Automic VaultAutomic Vault

brew

Installer exploitdb avec Homebrew, MacPorts, Nix, pacman

Consultez les chemins d'installation, exécutables, métadonnées et notes de sécurité de exploitdb pour les workflows d'agents IA.

installation

Commandes d'installation supplémentaires

macOS

Homebrewvérifié · 100%
brew install exploitdb

local Homebrew formula metadata

MacPortsvérifié · 94%
sudo port install exploitdb

MacPorts ports tree · security/exploitdb/Portfile · Source: api.github.com

Linux

Nixvérifié · 92%
nix profile install nixpkgs#exploitdb

nixpkgs package indexes · pkgs/by-name/ex/exploitdb/package.nix · Source: api.github.com

Arch Linux pacmanvérifié · 92%
sudo pacman -S exploitdb

Arch Linux sync databases · exploitdb · Source: geo.mirror.pkgbuild.com

aperçu

Résumé du paquet

Database of public exploits and corresponding vulnerable software

Commandes et alias

  • searchsploit

historique

Historique du projet et usages

Exploit-DB is OffSec's public archive of exploit code, shellcode, papers, and proof-of-concept material for vulnerable software. It is built for penetration testers and vulnerability researchers who need searchable, actionable examples rather than advisory prose.

The Homebrew package is mostly useful because it installs the database and SearchSploit, the command-line tool for querying a local checkout. That makes Exploit-DB one of the rare security datasets that package managers ship as a practical offline research corpus.

Historique du projet

The archive traces back to milw0rm, a public exploit archive started by str0ke in early 2004 after another exploit source moved behind a paid model. OffSec's history page presents milw0rm as a trusted community source because submitted exploits were verified before inclusion.

In July 2009, str0ke announced that milw0rm would close, then said it would continue temporarily because of community demand. OffSec took over the database in November 2009, launched the exploit-db.com domain that month, and continued the service as Exploit-DB.

The current GitLab repository is the official source tree for Exploit-DB exploits and shellcode, with companion repositories for binary exploits and papers. Its README says the repository is updated daily with recent submissions.

Historique d'adoption

Exploit-DB became a standard reference because it preserved working exploit and proof-of-concept material in a searchable form. OffSec describes it as a non-profit public-service project and a CVE-compliant archive intended for penetration testers and vulnerability researchers.

SearchSploit turned the web archive into a local Unix workflow. The official manual documents Kali Linux packaging, Git installation, and Homebrew installation, and notes that the standard Kali GNOME build includes the exploitdb package by default.

Modes d'utilisation

SearchSploit searches a local copy of Exploit-DB by one or more terms, with options for title-only searches, exact matching, CVE lookup, JSON output, Nmap XML correlation, path lookup, and mirroring selected exploits into a working directory.

The manual emphasizes offline use: a tester can take a local checkout into segregated or air-gapped networks, update it later, and optionally add binary-exploit and papers repositories for more complete local data.

Pourquoi les passionnés de paquets s'y intéressent

Exploit-DB is a package-manager oddity: it is both a command-line program and a frequently updated vulnerability corpus. Installing it with Homebrew or apt gives users a filesystem tree of exploits plus a shell-oriented search interface.

For Unix users, the interesting part is not just the executable but the layout and update behavior: SearchSploit reads CSV indexes, points at exploit/shellcode/paper paths through .searchsploit_rc, and can be kept current through package updates or git.

Chronologie

  • 2004: str0ke starts a public exploit archive that becomes milw0rm.
  • 2009-07-08: str0ke announces the site will close.
  • 2009-11-04: OffSec is publicly reported as the group taking over the database.
  • 2009-11-16: The OffSec handover goes live.
  • 2009-11-17: exploit-db.com is set up.
  • 2010: milw0rm closes for good after no longer accepting updates.
  • 2016: SearchSploit users with older Kali packages are directed to update through the traditional package manager before using newer update behavior.

Related projects

  • SearchSploit is the bundled command-line search tool for the local Exploit-DB repository.
  • The Google Hacking Database is maintained by OffSec as an extension of Exploit-DB.
  • exploitdb-bin-sploits and exploitdb-papers are companion repositories for binary exploit files and papers.

posture de sécurité

Niveau de risque : red

escape, surveillance, or offensive capability signal.

Classificateur de risque

risque red · confiance moyen · escape-surveillance-offensive

Pourquoi

  • escape, surveillance, or offensive capability signal

Signaux

  • text:exploit

Comportement d'installation

  • Aucun hook post-install Homebrew n’est enregistré dans les métadonnées de formule.
  • Les métadonnées de bottle Homebrew sont disponibles pour 6 plateformes.

Revue recommandée

Avant une utilisation sans surveillance par un agent, vérifiez si l'outil lit des identifiants en clair, écrit un état distant, publie des artefacts ou lance des plugins.

local files

Configuration and credential file locations

These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.

Configuration files

Config paths the tool may read or write during local use.

Unix
<exploitdb checkout>/.searchsploit_rc

exécutables

Exécutables installés

CommandeTypeExpositionNote
searchsploitcliexécutable global

fraîcheur

Version et fraîcheur

Ces signaux séparent l'âge de génération de la page, l'activité du gestionnaire de paquets et la comparaison avec les versions amont. Un retard de version n'est signalé que lorsqu'une URL de preuve et des versions comparables sont présentes.

page générée2026-07-25
version du gestionnaire2026-07-09
gestionnaire mis à jour2026-07-09
données localesOK
amontnot checked
dernière version détectéenon détecté

https://www.exploit-db.com/

métadonnées d'installation

Métadonnées du paquet

Clé du paquetbrew:exploitdb
Version2026-07-09
Gestionnaire de paquetsHomebrew
Page du gestionnaire de paquetshttps://formulae.brew.sh/formula/exploitdb
Page d'accueilhttps://www.exploit-db.com/
Dépôthttps://gitlab.com/exploit-database/exploitdb
Docs amonthttps://gitlab.com/exploit-database/exploitdb
LicenceGPL-2.0-or-later
Archive sourcehttps://gitlab.com/exploit-database/exploitdb.git
Dernière mise à jour2026-07-09T06:53:23Z
Pulseupdated
Bouteilledisponible (sur arm64_linux, arm64_sequoia, arm64_sonoma, arm64_tahoe, sonoma, x86_64_linux)
post-install Homebrewnon défini
Serviceaucun déclaré

faits du registre

Détails de la base source

Source DatabaseHomebrew formula API
Taphomebrew/core
Full Nameexploitdb
Version Scheme0
Revision0
Head VersionHEAD
Bottle Stable Root URLhttps://ghcr.io/v2/homebrew/core
Deprecatedno
Disabledno
Keg Onlyno
URL Keys
  • head
  • stable

correspondances dans les bases sources

Autres enregistrements de gestionnaires de paquets

Les correspondances proviennent d’index externes de gestionnaires de paquets et restent séparées des liens de paquets Automic Vault locaux.

Nix95%

exploitdb

nix profile install nixpkgs#exploitdb
  • normalized package name match
  • Correspondance par : Exploitdb
nixpkgs package indexes · api.github.com · nixpkgs package indexes: pkgs/by-name/ex/exploitdb/package.nix from https://api.github.com/repos/NixOS/nixpkgs/git/trees/master?recursive=1
pacman95%

exploitdb 20260602-1

Offensive Security’s Exploit Database Archive

https://www.exploit-db.com/

sudo pacman -S exploitdb
  • License: GPL-2.0-or-later
  • Architecture: any
  • 2 dépendances optionnelles
  • normalized package name match
  • Correspondance par : Exploitdb
Arch Linux sync databases · geo.mirror.pkgbuild.com · Arch Linux sync databases: exploitdb from https://geo.mirror.pkgbuild.com/extra/os/x86_64/extra.db.tar.gz
MacPorts95%

exploitdb

sudo port install exploitdb
  • normalized package name match
  • Correspondance par : Exploitdb
MacPorts ports tree · api.github.com · MacPorts ports tree: security/exploitdb/Portfile from https://api.github.com/repos/macports/macports-ports/git/trees/master?recursive=1

piste source

Généré depuis les données du dépôt

Cette page est servie par av-web depuis l'artéfact SQLite privé des paquets généré par scripts/generate-pkg-sqlite.py.

Sources utilisées

  • Geiger risk classifier
  • Nucleus package database
  • av.db category and tag curation
  • cross-ecosystem install command graph
  • curated configuration and credential file locations
  • curated package history
  • external package-manager database matches
  • package relationship graph
  • package version freshness
  • package-page enrichment