GitHub 红队武器库🚨
14.3K subscribers
25 photos
11 videos
27.5K links
​📦 GitHub 全球红队渗透资源中转站。
​旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
​⚠️ 本频道仅供安全研究与授权测试使用。
Download Telegram
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #rules #malware

📦 项目名称: malware-static-triage
👤 项目作者: ZakariaHibaoui2
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-05 14:43:26

📝 项目描述:
Static malware triage: magic-byte typing, entropy, strings/IOCs, pure-Python PE parser (sections, imports), YARA-style rules, capability vs evasion scoring. Validated on real Windows binaries.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #Exploit #RCE

📦 项目名称: CVE-2026-39987-Marimo-RCE
👤 项目作者: Industri4l-H3ll-Xpl0it3rs
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-05 15:58:24

📝 项目描述:
CVE-2026-39987 Exploit | by infrar3d

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: dependency-vulnerability-scanner
👤 项目作者: ZakariaHibaoui2
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-05 15:56:05

📝 项目描述:
Software composition analysis for Python, npm and Composer: OSV.dev lookups, built-in CVSS 3.1 calculator, alias-aware dedup, branch-aware fix versions, CI policy gates and CycloneDX 1.5 SBOM export.

🔗 点击访问项目地址
Forwarded from Channel Help
This media is not supported in your browser
VIEW IN TELEGRAM
🤩🤩🤩🤩 🤩🤩🤩🤩🤩
0审核|包出款🤩🤩🤩
东南亚大事件联合担保🤩🤩🤩🤩🤩(电子)

🤩亿级域名|78.COM
🤩官方飞投|充提自由
🔝实力派:78.COM 数字够短 品牌够大

🔥香港六合彩 · 独家盈利无上限!
🤩所有的特码🤩🤩倍
🤩连码三中三🤩🤩🤩倍
🤩百家乐全网最高起步返水🤩%
🤩电子|棋牌|捕鱼起步返水🤩.🤩%
🤩十三水|德州自主组队,无抽佣;
🏆电子单注🤩🤩🤩🤩U一拉;
⭐️百家乐真人视讯台红🤩🤩万U;

🚩诚招代理合作(二选一):
1、打码返佣,限指定平台;
2、占成模式,可自由选择占成比例及游戏平台;
🤩🤩🤩🤩:@DL78

💥高额战绩,巅峰记录持续刷新:
🥇PP电子|极速糖果1000
玩家游戏中购买30000u超级免费旋转,高倍爆奖,最终拿下378万U,已出款;

🥈PG电子|麻将胡了
又又又欧气爆棚,3000U一拉,连番触发,单局斩获193万U;

🥉香港六合彩|特码49倍
爱拼才会赢,大佬单码下注18万U,一注直接拿下本期最高派彩 882万U;

🤩CHOICE真人|原AG
西港盘总百家乐多轮连胜,战绩一路走高,两天累计已提款1200万U;

🤩🤩🤩🤩🤩🤩🤩🤩🤩

🤩🤩🤩🤩 : 78.COM 😀
🤩🤩🤩🤩 : @TG78
🤩🤩🤩🤩 : @DF78⭐关注领📱VIP
🤩🤩🤩🤩 : @KF78
Please open Telegram to view this post
VIEW IN TELEGRAM
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Shellcode #Evasion #EDR

📦 项目名称: Golopas
👤 项目作者: NitelPhyoe
🛠 开发语言: Go
⭐ Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-05 15:40:41

📝 项目描述:
A minimal Windows shellcode runner written in Go - loads base64 shellcode from disk or a remote URL, decodes it in memory, and executes it via VirtualAlloc + CreateThread. For authorized pentests and security research only. Use at your own risk.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #RCE #CVE #POC

📦 项目名称: FreePBX-Breaker
👤 项目作者: kelltich-756
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-05 16:03:53

📝 项目描述:
PoC y código automatizado para explotar CVE-2025-57819 en FreePBX. Demuestra la vulnerabilidad de Ejecución Remota de Código (RCE) mediante inyección de comandos en el sistema Asterisk. Ideal para entornos HackTheBox.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #malware

📦 项目名称: yara-malware-detector
👤 项目作者: ylimme714
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-05 16:20:09

📝 项目描述:
无描述

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Nuclei #template #templates #CVE

📦 项目名称: deckard
👤 项目作者: chainseer-xyz
🛠 开发语言: Go
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-05 16:33:37

📝 项目描述:
Self-hosted, always-on external attack-surface monitoring. Finds dangling DNS, subdomain takeovers, expiring certificates and exposed services across Cloudflare, AWS and Kubernetes. Alerts via Alertmanager.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #Stored #Reflected

📦 项目名称: security-research-library
👤 项目作者: gkdataio
🛠 开发语言: Python
⭐ Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-05 16:36:51

📝 项目描述:
Source-backed web security research and bug bounty disclosures: stored, reflected and blind XSS, SSRF, SSTI, API authorization, OAuth, AI integrations, diagrams and structured JSON.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #Reflected

📦 项目名称: Reflected-XSS-protected-by-CSP-with-CSP-bypass
👤 项目作者: gabrielhusa0-hash
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-05 16:16:34

📝 项目描述:
无描述

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #漏洞 #利用

📦 项目名称: NacosExploit
👤 项目作者: gandli
🛠 开发语言: Java
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-05 16:44:45

📝 项目描述:
Nacos 综合漏洞利用工具(重构版)

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: PySentinel
👤 项目作者: lekssayshamza
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-05 17:04:44

📝 项目描述:
A Python-based web vulnerability scanner for security testing and reconnaissance

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: Sqlmap
👤 项目作者: Counc
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-05 16:41:15

📝 项目描述:
A lightweight SQL injection vulnerability scanner

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #RCE

📦 项目名称: CVE-2026-31857
👤 项目作者: WhiteMachin3
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-05 17:57:56

📝 项目描述:
CVE-2026-31857 - Craft CMS authenticated RCE timing verifier.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #漏洞 #扫描 #复现 #利用 #CVE

📦 项目名称: gangmu
👤 项目作者: GANGMU-SBOM
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-05 17:17:40

📝 项目描述:
面向嵌入式 C/C++ 的构建期 SBOM 工具,配一份社区共建的芯片 SDK 组件识别规则库。 识别被芯片原厂改名、魔改、静态链接后的开源组件(包括国产芯片 SDK 与国密库), 生成 CycloneDX / SPDX 软件物料清单和 VEX,对照欧盟《网络弹性法案》(CRA)自查, 并起草 CRA 与工信部的漏洞报送材料。

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #CVE

📦 项目名称: CVE-2026-33534
👤 项目作者: EntroVyx
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-05 17:59:48

📝 项目描述:
EspoCRM 9.3.3 - Authenticated SSRF via Alternative IPv4 Notation

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #rules

📦 项目名称: sora-malvertising-analysis
👤 项目作者: anckhalion
🛠 开发语言: YARA
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-05 17:46:25

📝 项目描述:
Forensic analysis of a double Sora AI malvertising infection: Electron MaaS fake-installer kit + Braodo-like Python infostealer. IoCs, YARA rules, MITRE mapping. Research only, no samples.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #DOM

📦 项目名称: blog-frontend
👤 项目作者: vanshjain137
🛠 开发语言: JavaScript
⭐ Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-05 17:12:19

📝 项目描述:
A responsive React frontend for a full-stack blogging platform, equipped with DOMPurify for XSS protection and seamless content rendering.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #malware

📦 项目名称: inz-scan
👤 项目作者: Stephenmiles08
🛠 开发语言: JavaScript
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-05 18:58:59

📝 项目描述:
Detect and remove the NullReceiver / 'jsbot' npm supply-chain worm on developer machines (macOS + Linux). Covered packages: tailwindcss-motion-advanced, envpack-conf, postcss-initial-provider, agentgui, godot-kit, fluid-type-ui, bianira-ui, @kolbo/mcp. Single file, stdlib only, offline.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #rules

📦 项目名称: yara-rules
👤 项目作者: masterpaster1337
🛠 开发语言: YARA
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-05 18:08:40

📝 项目描述:
无描述

🔗 点击访问项目地址