GitHub 红队武器库🚨
14K subscribers
26 photos
10 videos
25.6K links
📦 GitHub 全球红队渗透资源中转站。
​旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
⚠️ 本频道仅供安全研究与授权测试使用。
Download Telegram
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #Reflected

📦 项目名称: Penetration-Testing-Project
👤 项目作者: oarabengkhunou-source
🛠 开发语言: PHP
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-07 13:41:23

📝 项目描述:
Ethical web application security testing project demonstrating SQL injection and reflected XSS vulnerabilities in an isolated lab environment.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #POC #Stored

📦 项目名称: fashion-shop-security-lab
👤 项目作者: hieujojo
🛠 开发语言: TypeScript
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-07 11:41:26

📝 项目描述:
Deliberately vulnerable fashion e-commerce web app (FashionHub) for hands-on security testing.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Nuclei #template

📦 项目名称: UpdateNucleiTemplates
👤 项目作者: MarkBMoss
🛠 开发语言: Python
Star数量: 2 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-07 13:30:12

📝 项目描述:
每日自动收集全网可用 Nuclei Template

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #Stored

📦 项目名称: Argus_Assessment
👤 项目作者: nyx007-code
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-07 14:46:47

📝 项目描述:
Black-box penetration test of a PHP internal management system. Identified 5 vulnerabilities: Critical SQL injection with query disclosure, stored XSS with session cookie theft, IDOR across client data, path traversal, and unrestricted file upload. Includes evidence, CVSS scores, remediation.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Afrog #POC #漏洞

📦 项目名称: DistributedAfrog
👤 项目作者: wffwf
🛠 开发语言: HTML
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-07 09:19:44

📝 项目描述:
Afrog Distributed Master

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: bobscan
👤 项目作者: Xuxu1020
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-07 14:52:31

📝 项目描述:
Web vulnerability scanner

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #Exploit

📦 项目名称: CVE-2026-11991-Exploit
👤 项目作者: 0x00phantom-hat
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-07 15:57:49

📝 项目描述:
无描述

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #漏洞 #扫描

📦 项目名称: vuln-scan-agent
👤 项目作者: bear561
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-07 16:05:47

📝 项目描述:
漏洞扫描智能体

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #rules #malware

📦 项目名称: Malware-Analysis-Portfolio
👤 项目作者: R3DN1GHT2005
🛠 开发语言: YARA
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-07 16:02:10

📝 项目描述:
End-to-end malware analysis reports, extracted IOCs, and custom YARA detection rules developed in an isolated lab (FLARE-VM / REMnux). Includes WannaCry, trojans, and malscripts.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #rules #malware

📦 项目名称: yara-rules
👤 项目作者: ilyas7
🛠 开发语言: YARA
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-07 16:00:18

📝 项目描述:
This repository contains my detection rules for all kinds of malware and suspicious software.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #C2 #Framework

📦 项目名称: AndroidPentest-Framework
👤 项目作者: UsamaMatrix
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-07 16:56:15

📝 项目描述:
Professional-grade modular Android 12+ penetration testing framework — 10 modules: Recon, Payload, Installer, C2, PrivEsc, Persistence, Exfiltration, MITM, Automation, Reporting

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Log4j #CVE

📦 项目名称: m5-log4shell-demo
👤 项目作者: aureliusgovenai
🛠 开发语言: Java
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-07 14:19:29

📝 项目描述:
Aurelius M5 demo — Maven project with a deliberately outdated log4j-core for the log4shell-bump patch runner to fix

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Log4j #CVE

📦 项目名称: transdep-demo-app
👤 项目作者: siddharthoak
🛠 开发语言: Java
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-07 10:33:18

📝 项目描述:
Demo: leaf app depending on transdep-demo-service-lib (2 hops from a vulnerable log4j-core dep in transdep-demo-util-common). Test target for the transitive-dependency gap in vuln-remediation-agent.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #Stored

📦 项目名称: bifrost-xss-disclosure
👤 项目作者: ChristopherPatrickKuntz
🛠 开发语言: Shell
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-07 16:24:08

📝 项目描述:
Bifrost Finance — stored XSS via backend database leading to one-click wallet drain. Submitted via Immunefi.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: CVE-2026-34975
👤 项目作者: romain-deperne
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-07 17:44:26

📝 项目描述:
CRLF email header injection in Plunk raw MIME construction — CVE-2026-34975 / CVSS 8.5

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: CVE-2026-34940
👤 项目作者: romain-deperne
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-07 17:44:25

📝 项目描述:
OS command injection in KubeAI via an Ollama model URL — CVE-2026-34940 / CVSS 8.7

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #CVE

📦 项目名称: CVE-2026-33715
👤 项目作者: romain-deperne
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-07 17:44:21

📝 项目描述:
Unauthenticated SSRF and open email relay in Chamilo LMS — CVE-2026-33715 / CVSS 7.2

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #POC

📦 项目名称: week-4-websec-w01-advanced
👤 项目作者: itsmariamfatima
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-07 17:27:23

📝 项目描述:
PortSwigger Web Security Academy — Advanced Track. Hands-on exploitation of SSRF, Insecure Deserialization, and SSTI, with full PDF report and PoC screenshots.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #RCE #CVE

📦 项目名称: cpanel-whm-authbypass-to-rce
👤 项目作者: bright77777
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-07 16:45:59

📝 项目描述:
无描述

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: android-application-penetration-testing
👤 项目作者: sravanibandreddy
🛠 开发语言: HTML
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-07 17:48:25

📝 项目描述:
Android Security Assessment and SAST Vulnerability Scanner based on OWASP MASVS & Mobile Top 5

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Burp #Extension

📦 项目名称: zap-ghostjs
👤 项目作者: ArkhaMahn
🛠 开发语言: Java
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-07 17:45:58

📝 项目描述:
GhostJS — ZAP add-on that passively scans JavaScript responses for hard-coded secrets and discovers API endpoints, source maps, and cloud-storage URLs (port of Ghost-Js-Burp-Extension).

🔗 点击访问项目地址