📦 GitHub 全球红队渗透资源中转站。
​旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
⚠️ 本频道仅供安全研究与授权测试使用。
🚨 GitHub 监控消息提醒

🚨 发现关键词: #C2 #Framework #Command and Control

📦 项目名称: covert-c2-framework-poc
👤 项目作者: ericust1
🛠 开发语言: Python
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-13 01:53:20

📝 项目描述:
Proof-of-concept command and control (C2) framework demonstrating domain fronting and DNS tunneling evasion techniques.

🔗 点击访问项目地址 GitHub - ericust1/covert-c2-framework-poc: Proof-of-concept command and control (C2) framework demonstrating domain fronting and…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #POC #CVE

📦 项目名称: CVE-PoC-Tracker
👤 项目作者: Boreas37
🛠 开发语言: Python
Star数量: 1 | 🍴 Fork数量: 1
📅 更新时间: 2026-08-13 01:58:00

📝 项目描述:
无描述

🔗 点击访问项目地址 GitHub - Boreas37/CVE-PoC-Tracker
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #rule #malware

📦 项目名称: automated-malware-sandbox-yara
👤 项目作者: ericust1
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-13 00:17:59

📝 项目描述:
Automated malware analysis sandbox with custom YARA rule generation and dynamic PE execution tracking.

🔗 点击访问项目地址 ericust1/automated-malware-sandbox-yara
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #RCE

📦 项目名称: CVE-2026-14282
👤 项目作者: nullwhisper
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-13 00:27:31

📝 项目描述:
GoDAM WordPress plugin <= 1.12.2 unauthenticated file upload RCE (CVE-2026-14282)

🔗 点击访问项目地址 GitHub - nullwhisper/CVE-2026-14282: GoDAM WordPress plugin <= 1.12.2 unauthenticated file upload RCE (CVE-2026-14282)
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: CVE-2026-24031
👤 项目作者: aramosf
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-12 23:37:39

📝 项目描述:
CVE-2026-24031 Dovecot 2.4.0/3.1.0 SQL authentication bypass (auth bypass + user enumeration) PoC

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #C2 #Command and Control

📦 项目名称: Zombieland
👤 项目作者: infinition
🛠 开发语言: HTML
Star数量: 42 | 🍴 Fork数量: 4
📅 更新时间: 2026-08-12 22:50:25

📝 项目描述:
Zombieland is a command and control (C2) server designed to manage and communicate multiple client machines (referred to as "zombies"). Encrypted communication with clients, allowing for the execution of various commands, and persistence on Zombies. Communication between the server and Zombie is secured using symmetric encryption with Fernet.

🔗 点击访问项目地址 GitHub - infinition/Zombieland: Zombieland is a  command and control (C2) server designed to manage and communicate multiple client…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Nuclei #templates

📦 项目名称: cybersagacity-rule-aggregator
👤 项目作者: Kasloco
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-12 20:12:50

📝 项目描述:
CyberSagacity Rule Intelligence Platform — Automated security rule aggregator for 30,000+ rules from Semgrep, SonarQube, Nuclei, Checkmarx, and more.

🔗 点击访问项目地址 GitHub - Kasloco/cybersagacity-rule-aggregator: CyberSagacity Rule Intelligence Platform — Automated security rule aggregator for…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #rules #malware

📦 项目名称: ThreatKB
👤 项目作者: InQuest
🛠 开发语言: JavaScript
Star数量: 104 | 🍴 Fork数量: 17
📅 更新时间: 2026-08-12 21:19:18

📝 项目描述:
Knowledge base workflow management for YARA rules and C2 artifacts (IP, DNS, SSL) (ALPHA STATE AT THE MOMENT)

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #BlueTeam #Response #Detection

📦 项目名称: logguard
👤 项目作者: adamiseek
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-12 19:47:15

📝 项目描述:
Zero-dependency server log triage: SSH brute-force, compromise signals, web scanners, firewall block detection

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: netdiag-vuln-sample
👤 项目作者: automateyournetwork
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-12 20:01:53

📝 项目描述:
Tiny network diagnostics CLI with a planted CWE-78 OS command injection - target codebase for the Antares-1B vulnerability scanner demo

🔗 点击访问项目地址 GitHub - automateyournetwork/netdiag-vuln-sample: Tiny network diagnostics CLI with a planted CWE-78 OS command injection - target…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Burp #Extension

📦 项目名称: burp-cookie-switcher-v2
👤 项目作者: real-kiwii
🛠 开发语言: Python
Star数量: 2 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-12 19:15:09

📝 项目描述:
无描述

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: cve-2026-39987
👤 项目作者: matesz44
🛠 开发语言: Go
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-12 19:17:10

📝 项目描述:
CVE-2026-39987 PoC: Marimo<0.23.0 Pre-Auth Remote Code Execution via Terminal WebSocket Authentication Bypass

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Burp #Extension

📦 项目名称: burp-cookie-switcher
👤 项目作者: real-kiwii
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-12 18:46:15

📝 项目描述:
Burp Suite extension for quickly switching between user and admin cookies while testing BAC manually.

🔗 点击访问项目地址 GitHub - real-kiwii/burp-cookie-switcher: Burp Suite extension for quickly switching between user and admin cookies while testing…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: CVE-2026-73034-PoC
👤 项目作者: Boreas37
🛠 开发语言: Shell
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-12 18:35:43

📝 项目描述:
CVE-2026-73034 — DB-GPT v0.8.1 unauth path traversal → arbitrary file write as root via user-id header. Verified + fix diff

🔗 点击访问项目地址 GitHub - Boreas37/CVE-2026-73034-PoC: CVE-2026-73034 — DB-GPT v0.8.1 unauth path traversal → arbitrary file write as root via user…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: CVE-2026-41452-PoC
👤 项目作者: Boreas37
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-12 18:36:12

📝 项目描述:
CVE-2026-41452 — Krayin CRM unauth installer bypass (X-Requested-With) → admin takeover. Verified: overwrite + login on 2.2.4, blocked on 2.2.5

🔗 点击访问项目地址 GitHub - Boreas37/CVE-2026-41452-PoC: CVE-2026-41452 — Krayin CRM unauth installer bypass (X-Requested-With) → admin takeover.…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: CVE-2026-17544-PoC
👤 项目作者: Boreas37
🛠 开发语言: PHP
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-12 17:48:38

📝 项目描述:
CVE-2026-17544 — PHP bcmath bccomp() OOB write (stack smashing). Verified: crash on 8.4.23/8.5.8, fixed in 8.4.24. GHSA-x692-q9x7-8c3f

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: CVE-2026-33267-PoC
👤 项目作者: Boreas37
🛠 开发语言: Python
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-12 17:49:52

📝 项目描述:
CVE-2026-33267 — Apache Traffic Server @ header internal-metadata spoof (CVSS 10.0). Verified: @ headers leak to plugins on 10.1.2, stripped on 10.1.4

🔗 点击访问项目地址 GitHub - Boreas37/CVE-2026-33267-PoC: CVE-2026-33267 — Apache Traffic Server @ header internal-metadata spoof (CVSS 10.0). Verified:…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Nuclei #template #templates #CVE

📦 项目名称: toolbox-sidenuclei
👤 项目作者: go-appsec
🛠 开发语言: Go
Star数量: 3 | 🍴 Fork数量: 1
📅 更新时间: 2026-08-12 15:55:40

📝 项目描述:
Toolbox sidecar to enable automated scanning with Nuclei

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Burp #Extension

📦 项目名称: burp-nn-extensions
👤 项目作者: n0r1k4zu
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-12 16:13:05

📝 项目描述:
无描述

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Burp #Plugin #Extension

📦 项目名称: burpai
👤 项目作者: openaideveloperai-png
🛠 开发语言: Java
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-12 17:00:12

📝 项目描述:
无描述

🔗 点击访问项目地址
Back to Top