Exploits & threat

Warning Read this before the tools. Four of the six gate their records behind a Pro plan while returning their counts to everyone. Every one of them sets a gated boolean and a note saying so. An empty list never means “none exist”, so check gated and the count first. Your agent reads the note too, which is why it travels with the data instead of living only here.

vulnetix_exploits

Weaponisation signal aggregated across 20 sources: ExploitDB, Metasploit, Nuclei, VulnCheck XDB, CrowdSec, GitHub, HackerOne, Bugcrowd, Intigriti, MISP, nmap NSE, Shadowserver, Vulnetix KEV and more.

ArgumentType
identifierstring, required

Log4Shell on Community:

{
  "id": "CVE-2021-44228",
  "exploitCount": 19868,
  "sightingCount": 2568,
  "activeSources": [
    { "source": "poc", "count": 15259 },
    { "source": "other", "count": 4507 },
    { "source": "crowdSec", "count": 101 },
    { "source": "vulnetixKev", "count": 82 },
    { "source": "nmapNse", "count": 70 },
    { "source": "hackerone", "count": 27 }
  ],
  "exploitsBySource": [],
  "note": "Per-source counts are present but the exploit records themselves are empty. That is tier gating, not an absence of exploits..."
}

activeSources is the decision input, and it is available on every plan. On Pro and above, exploitsBySource additionally carries samples per source with title, URL, type, publication date and author.

Is CVE-2021-44228 actually being exploited, or is it theoretical?

vulnetix_sightings

Observed exploitation over time: total count, first and last observation, and days since last seen.

This is the tool that separates historically exploited from being exploited right now. A CVE last seen in 2022 warrants different urgency from one seen this week, and severity scores alone will not tell you which you have.


vulnetix_iocs

Indicators of compromise: attacking IPs, ASNs, geographic distribution and Shadowserver scan counts. For blocklists, SIEM enrichment and SOAR feeds.


vulnetix_threat_actors

Actors and campaigns associated with an advisory, plus whether the advisory itself is flagged malicious or an impersonation trap.


vulnetix_attack_techniques

MITRE ATT&CK techniques and tactics for an advisory. Use it to map a CVE onto the controls you already run, find coverage gaps, or line it up against D3FEND counter-techniques.

Not gated.


vulnetix_scorecard

OpenSSF scorecard results, commit health, PR and repository health, and source-fix correlation for the projects an advisory touches.

The question it answers is whether an upstream is maintained well enough for a fix to plausibly land, which is worth knowing before you plan around one.

Not gated.