GitHub 红队武器库🚨
14K subscribers
25 photos
9 videos
26K links
📦 GitHub 全球红队渗透资源中转站。
​旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
⚠️ 本频道仅供安全研究与授权测试使用。
Download Telegram
🚨 GitHub 监控消息提醒

🚨 发现关键词: #C2 #Framework

📦 项目名称: c2-lite
👤 项目作者: ispectr3
🛠 开发语言: Go
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-13 17:59:23

📝 项目描述:
Lightweight C2 framework in Go with encrypted communications and interactive shell

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Nuclei #templates

📦 项目名称: nuclei-recon-templates
👤 项目作者: comradezephyr
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-13 17:34:44

📝 项目描述:
Curated collection of strict, zero-false-positive Nuclei v3 templates for bug bounty automation, infrastructure reconnaissance, and exposure hunting.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: CVE-2026-42536-PoC
👤 项目作者: erberkan
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-13 18:55:41

📝 项目描述:
无描述

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #rules #malware

📦 项目名称: malware-lab
👤 项目作者: samdem-ai
🛠 开发语言: HTML
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-13 18:42:11

📝 项目描述:
A small Python toolkit that turns malware triage notes into clean reports, a browsable IOC dashboard, and YARA rules, with write-ups of some Windows lab samples

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #RCE #CVE

📦 项目名称: metasploitable3-pentest-writeup
👤 项目作者: adfortunato
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-13 18:59:56

📝 项目描述:
Full home-lab penetration test of Rapid7's Metasploitable3 (Ubuntu 14.04) from Parrot OS. Covers recon, manual UNION SQLi, Drupalgeddon (CVE-2014-3704) RCE, SSH credential reuse, privilege escalation to root, and reverse shells. Written as a workable report — feed it back and re-run the whole lab.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: gitread
👤 项目作者: plur1bu5
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-13 19:56:45

📝 项目描述:
CVE-2026-85706 · GitLab CE/EE unauthenticated file read · research PoC with oracle mode, fd enumeration, and tiered loot targeting

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: vulnerability-scanner
👤 项目作者: alwa17
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-13 19:38:06

📝 项目描述:
A Java-based cybersecurity vulnerability scanner that identifies common security weaknesses such as open network ports and missing HTTP security headers, providing users with a clear security report.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSTI #RCE

📦 项目名称: vulnhub-web
👤 项目作者: oxihash
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-13 19:46:13

📝 项目描述:
A chained multi-service vulnerable web app: SSRF into an internal-trust bypass, leaked JWT secret, forged admin auth, and SSTI-to-RCE, fully automated end to end.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #metadata

📦 项目名称: ssrf-lab
👤 项目作者: roshan-amble
🛠 开发语言: TypeScript
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-13 20:01:15

📝 项目描述:
A local attack range and conformance checker for SSRF defenses in HTTP clients: 10 probes, 3 clients, verdicts measured with a canary and a hit counter.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: vulnerability-scanner
👤 项目作者: alwa-17
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-13 20:37:07

📝 项目描述:
A Java-based cybersecurity vulnerability scanner that identifies common security weaknesses such as open network ports and missing HTTP security headers, providing users with a clear security report.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC #Exploit

📦 项目名称: sentric-core
👤 项目作者: Freire007-byte
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-13 21:40:47

📝 项目描述:
Autonomous AI agent with its own crypto identity — hunts CVEs, builds exploit labs, validates vulnerabilities (first public PoC of CVE-2026-86283), trades crypto 24/7 to fund itself. Sentric Research.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Spring #CVE

📦 项目名称: cicd-compass-app
👤 项目作者: sachinthokal
🛠 开发语言: CSS
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-13 22:04:18

📝 项目描述:
CICD Compass is a production-grade educational and reference DevSecOps application built with Spring Boot (Java 21) and an interactive, dark-themed Mission Control Dashboard. It models and visualizes the 6 critical stages of an enterprise CI/CD delivery lifecycle alongside live runtime telemetry probes.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #rules #malware

📦 项目名称: android-malware-yara
👤 项目作者: Khamami13
🛠 开发语言: YARA
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-13 23:06:03

📝 项目描述:
YARA rules + hybrid scanner untuk deteksi keluarga malware APK Android (static analysis)

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Spring #POC

📦 项目名称: transaction-poc
👤 项目作者: henrickdaniel
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-13 23:06:18

📝 项目描述:
POC com alguns exemplos e testes para analisar o comportamento do Spring em relação a transação

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Shellcode #EDR #AV

📦 项目名称: Maldev-C
👤 项目作者: m4n14ck
🛠 开发语言: C
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-13 22:44:55

📝 项目描述:
MalDev-C — Técnicas de desarrollo de malware en C para operadores de Red Team. Inyección de procesos, ejecución de shellcode, hooking de APIs, evasión de AV/EDR, persistencia y fundamentos de C2. WinAPI puro. Sin frameworks. Sin dependencias. Solo C e internals de Windows.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #DOM

📦 项目名称: XSSAM
👤 项目作者: clipsncore911
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-13 23:17:42

📝 项目描述:
XSSAM is a professional XSS Reconnaissance & Validation framework for authorized bug-bounty testing. Featuring an async crawler, JS endpoint mining, and context-aware mutations, it uses Playwright for behavioral validation (sink-hooking) to eliminate false positives. Delivers high-fidelity HTML/JSON reports with proof-of-execution evidence.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #Reflected #DOM

📦 项目名称: HUGINN
👤 项目作者: BeardedVikingTX
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-13 21:36:58

📝 项目描述:
Automated recon & vulnerability discovery suite for authorized security testing. Five scanners — SQLi, XSS, SSRF, Open Redirect, Path Traversal — with 896 payload templates, OOB callback confirmation, and report-ready output. Named for Odin's raven. Speak, and the ravens shall listen.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Bypass #MFA

📦 项目名称: seleniumbase-mcp
👤 项目作者: seleniumbase
🛠 开发语言: Python
Star数量: 7 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-14 01:03:02

📝 项目描述:
SeleniumBase MCP Servers. Browser automation that bypasses anti-bot systems and handles web-scraping.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #rules

📦 项目名称: google-secops-batch-retrohunt
👤 项目作者: hzmndt
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-14 01:06:06

📝 项目描述:
Batch retrohunt orchestrator across hundreds of YARA-L detection rules for Google SecOps using secops-wrapper SDK with concurrency limits and safe alerting controls.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: vulnerability-analysis-tool
👤 项目作者: rufaidaafrin
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-14 01:52:54

📝 项目描述:
Python + Nmap network vulnerability scanner with a GUI, built to learn service detection and CVE analysis workflows.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #钓鱼 #演练

📦 项目名称: PhishSettings-v2.0
👤 项目作者: lalazi-tech
🛠 开发语言: TypeScript
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-14 01:28:38

📝 项目描述:
钓鱼演练-用户端-系统设置

🔗 点击访问项目地址