GitHub 红队武器库🚨
14.3K subscribers
25 photos
10 videos
27.5K links
​📦 GitHub 全球红队渗透资源中转站。
​旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
​⚠️ 本频道仅供安全研究与授权测试使用。
Download Telegram
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Nuclei #template #templates #CVE

📦 项目名称: deckard
👤 项目作者: chainseer-xyz
🛠 开发语言: Go
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-05 16:33:37

📝 项目描述:
Self-hosted, always-on external attack-surface monitoring. Finds dangling DNS, subdomain takeovers, expiring certificates and exposed services across Cloudflare, AWS and Kubernetes. Alerts via Alertmanager.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #Stored #Reflected

📦 项目名称: security-research-library
👤 项目作者: gkdataio
🛠 开发语言: Python
⭐ Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-05 16:36:51

📝 项目描述:
Source-backed web security research and bug bounty disclosures: stored, reflected and blind XSS, SSRF, SSTI, API authorization, OAuth, AI integrations, diagrams and structured JSON.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #Reflected

📦 项目名称: Reflected-XSS-protected-by-CSP-with-CSP-bypass
👤 项目作者: gabrielhusa0-hash
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-05 16:16:34

📝 项目描述:
无描述

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #漏洞 #利用

📦 项目名称: NacosExploit
👤 项目作者: gandli
🛠 开发语言: Java
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-05 16:44:45

📝 项目描述:
Nacos 综合漏洞利用工具(重构版)

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: PySentinel
👤 项目作者: lekssayshamza
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-05 17:04:44

📝 项目描述:
A Python-based web vulnerability scanner for security testing and reconnaissance

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: Sqlmap
👤 项目作者: Counc
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-05 16:41:15

📝 项目描述:
A lightweight SQL injection vulnerability scanner

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #RCE

📦 项目名称: CVE-2026-31857
👤 项目作者: WhiteMachin3
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-05 17:57:56

📝 项目描述:
CVE-2026-31857 - Craft CMS authenticated RCE timing verifier.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #漏洞 #扫描 #复现 #利用 #CVE

📦 项目名称: gangmu
👤 项目作者: GANGMU-SBOM
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-05 17:17:40

📝 项目描述:
面向嵌入式 C/C++ 的构建期 SBOM 工具,配一份社区共建的芯片 SDK 组件识别规则库。 识别被芯片原厂改名、魔改、静态链接后的开源组件(包括国产芯片 SDK 与国密库), 生成 CycloneDX / SPDX 软件物料清单和 VEX,对照欧盟《网络弹性法案》(CRA)自查, 并起草 CRA 与工信部的漏洞报送材料。

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #CVE

📦 项目名称: CVE-2026-33534
👤 项目作者: EntroVyx
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-05 17:59:48

📝 项目描述:
EspoCRM 9.3.3 - Authenticated SSRF via Alternative IPv4 Notation

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #rules

📦 项目名称: sora-malvertising-analysis
👤 项目作者: anckhalion
🛠 开发语言: YARA
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-05 17:46:25

📝 项目描述:
Forensic analysis of a double Sora AI malvertising infection: Electron MaaS fake-installer kit + Braodo-like Python infostealer. IoCs, YARA rules, MITRE mapping. Research only, no samples.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #DOM

📦 项目名称: blog-frontend
👤 项目作者: vanshjain137
🛠 开发语言: JavaScript
⭐ Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-05 17:12:19

📝 项目描述:
A responsive React frontend for a full-stack blogging platform, equipped with DOMPurify for XSS protection and seamless content rendering.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #malware

📦 项目名称: inz-scan
👤 项目作者: Stephenmiles08
🛠 开发语言: JavaScript
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-05 18:58:59

📝 项目描述:
Detect and remove the NullReceiver / 'jsbot' npm supply-chain worm on developer machines (macOS + Linux). Covered packages: tailwindcss-motion-advanced, envpack-conf, postcss-initial-provider, agentgui, godot-kit, fluid-type-ui, bianira-ui, @kolbo/mcp. Single file, stdlib only, offline.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #rules

📦 项目名称: yara-rules
👤 项目作者: masterpaster1337
🛠 开发语言: YARA
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-05 18:08:40

📝 项目描述:
无描述

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #Reflected

📦 项目名称: AccuKnox-DVWA-Kubernetes
👤 项目作者: nandita-d
🛠 开发语言: Makefile
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-05 19:55:09

📝 项目描述:
Deployment of DVWA on a local Kubernetes cluster using Docker Desktop, Minikube, Kubernetes, and MetalLB, with validation of SQL Injection, Reflected XSS, and Command Injection vulnerabilities.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #rules

📦 项目名称: security-research
👤 项目作者: anckhalion
🛠 开发语言: YARA
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-05 20:05:16

📝 项目描述:
Independent cybersecurity research: case studies, IoCs, YARA rules, forensic methodology. Case 001: double Sora AI malvertising infection (Electron MaaS kit + Braodo-like infostealer).

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #C2 #Framework

📦 项目名称: Trinity
👤 项目作者: iamgred
🛠 开发语言: C#
⭐ Star数量: 3 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-05 21:00:00

📝 项目描述:
Trinity C2 Framework

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Burp #Extension

📦 项目名称: burp-mcp
👤 项目作者: N0K0
🛠 开发语言: Java
⭐ Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-05 19:08:03

📝 项目描述:
无描述

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #Stored

📦 项目名称: CCD-Retail-Breach
👤 项目作者: eth-hac-steven
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-05 21:02:49

📝 项目描述:
Network forensics write-up for CyberDefenders' CCD RetailBreach lab tracing a brute-force, stored XSS, session hijack, and LFI attack chain through PCAP analysis in Wireshark.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #Reflected

📦 项目名称: Reflected-XSS-into-HTML-context-with-most-tags-and-attributes-blocked
👤 项目作者: Alvking
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-05 23:55:54

📝 项目描述:
Reflected XSS into HTML context with most tags and attributes blocked

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #Reflected

📦 项目名称: CTH-PROTOTYPE-DEMO-TARGET-vulnerable-storefront
👤 项目作者: makshamsheer
🛠 开发语言: JavaScript
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-05 23:54:16

📝 项目描述:
CTH Secure Remediation Shell prototype: DELIBERATELY VULNERABLE demo target (lodash 4.17.15 + reflected XSS). Not for deployment. CTH fixes it on a branch and opens a draft PR.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #C2 #Beacon

📦 项目名称: Home-SOC-Lab
👤 项目作者: Feras52
🛠 开发语言: PowerShell
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-06 00:02:15

📝 项目描述:
A Tier-1 SOC Analyst investigation of a real-world malware capture (.pcap). Features victim host profiling, HTTP C2 beacon analysis, OSINT threat intelligence, custom Suricata IDS/IPS rule engineering, automated PowerShell host firewall containment, and a formal IR post-mortem report.

🔗 点击访问项目地址