📦 GitHub 全球红队渗透资源中转站。
​旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
⚠️ 本频道仅供安全研究与授权测试使用。
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: websec-scanner
👤 项目作者: HamzaSudozai
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-15 18:11:42

📝 项目描述:
Passive web vulnerability scanner with OWASP Top 10 checks and generates HTML/PDF reports. Authorized security testing only.

🔗 点击访问项目地址 GitHub - HamzaSudozai/websec-scanner: Passive web vulnerability scanner with OWASP Top 10 checks and generates HTML/PDF reports.…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Exploit #CVE #POC

📦 项目名称: CVE-2026-20896-Gitea-Authentication-Bypass
👤 项目作者: judgedbykira
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-15 19:05:05

📝 项目描述:
An explanation and PoC to exploit CVE-2026-20896 Authentication Bypass Vulnerability on Gitea. Being able to steal session tokens for valid users in the Gitea instance.

🔗 点击访问项目地址 GitHub - judgedbykira/CVE-2026-20896-Gitea-Authentication-Bypass: An explanation and PoC to exploit CVE-2026-20896 Authentication…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #metadata

📦 项目名称: credjack
👤 项目作者: maximalfocus
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-15 18:29:37

📝 项目描述:
A local, container-only educational demonstration of SSRF to a cloud instance metadata service (CWE-918 / OWASP A10:2021), through to credential replay, and the resolved-address control that stops it. Everything is fictional and runs only on your machine.

🔗 点击访问项目地址 GitHub - maximalfocus/credjack: A local, container-only educational demonstration of SSRF to a cloud instance metadata service…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Burp #Extension

📦 项目名称: PassiveSight
👤 项目作者: yadavnikhil17102004
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-15 18:07:30

📝 项目描述:
AI-powered vulnerability scanner extension for Burp Suite with multi-provider support (Ollama, OpenAI, Claude, Gemini)

🔗 点击访问项目地址 GitHub - yadavnikhil17102004/PassiveSight: AI-powered vulnerability scanner extension for Burp Suite with multi-provider support…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Shellcode #Loader

📦 项目名称: zig0.16.0-shellcode
👤 项目作者: kingwei123
🛠 开发语言: Zig
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-15 14:59:42

📝 项目描述:
无描述

🔗 点击访问项目地址 kingwei123/zig0.16.0-shellcode
🚨 GitHub 监控消息提醒

🚨 发现关键词: #RCE #CVE #POC

📦 项目名称: MouseServer-1.7.8.5-RCE
👤 项目作者: mermehr
🛠 开发语言: PowerShell
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-15 17:58:08

📝 项目描述:
PoC for CVE-2022-3218

🔗 点击访问项目地址 GitHub - mermehr/MouseServer-1.7.8.5-RCE: PoC for CVE-2022-3218
🚨 GitHub 监控消息提醒

🚨 发现关键词: #漏洞 #CVE

📦 项目名称: VulnTracer
👤 项目作者: rockmelodies
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-15 17:21:22

📝 项目描述:
Vuln(漏洞)+ Tracer(追踪器),强调 AI 对污点数据流的深度追踪、对攻击面的精准测绘能力,直击代码审计挖 CVE 的核心技术逻辑,专业感强,适合主打审计深度的技术定位。

🔗 点击访问项目地址 rockmelodies/VulnTracer
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Shellcode #Evasion #EDR #AV

📦 项目名称: av-evasion-kit
👤 项目作者: Excalibra
🛠 开发语言: C
Star数量: 3 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-15 16:58:24

📝 项目描述:
AV Evasion Kit is a comprehensive shellcode evasion framework using Indirect Syscalls, ETW patching, Module Stomping, .text code caves, compile-time string encryption, IPv4 obfuscation, XOR encryption, HeapAlloc buffering and direct function-pointer calls to bypass mainstream AV/EDR via static signatures, behavioural traces and EDR perception.

🔗 点击访问项目地址 GitHub - Excalibra/av-evasion-kit: AV Evasion Kit is a comprehensive shellcode evasion framework using Indirect Syscalls, ETW patching…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: ShieldScan
👤 项目作者: sedat4ras
🛠 开发语言: Python
Star数量: 2 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-15 16:32:52

📝 项目描述:
Python & AI based automated vulnerability scanner and reporter.

🔗 点击访问项目地址 GitHub - sedat4ras/ShieldScan: Python & AI based automated vulnerability scanner and reporter.
🫤😐🫥😶🤥🫠🤫🫡🫢
😑 N9 国际认证 | 信誉平台
支持5倍验资 【验资:
@N9KF
担保域名:N9.TOP 点击查看
⚡️⚡️⚡️⚡️
💝
新会员好礼
注册就送28.8U
新人首存/二存/三存最高赠送
8️⃣8️⃣8️⃣8️⃣U
💝
老会员好礼
电子狂欢每日存款赠送10%
充值笔笔送3%无上限
夜间充值最高可优惠8888U

⚡️⚡️⚡️⚡️⚡️⚡️
⚡️⚡️⚡️⚡️⚡️⚡️⚡️
香港六合彩
4️⃣8️⃣.8️⃣
加拿大28全网返水最高

⚡️注册网址:N9.PRO

😇🧐🧐😗🧐😙😄
⚡️ 官方客服: @N9KF
⚡️ 官方飞投: @N9N9
⚡️ 彩票客服: @N9CP
⚡️ 彩票飞投: @N9N9N9
⚡️ 福利频道: @N9pd888
⚡️ 注册网址: N9.COM【USDT】
⚡️ 注册网址: N9.COM【人民币】

🔥欢迎各位老板加入N9国际娱乐城!
🔥关注N9官方频道参与更多优惠活动
🚨 GitHub 监控消息提醒

🚨 发现关键词: #RCE #CVE #POC

📦 项目名称: CVE-2025-64512-pdfminer-PoC
👤 项目作者: oguzylmzx
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-15 16:58:24

📝 项目描述:
PoC for CVE-2025-64512: pdfminer.six CMapDB pickle deserialization RCE via crafted PDF

🔗 点击访问项目地址 GitHub - oguzylmzx/CVE-2025-64512-pdfminer-PoC: PoC for CVE-2025-64512: pdfminer.six CMapDB pickle deserialization RCE via crafted…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: CVE-2026-9090-poc
👤 项目作者: Kimdir01
🛠 开发语言: Go
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-15 16:42:20

📝 项目描述:
PoC for CVE-2026-9090 — Casdoor SAML signature bypass (CWE-347). Reproduction-only; coordinated via CERT/CC VU#780781.

🔗 点击访问项目地址 GitHub - Kimdir01/CVE-2026-9090-poc: PoC for CVE-2026-9090 — Casdoor SAML signature bypass (CWE-347). Reproduction-only; coordinated…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Shellcode #Evasion #EDR #AV

📦 项目名称: AV-Evasion-Kit
👤 项目作者: Excalibra
🛠 开发语言: C
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-15 15:57:59

📝 项目描述:
AV Evasion Kit is a comprehensive shellcode evasion framework using Indirect Syscalls, ETW patching, Module Stomping, .text code caves, compile-time string encryption, IPv4 obfuscation, XOR encryption, HeapAlloc buffering and direct function-pointer calls to bypass mainstream AV/EDR via static signatures, behavioural traces and EDR perception.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #渗透测试 #漏洞

📦 项目名称: dsh-pentest
👤 项目作者: howmp
🛠 开发语言: JavaScript
Star数量: 1 | 🍴 Fork数量: 1
📅 更新时间: 2026-08-15 14:48:51

📝 项目描述:
面向 DeepSeek Harness(dsh)的渗透测试模式 @CloverSecLabs

🔗 点击访问项目地址 GitHub - howmp/dsh-pentest: DSH 渗透测试模式:记录探索链路、资产与漏洞,并在 Web 中可视化展示。
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #metadata

📦 项目名称: Ciber-Cloud
👤 项目作者: Constan4
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-15 15:33:12

📝 项目描述:
Cloud security & pentesting: AWS, Azure, GCP — IAM abuse, S3 misconfigs, SSRF metadata, secrets hunting, container security. ScoutSuite, Pacu, trufflehog.

🔗 点击访问项目地址 GitHub - Constan4/Ciber-Cloud: Cloud security & pentesting: AWS, Azure, GCP — IAM abuse, S3 misconfigs, SSRF metadata, secrets…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: website-vuln-scanner
👤 项目作者: zqqqqqx
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-15 16:02:41

📝 项目描述:
Pure-stdlib Python website vulnerability scanner (35+ checks) with a local safe lab target — zero third-party dependencies.

🔗 点击访问项目地址 zqqqqqx/website-vuln-scanner
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #Exploit

📦 项目名称: cve-2026-43499-honor
👤 项目作者: knowlily
🛠 开发语言: C
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-15 15:19:30

📝 项目描述:
CVE-2026-43499 (GhostLock) rt_mutex stack-UAF privilege escalation research on Honor BVL-AN16 (Magic6 Pro, SM8650, kernel 6.1.128). Includes analysis docs, reverse-engineering scripts, disassembly artifacts, and exploit source with honor-BVL-AN16 target adaptation.

🔗 点击访问项目地址 GitHub - knowlily/cve-2026-43499-honor: CVE-2026-43499 (GhostLock) rt_mutex stack-UAF privilege escalation research on Honor BVL…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #POC #CVE #RCE

📦 项目名称: PoCs
👤 项目作者: victorbonato
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-15 15:06:08

📝 项目描述:
PoC for CVE-2026-56197 — Windows Admin Center (WAC) command injection RCE via invokeCommand; scripted no-browser auth (csrf/JWK/RSA-OAEP login chain), --cmd/--proof/--rev reverse-shell modes

🔗 点击访问项目地址 GitHub - victorbonato/PoCs: PoC for CVE-2026-56197 — Windows Admin Center (WAC) command injection RCE via invokeCommand; scripted…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #CVE #Reflected

📦 项目名称: CVEX2SHEL
👤 项目作者: Alixploit22
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-15 14:17:16

📝 项目描述:
CVE-2026-64638 adalah kerentanan Pre-Auth Reflected Cross-Site Scripting (XSS) di WordPress yang ditemukan pada tahun 2026. Kerentanan ini memungkinkan penyerang untuk menyisipkan kode JavaScript berbahaya ke halaman login WordPress (/wp-login.php) tanpa perlu autentikasi terlebih dahulu.

🔗 点击访问项目地址 GitHub - Alixploit22/CVEX2SHEL: CVE-2026-64638 adalah kerentanan Pre-Auth Reflected Cross-Site Scripting (XSS) di WordPress yang…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Nuclei #template

📦 项目名称: Nuclei_Template_V1
👤 项目作者: sanacvn
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-15 14:08:32

📝 项目描述:
无描述

🔗 点击访问项目地址
Back to Top