GitHub 红队武器库🚨
14.2K subscribers
25 photos
10 videos
27.2K links
​📦 GitHub 全球红队渗透资源中转站。
​旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
​⚠️ 本频道仅供安全研究与授权测试使用。
Download Telegram
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #Stored #Reflected

📦 项目名称: cyberlab
👤 项目作者: ghani24ep10007-spec
🛠 开发语言: JavaScript
⭐ Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-30 05:51:32

📝 项目描述:
Proyek akhir MK Cyber Security: website materi + lab XSS/SQLi + mini-SIEM real-time (Node.js, hemat RAM)

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: binary-vuln-finder
👤 项目作者: VladaShudegova
🛠 开发语言: C++
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-30 06:38:53

📝 项目描述:
Automated binary vulnerability scanner and test generator based on directed symbolic execution and static analysis (Python + Angr framework)

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #漏洞 #扫描

📦 项目名称: agent-audit-action
👤 项目作者: mo9652962-ai
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-30 07:51:02

📝 项目描述:
GitHub Action: agent-audit 作为 CI 安全门禁——git 泄漏 + 依赖漏洞检查,OWASP/NSA 对齐

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #RCE #CVE #POC

📦 项目名称: CVE-2026-102425
👤 项目作者: murrez
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-30 08:04:21

📝 项目描述:
CVE-2026-102425 PoC (PoCbit) — Joomla Balbooa Forms (com_baforms) <2.4.3.4 unauth RCE via field shortcode injection in post-submission PHP eval(). check + exploit + mass bulk. https://pocbit.org/pocs/cve-2026-102425

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Exploit #CVE #POC

📦 项目名称: AVM-FRITZ-Box-CVE-2024-54767-Exploit
👤 项目作者: lowlevelsec
🛠 开发语言: Python
⭐ Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-30 08:02:23

📝 项目描述:
Research & PoC for CVE-2024-54767 and related unauthenticated FRITZ!OS information-disclosure findings across multiple FRITZ!Box models and firmware versions.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Burp #Extension

📦 项目名称: burp-body-only
👤 项目作者: Gtm0x01
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-30 07:40:22

📝 项目描述:
Burp Suite extension that adds a body-only response viewer with pretty-printed JSON, colored syntax highlighting, and a Monospaced 16 pt font.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: web-vuln-scanner
👤 项目作者: adeev-mardia
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-30 08:20:08

📝 项目描述:
A real web vulnerability scanner (SQLi, XSS, command injection, path traversal, IDOR, open redirect) + the deliberately vulnerable Flask app it targets, with an integration test that proves it end to end.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Sliver #C2

📦 项目名称: Daemon-Slayer
👤 项目作者: sickboy8388
🛠 开发语言: Rust
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-30 09:13:35

📝 项目描述:
Evasion wrapper for Sliver C2 beacons — AMSI + ETW bypass, AES-256-GCM encryption, in-process execution

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Shiro #反序列化

📦 项目名称: usrink-pro
👤 项目作者: mutolee
🛠 开发语言: Java
⭐ Star数量: 9 | 🍴 Fork数量: 1
📅 更新时间: 2026-09-30 08:56:27

📝 项目描述:
UsrInk-Pro 是一个基于SpringBoot + Mybatis + Shiro + Jwt + Vue3 + ElementPlus 的无状态前后端分离的后台管理系统,轻量、没有重度依赖,模块设计优雅,管理界面美观,可快速进行二次开发。

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: CVE-2026-26026-PoC
👤 项目作者: wuyou6956-glitch
🛠 开发语言: Shell
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-30 10:57:39

📝 项目描述:
无描述

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: CVE-2026-41096-POC
👤 项目作者: wuyou6956-glitch
🛠 开发语言: C
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-30 10:57:29

📝 项目描述:
无描述

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #RCE #Remote Code Execution

📦 项目名称: nethserver-nethsecurity-remote-code-execution-rce
👤 项目作者: gerico-lab
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-30 10:42:07

📝 项目描述:
Multiple Remote Code Execution (RCE) or Code Injection in NethServer NethSecurity

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Burp #Extension

📦 项目名称: BurpXSSGenerator
👤 项目作者: PinkCloudlet
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-30 10:42:27

📝 项目描述:
A Burp Suite extension (Jython, classic IBurpExtender API) that generates XSS payloads for Intruder, based on the PortSwigger cheatsheet — with a unique marker, encoding variants, and support for loading a custom payload list.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: Simple-Vulnerability-Scanner
👤 项目作者: Radifakhan
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-30 10:31:54

📝 项目描述:
Python-based vulnerability scanner with port scanning, Nmap vulnerability assessment, XSS testing, and automated reports.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: cve-2026-1668-poc
👤 项目作者: wuyou6956-glitch
🛠 开发语言: C
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-30 10:57:21

📝 项目描述:
无描述

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Kubernetes #EXP

📦 项目名称: wyrd
👤 项目作者: sre-norns
🛠 开发语言: Go
⭐ Star数量: 1 | 🍴 Fork数量: 1
📅 更新时间: 2026-09-30 12:04:17

📝 项目描述:
A collection of reusable components for all of your SRE project needs

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #metadata

📦 项目名称: Glowhaven-Dashboard
👤 项目作者: GlowhavenIndustries
🛠 开发语言: JavaScript
⭐ Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-30 11:58:08

📝 项目描述:
The open-source command center for your company. Monitor KPIs, incidents, services, workflows, GitHub Actions, and automation in one secure, self-hosted workspace with RBAC, OIDC SSO, encrypted secrets, SSRF protection, and tamper-evident audit logs.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #metadata

📦 项目名称: headerscope
👤 项目作者: joaquinbarbetta
🛠 开发语言: TypeScript
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-30 11:07:21

📝 项目描述:
Scan any website's HTTP security headers, get a grade and concrete fixes. Next.js + TypeScript, SSRF-hardened.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Burp #Extension

📦 项目名称: HTTPoverHTTP
👤 项目作者: Term1N8
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-30 12:46:30

📝 项目描述:
Custom Burp Extension to Tunnel HTTP Over Burp Suite

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #POC

📦 项目名称: poc-pdfjs-xss
👤 项目作者: gchem1se
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-30 13:53:14

📝 项目描述:
无描述

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #rules #malware

📦 项目名称: APK_MalwareTest
👤 项目作者: TheCogentNihit
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-30 14:01:42

📝 项目描述:
An enterprise-grade Static Analysis pipeline combining XGBoost machine learning with a custom Heuristics engine (Entropy analysis, API matching, Obfuscation tracking, and YARA rules) to detect advanced Android malware, dropper payloads, and banking trojans. Features Dynamic Weighting and a Stealth Penalty to counter evasion techniques.

🔗 点击访问项目地址