GitHub 红队武器库🚨
14.3K subscribers
25 photos
10 videos
27.4K links
​📦 GitHub 全球红队渗透资源中转站。
​旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
​⚠️ 本频道仅供安全研究与授权测试使用。
Download Telegram
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Shellcode #Loader

📦 项目名称: p3-crystal
👤 项目作者: joaovarelas
🛠 开发语言: C
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-03 07:11:35

📝 项目描述:
Crystal Palace PICO implementation of Process Parameter Poisoning (P³) — null-free shellcode injection via CreateProcessW parameter fields without VirtualAllocEx or WriteProcessMemory.

🔗 点击访问项目地址
👍1
🚨 GitHub 监控消息提醒

🚨 发现关键词: #POC #CVE

📦 项目名称: POC-CVE-2026-48842
👤 项目作者: XsanFlip
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-03 10:02:38

📝 项目描述:
CVE-2026-48842 Roundcube SQLi Verifier

🔗 点击访问项目地址
👍1
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #rules #malware

📦 项目名称: malware_scanner
👤 项目作者: Henil994
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-03 10:04:00

📝 项目描述:
A comprehensive Python-based malware scanner designed for cybersecurity professionals and enthusiasts. This tool recursively scans files and directories for suspicious keywords and patterns, leverages YARA rules for advanced malware detection, and integrates with VirusTotal's API to check file hashes against a global malware database.

🔗 点击访问项目地址
👍1
🚨 GitHub 监控消息提醒

🚨 发现关键词: #RCE #EXP

📦 项目名称: laravel_debug_rce_exp
👤 项目作者: ccdr4gon
🛠 开发语言: Python
⭐ Star数量: 2 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-03 09:33:17

📝 项目描述:
无描述

🔗 点击访问项目地址
👍1
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: web-vulnerability-scanner
👤 项目作者: codebyasad-asd
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-03 10:46:03

📝 项目描述:
Web Application Vulnerability Scanner for detecting SQL Injection, XSS, and security flaws

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Exploit #CVE

📦 项目名称: CVE-Exploits
👤 项目作者: d3adb3ef
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-03 10:55:51

📝 项目描述:
CVE exploit collections

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #漏洞

📦 项目名称: icome
👤 项目作者: simingmo
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-03 11:02:37

📝 项目描述:
项目支持源码、配置、测试、依赖、Git 历史及 Windows 系统审计,覆盖多种编程语言、配置文件和压缩包。可检测密钥泄露、注入风险、XSS、SSRF、弱配置、依赖漏洞等,并输出控制台、JSON、Markdown 和逐文件报告。当前规则主要基于文本匹配,适合基础安全检查,不能替代完整 SAST、DAST 或渗透测试。

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC #RCE

📦 项目名称: CVE-2026-4480-POC
👤 项目作者: saitoken241
🛠 开发语言: Python
⭐ Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-03 11:57:44

📝 项目描述:
smb spooler to RCE

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #Reflected #DOM

📦 项目名称: OWASP-Juice-Shop-Web-and-API-Security-Validation
👤 项目作者: anyaugo-200
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-03 11:23:19

📝 项目描述:
OWASP Juice Shop web and API security assessment with evidence-backed findings for SQL injection, XSS, IDOR, exposed files, and API disclosure.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: web-vulnerability-scanner
👤 项目作者: ashu307003-hub
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-03 11:39:22

📝 项目描述:
An interactive web vulnerability scanner built with Python and Streamlit to detect SQLi, XSS, open ports, and security headers.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: VulnScan
👤 项目作者: ArchitectOf82
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-03 11:23:45

📝 项目描述:
18-module read-only vulnerability scanner: CVE matching, binary audit, SBOM, fuzzer, web recon & more.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: Ghostlock-Honor70Pro
👤 项目作者: litianyuan-91
🛠 开发语言: C
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-03 12:59:35

📝 项目描述:
Honor 70 Pro privilege escalation PoC: GhostLock (CVE-2026-43499) but could not custom KernelSU module loading

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: CVE-2026-103648
👤 项目作者: EterNullSec
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-03 12:17:22

📝 项目描述:
CVE-2026-103648 | Path Traversal in image-downloader 4.3.0 | CVSS 9.1 Critical | CWE-22 | By EterNullSec

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #渗透测试 #漏洞

📦 项目名称: ArtCode
👤 项目作者: zhangjinxin-5454
🛠 开发语言: Batchfile
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-03 10:00:35

📝 项目描述:
本地优先的 AI 安全作战台 · 渗透测试 / 红蓝对抗 / 白盒审计(Windows)

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #malware

📦 项目名称: triage
👤 项目作者: Nesarf
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-03 13:03:53

📝 项目描述:
Static triage for an unknown executable: identify, unpack and report indicators. Never executes the target.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #Exploit

📦 项目名称: CVE-2026-19660-exploit
👤 项目作者: MRdark-ops
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-03 13:32:28

📝 项目描述:
Proof-of-concept scanner and exploit helper for CVE-2026-14378: unauthenticated administrator session takeover in the WordPress plugin DevKit Pro (dplugins) through a flawed user-switch “revert” flow.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #0day #POC #RCE

📦 项目名称: DbGate-cross-user-session-bypass
👤 项目作者: YonLiud
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-03 13:21:49

📝 项目描述:
zeroday PoC for authenticated account takeover and RCE in DbGate.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #DOM

📦 项目名称: JavaScript-AppSec-Lab
👤 项目作者: DEEPANSHU111-source
🛠 开发语言: HTML
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-03 13:57:39

📝 项目描述:
A practical JavaScript Application Security lab covering DOM XSS, postMessage, JWT handling, browser storage, Fetch/API analysis, CORS, WebSockets, prototype pollution and dynamic code execution.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #Stored

📦 项目名称: Luna
👤 项目作者: AlanNewberry
🛠 开发语言: Python
⭐ Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-03 13:34:51

📝 项目描述:
Luna - API Security Scanner. Modular Python tool for IDOR, authentication, SQL injection, XSS and HTTPS testing with structured JSON output.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Docker #Exploit

📦 项目名称: dvwa-devsecops-pipeline
👤 项目作者: janudaliyanage
🛠 开发语言: PHP
⭐ Star数量: 1 | 🍴 Fork数量: 1
📅 更新时间: 2026-10-03 14:03:56

📝 项目描述:
"DevSecOps pipeline securing DVWA (Damn Vulnerable Web App) — Docker containerisation, STRIDE threat modelling, exploit-and-fix remediation, and a CI/CD pipeline with SAST, dependency, secrets, and container scanning gates. IE3142 group project."

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #POC #metadata

📦 项目名称: fetchurlfence
👤 项目作者: ideator-labs
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-03 14:13:05

📝 项目描述:
POC: application-layer URL/IP fence for MCP-style fetch tools. Unguarded accepts cloud metadata; fenced rejects metadata and private redirect hops.

🔗 点击访问项目地址