Starred repositories
爬网站JS文件,自动fuzz api接口,指定api接口(针对前后端分离项目,可指定后端接口地址),回显api响应
一款基于各大企业信息API的工具,解决在遇到的各种针对国内企业信息收集难题。一键收集控股公司ICP备案、APP、小程序、微信公众号等信息聚合导出。
🧿 AutorizePro是一款强大越权检测 Burp 插件,通过增加 AI 辅助分析 && 进一步优化检测逻辑,大幅降低误报率,提升越权漏洞检出效率。 [ AutorizePro is a authorization enforcement detection extension for burp suite. By adding Ai-assisted analysis, it sign…
Automatic authorization enforcement detection extension for burp suite written in Jython developed by Barak Tawily in order to ease application security people work and allow them perform an automa…
SBSCAN是一款专注于spring框架的渗透测试工具,可以对指定站点进行springboot未授权扫描/敏感信息扫描以及进行spring框架漏洞扫描与验证的综合利用工具。 [SBSCAN is a penetration testing tool focused on the spring framework that can scan springboot sensitive infor…
A curated list of resources dedicated to open source GitHub repositories related to ChatGPT
sule01u / SysEnhance
Forked from xiaoyunjie/Shell_ScriptSystemEnhance是一款Linux系统安全基线检测&&Linux系统安全基线配置的工具。 SystemEnhance is a tool for system security baseline detection of Linux system && Linux system security baseline configuration.
Official repo for GPTFUZZER : Red Teaming Large Language Models with Auto-Generated Jailbreak Prompts
Bandit is a tool designed to find common security issues in Python code.
Kubernetes Security Training Platform - focusing on security mitigation
KCon is a famous Hacker Con powered by Knownsec Team.
A list of useful payloads and bypass for Web Application Security and Pentest/CTF
ysoserial修改版,着重修改ysoserial.payloads.util.Gadgets.createTemplatesImpl使其可以通过引入自定义class的形式来执行命令、内存马、反序列化回显。
A curated list of Awesome Threat Intelligence resources
悟空无代码平台正式开源,通过悟空无代码平台开发工具,企业可自主地快速开发出适合企业需要的信息化系统,开发过程只需要业务人员参与,开发效率极高,维护性很强。
A curated list of GPT agents for cybersecurity
What I do is generate dart beans based on json, as well as generics parameters and json build instances