Skip to content

Nuclei Templates

Templated vulnerability scanner templates used with ProjectDiscovery Nuclei for fast, customisable scans.

Self-hostedNot yet verified
Report issue
MIT★ 10000Source project only — not browser-runnable

External Tool

This open-source tool is maintained externally. View the source on GitHub to learn more or run it yourself.

Browse network tools →

What's next with Nuclei Templates?

Choose how you want to get started.

Use it free

Open the official tool or demo — no account needed.

Free

Self-host it

Run the open-source version on your own infrastructure.

Open

What is Nuclei Templates?

Nuclei Templates is an open-source project that provides a community-curated collection of templates for the Nuclei vulnerability scanner. Its primary purpose is to enable security professionals and developers to systematically identify security vulnerabilities in web applications and APIs. The tool is widely used by penetration testers, DevOps teams, and cybersecurity researchers to automate the detection of common issues like insecure direct object references (IDOR), cross-site scripting (XSS), and misconfigured cloud services. By leveraging pre-defined templates, users can streamline their security assessments and prioritize critical risks without manually crafting complex scan rules. The project addresses the challenge of maintaining up-to-date vulnerability detection rules, offering a scalable solution that evolves with community contributions.

How it works

Nuclei Templates is a repository of reusable scan rules designed for the Nuclei vulnerability scanner. These templates define specific patterns to detect security flaws in target systems, such as HTTP request payloads or response headers that indicate misconfigurations. The project serves as a centralized hub for security researchers to share and refine detection rules, reducing the time required to build custom scanners. It is particularly valuable for organizations needing rapid, standardized security testing workflows. The templates support multiple protocols (HTTP, DNS, SSH) and include specialized rules for detecting vulnerabilities like insecure API endpoints, exposed sensitive data, and misconfigured cloud storage. For example, a template might check for a missing `X-Content-Type-Options` header, which could enable MIME type sniffing attacks.

How to use it

  1. 1Install Nuclei via its official repository or package managers. 2. Clone the Nuclei Templates repository using `git clone https://github.com/projectdiscovery/nuclei-templates`. 3. Run scans with `nuclei -t templates/xxx.yaml -u <target>`, replacing `<target>` with the URL to test. 4. Filter results using tags like `tag:misconfig` to narrow findings. Practical tips include using the `--update` flag to sync with the latest templates, combining templates with custom rules, and leveraging the `--disable-all` flag to isolate specific rule sets for targeted testing.

What it can do

  • vulnerability templates

Use cases

Assumptions and limitations

Assumptions

  • source: https://github.com/projectdiscovery/nuclei-templates
  • license: MIT — free to use
  • privacy: Self-hosted — you control your data

Limitations

  • Requires prior installation of the Nuclei scanner, which may have a steeper learning curve for beginners
  • Templates depend on accurate target metadata (e.g., correct HTTP headers or endpoints), which may not always be available
  • False positives can occur if templates are applied to non-target systems without proper filtering
  • Does not inherently support real-time data sources like live network traffic or dynamic content
  • Customization of templates requires familiarity with YAML syntax and Nuclei's rule structure

Understanding the result

Templated vulnerability scanner templates used with ProjectDiscovery Nuclei for fast, customisable scans.

Tool details

  • Clearly flagged when a network request is needed.
  • No account, no sign-up, and no tracking of your content.
  • Powered by (MIT).
Built with
(projectdiscovery/nuclei-templates)
License
MIT
Runs locally
No — requires a network request
Verification
Not yet verified
Input
Query
Output
Text
Open-source source & license

Built with projectdiscovery/nuclei-templates. OpenToolVault provides the discovery and browser interface while crediting the original project maintainers.

Built with
License
MIT
View source on GitHub

Open-source project

OpenToolVault is an independent directory. We are not affiliated with or endorsed by this project.

References

Frequently asked

What is the relationship between Nuclei Templates and the Nuclei scanner?

Nuclei Templates is a separate repository that provides pre-built scan rules for the Nuclei scanner. While Nuclei handles the execution of scans, the templates define the specific patterns and conditions used to detect vulnerabilities. Users must install both tools separately, though the templates are often included in Nuclei's default configuration.

How does Nuclei Templates handle false positives?

The project minimizes false positives by using precise HTTP request/response patterns and context-aware checks. However, users should validate findings manually, as templates may trigger alerts for benign scenarios (e.g., a legitimate debug endpoint). Filtering with tags like `tag:low` or `tag:info` can help prioritize critical issues.

How do I create a custom template for Nuclei?

To create a template, define a YAML file with `id`, `info`, and `matchers` sections. For example, a template to detect an IDOR vulnerability might include a `matcher` that checks for a `200` response when a parameter is manipulated. Submit the template via a pull request to the nuclei-templates repository, ensuring it adheres to the project's contribution guidelines.

How does Nuclei Templates compare to tools like OpenVAS or Nikto?

Unlike OpenVAS (a comprehensive network scanner) or Nikto (a web server auditor), Nuclei Templates focuses on high-speed, rule-based vulnerability detection for specific targets. It excels in targeted scans with customizable rules, whereas OpenVAS and Nikto offer broader scanning capabilities but require more manual configuration.

What should I do if a template fails to run?

Common issues include incorrect file paths, missing dependencies, or incompatible template syntax. Verify the template's YAML structure, ensure the Nuclei version matches the template's requirements, and check for typos in the `matchers` section. If problems persist, consult the project's GitHub issues page for troubleshooting guidance.

Spotted something wrong with Nuclei Templates, or want to maintain it? See how to help.