yinhediyi's starred repositories

meilisearch

A lightning-fast search API that fits effortlessly into your apps, websites, and workflow

AndroidSecurityStudy

安卓应用安全学习

Awesome-Redteam

一个攻防知识仓库 Red Teaming and Offensive Security

ghauri

An advanced cross-platform tool that automates the process of detecting and exploiting SQL injection security flaws

Language:PythonLicense:MITStargazers:3095Issues:38Issues:171

NucleiTP

自动整合全网Nuclei的漏洞POC,实时同步更新最新POC!

joern

Open-source code analysis platform for C/C++/Java/Binary/Javascript/Python/Kotlin based on code property graphs. Discord https://discord.gg/vv4MH284Hc

Language:ScalaLicense:Apache-2.0Stargazers:2088Issues:39Issues:1119

XiebroC2

渗透测试C2、支持Lua插件扩展、域前置/CDN上线、自定义profile、前置sRDI、文件管理、进程管理、内存加载、截图、反向代理、分组管理

PoolParty

A set of fully-undetectable process injection techniques abusing Windows Thread Pools

Language:C++License:BSD-3-ClauseStargazers:952Issues:13Issues:3

RealBlindingEDR

Remove AV/EDR Kernel ObRegisterCallbacks、CmRegisterCallback、MiniFilter Callback、PsSetCreateProcessNotifyRoutine Callback、PsSetCreateThreadNotifyRoutine Callback、PsSetLoadImageNotifyRoutine Callback...

Language:C++License:MITStargazers:936Issues:20Issues:12

FastJsonParty

FastJson全版本Docker漏洞环境(涵盖1.2.47/1.2.68/1.2.80等版本),主要包括JNDI注入及高版本绕过、waf绕过、文件读写、原生反序列化、利用链探测绕过、不出网利用等。从黑盒的角度覆盖FastJson深入利用

LearnJavaMemshellFromZero

【三万字原创】完全零基础从0到1掌握Java内存马,公众号:追梦信安

SOAPHound

SOAPHound is a custom-developed .NET data collector tool which can be used to enumerate Active Directory environments via the Active Directory Web Services (ADWS) protocol.

Language:C#License:GPL-3.0Stargazers:650Issues:11Issues:10

SqlmapXPlus

sqlmap Xplus 基于 sqlmap,对经典的数据库注入漏洞利用工具进行二开!

Language:PythonLicense:GPL-2.0Stargazers:598Issues:12Issues:7

JavaRce

Common Exploitation Techniques for Java RCE Vulnerabilities in Real-World Scenarios | 实战场景较通用的 Java Rce 相关漏洞的利用方式

dalton

Suricata and Snort IDS rule and pcap testing system

Language:PythonLicense:Apache-2.0Stargazers:449Issues:44Issues:28

ConfluenceMemshell

Confluence CVE 2021,2022,2023 利用工具,支持命令执行,哥斯拉,冰蝎 内存马注入

sqinn-go

Golang SQLite without cgo

Language:GoLicense:UnlicenseStargazers:425Issues:5Issues:8

yuze

A socksv5 proxy tool Written by CLang. 一款纯C实现的基于socks5协议的轻量内网穿透工具,支持ew的全部数据转发方式,支持跨平台使用

nuclei-templates

nuclei-templates 4W+已校验

Language:PythonLicense:MITStargazers:176Issues:8Issues:0

static-analysis

静态分析基础教程

LearnFastjsonVulnFromZero-Basic

【两万字原创】零基础学fastjson漏洞(基础篇),公众号:追梦信安

ja3

Go package for Ja3 TLS client and server hello fingerprints

Language:GoLicense:BSD-3-ClauseStargazers:144Issues:9Issues:11

poc_exp

暂停更新·······正在谋划······

Bypass_JVM_Verifier

Bypass JVM Class ByteCode Verifier , 对抗反编译器

Language:JavaStargazers:108Issues:2Issues:0

gopher-tomcat-deployer

Gopher Tomcat Deployer

Language:PythonLicense:MITStargazers:47Issues:1Issues:0

dnsconn

DNS Tunneling as net.Conn

Language:GoLicense:NOASSERTIONStargazers:16Issues:2Issues:3

gosecretsdump

Dump ntds.dit really fast

Language:GoLicense:GPL-3.0Stargazers:3Issues:0Issues:0