GitHub 红队武器库🚨
14.2K subscribers
26 photos
9 videos
26.9K links
​📦 GitHub 全球红队渗透资源中转站。
​旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
​⚠️ 本频道仅供安全研究与授权测试使用。
Download Telegram
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: python-vulnerability-scanner
👤 项目作者: billkot
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-26 22:44:24

📝 项目描述:
A beginner Python cybersecurity project that scans authorized hosts for open TCP ports and performs basic web security checks.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Spring #EXP

📦 项目名称: exp-spring-petclinic-spring-petclinic-microservices
👤 项目作者: osflaky
🛠 开发语言: Java
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-27 01:03:26

📝 项目描述:
snapshot of spring-petclinic/spring-petclinic-microservices at a pinned commit, for cross platform ci legs

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #C2 #Framework

📦 项目名称: C2-Framework.
👤 项目作者: sampadghosh31
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-27 01:53:49

📝 项目描述:
A modular C2 Framework developed during my final year cyber project at KIIT, featuring DNS/GitHub communication channels, custom agent modules, and a dual GUI/CLI interface

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Bypass #WAF

📦 项目名称: nowafplsV2
👤 项目作者: irwankusuma
🛠 开发语言: Java
⭐ Star数量: 7 | 🍴 Fork数量: 3
📅 更新时间: 2026-09-27 04:00:42

📝 项目描述:
Burp Suite extension to bypass WAF by injecting junk data into HTTP requests. V2 adds auto-inject for Active Scanner/DAST, supports JSON/XML/multipart/CSV/YAML/GraphQL. Based on assetnote/nowafpls by Shubham Shah.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #rules

📦 项目名称: Wazuh
👤 项目作者: OrangeBox-Labs
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-27 04:04:29

📝 项目描述:
Reglas de seguridad, detección de amenazas, IOC, YARA, respuestas activas, automatización y reportes para Wazuh, desarrollados a partir de implementaciones reales.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: CVE-2026-100740
👤 项目作者: murrez
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-27 05:41:01

📝 项目描述:
CVE-2026-100740 PoC: D-Link DIR-895L A1_102b07 L2TP Host Name AVP out-of-bounds write in tunnel_set_params (UDP 1701). Device fingerprint + optional OOB trigger packet for authorized lab testing. https://pocbit.org/pocs/cve-2026-100740

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #漏洞 #扫描

📦 项目名称: RayScanX
👤 项目作者: ZapcoMan
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-27 05:55:40

📝 项目描述:
RayScanX 是一款开箱即用的 Web 漏洞扫描器,专注于中文 OA 系统和国产中间件的专项漏洞检测。支持 CLI 和 Web UI 双模式,一条命令即可输出可复核的扫描报告。

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Fortinet #CVE

📦 项目名称: cisco_bugsearch_analyzer
👤 项目作者: w-index-m
🛠 开发语言: Python
⭐ Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-27 04:44:18

📝 项目描述:
cisco_bugsearch_analyzer

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Burp #Extension

📦 项目名称: burp-mcp
👤 项目作者: saif-pvt
🛠 开发语言: Kotlin
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-27 04:40:30

📝 项目描述:
Private internal Burp Suite MCP adapter. No open-source license; internal use only, do not redistribute.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Kubernetes #EXP

📦 项目名称: DockVerseHub
👤 项目作者: SatvikPraveen
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-27 06:01:28

📝 项目描述:
Docker study material: 13 concept guides and 8 labs covering Kubernetes, GitOps, observability and security.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC #RCE

📦 项目名称: CVE-2026-44011-craftcms-auth-rce
👤 项目作者: 4xura
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-27 06:57:38

📝 项目描述:
The PoC of CVE-2026-44011: Craft CMS, from 4.0.0 to before 4.17.12 and 5.9.18, contains an input-handling flaw in a Yii object creation path that let any authenticated user inject malicious configuration and execute arbitrary commands on the server.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #漏洞 #POC #扫描 #利用

📦 项目名称: RuoyiScanX
👤 项目作者: ZapcoMan
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-27 06:45:51

📝 项目描述:
一款合法授权的 若依(RuoYi)专项漏洞扫描器。插件化架构,三态判定 (CONFIRMED / SAFE / UNKNOWN),51 个 POC,支持批量扫描、WAF 绕过、 漏洞利用链、Web API 等企业级特性。

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #malware

📦 项目名称: warden
👤 项目作者: ForrestLasiter
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-27 06:52:04

📝 项目描述:
Open-source, on-demand malware scanner (YARA + heuristics + hash reputation + optional ClamAV). No subscription, no telemetry.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #CVE

📦 项目名称: CVE-2026-8712-Wyoming
👤 项目作者: rahulreddykarne
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-27 07:01:59

📝 项目描述:
CVE-2026-8712: Unauthenticated SSRF / Backend URI Override in Wyoming HTTP API via uri Query Parameter

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #RCE

📦 项目名称: citrix-netscaler-cve-2026-8452-rce
👤 项目作者: techupdate24
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-27 07:29:57

📝 项目描述:
A complete guide and workflow for integrating Agile sprints with DevOps CI/CD pipelines.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC #Exploit

📦 项目名称: cve-2026-85706
👤 项目作者: unh00k3d
🛠 开发语言: Shell
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-27 08:57:09

📝 项目描述:
CVE-2026-85706 — GitLab unauthenticated arbitrary file read (CVSS 10.0). Root-cause analysis, vulnerable Docker lab, and PoC.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #Exploit

📦 项目名称: YellowKey-BitLocker-CVE-2026-45585
👤 项目作者: YellowKeyBitLocker-CVE
🛠 开发语言: C++
⭐ Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-27 08:32:41

📝 项目描述:
YellowKey BitLocker recovery audits CVE-2026-45585: yellowkey github, TPM, recovery key backup. Windows 10/11 CLI GUI, portable audit tool for volumes you own. Extract and run. Official free download. Download:➧

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #rule #malware

📦 项目名称: detonation-sandbox
👤 项目作者: malware-detonation-pipeline
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-27 08:42:12

📝 项目描述:
Static + dynamic malware analysis pipeline with ML classification and automated YARA/Suricata rule generation.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: CVE-2026-34990-poc
👤 项目作者: 0xc4rc3l
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-27 09:59:48

📝 项目描述:
无描述

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #RCE

📦 项目名称: CVE-2026-12227
👤 项目作者: be-keb
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-27 09:10:13

📝 项目描述:
CVE-2026-12227 is a critical (CVSS 9.8) unauthenticated Local File Inclusion (LFI) vulnerability in the Visual Composer Website Builder plugin for WordPress, affecting all versions up to and including 45.16.0, This can lead to sensitive data exposure, access control bypass, or even full Remote Code Execution (RCE).

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #C2 #Implant #Beacon #红队

📦 项目名称: Toshell
👤 项目作者: iQingshan
🛠 开发语言: Go
⭐ Star数量: 162 | 🍴 Fork数量: 43
📅 更新时间: 2026-09-27 09:59:48

📝 项目描述:
ToShell 是一个轻量 C2 框架,由 服务端(Team Server)+ Web 控制台 + 多平台植入端 组成,覆盖「生成载荷 → 会话管理 → 任务执行」的完整链路。单二进制即可部署整套服务,开箱即用。

🔗 点击访问项目地址