Hoang Nguyen Dinh's repositories
ApplicationInspector
A source code analyzer built for surfacing features of interest and other characteristics to answer the question 'What's in the code?' quickly using static analysis with a json based rules engine. Ideal for scanning components before use or detecting feature level changes.
awesome-bugbounty-tools
A curated list of various bug bounty tools
Awesome-WAF
🔥 Everything about web-application firewalls (WAF).
can-i-take-over-xyz
"Can I take over XYZ?" — a list of services and how to claim (sub)domains with dangling DNS records.
chaos-client
Go client to communicate with Chaos DNS API.
CodeAnalysis
Static Code Analysis - 静态代码分析
Cybersecurity-Resources
A Library of various cybersecurity resources
DefaultCreds-cheat-sheet
One place for all the default credentials to assist the Blue/Red teamers activities on finding devices with default password 🛡️
dotnet-deserialization
dotnet 反序列化学习笔记
ffuf
Fast web fuzzer written in Go
Fuzzing101
An step by step fuzzing tutorial. A GitHub Security Lab initiative
ghidra
Ghidra is a software reverse engineering (SRE) framework
google-dorks
Useful Google Dorks for WebSecurity and Bug Bounty
java-sec-code
Java web common vulnerabilities and security code which is base on springboot and spring security
Kunlun-M
KunLun-M是一个完全开源的静态白盒扫描工具,支持PHP、JavaScript的语义扫描,基础安全、组件安全扫描,Chrome Ext\Solidity的基础扫描。
metasploit-framework
Metasploit Framework
mimikatz
A little tool to play with Windows security
nmap-formatter
A tool that allows you to convert NMAP results to html, csv, json, markdown. Simply put it's nmap converter.
nuclei-burp-plugin
Nuclei plugin for BurpSuite
ofbiz-framework
Apache OFBiz is an open source product for the automation of enterprise processes. It includes framework components and business applications for ERP, CRM, E-Business/E-Commerce, Supply Chain Management and Manufacturing Resource Planning. OFBiz provides a foundation and starting point for reliable, secure and scalable enterprise solutions.
QLinspector
Finding Java gadget chains with CodeQL
secret-regex-list
List of regex for scraping secret API keys and juicy information.
SharPyShell
SharPyShell - tiny and obfuscated ASP.NET webshell for C# web applications
SpringCore0day
SpringCore0day from https://share.vx-underground.org/
SubOver
A Powerful Subdomain Takeover Tool