📦 GitHub 全球红队渗透资源中转站。
​旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
⚠️ 本频道仅供安全研究与授权测试使用。
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Burp #Extension

📦 项目名称: burp-cookie-switcher-v2
👤 项目作者: real-kiwii
🛠 开发语言: Python
Star数量: 2 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-12 19:15:09

📝 项目描述:
无描述

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: cve-2026-39987
👤 项目作者: matesz44
🛠 开发语言: Go
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-12 19:17:10

📝 项目描述:
CVE-2026-39987 PoC: Marimo<0.23.0 Pre-Auth Remote Code Execution via Terminal WebSocket Authentication Bypass

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Burp #Extension

📦 项目名称: burp-cookie-switcher
👤 项目作者: real-kiwii
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-12 18:46:15

📝 项目描述:
Burp Suite extension for quickly switching between user and admin cookies while testing BAC manually.

🔗 点击访问项目地址 GitHub - real-kiwii/burp-cookie-switcher: Burp Suite extension for quickly switching between user and admin cookies while testing…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: CVE-2026-73034-PoC
👤 项目作者: Boreas37
🛠 开发语言: Shell
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-12 18:35:43

📝 项目描述:
CVE-2026-73034 — DB-GPT v0.8.1 unauth path traversal → arbitrary file write as root via user-id header. Verified + fix diff

🔗 点击访问项目地址 GitHub - Boreas37/CVE-2026-73034-PoC: CVE-2026-73034 — DB-GPT v0.8.1 unauth path traversal → arbitrary file write as root via user…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: CVE-2026-41452-PoC
👤 项目作者: Boreas37
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-12 18:36:12

📝 项目描述:
CVE-2026-41452 — Krayin CRM unauth installer bypass (X-Requested-With) → admin takeover. Verified: overwrite + login on 2.2.4, blocked on 2.2.5

🔗 点击访问项目地址 GitHub - Boreas37/CVE-2026-41452-PoC: CVE-2026-41452 — Krayin CRM unauth installer bypass (X-Requested-With) → admin takeover.…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: CVE-2026-17544-PoC
👤 项目作者: Boreas37
🛠 开发语言: PHP
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-12 17:48:38

📝 项目描述:
CVE-2026-17544 — PHP bcmath bccomp() OOB write (stack smashing). Verified: crash on 8.4.23/8.5.8, fixed in 8.4.24. GHSA-x692-q9x7-8c3f

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: CVE-2026-33267-PoC
👤 项目作者: Boreas37
🛠 开发语言: Python
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-12 17:49:52

📝 项目描述:
CVE-2026-33267 — Apache Traffic Server @ header internal-metadata spoof (CVSS 10.0). Verified: @ headers leak to plugins on 10.1.2, stripped on 10.1.4

🔗 点击访问项目地址 GitHub - Boreas37/CVE-2026-33267-PoC: CVE-2026-33267 — Apache Traffic Server @ header internal-metadata spoof (CVSS 10.0). Verified:…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Nuclei #template #templates #CVE

📦 项目名称: toolbox-sidenuclei
👤 项目作者: go-appsec
🛠 开发语言: Go
Star数量: 3 | 🍴 Fork数量: 1
📅 更新时间: 2026-08-12 15:55:40

📝 项目描述:
Toolbox sidecar to enable automated scanning with Nuclei

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Burp #Extension

📦 项目名称: burp-nn-extensions
👤 项目作者: n0r1k4zu
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-12 16:13:05

📝 项目描述:
无描述

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Burp #Plugin #Extension

📦 项目名称: burpai
👤 项目作者: openaideveloperai-png
🛠 开发语言: Java
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-12 17:00:12

📝 项目描述:
无描述

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #rule #rules #malware

📦 项目名称: kizashi
👤 项目作者: kizashi-labs
🛠 开发语言: TypeScript
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-12 15:28:24

📝 项目描述:
Self-hosted open source EDR — 兆し, the first sign before anything has happened. Cross-platform agent (Linux eBPF / Windows ETW / macOS ESF), real-time detection, and a SOC console. Runs entirely on infrastructure you control. / セルフホスト型のオープンソース EDR。クロスプラットフォームのエージェント、リアルタイム検知、SOC コンソール。すべて自分の環境で動きます。

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #rules #malware

📦 项目名称: file-detective
👤 项目作者: hasnaintahir99-dev
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-12 16:51:38

📝 项目描述:
🔍 AI-Powered File Security Scanner | Multi-format malware detection with YARA rules and machine learning | Built with Python & FastAPI

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Shellcode #Inject #Execute #AV

📦 项目名称: shellcode-builder
👤 项目作者: exsarorrayzer
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-12 11:19:38

📝 项目描述:
无描述

🔗 点击访问项目地址 GitHub - exsarorrayzer/shellcode-builder
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: Network-Vulnerability-Scanner
👤 项目作者: Ruba-Project
🛠 开发语言: HTML
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-12 16:20:30

📝 项目描述:
A Python-based network vulnerability scanner using Flask and Nmap.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: vulnerability-scanner
👤 项目作者: divyadp08
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-12 16:58:14

📝 项目描述:
Python-based vulnerability scanner for port scanning, web security checks, risk analysis, and report generation.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC #Exploit

📦 项目名称: POC-CopyEscape-CVE-2026-17106
👤 项目作者: 686f6c61
🛠 开发语言: C
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-12 16:42:20

📝 项目描述:
PoC funcional de CVE-2026-17106 (CopyEscape): carrera TOCTOU en docker cp que permite escritura arbitraria en el host Docker. Laboratorio Docker + monitor inotify + LD_PRELOAD. Variante macOS inocua y Linux destructiva.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #EXP #利用

📦 项目名称: CVE-2026-64563_EXP
👤 项目作者: guard-wait
🛠 开发语言: C
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-12 16:53:51

📝 项目描述:
关于CVE-2026-64563未完全验证的一种利用思路

🔗 点击访问项目地址 GitHub - guard-wait/CVE-2026-64563_EXP: 关于CVE-2026-64563未完全验证的一种利用思路
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #malware

📦 项目名称: deepuash-Project-2-YARA-Malware-Detection
👤 项目作者: Y-Reethika
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-12 15:36:49

📝 项目描述:
无描述

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #malware

📦 项目名称: cybernova-malware-analysis-sandbox
👤 项目作者: ibrahim-mukhtar-saidu
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-12 15:45:32

📝 项目描述:
Modular Python static malware-analysis sandbox for IOC extraction, YARA scanning, entropy analysis, hashing, risk scoring, reports, and HTML dashboards.

🔗 点击访问项目地址 GitHub - ibrahim-mukhtar-saidu/cybernova-malware-analysis-sandbox: Modular Python static malware-analysis sandbox for IOC extraction…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #metadata

📦 项目名称: cloud-security-open-bucket
👤 项目作者: pavansai124
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-12 16:01:48

📝 项目描述:
Self-hosted cloud security attack range using LocalStack, Terraform, Docker and AWS CLI to demonstrate IAM, S3, SSRF, metadata credential exposure, remediation and verification.

🔗 点击访问项目地址
Back to Top