j5s's starred repositories

fastify

Fast and low overhead web framework, for Node.js

Language:JavaScriptLicense:NOASSERTIONStargazers:30860Issues:293Issues:1928

awesome-honeypots

an awesome list of honeypot resources

Language:PythonLicense:Artistic-2.0Stargazers:8114Issues:379Issues:19

LearnGolang

《Golang学习资源大全-只有Go语言才能改变世界》Only Golang Can Change The World.

HackJava

《Java安全-只有Java安全才能拯救宇宙》Only Java Security Can Save The Universe.

CodeQL

《深入理解CodeQL》Finding vulnerabilities with CodeQL.

Software-Security-Learning

Software-Security-Learning

labs

Vulnerability Labs for security analysis

chashell

Chashell is a Go reverse shell that communicates over DNS. It can be used to bypass firewalls or tightly restricted networks.

legion

Legion is an open source, easy-to-use, super-extensible and semi-automated network penetration testing tool that aids in discovery, reconnaissance and exploitation of information systems.

Language:PythonLicense:GPL-3.0Stargazers:988Issues:43Issues:169

identYwaf

Blind WAF identification tool

Language:PythonLicense:MITStargazers:558Issues:14Issues:12

Github_Nuggests

自动爬取Github上文件敏感信息泄露,抓取邮箱密码并自动登录邮箱验证,支持126,qq,sina,163邮箱

Language:PythonStargazers:337Issues:8Issues:0

CTF_SPECIAL_TRAINING_CAMP

《 CTF 特训营 》一书练习文件

SAST

《深入理解SAST静态应用安全测试》Static Application Security Testing.

articles

Personal Blog/主记录漏洞挖掘相关研究(文章位于issues)

FuckPHP

《PHP安全-只有PHP安全才能拯救世界》Only PHP Security Can Save The World.

iOSSecurity

《iOS安全测试与安全研究》

CORS-SCAN

扫描存在CORS跨域漏洞的网站。

Language:PythonStargazers:82Issues:3Issues:0

X-WebScan

Vulcan2.0|分布式扫描器|漏洞扫描|指纹识别

MetasploitModules_0x727

Metasploit Modules Development

Language:RubyLicense:MITStargazers:70Issues:4Issues:0

PassiveSecCheck

自动化被动扫描系统分为数据源、数据处理、漏洞验证等三个子系统,本系统属于漏洞验证部分,根据提供的数据进行分布式安全验证,确定是否包含相关严重漏洞。

Language:PythonStargazers:49Issues:1Issues:0

httpdoom

HttpDoom is a tool for response-based inspection of websites across a large amount of hosts for quickly gaining an overview of HTTP-based attack surface.

Language:C#Stargazers:49Issues:2Issues:0

DAST

《深入理解DAST动态应用程序安全测试》Dynamic Application Security Testing.

Hackaspx

《ASPX安全-只有ASPX安全才能拯救.NET》Only ASPX Security Can Save The NET.

DevSecOps

开发和安全和运营:DevSecOps-Software development (Dev) and Security (Sec) and IT operations (Ops).

depyword

渗透测试报告生成,省去繁琐的word编辑、修改样式过程

IAST

《深入理解IAST交互式应用安全测试》Interactive Application Security Testing.

Shangyang

商羊 - 智能化攻击目标识别/资产管理

License:MITStargazers:5Issues:2Issues:0

FishingBoat

安全攻防平台

License:MITStargazers:3Issues:0Issues:0

Tx

打造最好用的红队渗透测试辅助工具。

License:UnlicenseStargazers:2Issues:1Issues:0

A-shares

《A-shares:中国A股研究与实战》