常用工具及网站(武器库)

其他收录平台或项目传送门:
开源扫描器收录地址:https://github.com/We5ter/Scanners-Box
T00ls论坛收集工具集 https://github.com/tengzhangchao/Sec-Box
渗透师导航:https://www.shentoushi.top/
信息收集工具集:https://github.com/redhuntlabs/Awesome-Asset-Discovery
K8工具集: https://github.com/k8gege/K8tools
APP测试:https://github.com/Brucetg/App_Security
红队资源链接合集(干货超多):https://github.com/hudunkey/Red-Team-links
红队实用工具 :https://github.com/Threekiii/Awesome-Redteam 另一个工具+EXP合集:https://github.com/Mr-xn/Penetration_Testing_POC/

以下为个人整理收集

杂项

  • java 无文件webshell:https://github.com/rebeyond/memShell
  • 瑞士军刀Bettercap:https://github.com/bettercap/bettercap
  • XSS批量扫描,源自先知:https://github.com/bsmali4/xssfork
  • 个人收集编写的POC:
  1. 跨站数据劫持POC https://github.com/nccgroup/CrossSiteContentHijacking
  2. 自动化测试工具,POC在script路径下 https://github.com/Xyntax/POC-T/tree/master
  • 收集各种语言的webshell:https://github.com/tennc/webshell
  • XXE注入工具 Ruby编写:https://github.com/enjoiz/XXEinjector
  • xxe 测试工具:https://github.com/TheTwitchy/xxer
  • burp AES加密插件:https://github.com/Ebryx/AES-Killer
  • XXE payload生成:https://github.com/BuffaloWill/oxml_xxe/
  • Nginx 路径穿越burp测试插件:https://github.com/bayotop/off-by-slash
  • 红队自动化部署:https://github.com/360-A-Team/LuWu
  • JS反混淆:https://github.com/mindedsecurity/JStillery

一些比较有用的burp插件

自动化扫描

  • SN1PER(功能:扫描开放端口、waf、指纹识别、目录扫描):https://github.com/1N3/Sn1per
  • web页面直接调用工具(dirsearch、masscan、amass、patator)扫描:https://github.com/c0rvax/project-black
  • 自动化扫描网站的CORS配置的漏洞:https://github.com/chenjj/CORScanner
  • 长亭X-ray漏洞扫描器:https://github.com/chaitin/xray/
  • 美杜莎漏扫:https://github.com/Ascotbe/Medusa
  • w13scan:https://github.com/w-digital-scanner/w13scan
  • 利用github action 进行自动化扫描:https://github.com/inbug-team/InCloud
  • 集成了fofa、漏洞扫描、web指纹等多个扫描功能(也可在内网扫):https://github.com/P1-Team/AlliN

应急响应

勒索病毒解密查询:

字典payload、fuzz

信息收集

  • 在线协作markdown,可用于团队内部信息共享(可在离线环境搭建):https://github.com/hackmdio/codimd
  • FOFA浏览器插件:https://github.com/fofapro/fofa_view
  • WAF指纹识别及Bypass https://github.com/Ekultek/WhatWaf
  • 带截图go语言脚本扫描端口: https://github.com/michenriksen/aquatone
  • wfuzz:https://github.com/xmendez/wfuzz
  • 可用于host头碰撞或者各种fuzz:https://github.com/ffuf/ffuf
  • host头碰撞:https://github.com/fofapro/Hosts_scan
  • .git、.svn和.DS_Store利用:https://github.com/0xHJK/dumpall
  • 指纹识别(很多扫描工具都集成了,不列举了):
  • 目录扫描工具:
  • 端口扫描:
    • RustScan(可以配置自动调用nmap):https://github.com/RustScan/RustScan
  • 接口扫描:
  • 子域名收集:
    • 基于企业备案信息查询:https://github.com/canc3s/cDomain
    • 根据SSL证书收集子域名:https://github.com/yassineaboukir/sublert
    • python脚本+mangodb实时监控:https://github.com/guimaizi/get_domain
    • 可发现二级、三级子域名:https://github.com/infosec-au/altdns
    • asyncio+aiodns大字典暴破子域名 https://github.com/ldbfpiaoran/subdns
    • 基于Python3.8,可以通过多种API来获取并验证子域名: https://github.com/shmilylty/OneForAll
  • 浏览器插件:

WAF绕过

  • MYSQL_SQL注入: https://github.com/aleenzz/MYSQL_SQL_BYPASS_WIKI
  • waf指纹字典及绕过方式:https://github.com/0xInfection/Awesome-WAF
  • waf识别脚本:https://github.com/stamparm/identYwaf
  • 自动化绕WAF:https://github.com/khalilbijjou/WAFNinja
  • 绕过瑞数反爬:https://github.com/R0A1NG/Botgate_bypass
  • 一个基于fuzz的waf绕过测试工具:https://github.com/leveryd/x-waf

提权

  1. Windows
  1. Linux

后渗透

解密

  • 针对获取权限后各种加密数据进行解密,包括oa等:https://github.com/wafinfo/DecryptTools
  • 用友nc数据库解密:https://github.com/jas502n/ncDecode

数据库利用

内网渗透

1. 杂项

2. 内网隧道:

golang实现的支持多种场合的隧道代理工具:https://github.com/ginuerzh/gost

  1. http隧道:
  • 加密流量版的reGeorg,原生的regeorg已经能够被设备识别了:https://github.com/L-codes/Neo-reGeorg
  • node.js版的内网流量转发:https://github.com/johncant/node-http-tunnel
  • https://github.com/blackarrowsec/pivotnacci
  • 不出网上线cs:https://github.com/FunnyWolf/pystinger
  • 高性能的http代理,可植入内存马使用:https://github.com/zema1/suo5
  1. socks隧道
  • frp内网流量转发,支持tcp、udp,不支持正向:https://github.com/fatedier/frp
  • rust编写的类frp内网穿透工具:https://github.com/rapiz1/rathole
  • EarthWorm开启Socks5代理:https://github.com/idlefire/ew
  • 带Meterpreter的HTTP加密通道流量转发:https://github.com/nccgroup/ABPTTS
  • nps内网穿透:https://github.com/ehang-io/nps (nps使用教程
  • 端口转发:https://github.com/EddieIvan01/iox
  • 正向socks代理,支持设置用户名和密码:https://github.com/jqqjj/socks5
  • 多级代理(frp也支持多级代理):
  1. mssqlproxy:https://github.com/blackarrowsec/mssqlproxy
  2. pingtunnel:https://github.com/esrrhs/pingtunnel

3. 内网信息收集:

4. 免杀相关

  • powershell混淆:https://github.com/danielbohannon/Invoke-Obfuscation
  • 掩日:https://github.com/1y0n/AV_Evasion_Tool
  • https://github.com/Hangingsword/HouQing
  • 搭配cs4.1新出的bof实现内存执行PE:https://github.com/phra/PEzor
  • windows api添加用户:https://github.com/lengjibo/NetUser

5. 域渗透

基础学习

工具利用

6. 横向

  • 批量HASH传递:https://github.com/Kevin-Robertson/Invoke-TheHash
  • impacket横向(集成在examles中):https://github.com/SecureAuthCorp/impacket
  • impacket-binary(可执行文件):https://github.com/ropnop/impacket_static_binaries/releases/
  • vcenter后利用:https://github.com/horizon3ai/vcenter_saml_login

7. cs相关

部分CVE POC

云安全

Java 安全

中间件/组件Exp

Java安全学习

Java安全防护

  • 阿里巴巴安全SDK:https://github.com/alibaba/seckit

代码审计/开发工具

钓鱼

shell管理(c2)

  • 蚁剑:https://github.com/AntSwordProject/antSword
  • 冰蝎:https://github.com/rebeyond/Behinder
  • 哥斯拉(支持jsp和reGeorg内存版):https://github.com/BeichenDream/Godzilla
  • 天蝎(不再对外更新):https://github.com/shack2/skyscorpion
  • 反弹shell管理,可上传文件、建立隧道:https://github.com/WangYihang/Platypus
  • supershell:https://github.com/tdragon6/Supershell

APP 测试

资产扫描/收集

渗透辅助平台/工具

  1. https://github.com/firesunCN/BlueLotus_XSSReceiver (原项目代码已撤销,可点击fork查看其他人保存的源码)
  2. https://github.com/mandatoryprogrammer/xsshunter
  3. https://github.com/78778443/xssplatform
  • tp漏洞扫描:https://github.com/Lotus6/ThinkphpGUI
  • 自动化SSRF测试:https://github.com/swisskyrepo/SSRFmap
  • 验证码AI训练识别:https://github.com/kerlomz/captcha_trainer
  • flash xss 测试:https://github.com/cure53/flashbang
  • JWT token破解:https://github.com/brendan-rius/c-jwt-cracker
  • 自动化扫描JS中的API: https://github.com/rtcatc/Packer-Fuzzer
  • 子域名接管指纹:https://github.com/EdOverflow/can-i-take-over-xyz
  • 火眼公司windows测试虚拟机:https://github.com/fireeye/commando-vm

甲方安全

  • 漏洞信息推送:https://github.com/zema1/watchvuln
  • 巡风漏洞扫描器:https://github.com/ysrc/xunfeng
  • 宜信洞察:https://github.com/creditease-sec/insight2
  • 陌陌风控:https://github.com/momosecurity/aswan
  • HIDS:https://github.com/ossec/ossec-hids
  • 以Nginx为核心高性能服务器Openresty:https://github.com/openresty/openresty
  • Nginx安全配置检查:https://github.com/yandex/gixy
  • github监控工具:
  • 开源蜜罐合集:https://github.com/paralax/awesome-honeypots

其他知识整理

一些师傅的博客