標籤:

2017黑帽大會兵工廠工具列表

眾所周知,黑帽大會的兵工廠秀是會議的一大亮點,目前2017黑帽大會兵工廠的大部分工具都已經上傳到了 Github 社區中,此文旨在把相關工具和作者信息進行整理並梳理如下。n

Android, iOS and Mobile Hacking

  • Android Tamerngithub.com/AndroidTamernTwitter: @AndroidTamer ?nPresenter: Anant Shrivastava (@anantshri)
  • BadIntent?—?Integrating Android with Burpngithub.com/mateuszk87/BnPresenter: Mateusz Khalil (@mateuszk87)
  • DiffDroidngithub.com/antojoseph/dnPresenter: Anto Joseph (@antojosep007)
  • Kwetzangithub.com/sensepost/kwnPresenter: Chris Le Roy (@brompwnie)
  • Needlengithub.com/mwrlabs/neednTwitter: @mwrneedlenPresenter: Marco Lancini (@lancinimarco)
  • NoPE Proxy (Non-HTTP Proxy Extension)ngithub.com/summitt/BurpnPresenter: Josh H.S. (@null0perat0r)

Code Assessment

  • Puma Scanngithub.com/pumasecuritynTwitter: @puma_scannPresenter: Aaron Cure (@curea)
  • Tintorera: Source Code Intelligence (Code not yet uploaded)ngithub.com/vulnex/TintonPresenter: Simon Roses Femerling (@simonroses)

Cryptography

  • Hashviewngithub.com/hashview/hasnPresenters: Casey Cammilleri (@CaseyCammilleri), Hans Lakhan (@jarsnah12)
  • Gibber Sensengithub.com/smxlabs/gibbnPresenter: Ajit Hatti (@ajithatti)

Data Forensics and Incident Response

  • Answering When/Where/Who is my Insider?—?UserLinengithub.com/THIBER-ORG/unPresenter: Chema Garcia (@sch3m4)
  • DefPloreX: A Machine-Learning Toolkit for Large-scale eCrime Forensicsngithub.com/trendmicro/dnPresenters: Federico Maggi (@phretor), Marco Balduzzi (@embyte), Lion Gu, Ryan Flores, Vincenzo Ciancaglini
  • HoneyPingithub.com/mattymcfattynPresenter: Matt South (@mattymcfatty)
  • PcapDB: Optimized Full Network Packet Capture for Fast and Efficient Retrievalngithub.com/dirtbags/pcanPresenters: Paul Ferrell (@pflarr), Shannon Steinfadt
  • SCOT (Sandia Cyber Omni Tracker) Threat Intelligence and Incident Response Management Systemngithub.com/sandialabs/snPresenters: Nick Georgieff , Todd Bruner (@toddbruner)
  • Security Monkeyngithub.com/Netflix/secunPresenters: Mike Grima (@mikegrima) , Patrick Kelley (@MonkeySecurity)
  • ThreatResponse: An Open Source Toolkit for Automating Incident Response in AWSngithub.com/ThreatResponnPresenter: Andrew Krug (@andrewkrug)
  • Volatile Memory Analysis at Scale?—?the Highest Performing and Forensic Platform for Windows x64ngithub.com/ShaneK2/inVtnPresenter: Shane Macaulay (@ktwo_K2)
  • Yalda?—?Automated Bulk Intelligence Collection (Code not yet uploaded)ngithub.com/gitaziabari/nPresenter: Gita Ziabari (@gitaziabri)

Exploitation and Ethical Hacking

  • AVET?—?AntiVirus Evasion Toolngithub.com/govolution/anPresenter: Daniel Sauder (@DanielX4v3r)
  • Building C2 Environments with Warhorsengithub.com/war-horse/wanPresenter: Ralph May (@ralphte1)
  • umulus?—?A Cloud Exploitation Toolkitngithub.com/godinezj/metnPresenter: Javier Godinez (@isomorphix)
  • GDB Enhanced Features (GEF)ngithub.com/hugsy/gefnPresenter: Chris Alladoum (@_hugsy_)
  • Leviathan Frameworknithub.com/leviathan-franPresenters: Ozge Barbaros (@ozgebarbaros), Utku Sen (@utku1337)
  • MailSniperngithub.com/dafthack/MainPresenter: Beau Bullock (@dafthack)
  • Rattlerngithub.com/sensepost/ranPresenter: Chris Le Roy (@brompwnie)
  • Sethngithub.com/SySS-ResearcnPresenter: Adrian Vollmer (@AdrianVollmer)

Hardware/Embedded

  • ChipWhispererngithub.com/newaetech/chnPresenter: Colin O』Flynn (@colinoflynn)
  • DYODE, a DIY, Low-Cost Data Diode for ICSngithub.com/arnaudsoullinPresenters: Arnaud Soullié (@arnaudsoullie), Ary Kokos ()
  • FTW: Framework for Testing WAFsngithub.com/fastly/ftwnPresenters: Chaim Sanders, Zack Allen (@teachemtechy)
  • The Bicho: An Advanced Car Backdoor Makerngithub.com/UnaPibaGeek/nPresenters: Claudio Caracciolo (@holesec), Sheila Ayelen Berta (@UnaPibaGeek)

Human Factors

  • IsThisLegitngithub.com/duo-labs/istnPresenters: Jordan Wright (@jw_sec), Mikhail Davidov (@sirus)

Internet of Things

  • Hacker Modengithub.com/xssninja/AlenPresenter: David Cross (@10rdV4d3r)
  • Universal Radio Hacker: Investigate Wireless Protocols Like a Bossngithub.com/jopohl/urhnPresenter: Johannes Pohl (@jopohl)

Malware Defense

  • Aktaion v2?—?Open Source Machine Learning and Active Defense Toolngithub.com/jzadeh/AktainPresenters: Joseph Zadeh (@JosephZadeh), Rod Soto (@rodsoto)
  • Cuckoodroidngithub.com/idanr1986/cunPresenter: Idan Revivo (@idanr86)
  • Cuckoo Sandboxngithub.com/cuckoosandbonTwitter: @cuckoosandboxnPresenter: Jurriaan Bremer (@skier_t)
  • LimaCharliengithub.com/refractionPOnTwitter: @rp_limacharlienPresenter: Maxime Lamothe-Brassard (@_maximelb)
  • Malboxesngithub.com/GoSecure/malnPresenter: Olivier Bilodeau (@obilodeau)

Malware Offense

  • A New Take at Payload Generation: Empty-Nestngithub.com/empty-nest/enPresenters: James Cook (@_jbcook), Tom Steele (@_tomsteele)

Network Attacks

  • BloodHound 1.3 ngithub.com/BloodHoundADnPresenters: Andy Robbins (@_wald0), Rohan Vazarkar (@CptJesus), Will Schroeder (@harmj0y)
  • CrackMapExec v4ngithub.com/byt3bl33d3r/nPresenter: Marcello Salvati (@byt3bl33d3r)
  • DELTA: SDN Security Evaluation Frameworkngithub.com/OpenNetworkinPresenters: Jinwoo Kim, Seungsoo Lee, Seungwon Shin
  • eaphammerngithub.com/s0lst1c3/eapnPresenter: Gabriel Ryan (@s0lst1c3)
  • GoFetchngithub.com/GoFetchAD/GonPresenter: Tal Maor (@talthemaor)
  • gr-lora: An Open-Source SDR Implementation of the LoRa PHYngithub.com/BastilleResenPresenter: Matt Knight (@embeddedsec)
  • Yasuongithub.com/0xsauby/yasunPresenter: Saurabh Harit (@0xsauby)

Network Defense

  • Assimilatorngithub.com/videlanicolanPresenter: Nicolas Videla (@jsusvidela)
  • Noddosngithub.com/noddos/noddonPresenter: Steven Hessing
  • SITCH: Distributed, Coordinated GSM Counter-Surveillancengithub.com/sitch-io/sennTwitter: @sitch_ionPresenter: Ash Wilson (@ashmastaflash)
  • Sweet Securityngithub.com/TravisFSmithnPresenter: Travis Smith (@MrTrav)

OSINT?—?Open Source Intelligence

  • Datasploit?—?Automated Open Source Intelligence (OSINT) Toolngithub.com/DataSploit/dnTwitter: @datasploit nPresenter: Shubham Mittal (@upgoingstar)
  • Dradis: 10 Years Helping Security Teams Spend More Time Testing and Less Time Reportingngithub.com/dradis/dradinTwitter: @dradisfwnPresenter: Daniel Martin (@etdsoft)
  • OSRFramework: Open Sources Research Frameworkngithub.com/i3visio/osrfnPresenters: Félix Brezo Fernández (@febrezo), Yaiza Rubio Vi?uela (@yrubiosec)

Reverse Engineering

  • BinGrepngithub.com/m4b/bingrepnPresenter: Hiroki Hada
  • FLARE VMngithub.com/fireeye/flarnPresenter: Peter Kacherginsky (@_iphelix)

Vulnerability Assessment

  • Aardvark and Repokidngithub.com/Netflix-Skunngithub.com/Netflix/reponPresenters: Patrick Kelley (@MonkeySecurity), Travis McPeak (@travismcpeak)
  • Hack/400 and IBMiScanner Tooling for Checking Your IBM i (aka AS/400) Machines !ngithub.com/hackthelegacnPresenter: Bart Kulach (@bartholozz)
  • PowerSAP: Powershell Tool to Assess SAP Securityngithub.com/airbus-seclanPresenter: Joffrey Czarny (@Sn0rkY)
  • SERPICOngithub.com/SerpicoProjenTwitter: @SerpicoProjectnPresenters: Peter Arzamendi (@thebokojan), Will Vandevanter (@0xRST)
  • SimpleRiskngithub.com/simplerisk/cnTwitter: @simpleriskfreenPresenter: Josh Sokol (@joshsokol)

Web AppSec

  • BurpSmartBuster: A Smart Way to Find Hidden Treasuresngithub.com/pathetiq/BurnPresenter: Patrick Mathieu (@pathetiq)
  • CSP Auditorngithub.com/GoSecure/cspnPresenter: Philippe Arteau (@h3xstream)
  • Easily Exploit Timing Attacks in Web Applications with the 『timing_attack』 Gemngithub.com/ffleming/timnPresenter: Forrest Fleming (@ffleming)
  • Fuzzapi?—?Fuzzing Your RESTAPIs Since Yesterdayngithub.com/lalithr95/funTwitter: @Fuzzapi0x00nPresenters: Abhijeth Dugginapeddi (@abhijeth), Lalith Rallabhandi (@lalithr95), Srinivas Rao (@srini0x00)
  • Offensive Web Testing Framework (OWASP OWTF)ngithub.com/owtf/owtfnTwitter: @owtfpnPresenter: Viyat Bhalodia (@viyat)
  • PyMultiTorngithub.com/realgam3/pymnPresenter: Tomer Zait (@realgam3)
  • ThreadFix Web Application Attack Surface Calculationngithub.com/denimgroup/tnTwitter: @ThreadFixnPresenter: Dan Cornell (@danielcornell)
  • WaToBo?—?The Web Application Toolboxngithub.com/siberas/watonPresenter: Andreas Schmidt (@_znow)
  • WSSiP: A WebSocket Manipulation Proxyngithub.com/nccgroup/wssnPresenter: Samantha Chalker (@itsisatis)

SecWiki 專註安全領域最新資訊、專題和導航,做高質量聚合與評論。

-----微信ID:SecWiki-----nSecWiki,5年來一直專註安全技術資訊分析!nSecWiki:https://www.sec-wiki.comn

推薦閱讀:

進階玩法,那些牛逼的圖表是怎麼來的?
Chrome Tips #4:在任意頁面運行預定義腳本
製作橡皮章需要哪些工具?

TAG:工具 | 安全 |