GitHub 红队武器库🚨
13.5K subscribers
20 photos
8 videos
23K links
📦 GitHub 全球红队渗透资源中转站。
​旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
⚠️ 本频道仅供安全研究与授权测试使用。
Download Telegram
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Exploit #CVE

📦 项目名称: CVE-log4shell
👤 项目作者: sanasimran1403-jpg
🛠 开发语言: HTML
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-02 22:02:11

📝 项目描述:
Log4Shell (CVE-2021-44228) research report — technical breakdown, root cause analysis, and end-to-end lab-reproduced exploit chain with evidence screenshots.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #rule #malware

📦 项目名称: yara-scan
👤 项目作者: PSubutai
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-02 22:30:59

📝 项目描述:
Windows-focused command-line YARA scanner with live progress, file-type/hash/PE enrichment, and a built-in YARA Forge rule updater.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #CVE #Stored

📦 项目名称: CVE-2026-66421-OpenClaw-Dashboard-Stored-XSS-via-lastMessage-Session-Field
👤 项目作者: theopaid
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-02 22:17:23

📝 项目描述:
Security Advisory: Stored Cross-Site Scripting Via Agent Messages Leading To Session Token Theft (openclaw-dashboard)

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #CVE #Stored

📦 项目名称: CVE-2026-66418-OpenClaw-Dashboard-v3.0.0-Stored-XSS-via-Failed-Login-Username-Field
👤 项目作者: theopaid
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-02 22:15:40

📝 项目描述:
Security Advisory: Unauthenticated Stored Cross-Site Scripting Leading To Administrator Account Takeover (openclaw-dashboard)

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #Exploit

📦 项目名称: Kangaroo
👤 项目作者: MonkeySeC-sys
🛠 开发语言: Go
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-02 23:04:34

📝 项目描述:
Kangaroo is a exploit built on CVE-2026-32746. i made this for security researchers, IT professionals, DevOps. so they can understand it better. DO NOT USE THIS FOR ILLEGAL USE, IF YOU DO... YOU MAY BE SUBJECT TO ARREST, AND FINES.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #Stored

📦 项目名称: vuln-lab
👤 项目作者: thisistanujjoshi
🛠 开发语言: TypeScript
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-03 00:03:24

📝 项目描述:
Intentionally vulnerable app for practicing OWASP Top 10 discovery/fixes (SQLi, XSS, broken auth) — local learning only

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #漏洞 #扫描

📦 项目名称: web-scanner
👤 项目作者: Wzzm-123
🛠 开发语言: Python
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-03 00:48:52

📝 项目描述:
一个从零开始编写的Web漏洞扫描器,支持多线程、数据库存储和报告生成。

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #RCE

📦 项目名称: CVE-2026-4040-Race-Condition-in-File-Upload-Leading-to-RCE
👤 项目作者: George0Papasotiriou
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-03 01:48:22

📝 项目描述:
无描述

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #CVE

📦 项目名称: CVE-2026-2020-SSRF-via-URL-Parser-Differential
👤 项目作者: George0Papasotiriou
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-03 01:43:43

📝 项目描述:
无描述

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #应急响应 #取证

📦 项目名称: IRTools-framework
👤 项目作者: 0xMouise
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-03 01:59:07

📝 项目描述:
Windows 应急响应工具管理框架(不含第三方工具与运行时)

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC #Exploit #RCE

📦 项目名称: CVE-2026-63223-POC
👤 项目作者: imbas007
🛠 开发语言: PHP
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-03 03:58:35

📝 项目描述:
CVE-2026-63223 PoC — CodeIgniter 4 is_image/mime_in File Upload RCE (CVSS 9.8). Unauthenticated remote code execution via unrestricted file upload bypass using image magic bytes. Fixed in v4.7.4.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC #Exploit #RCE

📦 项目名称: CVE-2026-52887-NocoBase-SQLi-RCE
👤 项目作者: BiiTts
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-03 03:57:44

📝 项目描述:
CVE-2026-52887 — NocoBase SQL injection -> PostgreSQL-superuser RCE (myInAppChannels:list filter, CVSS 10.0). Author PoC + source analysis + docker lab.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #RCE #CVE #POC

📦 项目名称: CVE-2026-12940-Langflow-Unauth-RCE
👤 项目作者: BiiTts
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-03 03:15:24

📝 项目描述:
CVE-2026-12940 — Langflow OSS <=1.10.1 unauthenticated RCE via MCP stdio environment-variable injection (SHELLOPTS/PS4). Author PoC + source analysis + lab.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: vulnerability-scanner_v1
👤 项目作者: Mithunvm92
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-03 03:48:06

📝 项目描述:
vulnerability-scanner_v1

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: Thiranex-Task-2-Vulnerability-Scanner-
👤 项目作者: mgokulsaran67-boop
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-03 03:45:31

📝 项目描述:
A lightweight Python vulnerability scanner for learning penetration testing basics. Scans open TCP ports, grabs banners to flag outdated software, detects weak configs (Telnet, FTP, exposed RDP), and generates severity-rated reports in TXT and HTML. For educational use on authorized targets only.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Sliver #C2

📦 项目名称: RedTeam-C2-Lab
👤 项目作者: DarthWakamiya
🛠 开发语言: Dockerfile
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-03 04:02:49

📝 项目描述:
A hands-on Red Team laboratory demonstrating the deployment of a Sliver Command and Control (C2) infrastructure with an Nginx redirector, Docker-based isolated environment, HTTPS communication, and network traffic analysis using Wireshark.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #C2 #Implant

📦 项目名称: hvnc_implant
👤 项目作者: ekomsSavior
🛠 开发语言: C++
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-03 04:06:54

📝 项目描述:
hvnc implant with c2 for super educational puroses xo

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: Web-Application-Vulnerability-Scanner
👤 项目作者: ronaksorout
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-03 04:58:10

📝 项目描述:
A Python-based Web Application Vulnerability Scanner that automates the detection of common web security vulnerabilities, including SQL Injection, Cross-Site Scripting (XSS), missing security headers, and other security misconfigurations.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #信息收集 #渗透 #recon

📦 项目名称: RedTeam-Recon
👤 项目作者: jiege56
🛠 开发语言: Python
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-03 04:16:17

📝 项目描述:
基于天狐渗透工具箱二次开发的一体化信息收集工具

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #POC #CVE

📦 项目名称: cve-2026-poc-collection
👤 项目作者: TreasureBoy520
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-03 05:06:50

📝 项目描述:
Restored from anonymous99-Rise

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #Reflected #DOM

📦 项目名称: XSSurge
👤 项目作者: ssn-code
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-03 04:29:42

📝 项目描述:
Advanced XSS detection suite with context-aware payload generation, custom HTML/JS parsing, intelligent fuzzing, fast crawling, and DOM/reflected XSS scanning. Includes WAF detection/evasion, parameter discovery, outdated JS library checks, blind XSS support, and extensible attack workflows.

🔗 点击访问项目地址