neo's starred repositories

http-server

a simple zero-configuration command-line http server

Language:JavaScriptLicense:MITStargazers:13589Issues:0Issues:0

awesome-google-vrp-writeups

🐛 A list of writeups from the Google VRP Bug Bounty program

Language:PythonStargazers:1131Issues:0Issues:0

WinPwn

Automation for internal Windows Penetrationtest / AD-Security

Language:PowerShellLicense:BSD-3-ClauseStargazers:3295Issues:0Issues:0

frida-snippets

Hand-crafted Frida examples

Language:JavaScriptStargazers:2265Issues:0Issues:0

Juggler

A system that may trick hackers. 针对黑客的拟态欺骗系统。

Language:GoLicense:Apache-2.0Stargazers:437Issues:0Issues:0

yaml-payload

Spring Cloud SnakeYAML 反序列化一键注入cmdshell和reGeorg

Language:JavaStargazers:129Issues:0Issues:0

7kbscan-WebPathBrute

7kbscan-WebPathBrute Web路径暴力探测工具

Stargazers:1312Issues:0Issues:0

APT_Digital_Weapon

Indicators of compromise (IOCs) collected from public resources and categorized by Qi-AnXin.

License:GPL-3.0Stargazers:885Issues:0Issues:0

BurpFastJsonScan

一款基于BurpSuite的被动式FastJson检测插件

Language:JavaStargazers:1126Issues:0Issues:0

HaE

HaE - Highlighter and Extractor, Empower ethical hacker for efficient operations.

Language:JavaLicense:Apache-2.0Stargazers:2980Issues:0Issues:0

domainNamePredictor

一个简单的现代化公司域名使用规律预测及生成工具

Language:PythonStargazers:377Issues:0Issues:0

31-days-of-API-Security-Tips

This challenge is Inon Shkedy's 31 days API Security Tips.

Stargazers:2096Issues:0Issues:0

awesome-cybersecurity-blueteam

:computer:🛡️ A curated collection of awesome resources, tools, and other shiny things for cybersecurity blue teams.

Stargazers:4316Issues:0Issues:0

cnblogs-theme-silence

📖 一款专注于阅读的博客园主题

Language:HTMLLicense:MITStargazers:2026Issues:0Issues:0

JSFinder

JSFinder is a tool for quickly extracting URLs and subdomains from JS files on a website.

Language:PythonStargazers:2599Issues:0Issues:0

BugBounty

RepoToStoreBugBountyInfo

Language:CSSStargazers:267Issues:0Issues:0

Pentest_Note

渗透测试常规操作记录

Stargazers:3667Issues:0Issues:0

fileleak

又一款敏感文件泄漏检测工具

Stargazers:106Issues:0Issues:0

common-regex

:jack_o_lantern: 常用正则表达式 - 收集一些在平时项目开发中经常用到的正则表达式。

License:MITStargazers:3081Issues:0Issues:0

fuxi

Penetration Testing Platform

Language:PythonLicense:MITStargazers:1334Issues:0Issues:0

redtool

日常积累的一些红队工具及自己写的脚本,更偏向于一些diy的好用的工具,并不是一些比较常用的msf/awvs/xray这种

Language:ShellStargazers:1355Issues:0Issues:0

Learn-Web-Hacking

Study Notes For Web Hacking / Web安全学习笔记

Language:PythonLicense:CC0-1.0Stargazers:4563Issues:0Issues:0

wso-webshell

🕹 wso php webshell

Language:PHPLicense:MITStargazers:343Issues:0Issues:0

BBTz

BBT - Bug Bounty Tools (examples💡)

Language:PythonStargazers:1699Issues:0Issues:0

xsshunter

The XSS Hunter service - a portable version of XSSHunter.com

Language:JavaScriptLicense:MITStargazers:1477Issues:0Issues:0

Mars

Mars(战神)——资产发现、子域名枚举、C段扫描、资产变更监测、端口变更监测、域名解析变更监测、Awvs扫描、POC检测、web指纹探测、端口指纹探测、CDN探测、操作系统指纹探测、泛解析探测、WAF探测、敏感信息检测等等

Language:RubyStargazers:1233Issues:0Issues:0

Spring-Boot-Actuator-Exploit

Spring Boot Actuator (jolokia) XXE/RCE

Language:JavaStargazers:318Issues:0Issues:0

Violation_Pnetest

渗透红线Checklist

Stargazers:438Issues:0Issues:0

webshell-detect-bypass

绕过专业工具检测的Webshell研究文章和免杀的Webshell

Language:Classic ASPStargazers:1681Issues:0Issues:0

AppInfoScanner

一款适用于以HW行动/红队/渗透测试团队为场景的移动端(Android、iOS、WEB、H5、静态网站)信息收集扫描工具,可以帮助渗透测试工程师、攻击队成员、红队成员快速收集到移动端或者静态WEB站点中关键的资产信息并提供基本的信息输出,如:Title、Domain、CDN、指纹信息、状态信息等。

Language:PythonLicense:GPL-3.0Stargazers:3133Issues:0Issues:0