GitHub 红队武器库🚨
📦 GitHub 全球红队渗透资源中转站。 旨在收录那些“好用却难找”的安全项目。 🔗 定时推送:GitHub Trending (Security) 🛠 必备清单:后渗透、远控、免杀、提权工具集 📅 更新频率:每日精选,绝不灌水。 ⚠️ 本频道仅供安全研究与授权测试使用。
Show more📈 Analytical overview of Telegram channel GitHub 红队武器库🚨
Channel GitHub 红队武器库🚨 (@githubredteam) in the Chinese language segment is an active participant. Currently, the community unites 14 068 subscribers, ranking 8 807 in the Technologies & Applications category and 14 947 in the China region.
📊 Audience metrics and dynamics
Since its creation on невідомо, the project has demonstrated rapid growth, gathering an audience of 14 068 subscribers.
According to the latest data from 15 September, 2026, the channel demonstrates stable activity. Although there has been a change in the number of participants by 363 over the last 30 days and by 7 over the last 24 hours, overall reach remains high.
- Verification status: Not verified
- Engagement rate (ER): The average audience engagement rate is 0.38%. Within the first 24 hours after publication, content typically collects 0.48% reactions from the total number of subscribers.
- Post reach: On average, each post receives 53 views. Within the first day, a publication typically gains 68 views.
- Reactions and interaction: The audience actively supports content: the average number of reactions per post is 1.
- Thematic interests: Content is focused on key topics such as fork, github, powered, 六合彩, cve-2026.
📝 Description and content policy
The author describes the resource as a platform for expressing subjective opinions:
“📦 GitHub 全球红队渗透资源中转站。
旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
⚠️ 本频道仅供安全研究与授权测试使用。”
Thanks to the high frequency of updates (latest data received on 16 September, 2026), the channel maintains relevance and a high level of publication reach. Analytics show that the audience actively interacts with content, making it an important point of influence in the Technologies & Applications category.
AD AutoPwn v4.13.0 — automated AD attack chain, zero-auth to Domain Admin. Discover/Kerberoast/AS-REP/AD CS ESC1-16/Shadow Creds/RBCD+KCD/Ghost-SPN/TGS-rewrite/Dollar-Ticket/WPAD/WSUS/PXE/SCCM/BloodHound auto-action/Loot/DCSync/DPAPI + Synacktiv 2026 reflection (CVE-2025-58726/2026-24294/2026-26128). Authorized pentesting only.
🔗 点击访问项目地址CVE-2026-43499 GhostLock root exploit for Chromecast with Google TV (sabrina)
🔗 点击访问项目地址Proof of Concept for CVE-2026-61797, a time-based blind SQL Injection vulnerability affecting the GLPI PDF plugin.
🔗 点击访问项目地址Linux 应急响应一键排查脚本 — 28 个模块,只检测不处置,一份完整报告 + 疑似清单 + 简报
🔗 点击访问项目地址Injection via `%username%` in Store Command Execution — GameStores Plugin
🔗 点击访问项目地址SnowEdge 是面向个人使用的授权安全评估工作台,将资产、请求、漏洞与证据集中管理,并通过 AI 辅助研判和工具联动,减少测试过程中反复切换工具、整理结果的负担。
🔗 点击访问项目地址基于Pi内核的双Agent的漏洞挖掘工具,主打极简复用Pi的四个工具,一个负责元认知,一个负责执行
🔗 点击访问项目地址OpenMAIC 1.0.0: Unauthenticated Outbound SSRF to Cloud Metadata Service via Fail-Open Middleware and Environment-Gated Validation Bypass
🔗 点击访问项目地址An automated Web Security Testing (DAST) framework built with Python, Selenium, and pytest using the Page Object Model (POM). Automates vulnerability audits for OWASP Top 10 flaws (Reflected XSS & Auth brute-force) with OWASP ZAP proxy routing and CI/CD reporting.
🔗 点击访问项目地址💉 TBH-XSS - Reflected XSS Detector | Bug Bounty | JSON | Safe Payload
🔗 点击访问项目地址基于 Burp Montoya API 的被动扫描插件:4 条检测规则,自动识别敏感路径暴露、明文口令传输、CORS 误配、可疑调试参数
🔗 点击访问项目地址这是一个在补天SRC上进行授权漏洞挖掘的实战作品集,包含渗透测试方法论、完整实战流程、报告提交和零基础教学 This is a hands-on portfolio for authorized vulnerability hunting on Butian SRC, including penetration testing methodology, a complete real-world workflow, report submission, and beginner-friendly training
🔗 点击访问项目地址Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
🔗 点击访问项目地址Wordfence malware and vulnerability scanner command line utility.
🔗 点击访问项目地址Safety-first Python vulnerability scanner for authorized private lab environments.
🔗 点击访问项目地址dockerDesktop
🔗 点击访问项目地址