📦 GitHub 全球红队渗透资源中转站。
​旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
⚠️ 本频道仅供安全研究与授权测试使用。
🚨 GitHub 监控消息提醒

🚨 发现关键词: #RCE #POC

📦 项目名称: poc-mutable-action-consumer
👤 项目作者: venkatchalla06
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-20 19:23:26

📝 项目描述:
Controlled PoC: consumer workflow demonstrating mutable-tag action RCE (authorized self-owned sandbox)

🔗 点击访问项目地址 venkatchalla06/poc-mutable-action-consumer
🚨 GitHub 监控消息提醒

🚨 发现关键词: #RCE #POC

📦 项目名称: poc-mutable-action-demo
👤 项目作者: venkatchalla06
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-20 19:24:31

📝 项目描述:
Controlled PoC: composite action for demonstrating mutable-tag supply-chain RCE mechanism (authorized self-owned sandbox)

🔗 点击访问项目地址 GitHub - venkatchalla06/poc-mutable-action-demo: Controlled PoC: composite action for demonstrating mutable-tag supply-chain RCE…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #Exploit

📦 项目名称: CVE-2026-39987.py
👤 项目作者: dodeepsink
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-20 19:41:06

📝 项目描述:
This python script exploit the vulnerable marimo /terminal/ws endpoint and returns a interactive shell.

🔗 点击访问项目地址 GitHub - dodeepsink/CVE-2026-39987.py: This python script exploit the vulnerable marimo /terminal/ws endpoint and returns a interactive…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #C2 #Framework

📦 项目名称: UzA-Rat
👤 项目作者: UzairAliSheikh786
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-20 18:57:37

📝 项目描述:
Lightweight C2 agent simulation framework for red team adversary emulation & offensive security research. Demonstrates basic C2 callback patterns for SOC monitoring, custom TCP packet framing, multi-threaded C2 infrastructure setup, & application-layer XOR encrypted payload analysis via Wireshark.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: CVE-2026-18366
👤 项目作者: ghostpels
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-20 18:50:40

📝 项目描述:
CVE-2026-18366: Events Manager < 7.4.1 — Unauthenticated Privilege Escalation to Administrator. Write-up and proof-of-concept (poc.py).

🔗 点击访问项目地址 ghostpels/CVE-2026-18366
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Shellcode #Execute #EDR #AV

📦 项目名称: havoc-fileless-dropper
👤 项目作者: Segaotava
🛠 开发语言: C++
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-20 13:53:35

📝 项目描述:
Fileless shellcode dropper in C++ using WinINet API. Downloads and executes shellcode in-memory without touching disk. Educational purposes only.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Shellcode #Evasion #AV

📦 项目名称: Shellcode-Obfuscation
👤 项目作者: n1h-nb
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 1
📅 更新时间: 2026-08-20 17:32:08

📝 项目描述:
The project studies how antivirus engines detect shellcode and develops obfuscation techniques to evade them, then measures how successfully these modified payloads bypass detection in an isolated lab using tools like VirusTotal and Windows Defender.​

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: py-web-vuln-scanner
👤 项目作者: bante27
🛠 开发语言: Python
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-20 17:47:47

📝 项目描述:
A modular Web Application Vulnerability Scanner built with Python. Features HTTP header analysis, directory fuzzing, custom payload injection for SQLi/XSS detection, and automated reporting. Designed for security professionals and ethical hackers.

🔗 点击访问项目地址 GitHub - bante27/py-web-vuln-scanner: A modular Web Application Vulnerability Scanner built with Python. Features HTTP header analysis…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #rules

📦 项目名称: sigmaker
👤 项目作者: jhumble
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-20 17:58:03

📝 项目描述:
Autogenerate YARA rules from collections of similar files

🔗 点击访问项目地址 GitHub - jhumble/sigmaker: Autogenerate YARA rules from collections of similar files
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: CVE-2026-18315-PoC
👤 项目作者: nastar-id
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-20 17:38:38

📝 项目描述:
Proof-of-concept for CVE-2026-18315 (TrueBooker WordPress Plugin): Unauthenticated Authorization Bypass Through User-Controlled Key to Account Takeover

🔗 点击访问项目地址
Back to Top