📦 GitHub 全球红队渗透资源中转站。
旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
⚠️ 本频道仅供安全研究与授权测试使用。
旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
⚠️ 本频道仅供安全研究与授权测试使用。
GitHub监控消息提醒!!!
更新了:CVE-2025
描述:Blackash-CVE-2025-57773
URL:https://github.com/B1ack4sh/Blackash-CVE-2025-57773
标签:#CVE-2025
更新了:CVE-2025
描述:Blackash-CVE-2025-57773
URL:https://github.com/B1ack4sh/Blackash-CVE-2025-57773
标签:#CVE-2025
GitHub监控消息提醒!!!
更新了:RCE
描述:A critical remote code execution (RCE) vulnerability (CVE‑2025‑24893) exists in the XWiki Platform, specifically in the SolrSearch RSS feed endpoint.
URL:https://github.com/ibadovulfat/CVE-2025-24893_HackTheBox-Editor-Writeup
标签:#RCE
更新了:RCE
描述:A critical remote code execution (RCE) vulnerability (CVE‑2025‑24893) exists in the XWiki Platform, specifically in the SolrSearch RSS feed endpoint.
URL:https://github.com/ibadovulfat/CVE-2025-24893_HackTheBox-Editor-Writeup
标签:#RCE
GitHub监控消息提醒!!!
更新了:Cobalt Strike
描述:Robust Cobalt Strike shellcode loader with multiple advanced evasion features
URL:https://github.com/Basyaact/CobaltStrikeBeaconDLLSourceLeaked-CSVersion2022-4.5
标签:#Cobalt Strike
更新了:Cobalt Strike
描述:Robust Cobalt Strike shellcode loader with multiple advanced evasion features
URL:https://github.com/Basyaact/CobaltStrikeBeaconDLLSourceLeaked-CSVersion2022-4.5
标签:#Cobalt Strike
GitHub监控消息提醒!!!
更新了:绕过
描述:基于selenium的自动化工具,用于绕过逆向页面加密
URL:https://github.com/wzpro/selenium_burst
标签:#绕过
更新了:绕过
描述:基于selenium的自动化工具,用于绕过逆向页面加密
URL:https://github.com/wzpro/selenium_burst
标签:#绕过
GitHub监控消息提醒!!!
更新了:CVE-2025
描述:PoC for CVE-2025-34030 sar2html 'plot' parameter RCE
URL:https://github.com/HackerTyperAbuser/CVE-2025-34030-PoC
标签:#CVE-2025
更新了:CVE-2025
描述:PoC for CVE-2025-34030 sar2html 'plot' parameter RCE
URL:https://github.com/HackerTyperAbuser/CVE-2025-34030-PoC
标签:#CVE-2025
GitHub监控消息提醒!!!
更新了:渗透测试
描述:提供给网安牛马快速自定义渗透测试工具集GUI的菜鸡项目,可自定义GUI界面大部分是AI,仅供参考
URL:https://github.com/PandaSecNB/SecToolsGUI
标签:#渗透测试
更新了:渗透测试
描述:提供给网安牛马快速自定义渗透测试工具集GUI的菜鸡项目,可自定义GUI界面大部分是AI,仅供参考
URL:https://github.com/PandaSecNB/SecToolsGUI
标签:#渗透测试
GitHub监控消息提醒!!!
更新了:Cobalt Strike
描述:Cobalt Strike 4.x Aggressor Script to assist the Red Team Operator with number/datetime conversions.
URL:https://github.com/SavSanta/numbreaker
标签:#Cobalt Strike
更新了:Cobalt Strike
描述:Cobalt Strike 4.x Aggressor Script to assist the Red Team Operator with number/datetime conversions.
URL:https://github.com/SavSanta/numbreaker
标签:#Cobalt Strike
GitHub监控消息提醒!!!
更新了:绕过
描述:Koishi插件。QQ apk.1 文件重命名,自动处理 .apk.1 文件重命名为 .apk 并封装为 ZIP 压缩包,绕过 QQ 限制
URL:https://github.com/WhiteBr1ck/koishi-plugin-qqapk-renamer
标签:#绕过
更新了:绕过
描述:Koishi插件。QQ apk.1 文件重命名,自动处理 .apk.1 文件重命名为 .apk 并封装为 ZIP 压缩包,绕过 QQ 限制
URL:https://github.com/WhiteBr1ck/koishi-plugin-qqapk-renamer
标签:#绕过
GitHub监控消息提醒!!!
更新了:RCE
描述:🚀 Exploit for Moodle 4.4.0 Authenticated RCE (CVE-2024-43425) — run commands remotely ⚡
URL:https://github.com/aayush256-sys/Moodle-authenticated-RCE
标签:#RCE
更新了:RCE
描述:🚀 Exploit for Moodle 4.4.0 Authenticated RCE (CVE-2024-43425) — run commands remotely ⚡
URL:https://github.com/aayush256-sys/Moodle-authenticated-RCE
标签:#RCE
GitHub监控消息提醒!!!
更新了:CVE-2025
描述:This is POC for IOS 0click CVE-2025-43300
URL:https://github.com/hunters-sec/CVE-2025-43300
标签:#CVE-2025
更新了:CVE-2025
描述:This is POC for IOS 0click CVE-2025-43300
URL:https://github.com/hunters-sec/CVE-2025-43300
标签:#CVE-2025
GitHub监控消息提醒!!!
更新了:弱口令
描述:该项目是一个检测众勤通信设备贸易有限公司ZyXEL-EMG3425-Q10A存在弱口令的脚本
URL:https://github.com/34107/--weakpassword-poc
标签:#弱口令
更新了:弱口令
描述:该项目是一个检测众勤通信设备贸易有限公司ZyXEL-EMG3425-Q10A存在弱口令的脚本
URL:https://github.com/34107/--weakpassword-poc
标签:#弱口令
GitHub监控消息提醒!!!
更新了:漏洞扫描
描述:A Nuclei security scanning server based on MCP (Model Control Protocol), providing convenient vulnerability scanning services.一个基于 MCP (Model Control Protocol) 的 Nuclei 安全扫描服务器,提供便捷的漏洞扫描服务。
URL:https://github.com/crazyMarky/mcp_nuclei_server
标签:#漏洞扫描
更新了:漏洞扫描
描述:A Nuclei security scanning server based on MCP (Model Control Protocol), providing convenient vulnerability scanning services.一个基于 MCP (Model Control Protocol) 的 Nuclei 安全扫描服务器,提供便捷的漏洞扫描服务。
URL:https://github.com/crazyMarky/mcp_nuclei_server
标签:#漏洞扫描
GitHub监控消息提醒!!!
更新了:CVE-2025
描述:POC of CVE-2025-49113
URL:https://github.com/Zwique/CVE-2025-49113
标签:#CVE-2025
更新了:CVE-2025
描述:POC of CVE-2025-49113
URL:https://github.com/Zwique/CVE-2025-49113
标签:#CVE-2025
GitHub监控消息提醒!!!
更新了:代码审计
描述:Fenrir 是一个基于 MCP 协议与 AST 技术的代码审计工具,旨在解决安全研究与自动化代码审计领域中,面对大规模、结构复杂甚至反编译代码时,传统代码搜索与分析手段效率低、准确性差的问题。
URL:https://github.com/ChangeYourWay/Fenrir-CodeAuditTool
标签:#代码审计
更新了:代码审计
描述:Fenrir 是一个基于 MCP 协议与 AST 技术的代码审计工具,旨在解决安全研究与自动化代码审计领域中,面对大规模、结构复杂甚至反编译代码时,传统代码搜索与分析手段效率低、准确性差的问题。
URL:https://github.com/ChangeYourWay/Fenrir-CodeAuditTool
标签:#代码审计
GitHub监控消息提醒!!!
更新了:应急响应
描述:用Go编写的轻量文件监控器. 可以监控终端上指定文件夹内的变化, 阻止删除,修改,新增操作. 可以用于AWD比赛或者终端应急响应
URL:https://github.com/christarcher/0RAYS-AWD-Filechecker
标签:#应急响应
更新了:应急响应
描述:用Go编写的轻量文件监控器. 可以监控终端上指定文件夹内的变化, 阻止删除,修改,新增操作. 可以用于AWD比赛或者终端应急响应
URL:https://github.com/christarcher/0RAYS-AWD-Filechecker
标签:#应急响应