2018 黑帽大會 工具清單


AndroidiOS和移動黑客

 

易受攻擊的iOS應用程序:Swift

 

https://github.com/prateek147/DVIA-v2

 

 

代碼評估

 

OWASP依賴性檢查

 

https://github.com/jeremylong/DependencyCheck

 

美洲獅掃描

 

https://github.com/pumasecurity/puma-scan

 

加密

 

DeepVioletSSL / TLS掃描API和工具

 

https://github.com/spoofzu/DeepViolet

 

數據取證和事件響應

 

初學者到專家

 

https://github.com/bro/bro

 

CyBot:開源威脅情報聊天機器人

 

https://github.com/CylanceSPEAR/CyBot

 

LogonTracer

 

https://github.com/JPCERTCC/LogonTracer

 

rastrea2r(重新加載!):用GustoStyle收集和狩獵IOC

https://github.com/rastrea2r/rastrea2r

 

RedHunt OSVM):用於對手仿真和威脅搜索的虛擬機

https://github.com/redhuntlabs/RedHunt-OS

 

剝削與道德黑客

AVETAntiVirus Evasion Tool

 

https://github.com/govolution/avet

 

DSPDocker安全游樂場

https://github.com/giper45/DockerSecurityPlayground

 

hideNsneak:攻擊混淆框架

https://github.com/rmikehodges/hideNsneak

 

梅林

https://github.com/Ne0nd0g/merlin

 

RouterSploit

https://github.com/threat9/routersploit

 

硬件/嵌入式

ChipWhisperer

https://github.com/newaetech/chipwhisperer

 

️JTAGulator :揭開硬件安全的致命弱點

https://github.com/grandideastudio/jtagulator

 

Micro-Renovator:將處理器固件帶入代碼

https://github.com/syncsrc/MicroRenovator

 

TumbleRFRF模糊變得容易

https://github.com/riverloopsec/tumblerf

 

 

Walrus:充分利用您的卡片克隆設備

https://github.com/TeamWalrus/Walrus

 

物聯網

物聯網設備的可擴展動態分析框架

https://github.com/sycurelab/DECAF

 

BLE CTF項目

https://github.com/hackgnar/ble_ctf

 

WHID注射器和WHID Elite:新一代HID攻擊性設備

https://github.com/whid-injector/WHID

 

惡意軟件防御

為每位安全研究人員提供高級深度學習分析平台

https://github.com/intel/Resilient-ML-Research-Platform

 

EKTotal

https://github.com/nao-sec/ektotal

 

固件審計:Blue TeamsDFIR的平台固件安全自動化

https://github.com/PreOS-Security/fwaudit

 

MaliceIO

https://github.com/maliceio/malice

 

目標 - 參見MacOS安全工具

https://github.com/objective-see

 

 

惡意軟件進攻

BloodHound 1.5

https://github.com/BloodHoundAD/BloodHound

 

網絡攻擊

軍械庫

https://github.com/depthsecurity/armory

 

Chiron:一種先進的IPv6安全評估和滲透測試框架

https://github.com/aatlasis/Chiron

 

DELTASDN安全評估框架

https://github.com/OpenNetworkingFoundation/DELTA

 

Mallet:任意協議的攔截代理

 

https://github.com/sensepost/mallet

 

 

PowerUpSQL:用於在企業環境中攻擊SQL ServerPowerShell工具包

https://github.com/NetSPI/PowerUpSQL

 

️WarBerryPi

https://github.com/secgroundzero/warberry

 

網絡防御

ANWI(全新無線IDS):5美元的WIDS

https://github.com/SanketKarpe/anwi

 

CHIRON:基於家庭的網絡分析和機器學習威脅檢測框架

https://github.com/jzadeh/chiron-elk

 

雲安全套件:AWS / GCP / Azure安全審計的一站式工具

https://github.com/SecurityFTW/cs-suite

 

DejaVu:一個開源欺騙框架

https://github.com/bhdresh/Dejavu

 

OSINT - 開源智能

DataSploit 2.0

https://github.com/DataSploit/datasploit

 

️Dradis 框架:了解如何將報告時間縮短一半

https://github.com/dradis/dradis-ce

 

逆向工程

Snake:惡意軟件存儲動物園

https://github.com/countercept/snake

 

智能電網/工業安全

️GRFICS :工業控制模擬的圖形現實主義框架

https://github.com/djformby/GRFICS

 

漏洞評估

用於機器學習模型的對抗魯棒性工具箱

https://github.com/IBM/adversarial-robustness-toolbox

 

Android動態分析工具(ADA

https://github.com/ANELKAOS/ada

 

射箭:開源漏洞評估和管理

https://github.com/archerysec/archerysec

 

boofuzz

https://github.com/jtpereyda/boofuzz

 

BTA

https://github.com/airbus-seclab/bta

 

深度利用

https://github.com/13o-bbr-bbq/machine_learning_security/tree/master/DeepExploit

 

Halcyon IDE:適用於Nmap腳本開發人員

https://github.com/s4n7h0/Halcyon

   

️SimpleRisk

https://github.com/simplerisk

 

️TROMMEL

https://github.com/CERTCC/trommel

 

Web AppSec

看看NGINXModSec 3.0:軟件Web應用程序防火牆

https://github.com/SpiderLabs/ModSecurity

 

AstraREST API的自動安全測試

https://github.com/flipkart-incubator/Astra

 

Burp Replicator:自動化復雜漏洞的復制

https://github.com/PortSwigger/replicator

 

OWASP進攻性Web測試框架

https://github.com/owtf/owtf

 

OWASP JoomScan項目

https://github.com/rezasp/joomscan

 

WSSAT

https://github.com/YalcinYolalan/WSSAT


免責聲明!

本站轉載的文章為個人學習借鑒使用,本站對版權不負任何法律責任。如果侵犯了您的隱私權益,請聯系本站郵箱yoyou2525@163.com刪除。



 
粵ICP備18138465號   © 2018-2025 CODEPRJ.COM