GitHub 红队武器库🚨
14.2K subscribers
26 photos
9 videos
26.9K links
​📦 GitHub 全球红队渗透资源中转站。
​旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
​⚠️ 本频道仅供安全研究与授权测试使用。
Download Telegram
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: COWSlip
👤 项目作者: k4ntux
🛠 开发语言: C
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-26 10:23:08

📝 项目描述:
xfs kernel LPE (CVE-2026-64600), disclosed by Qualys on 22 July 2026

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Spring #EXP

📦 项目名称: polycodehub
👤 项目作者: anyuer678
🛠 开发语言: TypeScript
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-26 11:00:32

📝 项目描述:
PolycodeHub — 全栈在线判题平台(Next.js + Express + Spring Boot + FastAPI + seccomp 沙箱)

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #rule #rules #malware

📦 项目名称: fresh-yara-rules
👤 项目作者: Marjoriefort
🛠 开发语言: YARA
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-26 11:05:50

📝 项目描述:
Collection personnelle de règles YARA forgées sur du malware frais (veille quotidienne MalwareBazaar / corpus VX-Underground).

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #malware

📦 项目名称: specimen
👤 项目作者: rakshit-737
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-26 10:35:59

📝 项目描述:
Sample-to-story malware analysis pipeline: explainable static gate, CAPE report replay into a provenance graph + ATT&CK timeline, family attribution, and specificity-checked auto YARA/Sigma - benchmarked on EMBER, Avast-CTU CAPEv2 and MalbehavD-V1

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC #Exploit #RCE

📦 项目名称: CVE-2026-13249
👤 项目作者: murrez
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-26 11:59:57

📝 项目描述:
Unauthenticated arbitrary file upload on Honeywell PD45 web admin (firmware F10.19.010040–before F10.22.030745) leading to RCE. Python check/exploit PoC

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #Exploit

📦 项目名称: zenfone9-ghostlock
👤 项目作者: CKwasd
🛠 开发语言: C
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-26 11:40:13

📝 项目描述:
CVE-2026-43499 (GhostLock) exploit for ASUS Zenfone 9 (SM8475, GKI 5.10.205) + KernelSU late-load.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC #Exploit #RCE

📦 项目名称: POC-WP-CORE-CVE-2026-93485
👤 项目作者: 686f6c61
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-26 12:55:46

📝 项目描述:
Laboratorio pedagógico de CVE-2026-93485 (Comment2Shell): stored XSS no autenticado en WordPress core vía wpautop -> RCE, con demo del root cause auto-verificada, control 7.1.1 y la vía Post2Shell

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #Exploit #漏洞 #利用

📦 项目名称: opace6-cve-2026-64560
👤 项目作者: qingle009
🛠 开发语言: C
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-26 12:40:00

📝 项目描述:
OnePlus Ace 6 temporary root tool (CVE-2026-64560) - device-verified port with corrected bootidParent address

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #Exploit #RCE

📦 项目名称: CVE-2026-29053
👤 项目作者: K3ysTr0K3R
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-26 13:24:36

📝 项目描述:
CVE-2026-29053 - Ghost CMS < 6.19.0 - Authenticated Remote Code Execution via Malicious Theme

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Exploit #POC

📦 项目名称: rainbet-casino-exploit
👤 项目作者: zephyrcore
🛠 开发语言: JavaScript
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-26 14:03:01

📝 项目描述:
A race condition in rainbet.com allowing to predict outcomes of specified games ( original ). POC

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #Reflected

📦 项目名称: threatharbor
👤 项目作者: Kassidi-Iliasse
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-26 13:59:03

📝 项目描述:
CLI web vulnerability scanner: headers, TLS, cookies, redirects, forms, reflected XSS. HTML/JSON reports.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Shellcode #Loader

📦 项目名称: Syscall-Early-Bird-Injection-Trojans
👤 项目作者: Hue-Jhan
🛠 开发语言: C
⭐ Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-26 14:06:17

📝 项目描述:
Collection of remote shellcode Loaders using Early Bird APC injection, direct/indirect syscalls, ntdll and low level utilities, undetected by Windows Defender and BitDefender

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Shellcode #Loader

📦 项目名称: Syscall-Apc-Injection-Trojans
👤 项目作者: Hue-Jhan
🛠 开发语言: C
⭐ Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-26 14:01:23

📝 项目描述:
Collection of remote shellcode Loaders using APCs, direct/indirect syscalls, ntdll and low level utilities, undetected by Windows Defender and BitDefender

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: webapp-vuln-scanner
👤 项目作者: santiagosantofimio
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-26 15:01:08

📝 项目描述:
Argus Sentinel: a defensive, non-destructive web application vulnerability scanner (OWASP Top 10 2025).

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: mcvs-python-action
👤 项目作者: schubergphilis
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 1
📅 更新时间: 2026-09-26 14:22:56

📝 项目描述:
Mission Critical Vulnerability Scanner (MCVS) Python Action. Create Python code without high and critical vulnerabilities.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Shellcode #Inject

📦 项目名称: DFIR-Case-Study
👤 项目作者: jawad9522
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-26 15:01:44

📝 项目描述:
This report details a digital forensic investigation of a fileless malware attack initiated by a compromised USB device. The analysis reconstructs a multi-stage execution chain (VBS, BAT, and Python) used to inject shellcode, establish a reverse shell, and stage data for exfiltration.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #漏扫

📦 项目名称: crackws
👤 项目作者: guaidao2
🛠 开发语言: Go
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-26 14:52:19

📝 项目描述:
现代的websocket渗透测试工具,本身支持websocket协议漏扫,同时支持websocket协议转http协议。

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC #RCE

📦 项目名称: CVE-2026-61500
👤 项目作者: aramosf
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-26 15:32:18

📝 项目描述:
CVE-2026-61500 Rejetto HFS predictable PRNG session forgery to RCE PoC and Docker lab

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #malware

📦 项目名称: SMAHG-XDR-DFIR
👤 项目作者: AwaisGardezi
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-26 15:35:52

📝 项目描述:
Enterprise Malware Intelligence, Dynamic Analysis & Digital Forensics platform - sample/case management, sandbox detonation, YARA/ATT&CK/IOC analysis, threat intel, reporting

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #Reflected

📦 项目名称: aegis-lens
👤 项目作者: sourabhbeni
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-26 16:01:59

📝 项目描述:
Browser extension (MV3) for in-browser SQL injection, reflected XSS, and security-header probing — companion to aegis

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #漏洞 #复现

📦 项目名称: FirmAudit2
👤 项目作者: JiuZero
🛠 开发语言: HTML
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-26 15:39:54

📝 项目描述:
FirmAudit2 — AI Agent firmware vulnerability audit pipeline, from unpacking to a CNVD-ready delivery bundle. | 从解包到 CNVD 交付总包,一条固件漏洞审计流水线:Agent 负责挖,平台负责把关 —— 八段引导、四道结果门、命令级复现,全程可回放、可校验、可交付

🔗 点击访问项目地址