melon's starred repositories

bcc

BCC - Tools for BPF-based Linux IO analysis, networking, monitoring, and more

Language:CLicense:Apache-2.0Stargazers:19897Issues:554Issues:1879

windows

Windows inside a Docker container.

Language:ShellLicense:MITStargazers:15672Issues:99Issues:361

jsoup

jsoup: the Java HTML parser, built for HTML editing, cleaning, scraping, and XSS safety.

learnjavabug

Java安全相关的漏洞和技术demo,原生Java、Fastjson、Jackson、Hessian2、XML反序列化漏洞利用和Spring、Dubbo、Shiro、CAS、Tomcat、RMI、Nexus等框架\中间件\功能的exploits以及Java Security Manager绕过、Dubbo-Hessian2安全加固等等实践代码。

Language:JavaLicense:MITStargazers:2555Issues:73Issues:6

bpf-developer-tutorial

eBPF Developer Tutorial: Learning eBPF Step by Step with Examples

no-defender

A slightly more fun way to disable windows defender + firewall. (through the WSC api)

SecGPT

SecGPT网络安全大模型

Language:PythonLicense:Apache-2.0Stargazers:1541Issues:15Issues:53

AutoBlue-MS17-010

This is just an semi-automated fully working, no-bs, non-metasploit version of the public exploit code for MS17-010

Language:PythonLicense:MITStargazers:1116Issues:31Issues:33

TsojanScan

An integrated BurpSuite vulnerability detection plug-in.

Windows-Local-Privilege-Escalation-Cookbook

Windows Local Privilege Escalation Cookbook

Language:PowerShellLicense:MITStargazers:857Issues:11Issues:1

JavaSecurityLearning

记录一下 Java 安全学习历程,也算是半条学习路线了

Language:HTMLLicense:GPL-3.0Stargazers:817Issues:9Issues:2

Frida-Labs

The repo contains a series of challenges for learning Frida for Android Exploitation.

License:MITStargazers:784Issues:8Issues:0

LoaderFly

助力每一位RT队员,快速生成免杀木马

dismember

:knife: Scan memory for secrets and more. Maybe eventually a full /proc toolkit.

Language:GoLicense:MITStargazers:595Issues:9Issues:2

FastJsonParty

FastJson全版本Docker漏洞环境(涵盖1.2.47/1.2.68/1.2.80等版本),主要包括JNDI注入及高版本绕过、waf绕过、文件读写、原生反序列化、利用链探测绕过、不出网利用等。从黑盒的角度覆盖FastJson深入利用

JavaRce

Common Exploitation Techniques for Java RCE Vulnerabilities in Real-World Scenarios | 实战场景较通用的 Java Rce 相关漏洞的利用方式

Language:JavaStargazers:413Issues:5Issues:0

java-echo-generator

一款支持高度自定义的 Java 回显载荷生成工具|A highly customizable Java echo payload generation tool.

SspiUacBypass

Bypassing UAC with SSPI Datagram Contexts

Language:C++License:MITStargazers:328Issues:4Issues:6

cnext-exploits

Exploits for CNEXT (CVE-2024-2961), a buffer overflow in the glibc's iconv()

Language:PythonStargazers:311Issues:7Issues:0

SharpShares

Multithreaded C# .NET Assembly to enumerate accessible network shares in a domain

Language:C#License:MITStargazers:310Issues:11Issues:3

vagent

多功能 java agent 内存马

SGK-bot

🤖 几个数据质量较高的社工库机器人

jdwp-codeifier

基于 jdwp-shellifier 的进阶JDWP漏洞利用脚本(动态执行Java/Js代码并获得回显)

Language:PythonLicense:MITStargazers:199Issues:1Issues:0

EchoDrv

Exploitation of echo_driver.sys

Language:C#Stargazers:164Issues:2Issues:0

Awsome-Sec.CTF-Videomaker

【Hello CTF】收录国内网络安全以及CTF领域的优秀视频作者

Language:PythonStargazers:148Issues:3Issues:0

AheadLibEx

hijack dll Source Code Generator .

Language:C++License:GPL-3.0Stargazers:145Issues:5Issues:3

Unique_DLL_Hijacking_Scan

DLL Hijacking 批量挖掘工具,用于快速生成指定文件夹下所有 EXE 的 Unique DLL Hijacking Payload

Language:PythonStargazers:79Issues:2Issues:0

ten

A (small) web exploit framework