Skip to content
KitploitKITPLOIT
أدواتعمليات الاستغلالالمدونة
Log in
إرسال
أدواتعمليات الاستغلالالمدونة
إرسال

أدوات الاختراق واختبار الاختراق والأمن السيبراني لترسانتك الأمنية!

Kitploit هو دليل لأدوات الاختراق والأمن السيبراني واختبار الاختراق. اكتشف آخر تحديثات المشاريع للعثور على الثغرات وتحليل الأنظمة وأتمتة الاختبارات وتعزيز أمنك.

··الخلاصات·اتصال·الخصوصية·© 2026 Kitploit

دليل الأدوات

الفئات

عرض جميع الفئات
Loading categories
Vulfy — 🐺 Vulfy – ماسح إصدارات الحزم السريع المبني على Rust | Kitploit
أدوات/GitHubGitHub/mindpatch/vulfy
ماسحات الثغرات الأمنيةتحليل الثغرات الأمنيةتحليل الكودDevSecOpsأمن سلسلة التوريد
GitHubmindpatch/vulfy

Vulfy

🐺 Vulfy – ماسح إصدارات الحزم السريع المبني على Rust

عرض المستودع
16312منذ سنة واحدةلم تتم المراجعة بعد

الأكثر شعبية

عرض الكل →

اكتشف الأدوات الأكثر استخدامًا من قبل مجتمعنا.

استكشف جميع الأدوات

تصفح مجموعتنا من الأدوات

عرض جميع الأدوات →
مشاركة
شعار Vulfy

🐺 Vulfy

ماسح ثغرات سريع متعدد اللغات لا يضيّع الوقت.

Release License: MIT Rust CI


🚀 ما هو Vulfy؟

Vulfy هو ماسح ثغرات فائق السرعة يفحص تبعيات مشروعك بحثًا عن مشكلات أمنية معروفة عبر 9 لغات برمجة. مبني باستخدام Rust لتحقيق أقصى أداء، ويتكامل مع قاعدة بيانات OSV.dev لتوفير معلومات دقيقة ومحدّثة عن الثغرات.

✨ الميزات الرئيسية

  • 🔥 سريع للغاية - أداء Rust غير المتزامن مع فحص متزامن
  • 🌍 دعم متعدد الأنظمة البيئية - npm, Python, Rust, Java, Go, Ruby, C/C++, PHP, .NET
  • 📊 تنسيقات إخراج متعددة - جدول، JSON، CSV، SARIF لحالات استخدام مختلفة
  • 🎯 تكامل OSV.dev - بيانات ثغرات حقيقية من قاعدة بيانات الثغرات مفتوحة المصدر من Google
  • ⚡ بدون إعدادات - يعمل مباشرة، وهيئ فقط ما تحتاجه
  • 🔄 جاهز للتكامل مع CI/CD - أكواد خروج وتنسيقات مثالية لخطوط الأنابيب الآلية
  • 🤖 الأتمتة والمراقبة - مراقبة مستمرة لمستودعات Git مع إشعارات ذكية
  • 📋 محرك سياسات متقدم - تصفية مخصصة للثغرات وسياسات أمنية
  • 🔔 إشعارات متعددة المنصات - تكاملات Discord وSlack وwebhook

📚 التوثيق

📖 التوثيق الكامل - أدلة شاملة ودروس تعليمية ومرجع API

التنقل السريع

  • 🚀 بدء سريع في 5 دقائق - ابدأ الفحص فورًا
  • ⚙️ دليل التثبيت - جميع طرق التثبيت
  • 📋 مرجع CLI - توثيق كامل للأوامر
  • 🤖 إعداد الأتمتة - مراقبة مستمرة
  • 🔧 مخطط الإعدادات - مرجع إعدادات كامل

📦 التثبيت

الخيار 1: حزم تنفيذية جاهزة (موصى به)

# Linux/WSL
curl -LO https://github.com/mindPatch/vulfy/releases/latest/download/vulfy-linux-x86_64.tar.gz
tar -xzf vulfy-linux-x86_64.tar.gz
sudo mv vulfy /usr/local/bin/

# macOS (Intel)
curl -LO https://github.com/mindPatch/vulfy/releases/latest/download/vulfy-macos-x86_64.tar.gz
tar -xzf vulfy-macos-x86_64.tar.gz
sudo mv vulfy /usr/local/bin/

# macOS (Apple Silicon)
curl -LO https://github.com/mindPatch/vulfy/releases/latest/download/vulfy-macos-aarch64.tar.gz
tar -xzf vulfy-macos-aarch64.tar.gz
sudo mv vulfy /usr/local/bin/

الخيار 2: باستخدام Cargo

cargo install vulfy

الخيار 3: من المصدر

git clone https://github.com/mindPatch/vulfy.git
cd vulfy
cargo build --release
sudo cp target/release/vulfy /usr/local/bin/

التحقق من التثبيت:

vulfy --version
# Should output: vulfy 0.1.0

🏃‍♂️ البدء السريع

الفحص الأساسي للثغرات

# Scan current directory
vulfy scan packages

# Scan specific directory
vulfy scan packages --path /path/to/project

# Only show high-severity vulnerabilities
vulfy scan packages --high-only

إنشاء التقارير

# JSON for automation/CI
vulfy scan packages --format json --output security-report.json

# CSV for spreadsheet analysis
vulfy scan packages --format csv --output vulnerabilities.csv

# SARIF for GitHub Security tab
vulfy scan packages --format sarif --output vulfy.sarif

التكامل مع CI/CD

# Fail build if high-severity vulnerabilities found
vulfy scan packages --high-only --quiet || exit 1

# Scan specific ecosystems only
vulfy scan packages --ecosystems npm,pypi --no-dev-deps

🎯 الأنظمة البيئية المدعومة

النظام البيئيملفات الحزمالحالة
📦 npmpackage-lock.json, yarn.lock, pnpm-lock.yaml, package.json✅
🐍 Pythonrequirements.txt, Pipfile.lock, poetry.lock, pyproject.toml✅
🦀 RustCargo.lock, Cargo.toml✅
☕ Javapom.xml, build.gradle, build.gradle.kts✅
🐹 Gogo.mod, go.sum, go.work✅
💎 RubyGemfile.lock, Gemfile, *.gemspec✅
⚙️ C/C++vcpkg.json, CMakeLists.txt, conanfile.txt🆕 جديد!
🐘 PHPcomposer.json, composer.lock🆕 جديد!
🔷 .NET*.csproj, packages.config, *.nuspec🆕 جديد!

📋 مثال على المخرجات

تنسيق الجدول الجميل (الافتراضي)

🔍 Scanning for package files...
📦 Found 6 package files across 4 ecosystems

🛡️  VULNERABILITY REPORT
┌─────────────────────────────────────────┬──────────────┬──────────┬─────────────────┬──────┐
│ Title                                   │ CVE ID       │ Severity │ Package         │ Year │
├─────────────────────────────────────────┼──────────────┼──────────┼─────────────────┼──────┤
│ Remote Code Execution in lodash        │ CVE-2021-123 │ 🔥 High  │ [email protected]   │ 2021 │
│ Path Traversal in express              │ CVE-2022-456 │ 🟡 Medium│ [email protected]  │ 2022 │
│ SQL Injection in sequelize             │ CVE-2020-789 │ 🔥 High  │ [email protected] │ 2020 │
└─────────────────────────────────────────┴──────────────┴──────────┴─────────────────┴──────┘

📊 SCAN SUMMARY
• Total packages scanned: 42
• Vulnerable packages: 8
• Total vulnerabilities: 12
• 🔥 High severity: 4
• 🟡 Medium severity: 6
• 🟢 Low severity: 2

📖 شاهد جميع تنسيقات المخرجات - أمثلة JSON وCSV وSARIF


🤖 الأتمتة والمراقبة

تتضمن Vulfy نظام أتمتة قويًا للمراقبة الأمنية المستمرة لمستودعات Git.

ميزات الأتمتة الرئيسية

  • 📂 مراقبة متعددة المستودعات - تتبّع عدة مستودعات Git مع فحص مخصص لكل فرع
  • ⏰ جدولة مرنة - كل ساعة أو يوميًا أو أسبوعيًا أو تعبيرات cron مخصصة
  • 🔔 إشعارات ذكية - تنبيهات غنية عبر Discord/Slack مع تصفية حسب الخطورة
  • 📋 محرك سياسات متقدم - تصفية مخصصة للثغرات مع مطابقة الكلمات المفتاحية
  • 🔐 دعم المصادقة - رموز GitHub ومفاتيح SSH والوصول إلى المستودعات الخاصة
  • 🏗️ تصفية الأنظمة البيئية - استهداف النظام البيئي لكل مستودع لإجراء فحوصات مركّزة

إعداد الأتمتة السريع

# Initialize automation with example configuration
vulfy automation init --with-examples

# Validate configuration
vulfy automation validate

# Run manual scan using automation config
vulfy automation run

# Start continuous monitoring
vulfy automation start --foreground

مثال على الإعدادات

# Monitor multiple repositories
[[repositories]]
name = "my-web-app"
url = "https://github.com/user/my-web-app.git"
branches = ["main", "develop"]
ecosystems = ["npm", "pypi"]

[repositories.credentials]
username = "git"
token = "your_github_token_here"

# Schedule daily scans at 2:00 AM UTC
[schedule]
frequency = "daily"
time = "02:00"
timezone = "UTC"

# Discord webhook notifications
[[notifications.webhooks]]
name = "Security Alerts"
url = "https://discord.com/api/webhooks/..."
webhook_type = "discord"
enabled = true

# Advanced security policies
[[policies]]
name = "Critical Authentication Issues"
enabled = true

[policies.conditions]
title_contains = ["authentication", "auth", "bypass"]
severity = ["high", "critical"]

[policies.actions]
notify = true
priority = "critical"
custom_message = "🚨 Critical auth vulnerability detected!"

📖 دليل الأتمتة الكامل - إعداد وتكوين مفصّل


تنزيل الأداة