Lists (16)
Sort Name ascending (A-Z)
APP
Android APP and miniAPPBypassAV/EDR
backdoor bypassC# & .Net
Trying to impersonate Java (just a joke)CloudAPP
云资产 集群设施IOT
Java
Jvav a kind of coffee beans.JS & Web Browser
JS逆向loader
加载器PHP
PHP is the best language in the world.Post-exploitation
Privilege Escalation, Lateral Movement, Maintaining Access, Covering TracksRE&Pwn
WebShell
新型、生成、免杀创意无极限
6大手子们
打点
Script Kiddie (bushi)靶场
Learning and trainingStarred repositories
Interesting APT Report Collection And Some Special IOC
BTrace - a safe, dynamic tracing tool for the Java platform
Get a job from Xuanwu Lab in 365 days
[WIP] 整理过去的分享,从零开始的Kubernetes攻防 🧐
Hack-a-Sat 4 2023 - Finals Public Release
Blackbox tool to disable SSL certificate validation - including certificate pinning - within iOS and macOS applications.
在线批量导出微信公众号文章,支持阅读量、评论数据的导出,支持内嵌的音视频导出,无需搭建任何环境,可100%还原文章样式,支持私有部署
Real - time non-invasive AOP framework container based on JVM
Generating legitimate call stack frame along with indirect syscalls by abusing Vectored Exception Handling (VEH) to bypass User-Land EDR hooks in Windows.
4个 .soap 版本的WebShell(持续更新维护),优点:可以运行于子目录,突破了过去只能运行于根目录的限制。4个脚本分别支持调用cmd.exe/哥斯拉/冰蝎/天蝎 客户端。
Hacking Windows through iTunes - Local Privilege Escalation 0-day
A tool for generating .NET serialized gadgets that can trigger .NET assembly load/execution when deserialized using BinaryFormatter from JS/VBS/VBA based scripts.
之前方便自己研究RASP原理和绕过时顺手写的,用于快速启动和重置RASP环境
MSDAT: Microsoft SQL Database Attacking Tool