📦 GitHub 全球红队渗透资源中转站。
​旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
⚠️ 本频道仅供安全研究与授权测试使用。
🚨 GitHub 监控消息提醒

🚨 发现关键词: #RCE #CVE

📦 项目名称: Codify-TJNULL-OSCP-
👤 项目作者: R3fr4kt
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-03 12:17:48

📝 项目描述:
Walkthrough for Codify (Linux - Easy). Exploits vm2 RCE (CVE-2023-30547), SQLite DB hash extraction, Bcrypt cracking with John, and Privilege Escalation via Bash wildcard comparison in `mysql-backup.sh`.

🔗 点击访问项目地址 GitHub - R3fr4kt/Codify-TJNULL-OSCP-: Walkthrough for Codify (Linux - Easy). Exploits vm2 RCE (CVE-2023-30547), SQLite DB hash…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #RCE #CVE #POC

📦 项目名称: kindarails2shell-poc
👤 项目作者: HackSpeak
🛠 开发语言: Python
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-03 12:54:32

📝 项目描述:
CVE-2026-66066 (KindaRails2Shell) PoC - Rails Active Storage/libvips arbitrary file read to RCE; for authorized security testing

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Exchange #EXP

📦 项目名称: oasis
👤 项目作者: navikt
🛠 开发语言: TypeScript
Star数量: 3 | 🍴 Fork数量: 7
📅 更新时间: 2026-08-03 13:03:33

📝 项目描述:
Bibliotek for å validere tokens fra Wonderwall og utføre On-Behalf-Of Exchange mot både Azure og IDporten

🔗 点击访问项目地址 GitHub - navikt/oasis: Bibliotek for å validere tokens fra Wonderwall og utføre On-Behalf-Of Exchange mot både Azure og IDporten
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Fastjson #漏洞 #CVE

📦 项目名称: fastjson-check
👤 项目作者: xiaoqiMikko
🛠 开发语言: Java
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-03 13:02:01

📝 项目描述:
Find fastjson in your JARs and Spring Boot fat-JARs, and check exposure to CVE-2026-16723. Zero dependencies, fully offline. 一条命令排查 fastjson 漏洞影响范围。

🔗 点击访问项目地址 GitHub - xiaoqiMikko/fastjson-check: Find fastjson in your JARs and Spring Boot fat-JARs, and check exposure to CVE-2026-16723.…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC #Exploit #RCE

📦 项目名称: CVE-2026-60004
👤 项目作者: shinthink
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-03 12:49:46

📝 项目描述:
CVE-2026-60004 — Gitea/Forgejo Diffpatch Git Hook RCE. Bare clone → post-index-change hook injection. CVSS 9.8 | CWE-94 | Gitea < 1.27.1

🔗 点击访问项目地址 GitHub - shinthink/CVE-2026-60004: CVE-2026-60004 — Gitea/Forgejo Diffpatch Git Hook RCE. Bare clone → post-index-change hook injection.…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: checkpoint-smartconsole-poc
👤 项目作者: HackSpeak
🛠 开发语言: Python
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-03 12:56:53

📝 项目描述:
CVE-2026-16232 (Check Point SmartConsole authentication bypass) PoC - unauth to admin; for authorized security testing

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: vulnscope
👤 项目作者: Crow-developers
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-03 12:04:32

📝 项目描述:
A lightweight Python vulnerability scanner that maps open ports and service banners to known CVEs.

🔗 点击访问项目地址 Crow-developers/vulnscope
🚨 GitHub 监控消息提醒

🚨 发现关键词: #渗透测试 #漏洞

📦 项目名称: JiyuUdpAttack
👤 项目作者: yangsongh
🛠 开发语言: VBScript
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-03 10:45:52

📝 项目描述:
极域电子教室 UDP 重放攻击研究与渗透测试工具集

🔗 点击访问项目地址 GitHub - yangsongh/JiyuUdpAttack: 极域电子教室 UDP 重放攻击研究与渗透测试工具集
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: ovswrap-poc
👤 项目作者: HackSpeak
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-03 11:25:41

📝 项目描述:
CVE-2026-64531 (OVSwrap) PoC - Linux kernel Open vSwitch LPE; for patch validation and security research

🔗 点击访问项目地址 GitHub - HackSpeak/ovswrap-poc: CVE-2026-64531 (OVSwrap) PoC - Linux kernel Open vSwitch LPE; for patch validation and security…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #Reflected #DOM

📦 项目名称: juice-shop-pentest
👤 项目作者: aryaparge
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-03 10:47:22

📝 项目描述:
Manual web application penetration testing of OWASP Juice Shop using Burp Suite Community Edition. Identified and validated SQL Injection, XSS, Broken Access Control, Sensitive Data Exposure, and Business Logic vulnerabilities, with findings documented in a professional penetration testing report.

🔗 点击访问项目地址 GitHub - aryaparge/juice-shop-pentest: Manual web application penetration testing of OWASP Juice Shop using Burp Suite Community…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSTI #RCE

📦 项目名称: do-not-disturb-thm
👤 项目作者: HackerRank7
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-03 10:48:54

📝 项目描述:
Full Boot2Root writeup for TryHackMe's "Do Not Disturb" room (Hacker Holidays 2026) — NoSQL injection auth bypass → EJS SSTI/RCE → exposed Node inspector abuse → disk-group raw partition read for root.

🔗 点击访问项目地址 GitHub - HackerRank7/do-not-disturb-thm: Full Boot2Root writeup for TryHackMe's
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: vulnerability-scanner
👤 项目作者: Shivam74918
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-03 10:28:13

📝 项目描述:
A Python-based web vulnerability scanner that identifies missing security headers, scans open ports, checks SSL/TLS configurations, detects directory listing, and discovers common web security vulnerabilities.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Spring #POC

📦 项目名称: distributed-ride-hailing-saga
👤 项目作者: jamesiit
🛠 开发语言: Java
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-03 07:03:20

📝 项目描述:
An End-to-End AWS Serverless PoC demonstrating the Saga Pattern, distributed transactions, and automated microservice rollbacks using Spring Boot and Step Functions.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #渗透测试 #漏洞

📦 项目名称: PenScope
👤 项目作者: wanlqx
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-03 10:58:04

📝 项目描述:
授权式本地自动化渗透测试桌面工具。PenScope 是一款面向安全测试人员 / 授权渗透测试场景的桌面应用。它把端口扫描、Web 漏洞扫描(SQL 注入、XSS、CSRF、文件上传)、利用验证、报告生成等工作流整合在一个原生窗口中,所有逻辑都在你本机运行,不依赖任何远程服务器,也不需要账号密码。

🔗 点击访问项目地址 GitHub - wanlqx/PenScope: 授权式本地自动化渗透测试桌面工具。PenScope 是一款面向安全测试人员 / 授权渗透测试场景的桌面应用。它把端口扫描、Web 漏洞扫描(SQL 注入、XSS、CSRF、文件上传)、利用验证、报告生…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #RCE

📦 项目名称: CVE-2026-63720-datamodel-code-generator
👤 项目作者: rahulreddykarne
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-03 10:51:14

📝 项目描述:
Code injection (RCE) in datamodel-code-generator via unvalidated customBasePath (CVE-2026-63720)

🔗 点击访问项目地址 GitHub - rahulreddykarne/CVE-2026-63720-datamodel-code-generator: Code injection (RCE) in datamodel-code-generator via unvalidated…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Shellcode #Loader

📦 项目名称: CSharpShellcodeInjector
👤 项目作者: nostdlib
🛠 开发语言: C#
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-03 06:00:39

📝 项目描述:
无描述

🔗 点击访问项目地址 GitHub - nostdlib/CSharpShellcodeInjector
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Shellcode #Execute

📦 项目名称: vamp-shellcode-lab
👤 项目作者: Vampsecure-Labs
🛠 开发语言: C
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-03 09:38:36

📝 项目描述:
VampSecure Labs — Laboratorio shellcode ARM64: mmap RWX, syscalls directas y ejecucion de codigo nativo

🔗 点击访问项目地址 GitHub - Vampsecure-Labs/vamp-shellcode-lab: VampSecure Labs — Laboratorio shellcode ARM64: mmap RWX, syscalls directas y ejecucion…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: SecureScanPRO
👤 项目作者: konavenkatesh23
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-03 09:38:37

📝 项目描述:
SecureScanPRO is a Flask-based web application vulnerability scanner that automates website security assessment. It performs URL validation, website crawling, endpoint discovery, HTTP security header analysis, SQL Injection and XSS detection, CVSS risk scoring, MySQL-based scan management, and generates detailed PDF security reports.

🔗 点击访问项目地址 konavenkatesh23/SecureScanPRO
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC #Exploit

📦 项目名称: CVE-2026-32941
👤 项目作者: skoveit
🛠 开发语言: Go
Star数量: 6 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-03 08:51:11

📝 项目描述:
CVE-2026-32941 PoC - Sliver Remote OOM

🔗 点击访问项目地址 GitHub - skoveit/CVE-2026-32941: CVE-2026-32941 PoC - Sliver Remote OOM
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: Network-Recon-Concept-leanring
👤 项目作者: rahulkmr1502
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-03 07:33:10

📝 项目描述:
All the concept I learn during the project "Network Recon & Vulnerability Scanner"

🔗 点击访问项目地址 GitHub - rahulkmr1502/Network-Recon-Concept-leanring: All the concept I learn during the project
Back to Top