Browse the catalog to find actively maintained open source tools for internal network scanning or container penetration testing.
Track new security tool releases through the StarLink weekly update log.
Discover vetted browser credential extraction or vulnerability scanning tools admitted to the catalog by the 404 Lab team.
404 StarLink is a curated directory of open source security tools maintained by the Knownsec 404 Lab, a Chinese cybersecurity research group. The project started in August 2020 with the stated goal of improving the fragmented state of the Chinese security tool ecosystem, where many projects were scattered, inconsistently maintained, and hard to discover. The README is written entirely in Chinese. The repository does not contain tools itself. Instead, it acts as a continuously updated catalog, linking to other repositories and tracking their activity. For each project in the catalog, the 404 StarLink team provides some technical support, monitors for new releases, and surfaces updates to the community. Users can browse the catalog to find tools relevant to their area of interest and ask questions about those tools through the StarLink community channel. The catalog is organized into categories. The top-starred projects at time of writing include tools for extracting browser-stored credentials, internal network scanning, container environment penetration testing, vulnerability scanning with customizable detection rules, and a plugin for the Burp web security testing tool. Other categories listed in the README cover information reconnaissance tools, defensive security tools aimed at enterprise defenders, and tools for Android app privacy compliance analysis. The StarLink index also maintains a weekly update log showing which projects received new releases, and a running list of newly admitted projects with their descriptions. Admission requires the project to be high quality, meaningful, and actively maintained, according to the README's description of selection criteria. This is primarily a reference and community resource for Chinese-speaking security researchers and practitioners rather than a tool to install or run directly.
← knownsec on gitmyhub — every repo by this author, as a profile.
Verify against the repo before relying on details.