GitHub 红队武器库🚨
13.4K subscribers
19 photos
8 videos
22.6K links
📦 GitHub 全球红队渗透资源中转站。
​旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
⚠️ 本频道仅供安全研究与授权测试使用。
Download Telegram
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: Sentryline-Network-Vulnerability-Scanner
👤 项目作者: TejasGowda2012
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-28 11:49:44

📝 项目描述:
Sentryline Network Vulnerability Scanner

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: Web-Application-Vulnerability-Scanner
👤 项目作者: kondojupavani927-sketch
🛠 开发语言: HTML
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-28 11:48:49

📝 项目描述:
A Python-based web application vulnerability scanner that detects common vulnerabilities such as XSS, SQL Injection, and CSRF using Flask, Requests, and BeautifulSoup.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Burp #扩展 #Extension

📦 项目名称: burp-expansion-skills
👤 项目作者: helGayhub233
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-28 10:54:16

📝 项目描述:
无描述

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #Exploit

📦 项目名称: CP-PLUS-EZ-P21-CVE-2026-65893-65894
👤 项目作者: CyberVinner
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-28 12:29:30

📝 项目描述:
无描述

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Bypass #WAF

📦 项目名称: CloudflareBypass-2020-2026
👤 项目作者: Hokage-linchik
🛠 开发语言: JavaScript
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-28 12:58:06

📝 项目描述:
DDoS bypass CloudFlare

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #RCE #POC

📦 项目名称: handlebars-ssti-ast-rce
👤 项目作者: adilaxmdv
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-28 12:54:53

📝 项目描述:
PoC: turning Handlebars SSTI into RCE via server-side AST injection (object-typed template input) — works on Handlebars ≥4.6, no prototype pollution.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #RCE #Remote Code Execution

📦 项目名称: php-scanner
👤 项目作者: ShaikhNaasir
🛠 开发语言: HTML
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-28 12:57:11

📝 项目描述:
A client-side PHP security scanner that detects dangerous patterns like RCE, SQLi, XSS, file inclusion, command injection, and 40+ vulnerability types across your entire project

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Nuclei #templates

📦 项目名称: advanced-nuclei-templates
👤 项目作者: eabubakr21
🛠 开发语言: Unknown
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-28 12:40:36

📝 项目描述:
无描述

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #漏洞

📦 项目名称: ssrf_scan
👤 项目作者: LilDean17
🛠 开发语言: Java
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-28 13:01:21

📝 项目描述:
ssrf_scan 是一个基于 Burp Suite 的 SSRF 检测插件,改造自 ssrf_fuzzer 项目,使用 ceye.io 作为带外(OOB)回调平台。插件通过拦截 Burp Proxy 的所有 HTTP 请求,智能识别请求参数中的 URL / IP / 域名值,并将其替换为 ceye.io 的随机子域名地址;随后调用 ceye.io API 查询 DNS 与 HTTP 记录,自动判断是否存在 SSRF 漏洞,最终以类似 Proxy 的列表界面可视化展示检测结果。

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #信息收集 #渗透

📦 项目名称: reg-finder
👤 项目作者: LilDean17
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-28 12:26:04

📝 项目描述:
reg-finder — 批量 URL 注册入口筛选器 — 面向渗透测试工程师的高通量工具,对信息收集平台每日产出的数千个 URL 并发探测,通过 页面内容关键词匹配、表单检测与分类规则进行"注册可能性"置信度打分,输出高优先级候选列表及业务类型标注,优先保障召回率。

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Burp #扩展 #渗透

📦 项目名称: js-collector
👤 项目作者: LilDean17
🛠 开发语言: Java
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-28 13:07:01

📝 项目描述:
burp-js-collector 是一个 Burp Suite 扩展项目,通过 Burp Extender API 被动拦截响应中的 .js 资源并按域名归类展示,同时内置一个独立的 Java 静态扫描器 JsScanner,可对 JS 文件内容做正则提取,向前追溯上下文并过滤噪音,最终输出隐藏的 API 端点和路径调用片段,用于渗透测试中的 JS 资源收集与端点发现。

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Burp #Extension

📦 项目名称: gRPC-Web-Burp-Repeater
👤 项目作者: Lu3ky13
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-28 12:55:31

📝 项目描述:
A powerful Burp Suite extension for **penetration testers** and **bug bounty hunters** to intercept, decode, edit, and replay **gRPC-Web** traffic.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SQL注入 #漏洞

📦 项目名称: sql-injection-guide
👤 项目作者: xzhibo99-code
🛠 开发语言: Python
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-28 09:16:23

📝 项目描述:
一份涵盖SQL注入原理、sqli-labs靶场实战、防护方案与心得的系统学习笔记。 适合Web安全入门者阅读,同样可作为面试准备的技术展示材料。

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Burp #Extension

📦 项目名称: WTFirewall---Burpsuite-Extension
👤 项目作者: dhruva-code
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-28 14:04:48

📝 项目描述:
WTFirewall is a Dynamic Application Security Testing (DAST) extension for Burp Suite, written in Python (Jython). It serves as an automated Web Application Firewall (WAF) finger-printer, payload testing assistant, and bypass recommendation engine.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #RCE

📦 项目名称: CVE-2026-53921
👤 项目作者: 0xBlackash
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-28 14:48:04

📝 项目描述:
CVE-2026-53921

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #红蓝对抗 #演练 #红队 #蓝队

📦 项目名称: ebook-email-hardening
👤 项目作者: LeisureLinux
🛠 开发语言: CSS
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-28 01:54:47

📝 项目描述:
🛡️ 邮件安全架构师的完整作战地图:底层RFC协议族→中游SEG/Rspamd/DLP纵深防御→顶层红蓝对抗与ISO27001合规收束

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #C2 #Beacon

📦 项目名称: CobaltStrike_OpenBeacon
👤 项目作者: ElJaviLuki
🛠 开发语言: C
Star数量: 270 | 🍴 Fork数量: 54
📅 更新时间: 2026-07-28 14:59:04

📝 项目描述:
Fully functional, from-scratch alternative to the Cobalt Strike Beacon (red teaming tool), offering transparency and flexibility for security professionals and enthusiasts.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #C2 #Beacon

📦 项目名称: c2-detecter
👤 项目作者: jaloliddin-sec
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-28 14:58:58

📝 项目描述:
Statistical C2 beacon detector — flags periodic, low-jitter connection patterns in network logs using timing analysis, without payload inspection. Supports CSV and Zeek conn.log

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: WebShield-Scanner
👤 项目作者: rajpadhiyar615
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-28 14:18:34

📝 项目描述:
Python Based Website Vulnerability Scanner using Streamlit

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSTI #RCE

📦 项目名称: NordArosa-Enterprise-Security-Lab
👤 项目作者: NordArosa
🛠 开发语言: Shell
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-28 14:56:13

📝 项目描述:
Hands-on penetration testing lab with 15 real-world vulnerability scenarios (SQLi, XSS, LFI, RCE, SSRF, JWT, CSRF, SSTI, XXE, deserialization, LDAP, broken auth). Automated setup on Ubuntu. Attack from Kali. Perfect for OSCP prep, portfolio, or learning OWASP Top 10.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #DOM

📦 项目名称: TaintSight
👤 项目作者: zixvict001-eng
🛠 开发语言: Shell
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-28 14:13:56

📝 项目描述:
Passive DOM XSS reconnaissance tool with deep source-to-sink and parameter flow analysis

🔗 点击访问项目地址