Exploits & threat
gated
boolean and a note saying so. An empty list never means “none exist”, so
check gated and the count first. Your agent reads the note too, which is why it
travels with the data instead of living only here.vulnetix_exploits
Weaponisation signal aggregated across 20 sources: ExploitDB, Metasploit, Nuclei, VulnCheck XDB, CrowdSec, GitHub, HackerOne, Bugcrowd, Intigriti, MISP, nmap NSE, Shadowserver, Vulnetix KEV and more.
| Argument | Type |
|---|---|
identifier | string, required |
Log4Shell on Community:
{
"id": "CVE-2021-44228",
"exploitCount": 19868,
"sightingCount": 2568,
"activeSources": [
{ "source": "poc", "count": 15259 },
{ "source": "other", "count": 4507 },
{ "source": "crowdSec", "count": 101 },
{ "source": "vulnetixKev", "count": 82 },
{ "source": "nmapNse", "count": 70 },
{ "source": "hackerone", "count": 27 }
],
"exploitsBySource": [],
"note": "Per-source counts are present but the exploit records themselves are empty. That is tier gating, not an absence of exploits..."
}
activeSources is the decision input, and it is available on every plan. On Pro
and above, exploitsBySource additionally carries samples per source with title,
URL, type, publication date and author.
Is CVE-2021-44228 actually being exploited, or is it theoretical?
vulnetix_sightings
Observed exploitation over time: total count, first and last observation, and days since last seen.
This is the tool that separates historically exploited from being exploited right now. A CVE last seen in 2022 warrants different urgency from one seen this week, and severity scores alone will not tell you which you have.
vulnetix_iocs
Indicators of compromise: attacking IPs, ASNs, geographic distribution and Shadowserver scan counts. For blocklists, SIEM enrichment and SOAR feeds.
vulnetix_threat_actors
Actors and campaigns associated with an advisory, plus whether the advisory itself is flagged malicious or an impersonation trap.
vulnetix_attack_techniques
MITRE ATT&CK techniques and tactics for an advisory. Use it to map a CVE onto the controls you already run, find coverage gaps, or line it up against D3FEND counter-techniques.
Not gated.
vulnetix_scorecard
OpenSSF scorecard results, commit health, PR and repository health, and source-fix correlation for the projects an advisory touches.
The question it answers is whether an upstream is maintained well enough for a fix to plausibly land, which is worth knowing before you plan around one.
Not gated.