GitHub 红队武器库🚨
14.3K subscribers
25 photos
10 videos
27.3K links
​📦 GitHub 全球红队渗透资源中转站。
​旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
​⚠️ 本频道仅供安全研究与授权测试使用。
Download Telegram
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #云元数据 #metadata

📦 项目名称: web-fetch-mcp
👤 项目作者: asd369932
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-02 09:47:54

📝 项目描述:
MCP server: SSRF-guarded web/JSON fetching for AI assistants. IP-class validation, 2MB cap, 20s timeout.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #Exploit

📦 项目名称: CVE-2026-57973
👤 项目作者: riddhimaan-sth404
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-02 09:56:52

📝 项目描述:
CVE-2026-57973 is a time-of-check to time-of-use (TOCTOU) race condition vulnerability in the Microsoft Windows Subsystem for Linux (WSL2) that allows an authorized local attacker to perform tampering.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #Exploit

📦 项目名称: RootMyVivo-rs
👤 项目作者: L-1124
🛠 开发语言: Rust
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-02 09:46:01

📝 项目描述:
Cross-platform pure-Rust toolchain for unlock-free temporary root and KernelSU late-loading on vivo/iQOO devices (CVE-2026-43499)

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #Reflected

📦 项目名称: pentrix-xss
👤 项目作者: mizazhaider-ceh
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-02 11:52:08

📝 项目描述:
Reflected XSS scanner with reflection context classification. Python 3, zero dependencies.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #Stored

📦 项目名称: bank-app
👤 项目作者: RataDarius
🛠 开发语言: PHP
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-02 11:58:12

📝 项目描述:
Deliberately vulnerable banking web app — a CTF / pentest lab. PHP + MySQL in Docker, admin session takeover via stored XSS, Puppeteer bot.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Burp #Extension

📦 项目名称: network-pentest
👤 项目作者: dotbiru
🛠 开发语言: Java
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-02 12:06:04

📝 项目描述:
Network penetration testing extension for Burp Suite - port scanning, service fingerprinting, vulnerability checks, credential testing

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Burp #Extension

📦 项目名称: burp-es-logger
👤 项目作者: cymetrics
🛠 开发语言: Kotlin
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-02 09:38:10

📝 项目描述:
无描述

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #Exploit

📦 项目名称: fortimail-zero-day-cve-2026-104286
👤 项目作者: techupdate24
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-02 12:48:07

📝 项目描述:
A complete guide and workflow for integrating Agile sprints with DevOps CI/CD pipelines.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #Stored #Reflected

📦 项目名称: OWASP-Top-10-Vulnerabilities-Simulation-Lab
👤 项目作者: edrees078
🛠 开发语言: HTML
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-02 12:35:24

📝 项目描述:
A local-only OWASP Top 10 training lab with intentionally vulnerable exercises in SQL injection, cross-site scripting (XSS), broken access control, and 7 more vulnerabilities, featuring PHP, JavaScript, and MySQL exercises for hands-on learning.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #C2 #Beacon

📦 项目名称: specter
👤 项目作者: 0xC9H
🛠 开发语言: C
⭐ Star数量: 5 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-02 12:50:36

📝 项目描述:
AdaptixC2 Windows x64 agent focused on EDR evasion - position-independent beacon (C/NASM, no CRT, single .text section) with encrypted sleep, indirect syscalls, hardware-breakpoint hooking, and malleable C2 profiles

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #RCE #CVE

📦 项目名称: CVE-2025-24801-GLPI-10.0.17-and-prior-Authenticated-RCE
👤 项目作者: kevenpanchal
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-02 12:11:42

📝 项目描述:
无描述

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: cve-2026-102268-poc
👤 项目作者: covepseng
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-02 13:20:27

📝 项目描述:
Exploitability PoC for CVE-2026-102-268 (PyJWT Asymmetric-PEM detection bypass).

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #提权 #CVE

📦 项目名称: CVE-2025-45737
👤 项目作者: Shinn-Home
🛠 开发语言: C++
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-02 13:52:49

📝 项目描述:
利用CVE-2025-45737漏洞,实现提权

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #RCE #CVE

📦 项目名称: metasploitable2-php-cgi-exploit
👤 项目作者: mujtaba815
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-02 13:32:38

📝 项目描述:
Exploited a known RCE vulnerability (PHP-CGI Argument Injection, CVE-2012-1823) on Metasploitable2 using Metasploit Framework, gained a shell, and documented post-exploitation

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #Reflected

📦 项目名称: XSS-Hunter
👤 项目作者: mizazhaider-ceh
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-02 13:33:47

📝 项目描述:
Exam-grade reflected-XSS fuzzer: threaded, grep-filter, Burp-aware, auto-detect. Python, zero dependencies.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #POC #CVE

📦 项目名称: CVE-2026-42589xCVE-2026-40281-PoC
👤 项目作者: codeb0ssx
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-02 14:05:55

📝 项目描述:
CVE-2026-42589 & CVE-2026-40281 - GotenBerg

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #漏洞 #利用

📦 项目名称: ghidra-skill-for-dsh
👤 项目作者: Cristallin2006
🛠 开发语言: Python
⭐ Star数量: 7 | 🍴 Fork数量: 1
📅 更新时间: 2026-10-02 11:42:24

📝 项目描述:
dsh (DeepSeek Harness) 逆向 agent skill 家族:Ghidra headless daemon + 分诊/脱壳/静态/漏洞/动态/流量/安卓七场景 | Reverse-engineering agent skills: triage, unpacking, decompile, pwn audit, pcap forensics, APK analysis

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #Exploit

📦 项目名称: netscaler_threat_hunt_helper
👤 项目作者: orjanj
🛠 开发语言: Shell
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-02 14:50:23

📝 项目描述:
NetScaler CTX697096 Threat Hunt Helper (IoC scanner) - CVE-2026-88771, CVE-2026-88772

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #RCE

📦 项目名称: CVE-2026-55559
👤 项目作者: MRdark-ops
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-02 14:33:27

📝 项目描述:
Unauthenticated RCE in Yamcs mission control via YAML injection in reconfigureInstance()

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #DOM

📦 项目名称: huellanativa
👤 项目作者: jocelin-portafolio
🛠 开发语言: JavaScript
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-02 14:32:22

📝 项目描述:
SPA en JavaScript vanilla: perfiles sensoriales para niños neurodivergentes, e-commerce con carrito persistente y monitor IoT simulado. Renderizado seguro sin innerHTML (anti-XSS).

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #RCE #CVE

📦 项目名称: CVE-2026-40281-exploit
👤 项目作者: MRdark-ops
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-02 14:26:07

📝 项目描述:
Gotenberg 8.30.1 unauthenticated RCE exploit

🔗 点击访问项目地址