📦 GitHub 全球红队渗透资源中转站。
​旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
⚠️ 本频道仅供安全研究与授权测试使用。
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #rules #malware

📦 项目名称: ReverseEngine
👤 项目作者: aerovfx
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-17 09:01:45

📝 项目描述:
This course trains cybersecurity professionals to safely dissect, analyze, and neutralize malware like ransomware and trojans. Students build isolated labs, perform dynamic and static triage, and master disassemblers like Ghidra and x64dbg. Learn to unpack code, bypass anti-analysis tricks, extract IoCs, and build YARA rules to defend networks.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #漏洞 #Nuclei

📦 项目名称: ai-src-hunter
👤 项目作者: yuan-Sec
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-17 08:35:47

📝 项目描述:
AI辅助SRC漏洞挖掘工作流 - 信息收集/泄露检测/Nuclei/AI分析

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #漏洞 #EXP #复现

📦 项目名称: fastjson2--exp
👤 项目作者: kaoniniang2
🛠 开发语言: Java
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-17 08:59:04

📝 项目描述:
漏洞复现

🔗 点击访问项目地址 GitHub - kaoniniang2/fastjson2--exp: 漏洞复现
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Exploit #RCE

📦 项目名称: SSTI-Exploiter
👤 项目作者: ArmanAbr
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-17 08:06:22

📝 项目描述:
Server-Side Template Injection detection & exploitation toolkit

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Exploit #CVE

📦 项目名称: CVE-2026-68138
👤 项目作者: jangkrikkbozz
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-17 08:04:52

📝 项目描述:
CVE-2026-68138 Linux Local Privilege Escalation Exploit

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Nuclei #template #templates #CVE

📦 项目名称: easm-recon
👤 项目作者: Lockbearer
🛠 开发语言: Python
Star数量: 3 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-17 07:55:18

📝 项目描述:
Cross-platform domain reconnaissance wrapper: one command runs DNS, HTTP, WAF/CDN, TLS, port and nuclei scans, with a graceful fallback for every stage

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #渗透测试 #红队

📦 项目名称: dsh-redteam-model
👤 项目作者: SeaOf0
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-17 08:01:15

📝 项目描述:
基于dsh web实现的工作模式,目的是服务于redteam进行安全研究,覆盖渗透测试、红队评估、代码审计等范围领域,请勿用于非法行为。

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #Reflected

📦 项目名称: xss-lab
👤 项目作者: rgsecteam
🛠 开发语言: HTML
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-17 07:17:07

📝 项目描述:
An offline, Dockerized web app for teaching reflected XSS → cookie theft → account takeover, with three difficulty levels (Low / Medium / High).

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Burp #Extension

📦 项目名称: gap
👤 项目作者: ArkhaMahn
🛠 开发语言: Java
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-17 07:11:45

📝 项目描述:
GAP for ZAP: find the parameters, links and words that may not be obvious. Port of xnl-h4ck3r's GAP Burp extension.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: CVE-2026-59310
👤 项目作者: HORKimhab
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-17 07:52:35

📝 项目描述:
CVE-2026-59310

🔗 点击访问项目地址 GitHub - HORKimhab/CVE-2026-59310: CVE-2026-59310
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSTI #RCE

📦 项目名称: SSTI-CHECKER
👤 项目作者: ebrahimgh21
🛠 开发语言: Python
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-16 23:28:04

📝 项目描述:
无描述

🔗 点击访问项目地址 GitHub - ebrahimgh21/SSTI-CHECKER
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSTI #RCE

📦 项目名称: PipePwned---Writeup
👤 项目作者: baheandiego07
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-17 04:40:09

📝 项目描述:
PipePwned es un laboratorio que simula un entorno CI/CD vulnerable, donde se explota una cadena de vulnerabilidades que incluyen IDOR, SSTI, fuga de información y escalada de privilegios mediante Poisoned Pipeline Execution (PPE) en un runner self-hosted de GitLab.

🔗 点击访问项目地址 GitHub - baheandiego07/PipePwned---Writeup: PipePwned es un laboratorio que simula un entorno CI/CD vulnerable, donde se explota…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Burp #Plugin

📦 项目名称: dsh-heath-mcp
👤 项目作者: Heath96
🛠 开发语言: JavaScript
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-17 06:33:04

📝 项目描述:
MCP server bridge for DeepSeek Harness: stdio / streamable-http / legacy-SSE transports, web settings UI (form + JSON), tools as mcp__<server>__<tool>. Burp Suite ready out of the box.

🔗 点击访问项目地址 GitHub - Heath96/dsh-heath-mcp: MCP server bridge for DeepSeek Harness: stdio / streamable-http / legacy-SSE transports, web settings…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Burp #Extension

📦 项目名称: converttype
👤 项目作者: ArkhaMahn
🛠 开发语言: Java
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-17 06:55:19

📝 项目描述:
ZAP add-on that converts HTTP requests between content types (JSON, XML, SOAP, URL-encoded, multipart form-data, YAML, GraphQL and plain text). Port of h0tak88r's Burp extension.

🔗 点击访问项目地址 GitHub - ArkhaMahn/converttype: ZAP add-on that converts HTTP requests between content types (JSON, XML, SOAP, URL-encoded, multipart…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #Exploit #漏洞

📦 项目名称: root-my-s9280
👤 项目作者: NanoTurtle1145
🛠 开发语言: Kotlin
Star数量: 2 | 🍴 Fork数量: 1
📅 更新时间: 2026-08-17 05:48:50

📝 项目描述:
Using CVE-2026-43499 to root your Galaxy S24 Ultra(SM-S9280 ,(China / Hong Kong SAR / Taiwan))

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #metadata

📦 项目名称: doujin-scraper
👤 项目作者: kyy0887
🛠 开发语言: JavaScript
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-16 23:56:19

📝 项目描述:
Scraper ringan untuk doujin.desu.xxx (API terenkripsi) & nekopoi.care — tanpa dependensi, anti-SSRF, sanitasi URL

🔗 点击访问项目地址 GitHub - kyy0887/doujin-scraper: Scraper ringan untuk doujin.desu.xxx (API terenkripsi) & nekopoi.care — tanpa dependensi, anti…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #云元数据 #metadata

📦 项目名称: dsh-web-fetch-zhipu
👤 项目作者: FWW321
🛠 开发语言: JavaScript
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-17 03:17:32

📝 项目描述:
Zhipu BigModel web fetch provider for DeepSeek Harness (dsh) — delegated web_reader MCP behind a ctx.web WebFetchProvider; SSRF surface nil, session handshake, per-fetch auditing

🔗 点击访问项目地址 GitHub - FWW321/dsh-web-fetch-zhipu: Zhipu BigModel web fetch provider for DeepSeek Harness (dsh) — delegated web_reader MCP behind…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Spring #POC

📦 项目名称: SpringAIJIRAColab
👤 项目作者: shrutikulkarni5020
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-17 05:02:31

📝 项目描述:
Agentic life cycle for this Spring project POC

🔗 点击访问项目地址 shrutikulkarni5020/SpringAIJIRAColab
🚨 GitHub 监控消息提醒

🚨 发现关键词: #渗透测试 #内网 #漏洞

📦 项目名称: kali-pentest
👤 项目作者: githuBlijingai
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-17 03:37:10

📝 项目描述:
kali-pentest基于《Kali Linux渗透测试的艺术》方法论蒸馏,提供一个可被agent调用的、面向远程Kali Linux渗透测试的完整执行框架。

🔗 点击访问项目地址 GitHub - githuBlijingai/kali-pentest: kali-pentest基于《Kali Linux渗透测试的艺术》方法论蒸馏,提供一个可被agent调用的、面向远程Kali Linux渗透测试的完整执行框架。
Back to Top