​📦 GitHub 全球红队渗透资源中转站。
​旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
​⚠️ 本频道仅供安全研究与授权测试使用。
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC #RCE

📦 项目名称: CVE-2026-41089-Netlogon-RCE-PoC
👤 项目作者: SyntaxMethod
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-11 10:43:55

📝 项目描述:
Description: Unauthenticated Netlogon RCE vulnerability scanner & PoC research for CVE-2026-41089 (CVSS 9.8). Integrated module for AI Security Tool.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Burp #Extension

📦 项目名称: burp-games
👤 项目作者: enochgitgamefied
🛠 开发语言: Java
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-11 09:59:18

📝 项目描述:
无描述

🔗 点击访问项目地址 GitHub - enochgitgamefied/burp-games
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: tugtainer-PoC
👤 项目作者: squeeze440
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-11 09:52:13

📝 项目描述:
PoC — OIDC id_token accepted without signature/audience/expiry check in Tugtainer (GHSA-crjc-6vc7-xrfh, CVE-2026-87004, CVSS 8.1).

🔗 点击访问项目地址 GitHub - squeeze440/tugtainer-PoC: PoC — OIDC id_token accepted without signature/audience/expiry check in Tugtainer (GHSA-crjc…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: zotlit-PoC
👤 项目作者: squeeze440
🛠 开发语言: JavaScript
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-11 09:52:18

📝 项目描述:
PoC — attachment import copies files from unapproved local paths in ZotLit (GHSA-4qh7-66xv-h329, CVE-2026-87000, CVSS 5.5).

🔗 点击访问项目地址 GitHub - squeeze440/zotlit-PoC: PoC — attachment import copies files from unapproved local paths in ZotLit (GHSA-4qh7-66xv-h329…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #metadata

📦 项目名称: mcrta-gcp-redteam
👤 项目作者: alorentiar
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-11 08:51:48

📝 项目描述:
Red team write-up & tooling: GCP cloud exploitation lab (mcrta-exam) — leaked SA key → .git exposure → SSRF/RCE → metadata token theft → Cloud Storage bucket enumeration

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: Basic-Vulnerability-Scanner-
👤 项目作者: arjunbhardwaj19
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-11 08:39:30

📝 项目描述:
A simple beginner-level vulnerability scanner developed checking a website for commonly used security-related issues.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #DOM

📦 项目名称: XSS_DOM_TRADINGVIEW
👤 项目作者: Hack-Oeil
🛠 开发语言: HTML
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-11 07:28:29

📝 项目描述:
Premier CTF en XSS DOM

🔗 点击访问项目地址 GitHub - Hack-Oeil/XSS_DOM_TRADINGVIEW: Premier CTF en XSS DOM
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #Stored

📦 项目名称: CRLF_XSS_STORED_SESSION
👤 项目作者: Hack-Oeil
🛠 开发语言: CSS
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-11 07:31:14

📝 项目描述:
Du CRLF du XSS Stored et un vol de session.

🔗 点击访问项目地址 GitHub - Hack-Oeil/CRLF_XSS_STORED_SESSION: Du CRLF du XSS Stored et un vol de session.
🚨 GitHub 监控消息提醒

🚨 发现关键词: #漏洞 #扫描

📦 项目名称: whh_scan
👤 项目作者: whhcraft
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-11 07:17:14

📝 项目描述:
轻量漏洞扫描工具

🔗 点击访问项目地址 GitHub - whhcraft/whh_scan: 轻量漏洞扫描工具
🚨 GitHub 监控消息提醒

🚨 发现关键词: #云安全 #云原生

📦 项目名称: cloud-security-learning
👤 项目作者: lychee27z
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-11 07:33:54

📝 项目描述:
云安全与AI基础设施学习平台:隐私计算、密钥管理、云原生等模块化学习网站

🔗 点击访问项目地址 GitHub - lychee27z/cloud-security-learning: 云安全与AI基础设施学习平台:隐私计算、密钥管理、云原生等模块化学习网站
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Jenkins #POC

📦 项目名称: jenkins-shared-library
👤 项目作者: princehann
🛠 开发语言: Groovy
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-11 07:56:32

📝 项目描述:
POC CI/CD with Jenkins

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #C2 #Framework

📦 项目名称: Rshell-web
👤 项目作者: Rubby2001
🛠 开发语言: Vue
⭐ Star数量: 32 | 🍴 Fork数量: 42
📅 更新时间: 2026-09-11 07:59:39

📝 项目描述:
Web console for the Rshell C2 framework — Vue 3 + TypeScript + Element Plus

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Exploit #RCE

📦 项目名称: bexploit
👤 项目作者: bbaobaob
🛠 开发语言: Objective-C
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-11 06:58:59

📝 项目描述:
bexploit — kernel R/W exploit for iOS 27 beta 1-4 (24A5390f) — full filesystem access

🔗 点击访问项目地址 GitHub - bbaobaob/bexploit: bexploit — kernel R/W exploit for iOS 27 beta 1-4 (24A5390f) — full filesystem access
🚨 GitHub 监控消息提醒

🚨 发现关键词: #漏洞 #POC #Exploit #扫描 #利用 #Nuclei #CVE

📦 项目名称: SRCTOOLS
👤 项目作者: 99-sketch
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-11 07:02:24

📝 项目描述:
SRC漏洞挖掘器

🔗 点击访问项目地址 GitHub - 99-sketch/SRCTOOLS: SRC漏洞挖掘器
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: CVE-2026-82222-PoC
👤 项目作者: sajjadsiam
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-11 06:59:12

📝 项目描述:
无描述

🔗 点击访问项目地址 GitHub - sajjadsiam/CVE-2026-82222-PoC
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Nuclei #CVE

📦 项目名称: Vulnerability-Management-Platform
👤 项目作者: KshitizSadh
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-11 05:15:59

📝 项目描述:
Automated Vulnerability Management: Nmap+Nuclei, CVE/CVSS risk prioritization, SIEM/SOAR, remediation verification

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: vuln-scanner
👤 项目作者: persie-alt
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-11 04:46:05

📝 项目描述:
Python vulnerability scanner - portfolio project

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #漏洞 #云元数据 #metadata

📦 项目名称: scrapling-mcp
👤 项目作者: zouzhengshi
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-11 05:03:27

📝 项目描述:
面向 AI Agent 的安全通用网页抓取 MCP 服务,基于 Crawl4AI 与 Scrapling,支持双引擎、批量抓取、正文提取和 SSRF 防护。 Secure, bounded web scraping MCP server for AI Agents, powered by Crawl4AI and Scrapling.

🔗 点击访问项目地址 GitHub - zouzhengshi/scrapling-mcp: 面向 AI Agent 的安全通用网页抓取 MCP 服务,基于 Crawl4AI 与 Scrapling,支持双引擎、批量抓取、正文提取和 SSRF 防护。 Secure, bounded…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Bypass #Sandbox

📦 项目名称: agent-egress-proxies
👤 项目作者: wanhutiger
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-11 04:01:33

📝 项目描述:
67 public URL proxies used by autonomous agents to bypass sandbox egress allowlists - measured from a public forensic corpus of 14,591 agent edits

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #Exploit #RCE

📦 项目名称: Exploit-CVE-2026-18351
👤 项目作者: ChiefYoru
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-11 03:30:49

📝 项目描述:
Drag and Drop File Upload for Elementor Forms - Unauthenticated Arbitrary File Upload to RCE.🔥

🔗 点击访问项目地址 GitHub - ChiefYoru/Exploit-CVE-2026-18351: Drag and Drop File Upload for Elementor Forms - Unauthenticated Arbitrary File Upload…
Back to Top