📦 GitHub 全球红队渗透资源中转站。
旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
⚠️ 本频道仅供安全研究与授权测试使用。
旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
⚠️ 本频道仅供安全研究与授权测试使用。
🚨 GitHub 监控消息提醒
🚨 发现关键词: #CVE-2026 #Exploit
📦 项目名称: CVE-2026-5029-Exploit
👤 项目作者: 0x00phantom-hat
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-20 11:55:34
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #CVE-2026 #Exploit
📦 项目名称: CVE-2026-5029-Exploit
👤 项目作者: 0x00phantom-hat
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-20 11:55:34
📝 项目描述:
无描述🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #Exploit #POC
📦 项目名称: malleable-signatures
👤 项目作者: pcaversaccio
🛠 开发语言: Solidity
⭐ Star数量: 113 | 🍴 Fork数量: 9
📅 更新时间: 2026-07-20 10:46:52
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #Exploit #POC
📦 项目名称: malleable-signatures
👤 项目作者: pcaversaccio
🛠 开发语言: Solidity
⭐ Star数量: 113 | 🍴 Fork数量: 9
📅 更新时间: 2026-07-20 10:46:52
📝 项目描述:
This repository implements a simplified PoC that demonstrates how signature malleability attacks using compact signatures can be executed.🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #Exploit #POC
📦 项目名称: tornado-cash-exploit
👤 项目作者: pcaversaccio
🛠 开发语言: Solidity
⭐ Star数量: 63 | 🍴 Fork数量: 11
📅 更新时间: 2026-07-20 10:48:06
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #Exploit #POC
📦 项目名称: tornado-cash-exploit
👤 项目作者: pcaversaccio
🛠 开发语言: Solidity
⭐ Star数量: 63 | 🍴 Fork数量: 11
📅 更新时间: 2026-07-20 10:48:06
📝 项目描述:
This repository implements a simplified PoC that showcases how a contract can morph. A similar approach was used as part of the governance attack on Tornado Cash in May 2023.🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #Burp #Extension
📦 项目名称: burpforge
👤 项目作者: Gopesh-K
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-20 10:14:22
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #Burp #Extension
📦 项目名称: burpforge
👤 项目作者: Gopesh-K
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-20 10:14:22
📝 项目描述:
AI-assisted Burp Suite extension with JWT decoder, secret scanner, CVSS calculator, and more...🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #YARA #rule
📦 项目名称: yara-rule-generator
👤 项目作者: fetihcakmak
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-20 10:38:03
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #YARA #rule
📦 项目名称: yara-rule-generator
👤 项目作者: fetihcakmak
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-20 10:38:03
📝 项目描述:
无描述🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #漏洞 #复现
📦 项目名称: web-security-lab
👤 项目作者: genius1h
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-20 11:01:55
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #漏洞 #复现
📦 项目名称: web-security-lab
👤 项目作者: genius1h
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-20 11:01:55
📝 项目描述:
「Web安全学习笔记与漏洞攻防手册,含 SQL注入/XSS/CSRF/SSRF/文件上传/命令注入 6类漏洞的复现、检测与防御方案。」🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #CVE-2026 #Exploit #RCE
📦 项目名称: sxwp2shell
👤 项目作者: SentinelXofficial
🛠 开发语言: Python
⭐ Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-20 10:49:08
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #CVE-2026 #Exploit #RCE
📦 项目名称: sxwp2shell
👤 项目作者: SentinelXofficial
🛠 开发语言: Python
⭐ Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-20 10:49:08
📝 项目描述:
WordPress wp2shell pre-auth RCE exploit kit (CVE-2026-63030 + CVE-2026-60137)🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #Vulnerability Scanner
📦 项目名称: vcpkg-vuln-scan
👤 项目作者: emabrey
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-20 09:50:11
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #Vulnerability Scanner
📦 项目名称: vcpkg-vuln-scan
👤 项目作者: emabrey
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-20 09:50:11
📝 项目描述:
A small vulnerability scanner for projects that get their C/C++ dependencies from vcpkg🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #Vulnerability Scanner
📦 项目名称: Cybersecurity-Vulnerability-Scanner
👤 项目作者: Vignesh1231234
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-20 10:01:57
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #Vulnerability Scanner
📦 项目名称: Cybersecurity-Vulnerability-Scanner
👤 项目作者: Vignesh1231234
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-20 10:01:57
📝 项目描述:
Cybersecurity Vulnerability Scanner is a Python-based security tool designed to identify common vulnerabilities in web applications and networks. It performs automated security assessments by scanning for open ports, detecting SQL Injection (SQLi), Cross-Site Scripting (XSS), insecure HTTP headers, and other common security misconfigurations.🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #RCE #POC
📦 项目名称: POC-NodeRed-RCE-Import
👤 项目作者: MathisFranel
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-20 08:14:50
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #RCE #POC
📦 项目名称: POC-NodeRed-RCE-Import
👤 项目作者: MathisFranel
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-20 08:14:50
📝 项目描述:
无描述🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #Vulnerability Scanner
📦 项目名称: Vulnerability-Scanner
👤 项目作者: nagabalaji894-sketch
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-20 08:53:00
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #Vulnerability Scanner
📦 项目名称: Vulnerability-Scanner
👤 项目作者: nagabalaji894-sketch
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-20 08:53:00
📝 项目描述:
Mini Vulnerability Scanner is an educational Python tool designed for learning the fundamentals of penetration testing and vulnerability assessment. 🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #GitLab #EXP
📦 项目名称: status-led
👤 项目作者: Riscue
🛠 开发语言: Python
⭐ Star数量: 2 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-20 08:59:29
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #GitLab #EXP
📦 项目名称: status-led
👤 项目作者: Riscue
🛠 开发语言: Python
⭐ Star数量: 2 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-20 08:59:29
📝 项目描述:
Priority-based status aggregator for WS2812B LED strips. ESP8266 firmware + Python daemon; any source (Claude Code, GitLab CI, scripts) drives it, most urgent wins.🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #CVE-2026 #Exploit #RCE
📦 项目名称: ghostlock-vagrant-box
👤 项目作者: Daniyal48
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-20 08:11:00
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #CVE-2026 #Exploit #RCE
📦 项目名称: ghostlock-vagrant-box
👤 项目作者: Daniyal48
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-20 08:11:00
📝 项目描述:
An isolated Vagrant testbed designed to simulate a complete attack chain: Initial access via the Nginx heap buffer overflow (CVE-2026-42533) followed by root privilege escalation using the Ghostlock kernel vulnerability (CVE-2026-43449).🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #CVE-2026 #POC
📦 项目名称: wp2shell
👤 项目作者: Crypto-Cat
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-20 08:26:53
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #CVE-2026 #POC
📦 项目名称: wp2shell
👤 项目作者: Crypto-Cat
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-20 08:26:53
📝 项目描述:
PoC for CVE-2026-63030 + CVE-2026-60137, AKA WP2Shell🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #YARA #rules
📦 项目名称: custom-payload-encoder-obfuscation-framework
👤 项目作者: DivyanshiKishore
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-20 07:06:58
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #YARA #rules
📦 项目名称: custom-payload-encoder-obfuscation-framework
👤 项目作者: DivyanshiKishore
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-20 07:06:58
📝 项目描述:
Academic cybersecurity framework for analyzing payload encoding, obfuscation techniques, entropy metrics, and signature-based detection using a modular transformation pipeline.🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #YARA #malware
📦 项目名称: SOAR-Threat-Intelligence-Automation
👤 项目作者: madmaxx090
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-20 08:01:56
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #YARA #malware
📦 项目名称: SOAR-Threat-Intelligence-Automation
👤 项目作者: madmaxx090
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-20 08:01:56
📝 项目描述:
An end-to-end SOAR automation project integrating YARA, Splunk Enterprise, n8n, VirusTotal, Docker, and PowerShell to automate malware detection, threat intelligence enrichment, centralized logging, and SOC analyst notifications.🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #Burp #Plugin
📦 项目名称: ActiveScanPlusPlus
👤 项目作者: albinowax
🛠 开发语言: Java
⭐ Star数量: 661 | 🍴 Fork数量: 203
📅 更新时间: 2026-07-20 07:55:56
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #Burp #Plugin
📦 项目名称: ActiveScanPlusPlus
👤 项目作者: albinowax
🛠 开发语言: Java
⭐ Star数量: 661 | 🍴 Fork数量: 203
📅 更新时间: 2026-07-20 07:55:56
📝 项目描述:
ActiveScan++ Burp Suite Plugin🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #XSS #Reflected
📦 项目名称: GRC-Project-02-Web-Application-Security-Assessment
👤 项目作者: Oracleo
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-20 05:55:33
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #XSS #Reflected
📦 项目名称: GRC-Project-02-Web-Application-Security-Assessment
👤 项目作者: Oracleo
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-20 05:55:33
📝 项目描述:
Web App Risk Assessment | 4 Critical/High findings | SQLi 9.8 · XSS 7.3 · Brute Force 7.5 · CSRF 6.5 | CVSS · OWASP · ISO 27001 | Audit-grade report🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #Nuclei #漏洞
📦 项目名称: -LangGraph-Agent
👤 项目作者: LuckPony
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-20 06:21:37
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #Nuclei #漏洞
📦 项目名称: -LangGraph-Agent
👤 项目作者: LuckPony
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-20 06:21:37
📝 项目描述:
用户用自然语言描述目标、关注漏洞、资产重要性和扫描约束,系统先用规则或 LangChain 结构化输出转成 Intent,再通过授权、域名白名单、私网和 DNS 策略门。策略通过后调用 Mock 或受控 Nuclei 扫描器。Nuclei、ZAP、Nessus 报告会被归一化成统一 Finding,通过稳定指纹去重,然后结合 CVSS、资产重要性、证据置信度做确定性风险评分。最后从 Chroma 检索修复基线,生成带验证步骤的建议。整个流程有 11 个 LangGraph 节点,每个节点有审计事件。项目提供 Django REST API、Swagger、Web 页面、Docker Compose 和端到端测试。”🔗 点击访问项目地址