gitmyhub

404StarLink

★ 11k updated 3mo ago

404StarLink - 推荐优质、有意义、有趣、坚持维护的安全开源项目

A curated, continuously updated catalog of open source security tools maintained by the Knownsec 404 Lab, covering reconnaissance, network scanning, penetration testing, and defensive security for Chinese-speaking researchers.

setup: easycomplexity 1/5

404 StarLink is a curated directory of open source security tools maintained by the Knownsec 404 Lab, a Chinese cybersecurity research group. The project started in August 2020 with the stated goal of improving the fragmented state of the Chinese security tool ecosystem, where many projects were scattered, inconsistently maintained, and hard to discover. The README is written entirely in Chinese.

The repository does not contain tools itself. Instead, it acts as a continuously updated catalog, linking to other repositories and tracking their activity. For each project in the catalog, the 404 StarLink team provides some technical support, monitors for new releases, and surfaces updates to the community. Users can browse the catalog to find tools relevant to their area of interest and ask questions about those tools through the StarLink community channel.

The catalog is organized into categories. The top-starred projects at time of writing include tools for extracting browser-stored credentials, internal network scanning, container environment penetration testing, vulnerability scanning with customizable detection rules, and a plugin for the Burp web security testing tool. Other categories listed in the README cover information reconnaissance tools, defensive security tools aimed at enterprise defenders, and tools for Android app privacy compliance analysis.

The StarLink index also maintains a weekly update log showing which projects received new releases, and a running list of newly admitted projects with their descriptions. Admission requires the project to be high quality, meaningful, and actively maintained, according to the README's description of selection criteria.

This is primarily a reference and community resource for Chinese-speaking security researchers and practitioners rather than a tool to install or run directly.

Where it fits