GitHub 红队武器库🚨
13.6K subscribers
20 photos
9 videos
23.6K links
📦 GitHub 全球红队渗透资源中转站。
​旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
⚠️ 本频道仅供安全研究与授权测试使用。
Download Telegram
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Exploit #CVE #RCE

📦 项目名称: CVE-2025-55182-Exploit
👤 项目作者: dotnetguard
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-12 01:01:39

📝 项目描述:
CVE-2025-55182 — Next.js Flight Deserialization RCE exploit with interactive shell, single-command execution and multi-payload reverse shell chain. For authorized penetration testing only.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #RCE #POC

📦 项目名称: rules-cuda-comment-trigger-rce-poc
👤 项目作者: 2423gen-stack
🛠 开发语言: Shell
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-12 00:56:06

📝 项目描述:
Responsible PoC for a missing-authorization-check comment-triggered RCE finding in bazel-contrib/rules_cuda integration-tests.yaml (reported to Google Bug Hunters OSS VRP)

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Burp #Extension

📦 项目名称: portswigger
👤 项目作者: api-evangelist
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-12 00:24:59

📝 项目描述:
PortSwigger is the UK-based security research company behind Burp Suite, the industry-standard web and API security testing platform used by penetration testers and enterprise AppSec teams worldwide.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: ReconPulse
👤 项目作者: YVORYU
🛠 开发语言: Python
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-12 01:44:43

📝 项目描述:
ReconPulse - A lightweight vulnerability scanner written in Python. Functional subdomain enumeration (passive + brute force), multi-threaded port scanning, and verification through PocSuite 3 POC. Output an HTML report.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Exploit #CVE

📦 项目名称: CVE-2022-22947_exp
👤 项目作者: Arrnitage
🛠 开发语言: Python
Star数量: 5 | 🍴 Fork数量: 3
📅 更新时间: 2026-08-12 01:57:03

📝 项目描述:
CVE-2022-22947 Exploit script

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Sliver #C2

📦 项目名称: siren
👤 项目作者: Gubarz
🛠 开发语言: Svelte
Star数量: 17 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-12 02:04:36

📝 项目描述:
A fast, reactive graphical interface (GUI) for managing Sliver C2 operations, powered by Wails and Svelte.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Bypass #WAF

📦 项目名称: wafrift
👤 项目作者: santhreal
🛠 开发语言: Rust
Star数量: 20 | 🍴 Fork数量: 4
📅 更新时间: 2026-08-12 02:59:58

📝 项目描述:
WAF evasion testing toolkit. Grammar + encoding mutation, dialect-specific bypasses, evolutionary search, per-WAF gene-bank persistence. Rust.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Sliver #C2

📦 项目名称: c4
👤 项目作者: CR1MS0N-Operator
🛠 开发语言: Go
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-12 03:46:25

📝 项目描述:
C2 Control Center — deploy, manage, and destroy C2 frameworks (Mythic, Sliver) from one CLI

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Kubernetes #POC

📦 项目名称: ai-self-healing-cicd
👤 项目作者: narayanareddy11
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-12 04:06:32

📝 项目描述:
AI-assisted self-healing CI/CD platform POC with FastAPI services, Docker, Kubernetes, GitHub Actions, LangGraph RCA agents, verification, and human-reviewed remediation PRs.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #RCE #Remote Code Execution

📦 项目名称: trustload
👤 项目作者: jay-tank
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-12 03:39:53

📝 项目描述:
A zero-config Python AST linter that flags unsafe loading of an ML model/artifact (torch.load without weights_only, pickle/joblib/dill.load, np.load allow_pickle, keras load_model, yaml.load) - arbitrary code execution (CWE-502), the model-supply-chain RCE class. Points you at weights_only=True / safetensors.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #漏洞 #POC #EXP #Exploit #扫描 #复现 #利用 #Nuclei #CVE

📦 项目名称: AutoPoc
👤 项目作者: 1diot9
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-12 02:52:45

📝 项目描述:
根据漏洞公告自动生成Poc

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: network-security-suite
👤 项目作者: prince-dholakiya
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-12 05:03:25

📝 项目描述:
Network vulnerability scanner and traffic monitor with web dashboard.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #POC #CVE

📦 项目名称: CVE-2022-3590
👤 项目作者: 4chech
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-12 04:26:34

📝 项目描述:
PoC Exploit for blind SSRF in XML-RPC Wordpress

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #RCE #CVE #POC

📦 项目名称: MySQL-Remote-Root-Code-Execution
👤 项目作者: Ashrafdev
🛠 开发语言: Python
Star数量: 9 | 🍴 Fork数量: 9
📅 更新时间: 2026-08-12 06:00:42

📝 项目描述:
0ldSQL_MySQL_RCE_exploit.py (ver. 1.0) (CVE-2016-6662) MySQL Remote Root Code Execution / Privesc PoC Exploit For testing purposes only. Do no harm.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #rules

📦 项目名称: basic-python-antivirus
👤 项目作者: vijaykumarsistu789-stack
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-12 05:53:39

📝 项目描述:
Python-based antivirus and endpoint security prototype using SHA-256 signatures, YARA rules, real-time monitoring, quarantine, logging and security reporting.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #云元数据

📦 项目名称: SSRF
👤 项目作者: TaoLjx
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-12 05:35:54

📝 项目描述:
SSRF靶场,覆盖9大分类(基础SSRF、协议级SSRF、IP地址过滤绕过、URL解析器混淆、302重定向SSRF、DNS Rebinding、Blind SSRF、云元数据攻击、真是业务场景),真实业务场景覆盖12个真实的业务场景(webhook测试器、URL预览、图片代理/CDN、PDF生成器、API网关/代理、RSS阅读器、从URL导入文件、短链接展开器、健康检查监控、OAuth SSO重定向、支付回调曾是、网页截图服务)

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Fastjson #反序列化

📦 项目名称: JavaDeserialization
👤 项目作者: TaoLjx
🛠 开发语言: Java
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-12 06:41:33

📝 项目描述:
Java反序列化靶场,涵盖CB、CC、Dubbo、Fastjson、Hessian、Jndi、Log4j、Shiro、Weblogic等Java反序列化场景

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: cyber-ghost-scanner
👤 项目作者: eghbalizade411-ux
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-12 06:43:24

📝 项目描述:
An advanced web vulnerability scanner with WAF bypass, AI assistance, and hacker-style terminal.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: vulnerability-scanner
👤 项目作者: 2403396160267-crypto
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-12 06:32:49

📝 项目描述:
vulnerability scanner

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #rules #malware

📦 项目名称: dev-trap-dossiers
👤 项目作者: bryanchriswhite
🛠 开发语言: Unknown
Star数量: 3 | 🍴 Fork数量: 1
📅 更新时间: 2026-08-12 07:22:22

📝 项目描述:
Dossiers of developer-targeted malware campaigns delivered via fake-recruiter pitches. Each case has a master analysis plus copy-paste-ready artifacts for would-be victims, abuse desks, detection engineers, and researchers.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #RCE #Remote Code Execution

📦 项目名称: CodeForge-RCE
👤 项目作者: DevXDividends
🛠 开发语言: Jupyter Notebook
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-12 07:36:48

📝 项目描述:
无描述

🔗 点击访问项目地址