maux339-cpu/exploits
GitHub: maux339-cpu/exploits
一个整合了AI红队渗透测试、OSINT情报收集与DeFi安全审计工具的综合安全研究仓库。
Stars: 0 | Forks: 0
# exploits — 统一中心 `maux339-cpu`
旧的索引仓库(`ai-redteam-arsenal-2026`、`arsenal-osint-defi-2026`、`osint-x-intel-arsenal-2026`、`security-agent-skills-arsenal`)**作为历史归档保留**,并重定向至此。
## ⚠️ 仅限授权
- 仅限您**拥有**或拥有**书面许可**的目标(bounty、商业渗透测试、自有实验室)。
- 未经授权的访问是犯罪行为。您需自行承担全部责任。
- 第三方 Skills(SKILL.md)可能存在供应链风险——**安装前请务必阅读**。
- **upstreams** 的 AGPL/Apache/MIT 许可证适用于各个 fork;本索引(MIT)**不**重新授权 `tools/*` 中的代码。
## 军火库地图(过去 → 现在)
| 遗留仓库 | 原始焦点 | 状态 |
|-------------|---------------|--------|
| **[exploits](https://github.com/maux339-cpu/exploits)**(本仓库) | **规范中心** + AI 渗透测试子模块 | ✅ **使用此仓库** |
| [ai-redteam-arsenal-2026](https://github.com/maux339-cpu/ai-redteam-arsenal-2026) | T3 / WallBreaker / Heretic / OBLITERATUS / Strix | 📦 重定向 → 此处 |
| [arsenal-osint-defi-2026](https://github.com/maux339-cpu/arsenal-osint-defi-2026) | Waves OSINT + DeFi + 链上 + agent skills | 📦 遗留仓库中的 Waves 详情;此处为摘要 |
| [osint-x-intel-arsenal-2026](https://github.com/maux339-cpu/osint-x-intel-arsenal-2026) | X 平台的 OSINT 收集 | 📦 此处为摘要 |
| [security-agent-skills-arsenal](https://github.com/maux339-cpu/security-agent-skills-arsenal) | exploit-type 映射 → DeFi/SC skill | 📦 此处为摘要 |
| [agent-hijack-defi-defense-2026](https://github.com/maux339-cpu/agent-hijack-defi-defense-2026) | 第 6 波 agent hijack / 防御 skills | 📎 姊妹索引(本地 skills) |
机器可读:[`INVENTORY.json`](./INVENTORY.json)。
## 1) AI 渗透测试 / red-team agents(本仓库中的子模块)
克隆:
```
git clone --recurse-submodules https://github.com/maux339-cpu/exploits.git
cd exploits
git submodule update --init --recursive --depth 1
```
| Path | Fork | Upstream | 许可证 | 角色 |
|------|------|----------|---------|-------|
| `tools/shannon` | [shannon](https://github.com/maux339-cpu/shannon) | KeygraphHQ/shannon | AGPL-3.0 | 自主 white-box;报告 + PoC |
| `tools/pentest-ai` | [pentest-ai](https://github.com/maux339-cpu/pentest-ai) | 0xSteph/pentest-ai | MIT | 在赋予 badge 前验证 finding (oracle) |
| `tools/strix` | [strix](https://github.com/maux339-cpu/strix) | usestrix/strix | Apache-2.0 | 应用/Web agent;高精度 |
| `tools/pentagi` | [pentagi](https://github.com/maux339-cpu/pentagi) | vxcontrol/pentagi | MIT | 多 agent 平台 + 报告 |
| `tools/hexstrike-ai` | [hexstrike-ai](https://github.com/maux339-cpu/hexstrike-ai) | 0x4m4/hexstrike-ai | MIT | MCP + 150+ 进攻性工具 |
| `tools/osmedeus` | [osmedeus](https://github.com/maux339-cpu/osmedeus) | j3ssie/osmedeus | MIT | recon 编排 (YAML) |
| `tools/Decepticon` | [Decepticon](https://github.com/maux339-cpu/Decepticon) | PurpleAILAB/Decepticon | Apache-2.0 | Red team agent (sandbox) |
| `tools/T3MP3ST` | [T3MP3ST](https://github.com/maux339-cpu/T3MP3ST) | elder-plinius/T3MP3ST | AGPL-3.0 | 多操作者 meta-harness + War Room |
| `tools/Pentest-Swarm-AI` | [Pentest-Swarm-AI](https://github.com/maux339-cpu/Pentest-Swarm-AI) | Armur-Ai/Pentest-Swarm-AI | AGPL-3.0 | Swarm recon → 报告 |
| `tools/pentest-ai-agents` | [pentest-ai-agents](https://github.com/maux339-cpu/pentest-ai-agents) | 0xSteph/pentest-ai-agents | MIT | Claude Code 子 agent |
| `tools/xalgorix` | [xalgorix](https://github.com/maux339-cpu/xalgorix) | xalgord/xalgorix | MIT | Go/TS 渗透测试 agent |
### 心智排名(“扫描并返回结果”)
1. **pentest-ai** — 仅在通过二次验证时报告
2. **shannon** — 自主 + 证据
3. **strix** — Web agent,高精度
4. **pentagi** / **hexstrike-ai** — 平台 / 军火库
5. **osmedeus** — recon pipeline
6. **T3MP3ST** — harness(需要 spawn operator + mission)
7. **Decepticon** / **Pentest-Swarm-AI** / **xalgorix** — swarm / 变体
## 2) AI red-team / LLM(账户中的 fork — 暂无子模块)
继承自 `ai-redteam-arsenal-2026`。
| 项目 | Fork | Upstream | 功能 |
|---------|------|----------|--------|
| **T3MP3ST** | [T3MP3ST](https://github.com/maux339-cpu/T3MP3ST) | elder-plinius | 多 agent harness(亦在 `tools/` 中) |
| **Strix** | [strix](https://github.com/maux339-cpu/strix) | usestrix | AI 渗透测试应用(亦在 `tools/` 中) |
| **WallBreaker** | [wallbreaker](https://github.com/maux339-cpu/wallbreaker) | JailbrokenAI | 针对 LLM 的 red-team / jailbreak(活动) |
| **OBLITERATUS** | [OBLITERATUS](https://github.com/maux339-cpu/OBLITERATUS) | elder-plinius | 模型拒绝/言论自由工具包 |
| **Heretic** | [heretic](https://github.com/maux339-cpu/heretic) | p-e-w | 自动 Abliteration(开源权重) |
| **garak** | [garak](https://github.com/maux339-cpu/garak) | NVIDIA | LLM 漏洞扫描器 |
| **promptfoo** | [promptfoo](https://github.com/maux339-cpu/promptfoo) | promptfoo | prompt 评估 / red-team |
| **deepteam** | [deepteam](https://github.com/maux339-cpu/deepteam) | — | Red team LLM/agents |
| **agentic_security** | [agentic_security](https://github.com/maux339-cpu/agentic_security) | — | agentic 扫描器 |
| **hackagent** | [hackagent](https://github.com/maux339-cpu/hackagent) | — | agents 中的漏洞 |
| **agentseal** | [agentseal](https://github.com/maux339-cpu/agentseal) | getagentseal | MCP poisoning / injection 防御 |
| **rebuff** | [rebuff](https://github.com/maux339-cpu/rebuff) | protectai | prompt injection 检测器 |
| **PentestGPT** | [PentestGPT](https://github.com/maux339-cpu/PentestGPT) | GreyDGL | LLM 渗透测试助手 |
| **Awesome-AI-Hacking-Agents** | [Awesome-AI-Hacking-Agents](https://github.com/maux339-cpu/Awesome-AI-Hacking-Agents) | — | agents 策展 |
### 克隆经典 red-team 包(Windows)
```
$Dest = "$env:USERPROFILE\repos\ai-redteam-tools"
New-Item -ItemType Directory -Force -Path $Dest | Out-Null
foreach ($r in @('T3MP3ST','wallbreaker','OBLITERATUS','heretic','strix','garak','promptfoo')) {
if (-not (Test-Path "$Dest\$r")) { gh repo clone "maux339-cpu/$r" "$Dest\$r" }
}
```
### 同步 forks
```
foreach ($r in @('T3MP3ST','wallbreaker','OBLITERATUS','heretic','strix','shannon','pentest-ai','pentagi','hexstrike-ai','osmedeus','Decepticon')) {
gh repo sync "maux339-cpu/$r"
}
```
### 快速参考
```
# T3MP3ST
npm install && npm run server # War Room :3333
# Ollama: TEMPEST_LOCAL_BASE_URL + TEMPEST_LOCAL_MODEL (例如 ~/.t3mp3st/.env)
# WallBreaker
pip install -e ".[dev]"
cp config.example.toml config.toml && wallbreaker check
# Strix — https://docs.strix.ai/
strix --target http://localhost:3000
```
## 3) OSINT(统一摘要)
X 平台收集详情:遗留仓库 [osint-x-intel-arsenal-2026](https://github.com/maux339-cpu/osint-x-intel-arsenal-2026)。
第 1–6 波:遗留仓库 [arsenal-osint-defi-2026](https://github.com/maux339-cpu/arsenal-osint-defi-2026)。
### Stack footprint(最常用)
| Tool | Fork | 用途 |
|------|------|-----|
| theHarvester | [theHarvester](https://github.com/maux339-cpu/theHarvester) | emails / hosts / subdomains |
| SpiderFoot | [spiderfoot](https://github.com/maux339-cpu/spiderfoot) | 自动关联 |
| Sherlock | [sherlock](https://github.com/maux339-cpu/sherlock) | username → sites |
| Maigret | [maigret](https://github.com/maux339-cpu/maigret) | username / SOCMINT |
| Blackbird | [blackbird](https://github.com/maux339-cpu/blackbird) | username |
| Holehe | [holehe](https://github.com/maux339-cpu/holehe) | email → 注册记录 |
| PhoneInfoga | [phoneinfoga](https://github.com/maux339-cpu/phoneinfoga) | 电话 OSINT |
| SearchPhone | [SearchPhone](https://github.com/maux339-cpu/SearchPhone) | 电话 (CLI) |
| recon-ng | [recon-ng](https://github.com/maux339-cpu/recon-ng) | recon 框架 |
| Amass | [amass](https://github.com/maux339-cpu/amass) | subdomains |
| OpenOSINT | [OpenOSINT](https://github.com/maux339-cpu/OpenOSINT) | AI + MCP OSINT |
| osint-tools-radar | [osint-tools-radar](https://github.com/maux339-cpu/osint-tools-radar) | agentic/skills 雷达 |
| awesome-osint | [awesome-osint](https://github.com/maux339-cpu/awesome-osint) | 经典列表 |
| awesome-osint-arsenal | [awesome-osint-arsenal](https://github.com/maux339-cpu/awesome-osint-arsenal) | 1100+ 工具包 / 安装 |
其他:social-analyzer、D4rk_Intel toolkit、non-typical-OSINT-guide、Legendary_OSINT、nuclei、httpx、katana、trufflehog…
## 4) 链上 / DeFi 取证(摘要)
| 领域 | 关键 Forks |
|------|-------------|
| 列表 / 手册 | On-Chain-Investigations-Tools-List, Crypto-Asset-Tracing-Handbook, Blockchain-dark-forest-selfguard-handbook, Knowledge-Base (SlowMist), Legendary_Crypto |
| GraphSense | graphsense-dashboard, graphsense-lib, graphsense-tagpacks, GraphSense-Maltego-transform |
| BlockSec stack | metasuites, Phalcon, metasleuth_resources |
| Labs SC | damn-vulnerable-defi, DeFiHackLabs, DeFiVulnLabs, ethernaut |
| 静态 / 模糊测试 | slither, aderyn, mythril, echidna, medusa, foundry |
| Solana | helius-sdk, xray |
无实用 fork 的 SaaS(仅供参考):TRM、Chainalysis、Elliptic、Arkham、MistTrack 等。
## 5) SC 漏洞类型 → 去向(skills)映射
继承自 `security-agent-skills-arsenal`。顺序:**检测 → 理解 → 实验室验证 → 报告**。
| 类别 | 实验室 / 案例 | 静态 / 模糊测试 | AI Skills |
|--------|--------------|---------------|-----------|
| **重入 (Reentrancy)** | DeFiHackLabs, damn-vulnerable-defi, ethernaut | slither, aderyn | trailofbits-skills, pashov-skills, solskill |
| **闪电贷 / 预言机** | DeFiHackLabs, DeFiVulnLabs | medusa, echidna | pashov-skills, sc-auditor |
| **访问控制 / 代理** | ethernaut, DeFiVulnLabs | slither, mythril, aderyn | trailofbits-skills, solskill |
| **逻辑 / 不变量** | DeFiHackLabs, solodit_content | echidna, medusa, halmos, kontrol | pashov-skills, sc-auditor |
| **Rug / 蜜罐 / 后门** | selfguard handbooks | slither, aderyn | kali-claw, quillshield_skills |
| **跨链桥 / L2** | DeFiHackLabs, contests | — | kali-claw L2 |
| **报告 / PoC** | forge-poc-templates + foundry | — | trailofbits-skills, claude-code-security-review |
**Web/CEX(非 SC):** Claude-Red、Claude-BugHunter、claude-bug-bounty — **仅在授权 / bounty 的情况下使用**。
### 针对单个 SC 目标的快速流程
1. 代码 Recon → solskill / pashov / trailofbits-skills
2. 静态分析 → slither + aderyn
3. 实验 PoC → foundry + forge-poc-templates
4. 模糊测试 → echidna / medusa
5. 报告 → solodit patterns / 负责任披露
## 6) Agent 劫持 / DeFi AI(第 6 波)
姊妹索引:[agent-hijack-defi-defense-2026](https://github.com/maux339-cpu/agent-hijack-defi-defense-2026)。
| 攻击向量 | 防御 / 工具 |
|-------|----------------|
| 目标劫持 / prompt injection | agentseal, promptfoo, garak, rebuff HITL |
| MCP 工具滥用 | pipelock, prismor, agentguard |
| 利用 IA 挖掘 SC | slither → foundry → echidna(仅限授权目标) |
## 7) `pentest*` 家族(并非同一个项目)
| 仓库 | 母仓库 | 不要混淆于 |
|------|--------|-------------------|
| pentest-ai | 0xSteph/pentest-ai | — |
| pentest-ai-agents | 0xSteph/pentest-ai-agents | pentest-ai |
| pentest-agents | H-mmer/pentest-agents | pentest-ai-agents |
| pentestagent | GH05TCREW/pentestagent | pentest-agents |
| PentestGPT | GreyDGL/PentestGPT | — |
| Pentest-Swarm-AI | Armur-Ai/Pentest-Swarm-AI | — |
## 8) 后渗透 & 提权(2026-07-19 包)
完整清单:[`docs/POSTEX-PRIVESC.md`](./docs/POSTEX-PRIVESC.md) · JSON:[`docs/POSTEX-INVENTORY.json`](./docs/POSTEX-INVENTORY.json)
| 层级 | 工具(账户中的 forks) |
|--------|------------------------|
| 枚举 LPE | PEASS-ng, LinEnum, lse, LES, Seatbelt, SharpUp, Watson, BeRoot |
| 滥用参考 | GTFOBins, LOLBAS, WADComs |
| 凭据 / 票据 | mimikatz, Rubeus, Certipy |
| AD / 图谱 | BloodHound, SharpHound, AzureHound, bloodyAD, ROADtools |
| 横向移动 / 网络 | Impacket, NetExec, evil-winrm, Responder, PowerSploit |
| C2 / 运维 | Sliver, Havoc, Mythic, Caldera, Villain, dnscat2 |
| AD 实验室 | **GOAD** |
本地克隆:
```
powershell -File scripts\clone-postex.ps1
# → C:\Users\maux3\repos\postex-privesc\
```
## 9) 未解决(X 上无稳定规范仓库)
- PentesterFlow
- Argo (LLM SAST)
- Bug Hunter (Hunter / Skeptic / Referee)
- RedGhost(搜索到的 upstream 不稳定)
稳定后请更新 `INVENTORY.json`。
## 10) HexStrike:注意重复项
| 仓库 | 备注 |
|------|------|
| [hexstrike-ai](https://github.com/maux339-cpu/hexstrike-ai) | 官方 **fork**(首选)+ `tools/` 中的子模块 |
| [hexstrike-ai-private](https://github.com/maux339-cpu/hexstrike-ai-private) | **私有**副本 — 如果没有你的补丁,则考虑归档 |
## 本索引的许可
- 自有内容(README、INVENTORY、NOTICE):**MIT** — 见 [`LICENSE`](./LICENSE)。
- `tools/*` 及 forks 中的代码:**遵循各个 upstream 的许可证**(AGPL-3.0、MIT、Apache-2.0、…)。
- 见 [`NOTICE`](./NOTICE)。
## 致谢
感谢所有列出项目的作者及社区。镜像/ fork 仅供授权实验室与研究使用。
**Hub:** https://github.com/maux339-cpu/exploits
**账户:** https://github.com/maux339-cpu
标签:AI安全, Chat Copilot, CISA项目, DeFi安全, ESC4, GitHub, Libemu, MITM代理, OSINT, 工具集, 日志审计, 网络连接监控, 逆向工具