GitHub 红队武器库🚨
13.6K subscribers
20 photos
9 videos
23.6K links
📦 GitHub 全球红队渗透资源中转站。
​旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
⚠️ 本频道仅供安全研究与授权测试使用。
Download Telegram
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Exploit #RCE

📦 项目名称: deepslop
👤 项目作者: badrcoderman
🛠 开发语言: HTML
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-10 18:04:53

📝 项目描述:
DEEPSLOP — PS5 WebKit exploit kit (RCE dashboard): PROBE mode, self-porting offset scanner, LOW_MEM, beacon logging, REPL loader

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Burp #Plugin

📦 项目名称: anomaly-ranker-caido
👤 项目作者: aleister1102
🛠 开发语言: TypeScript
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-10 18:23:43

📝 项目描述:
Caido plugin that ranks HTTP responses by anomaly using a Burp-inspired categorical frequency model.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: SentinelScan
👤 项目作者: Roxxhard
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-10 19:47:17

📝 项目描述:
AI-powered Web Vulnerability Scanner

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #C2 #Framework

📦 项目名称: BEAR-C2
👤 项目作者: S3N4T0R-0X0
🛠 开发语言: Python
Star数量: 530 | 🍴 Fork数量: 106
📅 更新时间: 2026-08-10 19:59:38

📝 项目描述:
BEAR-C2 is an adversary simulation and emulation framework built around real world TTPs inspired by Russian, Chinese, North Korean, and Iranian APT groups.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Burp #Extension

📦 项目名称: socketsleuth
👤 项目作者: snyk
🛠 开发语言: Java
Star数量: 107 | 🍴 Fork数量: 19
📅 更新时间: 2026-08-10 19:31:21

📝 项目描述:
Burp Extension to add additional functionality for pentesting websocket based applications

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: God-eye
👤 项目作者: g0d150ne
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-10 20:58:10

📝 项目描述:
Ultimate Vulnerability Scanner - Web + Cloud + Infrastructure 100+ Vulnerability Types • 1100+ Payloads • Full Takeover Capable

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: php-ai-security-scanner
👤 项目作者: BangPiyus
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-10 20:54:53

📝 项目描述:
AI-powered PHP vulnerability scanner and static security analyzer for detecting SQL injection, XSS, RCE, malware, backdoors, secrets, and insecure code.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #RCE #CVE #Remote Code Execution

📦 项目名称: CVE-2025-2945
👤 项目作者: g0d150ne
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-10 20:52:45

📝 项目描述:
Exploit for pgAdmin4 Remote Code Execution (RCE) vulnerability affecting versions 8.10 to 9.1.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #RCE

📦 项目名称: XSS2Shell
👤 项目作者: g0d150ne
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-10 21:08:48

📝 项目描述:
XSS2Shell ULTIMATE v3.0 is a powerful exploitation tool that chains Cross-Site Scripting (XSS) vulnerabilities in WordPress to achieve Remote Code Execution (RCE). This tool exploits CVE-2026-64638 to gain full control over vulnerable WordPress installations.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #Exploit

📦 项目名称: WP2Shell
👤 项目作者: g0d150ne
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-10 21:08:17

📝 项目描述:
WP2Shell is a powerful and modular exploit framework that combines two critical WordPress vulnerabilities (CVE-2026-63030 and CVE-2026-60137) to achieve complete compromise of a target site without any credentials.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #提权 #CVE

📦 项目名称: ghostlock-apk
👤 项目作者: oopnv70-lab
🛠 开发语言: Java
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-10 22:03:42

📝 项目描述:
独立 APK:CVE-2026-43499 GhostLock 提权 + Shizuku shell 身份执行

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #malware

📦 项目名称: dfir-malware-lab
👤 项目作者: ronankongala
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-10 22:31:22

📝 项目描述:
DFIR and Malware Analysis Lab - FlareVM, REMnux, Ghidra, CAPA, YARA, Volatility 3

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #rules #malware

📦 项目名称: iocs
👤 项目作者: ThreatLabz
🛠 开发语言: YARA
Star数量: 79 | 🍴 Fork数量: 16
📅 更新时间: 2026-08-10 22:20:54

📝 项目描述:
This repository is for Indicators of Compromise (IOCs) from Zscaler ThreatLabz public reports

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Credential Dumping #LSASS

📦 项目名称: Lab-05-Wazuh-XDR-EDR-Deployment
👤 项目作者: Izaiah1996
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-10 22:12:40

📝 项目描述:
Single-node Wazuh 4.12.0 stack deployed on the management segment of a multi-VLAN home SOC lab, with agents enrolled on a Windows domain controller and workstation, plus a custom MITRE ATT&CK mapped detection rule for LSASS credential dumping.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #利用

📦 项目名称: CVE-2026-9198
👤 项目作者: CuteeCat
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-11 00:55:51

📝 项目描述:
CVE-2026-9198利用代码

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: vuln-scanner
👤 项目作者: devkroz
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-11 00:41:42

📝 项目描述:
Web vulnerability scanner — XSS, SQLi, CRLF, path traversal, command injection, open redirect, security headers

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: CVE-2026-23744-PoC
👤 项目作者: Mluex0
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-11 01:52:07

📝 项目描述:
CVE-2026-23744 is an unauthenticated command injection in MCPJam Inspector ≤1.4.2 via /api/mcp/connect. This POC exploits it by sending a crafted JSON payload to execute arbitrary commands, granting a reverse shell with PTY.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #Stored

📦 项目名称: task-manager-rest-api
👤 项目作者: RamahB0
🛠 开发语言: JavaScript
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-11 00:20:21

📝 项目描述:
A secure Task Manager REST API with JWT + Google OAuth (Passport.js) auth, HTTP-only cookie sessions, owner-scoped task routes, helmet/xss-clean/mongo-sanitize hardening, rate limiting, and centralized error handling (AppError + catchAsync).

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #Stored #Reflected #DOM

📦 项目名称: devtalks-xss
👤 项目作者: orfloresti
🛠 开发语言: HTML
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-11 00:15:48

📝 项目描述:
无描述

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #RCE #CVE #POC #Remote Code Execution

📦 项目名称: Dead-Dial
👤 项目作者: 0xReadingSteiner
🛠 开发语言: Shell
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-11 00:11:27

📝 项目描述:
Pre-authentication RCE in Cisco CUCM 15.x via Apache Axis JNDI injection — independent chain, survives Silent;Call patches

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Burp #Extension

📦 项目名称: burp-sf-aura
👤 项目作者: n0r1k4zu
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-11 00:21:54

📝 项目描述:
无描述

🔗 点击访问项目地址