📦 GitHub 全球红队渗透资源中转站。
​旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
⚠️ 本频道仅供安全研究与授权测试使用。
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: xss2shell
👤 项目作者: 0xlipon
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-09 14:59:43

📝 项目描述:
🔥 XSS2Shell — CVE-2026-64638 Scanner & PoC Toolkit

🔗 点击访问项目地址 GitHub - 0xlipon/xss2shell: 🔥 XSS2Shell — CVE-2026-64638 Scanner & PoC Toolkit
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Nuclei #template #POC #CVE

📦 项目名称: CVE-2026-64638-PoC-XSS2Shell-
👤 项目作者: Boreas37
🛠 开发语言: Python
Star数量: 12 | 🍴 Fork数量: 3
📅 更新时间: 2026-08-09 14:03:52

📝 项目描述:
XSS2Shell (CVE-2026-64638) WordPress pre-auth XSS to RCE chain — PoC exploit + defensive audit tool + nuclei template

🔗 点击访问项目地址 GitHub - Boreas37/CVE-2026-64638-PoC-XSS2Shell-: XSS2Shell (CVE-2026-64638) WordPress pre-auth XSS to RCE chain — PoC exploit +…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: AI-Code-Vulnerability-Scanner
👤 项目作者: anushkounain
🛠 开发语言: JavaScript
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-09 13:58:44

📝 项目描述:
AI-powered code vulnerability scanner using AST, Bandit, Semgrep, and Ollama for automated security analysis and reporting.

🔗 点击访问项目地址 GitHub - anushkounain/AI-Code-Vulnerability-Scanner: AI-powered code vulnerability scanner using AST, Bandit, Semgrep, and Ollama…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: Project-Nemesis
👤 项目作者: ErfanNahidi
🛠 开发语言: Shell
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-09 13:59:49

📝 项目描述:
Advanced Network Reconnaissance & Vulnerability Scanner

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #Exploit

📦 项目名称: CVE-2026-4282-Scanner
👤 项目作者: hexissam
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-09 13:16:29

📝 项目描述:
Non-intrusive version-based vulnerability scanner for CVE-2026-4282 (Keycloak SingleUseObjectProvider isolation flaw enabling authorization code forgery & privilege escalation)

🔗 点击访问项目地址 GitHub - hexissam/CVE-2026-4282-Scanner: Non-intrusive version-based vulnerability scanner for CVE-2026-4282 (Keycloak SingleU…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Burp #Extension

📦 项目名称: burp-method-analyzer
👤 项目作者: EslamMonex
🛠 开发语言: Java
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-09 12:18:38

📝 项目描述:
无描述

🔗 点击访问项目地址 GitHub - EslamMonex/burp-method-analyzer
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: web-vulnerability-scanner
👤 项目作者: CHAITHANYAHEGDE
🛠 开发语言: Python
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-09 12:53:36

📝 项目描述:
Scoped Python web security scanner for detecting common OWASP-aligned vulnerabilities in controlled environments.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: Vulnerability-Scanner
👤 项目作者: Kunal-CodeLab
🛠 开发语言: HTML
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-09 11:41:50

📝 项目描述:
Developed a security platform using Python (Flask) that detects 14+ web vulnerabilities (including SQL Injection, XSS, CSRF, and SSL/TLS issues). Features a real-time responsive dashboard, JWT-based authentication, scan history tracking, risk assessment, and downloadable PDF security reports.

🔗 点击访问项目地址 GitHub - Kunal-CodeLab/Vulnerability-Scanner: Developed a security platform using Python (Flask) that detects 14+ web vulnerabilities…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #Exploit

📦 项目名称: RedSun-
👤 项目作者: s4m98
🛠 开发语言: C++
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-09 11:27:48

📝 项目描述:
Windwos Zero Day Local PrivESc Exploit (CVE-2026-41091)

🔗 点击访问项目地址 GitHub - s4m98/RedSun-: Windwos Zero Day Local PrivESc Exploit (CVE-2026-41091)
🚨 GitHub 监控消息提醒

🚨 发现关键词: #渗透测试 #漏洞

📦 项目名称: Waystone
👤 项目作者: Star-233
🛠 开发语言: TypeScript
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-09 08:57:33

📝 项目描述:
通用问题求解引擎(oritera/Cairn 的 AGPL-3.0 修改版):黑板架构 + 事实-意图图谱,AI 渗透测试验证领域

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #威胁情报 #IOC #溯源

📦 项目名称: AgentCTI
👤 项目作者: lwt555
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-09 07:59:19

📝 项目描述:
面向不可信网络威胁情报的多智能体协作分析平台

🔗 点击访问项目地址 GitHub - lwt555/AgentCTI: 面向不可信网络威胁情报的多智能体协作分析平台
🚨 GitHub 监控消息提醒

🚨 发现关键词: #漏洞 #扫描 #复现

📦 项目名称: AutoSRC-AISkill
👤 项目作者: Chenggaorui
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-09 09:25:58

📝 项目描述:
全自动SRC漏洞挖掘AI-Skill一体化技能包,整合主流开源资产搜集、漏洞扫描、AI 误报过滤、自动取证、漏洞报告生成工具链,面向零基础安全新手打造轻量化全自动 SRC 漏洞挖掘一体化技能包。内置子域名探测、目录爆破、漏洞批量扫描、AI 智能筛报、漏洞截图复现、SRC 标准化报告一键生成全流程自动化脚本,适配 Windows、Kali、Docker 云服务器多端部署,附带保姆级落地教程,仅可用于厂商公开授权范围内的安全测试。

🔗 点击访问项目地址 GitHub - Chenggaorui/AutoSRC-AISkill: 全自动SRC漏洞挖掘AI-Skill一体化技能包,整合主流开源资产搜集、漏洞扫描、AI 误报过滤、自动取证、漏洞报告生成工具链,面向零基础安全新手打造轻量化全自动 SRC 漏洞…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Exploit #POC

📦 项目名称: exploit
👤 项目作者: roshanrazz
🛠 开发语言: HTML
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-09 09:03:15

📝 项目描述:
无描述

🔗 点击访问项目地址 roshanrazz/exploit
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Log4j #CVE #POC

📦 项目名称: log4j-shell-poc
👤 项目作者: Jiahong-Guan
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-09 07:05:50

📝 项目描述:
A Proof-Of-Concept for the CVE-2021-44228 vulnerability.

🔗 点击访问项目地址 GitHub - Jiahong-Guan/log4j-shell-poc: A Proof-Of-Concept for the CVE-2021-44228 vulnerability.
🚨 GitHub 监控消息提醒

🚨 发现关键词: #C2 #Command and Control

📦 项目名称: Case-02-Lumma-In-The-Room-Ah
👤 项目作者: AustinWaldron
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-09 07:03:36

📝 项目描述:
Triage and forensic analysis of a high-severity network alert indicating a Lumma Stealer infection. This investigation covers identifying the compromised internal asset, mapping its Active Directory user identity properties via network protocols, and extracting malicious Command and Control (C2) indicators.

🔗 点击访问项目地址 GitHub - AustinWaldron/Case-02-Lumma-In-The-Room-Ah: Triage and forensic analysis of a high-severity network alert indicating a…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #CVE

📦 项目名称: XSS2Shell
👤 项目作者: Ahmall-sec
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-09 07:04:46

📝 项目描述:
XSS2Shell ULTIMATE v3.0** is a powerful exploitation tool that chains **Cross-Site Scripting (XSS)** vulnerabilities in **WordPress** to achieve **Remote Code Execution (RCE)**. This tool exploits CVE-2026-64638 to gain full control over vulnerable WordPress installations.

🔗 点击访问项目地址 Ahmall-sec/XSS2Shell
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSTI #RCE

📦 项目名称: fmfuzz_tool
👤 项目作者: Mr-xn
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-09 06:36:29

📝 项目描述:
freemarker SSTI 命令执行/混淆/文件写入,以及jmreport组件利用payload生成

🔗 点击访问项目地址 GitHub - Mr-xn/fmfuzz_tool: freemarker SSTI 命令执行/混淆/文件写入,以及jmreport组件利用payload生成
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Xray #CVE

📦 项目名称: AegisPanel
👤 项目作者: QAdversif
🛠 开发语言: Go
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-09 06:04:35

📝 项目描述:
无描述

🔗 点击访问项目地址 GitHub - QAdversif/AegisPanel
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #malware

📦 项目名称: quietvault-agent-hijack
👤 项目作者: yankywilson
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-09 05:49:41

📝 项目描述:
Analysis of QUIETVAULT (nx/s1ngularity, Aug 2025) — malware that hijacks the victim's own AI coding agents to find their secrets. Validated YARA/Sigma/KQL, a detonation harness, and evidence that 6 of 8 commercial sandbox runs never executed the sample.

🔗 点击访问项目地址 GitHub - yankywilson/quietvault-agent-hijack: Analysis of QUIETVAULT (nx/s1ngularity, Aug 2025) — malware that hijacks the victim's…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Burp #扩展 #Extension

📦 项目名称: burp-decrypt-tab
👤 项目作者: zhaguiya
🛠 开发语言: Java
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-09 03:10:06

📝 项目描述:
无描述

🔗 点击访问项目地址 GitHub - zhaguiya/burp-decrypt-tab
Back to Top