📦 GitHub 全球红队渗透资源中转站。
​旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
⚠️ 本频道仅供安全研究与授权测试使用。
🚨 GitHub 监控消息提醒

🚨 发现关键词: #漏洞 #扫描 #利用

📦 项目名称: Forgex
👤 项目作者: AWY-Cipher
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-16 07:08:50

📝 项目描述:
Forgex 是一款面向 Windows 平台的集成式渗透测试工具箱。它将信息收集、漏洞扫描、爆破利用、逆向分析、移动端 Hook、代理隧道等数十款主流安全工具聚合在一个统一的可视化界面中,单击即可启动,免去了手工配置环境、切换多套软件的繁琐

🔗 点击访问项目地址 GitHub - AWY-Cipher/Forgex: Forgex 是一款面向 Windows 平台的集成式渗透测试工具箱。它将信息收集、漏洞扫描、爆破利用、逆向分析、移动端 Hook、代理隧道等数十款主流安全工具聚合在一个统一的可视化界面中,单击即…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #漏洞 #扫描

📦 项目名称: MrCipher
👤 项目作者: AWY-Cipher
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-16 07:59:23

📝 项目描述:
**MrCipher 是一款一体化的综合漏洞扫描与资产测绘工具**,把"主机发现 → 端口扫描 → 协议识别 → 子域枚举 → Web 指纹探测 → 漏洞检测 → 后渗透验证"整合成一条流水线,面向红队 / 安服 / 授权自检场景,提供 **命令行、交互式控制台、Web 界面(-ui)** 三种使用方式。 它的核心特点是:**自带一套 Go 原生重新实现的 MSF(Metasploit)风格模块系统**,并且把多个知名开源安全工具的优秀思路融合进来,做成"一个二进制、多种打法"。

🔗 点击访问项目地址 GitHub - AWY-Cipher/MrCipher: **MrCipher 是一款一体化的综合漏洞扫描与资产测绘工具**,把
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #Stored

📦 项目名称: infomaniak-stored-xss-assessment
👤 项目作者: unknownAgent10
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-16 05:30:53

📝 项目描述:
External attack-surface assessment identifying a Stored XSS condition through reconnaissance, asset enumeration, and web application testing.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #POC #DOM

📦 项目名称: -VULNERABILITIES-ASSESSMENT-REPORT
👤 项目作者: profdniel
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-16 06:02:42

📝 项目描述:
Vulnerability Assessment Report — DOM-Based XSS on OWASP Juice Shop. Manual black-box testing, PoC, and professional remediation writeup for Project 03: Web App Security.

🔗 点击访问项目地址 GitHub - profdniel/-VULNERABILITIES-ASSESSMENT-REPORT: Vulnerability Assessment Report — DOM-Based XSS on OWASP Juice Shop.  Manual…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #GitLab #POC

📦 项目名称: llvm-sys.rs
👤 项目作者: tari
🛠 开发语言: Rust
Star数量: 227 | 🍴 Fork数量: 44
📅 更新时间: 2026-08-16 06:05:08

📝 项目描述:
Rust bindings to LLVM. (Mirror of https://gitlab.com/taricorp/llvm-sys.rs/)

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: ExploiterX
👤 项目作者: anishalx
🛠 开发语言: Python
Star数量: 16 | 🍴 Fork数量: 13
📅 更新时间: 2026-08-16 05:24:17

📝 项目描述:
ExploiterX is a lightweight, customizable vulnerability scanner designed to detect security weaknesses in web applications. This tool crawls target websites, identifies potential links and forms, and checks for Cross-Site Scripting (XSS) vulnerabilities, helping security researchers and developers find exploitable points in their web applications.

🔗 点击访问项目地址 GitHub - anishalx/ExploiterX: ExploiterX is a lightweight, customizable vulnerability scanner designed to detect security weaknesses…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #漏洞 #扫描

📦 项目名称: awvs_json_word.py
👤 项目作者: kabuqin
🛠 开发语言: Python
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-16 05:31:41

📝 项目描述:
`awvs_json_word.py` 是一个将 **Acunetix(AWVS)/ Invicti** 扫描器导出的 JSON 结果文件,自动生成为**中文 Word 安全漏洞报告**的一体化工具。 脚本内置了数据解析、格式转换、中文化翻译、统计图表生成和报告排版等全部功能,只需一条命令即可完成从原始扫描数据到正式报告的全过程,无需任何人工干预。

🔗 点击访问项目地址 GitHub - kabuqin/awvs_json_word.py: `awvs_json_word.py` 是一个将 **Acunetix(AWVS)/ Invicti** 扫描器导出的 JSON 结果文件,自动生成为**中文 Word 安全漏洞报告**的一体化工具。…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC #RCE

📦 项目名称: CVE-2026-73519-WolfStack-PoC
👤 项目作者: squeeze440
🛠 开发语言: Shell
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-16 04:38:30

📝 项目描述:
PoC for CVE-2026-73519 - WolfStack hardcoded cluster secret leads to unauthenticated RCE (CVSS 9.8)

🔗 点击访问项目地址 GitHub - squeeze440/CVE-2026-73519-WolfStack-PoC: PoC for CVE-2026-73519 - WolfStack hardcoded cluster secret leads to unauthenticated…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: CVE-2026-73847-emlog-PoC
👤 项目作者: squeeze440
🛠 开发语言: Shell
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-16 04:38:36

📝 项目描述:
PoC for CVE-2026-73847 - emlog AI Assistant CSRF to SQL execution to admin takeover (CVSS 6.8)

🔗 点击访问项目地址 GitHub - squeeze440/CVE-2026-73847-emlog-PoC: PoC for CVE-2026-73847 - emlog AI Assistant CSRF to SQL execution to admin takeover…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #反序列化 #CVE

📦 项目名称: PHP-Deserialization-Payload-Generator
👤 项目作者: Zekon-Xu
🛠 开发语言: HTML
Star数量: 2 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-15 16:50:09

📝 项目描述:
PHP反序列化Payload构造工具

🔗 点击访问项目地址 GitHub - Zekon-Xu/PHP-Deserialization-Payload-Generator: PHP反序列化Payload构造工具
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #malware

📦 项目名称: malware-sandbox-analysis
👤 项目作者: JohnOkoji-source
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-16 01:01:40

📝 项目描述:
Malware analysis investigation using sandbox evidence to examine file indicators, behavioral activity, YARA detections, and command-and-control communications.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: flar3ad
👤 项目作者: daemoncibsec
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-16 00:33:36

📝 项目描述:
POC of CVE-2026-51031 for arbitrary local file read

🔗 点击访问项目地址 GitHub - daemoncibsec/flar3ad: POC of CVE-2026-51031 for arbitrary local file read
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: roblox-exploit-scanner
👤 项目作者: marvtem2210
🛠 开发语言: Lua
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-16 00:06:41

📝 项目描述:
Universal security vulnerability scanner for Roblox games - Auto-detect RemoteEvents and test 8+ exploit vectors

🔗 点击访问项目地址 marvtem2210/roblox-exploit-scanner
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #CVE

📦 项目名称: WALLABAG-FULL-DISCLOSURE-Stored-XSS-SSRF-CVSS-8.5-GHSA-q2g2-
👤 项目作者: FUNFACTOR1
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-15 23:18:14

📝 项目描述:
This is a full disclosure. The vulnerability was reported to the wallabag maintainers via GitHub Private Security Advisory on June 5, 2026. 3 FIX NO 1 MERGE NO CVE

🔗 点击访问项目地址 FUNFACTOR1/WALLABAG-FULL-DISCLOSURE-Stored-XSS-SSRF-CVSS-8.5-GHSA-q2g2-
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #DOM

📦 项目名称: Xss
👤 项目作者: Kcoof
🛠 开发语言: Go
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-15 23:18:56

📝 项目描述:
This script is designed to be fast and efficient, leveraging Go's concurrency features to check multiple URLs simultaneously.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #DOM

📦 项目名称: websec-scout
👤 项目作者: jordannpearce
🛠 开发语言: TypeScript
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-15 23:26:13

📝 项目描述:
Next.js domain security scanner using Scrappey — headers, XSS posture, WHOIS, email auth, stack fingerprints, and crawls.

🔗 点击访问项目地址 GitHub - jordannpearce/websec-scout: Next.js domain security scanner using Scrappey — headers, XSS posture, WHOIS, email auth,…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #RCE

📦 项目名称: CVE-2026-17544
👤 项目作者: r2qa
🛠 开发语言: PHP
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-15 22:28:52

📝 项目描述:
CVE-2026-17544: PHP bcmath OOB write → universal memory-only RCE & disable_functions/open_basedir bypass. Offset-free runtime resolver. Verified on PHP 8.4.x / 8.5.x.

🔗 点击访问项目地址 GitHub - r2qa/CVE-2026-17544: CVE-2026-17544: PHP bcmath OOB write → universal memory-only RCE & disable_functions/open_basedir…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #提权 #UAC

📦 项目名称: patch-icloud-secd-com
👤 项目作者: kiiki290
🛠 开发语言: PowerShell
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-15 18:01:16

📝 项目描述:
修复 Windows 版 iCloud 密码扩展验证码弹窗失效:WindowsApps 权限提权状态下安装导致 secd 打包 COM 挂载失效(急救补丁 / 治本还原权限+重装)| Fix iCloud Passwords popup failure on Windows: broken packaged-COM mount caused by installing with elevated WindowsApps permissions (first-aid patch / permanent ACL restore + reinstall)

🔗 点击访问项目地址 GitHub - kiiki290/patch-icloud-secd-com: 修复 Windows 版 iCloud 密码扩展验证码弹窗失效:WindowsApps 权限提权状态下安装导致 secd 打包 COM 挂载失效(急救补丁 / 治本还原权限+重装)|…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #Stored #Reflected #DOM

📦 项目名称: XSS_Labs
👤 项目作者: NazaninNazari
🛠 开发语言: HTML
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-15 21:57:27

📝 项目描述:
Hands-on XSS labs for learning, practicing, and understanding Cross-Site Scripting vulnerabilities.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #RCE

📦 项目名称: CVE-2026-47103-python-statemachine-rce
👤 项目作者: SaiTeja-Erukude
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-15 21:29:01

📝 项目描述:
Python StateMachine 3.0.0 < 3.2.0 RCE via unsafe SCXML <data expr> evaluation and Python eval() injection.

🔗 点击访问项目地址 GitHub - SaiTeja-Erukude/CVE-2026-47103-python-statemachine-rce: Python StateMachine 3.0.0 < 3.2.0 RCE via unsafe SCXML <data expr>…
Back to Top