📦 GitHub 全球红队渗透资源中转站。
​旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
⚠️ 本频道仅供安全研究与授权测试使用。
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #CVE

📦 项目名称: patch-CVE-2025-37654
👤 项目作者: gduma-phData
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-24 03:03:53

📝 项目描述:
Patch: XSS leading to RCE (Zimbra Collaboration)

🔗 点击访问项目地址 GitHub - gduma-phData/patch-CVE-2025-37654: Patch: XSS leading to RCE (Zimbra Collaboration)
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Weblogic #CVE

📦 项目名称: patch-CVE-2026-22024
👤 项目作者: gduma-phData
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-24 03:02:30

📝 项目描述:
Patch: Deserialization vulnerability (Oracle WebLogic Server)

🔗 点击访问项目地址 GitHub - gduma-phData/patch-CVE-2026-22024: Patch: Deserialization vulnerability (Oracle WebLogic Server)
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Fortinet #CVE

📦 项目名称: fortitool
👤 项目作者: mosajjal
🛠 开发语言: Go
Star数量: 26 | 🍴 Fork数量: 6
📅 更新时间: 2026-08-24 00:48:36

📝 项目描述:
Fortinet Firmware decryption and analysis tools

🔗 点击访问项目地址 GitHub - mosajjal/fortitool: Fortinet Firmware decryption and analysis tools
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Fortinet #CVE

📦 项目名称: patch-CVE-2026-12087
👤 项目作者: gduma-phData
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-24 03:02:27

📝 项目描述:
Patch: Heap overflow in SSL-VPN (Fortinet FortiOS)

🔗 点击访问项目地址 GitHub - gduma-phData/patch-CVE-2026-12087: Patch: Heap overflow in SSL-VPN (Fortinet FortiOS)
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SQL注入 #漏洞

📦 项目名称: API
👤 项目作者: TaoLjx
🛠 开发语言: Java
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-24 01:40:19

📝 项目描述:
一个精心设计的API安全靶场,模拟真实电商平台+第三方支付集成的生产环境,覆盖 OWASP API Security Top 10 及SQL注入、命令注入、路径遍历、XXE、GraphQL、信息泄露、webhookAPI、业务逻辑、开放重定向等专项漏洞

🔗 点击访问项目地址 GitHub - TaoLjx/API: 一个精心设计的API安全靶场,模拟真实电商平台+第三方支付集成的生产环境,覆盖 OWASP API Security Top 10 及SQL注入、命令注入、路径遍历、XXE、GraphQL、信息泄露、webho…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Kubernetes #POC

📦 项目名称: mlmodels_serving_ai_service_apps
👤 项目作者: zeiglerit
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-24 02:04:49

📝 项目描述:
2 "apps" or poc app as services, 1 ml model serving app, 1 ai gen ai app, both designed to run on mlflow or gcp cloud container kubernetes

🔗 点击访问项目地址 GitHub - zeiglerit/mlmodels_serving_ai_service_apps: 2
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Exploit #POC

📦 项目名称: WP2SHELL-EXPLOIT
👤 项目作者: zncomsddsdela
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-24 01:50:39

📝 项目描述:
w2pshell

🔗 点击访问项目地址 GitHub - zncomsddsdela/WP2SHELL-EXPLOIT: w2pshell
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: Security-Auditing-Project
👤 项目作者: Faizan0124
🛠 开发语言: TypeScript
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-24 00:24:16

📝 项目描述:
A dual-tier security auditing platform featuring a client-side web vulnerability scanner and an AST-powered SAST/SCA CLI engine with automated SARIF reporting and CI/CD security gates.

🔗 点击访问项目地址 GitHub - Faizan0124/Security-Auditing-Project: A dual-tier security auditing platform featuring a client-side web vulnerability…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #rule

📦 项目名称: YK
👤 项目作者: mohamed-murad7
🛠 开发语言: CSS
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-24 00:19:18

📝 项目描述:
Yara & Kareem

🔗 点击访问项目地址 GitHub - mohamed-murad7/YK: Yara & Kareem
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #rules

📦 项目名称: Isolation_Bytes
👤 项目作者: soluzka
🛠 开发语言: Python
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-24 00:33:01

📝 项目描述:
learning/research project AV Desktop App

🔗 点击访问项目地址 GitHub - soluzka/Isolation_Bytes: learning/research project AV Desktop App
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #POC #CVE #metadata

📦 项目名称: laradock_thumbor_ssrf_insecure_defaults
👤 项目作者: s4hilpuni4
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-24 00:49:16

📝 项目描述:
Thumbor open SSRF proxy via insecure defaults (CWE-918/798/1188)

🔗 点击访问项目地址 GitHub - s4hilpuni4/laradock_thumbor_ssrf_insecure_defaults: Thumbor open SSRF proxy via insecure defaults (CWE-918/798/1188)
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Shellcode #Loader

📦 项目名称: CodeCaver
👤 项目作者: pavelkalas
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-23 23:37:46

📝 项目描述:
Code cave injector pro PE soubory (EXE/DLL). Našije do binárky novou spustitelnou sekci a zařídí načtení vlastní DLL při startu. Podpora x86 i x64, čistý Python bez závislostí.

🔗 点击访问项目地址 GitHub - pavelkalas/CodeCaver: Code cave injector pro PE soubory (EXE/DLL). Našije do binárky novou spustitelnou sekci a zařídí…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: osv-depguard
👤 项目作者: CodeAbbas
🛠 开发语言: JavaScript
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-24 00:00:35

📝 项目描述:
AI-powered npm vulnerability scanner using OSV.dev. Deterministic Hybrid Vulnerability Scanner for Node.js projects.

🔗 点击访问项目地址 GitHub - CodeAbbas/osv-depguard: AI-powered npm vulnerability scanner using OSV.dev. Deterministic Hybrid Vulnerability Scanner…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Shellcode #Evasion #EDR #AV

📦 项目名称: hells-gate-runner
👤 项目作者: Segaotava
🛠 开发语言: C++
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-23 19:10:37

📝 项目描述:
Shellcode runner using Hell's Gate syscalls + XOR encryption

🔗 点击访问项目地址 GitHub - Segaotava/hells-gate-runner: Shellcode runner using Hell's Gate syscalls + XOR encryption
🚨 GitHub 监控消息提醒

🚨 发现关键词: #漏扫

📦 项目名称: lousao-data-analysis
👤 项目作者: Fyx2003-ctrl
🛠 开发语言: HTML
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-23 20:50:14

📝 项目描述:
转运中心漏扫描数据分析 - Python数据清洗/分析/可视化项目

🔗 点击访问项目地址 GitHub - Fyx2003-ctrl/lousao-data-analysis: 转运中心漏扫描数据分析 - Python数据清洗/分析/可视化项目
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: web-vulnerability-scanner
👤 项目作者: 4ynow
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-23 20:55:32

📝 项目描述:
无描述

🔗 点击访问项目地址 GitHub - 4ynow/web-vulnerability-scanner
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #metadata

📦 项目名称: ssrf
👤 项目作者: cplieger
🛠 开发语言: Go
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-23 20:12:53

📝 项目描述:
SSRF + DNS-rebinding protection for Go: validate outbound URLs and dial safely

🔗 点击访问项目地址 GitHub - cplieger/ssrf: SSRF + DNS-rebinding protection for Go: validate outbound URLs and dial safely
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #POC #metadata

📦 项目名称: Gamal
👤 项目作者: Fadavvi
🛠 开发语言: Python
Star数量: 14 | 🍴 Fork数量: 1
📅 更新时间: 2026-08-23 21:00:48

📝 项目描述:
A tiny app to help red-teamers, purple teamers, and pentesters in delivery, data exfiltration, and some attacks (SSRF, XXE, XSS, Session Hijacking, Session Riding)

🔗 点击访问项目地址 GitHub - Fadavvi/Gamal: A tiny app to help red-teamers, purple teamers, and pentesters in delivery, data exfiltration, and some…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: Web-Vulnerability-Scanner
👤 项目作者: muzaffarjutt470-star
🛠 开发语言: Python
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-23 19:28:25

📝 项目描述:
Web Vulnerability Scanner — A Python-based defensive security tool designed to assess authorized web applications for common security weaknesses, analyze HTTP responses and security-related configurations, and generate structured findings to support vulnerability assessment and secure development.

🔗 点击访问项目地址 GitHub - muzaffarjutt470-star/Web-Vulnerability-Scanner: Web Vulnerability Scanner — A Python-based defensive security tool designed…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #rules

📦 项目名称: Mandravasarotra-AV
👤 项目作者: tantelyorion
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-23 18:32:36

📝 项目描述:
Mandravasarotra Antivirus — A fully local, open-source antivirus engine with zero cloud/AI dependency. Combines hash signatures, YARA rules, behavioral heuristics, real-time file/USB/process monitoring, and quarantine — all in Python. MIT licensed, tested with pytest + CI. Built with Malagasy 🇲🇬 identity, global cybersecurity ambition.

🔗 点击访问项目地址 GitHub - tantelyorion/Mandravasarotra-AV: Mandravasarotra Antivirus — A fully local, open-source antivirus engine with zero cloud/AI…
Back to Top