GitHub 红队武器库🚨
13.3K subscribers
19 photos
7 videos
22K links
📦 GitHub 全球红队渗透资源中转站。
​旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
⚠️ 本频道仅供安全研究与授权测试使用。
Download Telegram
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Nuclei #template

📦 项目名称: Custom-Nuclei-Template
👤 项目作者: carsonchan12345
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-20 15:14:26

📝 项目描述:
无描述

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #POC #CVE

📦 项目名称: cve-2026-23550-poc
👤 项目作者: baktistr
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-20 16:03:52

📝 项目描述:
无描述

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: CVE-2026-49098
👤 项目作者: oscerd
🛠 开发语言: Java
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-20 16:39:56

📝 项目描述:
PoC reproducer for CVE-2026-49098 (Apache Camel camel-kafka): the non-Camel-prefixed kafka.OVERRIDE_TOPIC header escapes the upstream HTTP header filter and overrides the producer's configured topic, injecting an attacker-forged record onto a privileged Kafka topic (cross-topic injection). Fixed in 4.14.8/4.18.3/4.21.0.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #RCE

📦 项目名称: wp2shell-Wordpress-TOWN
👤 项目作者: lucifer0xf
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-20 16:28:28

📝 项目描述:
Unauthenticated Remote Code Execution (RCE) in WordPress Core allows attackers to execute arbitrary code without logging in by chaining CVE-2026-63030 and CVE-2026-60137, potentially leading to full site compromise.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Fastjson #RCE

📦 项目名称: fastjson-jsontype-rce-lab
👤 项目作者: dinosn
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-20 17:00:04

📝 项目描述:
Docker lab + one-payload exploit + defensive scanner for the fastjson 1.2.66-1.2.83 @JSONType remote-class-load RCE (SSRF->defineClass under Spring Boot LaunchedURLClassLoader; autoType OFF; parseObject binding is not a mitigation)

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Fastjson #RCE

📦 项目名称: 2026FastjsonPoC
👤 项目作者: ThanatosXingYu
🛠 开发语言: Java
Star数量: 4 | 🍴 Fork数量: 4
📅 更新时间: 2026-07-20 16:56:43

📝 项目描述:
【已复现】Fastjson 1.2.66–1.2.83 JsonType 纯库一键 RCE(AutoType 关闭仍可利用;完整 RCE 需 JDK8 + Spring Boot LaunchedURLClassLoader)。仅限授权安全研究与本地防御验证。

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #渗透测试 #漏洞

📦 项目名称: SecAtlas
👤 项目作者: shuaiqideyu
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-20 16:42:35

📝 项目描述:
SecAtlas:系统整理网络渗透测试基础、漏洞原理、实战方法与案例的中文学习资料库。

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #rules #malware

📦 项目名称: malware-analysis
👤 项目作者: exhaustingsky
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-20 16:32:31

📝 项目描述:
Static malware analysis reports, YARA rules and IOCs

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #rule #malware

📦 项目名称: Automated-Malware-Detection-Platform
👤 项目作者: zainalvi95
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-20 16:26:21

📝 项目描述:
This is the malware detection platform user just upload the malware and check the malware risk level, file type and this tool generate the Snort rule, YARA rule and also extract the string and user can download the analysis report. It is the static analysis tool so user can safely analyse the malware.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: Keke
👤 项目作者: MonkeySeC-sys
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-20 16:43:38

📝 项目描述:
A lightweight web vulnerability scanner built for educational research and authorized network testing

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC #Exploit

📦 项目名称: CVE-2026-44680-MikroORM-SQL-Injection-Exploit-Framework
👤 项目作者: CerberusMrXi
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-20 17:56:25

📝 项目描述:
PoC tool for CVE-2026-44680 affecting MikroORM ≤7.0.13. Exploits JSON path injection to extract database contents via UNION-based attacks. Features vulnerability detection, automated data extraction, table enumeration, and blind injection support. Includes proxy integration for Burp Suite and WAF evasion techniques.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: Basic-Vulnerability-Scanner-IIT-jammu-Project-
👤 项目作者: Obscure-07
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 1
📅 更新时间: 2026-07-20 17:59:46

📝 项目描述:
A Python-based banner grabbing vulnerability scanner built using sockets.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Fastjson #RCE

📦 项目名称: fastjson-1.2.83-rce
👤 项目作者: 0x7eTeam
🛠 开发语言: Java
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-20 17:32:12

📝 项目描述:
Fastjson 1.2.68 ~ 1.2.83 RCE

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Fastjson #RCE #POC

📦 项目名称: Fastjson-JsonType-RCE-Demo
👤 项目作者: fzypl
🛠 开发语言: Java
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-20 17:07:19

📝 项目描述:
Fastjson-JsonType-RCE-PoC

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Burp #Extension

📦 项目名称: burp-suite-executor-scripts-2026
👤 项目作者: felixhillebqw2716
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-20 18:05:03

📝 项目描述:
Reusable Burp Suite scripts for security testers, with automation snippets, extension examples, and targeted utilities collected in one repository.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #CVE

📦 项目名称: Aegis-tool
👤 项目作者: maxi-schaefer
🛠 开发语言: Go
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-20 17:21:18

📝 项目描述:
Authorized-use security assessment pipeline: subdomain enum, port/service fingerprinting, TLS/header checks, sensitive-path & XSS/SQLi detection, CVE correlation, and takeover detection, with an interactive HTML report.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC #Exploit

📦 项目名称: CVE-2026-63030
👤 项目作者: Ch4120N
🛠 开发语言: Python
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-20 18:41:40

📝 项目描述:
CVE-2026-63030 - WordPress REST Batch Route-Confusion SQL Injection Proof of Concept

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #Exploit

📦 项目名称: YellowKey-Bitlocker-CVE-2026-45585
👤 项目作者: yellowkeys
🛠 开发语言: TypeScript
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-20 18:15:43

📝 项目描述:
YellowKey BitLocker CVE-2026-45585 is an open-source utility to extract, backup, and organize BitLocker recovery keys on Windows encrypted drives. Automate volume decryption, manage drive encryption states via command-line tools, export secure configuration files, and track recovery key logs. Download direct repository setup files.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Weblogic #EXP

📦 项目名称: adf-weblogic-clone-recovery
👤 项目作者: tagtuner
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-20 08:16:20

📝 项目描述:
无描述

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: Basic-Vulnerability-Scanner
👤 项目作者: Obscure-07
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-20 18:57:06

📝 项目描述:
A Python-based TCP banner grabbing vulnerability scanner using only the standard library.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: CVE-2026-12191
👤 项目作者: hakaioffsec
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-20 19:39:49

📝 项目描述:
PoC for CVE-2026-12191

🔗 点击访问项目地址