📦 GitHub 全球红队渗透资源中转站。
旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
⚠️ 本频道仅供安全研究与授权测试使用。
旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
⚠️ 本频道仅供安全研究与授权测试使用。
🚨 GitHub 监控消息提醒
🚨 发现关键词: #RCE #CVE #POC #Remote Code Execution
📦 项目名称: Dead-Dial
👤 项目作者: 0xReadingSteiner
🛠 开发语言: Shell
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-11 00:11:27
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #RCE #CVE #POC #Remote Code Execution
📦 项目名称: Dead-Dial
👤 项目作者: 0xReadingSteiner
🛠 开发语言: Shell
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-11 00:11:27
📝 项目描述:
Pre-authentication RCE in Cisco CUCM 15.x via Apache Axis JNDI injection — independent chain, survives Silent;Call patches🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #XSS #Stored #Reflected #DOM
📦 项目名称: devtalks-xss
👤 项目作者: orfloresti
🛠 开发语言: HTML
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-11 00:15:48
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #XSS #Stored #Reflected #DOM
📦 项目名称: devtalks-xss
👤 项目作者: orfloresti
🛠 开发语言: HTML
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-11 00:15:48
📝 项目描述:
无描述🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #XSS #Stored
📦 项目名称: task-manager-rest-api
👤 项目作者: RamahB0
🛠 开发语言: JavaScript
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-11 00:20:21
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #XSS #Stored
📦 项目名称: task-manager-rest-api
👤 项目作者: RamahB0
🛠 开发语言: JavaScript
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-11 00:20:21
📝 项目描述:
A secure Task Manager REST API with JWT + Google OAuth (Passport.js) auth, HTTP-only cookie sessions, owner-scoped task routes, helmet/xss-clean/mongo-sanitize hardening, rate limiting, and centralized error handling (AppError + catchAsync).🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #CVE-2026 #POC
📦 项目名称: CVE-2026-23744-PoC
👤 项目作者: Mluex0
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-11 01:52:07
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #CVE-2026 #POC
📦 项目名称: CVE-2026-23744-PoC
👤 项目作者: Mluex0
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-11 01:52:07
📝 项目描述:
CVE-2026-23744 is an unauthenticated command injection in MCPJam Inspector ≤1.4.2 via /api/mcp/connect. This POC exploits it by sending a crafted JSON payload to execute arbitrary commands, granting a reverse shell with PTY.🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #Vulnerability Scanner
📦 项目名称: vuln-scanner
👤 项目作者: devkroz
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-11 00:41:42
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #Vulnerability Scanner
📦 项目名称: vuln-scanner
👤 项目作者: devkroz
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-11 00:41:42
📝 项目描述:
Web vulnerability scanner — XSS, SQLi, CRLF, path traversal, command injection, open redirect, security headers🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #CVE-2026 #利用
📦 项目名称: CVE-2026-9198
👤 项目作者: CuteeCat
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-11 00:55:51
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #CVE-2026 #利用
📦 项目名称: CVE-2026-9198
👤 项目作者: CuteeCat
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-11 00:55:51
📝 项目描述:
CVE-2026-9198利用代码🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #Credential Dumping #LSASS
📦 项目名称: Lab-05-Wazuh-XDR-EDR-Deployment
👤 项目作者: Izaiah1996
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-10 22:12:40
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #Credential Dumping #LSASS
📦 项目名称: Lab-05-Wazuh-XDR-EDR-Deployment
👤 项目作者: Izaiah1996
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-10 22:12:40
📝 项目描述:
Single-node Wazuh 4.12.0 stack deployed on the management segment of a multi-VLAN home SOC lab, with agents enrolled on a Windows domain controller and workstation, plus a custom MITRE ATT&CK mapped detection rule for LSASS credential dumping.🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #YARA #malware
📦 项目名称: dfir-malware-lab
👤 项目作者: ronankongala
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-10 22:31:22
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #YARA #malware
📦 项目名称: dfir-malware-lab
👤 项目作者: ronankongala
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-10 22:31:22
📝 项目描述:
DFIR and Malware Analysis Lab - FlareVM, REMnux, Ghidra, CAPA, YARA, Volatility 3🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #提权 #CVE
📦 项目名称: ghostlock-apk
👤 项目作者: oopnv70-lab
🛠 开发语言: Java
⭐ Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-10 22:03:42
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #提权 #CVE
📦 项目名称: ghostlock-apk
👤 项目作者: oopnv70-lab
🛠 开发语言: Java
⭐ Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-10 22:03:42
📝 项目描述:
独立 APK:CVE-2026-43499 GhostLock 提权 + Shizuku shell 身份执行🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #CVE-2026 #Exploit
📦 项目名称: WP2Shell
👤 项目作者: g0d150ne
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-10 21:08:17
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #CVE-2026 #Exploit
📦 项目名称: WP2Shell
👤 项目作者: g0d150ne
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-10 21:08:17
📝 项目描述:
WP2Shell is a powerful and modular exploit framework that combines two critical WordPress vulnerabilities (CVE-2026-63030 and CVE-2026-60137) to achieve complete compromise of a target site without any credentials. 🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #CVE-2026 #RCE
📦 项目名称: XSS2Shell
👤 项目作者: g0d150ne
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-10 21:08:48
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #CVE-2026 #RCE
📦 项目名称: XSS2Shell
👤 项目作者: g0d150ne
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-10 21:08:48
📝 项目描述:
XSS2Shell ULTIMATE v3.0 is a powerful exploitation tool that chains Cross-Site Scripting (XSS) vulnerabilities in WordPress to achieve Remote Code Execution (RCE). This tool exploits CVE-2026-64638 to gain full control over vulnerable WordPress installations.🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #Vulnerability Scanner
📦 项目名称: php-ai-security-scanner
👤 项目作者: BangPiyus
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-10 20:54:53
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #Vulnerability Scanner
📦 项目名称: php-ai-security-scanner
👤 项目作者: BangPiyus
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-10 20:54:53
📝 项目描述:
AI-powered PHP vulnerability scanner and static security analyzer for detecting SQL injection, XSS, RCE, malware, backdoors, secrets, and insecure code.🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #Vulnerability Scanner
📦 项目名称: God-eye
👤 项目作者: g0d150ne
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-10 20:58:10
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #Vulnerability Scanner
📦 项目名称: God-eye
👤 项目作者: g0d150ne
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-10 20:58:10
📝 项目描述:
Ultimate Vulnerability Scanner - Web + Cloud + Infrastructure 100+ Vulnerability Types • 1100+ Payloads • Full Takeover Capable🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #Burp #Extension
📦 项目名称: socketsleuth
👤 项目作者: snyk
🛠 开发语言: Java
⭐ Star数量: 107 | 🍴 Fork数量: 19
📅 更新时间: 2026-08-10 19:31:21
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #Burp #Extension
📦 项目名称: socketsleuth
👤 项目作者: snyk
🛠 开发语言: Java
⭐ Star数量: 107 | 🍴 Fork数量: 19
📅 更新时间: 2026-08-10 19:31:21
📝 项目描述:
Burp Extension to add additional functionality for pentesting websocket based applications 🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #C2 #Framework
📦 项目名称: BEAR-C2
👤 项目作者: S3N4T0R-0X0
🛠 开发语言: Python
⭐ Star数量: 530 | 🍴 Fork数量: 106
📅 更新时间: 2026-08-10 19:59:38
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #C2 #Framework
📦 项目名称: BEAR-C2
👤 项目作者: S3N4T0R-0X0
🛠 开发语言: Python
⭐ Star数量: 530 | 🍴 Fork数量: 106
📅 更新时间: 2026-08-10 19:59:38
📝 项目描述:
BEAR-C2 is an adversary simulation and emulation framework built around real world TTPs inspired by Russian, Chinese, North Korean, and Iranian APT groups.🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #Vulnerability Scanner
📦 项目名称: SentinelScan
👤 项目作者: Roxxhard
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-10 19:47:17
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #Vulnerability Scanner
📦 项目名称: SentinelScan
👤 项目作者: Roxxhard
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-10 19:47:17
📝 项目描述:
AI-powered Web Vulnerability Scanner🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #Burp #Plugin
📦 项目名称: anomaly-ranker-caido
👤 项目作者: aleister1102
🛠 开发语言: TypeScript
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-10 18:23:43
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #Burp #Plugin
📦 项目名称: anomaly-ranker-caido
👤 项目作者: aleister1102
🛠 开发语言: TypeScript
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-10 18:23:43
📝 项目描述:
Caido plugin that ranks HTTP responses by anomaly using a Burp-inspired categorical frequency model.🔗 点击访问项目地址