GitHub 红队武器库🚨
14.1K subscribers
25 photos
8 videos
26.1K links
📦 GitHub 全球红队渗透资源中转站。
​旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
⚠️ 本频道仅供安全研究与授权测试使用。
Download Telegram
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #Exploit

📦 项目名称: ad-autopwn
👤 项目作者: jonaslejon
🛠 开发语言: Python
Star数量: 84 | 🍴 Fork数量: 16
📅 更新时间: 2026-09-14 19:57:03

📝 项目描述:
AD AutoPwn v4.13.0 — automated AD attack chain, zero-auth to Domain Admin. Discover/Kerberoast/AS-REP/AD CS ESC1-16/Shadow Creds/RBCD+KCD/Ghost-SPN/TGS-rewrite/Dollar-Ticket/WPAD/WSUS/PXE/SCCM/BloodHound auto-action/Loot/DCSync/DPAPI + Synacktiv 2026 reflection (CVE-2025-58726/2026-24294/2026-26128). Authorized pentesting only.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: SaadStrike
👤 项目作者: championsaad786-dev
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-14 20:37:02

📝 项目描述:
💀 Advanced Web Vulnerability Scanner & Exploit Toolkit | WAF Detection, SQLi/XSS Fuzzer, Payload Generator | Red Team Utility

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #Stored

📦 项目名称: ILEAPP-Stored-XSS
👤 项目作者: blue0x1
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-14 20:58:41

📝 项目描述:
iLEAPP Stored XSS in SMS/iMessage Chat HTML Report

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Bypass #MFA

📦 项目名称: mfa-bypass-detection
👤 项目作者: Ranallkolo
🛠 开发语言: Python
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-14 21:07:48

📝 项目描述:
AI-driven MFA bypass detection framework using Random Forest + LSTM fusion. Targets SIM swap, AiTM phishing, session hijacking, and MFA fatigue. FastAPI dashboard.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: CVE-2026-25057
👤 项目作者: ustr
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-14 21:58:09

📝 项目描述:
PoC for CVE-2026-25057

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Nuclei #template #CVE

📦 项目名称: exact-surface
👤 项目作者: whxitte
🛠 开发语言: Python
Star数量: 5 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-14 19:52:39

📝 项目描述:
Open-source, self-hosted external attack-surface management (EASM). Continuous discovery + 28 detection modules, the exact request behind every finding, and a visual Playground. Detection only.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #Exploit

📦 项目名称: aquos-r6-ghostlock
👤 项目作者: mouseos
🛠 开发语言: C
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-14 23:25:42

📝 项目描述:
Temporary root exploit for Sharp AQUOS R6 A101SH S0029 using GhostLock CVE-2026-43499

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #metadata

📦 项目名称: nyxeara
👤 项目作者: Nyxeara
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-15 00:02:31

📝 项目描述:
DAST platform with WAF detection/evasion, OAST, SARIF 2.1.0, workflow automation, and cryptographically verified per-finding evidence. 22 check families, 22 tool integrations, evidence-first verification.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #Exploit

📦 项目名称: CVE-2026-69328
👤 项目作者: 0xf9b6a41ec
🛠 开发语言: C
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-15 00:15:49

📝 项目描述:
无描述

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Docker #POC

📦 项目名称: AutoQ-Guard
👤 项目作者: tbvjqlqlaqkq-coder
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-15 01:59:46

📝 项目描述:
Automotive quality-risk and recall early-warning PoC with LOT/VIN traceability, ROI simulation, RBAC and privacy controls.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #漏洞 #扫描

📦 项目名称: scop-ai-review
👤 项目作者: yeeqen00111
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-15 01:43:54

📝 项目描述:
AI 代码评审 Agent——扫描本地 Git 仓库,全量多维审核(安全/漏洞/Bug/规范/性能),异步任务 API,输出 Markdown 报告与改进对比。Python 3.11 · FastAPI · DeepSeek

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #rules

📦 项目名称: Detection_rules
👤 项目作者: bb-chani
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-15 01:46:11

📝 项目描述:
YARA and Sigma detection rules

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Nuclei #template

📦 项目名称: TodoApp-Nuclei
👤 项目作者: priyanshisoni14
🛠 开发语言: TypeScript
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-15 01:01:45

📝 项目描述:
无描述

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SQL注入 #漏洞

📦 项目名称: sql-inject-demo
👤 项目作者: dxiangwiki
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-15 03:02:22

📝 项目描述:
SQL注入教学演示,对比字符串拼接漏洞与参数化查询防御。Node+Express+MySQL,含3个标签页与滑动开关。

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #0day #POC

📦 项目名称: Godot-0day-UNIX-OS-Command-Injection
👤 项目作者: SAAITAAMAA
🛠 开发语言: Unknown
Star数量: 2 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-15 02:08:11

📝 项目描述:
Godot 0day : OS Command Injection

🔗 点击访问项目地址
TG必备的搜索引擎,快搜kuai帮你发现有趣群组、频道、视频、音乐、电影、新闻 | Find cool stuff all in one bot!

机器人:@kuai @kuaia @kuaiaa

👉 https://t.me/kuai?start=a_3URZVD0
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #Exploit #RCE

📦 项目名称: CVE-2026-48907
👤 项目作者: NONAME-ELV
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-15 05:54:13

📝 项目描述:
无描述

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #漏洞 #扫描

📦 项目名称: SDL
👤 项目作者: evilthan9
🛠 开发语言: Python
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-15 04:09:57

📝 项目描述:
面向合规的漏洞管理系统的设计与实现

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #Stored

📦 项目名称: Web-Cache-Poisoning-Lab
👤 项目作者: ManuelKy08
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-15 05:40:44

📝 项目描述:
Web Cache Poisoning & Cache Deception Lab - 4 real vector: web cache deception (css padding) bocorkan profil privat, poison 302 via unkeyed Host, unkeyed X-Forwarded-Host -> stored XSS massal, refleksi query param unkeyed. Flask + cache in-memory + endpoint curl, toggle RENTAN/FIXED, Docker. Localhost only.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #钓鱼 #二维码

📦 项目名称: FishingFun
👤 项目作者: kenton1215
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-14 23:51:02

📝 项目描述:
钓鱼爱好者与水族爱好者的分享、学习、展示与消费一体化平台

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #反序列化 #Fastjson #Shiro #漏洞

📦 项目名称: Lyrasuite
👤 项目作者: testitok
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-12 15:28:58

📝 项目描述:
Java 安全利用链生成器 & JNDI 服务 — 集成多种反序列化利用链、JNDI 注入、Shiro/Fastjson/SnakeYAML 漏洞利用的综合工具

🔗 点击访问项目地址