📦 GitHub 全球红队渗透资源中转站。
​旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
⚠️ 本频道仅供安全研究与授权测试使用。
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Bypass #UAC

📦 项目名称: uac-bypass-path-mapper-utility-2026
👤 项目作者: divinecheetahshow68
🛠 开发语言: HTML
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-12 15:05:37

📝 项目描述:
Uac Bypass Path Mapper 2026 — clear documentation, release channel, and getting-started workflows.

🔗 点击访问项目地址 GitHub - divinecheetahshow68/uac-bypass-path-mapper-utility-2026: Uac Bypass Path Mapper 2026 — clear documentation, release channel…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: -CloudStorageVulnerabilityScanner
👤 项目作者: shaikaneesa19
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-12 13:21:36

📝 项目描述:
A Flask-based cloud storage public bucket vulnerability scanner.

🔗 点击访问项目地址 GitHub - shaikaneesa19/-CloudStorageVulnerabilityScanner: A Flask-based cloud storage public bucket vulnerability scanner.
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: dependency-remediation-engine
👤 项目作者: BharathKumarMurugan
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-12 13:58:37

📝 项目描述:
An automated, local-first dependency vulnerability scanner, auto-updater, and structural refactoring (AST) companion tool designed to safely remediate security advisories within the local development environment.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Burp #插件

📦 项目名称: JsStrike
👤 项目作者: C4nXu3
🛠 开发语言: Java
Star数量: 2 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-12 14:00:38

📝 项目描述:
Burp Suite 敏感信息实时提取插件 - JsStrike By NANA

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: CVE-2026-0075
👤 项目作者: QM4RS
🛠 开发语言: Java
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-12 13:15:22

📝 项目描述:
CVE-2026-0075 — Android ContactsProvider information disclosure via JSON error side-channel, including PoC, root-cause analysis, and patch details.

🔗 点击访问项目地址 GitHub - QM4RS/CVE-2026-0075
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC #Exploit

📦 项目名称: CVE-2026-23111-POC-noddlenpottato
👤 项目作者: Knz-source
🛠 开发语言: C
Star数量: 3 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-12 13:54:15

📝 项目描述:
CVE-2026-23111 nf_tables catchall UAF — unprivileged LPE for Linux 5.10-6.18. Auto-adaptive exploit with KASLR bypass, arbitrary kernel read, and ROP chain. Supports Debian, Ubuntu, RHEL, Fedora. C/Python/Rust + autopwn.

🔗 点击访问项目地址 GitHub - Knz-source/CVE-2026-23111-POC-noddlenpottato: s
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Nuclei #templates

📦 项目名称: nuclei-templates-evolution
👤 项目作者: Leonideath
🛠 开发语言: Unknown
Star数量: 2 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-12 12:28:55

📝 项目描述:
无描述

🔗 点击访问项目地址 GitHub - Leonideath/nuclei-templates-evolution
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #RCE

📦 项目名称: CVE-2026-69263
👤 项目作者: leoelsolh
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-12 12:25:22

📝 项目描述:
MCP environment-variable blocklist bypass leads to unauthenticated RCE in Flowise 3.1.1

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: cyber-ghost-scanner
👤 项目作者: danial-eghbalizade
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-12 11:35:06

📝 项目描述:
An advanced web vulnerability scanner with WAF bypass, AI assistance, and hacker-style terminal.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Exploit #CVE #RCE #POC

📦 项目名称: PluckCMS-CSRF-RCE
👤 项目作者: IlhomjonR
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-12 12:02:34

📝 项目描述:
CVE-2026-70376 — Pluck CMS site-wide CSRF (fail-open Referer check) → RCE via double-extension upload. CWE-352/434, CVSS 8.0. Advisory + PoC by @IlhomjonR.

🔗 点击访问项目地址 GitHub - IlhomjonR/PluckCMS-CSRF-RCE: Pluck CMS site-wide CSRF (fail-open Referer check) → RCE via double-extension upload. PT…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #Stored

📦 项目名称: dvwa-rce-finding-chain
👤 项目作者: Mastertactician23
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-12 11:52:32

📝 项目描述:
Pentest-styled report of a 4-finding DVWA vulnerability chain — stored XSS to session theft, SQL injection to credential extraction, command injection to RCE, and persistent web shell

🔗 点击访问项目地址 GitHub - Mastertactician23/dvwa-rce-finding-chain: Pentest-styled report of a 4-finding DVWA vulnerability chain — stored XSS to…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #metadata

📦 项目名称: ens-metadata-security-disclosure
👤 项目作者: Julik000
🛠 开发语言: JavaScript
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-12 11:20:59

📝 项目描述:
Security vulnerability disclosure for ENS Metadata Service (SSRF & DoS)

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #Stored

📦 项目名称: Emoji_ShopXSS2SHELL
👤 项目作者: giriaryan694-a11y
🛠 开发语言: Shell
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-12 10:16:32

📝 项目描述:
Emoji_ShopXSS2SHELL is an intentionally vulnerable web application lab demonstrating a Stored XSS-to-RCE attack chain through insecure administrative functionality. Built for authorized cybersecurity research, CTFs, and web security learning. 🔓🎯

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Burp #Extension

📦 项目名称: pentest-tools-integration
👤 项目作者: pentesttoolscom
🛠 开发语言: Java
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-12 10:35:57

📝 项目描述:
Easily push Burp findings into your Pentest-Tools.com workspace.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #渗透测试 #漏洞

📦 项目名称: web-penetration-risk-assessment
👤 项目作者: wangyu-wycc
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-12 09:38:44

📝 项目描述:
模拟乙方安全服务流程完成企业Web应用渗透测试与风险评估项目。遵循正规渗透测试授权流程,完成信息收集、漏洞探测、人工漏洞复现、风险分级、输出整改方案,最终生成标准化安全评估报告。

🔗 点击访问项目地址 wangyu-wycc/web-penetration-risk-assessment
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #rule #malware

📦 项目名称: malware-pe-analyzer-yara
👤 项目作者: umitakpinarumit
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-12 09:20:28

📝 项目描述:
A modular Python tool for Static Malware Analysis: PE Header Parsing, Shannon Entropy Calculation (Packer/Crypter detection), Suspicious Win32 API Identification, and YARA Rule Engine Integration.

🔗 点击访问项目地址 GitHub - umitakpinarumit/malware-pe-analyzer-yara: A modular Python tool for Static Malware Analysis: PE Header Parsing, Shannon…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #Stored

📦 项目名称: csz-ctf-range
👤 项目作者: haroonatieeq352
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-12 09:51:06

📝 项目描述:
A multi-phase offensive security CTF range covering SQLi, Stored XSS, CSRF, IDOR, SSRF, Cache Deception, and Cache Poisoning using Python Flask, SQLite, Docker, and Nginx.

🔗 点击访问项目地址 GitHub - haroonatieeq352/csz-ctf-range: A multi-phase offensive security CTF range covering SQLi, Stored XSS, CSRF, IDOR, SSRF…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #DOM

📦 项目名称: Cross-Site-Scripting
👤 项目作者: princemhzn007-ui
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-12 09:55:00

📝 项目描述:
A web security project focused on identifying and mitigating Cross-Site Scripting (XSS) vulnerabilities using secure coding practices, input validation, output encoding, and safe DOM manipulation.

🔗 点击访问项目地址 GitHub - princemhzn007-ui/Cross-Site-Scripting: A web security project focused on identifying and mitigating Cross-Site Scripting…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSTI #RCE

📦 项目名称: ssti-labs
👤 项目作者: Caxtiq
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-11 14:34:04

📝 项目描述:
无描述

🔗 点击访问项目地址 GitHub - Caxtiq/ssti-labs
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: usmankhan560026-prog.github.io
👤 项目作者: usmankhan560026-prog
🛠 开发语言: HTML
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-12 08:18:35

📝 项目描述:
My cybersecurity portfolio — SOC dashboards, threat intel platform, and vulnerability scanner projects.

🔗 点击访问项目地址 GitHub - usmankhan560026-prog/usmankhan560026-prog.github.io: My cybersecurity portfolio — SOC dashboards, threat intel platform…
Back to Top