
puncia v0.36
Panthera(P.)uncia - 子域中心与漏洞利用观察者的官方 CLI 实用工具。
Panthera(P.)uncia
Subdomain Center 与 Exploit Observer 的官方 CLI 工具
Puncia 是两个 A.R.P. Syndicate 情报 API 的官方命令行客户端——只需指向一个域名、一个品牌或一个漏洞 ID,即可在几秒内获得结构化 JSON 数据,无需浏览器:
- 🕸️ Subdomain Center — 互联网规模的子域名枚举、子域名接管发现、影子 IT 发现以及品牌仿冒 / 仿冒域名(域名抢注)检测。
- 💥 Exploit Observer — 覆盖 150 多种标识符体系(CVE、GHSA、EDB、MSF、ZDI、国家级行为体情报源等)的漏洞利用与漏洞情报,支持 CVE/GHSA 富化(EPSS + VEDAS 成熟度评分)以及 SBOM 扫描。
$ puncia subdomain arpsyndicate.io
╭──────────────────────────────────────────────────────────────────────╮
│ Panthera(P.)uncia v0.38 │
│ subdomain recon · brand impersonation · exploit intel · sbom analysis│
│ A.R.P. Syndicate — https://www.arpsyndicate.io │
╰──────────────────────────────────────────────────────────────────────╯
[
"advisories.arpsyndicate.io",
"asm.arpsyndicate.io",
"blog.arpsyndicate.io",
...
]
$ puncia sbom bom.json ./out
puncia ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ 100% (128/128) 0:00:41
请注意,尽管这些结果有时可能相当不准确且不可靠,但由于其自我改进能力,它们在不同时间可能会有很大差异。
使用 API 密钥可以避免激进的速率限制:https://www.arpsyndicate.io/pricing.html
实际应用
- 品牌仿冒与钓鱼域名检测
在仿冒、相似和域名抢注域名被用于攻击您或您的客户之前,发现它们。 - 影子 IT 与外部攻击面发现
识别并监控在官方渠道之外暴露的子域名和基础设施。 - 子域名接管侦察
枚举目标的完整子域名足迹,这是发现悬空/易被接管记录的关键第一步。 - 高级漏洞研究与监控
发现并跟踪已知和新兴威胁,包括冷门或未列出的漏洞。 - CVE/GHSA 数据的上下文富化
为已知漏洞添加深度和可操作情报(EPSS + VEDAS 成熟度评分),以便更好地确定优先级。 - 软件物料清单(SBOM)中的漏洞检测
使用结构化 SBOM 数据分析软件组件中的已知漏洞利用和安全问题。 - 与 CI/CD 及威胁情报工作流无缝集成
在开发或安全流水线中自动化情报收集和漏洞检查。 - 监控国家级漏洞利用趋势
通过跟踪被外国行为体标记但尚未被主流数据库识别的漏洞,保持领先于威胁。 - 基于关键字的子域名发现
在互联网上发现包含给定关键字的主机,独立于特定的父域名。 - 批量威胁情报处理
运行批量查询(域名、漏洞等),以便在大型数据集或企业资产清单中进行可扩展分析。 - 红队被动侦察
使用被动数据源(不与目标直接交互)进行隐蔽侦察。 - 开源情报(OSINT)收集
结合子域名和漏洞利用情报,增强 OSINT 调查。 - 合规与风险管理支持
丰富漏洞数据,以更深入的上下文支持合规审计(例如 ISO 27001、SOC 2)。
安装
- 从 PyPi 安装 -
pip3 install puncia - 从源码安装 -
pip3 install .
30 秒快速上手
pip3 install puncia
# subdomain footprint of a target (shadow IT / attack surface / takeover recon)
puncia subdomain example.com
# lookalike / typosquat / brand-impersonation domains
puncia replica example.com
# what's known about a CVE
puncia exploit CVE-2021-44228
用法
puncia <mode> <query> [output] [--match M] [--domain D] [--limit N] [--offset N]
[--crawl] [--api-key K] [--concurrency N]
[--timeout S] [--retries N] [--quiet]
运行 puncia --help 查看完整参考。结果输出到 stdout;横幅、进度条、警告和错误都输出到 stderr,因此 puncia subdomain example.com > out.json 始终会生成干净、有效的 JSON。
退出码: 0 成功 · 1 请求或输入错误 · 2 用法错误。
-
(付费)存储 API 密钥(storekey)-
puncia storekey <api-key>- 存储在
~/.puncia,权限为0600。$PUNCIA_API_KEY会覆盖它, 这在 CI 中通常正是您想要的。
- 存储在
-
(免费增值)查询域名,按域名聚类(subdomain /
cuttlefish引擎)-puncia subdomain <domain> <output-file>- 分页(仅限已认证): 已认证的结果没有总数
上限。默认情况下,
subdomain/replica/keyword会遍历每一页并为您合并 它们。传入--offset(可带或不带--limit)可自行获取恰好 一个原始页面,例如用于可恢复或流式遍历:匿名请求在服务端会忽略puncia subdomain bigco.com --limit 50000 --offset 0 # stderr prints: note: more results available — continue with --offset 50000 puncia subdomain bigco.com --limit 50000 --offset 50000--limit/--offset(始终是 最多 500 行的打乱样本);puncia 会发出警告,而不是假装 它们起了作用。 - 实时爬取(仅限已认证):
--crawl通过一次实时发现过程补充已存储的 结果。给定域名实际上每约 6 小时才会被重新爬取一次——该时间窗口内的请求会立即 获得缓存的爬取结果。Puncia 会在 stderr 上报告结果:crawl: fresh, 12 newly discovered name(s)(还有partial/cooldown/disabled)。puncia subdomain bigco.com --crawl
- 分页(仅限已认证): 已认证的结果没有总数
上限。默认情况下,
-
(免费增值)查询仿冒域名,按品牌聚类(replica /
octopus引擎)-puncia replica <domain> --match <prefix|exact|substring> <output-file> -
(免费增值)按关键字查询,按关键字聚类(keyword /
ammonites引擎)-puncia keyword <keyword> --match <exact|prefix> <output-file>- 可选地使用
--domain将关键字限定到单个域名:puncia keyword blog --domain bandcamp.com
- 可选地使用
-
查询漏洞利用与漏洞标识符(exploit)
- (免费)漏洞利用与漏洞标识符观察列表(^WATCHLIST_IDES)-
puncia exploit ^WATCHLIST_IDES <output-file> - (免费)带描述的漏洞利用与漏洞标识符观察列表(^WATCHLIST_INFO)-
puncia exploit ^WATCHLIST_INFO <output-file> - (免费)易受攻击技术观察列表(^WATCHLIST_TECH)-
puncia exploit ^WATCHLIST_TECH <output-file> - (免费)聚合漏洞/漏洞利用统计(^STATS)-
puncia exploit ^STATS <output-file> - (免费)服务健康状态(^HEALTH)-
puncia exploit ^HEALTH <output-file> - (免费增值)支持的漏洞标识符 -
puncia exploit <eoidentifier> --match <substring|prefix|exact> <output-file>
- (免费)漏洞利用与漏洞标识符观察列表(^WATCHLIST_IDES)-
-
(免费增值)富化 CVE/GHSA 标识符(enrich)-
puncia enrich <cve-id/ghsa-id> <output-file>enrich=true仅对CVE-/GHSA-标识符生效;它会将 完整的上游公告记录与 EPSS + VEDAS 评分合并。
-
(付费)按 VEDAS 分组的非 CVE 标识符(noncve)-
puncia noncve <browser/china/russia/europe/exploitable> <output-file> -
(免费)Subdomain Center 服务健康状态(^HEALTH)-
puncia subdomain ^HEALTH <output-file> -
多查询(bulk/sbom)
- (免费增值)批量输入 JSON 文件格式 -
puncia bulk <json-file> <output-directory>{ "subdomain": [ "domainA.com", "domainB.com" ], "replica": [ "domainA.com", "domainB.com" ], "keyword": [ "keywordA", "keywordB" ], "exploit": [ "eoidentifierA", "eoidentifierB" ], "enrich": [ "eoidentifierA", "eoidentifierB" ] } - (免费增值)SBOM 输入 JSON 文件格式 -
puncia sbom <json-file> <output-directory>
批量与 SBOM 运行会对查询去重,将并行度限制在
--concurrency(默认 10),并且——当没有 API 密钥时——自动调整请求节奏以保持在 免费层预算之内。 - (免费增值)批量输入 JSON 文件格式 -
-
(免费增值)外部导入
import asyncio
import puncia
async def main():
# Without an API key (ratelimited)
print(await puncia.query_api("exploit", "CVE-2021-3450"))
print(await puncia.query_api("subdomain", "arpsyndicate.io"))
# With an API key
await puncia.store_key("ARPS-xxxxxxxxxx")
api_key = await puncia.read_key()
print(await puncia.query_api("subdomain", "arpsyndicate.io", apikey=api_key))
print(await puncia.query_api("replica", "arpsyndicate.io", match="exact", apikey=api_key))
print(await puncia.query_api("enrich", "CVE-2021-3450", apikey=api_key))
print(await puncia.query_api("noncve", "exploitable", apikey=api_key))
# Static endpoints (unauthenticated, unlimited)
print(await puncia.query_api("subdomain", "^HEALTH"))
print(await puncia.query_api("exploit", "^STATS"))
# Live crawl, with the outcome surfaced via a callback
await puncia.query_api(
"subdomain", "bigco.com", apikey=api_key, crawl=True,
on_crawl=lambda h: print("crawl status:", h.get("X-Crawl-Status")),
)
# Write straight to disk
await puncia.query_api("subdomain", "arpsyndicate.io", "out.json", apikey=api_key)
asyncio.run(main())
失败会抛出 puncia.PunciaError;空结果({} / [])会
原样返回,而不会被当作错误处理。通过传入 session= 和共享的 limiter=,可以在多个
查询之间复用同一个会话,正如
process_bulk() 所做的那样。
from puncia import PunciaError, query_api
try:
data = await query_api("exploit", "CVE-2021-3450", apikey=api_key)
except PunciaError as exc:
print(f"lookup failed: {exc}")
开发
git clone https://github.com/ARPSyndicate/puncia && cd puncia
pip install --upgrade pip # editable installs need pip >= 21.3
pip install -e ".[dev]"
pytest # 42 offline tests, no API calls or network access
测试套件完全离线——它覆盖 URL 构造、输出路径 包含、SBOM 解析、批量规划和速率限制器计时,而不触及 网络,因此可以在任何环境中安全运行。
CVE 富化
GHSA 富化
值得注意的提及
- Passive Subdomain Enumeration: Uncovering More Subdomains than Subfinder & Amass
- Around 1000 exploitable cybersecurity vulnerabilities that MITRE & NIST ‘might’ have missed but China or Russia didn’t.
- Utilizing GitHub Actions for gathering Subdomain & Exploit Intelligence
- Introducing Exploit Observer — More than Shodan Exploits, Less than Vulners
- PUNCIA — The Panthera(P.)uncia of Cybersecurity
- Subdomain Enumeration Tool Face-off - 2023 Edition