GitHub 红队武器库🚨
14.3K subscribers
25 photos
10 videos
27.7K links
​📦 GitHub 全球红队渗透资源中转站。
​旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
​⚠️ 本频道仅供安全研究与授权测试使用。
Download Telegram
🚨 GitHub 监控消息提醒

🚨 发现关键词: #0day #漏洞

📦 项目名称: coruna
👤 项目作者: corunalab
🛠 开发语言: JavaScript
⭐ Star数量: 0 | 🍴 Fork数量: 1
📅 更新时间: 2026-10-07 20:12:08

📝 项目描述:
Latest Frontiers in Mobile Security (2026): Focused on gathering and synchronizing the latest threat intelligence regarding iOS Coruna vulnerabilities and DarkSword zero-day exploits. 2026 最新移动安全前沿:专注收集与同步 iOS Coruna 漏洞及 DarkSword 零日(0day)最新威胁情报。

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #Stored #Reflected #DOM

📦 项目名称: web-security-scanner
👤 项目作者: AlphaFoxDelta
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-07 22:09:39

📝 项目描述:
Lightweight web security scanner: security headers, cookie flags, and XSS/SQLi/open-redirect probes.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Nuclei #template #POC #CVE

📦 项目名称: CVE-2025-58226-PoC
👤 项目作者: QASIM1401
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-07 23:46:59

📝 项目描述:
CVE-2025-58226 — 3D FlipBook <= 1.16.16 unauthenticated sensitive data exposure: two-stage PoC (enumerate -> leak file URLs -> download) + nuclei template

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Vulnerability Scanner

📦 项目名称: san25-scanner
👤 项目作者: priyanshu-dhaliwal
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-07 23:55:15

📝 项目描述:
SAN-25: 25-check vulnerability scanner (network, web, TLS, creds, config, DVWA lab). Pure Python, zero deps.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #XSS #POC

📦 项目名称: POC_10072026_Manager_4
👤 项目作者: Ibrahim-Sartawi
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-07 23:28:01

📝 项目描述:
XSS_to_CSRF_create_New_Admin_account

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Spring #POC

📦 项目名称: consignado
👤 项目作者: robertosrjr
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-08 00:04:37

📝 项目描述:
PoC de arquitetura para a virada de folha do crédito consignado: absorve 10.000 propostas/s na borda com HTTP 202 em p95 < 100 ms, garante idempotência atômica no DynamoDB e alimenta o Core Banking legado em no máximo 180 TPS com QoS 70/30. Java 25, Spring Boot 4, AWS.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #CVE-2026 #POC

📦 项目名称: CVE-2026-5430-WSO2
👤 项目作者: davidvrns
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-08 00:43:34

📝 项目描述:
Detection PoC for CVE-2026-5430 — unauthenticated JWT algorithm bypass (CVSS 10.0) affecting WSO2 API Manager 4.1.0–4.6.0. Read-only assessment tool with patch confirmation and WAF detection. Authorized use only.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #漏洞 #复现 #利用

📦 项目名称: found-issues
👤 项目作者: sodesu99
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-07 21:35:31

📝 项目描述:
我发现过的 bug / 漏洞 / 设计缺陷记录库 — 任何人都可以在这里提交自己的发现

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #漏洞 #扫描 #利用

📦 项目名称: Darksword
👤 项目作者: daniel875147-crypto
🛠 开发语言: JavaScript
⭐ Star数量: 1 | 🍴 Fork数量: 1
📅 更新时间: 2026-10-08 01:48:48

📝 项目描述:
DarkSword内核漏洞,支持 iOS13-17.2.1以及18.4-18.7.2

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #漏洞 #复现

📦 项目名称: k33etfpp8
👤 项目作者: gemini0ani
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-08 01:30:57

📝 项目描述:
x674q9ifJeecgBoot 未授权权限绕过 + SQL 注入组合漏洞分析与复现4j9em1kkcv0m

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Exploit #CVE

📦 项目名称: cve-exploit-prediction
👤 项目作者: nicky-quist
🛠 开发语言: Jupyter Notebook
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-08 02:05:19

📝 项目描述:
无描述

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #RCE #Remote Code Execution

📦 项目名称: ARTXploit
👤 项目作者: therustymate
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-08 02:55:16

📝 项目描述:
ARTEX v0.3.14 Remote Code Execution via TOCTOU Race Condition

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Nuclei #templates

📦 项目名称: personal-nuclei-templates
👤 项目作者: axosecurity
🛠 开发语言: JavaScript
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-08 02:20:10

📝 项目描述:
Personal Nuclei Templates - Custom Nuclei templates collection with instant NPX sync utility

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Jenkins #EXP

📦 项目名称: Jenkins_tomcat
👤 项目作者: Mariaa-del
🛠 开发语言: Java
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-08 02:51:37

📝 项目描述:
jenkins tomcat exp

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #漏洞

📦 项目名称: vuln-scan-fix
👤 项目作者: lng255639-cpu
🛠 开发语言: Python
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-08 02:18:38

📝 项目描述:
Claude Code skill:掃描整個專案的資安漏洞(注入、XSS、SSRF、寫死密鑰、相依套件等),確認後修補、跑測試驗證並產出報告

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Bypass #MFA

📦 项目名称: naulidata-cyberrange
👤 项目作者: iduy01
🛠 开发语言: Unknown
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-08 03:00:09

📝 项目描述:
Cyber Range Lab - "Cookies Reuse & MFA Bypass" (Red vs Blue) | PT Nauli Mula Data Assessment

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #渗透测试 #内网

📦 项目名称: dsh-pentest-framework-desktop
👤 项目作者: Nanmu-del
🛠 开发语言: JavaScript
⭐ Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-08 02:07:24

📝 项目描述:
DSH 渗透测试框架桌面端(DSH Desktop / Electron):九模式 + 插件 + 一键部署 CLI

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #渗透测试 #内网

📦 项目名称: dsh-pentest-framework
👤 项目作者: Nanmu-del
🛠 开发语言: JavaScript
⭐ Star数量: 1 | 🍴 Fork数量: 1
📅 更新时间: 2026-10-08 02:07:16

📝 项目描述:
DSH 渗透测试框架:索引式提示词 + 按需规则库 + 9 模式 + 17 插件 + 一键部署 CLI

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Shellcode #Evasion

📦 项目名称: ShellcodeFluctuation_crosscompile
👤 项目作者: grisuno
🛠 开发语言: C
⭐ Star数量: 2 | 🍴 Fork数量: 1
📅 更新时间: 2026-10-08 03:33:55

📝 项目描述:
An advanced in-memory evasion technique fluctuating shellcode's memory protection between RW/NoAccess & RX and then encrypting/decrypting its contents, i only rewrite in c to be compatible with x86_64-w64-mingw32-gcc, original idea from mgeeky https://github.com/mgeeky/ShellcodeFluctuation

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #Shellcode #Execute #Evasion

📦 项目名称: netsh_helper_dll
👤 项目作者: grisuno
🛠 开发语言: C
⭐ Star数量: 4 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-08 03:33:35

📝 项目描述:
This project leverages the legitimate "Netsh Helper DLL" functionality in Windows to execute malicious code (shellcode) within the context of the trusted netsh.exe process. Ideal for evasion and lateral movement in Windows environments.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #metadata

📦 项目名称: hostfence
👤 项目作者: hon900
🛠 开发语言: JavaScript
⭐ Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-10-08 02:51:29

📝 项目描述:
SSRF defense research and URL/DNS validation for Node.js, with reproducible case studies and socket-pinning adapters.

🔗 点击访问项目地址