Web filtering: Exploit archives

osint_exploit_archives

Resolves and fetches exploit-DB, Packet Storm and Vulners: public archives of working exploit code. Each service is tested twice — the hostname is resolved and the landing page is fetched — because DNS filtering and URL filtering are different controls. Nothing is downloaded and no query is run.

Severity high how bad it would be if it were real
Expected outcome Something should prevent it
Platforms 3 macOS, Linux, Windows
Isolation subprocess runs in its own process, so a kill is a measurement

What it needs before it will run

  • runs in --safe

    Observation only. It runs even in the inert mode, because it changes nothing and sends nothing.

  • sends traffic

    Generates outbound traffic. --no-network suppresses it entirely.

Gates are cumulative and none of them is implied by another: see the three gates for why they are separate decisions.

ATT&CK techniques it exercises

MITRE ATT&CK techniques this test maps to.
Technique Name Tactic Across public reports
T1588.005 Obtain Capabilities: Exploits Resource Development coverage statistics
T1596 Search Open Technical Databases Reconnaissance coverage statistics

How often anything notices

Not enough data: fewer than 3 public reports have run this test, so no rate is published for it. Groups below that threshold are withheld everywhere on the site — with one or two contributors an average is one organisation's result with a percent sign after it.

Other hacking services and web filtering tests

Other tests in the Hacking services and web filtering category.
Test What it does Severity
Web filtering: Anonymisers and web proxies osint_anonymisers Resolves and fetches browser-based web proxies and consumer VPN clients. Each service is tested twice — the hostname is resolved and the landing page … high
Web filtering: Malware repositories osint_malware_repositories Resolves and fetches vx-underground, MalShare and Malware Traffic Analysis: live samples and campaign captures. Each service is tested twice — the hos… high
Web filtering: Breach and credential data osint_breach_data Resolves and fetches deHashed, Intelligence X and Have I Been Pwned: searchable credential and leak data. Each service is tested twice — the hostname … medium
Web filtering: Offensive tooling distribution osint_offensive_tooling Resolves and fetches kali image mirrors, Metasploit, Cobalt Strike and implant hardware vendors. Each service is tested twice — the hostname is resolv… medium
Web filtering: Internet-wide scan databases osint_scan_databases Resolves and fetches shodan, Censys, ZoomEye, GreyNoise, FOFA, LeakIX and Onyphe: searchable indexes of every reachable service on the internet. Each … medium
Shodan API reachability and self-exposure lookup osint_shodan_self_lookup Calls Shodan's keyless endpoint, which returns this host's public IP address, and then its host-lookup API with a deliberately invalid key. Reaching t… medium
Web filtering: Hacking communities osint_hacking_communities Resolves and fetches long-running hacking forums, a standard web-filter category. Each service is tested twice — the hostname is resolved and the land… low

Catalogue generated from client 0.1.0. A test's behaviour can change between releases; this page describes the version named here.