📦 GitHub 全球红队渗透资源中转站。
​旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
⚠️ 本频道仅供安全研究与授权测试使用。
🚨 GitHub 监控消息提醒

🚨 发现关键词: #0day #Exploit #RCE

📦 项目名称: darksword-en
👤 项目作者: coruna19980101
🛠 开发语言: JavaScript
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-31 06:36:22

📝 项目描述:
2026 Latest iOS Coruna Vulnerability Drill and DarkSword 0day Frontier Monitoring.

🔗 点击访问项目地址 GitHub - coruna19980101/darksword-en: 2026 Latest iOS Coruna Vulnerability Drill and DarkSword 0day Frontier Monitoring.
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #Stored

📦 项目名称: intigriti-0826
👤 项目作者: Rajib-Mahmud
🛠 开发语言: HTML
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-01 05:20:11

📝 项目描述:
Bad Reception — one leading digit past a validator, stored XSS in the moderation bot, exfiltrating an admin-only TV channel. Intigriti August 2026 write-up.

🔗 点击访问项目地址 GitHub - Rajib-Mahmud/intigriti-0826: Bad Reception — one leading digit past a validator, stored XSS in the moderation bot, exfiltrating…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Nuclei #template

📦 项目名称: raptor
👤 项目作者: Matheuz7k
🛠 开发语言: Shell
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-01 04:21:06

📝 项目描述:
Automated reconnaissance and security assessment pipeline for Linux. One CLI orchestrating subdomain enumeration, port and service scanning, HTTP fingerprinting, crawling, source and secret analysis, content discovery and template based vulnerability scanning.

🔗 点击访问项目地址 GitHub - Matheuz7k/raptor: Automated reconnaissance and security assessment pipeline for Linux. One CLI orchestrating subdomain…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: Python-Based-Vulnerability-Scanner
👤 项目作者: sakthibalan007
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-01 04:34:18

📝 项目描述:
无描述

🔗 点击访问项目地址 GitHub - sakthibalan007/Python-Based-Vulnerability-Scanner
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: AI-Vulnerability-Scanner
👤 项目作者: thoufeeq1605
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-01 05:01:10

📝 项目描述:
无描述

🔗 点击访问项目地址 GitHub - thoufeeq1605/AI-Vulnerability-Scanner
🚨 GitHub 监控消息提醒

🚨 发现关键词: #漏洞 #POC #复现 #CVE

📦 项目名称: log4j2-vuln-lab
👤 项目作者: 14free
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-01 04:15:15

📝 项目描述:
CVE-2021-44228 (Log4Shell) 漏洞复现靶场 | SpringBoot + Log4j2 2.14.1 | 3 个攻击向量 PoC 验证

🔗 点击访问项目地址 GitHub - 14free/log4j2-vuln-lab: CVE-2021-44228 (Log4Shell) 漏洞复现靶场 | SpringBoot + Log4j2 2.14.1 | 3 个攻击向量 PoC 验证
🚨 GitHub 监控消息提醒

🚨 发现关键词: #渗透测试 #靶场

📦 项目名称: 90sqli-skills
👤 项目作者: JiuZero
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-01 02:05:44

📝 项目描述:
面向已授权渗透测试 / CTF / 靶场场景的 SQL 注入验证与取证 AI Skill,将测试固化为低噪声、证据化、可复核的六环节流程。

🔗 点击访问项目地址 GitHub - JiuZero/90sqli-skills: 面向已授权渗透测试 / CTF / 靶场场景的 SQL 注入验证与取证 AI Skill,将测试固化为低噪声、证据化、可复核的六环节流程。
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Exploit #CVE

📦 项目名称: CVE-2021-3493-Exploit
👤 项目作者: r3dw4n48m3d
🛠 开发语言: C
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-01 02:57:11

📝 项目描述:
It's a CVE-2021-3493 Exploit written in C

🔗 点击访问项目地址 GitHub - r3dw4n48m3d/CVE-2021-3493-Exploit: It's a CVE-2021-3493 Exploit written in C
🚨 GitHub 监控消息提醒

🚨 发现关键词: #钓鱼 #演练 #Phishing

📦 项目名称: SmishingDrill
👤 项目作者: baohuiking
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-01 02:12:07

📝 项目描述:
短信钓鱼(Smishing)内部安全意识演练与追踪平台 · Flask + SQLite 单文件 · 多通道发送 / 唯一令牌点击归因 / 实时看板

🔗 点击访问项目地址 GitHub - baohuiking/SmishingDrill: 短信钓鱼(Smishing)内部安全意识演练与追踪平台 · Flask + SQLite 单文件 · 多通道发送 / 唯一令牌点击归因 / 实时看板
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Exploit #POC

📦 项目名称: IW-Knowledge-Base
👤 项目作者: iwcyberops
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-01 01:46:49

📝 项目描述:
Centralized technical vault for IW Cyber Ops. Deep research documentation covering OS Internals, Reverse Engineering, Binary Exploitation, Fuzzing, and 0-Day Methodologies. The digital brain. 🧠

🔗 点击访问项目地址 GitHub - iwcyberops/IW-Knowledge-Base: Centralized technical vault for IW Cyber Ops. Deep research documentation covering OS Internals…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #rule #malware

📦 项目名称: ARGUS
👤 项目作者: mikeperrella
🛠 开发语言: Python
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-01 00:09:28

📝 项目描述:
Supervised detection-engineering pipeline — CAPA/FLOSS/DIE → Claude-drafted YARA-X rule → automated validation → human accept/reject gate. Includes a full malware analysis Detection Story.

🔗 点击访问项目地址 GitHub - mikeperrella/ARGUS: Supervised detection-engineering pipeline — CAPA/FLOSS/DIE → Claude-drafted YARA-X rule → automated…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Burp #Extension

📦 项目名称: Ghost-Js-Burp-Extension
👤 项目作者: trinetlayer
🛠 开发语言: Java
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-31 23:59:24

📝 项目描述:
Burp Suite extension to find hardcoded secrets & hidden endpoints in JavaScript. 150+ detection patterns, active JS fetch, low-noise false-positive filter. Part of TrinetLayer.

🔗 点击访问项目地址 GitHub - trinetlayer/Ghost-Js-Burp-Extension: Burp Suite extension to find hardcoded secrets & hidden endpoints in JavaScript.…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Nuclei #templates

📦 项目名称: nuclei-templates-auto
👤 项目作者: andreich85
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-31 23:59:44

📝 项目描述:
无描述

🔗 点击访问项目地址 GitHub - andreich85/nuclei-templates-auto
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: cloudanix-image-scanner-github-action
👤 项目作者: Cloudanix
🛠 开发语言: Dockerfile
Star数量: 9 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-31 23:52:02

📝 项目描述:
Image Vulnerability Scanner Github Action

🔗 点击访问项目地址 GitHub - Cloudanix/cloudanix-image-scanner-github-action: Image Vulnerability Scanner Github Action
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: crypto-guard-engine
👤 项目作者: tcp-raw
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-31 23:54:16

📝 项目描述:
Multi-Chain Token Risk & Smart Contract Vulnerability Scanner (Solana & EVM)

🔗 点击访问项目地址 GitHub - tcp-raw/crypto-guard-engine: Multi-Chain Token Risk & Smart Contract Vulnerability Scanner (Solana & EVM)
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Nuclei #templates

📦 项目名称: nuclei-templates-auto
👤 项目作者: fofovicfof-ai
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-31 22:16:29

📝 项目描述:
nuclei-templates-auto

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #渗透测试 #漏洞

📦 项目名称: autovibe_pentest
👤 项目作者: kabuqin
🛠 开发语言: Python
Star数量: 3 | 🍴 Fork数量: 1
📅 更新时间: 2026-08-31 16:22:31

📝 项目描述:
基于 Vibe Pentest 的增强版本,采用 AI Agent 架构的自动化渗透测试工具。支持多 Agent 并行执行,能够对 Web 应用、API、管理后台等进行全面的黑盒渗透测试,输出稳定可靠的安全报告。

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #metadata

📦 项目名称: vulnerable-java-application
👤 项目作者: DataDog
🛠 开发语言: Java
Star数量: 23 | 🍴 Fork数量: 153
📅 更新时间: 2026-08-31 19:27:55

📝 项目描述:
This repository contains a sample Java application vulnerable to command injection and server-side request forgery (SSRF).

🔗 点击访问项目地址 GitHub - DataDog/vulnerable-java-application: This repository contains a sample Java application vulnerable to command injection…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #CVE

📦 项目名称: nextjs-react-security
👤 项目作者: AhmedNnasser11
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-31 19:46:07

📝 项目描述:
Senior-AppSec-style OpenCode skill for auditing and hardening Next.js App Router + React + TypeScript apps — injection, auth, Server Actions, CSRF/SSRF, CSP, and dependency risk. No CAPTCHA, no blind sanitization, no unjustified deps.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #CVE #Reflected

📦 项目名称: CVE-2026-30251
👤 项目作者: vEnablee
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-31 20:06:47

📝 项目描述:
A reflected cross-site scripting (XSS) vulnerability in the login_newpwd.php endpoint of Interzen Consulting S.r.l ZenShare Suite v17.0 allows attackers to execute arbitrary Javascript in the context of the user's browser via a crafted URL injected into the codice_azienda parameter.

🔗 点击访问项目地址 GitHub - vEnablee/CVE-2026-30251: A reflected cross-site scripting (XSS) vulnerability in the login_newpwd.php endpoint of Interzen…
Back to Top