📦 GitHub 全球红队渗透资源中转站。
​旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
⚠️ 本频道仅供安全研究与授权测试使用。
🚨 GitHub 监控消息提醒

🚨 发现关键词: #RCE #CVE

📦 项目名称: Cerberus-React2Shell-Scanner-Exploit
👤 项目作者: CerberusMrXi
🛠 开发语言: Python
Star数量: 2 | 🍴 Fork数量: 1
📅 更新时间: 2026-08-22 18:26:21

📝 项目描述:
Elite exploitation toolkit for CVE-2025-55182 (React Server Components RCE). Async polymorphic payloads, advanced WAF/CDN bypass, proxy rotation, Shodan/Censys mass scan, auto-pwn + reverse shells, Nuclei templates, K8s lab & C2 dashboard. Authored by Sudeepa Wanigarathna – strictly for authorized red team and penetration testing.

🔗 点击访问项目地址 GitHub - CerberusMrXi/Cerberus-React2Shell-Scanner-Exploit: Elite exploitation toolkit for CVE-2025-55182 (React Server Components…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #蜜罐 #部署 #捕获

📦 项目名称: sshfakekeyhome
👤 项目作者: ra1nyxin
🛠 开发语言: Python
Star数量: 3 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-22 17:46:21

📝 项目描述:
多诱饵紧凑型无状态SSH蜜罐,包含假Claude、Codex、Cursor、云平台与运维凭据,支持任意账户密码、公钥及交互认证,模拟Linux文件系统、网络、防火墙和常用命令,实时记录来源、凭据、命令与行为,并提供Web审计控制台

🔗 点击访问项目地址 GitHub - ra1nyxin/sshfakekeyhome: 多诱饵紧凑型无状态SSH蜜罐,包含假Claude、Codex、Cursor、云平台与运维凭据,支持任意账户密码、公钥及交互认证,模拟Linux文件系统、网络、防火墙和常用命令,实时记录…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #C2 #Framework

📦 项目名称: Argus-C2
👤 项目作者: Oreki0504
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-22 17:50:33

📝 项目描述:
A modular C2 framework for studying agent communication, remote tasking, and endpoint security in controlled environments.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #Stored #Reflected

📦 项目名称: Cybersecurity-internship-task-3
👤 项目作者: rutujalkhade2026
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-22 17:51:45

📝 项目描述:
Web application security testing project covering SQL Injection, Stored XSS, Reflected XSS and CSRF using DVWA.

🔗 点击访问项目地址 GitHub - rutujalkhade2026/Cybersecurity-internship-task-3: Web application security testing project covering SQL Injection, Stored…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #Stored #Reflected #DOM

📦 项目名称: Cross-Site-Scripting-XSS-Payload-Sanitizer
👤 项目作者: jenishs524
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-22 17:59:06

📝 项目描述:
An advanced, context-aware input sanitizer and XSS detection engine written in Python. Performs structural tokenization, recursive obfuscation decoding (URL, Base64, HTML entities), and context-sensitive sanitization to neutralize stored, reflected, and DOM-based XSS attacks.

🔗 点击访问项目地址 GitHub - jenishs524/Cross-Site-Scripting-XSS-Payload-Sanitizer: An advanced, context-aware input sanitizer and XSS detection engine…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: Web-VulnScan
👤 项目作者: Mayank045
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-22 17:55:32

📝 项目描述:
Modular web vulnerability scanner and security assessment framework. 🚧 Under Development

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Shellcode #Loader

📦 项目名称: SleepyLoader
👤 项目作者: lukehebe
🛠 开发语言: C
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-22 17:34:50

📝 项目描述:
Shellcode Loader

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #POC #CVE

📦 项目名称: CVE-2026-13736
👤 项目作者: MinhHK68
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-22 18:01:40

📝 项目描述:
无描述

🔗 点击访问项目地址 GitHub - MinhHK68/CVE-2026-13736
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #metadata

📦 项目名称: HIPR
👤 项目作者: Jboxbobby
🛠 开发语言: Python
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-22 15:06:46

📝 项目描述:
HIPR (Hardened Isolated Proxy Runtime) — A fault-tolerant, async egress proxy and outbound guardrail engine built with FastAPI and HTTPX. Features phase-decoupled timeouts, exponential backoff with full jitter, connection pooling, and defense-in-depth SSRF/DNS-rebinding protection.

🔗 点击访问项目地址 GitHub - Jboxbobby/HIPR: HIPR (Hardened Isolated Proxy Runtime) — A fault-tolerant, async egress proxy and outbound guardrail engine…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #metadata

📦 项目名称: langchain-hardened
👤 项目作者: hedgerow-dev
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-22 16:51:05

📝 项目描述:
Secure-defaults drop-in shim for LangChain: SSRF-checked loaders, deserialization allowlisting, jinja2 SSTI gate, human-approval-gated tools. MIT. From Hedgerow.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #RCE #Remote Code Execution

📦 项目名称: File-Upload-Vulnerability-Magic-Bytes-ValidatorFile-Upload-Vulnerability-Magic-Bytes-Validator
👤 项目作者: jenishs524
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-22 17:43:30

📝 项目描述:
An enterprise file upload security engine written in Python. Protects applications against Remote Code Execution (RCE), Unrestricted File Upload vulnerabilities, Polyglot web shells, and MIME-type spoofing through deep file inspection and magic byte validation.

🔗 点击访问项目地址 GitHub - jenishs524/File-Upload-Vulnerability-Magic-Bytes-ValidatorFile-Upload-Vulnerability-Magic-Bytes-Validator: An enterprise…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: api-ac-scanner
👤 项目作者: Fokkio
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-22 16:33:39

📝 项目描述:
API Access-Control vulnerability scanner: source scan (Semgrep) + domain auth-swap BOLA testing. Node/Express web UI + Python/FastAPI scanner.

🔗 点击访问项目地址 GitHub - Fokkio/api-ac-scanner: API Access-Control vulnerability scanner: source scan (Semgrep) + domain auth-swap BOLA testing.…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #C2 #Framework

📦 项目名称: dark-arts
👤 项目作者: kelvinweijun
🛠 开发语言: Go
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-22 16:53:47

📝 项目描述:
Repository for Command-and-Control (C2) framework for adversary simulation

🔗 点击访问项目地址 GitHub - kelvinweijun/dark-arts: Repository for Command-and-Control (C2) framework for adversary simulation
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Jenkins #EXP

📦 项目名称: calculator-jenkins
👤 项目作者: kavyatelavane2005
🛠 开发语言: HTML
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-22 16:59:19

📝 项目描述:
Devops Exp 3

🔗 点击访问项目地址 GitHub - kavyatelavane2005/calculator-jenkins: Devops Exp 3
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC #Exploit #RCE

📦 项目名称: CVE-2026-9198
👤 项目作者: K3ysTr0K3R
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-22 16:05:56

📝 项目描述:
CVE-2026-9198 - IBM Langflow OSS Unauthenticated Remote Code Execution (RCE)

🔗 点击访问项目地址 GitHub - K3ysTr0K3R/CVE-2026-9198
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: onyx-db
👤 项目作者: Boreas37
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-22 15:44:26

📝 项目描述:
Onyx — local-first WordPress vulnerability scanner'ın veri mirror'ı (Wordfence Production Feed, günlük güncel, commercial-free)

🔗 点击访问项目地址 GitHub - Boreas37/onyx-db: Onyx — local-first WordPress vulnerability scanner'ın veri mirror'ı (Wordfence Production Feed, günlük…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Exploit #POC

📦 项目名称: hole-in-bin
👤 项目作者: Ryuk0x01
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-22 16:00:39

📝 项目描述:
Hands-on binary exploitation and reverse engineering project focused on analyzing vulnerabilities, memory corruption, buffer overflows, and low-level system mechanics using GDB, PEDA, Ghidra, and Radare2.

🔗 点击访问项目地址 GitHub - Ryuk0x01/hole-in-bin: Hands-on binary exploitation and reverse engineering project focused on analyzing vulnerabilities…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #信息收集 #侦察

📦 项目名称: jsscout
👤 项目作者: eonun
🛠 开发语言: Go
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-22 15:50:05

📝 项目描述:
JS 侦察工具 —— 一站式 JS 信息收集 / 敏感信息提取 / API 发现,单二进制免环境跨平台。

🔗 点击访问项目地址 eonun/jsscout
🚨 GitHub 监控消息提醒

🚨 发现关键词: #C2 #Framework

📦 项目名称: M7MD-RAT-NG
👤 项目作者: almahasher016-lang
🛠 开发语言: Rust
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-22 15:03:10

📝 项目描述:
Multi-component remote administration / C2 framework (authorized red teaming and research use)

🔗 点击访问项目地址 GitHub - almahasher016-lang/M7MD-RAT-NG: Multi-component remote administration / C2 framework (authorized red teaming and research…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: network-vulnerability-scanner
👤 项目作者: yazhiniM29
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-22 14:41:38

📝 项目描述:
Python-based network vulnerability scanner using Nmap, vulnerability rules, version checking, CVE matching, risk scoring, and HTML reporting.

🔗 点击访问项目地址 yazhiniM29/network-vulnerability-scanner
Back to Top