- All languages
- ASP
- Assembly
- AutoIt
- Batchfile
- BlitzBasic
- C
- C#
- C++
- CSS
- Classic ASP
- CodeQL
- Dockerfile
- Go
- HTML
- Hack
- Haskell
- Java
- JavaScript
- Jupyter Notebook
- Kotlin
- Lua
- MATLAB
- Makefile
- Markdown
- Mask
- Max
- Nim
- OCaml
- PHP
- POV-Ray SDL
- Pascal
- Perl
- PowerShell
- Python
- Ruby
- Rust
- SCSS
- Scala
- Shell
- Smarty
- Solidity
- TeX
- TypeScript
- VBScript
- Vim Script
- Vue
- WebAssembly
- XSLT
- YARA
Starred repositories
WTF Solidity 极简入门教程,供小白们使用。Now supports English! 官网: https://wtf.academy
Web3 CTF Intensive CoLearning
Unlock the Power of Web3: Hack the Future! Restart the Universe!!!
Extract URLs, paths, secrets, and other interesting bits from JavaScript
Our main goal is to share tips from some well-known bughunters. Using recon methodology, we are able to find subdomains, apis, and tokens that are already exploitable, so we can report them. We wis…
A curated list of awesome LLM agents frameworks.
GBounty is a multi-step website vulnerability scanner developed in Golang designed to help companies, pentesters, and bug hunters identify potential vulnerabilities in web applications.
xia Liao(瞎料)burp插件 用于Windows在线进程/杀软识别 与 web渗透注册时,快速生成需要的资料用来填写,资料包含:姓名、手机号、身份证、统一社会信用代码、组织机构代码、银行卡,以及各类web语言的hello world输出和生成弱口令字典等。
LLM notes, including model inference, transformer model structure, and llm framework code analysis notes.
用Go+Fyne开发的,展示JAVA序列化流以及集成一键插入脏数据,UTF过长编码绕WAF(Utf OverLoad Encoding),修改类SerializeVersionUID功能的图形化工具。
vulhub Vulnerability Reproduction Designated Platform
Jar Analyzer - 一个JAR包分析工具,批量分析,SCA漏洞分析,方法调用关系搜索,字符串搜索,Spring组件分析,信息泄露检查,CFG程序分析,JVM栈帧分析,进阶表达式搜索,字节码指令级的动态调试分析,反编译JAR包一键导出,一键提取序列化数据恶意代码,一键分析BCEL字节码
🛡️ Awesome Cloud Security Resources ⚔️
A curated list for Awesome Kubernetes Security resources
AV/EDR Lab environment setup references to help in Malware development
GTFOBins is a curated list of Unix binaries that can be used to bypass local security restrictions in misconfigured systems
Puredns is a fast domain resolver and subdomain bruteforcing tool that can accurately filter out wildcard subdomains and DNS poisoned entries.
Anything about kernel security. CTF kernel pwn, kernel exploit, kernel fuzz and kernel defense paper, kernel debugging technique, kernel CVE debug.
前端加密对抗练习靶场,包含非对称加密、对称加密、加签以及禁止重放的测试场景,比如AES、DES、RSA,用于渗透测试练习
A guide that explains how programs transform from source code to executables. Deep dive into ELF format, linking processes, and binary optimization techniques. Perfect for systems programmers, C de…
Active Directory data ingestor for BloodHound Community Edition written in Rust. 🦀
(持续更新)对网上出现的各种OA、中间件、CMS等漏洞进行整理,主要包括漏洞介绍、漏洞影响版本以及漏洞POC/EXP等,并且会持续更新。