GitHub 红队武器库🚨
13.3K subscribers
19 photos
7 videos
22K links
📦 GitHub 全球红队渗透资源中转站。
​旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
⚠️ 本频道仅供安全研究与授权测试使用。
Download Telegram
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Kubernetes #POC

📦 项目名称: POC-VAULT-ARGOCD
👤 项目作者: victor54454
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-20 13:05:11

📝 项目描述:
ArgoCD + Vault self-hosted injection de secrets via Vault Secrets Operator et auth Kubernetes. Chart Helm sans aucun secret en Git.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: wp2shell-cf-WAF-bypass
👤 项目作者: ASYquan
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-20 13:59:44

📝 项目描述:
wp2shell PoC with Cloudflare WAF bypass via body padding (CVE-2026-63030)

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: CVE-2026-49097
👤 项目作者: oscerd
🛠 开发语言: Java
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-20 13:42:24

📝 项目描述:
PoC reproducer for CVE-2026-49097 (Apache Camel camel-irc): the non-Camel-prefixed irc.sendTo header escapes the HTTP header filter and overrides the producer's configured channel, redirecting an IRC message to an attacker-chosen destination. Fixed in 4.14.8/4.18.3/4.21.0.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSTI #RCE

📦 项目名称: waf-bypass
👤 项目作者: nemesida-waf
🛠 开发语言: Python
Star数量: 1503 | 🍴 Fork数量: 186
📅 更新时间: 2026-07-20 13:09:00

📝 项目描述:
Check your WAF before an attacker does

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: vulnerability-scanner
👤 项目作者: AiHd1
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-20 13:45:27

📝 项目描述:
Educational project: Building a Vulnerability Scanner in Python

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: cve-2026-41940-PoC
👤 项目作者: soverineg
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-20 14:25:59

📝 项目描述:
A cPanel and WHM authentication bypassing tool

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC #Exploit

📦 项目名称: cve-2026-16219-croogo-lab
👤 项目作者: HELLBOY3110
🛠 开发语言: Shell
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-20 14:07:41

📝 项目描述:
无描述

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #RCE #POC

📦 项目名称: Fastjson-JsonType-RCE-PoC
👤 项目作者: Percivalll
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-20 15:00:25

📝 项目描述:
无描述

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #RCE #CVE

📦 项目名称: CVE-2026-63030-Wp2Shell
👤 项目作者: OffByOn3
🛠 开发语言: Python
Star数量: 4 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-20 14:57:27

📝 项目描述:
WordPress REST API SQLi to RCE (CVE-2026-63030)

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: local-vulnerability-scanner
👤 项目作者: abhi050206
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-20 14:16:29

📝 项目描述:
A Python-based local network vulnerability scanner that uses Nmap to detect active hosts, open ports, and insecure services, and generates an automated HTML report.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Shellcode #Inject

📦 项目名称: Thread-Map-Technique
👤 项目作者: ShlokBorad
🛠 开发语言: C++
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-20 14:33:42

📝 项目描述:
This is Thread Manuall mapping Technique Create By Shlok That Inject shellcode (dll hex) into process memory Using Direct Thread Hijacking

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #Exploit

📦 项目名称: CVE-2026-11374-check
👤 项目作者: BishopFox
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-20 15:53:14

📝 项目描述:
Detection script for CVE-2026-11374

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #Exploit #RCE

📦 项目名称: CVE-2026-42533-Config-Scanner
👤 项目作者: 0xCyberstan
🛠 开发语言: Python
Star数量: 6 | 🍴 Fork数量: 1
📅 更新时间: 2026-07-20 15:15:44

📝 项目描述:
Static config scanner that flags nginx configs vulnerable to the complex_value two-pass capture-clobbering bug (regex map + regex capture → heap overflow / info leak).

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #RCE #CVE #POC

📦 项目名称: PoC-Unauthenticated-RCE-in-WatchGuard-Fireware-12.7-Build-640389-CVE-2025-9242
👤 项目作者: UnusualGiraffe
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-20 15:19:28

📝 项目描述:
Version-pinned archival PoC for CVE-2025-9242 on WatchGuard Fireware 12.7 build 640389. Includes safe detection, offline payload analysis, and an explicitly gated reverse-shell exploit using a caller-supplied IPv4 callback endpoint.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #RCE #POC

📦 项目名称: Fastjson-JsonType-RCE-PoC
👤 项目作者: wouijvziqy
🛠 开发语言: Unknown
Star数量: 17 | 🍴 Fork数量: 56
📅 更新时间: 2026-07-20 16:01:13

📝 项目描述:
无描述

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: webscan
👤 项目作者: Linabourd
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-20 15:51:27

📝 项目描述:
A modular web vulnerability scanner written in Python.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Nuclei #template

📦 项目名称: Custom-Nuclei-Template
👤 项目作者: carsonchan12345
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-20 15:14:26

📝 项目描述:
无描述

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #POC #CVE

📦 项目名称: cve-2026-23550-poc
👤 项目作者: baktistr
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-20 16:03:52

📝 项目描述:
无描述

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: CVE-2026-49098
👤 项目作者: oscerd
🛠 开发语言: Java
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-20 16:39:56

📝 项目描述:
PoC reproducer for CVE-2026-49098 (Apache Camel camel-kafka): the non-Camel-prefixed kafka.OVERRIDE_TOPIC header escapes the upstream HTTP header filter and overrides the producer's configured topic, injecting an attacker-forged record onto a privileged Kafka topic (cross-topic injection). Fixed in 4.14.8/4.18.3/4.21.0.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #RCE

📦 项目名称: wp2shell-Wordpress-TOWN
👤 项目作者: lucifer0xf
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-20 16:28:28

📝 项目描述:
Unauthenticated Remote Code Execution (RCE) in WordPress Core allows attackers to execute arbitrary code without logging in by chaining CVE-2026-63030 and CVE-2026-60137, potentially leading to full site compromise.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Fastjson #RCE

📦 项目名称: fastjson-jsontype-rce-lab
👤 项目作者: dinosn
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-20 17:00:04

📝 项目描述:
Docker lab + one-payload exploit + defensive scanner for the fastjson 1.2.66-1.2.83 @JSONType remote-class-load RCE (SSRF->defineClass under Spring Boot LaunchedURLClassLoader; autoType OFF; parseObject binding is not a mitigation)

🔗 点击访问项目地址