gitfuzzing's starred repositories

SecLists

SecLists is the security tester's companion. It's a collection of multiple types of lists used during security assessments, collected in one place. List types include usernames, passwords, URLs, sensitive data patterns, fuzzing payloads, web shells, and many more.

XSStrike

Most advanced XSS scanner.

Language:PythonLicense:GPL-3.0Stargazers:12846Issues:273Issues:278

windows-kernel-exploits

windows-kernel-exploits Windows平台提权漏洞集合

wafw00f

WAFW00F allows one to identify and fingerprint Web Application Firewall (WAF) products protecting a website.

Language:PythonLicense:BSD-3-ClauseStargazers:4957Issues:140Issues:92

SSRF-Testing

SSRF (Server Side Request Forgery) testing resources

AngelSword

Python3编写的CMS漏洞检测框架

openstar

lua waf,nginx+lua,openresty,luajit,waf+,cdn,nginx

filterbypass

Browser's XSS Filter Bypass Cheat Sheet

Eternalblue-Doublepulsar-Metasploit

Module of Metasploit to exploit the vulnerability Eternalblue-Doublepulsar.

Language:RubyLicense:LGPL-2.1Stargazers:1077Issues:103Issues:111

attifyos

Attify OS - Distro for pentesting IoT devices

android_vuln_poc-exp

This project contains pocs and exploits for vulneribilities I found (mostly)

x-waf

适用于中小企业的云waf

passmaker

可以自定义规则的密码字典生成器,支持图形界面 A password-generator that base on the rules that you specified

Language:PythonLicense:GPL-3.0Stargazers:530Issues:16Issues:7

web-log-parser

An open source analysis web log tool

Fwaf-Machine-Learning-driven-Web-Application-Firewall

Machine learning driven web application firewall to detect malicious queries with high accuracy.

pentestER-Fully-automatic-scanner

DNS Subdomain● Brute force ● Web Spider ● Nmap Scan ● etc

subdomain-takeover

Subdomain Takeover Scanner | Subdomain Takeover Tool | by 0x94

Language:JavaScriptLicense:NOASSERTIONStargazers:312Issues:22Issues:24

Exploit-Exercises-Nebula

Exploit-Exercises Nebula全攻略——Linux平台下的漏洞分析入门

cangibrina

A fast and powerfull dashboard (admin) finder

Language:PythonLicense:GPL-2.0Stargazers:226Issues:24Issues:5

apparatus

A graphical security analysis tool for IoT networks

Language:JavaScriptLicense:MITStargazers:202Issues:25Issues:25

CAPTCHA_Reader

:honeybee: PHP 验证码识别与训练 脚手架

Language:PHPLicense:WTFPLStargazers:150Issues:7Issues:21

icstools

ics security tools

Language:LuaStargazers:135Issues:0Issues:0

burp-flow

Extension providing view with filtering capabilities for both complete and incomplete requests from all burp tools.

Language:JavaLicense:MITStargazers:46Issues:6Issues:15

Log-Analysis

SSH & Basic Web Applications brute-forcing attempts are visible in your mailbox with this tool.

slowdos

慢连接攻击

Language:PythonStargazers:8Issues:2Issues:0

web_log_hunting

Python scripts to perform triage of web server logs for signs of attack

Language:PythonLicense:GPL-3.0Stargazers:4Issues:1Issues:0

asmc

应用安全日志审计系统

Language:JavaScriptStargazers:1Issues:1Issues:1