GitHub 红队武器库🚨
14.1K subscribers
25 photos
9 videos
26.5K links
📦 GitHub 全球红队渗透资源中转站。
​旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
⚠️ 本频道仅供安全研究与授权测试使用。
Download Telegram
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC #RCE

📦 项目名称: xss2shell-poc
👤 项目作者: madfxr
🛠 开发语言: Python
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-21 22:57:35

📝 项目描述:
XSS2Shell: WordPress Preauth XSS to RCE Chain (CVE-2026-64638)

🔗 点击访问项目地址
👍1
🚨 GitHub 监控消息提醒

🚨 发现关键词: #RCE #POC

📦 项目名称: click2shell-poc
👤 项目作者: madfxr
🛠 开发语言: Python
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-21 22:57:32

📝 项目描述:
Click2Shell: Preauth WordPress Core Theme Preview Injection to RCE Chain

🔗 点击访问项目地址
👍1
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Exploit #CVE #RCE #POC

📦 项目名称: ArchiveBox-RCE-Exploit-CVE-XSS-to-Command-Injection-CVSS-10.0
👤 项目作者: FUNFACTOR1
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-21 23:07:56

📝 项目描述:
Indirect Prompt Injection to RCE (CVSS 10.0) — XSS primitive escalates to arbitrary command execution via AI agent. CAN-2026-2036559. Full exploit chain. PoC advisory.

🔗 点击访问项目地址
👍1
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC #RCE

📦 项目名称: CVE-2026-41089-Netlogon-RCE-PoC
👤 项目作者: Gillarchnganasan2735
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-21 23:20:57

📝 项目描述:
Automate Netlogon CVE-2026-41089 validation and defensive testing through integrated AI security workflows, enabling rapid risk assessment and mitigation verification.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: POC-CVE-2026-93680
👤 项目作者: rmhowe425
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-21 23:18:34

📝 项目描述:
无描述

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: coactionbrittlemaidenhair51.github.io
👤 项目作者: coactionbrittlemaidenhair51
🛠 开发语言: HTML
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-21 23:17:35

📝 项目描述:
Explore and validate CVE-2026-42978 PoC with an integrated AI security tool, multi-protocol terminal, and autonomous agent suite for Windows Push Notifications.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC #Exploit

📦 项目名称: CVE-2026-42978-PoC-Research
👤 项目作者: coactionbrittlemaidenhair51
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-21 23:16:17

📝 项目描述:
Exploit and analyze CVE-2026-42978 with a Windows Push Notifications module for AI security, multi-protocol terminal, and autonomous agent suite.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #rules #malware

📦 项目名称: Malware-Analysis-Reverse-Engineering-Lab
👤 项目作者: nolo5x
🛠 开发语言: YARA
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-22 01:01:22

📝 项目描述:
Hands-on malware analysis and reverse engineering lab using YARA, Sigma, Ghidra, PEStudio, Detect It Easy, and Wireshark to perform static analysis, extract IOCs, develop detection rules, and document findings in an isolated Windows environment.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: Net-Sentry
👤 项目作者: bangladeshcyberspectre
🛠 开发语言: Shell
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-22 01:01:30

📝 项目描述:
**NetSentry** — A lightweight, dependency-free Bash port & vulnerability scanner. Checks a target host against common exploited ports (FTP, SSH, Telnet, SMB, RDP, VNC, etc.), grabs service banners, and reports open ports with security notes. Built for authorized network audits only — detects and reports, never exploits.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: POC-CVE-2026-93674
👤 项目作者: rmhowe425
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-22 01:54:51

📝 项目描述:
无描述

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #Reflected

📦 项目名称: Day-22--Reflected-Cross-Site-Scripting-XSS-in-HTML-Context
👤 项目作者: itzumaz
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-22 01:52:41

📝 项目描述:
Reflected Cross-Site Scripting (XSS) in HTML Context

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #rules

📦 项目名称: loki
👤 项目作者: Impeded-seth4314
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-22 02:05:26

📝 项目描述:
Automate, monitor, and secure your infrastructure with Loki Agent—the lightweight DevOps copilot that streamlines workflows and boosts deployment efficiency.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #漏洞 #复现

📦 项目名称: WebSafetyAttack-DefensePlatform
👤 项目作者: X1ngHe159
🛠 开发语言: Unknown
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-22 02:54:26

📝 项目描述:
面向教学场景的轻量化Web安全攻防实训平台,集成常见Web漏洞复现环境与基础防护验证模块,适合课程作业、新手入门安全攻防实操练习。

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Nuclei #templates

📦 项目名称: mcp-netscan
👤 项目作者: nullable-eth
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-21 22:21:45

📝 项目描述:
Network recon & vulnerability-scanning MCP server for the Whitehorse cluster agent (nmap/nuclei/sslscan; detection only)

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #Exploit #RCE

📦 项目名称: CVE-2026-91097-CVE-2026-91106
👤 项目作者: Nxploited
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-22 04:58:08

📝 项目描述:
HPLIP < 3.26.6 — Full admin takeover via PAPPL web interface (no auth). Related to CVE-2026-91097 through CVE-2026-91106 (CVSS 9.3)

🔗 点击访问项目地址
👍1
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: cve-2026-28576
👤 项目作者: Aayushbankar
🛠 开发语言: Java
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-22 04:23:21

📝 项目描述:
CVE-2026-28576 (GHSA-ph86-9mcx-3p6r) — Android Contacts Provider SQL Injection via targetSdk-gated ENFORCE_STRICT_SQL_CHECKS. Zero-permission boolean-oracle PoC + Red Team app with consent-gated dashboard exfiltration.

🔗 点击访问项目地址
👍1
🚨 GitHub 监控消息提醒

🚨 发现关键词: #云安全 #AK

📦 项目名称: cloud-competition-prep
👤 项目作者: CZC-Max
🛠 开发语言: HCL
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-22 03:03:41

📝 项目描述:
世界技能大赛云计算项目备赛 · Terraform IaC 模板 + 安全加固脚本 + 排错记录

🔗 点击访问项目地址
👍1
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #metadata

📦 项目名称: ai-job-gateway
👤 项目作者: Furkiozknn
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-22 04:53:25

📝 项目描述:
The async job contract fal.ai, Black Forest Labs and RunPod each arrived at independently, as one hardened reference server: submit, poll, webhook. Idempotency keys that survive a restart, SSRF-guarded signed webhooks, and expiry as a status you can read rather than a silent 404. 156 tests.

🔗 点击访问项目地址
👍1
🚨 GitHub 监控消息提醒

🚨 发现关键词: #渗透测试 #漏洞

📦 项目名称: prs-plugin-legacy
👤 项目作者: raystyle
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-22 04:18:35

📝 项目描述:
pentest_rs(agent plugin 层):五域 skill(资产侦察/漏洞扫描/漏洞利用/后渗透操作/攻击产物分析)+ rs-scripting 创作技能,教 agent 使用并按需编写沉淀 rust-script 脚本。执行层在 raystyle/prs_workspace(pdt = Pentest Development Toolkit)。仅限合法授权测试。

🔗 点击访问项目地址
👍1
🚨 GitHub 监控消息提醒

🚨 发现关键词: #漏洞 #POC #扫描 #利用 #CVE

📦 项目名称: deepopen
👤 项目作者: Ms-liyc
🛠 开发语言: Python
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-22 03:37:05

📝 项目描述:
代码检测漏洞工具

🔗 点击访问项目地址
👍1
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: web-vulnerability-scanner
👤 项目作者: jigyasagarg08
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-22 05:01:29

📝 项目描述:
A Python-based web vulnerability scanner for authorized security assessment and automated detection of common web application security issues.

🔗 点击访问项目地址
👍2