📦 GitHub 全球红队渗透资源中转站。
​旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
⚠️ 本频道仅供安全研究与授权测试使用。
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Credential Dumping #LSASS

📦 项目名称: Cyber-Defense-LSASS-Detection-Lab
👤 项目作者: yusuf-aq
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-01 09:37:51

📝 项目描述:
End-to-end SIEM deployment with custom rule detection for LSASS credential dumping (MITRE T1003.001)

🔗 点击访问项目地址 GitHub - yusuf-aq/Cyber-Defense-LSASS-Detection-Lab: End-to-end SIEM deployment with custom rule detection for LSASS credential…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #metadata

📦 项目名称: mcp-internal-hosts
👤 项目作者: ni-c
🛠 开发语言: TypeScript
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-01 10:49:57

📝 项目描述:
Is this host only reachable from where you stand? Classifies loopback, link-local and cloud-metadata hostnames — numerically, in every spelling

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Burp #Extension

📦 项目名称: TheAlchemist
👤 项目作者: I-blank-I
🛠 开发语言: Java
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-01 10:40:26

📝 项目描述:
Burp extension to tamper HTTP traffic at all 4 proxy pipeline stages with custom Java or Python snippets.

🔗 点击访问项目地址 GitHub - I-blank-I/TheAlchemist: Burp extension to tamper HTTP traffic at all 4 proxy pipeline stages with custom Java or Python…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #渗透测试 #漏洞

📦 项目名称: dsh-pentester
👤 项目作者: fb0sh
🛠 开发语言: TypeScript
Star数量: 6 | 🍴 Fork数量: 2
📅 更新时间: 2026-09-01 10:54:15

📝 项目描述:
基于 DeepSeek Harness 的多 Agent PTES 渗透测试编排插件,支持自动化侦察、漏洞分析、验证与报告,使用 Docker/Kali 隔离工具箱 | Multi-agent PTES penetration testing plugin for DeepSeek Harness with automated recon, vulnerability analysis, validation, reporting, and Docker/Kali toolbox

🔗 点击访问项目地址 GitHub - fb0sh/dsh-pentester
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: CVE-2026-27475
👤 项目作者: Trachinus
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-01 09:24:24

📝 项目描述:
PoC for CVE-2026-27475

🔗 点击访问项目地址 GitHub - Trachinus/CVE-2026-27475: PoC for CVE-2026-27475
Back to Top