​📦 GitHub 全球红队渗透资源中转站。
​旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
​⚠️ 本频道仅供安全研究与授权测试使用。
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #malware

📦 项目名称: poc-malware-control
👤 项目作者: anaselkarkouri
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-13 02:02:45

📝 项目描述:
Automated suspicious-file analysis with Python, ClamAV, YARA, CAPEv2, Sysmon and Wazuh

🔗 点击访问项目地址 GitHub - anaselkarkouri/poc-malware-control: Automated suspicious-file analysis with Python, ClamAV, YARA, CAPEv2, Sysmon and Wazuh
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #Stored #Reflected #DOM

📦 项目名称: Cross-Site-Scripting-XSS-
👤 项目作者: Kyzerz53
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-12 22:59:50

📝 项目描述:
无描述

🔗 点击访问项目地址 GitHub - Kyzerz53/Cross-Site-Scripting-XSS-
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC #RCE

📦 项目名称: CVE-2026-33439-Python-PoC
👤 项目作者: infernosalex
🛠 开发语言: Python
⭐ Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-12 22:20:26

📝 项目描述:
Python PoC for CVE-2026-33439, an OpenAM pre-authentication RCE via jato.clientSession deserialization

🔗 点击访问项目地址 GitHub - infernosalex/CVE-2026-33439-Python-PoC: Python PoC for CVE-2026-33439, an OpenAM pre-authentication RCE via jato.clientSession…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Burp #Extension

📦 项目名称: reverse-api-burp
👤 项目作者: JonsTech
🛠 开发语言: Java
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-12 21:13:00

📝 项目描述:
Burp Suite extension that passively discovers APIs in Proxy traffic and generates OpenAPI 3.1 specifications and Postman collections.

🔗 点击访问项目地址 GitHub - JonsTech/reverse-api-burp: Burp Suite extension that passively discovers APIs in Proxy traffic and generates OpenAPI 3.1…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Bypass #WAF

📦 项目名称: rust-recaptcha-bypass
👤 项目作者: itsanwar
🛠 开发语言: Rust
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-12 22:03:29

📝 项目描述:
无描述

🔗 点击访问项目地址 GitHub - itsanwar/rust-recaptcha-bypass
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC #Exploit

📦 项目名称: cve-2026-85706-poc-exploit-gitlab
👤 项目作者: 0xlyvio
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-12 20:42:11

📝 项目描述:
cve-2026-85706-poc-exploit-gitlab

🔗 点击访问项目地址 GitHub - 0xlyvio/cve-2026-85706-poc-exploit-gitlab: cve-2026-85706-poc-exploit-gitlab
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: action-wordpress-vulnerability-scanner
👤 项目作者: jazzsequence
🛠 开发语言: Shell
⭐ Star数量: 4 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-12 19:57:32

📝 项目描述:
A GitHub action that can be used to run vulnerability checks using the 10up WP-CLI Vulnerability Scanner

🔗 点击访问项目地址 GitHub - jazzsequence/action-wordpress-vulnerability-scanner: A GitHub action that can be used to run vulnerability checks using…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Nuclei #templates

📦 项目名称: bb-recon-toolkit
👤 项目作者: Ngelcondor
🛠 开发语言: Shell
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-12 19:33:55

📝 项目描述:
Scoped, rate-limited bug bounty recon tooling in Bash + HackerOne report templates

🔗 点击访问项目地址 GitHub - Ngelcondor/bb-recon-toolkit: Scoped, rate-limited bug bounty recon tooling in Bash + HackerOne report templates
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #Stored #Reflected #DOM

📦 项目名称: DVWA-Web-App-Pentesting
👤 项目作者: Mahhyya
🛠 开发语言: Unknown
⭐ Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-12 18:04:24

📝 项目描述:
Pentesting DVWA across SQLi, XSS, Command Injection, File Inclusion, File Upload, Brute Force, and CSRF — Low to High difficulty

🔗 点击访问项目地址 GitHub - Mahhyya/DVWA-Web-App-Pentesting: Pentesting DVWA across SQLi, XSS, Command Injection, File Inclusion, File Upload, Brute…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Bypass #WAF

📦 项目名称: nuclei-bb-templates
👤 项目作者: unrandoms
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-12 17:59:00

📝 项目描述:
Custom Nuclei templates for IDOR, SSRF, JWT attacks, WAF bypass detection, and secrets exposure

🔗 点击访问项目地址 unrandoms/nuclei-bb-templates
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: Cyber-security-and-ethical-hacking
👤 项目作者: anushree-cyber1
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-12 16:50:34

📝 项目描述:
Cyber security and ethical hacking .The project:1password strength Analyzer 2Data encryption and decryption tool 3phishing email simulation 4simple vulnerability scanner

🔗 点击访问项目地址 GitHub - anushree-cyber1/Cyber-security-and-ethical-hacking: Cyber security and ethical hacking .The project:1password strength…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #C2 #Framework #Implant #Beacon

📦 项目名称: Unkn0wnC2
👤 项目作者: abb3rrant
🛠 开发语言: Go
⭐ Star数量: 7 | 🍴 Fork数量: 4
📅 更新时间: 2026-09-12 16:58:16

📝 项目描述:
Stealth focused DNS C2 with Shadow Mesh architecture and malleable timing and payloads for Adversary Emulation.

🔗 点击访问项目地址 GitHub - abb3rrant/Unkn0wnC2: Stealth focused DNS C2 with Shadow Mesh architecture and malleable timing and payloads for Adversary…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #Stored #Reflected #DOM

📦 项目名称: vulnXss
👤 项目作者: bashx7
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-12 15:46:24

📝 项目描述:
A practical XSS lab covering Reflected, Stored, and DOM-based Cross-Site Scripting vulnerabilities, with multiple beginner-friendly scenarios to help learners understand and practice different XSS techniques.

🔗 点击访问项目地址 GitHub - bashx7/vulnXss: A practical XSS lab covering Reflected, Stored, and DOM-based Cross-Site Scripting vulnerabilities, with…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #Stored

📦 项目名称: Stored-XSS-and-Session-Hijacking-Simulation-
👤 项目作者: lepemiran47-png
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-12 15:49:22

📝 项目描述:
无描述

🔗 点击访问项目地址 GitHub - lepemiran47-png/Stored-XSS-and-Session-Hijacking-Simulation-
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: PhantomRecon
👤 项目作者: jaylukdevelopment
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-12 13:29:24

📝 项目描述:
PhantomRecon — Professional bug bounty vulnerability scanner with CLI + Streamlit dashboard

🔗 点击访问项目地址 GitHub - jaylukdevelopment/PhantomRecon: PhantomRecon — Professional bug bounty vulnerability scanner with CLI + Streamlit dashboard
🚨 GitHub 监控消息提醒

🚨 发现关键词: #内网渗透 #域控 #提权 #隧道 #代理

📦 项目名称: pivothub
👤 项目作者: ProbiusOfficial
🛠 开发语言: Python
⭐ Star数量: 8 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-12 13:21:54

📝 项目描述:
CTF多层内网渗透辅助工具

🔗 点击访问项目地址 GitHub - ProbiusOfficial/pivothub: CTF多层内网渗透辅助工具
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Exploit #RCE

📦 项目名称: vuln-chain-labs
👤 项目作者: Boubekeur-Khalil
🛠 开发语言: PHP
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-12 13:58:16

📝 项目描述:
Deliberately vulnerable API reproducing a real-world exploit chain: nOAuth ATO → LFI → JWT Forgery → RCE. 7 Docker-based labs with walkthroughs. From an authorized bug bounty engagement.

🔗 点击访问项目地址 GitHub - Boubekeur-Khalil/vuln-chain-labs: Deliberately vulnerable API reproducing a real-world exploit chain: nOAuth ATO → LFI…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Nuclei #template

📦 项目名称: CTPAX
👤 项目作者: Takopipipi
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-12 12:31:43

📝 项目描述:
CTPAX - reverse-engineering MCP server: Ghidra, x64dbg, Nuclei, Metasploit, Wireshark, forgery & license-gate tooling (248 tools)

🔗 点击访问项目地址 GitHub - Takopipipi/CTPAX: CTPAX - reverse-engineering MCP server: Ghidra, x64dbg, Nuclei, Metasploit, Wireshark, forgery & license…
Back to Top