📦 GitHub 全球红队渗透资源中转站。
​旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
⚠️ 本频道仅供安全研究与授权测试使用。
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #rule #rules #malware

📦 项目名称: detection-as-code
👤 项目作者: Howard1x5
🛠 开发语言: YARA
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-20 04:10:18

📝 项目描述:
● Automated malware analysis and detection rule generation pipeline using Wazuh SIEM, YARA, and Sigma rules

🔗 点击访问项目地址 GitHub - Howard1x5/detection-as-code: ● Automated malware analysis and detection rule generation pipeline using Wazuh SIEM, YARA…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Jenkins #POC

📦 项目名称: jenkins-poc
👤 项目作者: BayajidAlam
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-20 04:03:40

📝 项目描述:
无描述

🔗 点击访问项目地址 BayajidAlam/jenkins-poc
🚨 GitHub 监控消息提醒

🚨 发现关键词: #C2 #Framework

📦 项目名称: GhostC2
👤 项目作者: santiagoalza2132-art
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-20 03:53:55

📝 项目描述:
GhostC2: Un framework de Comando y Control (C2) sigiloso que utiliza protocolos no convencionales para comunicación encubierta.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Bypass #AMSI

📦 项目名称: SharpDonut
👤 项目作者: Ptkatz
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-20 03:04:45

📝 项目描述:
https://github.com/TheWover/donut in pure C#(.NET 10). supports compression, AMSI/WLDP/ETW bypass, etc.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC #Exploit #RCE

📦 项目名称: CVE-2026-2796-escape-wasm-by-using-wasm
👤 项目作者: SneakyNachos
🛠 开发语言: JavaScript
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-20 02:42:58

📝 项目描述:
PoC exploit chain for CVE-2026-2796: SpiderMonkey WebAssembly sandbox escape (signature type confusion -> arbitrary R/W -> RCE)

🔗 点击访问项目地址 GitHub - SneakyNachos/CVE-2026-2796-escape-wasm-by-using-wasm: PoC exploit chain for CVE-2026-2796: SpiderMonkey WebAssembly sandbox…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Sliver #C2

📦 项目名称: zeek-suricata-malware-traffic-analysis
👤 项目作者: ronaplayda4
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-20 01:25:16

📝 项目描述:
PCAP investigations using Zeek and Suricata to analyze DarkGate malware delivery and Sliver C2 activity, with Linux log parsing, file extraction, hashing, and OSINT enrichment.

🔗 点击访问项目地址 GitHub - ronaplayda4/zeek-suricata-malware-traffic-analysis: PCAP investigations using Zeek and Suricata to analyze DarkGate malware…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Exchange #CVE

📦 项目名称: currenzy
👤 项目作者: suchlab
🛠 开发语言: TypeScript
Star数量: 5 | 🍴 Fork数量: 1
📅 更新时间: 2026-08-20 02:04:05

📝 项目描述:
Get the exchange rates for currencies

🔗 点击访问项目地址 GitHub - suchlab/currenzy: Get the exchange rates for currencies
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Exploit #CVE

📦 项目名称: cve-2025-21479_iqooneo8
👤 项目作者: Qingizi7
🛠 开发语言: C
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-20 01:59:51

📝 项目描述:
Local root exploit for CVE-2025-21479 (Adreno KGSL) on iQOO Neo8 (SM8475) - physical memory r/w, disables SELinux, spawns root shell

🔗 点击访问项目地址 GitHub - Qingizi7/cve-2025-21479_iqooneo8: Local root exploit for CVE-2025-21479 (Adreno KGSL) on iQOO Neo8 (SM8475) - physical…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Exploit #RCE

📦 项目名称: vulnerability-notes
👤 项目作者: parsamajidipour
🛠 开发语言: Unknown
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-20 02:04:35

📝 项目描述:
A comprehensive collection of web security vulnerability notes covering concepts, attack techniques, real-world examples, exploitation methodologies, and mitigation strategies for security researchers, penetration testers, and bug bounty hunters.

🔗 点击访问项目地址 GitHub - parsamajidipour/vulnerability-notes: A comprehensive collection of web security vulnerability notes covering concepts…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #DOM

📦 项目名称: DSXS
👤 项目作者: stamparm
🛠 开发语言: Python
Star数量: 430 | 🍴 Fork数量: 131
📅 更新时间: 2026-08-19 22:14:18

📝 项目描述:
Damn Small XSS Scanner

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #Reflected #DOM

📦 项目名称: form-validation-security-testing
👤 项目作者: Djones-qa
🛠 开发语言: TypeScript
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-19 23:22:04

📝 项目描述:
Form validation security testing - XSS injection, SQL injection, boundary lengths, special characters. Found real vulnerability: checkout accepts malicious payloads. Playwright + TypeScript.

🔗 点击访问项目地址 GitHub - Djones-qa/form-validation-security-testing: Form validation security testing - XSS injection, SQL injection, boundary…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #Reflected

📦 项目名称: CodeAlpha_SecureCodingReview
👤 项目作者: amantlemaakelo
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-20 00:28:08

📝 项目描述:
Secure code review of a sample banking application,10 vulnerabilities identified (SQLi, broken access control, XSS, CSRF) via manual review + Bandit, remediated and verified with a re-scan.

🔗 点击访问项目地址 GitHub - amantlemaakelo/CodeAlpha_SecureCodingReview: Secure code review of a sample banking application,10 vulnerabilities identified…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: AegisWeb
👤 项目作者: Saura0S
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-20 01:01:09

📝 项目描述:
🛡️ Enterprise-Grade Web Security Auditor, Vulnerability Scanner & Dual-Report Engine in Python

🔗 点击访问项目地址 GitHub - Saura0S/AegisWeb: 🛡️ Enterprise-Grade Web Security Auditor, Vulnerability Scanner & Dual-Report Engine in Python
🚨 GitHub 监控消息提醒

🚨 发现关键词: #C2 #Framework

📦 项目名称: SinyC2
👤 项目作者: sinyblack59-del
🛠 开发语言: HTML
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-20 00:31:10

📝 项目描述:
A simple Open-Source C2 framework for Red Teaming labs.

🔗 点击访问项目地址 GitHub - sinyblack59-del/SinyC2: A simple Open-Source C2 framework for Red Teaming labs.
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Jenkins #POC

📦 项目名称: sf-github-jenkins-poc
👤 项目作者: sirfmandeep-coast
🛠 开发语言: Apex
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-19 23:55:24

📝 项目描述:
Salesforce DX GitHub Jenkins POC

🔗 点击访问项目地址 GitHub - sirfmandeep-coast/sf-github-jenkins-poc: Salesforce DX GitHub Jenkins POC
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Log4j #CVE #RCE

📦 项目名称: log4j-ransomware-bruteforcer
👤 项目作者: emad-123
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-19 21:31:22

📝 项目描述:
automated Python-based cryptographic data recovery tool designed to mitigate post-exploit ransomware encryption vectors.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #rules

📦 项目名称: awesome-yara
👤 项目作者: cybersecurity-dev
🛠 开发语言: Unknown
Star数量: 2 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-19 23:05:10

📝 项目描述:
Awesome YARA

🔗 点击访问项目地址 GitHub - cybersecurity-dev/awesome-yara: Awesome YARA
🚨 GitHub 监控消息提醒

🚨 发现关键词: #BlueTeam #Detection

📦 项目名称: decoy
👤 项目作者: nizartuanku
🛠 开发语言: Go
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-19 23:29:20

📝 项目描述:
Self-hosted canary tokens and honeypots — free edition of the Sentinel line

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: CVE-2026-76070
👤 项目作者: ozcanpng
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-19 23:35:47

📝 项目描述:
Original research and non-destructive PoC for a pre-auth Base64-decoded password stack buffer overflow in Netis NC63 login.cgi

🔗 点击访问项目地址 GitHub - ozcanpng/CVE-2026-76070: Original research and non-destructive PoC for a pre-auth Base64-decoded password stack buffer…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: CVE-2026-76071
👤 项目作者: ozcanpng
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-19 23:35:49

📝 项目描述:
Original research and non-destructive PoC for a pre-auth stack buffer overflow via unbounded sscanf scanset in the Netis NC63 ipFilterList handler

🔗 点击访问项目地址 GitHub - ozcanpng/CVE-2026-76071: Original research and non-destructive PoC for a pre-auth stack buffer overflow via unbounded…
Back to Top