📦 GitHub 全球红队渗透资源中转站。
​旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
⚠️ 本频道仅供安全研究与授权测试使用。
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: Okibo
👤 项目作者: seventyoseven
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-05 06:51:13

📝 项目描述:
Final year project - perfecting my vulnerability scanner

🔗 点击访问项目地址 GitHub - seventyoseven/Okibo: Final year project - perfecting my vulnerability scanner
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #malware

📦 项目名称: NT-Forensik
👤 项目作者: netztaucher
🛠 开发语言: Shell
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-05 06:17:17

📝 项目描述:
Read-only Incident-Response-Forensik für WordPress/Plesk-Server: erkennt obfuskierte Cookie-Backdoors, prüft WP-DB & Root-Eskalation, erzeugt Kunden-, BSI- & Technik-Bericht mit SHA256-Belegen.

🔗 点击访问项目地址 GitHub - netztaucher/NT-Forensik: Read-only Incident-Response-Forensik für WordPress/Plesk-Server: erkennt obfuskierte Cookie-Backdoors…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #POC

📦 项目名称: xss-payloads-for-poc
👤 项目作者: bugmithlegend
🛠 开发语言: JavaScript
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-05 05:54:17

📝 项目描述:
无描述

🔗 点击访问项目地址 GitHub - bugmithlegend/xss-payloads-for-poc
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: SecureScan-AI
👤 项目作者: pooja383971
🛠 开发语言: JavaScript
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-05 05:52:44

📝 项目描述:
AI-powered Cyber Security Vulnerability Scanner using Spring Boot, React, MySQL and AI technologies.

🔗 点击访问项目地址 GitHub - pooja383971/SecureScan-AI: AI-powered Cyber Security Vulnerability Scanner using Spring Boot, React, MySQL and AI technologies.
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: Web-Vulnerability-Scanner-VulneraX-
👤 项目作者: sydneymiranda
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-05 05:57:03

📝 项目描述:
Full-stack AI-powered web vulnerability scanner — crawls live targets, injects security payloads, and classifies SQLi/XSS/Command Injection/Path Traversal using a trained XGBoost model with OWASP remediation guidance.

🔗 点击访问项目地址 GitHub - sydneymiranda/Web-Vulnerability-Scanner-VulneraX-: Full-stack AI-powered web vulnerability scanner — crawls live targets…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #malware

📦 项目名称: Astra
👤 项目作者: CyberMage07
🛠 开发语言: Python
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-05 05:39:00

📝 项目描述:
Enterprise-grade malware analysis, reverse engineering & cyber threat intelligence platform for Offensive Security, Red Teaming, VAPT, DFIR, threat hunting & compliance. Modular, evidence-driven architecture with explainable static & dynamic analysis, YARA, IOC extraction, digital forensics & extensible analyzer pipelines.

🔗 点击访问项目地址 GitHub - CyberMage07/Astra: Enterprise-grade malware analysis, reverse engineering & cyber threat intelligence platform for Offensive…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: CVE-2026-17532
👤 项目作者: kalhoralireza
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-05 05:29:07

📝 项目描述:
Seraphinite Accelerator <= 2.29.18 - Reflected Cross-Site Scripting PoC

🔗 点击访问项目地址 GitHub - kalhoralireza/CVE-2026-17532: Seraphinite Accelerator <= 2.29.18 - Reflected Cross-Site Scripting PoC
🚨 GitHub 监控消息提醒

🚨 发现关键词: #GitLab #CVE

📦 项目名称: bare-metal-kubernetes-platform-astroshop
👤 项目作者: mohiuddin89
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-05 04:56:20

📝 项目描述:
Production-inspired Kubernetes on bare-metal with GitLab CI, ArgoCD, ESO, Prometheus/Loki/Jaeger, CVE hardening cycle, and etcd restore drill — Astroshop OpenTelemetry reference workload.

🔗 点击访问项目地址 GitHub - mohiuddin89/bare-metal-kubernetes-platform-astroshop: Production-inspired Kubernetes on bare-metal with GitLab CI, ArgoCD…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #metadata

📦 项目名称: news-extractor
👤 项目作者: okturan
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-05 04:01:19

📝 项目描述:
Dependency-free Python library and CLI for structured Turkish news extraction with JSON-LD/semantic HTML parsing and SSRF-aware fetching.

🔗 点击访问项目地址 GitHub - okturan/news-extractor: Dependency-free Python library and CLI for structured Turkish news extraction with JSON-LD/semantic…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #rules #malware

📦 项目名称: edge-yara-detection
👤 项目作者: cy-bkewusie3923-commits
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-05 04:30:29

📝 项目描述:
Building and testing custom YARA rules for malware detection at the network edge

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #漏洞 #扫描

📦 项目名称: tradeguard
👤 项目作者: dongbofale
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-05 03:32:25

📝 项目描述:
外贸网站安全扫描器 — 一行命令出报告,漏洞+评分+修复方案。专为中国中小外贸网站设计,零门槛零依赖。

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #Stored #Reflected #DOM

📦 项目名称: xss-learning-log
👤 项目作者: Daddypool-44418
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-05 03:42:14

📝 项目描述:
无描述

🔗 点击访问项目地址 GitHub - Daddypool-44418/xss-learning-log
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSTI #RCE

📦 项目名称: ai-escape-room
👤 项目作者: an4kronism
🛠 开发语言: Python
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-04 20:31:33

📝 项目描述:
Educational CTF lab recreating the July 2026 autonomous AI agent intrusion at Hugging Face. Sandbox escape → SSRF → HDF5 file read → Jinja2 SSTI → Kubernetes lateral movement → supply chain pivot. 11 Docker containers, 7 flags.

🔗 点击访问项目地址 GitHub - an4kronism/ai-escape-room: Educational CTF lab recreating the July 2026 autonomous AI agent intrusion at Hugging Face.…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #C2 #Framework

📦 项目名称: Exodia
👤 项目作者: nickpupp0
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-05 01:53:37

📝 项目描述:
Autonomous AI-driven C2-style penetration testing framework with real-time tool orchestration, operator-confirmed exploit execution, attack surface management, and automated report generation.

🔗 点击访问项目地址 GitHub - nickpupp0/Exodia: Autonomous AI-driven penetration testing framework with real-time tool orchestration, operator-confirmed…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC #Exploit

📦 项目名称: CVE-2026-54917-SeaweedFS-Cross-Bucket-Traversal
👤 项目作者: BiiTts
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-05 01:47:03

📝 项目描述:
PoC + analysis for CVE-2026-54917 — SeaweedFS S3 gateway cross-bucket path traversal (CVSS 10.0, <4.30). Read/write any bucket via .. in the object key.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #Exploit

📦 项目名称: copyfail-guard
👤 项目作者: joaocalciolari07
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-05 01:58:43

📝 项目描述:
Defensive detection & mitigation tool for CVE-2026-31431 ("Copy Fail") — Linux kernel algif_aead LPE. No exploit code included.

🔗 点击访问项目地址 GitHub - joaocalciolari07/copyfail-guard: Defensive detection & mitigation tool for CVE-2026-31431 (
🚨 GitHub 监控消息提醒

🚨 发现关键词: #漏洞 #扫描

📦 项目名称: FGRdlWYVDO
👤 项目作者: q015r4obh2
🛠 开发语言: Unknown
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-05 01:02:44

📝 项目描述:
【Java计算机毕业设计分享】基于SSM的漏洞扫描器管理系统,MySQL Java开发 毕业设计 实战项目【附源码、文档报告、代码讲解】

🔗 点击访问项目地址 GitHub - q015r4obh2/FGRdlWYVDO: 【Java计算机毕业设计分享】基于SSM的漏洞扫描器管理系统,MySQL Java开发 毕业设计 实战项目【附源码、文档报告、代码讲解】
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #Stored #DOM

📦 项目名称: mitigator
👤 项目作者: MohamedSoliman21
🛠 开发语言: TypeScript
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-04 22:00:23

📝 项目描述:
A production-grade, zero-trust security library for Node.js & TypeScript. Defends against OWASP Top 10, Prototype Pollution, XSS, SQLi, and Path Traversal with WebAuthn, AES-256-GCM, Adaptive Rate Limiting, and Winternitz PQC.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: network-vulnerability-scanner
👤 项目作者: Freddricklogan
🛠 开发语言: HTML
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-05 00:52:22

📝 项目描述:
Simulated network vulnerability assessment with CVE detection, CVSS scoring, compliance checking, and remediation guidance

🔗 点击访问项目地址 GitHub - Freddricklogan/network-vulnerability-scanner: Simulated network vulnerability assessment with CVE detection, CVSS scoring…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC #Exploit

📦 项目名称: CVE-2026-60137-WordPress-Core-SQL-Injection-PoC
👤 项目作者: AbdullahMaqbool22
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-05 00:16:17

📝 项目描述:
Non-destructive proof-of-concept and verification harness for CVE-2026-60137, a blind SQL injection in WordPress core (`WP_Query::author__not_in`), reachable via the REST API's `author_exclude` parameter.

🔗 点击访问项目地址 GitHub - AbdullahMaqbool22/CVE-2026-60137-WordPress-Core-SQL-Injection-PoC: Non-destructive proof-of-concept and verification harness…
Back to Top