跳到主要内容
知仓学习社ZHICANG

cve-triage

CVE lookup and triage — map discovered services/versions to known CVEs via the cve_lookup tool, score by CVSS/exploitability, and prioritize what to…

不碰外部(只输出文字)无严重或高危命中Netw0rkNoob/VulnClaw

它会碰到什么

扫了多少2 个文本文件,5 KB
它会碰到什么不碰外部(只输出文字)
命中总数0 处
命中统计严重 0 · 高 0 · 中 0 · 低 0

这一栏是扫描器报的事实,不是结论。命中多不等于有毒(安全工具、规则库、示例脚本本来就会包含危险写法),命中少也不等于干净。它和你手上的凭据、文件、网络有什么关系,需要你自己看。

技能内容

CVE Triage

Turn version/banner evidence from recon into a prioritized, exploitability-aware

list of CVEs worth verifying. Use this after fingerprinting a service, when a

banner or Server: header reveals a product and version, or whenever the target

exposes software with a known version.

The cve_lookup tool

VulnClaw ships a read-only cve_lookup tool backed by NVD:

  • Keyword searchcve_lookup(query="Apache httpd 2.4.49", limit=5) returns

the top CVEs sorted by CVSS, highest first.

  • CVE-ID detailcve_lookup(query="CVE-2021-44228") returns the full record

plus best-effort exploit / PoC repositories discovered on GitHub.

It performs no egress to the target and is safe during recon. Without an

NVD_API_KEY it still works (lower rate limit); set one for heavier use.

Workflow

  1. Extract product + version from recon — service banners, Server headers,

JS bundles, login footers, package manifests. A precise version string

(OpenSSH 8.2p1, nginx 1.18.0) yields far better matches than a bare name.

  1. Query cve_lookup with "<product> <version>". Pull the detail record for

any high/critical hit by re-querying its CVE-ID.

  1. Score & prioritize — see references/cve-triage-workflow.md. Rank by CVSS,

then by exploit availability, then by exposure (is the vulnerable surface

actually reachable on this target?).

  1. Confirm version applicability — match the target's version against the

CVE's affected cpe range before claiming it. Banner ≠ proof of vulnerability.

  1. Record findings with the CVE-ID, CVSS, and the evidence that maps this

target to it. Mark unconfirmed version-only matches as needs-manual-review,

not verified.

Pitfalls

  • A keyword match is a hypothesis, not a finding — version ranges and backported

patches mean a banner version can be patched in place.

  • GitHub "PoC" repos are unverified third-party code; treat as leads, never run

blindly against a target.

  • Prefer the CVSS base score for triage, but let exploit availability and real

exposure override raw score when prioritizing verification effort.

想直接用这个技能?

本站把开放许可(MIT / Apache 等)的技能按仓库打包整理到网盘,点一下转存到你自己的网盘,不用一个个从 GitHub 拉。许可未声明的技能只给原始仓库链接,不打包。

它属于哪个仓库

星标★ 3,350
本站分层T1
该仓技能数50
原文件路径vulnclaw/skills/specialized/cve-triage/SKILL.md

同一个仓库里的其他技能

看这个仓库的全部 50 个技能