GitHub 红队武器库🚨
13.4K subscribers
19 photos
8 videos
22.4K links
📦 GitHub 全球红队渗透资源中转站。
​旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
⚠️ 本频道仅供安全研究与授权测试使用。
Download Telegram
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #DOM

📦 项目名称: b0dj0xstrike
👤 项目作者: b0dj0x
🛠 开发语言: Python
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-25 23:59:31

📝 项目描述:
b0dj0xstrike is an all-in-one XSS vulnerability discovery tool that automates the entire attack chain: subdomain enumeration → port scanning → live host detection → link harvesting → JavaScript analysis → parameter discovery → XSS detection → payload generation → WAF bypass → DOM analysis → reporting.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Fscan #POC

📦 项目名称: FscanOutput-Beautify
👤 项目作者: Trivexqbk
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-25 23:46:37

📝 项目描述:
lightweight script to parse, clean, and beautify Fscan output results — optimized for large asset scans, helping pentesters quickly organize and analyze vulnerability scan data with structured reporting.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: vulneon-bot
👤 项目作者: abswood-creator
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-26 01:03:22

📝 项目描述:
VULNEON – AI-powered Web3 vulnerability scanner with void-wire cyberpunk style

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #malware

📦 项目名称: skauswatch
👤 项目作者: penguintechinc
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-26 03:00:37

📝 项目描述:
Cloud security platform: S3 malware scanning (ClamAV/YARA) with threat intelligence enrichment, vulnerability detection, EDR endpoint monitoring, enterprise secrets management with JIT access (IceBox), and AI-powered code review integration (Darwin).

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: Helios-Web-VulnScanner
👤 项目作者: HeinHtetZaw-hub
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-26 03:49:31

📝 项目描述:
An automated web application vulnerability scanner with CVSS v3.1 scoring, OWASP Top 10:2025 mapping, evidence-based findings, and professional security reports.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #malware

📦 项目名称: OffsetInspect
👤 项目作者: warpedatom
🛠 开发语言: PowerShell
Star数量: 36 | 🍴 Fork数量: 6
📅 更新时间: 2026-07-26 03:42:10

📝 项目描述:
PowerShell toolkit for AMSI/Defender detection-boundary analysis and static malware triage — maps byte offsets to detection triggers, plus YARA, entropy, string, and PE/imphash analysis. Companion to OffsetScan.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #malware

📦 项目名称: OffsetScan
👤 项目作者: warpedatom
🛠 开发语言: Rust
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-26 03:28:07

📝 项目描述:
Rust binary for corpus-scale static triage of PE files — entropy scoring, string extraction, and IOC detection. Companion to OffsetInspect

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: web-vulnerability-scanner
👤 项目作者: chuiki001
🛠 开发语言: HTML
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-26 04:45:49

📝 项目描述:
Lightweight multi-threaded Flask web vulnerability scanner and audit report generator

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: sentinel-cyber-core
👤 项目作者: selormwalker
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-26 04:41:28

📝 项目描述:
An advanced automated cybersecurity vulnerability scanner for network misconfigurations and security flaws.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #metadata

📦 项目名称: ssrf-guard
👤 项目作者: anatolyben
🛠 开发语言: JavaScript
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-26 04:54:12

📝 项目描述:
SSRF-safe URL validation and bounded, redirect-controlled HTTP fetch for untrusted outbound requests.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #POC #CVE

📦 项目名称: cve-poc-mapper
👤 项目作者: eavil666
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-26 05:05:07

📝 项目描述:
CVE PoC 情报聚合平台

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: bughunter-ai
👤 项目作者: Nexreaper
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-26 05:54:32

📝 项目描述:
AI-powered security vulnerability scanner. Scans websites for XSS, SQL injection, and more. Built with FastAPI + Next.js.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: pentool
👤 项目作者: docxqwerty
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-26 05:51:23

📝 项目描述:
A modern, console-based web penetration testing toolkit with a TUI. Features an HTTP/HTTPS proxy, active/passive vulnerability scanner, Repeater, Intruder, Spider, and more. Free & open-source.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #Reflected

📦 项目名称: web-attack-toolkit
👤 项目作者: JIMIT-PARIKH-01
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-26 05:53:55

📝 项目描述:
Web app testing: content discovery, fingerprint, SQLi, XSS (authorized use)

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Exploit #CVE

📦 项目名称: Exploit-diary
👤 项目作者: Arjun-7x
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-26 06:52:23

📝 项目描述:
Hands-on penetration testing writeups from my home lab — real exploits, real methodology.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #RCE

📦 项目名称: CVE-2026-58480-Blocksy-Companion-Pro-RCE
👤 项目作者: shinthink
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-26 08:59:37

📝 项目描述:
CVE-2026-58480 / CVE-2026-15158 — Unauthenticated RCE in Blocksy Companion Pro < 2.1.47 (300K+ installs). Pre-auth arbitrary file upload via double-extension bypass.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Jenkins #POC

📦 项目名称: jenkins-job-poc
👤 项目作者: Sasta-Jarvis
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-26 08:55:21

📝 项目描述:
Git-driven Jenkins job management proof of concept

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #rules #malware

📦 项目名称: malware-detector
👤 项目作者: Dev9269
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-26 08:45:00

📝 项目描述:
AI-powered PE malware detector — static analysis, YARA rules, Random Forest + EMBER 2381-feature ML, SHAP explainability

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Fastjson #RCE

📦 项目名称: Fastjson-JsonType-RCE-Tool
👤 项目作者: lianqingsec
🛠 开发语言: Java
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-26 09:04:52

📝 项目描述:
FastJson JsonType RCE 利用工具

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC #Exploit #RCE

📦 项目名称: CVE-2026-58480
👤 项目作者: shinthink
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-26 09:51:59

📝 项目描述:
CVE-2026-58480 / CVE-2026-15158 — Unauthenticated RCE in Blocksy Companion Pro < 2.1.47 (300K+ installs). Pre-auth arbitrary file upload via double-extension bypass.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #信息收集 #渗透 #子域名 #侦察 #recon

📦 项目名称: FindSomething-MCP
👤 项目作者: wodefox
🛠 开发语言: JavaScript
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-26 06:23:48

📝 项目描述:
解决安全人员在面对AI信息收集疏忽导致的攻击不全面的问题

🔗 点击访问项目地址