1.应急响应
GScan
https://github.com/grayddq/GScan
应急响应实战笔记
https://github.com/Bypass007/Emergency-Response-Notes
2.目录字典
fuzzDicts
https://github.com/TheKingOfDuck/fuzzDicts
Web-Fuzzing-Box
https://github.com/gh0stkey/Web-Fuzzing-Box
3.扫描工具
nuclei
https://github.com/projectdiscovery/nuclei
subfinder
https://github.com/projectdiscovery/subfinder
httpx
https://github.com/projectdiscovery/httpx
gobuster
https://github.com/OJ/gobuster
dirsearch
https://github.com/maurosoria/dirsearch
4.poc/payload
PayloadsAllTheThings
https://github.com/swisskyrepo/PayloadsAllTheThings
nuclei-templates
https://github.com/projectdiscovery/nuclei-templates
5.开源类防御产品
SafeLine
https://github.com/chaitin/SafeLine
jumpserver
https://github.com/jumpserver/jumpserver
6.绕过某些策略
Linux
Windows
https://lolbas-project.github.io/
7.DNSLOG平台
callback.red
https://sec.lintstar.top/Dnslog.html
dnslog