防御 ---------------------------------------- 日志检查 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ - `Sysmon `_ - `LastActivityView `_ - `Regshot `_ 终端监控 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ - `attack monitor `_ Endpoint detection & Malware analysis software - `artillery `_ The Artillery Project is an open-source blue team tool designed to protect Linux and Windows operating systems through multiple methods. - `yurita `_ Anomaly detection framework @ PayPal XSS防护 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ - `js xss `_ - `DOMPurify `_ - `google csp evaluator `_ 配置检查 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ - `Attack Surface Analyzer `_ analyze operating system's security configuration for changes during software installation. - `gixy `_ Nginx 配置检查工具 - `dockerscan `_ Docker security analysis & hacking tools 安全检查 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ - `lynis `_ - `linux malware detect `_ IDS ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ - `ossec `_ - `yulong `_ - `AgentSmith `_ SIEM ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ - `panther `_ Detect threats with log data and improve cloud security posture 威胁情报 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ - `threatfeeds `_ - `abuseipdb `_ APT ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ - `APT Groups and Operations `_ - `APTnotes `_ 入侵检查 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ - `huorong `_ - `check rootkit `_ - `rootkit hunter `_ - `PC Hunter `_ - `autoruns `_ 进程查看 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ - `Process Explorer `_ - `ProcessHacker `_ Waf ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ - `naxsi `_ - `ModSecurity `_ - `ngx_lua_waf `_ - `OpenWAF `_ 病毒在线查杀 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ - `virustotal `_ - `virscan `_ - `habo `_ WebShell查杀 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ - `D盾 `_ - `深信服WebShell查杀 `_ IoC ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ - `malware ioc `_ - `fireeye public iocs `_ - `signature base `_ - `yara rules `_ 内存取证 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ - `SfAntiBotPro `_ - `volatility `_ 审计工具 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ - `Cobra `_ - `NodeJsScan `_ - `RIPS `_ - `pyvulhunter `_ - `pyt `_ - `Semmle QL `_ - `prvd `_ - `find sec bugs `_ - `trivy `_ - `chip `_ - `php malware finder `_ - `phpvulhunter `_ - `Sourcetrail `_ free and open-source cross-platform source explorer Security Advisories ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ - `apache httpd security advisories `_ - `nginx security advisories `_ - `Jetty Security Reports `_ - `Apache Tomcat `_ - `OpenSSL `_ 风险控制 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ - `aswan `_ 陌陌风控系统静态规则引擎