GitHub 红队武器库🚨
13.9K subscribers
21 photos
10 videos
24.7K links
📦 GitHub 全球红队渗透资源中转站。
​旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
⚠️ 本频道仅供安全研究与授权测试使用。
Download Telegram
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: VulnerabilityManager
👤 项目作者: jordobe
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-25 11:52:38

📝 项目描述:
Docker based vulnerability scanner project based on the Greenbone Community Edition/OpenVAS

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Burp #Extension

📦 项目名称: WorkflowGuard
👤 项目作者: aleff-github
🛠 开发语言: Java
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-25 11:56:00

📝 项目描述:
State-aware Burp Suite extension for mutating multi-step workflows and detecting business-logic flaws with probes, invariants, isolated actors, and cleanup.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #RCE #Remote Code Execution

📦 项目名称: Acelle-Mail-4.2.0-p97-Unauthenticated-SSTI-to-RCE-Chain
👤 项目作者: Yucaerin
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-25 11:46:07

📝 项目描述:
The email marketing platform Acelle Mail version 4.2.0-p97 is vulnerable to a full unauthenticated Remote Code Execution through a multi-step exploitation chain

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #RCE #POC #Remote Code Execution

📦 项目名称: QVD-2026-57410
👤 项目作者: HackSpeak
🛠 开发语言: Python
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-25 12:40:16

📝 项目描述:
QVD-2026-57410 (DeepSeek Harness Host Header Bypass → RCE) PoC toolkit - HTTP Host header trust flaw leading to unauthenticated remote code execution; for authorized security testing

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Burp #Extension

📦 项目名称: Burp-MCP-Client
👤 项目作者: TiggySkibbles
🛠 开发语言: Java
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-25 12:57:23

📝 项目描述:
A simple burp extension to simplify MCP testing.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: owasp-observatory
👤 项目作者: nizarmochamad
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-25 12:56:36

📝 项目描述:
Vulnerability scanner tools based on OWAPS TOP 10

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #malware

📦 项目名称: MalyxScanner
👤 项目作者: maelmeriguet4-glitch
🛠 开发语言: Python
Star数量: 2 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-25 13:18:05

📝 项目描述:
Offline static malware analysis engine, PE inspector & incident triage desktop utility.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #Reflected

📦 项目名称: web-vuln-scanner
👤 项目作者: Vadivel-dotcom
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-25 13:44:34

📝 项目描述:
Modular Python web vulnerability scanner — SQLi, reflected XSS, port scan, SSL/TLS & security-header checks with console + HTML reporting.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Burp #插件 #漏洞

📦 项目名称: API-Sentinel
👤 项目作者: Flechzao
🛠 开发语言: Unknown
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-25 14:06:53

📝 项目描述:
AI 驱动的 Burp Suite API 安全自动化分析插件 —— 流量捕获、漏洞验证、证据驱动的全流程,无需手动把流量复制粘贴给 ChatGPT 网页。

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Burp #Extension

📦 项目名称: Burp-Extension
👤 项目作者: tjat94
🛠 开发语言: Java
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-25 13:41:19

📝 项目描述:
无描述

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #RCE #Remote Code Execution

📦 项目名称: Conversor-XSLT-RCE
👤 项目作者: ChrisLPJones
🛠 开发语言: C#
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-25 14:38:49

📝 项目描述:
C# exploit chaining XSLT injection to remote code execution against the retired Hack The Box machine "Conversor". Includes vulnerability analysis and defensive mitigations.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #Reflected

📦 项目名称: security-scanner
👤 项目作者: YavuzSelimUnal
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-25 14:34:59

📝 项目描述:
Full-stack web security scanner that checks a site for common vulnerabilities (headers, TLS, exposed paths, cookies, open ports, outdated libraries, reflected XSS) and presents findings as a live "detective case file" UI.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: keycloak-CVE-2026-18963
👤 项目作者: gman0x00
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-25 15:27:37

📝 项目描述:
PoC, Dockerfile playground and root cause from patch diff analysis.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Exploit #CVE #POC

📦 项目名称: CVE-Exploit-POC
👤 项目作者: pyshawon
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-25 15:51:32

📝 项目描述:
CVE Exploit POCs

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Spring #POC

📦 项目名称: spring-boot-calcite-federated-poc
👤 项目作者: misonny-su
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-25 16:00:45

📝 项目描述:
Spring Boot 2 + MyBatis-Plus + Druid + Dynamic-Datasource + Calcite federated query POC

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: hiteshnexussecurity
👤 项目作者: Hitesh200906
🛠 开发语言: TypeScript
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-25 16:00:27

📝 项目描述:
Nexus Security - AI-powered vulnerability scanner

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #漏洞 #Exploit #利用

📦 项目名称: dsh-exploit-kit
👤 项目作者: jonah791
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-25 15:39:29

📝 项目描述:
漏洞利用原语库:把打靶场经验固化为可组合的利用原语(命令注入/弱类型/Web绕过/JWT/序列化/ECB块拼接),模型负责策略、工具负责生成

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #CVE

📦 项目名称: CVE-2026-32635-Angular-XSS-Mitigation-
👤 项目作者: fevar54
🛠 开发语言: YARA
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-25 16:01:58

📝 项目描述:
Este repositorio contiene una demostración educativa de la mitigación y detección para **CVE-2026-32635**, una vulnerabilidad de **Cross-Site Scripting (XSS)** en Angular que afecta a los atributos internacionalizados (i18n).

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #CVE #Stored

📦 项目名称: CVE-2026-26211
👤 项目作者: LindHunt
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-25 16:01:02

📝 项目描述:
Public disclosure for CVE-2026-26211, a stored XSS vulnerability affecting Ekushey Project Manager CRM v5.0.

🔗 点击访问项目地址
😨1
🚨 GitHub 监控消息提醒

🚨 发现关键词: #RCE #CVE

📦 项目名称: CVE-2018-16763_fuel_cms_exploit
👤 项目作者: gh0stuncle
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-25 15:31:24

📝 项目描述:
A fuel CMS exploit based on Python for RCE mentioned in CVE-2018-16763.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #rules #malware

📦 项目名称: yara-detection-rules
👤 项目作者: Ashishnagar496
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-25 16:05:21

📝 项目描述:
A collection of YARA detection rules for identifying malware, ransomware, trojans, stealers, and other suspicious files using static and behavioral indicators.

🔗 点击访问项目地址