GitHub 红队武器库🚨
13.4K subscribers
19 photos
8 videos
22.3K links
📦 GitHub 全球红队渗透资源中转站。
​旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
⚠️ 本频道仅供安全研究与授权测试使用。
Download Telegram
🚨 GitHub 监控消息提醒

🚨 发现关键词: #RCE #CVE

📦 项目名称: GuppY-exploit-rce
👤 项目作者: blue0x1
🛠 开发语言: PHP
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-25 01:18:45

📝 项目描述:
GuppY 6.00.10 CMS is vulnerable to Unrestricted File Upload allows remote attackers to execute arbitrary code by uploading a php file.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #Exploit

📦 项目名称: YellowKey-Bitlocker
👤 项目作者: tchuin2609
🛠 开发语言: TypeScript
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-25 02:52:58

📝 项目描述:
Manage BitLocker encrypted drives on Windows. Extract recovery keys, check encryption status, and apply security mitigations for CVE-2026-45585.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #漏洞 #利用 #CVE

📦 项目名称: GhostLock-for-OnePlus15T
👤 项目作者: cuteaplane
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-25 03:02:30

📝 项目描述:
(CVE-2026-43499)内核漏洞利用程序,适用于未解锁 Bootloader 的一加15T.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #漏洞 #扫描 #利用

📦 项目名称: Wireless-Security-Research-Knowledge-Base-In-depth-Analysis-of-Security-in-802.11-Protocol
👤 项目作者: t84RT
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-25 01:24:00

📝 项目描述:
本项目是一套 完整的无线安全研究知识库与实验平台,系统性地整理和分析了 802.11 协议族的安全架构、管理帧漏洞及纵深防御策略。内容涵盖: 802.11 管理帧体系深度解析(Beacon / Probe / Auth / Assoc / Deauth / Disassoc) Deauthentication / Disassociation 攻击的协议原理、帧结构、代码实现与工具实战 PMF(802.11w 受保护管理帧)的密码学防护机制与部署策略 WPA/WPA2/WPA3 认证与加密体系全链路对比 无线安全研究全景知识树(309 个知识点,12 大章节) ESP8266/ESP32 嵌入式平台上的完整实现代码

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #Exploit

📦 项目名称: UnPlus
👤 项目作者: No-22-Github
🛠 开发语言: C
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-25 03:57:48

📝 项目描述:
CVE-2026-43499 per-boot root exploit — core logic (arm64 Android GKI 6.6)

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Exploit #CVE

📦 项目名称: api
👤 项目作者: vulnersCom
🛠 开发语言: Python
Star数量: 371 | 🍴 Fork数量: 65
📅 更新时间: 2026-07-25 04:01:10

📝 项目描述:
Official Python SDK for the Vulners vulnerability-intelligence API — search CVEs, exploits and advisories (CVSS/EPSS/KEV), audit software, Linux/Windows hosts and SBOMs, and stream the whole graph. Typed sync + async clients, 100% v3-compatible, with a built-in MCP server for AI agents.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #rule #rules

📦 项目名称: HunterEngine
👤 项目作者: dreamsudo
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-25 03:03:29

📝 项目描述:
Deterministic, auditable threat-enrichment engine — maps phishing/BEC/insider lures to MITRE ATT&CK, generates YARA + STIX 2.1, with an optional Claude advisory layer.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Bypass #WAF

📦 项目名称: xssniper
👤 项目作者: Athexblackhat
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-25 05:02:07

📝 项目描述:
XSSniper is an enterprise-grade, automated penetration testing framework designed to detect exploit and report Cross-Site ns. WScripting (XSS) vulnerabilities in web applicatioith over 1500+ pre-installed payloads context-aware validation and advanced WAF bypass techniques XSSniper is the ultimate weapon for security professionals and bug hunters.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Bypass #WAF

📦 项目名称: agentrouter-opencode-proxy
👤 项目作者: Goodnessmbakara
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-25 05:01:37

📝 项目描述:
Local proxy that lets OpenCode use AgentRouter (agentrouter.org) by routing requests through Python sync httpx to bypass the Aliyun WAF fingerprint check

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #漏洞 #RCE #利用 #CVE

📦 项目名称: Vulnerability-Reports
👤 项目作者: hackliu
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-25 04:53:59

📝 项目描述:
安全漏洞审计报告集 | Security Vulnerability Assessment Reports

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: nidana
👤 项目作者: AbhigyanBaruah
🛠 开发语言: C++
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-25 05:38:20

📝 项目描述:
Architecture-neutral vulnerability scanner using ESIL and vector embeddings

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Shellcode #Inject #Execute #Evasion

📦 项目名称: shellcode-xor-encrypt
👤 项目作者: lfgrillo83
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-25 05:37:09

📝 项目描述:
无描述

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #metadata

📦 项目名称: hermes-trafilatura-plugin
👤 项目作者: jcjc81
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-25 05:37:13

📝 项目描述:
Hardened local Trafilatura web_extract provider for Hermes Agent — no API key, SSRF-safe, quality-gated

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #metadata

📦 项目名称: Basic-SSRF-Against-the-Local-Server-PortSwigger-Web-Security-Academy
👤 项目作者: pawan-9999
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-25 03:50:51

📝 项目描述:
A detailed write-up of the Basic SSRF Against the Local Server lab from PortSwigger Web Security Academy. This repository covers vulnerability identification, exploitation using Burp Suite, access to the internal admin interface through localhost, security impact, root cause analysis, remediation techniques, and key lessons for penetration testers.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #Exploit

📦 项目名称: CVE-2026-31431
👤 项目作者: LeoxSoft
🛠 开发语言: Shell
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-25 06:54:03

📝 项目描述:
🚀 CVE-2026-31431 - Linux Kernel AF_ALG + splice() Privilege Escalation Exploit (Zero-Day → Root Persistence)

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #漏洞 #复现

📦 项目名称: Vuln-Study
👤 项目作者: retongle-dev
🛠 开发语言: Python
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-25 06:58:50

📝 项目描述:
个人尝试复现的各种漏洞复现环境

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #malware

📦 项目名称: AI-Malware-Detection-System
👤 项目作者: vinay-kumar-sk
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-25 06:42:21

📝 项目描述:
AI-powered malware detection system built with Python, Streamlit, Machine Learning, YARA, and VirusTotal integration.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC #Exploit

📦 项目名称: CVE-2026-12960
👤 项目作者: l0lsec
🛠 开发语言: Shell
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-25 07:08:15

📝 项目描述:
CVE-2026-12960 - Improper Export of Android Application Components in the ASUS Router app (com.asus.aihome). PoC, exploit APK, video, and vendor report. Fixed in 1.0.0.9.74.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #信息收集 #渗透 #recon

📦 项目名称: AI-Recon-Agent
👤 项目作者: wnm795
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-25 07:51:46

📝 项目描述:
AI渗透测试信息收集 Agent,基于 LangGraph 状态驱动工作流,支持自然语言对话和 CLI 直扫。集成被动信息收集、主动扫描、NVD/CVE 向量知识库、漏洞匹配与 Markdown 报告生成,支持环境自检、缓存管理和快速同步 CVE 数据。

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #DOM

📦 项目名称: Movie-Streaming-Website
👤 项目作者: andreeaiban
🛠 开发语言: HTML
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-25 07:11:09

📝 项目描述:
Movie streaming website built with HTML, CSS, and JavaScript for CSCI 355, featuring genre-based browsing, a shopping cart, and full design documentation with wireframes and a whitepaper. This DOM-heavy, form-driven front end is where I got hands-on with the exact client-side mechanics that XSS and CSRF attacks specifically target.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #漏洞 #扫描

📦 项目名称: ai-sast
👤 项目作者: pqfhappy
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-25 07:24:03

📝 项目描述:
AI-SAST: AI自动扫描漏洞

🔗 点击访问项目地址