📦 GitHub 全球红队渗透资源中转站。
​旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
⚠️ 本频道仅供安全研究与授权测试使用。
🚨 GitHub 监控消息提醒

🚨 发现关键词: #RCE #CVE

📦 项目名称: zimbra-cve
👤 项目作者: gagaltotal
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-27 16:05:08

📝 项目描述:
Zimbra CVE Research Toolkit

🔗 点击访问项目地址 GitHub - gagaltotal/zimbra-cve: Zimbra CVE Research Toolkit
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #漏洞

📦 项目名称: VulnArena
👤 项目作者: 1t01x1w4
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-27 17:03:25

📝 项目描述:
自建 Java Web 漏洞靶场:SQLi / XSS / 文件上传 / 越权 / SSRF / 命令注入

🔗 点击访问项目地址 GitHub - 1t01x1w4/VulnArena: 自建 Java Web 漏洞靶场:SQLi / XSS / 文件上传 / 越权 / SSRF / 命令注入
🚨 GitHub 监控消息提醒

🚨 发现关键词: #反序列化 #Fastjson #Jackson

📦 项目名称: Just-SAST
👤 项目作者: Qmoyue
🛠 开发语言: Java
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-27 13:54:35

📝 项目描述:
一个轻量的用于挖掘反序列化利用链的分析工具。

🔗 点击访问项目地址 GitHub - Qmoyue/Just-SAST: 一个轻量的用于挖掘反序列化利用链的分析工具。
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: Vulnerability_Scanner
👤 项目作者: Preethik09
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-27 16:42:14

📝 项目描述:
A simple python based on vulnerability scanner that scans common ports and detects whether they are open or closed

🔗 点击访问项目地址 GitHub - Preethik09/Vulnerability_Scanner: A simple python based on vulnerability scanner that scans common ports and detects whether…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: VULNERABILITY-SCANNER
👤 项目作者: MiteshBagul008
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-27 16:20:48

📝 项目描述:
无描述

🔗 点击访问项目地址 GitHub - MiteshBagul008/VULNERABILITY-SCANNER
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: CVE-2026-20687-AppleJPEGDriver-UAF
👤 项目作者: 0xjohnnydev
🛠 开发语言: Objective-C
Star数量: 19 | 🍴 Fork数量: 3
📅 更新时间: 2026-08-27 16:43:17

📝 项目描述:
CVE-2026-20687: AppleJPEGDriver startDecoder Timeout UAF — iOS/macOS kernel vulnerability leading to deferred panic (A19 Pro, iOS 26.3 RC)

🔗 点击访问项目地址 GitHub - 0xjohnnydev/CVE-2026-20687-AppleJPEGDriver-UAF: CVE-2026-20687: AppleJPEGDriver startDecoder Timeout UAF — iOS/macOS kernel…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #metadata

📦 项目名称: url-insight-service
👤 项目作者: Aman-Verma-28
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-27 15:30:29

📝 项目描述:
Crawls a URL, extracts page metadata, and classifies the page into topics. FastAPI on AWS Lambda, with SSRF hardening, RFC 9309 robots.txt, content-based bot-wall detection, and a deterministic topic classifier.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: POC-CVE-2026-19295
👤 项目作者: rmhowe425
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-27 15:55:49

📝 项目描述:
无描述

🔗 点击访问项目地址 GitHub - rmhowe425/POC-CVE-2026-19295
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #rules #malware

📦 项目名称: Malware-Scanner-Using-YARA
👤 项目作者: Irfan2311
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-27 14:52:32

📝 项目描述:
A Python-based malware scanner using custom YARA rules to detect suspicious files, generate reports, calculate MD5 hashes, quarantine threats, and monitor files in real time.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #RCE #POC

📦 项目名称: qemu-cxl-mailbox-rce-lab
👤 项目作者: dinosn
🛠 开发语言: Python
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-27 14:28:38

📝 项目描述:
Docker-bounded validation lab for the QEMU CXL mailbox disclosure and handler-overwrite chain

🔗 点击访问项目地址 GitHub - dinosn/qemu-cxl-mailbox-rce-lab: Docker-bounded validation lab for the QEMU CXL mailbox disclosure and handler-overwrite…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #RCE

📦 项目名称: mssharepoint-scanner
👤 项目作者: virologi-info
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-27 13:41:12

📝 项目描述:
A scanner for CVE-2026-55040 and CVE-2026-63520, designed to determine whether the server is affected by these two CVEs.

🔗 点击访问项目地址 virologi-info/mssharepoint-scanner
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: spring-ai-sibling-loop-poc
👤 项目作者: tangyaofq
🛠 开发语言: Java
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-27 13:53:44

📝 项目描述:
Minimal reproduction for Spring AI ParagraphManager sibling self-loop OOM (incomplete fix of CVE-2026-47851)

🔗 点击访问项目地址 GitHub - tangyaofq/spring-ai-sibling-loop-poc: Minimal reproduction for Spring AI ParagraphManager sibling self-loop OOM (incomplete…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Kubernetes #POC

📦 项目名称: krakend-gitops
👤 项目作者: taroninak
🛠 开发语言: HCL
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-27 11:16:07

📝 项目描述:
GitOps POC: KrakenD API gateway on Kubernetes, delivered by Argo CD

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Burp #Plugin #Extension

📦 项目名称: API-Validation
👤 项目作者: MMWARRIOR03
🛠 开发语言: Java
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-27 10:43:47

📝 项目描述:
Automated API security testing framework in Java. Detects SQLi, XSS, SSRF, JWT flaws, CSRF, IDOR, deserialization, and more. Integrates with Burp Suite & OWASP ZAP. Supports CLI usage, Docker deployment, and JSON/PDF reporting with CVSS scoring.

🔗 点击访问项目地址 GitHub - MMWARRIOR03/API-Validation: Automated API security testing framework in Java. Detects SQLi, XSS, SSRF, JWT flaws, CSRF…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Burp #Extension

📦 项目名称: burp-cloudflare-fp-proxy
👤 项目作者: hyderpwn
🛠 开发语言: Go
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-27 13:40:00

📝 项目描述:
Burp upstream proxy that re-originates requests with a real Chrome uTLS (JA3/JA4) + HTTP/2 fingerprint to bypass Cloudflare TLS-fingerprint blocking

🔗 点击访问项目地址 GitHub - hyderpwn/burp-cloudflare-fp-proxy: Burp upstream proxy that re-originates requests with a real Chrome uTLS (JA3/JA4) +…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #malware

📦 项目名称: Malware-analysis-AsphDex
👤 项目作者: dRafaleD
🛠 开发语言: JavaScript
Star数量: 6 | 🍴 Fork数量: 1
📅 更新时间: 2026-08-27 13:49:26

📝 项目描述:
无描述

🔗 点击访问项目地址 GitHub - dRafaleD/Malware-analysis-AsphDex
🚨 GitHub 监控消息提醒

🚨 发现关键词: #威胁情报 #IOC

📦 项目名称: yotta-intel
👤 项目作者: YottaMeta
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-27 13:22:31

📝 项目描述:
元情 yotta-intel — 威胁情报 IOC 提取与规范化引擎:IP/域名/URL/邮箱/哈希/CVE,defang/refang、去重归一、输出 CSV/JSON/STIX-lite(零依赖 Python 3.8+)

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #RCE #CVE

📦 项目名称: weblogic
👤 项目作者: hyderpwn
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-27 13:04:00

📝 项目描述:
Oracle WebLogic Console unauthenticated auth bypass + RCE exploit (CVE-2020-14882 / CVE-2020-14750)

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #rule

📦 项目名称: sigil
👤 项目作者: sltcnb
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-27 12:53:28

📝 项目描述:
Detection engine — Sigma and native rule matching plus YARA over a normalized forensic timeline; detections emitted as events. Part of the Citadel suite.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: nessus
👤 项目作者: nwarila-platform
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-27 12:45:38

📝 项目描述:
Infrastructure-as-code deployment and configuration for a Tenable Nessus vulnerability scanner on the nwarila platform.

🔗 点击访问项目地址
Back to Top