
Vulnerability & exploit intelligence — ExploitDB, NVD, Metasploit search with CVE→ATT&CK mapping and LogNorm/HuntForge integration | Part of Nebula Forge
Vulnerability & Exploit Intelligence Tool | Nebula Forge Detection Suite v2
VulnForge aggregates exploit intelligence from ExploitDB, NVD, and Metasploit, maps findings to MITRE ATT&CK techniques, and feeds results directly into the Nebula Forge purple team pipeline — generating hunt playbooks, LogNorm-ready exports, and AtomicLoop simulation triggers from a single search.
VulnForge closes the gap between vulnerability discovery and detection engineering. Search for a CVE or keyword, get back exploit data mapped to ATT&CK techniques, then push that context downstream — straight into HuntForge for playbook generation or AtomicLoop for simulation.
Pipeline position:
VulnForge → HuntForge (hunt playbook) → AtomicLoop (simulation) → Wazuh (detection)
mitreattack-python

VulnForge is part of Nebula Forge — an open-source SOC platform covering the full detection engineering workflow.
| Tool | Port | Role |
|---|---|---|
| LogNorm | 5006 | Log normalization (ECS-lite) |
| HuntForge | 5007 | ATT&CK hunt playbook generation |
| DriftWatch | 5008 | Sigma rule drift analysis |
| ClusterIQ | 5009 | Alert clustering and triage |
| AtomicLoop | 5011 | Atomic Red Team test runner |
| VulnForge | 5012 | Vulnerability & exploit intelligence |
git clone https://github.com/Rootless-Ghost/VulnForge.git
cd VulnForge
pip install -r requirements.txt
python app.py
Access at http://localhost:5012
This tool runs as a containerized service in the Nebula Forge suite. The recommended way to start everything together:
# From the Nebula-Forge repo root
cp .env.example .env # POSTGRES_PASSWORD and ATOMICLOOP_API_KEY required; NVD_API_KEY (higher rate limits) is optional
docker compose up -d # starts all services including vulnforge
Access: http://localhost:5012
Standalone container:
docker build -t vulnforge .
docker run -p 5012:5012 \
-e NVD_API_KEY=your-key-here \
vulnforge
apache 2.4), CVE ID (e.g. CVE-2021-44228), or bothSearch:
curl -X POST http://localhost:5012/api/search \
-H "Content-Type: application/json" \
-d '{"keyword": "log4j", "cve": "CVE-2021-44228"}'
Export to LogNorm:
curl -X POST http://localhost:5012/export/lognorm \
-H "Content-Type: application/json" \
-d '{"results": [...]}'
Send to HuntForge:
curl -X POST http://localhost:5012/export/huntforge \
-H "Content-Type: application/json" \
-d '{"technique_id": "T1190", "cve": "CVE-2021-44228"}'
Health check:
curl http://localhost:5012/health
VulnForge maps CVEs to ATT&CK techniques using a chained lookup:
CVE → NVD CWE tags → CAPEC → ATT&CK Technique
Results include technique ID, technique name, tactic, and confidence level (high/medium/low). When no mapping is found, UNKNOWN is returned rather than silently omitting the field.
{
"event.kind": "vulnerability",
"cve.id": "CVE-2021-44228",
"vulnerability.score.base": 10.0,
"vulnerability.severity": "CRITICAL",
"threat.technique.id": "T1190",
"threat.technique.name": "Exploit Public-Facing Application",
"threat.tactic.name": "Initial Access",
"source.tool": "VulnForge",
"@timestamp": "2026-04-15T00:00:00Z"
}
flask, requests, beautifulsoup4, mitreattack-pythonVulnForge is intended for authorized security testing, detection engineering, and purple team operations. Do not use against systems you do not own or have explicit written permission to test.
This project is licensed under the MIT License — see the LICENSE file for details.
Built by Rootless-Ghost