📦 GitHub 全球红队渗透资源中转站。
旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
⚠️ 本频道仅供安全研究与授权测试使用。
旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
⚠️ 本频道仅供安全研究与授权测试使用。
GitHub监控消息提醒!!!
更新了:命令注入
描述:JNDIBypass 是一个用于测试 Java JNDI 注入漏洞的工具,可用于安全研究和渗透测试。该工具提供了一个 LDAP 服务器实现,可以用来模拟 JNDI 注入攻击,执行命令或注入内存马。
URL:https://github.com/fb0sh/echout
标签:#命令注入
更新了:命令注入
描述:JNDIBypass 是一个用于测试 Java JNDI 注入漏洞的工具,可用于安全研究和渗透测试。该工具提供了一个 LDAP 服务器实现,可以用来模拟 JNDI 注入攻击,执行命令或注入内存马。
URL:https://github.com/fb0sh/echout
标签:#命令注入
GitHub监控消息提醒!!!
更新了:getshell
描述:This is a Compilation of ueditor exps like file upload 、xss 、ssrf 、getshell
URL:https://github.com/xueba001/ueditor_exp
标签:#getshell
更新了:getshell
描述:This is a Compilation of ueditor exps like file upload 、xss 、ssrf 、getshell
URL:https://github.com/xueba001/ueditor_exp
标签:#getshell
GitHub监控消息提醒!!!
更新了:CVE-2025
描述:This is the exploit for the CVE-2025-32463
URL:https://github.com/Rajneeshkarya/CVE-2025-32463
标签:#CVE-2025
更新了:CVE-2025
描述:This is the exploit for the CVE-2025-32463
URL:https://github.com/Rajneeshkarya/CVE-2025-32463
标签:#CVE-2025
GitHub监控消息提醒!!!
更新了:CVE-2025
描述:Disclosure for CVE-2025-50716 to CVE-2025-50721
URL:https://github.com/MooseLoveti/realestate-php-cve-report
标签:#CVE-2025
更新了:CVE-2025
描述:Disclosure for CVE-2025-50716 to CVE-2025-50721
URL:https://github.com/MooseLoveti/realestate-php-cve-report
标签:#CVE-2025
GitHub监控消息提醒!!!
更新了:渗透测试
描述:GateSentinel 是一个现代化的 C2 (Command and Control) 框架,专为安全研究和渗透测试设计。该项目采用 Go 语言开发服务端,C 语言开发客户端,提供了强大的远程控制和管理功能。
URL:https://github.com/kyxiaxiang/GateSentinel
标签:#渗透测试
更新了:渗透测试
描述:GateSentinel 是一个现代化的 C2 (Command and Control) 框架,专为安全研究和渗透测试设计。该项目采用 Go 语言开发服务端,C 语言开发客户端,提供了强大的远程控制和管理功能。
URL:https://github.com/kyxiaxiang/GateSentinel
标签:#渗透测试
GitHub监控消息提醒!!!
更新了:CVE-2025
描述:CVE-2025-22870
URL:https://github.com/B1ack4sh/Blackash-CVE-2025-22870
标签:#CVE-2025
更新了:CVE-2025
描述:CVE-2025-22870
URL:https://github.com/B1ack4sh/Blackash-CVE-2025-22870
标签:#CVE-2025
GitHub监控消息提醒!!!
更新了:RCE
描述:Non-coding RNA sets Cis Enrichment Tool (NoRCE)
URL:https://github.com/guldenolgun/NoRCE
标签:#RCE
更新了:RCE
描述:Non-coding RNA sets Cis Enrichment Tool (NoRCE)
URL:https://github.com/guldenolgun/NoRCE
标签:#RCE
GitHub监控消息提醒!!!
更新了:CVE-2025
描述:CVE-2025-5777
URL:https://github.com/B1ack4sh/Blackash-CVE-2025-5777
标签:#CVE-2025
更新了:CVE-2025
描述:CVE-2025-5777
URL:https://github.com/B1ack4sh/Blackash-CVE-2025-5777
标签:#CVE-2025
GitHub监控消息提醒!!!
更新了:CVE-2025
描述:CVE-2025-32432
URL:https://github.com/B1ack4sh/Blackash-CVE-2025-32432
标签:#CVE-2025
更新了:CVE-2025
描述:CVE-2025-32432
URL:https://github.com/B1ack4sh/Blackash-CVE-2025-32432
标签:#CVE-2025
GitHub监控消息提醒!!!
更新了:反序列化
描述:基于toml++的TOML文件反序列化便利设施
URL:https://github.com/Anglebase/toml_serde
标签:#反序列化
更新了:反序列化
描述:基于toml++的TOML文件反序列化便利设施
URL:https://github.com/Anglebase/toml_serde
标签:#反序列化
GitHub监控消息提醒!!!
更新了:信息收集
描述:在当今数据驱动的世界中,网页采集已经成为信息收集、商业监控、市场分析等多个行业的核心工具。然而,许多开发者在实践中都会遭遇同一个噩梦:**IP 被封、请求被阻、系统崩溃**。
URL:https://github.com/LunaNova88/pachong-fengsuo-yu-bengkui-weishenme-wangye-caiji-xuyao-geng-congming-de-celue
标签:#信息收集
更新了:信息收集
描述:在当今数据驱动的世界中,网页采集已经成为信息收集、商业监控、市场分析等多个行业的核心工具。然而,许多开发者在实践中都会遭遇同一个噩梦:**IP 被封、请求被阻、系统崩溃**。
URL:https://github.com/LunaNova88/pachong-fengsuo-yu-bengkui-weishenme-wangye-caiji-xuyao-geng-congming-de-celue
标签:#信息收集
GitHub监控消息提醒!!!
更新了:CVE-2025
描述:This repository contains POC scenarios as part of CVE-2025-0411 MotW bypass.
URL:https://github.com/absholi7ly/CVE-2025-27210_NodeJS_Path_Traversal_Exploit
标签:#CVE-2025
更新了:CVE-2025
描述:This repository contains POC scenarios as part of CVE-2025-0411 MotW bypass.
URL:https://github.com/absholi7ly/CVE-2025-27210_NodeJS_Path_Traversal_Exploit
标签:#CVE-2025
GitHub监控消息提醒!!!
更新了:RCE
描述:ThinVNC 1.0b1 - Authentication Bypass to RCE
URL:https://github.com/krill-x7/CVE-2022-25226
标签:#RCE
更新了:RCE
描述:ThinVNC 1.0b1 - Authentication Bypass to RCE
URL:https://github.com/krill-x7/CVE-2022-25226
标签:#RCE
GitHub监控消息提醒!!!
更新了:免杀
描述:工具推荐-免杀-二开一个漏洞扫描、目录扫描、端口扫描的工具
URL:https://github.com/Zer08Bytes/GhostRecon
标签:#免杀
更新了:免杀
描述:工具推荐-免杀-二开一个漏洞扫描、目录扫描、端口扫描的工具
URL:https://github.com/Zer08Bytes/GhostRecon
标签:#免杀
GitHub监控消息提醒!!!
更新了:RCE
描述:Secure, open-source RCE platform with Docker isolation, JWT auth, rate limiting, and multi-language support.
URL:https://github.com/vikashkrdeveloper/SafeExec
标签:#RCE
更新了:RCE
描述:Secure, open-source RCE platform with Docker isolation, JWT auth, rate limiting, and multi-language support.
URL:https://github.com/vikashkrdeveloper/SafeExec
标签:#RCE
GitHub监控消息提醒!!!
更新了:CVE-2025
描述:Working exploit for CVE-2025-23167 – HTTP request smuggling in vulnerable Node.js 20.x versions before 20.19.2
URL:https://github.com/abhisek3122/CVE-2025-23167
标签:#CVE-2025
更新了:CVE-2025
描述:Working exploit for CVE-2025-23167 – HTTP request smuggling in vulnerable Node.js 20.x versions before 20.19.2
URL:https://github.com/abhisek3122/CVE-2025-23167
标签:#CVE-2025
GitHub监控消息提醒!!!
更新了:漏洞挖掘
描述:漏洞赏金工具是一款专为安全研究人员和白帽子黑客设计的图形化渗透测试工具集。它集成了多个常用的安全测试工具,提供了直观的用户界面,让漏洞挖掘变得更加简单和高效。
URL:https://github.com/hengweijieke/drearm_hw
标签:#漏洞挖掘
更新了:漏洞挖掘
描述:漏洞赏金工具是一款专为安全研究人员和白帽子黑客设计的图形化渗透测试工具集。它集成了多个常用的安全测试工具,提供了直观的用户界面,让漏洞挖掘变得更加简单和高效。
URL:https://github.com/hengweijieke/drearm_hw
标签:#漏洞挖掘