GitHub 红队武器库🚨
13.6K subscribers
20 photos
8 videos
23.3K links
📦 GitHub 全球红队渗透资源中转站。
​旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
⚠️ 本频道仅供安全研究与授权测试使用。
Download Telegram
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Burp #插件

📦 项目名称: burp-cn-NoPE
👤 项目作者: keiokr
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-07 19:41:01

📝 项目描述:
burp插件tcp抓包改包

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: Automated-Vulnerability-Scanner
👤 项目作者: abrashiazia
🛠 开发语言: Unknown
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-07 19:38:47

📝 项目描述:
This repository hosts the Automated Vulnerability Scanner Dashboard, a Python/Flask web app integrating Nmap, WhatWeb, and Nikto for unified security assessments. It features an automated risk-scoring engine, SQLite-backed scan history, and downloadable PDF security reports, built with a clean, modular architecture.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Docker #POC

📦 项目名称: gestion-pedidos
👤 项目作者: roberthmartinezv
🛠 开发语言: Java
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-07 20:03:56

📝 项目描述:
PoC: módulo de Gestión de Pedidos de Repuestos B2B (Fanalca) — Java 17 + Spring Boot 3 (Clean Architecture), PostgreSQL 16 + Flyway, Angular 22, Docker Compose

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Log4j #CVE

📦 项目名称: log4j-check
👤 项目作者: xiaoqiMikko
🛠 开发语言: Java
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-07 19:09:56

📝 项目描述:
log4j 2025/2026 年 7 条「配置静默失效」CVE 自查:按 CVE×模块 判定 4 个模块,结构化解析 log4j2 配置做 applicability 降噪,并算出该升到哪个版本才一次到位(6 条写 2.25.4,但有一条要 2.25.5,而它 Dependabot 报不出来)

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #RCE #CVE

📦 项目名称: panos-captive-portal-rce
👤 项目作者: ridhinva
🛠 开发语言: Python
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-07 20:05:52

📝 项目描述:
Scanner: CVE-2026-0300 PAN-OS User-ID Captive Portal Buffer Overflow RCE — Python CLI for detecting actively exploited BOF vulnerability in Palo Alto firewalls (CISA KEV 2026-05-13)

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #POC #CVE

📦 项目名称: CVE-2026-55957-PoC
👤 项目作者: mdvpat
🛠 开发语言: Java
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-07 20:05:32

📝 项目描述:
Reproducible Docker lab for the Apache Tomcat JNDIRealm GSSAPI authentication bypass

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: linux-kernel-algif-aead-checker
👤 项目作者: ridhinva
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-07 20:38:51

📝 项目描述:
Scanner: CVE-2026-31431 Linux kernel algif_aead Copy Fail vulnerability checker — Python PoC for heap overflow path

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #RCE

📦 项目名称: ghe-push-option-rce-scanner
👤 项目作者: ridhinva
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-07 20:36:48

📝 项目描述:
Scanner: CVE-2026-3854 GitHub Enterprise Server Pre-auth RCE via Push Option Injection — Python checker (CISA KEV)

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: vuln-scanner
👤 项目作者: ridhinva
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-07 20:41:03

📝 项目描述:
Scanner: Generic vulnerability scanner — web, network, and config checks in Python

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #RCE #CVE

📦 项目名称: drupal-jsonapi-sqli-scanner
👤 项目作者: ridhinva
🛠 开发语言: Python
Star数量: 1 | 🍴 Fork数量: 1
📅 更新时间: 2026-08-07 20:36:46

📝 项目描述:
Scanner: CVE-2026-9082 Drupal PostgreSQL SQLi via JSON:API — Python scanner for unauthenticated SQLi leading to RCE (CISA KEV)

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #RCE #CVE

📦 项目名称: beyondtrust-rce-scanner
👤 项目作者: ridhinva
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-07 20:36:42

📝 项目描述:
Scanner: CVE-2026-1731 BeyondTrust Remote Support Pre-auth RCE — Python checker for actively exploited vulnerability (CISA KEV)

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #POC #CVE

📦 项目名称: poc-h2-duplicate-host
👤 项目作者: SunandM
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-07 21:02:42

📝 项目描述:
PoC: h2 duplicate Host header request smuggling primitive (CVE pending)

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: poc-h2-CVE-2026-71554
👤 项目作者: SunandM
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-07 21:19:15

📝 项目描述:
PoC for CVE-2026-71554 - h2 duplicate Host header request smuggling primitive (fixed in 4.4.1)

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #Exploit

📦 项目名称: CVE-2026-57858
👤 项目作者: zylideum
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-07 21:09:19

📝 项目描述:
Wormable exploit for CVE-2026-57858

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #Stored

📦 项目名称: Stored-XSS-Session-Hijacking
👤 项目作者: unisonj
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-07 21:38:39

📝 项目描述:
A technical demonstration of exploiting Stored Cross-Site Scripting (XSS) to exfiltrate administrative tokens, perform session hijacking, and expose plaintext credentials in a mock web application.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: web3-defi-scanner
👤 项目作者: ridhinva
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-07 21:26:48

📝 项目描述:
Scanner: Web3/DeFi smart contract vulnerability scanner — reentrancy, oracle manipulation, flash loans, governance attacks in Python

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #RCE #CVE #POC #Remote Code Execution

📦 项目名称: CVE-2025-32432-PoC
👤 项目作者: EzraMansor
🛠 开发语言: Go
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-07 21:21:30

📝 项目描述:
A simple PoC on the Remote Code Execution (RCE) Vulnerability of CraftCMS designated as CVE-2025-32432 written in Go

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #CVE

📦 项目名称: api-security-scanner
👤 项目作者: ridhinva
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-07 21:52:12

📝 项目描述:
Scanner: OWASP API Top 10 2023 + GraphQL security scanner — BOLA, BFLA, SSRF, introspection leaks, depth DoS in Python

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #RCE #Nuclei

📦 项目名称: CVE-2026-64638-WordPress-Core-XSS2Shell
👤 项目作者: renzi25031469
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-07 23:51:38

📝 项目描述:
Template Nuclei para detecção não-intrusiva do XSS2Shell, um parser differential pré-autenticado no WordPress Core que permite injeção de elementos DOM na página de login, servindo de base para uma cadeia de XSS → RCE.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Shellcode #Execute #Evasion

📦 项目名称: PayloadGenerator-Advanced-Obfuscation-Toolkit
👤 项目作者: carped-955514-terry
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-07 23:51:15

📝 项目描述:
extension Tools & Packers – A professional-grade Windows toolkit for advanced payload generation, obfuscation, and analysis for security research.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Shellcode #Execute

📦 项目名称: Exploit-Dev-Toolkit
👤 项目作者: ridhinva
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-07 20:20:06

📝 项目描述:
Toolkit: Modular exploit development — protocol fuzzer, payload generator, ROP builder, shellcode encoder in Python

🔗 点击访问项目地址