TwKit

推文

@0xluffy_eth · 2026-10-09 09:32

美国国安局自己的逆向工程工具包在 GitHub 上免费开放。 5 个开源安全仓库,帮你看清自己的应用到底在干什么、又暴露了什么: 1. Sherlock 跨平台查找和你用户名匹配的公开账号。 https://github.com/sherlock-project/sherlock 2. Ghidra 美国国安局的逆向工程框架,把编译好的软件拆开,看它内部怎么运作。 https://github.com/NationalSecurityAgency/ghidra 3. mitmproxy 检查你应用和设备发出的网络流量。 https://github.com/mitmproxy/mitmproxy 4. TruffleHog 扫描你的 Git 历史,找出泄露的 API 密钥、密码和其他机密。 https://github.com/trufflesecurity/trufflehog 5. ESP32 Marauder 跑在 ESP32 硬件上的 Wi-Fi 和蓝牙审计工具。 https://github.com/justcallmekoko/ESP32Marauder 只在自己的系统上用,或者拿到明确授权再用。 与其被别人先找到漏洞,不如自己先找出来。

曝光 4051 · 评论 5 · 点赞 63 · 书签 80 · 曝光/时 517.5738621608638