📦 GitHub 全球红队渗透资源中转站。
旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
⚠️ 本频道仅供安全研究与授权测试使用。
旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
⚠️ 本频道仅供安全研究与授权测试使用。
🚨 GitHub 监控消息提醒
🚨 发现关键词: #RCE #Remote Code Execution
📦 项目名称: trustload
👤 项目作者: jay-tank
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-12 03:39:53
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #RCE #Remote Code Execution
📦 项目名称: trustload
👤 项目作者: jay-tank
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-12 03:39:53
📝 项目描述:
A zero-config Python AST linter that flags unsafe loading of an ML model/artifact (torch.load without weights_only, pickle/joblib/dill.load, np.load allow_pickle, keras load_model, yaml.load) - arbitrary code execution (CWE-502), the model-supply-chain RCE class. Points you at weights_only=True / safetensors.🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #Kubernetes #POC
📦 项目名称: ai-self-healing-cicd
👤 项目作者: narayanareddy11
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-12 04:06:32
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #Kubernetes #POC
📦 项目名称: ai-self-healing-cicd
👤 项目作者: narayanareddy11
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-12 04:06:32
📝 项目描述:
AI-assisted self-healing CI/CD platform POC with FastAPI services, Docker, Kubernetes, GitHub Actions, LangGraph RCA agents, verification, and human-reviewed remediation PRs.🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #Sliver #C2
📦 项目名称: c4
👤 项目作者: CR1MS0N-Operator
🛠 开发语言: Go
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-12 03:46:25
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #Sliver #C2
📦 项目名称: c4
👤 项目作者: CR1MS0N-Operator
🛠 开发语言: Go
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-12 03:46:25
📝 项目描述:
C2 Control Center — deploy, manage, and destroy C2 frameworks (Mythic, Sliver) from one CLI🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #Exploit #CVE
📦 项目名称: CVE-2022-22947_exp
👤 项目作者: Arrnitage
🛠 开发语言: Python
⭐ Star数量: 5 | 🍴 Fork数量: 3
📅 更新时间: 2026-08-12 01:57:03
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #Exploit #CVE
📦 项目名称: CVE-2022-22947_exp
👤 项目作者: Arrnitage
🛠 开发语言: Python
⭐ Star数量: 5 | 🍴 Fork数量: 3
📅 更新时间: 2026-08-12 01:57:03
📝 项目描述:
CVE-2022-22947 Exploit script🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #Vulnerability Scanner
📦 项目名称: ReconPulse
👤 项目作者: YVORYU
🛠 开发语言: Python
⭐ Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-12 01:44:43
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #Vulnerability Scanner
📦 项目名称: ReconPulse
👤 项目作者: YVORYU
🛠 开发语言: Python
⭐ Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-12 01:44:43
📝 项目描述:
ReconPulse - A lightweight vulnerability scanner written in Python. Functional subdomain enumeration (passive + brute force), multi-threaded port scanning, and verification through PocSuite 3 POC. Output an HTML report.🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #Burp #Extension
📦 项目名称: portswigger
👤 项目作者: api-evangelist
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-12 00:24:59
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #Burp #Extension
📦 项目名称: portswigger
👤 项目作者: api-evangelist
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-12 00:24:59
📝 项目描述:
PortSwigger is the UK-based security research company behind Burp Suite, the industry-standard web and API security testing platform used by penetration testers and enterprise AppSec teams worldwide.🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #RCE #POC
📦 项目名称: rules-cuda-comment-trigger-rce-poc
👤 项目作者: 2423gen-stack
🛠 开发语言: Shell
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-12 00:56:06
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #RCE #POC
📦 项目名称: rules-cuda-comment-trigger-rce-poc
👤 项目作者: 2423gen-stack
🛠 开发语言: Shell
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-12 00:56:06
📝 项目描述:
Responsible PoC for a missing-authorization-check comment-triggered RCE finding in bazel-contrib/rules_cuda integration-tests.yaml (reported to Google Bug Hunters OSS VRP)🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #Exploit #CVE #RCE
📦 项目名称: CVE-2025-55182-Exploit
👤 项目作者: dotnetguard
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-12 01:01:39
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #Exploit #CVE #RCE
📦 项目名称: CVE-2025-55182-Exploit
👤 项目作者: dotnetguard
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-12 01:01:39
📝 项目描述:
CVE-2025-55182 — Next.js Flight Deserialization RCE exploit with interactive shell, single-command execution and multi-payload reverse shell chain. For authorized penetration testing only.🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #Burp #Extension
📦 项目名称: burp-jwt-viewer
👤 项目作者: zw00sh
🛠 开发语言: Java
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-12 00:54:45
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #Burp #Extension
📦 项目名称: burp-jwt-viewer
👤 项目作者: zw00sh
🛠 开发语言: Java
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-12 00:54:45
📝 项目描述:
A Burp Suite extension for viewing JWTs that actually gives you the space to view them.🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #SSRF #metadata
📦 项目名称: ssrf
👤 项目作者: 0xSt4rk007
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-11 22:07:50
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #SSRF #metadata
📦 项目名称: ssrf
👤 项目作者: 0xSt4rk007
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-11 22:07:50
📝 项目描述:
无描述🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #SSRF #metadata
📦 项目名称: security-boundary-tests
👤 项目作者: messaging-intel-test
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-11 22:26:21
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #SSRF #metadata
📦 项目名称: security-boundary-tests
👤 项目作者: messaging-intel-test
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-11 22:26:21
📝 项目描述:
Tenant isolation, replay protection, signature verification, path traversal, SSRF, redaction, and CI supply-chain boundary tests.🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #YARA #malware
📦 项目名称: malware-scanner
👤 项目作者: trashdino0
🛠 开发语言: YARA
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-11 20:19:28
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #YARA #malware
📦 项目名称: malware-scanner
👤 项目作者: trashdino0
🛠 开发语言: YARA
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-11 20:19:28
📝 项目描述:
Local-first, modular static malware scanner: YARA, PE/JAR/APK/Office/PDF analysis, safe archive extraction, explainable verdicts, optional hash reputation lookups.🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #Exploit #CVE #POC
📦 项目名称: CVE-2025-5781
👤 项目作者: jasonbernier
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-11 20:02:39
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #Exploit #CVE #POC
📦 项目名称: CVE-2025-5781
👤 项目作者: jasonbernier
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-11 20:02:39
📝 项目描述:
CVE-2025-5781 FreePBX Exploit POC🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #YARA #rules #malware
📦 项目名称: apihash_to_yara
👤 项目作者: tbarabosch
🛠 开发语言: YARA
⭐ Star数量: 17 | 🍴 Fork数量: 2
📅 更新时间: 2026-08-11 20:02:48
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #YARA #rules #malware
📦 项目名称: apihash_to_yara
👤 项目作者: tbarabosch
🛠 开发语言: YARA
⭐ Star数量: 17 | 🍴 Fork数量: 2
📅 更新时间: 2026-08-11 20:02:48
📝 项目描述:
Generate YARA rules from Windows API hashes for malware detection and hunting.🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #Burp #Extension
📦 项目名称: ip-rotator-free
👤 项目作者: BlasterX24
🛠 开发语言: Go
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-11 19:26:27
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #Burp #Extension
📦 项目名称: ip-rotator-free
👤 项目作者: BlasterX24
🛠 开发语言: Go
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-11 19:26:27
📝 项目描述:
Free open-source IP rotation proxy (SOCKS5/HTTP) + Burp extension for people without money🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #Shellcode #Evasion #EDR
📦 项目名称: epidura
👤 项目作者: arushacracks
🛠 开发语言: Rust
⭐ Star数量: 2 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-11 19:44:02
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #Shellcode #Evasion #EDR
📦 项目名称: epidura
👤 项目作者: arushacracks
🛠 开发语言: Rust
⭐ Star数量: 2 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-11 19:44:02
📝 项目描述:
A Rust-based tool for staged remote process injection via IPC orchestration in Windows. It bypasses EDR flagging and avoids noisy shellcode by separating the dormant stager (pipe server) from the external trigger.🔗 点击访问项目地址