ShenMingF's starred repositories

BurpHttpHelper

BurpHttpHelper是一款Burpsuite插件,主要用于简化和解决Burpsuite对Http的一些操作.

Language:JavaLicense:Apache-2.0Stargazers:85Issues:0Issues:0

LangSrcCurise

SRC子域名资产监控

Language:PythonStargazers:1253Issues:0Issues:0

BurpShiroPassiveScan

一款基于BurpSuite的被动式shiro检测插件

Language:JavaStargazers:1610Issues:0Issues:0

DragonCastle

A PoC that combines AutodialDLL lateral movement technique and SSP to scrape NTLM hashes from LSASS process.

Language:C++Stargazers:293Issues:0Issues:0

BypassAV

This map lists the essential techniques to bypass anti-virus and EDR

Stargazers:2257Issues:0Issues:0

Caesar

一个全新的敏感文件发现工具

Stargazers:2Issues:0Issues:0

RedisEXP

Redis 漏洞利用工具

Language:GoStargazers:731Issues:0Issues:0

NtDetours

Detours implementation (x64/x86) which used only ntdll import

Language:CStargazers:85Issues:0Issues:0

vuldirscan

一个介于目录扫描与poc验证之间的新生儿

Language:PythonStargazers:20Issues:0Issues:0

UEditorGetShell

UEditor编辑器批量GetShell / Code By:Tas9er

Stargazers:222Issues:0Issues:0

IDOR_detect_tool

一款API水平越权漏洞检测工具

Language:PythonLicense:GPL-3.0Stargazers:716Issues:0Issues:0

Invoke-TheHash

PowerShell Pass The Hash Utils

Language:PowerShellLicense:BSD-3-ClauseStargazers:1443Issues:0Issues:0

Privileger

Privileger is a tool to work with Windows Privileges

Language:C++Stargazers:130Issues:0Issues:0

titan

Titan: A generic user defined reflective DLL for Cobalt Strike

Stargazers:68Issues:0Issues:0

NetDLLSpy

.NET后渗透下的权限维持,附下载DLL

Stargazers:200Issues:0Issues:0

adduserbysamr-bof

Cobalt Strike BOF that Add a user to localgroup by samr

Language:CStargazers:113Issues:0Issues:0

myscan

构建信息搜集/漏洞扫描

Language:PythonStargazers:192Issues:0Issues:0

probable_subdomains

Subdomains analysis and generation tool. Reveal the hidden!

License:GPL-3.0Stargazers:225Issues:0Issues:0

burp_nu_te_gen

nuclei模版生成插件

Language:JavaLicense:Apache-2.0Stargazers:100Issues:0Issues:0

sshd_backdoor

/root/.ssh/authorized_keys evil file watchdog with ebpf tracepoint hook.

Language:CStargazers:313Issues:0Issues:0

Zentao-Captcha-RCE

禅道研发项目管理系统`misc-captcha-user`认证绕过后台命令注入漏洞

Language:GoStargazers:80Issues:0Issues:0

swagger-exp

A Swagger API Exploit

Language:JavaScriptStargazers:1094Issues:0Issues:0

goomba

gooMBA is a Hex-Rays Decompiler plugin to simplify Mixed Boolean-Arithmetic (MBA) expressions

Language:C++Stargazers:550Issues:0Issues:0

Headers

Headers Burp Extension

Language:PythonLicense:MITStargazers:17Issues:0Issues:0

BypassCredGuard

Credential Guard Bypass Via Patching Wdigest Memory

Language:C++Stargazers:301Issues:0Issues:0

CaA

CaA - Collector and Analyzer, Insight into information, exploring with intelligence in a thousand ways.

Language:JavaLicense:Apache-2.0Stargazers:677Issues:0Issues:0

TrackRay

溯光 (TrackRay) 3 beta⚡渗透测试框架(资产扫描|指纹识别|暴力破解|网页爬虫|端口扫描|漏洞扫描|代码审计|AWVS|NMAP|Metasploit|SQLMap)

Language:JavaLicense:GPL-3.0Stargazers:2018Issues:0Issues:0

sec-books-part1

:books: 网安类绝版图书

Stargazers:730Issues:0Issues:0

scalpel

scalpel是一款命令行漏洞扫描工具,支持深度参数注入,拥有一个强大的数据解析和变异算法,可以将常见的数据格式(json, xml, form等)解析为树结构,然后根据poc中的规则,对树进行变异,包括对叶子节点和树结构 的变异。变异完成之后,将树结构还原为原始的数据格式。

Stargazers:720Issues:0Issues:0

AmsiBypassHookManagedAPI

A new AMSI Bypass technique using .NET ALI Call Hooking.

Language:PowerShellLicense:GPL-3.0Stargazers:180Issues:0Issues:0