-
Notifications
You must be signed in to change notification settings - Fork 20
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
- Loading branch information
Mohammed Diaa
committed
Mar 21, 2022
1 parent
da949d3
commit 28ea930
Showing
1 changed file
with
43 additions
and
2 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -1,2 +1,43 @@ | ||
# pocs | ||
Get the CVE POCs from Github. | ||
# Find-gh-poc | ||
The centerpiece of the [trickest/cve](https://github.com/trickest/cve) project; finds CVE POCs in Github. | ||
## Installation | ||
### From binary | ||
Download a prebuilt binary from the [releases page](https://github.com/trickest/find-gh-poc/releases/latest) and unzip it. | ||
|
||
### From source | ||
Go version 1.17 is recommended. | ||
``` | ||
go install -v github.com/trickest/find-gh-poc@latest | ||
``` | ||
|
||
### Docker | ||
``` | ||
docker pull trickest/find-gh-poc | ||
``` | ||
|
||
## Command line options | ||
``` | ||
-query-string string | ||
GraphQL search query | ||
-query-file string | ||
File to read GraphQL search query from | ||
-silent | ||
Don't print JSON output to stdout | ||
-token-string string | ||
Github token | ||
-token-file string | ||
File to read Github token from | ||
-o string | ||
Output file name | ||
``` | ||
|
||
## Query examples | ||
- cve-2022 | ||
- cve-2022-1234 | ||
- jenkins | ||
|
||
## Note on Results | ||
Depending on the search query, the results will most likely contain a few false positives (either PoCs of other CVEs or irrelevant repositories). Find-gh-poc outputs all of the query results without (currently) trying to filter them. We recommend that you use the results as a starting point and do your own filtering as you see fit for your use case. | ||
|
||
## References | ||
https://github.com/trickest/cve |