GitHub 红队武器库🚨
13.5K subscribers
20 photos
8 videos
22.7K links
📦 GitHub 全球红队渗透资源中转站。
​旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
⚠️ 本频道仅供安全研究与授权测试使用。
Download Telegram
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: vulnerability-scanner
👤 项目作者: ankitpandey703393-collab
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-29 18:01:03

📝 项目描述:
A hybrid cybersecurity vulnerability scanner that detects open ports, identifies services, analyzes security risks, and generates professional vulnerability reports with an intuitive web dashboard.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #RCE #Remote Code Execution

📦 项目名称: Black-box-project
👤 项目作者: DDulich
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-29 18:03:02

📝 项目描述:
Comprehensive Black Box Penetration Testing report on a web application (tech-world.live). Demonstrates a full attack chain from initial reconnaissance to Remote Code Execution (RCE) and Root Privilege Escalation. Final project for the Offensive Security Expert Program.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Burp #Extension

📦 项目名称: TimeSQLi-Burp-Extension
👤 项目作者: parkerzanta
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-29 18:00:38

📝 项目描述:
TimeSQLi Scanner is a Burp Suite extension for time-based SQL injection detection with Base64-aware parameter handling and a Retest workflow (custom delays + request/response viewer).

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC #Exploit #RCE

📦 项目名称: CVE-2026-58025
👤 项目作者: shinthink
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-29 18:18:35

📝 项目描述:
CVE-2026-58025 — MediaWiki Deserialization RCE via Log Entry Import. LogEntryBase::extractParams() unserialize() user-controlled log_params. CVSS 9.8 | CWE-502 | MediaWiki < 1.43.9, < 1.44.6, < 1.45.4, < 1.46.0

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #0day #RCE

📦 项目名称: rustdesk-security-audit-2026
👤 项目作者: dinosn
🛠 开发语言: JavaScript
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-29 18:33:11

📝 项目描述:
RustDesk client+server security audit (RAPTOR loop-hunt) — F-C10 RCE + rendezvous/relay secure-channel-bypass cluster, 2 live-proven. Private 0day.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #Exploit

📦 项目名称: CVE-2026-43813
👤 项目作者: EastArctica
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-29 19:41:52

📝 项目描述:
CVE-2026-43813: CloudAttestation enforceEnvironment bypass

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #Exploit

📦 项目名称: CVE-2026-54107
👤 项目作者: Pravin761
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-29 19:22:46

📝 项目描述:
无描述

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #metadata

📦 项目名称: HostHeaderScanner
👤 项目作者: kabiri-labs
🛠 开发语言: Python
Star数量: 3 | 🍴 Fork数量: 1
📅 更新时间: 2026-07-29 14:18:01

📝 项目描述:
Practical Host header attack scanner — injection, SSRF, cache poisoning, open redirect, auth bypass & vhost discovery, with raw-HTTP bypasses and OOB confirmation.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: Java-issue-detector
👤 项目作者: zubair-ulhasan
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-29 19:41:46

📝 项目描述:
oss-vuln-scanner (Python) — an OSS dependency vulnerability scanner that queries the OSV.dev API, with parsers for package.json and pom.xml, plus a SQLite caching layer. The assistant verified both manifest parsers and the SQLite cache read/write cycle with mocked data. It couldn't test the live OSV API call itself since the sandbox's network allow

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #Exploit #RCE

📦 项目名称: CVE-2026-66066
👤 项目作者: 0xBlackash
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-29 20:49:30

📝 项目描述:
CVE-2026-66066

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC #Exploit #RCE

📦 项目名称: CVE-2026-57827
👤 项目作者: shinthink
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-29 20:38:57

📝 项目描述:
CVE-2026-57827 — RSFiles! Joomla Component Unauthenticated File Upload RCE. Split-controller upload bypass. CVSS 9.8 | CWE-434 | com_rsfiles < 1.17.12

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #C2 #Framework #Command and Control

📦 项目名称: AltaXploit-C2
👤 项目作者: AltaXploit
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-29 20:53:55

📝 项目描述:
无描述

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #BlueTeam #Response #Detection

📦 项目名称: Active-Directory-Attack-Detection-Lab---Splunk-SIEM-Microsoft-Defender
👤 项目作者: DurgaRamireddy
🛠 开发语言: Unknown
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-29 20:57:29

📝 项目描述:
Full AD attack chain: Kerberoasting, AS-REP Roasting, Pass-the-Hash, DCSync, BloodHound - detected via Splunk SIEM + Windows Event IDs. Detection gap analysis included.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #BlueTeam #Detection

📦 项目名称: cowrie-ssh-honeypot
👤 项目作者: bigcnash
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-29 20:41:01

📝 项目描述:
A hands-on SSH honeypot lab using Cowrie to simulate attacker activity, capture commands, and analyze session logs.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: CVE-2026-66066-POC
👤 项目作者: Zer0SumGam3
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-29 21:57:10

📝 项目描述:
PoC for CVE-2026-66066 in Ruby on Rails

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #RCE

📦 项目名称: Termix-research
👤 项目作者: GabrielHA12
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-29 21:15:43

📝 项目描述:
CVE-2026-45746, CVE-2026-45750, CVE-2026-53547 — three critical vulnerabilities in Termix: cross-tenant session hijacking, OS command injection, and account takeover

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Burp #Extension

📦 项目名称: PentestVault
👤 项目作者: Ganesha-hk
🛠 开发语言: JavaScript
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-29 21:22:16

📝 项目描述:
🛡️ AI-powered web penetration testing report writer. Document findings across 6 categories, auto-sanitize sensitive data, generate professional PDF/DOCX/Markdown reports using free AI models. Includes Burp Suite integration, CVSS calculator, evidence linking & screenshot management. Self-hosted.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #RCE #CVE #POC

📦 项目名称: CVE-2024-36104-PoC
👤 项目作者: Groppoxx
🛠 开发语言: Python
Star数量: 3 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-29 21:39:57

📝 项目描述:
PoC for CVE-2024-36104 — unauthenticated Groovy RCE in Apache OFBiz (<18.12.14) via /%2e/%2e/ view path traversal to ProgramExport

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #CVE

📦 项目名称: laboratorio-owasp
👤 项目作者: Paulo-Marcos-Lucio
🛠 开发语言: Java
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-29 22:23:29

📝 项目描述:
Laboratório didático OWASP Top 10 em Spring Boot — cada vuln em par vulnerável→exploit→corrigido, com teste JUnit provando os dois lados. SQLi · XSS · IDOR · Path Traversal · MD5→BCrypt. Java 21 · MIT.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Nuclei #templates

📦 项目名称: nuclei-templates-rtb
👤 项目作者: RedTeamBrasil
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-29 22:59:15

📝 项目描述:
无描述

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #RCE #Remote Code Execution

📦 项目名称: RCE-demo
👤 项目作者: AstixxxX
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-29 20:30:32

📝 项目描述:
无描述

🔗 点击访问项目地址