Volver al ranking

Ascotbe/Medusa

Pythonmedusa.ascotbe.com

:cat2:Medusa是一个红队武器库平台,目前包括XSS平台、协同平台、CVE监控、免杀生成、DNSLOG、钓鱼邮件、文件获取等功能,持续开发中

pocexppayloadmedusacvexssreadteamdnslogvirusemailcobaltstrikemetasploit-framework
Crecimiento de estrellas
Estrellas
2.2k
Forks
341
Crecimiento semanal
Issues
0
1k2k
ago 2019nov 2021mar 2024jul 2026
ArtefactosPyPIpip install medusa
README
Medusa

Release Release Release Release Release Release Release Release

Welcome to Medusa

:point_right:About Medusa

The project is licensed under GPL.Free for non-commercial use.

Due to the lack of front -end, the project restart time is unknown. If you can provide help, please submit the issue

中文文档 | EnglishDocumentation

:bulb:Document

http://medusa.ascotbe.com

:clipboard:Web Ver. installation instructions

https://medusa.ascotbe.com/Documentation/#/Installation

:space_invader:Web interface

demo

:four_leaf_clover:Updating logs

http://medusa.ascotbe.com/Documentation/#/UpDataLog

:green_heart:Discussion

  • If you find that the corresponding vulnerability cannot be scanned by the plug-in, please submit the [Bug] issue
  • If you have any problems that cannot be solved by the documentation, please submit an issue of [help]
  • If you have any good comments or ideas, please submit [idea] issue

:warning:Disclaimer

Add the following content to the original protocol:

  • If there is any ambiguity, the Chinese version of the description shall be the only explanation
  • Commercial use after secondary development is prohibited in this project
  • Unauthorized commercial use is prohibited for this project
  • This project is only for the safe construction activities of enterprises that are legally authorized. When using this project for testing, you should ensure that the behavior complies with local laws and regulations and has obtained sufficient authorization.
  • If you have any illegal behavior in the process of using this project, you need to bear the corresponding consequences yourself, and we will not bear any legal and joint liabilities.
  • Before using this project, please read carefully and fully understand the content of each clause. Restrictions, exemption clauses or other clauses involving your major rights and interests may be bolded, underlined, etc. to remind you to pay attention. Unless you have fully read, fully understood and accepted all the terms of this agreement, please do not use this item. Your use behavior or your acceptance of this agreement in any other express or implied manner shall be deemed to have been read and agreed to be bound by this agreement.

:palm_tree:Contributors

commit

:checkered_flag:Timeline

Alt

star

Repositorios relacionados
chaitin/xray

一款长亭自研的完善的安全评估工具,支持常见 web 安全问题扫描和自定义 poc | 使用之前务必先阅读文档

VueOthersecurityvulnerability
docs.xray.cool
11.7k1.9k
frohoff/ysoserial

A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.

JavaMavenMIT Licensejavadeserialization
frohoff.github.io/appseccali-marshalling-pickles/
9k1.9k
trickest/cve

Gather and update all available and newest CVEs with their PoC.

HTMLMIT Licensepoccve
trickest.com
8k981
nomi-sec/PoC-in-GitHub

📡 PoC auto collect from GitHub. ⚠️ Be careful Malware.

securitycve
poc-in-github.motikan2010.net
7.9k1.3k
Mr-xn/Penetration_Testing_POC

渗透测试有关的POC、EXP、脚本、提权、小工具等---About penetration-testing python-script poc getshell csrf xss cms php-getshell domainmod-xss csrf-webshell cobub-razor cve rce sql sql-poc poc-exp bypass oa-getshell cve-cms

HTMLApache License 2.0penetration-testingpoc
mrxn.net
7.4k2k
k8gege/K8tools

K8工具合集(内网渗透/提权工具/远程溢出/漏洞利用/扫描工具/密码破解/免杀工具/Exploit/APT/0day/Shellcode/Payload/priviledge/BypassUAC/OverFlow/WebShell/PenTest) Web GetShell Exploit(Struts2/Zimbra/Weblogic/Tomcat/Apache/Jboss/DotNetNuke/zabbix)

PowerShellMIT Licenseexploit0day
k8gege.org
6.2k2.1k
ffffffff0x/1earn

ffffffff0x 团队维护的安全知识框架,内容包括不仅限于 web安全、工控安全、取证、应急、蓝队设施部署、后渗透、Linux安全、各类靶机writup

C++markdown-articlelinux-learning
home.ffffffff0x.com
5.7k1.3k
drk1wi/Modlishka

Modlishka. Reverse Proxy.

GoGo ModulesOtherpenetration-testing-toolsmitm
5.4k956
k8gege/Ladon

Ladon大型内网渗透扫描器,PowerShell、Cobalt Strike插件、内存加载、无文件扫描。含端口扫描、服务识别、网络资产探测、密码审计、高危漏洞检测、漏洞利用、密码读取以及一键GetShell,支持批量A段/B段/C段以及跨网段扫描,支持URL、主机、域名列表扫描等。网络资产探测32种协议(ICMP\NBT\DNS\MAC\SMB\WMI\SSH\HTTP\HTTPS\Exchange\mssql\FTP\RDP)或方法快速获取目标网络存活主机IP、计算机名、工作组、共享资源、网卡地址、操作系统版本、网站、子域名、中间件、开放服务、路由器、交换机、数据库、打印机等,大量高危漏洞检测模块MS17010、Zimbra、Exchange

C#MIT Licensescannerportscan
k8gege.org/Ladon/
5.3k881
Threekiii/Awesome-POC

一个漏洞 PoC 知识库。A knowledge base for vulnerability PoCs(Proof of Concept), with 1k+ vulnerabilities.

JavaMavenpoc
5.1k1k
gommzystudio/device-activity-tracker

A phone number can reveal whether a device is active, in standby or offline (and more). This PoC demonstrates how delivery receipts + RTT timing leak sensitive device-activity patterns. (WhatsApp / Signal)

TypeScriptnpmOtherphone-numbersignal
5k692
wy876/POC

收集整理漏洞EXP/POC,大部分漏洞来源网络,目前收集整理了1400多个poc/exp,长期更新。

poc
wiki.wy876.cn
4.7k1k