📦 GitHub 全球红队渗透资源中转站。
​旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
⚠️ 本频道仅供安全研究与授权测试使用。
🚨 GitHub 监控消息提醒

🚨 发现关键词: #钓鱼 #红队

📦 项目名称: phish-login
👤 项目作者: nihaodg
🛠 开发语言: PHP
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-22 13:54:25

📝 项目描述:
红队钓鱼网站复刻生成skill,生成钓鱼网站

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #漏洞 #利用

📦 项目名称: fastjson1.8.23
👤 项目作者: Easy-Debug
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-22 13:54:44

📝 项目描述:
fastjson-1.2.83-gadget-rce漏洞利用工具

🔗 点击访问项目地址 GitHub - Easy-Debug/fastjson1.8.23: fastjson-1.2.83-gadget-rce漏洞利用工具
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #rule

📦 项目名称: yara-tester
👤 项目作者: janderik
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-22 13:15:35

📝 项目描述:
Fast YARA rule validation and testing. Check syntax, test against files, detect common issues.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #malware

📦 项目名称: Windows-Malware-Analysis-Lab
👤 项目作者: aaditya-w
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-22 14:00:20

📝 项目描述:
Windows malware analysis lab built with VirtualBox. Demonstrates static analysis of an AgentTesla sample using PEStudio, Detect It Easy, YARA, Strings, and VirusTotal.

🔗 点击访问项目地址 GitHub - aaditya-w/Windows-Malware-Analysis-Lab: Windows malware analysis lab built with VirtualBox. Demonstrates static analysis…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #DOM

📦 项目名称: reflex
👤 项目作者: EuanSmith2
🛠 开发语言: Python
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-22 13:28:24

📝 项目描述:
Educational Python toolkit for discovering and understanding common web vulnerabilities: XSS, open redirects, DOM XSS, mutation fuzzing.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: wp2shell-poc-fulljs
👤 项目作者: raphy76
🛠 开发语言: HTML
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-22 13:31:45

📝 项目描述:
full javascript reproduction of CVE-2026-63030 (author_exclude, author__not_in and misalignment between validations and matches)

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Kubernetes #POC

📦 项目名称: poc_kubernetes
👤 项目作者: nblinpro
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-22 12:07:08

📝 项目描述:
无描述

🔗 点击访问项目地址 GitHub - nblinpro/poc_kubernetes
🚨 GitHub 监控消息提醒

🚨 发现关键词: #C2 #Framework

📦 项目名称: nd073-c2-Dental-Office-Virtual-Assistant
👤 项目作者: arindam-banerjee-2021
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-22 12:58:08

📝 项目描述:
无描述

🔗 点击访问项目地址 GitHub - arindam-banerjee-2021/nd073-c2-Dental-Office-Virtual-Assistant
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #metadata

📦 项目名称: ssrfguard
👤 项目作者: varunmahajan1
🛠 开发语言: Go
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-22 12:06:12

📝 项目描述:
SSRF-safe HTTP fetching for Go — resolved-IP dial guard that defeats DNS rebinding. Blocks metadata endpoints, private ranges, loopback. Zero dependencies.

🔗 点击访问项目地址 GitHub - varunmahajan1/ssrfguard: SSRF-safe HTTP fetching for Go — resolved-IP dial guard that defeats DNS rebinding. Blocks metadata…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: LangGraph-SAST-CICD
👤 项目作者: varkeymjohn
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-22 12:46:52

📝 项目描述:
AI vulnerability scanner for CI/CD

🔗 点击访问项目地址 GitHub - varkeymjohn/LangGraph-SAST-CICD: AI vulnerability scanner for CI/CD
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #RCE

📦 项目名称: wp2shell-vulnerability-scanner
👤 项目作者: Adrees-Basheer
🛠 开发语言: Shell
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-22 12:34:49

📝 项目描述:
Scan WordPress installations for wp2shell vulnerabilities (CVE-2026-63030 + CVE-2026-60137). Identifies full RCE and SQL injection risks across multiple sites with severity classification and CSV reporting.

🔗 点击访问项目地址 GitHub - Adrees-Basheer/wp2shell-vulnerability-scanner: Scan WordPress installations for wp2shell vulnerabilities (CVE-2026-63030…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Exchange #POC

📦 项目名称: StockX-POC
👤 项目作者: technicalpro
🛠 开发语言: TypeScript
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-22 12:01:51

📝 项目描述:
StockX is a decentralized, AI-powered stock exchange platform designed to enable secure, transparent, and near-real-time trading of tokenized equities.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #malware

📦 项目名称: Malware-Analysis-Using-LitterBox
👤 项目作者: jayaprasath05
🛠 开发语言: YARA
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-22 10:49:09

📝 项目描述:
Developed a malware analysis web application using Python, Flask, Docker, and YARA. Implemented secure file uploads, automated malware scanning, detection scoring, and detailed report generation while creating a responsive and user-friendly interface for cybersecurity analysis.

🔗 点击访问项目地址 GitHub - jayaprasath05/Malware-Analysis-Using-LitterBox: Developed a malware analysis web application using Python, Flask, Docker…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Exploit #RCE #POC

📦 项目名称: oscommerce-2.3.4-rce
👤 项目作者: raikoho
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-22 10:58:58

📝 项目描述:
POC Exploit for oscommerce-2.3.4

🔗 点击访问项目地址 GitHub - raikoho/oscommerce-2.3.4-rce: POC Exploit for oscommerce-2.3.4
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: CVE-2026-56139
👤 项目作者: oscerd
🛠 开发语言: Java
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-22 10:39:25

📝 项目描述:
PoC reproducer for CVE-2026-56139 (Apache Camel camel-undertow Rest DSL): the Rest DSL binding hard-codes muteException=false, so a configured muteException=true is ignored and an uncaught exception's full stack trace is returned to the client (CWE-209). Fixed in 4.14.8/4.18.3/4.21.0.

🔗 点击访问项目地址 GitHub - oscerd/CVE-2026-56139: PoC reproducer for CVE-2026-56139 (Apache Camel camel-undertow Rest DSL): the Rest DSL binding…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC #RCE

📦 项目名称: wp2shell
👤 项目作者: mcipekci
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-22 10:58:52

📝 项目描述:
Pre-auth RCE PoC for WordPress core — chains CVE-2026-63030 (REST /batch/v1 route-confusion desync) with CVE-2026-60137 (author__not_in SQLi) into an unauthenticated shell. Authorized testing only.

🔗 点击访问项目地址 GitHub - mcipekci/wp2shell: Pre-auth RCE PoC for WordPress core — chains CVE-2026-63030 (REST /batch/v1 route-confusion desync)…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #POC #CVE

📦 项目名称: CVE-2026-55994
👤 项目作者: oscerd
🛠 开发语言: Java
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-22 10:04:11

📝 项目描述:
PoC reproducer for CVE-2026-55994 (Apache Camel camel-iggy): the consumer copies an Iggy message's user-headers onto the Exchange unfiltered, so an injected CamelHttpUri drives a server-side request (SSRF) and leaks resolved property placeholders. Fixed in 4.18.3/4.21.0.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Fastjson #EXP

📦 项目名称: fastjson1.2.66-1.2.83-Exploit-tool
👤 项目作者: BdYyWrez
🛠 开发语言: Python
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-22 09:42:31

📝 项目描述:
无描述

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Exploit #RCE

📦 项目名称: AR-GhostNet
👤 项目作者: rickrana077-lgtm
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-22 09:59:27

📝 项目描述:
AR-GhostNet` is a high-performance, modular network reconnaissance and exploitation framework. Designed for stealth, speed, and precision, it integrates adaptive payloading and advanced network fingerprinting to bypass modern security layers. Built for those who operate in the shadows. 💀

🔗 点击访问项目地址
Back to Top