
OffSec Exploit-DB
Threat Intelligence- Overview
- Setup
- Data & mappings
- Operations & API
- Changelog
The OffSec Exploit-DB Connector synchronizes the public Exploit Database, OffSec's archive of exploits and proof-of-concept code, into Brinqa. It reads the three index files OffSec publishes in the official exploit-database/exploitdb GitLab repository — the exploit index, the shellcode index and the Google Hacking Database — and maps each record to a Threat Intel record. Every record that names a CVE carries it in CVE_IDS and CVE_RECORDS, so exploit availability links to the platform's CVE records and can enrich vulnerability prioritization. The index is refreshed daily by OffSec.
Data retrieved from OffSec Exploit-DB
| Connector Object | Required | Maps to Data Model |
|---|---|---|
| Exploit | Yes | Threat Intel |
| Shellcode | Yes | Threat Intel |
| Google Hack | Yes | Threat Intel |
Model relationships
For detailed steps on how to view the data retrieved from OffSec Exploit-DB in the Brinqa Platform, see How to view your data.
Connection settings
When setting up a data integration, select OffSec Exploit-DB from the Connector dropdown and provide the following:
| Setting | Required | Default | Description |
|---|---|---|---|
| URL | Yes | https://gitlab.com/exploit-database/exploitdb/-/raw/main | Base URL of the raw Exploit-DB repository files (files_exploits.csv, files_shellcodes.csv, ghdb.xml) |
| Maximum retries | No | 5 | The maximum number of retry attempts before giving up a request |
Authentication
The Exploit-DB repository is public and served over anonymous HTTPS. The connector does not send any credential, API key, bearer token or basic-auth header, and no authentication configuration is required.
| Method | URL |
|---|---|
GET | {url}/files_shellcodes.csv |
Connectivity is verified by fetching the shellcode index, the smallest of the three files. All sync requests are plain anonymous GET requests against the same base URL.
Sync Behavior
Each sync downloads the complete index file for the model being synced and filters it locally. The first sync (no sync token) emits every record. Later syncs are incremental: the connector keeps the start time of the previous sync as its sync token and emits only the records whose change date falls on or after that day. Exploit-DB dates carry no time of day, so the token is rounded down to midnight UTC before comparing, and a record changed later on the same day as the previous sync is still picked up.
The repository does not support If-Modified-Since, so the files are downloaded on every sync (about 10 MB for exploits, 5.5 MB for the Google Hacking Database and 0.2 MB for shellcodes) and parsed as a stream.
How to obtain OffSec Exploit-DB credentials
Obtain the required credentials (url) from your OffSec Exploit-DB administrator or the OffSec Exploit-DB admin console, then enter them in the connection settings above.
Attribute mappings
Expand the sections below to view the mappings between the source and the Brinqa data model attributes:
Exploit
| Source Field Name | SDM Attribute |
|---|---|
ExploitResource.aliases | ALIASES |
ExploitResource.application_url | APPLICATION_URL |
ExploitResource.author | AUTHOR |
ExploitResource.codes | CVE_IDS |
ExploitResource.codes | CVE_RECORDS |
ExploitResource.codes | CODES |
ExploitResource.date_added | SOURCE_CREATED_DATE |
ExploitResource.date_published | PUBLISHED_DATE |
ExploitResource.date_updated | SOURCE_LAST_MODIFIED |
ExploitResource.description | NAME |
ExploitResource.file | PATH |
ExploitResource.id | UID |
ExploitResource.id | URL |
ExploitResource.platform | PLATFORM |
ExploitResource.port | PORT |
ExploitResource.screenshot_url | SCREENSHOT_URL |
ExploitResource.source_url | SOURCE_URL |
ExploitResource.tags | TAGS |
ExploitResource.type | EXPLOIT_TYPE |
ExploitResource.verified | VERIFIED |
| sync start time | LAST_CAPTURED |
Shellcode
| Source Field Name | SDM Attribute |
|---|---|
ShellcodeResource.aliases | ALIASES |
ShellcodeResource.application_url | APPLICATION_URL |
ShellcodeResource.author | AUTHOR |
ShellcodeResource.codes | CVE_IDS |
ShellcodeResource.codes | CVE_RECORDS |
ShellcodeResource.codes | CODES |
ShellcodeResource.date_added | SOURCE_CREATED_DATE |
ShellcodeResource.date_published | PUBLISHED_DATE |
ShellcodeResource.date_updated | SOURCE_LAST_MODIFIED |
ShellcodeResource.description | NAME |
ShellcodeResource.file | PATH |
ShellcodeResource.id | UID |
ShellcodeResource.id | URL |
ShellcodeResource.platform | PLATFORM |
ShellcodeResource.screenshot_url | SCREENSHOT_URL |
ShellcodeResource.size | SIZE |
ShellcodeResource.source_url | SOURCE_URL |
ShellcodeResource.tags | TAGS |
ShellcodeResource.type | SHELLCODE_TYPE |
ShellcodeResource.verified | VERIFIED |
| sync start time | LAST_CAPTURED |
Google Hack
| Source Field Name | SDM Attribute |
|---|---|
GoogleHackResource.author | AUTHOR |
GoogleHackResource.category | CATEGORIES |
GoogleHackResource.date | PUBLISHED_DATE |
GoogleHackResource.edb | EXPLOITS |
GoogleHackResource.id | UID |
GoogleHackResource.link | URL |
GoogleHackResource.query | QUERY |
GoogleHackResource.querystring | SEARCH_URL |
GoogleHackResource.shortDescription | NAME |
GoogleHackResource.textualDescription | DESCRIPTION |
GoogleHackResource.textualDescription | CVE_IDS |
GoogleHackResource.textualDescription | CVE_RECORDS |
| sync start time | LAST_CAPTURED |
Operations & API
Expand each connector object to see its operation options, delta-sync behavior, and the API it uses. See connector operation options for how to apply operation options (keys and values are case-sensitive).
Exploit
Operation options
This object does not support any operation options.
Delta sync
Supported. The connector performs an incremental (delta) sync via the since sync token, filtering on date_updated.
API
- Type: CSV report (anonymous HTTPS download of a raw repository file) · Endpoint:
GET {url}/files_exploits.csv - Default filters: None — every row is read; incremental syncs filter locally on the change date
Shellcode
Operation options
This object does not support any operation options.
Delta sync
Supported. The connector performs an incremental (delta) sync via the since sync token, filtering on date_updated.
API
- Type: CSV report (anonymous HTTPS download of a raw repository file) · Endpoint:
GET {url}/files_shellcodes.csv - Default filters: None — every row is read; incremental syncs filter locally on the change date
Google Hack
Operation options
This object does not support any operation options.
Delta sync
Supported. The connector performs an incremental (delta) sync via the since sync token, filtering on date.
API
- Type: REST endpoint (anonymous HTTPS download of a raw XML repository file) · Endpoint:
GET {url}/ghdb.xml - Default filters: None — every entry is read; incremental syncs filter locally on the entry date
- GHDB has no CVE field. CVE ids are extracted from the description text, which covers about 1,000 of the 8,000 entries; entries that describe a vulnerability without naming its CVE carry no
CVE_IDS.
Changelog
The OffSec Exploit-DB connector has undergone the following changes:
| Version | Description | Migration Steps |
|---|---|---|
| 3.0.0 | Overview The OffSec Exploit-DB connector integrates with the public Exploit Database maintained by OffSec to synchronize exploits, shellcodes and Google Hacking Database queries, each linked to the CVE records it names, as an open signal of exploit availability for vulnerability prioritization. No credentials are required. Category: Threat Intelligence Models | N/A |