GitHub 红队武器库🚨
14.3K subscribers
25 photos
10 videos
27.7K links
​📦 GitHub 全球红队渗透资源中转站。
​旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
​⚠️ 本频道仅供安全研究与授权测试使用。
Download Telegram
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: vulnerability-scanner
👤 项目作者: spoorthisb183-dot
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-05 11:42:55

📝 项目描述:
A simple Python vulnerability scanner mini project for educational purposes.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #CVE

📦 项目名称: advanced_pentesting_challenge
👤 项目作者: laurent-fauveau
🛠 开发语言: Unknown
⭐ Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-05 11:48:36

📝 项目描述:
Dépôt du Challenge de Pentesting. Il regroupe la méthodologie, les scripts et les rapports d'audit pour 3 cas pratiques : reconnaissance et exploitation d'infrastructures réseau, pentest d'applications web (OWASP Top 10, SQLi, XSS) et élévation de privilèges sur vulnérabilités système. Inclut fiches CVE, journaux d'attaque et remédiations.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Shellcode #Evasion

📦 项目名称: Python-Shellcode-Anydesk-Apc-injection-Remote-IP-Address-Analysis
👤 项目作者: kaandemir993
🛠 开发语言: Unknown
⭐ Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-05 12:31:10

📝 项目描述:
Reverse engineering analysis of Python shellcode that injects into AnyDesk via APC injection and attempts to connect to a C2 server through AnyDesk. The shellcode was observed to use AES and RSA encryption algorithms to conceal the C2 connection and to establish persistence via the Registry.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #Stored

📦 项目名称: XSS-CloudComputing_Cybersecurity
👤 项目作者: nahasBeatriz
🛠 开发语言: PHP
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-05 12:44:57

📝 项目描述:
Cloud Computing project 02

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #POC

📦 项目名称: BugBounty-Payloads
👤 项目作者: Raunaksplanet
🛠 开发语言: Python
⭐ Star数量: 8 | 🍴 Fork数量: 4
📅 更新时间: 2026-10-05 11:57:32

📝 项目描述:
Curated custom payloads and wordlists for fuzzing: XSS, SQLi, SSRF, LFI, open redirect, WAF bypass, PDF exploits + recon wordlists and regex patterns for bug bounty.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #metadata

📦 项目名称: python-async-servic-payments
👤 项目作者: Sskutushev
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-05 12:27:45

📝 项目描述:
Async payment processing service: FastAPI + PostgreSQL + RabbitMQ (FastStream). Transactional outbox, idempotent API, single checkpointed consumer, 3-attempt retries with DLQ, signed webhooks with SSRF policy. Tested on real PostgreSQL/RabbitMQ + compose e2e.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #metadata

📦 项目名称: ai-docs-rag-agent
👤 项目作者: eliv1982
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-05 12:20:41

📝 项目描述:
Telegram RAG assistant for technical docs: SSRF-aware ingestion, grounded answers over Pinecone, and a bounded tool-calling agent.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: clrfkd
👤 项目作者: type5afe
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-05 12:23:08

📝 项目描述:
Blazing Fast CLRF Vulnerability Scanner

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #Exploit

📦 项目名称: CVE-2026-41875-EXPLOIT-QuickCart-one-click-Account-Takeover
👤 项目作者: krl5
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-05 13:59:30

📝 项目描述:
无描述

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Spring #POC

📦 项目名称: spring-keycloak-2fa-poc
👤 项目作者: rutven
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-05 14:02:08

📝 项目描述:
无描述

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Burp #Extension

📦 项目名称: authentix-enterprise
👤 项目作者: pratik-khairnar-sec
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-05 14:03:16

📝 项目描述:
Official Enterprise Showcase & Executive Demonstration Portal for AUTHENTIX v2.1.0 - Burp Suite Montoya Security Suite

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #Exploit

📦 项目名称: CVE-2026-41875-EXPLOIT-QuickCart-one-click-Account-Takeover
👤 项目作者: hhg69
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-05 13:59:30

📝 项目描述:
无描述

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #漏洞 #POC #扫描 #复现

📦 项目名称: src-report
👤 项目作者: do-whilefor
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-05 11:29:01

📝 项目描述:
针对于SRC漏洞报告的撰写,现在有的字段是京东、美团、快手三家,后续可以添加其他SRC字段

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Shellcode #Evasion #EDR

📦 项目名称: golopas
👤 项目作者: NitelPhyoe
🛠 开发语言: Go
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-05 14:30:57

📝 项目描述:
A minimal Windows shellcode runner written in Go - loads base64 shellcode from disk or a remote URL, decodes it in memory, and executes it via VirtualAlloc + CreateThread. For authorized pentests and security research only. Use at your own risk.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: ProStackHub_NetworkScanner
👤 项目作者: azka-code
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-05 14:50:12

📝 项目描述:
Network Vulnerability Scanner developed for the ProStackHub Cyber Security Internship.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #YARA #rules #malware

📦 项目名称: malware-static-triage
👤 项目作者: ZakariaHibaoui2
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-05 14:43:26

📝 项目描述:
Static malware triage: magic-byte typing, entropy, strings/IOCs, pure-Python PE parser (sections, imports), YARA-style rules, capability vs evasion scoring. Validated on real Windows binaries.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #Exploit #RCE

📦 项目名称: CVE-2026-39987-Marimo-RCE
👤 项目作者: Industri4l-H3ll-Xpl0it3rs
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-05 15:58:24

📝 项目描述:
CVE-2026-39987 Exploit | by infrar3d

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: dependency-vulnerability-scanner
👤 项目作者: ZakariaHibaoui2
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-05 15:56:05

📝 项目描述:
Software composition analysis for Python, npm and Composer: OSV.dev lookups, built-in CVSS 3.1 calculator, alias-aware dedup, branch-aware fix versions, CI policy gates and CycloneDX 1.5 SBOM export.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Shellcode #Evasion #EDR

📦 项目名称: Golopas
👤 项目作者: NitelPhyoe
🛠 开发语言: Go
⭐ Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-05 15:40:41

📝 项目描述:
A minimal Windows shellcode runner written in Go - loads base64 shellcode from disk or a remote URL, decodes it in memory, and executes it via VirtualAlloc + CreateThread. For authorized pentests and security research only. Use at your own risk.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #RCE #CVE #POC

📦 项目名称: FreePBX-Breaker
👤 项目作者: kelltich-756
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-05 16:03:53

📝 项目描述:
PoC y código automatizado para explotar CVE-2025-57819 en FreePBX. Demuestra la vulnerabilidad de Ejecución Remota de Código (RCE) mediante inyección de comandos en el sistema Asterisk. Ideal para entornos HackTheBox.

🔗 点击访问项目地址