​📦 GitHub 全球红队渗透资源中转站。
​旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
​⚠️ 本频道仅供安全研究与授权测试使用。
🚨 GitHub 监控消息提醒

🚨 发现关键词: #C2 #Command and Control

📦 项目名称: Command-and-Control-C2-Server
👤 项目作者: saleh-a23
🛠 开发语言: PHP
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-17 14:57:45

📝 项目描述:
A web-based command and control (C2) server — developed for academic purposes.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #渗透测试 #漏洞

📦 项目名称: pentest-portfolio
👤 项目作者: Y3128
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-17 14:39:25

📝 项目描述:
这是一个进行授权漏洞挖掘的实战作品集,包含渗透测试方法论、完整实战流程、报告提交和零基础教学

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Burp #Plugin #Extension

📦 项目名称: Burpnake
👤 项目作者: egnake
🛠 开发语言: Python
⭐ Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-17 14:24:52

📝 项目描述:
An autonomous AI Bug Bounty platform that intercepts HTTP traffic, performs deep DOM recon, chains vulnerabilities, and generates PoC exploits entirely on its own.

🔗 点击访问项目地址 GitHub - egnake/Burpnake: An autonomous AI Bug Bounty platform that intercepts HTTP traffic, performs deep DOM recon, chains vulnerabilities…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Bypass #EDR

📦 项目名称: hosting
👤 项目作者: Gerjan-CC
🛠 开发语言: JavaScript
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-17 14:04:41

📝 项目描述:
Hosting files on github to bypass firewall / EDR

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #DOM

📦 项目名称: xss-dragon
👤 项目作者: unvalidor
🛠 开发语言: Go
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-17 13:53:50

📝 项目描述:
A powerful, XSS scanner written in Go. XSS-Dragon automates the full reflective-XSS discovery workflow: reflection probing, encoding analysis, context detection, context-specific payload injection, DOM-XSS testing, and headless-browser popup confirmation.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: my-scanner
👤 项目作者: ahmedzaglouledu-debug
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-17 13:54:54

📝 项目描述:
Web vulnerability scanner

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #rule #rules #malware

📦 项目名称: macos-inspector
👤 项目作者: bacescuandrei
🛠 开发语言: Python
⭐ Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-17 13:23:24

📝 项目描述:
Read-only macOS security inspection and DFIR triage tool for incident responders, forensic analysts, and system administrators.

🔗 点击访问项目地址 GitHub - bacescuandrei/macos-inspector: Read-only macOS security inspection and DFIR triage tool for incident responders, forensic…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #metadata

📦 项目名称: ComfyUI-ImmichManager
👤 项目作者: oitsukiii
🛠 开发语言: Python
⭐ Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-17 13:14:27

📝 项目描述:
Upload ComfyUI images/videos to Immich with a built-in preview & management panel. Save nodes embed workflow metadata into PNG/MP4 — download from Immich and drag back to restore workflows. Timeline preview, favorites, trash-safe delete, batch actions, i18n. SSRF-checked, optional Bearer-token panel auth.

🔗 点击访问项目地址 GitHub - oitsukiii/ComfyUI-ImmichManager: Upload ComfyUI images/videos to Immich with a built-in preview & management panel. Save…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #越权 #水平 #逻辑

📦 项目名称: test-lab-api
👤 项目作者: bingu7
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-17 09:20:55

📝 项目描述:
零依赖的测试练习用 Mock 服务:可控缺陷模式,覆盖下单/支付/幂等/越权/并发超卖等真实测试场景

🔗 点击访问项目地址 GitHub - bingu7/test-lab-api: 零依赖的测试练习用 Mock 服务:可控缺陷模式,覆盖下单/支付/幂等/越权/并发超卖等真实测试场景
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #rules

📦 项目名称: yara-rules
👤 项目作者: Marjoriefort
🛠 开发语言: YARA
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-17 12:33:08

📝 项目描述:
无描述

🔗 点击访问项目地址 GitHub - Marjoriefort/yara-rules
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Jenkins #EXP

📦 项目名称: jenkins-exp
👤 项目作者: b-chetna
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-17 12:00:07

📝 项目描述:
无描述

🔗 点击访问项目地址 GitHub - b-chetna/jenkins-exp
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Burp #Extension

📦 项目名称: mcploit-burp
👤 项目作者: Tr0j4n1
🛠 开发语言: Kotlin
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-17 11:18:03

📝 项目描述:
A Burp Suite extension that speaks MCP: connect, enumerate tools/resources/prompts, and hand-craft calls from inside Burp. Repeater for a protocol Burp does not natively understand.

🔗 点击访问项目地址 GitHub - Tr0j4n1/mcploit-burp: A Burp Suite extension that speaks MCP: connect, enumerate tools/resources/prompts, and hand-craft…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Fortinet #Exploit

📦 项目名称: vigil
👤 项目作者: vigiltech01
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-17 12:02:50

📝 项目描述:
Live 3D FortiGate traffic dashboard: open-source, self-hosted FortiGate syslog analyzer with real-time attack visualization, firewall rule risk grading and plain-English log investigations. One Docker container, no agent or API keys.

🔗 点击访问项目地址 GitHub - vigiltech01/vigil: Live 3D FortiGate traffic dashboard: open-source, self-hosted FortiGate syslog analyzer with real-time…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #C2 #Framework

📦 项目名称: wraith
👤 项目作者: Kronoscba
🛠 开发语言: Go
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-17 11:54:29

📝 项目描述:
Professional C2 framework written in Go — multi-protocol (TCP/HTTP/HTTPS/DNS), AES-256-GCM encrypted, cross-platform agent (Linux/Windows/macOS). Integrates with shroud for payload obfuscation.

🔗 点击访问项目地址 GitHub - Kronoscba/wraith: Professional C2 framework written in Go — multi-protocol (TCP/HTTP/HTTPS/DNS), AES-256-GCM encrypted…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: SmartGraphical
👤 项目作者: mohamadpishdar
🛠 开发语言: Solidity
⭐ Star数量: 1 | 🍴 Fork数量: 1
📅 更新时间: 2026-09-17 11:34:34

📝 项目描述:
SmartGraphical: a Solidity Contract Logical Vulnerability Scanner

🔗 点击访问项目地址 GitHub - mohamadpishdar/SmartGraphical: SmartGraphical: a Solidity Contract Logical Vulnerability Scanner
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #metadata

📦 项目名称: ZeroPhish
👤 项目作者: Sarvadnya07
🛠 开发语言: Python
⭐ Star数量: 2 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-17 09:19:14

📝 项目描述:
ZeroPhish is an AI-powered phishing and threat-forensics platform that combines browser-side heuristics, threat intelligence, ML/ONNX analysis, multimodal Gemini reasoning, URL/email inspection, SSRF protection, Redis acceleration, persistent analytics, RBAC, real-time SSE telemetry, and a Chrome MV3 security extension.

🔗 点击访问项目地址 GitHub - Sarvadnya07/ZeroPhish: ZeroPhish is an AI-powered phishing and threat-forensics platform that combines browser-side heuristics…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Burp #Extension

📦 项目名称: My-burp-extension
👤 项目作者: Thinker-cyber
🛠 开发语言: Java
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-17 10:58:42

📝 项目描述:
无描述

🔗 点击访问项目地址 GitHub - Thinker-cyber/My-burp-extension
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Shellcode #Evasion #EDR #AV

📦 项目名称: shroud
👤 项目作者: Kronoscba
🛠 开发语言: Rust
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-17 09:16:27

📝 项目描述:
Professional shellcode encoder & AV/EDR evasion framework written in Rust

🔗 点击访问项目地址 GitHub - Kronoscba/shroud: Professional shellcode encoder & AV/EDR evasion framework written in Rust
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: Automated-Network-Vulnerability-Scanner
👤 项目作者: SrinandHardikar05
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-17 09:59:11

📝 项目描述:
无描述

🔗 点击访问项目地址 GitHub - SrinandHardikar05/Automated-Network-Vulnerability-Scanner
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Burp #Extension

📦 项目名称: jwt-scanner
👤 项目作者: CompassSecurity
🛠 开发语言: Java
⭐ Star数量: 64 | 🍴 Fork数量: 7
📅 更新时间: 2026-09-17 08:48:53

📝 项目描述:
JWT-scanner Burp Extension

🔗 点击访问项目地址 GitHub - CompassSecurity/jwt-scanner: JWT-scanner Burp Extension
Back to Top