GitHub 红队武器库🚨
13.4K subscribers
19 photos
8 videos
22.4K links
📦 GitHub 全球红队渗透资源中转站。
​旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
⚠️ 本频道仅供安全研究与授权测试使用。
Download Telegram
🚨 GitHub 监控消息提醒

🚨 发现关键词: #漏洞 #扫描

📦 项目名称: ai-sast
👤 项目作者: pqfhappy
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-25 07:24:03

📝 项目描述:
AI-SAST: AI自动扫描漏洞

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: CVE-2026-50522
👤 项目作者: 4minx
🛠 开发语言: C#
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-25 08:54:12

📝 项目描述:
CVE-2026-50522 PoC

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #免杀 #Evasion

📦 项目名称: apk-antivirus-evasion-20260725
👤 项目作者: scdnai
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-25 09:01:40

📝 项目描述:
APK爆毒免杀处理方案 - https://www.133l.com

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: WPGhost
👤 项目作者: Mr-Destroyer
🛠 开发语言: Python
Star数量: 3 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-25 09:36:31

📝 项目描述:
A vulnerability Scanner and Exploiter for Wordpress based on CVE 2024-10924

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Nuclei #templates

📦 项目名称: nuclei-custom-templates
👤 项目作者: y0no
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-25 09:27:43

📝 项目描述:
Custom nuclei templates from authorized security assessments — full PoCs, version-based advisory triage, and exposure checks (Dolibarr and more).

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #漏洞 #POC

📦 项目名称: fastjson1283poc_public
👤 项目作者: Ape1ron
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-25 10:42:52

📝 项目描述:
Fastjson 1.2.83 漏洞验证环境 + POC + 调试。

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #Reflected

📦 项目名称: Reflected-xss
👤 项目作者: ea826827-beep
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-25 10:34:25

📝 项目描述:
无描述

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #DOM

📦 项目名称: XSS_SCANEER
👤 项目作者: zeroSlick
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-25 10:19:05

📝 项目描述:
Automated cross-site scripting vulnerability detector.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: vulnassess
👤 项目作者: mukidulislamzihad
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-25 10:45:44

📝 项目描述:
"Lightweight Python network + web vulnerability scanner with CLI and desktop GUI, automatic CVE lookup, and HTML/JSON reporting"

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: CVE-2026-65694-PoC
👤 项目作者: abdugafforov-bobur
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-25 11:34:23

📝 项目描述:
PoC for CVE-2026-65694 — Microweber CMS (<=2.0.20) unauthenticated path traversal → arbitrary file read (.env / secrets)

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: HexHunter
👤 项目作者: utkarsh206
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-25 11:39:59

📝 项目描述:
HexHunter is a lightweight and beginner-friendly web vulnerability scanner designed for basic penetration testing. It crawls websites and detects common vulnerabilities such as SQL Injection (SQLi) and Cross-Site Scripting (XSS).

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Fastjson #RCE

📦 项目名称: fastjson-1.2.83-rce-jar-generator
👤 项目作者: heihu577
🛠 开发语言: Java
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-25 11:32:47

📝 项目描述:
用于生成 fastjson 1.2.83 RCE 所需要的 Jar 包,含内存马注入功能。

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #RCE

📦 项目名称: CVE-2026-48908-Joomla-SP-Page-Builder-RCE
👤 项目作者: imXur
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-25 12:57:50

📝 项目描述:
Technical analysis and advisory for CVE-2026-48908: Unauthenticated Arbitrary File Upload to RCE in JoomShaper SP Page Builder.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC #RCE

📦 项目名称: CVE-2026-14266
👤 项目作者: liyuxuan504-byte
🛠 开发语言: PowerShell
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-25 12:32:43

📝 项目描述:
7-Zip XZ Decoder Heap Buffer Overflow - Full analysis, root cause, PoC, and RCE exploitation roadmap

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #C2 #Framework #Beacon

📦 项目名称: redops-hub-website
👤 项目作者: AbdoFawzi777
🛠 开发语言: Dart
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-25 13:03:23

📝 项目描述:
Mobile command center for Red Team operators. Vuln tracking, C2 monitoring, encrypted payload vault. Built with Flutter + Firebase.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #GitLab #EXP

📦 项目名称: glsec
👤 项目作者: glsec
🛠 开发语言: Go
Star数量: 19 | 🍴 Fork数量: 1
📅 更新时间: 2026-07-25 12:45:57

📝 项目描述:
Static security scanner and linter for GitLab CI. Finds .gitlab-ci.yml misconfigurations, supply-chain risks, and leaked secrets. Offline, SARIF output, OWASP CICD-SEC and CWE mappings.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #信息收集 #渗透

📦 项目名称: InformationCollecter-With-AI-analyzing
👤 项目作者: SilasWu50
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-25 12:59:56

📝 项目描述:
接入ai分析的集成信息收集工具,集成了多个主流github上优秀的信息收集工具,并通过ai进行自动化信息整理,精准高效暴露突破口给予渗透人员

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: Syntecxhub_Vulnerability_Scanner
👤 项目作者: Kalsoom-Gill
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-25 13:05:15

📝 项目描述:
A simple Python-based vulnerability scanner that detects open ports, identifies common services, checks possible security issues, and generates a scan report.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #NTLM Relay #AD

📦 项目名称: adscan
👤 项目作者: ADScanPro
🛠 开发语言: Python
Star数量: 492 | 🍴 Fork数量: 54
📅 更新时间: 2026-07-25 13:10:09

📝 项目描述:
Free Active Directory pentesting tool for Linux. Automates AD and LDAP enumeration, Kerberoasting, ASREPRoast, password spraying, ADCS/ESC1, DCSync, RBCD, gMSA, shadow credentials, NTLM relay and credential dumping across 104 techniques, mapping BloodHound-compatible attack paths to Domain Admin. NIS2 / ISO 27001 reports. No Windows needed.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #信息收集 #渗透

📦 项目名称: WebScanner-with-AI
👤 项目作者: SilasWu50
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-25 13:58:29

📝 项目描述:
这是一款接入ai分析的集成信息收集工具,集成了多个主流github上优秀的信息收集工具,并通过ai进行自动化信息整理,精准高效暴露突破口给予渗透人员

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Burp #Extension

📦 项目名称: Burp2Postman
👤 项目作者: tobiasGuta
🛠 开发语言: Java
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-25 13:30:41

📝 项目描述:
Burp2Postman is a Java/Montoya Burp Suite extension that sends selected HTTP requests directly to Postman. It does not export a collection file and does not hardcode workspace, collection, or folder IDs.

🔗 点击访问项目地址