GitHub 红队武器库🚨
14.3K subscribers
25 photos
10 videos
27.8K links
​📦 GitHub 全球红队渗透资源中转站。
​旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
​⚠️ 本频道仅供安全研究与授权测试使用。
Download Telegram
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Shellcode #Inject

📦 项目名称: RustyShell
👤 项目作者: LostAquilae
🛠 开发语言: Rust
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-09 19:53:23

📝 项目描述:
Custom Shellcode Template in Rust

🔗 点击访问项目地址
👍1
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #metadata

📦 项目名称: attack-sandbox
👤 项目作者: divyanaras
🛠 开发语言: JavaScript
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-09 20:00:18

📝 项目描述:
Authorized hackathon honeypot: SSRF -> fake cloud metadata -> excessive-permissions chain on Akash

🔗 点击访问项目地址
👍1
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #metadata

📦 项目名称: superiorAPI
👤 项目作者: saifGawdat
🛠 开发语言: TypeScript
⭐ Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-09 20:57:35

📝 项目描述:
Black-box API performance profiler: Go benchmark engine with SSRF protection and a live Next.js report

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #metadata

📦 项目名称: typo3_http_guard
👤 项目作者: netresearch
🛠 开发语言: PHP
⭐ Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-09 20:17:28

📝 项目描述:
Plug-and-play SSRF protection for TYPO3's HTTP client, with default private-network blocking and classic TER installation - by Netresearch

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #Reflected

📦 项目名称: librebugbounty
👤 项目作者: tfgrass
🛠 开发语言: PHP
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-09 21:39:41

📝 项目描述:
Self-hosted bug bounty workspace for reflected XSS: URL intake, automated rechecks, Playwright screenshot evidence, manual triage, statistics, and disclosure-ready exports. Local-first, PHP/Symfony + SQLite.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #C2 #Beacon

📦 项目名称: beacon-hunt
👤 项目作者: AshongLabs
🛠 开发语言: HTML
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-09 22:03:16

📝 项目描述:
Browser-based log analysis exercise: find the host beaconing to a C2 server. Synthetic data.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #rules

📦 项目名称: compiler-design-and-language-tools
👤 项目作者: arseniy-maymistov
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-09 21:36:06

📝 项目描述:
Compiler construction and formal language processing. Projects include lexical and syntax analysis with Flex/Bison, abstract syntax tree generation, translation of a C-like language into x86-64 assembly, compiler implementation, and parsing of YARA detection rules.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: CVE-2026-84520
👤 项目作者: csrXamfi
🛠 开发语言: C
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-10 00:45:45

📝 项目描述:
AppleFDEKeyStore poc

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Log4j #CVE

📦 项目名称: cve-2021-44228
👤 项目作者: corelight
🛠 开发语言: Zeek
⭐ Star数量: 19 | 🍴 Fork数量: 9
📅 更新时间: 2026-10-10 00:30:06

📝 项目描述:
Log4j Exploit Detection Logic for Zeek

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #rules

📦 项目名称: lumma-go-analysis
👤 项目作者: ArtfulDodger10
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-10 01:55:08

📝 项目描述:
Static unpacker, config extractor, YARA rules and IOCs for a Lumma Stealer chain delivered by a Go process-hollowing loader

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #弱口令 #口令 #密码

📦 项目名称: WebCrack-plus
👤 项目作者: Curator-Kim
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-10 02:23:56

📝 项目描述:
WebCrack是一款web后台弱口令/万能密码批量检测工具,在工具中导入后台地址即可进行自动化检测。

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Shellcode #Loader

📦 项目名称: first_shell_loader
👤 项目作者: Taepe13
🛠 开发语言: C
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-10 02:17:42

📝 项目描述:
A classis shellcode and simple loader written in pure C with using WinAPI and XOR-encryption.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Exploit #POC

📦 项目名称: pymap
👤 项目作者: Edxx1
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-10 03:00:23

📝 项目描述:
pymap - sqlmap-style SQL injection discovery & exploitation toolkit (scanner + exploiter)

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #漏洞 #复现

📦 项目名称: llmxcpg-reproduction
👤 项目作者: bpeng2550-dot
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-10 03:54:39

📝 项目描述:
基于 LLMxCPG-D 的代码漏洞检测复现与离线部署:QwQ-32B 4-bit、公开 LoRA 适配器、FormAI 383 条评测与后续 CPG 流程复现。

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Kubernetes #POC

📦 项目名称: vks-poc-kit
👤 项目作者: edric45
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-10 04:00:47

📝 项目描述:
Portable GitOps POC kit for VMware vSphere Kubernetes Service (VKS): give a cluster name, ArgoCD brings up the cluster, add-ons and ingress.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC #Exploit

📦 项目名称: cve-2026-1668-poc
👤 项目作者: tangrs
🛠 开发语言: C
⭐ Star数量: 3 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-10 04:24:22

📝 项目描述:
Proof-of-concept exploit for CVE-2026-1668.

🔗 点击访问项目地址
👍1
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Exploit #CVE

📦 项目名称: kernel-security-learning
👤 项目作者: bsauce
🛠 开发语言: C
⭐ Star数量: 777 | 🍴 Fork数量: 87
📅 更新时间: 2026-10-10 04:43:12

📝 项目描述:
Anything about kernel security. CTF kernel pwn, kernel exploit, kernel fuzz and kernel defense paper, kernel debugging technique, kernel CVE debug.

🔗 点击访问项目地址
👍1
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #CVE #Stored #Reflected #DOM

📦 项目名称: sakuda
👤 项目作者: northraystudio
🛠 开发语言: TypeScript
⭐ Star数量: 2 | 🍴 Fork数量: 1
📅 更新时间: 2026-10-10 05:34:01

📝 项目描述:
Self-hosted DAST (dynamic application security testing) in one Docker image — OWASP ZAP, nuclei, katana, httpx and dalfox behind a Nuxt UI: authenticated SPA crawling, OpenAPI-driven active scans, per-engine reports with diffs and history. さくっとDAST.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: CJF
👤 项目作者: AVII-VERSE
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-10 06:06:38

📝 项目描述:
Advanced multi-threaded Clickjacking & security header vulnerability scanner with live PoC simulator.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: roblox-revival-scanner
👤 项目作者: poggersisskibidi
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-10 07:01:18

📝 项目描述:
A comprehensive vulnerability scanner for Roblox revival servers, detecting path traversal, RCE, exposed ports, and common misconfigurations

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #RCE #POC

📦 项目名称: AnyDesk-AnyPwn-RCE
👤 项目作者: mhtsec
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-10 06:55:06

📝 项目描述:
AnyDesk Linux 8.0.2 pre-auth heap overflow RCE (AnyPwn) — PoC with vulnerability analysis & reproduction notes (fixed in 8.0.3)

🔗 点击访问项目地址