Skip to content
KitploitKITPLOIT
도구블로그
제출
도구블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

··피드·문의·개인정보·© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
SploitScan — CVE 세부 정보, 익스플로잇 데이터베이스 및 EPSS 점수를 집계하고 AI 위험 평가 및 취약점 스캐너 가져오기를 통해 우선 순위가 지정된 패치를 제공합니다. | Kitploit
도구/GitHubGitHub/xaitax/sploitscan
OSINT (Open Source Intelligence)Exploit FrameworksVulnerability AnalysisPenetration TestingThreat Intelligence
GitHubxaitax/sploitscan

SploitScan

CVE 세부 정보, 익스플로잇 데이터베이스 및 EPSS 점수를 집계하고 AI 위험 평가 및 취약점 스캐너 가져오기를 통해 우선 순위가 지정된 패치를 제공합니다.

저장소 보기
1.4k17512일 전Kitploit 검토 완료

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유

SploitScan

SPLOITSCAN-LOGO Version License

📜 설명

SploitScan은 알려진 취약점에 대한 익스플로잇과 각각의 악용 가능성을 식별하는 과정을 간소화하기 위해 설계된 강력하고 사용자 친화적인 도구입니다. 사이버 보안 전문가가 알려진 익스플로잇과 테스트된 익스플로잇을 신속하게 식별하고 적용할 수 있도록 지원합니다. 특히 보안 조치를 강화하거나 새로운 위협에 대비한 강력한 탐지 전략을 개발하려는 전문가에게 유용합니다.

📖 목차

  • 📜 설명
  • 🌟 기능
  • 💣 지원되는 익스플로잇 데이터베이스
  • 📁 지원되는 취약점 스캐너 가져오기
  • ⚙️ 설치
  • 🚀 사용법
  • 🤖 AI 기반 위험 평가
  • 🛡️ 패치 우선순위 시스템
  • 🫱🏼‍🫲🏽 기여
  • 📌 저자
  • 📆 변경 로그

🌟 기능

  • CVE 정보 검색
    취약점에 대한 상세 정보를 검색합니다.

  • EPSS 통합
    익스플로잇 예측 점수 시스템(EPSS) 데이터를 사용하여 악용 가능성을 확인합니다.

  • 공개 익스플로잇 집계
    공개적으로 이용 가능한 익스플로잇 데이터를 수집하여 각 취약점의 맥락을 이해하는 데 도움을 줍니다.

  • CISA KEV 통합
    취약점이 CISA의 알려진 악용 취약점(KEV) 목록에 있는지 빠르게 확인합니다.

  • AI 기반 위험 평가
    여러 AI 제공업체(OpenAI ChatGPT, Google Gemini, Grok AI, DeepSeek)를 사용하여 잠재적 위험을 설명하고 완화 방안을 제시하는 위험 평가를 받습니다.

  • HackerOne 보고서
    해당 취약점이 HackerOne 버그 바운티 보고서에 포함되었는지 확인하고 기본 순위 및 심각도 정보를 제공합니다.

  • 패치 우선순위 시스템
    CVSS, EPSS 및 사용 가능한 익스플로잇 정보를 기반으로 패치를 위한 간단한 우선순위 등급을 제공합니다.

  • 다중 CVE 지원 및 내보내기 옵션
    여러 CVE를 동시에 처리하고 결과를 HTML, JSON 또는 CSV 형식으로 내보낼 수 있습니다.

  • 취약점 스캐너 가져오기
    Nessus, Nexpose, OpenVAS, Docker 등의 취약점 스캐너에서 스캔 결과를 가져와 알려진 익스플로잇을 직접 검색할 수 있습니다. 이제 --input-dir을 사용한 디렉터리 기반 가져오기를 지원하여 여러 보고서를 일괄 처리할 수 있습니다.

  • 세분화된 메서드 선택
    실행할 특정 데이터 검색 메서드(CISA, EPSS, HackerOne, AI 등)를 선택하여 필요한 정보만 얻을 수 있습니다.

  • 로컬 CVE 데이터베이스 업데이트 및 복제
    CVE 목록 V5 저장소의 로컬 사본을 유지 관리합니다. 이를 통해 전체 CVE 데이터를 로컬 기계에 업데이트하여 오프라인 사용 및 검색이 가능합니다.

  • 키워드 기반 CVE 소스 검색
    로컬 데이터베이스와 CISA, Nuclei Templates 같은 원격 소스에서 키워드(예: "Apple")로 CVE를 검색합니다.

  • 간소화된 출력을 위한 빠른 모드
    빠른 모드를 사용하여 기본 CVE 정보만 표시하고 추가 조회를 건너뛰어 더 빠른 결과를 얻을 수 있습니다.

  • 사용자 친화적 인터페이스
    모든 정보를 읽기 쉬운 형식으로 제공하는 명확하고 직관적인 인터페이스를 제공합니다.

sploitscan_v0 10 4

💣 지원되는 익스플로잇 데이터베이스

  • GitHub
  • ExploitDB
  • VulnCheck (무료 VulnCheck API 키 필요)
  • Nuclei
  • Metasploit

📁 지원되는 취약점 스캐너 가져오기

  • Nessus (.nessus)
  • Nexpose (.xml)
  • OpenVAS (.xml)
  • Docker (.json)

⚙️ 설치

GitHub```shell

git clone https://github.com/xaitax/SploitScan.git cd sploitscan pip install -r requirements.txt

root@kitploit:~
### pip```shell
pip install --user sploitscan

Kali/Ubuntu/Debian (최신 버전이 아닐 수 있음)```shell

apt install sploitscan

root@kitploit:~
### API 키 획득

- **VulnCheck**: [VulnCheck](https://vulncheck.com/)에서 무료 계정을 등록하여 API 키를 받으세요.
- **OpenAI**: [OpenAI](https://platform.openai.com/signup/)에서 계정을 만들고 API 키를 받으세요.
- **Google Gemini**: [Google AI Studio](https://aistudio.google.com/app/apikey)에서 계정을 만들고 API 키를 받으세요.
- **xAI Grok**: [xAI](https://x.ai/api)에서 계정을 만들고 API 키를 받으세요.
- **DeepSeek**: [DeepSeek](https://platform.deepseek.com/api_keys)에서 계정을 만들고 API 키를 받으세요.

### 설정 파일

SploitScan은 기본적으로 여러 위치에서 `config.json`을 검색합니다. 발견된 첫 번째 유효한 파일을 다음 순서로 로드합니다:

1. **`--config` 또는 `-c`로 전달된 사용자 지정 경로**  
2. **환경 변수**: `SPLOITSCAN_CONFIG_PATH`  
3. **로컬 및 표준 설정 파일 위치**:  
   - 현재 작업 디렉터리  
   - `~/.sploitscan/config.json`  
   - `~/.config/sploitscan/config.json`  
   - `~/Library/Application Support/sploitscan/config.json` (macOS)  
   - `%APPDATA%/sploitscan/config.json` (Windows)  
   - `/etc/sploitscan/config.json`

> **참고**: 하나의 파일만 로드됩니다 — 위 순서에서 처음 발견된 파일입니다. `config.json`을 이 경로들 중 아무 곳에나 배치할 수 있습니다.

일반적인 `config.json`은 다음과 같습니다:```json
{
    "vulncheck_api_key": "",
    "openai_api_key": "",
    "google_ai_api_key": "",
    "grok_api_key": "",
    "deepseek_api_key": ""
}

🚀 사용법```shell

$ python .\sploitscan.py -h

███████╗██████╗ ██╗ ██████╗ ██╗████████╗███████╗ ██████╗ █████╗ ███╗ ██╗ ██╔════╝██╔══██╗██║ ██╔═══██╗██║╚══██╔══╝██╔════╝██╔════╝██╔══██╗████╗ ██║ ███████╗██████╔╝██║ ██║ ██║██║ ██║ ███████╗██║ ███████║██╔██╗ ██║ ╚════██║██╔═══╝ ██║ ██║ ██║██║ ██║ ╚════██║██║ ██╔══██║██║╚██╗██║ ███████║██║ ███████╗╚██████╔╝██║ ██║ ███████║╚██████╗██║ ██║██║ ╚████║ ╚══════╝╚═╝ ╚══════╝ ╚═════╝ ╚═╝ ╚═╝ ╚══════╝ ╚═════╝╚═╝ ╚═╝╚═╝ ╚═══╝ v0.14.0 / Alexander Hagenah / @xaitax / [email protected]

usage: sploitscan.py [-h] [-e {json,csv,html}] [-t {nessus,nexpose,openvas,docker}] [--ai {openai,google,grok,deepseek}] [-k KEYWORDS [KEYWORDS ...]] [-local] [-f] [-m METHODS] [-i IMPORT_FILE] [-c CONFIG] [-d] [cve_ids ...]

SploitScan: Retrieve and display vulnerability and exploit data for specified CVE ID(s).

positional arguments: cve_ids Enter one or more CVE IDs (e.g., CVE-YYYY-NNNNN). This is optional if an import file is provided via -i.

options: -h, --help show this help message and exit -e {json,csv,html}, --export {json,csv,html} Export the results in the specified format ('json', 'csv', or 'html'). -t {nessus,nexpose,openvas,docker}, --type {nessus,nexpose,openvas,docker} Specify the type of the import file ('nessus', 'nexpose', 'openvas', or 'docker'). --ai {openai,google,grok,deepseek} Select the AI provider for risk assessment (e.g., 'openai', 'google', 'grok', or 'deepseek'). -k KEYWORDS [KEYWORDS ...], --keywords KEYWORDS [KEYWORDS ...] Search for CVEs related to specific keywords (e.g., product name). -local, --local-database Download the cvelistV5 repository into the local directory. Use the local database over online research if available. -f, --fast-mode Enable fast mode: only display basic CVE information without fetching additional exploits or data. -m METHODS, --methods METHODS Specify which methods to run, separated by commas (e.g., 'cisa,epss,hackerone,ai,prio,references'). -i IMPORT_FILE, --import-file IMPORT_FILE Path to an import file. When provided, positional CVE IDs can be omitted. The file should be a plain text list with one CVE per line. --input-dir INPUT_DIR Path to a directory containing vulnerability reports to scan for CVE IDs. -c CONFIG, --config CONFIG Path to a custom configuration file. -d, --debug Enable debug output.

root@kitploit:~
### 단일 CVE 쿼리```bash
sploitscan CVE-2024-1709

다중 CVE 조회```bash

sploitscan CVE-2024-1709 CVE-2024-21413

root@kitploit:~
### 로컬 CVE 데이터베이스 업데이트

이제 `--local` 옵션을 사용하여 전체 CVE 목록 V5 저장소를 로컬에서 업데이트(또는 초기 클론)할 수 있습니다. 이 저장소의 크기가 수 GB에 달하므로 다운로드에 시간이 걸릴 수 있습니다. 예를 들어:```bash
sploitscan -local

███████╗██████╗ ██╗      ██████╗ ██╗████████╗███████╗ ██████╗ █████╗ ███╗   ██╗
██╔════╝██╔══██╗██║     ██╔═══██╗██║╚══██╔══╝██╔════╝██╔════╝██╔══██╗████╗  ██║
███████╗██████╔╝██║     ██║   ██║██║   ██║   ███████╗██║     ███████║██╔██╗ ██║
╚════██║██╔═══╝ ██║     ██║   ██║██║   ██║   ╚════██║██║     ██╔══██║██║╚██╗██║
███████║██║     ███████╗╚██████╔╝██║   ██║   ███████║╚██████╗██║  ██║██║ ╚████║
╚══════╝╚═╝     ╚══════╝ ╚═════╝ ╚═╝   ╚═╝   ╚══════╝ ╚═════╝╚═╝  ╚═╝╚═╝  ╚═══╝
v0.14.0 / Alexander Hagenah / @xaitax / [email protected]

📥 Cloning CVE List V5 into 'C:\Users\ah/.sploitscan\cvelistV5'.
⚠️ Warning: The repository is several GB in size and the download may take a while.
🔄 Progress: 100.00% - 940.62 MiB | 4.97 MiB/s
✅ CVE List V5 cloned successfully.

소스 전반에 걸친 키워드 기반 검색

로컬 데이터베이스, CISA 및 Nuclei Templates에서 키워드(예: "Apple")로 CVE를 검색합니다.

[!TIP] 이는 searchsploit을 대체할 수 있습니다. ExploitDB가 더 이상 정기적으로 업데이트되지 않기 때문입니다.```bash sploitscan -k "Outlook Express"

███████╗██████╗ ██╗ ██████╗ ██╗████████╗███████╗ ██████╗ █████╗ ███╗ ██╗ ██╔════╝██╔══██╗██║ ██╔═══██╗██║╚══██╔══╝██╔════╝██╔════╝██╔══██╗████╗ ██║ ███████╗██████╔╝██║ ██║ ██║██║ ██║ ███████╗██║ ███████║██╔██╗ ██║ ╚════██║██╔═══╝ ██║ ██║ ██║██║ ██║ ╚════██║██║ ██╔══██║██║╚██╗██║ ███████║██║ ███████╗╚██████╔╝██║ ██║ ███████║╚██████╗██║ ██║██║ ╚████║ ╚══════╝╚═╝ ╚══════╝ ╚═════╝ ╚═╝ ╚═╝ ╚══════╝ ╚═════╝╚═╝ ╚═╝╚═╝ ╚═══╝ v0.14.0 / Alexander Hagenah / @xaitax / [email protected]

┌───[ 🕵️ Searching local database for keywords: outlook express ] Processing CVE files: 100%|████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████████| 282372/282372 [04:38<00:00, 1013.92it/s]

╔═══════════════════════════════════════════╗ ║ Found 48 CVE(s) matching: Outlook Express ║ ╚═══════════════════════════════════════════╝

CVE-1999-0967, CVE-1999-1016, CVE-1999-1033, CVE-2000-0036, CVE-2000-0105, CVE-2000-0415, CVE-2000-0524, CVE-2000-0567, CVE-2000-0621, CVE-2000-0653, CVE-2001-0145, CVE-2001-0149, CVE-2001-0945, CVE-2001-0999, CVE-2001-1088, CVE-2001-1325, CVE-2001-1547, CVE-2002-0152, CVE-2002-0285, CVE-2002-0637, CVE-2002-0862, CVE-2002-1121, CVE-2002-1179, CVE-2002-2164, CVE-2002-2202, CVE-2003-0301, CVE-2003-1105, CVE-2003-1378, CVE-2004-0215, CVE-2004-0380, CVE-2004-0526, CVE-2004-2137, CVE-2004-2694, CVE-2005-1213, CVE-2005-2226, CVE-2005-4840, CVE-2006-0014, CVE-2006-2111, CVE-2006-2386, CVE-2006-2766, CVE-2007-2225, CVE-2007-2227, CVE-2007-3897, CVE-2007-4040, CVE-2008-1448, CVE-2008-5424, CVE-2010-0816, CVE-2024-1187

╔═══════════════════════╗ ║ CVE ID: CVE-2001-1547 ║ ╚═══════════════════════╝

┌───[ 🔍 Vulnerability information ] | ├ Published: 2005-07-14 ├ Base Score: N/A (N/A) ├ Vector: N/A └ Description: Outlook Express 6.0, with "Do not allow attachments to be saved or opened that could potentially be a virus" enabled, does not block email attachments from forwarded messages, which could allow remote attackers to execute arbitrary code. [...]

root@kitploit:~
### 빠른 모드

빠른 모드를 활성화하면 추가 조회 없이 기본 CVE 정보만 표시됩니다.```bash
sploitscan CVE-2024-1709 --fast-mode

취약점 스캐너에서 가져오기

유형을 지정하세요: 'nessus', 'nexpose', 'openvas' 또는 'docker'를 선택하고 파일 경로를 제공하십시오.```bash sploitscan --import-file path/to/yourfile.nessus --type nessus

root@kitploit:~
### 디렉토리에서 가져오기

전체 디렉토리를 재귀적으로 스캔하여 취약점 보고서를 찾고 모든 파일에서 CVE ID를 추출합니다.```bash
sploitscan --input-dir path/to/reports/directory

특정 방법 선택

특정 데이터 검색 방법(예: CISA, EPSS, AI risk assessment)만 실행하려면 -m 인수를 사용하세요:```bash sploitscan CVE-2024-1709 -m cisa,epss

root@kitploit:~
### 결과 내보내기

내보내기 형식을 지정하세요: 'json', 'csv', 또는 'html'.```bash
sploitscan CVE-2024-1709 -e html

Docker

Docker가 설치되어 있는지 확인하십시오. 설치 방법은 Docker 공식 설치 가이드를 참조하십시오.

Docker에서 SploitScan을 빌드하고 실행하려면:```shell docker build -t sploitscan . docker run --rm sploitscan CVE-2024-1709

root@kitploit:~
현재 디렉터리에서 볼륨을 마운트한 상태에서

#### Windows (Powershell)```shell
docker run -v ${PWD}:/app --rm sploitscan CVE-2024-1709 -e JSON

Linux```shell

docker run -v $(pwd):/app --rm sploitscan CVE-2024-1709 -e JSON

root@kitploit:~
## 🤖 AI 기반 위험 평가

위험 평가를 위한 AI 제공자를 선택하세요 (OpenAI ChatGPT, Google Gemini, Grok AI 및 DeepSeek).

SploitScan은 OpenAI와 통합하여 각 CVE에 대한 포괄적인 AI 기반 위험 평가를 제공합니다. 이 기능은 다음을 포함합니다:

- 상세 위험 평가: 취약점의 특성과 비즈니스 영향을 이해합니다.
- 잠재적 공격 시나리오: 취약점을 악용하는 잠재적 공격 시나리오에 대한 설명을 제공합니다.
- 완화 권장 사항: 위험을 완화하기 위한 구체적이고 실행 가능한 권장 사항을 제공합니다.
- 경영진 요약: 비기술적 이해 관계자도 접근할 수 있는 간결한 요약으로, 비즈니스 영향과 긴급성을 강조합니다.

### 예제 출력```text

$ sploitscan.py --ai openai CVE-2024-21413

[...]

┌───[ 🤖 AI-Powered Risk Assessment ]
|
| 1. Risk Assessment
| -------------------
| The vulnerability identified by CVE-2024-21413 is a critical remote code execution flaw in
| Microsoft Outlook with a CVSS score of 9.8. The impact on business operations can be severe due to
| its high potential to be exploited over a network without any user interactions or elevated
| privileges. This unvalidated input vulnerability (CWE-20) could allow an attacker to execute
| arbitrary code on the target system, thereby compromising the confidentiality, integrity, and
| availability of critical business data and systems. Given its critical rating and the existence of
| multiple exploits on public repositories like GitHub, the likelihood of exploitation is very high.
| This necessitates immediate attention from the security teams to mitigate the risks associated.
|
| 2. Potential Attack Scenarios
| ------------------------------
| An attacker could exploit this vulnerability by sending a specially crafted email to a victim
| using Microsoft Outlook. Once the email is opened or previewed, the malicious payload would
| execute, allowing the attacker to gain control over the victim's system. The process involves: 1.
| Crafting a malicious email leveraging the specific flaw in email handling within Microsoft
| Outlook. 2. Sending the email to the intended victim. 3. Upon opening or previewing the email, the
| victim’s system executes the malicious code. The potential outcomes of this attack include theft
| of sensitive information, installation of malware or ransomware, and compromising other systems
| within the same network due to lateral movement capabilities.
|
| 3. Mitigation Recommendations
| ------------------------------
| Immediate mitigation recommendation includes: 1. Applying the latest security patches provided by
| Microsoft. Reference: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21413 2.
| Implementing network-level protections such as email filtering and network segmentation to limit
| the spread of potential infections. 3. Conducting regular security awareness training for users to
| recognize phishing and malicious emails. 4. Monitoring network and system activity for signs of
| suspicious behavior and unauthorized execution. 5. Regularly backing up critical data and ensuring
| the integrity of backups.
|
| 4. Executive Summary
| ---------------------
| CVE-2024-21413, a critical remote code execution vulnerability in Microsoft Outlook, poses a
| significant risk to businesses due to its potential to be exploited without user interaction.
| Multiple exploit proofs are publicly available, increasing the likelihood of attacks.
| Organizations must act swiftly by applying the necessary patches from Microsoft, enhancing their
| email security protocols, and educating their staff to identify potential phishing attempts.
| Mitigating this vulnerability is essential to protect sensitive information, maintain business
| integrity, and ensure system availability, thus preventing potential financial and reputational
| damage. Immediate action is crucial to safeguard the organization against this severe threat.
|
└────────────────────────────────────────

🛡️ 패치 우선순위 시스템

SploitScan의 패치 우선순위 시스템은 취약점의 심각도와 악용 가능성을 기반으로 보안 패치의 우선순위를 정하는 전략적 접근 방식을 제공합니다. 이는 CVE Prioritizer의 모델에 영향을 받았으며, 공개적으로 제공되는 익스플로잇을 처리하기 위한 개선 사항이 포함되어 있습니다. 이 시스템은 사용자가 잠재적 영향과 악용 가능성을 고려하여 어떤 취약점을 먼저 패치할지 정보에 기반한 결정을 내리도록 돕습니다. 임계값은 비즈니스 요구에 맞게 변경할 수 있습니다. 작동 방식은 다음과 같습니다.

  • A+ 우선순위: CISA의 Known Exploited Vulnerabilities (KEV) 카탈로그에 등록된 취약점에 할당됩니다. 이는 실제 환경에서 악용이 확인되었기 때문에 가장 높은 긴급성을 나타냅니다.
  • A~D 우선순위: CVSS 기본 점수와 EPSS (Exploit Prediction Scoring System) 확률의 조합으로 결정됩니다.
    • A: CVSS 점수 >= 6.0 및 EPSS 점수 >= 0.2. 높은 심각도와 높은 악용 확률.
    • B: CVSS 점수 >= 6.0이지만 EPSS 점수 < 0.2. 높은 심각도이지만 낮은 악용 확률.
    • C: CVSS 점수 < 6.0 및 EPSS 점수 >= 0.2. 낮은 심각도이지만 높은 악용 확률.
    • D: CVSS 점수 < 6.0 및 EPSS 점수 < 0.2. 낮은 심각도와 낮은 악용 확률.

🚨 익스플로잇 기반 상향 조정

아직 A+ 등급이 아닌 취약점에 대해 공개 익스플로잇이 알려진 경우, 해당 우선순위는 두 단계 상향됩니다. 예를 들어:

  • 공개 익스플로잇이 있는 C 등급 취약점은 A 등급이 됩니다.
  • 공개 익스플로잇이 있는 D 등급 취약점은 B 등급이 됩니다.

이를 통해 알려진 악용 가능성이 있는 취약점이 적절한 긴급성으로 처리됩니다.

🫱🏼‍🫲🏽 기여

기여를 환영합니다! 버그 수정, 새 기능 추가 또는 문서 개선 등 무엇이든 자유롭게 저장소를 포크하고 풀 리퀘스트를 제출해 주세요. GitHub 이슈 트래커를 통해 문제를 보고하거나 개선 사항을 제안할 수도 있습니다.

특별히 감사드립니다:

  • UjjwalBudha - 아이디어 및 코드
  • hexwreaker - 아이디어 및 코드
  • Nilsonfsilva - Debian 패키징 지원
  • bcoles - 버그 수정
  • Javier Álvarez - 버그 수정
  • Romullo - 아이디어 및 제안
  • davidfortytwo - 개선 사항 (CVE 검색 업데이트 및 PacketStorm 추가)
  • con-f-use - setuptools/PyPi 지원 및 수정
  • Martijn Russchen - HackerOne GraphQL에 대한 피드백 및 아이디어
  • diwskx - 디렉토리 가져오기 기능 및 Docker 개선
  • Manuel Sommer - 패치 우선순위 계산 개선 및 Dependabot 추가

📌 저자

Alexander Hagenah

  • URL
  • Twitter
  • LinkedIn

📆 변경 로그

업데이트, 수정 사항 및 새로운 기능에 대한 자세한 목록은 변경 로그를 확인하세요.

도구 다운로드