
CVEの詳細、エクスプロイトデータベース、EPSSスコアを集約し、AIによるリスク評価と脆弱性スキャナーのインポート機能を備え、優先順位付けされたパッチ適用を実現します。
SploitScanは、既知の脆弱性に対するエクスプロイトとその悪用確率を特定するプロセスを効率化する、強力でユーザーフレンドリーなツールです。サイバーセキュリティの専門家が、既知のエクスプロイトやテスト済みエクスプロイトを迅速に特定し適用できるようにします。これは、セキュリティ対策を強化したり、新たな脅威に対する堅牢な検出戦略を策定しようとする専門家にとって特に価値があります。
CVE情報の取得
脆弱性に関する詳細情報を取得します。
EPSS統合
悪用予測スコアリングシステム(EPSS)のデータを用いて悪用の可能性を確認します。
公開エクスプロイトの集約
公開されているエクスプロイトデータを収集し、各脆弱性のコンテキストを理解するのに役立てます。
CISA KEV統合
脆弱性がCISAの既知の悪用された脆弱性カタログに掲載されているかを素早く確認します。
AI搭載リスク評価
複数のAIプロバイダー(OpenAI ChatGPT、Google Gemini、Grok AI、DeepSeek)を使用してリスク評価を取得し、潜在的なリスクを説明し、緩和策のアイデアを提供します。
HackerOneレポート
脆弱性がHackerOneのバグ報奨金プログラムに関与しているかを確認し、基本的なランクや重大度の詳細を提供します。
パッチ優先度システム
CVSS、EPSS、利用可能なエクスプロイト情報に基づいて、パッチ適用のシンプルな優先度評価を提供します。
複数CVE対応とエクスポートオプション
複数のCVEを同時に処理し、結果をHTML、JSON、またはCSV形式でエクスポートできます。
脆弱性スキャナーインポート
一般的な脆弱性スキャナー(Nessus、Nexpose、OpenVAS、Docker)のスキャン結果をインポートし、既知のエクスプロイトを直接検索します。--input-dirを使用したディレクトリベースのインポートに対応し、複数のレポートを一括処理できます。
細かいメソッド選択
実行する特定のデータ取得メソッド(CISA、EPSS、HackerOne、AIなど)を選択できるため、必要な情報だけを取得できます。
ローカルCVEデータベースの更新とクローン
CVE List V5リポジトリのローカルコピーを維持します。これにより、オフラインで使用したり検索するために、完全なCVEデータをマシン上で更新できます。
キーワードベースのCVE検索(複数ソース)
キーワード(例:「Apple」)を使用して、ローカルデータベースとCISAやNucleiテンプレートなどのリモートソースの両方でCVEを検索します。
高速モードによる簡潔な出力
高速モードを使用すると、基本的なCVE情報のみを表示し、追加のルックアップをスキップして迅速な結果を得られます。
ユーザーフレンドリーなインターフェース
明確で分かりやすいインターフェースを備え、すべての情報を読みやすい形式で表示します。

git clone https://github.com/xaitax/SploitScan.git cd sploitscan pip install -r requirements.txt
### pip```shell
pip install --user sploitscan
apt install sploitscan
### APIキーの取得
- **VulnCheck**: 無料アカウントを登録し、[VulnCheck](https://vulncheck.com/) でAPIキーを取得します。
- **OpenAI**: アカウントを作成し、[OpenAI](https://platform.openai.com/signup/) でAPIキーを取得します。
- **Google Gemini**: アカウントを作成し、[Google AI Studio](https://aistudio.google.com/app/apikey) でAPIキーを取得します。
- **xAI Grok**: アカウントを作成し、[xAI](https://x.ai/api) でAPIキーを取得します。
- **DeepSeek**: アカウントを作成し、[DeepSeek](https://platform.deepseek.com/api_keys) でAPIキーを取得します。
### 設定ファイル
SploitScanはデフォルトで複数の場所から `config.json` を検索します。最初に見つかった有効なファイルを以下の順序で読み込みます:
1. **`--config` または `-c` で指定されたカスタムパス**
2. **環境変数**: `SPLOITSCAN_CONFIG_PATH`
3. **ローカルおよび標準の設定ファイルの場所**:
- カレントワーキングディレクトリ
- `~/.sploitscan/config.json`
- `~/.config/sploitscan/config.json`
- `~/Library/Application Support/sploitscan/config.json` (macOS)
- `%APPDATA%/sploitscan/config.json` (Windows)
- `/etc/sploitscan/config.json`
> **注意**: 読み込まれるファイルは1つだけです — 上記の順序で最初に見つかったものです。`config.json` はこれらのパスのいずれかに配置できます。
典型的な `config.json` は次のようになります:
``````json
{
"vulncheck_api_key": "",
"openai_api_key": "",
"google_ai_api_key": "",
"grok_api_key": "",
"deepseek_api_key": ""
}
$ python .\sploitscan.py -h
███████╗██████╗ ██╗ ██████╗ ██╗████████╗███████╗ ██████╗ █████╗ ███╗ ██╗ ██╔════╝██╔══██╗██║ ██╔═══██╗██║╚══██╔══╝██╔════╝██╔════╝██╔══██╗████╗ ██║ ███████╗██████╔╝██║ ██║ ██║██║ ██║ ███████╗██║ ███████║██╔██╗ ██║ ╚════██║██╔═══╝ ██║ ██║ ██║██║ ██║ ╚════██║██║ ██╔══██║██║╚██╗██║ ███████║██║ ███████╗╚██████╔╝██║ ██║ ███████║╚██████╗██║ ██║██║ ╚████║ ╚══════╝╚═╝ ╚══════╝ ╚═════╝ ╚═╝ ╚═╝ ╚══════╝ ╚═════╝╚═╝ ╚═╝╚═╝ ╚═══╝ v0.14.0 / Alexander Hagenah / @xaitax / [email protected]
usage: sploitscan.py [-h] [-e {json,csv,html}] [-t {nessus,nexpose,openvas,docker}] [--ai {openai,google,grok,deepseek}] [-k KEYWORDS [KEYWORDS ...]] [-local] [-f] [-m METHODS] [-i IMPORT_FILE] [-c CONFIG] [-d] [cve_ids ...]
SploitScan: Retrieve and display vulnerability and exploit data for specified CVE ID(s).
positional arguments: cve_ids Enter one or more CVE IDs (e.g., CVE-YYYY-NNNNN). This is optional if an import file is provided via -i.
options: -h, --help show this help message and exit -e {json,csv,html}, --export {json,csv,html} Export the results in the specified format ('json', 'csv', or 'html'). -t {nessus,nexpose,openvas,docker}, --type {nessus,nexpose,openvas,docker} Specify the type of the import file ('nessus', 'nexpose', 'openvas', or 'docker'). --ai {openai,google,grok,deepseek} Select the AI provider for risk assessment (e.g., 'openai', 'google', 'grok', or 'deepseek'). -k KEYWORDS [KEYWORDS ...], --keywords KEYWORDS [KEYWORDS ...] Search for CVEs related to specific keywords (e.g., product name). -local, --local-database Download the cvelistV5 repository into the local directory. Use the local database over online research if available. -f, --fast-mode Enable fast mode: only display basic CVE information without fetching additional exploits or data. -m METHODS, --methods METHODS Specify which methods to run, separated by commas (e.g., 'cisa,epss,hackerone,ai,prio,references'). -i IMPORT_FILE, --import-file IMPORT_FILE Path to an import file. When provided, positional CVE IDs can be omitted. The file should be a plain text list with one CVE per line. --input-dir INPUT_DIR Path to a directory containing vulnerability reports to scan for CVE IDs. -c CONFIG, --config CONFIG Path to a custom configuration file. -d, --debug Enable debug output.
### 単一CVEクエリ```bash
sploitscan CVE-2024-1709
sploitscan CVE-2024-1709 CVE-2024-21413
### ローカルCVEデータベースの更新
`--local`オプションを使用して、フルCVEリストV5リポジトリをローカルに更新(または最初にクローン)できるようになりました。このリポジトリは数GBのサイズがあるため、ダウンロードには時間がかかる場合があることに注意してください。例:```bash
sploitscan -local
███████╗██████╗ ██╗ ██████╗ ██╗████████╗███████╗ ██████╗ █████╗ ███╗ ██╗
██╔════╝██╔══██╗██║ ██╔═══██╗██║╚══██╔══╝██╔════╝██╔════╝██╔══██╗████╗ ██║
███████╗██████╔╝██║ ██║ ██║██║ ██║ ███████╗██║ ███████║██╔██╗ ██║
╚════██║██╔═══╝ ██║ ██║ ██║██║ ██║ ╚════██║██║ ██╔══██║██║╚██╗██║
███████║██║ ███████╗╚██████╔╝██║ ██║ ███████║╚██████╗██║ ██║██║ ╚████║
╚══════╝╚═╝ ╚══════╝ ╚═════╝ ╚═╝ ╚═╝ ╚══════╝ ╚═════╝╚═╝ ╚═╝╚═╝ ╚═══╝
v0.14.0 / Alexander Hagenah / @xaitax / [email protected]