子域名枚舉類
https://github.com/lijiejie/subDomainsBrute(經(jīng)典的子域名爆破枚舉腳本)
https://github.com/ring04h/wydomain(子域名字典窮舉)
https://github.com/le4f/dnsmaper(子域名枚舉與地圖標(biāo)記)
https://github.com/0xbug/orangescan(在線子域名信息收集工具)
https://github.com/TheRook/subbrute(根據(jù)DNS記錄查詢子域名)
https://github.com/We5ter/GoogleSSLdomainFinder(基于谷歌SSL透明證書的子域名查詢腳本)
https://github.com/0xbug/SQLiScanner(一款基于SQLMAP和Charles的被動(dòng)SQL注入漏洞掃描工具)
https://github.com/stamparm/DSSS(99行代碼實(shí)現(xiàn)的sql注入漏洞掃描器)
https://github.com/LoRexxar/Feigong(針對(duì)各種情況自由變化的MySQL注入腳本)
https://github.com/lijiejie/htpwdScan(一個(gè)簡(jiǎn)單的HTTP暴力破解、撞庫攻擊腳本)
https://github.com/lijiejie/BBScan(一個(gè)迷你的信息泄漏批量掃描腳本)
https://github.com/lijiejie/GitHack(.git文件夾泄漏利用工具)
https://github.com/wilson9x1/fenghuangscanner_v3(端口及弱口令檢測(cè))
https://github.com/ysrc/F-Scrack(對(duì)各類服務(wù)進(jìn)行弱口令檢測(cè)的腳本)
https://github.com/shawarkhanethicalhacker/BruteXSS(Cross-Site Scripting Bruteforcer)
https://github.com/1N3/XSSTracer(A small python script to check for Cross-Site Tracing)
https://github.com/0x584A/fuzzXssPHP(PHP版本的反射型xss掃描)
https://github.com/chuhades/xss_scan(批量掃描xss的python腳本)
https://github.com/sowish/LNScan(詳細(xì)的內(nèi)部網(wǎng)絡(luò)信息掃描器)
https://github.com/SkyLined/LocalNetworkScanner(javascript實(shí)現(xiàn)的本地網(wǎng)絡(luò)掃描器)
https://github.com/ysrc/xunfeng(網(wǎng)絡(luò)資產(chǎn)識(shí)別引擎,漏洞檢測(cè)引擎)
https://github.com/laramies/theHarvester(企業(yè)被搜索引擎收錄敏感資產(chǎn)信息監(jiān)控腳本:?jiǎn)T工郵箱谅摄、子域名商虐、Hosts)
https://github.com/x0day/Multisearch-v2(bing望忆、google浅妆、360变秦、zoomeye等搜索引擎聚合搜索,可用于發(fā)現(xiàn)企業(yè)被搜索引擎收錄的敏感資產(chǎn)信息)
https://github.com/We5ter/Scanners-Box/tree/master/Find_webshell/(php后門檢測(cè)席爽,腳本較簡(jiǎn)單意荤,因此存在誤報(bào)高和效率低下的問題)
https://github.com/yassineaddi/BackdoorMan(A toolkit find malicious, hidden and suspicious PHP scripts and shells in a chosen destination)
https://github.com/0xwindows/VulScritp(企業(yè)內(nèi)網(wǎng)滲透腳本,包括banner掃描只锻、端口掃描玖像;phpmyadmin、jenkins等通用漏洞利用等)
https://github.com/ring04h/wyportmap(目標(biāo)端口掃描+系統(tǒng)服務(wù)指紋識(shí)別)
https://github.com/ring04h/weakfilescan(動(dòng)態(tài)多線程敏感信息泄露檢測(cè)工具)
https://github.com/EnableSecurity/wafw00f(WAF產(chǎn)品指紋識(shí)別)
https://github.com/rbsec/sslscan(ssl類型識(shí)別)
https://github.com/urbanadventurer/whatweb(web指紋識(shí)別)
https://github.com/tanjiti/FingerPrint(web應(yīng)用指紋識(shí)別)
https://github.com/nanshihui/Scan-T(網(wǎng)絡(luò)爬蟲式指紋識(shí)別)
https://github.com/OffensivePython/Nscan(a fast Network scanner inspired by Masscan and Zmap)
https://github.com/ywolf/F-NAScan(網(wǎng)絡(luò)資產(chǎn)信息掃描, ICMP存活探測(cè),端口掃描捐寥,端口指紋服務(wù)識(shí)別)
https://github.com/ywolf/F-MiddlewareScan(中間件掃描)
https://github.com/maurosoria/dirsearch(Web path scanner)
https://github.com/x0day/bannerscan(C段Banner與路徑掃描)
https://github.com/RASSec/RASscan(端口服務(wù)掃描)
https://github.com/3xp10it/bypass_waf(waf自動(dòng)暴破)
https://github.com/blackye/Jenkins(Jenkins漏洞探測(cè)、用戶抓取爆破)
https://github.com/code-scan/dzscan(discuz掃描)
https://github.com/chuhades/CMS-Exploit-Framework(CMS攻擊框架)
https://github.com/lijiejie/IIS_shortname_Scanner(an IIS shortname Scanner)
https://github.com/We5ter/Scanners-Box/tree/master/FlashScanner.pl(flashxss掃描)
https://github.com/coffeehb/SSTIF(一個(gè)Fuzzing服務(wù)器端模板注入漏洞的半自動(dòng)化工具)
https://github.com/az0ne/AZScanner(自動(dòng)漏洞掃描器祖驱,子域名爆破握恳,端口掃描,目錄爆破捺僻,常用框架漏洞檢測(cè))
https://github.com/blackye/lalascan(自主開發(fā)的分布式web漏洞掃描框架乡洼,集合owasp top10漏洞掃描和邊界資產(chǎn)發(fā)現(xiàn)能力)
https://github.com/blackye/BkScanner(BkScanner 分布式、插件化web漏洞掃描器)
https://github.com/ysrc/GourdScanV2(被動(dòng)式漏洞掃描)
https://github.com/alpha1e0/pentestdb(WEB滲透測(cè)試數(shù)據(jù)庫)
https://github.com/netxfly/passive_scan(基于http代理的web漏洞掃描器)
https://github.com/1N3/Sn1per(自動(dòng)化掃描器匕坯,包括中間件掃描以及設(shè)備指紋識(shí)別)
https://github.com/RASSec/pentestEr_Fully-automatic-scanner(定向全自動(dòng)化滲透測(cè)試工具)
https://github.com/3xp10it/3xp10it(自動(dòng)化滲透測(cè)試框架)