📦 GitHub 全球红队渗透资源中转站。
旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
⚠️ 本频道仅供安全研究与授权测试使用。
旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
⚠️ 本频道仅供安全研究与授权测试使用。
🚨 GitHub 监控消息提醒
🚨 发现关键词: #SSRF #metadata
📦 项目名称: ssrfguard
👤 项目作者: varunmahajan1
🛠 开发语言: Go
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-22 12:06:12
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #SSRF #metadata
📦 项目名称: ssrfguard
👤 项目作者: varunmahajan1
🛠 开发语言: Go
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-22 12:06:12
📝 项目描述:
SSRF-safe HTTP fetching for Go — resolved-IP dial guard that defeats DNS rebinding. Blocks metadata endpoints, private ranges, loopback. Zero dependencies.🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #Vulnerability Scanner
📦 项目名称: LangGraph-SAST-CICD
👤 项目作者: varkeymjohn
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-22 12:46:52
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #Vulnerability Scanner
📦 项目名称: LangGraph-SAST-CICD
👤 项目作者: varkeymjohn
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-22 12:46:52
📝 项目描述:
AI vulnerability scanner for CI/CD🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #CVE-2026 #RCE
📦 项目名称: wp2shell-vulnerability-scanner
👤 项目作者: Adrees-Basheer
🛠 开发语言: Shell
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-22 12:34:49
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #CVE-2026 #RCE
📦 项目名称: wp2shell-vulnerability-scanner
👤 项目作者: Adrees-Basheer
🛠 开发语言: Shell
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-22 12:34:49
📝 项目描述:
Scan WordPress installations for wp2shell vulnerabilities (CVE-2026-63030 + CVE-2026-60137). Identifies full RCE and SQL injection risks across multiple sites with severity classification and CSV reporting.🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #Exchange #POC
📦 项目名称: StockX-POC
👤 项目作者: technicalpro
🛠 开发语言: TypeScript
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-22 12:01:51
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #Exchange #POC
📦 项目名称: StockX-POC
👤 项目作者: technicalpro
🛠 开发语言: TypeScript
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-22 12:01:51
📝 项目描述:
StockX is a decentralized, AI-powered stock exchange platform designed to enable secure, transparent, and near-real-time trading of tokenized equities.🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #YARA #malware
📦 项目名称: Malware-Analysis-Using-LitterBox
👤 项目作者: jayaprasath05
🛠 开发语言: YARA
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-22 10:49:09
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #YARA #malware
📦 项目名称: Malware-Analysis-Using-LitterBox
👤 项目作者: jayaprasath05
🛠 开发语言: YARA
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-22 10:49:09
📝 项目描述:
Developed a malware analysis web application using Python, Flask, Docker, and YARA. Implemented secure file uploads, automated malware scanning, detection scoring, and detailed report generation while creating a responsive and user-friendly interface for cybersecurity analysis.🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #CVE-2026 #POC
📦 项目名称: CVE-2026-56139
👤 项目作者: oscerd
🛠 开发语言: Java
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-22 10:39:25
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #CVE-2026 #POC
📦 项目名称: CVE-2026-56139
👤 项目作者: oscerd
🛠 开发语言: Java
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-22 10:39:25
📝 项目描述:
PoC reproducer for CVE-2026-56139 (Apache Camel camel-undertow Rest DSL): the Rest DSL binding hard-codes muteException=false, so a configured muteException=true is ignored and an uncaught exception's full stack trace is returned to the client (CWE-209). Fixed in 4.14.8/4.18.3/4.21.0.🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #CVE-2026 #POC #RCE
📦 项目名称: wp2shell
👤 项目作者: mcipekci
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-22 10:58:52
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #CVE-2026 #POC #RCE
📦 项目名称: wp2shell
👤 项目作者: mcipekci
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-22 10:58:52
📝 项目描述:
Pre-auth RCE PoC for WordPress core — chains CVE-2026-63030 (REST /batch/v1 route-confusion desync) with CVE-2026-60137 (author__not_in SQLi) into an unauthenticated shell. Authorized testing only.🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #POC #CVE
📦 项目名称: CVE-2026-55994
👤 项目作者: oscerd
🛠 开发语言: Java
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-22 10:04:11
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #POC #CVE
📦 项目名称: CVE-2026-55994
👤 项目作者: oscerd
🛠 开发语言: Java
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-22 10:04:11
📝 项目描述:
PoC reproducer for CVE-2026-55994 (Apache Camel camel-iggy): the consumer copies an Iggy message's user-headers onto the Exchange unfiltered, so an injected CamelHttpUri drives a server-side request (SSRF) and leaks resolved property placeholders. Fixed in 4.18.3/4.21.0.🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #XSS #Stored
📦 项目名称: Altai-A8n-AC-Firmware-v2.2.1.1935-Stored-Cross-Site-Scripting-XSS-
👤 项目作者: Binary-Assassin
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-22 09:39:30
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #XSS #Stored
📦 项目名称: Altai-A8n-AC-Firmware-v2.2.1.1935-Stored-Cross-Site-Scripting-XSS-
👤 项目作者: Binary-Assassin
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-22 09:39:30
📝 项目描述:
无描述🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #Fastjson #EXP
📦 项目名称: fastjson1.2.66-1.2.83-Exploit-tool
👤 项目作者: BdYyWrez
🛠 开发语言: Python
⭐ Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-22 09:42:31
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #Fastjson #EXP
📦 项目名称: fastjson1.2.66-1.2.83-Exploit-tool
👤 项目作者: BdYyWrez
🛠 开发语言: Python
⭐ Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-22 09:42:31
📝 项目描述:
无描述🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #Exploit #RCE
📦 项目名称: AR-GhostNet
👤 项目作者: rickrana077-lgtm
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-22 09:59:27
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #Exploit #RCE
📦 项目名称: AR-GhostNet
👤 项目作者: rickrana077-lgtm
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-22 09:59:27
📝 项目描述:
AR-GhostNet` is a high-performance, modular network reconnaissance and exploitation framework. Designed for stealth, speed, and precision, it integrates adaptive payloading and advanced network fingerprinting to bypass modern security layers. Built for those who operate in the shadows. 💀🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #红蓝对抗 #靶场
📦 项目名称: xuandun-cyber-range
👤 项目作者: TrueFurina
🛠 开发语言: JavaScript
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-22 09:49:27
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #红蓝对抗 #靶场
📦 项目名称: xuandun-cyber-range
👤 项目作者: TrueFurina
🛠 开发语言: JavaScript
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-22 09:49:27
📝 项目描述:
玄盾 XUANDUN · AI 攻防靶场系统 — 面向红蓝对抗训练的 AI 攻防靶场 / 多智能体强化学习🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #Burp #Extension
📦 项目名称: rolebreaker
👤 项目作者: Guarina0x0
🛠 开发语言: Kotlin
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-22 09:47:01
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #Burp #Extension
📦 项目名称: rolebreaker
👤 项目作者: Guarina0x0
🛠 开发语言: Kotlin
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-22 09:47:01
📝 项目描述:
Burp Suite extension for JWT multi-role broken access control testing — auto-discovery, access matrix, privilege hierarchy, JWT attacks, HMAC cracker, IDOR analysis🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #CVE-2026 #POC
📦 项目名称: CVE-2026-55993
👤 项目作者: oscerd
🛠 开发语言: Java
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-22 09:15:09
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #CVE-2026 #POC
📦 项目名称: CVE-2026-55993
👤 项目作者: oscerd
🛠 开发语言: Java
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-22 09:15:09
📝 项目描述:
PoC reproducer for CVE-2026-55993 (Apache Camel camel-atmosphere-websocket): the WebSocket consumer copies connection query parameters onto the Exchange unfiltered, so an injected CamelHttpUri drives a server-side request (SSRF) and leaks resolved property placeholders. Fixed in 4.14.8/4.18.3/4.21.0.🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #Shellcode #AV
📦 项目名称: shellcod_encoder
👤 项目作者: Wissemben84
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-22 08:27:03
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #Shellcode #AV
📦 项目名称: shellcod_encoder
👤 项目作者: Wissemben84
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-22 08:27:03
📝 项目描述:
a python script for encoding shellcode, and then adding it to the syntax script files in C for bypassing AV 2026🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #Fastjson #RCE
📦 项目名称: fastjson-1.2.83-getresource-rce-lab-java-only-20260722-155842
👤 项目作者: hg0434hongzh0
🛠 开发语言: Java
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-22 08:42:23
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #Fastjson #RCE
📦 项目名称: fastjson-1.2.83-getresource-rce-lab-java-only-20260722-155842
👤 项目作者: hg0434hongzh0
🛠 开发语言: Java
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-22 08:42:23
📝 项目描述:
无描述🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #SSRF #metadata
📦 项目名称: ocular
👤 项目作者: guatxlabs
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-22 08:51:45
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #SSRF #metadata
📦 项目名称: ocular
👤 项目作者: guatxlabs
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-22 08:51:45
📝 项目描述:
Moteur de capture et d'analyse web durci : recon anti-bot, analyse de HTML hostile, sessions interactives isolées. Séparation de privilèges, conteneurs éphémères, garde SSRF.🔗 点击访问项目地址