explaingit

knownsec/404starlink

10,630Audience · ops devopsComplexity · 1/5Setup · easy

TLDR

A curated, continuously updated catalog of open source security tools maintained by the Knownsec 404 Lab, covering reconnaissance, network scanning, penetration testing, and defensive security for Chinese-speaking researchers.

Mindmap

mindmap
  root((404StarLink))
    What It Is
      Tool catalog
      Curated directory
      Chinese security
    Categories
      Reconnaissance
      Network scanning
      Container pentest
      Defensive tools
      Android analysis
    How It Works
      Weekly updates
      Admission criteria
      Community support
    Audience
      Security researchers
      Pentesters
      Enterprise defenders
Click or tap to explore — scroll the page freely

Code map

Detail Auto

An interactive map of this repo's files and how they connect — its source is parsed live in your browser. Click Visualize to build it.

filefunction / class

Things people build with this

USE CASE 1

Browse the catalog to find actively maintained open source tools for internal network scanning or container penetration testing.

USE CASE 2

Track new security tool releases through the StarLink weekly update log.

USE CASE 3

Discover vetted browser credential extraction or vulnerability scanning tools admitted to the catalog by the 404 Lab team.

Getting it running

Difficulty · easy Time to first run · 5min

In plain English

404 StarLink is a curated directory of open source security tools maintained by the Knownsec 404 Lab, a Chinese cybersecurity research group. The project started in August 2020 with the stated goal of improving the fragmented state of the Chinese security tool ecosystem, where many projects were scattered, inconsistently maintained, and hard to discover. The README is written entirely in Chinese. The repository does not contain tools itself. Instead, it acts as a continuously updated catalog, linking to other repositories and tracking their activity. For each project in the catalog, the 404 StarLink team provides some technical support, monitors for new releases, and surfaces updates to the community. Users can browse the catalog to find tools relevant to their area of interest and ask questions about those tools through the StarLink community channel. The catalog is organized into categories. The top-starred projects at time of writing include tools for extracting browser-stored credentials, internal network scanning, container environment penetration testing, vulnerability scanning with customizable detection rules, and a plugin for the Burp web security testing tool. Other categories listed in the README cover information reconnaissance tools, defensive security tools aimed at enterprise defenders, and tools for Android app privacy compliance analysis. The StarLink index also maintains a weekly update log showing which projects received new releases, and a running list of newly admitted projects with their descriptions. Admission requires the project to be high quality, meaningful, and actively maintained, according to the README's description of selection criteria. This is primarily a reference and community resource for Chinese-speaking security researchers and practitioners rather than a tool to install or run directly.

Copy-paste prompts

Prompt 1
I'm doing a penetration test on a containerized environment. Which tools in the 404StarLink catalog cover container escape or lateral movement inside a container?
Prompt 2
I need a vulnerability scanner with customizable detection rules. What tools in the 404StarLink index provide this capability?
Prompt 3
How is the 404StarLink project organized and what criteria must a security tool meet to be admitted to the catalog?
Prompt 4
I want to analyze an Android app for privacy compliance issues. Which tools in the 404StarLink catalog are relevant for Android app analysis?
Open on GitHub → Explain another repo

← knownsec on gitmyhub — every repo by this author, as a profile.

Verify against the repo before relying on details.