如何直接在 GitHub 仓库中追踪最新漏洞利用代码
了解如何使用 nomi-sec/PoC-in-GitHub 在 GitHub 仓库中追踪最新 PoC 漏洞利用代码,理解真实攻击向量,在关键漏洞面前抢先一步。
语言
首页语言
板块
渗透测试、密码学、网络安全,以及面向防御者和研究人员的工具。
了解如何使用 nomi-sec/PoC-in-GitHub 在 GitHub 仓库中追踪最新 PoC 漏洞利用代码,理解真实攻击向量,在关键漏洞面前抢先一步。
AI-Infra-Guard 是一个开源平台,用于保护 AI 服务和代理。它扫描 AI 基础设施中的 CVE、审计 MCP 服务器和代理技能,并测试 LLM 对越狱的抵抗能力。
Delegating Google Dorking to neural network agents: a look at DorkAgent, a tool that automates search queries using Serper API and LLMs.
Tool combines ARP scanning, Nmap, and passive traffic monitoring with an interactive topology map for network audits.
Krawl is a deception server that pretends to be a vulnerable web app, feeding scanners infinite trap pages and wasting their resources.
Open-source mcp-scanner audits MCP servers for hidden threats using YARA, LLM-as-judge, and Docker sandboxing.
AuthPass 为 KeePass 带来了全新的面貌,通过一个统一的 Flutter 客户端在 Android、iOS、macOS、Windows、Linux 和浏览器上运行——全部开源。
Google built Zanzibar for authorization at scale. Learn how SpiceDB, an open-source database inspired by it, handles permissions for billions of users.
Coldcard 固件完全开源。本文介绍代码库内部结构、可重现构建的工作原理,以及为什么值得在 PC 上运行模拟器。
了解 Nono——一款基于 Rust 的沙箱工具,无需容器即可隔离 AI Agent,保护 SSH 密钥和云凭证,同时保持终端性能流畅。
一款基于 MIT 许可证的开源 CCleaner 替代品,无需广告、遥测或高级订阅即可完成系统维护和清理。
Decepticon是一个自主红队代理,能够像真实渗透测试人员一样执行攻击链。它在XBOW基准测试中获得了98%的分数,并使用16个专业代理处理不同的攻击阶段。
了解如何使用 konstruktoid 的 Shell 脚本自动加固 Ubuntu 服务器,利用 systemd 隔离和 CIS 基准测试最大限度地减少攻击面。
作为安全研究人员的必备工具,NFCGate 是一款由 TU Darmstadt 研究人员开发的开源 Android 应用,可用于捕获、分析和转发 NFC 流量。
Andriller CE 是一款基于 Python 的安卓设备取证工具包,可提取数据、绕过锁屏密码,并分析应用备份(包括加密的 WhatsApp 数据库)。
Discover Ciphey, an automated decryption tool that identifies encryption types and decodes data in under 3 seconds using AI and NLP.
openSquat 是一个 Python OSINT 工具,用于检测钓鱼域名、typosquatting、IDN 攻击和相似域名,在攻击者使用前发现威胁。