GitHub 红队武器库🚨
13.5K subscribers
20 photos
8 videos
22.7K links
📦 GitHub 全球红队渗透资源中转站。
​旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
⚠️ 本频道仅供安全研究与授权测试使用。
Download Telegram
🚨 GitHub 监控消息提醒

🚨 发现关键词: #C2 #Framework #Command and Control

📦 项目名称: AltaXploit-C2
👤 项目作者: AltaXploit
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-29 20:53:55

📝 项目描述:
无描述

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #BlueTeam #Response #Detection

📦 项目名称: Active-Directory-Attack-Detection-Lab---Splunk-SIEM-Microsoft-Defender
👤 项目作者: DurgaRamireddy
🛠 开发语言: Unknown
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-29 20:57:29

📝 项目描述:
Full AD attack chain: Kerberoasting, AS-REP Roasting, Pass-the-Hash, DCSync, BloodHound - detected via Splunk SIEM + Windows Event IDs. Detection gap analysis included.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #BlueTeam #Detection

📦 项目名称: cowrie-ssh-honeypot
👤 项目作者: bigcnash
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-29 20:41:01

📝 项目描述:
A hands-on SSH honeypot lab using Cowrie to simulate attacker activity, capture commands, and analyze session logs.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: CVE-2026-66066-POC
👤 项目作者: Zer0SumGam3
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-29 21:57:10

📝 项目描述:
PoC for CVE-2026-66066 in Ruby on Rails

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #RCE

📦 项目名称: Termix-research
👤 项目作者: GabrielHA12
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-29 21:15:43

📝 项目描述:
CVE-2026-45746, CVE-2026-45750, CVE-2026-53547 — three critical vulnerabilities in Termix: cross-tenant session hijacking, OS command injection, and account takeover

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Burp #Extension

📦 项目名称: PentestVault
👤 项目作者: Ganesha-hk
🛠 开发语言: JavaScript
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-29 21:22:16

📝 项目描述:
🛡️ AI-powered web penetration testing report writer. Document findings across 6 categories, auto-sanitize sensitive data, generate professional PDF/DOCX/Markdown reports using free AI models. Includes Burp Suite integration, CVSS calculator, evidence linking & screenshot management. Self-hosted.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #RCE #CVE #POC

📦 项目名称: CVE-2024-36104-PoC
👤 项目作者: Groppoxx
🛠 开发语言: Python
Star数量: 3 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-29 21:39:57

📝 项目描述:
PoC for CVE-2024-36104 — unauthenticated Groovy RCE in Apache OFBiz (<18.12.14) via /%2e/%2e/ view path traversal to ProgramExport

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #CVE

📦 项目名称: laboratorio-owasp
👤 项目作者: Paulo-Marcos-Lucio
🛠 开发语言: Java
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-29 22:23:29

📝 项目描述:
Laboratório didático OWASP Top 10 em Spring Boot — cada vuln em par vulnerável→exploit→corrigido, com teste JUnit provando os dois lados. SQLi · XSS · IDOR · Path Traversal · MD5→BCrypt. Java 21 · MIT.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Nuclei #templates

📦 项目名称: nuclei-templates-rtb
👤 项目作者: RedTeamBrasil
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-29 22:59:15

📝 项目描述:
无描述

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #RCE #Remote Code Execution

📦 项目名称: RCE-demo
👤 项目作者: AstixxxX
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-29 20:30:32

📝 项目描述:
无描述

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: Hexora
👤 项目作者: alannagonzalez
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-30 00:40:38

📝 项目描述:
Web security vulnerability scanner developed in Python

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Burp #Plugin #Extension

📦 项目名称: burpsuite-for-ai-agent
👤 项目作者: whoismemas
🛠 开发语言: JavaScript
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-30 00:42:43

📝 项目描述:
Two-way Burp Suite MCP bridge for AI agents — capture traffic, queue scan tasks, send findings back to Burp as Scanner issues or Repeater tabs. MCP server + Jython plugin.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #漏扫

📦 项目名称: Poc_list
👤 项目作者: fxa-2013
🛠 开发语言: Unknown
Star数量: 5 | 🍴 Fork数量: 1
📅 更新时间: 2026-07-30 01:13:12

📝 项目描述:
一个基于Python Flask开发的漏洞管理平台,支持导入Excel格式的漏洞扫描报告,智能关联资产信息,实现漏洞的可视化管理。

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #漏扫

📦 项目名称: vulnerabilities_scan
👤 项目作者: fxa-2013
🛠 开发语言: Unknown
Star数量: 14 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-30 01:12:02

📝 项目描述:
梦鉴-网络安全评估系统,Mj_scan是一款强大的多功能漏扫系统,包括资产管理、端口扫描、指纹探测、漏洞扫描、密码爆破等功能,具备强大的指纹库和漏洞库

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #漏洞

📦 项目名称: SentinelScan
👤 项目作者: GY-000
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-30 01:30:49

📝 项目描述:
基于 Python + Flask 开发的轻量级 Web 漏洞检测工具,支持 SQL 注入、XSS、敏感目录枚举、端口探测,自动生成可视化安全报告。

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Kubernetes #POC

📦 项目名称: oadp-pipelines-poc
👤 项目作者: weihao-s
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-30 02:06:25

📝 项目描述:
Proof-of-concept involving the use of OADP (Velero) & OpenShift Pipelines (Tekton) to orchestrate the backup and restoration of Kubernetes application to and fro local NFS storage using a pipeline.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #信息收集 #渗透

📦 项目名称: kali-web-CLI
👤 项目作者: fxa-2013
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-30 01:22:59

📝 项目描述:
在kali上运行的集成的网络安全风险评估平台,整合了102个主流渗透测试工具,覆盖了从信息收集到后渗透的完整攻击链

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: Vulnerabilityscanner
👤 项目作者: gopikahub006
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-30 03:03:18

📝 项目描述:
Python-based Web Vulnerability Scanner with GUI, PDF reporting, and automated security testing.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: Nemesis-Python-Beta
👤 项目作者: Nemesis-Tools
🛠 开发语言: Python
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-30 02:45:44

📝 项目描述:
A Selenium-based web vulnerability scanner · HTTP/HTTPS · 323 techniques · HackerOne-format reports (auto CWE/CVSS)

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #Stored #Reflected #DOM

📦 项目名称: XSS
👤 项目作者: lakxitt
🛠 开发语言: Unknown
Star数量: 3 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-30 03:16:54

📝 项目描述:
XSS notes, payloads, and bypass techniques for bug hunting

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #metadata

📦 项目名称: feed-digest
👤 项目作者: Vey87
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-30 01:22:54

📝 项目描述:
Pull RSS/Atom feeds, filter by keyword, get one daily digest email. SSRF-guarded fetching, background scheduler, SMTP. Live at feeds.tonyvt.com

🔗 点击访问项目地址