GitHub 红队武器库🚨
14K subscribers
25 photos
8 videos
25.9K links
📦 GitHub 全球红队渗透资源中转站。
​旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
⚠️ 本频道仅供安全研究与授权测试使用。
Download Telegram
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #Exploit

📦 项目名称: CVE-2026-89013
👤 项目作者: Faceless0x7
🛠 开发语言: Python
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-11 22:49:48

📝 项目描述:
CVE-2026-89013 Exploit — Authorization bypass in Dolibarr via the hashp parameter, enabling unauthenticated access to protected documents and files.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #Exploit

📦 项目名称: CVE-2026-89012
👤 项目作者: Faceless0x7
🛠 开发语言: Python
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-11 22:49:43

📝 项目描述:
CVE-2026-89012 Exploit — SQL filter denylist bypass in Dolibarr via case-insensitive SQL column resolution and case-sensitive denylist matching.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #C2 #Framework

📦 项目名称: jocky
👤 项目作者: A73r0id
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-11 23:48:52

📝 项目描述:
JOCKY - forensic scripting framework that runs without triggering security solutions (SIH 2026, PS SIH26148, NTRO). Custom language, polymorphic bytecode, native Rust VM, C2 fabric.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #RCE

📦 项目名称: CVE-2026-21858-n8n-FullChain
👤 项目作者: ZeroDayEvil
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-12 00:10:10

📝 项目描述:
🛡️ Official AI Security Tool module for CVE-2026-21858 + CVE-2025-68613 (n8n "Ni8mare" Unauthenticated Arbitrary File Read & Expression Injection RCE Full Chain).

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #DOM

📦 项目名称: domxss_hunter
👤 项目作者: legacy-so
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-12 01:00:10

📝 项目描述:
Static and dynamic JavaScript analyzer for detecting DOM-based XSS sources and dangerous sinks in web applications.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: webhunter
👤 项目作者: jmsD3v
🛠 开发语言: Python
Star数量: 1 | 🍴 Fork数量: 1
📅 更新时间: 2026-09-12 01:35:42

📝 项目描述:
P-02 | OWASP Top 10 web vulnerability scanner with AI-powered exploit suggestions

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #rules

📦 项目名称: ATR-to-Yara-L-Converter
👤 项目作者: ajaynyayapathi
🛠 开发语言: Python
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-12 01:57:05

📝 项目描述:
Converts ATR Rules to Google SecOps Yara-L Rules

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #rule #rules #malware

📦 项目名称: security-suite-dashboard
👤 项目作者: gocar112
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-12 01:51:41

📝 项目描述:
YARA-backed SOC detector with a live dashboard: real-time file monitoring, time-windowed auth telemetry correlation, and in-place triage. Stdlib-only server.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #rules #malware

📦 项目名称: malwarescope
👤 项目作者: jmsD3v
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-12 02:55:32

📝 项目描述:
F-02 | Static malware analyzer — PE analysis, YARA-lite rules, entropy, IOC extraction, AI verdict

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #漏洞 #复现

📦 项目名称: vuln-campus-cms
👤 项目作者: shayebuhui23
🛠 开发语言: PHP
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-12 02:33:17

📝 项目描述:
PHP + MySQL Web 安全教学靶场,包含 8 个典型 Web 漏洞、漏洞复现、修复版本及渗透测试报告。

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: ClzProject
👤 项目作者: Rahul-Das2
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-12 03:07:39

📝 项目描述:
A web-based Network Vulnerability Scanner built with Python, Streamlit, Nmap, and MariaDB. It scans networks for open ports and running services, stores scan results, and presents security information through a simple, user-friendly interface for educational purposes.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #C2 #Framework #Beacon

📦 项目名称: c2
👤 项目作者: guguguc
🛠 开发语言: C++
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-12 04:48:21

📝 项目描述:
无描述

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #rule

📦 项目名称: Google-Cloud-Professional-Security-Operations-Engineer-Study-Guide-Notes-2026-
👤 项目作者: sifatnotes
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-12 05:27:07

📝 项目描述:
Complete, practical Google Cloud Professional Security Operations Engineer study guide. Features YARA-L detection rule engineering, Google SecOps (SIEM/SOAR) setups, Security Command Center architecture, hands-on labs, a 30-day study roadmap, and exam voucher tips.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #rule

📦 项目名称: gcp-professional-security-operations-engineer-study-guide
👤 项目作者: sifatnotes
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-12 05:22:40

📝 项目描述:
Complete, practical Google Cloud Professional Security Operations Engineer study guide. Features YARA-L detection rule engineering, Google SecOps (SIEM/SOAR) setups, Security Command Center architecture, hands-on labs, a 30-day study roadmap, and exam voucher recommendations.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #NTLM Relay #AD

📦 项目名称: mitm6-ipv6-ad-attack
👤 项目作者: mehedi-hasan-sami98
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-12 05:36:19

📝 项目描述:
IPv6 DNS takeover & NTLM relay attack chain in Active Directory using mitm6 — covering DHCPv6 spoofing, LDAP/LDAPS relay, passback attacks, and blue-team defenses.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: Agent-of-Death
👤 项目作者: Deaths-Head-Software
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-12 07:43:51

📝 项目描述:
Agent of Death is an AI powered AI Agent vulnerability scanner.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #渗透测试 #漏洞

📦 项目名称: dsh-pentest
👤 项目作者: baianquanzu
🛠 开发语言: JavaScript
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-12 07:52:40

📝 项目描述:
可恢复的 DSH 渗透测试模式:资产归档、证据复核、断点续跑与 Web 可视化

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Bypass #MFA

📦 项目名称: Cyber-Range-Lab
👤 项目作者: DarthWakamiya
🛠 开发语言: JavaScript
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-12 08:03:34

📝 项目描述:
Self-contained Red vs Blue cyber range lab simulating a Cookie Reuse & MFA Bypass vulnerability (XSS session replay) with full attack telemetry for Blue Team forensics.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Exploit #CVE

📦 项目名称: AI-exploit-CVE
👤 项目作者: J-Dheeraj
🛠 开发语言: Python
Star数量: 2 | 🍴 Fork数量: 1
📅 更新时间: 2026-09-12 08:02:07

📝 项目描述:
Experimentation

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #Stored

📦 项目名称: red-blue-ctf-lab
👤 项目作者: christopherbaptista
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-12 09:03:56

📝 项目描述:
Red vs. Blue CTF lab: stored XSS → cookie theft → MFA bypass via session replay, with Blue Team log forensics. Dockerized, single-VM deployment.

🔗 点击访问项目地址