GitHub 红队武器库🚨
14.1K subscribers
25 photos
8 videos
26.1K links
📦 GitHub 全球红队渗透资源中转站。
​旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
⚠️ 本频道仅供安全研究与授权测试使用。
Download Telegram
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: python-vulnerability-scanner
👤 项目作者: GabrielGhedin
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-14 15:03:26

📝 项目描述:
Safety-first Python vulnerability scanner for authorized private lab environments.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: wordfence-cli
👤 项目作者: wordfence
🛠 开发语言: Python
Star数量: 157 | 🍴 Fork数量: 34
📅 更新时间: 2026-09-14 15:01:36

📝 项目描述:
Wordfence malware and vulnerability scanner command line utility.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: CVE-2026-60004-PoC
👤 项目作者: erberkan
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-14 15:57:00

📝 项目描述:
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #渗透测试 #漏洞

📦 项目名称: pentest_portfolio
👤 项目作者: Y3128
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-14 15:35:32

📝 项目描述:
这是一个在补天SRC上进行授权漏洞挖掘的实战作品集,包含渗透测试方法论、完整实战流程、报告提交和零基础教学 This is a hands-on portfolio for authorized vulnerability hunting on Butian SRC, including penetration testing methodology, a complete real-world workflow, report submission, and beginner-friendly training

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Burp #插件

📦 项目名称: burp-passive-scan
👤 项目作者: ZYM-X
🛠 开发语言: Java
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-14 15:32:03

📝 项目描述:
基于 Burp Montoya API 的被动扫描插件:4 条检测规则,自动识别敏感路径暴露、明文口令传输、CORS 误配、可疑调试参数

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #Reflected

📦 项目名称: TBH-XSS
👤 项目作者: TulungagungBlackHat
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-14 16:55:23

📝 项目描述:
💉 TBH-XSS - Reflected XSS Detector | Bug Bounty | JSON | Safe Payload

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #Reflected

📦 项目名称: Automation
👤 项目作者: akkamble90
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-14 16:50:17

📝 项目描述:
An automated Web Security Testing (DAST) framework built with Python, Selenium, and pytest using the Page Object Model (POM). Automates vulnerability audits for OWASP Top 10 flaws (Reflected XSS & Auth brute-force) with OWASP ZAP proxy routing and CI/CD reporting.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #CVE #metadata

📦 项目名称: CVE-2026-86259
👤 项目作者: uziii2208
🛠 开发语言: TypeScript
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-14 16:56:08

📝 项目描述:
OpenMAIC 1.0.0: Unauthenticated Outbound SSRF to Cloud Metadata Service via Fail-Open Middleware and Environment-Gated Validation Bypass

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #漏洞 #POC #扫描 #复现 #利用

📦 项目名称: Xloom
👤 项目作者: do-whilefor
🛠 开发语言: TypeScript
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-14 16:22:23

📝 项目描述:
基于Pi内核的双Agent的漏洞挖掘工具,主打极简复用Pi的四个工具,一个负责元认知,一个负责执行

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #漏洞 #扫描 #Nuclei

📦 项目名称: SnowEdge
👤 项目作者: HooXuefeng
🛠 开发语言: Python
Star数量: 4 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-14 15:57:08

📝 项目描述:
SnowEdge 是面向个人使用的授权安全评估工作台,将资产、请求、漏洞与证据集中管理,并通过 AI 辅助研判和工具联动,减少测试过程中反复切换工具、整理结果的负担。

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #0day #POC

📦 项目名称: gamestore-CVE-0DAY
👤 项目作者: makaf01
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-14 10:16:28

📝 项目描述:
Injection via `%username%` in Store Command Execution — GameStores Plugin

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #应急响应 #取证 #Webshell

📦 项目名称: hw_toolkit
👤 项目作者: GoghOrz
🛠 开发语言: Shell
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-14 16:40:30

📝 项目描述:
Linux 应急响应一键排查脚本 — 28 个模块,只检测不处置,一份完整报告 + 疑似清单 + 简报

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #Exploit

📦 项目名称: CVE-2026-61797
👤 项目作者: itres-labs
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-14 19:11:41

📝 项目描述:
Proof of Concept for CVE-2026-61797, a time-based blind SQL Injection vulnerability affecting the GLPI PDF plugin.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #Exploit

📦 项目名称: ghostlock-sabrina
👤 项目作者: k-o-n-t-o-r
🛠 开发语言: C
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-14 20:16:21

📝 项目描述:
CVE-2026-43499 GhostLock root exploit for Chromecast with Google TV (sabrina)

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #Exploit

📦 项目名称: ad-autopwn
👤 项目作者: jonaslejon
🛠 开发语言: Python
Star数量: 84 | 🍴 Fork数量: 16
📅 更新时间: 2026-09-14 19:57:03

📝 项目描述:
AD AutoPwn v4.13.0 — automated AD attack chain, zero-auth to Domain Admin. Discover/Kerberoast/AS-REP/AD CS ESC1-16/Shadow Creds/RBCD+KCD/Ghost-SPN/TGS-rewrite/Dollar-Ticket/WPAD/WSUS/PXE/SCCM/BloodHound auto-action/Loot/DCSync/DPAPI + Synacktiv 2026 reflection (CVE-2025-58726/2026-24294/2026-26128). Authorized pentesting only.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: SaadStrike
👤 项目作者: championsaad786-dev
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-14 20:37:02

📝 项目描述:
💀 Advanced Web Vulnerability Scanner & Exploit Toolkit | WAF Detection, SQLi/XSS Fuzzer, Payload Generator | Red Team Utility

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #Stored

📦 项目名称: ILEAPP-Stored-XSS
👤 项目作者: blue0x1
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-14 20:58:41

📝 项目描述:
iLEAPP Stored XSS in SMS/iMessage Chat HTML Report

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Bypass #MFA

📦 项目名称: mfa-bypass-detection
👤 项目作者: Ranallkolo
🛠 开发语言: Python
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-14 21:07:48

📝 项目描述:
AI-driven MFA bypass detection framework using Random Forest + LSTM fusion. Targets SIM swap, AiTM phishing, session hijacking, and MFA fatigue. FastAPI dashboard.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: CVE-2026-25057
👤 项目作者: ustr
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-14 21:58:09

📝 项目描述:
PoC for CVE-2026-25057

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Nuclei #template #CVE

📦 项目名称: exact-surface
👤 项目作者: whxitte
🛠 开发语言: Python
Star数量: 5 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-14 19:52:39

📝 项目描述:
Open-source, self-hosted external attack-surface management (EASM). Continuous discovery + 28 detection modules, the exact request behind every finding, and a visual Playground. Detection only.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #Exploit

📦 项目名称: aquos-r6-ghostlock
👤 项目作者: mouseos
🛠 开发语言: C
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-14 23:25:42

📝 项目描述:
Temporary root exploit for Sharp AQUOS R6 A101SH S0029 using GhostLock CVE-2026-43499

🔗 点击访问项目地址