maux339-cpu/exploits

GitHub: maux339-cpu/exploits

一个整合了AI红队渗透测试、OSINT情报收集与DeFi安全审计工具的综合安全研究仓库。

Stars: 0 | Forks: 0

# exploits — 统一中心 `maux339-cpu` 旧的索引仓库(`ai-redteam-arsenal-2026`、`arsenal-osint-defi-2026`、`osint-x-intel-arsenal-2026`、`security-agent-skills-arsenal`)**作为历史归档保留**,并重定向至此。 ## ⚠️ 仅限授权 - 仅限您**拥有**或拥有**书面许可**的目标(bounty、商业渗透测试、自有实验室)。 - 未经授权的访问是犯罪行为。您需自行承担全部责任。 - 第三方 Skills(SKILL.md)可能存在供应链风险——**安装前请务必阅读**。 - **upstreams** 的 AGPL/Apache/MIT 许可证适用于各个 fork;本索引(MIT)**不**重新授权 `tools/*` 中的代码。 ## 军火库地图(过去 → 现在) | 遗留仓库 | 原始焦点 | 状态 | |-------------|---------------|--------| | **[exploits](https://github.com/maux339-cpu/exploits)**(本仓库) | **规范中心** + AI 渗透测试子模块 | ✅ **使用此仓库** | | [ai-redteam-arsenal-2026](https://github.com/maux339-cpu/ai-redteam-arsenal-2026) | T3 / WallBreaker / Heretic / OBLITERATUS / Strix | 📦 重定向 → 此处 | | [arsenal-osint-defi-2026](https://github.com/maux339-cpu/arsenal-osint-defi-2026) | Waves OSINT + DeFi + 链上 + agent skills | 📦 遗留仓库中的 Waves 详情;此处为摘要 | | [osint-x-intel-arsenal-2026](https://github.com/maux339-cpu/osint-x-intel-arsenal-2026) | X 平台的 OSINT 收集 | 📦 此处为摘要 | | [security-agent-skills-arsenal](https://github.com/maux339-cpu/security-agent-skills-arsenal) | exploit-type 映射 → DeFi/SC skill | 📦 此处为摘要 | | [agent-hijack-defi-defense-2026](https://github.com/maux339-cpu/agent-hijack-defi-defense-2026) | 第 6 波 agent hijack / 防御 skills | 📎 姊妹索引(本地 skills) | 机器可读:[`INVENTORY.json`](./INVENTORY.json)。 ## 1) AI 渗透测试 / red-team agents(本仓库中的子模块) 克隆: ``` git clone --recurse-submodules https://github.com/maux339-cpu/exploits.git cd exploits git submodule update --init --recursive --depth 1 ``` | Path | Fork | Upstream | 许可证 | 角色 | |------|------|----------|---------|-------| | `tools/shannon` | [shannon](https://github.com/maux339-cpu/shannon) | KeygraphHQ/shannon | AGPL-3.0 | 自主 white-box;报告 + PoC | | `tools/pentest-ai` | [pentest-ai](https://github.com/maux339-cpu/pentest-ai) | 0xSteph/pentest-ai | MIT | 在赋予 badge 前验证 finding (oracle) | | `tools/strix` | [strix](https://github.com/maux339-cpu/strix) | usestrix/strix | Apache-2.0 | 应用/Web agent;高精度 | | `tools/pentagi` | [pentagi](https://github.com/maux339-cpu/pentagi) | vxcontrol/pentagi | MIT | 多 agent 平台 + 报告 | | `tools/hexstrike-ai` | [hexstrike-ai](https://github.com/maux339-cpu/hexstrike-ai) | 0x4m4/hexstrike-ai | MIT | MCP + 150+ 进攻性工具 | | `tools/osmedeus` | [osmedeus](https://github.com/maux339-cpu/osmedeus) | j3ssie/osmedeus | MIT | recon 编排 (YAML) | | `tools/Decepticon` | [Decepticon](https://github.com/maux339-cpu/Decepticon) | PurpleAILAB/Decepticon | Apache-2.0 | Red team agent (sandbox) | | `tools/T3MP3ST` | [T3MP3ST](https://github.com/maux339-cpu/T3MP3ST) | elder-plinius/T3MP3ST | AGPL-3.0 | 多操作者 meta-harness + War Room | | `tools/Pentest-Swarm-AI` | [Pentest-Swarm-AI](https://github.com/maux339-cpu/Pentest-Swarm-AI) | Armur-Ai/Pentest-Swarm-AI | AGPL-3.0 | Swarm recon → 报告 | | `tools/pentest-ai-agents` | [pentest-ai-agents](https://github.com/maux339-cpu/pentest-ai-agents) | 0xSteph/pentest-ai-agents | MIT | Claude Code 子 agent | | `tools/xalgorix` | [xalgorix](https://github.com/maux339-cpu/xalgorix) | xalgord/xalgorix | MIT | Go/TS 渗透测试 agent | ### 心智排名(“扫描并返回结果”) 1. **pentest-ai** — 仅在通过二次验证时报告 2. **shannon** — 自主 + 证据 3. **strix** — Web agent,高精度 4. **pentagi** / **hexstrike-ai** — 平台 / 军火库 5. **osmedeus** — recon pipeline 6. **T3MP3ST** — harness(需要 spawn operator + mission) 7. **Decepticon** / **Pentest-Swarm-AI** / **xalgorix** — swarm / 变体 ## 2) AI red-team / LLM(账户中的 fork — 暂无子模块) 继承自 `ai-redteam-arsenal-2026`。 | 项目 | Fork | Upstream | 功能 | |---------|------|----------|--------| | **T3MP3ST** | [T3MP3ST](https://github.com/maux339-cpu/T3MP3ST) | elder-plinius | 多 agent harness(亦在 `tools/` 中) | | **Strix** | [strix](https://github.com/maux339-cpu/strix) | usestrix | AI 渗透测试应用(亦在 `tools/` 中) | | **WallBreaker** | [wallbreaker](https://github.com/maux339-cpu/wallbreaker) | JailbrokenAI | 针对 LLM 的 red-team / jailbreak(活动) | | **OBLITERATUS** | [OBLITERATUS](https://github.com/maux339-cpu/OBLITERATUS) | elder-plinius | 模型拒绝/言论自由工具包 | | **Heretic** | [heretic](https://github.com/maux339-cpu/heretic) | p-e-w | 自动 Abliteration(开源权重) | | **garak** | [garak](https://github.com/maux339-cpu/garak) | NVIDIA | LLM 漏洞扫描器 | | **promptfoo** | [promptfoo](https://github.com/maux339-cpu/promptfoo) | promptfoo | prompt 评估 / red-team | | **deepteam** | [deepteam](https://github.com/maux339-cpu/deepteam) | — | Red team LLM/agents | | **agentic_security** | [agentic_security](https://github.com/maux339-cpu/agentic_security) | — | agentic 扫描器 | | **hackagent** | [hackagent](https://github.com/maux339-cpu/hackagent) | — | agents 中的漏洞 | | **agentseal** | [agentseal](https://github.com/maux339-cpu/agentseal) | getagentseal | MCP poisoning / injection 防御 | | **rebuff** | [rebuff](https://github.com/maux339-cpu/rebuff) | protectai | prompt injection 检测器 | | **PentestGPT** | [PentestGPT](https://github.com/maux339-cpu/PentestGPT) | GreyDGL | LLM 渗透测试助手 | | **Awesome-AI-Hacking-Agents** | [Awesome-AI-Hacking-Agents](https://github.com/maux339-cpu/Awesome-AI-Hacking-Agents) | — | agents 策展 | ### 克隆经典 red-team 包(Windows) ``` $Dest = "$env:USERPROFILE\repos\ai-redteam-tools" New-Item -ItemType Directory -Force -Path $Dest | Out-Null foreach ($r in @('T3MP3ST','wallbreaker','OBLITERATUS','heretic','strix','garak','promptfoo')) { if (-not (Test-Path "$Dest\$r")) { gh repo clone "maux339-cpu/$r" "$Dest\$r" } } ``` ### 同步 forks ``` foreach ($r in @('T3MP3ST','wallbreaker','OBLITERATUS','heretic','strix','shannon','pentest-ai','pentagi','hexstrike-ai','osmedeus','Decepticon')) { gh repo sync "maux339-cpu/$r" } ``` ### 快速参考 ``` # T3MP3ST npm install && npm run server # War Room :3333 # Ollama: TEMPEST_LOCAL_BASE_URL + TEMPEST_LOCAL_MODEL (例如 ~/.t3mp3st/.env) # WallBreaker pip install -e ".[dev]" cp config.example.toml config.toml && wallbreaker check # Strix — https://docs.strix.ai/ strix --target http://localhost:3000 ``` ## 3) OSINT(统一摘要) X 平台收集详情:遗留仓库 [osint-x-intel-arsenal-2026](https://github.com/maux339-cpu/osint-x-intel-arsenal-2026)。 第 1–6 波:遗留仓库 [arsenal-osint-defi-2026](https://github.com/maux339-cpu/arsenal-osint-defi-2026)。 ### Stack footprint(最常用) | Tool | Fork | 用途 | |------|------|-----| | theHarvester | [theHarvester](https://github.com/maux339-cpu/theHarvester) | emails / hosts / subdomains | | SpiderFoot | [spiderfoot](https://github.com/maux339-cpu/spiderfoot) | 自动关联 | | Sherlock | [sherlock](https://github.com/maux339-cpu/sherlock) | username → sites | | Maigret | [maigret](https://github.com/maux339-cpu/maigret) | username / SOCMINT | | Blackbird | [blackbird](https://github.com/maux339-cpu/blackbird) | username | | Holehe | [holehe](https://github.com/maux339-cpu/holehe) | email → 注册记录 | | PhoneInfoga | [phoneinfoga](https://github.com/maux339-cpu/phoneinfoga) | 电话 OSINT | | SearchPhone | [SearchPhone](https://github.com/maux339-cpu/SearchPhone) | 电话 (CLI) | | recon-ng | [recon-ng](https://github.com/maux339-cpu/recon-ng) | recon 框架 | | Amass | [amass](https://github.com/maux339-cpu/amass) | subdomains | | OpenOSINT | [OpenOSINT](https://github.com/maux339-cpu/OpenOSINT) | AI + MCP OSINT | | osint-tools-radar | [osint-tools-radar](https://github.com/maux339-cpu/osint-tools-radar) | agentic/skills 雷达 | | awesome-osint | [awesome-osint](https://github.com/maux339-cpu/awesome-osint) | 经典列表 | | awesome-osint-arsenal | [awesome-osint-arsenal](https://github.com/maux339-cpu/awesome-osint-arsenal) | 1100+ 工具包 / 安装 | 其他:social-analyzer、D4rk_Intel toolkit、non-typical-OSINT-guide、Legendary_OSINT、nuclei、httpx、katana、trufflehog… ## 4) 链上 / DeFi 取证(摘要) | 领域 | 关键 Forks | |------|-------------| | 列表 / 手册 | On-Chain-Investigations-Tools-List, Crypto-Asset-Tracing-Handbook, Blockchain-dark-forest-selfguard-handbook, Knowledge-Base (SlowMist), Legendary_Crypto | | GraphSense | graphsense-dashboard, graphsense-lib, graphsense-tagpacks, GraphSense-Maltego-transform | | BlockSec stack | metasuites, Phalcon, metasleuth_resources | | Labs SC | damn-vulnerable-defi, DeFiHackLabs, DeFiVulnLabs, ethernaut | | 静态 / 模糊测试 | slither, aderyn, mythril, echidna, medusa, foundry | | Solana | helius-sdk, xray | 无实用 fork 的 SaaS(仅供参考):TRM、Chainalysis、Elliptic、Arkham、MistTrack 等。 ## 5) SC 漏洞类型 → 去向(skills)映射 继承自 `security-agent-skills-arsenal`。顺序:**检测 → 理解 → 实验室验证 → 报告**。 | 类别 | 实验室 / 案例 | 静态 / 模糊测试 | AI Skills | |--------|--------------|---------------|-----------| | **重入 (Reentrancy)** | DeFiHackLabs, damn-vulnerable-defi, ethernaut | slither, aderyn | trailofbits-skills, pashov-skills, solskill | | **闪电贷 / 预言机** | DeFiHackLabs, DeFiVulnLabs | medusa, echidna | pashov-skills, sc-auditor | | **访问控制 / 代理** | ethernaut, DeFiVulnLabs | slither, mythril, aderyn | trailofbits-skills, solskill | | **逻辑 / 不变量** | DeFiHackLabs, solodit_content | echidna, medusa, halmos, kontrol | pashov-skills, sc-auditor | | **Rug / 蜜罐 / 后门** | selfguard handbooks | slither, aderyn | kali-claw, quillshield_skills | | **跨链桥 / L2** | DeFiHackLabs, contests | — | kali-claw L2 | | **报告 / PoC** | forge-poc-templates + foundry | — | trailofbits-skills, claude-code-security-review | **Web/CEX(非 SC):** Claude-Red、Claude-BugHunter、claude-bug-bounty — **仅在授权 / bounty 的情况下使用**。 ### 针对单个 SC 目标的快速流程 1. 代码 Recon → solskill / pashov / trailofbits-skills 2. 静态分析 → slither + aderyn 3. 实验 PoC → foundry + forge-poc-templates 4. 模糊测试 → echidna / medusa 5. 报告 → solodit patterns / 负责任披露 ## 6) Agent 劫持 / DeFi AI(第 6 波) 姊妹索引:[agent-hijack-defi-defense-2026](https://github.com/maux339-cpu/agent-hijack-defi-defense-2026)。 | 攻击向量 | 防御 / 工具 | |-------|----------------| | 目标劫持 / prompt injection | agentseal, promptfoo, garak, rebuff HITL | | MCP 工具滥用 | pipelock, prismor, agentguard | | 利用 IA 挖掘 SC | slither → foundry → echidna(仅限授权目标) | ## 7) `pentest*` 家族(并非同一个项目) | 仓库 | 母仓库 | 不要混淆于 | |------|--------|-------------------| | pentest-ai | 0xSteph/pentest-ai | — | | pentest-ai-agents | 0xSteph/pentest-ai-agents | pentest-ai | | pentest-agents | H-mmer/pentest-agents | pentest-ai-agents | | pentestagent | GH05TCREW/pentestagent | pentest-agents | | PentestGPT | GreyDGL/PentestGPT | — | | Pentest-Swarm-AI | Armur-Ai/Pentest-Swarm-AI | — | ## 8) 后渗透 & 提权(2026-07-19 包) 完整清单:[`docs/POSTEX-PRIVESC.md`](./docs/POSTEX-PRIVESC.md) · JSON:[`docs/POSTEX-INVENTORY.json`](./docs/POSTEX-INVENTORY.json) | 层级 | 工具(账户中的 forks) | |--------|------------------------| | 枚举 LPE | PEASS-ng, LinEnum, lse, LES, Seatbelt, SharpUp, Watson, BeRoot | | 滥用参考 | GTFOBins, LOLBAS, WADComs | | 凭据 / 票据 | mimikatz, Rubeus, Certipy | | AD / 图谱 | BloodHound, SharpHound, AzureHound, bloodyAD, ROADtools | | 横向移动 / 网络 | Impacket, NetExec, evil-winrm, Responder, PowerSploit | | C2 / 运维 | Sliver, Havoc, Mythic, Caldera, Villain, dnscat2 | | AD 实验室 | **GOAD** | 本地克隆: ``` powershell -File scripts\clone-postex.ps1 # → C:\Users\maux3\repos\postex-privesc\ ``` ## 9) 未解决(X 上无稳定规范仓库) - PentesterFlow - Argo (LLM SAST) - Bug Hunter (Hunter / Skeptic / Referee) - RedGhost(搜索到的 upstream 不稳定) 稳定后请更新 `INVENTORY.json`。 ## 10) HexStrike:注意重复项 | 仓库 | 备注 | |------|------| | [hexstrike-ai](https://github.com/maux339-cpu/hexstrike-ai) | 官方 **fork**(首选)+ `tools/` 中的子模块 | | [hexstrike-ai-private](https://github.com/maux339-cpu/hexstrike-ai-private) | **私有**副本 — 如果没有你的补丁,则考虑归档 | ## 本索引的许可 - 自有内容(README、INVENTORY、NOTICE):**MIT** — 见 [`LICENSE`](./LICENSE)。 - `tools/*` 及 forks 中的代码:**遵循各个 upstream 的许可证**(AGPL-3.0、MIT、Apache-2.0、…)。 - 见 [`NOTICE`](./NOTICE)。 ## 致谢 感谢所有列出项目的作者及社区。镜像/ fork 仅供授权实验室与研究使用。 **Hub:** https://github.com/maux339-cpu/exploits **账户:** https://github.com/maux339-cpu
标签:AI安全, Chat Copilot, CISA项目, DeFi安全, ESC4, GitHub, Libemu, MITM代理, OSINT, 工具集, 日志审计, 网络连接监控, 逆向工具