📦 GitHub 全球红队渗透资源中转站。
​旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
⚠️ 本频道仅供安全研究与授权测试使用。
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #RCE

📦 项目名称: CVE-2026-58138
👤 项目作者: 0xgh057r3c0n
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-22 17:29:55

📝 项目描述:
CVE-2026-58138 - Conductor (3.21.21..<3.30.2) unauthenticated RCE via INLINE GraalVM evaluator

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #RCE #CVE #POC

📦 项目名称: CVE-2024-9264
👤 项目作者: ozcanpng
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-22 16:28:35

📝 项目描述:
CVE-2024-9264 Grafana SQL Expressions DuckDB LFI/RCE PoC

🔗 点击访问项目地址 GitHub - ozcanpng/CVE-2024-9264: CVE-2024-9264 Grafana SQL Expressions DuckDB LFI/RCE PoC
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #metadata

📦 项目名称: arrowhead
👤 项目作者: jagguvarma15
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-22 16:59:09

📝 项目描述:
Arrowhead is a hardened, general-purpose MCP server built to demonstrate, not just document, best-practice Model Context Protocol security: OAuth 2.1 auth, SSRF and path-traversal protection, sandboxed tool execution, and token-efficient schema design, all in working code.

🔗 点击访问项目地址 GitHub - jagguvarma15/arrowhead: Arrowhead is a hardened, general-purpose MCP server built to demonstrate, not just document, best…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: Network-Vulnerability-scanner
👤 项目作者: nayanjani120-cpu
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-22 17:02:30

📝 项目描述:
无描述

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #NTLM Relay #SMB

📦 项目名称: NTLMancer
👤 项目作者: abdelaaziz0
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-22 13:30:12

📝 项目描述:
Connection-bound NTLM relay broker for controlled HTTP/HTTPS browser sessions over SOCKS.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Shellcode #Execute

📦 项目名称: binary-exploitation-writeups
👤 项目作者: susheel-cybercode
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-22 12:05:06

📝 项目描述:
CTF binary exploitation challenges — buffer overflow, ROP, ret2libc, format string, shellcode injection. Full walkthroughs with exploit code.

🔗 点击访问项目地址 susheel-cybercode/binary-exploitation-writeups
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC #Exploit #RCE

📦 项目名称: CVE-2026-41089-Netlogon-RCE
👤 项目作者: opensource-arrozconpollo191
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-22 15:43:06

📝 项目描述:
Scan Windows Domain Controllers for CVE-2026-41089 to detect unauthenticated remote code execution vulnerabilities in the Netlogon service.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #BlueTeam #Response

📦 项目名称: WAZUH-Process-Tree-Viewer
👤 项目作者: mym0us3r
🛠 开发语言: Python
Star数量: 8 | 🍴 Fork数量: 3
📅 更新时间: 2026-07-22 15:00:25

📝 项目描述:
A forensic visualization tool for Wazuh that transforms Windows process creation logs (Event ID 4688) into interactive, draggable relationship graphs. Optimized for Threat Hunting and Incident Response.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #metadata

📦 项目名称: ressrf
👤 项目作者: timescale
🛠 开发语言: Rust
Star数量: 4 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-22 12:55:45

📝 项目描述:
Multi-platform SSRF prevention library

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: CVE-2026-33825_BlueHammer-POC
👤 项目作者: jahithoque
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-22 14:50:10

📝 项目描述:
无描述

🔗 点击访问项目地址 GitHub - jahithoque/CVE-2026-33825_BlueHammer-POC
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: CVE-2026-14266
👤 项目作者: 4minx
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-22 14:32:35

📝 项目描述:
CVE-2026-14266 - XZ Heap Buffer Overflow PoC Generator for 7-Zip

🔗 点击访问项目地址 GitHub - 4minx/CVE-2026-14266: CVE-2026-14266 - XZ Heap Buffer Overflow PoC Generator for 7-Zip
🚨 GitHub 监控消息提醒

🚨 发现关键词: #钓鱼 #红队

📦 项目名称: phish-login
👤 项目作者: nihaodg
🛠 开发语言: PHP
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-22 13:54:25

📝 项目描述:
红队钓鱼网站复刻生成skill,生成钓鱼网站

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #漏洞 #利用

📦 项目名称: fastjson1.8.23
👤 项目作者: Easy-Debug
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-22 13:54:44

📝 项目描述:
fastjson-1.2.83-gadget-rce漏洞利用工具

🔗 点击访问项目地址 GitHub - Easy-Debug/fastjson1.8.23: fastjson-1.2.83-gadget-rce漏洞利用工具
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #rule

📦 项目名称: yara-tester
👤 项目作者: janderik
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-22 13:15:35

📝 项目描述:
Fast YARA rule validation and testing. Check syntax, test against files, detect common issues.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #malware

📦 项目名称: Windows-Malware-Analysis-Lab
👤 项目作者: aaditya-w
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-22 14:00:20

📝 项目描述:
Windows malware analysis lab built with VirtualBox. Demonstrates static analysis of an AgentTesla sample using PEStudio, Detect It Easy, YARA, Strings, and VirusTotal.

🔗 点击访问项目地址 GitHub - aaditya-w/Windows-Malware-Analysis-Lab: Windows malware analysis lab built with VirtualBox. Demonstrates static analysis…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #DOM

📦 项目名称: reflex
👤 项目作者: EuanSmith2
🛠 开发语言: Python
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-22 13:28:24

📝 项目描述:
Educational Python toolkit for discovering and understanding common web vulnerabilities: XSS, open redirects, DOM XSS, mutation fuzzing.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: wp2shell-poc-fulljs
👤 项目作者: raphy76
🛠 开发语言: HTML
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-22 13:31:45

📝 项目描述:
full javascript reproduction of CVE-2026-63030 (author_exclude, author__not_in and misalignment between validations and matches)

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Kubernetes #POC

📦 项目名称: poc_kubernetes
👤 项目作者: nblinpro
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-22 12:07:08

📝 项目描述:
无描述

🔗 点击访问项目地址 GitHub - nblinpro/poc_kubernetes
🚨 GitHub 监控消息提醒

🚨 发现关键词: #C2 #Framework

📦 项目名称: nd073-c2-Dental-Office-Virtual-Assistant
👤 项目作者: arindam-banerjee-2021
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-22 12:58:08

📝 项目描述:
无描述

🔗 点击访问项目地址 GitHub - arindam-banerjee-2021/nd073-c2-Dental-Office-Virtual-Assistant
Back to Top