GitHub 红队武器库🚨
14.3K subscribers
25 photos
11 videos
27.8K links
​📦 GitHub 全球红队渗透资源中转站。
​旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
​⚠️ 本频道仅供安全研究与授权测试使用。
Download Telegram
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #Reflected

📦 项目名称: VulnWatch
👤 项目作者: oluwaseyi-rgb
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-09 15:59:57

📝 项目描述:
headers, SSL, SQLi, XSS, CORS checks

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #DOM

📦 项目名称: skf-xss-dom
👤 项目作者: CyberCTF
🛠 开发语言: CSS
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-09 15:53:36

📝 项目描述:
OWASP SKF labs: DOM-Based Cross-Site Scripting lab, run with Isoloom

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #metadata

📦 项目名称: ogpreview-node
👤 项目作者: alianjum0
🛠 开发语言: JavaScript
⭐ Star数量: 4 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-09 16:25:48

📝 项目描述:
Node.js SEO and social metadata analyzer with safe URL fetching, API reports, previews, and automated tests.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Exploit #CVE

📦 项目名称: Penetration-testing-lab-001
👤 项目作者: cvonclark
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-09 16:52:28

📝 项目描述:
Project 001: Network Enumeration & Exploitation

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Nuclei #template #templates

📦 项目名称: webmeasy
👤 项目作者: Fad-X
🛠 开发语言: Rust
⭐ Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-09 15:57:15

📝 项目描述:
Rust-based web app enumeration tool: subdomain mapping, Nuclei scanning, backup/config fuzzing, .git exposure detection

🔗 点击访问项目地址
👍1
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #DOM

📦 项目名称: svg-sanitizer
👤 项目作者: Borewit
🛠 开发语言: Java
⭐ Star数量: 2 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-09 16:07:40

📝 项目描述:
SVG Sanitizer, preventing XSS

🔗 点击访问项目地址
👍1
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Confluence #CVE

📦 项目名称: AtlasSniper
👤 项目作者: ynsmroztas
🛠 开发语言: Python
⭐ Star数量: 7 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-09 16:04:55

📝 项目描述:
CVE-2026-21589 detector for Atlassian Data Center webresource traversal. Pre-auth webroot file read confirm for Jira, Confluence and Bitbucket.

🔗 点击访问项目地址
👍1
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Jenkins #CVE #EXP

📦 项目名称: grafana-cicd-monitoring
👤 项目作者: AmbujKRai
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-09 17:56:24

📝 项目描述:
Monitoring CI/CD pipeline performance and build metrics with Grafana, Prometheus, GitHub Actions and Jenkins

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: openvpn-container
👤 项目作者: ThaseG
🛠 开发语言: Shell
⭐ Star数量: 2 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-09 18:02:24

📝 项目描述:
Maintained OpenVPN community container with build-in exporter. Tested with vulnerability scanner and full e2e tests.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Spring #POC

📦 项目名称: payment-compliance-saga-orchestrator
👤 项目作者: gkiepuszewski
🛠 开发语言: Java
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-09 19:00:30

📝 项目描述:
Payment + Compliance (AML screening) saga PoC. A custom Java saga orchestrator coordinates two independently deployable Spring Boot microservices (payment-service, compliance-service) over plain REST calls, using the transactional Outbox/Inbox pattern for reliable, idempotent, at-least-once messaging without a broker.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Shellcode #Inject

📦 项目名称: RustyShell
👤 项目作者: LostAquilae
🛠 开发语言: Rust
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-09 19:53:23

📝 项目描述:
Custom Shellcode Template in Rust

🔗 点击访问项目地址
👍1
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #metadata

📦 项目名称: attack-sandbox
👤 项目作者: divyanaras
🛠 开发语言: JavaScript
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-09 20:00:18

📝 项目描述:
Authorized hackathon honeypot: SSRF -> fake cloud metadata -> excessive-permissions chain on Akash

🔗 点击访问项目地址
👍1
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #metadata

📦 项目名称: superiorAPI
👤 项目作者: saifGawdat
🛠 开发语言: TypeScript
⭐ Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-09 20:57:35

📝 项目描述:
Black-box API performance profiler: Go benchmark engine with SSRF protection and a live Next.js report

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #metadata

📦 项目名称: typo3_http_guard
👤 项目作者: netresearch
🛠 开发语言: PHP
⭐ Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-09 20:17:28

📝 项目描述:
Plug-and-play SSRF protection for TYPO3's HTTP client, with default private-network blocking and classic TER installation - by Netresearch

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #Reflected

📦 项目名称: librebugbounty
👤 项目作者: tfgrass
🛠 开发语言: PHP
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-09 21:39:41

📝 项目描述:
Self-hosted bug bounty workspace for reflected XSS: URL intake, automated rechecks, Playwright screenshot evidence, manual triage, statistics, and disclosure-ready exports. Local-first, PHP/Symfony + SQLite.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #C2 #Beacon

📦 项目名称: beacon-hunt
👤 项目作者: AshongLabs
🛠 开发语言: HTML
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-09 22:03:16

📝 项目描述:
Browser-based log analysis exercise: find the host beaconing to a C2 server. Synthetic data.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #rules

📦 项目名称: compiler-design-and-language-tools
👤 项目作者: arseniy-maymistov
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-09 21:36:06

📝 项目描述:
Compiler construction and formal language processing. Projects include lexical and syntax analysis with Flex/Bison, abstract syntax tree generation, translation of a C-like language into x86-64 assembly, compiler implementation, and parsing of YARA detection rules.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: CVE-2026-84520
👤 项目作者: csrXamfi
🛠 开发语言: C
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-10 00:45:45

📝 项目描述:
AppleFDEKeyStore poc

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Log4j #CVE

📦 项目名称: cve-2021-44228
👤 项目作者: corelight
🛠 开发语言: Zeek
⭐ Star数量: 19 | 🍴 Fork数量: 9
📅 更新时间: 2026-10-10 00:30:06

📝 项目描述:
Log4j Exploit Detection Logic for Zeek

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #rules

📦 项目名称: lumma-go-analysis
👤 项目作者: ArtfulDodger10
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-10 01:55:08

📝 项目描述:
Static unpacker, config extractor, YARA rules and IOCs for a Lumma Stealer chain delivered by a Go process-hollowing loader

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #弱口令 #口令 #密码

📦 项目名称: WebCrack-plus
👤 项目作者: Curator-Kim
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-10 02:23:56

📝 项目描述:
WebCrack是一款web后台弱口令/万能密码批量检测工具,在工具中导入后台地址即可进行自动化检测。

🔗 点击访问项目地址