hatnoop

hatnoop

Geek Repo

Location:Beijing

Github PK Tool:Github PK Tool

hatnoop's starred repositories

LKY_OfficeTools

一键自动化 下载、安装、激活 Office 的利器。

Language:C#License:GPL-3.0Stargazers:8202Issues:58Issues:50

POC

收集整理漏洞EXP/POC,大部分漏洞来源网络,目前收集整理了1000多个poc/exp,长期更新。

b0pass

百灵快传(B0Pass):基于Go语言的高性能 "手机电脑超大文件传输神器"、"局域网共享文件服务器"。LAN large file transfer tool。

Language:GoLicense:Apache-2.0Stargazers:2091Issues:42Issues:54

domain_hunter_pro

domain_hunter的高级版本,SRC挖洞、HW打点之必备!自动化资产收集;快速Title获取;外部工具联动;等等

XXEinjector

Tool for automatic exploitation of XXE vulnerability using direct and different out of band methods.

SGK_Sites_and_Bots

免费在线社工库,免费Telegram社工库

bylibrary

白阁文库是白泽Sec安全团队维护的一个漏洞POC和EXP公开项目

Tai-e

An easy-to-learn/use static analysis framework for Java

Language:JavaLicense:LGPL-3.0Stargazers:1336Issues:30Issues:109

kubesploit

Kubesploit is a cross-platform post-exploitation HTTP/2 Command & Control server and agent written in Golang, focused on containerized environments.

Language:GoLicense:GPL-3.0Stargazers:1102Issues:28Issues:2

Z-Godzilla_ekp

哥斯拉webshell管理工具二次开发规避流量检测设备

e0e1-wx

微信小程序辅助渗透-自动化

darkPulse

darkPulse是一个用go编写的shellcode Packer,用于生成各种各样的shellcode loader,免杀火绒,360核晶等国内常见杀软。

alterx

Fast and customizable subdomain wordlist generator using DSL

Language:GoLicense:MITStargazers:688Issues:12Issues:23

xxer

A blind XXE injection callback handler. Uses HTTP and FTP to extract information. Originally written in Ruby by ONsec-Lab.

Language:PythonLicense:MITStargazers:508Issues:8Issues:0

jsubfinder

jsubfinder searches webpages for javascript & analyzes them for hidden subdomains and secrets (wip).

Language:GoLicense:MITStargazers:258Issues:9Issues:11

OSSFileBrowse

存储桶遍历漏洞利用工具

blackjump

JumpServer 堡垒机未授权综合漏洞利用, Exploit for CVE-2023-42442 / CVE-2023-42820 / RCE 2021

Language:PythonLicense:MITStargazers:205Issues:3Issues:1

GodzillaPlugin-Suo5-MemProxy

一款高性能 HTTP 内存代理 | 哥斯拉插件 | readteam | 红队 | 内存马 | Suo5 | Godzilla | 正向代理

spark

全自动字典生成---定向字典/社工字典/字典碰撞---火花(spark)

xianzhi_assistant

这是一个基于先知社区知识构建的向量知识库

TomcatVuln

Tomcat漏洞利用工具

PPPYSO

proof-of-concept for generating Java deserialization payload | Proxy MemShell

Botgate_bypass

绕过瑞数waf的动态验证机制,实现请求包重放,理论支持不同网站环境使用,如网页、小程序、APP等。

Language:PythonLicense:Apache-2.0Stargazers:147Issues:1Issues:5

HikvisionExploitGUI

海康威视漏洞综合利用工具,支持一键上传哥斯拉等多种利用方式

fastjsonChecker

burp手工检测fastjson辅助

isCdn

检查一个ip是否在cdn范围内

Language:GoLicense:MITStargazers:35Issues:0Issues:0

Tai-e-WebPlugin

Tai-e的Web插件

Language:JavaStargazers:17Issues:0Issues:0

CVE-2020-0688-GUI

GUI Exploit Tool for CVE-2020-0688(Microsoft Exchange default MachineKeySection deserialize vulnerability)

Language:C#Stargazers:14Issues:1Issues:0
Language:GoStargazers:2Issues:0Issues:0