GitHub 红队武器库🚨
13.3K subscribers
19 photos
7 videos
22K links
📦 GitHub 全球红队渗透资源中转站。
​旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
⚠️ 本频道仅供安全研究与授权测试使用。
Download Telegram
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: ai-vulnerability-scanner
👤 项目作者: mlyu2000
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-20 00:58:05

📝 项目描述:
Self-hosted AI web-app vulnerability scanner — HPE Private Cloud AI framework

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Exploit #CVE #RCE

📦 项目名称: h3x-dash
👤 项目作者: Null-H3x
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-20 01:07:43

📝 项目描述:
My penetration testing dashboard - runs nmap scans, msf exploitation, and loot the information in an easily digestible browser-based workflow.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #Exploit

📦 项目名称: nginx-map-risk-audit
👤 项目作者: srkyn
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-20 01:45:05

📝 项目描述:
Defensive NGINX CVE-2026-42533 map regex risk audit with config scanner, Splunk/Defender notes, and lab evidence.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #Exploit

📦 项目名称: CVE-2026-63030
👤 项目作者: administrator-01001
🛠 开发语言: Python
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-20 01:38:20

📝 项目描述:
Proof-of-concept exploit for CVE-2026-63030, a pre-authentication vulnerability in WordPress (versions 6.9.0 through 7.0.1).

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #C2 #Framework

📦 项目名称: higgsc2
👤 项目作者: ebx32
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-20 02:56:34

📝 项目描述:
A C2 Framework (for proof of concept)

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Shiro #EXP

📦 项目名称: pyshiro
👤 项目作者: wavtechyukky
🛠 开发语言: Jupyter Notebook
Star数量: 19 | 🍴 Fork数量: 1
📅 更新时间: 2026-07-19 20:15:28

📝 项目描述:
Python reimplementation of SHIRO phoneme-to-speech alignment toolkit for Japanese singing voice

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Shellcode #Execute

📦 项目名称: staticbypass
👤 项目作者: dodokaicho
🛠 开发语言: Python
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-20 02:15:09

📝 项目描述:
Template-based, modular, multi-language, shellcode obfuscator and compiler

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Shellcode #Execute

📦 项目名称: osed-windbg
👤 项目作者: rogdooley
🛠 开发语言: TypeScript
Star数量: 0 | 🍴 Fork数量: 1
📅 更新时间: 2026-07-20 01:30:58

📝 项目描述:
WinDbg JavaScript extension for x86 exploit development using pattern matching, ROP scanning, format-string payload generation, and shellcode encoding from the dx evaluator.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Spring #EXP

📦 项目名称: microservice-exp
👤 项目作者: harshbgupta
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-20 04:02:16

📝 项目描述:
A hands-on Spring Boot microservices playground for experimenting with production-grade distributed-systems patterns — service discovery, API gateway routing, centralized configuration, event-driven communication with Kafka, and resilience patterns — wired together locally with Docker Compose.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #Exploit

📦 项目名称: EXPLOIT-CVE-2026-63030
👤 项目作者: joaovicdev
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-20 04:59:00

📝 项目描述:
无描述

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #云元数据

📦 项目名称: h_claw
👤 项目作者: majehuang
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-20 03:23:34

📝 项目描述:
Hermes 一体化爬虫 MCP 服务:单进程 FastMCP + Scrapling 三层抓取 + PostgreSQL 缓存 + SSRF 防护

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Weblogic #POC

📦 项目名称: weblogic-poc
👤 项目作者: lightrun-platform
🛠 开发语言: Java
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-20 05:10:53

📝 项目描述:
无描述

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #BlueTeam #Response #Detection

📦 项目名称: NorthBridge-Manufacturing-Lateral-Movement-Investigation
👤 项目作者: ravesnoopy
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-20 05:37:58

📝 项目描述:
SOC investigation of a suspected lateral movement attack using Sysmon, Windows Event Logs, Elastic SIEM, and MITRE ATT&CK to analyze Living-off-the-Land (LotL) activity and reconstruct the attack timeline.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Bypass #EDR

📦 项目名称: ProcAudit-Engine
👤 项目作者: shubhangithakur07
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-20 06:03:42

📝 项目描述:
Bare-metal cybersecurity & edge telemetry engine. Bypasses Python interpreter bottlenecks using native C-Bridges, SIMD bitwise vectorization, and cache-aligned memory blocks for sub-millisecond O(1) anomaly triage.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Bypass #WAF

📦 项目名称: security-writeups
👤 项目作者: afuckingco
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-20 06:03:36

📝 项目描述:
Authorized bug bounty & security research writeups — methodology, recon, and detection-bypass case studies.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #RCE

📦 项目名称: wp2shell-checker
👤 项目作者: 0xjessie21
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-20 06:44:22

📝 项目描述:
WordPress Core Unauthenticated RCE (CVE-2026-63030, CVE-2026-60137)

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC #Exploit

📦 项目名称: wp2shell-scan
👤 项目作者: InstaWP
🛠 开发语言: Shell
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-20 06:27:01

📝 项目描述:
Detect & clean up wp2shell (CVE-2026-63030) WordPress compromise — bulk-runnable, read-only by default

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SQL注入 #漏洞 #POC #CVE

📦 项目名称: CVE-2025-57819-POC
👤 项目作者: Neobee714
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-20 06:32:01

📝 项目描述:
FreePBX 未认证SQL注入导致远程代码执行,FreePBX 15 (低于 15.0.66)、16 (低于 16.0.89)、17 (低于 17.0.3)。该漏洞位于商业化“endpoint”模块中,因对用户输入过滤不严,允许未认证的攻击者绕过管理员权限,执行SQL注入,并最终实现远程代码执行

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: web-cross
👤 项目作者: MacTash
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-20 06:40:42

📝 项目描述:
A comprehensive and growing web vulnerability scanner that aims to provide a professional report at the end of scanning

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: WebVulnerabilityScanner
👤 项目作者: sohailhassanjutt0011-cmyk7ik
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-20 06:39:03

📝 项目描述:
A Python-based Web Vulnerability Scanner that detects basic Reflected XSS vulnerabilities in authorized web applications. It analyzes responses, identifies potential vulnerabilities, and generates a report for educational and ethical cybersecurity testing.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Nuclei #漏洞

📦 项目名称: -LangGraph-Agent
👤 项目作者: LuckPony
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-20 06:21:37

📝 项目描述:
用户用自然语言描述目标、关注漏洞、资产重要性和扫描约束,系统先用规则或 LangChain 结构化输出转成 Intent,再通过授权、域名白名单、私网和 DNS 策略门。策略通过后调用 Mock 或受控 Nuclei 扫描器。Nuclei、ZAP、Nessus 报告会被归一化成统一 Finding,通过稳定指纹去重,然后结合 CVSS、资产重要性、证据置信度做确定性风险评分。最后从 Chroma 检索修复基线,生成带验证步骤的建议。整个流程有 11 个 LangGraph 节点,每个节点有审计事件。项目提供 Django REST API、Swagger、Web 页面、Docker Compose 和端到端测试。”

🔗 点击访问项目地址