GitHub 红队武器库🚨
14.2K subscribers
25 photos
10 videos
27.1K links
​📦 GitHub 全球红队渗透资源中转站。
​旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
​⚠️ 本频道仅供安全研究与授权测试使用。
Download Telegram
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Exploit #CVE

📦 项目名称: Vulnerability-Scanner-CVE-Prioritization
👤 项目作者: hassanali-30
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-29 11:59:18

📝 项目描述:
Authorization-first vulnerability scanner with service and version detection, CVE/CVSS analysis, CISA KEV prioritization, asset criticality weighting, evidence-based findings, remediation guidance, and JSON/CSV/HTML reports without exploit execution.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Exploit #CVE #POC

📦 项目名称: CVE-2025-32463
👤 项目作者: klvlo
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-29 12:58:48

📝 项目描述:
PoC / Exploit for CVE-2025-32463(sudo LPE)

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSTI #RCE

📦 项目名称: solarvault-pentest-writeup
👤 项目作者: kamelisas
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-29 13:00:28

📝 项目描述:
Pentest exam write-up (CYBERUS course, Univ. Bretagne Sud): exposed .git → forged session cookie + SSTI RCE → command injection → AD compromise, across a 6-host lab.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Bypass #AV #MFA

📦 项目名称: CVE-2026-8065
👤 项目作者: murrez
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-29 13:02:57

📝 项目描述:
CVE-2026-8065 PoC: Hitachi Energy RTU500 unauth firmware update bypass (CWE-306, CVSS 9.1). IoT/OT colored check + mass exploit — RTU500 fingerprint, firmware endpoint probe, lab-safe upload test. https://pocbit.org/pocs/cve-2026-8065

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #漏洞 #扫描

📦 项目名称: -
👤 项目作者: baby1-ux
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-29 12:49:31

📝 项目描述:
将扫描的漏洞进行分类管理

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #渗透测试 #红队

📦 项目名称: Xuanji
👤 项目作者: EthanJulina
🛠 开发语言: Unknown
⭐ Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-29 13:04:44

📝 项目描述:
玄机 —— 纯本地运行的桌面安全操作台。工具启动器 × 工作空间 × 命令面板,面向渗透测试/红队工作流。不联网、零上报、无数据库。Electron + Vue3

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC #Exploit #RCE

📦 项目名称: CVE-2026-85520
👤 项目作者: murrez
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-29 13:52:17

📝 项目描述:
CVE-2026-85520 PoC (PoCbit) — PrestaShop MyPresta gmfeed ≤2.3.9 unauthenticated arbitrary file write via feed.php (Save to file URL) → RCE. check + exploit + mass bulk (--list -j). https://pocbit.org/pocs/cve-2026-85520

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC #Exploit

📦 项目名称: CVE-2026-8065
👤 项目作者: MRdark-ops
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-29 13:11:04

📝 项目描述:
CVE-2026-8065 PoC: Hitachi Energy RTU500 unauth firmware update bypass (CWE-306, CVSS 9.1). IoT/OT colored check + mass exploit — RTU500 fingerprint, firmware endpoint probe, lab-safe upload test. https://pocbit.org/pocs/cve-2026-8065

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #漏洞 #POC #CVE #Stored #DOM

📦 项目名称: xss
👤 项目作者: feixingxuerong123
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-29 13:23:38

📝 项目描述:
无描述

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #Reflected

📦 项目名称: dvwa-k8s-demo
👤 项目作者: vinshriv
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-29 13:04:46

📝 项目描述:
DVWA deployment on a local Kubernetes cluster with demonstrations of SQL Injection, Command Injection, and Reflected XSS.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSTI #RCE

📦 项目名称: solarvault-pentest
👤 项目作者: MRdark-ops
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-29 13:21:20

📝 项目描述:
exposed .git → forged session cookie + SSTI RCE → command injection → AD compromise, across a 6-host lab.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: the-OWASP-Top-10-Vulnerability-Scanner
👤 项目作者: gocar112
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-29 14:30:58

📝 项目描述:
# Vulnerability Scanner Based on OWASP Top 10

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #DOM

📦 项目名称: Reflectra
👤 项目作者: pratik-khairnar-sec
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-29 14:31:57

📝 项目描述:
Context-aware XSS scanner with real browser confirmation, reflection analysis, DOM-sink detection, blind XSS support, and automated reporting for authorized security testing.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #rules #malware

📦 项目名称: detection-rules
👤 项目作者: Garylee833
🛠 开发语言: YARA
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-29 15:09:54

📝 项目描述:
YARA + Sigma detections from published threat intel — fingerprints only, no live malware handled. Currently: NeedyMantis (T1574.002, T1071.001).

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #POC

📦 项目名称: nextjs-image-optimizer-dns-rebinding-poc
👤 项目作者: rudy128
🛠 开发语言: JavaScript
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-29 15:32:48

📝 项目描述:
Reproducible Next.js image optimizer DNS rebinding SSRF PoC

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: mcvs-dotnet-action
👤 项目作者: schubergphilis
🛠 开发语言: C#
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-29 15:11:41

📝 项目描述:
Mission Critical Vulnerability Scanner (MCVS) .NET Action. Create .NET code without high and critical vulnerabilities.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: Web_vuln_scanner
👤 项目作者: Shobith15
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-29 15:13:21

📝 项目描述:
Web Vulnerability Scanner

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: WP2Shell--CVE-2026-63030-CVE-2026-60137-
👤 项目作者: MRdark-ops
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-29 16:29:32

📝 项目描述:
Unauthenticated SQL injection PoC and vulnerable lab environment for WP2Shell (CVE-2026-63030 + CVE-2026-60137) — a WordPress REST API batch route confusion chained into a WP_Query SQL injection. Includes Docker Compose lab setup and a Python exploitation script. For authorized security research only.

🔗 点击访问项目地址
👍1
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: Simple-vulnerability-scanner
👤 项目作者: malliswaricheeli
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-29 16:51:46

📝 项目描述:
A Simple Vulnerability Scanner is a cybersecurity application that scans a system or website for common security weaknesses. It checks for issues such as open ports, weak configurations, outdated software indicators, and common web vulnerabilities, then generates a basic report with the detected risks and recommendations.

🔗 点击访问项目地址
👍1
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: Simple-Vulnerability-Scanner-Python
👤 项目作者: chipurupallisandeepsagar12-cloud
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-29 16:37:34

📝 项目描述:
Python Simple Vulnerability Scanner Project

🔗 点击访问项目地址
👍1
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSTI #RCE

📦 项目名称: OSWE_cheatsheet
👤 项目作者: guzbytes
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-29 14:23:14

📝 项目描述:
A personal cheatsheet and toolkit for OSWE/AWAE exam prep — Python scripts for blind SQLi, JWT attacks, cookie/session forging, and WebSocket exploitation, plus JS payloads for XSS/CSRF via fetch, and a manual testing checklist covering SQLi, SSTI, XXE, SSRF, deserialization, and more.

🔗 点击访问项目地址
👍1