← All cheat sheets

NUCLEI

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

Fast, template-based vulnerability scanner by ProjectDiscovery.
Massive community template library covering CVEs, misconfigs,
exposures, and more.

INSTALLATION#

# Go install
go install -v github.com/projectdiscovery/nuclei/v3/cmd/nuclei@latest

# Homebrew
brew install nuclei

# Docker
docker pull projectdiscovery/nuclei

# Download binary
# https://github.com/projectdiscovery/nuclei/releases

# Update templates
nuclei -ut                                  # Update templates
nuclei -update                              # Update nuclei binary

BASIC USAGE#

# Single target
nuclei -u https://example.com

# Multiple targets
nuclei -u https://example.com -u https://test.com

# From file
nuclei -l targets.txt

# From stdin (pipe from other tools)
cat targets.txt | nuclei
subfinder -d example.com | httpx | nuclei
echo https://example.com | nuclei

TEMPLATE SELECTION#

# By template ID
nuclei -u URL -t cves/2021/CVE-2021-44228.yaml
nuclei -u URL -t cves/                      # All CVE templates

# By template directory
nuclei -u URL -t cves/
nuclei -u URL -t exposures/
nuclei -u URL -t misconfiguration/
nuclei -u URL -t vulnerabilities/
nuclei -u URL -t technologies/
nuclei -u URL -t default-logins/
nuclei -u URL -t takeovers/

# By tags
nuclei -u URL -tags cve                     # All CVE templates
nuclei -u URL -tags rce                     # Remote code execution
nuclei -u URL -tags sqli                    # SQL injection
nuclei -u URL -tags xss                     # Cross-site scripting
nuclei -u URL -tags ssrf                    # Server-side request forgery
nuclei -u URL -tags lfi                     # Local file inclusion
nuclei -u URL -tags redirect                # Open redirect
nuclei -u URL -tags exposure                # Information exposure
nuclei -u URL -tags misconfig               # Misconfigurations
nuclei -u URL -tags takeover                # Subdomain takeover
nuclei -u URL -tags default-login           # Default credentials
nuclei -u URL -tags tech                    # Technology detection
nuclei -u URL -tags panel                   # Admin panels
nuclei -u URL -tags wordpress               # WordPress specific
nuclei -u URL -tags joomla                  # Joomla specific
nuclei -u URL -tags apache                  # Apache specific
nuclei -u URL -tags nginx                   # nginx specific

# By severity
nuclei -u URL -severity critical
nuclei -u URL -severity critical,high
nuclei -u URL -severity critical,high,medium
nuclei -u URL -severity low,info

# By author
nuclei -u URL -author pdteam
nuclei -u URL -author dhiyaneshdk

# Exclude templates
nuclei -u URL -exclude-tags dos             # Exclude DoS templates
nuclei -u URL -exclude-tags fuzz            # Exclude fuzzing
nuclei -u URL -et cves/2020/               # Exclude old CVEs

# Multiple filters
nuclei -u URL -tags cve -severity critical,high

TEMPLATE CATEGORIES#

Directory              Contents
---------              --------
cves/                  Known CVE exploits (by year)
vulnerabilities/       Generic vulnerability checks
misconfiguration/      Security misconfigurations
exposures/             Sensitive file/data exposure
technologies/          Technology/version detection
default-logins/        Default credential checks
takeovers/             Subdomain takeover detection
file/                  Local file analysis templates
dns/                   DNS-based checks
ssl/                   SSL/TLS configuration checks
headless/              Browser-based (headless) checks
workflows/             Multi-step template workflows
fuzzing/               Fuzzing templates

OUTPUT OPTIONS#

# Output to file
nuclei -u URL -o results.txt

# JSON output
nuclei -u URL -json -o results.json
nuclei -u URL -jsonl -o results.jsonl       # JSON Lines

# Markdown output
nuclei -u URL -markdown-export report/

# SARIF output (for CI/CD integration)
nuclei -u URL -sarif-export results.sarif

# Verbose output
nuclei -u URL -v                            # Verbose
nuclei -u URL -vv                           # Very verbose
nuclei -u URL -debug                        # Debug mode

# Silent (results only)
nuclei -u URL -silent

# Store matched responses
nuclei -u URL -store-resp -store-resp-dir ./responses/

# No color
nuclei -u URL -nc

PERFORMANCE TUNING#

# Rate limiting
nuclei -u URL -rl 100                       # 100 requests/second
nuclei -u URL -rlm 1000                     # 1000 requests/minute

# Concurrency
nuclei -u URL -c 50                         # 50 concurrent templates
nuclei -u URL -bs 25                        # Bulk size (hosts in parallel)
nuclei -u URL -hbs 10                       # Host-based semaphore

# Timeout
nuclei -u URL -timeout 10                   # Request timeout (seconds)
nuclei -u URL -retries 3                    # Max retries

# HTTP options
nuclei -u URL -header "Authorization: Bearer TOKEN"
nuclei -u URL -header "Cookie: session=abc123"
nuclei -u URL -proxy http://127.0.0.1:8080
nuclei -u URL -follow-redirects
nuclei -u URL -max-redirects 5

AUTHENTICATION#

# Custom headers
nuclei -l targets.txt -H "Authorization: Bearer TOKEN"
nuclei -l targets.txt -H "Cookie: session=VALUE"

# Multiple headers
nuclei -l targets.txt -H "Authorization: Bearer TOKEN" -H "X-Custom: value"

SCANNING WORKFLOWS#

# 1. Quick recon scan (technology detection)
nuclei -u URL -tags tech -silent

# 2. Vulnerability scan (critical + high only)
nuclei -l targets.txt -severity critical,high -o vulns.txt

# 3. Full scan with all templates
nuclei -l targets.txt -o full_scan.txt

# 4. CVE-specific scan
nuclei -l targets.txt -t cves/ -severity critical -o cves.txt

# 5. Misconfig + exposure check
nuclei -l targets.txt -tags misconfig,exposure -o misconfig.txt

# 6. Default credential check
nuclei -l targets.txt -t default-logins/ -o defaults.txt

# 7. Subdomain takeover
nuclei -l subdomains.txt -t takeovers/ -o takeovers.txt

# 8. CI/CD pipeline integration
nuclei -l targets.txt -severity critical,high -sarif-export results.sarif

PROJECTDISCOVERY PIPELINE#

# Full recon → scan pipeline
# 1. Subdomain enumeration
subfinder -d example.com -o subs.txt

# 2. HTTP probing
cat subs.txt | httpx -o alive.txt

# 3. Vulnerability scanning
nuclei -l alive.txt -severity critical,high -o vulns.txt

# 4. With more tools
subfinder -d example.com | httpx | nuclei -severity critical,high

# Additional tools in the pipeline
katana -u URL                               # Web crawling
httpx -l subs.txt -tech-detect              # HTTP probing + tech
dnsx -l subs.txt                            # DNS resolution
naabu -l subs.txt -p -                      # Port scanning

WRITING CUSTOM TEMPLATES#

# Template structure
id: my-custom-check
info:
  name: Custom Security Check
  author: yourname
  severity: medium
  description: Checks for specific vulnerability
  tags: custom,web

http:
  - method: GET
    path:
      - "{{BaseURL}}/admin"
    matchers-condition: and
    matchers:
      - type: status
        status:
          - 200
      - type: word
        words:
          - "Admin Panel"

# Request methods
  method: GET | POST | PUT | DELETE | PATCH | HEAD | OPTIONS

# Variables
  {{BaseURL}}                               # Full URL with path
  {{RootURL}}                               # URL without path
  {{Hostname}}                              # Just hostname
  {{Host}}                                  # Host:port
  {{Port}}                                  # Port number
  {{Path}}                                  # URL path
  {{Scheme}}                                # http or https

# Matchers
  - type: status                            # HTTP status code
  - type: word                              # String match
  - type: regex                             # Regex match
  - type: binary                            # Binary match
  - type: size                              # Response size
  - type: dsl                               # DSL expression

# Extractors
  extractors:
    - type: regex
      regex:
        - 'version["\s:]+([0-9.]+)'
      group: 1

# Multi-step requests
http:
  - raw:
      - |
        POST /login HTTP/1.1
        Host: {{Hostname}}
        Content-Type: application/json

        {"user":"admin","pass":"admin"}
      - |
        GET /admin HTTP/1.1
        Host: {{Hostname}}
    cookie-reuse: true

# Validate custom template
nuclei -t my-template.yaml -validate

INTERACTSH (OOB TESTING)#

# Built-in out-of-band interaction server
nuclei -u URL -iserver https://interact.sh
nuclei -u URL -itoken YOUR_TOKEN

# Used for detecting:
  - Blind SSRF
  - Blind XSS
  - DNS exfiltration
  - Out-of-band RCE

TIPS#

  - Update templates frequently (nuclei -ut)
  - Start with -severity critical,high to reduce noise
  - Use -tags to focus on specific vulnerability classes
  - Pipe from subfinder + httpx for full recon workflows
  - Write custom templates for app-specific checks
  - Use -proxy to route through Burp/Caido for manual review
  - -rl flag prevents overwhelming targets
  - Community templates cover 7000+ checks
  - Use -store-resp to save evidence for reporting
  - Combine with katana (crawler) for deeper coverage
  - -exclude-tags dos,fuzz for safe scanning
  - JSON output integrates with SIEM and ticketing systems