GitHub 红队武器库🚨
14.2K subscribers
25 photos
10 videos
27.2K links
​📦 GitHub 全球红队渗透资源中转站。
​旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
​⚠️ 本频道仅供安全研究与授权测试使用。
Download Telegram
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: fintool
👤 项目作者: dianatarhoniy
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-30 22:29:33

📝 项目描述:
Fintech vulnerability scanner for banking web applications

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #CVE #Stored

📦 项目名称: CVE-Umbraco-svg-xss
👤 项目作者: Mesh3l911
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-30 22:54:09

📝 项目描述:
Umbraco CMS 17.6.2 LTS - Stored XSS Leading to Silent Administrator Account Creation

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC #Exploit

📦 项目名称: 0xKern3lCrush
👤 项目作者: DeathShotXD
🛠 开发语言: C
⭐ Star数量: 55 | 🍴 Fork数量: 6
📅 更新时间: 2026-09-30 23:32:15

📝 项目描述:
Advanced PoC & Research for CVE-2026-0828 (Safetica) and CVE-2025-7771 (ThrottleStop). Analysis of BYOVD (Bring Your Own Vulnerable Driver) TTPs for Ring 0 process termination and physical memory R/W. Researching EDR-Killer patterns, PPL bypasses, and kernel-mode primitives used by MedusaLocker and other threat actors.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #C2 #Command and Control

📦 项目名称: splunk-investigation3
👤 项目作者: alenicakariz
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-30 23:53:12

📝 项目描述:
domain generation algorithim (DGA) style domain guessing to command and control (C2)

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: Projects
👤 项目作者: raphaelybsk
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-01 00:07:51

📝 项目描述:
Security-focused engineering projects built to learn by doing: an API vulnerability scanner, secrets/credential scanner, SIEM dashboard, and more, covering AppSec, DevSecOps, and backend engineering.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #RCE #Remote Code Execution

📦 项目名称: fwdsh
👤 项目作者: Amirabbas-RU
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-01 00:09:45

📝 项目描述:
Forward Shell - interactive shell through RCE via HTTP

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #Exploit #RCE

📦 项目名称: vc-strike
👤 项目作者: chu0119
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-01 01:31:30

📝 项目描述:
VC-Strike — VMware vCenter CVE-2026-59310 (unauth root RCE) & CVE-2026-59309 (SRP auth bypass) authorized pentest suite. GUI+CLI, multi-session C2, stdlib-only. 授权测试专用

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: CVE-2026-103585
👤 项目作者: BomboBombone
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-01 01:08:47

📝 项目描述:
Sanitized report and local PoC for CVE-2026-103585

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Sliver #C2

📦 项目名称: red-team-c2-lab
👤 项目作者: ronankongala
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-01 02:01:31

📝 项目描述:
Sliver C2 adversary emulation against a Windows 11 victim on an isolated network: 7 ATT&CK techniques and 3 Sigma detection rules.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #rules

📦 项目名称: Yara-Sigma-Detection-Rules
👤 项目作者: TACyber7
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-01 02:46:02

📝 项目描述:
This will be a public repo for Yara/Sigma Detection Rules

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #DOM

📦 项目名称: DOM-XSS
👤 项目作者: drg1bl3ts
🛠 开发语言: HTML
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-01 02:46:15

📝 项目描述:
DOM-XSS Practice Hub

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #渗透测试 #漏洞

📦 项目名称: YuCode
👤 项目作者: sywinksvg
🛠 开发语言: Unknown
⭐ Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-30 16:16:04

📝 项目描述:
YuCode — 本地优先的 AI 安全作战台(渗透测试工作台 + 多智能体协作)。本仓库仅公开文档与发行包,源码不公开。

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Docker #Exploit

📦 项目名称: skill-quarantine
👤 项目作者: Yehiak
🛠 开发语言: Shell
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-01 04:05:37

📝 项目描述:
Vet third-party Claude Code skills in a disposable Docker sandbox before installing them

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC #Exploit #RCE

📦 项目名称: CVE-2026-96349
👤 项目作者: murrez
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-01 04:23:41

📝 项目描述:
CVE-2026-96349 — WordPress SiteSkite plugin ≤2.1.8 unauthenticated RCE (CVSS 10.0, CWE-94). PoCbit mass-exploit PoC: legacy API-key autologin (?token=) + REST MCP siteskite_execute_php eval chain; fixed in 2.2.0. Check/exploit/mass bulk, hits.txt & exploited.txt, --lab self-test. Catalog: https://pocbit.org/pocs/cve-2026-96349

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Bypass #Sandbox

📦 项目名称: dsh-api-balance
👤 项目作者: CH2008445
🛠 开发语言: JavaScript
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-01 04:59:52

📝 项目描述:
DeepSeek API account balance and per-run usage cost in the DSH web GUI sidebar footer. The API key stays in the host process: no shell, no sandbox bypass, official endpoint only.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #rules

📦 项目名称: quipu
👤 项目作者: corelight
🛠 开发语言: Rust
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-01 04:46:58

📝 项目描述:
A desktop workbench for writing, validating, compiling, and testing YARA rules.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #提权 #UAC

📦 项目名称: PTB-Python
👤 项目作者: liuchenglin19850617-art
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-01 04:05:41

📝 项目描述:
# ComConver PTB-python 是一个基于 Python 的 Windows 便携版应用。它内置 Python 运行时与所需依赖,无需系统预装 Python,也不修改注册表或系统目录,可放在 U 盘或任意文件夹中直接运行。程序支持以管理员权限启动,适合需要提权操作的工具类场景。 本项目源码以 LGPL 许可证开源。发行版中包含 Python Software Foundation License Version 2 及其他第三方许可证,详见 licenses/ 目录“Python”是 Python Software Foundation 的注册商标 本项目与 Python Software Foundation 无隶属关系,也未获得其背书

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: Jet-Vuln-Scanner
👤 项目作者: wesssso512
🛠 开发语言: Python
⭐ Star数量: 2 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-01 04:28:29

📝 项目描述:
A hybrid desktop vulnerability scanner — Socket, Nmap, SQLi, XSS, and AI Advisor

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Nuclei #POC #CVE

📦 项目名称: cve-intelligence-bot
👤 项目作者: realsandeep1271-ui
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-01 05:45:47

📝 项目描述:
24/7 serverless CVE & CISA KEV threat intel bot with EPSS scoring, GitHub PoC search, and Telegram alerts

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSTI #RCE

📦 项目名称: render
👤 项目作者: het-P301204
🛠 开发语言: TypeScript
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-30 21:53:15

📝 项目描述:
SSTI Security Research Platform — 5-stage attack chain across Jinja2, Handlebars, Nunjucks & Mako · FastAPI + React+TS+Vite

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Docker #Exploit

📦 项目名称: AirCard-Windows
👤 项目作者: Lauracol26
🛠 开发语言: Rust
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-01 06:06:23

📝 项目描述:
Skin and theme Apple Wallet cards and lockscreen passcodes on iOS 18+ from Windows—no jailbreak needed.

🔗 点击访问项目地址