信息收集 ---------------------------------------- 子域爆破 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ - `subDomainsBrute `_ - `wydomain `_ - `broDomain `_ - `ESD `_ - `aiodnsbrute `_ - `OneForAll `_ - `subfinder `_ 域名获取 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ - `the art of subdomain enumeration `_ - `sslScrape `_ - `aquatone `_ A Tool for Domain Flyovers 弱密码爆破 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ - `hydra `_ - `medusa `_ - `htpwdScan `_ - `patator `_ Git信息泄漏 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ - `GitHack By lijiejie `_ - `GitHack By BugScan `_ - `GitTools `_ - `Zen `_ - `dig github history `_ - `gitrob Reconnaissance tool for GitHub organizations `_ - `git secrets `_ - `shhgit `_ Find GitHub secrets in real time - `GitHound `_ GitHound pinpoints exposed API keys on GitHub using pattern matching, commit history searching, and a unique result scoring system. A batch-catching, pattern-matching, patch-attacking secret snatcher. Github监控 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ - `Github Monitor `_ - `Github Dorks `_ - `GSIL `_ - `Hawkeye `_ - `gshark `_ - `GitGot `_ - `gitGraber `_ 路径及文件扫描 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ - `weakfilescan `_ - `DirBrute `_ - `dirsearch `_ - `bfac `_ - `ds_store_exp `_ 路径爬虫 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ - `crawlergo `_ A powerful dynamic crawler for web vulnerability scanners 指纹识别 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ - `Wappalyzer `_ - `whatweb `_ - `Wordpress Finger Print `_ - `CMS指纹识别 `_ - `JA3 `_ is a standard for creating SSL client fingerprints in an easy to produce and shareable way Waf指纹 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ - `identywaf `_ - `wafw00f `_ - `WhatWaf `_ 端口扫描 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ - `nmap `_ - `zmap `_ - `masscan `_ - `ShodanHat `_ - DNS ``dnsenum nslookup dig fierce`` - SNMP ``snmpwalk`` DNS数据查询 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ - `VirusTotal `_ - `PassiveTotal `_ - `DNSDB `_ - `sitedossier `_ DNS关联 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ - `Cloudflare Enumeration Tool `_ - `amass `_ - `Certificate Search `_ 云服务 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ - `Find aws s3 buckets `_ - `CloudScraper `_ - `AWS Bucket Dump `_ 数据查询 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ - `Censys `_ - `Shodan `_ - `Zoomeye `_ - `fofa `_ - `scans `_ - `Just Metadata `_ - `publicwww - Find Web Pages via Snippet `_ Password ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ - `Probable Wordlists `_ Wordlists sorted by probability originally created for password generation and testing - `Common User Passwords Profiler `_ - `chrome password grabber `_ 字典 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ - `Blasting dictionary `_ - `pydictor `_ CI信息泄露 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ - `secretz `_ minimizing the large attack surface of Travis CI 其他 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ - `datasploit `_ - `watchdog `_ - `archive `_ - `HTTPLeaks `_ - `htrace `_ - `AWSBucketDump `_