📦 GitHub 全球红队渗透资源中转站。
​旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
⚠️ 本频道仅供安全研究与授权测试使用。
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Burp #Extension

📦 项目名称: converttype
👤 项目作者: ArkhaMahn
🛠 开发语言: Java
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-17 06:55:19

📝 项目描述:
ZAP add-on that converts HTTP requests between content types (JSON, XML, SOAP, URL-encoded, multipart form-data, YAML, GraphQL and plain text). Port of h0tak88r's Burp extension.

🔗 点击访问项目地址 GitHub - ArkhaMahn/converttype: ZAP add-on that converts HTTP requests between content types (JSON, XML, SOAP, URL-encoded, multipart…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #Exploit #漏洞

📦 项目名称: root-my-s9280
👤 项目作者: NanoTurtle1145
🛠 开发语言: Kotlin
Star数量: 2 | 🍴 Fork数量: 1
📅 更新时间: 2026-08-17 05:48:50

📝 项目描述:
Using CVE-2026-43499 to root your Galaxy S24 Ultra(SM-S9280 ,(China / Hong Kong SAR / Taiwan))

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #metadata

📦 项目名称: doujin-scraper
👤 项目作者: kyy0887
🛠 开发语言: JavaScript
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-16 23:56:19

📝 项目描述:
Scraper ringan untuk doujin.desu.xxx (API terenkripsi) & nekopoi.care — tanpa dependensi, anti-SSRF, sanitasi URL

🔗 点击访问项目地址 GitHub - kyy0887/doujin-scraper: Scraper ringan untuk doujin.desu.xxx (API terenkripsi) & nekopoi.care — tanpa dependensi, anti…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #云元数据 #metadata

📦 项目名称: dsh-web-fetch-zhipu
👤 项目作者: FWW321
🛠 开发语言: JavaScript
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-17 03:17:32

📝 项目描述:
Zhipu BigModel web fetch provider for DeepSeek Harness (dsh) — delegated web_reader MCP behind a ctx.web WebFetchProvider; SSRF surface nil, session handshake, per-fetch auditing

🔗 点击访问项目地址 GitHub - FWW321/dsh-web-fetch-zhipu: Zhipu BigModel web fetch provider for DeepSeek Harness (dsh) — delegated web_reader MCP behind…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Spring #POC

📦 项目名称: SpringAIJIRAColab
👤 项目作者: shrutikulkarni5020
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-17 05:02:31

📝 项目描述:
Agentic life cycle for this Spring project POC

🔗 点击访问项目地址 shrutikulkarni5020/SpringAIJIRAColab
🚨 GitHub 监控消息提醒

🚨 发现关键词: #渗透测试 #内网 #漏洞

📦 项目名称: kali-pentest
👤 项目作者: githuBlijingai
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-17 03:37:10

📝 项目描述:
kali-pentest基于《Kali Linux渗透测试的艺术》方法论蒸馏,提供一个可被agent调用的、面向远程Kali Linux渗透测试的完整执行框架。

🔗 点击访问项目地址 GitHub - githuBlijingai/kali-pentest: kali-pentest基于《Kali Linux渗透测试的艺术》方法论蒸馏,提供一个可被agent调用的、面向远程Kali Linux渗透测试的完整执行框架。
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #POC

📦 项目名称: XSS-challenges
👤 项目作者: brono04
🛠 开发语言: HTML
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-17 03:55:41

📝 项目描述:
About This is a repo of my solution of one XSS challenge website (http://sudo.co.il/xss/) . This challenges may have different types of solutions. My solutions are not the only one. So, keep searching & keep sharing.

🔗 点击访问项目地址 GitHub - brono04/XSS-challenges: About This is a repo of my solution of one XSS challenge website (http://sudo.co.il/xss/) . This…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #Stored #Reflected #DOM

📦 项目名称: scriptjack
👤 项目作者: maximalfocus
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-17 02:49:13

📝 项目描述:
Educational, container-only demonstration of cross-site scripting (XSS / CWE-79): a deliberately vulnerable app and its secure twin, side by side. Runs locally over loopback via Docker Compose against fictional data; the vulnerable app is opt-in. Not hosted, not production-safe, must not be deployed.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #Stored #Reflected

📦 项目名称: HakShop
👤 项目作者: Abdelrhman-Sherif-Mohamed
🛠 开发语言: PHP
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-17 02:58:01

📝 项目描述:
Vulnerable-by-design e-commerce training shop (XSS / SQLi / CSRF) built with PHP + SQLite - for educational purposes only.

🔗 点击访问项目地址 GitHub - Abdelrhman-Sherif-Mohamed/HakShop: Vulnerable-by-design e-commerce training shop (XSS / SQLi / CSRF) built with PHP +…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #RCE #CVE #Remote Code Execution

📦 项目名称: Responsive-FileManager-9.14.0
👤 项目作者: Yucaerin
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-17 00:58:40

📝 项目描述:
Responsive FileManager <= 9.14.0 — Authenticated RCE via `save_img` Path Traversal + Arbitrary File Write

🔗 点击访问项目地址 GitHub - Yucaerin/Responsive-FileManager-9.14.0: Responsive FileManager <= 9.14.0 — Authenticated RCE via `save_img` Path Traversal…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #RCE #POC

📦 项目名称: makeswift-rce-poc
👤 项目作者: Black1hp
🛠 开发语言: JavaScript
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-17 02:36:39

📝 项目描述:
无描述

🔗 点击访问项目地址 GitHub - Black1hp/makeswift-rce-poc
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Nuclei #template

📦 项目名称: dast-harness
👤 项目作者: moovingGun
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-17 02:58:05

📝 项目描述:
Minimal DAST harness: run nuclei/nikto behind one interface with local-only safety, per-scanner completion evidence, and a merged report

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC #Exploit

📦 项目名称: EITS-Portal-Exploit-CVE-2026-31367-PoC
👤 项目作者: hereticL1nk
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-17 02:29:09

📝 项目描述:
无描述

🔗 点击访问项目地址 GitHub - hereticL1nk/EITS-Portal-Exploit-CVE-2026-31367-PoC
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #Exploit

📦 项目名称: CVE-2026-74251
👤 项目作者: toanln-cov
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-17 02:55:07

📝 项目描述:
Unauthenticated SQL Injection via Attribute Filter in Phoca Cart

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Shellcode #Execute

📦 项目名称: staticbypass
👤 项目作者: nanmonee
🛠 开发语言: Python
Star数量: 2 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-17 02:03:32

📝 项目描述:
Template-based, modular, multi-language, shellcode obfuscator and compiler

🔗 点击访问项目地址 GitHub - nanmonee/staticbypass: Template-based, modular, multi-language, shellcode obfuscator and compiler
🚨 GitHub 监控消息提醒

🚨 发现关键词: #漏洞 #POC #RCE #复现 #利用

📦 项目名称: -
👤 项目作者: InKu0721
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-17 02:04:23

📝 项目描述:
用于自动化归档漏洞情报,输出分析报告以及poc

🔗 点击访问项目地址 GitHub - InKu0721/-: 用于自动化归档漏洞情报,输出分析报告以及poc
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #POC

📦 项目名称: lethal
👤 项目作者: Zuk4r1
🛠 开发语言: Python
Star数量: 2 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-16 23:31:10

📝 项目描述:
Herramienta ofensiva avanzada para la explotación automatizada de vulnerabilidades IDOR y CSRF, diseñada para Bug Bounty, Red Team y pentesters. Permite detectar referencias inseguras a objetos, generar exploits modernos de CSRF (auto-submit, fetch, iframe, XSS), simular privilegios y exportar pruebas de concepto profesionales listas para reportar.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: web-vuln-scanner
👤 项目作者: sanasimran1403-jpg
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-16 23:21:33

📝 项目描述:
Python CLI web vulnerability scanner — crawls target URLs and tests for SQLi, XSS, Open Redirect, missing security headers, and sensitive file exposure. Authenticated scanning supported via cookie injection. S&S Security Research — Portfolio Project 6.

🔗 点击访问项目地址 GitHub - sanasimran1403-jpg/web-vuln-scanner: Python CLI web vulnerability scanner — crawls target URLs and tests for SQLi, XSS…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #C2 #Framework #Command and Control

📦 项目名称: EdgeStealth-C2
👤 项目作者: MoMhaidat05
🛠 开发语言: C++
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-16 23:48:13

📝 项目描述:
EdgeStealth-C2 is a Command and Control (C2) framework developed as a proof of concept for the academic research paper "Stealth at The Edge".

🔗 点击访问项目地址 GitHub - MoMhaidat05/EdgeStealth-C2: EdgeStealth-C2 is a Command and Control (C2) framework developed as a proof of concept for…
Back to Top