Modlishka. Reverse Proxy.
翻译 - Modlishka。反向代理。
📦 Make security testing of K8s, Docker, and Containerd easier.
翻译 - CDK是一个开放源代码的容器渗透工具包,可在不依赖任何操作系统的情况下,在不同的瘦容器中进行稳定利用。它带有有用的网络工具,许多强大的PoC / EXP可帮助您轻松逃脱容器并接管K8s集群。
Villain is a high level stage 0/1 C2 framework that can handle multiple reverse TCP & HoaxShell-based shells, enhance their functionality with additional features (commands, utilities) and share them ...
Automating situational awareness for cloud penetration tests.
SSH based reverse shell
An HTTP/HTTPS intercept proxy written in Go.
翻译 - 用Go编写的HTTP / HTTPS拦截代理。
Automatic SSTI detection tool with interactive interface
Statically-linked ssh server with reverse shell functionality for CTFs and such
翻译 - 静态链接的 ssh 服务器,具有 CTF 等的反向 shell 功能
Web Cache Vulnerability Scanner is a Go-based CLI tool for testing for web cache poisoning. It is developed by Hackmanit GmbH (
翻译 - Web Cache Vulnerability Scanner 是一个基于 Go 的 CLI 工具,用于测试 Web 缓存中毒。它由 Hackmanit GmbH ( 开发。
Dangerously fast DNS/network/port scanner
Dude Suite Web Security Tools
JustTryHarder, a cheat sheet which will aid you through the PWK course & the OSCP Exam. (Inspired by PayloadAllTheThings)
An automation tool that scans sub-domains, sub-domain takeover, then filters out XSS, SSTI, SSRF, and more injection point parameters and scans for some low hanging vulnerabilities automatically.
Spoofy is a program that checks if a list of domains can be spoofed based on SPF and DMARC records.
A rapid API for the Project Sonar dataset
A command-line utility designed to discover URLs for a given domain in a simple, efficient way. It works by gathering information from a variety of passive sources, meaning it doesn't interact directl...
A repository of tools for pentesting of restricted and isolated environments.