📦 GitHub 全球红队渗透资源中转站。
旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
⚠️ 本频道仅供安全研究与授权测试使用。
旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
⚠️ 本频道仅供安全研究与授权测试使用。
🚨 GitHub 监控消息提醒
🚨 发现关键词: #提权 #UAC
📦 项目名称: credmgr-public
👤 项目作者: SunshineR04
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-11 05:00:42
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #提权 #UAC
📦 项目名称: credmgr-public
👤 项目作者: SunshineR04
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-11 05:00:42
📝 项目描述:
Windows 本地环境与凭据管理器(Python + PySide6 GUI):API 凭据加密管理(Argon2id + AES-256-GCM)+ 环境变量可视化编辑(Path 编辑器/多版本切换/UAC 提权)。纯本地运行,全程脱敏。MIT 风格开源示例。🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #Exploit #POC
📦 项目名称: Exploit-Path-Tracer
👤 项目作者: blacksinisterx
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-11 05:01:39
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #Exploit #POC
📦 项目名称: Exploit-Path-Tracer
👤 项目作者: blacksinisterx
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-11 05:01:39
📝 项目描述:
Upload a codebase, and the AI traces how user input flows through the code to find security vulnerabilities. It checks each step for proper sanitization and suggests a PoC and fix.🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #XSS #Reflected #DOM
📦 项目名称: xssrecon
👤 项目作者: rix4uni
🛠 开发语言: Go
⭐ Star数量: 54 | 🍴 Fork数量: 11
📅 更新时间: 2026-08-11 04:42:38
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #XSS #Reflected #DOM
📦 项目名称: xssrecon
👤 项目作者: rix4uni
🛠 开发语言: Go
⭐ Star数量: 54 | 🍴 Fork数量: 11
📅 更新时间: 2026-08-11 04:42:38
📝 项目描述:
XSSRecon automates the process of testing URL parameters for reflection of a test payload rix4uni and further checks how special characters are handled (allowed, blocked, or converted).🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #XSS #Reflected
📦 项目名称: Web_Vulnerability_Scanner
👤 项目作者: rajputisha058-ship-it
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-11 04:47:22
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #XSS #Reflected
📦 项目名称: Web_Vulnerability_Scanner
👤 项目作者: rajputisha058-ship-it
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-11 04:47:22
📝 项目描述:
Python-based Web Vulnerability Scanner for detecting Reflected XSS vulnerabilities in a controlled DVWA environment. Developed as part of a Cybersecurity Internship.🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #0day #POC
📦 项目名称: Metabase-0day
👤 项目作者: codeb0ssx
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-11 04:15:30
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #0day #POC
📦 项目名称: Metabase-0day
👤 项目作者: codeb0ssx
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-11 04:15:30
📝 项目描述:
Security research and authorized testing PoC for a Metabase zero-day vulnerability. Intended for defensive research, detection development, and use in controlled lab environments.🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #Burp #Extension
📦 项目名称: burp-sf-aura
👤 项目作者: n0r1k4zu
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-11 00:21:54
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #Burp #Extension
📦 项目名称: burp-sf-aura
👤 项目作者: n0r1k4zu
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-11 00:21:54
📝 项目描述:
无描述🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #RCE #CVE #POC #Remote Code Execution
📦 项目名称: Dead-Dial
👤 项目作者: 0xReadingSteiner
🛠 开发语言: Shell
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-11 00:11:27
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #RCE #CVE #POC #Remote Code Execution
📦 项目名称: Dead-Dial
👤 项目作者: 0xReadingSteiner
🛠 开发语言: Shell
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-11 00:11:27
📝 项目描述:
Pre-authentication RCE in Cisco CUCM 15.x via Apache Axis JNDI injection — independent chain, survives Silent;Call patches🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #XSS #Stored #Reflected #DOM
📦 项目名称: devtalks-xss
👤 项目作者: orfloresti
🛠 开发语言: HTML
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-11 00:15:48
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #XSS #Stored #Reflected #DOM
📦 项目名称: devtalks-xss
👤 项目作者: orfloresti
🛠 开发语言: HTML
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-11 00:15:48
📝 项目描述:
无描述🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #XSS #Stored
📦 项目名称: task-manager-rest-api
👤 项目作者: RamahB0
🛠 开发语言: JavaScript
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-11 00:20:21
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #XSS #Stored
📦 项目名称: task-manager-rest-api
👤 项目作者: RamahB0
🛠 开发语言: JavaScript
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-11 00:20:21
📝 项目描述:
A secure Task Manager REST API with JWT + Google OAuth (Passport.js) auth, HTTP-only cookie sessions, owner-scoped task routes, helmet/xss-clean/mongo-sanitize hardening, rate limiting, and centralized error handling (AppError + catchAsync).🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #CVE-2026 #POC
📦 项目名称: CVE-2026-23744-PoC
👤 项目作者: Mluex0
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-11 01:52:07
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #CVE-2026 #POC
📦 项目名称: CVE-2026-23744-PoC
👤 项目作者: Mluex0
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-11 01:52:07
📝 项目描述:
CVE-2026-23744 is an unauthenticated command injection in MCPJam Inspector ≤1.4.2 via /api/mcp/connect. This POC exploits it by sending a crafted JSON payload to execute arbitrary commands, granting a reverse shell with PTY.🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #Vulnerability Scanner
📦 项目名称: vuln-scanner
👤 项目作者: devkroz
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-11 00:41:42
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #Vulnerability Scanner
📦 项目名称: vuln-scanner
👤 项目作者: devkroz
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-11 00:41:42
📝 项目描述:
Web vulnerability scanner — XSS, SQLi, CRLF, path traversal, command injection, open redirect, security headers🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #CVE-2026 #利用
📦 项目名称: CVE-2026-9198
👤 项目作者: CuteeCat
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-11 00:55:51
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #CVE-2026 #利用
📦 项目名称: CVE-2026-9198
👤 项目作者: CuteeCat
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-11 00:55:51
📝 项目描述:
CVE-2026-9198利用代码🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #Credential Dumping #LSASS
📦 项目名称: Lab-05-Wazuh-XDR-EDR-Deployment
👤 项目作者: Izaiah1996
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-10 22:12:40
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #Credential Dumping #LSASS
📦 项目名称: Lab-05-Wazuh-XDR-EDR-Deployment
👤 项目作者: Izaiah1996
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-10 22:12:40
📝 项目描述:
Single-node Wazuh 4.12.0 stack deployed on the management segment of a multi-VLAN home SOC lab, with agents enrolled on a Windows domain controller and workstation, plus a custom MITRE ATT&CK mapped detection rule for LSASS credential dumping.🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #YARA #malware
📦 项目名称: dfir-malware-lab
👤 项目作者: ronankongala
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-10 22:31:22
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #YARA #malware
📦 项目名称: dfir-malware-lab
👤 项目作者: ronankongala
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-10 22:31:22
📝 项目描述:
DFIR and Malware Analysis Lab - FlareVM, REMnux, Ghidra, CAPA, YARA, Volatility 3🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #提权 #CVE
📦 项目名称: ghostlock-apk
👤 项目作者: oopnv70-lab
🛠 开发语言: Java
⭐ Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-10 22:03:42
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #提权 #CVE
📦 项目名称: ghostlock-apk
👤 项目作者: oopnv70-lab
🛠 开发语言: Java
⭐ Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-10 22:03:42
📝 项目描述:
独立 APK:CVE-2026-43499 GhostLock 提权 + Shizuku shell 身份执行🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #CVE-2026 #Exploit
📦 项目名称: WP2Shell
👤 项目作者: g0d150ne
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-10 21:08:17
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #CVE-2026 #Exploit
📦 项目名称: WP2Shell
👤 项目作者: g0d150ne
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-10 21:08:17
📝 项目描述:
WP2Shell is a powerful and modular exploit framework that combines two critical WordPress vulnerabilities (CVE-2026-63030 and CVE-2026-60137) to achieve complete compromise of a target site without any credentials. 🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #CVE-2026 #RCE
📦 项目名称: XSS2Shell
👤 项目作者: g0d150ne
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-10 21:08:48
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #CVE-2026 #RCE
📦 项目名称: XSS2Shell
👤 项目作者: g0d150ne
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-10 21:08:48
📝 项目描述:
XSS2Shell ULTIMATE v3.0 is a powerful exploitation tool that chains Cross-Site Scripting (XSS) vulnerabilities in WordPress to achieve Remote Code Execution (RCE). This tool exploits CVE-2026-64638 to gain full control over vulnerable WordPress installations.🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #Vulnerability Scanner
📦 项目名称: php-ai-security-scanner
👤 项目作者: BangPiyus
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-10 20:54:53
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #Vulnerability Scanner
📦 项目名称: php-ai-security-scanner
👤 项目作者: BangPiyus
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-10 20:54:53
📝 项目描述:
AI-powered PHP vulnerability scanner and static security analyzer for detecting SQL injection, XSS, RCE, malware, backdoors, secrets, and insecure code.🔗 点击访问项目地址