GitHub 红队武器库🚨
13.4K subscribers
19 photos
8 videos
22.5K links
📦 GitHub 全球红队渗透资源中转站。
​旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
⚠️ 本频道仅供安全研究与授权测试使用。
Download Telegram
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: CVE-2026-43499
👤 项目作者: dnlid
🛠 开发语言: C
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-27 15:22:53

📝 项目描述:
CVE-2026-43499: Linux kernel futex PI use-after-free research package

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC #Exploit #RCE

📦 项目名称: CVE-2026-65008
👤 项目作者: zer0dayf
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-27 14:32:46

📝 项目描述:
无描述

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: web-vulnerability-scanner
👤 项目作者: derekwango
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-27 16:35:48

📝 项目描述:
Web-based vulnerability scanner that orchestrates Kali/Debian security tools (nmap, nikto, whatweb, sqlmap, testssl.sh) via Docker. Built with PHP/MariaDB, features a dark cybersecurity UI, scan result persistence, and a planned CVE/NVD mapping layer.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #反序列化 #RCE

📦 项目名称: fastjson2-rce
👤 项目作者: heart147
🛠 开发语言: Java
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-27 16:58:12

📝 项目描述:
fastjson2 ≤ 2.0.62 利用多态反序列化(ObjectReaderSeeAlso)+ URLClassLoader.findClass 点号转斜杠替换,绕过 AutoType 白名单及 JDK ClassLoader.checkName,实现远程代码执行。

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #BlueTeam #Response #Detection

📦 项目名称: BlueTeam
👤 项目作者: mattp8638
🛠 开发语言: Python
Star数量: 1 | 🍴 Fork数量: 1
📅 更新时间: 2026-07-27 12:34:56

📝 项目描述:
无描述

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: CVE-2026-66731-Negative-Chunk-Size-Parsing-Causes-Memory-Corruption-leading-to-Server-Crash
👤 项目作者: theopaid
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-27 17:44:53

📝 项目描述:
Security Advisory: Negative Chunk-Size Parsing Causes Memory Corruption in facil.io

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: CVE-2026-66730-Infinite-Loop-DoS-in-facil.io-MIME-Parser
👤 项目作者: theopaid
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-27 17:41:51

📝 项目描述:
Security Advisory: Infinite Loop DoS in facil.io MIME Parser (Partial Boundary)

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #Stored #Reflected

📦 项目名称: vulnpractice-lab-for-xampp
👤 项目作者: mukidulislamzihad
🛠 开发语言: PHP
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-27 17:08:43

📝 项目描述:
⚠️ Intentionally vulnerable PHP + MySQL web app for practicing OWASP Top 10 (SQLi, XSS, CSRF, LFI, Command Injection, File Upload, IDOR) — for local/educational use only, DVWA-style with Low/Medium/High security levels.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #metadata

📦 项目名称: forage
👤 项目作者: kontourai
🛠 开发语言: TypeScript
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-27 17:39:17

📝 项目描述:
Safe, replayable web acquisition for review pipelines: SSRF-pinned crawling, provenance-bearing snapshots, and deterministic replay.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: CVE-2026-66729-Out-of-Bounds-Read-in-facil.io-MIME-Parser-leads-to-Server-Crash
👤 项目作者: theopaid
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-27 17:40:54

📝 项目描述:
Security Advisory: Out-of-Bounds Read in facil.io MIME Parser leads to Server crash

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC #Exploit

📦 项目名称: CVE-2026-9830
👤 项目作者: ChPratik
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-27 16:42:49

📝 项目描述:
The bookingpress-appointment-booking-pro WordPress plugin before 5.7.3 does not correctly invoke its REST permission callback, leaving every route in one of its API namespaces reachable without authentication and allowing unauthenticated attackers to read customer booking data and modify other users' bookings.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #malware

📦 项目名称: reporeaver
👤 项目作者: srinathsankara
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-27 18:59:53

📝 项目描述:
Pre-clone repo security scanner. Detects obfuscated payloads, hardcoded secrets, Unicode tricks, typo-squatting, CI/CD abuse, and supply-chain attacks before you clone.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #rules #malware

📦 项目名称: malware-analysis
👤 项目作者: lewandovskii9
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-27 18:42:37

📝 项目描述:
Static and dynamic analysis of real malware samples using Any.Run, comprehensive malware reports, and YARA detection rules.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Nuclei #templates

📦 项目名称: nuclei-templates-custom
👤 项目作者: k11h-de
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-27 18:47:16

📝 项目描述:
a collection of my very personal nuclei templates

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC #Exploit

📦 项目名称: CVE-2026-39875-macOS-CUPS-LPE
👤 项目作者: mac-123456789-lab
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-27 19:57:25

📝 项目描述:
Unprivileged user to root via CUPS logic flaw — macOS Sonoma, Sequoia, and Tahoe. Patched in macOS 26.6 / 15.7.8 / 14.8.8.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: CVE-2026-40000
👤 项目作者: Skorpion96
🛠 开发语言: Java
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-27 19:42:32

📝 项目描述:
A poc for a vulnerability in ZTE File Manager (zte.com.cn.filer) which allows to read arbitrary files from other apps with the privileges of this file manager

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #rules #malware

📦 项目名称: Apophis-Detection
👤 项目作者: apophis133
🛠 开发语言: YARA
Star数量: 2 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-27 19:59:48

📝 项目描述:
Repository of Yara Rules & Config Extractors

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #malware

📦 项目名称: malware-pipeline
👤 项目作者: ARES-SYS
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-27 19:33:50

📝 项目描述:
17-stage deterministic malware analysis pipeline. Hash → entropy → signature → sandbox → triage. No ML hype. Just math, YARA, and syscalls.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #RCE #CVE

📦 项目名称: CVE-2025-64512---pdfminer.six-Remote-Code-Execution-RCE-
👤 项目作者: saadhassan77
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-27 19:50:06

📝 项目描述:
无描述

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #Reflected

📦 项目名称: real-time-log-analyzer
👤 项目作者: sofiaboiko
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-27 19:54:19

📝 项目描述:
Real-time log analysis project featuring a deliberately vulnerable Flask app, custom Python detection rules mapped to MITRE ATT&CK, Telegram alerting, and a hardened remediated version for comparison.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #Stored #Reflected

📦 项目名称: hackbox-windows-xampp-version
👤 项目作者: mukidulislamzihad
🛠 开发语言: PHP
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-27 18:08:37

📝 项目描述:
⚠️ Intentionally vulnerable PHP + MySQL web app for practicing OWASP Top 10 (SQLi, XSS, CSRF, LFI, Command Injection, File Upload, IDOR) — for local/educational use only, DVWA-style with Low/Medium/High security levels.

🔗 点击访问项目地址