> For the complete documentation index, see [llms.txt](https://hacking-notes.jord4n.pro/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://hacking-notes.jord4n.pro/zh/hacking-tools.md).

# 黑客工具

本部分是授权安全测试的主要工具目录。所有内容都按类别组织，因此侧边栏保持整洁，工具也不会以零散、重复的链接形式出现。

可将其当作地图使用：从任务类型入手，打开对应类别，并将方法论或利用步骤保留在专门的技术页面中。

## 主要领域

## 工作流程

1. 从发现开始：DNS、Web 画像、服务枚举、OSINT 和漏洞扫描。
2. 进入验证阶段：Burp Suite、SQLMap、特定协议工具、漏洞利用研究和手动检查。
3. 仅在与已验证问题匹配且预期影响明确时才使用利用框架。
4. 将凭据、载荷、权限提升辅助工具和研究参考资料保存在各自专门的类别中。
5. 记录准确的版本、命令、截图、载荷和证据，以便日后能够复现发现。

## 导航指南

* 使用 [计算器](/zh/hacking-tools/calculators.md) 用于子网划分、Linux 权限和 cron 表达式查询的计算器。
* 使用 [Web 应用测试工具](/zh/hacking-tools/web.md) 用于 Burp Suite、SQLMap、WMAP、模糊测试、画像分析、载荷参考和 WAF 资料。
* 使用 [发现与枚举工具](/zh/hacking-tools/enumeration.md) 用于 Nessus、DNS、Git-Dumper、网络服务、子域名和攻击面映射。
* 使用 [利用与研究工具](/zh/hacking-tools/exploitation.md) 用于 Metasploit、Searchsploit、漏洞利用参考、漏洞数据库和研究工作流。
* 使用 [凭据与身份工具](/zh/hacking-tools/credentials.md) 用于泄露检查、哈希查询、破解支持、默认凭据、字典和用户名资源。
* 使用 [OSINT 和研究工具](/zh/hacking-tools/osint.md) 用于公开来源研究、人物查询、泄露事件、基础设施、地图、图像、社交平台以及迁移后的 OSINT 方法论。
* 使用 [Windows 工具](/zh/hacking-tools/windows.md) 和 [Linux 工具](/zh/hacking-tools/linux.md) 用于本地枚举和权限提升支持。

<table data-view="cards" data-full-width="false" data-search="false"><thead><tr><th></th><th></th><th></th><th data-hidden data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td><h3><i class="fa-calculator" style="color:$primary;">:calculator:</i></h3></td><td><h4>计算器</h4></td><td>用于子网划分、Linux 权限转换和 cron 表达式查询的实用可搜索计算器。</td><td><a href="/pages/a2e6d508b0335a599c124a0dc1cda81b5fea2ba2">/pages/a2e6d508b0335a599c124a0dc1cda81b5fea2ba2</a></td></tr><tr><td><h3><i class="fa-bug" style="color:$primary;">:bug:</i></h3></td><td><h4>Web 应用测试工具</h4></td><td>面向代理工作流、SQL 注入自动化、Web 漏洞扫描、模糊测试、画像分析、载荷研究和 WAF 绕过支持的 Web 应用测试工具与资源。</td><td><a href="/pages/95eed8a13a802a73fca044b2da4615de753cef9f">/pages/95eed8a13a802a73fca044b2da4615de753cef9f</a></td></tr><tr><td><h3><i class="fa-magnifying-glass" style="color:$primary;">:magnifying-glass:</i></h3></td><td><h4>发现与枚举工具</h4></td><td>用于 DNS、服务评估、漏洞扫描、暴露的 Git 仓库、子域名、Web 画像分析和攻击面映射的发现与枚举工具。</td><td><a href="/pages/9f9f9b0f995eb941e6a5ee58b8bf392f6e1184c1">/pages/9f9f9b0f995eb941e6a5ee58b8bf392f6e1184c1</a></td></tr><tr><td><h3><i class="fa-rocket" style="color:$primary;">:rocket:</i></h3></td><td><h4>利用与研究工具</h4></td><td>用于 Metasploit、Searchsploit、漏洞利用参考、漏洞数据库、漏洞赏金报告和模块驱动验证工作流的利用与研究工具。</td><td><a href="/pages/86860c11a2280736b088bb62ffab167b66cf10b0">/pages/86860c11a2280736b088bb62ffab167b66cf10b0</a></td></tr><tr><td><h3><i class="fa-key" style="color:$primary;">:key:</i></h3></td><td><h4>凭据与身份工具</h4></td><td>用于泄露检查、密码强度审查、哈希查询、密码破解、默认凭据、字典和用户名资源的凭据与身份工具参考。</td><td><a href="/pages/41c9def5cf4d378f8b7be694b68ad178cd15fdd6">/pages/41c9def5cf4d378f8b7be694b68ad178cd15fdd6</a></td></tr><tr><td><h3><i class="fa-compass" style="color:$primary;">:compass:</i></h3></td><td><h4>OSINT 和研究工具</h4></td><td>精选的 OSINT 与研究工具，用于地图、影像、社交平台、人物查询、泄露情报、网站、基础设施监控和 OSINT 方法论。</td><td><a href="/pages/0994d933c83036e0469f2f9578ad7083b194ca23">/pages/0994d933c83036e0469f2f9578ad7083b194ca23</a></td></tr><tr><td><h3><i class="fa-windows" style="color:$primary;">:windows:</i></h3></td><td><h4>Windows 工具</h4></td><td>Windows 攻击性安全工具笔记，用于本地枚举、权限检查、Active Directory 攻击路径映射、BloodHound、SharpHound、WinPEAS、PrivescCheck、LOLBAS、PowerUp、Invoke-Obfuscation、Shellter 以及利用后验证。</td><td><a href="/pages/ca6a212d38126fe7536e23ee0582e448176c96c2">/pages/ca6a212d38126fe7536e23ee0582e448176c96c2</a></td></tr><tr><td><h3><i class="fa-linux" style="color:$primary;">:linux:</i></h3></td><td><h4>Linux 工具</h4></td><td>Linux 攻击性工具目录，用于本地枚举、权限提升检查、GTFOBins 验证、LinPEAS、LinEnum、Smart Enumeration、内核 CVE 研究、SUID 和 sudo 审查、capabilities、cron 任务以及利用后证据收集。</td><td><a href="/pages/9d4aed2a36e06f3c06ce9d9662665d27586310dc">/pages/9d4aed2a36e06f3c06ce9d9662665d27586310dc</a></td></tr></tbody></table>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://hacking-notes.jord4n.pro/zh/hacking-tools.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
