GitHub 红队武器库🚨
14K subscribers
24 photos
8 videos
25.9K links
📦 GitHub 全球红队渗透资源中转站。
​旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
⚠️ 本频道仅供安全研究与授权测试使用。
Download Telegram
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Burp #Extension

📦 项目名称: burp-games
👤 项目作者: enochgitgamefied
🛠 开发语言: Java
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-11 09:59:18

📝 项目描述:
无描述

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC #RCE

📦 项目名称: CVE-2026-41089-Netlogon-RCE-PoC
👤 项目作者: SyntaxMethod
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-11 10:43:55

📝 项目描述:
Description: Unauthenticated Netlogon RCE vulnerability scanner & PoC research for CVE-2026-41089 (CVSS 9.8). Integrated module for AI Security Tool.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #Exploit

📦 项目名称: UEFI-Security-Research-Howyar-SysReturn-NetCopy
👤 项目作者: TheMalwareGuardian
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-11 10:36:15

📝 项目描述:
Post CVE-2024-7344 analysis of Howyar SysReturn NetCopy - reverse engineering notes, vulnerable binaries, vendor correspondence, and proof-of-concept tooling for CVE-2026-79298 (IA-32 Secure Boot bypass via the RxPE custom PE loader in BOOTia32.efi).

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #metadata

📦 项目名称: timmypanel
👤 项目作者: lovetimmy1314
🛠 开发语言: Go
Star数量: 2 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-11 09:45:26

📝 项目描述:
Timmypanel 是自托管的私人网址导航站:登录后把常用网站按分组以卡片形式聚合到首页,多账号数据完全隔离。Go 后端 + Vue 3 前端,前端 embed 进二进制,部署产物就是一个可执行文件加一个 sqlite 文件,也有多架构 Docker 镜像。支持书签批量导入、URL 自动抓取标题图标、bookmarklet、拖拽排序、模糊搜索、公网/内网双地址切换、壁纸明暗模式、中英双语、备份快照。安全上做了 SSRF 建连层防护、上传内容判型、CSRF 自定义头、图标全离线。AGPL-3.0 开源

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #rules

📦 项目名称: YaraHunter-Y
👤 项目作者: irmygmr
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-11 10:30:27

📝 项目描述:
Python ve Streamlit tabanlı YARA ve IOC güvenlik analiz aracı

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #C2 #Command and Control

📦 项目名称: uav-swarm-simulation
👤 项目作者: HaticeKubraUnal
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-11 11:06:32

📝 项目描述:
A real-time Command and Control (C2) simulation platform for autonomous UAV swarms. Built with a decoupled microservices architecture using FastAPI, Redis, PostgreSQL, and WebSockets.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #Stored

📦 项目名称: web-app-security-lab
👤 项目作者: ryj0-1
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-11 10:56:12

📝 项目描述:
Full-stack lab environment (Nginx/Flask/SQLite) demonstrating OWASP Top 10 web vulnerability exploitation (SQLi, Stored XSS, Comand Injection) and practical remediation.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #EXP

📦 项目名称: CVE-2026-85706_docker_exp
👤 项目作者: FlowerWitch
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-11 11:59:58

📝 项目描述:
CVE-2026-85706_docker_exp

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Shellcode #Inject

📦 项目名称: Winx86_64-Process-Injection
👤 项目作者: aghaasfandyarkhan
🛠 开发语言: Rust
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-11 11:59:10

📝 项目描述:
Process Injection is the most stealthy technique that threat actors use for creating thread in existing legitimate process. I dev this prototype to demonstrate how process injection malwares inject their malicious shellcode inside explorer.exe's process.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #malware

📦 项目名称: SecureGuard-Clients
👤 项目作者: Dhruv0306
🛠 开发语言: Rust
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-11 12:01:15

📝 项目描述:
Standalone desktop and Android clients for SecureGuard Antivirus. Rust core (YARA-X + weighted scoring + entropy-based packer detection), no backend dependency, distributed via GitHub Releases only.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #POC

📦 项目名称: nba-gleague-xss-poc
👤 项目作者: the-good-tiger
🛠 开发语言: HTML
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-11 11:30:30

📝 项目描述:
NBA G League block-preview XSS to NBA Identity rendezvous ATO PoC

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #0day #漏洞

📦 项目名称: HDM63
👤 项目作者: dashen666666-gif
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-11 13:01:05

📝 项目描述:
2026: Coruna 漏洞及 DarkSword 零日(0day)最新威胁情报

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #BlueTeam #Response #Detection

📦 项目名称: blueteam-labs
👤 项目作者: CYBERS3CPT
🛠 开发语言: Shell
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-11 12:07:26

📝 项目描述:
Practical blue team lab scripts — one folder per session of the Operational Defensive Cybersecurity specialisation course.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #RCE #Remote Code Execution

📦 项目名称: Mini-Leetcode-Engine
👤 项目作者: muditaKalsan
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-11 12:37:26

📝 项目描述:
A scalable, multi-language remote code execution (RCE) engine built with FastAPI, Redis, Celery, and Docker to evaluate algorithmic problem-solving submissions safely.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: scan-grid
👤 项目作者: gorkemguler
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-11 12:55:52

📝 项目描述:
Distributed authorised vulnerability scanner + asset inventory for Raspberry Pi (orchestrator + worker): nmap scanning, CVE matching via NVD, change detection. Allowlist-enforced.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: cve-2026-22732-poc
👤 项目作者: dylan-chainguard
🛠 开发语言: Shell
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-11 13:16:21

📝 项目描述:
无描述

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Bypass #UAC

📦 项目名称: Zapret-2-GUI
👤 项目作者: TheFirstNoob
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-11 14:02:05

📝 项目描述:
GUI Zapret 2 (winws2 / lua-desync) bypass DPI/TSPU

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Exploit #CVE #POC

📦 项目名称: exploitcode
👤 项目作者: morimori-dev
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-11 14:02:17

📝 项目描述:
Lab-validated proof-of-concept code for publicly disclosed vulnerabilities

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Exploit #POC

📦 项目名称: Modular-Exploit-PoC-Runner
👤 项目作者: MAlkaber
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-11 13:56:07

📝 项目描述:
无描述

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #CVE #metadata

📦 项目名称: strata
👤 项目作者: m0m0x01d
🛠 开发语言: HTML
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-11 13:56:18

📝 项目描述:
See why a web vulnerability works, not just how to trigger it — a single-file, zero-dependency security lab that renders a vulnerable app as a 7-layer cross-section. 17 labs, attacker & defender modes, AI-authorable.

🔗 点击访问项目地址