📦 GitHub 全球红队渗透资源中转站。
旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
⚠️ 本频道仅供安全研究与授权测试使用。
旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
⚠️ 本频道仅供安全研究与授权测试使用。
🚨 GitHub 监控消息提醒
🚨 发现关键词: #Burp #Extension
📦 项目名称: gap
👤 项目作者: ArkhaMahn
🛠 开发语言: Java
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-17 07:11:45
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #Burp #Extension
📦 项目名称: gap
👤 项目作者: ArkhaMahn
🛠 开发语言: Java
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-17 07:11:45
📝 项目描述:
GAP for ZAP: find the parameters, links and words that may not be obvious. Port of xnl-h4ck3r's GAP Burp extension.🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #CVE-2026 #POC
📦 项目名称: CVE-2026-59310
👤 项目作者: HORKimhab
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-17 07:52:35
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #CVE-2026 #POC
📦 项目名称: CVE-2026-59310
👤 项目作者: HORKimhab
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-17 07:52:35
📝 项目描述:
CVE-2026-59310🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #SSTI #RCE
📦 项目名称: SSTI-CHECKER
👤 项目作者: ebrahimgh21
🛠 开发语言: Python
⭐ Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-16 23:28:04
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #SSTI #RCE
📦 项目名称: SSTI-CHECKER
👤 项目作者: ebrahimgh21
🛠 开发语言: Python
⭐ Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-16 23:28:04
📝 项目描述:
无描述🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #SSTI #RCE
📦 项目名称: PipePwned---Writeup
👤 项目作者: baheandiego07
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-17 04:40:09
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #SSTI #RCE
📦 项目名称: PipePwned---Writeup
👤 项目作者: baheandiego07
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-17 04:40:09
📝 项目描述:
PipePwned es un laboratorio que simula un entorno CI/CD vulnerable, donde se explota una cadena de vulnerabilidades que incluyen IDOR, SSTI, fuga de información y escalada de privilegios mediante Poisoned Pipeline Execution (PPE) en un runner self-hosted de GitLab.🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #Burp #Plugin
📦 项目名称: dsh-heath-mcp
👤 项目作者: Heath96
🛠 开发语言: JavaScript
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-17 06:33:04
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #Burp #Plugin
📦 项目名称: dsh-heath-mcp
👤 项目作者: Heath96
🛠 开发语言: JavaScript
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-17 06:33:04
📝 项目描述:
MCP server bridge for DeepSeek Harness: stdio / streamable-http / legacy-SSE transports, web settings UI (form + JSON), tools as mcp__<server>__<tool>. Burp Suite ready out of the box.🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #Burp #Extension
📦 项目名称: converttype
👤 项目作者: ArkhaMahn
🛠 开发语言: Java
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-17 06:55:19
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #Burp #Extension
📦 项目名称: converttype
👤 项目作者: ArkhaMahn
🛠 开发语言: Java
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-17 06:55:19
📝 项目描述:
ZAP add-on that converts HTTP requests between content types (JSON, XML, SOAP, URL-encoded, multipart form-data, YAML, GraphQL and plain text). Port of h0tak88r's Burp extension.🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #CVE-2026 #Exploit #漏洞
📦 项目名称: root-my-s9280
👤 项目作者: NanoTurtle1145
🛠 开发语言: Kotlin
⭐ Star数量: 2 | 🍴 Fork数量: 1
📅 更新时间: 2026-08-17 05:48:50
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #CVE-2026 #Exploit #漏洞
📦 项目名称: root-my-s9280
👤 项目作者: NanoTurtle1145
🛠 开发语言: Kotlin
⭐ Star数量: 2 | 🍴 Fork数量: 1
📅 更新时间: 2026-08-17 05:48:50
📝 项目描述:
Using CVE-2026-43499 to root your Galaxy S24 Ultra(SM-S9280 ,(China / Hong Kong SAR / Taiwan))🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #SSRF #metadata
📦 项目名称: doujin-scraper
👤 项目作者: kyy0887
🛠 开发语言: JavaScript
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-16 23:56:19
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #SSRF #metadata
📦 项目名称: doujin-scraper
👤 项目作者: kyy0887
🛠 开发语言: JavaScript
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-16 23:56:19
📝 项目描述:
Scraper ringan untuk doujin.desu.xxx (API terenkripsi) & nekopoi.care — tanpa dependensi, anti-SSRF, sanitasi URL🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #SSRF #云元数据 #metadata
📦 项目名称: dsh-web-fetch-zhipu
👤 项目作者: FWW321
🛠 开发语言: JavaScript
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-17 03:17:32
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #SSRF #云元数据 #metadata
📦 项目名称: dsh-web-fetch-zhipu
👤 项目作者: FWW321
🛠 开发语言: JavaScript
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-17 03:17:32
📝 项目描述:
Zhipu BigModel web fetch provider for DeepSeek Harness (dsh) — delegated web_reader MCP behind a ctx.web WebFetchProvider; SSRF surface nil, session handshake, per-fetch auditing🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #Spring #POC
📦 项目名称: SpringAIJIRAColab
👤 项目作者: shrutikulkarni5020
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-17 05:02:31
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #Spring #POC
📦 项目名称: SpringAIJIRAColab
👤 项目作者: shrutikulkarni5020
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-17 05:02:31
📝 项目描述:
Agentic life cycle for this Spring project POC🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #渗透测试 #内网 #漏洞
📦 项目名称: kali-pentest
👤 项目作者: githuBlijingai
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-17 03:37:10
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #渗透测试 #内网 #漏洞
📦 项目名称: kali-pentest
👤 项目作者: githuBlijingai
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-17 03:37:10
📝 项目描述:
kali-pentest基于《Kali Linux渗透测试的艺术》方法论蒸馏,提供一个可被agent调用的、面向远程Kali Linux渗透测试的完整执行框架。🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #文件上传 #漏洞 #Webshell
📦 项目名称: File-Upload-Security-Testing-Workbench
👤 项目作者: HooXuefeng
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-17 03:27:51
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #文件上传 #漏洞 #Webshell
📦 项目名称: File-Upload-Security-Testing-Workbench
👤 项目作者: HooXuefeng
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-17 03:27:51
📝 项目描述:
UploadSentinel 是一个面向授权安全测试、Web 安全评估和文件上传接口复核的桌面工具🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #XSS #POC
📦 项目名称: XSS-challenges
👤 项目作者: brono04
🛠 开发语言: HTML
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-17 03:55:41
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #XSS #POC
📦 项目名称: XSS-challenges
👤 项目作者: brono04
🛠 开发语言: HTML
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-17 03:55:41
📝 项目描述:
About This is a repo of my solution of one XSS challenge website (http://sudo.co.il/xss/) . This challenges may have different types of solutions. My solutions are not the only one. So, keep searching & keep sharing.🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #XSS #Stored #Reflected #DOM
📦 项目名称: scriptjack
👤 项目作者: maximalfocus
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-17 02:49:13
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #XSS #Stored #Reflected #DOM
📦 项目名称: scriptjack
👤 项目作者: maximalfocus
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-17 02:49:13
📝 项目描述:
Educational, container-only demonstration of cross-site scripting (XSS / CWE-79): a deliberately vulnerable app and its secure twin, side by side. Runs locally over loopback via Docker Compose against fictional data; the vulnerable app is opt-in. Not hosted, not production-safe, must not be deployed.🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #XSS #Stored #Reflected
📦 项目名称: HakShop
👤 项目作者: Abdelrhman-Sherif-Mohamed
🛠 开发语言: PHP
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-17 02:58:01
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #XSS #Stored #Reflected
📦 项目名称: HakShop
👤 项目作者: Abdelrhman-Sherif-Mohamed
🛠 开发语言: PHP
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-17 02:58:01
📝 项目描述:
Vulnerable-by-design e-commerce training shop (XSS / SQLi / CSRF) built with PHP + SQLite - for educational purposes only.🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #RCE #POC
📦 项目名称: makeswift-rce-poc
👤 项目作者: Black1hp
🛠 开发语言: JavaScript
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-17 02:36:39
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #RCE #POC
📦 项目名称: makeswift-rce-poc
👤 项目作者: Black1hp
🛠 开发语言: JavaScript
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-17 02:36:39
📝 项目描述:
无描述🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #Nuclei #template
📦 项目名称: dast-harness
👤 项目作者: moovingGun
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-17 02:58:05
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #Nuclei #template
📦 项目名称: dast-harness
👤 项目作者: moovingGun
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-17 02:58:05
📝 项目描述:
Minimal DAST harness: run nuclei/nikto behind one interface with local-only safety, per-scanner completion evidence, and a merged report🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #CVE-2026 #POC #Exploit
📦 项目名称: EITS-Portal-Exploit-CVE-2026-31367-PoC
👤 项目作者: hereticL1nk
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-17 02:29:09
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #CVE-2026 #POC #Exploit
📦 项目名称: EITS-Portal-Exploit-CVE-2026-31367-PoC
👤 项目作者: hereticL1nk
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-17 02:29:09
📝 项目描述:
无描述🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #CVE-2026 #Exploit
📦 项目名称: CVE-2026-74251
👤 项目作者: toanln-cov
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-17 02:55:07
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #CVE-2026 #Exploit
📦 项目名称: CVE-2026-74251
👤 项目作者: toanln-cov
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-17 02:55:07
📝 项目描述:
Unauthenticated SQL Injection via Attribute Filter in Phoca Cart🔗 点击访问项目地址