GitHub 红队武器库🚨
13.3K subscribers
19 photos
7 videos
21.9K links
📦 GitHub 全球红队渗透资源中转站。
​旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
⚠️ 本频道仅供安全研究与授权测试使用。
Download Telegram
🚨 GitHub 监控消息提醒

🚨 发现关键词: #漏洞 #利用

📦 项目名称: immunex
👤 项目作者: tyatca
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-18 11:07:33

📝 项目描述:
自免疫安全平台 | 带洞安全运行 - 基于 eBPF + 深度学习的浏览器内核漏洞利用检测

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #rules

📦 项目名称: SentinelPDF
👤 项目作者: adnandudhwala010
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-18 11:54:20

📝 项目描述:
Developed a Flask-based web application to analyze PDF files for malicious content using static analysis, YARA rules, metadata inspection, entropy analysis, and detailed PDF reports. Implemented secure authentication, scan history, and a responsive dashboard.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: WaveGuard
👤 项目作者: abhishek969179
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-18 11:35:17

📝 项目描述:
A Python-based vulnerability scanner with port scanning, security header analysis, and report generation

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Bypass #WAF

📦 项目名称: scrAPE
👤 项目作者: rhaffle87
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-18 12:07:57

📝 项目描述:
Batch media scraper with Turnstile/WAF bypass, parallel downloads, CapSolver integration, and cross-platform compatibility.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: CVE-2026-63030
👤 项目作者: 4minx
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-18 12:54:46

📝 项目描述:
CVE-2026-63030 (wp2shell) POC.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #C2 #Beacon

📦 项目名称: NetSupport-RAT-Suricata-Detection
👤 项目作者: gowtham526
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-18 12:58:30

📝 项目描述:
Custom Suricata detection rule built and tested against a NetSupport RAT C2 beacon PCAP — from manual traffic analysis to automated detection.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: Vulnerability_Scanner
👤 项目作者: MR-dineshe
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-18 13:54:29

📝 项目描述:
a simple script to detect common vulnerabilities in a web application or network. Key Features: Scan for open ports or weak configurations Identify outdated software versions Generate a simple vulnerability report

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Nuclei #template

📦 项目名称: Wordpress-wp2shell-version-detect
👤 项目作者: renzi25031469
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-18 13:45:59

📝 项目描述:
A passive, non-intrusive Nuclei template that fingerprints WordPress installations running versions vulnerable to wp2shell — a pre-authentication RCE chain in WordPress Core disclosed by Searchlight Cyber / Assetnote on July 17, 2026.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #RCE #CVE

📦 项目名称: wp2shell-detector
👤 项目作者: Christbowel
🛠 开发语言: Python
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-18 13:11:58

📝 项目描述:
ependency-free detector for the wp2shell WordPress Core RCE chain

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC #Exploit #RCE

📦 项目名称: CVE-2026-63030
👤 项目作者: mverschu
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-18 14:39:10

📝 项目描述:
PoC Exploit of WordPress Core Unauthenticated RCE

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #RCE

📦 项目名称: wp2shell
👤 项目作者: 0xsha
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-18 14:29:00

📝 项目描述:
CVE-2026-63030 + CVE-2026-60137 - “wp2shell”: unauthenticated RCE in WordPress core

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: SecureScan
👤 项目作者: pratyushCyber01
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-18 14:40:31

📝 项目描述:
A modular web vulnerability scanner built with Python and Flask for identifying common web security misconfigurations and generating detailed security assessment reports.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #POC #RCE

📦 项目名称: wp2shell-poc
👤 项目作者: sergiointel
🛠 开发语言: Python
Star数量: 17 | 🍴 Fork数量: 5
📅 更新时间: 2026-07-18 16:00:18

📝 项目描述:
Stock vulnerable wordpress RCE poc for wp2shell.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Nuclei #template #CVE

📦 项目名称: nuclei-scan
👤 项目作者: eazypyz
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-18 15:17:41

📝 项目描述:
Scan nuclei

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: vulnerability-scanner
👤 项目作者: annanthu
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-18 16:01:47

📝 项目描述:
AI Automated vulnerability scanner

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: purple-grid
👤 项目作者: Amir-Abdaoui
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-18 15:49:31

📝 项目描述:
AI-Powered Vulnerability Scanner API — Production-grade DevSecOps portfolio project

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #RCE

📦 项目名称: wp2shell
👤 项目作者: h4cd0c
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-18 16:41:06

📝 项目描述:
wp2shell — Pre-authentication RCE in WordPress Core (CVE-2026-60137 + CVE-2026-63030). Chains an SQL injection in author__not_in with batch-route confusion for unauthenticated remote code execution on WP 6.9.0–6.9.4 / 7.0.0–7.0.1.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #malware

📦 项目名称: YARA-Hello-World-Malware-Detection-Lab
👤 项目作者: dontrellkwilson-cyber
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-18 16:58:53

📝 项目描述:
This lab introduces malware analysis with YARA, an open-source pattern-matching tool used to detect files or processes that contain defined strings, regular expressions, or other conditions.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #RCE

📦 项目名称: wp2shell_scanner
👤 项目作者: zi3lak
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-18 17:56:49

📝 项目描述:
Non-intrusive detection scanner for the WordPress wp2shell pre-auth RCE chain (CVE-2026-63030 + CVE-2026-60137). Detection-only, no exploitation.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC #Exploit

📦 项目名称: wp2shell
👤 项目作者: 0xWhoknows
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-07-18 17:33:49

📝 项目描述:
Automated exploit chain for CVE-2026-63030 / CVE-2026-60137 — unauthenticated blind SQLi via WordPress REST batch route-confusion. Dumps user hashes, cracks credentials, deploys webshell. Supports single target and bulk site lists. For authorized security testing only.

🔗 点击访问项目地址