​📦 GitHub 全球红队渗透资源中转站。
​旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
​⚠️ 本频道仅供安全研究与授权测试使用。
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Log4j #POC

📦 项目名称: log4j-shell-poc-azure
👤 项目作者: binhlam
🛠 开发语言: Roff
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-21 11:25:19

📝 项目描述:
Migrated from Azure Devops

🔗 点击访问项目地址 GitHub - binhlam/log4j-shell-poc-azure: Migrated from Azure Devops
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Log4j #CVE

📦 项目名称: springboot-log4j-fix
👤 项目作者: ajayrahul11
🛠 开发语言: Java
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-19 15:16:02

📝 项目描述:
This repo is a dummy repo for the vuln-agent project

🔗 点击访问项目地址 GitHub - ajayrahul11/springboot-log4j-fix: This repo is a dummy repo for the vuln-agent project
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Log4j #CVE

📦 项目名称: gradle-jfrog-private-test
👤 项目作者: Backline-playground
🛠 开发语言: Java
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-08 14:17:33

📝 项目描述:
BKLN-2092 E2E test (Gradle counterpart): Gradle project consuming a private artifact from JFrog (com.backline.test:demo-lib:1.0.0) that transitively pulls in vulnerable log4j-core. Validates that the JFrogRegistryMavenPackageRegistryHandler-written ~/.gradle/init.gradle authenticates correctly.

🔗 点击访问项目地址 GitHub - Backline-playground/gradle-jfrog-private-test: BKLN-2092 E2E test (Gradle counterpart): Gradle project consuming a private…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Log4j #CVE

📦 项目名称: transdep-demo-util-common
👤 项目作者: siddharthoak
🛠 开发语言: Java
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-07 10:32:24

📝 项目描述:
Demo: company-standard logging/tracing util lib. Part of a 3-repo chain used to test transitive-dependency vulnerability handling in vuln-remediation-agent. Deliberately depends on a vulnerable log4j-core version.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Log4j #CVE

📦 项目名称: transdep-demo-app
👤 项目作者: siddharthoak
🛠 开发语言: Java
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-07 10:33:18

📝 项目描述:
Demo: leaf app depending on transdep-demo-service-lib (2 hops from a vulnerable log4j-core dep in transdep-demo-util-common). Test target for the transitive-dependency gap in vuln-remediation-agent.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Log4j #CVE

📦 项目名称: m5-log4shell-demo
👤 项目作者: aureliusgovenai
🛠 开发语言: Java
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-07 14:19:29

📝 项目描述:
Aurelius M5 demo — Maven project with a deliberately outdated log4j-core for the log4shell-bump patch runner to fix

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Log4j #CVE

📦 项目名称: log4shell-exploitation-lab
👤 项目作者: Wafeeq-Fareed
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-06 14:54:09

📝 项目描述:
CVE-2021-44228 Log4Shell reproduced end to end: exploitation through remediation

🔗 点击访问项目地址 GitHub - Wafeeq-Fareed/log4shell-exploitation-lab: CVE-2021-44228 Log4Shell reproduced end to end: exploitation through remediation
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Log4j #CVE

📦 项目名称: log4j2-filter-lab
👤 项目作者: jctommasi
🛠 开发语言: Java
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-29 23:35:38

📝 项目描述:
Log4j 2's deserialization allowlist permits java.rmi.MarshalledObject, which carries bytes it never inspects. A fully-caged lab for logging-log4j2#4255: six transports, two log4j-core versions, Apache's own receiver unmodified, and a swimlane UI over the unfiltered zone. Docker only.

🔗 点击访问项目地址 jctommasi/log4j2-filter-lab
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Log4j #RCE

📦 项目名称: log4j2-4255-lab
👤 项目作者: Per0x1de-1337
🛠 开发语言: Shell
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-28 23:21:48

📝 项目描述:
无描述

🔗 点击访问项目地址 GitHub - Per0x1de-1337/log4j2-4255-lab
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Log4j #RCE #POC

📦 项目名称: log4j-4255
👤 项目作者: Clarapotbellied1003
🛠 开发语言: Java
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-29 07:26:47

📝 项目描述:
Reproduce log4j2 #4255 deserialization RCE in Docker with JDK 17, validate mitigations, and test detection controls.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Log4j #RCE

📦 项目名称: log4j2-fois-rce
👤 项目作者: yijinglab
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-28 06:57:34

📝 项目描述:
log4j-4255

🔗 点击访问项目地址 GitHub - yijinglab/log4j2-fois-rce: log4j-4255
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Log4j #CVE #RCE #POC

📦 项目名称: log4j2-fois-analysis
👤 项目作者: RogueValleyInformationSecurity
🛠 开发语言: Python
⭐ Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-26 21:07:00

📝 项目描述:
Defensive analysis of an unpatched Log4j2 FilteredObjectInputStream / MarshalledObject deserialization flaw, with a container exposure scanner and a 53-build survey of real-world Java products.

🔗 点击访问项目地址 GitHub - RogueValleyInformationSecurity/log4j2-fois-analysis: Defensive analysis of an unpatched Log4j2 FilteredObjectInputStream…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Log4j #RCE #POC

📦 项目名称: log4j2-4255-exploit
👤 项目作者: joanbono
🛠 开发语言: Python
⭐ Star数量: 1 | 🍴 Fork数量: 3
📅 更新时间: 2026-08-26 16:22:20

📝 项目描述:
exploit for Log4j2 (issue 4255)

🔗 点击访问项目地址 GitHub - joanbono/log4j2-4255-exploit: exploit for Log4j2 (issue 4255)
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Log4j #RCE

📦 项目名称: log4j2-rce
👤 项目作者: hypnguyen1209
🛠 开发语言: Java
⭐ Star数量: 6 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-26 17:00:08

📝 项目描述:
Pre-auth RCE via FilteredObjectInputStream MarshalledObject bypass in Apache Log4j 2

🔗 点击访问项目地址 GitHub - hypnguyen1209/log4j2-rce: Pre-auth RCE via FilteredObjectInputStream MarshalledObject bypass in Apache Log4j 2
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Log4j #RCE

📦 项目名称: log4j-fois-marshalledobject
👤 项目作者: striga-ai
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-26 13:04:49

📝 项目描述:
FilteredObjectInputStream allowlist bypass via java.rmi.MarshalledObject, auto-triggered during Log4jLogEvent deserialization, leading to unauthenticated RCE on serialized log receivers.

🔗 点击访问项目地址 GitHub - striga-ai/log4j-fois-marshalledobject: FilteredObjectInputStream allowlist bypass via java.rmi.MarshalledObject, auto…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Log4j #CVE #JNDI

📦 项目名称: patch-CVE-2025-19000
👤 项目作者: gduma-phData
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-24 03:05:08

📝 项目描述:
Patch: JNDI injection variant (Apache Log4j)

🔗 点击访问项目地址 GitHub - gduma-phData/patch-CVE-2025-19000: Patch: JNDI injection variant (Apache Log4j)
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Log4j #CVE #RCE

📦 项目名称: log4j-ransomware-bruteforcer
👤 项目作者: emad-123
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-19 21:31:22

📝 项目描述:
automated Python-based cryptographic data recovery tool designed to mitigate post-exploit ransomware encryption vectors.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Log4j #CVE #RCE

📦 项目名称: aig-shields-up-cybersecurity
👤 项目作者: alainmartar
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-13 21:25:39

📝 项目描述:
Cybersecurity virtual experience projects covering Log4j vulnerability response and ransomware recovery with Python.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Log4j #漏洞 #CVE

📦 项目名称: CVE-Apache-Ecosystem
👤 项目作者: chengbochuan3
🛠 开发语言: Shell
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-13 11:38:25

📝 项目描述:
Apache 生态系统 CVE 漏洞复现靶场 — Struts2, Tomcat, Solr, HTTP Server, Log4j, Commons Text

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Log4j #CVE #RCE

📦 项目名称: Log4j-Ransomware-Analysis-Simulation
👤 项目作者: Danko0210
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-10 15:59:10

📝 项目描述:
Custom Python script and incident report for Log4j and nested ransomware emulation

🔗 点击访问项目地址 GitHub - Danko0210/Log4j-Ransomware-Analysis-Simulation: Custom Python script and incident report for Log4j and nested ransomware…
 
 
Back to Top