📦 GitHub 全球红队渗透资源中转站。
​旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
⚠️ 本频道仅供安全研究与授权测试使用。
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSTI #RCE

📦 项目名称: sentinelhub
👤 项目作者: JinBaiWansec
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-13 05:47:46

📝 项目描述:
OSWE-style white-box web exploitation lab. A Flask monitoring app with chained RCE paths buried in normal business logic — practice source-code review.

🔗 点击访问项目地址 GitHub - JinBaiWansec/sentinelhub: OSWE-style white-box web exploitation lab. A Flask monitoring app with chained RCE paths buried…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: Web-Vulnerability-Scanner
👤 项目作者: mdhkalgudaricy24-max
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-13 05:41:11

📝 项目描述:
Python Flask-based web vulnerability scanner for detecting common security weaknesses.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Spring #POC

📦 项目名称: Migration-POC
👤 项目作者: SushantAhuja1
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-13 06:02:38

📝 项目描述:
The migration POC using spring batch.

🔗 点击访问项目地址 SushantAhuja1/Migration-POC
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Burp #Extension

📦 项目名称: burp-tls-plus
👤 项目作者: nguyenthdat
🛠 开发语言: Kotlin
Star数量: 11 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-13 04:39:27

📝 项目描述:
Burp extension to evade TLS fingerprinting. Bypass WAF, spoof any browser.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #POC #CVE

📦 项目名称: dbus-security-poc
👤 项目作者: APEvul-cyber
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-13 05:00:34

📝 项目描述:
D-Bus protocol security PoC verification - MEMBER/DESTINATION/INTERFACE/SENDER/SIGNAL attack scenarios

🔗 点击访问项目地址 GitHub - APEvul-cyber/dbus-security-poc: D-Bus protocol security PoC verification - MEMBER/DESTINATION/INTERFACE/SENDER/SIGNAL…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #漏洞

📦 项目名称: CVE-2026-41940-Security-Patch
👤 项目作者: yanchenyu360
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-13 04:58:37

📝 项目描述:
针对CVE-2026-41940漏洞的临时缓解措施

🔗 点击访问项目地址 GitHub - yanchenyu360/CVE-2026-41940-Security-Patch: 针对CVE-2026-41940漏洞的临时缓解措施
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Fscan #内网 #漏洞 #POC

📦 项目名称: RScan
👤 项目作者: Sunmedalia
🛠 开发语言: Rust
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-13 03:12:07

📝 项目描述:
vibecoding 使用 rust重写fscan

🔗 点击访问项目地址 GitHub - Sunmedalia/RScan: vibecoding 使用 rust重写fscan
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: reconspider
👤 项目作者: adamiseek
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-13 02:52:55

📝 项目描述:
Wordlist-free web recon and vulnerability scanner — discovers directories, detects XSS/SQLi, scans ports, and fingerprints tech stacks.

🔗 点击访问项目地址 GitHub - adamiseek/reconspider: Wordlist-free web recon and vulnerability scanner — discovers directories, detects XSS/SQLi, scans…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Burp #扩展

📦 项目名称: BurpJsBeautifier
👤 项目作者: SysN1t
🛠 开发语言: Unknown
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-13 02:29:08

📝 项目描述:
Burp Suite 扩展:API 攻击面测绘 + JS 美化 + 敏感凭证检测 + 未授权/越权验证工作台。 加载:Extensions → Add → Java → 选择 jar。 仅用于授权安全测试。© 2026 SysN3t

🔗 点击访问项目地址 GitHub - SysN1t/BurpJsBeautifier: Burp Suite 扩展:API 攻击面测绘 + JS 美化 + 敏感凭证检测 + 未授权/越权验证工作台。 加载:Extensions → Add → Java → 选择 jar。…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #渗透测试 #漏洞

📦 项目名称: MY_SKILLS
👤 项目作者: int-wc
🛠 开发语言: JavaScript
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-13 02:50:34

📝 项目描述:
渗透测试技能仓库: SRC_SKILLS_V1 + ZC_SKILLS_V1

🔗 点击访问项目地址 GitHub - int-wc/MY_SKILLS: 渗透测试技能仓库: SRC_SKILLS_V1 + ZC_SKILLS_V1
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: Vulnerability_scanner
👤 项目作者: Yaswanthgorle47
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-13 01:16:52

📝 项目描述:
A Python-based vulnerability scanner that detects open ports, identifies running services, checks them against a local CVE database, and generates a security report. Built with Flask, it provides a simple web interface and downloadable scan reports.

🔗 点击访问项目地址 GitHub - Yaswanthgorle47/Vulnerability_scanner: A Python-based vulnerability scanner that detects open ports, identifies running…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: clair-helm
👤 项目作者: hackertwinten
🛠 开发语言: Go Template
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-13 01:36:01

📝 项目描述:
Helm chart for Clair container vulnerability scanner

🔗 点击访问项目地址 GitHub - hackertwinten/clair-helm: Helm chart for Clair container vulnerability scanner
🚨 GitHub 监控消息提醒

🚨 发现关键词: #C2 #Framework #Command and Control

📦 项目名称: covert-c2-framework-poc
👤 项目作者: ericust1
🛠 开发语言: Python
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-13 01:53:20

📝 项目描述:
Proof-of-concept command and control (C2) framework demonstrating domain fronting and DNS tunneling evasion techniques.

🔗 点击访问项目地址 GitHub - ericust1/covert-c2-framework-poc: Proof-of-concept command and control (C2) framework demonstrating domain fronting and…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #POC #CVE

📦 项目名称: CVE-PoC-Tracker
👤 项目作者: Boreas37
🛠 开发语言: Python
Star数量: 1 | 🍴 Fork数量: 1
📅 更新时间: 2026-08-13 01:58:00

📝 项目描述:
无描述

🔗 点击访问项目地址 GitHub - Boreas37/CVE-PoC-Tracker
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #rule #malware

📦 项目名称: automated-malware-sandbox-yara
👤 项目作者: ericust1
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-13 00:17:59

📝 项目描述:
Automated malware analysis sandbox with custom YARA rule generation and dynamic PE execution tracking.

🔗 点击访问项目地址 ericust1/automated-malware-sandbox-yara
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #RCE

📦 项目名称: CVE-2026-14282
👤 项目作者: nullwhisper
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-13 00:27:31

📝 项目描述:
GoDAM WordPress plugin <= 1.12.2 unauthenticated file upload RCE (CVE-2026-14282)

🔗 点击访问项目地址 GitHub - nullwhisper/CVE-2026-14282: GoDAM WordPress plugin <= 1.12.2 unauthenticated file upload RCE (CVE-2026-14282)
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: CVE-2026-24031
👤 项目作者: aramosf
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-12 23:37:39

📝 项目描述:
CVE-2026-24031 Dovecot 2.4.0/3.1.0 SQL authentication bypass (auth bypass + user enumeration) PoC

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #C2 #Command and Control

📦 项目名称: Zombieland
👤 项目作者: infinition
🛠 开发语言: HTML
Star数量: 42 | 🍴 Fork数量: 4
📅 更新时间: 2026-08-12 22:50:25

📝 项目描述:
Zombieland is a command and control (C2) server designed to manage and communicate multiple client machines (referred to as "zombies"). Encrypted communication with clients, allowing for the execution of various commands, and persistence on Zombies. Communication between the server and Zombie is secured using symmetric encryption with Fernet.

🔗 点击访问项目地址 GitHub - infinition/Zombieland: Zombieland is a  command and control (C2) server designed to manage and communicate multiple client…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Nuclei #templates

📦 项目名称: cybersagacity-rule-aggregator
👤 项目作者: Kasloco
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-12 20:12:50

📝 项目描述:
CyberSagacity Rule Intelligence Platform — Automated security rule aggregator for 30,000+ rules from Semgrep, SonarQube, Nuclei, Checkmarx, and more.

🔗 点击访问项目地址 GitHub - Kasloco/cybersagacity-rule-aggregator: CyberSagacity Rule Intelligence Platform — Automated security rule aggregator for…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #rules #malware

📦 项目名称: ThreatKB
👤 项目作者: InQuest
🛠 开发语言: JavaScript
Star数量: 104 | 🍴 Fork数量: 17
📅 更新时间: 2026-08-12 21:19:18

📝 项目描述:
Knowledge base workflow management for YARA rules and C2 artifacts (IP, DNS, SSL) (ALPHA STATE AT THE MOMENT)

🔗 点击访问项目地址
Back to Top