GitHub 红队武器库🚨
14.3K subscribers
25 photos
10 videos
27.3K links
​📦 GitHub 全球红队渗透资源中转站。
​旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
​⚠️ 本频道仅供安全研究与授权测试使用。
Download Telegram
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #DOM

📦 项目名称: DOM-XSS
👤 项目作者: drg1bl3ts
🛠 开发语言: HTML
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-01 02:46:15

📝 项目描述:
DOM-XSS Practice Hub

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #渗透测试 #漏洞

📦 项目名称: YuCode
👤 项目作者: sywinksvg
🛠 开发语言: Unknown
⭐ Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-30 16:16:04

📝 项目描述:
YuCode — 本地优先的 AI 安全作战台(渗透测试工作台 + 多智能体协作)。本仓库仅公开文档与发行包,源码不公开。

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Docker #Exploit

📦 项目名称: skill-quarantine
👤 项目作者: Yehiak
🛠 开发语言: Shell
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-01 04:05:37

📝 项目描述:
Vet third-party Claude Code skills in a disposable Docker sandbox before installing them

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC #Exploit #RCE

📦 项目名称: CVE-2026-96349
👤 项目作者: murrez
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-01 04:23:41

📝 项目描述:
CVE-2026-96349 — WordPress SiteSkite plugin ≤2.1.8 unauthenticated RCE (CVSS 10.0, CWE-94). PoCbit mass-exploit PoC: legacy API-key autologin (?token=) + REST MCP siteskite_execute_php eval chain; fixed in 2.2.0. Check/exploit/mass bulk, hits.txt & exploited.txt, --lab self-test. Catalog: https://pocbit.org/pocs/cve-2026-96349

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Bypass #Sandbox

📦 项目名称: dsh-api-balance
👤 项目作者: CH2008445
🛠 开发语言: JavaScript
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-01 04:59:52

📝 项目描述:
DeepSeek API account balance and per-run usage cost in the DSH web GUI sidebar footer. The API key stays in the host process: no shell, no sandbox bypass, official endpoint only.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #rules

📦 项目名称: quipu
👤 项目作者: corelight
🛠 开发语言: Rust
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-01 04:46:58

📝 项目描述:
A desktop workbench for writing, validating, compiling, and testing YARA rules.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #提权 #UAC

📦 项目名称: PTB-Python
👤 项目作者: liuchenglin19850617-art
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-01 04:05:41

📝 项目描述:
# ComConver PTB-python 是一个基于 Python 的 Windows 便携版应用。它内置 Python 运行时与所需依赖,无需系统预装 Python,也不修改注册表或系统目录,可放在 U 盘或任意文件夹中直接运行。程序支持以管理员权限启动,适合需要提权操作的工具类场景。 本项目源码以 LGPL 许可证开源。发行版中包含 Python Software Foundation License Version 2 及其他第三方许可证,详见 licenses/ 目录“Python”是 Python Software Foundation 的注册商标 本项目与 Python Software Foundation 无隶属关系,也未获得其背书

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: Jet-Vuln-Scanner
👤 项目作者: wesssso512
🛠 开发语言: Python
⭐ Star数量: 2 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-01 04:28:29

📝 项目描述:
A hybrid desktop vulnerability scanner — Socket, Nmap, SQLi, XSS, and AI Advisor

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Nuclei #POC #CVE

📦 项目名称: cve-intelligence-bot
👤 项目作者: realsandeep1271-ui
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-01 05:45:47

📝 项目描述:
24/7 serverless CVE & CISA KEV threat intel bot with EPSS scoring, GitHub PoC search, and Telegram alerts

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSTI #RCE

📦 项目名称: render
👤 项目作者: het-P301204
🛠 开发语言: TypeScript
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-09-30 21:53:15

📝 项目描述:
SSTI Security Research Platform — 5-stage attack chain across Jinja2, Handlebars, Nunjucks & Mako · FastAPI + React+TS+Vite

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Docker #Exploit

📦 项目名称: AirCard-Windows
👤 项目作者: Lauracol26
🛠 开发语言: Rust
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-01 06:06:23

📝 项目描述:
Skin and theme Apple Wallet cards and lockscreen passcodes on iOS 18+ from Windows—no jailbreak needed.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #RCE

📦 项目名称: CVE-2026-58138-Research
👤 项目作者: Ez4rd1x1
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-01 06:57:10

📝 项目描述:
critical-severity unauthenticated Remote Code Execution (RCE) vulnerability impacting Orkes Conductor

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: python-vulnerability-scanner
👤 项目作者: mjibral466
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-01 07:03:09

📝 项目描述:
Lightweight web security scanner & TCP port scanner written in Python.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC #Exploit

📦 项目名称: CVE-2026-92966
👤 项目作者: murrez
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-01 07:39:07

📝 项目描述:
CVE-2026-92966 — WordPress LatePoint ≤5.7.0 unauthenticated stored shortcode execution (CVSS 9.1, CWE-94). PoCbit mass-exploit PoC: plant [caption]/custom shortcode in booking first name → Customer Cabinet block double do_shortcode; fixed in 5.7.1. No API key. check/exploit/mass, hits.txt & exploited.txt, https://pocbit.org/pocs/cve-2026-92966

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #malware

📦 项目名称: vishwas
👤 项目作者: DawnofGenX
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-01 08:02:28

📝 项目描述:
WhatsApp-first verification & safety platform — checks URLs, files, images, audio, video & govt docs; deepfake detection, malware analysis, zero-cloud, CPU-only

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #漏洞 #POC #复现 #CVE

📦 项目名称: VulWiki
👤 项目作者: Ares-X
🛠 开发语言: Unknown
⭐ Star数量: 216 | 🍴 Fork数量: 72
📅 更新时间: 2026-10-01 07:35:30

📝 项目描述:
中文漏洞知识库,整理 Web、中间件、网络设备与系统漏洞的原理和公开复现资料,支持按产品、CVE、指纹检索。Chinese vulnerability knowledge base.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #0day #漏洞

📦 项目名称: coruna
👤 项目作者: dashen666666-gif
🛠 开发语言: JavaScript
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-01 08:12:49

📝 项目描述:
专注追踪2026最新 iOS Coruna漏洞 及 DarkSword 0day 动向

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XXE #CVE

📦 项目名称: CVE-2026-88789
👤 项目作者: oscerd
🛠 开发语言: Java
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-01 10:33:28

📝 项目描述:
Reproducer for CVE-2026-88789 (Apache Camel Quarkus camel-quarkus-support-xalan drops the JAXP external access restrictions, XXE / SSRF) — Camel Quarkus

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #malware

📦 项目名称: windows-malware-analysis-yara
👤 项目作者: AbhishekReddy23
🛠 开发语言: YARA
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-01 10:25:03

📝 项目描述:
malware-analysis, yara, reverse-engineering, mitre-attack, blue-team

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #提权 #Kernel #CVE #POC

📦 项目名称: IQOO-neo7-ghostlock-43499
👤 项目作者: YUE546
🛠 开发语言: C
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-01 08:34:05

📝 项目描述:
基于CVE-2026-43499(ghostlock)的 iQOO Neo7 提权移植,希望能为5.10系内核的机型提供一些参考。

🔗 点击访问项目地址