返回更新列表
新发布Aug 6, 2026

puncia v0.35

Panthera(P.)uncia - 子域中心与漏洞利用观察者的官方 CLI 实用工具。

分享

Panthera(P.)uncia

Subdomain Center 与 Exploit Observer 的官方 CLI 工具

Downloads GitHub stars

Puncia 是两款 A.R.P. Syndicate 情报 API 的官方命令行客户端——只需指向一个域名、一个品牌或一个漏洞 ID,即可在几秒内获得结构化 JSON 结果,无需浏览器:

  • 🕸️ Subdomain Center — 互联网规模的子域名枚举、子域名接管发现、影子 IT 发现,以及品牌仿冒 / 相似域名(域名抢注)检测。
  • 💥 Exploit Observer — 覆盖 150 多种标识符体系(CVE、GHSA、EDB、MSF、ZDI、国家行为体情报源等)的漏洞利用与漏洞情报,支持 CVE/GHSA 富化(EPSS + VEDAS 成熟度评分)以及 SBOM 扫描。
$ puncia subdomain arpsyndicate.io
╭──────────────────────────────────────────────────────────────────────╮
│ Panthera(P.)uncia v0.39                                              │
│ subdomain recon · brand impersonation · exploit intel · sbom analysis│
│ A.R.P. Syndicate — https://www.arpsyndicate.io                       │
╰──────────────────────────────────────────────────────────────────────╯
[
  "advisories.arpsyndicate.io",
  "asm.arpsyndicate.io",
  "blog.arpsyndicate.io",
  ...
]

$ puncia sbom bom.json ./out
puncia ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ 100% (128/128) 0:00:41

请注意,尽管这些结果有时可能相当不准确且不可靠,但由于其自我改进能力,它们在不同时间可能会有很大差异。

使用 API 密钥可以避免激进的速率限制:https://www.arpsyndicate.io/pricing.html

实际应用

  1. 品牌仿冒与钓鱼域名检测
    在仿冒、相似及域名抢注域名被用于攻击你或你的客户之前,发现它们。
  2. 影子 IT 与外部攻击面发现
    识别并监控在官方渠道之外暴露的子域名和基础设施。
  3. 子域名接管侦察
    枚举目标的完整子域名足迹,这是发现悬空/易被接管记录的关键第一步。
  4. 高级漏洞研究与监控
    发现并跟踪已知和新兴威胁,包括冷门或未列出的漏洞。
  5. CVE/GHSA 数据的上下文富化
    为已知漏洞添加深度和可操作情报(EPSS + VEDAS 成熟度评分),以便更好地确定优先级。
  6. 软件物料清单(SBOM)中的漏洞检测
    使用结构化 SBOM 数据分析软件组件中的已知漏洞利用和安全问题。
  7. 与 CI/CD 及威胁情报工作流无缝集成
    在开发或安全流水线中自动化情报收集和漏洞检查。
  8. 监控国家行为体漏洞利用趋势
    通过跟踪被外国行为体标记但尚未被主流数据库认可的漏洞,保持领先于威胁。
  9. 基于关键字的子域名发现
    在互联网上发现包含给定关键字的主机,独立于特定的父域名。
  10. 批量威胁情报处理
    运行批量查询(域名、漏洞等),以便在大型数据集或企业资产清单中进行可扩展分析。
  11. 红队被动侦察
    使用被动数据源(不与目标直接交互)进行隐蔽侦察。
  12. 开源情报(OSINT)收集
    结合子域名和漏洞利用情报,增强 OSINT 调查。
  13. 合规与风险管理支持
    富化漏洞数据,以更深入的上下文支持合规审计(例如 ISO 27001、SOC 2)。

安装

  1. 从 PyPi 安装 - pip3 install puncia
  2. 从源码安装 - pip3 install .

30 秒快速上手

pip3 install puncia

# subdomain footprint of a target (shadow IT / attack surface / takeover recon)
puncia subdomain example.com

# lookalike / typosquat / brand-impersonation domains
puncia replica example.com

# what's known about a CVE
puncia exploit CVE-2021-44228

用法

puncia <mode> <query> [output] [--match M] [--domain D] [--limit N] [--offset N]
                               [--crawl] [--filter KEY=VALUE] [--format json|csv]
                               [--api-key K] [--concurrency N]
                               [--timeout S] [--retries N] [--quiet]

运行 puncia --help 查看完整参考。结果输出到 stdout;横幅、进度条、警告和错误都输出到 stderr,因此 puncia subdomain example.com > out.json 始终能生成干净、有效的 JSON。

退出码: 0 成功 · 1 请求或输入错误 · 2 用法错误。

  1. (付费)存储 API 密钥(storekey)- puncia storekey <api-key>

    • 存储在 ~/.puncia,权限为 0600。$PUNCIA_API_KEY 会覆盖它,这在 CI 中通常是你想要的。
  2. (免费增值)查询域名,按域名聚类(subdomain / cuttlefish 引擎)- puncia subdomain <domain> <output-file>

    • 分页(仅限已认证): 已认证的结果没有总数上限。默认情况下,subdomain/replica/keyword 会遍历每一页并为你合并。传入 --offset(无论是否带 --limit)则改为自行获取恰好一页原始数据,例如用于可恢复或流式遍历:
      puncia subdomain bigco.com --limit 50000 --offset 0
      # stderr prints: note: more results available — continue with --offset 50000
      puncia subdomain bigco.com --limit 50000 --offset 50000
      
      匿名请求在服务端会忽略 --limit/--offset(始终是最多 500 行的打乱样本);puncia 会发出警告,而不是假装它们起了作用。
    • 实时爬取(仅限已认证): --crawl 通过一次实时发现过程补充已存储的结果。给定域名大约每 6 小时才会真正重新爬取一次——该时间窗口内的请求会立即获得缓存的爬取结果。Puncia 会在 stderr 上报告结果: crawl: fresh, 12 newly discovered name(s)(还有 partial / running / cooldown / disabled)。在 partial/running 状态下,部分爬取仍在服务端进行;一分钟后再用 --crawl 重新运行以获取其余部分。
      puncia subdomain bigco.com --crawl
      
  3. (免费增值)查询仿冒域名,按品牌聚类(replica / octopus 引擎)- puncia replica <domain> --match <prefix|exact|substring> <output-file>

  4. (免费增值)按关键字查询,按关键字聚类(keyword / ammonites 引擎)- puncia keyword <keyword> --match <exact|prefix> <output-file>

    • 可选地使用 --domain 将关键字限定到单个域名: puncia keyword blog --domain bandcamp.com
  5. 查询漏洞利用与漏洞标识符(exploit)

    • (免费)漏洞利用与漏洞标识符观察列表(^WATCHLIST_IDES)- puncia exploit ^WATCHLIST_IDES <output-file>
    • (免费)带描述的漏洞利用与漏洞标识符观察列表(^WATCHLIST_INFO)- puncia exploit ^WATCHLIST_INFO <output-file>
    • (免费)易受攻击技术观察列表(^WATCHLIST_TECH)- puncia exploit ^WATCHLIST_TECH <output-file>
    • (免费)聚合漏洞/利用统计(^STATS)- puncia exploit ^STATS <output-file>
    • (免费)服务健康状态(^HEALTH)- puncia exploit ^HEALTH <output-file>
    • (免费增值)支持的漏洞标识符 - puncia exploit <eoidentifier> --match <substring|prefix|exact> <output-file>
  6. (免费增值)富化 CVE/GHSA 标识符(enrich)- puncia enrich <cve-id/ghsa-id> <output-file>

    • enrich=true 仅对 CVE-/GHSA- 标识符生效;它会将完整的上游公告记录与 EPSS + VEDAS 评分合并。
  7. (付费)按 VEDAS 分组的非 CVE 标识符(noncve)- puncia noncve <browser/china/russia/europe/exploitable> <output-file>

  8. (付费)Nuclei 模板候选(nuclei)- puncia nuclei candidates <output-file>

    • 拥有 VEDAS id 且尚无 nuclei 模板但看起来可模板化的 CVE
    • 每一页都会自动获取并合并;--limit 设置页大小(最大 1000),--offset 则改为只获取一页。
    • 使用可重复的 --filter KEY=VALUE 缩小范围:min_feasibility、vendor、product、platform、cwe、method、protocol、kev、poc、portable。
    • CSV 导出: --format csv,或者直接给出以 .csv 结尾的输出路径——每个 CVE 一行,列表字段用 ; 连接(原因用 | 连接),电子表格会视为公式的单元格会被置为惰性。
      puncia nuclei candidates candidates.csv
      puncia nuclei candidates wp.csv --filter platform=wordpress --filter poc=true
      puncia nuclei candidates --filter kev=true --filter min_feasibility=0.5 --format csv > kev.csv
      
  9. (免费)Subdomain Center 服务健康状态(^HEALTH)- puncia subdomain ^HEALTH <output-file>

  10. 多查询(bulk/sbom)

    • (免费增值)批量输入 JSON 文件格式 - puncia bulk <json-file> <output-directory>
      {
          "subdomain": [
              "domainA.com",
              "domainB.com"
          ],
          "replica": [
              "domainA.com",
              "domainB.com"
          ],
          "keyword": [
              "keywordA",
              "keywordB"
          ],
          "exploit": [
              "eoidentifierA",
              "eoidentifierB"
          ],
          "enrich": [
              "eoidentifierA",
              "eoidentifierB"
          ]
      }
      
    • (免费增值)SBOM 输入 JSON 文件格式 - puncia sbom <json-file> <output-directory>

    批量与 SBOM 运行会对查询去重,将并行度限制在 --concurrency(默认 10),并且——当没有 API 密钥时——自动调整请求节奏以保持在免费额度预算内。

  11. (免费增值)外部导入

import asyncio
import puncia

async def main():
   # Without an API key (ratelimited)
   print(await puncia.query_api("exploit", "CVE-2021-3450"))
   print(await puncia.query_api("subdomain", "arpsyndicate.io"))

   # With an API key
   await puncia.store_key("ARPS-xxxxxxxxxx")
   api_key = await puncia.read_key()
   print(await puncia.query_api("subdomain", "arpsyndicate.io", apikey=api_key))
   print(await puncia.query_api("replica", "arpsyndicate.io", match="exact", apikey=api_key))
   print(await puncia.query_api("enrich", "CVE-2021-3450", apikey=api_key))
   print(await puncia.query_api("noncve", "exploitable", apikey=api_key))

分类