NUCLEI
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
Fast, template-based vulnerability scanner by ProjectDiscovery. Massive community template library covering CVEs, misconfigs, exposures, and more.
INSTALLATION#
# Go install go install -v github.com/projectdiscovery/nuclei/v3/cmd/nuclei@latest # Homebrew brew install nuclei # Docker docker pull projectdiscovery/nuclei # Download binary # https://github.com/projectdiscovery/nuclei/releases # Update templates nuclei -ut # Update templates nuclei -update # Update nuclei binary
BASIC USAGE#
# Single target nuclei -u https://example.com # Multiple targets nuclei -u https://example.com -u https://test.com # From file nuclei -l targets.txt # From stdin (pipe from other tools) cat targets.txt | nuclei subfinder -d example.com | httpx | nuclei echo https://example.com | nuclei
TEMPLATE SELECTION#
# By template ID nuclei -u URL -t cves/2021/CVE-2021-44228.yaml nuclei -u URL -t cves/ # All CVE templates # By template directory nuclei -u URL -t cves/ nuclei -u URL -t exposures/ nuclei -u URL -t misconfiguration/ nuclei -u URL -t vulnerabilities/ nuclei -u URL -t technologies/ nuclei -u URL -t default-logins/ nuclei -u URL -t takeovers/ # By tags nuclei -u URL -tags cve # All CVE templates nuclei -u URL -tags rce # Remote code execution nuclei -u URL -tags sqli # SQL injection nuclei -u URL -tags xss # Cross-site scripting nuclei -u URL -tags ssrf # Server-side request forgery nuclei -u URL -tags lfi # Local file inclusion nuclei -u URL -tags redirect # Open redirect nuclei -u URL -tags exposure # Information exposure nuclei -u URL -tags misconfig # Misconfigurations nuclei -u URL -tags takeover # Subdomain takeover nuclei -u URL -tags default-login # Default credentials nuclei -u URL -tags tech # Technology detection nuclei -u URL -tags panel # Admin panels nuclei -u URL -tags wordpress # WordPress specific nuclei -u URL -tags joomla # Joomla specific nuclei -u URL -tags apache # Apache specific nuclei -u URL -tags nginx # nginx specific # By severity nuclei -u URL -severity critical nuclei -u URL -severity critical,high nuclei -u URL -severity critical,high,medium nuclei -u URL -severity low,info # By author nuclei -u URL -author pdteam nuclei -u URL -author dhiyaneshdk # Exclude templates nuclei -u URL -exclude-tags dos # Exclude DoS templates nuclei -u URL -exclude-tags fuzz # Exclude fuzzing nuclei -u URL -et cves/2020/ # Exclude old CVEs # Multiple filters nuclei -u URL -tags cve -severity critical,high
TEMPLATE CATEGORIES#
Directory Contents --------- -------- cves/ Known CVE exploits (by year) vulnerabilities/ Generic vulnerability checks misconfiguration/ Security misconfigurations exposures/ Sensitive file/data exposure technologies/ Technology/version detection default-logins/ Default credential checks takeovers/ Subdomain takeover detection file/ Local file analysis templates dns/ DNS-based checks ssl/ SSL/TLS configuration checks headless/ Browser-based (headless) checks workflows/ Multi-step template workflows fuzzing/ Fuzzing templates
OUTPUT OPTIONS#
# Output to file nuclei -u URL -o results.txt # JSON output nuclei -u URL -json -o results.json nuclei -u URL -jsonl -o results.jsonl # JSON Lines # Markdown output nuclei -u URL -markdown-export report/ # SARIF output (for CI/CD integration) nuclei -u URL -sarif-export results.sarif # Verbose output nuclei -u URL -v # Verbose nuclei -u URL -vv # Very verbose nuclei -u URL -debug # Debug mode # Silent (results only) nuclei -u URL -silent # Store matched responses nuclei -u URL -store-resp -store-resp-dir ./responses/ # No color nuclei -u URL -nc
PERFORMANCE TUNING#
# Rate limiting nuclei -u URL -rl 100 # 100 requests/second nuclei -u URL -rlm 1000 # 1000 requests/minute # Concurrency nuclei -u URL -c 50 # 50 concurrent templates nuclei -u URL -bs 25 # Bulk size (hosts in parallel) nuclei -u URL -hbs 10 # Host-based semaphore # Timeout nuclei -u URL -timeout 10 # Request timeout (seconds) nuclei -u URL -retries 3 # Max retries # HTTP options nuclei -u URL -header "Authorization: Bearer TOKEN" nuclei -u URL -header "Cookie: session=abc123" nuclei -u URL -proxy http://127.0.0.1:8080 nuclei -u URL -follow-redirects nuclei -u URL -max-redirects 5
AUTHENTICATION#
# Custom headers nuclei -l targets.txt -H "Authorization: Bearer TOKEN" nuclei -l targets.txt -H "Cookie: session=VALUE" # Multiple headers nuclei -l targets.txt -H "Authorization: Bearer TOKEN" -H "X-Custom: value"
SCANNING WORKFLOWS#
# 1. Quick recon scan (technology detection) nuclei -u URL -tags tech -silent # 2. Vulnerability scan (critical + high only) nuclei -l targets.txt -severity critical,high -o vulns.txt # 3. Full scan with all templates nuclei -l targets.txt -o full_scan.txt # 4. CVE-specific scan nuclei -l targets.txt -t cves/ -severity critical -o cves.txt # 5. Misconfig + exposure check nuclei -l targets.txt -tags misconfig,exposure -o misconfig.txt # 6. Default credential check nuclei -l targets.txt -t default-logins/ -o defaults.txt # 7. Subdomain takeover nuclei -l subdomains.txt -t takeovers/ -o takeovers.txt # 8. CI/CD pipeline integration nuclei -l targets.txt -severity critical,high -sarif-export results.sarif
PROJECTDISCOVERY PIPELINE#
# Full recon → scan pipeline # 1. Subdomain enumeration subfinder -d example.com -o subs.txt # 2. HTTP probing cat subs.txt | httpx -o alive.txt # 3. Vulnerability scanning nuclei -l alive.txt -severity critical,high -o vulns.txt # 4. With more tools subfinder -d example.com | httpx | nuclei -severity critical,high # Additional tools in the pipeline katana -u URL # Web crawling httpx -l subs.txt -tech-detect # HTTP probing + tech dnsx -l subs.txt # DNS resolution naabu -l subs.txt -p - # Port scanning
WRITING CUSTOM TEMPLATES#
# Template structure
id: my-custom-check
info:
name: Custom Security Check
author: yourname
severity: medium
description: Checks for specific vulnerability
tags: custom,web
http:
- method: GET
path:
- "{{BaseURL}}/admin"
matchers-condition: and
matchers:
- type: status
status:
- 200
- type: word
words:
- "Admin Panel"
# Request methods
method: GET | POST | PUT | DELETE | PATCH | HEAD | OPTIONS
# Variables
{{BaseURL}} # Full URL with path
{{RootURL}} # URL without path
{{Hostname}} # Just hostname
{{Host}} # Host:port
{{Port}} # Port number
{{Path}} # URL path
{{Scheme}} # http or https
# Matchers
- type: status # HTTP status code
- type: word # String match
- type: regex # Regex match
- type: binary # Binary match
- type: size # Response size
- type: dsl # DSL expression
# Extractors
extractors:
- type: regex
regex:
- 'version["\s:]+([0-9.]+)'
group: 1
# Multi-step requests
http:
- raw:
- |
POST /login HTTP/1.1
Host: {{Hostname}}
Content-Type: application/json
{"user":"admin","pass":"admin"}
- |
GET /admin HTTP/1.1
Host: {{Hostname}}
cookie-reuse: true
# Validate custom template
nuclei -t my-template.yaml -validate
INTERACTSH (OOB TESTING)#
# Built-in out-of-band interaction server nuclei -u URL -iserver https://interact.sh nuclei -u URL -itoken YOUR_TOKEN # Used for detecting: - Blind SSRF - Blind XSS - DNS exfiltration - Out-of-band RCE
TIPS#
- Update templates frequently (nuclei -ut) - Start with -severity critical,high to reduce noise - Use -tags to focus on specific vulnerability classes - Pipe from subfinder + httpx for full recon workflows - Write custom templates for app-specific checks - Use -proxy to route through Burp/Caido for manual review - -rl flag prevents overwhelming targets - Community templates cover 7000+ checks - Use -store-resp to save evidence for reporting - Combine with katana (crawler) for deeper coverage - -exclude-tags dos,fuzz for safe scanning - JSON output integrates with SIEM and ticketing systems