📦 GitHub 全球红队渗透资源中转站。
​旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
⚠️ 本频道仅供安全研究与授权测试使用。
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #CVE #Reflected

📦 项目名称: CVE-2026-30252
👤 项目作者: vEnablee
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-31 20:06:25

📝 项目描述:
The ZenShare Suite application is vulnerable by a Reflected Cross-Site Scripting (XSS) vulnerability, affecting web application login and recovery password functionalities.

🔗 点击访问项目地址 GitHub - vEnablee/CVE-2026-30252: The ZenShare Suite application is vulnerable by a Reflected Cross-Site Scripting (XSS) vulnerability…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Docker #Exploit

📦 项目名称: offsec-lab
👤 项目作者: j32ryc
🛠 开发语言: HTML
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-31 20:00:22

📝 项目描述:
OSCP/OSCP+/OSAI knowledge base + 6 real Docker exploit labs (Log4Shell, Shellshock, Heartbleed, Fastjson, Commons Collections CC6, Shiro-550)

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #渗透测试 #红队

📦 项目名称: Qtzuu-pentest-toolbox
👤 项目作者: fakedon
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 1
📅 更新时间: 2026-08-31 17:57:36

📝 项目描述:
TGSEC社区 @TGSEC · 擎天柱@Qtzuu 渗透测试工具包 —— 假设驱动的授权红队渗透测试技能框架:15个域 + 状态机攻击链 + 证据账本引擎

🔗 点击访问项目地址 GitHub - fakedon/Qtzuu-pentest-toolbox: TGSEC社区 @TGSEC · 擎天柱@Qtzuu 渗透测试工具包 —— 假设驱动的授权红队渗透测试技能框架:15个域 + 状态机攻击链 + 证据账本引擎
🚨 GitHub 监控消息提醒

🚨 发现关键词: #文件上传 #漏洞

📦 项目名称: go-download
👤 项目作者: gomail1
🛠 开发语言: Dockerfile
Star数量: 6 | 🍴 Fork数量: 1
📅 更新时间: 2026-08-31 16:25:25

📝 项目描述:
Go语言开发的高性能文件下载站,提供文件上传、下载、浏览、审核和管理功能,支持基于角色的用户权限控制。

🔗 点击访问项目地址 GitHub - gomail1/go-download: Go语言开发的高性能文件下载站,提供文件上传、下载、浏览、审核和管理功能,支持基于角色的用户权限控制。
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Jenkins #CVE

📦 项目名称: kente-retail-order-service
👤 项目作者: josephakayesi
🛠 开发语言: Shell
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-31 17:53:21

📝 项目描述:
Kente Retail order-service: Jenkins CI/CD with a gating Trivy scan and blue-green deploys (CI/CD lab, 'No More 2 A.M. Releases')

🔗 点击访问项目地址 GitHub - josephakayesi/kente-retail-order-service: Kente Retail order-service: Jenkins CI/CD with a gating Trivy scan and blue…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: securewebsentinel
👤 项目作者: pranaymakkena
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-31 17:02:53

📝 项目描述:
Python-based web application vulnerability scanner using OWASP ZAP, Nmap, and Flask which detects exposed services, insecure headers, and misconfigurations with severity-classified reports.

🔗 点击访问项目地址 GitHub - pranaymakkena/securewebsentinel: Python-based web application vulnerability scanner using OWASP ZAP, Nmap, and Flask which…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #威胁情报 #IOC

📦 项目名称: silverfox-ioc
👤 项目作者: Detect-DefenseLab
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-31 16:52:05

📝 项目描述:
银狐(SilverFox)威胁情报 IOC 数据

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #rule #rules

📦 项目名称: YaraFlux
👤 项目作者: ThreatFlux
🛠 开发语言: Python
Star数量: 23 | 🍴 Fork数量: 7
📅 更新时间: 2026-08-31 16:41:44

📝 项目描述:
A yara based MCP Server

🔗 点击访问项目地址 GitHub - ThreatFlux/YaraFlux: A yara based MCP Server
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Bypass #WAF

📦 项目名称: nimble-csp-ddos-exposure-detection
👤 项目作者: geekyshubham
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-31 15:59:06

📝 项目描述:
Evidence-first multi-cloud DDoS exposure detection and posture management for AWS, Azure, and GCP — WAF, Shield, origin bypass analysis, and attack-path inference.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #rules #malware

📦 项目名称: yarafy
👤 项目作者: Lynk4
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-31 15:00:18

📝 项目描述:
Automated YARA malware hunting and detection framework for security research. Collects malware samples from public feeds, scans them with platform-specific YARA rules, enriches detections with VirusTotal, and generates detection telemetry and reports.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #漏洞

📦 项目名称: Game_SQL_XSS_CSRF_WebSecurity2027
👤 项目作者: bysj2022NB
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-31 14:31:42

📝 项目描述:
基于SQL注入+XSS漏洞检测+CSRF攻击的游戏资讯交流网站安全系统

🔗 点击访问项目地址 GitHub - bysj2022NB/Game_SQL_XSS_CSRF_WebSecurity2027: 基于SQL注入+XSS漏洞检测+CSRF攻击的游戏资讯交流网站安全系统
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #Stored

📦 项目名称: File-Safety-API
👤 项目作者: ishoediah
🛠 开发语言: JavaScript
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-31 15:01:48

📝 项目描述:
File Safety API: Sanitize uploaded files — strip GPS/metadata from images, neutralize CSV formula injection, and remove SVG XSS. A REST API on RapidAPI.

🔗 点击访问项目地址 GitHub - ishoediah/File-Safety-API: File Safety API: Sanitize uploaded files — strip GPS/metadata from images, neutralize CSV formula…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Sliver #C2 #Implant #Beacon

📦 项目名称: sliver-gui
👤 项目作者: 0xnoobsec
🛠 开发语言: Go
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-31 11:55:10

📝 项目描述:
无描述

🔗 点击访问项目地址 GitHub - 0xnoobsec/sliver-gui
🚨 GitHub 监控消息提醒

🚨 发现关键词: #漏洞 #扫描

📦 项目名称: ai-pentest-agent
👤 项目作者: zyjzyjlh3-alt
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-31 14:23:51

📝 项目描述:
AI 自动渗透测试代理系统,基于 CrewAI 框架,集成多种安全扫描工具和漏洞检测能力

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: simple-vulnerability-scanner
👤 项目作者: osmankaankars
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-31 13:28:02

📝 项目描述:
Simple Vulnerability Scanner: scan CycloneDX/SPDX SBOMs against OSV with JSON/HTML/SARIF reports

🔗 点击访问项目地址 GitHub - osmankaankars/simple-vulnerability-scanner: Simple Vulnerability Scanner: scan CycloneDX/SPDX SBOMs against OSV with JSON/HTML/SARIF…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #metadata

📦 项目名称: relay
👤 项目作者: C-Rogs
🛠 开发语言: TypeScript
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-31 13:31:16

📝 项目描述:
Webhook inbox: HMAC, idempotency, SSRF-gated replay, DLQ redrive.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Exchange #EXP

📦 项目名称: home-exchange-cal-sync
👤 项目作者: jeromevidaao
🛠 开发语言: TypeScript
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-31 14:00:58

📝 项目描述:
无描述

🔗 点击访问项目地址 GitHub - jeromevidaao/home-exchange-cal-sync
🚨 GitHub 监控消息提醒

🚨 发现关键词: #漏洞 #利用

📦 项目名称: vibe-csa
👤 项目作者: ok-helloworld
🛠 开发语言: Python
Star数量: 62 | 🍴 Fork数量: 6
📅 更新时间: 2026-08-31 10:36:52

📝 项目描述:
Vibe CSA (Code Security Audit),是一款基于 AI Agent 架构的代码审计工具,采用多 Agent 并行执行架构,用“上帝视角”静态审计源代码,用“实战模拟”动态验证漏洞,保证了 Web 漏洞挖掘的全面性和准确性,输出稳定可靠的安全报告,并提供可落地整改建议。

🔗 点击访问项目地址 GitHub - ok-helloworld/vibe-csa: Vibe CSA (Code Security Audit),是一款基于 AI Agent 架构的代码审计工具,采用多 Agent 并行执行架构,用“上帝视角”静态审计源代码,用“实战模拟”动态验证漏洞,保证了…
🌈🌈🌈🌈8K国际 信誉至上·财富相伴

🌈🌈🌈🌈🌈 8k2289.com

#东南亚盘总首选最权威综合😃台 集团耗资2亿美金 打造全网最牛逼的线上娱乐平台。😄😄😄😄

#大户首选  免实名 免手机号 电子可3000U一拉
😀😀😀😀😀😀😀😀⚡️😀😀😀

😂😂😂😂 1821912.com
TG玩家首选人民币台不限ip 无需手机号无需绑卡

😀😀😀😀😀😀😀😀😀

😀😀😀😀😀😀😀😀😀😀😀😀

1、
极速糖果 30U爆25000倍满倍75万U
2、
百家乐战神 大哥一天时间狂砍100万U
3、
PP电子极速糖果 单注500爆得500万U
4、
神秘大哥 连续稳定输出一天净赚59万U

😀😀😀😀😀😀😀😀😀😀😀
#全网福利天花板
1、单笔提款50万U+ ,赠送5888U-88888U额外奖励
2、支持任意平台vip等级平移
3、每日存款彩金每日送,每笔存款加增1%

存100送28 存500送58
存1000送108 存3000送318
存10000送1288 存50000送5888
存100000送8888 存200000送12888

😀😀😀😀😀😀😀😀😀😀

🔗 官方网址: 8k2289.com
官方频道:@PG8K8K
申请客服:@vipkf8K
🚨 GitHub 监控消息提醒

🚨 发现关键词: #POC #CVE

📦 项目名称: CVE-2018-14667_Lab_POC
👤 项目作者: aitLmalem
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-31 13:05:15

📝 项目描述:
Demonstration of the expression language (EL) injection vulnerability CVE-2018-14667 using the photoalbum lab under Jboss application server

🔗 点击访问项目地址 GitHub - aitLmalem/CVE-2018-14667_Lab_POC: Demonstration of the expression language (EL) injection vulnerability CVE-2018-14667…
Back to Top