📦 GitHub 全球红队渗透资源中转站。
​旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
⚠️ 本频道仅供安全研究与授权测试使用。
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: CVE-2026-9090-poc
👤 项目作者: Kimdir01
🛠 开发语言: Go
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-15 16:42:20

📝 项目描述:
PoC for CVE-2026-9090 — Casdoor SAML signature bypass (CWE-347). Reproduction-only; coordinated via CERT/CC VU#780781.

🔗 点击访问项目地址 GitHub - Kimdir01/CVE-2026-9090-poc: PoC for CVE-2026-9090 — Casdoor SAML signature bypass (CWE-347). Reproduction-only; coordinated…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Shellcode #Evasion #EDR #AV

📦 项目名称: AV-Evasion-Kit
👤 项目作者: Excalibra
🛠 开发语言: C
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-15 15:57:59

📝 项目描述:
AV Evasion Kit is a comprehensive shellcode evasion framework using Indirect Syscalls, ETW patching, Module Stomping, .text code caves, compile-time string encryption, IPv4 obfuscation, XOR encryption, HeapAlloc buffering and direct function-pointer calls to bypass mainstream AV/EDR via static signatures, behavioural traces and EDR perception.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #渗透测试 #漏洞

📦 项目名称: dsh-pentest
👤 项目作者: howmp
🛠 开发语言: JavaScript
Star数量: 1 | 🍴 Fork数量: 1
📅 更新时间: 2026-08-15 14:48:51

📝 项目描述:
面向 DeepSeek Harness(dsh)的渗透测试模式 @CloverSecLabs

🔗 点击访问项目地址 GitHub - howmp/dsh-pentest: DSH 渗透测试模式:记录探索链路、资产与漏洞,并在 Web 中可视化展示。
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #metadata

📦 项目名称: Ciber-Cloud
👤 项目作者: Constan4
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-15 15:33:12

📝 项目描述:
Cloud security & pentesting: AWS, Azure, GCP — IAM abuse, S3 misconfigs, SSRF metadata, secrets hunting, container security. ScoutSuite, Pacu, trufflehog.

🔗 点击访问项目地址 GitHub - Constan4/Ciber-Cloud: Cloud security & pentesting: AWS, Azure, GCP — IAM abuse, S3 misconfigs, SSRF metadata, secrets…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: website-vuln-scanner
👤 项目作者: zqqqqqx
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-15 16:02:41

📝 项目描述:
Pure-stdlib Python website vulnerability scanner (35+ checks) with a local safe lab target — zero third-party dependencies.

🔗 点击访问项目地址 zqqqqqx/website-vuln-scanner
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #Exploit

📦 项目名称: cve-2026-43499-honor
👤 项目作者: knowlily
🛠 开发语言: C
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-15 15:19:30

📝 项目描述:
CVE-2026-43499 (GhostLock) rt_mutex stack-UAF privilege escalation research on Honor BVL-AN16 (Magic6 Pro, SM8650, kernel 6.1.128). Includes analysis docs, reverse-engineering scripts, disassembly artifacts, and exploit source with honor-BVL-AN16 target adaptation.

🔗 点击访问项目地址 GitHub - knowlily/cve-2026-43499-honor: CVE-2026-43499 (GhostLock) rt_mutex stack-UAF privilege escalation research on Honor BVL…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #POC #CVE #RCE

📦 项目名称: PoCs
👤 项目作者: victorbonato
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-15 15:06:08

📝 项目描述:
PoC for CVE-2026-56197 — Windows Admin Center (WAC) command injection RCE via invokeCommand; scripted no-browser auth (csrf/JWK/RSA-OAEP login chain), --cmd/--proof/--rev reverse-shell modes

🔗 点击访问项目地址 GitHub - victorbonato/PoCs: PoC for CVE-2026-56197 — Windows Admin Center (WAC) command injection RCE via invokeCommand; scripted…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #CVE #Reflected

📦 项目名称: CVEX2SHEL
👤 项目作者: Alixploit22
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-15 14:17:16

📝 项目描述:
CVE-2026-64638 adalah kerentanan Pre-Auth Reflected Cross-Site Scripting (XSS) di WordPress yang ditemukan pada tahun 2026. Kerentanan ini memungkinkan penyerang untuk menyisipkan kode JavaScript berbahaya ke halaman login WordPress (/wp-login.php) tanpa perlu autentikasi terlebih dahulu.

🔗 点击访问项目地址 GitHub - Alixploit22/CVEX2SHEL: CVE-2026-64638 adalah kerentanan Pre-Auth Reflected Cross-Site Scripting (XSS) di WordPress yang…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Nuclei #template

📦 项目名称: Nuclei_Template_V1
👤 项目作者: sanacvn
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-15 14:08:32

📝 项目描述:
无描述

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #metadata

📦 项目名称: mcp-web-engine
👤 项目作者: Arbolencio
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-15 13:37:27

📝 项目描述:
Privacy-First, Self-Hostable & SSRF-Hardened MCP Server & Web Engine for AI Agents

🔗 点击访问项目地址 GitHub - Arbolencio/mcp-web-engine: Privacy-First, Self-Hostable & SSRF-Hardened MCP Server & Web Engine for AI Agents
🚨 GitHub 监控消息提醒

🚨 发现关键词: #GitLab #漏洞 #CVE

📦 项目名称: botler
👤 项目作者: CodeFuckee
🛠 开发语言: Python
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-15 14:56:40

📝 项目描述:
GitLab AI Issue Bot 平台:webhook 监控 issue,Claude Code 自动处理并推送修复

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: Vulnerability-Scanner
👤 项目作者: RAJESHWARI-456
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-15 14:44:14

📝 项目描述:
Python-based vulnerability scanner for detecting open ports, basic web security issues, and potential vulnerabilities with HTML report generation.

🔗 点击访问项目地址 GitHub - RAJESHWARI-456/Vulnerability-Scanner: Python-based vulnerability scanner for detecting open ports, basic web security…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: Vuln-GLM-5.3
👤 项目作者: 0xBuildx
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-15 14:51:12

📝 项目描述:
A vulnerability scanner powered by GLM-5.3.

🔗 点击访问项目地址 0xBuildx/Vuln-GLM-5.3
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: cve-2026-71362-magento-lab
👤 项目作者: dinosn
🛠 开发语言: Python
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-15 14:22:48

📝 项目描述:
One-command Docker lab reproducing CVE-2026-71362 (Adobe Commerce / Magento Open Source customer-session identity-switch account takeover, APSB26-92, CVSS 9.1) with a PoC and an A/B/A official-patch negative control. For authorized security research and education.

🔗 点击访问项目地址 GitHub - dinosn/cve-2026-71362-magento-lab: One-command Docker lab reproducing CVE-2026-71362 (Adobe Commerce / Magento Open Source…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #BlueTeam #Detection

📦 项目名称: Featured-Work
👤 项目作者: thedetectlab
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-15 13:37:29

📝 项目描述:
Reference-grade cheat sheets and query sets — Nmap, Wireshark, SOC detection queries, Python automation, and a one-command Elasticsearch detection lab. Tested in the field, not written for a course.

🔗 点击访问项目地址 GitHub - thedetectlab/Featured-Work: Reference-grade cheat sheets and query sets — Nmap, Wireshark, SOC detection queries, Python…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #rule

📦 项目名称: YARA-RULE_GENERATOR
👤 项目作者: FajrJauhar
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-15 13:10:03

📝 项目描述:
无描述

🔗 点击访问项目地址 FajrJauhar/YARA-RULE_GENERATOR
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Burp #Extension

📦 项目名称: Burp_Keyword_Search_Extension
👤 项目作者: Laith-Abo-Hala
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-15 13:52:29

📝 项目描述:
A lightweight HTTP history and keyword-search extension for **Burp Suite Community Edition**.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Shellcode #Loader #Evasion #AV

📦 项目名称: shellcode-runner-research
👤 项目作者: Segaotava
🛠 开发语言: C++
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-15 12:43:23

📝 项目描述:
Progressive shellcode loader samples in C++ — educational research on Windows memory execution and AV evasion techniques. No payloads included.

🔗 点击访问项目地址 GitHub - Segaotava/shellcode-runner-research: Progressive shellcode loader samples in C++ — educational research on Windows memory…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #Reflected #DOM

📦 项目名称: unified-vuln-scanner
👤 项目作者: harshalsec
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-15 12:34:15

📝 项目描述:
Async Python detection engine covering Reflected/DOM XSS, BOLA static analysis, and Subdomain Takeover.

🔗 点击访问项目地址 GitHub - harshalsec/unified-vuln-scanner: Async Python detection engine covering Reflected/DOM XSS, BOLA static analysis, and Subdomain…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Sliver #C2

📦 项目名称: Wazuh-SIEM-Sliver-C2-Lab
👤 项目作者: Arshiarpmsl
🛠 开发语言: Shell
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-15 12:44:37

📝 项目描述:
This is a walkthrough for Wazuh siem lab monitoring the attack directly from my kali and catch the attack.

🔗 点击访问项目地址 GitHub - Arshiarpmsl/Wazuh-SIEM-Sliver-C2-Lab: This is a walkthrough for Wazuh siem lab monitoring the attack directly from my…
Back to Top