Automic VaultAutomic Vault

brew

exploitdb を Homebrew, MacPorts, Nix, pacman でインストール

exploitdb のインストール経路、実行ファイル、メタデータ、AI エージェント向けセキュリティノートを確認します。

インストール

追加のインストールコマンド

macOS

Homebrew確認済み · 100%
brew install exploitdb

local Homebrew formula metadata

MacPorts確認済み · 94%
sudo port install exploitdb

MacPorts ports tree · security/exploitdb/Portfile · ソース: api.github.com

Linux

Nix確認済み · 92%
nix profile install nixpkgs#exploitdb

nixpkgs package indexes · pkgs/by-name/ex/exploitdb/package.nix · ソース: api.github.com

Arch Linux pacman確認済み · 92%
sudo pacman -S exploitdb

Arch Linux sync databases · exploitdb · ソース: geo.mirror.pkgbuild.com

概要

パッケージ概要

Database of public exploits and corresponding vulnerable software

コマンドとエイリアス

  • searchsploit

履歴

プロジェクトの歴史と使われ方

Exploit-DB is OffSec's public archive of exploit code, shellcode, papers, and proof-of-concept material for vulnerable software. It is built for penetration testers and vulnerability researchers who need searchable, actionable examples rather than advisory prose.

The Homebrew package is mostly useful because it installs the database and SearchSploit, the command-line tool for querying a local checkout. That makes Exploit-DB one of the rare security datasets that package managers ship as a practical offline research corpus.

プロジェクトの歴史

The archive traces back to milw0rm, a public exploit archive started by str0ke in early 2004 after another exploit source moved behind a paid model. OffSec's history page presents milw0rm as a trusted community source because submitted exploits were verified before inclusion.

In July 2009, str0ke announced that milw0rm would close, then said it would continue temporarily because of community demand. OffSec took over the database in November 2009, launched the exploit-db.com domain that month, and continued the service as Exploit-DB.

The current GitLab repository is the official source tree for Exploit-DB exploits and shellcode, with companion repositories for binary exploits and papers. Its README says the repository is updated daily with recent submissions.

採用の歴史

Exploit-DB became a standard reference because it preserved working exploit and proof-of-concept material in a searchable form. OffSec describes it as a non-profit public-service project and a CVE-compliant archive intended for penetration testers and vulnerability researchers.

SearchSploit turned the web archive into a local Unix workflow. The official manual documents Kali Linux packaging, Git installation, and Homebrew installation, and notes that the standard Kali GNOME build includes the exploitdb package by default.

使われ方

SearchSploit searches a local copy of Exploit-DB by one or more terms, with options for title-only searches, exact matching, CVE lookup, JSON output, Nmap XML correlation, path lookup, and mirroring selected exploits into a working directory.

The manual emphasizes offline use: a tester can take a local checkout into segregated or air-gapped networks, update it later, and optionally add binary-exploit and papers repositories for more complete local data.

パッケージ好きにとっての重要性

Exploit-DB is a package-manager oddity: it is both a command-line program and a frequently updated vulnerability corpus. Installing it with Homebrew or apt gives users a filesystem tree of exploits plus a shell-oriented search interface.

For Unix users, the interesting part is not just the executable but the layout and update behavior: SearchSploit reads CSV indexes, points at exploit/shellcode/paper paths through .searchsploit_rc, and can be kept current through package updates or git.

タイムライン

  • 2004: str0ke starts a public exploit archive that becomes milw0rm.
  • 2009-07-08: str0ke announces the site will close.
  • 2009-11-04: OffSec is publicly reported as the group taking over the database.
  • 2009-11-16: The OffSec handover goes live.
  • 2009-11-17: exploit-db.com is set up.
  • 2010: milw0rm closes for good after no longer accepting updates.
  • 2016: SearchSploit users with older Kali packages are directed to update through the traditional package manager before using newer update behavior.

Related projects

  • SearchSploit is the bundled command-line search tool for the local Exploit-DB repository.
  • The Google Hacking Database is maintained by OffSec as an extension of Exploit-DB.
  • exploitdb-bin-sploits and exploitdb-papers are companion repositories for binary exploit files and papers.

セキュリティ状態

リスクレベル: red

escape, surveillance, or offensive capability signal.

リスク分類器

リスク red · 信頼度 中 · escape-surveillance-offensive

理由

  • escape, surveillance, or offensive capability signal

信号

  • text:exploit

インストール挙動

  • formula メタデータに Homebrew post-install フックは記録されていません。
  • Homebrew bottle メタデータは 6 個のプラットフォームターゲットで利用できます。

推奨レビュー

エージェントに無人実行させる前に、このツールが平文の認証情報を読むか、リモート状態を書き込むか、成果物を公開するか、プラグインを起動するかを確認してください。

local files

Configuration and credential file locations

These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.

Configuration files

Config paths the tool may read or write during local use.

Unix
<exploitdb checkout>/.searchsploit_rc

実行可能ファイル

インストールされる実行可能ファイル

コマンド種類公開範囲メモ
searchsploitcliグローバル実行可能ファイル

鮮度

バージョンと鮮度

これらの信号は、ページ生成時期、パッケージマネージャの活動、上流リリース比較を分けて示します。バージョン遅れは、証拠 URL と比較可能なバージョンがある場合だけ警告されます。

ページ生成日2026-07-25
マネージャ版2026-07-09
マネージャ更新日2026-07-09
ローカルデータOK
上流not checked
検出された最新未検出

https://www.exploit-db.com/

インストールメタデータ

パッケージメタデータ

パッケージキーbrew:exploitdb
バージョン2026-07-09
パッケージマネージャHomebrew
パッケージマネージャページhttps://formulae.brew.sh/formula/exploitdb
ホームページhttps://www.exploit-db.com/
リポジトリhttps://gitlab.com/exploit-database/exploitdb
上流ドキュメントhttps://gitlab.com/exploit-database/exploitdb
ライセンスGPL-2.0-or-later
ソースアーカイブhttps://gitlab.com/exploit-database/exploitdb.git
最終更新2026-07-09T06:53:23Z
Pulseupdated
Bottle利用可能 (対象 arm64_linux, arm64_sequoia, arm64_sonoma, arm64_tahoe, sonoma, x86_64_linux)
Homebrew post-install未定義
サービス宣言なし

レジストリ情報

ソースデータベース詳細

Source DatabaseHomebrew formula API
Taphomebrew/core
Full Nameexploitdb
Version Scheme0
Revision0
Head VersionHEAD
Bottle Stable Root URLhttps://ghcr.io/v2/homebrew/core
Deprecatedno
Disabledno
Keg Onlyno
URL Keys
  • head
  • stable

ソースデータベース一致

他のパッケージマネージャ記録

一致は外部パッケージマネージャインデックスから取得され、ローカルの Automic Vault パッケージリンクとは分けて表示されます。

Nix95%

exploitdb

nix profile install nixpkgs#exploitdb
  • normalized package name match
  • 一致条件: Exploitdb
nixpkgs package indexes · api.github.com · nixpkgs package indexes: pkgs/by-name/ex/exploitdb/package.nix from https://api.github.com/repos/NixOS/nixpkgs/git/trees/master?recursive=1
pacman95%

exploitdb 20260602-1

Offensive Security’s Exploit Database Archive

https://www.exploit-db.com/

sudo pacman -S exploitdb
  • License: GPL-2.0-or-later
  • Architecture: any
  • 2 任意依存関係
  • normalized package name match
  • 一致条件: Exploitdb
Arch Linux sync databases · geo.mirror.pkgbuild.com · Arch Linux sync databases: exploitdb from https://geo.mirror.pkgbuild.com/extra/os/x86_64/extra.db.tar.gz
MacPorts95%

exploitdb

sudo port install exploitdb
  • normalized package name match
  • 一致条件: Exploitdb
MacPorts ports tree · api.github.com · MacPorts ports tree: security/exploitdb/Portfile from https://api.github.com/repos/macports/macports-ports/git/trees/master?recursive=1

ソース経路

リポジトリデータから生成

このページは scripts/generate-pkg-sqlite.py が生成した非公開のパッケージ SQLite アーティファクトから av-web によって提供されます。

使用ソース

  • Geiger risk classifier
  • Nucleus package database
  • av.db category and tag curation
  • cross-ecosystem install command graph
  • curated configuration and credential file locations
  • curated package history
  • external package-manager database matches
  • package relationship graph
  • package version freshness
  • package-page enrichment