GitHub 红队武器库🚨
13.3K subscribers
19 photos
7 videos
22K links
📦 GitHub 全球红队渗透资源中转站。
​旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
⚠️ 本频道仅供安全研究与授权测试使用。
Download Telegram
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: vcpkg-vuln-scan
👤 项目作者: emabrey
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-20 09:50:11

📝 项目描述:
A small vulnerability scanner for projects that get their C/C++ dependencies from vcpkg

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC #RCE

📦 项目名称: wp2shell-poc
👤 项目作者: OffByOn3
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-20 10:59:37

📝 项目描述:
WordPress REST API SQLi to RCE (CVE-2026-63030)

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #Exploit #RCE

📦 项目名称: sxwp2shell
👤 项目作者: SentinelXofficial
🛠 开发语言: Python
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-20 10:49:08

📝 项目描述:
WordPress wp2shell pre-auth RCE exploit kit (CVE-2026-63030 + CVE-2026-60137)

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #漏洞 #复现

📦 项目名称: web-security-lab
👤 项目作者: genius1h
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-20 11:01:55

📝 项目描述:
「Web安全学习笔记与漏洞攻防手册,含 SQL注入/XSS/CSRF/SSRF/文件上传/命令注入 6类漏洞的复现、检测与防御方案。」

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #rule

📦 项目名称: yara-rule-generator
👤 项目作者: fetihcakmak
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-20 10:38:03

📝 项目描述:
无描述

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Burp #Extension

📦 项目名称: burpforge
👤 项目作者: Gopesh-K
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-20 10:14:22

📝 项目描述:
AI-assisted Burp Suite extension with JWT decoder, secret scanner, CVSS calculator, and more...

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Exploit #POC

📦 项目名称: tornado-cash-exploit
👤 项目作者: pcaversaccio
🛠 开发语言: Solidity
Star数量: 63 | 🍴 Fork数量: 11
📅 更新时间: 2026-07-20 10:48:06

📝 项目描述:
This repository implements a simplified PoC that showcases how a contract can morph. A similar approach was used as part of the governance attack on Tornado Cash in May 2023.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Exploit #POC

📦 项目名称: malleable-signatures
👤 项目作者: pcaversaccio
🛠 开发语言: Solidity
Star数量: 113 | 🍴 Fork数量: 9
📅 更新时间: 2026-07-20 10:46:52

📝 项目描述:
This repository implements a simplified PoC that demonstrates how signature malleability attacks using compact signatures can be executed.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #Exploit

📦 项目名称: CVE-2026-5029-Exploit
👤 项目作者: 0x00phantom-hat
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-20 11:55:34

📝 项目描述:
无描述

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC #Exploit #RCE

📦 项目名称: wp2shell-lab
👤 项目作者: dinosn
🛠 开发语言: Python
Star数量: 31 | 🍴 Fork数量: 8
📅 更新时间: 2026-07-20 09:43:13

📝 项目描述:
Non-destructive detector + Docker lab for wp2shell (CVE-2026-63030 REST /batch/v1 route confusion + CVE-2026-60137 author__not_in SQLi) in WordPress core 6.9.0-6.9.4 / 7.0.0-7.0.1

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Nuclei #CVE

📦 项目名称: router-cve-audit
👤 项目作者: gluckdev
🛠 开发语言: Python
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-20 11:44:18

📝 项目描述:
Defensive CVE audit toolkit for consumer/SOHO routers (MikroTik, TP-Link, Huawei, D-Link, ASUS, Zyxel, Keenetic, Ubiquiti). Detection only - no exploitation. Project Discovery nuclei + Python collectors.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: Vulnerability-Scanner
👤 项目作者: misdivya31-collab
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-20 11:37:12

📝 项目描述:
无描述

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: CVE-2026-49086
👤 项目作者: oscerd
🛠 开发语言: Java
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-20 12:14:26

📝 项目描述:
PoC reproducer for CVE-2026-49086 (Apache Camel camel-dapr): the pub/sub consumer copies the untrusted CloudEvent's pubsubName/topic into producer-routing headers, letting an attacker redirect a republished message to an arbitrary Dapr pub/sub component+topic (confused deputy). Fixed in 4.14.8/4.18.3/4.21.0.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: CVE-2026-50369
👤 项目作者: syxlox
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-20 12:02:37

📝 项目描述:
无描述

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #CVE #metadata

📦 项目名称: SSRF-Scanner
👤 项目作者: Dancas93
🛠 开发语言: Python
Star数量: 40 | 🍴 Fork数量: 11
📅 更新时间: 2026-07-20 09:44:41

📝 项目描述:
A Complete SSRF (Server Side Request Forgery) Scanner.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #漏洞 #POC

📦 项目名称: Class02-SQL-Injection-Fix-Report
👤 项目作者: fankfc
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-20 13:01:28

📝 项目描述:
SQL 注入漏洞发现、POC 验证与参数化查询修复全流程报告

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Kubernetes #POC

📦 项目名称: POC-VAULT-ARGOCD
👤 项目作者: victor54454
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-20 13:05:11

📝 项目描述:
ArgoCD + Vault self-hosted injection de secrets via Vault Secrets Operator et auth Kubernetes. Chart Helm sans aucun secret en Git.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: wp2shell-cf-WAF-bypass
👤 项目作者: ASYquan
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-20 13:59:44

📝 项目描述:
wp2shell PoC with Cloudflare WAF bypass via body padding (CVE-2026-63030)

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: CVE-2026-49097
👤 项目作者: oscerd
🛠 开发语言: Java
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-20 13:42:24

📝 项目描述:
PoC reproducer for CVE-2026-49097 (Apache Camel camel-irc): the non-Camel-prefixed irc.sendTo header escapes the HTTP header filter and overrides the producer's configured channel, redirecting an IRC message to an attacker-chosen destination. Fixed in 4.14.8/4.18.3/4.21.0.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSTI #RCE

📦 项目名称: waf-bypass
👤 项目作者: nemesida-waf
🛠 开发语言: Python
Star数量: 1503 | 🍴 Fork数量: 186
📅 更新时间: 2026-07-20 13:09:00

📝 项目描述:
Check your WAF before an attacker does

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: vulnerability-scanner
👤 项目作者: AiHd1
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-20 13:45:27

📝 项目描述:
Educational project: Building a Vulnerability Scanner in Python

🔗 点击访问项目地址