📦 GitHub 全球红队渗透资源中转站。
旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
⚠️ 本频道仅供安全研究与授权测试使用。
旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
⚠️ 本频道仅供安全研究与授权测试使用。
🚨 GitHub 监控消息提醒
🚨 发现关键词: #YARA #APT #malware
📦 项目名称: intel-reports
👤 项目作者: dalthunter
🛠 开发语言: HTML
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-06 19:38:50
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #YARA #APT #malware
📦 项目名称: intel-reports
👤 项目作者: dalthunter
🛠 开发语言: HTML
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-06 19:38:50
📝 项目描述:
Threat Actor Profiles🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #YARA #rules #APT
📦 项目名称: multistage-apt-sim
👤 项目作者: nizamshanidahammed-collab
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-27 08:56:34
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #YARA #rules #APT
📦 项目名称: multistage-apt-sim
👤 项目作者: nizamshanidahammed-collab
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-27 08:56:34
📝 项目描述:
Internship task where I simulated a multi-stage APT — phishing, persistence, lateral movement, DNS tunnelling exfil — then switched to Blue Team and detected/investigated it using Security Onion, Wazuh, TheHive & Cortex, and MISP. Wrote Sigma & YARA rules and an IR report at the end.🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #YARA #APT #malware
📦 项目名称: prince-of-persia-tornado-cti
👤 项目作者: yankywilson
🛠 开发语言: YARA
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-21 22:08:52
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #YARA #APT #malware
📦 项目名称: prince-of-persia-tornado-cti
👤 项目作者: yankywilson
🛠 开发语言: YARA
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-21 22:08:52
📝 项目描述:
Threat intelligence, reverse engineering, and detection content (YARA, Sigma, Suricata, YARA-L, KQL/SPL hunting) for Infy / Prince of Persia (APT-C-07) "Tornado v51" — Iranian Foudre-family surveillance malware. TLP:GREEN.🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #威胁情报 #APT
📦 项目名称: IPGEO-Query
👤 项目作者: Samsepik9
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-06-23 05:09:40
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #威胁情报 #APT
📦 项目名称: IPGEO-Query
👤 项目作者: Samsepik9
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-06-23 05:09:40
📝 项目描述:
专业的 IP / 域名 / URL 地理位置 & 威胁情报查询 GUI 工具;Professional GUI tool for querying IP/domain/URL geolocation and threat intelligence🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #威胁情报 #APT #样本
📦 项目名称: attack-bench-zh
👤 项目作者: uninhibited-scholar
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-06-21 04:13:36
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #威胁情报 #APT #样本
📦 项目名称: attack-bench-zh
👤 项目作者: uninhibited-scholar
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-06-21 04:13:36
📝 项目描述:
中文威胁情报→ATT&CK技术编号标注映射集:封闭词表可机器评分,检测工程上游,防御导向。WIP.🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #YARA #APT
📦 项目名称: Titan
👤 项目作者: 4b75726169736859
🛠 开发语言: HTML
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-06-19 01:01:37
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #YARA #APT
📦 项目名称: Titan
👤 项目作者: 4b75726169736859
🛠 开发语言: HTML
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-06-19 01:01:37
📝 项目描述:
self-hosted SOC & DFIR suite for automated forensic analysis, threat hunting, and incident triage. Features YARA scanning, APT attribution, and AI-powered investigation🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #威胁情报 #APT
📦 项目名称: Dark-Web-Threat-Intelligence-System
👤 项目作者: CierraRunnis
🛠 开发语言: HTML
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-06-17 06:58:20
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #威胁情报 #APT
📦 项目名称: Dark-Web-Threat-Intelligence-System
👤 项目作者: CierraRunnis
🛠 开发语言: HTML
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-06-17 06:58:20
📝 项目描述:
暗网公开信息收集与威胁情报提取🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #YARA #rule #rules #APT #malware
📦 项目名称: rspamd-yarad
👤 项目作者: eilandert
🛠 开发语言: Go
⭐ Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-06-17 14:38:53
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #YARA #rule #rules #APT #malware
📦 项目名称: rspamd-yarad
👤 项目作者: eilandert
🛠 开发语言: Go
⭐ Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-06-17 14:38:53
📝 项目描述:
Out-of-process YARA scanner backend, with rspamd plugin. Go + libyara, HTTP /scan, verdict cache + singleflight + optional Redis, distroless.🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #YARA #APT
📦 项目名称: graphworm-webworm-detection
👤 项目作者: yankywilson
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-06-16 13:54:57
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #YARA #APT
📦 项目名称: graphworm-webworm-detection
👤 项目作者: yankywilson
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-06-16 13:54:57
📝 项目描述:
Detection pack for GraphWorm backdoor (Webworm APT) — OneDrive/Graph API C2. YARA, KQL, Sigma, IOCs, ATT&CK mapping. Based on full static RE (FLOSS + Ghidra) of SHA256: 6eb6a342...🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #YARA #rule #rules #APT #malware
📦 项目名称: blazehash
👤 项目作者: SecurityRonin
🛠 开发语言: Rust
⭐ Star数量: 5 | 🍴 Fork数量: 1
📅 更新时间: 2026-06-15 17:37:22
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #YARA #rule #rules #APT #malware
📦 项目名称: blazehash
👤 项目作者: SecurityRonin
🛠 开发语言: Rust
⭐ Star数量: 5 | 🍴 Fork数量: 1
📅 更新时间: 2026-06-15 17:37:22
📝 项目描述:
Forensic file hasher — BLAKE3 at 1,640 MB/s, 25 hash algorithms, Ed25519 + post-quantum signing, Bitcoin timestamps, YARA scanning, 50+ remote backends. hashdeep for the modern era.🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #YARA #rule #rules #APT #malware
📦 项目名称: SIEM-WAZUH
👤 项目作者: dan2022005
🛠 开发语言: Unknown
⭐ Star数量: 2 | 🍴 Fork数量: 0
📅 更新时间: 2026-06-13 07:55:03
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #YARA #rule #rules #APT #malware
📦 项目名称: SIEM-WAZUH
👤 项目作者: dan2022005
🛠 开发语言: Unknown
⭐ Star数量: 2 | 🍴 Fork数量: 0
📅 更新时间: 2026-06-13 07:55:03
📝 项目描述:
Triển khai hệ thống SIEM bằng Wazuh nhằm phát hiện, và ứng phó với các mối đe dọa an ninh mạng. Hệ thống tích hợp Suricata và Yara để giám sát tính toàn vẹn của tệp, phát hiện và tự động ngăn chặn dò quét mật khẩu, dò quét mạng và phát hiện phần mềm độc hại.🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #YARA #rule #rules #APT
📦 项目名称: azul-plugin-retrohunt
👤 项目作者: AustralianCyberSecurityCentre
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-05-30 14:53:29
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #YARA #rule #rules #APT
📦 项目名称: azul-plugin-retrohunt
👤 项目作者: AustralianCyberSecurityCentre
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-05-30 14:53:29
📝 项目描述:
AZUL plugins for indexing and querying historical samples with yara queries.🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #YARA #rule #rules #APT #malware
📦 项目名称: ohmypcap
👤 项目作者: dougburks
🛠 开发语言: Python
⭐ Star数量: 200 | 🍴 Fork数量: 14
📅 更新时间: 2026-05-26 10:03:05
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #YARA #rule #rules #APT #malware
📦 项目名称: ohmypcap
👤 项目作者: dougburks
🛠 开发语言: Python
⭐ Star数量: 200 | 🍴 Fork数量: 14
📅 更新时间: 2026-05-26 10:03:05
📝 项目描述:
OhMyPCAP is a FOSS web application for analyzing PCAP files using Suricata and other files using YARA. View network alerts and file alerts, browse network metadata (DNS, HTTP, TLS, flows), extract ASCII transcripts, view per-packet hexdumps, and carve individual streams.🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #YARA #rule #rules #APT #malware
📦 项目名称: mailhook
👤 项目作者: izm1chael
🛠 开发语言: Go
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-05-26 09:39:40
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #YARA #rule #rules #APT #malware
📦 项目名称: mailhook
👤 项目作者: izm1chael
🛠 开发语言: Go
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-05-26 09:39:40
📝 项目描述:
Self-hosted email security gateway: IMAP IDLE monitoring with Rspamd/ClamAV/YARA/URL-feed scanning, a quarantine workflow, and a web dashboard.🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #YARA #APT #malware
📦 项目名称: gamybear
👤 项目作者: yankywilson
🛠 开发语言: Go
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-05-24 22:50:11
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #YARA #APT #malware
📦 项目名称: gamybear
👤 项目作者: yankywilson
🛠 开发语言: Go
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-05-24 22:50:11
📝 项目描述:
First public reverse engineering of GAMYBEAR, the Go backdoor used by UAC-0241 against Ukrainian education and state-authority targets. Static + dynamic analysis with 15 findings extending CERT-UA#18329, including a persistence correction and the http.DefaultClient TLS failure. IOCs, YARA, Suricata, Snort, STIX.🔗 点击访问项目地址