More Tools
Timu ya Bluu
https://github.com/PaperMtn/lil-pwny : Angalia akaunti zilizofichuliwa
OSINT
https://www.nmmapper.com/sys/tools/subdomainfinder/ : Zana 8 za kutafuta Subdomain, sublist3r, amass na zingine
WEB
https://github.com/blark/aiodnsbrute : Kuvunja jina la uwanja kwa njia isiyo ya kawaida
https://crt.sh/?q=%.yahoo.com : Kuvunja Subdomain
https://github.com/tomnomnom/httprobe: Angalia ikiwa seva za wavuti katika kikoa zinapatikana
https://github.com/aboul3la/Sublist3r : Ugunduzi wa Subdomain
https://github.com/gwen001/github-search/blob/master/github-subdomains.py : Ugunduzi wa Subdomain kwenye github
https://github.com/robertdavidgraham/masscan : Uchunguzi wa haraka wa bandari
https://github.com/Threezh1/JSFinder : Subdomains na URLs kutoka kwenye faili za JS kwenye wavuti
https://github.com/C1h2e1/MyFuzzingDict : Kamusi ya faili za Wavuti
https://github.com/TypeError/Bookmarks/blob/master/README.md : BurpExtension kuepuka vichupo vingi vya repeater
https://github.com/hakluke/hakrawler : Pata mali
https://github.com/izo30/google-dorker : Google dorks
https://github.com/sehno/Bug-bounty/blob/master/bugbounty_checklist.md : Orodha ya BugBounty ya Wavuti
https://github.com/Naategh/dom-red : Angalia orodha ya kikoa dhidi ya Uelekezaji wa Wazi
https://github.com/prodigysml/Dr.-Watson : Programu-jalizi ya Burp, uchambuzi wa nje ili kugundua vikoa, subdomains na IPs
https://github.com/hahwul/WebHackersWeapons: Orodha ya zana tofauti
https://github.com/gauravnarwani97/Trishul : Programu-jalizi ya BurpSuite kutafuta udhaifu (SQLi, XSS, SSTI)
https://github.com/fransr/postMessage-tracker : Kifaa cha Chrome cha kufuatilia kazi za ujumbe wa baada
https://github.com/Quitten/Autorize : Vipimo vya uthibitishaji wa moja kwa moja (ondoa vidakuzi na jaribu kutuma ombi)
https://github.com/pikpikcu/xrcross: XRCross ni Zana ya Ujenzi, Scanner, na zana ya uchunguzi wa uingiliaji / jaribio la BugBounty. Zana hii ilijengwa kwa ajili ya kujaribu (XSS|SSRF|CORS|SSTI|IDOR|RCE|LFI|SQLI) vulnerabilities
Windows
https://github.com/Mr-Un1k0d3r/PoisonHandler : Harakati za upande
https://freddiebarrsmith.com/trix/trix.html : LOL bins
https://github.com/odzhan/injection : Mbinu za Kuingiza Mchakato wa Windows
https://github.com/BankSecurity/Red_Team : Skripti za Timu Nyekundu
https://github.com/l0ss/Grouper2 : pata upangishaji wa usalama katika Sera ya Kikundi cha Active Directory.
https://www.wietzebeukema.nl/blog/powershell-obfuscation-using-securestring : Ufichaji wa Securestring
https://pentestlab.blog/2020/02/24/parent-pid-spoofing/ : Udukuzi wa PID ya Wazazi
https://github.com/the-xentropy/xencrypt : Ficha Malipo ya Powershell
https://windows-internals.com/faxing-your-way-to-system/ : Mfululizo wa magogo kuhusu Windows Internals
https://bestestredteam.com/2018/10/02/tracking-pixel-in-microsoft-office-document/ : Fuatilia nani amefungua hati
https://github.com/Integration-IT/Active-Directory-Exploitation-Cheat-Sheet : Karatasi ya Kudanganya ya Udukuzi wa Active Directory
Firmware
Zana ambazo ninaona zinaweza kuwa nzuri kwa uchambuzi wa firmware (za moja kwa moja):
Baada ya kumaliza:
Jinsi ya kutoa firmware ikiwa hatuipati mtandaoni: https://www.youtube.com/watch?v=Kxvpbu9STU4
Hapa kuna firmware na mapungufu ya usalama ya kuchambua: https://github.com/scriptingxss/IoTGoat
na hapa kuna metodolojia ya owasp ya kuchambua firmware: https://github.com/scriptingxss/owasp-fstm
Uigaji wa Firmware: FIRMADYNE (https://github.com/firmadyne/firmadyne/) ni jukwaa la kiotomatiki la uigaji na uchambuzi wa kina wa firmware za Linux.
NYINGINE
https://github.com/CoatiSoftware/Sourcetrail : Uchambuzi wa Kanuni za Statis
https://github.com/skeeto/endlessh : Tarpit ya SSH ambayo inatuma bango lisiloisha polepole.
Zana za AWS na Cloud: https://github.com/toniblyx/my-arsenal-of-aws-security-tools
IFS (Interplanetary File System) kwa ajili ya kudanganya: https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/using-the-interplanetary-file-system-for-offensive-operations/
Huduma za mzunguko wa IP: https://medium.com/@lokeshdlk77/how-to-rotate-ip-address-in-brute-force-attack-e66407259212
Rootkit ya Linux: https://github.com/aesophor/satanic-rootkit
https://theia-ide.org/ : IDE mtandaoni
https://github.com/nahamsec/Resources-for-Beginner-Bug-Bounty-Hunters/ : Rasilimali za kuanza BugBounties
https://github.com/ElevenPaths/HomePWN : Udukuzi wa IoT (Wifi, BLE, SSDP, MDNS)
https://github.com/rackerlabs/scantron : uchunguzi wa kiotomatiki
https://github.com/doyensec/awesome-electronjs-hacking : Orodha hii inalenga kufunika mada zinazohusiana na usalama wa Electron.js.
https://github.com/serain/bbrecon : Habari kuhusu mipango ya BB
Last updated