📦 GitHub 全球红队渗透资源中转站。
​旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
⚠️ 本频道仅供安全研究与授权测试使用。
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC #RCE

📦 项目名称: wp2shell
👤 项目作者: mcipekci
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-22 10:58:52

📝 项目描述:
Pre-auth RCE PoC for WordPress core — chains CVE-2026-63030 (REST /batch/v1 route-confusion desync) with CVE-2026-60137 (author__not_in SQLi) into an unauthenticated shell. Authorized testing only.

🔗 点击访问项目地址 GitHub - mcipekci/wp2shell: Pre-auth RCE PoC for WordPress core — chains CVE-2026-63030 (REST /batch/v1 route-confusion desync)…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #POC #CVE

📦 项目名称: CVE-2026-55994
👤 项目作者: oscerd
🛠 开发语言: Java
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-22 10:04:11

📝 项目描述:
PoC reproducer for CVE-2026-55994 (Apache Camel camel-iggy): the consumer copies an Iggy message's user-headers onto the Exchange unfiltered, so an injected CamelHttpUri drives a server-side request (SSRF) and leaks resolved property placeholders. Fixed in 4.18.3/4.21.0.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Fastjson #EXP

📦 项目名称: fastjson1.2.66-1.2.83-Exploit-tool
👤 项目作者: BdYyWrez
🛠 开发语言: Python
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-22 09:42:31

📝 项目描述:
无描述

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Exploit #RCE

📦 项目名称: AR-GhostNet
👤 项目作者: rickrana077-lgtm
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-22 09:59:27

📝 项目描述:
AR-GhostNet` is a high-performance, modular network reconnaissance and exploitation framework. Designed for stealth, speed, and precision, it integrates adaptive payloading and advanced network fingerprinting to bypass modern security layers. Built for those who operate in the shadows. 💀

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #红蓝对抗 #靶场

📦 项目名称: xuandun-cyber-range
👤 项目作者: TrueFurina
🛠 开发语言: JavaScript
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-22 09:49:27

📝 项目描述:
玄盾 XUANDUN · AI 攻防靶场系统 — 面向红蓝对抗训练的 AI 攻防靶场 / 多智能体强化学习

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Burp #Extension

📦 项目名称: rolebreaker
👤 项目作者: Guarina0x0
🛠 开发语言: Kotlin
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-22 09:47:01

📝 项目描述:
Burp Suite extension for JWT multi-role broken access control testing — auto-discovery, access matrix, privilege hierarchy, JWT attacks, HMAC cracker, IDOR analysis

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: CVE-2026-55993
👤 项目作者: oscerd
🛠 开发语言: Java
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-22 09:15:09

📝 项目描述:
PoC reproducer for CVE-2026-55993 (Apache Camel camel-atmosphere-websocket): the WebSocket consumer copies connection query parameters onto the Exchange unfiltered, so an injected CamelHttpUri drives a server-side request (SSRF) and leaks resolved property placeholders. Fixed in 4.14.8/4.18.3/4.21.0.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Shellcode #AV

📦 项目名称: shellcod_encoder
👤 项目作者: Wissemben84
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-22 08:27:03

📝 项目描述:
a python script for encoding shellcode, and then adding it to the syntax script files in C for bypassing AV 2026

🔗 点击访问项目地址 GitHub - Wissemben84/shellcod_encoder: a python script for encoding shellcode, and then adding it to the syntax script files in…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #metadata

📦 项目名称: ocular
👤 项目作者: guatxlabs
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-22 08:51:45

📝 项目描述:
Moteur de capture et d'analyse web durci : recon anti-bot, analyse de HTML hostile, sessions interactives isolées. Séparation de privilèges, conteneurs éphémères, garde SSRF.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #metadata

📦 项目名称: laravel-ssrf
👤 项目作者: securized
🛠 开发语言: PHP
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-22 08:59:25

📝 项目描述:
SSRF prevention for Laravel. Protect Http::, Guzzle, and validate user-supplied URLs against server-side request forgery.

🔗 点击访问项目地址 GitHub - securized/laravel-ssrf: SSRF prevention for Laravel. Protect Http::, Guzzle, and validate user-supplied URLs against server…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: login-fish-scanner
👤 项目作者: mailsaiat96-beep
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-22 07:56:47

📝 项目描述:
An automated DAST tool for identifying authentication vulnerabilities

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: AI-Powered-Code-Vulnerability-Scanner
👤 项目作者: bhargavismiley314-cpu
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-22 08:29:54

📝 项目描述:
Automated static code analysis and security vulnerability scanner using Python AST.

🔗 点击访问项目地址 GitHub - bhargavismiley314-cpu/AI-Powered-Code-Vulnerability-Scanner: Automated static code analysis and security vulnerability…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Nuclei #template

📦 项目名称: m2nGAN
👤 项目作者: chiellini
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-22 08:27:46

📝 项目描述:
Real fluorescence membrane to pseudo nuclei image for cell lineage tracing

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Exploit #CVE

📦 项目名称: epss-cve-feed
👤 项目作者: novadyne-hq
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-22 08:46:33

📝 项目描述:
A free, machine-readable feed of notable open-source dependency CVEs ranked by live EPSS exploit-probability (FIRST.org, daily). Pure-stdlib Python.

🔗 点击访问项目地址 GitHub - novadyne-hq/epss-cve-feed: A free, machine-readable feed of notable open-source dependency CVEs ranked by live EPSS exploit…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #钓鱼 #邮件 #Phishing

📦 项目名称: phishing-trainer
👤 项目作者: EarthOnline0115
🛠 开发语言: HTML
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-22 07:56:36

📝 项目描述:
钓鱼邮件鉴别训练营

🔗 点击访问项目地址 GitHub - EarthOnline0115/phishing-trainer: 钓鱼邮件鉴别训练营
🚨 GitHub 监控消息提醒

🚨 发现关键词: #RCE #POC

📦 项目名称: Fastjson_RCE_POC
👤 项目作者: FishOfDead
🛠 开发语言: Java
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-22 07:53:44

📝 项目描述:
Fastjson_RCE_POC

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Burp #插件 #渗透

📦 项目名称: Aipentest-burp
👤 项目作者: nmcp0114
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-22 07:28:10

📝 项目描述:
burpsuite的AI渗透插件demo

🔗 点击访问项目地址
Back to Top