📦 GitHub 全球红队渗透资源中转站。
旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
⚠️ 本频道仅供安全研究与授权测试使用。
旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
⚠️ 本频道仅供安全研究与授权测试使用。
🚨 GitHub 监控消息提醒
🚨 发现关键词: #Vulnerability Scanner
📦 项目名称: guardrail
👤 项目作者: Eragon1x2
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-10 10:47:37
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #Vulnerability Scanner
📦 项目名称: guardrail
👤 项目作者: Eragon1x2
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-10 10:47:37
📝 项目描述:
🛡️ DevSecOps API Vulnerability Scanner — real-time BOLA, XSS, JWT, Prompt Injection scanning via WebSockets. FastAPI + React.🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #XSS #Reflected
📦 项目名称: PAYLAOD_SQLi_XSS
👤 项目作者: MUHAMMAD-HASEEB368
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-10 10:58:51
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #XSS #Reflected
📦 项目名称: PAYLAOD_SQLi_XSS
👤 项目作者: MUHAMMAD-HASEEB368
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-10 10:58:51
📝 项目描述:
PayloaderX is an automated web vulnerability scanner with BFS crawling, tech fingerprinting, and false-positive-resistant SQL Injection & Reflected XSS detection via differential baseline analysis. Multi-threaded for speed, it auto-generates CVSS v3.1 scored, CWE-mapped reports for authorized security assessments.🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #C2 #Framework
📦 项目名称: endgame-community-plugins
👤 项目作者: endgamec2framework
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-10 10:58:48
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #C2 #Framework
📦 项目名称: endgame-community-plugins
👤 项目作者: endgamec2framework
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-10 10:58:48
📝 项目描述:
Community plugins for ENDGAME C2 🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #CVE-2026 #POC
📦 项目名称: CVE-2026-9086-poc
👤 项目作者: Saku0512
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-10 10:19:31
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #CVE-2026 #POC
📦 项目名称: CVE-2026-9086-poc
👤 项目作者: Saku0512
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-10 10:19:31
📝 项目描述:
无描述🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #CVE-2026 #POC #Exploit #漏洞
📦 项目名称: GhostLock-GOT-W29
👤 项目作者: zzzxxxxxxxxxx
🛠 开发语言: C
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-10 10:54:59
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #CVE-2026 #POC #Exploit #漏洞
📦 项目名称: GhostLock-GOT-W29
👤 项目作者: zzzxxxxxxxxxx
🛠 开发语言: C
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-10 10:54:59
📝 项目描述:
CVE-2026-43499 (GhostLock) research on HUAWEI MatePad Pro 11 GOT-W29🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #Burp #Extension
📦 项目名称: ASTra-AST-Driven-JS-API-Extractor
👤 项目作者: rebornindishell
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-10 09:42:41
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #Burp #Extension
📦 项目名称: ASTra-AST-Driven-JS-API-Extractor
👤 项目作者: rebornindishell
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-10 09:42:41
📝 项目描述:
ASTra is an AST-driven Burp Suite extension and reverse-engineering framework that parses minified client-side JavaScript bundles to extract API routes, POST/PUT payload shapes, BOLA targets, client-side secrets, and feature flags.🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #Burp #Extension
📦 项目名称: BurpMCP-Mobile-Integration
👤 项目作者: muhammedikbalyildiz
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-10 10:03:51
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #Burp #Extension
📦 项目名称: BurpMCP-Mobile-Integration
👤 项目作者: muhammedikbalyildiz
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-10 10:03:51
📝 项目描述:
Burp MCP Mobile is a Flutter-based application that allows you to control Burp MCP Server configurations and real-time request permissions from a mobile interface.🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #CVE-2026 #POC
📦 项目名称: CVE-2026-23744-PoC
👤 项目作者: amao26
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-10 09:53:23
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #CVE-2026 #POC
📦 项目名称: CVE-2026-23744-PoC
👤 项目作者: amao26
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-10 09:53:23
📝 项目描述:
CVE-2026-23744 is an unauthenticated command injection in MCPJam Inspector ≤1.4.2 via /api/mcp/connect. This POC exploits it by sending a crafted JSON payload to execute arbitrary commands, granting a reverse shell with PTY.🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #POC #CVE #RCE
📦 项目名称: CVE-2026-23744-MCPJam-Inspector-Unauthenticated-RCE-Proof-of-Concept
👤 项目作者: amao26
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-10 09:07:17
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #POC #CVE #RCE
📦 项目名称: CVE-2026-23744-MCPJam-Inspector-Unauthenticated-RCE-Proof-of-Concept
👤 项目作者: amao26
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-10 09:07:17
📝 项目描述:
CVE-2026-23744 is an unauthenticated command injection in MCPJam Inspector ≤1.4.2 via /api/mcp/connect. This POC exploits it by sending a crafted JSON payload to execute arbitrary commands, granting a reverse shell with PTY.🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #漏洞 #CVE
📦 项目名称: CVE-2017-7921-Research-Toolkit
👤 项目作者: Wyl-cmd
🛠 开发语言: Python
⭐ Star数量: 5 | 🍴 Fork数量: 1
📅 更新时间: 2026-08-10 08:21:55
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #漏洞 #CVE
📦 项目名称: CVE-2017-7921-Research-Toolkit
👤 项目作者: Wyl-cmd
🛠 开发语言: Python
⭐ Star数量: 5 | 🍴 Fork数量: 1
📅 更新时间: 2026-08-10 08:21:55
📝 项目描述:
用于借助FOFA快速测试海康威视的CVE-2017-7921漏洞,并且给出登陆账号和密码,并输出json文件。🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #YARA #rules #malware
📦 项目名称: Threat-Lens
👤 项目作者: AhmedELNajjar-dev
🛠 开发语言: YARA
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-10 08:41:51
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #YARA #rules #malware
📦 项目名称: Threat-Lens
👤 项目作者: AhmedELNajjar-dev
🛠 开发语言: YARA
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-10 08:41:51
📝 项目描述:
Automated Malware Intelligence Pipeline powered by LangGraph & Groq AI. Perform static analysis, YARA scanning, string extraction, and VirusTotal lookups with a single click.🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #Bypass #Sandbox
📦 项目名称: W0lfSword
👤 项目作者: kaffeindecaf
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-10 08:07:31
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #Bypass #Sandbox
📦 项目名称: W0lfSword
👤 项目作者: kaffeindecaf
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-10 08:07:31
📝 项目描述:
iOS Kernel Exploit Toolkit | DarkSword Engine, Sandbox escape, SSV bypass, multi-app support. iOS 17.0–26.0.1.🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #Sliver #C2
📦 项目名称: SliverC2-Evasion-Suite-swzhouu
👤 项目作者: swzhouu
🛠 开发语言: Go
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-10 08:06:08
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #Sliver #C2
📦 项目名称: SliverC2-Evasion-Suite-swzhouu
👤 项目作者: swzhouu
🛠 开发语言: Go
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-10 08:06:08
📝 项目描述:
Modified four-kit defense evasion suite for Sliver C2: Crystal Palace loader, sleep masking, in-memory PE execution, and remote process injection with PPID spoofing.🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #蜜罐 #部署
📦 项目名称: NezhaGuard
👤 项目作者: ctkqiang
🛠 开发语言: C++
⭐ Star数量: 3 | 🍴 Fork数量: 1
📅 更新时间: 2026-08-10 07:29:31
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #蜜罐 #部署
📦 项目名称: NezhaGuard
👤 项目作者: ctkqiang
🛠 开发语言: C++
⭐ Star数量: 3 | 🍴 Fork数量: 1
📅 更新时间: 2026-08-10 07:29:31
📝 项目描述:
NezhaGuard — 基于 Qt6 / C++26 的实时安全信息与事件管理系统,面向蓝队的主动防御平台。部署于服务器/边缘节点,通过 libpcap 混杂模式抓包 + 日志文件监控 + 蜜罐诱饵三层数据源,经协议解码 → 攻击签名匹配 → 速率异常检测 → 告警聚合去重 → 主动响应(ICMP/TCP RST 隔离)的完整流水线,实现对网络威胁的实时感知与自动阻断。🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #Vulnerability Scanner
📦 项目名称: Automated-Web-Vulnerability
👤 项目作者: Tsuru-chan
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-10 07:52:56
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #Vulnerability Scanner
📦 项目名称: Automated-Web-Vulnerability
👤 项目作者: Tsuru-chan
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-10 07:52:56
📝 项目描述:
Automated Web Vulnerability Scanner & Report Generator🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #Shellcode #Loader
📦 项目名称: Resource-Loading
👤 项目作者: Evilearth-dotcom
🛠 开发语言: C++
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-10 07:14:07
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #Shellcode #Loader
📦 项目名称: Resource-Loading
👤 项目作者: Evilearth-dotcom
🛠 开发语言: C++
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-10 07:14:07
📝 项目描述:
Embedding Shellcode in C++🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #提权 #UAC
📦 项目名称: FileUnlocker
👤 项目作者: yangshu114514
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-10 04:24:30
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #提权 #UAC
📦 项目名称: FileUnlocker
👤 项目作者: yangshu114514
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-10 04:24:30
📝 项目描述:
Windows 右键菜单解除文件/文件夹占用 (handle检测 + SYSTEM提权 + 多选合并)🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #提权 #UAC
📦 项目名称: Windows-Sudo
👤 项目作者: wudream813
🛠 开发语言: C++
⭐ Star数量: 3 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-10 05:32:05
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #提权 #UAC
📦 项目名称: Windows-Sudo
👤 项目作者: wudream813
🛠 开发语言: C++
⭐ Star数量: 3 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-10 05:32:05
📝 项目描述:
一个单文件、静态编译的 Windows 提权工具。它能够在不弹出新窗口的情况下(内联模式),以任意用户身份运行命令。🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #信息收集 #子域名
📦 项目名称: InfoSec-Learning
👤 项目作者: mumuuuuuuuuu
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-10 03:46:34
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #信息收集 #子域名
📦 项目名称: InfoSec-Learning
👤 项目作者: mumuuuuuuuuu
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-10 03:46:34
📝 项目描述:
信息收集学习笔记与工具实践🔗 点击访问项目地址