📦 GitHub 全球红队渗透资源中转站。
​旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
⚠️ 本频道仅供安全研究与授权测试使用。
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #Stored

📦 项目名称: php-mime-type
👤 项目作者: nguyenquocanhz
🛠 开发语言: PHP
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-14 03:20:45

📝 项目描述:
Xac dinh va kiem tra MIME type an toan cho PHP - chong path traversal, SVG XSS, upload gia mao

🔗 点击访问项目地址 GitHub - nguyenquocanhz/php-mime-type: Xac dinh va kiem tra MIME type an toan cho PHP - chong path traversal, SVG XSS, upload gia…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #Reflected #DOM

📦 项目名称: xss-challenges
👤 项目作者: secrecyberuz-commits
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-14 05:27:29

📝 项目描述:
Reflected, DOM-based, filter bypass va boshqa Cross-Site Scripting (XSS) usullarida amaliy XSS laboratoriya yechimlari va ularning tahlili.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #POC

📦 项目名称: PenTesting-001
👤 项目作者: Nizuii
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-14 04:58:56

📝 项目描述:
OWASP checklist mastery, auth flow attacks, CSRF/SSRF/Session Fixation/Hijacking, payment gateway pentesting, VulnHub VMs (Mr. Robot, Zero Bank, Jangow, N7), and PoC/VAPT-style reporting.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #攻防演练 #靶场

📦 项目名称: spear-and-shield
👤 项目作者: AGIHunt
🛠 开发语言: TypeScript
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-14 04:48:09

📝 项目描述:
矛与盾 — AI 攻防演练场:攻方 AI agent 入侵 Docker 靶场,守方 AI agent 实时防御,人类在可视化控制台围观全过程

🔗 点击访问项目地址 GitHub - AGIHunt/spear-and-shield: 矛与盾 — AI 攻防演练场:攻方 AI agent 入侵 Docker 靶场,守方 AI agent 实时防御,人类在可视化控制台围观全过程
😂😂😂😂 😂😂😂😂 球速 体育 相信品牌的力量,老品牌,值得信赖

🤩🤩🤩🤩🤩🤩🤩 qsty685.cc

🏆 球速体育 豪礼大放送、高端嫩模、劳力士手表、奔驰E300 等大礼等你来豪夺

😀😀😀😀😀😀😀😀😀😀😀😀😀

球速体育 大会员再创新高:
1.
泰国大老板百家乐存50万出512万
2.
斯里兰卡神秘大哥连续5天总提4000万+
3.
实力盘总PA真人喜提990万一路爆红
4.
pp电子糖果1000小注一拉爆出70万大奖

😁😀😁😁😁😁😚🙁😛☺️😉😋以及多种电子钱包存取款、大额出款无忧 (您的最佳选择,欢迎体验)

大额出款额外奖励8888-128888,双重日存彩金128888+4688每日送,周流水彩金68888每周送,双重签到彩金16888+3888送不停

😅😏😃😃🙃😢😅😚😍😀😏😝
#球速体育 安全有保障】
老品牌值得信赖、安全第一、保障第一
不限ip、免实名、免绑卡、免绑手机号码
每日存款彩金每日送,每笔存款加赠1
%

🤩🤩🤩🤩🤩🤩🤩🤩🤩🤩🤩🤩
体育推荐: @qsty789
官方频道:
@PG012456
vip专属热线添加客服领取活动福利
专属客服:
@shiya168
双向用户可联系:
@shiya168_bot


😁😊😁😁 qsty685.cc
TG必备的搜索引擎,快搜kuai帮你发现有趣群组、频道、视频、音乐、电影、新闻 | Find cool stuff all in one bot!

机器人:@kuai @kuaia @kuaiaa

👉 https://t.me/kuai?start=a_3URZVD0
🚨 GitHub 监控消息提醒

🚨 发现关键词: #BlueTeam #Response

📦 项目名称: dfir-toolkit.github.io
👤 项目作者: dfir-toolkit
🛠 开发语言: HTML
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-14 03:57:10

📝 项目描述:
A curated, searchable index of 880 digital forensics and incident response tools, resources and references.

🔗 点击访问项目地址 GitHub - dfir-toolkit/dfir-toolkit.github.io: A curated, searchable index of 880 digital forensics and incident response tools…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #Stored

📦 项目名称: sabana-corp-network
👤 项目作者: maosuarez
🛠 开发语言: PHP
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-14 03:02:42

📝 项目描述:
Intentionally vulnerable CTF lab simulating a full corporate breach — chain SQLi, IDOR, LFI, insecure JWT, and stored XSS through a PHP helpdesk into a weakly-hashed database, then privilege-escalate on Linux to root. 100% Docker, zero manual steps.

🔗 点击访问项目地址 GitHub - maosuarez/sabana-corp-network: Intentionally vulnerable CTF lab simulating a full corporate breach — chain SQLi, IDOR…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Fastjson #漏洞 #反序列化

📦 项目名称: fastjson-1.2.24-TemplatesImpl
👤 项目作者: tiandeyiliushang-sudo
🛠 开发语言: Java
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-13 13:41:45

📝 项目描述:
无描述

🔗 点击访问项目地址 GitHub - tiandeyiliushang-sudo/fastjson-1.2.24-TemplatesImpl
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Fastjson #反序列化

📦 项目名称: fastjson-safemode-detector
👤 项目作者: hl0rey
🛠 开发语言: Java
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-14 00:55:03

📝 项目描述:
基于 Java Attach API(参考 Arthas 原理)的 fastjson safeMode 运行时检测工具。无需重启目标应用、无需修改目标代码,即可在线检测目标 JVM 中 fastjson 的 safeMode 配置状态、AutoType 行为及绕过风险。

🔗 点击访问项目地址 GitHub - hl0rey/fastjson-safemode-detector: 基于 Java Attach API(参考 Arthas 原理)的 fastjson safeMode 运行时检测工具。无需重启目标应用、无需修改目标代码,即可在线检测目标…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #漏洞 #复现 #CVE

📦 项目名称: Security-Blog
👤 项目作者: chengbochuan3
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-14 02:46:41

📝 项目描述:
网络安全学习笔记 — CVE 漏洞研究与复现记录

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: bugseye
👤 项目作者: senseiink
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-14 01:53:57

📝 项目描述:
Lightweight, dependency-free web vulnerability scanner for common misconfigurations and application flaws.

🔗 点击访问项目地址 GitHub - senseiink/bugseye: Lightweight, dependency-free web vulnerability scanner for common misconfigurations and application…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #漏洞 #复现

📦 项目名称: Security-Learning-Notes
👤 项目作者: Sukimjin
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-14 01:58:15

📝 项目描述:
网络安全学习笔记 | DVWA漏洞复现 + 等保2.0 + 安全工具实操

🔗 点击访问项目地址 GitHub - Sukimjin/Security-Learning-Notes: 网络安全学习笔记 | DVWA漏洞复现 + 等保2.0 + 安全工具实操
🚨 GitHub 监控消息提醒

🚨 发现关键词: #RCE #CVE

📦 项目名称: CyberPanel-Authenticated-RCE
👤 项目作者: dennywise
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-13 20:38:04

📝 项目描述:
无描述

🔗 点击访问项目地址 GitHub - dennywise/CyberPanel-Authenticated-RCE
🚨 GitHub 监控消息提醒

🚨 发现关键词: #RCE #Remote Code Execution

📦 项目名称: UBITQUITY-GeoServer-Security-Patch
👤 项目作者: ubitquity
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-14 01:49:20

📝 项目描述:
An emergency security patch by UBITQUITY to mitigate the unauthenticated SQL injection zero-day vulnerability in GeoServer's jsonArrayContains function. This hotfix sanitizes input parameters for PostGIS and Oracle DataStores to prevent potential Remote Code Execution (RCE).

🔗 点击访问项目地址 GitHub - ubitquity/UBITQUITY-GeoServer-Security-Patch: An emergency security patch by UBITQUITY to mitigate the unauthenticated…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Exploit #CVE

📦 项目名称: empirical-security
👤 项目作者: api-evangelist
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-14 00:54:35

📝 项目描述:
Empirical Security builds data-driven models that predict which vulnerabilities will actually be exploited, so security teams can prioritize remediation by real-world risk instead of raw CVSS severity.

🔗 点击访问项目地址 GitHub - api-evangelist/empirical-security: Empirical Security builds data-driven models that predict which vulnerabilities will…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #rules

📦 项目名称: Bam-Parser-Melhorado-WARP-SS
👤 项目作者: arthurex1
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-13 23:26:33

📝 项目描述:
Bam parser com YARA Rules modificadas e melhoradas

🔗 点击访问项目地址 GitHub - arthurex1/Bam-Parser-Melhorado-WARP-SS: Bam parser com YARA Rules modificadas e melhoradas
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Shellcode #Loader #Execute #Evasion

📦 项目名称: ShellCode-Encrypt-Tool-Xor-Aes-Fud-Stable
👤 项目作者: Krwozer
🛠 开发语言: C++
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-13 21:43:04

📝 项目描述:
RAT tools use shellcodes for remote access and system control. Shellcode injection and execution techniques bypass defenses, while red team tools focus on compiling and handling payloads for post-exploitation scenarios.

🔗 点击访问项目地址 GitHub - Krwozer/ShellCode-Encrypt-Tool-Xor-Aes-Fud-Stable: RAT tools use shellcodes for remote access and system control. Shellcode…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #POC #CVE #Stored

📦 项目名称: CVE-PoC-School-Management-System-PHP-XSS
👤 项目作者: elshanmammadoov
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-13 23:01:57

📝 项目描述:
Stored XSS vulnerability in codingWithElias school-management-system-php

🔗 点击访问项目地址 GitHub - elshanmammadoov/CVE-PoC-School-Management-System-PHP-XSS: Stored XSS vulnerability in codingWithElias school-management…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Shellcode #Loader #Inject #Execute #Evasion

📦 项目名称: ShellCode-Elevator-Uac-Bypass-Inject-Any-X64-fud
👤 项目作者: Krwozer
🛠 开发语言: C++
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-13 21:43:07

📝 项目描述:
Shellcode development involves creating payloads for post-exploitation tasks like antivirus evasion and UAC bypass. Tools like shellcode loaders and injectors enable execution, while assembly and encoders ensure stealth on Windows systems.

🔗 点击访问项目地址 GitHub - Krwozer/ShellCode-Elevator-Uac-Bypass-Inject-Any-X64-fud: Shellcode development involves creating payloads for post-exploitation…
Back to Top