In-depth attack surface mapping and asset discovery
弱口令检测、 漏洞扫描、端口扫描(协议识别,组件识别)、web目录扫描、等保模拟定级、自动化运维、等保工具(网络安全等级保护现场测评工具)内置3级等保核查命令、基线核查工具、键盘记录器
sqlmap Xplus 基于 sqlmap,对经典的数据库注入漏洞利用工具进行二开!
httpx is a fast and multi-purpose HTTP toolkit that allows running multiple probes using the retryablehttp library.
Fast passive subdomain enumeration tool.
An incredibly fast proxy checker & IP rotator with ease.
World's fastest and most advanced password recovery utility
Impacket is a collection of Python classes for working with network protocols.
Extract and decrypt browser data, supporting multiple data types, runnable on various operating systems (macOS, Windows, Linux).
ARL官方仓库备份项目:ARL(Asset Reconnaissance Lighthouse)资产侦察灯塔系统旨在快速侦察与目标关联的互联网资产,构建基础资产信息库。 协助甲方安全团队或者渗透测试人员有效侦察和检索资产,发现存在的薄弱点和攻击面。
Chisel: A Modern Hardware Design Language
Pingtunnel is a tool that send TCP/UDP traffic over ICMP
A list of useful payloads and bypass for Web Application Security and Pentest/CTF
SecLists is the security tester's companion. It's a collection of multiple types of lists used during security assessments, collected in one place. List types include usernames, passwords, URLs, se…