GitHub 红队武器库🚨
📦 GitHub 全球红队渗透资源中转站。 旨在收录那些“好用却难找”的安全项目。 🔗 定时推送:GitHub Trending (Security) 🛠 必备清单:后渗透、远控、免杀、提权工具集 📅 更新频率:每日精选,绝不灌水。 ⚠️ 本频道仅供安全研究与授权测试使用。
Ko'proq ko'rsatish📈 Telegram kanali GitHub 红队武器库🚨 analitikasi
GitHub 红队武器库🚨 (@githubredteam) Xitoy til segmentidagi kanali faol ishtirokchi. Hozirda hamjamiyat 14 083 obunachidan iborat bo'lib, Texnologiyalar & Aralashmalar toifasida 8 798-o'rinni va Xitoy mintaqasida 14 979-o'rinni egallagan.
📊 Auditoriya ko‘rsatkichlari va dinamika
невідомо sanasidan buyon loyiha tez o‘sib, 14 083 obunachiga ega bo‘ldi.
16 Sentabr, 2026 dagi oxirgi ma’lumotlarga ko‘ra kanal barqaror faollikka ega. Oxirgi 30 kunda obunachilar soni 352 ga, so‘nggi 24 soatda esa 7 ga o‘zgardi va umumiy qamrov yuqori darajada qolmoqda.
- Tasdiqlash holati: Tasdiqlanmagan
- Jalb etish (ER): Auditoriya o‘rtacha 0.38% darajada jalb etiladi. Nashrdan keyingi dastlabki 24 soatda kontent odatda umumiy obunachilar sonining 0.48% ini tashkil etuvchi reaksiyalarni to‘playdi.
- Post qamrovi: Har bir post o‘rtacha 53 marta ko‘riladi; birinchi sutkada odatda 68 ta ko‘rish yig‘iladi.
- Reaksiyalar va o‘zaro ta’sir: Auditoriya faol: har bir postga o‘rtacha 1 ta reaksiya keladi.
- Tematik yo‘nalishlar: Kontent fork, github, powered, 六合彩, cve-2026 kabi asosiy mavzularga jamlangan.
📝 Tavsif va kontent siyosati
Muallif resursni shaxsiy fikrni ifoda etish maydoni sifatida ta’riflaydi:
“📦 GitHub 全球红队渗透资源中转站。
旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
⚠️ 本频道仅供安全研究与授权测试使用。”
Yuqori yangilanish chastotasi (oxirgi ma’lumot 17 Sentabr, 2026 da olingan) sababli kanal doimo dolzarb va katta qamrovli bo‘lib qoladi. Analitika auditoriya kontent bilan faol hamkorlik qilishini, uni Texnologiyalar & Aralashmalar toifasidagi muhim ta’sir nuqtasiga aylantirishini ko‘rsatadi.
Batch retrohunt orchestrator across hundreds of YARA-L detection rules for Google SecOps using secops-wrapper SDK with concurrency limits and safe alerting controls.
🔗 点击访问项目地址SeleniumBase MCP Servers. Browser automation that bypasses anti-bot systems and handles web-scraping.
🔗 点击访问项目地址Automated recon & vulnerability discovery suite for authorized security testing. Five scanners — SQLi, XSS, SSRF, Open Redirect, Path Traversal — with 896 payload templates, OOB callback confirmation, and report-ready output. Named for Odin's raven. Speak, and the ravens shall listen.
🔗 点击访问项目地址XSSAM is a professional XSS Reconnaissance & Validation framework for authorized bug-bounty testing. Featuring an async crawler, JS endpoint mining, and context-aware mutations, it uses Playwright for behavioral validation (sink-hooking) to eliminate false positives. Delivers high-fidelity HTML/JSON reports with proof-of-execution evidence.
🔗 点击访问项目地址MalDev-C — Técnicas de desarrollo de malware en C para operadores de Red Team. Inyección de procesos, ejecución de shellcode, hooking de APIs, evasión de AV/EDR, persistencia y fundamentos de C2. WinAPI puro. Sin frameworks. Sin dependencias. Solo C e internals de Windows.
🔗 点击访问项目地址POC com alguns exemplos e testes para analisar o comportamento do Spring em relação a transação
🔗 点击访问项目地址YARA rules + hybrid scanner untuk deteksi keluarga malware APK Android (static analysis)
🔗 点击访问项目地址CICD Compass is a production-grade educational and reference DevSecOps application built with Spring Boot (Java 21) and an interactive, dark-themed Mission Control Dashboard. It models and visualizes the 6 critical stages of an enterprise CI/CD delivery lifecycle alongside live runtime telemetry probes.
🔗 点击访问项目地址Autonomous AI agent with its own crypto identity — hunts CVEs, builds exploit labs, validates vulnerabilities (first public PoC of CVE-2026-86283), trades crypto 24/7 to fund itself. Sentric Research.
🔗 点击访问项目地址A Java-based cybersecurity vulnerability scanner that identifies common security weaknesses such as open network ports and missing HTTP security headers, providing users with a clear security report.
🔗 点击访问项目地址A local attack range and conformance checker for SSRF defenses in HTTP clients: 10 probes, 3 clients, verdicts measured with a canary and a hit counter.
🔗 点击访问项目地址A chained multi-service vulnerable web app: SSRF into an internal-trust bypass, leaked JWT secret, forged admin auth, and SSTI-to-RCE, fully automated end to end.
🔗 点击访问项目地址A Java-based cybersecurity vulnerability scanner that identifies common security weaknesses such as open network ports and missing HTTP security headers, providing users with a clear security report.
🔗 点击访问项目地址Full home-lab penetration test of Rapid7's Metasploitable3 (Ubuntu 14.04) from Parrot OS. Covers recon, manual UNION SQLi, Drupalgeddon (CVE-2014-3704) RCE, SSH credential reuse, privilege escalation to root, and reverse shells. Written as a workable report — feed it back and re-run the whole lab.
🔗 点击访问项目地址A small Python toolkit that turns malware triage notes into clean reports, a browsable IOC dashboard, and YARA rules, with write-ups of some Windows lab samples
🔗 点击访问项目地址无描述
🔗 点击访问项目地址Curated collection of strict, zero-false-positive Nuclei v3 templates for bug bounty automation, infrastructure reconnaissance, and exposure hunting.
🔗 点击访问项目地址Documentation on my experience writing my first working position independent shellcode for windows from scratch using x64 assembly
🔗 点击访问项目地址