📦 GitHub 全球红队渗透资源中转站。
​旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
⚠️ 本频道仅供安全研究与授权测试使用。
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #CVE

📦 项目名称: mcp-attack-detection-sentinel
👤 项目作者: j-dahl7
🛠 开发语言: PowerShell
Star数量: 1 | 🍴 Fork数量: 1
📅 更新时间: 2026-07-26 10:14:32

📝 项目描述:
Sentinel detection lab for MCP attack chains: CVE-2026-26118 SSRF token theft, tool poisoning, cross-server exfiltration, identity post-exploitation. Maps to OWASP Agentic Top 10. 5 analytics rules, 7 hunting queries, workbook. Companion to nineliveszerotrust.com.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #rule #malware

📦 项目名称: antirescan
👤 项目作者: ReckleGonzales
🛠 开发语言: Rust
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-26 10:59:38

📝 项目描述:
Offline PE malware detection engine. YARA-like rule matching for Windows PE files.

🔗 点击访问项目地址 GitHub - ReckleGonzales/antirescan: Offline PE malware detection engine. YARA-like rule matching for Windows PE files.
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Nuclei #templates #POC #CVE

📦 项目名称: nuclei-sdk
👤 项目作者: hexbay
🛠 开发语言: Go
Star数量: 2 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-26 09:57:09

📝 项目描述:
无描述

🔗 点击访问项目地址 GitHub - hexbay/nuclei-sdk
🚨 GitHub 监控消息提醒

🚨 发现关键词: #信息收集 #渗透 #子域名 #侦察 #recon

📦 项目名称: FindSomething-MCP
👤 项目作者: wodefox
🛠 开发语言: JavaScript
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-26 06:23:48

📝 项目描述:
解决安全人员在面对AI信息收集疏忽导致的攻击不全面的问题

🔗 点击访问项目地址 GitHub - wodefox/FindSomething-MCP: 解决安全人员在面对AI信息收集疏忽导致的攻击不全面的问题
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC #Exploit #RCE

📦 项目名称: CVE-2026-58480
👤 项目作者: shinthink
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-26 09:51:59

📝 项目描述:
CVE-2026-58480 / CVE-2026-15158 — Unauthenticated RCE in Blocksy Companion Pro < 2.1.47 (300K+ installs). Pre-auth arbitrary file upload via double-extension bypass.

🔗 点击访问项目地址 GitHub - shinthink/CVE-2026-58480: CVE-2026-58480 / CVE-2026-15158 — Unauthenticated RCE in Blocksy Companion Pro < 2.1.47 (300K+…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Fastjson #RCE

📦 项目名称: Fastjson-JsonType-RCE-Tool
👤 项目作者: lianqingsec
🛠 开发语言: Java
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-26 09:04:52

📝 项目描述:
FastJson JsonType RCE 利用工具

🔗 点击访问项目地址 GitHub - lianqingsec/Fastjson-JsonType-RCE-Tool: FastJson JsonType RCE 利用工具
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #rules #malware

📦 项目名称: malware-detector
👤 项目作者: Dev9269
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-26 08:45:00

📝 项目描述:
AI-powered PE malware detector — static analysis, YARA rules, Random Forest + EMBER 2381-feature ML, SHAP explainability

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Jenkins #POC

📦 项目名称: jenkins-job-poc
👤 项目作者: Sasta-Jarvis
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-26 08:55:21

📝 项目描述:
Git-driven Jenkins job management proof of concept

🔗 点击访问项目地址 GitHub - Sasta-Jarvis/jenkins-job-poc: Git-driven Jenkins job management proof of concept
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #RCE

📦 项目名称: CVE-2026-58480-Blocksy-Companion-Pro-RCE
👤 项目作者: shinthink
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-26 08:59:37

📝 项目描述:
CVE-2026-58480 / CVE-2026-15158 — Unauthenticated RCE in Blocksy Companion Pro < 2.1.47 (300K+ installs). Pre-auth arbitrary file upload via double-extension bypass.

🔗 点击访问项目地址 shinthink/CVE-2026-58480-Blocksy-Companion-Pro-RCE
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Exploit #CVE

📦 项目名称: Exploit-diary
👤 项目作者: Arjun-7x
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-26 06:52:23

📝 项目描述:
Hands-on penetration testing writeups from my home lab — real exploits, real methodology.

🔗 点击访问项目地址 GitHub - Arjun-7x/Exploit-diary: Hands-on penetration testing writeups from my home lab — real exploits, real methodology.
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #Reflected

📦 项目名称: web-attack-toolkit
👤 项目作者: JIMIT-PARIKH-01
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-26 05:53:55

📝 项目描述:
Web app testing: content discovery, fingerprint, SQLi, XSS (authorized use)

🔗 点击访问项目地址 GitHub - JIMIT-PARIKH-01/web-attack-toolkit: Web app testing: content discovery, fingerprint, SQLi, XSS (authorized use)
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: pentool
👤 项目作者: docxqwerty
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-26 05:51:23

📝 项目描述:
A modern, console-based web penetration testing toolkit with a TUI. Features an HTTP/HTTPS proxy, active/passive vulnerability scanner, Repeater, Intruder, Spider, and more. Free & open-source.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: bughunter-ai
👤 项目作者: Nexreaper
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-26 05:54:32

📝 项目描述:
AI-powered security vulnerability scanner. Scans websites for XSS, SQL injection, and more. Built with FastAPI + Next.js.

🔗 点击访问项目地址 Nexreaper/bughunter-ai
🚨 GitHub 监控消息提醒

🚨 发现关键词: #POC #CVE

📦 项目名称: cve-poc-mapper
👤 项目作者: eavil666
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-26 05:05:07

📝 项目描述:
CVE PoC 情报聚合平台

🔗 点击访问项目地址 GitHub - eavil666/cve-poc-mapper: CVE PoC 情报聚合平台
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #metadata

📦 项目名称: ssrf-guard
👤 项目作者: anatolyben
🛠 开发语言: JavaScript
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-26 04:54:12

📝 项目描述:
SSRF-safe URL validation and bounded, redirect-controlled HTTP fetch for untrusted outbound requests.

🔗 点击访问项目地址 GitHub - anatolyben/ssrf-guard: SSRF-safe URL validation and bounded, redirect-controlled HTTP fetch for untrusted outbound requests.
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: sentinel-cyber-core
👤 项目作者: selormwalker
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-26 04:41:28

📝 项目描述:
An advanced automated cybersecurity vulnerability scanner for network misconfigurations and security flaws.

🔗 点击访问项目地址 GitHub - selormwalker/sentinel-cyber-core: An advanced automated cybersecurity vulnerability scanner for network misconfigurations…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: web-vulnerability-scanner
👤 项目作者: chuiki001
🛠 开发语言: HTML
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-26 04:45:49

📝 项目描述:
Lightweight multi-threaded Flask web vulnerability scanner and audit report generator

🔗 点击访问项目地址 GitHub - chuiki001/web-vulnerability-scanner: Lightweight multi-threaded Flask web vulnerability scanner and audit report generator
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #malware

📦 项目名称: OffsetScan
👤 项目作者: warpedatom
🛠 开发语言: Rust
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-26 03:28:07

📝 项目描述:
Rust binary for corpus-scale static triage of PE files — entropy scoring, string extraction, and IOC detection. Companion to OffsetInspect

🔗 点击访问项目地址 GitHub - warpedatom/OffsetScan: Native corpus-scale static-triage engine (PE parsing, entropy, strings, IOC panels) - schema-compatible…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #malware

📦 项目名称: OffsetInspect
👤 项目作者: warpedatom
🛠 开发语言: PowerShell
Star数量: 36 | 🍴 Fork数量: 6
📅 更新时间: 2026-07-26 03:42:10

📝 项目描述:
PowerShell toolkit for AMSI/Defender detection-boundary analysis and static malware triage — maps byte offsets to detection triggers, plus YARA, entropy, string, and PE/imphash analysis. Companion to OffsetScan.

🔗 点击访问项目地址 GitHub - warpedatom/OffsetInspect: PowerShell toolkit for AMSI/Defender detection-boundary analysis and static malware triage maps…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: Helios-Web-VulnScanner
👤 项目作者: HeinHtetZaw-hub
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-26 03:49:31

📝 项目描述:
An automated web application vulnerability scanner with CVSS v3.1 scoring, OWASP Top 10:2025 mapping, evidence-based findings, and professional security reports.

🔗 点击访问项目地址 GitHub - HeinHtetZaw-hub/Helios-Web-VulnScanner: An automated web application vulnerability scanner with CVSS v3.1 scoring, OWASP…
Back to Top