GitHub 红队武器库🚨
13.4K subscribers
19 photos
8 videos
22.4K links
📦 GitHub 全球红队渗透资源中转站。
​旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
⚠️ 本频道仅供安全研究与授权测试使用。
Download Telegram
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Nuclei #templates #POC #CVE

📦 项目名称: penclaw
👤 项目作者: andupetcu
🛠 开发语言: TypeScript
Star数量: 2 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-27 06:28:48

📝 项目描述:
AI-powered penetration testing CLI — static analysis, dynamic scanning, and intelligent triage.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Nuclei #template #templates

📦 项目名称: orion-web-test
👤 项目作者: website-f
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-27 05:50:11

📝 项目描述:
Self-hosted toolkit to load-test & security-scan your own apps — any stack, sandboxed, Docker-based. Orchestrates k6, ZAP, Nuclei, nmap. Authorized testing only.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #Exploit

📦 项目名称: CVE-2026-57239
👤 项目作者: Paradoxis
🛠 开发语言: Rust
Star数量: 4 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-27 07:54:03

📝 项目描述:
Proof of concept exploit for CVE-2026-3775/CVE-2026-3780 and CVE-2026-57239 which lets you obtain NT AUTHORITY\SYSTEM rights via the Foxit PDF Reader updater service.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #钓鱼 #Phishing

📦 项目名称: phishing-detector
👤 项目作者: kamisheng
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-27 07:51:02

📝 项目描述:
基于 Spring Boot 4.0 + Spring AI 2.0 的钓鱼网站检测后端服务,通过大语言模型对网页内容进行语义分析,识别钓鱼/欺诈网站。

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #POC #CVE #RCE

📦 项目名称: CVE-2026-42533
👤 项目作者: imbas007
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-27 08:03:08

📝 项目描述:
nginx heap buffer overflow PoC — CVE-2026-42533 pre-auth RCE via two-pass capture clobbering. Crash confirmed on Ubuntu 24.04.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #漏洞 #利用

📦 项目名称: Web-Master-Lab
👤 项目作者: CHN-zlt-666
🛠 开发语言: PHP
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-27 07:52:16

📝 项目描述:
Web安全漏洞学习平台 | PHP + MySQL | OWASP Top 10 常见漏洞原理、利用与修复 | 个人首个安全项目

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #rules #APT

📦 项目名称: multistage-apt-sim
👤 项目作者: nizamshanidahammed-collab
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-27 08:56:34

📝 项目描述:
Internship task where I simulated a multi-stage APT — phishing, persistence, lateral movement, DNS tunnelling exfil — then switched to Blue Team and detected/investigated it using Security Onion, Wazuh, TheHive & Cortex, and MISP. Wrote Sigma & YARA rules and an IR report at the end.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #渗透测试 #内网 #靶场 #漏洞

📦 项目名称: Dual-Network-Penetration-Test
👤 项目作者: buzhimingdeaikun
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-27 08:53:58

📝 项目描述:
基于VMware搭建的双层网络渗透测试靶场环境(DMZ区+服务器区),包含Web漏洞挖掘、内网穿透代理搭建、Metasploit提权及安全告警联动。

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Burp #Extension

📦 项目名称: authorize-pro
👤 项目作者: PratikKaran23
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-27 08:28:00

📝 项目描述:
Enhanced fork of the Autorize Burp Suite extension — adds a 'Scope & Exclude' tab (in-scope-only filtering + URL/endpoint exclusion list).

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: Vulnerability-scanner
👤 项目作者: Yaswanthgorle47
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-27 09:57:30

📝 项目描述:
A Python-based vulnerability scanner that detects open ports, identifies running services, checks them against a local CVE database, and generates a security report. Built with Flask, it provides a simple web interface and downloadable scan reports.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #漏洞

📦 项目名称: mcp-sentinel
👤 项目作者: syltharion
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-27 09:51:17

📝 项目描述:
MCP Server Security Audit Engine — scan MCP servers for exec injection, path traversal, tool poisoning, SQL injection, command injection, SSRF vulnerabilities

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Burp #Extension

📦 项目名称: extension-in-the-loop
👤 项目作者: d0ge
🛠 开发语言: Java
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-27 10:44:50

📝 项目描述:
Burp Suite Extension Template that helps test Burp Suite code with real Montoya API.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #rules

📦 项目名称: yara-rules
👤 项目作者: luantq0
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-27 10:14:02

📝 项目描述:
无描述

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: CVE-2026-54121-CertiGhost
👤 项目作者: marcgoam
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-27 11:48:41

📝 项目描述:
CVE-2026-54121 (Certighost) AD CS DC-impersonation PoC. Patched SAN handling + MAQ-safe account reuse.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #metadata

📦 项目名称: Cloud-pentest-guide
👤 项目作者: abdallaabdalrhman
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-27 11:09:03

📝 项目描述:
Practitioner field guide + hands-on lab walkthrough for AWS, Azure, and GCP red teaming — IAM/Entra ID enumeration, privilege escalation, metadata SSRF, and automated tooling.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #BlueTeam #Response #Detection

📦 项目名称: tyrian-detection-pack
👤 项目作者: zshguy
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-27 11:10:54

📝 项目描述:
Sigma detections for real ATT&CK techniques, with a compiler that emits Wazuh, Splunk and Sentinel from one source. 36 rules, 33 techniques, MIT.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #应急响应 #取证

📦 项目名称: forensic-collector
👤 项目作者: stushansusu
🛠 开发语言: Python
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-27 12:02:23

📝 项目描述:
一个 Windows 桌面取证工具,用于快速采集计算机上的各类数字痕迹和证据,适合安全调查、应急响应和内部审计场景。

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #红蓝对抗 #演练

📦 项目名称: yuqing
👤 项目作者: simonliu1358
🛠 开发语言: TypeScript
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-27 11:28:35

📝 项目描述:
舆情演练红蓝对抗

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: Vaelion-XSS
👤 项目作者: pratikkhairnar160
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-27 12:02:52

📝 项目描述:
Advanced XSS vulnerability scanner using Selenium and real browser execution verification for authorized security testing and bug bounty research.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: Vulnerability-Scanner
👤 项目作者: Mactoy1
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-27 11:47:48

📝 项目描述:
A Python-based mini vulnerability scanner for port scanning and security checks.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #rule #malware

📦 项目名称: Putty_Patrol
👤 项目作者: Stefan-Krijt
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-27 13:00:06

📝 项目描述:
Malware analysis of a malicious PuTTY executable (Trojan.Dropper) that extracts a PowerFun PowerShell reverse shell. Includes IOCs, YARA rule, and full analysis report.

🔗 点击访问项目地址