当前位置:网站首页>企业安全攻击面分析工具
企业安全攻击面分析工具
2022-06-24 15:46:00 【Bypass】
以攻击者的视角来审视企业互联网资产可能存在的漏洞或其它可被攻击的可能性,这是一项极其重要的工作。今天分享几款开源的企业攻击面分析工具,可帮助甲方安全团队对攻击面进行梳理和检测。
01、Goby - Attack surface mapping
Goby是新一代的网络安全评估工具,它能够为企业梳理出最完整的攻击面信息,同时可以根据暴露在外网的漏洞快速渗透到企业内网。
官网地址:
https://gobies.org/
02、ARL - 资产安全灯塔
快速发现并整理企业外网资产,构建资产信息库,协助甲方安全团队或者渗透测试人员快速找到企业资产中的薄弱点和攻击面。
github项目地址:
https://github.com/TophantTechnology/ARL
03、linglong - 资产巡航扫描系统
系统定位是通过masscan+nmap无限循环去发现新增资产,自动进行端口弱口令爆破、指纹识别、XrayPoc扫描。
github项目地址:
https://github.com/awake1t/linglong
04、SEC-分布式资产安全扫描
SEC可用于企业对服务器资源安全进行扫描排查,可控性强、可停止运行中的扫描任务、支持分布式多节点部署,更快的扫描进度 + 节点执行信息动态反馈,快速定位漏洞。
github项目地址:
https://github.com/smallcham/sec-admin
05、w12scan - 网络安全资产扫描引擎
通过WEB接口下发任务,w12scan会自动将相关的资产聚合在一起方便分析使用。
github项目地址:
https://github.com/w-digital-scanner/w12scan
边栏推荐
- CAP:多重注意力机制,有趣的细粒度分类方案 | AAAI 2021
- Apple is no match for the longest selling mobile phone made in China, and has finally brought back the face of the domestic mobile phone
- 安装ImageMagick7.1库以及php的Imagick扩展
- MySQL 开发规范
- Junit5中的参数化测试(Parameterized Tests)指南
- 实现领域驱动设计 - 使用ABP框架 - 领域逻辑 & 应用逻辑
- Remain true to our original aspiration
- Several common DoS attacks
- 【Prometheus】4. Monitoring cases
- Install the imagemagick7.1 library and the imageick extension for PHP
猜你喜欢

如何扩展aws主机上的磁盘空间

Still worried about missing measurements? Let's use Jacobo to calculate the code coverage
![[interview high frequency questions] sequential DP questions with difficulty of 3/5 and direct construction](/img/32/720ffa63a90cd5d37460face3fde38.png)
[interview high frequency questions] sequential DP questions with difficulty of 3/5 and direct construction

我与“Apifox”的网络情缘

国产芯片的赶超,让美国手机芯片龙头高通害怕了,出招应对竞争

Using oasis to develop a hop by hop (I) -- Scene Building

实现领域驱动设计 - 使用ABP框架 - 领域逻辑 & 应用逻辑

一文理解OpenStack网络

MySQL binlog

Solution to the problem that FreeRTOS does not execute new tasks
随机推荐
clang: warning: argument unused during compilation: ‘-no-pie‘ [-Wunused-command-line-argument]
Ascinema with asciicast2gif for efficient command line terminal recording
CAP:多重注意力机制,有趣的细粒度分类方案 | AAAI 2021
10 hands-free idea plug-ins. These codes do not need to be written (the second bullet)
2021-04-27: if the adjacent position of a character does not have the same character
Paper: Google TPU
2021-05-01: given an ordered array arr, it represents the points located on the X axis. Given a positive number k
国产芯片的赶超,让美国手机芯片龙头高通害怕了,出招应对竞争
clang: warning: argument unused during compilation: ‘-no-pie‘ [-Wunused-command-line-argument]
Jenkins的便捷式安装
打破内存墙的新利器成行业“热搜”!持久内存让打工人也能玩转海量数据+高维模型
Parameterized tests guide in junit5
Mongodb introductory practical tutorial: learning summary directory
I just came back from the Ali software test. I worked for Alibaba P7 in 3+1, with an annual salary of 28*15
Using oasis to develop a hop by hop (I) -- Scene Building
2021-04-24: handwriting Code: topology sorting.
How to efficiently transfer enterprise business data?
Istio FAQ: return 426 status code
April 30, 2021: there are residential areas on a straight line, and the post office can only be built on residential areas. Given an ordered positive array arr
【Prometheus】4. Monitoring cases