DSH HUB
HomePlugin StorePlugin PacksCommunityRankingsResourcesPublish Guide
Plugin source
Back to catalog

jonah791 /

jonah791/dsh-red-team

Topic repository only

红队渗透辅助插件:侦察/枚举/指纹/CVE 匹配/敏感路径(8 工具,仅限授权测试)

★ 1 Stars0 Forks0 IssuesN/A Community rating0 Confirmed installs
View on GitHub
READMESource: master@d5efd7fb

dsh-red-team

version license TypeScript

红队渗透辅助插件——**爱丽丝的攻击之手**。按 PTES 流程(侦察→枚举→利用辅助→报告),每个工具带**仅限授权测试**边界声明。用于主人自有/授权/靶场环境。

工具面(8 工具)

阶段 工具 能力
侦察 red_subdomain_enum 子域枚举(crt.sh 证书透明日志,502 自动重试)
枚举 red_dir_brute 目录/文件枚举(内置 70+ 字典,非 404 视为存在)
red_crawl_links 链接爬取(同域去重,发现隐藏端点)
red_tech_fingerprint 技术栈指纹(Server/X-Powered-By + 20 框架特征)
red_banner_grab 服务 banner 抓取(端口服务版本识别)
利用辅助 red_cve_match 软件+版本 CVE 匹配(CVSS 排序 + exploit 参考标注)
防御评估 red_security_headers 安全响应头检测(缺 HSTS/CSP 等 = 攻击面)
red_sensitive_paths 敏感路径探测(.git 泄露/.env/phpinfo/备份/后台)

技术要点

  • 全部 Node 原生实现(fetch/net),零外部依赖
  • crt.sh 偶发 502 已加重试(3 次退避)
  • 已知边界:SPA 应用(如 Vite/React)对任意路径返回 200 → 目录/敏感路径探测会全 200 误报;真实传统服务器无此问题。.git 泄露通过响应体 ref: 特征判定(防 SPA 误报)

合规红线(硬性)

  • 仅用于主人自有/明确授权的系统与开源靶场
  • 不触碰未经授权的第三方系统
  • 工具为侦察/评估性质,不含破坏性利用载荷

使用示例

red_subdomain_enum domain="example.com"
red_dir_brute url="http://192.168.1.10/"
red_tech_fingerprint url="http://192.168.1.10/"
red_banner_grab host="192.168.1.10" port="22"
red_cve_match software="openssl" version="1.0.2"
red_security_headers url="http://192.168.1.10/"
red_sensitive_paths url="http://192.168.1.10/"
red_crawl_links url="http://192.168.1.10/"
—/ 5

No ratings yet

Manifest verification required

Commit d5efd7fbda1d

Community comments

No comments yet. Be the first to write one.

DSH HUB

A community index for DSH plugins. Not an official GitHub or DeepSeek AI product.

CommunityResourcesAPIAbout