Nuclei
Fast, template-based vulnerability scanner that sends requests to targets and matches results against templates.
External Tool
This open-source tool is maintained externally. View the source on GitHub to learn more or run it yourself.
Browse security tools →What's next with Nuclei?
Choose how you want to get started.
Use it free
Open the official tool or demo — no account needed.
Self-host it
Run the open-source version on your own infrastructure.
What is Nuclei?
Nuclei is an open-source vulnerability scanner designed to identify security weaknesses in web applications, APIs, networks, DNS configurations, and cloud infrastructure. It leverages a YAML-based domain-specific language (DSL) to enable users to create customizable templates for detecting vulnerabilities, making it a collaborative tool for security professionals and DevOps teams. The tool addresses the challenge of efficiently scanning large attack surfaces while minimizing false positives through real-world scenario simulations. Its high-performance architecture allows for rapid parallel processing, making it suitable for both manual audits and automated CI/CD pipeline integrations. Nuclei is particularly valuable for organizations seeking to proactively manage security risks across diverse systems without relying on proprietary solutions.
How it works
Nuclei is a fast, open-source vulnerability scanner developed by the projectdiscovery team. It enables security researchers and developers to detect vulnerabilities in target systems by executing customizable templates that mimic real-world attack vectors. The primary purpose of Nuclei is to streamline the process of identifying security flaws in web applications, APIs, and infrastructure. By using a YAML-based DSL, users can define precise detection rules, ensuring accurate and repeatable scans. Nuclei supports rapid, parallelized scanning with request clustering to optimize performance. It integrates with CI/CD pipelines for continuous vulnerability detection and regression testing. The tool also includes a vast library of templates contributed by the security community, covering common vulnerabilities like misconfigurations, insecure endpoints, and outdated dependencies.
How to use it
- 1Install Nuclei via package managers like Homebrew or by cloning the GitHub repository. 2. Download pre-built templates from the official templates repository or create custom YAML rules. 3. Run scans using the `nuclei -t` command with target URLs or IP ranges. 4. Analyze results in real-time with the built-in terminal interface or export to JSON/CSV for further processing. Practical tips include using the `-u` flag for single-target scans, leveraging the `--update-templates` flag to sync with the latest community templates, and combining Nuclei with tools like HTTP servers for testing custom payloads.
What it can do
- vulnerability template scanner
Use cases
Assumptions and limitations
Assumptions
- source: https://github.com/projectdiscovery/nuclei
- license: MIT — free to use
- privacy: Self-hosted — you control your data
Limitations
- Dual-use tool — use only with explicit authorization on systems you own or have permission to test.
- Requires technical expertise to create and customize YAML templates
- May generate false positives if templates lack precise matching criteria
- Limited support for non-HTTP protocols beyond basic network scanning
- Depends on community-maintained templates for emerging vulnerabilities
Understanding the result
Fast, template-based vulnerability scanner that sends requests to targets and matches results against templates.
Tool details
- Clearly flagged when a network request is needed.
- No account, no sign-up, and no tracking of your content.
- Powered by (MIT).
- Built with
- (projectdiscovery/nuclei)
- License
- MIT
- Runs locally
- No — requires a network request
- Verification
- Not yet verified
- Input
- Query
- Output
- Text
Built with projectdiscovery/nuclei. OpenToolVault provides the discovery and browser interface while crediting the original project maintainers.
- Built with
- License
- MIT
Open-source project
OpenToolVault is an independent directory. We are not affiliated with or endorsed by this project.
References
- / — GitHub Repository
Upstream project · GitHub
- MIT License
Upstream project
Frequently asked
What is Nuclei and how does it differ from other vulnerability scanners?
Nuclei is a YAML-based vulnerability scanner focused on speed and customization. Unlike traditional tools that rely on predefined rules, Nuclei uses a domain-specific language (DSL) to allow users to define precise detection scenarios. This enables real-time adaptability to new threats while maintaining high performance through parallel processing. Its open-source model also fosters community contributions, expanding its coverage beyond proprietary tools.
How does Nuclei handle false positives during scans?
Nuclei reduces false positives by simulating real-world attack steps in its templates. For example, a template for detecting misconfigured S3 buckets includes specific HTTP request patterns and response validation. Users can further refine accuracy by adjusting matchers, thresholds, and request parameters. The tool also provides filtering options to exclude non-critical findings.
How do I run a basic scan with Nuclei?
Install Nuclei using `go get github.com/projectdiscovery/nuclei/cmd/nuclei` or download binaries. Then, execute `nuclei -t templates/techniques/http/brute-force.yaml -u https://target.com` to run a brute-force detection scan. Replace the template path with your custom YAML file or a community template. Use `-u` for single-target scans or `-l` to load multiple URLs from a file.
How does Nuclei compare to tools like Nikto or OpenVAS?
Nuclei excels in speed and customization, using YAML templates for precise vulnerability detection. Nikto is a legacy tool focused on web server checks with limited extensibility, while OpenVAS offers comprehensive vulnerability management but requires complex setup. Nuclei's parallel processing and modular design make it more suitable for modern, large-scale infrastructure audits compared to these alternatives.
What should I do if Nuclei returns 'no templates found'?
This error occurs when the templates directory is missing or corrupted. Verify the installation by checking the `templates` folder in your Nuclei directory. If absent, re-download the templates using `nuclei -u https://raw.githubusercontent.com/projectdiscovery/nuclei-templates/master/` or reinstall the tool. Ensure internet connectivity and correct file permissions for template access.