GitHub 红队武器库🚨
13.3K subscribers
19 photos
7 videos
21.9K links
📦 GitHub 全球红队渗透资源中转站。
​旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
⚠️ 本频道仅供安全研究与授权测试使用。
Download Telegram
🚨 GitHub 监控消息提醒

🚨 发现关键词: #C2 #Framework

📦 项目名称: ToxNetV2
👤 项目作者: dsagt315fgvds
🛠 开发语言: C
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-18 19:59:39

📝 项目描述:
ToxNetV2 C2 framework with bot_stub scanner

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: abdal-cve-2026-63030
👤 项目作者: ebrasha
🛠 开发语言: Go
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-18 20:02:51

📝 项目描述:
Abdal CVE-2026-63030 is a professional WordPress vulnerability scanner designed to detect exposure to CVE-2026-63030 through version analysis and REST API security checks. Developed by Ebrahim Shafiei (EbraSha) for cybersecurity research, penetration testing, and WordPress security assessment.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #CVE

📦 项目名称: CVE-2025-68616-Detecting-and-Patching-an-SSRF-in-WeasyPrint-with-Wazuh
👤 项目作者: rauljvc8
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-18 20:04:53

📝 项目描述:
Hands-on vulnerability management case study: how Wazuh flagged a real SSRF (CVE-2025-68616) in WeasyPrint, and how I reproduced and patched it.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC #Exploit #RCE

📦 项目名称: CVE-2026-63030_PoC
👤 项目作者: ChiefYoru
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-18 20:59:27

📝 项目描述:
CVE-2026-63030 - WordPress Core Pre-Auth RCE Mass Exploit

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC #Exploit

📦 项目名称: wp2shell-scan
👤 项目作者: fullhunt
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-18 20:45:11

📝 项目描述:
A scanner and proof-of-concept toolkit for CVE-2026-63030 (wp2shell) - pre-authenticated remote code execution in WordPress core

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: CVE-2026-21628_PoC
👤 项目作者: ChiefYoru
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-18 21:49:58

📝 项目描述:
Unauthenticated Remote Code Execution in Astroid Framework 2.0.0 - 3.3.10 for Joomla

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC #RCE

📦 项目名称: wp2shell
👤 项目作者: JohenLastGen-JLG
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-18 21:39:44

📝 项目描述:
wp2shell - WordPress RCE & PoC (CVE-2026-63030 + CVE-2026-60137)

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #POC #CVE

📦 项目名称: CVE-2026-48939_PoC
👤 项目作者: ChiefYoru
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-18 22:02:51

📝 项目描述:
iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #RCE #CVE

📦 项目名称: wp2shell-detect
👤 项目作者: own2pwn-fr
🛠 开发语言: Python
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-18 21:36:14

📝 项目描述:
Blackbox, non-intrusive detector for wp2shell (WordPress core pre-auth RCE, CVE-2026-63030 / CVE-2026-60137). Detection only.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Burp #Extension

📦 项目名称: mohiteprathamesh369-a11y.github.io
👤 项目作者: mohiteprathamesh369-a11y
🛠 开发语言: HTML
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-18 21:32:10

📝 项目描述:
Automate security testing tasks with this curated collection of Burp Suite scripts, extension samples, and workflow helpers.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Burp #Extension

📦 项目名称: burp-suite-executor-scripts
👤 项目作者: mohiteprathamesh369-a11y
🛠 开发语言: HTML
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-18 21:31:07

📝 项目描述:
Automate Burp Suite tasks with this collection of extension scripts and security testing helpers for efficient web application assessments.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: CVE-2026-46420
👤 项目作者: Jvr2022
🛠 开发语言: Unknown
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-18 22:28:25

📝 项目描述:
PoC for CVE-2026-46420, command injection in shivammathur/setup-php via repository-controlled PHP version resolution.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC #RCE

📦 项目名称: CVE-2026-56291_PoC
👤 项目作者: ChiefYoru
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-18 22:12:23

📝 项目描述:
The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Bypass #EDR

📦 项目名称: awareness-edr-tamper-bypass
👤 项目作者: adios255
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-18 23:07:02

📝 项目描述:
无描述

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Bypass #Sandbox

📦 项目名称: mcp-proxy
👤 项目作者: sevket
🛠 开发语言: JavaScript
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-19 00:03:05

📝 项目描述:
Lightweight MCP proxy that consolidates multiple MCP servers into single meta-tools — bypass per-client tool limits without losing functionality

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: dependency-vulnerability-scanner
👤 项目作者: gustavogeraldelli
🛠 开发语言: Java
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-18 23:58:05

📝 项目描述:
Distributed dependency vulnerability scanner with Spring Boot, RabbitMQ, OSV API, scan history, Redis caching, and resilient asynchronous processing.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #DOM

📦 项目名称: dom-based-xss-lab
👤 项目作者: coolnn
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-18 23:06:46

📝 项目描述:
无描述

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: vulnerability-scanner
👤 项目作者: elidiosozinho
🛠 开发语言: Jupyter Notebook
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-19 00:16:58

📝 项目描述:
A Python-based web vulnerability scanner designed to detect security issues such as missing HTTP headers, insecure configurations, and basic web vulnerabilities.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Exploit #CVE

📦 项目名称: Vulnary
👤 项目作者: svemulapati
🛠 开发语言: TypeScript
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-19 02:04:41

📝 项目描述:
Newly published and newly exploited security vulnerabilities three times a day, translates each one from dense technical language into plain English, and surfaces the remediation that the source itself provides

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Exploit #CVE

📦 项目名称: Root-My-Galaxy-Payloads
👤 项目作者: BuSung-dev
🛠 开发语言: C
Star数量: 3 | 🍴 Fork数量: 1
📅 更新时间: 2026-07-19 02:00:53

📝 项目描述:
Signed device profiles, mobile exploit payloads, and KernelSU artifacts for Root My Galaxy

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #Stored

📦 项目名称: owasp-juice-shop-penetration-test
👤 项目作者: Vicks298
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-19 01:43:46

📝 项目描述:
Professional Web Application Penetration Test Report for OWASP Juice Shop including reconnaissance, enumeration, vulnerability assessment, exploitation, and remediation recommendations.

🔗 点击访问项目地址