Open-Source Detector of CISA's Known Exploitable Vulnerabilities

This page summarizes the projects mentioned and recommended in the original post on news.ycombinator.com

Our great sponsors
  • WorkOS - The modern identity platform for B2B SaaS
  • InfluxDB - Power Real-Time Data Analytics at Scale
  • SaaSHub - Software Alternatives and Reviews
  • KEV

    Ostorlab KEV: One-command to detect most remotely known exploitable vulnerabilities. Sourced from CISA KEV, Google's Tsunami, Ostorlab's Asteroid and Bug Bounty programs.

  • agent_metasploit

    Agent metasploit

  • WorkOS

    The modern identity platform for B2B SaaS. The APIs are flexible and easy-to-use, supporting authentication, user identity, and complex enterprise features like SSO and SCIM provisioning.

    WorkOS logo
  • agent_nuclei

    Agent responsible for fast vulnerability scanning using Nuclei.

  • agent_openvas

    Agent responsible for network security and vulnerability scanning using OpenVas.

  • OpenVas (not used though due to many issues): https://github.com/Ostorlab/agent_openvas

  • agent_asteroid

    Agent responsible for detecting remote vulnerabilities, a robust scanner.

  • agent_subfinder

    Agent implementation of Subfinder. subdomain discovery tool that discovers valid subdomains for websites.

  • There is, see the section "Targetting all subdomains".

    You can do so by adding your domain name generation tool of your choice, or all. The ones supported for now are `subfinder` and `amass`.

    Agent Subfinder: https://github.com/Ostorlab/agent_subfinder

  • agent_amass

    Agent for OWASP for network mapping of attack surfaces and external asset discovery using open source information gathering and active reconnaissance techniques.

  • InfluxDB

    Power Real-Time Data Analytics at Scale. Get real-time insights from all types of time series data with InfluxDB. Ingest, query, and analyze billions of data points in real-time with unbounded cardinality.

    InfluxDB logo
  • oxo

    OXO is a security scanning orchestrator for the modern age.

  • That repo also has no license information that I can tell, although the pip install is Apache 2 <https://github.com/Ostorlab/ostorlab#readme>

NOTE: The number of mentions on this list indicates mentions on common posts plus user suggested alternatives. Hence, a higher number means a more popular project.

Suggest a related project

Related posts