14 个仓库
Mechanisms for updating local security definitions from remote vulnerability sources.
Distinct from Vulnerability Scanning: Focuses on the synchronization of vulnerability data rather than the act of scanning images or code.
Explore 14 awesome GitHub repositories matching security & cryptography · Vulnerability Data Synchronization. Refine with filters or upvote what's useful.
WPScan is a security analysis utility and vulnerability scanner designed specifically for auditing WordPress installations and other content management systems. It functions as a web application security tool that identifies misconfigurations, outdated software, and security holes in core installations, plugins, and themes. The tool employs black-box scanning techniques to perform site component enumeration, identifying users, themes, and plugins by matching known file paths and response signatures. It matches these detected components against a database of known security flaws to analyze the
Retrieves real-time security information from a remote database via API tokens to ensure scan accuracy.
This project is a vulnerability intelligence database and aggregator that organizes common vulnerabilities and exposures alongside their corresponding proof-of-concept exploit code. It functions as a security vulnerability tracker and an indexed directory of public exploit payloads. The system monitors new security flaws and updates to known exploits through repository watches and atom feeds. It utilizes automated aggregation to collect vulnerability details from centralized repositories and discovers associated exploit code via reference analysis and global searches. The tool provides capab
Collects security flaw details and exploit references into a centralized, searchable format for researchers.
This project is a public exploit code archive and vulnerability database. It serves as a collection of documented software exploits and vulnerability data, providing a reference library of exploit scripts and payloads used to validate security flaws in target environments. The archive supports security threat intelligence, vulnerability research, and penetration testing workflows. It functions as a historical record of software vulnerabilities and the proof-of-concept code used to trigger them. The codebase is organized through directory-based categorization and flat-file data storage, utili
Provides a centralized aggregator of vulnerability details and their corresponding proof-of-concept exploit code.
Naabu is a port scanner library and tool that probes hosts for open ports using SYN, CONNECT, and UDP methods to identify active services. It functions as a Go library for embedding port scanning into programs, and as a standalone tool that accepts targets as hostnames, IP addresses, CIDR ranges, or ASN numbers. The tool discovers live hosts before scanning, filters ports by range or top lists, and can integrate with Nmap for service version detection. The project distinguishes itself through its SYN-based port probing approach that sends TCP SYN packets and analyzes responses without complet
Filters CVE results by exploit status including known exploited, public PoCs, and remote exploitability.
该项目是一套用于 Windows 漏洞评估和补丁管理审计的专用工具。它作为一个漏洞扫描器和漏洞利用建议工具,通过分析已安装的更新来识别缺失的安全补丁及其对应的已知漏洞。 该系统的独特之处在于,它将缺失的更新与整合后的漏洞数据库进行匹配,从而推荐特定的公开漏洞利用程序。它通过将远程安全公告同步到本地数据库,并将识别出的漏洞与官方更新目录进行交叉引用,来处理补丁替代关系并消除误报,从而保持准确性。 该工具提供了安全表面分析功能,允许用户通过基于严重程度的过滤和安装日期细化来优先处理高风险漏洞。它还包含一个数据库客户端,用于从多个远程源收集和同步安全定义更新。
Updates local security definitions and exploit records from remote vulnerability sources.
openvas-scanner 是一个漏洞扫描器,旨在识别目标系统中的安全弱点和过时软件。它通过执行安全测试和网络攻击脚本进行网络漏洞扫描,并通过对已安装软件进行静态版本检查来执行本地安全审计。 该项目利用社区管理的源(feeds)来同步和更新本地安全定义和漏洞测试。这些测试和扫描配置通过容器镜像或手动传输加载到系统中,并存储在持久化关系型数据库中,以便进行长期跟踪和报告。 该系统包含一个可以使用容器编排部署的管理栈。通过 Web 管理仪表板、专用命令行工具以及各种远程过程接口(包括基于 XML 的 API 和用于 Windows 系统远程进程执行的 WMI)提供管理控制。 安全和访问通过基于角色的访问控制(RBAC)、密码策略强制执行以及 Web 界面的 TLS 加密进行管理。该扫描器还具有异步任务调度功能以自动化安全审计,并支持通过 SMTP 发送电子邮件通知以进行安全警报。
Imports and updates vulnerability tests and compliance policies into persistent storage volumes.
Lists is a curated collection of DNS blocklists, a domain blocklist generator, and a categorized library of domains used for network content filtering. The project provides a command-line pipeline that aggregates upstream sources to build and validate blocklists used to redirect unwanted traffic to null addresses. The project distinguishes itself through a CLI-driven build pipeline that automates the fetching, validation, and daily regeneration of datasets. It organizes domains into discrete functional categories rather than a single monolithic list and exports them in multiple syntaxes, incl
Catalogs known fraudulent domains to prevent users from accessing sites associated with scams or malware.
Windows-Exploit-Suggester is a security analysis tool designed to audit patch levels and identify vulnerabilities on Windows hosts. It functions as a vulnerability scanner and patch level auditor that compares installed system hotfixes against Microsoft security bulletins to detect missing updates. The project maps these missing security updates to known public exploits and available Metasploit modules. It uses a vulnerability database interface to download and query external security bulletin data, linking specific unpatched vulnerabilities to viable exploit vectors. The tool's capabilities
Synchronizes local vulnerability definitions by downloading and parsing security bulletins from remote sources.
Windows-Exploit-Suggester 是一个安全审计工具,旨在扫描 Windows 系统中的过时组件和缺失的安全补丁。它作为一个漏洞扫描器,将目标补丁级别与官方供应商安全公告进行比较,以识别安全漏洞。 该工具专注于漏洞利用映射,将识别出的缺失更新链接到已知的公共漏洞利用代码和可用的渗透测试模块。它通过将缺失的补丁与特定的漏洞标识符进行交叉引用,自动执行研究过程,以确定适用的攻击向量。 该系统包括远程补丁级别比较和启发式检测功能,以推断主机的状态。它通过同步机制保持准确性,该机制从供应商源下载并解析最新的安全数据,以更新其内部漏洞数据库。
Updates local security definitions from remote vendor vulnerability sources to maintain accuracy.
x-cmd is an AI agent orchestrator, cloud infrastructure CLI, and cross-platform package manager that provides an enhanced POSIX shell toolkit. It integrates large language models directly into the terminal for chatting, code generation, and the execution of agentic workflows, while offering a framework for building interactive terminal user interface components. The project distinguishes itself by deploying containerized AI agents within isolated sandboxes, provisioning them with specialized skills and headless browser automation capabilities. It further streamlines development through a unif
Monitors open-source vulnerabilities by cross-referencing against known exploited vulnerability catalogs.
Vulscan is a network service auditor and vulnerability scanner that utilizes the Nmap Scripting Engine to identify security flaws. It functions as a version-based flaw detector, matching detected software banners against an offline vulnerability database to identify potential security risks without requiring a constant internet connection. The tool provides mechanisms for refining identification accuracy, including an interactive mode for manual version overriding and configurable matching logic to filter results. It manages security data through a system for loading local datasets and synchr
Provides mechanisms for updating local security definitions from remote vulnerability sources.
Dependency-Track is a software composition analysis tool and vulnerability management system designed to track dependencies and supply chain risk. It functions as a platform for ingesting and analyzing CycloneDX software bills of materials to identify known vulnerabilities and license compliance issues within third-party software components. The system distinguishes itself by mirroring external vulnerability databases locally to enable fast offline analysis and using VEX documents to differentiate between technical vulnerabilities and actual contextual risks. It also integrates with identity
Synchronizes with external vulnerability databases and scoring systems to prioritize mitigation based on exploitability.
cve-search is a vulnerability search engine and database manager designed to index, synchronize, and query CVE and CPE security vulnerability data. It functions as a security data warehouse that imports vulnerability feeds into a local database to enable fast, keyword-based discovery of security flaws. The project provides a web-based vulnerability browser and a programmatic JSON API for retrieving records and risk scores. It utilizes full-text indexing for vulnerability descriptions and implements an identity-verified security portal using the OpenID Connect standard for user authentication.
Loads and synchronizes security vulnerability records from remote sources into a local searchable database.
OSV is a distributed database and aggregator of open-source security advisories that uses a standardized vulnerability schema to track security flaws. It functions as a system for collecting and normalizing security data from diverse ecosystems into a single unified format, providing a web API for querying package vulnerabilities and submitting standardized records. The project distinguishes itself through a security advisory distribution service that supports bulk dataset exports via cloud storage buckets and incremental synchronization of security record updates. It also employs sandbox-bas
Imports security records from public repositories, web APIs, or cloud storage buckets after validating they match a specific schema.