# tr0uble-mAker/POC-bomber

利用大量高威胁poc/exp快速获取目标权限，用于渗透和红队快速打点

Repository: https://github.com/tr0uble-mAker/POC-bomber
Canonical: https://ross.abutalabs.com/products/poc-bomber
Language: Python
License: GPL-3.0
License Family: copyleft
Topics: poc, vulnerability-scanner, poc-bomber, cve, rce, getshell, redteam, exp
Last push: 2023-06-09T13:20:09+00:00

## Health v2 (maintenance only)
Score: 23/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 0, release rhythm 8, longevity 100
- inputs: {"age_days": 1741, "days_push": 1181, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 2369, forks 386 (observed 2026-08-28T04:06:41.728970+00:00)

## What it is
POC-bomber is a Python-based offensive security tool that bundles a large arsenal of high-impact POCs and EXPs (RCE, deserialization, file upload, SQL injection) to rapidly detect and exploit vulnerable targets. It supports single and batch scanning with a concurrent thread pool, DNSLOG-based blind RCE detection, custom POC import, and an attack mode for one-click exploitation.

## Use cases
- batch scan a list of urls for known cve exploits
- quickly find exploitable assets during red team engagements
- detect blind rce like log4j2 using dnslog
- run a specific exploit like thinkphp rce against a target
- build a personal vulnerability scanner with custom pocs
- fuzz many targets for high-severity vulnerabilities

## When to choose
- you need fast bulk exploitation of known high-severity vulnerabilities across many targets
- you are doing authorized red team work or attack-surface assessment and want a ready-made poc arsenal
- you want dnslog-based detection of no-echo rce vulnerabilities

## When to avoid
- you need a compliant enterprise vulnerability scanner with reporting and asset management
- you only want passive or non-intrusive vulnerability assessment
- you lack explicit authorization to test the targets, as this tool performs active exploitation

## Facets
- artifact type: cli-tool
- maturity: maintenance
- function: vulnerability-scanning, penetration-testing, security
- domain: security, penetration-testing, developer-tools
- platform: python, cli, windows
- tags: poc, exp, redteam, rce, getshell, cve, offensive-security, dnslog, batch-scanning, linux, macos

## Member repositories
- tr0uble-mAker/POC-bomber (main) score 23

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:06:41.728970+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T02:35:26.337111+00:00, confidence not recorded.
  - readme: https://github.com/tr0uble-mAker/POC-bomber (fetched 2026-08-28T04:06:41.728970+00:00, sha 5d560acda00e)
- Data as of 2026-08-30T08:39:29.467469+00:00.
