📦 GitHub 全球红队渗透资源中转站。
旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
⚠️ 本频道仅供安全研究与授权测试使用。
旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
⚠️ 本频道仅供安全研究与授权测试使用。
GitHub监控消息提醒!!!
更新了:CVE-2025
描述:Remote Code Execution via Use-After-Free in JScript.dll (CVE-2025-30397)
URL:https://github.com/mbanyamer/CVE-2025-30397---Windows-Server-2025-JScript-RCE-Use-After-Free-
标签:#CVE-2025
更新了:CVE-2025
描述:Remote Code Execution via Use-After-Free in JScript.dll (CVE-2025-30397)
URL:https://github.com/mbanyamer/CVE-2025-30397---Windows-Server-2025-JScript-RCE-Use-After-Free-
标签:#CVE-2025
GitHub监控消息提醒!!!
更新了:RCE
描述:CVE-2025-20188: Unauthenticated RCE in Cisco IOS XE WLC via Hard-Coded JWT
URL:https://github.com/voyagken/CVE-2025-20188
标签:#RCE
更新了:RCE
描述:CVE-2025-20188: Unauthenticated RCE in Cisco IOS XE WLC via Hard-Coded JWT
URL:https://github.com/voyagken/CVE-2025-20188
标签:#RCE
GitHub监控消息提醒!!!
更新了:RCE
描述:Peyara Remote Mouse v2.0.0- Remote Code Execution (RCE)
URL:https://github.com/capture0x/Peyara
标签:#RCE
更新了:RCE
描述:Peyara Remote Mouse v2.0.0- Remote Code Execution (RCE)
URL:https://github.com/capture0x/Peyara
标签:#RCE
GitHub监控消息提醒!!!
更新了:代码审计
描述:运维管理平台(agent端代码) ,平台是集轻量化、极简操作、高效运维为一体的智能运维平台,具备纳管、监控、巡检、自愈、支持异构网络环境、秒级执行运维作业、多云管理,运维工单、k8s集群管理,webshell,安全审计,堡垒机等功能。
URL:https://github.com/wylok/opsone-dog
标签:#代码审计
更新了:代码审计
描述:运维管理平台(agent端代码) ,平台是集轻量化、极简操作、高效运维为一体的智能运维平台,具备纳管、监控、巡检、自愈、支持异构网络环境、秒级执行运维作业、多云管理,运维工单、k8s集群管理,webshell,安全审计,堡垒机等功能。
URL:https://github.com/wylok/opsone-dog
标签:#代码审计
GitHub监控消息提醒!!!
更新了:RCE
描述:ScadaFlare Authenticated RCE Exploit Framework for ScadaBR (CVE-2021-26828) OpenPLC ScadaBR
URL:https://github.com/ridpath/CVE-2021-26828-Ultimate
标签:#RCE
更新了:RCE
描述:ScadaFlare Authenticated RCE Exploit Framework for ScadaBR (CVE-2021-26828) OpenPLC ScadaBR
URL:https://github.com/ridpath/CVE-2021-26828-Ultimate
标签:#RCE
GitHub监控消息提醒!!!
更新了:CVE-2025
描述:CVE-2025-5328 – Path Traversal in chshcms mccms 2.7
URL:https://github.com/voyagken/CVE-2025-5328
标签:#CVE-2025
更新了:CVE-2025
描述:CVE-2025-5328 – Path Traversal in chshcms mccms 2.7
URL:https://github.com/voyagken/CVE-2025-5328
标签:#CVE-2025
GitHub监控消息提醒!!!
更新了:CVE-2025
描述:PoC of CVE-2025-46204
URL:https://github.com/spbavarva/CVE-2025-46204
标签:#CVE-2025
更新了:CVE-2025
描述:PoC of CVE-2025-46204
URL:https://github.com/spbavarva/CVE-2025-46204
标签:#CVE-2025
GitHub监控消息提醒!!!
更新了:RCE
描述:RCE in backdrop_CMS using module features.
URL:https://github.com/Goultarde/Backdrop_CMS_1.27.1_RCE
标签:#RCE
更新了:RCE
描述:RCE in backdrop_CMS using module features.
URL:https://github.com/Goultarde/Backdrop_CMS_1.27.1_RCE
标签:#RCE
GitHub监控消息提醒!!!
更新了:RCE
描述:RustFly v2.0.0- Remote Code Execution (RCE)
URL:https://github.com/capture0x/RustFly-RCE
标签:#RCE
更新了:RCE
描述:RustFly v2.0.0- Remote Code Execution (RCE)
URL:https://github.com/capture0x/RustFly-RCE
标签:#RCE
GitHub监控消息提醒!!!
更新了:bypassav
描述:免杀shellcode加载器
URL:https://github.com/MentalityXt/bypassAV
标签:#bypassav
更新了:bypassav
描述:免杀shellcode加载器
URL:https://github.com/MentalityXt/bypassAV
标签:#bypassav
GitHub监控消息提醒!!!
更新了:CVE-2025
描述:vulnerable-nextjs-14-CVE-2025-29927
URL:https://github.com/SugiB3o/vulnerable-nextjs-14-CVE-2025-29927
标签:#CVE-2025
更新了:CVE-2025
描述:vulnerable-nextjs-14-CVE-2025-29927
URL:https://github.com/SugiB3o/vulnerable-nextjs-14-CVE-2025-29927
标签:#CVE-2025
GitHub监控消息提醒!!!
更新了:CVE-2025
描述:PoC of CVE-2025-46203
URL:https://github.com/spbavarva/CVE-2025-46203
标签:#CVE-2025
更新了:CVE-2025
描述:PoC of CVE-2025-46203
URL:https://github.com/spbavarva/CVE-2025-46203
标签:#CVE-2025
GitHub监控消息提醒!!!
更新了:RCE
描述:RCE PSE - Rynkowa Cena Energii for HomeAssistant
URL:https://github.com/Lewa-Reka/ha-rce-pse
标签:#RCE
更新了:RCE
描述:RCE PSE - Rynkowa Cena Energii for HomeAssistant
URL:https://github.com/Lewa-Reka/ha-rce-pse
标签:#RCE
GitHub监控消息提醒!!!
更新了:红蓝对抗
描述:Vue-Attack-Defense-Admin-Master 是一个结合 Wazuh 和 人脸识别验证 技术的 红蓝对抗与网络安全事件监控展示平台。该项目旨在为用户提供一个集成化、安全性高、可视化友好的网络安全管理系统,主要用于支持网络攻防对抗及事件监控场景。
URL:https://github.com/NutMilk0612/vue-attack-defense-admin-master
标签:#红蓝对抗
更新了:红蓝对抗
描述:Vue-Attack-Defense-Admin-Master 是一个结合 Wazuh 和 人脸识别验证 技术的 红蓝对抗与网络安全事件监控展示平台。该项目旨在为用户提供一个集成化、安全性高、可视化友好的网络安全管理系统,主要用于支持网络攻防对抗及事件监控场景。
URL:https://github.com/NutMilk0612/vue-attack-defense-admin-master
标签:#红蓝对抗
GitHub监控消息提醒!!!
更新了:渗透测试
描述:G700RAT 是一款为 Android 设备设计的强大远程管理工具(RAT),专为网络安全研究人员、渗透测试人员和红队专家而开发。该工具仅适用于获得授权的合法环境中,用于测试、研究和演示用途。
URL:https://github.com/g700rats/-G700RAT-
标签:#渗透测试
更新了:渗透测试
描述:G700RAT 是一款为 Android 设备设计的强大远程管理工具(RAT),专为网络安全研究人员、渗透测试人员和红队专家而开发。该工具仅适用于获得授权的合法环境中,用于测试、研究和演示用途。
URL:https://github.com/g700rats/-G700RAT-
标签:#渗透测试
GitHub监控消息提醒!!!
更新了:RCE
描述:Updated exploit for CVE-2021-22911 (Rocket.Chat 3.12.1 - NoSQL Injection to RCE (Unauthenticated))
URL:https://github.com/octodi/CVE-2021-22911
标签:#RCE
更新了:RCE
描述:Updated exploit for CVE-2021-22911 (Rocket.Chat 3.12.1 - NoSQL Injection to RCE (Unauthenticated))
URL:https://github.com/octodi/CVE-2021-22911
标签:#RCE
GitHub监控消息提醒!!!
更新了:护网
描述:护网期间或日常运维期间,运维人员或网络安全人员使用的网站内容安全 + 实时监测告警工具
URL:https://github.com/Zer08Bytes/SentinelSite
标签:#护网
更新了:护网
描述:护网期间或日常运维期间,运维人员或网络安全人员使用的网站内容安全 + 实时监测告警工具
URL:https://github.com/Zer08Bytes/SentinelSite
标签:#护网
GitHub监控消息提醒!!!
更新了:CVE-2025
描述:the information for the vulnerability covered by CVE-2025-29632
URL:https://github.com/OHnogood/CVE-2025-29632
标签:#CVE-2025
更新了:CVE-2025
描述:the information for the vulnerability covered by CVE-2025-29632
URL:https://github.com/OHnogood/CVE-2025-29632
标签:#CVE-2025