📦 GitHub 全球红队渗透资源中转站。
​旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
⚠️ 本频道仅供安全研究与授权测试使用。
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Burp #Plugin #Extension

📦 项目名称: API-Validation
👤 项目作者: MMWARRIOR03
🛠 开发语言: Java
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-27 10:43:47

📝 项目描述:
Automated API security testing framework in Java. Detects SQLi, XSS, SSRF, JWT flaws, CSRF, IDOR, deserialization, and more. Integrates with Burp Suite & OWASP ZAP. Supports CLI usage, Docker deployment, and JSON/PDF reporting with CVSS scoring.

🔗 点击访问项目地址 GitHub - MMWARRIOR03/API-Validation: Automated API security testing framework in Java. Detects SQLi, XSS, SSRF, JWT flaws, CSRF…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Burp #Extension

📦 项目名称: burp-cloudflare-fp-proxy
👤 项目作者: hyderpwn
🛠 开发语言: Go
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-27 13:40:00

📝 项目描述:
Burp upstream proxy that re-originates requests with a real Chrome uTLS (JA3/JA4) + HTTP/2 fingerprint to bypass Cloudflare TLS-fingerprint blocking

🔗 点击访问项目地址 GitHub - hyderpwn/burp-cloudflare-fp-proxy: Burp upstream proxy that re-originates requests with a real Chrome uTLS (JA3/JA4) +…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #malware

📦 项目名称: Malware-analysis-AsphDex
👤 项目作者: dRafaleD
🛠 开发语言: JavaScript
Star数量: 6 | 🍴 Fork数量: 1
📅 更新时间: 2026-08-27 13:49:26

📝 项目描述:
无描述

🔗 点击访问项目地址 GitHub - dRafaleD/Malware-analysis-AsphDex
🚨 GitHub 监控消息提醒

🚨 发现关键词: #威胁情报 #IOC

📦 项目名称: yotta-intel
👤 项目作者: YottaMeta
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-27 13:22:31

📝 项目描述:
元情 yotta-intel — 威胁情报 IOC 提取与规范化引擎:IP/域名/URL/邮箱/哈希/CVE,defang/refang、去重归一、输出 CSV/JSON/STIX-lite(零依赖 Python 3.8+)

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #RCE #CVE

📦 项目名称: weblogic
👤 项目作者: hyderpwn
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-27 13:04:00

📝 项目描述:
Oracle WebLogic Console unauthenticated auth bypass + RCE exploit (CVE-2020-14882 / CVE-2020-14750)

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #rule

📦 项目名称: sigil
👤 项目作者: sltcnb
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-27 12:53:28

📝 项目描述:
Detection engine — Sigma and native rule matching plus YARA over a normalized forensic timeline; detections emitted as events. Part of the Citadel suite.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: nessus
👤 项目作者: nwarila-platform
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-27 12:45:38

📝 项目描述:
Infrastructure-as-code deployment and configuration for a Tenable Nessus vulnerability scanner on the nwarila platform.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Exploit #CVE #RCE

📦 项目名称: CVE-2020-14882-weblogic
👤 项目作者: hyderpwn
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-27 12:57:47

📝 项目描述:
Oracle WebLogic Console unauthenticated auth bypass + RCE exploit (CVE-2020-14882 / CVE-2020-14750)

🔗 点击访问项目地址 GitHub - hyderpwn/CVE-2020-14882-weblogic: Oracle WebLogic Console unauthenticated auth bypass + RCE exploit (CVE-2020-14882 /…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #Exploit

📦 项目名称: rmg-s9180-fzg1
👤 项目作者: hackyangwen-lgtm
🛠 开发语言: C
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-27 12:38:55

📝 项目描述:
Root My Galaxy SM-S9180 (dm3q) S9180ZHS8FZG1 payload port - CVE-2026-43499 + KernelSU LKM

🔗 点击访问项目地址 GitHub - hackyangwen-lgtm/rmg-s9180-fzg1: Root My Galaxy SM-S9180 (dm3q) S9180ZHS8FZG1 payload port - CVE-2026-43499 + KernelSU…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Bypass #Sandbox

📦 项目名称: sandbox
👤 项目作者: satishbabariya
🛠 开发语言: Swift
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-27 12:06:24

📝 项目描述:
Run coding agents in Apple Virtualization VMs whose network egress they cannot bypass. Enforcement lives outside the guest, so it holds even against root with every capability.

🔗 点击访问项目地址 GitHub - satishbabariya/sandbox: Run coding agents in Apple Virtualization VMs whose network egress they cannot bypass. Enforcement…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #漏洞 #扫描

📦 项目名称: network-security-lab
👤 项目作者: Xufazhong
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-27 12:01:50

📝 项目描述:
网络安全实验室:漏洞扫描与防御策略

🔗 点击访问项目地址 GitHub - Xufazhong/network-security-lab: 网络安全实验室:漏洞扫描与防御策略
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: Website-Vulnerability-Scanner
👤 项目作者: Ibrahimx07
🛠 开发语言: JavaScript
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-27 11:20:11

📝 项目描述:
A web-based vulnerability scanner for authorized security assessments using OWASP ZAP.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: python-security-tools
👤 项目作者: Sharan-Ravindran
🛠 开发语言: Python
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-27 11:56:51

📝 项目描述:
Python security tools built from scratch while learning ethical hacking — port scanner, web vulnerability scanner, and password analyser.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Exploit #CVE

📦 项目名称: pentesting-ai-agent
👤 项目作者: dishant-vaidya
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-27 10:58:01

📝 项目描述:
Autonomous AI-powered penetration testing agent built with LangGraph and Groq (Llama 3). Automates recon, nmap scanning, CVE lookup via ChromaDB, and exploit planning through a multi-phase reasoning pipeline, with a Streamlit UI. Dockerized for deployment. For authorized CTF, VulnHub, and HackTheBox lab environments only.

🔗 点击访问项目地址 dishant-vaidya/pentesting-ai-agent
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #APT

📦 项目名称: packages
👤 项目作者: vsdudakov
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-27 11:01:03

📝 项目描述:
APT and DNF repositories for Yara Code

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #C2 #Framework #Command and Control

📦 项目名称: concorde-redteam-suite
👤 项目作者: e-migi
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-27 10:54:42

📝 项目描述:
Concorde is an advanced, GUI-based Red Team command and control (C2) framework designed for penetration testers and security professionals. It provides a comprehensive suite of tools for reverse shell management, payload generation, and post-exploitation activities in Windows environments.

🔗 点击访问项目地址 GitHub - e-migi/concorde-redteam-suite: Concorde is an advanced, GUI-based Red Team command and control (C2) framework designed…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Nuclei #POC

📦 项目名称: nuclei_check_repertev
👤 项目作者: BeliefGuy
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-27 10:23:45

📝 项目描述:
检查并自动删除完全重复的nuclei poc,也可以设置相似度阈值,匹配相似度删除。

🔗 点击访问项目地址 GitHub - BeliefGuy/nuclei_check_repertev: 检查并自动删除完全重复的nuclei poc,也可以设置相似度阈值,匹配相似度删除。
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: web-xss-scanner-and-patcher
👤 项目作者: pubudud735-dotcom
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-27 11:00:05

📝 项目描述:
Automated Python XSS Vulnerability Scanner and PHP Remediation Project

🔗 点击访问项目地址 GitHub - pubudud735-dotcom/web-xss-scanner-and-patcher: Automated Python XSS Vulnerability Scanner and PHP Remediation Project
🚨 GitHub 监控消息提醒

🚨 发现关键词: #RCE #CVE #Remote Code Execution

📦 项目名称: App-Vibe-Security
👤 项目作者: HajibagheriLabs
🛠 开发语言: JavaScript
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-27 08:25:37

📝 项目描述:
Zero-trust security guardrails and automated audit tools for AI-generated mobile and desktop apps. Prevents Electron RCE escapes, unsafe IPC channels, plaintext credential storage, and deep link tampering across React Native, Flutter, Android, iOS, and Electron vibe-coded projects.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #rules

📦 项目名称: portfolio-secops-detections
👤 项目作者: kelvinodarikpe88
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-27 09:42:38

📝 项目描述:
GitHub-only: Chronicle YARA-L, Splunk SPL, Defender XDR hunting concepts, Gitleaks/Semgrep CI. Not employer production.

🔗 点击访问项目地址 GitHub - kelvinodarikpe88/portfolio-secops-detections: GitHub-only: Chronicle YARA-L, Splunk SPL, Defender XDR hunting concepts…
Back to Top