GitHub 红队武器库🚨
13.3K subscribers
19 photos
7 videos
22K links
📦 GitHub 全球红队渗透资源中转站。
​旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
⚠️ 本频道仅供安全研究与授权测试使用。
Download Telegram
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Fastjson #RCE #POC

📦 项目名称: 2026FastjsonPoC
👤 项目作者: triplexlove
🛠 开发语言: Unknown
Star数量: 5 | 🍴 Fork数量: 71
📅 更新时间: 2026-07-21 03:26:13

📝 项目描述:
Fastjson 1.2.66-1.2.83 JsonType pure-library RCE PoC (AutoType off, JDK8 + Spring Boot LaunchedURLClassLoader). Authorized research only.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Exploit #POC

📦 项目名称: nodejs-supply-chain-attack-poc
👤 项目作者: unitnikolai
🛠 开发语言: JavaScript
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-21 03:57:45

📝 项目描述:
NodeJS reverse shell exploit // supply chain attack proof of concept - npm run preinstall -> breach

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: ScreenOff
👤 项目作者: Dere3046
🛠 开发语言: C
Star数量: 2 | 🍴 Fork数量: 1
📅 更新时间: 2026-07-21 04:52:17

📝 项目描述:
CVE-2026-52910 kernel crash PoC. screen goes off.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Fastjson #RCE #POC

📦 项目名称: fastjson-1.2.83-rce
👤 项目作者: hello0matter
🛠 开发语言: Java
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-21 04:48:14

📝 项目描述:
fastjson-1.2.83-rce poc 热乎的

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Fastjson #漏洞 #RCE #POC

📦 项目名称: 2026-Fastjson-RCE-PoC
👤 项目作者: KaiSa028
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-21 04:31:58

📝 项目描述:
伤害最小化测试是否存在此漏洞

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #漏洞 #扫描

📦 项目名称: baota-server-vulnerability-guard
👤 项目作者: belone1993
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-21 05:37:02

📝 项目描述:
宝塔服务器漏洞检测与分级修复插件:本地审计、备份回滚、维护窗口边界

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #POC #metadata

📦 项目名称: wp-ssrf-cloud-metadata
👤 项目作者: shinthink
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-21 05:34:34

📝 项目描述:
WordPress Core SSRF via Cloud Metadata Endpoint Bypass in wp_http_validate_url()

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: Ai-assited-client-side-web-vulnerability-scanner
👤 项目作者: Yuva-shreee
🛠 开发语言: HTML
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-21 06:37:54

📝 项目描述:
Developed a client-side Web Vulnerability Scanner that analyzes HTML and JavaScript to detect security issues like XSS, insecure eval(), and data exposure. Implemented DOM parsing, AST analysis, and OWASP-based risk scoring with automated fix suggestions and secure coding guidance.

🔗 点击访问项目地址
👍1
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC #RCE

📦 项目名称: CVE-2026-27971_POC
👤 项目作者: Ghalendar
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-21 07:59:18

📝 项目描述:
CVE-2026-27971 qwik rce

🔗 点击访问项目地址
👍1
🚨 GitHub 监控消息提醒

🚨 发现关键词: #C2 #Beacon

📦 项目名称: dns-https-c2-ueba-detection
👤 项目作者: Sushanth2624
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-21 07:56:21

📝 项目描述:
Capstone 2 — Behavioral Detection of Hidden DNS/HTTPS C2 Using UEBA and Multi-Indicator Analysis. All 7 phases (0-6) complete; deployed end-to-end (Zeek/Suricata/ES/Kibana). Result C>B>A: F1 1.00 vs 0.80 vs 0.67.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Fastjson #漏洞 #RCE #反序列化 #POC

📦 项目名称: Fastjson1.2.83-JsonType-RCE-Demo
👤 项目作者: w0x68y
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-21 07:53:02

📝 项目描述:
无描述

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Bypass #WAF

📦 项目名称: Script
👤 项目作者: hemalathasriram96-pentester
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-21 07:59:21

📝 项目描述:
A Python script for vulnerability scanning with double encoding and WAF bypass capabilities.

🔗 点击访问项目地址
👍1
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #malware

📦 项目名称: C52-CRUNCH-MALWARE
👤 项目作者: CODECRUNCHWORLDWIDE
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-21 07:51:55

📝 项目描述:
A free, open-source 12-week course on taking malware apart safely: static and dynamic analysis, disassembly, sandboxing, and YARA — strict

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #Exploit #RCE

📦 项目名称: n8n-cve-2026-21858
👤 项目作者: qianlijaingshan
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-21 08:56:22

📝 项目描述:
CVE-2026-21858 + CVE-2025-68613 — n8n unauthenticated file read to RCE exploit

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Nuclei #templates

📦 项目名称: security-templates
👤 项目作者: FURQANAHMAD34
🛠 开发语言: Shell
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-21 08:49:40

📝 项目描述:
DAST and SAST bug-bounty automation toolkit (secsuite.sh).

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Exploit #CVE

📦 项目名称: user999leak
👤 项目作者: congyu-bot
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-21 08:58:17

📝 项目描述:
CVE-2025-21479_Exploit.bin

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #Stored #Reflected

📦 项目名称: XSSweep
👤 项目作者: Calimeg
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-21 08:48:38

📝 项目描述:
Modern reflected & stored XSS scanner with automatic WAF bypass. Python 3.8+

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: CVE-2026-49365
👤 项目作者: oscerd
🛠 开发语言: Java
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-21 09:56:56

📝 项目描述:
PoC reproducer for CVE-2026-49365 (Apache Camel camel-netty-http / camel-undertow): muteException defaults to false, so an uncaught exception's full Java stack trace is returned to the HTTP client (CWE-209). Fixed in 4.14.8/4.18.3/4.21.0.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: CVE-2026-49099
👤 项目作者: oscerd
🛠 开发语言: Java
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-21 09:20:39

📝 项目描述:
PoC reproducer for CVE-2026-49099 (Apache Camel camel-salesforce): the non-Camel-prefixed sObjectQuery header escapes the HTTP header filter and overrides the producer's configured SOQL (SOQL injection / broken access control). Fixed in 4.14.8/4.18.3/4.21.0.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Bypass #WAF

📦 项目名称: agentrouter-setup-guide
👤 项目作者: marko1olo
🛠 开发语言: HTML
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-21 10:00:33

📝 项目描述:
Complete guide to run Claude Code CLI & VS Code with AgentRouter using a WAF bypass proxy

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #漏洞 #扫描

📦 项目名称: SentinelScan
👤 项目作者: gutddts
🛠 开发语言: TypeScript
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-21 09:56:08

📝 项目描述:
🔍 全栈漏洞扫描管理平台 — React + FastAPI,支持端口扫描/HTTP头检测/SSL验证/漏洞检测,可视化仪表盘与PDF报告

🔗 点击访问项目地址