📦 GitHub 全球红队渗透资源中转站。
​旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
⚠️ 本频道仅供安全研究与授权测试使用。
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #rule #malware

📦 项目名称: ARGUS
👤 项目作者: mikeperrella
🛠 开发语言: Python
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-01 00:09:28

📝 项目描述:
Supervised detection-engineering pipeline — CAPA/FLOSS/DIE → Claude-drafted YARA-X rule → automated validation → human accept/reject gate. Includes a full malware analysis Detection Story.

🔗 点击访问项目地址 GitHub - mikeperrella/ARGUS: Supervised detection-engineering pipeline — CAPA/FLOSS/DIE → Claude-drafted YARA-X rule → automated…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Burp #Extension

📦 项目名称: Ghost-Js-Burp-Extension
👤 项目作者: trinetlayer
🛠 开发语言: Java
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-31 23:59:24

📝 项目描述:
Burp Suite extension to find hardcoded secrets & hidden endpoints in JavaScript. 150+ detection patterns, active JS fetch, low-noise false-positive filter. Part of TrinetLayer.

🔗 点击访问项目地址 GitHub - trinetlayer/Ghost-Js-Burp-Extension: Burp Suite extension to find hardcoded secrets & hidden endpoints in JavaScript.…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Nuclei #templates

📦 项目名称: nuclei-templates-auto
👤 项目作者: andreich85
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-31 23:59:44

📝 项目描述:
无描述

🔗 点击访问项目地址 GitHub - andreich85/nuclei-templates-auto
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: cloudanix-image-scanner-github-action
👤 项目作者: Cloudanix
🛠 开发语言: Dockerfile
Star数量: 9 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-31 23:52:02

📝 项目描述:
Image Vulnerability Scanner Github Action

🔗 点击访问项目地址 GitHub - Cloudanix/cloudanix-image-scanner-github-action: Image Vulnerability Scanner Github Action
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: crypto-guard-engine
👤 项目作者: tcp-raw
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-31 23:54:16

📝 项目描述:
Multi-Chain Token Risk & Smart Contract Vulnerability Scanner (Solana & EVM)

🔗 点击访问项目地址 GitHub - tcp-raw/crypto-guard-engine: Multi-Chain Token Risk & Smart Contract Vulnerability Scanner (Solana & EVM)
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Nuclei #templates

📦 项目名称: nuclei-templates-auto
👤 项目作者: fofovicfof-ai
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-31 22:16:29

📝 项目描述:
nuclei-templates-auto

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #渗透测试 #漏洞

📦 项目名称: autovibe_pentest
👤 项目作者: kabuqin
🛠 开发语言: Python
Star数量: 3 | 🍴 Fork数量: 1
📅 更新时间: 2026-08-31 16:22:31

📝 项目描述:
基于 Vibe Pentest 的增强版本,采用 AI Agent 架构的自动化渗透测试工具。支持多 Agent 并行执行,能够对 Web 应用、API、管理后台等进行全面的黑盒渗透测试,输出稳定可靠的安全报告。

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #metadata

📦 项目名称: vulnerable-java-application
👤 项目作者: DataDog
🛠 开发语言: Java
Star数量: 23 | 🍴 Fork数量: 153
📅 更新时间: 2026-08-31 19:27:55

📝 项目描述:
This repository contains a sample Java application vulnerable to command injection and server-side request forgery (SSRF).

🔗 点击访问项目地址 GitHub - DataDog/vulnerable-java-application: This repository contains a sample Java application vulnerable to command injection…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #CVE

📦 项目名称: nextjs-react-security
👤 项目作者: AhmedNnasser11
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-31 19:46:07

📝 项目描述:
Senior-AppSec-style OpenCode skill for auditing and hardening Next.js App Router + React + TypeScript apps — injection, auth, Server Actions, CSRF/SSRF, CSP, and dependency risk. No CAPTCHA, no blind sanitization, no unjustified deps.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #CVE #Reflected

📦 项目名称: CVE-2026-30251
👤 项目作者: vEnablee
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-31 20:06:47

📝 项目描述:
A reflected cross-site scripting (XSS) vulnerability in the login_newpwd.php endpoint of Interzen Consulting S.r.l ZenShare Suite v17.0 allows attackers to execute arbitrary Javascript in the context of the user's browser via a crafted URL injected into the codice_azienda parameter.

🔗 点击访问项目地址 GitHub - vEnablee/CVE-2026-30251: A reflected cross-site scripting (XSS) vulnerability in the login_newpwd.php endpoint of Interzen…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #CVE #Reflected

📦 项目名称: CVE-2026-30252
👤 项目作者: vEnablee
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-31 20:06:25

📝 项目描述:
The ZenShare Suite application is vulnerable by a Reflected Cross-Site Scripting (XSS) vulnerability, affecting web application login and recovery password functionalities.

🔗 点击访问项目地址 GitHub - vEnablee/CVE-2026-30252: The ZenShare Suite application is vulnerable by a Reflected Cross-Site Scripting (XSS) vulnerability…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Docker #Exploit

📦 项目名称: offsec-lab
👤 项目作者: j32ryc
🛠 开发语言: HTML
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-31 20:00:22

📝 项目描述:
OSCP/OSCP+/OSAI knowledge base + 6 real Docker exploit labs (Log4Shell, Shellshock, Heartbleed, Fastjson, Commons Collections CC6, Shiro-550)

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #渗透测试 #红队

📦 项目名称: Qtzuu-pentest-toolbox
👤 项目作者: fakedon
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 1
📅 更新时间: 2026-08-31 17:57:36

📝 项目描述:
TGSEC社区 @TGSEC · 擎天柱@Qtzuu 渗透测试工具包 —— 假设驱动的授权红队渗透测试技能框架:15个域 + 状态机攻击链 + 证据账本引擎

🔗 点击访问项目地址 GitHub - fakedon/Qtzuu-pentest-toolbox: TGSEC社区 @TGSEC · 擎天柱@Qtzuu 渗透测试工具包 —— 假设驱动的授权红队渗透测试技能框架:15个域 + 状态机攻击链 + 证据账本引擎
🚨 GitHub 监控消息提醒

🚨 发现关键词: #文件上传 #漏洞

📦 项目名称: go-download
👤 项目作者: gomail1
🛠 开发语言: Dockerfile
Star数量: 6 | 🍴 Fork数量: 1
📅 更新时间: 2026-08-31 16:25:25

📝 项目描述:
Go语言开发的高性能文件下载站,提供文件上传、下载、浏览、审核和管理功能,支持基于角色的用户权限控制。

🔗 点击访问项目地址 GitHub - gomail1/go-download: Go语言开发的高性能文件下载站,提供文件上传、下载、浏览、审核和管理功能,支持基于角色的用户权限控制。
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Jenkins #CVE

📦 项目名称: kente-retail-order-service
👤 项目作者: josephakayesi
🛠 开发语言: Shell
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-31 17:53:21

📝 项目描述:
Kente Retail order-service: Jenkins CI/CD with a gating Trivy scan and blue-green deploys (CI/CD lab, 'No More 2 A.M. Releases')

🔗 点击访问项目地址 GitHub - josephakayesi/kente-retail-order-service: Kente Retail order-service: Jenkins CI/CD with a gating Trivy scan and blue…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: securewebsentinel
👤 项目作者: pranaymakkena
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-31 17:02:53

📝 项目描述:
Python-based web application vulnerability scanner using OWASP ZAP, Nmap, and Flask which detects exposed services, insecure headers, and misconfigurations with severity-classified reports.

🔗 点击访问项目地址 GitHub - pranaymakkena/securewebsentinel: Python-based web application vulnerability scanner using OWASP ZAP, Nmap, and Flask which…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #威胁情报 #IOC

📦 项目名称: silverfox-ioc
👤 项目作者: Detect-DefenseLab
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-31 16:52:05

📝 项目描述:
银狐(SilverFox)威胁情报 IOC 数据

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #rule #rules

📦 项目名称: YaraFlux
👤 项目作者: ThreatFlux
🛠 开发语言: Python
Star数量: 23 | 🍴 Fork数量: 7
📅 更新时间: 2026-08-31 16:41:44

📝 项目描述:
A yara based MCP Server

🔗 点击访问项目地址 GitHub - ThreatFlux/YaraFlux: A yara based MCP Server
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Bypass #WAF

📦 项目名称: nimble-csp-ddos-exposure-detection
👤 项目作者: geekyshubham
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-31 15:59:06

📝 项目描述:
Evidence-first multi-cloud DDoS exposure detection and posture management for AWS, Azure, and GCP — WAF, Shield, origin bypass analysis, and attack-path inference.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #rules #malware

📦 项目名称: yarafy
👤 项目作者: Lynk4
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-31 15:00:18

📝 项目描述:
Automated YARA malware hunting and detection framework for security research. Collects malware samples from public feeds, scans them with platform-specific YARA rules, enriches detections with VirusTotal, and generates detection telemetry and reports.

🔗 点击访问项目地址
Back to Top