Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
vedas-signatures — VEDAS-Driven Autonomous Generation + Community Contributions of Suricata & Nuclei Rules for over 12000 CVEs | Kitploit
Tools/GitHubGitHub/arpsyndicate/vedas-signatures
Defensive ToolsIndicator of Compromise (IOC) ManagementVulnerability ScannersWeb Vulnerability ScannersThreat Feeds & AggregatorsVulnerability AnalysisScripting & AutomationNetwork SecurityThreat IntelligenceIntrusion DetectionCurated Resources
19131 day agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
GitHubarpsyndicate/vedas-signatures

vedas-signatures

VEDAS-Driven Autonomous Generation + Community Contributions of Suricata & Nuclei Rules for over 12000 CVEs

View RepositoryWebsite
Share

VEDAS-Driven Autonomous Generation + Community Contributions of Suricata & Nuclei Rules for CVEs

Suricata Nuclei

This repository is an open, collaborative validation space for CVE detection content:

  • Suricata rules: network detection of exploitation attempts.
  • Nuclei templates: active, non-destructive checks for exposure to a CVE.

Most signatures are generated autonomously by ARPSyndicate's Vulnerability & Exploit Data Aggregation System (VEDAS). AI lets us create detection content quickly and at scale from vulnerability and exploit intelligence. Reliable detection still needs transparency, human review and real-world testing, so the content is published here for the community to review, validate, fix and extend through issues and pull requests.

Coverage

12,466 unique CVEs covered — each with a Suricata rule and a Nuclei template.

CVE yearSuricata SignaturesNuclei Signatures
199944
200066
20011010
20025151
20035555
2004153153
2005495495
20061,2811,281
20071,0091,009
20081,5441,544
2009737737
2010620620
2011155155
2012266266
2013185185
2014283283
2015201201
2016142142
2017343343
2018509509
2019351351
2020462462
2021653653
2022649649
2023651651
2024735735
2025493493
2026423423

Layout

suricata/<YYYY>/CVE-YYYY-NNNNN.rules   # one file per CVE, one rule per line
nuclei/<YYYY>/CVE-YYYY-NNNNN.yaml      # one template per CVE
payloads/                              # self-hosted PoC payloads (SVG/DTD/CSV/…) so checks need no external host
scripts/                               # validation tooling used by CI (run it locally too)
.github/                               # CI workflows, issue forms, PR template

<YYYY> is the CVE year, not the year the signature was written.

Using the signatures

Suricata (tested on Suricata 8.x):

cat suricata/*/*.rules > vedas.rules
suricata -T -c /etc/suricata/suricata.yaml -S vedas.rules   # test-load first

Or add the directory to rule-files: in suricata.yaml. SIDs 1000000-1999999 come from VEDAS and 3000000-3999999 from the community. Neither range overlaps ET Open.

Nuclei (tested on Nuclei v3):

nuclei -t nuclei/ -u https://target.example

Only scan systems you are authorised to test.

Contributing

Contributions of every kind are welcome:

You want to...Do this
Report a rule that fires on benign trafficFalse positive issue
Report a rule that misses real exploitationFalse negative issue
Report a rule that fails to load or is slowBroken signature issue
Ask for coverage of a CVESignature request
Fix or add a signatureOpen a pull request: see CONTRIBUTING.md

Every pull request is checked automatically. It must load in real Suricata/Nuclei engines and pass the repository lint, and the target CVE must exist on cve.org. You can run the same checks locally before pushing (see CONTRIBUTING.md).

Disclaimer

Signatures generated by VEDAS are syntactically validated only. Logical testing has not been performed in most cases. Validate every signature in your own environment before deploying it. Community-reviewed signatures are marked as such in their pull request history. This content is provided as-is, without warranty of any kind (see LICENSE).

Signatures are self-contained and on-prem friendly: every PoC payload a check needs is stored in payloads/ and served from this repository, with no dependency on any third-party host.

Acknowledgements

VEDAS aggregates openly available intelligence (OSINT) from across the internet — vulnerability databases, advisories, exploit and PoC publications, detection rulesets, and research shared by vendors, CERTs, independent researchers, and the wider cybersecurity community. This feed is built on that collective knowledge, and we're grateful to everyone who contributes to it. Where specific detection logic was adapted from an openly licensed project — notably projectdiscovery/nuclei-templates (MIT) — it is credited in NOTICE. Community contributors are credited in each template's info.author and in the pull-request history.

Please report security issues in this repository's tooling privately. See SECURITY.md.

Download Tool