📦 GitHub 全球红队渗透资源中转站。
​旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
⚠️ 本频道仅供安全研究与授权测试使用。
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026

📦 项目名称: CVE-2026-25731
👤 项目作者: dxlerYT
🛠 开发语言: None
Star数量: 2 | 🍴 Fork数量: 0
📅 更新时间: 2026-02-07 21:37:01

📝 项目描述:
Proof of Concept for a Server-Side Template Injection (SSTI) vulnerability in Calibre’s Templite engine (GHSA-xrh9-w7qx-3gcc). Demonstrates arbitrary Python code execution via user-supplied HTML export templates in affected versions (≤ 9.1.0).

🔗 点击访问项目地址 GitHub - dxlerYT/CVE-2026-25731: Proof of Concept for a Server-Side Template Injection (SSTI) vulnerability in Calibre’s Templite…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Burp #Plugin #Extension

📦 项目名称: BurpAIAnalyst
👤 项目作者: TheDudesRepo
🛠 开发语言: Java
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-02-07 21:02:29

📝 项目描述:
无描述

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #C2 #Command

📦 项目名称: Backdoor
👤 项目作者: Salahidk
🛠 开发语言: None
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-02-07 20:02:53

📝 项目描述:
🛡️ A Python-based Backdoor Proof-of-Concept (PoC) demonstrating C2 communication, persistence mechanisms, and remote command execution for educational analysis.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Bypass #AV

📦 项目名称: ModioDirect
👤 项目作者: Therootexec
🛠 开发语言: Python
Star数量: 3 | 🍴 Fork数量: 0
📅 更新时间: 2026-02-07 20:01:08

📝 项目描述:
ModioDirect is a lightweight, single-file CLI that reliably downloads mods straight from mod.io via the official API—safe, fast, and free for use. Supports manual API-key downloads, bypassing the official client. Works with Space Engineers, SnowRunner, and more.

🔗 点击访问项目地址 GitHub - Therootexec/ModioDirect: A lightweight Python CLI tool to download mods directly from mod.io via offiAPI.
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026

📦 项目名称: cve-2026-21509
👤 项目作者: PinPin1140
🛠 开发语言: None
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-02-07 19:14:24

📝 项目描述:
无描述

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Burp #Extension

📦 项目名称: venom-cache
👤 项目作者: invaen
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-02-07 17:44:51

📝 项目描述:
Web cache poisoning detection from the command line. No Burp Suite required.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #C2 #Command

📦 项目名称: hermes
👤 项目作者: 0xbbuddha
🛠 开发语言: Python
Star数量: 10 | 🍴 Fork数量: 1
📅 更新时间: 2026-02-07 17:56:23

📝 项目描述:
A Python agent targeting Linux for Mythic C2

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF

📦 项目名称: agent-fetch
👤 项目作者: Parassharmaa
🛠 开发语言: Rust
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-02-07 18:01:00

📝 项目描述:
Sandboxed HTTP client with SSRF protection for AI agents. Prevents DNS rebinding, blocks private IPs, and validates every connection — available as a Rust crate and npm package.

🔗 点击访问项目地址 GitHub - Parassharmaa/agent-fetch: Sandboxed HTTP client with SSRF protection for AI agents. Prevents DNS rebinding, blocks private…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Bypass #EDR

📦 项目名称: googledrive-bypass
👤 项目作者: Clovie8
🛠 开发语言: PHP
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-02-07 17:00:27

📝 项目描述:
Bypass Google Virus warning page with download anyway button when your trying to download larger file from google drive >100 MBs

🔗 点击访问项目地址 GitHub - Clovie8/googledrive-bypass: Bypass Google Virus warning page with download anyway button when your trying to download…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Burp #Extension

📦 项目名称: jwt-editor
👤 项目作者: DolphFlynn
🛠 开发语言: Java
Star数量: 25 | 🍴 Fork数量: 17
📅 更新时间: 2026-02-07 16:02:29

📝 项目描述:
A Burp Suite extension for creating and editing JSON Web Tokens. This tool supports signing and verification of JWS, encryption and decryption of JWE and automation of several well-known attacks against applications that consume JWT.

🔗 点击访问项目地址 GitHub - DolphFlynn/jwt-editor: A Burp Suite extension for creating and editing JSON Web Tokens. This tool supports signing and…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Bypass #AV

📦 项目名称: A16-FuseBypass
👤 项目作者: Seegioberserk
🛠 开发语言: None
Star数量: 0 | 🍴 Fork数量: 1
📅 更新时间: 2026-02-07 16:00:36

📝 项目描述:
🔍 Expose a critical flaw in Apple A16 Bionic, enabling unauthorized debug access on iPhone 14 Pro Max without jailbreak, impacting device security.

🔗 点击访问项目地址 GitHub - Seegioberserk/A16-FuseBypass: 🔍 Expose a critical flaw in Apple A16 Bionic, enabling unauthorized debug access on iPhone…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #信息收集

📦 项目名称: film-site-info-collection-log
👤 项目作者: patriciaunlve
🛠 开发语言: None
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-02-07 14:13:59

📝 项目描述:
影视站点信息收集记录。

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026

📦 项目名称: CVE-2026-1281-Ivanti-EPMM-RCE
👤 项目作者: MehdiLeDeaut
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-02-07 14:27:16

📝 项目描述:
Proof of Concept for CVE-2026-1281 & CVE-2026-1340 - Ivanti EPMM Pre-Auth RCE via Bash Arithmetic Expansion

🔗 点击访问项目地址 GitHub - MehdiLeDeaut/CVE-2026-1281-Ivanti-EPMM-RCE: Proof of Concept for CVE-2026-1281 & CVE-2026-1340 - Ivanti EPMM Pre-Auth…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #信息收集

📦 项目名称: movie-site-info-collection
👤 项目作者: patriciaunlve
🛠 开发语言: None
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-02-07 13:43:34

📝 项目描述:
电影站点基础信息收集与整理。

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #C2 #Framework #Server

📦 项目名称: JirBrewStack
👤 项目作者: Jiraphat-DEV
🛠 开发语言: JavaScript
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-02-07 14:02:12

📝 项目描述:
Coffee brewing calculator and timer with roast levels, bean types, and Timemore C2 grind settings

🔗 点击访问项目地址 GitHub - Jiraphat-DEV/JirBrewStack: Coffee brewing calculator and timer with roast levels, bean types, and Timemore C2 grind settings
🚨 GitHub 监控消息提醒

🚨 发现关键词: #BlueTeam #Response

📦 项目名称: cyberbro
👤 项目作者: stanfrbd
🛠 开发语言: Python
Star数量: 583 | 🍴 Fork数量: 53
📅 更新时间: 2026-02-07 13:59:45

📝 项目描述:
A simple application that extracts your IoCs from garbage input and checks their reputation using multiple CTI services.

🔗 点击访问项目地址 GitHub - stanfrbd/cyberbro: A simple application that extracts your IoCs from garbage input and checks their reputation using multiple…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Burp #Extension

📦 项目名称: burp-auto-note
👤 项目作者: boxobi-tech
🛠 开发语言: Shell
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-02-07 12:59:42

📝 项目描述:
Run testing outside burp, but automatically add note to it

🔗 点击访问项目地址 GitHub - boxobi-tech/burp-auto-note: Run testing outside burp, but automatically add note to it
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Shellcode #Inject

📦 项目名称: Native-Adversary-Framework
👤 项目作者: 0x3xp
🛠 开发语言: C
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-02-07 13:02:07

📝 项目描述:
A centralized repository housing comprehensive research and implementations in Low-Level Windows Internals. This lab covers the full spectrum of Offensive Security: from manual PE parsing and shellcode development to advanced process injection and reverse engineering write-ups.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #Attack

📦 项目名称: aaWAF
👤 项目作者: aaPanel
🛠 开发语言: Go
Star数量: 666 | 🍴 Fork数量: 127
📅 更新时间: 2026-02-07 13:02:17

📝 项目描述:
堡塔云WAF,宝塔免费(free)的私有云网站应用防火墙(firewall),基于docker/nginx/lua开发

🔗 点击访问项目地址
Back to Top