GitHub 红队武器库🚨
13.4K subscribers
19 photos
8 videos
22.6K links
📦 GitHub 全球红队渗透资源中转站。
​旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
⚠️ 本频道仅供安全研究与授权测试使用。
Download Telegram
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: WebShield-Scanner
👤 项目作者: rajpadhiyar615
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-28 14:18:34

📝 项目描述:
Python Based Website Vulnerability Scanner using Streamlit

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSTI #RCE

📦 项目名称: NordArosa-Enterprise-Security-Lab
👤 项目作者: NordArosa
🛠 开发语言: Shell
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-28 14:56:13

📝 项目描述:
Hands-on penetration testing lab with 15 real-world vulnerability scenarios (SQLi, XSS, LFI, RCE, SSRF, JWT, CSRF, SSTI, XXE, deserialization, LDAP, broken auth). Automated setup on Ubuntu. Attack from Kali. Perfect for OSCP prep, portfolio, or learning OWASP Top 10.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #DOM

📦 项目名称: TaintSight
👤 项目作者: zixvict001-eng
🛠 开发语言: Shell
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-28 14:13:56

📝 项目描述:
Passive DOM XSS reconnaissance tool with deep source-to-sink and parameter flow analysis

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #漏洞 #RCE

📦 项目名称: aspx_vul
👤 项目作者: 0x7556
🛠 开发语言: ASP.NET
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-28 15:04:59

📝 项目描述:
ASP.NET RCE 反序列化 靶场 漏洞环境

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC #Exploit

📦 项目名称: CVE-2026-65761
👤 项目作者: ywh-jfellus
🛠 开发语言: PHP
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-28 15:48:20

📝 项目描述:
Proof of Concept for CVE-2026-65761 - EasyStore Pro Unauthenticated SQL Injection via `filter_sortby`

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Fastjson #RCE

📦 项目名称: fastjson2-2.0.62-seealso-rce
👤 项目作者: joysinleung
🛠 开发语言: Java
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-28 15:47:19

📝 项目描述:
fastjson2 2.0.62 seeAlso 多态路径 RCE 复现 — 默认配置即触发,仅创建 /tmp/pwned 标记文件。基于 dinosn/fastjson-jsontype-rce-lab 重建。

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SQL注入 #漏洞

📦 项目名称: vulnlab
👤 项目作者: Y4n9Ch
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-28 16:02:04

📝 项目描述:
Web安全靶场 - SQL注入/XSS/命令注入/文件上传/SSRF/XXE/SSTI等漏洞练习

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #POC

📦 项目名称: ssrf-poc-wp-6-8-3
👤 项目作者: ebrasha
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-28 15:27:05

📝 项目描述:
Proof-of-Concept (PoC) demonstrating a Server-Side Request Forgery (SSRF) via the XML-RPC pingback.ping endpoint in WordPress Core 6.8.3, resulting in origin IP disclosure behind Cloudflare. Discovered by: Ebrahim Shafiei (EbraSha).

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #malware

📦 项目名称: NEXAR-MAAS
👤 项目作者: RIPJAW1316
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-28 15:54:45

📝 项目描述:
AI-powered Android Malware Analysis & Assessment System using FastAPI, React, YARA, VirusTotal, Frida and Local LLMs.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Shellcode #Loader #Inject

📦 项目名称: machine-code-shellcode
👤 项目作者: mrzaxaryan
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-28 15:50:33

📝 项目描述:
无描述

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Nuclei #template

📦 项目名称: embryo_image_analysis
👤 项目作者: elyssephillips
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-28 16:41:01

📝 项目描述:
Get fluorescence intensity information from segmented nuclei masks and raw hyperstacks

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Nuclei #template #templates

📦 项目名称: AutoRecon
👤 项目作者: LuizWT
🛠 开发语言: Python
Star数量: 6 | 🍴 Fork数量: 2
📅 更新时间: 2026-07-28 16:22:20

📝 项目描述:
O AutoRecon é um projeto de automação de ferramentas de segurança focado em facilitar o processo de varredura e coleta de informações em ambientes de rede.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #RCE #漏洞

📦 项目名称: Fastjson2-RCE
👤 项目作者: NHPT
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-28 16:53:42

📝 项目描述:
Fastjson2 详细的漏洞分析和复现

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Burp #Extension

📦 项目名称: WebSocket-Smuggler-Modular
👤 项目作者: tobiasGuta
🛠 开发语言: Java
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-28 17:02:30

📝 项目描述:
The WebSocket Smuggler (Modular) is a specialized Burp Suite extension designed to automate the detection and exploitation of HTTP Request Smuggling vulnerabilities that arise from faulty WebSocket connection handling by reverse proxies.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Spring #POC

📦 项目名称: modular-erp-poc
👤 项目作者: dimidotdev
🛠 开发语言: Java
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-28 17:03:22

📝 项目描述:
Multi-tenant modular ERP backend proof of concept built with Java, Spring Boot and Spring Modulith

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Bypass #Sandbox

📦 项目名称: iFetch
👤 项目作者: weekanya
🛠 开发语言: Objective-C
Star数量: 2 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-28 17:01:38

📝 项目描述:
Native system monitor and utility suite for iOS 14–17 (Rootless) with sandbox bypass and kernel access.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC #Exploit #RCE

📦 项目名称: CVE-2026-53921-PoC-Exploit
👤 项目作者: tc4dy
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-28 17:54:09

📝 项目描述:
CVE-2026-53921 – odhcpd Stack Overflow (CVSS 9.8) 🛡️ Vuln detailed and comprehensive Write-Up and Verifier & Multi-exploit for OpenWrt DHCPv6 RCE. Dual-vector (IA_NA/IA_PD) overflow with MIPS/ARM shellcode, ROP chains, SOCKS5 proxy, persistence, log wiping & mass scanning. Use Ethically, Stay Legal. 🔒

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #C2 #红队

📦 项目名称: SilverFox-C2
👤 项目作者: hello-world-3511
🛠 开发语言: HTML
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-28 17:57:59

📝 项目描述:
多协议、跨平台、插件化 C2 平台 | Go + C | 红队安全研究

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #C2 #Framework

📦 项目名称: Megaploit
👤 项目作者: Josefifir
🛠 开发语言: Python
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-28 17:57:50

📝 项目描述:
Professional Python C2 framework — encrypted transport, Go agent, WebSocket evasion, post-exploitation pipeline, malleable profiles, web dashboard & multi-operator RPC.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #CVE #Reflected

📦 项目名称: CVE-2025-6563
👤 项目作者: praksokchea
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-28 17:10:31

📝 项目描述:
Reflected XSS vulnerability in MikroTik Hotspot login page

🔗 点击访问项目地址