GitHub 红队武器库🚨
13.6K subscribers
20 photos
8 videos
23.4K links
📦 GitHub 全球红队渗透资源中转站。
​旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
⚠️ 本频道仅供安全研究与授权测试使用。
Download Telegram
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #rules #malware

📦 项目名称: YARA-Rules-Collection-Malware-Families
👤 项目作者: fantasywastaken
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-08 06:37:20

📝 项目描述:
Curated YARA rules collection covering common malware families and techniques: packed PE detection, Cobalt Strike beacons, downloader stagers, and token grabbers.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #rules #malware

📦 项目名称: drosera-threat-intel
👤 项目作者: AfterPacket
🛠 开发语言: HTML
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-08 07:41:03

📝 项目描述:
Detection artifacts for malware captured live by the Drosera honeypot — YARA, Suricata and Sigma rules, IOC feeds, a machine-readable blocklist and full analysis reports. TLP:WHITE.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #Reflected #DOM

📦 项目名称: detonate
👤 项目作者: santhreal
🛠 开发语言: Rust
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-08 07:59:22

📝 项目描述:
Prove an injected web payload actually EXECUTES (alert(1) fires), not just reflects (a shared XSS-execution oracle over Santh's jsdet sandbox).

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #POC #CVE #Reflected

📦 项目名称: XSS2Shell-CVE-2026-64638
👤 项目作者: yogaGymn
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-08 07:19:28

📝 项目描述:
无描述

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: CVE-2026-64638
👤 项目作者: 4minx
🛠 开发语言: HTML
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-08 08:58:57

📝 项目描述:
CVE-2026-64638 (XSS2shell) POC.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC #RCE

📦 项目名称: CVE-2026-64638
👤 项目作者: HackSpeak
🛠 开发语言: Python
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-08 08:57:26

📝 项目描述:
XSS2Shell (CVE-2026-64638) WordPress pre-auth XSS to RCE PoC mirror — WordSec, MIT; for authorized security testing

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #metadata

📦 项目名称: Common-Web-Application-Bug-Classes-Cheatsheet
👤 项目作者: fantasywastaken
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-08 06:32:05

📝 项目描述:
Defensive OWASP-style cheatsheet of common web application bug classes including SQLi, XSS, SSRF, XXE, IDOR, path traversal, deserialization, and command injection with mitigations.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #RCE #CVE #POC

📦 项目名称: XSS2Shell-CVE-2026-64638
👤 项目作者: Linuxhackingid-official
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-08 08:12:22

📝 项目描述:
CVE-2026-64638 — WordPress Pre-Auth Reflected XSS → RCE via DOM Clobbering + Application Password Theft + REST API Plugin Activation. Dual-mode PoC (XSS chain & direct).

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: Vulnerability-Scanner-SIEM-Dashboard
👤 项目作者: tharushiwickramasinghe
🛠 开发语言: HTML
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-08 08:58:17

📝 项目描述:
An automated vulnerability assessment and patch management engine with an interactive SOC SIEM dashboard in Python, HTML5, and Bootstrap.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #Stored #Reflected

📦 项目名称: vulnub
👤 项目作者: GoDSPIDER212
🛠 开发语言: PHP
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-08 08:55:01

📝 项目描述:
Intentionally vulnerable web app for learning security: SQLi, XSS, IDOR, auth bypass. Docker one-liner, flag-based challenges.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #POC #CVE #Reflected #DOM

📦 项目名称: xss2shell
👤 项目作者: Christbowel
🛠 开发语言: Python
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-08 08:42:41

📝 项目描述:
xss2shell poc and detector

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Exploit #CVE

📦 项目名称: cve-scores
👤 项目作者: ARPSyndicate
🛠 开发语言: Unknown
Star数量: 258 | 🍴 Fork数量: 39
📅 更新时间: 2026-08-08 10:03:33

📝 项目描述:
EPSS & VEDAS Score Aggregator for CVEs

🔗 点击访问项目地址
👍1
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Exploit #RCE

📦 项目名称: java-chains
👤 项目作者: vulhub
🛠 开发语言: Shell
Star数量: 2138 | 🍴 Fork数量: 170
📅 更新时间: 2026-08-08 09:59:34

📝 项目描述:
Java Vulnerability Exploitation Platform

🔗 点击访问项目地址
👍1
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: Automation_Vulnerability-scanning-
👤 项目作者: harukato588
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-08 10:02:39

📝 项目描述:
A Python-based Automated Vulnerability Scanner featuring multithreaded port scanning, service enumeration, CVE database matching, and basic web vulnerability checks. Built for educational purposes

🔗 点击访问项目地址
👍1
🚨 GitHub 监控消息提醒

🚨 发现关键词: #提权 #UAC

📦 项目名称: AdminTerminal-ContextMenu
👤 项目作者: Amoption
🛠 开发语言: PowerShell
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-08 11:03:01

📝 项目描述:
右键"在管理员终端中打开" — Explorer 右键菜单打开已提权 Windows Terminal(v1 PowerShell + v2 wscript 无闪屏版)

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC #Exploit

📦 项目名称: CVE-2026-64638-PoC-Exploit
👤 项目作者: tc4dy
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-08 11:56:07

📝 项目描述:
🛡️ CVE-2026-64638 - WordPress Security Assessment Suite (CVSS 8.9) | WordPress 4.7.0-7.0.2 pentest toolkit. Includes vulnerability assessment & advanced analysis modules. 🐍 Safe Check & Exploit, 2 mode. Advanced Blue&Red Team Best 2026-64638 Toolkit, Authorized use only. Stay Legal <3zd

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #RCE

📦 项目名称: CVE-2026-3844
👤 项目作者: AnggaTechI
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-08 11:45:18

📝 项目描述:
CVE-2026-3844 — Unauthenticated Arbitrary File Upload to RCE in Breeze Cache (WordPress). CVSS 9.8 CRITICAL. Mass scanner + auto shell injector with multi-threading.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: Web-Application-Vulnerability-Scanner
👤 项目作者: subuddhijadhav
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-08 11:30:39

📝 项目描述:
A Python and Flask-based Web Application Vulnerability Scanner that detects common web security vulnerabilities, including XSS, SQL Injection, and insecure HTTP headers. Developed as a cybersecurity project with ongoing enhancements.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #漏洞 #POC

📦 项目名称: poc_scout
👤 项目作者: kaf6rim
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-08 12:03:45

📝 项目描述:
Query IoT firmware CVEs by device/component and auto-download PoCs — an MCP server for AI agents. 物联网固件漏洞情报 + PoC 自动下载的 MCP 工具,供 AI agent 直接调用。

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #metadata

📦 项目名称: algovoi-rfc9421-keyid
👤 项目作者: chopmob-cloud
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-08 11:03:45

📝 项目描述:
SSRF-guarded RFC 9421 keyid resolver (did:key / did:web / HTTPS) to Ed25519 public keys. Apache-2.0.

🔗 点击访问项目地址
Forwarded from 广告赞助
🔥 【全新升级】墙势汹汹,大批机场已阵亡?网络软了,试试 ZTNET 魔法防封! 🛡️🚀

最近大量节点集体断连?别慌!ZTNET 采用自研独家自愈协议,专门治愈各种“失联”焦虑,让你稳如泰山,直接起飞!🔥💦

魔法防封 - 独家混淆技术,无视封锁,大封锁期也丝滑
4K 看片极速 - 拒绝转圈,深夜高清必备,资源秒加载
AI 生产力全开 - 稳定直通 ChatGPT/Claude/Midjourney
全线加速 - TG/X/IG 瞬间刷新,彻底告别“连接中...”

🚀 全新升级 v1.2.0 定制客户端:一键登录,无需配置,老司机的避风港!

👉 【全平台最新 App 下载】
💻 Windows:安装包下载 | 便携版(Zip)
🍏 Mac (M系列):点击下载
🍎 Mac (Intel):点击下载
🤖 Android:点击下载

【 避难入口:点击注册,永不失联 🚀

别人在抓狂,你在起飞!这波稳了,兄弟们速来体验“魔法”! 😈