- [**816**星][1m] [Java] [stealthcopter/androidnetworktools](https://github.com/stealthcopter/androidnetworktools) Set of useful android network tools -- [**816**星][7d] [cveproject/cvelist](https://github.com/cveproject/cvelist) Pilot program for CVE submission through GitHub -- [**815**星][2m] [Py] [jeffzh3ng/fuxi](https://github.com/jeffzh3ng/fuxi) Penetration Testing Platform -- [**815**星][19d] [PHP] [symfony/security-csrf](https://github.com/symfony/security-csrf) The Security CSRF (cross-site request forgery) component provides a class CsrfTokenManager for generating and validating CSRF tokens. -- [**815**星][27d] [Elixir] [nccgroup/sobelow](https://github.com/nccgroup/sobelow) Phoenix 框架安全方面的静态分析工具(Phoenix 框架:支持对webUI,接口, web性能,mobile app 或 mobile browser 进行自动化测试和监控的平台) -- [**815**星][7d] [JS] [cypress-io/cypress-example-recipes](https://github.com/cypress-io/cypress-example-recipes) Various recipes for testing common scenarios with Cypress -- [**815**星][2y] [PowerShell] [besimorhino/powercat](https://github.com/besimorhino/powercat) PowerShell实现的Netcat -- [**814**星][27d] [C] [rust-fuzz/afl.rs](https://github.com/rust-fuzz/afl.rs) +- [**825**星][21d] [PHP] [symfony/security-csrf](https://github.com/symfony/security-csrf) 一个CsrfTokenManager类,用于生成和验证CSRF令牌 +- [**825**星][29d] [Py] [salesforce/ja3](https://github.com/salesforce/ja3) SSL/TLS 客户端指纹,用于恶意代码检测 +- [**825**星][2m] [C++] [redasmorg/redasm](https://github.com/redasmorg/redasm) The OpenSource Disassembler +- [**824**星][3d] [GLSL] [khronosgroup/spirv-cross](https://github.com/khronosgroup/spirv-cross) a practical tool and library for performing reflection on SPIR-V and disassembling SPIR-V back to high level languages. +- [**824**星][5m] [Shell] [danielmiessler/robotsdisallowed](https://github.com/danielmiessler/robotsdisallowed) A curated list of the most common and most interesting robots.txt disallowed directories. +- [**824**星][4y] [PS] [clymb3r/powershell](https://github.com/clymb3r/powershell) Useful PowerShell scripts +- [**823**星][1m] [Py] [corelan/mona](https://github.com/corelan/mona) 用于Immunity Debugger的mona.py +- [**823**星][2y] [PS] [besimorhino/powercat](https://github.com/besimorhino/powercat) PowerShell实现的Netcat +- [**822**星][24d] [Shell] [zfl9/ss-tproxy](https://github.com/zfl9/ss-tproxy) SS/SSR/V2Ray/Socks5 透明代理 for Linux +- [**822**星][2d] [Py] [kerlomz/captcha_trainer](https://github.com/kerlomz/captcha_trainer) 基于深度学习的图片验证码的解决方案 +- [**821**星][6y] [Py] [ilektrojohn/creepy](https://github.com/ilektrojohn/creepy) A geolocation OSINT tool. Offers geolocation information gathering through social networking platforms. +- [**821**星][9d] [Py] [yampelo/beagle](https://github.com/yampelo/beagle) Beagle is an incident response and digital forensics tool which transforms security logs and data into graphs. +- [**821**星][8d] [Elixir] [nccgroup/sobelow](https://github.com/nccgroup/sobelow) Phoenix 框架安全方面的静态分析工具(Phoenix 框架:支持对webUI,接口, web性能,mobile app 或 mobile browser 进行自动化测试和监控的平台) +- [**821**星][2d] [cveproject/cvelist](https://github.com/cveproject/cvelist) Pilot program for CVE submission through GitHub +- [**820**星][24d] [C] [emmericp/ixy](https://github.com/emmericp/ixy) Simple userspace packet processing for educational purposes +- [**819**星][1m] [Java] [stealthcopter/androidnetworktools](https://github.com/stealthcopter/androidnetworktools) Set of useful android network tools +- [**819**星][2m] [Py] [jeffzh3ng/fuxi](https://github.com/jeffzh3ng/fuxi) 渗透测试平台 +- [**819**星][2m] [AutoIt] [bioruebe/uniextract2](https://github.com/bioruebe/uniextract2) Universal Extractor 2 is an unofficial updated and extended version of the original UniExtract by Jared Breland. It brings several hundred changes including community-wanted ones such as a batch mode, auto-updater and scan-only-functionality. +- [**818**星][6m] [numirias/security](https://github.com/numirias/security) Some of my security stuff and vulnerabilities. Nothing advanced. More to come. +- [**817**星][2m] [Shell] [shr3ddersec/shr3dkit](https://github.com/shr3ddersec/shr3dkit) Red Team Tool Kit +- [**816**星][29d] [C] [rust-fuzz/afl.rs](https://github.com/rust-fuzz/afl.rs) - [**814**星][2y] [Py] [pirate/security-growler](https://github.com/pirate/security-growler) -- [**813**星][5m] [Shell] [danielmiessler/robotsdisallowed](https://github.com/danielmiessler/robotsdisallowed) A curated list of the most common and most interesting robots.txt disallowed directories. -- [**812**星][8d] [JS] [mellow-io/mellow](https://github.com/mellow-io/mellow) Mellow is a rule-based global transparent proxy client for Windows, macOS and Linux. -- [**812**星][2y] [Ruby] [elevenpaths/eternalblue-doublepulsar-metasploit](https://github.com/elevenpaths/eternalblue-doublepulsar-metasploit) Module of Metasploit to exploit the vulnerability Eternalblue-Doublepulsar. -- [**811**星][8m] [Py] [nccgroup/featherduster](https://github.com/nccgroup/featherduster) An automated, modular cryptanalysis tool; i.e., a Weapon of Math Destruction -- [**811**星][2m] [feeicn/security-ppt](https://github.com/feeicn/security-ppt) 大安全各领域各公司各会议分享的PPT -- [**811**星][25d] [C] [dynup/kpatch](https://github.com/dynup/kpatch) live kernel patching -- [**810**星][2m] [Shell] [shr3ddersec/shr3dkit](https://github.com/shr3ddersec/shr3dkit) Red Team Tool Kit -- [**810**星][5y] [Objective-C] [isecpartners/ios-ssl-kill-switch](https://github.com/isecpartners/ios-ssl-kill-switch) Blackbox tool to disable SSL certificate validation - including certificate pinning - within iOS Apps -- [**809**星][1y] [Py] [utkusen/leviathan](https://github.com/utkusen/leviathan) wide range mass audit toolkit -- [**809**星][1y] [Py] [utkusen/leviathan](https://github.com/utkusen/leviathan) 多功能审计工具包,包括多种服务发现(FTP、SSH、Talnet、RDP、MYSQL)、爆破、远程命令执行、SQL注入扫描、指定漏洞利用,集成了Masscan、Ncrack、DSSS等工具。 -- [**809**星][2y] [C] [timwr/cve-2016-5195](https://github.com/timwr/cve-2016-5195) CVE-2016-5195 (dirtycow/dirtyc0w) proof of concept for Android -- [**809**星][2m] [AutoIt] [bioruebe/uniextract2](https://github.com/bioruebe/uniextract2) Universal Extractor 2 is an unofficial updated and extended version of the original UniExtract by Jared Breland. It brings several hundred changes including community-wanted ones such as a batch mode, auto-updater and scan-only-functionality. -- [**808**星][13d] [JS] [sindresorhus/is-online](https://github.com/sindresorhus/is-online) Check if the internet connection is up -- [**808**星][7y] [C] [inquisb/icmpsh](https://github.com/inquisb/icmpsh) Simple reverse ICMP shell -- [**807**星][22d] [Shell] [zfl9/ss-tproxy](https://github.com/zfl9/ss-tproxy) SS/SSR/V2Ray/Socks5 透明代理 for Linux -- [**807**星][3m] [C] [strazzere/android-unpacker](https://github.com/strazzere/android-unpacker) Android Unpacker presented at Defcon 22: Android Hacker Protection Level 0 +- [**814**星][3m] [feeicn/security-ppt](https://github.com/feeicn/security-ppt) 大安全各领域各公司各会议分享的PPT +- [**814**星][5d] [C] [dynup/kpatch](https://github.com/dynup/kpatch) live kernel patching +- [**813**星][2y] [Ruby] [elevenpaths/eternalblue-doublepulsar-metasploit](https://github.com/elevenpaths/eternalblue-doublepulsar-metasploit) Module of Metasploit to exploit the vulnerability Eternalblue-Doublepulsar. +- [**812**星][15d] [JS] [sindresorhus/is-online](https://github.com/sindresorhus/is-online) 检查互联网连接是否正常 +- [**811**星][1y] [Py] [utkusen/leviathan](https://github.com/utkusen/leviathan) wide range mass audit toolkit +- [**811**星][1y] [Py] [utkusen/leviathan](https://github.com/utkusen/leviathan) 多功能审计工具包,包括多种服务发现(FTP、SSH、Talnet、RDP、MYSQL)、爆破、远程命令执行、SQL注入扫描、指定漏洞利用,集成了Masscan、Ncrack、DSSS等工具。 +- [**811**星][2y] [C] [timwr/cve-2016-5195](https://github.com/timwr/cve-2016-5195) CVE-2016-5195 (dirtycow/dirtyc0w) proof of concept for Android +- [**811**星][5y] [ObjC] [isecpartners/ios-ssl-kill-switch](https://github.com/isecpartners/ios-ssl-kill-switch) Blackbox tool to disable SSL certificate validation - including certificate pinning - within iOS Apps +- [**811**星][7y] [C] [inquisb/icmpsh](https://github.com/inquisb/icmpsh) Simple reverse ICMP shell +- [**810**星][8m] [Py] [nccgroup/featherduster](https://github.com/nccgroup/featherduster) 自动化的密码分析工具,模块化 +- [**809**星][1y] [C++] [tencent/tscancode](https://github.com/tencent/tscancode) A static code analyzer for C++, C#, Lua +- [**808**星][2y] [C#] [nicehash/nicehashminer-archived](https://github.com/nicehash/nicehashminer-archived) NiceHash easy to use CPU&GPU Miner +- [**808**星][3m] [C] [strazzere/android-unpacker](https://github.com/strazzere/android-unpacker) Android Unpacker presented at Defcon 22: Android Hacker Protection Level 0 +- [**806**星][1m] [Swift] [googleprojectzero/fuzzilli](https://github.com/googleprojectzero/fuzzilli) A JavaScript Engine Fuzzer +- [**806**星][3y] [Py] [fuzzbunch/fuzzbunch](https://github.com/fuzzbunch/fuzzbunch) NSA finest tool - [**806**星][2y] [Ruby] [dmayer/idb](https://github.com/dmayer/idb) iOS 渗透和研究过程中简化一些常见的任务 -- [**804**星][3y] [Py] [fuzzbunch/fuzzbunch](https://github.com/fuzzbunch/fuzzbunch) NSA finest tool -- [**803**星][3y] [shmilylty/awesome-hacking](https://github.com/shmilylty/awesome-hacking) awesome hacking chinese version +- [**805**星][17d] [Ruby] [rastating/wordpress-exploit-framework](https://github.com/rastating/wordpress-exploit-framework) WordPress 漏洞利用框架 +- [**805**星][5m] [C++] [ptrkrysik/gr-gsm](https://github.com/ptrkrysik/gr-gsm) Gnuradio blocks and tools for receiving GSM transmissions +- [**804**星][2y] [Swift] [zhuhaow/specht](https://github.com/zhuhaow/specht) A rule-based proxy app built with Network Extension for macOS +- [**804**星][3y] [shmilylty/awesome-hacking](https://github.com/shmilylty/awesome-hacking) awesome hacking chinese version +- [**804**星][6d] [Py] [jivoi/pentest](https://github.com/jivoi/pentest) 渗透测试工具 +- [**803**星][2m] [Py] [acmesec/ctfcracktools](https://github.com/Acmesec/CTFCrackTools) 中国国内首个CTF工具框架,旨在帮助CTFer快速攻克难关 - [**803**星][3y] [te-k/flexidie](https://github.com/te-k/flexidie) Source code and binaries of FlexiSpy from the Flexidie dump -- [**802**星][15d] [Ruby] [rastating/wordpress-exploit-framework](https://github.com/rastating/wordpress-exploit-framework) WordPress 漏洞利用框架 -- [**801**星][5m] [C++] [ptrkrysik/gr-gsm](https://github.com/ptrkrysik/gr-gsm) Gnuradio blocks and tools for receiving GSM transmissions +- [**803**星][2y] [Go] [schollz/find-lf](https://github.com/schollz/find-lf) Track the location of every Wi-Fi device ( +- [**802**星][3m] [Py] [techgaun/github-dorks](https://github.com/techgaun/github-dorks) 快速搜索Github repo中的敏感信息 +- [**802**星][3m] [Py] [secforce/tunna](https://github.com/secforce/tunna) Tunna is a set of tools which will wrap and tunnel any TCP communication over HTTP. It can be used to bypass network restrictions in fully firewalled environments. +- [**802**星][2m] [Py] [hellman/xortool](https://github.com/hellman/xortool) 分析多字节异或密码 +- [**802**星][1m] [Shell] [andreyvit/create-dmg](https://github.com/andreyvit/create-dmg) 用于构建精美DMG的Shell脚本 +- [**801**星][2y] [vysecurity/redtips](https://github.com/vysecurity/RedTips) Red Team Tips as posted by - [**801**星][3y] [C#] [netflix/fido](https://github.com/netflix/fido) an orchestration layer used to automate the incident response process by evaluating, assessing and responding to malware -- [**800**星][2y] [vysecurity/redtips](https://github.com/vysecurity/RedTips) Red Team Tips as posted by +- [**801**星][2d] [Py] [ericsson/codechecker](https://github.com/ericsson/codechecker) CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy +- [**800**星][28d] [Rust] [edu4rdshl/findomain](https://github.com/edu4rdshl/findomain) The fastest and cross-platform subdomain enumerator, don't waste your time. +- [**800**星][6d] [C++] [aslody/whale](https://github.com/aslody/whale) Hook Framework for Android/IOS/Linux/MacOS - [**799**星][6y] [Pascal] [prof7bit/torchat](https://github.com/prof7bit/torchat) Decentralized anonymous instant messenger on top of Tor Hidden Services -- [**798**星][2m] [Py] [acmesec/ctfcracktools](https://github.com/Acmesec/CTFCrackTools) 中国国内首个CTF工具框架,旨在帮助CTFer快速攻克难关 -- [**798**星][3m] [Py] [secforce/tunna](https://github.com/secforce/tunna) Tunna is a set of tools which will wrap and tunnel any TCP communication over HTTP. It can be used to bypass network restrictions in fully firewalled environments. -- [**798**星][1y] [Objective-C] [igrsoft/kismac2](https://github.com/igrsoft/kismac2) KisMAC is a free, open source wireless stumbling and security tool for Mac OS X. -- [**798**星][1m] [Shell] [andreyvit/create-dmg](https://github.com/andreyvit/create-dmg) A shell script to build fancy DMGs -- [**797**星][2m] [Py] [hellman/xortool](https://github.com/hellman/xortool) A tool to analyze multi-byte xor cipher -- [**797**星][1m] [Swift] [googleprojectzero/fuzzilli](https://github.com/googleprojectzero/fuzzilli) A JavaScript Engine Fuzzer +- [**799**星][1y] [ObjC] [igrsoft/kismac2](https://github.com/igrsoft/kismac2) KisMAC is a free, open source wireless stumbling and security tool for Mac OS X. +- [**799**星][3m] [Py] [awslabs/aws-config-rules](https://github.com/awslabs/aws-config-rules) [Node, Python, Java] Repository of sample Custom Rules for AWS Config. +- [**798**星][3d] [Py] [complianceascode/content](https://github.com/ComplianceAsCode/content) Security compliance content in SCAP, Bash, Ansible, and other formats +- [**798**星][8d] [proxymanapp/proxyman](https://github.com/proxymanapp/proxyman) Modern and Delightful HTTP Debugging Proxy for macOS, iOS and Android +- [**798**星][11m] [Py] [mak-/parameth](https://github.com/mak-/parameth) 在文件中(例如PHP 文件)暴力搜索GET 和 POST 请求的参数 +- [**797**星][3y] [Go] [ryhanson/phishery](https://github.com/ryhanson/phishery) 启用 SSL 的 HTTP 服务器,首要目的是通过基本身份认证进行网络钓鱼,以获取凭证。自带将钓鱼url 注入 .docx Word 文档的功能,用户打开Word 文档时会向钓鱼 url 发送请求,并自动弹出认证对话框。 - [**797**星][3y] [Go] [codahale/sneaker](https://github.com/codahale/sneaker) A tool for securely storing secrets on S3 using Amazon KMS. -- [**796**星][2y] [Go] [schollz/find-lf](https://github.com/schollz/find-lf) Track the location of every Wi-Fi device ( -- [**796**星][20d] [Py] [jivoi/pentest](https://github.com/jivoi/pentest) -- [**796**星][8d] [Py] [ericsson/codechecker](https://github.com/ericsson/codechecker) CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy - [**795**星][7m] [Py] [phaethon/kamene](https://github.com/phaethon/kamene) Network packet and pcap file crafting/sniffing/manipulation/visualization security tool. Originally forked from scapy in 2015 and providing python3 compatibility since then. -- [**795**星][7m] [C++] [aslody/whale](https://github.com/aslody/whale) Hook Framework for Android/IOS/Linux/MacOS -- [**794**星][11m] [Py] [mak-/parameth](https://github.com/mak-/parameth) 在文件中(例如PHP 文件)暴力搜索GET 和 POST 请求的参数 -- [**794**星][3m] [Py] [awslabs/aws-config-rules](https://github.com/awslabs/aws-config-rules) [Node, Python, Java] Repository of sample Custom Rules for AWS Config. -- [**793**星][7d] [Py] [complianceascode/content](https://github.com/ComplianceAsCode/content) Security compliance content in SCAP, Bash, Ansible, and other formats -- [**793**星][20d] [Py] [yeti-platform/yeti](https://github.com/yeti-platform/yeti) 情报威胁管理平台 -- [**793**星][3y] [Go] [ryhanson/phishery](https://github.com/ryhanson/phishery) 启用 SSL 的 HTTP 服务器,首要目的是通过基本身份认证进行网络钓鱼,以获取凭证。自带将钓鱼url 注入 .docx Word 文档的功能,用户打开Word 文档时会向钓鱼 url 发送请求,并自动弹出认证对话框。 -- [**791**星][3m] [Py] [techgaun/github-dorks](https://github.com/techgaun/github-dorks) 快速搜索Github repo中的敏感信息 -- [**791**星][3y] [Py] [empireproject/empyre](https://github.com/empireproject/empyre) A post-exploitation OS X/Linux agent written in Python 2.7 +- [**795**星][22d] [Py] [yeti-platform/yeti](https://github.com/yeti-platform/yeti) 情报威胁管理平台 +- [**794**星][2m] [sh4hin/androl4b](https://github.com/sh4hin/androl4b) 用于评估Android应用程序,逆向工程和恶意软件分析的虚拟机 +- [**793**星][3y] [Py] [empireproject/empyre](https://github.com/empireproject/empyre) A post-exploitation OS X/Linux agent written in Python 2.7 +- [**791**星][4m] [Py] [srinivas11789/pcapxray](https://github.com/srinivas11789/pcapxray) A Network Forensics Tool - [**790**星][2y] [Go] [evilsocket/dnssearch](https://github.com/evilsocket/dnssearch) A subdomain enumeration tool. -- [**789**星][2m] [sh4hin/androl4b](https://github.com/sh4hin/androl4b) 用于评估Android应用程序,逆向工程和恶意软件分析的虚拟机 -- [**789**星][26d] [Rust] [edu4rdshl/findomain](https://github.com/edu4rdshl/findomain) The fastest and cross-platform subdomain enumerator, don't waste your time. -- [**789**星][3y] [C++] [bwall/hashpump](https://github.com/bwall/hashpump) A tool to exploit the hash length extension attack in various hashing algorithms -- [**787**星][4m] [Py] [srinivas11789/pcapxray](https://github.com/srinivas11789/pcapxray) A Network Forensics Tool +- [**790**星][3y] [C++] [bwall/hashpump](https://github.com/bwall/hashpump) A tool to exploit the hash length extension attack in various hashing algorithms +- [**789**星][10m] [C#] [terminals-origin/terminals](https://github.com/terminals-origin/terminals) Terminals is a secure, multi tab terminal services/remote desktop client. It uses Terminal Services ActiveX Client (mstscax.dll). The project started from the need of controlling multiple connections simultaneously. It is a complete replacement for the mstsc.exe (Terminal Services) client. This is official source moved from Codeplex. +- [**789**星][2d] [C] [fwupd/fwupd](https://github.com/fwupd/fwupd) A simple daemon to allow session software to update firmware +- [**788**星][3d] [Java] [zstackio/zstack](https://github.com/zstackio/zstack) ZStack - the open-source IaaS software +- [**787**星][1m] [CSS] [smartping/smartping](https://github.com/smartping/smartping) 综合性网络质量(PING)检测工具,支持正/反向PING绘图、互PING拓扑绘图与报警、全国PING延迟地图与在线检测工具等功能 - [**787**星][2y] [Shell] [screetsec/dracnmap](https://github.com/screetsec/dracnmap) Dracnmap is an open source program which is using to exploit the network and gathering information with nmap help. Nmap command comes with lots of options that can make the utility more robust and difficult to follow for new users. Hence Dracnmap is designed to perform fast scaning with the utilizing script engine of nmap and nmap can perform va… -- [**784**星][2m] [C] [netsniff-ng/netsniff-ng](https://github.com/netsniff-ng/netsniff-ng) A Swiss army knife for your daily Linux network plumbing. -- [**784**星][8d] [C] [fwupd/fwupd](https://github.com/fwupd/fwupd) A simple daemon to allow session software to update firmware -- [**784**星][8d] [Java] [zstackio/zstack](https://github.com/zstackio/zstack) ZStack - the open-source IaaS software -- [**783**星][4y] [Assembly] [xoreaxeaxeax/sinkhole](https://github.com/xoreaxeaxeax/sinkhole) Architectural privilege escalation on x86 -- [**783**星][8m] [Go] [parsiya/hacking-with-go](https://github.com/parsiya/hacking-with-go) Golang for Security Professionals -- [**783**星][27d] [Ruby] [net-ssh/net-ssh](https://github.com/net-ssh/net-ssh) Pure Ruby implementation of an SSH (protocol 2) client -- [**783**星][2y] [C] [jklmnn/imagejs](https://github.com/jklmnn/imagejs) Small tool to package javascript into a valid image file. -- [**783**星][2m] [Go] [dreddsa5dies/gohacktools](https://github.com/dreddsa5dies/gohacktools) Hacker tools on Go (Golang) +- [**787**星][2m] [Py] [numba/llvmlite](https://github.com/numba/llvmlite) A lightweight LLVM python binding for writing JIT compilers +- [**787**星][1m] [microsoft/msrc-security-research](https://github.com/microsoft/msrc-security-research) Security Research from the Microsoft Security Response Center (MSRC) +- [**786**星][2m] [Go] [dreddsa5dies/gohacktools](https://github.com/dreddsa5dies/gohacktools) Golang编写的多款Hacking工具 +- [**785**星][2m] [C] [netsniff-ng/netsniff-ng](https://github.com/netsniff-ng/netsniff-ng) A Swiss army knife for your daily Linux network plumbing. +- [**785**星][12d] [Go] [rebuy-de/aws-nuke](https://github.com/rebuy-de/aws-nuke) Nuke a whole AWS account and delete all its resources. +- [**785**星][2y] [C] [jklmnn/imagejs](https://github.com/jklmnn/imagejs) 将javascript打包到有效的图像文件。 +- [**784**星][4y] [Assembly] [xoreaxeaxeax/sinkhole](https://github.com/xoreaxeaxeax/sinkhole) Architectural privilege escalation on x86 +- [**784**星][5m] [TSQL] [threathunterx/nebula](https://github.com/threathunterx/nebula) "星云"业务风控系统,主工程 +- [**784**星][8m] [Go] [parsiya/hacking-with-go](https://github.com/parsiya/hacking-with-go) Golang for Security Professionals +- [**784**星][7m] [Java] [blankeer/mdwechat](https://github.com/blankeer/mdwechat) 一个能让微信 Material Design 化的 Xposed 模块 +- [**784**星][2m] [Py] [bishopfox/gitgot](https://github.com/bishopfox/gitgot) Semi-automated, feedback-driven tool to rapidly search through troves of public data on GitHub for sensitive secrets. +- [**784**星][3y] [Go] [armon/go-socks5](https://github.com/armon/go-socks5) SOCKS5 server in Golang +- [**782**星][11m] [v2-dev/awesome-social-engineering](https://github.com/v2-dev/awesome-social-engineering) 社会工程学资源集合 - [**782**星][3y] [Go] [summitroute/osxlockdown](https://github.com/summitroute/osxlockdown) [No longer maintained] Apple OS X tool to audit for, and remediate, security configuration settings. -- [**782**星][7m] [Java] [blankeer/mdwechat](https://github.com/blankeer/mdwechat) 一个能让微信 Material Design 化的 Xposed 模块 -- [**781**星][5m] [TSQL] [threathunterx/nebula](https://github.com/threathunterx/nebula) "星云"业务风控系统,主工程 -- [**781**星][30d] [microsoft/msrc-security-research](https://github.com/microsoft/msrc-security-research) Security Research from the Microsoft Security Response Center (MSRC) -- [**781**星][3y] [Go] [armon/go-socks5](https://github.com/armon/go-socks5) SOCKS5 server in Golang +- [**782**星][29d] [Ruby] [net-ssh/net-ssh](https://github.com/net-ssh/net-ssh) Pure Ruby implementation of an SSH (protocol 2) client +- [**782**星][1y] [PS] [kevin-robertson/invoke-thehash](https://github.com/kevin-robertson/invoke-thehash) 执行 pass the hash WMI 和 SMB 任务的PowerShell函数 +- [**780**星][2m] [C] [nixos/patchelf](https://github.com/nixos/patchelf) A small utility to modify the dynamic linker and RPATH of ELF executables - [**780**星][4y] [C++] [denandz/keefarce](https://github.com/denandz/keefarce) Extracts passwords from a KeePass 2.x database, directly from memory. - [**779**星][2y] [Py] [secretsquirrel/bdfproxy](https://github.com/secretsquirrel/bdfproxy) Patch Binaries via MITM: BackdoorFactory + mitmProxy. (NOT SUPPORTED) -- [**779**星][2m] [Py] [numba/llvmlite](https://github.com/numba/llvmlite) A lightweight LLVM python binding for writing JIT compilers -- [**779**星][1y] [PowerShell] [kevin-robertson/invoke-thehash](https://github.com/kevin-robertson/invoke-thehash) PowerShell Pass The Hash Utils -- [**778**星][10d] [Go] [rebuy-de/aws-nuke](https://github.com/rebuy-de/aws-nuke) Nuke a whole AWS account and delete all its resources. -- [**778**星][2m] [C] [nixos/patchelf](https://github.com/nixos/patchelf) A small utility to modify the dynamic linker and RPATH of ELF executables -- [**777**星][11m] [v2-dev/awesome-social-engineering](https://github.com/v2-dev/awesome-social-engineering) 社会工程学资源集合 +- [**779**星][1m] [Py] [konradit/gopro-py-api](https://github.com/konradit/gopro-py-api) Unofficial GoPro API Library for Python - connect to GoPro via WiFi. +- [**777**星][7d] [Go] [kolide/fleet](https://github.com/kolide/fleet) A flexible control server for osquery fleets +- [**777**星][1m] [Py] [kevthehermit/ratdecoders](https://github.com/kevthehermit/ratdecoders) Python Decoders for Common Remote Access Trojans +- [**777**星][8d] [C#] [justcoding121/titanium-web-proxy](https://github.com/justcoding121/titanium-web-proxy) A cross-platform asynchronous HTTP(S) proxy server in C#. - [**777**星][2m] [Py] [gosecure/malboxes](https://github.com/gosecure/malboxes) Builds malware analysis Windows VMs so that you don't have to. -- [**776**星][1m] [Py] [konradit/gopro-py-api](https://github.com/konradit/gopro-py-api) Unofficial GoPro API Library for Python - connect to GoPro via WiFi. -- [**776**星][2m] [Py] [bishopfox/gitgot](https://github.com/bishopfox/gitgot) Semi-automated, feedback-driven tool to rapidly search through troves of public data on GitHub for sensitive secrets. -- [**775**星][1y] [C++] [polysync/oscc](https://github.com/polysync/oscc) Open Source Car Control +- [**777**星][2y] [C++] [dor1s/libfuzzer-workshop](https://github.com/dor1s/libfuzzer-workshop) Repository for materials of "Modern fuzzing of C/C++ Projects" workshop. +- [**777**星][15d] [Go] [bishopfox/sliver](https://github.com/bishopfox/sliver) 一个通用的跨平台植入程序框架,该框架C3支持Mutual-TLS,HTTP(S)和DNS +- [**777**星][14d] [Shell] [aqzt/kjyw](https://github.com/aqzt/kjyw) 快捷运维,代号kjyw,项目基于shell、python,运维脚本工具库,收集各类运维常用工具脚本,实现快速安装nginx、mysql、php、redis、nagios、运维经常使用的脚本等等... +- [**776**星][2y] [Py] [marvis/pytorch-caffe-darknet-convert](https://github.com/marvis/pytorch-caffe-darknet-convert) convert between pytorch, caffe prototxt/weights and darknet cfg/weights +- [**776**星][1y] [C++] [polysync/oscc](https://github.com/polysync/oscc) Open Source Car Control +- [**776**星][2m] [C++] [nodejs/llnode](https://github.com/nodejs/llnode) An lldb plugin for Node.js and V8, which enables inspection of JavaScript states for insights into Node.js processes and their core dumps. +- [**775**星][12m] [HTML] [sense-of-security/adrecon](https://github.com/sense-of-security/adrecon) 收集Active Directory信息并生成报告 - [**775**星][2y] [Py] [dagrz/aws_pwn](https://github.com/dagrz/aws_pwn) A collection of AWS penetration testing junk -- [**774**星][2m] [C++] [nodejs/llnode](https://github.com/nodejs/llnode) An lldb plugin for Node.js and V8, which enables inspection of JavaScript states for insights into Node.js processes and their core dumps. -- [**774**星][2y] [C++] [dor1s/libfuzzer-workshop](https://github.com/dor1s/libfuzzer-workshop) Repository for materials of "Modern fuzzing of C/C++ Projects" workshop. +- [**774**星][2y] [TS] [uwnetworkslab/uproxy-p2p](https://github.com/uwnetworkslab/uproxy-p2p) Internet without borders - [**774**星][4y] [amq/firefox-debloat](https://github.com/amq/firefox-debloat) Stop Firefox leaking data about you - [**773**星][2y] [Py] [viralmaniar/passhunt](https://github.com/viralmaniar/passhunt) Passhunt is a simple tool for searching of default credentials for network devices, web applications and more. Search through 523 vendors and their 2084 default passwords. -- [**773**星][2y] [TypeScript] [uwnetworkslab/uproxy-p2p](https://github.com/uwnetworkslab/uproxy-p2p) Internet without borders -- [**771**星][12m] [HTML] [sense-of-security/adrecon](https://github.com/sense-of-security/adrecon) 收集Active Directory信息并生成报告 -- [**771**星][20d] [Go] [kolide/fleet](https://github.com/kolide/fleet) A flexible control server for osquery fleets -- [**771**星][1m] [Py] [kevthehermit/ratdecoders](https://github.com/kevthehermit/ratdecoders) Python Decoders for Common Remote Access Trojans -- [**771**星][9d] [C#] [justcoding121/titanium-web-proxy](https://github.com/justcoding121/titanium-web-proxy) A cross-platform asynchronous HTTP(S) proxy server in C#. -- [**771**星][4y] [C++] [google/rowhammer-test](https://github.com/google/rowhammer-test) Test DRAM for bit flips caused by the rowhammer problem -- [**769**星][13d] [Go] [bishopfox/sliver](https://github.com/bishopfox/sliver) Implant framework +- [**772**星][8d] [payloadbox/xss-payload-list](https://github.com/payloadbox/xss-payload-list) XSS 漏洞Payload列表 +- [**772**星][10d] [Go] [liamg/tfsec](https://github.com/liamg/tfsec) +- [**771**星][4y] [C++] [google/rowhammer-test](https://github.com/google/rowhammer-test) 以正常的用户模式进程执行,检测rowhammer漏洞 +- [**769**星][2y] [HTML] [wi-fi-analyzer/fluxion](https://github.com/wi-fi-analyzer/fluxion) fluxion:linset 的重制版,兼容最新版 Kali +- [**769**星][2d] [C++] [shekyan/slowhttptest](https://github.com/shekyan/slowhttptest) 应用层DoS攻击模拟器 +- [**769**星][2m] [HTML] [rewardone/oscprepo](https://github.com/rewardone/oscprepo) A list of commands, scripts, resources, and more that I have gathered and attempted to consolidate for use as OSCP (and more) study material. Commands in 'Usefulcommands' Keepnote. Bookmarks and reading material in 'BookmarkList' Keepnote. Reconscan in scripts folder. +- [**769**星][2d] [Py] [jtpereyda/boofuzz](https://github.com/jtpereyda/boofuzz) 网络协议Fuzzing框架, sulley的继任者 +- [**769**星][4d] [C#] [damianh/proxykit](https://github.com/damianh/proxykit) A toolkit to create code-first HTTP reverse proxies on ASP.NET Core - [**768**星][5y] [Py] [shadowsocks/chinadns-python](https://github.com/shadowsocks/chinadns-python) Protect yourself against DNS poisoning in China. -- [**767**星][2m] [HTML] [rewardone/oscprepo](https://github.com/rewardone/oscprepo) A list of commands, scripts, resources, and more that I have gathered and attempted to consolidate for use as OSCP (and more) study material. Commands in 'Usefulcommands' Keepnote. Bookmarks and reading material in 'BookmarkList' Keepnote. Reconscan in scripts folder. -- [**766**星][2y] [HTML] [wi-fi-analyzer/fluxion](https://github.com/wi-fi-analyzer/fluxion) fluxion:linset 的重制版,兼容最新版 Kali -- [**766**星][1m] [Py] [vesche/scanless](https://github.com/vesche/scanless) 端口扫描器 -- [**766**星][12d] [Shell] [aqzt/kjyw](https://github.com/aqzt/kjyw) 快捷运维,代号kjyw,项目基于shell、python,运维脚本工具库,收集各类运维常用工具脚本,实现快速安装nginx、mysql、php、redis、nagios、运维经常使用的脚本等等... +- [**768**星][1m] [Py] [vesche/scanless](https://github.com/vesche/scanless) 端口扫描器 +- [**768**星][2d] [Java] [tmobile/pacbot](https://github.com/tmobile/pacbot) PacBot (Policy as Code Bot) +- [**767**星][2m] [daviddias/awesome-hacking-locations](https://github.com/daviddias/awesome-hacking-locations) +- [**767**星][3d] [JS] [brianlovin/security-checklist](https://github.com/brianlovin/security-checklist) A checklist for staying safe on the internet +- [**766**星][7d] [C++] [snort3/snort3](https://github.com/snort3/snort3) 下一代Snort IPS(入侵防御系统)。 - [**765**星][5y] [C#] [azzvx/gogotester](https://github.com/azzvx/gogotester) -- [**765**星][2m] [daviddias/awesome-hacking-locations](https://github.com/daviddias/awesome-hacking-locations) -- [**765**星][1m] [C++] [shekyan/slowhttptest](https://github.com/shekyan/slowhttptest) Application Layer DoS attack simulator -- [**764**星][10d] [Py] [jtpereyda/boofuzz](https://github.com/jtpereyda/boofuzz) 网络协议Fuzzing框架, sulley的继任者 -- [**764**星][11d] [C#] [damianh/proxykit](https://github.com/damianh/proxykit) A toolkit to create code-first HTTP reverse proxies on ASP.NET Core -- [**764**星][8d] [JS] [brianlovin/security-checklist](https://github.com/brianlovin/security-checklist) A checklist for staying safe on the internet -- [**762**星][2m] [Java] [tmobile/pacbot](https://github.com/tmobile/pacbot) PacBot (Policy as Code Bot) +- [**765**星][1y] [pfarb/awesome-crypto-papers](https://github.com/pfarb/awesome-crypto-papers) A curated list of cryptography papers, articles, tutorials and howtos. +- [**765**星][15d] [axtmueller/windows-kernel-explorer](https://github.com/axtmueller/windows-kernel-explorer) Windows内核研究工具 +- [**764**星][7m] [Py] [gkbrk/slowloris](https://github.com/gkbrk/slowloris) HTTP DoS 服务攻击,主要影响多线程服务器 +- [**764**星][2m] [Py] [ashutosh1206/crypton](https://github.com/ashutosh1206/crypton) Library consisting of explanation and implementation of all the existing attacks on various Encryption Systems, Digital Signatures, Authentication methods along with example challenges from CTFs +- [**763**星][1y] [Java] [mbechler/marshalsec](https://github.com/mbechler/marshalsec) Java解密器(Unmarshaller)安全 - 将数据转换为可执行的代码 +- [**763**星][10m] [Py] [hlldz/spookflare](https://github.com/hlldz/spookflare) Loader, dropper generator with multiple features for bypassing client-side and network-side countermeasures. +- [**762**星][7y] [grugq/portal](https://github.com/grugq/portal) Personal Onion Router To Assure Liberty - [**762**星][11m] [C++] [comaeio/porosity](https://github.com/comaeio/porosity) *UNMAINTAINED* Decompiler and Security Analysis tool for Blockchain-based Ethereum Smart-Contracts -- [**761**星][10m] [Py] [hlldz/spookflare](https://github.com/hlldz/spookflare) Loader, dropper generator with multiple features for bypassing client-side and network-side countermeasures. -- [**761**星][7y] [grugq/portal](https://github.com/grugq/portal) Personal Onion Router To Assure Liberty -- [**760**星][17d] [C++] [snort3/snort3](https://github.com/snort3/snort3) Snort++ -- [**760**星][13d] [axtmueller/windows-kernel-explorer](https://github.com/axtmueller/windows-kernel-explorer) Windows内核研究工具 -- [**759**星][7d] [HTML] [payloadbox/xss-payload-list](https://github.com/payloadbox/xss-payload-list) XSS 漏洞Payload列表 -- [**759**星][1y] [Java] [mbechler/marshalsec](https://github.com/mbechler/marshalsec) Java解密器(Unmarshaller)安全 - 将数据转换为可执行的代码 -- [**758**星][4m] [Py] [s0md3v/hash-buster](https://github.com/s0md3v/Hash-Buster) Crack hashes in seconds. -- [**758**星][1y] [pfarb/awesome-crypto-papers](https://github.com/pfarb/awesome-crypto-papers) A curated list of cryptography papers, articles, tutorials and howtos. -- [**758**星][5m] [Py] [lgandx/pcredz](https://github.com/lgandx/pcredz) This tool extracts Credit card numbers, NTLM(DCE-RPC, HTTP, SQL, LDAP, etc), Kerberos (AS-REQ Pre-Auth etype 23), HTTP Basic, SNMP, POP, SMTP, FTP, IMAP, etc from a pcap file or from a live interface. -- [**757**星][20d] [Go] [thoughtworks/talisman](https://github.com/thoughtworks/talisman) By hooking into the pre-push hook provided by Git, Talisman validates the outgoing changeset for things that look suspicious - such as authorization tokens and private keys. -- [**757**星][1m] [Py] [snovvcrash/usbrip](https://github.com/snovvcrash/usbrip) Simple CLI forensics tool for tracking USB device artifacts (history of USB events) on GNU/Linux -- [**757**星][18d] [Py] [mubix/shellshocker-pocs](https://github.com/mubix/shellshocker-pocs) Collection of Proof of Concepts and Potential Targets for #ShellShocker -- [**756**星][8m] [Py] [misterbianco/boopsuite](https://github.com/MisterBianco/BoopSuite) 无线审计与安全测试 -- [**756**星][2m] [Py] [ashutosh1206/crypton](https://github.com/ashutosh1206/crypton) Library consisting of explanation and implementation of all the existing attacks on various Encryption Systems, Digital Signatures, Authentication methods along with example challenges from CTFs -- [**755**星][3y] [masatokinugawa/filterbypass](https://github.com/masatokinugawa/filterbypass) 浏览器XSS 过滤绕过清单 -- [**754**星][1y] [Py] [greatsct/greatsct](https://github.com/greatsct/greatsct) The project is called Great SCT (Great Scott). Great SCT is an open source project to generate application white list bypasses. This tool is intended for BOTH red and blue team. -- [**754**星][3y] [Py] [eastee/rebreakcaptcha](https://github.com/eastee/rebreakcaptcha) A logic vulnerability, dubbed ReBreakCaptcha, which lets you easily bypass Google's ReCaptcha v2 anywhere on the web +- [**761**星][20d] [Py] [mubix/shellshocker-pocs](https://github.com/mubix/shellshocker-pocs) Collection of Proof of Concepts and Potential Targets for #ShellShocker +- [**761**星][3m] [jakejarvis/awesome-shodan-queries](https://github.com/jakejarvis/awesome-shodan-queries) +- [**760**星][4m] [Py] [s0md3v/hash-buster](https://github.com/s0md3v/Hash-Buster) Crack hashes in seconds. +- [**760**星][8m] [Py] [misterbianco/boopsuite](https://github.com/MisterBianco/BoopSuite) 无线审计与安全测试 +- [**760**星][22d] [Go] [thoughtworks/talisman](https://github.com/thoughtworks/talisman) By hooking into the pre-push hook provided by Git, Talisman validates the outgoing changeset for things that look suspicious - such as authorization tokens and private keys. +- [**760**星][1m] [Py] [snovvcrash/usbrip](https://github.com/snovvcrash/usbrip) Simple CLI forensics tool for tracking USB device artifacts (history of USB events) on GNU/Linux +- [**760**星][5m] [Py] [lgandx/pcredz](https://github.com/lgandx/pcredz) This tool extracts Credit card numbers, NTLM(DCE-RPC, HTTP, SQL, LDAP, etc), Kerberos (AS-REQ Pre-Auth etype 23), HTTP Basic, SNMP, POP, SMTP, FTP, IMAP, etc from a pcap file or from a live interface. +- [**760**星][4m] [Go] [haccer/subjack](https://github.com/haccer/subjack) 异步多线程扫描子域列表,识别能够被劫持的子域。Go 编写 +- [**759**星][3y] [masatokinugawa/filterbypass](https://github.com/masatokinugawa/filterbypass) 浏览器XSS 过滤绕过清单 +- [**756**星][1m] [Py] [nekmo/dirhunt](https://github.com/nekmo/dirhunt) Web爬虫, 针对搜索和分析路径做了优化 +- [**756**星][1y] [Py] [greatsct/greatsct](https://github.com/greatsct/greatsct) 生成绕过常见防病毒解决方案和应用程序白名单解决方案的metasploit payload +- [**755**星][3y] [Py] [eastee/rebreakcaptcha](https://github.com/eastee/rebreakcaptcha) A logic vulnerability, dubbed ReBreakCaptcha, which lets you easily bypass Google's ReCaptcha v2 anywhere on the web +- [**755**星][2d] [Go] [banzaicloud/bank-vaults](https://github.com/banzaicloud/bank-vaults) A Vault swiss-army knife: a K8s operator, Go client with automatic token renewal, automatic configuration, multiple unseal options and more. A CLI tool to init, unseal and configure Vault (auth methods, secret engines). Direct secret injection into Pods. +- [**754**星][6d] [Ruby] [rubysec/ruby-advisory-db](https://github.com/rubysec/ruby-advisory-db) A database of vulnerable Ruby Gems +- [**753**星][4m] [Py] [threatexpress/domainhunter](https://github.com/threatexpress/domainhunter) Checks expired domains for categorization/reputation and Archive.org history to determine good candidates for phishing and C2 domain names - [**753**星][2y] [Py] [redballoonshenanigans/monitordarkly](https://github.com/redballoonshenanigans/monitordarkly) Poc, Presentation of Monitor OSD Exploitation, and shenanigans of high quality. -- [**752**星][7m] [Py] [gkbrk/slowloris](https://github.com/gkbrk/slowloris) Low bandwidth DoS tool. Slowloris rewrite in Python. -- [**751**星][1m] [Py] [nekmo/dirhunt](https://github.com/nekmo/dirhunt) Web爬虫, 针对搜索和分析路径做了优化 -- [**751**星][17d] [Py] [korcankaraokcu/pince](https://github.com/korcankaraokcu/pince) A reverse engineering tool that'll supply the place of Cheat Engine for linux -- [**751**星][10m] [PowerShell] [davehull/kansa](https://github.com/davehull/kansa) A Powershell incident response framework -- [**750**星][22d] [Ruby] [rubysec/ruby-advisory-db](https://github.com/rubysec/ruby-advisory-db) A database of vulnerable Ruby Gems +- [**753**星][4m] [Shell] [nahamsec/lazyrecon](https://github.com/nahamsec/lazyrecon) 侦查(reconnaissance)过程自动化脚本, 可自动使用Sublist3r/certspotter获取子域名, 调用nmap/dirsearch等 +- [**753**星][19d] [Py] [korcankaraokcu/pince](https://github.com/korcankaraokcu/pince) A reverse engineering tool that'll supply the place of Cheat Engine for linux +- [**752**星][5d] [C] [wolfssl/wolfssl](https://github.com/wolfssl/wolfssl) wolfSSL (formerly CyaSSL) is a small, fast, portable implementation of TLS/SSL for embedded devices to the cloud. wolfSSL supports up to TLS 1.3! +- [**752**星][10m] [PS] [davehull/kansa](https://github.com/davehull/kansa) A Powershell incident response framework +- [**751**星][2d] [Py] [rajkumrdusad/tool-x](https://github.com/rajkumrdusad/tool-x) Tool-X is a kali linux hacking Tool installer. Tool-X developed for termux and other android terminals. using Tool-X you can install almost 370+ hacking tools in termux app and other linux based distributions. +- [**751**星][23d] [Java] [owasp/securityshepherd](https://github.com/owasp/securityshepherd) Web and mobile application security training platform +- [**749**星][15d] [HTML] [tennc/fuzzdb](https://github.com/tennc/fuzzdb) 一个fuzzdb扩展库 - [**749**星][2y] [PHP] [sektioneins/pcc](https://github.com/sektioneins/pcc) PHP 安全配置检查器 -- [**749**星][8d] [Go] [liamg/tfsec](https://github.com/liamg/tfsec) -- [**748**星][4m] [Py] [threatexpress/domainhunter](https://github.com/threatexpress/domainhunter) Checks expired domains for categorization/reputation and Archive.org history to determine good candidates for phishing and C2 domain names +- [**748**星][2y] [Go] [pforemski/dingo](https://github.com/pforemski/dingo) A DNS client in Go that supports Google DNS over HTTPS - [**748**星][2y] [Py] [d35m0nd142/lfisuite](https://github.com/d35m0nd142/lfisuite) Totally Automatic LFI Exploiter (+ Reverse Shell) and Scanner -- [**747**星][2y] [Go] [pforemski/dingo](https://github.com/pforemski/dingo) A DNS client in Go that supports Google DNS over HTTPS -- [**747**星][21d] [Java] [owasp/securityshepherd](https://github.com/owasp/securityshepherd) Web and mobile application security training platform +- [**748**星][2m] [Py] [buffer/thug](https://github.com/buffer/thug) Python low-interaction honeyclient - [**747**星][11m] [Py] [infobyte/spoilerwall](https://github.com/infobyte/spoilerwall) Spoilerwall introduces a brand new concept in the field of network hardening. Avoid being scanned by spoiling movies on all your ports! -- [**746**星][7d] [C] [wolfssl/wolfssl](https://github.com/wolfssl/wolfssl) wolfSSL (formerly CyaSSL) is a small, fast, portable implementation of TLS/SSL for embedded devices to the cloud. wolfSSL supports up to TLS 1.3! -- [**746**星][13d] [HTML] [tennc/fuzzdb](https://github.com/tennc/fuzzdb) 一个fuzzdb扩展库 -- [**746**星][3m] [jakejarvis/awesome-shodan-queries](https://github.com/jakejarvis/awesome-shodan-queries) -- [**746**星][4y] [fabiobaroni/awesome-exploit-development](https://github.com/fabiobaroni/awesome-exploit-development) A curated list of resources (books, tutorials, courses, tools and vulnerable applications) for learning about Exploit Development -- [**745**星][4m] [Shell] [nahamsec/lazyrecon](https://github.com/nahamsec/lazyrecon) 侦查(reconnaissance)过程自动化脚本, 可自动使用Sublist3r/certspotter获取子域名, 调用nmap/dirsearch等 -- [**745**星][3y] [PHP] [googleinurl/scanner-inurlbr](https://github.com/googleinurl/scanner-inurlbr) Advanced search in search engines, enables analysis provided to exploit GET / POST capturing emails & urls, with an internal custom validation junction for each target / url found. -- [**745**星][2m] [Py] [buffer/thug](https://github.com/buffer/thug) Python low-interaction honeyclient +- [**747**星][4y] [fabiobaroni/awesome-exploit-development](https://github.com/fabiobaroni/awesome-exploit-development) A curated list of resources (books, tutorials, courses, tools and vulnerable applications) for learning about Exploit Development +- [**747**星][6m] [Go] [cbeuw/goquiet](https://github.com/cbeuw/goquiet) A Shadowsocks obfuscation plugin utilising domain fronting to evade deep packet inspection +- [**747**星][4m] [aleenzz/cobalt_strike_wiki](https://github.com/aleenzz/cobalt_strike_wiki) Cobalt Strike系列 +- [**746**星][3y] [PHP] [googleinurl/scanner-inurlbr](https://github.com/googleinurl/scanner-inurlbr) Advanced search in search engines, enables analysis provided to exploit GET / POST capturing emails & urls, with an internal custom validation junction for each target / url found. +- [**745**星][1y] [Py] [oddcod3/phantom-evasion](https://github.com/oddcod3/phantom-evasion) Python AV evasion tool capable to generate FUD executable even with the most common 32 bit metasploit payload(exe/elf/dmg/apk) - [**744**星][5y] [C++] [zerovm/zerovm](https://github.com/zerovm/zerovm) Open-source lightweight virtualization platform -- [**744**星][7d] [Go] [banzaicloud/bank-vaults](https://github.com/banzaicloud/bank-vaults) A Vault swiss-army knife: a K8s operator, Go client with automatic token renewal, automatic configuration, multiple unseal options and more. A CLI tool to init, unseal and configure Vault (auth methods, secret engines). Direct secret injection into Pods. -- [**742**星][25d] [Go] [activecm/rita](https://github.com/activecm/rita) Real Intelligence Threat Analytics -- [**741**星][9d] [Py] [rajkumrdusad/tool-x](https://github.com/rajkumrdusad/tool-x) Tool-X is a kali linux hacking Tool installer. Tool-X developed for termux and other android terminals. using Tool-X you can install almost 263 hacking tools in termux app and other linux based distributions. -- [**741**星][1y] [Py] [oddcod3/phantom-evasion](https://github.com/oddcod3/phantom-evasion) Python AV evasion tool capable to generate FUD executable even with the most common 32 bit metasploit payload(exe/elf/dmg/apk) -- [**741**星][5m] [C] [neurobin/shc](https://github.com/neurobin/shc) Shell script compiler -- [**741**星][6m] [Go] [cbeuw/goquiet](https://github.com/cbeuw/goquiet) A Shadowsocks obfuscation plugin utilising domain fronting to evade deep packet inspection +- [**744**星][1y] [Perl] [moham3driahi/th3inspector](https://github.com/moham3driahi/th3inspector) 多合一信息收集工具 +- [**744**星][8d] [Go] [activecm/rita](https://github.com/activecm/rita) Real Intelligence Threat Analytics +- [**743**星][5m] [C] [neurobin/shc](https://github.com/neurobin/shc) Shell script compiler +- [**743**星][27d] [HTML] [m4cs/babysploit](https://github.com/m4cs/babysploit) 渗透测试工具包,旨在使您轻松学习如何使用更大,更复杂的框架(例如Metasploit) +- [**743**星][11d] [Py] [jendrikseipp/vulture](https://github.com/jendrikseipp/vulture) Find dead Python code +- [**742**星][1m] [Py] [khast3x/h8mail](https://github.com/khast3x/h8mail) Password Breach Hunting and Email OSINT tool, locally or using premium services. Supports chasing down related email +- [**741**星][9d] [trimstray/linux-hardening-checklist](https://github.com/trimstray/linux-hardening-checklist) Simple checklist to help you deploying the most important areas of the GNU/Linux production systems - work in progress. +- [**741**星][4y] [ObjC] [kjcracks/yololib](https://github.com/kjcracks/yololib) dylib injector for mach-o binaries +- [**741**星][3y] [C] [gentilkiwi/wanakiwi](https://github.com/gentilkiwi/wanakiwi) wanakiwi +- [**741**星][3d] [C++] [csmith-project/creduce](https://github.com/csmith-project/creduce) C-Reduce, a C program reducer - [**740**星][1m] [C] [yrp604/rappel](https://github.com/yrp604/rappel) A linux-based assembly REPL for x86, amd64, armv7, and armv8 - [**740**星][6m] [Go] [talkingdata/owl](https://github.com/talkingdata/owl) 企业级分布式监控告警系 -- [**740**星][2y] [C] [gentilkiwi/wanakiwi](https://github.com/gentilkiwi/wanakiwi) wanakiwi -- [**739**星][20d] [Py] [ricterz/genpass](https://github.com/ricterz/genpass) 中国特色的弱口令生成器 +- [**740**星][1y] [C#] [eladshamir/internal-monologue](https://github.com/eladshamir/internal-monologue) 在不接触LSASS的情况下提取NTLM hash +- [**739**星][22d] [Py] [ricterz/genpass](https://github.com/ricterz/genpass) 中国特色的弱口令生成器 - [**739**星][2y] [Swift] [novatecconsulting/facerecognition-in-arkit](https://github.com/novatecconsulting/facerecognition-in-arkit) Detects faces using the Vision-API and runs the extracted face through a CoreML-model to identiy the specific persons. -- [**739**星][4m] [aleenzz/cobalt_strike_wiki](https://github.com/aleenzz/cobalt_strike_wiki) Cobalt Strike系列 -- [**738**星][5m] [PowerShell] [hausec/adape-script](https://github.com/hausec/adape-script) Active Directory Assessment and Privilege Escalation Script -- [**738**星][30d] [C++] [csmith-project/creduce](https://github.com/csmith-project/creduce) C-Reduce, a C program reducer -- [**737**星][7d] [trimstray/linux-hardening-checklist](https://github.com/trimstray/linux-hardening-checklist) Simple checklist to help you deploying the most important areas of the GNU/Linux production systems - work in progress. -- [**737**星][1y] [Perl] [moham3driahi/th3inspector](https://github.com/moham3driahi/th3inspector) All in one tool for Information Gathering -- [**736**星][25d] [HTML] [m4cs/babysploit](https://github.com/m4cs/babysploit) -- [**736**星][4y] [Objective-C] [kjcracks/yololib](https://github.com/kjcracks/yololib) dylib injector for mach-o binaries -- [**735**星][1y] [Py] [uber-common/metta](https://github.com/uber-common/metta) An information security preparedness tool to do adversarial simulation. -- [**735**星][7m] [sandboxescaper/polarbearrepo](https://github.com/sandboxescaper/polarbearrepo) -- [**735**星][9d] [Py] [jendrikseipp/vulture](https://github.com/jendrikseipp/vulture) Find dead Python code -- [**735**星][1y] [C#] [eladshamir/internal-monologue](https://github.com/eladshamir/internal-monologue) Internal Monologue Attack: Retrieving NTLM Hashes without Touching LSASS -- [**735**星][6m] [Py] [devttys0/ida](https://github.com/devttys0/ida) IDA插件/脚本/模块收集 +- [**739**星][5m] [PS] [hausec/adape-script](https://github.com/hausec/adape-script) Active Directory Assessment and Privilege Escalation Script +- [**738**星][1y] [Py] [uber-common/metta](https://github.com/uber-common/metta) An information security preparedness tool to do adversarial simulation. +- [**738**星][2y] [Py] [toolswatch/vfeed](https://github.com/toolswatch/vfeed) The Correlated CVE Vulnerability And Threat Intelligence Database API +- [**738**星][15d] [Jupyter Notebook] [bukosabino/ta](https://github.com/bukosabino/ta) Technical Analysis Library using Pandas (Python) +- [**737**星][3y] [HTML] [xyntax/1000php](https://github.com/xyntax/1000php) 1000个PHP代码审计案例(2016.7以前乌云公开漏洞) +- [**737**星][5d] [C] [rapid7/metasploit-payloads](https://github.com/rapid7/metasploit-payloads) Unified repository for different Metasploit Framework payloads +- [**736**星][6m] [C] [unamer/vmware_escape](https://github.com/unamer/vmware_escape) VMwareWorkStation 12.5.5 之前版本的逃逸 Exploit +- [**736**星][6m] [Py] [devttys0/ida](https://github.com/devttys0/ida) IDA插件/脚本/模块收集 - [wpsearch](https://github.com/devttys0/ida/blob/master/scripts/wpsearch.py) 查找在MIPS WPS checksum实现中常见的立即数 - [md5hash](https://github.com/devttys0/ida/tree/master/modules/md5hash) 纯Python版的MD5 hash实现(IDA的hashlib有问题) - [alleycat](https://github.com/devttys0/ida/tree/master/plugins/alleycat) 查找向指定的函数内代码块的路径、查找两个或多个函数之间的路径、生成交互式调用图、可编程 @@ -1678,333 +1794,354 @@ - [mipslocalvars](https://github.com/devttys0/ida/tree/master/plugins/mipslocalvars) 对栈上只用于存储寄存器的变量进行命名,简化栈数据分析(MISP) - [mipsrop](https://github.com/devttys0/ida/tree/master/plugins/mipsrop) 在MIPS可执行代码中搜寻ROP。查找常见的ROP - [rizzo](https://github.com/devttys0/ida/tree/master/plugins/rizzo) 对2个或多个IDB之间的函数进行识别和重命名,基于:函数签名、对唯一字符串/常量的引用、模糊签名、调用图 +- [**735**星][7m] [sandboxescaper/polarbearrepo](https://github.com/sandboxescaper/polarbearrepo) +- [**735**星][6d] [C++] [google/shaderc](https://github.com/google/shaderc) A collection of tools, libraries, and tests for Vulkan shader compilation. +- [**735**星][10d] [Shell] [dokku/dokku-letsencrypt](https://github.com/dokku/dokku-letsencrypt) BETA: Automatic Let's Encrypt TLS Certificate installation for dokku - [**735**星][1y] [Py] [averagesecurityguy/scripts](https://github.com/averagesecurityguy/scripts) Scripts I use during pentest engagements. -- [**733**星][6m] [C] [unamer/vmware_escape](https://github.com/unamer/vmware_escape) VMwareWorkStation 12.5.5 之前版本的逃逸 Exploit -- [**733**星][2y] [Py] [toolswatch/vfeed](https://github.com/toolswatch/vfeed) The Correlated CVE Vulnerability And Threat Intelligence Database API -- [**732**星][8d] [Shell] [dokku/dokku-letsencrypt](https://github.com/dokku/dokku-letsencrypt) BETA: Automatic Let's Encrypt TLS Certificate installation for dokku -- [**731**星][27d] [C] [iaik/zombieload](https://github.com/iaik/zombieload) Proof-of-concept for the ZombieLoad attack -- [**731**星][11d] [C++] [google/shaderc](https://github.com/google/shaderc) A collection of tools, libraries, and tests for Vulkan shader compilation. +- [**734**星][3d] [TS] [casbin/node-casbin](https://github.com/casbin/node-casbin) An authorization library that supports access control models like ACL, RBAC, ABAC in Node.js +- [**733**星][2y] [Java] [gcssloop/encrypt](https://github.com/gcssloop/encrypt) [暂停维护]Android 加密解密工具包。 +- [**732**星][3m] [C] [rdesktop/rdesktop](https://github.com/rdesktop/rdesktop) rdesktop is an open source UNIX client for connecting to Windows Remote Desktop Services, capably of natively speaking Remote Desktop Protocol (RDP) in order to present the user's Windows desktop. rdesktop is known to work with Windows server version ranging from NT 4 terminal server to Windows 2012 R2. +- [**732**星][27d] [HTML] [pagerduty/incident-response-docs](https://github.com/pagerduty/incident-response-docs) PagerDuty's Incident Response Documentation. +- [**731**星][2y] [JS] [xl7dev/burpsuite](https://github.com/xl7dev/burpsuite) BurpSuite using the document and some extensions +- [**731**星][9m] [Py] [mr-un1k0d3r/dkmc](https://github.com/mr-un1k0d3r/dkmc) DKMC - Dont kill my cat - Malicious payload evasion tool +- [**731**星][29d] [C] [iaik/zombieload](https://github.com/iaik/zombieload) ZombieLoad攻击PoC - [**731**星][4m] [Lua] [cldrn/nmap-nse-scripts](https://github.com/cldrn/nmap-nse-scripts) My collection of nmap NSE scripts -- [**731**星][13d] [Jupyter Notebook] [bukosabino/ta](https://github.com/bukosabino/ta) Technical Analysis Library using Pandas (Python) - [**731**星][2y] [Py] [alex/letsencrypt-aws](https://github.com/alex/letsencrypt-aws) +- [**730**星][2m] [JS] [mandatoryprogrammer/xsshunter](https://github.com/mandatoryprogrammer/xsshunter) The XSS Hunter service - a portable version of XSSHunter.com - [**730**星][3y] [C++] [ionescu007/lxss](https://github.com/ionescu007/lxss) Win10 Linux 子系统相关 -- [**729**星][1m] [C] [rapid7/metasploit-payloads](https://github.com/rapid7/metasploit-payloads) Unified repository for different Metasploit Framework payloads -- [**729**星][25d] [HTML] [pagerduty/incident-response-docs](https://github.com/pagerduty/incident-response-docs) PagerDuty's Incident Response Documentation. +- [**729**星][3d] [C] [pmem/pmdk](https://github.com/pmem/pmdk) Persistent Memory Development Kit - [**729**星][1y] [Ruby] [chaps-io/access-granted](https://github.com/chaps-io/access-granted) Multi-role and whitelist based authorization gem for Rails (and not only Rails!) -- [**728**星][2y] [JS] [xl7dev/burpsuite](https://github.com/xl7dev/burpsuite) BurpSuite using the document and some extensions -- [**727**星][6m] [Py] [ztgrace/changeme](https://github.com/ztgrace/changeme) 默认证书扫描器 -- [**727**星][1m] [C++] [stealth/sshttp](https://github.com/stealth/sshttp) SSH/HTTP(S) multiplexer. Run a webserver and a sshd on the same port w/o changes. -- [**727**星][2m] [JS] [mandatoryprogrammer/xsshunter](https://github.com/mandatoryprogrammer/xsshunter) The XSS Hunter service - a portable version of XSSHunter.com -- [**726**星][1y] [Py] [rfunix/pompem](https://github.com/rfunix/pompem) Find exploit tool -- [**726**星][10m] [PowerShell] [l0ss/grouper](https://github.com/l0ss/grouper) A PowerShell script for helping to find vulnerable settings in AD Group Policy. (deprecated, use Grouper2 instead!) -- [**726**星][1m] [Py] [khast3x/h8mail](https://github.com/khast3x/h8mail) Password Breach Hunting and Email OSINT tool, locally or using premium services. Supports chasing down related email -- [**725**星][1y] [Py] [the-robot/sqliv](https://github.com/the-robot/sqliv) massive SQL injection vulnerability scanner -- [**725**星][2m] [C] [jedisct1/minisign](https://github.com/jedisct1/minisign) A dead simple tool to sign files and verify digital signatures. -- [**724**星][21d] [TypeScript] [casbin/node-casbin](https://github.com/casbin/node-casbin) An authorization library that supports access control models like ACL, RBAC, ABAC in Node.js -- [**723**星][7d] [Py] [globaleaks/globaleaks](https://github.com/globaleaks/globaleaks) The Open-Source Whistleblowing Software -- [**723**星][6m] [Assembly] [cirosantilli/x86-assembly-cheat](https://github.com/cirosantilli/x86-assembly-cheat) the bulk of the x86 instruction examples with assertions. -- [**723**星][6m] [Go] [anshumanbh/git-all-secrets](https://github.com/anshumanbh/git-all-secrets) 结合多个开源 git 搜索工具实现的代码审计工具 -- [**722**星][8m] [C] [mempodippy/vlany](https://github.com/mempodippy/vlany) Linux LD_PRELOAD rootkit (x86 and x86_64 architectures) -- [**721**星][8d] [Perl] [gouveaheitor/nipe](https://github.com/GouveaHeitor/nipe) Nipe is a script to make Tor Network your default gateway. -- [**721**星][3y] [HTML] [xyntax/1000php](https://github.com/xyntax/1000php) 1000个PHP代码审计案例(2016.7以前乌云公开漏洞) -- [**721**星][1m] [C++] [facebook/threatexchange](https://github.com/facebook/threatexchange) Share threat information with vetted partners +- [**728**星][6m] [Py] [ztgrace/changeme](https://github.com/ztgrace/changeme) 默认证书扫描器 +- [**727**星][1y] [Py] [the-robot/sqliv](https://github.com/the-robot/sqliv) massive SQL injection vulnerability scanner +- [**727**星][10m] [PS] [l0ss/grouper](https://github.com/l0ss/grouper) A PowerShell script for helping to find vulnerable settings in AD Group Policy. (deprecated, use Grouper2 instead!) +- [**726**星][1m] [C++] [stealth/sshttp](https://github.com/stealth/sshttp) SSH/HTTP(S) multiplexer. Run a webserver and a sshd on the same port w/o changes. +- [**726**星][2m] [C] [jedisct1/minisign](https://github.com/jedisct1/minisign) A dead simple tool to sign files and verify digital signatures. +- [**726**星][5d] [Py] [anchore/anchore-engine](https://github.com/anchore/anchore-engine) A service that analyzes docker images and applies user-defined acceptance policies to allow automated container image validation and certification +- [**725**星][1y] [Py] [rfunix/pompem](https://github.com/rfunix/pompem) Find exploit tool +- [**725**星][3d] [Py] [globaleaks/globaleaks](https://github.com/globaleaks/globaleaks) The Open-Source Whistleblowing Software +- [**725**星][6m] [Assembly] [cirosantilli/x86-assembly-cheat](https://github.com/cirosantilli/x86-assembly-cheat) the bulk of the x86 instruction examples with assertions. +- [**725**星][2d] [Py] [abhinavsingh/proxy.py](https://github.com/abhinavsingh/proxy.py) ⚡⚡⚡Fast, Lightweight, Pluggable, TLS interception capable proxy server focused on Network monitoring, controls & Application development, testing, debugging +- [**724**星][10d] [Perl] [gouveaheitor/nipe](https://github.com/GouveaHeitor/nipe) Nipe is a script to make Tor Network your default gateway. +- [**724**星][3m] [Java] [isafeblue/trackray](https://github.com/isafeblue/trackray) 溯光 (TrackRay) 3 beta⚡渗透测试框架(资产扫描|指纹识别|暴力破解|网页爬虫|端口扫描|漏洞扫描|代码审计|AWVS|NMAP|Metasploit|SQLMap) +- [**724**星][6m] [Go] [anshumanbh/git-all-secrets](https://github.com/anshumanbh/git-all-secrets) 结合多个开源 git 搜索工具实现的代码审计工具 +- [**723**星][8d] [C] [strace/strace](https://github.com/strace/strace) strace is a diagnostic, debugging and instructional userspace utility for Linux +- [**723**星][8m] [C] [mempodippy/vlany](https://github.com/mempodippy/vlany) Linux LD_PRELOAD rootkit (x86 and x86_64 architectures) +- [**722**星][2m] [Py] [shawndevans/smbmap](https://github.com/shawndevans/smbmap) SMB枚举 +- [**722**星][1y] [Py] [keystone-engine/keypatch](https://github.com/keystone-engine/keypatch) 汇编/补丁插件, 支持多架构, 基于Keystone引擎 +- [**722**星][1m] [C++] [facebook/threatexchange](https://github.com/facebook/threatexchange) Share threat information with vetted partners +- [**722**星][3m] [Py] [cloudflare/bpftools](https://github.com/cloudflare/bpftools) BPF Tools - packet analyst toolkit +- [**721**星][3d] [CSS] [w-digital-scanner/w12scan](https://github.com/w-digital-scanner/w12scan) a network asset discovery engine that can automatically aggregate related assets for analysis and use +- [**721**星][2m] [JS] [kohgylw/kiftd](https://github.com/kohgylw/kiftd) sky driver & cloud driver open source server application : kiftd . welcome to the home page: +- [**721**星][1m] [Py] [diyan/pywinrm](https://github.com/diyan/pywinrm) Python实现的WinRM客户端 - [**720**星][6m] [Py] [zyantific/idaskins](https://github.com/zyantific/idaskins) 皮肤插件 -- [**720**星][12m] [Py] [keystone-engine/keypatch](https://github.com/keystone-engine/keypatch) 汇编/补丁插件, 支持多架构, 基于Keystone引擎 -- [**719**星][7d] [C] [pmem/pmdk](https://github.com/pmem/pmdk) Persistent Memory Development Kit -- [**719**星][9m] [Py] [mr-un1k0d3r/dkmc](https://github.com/mr-un1k0d3r/dkmc) DKMC - Dont kill my cat - Malicious payload evasion tool -- [**719**星][3m] [Py] [cloudflare/bpftools](https://github.com/cloudflare/bpftools) BPF Tools - packet analyst toolkit -- [**717**星][11d] [C] [strace/strace](https://github.com/strace/strace) strace is a diagnostic, debugging and instructional userspace utility for Linux -- [**716**星][10m] [C] [ztane/python-levenshtein](https://github.com/ztane/python-levenshtein) The Levenshtein Python C extension module contains functions for fast computation of Levenshtein distance and string similarity -- [**716**星][2m] [Py] [shawndevans/smbmap](https://github.com/shawndevans/smbmap) SMBMap is a handy SMB enumeration tool +- [**720**星][10m] [C] [ztane/python-levenshtein](https://github.com/ztane/python-levenshtein) The Levenshtein Python C extension module contains functions for fast computation of Levenshtein distance and string similarity +- [**719**星][7d] [Py] [skelsec/pypykatz](https://github.com/skelsec/pypykatz) 纯Python实现的Mimikatz +- [**719**星][7m] [C] [meyerd/n2n](https://github.com/meyerd/n2n) A development branch of the n2n p2p vpn software +- [**718**星][1y] [Shell] [c0ny1/vulstudy](https://github.com/c0ny1/vulstudy) 使用docker快速搭建各大漏洞学习平台,目前可以一键搭建12个平台。 +- [**717**星][1y] [JS] [melonproject/oyente](https://github.com/melonproject/oyente) An Analysis Tool for Smart Contracts +- [**716**星][8d] [voorivex/pentest-guide](https://github.com/voorivex/pentest-guide) 基于OWASP的渗透测试指南,包括测试案例,资源和示例。 - [**716**星][2y] [Py] [madeye/sssniff](https://github.com/madeye/sssniff) sssniff:ShadowSocks流量嗅探 -- [**715**星][1y] [JS] [melonproject/oyente](https://github.com/melonproject/oyente) An Analysis Tool for Smart Contracts +- [**715**星][1m] [streaak/keyhacks](https://github.com/streaak/keyhacks) Keyhacks is a repository which shows quick ways in which API keys leaked by a bug bounty program can be checked to see if they're valid. - [**715**星][2y] [kristate/krackinfo](https://github.com/kristate/krackinfo) Vendor Response Matrix for KRACK WPA2 (Key Reinstallation Attack) +- [**715**星][10d] [Py] [f-secure/see](https://github.com/f-secure/see) 在安全环境中构建测试自动化的框架 +- [**715**星][2m] [Java] [col-e/recaf](https://github.com/col-e/recaf) A modern Java bytecode editor +- [**714**星][2m] [HTML] [j00ru/windows-syscalls](https://github.com/j00ru/windows-syscalls) Windows 系统调用表(NT/2000/XP/2003/Vista/2008/7/2012/8/10) - [**714**星][11m] [PHP] [defuse/password-hashing](https://github.com/defuse/password-hashing) Password hashing code. -- [**713**星][3m] [Java] [isafeblue/trackray](https://github.com/isafeblue/trackray) 溯光 (TrackRay) 3 beta⚡渗透测试框架(资产扫描|指纹识别|暴力破解|网页爬虫|端口扫描|漏洞扫描|代码审计|AWVS|NMAP|Metasploit|SQLMap) -- [**713**星][7d] [Py] [anchore/anchore-engine](https://github.com/anchore/anchore-engine) A service that analyzes docker images and applies user-defined acceptance policies to allow automated container image validation and certification +- [**714**星][1y] [Java] [d3vilbug/hackbar](https://github.com/d3vilbug/hackbar) HackBar plugin for Burpsuite +- [**713**星][4m] [Py] [rhinosecuritylabs/security-research](https://github.com/rhinosecuritylabs/security-research) Exploits written by the Rhino Security Labs team +- [**713**星][3d] [Py] [idapython/src](https://github.com/idapython/src) IDAPython源码 - [**713**星][5m] [Py] [adamlaurie/rfidiot](https://github.com/adamlaurie/rfidiot) python RFID / NFC library & tools -- [**712**星][1y] [snifer/security-cheatsheets](https://github.com/snifer/security-cheatsheets) A collection of cheatsheets for various infosec tools and topics. +- [**712**星][1y] [C#] [p3nt4/powershdll](https://github.com/p3nt4/powershdll) 使用rundll32执行PowerShell,绕过软件限制 +- [**712**星][9d] [C] [openvisualcloud/svt-av1](https://github.com/openvisualcloud/svt-av1) Welcome to the GitHub repo for the SVT-AV1! Help us grow the community by subscribing to our SVT-AV1 mailing list! - [**712**星][3y] [JS] [mozilla/node-client-sessions](https://github.com/mozilla/node-client-sessions) secure sessions stored in cookies -- [**712**星][2m] [HTML] [j00ru/windows-syscalls](https://github.com/j00ru/windows-syscalls) Windows 系统调用表(NT/2000/XP/2003/Vista/2008/7/2012/8/10) -- [**712**星][1m] [Py] [diyan/pywinrm](https://github.com/diyan/pywinrm) Python实现的WinRM客户端 -- [**712**星][1y] [Java] [d3vilbug/hackbar](https://github.com/d3vilbug/hackbar) HackBar plugin for Burpsuite v1.0 -- [**712**星][2m] [Java] [col-e/recaf](https://github.com/col-e/recaf) A modern Java bytecode editor -- [**712**星][7d] [Py] [abhinavsingh/proxy.py](https://github.com/abhinavsingh/proxy.py) ⚡⚡⚡Fast, Lightweight, Pluggable, TLS interception capable proxy server focused on Network monitoring, controls & Application development, testing, debugging -- [**711**星][3m] [CSS] [w-digital-scanner/w12scan](https://github.com/w-digital-scanner/w12scan) a network asset discovery engine that can automatically aggregate related assets for analysis and use -- [**711**星][4m] [Py] [rhinosecuritylabs/security-research](https://github.com/rhinosecuritylabs/security-research) Exploits written by the Rhino Security Labs team +- [**712**星][2d] [Go] [gruntwork-io/cloud-nuke](https://github.com/gruntwork-io/cloud-nuke) 通过检查(删除)其中的所有资源来清理云帐户 +- [**712**星][3d] [C] [aircrack-ng/rtl8812au](https://github.com/aircrack-ng/rtl8812au) RTL8812AU/21AU and RTL8814AU driver with monitor mode and frame injection +- [**711**星][4d] [C++] [tandasat/hyperplatform](https://github.com/tandasat/hyperplatform) 基于Intel VT-x的虚拟机管理程序,旨在在Windows上提供精简的VM-exit过滤平台 +- [**711**星][1y] [snifer/security-cheatsheets](https://github.com/snifer/security-cheatsheets) A collection of cheatsheets for various infosec tools and topics. - [**711**星][3y] [C++] [nicehash/nheqminer](https://github.com/nicehash/nheqminer) Equihash miner for NiceHash -- [**711**星][25d] [Py] [idapython/src](https://github.com/idapython/src) IDAPython源码 -- [**711**星][4m] [Go] [haccer/subjack](https://github.com/haccer/subjack) 异步多线程扫描子域列表,识别能够被劫持的子域。Go 编写 -- [**711**星][8d] [Py] [f-secure/see](https://github.com/f-secure/see) Sandboxed Execution Environment -- [**710**星][14d] [voorivex/pentest-guide](https://github.com/voorivex/pentest-guide) Penetration tests guide based on OWASP including test cases, resources and examples. -- [**710**星][7d] [Py] [skelsec/pypykatz](https://github.com/skelsec/pypykatz) 纯Python实现的Mimikatz -- [**709**星][1y] [C#] [p3nt4/powershdll](https://github.com/p3nt4/powershdll) Run PowerShell with rundll32. Bypass software restrictions. -- [**709**星][1m] [JS] [kohgylw/kiftd](https://github.com/kohgylw/kiftd) sky driver & cloud driver open source server application : kiftd . welcome to the home page: -- [**708**星][17d] [Scala] [linkedin/photon-ml](https://github.com/linkedin/photon-ml) A scalable machine learning library on Apache Spark -- [**708**星][3m] [C++] [tandasat/hyperplatform](https://github.com/tandasat/hyperplatform) 基于Intel VT-x的虚拟机管理程序,旨在在Windows上提供精简的VM-exit过滤平台 +- [**710**星][2y] [Java] [rover12421/shakaapktool](https://github.com/rover12421/shakaapktool) ShakaApktool +- [**709**星][2y] [HTML] [rapid7/hackazon](https://github.com/rapid7/hackazon) A modern vulnerable web app +- [**709**星][2m] [C] [nuand/bladerf](https://github.com/nuand/bladerf) bladeRF USB 3.0 Superspeed Software Defined Radio Source Code +- [**709**星][2y] [Py] [google/ssl_logger](https://github.com/google/ssl_logger) 解密并记录进程的SSL 流程 +- [**709**星][4m] [bit4woo/python_sec](https://github.com/bit4woo/python_sec) python安全和代码审计相关资料收集 resource collection of python security and code review +- [**708**星][2d] [ly0n/awesome-robotic-tooling](https://github.com/ly0n/awesome-robotic-tooling) Robotic resources and tools for professional robotic development with ROS in C++ and Python. +- [**708**星][19d] [Scala] [linkedin/photon-ml](https://github.com/linkedin/photon-ml) A scalable machine learning library on Apache Spark - [**708**星][2y] [Go] [sidkshatriya/dontbug](https://github.com/sidkshatriya/dontbug) Dontbug is a reverse debugger for PHP -- [**708**星][2y] [Py] [google/ssl_logger](https://github.com/google/ssl_logger) 解密并记录进程的SSL 流程 -- [**708**星][1y] [Shell] [c0ny1/vulstudy](https://github.com/c0ny1/vulstudy) 使用docker快速搭建各大漏洞学习平台,目前可以一键搭建12个平台。 -- [**707**星][1m] [streaak/keyhacks](https://github.com/streaak/keyhacks) Keyhacks is a repository which shows quick ways in which API keys leaked by a bug bounty program can be checked to see if they're valid. -- [**707**星][2y] [Java] [rover12421/shakaapktool](https://github.com/rover12421/shakaapktool) ShakaApktool -- [**707**星][2y] [HTML] [rapid7/hackazon](https://github.com/rapid7/hackazon) A modern vulnerable web app -- [**707**星][2m] [C] [nuand/bladerf](https://github.com/nuand/bladerf) bladeRF USB 3.0 Superspeed Software Defined Radio Source Code +- [**708**星][7m] [Py] [giacomolaw/keylogger](https://github.com/giacomolaw/keylogger) A simple keylogger for Windows, Linux and Mac +- [**707**星][5d] [Go] [pomerium/pomerium](https://github.com/pomerium/pomerium) Pomerium is an identity-aware access proxy. +- [**707**星][3m] [Py] [sevagas/macro_pack](https://github.com/sevagas/macro_pack) 自动生成并混淆MS 文档, 用于渗透测试、演示、社会工程评估等 - [**707**星][11m] [HTML] [juansacco/exploitpack](https://github.com/juansacco/exploitpack) Exploit Pack -The next generation exploit framework -- [**707**星][7m] [Py] [giacomolaw/keylogger](https://github.com/giacomolaw/keylogger) A simple keylogger for Windows, Linux and Mac -- [**706**星][12d] [C] [openvisualcloud/svt-av1](https://github.com/openvisualcloud/svt-av1) Welcome to the GitHub repo for the SVT-AV1! Help us grow the community by subscribing to our SVT-AV1 mailing list! -- [**706**星][21d] [Go] [gruntwork-io/cloud-nuke](https://github.com/gruntwork-io/cloud-nuke) A tool for cleaning up your cloud accounts by nuking (deleting) all resources within it -- [**706**星][4m] [JS] [crits/crits](https://github.com/crits/crits) 恶意软件和威胁仓库,利用其他开源软件为分析师和安全专家构建威胁防御的统一工具 -- [**704**星][3y] [PowerShell] [gimini/powermemory](https://github.com/gimini/powermemory) Exploit the credentials present in files and memory -- [**704**星][4m] [bit4woo/python_sec](https://github.com/bit4woo/python_sec) python安全和代码审计相关资料收集 resource collection of python security and code review -- [**703**星][2y] [PowerShell] [samratashok/kautilya](https://github.com/samratashok/kautilya) Kautilya - Tool for easy use of Human Interface Devices for offensive security and penetration testing. -- [**703**星][10d] [C] [aircrack-ng/rtl8812au](https://github.com/aircrack-ng/rtl8812au) RTL8812AU/21AU and RTL8814AU driver with monitor mode and frame injection -- [**701**星][4y] [Py] [androbugs/androbugs_framework](https://github.com/androbugs/androbugs_framework) AndroBugs Framework is an efficient Android vulnerability scanner that helps developers or hackers find potential security vulnerabilities in Android applications. No need to install on Windows. +- [**707**星][5m] [JS] [crits/crits](https://github.com/crits/crits) 恶意软件和威胁仓库,利用其他开源软件为分析师和安全专家构建威胁防御的统一工具 +- [**706**星][27d] [PHP] [ssl/ezxss](https://github.com/ssl/ezxss) ezXSS is an easy way for penetration testers and bug bounty hunters to test (blind) Cross Site Scripting. +- [**705**星][3y] [PS] [gimini/powermemory](https://github.com/gimini/powermemory) Exploit the credentials present in files and memory +- [**705**星][4y] [Py] [androbugs/androbugs_framework](https://github.com/androbugs/androbugs_framework) AndroBugs Framework is an efficient Android vulnerability scanner that helps developers or hackers find potential security vulnerabilities in Android applications. No need to install on Windows. +- [**704**星][5d] [hackplayers/hackthebox-writeups](https://github.com/hackplayers/hackthebox-writeups) Writeups for HacktheBox 'boot2root' machines +- [**704**星][2y] [PS] [samratashok/kautilya](https://github.com/samratashok/kautilya) 可为人机接口设备提供各种有效Payload,这可能有助于在渗透测试期间破坏计算机 +- [**704**星][9d] [Py] [mushorg/conpot](https://github.com/mushorg/conpot) ICS/SCADA honeypot +- [**703**星][1y] [Jupyter Notebook] [anishathalye/obfuscated-gradients](https://github.com/anishathalye/obfuscated-gradients) Obfuscated Gradients Give a False Sense of Security: Circumventing Defenses to Adversarial Examples +- [**702**星][4m] [C++] [darthton/xenos](https://github.com/darthton/xenos) Windows DLL 注入器 +- [**701**星][5y] [C] [malcolmrobb/dump1090](https://github.com/malcolmrobb/dump1090) Dump1090 is a simple Mode S decoder for RTLSDR devices +- [**701**星][1m] [C++] [cmu-sei/pharos](https://github.com/cmu-sei/pharos) 二进制程序的自动化静态分析工具 - [**700**星][2y] [yichengchen/shadowsocksx-r](https://github.com/yichengchen/shadowsocksx-r) Next Generation of ShadowsocksX -- [**700**星][3m] [Py] [sevagas/macro_pack](https://github.com/sevagas/macro_pack) 自动生成并混淆MS 文档, 用于渗透测试、演示、社会工程评估等 -- [**700**星][1m] [C++] [cmu-sei/pharos](https://github.com/cmu-sei/pharos) 二进制程序的自动化静态分析工具 -- [**699**星][5y] [C] [malcolmrobb/dump1090](https://github.com/malcolmrobb/dump1090) Dump1090 is a simple Mode S decoder for RTLSDR devices -- [**699**星][8d] [Ruby] [intrigueio/intrigue-core](https://github.com/intrigueio/intrigue-core) 外部攻击面发现框架,自动化OSINT -- [**699**星][4m] [C++] [darthton/xenos](https://github.com/darthton/xenos) Windows DLL 注入器 -- [**698**星][4y] [Py] [gunnery/gunnery](https://github.com/gunnery/gunnery) Remote task execution tool -- [**698**星][1y] [Jupyter Notebook] [anishathalye/obfuscated-gradients](https://github.com/anishathalye/obfuscated-gradients) Obfuscated Gradients Give a False Sense of Security: Circumventing Defenses to Adversarial Examples -- [**697**星][13d] [C#] [mganss/htmlsanitizer](https://github.com/mganss/htmlsanitizer) Cleans HTML to avoid XSS attacks -- [**697**星][1y] [Py] [bugscanteam/dnslog](https://github.com/bugscanteam/dnslog) 监控 DNS 解析记录和 HTTP 访问记录 +- [**700**星][15d] [C#] [multipoolminer/multipoolminer](https://github.com/multipoolminer/multipoolminer) Monitors crypto mining pools in real-time in order to find the most profitable for your machine. Controls any miner that is available via command line. +- [**699**星][8d] [C#] [mganss/htmlsanitizer](https://github.com/mganss/htmlsanitizer) Cleans HTML to avoid XSS attacks +- [**699**星][10d] [Ruby] [intrigueio/intrigue-core](https://github.com/intrigueio/intrigue-core) 外部攻击面发现框架,自动化OSINT +- [**699**星][4y] [Py] [gunnery/gunnery](https://github.com/gunnery/gunnery) Remote task execution tool +- [**699**星][1y] [Py] [bugscanteam/dnslog](https://github.com/bugscanteam/dnslog) 监控 DNS 解析记录和 HTTP 访问记录 +- [**698**星][22d] [C] [scanmem/scanmem](https://github.com/scanmem/scanmem) memory scanner for Linux +- [**698**星][2m] [Py] [mjg59/python-broadlink](https://github.com/mjg59/python-broadlink) Python模块,用于控制Broadlink RM2 / 3(Pro)遥控器、A1传感器平台和SP2 / 3智能插头 +- [**697**星][8m] [C] [hfiref0x/tdl](https://github.com/hfiref0x/tdl) Driver loader for bypassing Windows x64 Driver Signature Enforcement - [**697**星][4m] [CSS] [ajinabraham/cmsscan](https://github.com/ajinabraham/cmsscan) Scan Wordpress, Drupal, Joomla, vBulletin websites for Security issues -- [**696**星][25d] [PHP] [ssl/ezxss](https://github.com/ssl/ezxss) ezXSS is an easy way for penetration testers and bug bounty hunters to test (blind) Cross Site Scripting. -- [**696**星][20d] [C] [scanmem/scanmem](https://github.com/scanmem/scanmem) memory scanner for Linux -- [**696**星][8d] [Py] [mushorg/conpot](https://github.com/mushorg/conpot) ICS/SCADA honeypot -- [**694**星][2y] [Py] [sensepost/det](https://github.com/sensepost/det) (extensible) Data Exfiltration Toolkit (DET) -- [**694**星][2m] [Py] [mjg59/python-broadlink](https://github.com/mjg59/python-broadlink) Python module for controlling Broadlink RM2/3 (Pro) remote controls, A1 sensor platforms and SP2/3 smartplugs -- [**694**星][8m] [C] [hfiref0x/tdl](https://github.com/hfiref0x/tdl) Driver loader for bypassing Windows x64 Driver Signature Enforcement -- [**693**星][11d] [hackplayers/hackthebox-writeups](https://github.com/hackplayers/hackthebox-writeups) Writeups for HacktheBox 'boot2root' machines -- [**693**星][5m] [C++] [stealth/opmsg](https://github.com/stealth/opmsg) opmsg message encryption +- [**696**星][2m] [C#] [harleyqu1nn/aggressorscripts](https://github.com/harleyqu1nn/aggressorscripts) Collection of Aggressor scripts for Cobalt Strike 3.0+ pulled from multiple sources +- [**695**星][3m] [uknowsec/active-directory-pentest-notes](https://github.com/uknowsec/active-directory-pentest-notes) 个人域渗透学习笔记 +- [**695**星][5m] [C++] [stealth/opmsg](https://github.com/stealth/opmsg) opmsg message encryption +- [**695**星][2y] [Py] [sensepost/det](https://github.com/sensepost/det) 可以同时使用单个或多个通道执行数据渗透的PoC +- [**693**星][1m] [YARA] [rednaga/apkid](https://github.com/rednaga/apkid) Android Application Identifier for Packers, Protectors, Obfuscators and Oddities - PEiD for Android - [**693**星][3m] [netflix/security-bulletins](https://github.com/netflix/security-bulletins) Security Bulletins that relate to Netflix Open Source -- [**693**星][2m] [C#] [harleyqu1nn/aggressorscripts](https://github.com/harleyqu1nn/aggressorscripts) Collection of Aggressor scripts for Cobalt Strike 3.0+ pulled from multiple sources +- [**693**星][2m] [Go] [dliv3/venom](https://github.com/dliv3/venom) Venom - A Multi-hop Proxy for Penetration Testers - [**692**星][3y] [Ruby] [phatworx/devise_security_extension](https://github.com/phatworx/devise_security_extension) An enterprise security extension for devise, trying to meet industrial standard security demands for web applications. -- [**691**星][3m] [uknowsec/active-directory-pentest-notes](https://github.com/uknowsec/active-directory-pentest-notes) 个人域渗透学习笔记 -- [**691**星][8m] [JS] [zyfworks/steam-key](https://github.com/zyfworks/steam-key) Steam远程激活 -- [**691**星][1m] [YARA] [rednaga/apkid](https://github.com/rednaga/apkid) Android Application Identifier for Packers, Protectors, Obfuscators and Oddities - PEiD for Android -- [**689**星][5m] [C++] [google/certificate-transparency](https://github.com/google/certificate-transparency) Auditing for TLS certificates. -- [**688**星][5y] [C] [vmt/udis86](https://github.com/vmt/udis86) Disassembler Library for x86 and x86-64 +- [**692**星][3d] [HTML] [owasp/asvs](https://github.com/owasp/asvs) Application Security Verification Standard +- [**691**星][15d] [C] [shadow/shadow](https://github.com/shadow/shadow) shadow:独特的离散事件(discrete-event)网络仿真器/模拟器,可以通过模拟互联网拓扑运行真正的应用程序,如 Tor 和 Bitcoin +- [**691**星][5m] [C++] [google/certificate-transparency](https://github.com/google/certificate-transparency) Auditing for TLS certificates. +- [**691**星][2m] [C++] [bareflank/hypervisor](https://github.com/bareflank/hypervisor) lightweight hypervisor SDK written in C++ with support for Windows, Linux and UEFI +- [**690**星][8m] [JS] [zyfworks/steam-key](https://github.com/zyfworks/steam-key) Steam远程激活 +- [**690**星][5y] [C] [vmt/udis86](https://github.com/vmt/udis86) Disassembler Library for x86 and x86-64 +- [**690**星][2d] [C] [powershell/openssh-portable](https://github.com/powershell/openssh-portable) Portable OpenSSH, all Win32-OpenSSH releases and wiki are managed at +- [**690**星][7m] [Py] [mr-un1k0d3r/powerlessshell](https://github.com/mr-un1k0d3r/powerlessshell) 依靠MSBuild.exe远程执行PowerShell脚本和命令 +- [**689**星][28d] [Java] [wrbug/developerhelper](https://github.com/wrbug/developerhelper) 帮助开发人员快速开发的工具 +- [**688**星][6m] [Py] [mobier/shadowsocksr-speed](https://github.com/mobier/shadowsocksr-speed) SSR 批量测试节点有效带宽 - [**688**星][7y] [Ruby] [juuso/bozocrack](https://github.com/juuso/bozocrack) A silly & effective MD5 cracker in Ruby -- [**687**星][7m] [Py] [mr-un1k0d3r/powerlessshell](https://github.com/mr-un1k0d3r/powerlessshell) Run PowerShell command without invoking powershell.exe -- [**687**星][2m] [Go] [dliv3/venom](https://github.com/dliv3/venom) Venom - A Multi-hop Proxy for Penetration Testers -- [**686**星][21d] [OCaml] [moby/vpnkit](https://github.com/moby/vpnkit) A toolkit for embedding VPN capabilities in your application -- [**686**星][7d] [C] [powershell/openssh-portable](https://github.com/powershell/openssh-portable) Portable OpenSSH, all Win32-OpenSSH releases and wiki are managed at -- [**686**星][7d] [Java] [peergos/peergos](https://github.com/peergos/peergos) A decentralised, secure file storage and social network -- [**686**星][8m] [Py] [kiorky/spynner](https://github.com/kiorky/spynner) Programmatic web browsing module with AJAX support for Python -- [**685**星][2m] [C#] [cobbr/sharpsploit](https://github.com/cobbr/sharpsploit) SharpSploit is a .NET post-exploitation library written in C# -- [**685**星][8m] [Shell] [1n3/brutex](https://github.com/1n3/brutex) Automatically brute force all services running on a target. -- [**684**星][1y] [C] [saelo/pwn2own2018](https://github.com/saelo/pwn2own2018) Pwn2Own 2018 Safari+macOS 漏洞利用链 -- [**684**星][10m] [Py] [merrychap/shellen](https://github.com/merrychap/shellen) 交互式Shellcode开发环境 -- [**682**星][9m] [Shell] [dmarmor/epichrome](https://github.com/dmarmor/epichrome) An application (Epichrome.app) and Chrome extension (Epichrome Helper) to create and use Chrome-based SSBs on Mac OSX. -- [**681**星][12m] [HTML] [zhengmin1989/myarticles](https://github.com/zhengmin1989/myarticles) 蒸米的文章(iOS冰与火之歌系列,一步一步学ROP系列,安卓动态调试七种武器系列等) -- [**681**星][22d] [HTML] [owasp/asvs](https://github.com/owasp/asvs) Application Security Verification Standard -- [**681**星][5m] [leezj9671/pentest_interview](https://github.com/leezj9671/pentest_interview) 个人准备渗透测试和安全面试的经验之谈,和去部分厂商的面试题,干货真的满满~ -- [**680**星][10m] [Objective-C] [unixpickle/jamwifi](https://github.com/unixpickle/jamwifi) A GUI, easy to use WiFi network jammer for Mac OS X -- [**679**星][17d] [Py] [rurik/noriben](https://github.com/rurik/noriben) Portable, Simple, Malware Analysis Sandbox -- [**679**星][1m] [Py] [iceyhexman/onlinetools](https://github.com/iceyhexman/onlinetools) 在线cms识别|信息泄露|工控|系统|物联网安全|cms漏洞扫描|nmap端口扫描|子域名获取|待续.. -- [**679**星][11d] [Py] [grayddq/gscan](https://github.com/grayddq/gscan) 本程序旨在为安全应急响应人员对Linux主机排查时提供便利,实现主机侧Checklist的自动全面化检测,根据检测结果自动数据聚合,进行黑客攻击路径溯源。 -- [**679**星][2m] [andrewjkerr/security-cheatsheets](https://github.com/andrewjkerr/security-cheatsheets) -- [**678**星][2m] [Swift] [yenom/bitcoinkit](https://github.com/yenom/BitcoinKit) Bitcoin protocol toolkit for Swift +- [**688**星][13d] [Py] [grayddq/gscan](https://github.com/grayddq/gscan) 本程序旨在为安全应急响应人员对Linux主机排查时提供便利,实现主机侧Checklist的自动全面化检测,根据检测结果自动数据聚合,进行黑客攻击路径溯源。 +- [**688**星][2m] [C#] [cobbr/sharpsploit](https://github.com/cobbr/sharpsploit) SharpSploit is a .NET post-exploitation library written in C# +- [**687**星][2d] [Java] [peergos/peergos](https://github.com/peergos/peergos) A decentralised, secure file storage and social network +- [**687**星][8m] [Py] [kiorky/spynner](https://github.com/kiorky/spynner) Programmatic web browsing module with AJAX support for Python +- [**687**星][2y] [C] [1n3/privesc](https://github.com/1n3/privesc) A collection of Windows, Linux and MySQL privilege escalation scripts and exploits. +- [**687**星][8m] [Shell] [1n3/brutex](https://github.com/1n3/brutex) Automatically brute force all services running on a target. +- [**686**星][23d] [OCaml] [moby/vpnkit](https://github.com/moby/vpnkit) A toolkit for embedding VPN capabilities in your application +- [**686**星][10m] [Py] [merrychap/shellen](https://github.com/merrychap/shellen) 交互式Shellcode开发环境 +- [**686**星][5m] [leezj9671/pentest_interview](https://github.com/leezj9671/pentest_interview) 个人准备渗透测试和安全面试的经验之谈,和去部分厂商的面试题,干货真的满满~ +- [**685**星][1y] [C] [saelo/pwn2own2018](https://github.com/saelo/pwn2own2018) Pwn2Own 2018 Safari+macOS 漏洞利用链 +- [**685**星][1m] [Py] [iceyhexman/onlinetools](https://github.com/iceyhexman/onlinetools) 在线cms识别|信息泄露|工控|系统|物联网安全|cms漏洞扫描|nmap端口扫描|子域名获取|待续.. +- [**683**星][12m] [HTML] [zhengmin1989/myarticles](https://github.com/zhengmin1989/myarticles) 蒸米的文章(iOS冰与火之歌系列,一步一步学ROP系列,安卓动态调试七种武器系列等) +- [**683**星][5y] [C] [antirez/hping](https://github.com/antirez/hping) send custom TCP/IP packets and to display target replies like ping do with ICMP replies +- [**683**星][2m] [JS] [animir/node-rate-limiter-flexible](https://github.com/animir/node-rate-limiter-flexible) Node.js rate limit requests by key with atomic increments. Protection from DDoS and Brute-Force attacks in process Memory, Redis, MongoDb, Memcached, MySQL, PostgreSQL, Cluster or PM +- [**681**星][11m] [ObjC] [unixpickle/jamwifi](https://github.com/unixpickle/jamwifi) A GUI, easy to use WiFi network jammer for Mac OS X +- [**681**星][19d] [Py] [rurik/noriben](https://github.com/rurik/noriben) Portable, Simple, Malware Analysis Sandbox +- [**680**星][6m] [Py] [paranoidninja/carboncopy](https://github.com/paranoidninja/carboncopy) A tool which creates a spoofed certificate of any online website and signs an Executable for AV Evasion. Works for both Windows and Linux +- [**680**星][9m] [Shell] [dmarmor/epichrome](https://github.com/dmarmor/epichrome) An application (Epichrome.app) and Chrome extension (Epichrome Helper) to create and use Chrome-based SSBs on Mac OSX. +- [**680**星][2m] [andrewjkerr/security-cheatsheets](https://github.com/andrewjkerr/security-cheatsheets) +- [**679**星][2m] [Swift] [yenom/bitcoinkit](https://github.com/yenom/BitcoinKit) Bitcoin protocol toolkit for Swift +- [**679**星][1y] [PS] [arvanaghi/sessiongopher](https://github.com/Arvanaghi/SessionGopher) 使用WMI为远程访问工具(如WinSCP,PuTTY,SuperPuTTY,FileZilla和Microsoft远程桌面)提取保存的会话信息。PowerShell编写 +- [**678**星][2d] [Java] [ron190/jsql-injection](https://github.com/ron190/jsql-injection) Java编写的自动化 SQL 注入工具,跨平台 +- [**678**星][2m] [Go] [pquerna/otp](https://github.com/pquerna/otp) 一次性密码工具,Golang编写 +- [**678**星][2d] [Kotlin] [mygod/vpnhotspot](https://github.com/mygod/vpnhotspot) Share your VPN connection over hotspot or repeater! (root required) - [**678**星][2y] [Py] [kkevsterrr/backdoorme](https://github.com/kkevsterrr/backdoorme) powerful auto-backdooring utility -- [**677**星][5m] [Py] [mobier/shadowsocksr-speed](https://github.com/mobier/shadowsocksr-speed) SSR 批量测试节点有效带宽 -- [**676**星][8d] [Java] [ron190/jsql-injection](https://github.com/ron190/jsql-injection) Java编写的自动化 SQL 注入工具,跨平台 -- [**676**星][5y] [C] [antirez/hping](https://github.com/antirez/hping) send custom TCP/IP packets and to display target replies like ping do with ICMP replies -- [**676**星][11d] [XSLT] [adon90/pentest_compilation](https://github.com/adon90/pentest_compilation) Compilation of commands, tips and scripts that helped me throughout Vulnhub, Hackthebox, OSCP and real scenarios -- [**675**星][26d] [Java] [wrbug/developerhelper](https://github.com/wrbug/developerhelper) 帮助开发人员快速开发的工具 -- [**675**星][27d] [ptresearch/attackdetection](https://github.com/ptresearch/attackdetection) Attack Detection -- [**674**星][7m] [PHP] [ircmaxell/php-compiler](https://github.com/ircmaxell/php-compiler) A compiler. For PHP -- [**674**星][7m] [C] [google/boringssl](https://github.com/google/boringssl) Mirror of BoringSSL -- [**673**星][1y] [PowerShell] [arvanaghi/sessiongopher](https://github.com/Arvanaghi/SessionGopher) SessionGopher is a PowerShell tool that uses WMI to extract saved session information for remote access tools such as WinSCP, PuTTY, SuperPuTTY, FileZilla, and Microsoft Remote Desktop. It can be run remotely or locally. -- [**673**星][2m] [Go] [pquerna/otp](https://github.com/pquerna/otp) TOTP library for Go +- [**678**星][3d] [Py] [kevthehermit/pastehunter](https://github.com/kevthehermit/pastehunter) Scanning pastebin with yara rules +- [**677**星][29d] [ptresearch/attackdetection](https://github.com/ptresearch/attackdetection) 搜索新的漏洞和0day,进行服现并创建PoC exp,以了解这些安全漏洞的工作方式,以及如何在网络层上检测到相关的攻击 +- [**677**星][1m] [Go] [google/gofuzz](https://github.com/google/gofuzz) Fuzz testing for go. +- [**677**星][13d] [XSLT] [adon90/pentest_compilation](https://github.com/adon90/pentest_compilation) Compilation of commands, tips and scripts that helped me throughout Vulnhub, Hackthebox, OSCP and real scenarios +- [**676**星][10d] [C] [zerbea/hcxdumptool](https://github.com/zerbea/hcxdumptool) Small tool to capture packets from wlan devices. +- [**676**星][5m] [C#] [outflanknl/evilclippy](https://github.com/outflanknl/evilclippy) A cross-platform assistant for creating malicious MS Office documents. Can hide VBA macros, stomp VBA code (via P-Code) and confuse macro analysis tools. Runs on Linux, OSX and Windows. +- [**675**星][5d] [C] [google/boringssl](https://github.com/google/boringssl) Mirror of BoringSSL +- [**674**星][7m] [Java] [pagalaxylab/yahfa](https://github.com/PAGalaxyLab/YAHFA) Yet Another Hook Framework for ART +- [**674**星][3y] [PHP] [xl7dev/webshell](https://github.com/xl7dev/webshell) Webshell && Backdoor Collection +- [**674**星][3y] [Batchfile] [ufologist/onekey-decompile-apk](https://github.com/ufologist/onekey-decompile-apk) 一步到位反编译apk工具(onekey decompile apk) +- [**674**星][1y] [Py] [endgameinc/rta](https://github.com/endgameinc/rta) 根据MITER ATT&CK进行建模,针对恶意tradecraft测试其检测功能。脚本框架 +- [**674**星][1y] [C] [billy-ellis/exploit-challenges](https://github.com/billy-ellis/exploit-challenges) A collection of vulnerable ARM binaries for practicing exploit development +- [**673**星][2y] [Py] [trycatchhcf/dumpsterfire](https://github.com/trycatchhcf/dumpsterfire) 用于构建自定义的、时间延迟的分布式安全事件,模块化、菜单驱动、跨平台。轻松为Blue&Red Team演习和传感器/警报映射创建自定义事件链。 - [**673**星][8m] [offensive-security/kali-arm-build-scripts](https://github.com/offensive-security/kali-arm-build-scripts) Kali Linux ARM build scripts -- [**673**星][1m] [Kotlin] [mygod/vpnhotspot](https://github.com/mygod/vpnhotspot) Share your VPN connection over hotspot or repeater! (root required) -- [**673**星][9d] [Py] [kevthehermit/pastehunter](https://github.com/kevthehermit/pastehunter) Scanning pastebin with yara rules -- [**673**星][1y] [C] [billy-ellis/exploit-challenges](https://github.com/billy-ellis/exploit-challenges) A collection of vulnerable ARM binaries for practicing exploit development -- [**672**星][3y] [PHP] [xl7dev/webshell](https://github.com/xl7dev/webshell) Webshell && Backdoor Collection -- [**672**星][7m] [Go] [honeytrap/honeytrap](https://github.com/honeytrap/honeytrap) 高级蜜罐框架, 可以运行/监控/管理蜜罐. Go语言编写 -- [**671**星][3y] [Batchfile] [ufologist/onekey-decompile-apk](https://github.com/ufologist/onekey-decompile-apk) 一步到位反编译apk工具(onekey decompile apk) -- [**671**星][6y] [C] [robertdavidgraham/heartleech](https://github.com/robertdavidgraham/heartleech) Demonstrates the "heartbleed" problem using full OpenSSL stack -- [**671**星][1m] [Go] [google/gofuzz](https://github.com/google/gofuzz) Fuzz testing for go. +- [**673**星][7m] [PHP] [ircmaxell/php-compiler](https://github.com/ircmaxell/php-compiler) A compiler. For PHP +- [**673**星][7m] [Go] [honeytrap/honeytrap](https://github.com/honeytrap/honeytrap) 高级蜜罐框架, 可以运行/监控/管理蜜罐. Go语言编写 +- [**672**星][4m] [Py] [v3n0m-scanner/v3n0m-scanner](https://github.com/v3n0m-scanner/v3n0m-scanner) Popular Pentesting scanner in Python3.6 for SQLi/XSS/LFI/RFI and other Vulns +- [**672**星][22d] [C#] [obfuscar/obfuscar](https://github.com/obfuscar/obfuscar) Open source obfuscation tool for .NET assemblies +- [**672**星][2m] [Ruby] [mozilla/ssh_scan](https://github.com/mozilla/ssh_scan) A prototype SSH configuration and policy scanner (Blog: +- [**672**星][7d] [Py] [blackorbird/apt_report](https://github.com/blackorbird/apt_report) Interesting apt report collection and some special ioc express +- [**671**星][10m] [JS] [theori-io/pwnjs](https://github.com/theori-io/pwnjs) 辅助开发浏览器exploit 的 JS 模块 - [**671**星][5m] [bloodzer0/ossa](https://github.com/bloodzer0/ossa) Open-Source Security Architecture | 开源安全架构 -- [**670**星][7m] [Java] [pagalaxylab/yahfa](https://github.com/PAGalaxyLab/YAHFA) Yet Another Hook Framework for ART -- [**670**星][2y] [Py] [trycatchhcf/dumpsterfire](https://github.com/trycatchhcf/dumpsterfire) "Security Incidents In A Box!" A modular, menu-driven, cross-platform tool for building customized, time-delayed, distributed security events. Easily create custom event chains for Blue- & Red Team drills and sensor / alert mapping. Red Teams can create decoy incidents, distractions, and lures to support and scale their operations. Build event s… -- [**670**星][10m] [JS] [theori-io/pwnjs](https://github.com/theori-io/pwnjs) 辅助开发浏览器exploit 的 JS 模块 -- [**670**星][4m] [C#] [outflanknl/evilclippy](https://github.com/outflanknl/evilclippy) A cross-platform assistant for creating malicious MS Office documents. Can hide VBA macros, stomp VBA code (via P-Code) and confuse macro analysis tools. Runs on Linux, OSX and Windows. +- [**670**星][4y] [praetorian-code/hob0rules](https://github.com/praetorian-code/Hob0Rules) Password cracking rules for Hashcat based on statistics and industry patterns +- [**670**星][4d] [C#] [uxmal/reko](https://github.com/uxmal/reko) Reko is a binary decompiler. +- [**670**星][6y] [C] [robertdavidgraham/heartleech](https://github.com/robertdavidgraham/heartleech) Demonstrates the "heartbleed" problem using full OpenSSL stack - [**670**星][3y] [Py] [n1nj4sec/memorpy](https://github.com/n1nj4sec/memorpy) Python库, 使用ctypes搜索/编辑 Windows / Linux / macOS / SunOS 程序内存 -- [**670**星][2m] [Ruby] [mozilla/ssh_scan](https://github.com/mozilla/ssh_scan) A prototype SSH configuration and policy scanner (Blog: -- [**670**星][1y] [Py] [endgameinc/rta](https://github.com/endgameinc/rta) -- [**670**星][2m] [JS] [animir/node-rate-limiter-flexible](https://github.com/animir/node-rate-limiter-flexible) Node.js rate limit requests by key with atomic increments. Protection from DDoS and Brute-Force attacks in process Memory, Redis, MongoDb, Memcached, MySQL, PostgreSQL, Cluster or PM -- [**670**星][2y] [C] [1n3/privesc](https://github.com/1n3/privesc) A collection of Windows, Linux and MySQL privilege escalation scripts and exploits. -- [**669**星][4m] [Py] [v3n0m-scanner/v3n0m-scanner](https://github.com/v3n0m-scanner/v3n0m-scanner) Popular Pentesting scanner in Python3.6 for SQLi/XSS/LFI/RFI and other Vulns -- [**669**星][7d] [C#] [uxmal/reko](https://github.com/uxmal/reko) Reko is a binary decompiler. -- [**668**星][4y] [praetorian-code/hob0rules](https://github.com/praetorian-code/Hob0Rules) Password cracking rules for Hashcat based on statistics and industry patterns -- [**666**星][20d] [C#] [obfuscar/obfuscar](https://github.com/obfuscar/obfuscar) Open source obfuscation tool for .NET assemblies -- [**666**星][2y] [Py] [lijiejie/htpwdscan](https://github.com/lijiejie/htpwdscan) A python HTTP weak pass scanner -- [**666**星][1m] [doridori/android-security-reference](https://github.com/doridori/android-security-reference) A W.I.P Android Security Ref -- [**666**星][18d] [Py] [blackorbird/apt_report](https://github.com/blackorbird/apt_report) Interesting apt report collection and some special ioc express -- [**664**星][8d] [C] [zerbea/hcxdumptool](https://github.com/zerbea/hcxdumptool) Small tool to capture packets from wlan devices. -- [**664**星][6m] [Py] [paranoidninja/carboncopy](https://github.com/paranoidninja/carboncopy) A tool which creates a spoofed certificate of any online website and signs an Executable for AV Evasion. Works for both Windows and Linux -- [**664**星][2y] [Py] [jhaddix/domain](https://github.com/jhaddix/domain) Setup script for Regon-ng -- [**664**星][7y] [Java] [honeynet/apkinspector](https://github.com/honeynet/apkinspector) APKinspector is a powerful GUI tool for analysts to analyze the Android applications. -- [**664**星][1y] [dsasmblr/hacking-online-games](https://github.com/dsasmblr/hacking-online-games) A curated list of tutorials/resources for hacking online games. -- [**664**星][1y] [Go] [0x09al/raven](https://github.com/0x09al/raven) raven is a Linkedin information gathering tool that can be used by pentesters to gather information about an organization employees using Linkedin. -- [**663**星][10m] [C++] [zrax/pycdc](https://github.com/zrax/pycdc) C++ python bytecode disassembler and decompiler +- [**669**星][11d] [Shell] [wslutilities/wslu](https://github.com/wslutilities/wslu) A collection of utilities for Windows 10 Linux Subsystems +- [**668**星][8d] [C++] [leggedrobotics/darknet_ros](https://github.com/leggedrobotics/darknet_ros) YOLO ROS: Real-Time Object Detection for ROS +- [**668**星][23d] [HCL] [rhinosecuritylabs/cloudgoat](https://github.com/rhinosecuritylabs/cloudgoat) CloudGoat is Rhino Security Labs' "Vulnerable by Design" AWS deployment tool +- [**667**星][10m] [C++] [zrax/pycdc](https://github.com/zrax/pycdc) C++ python bytecode disassembler and decompiler +- [**667**星][2y] [Py] [lijiejie/htpwdscan](https://github.com/lijiejie/htpwdscan) A python HTTP weak pass scanner +- [**667**星][11d] [Py] [kbandla/dpkt](https://github.com/kbandla/dpkt) fast, simple packet creation / parsing, with definitions for the basic TCP/IP protocols +- [**667**星][3m] [C#] [ghostpack/rubeus](https://github.com/ghostpack/rubeus) 原始Kerberos交互和滥用,C#编写 +- [**667**星][1y] [dsasmblr/hacking-online-games](https://github.com/dsasmblr/hacking-online-games) A curated list of tutorials/resources for hacking online games. +- [**667**星][1m] [doridori/android-security-reference](https://github.com/doridori/android-security-reference) A W.I.P Android Security Ref +- [**667**星][17d] [Py] [anouarbensaad/vulnx](https://github.com/anouarbensaad/vulnx) An Intelligent Bot Auto Shell Injector that detect vulnerabilities in multiple types of CMS +- [**666**星][8m] [Py] [m4ll0k/wpseku](https://github.com/m4ll0k/wpseku) WPSeku - Wordpress Security Scanner +- [**665**星][6m] [C] [robertdavidgraham/rdpscan](https://github.com/robertdavidgraham/rdpscan) A quick scanner for the CVE-2019-0708 "BlueKeep" vulnerability. +- [**665**星][2y] [Py] [jhaddix/domain](https://github.com/jhaddix/domain) Setup script for Regon-ng +- [**665**星][7y] [Java] [honeynet/apkinspector](https://github.com/honeynet/apkinspector) APKinspector is a powerful GUI tool for analysts to analyze the Android applications. +- [**665**星][23d] [C] [google/afl](https://github.com/google/afl) american fuzzy lop - a security-oriented fuzzer +- [**664**星][8d] [Py] [jazzband/django-axes](https://github.com/jazzband/django-axes) Keep track of failed login attempts in Django-powered sites. +- [**664**星][7d] [Py] [gwen001/pentest-tools](https://github.com/gwen001/pentest-tools) 日常使用的渗透工具集合 +- [**664**星][6m] [Py] [droope/droopescan](https://github.com/droope/droopescan) A plugin-based scanner that aids security researchers in identifying issues with several CMSs, mainly Drupal & Silverstripe. +- [**663**星][11m] [C#] [wwillv/godofhacker](https://github.com/wwillv/godofhacker) 由各种顶级黑客技术结合而成,基本功能覆盖面广,可满足大多数人的基本需求 - [**663**星][2y] [shadowsocksr-backup/shadowsocksx-ng](https://github.com/shadowsocksr-backup/shadowsocksx-ng) Next Generation of ShadowsocksX -- [**663**星][8m] [Py] [m4ll0k/wpseku](https://github.com/m4ll0k/wpseku) WPSeku - Wordpress Security Scanner -- [**663**星][6m] [Py] [droope/droopescan](https://github.com/droope/droopescan) A plugin-based scanner that aids security researchers in identifying issues with several CMSs, mainly Drupal & Silverstripe. -- [**662**星][11m] [C#] [wwillv/godofhacker](https://github.com/wwillv/godofhacker) 黑客神器 -- [**662**星][3m] [C#] [ghostpack/rubeus](https://github.com/ghostpack/rubeus) Trying to tame the three-headed dog. +- [**663**星][6m] [C++] [gossip-sjtu/armariris](https://github.com/gossip-sjtu/armariris) 孤挺花(Armariris) -- 由上海交通大学密码与计算机安全实验室维护的LLVM混淆框架 +- [**663**星][28d] [Java] [google/conscrypt](https://github.com/google/conscrypt) Conscrypt is a Java Security Provider that implements parts of the Java Cryptography Extension and Java Secure Socket Extension. +- [**663**星][5m] [Py] [aploium/shootback](https://github.com/aploium/shootback) a reverse TCP tunnel let you access target behind NAT or firewall +- [**663**星][1y] [Go] [0x09al/raven](https://github.com/0x09al/raven) raven is a Linkedin information gathering tool that can be used by pentesters to gather information about an organization employees using Linkedin. +- [**662**星][9m] [C] [samdenty/wi-pwn](https://github.com/samdenty/Wi-PWN) performs deauth attacks on cheap Arduino boards +- [**662**星][4d] [JS] [sadeghhayeri/greentunnel](https://github.com/sadeghhayeri/greentunnel) Green Tunnel is an anti-censorship utility designed to bypass DPI system that are put in place by various ISPs to block access to certain websites. +- [**662**星][6m] [Py] [golismero/golismero](https://github.com/golismero/golismero) 安全测试框架,当前主要是Web安全,可轻松扩展到其他扫描 - [**661**星][2y] [Py] [ysrc/gourdscanv2](https://github.com/ysrc/gourdscanv2) 被动式漏洞扫描系统 -- [**661**星][6m] [C] [robertdavidgraham/rdpscan](https://github.com/robertdavidgraham/rdpscan) A quick scanner for the CVE-2019-0708 "BlueKeep" vulnerability. -- [**661**星][5m] [Py] [aploium/shootback](https://github.com/aploium/shootback) a reverse TCP tunnel let you access target behind NAT or firewall -- [**661**星][15d] [Py] [anouarbensaad/vulnx](https://github.com/anouarbensaad/vulnx) An Intelligent Bot Auto Shell Injector that detect vulnerabilities in multiple types of CMS -- [**660**星][9d] [Shell] [wslutilities/wslu](https://github.com/wslutilities/wslu) A collection of utilities for Windows 10 Linux Subsystems -- [**660**星][21d] [HCL] [rhinosecuritylabs/cloudgoat](https://github.com/rhinosecuritylabs/cloudgoat) CloudGoat is Rhino Security Labs' "Vulnerable by Design" AWS deployment tool - [**660**星][3y] [Ruby] [igrigorik/em-proxy](https://github.com/igrigorik/em-proxy) EventMachine Proxy DSL for writing high-performance transparent / intercepting proxies in Ruby -- [**660**星][26d] [Java] [google/conscrypt](https://github.com/google/conscrypt) Conscrypt is a Java Security Provider that implements parts of the Java Cryptography Extension and Java Secure Socket Extension. -- [**660**星][6m] [Py] [golismero/golismero](https://github.com/golismero/golismero) GoLismero - The Web Knife - [**660**星][1y] [Py] [deepzec/bad-pdf](https://github.com/deepzec/bad-pdf) create malicious PDF file to steal NTLM(NTLMv1/NTLMv2) Hashes from windows machines -- [**659**星][9d] [Py] [kbandla/dpkt](https://github.com/kbandla/dpkt) fast, simple packet creation / parsing, with definitions for the basic TCP/IP protocols -- [**659**星][6m] [C++] [gossip-sjtu/armariris](https://github.com/gossip-sjtu/armariris) 孤挺花(Armariris) -- 由上海交通大学密码与计算机安全实验室维护的LLVM混淆框架 +- [**660**星][1y] [chybeta/code-audit-challenges](https://github.com/chybeta/code-audit-challenges) Code-Audit-Challenges +- [**660**星][1m] [Kotlin] [chuckerteam/chucker](https://github.com/chuckerteam/chucker) simplifies the inspection of HTTP(S) requests/responses, and Throwables fired by your Android App +- [**659**星][24d] [redhuntlabs/awesome-asset-discovery](https://github.com/redhuntlabs/awesome-asset-discovery) List of Awesome Asset Discovery Resources - [**659**星][2y] [Py] [galkan/crowbar](https://github.com/galkan/crowbar) 渗透测试期间使用的暴力破解工具 +- [**658**星][2y] [Py] [travisfsmith/sweetsecurity](https://github.com/travisfsmith/sweetsecurity) Network Security Monitoring on Raspberry Pi type devices +- [**658**星][8m] [Shell] [rfxn/linux-malware-detect](https://github.com/rfxn/linux-malware-detect) Linux Malware Detection (LMD) +- [**658**星][8d] [Py] [igogo-x86/hexrayspytools](https://github.com/igogo-x86/hexrayspytools) 结构体和类重建插件 - [**658**星][6m] [TeX] [bettercrypto/applied-crypto-hardening](https://github.com/bettercrypto/applied-crypto-hardening) Best Current Practices regarding secure online communication and configuration of services using cryptography. -- [**657**星][2y] [Py] [travisfsmith/sweetsecurity](https://github.com/travisfsmith/sweetsecurity) Network Security Monitoring on Raspberry Pi type devices -- [**657**星][21d] [C] [google/afl](https://github.com/google/afl) american fuzzy lop - a security-oriented fuzzer -- [**656**星][16d] [Py] [igogo-x86/hexrayspytools](https://github.com/igogo-x86/hexrayspytools) 结构体和类重建插件 -- [**656**星][1y] [Rust] [endgameinc/xori](https://github.com/endgameinc/xori) Xori is an automation-ready disassembly and static analysis library for PE32, 32+ and shellcode -- [**656**星][1y] [chybeta/code-audit-challenges](https://github.com/chybeta/code-audit-challenges) Code-Audit-Challenges -- [**654**星][9d] [the-akira/computer-science-resources](https://github.com/the-akira/Computer-Science-Resources) A list of resources in different fields of Computer Science (multiple languages) -- [**654**星][8m] [C] [samdenty/wi-pwn](https://github.com/samdenty/Wi-PWN) performs deauth attacks on cheap Arduino boards -- [**654**星][9m] [Java] [vulnerscom/burp-vulners-scanner](https://github.com/vulnerscom/burp-vulners-scanner) Vulnerability scanner based on vulners.com search API -- [**654**星][8m] [Shell] [rfxn/linux-malware-detect](https://github.com/rfxn/linux-malware-detect) Linux Malware Detection (LMD) -- [**654**星][1m] [Kotlin] [chuckerteam/chucker](https://github.com/chuckerteam/chucker) simplifies the inspection of HTTP(S) requests/responses, and Throwables fired by your Android App -- [**653**星][9m] [Jupyter Notebook] [supercowpowers/data_hacking](https://github.com/SuperCowPowers/data_hacking) Data Hacking Project -- [**653**星][6m] [Go] [yawning/obfs4](https://github.com/yawning/obfs4) The obfourscator (Courtesy mirror) -- [**652**星][8m] [C] [wifidog/wifidog-gateway](https://github.com/wifidog/wifidog-gateway) Repository for the wifidog-gateway captive portal designed for embedded systems -- [**652**星][4y] [Py] [praetorian-code/pentestly](https://github.com/praetorian-code/pentestly) Python and Powershell internal penetration testing framework -- [**652**星][22d] [redhuntlabs/awesome-asset-discovery](https://github.com/redhuntlabs/awesome-asset-discovery) List of Awesome Asset Discovery Resources +- [**657**星][2m] [Py] [tib3rius/autorecon](https://github.com/tib3rius/autorecon) AutoRecon is a multi-threaded network reconnaissance tool which performs automated enumeration of services. +- [**657**星][5m] [Perl] [jondonas/linux-exploit-suggester-2](https://github.com/jondonas/linux-exploit-suggester-2) Next-Generation Linux Kernel Exploit Suggester +- [**657**星][1y] [Rust] [endgameinc/xori](https://github.com/endgameinc/xori) Xori is an automation-ready disassembly and static analysis library for PE32, 32+ and shellcode +- [**656**星][2d] [the-akira/computer-science-resources](https://github.com/the-akira/Computer-Science-Resources) A list of resources in different fields of Computer Science (multiple languages) +- [**656**星][9m] [Java] [vulnerscom/burp-vulners-scanner](https://github.com/vulnerscom/burp-vulners-scanner) Vulnerability scanner based on vulners.com search API +- [**656**星][2d] [Py] [quentinhardy/odat](https://github.com/quentinhardy/odat) Oracle Database Attacking Tool +- [**655**星][9m] [Jupyter Notebook] [supercowpowers/data_hacking](https://github.com/SuperCowPowers/data_hacking) Data Hacking Project +- [**655**星][6m] [Go] [yawning/obfs4](https://github.com/yawning/obfs4) The obfourscator (Courtesy mirror) +- [**655**星][6m] [Perl] [moham3driahi/xattacker](https://github.com/moham3driahi/xattacker) X Attacker Tool ☣ Website Vulnerability Scanner & Auto Exploiter +- [**654**星][6m] [Py] [rabbitmask/weblogicscan](https://github.com/rabbitmask/weblogicscan) Weblogic一键漏洞检测工具,V1.3 +- [**654**星][2m] [Py] [hisxo/gitgraber](https://github.com/hisxo/gitgraber) monitor GitHub to search and find sensitive data in real time for different online services such as: Google, Amazon, Paypal, Github, Mailgun, Facebook, Twitter, Heroku, Stripe... +- [**654**星][18d] [Shell] [diego-treitos/linux-smart-enumeration](https://github.com/diego-treitos/linux-smart-enumeration) Linux enumeration tool for pentesting and CTFs with verbosity levels +- [**653**星][8m] [C] [wifidog/wifidog-gateway](https://github.com/wifidog/wifidog-gateway) Repository for the wifidog-gateway captive portal designed for embedded systems +- [**653**星][4y] [Py] [praetorian-code/pentestly](https://github.com/praetorian-code/pentestly) Python和Powershell内部渗透测试框架 +- [**653**星][2y] [C] [fail0verflow/shofel2](https://github.com/fail0verflow/shofel2) Tegra X1 bootrom exploit +- [**653**星][20d] [Java] [dineshshetty/android-insecurebankv2](https://github.com/dineshshetty/android-insecurebankv2) Vulnerable Android application for developers and security enthusiasts to learn about Android insecurities +- [**652**星][3y] [C] [rentzsch/mach_inject](https://github.com/rentzsch/mach_inject) interprocess code injection for Mac OS X +- [**651**星][10m] [Roff] [palantir/windows-event-forwarding](https://github.com/palantir/windows-event-forwarding) 使用 Windows 事件转发实现网络事件监测和防御 - [**651**星][1y] [Py] [knownsec/rd_checklist](https://github.com/knownsec/rd_checklist) 知道创宇研发技能表 -- [**651**星][2y] [C] [fail0verflow/shofel2](https://github.com/fail0verflow/shofel2) Tegra X1 bootrom exploit -- [**650**星][11d] [JS] [sadeghhayeri/greentunnel](https://github.com/sadeghhayeri/greentunnel) Green Tunnel is an anti-censorship utility designed to bypass DPI system that are put in place by various ISPs to block access to certain websites. -- [**650**星][3y] [C] [rentzsch/mach_inject](https://github.com/rentzsch/mach_inject) interprocess code injection for Mac OS X -- [**650**星][5m] [Perl] [jondonas/linux-exploit-suggester-2](https://github.com/jondonas/linux-exploit-suggester-2) Next-Generation Linux Kernel Exploit Suggester -- [**649**星][2m] [Py] [quentinhardy/odat](https://github.com/quentinhardy/odat) Oracle Database Attacking Tool -- [**649**星][2y] [C++] [nathancastle/bootshellcredentialprovider](https://github.com/nathancastle/bootshellcredentialprovider) Windows 10 Credential Provider intended to simplify the process of logging directly into alternative shells to Windows Explorer. -- [**649**星][6m] [Perl] [moham3driahi/xattacker](https://github.com/moham3driahi/xattacker) X Attacker Tool ☣ Website Vulnerability Scanner & Auto Exploiter -- [**649**星][18d] [Java] [dineshshetty/android-insecurebankv2](https://github.com/dineshshetty/android-insecurebankv2) Vulnerable Android application for developers and security enthusiasts to learn about Android insecurities -- [**648**星][2y] [C] [eugnis/spectre-attack](https://github.com/eugnis/spectre-attack) Example of using revealed "Spectre" exploit (CVE-2017-5753 and CVE-2017-5715) -- [**647**星][3y] [Objective-C] [isecpartners/introspy-ios](https://github.com/isecpartners/introspy-ios) Security profiling for blackbox iOS -- [**647**星][16d] [Shell] [diego-treitos/linux-smart-enumeration](https://github.com/diego-treitos/linux-smart-enumeration) Linux enumeration tool for pentesting and CTFs with verbosity levels +- [**650**星][4m] [C#] [shack2/snetcracker](https://github.com/shack2/snetcracker) 超级弱口令检查工具是一款Windows平台的弱口令审计工具,支持批量多线程检查,可快速发现弱密码、弱口令账号,密码支持和用户名结合进行检查,大大提高成功率,支持自定义服务端口和字典。 +- [**650**星][2y] [C++] [nathancastle/bootshellcredentialprovider](https://github.com/nathancastle/bootshellcredentialprovider) Windows 10 Credential Provider intended to simplify the process of logging directly into alternative shells to Windows Explorer. +- [**649**星][1m] [Shell] [toutyrater/v2ray-guide](https://github.com/toutyrater/v2ray-guide) +- [**649**星][6m] [PHP] [l3m0n/bypass_disable_functions_shell](https://github.com/l3m0n/bypass_disable_functions_shell) 一个各种方式突破Disable_functions达到命令执行的shell +- [**649**星][2y] [C] [eugnis/spectre-attack](https://github.com/eugnis/spectre-attack) Example of using revealed "Spectre" exploit (CVE-2017-5753 and CVE-2017-5715) +- [**649**星][15d] [YARA] [eset/malware-ioc](https://github.com/eset/malware-ioc) Indicators of Compromises (IOC) of our various investigations +- [**648**星][3y] [ObjC] [isecpartners/introspy-ios](https://github.com/isecpartners/introspy-ios) Security profiling for blackbox iOS +- [**647**星][1y] [Py] [simplysecurity/simplyemail](https://github.com/SimplySecurity/SimplyEmail) Email recon made fast and easy, with a framework to build on +- [**647**星][9m] [ObjC] [chenxiancai/stcobfuscator](https://github.com/chenxiancai/stcobfuscator) iOS全局自动化 代码混淆 工具!支持cocoapod组件代码一并 混淆,完美避开hardcode方法、静态库方法和系统库方法! - [**646**星][3y] [Java] [facebookarchive/proguard](https://github.com/facebookarchive/proguard) A fork of ProGuard. -- [**646**星][10m] [Roff] [palantir/windows-event-forwarding](https://github.com/palantir/windows-event-forwarding) 使用 Windows 事件转发实现网络事件监测和防御 -- [**645**星][1y] [Py] [simplysecurity/simplyemail](https://github.com/SimplySecurity/SimplyEmail) Email recon made fast and easy, with a framework to build on -- [**645**星][6m] [PHP] [l3m0n/bypass_disable_functions_shell](https://github.com/l3m0n/bypass_disable_functions_shell) 一个各种方式突破Disable_functions达到命令执行的shell - [**645**星][5y] [Shell] [hannob/bashcheck](https://github.com/hannob/bashcheck) test script for shellshocker and related vulnerabilities -- [**644**星][13d] [YARA] [eset/malware-ioc](https://github.com/eset/malware-ioc) Indicators of Compromises (IOC) of our various investigations -- [**643**星][1m] [Py] [tib3rius/autorecon](https://github.com/tib3rius/autorecon) AutoRecon is a multi-threaded network reconnaissance tool which performs automated enumeration of services. -- [**643**星][4m] [C#] [shack2/snetcracker](https://github.com/shack2/snetcracker) 超级弱口令检查工具是一款Windows平台的弱口令审计工具,支持批量多线程检查,可快速发现弱密码、弱口令账号,密码支持和用户名结合进行检查,大大提高成功率,支持自定义服务端口和字典。 +- [**645**星][1y] [Java] [faizann24/wifi-bruteforcer-fsecurify](https://github.com/faizann24/wifi-bruteforcer-fsecurify) Android app,无需 Root 即可爆破 Wifi 密码 +- [**644**星][5m] [C++] [eliboa/tegrarcmgui](https://github.com/eliboa/tegrarcmgui) C++ GUI for TegraRcmSmash (Fusée Gelée exploit for Nintendo Switch) +- [**644**星][5m] [JS] [draios/sysdig-inspect](https://github.com/draios/sysdig-inspect) A powerful opensource interface for container troubleshooting and security investigation +- [**643**星][3m] [Py] [gquere/pwn_jenkins](https://github.com/gquere/pwn_jenkins) 有关攻击Jenkins服务器的笔记 +- [**643**星][2y] [C] [coolstar/electra](https://github.com/coolstar/electra) iOS 11.0 - 11.1.2 越狱工具包, 基于 async_awake +- [**642**星][22d] [C++] [thingpulse/esp8266-weather-station](https://github.com/ThingPulse/esp8266-weather-station) New version of the ESP8266 Weather Station - [**642**星][4y] [Py] [paulsec/twittor](https://github.com/paulsec/twittor) A fully featured backdoor that uses Twitter as a C&C server -- [**642**星][5m] [JS] [draios/sysdig-inspect](https://github.com/draios/sysdig-inspect) A powerful opensource interface for container troubleshooting and security investigation -- [**642**星][2y] [C] [coolstar/electra](https://github.com/coolstar/electra) iOS 11.0 - 11.1.2 越狱工具包, 基于 async_awake -- [**642**星][9m] [Objective-C] [chenxiancai/stcobfuscator](https://github.com/chenxiancai/stcobfuscator) iOS全局自动化 代码混淆 工具!支持cocoapod组件代码一并 混淆,完美避开hardcode方法、静态库方法和系统库方法! +- [**642**星][5m] [PHP] [mattiasgeniar/php-exploit-scripts](https://github.com/mattiasgeniar/php-exploit-scripts) A collection of PHP exploit scripts, found when investigating hacked servers. These are stored for educational purposes and to test fuzzers and vulnerability scanners. Feel free to contribute. +- [**642**星][10m] [Dockerfile] [aquasecurity/microscanner](https://github.com/aquasecurity/microscanner) Scan your container images for package vulnerabilities with Aqua Security - [**641**星][5m] [Py] [pyupio/safety](https://github.com/pyupio/safety) 检查所有已安装 Python 包, 查找已知的安全漏洞 -- [**641**星][1y] [Java] [faizann24/wifi-bruteforcer-fsecurify](https://github.com/faizann24/wifi-bruteforcer-fsecurify) Android app,无需 Root 即可爆破 Wifi 密码 -- [**640**星][20d] [C++] [thingpulse/esp8266-weather-station](https://github.com/ThingPulse/esp8266-weather-station) New version of the ESP8266 Weather Station +- [**641**星][2y] [harmj0y/cheatsheets](https://github.com/harmj0y/cheatsheets) Cheat sheets for various projects. +- [**641**星][1y] [Go] [ga0/netgraph](https://github.com/ga0/netgraph) A cross platform http sniffer with a web UI +- [**640**星][2y] [Shell] [kitten/setup-simple-ipsec-l2tp-vpn](https://github.com/kitten/setup-simple-ipsec-l2tp-vpn) Setup a simple IPSec/L2TP VPN Server for Ubuntu and Debian - [**640**星][3m] [C++] [stevemk14ebr/polyhook](https://github.com/stevemk14ebr/polyhook) x86/x64 C++ Hooking Library -- [**640**星][6m] [Py] [rabbitmask/weblogicscan](https://github.com/rabbitmask/weblogicscan) Weblogic一键漏洞检测工具,V1.3 -- [**640**星][5m] [PHP] [mattiasgeniar/php-exploit-scripts](https://github.com/mattiasgeniar/php-exploit-scripts) A collection of PHP exploit scripts, found when investigating hacked servers. These are stored for educational purposes and to test fuzzers and vulnerability scanners. Feel free to contribute. -- [**640**星][2y] [harmj0y/cheatsheets](https://github.com/harmj0y/cheatsheets) Cheat sheets for various projects. -- [**640**星][3m] [Py] [gquere/pwn_jenkins](https://github.com/gquere/pwn_jenkins) Notes about attacking Jenkins servers -- [**640**星][1y] [Go] [ga0/netgraph](https://github.com/ga0/netgraph) A cross platform http sniffer with a web UI +- [**640**星][3d] [Java] [ganyao114/sandhook](https://github.com/ganyao114/sandhook) Android ART Hook/Native Inline Hook/Single Instruction Hook - support 4.4 - 10.0 32/64 bit - Xposed API Compat +- [**639**星][3d] [Go] [ullaakut/gorsair](https://github.com/ullaakut/gorsair) Gorsair hacks its way into remote docker containers that expose their APIs +- [**639**星][7d] [Py] [thewhiteh4t/seeker](https://github.com/thewhiteh4t/seeker) Accurately Locate Smartphones using Social Engineering - [**639**星][1y] [Py] [lmco/laikaboss](https://github.com/lmco/laikaboss) Laika BOSS: Object Scanning System -- [**639**星][2m] [Py] [hisxo/gitgraber](https://github.com/hisxo/gitgraber) monitor GitHub to search and find sensitive data in real time for different online services such as: Google, Amazon, Paypal, Github, Mailgun, Facebook, Twitter, Heroku, Stripe... -- [**639**星][5m] [C++] [eliboa/tegrarcmgui](https://github.com/eliboa/tegrarcmgui) C++ GUI for TegraRcmSmash (Fusée Gelée exploit for Nintendo Switch) -- [**638**星][8d] [Go] [ullaakut/gorsair](https://github.com/ullaakut/gorsair) Gorsair hacks its way into remote docker containers that expose their APIs -- [**638**星][8m] [cryptogenic/exploit-writeups](https://github.com/cryptogenic/exploit-writeups) A collection where my current and future writeups for exploits/CTF will go +- [**639**星][8m] [Py] [klen/pylama](https://github.com/klen/pylama) Code audit tool for python. +- [**639**星][23d] [C] [kernelslacker/trinity](https://github.com/kernelslacker/trinity) Linux system call fuzzer +- [**639**星][8m] [cryptogenic/exploit-writeups](https://github.com/cryptogenic/exploit-writeups) A collection where my current and future writeups for exploits/CTF will go - [**638**星][11m] [HTML] [bl4de/security_whitepapers](https://github.com/bl4de/security_whitepapers) Collection of misc IT Security related whitepapers, presentations, slides - hacking, bug bounty, web application security, XSS, CSRF, SQLi -- [**637**星][4m] [smgorelik/windows-rce-exploits](https://github.com/smgorelik/windows-rce-exploits) The exploit samples database is a repository for **RCE** (remote code execution) exploits and Proof-of-Concepts for **WINDOWS**, the samples are uploaded for education purposes for red and blue teams. -- [**637**星][21d] [C] [kernelslacker/trinity](https://github.com/kernelslacker/trinity) Linux system call fuzzer -- [**636**星][1m] [Shell] [toutyrater/v2ray-guide](https://github.com/toutyrater/v2ray-guide) -- [**636**星][8m] [Py] [klen/pylama](https://github.com/klen/pylama) Code audit tool for python. -- [**636**星][1y] [JS] [alcuadrado/hieroglyphy](https://github.com/alcuadrado/hieroglyphy) Transform any javascript code to an equivalent sequence of ()[]{}!+ characters that runs in the browser! -- [**635**星][2y] [C] [qihoo360/mysql-sniffer](https://github.com/qihoo360/mysql-sniffer) mysql-sniffer is a network traffic analyzer tool for mysql, it is developed by Qihoo DBA and infrastructure team -- [**635**星][4m] [Jupyter Notebook] [parrt/lolviz](https://github.com/parrt/lolviz) A simple Python data-structure visualization tool for lists of lists, lists, dictionaries; primarily for use in Jupyter notebooks / presentations +- [**637**星][1y] [Py] [floodsung/learningtocompare_fsl](https://github.com/floodsung/LearningToCompare_FSL) PyTorch code for CVPR 2018 paper: Learning to Compare: Relation Network for Few-Shot Learning (Few-Shot Learning part) +- [**637**星][5m] [smgorelik/windows-rce-exploits](https://github.com/smgorelik/windows-rce-exploits) The exploit samples database is a repository for **RCE** (remote code execution) exploits and Proof-of-Concepts for **WINDOWS**, the samples are uploaded for education purposes for red and blue teams. +- [**637**星][4m] [Jupyter Notebook] [parrt/lolviz](https://github.com/parrt/lolviz) A simple Python data-structure visualization tool for lists of lists, lists, dictionaries; primarily for use in Jupyter notebooks / presentations +- [**637**星][26d] [Ruby] [markets/invisible_captcha](https://github.com/markets/invisible_captcha) Simple and flexible spam protection solution for Rails applications. + +- [**637**星][2y] [PHP] [duoergun0729/1book](https://github.com/duoergun0729/1book) 《Web安全之机器学习入门》 +- [**636**星][2y] [C] [qihoo360/mysql-sniffer](https://github.com/qihoo360/mysql-sniffer) mysql-sniffer is a network traffic analyzer tool for mysql, it is developed by Qihoo DBA and infrastructure team +- [**636**星][3y] [PS] [hlldz/invoke-phant0m](https://github.com/hlldz/invoke-phant0m) Windows Event Log Killer +- [**636**星][1y] [JS] [alcuadrado/hieroglyphy](https://github.com/alcuadrado/hieroglyphy) 将所有JavaScript代码转换为等价的()[] {}!+字符序列!,可在浏览器中运行 +- [**635**星][2m] [C++] [apple/swift-lldb](https://github.com/apple/swift-lldb) This is the version of LLDB that supports the Swift programming language & REPL. +- [**635**星][15d] [webdigi/aws-vpn-server-setup](https://github.com/webdigi/aws-vpn-server-setup) Setup your own private, secure, free* VPN on the Amazon AWS Cloud in 10 minutes. CloudFormation +- [**635**星][1y] [Swift] [phynet/ios-url-schemes](https://github.com/phynet/ios-url-schemes) a github solution from my gist of iOS list for urls schemes +- [**635**星][6d] [C++] [nodejs/node-addon-api](https://github.com/nodejs/node-addon-api) Module for using N-API from C++ - [**635**星][2y] [Py] [mschwager/dhcpwn](https://github.com/mschwager/dhcpwn) testing DHCP IP exhaustion attacks, sniff local DHCP traffic -- [**634**星][2m] [C++] [apple/swift-lldb](https://github.com/apple/swift-lldb) This is the version of LLDB that supports the Swift programming language & REPL. -- [**634**星][1y] [Swift] [phynet/ios-url-schemes](https://github.com/phynet/ios-url-schemes) a github solution from my gist of iOS list for urls schemes +- [**635**星][11d] [Py] [igio90/dwarf](https://github.com/igio90/dwarf) Full featured multi arch/os debugger built on top of PyQt5 and frida +- [**635**星][10m] [Py] [dirkjanm/privexchange](https://github.com/dirkjanm/privexchange) 通过滥用Exchange交换您对Domain Admin privs的特权 +- [**634**星][4y] [PHP] [emposha/php-shell-detector](https://github.com/emposha/php-shell-detector) Web Shell Detector – is a php script that helps you find and identify php/cgi(perl)/asp/aspx shells. Web Shell Detector has a “web shells” signature database that helps to identify “web shell” up to 99%. - [**633**星][6m] [C] [travisgoodspeed/md380tools](https://github.com/travisgoodspeed/md380tools) Python tools and patched firmware for the TYT-MD380 -- [**633**星][3y] [PowerShell] [hlldz/invoke-phant0m](https://github.com/hlldz/invoke-phant0m) Windows Event Log Killer -- [**633**星][21d] [Java] [ganyao114/sandhook](https://github.com/ganyao114/sandhook) Android ART Hook/Native Inline Hook/Single Instruction Hook - support 4.4 - 10.0 32/64 bit - Xposed API Compat -- [**633**星][4y] [PHP] [emposha/php-shell-detector](https://github.com/emposha/php-shell-detector) Web Shell Detector – is a php script that helps you find and identify php/cgi(perl)/asp/aspx shells. Web Shell Detector has a “web shells” signature database that helps to identify “web shell” up to 99%. -- [**632**星][1y] [Py] [floodsung/learningtocompare_fsl](https://github.com/floodsung/LearningToCompare_FSL) PyTorch code for CVPR 2018 paper: Learning to Compare: Relation Network for Few-Shot Learning (Few-Shot Learning part) -- [**632**星][9d] [Py] [igio90/dwarf](https://github.com/igio90/dwarf) Full featured multi arch/os debugger built on top of PyQt5 and frida -- [**632**星][10m] [Py] [dirkjanm/privexchange](https://github.com/dirkjanm/privexchange) Exchange your privileges for Domain Admin privs by abusing Exchange -- [**632**星][6m] [Py] [binarydefense/artillery](https://github.com/binarydefense/artillery) The Artillery Project is an open-source blue team tool designed to protect Linux and Windows operating systems through multiple methods. +- [**633**星][6m] [Py] [binarydefense/artillery](https://github.com/binarydefense/artillery) The Artillery Project is an open-source blue team tool designed to protect Linux and Windows operating systems through multiple methods. +- [**632**星][9m] [webbreacher/offensiveinterview](https://github.com/webbreacher/offensiveinterview) Interview questions to screen offensive (red team/pentest) candidates - [**631**星][4y] [CoffeeScript] [shadowsocks/shadowsocks-chromeapp](https://github.com/shadowsocks/shadowsocks-chromeapp) Chrome client for shadowsocks - [**631**星][10m] [Py] [mehulj94/braindamage](https://github.com/mehulj94/braindamage) Remote administration tool which uses Telegram as a C&C server -- [**629**星][9m] [webbreacher/offensiveinterview](https://github.com/webbreacher/offensiveinterview) Interview questions to screen offensive (red team/pentest) candidates -- [**629**星][10m] [Dockerfile] [aquasecurity/microscanner](https://github.com/aquasecurity/microscanner) Scan your container images for package vulnerabilities with Aqua Security +- [**630**星][5m] [Go] [zmap/zgrab](https://github.com/zmap/zgrab) A Banner Grabber, in Go +- [**629**星][8m] [Shell] [g0tmi1k/msfpc](https://github.com/g0tmi1k/msfpc) MSFvenom Payload Creator (MSFPC) +- [**629**星][2y] [C] [client9/libinjection](https://github.com/client9/libinjection) SQL / SQLI tokenizer parser analyzer +- [**629**星][5m] [ankane/secure_rails](https://github.com/ankane/secure_rails) Rails安全最佳实战 - [**629**星][4m] [3gstudent/pentest-and-development-tips](https://github.com/3gstudent/pentest-and-development-tips) A collection of pentest and development tips -- [**628**星][8m] [Shell] [g0tmi1k/msfpc](https://github.com/g0tmi1k/msfpc) MSFvenom Payload Creator (MSFPC) -- [**628**星][5m] [Go] [zmap/zgrab](https://github.com/zmap/zgrab) A Banner Grabber, in Go -- [**626**星][13d] [PowerShell] [olafhartong/sysmon-modular](https://github.com/olafhartong/sysmon-modular) sysmon配置模块收集 -- [**626**星][2y] [C] [client9/libinjection](https://github.com/client9/libinjection) SQL / SQLI tokenizer parser analyzer -- [**626**星][5m] [ankane/secure_rails](https://github.com/ankane/secure_rails) Rails security best practices -- [**625**星][2y] [C++] [codilime/veles](https://github.com/codilime/veles) Binary data analysis and visualization tool -- [**624**星][2y] [C] [shadowsocksr-backup/shadowsocksr-libev](https://github.com/shadowsocksr-backup/shadowsocksr-libev) libev port of ShadowsocksR -- [**624**星][7m] [yeyintminthuhtut/awesome-advanced-windows-exploitation-references](https://github.com/yeyintminthuhtut/Awesome-Advanced-Windows-Exploitation-References) List of Awesome Advanced Windows Exploitation References -- [**623**星][23d] [Ruby] [markets/invisible_captcha](https://github.com/markets/invisible_captcha) Simple and flexible spam protection solution for Rails applications. - -- [**623**星][4y] [jeanphorn/wordlist](https://github.com/jeanphorn/wordlist) Collection of some common wordlists such as RDP password, user name list, ssh password wordlist for brute force. IP Cameras Default Passwords. -- [**623**星][3y] [C] [chokepoint/azazel](https://github.com/chokepoint/azazel) Azazel is a userland rootkit based off of the original LD_PRELOAD technique from Jynx rootkit. It is more robust and has additional features, and focuses heavily around anti-debugging and anti-detection. -- [**622**星][2y] [C] [tgraf/bmon](https://github.com/tgraf/bmon) bandwidth monitor and rate estimator -- [**622**星][1y] [C] [nfc-tools/mfoc](https://github.com/nfc-tools/mfoc) Mifare Classic Offline Cracker -- [**622**星][2y] [Py] [0xbug/sqliscanner](https://github.com/0xbug/sqliscanner) Automatic SQL injection with Charles and sqlmap api +- [**628**星][2d] [PS] [olafhartong/sysmon-modular](https://github.com/olafhartong/sysmon-modular) sysmon配置模块收集 +- [**628**星][2y] [C++] [codilime/veles](https://github.com/codilime/veles) Binary data analysis and visualization tool +- [**627**星][7m] [yeyintminthuhtut/awesome-advanced-windows-exploitation-references](https://github.com/yeyintminthuhtut/Awesome-Advanced-Windows-Exploitation-References) List of Awesome Advanced Windows Exploitation References +- [**626**星][1y] [C] [nfc-tools/mfoc](https://github.com/nfc-tools/mfoc) Mifare Classic Offline Cracker +- [**626**星][4y] [jeanphorn/wordlist](https://github.com/jeanphorn/wordlist) Collection of some common wordlists such as RDP password, user name list, ssh password wordlist for brute force. IP Cameras Default Passwords. +- [**625**星][2y] [C] [shadowsocksr-backup/shadowsocksr-libev](https://github.com/shadowsocksr-backup/shadowsocksr-libev) libev port of ShadowsocksR +- [**625**星][11m] [C++] [ohpe/juicy-potato](https://github.com/ohpe/juicy-potato) A sugared version of RottenPotatoNG, with a bit of juice, i.e. another Local Privilege Escalation tool, from a Windows Service Accounts to NT AUTHORITY\SYSTEM. +- [**625**星][3y] [C] [chokepoint/azazel](https://github.com/chokepoint/azazel) Azazel is a userland rootkit based off of the original LD_PRELOAD technique from Jynx rootkit. It is more robust and has additional features, and focuses heavily around anti-debugging and anti-detection. +- [**625**星][2m] [Py] [alichtman/stronghold](https://github.com/alichtman/stronghold) Easily configure macOS security settings from the terminal. +- [**624**星][4y] [JS] [n0wa11/gfw_whitelist](https://github.com/n0wa11/gfw_whitelist) A Pac File of the Whitelisted Websites for the Great Firewall of China (GFW) +- [**624**星][2d] [arkadiyt/bounty-targets-data](https://github.com/arkadiyt/bounty-targets-data) This repo contains hourly-updated data dumps of bug bounty platform scopes (like Hackerone/Bugcrowd/etc) that are eligible for reports +- [**623**星][2y] [C] [tgraf/bmon](https://github.com/tgraf/bmon) 带宽监控器和速率估计器 +- [**623**星][3m] [C] [gdabah/distorm](https://github.com/gdabah/distorm) Powerful Disassembler Library For x86/AMD64 +- [**622**星][9d] [Py] [virt-manager/virt-manager](https://github.com/virt-manager/virt-manager) Desktop tool for managing virtual machines via libvirt +- [**622**星][6m] [Java] [sigploiter/sigploit](https://github.com/sigploiter/sigploit) Telecom Signaling Exploitation Framework - SS7, GTP, Diameter & SIP +- [**622**星][3m] [PHP] [hongrisec/php-audit-labs](https://github.com/hongrisec/php-audit-labs) 一个关于PHP的代码审计项目 +- [**621**星][2y] [turbo/openftp4](https://github.com/turbo/openftp4) A list of all FTP servers in IPv4 that allow anonymous logins. - [**621**星][3m] [Py] [3xp10it/xwaf](https://github.com/3xp10it/xwaf) waf 自动爆破(绕过)工具 -- [**621**星][6m] [Java] [sigploiter/sigploit](https://github.com/sigploiter/sigploit) Telecom Signaling Exploitation Framework - SS7, GTP, Diameter & SIP -- [**621**星][3m] [C] [gdabah/distorm](https://github.com/gdabah/distorm) Powerful Disassembler Library For x86/AMD64 -- [**620**星][14d] [Py] [virt-manager/virt-manager](https://github.com/virt-manager/virt-manager) Desktop tool for managing virtual machines via libvirt +- [**621**星][5m] [Py] [deibit/cansina](https://github.com/deibit/cansina) web 内容发现工具。发出各种请求并过滤回复,识别是否存在请求的资源。 +- [**621**星][2y] [Py] [0xbug/sqliscanner](https://github.com/0xbug/sqliscanner) Automatic SQL injection with Charles and sqlmap api +- [**620**星][9m] [Py] [epsylon/ufonet](https://github.com/epsylon/ufonet) 用于发起DDoS和DoS攻击的工具包。 - [**620**星][5m] [JS] [derhuerst/tcp-over-websockets](https://github.com/derhuerst/tcp-over-websockets) Tunnel TCP through WebSockets. -- [**619**星][19d] [C++] [nodejs/node-addon-api](https://github.com/nodejs/node-addon-api) Module for using N-API from C++ -- [**619**星][4y] [JS] [n0wa11/gfw_whitelist](https://github.com/n0wa11/gfw_whitelist) A Pac File of the Whitelisted Websites for the Great Firewall of China (GFW) +- [**619**星][5y] [PHP] [pr0x13/idict](https://github.com/pr0x13/idict) iCloud Apple iD BruteForcer +- [**619**星][10m] [PS] [mattifestation/powershellarsenal](https://github.com/mattifestation/powershellarsenal) A PowerShell Module Dedicated to Reverse Engineering - [**619**星][4y] [Go] [leo-stone/hack-petya](https://github.com/leo-stone/hack-petya) 搜索key,恢复 petya 加密的 mft -- [**619**星][2m] [Py] [alichtman/stronghold](https://github.com/alichtman/stronghold) Easily configure macOS security settings from the terminal. -- [**618**星][10m] [PowerShell] [mattifestation/powershellarsenal](https://github.com/mattifestation/powershellarsenal) A PowerShell Module Dedicated to Reverse Engineering -- [**618**星][2y] [PHP] [duoergun0729/1book](https://github.com/duoergun0729/1book) 《Web安全之机器学习入门》 -- [**618**星][5m] [Py] [deibit/cansina](https://github.com/deibit/cansina) web 内容发现工具。发出各种请求并过滤回复,识别是否存在请求的资源。 -- [**617**星][5y] [PHP] [pr0x13/idict](https://github.com/pr0x13/idict) iCloud Apple iD BruteForcer -- [**617**星][11m] [C++] [ohpe/juicy-potato](https://github.com/ohpe/juicy-potato) A sugared version of RottenPotatoNG, with a bit of juice, i.e. another Local Privilege Escalation tool, from a Windows Service Accounts to NT AUTHORITY\SYSTEM. +- [**618**星][4m] [bypass007/safety-project-collection](https://github.com/bypass007/safety-project-collection) 收集一些比较优秀的开源安全项目,以帮助甲方安全从业人员构建企业安全能力。 +- [**617**星][1y] [Lua] [unixhot/waf](https://github.com/unixhot/waf) 使用Nginx+Lua实现的WAF(版本v1.0) +- [**617**星][12d] [C] [thewover/donut](https://github.com/thewover/donut) Generates x86, x64, or AMD64+x86 position-independent shellcode that loads .NET Assemblies, PE files, and other Windows payloads from memory and runs them with parameters - [**617**星][1y] [Go] [lunixbochs/usercorn](https://github.com/lunixbochs/usercorn) 通过模拟器对二进制文件进行动态分析 -- [**617**星][3m] [PHP] [hongrisec/php-audit-labs](https://github.com/hongrisec/php-audit-labs) 一个关于PHP的代码审计项目 -- [**617**星][9m] [Py] [epsylon/ufonet](https://github.com/epsylon/ufonet) UFONet - Denial of Service Toolkit -- [**615**星][3m] [C] [matheus-garbelini/esp32_esp8266_attacks](https://github.com/matheus-garbelini/esp32_esp8266_attacks) Proof of Concept of ESP32/8266 Wi-Fi vulnerabilties (CVE-2019-12586, CVE-2019-12587, CVE-2019-12588) -- [**614**星][1y] [Lua] [unixhot/waf](https://github.com/unixhot/waf) 使用Nginx+Lua实现的WAF(版本v1.0) -- [**613**星][4m] [bypass007/safety-project-collection](https://github.com/bypass007/safety-project-collection) 收集一些比较优秀的开源安全项目,以帮助甲方安全从业人员构建企业安全能力。 -- [**613**星][9m] [Py] [al-azif/ps4-exploit-host](https://github.com/al-azif/ps4-exploit-host) Easy PS4 Exploit Hosting -- [**613**星][1y] [Py] [adamcaudill/equationgroupleak](https://github.com/adamcaudill/equationgroupleak) Archive of leaked Equation Group materials -- [**612**星][10d] [HTML] [v2ray/manual](https://github.com/v2ray/manual) Source code for +- [**616**星][3d] [HTML] [v2ray/manual](https://github.com/v2ray/manual) Source code for +- [**616**星][1y] [Shell] [wireghoul/htshells](https://github.com/wireghoul/htshells) 自包含的Web Shell和通过.htaccess文件进行的其他攻击。 +- [**616**星][3m] [C] [matheus-garbelini/esp32_esp8266_attacks](https://github.com/matheus-garbelini/esp32_esp8266_attacks) Proof of Concept of ESP32/8266 Wi-Fi vulnerabilties (CVE-2019-12586, CVE-2019-12587, CVE-2019-12588) +- [**616**星][21d] [Go] [evilsocket/arc](https://github.com/evilsocket/arc) 可用于管理私密数据的工具. 后端是 Go 语言编写的 RESTful 服务器, 前台是Html + JavaScript +- [**615**星][4m] [Lua] [jx-sec/jxwaf](https://github.com/jx-sec/jxwaf) JXWAF(锦衣盾)是一款基于openresty(nginx+lua)开发的web应用防火墙 +- [**615**星][1y] [jiangsir404/audit-learning](https://github.com/jiangsir404/audit-learning) 记录自己对《代码审计》的理解和总结,对危险函数的深入分析以及在p牛的博客和代码审计圈的收获 +- [**614**星][3y] [ObjC] [macmade/keychaincracker](https://github.com/macmade/keychaincracker) macOS keychain cracking tool +- [**614**星][6y] [Assembly] [adriancable/8086tiny](https://github.com/adriancable/8086tiny) Official repository for 8086tiny: a tiny PC emulator/virtual machine +- [**614**星][1y] [Py] [adamcaudill/equationgroupleak](https://github.com/adamcaudill/equationgroupleak) Archive of leaked Equation Group materials +- [**613**星][1m] [C++] [acidanthera/virtualsmc](https://github.com/acidanthera/virtualsmc) SMC emulator layer +- [**613**星][2m] [Py] [sourcelair/ceryx](https://github.com/sourcelair/ceryx) Dynamic reverse proxy based on NGINX OpenResty with an API +- [**613**星][1y] [langyanduan/reborn](https://github.com/langyanduan/reborn) The missing proxy for macOS +- [**613**星][2y] [Py] [fanhuaandluomu/geetest_break](https://github.com/fanhuaandluomu/geetest_break) 极验验证码破解-源码+手册 +- [**612**星][10m] [Py] [zdresearch/owasp-nettacker](https://github.com/zdresearch/OWASP-Nettacker) Automated Penetration Testing Framework - [**612**星][1y] [Ruby] [thesp0nge/dawnscanner](https://github.com/thesp0nge/dawnscanner) Dawn is a static analysis security scanner for ruby written web applications. It supports Sinatra, Padrino and Ruby on Rails frameworks. -- [**612**星][25d] [C] [quiet/quiet-lwip](https://github.com/quiet/quiet-lwip) create TCP and UDP connections over an audio channel -- [**611**星][1y] [Shell] [wireghoul/htshells](https://github.com/wireghoul/htshells) Self contained htaccess shells and attacks +- [**612**星][27d] [C] [quiet/quiet-lwip](https://github.com/quiet/quiet-lwip) create TCP and UDP connections over an audio channel +- [**612**星][3m] [Py] [netflix/repokid](https://github.com/netflix/repokid) AWS Least Privilege for Distributed, High-Velocity Deployment +- [**612**星][6m] [Py] [eliasgranderubio/dagda](https://github.com/eliasgranderubio/dagda) Docker安全套件 +- [**612**星][3m] [Go] [eldadru/ksniff](https://github.com/eldadru/ksniff) Kubectl plugin to ease sniffing on kubernetes pods using tcpdump and wireshark +- [**612**星][3m] [Shell] [ashishb/osx-and-ios-security-awesome](https://github.com/ashishb/osx-and-ios-security-awesome) OSX and iOS related security tools +- [**612**星][9m] [Py] [al-azif/ps4-exploit-host](https://github.com/al-azif/ps4-exploit-host) Easy PS4 Exploit Hosting - [**611**星][4y] [Batchfile] [windowslies/blockwindows](https://github.com/windowslies/blockwindows) Stop Windows 10 Nagging and Spying. Works with Win7-10 -- [**611**星][3m] [Py] [netflix/repokid](https://github.com/netflix/repokid) AWS Least Privilege for Distributed, High-Velocity Deployment -- [**611**星][3y] [Objective-C] [macmade/keychaincracker](https://github.com/macmade/keychaincracker) macOS keychain cracking tool -- [**611**星][19d] [Go] [evilsocket/arc](https://github.com/evilsocket/arc) 可用于管理私密数据的工具. 后端是 Go 语言编写的 RESTful 服务器, 前台是Html + JavaScript -- [**611**星][3m] [Shell] [ashishb/osx-and-ios-security-awesome](https://github.com/ashishb/osx-and-ios-security-awesome) OSX and iOS related security tools -- [**610**星][4m] [Lua] [jx-sec/jxwaf](https://github.com/jx-sec/jxwaf) JXWAF(锦衣盾)是一款基于openresty(nginx+lua)开发的web应用防火墙 -- [**610**星][1y] [jiangsir404/audit-learning](https://github.com/jiangsir404/audit-learning) 记录自己对《代码审计》的理解和总结,对危险函数的深入分析以及在p牛的博客和代码审计圈的收获 -- [**610**星][2y] [Py] [fanhuaandluomu/geetest_break](https://github.com/fanhuaandluomu/geetest_break) 极验验证码破解-源码+手册 -- [**609**星][4m] [Py] [faizann24/xsspy](https://github.com/faizann24/xsspy) Web Application XSS Scanner -- [**609**星][6m] [Py] [eliasgranderubio/dagda](https://github.com/eliasgranderubio/dagda) Docker安全套件 -- [**609**星][6y] [Assembly] [adriancable/8086tiny](https://github.com/adriancable/8086tiny) Official repository for 8086tiny: a tiny PC emulator/virtual machine +- [**611**星][4m] [Py] [faizann24/xsspy](https://github.com/faizann24/xsspy) Web Application XSS Scanner +- [**611**星][8m] [denji/golang-tls](https://github.com/denji/golang-tls) Simple Golang HTTPS/TLS Examples - [**608**星][7m] [JS] [vincentcox/stacoan](https://github.com/vincentcox/stacoan) StaCoAn is a crossplatform tool which aids developers, bugbounty hunters and ethical hackers performing static code analysis on mobile applications. -- [**608**星][12d] [Py] [thewhiteh4t/seeker](https://github.com/thewhiteh4t/seeker) Accurately Locate Smartphones using Social Engineering -- [**606**星][7m] [denji/golang-tls](https://github.com/denji/golang-tls) Simple Golang HTTPS/TLS Examples -- [**605**星][10d] [C] [thewover/donut](https://github.com/thewover/donut) Generates x86, x64, or AMD64+x86 position-independent shellcode that loads .NET Assemblies, PE files, and other Windows payloads from memory and runs them with parameters -- [**604**星][3m] [Py] [matlink/gplaycli](https://github.com/matlink/gplaycli) Google Play Downloader via Command line -- [**604**星][3m] [Py] [0xgalz/virtuailor](https://github.com/0xgalz/virtuailor) 利用IDA调试获取的信息,自动创建C++的虚表 +- [**607**星][24d] [PS] [farag2/windows-10-setup-script](https://github.com/farag2/windows-10-setup-script) Script to setup Windows 10 1903/1909 +- [**607**星][3m] [Py] [matlink/gplaycli](https://github.com/matlink/gplaycli) Google Play Downloader via Command line +- [**607**星][8m] [Shell] [cokebar/gfwlist2dnsmasq](https://github.com/cokebar/gfwlist2dnsmasq) A shell script which convert gfwlist into dnsmasq rules. Python version: +- [**607**星][1y] [C#] [bonesoul/coiniumserv](https://github.com/bonesoul/coiniumserv) Next-gen crypto currency mining pool software +- [**606**星][2y] [PS] [peewpw/invoke-wcmdump](https://github.com/peewpw/invoke-wcmdump) PowerShell Script to Dump Windows Credentials from the Credential Manager +- [**606**星][7m] [aleenzz/mysql_sql_bypass_wiki](https://github.com/aleenzz/mysql_sql_bypass_wiki) mysql注入,bypass的一些心得 +- [**606**星][9m] [C#] [0xbadjuju/tokenvator](https://github.com/0xbadjuju/tokenvator) A tool to elevate privilege with Windows Tokens +- [**605**星][15d] [404notf0und/ai-for-security-learning](https://github.com/404notf0und/ai-for-security-learning) 安全场景、基于AI的安全算法和安全数据分析学习资料整理 +- [**605**星][3m] [Py] [0xgalz/virtuailor](https://github.com/0xgalz/virtuailor) 利用IDA调试获取的信息,自动创建C++的虚表
查看详情 @@ -2024,1273 +2161,1311 @@
-- [**603**星][10m] [Py] [zdresearch/owasp-nettacker](https://github.com/zdresearch/OWASP-Nettacker) Automated Penetration Testing Framework -- [**603**星][2y] [PowerShell] [peewpw/invoke-wcmdump](https://github.com/peewpw/invoke-wcmdump) PowerShell Script to Dump Windows Credentials from the Credential Manager -- [**603**星][3m] [Go] [eldadru/ksniff](https://github.com/eldadru/ksniff) Kubectl plugin to ease sniffing on kubernetes pods using tcpdump and wireshark -- [**603**星][8m] [Shell] [cokebar/gfwlist2dnsmasq](https://github.com/cokebar/gfwlist2dnsmasq) A shell script which convert gfwlist into dnsmasq rules. Python version: -- [**602**星][1y] [C] [scottybauer/android_kernel_cve_pocs](https://github.com/scottybauer/android_kernel_cve_pocs) A list of my CVE's with POCs +- [**604**星][2m] [Swift] [gradients/gradients](https://github.com/Gradients/Gradients) A curated collection of 180 splendid gradients made in swift +- [**604**星][10d] [Shell] [securityftw/cs-suite](https://github.com/securityftw/cs-suite) Cloud Security Suite - One stop tool for auditing the security posture of AWS/GCP/Azure infrastructure. +- [**603**星][1y] [C] [scottybauer/android_kernel_cve_pocs](https://github.com/scottybauer/android_kernel_cve_pocs) A list of my CVE's with POCs +- [**602**星][28d] [Max] [maktm/flirtdb](https://github.com/Maktm/FLIRTDB) A community driven collection of IDA FLIRT signature files +- [**602**星][19d] [Py] [webrecorder/pywb](https://github.com/webrecorder/pywb) 重放和记录Web存档 +- [**602**星][6m] [C] [pelya/android-keyboard-gadget](https://github.com/pelya/android-keyboard-gadget) Convert your Android device into USB keyboard/mouse, control your PC from your Android device remotely, including BIOS/bootloader. +- [**602**星][7y] [Py] [m0mchil/poclbm](https://github.com/m0mchil/poclbm) poclbm:比特币挖掘 - [**602**星][2y] [Py] [bhdresh/cve-2017-0199](https://github.com/bhdresh/cve-2017-0199) Exploit toolkit CVE-2017-0199 - v4.0 is a handy python script which provides pentesters and security researchers a quick and effective way to test Microsoft Office RCE. It could generate a malicious RTF/PPSX file and deliver metasploit / meterpreter / other payload to victim without any complex configuration. -- [**602**星][7d] [arkadiyt/bounty-targets-data](https://github.com/arkadiyt/bounty-targets-data) This repo contains hourly-updated data dumps of bug bounty platform scopes (like Hackerone/Bugcrowd/etc) that are eligible for reports -- [**601**星][2m] [Swift] [gradients/gradients](https://github.com/Gradients/Gradients) A curated collection of 180 splendid gradients made in swift - [**601**星][3y] [Py] [omriher/captipper](https://github.com/omriher/captipper) Malicious HTTP traffic explorer -- [**601**星][7m] [aleenzz/mysql_sql_bypass_wiki](https://github.com/aleenzz/mysql_sql_bypass_wiki) mysql注入,bypass的一些心得 -- [**600**星][17d] [Py] [webrecorder/pywb](https://github.com/webrecorder/pywb) Core Python Web Archiving Toolkit for replay and recording of web archives -- [**600**星][8d] [Shell] [securityftw/cs-suite](https://github.com/securityftw/cs-suite) Cloud Security Suite - One stop tool for auditing the security posture of AWS/GCP/Azure infrastructure. -- [**600**星][4y] [Py] [hatriot/clusterd](https://github.com/hatriot/clusterd) application server attack toolkit -- [**599**星][26d] [Max] [maktm/flirtdb](https://github.com/Maktm/FLIRTDB) A community driven collection of IDA FLIRT signature files -- [**599**星][6m] [C] [pelya/android-keyboard-gadget](https://github.com/pelya/android-keyboard-gadget) Convert your Android device into USB keyboard/mouse, control your PC from your Android device remotely, including BIOS/bootloader. -- [**599**星][13d] [404notf0und/ai-for-security-learning](https://github.com/404notf0und/ai-for-security-learning) 安全场景、基于AI的安全算法和安全数据分析学习资料整理 -- [**598**星][1y] [PowerShell] [fortynorthsecurity/wmimplant](https://github.com/FortyNorthSecurity/WMImplant) This is a PowerShell based tool that is designed to act like a RAT. Its interface is that of a shell where any command that is supported is translated into a WMI-equivalent for use on a network/remote machine. WMImplant is WMI based. +- [**601**星][2d] [C#] [microsoft/clrmd](https://github.com/microsoft/clrmd) Microsoft.Diagnostics.Runtime is a set of APIs for introspecting processes and dumps. +- [**601**星][2y] [HTML] [jiji262/wooyun_articles](https://github.com/jiji262/wooyun_articles) drops.wooyun.org 乌云Drops文章备份 +- [**601**星][4y] [Py] [hatriot/clusterd](https://github.com/hatriot/clusterd) 应用程序服务器攻击工具包 +- [**601**星][9m] [Java] [c0ny1/chunked-coding-converter](https://github.com/c0ny1/chunked-coding-converter) Burp suite 分块传输辅助插件 +- [**600**星][30d] [C++] [mdhiggins/esp8266-http-ir-blaster](https://github.com/mdhiggins/esp8266-http-ir-blaster) ESP8266 Compatible IR Blaster that accepts HTTP commands for use with services like Amazon Echo +- [**599**星][3d] [Py] [witten/borgmatic](https://github.com/witten/borgmatic) Simple, configuration-driven backup software for servers and workstations +- [**599**星][2y] [Py] [secretsquirrel/sigthief](https://github.com/secretsquirrel/sigthief) 一次窃取签名并制作一个无效签名 +- [**599**星][5d] [ntkernel/lantern](https://github.com/ntkernel/lantern) V2Ray配置文件,蓝灯(Lantern)破解,手机版+win版 +- [**598**星][1y] [PS] [fortynorthsecurity/wmimplant](https://github.com/FortyNorthSecurity/WMImplant) This is a PowerShell based tool that is designed to act like a RAT. Its interface is that of a shell where any command that is supported is translated into a WMI-equivalent for use on a network/remote machine. WMImplant is WMI based. - [**598**星][1y] [Shell] [pires/kubernetes-vagrant-coreos-cluster](https://github.com/pires/kubernetes-vagrant-coreos-cluster) Kubernetes cluster (for testing purposes) made easy with Vagrant and CoreOS. -- [**598**星][7d] [C#] [microsoft/clrmd](https://github.com/microsoft/clrmd) Microsoft.Diagnostics.Runtime is a set of APIs for introspecting processes and dumps. -- [**597**星][2y] [Py] [secretsquirrel/sigthief](https://github.com/secretsquirrel/sigthief) Stealing Signatures and Making One Invalid Signature at a Time -- [**597**星][28d] [C++] [mdhiggins/esp8266-http-ir-blaster](https://github.com/mdhiggins/esp8266-http-ir-blaster) ESP8266 Compatible IR Blaster that accepts HTTP commands for use with services like Amazon Echo -- [**597**星][2y] [HTML] [jiji262/wooyun_articles](https://github.com/jiji262/wooyun_articles) drops.wooyun.org 乌云Drops文章备份 -- [**596**星][9m] [C#] [0xbadjuju/tokenvator](https://github.com/0xbadjuju/tokenvator) A tool to elevate privilege with Windows Tokens -- [**595**星][9d] [Py] [witten/borgmatic](https://github.com/witten/borgmatic) Simple, configuration-driven backup software for servers and workstations -- [**595**星][2m] [PowerShell] [ramblingcookiemonster/powershell](https://github.com/ramblingcookiemonster/powershell) Various PowerShell functions and scripts -- [**595**星][6m] [C] [hashcat/hashcat-utils](https://github.com/hashcat/hashcat-utils) Small utilities that are useful in advanced password cracking -- [**594**星][4y] [Makefile] [zhengmin1989/thesevenweapons](https://github.com/zhengmin1989/thesevenweapons) 安卓动态调试七种武器 +- [**597**星][18d] [Py] [nongiach/arm_now](https://github.com/nongiach/arm_now) 快速创建并运行不同CPU架构的虚拟机, 用于逆向分析或执行二进制文件. 基于QEMU +- [**597**星][1m] [Py] [hslatman/awesome-industrial-control-system-security](https://github.com/hslatman/awesome-industrial-control-system-security) 工控系统安全资源列表 +- [**597**星][6m] [C] [hashcat/hashcat-utils](https://github.com/hashcat/hashcat-utils) Small utilities that are useful in advanced password cracking +- [**597**星][3d] [YARA] [didierstevens/didierstevenssuite](https://github.com/didierstevens/didierstevenssuite) 工具、脚本列表 +- [**597**星][12d] [Go] [antoniomika/sish](https://github.com/antoniomika/sish) An open source serveo/ngrok alternative. HTTP(S)/WS(S)/TCP Tunnels to localhost using only SSH. +- [**596**星][1m] [siguza/ios-resources](https://github.com/siguza/ios-resources) Useful resources for iOS hacking +- [**596**星][2m] [PS] [ramblingcookiemonster/powershell](https://github.com/ramblingcookiemonster/powershell) 各种PowerShell函数和脚本 +- [**596**星][5d] [azure/aks](https://github.com/azure/aks) Azure Kubernetes Service +- [**595**星][4y] [Makefile] [zhengmin1989/thesevenweapons](https://github.com/zhengmin1989/thesevenweapons) 安卓动态调试七种武器 +- [**595**星][16d] [C] [openvpn/openvpn-gui](https://github.com/openvpn/openvpn-gui) OpenVPN GUI is a graphical frontend for OpenVPN running on Windows XP / Vista / 7 / 8. It creates an icon in the notification area from which you can control OpenVPN to start/stop your VPN tunnels, view the log and do other useful things. +- [**595**星][5m] [fabrimagic72/malware-samples](https://github.com/fabrimagic72/malware-samples) 恶意软件样本 +- [**595**星][7d] [Go] [cloudflare/cloudflared](https://github.com/cloudflare/cloudflared) Argo Tunnel client +- [**595**星][1y] [Py] [brannondorsey/passgan](https://github.com/brannondorsey/passgan) A Deep Learning Approach for Password Guessing ( +- [**594**星][23d] [Py] [glasgowembedded/glasgow](https://github.com/GlasgowEmbedded/glasgow) Scots Army Knife for electronics +- [**594**星][3m] [Py] [thewhiteh4t/pwnedornot](https://github.com/thewhiteh4t/pwnedornot) OSINT Tool for Finding Passwords of Compromised Email Addresses +- [**594**星][6m] [Py] [dmpayton/django-admin-honeypot](https://github.com/dmpayton/django-admin-honeypot) - [**594**星][3y] [C++] [breakingmalwareresearch/atom-bombing](https://github.com/breakingmalwareresearch/atom-bombing) Brand New Code Injection for Windows -- [**593**星][16d] [Py] [nongiach/arm_now](https://github.com/nongiach/arm_now) 快速创建并运行不同CPU架构的虚拟机, 用于逆向分析或执行二进制文件. 基于QEMU -- [**593**星][1m] [YARA] [didierstevens/didierstevenssuite](https://github.com/didierstevens/didierstevenssuite) Please no pull requests for this repository. Thanks! -- [**593**星][1y] [Py] [brannondorsey/passgan](https://github.com/brannondorsey/passgan) A Deep Learning Approach for Password Guessing ( -- [**592**星][21d] [Py] [glasgowembedded/glasgow](https://github.com/GlasgowEmbedded/glasgow) Scots Army Knife for electronics -- [**592**星][1m] [siguza/ios-resources](https://github.com/siguza/ios-resources) Useful resources for iOS hacking -- [**592**星][14d] [C] [openvpn/openvpn-gui](https://github.com/openvpn/openvpn-gui) OpenVPN GUI is a graphical frontend for OpenVPN running on Windows XP / Vista / 7 / 8. It creates an icon in the notification area from which you can control OpenVPN to start/stop your VPN tunnels, view the log and do other useful things. -- [**592**星][6m] [Py] [dmpayton/django-admin-honeypot](https://github.com/dmpayton/django-admin-honeypot) -- [**592**星][9m] [Java] [c0ny1/chunked-coding-converter](https://github.com/c0ny1/chunked-coding-converter) Burp suite 分块传输辅助插件 -- [**591**星][3m] [Py] [thewhiteh4t/pwnedornot](https://github.com/thewhiteh4t/pwnedornot) OSINT Tool for Finding Passwords of Compromised Email Addresses -- [**591**星][2m] [Py] [pwning/public-writeup](https://github.com/pwning/public-writeup) CTF write-ups by Plaid Parliament of Pwning -- [**591**星][5m] [fabrimagic72/malware-samples](https://github.com/fabrimagic72/malware-samples) 恶意软件样本 -- [**591**星][18d] [azure/aks](https://github.com/azure/aks) Azure Kubernetes Service +- [**593**星][18d] [PHP] [zhuifengshaonianhanlu/pikachu](https://github.com/zhuifengshaonianhanlu/pikachu) 一个好玩的Web安全-漏洞测试平台 +- [**593**星][8d] [Py] [trustedsec/trevorc2](https://github.com/trustedsec/trevorc2) 通过正常的可浏览的网站隐藏 C&C 指令的客户端/服务器模型,因为时间间隔不同,检测变得更加困难,并且获取主机数据时不会使用 POST 请求 +- [**593**星][6d] [C] [mrexodia/titanhide](https://github.com/mrexodia/titanhide) 用于隐藏某些进程调试器的驱动程序 +- [**592**星][2m] [Py] [pwning/public-writeup](https://github.com/pwning/public-writeup) CTF write-ups by Plaid Parliament of Pwning +- [**592**星][1m] [HTML] [owasp/railsgoat](https://github.com/owasp/railsgoat) A vulnerable version of Rails that follows the OWASP Top 10 +- [**592**星][2y] [Go] [nim4/dbshield](https://github.com/nim4/dbshield) Database firewall written in Go +- [**591**星][2y] [Py] [sc0tfree/mentalist](https://github.com/sc0tfree/mentalist) 自定义wordlist 生成器,带界面,可生成与 Hashcat、Johnthe Ripper 兼容的 wordlist +- [**591**星][3m] [Go] [moul/sshportal](https://github.com/moul/sshportal) Transparent SSH bastion - [**590**星][2y] [Go] [timest/goscan](https://github.com/timest/goscan) goscan is a simple and efficient IPv4 network scanner that discovers all active devices on local subnet. - [**590**星][11m] [pandazheng/ioshackstudy](https://github.com/pandazheng/ioshackstudy) IOS安全学习资料汇总 -- [**590**星][1m] [HTML] [owasp/railsgoat](https://github.com/owasp/railsgoat) A vulnerable version of Rails that follows the OWASP Top 10 -- [**590**星][1m] [ntkernel/lantern](https://github.com/ntkernel/lantern) V2Ray配置文件,蓝灯(Lantern)破解,手机版+win版 -- [**590**星][2y] [Go] [nim4/dbshield](https://github.com/nim4/dbshield) Database firewall written in Go -- [**590**星][30d] [Py] [hslatman/awesome-industrial-control-system-security](https://github.com/hslatman/awesome-industrial-control-system-security) 工控系统安全资源列表 +- [**590**星][2y] [Py] [eldraco/salamandra](https://github.com/eldraco/salamandra) Salamandra is a tool to find spy microphones that use radio freq to transmit. It uses SDR. - [**590**星][7y] [Py] [dabeaz/bitey](https://github.com/dabeaz/bitey) Import LLVM bitcode directly into Python and use it as an extension module. -- [**589**星][2y] [Py] [eldraco/salamandra](https://github.com/eldraco/salamandra) Salamandra is a tool to find spy microphones that use radio freq to transmit. It uses SDR. -- [**588**星][20d] [Py] [trustedsec/trevorc2](https://github.com/trustedsec/trevorc2) 通过正常的可浏览的网站隐藏 C&C 指令的客户端/服务器模型,因为时间间隔不同,检测变得更加困难,并且获取主机数据时不会使用 POST 请求 -- [**588**星][14d] [Go] [cloudflare/cloudflared](https://github.com/cloudflare/cloudflared) Argo Tunnel client -- [**588**星][6m] [Ruby] [bit4woo/summit_ppt](https://github.com/bit4woo/summit_ppt) 各种安全大会PPT PDF +- [**590**星][6m] [Ruby] [bit4woo/summit_ppt](https://github.com/bit4woo/summit_ppt) 各种安全大会PPT PDF +- [**589**星][3m] [Py] [pahaz/sshtunnel](https://github.com/pahaz/sshtunnel) SSH tunnels to remote server. +- [**589**星][1y] [brunty/awesome-checker-services](https://github.com/brunty/awesome-checker-services) List of links to the various checkers out there on the web for sites, domains, security etc +- [**589**星][1m] [Py] [1n3/blackwidow](https://github.com/1n3/blackwidow) A Python based web application scanner to gather OSINT and fuzz for OWASP vulnerabilities on a target website. +- [**588**星][28d] [Go] [nytimes/gziphandler](https://github.com/nytimes/gziphandler) Go middleware to gzip HTTP responses +- [**587**星][13d] [C++] [lhy0403/qv2ray](https://github.com/lhy0403/qv2ray) v2ray linux Windows macOS GUI, 使用 Qt & c++, 支持 vmess ss socks,支持 vmess:// 扫描二维码,路由编辑,附带 Windows/Plasma 工具栏 - [**587**星][3y] [Perl 6] [rapid7/iotseeker](https://github.com/rapid7/iotseeker) scan a network for specific types of IoT devices to detect if they are using the default, factory set credentials. -- [**587**星][26d] [Go] [nytimes/gziphandler](https://github.com/nytimes/gziphandler) Go middleware to gzip HTTP responses -- [**587**星][2y] [Swift] [krisyu/swift14macosapps](https://github.com/krisyu/swift14macosapps) approaching macOS development using swift with 14 mini projects. +- [**587**星][3y] [hack-with-github/windows](https://github.com/hack-with-github/windows) Awesome tools to exploit Windows ! - [**587**星][3y] [C] [cr4sh/thinkpwn](https://github.com/cr4sh/thinkpwn) Lenovo ThinkPad System Management Mode arbitrary code execution 0day exploit -- [**586**星][3m] [Py] [pahaz/sshtunnel](https://github.com/pahaz/sshtunnel) SSH tunnels to remote server. -- [**586**星][1m] [Py] [1n3/blackwidow](https://github.com/1n3/blackwidow) A Python based web application scanner to gather OSINT and fuzz for OWASP vulnerabilities on a target website. +- [**586**星][12d] [lirantal/awesome-nodejs-security](https://github.com/lirantal/awesome-nodejs-security) Awesome Node.js Security resources +- [**586**星][2y] [Swift] [krisyu/swift14macosapps](https://github.com/krisyu/swift14macosapps) approaching macOS development using swift with 14 mini projects. +- [**585**星][2m] [Py] [thinkst/opencanary](https://github.com/thinkst/opencanary) Modular and decentralised honeypot - [**585**星][8m] [Java] [olacabs/jackhammer](https://github.com/olacabs/jackhammer) 安全漏洞评估和管理工具 -- [**585**星][3y] [hack-with-github/windows](https://github.com/hack-with-github/windows) Awesome tools to exploit Windows ! +- [**585**星][21d] [C++] [henrypp/memreduct](https://github.com/henrypp/memreduct) Lightweight real-time memory management application to monitor and clean system memory on your computer. +- [**585**星][4y] [certsocietegenerale/irm](https://github.com/certsocietegenerale/irm) Incident Response Methodologies - [**584**星][8m] [Py] [woj-ciech/danger-zone](https://github.com/woj-ciech/danger-zone) Correlate data between domains, IPs and email addresses, present it as a graph and store everything into Elasticsearch and JSON files. - [**584**星][9m] [C++] [secrary/makin](https://github.com/secrary/makin) reveal anti-debugging and anti-VM tricks -- [**584**星][2y] [Java] [findbugsproject/findbugs](https://github.com/findbugsproject/findbugs) The new home of the FindBugs project -- [**584**星][4y] [certsocietegenerale/irm](https://github.com/certsocietegenerale/irm) Incident Response Methodologies -- [**584**星][10d] [Go] [antoniomika/sish](https://github.com/antoniomika/sish) An open source serveo/ngrok alternative. HTTP(S)/WS(S)/TCP Tunnels to localhost using only SSH. -- [**583**星][2y] [Py] [sc0tfree/mentalist](https://github.com/sc0tfree/mentalist) 自定义wordlist 生成器,带界面,可生成与 Hashcat、Johnthe Ripper 兼容的 wordlist -- [**583**星][10d] [lirantal/awesome-nodejs-security](https://github.com/lirantal/awesome-nodejs-security) Awesome Node.js Security resources +- [**584**星][1m] [PS] [monoxgas/srdi](https://github.com/monoxgas/srdi) Shellcode implementation of Reflective DLL Injection. Convert DLLs to position independent shellcode +- [**584**星][2y] [Java] [findbugsproject/findbugs](https://github.com/findbugsproject/findbugs) 一个使用静态分析在Java代码中查找错误的程序 +- [**584**星][11d] [Ruby] [dev-sec/ansible-ssh-hardening](https://github.com/dev-sec/ansible-ssh-hardening) This Ansible role provides numerous security-related ssh configurations, providing all-round base protection. +- [**583**星][2d] [Py] [vivisect/vivisect](https://github.com/vivisect/vivisect) +- [**583**星][3y] [C] [ktap/ktap](https://github.com/ktap/ktap) a new scripting dynamic tracing tool for Linux - [**583**星][5m] [d30sa1/rootkits-list-download](https://github.com/d30sa1/rootkits-list-download) Rootkit收集 -- [**582**星][16d] [PHP] [zhuifengshaonianhanlu/pikachu](https://github.com/zhuifengshaonianhanlu/pikachu) 一个好玩的Web安全-漏洞测试平台 -- [**582**星][7d] [Py] [vivisect/vivisect](https://github.com/vivisect/vivisect) -- [**582**星][2m] [Py] [thinkst/opencanary](https://github.com/thinkst/opencanary) Modular and decentralised honeypot -- [**582**星][17d] [C] [mrexodia/titanhide](https://github.com/mrexodia/titanhide) Hiding kernel-driver for x86/x64. -- [**582**星][3y] [C] [ktap/ktap](https://github.com/ktap/ktap) a new scripting dynamic tracing tool for Linux +- [**582**星][8d] [Py] [facebookincubator/weasel](https://github.com/facebookincubator/weasel) DNS covert channel implant for Red Teams. +- [**582**星][1y] [Py] [softscheck/tplink-smartplug](https://github.com/softscheck/tplink-smartplug) TP-Link WiFi SmartPlug Client and Wireshark Dissector +- [**582**星][7m] [Py] [ekultek/zeus-scanner](https://github.com/ekultek/zeus-scanner) Advanced reconnaissance utility +- [**582**星][2m] [Go] [dimitarpetrov/stegify](https://github.com/dimitarpetrov/stegify) Go tool for LSB steganography, capable of hiding any file within an image. +- [**581**星][1y] [Py] [spencerdodd/kernelpop](https://github.com/spencerdodd/kernelpop) 内核提权枚举和漏洞利用框架 +- [**581**星][2m] [C++] [secrary/andromeda](https://github.com/secrary/andromeda) Andromeda - Interactive Reverse Engineering Tool for Android Applications +- [**581**星][9m] [Py] [romanz/amodem](https://github.com/romanz/amodem) 使用简单的耳机在两台计算机之间传输文件,实现真正的气密通信(通过扬声器和麦克风)或音频电缆(以提高传输速度) - [**581**星][3y] [Py] [mlsecproject/combine](https://github.com/mlsecproject/combine) 从公开的资源中收集IOC -- [**581**星][9d] [Ruby] [dev-sec/ansible-ssh-hardening](https://github.com/dev-sec/ansible-ssh-hardening) This Ansible role provides numerous security-related ssh configurations, providing all-round base protection. +- [**581**星][24d] [Ruby] [hackplayers/evil-winrm](https://github.com/hackplayers/evil-winrm) 用户Hacking/渗透的终极WinRM shell - [**581**星][1y] [JS] [cryptogenic/ps4-5.05-kernel-exploit](https://github.com/cryptogenic/ps4-5.05-kernel-exploit) A fully implemented kernel exploit for the PS4 on 5.05FW -- [**580**星][1y] [Py] [spencerdodd/kernelpop](https://github.com/spencerdodd/kernelpop) 内核提权枚举和漏洞利用框架 +- [**581**星][3d] [clarketm/proxy-list](https://github.com/clarketm/proxy-list) A list of free, public, forward proxy servers. UPDATED DAILY! - [**580**星][2m] [C] [pyca/bcrypt](https://github.com/pyca/bcrypt) Modern(-ish) password hashing for your software and your servers -- [**580**星][19d] [C++] [henrypp/memreduct](https://github.com/henrypp/memreduct) Lightweight real-time memory management application to monitor and clean system memory on your computer. -- [**580**星][13d] [Py] [gwen001/pentest-tools](https://github.com/gwen001/pentest-tools) Custom pentesting tools -- [**580**星][7m] [Py] [ekultek/zeus-scanner](https://github.com/ekultek/zeus-scanner) Advanced reconnaissance utility +- [**580**星][2y] [PHP] [pentestgeek/phishing-frenzy](https://github.com/pentestgeek/phishing-frenzy) Rubyon Rails 钓鱼框架 +- [**580**星][6m] [nshalabi/sysmontools](https://github.com/nshalabi/sysmontools) Utilities for Sysmon +- [**580**星][7m] [Py] [googlecloudplatform/flask-talisman](https://github.com/googlecloudplatform/flask-talisman) HTTP security headers for Flask - [**580**星][2y] [Py] [ant4g0nist/lisa.py](https://github.com/ant4g0nist/lisa.py) -An Exploit Dev Swiss Army Knife. -- [**579**星][2y] [PHP] [pentestgeek/phishing-frenzy](https://github.com/pentestgeek/phishing-frenzy) Rubyon Rails 钓鱼框架 +- [**579**星][1y] [CSS] [functionclub/ssr-bash-python](https://github.com/functionclub/ssr-bash-python) 一个SSR多用户控制脚本 - [**579**星][1y] [Go] [manifoldco/torus-cli](https://github.com/manifoldco/torus-cli) A secure, shared workspace for secrets +- [**579**星][1m] [C] [getdnsapi/stubby](https://github.com/getdnsapi/stubby) Stubby is the name given to a mode of using getdns which enables it to act as a local DNS Privacy stub resolver (using DNS-over-TLS). +- [**579**星][1y] [Java] [federicodotta/brida](https://github.com/federicodotta/brida) The new bridge between Burp Suite and Frida! - [**579**星][4y] [80vul/phpcodz](https://github.com/80vul/phpcodz) 在php源代码的基础上去分析容易导致php应用程序的一些安全问题的根本所在 -- [**578**星][9m] [Py] [romanz/amodem](https://github.com/romanz/amodem) transmit a file between 2 computers, using a simple headset, allowing true air-gapped communication (via a speaker and a microphone), or an audio cable (for higher transmission speed) +- [**578**星][1y] [C#] [tyranid/dotnettojscript](https://github.com/tyranid/dotnettojscript) 创建从内存中加载.NET v2程序集的JScript文件 +- [**578**星][6m] [Py] [timthony/self_drive](https://github.com/timthony/self_drive) 基于树莓派的自动驾驶小车,利用树莓派和tensorflow实现小车在赛道的自动驾驶。(Self-driving car based on raspberry pi(tensorflow)) +- [**578**星][3y] [Pascal] [t-d-k/librecrypt](https://github.com/t-d-k/librecrypt) Windows的透明、即时磁盘加密,兼容LUKS - [**578**星][10m] [mtivadar/windows10_ntfs_crash_dos](https://github.com/mtivadar/windows10_ntfs_crash_dos) Windows NTFS文件系统崩溃漏洞PoC -- [**577**星][3y] [Pascal] [t-d-k/librecrypt](https://github.com/t-d-k/librecrypt) Windows的透明、即时磁盘加密,兼容LUKS -- [**577**星][1y] [Py] [softscheck/tplink-smartplug](https://github.com/softscheck/tplink-smartplug) TP-Link WiFi SmartPlug Client and Wireshark Dissector -- [**577**星][2m] [C++] [secrary/andromeda](https://github.com/secrary/andromeda) Andromeda - Interactive Reverse Engineering Tool for Android Applications +- [**577**星][1y] [C++] [qbdi/qbdi](https://github.com/QBDI/QBDI) A Dynamic Binary Instrumentation framework based on LLVM. - [**577**星][12m] [HTML] [r00t-3xp10it/morpheus](https://github.com/r00t-3xp10it/morpheus) Morpheus - Automating Ettercap TCP/IP (MITM-hijacking Tool) -- [**577**星][2m] [Go] [dimitarpetrov/stegify](https://github.com/dimitarpetrov/stegify) Go tool for LSB steganography, capable of hiding any file within an image. -- [**576**星][1y] [C#] [tyranid/dotnettojscript](https://github.com/tyranid/dotnettojscript) A tool to create a JScript file which loads a .NET v2 assembly from memory. -- [**576**星][5m] [nshalabi/sysmontools](https://github.com/nshalabi/sysmontools) Utilities for Sysmon -- [**576**星][7m] [Py] [googlecloudplatform/flask-talisman](https://github.com/googlecloudplatform/flask-talisman) HTTP security headers for Flask +- [**576**星][24d] [PS] [threatexpress/red-team-scripts](https://github.com/threatexpress/red-team-scripts) A collection of Red Team focused tools, scripts, and notes +- [**576**星][3d] [Go] [mysteriumnetwork/node](https://github.com/mysteriumnetwork/node) Mysterium Node - VPN server and client for Mysterium Network +- [**576**星][3m] [Py] [jonluca/anubis](https://github.com/jonluca/anubis) Subdomain enumeration and information gathering tool - [**576**星][2y] [Py] [dutchgraa/crackcoin](https://github.com/dutchgraa/crackcoin) Very basic blockchain-free cryptocurrency PoC in Python -- [**575**星][1y] [CSS] [functionclub/ssr-bash-python](https://github.com/functionclub/ssr-bash-python) 一个SSR多用户控制脚本 -- [**575**星][1y] [C++] [qbdi/qbdi](https://github.com/QBDI/QBDI) A Dynamic Binary Instrumentation framework based on LLVM. +- [**575**星][18d] [Go] [yggdrasil-network/yggdrasil-go](https://github.com/yggdrasil-network/yggdrasil-go) An experiment in scalable routing as an encrypted IPv6 overlay network +- [**575**星][2m] [Go] [shopify/kubeaudit](https://github.com/shopify/kubeaudit) kubeaudit helps you audit your Kubernetes clusters against common security controls - [**575**星][2y] [JS] [shadowsocks-plus/shadowsocks-plus](https://github.com/shadowsocks-plus/shadowsocks-plus) -- [**575**星][3m] [Py] [jonluca/anubis](https://github.com/jonluca/anubis) Subdomain enumeration and information gathering tool +- [**575**星][9m] [Py] [fox-it/mitm6](https://github.com/fox-it/mitm6) exploits the default configuration of Windows to take over the default DNS server - [**574**星][1m] [Py] [nekmo/amazon-dash](https://github.com/nekmo/amazon-dash) Hack your Amazon Dash to run what you want. -- [**574**星][22d] [PowerShell] [threatexpress/red-team-scripts](https://github.com/threatexpress/red-team-scripts) A collection of Red Team focused tools, scripts, and notes +- [**574**星][6m] [PHP] [s3inlc/hashtopolis](https://github.com/s3inlc/hashtopolis) Hashcat wrapper, 用于跨平台分布式Hash破解 +- [**574**星][5m] [Py] [nidem/kerberoast](https://github.com/nidem/kerberoast) 一系列用于攻击MS Kerberos实现的工具 +- [**574**星][4m] [Py] [neo23x0/yargen](https://github.com/neo23x0/yargen) yarGen is a generator for YARA rules +- [**574**星][3y] [C] [iagox86/hash_extender](https://github.com/iagox86/hash_extender) +- [**574**星][4y] [C#] [elevenpaths/evilfoca](https://github.com/elevenpaths/evilfoca) Tool to analyze and test security in IPv4 and IPv6 data networks +- [**574**星][14d] [Perl] [bollwarm/sectoolset](https://github.com/bollwarm/sectoolset) 安全项目工具集合 +- [**573**星][2y] [C++] [zneak/fcd](https://github.com/zneak/fcd) An optimizing decompiler - [**573**星][4y] [C++] [microsoft/iediagnosticsadapter](https://github.com/microsoft/iediagnosticsadapter) IE Diagnostics Adapter is a standalone exe that enables tools to debug and diagnose IE11 using the Chrome remote debug protocol. - [**573**星][3y] [C] [jgarzik/cpuminer](https://github.com/jgarzik/cpuminer) CPU miner for bitcoin -- [**573**星][3y] [C] [iagox86/hash_extender](https://github.com/iagox86/hash_extender) -- [**573**星][4y] [C#] [elevenpaths/evilfoca](https://github.com/elevenpaths/evilfoca) Tool to analyze and test security in IPv4 and IPv6 data networks -- [**572**星][2y] [C++] [zneak/fcd](https://github.com/zneak/fcd) An optimizing decompiler +- [**573**星][3m] [Perl] [alisamtechnology/atscan](https://github.com/alisamtechnology/atscan) Advanced dork Search & Mass Exploit Scanner +- [**572**星][27d] [Py] [0kee-team/watchad](https://github.com/0kee-team/watchad) AD Security Intrusion Detection System +- [**572**星][2y] [Py] [nnamon/linux-exploitation-course](https://github.com/nnamon/linux-exploitation-course) 中级 Linux 漏洞开发课程 +- [**572**星][2y] [hack-with-github/awesome-security-gists](https://github.com/hack-with-github/awesome-security-gists) Gist收集 - [**572**星][2m] [HTML] [gwillem/magento-malware-scanner](https://github.com/gwillem/magento-malware-scanner) 用于检测 Magento 恶意软件的规则/样本集合 -- [**572**星][1m] [C] [getdnsapi/stubby](https://github.com/getdnsapi/stubby) Stubby is the name given to a mode of using getdns which enables it to act as a local DNS Privacy stub resolver (using DNS-over-TLS). -- [**572**星][8d] [clarketm/proxy-list](https://github.com/clarketm/proxy-list) A list of free, public, forward proxy servers. UPDATED DAILY! -- [**572**星][3y] [HTML] [bitdust/wamacry](https://github.com/bitdust/wamacry) a fake WannaCry +- [**572**星][16d] [Java] [alexzaitsev/apk-dependency-graph](https://github.com/alexzaitsev/apk-dependency-graph) Android class dependency visualizer. This tool helps to visualize the current state of the project. +- [**571**星][10d] [Py] [nsacyber/walkoff](https://github.com/nsacyber/WALKOFF) A flexible, easy to use, automation framework allowing users to integrate their capabilities and devices to cut through the repetitive, tedious tasks slowing them down. #nsacyber - [**571**星][11m] [Py] [ddevault/pass-rotate](https://github.com/ddevault/pass-rotate) A tool and library for rotating your password on online services -- [**571**星][5m] [Py] [nidem/kerberoast](https://github.com/nidem/kerberoast) a series of tools for attacking MS Kerberos implementations -- [**571**星][8m] [Py] [fox-it/mitm6](https://github.com/fox-it/mitm6) exploits the default configuration of Windows to take over the default DNS server -- [**571**星][14d] [Java] [alexzaitsev/apk-dependency-graph](https://github.com/alexzaitsev/apk-dependency-graph) Android class dependency visualizer. This tool helps to visualize the current state of the project. -- [**570**星][16d] [Go] [yggdrasil-network/yggdrasil-go](https://github.com/yggdrasil-network/yggdrasil-go) An experiment in scalable routing as an encrypted IPv6 overlay network -- [**570**星][2y] [Py] [nnamon/linux-exploitation-course](https://github.com/nnamon/linux-exploitation-course) 中级 Linux 漏洞开发课程 -- [**570**星][1y] [Java] [federicodotta/brida](https://github.com/federicodotta/brida) The new bridge between Burp Suite and Frida! -- [**570**星][12d] [Perl] [bollwarm/sectoolset](https://github.com/bollwarm/sectoolset) 安全项目工具集合 +- [**571**星][4y] [Go] [fzipp/gocyclo](https://github.com/fzipp/gocyclo) Calculate cyclomatic complexities of functions in Go source code. +- [**571**星][3y] [HTML] [bitdust/wamacry](https://github.com/bitdust/wamacry) 假装自己是个病毒 +- [**570**星][2m] [Py] [tarunkant/gopherus](https://github.com/tarunkant/gopherus) This tool generates gopher link for exploiting SSRF and gaining RCE in various servers +- [**570**星][23d] [C] [jhallen/joes-sandbox](https://github.com/jhallen/joes-sandbox) +- [**570**星][18d] [Py] [graphenex/graphenex](https://github.com/graphenex/graphenex) Automated System Hardening Framework +- [**570**星][2y] [PS] [411hall/jaws](https://github.com/411hall/jaws) JAWS - Just Another Windows (Enum) Script +- [**569**星][7m] [ObjC] [rpetrich/captainhook](https://github.com/rpetrich/captainhook) Common hooking/monkey patching headers for Objective-C on Mac OS X and iPhone OS. MIT licensed - [**569**星][4y] [Py] [musalbas/heartbleed-masstest](https://github.com/musalbas/heartbleed-masstest) Multi-threaded tool for scanning many hosts for CVE-2014-0160. -- [**569**星][1m] [PowerShell] [monoxgas/srdi](https://github.com/monoxgas/srdi) Shellcode implementation of Reflective DLL Injection. Convert DLLs to position independent shellcode -- [**569**星][2y] [hack-with-github/awesome-security-gists](https://github.com/hack-with-github/awesome-security-gists) Gist收集 -- [**569**星][10d] [Java] [guardianproject/netcipher](https://github.com/guardianproject/netcipher) a library for Android that provides multiple means to improve network security in mobile applications -- [**569**星][16d] [Py] [graphenex/graphenex](https://github.com/graphenex/graphenex) Automated System Hardening Framework -- [**569**星][1y] [C] [externalist/exploit_playground](https://github.com/externalist/exploit_playground) Analysis of public exploits or my 1day exploits -- [**569**星][3m] [Perl] [alisamtechnology/atscan](https://github.com/alisamtechnology/atscan) Advanced dork Search & Mass Exploit Scanner -- [**568**星][1y] [Solidity] [crytic/not-so-smart-contracts](https://github.com/crytic/not-so-smart-contracts) Examples of Solidity security issues -- [**568**星][2m] [Go] [shopify/kubeaudit](https://github.com/shopify/kubeaudit) kubeaudit helps you audit your Kubernetes clusters against common security controls -- [**568**星][7m] [Objective-C] [rpetrich/captainhook](https://github.com/rpetrich/captainhook) Common hooking/monkey patching headers for Objective-C on Mac OS X and iPhone OS. MIT licensed -- [**568**星][21d] [C] [jhallen/joes-sandbox](https://github.com/jhallen/joes-sandbox) -- [**568**星][2y] [PowerShell] [411hall/jaws](https://github.com/411hall/jaws) JAWS - Just Another Windows (Enum) Script -- [**567**星][6m] [PHP] [s3inlc/hashtopolis](https://github.com/s3inlc/hashtopolis) Hashcat wrapper, 用于跨平台分布式Hash破解 -- [**567**星][4m] [Py] [neo23x0/yargen](https://github.com/neo23x0/yargen) yarGen is a generator for YARA rules -- [**567**星][4y] [Go] [fzipp/gocyclo](https://github.com/fzipp/gocyclo) Calculate cyclomatic complexities of functions in Go source code. -- [**566**星][8d] [Py] [nsacyber/walkoff](https://github.com/nsacyber/WALKOFF) A flexible, easy to use, automation framework allowing users to integrate their capabilities and devices to cut through the repetitive, tedious tasks slowing them down. #nsacyber -- [**566**星][2m] [Py] [tarunkant/gopherus](https://github.com/tarunkant/gopherus) This tool generates gopher link for exploiting SSRF and gaining RCE in various servers -- [**566**星][10m] [JS] [raineorshine/solgraph](https://github.com/raineorshine/solgraph) Visualize Solidity control flow for smart contract security analysis. -- [**566**星][2y] [C] [matthijskooijman/arduino-lmic](https://github.com/matthijskooijman/arduino-lmic) LoraWAN-in-C library, adapted to run under the Arduino environment -- [**565**星][6d] [Py] [facebookincubator/weasel](https://github.com/facebookincubator/weasel) DNS covert channel implant for Red Teams. -- [**565**星][5m] [C++] [sgan81/apfs-fuse](https://github.com/sgan81/apfs-fuse) FUSE driver for APFS (Apple File System) -- [**565**星][3m] [C++] [lowpowerlab/rfm69](https://github.com/lowpowerlab/rfm69) RFM69 library for RFM69W, RFM69HW, RFM69CW, RFM69HCW (semtech SX1231, SX1231H) +- [**569**星][12d] [Java] [guardianproject/netcipher](https://github.com/guardianproject/netcipher) a library for Android that provides multiple means to improve network security in mobile applications +- [**569**星][5m] [Py] [codingo/vhostscan](https://github.com/codingo/vhostscan) A virtual host scanner that performs reverse lookups, can be used with pivot tools, detect catch-all scenarios, work around wildcards, aliases and dynamic default pages. +- [**568**星][1y] [Solidity] [crytic/not-so-smart-contracts](https://github.com/crytic/not-so-smart-contracts) 常见的以太坊智能合约漏洞示例,包括来自真实智能合约的代码。 +- [**568**星][5m] [C++] [sgan81/apfs-fuse](https://github.com/sgan81/apfs-fuse) FUSE driver for APFS (Apple File System) +- [**568**星][11m] [Py] [genetic-malware/ebowla](https://github.com/genetic-malware/ebowla) Framework for Making Environmental Keyed Payloads (NO LONGER SUPPORTED) +- [**568**星][2d] [HTML] [fate0/proxylist](https://github.com/fate0/proxylist) proxylist, generate by fate0/getproxy project in every 15 minute +- [**568**星][1y] [C] [externalist/exploit_playground](https://github.com/externalist/exploit_playground) Analysis of public exploits or my 1day exploits +- [**567**星][2y] [Visual Basic .NET] [mdsecactivebreach/cactustorch](https://github.com/mdsecactivebreach/cactustorch) Payload Generation for Adversary Simulations +- [**567**星][2y] [C] [matthijskooijman/arduino-lmic](https://github.com/matthijskooijman/arduino-lmic) LoraWAN-in-C library, adapted to run under the Arduino environment +- [**567**星][3m] [C++] [lowpowerlab/rfm69](https://github.com/lowpowerlab/rfm69) RFM69 library for RFM69W, RFM69HW, RFM69CW, RFM69HCW (semtech SX1231, SX1231H) +- [**566**星][11m] [JS] [raineorshine/solgraph](https://github.com/raineorshine/solgraph) Visualize Solidity control flow for smart contract security analysis. +- [**566**星][10m] [C] [justinsteven/dostackbufferoverflowgood](https://github.com/justinsteven/dostackbufferoverflowgood) 跨站点脚本编写者的演示和教程,这些站点编写者不能很好地堆积缓冲区溢出,并且也想做其他事情 +- [**565**星][3y] [HTML] [salesforce/vulnreport](https://github.com/salesforce/vulnreport) 渗透测试管理和自动化平台 +- [**565**星][21d] [ObjC] [hdb-li/lldebugtool](https://github.com/hdb-li/lldebugtool) LLDebugTool is a debugging tool for developers and testers that can help you analyze and manipulate data in non-xcode situations. - [**565**星][6m] [C#] [fremag/memoscope.net](https://github.com/fremag/memoscope.net) Dump and analyze .Net applications memory ( a gui for WinDbg and ClrMd ) - [**565**星][3y] [Py] [edwardz246003/iis_exploit](https://github.com/edwardz246003/iis_exploit) Buffer overflow in the ScStoragePathFromUrl function in the WebDAV service in Internet Information Services (IIS) 6.0 in Microsoft Windows Server 2003 R2 allows remote attackers to execute arbitrary code via a long header beginning with "If: