FofaInfo/Awesome-FOFA

GitHub: FofaInfo/Awesome-FOFA

FOFA 官方维护的网络空间测绘知识库,汇集使用指南、实战案例、APT 追踪报告及社区 API 工具索引,帮助安全从业者高效利用 FOFA 进行攻击面发现与威胁分析。

Stars: 344 | Forks: 40

# Awesome-FOFA 知识库 [:ledger: 中文 README](https://github.com/FofaInfo/FOFA-Library/blob/main/README_zh.md)
## FOFA 入门指南 [新手指南](https://github.com/FofaInfo/Awesome-FOFA/blob/main/Get%20Started%20with%20FOFA/A%20Beginner%E2%80%98s%20Guide.md) [如何从 FOFA 获取免费 F 点? ](https://github.com/FofaInfo/Awesome-FOFA/blob/main/Get%20Started%20with%20FOFA/How%20to%20Get%20Free%20F-point%20from%20FOFA%3F.md) ## FOFA 与 AI [下一代攻击面测绘:免费试用开启!](https://github.com/FofaInfo/Awesome-FOFA/blob/2718f88e56d0dc678b07ece1793707a9c3bb9542/FOFA%2BAI/Next-Generation%20Attack%20Surface%20Inventory%3A%20Free%20Trial%20Available!.md) ## 基础场景 [如何使用 FOFA 发现免费的 LLM 资源?](https://github.com/FofaInfo/Awesome-FOFA/blob/76d6ff924c4c498a6752fad32c46d71441e40994/Basic%20scenario/How%20to%20use%20FOFA%20to%20discover%20free%20LLM%20resources%3F.md) [通过新颖方法提升 FOFA 搜索效率](https://github.com/FofaInfo/Awesome-FOFA/blob/61e0e3ca4d783fb24ea5f5211663cfb3429f1334/Basic%20scenario/Elevating%20FOFA%20Search%20Efficiency%20through%20Novel%20Approaches.md) [如何在 FOFA 上独立刷新你的资产?](https://github.com/FofaInfo/Awesome-FOFA/blob/a8084af052b699899ada7e9f6b9adb05f349817f/Basic%20scenario/How%20to%20Independently%20Refresh%20Your%20Assets%20on%20FOFA%3F.md) [在 FOFA 中使用模糊搜索的正确姿势](https://github.com/FofaInfo/FOFA-Library/blob/main/Basic%20scenario/The%20correct%20way%20to%20use%20Fuzzy%20Search%20in%20FOFA.md) [如何在资产发现中通过证书有效排除干扰](https://github.com/FofaInfo/Awesome-FOFA/blob/main/Basic%20scenario/How%20to%20effectively%20eliminate%20interference%20through%20certificates%20in%20the%20asset%20discovery.md) [上帝视角的资产测绘](https://github.com/FofaInfo/Awesome-FOFA/blob/main/Basic%20scenario/Asset%20Inventory%20from%20a%20God%E2%80%98s%20Perspective.md) [在 FOFA 中获取大量资产的最佳方案](https://github.com/FofaInfo/Awesome-FOFA/blob/main/Basic%20scenario/Best%20Approach%20for%20Fetching%20Large%20Amounts%20of%20Asset%20in%20FOFA.md) ## 进阶用例 [开放目录中的威胁狩猎]() [使用 FOFA 发现威胁情报的全面指南](https://github.com/FofaInfo/Awesome-FOFA/blob/4144088aed5815e7eee565d270c29892478992ed/Basic%20scenario/A%20Comprehensive%20Guide%20to%20Threat%20Intelligence%20Discovery%20Using%20FOFA.md) [FOFA 资产拓展实战:揭开“银狐”APT 的踪迹](https://github.com/FofaInfo/Awesome-FOFA/blob/5e54a179c7203cadc1e950e4e8f679caed5f9dee/Basic%20scenario/Practical%20FOFA%20Asset%20Expansion-%20Unmasking%20the%20Trail%20of%20the%20'Silver%20Fox'%20APT.md) [使用 FOFA 执行 APT Bitter 追踪行动](https://github.com/FofaInfo/Awesome-FOFA/blob/159a94ef0098db6fa5093f8cefff4d133f25ed8c/Basic%20scenario/Conducting%20APT%20Bitter%20Tracking%20Operation%20Using%20FOFA.md) [ObserverStealer 分析与追踪](https://github.com/FofaInfo/Awesome-FOFA/blob/1c416977d7f4dc2dd9d6d7a13e15c3dea7bfa60a/Basic%20scenario/Analysis%20and%20Tracing%20of%20the%20ObserverStealer.md) [FOFA 资产拓展实战:Sidewinder APT](https://github.com/FofaInfo/Awesome-FOFA/blob/e270c63b8849999f44da81cb13746ca659bbbdea/Basic%20scenario/Practical%20FOFA%20Asset%20Expansion-%20Sidewinder%20APT.md) [FOFA 资产拓展实战:APT-C-23 Android 恶意软件](https://github.com/FofaInfo/Awesome-FOFA/blob/3bd23cfc1e4850584320a5d90529913901396dca/Basic%20scenario/Practical%20FOFA%20Asset%20Expansion-%20APT-C-23%20Android%20Malware.md) [FOFA 资产拓展实战:Ducktail](https://github.com/FofaInfo/Awesome-FOFA/blob/9ff7a1b8e225a0ed93e2776c37deb0d56c26e7bb/Basic%20scenario/Practical%20FOFA%20Asset%20Expansion%EF%BC%9ADucktail.md) [FOFA 资产发现实战:COLDRIVER](https://github.com/FofaInfo/Awesome-FOFA/blob/f0fdb52c77d81c3cbe4a6dcdb3d59ac735f55991/Basic%20scenario/Practical%20FOFA%20Asset%20Discovery-%20COLDRIVER.md) ## 实用 FOFA API 工具 [fofa-py](https://github.com/fofapro/fofa-py/blob/master/docs/README_EN.md) [fofa_Viewer](https://github.com/wgpsec/fofa_viewer/blob/master/README.en.md) [fofax](https://github.com/xiecat/fofax/blob/main/README.md) [gofofa](https://github.com/LubyRuffy/gofofa) [fofa_search](https://github.com/thebatmanfuture/fofa_search) ## FOFAHub ### 工作流介绍 [开放站点发现](https://github.com/FofaInfo/Awesome-FOFA/blob/main/FofaHub/Archive/Unleash%20the%20Power%20of%20Workflow-%20Unleash%20Your%20Creativity%20in%20Open%20Site%20Discovery.md) [登录页面发现](https://github.com/FofaInfo/Awesome-FOFA/blob/main/FofaHub/Login%20Discovery.md) [独立 IP 筛选](https://github.com/FofaInfo/Awesome-FOFA/blob/main/FofaHub/Filter%20Independent%20IP.md) [产品聚合](https://github.com/FofaInfo/Awesome-FOFA/blob/main/FofaHub/Product%20Aggregation.md) [AI 发现器](https://github.com/FofaInfo/Awesome-FOFA/blob/main/FofaHub/AI%20Finder.md) ## 其他 [LLM 是如何沦为犯罪帮凶的?](https://github.com/FofaInfo/Awesome-FOFA/blob/615dd1a7201aa3b2e58b391d7681b598ad976930/Basic%20scenario/How%20did%20LLM%20become%20accomplices%20to%20crime%3F.md) ### 精彩分析报告 [Roundcube ≤ 1.6.10 Post-Auth RCE via PHP Object Deserialization [CVE-2025-49113]](https://fearsoff.org/research/roundcube) [Murdoc Botnet Mirai 的大规模活动:Corona Mirai 的新变种](https://blog.qualys.com/vulnerabilities-threat-research/2025/01/21/mass-campaign-of-murdoc-botnet-mirai-a-new-variant-of-corona-mirai) [使用 Web Scraping 算法检测隐藏在 .go.id 域名上的非法在线赌博 ](https://journal.universitasbumigora.ac.id/index.php/matrik/article/view/3824/1616) [使用 FOFA 揭露一起“Correios”钓鱼骗局](https://debugactiveprocess.medium.com/exposing-a-correios-phishing-scam-with-fofa-57cfa375fdeb) [分析一场大规模的 Microsoft 365 凭证窃取活动](https://www.bridewell.com/insights/blogs/detail/analysing-widespread-microsoft365-credential-harvesting-campaign) [揭露“Easy Stealer” Infostealer](https://www.bridewell.com/insights/blogs/detail/uncovering-the-easy-stealer-infostealer) [HostingHunter 系列:CHANG WAY TECHNOLOGIES CO. LIMITED](https://medium.com/@joshuapenny88/hostinghunter-series-chang-way-technologies-co-limited-a9ba4fce0f65) [Chenlun aka Sinkinto01:全球性钓鱼与盗刷活动提供者](https://g0njxa.medium.com/chenlun-a-worldwide-phishing-carding-campaigns-provider-a45c4fed6d1b) [Traque de l’infrastructure cybercriminelle de l’infostealer RisePro](https://projetfox.com/2023/11/traque-de-linfrastructure-cybercriminelle-de-linfostealer-risepro/) [检测到新威胁:深入解析我们对 Log4j 活动及其 XMRig 恶意软件的发现](https://www.uptycs.com/blog/log4j-campaign-xmrig-malware)
标签:使用指南, 安全搜索引擎, 实时处理, 日志审计, 逆向工具, 防御加固