awesome-repositories.com
Blog
awesome-repositories.com

Découvrez les meilleurs dépôts open-source grâce à notre recherche par IA.

ExplorerRecherches sélectionnéesAlternatives open sourceLogiciels auto-hébergésBlogPlan du site
ProjetÀ proposNotre méthodologiePresseServeur MCP
Mentions légalesConfidentialitéConditions d'utilisation
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
bitsadmin avatar

bitsadmin/wesng

0
View on GitHub↗
4,881 stars·603 forks·Python·BSD-3-Clause·1 vue

Wesng

Ce projet est un ensemble d'utilitaires spécialisés pour l'évaluation des vulnérabilités Windows et l'audit de gestion des correctifs. Il fonctionne comme un scanner de vulnérabilités et un suggéreur d'exploits qui analyse les mises à jour installées pour identifier les correctifs de sécurité manquants et leurs vulnérabilités connues correspondantes.

Le système se distingue en faisant correspondre les mises à jour manquantes avec une base de données de vulnérabilités consolidée pour recommander des exploits publiquement disponibles spécifiques. Il maintient la précision en synchronisant les bulletins de sécurité distants dans une base de données locale et en recoupant les lacunes identifiées avec les catalogues de mises à jour officiels pour gérer la supersédence des correctifs et éliminer les faux positifs.

L'outil fournit des capacités pour l'analyse de la surface de sécurité, permettant aux utilisateurs de prioriser les lacunes à haut risque via un filtrage basé sur la sévérité et un affinement par date d'installation. Il inclut également un client de base de données pour la collecte et la synchronisation des mises à jour de définitions de sécurité provenant de multiples sources distantes.

Features

  • Windows Vulnerability Assessments - Performs security audits on Windows hosts to identify missing security updates and configuration gaps.
  • Exploit Suggesters - Identifies potential vulnerabilities and suggests applicable exploits based on the target system configuration.
  • Exploit Recommendations - Suggests specific publicly available exploits by mapping missing security patches against a vulnerability database.
  • Security Definition Synchronizations - Downloads and merges external security bulletins and vulnerability metadata into a local database.
  • Patch Auditing Tools - Provides utilities for auditing installed fixes against official catalogs to identify security gaps.
  • Kernel Exploit Identification - Matches system versions and missing patches against vulnerability databases to find applicable exploits.
  • Missing Patch Detection - Identifies missing security updates on target systems to uncover potential vulnerabilities.
  • Patch Supersedence Filters - Filters out vulnerabilities that have been resolved by newer, cumulative security updates.
  • Vulnerability Database Management - Synchronizes and maintains local copies of security metadata and bulletins from external sources.
  • Update Catalog Querying - Queries official update catalogs to verify the status of missing security patches and eliminate false positives.
  • Exploit Mapping - Connects missing patches to associated vulnerabilities based on severity, impact, and the availability of known exploits.
  • Update Service Integrations - Interfaces with system update services and offline scan files to identify missing security patches.
  • Vulnerability Result Refinements - Refines vulnerability findings using severity thresholds and installation dates to isolate high-risk gaps.
  • Patch Accuracy Validation - Cross-references missing patches against official catalogs to remove false positives and verify installation requirements.
  • Attack Surface Analysis - Analyzes the attack surface by filtering and prioritizing critical vulnerabilities on a target machine.
  • Patch Exclusion Lists - Excludes specific update identifiers from results to remove false positives and refine identified gaps.
  • Patch Date Filters - Filters vulnerability results based on the installation or release date of security patches.
  • Security Data Consolidations - Aggregates vulnerability data and patch details from multiple remote sources into a unified local database.
  • Security Vulnerability Trackers - Tracks the emergence of security flaws and updates vulnerability lists to maintain current analysis data.
  • Vulnerability Data Synchronization - Updates local security definitions and exploit records from remote vulnerability sources.
  • Security Patch False Positives - Removes known incorrect update results from the analysis to ensure only truly missing patches are reported.
  • Vulnerability Severity Filtering - Filters vulnerability results using severity thresholds and installation dates to prioritize high-risk gaps.
  • Exploit Development - Tool for identifying missing patches and potential exploits.
  • Post Exploitation - Tool for identifying missing Windows patches.
  • Privilege Escalation - Checks Windows systems for missing patches.
  • Privilege Escalation Tools - Tool for suggesting Windows exploits based on system information.

Historique des stars

Graphique de l'historique des stars pour bitsadmin/wesngGraphique de l'historique des stars pour bitsadmin/wesng

Recherche par IA

Explorez plus de dépôts awesome

Décrivez vos besoins en langage naturel — l'IA classe des milliers de projets open source sélectionnés par pertinence.

Start searching with AI

Alternatives open source à Wesng

Projets open source similaires, classés selon le nombre de fonctionnalités partagées avec Wesng.
  • gdssecurity/windows-exploit-suggesterAvatar de GDSSecurity

    GDSSecurity/Windows-Exploit-Suggester

    4,209Voir sur GitHub↗

    Windows-Exploit-Suggester is a security audit tool designed to scan Windows systems for outdated components and missing security patches. It functions as a vulnerability scanner that compares target patch levels against official vendor security bulletins to identify security gaps. The tool specializes in exploit mapping, linking identified missing updates to known public exploit code and available penetration testing modules. It automates the research process by cross-referencing missing patches with specific vulnerability identifiers to determine applicable attack vectors. The system includ

    Python
    Voir sur GitHub↗4,209
  • strozfriedberg/windows-exploit-suggesterAvatar de strozfriedberg

    strozfriedberg/Windows-Exploit-Suggester

    4,211Voir sur GitHub↗

    Windows-Exploit-Suggester is a security analysis tool designed to audit patch levels and identify vulnerabilities on Windows hosts. It functions as a vulnerability scanner and patch level auditor that compares installed system hotfixes against Microsoft security bulletins to detect missing updates. The project maps these missing security updates to known public exploits and available Metasploit modules. It uses a vulnerability database interface to download and query external security bulletin data, linking specific unpatched vulnerabilities to viable exploit vectors. The tool's capabilities

    Python
    Voir sur GitHub↗4,211
  • mzet-/linux-exploit-suggesterAvatar de mzet-

    mzet-/linux-exploit-suggester

    6,528Voir sur GitHub↗

    linux-exploit-suggester is a diagnostic utility and vulnerability scanner designed to identify potential kernel exploits on Linux systems. It functions as a privilege escalation auditor by matching system information and kernel versions against a database of known security flaws. The tool differentiates itself by filtering and ranking exploits based on specific system properties and runtime security configurations. It evaluates kernel hardening settings, such as memory protection mechanisms, to discard inapplicable exploits and prioritize candidates by their probability of success. The softw

    Shell
    Voir sur GitHub↗6,528
  • itm4n/privesccheckAvatar de itm4n

    itm4n/PrivescCheck

    3,860Voir sur GitHub↗

    PrivescCheck is a PowerShell-based security auditing tool designed to scan Windows configurations for potential privilege escalation paths and local host vulnerabilities. It functions as a vulnerability assessment utility that analyzes system settings and registry configurations to identify weaknesses that could allow unauthorized administrative access. The tool automates internal security reconnaissance and post-exploitation data collection to gather environmental information. It serves as a security compliance reporter by exporting scan results into structured formats, including HTML, CSV,

    PowerShellpentest-toolpentestingprivilege-escalation
    Voir sur GitHub↗3,860
Voir les 30 alternatives à Wesng→

Questions fréquentes

Que fait bitsadmin/wesng ?

Ce projet est un ensemble d'utilitaires spécialisés pour l'évaluation des vulnérabilités Windows et l'audit de gestion des correctifs. Il fonctionne comme un scanner de vulnérabilités et un suggéreur d'exploits qui analyse les mises à jour installées pour identifier les correctifs de sécurité manquants et leurs vulnérabilités connues correspondantes.

Quelles sont les fonctionnalités principales de bitsadmin/wesng ?

Les fonctionnalités principales de bitsadmin/wesng sont : Windows Vulnerability Assessments, Exploit Suggesters, Exploit Recommendations, Security Definition Synchronizations, Patch Auditing Tools, Kernel Exploit Identification, Missing Patch Detection, Patch Supersedence Filters.

Quelles sont les alternatives open-source à bitsadmin/wesng ?

Les alternatives open-source à bitsadmin/wesng incluent : gdssecurity/windows-exploit-suggester — Windows-Exploit-Suggester is a security audit tool designed to scan Windows systems for outdated components and… strozfriedberg/windows-exploit-suggester — Windows-Exploit-Suggester is a security analysis tool designed to audit patch levels and identify vulnerabilities on… mzet-/linux-exploit-suggester — linux-exploit-suggester is a diagnostic utility and vulnerability scanner designed to identify potential kernel… itm4n/privesccheck — PrivescCheck is a PowerShell-based security auditing tool designed to scan Windows configurations for potential… jondonas/linux-exploit-suggester-2 — Next-Generation Linux Kernel Exploit Suggester. carlospolop/peass-ng — PEASS-ng is a Linux privilege escalation scanner and post-exploitation enumeration tool. It identifies security…