​📦 GitHub 全球红队渗透资源中转站。
​旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
​⚠️ 本频道仅供安全研究与授权测试使用。
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Exploit #CVE

📦 项目名称: blitzstrike
👤 项目作者: shinthink
🛠 开发语言: TypeScript
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-12 13:02:32

📝 项目描述:
⚡ Blitz Strike — a universal MCP security-audit toolbelt. BLITZ sweeps the attack surface, EAGLE-EYE traces source-to-sink, STRIKE verifies live. 57 chains, 130-tool catalog, intelligence data layer. One server, every agent.

🔗 点击访问项目地址 GitHub - shinthink/blitzstrike: ⚡ Blitz Strike — a universal MCP penetration-testing toolbelt. Structured methodology: reconnaissance…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: ai-web-vulnerability-scanner
👤 项目作者: Akhyame
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-12 13:01:38

📝 项目描述:
AI-assisted Python web vulnerability scanner for security analysis, risk scoring, and remediation reporting.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #POC

📦 项目名称: quillshield-submodule-ssrf-poc
👤 项目作者: whozzz988
🛠 开发语言: Solidity
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-12 11:29:47

📝 项目描述:
throwaway PoC repo for authorized pentest - QuillShield engagement

🔗 点击访问项目地址 GitHub - whozzz988/quillshield-submodule-ssrf-poc: throwaway PoC repo for authorized pentest - QuillShield engagement
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #DOM

📦 项目名称: Exploit-Diary
👤 项目作者: Bugatsec
🛠 开发语言: Python
⭐ Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-12 10:27:03

📝 项目描述:
A collection of notes and scripts on web application vulnerabilities, created while learning ethical hacking and practicing on legal labs like PortSwigger. This is part of my personal journey into cybersecurity — built for learners, by a learner.

🔗 点击访问项目地址 GitHub - Bugatsec/Exploit-Diary: A collection of notes and scripts on web application vulnerabilities, created while learning ethical…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #漏洞 #Exploit

📦 项目名称: A58-Exploit
👤 项目作者: RenAhsAcme
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-12 11:08:06

📝 项目描述:
系统披露 A58 存在的网络安全漏洞。

🔗 点击访问项目地址 GitHub - RenAhsAcme/A58-Exploit: 系统披露 A58 存在的网络安全漏洞。
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: CVE-2026-78006-POC
👤 项目作者: DeadExpl0it
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-12 11:42:16

📝 项目描述:
POC for CVE-2026-78006 The Events Calendar <= 6.17.4 - Unauthenticated PHP Object Injection to Remote Code Execution

🔗 点击访问项目地址 GitHub - DeadExpl0it/CVE-2026-78006-POC: POC for CVE-2026-78006 The Events Calendar <= 6.17.4 - Unauthenticated PHP Object Injection…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: burp-autopilot
👤 项目作者: jamaxm
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-12 10:58:50

📝 项目描述:
Professional web vulnerability scanner with Burp Suite integration. 14 checks, async performance, HTML/JSON reports.

🔗 点击访问项目地址 jamaxm/burp-autopilot
🚨 GitHub 监控消息提醒

🚨 发现关键词: #RCE #CVE

📦 项目名称: CVE-2026-86218-N-central-IOC-Toolkit
👤 项目作者: jithinkrishnanrs
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-12 11:04:05

📝 项目描述:
Defensive IOC and detection toolkit for CVE-2026-86218, a critical pre-auth RCE in N-able N-central. Includes IOCs, log scanner, Sigma, Splunk, Elastic/KQL detections, and incident response guidance.

🔗 点击访问项目地址 GitHub - jithinkrishnanrs/CVE-2026-86218-N-central-IOC-Toolkit: Defensive IOC and detection toolkit for CVE-2026-86218, a critical…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Exploit #CVE

📦 项目名称: Binary-Exploitation
👤 项目作者: TheMalwareGuardian
🛠 开发语言: Python
⭐ Star数量: 8 | 🍴 Fork数量: 4
📅 更新时间: 2026-09-12 09:59:12

📝 项目描述:
A hands-on foundation in memory corruption, fuzzing, crash triage, and mitigation bypasses (from lab setup through CVE research to exploit development).

🔗 点击访问项目地址 GitHub - TheMalwareGuardian/Binary-Exploitation: A hands-on foundation in memory corruption, fuzzing, crash triage, and mitigation…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #漏洞 #POC #EXP #RCE #复现

📦 项目名称: All_Stars
👤 项目作者: duskto
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-12 07:24:48

📝 项目描述:
千星计划漏洞挖掘项目

🔗 点击访问项目地址 duskto/All_Stars
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #malware

📦 项目名称: explainable-malware-analyzer
👤 项目作者: BaghdasaryanNarek
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-12 09:49:31

📝 项目描述:
Cloud-native malware analysis engine utilizing Explainable AI (SHAP) and Threat Intelligence. Replaces black-box AV verdicts with forensic reports. Features PE/ELF analysis, YARA heuristics, XGBoost ML, and encrypted quarantine. Built for DevSecOps.

🔗 点击访问项目地址 GitHub - BaghdasaryanNarek/explainable-malware-analyzer: Cloud-native malware analysis engine utilizing Explainable AI (SHAP) and…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #Exploit

📦 项目名称: ghostlock-s26
👤 项目作者: 1ndevelopment
🛠 开发语言: C
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-12 09:35:17

📝 项目描述:
GhostLock (CVE-2026-43499) app for the Galaxy S26 series

🔗 点击访问项目地址 GitHub - 1ndevelopment/ghostlock-s26: GhostLock (CVE-2026-43499) app for the Galaxy S26 series
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #Stored

📦 项目名称: red-blue-ctf-lab
👤 项目作者: christopherbaptista
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-12 09:03:56

📝 项目描述:
Red vs. Blue CTF lab: stored XSS → cookie theft → MFA bypass via session replay, with Blue Team log forensics. Dockerized, single-VM deployment.

🔗 点击访问项目地址 christopherbaptista/red-blue-ctf-lab
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Exploit #CVE

📦 项目名称: AI-exploit-CVE
👤 项目作者: J-Dheeraj
🛠 开发语言: Python
⭐ Star数量: 2 | 🍴 Fork数量: 1
📅 更新时间: 2026-09-12 08:02:07

📝 项目描述:
Experimentation

🔗 点击访问项目地址 GitHub - J-Dheeraj/AI-exploit-CVE: Experimentation
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Bypass #MFA

📦 项目名称: Cyber-Range-Lab
👤 项目作者: DarthWakamiya
🛠 开发语言: JavaScript
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-12 08:03:34

📝 项目描述:
Self-contained Red vs Blue cyber range lab simulating a Cookie Reuse & MFA Bypass vulnerability (XSS session replay) with full attack telemetry for Blue Team forensics.

🔗 点击访问项目地址 GitHub - DarthWakamiya/Cyber-Range-Lab: Self-contained Red vs Blue cyber range lab simulating a Cookie Reuse & MFA Bypass vulnerability…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #渗透测试 #漏洞

📦 项目名称: dsh-pentest
👤 项目作者: baianquanzu
🛠 开发语言: JavaScript
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-12 07:52:40

📝 项目描述:
可恢复的 DSH 渗透测试模式:资产归档、证据复核、断点续跑与 Web 可视化

🔗 点击访问项目地址 GitHub - baianquanzu/dsh-pentest: 可恢复的 DSH 渗透测试模式:资产归档、证据复核、断点续跑与 Web 可视化
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: Agent-of-Death
👤 项目作者: Deaths-Head-Software
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-12 07:43:51

📝 项目描述:
Agent of Death is an AI powered AI Agent vulnerability scanner.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #NTLM Relay #AD

📦 项目名称: mitm6-ipv6-ad-attack
👤 项目作者: mehedi-hasan-sami98
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-12 05:36:19

📝 项目描述:
IPv6 DNS takeover & NTLM relay attack chain in Active Directory using mitm6 — covering DHCPv6 spoofing, LDAP/LDAPS relay, passback attacks, and blue-team defenses.

🔗 点击访问项目地址 GitHub - mehedi-hasan-sami98/mitm6-ipv6-ad-attack: IPv6 DNS takeover & NTLM relay attack chain in Active Directory using mitm6…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #rule

📦 项目名称: gcp-professional-security-operations-engineer-study-guide
👤 项目作者: sifatnotes
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-12 05:22:40

📝 项目描述:
Complete, practical Google Cloud Professional Security Operations Engineer study guide. Features YARA-L detection rule engineering, Google SecOps (SIEM/SOAR) setups, Security Command Center architecture, hands-on labs, a 30-day study roadmap, and exam voucher recommendations.

🔗 点击访问项目地址
Back to Top