GitHub 红队武器库🚨
13.5K subscribers
20 photos
8 videos
23.1K links
📦 GitHub 全球红队渗透资源中转站。
​旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
⚠️ 本频道仅供安全研究与授权测试使用。
Download Telegram
🚨 GitHub 监控消息提醒

🚨 发现关键词: #渗透测试 #漏洞

📦 项目名称: PenScope
👤 项目作者: wanlqx
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-03 10:58:04

📝 项目描述:
授权式本地自动化渗透测试桌面工具。PenScope 是一款面向安全测试人员 / 授权渗透测试场景的桌面应用。它把端口扫描、Web 漏洞扫描(SQL 注入、XSS、CSRF、文件上传)、利用验证、报告生成等工作流整合在一个原生窗口中,所有逻辑都在你本机运行,不依赖任何远程服务器,也不需要账号密码。

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Spring #POC

📦 项目名称: distributed-ride-hailing-saga
👤 项目作者: jamesiit
🛠 开发语言: Java
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-03 07:03:20

📝 项目描述:
An End-to-End AWS Serverless PoC demonstrating the Saga Pattern, distributed transactions, and automated microservice rollbacks using Spring Boot and Step Functions.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: vulnerability-scanner
👤 项目作者: Shivam74918
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-03 10:28:13

📝 项目描述:
A Python-based web vulnerability scanner that identifies missing security headers, scans open ports, checks SSL/TLS configurations, detects directory listing, and discovers common web security vulnerabilities.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSTI #RCE

📦 项目名称: do-not-disturb-thm
👤 项目作者: HackerRank7
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-03 10:48:54

📝 项目描述:
Full Boot2Root writeup for TryHackMe's "Do Not Disturb" room (Hacker Holidays 2026) — NoSQL injection auth bypass → EJS SSTI/RCE → exposed Node inspector abuse → disk-group raw partition read for root.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #Reflected #DOM

📦 项目名称: juice-shop-pentest
👤 项目作者: aryaparge
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-03 10:47:22

📝 项目描述:
Manual web application penetration testing of OWASP Juice Shop using Burp Suite Community Edition. Identified and validated SQL Injection, XSS, Broken Access Control, Sensitive Data Exposure, and Business Logic vulnerabilities, with findings documented in a professional penetration testing report.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: ovswrap-poc
👤 项目作者: HackSpeak
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-03 11:25:41

📝 项目描述:
CVE-2026-64531 (OVSwrap) PoC - Linux kernel Open vSwitch LPE; for patch validation and security research

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #渗透测试 #漏洞

📦 项目名称: JiyuUdpAttack
👤 项目作者: yangsongh
🛠 开发语言: VBScript
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-03 10:45:52

📝 项目描述:
极域电子教室 UDP 重放攻击研究与渗透测试工具集

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: vulnscope
👤 项目作者: Crow-developers
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-03 12:04:32

📝 项目描述:
A lightweight Python vulnerability scanner that maps open ports and service banners to known CVEs.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: checkpoint-smartconsole-poc
👤 项目作者: HackSpeak
🛠 开发语言: Python
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-03 12:56:53

📝 项目描述:
CVE-2026-16232 (Check Point SmartConsole authentication bypass) PoC - unauth to admin; for authorized security testing

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC #Exploit #RCE

📦 项目名称: CVE-2026-60004
👤 项目作者: shinthink
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-03 12:49:46

📝 项目描述:
CVE-2026-60004 — Gitea/Forgejo Diffpatch Git Hook RCE. Bare clone → post-index-change hook injection. CVSS 9.8 | CWE-94 | Gitea < 1.27.1

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Fastjson #漏洞 #CVE

📦 项目名称: fastjson-check
👤 项目作者: xiaoqiMikko
🛠 开发语言: Java
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-03 13:02:01

📝 项目描述:
Find fastjson in your JARs and Spring Boot fat-JARs, and check exposure to CVE-2026-16723. Zero dependencies, fully offline. 一条命令排查 fastjson 漏洞影响范围。

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Exchange #EXP

📦 项目名称: oasis
👤 项目作者: navikt
🛠 开发语言: TypeScript
Star数量: 3 | 🍴 Fork数量: 7
📅 更新时间: 2026-08-03 13:03:33

📝 项目描述:
Bibliotek for å validere tokens fra Wonderwall og utføre On-Behalf-Of Exchange mot både Azure og IDporten

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #RCE #CVE #POC

📦 项目名称: kindarails2shell-poc
👤 项目作者: HackSpeak
🛠 开发语言: Python
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-03 12:54:32

📝 项目描述:
CVE-2026-66066 (KindaRails2Shell) PoC - Rails Active Storage/libvips arbitrary file read to RCE; for authorized security testing

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #RCE #CVE

📦 项目名称: Codify-TJNULL-OSCP-
👤 项目作者: R3fr4kt
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-03 12:17:48

📝 项目描述:
Walkthrough for Codify (Linux - Easy). Exploits vm2 RCE (CVE-2023-30547), SQLite DB hash extraction, Bcrypt cracking with John, and Privilege Escalation via Bash wildcard comparison in `mysql-backup.sh`.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #Exploit

📦 项目名称: ghostlock-myron-tw
👤 项目作者: jason5545
🛠 开发语言: C
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-03 13:30:47

📝 项目描述:
GhostLock (CVE-2026-43499) kernel exploit port for REDMI K90 Pro Max Taiwan firmware (myron, WPMTWXM) — offsets, build guide, prebuilt binary

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Spring #POC

📦 项目名称: naveenvanam789
👤 项目作者: naveenvanam789
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-03 14:04:56

📝 项目描述:
Hi, I'm Naveen 👋 I'm an Associate Software Engineer at Tech Mahindra, based in Hyderabad, India, with about a year and a half of experience building backend systems and full-stack applications. My core stack is **Java and Spring Boot**, and I work regularly with **MySQL** and **Git** in my day-to-day development work.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Shellcode #Evasion #EDR

📦 项目名称: PwnyBolty
👤 项目作者: mr-rizwan-syed
🛠 开发语言: HTML
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-03 12:05:53

📝 项目描述:
Turn a Microsoft-signed binary into a red team implant — no admin rights, no custom signing. ClickOnce delivery via AppDomainManager hijack with shellcode execution, file drop, reverse SSH + SOCKS5 tunnel modes, and a web UI for quick payload generation and deployment.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #malware

📦 项目名称: safe-install
👤 项目作者: haycarlitos
🛠 开发语言: Shell
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-03 13:49:15

📝 项目描述:
Detect fake-job-interview malware before it runs. safe-install scans npm repos for the Contagious Interview (DPRK) attack, checks sites for ClickFix clipboard hijacks, and guides incident response if your wallet or machine was already compromised. Built from a real forensic teardown.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #Exploit #RCE

📦 项目名称: CVE-2026-15409
👤 项目作者: Ch4120N
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-03 14:59:05

📝 项目描述:
Proof-of-Concept exploit for CVE-2026-15409 (SonicWall SMA 1000 RCE) via Erlang distribution over WebSocket. Achieves unauthenticated remote code execution as couchdb user.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: POC-CVE-2026-54121-Certighost-
👤 项目作者: sam00
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-03 14:42:38

📝 项目描述:
无描述

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Bypass #EDR

📦 项目名称: edr-bypass-kit-
👤 项目作者: rootdz1337
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-03 15:02:26

📝 项目描述:
edr bypass kit dz

🔗 点击访问项目地址