📦 GitHub 全球红队渗透资源中转站。
旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
⚠️ 本频道仅供安全研究与授权测试使用。
旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
⚠️ 本频道仅供安全研究与授权测试使用。
GitHub监控消息提醒!!!
更新了:RCE
描述:A demonstration of the RCE vulnerability in the @nestjs/devtools-integration
URL:https://github.com/JLLeitschuh/nestjs-devtools-integration-rce-poc
标签:#RCE
更新了:RCE
描述:A demonstration of the RCE vulnerability in the @nestjs/devtools-integration
URL:https://github.com/JLLeitschuh/nestjs-devtools-integration-rce-poc
标签:#RCE
GitHub监控消息提醒!!!
更新了:RCE
描述:An automated recon tool for asset discovery and vulnerability scanning using open-source tools. Supports XSS, SQLi, LFI, RCE, IIS, Open Redirect, Swagger UI, .git exposures and more.
URL:https://github.com/rix4uni/GarudRecon
标签:#RCE
更新了:RCE
描述:An automated recon tool for asset discovery and vulnerability scanning using open-source tools. Supports XSS, SQLi, LFI, RCE, IIS, Open Redirect, Swagger UI, .git exposures and more.
URL:https://github.com/rix4uni/GarudRecon
标签:#RCE
GitHub监控消息提醒!!!
更新了:CVE-2025
描述:Disclosure of CVE-2025-46018: A Bluetooth-based payment bypass vulnerability in CSC Pay Mobile App v2.19.4\"
URL:https://github.com/niranjangaire1995/CVE-2025-46018-CSC-Pay-Mobile-App-Payment-Authentication-Bypass
标签:#CVE-2025
更新了:CVE-2025
描述:Disclosure of CVE-2025-46018: A Bluetooth-based payment bypass vulnerability in CSC Pay Mobile App v2.19.4\"
URL:https://github.com/niranjangaire1995/CVE-2025-46018-CSC-Pay-Mobile-App-Payment-Authentication-Bypass
标签:#CVE-2025
GitHub监控消息提醒!!!
更新了:应急响应
描述:这是一个基于 Jetpack Compose 的 Android 应用,专为安全学习者设计,包含渗透测试、内网渗透、Web 安全、应急响应和权限提升相关的题目,帮助用户学习。
URL:https://github.com/Aining777/MyFirstQuizApp
标签:#应急响应
更新了:应急响应
描述:这是一个基于 Jetpack Compose 的 Android 应用,专为安全学习者设计,包含渗透测试、内网渗透、Web 安全、应急响应和权限提升相关的题目,帮助用户学习。
URL:https://github.com/Aining777/MyFirstQuizApp
标签:#应急响应
GitHub监控消息提醒!!!
更新了:渗透测试
描述:changeHeaders是一个功能强大的Burp Suite扩展插件,允许安全专业人员和开发人员轻松修改HTTP请求头。无论您是在进行渗透测试、漏洞赏金 hunting,还是应用程序调试,changeHeaders都能简化跨多个Burp Suite工具的请求头操作过程。
URL:https://github.com/GitHubNull/changeHeaders
标签:#渗透测试
更新了:渗透测试
描述:changeHeaders是一个功能强大的Burp Suite扩展插件,允许安全专业人员和开发人员轻松修改HTTP请求头。无论您是在进行渗透测试、漏洞赏金 hunting,还是应用程序调试,changeHeaders都能简化跨多个Burp Suite工具的请求头操作过程。
URL:https://github.com/GitHubNull/changeHeaders
标签:#渗透测试
GitHub监控消息提醒!!!
更新了:CVE-2025
描述:test for CVE-2025-48384
URL:https://github.com/f1shh/CVE-2025-48384
标签:#CVE-2025
更新了:CVE-2025
描述:test for CVE-2025-48384
URL:https://github.com/f1shh/CVE-2025-48384
标签:#CVE-2025
GitHub监控消息提醒!!!
更新了:RCE
描述:Dashboard RCE Streamlit
URL:https://github.com/PedroVic12/Repopulation-With-Elite-Set
标签:#RCE
更新了:RCE
描述:Dashboard RCE Streamlit
URL:https://github.com/PedroVic12/Repopulation-With-Elite-Set
标签:#RCE
GitHub监控消息提醒!!!
更新了:CVE-2025
描述:CVE-2025-32463 - Sudo Chroot Privilege Escalation Exploit
URL:https://github.com/itstarsec/CVE-2025-48703
标签:#CVE-2025
更新了:CVE-2025
描述:CVE-2025-32463 - Sudo Chroot Privilege Escalation Exploit
URL:https://github.com/itstarsec/CVE-2025-48703
标签:#CVE-2025
GitHub监控消息提醒!!!
更新了:CVE-2025
描述:PoC for CVE-2025-54589 – a reflected XSS vulnerability in Copyparty ≤ 1.18.6.
URL:https://github.com/byteReaper77/CVE-2025-54589
标签:#CVE-2025
更新了:CVE-2025
描述:PoC for CVE-2025-54589 – a reflected XSS vulnerability in Copyparty ≤ 1.18.6.
URL:https://github.com/byteReaper77/CVE-2025-54589
标签:#CVE-2025
GitHub监控消息提醒!!!
更新了:CVE-2025
描述:CVE-2025-30406 ViewState Exploit PoC
URL:https://github.com/mchklt/CVE-2025-30406
标签:#CVE-2025
更新了:CVE-2025
描述:CVE-2025-30406 ViewState Exploit PoC
URL:https://github.com/mchklt/CVE-2025-30406
标签:#CVE-2025
GitHub监控消息提醒!!!
更新了:漏洞检测
描述:通过训练一个源码与二进制的跨模态对齐模型,来应用于二进制漏洞检测,通过源码与二进制之间的映射,在模型认知层面扩展二进制漏洞数据,缓解传统二进制漏洞检测模型对二进制漏洞数据集的依赖
URL:https://github.com/Binary-Bai/Ali2Vul
标签:#漏洞检测
更新了:漏洞检测
描述:通过训练一个源码与二进制的跨模态对齐模型,来应用于二进制漏洞检测,通过源码与二进制之间的映射,在模型认知层面扩展二进制漏洞数据,缓解传统二进制漏洞检测模型对二进制漏洞数据集的依赖
URL:https://github.com/Binary-Bai/Ali2Vul
标签:#漏洞检测
GitHub监控消息提醒!!!
更新了:Cobalt Strike
描述:Custom aggressor scripts en modules voor Cobalt Strike red team operations.
URL:https://github.com/neosecurity-nl/cobalt-extensions
标签:#Cobalt Strike
更新了:Cobalt Strike
描述:Custom aggressor scripts en modules voor Cobalt Strike red team operations.
URL:https://github.com/neosecurity-nl/cobalt-extensions
标签:#Cobalt Strike
GitHub监控消息提醒!!!
更新了:绕过
描述:通过模拟鼠标和其他技巧,来绕过网站的反机器人检测,从而批量获取数据。 Through simulating mouse movements and other techniques to bypass websites' bot detection systems and scrape data in bulk.
URL:https://github.com/Yanagisawa2002/StimulativeMouseForData
标签:#绕过
更新了:绕过
描述:通过模拟鼠标和其他技巧,来绕过网站的反机器人检测,从而批量获取数据。 Through simulating mouse movements and other techniques to bypass websites' bot detection systems and scrape data in bulk.
URL:https://github.com/Yanagisawa2002/StimulativeMouseForData
标签:#绕过
GitHub监控消息提醒!!!
更新了:CVE-2025
描述:a C exploit for CVE-2025-27591, which allow an attacker to escalate privilege to root.
URL:https://github.com/Cythonic1/CVE-2025-27591
标签:#CVE-2025
更新了:CVE-2025
描述:a C exploit for CVE-2025-27591, which allow an attacker to escalate privilege to root.
URL:https://github.com/Cythonic1/CVE-2025-27591
标签:#CVE-2025
GitHub监控消息提醒!!!
更新了:CVE-2025
描述:Stored XSS in a CMS platform leads to remote code execution (CVE-2025-50754)
URL:https://github.com/furk4nyildiz/CVE-2025-50754-PoC
标签:#CVE-2025
更新了:CVE-2025
描述:Stored XSS in a CMS platform leads to remote code execution (CVE-2025-50754)
URL:https://github.com/furk4nyildiz/CVE-2025-50754-PoC
标签:#CVE-2025
GitHub监控消息提醒!!!
更新了:RCE
描述:SQL Injections - exploitation and mitigation techniques like enumeration, UNION injections, file reading/writing, and RCE for offensive security.
URL:https://github.com/ramyardaneshgar/SQLInjection
标签:#RCE
更新了:RCE
描述:SQL Injections - exploitation and mitigation techniques like enumeration, UNION injections, file reading/writing, and RCE for offensive security.
URL:https://github.com/ramyardaneshgar/SQLInjection
标签:#RCE