GitHub 红队武器库🚨
14.2K subscribers
26 photos
9 videos
26.8K links
​📦 GitHub 全球红队渗透资源中转站。
​旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
​⚠️ 本频道仅供安全研究与授权测试使用。
Download Telegram
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #metadata

📦 项目名称: jack-sparrow
👤 项目作者: Pabl0l
🛠 开发语言: Rust
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-25 07:37:14

📝 项目描述:
web hacking sharp-tool kit. XSS, SSRF, IDOR...

🔗 点击访问项目地址
👍1
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #Exploit

📦 项目名称: ghostlock-mrx-w09
👤 项目作者: 0ch4
🛠 开发语言: C
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-25 09:50:19

📝 项目描述:
CVE-2026-43499 (GhostLock) port: working root on the Huawei MatePad Pro MRX-W09 (Kirin 990, EMUI 11, Linux 4.14.116) - disassembly-proven write primitive, perf cred leak, and a source-derived HKIP bypass

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Nuclei #templates

📦 项目名称: nuclei-fast-templates
👤 项目作者: reewardius
🛠 开发语言: Unknown
⭐ Star数量: 21 | 🍴 Fork数量: 8
📅 更新时间: 2026-09-25 09:52:14

📝 项目描述:
无描述

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #Stored

📦 项目名称: smoothwall-express-dhcp-static-gui-fixes
👤 项目作者: petter5
🛠 开发语言: Perl
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-25 09:45:35

📝 项目描述:
Bug fixes for Smoothwall Express 3.1's DHCP static-assignments GUI (garbled IP/MAC display, a related stored-XSS, and stale Active status), found while running the DHCP-WoL mod.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC #RCE

📦 项目名称: Kestra-cve-2026-53576
👤 项目作者: AtlasVector
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-25 10:24:11

📝 项目描述:
End-to-end reproduction and cross-layer detection of CVE-2026-53576, the unauthenticated RCE in Kestra — taken past the base PoC to show how a common Docker-socket misconfiguration turns container-root into full host compromise.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Spring #CVE

📦 项目名称: watchdog
👤 项目作者: impressionistic-permeation7619
🛠 开发语言: TypeScript
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-25 11:00:15

📝 项目描述:
Automate OSINT data collection and case management with machine-driven monitoring and human-in-the-loop decision making.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: VulnScan
👤 项目作者: hacksudo
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-25 10:39:46

📝 项目描述:
A powerful, containerized Web Vulnerability Scanner featuring industry-standard security tools (Nmap, Nikto, SSLScan, TestSSL). Fully packaged into a self-contained Docker deployment that sets up in seconds.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Nuclei #templates

📦 项目名称: omnistrike
👤 项目作者: shadowboykay
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-25 10:54:27

📝 项目描述:
Modular pentest framework — 195+ modules, 14k Nuclei templates, KEV/ExploitDB, Burp-lite proxy, Flask UI, SARIF/CI, Termux-native

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #C2 #Framework #Beacon

📦 项目名称: adaptix-graph-c2
👤 项目作者: stillbigjosh
🛠 开发语言: C++
⭐ Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-25 11:06:23

📝 项目描述:
Cloud dead-drop C2 channel plugin for Adaptix C2 v1.2.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #Reflected

📦 项目名称: PawXssScanner
👤 项目作者: Rushikesh362
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-25 11:00:30

📝 项目描述:
Fast reflected-XSS scanner with adaptive WAF-bypass engine

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: Simple-Vulnerability-
👤 项目作者: asinshaik274-dev
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-25 13:00:42

📝 项目描述:
A Simple Vulnerability Scanner is a cybersecurity application that scans a system or website for common security weaknesses. It checks for issues such as open ports, weak configurations, outdated software indicators, and common web vulnerabilities, then generates a basic report with the detected risks and recommendations.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: simple-vulnerability-scanner
👤 项目作者: asinshaik274-dev
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-25 12:57:53

📝 项目描述:
A Simple Vulnerability Scanner is a cybersecurity application that scans a system or website for common security weaknesses. It checks for issues such as open ports, weak configurations, outdated software indicators, and common web vulnerabilities, then generates a basic report with the detected risks and recommendations.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #Stored #Reflected #DOM

📦 项目名称: xss-penetration-testing
👤 项目作者: TEJASWANIANIMIREDDY
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-25 12:32:19

📝 项目描述:
XSS vulnerability testing guide and findings from DVWA and PortSwigger labs

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #Stored #DOM

📦 项目名称: xsshunter-express
👤 项目作者: man715
🛠 开发语言: SCSS
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-25 11:58:53

📝 项目描述:
Self-hosted XSS Hunter Express - collect and manage XSS payloads

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #复现

📦 项目名称: opace6-cve-2026-64560
👤 项目作者: Wangs-official
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-25 13:42:44

📝 项目描述:
针对 OnePlus Ace6 设备的 cve-2026-64560 复现

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #RCE #CVE

📦 项目名称: wp-plainview-auth-RCE-broken-cookie-to-session-fix
👤 项目作者: firasotoom85-droid
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-25 14:04:24

📝 项目描述:
WP Plainview Activity Monitor auth RCE fix: broken manual cookie parse to stable Session handling. CVE-2018-15877 educational fix.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #metadata

📦 项目名称: go-webhook-delivery
👤 项目作者: gabrieldosprazeres
🛠 开发语言: Go
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-25 13:13:34

📝 项目描述:
Reliable at-least-once webhook delivery engine in Go with PostgreSQL, retries, fencing, HMAC, SSRF defense and observability.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #BlueTeam #Detection

📦 项目名称: StaticSentinel
👤 项目作者: kamalx06
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-25 14:49:50

📝 项目描述:
YARA based static malware analysis tool that performs rule matching, entropy analysis, and VirusTotal hash lookups to assess files and avoid false positives

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #metadata

📦 项目名称: SubScope
👤 项目作者: ishasonaria568-prog
🛠 开发语言: TypeScript
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-25 14:18:00

📝 项目描述:
Professional subdomain enumeration & reconnaissance tool with DNS verification, HTTP/HTTPS probing, SSRF protection, real-time scanning, and security metadata analysis.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #RCE #Remote Code Execution

📦 项目名称: jsf-viewstate-lab
👤 项目作者: arslanben
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-25 14:37:41

📝 项目描述:
A deliberately vulnerable JSF/Mojarra app demonstrating pre-auth RCE via unencrypted client-side ViewState. Docker-based, CTF-style lab.

🔗 点击访问项目地址