GitHub 红队武器库🚨
14.2K subscribers
26 photos
10 videos
26.7K links
​📦 GitHub 全球红队渗透资源中转站。
​旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
​⚠️ 本频道仅供安全研究与授权测试使用。
Download Telegram
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #DOM

📦 项目名称: foster-parser
👤 项目作者: Robert-Doe
🛠 开发语言: HTML
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-23 07:51:32

📝 项目描述:
HTML5 parser internals from scratch: insertion modes, the stack of open elements, the foster-parenting algorithm, and how it enables mutation XSS.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #BlueTeam #Detection

📦 项目名称: chainsaw
👤 项目作者: WithSecureOpenSource
🛠 开发语言: Rust
⭐ Star数量: 3670 | 🍴 Fork数量: 306
📅 更新时间: 2026-09-23 08:01:09

📝 项目描述:
Rapidly Search and Hunt through Windows Forensic Artefacts

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSTI #RCE

📦 项目名称: SuperSecretTip-TryHackMe-Walkthrough
👤 项目作者: anurag-rvnkr1
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-23 07:35:28

📝 项目描述:
Professional TryHackMe SuperSecretTip walkthrough covering source-code disclosure, XOR secret reconstruction, SSTI, RCE, Linux lateral movement, PATH hijacking, cron abuse, and root-context curl configuration exploitation. Flags redacted for portfolio-safe documentation.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: heretix-cli
👤 项目作者: TITeee
🛠 开发语言: Go
⭐ Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-23 07:46:08

📝 项目描述:
Vulnerability scanner CLI: scans OS packages (RPM, DPKG, APK), OSS dependencies (PyPI, npm/yarn/pnpm, Go, Composer, Maven, Gradle, JAR), and Docker images for known CVEs via the heretix API, emits CycloneDX SBOMs, and flags supply-chain attacks (dependency confusion, malicious installs, CI/CD poisoning).

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #C2 #Framework

📦 项目名称: C2R2-v2
👤 项目作者: G4sp4rCS
🛠 开发语言: Rust
⭐ Star数量: 3 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-23 07:46:43

📝 项目描述:
A modular offensive security framework written in Rust, designed for authorized penetration testing and red team operations.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Exploit #CVE #POC

📦 项目名称: DYNAMIC-DATA-UPDATES-AND-WEIGHT-OPTIMIZATION-FOR-PREDICTING-VULNERABILITY-EXPLOITABILITY
👤 项目作者: sounthararajan2
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-23 09:56:59

📝 项目描述:
This project proposes a novel framework for predicting vulnerability exploitability using dynamic datasets and optimized scoring mechanisms.

🔗 点击访问项目地址
👍1
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #POC #Stored

📦 项目名称: wordpress-7.1-comment-stored-xss
👤 项目作者: Federico1976
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-23 09:46:55

📝 项目描述:
Studio tecnico e PoC della Stored XSS non autenticata nei commenti di WordPress 7.1, corretta in WordPress 7.1.1.

🔗 点击访问项目地址
👍2
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Burp #Extension

📦 项目名称: Burp-Save-Item-XML-Importer
👤 项目作者: 0xBrAinsTorM
🛠 开发语言: Java
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-23 10:29:29

📝 项目描述:
Burp Suite extension for importing saved Request/Response XML items back into the Site Map.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC #RCE #Nuclei

📦 项目名称: CVE-2026-87902
👤 项目作者: Hassham1
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-23 11:54:01

📝 项目描述:
WordPress Core <= 7.1.1 unauthenticated LFI to RCE - validation lab, PoC, nuclei template (GHSA-7hp8-65ch-5whp)

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #rules #malware

📦 项目名称: Malware_Detector-YARA_Rules-
👤 项目作者: MonicaMuthu
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-23 12:04:09

📝 项目描述:
无描述

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: MicroTrick
👤 项目作者: digiprosec
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-23 12:52:36

📝 项目描述:
cve-2026-86060 PoC

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Exploit #CVE

📦 项目名称: GymSIEGE
👤 项目作者: ElenaViewSynthesis
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-23 12:47:47

📝 项目描述:
▎ Fleet-evaluation harness for security-agent benchmarks (CyberGym-E2E, ExploitGym, ExploitBench), run in real disposable Daytona sandboxes per trial — with Modal-based KVM-capable sandboxes planned for kernel-exploit tasks. Measures agent capability and infra reliability, not simulated.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #DOM

📦 项目名称: campaignhub-lab
👤 项目作者: arslanben
🛠 开发语言: HTML
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-23 13:04:08

📝 项目描述:
CampaignHub DOM XSS CTF lab

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #RCE #Remote Code Execution

📦 项目名称: VoidStrike
👤 项目作者: CypherNova1337
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-23 13:48:45

📝 项目描述:
AI-assisted remote code execution testing framework - command injection, SSTI, deserialization, JNDI/Log4Shell and file upload, planned and adapted per request.

🔗 点击访问项目地址
👍1
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: CVE-2026-94545-nextjs-og-poc
👤 项目作者: Hassham1
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-23 14:52:43

📝 项目描述:
CVE-2026-94545 / GHSA-vcvr-r3jv-pc5j — Next.js next/og ImageResponse SVG injection (Satori, GHSA-wx4j-mvgx-mqwp): isolated Docker validation lab with vulnerable (16.3.5) vs patched (16.3.6) controls, non-destructive Python scanner with pixel-level PNG evidence, and root-cause analysis of the upstream Satori fix. Authorized security research only.

🔗 点击访问项目地址
👍1
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: CVE-2026-87902
👤 项目作者: bhideki
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-23 15:58:25

📝 项目描述:
CVE-2026-87902: PoC for WordPress's critical path traversal

🔗 点击访问项目地址
👍2
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: Vulnerability-Scanner-Mini-Project-
👤 项目作者: saivardhanlingam1-art
🛠 开发语言: C++
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-23 15:43:20

📝 项目描述:
give me jsut what i need to paste in discription A lightweight vulnerability scanner designed to detect common security flaws, open ports, and system misconfigurations.

🔗 点击访问项目地址
👍2
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #POC #DOM

📦 项目名称: Manual-Web-Penetration-Testing-and-Core-Vulnerability-Exploitation
👤 项目作者: cyber-Megha
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-23 15:46:44

📝 项目描述:
Hands-on manual penetration testing and Proof-of-Concept (PoC) exploitation framework targeting OWASP Top 10 vulnerabilities (SQLi, XSS, CSRF, Path Traversal) via advanced payload injection and DOM weaponization.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC #Nuclei

📦 项目名称: CVE-2026-89274-wp-recipe-maker-poc
👤 项目作者: Hassham1
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-23 16:29:11

📝 项目描述:
CVE-2026-89274 — WP Recipe Maker <= 10.8.1 arbitrary shortcode execution via rating-comment reviewBody (CVSS 9.1): Docker validation lab with vulnerable (10.8.1) vs patched (10.8.2) controls, Python PoC proving server-side shortcode execution in recipe JSON-LD, nuclei version screen. Authorized security research only.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #RCE #Remote Code Execution

📦 项目名称: Source-Code-Auditing-Lab
👤 项目作者: steelo-cmg
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-23 16:44:03

📝 项目描述:
A technical vulnerability lab modeling unvalidated user input vectors, remote code execution (RCE) flaws using eval(), and structural string sanitisation fixes.

🔗 点击访问项目地址