Skip to content
View ikbs's full-sized avatar

Block or report ikbs

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Please don't include any personal information such as legal names or email addresses. Maximum 100 characters, markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Beta Lists are currently in beta. Share feedback and report bugs.
Showing results

给woodpecker框架量身定制的ysoserial

Java 511 71 Updated Oct 26, 2022

Terminal session recorder 📹

Rust 14,004 906 Updated Sep 20, 2024

红队 C2 框架,使用 No X Loader 技术。Red Team C2 Framework, using No X Loader technology.

C++ 257 54 Updated Sep 13, 2024

Java安全相关的漏洞和技术demo,原生Java、Fastjson、Jackson、Hessian2、XML反序列化漏洞利用和Spring、Dubbo、Shiro、CAS、Tomcat、RMI、Nexus等框架\中间件\功能的exploits以及Java Security Manager绕过、Dubbo-Hessian2安全加固等等实践代码。

Java 2,591 495 Updated Mar 14, 2024

一款轻量级匹配Sink点的代码审计扫描器,为了帮助红队过程中快速代码审计的小工具

Go 144 11 Updated Sep 29, 2024

CodeQLpy是一款基于CodeQL实现的半自动化代码审计工具,目前仅支持java语言。实现从源码反编译,数据库生成,脆弱性发现的全过程,可以辅助代码审计人员快速定位源码可能存在的漏洞。

CodeQL 740 83 Updated Jul 6, 2023

Getting started with java code auditing 代码审计入门的小项目

JavaScript 889 120 Updated Feb 22, 2023

Java web common vulnerabilities and security code which is base on springboot and spring security

Java 2,380 636 Updated Sep 13, 2024

☕️ Java Security,安全编码和代码审计

Java 1,297 208 Updated Oct 18, 2023

从流量包匹配敏感信息的工具-可用作bp、浏览器的下游代理。0感知、无卡顿,支持https。

Go 216 11 Updated Aug 25, 2024

Exchange 信息收集工具

37 1 Updated Sep 21, 2024

burp插件开发指南

Java 591 98 Updated Aug 8, 2021

DuckDB is an analytical in-process SQL database management system

C++ 23,150 1,844 Updated Oct 2, 2024
C++ 787 206 Updated Dec 28, 2019

ZKar is a Java serialization protocol analysis tool implement in Go.

Go 596 52 Updated Aug 5, 2024

《APT Individual Combat Guide》

C++ 137 20 Updated Sep 26, 2024

Windows process injection methods

C 126 20 Updated Feb 2, 2023

A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.

Java 7,678 1,750 Updated Mar 31, 2024

蓝队分析研判工具箱,功能包括内存马反编译分析、各种代码格式化、网空资产测绘功能、溯源辅助、解密冰蝎流量、解密哥斯拉流量、解密Shiro/CAS/Log4j2的攻击payload、IP/端口连接分析、各种编码/解码功能、蓝队分析常用网址、java反序列化数据包分析、Java类名搜索、Fofa搜索、Hunter搜索等。

1,066 81 Updated Aug 26, 2024

《PHP代码审计入门指南》 这本指南包含了我在学习PHP代码审计过程中整理出的一些技巧和对漏洞的一些理解

316 27 Updated Apr 8, 2022

dirsx 是一款能够自动化过滤扫描结果的目录扫描工具

Go 60 3 Updated Sep 10, 2024

Java层frida hook学习笔记 https://uknowsec.cn

46 7 Updated Feb 6, 2020

个人域渗透学习笔记

1,720 357 Updated Feb 7, 2020

DomainFronting(aliyun)远程加载shellcode,远程获取shellcode使用aes动态加密传输数据

C++ 47 12 Updated Aug 26, 2020

修改frp支持域前置与配置文件自删除

390 81 Updated Dec 31, 2020

创建服务持久化

C++ 104 27 Updated Apr 26, 2021

键盘记录,支持定时回传

Go 132 35 Updated May 19, 2021

State-of-the-art native debugging tools

C 2,858 374 Updated Oct 2, 2024
Next