0x4C43's starred repositories

dive

A tool for exploring each layer in a docker image

grype

A vulnerability scanner for container images and filesystems

Language:GoLicense:Apache-2.0Stargazers:8245Issues:74Issues:806

CDK

📦 Make security testing of K8s, Docker, and Containerd easier.

Language:GoLicense:Apache-2.0Stargazers:3776Issues:70Issues:42

afrog

A Security Tool for Bug Bounty, Pentest and Red Teaming.

my-re0-k8s-security

:atom: [WIP] 整理过去的分享,从零开始的Kubernetes攻防 🧐

URLFinder

一款快速、全面、易用的页面信息提取工具,可快速发现和提取页面中的JS、URL和敏感信息。

feeds

免费的公众号 RSS,支持扩展任意 APP

APIKit

APIKit:Discovery, Scan and Audit APIs Toolkit All In One.

Language:JavaLicense:GPL-3.0Stargazers:1813Issues:20Issues:61

HummerRisk

HummerRisk 是云原生安全平台,包括混合云安全治理和云原生安全检测。

Language:JavaLicense:GPL-3.0Stargazers:1772Issues:111Issues:215

awesome-cloud-security

awesome cloud security 收集一些国内外不错的云安全资源,该项目主要面向国内的安全人员

License:Apache-2.0Stargazers:1672Issues:27Issues:0

QingScan

一个漏洞扫描器粘合剂,添加目标后30款工具自动调用;支持 web扫描、系统扫描、子域名收集、目录扫描、主机扫描、主机发现、组件识别、URL爬虫、XRAY扫描、AWVS自动扫描、POC批量验证,SSH批量测试、vulmap。

Language:PHPLicense:GPL-3.0Stargazers:1661Issues:22Issues:31

ggshield

Find and fix 400+ types of hardcoded secrets and 70+ types of infrastructure-as-code misconfigurations.

Language:PythonLicense:MITStargazers:1592Issues:34Issues:189

container-security-checklist

Checklist for container security - devsecops practices

SecurityInterviewGuide

网络信息安全从业者面试指南

Chinese-Security-RSS

网络安全资讯的RSS订阅,网络安全博客的RSS订阅,网络安全公众号的RSS订阅

redtool

日常积累的一些红队工具及自己写的脚本,更偏向于一些diy的好用的工具,并不是一些比较常用的msf/awvs/xray这种

peirates

Peirates - Kubernetes Penetration Testing tool

Language:GoLicense:GPL-2.0Stargazers:1185Issues:30Issues:35

fetch-github-hosts

🌏 同步github的hosts工具,支持多平台的图形化和命令行,内置客户端和服务端两种模式~ | Synchronize GitHub hosts tool, support multi-platform graphical and command line, built-in client and server modes

Language:GoLicense:GPL-3.0Stargazers:1076Issues:21Issues:19
Language:GoLicense:Apache-2.0Stargazers:1048Issues:27Issues:295

LAW-GPT

中文法律对话语言模型

goby-poc

451个goby poc,是否后门及重复自行判断,来源于网络收集的Goby&POC,不定时更新。

Language:GoStargazers:909Issues:20Issues:0

Library-POC

基于Pocsuite3、goby编写的漏洞poc&exp存档

Language:PythonStargazers:819Issues:31Issues:0

TheRoadOfSO

学习安全运营的记录 | The knowledge base of security operation

Language:HTMLStargazers:670Issues:9Issues:0

EasyPen

EasyPen is a GUI program which helps pentesters do target discovery, vulnerability scan and exploitation

container-escape-check

docker container escape check || Docker 容器逃逸检测

Language:ShellLicense:MITStargazers:523Issues:10Issues:5

BeeScan-web

网络空间资产探测、网络测绘、Go语言、分布式、扫描、资产探测、资产测绘、红队、SRC | Cyberspace Asset Detection, Network Mapping, Go Language, Distributed, Scanning, Asset Detection, Asset Mapping, Red Team, SRC

Language:CSSLicense:MITStargazers:380Issues:6Issues:10

14Finger

功能齐全的Web指纹识别和分享平台,基于vue3+django前后端分离的web架构,并集成了长亭出品的rad爬虫的功能,内置了一万多条互联网开源的指纹信息。

Language:PythonLicense:GPL-3.0Stargazers:371Issues:7Issues:12

awesome-cloud-native-security

awesome resources about cloud native security 🐿

Cloud-Native-Security-Test

云原生(容器云)安全测试镜像

Language:JavaStargazers:6Issues:0Issues:0