GitHub 红队武器库🚨
13.6K subscribers
20 photos
8 videos
23.4K links
📦 GitHub 全球红队渗透资源中转站。
​旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
⚠️ 本频道仅供安全研究与授权测试使用。
Download Telegram
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC #Exploit #RCE

📦 项目名称: XSS2Shell
👤 项目作者: wordsec
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-07 18:32:18

📝 项目描述:
Wordpress Pre-auth XSS to RCE exploit PoC (xss2shell & CVE-2026-64638)

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Exploit #CVE

📦 项目名称: Apache-Lua-Buffer-Overflow-Exploit-CVE-2021-44790
👤 项目作者: CerberusMrXi
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-07 19:00:53

📝 项目描述:
Apache HTTP Server 2.4.x mod_lua Buffer Overflow (CVE-2021-44790) - Advanced exploitation framework with fingerprinting, multi-stage scanning, plugin architecture, professional reporting, screenshot capture, SQLite database, and 95%+ confidence detection. Author: Sudeepa Wanigarathna.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #POC

📦 项目名称: vsm-xss-poc-test
👤 项目作者: lmacan1
🛠 开发语言: HTML
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-07 18:41:54

📝 项目描述:
无描述

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #渗透测试 #红队

📦 项目名称: pyexec-c2
👤 项目作者: paokuwansui
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-07 18:15:31

📝 项目描述:
PyExec2 是一个纯标准库的命令与控制(C2)框架,追求rce场景无文件植入、支持加密帧协议、多传输通道(TCP/TLS/HTTPS/DNS)、 socks5 动态代理、端口转发、持久化与自愈。面向授权红队/渗透测试场景。

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Burp #插件

📦 项目名称: burp-cn-NoPE
👤 项目作者: keiokr
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-07 19:41:01

📝 项目描述:
burp插件tcp抓包改包

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: Automated-Vulnerability-Scanner
👤 项目作者: abrashiazia
🛠 开发语言: Unknown
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-07 19:38:47

📝 项目描述:
This repository hosts the Automated Vulnerability Scanner Dashboard, a Python/Flask web app integrating Nmap, WhatWeb, and Nikto for unified security assessments. It features an automated risk-scoring engine, SQLite-backed scan history, and downloadable PDF security reports, built with a clean, modular architecture.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Docker #POC

📦 项目名称: gestion-pedidos
👤 项目作者: roberthmartinezv
🛠 开发语言: Java
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-07 20:03:56

📝 项目描述:
PoC: módulo de Gestión de Pedidos de Repuestos B2B (Fanalca) — Java 17 + Spring Boot 3 (Clean Architecture), PostgreSQL 16 + Flyway, Angular 22, Docker Compose

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Log4j #CVE

📦 项目名称: log4j-check
👤 项目作者: xiaoqiMikko
🛠 开发语言: Java
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-07 19:09:56

📝 项目描述:
log4j 2025/2026 年 7 条「配置静默失效」CVE 自查:按 CVE×模块 判定 4 个模块,结构化解析 log4j2 配置做 applicability 降噪,并算出该升到哪个版本才一次到位(6 条写 2.25.4,但有一条要 2.25.5,而它 Dependabot 报不出来)

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #RCE #CVE

📦 项目名称: panos-captive-portal-rce
👤 项目作者: ridhinva
🛠 开发语言: Python
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-07 20:05:52

📝 项目描述:
Scanner: CVE-2026-0300 PAN-OS User-ID Captive Portal Buffer Overflow RCE — Python CLI for detecting actively exploited BOF vulnerability in Palo Alto firewalls (CISA KEV 2026-05-13)

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #POC #CVE

📦 项目名称: CVE-2026-55957-PoC
👤 项目作者: mdvpat
🛠 开发语言: Java
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-07 20:05:32

📝 项目描述:
Reproducible Docker lab for the Apache Tomcat JNDIRealm GSSAPI authentication bypass

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: linux-kernel-algif-aead-checker
👤 项目作者: ridhinva
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-07 20:38:51

📝 项目描述:
Scanner: CVE-2026-31431 Linux kernel algif_aead Copy Fail vulnerability checker — Python PoC for heap overflow path

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #RCE

📦 项目名称: ghe-push-option-rce-scanner
👤 项目作者: ridhinva
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-07 20:36:48

📝 项目描述:
Scanner: CVE-2026-3854 GitHub Enterprise Server Pre-auth RCE via Push Option Injection — Python checker (CISA KEV)

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: vuln-scanner
👤 项目作者: ridhinva
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-07 20:41:03

📝 项目描述:
Scanner: Generic vulnerability scanner — web, network, and config checks in Python

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #RCE #CVE

📦 项目名称: drupal-jsonapi-sqli-scanner
👤 项目作者: ridhinva
🛠 开发语言: Python
Star数量: 1 | 🍴 Fork数量: 1
📅 更新时间: 2026-08-07 20:36:46

📝 项目描述:
Scanner: CVE-2026-9082 Drupal PostgreSQL SQLi via JSON:API — Python scanner for unauthenticated SQLi leading to RCE (CISA KEV)

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #RCE #CVE

📦 项目名称: beyondtrust-rce-scanner
👤 项目作者: ridhinva
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-07 20:36:42

📝 项目描述:
Scanner: CVE-2026-1731 BeyondTrust Remote Support Pre-auth RCE — Python checker for actively exploited vulnerability (CISA KEV)

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #POC #CVE

📦 项目名称: poc-h2-duplicate-host
👤 项目作者: SunandM
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-07 21:02:42

📝 项目描述:
PoC: h2 duplicate Host header request smuggling primitive (CVE pending)

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: poc-h2-CVE-2026-71554
👤 项目作者: SunandM
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-07 21:19:15

📝 项目描述:
PoC for CVE-2026-71554 - h2 duplicate Host header request smuggling primitive (fixed in 4.4.1)

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #Exploit

📦 项目名称: CVE-2026-57858
👤 项目作者: zylideum
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-07 21:09:19

📝 项目描述:
Wormable exploit for CVE-2026-57858

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #Stored

📦 项目名称: Stored-XSS-Session-Hijacking
👤 项目作者: unisonj
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-07 21:38:39

📝 项目描述:
A technical demonstration of exploiting Stored Cross-Site Scripting (XSS) to exfiltrate administrative tokens, perform session hijacking, and expose plaintext credentials in a mock web application.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: web3-defi-scanner
👤 项目作者: ridhinva
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-07 21:26:48

📝 项目描述:
Scanner: Web3/DeFi smart contract vulnerability scanner — reentrancy, oracle manipulation, flash loans, governance attacks in Python

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #RCE #CVE #POC #Remote Code Execution

📦 项目名称: CVE-2025-32432-PoC
👤 项目作者: EzraMansor
🛠 开发语言: Go
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-07 21:21:30

📝 项目描述:
A simple PoC on the Remote Code Execution (RCE) Vulnerability of CraftCMS designated as CVE-2025-32432 written in Go

🔗 点击访问项目地址