GitHub 红队武器库🚨
13.6K subscribers
20 photos
9 videos
23.5K links
📦 GitHub 全球红队渗透资源中转站。
​旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
⚠️ 本频道仅供安全研究与授权测试使用。
Download Telegram
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC #RCE

📦 项目名称: CVE-2026-39987-Poc
👤 项目作者: MADA0L
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-10 02:08:14

📝 项目描述:
Proof of Concept (PoC) WebSocket client for CVE-2026-39987 (Marimo Pre-Auth RCE), intended for authorized security testing.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #POC #漏洞

📦 项目名称: poc-lib
👤 项目作者: yangyu91
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-10 05:02:21

📝 项目描述:
POC 漏洞利用库:按类型与严重程度整理的漏洞验证/利用样本

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #漏洞 #扫描

📦 项目名称: Xuanjian-Sec-Agent
👤 项目作者: huoqi1004
🛠 开发语言: Python
Star数量: 4 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-10 04:54:41

📝 项目描述:
玄鉴安全智能体是一个基于AI和MCP (Model Context Protocol) 架构的网络安全解决方案,通过集成多种主流安全工具和大语言模型,实现智能化的威胁检测、漏洞扫描、防御响应和取证分析。 ### 核心特性 - 🤖 **AI双模型架构** - 监督模型 (DeepSeek): 战略规划、结果审查、安全合规 - 执行模型 (本地Qwen/DeepSeek-Code/Claude等): 工具调用、实时响应 。

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #rules #malware

📦 项目名称: malware-analysis
👤 项目作者: stalin003
🛠 开发语言: YARA
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-10 04:50:54

📝 项目描述:
malware analysis and yara rules

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Nuclei #templates

📦 项目名称: endolum-nuclei-templates
👤 项目作者: Endolum-io
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-10 05:08:03

📝 项目描述:
无描述

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #CVE

📦 项目名称: btcpay-scanner
👤 项目作者: iktok90-design
🛠 开发语言: JavaScript
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-10 05:59:57

📝 项目描述:
Network scanner for BTCPay Server instances — version detection, SSRF CVE auditor (< 2.4.2), and Lightning node discovery

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Sliver #C2

📦 项目名称: aws-redteam-iac
👤 项目作者: uLl0a
🛠 开发语言: HCL
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-10 05:23:19

📝 项目描述:
Automated Red Team infrastructure in AWS using Terraform and Ansible. Features a FortiGate firewall, Zero-Touch IPsec VPN, and secure Sliver C2 deployment.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #漏洞 #POC #利用

📦 项目名称: aipoc
👤 项目作者: yangyu91
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-10 05:29:56

📝 项目描述:
AI POC Thinking Skill - 从7468条真实POC中提炼的AI漏洞利用思维框架

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #信息收集 #子域名

📦 项目名称: InfoSec-Learning
👤 项目作者: mumuuuuuuuuu
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-10 03:46:34

📝 项目描述:
信息收集学习笔记与工具实践

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #提权 #UAC

📦 项目名称: Windows-Sudo
👤 项目作者: wudream813
🛠 开发语言: C++
Star数量: 3 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-10 05:32:05

📝 项目描述:
一个单文件、静态编译的 Windows 提权工具。它能够在不弹出新窗口的情况下(内联模式),以任意用户身份运行命令。

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #提权 #UAC

📦 项目名称: FileUnlocker
👤 项目作者: yangshu114514
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-10 04:24:30

📝 项目描述:
Windows 右键菜单解除文件/文件夹占用 (handle检测 + SYSTEM提权 + 多选合并)

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Shellcode #Loader

📦 项目名称: Resource-Loading
👤 项目作者: Evilearth-dotcom
🛠 开发语言: C++
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-10 07:14:07

📝 项目描述:
Embedding Shellcode in C++

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: Automated-Web-Vulnerability
👤 项目作者: Tsuru-chan
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-10 07:52:56

📝 项目描述:
Automated Web Vulnerability Scanner & Report Generator

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #蜜罐 #部署

📦 项目名称: NezhaGuard
👤 项目作者: ctkqiang
🛠 开发语言: C++
Star数量: 3 | 🍴 Fork数量: 1
📅 更新时间: 2026-08-10 07:29:31

📝 项目描述:
NezhaGuard — 基于 Qt6 / C++26 的实时安全信息与事件管理系统,面向蓝队的主动防御平台。部署于服务器/边缘节点,通过 libpcap 混杂模式抓包 + 日志文件监控 + 蜜罐诱饵三层数据源,经协议解码 → 攻击签名匹配 → 速率异常检测 → 告警聚合去重 → 主动响应(ICMP/TCP RST 隔离)的完整流水线,实现对网络威胁的实时感知与自动阻断。

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Sliver #C2

📦 项目名称: SliverC2-Evasion-Suite-swzhouu
👤 项目作者: swzhouu
🛠 开发语言: Go
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-10 08:06:08

📝 项目描述:
Modified four-kit defense evasion suite for Sliver C2: Crystal Palace loader, sleep masking, in-memory PE execution, and remote process injection with PPID spoofing.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Bypass #Sandbox

📦 项目名称: W0lfSword
👤 项目作者: kaffeindecaf
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-10 08:07:31

📝 项目描述:
iOS Kernel Exploit Toolkit | DarkSword Engine, Sandbox escape, SSV bypass, multi-app support. iOS 17.0–26.0.1.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #rules #malware

📦 项目名称: Threat-Lens
👤 项目作者: AhmedELNajjar-dev
🛠 开发语言: YARA
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-10 08:41:51

📝 项目描述:
Automated Malware Intelligence Pipeline powered by LangGraph & Groq AI. Perform static analysis, YARA scanning, string extraction, and VirusTotal lookups with a single click.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #漏洞 #CVE

📦 项目名称: CVE-2017-7921-Research-Toolkit
👤 项目作者: Wyl-cmd
🛠 开发语言: Python
Star数量: 5 | 🍴 Fork数量: 1
📅 更新时间: 2026-08-10 08:21:55

📝 项目描述:
用于借助FOFA快速测试海康威视的CVE-2017-7921漏洞,并且给出登陆账号和密码,并输出json文件。

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #POC #CVE #RCE

📦 项目名称: CVE-2026-23744-MCPJam-Inspector-Unauthenticated-RCE-Proof-of-Concept
👤 项目作者: amao26
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-10 09:07:17

📝 项目描述:
CVE-2026-23744 is an unauthenticated command injection in MCPJam Inspector ≤1.4.2 via /api/mcp/connect. This POC exploits it by sending a crafted JSON payload to execute arbitrary commands, granting a reverse shell with PTY.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: CVE-2026-23744-PoC
👤 项目作者: amao26
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-10 09:53:23

📝 项目描述:
CVE-2026-23744 is an unauthenticated command injection in MCPJam Inspector ≤1.4.2 via /api/mcp/connect. This POC exploits it by sending a crafted JSON payload to execute arbitrary commands, granting a reverse shell with PTY.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Fscan #内网 #漏洞 #POC

📦 项目名称: fscan-toolkit
👤 项目作者: chu0119
🛠 开发语言: HTML
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-10 00:26:29

📝 项目描述:
fscan 图形化管理工具套件 — 命令生成器 + 报告解析器,零依赖纯静态 HTML

🔗 点击访问项目地址