Skip to content
View cn-panda's full-sized avatar

Block or report cn-panda

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Please don't include any personal information such as legal names or email addresses. Maximum 100 characters, markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse

Starred repositories

Showing results

Easy and fast file sharing from the command-line.

Go 15,434 1,544 Updated Feb 14, 2025

辅助甲方安全人员巡检网站资产,发现并分析API安全问题

Python 278 20 Updated Jan 20, 2025

Nemo是用来进行自动化信息收集的一个简单平台,通过集成常用的信息收集工具和技术,实现对内网及互联网资产信息的自动收集,提高隐患排查和渗透测试的工作效率。

JavaScript 1,757 252 Updated Dec 25, 2024

一款用于快速导出URL、Domain和IP的小工具

Go 229 14 Updated Sep 2, 2024

ScopeSentry-Cyberspace mapping, subdomain enumeration, port scanning, sensitive information discovery, vulnerability scanning, distributed nodes

Python 1,010 152 Updated Mar 8, 2025

A Java 8+ Jar & Android APK Reverse Engineering Suite (Decompiler, Editor, Debugger & More)

Java 14,893 1,168 Updated Mar 9, 2025

📦 Make security testing of K8s, Docker, and Containerd easier.

Go 4,101 564 Updated Mar 8, 2025

从流量包匹配敏感信息的工具-可用作bp、浏览器的下游代理。0感知、无卡顿,支持https。

Go 263 16 Updated Aug 25, 2024

ARL 资产侦察灯塔系统(可运行,添加指纹,提高并发,升级工具及系统,无限制修改版) | ARL(Asset Reconnaissance Lighthouse)资产侦察灯塔系统旨在快速侦察与目标关联的互联网资产,构建基础资产信息库。 协助甲方安全团队或者渗透测试人员有效侦察和检索资产,发现存在的薄弱点和攻击面。

Python 596 265 Updated Mar 11, 2025

Ghostscript command injection vulnerability PoC (CVE-2023-36664)

Python 115 18 Updated Sep 7, 2023

攻防演练过程中,我们通常会用浏览器访问一些资产,但很多未授权/敏感信息/越权隐匿在已访问接口过html、JS文件等,该插件能让我们发现未授权/敏感信息/越权/登陆接口等。

Java 1,116 68 Updated Oct 3, 2024

Nuclei POC,每日更新 | 自动整合全网Nuclei的漏洞POC,实时同步更新最新POC,保存已被删除的POC。通过批量克隆Github项目,获取Nuclei POC,并将POC按类别分类存放,使用Github Action实现(已有19w+POC,已校验有效性并去重)

Python 1,049 348 Updated Mar 11, 2025

An advanced, yet simple, tunneling/pivoting tool that uses a TUN interface.

Go 3,218 328 Updated Mar 3, 2025

Supershell C2 远控平台,基于反向SSH隧道获取完全交互式Shell

1,540 195 Updated Sep 26, 2023

.NET Decompiler with support for PDB generation, ReadyToRun, Metadata (&more) - cross-platform!

C# 22,462 3,430 Updated Mar 8, 2025

CLI tool for tracking dependents repositories and sorting result by Stars ⭐

Go 44 1 Updated Jan 25, 2024

云环境利用框架(Cloud exploitation framework)主要用来方便红队人员在获得 AK 的后续工作。

Go 276 607 Updated Apr 29, 2023

EZ是一款集信息收集、端口扫描、服务暴破、URL爬虫、指纹识别、被动扫描为一体的跨平台漏洞扫描器。

821 31 Updated Jan 17, 2025

自动整合全网Nuclei的漏洞POC,实时同步更新最新POC!

2,738 358 Updated Aug 23, 2024

Java web路由内存分析工具

Java 430 25 Updated Dec 4, 2024

Official repo for GPTFUZZER : Red Teaming Large Language Models with Auto-Generated Jailbreak Prompts

Python 457 60 Updated Sep 24, 2024

cloudgrep is grep for cloud storage

Python 324 16 Updated Feb 26, 2025

Standalone utility for service discovery on open ports!

Go 598 48 Updated Mar 4, 2025

这是一个用于IP和域名碰撞匹配访问的小工具,旨意用来匹配出渗透过程中需要绑定hosts才能访问的弱主机或内部系统。https://github.com/fofapro/Hosts_scan implement in Go

Go 113 14 Updated Aug 30, 2022

burp 插件 xia_Yue(瞎越) 主要用于测试越权、未授权

552 15 Updated Aug 27, 2024

Burp Extension for a passive scanning JS files for endpoint links.

Python 765 103 Updated Mar 22, 2024

Community curated list of templates for the nuclei engine to find security vulnerabilities.

JavaScript 9,788 2,746 Updated Mar 12, 2025

Log4j2 RCE Passive Scanner plugin for BurpSuite

Java 792 95 Updated Aug 4, 2023
Next
Showing results