📦 GitHub 全球红队渗透资源中转站。
旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
⚠️ 本频道仅供安全研究与授权测试使用。
旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
⚠️ 本频道仅供安全研究与授权测试使用。
🚨 GitHub 监控消息提醒
🚨 发现关键词: #SSTI #RCE
📦 项目名称: sentinelhub
👤 项目作者: JinBaiWansec
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-13 05:47:46
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #SSTI #RCE
📦 项目名称: sentinelhub
👤 项目作者: JinBaiWansec
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-13 05:47:46
📝 项目描述:
OSWE-style white-box web exploitation lab. A Flask monitoring app with chained RCE paths buried in normal business logic — practice source-code review.🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #SSTI #RCE
📦 项目名称: purple-team-ssti-wazuh-lab
👤 项目作者: Vezzyyy
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-09 21:21:14
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #SSTI #RCE
📦 项目名称: purple-team-ssti-wazuh-lab
👤 项目作者: Vezzyyy
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-09 21:21:14
📝 项目描述:
无描述🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #SSTI #RCE
📦 项目名称: fmfuzz_tool
👤 项目作者: Mr-xn
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-09 06:36:29
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #SSTI #RCE
📦 项目名称: fmfuzz_tool
👤 项目作者: Mr-xn
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-09 06:36:29
📝 项目描述:
freemarker SSTI 命令执行/混淆/文件写入,以及jmreport组件利用payload生成🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #SSTI #RCE
📦 项目名称: SSTImap-Kali-2026-Guide
👤 项目作者: Mariokiilz
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-05 10:06:36
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #SSTI #RCE
📦 项目名称: SSTImap-Kali-2026-Guide
👤 项目作者: Mariokiilz
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-05 10:06:36
📝 项目描述:
无描述🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #SSTI #RCE
📦 项目名称: ai-escape-room
👤 项目作者: an4kronism
🛠 开发语言: Python
⭐ Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-04 20:31:33
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #SSTI #RCE
📦 项目名称: ai-escape-room
👤 项目作者: an4kronism
🛠 开发语言: Python
⭐ Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-04 20:31:33
📝 项目描述:
Educational CTF lab recreating the July 2026 autonomous AI agent intrusion at Hugging Face. Sandbox escape → SSRF → HDF5 file read → Jinja2 SSTI → Kubernetes lateral movement → supply chain pivot. 11 Docker containers, 7 flags.🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #SSTI #RCE
📦 项目名称: do-not-disturb-thm
👤 项目作者: HackerRank7
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-03 10:48:54
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #SSTI #RCE
📦 项目名称: do-not-disturb-thm
👤 项目作者: HackerRank7
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-03 10:48:54
📝 项目描述:
Full Boot2Root writeup for TryHackMe's "Do Not Disturb" room (Hacker Holidays 2026) — NoSQL injection auth bypass → EJS SSTI/RCE → exposed Node inspector abuse → disk-group raw partition read for root.🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #SSTI #RCE
📦 项目名称: SSTI-Vulnerable-Lab
👤 项目作者: hurrainjhl
🛠 开发语言: Unknown
⭐ Star数量: 2 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-30 19:13:53
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #SSTI #RCE
📦 项目名称: SSTI-Vulnerable-Lab
👤 项目作者: hurrainjhl
🛠 开发语言: Unknown
⭐ Star数量: 2 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-30 19:13:53
📝 项目描述:
无描述🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #SSTI #RCE
📦 项目名称: vulnerable-boutique-ctf
👤 项目作者: izzaddiin123
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-30 08:43:26
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #SSTI #RCE
📦 项目名称: vulnerable-boutique-ctf
👤 项目作者: izzaddiin123
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-30 08:43:26
📝 项目描述:
Vulnerable web app contains of 20 vulnerabilities including XSS,SSRF,SSTI,RCE,Insecure direct object refernce,Insecure Deserialization,jwt auth bypass,Race condition,and more others🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #SSTI #RCE
📦 项目名称: NordArosa-Enterprise-Security-Lab
👤 项目作者: NordArosa
🛠 开发语言: Shell
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-28 14:56:13
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #SSTI #RCE
📦 项目名称: NordArosa-Enterprise-Security-Lab
👤 项目作者: NordArosa
🛠 开发语言: Shell
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-28 14:56:13
📝 项目描述:
Hands-on penetration testing lab with 15 real-world vulnerability scenarios (SQLi, XSS, LFI, RCE, SSRF, JWT, CSRF, SSTI, XXE, deserialization, LDAP, broken auth). Automated setup on Ubuntu. Attack from Kali. Perfect for OSCP prep, portfolio, or learning OWASP Top 10.🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #SSTI #RCE
📦 项目名称: ssti-vulnerability
👤 项目作者: IAAMJIGSAW
🛠 开发语言: JavaScript
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-21 19:21:57
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #SSTI #RCE
📦 项目名称: ssti-vulnerability
👤 项目作者: IAAMJIGSAW
🛠 开发语言: JavaScript
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-21 19:21:57
📝 项目描述:
无描述🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #SSTI #RCE
📦 项目名称: HTB-Bike-Writeup
👤 项目作者: elmuallem994
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-21 20:40:04
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #SSTI #RCE
📦 项目名称: HTB-Bike-Writeup
👤 项目作者: elmuallem994
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-21 20:40:04
📝 项目描述:
My HackTheBox penetration testing write-ups🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #SSTI #RCE
📦 项目名称: waf-bypass
👤 项目作者: nemesida-waf
🛠 开发语言: Python
⭐ Star数量: 1503 | 🍴 Fork数量: 186
📅 更新时间: 2026-07-20 13:09:00
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #SSTI #RCE
📦 项目名称: waf-bypass
👤 项目作者: nemesida-waf
🛠 开发语言: Python
⭐ Star数量: 1503 | 🍴 Fork数量: 186
📅 更新时间: 2026-07-20 13:09:00
📝 项目描述:
Check your WAF before an attacker does🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #SSTI #RCE
📦 项目名称: ssti_full_shell
👤 项目作者: 0xcybermonk
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-19 17:49:34
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #SSTI #RCE
📦 项目名称: ssti_full_shell
👤 项目作者: 0xcybermonk
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-19 17:49:34
📝 项目描述:
Automated RCE shell for the Esh-Sewa CTF challenge.🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #SSTI #RCE
📦 项目名称: predator-sstimap
👤 项目作者: brahimamirzerbout
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-11 20:24:38
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #SSTI #RCE
📦 项目名称: predator-sstimap
👤 项目作者: brahimamirzerbout
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-11 20:24:38
📝 项目描述:
Blacktrack tool: SSTImap🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #SSTI #RCE
📦 项目名称: House-of-Liquor-
👤 项目作者: Samriddha-Sapkota
🛠 开发语言: HTML
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-09 14:51:02
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #SSTI #RCE
📦 项目名称: House-of-Liquor-
👤 项目作者: Samriddha-Sapkota
🛠 开发语言: HTML
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-09 14:51:02
📝 项目描述:
A deliberately vulnerable Flask web application built on Jinja2 to demonstrate SQL injection and Server-Side Template Injection (SSTI) via nmap, Gobuster, and tplmap to identify and exploit injection flaws.🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #SSTI #RCE
📦 项目名称: CVE-2026-4257
👤 项目作者: dann3xplo1t
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-09 08:19:15
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #SSTI #RCE
📦 项目名称: CVE-2026-4257
👤 项目作者: dann3xplo1t
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-09 08:19:15
📝 项目描述:
CVE-2026-4257 - Contact Form by Supsystic <= 1.7.36 # SSTI to RCE 🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #SSTI #RCE
📦 项目名称: rcekit
👤 项目作者: kabiri-labs
🛠 开发语言: Python
⭐ Star数量: 11 | 🍴 Fork数量: 2
📅 更新时间: 2026-07-08 05:00:36
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #SSTI #RCE
📦 项目名称: rcekit
👤 项目作者: kabiri-labs
🛠 开发语言: Python
⭐ Star数量: 11 | 🍴 Fork数量: 2
📅 更新时间: 2026-07-08 05:00:36
📝 项目描述:
RCEKit — an RCE testing toolkit for authorized security testing. Generate context- and sink-aware payloads across 14 environments, deliver them (Burp/Nuclei export or the built-in --verify harness), and auto-confirm execution — including blind/out-of-band callbacks via the built-in listener.🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #SSTI #RCE
📦 项目名称: Reaper
👤 项目作者: d3xm0s
🛠 开发语言: Ruby
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-07 17:19:21
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #SSTI #RCE
📦 项目名称: Reaper
👤 项目作者: d3xm0s
🛠 开发语言: Ruby
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-07 17:19:21
📝 项目描述:
Pure-Ruby web vulnerability scanner - crawls a target, injects every param/header/JSON field and confirms SSTI/SQLi/XSS/SSRF/XXE/LFI/RCE against each parameter's own baseline. Zero gems. Authorized testing only.🔗 点击访问项目地址
🚨 GitHub 监控消息提醒
🚨 发现关键词: #SSTI #RCE
📦 项目名称: sst1_filt3r_bypass
👤 项目作者: 6876h9
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-07 09:35:02
📝 项目描述:
🔗 点击访问项目地址
🚨 发现关键词: #SSTI #RCE
📦 项目名称: sst1_filt3r_bypass
👤 项目作者: 6876h9
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-07 09:35:02
📝 项目描述:
Server-Side Template Injection (SSTI) exploit for picoCTF 2025 SST1 web exploitation challenge. Demonstrates blacklist bypass techniques and Jinja2 template injection vulnerabilities.🔗 点击访问项目地址