📦 GitHub 全球红队渗透资源中转站。
旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
⚠️ 本频道仅供安全研究与授权测试使用。
旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
⚠️ 本频道仅供安全研究与授权测试使用。
🚨 GitHub 监控消息提醒
🚨 发现关键词: #XSS #Reflected #DOM
📦 项目名称: xss-challenges
👤 项目作者: secrecyberuz-commits
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-14 05:27:29
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #XSS #Reflected #DOM
📦 项目名称: xss-challenges
👤 项目作者: secrecyberuz-commits
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-14 05:27:29
📝 项目描述:
Reflected, DOM-based, filter bypass va boshqa Cross-Site Scripting (XSS) usullarida amaliy XSS laboratoriya yechimlari va ularning tahlili.🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #SSRF #POC
📦 项目名称: PenTesting-001
👤 项目作者: Nizuii
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-14 04:58:56
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #SSRF #POC
📦 项目名称: PenTesting-001
👤 项目作者: Nizuii
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-14 04:58:56
📝 项目描述:
OWASP checklist mastery, auth flow attacks, CSRF/SSRF/Session Fixation/Hijacking, payment gateway pentesting, VulnHub VMs (Mr. Robot, Zero Bank, Jangow, N7), and PoC/VAPT-style reporting.🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #攻防演练 #靶场
📦 项目名称: spear-and-shield
👤 项目作者: AGIHunt
🛠 开发语言: TypeScript
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-14 04:48:09
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #攻防演练 #靶场
📦 项目名称: spear-and-shield
👤 项目作者: AGIHunt
🛠 开发语言: TypeScript
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-14 04:48:09
📝 项目描述:
矛与盾 — AI 攻防演练场:攻方 AI agent 入侵 Docker 靶场,守方 AI agent 实时防御,人类在可视化控制台围观全过程🔗 点击访问项目地址
机器人:@kuai @kuaia @kuaiaa
👉 https://t.me/kuai?start=a_3URZVD0
🚨 GitHub 监控消息提醒
🚨 发现关键词: #BlueTeam #Response
📦 项目名称: dfir-toolkit.github.io
👤 项目作者: dfir-toolkit
🛠 开发语言: HTML
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-14 03:57:10
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #BlueTeam #Response
📦 项目名称: dfir-toolkit.github.io
👤 项目作者: dfir-toolkit
🛠 开发语言: HTML
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-14 03:57:10
📝 项目描述:
A curated, searchable index of 880 digital forensics and incident response tools, resources and references.🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #XSS #Stored
📦 项目名称: sabana-corp-network
👤 项目作者: maosuarez
🛠 开发语言: PHP
⭐ Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-14 03:02:42
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #XSS #Stored
📦 项目名称: sabana-corp-network
👤 项目作者: maosuarez
🛠 开发语言: PHP
⭐ Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-14 03:02:42
📝 项目描述:
Intentionally vulnerable CTF lab simulating a full corporate breach — chain SQLi, IDOR, LFI, insecure JWT, and stored XSS through a PHP helpdesk into a weakly-hashed database, then privilege-escalate on Linux to root. 100% Docker, zero manual steps.🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #Fastjson #漏洞 #反序列化
📦 项目名称: fastjson-1.2.24-TemplatesImpl
👤 项目作者: tiandeyiliushang-sudo
🛠 开发语言: Java
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-13 13:41:45
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #Fastjson #漏洞 #反序列化
📦 项目名称: fastjson-1.2.24-TemplatesImpl
👤 项目作者: tiandeyiliushang-sudo
🛠 开发语言: Java
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-13 13:41:45
📝 项目描述:
无描述🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #Fastjson #反序列化
📦 项目名称: fastjson-safemode-detector
👤 项目作者: hl0rey
🛠 开发语言: Java
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-14 00:55:03
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #Fastjson #反序列化
📦 项目名称: fastjson-safemode-detector
👤 项目作者: hl0rey
🛠 开发语言: Java
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-14 00:55:03
📝 项目描述:
基于 Java Attach API(参考 Arthas 原理)的 fastjson safeMode 运行时检测工具。无需重启目标应用、无需修改目标代码,即可在线检测目标 JVM 中 fastjson 的 safeMode 配置状态、AutoType 行为及绕过风险。🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #漏洞 #复现 #CVE
📦 项目名称: Security-Blog
👤 项目作者: chengbochuan3
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-14 02:46:41
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #漏洞 #复现 #CVE
📦 项目名称: Security-Blog
👤 项目作者: chengbochuan3
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-14 02:46:41
📝 项目描述:
网络安全学习笔记 — CVE 漏洞研究与复现记录🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #Vulnerability Scanner
📦 项目名称: bugseye
👤 项目作者: senseiink
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-14 01:53:57
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #Vulnerability Scanner
📦 项目名称: bugseye
👤 项目作者: senseiink
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-14 01:53:57
📝 项目描述:
Lightweight, dependency-free web vulnerability scanner for common misconfigurations and application flaws.🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #漏洞 #复现
📦 项目名称: Security-Learning-Notes
👤 项目作者: Sukimjin
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-14 01:58:15
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #漏洞 #复现
📦 项目名称: Security-Learning-Notes
👤 项目作者: Sukimjin
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-14 01:58:15
📝 项目描述:
网络安全学习笔记 | DVWA漏洞复现 + 等保2.0 + 安全工具实操🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #RCE #CVE
📦 项目名称: CyberPanel-Authenticated-RCE
👤 项目作者: dennywise
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-13 20:38:04
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #RCE #CVE
📦 项目名称: CyberPanel-Authenticated-RCE
👤 项目作者: dennywise
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-13 20:38:04
📝 项目描述:
无描述🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #RCE #Remote Code Execution
📦 项目名称: UBITQUITY-GeoServer-Security-Patch
👤 项目作者: ubitquity
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-14 01:49:20
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #RCE #Remote Code Execution
📦 项目名称: UBITQUITY-GeoServer-Security-Patch
👤 项目作者: ubitquity
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-14 01:49:20
📝 项目描述:
An emergency security patch by UBITQUITY to mitigate the unauthenticated SQL injection zero-day vulnerability in GeoServer's jsonArrayContains function. This hotfix sanitizes input parameters for PostGIS and Oracle DataStores to prevent potential Remote Code Execution (RCE).🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #Exploit #CVE
📦 项目名称: empirical-security
👤 项目作者: api-evangelist
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-14 00:54:35
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #Exploit #CVE
📦 项目名称: empirical-security
👤 项目作者: api-evangelist
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-14 00:54:35
📝 项目描述:
Empirical Security builds data-driven models that predict which vulnerabilities will actually be exploited, so security teams can prioritize remediation by real-world risk instead of raw CVSS severity.🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #YARA #rules
📦 项目名称: Bam-Parser-Melhorado-WARP-SS
👤 项目作者: arthurex1
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-13 23:26:33
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #YARA #rules
📦 项目名称: Bam-Parser-Melhorado-WARP-SS
👤 项目作者: arthurex1
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-13 23:26:33
📝 项目描述:
Bam parser com YARA Rules modificadas e melhoradas🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #Shellcode #Loader #Execute #Evasion
📦 项目名称: ShellCode-Encrypt-Tool-Xor-Aes-Fud-Stable
👤 项目作者: Krwozer
🛠 开发语言: C++
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-13 21:43:04
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #Shellcode #Loader #Execute #Evasion
📦 项目名称: ShellCode-Encrypt-Tool-Xor-Aes-Fud-Stable
👤 项目作者: Krwozer
🛠 开发语言: C++
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-13 21:43:04
📝 项目描述:
RAT tools use shellcodes for remote access and system control. Shellcode injection and execution techniques bypass defenses, while red team tools focus on compiling and handling payloads for post-exploitation scenarios.🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #XSS #POC #CVE #Stored
📦 项目名称: CVE-PoC-School-Management-System-PHP-XSS
👤 项目作者: elshanmammadoov
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-13 23:01:57
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #XSS #POC #CVE #Stored
📦 项目名称: CVE-PoC-School-Management-System-PHP-XSS
👤 项目作者: elshanmammadoov
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-13 23:01:57
📝 项目描述:
Stored XSS vulnerability in codingWithElias school-management-system-php🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #Shellcode #Loader #Inject #Execute #Evasion
📦 项目名称: ShellCode-Elevator-Uac-Bypass-Inject-Any-X64-fud
👤 项目作者: Krwozer
🛠 开发语言: C++
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-13 21:43:07
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #Shellcode #Loader #Inject #Execute #Evasion
📦 项目名称: ShellCode-Elevator-Uac-Bypass-Inject-Any-X64-fud
👤 项目作者: Krwozer
🛠 开发语言: C++
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-13 21:43:07
📝 项目描述:
Shellcode development involves creating payloads for post-exploitation tasks like antivirus evasion and UAC bypass. Tools like shellcode loaders and injectors enable execution, while assembly and encoders ensure stealth on Windows systems.🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #Shellcode #Evasion
📦 项目名称: Exe-UacBypass-Downloader-Crypter-Fud-Defender-Malware-Executable
👤 项目作者: Leemoys
🛠 开发语言: Visual Basic .NET
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-13 22:02:57
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #Shellcode #Evasion
📦 项目名称: Exe-UacBypass-Downloader-Crypter-Fud-Defender-Malware-Executable
👤 项目作者: Leemoys
🛠 开发语言: Visual Basic .NET
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-13 22:02:57
📝 项目描述:
Malware builders create hidden trojans with features like UAC bypass and defender bypass. Tools like crypters and FUD ensure antivirus evasion, while shellcode and memory exclusion enhance stealth.🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #YARA #malware
📦 项目名称: guarddoc
👤 项目作者: jfx21
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-13 21:39:05
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #YARA #malware
📦 项目名称: guarddoc
👤 项目作者: jfx21
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-13 21:39:05
📝 项目描述:
GuardDoc: Lightweight, local CLI tool & background daemon for document malware triage, extension spoofing detection, and real-time download watching on macOS & Linux.🔗 点击访问项目地址